]>
git.proxmox.com Git - qemu-server.git/blob - PVE/QemuMigrate.pm
1 package PVE
::QemuMigrate
;
5 use PVE
::AbstractMigrate
;
8 use POSIX
qw( WNOHANG );
14 use Time
::HiRes
qw( usleep );
15 use PVE
::RPCEnvironment
;
17 use base
qw(PVE::AbstractMigrate);
19 sub fork_command_pipe
{
20 my ($self, $cmd) = @_;
22 my $reader = IO
::File-
>new();
23 my $writer = IO
::File-
>new();
29 eval { $cpid = open2
($reader, $writer, @$cmd); };
34 if ($orig_pid != $$) {
35 $self->log('err', "can't fork command pipe\n");
42 return { writer
=> $writer, reader
=> $reader, pid
=> $cpid };
45 sub finish_command_pipe
{
46 my ($self, $cmdpipe, $timeout) = @_;
48 my $cpid = $cmdpipe->{pid
};
49 return if !defined($cpid);
51 my $writer = $cmdpipe->{writer
};
52 my $reader = $cmdpipe->{reader
};
57 my $collect_child_process = sub {
58 my $res = waitpid($cpid, WNOHANG
);
59 if (defined($res) && ($res == $cpid)) {
60 delete $cmdpipe->{cpid
};
68 for (my $i = 0; $i < $timeout; $i++) {
69 return if &$collect_child_process();
74 $self->log('info', "ssh tunnel still running - terminating now with SIGTERM\n");
78 for (my $i = 0; $i < 10; $i++) {
79 return if &$collect_child_process();
83 $self->log('info', "ssh tunnel still running - terminating now with SIGKILL\n");
87 $self->log('err', "ssh tunnel child process (PID $cpid) couldn't be collected\n")
88 if !&$collect_child_process();
92 my ($self, $tunnel_addr) = @_;
94 my @localtunnelinfo = defined($tunnel_addr) ?
('-L' , $tunnel_addr ) : ();
96 my $cmd = [@{$self->{rem_ssh
}}, '-o ExitOnForwardFailure=yes', @localtunnelinfo, 'qm', 'mtunnel' ];
98 my $tunnel = $self->fork_command_pipe($cmd);
100 my $reader = $tunnel->{reader
};
104 PVE
::Tools
::run_with_timeout
(60, sub { $helo = <$reader>; });
105 die "no reply\n" if !$helo;
106 die "no quorum on target node\n" if $helo =~ m/^no quorum$/;
107 die "got strange reply from mtunnel ('$helo')\n"
108 if $helo !~ m/^tunnel online$/;
113 $self->finish_command_pipe($tunnel);
114 die "can't open migration tunnel - $err";
120 my ($self, $tunnel) = @_;
122 my $writer = $tunnel->{writer
};
125 PVE
::Tools
::run_with_timeout
(30, sub {
126 print $writer "quit\n";
132 $self->finish_command_pipe($tunnel, 30);
134 if ($tunnel->{sock_addr
}) {
135 # ssh does not clean up on local host
136 my $cmd = ['rm', '-f', $tunnel->{sock_addr
}]; #
137 PVE
::Tools
::run_command
($cmd);
139 # .. and just to be sure check on remote side
140 unshift @{$cmd}, @{$self->{rem_ssh
}};
141 PVE
::Tools
::run_command
($cmd);
148 my ($self, $vmid, $code, @param) = @_;
150 return PVE
::QemuConfig-
>lock_config($vmid, $code, @param);
154 my ($self, $vmid) = @_;
156 my $online = $self->{opts
}->{online
};
158 $self->{storecfg
} = PVE
::Storage
::config
();
161 my $conf = $self->{vmconf
} = PVE
::QemuConfig-
>load_config($vmid);
163 PVE
::QemuConfig-
>check_lock($conf);
166 if (my $pid = PVE
::QemuServer
::check_running
($vmid)) {
167 die "can't migrate running VM without --online\n" if !$online;
