1 package PVE
::HA
::Manager
;
5 use Digest
::MD5
qw(md5_base64);
8 use PVE
::HA
::Tools
':exit_codes';
9 use PVE
::HA
::NodeStatus
;
12 my ($this, $haenv) = @_;
14 my $class = ref($this) || $this;
16 my $self = bless { haenv
=> $haenv }, $class;
18 my $old_ms = $haenv->read_manager_status();
20 # we only copy the state part of the manager which cannot be auto generated
22 $self->{ns
} = PVE
::HA
::NodeStatus-
>new($haenv, $old_ms->{node_status
} || {});
24 # fixme: use separate class PVE::HA::ServiceStatus
25 $self->{ss
} = $old_ms->{service_status
} || {};
27 $self->{ms
} = { master_node
=> $haenv->nodename() };
38 sub flush_master_status
{
41 my ($haenv, $ms, $ns, $ss) = ($self->{haenv
}, $self->{ms
}, $self->{ns
}, $self->{ss
});
43 $ms->{node_status
} = $ns->{status
};
44 $ms->{service_status
} = $ss;
45 $ms->{timestamp
} = $haenv->get_time();
47 $haenv->write_manager_status($ms);
50 sub get_service_group
{
51 my ($groups, $online_node_usage, $service_conf) = @_;
54 # add all online nodes to default group to allow try_next when no group set
55 foreach my $node (keys %$online_node_usage) {
56 $group->{nodes
}->{$node} = 1;
59 # overwrite default if service is bound to a specific group
60 if (my $group_id = $service_conf->{group
}) {
61 $group = $groups->{ids
}->{$group_id} if $groups->{ids
}->{$group_id};
67 # groups available nodes with their priority as group index
68 sub get_node_priority_groups
{
69 my ($group, $online_node_usage) = @_;
72 my $group_members = {};
73 foreach my $entry (keys %{$group->{nodes
}}) {
74 my ($node, $pri) = ($entry, 0);
75 if ($entry =~ m/^(\S+):(\d+)$/) {
76 ($node, $pri) = ($1, $2);
78 next if !defined($online_node_usage->{$node}); # offline
79 $pri_groups->{$pri}->{$node} = 1;
80 $group_members->{$node} = $pri;
83 # add non-group members to unrestricted groups (priority -1)
84 if (!$group->{restricted
}) {
86 foreach my $node (keys %$online_node_usage) {
87 next if defined($group_members->{$node});
88 $pri_groups->{$pri}->{$node} = 1;
89 $group_members->{$node} = -1;
93 return ($pri_groups, $group_members);
96 sub select_service_node
{
97 my ($groups, $online_node_usage, $service_conf, $current_node, $try_next, $tried_nodes, $maintenance_fallback) = @_;
99 my $group = get_service_group
($groups, $online_node_usage, $service_conf);
101 my ($pri_groups, $group_members) = get_node_priority_groups
($group, $online_node_usage);
103 my @pri_list = sort {$b <=> $a} keys %$pri_groups;
104 return undef if !scalar(@pri_list);
106 # stay on current node if possible (avoids random migrations)
107 if (!$try_next && $group->{nofailback
} && defined($group_members->{$current_node})) {
108 return $current_node;
111 # select node from top priority node list
113 my $top_pri = $pri_list[0];
115 # try to avoid nodes where the service failed already if we want to relocate
117 foreach my $node (@$tried_nodes) {
118 delete $pri_groups->{$top_pri}->{$node};
123 $online_node_usage->{$a} <=> $online_node_usage->{$b} || $a cmp $b
124 } keys %{$pri_groups->{$top_pri}};
127 my $found_maintenance_fallback;
128 for (my $i = scalar(@nodes) - 1; $i >= 0; $i--) {
129 my $node = $nodes[$i];
130 if ($node eq $current_node) {
133 if (defined($maintenance_fallback) && $node eq $maintenance_fallback) {
134 $found_maintenance_fallback = $i;
138 if (defined($found_maintenance_fallback)) {
139 return $nodes[$found_maintenance_fallback];
143 if (defined($found) && ($found < (scalar(@nodes) - 1))) {
