/* Used on a fresh "drbd_adm_prepare"d reply_skb, this cannot fail: The only
* reason it could fail was no space in skb, and there are 4k available. */ staticint drbd_msg_put_info(struct sk_buff *skb, constchar *info)
{ struct nlattr *nla; int err = -EMSGSIZE;
if (!info || !info[0]) return0;
nla = nla_nest_start_noflag(skb, DRBD_NLA_CFG_REPLY); if (!nla) return err;
adm_ctx->reply_dh = genlmsg_put_reply(adm_ctx->reply_skb,
info, &drbd_genl_family, 0, cmd); /* put of a few bytes into a fresh skb of >= 4k will always succeed.
* but anyways */ if (!adm_ctx->reply_dh) {
err = -ENOMEM; goto fail;
}
adm_ctx->volume = VOLUME_UNSPECIFIED; if (info->attrs[DRBD_NLA_CFG_CONTEXT]) { struct nlattr *nla; /* parse and validate only */
err = drbd_cfg_context_from_attrs(NULL, info); if (err) goto fail;
/* It was present, and valid,
* copy it over to the reply skb. */
err = nla_put_nohdr(adm_ctx->reply_skb,
info->attrs[DRBD_NLA_CFG_CONTEXT]->nla_len,
info->attrs[DRBD_NLA_CFG_CONTEXT]); if (err) goto fail;
/* and assign stuff to the adm_ctx */
nla = nested_attr_tb[__nla_type(T_ctx_volume)]; if (nla)
adm_ctx->volume = nla_get_u32(nla);
nla = nested_attr_tb[__nla_type(T_ctx_resource_name)]; if (nla)
adm_ctx->resource_name = nla_data(nla);
adm_ctx->my_addr = nested_attr_tb[__nla_type(T_ctx_my_addr)];
adm_ctx->peer_addr = nested_attr_tb[__nla_type(T_ctx_peer_addr)]; if ((adm_ctx->my_addr &&
nla_len(adm_ctx->my_addr) > sizeof(adm_ctx->connection->my_addr)) ||
(adm_ctx->peer_addr &&
nla_len(adm_ctx->peer_addr) > sizeof(adm_ctx->connection->peer_addr))) {
err = -EINVAL; goto fail;
}
}
/* We are protected by the global genl_lock(). *Butwemayexplicitlydropit/retakeitindrbd_adm_set_role(),
* so make sure this object stays around. */ if (adm_ctx->device)
kref_get(&adm_ctx->device->kref);
if (adm_ctx->resource_name) {
adm_ctx->resource = drbd_find_resource(adm_ctx->resource_name);
}
if (!adm_ctx->device && (flags & DRBD_ADM_NEED_MINOR)) {
drbd_msg_put_info(adm_ctx->reply_skb, "unknown minor"); return ERR_MINOR_INVALID;
} if (!adm_ctx->resource && (flags & DRBD_ADM_NEED_RESOURCE)) {
drbd_msg_put_info(adm_ctx->reply_skb, "unknown resource"); if (adm_ctx->resource_name) return ERR_RES_NOT_KNOWN; return ERR_INVALID_REQUEST;
}
if (flags & DRBD_ADM_NEED_CONNECTION) { if (adm_ctx->resource) {
drbd_msg_put_info(adm_ctx->reply_skb, "no resource name expected"); return ERR_INVALID_REQUEST;
} if (adm_ctx->device) {
drbd_msg_put_info(adm_ctx->reply_skb, "no minor number expected"); return ERR_INVALID_REQUEST;
} if (adm_ctx->my_addr && adm_ctx->peer_addr)
adm_ctx->connection = conn_get_by_addrs(nla_data(adm_ctx->my_addr),
nla_len(adm_ctx->my_addr),
nla_data(adm_ctx->peer_addr),
nla_len(adm_ctx->peer_addr)); if (!adm_ctx->connection) {
drbd_msg_put_info(adm_ctx->reply_skb, "unknown connection"); return ERR_INVALID_REQUEST;
}
}
/* some more paranoia, if the request was over-determined */ if (adm_ctx->device && adm_ctx->resource &&
adm_ctx->device->resource != adm_ctx->resource) {
pr_warn("request: minor=%u, resource=%s; but that minor belongs to resource %s\n",
adm_ctx->minor, adm_ctx->resource->name,
adm_ctx->device->resource->name);
drbd_msg_put_info(adm_ctx->reply_skb, "minor exists in different resource"); return ERR_INVALID_REQUEST;
} if (adm_ctx->device &&
adm_ctx->volume != VOLUME_UNSPECIFIED &&
adm_ctx->volume != adm_ctx->device->vnr) {
pr_warn("request: minor=%u, volume=%u; but that minor is volume %u in %s\n",
adm_ctx->minor, adm_ctx->volume,
adm_ctx->device->vnr, adm_ctx->device->resource->name);
drbd_msg_put_info(adm_ctx->reply_skb, "minor exists as different volume"); return ERR_INVALID_REQUEST;
}
/* still, provide adm_ctx->resource always, if possible. */ if (!adm_ctx->resource) {
adm_ctx->resource = adm_ctx->device ? adm_ctx->device->resource
: adm_ctx->connection ? adm_ctx->connection->resource : NULL; if (adm_ctx->resource)
kref_get(&adm_ctx->resource->kref);
}
fp = highest_fencing_policy(connection); switch (fp) { case FP_NOT_AVAIL:
drbd_warn(connection, "Not fencing peer, I'm not even Consistent myself.\n");
spin_lock_irq(&resource->req_lock); if (connection->cstate < C_WF_REPORT_PARAMS) {
_conn_request_state(connection,
(union drbd_state) { { .susp_fen = 1 } },
(union drbd_state) { { .susp_fen = 0 } },
CS_VERBOSE | CS_HARD | CS_DC_SUSP); /* We are no longer suspended due to the fencing policy. *Wemaystillbesuspendedduetotheon-no-data-accessiblepolicy.