170 $self->{forcemachine
} = PVE
::QemuServer
::qemu_machine_pxe
($vmid, $conf);
174 if (my $loc_res = PVE
::QemuServer
::check_local_resources
($conf, 1)) {
175 if ($self->{running
} || !$self->{opts
}->{force
}) {
176 die "can't migrate VM which uses local devices\n";
178 $self->log('info', "migrating VM which uses local devices");
182 my $vollist = PVE
::QemuServer
::get_vm_volumes
($conf);
184 my $need_activate = [];
185 foreach my $volid (@$vollist) {
186 my ($sid, $volname) = PVE
::Storage
::parse_volume_id
($volid, 1);
188 # check if storage is available on both nodes
189 my $scfg = PVE
::Storage
::storage_check_node
($self->{storecfg
}, $sid);
190 PVE
::Storage
::storage_check_node
($self->{storecfg
}, $sid, $self->{node
});
192 if ($scfg->{shared
}) {
193 # PVE::Storage::activate_storage checks this for non-shared storages
194 my $plugin = PVE
::Storage
::Plugin-
>lookup($scfg->{type
});
195 warn "Used shared storage '$sid' is not online on source node!\n"
196 if !$plugin->check_connection($sid, $scfg);
198 # only activate if not shared
199 push @$need_activate, $volid;
204 PVE
::Storage
::activate_volumes
($self->{storecfg
}, $need_activate);
206 # test ssh connection
207 my $cmd = [ @{$self->{rem_ssh
}}, '/bin/true' ];
208 eval { $self->cmd_quiet($cmd); };
209 die "Can't connect to destination address using public key\n" if $@;
215 my ($self, $vmid) = @_;
217 $self->log('info', "copying disk images");
219 my $conf = $self->{vmconf
};
221 # local volumes which have been copied
222 $self->{volumes
} = [];
228 # found local volumes and their origin
229 my $local_volumes = {};
233 my @sids = PVE
::Storage
::storage_ids
($self->{storecfg
});
234 foreach my $storeid (@sids) {
235 my $scfg = PVE
::Storage
::storage_config
($self->{storecfg
}, $storeid);
236 next if $scfg->{shared
};
237 next if !PVE
::Storage
::storage_check_enabled
($self->{storecfg
}, $storeid, undef, 1);
239 # get list from PVE::Storage (for unused volumes)
240 my $dl = PVE
::Storage
::vdisk_list
($self->{storecfg
}, $storeid, $vmid);
242 next if @{$dl->{$storeid}} == 0;
244 # check if storage is available on target node
245 PVE
::Storage
::storage_check_node
($self->{storecfg
}, $storeid, $self->{node
});
246 $sharedvm = 0; # there is a non-shared disk
248 PVE
::Storage
::foreach_volid
($dl, sub {
249 my ($volid, $sid, $volname) = @_;
251 $local_volumes->{$volid} = 'storage';
255 my $test_volid = sub {
256 my ($volid, $is_cdrom, $snapname) = @_;
260 die "can't migrate local file/device '$volid'\n" if $volid =~ m
|^/|;
263 die "can't migrate local cdrom drive\n" if $volid eq 'cdrom';
264 return if $volid eq 'none';
267 my ($sid, $volname) = PVE
::Storage
::parse_volume_id
($volid);
269 # check if storage is available on both nodes
270 my $scfg = PVE
::Storage
::storage_check_node
($self->{storecfg
}, $sid);
271 PVE
::Storage
::storage_check_node
($self->{storecfg
}, $sid, $self->{node
});
273 return if $scfg->{shared
};
277 $local_volumes->{$volid} = defined($snapname) ?
