A clone group is only visible while both copies are on disk, and the
run then deletes the clone, so writing only what this run saw erased
every mapping an earlier run had recorded. One real run took the map
from 69 entries to 1, and the canonical zips silently stopped answering
to the names they stand in for.
The map is merged now, the 68 lost entries are restored, and the one
whose canonical file is no longer in the collection is dropped.
dedup.py is the only script here that deletes BIOS files and it had no
tests: the sole guard was remembering --dry-run. These cover the
protected directories where two identical copies are both load-bearing,
the canonical choice between a primary and a variant, MAME zip clones
against same-content files that must keep every name, and that a dry
run reports exactly the plan the real run executes.
Disabling the NODEDUP guard fails four of them.