2 * Copyright 2006-2007, Sine Nomine Associates and others.
5 * This software has been released under the terms of the IBM Public
6 * License. For details, see the LICENSE file in the top-level source
7 * directory or online at http://www.openafs.org/dl/license10.html
12 * online salvager daemon
15 /* Main program file. Define globals. */
18 #include <afsconfig.h>
19 #include <afs/param.h>
31 #include <WINNT/afsevent.h>
33 #include <sys/param.h>
37 #endif /* ITIMER_REAL */
40 #define WCOREDUMP(x) ((x) & 0200)
43 #include <afs/afsint.h>
44 #include <afs/assert.h>
45 #if !defined(AFS_SGI_ENV) && !defined(AFS_NT40_ENV)
46 #if defined(AFS_VFSINCL_ENV)
47 #include <sys/vnode.h>
49 #include <sys/fs/ufs_inode.h>
51 #if defined(AFS_DARWIN_ENV) || defined(AFS_XBSD_ENV)
52 #include <ufs/ufs/dinode.h>
53 #include <ufs/ffs/fs.h>
55 #include <ufs/inode.h>
58 #else /* AFS_VFSINCL_ENV */
60 #include <ufs/inode.h>
61 #else /* AFS_OSF_ENV */
62 #if !defined(AFS_LINUX20_ENV) && !defined(AFS_XBSD_ENV)
63 #include <sys/inode.h>
66 #endif /* AFS_VFSINCL_ENV */
67 #endif /* AFS_SGI_ENV */
70 #include <sys/lockf.h>
74 #include <checklist.h>
76 #if defined(AFS_SGI_ENV)
81 #if defined(AFS_SUN_ENV) || defined(AFS_SUN5_ENV)
84 #include <sys/mnttab.h>
85 #include <sys/mntent.h>
90 #endif /* AFS_SGI_ENV */
91 #endif /* AFS_HPUX_ENV */
96 #include <afs/osi_inode.h>
99 #include <afs/afsutil.h>
100 #include <afs/fileutil.h>
101 #include <afs/procmgmt.h> /* signal(), kill(), wait(), etc. */
110 #include <afs/afssyscalls.h>
114 #include "partition.h"
115 #include "daemon_com.h"
117 #include "salvsync.h"
118 #include "viceinode.h"
120 #include "vol-salvage.h"
126 #if !defined(AFS_DEMAND_ATTACH_FS)
127 #error "online salvager only supported for demand attach fileserver"
128 #endif /* AFS_DEMAND_ATTACH_FS */
130 #if defined(AFS_NT40_ENV)
131 #error "online salvager not supported on NT"
132 #endif /* AFS_NT40_ENV */
135 /* Forward declarations */
136 /*@printflike@*/ void Log(const char *format, ...);
137 /*@printflike@*/ void Abort(const char *format, ...);
140 /*@+fcnmacros +macrofcndecl@*/
142 #define afs_fopen fopen64
143 #else /* !O_LARGEFILE */
144 #define afs_fopen fopen
145 #endif /* !O_LARGEFILE */
146 /*@=fcnmacros =macrofcndecl@*/
150 static volatile int current_workers = 0;
151 static volatile struct rx_queue pending_q;
152 static pthread_mutex_t worker_lock;
153 static pthread_cond_t worker_cv;
155 static void * SalvageChildReaperThread(void *);
156 static int DoSalvageVolume(struct SalvageQueueNode * node, int slot);
158 static void SalvageServer(void);
159 static void SalvageClient(VolumeId vid, char * pname);
161 static int Reap_Child(char * prog, int * pid, int * status);
163 static void * SalvageLogCleanupThread(void *);
164 static int SalvageLogCleanup(int pid);
166 static void * SalvageLogScanningThread(void *);
167 static void ScanLogs(struct rx_queue *log_watch_queue);
169 struct log_cleanup_node {
175 struct rx_queue queue_head;
176 pthread_cond_t queue_change_cv;
180 #define DEFAULT_PARALLELISM 4 /* allow 4 parallel salvage workers by default */
183 handleit(struct cmd_syndesc *as, void *arock)
185 register struct cmd_item *ti;
