Save<T> writes to a .tmp sibling and atomically renames, so a crash
mid-write leaves the previous file intact. Load<T>, Save<T>, and
EnsureFileExisits share a per-absolute-path lock so concurrent
Save+Save and Save+Load can't observe a half-written file.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>