QuantaStor Touch Files

From OSNEXUS Online Documentation Site
Jump to navigation Jump to search

A touch file is an empty marker file that switches a single piece of QuantaStor service behaviour on or off. The service keeps an internal registry of them -- 209 in this release -- and checks for each one by name. Creating the file changes what the service does; deleting it restores the shipping behaviour.

Touch files are for use only with guidance from OSNEXUS support. They exist so that support and engineering can carry a customer past a specific problem, or capture diagnostics from a system that is misbehaving, without waiting for a code change. They are not a configuration surface, they are not tunables, and they are not documented here so that they can be surveyed and tried. Several of them disable safety checks, several change how a Storage Pool is imported or exported, and a few are destructive. Nothing on this page should be created on a production appliance unless a support engineer asked for it by name and explained why.

This page exists for two readers: someone who found a tf_* file on an appliance and needs to know what it is, and someone who has been asked by support to create one and wants to confirm what it does before doing so. If you are looking for settings to tune, the pages that own that subject are Storage System Optimization, Performance Tuning and QuantaStor Configuration Files.

Section Purpose
What a touch file is Empty file, presence is the signal, one exception where content is read.
Where touch files live The touch-file directory, and the legacy paths that are still honoured.
The .enable and .disable naming convention How to read a name, and the names that follow neither form.
When a touch file takes effect Whether a service restart is needed. It depends on the touch file.
Identifying a file you found in the directory Most likely the product put it there. How to check.
Listing the touch files on a system The one supported way to dump the registry and see which are active.
Working with support Creating and removing one, and what to send with the request.
Touch file reference All 209 registered touch files, grouped by subsystem.
Deprecated touch files Four tagged deprecated, and twelve that are registered but read nowhere.
Touch files outside the registry A handful honoured by startup scripts rather than the service.

What a touch file is

A touch file is an ordinary empty file. The service asks only whether the file exists -- it does not read the contents, does not parse a value out of it, and does not care about its size, owner or timestamp. Creating one with touch is sufficient, and that is where the name comes from:

sudo touch /var/opt/osnexus/quantastor/touchfiles/tf_smartctl.disable

Removing the file restores the shipping behaviour:

sudo rm /var/opt/osnexus/quantastor/touchfiles/tf_smartctl.disable

One touch file is content-bearing rather than presence-only. /etc/qs_nfsv4rootoptions holds the NFSv4 root-level export options to use in place of the built-in defaults, one line of export options. The service reads it, trims surrounding whitespace and parentheses, and requires fsid=0 to appear in what it finds -- if that is missing the whole value is replaced with ro,fsid=0, so a malformed entry silently exports the NFSv4 root read-only rather than failing. Every other touch file in the reference below is presence-only.

The service also writes a few of these files itself, and in a couple of cases writes a short explanatory message into them. Those are covered under State markers written by the product and should be left alone.

Where touch files live

Touch files live in a single directory:

/var/opt/osnexus/quantastor/touchfiles/

The service creates the directory at startup if it is not already there. It is owned by root with mode 0755, so creating and removing touch files needs root -- log in as qadmin and use sudo. The files themselves are created empty and their permissions do not matter.

Legacy paths are still honoured

Touch files used to be scattered across /etc under names like /etc/qs_disable_smartctl. That is still recognised: 87 of the 209 registrations carry a legacy path alongside the modern name, and the service treats a file at either location as equivalent. The modern path in the touch-file directory is checked first; if it is absent the legacy path is checked, and a file at the legacy path is just as effective.

At service startup the legacy files are migrated -- copied to the touch-file directory under the modern name, and the old file deleted -- so a system upgraded from an older release ends up with everything in one place. The migration is deliberately narrow, and only covers a registration that has both a modern name and a legacy path and whose modern name contains enable or disable. Twenty registrations fall outside that, so a legacy file at, for example, /etc/qs_nfsv4rootoptions or /etc/qs_cleanshutdown stays where it is indefinitely and keeps working from there. Both columns are given in the reference tables for that reason.

