Make save writes atomic with one backup; sandbox observed runs master
A mis-scoped `HOME=x printf ... | ./binary` observed run truncated the real playthrough save in place on 2026-07-11. Close both surfaces: - `save_game` now writes to a sibling `.tmp`, fsyncs it, rotates the current save to the single `misaligned_save.txt.bak` generation by copy, then atomically renames the temp file over the target. A failed or killed write leaves the prior save readable at the save path or its backup; the load path never reads the `.bak` (manual recovery only). - `tools/observed-run.sh` runs any game-binary command under a freshly created sandbox HOME exported for the child process itself, prints the sandbox path, and fails loudly if the real save directory changed (fixtures: `tools/test_observed_run.sh`, wired into check.sh syntax and docs gates). Workflows now mandate the wrapper for observed runs. Defense: implements the player-contract continuity clause (wiki/vision/player-contract.md, clause 3), amended in this commit to bind the write mechanics: saves survive the act of saving — the game never truncates the existing save in place, every write is temp-file + fsync + atomic rename, and the prior save rotates by copy to exactly one backup generation that loading never auto-reads. The sim-mechanics save section and the workflows observed-run guidance are updated in the same landing.