A full ring overwrites its oldest slot in place, so the header commit that
followed was the only thing making that write consistent. If it failed, the
in-file header described a ring the file no longer held, and at(0) returned
the replacement record as the oldest, before and after a reboot.
Records now carry a sequence number, which doubles as the occupied flag, and
head/count/lastSeq are derived by scanning the slots on open. The header is
written once at create and never again, so a push is a single record write
with nothing left to commit afterwards. That also halves the writes per
reading, which matters on the flash-backed variants.
Also assert the truncating write in the geometry test, which would otherwise
pass on an empty file for the wrong reason.