Read identities up to three times before allowing replacement, publish only complete reads, and require new startup keys to be saved with bounded retries.
Use authoritative replay-file metadata throughout persistence and clock recovery. Validate setperm input before narrowing or mutating roles, and add production-path regression coverage.
Recover usable ESP32 preferences and channels before permitting replacement; keep identity and ACL persistence transactional and complete.
Preserve MQTT commit boundaries, restore OTA identity and policy after deferred allocation, retain radio gain retries, and reject invalid flood limits. Add production-path fault regressions and CI coverage.