| 1 | /* |
| 2 | * Replication Block filter |
| 3 | * |
| 4 | * Copyright (c) 2016 HUAWEI TECHNOLOGIES CO., LTD. |
| 5 | * Copyright (c) 2016 Intel Corporation |
| 6 | * Copyright (c) 2016 FUJITSU LIMITED |
| 7 | * |
| 8 | * Author: |
| 9 | * Wen Congyang <wency@cn.fujitsu.com> |
| 10 | * |
| 11 | * This work is licensed under the terms of the GNU GPL, version 2 or later. |
| 12 | * See the COPYING file in the top-level directory. |
| 13 | */ |
| 14 | |
| 15 | #include "qemu/osdep.h" |
| 16 | #include "qemu/module.h" |
| 17 | #include "qemu/option.h" |
| 18 | #include "block/nbd.h" |
| 19 | #include "block/blockjob.h" |
| 20 | #include "block/block_int.h" |
| 21 | #include "block/block_backup.h" |
| 22 | #include "system/block-backend.h" |
| 23 | #include "qapi/error.h" |
| 24 | #include "qobject/qdict.h" |
| 25 | #include "block/replication.h" |
| 26 | |
| 27 | typedef enum { |
| 28 | BLOCK_REPLICATION_NONE, /* block replication is not started */ |
| 29 | BLOCK_REPLICATION_RUNNING, /* block replication is running */ |
| 30 | BLOCK_REPLICATION_FAILOVER, /* failover is running in background */ |
| 31 | BLOCK_REPLICATION_FAILOVER_FAILED, /* failover failed */ |
| 32 | BLOCK_REPLICATION_DONE, /* block replication is done */ |
| 33 | } ReplicationStage; |
| 34 | |
| 35 | typedef struct BDRVReplicationState { |
| 36 | ReplicationMode mode; |
| 37 | ReplicationStage stage; |
| 38 | BlockJob *commit_job; |
| 39 | BdrvChild *hidden_disk; |
| 40 | BdrvChild *secondary_disk; |
| 41 | BlockJob *backup_job; |
| 42 | char *top_id; |
| 43 | ReplicationState *rs; |
| 44 | Error *blocker; |
| 45 | bool orig_hidden_read_only; |
| 46 | bool orig_secondary_read_only; |
| 47 | int error; |
| 48 | } BDRVReplicationState; |
| 49 | |
| 50 | static void replication_start(ReplicationState *rs, ReplicationMode mode, |
| 51 | Error **errp); |
| 52 | static void replication_do_checkpoint(ReplicationState *rs, Error **errp); |
| 53 | static void replication_get_error(ReplicationState *rs, Error **errp); |
| 54 | static void replication_stop(ReplicationState *rs, bool failover, |
| 55 | Error **errp); |
| 56 | |
| 57 | #define REPLICATION_MODE "mode" |
| 58 | #define REPLICATION_TOP_ID "top-id" |
| 59 | static QemuOptsList replication_runtime_opts = { |
| 60 | .name = "replication", |
| 61 | .head = QTAILQ_HEAD_INITIALIZER(replication_runtime_opts.head), |
| 62 | .desc = { |
| 63 | { |
| 64 | .name = REPLICATION_MODE, |
| 65 | .type = QEMU_OPT_STRING, |
| 66 | }, |
| 67 | { |
| 68 | .name = REPLICATION_TOP_ID, |
| 69 | .type = QEMU_OPT_STRING, |
| 70 | }, |
| 71 | { /* end of list */ } |
| 72 | }, |
| 73 | }; |
| 74 | |
| 75 | static ReplicationOps replication_ops = { |
| 76 | .start = replication_start, |
| 77 | .checkpoint = replication_do_checkpoint, |
| 78 | .get_error = replication_get_error, |
| 79 | .stop = replication_stop, |
| 80 | }; |
| 81 | |
| 82 | static int replication_open(BlockDriverState *bs, QDict *options, |
| 83 | int flags, Error **errp) |
| 84 | { |
| 85 | int ret; |
| 86 | BDRVReplicationState *s = bs->opaque; |
| 87 | QemuOpts *opts = NULL; |
| 88 | const char *mode; |