Fourteen registrations have only a legacy path and no modern name at all -- /etc/qs_disablelogrotate is one. For those, the legacy path in /etc (or /run) is the only place the service looks. Create them there.

The .enable and .disable naming convention

Most touch-file names end in one of two suffixes, and the suffix tells you which way the switch runs:

Suffix Count Meaning when the file is present
.enable 108 Turns on behaviour that is off by default.
.disable 62 Suppresses behaviour that is on by default.

So tf_smartctl.disable stops the service gathering SMART data, which it otherwise does; tf_iscsi_alua.enable switches on iSCSI ALUA support, which is otherwise off. In both cases the default is the opposite of what the file selects, which is the point -- a touch file is always an exception to the shipping behaviour, never a confirmation of it.

Read the suffix, not the stem. A name that reads oddly usually turns out to mean "enable the suppression of something": tf_sedutil_disable_unlocking.enable enables the disabling of boot-time SED unlocking, and tf_block_replication_sched.enable enables the blocking of replication schedules. The Effect when the file is present column in the reference is authoritative; use it rather than inferring from the name.

Names that follow neither convention

Thirty-nine registrations do not use either suffix, and they fall into recognisable kinds:

  • State markers written by the product -- tf_cleanshutdown, tf_vm_customize.completed, tf_enforce_httpsecure.applied, tf_loadbalancer.created. The service creates these to record that something happened. Do not create or delete them.
  • One-shot actions -- tf_all_ids.reset, tf_system_id.reset, tf_corosync_conf.rewrite, tf_systemd_linkgen.rebuild, tf_ceph_config_cleanup, tf_send_log_report.enable. The service performs the action once and then deletes the file itself. Several of these are destructive.
  • Suffixes that mean the same as .disable -- tf_cephfsmon.block, tf_cephinsecurereclaimwarn.block.
  • No suffix at all -- tf_verify_port_names, tf_force_netplan_conversion, tf_hotspare_debug_dump_pool_status and the fourteen legacy-path-only entries.

When a touch file takes effect

The service does not cache the answer. Every check stats the file at that moment, so a touch file becomes effective as soon as the next check runs -- and how soon that is depends entirely on where in the service the check sits. There is no single answer, so this is the practical question to settle with support before creating one.

Where the check runs When the file takes effect Groups where this is typical
Driver and service startup Requires a service restart. Nothing happens until the service starts again. SCST and ZFS driver bypass, ZIL sizing, netplan conversion, port-name verification, SED boot unlocking, VM customization
A monitoring or discovery cycle Within one cycle, no restart needed. SMART and IPMI polling, hotspare management, hardware and device correlation, HA connectivity and pool health checks, Ceph discovery, bucket discovery
A specific operation On the next time that operation runs. Pool create and import, volume assignment, share create and export, target login, replication schedule activation, HA failover
Once, then self-clearing On the next startup or next cycle, after which the service deletes the file. The one-shot actions listed above

Where a restart is needed, restart the service rather than rebooting:

sudo systemctl restart quantastor

A touch file that gates an HA failover path or a Storage Pool import path will not show any effect until that path is next exercised, which on a healthy cluster may be a long time. That is normal, and it is a reason to remove the file once the situation it was created for has passed.

Identifying a file you found in the directory

Almost certainly the product put it there. On a stock appliance the touch-file directory holds only markers the service and the installer write for their own bookkeeping -- typically half a dozen, all of them empty:

  • tf_cleanshutdown -- the last service shutdown was clean
  • tf_vm_customize.completed, tf_vm_pwd_customize.completed -- one-time VM OVF customization has run
  • tf_enforce_httpsecure.applied -- HTTPS enforcement has been applied once
  • tf_rdrand.enable -- the CPU supports the RDRAND instruction, recorded by the startup script
  • tf_multipath_autoconf.enable -- written by the installer

Look the name up in the reference below to see what it selects. If it is in State markers written by the product, leave it alone -- deleting a marker makes the service repeat work it has already done, and in the case of tf_enforce_httpsecure.applied re-applies a security setting that may have been deliberately changed since.