* If that was OND_IO_ERROR, fail pending requests. */ if (!resource_is_supended(resource))
_tl_restart(connection, CONNECTION_LOST_WHILE_PENDING);
} /* Else: in case we raced with a connection handshake, *letthehandshakefigureoutifwemaybecanRESEND, *anddonotresume/failpendingrequestshere. *Worstcaseiswestaysuspendedfornow,whichmaybe *resolvedbyeitherre-establishingthereplicationlink,or
* the next link failure, or eventually the administrator. */
spin_unlock_irq(&resource->req_lock); returnfalse;
case FP_DONT_CARE: returntrue; default: ;
}
r = conn_khelper(connection, "fence-peer");
switch ((r>>8) & 0xff) { case P_INCONSISTENT: /* peer is inconsistent */
ex_to_string = "peer is inconsistent or worse";
mask.pdsk = D_MASK;
val.pdsk = D_INCONSISTENT; break; case P_OUTDATED: /* peer got outdated, or was already outdated */
ex_to_string = "peer was fenced";
mask.pdsk = D_MASK;
val.pdsk = D_OUTDATED; break; case P_DOWN: /* peer was down */ if (conn_highest_disk(connection) == D_UP_TO_DATE) { /* we will(have) create(d) a new UUID anyways... */
ex_to_string = "peer is unreachable, assumed to be dead";
mask.pdsk = D_MASK;
val.pdsk = D_OUTDATED;
} else {
ex_to_string = "peer unreachable, doing nothing since disk != UpToDate";
} break; case P_PRIMARY: /* Peer is primary, voluntarily outdate myself. *ThisisusefulwhenanunconnectedR_SECONDARYisaskedto
* become R_PRIMARY, but finds the other peer being active. */
ex_to_string = "peer is active";
drbd_warn(connection, "Peer is primary, outdating myself.\n");
mask.disk = D_MASK;
val.disk = D_OUTDATED; break; case P_FENCING: /* THINK: do we need to handle this
* like case 4, or more like case 5? */ if (fp != FP_STONITH)
drbd_err(connection, "fence-peer() = 7 && fencing != Stonith !!!\n");
ex_to_string = "peer was stonithed";
mask.pdsk = D_MASK;
val.pdsk = D_OUTDATED; break; default: /* The script is broken ... */
drbd_err(connection, "fence-peer helper broken, returned %d\n", (r>>8)&0xff); returnfalse; /* Eventually leave IO frozen */
}
drbd_info(connection, "fence-peer helper returned %d (%s)\n",
(r>>8) & 0xff, ex_to_string);
/* Not using conn_request_state(connection,mask,val,CS_VERBOSE); here,becausewemightwereabletore-establishtheconnectioninthe
meantime. */
spin_lock_irq(&resource->req_lock); if (connection->cstate < C_WF_REPORT_PARAMS && !test_bit(STATE_SENT, &connection->flags)) { if (connection->connect_cnt != connect_cnt) /* In case the connection was established and droped
while the fence-peer handler was running, ignore it */
drbd_info(connection, "Ignoring fence-peer exit code\n"); else
_conn_request_state(connection, mask, val, CS_VERBOSE);
}
spin_unlock_irq(&resource->req_lock);
kref_get(&connection->kref); /* We may have just sent a signal to this thread *togetitoutofsomeblockingnetworkfunction. *Clearsignals;otherwisekthread_run(),whichinternallyuses *wait_on_completion_killable(),willmistakeourpendingsignal
* for a new fatal signal and fail. */
flush_signals(current);
opa = kthread_run(_try_outdate_peer_async, connection, "drbd_async_h"); if (IS_ERR(opa)) {
drbd_err(connection, "out of mem, failed to invoke fence-peer helper\n");
kref_put(&connection->kref, drbd_destroy_connection);
}
}
/* in case we first succeeded to outdate,
* but now suddenly could establish a connection */ if (rv == SS_CW_FAILED_BY_PEER && mask.pdsk != 0) {
val.pdsk = 0;
mask.pdsk = 0; continue;
}
if (rv == SS_NOTHING_TO_DO) goto out; if (rv == SS_PRIMARY_NOP && mask.pdsk == 0) { if (!conn_try_outdate_peer(connection) && force) {
drbd_warn(device, "Forced into split brain situation!\n");
mask.pdsk = D_MASK;
val.pdsk = D_OUTDATED;
} continue;
} if (rv == SS_TWO_PRIMARIES) { /* Maybe the peer is detected as dead very soon...
retry at most once more in this case. */ if (try < max_tries) { int timeo; try = max_tries - 1;
rcu_read_lock();
nc = rcu_dereference(connection->net_conf);
timeo = nc ? (nc->ping_timeo + 1) * HZ / 10 : 1;
rcu_read_unlock();
schedule_timeout_interruptible(timeo);
} continue;
} if (rv < SS_SUCCESS) {
rv = _drbd_request_state(device, mask, val,
CS_VERBOSE + CS_WAIT_COMPLETE); if (rv < SS_SUCCESS) goto out;
} break;
}
if (rv < SS_SUCCESS) goto out;
if (forced)
drbd_warn(device, "Forced to consider local data as UpToDate!\n");
/* Wait until nothing is on the fly :) */
wait_event(device->misc_wait, atomic_read(&device->ap_pending_cnt) == 0);
/* FIXME also wait for all pending P_BARRIER_ACK? */
if (new_role == R_SECONDARY) { if (get_ldev(device)) {
device->ldev->md.uuid[UI_CURRENT] &= ~(u64)1;
put_ldev(device);
}
} else {
mutex_lock(&device->resource->conf_update);
nc = connection->net_conf; if (nc)
nc->discard_my_data = 0; /* without copy; single bit op is atomic */
mutex_unlock(&device->resource->conf_update);
if (get_ldev(device)) { if (((device->state.conn < C_CONNECTED ||
device->state.pdsk <= D_FAILED)
&& device->ldev->md.uuid[UI_BITMAP] == 0) || forced)
drbd_uuid_new_current(device);
/* writeout of activity log covered areas of the bitmap
* to stable storage done in after state change already */
if (device->state.conn >= C_WF_REPORT_PARAMS) { /* if this was forced, we should consider sync */ if (forced)
drbd_send_uuids(peer_device);
drbd_send_current_state(peer_device);
}
/* input size is expected to be in KB */ char *ppsize(char *buf, unsignedlonglong size)
{ /* Needs 9 bytes at max including trailing NUL:
* -1ULL ==> "16384 EB" */ staticchar units[] = { 'K', 'M', 'G', 'T', 'P', 'E' }; int base = 0; while (size >= 10000 && base < sizeof(units)-1) { /* shift + round */
size = (size >> 10) + !!(size & (1<<9));
base++;
}
sprintf(buf, "%u %cB", (unsigned)size, units[base]);
return buf;
}
/* there is still a theoretical deadlock when called from receiver *onanD_INCONSISTENTR_PRIMARY: *remoteREADdoesinc_ap_bio,receiverwouldneedtoreceiveanswer *packetfromremotetodec_ap_bioagain. *receiverreceive_sizes(),comeshere, *waitsforap_bio_cnt==0.->deadlock. *butthiscannothappen,actually,because: *R_PRIMARYD_INCONSISTENT,andpeer'sdiskisunreachable *(notconnected,orbad/nodiskonpeer): *seedrbd_fail_request_early,ap_bio_cntiszero. *R_PRIMARYD_INCONSISTENT,andC_SYNC_TARGET: *peermaynotinitiatearesize.