| 89 | const char *top_id; |
| 90 | |
| 91 | ret = bdrv_open_file_child(NULL, options, "file", bs, errp); |
| 92 | if (ret < 0) { |
| 93 | return ret; |
| 94 | } |
| 95 | |
| 96 | ret = -EINVAL; |
| 97 | opts = qemu_opts_create(&replication_runtime_opts, NULL, 0, &error_abort); |
| 98 | if (!qemu_opts_absorb_qdict(opts, options, errp)) { |
| 99 | goto fail; |
| 100 | } |
| 101 | |
| 102 | mode = qemu_opt_get(opts, REPLICATION_MODE); |
| 103 | if (!mode) { |
| 104 | error_setg(errp, "Missing the option mode"); |
| 105 | goto fail; |
| 106 | } |
| 107 | |
| 108 | if (!strcmp(mode, "primary")) { |
| 109 | s->mode = REPLICATION_MODE_PRIMARY; |
| 110 | top_id = qemu_opt_get(opts, REPLICATION_TOP_ID); |
| 111 | if (top_id) { |
| 112 | error_setg(errp, |
| 113 | "The primary side does not support option top-id"); |
| 114 | goto fail; |
| 115 | } |
| 116 | } else if (!strcmp(mode, "secondary")) { |
| 117 | s->mode = REPLICATION_MODE_SECONDARY; |
| 118 | top_id = qemu_opt_get(opts, REPLICATION_TOP_ID); |
| 119 | s->top_id = g_strdup(top_id); |
| 120 | if (!s->top_id) { |
| 121 | error_setg(errp, "Missing the option top-id"); |
| 122 | goto fail; |
| 123 | } |
| 124 | } else { |
| 125 | error_setg(errp, |
| 126 | "The option mode's value should be primary or secondary"); |
| 127 | goto fail; |
| 128 | } |
| 129 | |
| 130 | s->rs = replication_new(bs, &replication_ops); |
| 131 | |
| 132 | ret = 0; |
| 133 | |
| 134 | fail: |
| 135 | qemu_opts_del(opts); |
| 136 | return ret; |
| 137 | } |
| 138 | |
| 139 | static void replication_close(BlockDriverState *bs) |
| 140 | { |
| 141 | BDRVReplicationState *s = bs->opaque; |
| 142 | Job *commit_job; |
| 143 | GLOBAL_STATE_CODE(); |
| 144 | |
| 145 | if (s->stage == BLOCK_REPLICATION_RUNNING) { |
| 146 | replication_stop(s->rs, false, NULL); |
| 147 | } |
| 148 | if (s->stage == BLOCK_REPLICATION_FAILOVER) { |
| 149 | commit_job = &s->commit_job->job; |
| 150 | assert(commit_job->aio_context == qemu_get_current_aio_context()); |
| 151 | job_cancel_sync(commit_job, false); |
| 152 | } |
| 153 | |
| 154 | if (s->mode == REPLICATION_MODE_SECONDARY) { |
| 155 | g_free(s->top_id); |
| 156 | } |
| 157 | |
| 158 | replication_remove(s->rs); |
| 159 | } |
| 160 | |
| 161 | static void replication_child_perm(BlockDriverState *bs, BdrvChild *c, |
| 162 | BdrvChildRole role, |
| 163 | BlockReopenQueue *reopen_queue, |
| 164 | uint64_t perm, uint64_t shared, |
| 165 | uint64_t *nperm, uint64_t *nshared) |
| 166 | { |
| 167 | if (role & BDRV_CHILD_PRIMARY) { |
| 168 | *nperm = BLK_PERM_CONSISTENT_READ; |
| 169 | } else { |
| 170 | *nperm = 0; |
| 171 | } |
| 172 | |
| 173 | if ((bs->open_flags & (BDRV_O_INACTIVE | BDRV_O_RDWR)) == BDRV_O_RDWR) { |
| 174 | *nperm |= BLK_PERM_WRITE; |
| 175 | } |
| 176 | *nshared = BLK_PERM_CONSISTENT_READ |
| 177 | | BLK_PERM_WRITE |
| 178 | | BLK_PERM_WRITE_UNCHANGED; |
| 179 | } |
| 180 | |
| 181 | static int64_t coroutine_fn GRAPH_RDLOCK |
| 182 | replication_co_getlength(BlockDriverState *bs) |
| 183 | { |
| 184 | return bdrv_co_getlength(bs->file->bs); |
| 185 | } |
| 186 | |
