Glossary
SQLite write-ahead log (WAL)
The -wal companion file where SQLite in WAL mode appends changed pages as frames before a checkpoint copies them into the database.
In WAL mode, SQLite does not overwrite the main database file directly. Changed pages are appended as frames to a -wal file next to it, and a checkpoint later copies them back. Each frame carries salts and a checksum, and a reader only trusts frames of committed transactions whose salts and checksums match the WAL header. The alternative, rollback-journal mode, saves original pages to a -journal file instead; the QuarantineEventsV2 database observed on macOS 26.6 used that mode.
Whichever companion exists must be copied with the database, or recent changes are lost. Superseded or uncommitted WAL frames and older page copies can also hold rows that were since deleted from the live file. See recovering deleted quarantine events.