'snapshot' : 'config';
279 die "can't migrate local cdrom '$volid'\n" if $is_cdrom;
281 my ($path, $owner) = PVE
::Storage
::path
($self->{storecfg
}, $volid);
283 die "can't migrate volume '$volid' - owned by other VM (owner = VM $owner)\n"
284 if !$owner || ($owner != $self->{vmid
});
286 if (defined($snapname)) {
287 # we cannot migrate shapshots on local storage
288 # exceptions: 'zfspool' or 'qcow2' files (on directory storage)
290 my $format = PVE
::QemuServer
::qemu_img_format
($scfg, $volname);
292 if (($scfg->{type
} eq 'zfspool') || ($format eq 'qcow2')) {
296 die "can't migrate snapshot of local volume '$volid'\n";
301 my $test_drive = sub {
302 my ($ds, $drive, $snapname) = @_;
304 &$test_volid($drive->{file
}, PVE
::QemuServer
::drive_is_cdrom
($drive), $snapname);
307 foreach my $snapname (keys %{$conf->{snapshots
}}) {
308 &$test_volid($conf->{snapshots
}->{$snapname}->{'vmstate'}, 0, undef)
309 if defined($conf->{snapshots
}->{$snapname}->{'vmstate'});
310 PVE
::QemuServer
::foreach_drive
($conf->{snapshots
}->{$snapname}, $test_drive, $snapname);
312 PVE
::QemuServer
::foreach_drive
($conf, $test_drive);
314 foreach my $vol (sort keys %$local_volumes) {
315 if ($local_volumes->{$vol} eq 'storage') {
316 $self->log('info', "found local disk '$vol' (via storage)\n");
317 } elsif ($local_volumes->{$vol} eq 'config') {
318 $self->log('info', "found local disk '$vol' (in current VM config)\n");
319 } elsif ($local_volumes->{$vol} eq 'snapshot') {
320 $self->log('info', "found local disk '$vol' (referenced by snapshot(s))\n");
322 $self->log('info', "found local disk '$vol'\n");
326 if ($self->{running
} && !$sharedvm) {
327 die "can't do online migration - VM uses local disks\n";
330 # additional checks for local storage
331 foreach my $volid (keys %$local_volumes) {
332 my ($sid, $volname) = PVE
::Storage
::parse_volume_id
($volid);
333 my $scfg = PVE
::Storage
::storage_config
($self->{storecfg
}, $sid);
335 my $migratable = ($scfg->{type
} eq 'dir') || ($scfg->{type
} eq 'zfspool') ||
336 ($scfg->{type
} eq 'lvmthin') || ($scfg->{type
} eq 'lvm');
338 die "can't migrate '$volid' - storage type '$scfg->{type}' not supported\n"
341 # image is a linked clone on local storage, se we can't migrate.
342 if (my $basename = (PVE
::Storage
::parse_volname
($self->{storecfg
}, $volid))[3]) {
343 die "can't migrate '$volid' as it's a clone of '$basename'";
347 foreach my $volid (keys %$local_volumes) {
348 my ($sid, $volname) = PVE
::Storage
::parse_volume_id
($volid);
349 push @{$self->{volumes
}}, $volid;
350 PVE
::Storage
::storage_migrate
($self->{storecfg
}, $volid, $self->{nodeip
}, $sid);
353 die "Failed to sync data - $@" if $@;
357 my ($self, $vmid) = @_;
359 $self->log('info', "starting migration of VM $vmid to node '$self->{node}' ($self->{nodeip})");
361 my $conf = $self->{vmconf
};
363 # set migrate lock in config file
364 $conf->{lock} = 'migrate';
365 PVE
::QemuConfig-
>write_config($vmid, $conf);
367 sync_disks
($self, $vmid);
372 my ($self, $vmid, $err) = @_;
374 $self->log('info', "aborting phase 1 - cleanup resources");
376 my $conf = $self->{vmconf
};
377 delete $conf->{lock};
378 eval { PVE
::QemuConfig-
>write_config($vmid, $conf) };
380 $self->log('err', $err);
383 if ($self->{volumes
}) {
384 foreach my $volid (@{$self->{volumes
}}) {
385 $self->log('err', "found stale volume copy '$volid' on node '$self->{node}'");
386 # fixme: try to remove ?
392 my ($self, $vmid) = @_;
394 my $conf = $self->{vmconf
};
396 $self->log('info', "starting VM $vmid on remote node '$self->{node}'");
400 my $ruri; # the whole migration dst. URI (protocol:address[:port])
401 my $nodename = PVE
::INotify
::nodename
();
403 ## start on remote node
404 my $cmd = [@{$self->{rem_ssh
}}];
407 if (PVE
::QemuServer
::vga_conf_has_spice
($conf->{vga
})) {
408 my $res = PVE
::QemuServer
::vm_mon_cmd
($vmid, 'query-spice');
409 $spice_ticket = $res->{ticket
};
412 push @$cmd , 'qm', 'start', $vmid, '--skiplock', '--migratedfrom', $nodename;
414 # we use TCP only for unsecure migrations as TCP ssh forward tunnels often
415 # did appeared to late (they are hard, if not impossible, to check for)
416 # secure migration use UNIX sockets now, this *breaks* compatibilty when trying
417 # to migrate from new to old but *not* from old to new.
