1 %define initdir %{_sysconfdir}/init.d
5 Packager: Samba Team <samba@samba.org>
10 License: GNU GPL version 3
11 Group: System Environment/Daemons
12 URL: http://ctdb.samba.org/
14 Source: ctdb-%{version}.tar.gz
16 Prereq: /sbin/chkconfig /bin/mktemp /usr/bin/killall
17 Prereq: fileutils sed /etc/init.d
19 Provides: ctdb = %{version}
22 BuildRoot: %{_tmppath}/%{name}-%{version}-root
25 ctdb is the clustered database used by samba
28 #######################################################################
32 # setup the init script and sysconfig file
33 %setup -T -D -n ctdb-%{version} -q
39 ## always run autogen.sh
42 CFLAGS="$RPM_OPT_FLAGS $EXTRA -O0 -D_GNU_SOURCE -DCTDB_VERS=\"%{version}-%{release}\"" ./configure \
44 --sysconfdir=%{_sysconfdir} \
46 --localstatedir="/var"
48 make docdir=%{_docdir} showflags
49 make docdir=%{_docdir}
52 # Clean up in case there is trash left from a previous build
53 rm -rf $RPM_BUILD_ROOT
55 # Create the target build directory hierarchy
56 mkdir -p $RPM_BUILD_ROOT%{_sysconfdir}/sysconfig
57 mkdir -p $RPM_BUILD_ROOT%{_sysconfdir}/init.d
59 make DESTDIR=$RPM_BUILD_ROOT docdir=%{_docdir} install
61 install -m644 config/ctdb.sysconfig $RPM_BUILD_ROOT%{_sysconfdir}/sysconfig/ctdb
62 install -m755 config/ctdb.init $RPM_BUILD_ROOT%{initdir}/ctdb
64 # Remove "*.old" files
65 find $RPM_BUILD_ROOT -name "*.old" -exec rm -f {} \;
68 rm -rf $RPM_BUILD_ROOT
71 [ -x /sbin/chkconfig ] && /sbin/chkconfig --add ctdb
75 [ -x /sbin/chkconfig ] && /sbin/chkconfig --del ctdb
80 if [ "$1" -ge "1" ]; then
81 %{initdir}/ctdb restart >/dev/null 2>&1 || true
85 #######################################################################
87 #######################################################################
92 %config(noreplace) %{_sysconfdir}/sysconfig/ctdb
93 %config(noreplace) %{_sysconfdir}/ctdb/functions
94 %attr(755,root,root) %{initdir}/ctdb
96 %{_docdir}/ctdb/README.eventscripts
97 %{_docdir}/ctdb/recovery-process.txt
98 %{_sysconfdir}/ctdb/events.d/00.ctdb
99 %{_sysconfdir}/ctdb/events.d/10.interface
100 %{_sysconfdir}/ctdb/events.d/20.multipathd
101 %{_sysconfdir}/ctdb/events.d/40.vsftpd
102 %{_sysconfdir}/ctdb/events.d/41.httpd
103 %{_sysconfdir}/ctdb/events.d/50.samba
104 %{_sysconfdir}/ctdb/events.d/60.nfs
105 %{_sysconfdir}/ctdb/events.d/61.nfstickle
106 %{_sysconfdir}/ctdb/events.d/70.iscsi
107 %{_sysconfdir}/ctdb/events.d/90.ipmux
108 %{_sysconfdir}/ctdb/events.d/91.lvs
109 %{_sysconfdir}/ctdb/events.d/99.routing
110 %{_sysconfdir}/ctdb/statd-callout
114 %{_bindir}/ctdb_ipmux
115 %{_bindir}/ctdb_diagnostics
117 %{_mandir}/man1/ctdb.1.gz
118 %{_mandir}/man1/ctdbd.1.gz
119 %{_mandir}/man1/onnode.1.gz
120 %{_includedir}/ctdb.h
121 %{_includedir}/ctdb_private.h
124 * Thu Apr 23 2009 : Version 1.0.69_2
125 - In the recovery daemon we dont need to check the nodemap status
127 * Wed Feb 5 2009 : Version 1.0.69_1
128 - Dont check the result of the modflags control, to allow compatibility
129 with earlier versions of ctdb
130 * Thu Dec 18 2008 : Version 1.0.69
131 - Various fixes to scripts by M Adam
132 - Dont call ctdb_fatal() when the transport is down during shutdown
133 * Fri Dec 12 2008 : Version 1.0.68
134 - Fixes for monitoring of interfaces status from Michael Adam.
