Skip to content
Trigora
Start building →

How recovery works

completed prefix
↓
durable boundary
↓
committed continuation
↓
failure
↓
load continuation
↓
resume

The completed prefix is the work the Program already finished. At a durable boundary the host commits a continuation. If the process dies after that commit, a new process loads the continuation and resumes. It does not walk the prefix again to rediscover the position.

What is restored:

  • Control position — the Program is at that boundary, not at the first line.
  • Artifact identity — the stored artifact hash is authoritative. A different blob is a mismatch, not a new compile of the same source.
  • Destination-live durable values — values the continuation still needs.
  • Committed effect outcomes — reused. The effect function is not the recovery mechanism.

What recovery is not:

  • a copy of process memory
  • a heap snapshot
  • a WASM memory snapshot
  • prefix replay of retained history
  • exactly-once I/O to systems outside the host
  • a promise that recovery time is constant

History can still exist for audit. Recovery does not use it to rebuild the present.

For a direct comparison with history replay, see Replay vs continuation recovery. The technical report defines the formal claim and presents the supporting measurements.