418 my $datacenterconf = PVE
::Cluster
::cfs_read_file
('datacenter.cfg');
419 my $secure_migration = ($datacenterconf->{migration_unsecure
}) ?
0 : 1;
421 if (!$secure_migration) {
422 push @$cmd, '--stateuri', 'tcp';
424 push @$cmd, '--stateuri', 'unix';
427 if ($self->{forcemachine
}) {
428 push @$cmd, '--machine', $self->{forcemachine
};
433 # Note: We try to keep $spice_ticket secret (do not pass via command line parameter)
434 # instead we pipe it through STDIN
435 PVE
::Tools
::run_command
($cmd, input
=> $spice_ticket, outfunc
=> sub {
438 if ($line =~ m/^migration listens on tcp:(localhost|[\d\.]+|\[[\d\.:a-fA-F]+\]):(\d+)$/) {
441 $ruri = "tcp:$raddr:$rport";
443 elsif ($line =~ m!^migration listens on unix:(/run/qemu-server/(\d+)\.migrate)$!) {
445 die "Destination UNIX sockets VMID does not match source VMID" if $vmid ne $2;
446 $ruri = "unix:$raddr";
448 elsif ($line =~ m/^migration listens on port (\d+)$/) {
449 $raddr = "localhost";
451 $ruri = "tcp:$raddr:$rport";
453 elsif ($line =~ m/^spice listens on port (\d+)$/) {
454 $spice_port = int($1);
458 $self->log('info', $line);
461 die "unable to detect remote migration address\n" if !$raddr;
463 if ($secure_migration) {
464 $self->log('info', "start remote tunnel");
466 if ($ruri =~ /^unix:/) {
468 $self->{tunnel
} = $self->fork_tunnel("$raddr:$raddr");
469 $self->{tunnel
}->{sock_addr
} = $raddr;
471 my $unix_socket_try = 0; # wait for the socket to become ready
472 while (! -S
$raddr) {
474 if ($unix_socket_try > 100) {
476 $self->finish_tunnel($self->{tunnel
});
477 die "Timeout, migration socket $ruri did not get ready";
483 } elsif ($ruri =~ /^tcp:/) {
485 if ($raddr eq "localhost") {
486 # for backwards compatibility with older qemu-server versions
487 my $pfamily = PVE
::Tools
::get_host_address_family
($nodename);
488 my $lport = PVE
::Tools
::next_migrate_port
($pfamily);
489 $tunnel_addr = "$lport:localhost:$rport";
492 $self->{tunnel
} = $self->fork_tunnel($tunnel_addr);
495 die "unsupported protocol in migration URI: $ruri\n";
500 $self->log('info', "starting online/live migration on $ruri");
501 $self->{livemigration
} = 1;
504 my $defaults = PVE
::QemuServer
::load_defaults
();
506 # always set migrate speed (overwrite kvm default of 32m)
507 # we set a very hight default of 8192m which is basically unlimited
508 my $migrate_speed = $defaults->{migrate_speed
} || 8192;
509 $migrate_speed = $conf->{migrate_speed
} || $migrate_speed;
510 $migrate_speed = $migrate_speed * 1048576;
511 $self->log('info', "migrate_set_speed: $migrate_speed");
513 PVE
::QemuServer
::vm_mon_cmd_nocheck
($vmid, "migrate_set_speed", value
=> int($migrate_speed));
515 $self->log('info', "migrate_set_speed error: $@") if $@;
517 my $migrate_downtime = $defaults->{migrate_downtime
};
518 $migrate_downtime = $conf->{migrate_downtime
} if defined($conf->{migrate_downtime
});
519 if (defined($migrate_downtime)) {
520 $self->log('info', "migrate_set_downtime: $migrate_downtime");
522 PVE
::QemuServer
::vm_mon_cmd_nocheck
($vmid, "migrate_set_downtime", value
=> int($migrate_downtime*100)/100);
524 $self->log('info', "migrate_set_downtime error: $@") if $@;
