Glossary
SQLite freeblock
A chunk of unused space inside a SQLite b-tree page, chained in a list. Deleted records often survive in freeblocks until overwritten.
Inside a SQLite b-tree page, the space released by a deleted cell becomes a freeblock. Freeblocks form a linked list within the page: the first 2 bytes of each give the offset of the next one and the following 2 bytes its size. Those 4 bytes overwrite the start of the old cell, but the rest of the record, including the serial types in its header, often survives.
That is why deleted QuarantineEventsV2 rows can be carved: anchor on the serial types of an LSQuarantineEvent record and read the values that follow. Nothing guarantees survival. SQLite's secure_delete setting overwrites freed content, and later writes reuse the space, so absence of recovered rows proves nothing. See recovering deleted quarantine events.