]> git.proxmox.com Git - qemu-server.git/blame - PVE/QemuMigrate.pm
migration: implement insecure offline migration
[qemu-server.git] / PVE / QemuMigrate.pm
CommitLineData
3ea94c60 1package PVE::QemuMigrate;
1ef75254 2
1e3baf05 3use strict;
3ea94c60 4use warnings;
16e903f2 5use PVE::AbstractMigrate;
3ea94c60 6use IO::File;
1e3baf05 7use IPC::Open2;
61b04c6d 8use POSIX qw( WNOHANG );
3ea94c60 9use PVE::INotify;
f9a971e0 10use PVE::Tools;
3ea94c60 11use PVE::Cluster;
1e3baf05 12use PVE::Storage;
3ea94c60 13use PVE::QemuServer;
e52bd94c 14use Time::HiRes qw( usleep );
95a4b4a9 15use PVE::RPCEnvironment;
1e3baf05 16
16e903f2 17use base qw(PVE::AbstractMigrate);
1e3baf05 18
1ef75254 19sub fork_command_pipe {
46a84fd4 20 my ($self, $cmd) = @_;
19672434 21
1ef75254
DM
22 my $reader = IO::File->new();
23 my $writer = IO::File->new();
24
25 my $orig_pid = $$;
26
27 my $cpid;
28
29 eval { $cpid = open2($reader, $writer, @$cmd); };
30
31 my $err = $@;
32
33 # catch exec errors
34 if ($orig_pid != $$) {
46a84fd4 35 $self->log('err', "can't fork command pipe\n");
19672434
DM
36 POSIX::_exit(1);
37 kill('KILL', $$);
1ef75254
DM
38 }
39
40 die $err if $err;
41
42 return { writer => $writer, reader => $reader, pid => $cpid };
43}
44
19672434 45sub finish_command_pipe {
97439670 46 my ($self, $cmdpipe, $timeout) = @_;
1ef75254 47
61b04c6d
TL
48 my $cpid = $cmdpipe->{pid};
49 return if !defined($cpid);
50
1ef75254
DM
51 my $writer = $cmdpipe->{writer};
52 my $reader = $cmdpipe->{reader};
53
54 $writer->close();
55 $reader->close();
56
61b04c6d
TL
57 my $collect_child_process = sub {
58 my $res = waitpid($cpid, WNOHANG);
59 if (defined($res) && ($res == $cpid)) {
60 delete $cmdpipe->{cpid};
61 return 1;
62 } else {
63 return 0;
64 }
65 };
1ef75254 66
97439670
DM
67 if ($timeout) {
68 for (my $i = 0; $i < $timeout; $i++) {
61b04c6d 69 return if &$collect_child_process();
97439670
DM
70 sleep(1);
71 }
72 }
73
74 $self->log('info', "ssh tunnel still running - terminating now with SIGTERM\n");
75 kill(15, $cpid);
1ef75254 76
97439670
DM
77 # wait again
78 for (my $i = 0; $i < 10; $i++) {
61b04c6d 79 return if &$collect_child_process();
97439670
DM
80 sleep(1);
81 }
82
83 $self->log('info', "ssh tunnel still running - terminating now with SIGKILL\n");
84 kill 9, $cpid;
85 sleep 1;
61b04c6d
TL
86
87 $self->log('err', "ssh tunnel child process (PID $cpid) couldn't be collected\n")
88 if !&$collect_child_process();
1ef75254
DM
89}
90
1e3baf05 91sub fork_tunnel {
1c9d54bf 92 my ($self, $tunnel_addr) = @_;
1e3baf05 93
e858e9d2 94 my @localtunnelinfo = defined($tunnel_addr) ? ('-L' , $tunnel_addr ) : ();
5bc1e039 95
1c9d54bf 96 my $cmd = [@{$self->{rem_ssh}}, '-o ExitOnForwardFailure=yes', @localtunnelinfo, 'qm', 'mtunnel' ];
19672434 97
46a84fd4 98 my $tunnel = $self->fork_command_pipe($cmd);
1e3baf05
DM
99
100 my $reader = $tunnel->{reader};
101
102 my $helo;
19672434 103 eval {
17eed025 104 PVE::Tools::run_with_timeout(60, sub { $helo = <$reader>; });
1e3baf05 105 die "no reply\n" if !$helo;
1ef75254 106 die "no quorum on target node\n" if $helo =~ m/^no quorum$/;
19672434 107 die "got strange reply from mtunnel ('$helo')\n"
1e3baf05
DM
108 if $helo !~ m/^tunnel online$/;
109 };
110 my $err = $@;
111
112 if ($err) {
46a84fd4 113 $self->finish_command_pipe($tunnel);
1e3baf05
DM
114 die "can't open migration tunnel - $err";
115 }
116 return $tunnel;
117}
118
19672434 119sub finish_tunnel {
16e903f2 120 my ($self, $tunnel) = @_;
1e3baf05
DM
121
122 my $writer = $tunnel->{writer};
123
19672434 124 eval {
17eed025 125 PVE::Tools::run_with_timeout(30, sub {
1e3baf05
DM
126 print $writer "quit\n";
127 $writer->flush();
19672434 128 });
1e3baf05
DM
129 };
130 my $err = $@;
19672434 131
97439670 132 $self->finish_command_pipe($tunnel, 30);
19672434 133
1c9d54bf
TL
134 if ($tunnel->{sock_addr}) {
135 # ssh does not clean up on local host
136 my $cmd = ['rm', '-f', $tunnel->{sock_addr}]; #
137 PVE::Tools::run_command($cmd);
138
139 # .. and just to be sure check on remote side
140 unshift @{$cmd}, @{$self->{rem_ssh}};
141 PVE::Tools::run_command($cmd);
142 }
143
1e3baf05
DM
144 die $err if $err;
145}
146
16e903f2
DM
147sub lock_vm {
148 my ($self, $vmid, $code, @param) = @_;
f5eb281a 149
ffda963f 150 return PVE::QemuConfig->lock_config($vmid, $code, @param);
16e903f2 151}
ff1a2432 152
16e903f2
DM
153sub prepare {
154 my ($self, $vmid) = @_;
ff1a2432 155