186 char pname[100], *temp;
187 afs_int32 seenpart = 0, seenvol = 0, vid = 0;
189 #ifdef AFS_SGI_VNODE_GLUE
190 if (afs_init_kernel_config(-1) < 0) {
192 ("Can't determine NUMA configuration, not starting salvager.\n");
197 if (as->parms[2].items) /* -debug */
199 if (as->parms[3].items) /* -nowrite */
201 if (as->parms[4].items) /* -inodes */
203 if (as->parms[5].items) /* -oktozap */
205 if (as->parms[6].items) /* -rootinodes */
207 if (as->parms[8].items) /* -ForceReads */
209 if ((ti = as->parms[9].items)) { /* -Parallel # */
211 if (strncmp(temp, "all", 3) == 0) {
215 if (strlen(temp) != 0) {
216 Parallel = atoi(temp);
219 if (Parallel > MAXPARALLEL) {
220 printf("Setting parallel salvages to maximum of %d \n",
222 Parallel = MAXPARALLEL;
226 Parallel = MIN(DEFAULT_PARALLELISM, MAXPARALLEL);
228 if ((ti = as->parms[10].items)) { /* -tmpdir */
232 dirp = opendir(tmpdir);
235 ("Can't open temporary placeholder dir %s; using current partition \n",
241 if ((ti = as->parms[11].items)) /* -showlog */
243 if ((ti = as->parms[12].items)) { /* -orphans */
245 orphans = ORPH_IGNORE;
246 else if (strcmp(ti->data, "remove") == 0
247 || strcmp(ti->data, "r") == 0)
248 orphans = ORPH_REMOVE;
249 else if (strcmp(ti->data, "attach") == 0
250 || strcmp(ti->data, "a") == 0)
251 orphans = ORPH_ATTACH;
253 #ifndef AFS_NT40_ENV /* ignore options on NT */
254 if ((ti = as->parms[13].items)) { /* -syslog */
258 if ((ti = as->parms[14].items)) { /* -syslogfacility */
259 useSyslogFacility = atoi(ti->data);
262 if ((ti = as->parms[15].items)) { /* -datelogs */
263 TimeStampLogFile((char *)AFSDIR_SERVER_SALSRVLOG_FILEPATH);
267 if ((ti = as->parms[16].items)) { /* -client */
268 if ((ti = as->parms[0].items)) { /* -partition */
270 strlcpy(pname, ti->data, sizeof(pname));
272 if ((ti = as->parms[1].items)) { /* -volumeid */
274 vid = atoi(ti->data);
278 printf("-showlog does not work with -client\n");
282 if (!seenpart || !seenvol) {
283 printf("You must specify '-partition' and '-volumeid' with the '-client' option\n");
287 SalvageClient(vid, pname);
289 } else { /* salvageserver mode */
297 #include "AFS_component_version_number.c"
301 char *save_args[MAX_ARGS];
303 pthread_t main_thread;
306 static char commandLine[150];
309 main(int argc, char **argv)
311 struct cmd_syndesc *ts;
318 * The following signal action for AIX is necessary so that in case of a
319 * crash (i.e. core is generated) we can include the user's data section
320 * in the core dump. Unfortunately, by default, only a partial core is
321 * generated which, in many cases, isn't too useful.
323 struct sigaction nsa;
325 sigemptyset(&nsa.sa_mask);
326 nsa.sa_handler = SIG_DFL;
327 nsa.sa_flags = SA_FULLDUMP;
328 sigaction(SIGABRT, &nsa, NULL);
329 sigaction(SIGSEGV, &nsa, NULL);
332 /* Initialize directory paths */
333 if (!(initAFSDirPath() & AFSDIR_SERVER_PATHS_OK)) {
335 ReportErrorEventAlt(AFSEVT_SVR_NO_INSTALL_DIR, 0, argv[0], 0);
337 fprintf(stderr, "%s: Unable to obtain AFS server directory.\n",
342 main_thread = pthread_self();
343 if (spawnDatap && spawnDataLen) {
344 /* This is a child per partition salvager. Don't setup log or
345 * try to lock the salvager lock.