If you find a file that is not a state marker and nobody remembers creating it, that is worth a support case: it means an exception was left in place after whatever it was created for was resolved, and it is now silently overriding a default.

Listing the touch files on a system

Ask the service to dump its registry into the service log. This is the supported way to see every registered touch file together with whether it is currently active:

qs trace-level-modify --trace-options=touchfiles

The command leaves the trace level and every other trace setting as they were; it only triggers the dump. One line per registration is written to /var/log/qs/qs_service.log:

ID: '9' STATUS: 'NOT-PRESENT' FILE: 'tf_smartctl.disable' LEGACY: '/etc/qs_disable_smartctl'
    DESC: 'Blocks the gathering of SMARTCTL information.'
ID: '50' STATUS: 'ACTIVE' FILE: 'tf_cleanshutdown' LEGACY: '/etc/qs_cleanshutdown'
    DESC: 'Indicates that the system completed a clean shutdown....'

STATUS reports ACTIVE when the file is present at either the modern or the legacy path, and NOT-PRESENT otherwise, so the dump is also the quickest way to confirm that a file support asked for has landed somewhere the service is actually looking. Filter it with:

sudo grep "STATUS: 'ACTIVE'" /var/log/qs/qs_service.log | tail -40

The numeric ID is internal to one service process and is not stable between releases -- match on the file name, never on the ID.

A plain directory listing shows what has been created but not what could be, and it misses anything sitting at a legacy path in /etc:

sudo ls -la /var/opt/osnexus/quantastor/touchfiles/

Working with support

Every registered touch file carries a one-line description in the service itself, which is why the reference below can be generated from the product rather than maintained by hand: a description is a required part of adding one, so the registry does not drift out of date. That description is what the touchfiles trace dump prints and what the Effect column reproduces.

When support asks for a touch file:

  1. Confirm the exact name. A misspelled name is inert -- the service is looking for one specific string, and nothing warns you that a file in the directory matches no registration.
  2. Ask which of the four timings above applies, so you know whether a service restart is part of the request.
  3. Create it with touch in /var/opt/osnexus/quantastor/touchfiles/, or at the legacy path for one of the fourteen entries that has no modern name.
  4. Confirm it is seen with the touchfiles trace dump -- the entry should read ACTIVE.
  5. Send a log report. Support will normally want the logs from before and after, which is what Send System Log Report collects.
  6. Remove it when the situation is resolved. A touch file has no expiry and no reminder. Left behind, it keeps overriding a default across upgrades and reboots, and it will not be obvious later why the system behaves differently from an identical appliance beside it.

In a grid or an HA cluster, a touch file applies only to the system it was created on. If the behaviour needs to be consistent across a failover pair, the file has to exist on both nodes -- and it has to be removed from both.

Touch file reference

Warning: These touch files change service behaviour, and a number of them disable safety checks, alter how a Storage Pool is imported or exported, or perform a destructive one-time action. Create one only when OSNEXUS support has asked for it by name. This reference is here so that you can confirm what a support engineer has requested and identify a file you have found -- it is not a list of options to evaluate. Entries marked (debug only) exist to produce diagnostics or to force an error-prone code path, and must not be left in place on a production system.

Generated from the touch-file registry in the QuantaStor service, grouped by the subsystem each one affects. The Legacy path column shows the older /etc location where one is still recognised.

