1 package PVE
::HA
::Manager
;
5 use Digest
::MD5
qw(md5_base64);
8 use PVE
::HA
::Tools
':exit_codes';
9 use PVE
::HA
::NodeStatus
;
12 my ($this, $haenv) = @_;
14 my $class = ref($this) || $this;
16 my $self = bless { haenv
=> $haenv }, $class;
18 my $old_ms = $haenv->read_manager_status();
20 # we only copy the state part of the manager which cannot be auto generated
22 $self->{ns
} = PVE
::HA
::NodeStatus-
>new($haenv, $old_ms->{node_status
} || {});
24 # fixme: use separate class PVE::HA::ServiceStatus
25 $self->{ss
} = $old_ms->{service_status
} || {};
27 $self->{ms
} = { master_node
=> $haenv->nodename() };
38 sub flush_master_status
{
41 my ($haenv, $ms, $ns, $ss) = ($self->{haenv
}, $self->{ms
}, $self->{ns
}, $self->{ss
});
43 $ms->{node_status
} = $ns->{status
};
44 $ms->{service_status
} = $ss;
45 $ms->{timestamp
} = $haenv->get_time();
47 $haenv->write_manager_status($ms);
50 sub get_service_group
{
51 my ($groups, $online_node_usage, $service_conf) = @_;
54 # add all online nodes to default group to allow try_next when no group set
55 foreach my $node (keys %$online_node_usage) {
56 $group->{nodes
}->{$node} = 1;
59 # overwrite default if service is bound to a specific group
60 $group = $groups->{ids
}->{$service_conf->{group
}} if $service_conf->{group
} &&
61 $groups->{ids
}->{$service_conf->{group
}};
66 # groups available nodes with their priority as group index
67 sub get_node_priority_groups
{
68 my ($group, $online_node_usage) = @_;
71 my $group_members = {};
72 foreach my $entry (keys %{$group->{nodes
}}) {
73 my ($node, $pri) = ($entry, 0);
74 if ($entry =~ m/^(\S+):(\d+)$/) {
75 ($node, $pri) = ($1, $2);
77 next if !defined($online_node_usage->{$node}); # offline
78 $pri_groups->{$pri}->{$node} = 1;
79 $group_members->{$node} = $pri;
82 # add non-group members to unrestricted groups (priority -1)
83 if (!$group->{restricted
}) {
85 foreach my $node (keys %$online_node_usage) {
86 next if defined($group_members->{$node});
87 $pri_groups->{$pri}->{$node} = 1;
88 $group_members->{$node} = -1;
92 return ($pri_groups, $group_members);
95 sub select_service_node
{
96 my ($groups, $online_node_usage, $service_conf, $current_node, $try_next, $tried_nodes) = @_;
98 my $group = get_service_group
($groups, $online_node_usage, $service_conf);
100 my ($pri_groups, $group_members) = get_node_priority_groups
($group, $online_node_usage);
102 my @pri_list = sort {$b <=> $a} keys %$pri_groups;
103 return undef if !scalar(@pri_list);
105 # stay on current node if possible (avoids random migrations)
106 if (!$try_next && $group->{nofailback
} && defined($group_members->{$current_node})) {
107 return $current_node;
110 # select node from top priority node list
112 my $top_pri = $pri_list[0];
114 # try to avoid nodes where the service failed already if we want to relocate
116 foreach my $node (@$tried_nodes) {
117 delete $pri_groups->{$top_pri}->{$node};
122 $online_node_usage->{$a} <=> $online_node_usage->{$b} || $a cmp $b
123 } keys %{$pri_groups->{$top_pri}};
126 for (my $i = scalar(@nodes) - 1; $i >= 0; $i--) {
127 my $node = $nodes[$i];
128 if ($node eq $current_node) {
136 if (defined($found) && ($found < (scalar(@nodes) - 1))) {
137 return $nodes[$found + 1];
144 return $nodes[$found] if defined($found);
153 sub compute_new_uuid
{
157 return md5_base64
($state . $$ . time() . $uid_counter);
160 my $valid_service_states = {
171 sub recompute_online_node_usage
{
174 my $online_node_usage = {};
176 my $online_nodes = $self->{ns
}->list_online_nodes();
178 foreach my $node (@$online_nodes) {
179 $online_node_usage->{$node} = 0;