144 return $nodes[$found + 1];
148 } elsif (defined($found)) {
149 return $nodes[$found];
157 sub compute_new_uuid
{
161 return md5_base64
($state . $$ . time() . $uid_counter);
164 my $valid_service_states = {
176 sub recompute_online_node_usage
{
179 my $online_node_usage = {};
181 my $online_nodes = $self->{ns
}->list_online_nodes();
183 foreach my $node (@$online_nodes) {
184 $online_node_usage->{$node} = 0;
187 foreach my $sid (keys %{$self->{ss
}}) {
188 my $sd = $self->{ss
}->{$sid};
189 my $state = $sd->{state};
190 if (defined($online_node_usage->{$sd->{node
}})) {
192 $state eq 'started' || $state eq 'request_stop' || $state eq 'fence' ||
193 $state eq 'freeze' || $state eq 'error' || $state eq 'recovery'
195 $online_node_usage->{$sd->{node
}}++;
196 } elsif (($state eq 'migrate') || ($state eq 'relocate')) {
197 # count it for both, source and target as load is put on both
198 $online_node_usage->{$sd->{node
}}++;
199 $online_node_usage->{$sd->{target
}}++;
200 } elsif ($state eq 'stopped') {
203 die "should not be reached (sid = '$sid', state = '$state')";
205 } elsif (defined(my $target = $sd->{target
})) {
206 if ($state eq 'migrate' || $state eq 'relocate') {
207 # to correctly track maintenance modi and also consider the target as used for the
208 # case a node dies, as we cannot really know if the to-be-aborted incoming migration
209 # has already cleaned up all used resources
210 $online_node_usage->{$target}++;
215 $self->{online_node_usage
} = $online_node_usage;
218 my $change_service_state = sub {
219 my ($self, $sid, $new_state, %params) = @_;
221 my ($haenv, $ss) = ($self->{haenv
}, $self->{ss
});
223 my $sd = $ss->{$sid} || die "no such service '$sid";
225 my $old_state = $sd->{state};
226 my $old_node = $sd->{node
};
227 my $old_failed_nodes = $sd->{failed_nodes
};
228 my $old_maintenance_node = $sd->{maintenance_node
};
230 die "no state change" if $old_state eq $new_state; # just to be sure
232 die "invalid CRM service state '$new_state'\n" if !$valid_service_states->{$new_state};
234 foreach my $k (keys %$sd) { delete $sd->{$k}; };
236 $sd->{state} = $new_state;
237 $sd->{node
} = $old_node;
238 $sd->{failed_nodes
} = $old_failed_nodes if defined($old_failed_nodes);
239 $sd->{maintenance_node
} = $old_maintenance_node if defined($old_maintenance_node);
242 foreach my $k (sort keys %params) {
244 $text_state .= ", " if $text_state;
245 $text_state .= "$k = $v";
249 $self->recompute_online_node_usage();
251 $sd->{uid
} = compute_new_uuid
($new_state);
253 $text_state = " ($text_state)" if $text_state;
254 $haenv->log('info', "service '$sid': state changed from '${old_state}'" .
255 " to '${new_state}'$text_state");
258 # clean up a possible bad state from a recovered service to allow its start
259 my $fence_recovery_cleanup = sub {
260 my ($self, $sid, $fenced_node) = @_;
262 my $haenv = $self->{haenv
};
264 my (undef, $type, $id) = $haenv->parse_sid($sid);
265 my $plugin = PVE
::HA
::Resources-
>lookup($type);
268 die "unknown resource type '$type'" if !$plugin;
270 # locks may block recovery, cleanup those which are safe to remove after fencing,
271 # i.e., after the original node was reset and thus all it's state
272 my $removable_locks = [
283 if (my $removed_lock = $plugin->remove_locks($haenv, $id, $removable_locks, $fenced_node)) {
284 $haenv->log('warning', "removed leftover lock '$removed_lock' from recovered " .
