Files
felhom-controller/controller/internal/quiesce/precheck.go
T

59 lines
3.0 KiB
Go

package quiesce
import "context"
// R-921 — CHECK FIRST, STOP SECOND.
//
// MEASURED 2026-10-08 night on demo-hp (felhom.eu documentation/audits/dooplex-survival-2026-10-09/partE/
// R-518.txt): the controller stopped every app for the off-site tier, the agent refused the backup
// („a heavy operation is already in flight", busy=backup:local — the night OS step that follows the local
// copy), and the apps were down about a minute for no copy.
//
// What the agent lets the controller see BEFORE a stop (felhom-agent v0.154.0, read 2026-10-09): the agent
// refuses POST /backup for two reasons. (1) A job of ANOTHER tier of this guest is in flight
// (localapi otherTierInFlight) — that IS readable, per tier, from GET /backup/status?target=…. (2) Its
// host-wide heavy-operation gate is held (backup.InFlight: the OS step after the night's local copy, a
// restore-test, fstrim) — that is served by NO endpoint (InFlight.Busy() exists and nothing exposes it).
// So the pre-check below covers reason (1) only. Reason (2) — the measured instance — is met by the
// BUSY path in quiesceAndPollTiers, which resumes the apps at once (pinned by
// TestR921_BusyRefusalResumesAtOnce); closing it before the stop needs the agent to serve its gate.
//
// The race (free at the check, busy at the start) needs nothing new: it is the BUSY path again.
// InFlightProber is the OPTIONAL pre-check surface (R-921). An adapter that does not implement it keeps
// the pre-R-921 behaviour exactly: stop, ask, and on refusal resume at once.
type InFlightProber interface {
// BackupJobsInFlight returns the tiers whose backup job the agent holds in flight right now
// (phase running or snapshotted). An agent without per-tier jobs (pre-R-82) answers nil, nil.
BackupJobsInFlight(ctx context.Context) ([]string, error)
}
// anotherTierInFlight reports whether the agent would refuse the window's first tier because a job of a
// DIFFERENT tier is in flight — so the window must not stop any app. The window's OWN tier in flight is
// not a refusal (the agent answers its start with the running job, 202), and that path is left as it was.
//
// Fail toward backing up: an unanswerable pre-check, an untargeted window (pre-R-82 agent) or an adapter
// without the surface all return false — the window runs as before.
func (l *Loop) anotherTierInFlight(ctx context.Context, first string) bool {
if first == "" {
return false
}
p, ok := l.backend.(InFlightProber)
if !ok {
return false
}
busy, err := p.BackupJobsInFlight(ctx)
if err != nil {
l.logger.Printf("[WARN] [quiesce] pre-check: could not ask the agent which backup jobs are in flight (%v) — stopping the apps and asking as before (R-921)", err)
return false
}
for _, t := range busy {
if t != first {
l.logger.Printf("[INFO] [quiesce] tier %s is due, but the agent still holds a backup job on tier %s — no app is stopped; the tier stays due and is asked again at the next poll (R-921)",
tierLabel(first), tierLabel(t))
return true
}
}
return false
}