SFToss32 - Safety and Backup Procedure
======================================

BEFORE INSTALLING OR UPGRADING
------------------------------

1. Save the current working SFTOSS32.EXE and SFTOSS32.CFG.
2. Back up every node's SFMCONF.DAT.
3. Back up the shared Spitfire MESSAGE directory.
4. Disable scheduled -toss and -scan jobs.
5. Pause mailer pickup during the first supervised outbound test.

FIRST-RUN CHECKLIST
-------------------

1. Confirm SFTOSS32.CFG contains the correct paths and FTN routing.
2. Run SFTOSS32.EXE -check.
3. Correct every ERROR before using -toss or -scan.
4. Confirm no caller is active.
5. Run one supervised -toss and review TOSSER.LOG.
6. Run one supervised -scan with mailer pickup paused.
7. Inspect the new packet or bundle before release.
8. Run -check again before restoring automation.

LOCKING AND CALLERS
-------------------

SFToss32 uses SFTOSS.BSY to prevent two instances from operating together. It
also reads SFWHOSON.DAT before accessing Spitfire message bases. When a caller
is active, SFToss32 waits and rechecks, then either continues after the caller
logs off or aborts safely.

Do not manually remove SFTOSS.BSY until you have confirmed that no SFTOSS32
process is still running.

RECOVERY
--------

* A failed or blocked run should leave unsent Spitfire messages available for a
  later scan.
* Outbound publication is committed per link only after the bundle is complete.
* Foreign-address inbound packets are left untouched.
* Processed inbound bundles are moved only after successful processing when
  KEEPPROCESSED is enabled.
* UNKNOWN-area messages are deleted from UNKNOWN only after a successful later
  Spitfire message-base commit.

Keep TOSSER.LOG and the original packet or bundle when reporting a problem.
Never publish a real packet password.
