xref: /openbmc/qemu/block/replication.c (revision 68ff2eeb299d562e437b49e9bb98f9d6f62fbf06)
1 /*
2  * Replication Block filter
3  *
4  * Copyright (c) 2016 HUAWEI TECHNOLOGIES CO., LTD.
5  * Copyright (c) 2016 Intel Corporation
6  * Copyright (c) 2016 FUJITSU LIMITED
7  *
8  * Author:
9  *   Wen Congyang <wency@cn.fujitsu.com>
10  *
11  * This work is licensed under the terms of the GNU GPL, version 2 or later.
12  * See the COPYING file in the top-level directory.
13  */
14 
15 #include "qemu/osdep.h"
16 #include "qemu/module.h"
17 #include "qemu/option.h"
18 #include "block/nbd.h"
19 #include "block/blockjob.h"
20 #include "block/block_int.h"
21 #include "block/block_backup.h"
22 #include "system/block-backend.h"
23 #include "qapi/error.h"
24 #include "qobject/qdict.h"
25 #include "block/replication.h"
26 
27 typedef enum {
28     BLOCK_REPLICATION_NONE,             /* block replication is not started */
29     BLOCK_REPLICATION_RUNNING,          /* block replication is running */
30     BLOCK_REPLICATION_FAILOVER,         /* failover is running in background */
31     BLOCK_REPLICATION_FAILOVER_FAILED,  /* failover failed */
32     BLOCK_REPLICATION_DONE,             /* block replication is done */
33 } ReplicationStage;
34 
35 typedef struct BDRVReplicationState {
36     ReplicationMode mode;
37     ReplicationStage stage;
38     BlockJob *commit_job;
39     BdrvChild *hidden_disk;
40     BdrvChild *secondary_disk;
41     BlockJob *backup_job;
42     char *top_id;
43     ReplicationState *rs;
44     Error *blocker;
45     bool orig_hidden_read_only;
46     bool orig_secondary_read_only;
47     int error;
48 } BDRVReplicationState;
49 
50 static void replication_start(ReplicationState *rs, ReplicationMode mode,
51                               Error **errp);
52 static void replication_do_checkpoint(ReplicationState *rs, Error **errp);
53 static void replication_get_error(ReplicationState *rs, Error **errp);
54 static void replication_stop(ReplicationState *rs, bool failover,
55                              Error **errp);
56 
57 #define REPLICATION_MODE        "mode"
58 #define REPLICATION_TOP_ID      "top-id"
59 static QemuOptsList replication_runtime_opts = {
60     .name = "replication",
61     .head = QTAILQ_HEAD_INITIALIZER(replication_runtime_opts.head),
62     .desc = {
63         {
64             .name = REPLICATION_MODE,
65             .type = QEMU_OPT_STRING,
66         },
67         {
68             .name = REPLICATION_TOP_ID,
69             .type = QEMU_OPT_STRING,
70         },
71         { /* end of list */ }
72     },
73 };
74 
75 static ReplicationOps replication_ops = {
76     .start = replication_start,
77     .checkpoint = replication_do_checkpoint,
78     .get_error = replication_get_error,
79     .stop = replication_stop,
80 };
81 
replication_open(BlockDriverState * bs,QDict * options,int flags,Error ** errp)82 static int replication_open(BlockDriverState *bs, QDict *options,
83                             int flags, Error **errp)
84 {
85     int ret;
86     BDRVReplicationState *s = bs->opaque;
87     QemuOpts *opts = NULL;
88     const char *mode;
89     const char *top_id;
90 
91     ret = bdrv_open_file_child(NULL, options, "file", bs, errp);
92     if (ret < 0) {
93         return ret;
94     }
95 
96     ret = -EINVAL;
97     opts = qemu_opts_create(&replication_runtime_opts, NULL, 0, &error_abort);
98     if (!qemu_opts_absorb_qdict(opts, options, errp)) {
99         goto fail;
100     }
101 
102     mode = qemu_opt_get(opts, REPLICATION_MODE);
103     if (!mode) {
104         error_setg(errp, "Missing the option mode");
105         goto fail;
106     }
107 
108     if (!strcmp(mode, "primary")) {
