mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-21 11:56:38 +00:00
b1b4e443b2
Two producer paths double-booked the same damage across repair records (backlog#1894 axis A): - The scanner's corrupt-metadata branch fired a durable MRF journal intent, an immediate High heal request, and a pending-ledger entry for the same object. When the MRF intent is accepted into the channel it already covers the repair durably (the consumer files a High Metadata heal and the journal replays it across restarts), so the immediate request and ledger entry are dropped in that case; on delivery failure (feature disabled, channel uninitialized, or full) the old immediate request + ledger path runs unchanged, keeping the repair safety net. - The read path filed a journal intent before the read-repair reservation check, so a burst of reads failing on one object booked a journal record per retry. The intent now rides the submission: it is filed only when the sighting wins the dedup TTL, next to the Low request, via a new optional mrf_intent field on ReadRepairHealSubmission (None keeps the historical no-intent behavior for the other read-repair call sites). Manager dedup-key semantics are untouched; the fix is that competing producers stop double-booking. With RUSTFS_HEAL_MRF_ENABLE off both paths behave exactly as before. Co-authored-by: heihutu <heihutu@gmail.com>