| 187 | static int replication_get_io_status(BDRVReplicationState *s) |
| 188 | { |
| 189 | switch (s->stage) { |
| 190 | case BLOCK_REPLICATION_NONE: |
| 191 | return -EIO; |
| 192 | case BLOCK_REPLICATION_RUNNING: |
| 193 | return 0; |
| 194 | case BLOCK_REPLICATION_FAILOVER: |
| 195 | return s->mode == REPLICATION_MODE_PRIMARY ? -EIO : 0; |
| 196 | case BLOCK_REPLICATION_FAILOVER_FAILED: |
| 197 | return s->mode == REPLICATION_MODE_PRIMARY ? -EIO : 1; |
| 198 | case BLOCK_REPLICATION_DONE: |
| 199 | /* |
| 200 | * active commit job completes, and active disk and secondary_disk |
| 201 | * is swapped, so we can operate bs->file directly |
| 202 | */ |
| 203 | return s->mode == REPLICATION_MODE_PRIMARY ? -EIO : 0; |
| 204 | default: |
| 205 | abort(); |
| 206 | } |
| 207 | } |
| 208 | |
| 209 | static int replication_return_value(BDRVReplicationState *s, int ret) |
| 210 | { |
| 211 | if (s->mode == REPLICATION_MODE_SECONDARY) { |
| 212 | return ret; |
| 213 | } |
| 214 | |
| 215 | if (ret < 0) { |
| 216 | s->error = ret; |
| 217 | ret = 0; |
| 218 | } |
| 219 | |
| 220 | return ret; |
| 221 | } |
| 222 | |
| 223 | static int coroutine_fn GRAPH_RDLOCK |
| 224 | replication_co_readv(BlockDriverState *bs, int64_t sector_num, |
| 225 | int remaining_sectors, QEMUIOVector *qiov) |
| 226 | { |
| 227 | BDRVReplicationState *s = bs->opaque; |
| 228 | int ret; |
| 229 | |
| 230 | if (s->mode == REPLICATION_MODE_PRIMARY) { |
| 231 | /* We only use it to forward primary write requests */ |
| 232 | return -EIO; |
| 233 | } |
| 234 | |
| 235 | ret = replication_get_io_status(s); |
| 236 | if (ret < 0) { |
| 237 | return ret; |
| 238 | } |
| 239 | |
| 240 | ret = bdrv_co_preadv(bs->file, sector_num * BDRV_SECTOR_SIZE, |
| 241 | remaining_sectors * BDRV_SECTOR_SIZE, qiov, 0); |
| 242 | |
| 243 | return replication_return_value(s, ret); |
| 244 | } |
| 245 | |
| 246 | static int coroutine_fn GRAPH_RDLOCK |
| 247 | replication_co_writev(BlockDriverState *bs, int64_t sector_num, |
| 248 | int remaining_sectors, QEMUIOVector *qiov, int flags) |
| 249 | { |
| 250 | BDRVReplicationState *s = bs->opaque; |
| 251 | QEMUIOVector hd_qiov; |
| 252 | uint64_t bytes_done = 0; |
| 253 | BdrvChild *top = bs->file; |
| 254 | BdrvChild *base = s->secondary_disk; |
| 255 | BdrvChild *target; |
| 256 | int ret; |
| 257 | int64_t n; |
| 258 | |
| 259 | ret = replication_get_io_status(s); |
| 260 | if (ret < 0) { |
| 261 | goto out; |
| 262 | } |
| 263 | |
| 264 | if (ret == 0) { |
| 265 | ret = bdrv_co_pwritev(top, sector_num * BDRV_SECTOR_SIZE, |
| 266 | remaining_sectors * BDRV_SECTOR_SIZE, qiov, 0); |
| 267 | return replication_return_value(s, ret); |
| 268 | } |
| 269 | |
| 270 | /* |
| 271 | * Failover failed, only write to active disk if the sectors |
| 272 | * have already been allocated in active disk/hidden disk. |
| 273 | */ |
| 274 | qemu_iovec_init(&hd_qiov, qiov->niov); |
| 275 | while (remaining_sectors > 0) { |
| 276 | int64_t count; |
| 277 | |
| 278 | ret = bdrv_co_is_allocated_above(top->bs, base->bs, false, |
| 279 | sector_num * BDRV_SECTOR_SIZE, |
| 280 | remaining_sectors * BDRV_SECTOR_SIZE, |