*/ /* Note these are not to be confused with *drbd_adm_suspend_io/drbd_adm_resume_io, *whichare(sub)statechangestriggeredbyadmin(drbdsetup), *andcanbelonglived. *Thischangesandevice->flag,istriggeredbydrbdinternals,
* and should be short-lived. */ /* It needs to be a counter, since multiple threads might
independently suspend and resume IO. */ void drbd_suspend_io(struct drbd_device *device)
{
atomic_inc(&device->suspend_cnt); if (drbd_suspended(device)) return;
wait_event(device->misc_wait, !atomic_read(&device->ap_bio_cnt));
}
void drbd_resume_io(struct drbd_device *device)
{ if (atomic_dec_and_test(&device->suspend_cnt))
wake_up(&device->misc_wait);
}
int md_moved, la_size_changed; enum determine_dev_size rv = DS_UNCHANGED;
/* We may change the on-disk offsets of our meta data below. Lock out *anythingthatmaycausemetadataIO,toavoidactingonincomplete *layoutchangesorscribblingovermetadatathatisintheprocess *ofbeingmoved. * *Moveisnotexactlycorrect,btw,currentlywehaveallourmeta *dataincorememory,to"move"itwejustwriteitallout,there
* are no reads. */
drbd_suspend_io(device);
buffer = drbd_md_get_buffer(device, __func__); /* Lock meta-data IO */ if (!buffer) {
drbd_resume_io(device); return DS_ERROR;
}
if (rs) { /* rs is non NULL if we should change the AL layout only */
md->al_stripes = rs->al_stripes;
md->al_stripe_size_4k = rs->al_stripe_size / 4;
md->al_size_4k = (u64)rs->al_stripes * rs->al_stripe_size / 4;
}
if (size < prev.last_agreed_sect) { if (rs && u_size == 0) { /* Remove "rs &&" later. This check should always be active, but
right now the receiver expects the permissive behavior */
drbd_warn(device, "Implicit shrink not allowed. " "Use --size=%llus for explicit shrink.\n",
(unsignedlonglong)size);
rv = DS_ERROR_SHRINK;
} if (u_size > size)
rv = DS_ERROR_SPACE_MD; if (rv != DS_UNCHANGED) goto err_out;
}
if (get_capacity(device->vdisk) != size ||
drbd_bm_capacity(device) != size) { int err;
err = drbd_bm_resize(device, size, !(flags & DDSF_NO_RESYNC)); if (unlikely(err)) { /* currently there is only one error: ENOMEM! */
size = drbd_bm_capacity(device); if (size == 0) {
drbd_err(device, "OUT OF MEMORY! " "Could not allocate bitmap!\n");
} else {
drbd_err(device, "BM resizing failed. " "Leaving size unchanged\n");
}
rv = DS_ERROR;
} /* racy, see comments above. */
drbd_set_my_capacity(device, size);
md->la_size_sect = size;
} if (rv <= DS_ERROR) goto err_out;
if (la_size_changed || md_moved || rs) {
u32 prev_flags;
/* We do some synchronous IO below, which may take some time. *Clearthetimer,toavoidscary"timerexpired!"messages,
* "Superblock" is written out at least twice below, anyways. */
timer_delete(&device->md_sync_timer);
/* We won't change the "al-extents" setting, we just may need *tomovetheon-disklocationoftheactivitylogringbuffer. *Lockfortransactionisgoodenough,itmaywellbe"dirty"
* or even "starving". */
wait_event(device->al_wait, lc_try_lock_for_transaction(device->act_log));
/* mark current on-disk bitmap and activity log as unreliable */
prev_flags = md->flags;
md->flags |= MDF_FULL_SYNC | MDF_AL_DISABLED;
drbd_md_write(device, buffer);
drbd_al_initialize(device, buffer);
drbd_info(device, "Writing the whole bitmap, %s\n",
la_size_changed && md_moved ? "size changed and md moved" :
la_size_changed ? "size changed" : "md moved"); /* next line implicitly does drbd_suspend_io()+drbd_resume_io() */
drbd_bitmap_io(device, md_moved ? &drbd_bm_write_all : &drbd_bm_write, "size changed", BM_LOCKED_MASK, NULL);
/* on-disk bitmap and activity log is authoritative again
* (unless there was an IO error meanwhile...) */
md->flags = prev_flags;
drbd_md_write(device, buffer);
if (rs)
drbd_info(device, "Changed AL layout to al-stripes = %d, al-stripe-size-kB = %d\n",
md->al_stripes, md->al_stripe_size_4k * 4);
}
if (size > prev.last_agreed_sect)
rv = prev.last_agreed_sect ? DS_GREW : DS_GREW_FROM_ZERO; if (size < prev.last_agreed_sect)
rv = DS_SHRUNK;
sector_t
drbd_new_dev_size(struct drbd_device *device, struct drbd_backing_dev *bdev,
sector_t u_size, int assume_peer_has_space)
{
sector_t p_size = device->p_size; /* partner's disk size. */
sector_t la_size_sect = bdev->md.la_size_sect; /* last agreed size. */
sector_t m_size; /* my size */
sector_t size = 0;
m_size = drbd_get_max_capacity(bdev);
if (device->state.conn < C_CONNECTED && assume_peer_has_space) {
drbd_warn(device, "Resize while not connected was forced by the user!\n");
p_size = m_size;
}
if (p_size && m_size) {
size = min_t(sector_t, p_size, m_size);
} else { if (la_size_sect) {
size = la_size_sect; if (m_size && m_size < size)
