Earlier quoted context omitted.
> Who reboots a production system without monitoring it? Anyone. > Also if you boot with a degraded disk are you not asking for massive trouble > not being able to boot until you add another disk Great. I'm just a [sys]admin who were given a task to do something on $server. I jump around the red tape, claw out a 15 minute downtime because the task requires reboot, proceed with all that corporate dance with notificati…
It sounds like you're hypothesizing a long chain of bad decisions, and then ridiculing btrfs for taking the choice that means your next bad decision only culminates in (predictable, preventable) downtime rather than data loss.
This is all the things what I encountered in my admin days.
Including BL670 with incorrectly connected drives, so despite everything saying (and indicating) what the failed drive was in bay 2 it was actually in bay 1.
> then ridiculing btrfs
I ridicule btrfs for it's RAID mode not being a RAID mode by default.
RAID is about availability of data.
If you so hell bent on the data safety then btfrs should kernel panic as soon as one drive degrades. THAT would make sure someone would come and investigate what happened and no data loss.
Right?