backup, migrate: fix races with suspended VMs that can wake up

Fix races with ACPI-suspended VMs which could wake up during migration
or during a suspend-mode backup.

Revert prevention, of ACPI-suspended VMs automatically resuming after
migration, introduced by 7ba974a682. The commit introduced a
potential problem that causes a suspended VM that wakes up during
migration to remain paused after the migration finishes.

This can be fixed once QEMU preserves the 'suspended' runstate during
migration (current patch on the qemu-devel list [0]) by checking for
the 'suspended' runstate on the target after migration.

Furthermore the commit increased the race window during the
preparation of a suspend-mode backup, when a suspended VM wakes up
between the vm_is_paused check in PVE::VZDump::QemuServer::prepare and
PVE::VZDump::QemuServer::qga_fs_freeze. This causes the code to skip
fs-freeze even if the VM has woken up, potentially leaving the file
system in an inconsistent state.

To prevent this, do not treat the suspended runstate as paused when
migrating or archiving a VM.

[0]: https://lists.nongnu.org/archive/html/qemu-devel/2023-08/msg05260.html

Signed-off-by: Filip Schauer <f.schauer@proxmox.com>
Reviewed-by: Fiona Ebner <f.ebner@proxmox.com>
 [ TL: massage in Fiona's extra info into commit message ]
Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
This commit is contained in:
Filip Schauer 2023-10-13 15:50:06 +02:00 committed by Thomas Lamprecht
parent 62c1904921
commit 6f0627d4bd
4 changed files with 11 additions and 7 deletions

View File

@ -3084,7 +3084,7 @@ __PACKAGE__->register_method({
# sending a graceful shutdown command to paused VMs runs into timeouts, and even worse, when # sending a graceful shutdown command to paused VMs runs into timeouts, and even worse, when
# the VM gets resumed later, it still gets the request delivered and powers off # the VM gets resumed later, it still gets the request delivered and powers off
if (PVE::QemuServer::vm_is_paused($vmid)) { if (PVE::QemuServer::vm_is_paused($vmid, 1)) {
if ($param->{forceStop}) { if ($param->{forceStop}) {
warn "VM is paused - stop instead of shutdown\n"; warn "VM is paused - stop instead of shutdown\n";
$shutdown = 0; $shutdown = 0;
@ -3160,7 +3160,7 @@ __PACKAGE__->register_method({
my $node = extract_param($param, 'node'); my $node = extract_param($param, 'node');
my $vmid = extract_param($param, 'vmid'); my $vmid = extract_param($param, 'vmid');
die "VM is paused - cannot shutdown\n" if PVE::QemuServer::vm_is_paused($vmid); die "VM is paused - cannot shutdown\n" if PVE::QemuServer::vm_is_paused($vmid, 1);
die "VM $vmid not running\n" if !PVE::QemuServer::check_running($vmid); die "VM $vmid not running\n" if !PVE::QemuServer::check_running($vmid);

View File

@ -224,7 +224,9 @@ sub prepare {
} }
} }
$self->{vm_was_paused} = 1 if PVE::QemuServer::vm_is_paused($vmid); # Do not treat a suspended VM as paused, as it might wake up
# during migration and remain paused after migration finishes.
$self->{vm_was_paused} = 1 if PVE::QemuServer::vm_is_paused($vmid, 0);
} }
my ($loc_res, $mapped_res, $missing_mappings_by_node) = PVE::QemuServer::check_local_resources($conf, 1); my ($loc_res, $mapped_res, $missing_mappings_by_node) = PVE::QemuServer::check_local_resources($conf, 1);

View File

@ -8497,7 +8497,7 @@ sub complete_migration_storage {
} }
sub vm_is_paused { sub vm_is_paused {
my ($vmid) = @_; my ($vmid, $include_suspended) = @_;
my $qmpstatus = eval { my $qmpstatus = eval {
PVE::QemuConfig::assert_config_exists_on_node($vmid); PVE::QemuConfig::assert_config_exists_on_node($vmid);
mon_cmd($vmid, "query-status"); mon_cmd($vmid, "query-status");
@ -8505,8 +8505,8 @@ sub vm_is_paused {
warn "$@\n" if $@; warn "$@\n" if $@;
return $qmpstatus && ( return $qmpstatus && (
$qmpstatus->{status} eq "paused" || $qmpstatus->{status} eq "paused" ||
$qmpstatus->{status} eq "suspended" || $qmpstatus->{status} eq "prelaunch" ||
$qmpstatus->{status} eq "prelaunch" ($include_suspended && $qmpstatus->{status} eq "suspended")
); );
} }

View File

@ -67,7 +67,9 @@ sub prepare {
$self->{vm_was_paused} = 0; $self->{vm_was_paused} = 0;
if (!PVE::QemuServer::check_running($vmid)) { if (!PVE::QemuServer::check_running($vmid)) {
$self->{vm_was_running} = 0; $self->{vm_was_running} = 0;
} elsif (PVE::QemuServer::vm_is_paused($vmid)) { } elsif (PVE::QemuServer::vm_is_paused($vmid, 0)) {
# Do not treat a suspended VM as paused, as it would cause us to skip
# fs-freeze even if the VM wakes up before we reach qga_fs_freeze.
$self->{vm_was_paused} = 1; $self->{vm_was_paused} = 1;
} }