Storage pools and ZFS

Touch file Legacy path Effect when the file is present
tf_ashift_12.enable — Hard set ashift=12 during zpool create commands.
tf_ashift_9.enable — Hard set ashift=9 during zpool create commands.
tf_auto_pool_metadata_backup.disable /etc/qs_auto_pool_metadata_backup.disable Disables automatic backup of the pool metadata on service startup.
tf_bypass_zfs_driver.enable /etc/qs_bypass_zfs_driver Skips initialization and startup of the ZFS drivers. Registered but read nowhere in this release, so creating it has no effect.
tf_disable_draid_size_check.enable — Disable the check for draid pool minimum disks.
tf_disk_optimizations.disable /etc/qs_disk_optimizations.disable Disables disk optimizations applied by the pool configuration settings in /etc/qs_io_profile.conf.
tf_exact_path_pool_import.enable — Enables pool import using specification of exact device paths when possible.
tf_fix_pool_mount.enable /etc/qs_fixpoolmount Attempts to fixup the pool mountpoint in the event that there are files in the way preventing the pool from cleanly mounting to /mnt/storage-pools/.
tf_import_all.enable — Imports metadata for volumes and shares even if the pool scan did not detect them.
tf_limit_data_set_depth.enable — Enable the use of depth limiting feature in ZFS discovery.
tf_maximize_zil.disable /etc/qs_maximize_zil.disable On system startup the ZIL size is checked and optimized for the amount of RAM in the system unless blocked by this touchfile.
tf_pool_export_triage.enable — Support-only: when a share/volume repeatedly fails to unmount during pool export (qs_pool_export.py) this spawns the deep triage call-out qs_pool_export_triage.sh to capture point-in-time diagnostics at the moment of failure. Off by default.
tf_premount_share_check.disable — Disables the share mount pre-check on pool startup.
tf_removebadudev.disable /etc/qs_optimizeudev.disabled Blocks the removal of unused udev device links under /dev/disk/ before pool import.
tf_storage_system_tunables.disable — Disables application of Storage System Tunables as defined in the qs_systemtunables.conf file.
tf_transient_snap_prefix.enable — Enable cleaning of custom GMT snapshots.
tf_zfs_import_use_cachefile.enable /etc/qs_zfsimport_usecachefile.enable Default behavior is to not use the ZFS cachefile as it can be stale and testing has shown little improvement in import speed. This touchfile enables its use.

Storage volumes, SAN targets and initiators

Touch file Legacy path Effect when the file is present
none -- legacy path only /etc/qs_scst_copymanager_lun_removal.disable Removal of the copy manager LUN is done before device removal, touching this file will disable that.
none -- legacy path only /etc/qs_scst_copymanager_lunnumber_fix.disable Copy manager LUN number reassignment to over 8000 after the t10 id is set correctly can be disabled with this touch file.
tf_assignment_issuelip.enable /etc/qs_assignment_issuelip.enable By default do we not issue a FC LIP on storage volume assignment, use this touchfile to enable it.
tf_bypass_fping.enable — Bypasses the fping check for nvme discover commands.
tf_bypass_target_driver.enable /etc/qs_bypass_target_driver Skips initialization and startup of the SCST drivers.
tf_fc_targetmode_autoenable.disable — Blocks service from automatically enabling FC target mode on target mode capable ports (Qlogic).
tf_iscsi_alua.enable — Enable support for iSCSI ALUA when FC card(s) are present.
tf_iscsi_login_bulkmode.enable /etc/qs_iscsilogin_bulkmode.enable (debug only) Bulk iSCSI target login mode, error-prone, debug only option.
tf_iscsi_login_nothreading.enable /etc/qs_iscsilogin_nothreading.enable (debug only) iSCSI target logins are parallelized by default unless this option is set.
tf_iscsiadm_mgmt.disable — Disables iSCSI software controller management.
tf_nvme_login_bulkmode.enable /etc/qs_nvmelogin_bulkmode.enable (debug only) Bulk NVMe target login mode, error-prone, debug only option.
tf_nvme_login_nothreading.enable /etc/qs_nvmelogin_nothreading.enable (debug only) NVMe target logins are parallelized by default unless this option is set.
tf_nvme_mgmt.disable — Disables NVMe software controller management.
tf_scst_auto_teardown.enable /etc/qs_scst_auto_teardown.enable Enables automatic teardown of target devices which are unassigned.
tf_scst_blocksize4k.enable /etc/qs_scst_blocksize4k Forces SCST to export all Storage Volumes with a 4K block size.
tf_scst_fc_reltgtid_setup.disable /etc/init.d/qs_fc_rel_tgt_id_setup.disabled Blocks the setup of the relative target IDs for FC devices in SCST.
tf_scst_fileio_controldev.enable /etc/qs_usefilecontroldev Every FC configuration has a LUN0 which is a NULLIO device, this touch file changes that to using a small FILEIO device on the boot drive instead (legacy mode).
tf_scst_naa_id.disable /etc/qs_scst_naa_id.disable Disables generation of NAA ID on storage volumes for backwards compatibility.
tf_scst_nonrotational.enable /etc/qs_scst_nonrotational Forces SCST to export all block devices reporting as non-rotational (SSD) media.
tf_scst_nvcache.enable /etc/qs_scst_nvcache Forces all SCST devices to enable NV cache mode, not for production use.
tf_scst_usn.disable /etc/qs_scst_usn.disable Blocks the setting of the universal serial number on block devices configured in SCST.
tf_startup_issuelip.disable /etc/qs_startup_issuelip.disable By default we issue a FC LIP on system startup so that clients can find FC target ports that have joined the fabric, use this touchfile to disable it.
tf_swadapter_force_rescan.enable — Forces a full SW adapter rescan on every service restart rather than just on service startup after a reboot.
tf_wwnemulation.enable — Enables WWN and device emulation mode of 3rd party SANs.