size = m_size; if (p_size && p_size < size)
size = p_size;
} else { if (m_size)
size = m_size; if (p_size)
size = p_size;
}
}
if (size == 0)
drbd_err(device, "Both nodes diskless!\n");
if (u_size) { if (u_size > size)
drbd_err(device, "Requested disk size is too big (%lu > %lu)\n",
(unsignedlong)u_size>>1, (unsignedlong)size>>1); else
size = u_size;
}
staticunsignedint drbd_max_discard_sectors(struct drbd_connection *connection)
{ /* when we introduced REQ_WRITE_SAME support, we also bumped
* our maximum supported batch bio size used for discards. */ if (connection->agreed_features & DRBD_FF_WSAME) return DRBD_MAX_BBIO_SECTORS; /* before, with DRBD <= 8.4.6, we only allowed up to one AL_EXTENT_SIZE. */ return AL_EXTENT_SIZE >> 9;
}
if (connection->cstate >= C_CONNECTED &&
!(connection->agreed_features & DRBD_FF_TRIM)) {
drbd_info(connection, "peer DRBD too old, does not support TRIM: disabling discards\n"); returnfalse;
}
returntrue;
}
/* This is the workaround for "bio would need to, but cannot, be split" */ staticunsignedint drbd_backing_dev_max_segments(struct drbd_device *device)
{ unsignedint max_segments;
if (device->act_log &&
device->act_log->nr_elements == dc->al_extents) return0;
drbd_suspend_io(device); /* If IO completion is currently blocked, we would likely wait
* "forever" for the activity log to become unused. So we don't. */ if (atomic_read(&device->ap_bio_cnt)) goto out;
err = disk_opts_check_al_size(device, new_disk_conf); if (err) { /* Could be just "busy". Ignore?
* Introduce dedicated error code? */
drbd_msg_put_info(adm_ctx.reply_skb, "Try again without changing current al-extents setting");
retcode = ERR_NOMEM; goto fail_unlock;
}
/* if you want to reconfigure, please tear down first */ if (device->state.disk > D_DISKLESS) {
retcode = ERR_DISK_CONFIGURED; goto fail;
} /* It may just now have detached because of IO error. Make sure *drbd_ldev_destroyisdonealready,wemayenduphereveryfast, *e.g.ifsomeonecallsattachfromtheon-io-errorhandler,
* to realize a "hot spare" feature (not that I'd recommend that) */
wait_event(device->misc_wait, !test_bit(GOING_DISKLESS, &device->flags));
/* make sure there is no leftover from previous force-detach attempts */
clear_bit(FORCE_DETACH, &device->flags);
clear_bit(WAS_IO_ERROR, &device->flags);
clear_bit(WAS_READ_ERROR, &device->flags);
/* and no leftover from previously aborted resync or verify, either */
device->rs_total = 0;
device->rs_failed = 0;
atomic_set(&device->rs_pending_cnt, 0);
/* allocation not in the IO path, drbdsetup context */
nbc = kzalloc(sizeof(struct drbd_backing_dev), GFP_KERNEL); if (!nbc) {
retcode = ERR_NOMEM; goto fail;
}
spin_lock_init(&nbc->md.uuid_lock);
/* Read our meta data super block early.
* This also sets other on-disk offsets. */
retcode = drbd_md_read(device, nbc); if (retcode != NO_ERROR) goto fail;
sanitize_disk_conf(device, new_disk_conf, nbc);
if (drbd_get_max_capacity(nbc) < new_disk_conf->disk_size) {
drbd_err(device, "max capacity %llu smaller than disk size %llu\n",
(unsignedlonglong) drbd_get_max_capacity(nbc),
(unsignedlonglong) new_disk_conf->disk_size);
retcode = ERR_DISK_TOO_SMALL; goto fail;
}
if (new_disk_conf->meta_dev_idx < 0) {
max_possible_sectors = DRBD_MAX_SECTORS_FLEX; /* at least one MB, otherwise it does not make sense */
min_md_device_sectors = (2<<10);
} else {
max_possible_sectors = DRBD_MAX_SECTORS;
min_md_device_sectors = MD_128MB_SECT * (new_disk_conf->meta_dev_idx + 1);
}
if (drbd_get_capacity(nbc->md_bdev) < min_md_device_sectors) {
retcode = ERR_MD_DISK_TOO_SMALL;
drbd_warn(device, "refusing attach: md-device too small, " "at least %llu sectors needed for this meta-disk type\n",
(unsignedlonglong) min_md_device_sectors); goto fail;
}
/* Make sure the new disk is big enough
* (we may currently be R_PRIMARY with no local disk...) */ if (drbd_get_max_capacity(nbc) < get_capacity(device->vdisk)) {
retcode = ERR_DISK_TOO_SMALL; goto fail;
}
if (nbc->known_size > max_possible_sectors) {
drbd_warn(device, "==> truncating very big lower level device " "to currently maximum possible %llu sectors <==\n",
(unsignedlonglong) max_possible_sectors); if (new_disk_conf->meta_dev_idx >= 0)
drbd_warn(device, "==>> using internal or flexible " "meta data may help <<==\n");
}
drbd_suspend_io(device); /* also wait for the last barrier ack. */ /* FIXME see also https://daiquiri.linbit/cgi-bin/bugzilla/show_bug.cgi?id=171 *Weneedawaytoeitherignorebarrieracksforbarrierssentbeforeadevice *wasattached,orawaytowaitforallpendingbarrierackstocomein. *Asbarriersarecountedperresource, *we'dneedtosuspendioonalldevicesofaresource.