16e903f2 156 my $online = $self->{opts}->{online};
3ea94c60 157
16e903f2 158 $self->{storecfg} = PVE::Storage::config();
3ea94c60 159
e1fc368d 160 # test if VM exists
ffda963f 161 my $conf = $self->{vmconf} = PVE::QemuConfig->load_config($vmid);
3ea94c60 162
ffda963f 163 PVE::QemuConfig->check_lock($conf);
3ea94c60 164
16e903f2
DM
165 my $running = 0;
166 if (my $pid = PVE::QemuServer::check_running($vmid)) {
b6adff33 167 die "can't migrate running VM without --online\n" if !$online;
16e903f2 168 $running = $pid;
42dbd2ee
AD
169
170 $self->{forcemachine} = PVE::QemuServer::qemu_machine_pxe($vmid, $conf);
7bac824e 171
3ea94c60
DM
172 }
173
16e903f2
DM
174 if (my $loc_res = PVE::QemuServer::check_local_resources($conf, 1)) {
175 if ($self->{running} || !$self->{opts}->{force}) {
176 die "can't migrate VM which uses local devices\n";
177 } else {
178 $self->log('info', "migrating VM which uses local devices");
179 }
3ea94c60
DM
180 }
181
ff1a2432 182 my $vollist = PVE::QemuServer::get_vm_volumes($conf);
16e903f2 183
73f5ee92 184 my $need_activate = [];
29701766
FG
185 foreach my $volid (@$vollist) {
186 my ($sid, $volname) = PVE::Storage::parse_volume_id($volid, 1);
187
188 # check if storage is available on both nodes
b74cad8a
AD
189 my $targetsid = $self->{opts}->{targetstorage} ? $self->{opts}->{targetstorage} : $sid;
190
29701766 191 my $scfg = PVE::Storage::storage_check_node($self->{storecfg}, $sid);
b74cad8a 192 PVE::Storage::storage_check_node($self->{storecfg}, $targetsid, $self->{node});
73f5ee92
FG
193
194 if ($scfg->{shared}) {
195 # PVE::Storage::activate_storage checks this for non-shared storages
196 my $plugin = PVE::Storage::Plugin->lookup($scfg->{type});
197 warn "Used shared storage '$sid' is not online on source node!\n"
198 if !$plugin->check_connection($sid, $scfg);
199 } else {
200 # only activate if not shared
201 push @$need_activate, $volid;
202 }
29701766 203 }
3ea94c60 204
73f5ee92
FG
205 # activate volumes
206 PVE::Storage::activate_volumes($self->{storecfg}, $need_activate);
207
3ea94c60 208 # test ssh connection
16e903f2
DM
209 my $cmd = [ @{$self->{rem_ssh}}, '/bin/true' ];
210 eval { $self->cmd_quiet($cmd); };
3ea94c60 211 die "Can't connect to destination address using public key\n" if $@;
ff1a2432 212
16e903f2 213 return $running;
3ea94c60
DM
214}
215
216sub sync_disks {
16e903f2
DM
217 my ($self, $vmid) = @_;
218
16e903f2
DM
219 my $conf = $self->{vmconf};
220
dabf2473 221 # local volumes which have been copied
16e903f2 222 $self->{volumes} = [];
3ea94c60
DM
223
224 my $res = [];
225
226 eval {
227
dabf2473
FG
228 # found local volumes and their origin
229 my $local_volumes = {};
5bf7f0f1
FG
230 my $local_volumes_errors = {};
231 my $other_errors = [];
232 my $abort = 0;
3ea94c60 233
a06c7f7e
DM
234 my $sharedvm = 1;
235
5bf7f0f1
FG
236 my $log_error = sub {
237 my ($msg, $volid) = @_;
238
239 if (defined($volid)) {
240 $local_volumes_errors->{$volid} = $msg;
241 } else {
242 push @$other_errors, $msg;
243 }
244 $abort = 1;
245 };
246
522c8f97 247 my @sids = PVE::Storage::storage_ids($self->{storecfg});
86638cc2 248 foreach my $storeid (@sids) {
522c8f97 249 my $scfg = PVE::Storage::storage_config($self->{storecfg}, $storeid);
86638cc2 250 next if $scfg->{shared};
373ea579
DM
251 next if !PVE::Storage::storage_check_enabled($self->{storecfg}, $storeid, undef, 1);
252
86638cc2
FG
253 # get list from PVE::Storage (for unused volumes)
254 my $dl = PVE::Storage::vdisk_list($self->{storecfg}, $storeid, $vmid);
89719f98
FG
255
256 next if @{$dl->{$storeid}} == 0;
257
d80ad67f
AD
258 my $targetsid = $self->{opts}->{targetstorage} ? $self->{opts}->{targetstorage} : $storeid;
259
86638cc2 260 # check if storage is available on target node
d80ad67f 261 PVE::Storage::storage_check_node($self->{storecfg}, $targetsid, $self->{node});
89719f98
FG
262 $sharedvm = 0; # there is a non-shared disk
263
86638cc2
FG
264 PVE::Storage::foreach_volid($dl, sub {
265 my ($volid, $sid, $volname) = @_;
80b2cbd1 266
dabf2473 267 $local_volumes->{$volid} = 'storage';
86638cc2
FG
268 });
269 }
3ea94c60 270
3629c19d 271 my $test_volid = sub {
b6adff33 272 my ($volid, $is_cdrom, $snapname) = @_;
3ea94c60 273
3ea94c60
DM
274 return if !$volid;
275
5bf7f0f1
FG
276 if ($volid =~ m|^/|) {
277 $local_volumes->{$volid} = 'config';
278 die "local file/device\n";
279 }
3ea94c60 280
d5769dc2 281 if ($is_cdrom) {
5bf7f0f1
FG
282 if ($volid eq 'cdrom') {
