Data Recovery Case File · NAS & RAID · The Stale Copy That Saved Him

Pruned by its own repair, rescued by its own mirror: a photographer's RAID 1, and the out-of-date drive that turned witness

This case turns on one of RAID's most elegant accidents. The amateur photographer's storage — a 2013-vintage LaCie 2big, two drives mirrored as RAID 1, 2TB of working capacity for a decade of photographs — had begun turning itself off and on again, repeatedly. His Windows laptop, meeting the misbehaving volume, "indicated it could repair the fault. (Mistakenly) I clicked yes." His own parenthesis, and accurate: the repair did calm the restarting, and the unit now mounts — showing some folders, about 221GB of them — but several other folders, mainly the photographs, are gone. The repair had traded his archive for stability. What he couldn't have known: on a mirror whose members were failing unevenly, the trade might not have been final — because one of the two drives was likely absent for the surgery.

SystemLaCie 2big Quadra (2013), 2 × 2TB in RAID 1 — an amateur photographer's decade of images and documents
Reported chainUnit power-cycling itself repeatedly → Windows repair offer accepted → restarts largely cease; volume mounts showing ~221GB of folders → the photograph folders no longer listed
Fault classOne member drive failing (the restarts' author); repair-pruned directory structures on the live volume — with the failing member's stale copy as the potential pre-repair witness
Equipment usedAtola TaskForce 2 (write-blocked imaging, both members separately) · ACE Lab Data Extractor (cross-member reconstruction)

Three decodes: the restarts, the repair, and the mirror's accidental time machine

The restarts were one drive's illness wearing the whole unit's clothes: a two-bay enclosure whose power and protection circuits reset when a member misbehaves — a failing drive stalling, faulting, drawing wrongly — cycles the box around it, and "turning itself off and on" is almost always one patient dragging down a shared chassis. The repair did what filesystem repairs do, decoded across this archive: walking a volume it found damaged (damaged largely because a failing drive was serving it unreliably), it pruned — discarding directory branches it couldn't reconcile — and the calm that followed was partly that pruning and partly the failing member deteriorating past participation. The vanished photo folders were the repair's discard pile: unlisted, their contents substantially still on disk, in the pattern every deletion case here documents. And the mirror's accident: RAID 1 writes everything twice — but only to members that are present and cooperating. A member that was faulting, resetting, or dropped from the array during the repair session didn't receive the repair's changes: it holds the volume as it stood before the surgery — stale by the array's standards, and precisely that staleness makes it a witness: the pre-repair directory structures, photo folders listed and whole, preserved by the drive too ill to attend its own archive's pruning.

The reconstruction — witness examined, archive restored

Both members came out of the enclosure labelled and were imaged separately, write-blocked, on the TaskForce 2 — the failing member handled at degraded-drive tempo, its cooperation coaxed rather than assumed — and the comparison confirmed the accident: one image carried the post-repair volume (the 221GB he could see, photo folders absent); the other, older by exactly the crisis, carried the pre-repair structures with the photograph folders intact in the listing. Reconstruction then took the best of both witnesses: the stale member's directory truth married to the freshest available copy of each file's contents across the pair, the pruned folders re-listed and re-populated, and the archive rising whole — the decade of photographs verified by opening images across its span, alongside everything the visible 221GB had already held. Delivered on new, plain storage; both veterans retired; and the report closing with the sentence the case earned: the repair deleted the folders from one drive, and the other drive was too broken to obey.

Outcome

The photographic decade recovered by cross-examination of its own mirror — and two rules published where his parenthesis pointed. Never accept a repair offer on a multi-drive volume that's misbehaving: repairs prune, arrays amplify, and a struggling RAID needs its members imaged separately before anything writes — the offer that "fixed" his restarts was surgery performed mid-earthquake. And the stale-copy principle, for every mirror owner: a RAID 1's out-of-sync member is evidence, not junk — never let anyone "rebuild" or resynchronise a troubled mirror before both sides are imaged, because resync is the step that overwrites the witness with the crime scene. His failing drive saved his archive by missing the meeting. The trade calls that luck; the procedure above is how you stop needing it.

Mirrored storage misbehaving

Power the unit down at the first self-restarting or dropout — one failing member is cycling the chassis, and every restart stresses both drives. Decline all repair offers from any connected computer; on arrays, repairs prune and both copies can inherit the pruning. Above all, don't rebuild or resync: an out-of-date member is your pre-crisis witness, destroyed the moment synchronisation "fixes" it. Bays labelled, both drives together, imaged separately — the mirror's whole value at recovery time is that its copies are allowed to disagree.

Repair "fixed" the array and lost the folders?
The other drive may remember — call Belfast Data Recovery on 028 9002 0144 before anything resyncs.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.

Call us — 028 9002 0144
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
028 9002 0144