aKeyNeverAdoptsAnotherKeysLegacyOrphan

A file left behind by the legacy scheme must never be readable as a different key.

The fix ships no migration, so legacy files stay on disk in the same directory forever. otel.logs was stored as otel_logs; a scheme that treated _ as a safe character would hand a future StoreKey("otel_logs") the abandoned buffer of otel.logs — silent wrong-key data, strictly worse than the loss orphaning already accepts. Escaping _ (and ., and uppercase) is what makes the two namespaces provably disjoint.

The control file is not decoration. Every other assertion here is an absence, and an absence is exactly what a plantRawFile that wrote nowhere would also produce — the whole property would be green on a broken fixture, which is the failure mode a hook like this invites. spans is planted alongside, under a name both schemes leave alone, and the store is required to find it: that is the assertion which fails when the plant did not land.