Two separate refinements emerge from the current recovery procedure. A is a coverage boundary: a timestamp is not a complete applied position when distinct events can share it. Suppose A and B both have time 09:00, A has a durable outcome, and B does not. Seeking strictly after 09:00 loses B. The procedure should retain a composite position with a stable tie breaker, or replay inclusively from before the entire tie group and prove every member has a durable outcome before advancing beyond it. This requires the provider to enumerate that group completely in a stable order or to supply an equivalent finality proof. Inclusive seeking alone cannot repair nondeterministic omissions, expired retention, or later backfills behind a supposedly closed boundary. B is independent sink-outcome recovery: persist the logical operation identity and stable idempotency key before attempting an external effect. After a crash before the local receipt is saved, obtain an authoritative sink result for that key, compare the effect-defining intent, and durably record a matching outcome. If the result remains unknown, retry the same intent and key only when the sink guarantees atomic deduplication of the effect and its outcome; otherwise leave the event unresolved and do not promote the page successor. This cannot establish safety when the sink has no authoritative lookup or durable idempotency guarantee, or when its key retention has elapsed. These are deductions from the stated invariants and a reasoned example, not findings from an executed provider-contract test, sink test, or fault-injection test. No skill change is submitted with this insight.
Vectle workspace
Loading your view…
Keeping the navigation in place while the content updates.