347 if (nt_SetupPartitionSalvage(spawnDatap, spawnDataLen) < 0)
351 for (commandLine[0] = '\0', i = 0; i < argc; i++) {
353 strlcat(commandLine, " ", sizeof(commandLine));
354 strlcat(commandLine, argv[i], sizeof(commandLine));
358 if (geteuid() != 0) {
359 printf("Salvager must be run as root.\n");
365 /* bad for normal help flag processing, but can do nada */
371 ts = cmd_CreateSyntax("initcmd", handleit, NULL, "initialize the program");
372 cmd_AddParm(ts, "-partition", CMD_SINGLE, CMD_OPTIONAL,
373 "Name of partition to salvage");
374 cmd_AddParm(ts, "-volumeid", CMD_SINGLE, CMD_OPTIONAL,
375 "Volume Id to salvage");
376 cmd_AddParm(ts, "-debug", CMD_FLAG, CMD_OPTIONAL,
377 "Run in Debugging mode");
378 cmd_AddParm(ts, "-nowrite", CMD_FLAG, CMD_OPTIONAL,
379 "Run readonly/test mode");
380 cmd_AddParm(ts, "-inodes", CMD_FLAG, CMD_OPTIONAL,
381 "Just list affected afs inodes - debugging flag");
382 cmd_AddParm(ts, "-oktozap", CMD_FLAG, CMD_OPTIONAL,
383 "Give permission to destroy bogus inodes/volumes - debugging flag");
384 cmd_AddParm(ts, "-rootinodes", CMD_FLAG, CMD_OPTIONAL,
385 "Show inodes owned by root - debugging flag");
386 cmd_AddParm(ts, "-salvagedirs", CMD_FLAG, CMD_OPTIONAL,
387 "Force rebuild/salvage of all directories");
388 cmd_AddParm(ts, "-blockreads", CMD_FLAG, CMD_OPTIONAL,
389 "Read smaller blocks to handle IO/bad blocks");
390 cmd_AddParm(ts, "-parallel", CMD_SINGLE, CMD_OPTIONAL,
391 "# of max parallel partition salvaging");
392 cmd_AddParm(ts, "-tmpdir", CMD_SINGLE, CMD_OPTIONAL,
393 "Name of dir to place tmp files ");
394 cmd_AddParm(ts, "-showlog", CMD_FLAG, CMD_OPTIONAL,
395 "Show log file upon completion");
396 cmd_AddParm(ts, "-orphans", CMD_SINGLE, CMD_OPTIONAL,
397 "ignore | remove | attach");
399 /* note - syslog isn't avail on NT, but if we make it conditional, have
400 * to deal with screwy offsets for cmd params */
401 cmd_AddParm(ts, "-syslog", CMD_FLAG, CMD_OPTIONAL,
402 "Write salvage log to syslogs");
403 cmd_AddParm(ts, "-syslogfacility", CMD_SINGLE, CMD_OPTIONAL,
404 "Syslog facility number to use");
405 cmd_AddParm(ts, "-datelogs", CMD_FLAG, CMD_OPTIONAL,
406 "Include timestamp in logfile filename");
408 cmd_AddParm(ts, "-client", CMD_FLAG, CMD_OPTIONAL,
409 "Use SALVSYNC to ask salvageserver to salvage a volume");
411 err = cmd_Dispatch(argc, argv);
413 return 0; /* not reached */
417 SalvageClient(VolumeId vid, char * pname)
422 SALVSYNC_response_hdr sres;
423 VolumePackageOptions opts;
425 VOptDefaults(volumeUtility, &opts);
426 if (VInitVolumePackage2(volumeUtility, &opts)) {
427 /* VInitVolumePackage2 can fail on e.g. partition attachment errors,
428 * but we don't really care, since all we're doing is trying to use
430 fprintf(stderr, "errors encountered initializing volume package, but "
431 "trying to continue anyway\n");
433 SALVSYNC_clientInit();
435 code = SALVSYNC_SalvageVolume(vid, pname, SALVSYNC_SALVAGE, SALVSYNC_OPERATOR, 0, NULL);
436 if (code != SYNC_OK) {
440 res.payload.buf = (void *) &sres;
441 res.payload.len = sizeof(sres);
445 code = SALVSYNC_SalvageVolume(vid, pname, SALVSYNC_QUERY, SALVSYNC_WHATEVER, 0, &res);