109         s->mode = REPLICATION_MODE_PRIMARY;
110         top_id = qemu_opt_get(opts, REPLICATION_TOP_ID);
111         if (top_id) {
112             error_setg(errp,
113                        "The primary side does not support option top-id");
114             goto fail;
115         }
116     } else if (!strcmp(mode, "secondary")) {
117         s->mode = REPLICATION_MODE_SECONDARY;
118         top_id = qemu_opt_get(opts, REPLICATION_TOP_ID);
119         s->top_id = g_strdup(top_id);
120         if (!s->top_id) {
121             error_setg(errp, "Missing the option top-id");
122             goto fail;
123         }
124     } else {
125         error_setg(errp,
126                    "The option mode's value should be primary or secondary");
127         goto fail;
128     }
129 
130     s->rs = replication_new(bs, &replication_ops);
131 
132     ret = 0;
133 
134 fail:
135     qemu_opts_del(opts);
136     return ret;
137 }
138 
replication_close(BlockDriverState * bs)139 static void replication_close(BlockDriverState *bs)
140 {
141     BDRVReplicationState *s = bs->opaque;
142     Job *commit_job;
143     GLOBAL_STATE_CODE();
144 
145     if (s->stage == BLOCK_REPLICATION_RUNNING) {
146         replication_stop(s->rs, false, NULL);
147     }
148     if (s->stage == BLOCK_REPLICATION_FAILOVER) {
149         commit_job = &s->commit_job->job;
150         assert(commit_job->aio_context == qemu_get_current_aio_context());
151         job_cancel_sync(commit_job, false);
152     }
153 
154     if (s->mode == REPLICATION_MODE_SECONDARY) {
155         g_free(s->top_id);
156     }
157 
158     replication_remove(s->rs);
159 }
160 
replication_child_perm(BlockDriverState * bs,BdrvChild * c,BdrvChildRole role,BlockReopenQueue * reopen_queue,uint64_t perm,uint64_t shared,uint64_t * nperm,uint64_t * nshared)161 static void replication_child_perm(BlockDriverState *bs, BdrvChild *c,
162                                    BdrvChildRole role,
163                                    BlockReopenQueue *reopen_queue,
164                                    uint64_t perm, uint64_t shared,
165                                    uint64_t *nperm, uint64_t *nshared)
166 {
167     if (role & BDRV_CHILD_PRIMARY) {
168         *nperm = BLK_PERM_CONSISTENT_READ;
169     } else {
170         *nperm = 0;
171     }
172 
173     if ((bs->open_flags & (BDRV_O_INACTIVE | BDRV_O_RDWR)) == BDRV_O_RDWR) {
174         *nperm |= BLK_PERM_WRITE;
175     }
176     *nshared = BLK_PERM_CONSISTENT_READ
177                | BLK_PERM_WRITE
178                | BLK_PERM_WRITE_UNCHANGED;
179 }
180 
181 static int64_t coroutine_fn GRAPH_RDLOCK
replication_co_getlength(BlockDriverState * bs)182 replication_co_getlength(BlockDriverState *bs)
183 {
184     return bdrv_co_getlength(bs->file->bs);
185 }
186 
replication_get_io_status(BDRVReplicationState * s)187 static int replication_get_io_status(BDRVReplicationState *s)
188 {
189     switch (s->stage) {
190     case BLOCK_REPLICATION_NONE:
191         return -EIO;
192     case BLOCK_REPLICATION_RUNNING:
193         return 0;
194     case BLOCK_REPLICATION_FAILOVER:
195         return s->mode == REPLICATION_MODE_PRIMARY ? -EIO : 0;
196     case BLOCK_REPLICATION_FAILOVER_FAILED:
197         return s->mode == REPLICATION_MODE_PRIMARY ? -EIO : 1;
198     case BLOCK_REPLICATION_DONE:
199         /*
200          * active commit job completes, and active disk and secondary_disk
201          * is swapped, so we can operate bs->file directly
202          */
203         return s->mode == REPLICATION_MODE_PRIMARY ? -EIO : 0;
204     default:
205         abort();
206     }
207 }
208 
replication_return_value(BDRVReplicationState * s,int ret)209 static int replication_return_value(BDRVReplicationState *s, int ret)
