Failure Modes
Recovery behavior differs by store and must be verified in the application.
Recovery is specific to the store
Persisted records and a usable in-memory index are distinct states. Restarting every Weave primitive does not automatically replay or restore its derived state. Preserve the source corpus and inspect errors before retrying or reconstructing a store.
| Component | Checked boundary | Application action |
|---|---|---|
| Strand | Append/read, storage and sparse transport paths have their own validation and failure behavior. | Check append results, writer ownership, durable records and a verified read using the selected backend. |
| Lens | Multi-operation atomic batching is not implemented by the current helper. | Do not infer all-or-nothing commits from a batch-shaped API. |
| Locus | File, blob and metadata operations can have separate failure points. | Inspect both metadata and payload outcomes before retrying or cleaning up. |
| Basis | Constructor creates an empty HNSW index; snapshots and public replay are absent. Present-id removal can deadlock. | Keep a recoverable corpus and validate a fresh application-controlled index before serving queries. |
| Forum | Constructor starts an empty tuple index; take can remove local state before a failed append. | Verify tuple/log consistency and define application reconciliation. |
| Gnosis | Constructor starts an empty derived index without automatic replay. | Build and verify the required projection explicitly. |
| Strand Vault | Construction does not automatically replay WAL; snapshots are best-effort directory copies. | Validate backups and recovery in an isolated copy of the configured store. |
| Discovery/network | A peer can be discovered without a completed authorized data read. | Retain the actual transport/data error and verify the requested result. |
| Compliance helpers | Several submission, audit-integrity and governance paths remain placeholders. | Require the real provider result before recording completion. |
Process crashes and storage errors
An operation returning an error does not establish atomic rollback or retry idempotence. Inspect its durable records and application state. Use the package-specific contract to decide whether an identifier can be retried, reconciled or replaced.
Avoid deleting a surviving log to repair an index. Reconstruct and validate derived state from retained source records or a separately recoverable corpus. The Basis recovery guide, Forum guide, Gnosis guide and vault guide describe current limits.
Network partitions and remote reads
Record which resource, writer key, peer and sequence were requested. Preserve timeouts and admission failures as failures. Provider discovery and a listener address are intermediate observations; verify the requested bytes and their protocol-specific checks before advancing application state.
Acceptance evidence
For the exact configured package/feature set, retain a successful first operation, an interrupted operation, a failed authorization, restart behavior and a verified result after recovery. Source documentation and local package availability do not by themselves establish those runtime outcomes.