]> git.proxmox.com Git - pve-ha-manager.git/blob - src/PVE/HA/Manager.pm
fix relocate/restart trial count leak on service deletion
[pve-ha-manager.git] / src / PVE / HA / Manager.pm
1 package PVE::HA::Manager;
2
3 use strict;
4 use warnings;
5 use Digest::MD5 qw(md5_base64);
6
7 use Data::Dumper;
8 use PVE::Tools;
9 use PVE::HA::Tools ':exit_codes';
10 use PVE::HA::NodeStatus;
11
12 sub new {
13 my ($this, $haenv) = @_;
14
15 my $class = ref($this) || $this;
16
17 my $ms = $haenv->read_manager_status();
18
19 $ms->{master_node} = $haenv->nodename();
20
21 my $ns = PVE::HA::NodeStatus->new($haenv, $ms->{node_status} || {});
22
23 # fixme: use separate class PVE::HA::ServiceStatus
24 my $ss = $ms->{service_status} || {};
25
26 my $self = bless {
27 haenv => $haenv,
28 ms => $ms, # master status
29 ns => $ns, # PVE::HA::NodeStatus
30 ss => $ss, # service status
31 }, $class;
32
33 return $self;
34 }
35
36 sub cleanup {
37 my ($self) = @_;
38
39 # todo: ?
40 }
41
42 sub flush_master_status {
43 my ($self) = @_;
44
45 my ($haenv, $ms, $ns, $ss) = ($self->{haenv}, $self->{ms}, $self->{ns}, $self->{ss});
46
47 $ms->{node_status} = $ns->{status};
48 $ms->{service_status} = $ss;
49 $ms->{timestamp} = $haenv->get_time();
50
51 $haenv->write_manager_status($ms);
52 }
53
54 sub select_service_node {
55 my ($groups, $online_node_usage, $service_conf, $current_node, $try_next) = @_;
56
57 my $group = { 'nodes' => { $service_conf->{node} => 1 } }; # default group
58
59 $group = $groups->{ids}->{$service_conf->{group}} if $service_conf->{group} &&
60 $groups->{ids}->{$service_conf->{group}};
61
62 my $pri_groups = {};
63 my $group_members = {};
64 foreach my $entry (keys %{$group->{nodes}}) {
65 my ($node, $pri) = ($entry, 0);
66 if ($entry =~ m/^(\S+):(\d+)$/) {
67 ($node, $pri) = ($1, $2);
68 }
69 next if !defined($online_node_usage->{$node}); # offline
70 $pri_groups->{$pri}->{$node} = 1;
71 $group_members->{$node} = $pri;
72 }
73
74
75 # add non-group members to unrestricted groups (priority -1)
76 if (!$group->{restricted}) {
77 my $pri = -1;
78 foreach my $node (keys %$online_node_usage) {
79 next if defined($group_members->{$node});
80 $pri_groups->{$pri}->{$node} = 1;
81 $group_members->{$node} = -1;
82 }
83 }
84
85
86 my @pri_list = sort {$b <=> $a} keys %$pri_groups;
87 return undef if !scalar(@pri_list);
88
89 if (!$try_next && $group->{nofailback} && defined($group_members->{$current_node})) {
90 return $current_node;
91 }
92
93 # select node from top priority node list
94
95 my $top_pri = $pri_list[0];
96
97 my @nodes = sort {
98 $online_node_usage->{$a} <=> $online_node_usage->{$b} || $a cmp $b
99 } keys %{$pri_groups->{$top_pri}};
100
101 my $found;
102 for (my $i = scalar(@nodes) - 1; $i >= 0; $i--) {
103 my $node = $nodes[$i];
104 if ($node eq $current_node) {
105 $found = $i;
106 last;
107 }
108 }
109
110 if ($try_next) {
111
112 if (defined($found) && ($found < (scalar(@nodes) - 1))) {
113 return $nodes[$found + 1];
114 } else {
115 return $nodes[0];
116 }
117
118 } else {
119
120 return $nodes[$found] if defined($found);
121
122 return $nodes[0];
123
124 }
125 }
126
127 my $uid_counter = 0;
128
129 sub compute_new_uuid {
130 my ($state) = @_;
131
132 $uid_counter++;
133 return md5_base64($state . $$ . time() . $uid_counter);
134 }
135
136 my $valid_service_states = {
