Two distinct failure contracts

Before ready

A load failure prevents readiness. The capability never becomes available, the path stops before the gate, and this scene shows no automatic restart continuation.

After active

An unexpected exit after active state makes the runtime unavailable. Amp-owned registry cleanup withdraws the capability, then Amp may launch the child three more times: restart 1, restart 2, and restart 3.

The initial launch is not a restart. The complete active-crash path therefore permits up to four launches. Backoff is shown as unlabeled quiet space; no exact schedule or guaranteed recovery is claimed.