Recovery semantics
Failure is an operating condition. The runtime can represent peer loss, communication loss, capability failure, stale state, expired leases and unsafe outcomes as explicit recovery signals.
Recovery follows a bounded loop:
- Detect and authenticate the failure signal.
- Stop or fence work whose authority is no longer valid.
- Preserve the causal predecessor and evidence.
- Re-evaluate eligible peers, roles and policy.
- Reassign or replan within the configured recovery budget.
- Resume only after readiness and authority checks pass.
Missing, conflicting or stale evidence remains unresolved. The safe default is pause or fail closed, not silent continuation.