theLegacyOverlapACaseFoldingFilesystemExposesIsExactlyTheDocumentedOne
The legacy/new disjointness re-asked under the equality a case-insensitive filesystem actually uses — measured against a real filesystem rather than modelled.
:kuilt-store's StoreKeyFilenameTest already asks this question of the encoder, deciding it with String.equals(ignoreCase = true). That is a model of a case-folding filesystem, and it is the only place in the tree the residual is stated. This property is where the model meets the medium: same boundary, decided by the filesystem the run is actually sitting on. It is the one filename property that cannot be stated at the encoder level at all.
Three things are asserted, and only the last one is filesystem-dependent:
A moved key's orphan is unreachable, in every case variant.
otel.logswas stored asotel_logs; no key —otel_logs,OTEL_LOGS,Otel_Logs— may read it, on any filesystem. This is the dangerous shape: silent wrong-key data.StoreKey("Config")does NOT find its own legacy fileConfig. Uppercase is escaped, so that key now encodes to%43onfigand its old bytes are orphaned — the documented, accepted cost of shipping no migration. Stated as an assertion because it is the direct filesystem-level witness of uppercase escaping: puttingA–Zback into the safe set reds this on every filesystem, which is precisely what keysDifferingOnlyInCaseAddressDistinctEntries cannot do on a case-sensitive runner.The residual itself. A consumer that once stored
StoreKey("Config")has an orphan atConfig, and a new, never-writtenStoreKey("config")encodes toconfig— which on APFS is that file. That overlap is real, documented, and deliberately not closed (closing it would mean forcing an escape into every encoded name, forfeiting the safe-set carry-over aKeyAlreadyInsideTheSafeSetStillFindsItsOwnFile describes).
Why it measures rather than skips
The third assertion has a different expected value on a case-folding filesystem than on a case-sensitive one. Skipping on ext4 would have been the wrong answer: a skipped test and a silently-passing one are the same colour in a green run, and the case-sensitive arm has real content of its own — it asserts the residual is absent there, which reds if a change ever made an encoded name collide with a legacy one outright.
So the suite measures which filesystem it is on, using a probe pair of names not otherwise used by this property — a lowercase name planted first, then its uppercase(). On a folding filesystem the second plant lands on the first file and the store reads the second value; on a case-sensitive one it reads the first. Deriving the branch from an independent pair is what keeps the third assertion from restating its own instrument — a branch computed from config's own read would be true by construction whatever the filesystem did.
The probe doubles as this property's plant-landed precondition: a plantRawFile that wrote nowhere makes the probe read null, which is neither planted value and fails before any conclusion is drawn from it.