182 foreach my $sid (keys %{$self->{ss
}}) {
183 my $sd = $self->{ss
}->{$sid};
184 my $state = $sd->{state};
185 if (defined($online_node_usage->{$sd->{node
}})) {
186 if (($state eq 'started') || ($state eq 'request_stop') ||
187 ($state eq 'fence') || ($state eq 'freeze') || ($state eq 'error')) {
188 $online_node_usage->{$sd->{node
}}++;
189 } elsif (($state eq 'migrate') || ($state eq 'relocate')) {
190 $online_node_usage->{$sd->{target
}}++;
191 } elsif ($state eq 'stopped') {
194 die "should not be reached";
199 $self->{online_node_usage
} = $online_node_usage;
202 my $change_service_state = sub {
203 my ($self, $sid, $new_state, %params) = @_;
205 my ($haenv, $ss) = ($self->{haenv
}, $self->{ss
});
207 my $sd = $ss->{$sid} || die "no such service '$sid";
209 my $old_state = $sd->{state};
210 my $old_node = $sd->{node
};
211 my $old_failed_nodes = $sd->{failed_nodes
};
213 die "no state change" if $old_state eq $new_state; # just to be sure
215 die "invalid CRM service state '$new_state'\n" if !$valid_service_states->{$new_state};
217 foreach my $k (keys %$sd) { delete $sd->{$k}; };
219 $sd->{state} = $new_state;
220 $sd->{node
} = $old_node;
221 $sd->{failed_nodes
} = $old_failed_nodes;
224 foreach my $k (sort keys %params) {
226 $text_state .= ", " if $text_state;
227 $text_state .= "$k = $v";
231 $self->recompute_online_node_usage();
233 $sd->{uid
} = compute_new_uuid
($new_state);
235 $text_state = " ($text_state)" if $text_state;
236 $haenv->log('info', "service '$sid': state changed from '${old_state}'" .
237 " to '${new_state}'$text_state");
240 # clean up a possible bad state from a recovered service to allow its start
241 my $fence_recovery_cleanup = sub {
242 my ($self, $sid, $fenced_node) = @_;
244 my $haenv = $self->{haenv
};
246 my (undef, $type, $id) = PVE
::HA
::Tools
::parse_sid
($sid);
247 my $plugin = PVE
::HA
::Resources-
>lookup($type);
250 die "unknown resource type '$type'" if !$plugin;
252 # locks may block recovery, cleanup those which are safe to remove after fencing
253 my $removable_locks = ['backup', 'mounted'];
254 if (my $removed_lock = $plugin->remove_locks($haenv, $id, $removable_locks, $fenced_node)) {
255 $haenv->log('warning', "removed leftover lock '$removed_lock' from recovered " .
256 "service '$sid' to allow its start.");
260 # after a node was fenced this recovers the service to a new node
261 my $recover_fenced_service = sub {
262 my ($self, $sid, $cd) = @_;
264 my ($haenv, $ss) = ($self->{haenv
}, $self->{ss
});
266 my $sd = $ss->{$sid};
268 if ($sd->{state} ne 'fence') { # should not happen
269 $haenv->log('err', "cannot recover service '$sid' from fencing," .
270 " wrong state '$sd->{state}'");
274 my $fenced_node = $sd->{node
}; # for logging purpose
276 $self->recompute_online_node_usage(); # we want the most current node state
278 my $recovery_node = select_service_node
($self->{groups
},
279 $self->{online_node_usage
},
282 if ($recovery_node) {
283 $haenv->log('info', "recover service '$sid' from fenced node " .
284 "'$fenced_node' to node '$recovery_node'");
286 &$fence_recovery_cleanup($self, $sid, $fenced_node);
288 $haenv->steal_service($sid, $sd->{node
}, $recovery_node);
290 # $sd *is normally read-only*, fencing is the exception
291 $cd->{node
} = $sd->{node
} = $recovery_node;
292 my $new_state = ($cd->{state} eq 'started') ?
'started' : 'request_stop';
293 &$change_service_state($self, $sid, $new_state, node
=> $recovery_node);
295 # no possible node found, cannot recover
296 $haenv->log('err', "recovering service '$sid' from fenced node " .