*/
wait_event(device->misc_wait, !atomic_read(&device->ap_pending_cnt) || drbd_suspended(device)); /* and for any other previously queued work */
drbd_flush_workqueue(&connection->sender_work);
if (!get_ldev_if_state(device, D_ATTACHING)) goto force_diskless;
if (!device->bitmap) { if (drbd_bm_init(device)) {
retcode = ERR_NOMEM; goto force_diskless_dec;
}
}
if (device->state.pdsk != D_UP_TO_DATE && device->ed_uuid &&
(device->state.role == R_PRIMARY || device->state.peer == R_PRIMARY) &&
(device->ed_uuid & ~((u64)1)) != (nbc->md.uuid[UI_CURRENT] & ~((u64)1))) {
drbd_err(device, "Can only attach to data with current UUID=%016llX\n",
(unsignedlonglong)device->ed_uuid);
retcode = ERR_DATA_NOT_CURRENT; goto force_diskless_dec;
}
/* Since we are diskless, fix the activity log first... */ if (drbd_check_al_size(device, new_disk_conf)) {
retcode = ERR_NOMEM; goto force_diskless_dec;
}
/* Prevent shrinking of consistent devices ! */
{ unsignedlonglong nsz = drbd_new_dev_size(device, nbc, nbc->disk_conf->disk_size, 0); unsignedlonglong eff = nbc->md.la_size_sect; if (drbd_md_test_flag(nbc, MDF_CONSISTENT) && nsz < eff) { if (nsz == nbc->disk_conf->disk_size) {
drbd_warn(device, "truncating a consistent device during attach (%llu < %llu)\n", nsz, eff);
} else {
drbd_warn(device, "refusing to truncate a consistent device (%llu < %llu)\n", nsz, eff);
drbd_msg_sprintf_info(adm_ctx.reply_skb, "To-be-attached device has last effective > current size, and is consistent\n" "(%llu > %llu sectors). Refusing to attach.", eff, nsz);
retcode = ERR_IMPLICIT_SHRINK; goto force_diskless_dec;
}
}
}
/* Reset the "barriers don't work" bits here, then force meta data to
* be written, to ensure we determine if barriers are supported. */ if (new_disk_conf->md_flushes)
clear_bit(MD_NO_FUA, &device->flags); else
set_bit(MD_NO_FUA, &device->flags);
/* Point of no return reached. *Devicesandmemoryarenolongerreleasedbyerrorcleanupbelow. *nowdevicetakesoverresponsibility,andthestateengineshould
* clean it up somewhere. */
D_ASSERT(device, device->ldev == NULL);
device->ldev = nbc;
device->resync = resync_lru;
device->rs_plan_s = new_plan;
nbc = NULL;
resync_lru = NULL;
new_disk_conf = NULL;
new_plan = NULL;
if (drbd_md_test_flag(device->ldev, MDF_FULL_SYNC) ||
(test_bit(CRASHED_PRIMARY, &device->flags) &&
drbd_md_test_flag(device->ldev, MDF_AL_DISABLED))) {
drbd_info(device, "Assuming that all blocks are out of sync " "(aka FullSync)\n"); if (drbd_bitmap_io(device, &drbd_bmio_set_n_write, "set_n_write from attaching", BM_LOCKED_MASK,
NULL)) {
retcode = ERR_IO_MD_DISK; goto force_diskless_dec;
}
} else { if (drbd_bitmap_io(device, &drbd_bm_read, "read from attaching", BM_LOCKED_MASK,
NULL)) {
retcode = ERR_IO_MD_DISK; goto force_diskless_dec;
}
}
if (_drbd_bm_total_weight(device) == drbd_bm_bits(device))
drbd_suspend_al(device); /* IO is still suspended here... */
spin_lock_irq(&device->resource->req_lock);
os = drbd_read_state(device);
ns = os; /* If MDF_CONSISTENT is not set go into inconsistent state, otherwiseinvestigateMDF_WasUpToDate... IfMDF_WAS_UP_TO_DATEisnotsetgointoD_OUTDATEDdiskstate, otherwiseintoD_CONSISTENTstate.
*/ if (drbd_md_test_flag(device->ldev, MDF_CONSISTENT)) { if (drbd_md_test_flag(device->ldev, MDF_WAS_UP_TO_DATE))
ns.disk = D_CONSISTENT; else
ns.disk = D_OUTDATED;
} else {
ns.disk = D_INCONSISTENT;
}
if (drbd_md_test_flag(device->ldev, MDF_PEER_OUT_DATED))
ns.pdsk = D_OUTDATED;
/* All tests on MDF_PRIMARY_IND, MDF_CONNECTED_IND, MDF_CONSISTENTandMDF_WAS_UP_TO_DATEmusthappenbefore thispoint,becausedrbd_request_state()modifiesthese
flags. */
if (rcu_dereference(device->ldev->disk_conf)->al_updates)
device->ldev->md.flags &= ~MDF_AL_DISABLED; else
device->ldev->md.flags |= MDF_AL_DISABLED;
rcu_read_unlock();
/* In case we are C_CONNECTED postpone any decision on the new disk
state after the negotiation phase. */ if (device->state.conn == C_CONNECTED) {
device->new_state_tmp.i = ns.i;
ns.i = os.i;
ns.disk = D_NEGOTIATING;
/* We expect to receive up-to-date UUIDs soon. Toavoidaraceinreceive_state,freep_uuidwhile
holding req_lock. I.e. atomic with the state change */
kfree(device->p_uuid);
device->p_uuid = NULL;
}
/* Detaching the disk is a process in multiple stages. First we need to lock *outapplicationIO,in-flightIO,IOstuckindrbd_al_begin_io. *ThenwetransitiontoD_DISKLESS,andwaitforput_ldev()toreturnall *internalreferencesaswell.
