Abstract
Presents and discusses the rationale behind a method for structuring complex computing systems by the use of what is termed `recovery blocks,' `conversations,' and `fault-tolerant interfaces.' The aim is to facilitate the provision of dependable error detection and recovery facilities which can cope with errors caused by residual design inadequacies, particularly in the system software, rather than merely the occasional malfunctioning of hardware components.