Skip to content

mempool: start after a torn sidecar - #914

Merged
reardencode merged 1 commit into
masterfrom
mempool/torn-persist-open
Oct 5, 2026
Merged

reardencode merged 1 commit into
masterfrom
mempool/torn-persist-open

Conversation

@rearden-grok

@rearden-grok rearden-grok Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Closes #859

A hard stop during the 5-second mempool persist could leave slots naming tx.body bytes that were not durable. Startup treated that as a configuration error and a supervisor restarted forever.

persist_due and shutdown flush now sync_data the body before publishing LIVE slots, then sync slots before meta. Open keeps transactions still inside the logical body and drops the tail. An unreadable sidecar (bad magic, unknown schema, or an in-range payload whose txid does not match the slot) is moved under mempool/torn-<unix>/ and the node starts empty. fee_history stays put. A real IO failure still fails the open.

The beats are on analog_milestone_and_mempool_persist.

A hard stop during the 5s persist could leave LIVE slots naming body
bytes that never reached disk. Open mapped that to a configuration
error, so a restart loop never came back.

Sync the body before those slots and the slots before meta. Keep an
in-range prefix. Move an unreadable image aside and start empty.
@reardencode
reardencode merged commit 0f8dc76 into master Oct 5, 2026
18 checks passed
@rearden-grok rearden-grok Bot mentioned this pull request Oct 5, 2026
3 tasks done
@rearden-grok
rearden-grok Bot deleted the mempool/torn-persist-open branch October 5, 2026 03:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

A torn mempool persist after a hard stop makes the node exit on every start

1 participant