Files
seaweedfs/weed/mount/peer_registrar.go
Chris Lu 8a6348d3e9 peer chunk sharing 4/8: mount registrar + HRW owner selection (#9133)
* proto: define MountRegister/MountList and MountPeer service

Adds the wire types for peer chunk sharing between weed mount clients:

* filer.proto: MountRegister / MountList RPCs so each mount can heartbeat
  its peer-serve address into a filer-hosted registry, and refresh the
  list of peers. Tiny payload; the filer stores only O(fleet_size) state.

* mount_peer.proto (new): ChunkAnnounce / ChunkLookup RPCs for the
  mount-to-mount chunk directory. Each fid's directory entry lives on
  an HRW-assigned mount; announces and lookups route to that mount.

No behavior yet — later PRs wire the RPCs into the filer and mount.
See design-weed-mount-peer-chunk-sharing.md for the full design.

* filer: add mount-server registry behind -peer.registry.enable

Implements tier 1 of the peer chunk sharing design: an in-memory registry
of live weed mount servers, keyed by peer address, refreshed by
MountRegister heartbeats and served by MountList.

* weed/filer/peer_registry.go: thread-safe map with TTL eviction; lazy
  sweep on List plus a background sweeper goroutine for bounded memory.

* weed/server/filer_grpc_server_peer.go: MountRegister / MountList RPC
  handlers. When -peer.registry.enable is false (the default), both RPCs
  are silent no-ops so probing older filers is harmless.

* -peer.registry.enable flag on weed filer; FilerOption.PeerRegistryEnabled
  wires it through.

Phase 1 is single-filer (no cross-filer replication of the registry);
mounts that fail over to another filer will re-register on the next
heartbeat, so the registry self-heals within one TTL cycle.

Part of the peer-chunk-sharing design; no behavior change at runtime
until a later PR enables the flag on both filer and mount.

* filer: nil-safe peerRegistryEnable + registry hardening

Addresses review feedback on PR #9131.

* Fix: nil pointer deref in the mini cluster. FilerOptions instances
  constructed outside weed/command/filer.go (e.g. miniFilerOptions in
  mini.go) do not populate peerRegistryEnable, so dereferencing the
  pointer panics at Filer startup. Use the same
  `nil && deref` idiom already used for distributedLock / writebackCache.

* Hardening (gemini review): registry now enforces three invariants:
  - empty peer_addr is silently rejected (no client-controlled sentinel
    mass-inserts)
  - TTL is capped at 1 hour so a runaway client cannot pin entries
  - new-entry count is capped at 10000 to bound memory; renewals of
    existing entries are always honored, so a full registry still
    heartbeats its existing members correctly

Covered by new unit tests.

* filer: rename -peer.registry.enable flag to -mount.p2p

Per review feedback: the old name "peer.registry.enable" leaked
the implementation ("registry") into the CLI surface. "mount.p2p"
is shorter and describes what it actually controls — whether this
filer participates in mount-to-mount peer chunk sharing.

Flag renames (all three keep default=true, idle cost is near-zero):
  -peer.registry.enable        ->  -mount.p2p         (weed filer)
  -filer.peer.registry.enable  ->  -filer.mount.p2p   (weed mini, weed server)

Internal variable names (mountPeerRegistryEnable, MountPeerRegistry)
keep their longer form — they describe the component, not the knob.

* filer: MountList returns DataCenter + List uses RLock

Two review follow-ups on the mount peer registry:

* weed/server/filer_grpc_server_mount_peer.go: MountList was dropping
  the DataCenter on the wire. The whole point of carrying DC separately
  from Rack is letting the mount-side fetcher re-rank peers by the
  two-level locality hierarchy (same-rack > same-DC > cross-DC); without
  DC in the response every remote peer collapsed to "unknown locality."

* weed/filer/mount_peer_registry.go: List() was taking a write lock so
  it could lazy-delete expired entries inline. But MountList is a
  read-heavy RPC hit on every mount's 30 s refresh loop, and Sweep is
  already wired as the sole reclamation path (same pattern as the
  mount-side PeerDirectory). Switch List to RLock + filter, let Sweep
  do the map mutation, so concurrent MountList callers don't serialize
  on each other.