285 "service '$sid' to allow its start.");
289 # read LRM status for all nodes
290 sub read_lrm_status
{
293 my $nodes = $self->{ns
}->list_nodes();
294 my $haenv = $self->{haenv
};
298 foreach my $node (@$nodes) {
299 my $lrm_status = $haenv->read_lrm_status($node);
300 $modes->{$node} = $lrm_status->{mode
} || 'active';
301 foreach my $uid (keys %{$lrm_status->{results
}}) {
302 next if $results->{$uid}; # should not happen
303 $results->{$uid} = $lrm_status->{results
}->{$uid};
307 return ($results, $modes);
310 # read new crm commands and save them into crm master status
311 sub update_crm_commands
{
314 my ($haenv, $ms, $ns, $ss) = ($self->{haenv
}, $self->{ms
}, $self->{ns
}, $self->{ss
});
316 my $cmdlist = $haenv->read_crm_commands();
318 foreach my $cmd (split(/\n/, $cmdlist)) {
321 if ($cmd =~ m/^(migrate|relocate)\s+(\S+)\s+(\S+)$/) {
322 my ($task, $sid, $node) = ($1, $2, $3);
323 if (my $sd = $ss->{$sid}) {
324 if (!$ns->node_is_online($node)) {
325 $haenv->log('err', "crm command error - node not online: $cmd");
327 if ($node eq $sd->{node
}) {
328 $haenv->log('info', "ignore crm command - service already on target node: $cmd");
330 $haenv->log('info', "got crm command: $cmd");
331 $ss->{$sid}->{cmd
} = [ $task, $node ];
335 $haenv->log('err', "crm command error - no such service: $cmd");
338 } elsif ($cmd =~ m/^stop\s+(\S+)\s+(\S+)$/) {
339 my ($sid, $timeout) = ($1, $2);
340 if (my $sd = $ss->{$sid}) {
341 $haenv->log('info', "got crm command: $cmd");
342 $ss->{$sid}->{cmd
} = [ 'stop', $timeout ];
344 $haenv->log('err', "crm command error - no such service: $cmd");
347 $haenv->log('err', "unable to parse crm command: $cmd");
356 my ($haenv, $ms, $ns, $ss) = ($self->{haenv
}, $self->{ms
}, $self->{ns
}, $self->{ss
});
358 my ($node_info) = $haenv->get_node_info();
359 my ($lrm_results, $lrm_modes) = $self->read_lrm_status();
361 $ns->update($node_info, $lrm_modes);
363 if (!$ns->node_is_operational($haenv->nodename())) {
364 $haenv->log('info', "master seems offline");
368 my $sc = $haenv->read_service_config();
370 $self->{groups
} = $haenv->read_group_config(); # update
372 # compute new service status
375 foreach my $sid (sort keys %$sc) {
376 next if $ss->{$sid}; # already there
377 my $cd = $sc->{$sid};
378 next if $cd->{state} eq 'ignored';
380 $haenv->log('info', "adding new service '$sid' on node '$cd->{node}'");
381 # assume we are running to avoid relocate running service at add
382 my $state = ($cd->{state} eq 'started') ?
'started' : 'request_stop';
383 $ss->{$sid} = { state => $state, node
=> $cd->{node
},
384 uid
=> compute_new_uuid
('started') };
387 # remove stale or ignored services from manager state
388 foreach my $sid (keys %$ss) {
389 next if $sc->{$sid} && $sc->{$sid}->{state} ne 'ignored';
391 my $reason = defined($sc->{$sid}) ?
'ignored state requested' : 'no config';
392 $haenv->log('info', "removing stale service '$sid' ($reason)");
394 # remove all service related state information
398 $self->update_crm_commands();
403 $self->recompute_online_node_usage();
405 foreach my $sid (sort keys %$ss) {
406 my $sd = $ss->{$sid};
407 my $cd = $sc->{$sid} || { state => 'disabled' };
409 my $lrm_res = $sd->{uid
} ?
$lrm_results->{$sd->{uid
}} : undef;
411 my $last_state = $sd->{state};
413 if ($last_state eq 'stopped') {
415 $self->next_state_stopped($sid, $cd, $sd, $lrm_res);
417 } elsif ($last_state eq 'started') {
419 $self->next_state_started($sid, $cd, $sd, $lrm_res);
421 } elsif ($last_state eq 'migrate' || $last_state eq 'relocate') {
423 $self->next_state_migrate_relocate($sid, $cd, $sd, $lrm_res);
425 } elsif ($last_state eq 'fence') {
427 # do nothing here - wait until fenced
429 } elsif ($last_state eq 'recovery') {
431 $self->next_state_recovery($sid, $cd, $sd, $lrm_res);
433 } elsif ($last_state eq 'request_stop') {
435 $self->next_state_request_stop($sid, $cd, $sd, $lrm_res);
437 } elsif ($last_state eq 'freeze') {
439 my $lrm_mode = $sd->{node
} ?
$lrm_modes->{$sd->{node
}} : undef;
441 my $state = ($cd->{state} eq 'started') ?
'started' : 'request_stop';
442 &$change_service_state($self, $sid, $state)
443 if $lrm_mode && $lrm_mode eq 'active';
445 } elsif ($last_state eq 'error') {
447 $self->next_state_error($sid, $cd, $sd, $lrm_res);
451 die "unknown service state '$last_state'";
454 my $lrm_mode = $sd->{node
} ?
