Expand description
Recovery primitives and source-preserving salvage.
Use recover_to for the E4 recovery workflow. It keeps the source intact,
follows verified published ancestry, streams named losses, and places raw
rootless evidence in a separate archive with no current-membership claim.
The older recover function below is a low-level, in-place forensic
rebuild retained for kernel regression coverage. Its global leaf sweep can
include obsolete CoW versions and resurrect deletes. Generation/page-number
dedup does not establish current membership; sibling pointers can also be
stale. A broken overflow aborts that strict rebuild. It is NOT the safe E4
recovery API and must not be used to publish a repaired user database.
See docs/RECOVERY_CONTRACT.md in the E4 root for the supported fault model, distinctions between current survivors and candidates, and open law gates.
Structs§
- Candidate
Reader - Leaf
Candidate - Leaf
Scan Report - Lost
Leaf - A leaf that failed verification, and what can honestly be said about it.
- Recovery
Report - Safe
Recovery Report
Enums§
Functions§
- recover
- Low-level in-place forensic rebuild; prefer
recover_to. - recover_
to - Recover into a NEW directory, leaving all source files unchanged on every
result.
COMPLETEis written last; failed attempts retain evidence and must be retried with another destination. This API never publishes over source.