210 {
211     if (s->mode == REPLICATION_MODE_SECONDARY) {
212         return ret;
213     }
214 
215     if (ret < 0) {
216         s->error = ret;
217         ret = 0;
218     }
219 
220     return ret;
221 }
222 
223 static int coroutine_fn GRAPH_RDLOCK
replication_co_readv(BlockDriverState * bs,int64_t sector_num,int remaining_sectors,QEMUIOVector * qiov)224 replication_co_readv(BlockDriverState *bs, int64_t sector_num,
225                      int remaining_sectors, QEMUIOVector *qiov)
226 {
227     BDRVReplicationState *s = bs->opaque;
228     int ret;
229 
230     if (s->mode == REPLICATION_MODE_PRIMARY) {
231         /* We only use it to forward primary write requests */
232         return -EIO;
233     }
234 
235     ret = replication_get_io_status(s);
236     if (ret < 0) {
237         return ret;
238     }
239 
240     ret = bdrv_co_preadv(bs->file, sector_num * BDRV_SECTOR_SIZE,
241                          remaining_sectors * BDRV_SECTOR_SIZE, qiov, 0);
242 
243     return replication_return_value(s, ret);
244 }
245 
246 static int coroutine_fn GRAPH_RDLOCK
replication_co_writev(BlockDriverState * bs,int64_t sector_num,int remaining_sectors,QEMUIOVector * qiov,int flags)247 replication_co_writev(BlockDriverState *bs, int64_t sector_num,
248                       int remaining_sectors, QEMUIOVector *qiov, int flags)
249 {
250     BDRVReplicationState *s = bs->opaque;
251     QEMUIOVector hd_qiov;
252     uint64_t bytes_done = 0;
253     BdrvChild *top = bs->file;
254     BdrvChild *base = s->secondary_disk;
255     BdrvChild *target;
256     int ret;
257     int64_t n;
258 
259     ret = replication_get_io_status(s);
260     if (ret < 0) {
261         goto out;
262     }
263 
264     if (ret == 0) {
265         ret = bdrv_co_pwritev(top, sector_num * BDRV_SECTOR_SIZE,
266                               remaining_sectors * BDRV_SECTOR_SIZE, qiov, 0);
267         return replication_return_value(s, ret);
268     }
269 
270     /*
271      * Failover failed, only write to active disk if the sectors
272      * have already been allocated in active disk/hidden disk.
273      */
274     qemu_iovec_init(&hd_qiov, qiov->niov);
275     while (remaining_sectors > 0) {
276         int64_t count;
277 
278         ret = bdrv_co_is_allocated_above(top->bs, base->bs, false,
279                                          sector_num * BDRV_SECTOR_SIZE,
280                                          remaining_sectors * BDRV_SECTOR_SIZE,
281                                          &count);
282         if (ret < 0) {
283             goto out1;
284         }
285 
286         assert(QEMU_IS_ALIGNED(count, BDRV_SECTOR_SIZE));
287         n = count >> BDRV_SECTOR_BITS;
288         qemu_iovec_reset(&hd_qiov);
289         qemu_iovec_concat(&hd_qiov, qiov, bytes_done, count);
290 
291         target = ret ? top : base;
292         ret = bdrv_co_pwritev(target, sector_num * BDRV_SECTOR_SIZE,
293                               n * BDRV_SECTOR_SIZE, &hd_qiov, 0);
294         if (ret < 0) {
295             goto out1;
296         }
297 
298         remaining_sectors -= n;
299         sector_num += n;
300         bytes_done += count;
301     }
302 
303 out1:
304     qemu_iovec_destroy(&hd_qiov);
305 out:
306     return ret;
307 }
308 
309 static void GRAPH_UNLOCKED
secondary_do_checkpoint(BlockDriverState * bs,Error ** errp)310 secondary_do_checkpoint(BlockDriverState *bs, Error **errp)
311 {
312     BDRVReplicationState *s = bs->opaque;
313     BdrvChild *active_disk;
314     Error *local_err = NULL;
315     int ret;
316 
317     GRAPH_RDLOCK_GUARD_MAINLOOP();
318 
319     if (!s->backup_job) {