$lrm_modes->{$sd->{node
}} : undef;
455 if ($lrm_mode && $lrm_mode eq 'restart') {
456 if (($sd->{state} eq 'started' || $sd->{state} eq 'stopped' ||
457 $sd->{state} eq 'request_stop')) {
458 &$change_service_state($self, $sid, 'freeze');
462 $repeat = 1 if $sd->{state} ne $last_state;
466 my $fenced_nodes = {};
467 foreach my $sid (sort keys %$ss) {
468 my ($service_state, $service_node) = $ss->{$sid}->@{'state', 'node'};
469 next if $service_state ne 'fence';
471 if (!defined($fenced_nodes->{$service_node})) {
472 $fenced_nodes->{$service_node} = $ns->fence_node($service_node) || 0;
475 next if !$fenced_nodes->{$service_node};
477 # node fence was successful - recover service
478 $change_service_state->($self, $sid, 'recovery');
479 $repeat = 1; # for faster recovery execution
482 # Avoid that a node without services in 'fence' state (e.g., removed
483 # manually by admin) is stuck with the 'fence' node state.
484 for my $node (sort grep { !defined($fenced_nodes->{$_}) } keys $ns->{status
}->%*) {
485 next if $ns->get_node_state($node) ne 'fence';
487 $haenv->log('notice', "node '$node' in fence state but no services to-fence! admin interference?!");
488 $repeat = 1 if $ns->fence_node($node);
494 $self->flush_master_status();
497 # functions to compute next service states
498 # $cd: service configuration data (read only)
499 # $sd: service status data (read only)
501 # Note: use change_service_state() to alter state
504 sub next_state_request_stop
{
505 my ($self, $sid, $cd, $sd, $lrm_res) = @_;
507 my $haenv = $self->{haenv
};
508 my $ns = $self->{ns
};
510 # check result from LRM daemon
512 my $exit_code = $lrm_res->{exit_code
};
513 if ($exit_code == SUCCESS
) {
514 &$change_service_state($self, $sid, 'stopped');
517 $haenv->log('err', "service '$sid' stop failed (exit code $exit_code)");
518 &$change_service_state($self, $sid, 'error'); # fixme: what state?
523 if ($ns->node_is_offline_delayed($sd->{node
})) {
524 &$change_service_state($self, $sid, 'fence');
529 sub next_state_migrate_relocate
{
530 my ($self, $sid, $cd, $sd, $lrm_res) = @_;
532 my $haenv = $self->{haenv
};
533 my $ns = $self->{ns
};
535 # check result from LRM daemon
537 my $exit_code = $lrm_res->{exit_code
};
538 my $req_state = $cd->{state} eq 'started' ?
'started' : 'request_stop';
539 if ($exit_code == SUCCESS
) {
540 &$change_service_state($self, $sid, $req_state, node
=> $sd->{target
});
542 } elsif ($exit_code == EWRONG_NODE
) {
543 $haenv->log('err', "service '$sid' - migration failed: service" .
544 " registered on wrong node!");
545 &$change_service_state($self, $sid, 'error');
547 $haenv->log('err', "service '$sid' - migration failed (exit code $exit_code)");
548 &$change_service_state($self, $sid, $req_state, node
=> $sd->{node
});
553 if ($ns->node_is_offline_delayed($sd->{node
})) {
554 &$change_service_state($self, $sid, 'fence');
559 sub next_state_stopped
{
560 my ($self, $sid, $cd, $sd, $lrm_res) = @_;
562 my $haenv = $self->{haenv
};
563 my $ns = $self->{ns
};
565 if ($sd->{node
} ne $cd->{node
}) {
566 # this can happen if we fence a node with active migrations
567 # hack: modify $sd (normally this should be considered read-only)
568 $haenv->log('info', "fixup service '$sid' location ($sd->{node} => $cd->{node})");
569 $sd->{node
} = $cd->{node
};
573 my $cmd = shift @{$sd->{cmd
}};
575 if ($cmd eq 'migrate' || $cmd eq 'relocate') {
576 my $target = shift @{$sd->{cmd
}};
577 if (!$ns->node_is_online($target)) {
578 $haenv->log('err', "ignore service '$sid' $cmd request - node '$target' not online");
579 } elsif ($sd->{node
} eq $target) {
580 $haenv->log('info', "ignore service '$sid' $cmd request - service already on node '$target'");
582 &$change_service_state($self, $sid, $cmd, node
=> $sd->{node
},
586 } elsif ($cmd eq 'stop') {