High availability, clustering and IO fencing

Touch file Legacy path Effect when the file is present
tf_cib_auto_update_hostname.enable /etc/qs_cibautoupdatehostname (debug only) When QS systems are renamed the corosync/pacemaker hostname information is not updated due to issues of potential downtime. With this option enabled the service tries to update the CIB database using the script qs_cibupdatehostname.sh.
tf_cluster_manual_standby.enable — Keeps cluster in manual standby mode after a reboot. This is used for maintenance purposes only.
tf_corosync_conf.rewrite — Loads and then writes the corosync configuration file to upgrade it from an older version to newer version.
tf_crm_no_auto_stop.enable /etc/qs_crmnoautostop Blocks the stopping of the corosync/pacemaker service even when CRM services are not required.
tf_dlm_cluster_pr.enable — SUPPORT OVERRIDE: forces SCST DLM cluster-wide SCSI-3 persistent reservations ON for every HA pool on this node, ignoring the 'Enable SCSI3-PR Distributed Locking' setting on each HA Group. Intended for pinning the DLM up while HA Groups are being created and deleted. Nothing in the product writes or removes this file. Removing it returns control to the per-HA-Group setting; a pool whose devices are still in cluster_mode keeps the feature on, because an HA Group left on 'auto' resolves to enabled while the pool is carrying clustered reservations - only an explicit 'disabled' takes them away.
tf_edr_agent_ha_guard.enable — Enables HA failover guard to stop EDR agents during the pool export stage to ensure EDR services are not holding open file handles which can delay the failover process.
tf_fc_linkstatecheck.disable /etc/qs_fc_linkstatecheck.disabled Blocks the FC target-port link-state failover health check so an HA pool can be hosted/imported even when its FC target links are down.
tf_ha_callouts.enable /etc/qs_hacalloutsenabled Enables the use of HA callout scripts. Registered but read nowhere in this release, so creating it has no effect. HA callout scripts are no longer invoked.
tf_ha_connectivity_checks.disable — Disables port health checks specified in HA group policy settings which can trigger an HA failover.
tf_ha_failover.disable — Disable pool health checks that can trigger a HA failover.
tf_ha_skip_checks.enable /etc/qs_haskipchecks (debug only) Skips the device connectivity checks for HA pools.
tf_hafailover_issuelip.enable /etc/qs_hafailover_issuelip.enable By default do we not issue a FC LIP on failover, use this touchfile to enable it.
tf_iofence_checks.disable — Disables IO fencing checks.
tf_iofence_use_serialnum.enable — Use serial num for IO fencing ID.
tf_iofence_use_shortnguid.enable — Use short NGUID for IO fencing ID.
tf_no_change_ptpl.enable — Does not change the PTPL state to '0' (clear reservations and registrations on power on).
tf_res_type_wear.enable /etc/qs_prout_type_t7.enable Enables T7 (Write Exclusive All Registrants) persistent reservation mode for io fencing.
tf_restart_nfs_smb_on_export.disable — Default behavior is to restart the NFS and SMB services after exporting a pool for HA failover in order to force session cleanup.
tf_unique_regkey_per_i_t_nexus.enable /etc/qs_unique_regkey_per_i_t_nexus.enable Enables unique regkeys per I_T nexus for all persistent reservations.

