Limitations
Every framework has edges. These are ours, stated plainly and before you find them in a bug report. Trust is worth more than a feature list, so nothing here is softened.
Verified versus unverified#
- Verified: the Edit Mode suite runs in the repository's environment, the IL2CPP probe ran in a built player on Windows x64, and every performance number was measured there. See Platform support for the per-environment table.
- Not verified: consoles and platforms with restricted filesystems, real third-party cloud services, and AOT behaviour on a device other than the one tested. Nothing is claimed on their behalf.
Storage#
- Single process. Two processes writing one save root are not coordinated: atomic promotion keeps either version intact, but the later writer still wins. Use separate roots.
- Backup retention is by count, not by time. With retention 1 you can recover from one bad write, not two.
- **There is no journal of what changed.** The framework version-checks and migrates whole documents; it does not diff your model.
- Settings assets and save folders survive uninstallation on purpose. Deleting player data is not an installer's job.
Serialization and scale#
- Documents are JSON-shaped and trusted only after integrity verification. Unknown members are preserved, which costs some size on documents that change schema often.
- Very large single documents (tens of megabytes) are written whole. There is no streaming or incremental save path. Splitting by slot is the intended answer — see Large saves.
Versioning#
- Migration is whole-document and sequential. A chain of 32 migrations (the ceiling) is slow by definition; if you need more than a handful, the older formats should probably be abandoned.
- Rolling a save back to an older schema is not supported. Migrations go forward only.
- Two builds writing the same schema number with different shapes cannot be detected, because the file claims to be something it is not. That is a versioning bug in the game.
Security#
- Encryption is opt-in; keys are the game's responsibility, and the framework never stores, derives or generates one.
- There is no rollback (replay) protection. A player can replace a save with an older valid one; detecting that needs a server-side sequence.
- Metadata is readable by design, so slot listings work without a key. Its contents are not secret.
- Memory is not protected, and neither is a key embedded in the build.
- Client-side protection raises the cost of tampering; it is not authority. See Security best practices.
Cloud#
- The framework is transport-agnostic and therefore cannot repair a provider's semantics. If a service has no conditional-write support, the framework falls back to
IfAbsentand would rather fail a write than overwrite silently — some lossy providers will produce more conflicts than their marketing implies. - Conflicts are detected by generation and revision, which requires the records to be intact. A provider that rewrites metadata behind the framework's back can defeat detection.
- There is no bandwidth management, delta sync or chunking: a save is uploaded whole.
FakeCloudTransportis a test double, not a simulator of latency, quota or eventual consistency under load.- No provider adapter ships. Implementing one is bounded, documented work, not a configuration toggle.
Threading#
- The projection — reading your model — runs on the caller's thread even when
OffloadWritesToThreadPoolis on, because reading a game's model off its own thread is unsafe. A manual save therefore still costs the projection synchronously. - Autosave writes are serialised: a slow disk delays the next autosave rather than corrupting the current one.
Unity objects#
- A reference is a pointer, not a copy. Restoring an object does not restore the objects it points at.
- Nested objects need a parameterless constructor to be restored.
- Several components of one type on one object share one entry; the save records components by type.
- Prefab reconstruction requires all three of: a recorded prefab key, the
ReconstructThroughFactorypolicy, and an installed factory. None is guessed. - Content types (
Texture2D,Material,Mesh,AudioClip,Sprite,Shader,UnityEvent, delegates) are refused rather than serialised — see Unsupported types.
Editor tooling#
- The window is a view over engine-free rule classes: it reports and never edits save data.
- The smoke test uses the real pipeline but a synthetic model, so it proves wiring, not your model's contract.
- It will not change your Player Settings, scripting backend or scenes.
Not implemented, on purpose#
Accounts, sign-in, entitlements, leaderboards, telemetry, multiplayer state, encryption key generation or rotation policy, save-file editing tools, and any notion of what a "player" or an "item" is.
Next#
- Platform support — what was run, where, and how to reproduce it.
- FAQ — the questions this page usually answers.
- Support — how to report something that is genuinely wrong.