587 $haenv->log('info', "ignore service '$sid' $cmd request - service already stopped");
589 $haenv->log('err', "unknown command '$cmd' for service '$sid'");
594 if ($cd->{state} eq 'disabled') {
595 # NOTE: do nothing here, the stop state is an exception as we do not
596 # process the LRM result here, thus the LRM always tries to stop the
597 # service (protection for the case no CRM is active)
601 if ($ns->node_is_offline_delayed($sd->{node
}) && $ns->get_node_state($sd->{node
}) ne 'maintenance') {
602 &$change_service_state($self, $sid, 'fence');
606 if ($cd->{state} eq 'stopped') {
607 # almost the same as 'disabled' state but the service will also get recovered
611 if ($cd->{state} eq 'started') {
612 # simply mark it started, if it's on the wrong node
613 # next_state_started will fix that for us
614 &$change_service_state($self, $sid, 'started', node
=> $sd->{node
});
618 $haenv->log('err', "service '$sid' - unknown state '$cd->{state}' in service configuration");
621 sub record_service_failed_on_node
{
622 my ($self, $sid, $node) = @_;
624 if (!defined($self->{ss
}->{$sid}->{failed_nodes
})) {
625 $self->{ss
}->{$sid}->{failed_nodes
} = [];
628 push @{$self->{ss
}->{$sid}->{failed_nodes
}}, $node;
631 sub next_state_started
{
632 my ($self, $sid, $cd, $sd, $lrm_res) = @_;
634 my $haenv = $self->{haenv
};
635 my $master_status = $self->{ms
};
636 my $ns = $self->{ns
};
638 if (!$ns->node_is_online($sd->{node
})) {
639 if ($ns->node_is_offline_delayed($sd->{node
})) {
640 &$change_service_state($self, $sid, 'fence');
642 if ($ns->get_node_state($sd->{node
}) ne 'maintenance') {
645 # save current node as fallback for when it comes out of
647 $sd->{maintenance_node
} = $sd->{node
};
651 if ($cd->{state} eq 'disabled' || $cd->{state} eq 'stopped') {
652 &$change_service_state($self, $sid, 'request_stop');
656 if ($cd->{state} eq 'started') {
659 my $cmd = shift @{$sd->{cmd
}};
661 if ($cmd eq 'migrate' || $cmd eq 'relocate') {
662 my $target = shift @{$sd->{cmd
}};
663 if (!$ns->node_is_online($target)) {
664 $haenv->log('err', "ignore service '$sid' $cmd request - node '$target' not online");
665 } elsif ($sd->{node
} eq $target) {
666 $haenv->log('info', "ignore service '$sid' $cmd request - service already on node '$target'");
668 $haenv->log('info', "$cmd service '$sid' to node '$target'");
669 &$change_service_state($self, $sid, $cmd, node
=> $sd->{node
}, target
=> $target);
671 } elsif ($cmd eq 'stop') {
672 my $timeout = shift @{$sd->{cmd
}};
674 $haenv->log('info', "request immediate service hard-stop for service '$sid'");
676 $haenv->log('info', "request graceful stop with timeout '$timeout' for service '$sid'");
678 &$change_service_state($self, $sid, 'request_stop', timeout
=> $timeout);
679 $haenv->update_service_config($sid, {'state' => 'stopped'});
681 $haenv->log('err', "unknown command '$cmd' for service '$sid'");
692 my $ec = $lrm_res->{exit_code
};
693 if ($ec == SUCCESS
) {
695 if (defined($sd->{failed_nodes
})) {
696 $haenv->log('info', "relocation policy successful for '$sid' on node '$sd->{node}'," .
697 " failed nodes: " . join(', ', @{$sd->{failed_nodes
}}) );
700 delete $sd->{failed_nodes
};
702 # store flag to indicate successful start - only valid while state == 'started'
705 } elsif ($ec == ERROR
) {
707 delete $sd->{running
};
709 # apply our relocate policy if we got ERROR from the LRM
710 $self->record_service_failed_on_node($sid, $sd->{node
});
712 if (scalar(@{$sd->{failed_nodes
}}) <= $cd->{max_relocate
}) {
714 # tell select_service_node to relocate if possible
717 $haenv->log('warning', "starting service $sid on node".
718 " '$sd->{node}' failed, relocating service.");
722 $haenv->log('err', "recovery policy for service $sid " .
723 "failed, entering error state. Failed nodes: ".