297 "'$fenced_node' failed, no recovery node found");
298 &$change_service_state($self, $sid, 'error');
302 # read LRM status for all nodes
303 sub read_lrm_status
{
306 my $nodes = $self->{ns
}->list_nodes();
307 my $haenv = $self->{haenv
};
311 foreach my $node (@$nodes) {
312 my $lrm_status = $haenv->read_lrm_status($node);
313 $modes->{$node} = $lrm_status->{mode
} || 'active';
314 foreach my $uid (keys %{$lrm_status->{results
}}) {
315 next if $results->{$uid}; # should not happen
316 $results->{$uid} = $lrm_status->{results
}->{$uid};
321 return ($results, $modes);
324 # read new crm commands and save them into crm master status
325 sub update_crm_commands
{
328 my ($haenv, $ms, $ns, $ss) = ($self->{haenv
}, $self->{ms
}, $self->{ns
}, $self->{ss
});
330 my $cmdlist = $haenv->read_crm_commands();
332 foreach my $cmd (split(/\n/, $cmdlist)) {
335 if ($cmd =~ m/^(migrate|relocate)\s+(\S+)\s+(\S+)$/) {
336 my ($task, $sid, $node) = ($1, $2, $3);
337 if (my $sd = $ss->{$sid}) {
338 if (!$ns->node_is_online($node)) {
339 $haenv->log('err', "crm command error - node not online: $cmd");
341 if ($node eq $sd->{node
}) {
342 $haenv->log('info', "ignore crm command - service already on target node: $cmd");
344 $haenv->log('info', "got crm command: $cmd");
345 $ss->{$sid}->{cmd
} = [ $task, $node];
349 $haenv->log('err', "crm command error - no such service: $cmd");
353 $haenv->log('err', "unable to parse crm command: $cmd");
362 my ($haenv, $ms, $ns, $ss) = ($self->{haenv
}, $self->{ms
}, $self->{ns
}, $self->{ss
});
364 $ns->update($haenv->get_node_info());
366 if (!$ns->node_is_online($haenv->nodename())) {
367 $haenv->log('info', "master seems offline");
371 my ($lrm_results, $lrm_modes) = $self->read_lrm_status();
373 my $sc = $haenv->read_service_config();
375 $self->{groups
} = $haenv->read_group_config(); # update
377 # compute new service status
380 foreach my $sid (sort keys %$sc) {
381 next if $ss->{$sid}; # already there
382 my $cd = $sc->{$sid};
383 $haenv->log('info', "adding new service '$sid' on node '$cd->{node}'");
384 # assume we are running to avoid relocate running service at add
385 my $state = ($cd->{state} eq 'started') ?
'started' : 'request_stop';
386 $ss->{$sid} = { state => $state, node
=> $cd->{node
},
387 uid
=> compute_new_uuid
('started') };
390 # remove stale service from manager state
391 foreach my $sid (keys %$ss) {
393 $haenv->log('info', "removing stale service '$sid' (no config)");
394 # remove all service related state information
398 $self->update_crm_commands();
403 $self->recompute_online_node_usage();
405 foreach my $sid (sort keys %$ss) {
406 my $sd = $ss->{$sid};
407 my $cd = $sc->{$sid} || { state => 'disabled' };
409 my $lrm_res = $sd->{uid
} ?
$lrm_results->{$sd->{uid
}} : undef;
411 my $last_state = $sd->{state};
413 if ($last_state eq 'stopped') {
415 $self->next_state_stopped($sid, $cd, $sd, $lrm_res);
417 } elsif ($last_state eq 'started') {
419 $self->next_state_started($sid, $cd, $sd, $lrm_res);
421 } elsif ($last_state eq 'migrate' || $last_state eq 'relocate') {
423 $self->next_state_migrate_relocate($sid, $cd, $sd, $lrm_res);
425 } elsif ($last_state eq 'fence') {
427 # do nothing here - wait until fenced
429 } elsif ($last_state eq 'request_stop') {
431 $self->next_state_request_stop($sid, $cd, $sd, $lrm_res);
433 } elsif ($last_state eq 'freeze') {
435 my $lrm_mode = $sd->{node
} ?
$lrm_modes->{$sd->{node
}} : undef;
437 my $state = ($cd->{state} eq 'started') ?
'started' : 'request_stop';
438 &$change_service_state($self, $sid, $state)
439 if $lrm_mode && $lrm_mode eq 'active';
441 } elsif ($last_state eq 'error') {
443 $self->next_state_error($sid, $cd, $sd, $lrm_res);
447 die "unknown service state '$last_state'";
450 my $lrm_mode = $sd->{node
} ?
