_loadConfig canonicalized legacy spellings in memory only (DC-092); the on-disk notifications.json kept email user/pass, camelCase event keys and string secure until the next explicit UI save — i.e. forever on installs that never open the settings page. - _persistCanonicalForm(): after the defaults merge, re-serialize and write back only when the bytes differ; idempotent on subsequent loads. - Best-effort: write failures (read-only mount, EACCES) warn and continue — the in-memory config is already correct; constructor never throws. - No secrets in new log lines; JSON.stringify(this.config) same as saveConfig. Judge notes (non-blocking, GLM-5.3 cold read): unknown top-level keys are now dropped from disk at boot (pre-existing merge-drop semantics, previously deferred to next UI save); write is non-atomic, matching saveConfig. Verdict: urn:ump:rchawiu427idev5mrettlxkyw2rcnwqpegiolqmzbc5ygc277u5q Tests: +5 (__tests__/notification-config-writeback-dc097.test.js) — canonical rewrite, idempotence, clean-file-untouched, EACCES no-throw, fresh-install no-write. Full suite 119 suites / 2740 tests green.