283 my $msg = "can't migrate local cdrom drive";
284 $msg .= " (referenced in snapshot '$snapname')"
285 if defined($snapname);
286
287 &$log_error("$msg\n");
288 return;
289 }
3ea94c60 290 return if $volid eq 'none';
3ea94c60
DM
291 }
292
293 my ($sid, $volname) = PVE::Storage::parse_volume_id($volid);
294
b74cad8a 295 my $targetsid = $self->{opts}->{targetstorage} ? $self->{opts}->{targetstorage} : $sid;
16e903f2
DM
296 # check if storage is available on both nodes
297 my $scfg = PVE::Storage::storage_check_node($self->{storecfg}, $sid);
d80ad67f 298 PVE::Storage::storage_check_node($self->{storecfg}, $targetsid, $self->{node});
3ea94c60
DM
299
300 return if $scfg->{shared};
301
3ea94c60
DM
302 $sharedvm = 0;
303
dabf2473 304 $local_volumes->{$volid} = defined($snapname) ? 'snapshot' : 'config';
d62fcf74 305
5bf7f0f1 306 die "local cdrom image\n" if $is_cdrom;
3629c19d 307
16e903f2 308 my ($path, $owner) = PVE::Storage::path($self->{storecfg}, $volid);
3ea94c60 309
5bf7f0f1 310 die "owned by other VM (owner = VM $owner)\n"
16e903f2 311 if !$owner || ($owner != $self->{vmid});
3ea94c60 312
3629c19d
DM
313 if (defined($snapname)) {
314 # we cannot migrate shapshots on local storage
315 # exceptions: 'zfspool' or 'qcow2' files (on directory storage)
316
317 my $format = PVE::QemuServer::qemu_img_format($scfg, $volname);
b74cad8a 318 die "online storage migration not possible if snapshot exists\n" if $self->{running};
b3205b15 319 if (!($scfg->{type} eq 'zfspool' || $format eq 'qcow2')) {
5bf7f0f1 320 die "non-migratable snapshot exists\n";
3629c19d 321 }
3629c19d 322 }
3a7bc9e2
FG
323
324 die "referenced by linked clone(s)\n"
325 if PVE::Storage::volume_is_base_and_used($self->{storecfg}, $volid);
3629c19d
DM
326 };
327
98d80cb6
FG
328 my $test_drive = sub {
329 my ($ds, $drive, $snapname) = @_;
330
5bf7f0f1
FG
331 eval {
332 &$test_volid($drive->{file}, PVE::QemuServer::drive_is_cdrom($drive), $snapname);
333 };
334
335 &$log_error($@, $drive->{file}) if $@;
98d80cb6
FG
336 };
337
b6adff33 338 foreach my $snapname (keys %{$conf->{snapshots}}) {
5bf7f0f1
FG
339 eval {
340 &$test_volid($conf->{snapshots}->{$snapname}->{'vmstate'}, 0, undef)
341 if defined($conf->{snapshots}->{$snapname}->{'vmstate'});
342 };
343 &$log_error($@, $conf->{snapshots}->{$snapname}->{'vmstate'}) if $@;
344
98d80cb6 345 PVE::QemuServer::foreach_drive($conf->{snapshots}->{$snapname}, $test_drive, $snapname);
3629c19d 346 }
4abdd867 347 PVE::QemuServer::foreach_drive($conf, $test_drive);
3ea94c60 348
dabf2473
FG
349 foreach my $vol (sort keys %$local_volumes) {
350 if ($local_volumes->{$vol} eq 'storage') {
d62fcf74 351 $self->log('info', "found local disk '$vol' (via storage)\n");
dabf2473 352 } elsif ($local_volumes->{$vol} eq 'config') {
56af7146 353 die "can't live migrate attached local disks without with-local-disks option\n" if $self->{running} && !$self->{opts}->{"with-local-disks"};
d62fcf74 354 $self->log('info', "found local disk '$vol' (in current VM config)\n");
dabf2473 355 } elsif ($local_volumes->{$vol} eq 'snapshot') {
d62fcf74
FG
356 $self->log('info', "found local disk '$vol' (referenced by snapshot(s))\n");
357 } else {
358 $self->log('info', "found local disk '$vol'\n");
359 }
360 }
361
5bf7f0f1
FG
362 foreach my $vol (sort keys %$local_volumes_errors) {
363 $self->log('warn', "can't migrate local disk '$vol': $local_volumes_errors->{$vol}");
364 }
365 foreach my $err (@$other_errors) {
366 $self->log('warn', "$err");
367 }
368
b74cad8a
AD
369 if ($self->{running} && !$sharedvm && !$self->{opts}->{targetstorage}) {
370 $self->{opts}->{targetstorage} = 1; #use same sid for remote local
3ea94c60
DM
371 }
372
5bf7f0f1
FG
373 if ($abort) {
374 die "can't migrate VM - check log\n";
375 }
376
c4d2d6c1 377 # additional checks for local storage
dabf2473 378 foreach my $volid (keys %$local_volumes) {
3ea94c60 379 my ($sid, $volname) = PVE::Storage::parse_volume_id($volid);
16e903f2 380 my $scfg = PVE::Storage::storage_config($self->{storecfg}, $sid);
3ea94c60 381
c4d2d6c1
WL
382 my $migratable = ($scfg->{type} eq 'dir') || ($scfg->{type} eq 'zfspool') ||
383 ($scfg->{type} eq 'lvmthin') || ($scfg->{type} eq 'lvm');
384
37a6dc78 385 die "can't migrate '$volid' - storage type '$scfg->{type}' not supported\n"
c4d2d6c1 386 if !$migratable;
d5604092 387
c4d2d6c1
WL
388 # image is a linked clone on local storage, se we can't migrate.
