anEntryNeverLandsOnAnotherEntrysTempSidecar
An entry's filename can never equal another entry's .tmp sidecar.
Both in-tree file backends write <name>.tmp beside <name> and then rename, so if a key could encode to a name ending in .tmp its entry would sit exactly where another key's in-flight write lands. Escaping . closes it: no encoded name contains a dot.
The pair below is the smallest witness — x owns the sidecar x.tmp, and x.tmp is a key in its own right — and the third write is what gives the property teeth. Two writes only establish that the two keys can coexist; it is x being written again, after x.tmp has a value, that makes an in-flight temp file collide with a live entry. A version of this test without that third write is green against a backend whose sidecar name is a live key's filename.
The .tmp suffix is this suite's one backend-shaped assumption. A backend staging its writes some other way (a sibling directory, an O_TMPFILE) satisfies this property for free — correctly, since it has no sidecar namespace to collide with — and pays one entry for it.