$lrm_modes->{$sd->{node
}} : undef;
451 if ($lrm_mode && $lrm_mode eq 'restart') {
452 if (($sd->{state} eq 'started' || $sd->{state} eq 'stopped' ||
453 $sd->{state} eq 'request_stop')) {
454 &$change_service_state($self, $sid, 'freeze');
458 $repeat = 1 if $sd->{state} ne $last_state;
462 my $fenced_nodes = {};
463 foreach my $sid (sort keys %$ss) {
464 my $sd = $ss->{$sid};
465 next if $sd->{state} ne 'fence';
467 if (!defined($fenced_nodes->{$sd->{node
}})) {
468 $fenced_nodes->{$sd->{node
}} = $ns->fence_node($sd->{node
}) || 0;
471 next if !$fenced_nodes->{$sd->{node
}};
473 # node fence was successful - recover service
474 &$recover_fenced_service($self, $sid, $sc->{$sid});
480 $self->flush_master_status();
483 # functions to compute next service states
484 # $cd: service configuration data (read only)
485 # $sd: service status data (read only)
487 # Note: use change_service_state() to alter state
490 sub next_state_request_stop
{
491 my ($self, $sid, $cd, $sd, $lrm_res) = @_;
493 my $haenv = $self->{haenv
};
494 my $ns = $self->{ns
};
496 # check result from LRM daemon
498 my $exit_code = $lrm_res->{exit_code
};
499 if ($exit_code == SUCCESS
) {
500 &$change_service_state($self, $sid, 'stopped');
503 $haenv->log('err', "service '$sid' stop failed (exit code $exit_code)");
504 &$change_service_state($self, $sid, 'error'); # fixme: what state?
509 if ($ns->node_is_offline_delayed($sd->{node
})) {
510 &$change_service_state($self, $sid, 'fence');
515 sub next_state_migrate_relocate
{
516 my ($self, $sid, $cd, $sd, $lrm_res) = @_;
518 my $haenv = $self->{haenv
};
519 my $ns = $self->{ns
};
521 # check result from LRM daemon
523 my $exit_code = $lrm_res->{exit_code
};
524 my $req_state = $cd->{state} eq 'started' ?
'started' : 'request_stop';
525 if ($exit_code == SUCCESS
) {
526 &$change_service_state($self, $sid, $req_state, node
=> $sd->{target
});
528 } elsif ($exit_code == EWRONG_NODE
) {
529 $haenv->log('err', "service '$sid' - migration failed: service" .
530 " registered on wrong node!");
531 &$change_service_state($self, $sid, 'error');
533 $haenv->log('err', "service '$sid' - migration failed (exit code $exit_code)");
534 &$change_service_state($self, $sid, $req_state, node
=> $sd->{node
});
539 if ($ns->node_is_offline_delayed($sd->{node
})) {
540 &$change_service_state($self, $sid, 'fence');
546 sub next_state_stopped
{
547 my ($self, $sid, $cd, $sd, $lrm_res) = @_;
549 my $haenv = $self->{haenv
};
550 my $ns = $self->{ns
};
552 if ($sd->{node
} ne $cd->{node
}) {
553 # this can happen if we fence a node with active migrations
554 # hack: modify $sd (normally this should be considered read-only)
555 $haenv->log('info', "fixup service '$sid' location ($sd->{node} => $cd->{node})");
556 $sd->{node
} = $cd->{node
};
560 my ($cmd, $target) = @{$sd->{cmd
}};
563 if ($cmd eq 'migrate' || $cmd eq 'relocate') {
564 if (!$ns->node_is_online($target)) {
565 $haenv->log('err', "ignore service '$sid' $cmd request - node '$target' not online");
566 } elsif ($sd->{node
} eq $target) {
567 $haenv->log('info', "ignore service '$sid' $cmd request - service already on node '$target'");
569 &$change_service_state($self, $sid, $cmd, node
=> $sd->{node
},
574 $haenv->log('err', "unknown command '$cmd' for service '$sid'");
578 if ($cd->{state} eq 'disabled') {
579 # NOTE: do nothing here, the stop state is an exception as we do not
580 # process the LRM result here, thus the LRM always tries to stop the
581 # service (protection for the case no CRM is active)
585 if ($ns->node_is_offline_delayed($sd->{node
})) {
586 &$change_service_state($self, $sid, 'fence');
590 if ($cd->{state} eq 'stopped') {
591 # almost the same as 'disabled' state but the service will also get recovered
595 if ($cd->{state} eq 'started') {
596 # simply mark it started, if it's on the wrong node
597 # next_state_started will fix that for us
598 &$change_service_state($self, $sid, 'started', node
=> $sd->{node
});
