Recover edge-journal scanning after a torn final record
Startup stops at partial data and loses earlier committed events. Scan the valid committed prefix conservatively.
- Focused work estimate
- 3h + prerequisites
- Priority in the scenario
- High
- Engineering practice
- Recovery · Integrity
Estimated field mix
- Storage systems60%
- Embedded and edge40%
Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.
Review it, then add it to your workspace.
The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.
Project context
Fictional edge display gateway stores noncritical synthetic readings while disconnected. Implement a byte-array flash emulator with explicit erase/write behavior and injected power cuts; no physical storage device is required.
Setup prerequisites
- Specify emulator page size write rules and erase behavior.
- Generate synthetic records and deterministic power-cut schedules.
Preceding work
Complete these dependencies, or supply their agreed outputs before taking this ticket.
- CJOUR-101 · Model edge-journal flash writes with explicit emulator constraints
- CJOUR-102 · Encode edge-journal records with bounded length and checksum
- CJOUR-103 · Assign edge-journal event identities independently from delivery attempts
- CJOUR-104 · Commit edge-journal records only after their marker is durable
Acceptance criteria
- Earlier committed records survive
- Incomplete tail is ignored with reason
- Middle corruption is not silently skipped
Implementation constraints
- Preserve damaged bytes for explicit local diagnosis.
Verification to include
- Cut final body write
- Corrupt an earlier committed record
Deliverables
- Recovery scanner and fault cases
Rollout and recovery
Open journal read-only when corruption is not a tail interruption.
Value of the work
For the engineer: Practice torn writes, wear-aware batching and acknowledged durability.
For the team: Inspect whether offline device records remain recoverable within stated constraints.
Evidence boundaries
Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.
Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.