446 if (code != SYNC_OK) {
449 switch (sres.state) {
450 case SALVSYNC_STATE_ERROR:
451 printf("salvageserver reports salvage ended in an error; check log files for more details\n");
452 case SALVSYNC_STATE_DONE:
453 case SALVSYNC_STATE_UNKNOWN:
457 SALVSYNC_clientFinis();
461 if (code == SYNC_DENIED) {
462 printf("salvageserver refused to salvage volume %u on partition %s\n",
464 } else if (code == SYNC_BAD_COMMAND) {
465 printf("SALVSYNC protocol mismatch; please make sure fileserver, volserver, salvageserver and salvager are same version\n");
466 } else if (code == SYNC_COM_ERROR) {
467 printf("SALVSYNC communications error\n");
469 SALVSYNC_clientFinis();
473 static int * child_slot;
479 struct SalvageQueueNode * node;
481 pthread_attr_t attrs;
483 VolumePackageOptions opts;
485 /* All entries to the log will be appended. Useful if there are
486 * multiple salvagers appending to the log.
489 CheckLogFile((char *)AFSDIR_SERVER_SALSRVLOG_FILEPATH);
491 #ifdef AFS_LINUX20_ENV
492 fcntl(fileno(logFile), F_SETFL, O_APPEND); /* Isn't this redundant? */
494 fcntl(fileno(logFile), F_SETFL, FAPPEND); /* Isn't this redundant? */
499 fprintf(logFile, "%s\n", cml_version_number);
500 Log("Starting OpenAFS Online Salvage Server %s (%s)\n", SalvageVersion, commandLine);
502 /* Get and hold a lock for the duration of the salvage to make sure
503 * that no other salvage runs at the same time. The routine
504 * VInitVolumePackage2 (called below) makes sure that a file server or
505 * other volume utilities don't interfere with the salvage.
508 /* even demand attach online salvager
509 * still needs this because we don't want
510 * a stand-alone salvager to conflict with
511 * the salvager daemon */
512 ObtainSharedSalvageLock();
514 child_slot = (int *) malloc(Parallel * sizeof(int));
515 assert(child_slot != NULL);
516 memset(child_slot, 0, Parallel * sizeof(int));
518 /* initialize things */
519 VOptDefaults(salvageServer, &opts);
520 if (VInitVolumePackage2(salvageServer, &opts)) {
521 Log("Shutting down: errors encountered initializing volume package\n");
525 queue_Init(&pending_q);
526 queue_Init(&log_cleanup_queue);
527 assert(pthread_mutex_init(&worker_lock, NULL) == 0);
528 assert(pthread_cond_init(&worker_cv, NULL) == 0);
529 assert(pthread_cond_init(&log_cleanup_queue.queue_change_cv, NULL) == 0);
530 assert(pthread_attr_init(&attrs) == 0);
532 /* start up the reaper and log cleaner threads */
533 assert(pthread_attr_setdetachstate(&attrs, PTHREAD_CREATE_DETACHED) == 0);
534 assert(pthread_create(&tid,
536 &SalvageChildReaperThread,
538 assert(pthread_create(&tid,
540 &SalvageLogCleanupThread,
542 assert(pthread_create(&tid,
544 &SalvageLogScanningThread,
547 /* loop forever serving requests */
549 node = SALVSYNC_getWork();
550 assert(node != NULL);
552 Log("dispatching child to salvage volume %u...\n",
553 node->command.sop.parent);
557 for (slot = 0; slot < Parallel; slot++) {
558 if (!child_slot[slot])
561 assert (slot < Parallel);
567 ret = DoSalvageVolume(node, slot);
569 } else if (pid < 0) {
570 Log("failed to fork child worker process\n");
574 child_slot[slot] = pid;