527 $self->log('info', "set migration_caps");
529 PVE
::QemuServer
::set_migration_caps
($vmid);
533 #set cachesize 10% of the total memory
534 my $cachesize = int($conf->{memory
}*1048576/10);
535 $self->log('info', "set cachesize: $cachesize");
537 PVE
::QemuServer
::vm_mon_cmd_nocheck
($vmid, "migrate-set-cache-size", value
=> int($cachesize));
539 $self->log('info', "migrate-set-cache-size error: $@") if $@;
541 if (PVE
::QemuServer
::vga_conf_has_spice
($conf->{vga
})) {
542 my $rpcenv = PVE
::RPCEnvironment
::get
();
543 my $authuser = $rpcenv->get_user();
545 my (undef, $proxyticket) = PVE
::AccessControl
::assemble_spice_ticket
($authuser, $vmid, $self->{node
});
547 my $filename = "/etc/pve/nodes/$self->{node}/pve-ssl.pem";
548 my $subject = PVE
::AccessControl
::read_x509_subject_spice
($filename);
550 $self->log('info', "spice client_migrate_info");
553 PVE
::QemuServer
::vm_mon_cmd_nocheck
($vmid, "client_migrate_info", protocol
=> 'spice',
554 hostname
=> $proxyticket, 'tls-port' => $spice_port,
555 'cert-subject' => $subject);
557 $self->log('info', "client_migrate_info error: $@") if $@;
561 $self->log('info', "start migrate command to $ruri");
563 PVE
::QemuServer
::vm_mon_cmd_nocheck
($vmid, "migrate", uri
=> $ruri);
566 $self->log('info', "migrate uri => $ruri failed: $merr") if $merr;
569 my $usleep = 2000000;
573 my $downtimecounter = 0;
576 my $avglstat = $lstat/$i if $lstat;
581 $stat = PVE
::QemuServer
::vm_mon_cmd_nocheck
($vmid, "query-migrate");
585 warn "query migrate failed: $err\n";
586 $self->log('info', "query migrate failed: $err");
587 if ($err_count <= 5) {
591 die "too many query migrate failures - aborting\n";
594 if (defined($stat->{status
}) && $stat->{status
} =~ m/^(setup)$/im) {
599 if (defined($stat->{status
}) && $stat->{status
} =~ m/^(active|completed|failed|cancelled)$/im) {
602 if ($stat->{status
} eq 'completed') {
603 my $delay = time() - $start;
605 my $mbps = sprintf "%.2f", $conf->{memory
}/$delay;
606 my $downtime = $stat->{downtime
} || 0;
607 $self->log('info', "migration speed: $mbps MB/s - downtime $downtime ms");
611 if ($stat->{status
} eq 'failed' || $stat->{status
} eq 'cancelled') {
612 $self->log('info', "migration status error: $stat->{status}");
616 if ($stat->{status
} ne 'active') {
617 $self->log('info', "migration status: $stat->{status}");
621 if ($stat->{ram
}->{transferred
} ne $lstat) {
622 my $trans = $stat->{ram
}->{transferred
} || 0;
623 my $rem = $stat->{ram
}->{remaining
} || 0;
624 my $total = $stat->{ram
}->{total
} || 0;
625 my $xbzrlecachesize = $stat->{"xbzrle-cache"}->{"cache-size"} || 0;
626 my $xbzrlebytes = $stat->{"xbzrle-cache"}->{"bytes"} || 0;
627 my $xbzrlepages = $stat->{"xbzrle-cache"}->{"pages"} || 0;
628 my $xbzrlecachemiss = $stat->{"xbzrle-cache"}->{"cache-miss"} || 0;
629 my $xbzrleoverflow = $stat->{"xbzrle-cache"}->{"overflow"} || 0;
630 #reduce sleep if remainig memory if lower than the everage transfert
631 $usleep = 300000 if $avglstat && $rem < $avglstat;
633 $self->log('info', "migration status: $stat->{status} (transferred ${trans}, " .