389 if (my $basename = (PVE::Storage::parse_volname($self->{storecfg}, $volid))[3]) {
390 die "can't migrate '$volid' as it's a clone of '$basename'";
d5604092 391 }
3ea94c60
DM
392 }
393
b74cad8a
AD
394 $self->log('info', "copying disk images");
395
dabf2473 396 foreach my $volid (keys %$local_volumes) {
3ea94c60 397 my ($sid, $volname) = PVE::Storage::parse_volume_id($volid);
b74cad8a
AD
398 if ($self->{running} && $self->{opts}->{targetstorage} && $local_volumes->{$volid} eq 'config') {
399 push @{$self->{online_local_volumes}}, $volid;
400 } else {
401 push @{$self->{volumes}}, $volid;
f1c2a53a
WB
402 my $insecure = $self->{opts}->{migration_type} eq 'insecure';
403 PVE::Storage::storage_migrate($self->{storecfg}, $volid, $self->{ssh_info}, $sid, undef, undef, undef, undef, $insecure);
b74cad8a 404 }
3ea94c60
DM
405 }
406 };
407 die "Failed to sync data - $@" if $@;
408}
409
b74cad8a
AD
410sub cleanup_remotedisks {
411 my ($self) = @_;
412
413 foreach my $target_drive (keys %{$self->{target_drive}}) {
414
415 my $drive = PVE::QemuServer::parse_drive($target_drive, $self->{target_drive}->{$target_drive}->{volid});
416 my ($storeid, $volname) = PVE::Storage::parse_volume_id($drive->{file});
417
418 my $cmd = [@{$self->{rem_ssh}}, 'pvesm', 'free', "$storeid:$volname"];
419
420 eval{ PVE::Tools::run_command($cmd, outfunc => sub {}, errfunc => sub {}) };
421 if (my $err = $@) {
422 $self->log('err', $err);
423 $self->{errors} = 1;
424 }
425 }
426}
427
1e3baf05 428sub phase1 {
16e903f2 429 my ($self, $vmid) = @_;
1e3baf05 430
16e903f2 431 $self->log('info', "starting migration of VM $vmid to node '$self->{node}' ($self->{nodeip})");
1e3baf05 432
16e903f2 433 my $conf = $self->{vmconf};
1e3baf05
DM
434
435 # set migrate lock in config file
1858638f 436 $conf->{lock} = 'migrate';
ffda963f 437 PVE::QemuConfig->write_config($vmid, $conf);
1e3baf05 438
f1c2a53a
WB
439 # we use TCP only for unsecure migrations as TCP ssh forward tunnels often
440 # did appeared to late (they are hard, if not impossible, to check for)
441 # secure migration use UNIX sockets now, this *breaks* compatibilty when trying
442 # to migrate from new to old but *not* from old to new.
443 my $datacenterconf = PVE::Cluster::cfs_read_file('datacenter.cfg');
444
445 my $migration_type = 'secure';
446 if (defined($self->{opts}->{migration_type})) {
447 $migration_type = $self->{opts}->{migration_type};
448 } elsif (defined($datacenterconf->{migration}->{type})) {
449 $migration_type = $datacenterconf->{migration}->{type};
450 }
451 $self->{opts}->{migration_type} = $migration_type;
452
16e903f2 453 sync_disks($self, $vmid);
1ef75254 454
1e3baf05
DM
455};
456
16e903f2
DM
457sub phase1_cleanup {
458 my ($self, $vmid, $err) = @_;
459
460 $self->log('info', "aborting phase 1 - cleanup resources");
461
1858638f
DM
462 my $conf = $self->{vmconf};
463 delete $conf->{lock};
ffda963f 464 eval { PVE::QemuConfig->write_config($vmid, $conf) };
16e903f2
DM
465 if (my $err = $@) {
466 $self->log('err', $err);
467 }
f5eb281a 468
16e903f2
DM
469 if ($self->{volumes}) {
470 foreach my $volid (@{$self->{volumes}}) {
471 $self->log('err', "found stale volume copy '$volid' on node '$self->{node}'");
472 # fixme: try to remove ?