137 stopped => 1,
138 request_stop => 1,
139 started => 1,
140 fence => 1,
141 migrate => 1,
142 relocate => 1,
143 freeze => 1,
144 error => 1,
145 };
146
147 sub recompute_online_node_usage {
148 my ($self) = @_;
149
150 my $online_node_usage = {};
151
152 my $online_nodes = $self->{ns}->list_online_nodes();
153
154 foreach my $node (@$online_nodes) {
155 $online_node_usage->{$node} = 0;
156 }
157
158 foreach my $sid (keys %{$self->{ss}}) {
159 my $sd = $self->{ss}->{$sid};
160 my $state = $sd->{state};
161 if (defined($online_node_usage->{$sd->{node}})) {
162 if (($state eq 'started') || ($state eq 'request_stop') ||
163 ($state eq 'fence') || ($state eq 'freeze') || ($state eq 'error')) {
164 $online_node_usage->{$sd->{node}}++;
165 } elsif (($state eq 'migrate') || ($state eq 'relocate')) {
166 $online_node_usage->{$sd->{target}}++;
167 } elsif ($state eq 'stopped') {
168 # do nothing
169 } else {
170 die "should not be reached";
171 }
172 }
173 }
174
175 $self->{online_node_usage} = $online_node_usage;
176 }
177
178 my $change_service_state = sub {
179 my ($self, $sid, $new_state, %params) = @_;
180
181 my ($haenv, $ss) = ($self->{haenv}, $self->{ss});
182
183 my $sd = $ss->{$sid} || die "no such service '$sid";
184
185 my $old_state = $sd->{state};
186 my $old_node = $sd->{node};
187
188 die "no state change" if $old_state eq $new_state; # just to be sure
189
190 die "invalid CRM service state '$new_state'\n" if !$valid_service_states->{$new_state};
191
192 foreach my $k (keys %$sd) { delete $sd->{$k}; };
193
194 $sd->{state} = $new_state;
195 $sd->{node} = $old_node;
196
197 my $text_state = '';
198 foreach my $k (sort keys %params) {
199 my $v = $params{$k};
200 $text_state .= ", " if $text_state;
201 $text_state .= "$k = $v";
202 $sd->{$k} = $v;
203 }
204
205 $self->recompute_online_node_usage();
206
207 $sd->{uid} = compute_new_uuid($new_state);
208
209 $text_state = " ($text_state)" if $text_state;
210 $haenv->log('info', "service '$sid': state changed from '${old_state}'" .
211 " to '${new_state}'$text_state");
212 };
213
214 # after a node was fenced this recovers the service to a new node
215 my $recover_fenced_service = sub {
216 my ($self, $sid, $cd) = @_;
217
218 my ($haenv, $ss) = ($self->{haenv}, $self->{ss});
219
220 my $sd = $ss->{$sid};
221
222 if ($sd->{state} ne 'fence') { # should not happen
223 $haenv->log('err', "cannot recover service '$sid' from fencing," .
224 " wrong state '$sd->{state}'");
225 return;
226 }
227
228 my $fenced_node = $sd->{node}; # for logging purpose
229
230 $self->recompute_online_node_usage(); # we want the most current node state
231
232 my $recovery_node = select_service_node($self->{groups},
233 $self->{online_node_usage},
234 $cd, $sd->{node});
235
236 if ($recovery_node) {
237 $haenv->log('info', "recover service '$sid' from fenced node " .
238 "'$fenced_node' to node '$recovery_node'");
239
240 $haenv->steal_service($sid, $sd->{node}, $recovery_node);
241
242 # $sd *is normally read-only*, fencing is the exception
243 $cd->{node} = $sd->{node} = $recovery_node;
244 &$change_service_state($self, $sid, 'started', node => $recovery_node);
245 } else {
246 # no node found, let the service in 'fence' state and try again
247 $haenv->log('err', "recovering service '$sid' from fenced node " .
248 "'$fenced_node' failed, no recovery node found");
249 }
250 };
251
252 # read LRM status for all nodes
253 sub read_lrm_status {
254 my ($self) = @_;
255
256 my $nodes = $self->{ns}->list_nodes();
257 my $haenv = $self->{haenv};
258
259 my $results = {};
260 my $modes = {};
261 foreach my $node (@$nodes) {
262 my $lrm_status = $haenv->read_lrm_status($node);
263 $modes->{$node} = $lrm_status->{mode} || 'active';
264 foreach my $uid (keys %{$lrm_status->{results}}) {
265 next if $results->{$uid}; # should not happen
266 $results->{$uid} = $lrm_status->{results}->{$uid};
267 }
268 }
269
270
271 return ($results, $modes);
272 }
273
274 # read new crm commands and save them into crm master status
275 sub update_crm_commands {
276 my ($self) = @_;
277
278 my ($haenv, $ms, $ns, $ss) = ($self->{haenv}, $self->{ms}, $self->{ns}, $self->{ss});
279
280 my $cmdlist = $haenv->read_crm_commands();
281
282 foreach my $cmd (split(/\n/, $cmdlist)) {
283 chomp $cmd;
284
285 if ($cmd =~ m/^(migrate|relocate)\s+(\S+)\s+(\S+)$/) {
286 my ($task, $sid, $node) = ($1, $2, $3);
287 if (my $sd = $ss->{$sid}) {
288 if (!$ns->node_is_online($node)) {
289 $haenv->log('err', "crm command error - node not online: $cmd");
290 } else {
291 if ($node eq $sd->{node}) {
292 $haenv->log('info', "ignore crm command - service already on target node: $cmd");
293 } else {
294 $haenv->log('info', "got crm command: $cmd");
295 $ss->{$sid}->{cmd} = [ $task, $node];
296 }
297 }
298 } else {
299 $haenv->log('err', "crm command error - no such service: $cmd");
300 }
301
302 } else {
303 $haenv->log('err', "unable to parse crm command: $cmd");
304 }
305 }
306
307 }
308
309 sub manage {
310 my ($self) = @_;
311
312 my ($haenv, $ms, $ns, $ss) = ($self->{haenv}, $self->{ms}, $self->{ns}, $self->{ss});
313
314 $ns->update($haenv->get_node_info());
315
316 if (!$ns->node_is_online($haenv->nodename())) {
317 $haenv->log('info', "master seems offline");
318 return;
319 }
320
321 my ($lrm_results, $lrm_modes) = $self->read_lrm_status();
322
323 my $sc = $haenv->read_service_config();
324
325 $self->{groups} = $haenv->read_group_config(); # update
326
327 # compute new service status
328
329 # add new service
330 foreach my $sid (sort keys %$sc) {
331 next if $ss->{$sid}; # already there
332 $haenv->log('info', "adding new service '$sid' on node '$sc->{$sid}->{node}'");
333 # assume we are running to avoid relocate running service at add
334 $ss->{$sid} = { state => 'started', node => $sc->{$sid}->{node},
335 uid => compute_new_uuid('started') };
336 }
337
338 # remove stale service from manager state
339 foreach my $sid (keys %$ss) {
340 next if $sc->{$sid};
341 $haenv->log('info', "removing stale service '$sid' (no config)");
342 delete $ss->{$sid};
343 }
344
345 # remove stale relocation try entries
346 foreach my $sid (keys %{$ms->{relocate_trial}}) {
347 delete $ms->{relocate_trial}->{$sid} if !$ss->{$sid};
348 }
349
350 $self->update_crm_commands();
351
352 for (;;) {
353 my $repeat = 0;
354
355 $self->recompute_online_node_usage();
356
357 foreach my $sid (keys %$ss) {
358 my $sd = $ss->{$sid};
359 my $cd = $sc->{$sid} || { state => 'disabled' };
360
361 my $lrm_res = $sd->{uid} ? $lrm_results->{$sd->{uid}} : undef;
362
363 my $last_state = $sd->{state};
364
365 if ($last_state eq 'stopped') {
366
367 $self->next_state_stopped($sid, $cd, $sd, $lrm_res);
368
369 } elsif ($last_state eq 'started') {
370
371 $self->next_state_started($sid, $cd, $sd, $lrm_res);
372
373 } elsif ($last_state eq 'migrate' || $last_state eq 'relocate') {
374
375 $self->next_state_migrate_relocate($sid, $cd, $sd, $lrm_res);
376
377 } elsif ($last_state eq 'fence') {
378
379 # do nothing here - wait until fenced
380
381 } elsif ($last_state eq 'request_stop') {
382
383 $self->next_state_request_stop($sid, $cd, $sd, $lrm_res);
384
385 } elsif ($last_state eq 'freeze') {
386
387 my $lrm_mode = $sd->{node} ? $lrm_modes->{$sd->{node}} : undef;
388 # unfreeze
389 &$change_service_state($self, $sid, 'started')
390 if $lrm_mode && $lrm_mode eq 'active';
391
392 } elsif ($last_state eq 'error') {
393
394 $self->next_state_error($sid, $cd, $sd, $lrm_res);
395
396 } else {
397
398 die "unknown service state '$last_state'";
399 }
400
401 my $lrm_mode = $sd->{node} ? $lrm_modes->{$sd->{node}} : undef;
402 if ($lrm_mode && $lrm_mode eq 'restart') {
403 if (($sd->{state} eq 'started' || $sd->{state} eq 'stopped' ||
404 $sd->{state} eq 'request_stop')) {
405 &$change_service_state($self, $sid, 'freeze');
406 }
407 }
408
409 $repeat = 1 if $sd->{state} ne $last_state;
410 }
411
412 # handle fencing
413 my $fenced_nodes = {};
414 foreach my $sid (keys %$ss) {
415 my $sd = $ss->{$sid};
416 next if $sd->{state} ne 'fence';
417
418 if (!defined($fenced_nodes->{$sd->{node}})) {
419 $fenced_nodes->{$sd->{node}} = $ns->fence_node($sd->{node}) || 0;
420 }
421
422 next if !$fenced_nodes->{$sd->{node}};
423
424 # node fence was successful - recover service
425 &$recover_fenced_service($self, $sid, $sc->{$sid});
426 }
427
428 last if !$repeat;
429 }
430
431 $self->flush_master_status();
432 }
433
434 # functions to compute next service states
435 # $cd: service configuration data (read only)
436 # $sd: service status data (read only)
437 #
438 # Note: use change_service_state() to alter state
439 #
440
441 sub next_state_request_stop {
442 my ($self, $sid, $cd, $sd, $lrm_res) = @_;
443
444 my $haenv = $self->{haenv};
445 my $ns = $self->{ns};
446
447 # check result from LRM daemon
448 if ($lrm_res) {
449 my $exit_code = $lrm_res->{exit_code};
450 if ($exit_code == SUCCESS) {
451 &$change_service_state($self, $sid, 'stopped');
452 return;
453 } else {
454 $haenv->log('err', "service '$sid' stop failed (exit code $exit_code)");
455 &$change_service_state($self, $sid, 'error'); # fixme: what state?
456 return;
457 }
458 }
459
460 if ($ns->node_is_offline_delayed($sd->{node})) {
461 &$change_service_state($self, $sid, 'fence');
462 return;
463 }
464 }
465
466 sub next_state_migrate_relocate {
467 my ($self, $sid, $cd, $sd, $lrm_res) = @_;
468
469 my $haenv = $self->{haenv};
470 my $ns = $self->{ns};
471
472 # check result from LRM daemon
473 if ($lrm_res) {
474 my $exit_code = $lrm_res->{exit_code};
475 my $req_state = $cd->{state} eq 'enabled' ? 'started' : 'request_stop';
476 if ($exit_code == SUCCESS) {
477 &$change_service_state($self, $sid, $req_state, node => $sd->{target});
478 return;
479 } elsif ($exit_code == EWRONG_NODE) {
480 $haenv->log('err', "service '$sid' - migration failed: service" .
481 " registered on wrong node!");
482 &$change_service_state($self, $sid, 'error');
483 } else {
484 $haenv->log('err', "service '$sid' - migration failed (exit code $exit_code)");
485 &$change_service_state($self, $sid, $req_state, node => $sd->{node});
486 return;
487 }
488 }
489
490 if ($ns->node_is_offline_delayed($sd->{node})) {
491 &$change_service_state($self, $sid, 'fence');
492 return;
493 }
494 }
495
496
497 sub next_state_stopped {
498 my ($self, $sid, $cd, $sd, $lrm_res) = @_;
499
500 my $haenv = $self->{haenv};
501 my $ns = $self->{ns};
502
503 if ($sd->{node} ne $cd->{node}) {
504 # this can happen if we fence a node with active migrations
505 # hack: modify $sd (normally this should be considered read-only)
506 $haenv->log('info', "fixup service '$sid' location ($sd->{node} => $cd->{node})");
507 $sd->{node} = $cd->{node};
508 }
509
510 if ($sd->{cmd}) {
511 my ($cmd, $target) = @{$sd->{cmd}};
512 delete $sd->{cmd};
513
514 if ($cmd eq 'migrate' || $cmd eq 'relocate') {
515 if (!$ns->node_is_online($target)) {
516 $haenv->log('err', "ignore service '$sid' $cmd request - node '$target' not online");
517 } elsif ($sd->{node} eq $target) {
518 $haenv->log('info', "ignore service '$sid' $cmd request - service already on node '$target'");
519 } else {
520 &$change_service_state($self, $sid, $cmd, node => $sd->{node},
521 target => $target);
522 return;
523 }
524 } else {
525 $haenv->log('err', "unknown command '$cmd' for service '$sid'");
526 }
527 }
528
529 if ($cd->{state} eq 'disabled') {
530 # NOTE: do nothing here, the stop state is an exception as we do not
531 # process the LRM result here, thus the LRM always tries to stop the
532 # service (protection for the case no CRM is active)
533 return;
534 }
535
536 if ($cd->{state} eq 'enabled') {
537 # simply mark it started, if it's on the wrong node
538 # next_state_started will fix that for us
539 &$change_service_state($self, $sid, 'started', node => $sd->{node});
540 return;
541 }
542
543 $haenv->log('err', "service '$sid' - unknown state '$cd->{state}' in service configuration");
544 }
545
546 sub next_state_started {
547 my ($self, $sid, $cd, $sd, $lrm_res) = @_;
548
549 my $haenv = $self->{haenv};
550 my $master_status = $self->{ms};
551 my $ns = $self->{ns};
552
553 if (!$ns->node_is_online($sd->{node})) {
554 if ($ns->node_is_offline_delayed($sd->{node})) {
555 &$change_service_state($self, $sid, 'fence');
556 }
557 return;
558 }
559
560 if ($cd->{state} eq 'disabled') {
561 &$change_service_state($self, $sid, 'request_stop');
562 return;
563 }
564
565 if ($cd->{state} eq 'enabled') {
566
567 if ($sd->{cmd}) {
568 my ($cmd, $target) = @{$sd->{cmd}};
569 delete $sd->{cmd};
570
571 if ($cmd eq 'migrate' || $cmd eq 'relocate') {
572 if (!$ns->node_is_online($target)) {
573 $haenv->log('err', "ignore service '$sid' $cmd request - node '$target' not online");
574 } elsif ($sd->{node} eq $target) {
575 $haenv->log('info', "ignore service '$sid' $cmd request - service already on node '$target'");
576 } else {
577 $haenv->log('info', "$cmd service '$sid' to node '$target'");
578 &$change_service_state($self, $sid, $cmd, node => $sd->{node}, target => $target);
579 }
580 } else {
581 $haenv->log('err', "unknown command '$cmd' for service '$sid'");
582 }
583 } else {
584
585 my $try_next = 0;
586 if ($lrm_res) {
587 my $ec = $lrm_res->{exit_code};
588 if ($ec == SUCCESS) {
589
590 $master_status->{relocate_trial}->{$sid} = 0;
591
592 } elsif ($ec == ERROR) {
593 # apply our relocate policy if we got ERROR from the LRM
594
595 my $try = $master_status->{relocate_trial}->{$sid} || 0;
596
597 if ($try < $cd->{max_relocate}) {
598
599 $try++;
600 # tell select_service_node to relocate if possible
601 $try_next = 1;
602
603 $haenv->log('warning', "starting service $sid on node".
604 " '$sd->{node}' failed, relocating service.");
605 $master_status->{relocate_trial}->{$sid} = $try;
606
607 } else {
608
609 $haenv->log('err', "recovery policy for service".
610 " $sid failed, entering error state!");
611 &$change_service_state($self, $sid, 'error');
612 return;
613
614 }
615 } else {
616 $haenv->log('err', "service '$sid' got unrecoverable error" .
617 " (exit code $ec))");
618 # we have no save way out (yet) for other errors
619 &$change_service_state($self, $sid, 'error');
620 return;
621 }
622 }
623
624 my $node = select_service_node($self->{groups}, $self->{online_node_usage},
625 $cd, $sd->{node}, $try_next);
626
627 if ($node && ($sd->{node} ne $node)) {
628 if ($cd->{type} eq 'vm') {
629 $haenv->log('info', "migrate service '$sid' to node '$node' (running)");
630 &$change_service_state($self, $sid, 'migrate', node => $sd->{node}, target => $node);
631 } else {
632 $haenv->log('info', "relocate service '$sid' to node '$node'");
633 &$change_service_state($self, $sid, 'relocate', node => $sd->{node}, target => $node);
634 }
635 } else {
636 # ensure service get started again if it went unexpected down
637 $sd->{uid} = compute_new_uuid($sd->{state});
638 }
639 }
640
641 return;
642 }
643
644 $haenv->log('err', "service '$sid' - unknown state '$cd->{state}' in service configuration");
645 }
646
647 sub next_state_error {
648 my ($self, $sid, $cd, $sd, $lrm_res) = @_;
649
650 my $ns = $self->{ns};
651
652 if ($cd->{state} eq 'disabled') {
653 &$change_service_state($self, $sid, 'stopped');
654 return;
655 }
656
657 if ($ns->node_is_offline_delayed($sd->{node})) {
658 &$change_service_state($self, $sid, 'fence');
659 return;
660 }
661
662 }
663
664 1;