Qualification: Redundancy Does Not Imply Fault Tolerance: Analysis of Distributed Storage Reactions to Single Errors and Corruptions

Record: kaal:position:2026-08-26-032 · 2026-08-26

A clean prefix is not a clean history. Ganesan and coauthors tested eight distributed storage systems under single file system faults and found that corruption of a small part of a log could affect a far larger recorded history. Kafka could lose an entire log or all entries from the corrupted entry onward. The finding supplies an independent systems mechanism for the institutional distinction in Kaal's Chronicle claim. The source does not inspect Chronicle, Mosaic Companion, or commit 2d920ce. It cannot establish that Chronicle.read skips malformed JSONL lines or applies an undisclosed default limit. Its evidence is narrower and still consequential. Recovery behavior determines what the reader may treat as the record. A reader that drops an unparseable entry or returns only a bounded view without an explicit completeness state converts detectable record damage into an apparently ordinary result. The interface then fails to distinguish four different states: complete history, intentionally bounded view, corrupted history, and history recovered after loss. Those states cannot carry the same audit meaning. The paper also shows why storage redundancy alone does not cure the problem. Local recovery policy can amplify a single corruption into broader inaccessibility or silent loss. Chronicle therefore needs an explicit read contract. It should report parse failures with stable locators, disclose every applied limit, return a continuation or completeness marker, preserve access to raw rejected bytes, and state whether the result is complete, bounded, or damaged. An audit surface that continues after corruption may remain available. It does not remain reliable unless the evidence loss is itself part of the record.

Affirmed commentary position. This record extends a source-bound scholarly claim but is not a verbatim paper claim.
Holds when
Current debate

Redundancy Does Not Imply Fault Tolerance: Analysis of Distributed Storage Reactions to Single Errors and Corruptions

Scholarly basis

kaal:claim:7314479-032
Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes (2026). SSRN: https://ssrn.com/abstract=7314479
Source PDF sha256: debace24a155ae924a155b1fafe98856d98cf83689feff2f87a32f1c06171ce6

Evidence and mapping

Evidence: peer-reviewed USENIX FAST systems paper with complete official proceedings full text and fault-injection evaluation across eight distributed storage systems
Review tier: independent substantive scholarly-growth qualification
Mapping confidence: 0.98
Mapping ambiguous: false

Topics

institutional-designgovernance-designai-and-agentsaudit-logserror-propagationdata-corruptionrecoveryobservabilityopen-source-and-code

Provenance

Affirmed in kaal-review:2026-08-26:scholarly-growth-7314479-032-reviewed-v1 on 2026-08-26. Review record.

Verify

Canonical markdown sha256: d864c82589a26ba5c6fa278ae45feae2bae1973f3c19bbef37a154039a182069
curl -s https://wulfkaal.github.io/positions/2026-08-26-032.md | sha256sum