Taking work now — the first look is freeWhole sets posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
RARRAID Array Data Recovery 0800 6890668 Price my job
RAR / Controllers and hosts / ZFS and TrueNAS

TrueNAS CORE · SCALE · Proxmox · FreeBSD · OpenZFS 2.1 · 2.2 · zpool status · zpool import · zdb · block cloning

ZFS and TrueNAS pool recovery. The file system that checks everything, the pool that needs every vdev, and the import flags that write.

ZFS is a file system and a volume manager in one: a pool of vdevs, each a mirror or a RAID-Z group of devices, with every block checksummed and every write a new transaction group that the pool can be opened at. TrueNAS CORE and SCALE, Proxmox, Ubuntu and FreeBSD servers and QNAP's QuTS hero all run it, and they arrive here for the same few reasons: a vdev past its parity, a pool that would not import after a power cut, a single-disk or mirror vdev added for space and lost, and a pool rewound with zpool import -F on the originals. The states and messages are on the ZFS error page; this page is about the platform: which OpenZFS version the pool ran, which tools open it, what zdb can read from the labels when zpool cannot, and the November 2023 bug that OpenZFS 2.2.1 worked around and 2.2.2 fixed. A pool of two to four members is £500 + VAT upwards after the free look, fixed in writing; larger pools from £1,250 + VAT.

Free first lookOne fixed figure in writingNo data, no bill on most jobsReturn postage paid

Rather talk it through? An engineer answers the bench line
0800 6890668

Power down. Label every slot before a drive comes out. Do not rebuild, do not force a drive online, do not import or clear a foreign configuration, do not initialise, and do not run chkdsk, fsck, zpool import -F or mdadm --create on the members. A rebuild reads every sector of every survivor and writes to the replacement; each of the commands writes to the drives. On images, all of them are reversible. On the originals, none of them is.

Models and versions we see.

Which level is it →
Family Models or versions Metadata, defaults and notes
TrueNASCORE 12, 13; SCALE 22.x to 25.xOpenZFS 2.1 and 2.2; feature flags by version
ProxmoxVE 6, 7, 8OpenZFS 2.0 to 2.2; zvols for VMs
Ubuntu and FreeBSD20.04–24.04; 12–14OpenZFS 0.8 to 2.2
OpenZFS 2.2.0October 2023Block cloning; corruption bug; 2.2.1 workaround 22 Nov 2023; 2.2.2 fix 30 Nov 2023
QuTS heroh5.xZFS under QNAP's dashboard

What tends to go wrong on ZFS.

Read-only diagnosticszpool status -v, zpool import with no flags, and zdb -l on a device all read without writing. zpool import -F, -X and -T rewind by writing; zpool clear resets error counts; zpool replace starts a resilver. The forum offers the second group.
Every vdevA pool is a stripe across its top-level vdevs, so losing any one of them loses the pool. A single-disk vdev added to a RAID-Z2 pool for space is a one-drive way to lose everything, and it is the commonest layout mistake on the bench.
The 2.2.0 bugOpenZFS 2.2.1, released 22 November 2023, disabled block cloning by default after Gentoo users found a data-corruption bug in 2.2.0; The Register reported that the bug was in fact older and that block cloning exacerbated it; OpenZFS 2.2.2 and 2.1.14 on 30 November fixed an incorrect dirty-dnode check, and The Register reported it might go back as far as 2006. Pools that ran 2.2.0 with block cloning on are checked for silently wrong files.
Feature flags and versionsA pool upgraded on a new OpenZFS may not import on an older one, and the tools that open pools from images follow the flags. The version is the first thing the bench asks.

ZFS and TrueNAS symptoms, and how long each gives you.

Not listed? Describe it on the form →
Packing it and posting it: power down, photograph the controller's screen or export its log, and write the slot number on each drive with a marker before it comes out of its carrier. Send every member of the set, including the one that failed first; it holds the stripes the rebuild never reached. Each drive travels in an anti-static bag inside its own padding, in a box with nothing able to move. Send the controller if it was replaced or holds an encryption key; otherwise it stays. Insure the parcel for what the data is worth, use a tracked service, and know that the posting address is not printed anywhere on this site; it arrives by email in reply to the form, with a booking sheet to print; the sheet inside the parcel is what matches it to your enquiry when it is opened. Or hand the sealed parcel in at the nearest of ten drop-off points, your name on the outside and the sheet inside; say where you are on the form and it comes by email. We pay the postage home either way. The whole of it is written up on the guide to packing and posting.

What the message means on ZFS.

Describe yours to us →
What you see The usual reason Where that leaves you
Pool imports read-only but not read-writeNewest transaction groups tornCopy out read-only; choose the rewind on images
Single-disk vdev failedThe pool is lost as a wholeThat device imaged; the pool opened from all images
Files wrong with no checksum errorThe 2.2.0 bug, or olderChecked file by file; snapshots compared
DegradedA member out; still readableImage the weak member before any resync or resilver
Will not assemble or importToo few current members, or metadata damagedMetadata read from images; assembled in software
Read-only or suspendedErrors stopped I/ORead-only on images at the newest consistent state
Command already run--create, -F, chkdsk, fsckAssessed for what was written

From the parcel arriving to your files going back.

