git/list[1] front-page[2] threads[3] people[4] search[5] about
 

repo consistency under crashes and power failures?

From
GTGreg Troxel <gdt@ir.bbn.com>
Date
Jul 15, 2013, 17:48 UTC
Message-ID
<rmiy597iujc.fsf@fnord.ir.bbn.com>

Clearly there is the possibility of creating a corrupt repository when receiving objects and updating refs, if a crash or power failure causes data not to get written to disk but that data is pointed to. Journaling mitigates this, but I'd argue that programs should function safely with only the guarantees from POSIX.

I am curious if anyone has actual experiences to share, either
  a report of corruption after a crash (where corruption means that
  either 1) git fsck reports worse than dangling objects or 2) some ref
  did not either point to the old place or the new place)
  experiments intended to provoke corruption, like dropping power during
  pushes, or forced panics in the kernel due to timers, etc.

Alternatively, is there somewhere a first-principles analysis vs POSIX specs (such as fsyncing object files before updating refs to point to them, which I realize has performance negatives)?

(I have not done experiments, but have observed no corruption.)
    Thanks,
    Greg
Next: Jonathan Nieder
Message 1 of 4 in “repo consistency under crashes and power failures?”
  1. Greg TroxelJul 15, 2013
  2. Jonathan NiederJul 15, 2013
  3. Johannes SixtJul 16, 2013
  4. Jeff KingJul 27, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.