320         error_setg(errp, "Backup job was cancelled unexpectedly");
321         return;
322     }
323 
324     backup_do_checkpoint(s->backup_job, &local_err);
325     if (local_err) {
326         error_propagate(errp, local_err);
327         return;
328     }
329 
330     active_disk = bs->file;
331     if (!active_disk->bs->drv) {
332         error_setg(errp, "Active disk %s is ejected",
333                    active_disk->bs->node_name);
334         return;
335     }
336 
337     ret = bdrv_make_empty(active_disk, errp);
338     if (ret < 0) {
339         return;
340     }
341 
342     if (!s->hidden_disk->bs->drv) {
343         error_setg(errp, "Hidden disk %s is ejected",
344                    s->hidden_disk->bs->node_name);
345         return;
346     }
347 
348     ret = bdrv_make_empty(s->hidden_disk, errp);
349     if (ret < 0) {
350         return;
351     }
352 }
353 
354 /* This function is supposed to be called twice:
355  * first with writable = true, then with writable = false.
356  * The first call puts s->hidden_disk and s->secondary_disk in
357  * r/w mode, and the second puts them back in their original state.
358  */
reopen_backing_file(BlockDriverState * bs,bool writable,Error ** errp)359 static void reopen_backing_file(BlockDriverState *bs, bool writable,
360                                 Error **errp)
361 {
362     BDRVReplicationState *s = bs->opaque;
363     BdrvChild *hidden_disk, *secondary_disk;
364     BlockReopenQueue *reopen_queue = NULL;
365 
366     GLOBAL_STATE_CODE();
367 
368     bdrv_graph_rdlock_main_loop();
369     /*
370      * s->hidden_disk and s->secondary_disk may not be set yet, as they will
371      * only be set after the children are writable.
372      */
373     hidden_disk = bs->file->bs->backing;
374     secondary_disk = hidden_disk->bs->backing;
375     bdrv_graph_rdunlock_main_loop();
376 
377     if (writable) {
378         s->orig_hidden_read_only = bdrv_is_read_only(hidden_disk->bs);
379         s->orig_secondary_read_only = bdrv_is_read_only(secondary_disk->bs);
380     }
381 
382     if (s->orig_hidden_read_only) {
383         QDict *opts = qdict_new();
384         qdict_put_bool(opts, BDRV_OPT_READ_ONLY, !writable);
385         reopen_queue = bdrv_reopen_queue(reopen_queue, hidden_disk->bs,
386                                          opts, true);
387     }
388 
389     if (s->orig_secondary_read_only) {
390         QDict *opts = qdict_new();
391         qdict_put_bool(opts, BDRV_OPT_READ_ONLY, !writable);
392         reopen_queue = bdrv_reopen_queue(reopen_queue, secondary_disk->bs,
393                                          opts, true);
394     }
395 
396     if (reopen_queue) {
397         bdrv_reopen_multiple(reopen_queue, errp);
398     }
399 }
400 
backup_job_cleanup(BlockDriverState * bs)401 static void backup_job_cleanup(BlockDriverState *bs)
402 {
403     BDRVReplicationState *s = bs->opaque;
404     BlockDriverState *top_bs;
405 
406     s->backup_job = NULL;
407 
408     top_bs = bdrv_lookup_bs(s->top_id, s->top_id, NULL);
409     if (!top_bs) {
410         return;
411     }
412     bdrv_op_unblock_all(top_bs, s->blocker);
413     error_free(s->blocker);
414     reopen_backing_file(bs, false, NULL);
415 }
416 
backup_job_completed(void * opaque,int ret)417 static void backup_job_completed(void *opaque, int ret)
418 {
419     BlockDriverState *bs = opaque;
420     BDRVReplicationState *s = bs->opaque;
421 
422     if (s->stage != BLOCK_REPLICATION_FAILOVER) {
423         /* The backup job is cancelled unexpectedly */
424         s->error = -EIO;
425     }
426 
427     backup_job_cleanup(bs);
428 }
429 
430 static bool GRAPH_RDLOCK
