Generations and recovery
(checkpoint) requires a clean Git worktree and a passing ./script/check. On POSIX it saves a retained image without stopping the active session. On Windows it saves the exact live heap, restarts through the stable launcher, and resumes the active conversation after the saved image passes its probe.
(generations)lists retained images.(rollback ID)selects a compatible image and exits through recovery.
Inspect or boot retained generations from the CLI:
autolith --recovery --list
autolith --recovery --generation GENERATION-IDRecovery starts the separately built pristine core, not the damaged active core. If that image is missing or invalid, it falls back to source.
Automatic recovery boots a private clean checkout of current committed source with --pristine. It does not load retained generations or private mutation replay. An intentional (rollback ID) still boots the selected generation. Explicit generation selection may use an older revision.
To start a rescue session directly, use:
autolith resume --pristine --permissions full--pristine forces tracked source instead of a saved active core and skips the selected private image commit, mutation journal reconstruction, and executable user initialization for this process. It implies --immutable so ordinary self-mutation tools cannot replace the selected private commit. It does not erase any mutation or conversation data. Ordinary startup remains unchanged.
A fatal active failure publishes a private crash capsule and restores the terminal. Recovery restores the conversation without duplicating scrollback. With a valid capsule, it queues one read-only diagnosis turn before ordinary input.
That turn can inspect:
- bounded crash context
- workspace and tracked source
- indexed source
- active state
It has no shell, MCP, hosted provider, image, write, mutation, checkpoint, or rollback tools. It asks before any repair. A manually started recovery image does not queue diagnosis.
Saved cores require their recorded SBCL version, OS build, and architecture. Source remains authoritative. To reconstruct without a core, check out the manifest revision, run ./script/bootstrap, load autolith, then load the manifest's ordered reconstruct.lisp in package AUTOLITH:
(asdf:load-asd (truename "autolith.asd"))
(asdf:load-system :autolith)
(load #P"/path/from/generation/manifest/reconstruct.lisp")