Skip to main content

Module recover

Module recover 

Source
Expand description

Recovery primitives and source-preserving salvage.

Use recover_to for the E4 recovery workflow. It keeps the source intact, follows verified published ancestry, streams named losses, and places raw rootless evidence in a separate archive with no current-membership claim.

The older recover function below is a low-level, in-place forensic rebuild retained for kernel regression coverage. Its global leaf sweep can include obsolete CoW versions and resurrect deletes. Generation/page-number dedup does not establish current membership; sibling pointers can also be stale. A broken overflow aborts that strict rebuild. It is NOT the safe E4 recovery API and must not be used to publish a repaired user database.

See docs/RECOVERY_CONTRACT.md in the E4 root for the supported fault model, distinctions between current survivors and candidates, and open law gates.

Structs§

CandidateReader
LeafCandidate
LeafScanReport
LostLeaf
A leaf that failed verification, and what can honestly be said about it.
RecoveryReport
SafeRecoveryReport

Enums§

LeafEvent
RecoveryClass

Functions§

recover
Low-level in-place forensic rebuild; prefer recover_to.
recover_to
Recover into a NEW directory, leaving all source files unchanged on every result. COMPLETE is written last; failed attempts retain evidence and must be retried with another destination. This API never publishes over source.