Test updated to reflect the new contract (List no longer mutates the
map; Sweep is what drops expired entries).

* mount: add peer chunk sharing options + advertise address resolver

First cut at the peer chunk sharing wiring on the mount side. No
functional behavior yet — this PR just introduces the option fields,
the -peer.* flags, and the helper that resolves a reachable
host:port from them. The server implementation arrives in PR #5
(gRPC service) and the fetcher in PR #7.

* ResolvePeerAdvertiseAddr: an explicit -peer.advertise wins; else we
  use -peer.listen's bind host if specific; else util.DetectedHostAddress
  combined with the port. This is what gets registered with the filer
  and announced to peers, so wildcard binds no longer result in
  unreachable identities like "[::]:18080".

* Option fields: PeerEnabled, PeerListen, PeerAdvertise, PeerRack.
  One port handles both directory RPCs and streaming chunk fetches
  (see PR #1 FetchChunk proto), so there is no second -peer.grpc.*
  flag — the old HTTP byte-transfer path is gone.

* New flags on weed mount: -peer.enable, -peer.listen (default :18080),
  -peer.advertise (default auto), -peer.rack.

* mount: register with filer and maintain HRW seed view

Adds the mount-side tier-1 client. On startup the mount calls
MountRegister with its advertise address (PR #3) and keeps both the
filer entry and the local seed view fresh via background tickers
(30 s register / 30 s list, 90 s filer TTL).

* peer_hrw.go: pure rendezvous-hashing helper picking a single owner
  per fid via top-1 HRW. Adding or removing one seed moves only
  ~1/N fids.

* peer_registrar.go: heartbeat + list poller. Seeds() returns the
  slice directly (no per-call copy) since listOnce atomically swaps;
  background RPCs bind their context to Stop() so unmount doesn't
  hang on a slow filer.

* WFS wiring uses ResolvePeerAdvertiseAddr from PR #3 for the
  identity registered with the filer. No HTTP server, no second
  port — one reachable address represents the mount.

* mount: broadcast MountRegister/MountList to every filer

Previously the registrar called through wfs.WithFilerClient, which only
reaches whichever filer the WFS filer-client session happens to be on.
That meant two mounts pointing at different filers would never see each
other: the filer mount registries are in-memory and per-filer (no
filer-to-filer sync), so each mount's MountList only returned peers
that had also registered through the same filer.

This commit makes the registrar multi-filer aware:

  * NewPeerRegistrar now takes the full FilerAddresses slice and a
    per-filer dial function. The old single-filer peerFilerClient
    interface is gone.

  * registerOnce fans a MountRegister RPC out to every filer in
    parallel. Succeeds if at least one filer accepted — an unreachable
    filer is tolerated, logged, and retried on the next heartbeat.

  * listOnce polls every filer's MountList in parallel and merges the
    responses by peer_addr, keeping the newest LastSeenNs on duplicates.
    Mounts talking to different filers therefore converge once every
    filer has been polled once.

The merged-list property is what lets a fleet of mounts spread across
multiple filers still form a single HRW seed view. Each filer only ever
sees the subset of mounts that heartbeat through it, but the registrar
reconstructs the union client-side.

New unit tests guard both properties:
  - RegisterBroadcastsToAllFilers: one registerOnce hits all N filers.
  - ListMergesAcrossFilers: mount-a on filer-1 and mount-b on filer-2
    both appear in the merged seed set.
  - ListMergeKeepsNewestLastSeen: the same mount reported by two
    filers collapses to one entry with the freshest timestamp.
2026-04-18 20:03:45 -07:00