473 }
474 }
475}
476
1e3baf05 477sub phase2 {
16e903f2 478 my ($self, $vmid) = @_;
1e3baf05 479
16e903f2
DM
480 my $conf = $self->{vmconf};
481
46a84fd4 482 $self->log('info', "starting VM $vmid on remote node '$self->{node}'");
1e3baf05 483
5bc1e039 484 my $raddr;
1e3baf05 485 my $rport;
1c9d54bf 486 my $ruri; # the whole migration dst. URI (protocol:address[:port])
7e8dcf2c
AD
487 my $nodename = PVE::INotify::nodename();
488
19672434 489 ## start on remote node
95a4b4a9
AD
490 my $cmd = [@{$self->{rem_ssh}}];
491
7c14dcae 492 my $spice_ticket;
86b8228b 493 if (PVE::QemuServer::vga_conf_has_spice($conf->{vga})) {
95a4b4a9 494 my $res = PVE::QemuServer::vm_mon_cmd($vmid, 'query-spice');
7c14dcae 495 $spice_ticket = $res->{ticket};
95a4b4a9
AD
496 }
497
1c9d54bf
TL
498 push @$cmd , 'qm', 'start', $vmid, '--skiplock', '--migratedfrom', $nodename;
499
f1c2a53a 500 my $migration_type = $self->{opts}->{migration_type};
2de2d6f7
TL
501
502 push @$cmd, '--migration_type', $migration_type;
503
504 push @$cmd, '--migration_network', $self->{opts}->{migration_network}
505 if $self->{opts}->{migration_network};
506
507 if ($migration_type eq 'insecure') {
1c9d54bf
TL
508 push @$cmd, '--stateuri', 'tcp';
509 } else {
510 push @$cmd, '--stateuri', 'unix';
511 }
95a4b4a9 512
42668529
DM
513 if ($self->{forcemachine}) {
514 push @$cmd, '--machine', $self->{forcemachine};
515 }
516
b74cad8a
AD
517 if ($self->{opts}->{targetstorage}) {
518 push @$cmd, '--targetstorage', $self->{opts}->{targetstorage};
519 }
520
86b8228b
DM
521 my $spice_port;
522
7c14dcae
DM
523 # Note: We try to keep $spice_ticket secret (do not pass via command line parameter)
524 # instead we pipe it through STDIN
525 PVE::Tools::run_command($cmd, input => $spice_ticket, outfunc => sub {
1e3baf05
DM
526 my $line = shift;
527
407e0b8b 528 if ($line =~ m/^migration listens on tcp:(localhost|[\d\.]+|\[[\d\.:a-fA-F]+\]):(\d+)$/) {
5bc1e039
SP
529 $raddr = $1;
530 $rport = int($2);
1c9d54bf
TL
531 $ruri = "tcp:$raddr:$rport";
532 }
533 elsif ($line =~ m!^migration listens on unix:(/run/qemu-server/(\d+)\.migrate)$!) {
534 $raddr = $1;
535 die "Destination UNIX sockets VMID does not match source VMID" if $vmid ne $2;
536 $ruri = "unix:$raddr";
5bc1e039
SP
537 }
538 elsif ($line =~ m/^migration listens on port (\d+)$/) {
539 $raddr = "localhost";
86b8228b 540 $rport = int($1);
1c9d54bf 541 $ruri = "tcp:$raddr:$rport";
5bc1e039
SP
542 }
543 elsif ($line =~ m/^spice listens on port (\d+)$/) {
86b8228b 544 $spice_port = int($1);
1e3baf05 545 }
b74cad8a
AD
546 elsif ($line =~ m/^storage migration listens on nbd:(localhost|[\d\.]+|\[[\d\.:a-fA-F]+\]):(\d+):exportname=(\S+) volume:(\S+)$/) {
547 my $volid = $4;
548 my $nbd_uri = "nbd:$1:$2:exportname=$3";
549 my $targetdrive = $3;
550 $targetdrive =~ s/drive-//g;
551
552 $self->{target_drive}->{$targetdrive}->{volid} = $volid;
553 $self->{target_drive}->{$targetdrive}->{nbd_uri} = $nbd_uri;
554
555 }
ab399b7c
AD
556 }, errfunc => sub {
557 my $line = shift;
558 $self->log('info', $line);
559 });
1e3baf05 560
5bc1e039 561 die "unable to detect remote migration address\n" if !$raddr;
1ef75254 562
2de2d6f7 563 if ($migration_type eq 'secure') {
1c9d54bf
TL
564 $self->log('info', "start remote tunnel");
565
566 if ($ruri =~ /^unix:/) {
54323eed 567 unlink $raddr;
1c9d54bf
TL
568 $self->{tunnel} = $self->fork_tunnel("$raddr:$raddr");
569 $self->{tunnel}->{sock_addr} = $raddr;
570
571 my $unix_socket_try = 0; # wait for the socket to become ready
572 while (! -S $raddr) {
573 $unix_socket_try++;
574 if ($unix_socket_try > 100) {
575 $self->{errors} = 1;
576 $self->finish_tunnel($self->{tunnel});
577 die "Timeout, migration socket $ruri did not get ready";
578 }
579
580 usleep(50000);
581 }
582
583 } elsif ($ruri =~ /^tcp:/) {
e858e9d2
TL
584 my $tunnel_addr;
585 if ($raddr eq "localhost") {
586 # for backwards compatibility with older qemu-server versions
587 my $pfamily = PVE::Tools::get_host_address_family($nodename);
588 my $lport = PVE::Tools::next_migrate_port($pfamily);
589 $tunnel_addr = "$lport:localhost:$rport";
590 }
1c9d54bf 591
e858e9d2 592 $self->{tunnel} = $self->fork_tunnel($tunnel_addr);
1c9d54bf
TL
593
594 } else {
595 die "unsupported protocol in migration URI: $ruri\n";
596 }
597 }
1e3baf05 598
1e3baf05 599 my $start = time();
b74cad8a 600
8b54f4b8 601 if ($self->{opts}->{targetstorage} && defined($self->{online_local_volumes})) {
b74cad8a
AD
602 $self->{storage_migration} = 1;
603 $self->{storage_migration_jobs} = {};
604 $self->log('info', "starting storage migration");
605
bd2d5fe6 606 die "The number of local disks does not match between the source and the destination.\n"
3b4cf0f0 607 if (scalar(keys %{$self->{target_drive}}) != scalar @{$self->{online_local_volumes}});
b74cad8a 608 foreach my $drive (keys %{$self->{target_drive}}){
3b4cf0f0
WB
609 my $nbd_uri = $self->{target_drive}->{$drive}->{nbd_uri};
610 $self->log('info', "$drive: start migration to to $nbd_uri");
611 PVE::QemuServer::qemu_drive_mirror($vmid, $drive, $nbd_uri, $vmid, undef, $self->{storage_migration_jobs}, 1);
b74cad8a
AD
612 }
613 }
614
1c9d54bf 615 $self->log('info', "starting online/live migration on $ruri");
5bc1e039 616 $self->{livemigration} = 1;
e18b0b99 617
3beb415b
AD