check_top_bs(BlockDriverState * top_bs,BlockDriverState * bs)431 check_top_bs(BlockDriverState *top_bs, BlockDriverState *bs)
432 {
433     BdrvChild *child;
434 
435     /* The bs itself is the top_bs */
436     if (top_bs == bs) {
437         return true;
438     }
439 
440     /* Iterate over top_bs's children */
441     QLIST_FOREACH(child, &top_bs->children, next) {
442         if (child->bs == bs || check_top_bs(child->bs, bs)) {
443             return true;
444         }
445     }
446 
447     return false;
448 }
449 
replication_start(ReplicationState * rs,ReplicationMode mode,Error ** errp)450 static void replication_start(ReplicationState *rs, ReplicationMode mode,
451                               Error **errp)
452 {
453     BlockDriverState *bs = rs->opaque;
454     BDRVReplicationState *s;
455     BlockDriverState *top_bs;
456     BdrvChild *active_disk, *hidden_disk, *secondary_disk;
457     int64_t active_length, hidden_length, disk_length;
458     Error *local_err = NULL;
459     BackupPerf perf = { .use_copy_range = true, .max_workers = 1 };
460 
461     GLOBAL_STATE_CODE();
462 
463     s = bs->opaque;
464 
465     if (s->stage == BLOCK_REPLICATION_DONE ||
466         s->stage == BLOCK_REPLICATION_FAILOVER) {
467         /*
468          * This case happens when a secondary is promoted to primary.
469          * Ignore the request because the secondary side of replication
470          * doesn't have to do anything anymore.
471          */
472         return;
473     }
474 
475     if (s->stage != BLOCK_REPLICATION_NONE) {
476         error_setg(errp, "Block replication is running or done");
477         return;
478     }
479 
480     if (s->mode != mode) {
481         error_setg(errp, "The parameter mode's value is invalid, needs %d,"
482                    " but got %d", s->mode, mode);
483         return;
484     }
485 
486     switch (s->mode) {
487     case REPLICATION_MODE_PRIMARY:
488         break;
489     case REPLICATION_MODE_SECONDARY:
490         bdrv_graph_rdlock_main_loop();
491         active_disk = bs->file;
492         if (!active_disk || !active_disk->bs || !active_disk->bs->backing) {
493             error_setg(errp, "Active disk doesn't have backing file");
494             bdrv_graph_rdunlock_main_loop();
495             return;
496         }
497 
498         hidden_disk = active_disk->bs->backing;
499         if (!hidden_disk->bs || !hidden_disk->bs->backing) {
500             error_setg(errp, "Hidden disk doesn't have backing file");
501             bdrv_graph_rdunlock_main_loop();
502             return;
503         }
504 
505         secondary_disk = hidden_disk->bs->backing;
506         if (!secondary_disk->bs || !bdrv_has_blk(secondary_disk->bs)) {
507             error_setg(errp, "The secondary disk doesn't have block backend");
508             bdrv_graph_rdunlock_main_loop();
509             return;
510         }
511         bdrv_graph_rdunlock_main_loop();
512 
513         /* verify the length */
514         active_length = bdrv_getlength(active_disk->bs);
515         hidden_length = bdrv_getlength(hidden_disk->bs);
516         disk_length = bdrv_getlength(secondary_disk->bs);
517         if (active_length < 0 || hidden_length < 0 || disk_length < 0 ||
518             active_length != hidden_length || hidden_length != disk_length) {
519             error_setg(errp, "Active disk, hidden disk, secondary disk's length"
520                        " are not the same");
521             return;
522         }
523 
524         /* Must be true, or the bdrv_getlength() calls would have failed */
525         assert(active_disk->bs->drv && hidden_disk->bs->drv);
526 
527         bdrv_graph_rdlock_main_loop();
528         if (!active_disk->bs->drv->bdrv_make_empty ||
