<html dir="ltr">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style id="owaParaStyle" type="text/css">P {margin-top:0;margin-bottom:0;}</style>
</head>
<body ocsi="0" fpstyle="1">
<div style="direction: ltr;font-family: Tahoma;color: #000000;font-size: 10pt;"><br>
Sounds similar to the issue I described here last week. We also had two nodes, and lost network connection between the two nodes while one was starting up after a fence. Although we had stonith resources configured, those resources were never called, and
the cluster was considered active on both nodes throughout the network split. We were able to reproduce this issue in our lab, it seems there is a window during corosync startup where if a node joins the cluster and then leaves before Pacemaker stonith resources
have started, it will not be fenced. This issue may be isolated to two node systems, as normally a single node that is separated from cluster will have lost quorum, which is not the case with two_node.
<br>
<br>
Are you running with "two_node" in corosync.conf?<br>
Are you running with "wait_for_all"? (It's on by default with "two_node")<br>
<br>
<div style="font-family: Times New Roman; color: #000000; font-size: 16px">
<hr tabindex="-1">
<div style="direction: ltr;" id="divRpF378731"><font face="Tahoma" size="2" color="#000000"><b>From:</b> Chris Walker [christopher.walker@gmail.com]<br>
<b>Sent:</b> Sunday, August 02, 2015 23:02<br>
<b>To:</b> pacemaker@oss.clusterlabs.org<br>
<b>Subject:</b> [Pacemaker] Node lost early in HA startup --> no STONITH<br>
</font><br>
</div>
<div></div>
<div>
<div dir="ltr">Hello,
<div><br>
<div>We recently had an unfortunate sequence on our two-node cluster (nodes n02 and n03) that can be summarized as:</div>
<div>1. n03 became pathologically busy and was STONITHed by n02</div>
<div>2. The heavy load migrated to n02, which also became pathologically busy<br>
</div>
<div>3. n03 was rebooted</div>
<div>4. During the startup of HA on n03, n02 was initially seen by n03:</div>
<div><br>
</div>
<div>Jul 26 15:23:43 n03 crmd: [143569]: info: crm_update_peer_proc: n02.ais is now online</div>
<div> <br>
</div>
<div>5. But later during the startup sequence (after DC election and CIB sync) we see n02 die (n02 is really wrapped around the axle, many stuck threads, etc)</div>
<div><br>
</div>
</div>
<div>
<div>Jul 26 15:27:44 n03 heartbeat: [143544]: WARN: node n02: is dead</div>
</div>
<div>...</div>
<div>
<div>
<div>Jul 26 15:27:45 n03 crmd: [143569]: info: ais_status_callback: status: n02 is now lost (was member)</div>
</div>
</div>
<div><br>
</div>
<div>our deadtime is 240 seconds, so n02 became unresponsive almost immediately after n03 reported it up at 15:23:43</div>
<div><br>
</div>
<div>6. The troubling aspect of this incident is that even though there are multiple STONITH resources configured for n03, none of them was engaged and n03 then mounted filesystems that were also active on n02.</div>
<div><br>
</div>
<div>I'm wondering whether the fact that no STONITH resources were started by this time explains why n02 was not STONITHed. Shortly after n02 is declared dead we see STONITH resources begin starting, e.g., </div>
<div><br>
</div>
<div>
<div>Jul 26 15:27:47 n03 pengine: [152499]: notice: LogActions: Start n03-3-ipmi-stonith (n03)</div>
<div><br>
</div>
</div>
<div>Does the fact that since there were no active STONITH resources when n02 was declared dead, no STONITH action was taken against this node? Is there a fix/workaround for this scenario (we're using heartbeat 3.0.5 and pacemaker 3.1.6 (RHEL6.2))?</div>
<div><br>
</div>
<div>Thanks very much!</div>
<div>Chris</div>
</div>
</div>
</div>
</div>
</body>
</html>