Problem: When flushing block or undo data fails, FlushStateToDisk() still writes block-index metadata and coins data, then advances m_last_flushed_block.
With a separate -blocksdir, persistent failures there can leave metadata referring to block data that is not durable even when chainstate writes succeed.
Fix: Return the flush error before those writes, leaving the last-flushed marker and on-disk coins tip unchanged in the failing call.
Later flushes can retry and write if they succeed, including during shutdown.
ConnectTip() and DisconnectTip() propagate the error before updating the chain tip, after applying the coins changes in memory.
History:
- #27866 raised whether saving other state after a flush failure was preferable. This change preserves later retries while skipping writes in the failing call.
- #34897 introduced
m_last_flushed_blockto prevent persistent indexes from advancing past flushed chainstate. This fix keeps it at the last successful flush.