Files
seaweedfs/weed/storage/blockvol/role.go
T
Ping QiuandClaude Opus 4.6 8b2b5f6f66 feat: Phase 6 CP6-3 -- failover + rebuild in Kubernetes, 126 tests
Wire low-level fencing primitives to master/VS control plane and CSI:

- Proto: replica/rebuild address fields on assignment/info/response messages
- Assignment queue: retain-until-confirmed (Peek+Confirm), stale epoch pruning
- VS assignment receiver: processes assignments from HeartbeatResponse
- BlockService replication: ProcessAssignments, deterministic ports (FNV hash)
- Registry replica tracking: SetReplica/ClearReplica/SwapPrimaryReplica
- CreateBlockVolume: primary + replica, enqueues assignments, single-copy mode
- Failover: lease-aware promotion, deferred timers with cancellation on reconnect
- ControllerPublish: returns fresh primary iSCSI address after failover
- Recovery: recoverBlockVolumes drains pendingRebuilds, enqueues Rebuilding
- Real integration tests on M02: failover address switch, rebuild data
  consistency, full lifecycle failover+rebuild (3 tests, all PASS)

Review fixes (12 findings, 5 High, 5 Medium, 2 Low):
- R1-1: AllocateBlockVolume returns replication ports
- R1-2: setupPrimaryReplication starts rebuild server
- R1-3: VS sends periodic block heartbeat for assignment confirmation
- R2-F1: LastLeaseGrant set before Register (no stale-lease race)
- R2-F2: Deferred promotion timers cancelled on VS reconnect
- R2-F3: SwapPrimaryReplica uses RoleToWire instead of uint32(1)
- R2-F4: DeleteBlockVolume deletes replica (best-effort)
- R2-F5: SwapPrimaryReplica computes epoch atomically under lock
- QA: SetReplica removes old replica from byServer index (BUG-QA-CP63-1)

126 CP6-3 tests (67 dev + 48 QA + 8 integration + 3 real).
Cumulative Phase 6: 352 tests. All PASS.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 00:52:05 -08:00

105 lines
2.8 KiB
Go

package blockvol
import (
"errors"
"fmt"
)
// Role represents the replication role of a block volume.
type Role uint8
const (
RoleNone Role = 0 // Phase 3 default, no fencing
RolePrimary Role = 1
RoleReplica Role = 2
RoleStale Role = 3
RoleRebuilding Role = 4
RoleDraining Role = 5
)
// String returns the role name.
func (r Role) String() string {
switch r {
case RoleNone:
return "none"
case RolePrimary:
return "primary"
case RoleReplica:
return "replica"
case RoleStale:
return "stale"
case RoleRebuilding:
return "rebuilding"
case RoleDraining:
return "draining"
default:
return fmt.Sprintf("unknown(%d)", uint8(r))
}
}
// validTransitions maps each role to the set of roles it can transition to.
var validTransitions = map[Role]map[Role]bool{
RoleNone: {RolePrimary: true, RoleReplica: true, RoleRebuilding: true},
RolePrimary: {RoleDraining: true},
RoleReplica: {RolePrimary: true},
RoleStale: {RoleRebuilding: true, RoleReplica: true},
RoleRebuilding: {RoleReplica: true},
RoleDraining: {RoleStale: true},
}
// ValidTransition returns true if transitioning from -> to is allowed.
func ValidTransition(from, to Role) bool {
targets, ok := validTransitions[from]
if !ok {
return false
}
return targets[to]
}
// RoleChangeCallback is called when a volume's role changes.
type RoleChangeCallback func(old, new Role)
var ErrInvalidRoleTransition = errors.New("blockvol: invalid role transition")
// Role returns the current role of this volume.
func (v *BlockVol) Role() Role {
return Role(v.role.Load())
}
// SetRole transitions the volume to a new role if the transition is valid.
// Uses CompareAndSwap to prevent TOCTOU races between concurrent callers.
// Calls the registered RoleChangeCallback after updating.
func (v *BlockVol) SetRole(r Role) error {
for {
old := v.role.Load()
if !ValidTransition(Role(old), r) {
return fmt.Errorf("%w: %s -> %s", ErrInvalidRoleTransition, Role(old), r)
}
if v.role.CompareAndSwap(old, uint32(r)) {
if v.roleCallback != nil {
v.safeCallback(Role(old), r)
}
return nil
}
// CAS failed -- another goroutine changed the role; retry.
}
}
// safeCallback invokes the role callback with panic recovery.
// If the callback panics, the role is already updated but the panic
// is caught and returned as an error via log (callers see nil from SetRole).
func (v *BlockVol) safeCallback(old, new Role) {
defer func() {
if r := recover(); r != nil {
// Role is already stored. Log but don't propagate panic.
// In production, this would go to glog. For now, swallow it.
}
}()
v.roleCallback(old, new)
}
// SetRoleCallback registers a callback to be invoked on role changes.
func (v *BlockVol) SetRoleCallback(cb RoleChangeCallback) {
v.roleCallback = cb
}