135 - Use -q instead of >/dev/null for grep to enhance readability of the
136 scripts from Michael Adam.
137 - Update to the "ctdb recover" command. This command now block until the
138 has completed. This makes it much easier to use in scripts and avoids
139 the common workaround :
141 ... loop while waiting for recovery completes ...
143 - Add a CTDB_TIMEOUT variable. If set, this variable provides an automatic
144 timeout for "ctdb <command>", similar to using -T <timeout>
145 - Set a unique errorcode for "ctdb <command>" when it terminates due to a
146 timeout so that scripts can distinguish between a hung command and what was
148 - Update "ctdb ban/unban" so that if the cluster is in recovery these commands
149 blocks and waits until after recovery is complete before the perform the
150 ban/unban operation. This is necessary since the recovery process can cause
151 nodes to become automatically unbanned.
152 - Update "ctdb ban/unban" to block until the recovery that will follow shortly
153 after this command has completed.
154 This makes it much easier to use in scripts and avoids the common
157 ... loop while waiting for recovery completes ...
159 - Bugfix for the new flags handling in 1.0.67. Abort and restart monitoring
160 if we failed to get proper nodemaps from a remote node instead of
161 dereferencing a null pointer.
162 - If ctdbd was explicitely started with the '--socket' argument, make
163 ctdbd automatically set CTDB_SOCKET to the specified argument.
164 This ensures that eventscripts spawned by the ctdb daemon will default to
165 using the same socket and talk to the correct daemon.
166 This primarily affects running multiple daemons on the same host and where
167 you want each instance of ctdb daemons have their eventscripts talk to the
169 - Update "ctdb ping" to return an error code if the ping fail so that it
170 can be used in scripts.
171 - Update to how to synchronize management of node flags across the cluster.
172 * Thu Dec 3 2008 : Version 1.0.67
173 - Add a document describing the recovery process.
174 - Fix a bug in "ctdb setdebug" where it would refuse to set a negative
176 - Print the list of literals for debug names if an invalid one was given
178 - Redesign how "ctdb reloadnodes" works and reduce the amont of tcp teardowns
179 used during this event.
180 - Make it possible to delete a public ip from all nodes at once using
182 * Mon Nov 24 2008 : Version 1.0.66
183 - Allow to change the recmaster even when we are not frozen.
184 - Remove two redundant SAMBA_CHECK variables from the sysconf example
185 - After a node failure it can take very long before some lock operations
186 ctdb needs to perform are allowed/works with gpfs again. Workaround this
187 by treating a hang/timeout as success.
188 - Dont override CTDB_BASE is fet in the shell already
189 - Always send keepalive packets regardless of whether the link is idle or not.
190 - Rewrite the disable/enable flag update logic to prevent a race between
191 "ctdb disable/enable" and the recovery daemon when updating the flags to
193 * Thu Nov 13 2008 : Version 1.0.65
194 - Update the sysconfig example: The default debug level is 2 (NOTICE) and not
196 - Add support for a CTDB_SOCKET environment variable for the ctdb command
197 line tool. If set, this overrides the default socket the ctdb tool will
199 - Add logging of high latency operations.
200 * Mon Oct 22 2008 : Version 1.0.64
201 - Add a context and a timed event so that once we have been in recovery for
202 too long we drop all public addresses.
203 * Mon Oct 20 2008 : Version 1.0.63
204 - Remove logging of "periodic cleanup ..." in 50.samba
205 - When we reload a nodes file, we must detect this and reload the file also
206 in the recovery daemon before we try to dereference somethoung beyond the end
208 * Thu Oct 16 2008 : Version 1.0.62
209 - Allow multiple eventscritps using the same prefix number.
210 It is undefined which order scripts with the same prefix will execute in.
211 * Wed Oct 15 2008 : Version 1.0.61
212 - Use "route add -net" instead of "ip route add" when adding routes in 99.routing
213 - lower the loglevel os several debug statements
214 - check the status returned from ctdb_ctrl_get_tickles() before we try to print them out to the screen.
215 - install a new eventscript 20.multipathd whoich can be used to monitor that multipath devices are healthy
216 * Wed Oct 15 2008 : Version 1.0.60
217 - Verify that nodes we try to ban/unban are reachable and print an error othervise.