529             !hidden_disk->bs->drv->bdrv_make_empty) {
530             error_setg(errp,
531                        "Active disk or hidden disk doesn't support make_empty");
532             bdrv_graph_rdunlock_main_loop();
533             return;
534         }
535         bdrv_graph_rdunlock_main_loop();
536 
537         /* reopen the backing file in r/w mode */
538         reopen_backing_file(bs, true, &local_err);
539         if (local_err) {
540             error_propagate(errp, local_err);
541             return;
542         }
543 
544         bdrv_graph_wrlock_drained();
545 
546         bdrv_ref(hidden_disk->bs);
547         s->hidden_disk = bdrv_attach_child(bs, hidden_disk->bs, "hidden disk",
548                                            &child_of_bds, BDRV_CHILD_DATA,
549                                            &local_err);
550         if (local_err) {
551             error_propagate(errp, local_err);
552             bdrv_graph_wrunlock();
553             return;
554         }
555 
556         bdrv_ref(secondary_disk->bs);
557         s->secondary_disk = bdrv_attach_child(bs, secondary_disk->bs,
558                                               "secondary disk", &child_of_bds,
559                                               BDRV_CHILD_DATA, &local_err);
560         if (local_err) {
561             error_propagate(errp, local_err);
562             bdrv_graph_wrunlock();
563             return;
564         }
565 
566         /* start backup job now */
567         error_setg(&s->blocker,
568                    "Block device is in use by internal backup job");
569 
570         top_bs = bdrv_lookup_bs(s->top_id, s->top_id, NULL);
571         if (!top_bs || !bdrv_is_root_node(top_bs) ||
572             !check_top_bs(top_bs, bs)) {
573             error_setg(errp, "No top_bs or it is invalid");
574             bdrv_graph_wrunlock();
575             reopen_backing_file(bs, false, NULL);
576             return;
577         }
578         bdrv_op_block_all(top_bs, s->blocker);
579 
580         bdrv_graph_wrunlock();
581 
582         s->backup_job = backup_job_create(
583                                 NULL, s->secondary_disk->bs, s->hidden_disk->bs,
584                                 0, MIRROR_SYNC_MODE_NONE, NULL, 0, false, false,
585                                 NULL, &perf,
586                                 BLOCKDEV_ON_ERROR_REPORT,
587                                 BLOCKDEV_ON_ERROR_REPORT,
588                                 ON_CBW_ERROR_BREAK_GUEST_WRITE,
589                                 JOB_INTERNAL,
590                                 backup_job_completed, bs, NULL, &local_err);
591         if (local_err) {
592             error_propagate(errp, local_err);
593             backup_job_cleanup(bs);
594             return;
595         }
596         job_start(&s->backup_job->job);
597         break;
598     default:
599         abort();
600     }
601 
602     s->stage = BLOCK_REPLICATION_RUNNING;
603 
604     if (s->mode == REPLICATION_MODE_SECONDARY) {
605         secondary_do_checkpoint(bs, errp);
606     }
607 
608     s->error = 0;
609 }
610 
replication_do_checkpoint(ReplicationState * rs,Error ** errp)611 static void replication_do_checkpoint(ReplicationState *rs, Error **errp)
612 {
613     BlockDriverState *bs = rs->opaque;
614     BDRVReplicationState *s = bs->opaque;
615 
616     if (s->stage == BLOCK_REPLICATION_DONE ||
617         s->stage == BLOCK_REPLICATION_FAILOVER) {
618         /*
619          * This case happens when a secondary was promoted to primary.
620          * Ignore the request because the secondary side of replication
621          * doesn't have to do anything anymore.