* Only then we have finally detached. */ int drbd_adm_detach(struct sk_buff *skb, struct genl_info *info)
{ struct drbd_config_context adm_ctx; enum drbd_ret_code retcode; struct detach_parms parms = { }; int err;
retcode = drbd_adm_prepare(&adm_ctx, skb, info, DRBD_ADM_NEED_MINOR); if (!adm_ctx.reply_skb) return retcode; if (retcode != NO_ERROR) goto out;
if (info->attrs[DRBD_NLA_DETACH_PARMS]) {
err = detach_parms_from_attrs(&parms, info); if (err) {
retcode = ERR_MANDATORY_TAG;
drbd_msg_put_info(adm_ctx.reply_skb, from_attrs_err_to_txt(err)); goto out;
}
}
crypto_free_shash(connection->integrity_tfm);
connection->integrity_tfm = crypto.integrity_tfm; if (connection->cstate >= C_WF_REPORT_PARAMS && connection->agreed_pro_version >= 100) /* Do this without trying to take connection->data.mutex again. */
__drbd_send_protocol(connection, P_PROTOCOL_UPDATE);
switch (rv) { case SS_NOTHING_TO_DO: break; case SS_ALREADY_STANDALONE: return SS_SUCCESS; case SS_PRIMARY_NOP: /* Our state checking code wants to see the peer outdated. */
rv = conn_request_state(connection, NS2(conn, C_DISCONNECTING, pdsk, D_OUTDATED), 0);
if (rv == SS_OUTDATE_WO_CONN) /* lost connection before graceful disconnect succeeded */
rv = conn_request_state(connection, NS(conn, C_DISCONNECTING), CS_VERBOSE);
break; case SS_CW_FAILED_BY_PEER:
spin_lock_irq(&connection->resource->req_lock);
cstate = connection->cstate;
spin_unlock_irq(&connection->resource->req_lock); if (cstate <= C_WF_CONNECTION) goto repeat; /* The peer probably wants to see us outdated. */
rv = conn_request_state(connection, NS2(conn, C_DISCONNECTING,
disk, D_OUTDATED), 0); if (rv == SS_IS_DISKLESS || rv == SS_LOWER_THAN_OUTDATED) {
rv = conn_request_state(connection, NS(conn, C_DISCONNECTING),
CS_HARD);
} break; default:; /* no special handling necessary */
}
if (rv >= SS_SUCCESS) { enum drbd_state_rv rv2; /* No one else can reconfigure the network while I am here. *Thestatehandlingonlyusesdrbd_thread_stop_nowait(), *wewanttoreallywaithereuntilthereceiverisnomore.
*/
drbd_thread_stop(&connection->receiver);
/* Race breaker. This additional state change request may be *necessary,ifthiswasaforceddisconnectduringareceiver *restart.Wemayhave"killed"thereceiverthreadjust *afterdrbd_receiver()returned.Typically,weshouldbe *C_STANDALONEalready,now,andthisbecomesano-op.
*/
rv2 = conn_request_state(connection, NS(conn, C_STANDALONE),
CS_VERBOSE | CS_HARD); if (rv2 < SS_SUCCESS)
drbd_err(connection, "unexpected rv2=%d in conn_try_disconnect()\n",
rv2); /* Unlike in DRBD 9, the state engine has generated
* NOTIFY_DESTROY events before clearing connection->net_conf. */
} return rv;
}
/* If there is still bitmap IO pending, probably because of a previous *resyncjustbeingfinished,waitforitbeforerequestinganewresync.
* Also wait for it's after_state_ch(). */
drbd_suspend_io(device);
wait_event(device->misc_wait, !test_bit(BITMAP_IO, &device->flags));
drbd_flush_workqueue(&first_peer_device(device)->connection->sender_work);
/* If we happen to be C_STANDALONE R_SECONDARY, just change to *D_INCONSISTENT,andsetallbitsinthebitmap.Otherwise, *trytostartaresynchandshakeassynctargetforfullsync.
*/ if (device->state.conn == C_STANDALONE && device->state.role == R_SECONDARY) {
retcode = drbd_request_state(device, NS(disk, D_INCONSISTENT)); if (retcode >= SS_SUCCESS) { if (drbd_bitmap_io(device, &drbd_bmio_set_n_write, "set_n_write from invalidate", BM_LOCKED_MASK, NULL))
retcode = ERR_IO_MD_DISK;
}
} else
retcode = drbd_request_state(device, NS(conn, C_STARTING_SYNC_T));
drbd_resume_io(device);
mutex_unlock(&adm_ctx.resource->adm_mutex);
put_ldev(device);
out:
drbd_adm_finish(&adm_ctx, info, retcode); return0;
}
staticint drbd_adm_simple_request_state(struct sk_buff *skb, struct genl_info *info, union drbd_state mask, union drbd_state val)
{ struct drbd_config_context adm_ctx; enum drbd_ret_code retcode;
retcode = drbd_adm_prepare(&adm_ctx, skb, info, DRBD_ADM_NEED_MINOR); if (!adm_ctx.reply_skb) return retcode; if (retcode != NO_ERROR) goto out;
/* If there is still bitmap IO pending, probably because of a previous *resyncjustbeingfinished,waitforitbeforerequestinganewresync.
* Also wait for it's after_state_ch(). */
drbd_suspend_io(device);
wait_event(device->misc_wait, !test_bit(BITMAP_IO, &device->flags));
drbd_flush_workqueue(&first_peer_device(device)->connection->sender_work);
/* If we happen to be C_STANDALONE R_PRIMARY, just set all bits *inthebitmap.Otherwise,trytostartaresynchandshake *assyncsourceforfullsync.
