Skip to content

fix(storage): propagate backend storage errors in direct store methods - #625

Open
rikysya wants to merge 10 commits into
lambdaclass:mainfrom
rikysya:yv/crates/storage-fix-propagate-direct-storage-errors
Open

rikysya wants to merge 10 commits into
lambdaclass:mainfrom
rikysya:yv/crates/storage-fix-propagate-direct-storage-errors

Conversation

@rikysya

@rikysya rikysya commented Sep 29, 2026 •

Copy link
Copy Markdown

Propagate backend failures from audited Result-returning Store methods, including reads, writes, commits, and LiveChain iteration, instead of panicking or returning an incomplete view.

🗒️ Description / Motivation

Several Store methods already returned Result but panicked when the storage backend failed. LiveChain scans could also hide iterator failures. This change makes those failures visible to callers, including during store initialization.

What Changed

  • Updated direct storage methods, metadata helpers, checkpoint and pruning paths, signed-block paths, state paths, and constructors to propagate backend errors.
  • Added MissingMetadata for required metadata keys that are absent.
  • Added GetForkchoiceStoreError::Store for initialization failures and CheckpointSyncError::StoreInit so checkpoint startup reports them separately from anchor-pair mismatches.
  • Moved state-cache insertion until after the state write commits successfully.

Correctness / Behavior Guarantees

  • Successful operations retain their existing behavior. Missing blocks, pruned proofs, and unknown states remain distinct from backend failures.
  • A failed LiveChain scan returns an error rather than a partial result.
  • A missing stored head header during proof pruning returns UnexpectedMissingBlockHeader.
  • Failed state writes do not leave an unpersisted state in the cache.
  • Malformed stored data still panics during decoding. Infallible accessors and callers that use expect may still panic on returned errors.
  • Checkpoint updates still commit before live-chain pruning; a pruning failure now returns an error after that commit instead of panicking.

Tests Added / Run

  • No tests added.
  • make fmt, make lint, and make test — passed.

Related Issues / PRs

✅ Verification Checklist

  • Ran make fmt — clean
  • Ran make lint — clean
  • Ran make test — passed

Return backend read and write failures from the nine Result-returning
Store methods instead of panicking. Propagate LiveChain iterator errors
rather than returning an incomplete view of the chain.
…etadata error

Propagate backend failures through the shared metadata helpers and return
MissingMetadata when a required key is absent.
Propagate backend write and live-chain pruning failures from
update_checkpoints instead of panicking. The checkpoint is still committed
before live-chain pruning, so a pruning failure now returns an error after
that commit.

Propagate read and proof-pruning failures from prune_old_data instead of
panicking or using the finalized slot as a fallback. Return
UnexpectedMissingBlockHeader when the stored head has no header.
Return backend failures from pending and signed block writes, single-block
reads, and range reads instead of panicking. Preserve existing behavior
for missing blocks and pruned proofs.
Return backend read and write failures from state retrieval and insertion.
Cache inserted states only after the write commits successfully.
Return backend failures from store restoration and anchor initialization
instead of panicking. Add a Store variant to GetForkchoiceStoreError and a
StoreInit variant to CheckpointSyncError so checkpoint startup reports

storage failures separately from anchor-pair mismatches.
@MegaRedHand MegaRedHand added the lean Lean consensus client label Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lean Lean consensus client

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants