What a rebuild really asksReading every sector of every survivor — on a four-drive 16TB array, roughly 48TB of sustained reads through drives the same age as the one that just died. That's the risk, plainly.
The URE number, honestlyConsumer drives are specified at about one unrecoverable read error per 1014 bits — roughly one bad sector per 12.5TB read; enterprise drives at 1015, ten times better. It's a warranty floor, not a schedule: most drives read far past it clean. The spec is real; the doom-graphs are marketing.
What controllers do when it happensBehaviour diverges: older controllers abort the whole rebuild at one URE; modern PERC and MegaRAID 'puncture' the stripe and continue; Linux mdadm logs it to a bad-block list. One unreadable sector should cost one stripe — not the array.
Why the second failure is usually mechanicalSame-batch drives, same hours, same heat — then a rebuild's marathon read. The survivor that was quietly marginal fails on the treadmill. Imaging gently, weakest regions last, is how we run that marathon instead.