| 281 | &count); |
| 282 | if (ret < 0) { |
| 283 | goto out1; |
| 284 | } |
| 285 | |
| 286 | assert(QEMU_IS_ALIGNED(count, BDRV_SECTOR_SIZE)); |
| 287 | n = count >> BDRV_SECTOR_BITS; |
| 288 | qemu_iovec_reset(&hd_qiov); |
| 289 | qemu_iovec_concat(&hd_qiov, qiov, bytes_done, count); |
| 290 | |
| 291 | target = ret ? top : base; |
| 292 | ret = bdrv_co_pwritev(target, sector_num * BDRV_SECTOR_SIZE, |
| 293 | n * BDRV_SECTOR_SIZE, &hd_qiov, 0); |
| 294 | if (ret < 0) { |
| 295 | goto out1; |
| 296 | } |
| 297 | |
| 298 | remaining_sectors -= n; |
| 299 | sector_num += n; |
| 300 | bytes_done += count; |
| 301 | } |
| 302 | |
| 303 | out1: |
| 304 | qemu_iovec_destroy(&hd_qiov); |
| 305 | out: |
| 306 | return ret; |
| 307 | } |
| 308 | |
| 309 | static void GRAPH_UNLOCKED |
| 310 | secondary_do_checkpoint(BlockDriverState *bs, Error **errp) |
| 311 | { |
| 312 | BDRVReplicationState *s = bs->opaque; |
| 313 | BdrvChild *active_disk; |
| 314 | Error *local_err = NULL; |
| 315 | int ret; |
| 316 | |
| 317 | GRAPH_RDLOCK_GUARD_MAINLOOP(); |
| 318 | |
| 319 | if (!s->backup_job) { |
| 320 | error_setg(errp, "Backup job was cancelled unexpectedly"); |
| 321 | return; |
| 322 | } |
| 323 | |
| 324 | backup_do_checkpoint(s->backup_job, &local_err); |
| 325 | if (local_err) { |
| 326 | error_propagate(errp, local_err); |
| 327 | return; |
| 328 | } |
| 329 | |
| 330 | active_disk = bs->file; |
| 331 | if (!active_disk->bs->drv) { |
| 332 | error_setg(errp, "Active disk %s is ejected", |
| 333 | active_disk->bs->node_name); |
| 334 | return; |
| 335 | } |
| 336 | |
| 337 | ret = bdrv_make_empty(active_disk, errp); |
| 338 | if (ret < 0) { |
| 339 | return; |
| 340 | } |
| 341 | |
| 342 | if (!s->hidden_disk->bs->drv) { |
| 343 | error_setg(errp, "Hidden disk %s is ejected", |
| 344 | s->hidden_disk->bs->node_name); |
| 345 | return; |
| 346 | } |
| 347 | |
| 348 | ret = bdrv_make_empty(s->hidden_disk, errp); |
| 349 | if (ret < 0) { |
| 350 | return; |
| 351 | } |
| 352 | } |
| 353 | |
| 354 | /* This function is supposed to be called twice: |
| 355 | * first with writable = true, then with writable = false. |
| 356 | * The first call puts s->hidden_disk and s->secondary_disk in |
| 357 | * r/w mode, and the second puts them back in their original state. |
| 358 | */ |
| 359 | static void reopen_backing_file(BlockDriverState *bs, bool writable, |
| 360 | Error **errp) |
| 361 | { |
| 362 | BDRVReplicationState *s = bs->opaque; |
| 363 | BdrvChild *hidden_disk, *secondary_disk; |
| 364 | BlockReopenQueue *reopen_queue = NULL; |
| 365 | |
| 366 | GLOBAL_STATE_CODE(); |
| 367 | |
| 368 | bdrv_graph_rdlock_main_loop(); |
| 369 | /* |
| 370 | * s->hidden_disk and s->secondary_disk may not be set yet, as they will |
| 371 | * only be set after the children are writable. |
| 372 | */ |
| 373 | hidden_disk = bs->file->bs->backing; |
| 374 | secondary_disk = hidden_disk->bs->backing; |
| 375 | bdrv_graph_rdunlock_main_loop(); |
| 376 | |
| 377 | if (writable) { |
| 378 | s->orig_hidden_read_only = bdrv_is_read_only(hidden_disk->bs); |