724 join(', ', @{$sd->{failed_nodes
}}));
725 &$change_service_state($self, $sid, 'error');
730 $self->record_service_failed_on_node($sid, $sd->{node
});
732 $haenv->log('err', "service '$sid' got unrecoverable error" .
733 " (exit code $ec))");
734 # we have no save way out (yet) for other errors
735 &$change_service_state($self, $sid, 'error');
740 my $node = select_service_node
(
742 $self->{online_node_usage
},
747 $sd->{maintenance_node
},
750 if ($node && ($sd->{node
} ne $node)) {
751 $self->{online_node_usage
}->{$node}++;
753 if (defined(my $fallback = $sd->{maintenance_node
})) {
754 if ($node eq $fallback) {
755 $haenv->log('info', "moving service '$sid' back to '$fallback', node came back from maintenance.");
756 delete $sd->{maintenance_node
};
757 } elsif ($sd->{node
} ne $fallback) {
758 $haenv->log('info', "dropping maintenance fallback node '$fallback' for '$sid'");
759 delete $sd->{maintenance_node
};
763 if ($cd->{type
} eq 'vm') {
764 $haenv->log('info', "migrate service '$sid' to node '$node' (running)");
765 &$change_service_state($self, $sid, 'migrate', node
=> $sd->{node
}, target
=> $node);
767 $haenv->log('info', "relocate service '$sid' to node '$node'");
768 &$change_service_state($self, $sid, 'relocate', node
=> $sd->{node
}, target
=> $node);
771 if ($try_next && !defined($node)) {
772 $haenv->log('warning', "Start Error Recovery: Tried all available " .
773 " nodes for service '$sid', retry start on current node. " .
774 "Tried nodes: " . join(', ', @{$sd->{failed_nodes
}}));
776 # ensure service get started again if it went unexpected down
777 # but ensure also no LRM result gets lost
778 $sd->{uid
} = compute_new_uuid
($sd->{state}) if defined($lrm_res);
785 $haenv->log('err', "service '$sid' - unknown state '$cd->{state}' in service configuration");
788 sub next_state_error
{
789 my ($self, $sid, $cd, $sd, $lrm_res) = @_;
791 my $ns = $self->{ns
};
792 my $ms = $self->{ms
};
794 if ($cd->{state} eq 'disabled') {
795 # clean up on error recovery
796 delete $sd->{failed_nodes
};
798 &$change_service_state($self, $sid, 'stopped');
804 # after a node was fenced this recovers the service to a new node
805 sub next_state_recovery
{
806 my ($self, $sid, $cd, $sd, $lrm_res) = @_;
808 my ($haenv, $ss) = ($self->{haenv
}, $self->{ss
});
809 my $ns = $self->{ns
};
810 my $ms = $self->{ms
};
812 if ($sd->{state} ne 'recovery') { # should not happen
813 $haenv->log('err', "cannot recover service '$sid' from fencing, wrong state '$sd->{state}'");
817 my $fenced_node = $sd->{node
}; # for logging purpose
819 $self->recompute_online_node_usage(); # we want the most current node state
821 my $recovery_node = select_service_node
(
823 $self->{online_node_usage
},
828 if ($recovery_node) {
829 my $msg = "recover service '$sid' from fenced node '$fenced_node' to node '$recovery_node'";
830 if ($recovery_node eq $fenced_node) {
831 # can happen if restriced groups and the node came up again OK
832 $msg = "recover service '$sid' to previous failed and fenced node '$fenced_node' again";
834 $haenv->log('info', "$msg");
836 $fence_recovery_cleanup->($self, $sid, $fenced_node);
838 $haenv->steal_service($sid, $sd->{node
}, $recovery_node);
839 $self->{online_node_usage
}->{$recovery_node}++;
841 # NOTE: $sd *is normally read-only*, fencing is the exception
842 $cd->{node
} = $sd->{node
} = $recovery_node;
843 my $new_state = ($cd->{state} eq 'started') ?
'started' : 'request_stop';
844 $change_service_state->($self, $sid, $new_state, node
=> $recovery_node);
846 # no possible node found, cannot recover - but retry later, as we always try to make it available
847 $haenv->log('err', "recovering service '$sid' from fenced node '$fenced_node' failed, no recovery node found");
849 if ($cd->{state} eq 'disabled') {
850 # allow getting a service out of recovery manually if an admin disables it.
851 delete $sd->{failed_nodes
}; # clean up on recovery to stopped
852 $change_service_state->($self, $sid, 'stopped'); # must NOT go through request_stop