218 - Update the client and server sides of TAKEIP/RELEASEIP/GETPUBLICIPS and GETNODEMAP to fall back to the old style ipv4-only controls if the new ipv4/ipv6 controls fail. This allows an ipv4/v6 enabled ctdb daemon to interoperate with earlier ipv4-only versions of the daemons.
219 - From Mathieu Parent : log debian systems log the package versions in ctdb diagnostics
220 - From Mathieu Parent : specify logdir location for debian (this patch was later reversed)
221 - From Michael Adams : allow # comments in nodes/public_addresses files
222 * Tue Oct 7 2008 : Version 1.0.59
223 - Updated "reloadnodes" logic. Instead of bouncing the entire tcp layer it is sufficient to just close and reopen all outgoing tcp connections.
224 - New eventscript 99.routing which can be used to re-attach routes to public interfaces after a takeip event. (routes may be deleted by the kernel when we release an ip)
225 - IDR tree fix from Jim Houston
226 - Better handling of critical events if the local clock is suddenly changed forward by a lot.
227 - Fix three slow memory leaks in the recovery daemon
228 - New ctdb command : ctdb recmaster which prints the pnn of the recmaster
229 - Onnode enhancements from Martin S : "healthy" and "connected" are now possible nodespecifiers
230 - From Martin S : doc fixes
231 - lowering some debug levels for some nonvital informational messages
232 - Make the daemon daemon monitoring stronger and allow ctdbd to detect a hung
234 - From C Cowan : patches to compile ipv6 under AIX
235 - zero out some structs to keep valgrind happy
236 * Wed Aug 27 2008 : Version 1.0.58
237 - revert the name change tcp_tcp_client back to tcp_control_tcp so
239 - Updates to the init script from Abhijith Das <adas@redhat.com>
240 * Mon Aug 25 2008 : Version 1.0.57
241 - initial support for IPv6
242 * Mon Aug 11 2008 : Version 1.0.56
243 - fix a memory leak in the recovery daemon.
244 * Mon Aug 11 2008 : Version 1.0.55
245 - Fix the releaseip message we seond to samba.
246 * Fri Aug 8 2008 : Version 1.0.54
247 - fix a looping error in the transaction code
248 - provide a more detailed error code for persistent store errors
249 so clients can make more intelligent choices on how to try to recover
250 * Thu Aug 7 2008 : Version 1.0.53
251 - Remove the reclock.pnn file it can cause gpfs to fail to umount
252 - New transaction code
253 * Mon Aug 4 2008 : Version 1.0.52
254 - Send an explicit gratious arp when starting sending the tcp tickles.
255 - When doing failover, issue a killtcp to non-NFS/non-CIFS clients
256 so that they fail quickly. NFS and CIFS already fail and recover
258 - Update the test scripts to handle CTRL-C to kill off the test.
259 * Mon Jul 28 2008 : Version 1.0.51
260 - Strip off the vlan tag from bond devices before we check in /proc
261 if the interface is up or not.
262 - Use testparm in the background in the scripts to allow probing
263 that the shares do exist.
264 - Fix a bug in the logging code to handle multiline entries better
265 - Rename private elements from private to private_data
266 * Fri Jul 18 2008 : Version 1.0.50
267 - Dont assume that just because we can establish a TCP connection
268 that we are actually talking to a functioning ctdb daemon.
269 So dont mark the node as CONNECTED just because the tcp handshake
271 - Dont try to set the recmaster to ourself during elections for those
272 cases we know this will fail. To remove some annoying benign but scary
273 looking entries from the log.
274 - Bugfix for eventsystem for signal handling that could cause a node to
276 * Thu Jul 17 2008 : Version 1.0.49
277 - Update the safe persistent update fix to work with unpatched samba
279 * Thu Jul 17 2008 : Version 1.0.48
280 - Update the spec file.
281 - Do not start new user-triggered eventscripts if we are already
282 inside recovery mode.
283 - Add two new controls to start/cancel a persistent update.
284 A client such as samba can use these to tell ctdbd that it will soon
285 be writing directly to the persistent database tdb file. So if
286 samba is -9ed before it has eitehr done the persistent_store or
287 canceled the operation, ctdb knows that the persistent databases
288 'may' be out of sync and therefore a full blown recovery is called for.
289 - Add two new options :
290 CTDB_SAMBA_SKIP_CONF_CHECK and CTDB_SAMBA_CHECK_PORTS that can be used
291 to override what checks to do when monitoring samba health.