578 assert(pthread_mutex_lock(&worker_lock) == 0);
581 /* let the reaper thread know another worker was spawned */
582 assert(pthread_cond_broadcast(&worker_cv) == 0);
584 /* if we're overquota, wait for the reaper */
585 while (current_workers >= Parallel) {
586 assert(pthread_cond_wait(&worker_cv, &worker_lock) == 0);
588 assert(pthread_mutex_unlock(&worker_lock) == 0);
594 DoSalvageVolume(struct SalvageQueueNode * node, int slot)
596 char childLog[AFSDIR_PATH_MAX];
597 struct DiskPartition64 * partP;
599 /* do not allow further forking inside salvager */
602 /* do not attempt to close parent's logFile handle as
603 * another thread may have held the lock on the FILE
604 * structure when fork was called! */
606 afs_snprintf(childLog, sizeof(childLog), "%s.%d",
607 AFSDIR_SERVER_SLVGLOG_FILEPATH, getpid());
609 logFile = afs_fopen(childLog, "a");
610 if (!logFile) { /* still nothing, use stdout */
615 if (node->command.sop.parent <= 0) {
616 Log("salvageServer: invalid volume id specified; salvage aborted\n");
620 partP = VGetPartition(node->command.sop.partName, 0);
622 Log("salvageServer: Unknown or unmounted partition %s; salvage aborted\n",
623 node->command.sop.partName);
627 /* obtain a shared salvage lock in the child worker, so if the
628 * salvageserver restarts (and we continue), we will still hold a lock and
629 * prevent standalone salvagers from interfering */
630 ObtainSharedSalvageLock();
632 /* Salvage individual volume; don't notify fs */
633 SalvageFileSys1(partP, node->command.sop.parent);
641 SalvageChildReaperThread(void * args)
643 int slot, pid, status;
644 struct log_cleanup_node * cleanup;
646 assert(pthread_mutex_lock(&worker_lock) == 0);
648 /* loop reaping our children */
650 /* wait() won't block unless we have children, so
651 * block on the cond var if we're childless */
652 while (current_workers == 0) {
653 assert(pthread_cond_wait(&worker_cv, &worker_lock) == 0);
656 assert(pthread_mutex_unlock(&worker_lock) == 0);
658 cleanup = (struct log_cleanup_node *) malloc(sizeof(struct log_cleanup_node));
660 while (Reap_Child("salvageserver", &pid, &status) < 0) {
661 /* try to prevent livelock if something goes wrong */
666 for (slot = 0; slot < Parallel; slot++) {
667 if (child_slot[slot] == pid)
670 assert(slot < Parallel);
671 child_slot[slot] = 0;
674 SALVSYNC_doneWorkByPid(pid, status);
676 assert(pthread_mutex_lock(&worker_lock) == 0);
680 queue_Append(&log_cleanup_queue, cleanup);
681 assert(pthread_cond_signal(&log_cleanup_queue.queue_change_cv) == 0);
684 /* ok, we've reaped a child */
686 assert(pthread_cond_broadcast(&worker_cv) == 0);
693 Reap_Child(char *prog, int * pid, int * status)
700 if (WCOREDUMP(*status))
701 Log("\"%s\" core dumped!\n", prog);
702 if ((WIFSIGNALED(*status) != 0) ||
703 ((WEXITSTATUS(*status) != 0) &&
704 (WEXITSTATUS(*status) != SALSRV_EXIT_VOLGROUP_LINK)))
705 Log("\"%s\" (pid=%d) terminated abnormally!\n", prog, ret);
707 Log("wait returned -1\n");
713 * thread to combine salvager child logs
714 * back into the main salvageserver log
717 SalvageLogCleanupThread(void * arg)
719 struct log_cleanup_node * cleanup;
