The save picker used to return only TryGetLocalPath(), so a target without a local path looked like a cancel and nothing was written. The dialog service now hands back an opener for the chosen file. The picker call is inside the error handler, and the workspace is read before the target is opened, so a failed read leaves an existing file untouched.