618 # load_defaults
619 my $defaults = PVE::QemuServer::load_defaults();
620
621 # always set migrate speed (overwrite kvm default of 32m)
622 # we set a very hight default of 8192m which is basically unlimited
623 my $migrate_speed = $defaults->{migrate_speed} || 8192;
624 $migrate_speed = $conf->{migrate_speed} || $migrate_speed;
625 $migrate_speed = $migrate_speed * 1048576;
626 $self->log('info', "migrate_set_speed: $migrate_speed");
627 eval {
628 PVE::QemuServer::vm_mon_cmd_nocheck($vmid, "migrate_set_speed", value => int($migrate_speed));
629 };
630 $self->log('info', "migrate_set_speed error: $@") if $@;
631
632 my $migrate_downtime = $defaults->{migrate_downtime};
633 $migrate_downtime = $conf->{migrate_downtime} if defined($conf->{migrate_downtime});
634 if (defined($migrate_downtime)) {
635 $self->log('info', "migrate_set_downtime: $migrate_downtime");
636 eval {
865ef132 637 PVE::QemuServer::vm_mon_cmd_nocheck($vmid, "migrate_set_downtime", value => int($migrate_downtime*100)/100);
3beb415b
AD
638 };
639 $self->log('info', "migrate_set_downtime error: $@") if $@;
640 }
641
f34d1466 642 $self->log('info', "set migration_caps");
e18b0b99 643 eval {
a89fded1 644 PVE::QemuServer::set_migration_caps($vmid);
e18b0b99 645 };
a89fded1 646 warn $@ if $@;
e18b0b99
AD
647
648 #set cachesize 10% of the total memory
649 my $cachesize = int($conf->{memory}*1048576/10);
f34d1466 650 $self->log('info', "set cachesize: $cachesize");
e18b0b99 651 eval {
f34d1466 652 PVE::QemuServer::vm_mon_cmd_nocheck($vmid, "migrate-set-cache-size", value => int($cachesize));
e18b0b99 653 };
f34d1466
TL
654 $self->log('info', "migrate-set-cache-size error: $@") if $@;
655
86b8228b 656 if (PVE::QemuServer::vga_conf_has_spice($conf->{vga})) {
95a4b4a9
AD
657 my $rpcenv = PVE::RPCEnvironment::get();
658 my $authuser = $rpcenv->get_user();
659
86b8228b 660 my (undef, $proxyticket) = PVE::AccessControl::assemble_spice_ticket($authuser, $vmid, $self->{node});
95a4b4a9 661
86b8228b 662 my $filename = "/etc/pve/nodes/$self->{node}/pve-ssl.pem";
dd25eecf 663 my $subject = PVE::AccessControl::read_x509_subject_spice($filename);
95a4b4a9
AD
664
665 $self->log('info', "spice client_migrate_info");
666
667 eval {
86b8228b
DM
668 PVE::QemuServer::vm_mon_cmd_nocheck($vmid, "client_migrate_info", protocol => 'spice',
669 hostname => $proxyticket, 'tls-port' => $spice_port,
670 'cert-subject' => $subject);
95a4b4a9
AD
671 };
672 $self->log('info', "client_migrate_info error: $@") if $@;
673
674 }
675
f34d1466 676 $self->log('info', "start migrate command to $ruri");
5a7835f5 677 eval {
1c9d54bf 678 PVE::QemuServer::vm_mon_cmd_nocheck($vmid, "migrate", uri => $ruri);
5a7835f5
AD
679 };
680 my $merr = $@;
1c9d54bf 681 $self->log('info', "migrate uri => $ruri failed: $merr") if $merr;
1e3baf05 682
a05b47a8 683 my $lstat = 0;
e52bd94c
AD
684 my $usleep = 2000000;
685 my $i = 0;
b0b756c1 686 my $err_count = 0;
865ef132
SP
687 my $lastrem = undef;
688 my $downtimecounter = 0;
1e3baf05 689 while (1) {
e52bd94c
AD
690 $i++;
691 my $avglstat = $lstat/$i if $lstat;
692
b0b756c1
DM
693 usleep($usleep);
694 my $stat;
695 eval {
696 $stat = PVE::QemuServer::vm_mon_cmd_nocheck($vmid, "query-migrate");
697 };
698 if (my $err = $@) {
699 $err_count++;
700 warn "query migrate failed: $err\n";
f34d1466 701 $self->log('info', "query migrate failed: $err");
b0b756c1
DM
702 if ($err_count <= 5) {
703 usleep(1000000);
704 next;
705 }
706 die "too many query migrate failures - aborting\n";
707 }
985a5f48 708
f34d1466 709 if (defined($stat->{status}) && $stat->{status} =~ m/^(setup)$/im) {
985a5f48
AD
710 sleep(1);
711 next;
712 }
713
f34d1466 714 if (defined($stat->{status}) && $stat->{status} =~ m/^(active|completed|failed|cancelled)$/im) {
d68afb26 715 $merr = undef;
b0b756c1 716 $err_count = 0;
5a7835f5 717 if ($stat->{status} eq 'completed') {
1e3baf05
DM
718 my $delay = time() - $start;
719 if ($delay > 0) {
720 my $mbps = sprintf "%.2f", $conf->{memory}/$delay;
135007c0
AD
721 my $downtime = $stat->{downtime} || 0;
722 $self->log('info', "migration speed: $mbps MB/s - downtime $downtime ms");
1e3baf05
DM
723 }
724 }
f5eb281a 725
5a7835f5 726 if ($stat->{status} eq 'failed' || $stat->{status} eq 'cancelled') {
f34d1466 727 $self->log('info', "migration status error: $stat->{status}");
1e3baf05
DM
728 die "aborting\n"
729 }
730
a05b47a8
DM
731 if ($stat->{status} ne 'active') {
732 $self->log('info', "migration status: $stat->{status}");
733 last;
734 }
735
736 if ($stat->{ram}->{transferred} ne $lstat) {
737 my $trans = $stat->{ram}->{transferred} || 0;
738 my $rem = $stat->{ram}->{remaining} || 0;
739 my $total = $stat->{ram}->{total} || 0;
e18b0b99
AD
740 my $xbzrlecachesize = $stat->{"xbzrle-cache"}->{"cache-size"} || 0;
741 my $xbzrlebytes = $stat->{"xbzrle-cache"}->{"bytes"} || 0;
742 my $xbzrlepages = $stat->{"xbzrle-cache"}->{"pages"} || 0;
743 my $xbzrlecachemiss = $stat->{"xbzrle-cache"}->{"cache-miss"} || 0;
744 my $xbzrleoverflow = $stat->{"xbzrle-cache"}->{"overflow"} || 0;
e52bd94c 745 #reduce sleep if remainig memory if lower than the everage transfert
94235c59 746 $usleep = 300000 if $avglstat && $rem < $avglstat;
a05b47a8
DM
747
748 $self->log('info', "migration status: $stat->{status} (transferred ${trans}, " .