721 assert(pthread_mutex_lock(&worker_lock) == 0);
724 while (queue_IsEmpty(&log_cleanup_queue)) {
725 assert(pthread_cond_wait(&log_cleanup_queue.queue_change_cv, &worker_lock) == 0);
728 while (queue_IsNotEmpty(&log_cleanup_queue)) {
729 cleanup = queue_First(&log_cleanup_queue, log_cleanup_node);
730 queue_Remove(cleanup);
731 assert(pthread_mutex_unlock(&worker_lock) == 0);
732 SalvageLogCleanup(cleanup->pid);
734 assert(pthread_mutex_lock(&worker_lock) == 0);
738 assert(pthread_mutex_unlock(&worker_lock) == 0);
742 #define LOG_XFER_BUF_SIZE 65536
744 SalvageLogCleanup(int pid)
747 char fn[AFSDIR_PATH_MAX];
748 static char buf[LOG_XFER_BUF_SIZE];
750 afs_snprintf(fn, sizeof(fn), "%s.%d",
751 AFSDIR_SERVER_SLVGLOG_FILEPATH, pid);
754 pidlog = open(fn, O_RDONLY);
759 len = read(pidlog, buf, LOG_XFER_BUF_SIZE);
761 fwrite(buf, len, 1, logFile);
762 len = read(pidlog, buf, LOG_XFER_BUF_SIZE);
770 /* wake up every five minutes to see if a non-child salvage has finished */
771 #define SALVAGE_SCAN_POLL_INTERVAL 300
774 * Thread to look for SalvageLog.$pid files that are not from our child
775 * worker salvagers, and notify SalvageLogCleanupThread to clean them
776 * up. This can happen if we restart during salvages, or the
777 * salvageserver crashes or something.
781 * @return always NULL
784 SalvageLogScanningThread(void * arg)
786 struct rx_queue log_watch_queue;
788 queue_Init(&log_watch_queue);
793 char prefix[AFSDIR_PATH_MAX];
796 afs_snprintf(prefix, sizeof(prefix), "%s.", AFSDIR_SLVGLOG_FILE);
797 prefix_len = strlen(prefix);
799 dp = opendir(AFSDIR_LOGS_DIR);
802 while ((dirp = readdir(dp)) != NULL) {
804 struct log_cleanup_node *cleanup;
807 if (strncmp(dirp->d_name, prefix, prefix_len) != 0) {
808 /* not a salvage logfile; skip */
813 pid = strtol(dirp->d_name + prefix_len, NULL, 10);
816 /* file is SalvageLog.<something> but <something> isn't
822 for (i = 0; i < Parallel; ++i) {
823 if (pid == child_slot[i]) {
829 /* this pid is one of our children, so the reaper thread
830 * will take care of it; skip */
835 (struct log_cleanup_node *) malloc(sizeof(struct log_cleanup_node));
838 queue_Append(&log_watch_queue, cleanup);
844 ScanLogs(&log_watch_queue);
846 while (queue_IsNotEmpty(&log_watch_queue)) {
847 sleep(SALVAGE_SCAN_POLL_INTERVAL);
848 ScanLogs(&log_watch_queue);
855 * look through log_watch_queue, and if any processes are not still
856 * running, hand them off to the SalvageLogCleanupThread
858 * @param log_watch_queue a queue of PIDs that we should clean up if
862 ScanLogs(struct rx_queue *log_watch_queue)
864 struct log_cleanup_node *cleanup, *next;
866 assert(pthread_mutex_lock(&worker_lock) == 0);
868 for (queue_Scan(log_watch_queue, cleanup, next, log_cleanup_node)) {
869 /* if a process is still running, assume it's the salvage process
870 * still going, and keep waiting for it */
871 if (kill(cleanup->pid, 0) < 0 && errno == ESRCH) {
872 queue_Remove(cleanup);
873 queue_Append(&log_cleanup_queue, cleanup);
874 assert(pthread_cond_signal(&log_cleanup_queue.queue_change_cv) == 0);
878 assert(pthread_mutex_unlock(&worker_lock) == 0);