| 379 | s->orig_secondary_read_only = bdrv_is_read_only(secondary_disk->bs); |
| 380 | } |
| 381 | |
| 382 | if (s->orig_hidden_read_only) { |
| 383 | QDict *opts = qdict_new(); |
| 384 | qdict_put_bool(opts, BDRV_OPT_READ_ONLY, !writable); |
| 385 | reopen_queue = bdrv_reopen_queue(reopen_queue, hidden_disk->bs, |
| 386 | opts, true); |
| 387 | } |
| 388 | |
| 389 | if (s->orig_secondary_read_only) { |
| 390 | QDict *opts = qdict_new(); |
| 391 | qdict_put_bool(opts, BDRV_OPT_READ_ONLY, !writable); |
| 392 | reopen_queue = bdrv_reopen_queue(reopen_queue, secondary_disk->bs, |
| 393 | opts, true); |
| 394 | } |
| 395 | |
| 396 | if (reopen_queue) { |
| 397 | bdrv_reopen_multiple(reopen_queue, errp); |
| 398 | } |
| 399 | } |
| 400 | |
| 401 | static void backup_job_cleanup(BlockDriverState *bs) |
| 402 | { |
| 403 | BDRVReplicationState *s = bs->opaque; |
| 404 | BlockDriverState *top_bs; |
| 405 | |
| 406 | s->backup_job = NULL; |
| 407 | |
| 408 | top_bs = bdrv_lookup_bs(s->top_id, s->top_id, NULL); |
| 409 | if (!top_bs) { |
| 410 | return; |
| 411 | } |
| 412 | bdrv_op_unblock_all(top_bs, s->blocker); |
| 413 | error_free(s->blocker); |
| 414 | reopen_backing_file(bs, false, NULL); |
| 415 | } |
| 416 | |
| 417 | static void backup_job_completed(void *opaque, int ret) |
| 418 | { |
| 419 | BlockDriverState *bs = opaque; |
| 420 | BDRVReplicationState *s = bs->opaque; |
| 421 | |
| 422 | if (s->stage != BLOCK_REPLICATION_FAILOVER) { |
| 423 | /* The backup job is cancelled unexpectedly */ |
| 424 | s->error = -EIO; |
| 425 | } |
| 426 | |
| 427 | backup_job_cleanup(bs); |
| 428 | } |
| 429 | |
| 430 | static bool GRAPH_RDLOCK |
| 431 | check_top_bs(BlockDriverState *top_bs, BlockDriverState *bs) |
| 432 | { |
| 433 | BdrvChild *child; |
| 434 | |
| 435 | /* The bs itself is the top_bs */ |
| 436 | if (top_bs == bs) { |
| 437 | return true; |
| 438 | } |
| 439 | |
| 440 | /* Iterate over top_bs's children */ |
| 441 | QLIST_FOREACH(child, &top_bs->children, next) { |
| 442 | if (child->bs == bs || check_top_bs(child->bs, bs)) { |
| 443 | return true; |
| 444 | } |
| 445 | } |
| 446 | |
| 447 | return false; |
| 448 | } |
| 449 | |
| 450 | static void replication_start(ReplicationState *rs, ReplicationMode mode, |
| 451 | Error **errp) |
| 452 | { |
| 453 | BlockDriverState *bs = rs->opaque; |
| 454 | BDRVReplicationState *s; |
| 455 | BlockDriverState *top_bs; |
| 456 | BdrvChild *active_disk, *hidden_disk, *secondary_disk; |
| 457 | int64_t active_length, hidden_length, disk_length; |
| 458 | Error *local_err = NULL; |
| 459 | BackupPerf perf = { .use_copy_range = true, .max_workers = 1 }; |
| 460 | |
| 461 | GLOBAL_STATE_CODE(); |
| 462 | |
| 463 | s = bs->opaque; |
| 464 | |
| 465 | if (s->stage == BLOCK_REPLICATION_DONE || |
| 466 | s->stage == BLOCK_REPLICATION_FAILOVER) { |
| 467 | /* |
| 468 | * This case happens when a secondary is promoted to primary. |
| 469 | * Ignore the request because the secondary side of replication |
| 470 | * doesn't have to do anything anymore. |
| 471 | */ |
| 472 | return; |
| 473 | } |
| 474 | |
| 475 | if (s->stage != BLOCK_REPLICATION_NONE) { |