292 We can no longer use the smbstatus, net or testparm commands to check
293 if samba or its config is healthy since these commands may block
294 indefinitely and thus can not be used in scripts.
295 * Fri Jul 11 2008 : Version 1.0.47
296 - Fix a double free bug where if a user striggered (ctdb eventscript)
297 hung and while the timeout handler was being processed a new user
298 triggered eventscript was started we would free state twice.
299 - Rewrite of onnode and associated documentation.
300 * Thu Jul 10 2008 : Version 1.0.46
301 - Document both the LVS:cingle-ip-address and the REMOTE-NODE:wan-accelerator
303 - Add commands "ctdb pnn", "ctdb lvs", "ctdb lvsmaster".
304 - LVS improvements. LVS is the single-ip-address mode for a ctdb cluster.
305 - Fixes to supress rpmlint warnings
307 - Change \s to [[:space:]] in some scripts. Not all RHEL5 packages come
308 with a egrep that handles \s even same version but different arch.
309 - Revert the change to NFS restart. CTDB should NOT attempt to restart
311 - Rewrite of the waitpid() patch to use the eventsystem for handling
313 * Tue Jul 8 2008 : Version 1.0.45
314 - Try to restart the nfs service if it has failed to respond 3 times in a row.
315 - waitpid() can block if the child does not respond promptly to SIGTERM.
316 ignore all SIGCHILD signals by setting SIGCHLD to SIG_DEF.
317 get rid of all calls to waitpid().
318 - make handling of eventscripts hanging more liberal.
319 only consider the script to have failed and making the node unhealthy
320 IF the eventscript terminated wiht an error
321 OR the eventscript hung 5 or more times in a row
322 * Mon Jul 7 2008 : Version 1.0.44
323 - Add a CTDB_VALGRIND option to /etc/sysconfig/ctdb to make it start
324 ctdb under valgrind. Logs go to /var/log/ctdb_valgrind.PID
325 - Add a hack to show the control opcode that caused uninitialized data
326 in the valgrind output by encoding the opcode as the line number.
327 - Initialize structures and allocated memory in various places in
328 ctdb to make it valgrind-clean and remove all valgrind errors/warnings.
329 - If/when we destroy a lockwait child, also make sure we cancel any pending transactions
330 - If a transaction_commit fails, delete/cancel any pending transactions and
331 return an error instead of calling ctdb_fatal()
332 - When running ctdb under valgrind, make sure we run it with --nosetsched and also
333 ensure that we do not use mem-mapped i/o when accessing the tdb's.
334 - zero out ctdb->freeze_handle when we free/destroy a freeze-child.
335 This prevent a heap corruption/ctdb crash bug that could trigger
336 if the freeze child times out.
337 - we dont need to explicitely thaw the databases from the recovery daemon
338 since this is done implicitely when we restore the recovery mode back to normal.
339 - track when we start and stop a recovery. Add the 'time it took to complete the
340 recovery' to the 'ctdb uptime' output.
341 Ensure by tracking the start/stop recovery timestamps that we do not
342 check that the ip allocation is consistend from inside the recovery daemon
343 while a different node (recovery master) is performing a recovery.
344 This prevent a race that could cause a full recovery to trigger if the
345 'ctdb disable/enable' commands took very long.
346 - The freeze child indicates to the master daemon that all databases are locked
347 by writing data to the pipe shared with the master daemon.
348 This write sometimes fail and thus the master daemon never notices that the databases
349 are locked cvausing long timeouts and extra recoveries.
350 Check that the write is successful and try the write again if it failed.
351 - In each node, verify that the recmaster have the right node flags for us
352 and force a push of our flags to the recmaster if wrong.
353 * Tue Jul 1 2008 : Version 1.0.43
354 - Updates and bugfixes to the specfile to keep rpmlint happy
355 - Force a global flags update after each recovery event.
356 - Verify that the recmaster agrees with our node flags and update the
358 - When writing back to the parent from a freeze-child across the pipe,
359 loop over the write in case the write failed with an error othervise
360 the parent will never be notified tha the child has completed the operation.
361 - Automatically thaw all databases when recmaster marks us as being in normal
362 mode instead of recovery mode.
363 * Fri Jun 13 2008 : Version 1.0.42
364 - When event scripts have hung/timedout more than EventScriptBanCount times
365 in a row the node will ban itself.
366 - Many updates to persistent write tests and the test scripts.
