=== every acquireRunning caller (non-test) ===
internal/backup/offbox_integrity.go:272:	if err := m.acquireRunning(); err != nil {
internal/backup/offbox_restore.go:549:	if err := m.acquireRunning(); err != nil {
internal/backup/offbox_reconstitute.go:491:	if err := m.acquireRunning(); err != nil {
internal/backup/backup.go:473:	if err := m.acquireRunning(); err != nil {
internal/backup/backup.go:935:func (m *Manager) AcquireRunningForTest() error { return m.acquireRunning() }
internal/backup/backup.go:939:func (m *Manager) acquireRunning() error {
internal/backup/shares_restore.go:203:	if err := m.acquireRunning(); err != nil {
internal/backup/offbox.go:864:	if err := m.acquireRunning(); err != nil {
internal/backup/tier2_restore.go:183:// do NOT add an acquireRunning() here. A second acquire would refuse the restore it is guarding.
internal/backup/tier2_restore.go:347:	if err := m.acquireRunning(); err != nil {

=== does RestoreOffboxScratch acquire it? ===
NO acquireRunning in RestoreOffboxScratch

=== restore_wizard.go:170-190 ===
// restoreOpInFlight reports whether a restore op is in flight, FOR DISPLAY.
//
// **Use this, not `Manager.IsRunning()`.** The Manager carries two different booleans and they are
// not interchangeable:
//
//   - `m.running` (read by `IsRunning`) is the CONCURRENCY single-flight. It is acquired *inside*
//     the restore function, on the background goroutine — and `RestoreOffboxScratch` never acquires
//     it at all. So for the verification restore and the full-restore preparation — the wizard's two
//     most-used actions, and the long ones, since they stream from restic — `IsRunning()` is false
//     for the entire operation.
//   - `m.opRunning` (read by `RestoreStatus`) is the DISPLAY flag, set synchronously by
//     `BeginRestoreOp` in the handler *before* the goroutine launches and cleared by `EndRestoreOp`.
//     It covers all four offsite actions with no start-up window.
//
// v0.154.0 shipped with `IsRunning()` here, which made the execution step unreachable for
// `RestoreOffboxScratch`: the page offered all three intents, with live buttons, while a restore was
// downloading — and the progress banner (which polls the op status) contradicted it on the same
// screen. Caught by the operator on the first live click-through.
func restoreOpInFlight(st backup.RestoreOpStatus) bool {
	return st.Running
}

// restoreOpBlocked reports whether a NEW restore must be refused right now, and returns the
// Hungarian refusal to show. It reads BOTH flags, deliberately:
//