602 $haenv->log('err', "service '$sid' - unknown state '$cd->{state}' in service configuration");
605 sub record_service_failed_on_node
{
606 my ($self, $sid, $node) = @_;
608 if (!defined($self->{ss
}->{$sid}->{failed_nodes
})) {
609 $self->{ss
}->{$sid}->{failed_nodes
} = [];
612 push @{$self->{ss
}->{$sid}->{failed_nodes
}}, $node;
615 sub next_state_started
{
616 my ($self, $sid, $cd, $sd, $lrm_res) = @_;
618 my $haenv = $self->{haenv
};
619 my $master_status = $self->{ms
};
620 my $ns = $self->{ns
};
622 if (!$ns->node_is_online($sd->{node
})) {
623 if ($ns->node_is_offline_delayed($sd->{node
})) {
624 &$change_service_state($self, $sid, 'fence');
629 if ($cd->{state} eq 'disabled' || $cd->{state} eq 'stopped') {
630 &$change_service_state($self, $sid, 'request_stop');
634 if ($cd->{state} eq 'started') {
637 my ($cmd, $target) = @{$sd->{cmd
}};
640 if ($cmd eq 'migrate' || $cmd eq 'relocate') {
641 if (!$ns->node_is_online($target)) {
642 $haenv->log('err', "ignore service '$sid' $cmd request - node '$target' not online");
643 } elsif ($sd->{node
} eq $target) {
644 $haenv->log('info', "ignore service '$sid' $cmd request - service already on node '$target'");
646 $haenv->log('info', "$cmd service '$sid' to node '$target'");
647 &$change_service_state($self, $sid, $cmd, node
=> $sd->{node
}, target
=> $target);
650 $haenv->log('err', "unknown command '$cmd' for service '$sid'");
658 my $ec = $lrm_res->{exit_code
};
659 if ($ec == SUCCESS
) {
661 if (defined($sd->{failed_nodes
})) {
662 $haenv->log('info', "relocation policy successful for '$sid' on node '$sd->{node}'," .
663 " failed nodes: " . join(', ', @{$sd->{failed_nodes
}}) );
666 delete $sd->{failed_nodes
};
668 # store flag to indicate successful start - only valid while state == 'started'
671 } elsif ($ec == ERROR
) {
673 delete $sd->{running
};
675 # apply our relocate policy if we got ERROR from the LRM
676 $self->record_service_failed_on_node($sid, $sd->{node
});
678 if (scalar(@{$sd->{failed_nodes
}}) <= $cd->{max_relocate
}) {
680 # tell select_service_node to relocate if possible
683 $haenv->log('warning', "starting service $sid on node".
684 " '$sd->{node}' failed, relocating service.");
688 $haenv->log('err', "recovery policy for service $sid " .
689 "failed, entering error state. Failed nodes: ".
690 join(', ', @{$sd->{failed_nodes
}}));
691 &$change_service_state($self, $sid, 'error');
696 $self->record_service_failed_on_node($sid, $sd->{node
});
698 $haenv->log('err', "service '$sid' got unrecoverable error" .
699 " (exit code $ec))");
700 # we have no save way out (yet) for other errors
701 &$change_service_state($self, $sid, 'error');
706 my $node = select_service_node
($self->{groups
}, $self->{online_node_usage
},
707 $cd, $sd->{node
}, $try_next, $sd->{failed_nodes
});
709 if ($node && ($sd->{node
} ne $node)) {
710 if ($cd->{type
} eq 'vm') {
711 $haenv->log('info', "migrate service '$sid' to node '$node' (running)");
712 &$change_service_state($self, $sid, 'migrate', node
=> $sd->{node
}, target
=> $node);
714 $haenv->log('info', "relocate service '$sid' to node '$node'");
715 &$change_service_state($self, $sid, 'relocate', node
=> $sd->{node
}, target
=> $node);
718 if ($try_next && !defined($node)) {
719 $haenv->log('warning', "Start Error Recovery: Tried all available " .
720 " nodes for service '$sid', retry start on current node. " .
721 "Tried nodes: " . join(', ', @{$sd->{failed_nodes
}}));
723 # ensure service get started again if it went unexpected down
724 # but ensure also no LRM result gets lost
725 $sd->{uid
} = compute_new_uuid
($sd->{state}) if defined($lrm_res);
732 $haenv->log('err', "service '$sid' - unknown state '$cd->{state}' in service configuration");
735 sub next_state_error
{
736 my ($self, $sid, $cd, $sd, $lrm_res) = @_;
738 my $ns = $self->{ns
};
739 my $ms = $self->{ms
};
741 if ($cd->{state} eq 'disabled') {
742 # clean up on error recovery
743 delete $sd->{failed_nodes
};
745 &$change_service_state($self, $sid, 'stopped');