| 476 | error_setg(errp, "Block replication is running or done"); |
| 477 | return; |
| 478 | } |
| 479 | |
| 480 | if (s->mode != mode) { |
| 481 | error_setg(errp, "The parameter mode's value is invalid, needs %d," |
| 482 | " but got %d", s->mode, mode); |
| 483 | return; |
| 484 | } |
| 485 | |
| 486 | switch (s->mode) { |
| 487 | case REPLICATION_MODE_PRIMARY: |
| 488 | break; |
| 489 | case REPLICATION_MODE_SECONDARY: |
| 490 | bdrv_graph_rdlock_main_loop(); |
| 491 | active_disk = bs->file; |
| 492 | if (!active_disk || !active_disk->bs || !active_disk->bs->backing) { |
| 493 | error_setg(errp, "Active disk doesn't have backing file"); |
| 494 | bdrv_graph_rdunlock_main_loop(); |
| 495 | return; |
| 496 | } |
| 497 | |
| 498 | hidden_disk = active_disk->bs->backing; |
| 499 | if (!hidden_disk->bs || !hidden_disk->bs->backing) { |
| 500 | error_setg(errp, "Hidden disk doesn't have backing file"); |
| 501 | bdrv_graph_rdunlock_main_loop(); |
| 502 | return; |
| 503 | } |
| 504 | |
| 505 | secondary_disk = hidden_disk->bs->backing; |
| 506 | if (!secondary_disk->bs || !bdrv_has_blk(secondary_disk->bs)) { |
| 507 | error_setg(errp, "The secondary disk doesn't have block backend"); |
| 508 | bdrv_graph_rdunlock_main_loop(); |
| 509 | return; |
| 510 | } |
| 511 | bdrv_graph_rdunlock_main_loop(); |
| 512 | |
| 513 | /* verify the length */ |
| 514 | active_length = bdrv_getlength(active_disk->bs); |
| 515 | hidden_length = bdrv_getlength(hidden_disk->bs); |
| 516 | disk_length = bdrv_getlength(secondary_disk->bs); |
| 517 | if (active_length < 0 || hidden_length < 0 || disk_length < 0 || |
| 518 | active_length != hidden_length || hidden_length != disk_length) { |
| 519 | error_setg(errp, "Active disk, hidden disk, secondary disk's length" |
| 520 | " are not the same"); |
| 521 | return; |
| 522 | } |
| 523 | |
| 524 | /* Must be true, or the bdrv_getlength() calls would have failed */ |
| 525 | assert(active_disk->bs->drv && hidden_disk->bs->drv); |
| 526 | |
| 527 | bdrv_graph_rdlock_main_loop(); |
| 528 | if (!active_disk->bs->drv->bdrv_make_empty || |
| 529 | !hidden_disk->bs->drv->bdrv_make_empty) { |
| 530 | error_setg(errp, |
| 531 | "Active disk or hidden disk doesn't support make_empty"); |
| 532 | bdrv_graph_rdunlock_main_loop(); |
| 533 | return; |
| 534 | } |
| 535 | bdrv_graph_rdunlock_main_loop(); |
| 536 | |
| 537 | /* reopen the backing file in r/w mode */ |
| 538 | reopen_backing_file(bs, true, &local_err); |
| 539 | if (local_err) { |
| 540 | error_propagate(errp, local_err); |
| 541 | return; |
| 542 | } |
| 543 | |
| 544 | bdrv_graph_wrlock_drained(); |
| 545 | |
| 546 | bdrv_ref(hidden_disk->bs); |
| 547 | s->hidden_disk = bdrv_attach_child(bs, hidden_disk->bs, "hidden disk", |
| 548 | &child_of_bds, BDRV_CHILD_DATA, |
| 549 | &local_err); |
| 550 | if (local_err) { |
| 551 | error_propagate(errp, local_err); |
| 552 | bdrv_graph_wrunlock(); |
| 553 | return; |
| 554 | } |
| 555 | |
| 556 | bdrv_ref(secondary_disk->bs); |
| 557 | s->secondary_disk = bdrv_attach_child(bs, secondary_disk->bs, |
| 558 | "secondary disk", &child_of_bds, |