634 "remaining ${rem}), total ${total})");
636 if (${xbzrlecachesize
}) {
637 $self->log('info', "migration xbzrle cachesize: ${xbzrlecachesize} transferred ${xbzrlebytes} pages ${xbzrlepages} cachemiss ${xbzrlecachemiss} overflow ${xbzrleoverflow}");
640 if (($lastrem && $rem > $lastrem ) || ($rem == 0)) {
645 if ($downtimecounter > 5) {
646 $downtimecounter = 0;
647 $migrate_downtime *= 2;
648 $self->log('info', "migrate_set_downtime: $migrate_downtime");
650 PVE
::QemuServer
::vm_mon_cmd_nocheck
($vmid, "migrate_set_downtime", value
=> int($migrate_downtime*100)/100);
652 $self->log('info', "migrate_set_downtime error: $@") if $@;
658 $lstat = $stat->{ram
}->{transferred
};
662 die "unable to parse migration status '$stat->{status}' - aborting\n";
666 # just to be sure that the tunnel gets closed on successful migration, on error
667 # phase2_cleanup closes it *after* stopping the remote waiting VM
668 if (!$self->{errors
} && $self->{tunnel
}) {
669 eval { finish_tunnel
($self, $self->{tunnel
}); };
671 $self->log('err', $err);
678 my ($self, $vmid, $err) = @_;
680 return if !$self->{errors
};
681 $self->{phase2errors
} = 1;
683 $self->log('info', "aborting phase 2 - cleanup resources");
685 $self->log('info', "migrate_cancel");
687 PVE
::QemuServer
::vm_mon_cmd_nocheck
($vmid, "migrate_cancel");
689 $self->log('info', "migrate_cancel error: $@") if $@;
691 my $conf = $self->{vmconf
};
692 delete $conf->{lock};
693 eval { PVE
::QemuConfig-
>write_config($vmid, $conf) };
695 $self->log('err', $err);
698 # cleanup ressources on target host
699 my $nodename = PVE
::INotify
::nodename
();
701 my $cmd = [@{$self->{rem_ssh
}}, 'qm', 'stop', $vmid, '--skiplock', '--migratedfrom', $nodename];
702 eval{ PVE
::Tools
::run_command
($cmd, outfunc
=> sub {}, errfunc
=> sub {}) };
704 $self->log('err', $err);
708 if ($self->{tunnel
}) {
709 eval { finish_tunnel
($self, $self->{tunnel
}); };
711 $self->log('err', $err);
718 my ($self, $vmid) = @_;
720 my $volids = $self->{volumes
};
721 return if $self->{phase2errors
};
723 # destroy local copies
724 foreach my $volid (@$volids) {
725 eval { PVE
::Storage
::vdisk_free
($self->{storecfg
}, $volid); };
727 $self->log('err', "removing local copy of '$volid' failed - $err");
729 last if $err =~ /^interrupted by signal$/;
735 my ($self, $vmid, $err) = @_;
737 my $conf = $self->{vmconf
};
738 return if $self->{phase2errors
};
740 # move config to remote node
741 my $conffile = PVE
::QemuConfig-
>config_file($vmid);
742 my $newconffile = PVE
::QemuConfig-
>config_file($vmid, $self->{node
});
744 die "Failed to move config to node '$self->{node}' - rename failed: $!\n"
745 if !rename($conffile, $newconffile);
747 if ($self->{livemigration
}) {
748 # now that config file is move, we can resume vm on target if livemigrate
749 my $cmd = [@{$self->{rem_ssh
}}, 'qm', 'resume', $vmid, '--skiplock', '--nocheck'];
750 eval{ PVE
::Tools
::run_command
($cmd, outfunc
=> sub {},
753 $self->log('err', $line);
757 $self->log('err', $err);
765 if (PVE
::QemuServer
::vga_conf_has_spice
($conf->{vga
}) && $self->{running
}) {
766 $self->log('info', "Waiting for spice server migration");
768 my $res = PVE
::QemuServer
::vm_mon_cmd_nocheck
($vmid, 'query-spice');
769 last if int($res->{'migrated'}) == 1;
777 # always stop local VM
778 eval { PVE
::QemuServer
::vm_stop
($self->{storecfg
}, $vmid, 1, 1); };
780 $self->log('err', "stopping vm failed - $err");
784 # always deactivate volumes - avoid lvm LVs to be active on several nodes
786 my $vollist = PVE
::QemuServer
::get_vm_volumes
($conf);
787 PVE
::Storage
::deactivate_volumes
($self->{storecfg
}, $vollist);
790 $self->log('err', $err);
795 my $cmd = [ @{$self->{rem_ssh
}}, 'qm', 'unlock', $vmid ];
796 $self->cmd_logerr($cmd, errmsg
=> "failed to clear migrate lock");
800 my ($self, $vmid) = @_;