Work we have closed →
01

Logged the day it lands, and the first look costs nothing Free

A case number goes on the parcel and a number on every member the day it is opened, matched to the slot you wrote on it. Each member goes on the imager its interface needs, never on a controller, and its metadata is read before a sector is: the level, the order, the stripe size, the event counts that say which member is current and which dropped out first. An engineer settles what has happened to the set and how much of it can honestly be read back. Back to you come two things together: a straight note of what is liftable and what is not, plus one figure, fixed and written down. Accept it, or decline and owe us nothing.

Nothing to pay for lookingA single figure, put in writingNo rebuilds, no imports, no initialise
02

Every member imaged, including the one that failed first

Every drive in the set is imaged sector by sector, weak areas last, on hardware that controls every retry, with a map of what could not be read kept for each. Members with failed heads go to the clean bench first; that is the drive site's work and the same bench does it. The drive that dropped out first is imaged too, because it still holds every stripe written before it dropped, and a rebuild that stalled part-way never reached them.

Sector by sector, weak areas lastThe first-dropped member included
03

The geometry, from the metadata or from the parity

Where the controller's metadata survives on the members, the order, stripe size, parity rotation and data offset are read from it. Where it was cleared or overwritten, they are recovered from the data: parity across the members at the same offset should XOR to zero on a consistent stripe, which confirms the level and finds the stale member; where parity lands says the rotation; entropy at stripe edges and the file system's own anchors give the stripe size, the order and the start.

Metadata first, parity secondOrder, stripe, rotation, offset
04

Assembled in software, and repaired on the virtual volume

The set is put together from the images in software, with nothing written to any of them: the current members in, the stale member used only to fill holes a survivor could not give. The file system is checked and repaired on a copy of the virtual volume, VMFS and CSV volumes opened and the virtual machines' disks extracted, databases repaired where they need it. The originals are not touched again.

Nothing written to the imagesVirtual machines and databases opened
05

You see the file list before you pay

What was recovered is listed for you first, and only then does a bill exist. Approve the list and it is invoiced; turn it down and it is not — and where nothing has come back, most jobs carry no charge at all. Recovered data travels home on fresh media bought in for your job, with the postage at our end. Your case is not closed until you have opened the files on a machine of your own.

No charge until you accept the figureFresh media, supplied with the job5–10 days at the bench

From the bench

  • zpool import with no flags is the diagnostic, and zdb -l reads the labels when zpool cannot. Copy both before anything else.
  • Say the OpenZFS version and whether block cloning was ever enabled.
  • Send the cache and log devices too. A separate log device holds the last writes.
  • Copy out the read-only diagnostics first: --examine, zpool status, Get-VirtualDisk, dmesg. They are the case.
  • The forum's fix writes. --create, --assemble --force, zpool import -F, chkdsk and fsck all belong on images.
  • Say the version. mdadm, OpenZFS and Windows all changed their on-disk formats, and the tools follow.

One job, followed all the way through.

UK · RAR-2026-0631JOB LOGGED ✓

A TrueNAS SCALE pool of two RAID-Z1 vdevs and a single SSD vdev added for space, the SSD failed, and the pool FAULTED with insufficient replicas despite every spinning drive being healthy

The SSD and the eight spinning drives came in. The SSD's controller answered at chip level and was imaged; all four labels were read on every image, the newest uberblock every member agreed on chosen, and the pool opened read-only from the images at that transaction group. The datasets were copied out with every checksum verified, and the report noted the vdev layout.

100% of the pool recovered9 days here, and back by post
Illustrative example — replace with a genuine case

What helps, and what harms.

Do this much first

  • Copy out the read-only diagnostics
  • Power down and label the members
  • Send every member, and any cache, log or witness device
  • Tell us the version and every command that was run

What sets us back

  • mdadm --create or --assemble --force
  • zpool import -F, -X or -T
  • chkdsk or fsck on a degraded or mis-assembled volume
  • Resetting or recreating the pool

Questions answered before you commit.

Which ZFS commands are safe on a failed pool?

zpool status, zpool import with no flags, and zdb -l on a device. The rewind options -F, -X and -T, zpool clear and zpool replace all write.

I added a single disk to my pool and it failed. Is the whole pool gone?

Offline, not gone. Any top-level vdev lost loses the pool, but the device is usually imageable and the pool is opened from images of every member.

Should I worry about the OpenZFS 2.2.0 bug?

If the pool ran 2.2.0 with block cloning enabled, files may be silently wrong with no checksum error. The bench checks file by file against snapshots where they exist.

What does it cost?

£500 + VAT upwards for a pool of two to four members after the free look, fixed in writing; larger pools from £1,250 + VAT.

Nothing gets worse while it is powered down.

Looking at it is free. Back comes a list of what opened and what did not, together with a single price to finish, set down in writing while you are still free to say no. On most jobs an invoice only follows the data. Until that list reaches you, leave the server off and the drives in their slots.

0800 6890668