*/ if (device->state.conn == C_STANDALONE && device->state.role == R_PRIMARY) { /* The peer will get a resync upon connect anyways. Just make that
into a full resync. */
retcode = drbd_request_state(device, NS(pdsk, D_INCONSISTENT)); if (retcode >= SS_SUCCESS) { if (drbd_bitmap_io(device, &drbd_bmio_set_susp_al, "set_n_write from invalidate_peer",
BM_LOCKED_SET_ALLOWED, NULL))
retcode = ERR_IO_MD_DISK;
}
} else
retcode = drbd_request_state(device, NS(conn, C_STARTING_SYNC_S));
drbd_resume_io(device);
mutex_unlock(&adm_ctx.resource->adm_mutex);
put_ldev(device);
out:
drbd_adm_finish(&adm_ctx, info, retcode); return0;
}
staticint nla_put_status_info(struct sk_buff *skb, struct drbd_device *device, conststruct sib_info *sib)
{ struct drbd_resource *resource = device->resource; struct state_info *si = NULL; /* for sizeof(si->member); */ struct nlattr *nla; int got_ldev; int err = 0; int exclude_sensitive;
/* If sib != NULL, this is drbd_bcast_event, which anyone can listen *to.Sowebetterexclude_sensitiveinformation. * *Ifsib==NULL,thisisdrbd_adm_get_status,executedsynchronously *inthecontextoftherequestinguserprocess.Excludesensitive *information,unlesscurrenthassuperuser. * *NOTE:fordrbd_adm_get_status_all(),thisisanetlinkdump,and *reliesonthecurrentimplementationofnetlink_dump(),which *executesthedumpcallbacksuccessivelyfromnetlink_recvmsg(),
* always in the context of the receiving process */
exclude_sensitive = sib || !capable(CAP_SYS_ADMIN);
got_ldev = get_ldev(device);
/* We need to add connection name and volume number information still.
* Minor number is in drbd_genlmsghdr. */ if (nla_put_drbd_cfg_context(skb, resource, the_only_connection(resource), device)) goto nla_put_failure;
if (res_opts_to_skb(skb, &device->resource->res_opts, exclude_sensitive)) goto nla_put_failure;
rcu_read_lock(); if (got_ldev) { struct disk_conf *disk_conf;
if (sib) { switch(sib->sib_reason) { case SIB_SYNC_PROGRESS: case SIB_GET_STATUS_REPLY: break; case SIB_STATE_CHANGE: if (nla_put_u32(skb, T_prev_state, sib->os.i) ||
nla_put_u32(skb, T_new_state, sib->ns.i)) goto nla_put_failure; break; case SIB_HELPER_POST: if (nla_put_u32(skb, T_helper_exit_code,
sib->helper_exit_code)) goto nla_put_failure;
fallthrough; case SIB_HELPER_PRE: if (nla_put_string(skb, T_helper, sib->helper_name)) goto nla_put_failure; break;
}
}
nla_nest_end(skb, nla);
if (0)
nla_put_failure:
err = -EMSGSIZE; if (got_ldev)
put_ldev(device); return err;
}
int drbd_adm_get_status(struct sk_buff *skb, struct genl_info *info)
{ struct drbd_config_context adm_ctx; enum drbd_ret_code retcode; int err;
retcode = drbd_adm_prepare(&adm_ctx, skb, info, DRBD_ADM_NEED_MINOR); if (!adm_ctx.reply_skb) return retcode; if (retcode != NO_ERROR) goto out;
/* synchronize with conn_create()/drbd_destroy_connection() */
rcu_read_lock(); /* revalidate iterator position */
for_each_resource_rcu(tmp, &drbd_resources) { if (pos == NULL) { /* first iteration */
pos = tmp;
resource = pos; break;
} if (tmp == pos) {
resource = pos; break;
}
} if (resource) {
next_resource:
device = idr_get_next(&resource->devices, &volume); if (!device) { /* No more volumes to dump on this resource.
* Advance resource iterator. */
pos = list_entry_rcu(resource->resources.next, struct drbd_resource, resources); /* Did we dump any volume of this resource yet? */ if (volume != 0) { /* If we reached the end of the list, *oronlyasingleresourcedumpwasrequested,
* we are done. */ if (&pos->resources == &drbd_resources || cb->args[2]) goto out;
volume = 0;
resource = pos; goto next_resource;
}
}
if (!device) { /* This is a connection without a single volume. *Suprisinglyenough,itmayhaveanetwork
* configuration. */ struct drbd_connection *connection;
/* Is this a followup call? */ if (cb->args[0]) { /* ... of a single resource dump,
* and the resource iterator has been advanced already? */ if (cb->args[2] && cb->args[2] != cb->args[0]) return0; /* DONE. */ goto dump;
}
/* First call (from netlink_dump_start). We need to figure out
* which resource(s) the user wants us to dump. */
nla = nla_find(nlmsg_attrdata(cb->nlh, hdrlen),
nlmsg_attrlen(cb->nlh, hdrlen),
DRBD_NLA_CFG_CONTEXT);
/* No explicit context given. Dump all. */ if (!nla) goto dump;
maxtype = ARRAY_SIZE(drbd_cfg_context_nl_policy) - 1;
nla = drbd_nla_find_nested(maxtype, nla, __nla_type(T_ctx_resource_name)); if (IS_ERR(nla)) return PTR_ERR(nla); /* context given, but no name present? */ if (!nla) return -EINVAL;
resource_name = nla_data(nla); if (!*resource_name) return -ENODEV;
resource = drbd_find_resource(resource_name); if (!resource) return -ENODEV;
kref_put(&resource->kref, drbd_destroy_resource); /* get_one_status() revalidates the resource */
/* prime iterators, and set "filter" mode mark:
* only dump this connection. */
cb->args[0] = (long)resource; /* cb->args[1] = 0; passed in this way. */
cb->args[2] = (long)resource;
dump: return get_one_status(skb, cb);
}
int drbd_adm_get_timeout_type(struct sk_buff *skb, struct genl_info *info)
{ struct drbd_config_context adm_ctx; enum drbd_ret_code retcode; struct timeout_parms tp; int err;
retcode = drbd_adm_prepare(&adm_ctx, skb, info, DRBD_ADM_NEED_MINOR); if (!adm_ctx.reply_skb) return retcode; if (retcode != NO_ERROR) goto out;
retcode = drbd_adm_prepare(&adm_ctx, skb, info, DRBD_ADM_NEED_MINOR); if (!adm_ctx.reply_skb) return retcode; if (retcode != NO_ERROR) goto out;
