Skip to content

Preflight ReFS MLog recovery before applying redo - #419

Merged
Hawkynt merged 3 commits into
mainfrom
fix/refs-mlog-replay-preflight
Sep 30, 2026
Merged

Hawkynt merged 3 commits into
mainfrom
fix/refs-mlog-replay-preflight

Conversation

@Hawkynt

@Hawkynt Hawkynt commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

What changed

  • Use checkpoint-bounded, checksum-checked MLog analysis for both replay entry points.
  • Validate the live predecessor chain, including the first selected record. Reject checksum-failed live records instead of silently dropping a corrupt final block; ignore stale blocks before the checkpoint boundary.
  • Preflight every selected redo opcode and target payload before applying any record.
  • Add synthetic regressions for broken links, corrupt recovery windows, unsupported later opcodes and rejected later payloads.

Validation

  • git diff --check passed locally.
  • Windows and Ubuntu CI build/test jobs are running; the local environment has no .NET SDK.

This is recovery safety infrastructure, not a concrete version-qualified redo target or mounted write support. Unknown payload grammar remains refused.

@Hawkynt
Hawkynt force-pushed the fix/refs-mlog-replay-preflight branch 3 times, most recently from 6557b0b to 615adc3 Compare September 30, 2026 16:12
The parallel replayer ignored the checkpoint recovery boundary and applied parsed records before learning whether a later opcode or payload was unsupported. Route both entry points through checksum-verified recovery analysis, preflight the complete selected window, and reject links to missing live records. Synthetic redo-target tests cover late failures and ordered replay; no on-disk payload grammar is inferred.
Recovery analysis filtered invalid XOR-fold records, so a corrupt final live record could disappear and leave a replayable prefix. Select the checkpoint recovery window first, calibrate within it, and reject any checksum-failed live record before applying redo. Regression tests cover a failed final record and a stale failed record outside the window. This follows the existing LogCore checksum codec and checkpoint boundary; no new redo payload grammar is assumed.
The chain check began at record two, so a first selected record could point to a missing predecessor inside the checkpoint recovery window. Validate its link against the oldest required LSN before replay and cover the missing-first-record case with a regression. This uses the already-decoded LSN linkage; no opcode-specific payloads are inferred.
@Hawkynt
Hawkynt force-pushed the fix/refs-mlog-replay-preflight branch from 260f83d to c77c1eb Compare September 30, 2026 18:09
@Hawkynt
Hawkynt merged commit dea71ad into main Sep 30, 2026
5 of 7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant