2 monitoring links to all other nodes to detect dead nodes
5 Copyright (C) Ronnie Sahlberg 2007
7 This program is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License as published by
9 the Free Software Foundation; either version 3 of the License, or
10 (at your option) any later version.
12 This program is distributed in the hope that it will be useful,
13 but WITHOUT ANY WARRANTY; without even the implied warranty of
14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 GNU General Public License for more details.
17 You should have received a copy of the GNU General Public License
18 along with this program; if not, see <http://www.gnu.org/licenses/>.
22 #include "lib/events/events.h"
23 #include "system/filesys.h"
24 #include "system/wait.h"
25 #include "../include/ctdb_private.h"
27 struct ctdb_monitor_state {
28 uint32_t monitoring_mode;
29 TALLOC_CTX *monitor_context;
30 uint32_t next_interval;
33 static void ctdb_check_health(struct event_context *ev, struct timed_event *te,
34 struct timeval t, void *private_data);
37 setup the notification script
39 int ctdb_set_notification_script(struct ctdb_context *ctdb, const char *script)
41 ctdb->notification_script = talloc_strdup(ctdb, script);
42 CTDB_NO_MEMORY(ctdb, ctdb->notification_script);
46 static int ctdb_run_notification_script_child(struct ctdb_context *ctdb, const char *event)
52 if (stat(ctdb->notification_script, &st) != 0) {
53 DEBUG(DEBUG_ERR,("Could not stat notification script %s. Can not send notifications.\n", ctdb->notification_script));
56 if (!(st.st_mode & S_IXUSR)) {
57 DEBUG(DEBUG_ERR,("Notification script %s is not executable.\n", ctdb->notification_script));
61 cmd = talloc_asprintf(ctdb, "%s %s\n", ctdb->notification_script, event);
62 CTDB_NO_MEMORY(ctdb, cmd);
65 /* if the system() call was successful, translate ret into the
66 return code from the command
69 ret = WEXITSTATUS(ret);
72 DEBUG(DEBUG_ERR,("Notification script \"%s\" failed with error %d\n", cmd, ret));
78 static void ctdb_run_notification_script(struct ctdb_context *ctdb, const char *event)
82 if (ctdb->notification_script == NULL) {
87 if (child == (pid_t)-1) {
88 DEBUG(DEBUG_ERR,("Failed to fork() a notification child process\n"));
94 ret = ctdb_run_notification_script_child(ctdb, event);
96 DEBUG(DEBUG_ERR,(__location__ " Notification script failed\n"));
105 called when a health monitoring event script finishes
107 static void ctdb_health_callback(struct ctdb_context *ctdb, int status, void *p)
109 struct ctdb_node *node = ctdb->nodes[ctdb->pnn];
111 struct ctdb_node_flag_change c;
112 uint32_t next_interval;
115 struct takeover_run_reply rd;
118 c.old_flags = node->flags;
121 rd.srvid = CTDB_SRVID_TAKEOVER_RUN_RESPONSE;
123 rddata.dptr = (uint8_t *)&rd;
124 rddata.dsize = sizeof(rd);
126 if (status != 0 && !(node->flags & NODE_FLAGS_UNHEALTHY)) {
127 DEBUG(DEBUG_NOTICE,("monitor event failed - disabling node\n"));
128 node->flags |= NODE_FLAGS_UNHEALTHY;
129 ctdb->monitor->next_interval = 1;
130 if (ctdb->tunable.disable_when_unhealthy != 0) {
131 DEBUG(DEBUG_INFO, ("DISABLING node since it became unhealthy\n"));
132 node->flags |= NODE_FLAGS_DISABLED;
135 ctdb_run_notification_script(ctdb, "unhealthy");
137 /* ask the recmaster to reallocate all addresses */
138 DEBUG(DEBUG_ERR,("Node became UNHEALTHY. Ask recovery master %u to perform ip reallocation\n", ctdb->recovery_master));
139 ret = ctdb_daemon_send_message(ctdb, ctdb->recovery_master, CTDB_SRVID_TAKEOVER_RUN, rddata);
141 DEBUG(DEBUG_ERR,(__location__ " Failed to send ip takeover run request message to %u\n", ctdb->recovery_master));
144 } else if (status == 0 && (node->flags & NODE_FLAGS_UNHEALTHY)) {
145 DEBUG(DEBUG_NOTICE,("monitor event OK - node re-enabled\n"));
146 node->flags &= ~NODE_FLAGS_UNHEALTHY;
147 ctdb->monitor->next_interval = 1;
149 ctdb_run_notification_script(ctdb, "healthy");
151 /* ask the recmaster to reallocate all addresses */
152 DEBUG(DEBUG_ERR,("Node became HEALTHY. Ask recovery master %u to perform ip reallocation\n", ctdb->recovery_master));
153 ret = ctdb_daemon_send_message(ctdb, ctdb->recovery_master, CTDB_SRVID_TAKEOVER_RUN, rddata);
155 DEBUG(DEBUG_ERR,(__location__ " Failed to send ip takeover run request message to %u\n", ctdb->recovery_master));
160 next_interval = ctdb->monitor->next_interval;
162 ctdb->monitor->next_interval *= 2;
163 if (ctdb->monitor->next_interval > ctdb->tunable.monitor_interval) {
164 ctdb->monitor->next_interval = ctdb->tunable.monitor_interval;
167 event_add_timed(ctdb->ev, ctdb->monitor->monitor_context,
168 timeval_current_ofs(next_interval, 0),
169 ctdb_check_health, ctdb);
171 if (c.old_flags == node->flags) {
175 c.new_flags = node->flags;
177 data.dptr = (uint8_t *)&c;
178 data.dsize = sizeof(c);
180 /* ask the recovery daemon to push these changes out to all nodes */
181 ctdb_daemon_send_message(ctdb, ctdb->pnn,
182 CTDB_SRVID_PUSH_NODE_FLAGS, data);
188 called when the startup event script finishes
190 static void ctdb_startup_callback(struct ctdb_context *ctdb, int status, void *p)
193 DEBUG(DEBUG_ERR,("startup event failed\n"));
194 } else if (status == 0) {
195 DEBUG(DEBUG_NOTICE,("startup event OK - enabling monitoring\n"));
196 ctdb->done_startup = true;
197 ctdb->monitor->next_interval = 1;
198 ctdb_run_notification_script(ctdb, "startup");
201 event_add_timed(ctdb->ev, ctdb->monitor->monitor_context,
202 timeval_current_ofs(ctdb->monitor->next_interval, 0),
203 ctdb_check_health, ctdb);
208 see if the event scripts think we are healthy
210 static void ctdb_check_health(struct event_context *ev, struct timed_event *te,
211 struct timeval t, void *private_data)
213 struct ctdb_context *ctdb = talloc_get_type(private_data, struct ctdb_context);
216 if (ctdb->recovery_mode != CTDB_RECOVERY_NORMAL ||
217 (ctdb->monitor->monitoring_mode == CTDB_MONITORING_DISABLED && ctdb->done_startup)) {
218 event_add_timed(ctdb->ev, ctdb->monitor->monitor_context,
219 timeval_current_ofs(ctdb->monitor->next_interval, 0),
220 ctdb_check_health, ctdb);
224 if (!ctdb->done_startup) {
225 ret = ctdb_event_script_callback(ctdb,
226 timeval_current_ofs(ctdb->tunable.script_timeout, 0),
227 ctdb->monitor->monitor_context, ctdb_startup_callback,
231 int skip_monitoring = 0;
233 if (ctdb->recovery_mode != CTDB_RECOVERY_NORMAL) {
235 DEBUG(DEBUG_ERR,("Skip monitoring during recovery\n"));
237 for (i=1; i<=NUM_DB_PRIORITIES; i++) {
238 if (ctdb->freeze_handles[i] != NULL) {
239 DEBUG(DEBUG_ERR,("Skip monitoring since databases are frozen\n"));
244 if (skip_monitoring) {
245 event_add_timed(ctdb->ev, ctdb->monitor->monitor_context,
246 timeval_current_ofs(ctdb->monitor->next_interval, 0),
247 ctdb_check_health, ctdb);
250 ret = ctdb_event_script_callback(ctdb,
251 timeval_current_ofs(ctdb->tunable.script_timeout, 0),
252 ctdb->monitor->monitor_context, ctdb_health_callback,
258 DEBUG(DEBUG_ERR,("Unable to launch monitor event script\n"));
259 ctdb->monitor->next_interval = 1;
260 event_add_timed(ctdb->ev, ctdb->monitor->monitor_context,
261 timeval_current_ofs(1, 0),
262 ctdb_check_health, ctdb);
267 (Temporaily) Disabling monitoring will stop the monitor event scripts
268 from running but node health checks will still occur
270 void ctdb_disable_monitoring(struct ctdb_context *ctdb)
272 ctdb->monitor->monitoring_mode = CTDB_MONITORING_DISABLED;
273 DEBUG(DEBUG_INFO,("Monitoring has been disabled\n"));
277 Re-enable running monitor events after they have been disabled
279 void ctdb_enable_monitoring(struct ctdb_context *ctdb)
281 ctdb->monitor->monitoring_mode = CTDB_MONITORING_ACTIVE;
282 ctdb->monitor->next_interval = 2;
283 DEBUG(DEBUG_INFO,("Monitoring has been enabled\n"));
286 /* stop any monitoring
287 this should only be done when shutting down the daemon
289 void ctdb_stop_monitoring(struct ctdb_context *ctdb)
291 talloc_free(ctdb->monitor->monitor_context);
292 ctdb->monitor->monitor_context = NULL;
294 ctdb->monitor->monitoring_mode = CTDB_MONITORING_DISABLED;
295 ctdb->monitor->next_interval = 1;
296 DEBUG(DEBUG_NOTICE,("Monitoring has been stopped\n"));
300 start watching for nodes that might be dead
302 void ctdb_start_monitoring(struct ctdb_context *ctdb)
304 struct timed_event *te;
306 if (ctdb->monitor != NULL) {
310 ctdb->monitor = talloc(ctdb, struct ctdb_monitor_state);
311 CTDB_NO_MEMORY_FATAL(ctdb, ctdb->monitor);
313 ctdb->monitor->next_interval = 1;
315 ctdb->monitor->monitor_context = talloc_new(ctdb->monitor);
316 CTDB_NO_MEMORY_FATAL(ctdb, ctdb->monitor->monitor_context);
318 te = event_add_timed(ctdb->ev, ctdb->monitor->monitor_context,
319 timeval_current_ofs(1, 0),
320 ctdb_check_health, ctdb);
321 CTDB_NO_MEMORY_FATAL(ctdb, te);
323 ctdb->monitor->monitoring_mode = CTDB_MONITORING_ACTIVE;
324 DEBUG(DEBUG_NOTICE,("Monitoring has been started\n"));
329 modify flags on a node
331 int32_t ctdb_control_modflags(struct ctdb_context *ctdb, TDB_DATA indata)
333 struct ctdb_node_flag_change *c = (struct ctdb_node_flag_change *)indata.dptr;
334 struct ctdb_node *node;
338 if (c->pnn >= ctdb->num_nodes) {
339 DEBUG(DEBUG_ERR,(__location__ " Node %d is invalid, num_nodes :%d\n", c->pnn, ctdb->num_nodes));
343 node = ctdb->nodes[c->pnn];
344 old_flags = node->flags;
345 c->old_flags = node->flags;
346 node->flags = c->new_flags & ~NODE_FLAGS_DISCONNECTED;
347 node->flags |= (c->old_flags & NODE_FLAGS_DISCONNECTED);
349 /* we dont let other nodes modify our STOPPED status */
350 if (c->pnn == ctdb->pnn) {
351 node->flags &= ~NODE_FLAGS_STOPPED;
352 if (old_flags & NODE_FLAGS_STOPPED) {
353 node->flags |= NODE_FLAGS_STOPPED;
357 /* we dont let other nodes modify our BANNED status */
358 if (c->pnn == ctdb->pnn) {
359 node->flags &= ~NODE_FLAGS_BANNED;
360 if (old_flags & NODE_FLAGS_BANNED) {
361 node->flags |= NODE_FLAGS_BANNED;
365 if (node->flags == c->old_flags) {
366 DEBUG(DEBUG_INFO, ("Control modflags on node %u - Unchanged - flags 0x%x\n", c->pnn, node->flags));
370 DEBUG(DEBUG_INFO, ("Control modflags on node %u - flags now 0x%x\n", c->pnn, node->flags));
373 /* tell the recovery daemon something has changed */
374 ctdb_daemon_send_message(ctdb, ctdb->pnn,
375 CTDB_SRVID_SET_NODE_FLAGS, indata);
377 /* if we have become banned, we should go into recovery mode */
378 if ((node->flags & NODE_FLAGS_BANNED) && !(c->old_flags & NODE_FLAGS_BANNED) && (node->pnn == ctdb->pnn)) {
379 /* make sure we are frozen */
380 DEBUG(DEBUG_NOTICE,("This node has been banned - forcing freeze and recovery\n"));
381 /* Reset the generation id to 1 to make us ignore any
382 REQ/REPLY CALL/DMASTER someone sends to us.
383 We are now banned so we shouldnt service database calls
386 ctdb->vnn_map->generation = INVALID_GENERATION;
388 for (i=1; i<=NUM_DB_PRIORITIES; i++) {
389 if (ctdb_start_freeze(ctdb, i) != 0) {
390 DEBUG(DEBUG_ERR,(__location__ " Failed to freeze db priority %u\n", i));
393 ctdb_release_all_ips(ctdb);
394 ctdb->recovery_mode = CTDB_RECOVERY_ACTIVE;
401 return the monitoring mode
403 int32_t ctdb_monitoring_mode(struct ctdb_context *ctdb)
405 if (ctdb->monitor == NULL) {
406 return CTDB_MONITORING_DISABLED;
408 return ctdb->monitor->monitoring_mode;