Ceph and scale-out object storage

Touch file Legacy path Effect when the file is present
tf_bucket_discovery.disable — Required to skip complete bucket discovery.
tf_bucket_sync_policy_discovery.enable — Required to enable getting bucket sync policies of all buckets. Registered but read nowhere in this release, so creating it has no effect.
tf_ceph_alua.nonoptimized /etc/qs_ceph_alua.nonoptimized Sets the secondary FC ALUA nodes for a given Ceph pool to ALUA state non-optimized. This is not a supported mode and is only provided for R&D purposes.
tf_ceph_alua.standby /etc/qs_ceph_alua.standby Sets the secondary FC ALUA nodes for a given Ceph pool to ALUA state to standby. This is not a supported mode and is only provided for R&D purposes.
tf_ceph_config_cleanup — Cleanup the local ceph configuration from the system, and Quantastor database.
tf_ceph_continue_on_error.enable — Enable continuation of Ceph Cluster creation even if an error happens.
tf_ceph_iscsi_sv_only.disable /etc/qs_ceph_iscsi_sv_only.disable Only virtual interface Site VIF ports are allowed as iSCSI portals for Ceph based Storage Volumes unless this option is disabled.
tf_ceph_key_rotation.disable — Disables the automatic post-upgrade rotation of cephx daemon keys to the aes256k key type.
tf_ceph_osd_auto_start.enable — Required to enable automatic start up of down Ceph OSDs.
tf_ceph_rbd_info_cache.disable — Disables the RBD info cache which caches information from 'rbd du' to speed up the discovery cycle. Registered but read nowhere in this release, so creating it has no effect.
tf_ceph_rgw_loadbalancer.disable — Disables loadbalancer configuration management of /etc/nginx/conf.d/ceph-rgw-loadbalance.conf.
tf_cephfs_share_usage_update.disable — Disables the automatic updating of the usage information on CephFS based Network Shares. This can be an expensive process to run on shares with > 1M files.
tf_cephfsmon.block — Block all use of the CephFS ceph-fuse mount point monitoring script.
tf_cephinsecurereclaimwarn.block — Supress ceph warning for insecure global id reclaim.
tf_fast_osd_down.enable — Runs a check systems that are not communicating to quickly down the OSDs so that file and other services can resume more quickly.
tf_gridsync_buckets.disable — Required to disable sync of bucket information across the grid.
tf_nfs_cephfs_root_export.enable — Enables NFS exporting of the CephFS root via the nfs-kernel-server. This is a legacy backward compatibility option as CephFS NFS access is now managed via NFS Ganesha.
tf_pvscan_on_startup.enable — Run an additional pvscan on first-boot service startup when local OSDs and a NVMeoF software adapter configuration is present.
tf_qs_ceph_volume_patch.disable — Disables custom patching for ceph-volume.

Networking and target ports

Touch file Legacy path Effect when the file is present
none -- legacy path only /etc/qs_disablelinger Disables the socket SO_LINGER mode, default is off/disabled but can auto-enable if network issues are detected.
none -- legacy path only /etc/qs_enablelinger Enables the socket SO_LINGER mode as always on.
tf_force_netplan_conversion — This touchfile will force the netplan to interfaces conversion routine during service start-up.
tf_opstate_check.disable /etc/qs_disable_opstate_check Disables the operational state check on network ports. When disabled all ports report as Link Up.
tf_port_repair.disable — (debug only) Blocks all automatic repairs to port settings to match the network interfaces config file state.
tf_proxy_url_env.disable — Disable all management of the proxy server related settings in /etc/environment. Registered but read nowhere in this release, so creating it has no effect.
tf_proxy_url_noproxy.enable — Disable just management of the no_proxy setting in /etc/environment. Registered but read nowhere in this release, so creating it has no effect.
tf_systemd_linkgen.enable /etc/qs_systemd_linkgen.enable Enables the auto-generation of ethernet interface mapping .link files under /etc/systemd/network.
tf_systemd_linkgen.rebuild /etc/qs_systemd_linkgen.rebuild Does a one-time re-generation of link files for ethernet interfaces placing .link files under /etc/systemd/network.
tf_verify_port_names — On the next service startup, verify port name to MAC address mapping.

