Tags:
create new tag
view all tags

CMS Tier-3 News Item

Downtime for major upgrade of the SE on Thu Nov 29th - Fri 30th

Summary

Dcache, the Storage Element SW will be upgraded. The upgrade involves a complete migration of the underlying data base to a new format (chimera). Therefore, all operations involving access to the SE must be stopped for the time of the upgrade.

Details

Main purpose of this downtime is the upgrade of some dCache components that got very old in respect of the others CMS sites and the recent dCache developments.

The downtime will start after 21:00 on 28th Nov to exploit also that night; probably it won't take all the weekend but for the time being please consider Sunday 2nd Dec at 23:00 as its scheduled end.

Each t3ui0[2-7] server will be left ON, but during the downtime any connection to the storage element will be unavailable, so please use the t3ui*/scratch filesystem to store in advance the files that you want to analyze.

Also the worker nodes and the batch system will be left ON but, again, users won't be able to download/upload files to the storage element.

Obviously all the Phedex operations will be stopped too.

Downtime outcome

Dear T3 Users

in the background I still have to sort out some post migration issues but the T3 functionality from the user side is ok, so you can work.

but there are good news too; until 28th Nov, all of you were mapped in dCache like one unique linux user cmsuser and it was not possible to distinguish between the files produced by 2 users apart from the agreement that an user A will write in /pnfs/psi.ch/cms/trivcat/store/user/A while a user B should write in /pnfs/psi.ch/cms/trivcat/store/user/B ; also it was possible for user B to erase the file produced by user A .

now the T3 dCache will map your x509 DN to your Linux user account and the files will be still readable by everyone but just the owner will be able to delete the files because the write permission on the dir hosting his/her files will be ON just for him/her; because we're using the x509 DN stored during your initial account creation it could be that this DN is outdated and the authentication will fail ( I already got and fixed a case like that ), in this case please simply write us about this error and I'll update your DN. Just to avoid confusion a DN is a string like /DC=ch/DC=cern/OU=Organic Units/OU=Users/CN=mdunser/CN=706134/CN=Name Surname and you can extract that for instance executing:

$ voms-proxy-info | grep identi
identity  : /DC=com/DC=quovadisglobal/DC=grid/DC=switch/DC=users/C=CH/O=Paul-Scherrer-Institut (PSI)/CN=Fabio Martinelli

This example shows as now a /pnfs dir belongs to an user and his/her group, by default, can not delete his/her files:

$ srm-get-permissions srm://t3se01.psi.ch/pnfs/psi.ch/cms/trivcat/store/user/martinelli_f
# file  : srm://t3se01.psi.ch/pnfs/psi.ch/cms/trivcat/store/user/martinelli_f
# owner : 2980
owner:2980:RWX
user:2980:RWX
group:500:RX   <---- no write
other:RX       <---- no write

The group write permission was instead left on for the shared dir like b-physics:

$ srm-get-permissions srm://t3se01.psi.ch/pnfs/psi.ch/cms/trivcat/store/user/b-physics
# file  : srm://t3se01.psi.ch/pnfs/psi.ch/cms/trivcat/store/user/b-physics
# owner : 501
owner:501:RWX
user:501:RWX
group:500:RWX
other:RX        <---- no write
but since today, all the new files and subdirs will have a well known owner.

if you need to create a dir where also the others can write and delete files you can proceed in this way:

$ srmmkdir srm://t3se01.psi.ch/pnfs/psi.ch/cms/trivcat/store/user/martinelli_f/TESTDIR
$ srm-get-permissions srm://t3se01.psi.ch/pnfs/psi.ch/cms/trivcat/store/user/martinelli_f/TESTDIR
# file  : srm://t3se01.psi.ch/pnfs/psi.ch/cms/trivcat/store/user/martinelli_f/TESTDIR
# owner : 2980
owner:2980:RWX
user:2980:RWX
group:500:RX   <----no write yet
other:RX

$ srm-set-permissions -type=ADD -group=RWX srm://t3se01.psi.ch/pnfs/psi.ch/cms/trivcat/store/user/martinelli_f/TESTDIR

$ srm-get-permissions srm://t3se01.psi.ch/pnfs/psi.ch/cms/trivcat/store/user/martinelli_f/TESTDIR
# file  : srm://t3se01.psi.ch/pnfs/psi.ch/cms/trivcat/store/user/martinelli_f/TESTDIR
# owner : 2980
owner:2980:RWX
user:2980:RWX
group:500:RWX   <---- now they can write and erase files.
other:RX

Last news, for security reasons, nobody will be able to create or remove dir in the main dir /pnfs/psi.ch/cms/trivcat/store/user , for instance this srmmkdir fails:

$ srmmkdir srm://t3se01//pnfs/psi.ch/cms/trivcat/store/user/TESTDIR
Return code: SRM_AUTHORIZATION_FAILURE
Explanation: srm://t3se01//pnfs/psi.ch/cms/trivcat/store/user/TESTDIR : Permission denied

DerekFeichtinger 02. 11. 2012

T3NewsForm
Title Downtime for major upgrade of the SE on Thu Nov 29th - Fri 30th
Summary Dcache, the Storage Element SW will be upgraded. The upgrade involves a complete migration of the underlying data base to a new format (chimera). Therefore, all operations involving access to the SE must be stopped for the time of the upgrade.
User DerekFeichtinger
Date 02. 11. 2012
Edit | Attach | Watch | Print version | History: r4 < r3 < r2 < r1 | Backlinks | Raw View | Raw edit | More topic actions
Topic revision: r4 - 2012-12-02 - FabioMartinelli
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © 2008-2024 by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding TWiki? Send feedback