Snapshot and Recovery
Current persistence boundaries: durable vector records, an empty index after restart, and no public replay operation.
Persisted records are not a restored search index
Basis keeps vector events in vector_strand. Its HNSW graph and identifier maps live in memory. index_strand is reserved for snapshots, but update_index_strand() currently returns successfully without saving an index.
Basis::new creates empty HNSW and identifier maps even when a supplied vector strand contains records. BasisStore::open does not replay those records. Restarting or replicating a strand therefore does not make its vectors searchable automatically.
Rebuild helper and deletion limitation
The private rebuild_index helper reads vector events in sequence, applies additions and removals, and constructs an index from surviving vectors. It is not callable through the public API.
The current remove(id) appends a tombstone while holding vector_strand.write(). For an id present in the in-memory map, it then awaits rebuild_index, which requests vector_strand.read() on the same lock. This source path can deadlock. Do not use removal as a recovery trigger or describe deletion as operationally safe until that runtime path is repaired and tested.
Application recovery boundary
Keep an independently recoverable source corpus. An application can reconstruct surviving vectors externally and populate a fresh store through public add calls, accounting for the new append records this creates. This is an application workflow, not an existing built-in restore operation. Validate recovered identifiers, vectors and search results before accepting traffic.
| Event | Current behavior |
|---|---|
| Restart | A newly constructed index is empty. |
| Replicated vector records | Transported records alone do not populate HNSW. |
| Add failure or interrupted process | Inspect the durable records and rebuild through an application-controlled workflow; there is no documented atomic rollback. |
| Index-strand loss | No implemented HNSW snapshot is available there. Preserve vector records and your original corpus. |
| Present-id removal | Can deadlock while attempting private rebuild. |
See the public API/source reference and internals. These limitations describe the checked source, not a runtime recovery certification.