Linux Storage - a Fibre Channel SAN for Linux hosts
In December 2013 I connected a blade enclosure full of Linux hypervisors to an HP 3PAR 7400 array through two Cisco MDS 9124e Fibre Channel blade switches. The array side was not part of my notes; they begin where its ports met the switches: the fabrics, the VSANs that kept the datacenter and the DMZ apart on the same hardware, the aliases and single-initiator zones that let each host see the storage and nothing else, port security so that no other adapter could take a host's place, and then the Linux side, where the operating system has to be asked, through sysfs and systool, what it sees through its HBAs before any LUN can be used.
This Solution is that work, written up from my working notes, in two parts. Articles 1 to 7 are the 2013 SAN: one array, two fabrics, two VSANs per switch, four or five blades with dual-port QLogic HBAs, one switch configured step by step, and one host inventoried down to the driver parameters. Articles 8 to 10 are older notes from 2010 on a different system that I kept with the SAN notes because they answer the question the 2013 notes stop at: what happens when a Linux host sees the same LUN down four paths. There the answer was the IBM/LSI RDAC multipath driver on Red Hat Enterprise Linux AS 4 in front of two IBM DS5300 arrays, built from source, with its own initrd, its own tools, and two problems that had to be solved by hand.
The system in one picture
flowchart TB subgraph storage1["Storage1, HP 3PAR 7400, ports as the schema names them"] n0["node 0: ports 0:1:1 and 0:1:2"] n1["node 1: ports 1:1:1 and 1:1:2"] end subgraph c7000["HP c7000 blade enclosure"] subgraph sw1["SW1, FCSwitch1, Cisco MDS 9124e"] v11["VSAN 11 MGMT_DC: ext1, bay1, bay2, bay5"] v12["VSAN 12 DMZ: ext2, bay3, bay4"] end subgraph sw2["SW2, per the schema only"] v21["VSAN 21: ext1, bay1, bay2, bay5"] v22["VSAN 22: ext2, bay3, bay4"] end hv01["bay1: HV01, BL660c Gen8, XenServer"] hv02["bay2: HV02, BL660c Gen8"] hv03["bay3: HV03, BL660c Gen8"] hv04["bay4: HV04, BL660c Gen8"] mgmt01["bay5: MGMT01, BL460c Gen8"] end n0 -- "0:1:1, Storage1-C0P0" --> v11 n0 -- "0:1:2, Storage1-C0P1" --> v12 n1 -- "1:1:1" --> v21 n1 -- "1:1:2" --> v22 v11 --- hv01 v11 --- hv02 v11 --- mgmt01 v12 --- hv03 v12 --- hv04 v21 --- hv01 v21 --- hv02 v21 --- mgmt01 v22 --- hv03 v22 --- hv04
The fictional environment
Every Article and every Config document uses the same names, addresses and World Wide Names.
| Thing | Value |
|---|---|
| Storage array | Storage1, HP 3PAR 7400, two controller nodes, FC ports 0:1:1, 0:1:2, 1:1:1, 1:1:2 by the cabling schema (aliases Storage1-C0P0, Storage1-C0P1 on the first switch); the port names themselves decode to the other node, see SCSI addressing and FC names |
| FC switches | SW1 configured as FCSwitch1 and SW2, Cisco MDS 9124e blade switches, NX-OS 5.2(8); management address 10.50.10.14/24, gateway 10.50.10.254 |
VSANs on FCSwitch1 | 11 MGMT_DC (datacenter) and 12 DMZ; the second switch uses 21 and 22 |
| Hosts | HV01 to HV04 (HP BL660c Gen8, XenServer; three or four of them, see the first finding below) in bays 1 to 4, MGMT01 (HP BL460c Gen8) in bay 5 |
| HBAs | QLogic QMH2572, two 8 Gb ports per blade, driver qla2xxx 8.05.00.03.55.6-k, firmware 5.09.00 |
| Host WWPNs | 50:01:43:80:12:34:xx:xx; storage WWPNs 2x:1x:00:02:ac:00:ab:cd; switch WWNs 54:7f:ee:ab:cd:xx and 54:7f:ee:ab:ce:xx |
| The 2010 system | host mppsrv01, Red Hat Enterprise Linux AS 4, kernel 2.6.9-89.0.9.ELsmp, RDAC driver 09.03.0B05.0331, arrays DS5300-SITEA (main) and DS5300-SITEB (standby) |
Host, switch, alias, zone and VSAN names are role names and were kept. The vendor parts of the World Wide Names are real, their serial parts are not; the array and LUN identifiers of the 2010 system are made up.
