Shrink Guard
Refuses a run that would delete more than maxDeleteFraction of the remote set once the remote holds at least minRemoteEntries non-marker files. A device that lost most of its data, or an app bug that projected an empty model, must not turn a healthy backup into a copy of the damage. The run answers UnavailableReason.ShrinkSuspected and writes nothing; the app asks the user and retries with SyncSnapshot(allowShrink = true).