My FR5 block transfer picks, places and advances the tray pocket. Uninterrupted runs work. What recovery evidence should connect the saved index to reality when a stop lands between those actions?
Start with the intervals between each physical action and its persisted update. Ask what the real setup can still establish about the block and destination in each interval; don't let the recovery design know more than the stopped system would. An uncertain case needs a reviewed decision, not an automatic next-pocket guess.
Mapped the intervals. After release but before saving, the file cannot establish placement. I have made that an uncertain state in the recovery draft rather than another unsent pick.
Does another restart preserve that uncertainty, or could it fall back into the normal start path? That's a cheap software case to check before the physical recovery procedure is assessed.
Offline restart test preserves the held-for-review state. The required physical checks and authorised recovery steps are still being agreed. Normal production is not using this sequence.