622          */
623         return;
624     }
625 
626     if (s->mode == REPLICATION_MODE_SECONDARY) {
627         secondary_do_checkpoint(bs, errp);
628     }
629 }
630 
replication_get_error(ReplicationState * rs,Error ** errp)631 static void replication_get_error(ReplicationState *rs, Error **errp)
632 {
633     BlockDriverState *bs = rs->opaque;
634     BDRVReplicationState *s = bs->opaque;
635 
636     if (s->stage == BLOCK_REPLICATION_NONE) {
637         error_setg(errp, "Block replication is not running");
638         return;
639     }
640 
641     if (s->error) {
642         error_setg(errp, "I/O error occurred");
643         return;
644     }
645 }
646 
replication_done(void * opaque,int ret)647 static void replication_done(void *opaque, int ret)
648 {
649     BlockDriverState *bs = opaque;
650     BDRVReplicationState *s = bs->opaque;
651 
652     if (ret == 0) {
653         s->stage = BLOCK_REPLICATION_DONE;
654 
655         bdrv_graph_wrlock_drained();
656         bdrv_unref_child(bs, s->secondary_disk);
657         s->secondary_disk = NULL;
658         bdrv_unref_child(bs, s->hidden_disk);
659         s->hidden_disk = NULL;
660         bdrv_graph_wrunlock();
661 
662         s->error = 0;
663     } else {
664         s->stage = BLOCK_REPLICATION_FAILOVER_FAILED;
665         s->error = -EIO;
666     }
667 }
668 
replication_stop(ReplicationState * rs,bool failover,Error ** errp)669 static void replication_stop(ReplicationState *rs, bool failover, Error **errp)
670 {
671     BlockDriverState *bs = rs->opaque;
672     BDRVReplicationState *s = bs->opaque;
673 
674     if (s->stage == BLOCK_REPLICATION_DONE ||
675         s->stage == BLOCK_REPLICATION_FAILOVER) {
676         /*
677          * This case happens when a secondary was promoted to primary.
678          * Ignore the request because the secondary side of replication
679          * doesn't have to do anything anymore.
680          */
681         return;
682     }
683 
684     if (s->stage != BLOCK_REPLICATION_RUNNING) {
685         error_setg(errp, "Block replication is not running");
686         return;
687     }
688 
689     switch (s->mode) {
690     case REPLICATION_MODE_PRIMARY:
691         s->stage = BLOCK_REPLICATION_DONE;
692         s->error = 0;
693         break;
694     case REPLICATION_MODE_SECONDARY:
695         /*
696          * This BDS will be closed, and the job should be completed
697          * before the BDS is closed, because we will access hidden
698          * disk, secondary disk in backup_job_completed().
699          */
700         if (s->backup_job) {
701             job_cancel_sync(&s->backup_job->job, true);
702         }
703 
704         if (!failover) {
705             secondary_do_checkpoint(bs, errp);
706             s->stage = BLOCK_REPLICATION_DONE;
707             return;
708         }
709 
710         bdrv_graph_rdlock_main_loop();
711         s->stage = BLOCK_REPLICATION_FAILOVER;
712         s->commit_job = commit_active_start(
713                             NULL, bs->file->bs, s->secondary_disk->bs,
714                             JOB_INTERNAL, 0, BLOCKDEV_ON_ERROR_REPORT,
715                             NULL, replication_done, bs, true, errp);
716         bdrv_graph_rdunlock_main_loop();
717         break;
718     default:
719         abort();
720     }
721 }
722 
723 static const char *const replication_strong_runtime_opts[] = {
724     REPLICATION_MODE,
725     REPLICATION_TOP_ID,
726 
727     NULL
728 };
729 
730 static BlockDriver bdrv_replication = {
731     .format_name                = "replication",
732     .instance_size              = sizeof(BDRVReplicationState),
733 
734     .bdrv_open                  = replication_open,
735     .bdrv_close                 = replication_close,
736     .bdrv_child_perm            = replication_child_perm,
737 
738     .bdrv_co_getlength          = replication_co_getlength,
739     .bdrv_co_readv              = replication_co_readv,
740     .bdrv_co_writev             = replication_co_writev,
741 
742     .is_filter                  = true,
743 
744     .strong_runtime_opts        = replication_strong_runtime_opts,
745 };
746 
bdrv_replication_init(void)747 static void bdrv_replication_init(void)
748 {
749     bdrv_register(&bdrv_replication);
750 }
751 
752 block_init(bdrv_replication_init);
753