| 559 | BDRV_CHILD_DATA, &local_err); |
| 560 | if (local_err) { |
| 561 | error_propagate(errp, local_err); |
| 562 | bdrv_graph_wrunlock(); |
| 563 | return; |
| 564 | } |
| 565 | |
| 566 | /* start backup job now */ |
| 567 | error_setg(&s->blocker, |
| 568 | "Block device is in use by internal backup job"); |
| 569 | |
| 570 | top_bs = bdrv_lookup_bs(s->top_id, s->top_id, NULL); |
| 571 | if (!top_bs || !bdrv_is_root_node(top_bs) || |
| 572 | !check_top_bs(top_bs, bs)) { |
| 573 | error_setg(errp, "No top_bs or it is invalid"); |
| 574 | bdrv_graph_wrunlock(); |
| 575 | reopen_backing_file(bs, false, NULL); |
| 576 | return; |
| 577 | } |
| 578 | bdrv_op_block_all(top_bs, s->blocker); |
| 579 | |
| 580 | bdrv_graph_wrunlock(); |
| 581 | |
| 582 | s->backup_job = backup_job_create( |
| 583 | NULL, s->secondary_disk->bs, s->hidden_disk->bs, |
| 584 | 0, MIRROR_SYNC_MODE_NONE, NULL, 0, false, false, |
| 585 | NULL, &perf, |
| 586 | BLOCKDEV_ON_ERROR_REPORT, |
| 587 | BLOCKDEV_ON_ERROR_REPORT, |
| 588 | ON_CBW_ERROR_BREAK_GUEST_WRITE, |
| 589 | JOB_INTERNAL, |
| 590 | backup_job_completed, bs, NULL, &local_err); |
| 591 | if (local_err) { |
| 592 | error_propagate(errp, local_err); |
| 593 | backup_job_cleanup(bs); |
| 594 | return; |
| 595 | } |
| 596 | job_start(&s->backup_job->job); |
| 597 | break; |
| 598 | default: |
| 599 | abort(); |
| 600 | } |
| 601 | |
| 602 | s->stage = BLOCK_REPLICATION_RUNNING; |
| 603 | |
| 604 | if (s->mode == REPLICATION_MODE_SECONDARY) { |
| 605 | secondary_do_checkpoint(bs, errp); |
| 606 | } |
| 607 | |
| 608 | s->error = 0; |
| 609 | } |
| 610 | |
| 611 | static void replication_do_checkpoint(ReplicationState *rs, Error **errp) |
| 612 | { |
| 613 | BlockDriverState *bs = rs->opaque; |
| 614 | BDRVReplicationState *s = bs->opaque; |
| 615 | |
| 616 | if (s->stage == BLOCK_REPLICATION_DONE || |
| 617 | s->stage == BLOCK_REPLICATION_FAILOVER) { |
| 618 | /* |
| 619 | * This case happens when a secondary was promoted to primary. |
| 620 | * Ignore the request because the secondary side of replication |
| 621 | * doesn't have to do anything anymore. |
| 622 | */ |
| 623 | return; |
| 624 | } |
| 625 | |
| 626 | if (s->mode == REPLICATION_MODE_SECONDARY) { |
| 627 | secondary_do_checkpoint(bs, errp); |
| 628 | } |
| 629 | } |
| 630 | |
| 631 | static void replication_get_error(ReplicationState *rs, Error **errp) |
| 632 | { |
| 633 | BlockDriverState *bs = rs->opaque; |
| 634 | BDRVReplicationState *s = bs->opaque; |
| 635 | |
| 636 | if (s->stage == BLOCK_REPLICATION_NONE) { |
| 637 | error_setg(errp, "Block replication is not running"); |
| 638 | return; |
| 639 | } |
| 640 | |
| 641 | if (s->error) { |
| 642 | error_setg(errp, "I/O error occurred"); |
| 643 | return; |
| 644 | } |
| 645 | } |
| 646 | |
| 647 | static void replication_done(void *opaque, int ret) |
| 648 | { |
| 649 | BlockDriverState *bs = opaque; |
| 650 | BDRVReplicationState *s = bs->opaque; |
| 651 | |
| 652 | if (ret == 0) { |
| 653 | s->stage = BLOCK_REPLICATION_DONE; |
| 654 | |
| 655 | bdrv_graph_wrlock_drained(); |
| 656 | bdrv_unref_child(bs, s->secondary_disk); |
