How recovery works
completed prefix ↓durable boundary ↓committed continuation ↓failure ↓load continuation ↓resumeThe completed prefix is the work the Program already finished. At a durable boundary the host commits a continuation. If the process dies after that commit, a new process loads the continuation and resumes. It does not walk the prefix again to rediscover the position.
What is restored:
- Control position — the Program is at that boundary, not at the first line.
- Artifact identity — the stored artifact hash is authoritative. A different blob is a mismatch, not a new compile of the same source.
- Destination-live durable values — values the continuation still needs.
- Committed effect outcomes — reused. The effect function is not the recovery mechanism.
What recovery is not:
- a copy of process memory
- a heap snapshot
- a WASM memory snapshot
- prefix replay of retained history
- exactly-once I/O to systems outside the host
- a promise that recovery time is constant
History can still exist for audit. Recovery does not use it to rebuild the present.
For a direct comparison with history replay, see Replay vs continuation recovery. The technical report defines the formal claim and presents the supporting measurements.