0302101c 749 "remaining ${rem}), total ${total})");
e18b0b99 750
2e787b18
SP
751 if (${xbzrlecachesize}) {
752 $self->log('info', "migration xbzrle cachesize: ${xbzrlecachesize} transferred ${xbzrlebytes} pages ${xbzrlepages} cachemiss ${xbzrlecachemiss} overflow ${xbzrleoverflow}");
753 }
754
865ef132
SP
755 if (($lastrem && $rem > $lastrem ) || ($rem == 0)) {
756 $downtimecounter++;
757 }
758 $lastrem = $rem;
759
760 if ($downtimecounter > 5) {
761 $downtimecounter = 0;
762 $migrate_downtime *= 2;
763 $self->log('info', "migrate_set_downtime: $migrate_downtime");
764 eval {
765 PVE::QemuServer::vm_mon_cmd_nocheck($vmid, "migrate_set_downtime", value => int($migrate_downtime*100)/100);
766 };
767 $self->log('info', "migrate_set_downtime error: $@") if $@;
768 }
769
a05b47a8
DM
770 }
771
865ef132 772
a05b47a8 773 $lstat = $stat->{ram}->{transferred};
e52bd94c 774
1e3baf05 775 } else {
d68afb26 776 die $merr if $merr;
5a7835f5 777 die "unable to parse migration status '$stat->{status}' - aborting\n";
1e3baf05 778 }
a05b47a8 779 }
92437b8d
TL
780
781 # just to be sure that the tunnel gets closed on successful migration, on error
782 # phase2_cleanup closes it *after* stopping the remote waiting VM
783 if (!$self->{errors} && $self->{tunnel}) {
386c6ba7
WL
784 eval { finish_tunnel($self, $self->{tunnel}); };
785 if (my $err = $@) {
786 $self->log('err', $err);
787 $self->{errors} = 1;
788 }
789 }
1e3baf05 790}
16e903f2 791
c04b5b04
AD
792sub phase2_cleanup {
793 my ($self, $vmid, $err) = @_;
794
af30308f
DM
795 return if !$self->{errors};
796 $self->{phase2errors} = 1;
797
c04b5b04
AD
798 $self->log('info', "aborting phase 2 - cleanup resources");
799
19168b91
SP
800 $self->log('info', "migrate_cancel");
801 eval {
802 PVE::QemuServer::vm_mon_cmd_nocheck($vmid, "migrate_cancel");
803 };
804 $self->log('info', "migrate_cancel error: $@") if $@;
805
c04b5b04
AD
806 my $conf = $self->{vmconf};
807 delete $conf->{lock};
ffda963f 808 eval { PVE::QemuConfig->write_config($vmid, $conf) };
c04b5b04
AD
809 if (my $err = $@) {
810 $self->log('err', $err);
811 }
812
af30308f 813 # cleanup ressources on target host
3b4cf0f0 814 if ($self->{storage_migration}) {
b74cad8a
AD
815
816 eval { PVE::QemuServer::qemu_blockjobs_cancel($vmid, $self->{storage_migration_jobs}) };
817 if (my $err = $@) {
818 $self->log('err', $err);
819 }
820
821 eval { PVE::QemuMigrate::cleanup_remotedisks($self) };
822 if (my $err = $@) {
823 $self->log('err', $err);
824 }
825 }
826
af30308f
DM
827 my $nodename = PVE::INotify::nodename();
828
829 my $cmd = [@{$self->{rem_ssh}}, 'qm', 'stop', $vmid, '--skiplock', '--migratedfrom', $nodename];
830 eval{ PVE::Tools::run_command($cmd, outfunc => sub {}, errfunc => sub {}) };
831 if (my $err = $@) {
832 $self->log('err', $err);
833 $self->{errors} = 1;
834 }
386c6ba7
WL
835
836 if ($self->{tunnel}) {
837 eval { finish_tunnel($self, $self->{tunnel}); };
838 if (my $err = $@) {
839 $self->log('err', $err);
840 $self->{errors} = 1;
841 }
842 }
c04b5b04
AD
843}
844
16e903f2
DM
845sub phase3 {
846 my ($self, $vmid) = @_;
f5eb281a 847
16e903f2 848 my $volids = $self->{volumes};
af30308f 849 return if $self->{phase2errors};
16e903f2
DM
850
851 # destroy local copies
852 foreach my $volid (@$volids) {
46883f80
DM
853 eval { PVE::Storage::vdisk_free($self->{storecfg}, $volid); };
854 if (my $err = $@) {
855 $self->log('err', "removing local copy of '$volid' failed - $err");
856 $self->{errors} = 1;
857 last if $err =~ /^interrupted by signal$/;
16e903f2
DM
858 }
859 }
16e903f2
DM
860}
861
862sub phase3_cleanup {
863 my ($self, $vmid, $err) = @_;
864
865 my $conf = $self->{vmconf};
af30308f 866 return if $self->{phase2errors};
16e903f2 867
b74cad8a 868 if ($self->{storage_migration}) {
3b4cf0f0
WB
869 # finish block-job