| 657 | s->secondary_disk = NULL; |
| 658 | bdrv_unref_child(bs, s->hidden_disk); |
| 659 | s->hidden_disk = NULL; |
| 660 | bdrv_graph_wrunlock(); |
| 661 | |
| 662 | s->error = 0; |
| 663 | } else { |
| 664 | s->stage = BLOCK_REPLICATION_FAILOVER_FAILED; |
| 665 | s->error = -EIO; |
| 666 | } |
| 667 | } |
| 668 | |
| 669 | static void replication_stop(ReplicationState *rs, bool failover, Error **errp) |
| 670 | { |
| 671 | BlockDriverState *bs = rs->opaque; |
| 672 | BDRVReplicationState *s = bs->opaque; |
| 673 | |
| 674 | if (s->stage == BLOCK_REPLICATION_DONE || |
| 675 | s->stage == BLOCK_REPLICATION_FAILOVER) { |
| 676 | /* |
| 677 | * This case happens when a secondary was promoted to primary. |
| 678 | * Ignore the request because the secondary side of replication |
| 679 | * doesn't have to do anything anymore. |
| 680 | */ |
| 681 | return; |
| 682 | } |
| 683 | |
| 684 | if (s->stage != BLOCK_REPLICATION_RUNNING) { |
| 685 | error_setg(errp, "Block replication is not running"); |
| 686 | return; |
| 687 | } |
| 688 | |
| 689 | switch (s->mode) { |
| 690 | case REPLICATION_MODE_PRIMARY: |
| 691 | s->stage = BLOCK_REPLICATION_DONE; |
| 692 | s->error = 0; |
| 693 | break; |
| 694 | case REPLICATION_MODE_SECONDARY: |
| 695 | /* |
| 696 | * This BDS will be closed, and the job should be completed |
| 697 | * before the BDS is closed, because we will access hidden |
| 698 | * disk, secondary disk in backup_job_completed(). |
| 699 | */ |
| 700 | if (s->backup_job) { |
| 701 | job_cancel_sync(&s->backup_job->job, true); |
| 702 | } |
| 703 | |
| 704 | if (!failover) { |
| 705 | secondary_do_checkpoint(bs, errp); |
| 706 | s->stage = BLOCK_REPLICATION_DONE; |
| 707 | return; |
| 708 | } |
| 709 | |
| 710 | bdrv_graph_rdlock_main_loop(); |
| 711 | s->stage = BLOCK_REPLICATION_FAILOVER; |
| 712 | s->commit_job = commit_active_start( |
| 713 | NULL, bs->file->bs, s->secondary_disk->bs, |
| 714 | JOB_INTERNAL, 0, BLOCKDEV_ON_ERROR_REPORT, |
| 715 | NULL, replication_done, bs, true, errp); |
| 716 | bdrv_graph_rdunlock_main_loop(); |
| 717 | break; |
| 718 | default: |
| 719 | abort(); |
| 720 | } |
| 721 | } |
| 722 | |
| 723 | static const char *const replication_strong_runtime_opts[] = { |
| 724 | REPLICATION_MODE, |
| 725 | REPLICATION_TOP_ID, |
| 726 | |
| 727 | NULL |
| 728 | }; |
| 729 | |
| 730 | static BlockDriver bdrv_replication = { |
| 731 | .format_name = "replication", |
| 732 | .instance_size = sizeof(BDRVReplicationState), |
| 733 | |
| 734 | .bdrv_open = replication_open, |
| 735 | .bdrv_close = replication_close, |
| 736 | .bdrv_child_perm = replication_child_perm, |
| 737 | |
| 738 | .bdrv_co_getlength = replication_co_getlength, |
| 739 | .bdrv_co_readv = replication_co_readv, |
| 740 | .bdrv_co_writev = replication_co_writev, |
| 741 | |
| 742 | .is_filter = true, |
| 743 | |
| 744 | .strong_runtime_opts = replication_strong_runtime_opts, |
| 745 | }; |
| 746 | |
| 747 | static void bdrv_replication_init(void) |
| 748 | { |
| 749 | bdrv_register(&bdrv_replication); |
| 750 | } |
| 751 | |
| 752 | block_init(bdrv_replication_init); |