Error recovery control explained

In computing, error recovery control (ERC) (Western Digital: time-limited error recovery (TLER), Samsung/Hitachi: command completion time limit (CCTL)) is a feature of hard disks which allow a system administrator to configure the amount of time a drive's firmware is allowed to spend recovering from a read or write error. Limiting the recovery time allows for improved error handling in hardware or software RAID environments. In some cases, there is a conflict as to whether error handling should be undertaken by the hard drive or by the RAID implementation, which leads to drives being marked as unusable and significant performance degradation, when this could otherwise have been avoided.

Overview

Modern hard drives feature an ability to recover from some read/write errors by internally remapping sectors and performing other forms of self-test and recovery. The process for this can sometimes take several seconds or (under heavy usage) minutes, during which time the drive is unresponsive. Hardware RAID controllers and software RAID implementations are designed to recognise a drive which does not respond within a few seconds, and mark it as unreliable, indicating that it should be withdrawn from use and the array rebuilt from parity data. This is a long process, degrades performance, and if more drives fail under the resulting additional workload, it may be catastrophic.

If the drive itself is inherently reliable but has some bad sectors, then TLER and similar features prevent a disk from being unnecessarily marked as 'failed' by limiting the time spent on correcting detected errors before advising the array controller of a failed operation. The array controller can then handle the data recovery for the limited amount involved, rather than marking the entire drive as faulty.

Typical defaults

Effectively, TLER and similar features limit the performance of on-drive error handling, to allow hardware RAID controllers and software RAID implementations to handle the error if problematic.

Generally, Western Digital enterprise drives such as Raptor, Caviar RE2 and RE2-GP (RAID Edition) come with TLER Read "Enabled" (7 seconds) and TLER Write "Enabled" (7 seconds) while desktop drives such as Caviar SE, SE16, and GP come with TLER Read and Write Disabled (configured as 0 seconds, to disable).

Standalone vs. RAID considerations

It is best for TLER to be "enabled" when in a RAID array to prevent the recovery time from a disk read or write error from exceeding the RAID implementation's timeout threshold. If a drive times out, the hard disk will need to be manually re-added to the array, requiring a re-build and re-synchronization of the hard disk. Enabling TLER seeks to prevent this by interrupting error correction before timeout, to report failures only for data segments. The result is increased reliability in a RAID array.

In a stand-alone configuration TLER should be disabled. As the drive is not redundant, reporting segments as failed will only increase manual intervention. Without a hardware RAID controller or a software RAID implementation to drop the disk, normal (no TLER) recovery ability is most stable.

In a software RAID configuration whether or not TLER is helpful is dependent on the operating system. For example, in FreeBSD the ATA/CAM stack controls the timeouts, and is set to progressively increase the timeouts as they occur. Thus, if a desktop disk without TLER starts delaying a response to a sector read, FreeBSD will retry the read with successively longer timeouts to prevent prematurely dropping the disk out of the array.

ModelTLER default (read / write)Stand-alone recommendationRAID recommendation
Caviar, SE, SE16, GP, RaptorDisabled (0s / 0s)DefaultEnabled (if possible)
Caviar RE2, RE2-GP, RedEnabled (7s / 7s)DisabledDefault

ZFS

The ZFS filesystem was written to immediately write data to a sector that reports as bad or takes an excessively long time to read (such as non-TLER drives); this will usually force an immediate sector remap on a weak sector in most drives.

RAID controllers

Disconnect timeout values for different hardware RAID controllers may vary between vendors; thus, TLER should trigger before the controller times out the drive. For example, 3ware 9650SE uses 20 seconds as the timeout,[1] while for the LSI Logic used in IBM x-series it is 10 seconds.[2]

Widely available Intel Matrix RAID / Intel Rapid Storage Technology, embedded in Intel server motherboards and modern desktop motherboards, is a pseudo-hardware controller, not a true hardware RAID controller.

