e43c02c36f
A backup folder is picked, not created: the frames in it carry the names a camera or a person gave them, and Chromium's IsSafePathComponent will not spell a name back onto a disk if it holds a control or format character, one of ": * ? " < > | \ /", a space, dot or tilde at either end, or a .lnk/.scf/ .url tail. The library is read through a handle, which lets all of those through, so the refusal only surfaced on the way out: getDirectoryHandle threw "Name is not allowed" on the first such folder, the run stopped there and left an empty thumbs/ behind it. Spell a component that would be refused as %XX per its UTF-8 bytes, on the way out and on the way back in, so those frames keep their tiles in the backup and the restore still finds them. A name that was already safe is handed back untouched, which keeps an existing folder readable, copyable and rsyncable by hand. The run also no longer dies on the one frame that will not write: it skips it, names it in the console, and finishes the rest.