252 lines
7.5 KiB
Go

package mount
import (
"context"
"fmt"
"sync"
"sync/atomic"
"time"
"github.com/seaweedfs/seaweedfs/weed/glog"
"github.com/seaweedfs/seaweedfs/weed/pb"
"github.com/seaweedfs/seaweedfs/weed/pb/filer_pb"
)
// PeerRegistrar maintains this mount's presence in every configured
// filer's mount registry and its local snapshot of the merged seed set.
// It runs two background tickers:
//
// - MountRegister heartbeats, fanned out to every filer in parallel so
// each filer keeps a fresh TTL entry for us. Mounts pointing at
// different filers therefore still see each other once all filers
// have been heartbeated.
// - MountList polling, fanned out identically, merged by peer_addr
// (newest LastSeenNs wins) so OwnerFor() has a view of the whole
// fleet regardless of which filer each peer happens to heartbeat
// through.
//
// An unreachable filer is tolerated: we log and continue as long as at
// least one filer succeeds. Entries cached on a permanently-gone filer
// fall out of the merged view on their own TTL.
type PeerRegistrar struct {
filerAddrs []pb.ServerAddress
dialFiler filerDialFn
selfPeerAddr string
selfDc string
selfRack string
registerInterval time.Duration
registerTTL time.Duration
listInterval time.Duration
mu sync.RWMutex
seeds []SeedPeer
// stopCtx cancels when Stop() is called. Background RPCs scope their
// deadline to this so unmount does not block on pending filer calls.
stopCtx context.Context
stopCancel context.CancelFunc
stopped atomic.Bool
}
// filerDialFn is how the registrar reaches one configured filer. The
// production wiring is pb.WithGrpcFilerClient; tests inject a fake.
type filerDialFn func(ctx context.Context, addr pb.ServerAddress, fn func(client filer_pb.SeaweedFilerClient) error) error
// NewPeerRegistrar constructs the registrar; Start launches the background
// loops. Callers must supply the full filer set so heartbeats and list
// polls reach every filer — otherwise mounts talking to different filers
// never observe each other.
func NewPeerRegistrar(filers []pb.ServerAddress, dial filerDialFn, selfAddr, dc, rack string) *PeerRegistrar {
ctx, cancel := context.WithCancel(context.Background())
return &PeerRegistrar{
filerAddrs: filers,
dialFiler: dial,
selfPeerAddr: selfAddr,
selfRack: rack,
selfDc: dc,
registerInterval: 30 * time.Second,
registerTTL: 90 * time.Second,
listInterval: 30 * time.Second,
stopCtx: ctx,
stopCancel: cancel,
}
}
// Start does an initial register+list synchronously (so OwnerFor has a
// usable view immediately) and then kicks off the background loops.
func (r *PeerRegistrar) Start(ctx context.Context) error {
if err := r.registerOnce(ctx); err != nil {
glog.V(1).Infof("initial MountRegister: %v", err)
// Do not fail startup — the mount must still serve reads even if
// no filer yet knows about us.
}
if err := r.listOnce(ctx); err != nil {
glog.V(1).Infof("initial MountList: %v", err)
}
go r.loopRegister()
go r.loopList()
return nil
}
// Stop halts the background loops and cancels any in-flight RPCs they
// may have launched. Safe to call multiple times.
func (r *PeerRegistrar) Stop() {
if r.stopped.Swap(true) {
return
}
r.stopCancel()
}
// Seeds returns the currently-known seed set. Callers MUST NOT mutate the
// returned slice — it is shared with concurrent listOnce readers. Because
// listOnce atomically swaps to a brand-new slice on every refresh rather
// than mutating in place, returning the slice header directly is safe and
// avoids a per-call allocation on the read-hot OwnerFor path.
func (r *PeerRegistrar) Seeds() []SeedPeer {
r.mu.RLock()
