Ruvio.

Testing · evidence · limitations

Durability and recovery

Fault-injection results show behavior in the tested failure model. A process kill or a container filesystem fault is not physical power-loss certification.

Docker resilience · 2026-10-03

Environment: Docker Engine 29.8.0, Linux/aarch64 container, image ruvio:resilience-test (digest starts 56dcb352). Method: five bounded scenarios: tmpfs disk full, WAL directory permissions, SIGKILL, replica partition/catch-up and a 30-second mixed-command soak. Results:

ScenarioObserved result
tmpfs ENOSPC9,216 acknowledged writes recovered after clearing the fault and restarting; fault-time writes returned MISCONF
WAL permission denial3 acknowledged writes recovered after permission repair and restart; fault-time writes returned MISCONF
Process SIGKILL100/100 acknowledged writes recovered in this scenario
Replica interruptionAll 200 writes present after catch-up and manual promotion; catch-up 0.371 s
30-second soak48,413 iterations / 145,239 SET/GET/INCR commands

Reproduce: ./scripts/test.sh --docker-resilience. Limit: Docker Desktop Linux VM on the tested host, not bare-metal Linux or host-power-loss proof; promotion was manual and is not partition-safe automatic failover. The JSON report was in ignored target/ output and is not publicly archived.

Scenario details Environment guide

Native in-flight process kills · 2026-10-03

Environment: Apple M4 Pro, macOS. Method: three randomized process kills during pipelined writes for each of everysec and always. Result: six of six trials restarted with a continuous key prefix and all client-observed acknowledged writes present; recovered key counts were 297/576/810 (everysec) and 592/621/320 (always). Limit: process termination only; native filesystem faults and host power loss remain untested. Run ./scripts/test.sh --native-resilience for a new local report.

Native trial and caveats Earlier Linux kill-9 trials