device = adm_ctx.device;
/* resume from last known position, if possible */
parms.ov_start_sector = device->ov_start_sector;
parms.ov_stop_sector = ULLONG_MAX; if (info->attrs[DRBD_NLA_START_OV_PARMS]) { int err = start_ov_parms_from_attrs(&parms, info); if (err) {
retcode = ERR_MANDATORY_TAG;
drbd_msg_put_info(adm_ctx.reply_skb, from_attrs_err_to_txt(err)); goto out;
}
}
mutex_lock(&adm_ctx.resource->adm_mutex);
/* w_make_ov_request expects position to be aligned */
device->ov_start_sector = parms.ov_start_sector & ~(BM_SECT_PER_BIT-1);
device->ov_stop_sector = parms.ov_stop_sector;
/* If there is still bitmap IO pending, e.g. previous resync or verify
* just being finished, wait for it before requesting a new resync. */
drbd_suspend_io(device);
wait_event(device->misc_wait, !test_bit(BITMAP_IO, &device->flags));
retcode = drbd_request_state(device, NS(conn, C_VERIFY_S));
drbd_resume_io(device);
mutex_lock(&adm_ctx.resource->adm_mutex);
mutex_lock(device->state_mutex); /* Protects us against serialized state changes. */
if (!get_ldev(device)) {
retcode = ERR_NO_DISK; goto out;
}
/* this is "skip initial sync", assume to be clean */ if (device->state.conn == C_CONNECTED &&
first_peer_device(device)->connection->agreed_pro_version >= 90 &&
device->ldev->md.uuid[UI_CURRENT] == UUID_JUST_CREATED && args.clear_bm) {
drbd_info(device, "Preparing to skip initial sync\n");
skip_initial_sync = 1;
} elseif (device->state.conn != C_STANDALONE) {
retcode = ERR_CONNECTED; goto out_dec;
}
drbd_uuid_set(device, UI_BITMAP, 0); /* Rotate UI_BITMAP to History 1, etc... */
drbd_uuid_new_current(device); /* New current, previous to UI_BITMAP */
if (args.clear_bm) {
err = drbd_bitmap_io(device, &drbd_bmio_clear_n_write, "clear_n_write from new_c_uuid", BM_LOCKED_MASK, NULL); if (err) {
drbd_err(device, "Writing bitmap failed with %d\n", err);
retcode = ERR_IO_MD_DISK;
} if (skip_initial_sync) {
drbd_send_uuids_skip_initial_sync(first_peer_device(device));
_drbd_uuid_set(device, UI_BITMAP, 0);
drbd_print_uuids(device, "cleared bitmap UUID");
spin_lock_irq(&device->resource->req_lock);
_drbd_set_state(_NS2(device, disk, D_UP_TO_DATE, pdsk, D_UP_TO_DATE),
CS_VERBOSE, NULL);
spin_unlock_irq(&device->resource->req_lock);
}
}
staticenum drbd_ret_code
drbd_check_resource_name(struct drbd_config_context *adm_ctx)
{ constchar *name = adm_ctx->resource_name; if (!name || !name[0]) {
drbd_msg_put_info(adm_ctx->reply_skb, "resource name missing"); return ERR_MANDATORY_TAG;
} /* if we want to use these in sysfs/configfs/debugfs some day,
* we must not allow slashes */ if (strchr(name, '/')) {
drbd_msg_put_info(adm_ctx->reply_skb, "invalid resource name"); return ERR_INVALID_REQUEST;
} return NO_ERROR;
}
retcode = drbd_adm_prepare(&adm_ctx, skb, info, DRBD_ADM_NEED_RESOURCE); if (!adm_ctx.reply_skb) return retcode; if (retcode != NO_ERROR) goto out;
if (dh->minor > MINORMASK) {
drbd_msg_put_info(adm_ctx.reply_skb, "requested minor out of range");
retcode = ERR_INVALID_REQUEST; goto out;
} if (adm_ctx.volume > DRBD_VOLUME_MAX) {
drbd_msg_put_info(adm_ctx.reply_skb, "requested volume id out of range");
retcode = ERR_INVALID_REQUEST; goto out;
}
/* drbd_adm_prepare made sure already
* that first_peer_device(device)->connection and device->vnr match the request. */ if (adm_ctx.device) { if (info->nlhdr->nlmsg_flags & NLM_F_EXCL)
retcode = ERR_MINOR_OR_VOLUME_EXISTS; /* else: still NO_ERROR */ goto out;
}
if (device->state.disk == D_DISKLESS && /* no need to be device->state.conn == C_STANDALONE && *wemaywanttodeleteaminorfromalivereplicationgroup.
*/
device->state.role == R_SECONDARY) { struct drbd_connection *connection =
first_connection(device->resource);
/* If the state engine hasn't stopped the sender thread yet, we *needtoflushthesenderworkqueuebeforegeneratingthe
* DESTROY events here. */ if (get_t_state(&connection->worker) == RUNNING)
drbd_flush_workqueue(&connection->sender_work);
for_each_connection(connection, resource) { if (connection->cstate > C_STANDALONE) return ERR_NET_CONFIGURED;
} if (!idr_is_empty(&resource->devices)) return ERR_RES_IN_USE;
/* The state engine has stopped the sender thread, so we don't *needtoflushthesenderworkqueuebeforegeneratingthe
* DESTROY event here. */
mutex_lock(¬ification_mutex);
notify_resource_state(NULL, 0, resource, NULL, NOTIFY_DESTROY);
mutex_unlock(¬ification_mutex);
mutex_lock(&resources_mutex);
list_del_rcu(&resource->resources);
mutex_unlock(&resources_mutex); /* Make sure all threads have actually stopped: state handling only
* does drbd_thread_stop_nowait(). */
list_for_each_entry(connection, &resource->connections, connections)
drbd_thread_stop(&connection->worker);
synchronize_rcu();
drbd_free_resource(resource); return NO_ERROR;
}
if (nla_put_status_info(msg, device, sib)) goto nla_put_failure;
genlmsg_end(msg, d_out);
err = drbd_genl_multicast_events(msg, GFP_NOWAIT); /* msg has been consumed or freed in netlink_broadcast() */ if (err && err != -ESRCH) goto failed;
/* There is no need for taking notification_mutex here: it doesn't matteriftheinitialstateeventsmixwithlaterstatechage events;wecanalwaystelltheeventsapartbytheNOTIFY_EXISTS
flag. */
¤ Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.0.135Bemerkung:
(vorverarbeitet am 2026-09-28)
¤
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.