Limitations

Every framework has edges. These are ours, stated plainly and before you find them in a bug report. Trust is worth more than a feature list, so nothing here is softened.

Verified versus unverified#

  • Verified: the Edit Mode suite runs in the repository's environment, the IL2CPP probe ran in a built player on Windows x64, and every performance number was measured there. See Platform support for the per-environment table.
  • Not verified: consoles and platforms with restricted filesystems, real third-party cloud services, and AOT behaviour on a device other than the one tested. Nothing is claimed on their behalf.

Storage#

  • Single process. Two processes writing one save root are not coordinated: atomic promotion keeps either version intact, but the later writer still wins. Use separate roots.
  • Backup retention is by count, not by time. With retention 1 you can recover from one bad write, not two.
  • **There is no journal of what changed.** The framework version-checks and migrates whole documents; it does not diff your model.
  • Settings assets and save folders survive uninstallation on purpose. Deleting player data is not an installer's job.

Serialization and scale#

  • Documents are JSON-shaped and trusted only after integrity verification. Unknown members are preserved, which costs some size on documents that change schema often.
  • Very large single documents (tens of megabytes) are written whole. There is no streaming or incremental save path. Splitting by slot is the intended answer — see Large saves.

Versioning#

  • Migration is whole-document and sequential. A chain of 32 migrations (the ceiling) is slow by definition; if you need more than a handful, the older formats should probably be abandoned.
  • Rolling a save back to an older schema is not supported. Migrations go forward only.
  • Two builds writing the same schema number with different shapes cannot be detected, because the file claims to be something it is not. That is a versioning bug in the game.

Security#

  • Encryption is opt-in; keys are the game's responsibility, and the framework never stores, derives or generates one.
  • There is no rollback (replay) protection. A player can replace a save with an older valid one; detecting that needs a server-side sequence.
  • Metadata is readable by design, so slot listings work without a key. Its contents are not secret.
  • Memory is not protected, and neither is a key embedded in the build.
  • Client-side protection raises the cost of tampering; it is not authority. See Security best practices.

Cloud#

  • The framework is transport-agnostic and therefore cannot repair a provider's semantics. If a service has no conditional-write support, the framework falls back to IfAbsent and would rather fail a write than overwrite silently — some lossy providers will produce more conflicts than their marketing implies.
  • Conflicts are detected by generation and revision, which requires the records to be intact. A provider that rewrites metadata behind the framework's back can defeat detection.
  • There is no bandwidth management, delta sync or chunking: a save is uploaded whole.
  • FakeCloudTransport is a test double, not a simulator of latency, quota or eventual consistency under load.
  • No provider adapter ships. Implementing one is bounded, documented work, not a configuration toggle.

Threading#

  • The projection — reading your model — runs on the caller's thread even when OffloadWritesToThreadPool is on, because reading a game's model off its own thread is unsafe. A manual save therefore still costs the projection synchronously.
  • Autosave writes are serialised: a slow disk delays the next autosave rather than corrupting the current one.

Unity objects#

  • A reference is a pointer, not a copy. Restoring an object does not restore the objects it points at.
  • Nested objects need a parameterless constructor to be restored.
  • Several components of one type on one object share one entry; the save records components by type.
  • Prefab reconstruction requires all three of: a recorded prefab key, the ReconstructThroughFactory policy, and an installed factory. None is guessed.
  • Content types (Texture2D, Material, Mesh, AudioClip, Sprite, Shader, UnityEvent, delegates) are refused rather than serialised — see Unsupported types.

Editor tooling#

  • The window is a view over engine-free rule classes: it reports and never edits save data.
  • The smoke test uses the real pipeline but a synthetic model, so it proves wiring, not your model's contract.
  • It will not change your Player Settings, scripting backend or scenes.

Not implemented, on purpose#

Accounts, sign-in, entitlements, leaderboards, telemetry, multiplayer state, encryption key generation or rotation policy, save-file editing tools, and any notion of what a "player" or an "item" is.

Next#

  • Platform support — what was run, where, and how to reproduce it.
  • FAQ — the questions this page usually answers.
  • Support — how to report something that is genuinely wrong.