367 * Wed May 28 2008 : Version 1.0.41
368 - Reactivate the safe writes to persistent databases and solve the
369 locking issues. Locking issues are solved the only possible way,
370 by using a child process to do the writes. Expensive and slow but... .
371 * Tue May 27 2008 : Version 1.0.40
372 - Read the samba sysconfig file from the 50.samba eventscript
373 - Fix some emmory hierarchical bugs in the persistent write handling
374 * Thu May 22 2008 : Version 1.0.39
375 - Moved a CTDB_MANAGES_NFS, CTDB_MANAGES_ISCSI and CTDB_MANAGES_CSFTPD
376 into /etc/sysconfig/ctdb
377 - Lowered some debug messages to not fill the logfile with entries
378 that normally occur in the default configuration.
379 * Fri May 16 2008 : Version 1.0.38
380 - Add machine readable output support to "ctdb getmonmode"
381 - Lots of tweaks and enhancements if the event scripts are "slow"
382 - Merge from tridge: an attempt to break the chicken-and-egg deadlock that
383 net conf introduces if used from an eventscript.
384 - Enhance tickles so we can tickle an ipv6 connection.
385 - Start adding ipv6 support : create a new container to replace sockaddr_in.
386 - Add a checksum routine for ipv6/tcp
387 - When starting up ctdb, let the init script do a tdbdump on all
388 persistent databases and verify that they are good (i.e. not corrupted).
389 - Try to use "safe transactions" when writing to a persistent database
390 that was opened with the TDB_NOSYNC flag. If we can get the transaction
391 thats great, if we cant we have to write anyway since we cant block here.
392 * Mon May 12 2008 : Version 1.0.37
393 - When we shutdown ctdb we close the transport down before we run the
394 "shutdown" eventscripts. If ctdb decides to send a packet to a remote node
395 after we have shutdown the transport but before we have shutdown ctdbd
396 itself this could lead to a SEGV instead of a clean shutdown. Fix.
397 - When using the "exportfs" command to extract which NFS export directories
398 to monitor, exportfs violates the "principle of least surprise" and
399 sometimes report a single export line as two lines of text output
400 causing the monitoring to fail.
401 * Fri May 9 2008 : Version 1.0.36
402 - fix a memory corruption bug that could cause the recovery daemon to crash.
403 - fix a bug with distributing public ip addresses during recovery.
404 If the node that is the recovery master did NOT use public addresses,
405 then it assumed that no other node in the cluster used them either and
406 thus skipped the entire step of reallocating public addresses.
407 * Wed May 7 2008 : Version 1.0.35
408 - During recovery, when we define the new set of lmasters (vnnmap)
409 only consider those nodes that have the can-be-lmaster capability
410 when we create the vnnmap. unless there are no nodes available which
411 supports this capability in which case we allow the recmaster to
412 become lmaster capable (temporarily).
413 - Extend the async framework so that we can use paralell async calls
414 to controls that return data.
415 - If we do not have the "can be recmaster" capability, make sure we will
416 lose any recmaster elections, unless there are no nodes available that
417 have the capability, in which case we "take/win" the election anyway.
418 - Close and reopen the reclock pnn file at regular intervals.
419 Make it a non-fatal event if we occasionally fail to open/read/write
421 - Monitor that the recovery daemon is still running from the main ctdb
422 daemon and shutdown the main daemon when recovery daemon has terminated.
423 - Add a "ctdb getcapabilities" command to read the capabilities off a node.
424 - Define two new capabilities : can be recmaster and can be lmaster
425 and default both capabilities to YES.
426 - Log denied tcp connection attempts with DEBUG_ERR and not DEBUG_WARNING
427 * Thu Apr 24 2008 : Version 1.0.34
428 - When deleting a public ip from a node, try to migrate the ip to a different
430 - Change catdb to produce output similar to tdbdump
431 - When adding a new public ip address, if this ip does not exist yet in
432 the cluster, then grab the ip on the local node and activate it.
433 - When a node disagrees with the recmaster on WHO is the recmaster, then
434 mark that node as a recovery culprit so it will eventually become
436 - Make ctdb eventscript support the -n all argument.
437 * Thu Apr 10 2008 : Version 1.0.33
438 - Add facilities to include site local adaptations to the eventscript
439 by /etc/ctdb/rc.local which will be read by all eventscripts.
440 - Add a "ctdb version" command.