Software RAID

Linux mdadm simply holds and lets the drive complete its recovery – however, the default command timeout for the SCSI Disk layer (/sys/block/sd?/device/timeout) is 30 seconds,[3] after which it will attempt to reset the drive, and if that fails, put the drive offline.[4]

Changing ERC

ATA-8 standard

The 2006 ATA-8 standard defines a SCT command.[5] For hard drives that implement this interface, the utility (part of the smartmontools package) can be used to change the error-recovery timeout via .[6] In 2018, ACS-4 added a functionality for the setting to persist across reboot; it is now supported by smartctl.[7]

Controlling the timeout behavior through the utility may not work on all hard disk drives because some manufacturers have changed their desktop drives not to include the support for the ERC parameter,[8] [9] purportedly to force sales of their more expensive RAID/enterprise models. Richard Gregory, who wrote the original ERC patch for smartctl, reports that Western Digital retracted ERC support by releasing a new model without notice.[6]

On Windows, the HDAT2 program is available in addition to smartctl (which is cross-platform).[6]

SCSI standard

SBC-4 describes a RECOVERY TIME LIMIT field in the Read-Write Error Recovery mode page used to define how the drive performs error recovery.[10] The sdparm program can change this setting with .

Vendor utilities

Western Digital

A utility allows the enabling or disabling of the TLER parameter on Western Digital hard drives. This utility is written for DOS. The utility works on and makes changes to all compatible Western Digital hard disk drives connected to the computer. The change survives power-cycling. Western Digital used to mention the tool in an FAQ.[11]

The utility comes with three batch files, to get the current state of the TLER setting on all the hard drives, to enable TLER, and to disable TLER. The included will set the Read & Write TLER time to seven seconds. It is possible to can use the utility directly with the -r# -w# parameters for a custom timeout.

Western Digital claims that using the utility on newer drives can damage the firmware and make the disk unusable. The utility is no longer available from Western Digital, and new drives will not be able to have the TLER setting changed. RE disks are only suitable for RAID arrays and Caviar are only suitable for non-RAID use. The utility still works for older drives.

Hitachi

Hitachi customer service stated in 2009 that there is a Feature Tool for changing ERC (referred to as CCTL).[11]

Seagate

Seagate provides a utility to allow you to interrogate and change many firmware settings including TLER. If you cannot use smartctl -l scterr,x,y to set the TLER, the relevant command-line commands are openSeaChest_Configure -d /dev/sg0 --sctReadTimer and openSeaChest_Configure -d /dev/sg0 --sctWriteTimer.

External links

Notes and References

  1. Web site: User Guide for 9650SE 9690SA from 9.5.2 Complete Codeset. https://web.archive.org/web/20120203053819/http://kb.lsi.com/KnowledgebaseArticle15639.aspx. 3 February 2012. lsi.com. 10 June 2015.
  2. Available in BIOS Raid Config Utility > Advanced Device Properties
  3. Web site: linux/sd.h at master · torvalds/linux · GitHub. GitHub.
  4. Web site: Linux SCSI Subsystem: SCSI EH. kernel.org.
  5. https://www.singlix.org/trdos/8086/archive/specs/D1699r3e-ATA8_ACS.pdf ATA/ATAPI Command Set (ATA8-ACS)
  6. Web site: Richard Gregory . Author's description of the original patch to smartctl that implemented that feature . 2013-02-15 . https://web.archive.org/web/20130910034510/http://cgi.csc.liv.ac.uk:80/~greg/projects/erc/ . 2013-09-10 . live .
  7. Web site: #1427 (Add support for SCT Error Recovery Timer features added in ACS-4) – smartmontools . www.smartmontools.org.
  8. Web site: Re: md RAID with enterprise-class SATA or SAS drives. spinics.net.
  9. Web site: Seagate FAQ: What is Error Recovery Control?. seagate.com.
  10. Web site: INCITS 506-202x - Information technology - SCSI Block Commands - 4 (SBC-4) draft revision 22 . 22 May 2023 . 15 September 2020.
  11. Web site: TLER / CCTL / ERC thread . [H]ardForum . 16 November 2010.