Right now there is very little test coverage of situations where one or more of the edits directories fails. In trunk, the behavior when all of the edits directories are dead is that the NN prints a fatal level log message and calls Runtime.exit(-1).
I don't think this is really the behavior we want. Needs a bit of thought, but I think something like the following would make more sense:
- any calls currently waiting on logSync should end up throwing an exception
- NN should probably enter safe mode
- ops can restore edits directories and then ask the NN to restore storage, at which point it could edit safemode
- alternatively, ops could call ask the NN to do saveNamespace and then shut it down