RocksDB lazy format upgrade one-way MANIFEST rewrite and recovery options
26.5K reputation · 12 Jan 2023, 19:20 UTC
RocksDB performs format upgrades lazily on open when a newer library version implies a newer on-disk layout. The upgrade rewrites MANIFEST and SST metadata rather than requiring an explicit upgrade command, and the change is effectively one-way. Once the MANIFEST is rewritten for a newer format, older RocksDB binaries typically cannot open the database, so downgrade is not supported by design.
There is no built-in automatic rollback mechanism for a failed or interrupted upgrade. Safe recovery therefore depends on operator-provided safeguards such as pre-upgrade backups, checkpoints, or retaining the previous binary version. The operational decision of whether and how to preserve a pre-upgrade MANIFEST snapshot automatically remains unresolved, and the exact state left after interruption is version-sensitive and may interact with WAL recovery and compaction state.
Is a pre-upgrade MANIFEST snapshot preserved automatically by RocksDB during a lazy format upgrade? If the upgrade is interrupted during MANIFEST rewrite, what state is the database left in for the same version that initiated the upgrade? What operator safeguards are considered sufficient for safe recovery given the lack of built-in rollback?