441 - Secure the domain socket with proper permissions from Chris Cowan
442 - Bugfixes for AIX from Chris Cowan
443 * Wed Apr 02 2008 : Version 1.0.32
444 - Add a control to have a node execute the eventscripts with arbitrary
445 command line arguments.
446 - Add a control "rddumpmemory" that will dump the talloc memory allocations
447 for the recovery daemon.
448 - Decorate the talloc memdump to produce better and easier memory leak
450 - Update the RHEL5 iscsi tgtd scripts to allow one iscsi target for each
452 - Add two new controls "addip/delip" that can be used to add/remove public
453 addresses to a node at runtime. After using these controls a "ctdb recover"
454 ir required to make the changes take.
455 - Fix a couple of slow memory leaks.
456 * Tue Mar 25 2008 : Version 1.0.31
457 - Add back controls to disable/enable monitoring on a node.
458 - Fix a memory leak where we used to attach CALL data to the ctdb structure
459 when performing a local call. Memory which would be lost if the call was
461 - Reduce the loglevel for the log output when someone connects to a non
462 public ip address for samba.
463 - Redo and optimize the vacuuming process to send only one control to each
464 other node containing all records to be vacuumed instead of one
465 control per node per record.
466 * Tue Mar 04 2008 : Version 1.0.30
467 - Update documentation cor new commands and tuneables
468 - Add machinereadable output to the ip,uptime and getdebug commands
469 - Add a moveip command to manually failover/failback public ips
470 - Add NoIPFallback tuneable that prevents ip address failback
471 - Use file locking inside the CFS as alternative to verify when other nodes
472 Are connected/disconnected to be able to recover from split network
473 - Add DisableWhenUnhealthy tunable
474 - Add CTDB_START_AS_DISABLED sysconfig param
475 - Add --start-as-disabled flag to ctdb
476 - Add ability to monitor for OOM condition
477 * Thu Feb 21 2008 : Version 1.0.29
478 - Add a new command to make expansion of an existing cluster easier
479 - Fix bug with references to freed objects in the ctdb structure
480 - Propagate debuglevel changes to the recovery daemon
481 - Merge patches to event scripts from Mathieu Parent :
482 - MP: Simulate "service" on systems which do not provide this tool
483 - MP: Set correct permissions for events.d/README
484 - Add nice helper functions to start/stop nfs from the event scripts
485 * Fri Feb 08 2008 : Version 1.0.28
486 - Fix a problem where we tried to use ethtool on non-ethernet interfaces
487 - Warn if the ipvsadm packege is missing when LVS is used
488 - Dont use absolute pathnames in some of the event scripts
489 - Fix for persistent tdbs growing inifinitely.
490 * Wed Feb 06 2008 : Version 1.0.27
491 - Add eventscript for iscsi
492 * Thu Jan 31 2008 : Version 1.0.26
493 - Fix crashbug in tdb transaction code
494 * Tue Jan 29 2008 : Version 1.0.25
495 - added async recovery code
496 - make event scripts more portable
497 - fixed ctdb dumpmemory
498 - more efficient tdb allocation code
499 - improved machine readable ctdb status output
501 * Wed Jan 16 2008 : Version 1.0.24
502 - added syslog support
503 - documentation updates
504 * Wed Jan 16 2008 : Version 1.0.23
505 - fixed a memory leak in the recoveryd
506 - fixed a corruption bug in the new transaction code
507 - fixed a case where an packet for a disconnected client could be processed
508 - added http event script
509 - updated documentation
510 * Thu Jan 10 2008 : Version 1.0.22
511 - auto-run vacuum and repack ops
512 * Wed Jan 09 2008 : Version 1.0.21
513 - added ctdb vacuum and ctdb repack code
514 * Sun Jan 06 2008 : Version 1.0.20
515 - new transaction based recovery code
516 * Sat Jan 05 2008 : Version 1.0.19
517 - fixed non-master bug
518 - big speedup in recovery for large databases
519 - lots of changes to improve tdb and ctdb for high churn databases
520 * Thu Dec 27 2007 : Version 1.0.18
521 - fixed crash bug in monitor_handler
522 * Tue Dec 04 2007 : Version 1.0.17
523 - fixed bugs related to ban/unban of nodes
524 - fixed a race condition that could lead to monitoring being permanently disabled,
525 which would lead to long recovery times
526 - make deterministic IPs the default
527 - fixed a bug related to continuous recovery
528 - added a debugging option --node-ip