Articles
Read in this order; it is the order the work was done in.
| # | Article | What it covers |
|---|---|---|
| 1 | Overview and design | What was connected to what, the two fabrics and four VSANs, why the zoning looks the way it does, what the notes do not hold |
| 2 | SCSI addressing and FC names | Host, bus, target and LUN; WWNN, WWPN and FCID; how one HBA port's name is found again in the switch's login database, the alias, the zone and the array's port |
| 3 | Cisco MDS base configuration | Wiping the switch, the setup dialogue, management address, SSH, two VSANs and the interfaces assigned to them |
| 4 | FC aliases, zones and zonesets | Who is logged in, an alias per port, a zone per server, a zoneset per VSAN, and the interface-based zoning they replaced |
| 5 | Port security | Binding every WWPN to its interface, the licence grace period, learning turned off, and the checks |
| 6 | Linux HBA and SCSI inventory | What sysfs and systool tell about the HBAs, the fabric, the remote ports and the qla2xxx driver |
| 7 | LUNs seen and SCSI bus rescan | Six volumes and an enclosure device down two paths, and three ways to make the host look again |
| 8 | RDAC multipath driver basics | A different system in 2010: what the IBM/LSI MPP driver is, its modules, files, tools and the paths it manages |
| 9 | RDAC installation and operation | Building the driver, a GRUB entry with its own initrd, and the tools that show arrays, paths and LUNs |
| 10 | RDAC problems and LUN removal | A standby mirror that showed up as a second array, and removing LUNs and paths without a reboot |
Configuration
Each document holds one file, one command set or one listing as it was used, with comments and a check against the current release. The switch and the multipath driver leave few files to show, so most documents are command sets with the output they produced.
Cisco MDS 9124e
Linux host
| Document | Explained in |
|---|---|
| HBA attributes in sysfs | 6 |
| systool, class fc_host | 6 |
| systool, classes fc_transport and fc_remote_ports | 6 |
| systool, module qla2xxx | 6 |
| /proc/scsi/scsi | 7 |
| SCSI bus rescan | 7 |
RDAC multipath driver, 2010
What the write-up found
Reading the notes again turned up things I did not see when I wrote them. Each is told in its Article.
| Finding | Where |
|---|---|
The two sets of notes count three and four BL660c blades, and one of the two cabling schemas has no HV04 | 1 |
The notes name the switches MDS 9124e, a 4-Gbps model as far as Cisco's documents tell, while both HBA ports of HV01 report speed 8 Gbit; which blade switch it really was the notes do not say | 1 |
| The array's port names, read with HPE's documented scheme, do not sit on the switches where the cabling schema puts them | 2 |
| The old interface-based zones and zonesets stayed in the full zone database next to the new ones | 4 |
| In VSAN 12 the old interface-based zone had three members in the active database and two in the full database | 4 |
| The port-security headings say VSAN 21 and 22 while the commands say 11 and 12, and the prompt is misspelt throughout that section | 5 |
The remote ports ran with dev_loss_tmo 16 and fast_io_fail_tmo off, and the notes do not say whether anyone chose that | 6 |
| The notes stop at two paths to every volume; the host's multipathing is not in them | 7 |
The /proc/mpp listing after the installation has three LUNs per path and three virtual LUNs, where every other listing in the notes has two | 9 |
mppUtil -g 0 reports AVTEnabled: Y, while the vendor text quoted in the notes says AVT must be disabled for RDAC | 9 |
Four rescan examples (-s, -d, -u, -c) come from another host with six mptscsih adapters | 9 |
The vendor/model script has a typographic quote, and the path deletions redirect echo without an argument, which, as I understand the kernel, worked by accident | 10 |