defer r.mu.RUnlock()
return r.seeds
}
// OwnerFor is a convenience wrapper that runs HRW against the current
// seed snapshot.
func (r *PeerRegistrar) OwnerFor(fid string) string {
return OwnerFor(fid, r.Seeds())
}
// filerRPCTimeout bounds a single MountRegister / MountList call so a slow
// or partitioned filer can't wedge the background loops (which run on a
// 30 s cadence). 20 s gives room for TLS handshakes on cold connections
// while leaving headroom before the next tick.
const filerRPCTimeout = 20 * time.Second
// registerOnce fans a MountRegister out to every configured filer in
// parallel. Returns an error only if every filer failed; otherwise the
// best-effort semantics let the mount proceed when some filer is down.
func (r *PeerRegistrar) registerOnce(ctx context.Context) error {
if len(r.filerAddrs) == 0 {
return fmt.Errorf("no filers configured")
}
ctx, cancel := context.WithTimeout(ctx, filerRPCTimeout)
defer cancel()
req := &filer_pb.MountRegisterRequest{
PeerAddr: r.selfPeerAddr,
Rack: r.selfRack,
DataCenter: r.selfDc,
TtlSeconds: int32(r.registerTTL / time.Second),
}
var wg sync.WaitGroup
var successes atomic.Int32
for _, addr := range r.filerAddrs {
wg.Add(1)
go func(addr pb.ServerAddress) {
defer wg.Done()
err := r.dialFiler(ctx, addr, func(c filer_pb.SeaweedFilerClient) error {
_, err := c.MountRegister(ctx, req)
return err
})
if err != nil {
glog.V(2).Infof("MountRegister %s: %v", addr, err)
return
}
successes.Add(1)
}(addr)
}
wg.Wait()
if successes.Load() == 0 {
return fmt.Errorf("MountRegister failed on all %d filer(s)", len(r.filerAddrs))
}
return nil
}
// listOnce polls MountList from every filer in parallel and merges the
// responses by peer_addr (newest LastSeenNs wins). This way two mounts
// heartbeating through different filers still end up in each other's
// seed view as soon as at least one filer has been listed on each side.
func (r *PeerRegistrar) listOnce(ctx context.Context) error {
if len(r.filerAddrs) == 0 {
r.mu.Lock()
r.seeds = nil
r.mu.Unlock()
return nil
}
ctx, cancel := context.WithTimeout(ctx, filerRPCTimeout)
defer cancel()
var (
mu sync.Mutex
merged = map[string]*filer_pb.MountInfo{}
fails int
)
var wg sync.WaitGroup
for _, addr := range r.filerAddrs {
wg.Add(1)
go func(addr pb.ServerAddress) {
defer wg.Done()
err := r.dialFiler(ctx, addr, func(c filer_pb.SeaweedFilerClient) error {
resp, err := c.MountList(ctx, &filer_pb.MountListRequest{})
if err != nil {
return err
}
mu.Lock()
for _, m := range resp.Mounts {
if prev, ok := merged[m.PeerAddr]; !ok || m.LastSeenNs > prev.LastSeenNs {
merged[m.PeerAddr] = m
}
}
mu.Unlock()
return nil
})
if err != nil {
mu.Lock()
fails++
mu.Unlock()
glog.V(2).Infof("MountList %s: %v", addr, err)
}
}(addr)
}
wg.Wait()
if fails == len(r.filerAddrs) {
return fmt.Errorf("MountList failed on all %d filer(s)", len(r.filerAddrs))
}
next := make([]SeedPeer, 0, len(merged))
for _, m := range merged {
next = append(next, SeedPeer{PeerAddr: m.PeerAddr, DataCenter: m.DataCenter, Rack: m.Rack})
}
r.mu.Lock()
r.seeds = next
r.mu.Unlock()
return nil
}
func (r *PeerRegistrar) loopRegister() {
t := time.NewTicker(r.registerInterval)
defer t.Stop()
for {
select {
case <-r.stopCtx.Done():
return
case <-t.C:
if err := r.registerOnce(r.stopCtx); err != nil {
glog.V(2).Infof("MountRegister heartbeat: %v", err)
}
}
}
}
func (r *PeerRegistrar) loopList() {
t := time.NewTicker(r.listInterval)
defer t.Stop()
for {
select {
case <-r.stopCtx.Done():
return
case <-t.C:
if err := r.listOnce(r.stopCtx); err != nil {
glog.V(2).Infof("MountList refresh: %v", err)
}
}
}
}