870 eval { PVE::QemuServer::qemu_drive_mirror_monitor($vmid, undef, $self->{storage_migration_jobs}); };
b74cad8a
AD
871
872 if (my $err = $@) {
873 eval { PVE::QemuServer::qemu_blockjobs_cancel($vmid, $self->{storage_migration_jobs}) };
874 eval { PVE::QemuMigrate::cleanup_remotedisks($self) };
875 die "Failed to completed storage migration\n";
876 } else {
b74cad8a
AD
877 foreach my $target_drive (keys %{$self->{target_drive}}) {
878 my $drive = PVE::QemuServer::parse_drive($target_drive, $self->{target_drive}->{$target_drive}->{volid});
879 $conf->{$target_drive} = PVE::QemuServer::print_drive($vmid, $drive);
880 PVE::QemuConfig->write_config($vmid, $conf);
881 }
882 }
883 }
884
b8d20802 885 # move config to remote node
ffda963f
FG
886 my $conffile = PVE::QemuConfig->config_file($vmid);
887 my $newconffile = PVE::QemuConfig->config_file($vmid, $self->{node});
b8d20802
AD
888
889 die "Failed to move config to node '$self->{node}' - rename failed: $!\n"
890 if !rename($conffile, $newconffile);
891
5bc1e039 892 if ($self->{livemigration}) {
504105c6 893 if ($self->{storage_migration}) {
28412ae4
FG
894 # remove drives referencing the nbd server from source
895 # otherwise vm_stop might hang later on
896 foreach my $drive (keys %{$self->{target_drive}}){
897 PVE::QemuServer::vm_mon_cmd_nocheck($vmid, "device_del", id => $drive);
898 }
504105c6
FG
899 # stop nbd server on remote vm - requirement for resume since 2.9
900 my $cmd = [@{$self->{rem_ssh}}, 'qm', 'nbdstop', $vmid];
901
902 eval{ PVE::Tools::run_command($cmd, outfunc => sub {}, errfunc => sub {}) };
903 if (my $err = $@) {
904 $self->log('err', $err);
905 $self->{errors} = 1;
906 }
907 }
877e2ea7 908 # config moved and nbd server stopped - now we can resume vm on target
289e0b85 909 my $cmd = [@{$self->{rem_ssh}}, 'qm', 'resume', $vmid, '--skiplock', '--nocheck'];
d5f315fd
AD
910 eval{ PVE::Tools::run_command($cmd, outfunc => sub {},
911 errfunc => sub {
912 my $line = shift;
913 $self->log('err', $line);
914 });
915 };
f5eb281a 916 if (my $err = $@) {
b67900f1
AD
917 $self->log('err', $err);
918 $self->{errors} = 1;
919 }
920 }
921
fd8469f7 922 eval {
fd8469f7
AD
923 my $timer = 0;
924 if (PVE::QemuServer::vga_conf_has_spice($conf->{vga}) && $self->{running}) {
925 $self->log('info', "Waiting for spice server migration");
926 while (1) {
927 my $res = PVE::QemuServer::vm_mon_cmd_nocheck($vmid, 'query-spice');
928 last if int($res->{'migrated'}) == 1;
929 last if $timer > 50;
930 $timer ++;
931 usleep(200000);
932 }
933 }
934 };
95a4b4a9 935
16e903f2
DM
936 # always stop local VM
937 eval { PVE::QemuServer::vm_stop($self->{storecfg}, $vmid, 1, 1); };
938 if (my $err = $@) {
939 $self->log('err', "stopping vm failed - $err");
940 $self->{errors} = 1;
941 }
942
943 # always deactivate volumes - avoid lvm LVs to be active on several nodes
944 eval {
945 my $vollist = PVE::QemuServer::get_vm_volumes($conf);
946 PVE::Storage::deactivate_volumes($self->{storecfg}, $vollist);
947 };
948 if (my $err = $@) {
949 $self->log('err', $err);
950 $self->{errors} = 1;
951 }
952
b74cad8a
AD
953 if($self->{storage_migration}) {
954 # destroy local copies
955 my $volids = $self->{online_local_volumes};
956
957 foreach my $volid (@$volids) {
958 eval { PVE::Storage::vdisk_free($self->{storecfg}, $volid); };
959 if (my $err = $@) {
960 $self->log('err', "removing local copy of '$volid' failed - $err");
961 $self->{errors} = 1;
962 last if $err =~ /^interrupted by signal$/;
963 }
964 }
965
b74cad8a
AD
966 }
967
16e903f2
DM
968 # clear migrate lock
969 my $cmd = [ @{$self->{rem_ssh}}, 'qm', 'unlock', $vmid ];
970 $self->cmd_logerr($cmd, errmsg => "failed to clear migrate lock");
971}
972
973sub final_cleanup {
974 my ($self, $vmid) = @_;
975
976 # nothing to do
977}
978
9791;