whatWasWrittenBeforeARestartIsReadableAfterIt

The property DurableStore exists for: "A crash after DurableStore.write returns implies the bytes survive a restart and are returned by the next DurableStore.read."

Every other property in this file reads back off the object that took the write, so all of them are satisfied by a backend that has written nothing anywhere. This is the only place a second handle onto the medium is obtained, and therefore the only place the interface's own headline sentence is checked at all.

Three values cross the restart together, each catching a different way a backend loses one:

  1. kept — written once. The plain case.

  2. overwritten — written twice. A backend that commits the first write durably and the second only in memory comes back holding a stale value, which is worse than an absent one: the caller has no reason to distrust it.

  3. Both carry the everyByteValueSurvivesTheRoundTrip payload rather than 1, 2, 3, because a restart is the one path in this suite that crosses an encode/decode boundary, and that is exactly where a byte that widens on the way through bites.

On RestartFixture.KeepsNothing the assertions invert: everything must be gone. That arm is not a formality — a durable backend that declared it reds here, because its bytes come back. What it cannot do is prove anything about durability; see restart.