Network shares -- SMB, NFS and CephFS

Touch file Legacy path Effect when the file is present
none -- legacy path only /etc/qs_nfsv4rootoptions File contains a list of custom NFSv4 options to be applied to the root level export.
none -- legacy path only /etc/qs_xfsmountoptions Custom mount options for XFS based filesystems. Registered but read nowhere in this release, so creating it has no effect.
tf_fsids_on_reboot.enable /etc/qs_enablefsidsonreboot Disables the use of NFS fsids.
tf_nested_share_delimiter.enable — Enable the use of a custom delimiter rather than / for nested shares as presented via SMB.
tf_nested_share_fsid.enable — Default behavior is to not add fsid for nested shares. Creating this touch file will add fsid for nested shares.
tf_nfs_manage_gids.enable /etc/qs_enablenfsmanagegids This touch file must be present to use RPCMOUNTDOPTS=--manage-gids else the option will be removed from the NFS service configuration file.
tf_nfsv4_root_options.disable /etc/qs_nfsv4rootoptions.disable Blocks use of the NFSv4 root options when in NFSv4 mode.
tf_no_posix_acls.enable /etc/qs_noposixacls ZFS option acltype=posixacl is set by default on all new shares unless blocked by this touchfile.
tf_no_snap_links.enable /etc/qs_nosnaplinks Removes all the associated snapshot links to all share snapshot dirs 'sharename/.qsnaps'.
tf_smb_allow_insecure_wide_links.enable /etc/qs_smb_allowinsecurewidelinks.enable Allows SMB to use insecure wide links which is helpful for making symbolic links between local pools.
tf_smb_unix_extensions.enable /etc/qs_smb_unixextensions.enable Sets the 'unix extensions'='yes' in the SMB globals section. Default is 'no' unless insecure wide links are enable.
tf_zfs_no_xattr_sa.enable /etc/qs_zfs_no_xattr_sa Blocks the use of xattr=sa mode by default on ZFS based Network Shares.

Replication

Touch file Legacy path Effect when the file is present
none -- legacy path only /etc/rratelimit Old configuration file used to limit replication bandwidth for a system. Read once at service startup to carry an older system-wide replication rate limit onto the individual Storage System Links, after which the service deletes it. Set a bandwidth limit on the link instead.
tf_block_replication_sched.enable /etc/qs_blockrsched Completely blocks the activation of replication schedules.
tf_encrypted_share_replication.enable — Enables replication of encrypted shares.
tf_replication_rate_limit.disable /etc/rratelimit.disable (debug only) Disables the replication rate rebalancer so that replication bandwidth is not adjusted.
tf_resume_token_cleanup.disable — Default behavior is to cleanup any stale resume replication token. Adding this touch file will disable cleaning up of the token.
tf_sslink_default_online.enable /etc/qs_sslinkdefaultonline (debug only) Sets the default mode for System Replication Links to ONLINE/NORMAL at startup instead of OFFLINE.

Hardware controllers, enclosures and disks

Touch file Legacy path Effect when the file is present
tf_all_writeback_cache.disable — Disables write-back cache for all media types, not just rotational media.
tf_all_writeback_checks.disable — Disables write-back cache policy checks leaving them in their manufacturer default settings.
tf_bus_rescan.disable /etc/qs_bus_rescan.disable Blocks the rescanning of HBAs for new or missing devices.
tf_correlation_portsasaddress.enable — Enables physicalDisk--hwDisk device correlation by port sasAddress.
tf_correlation_serialnum.disable — Disables physicalDisk--hwDisk device correlation by serial number.
tf_correlation_vpd83id.disable — Disables physicalDisk--hwDisk device correlation by VPD page 83 Id.
tf_hotspare_debug_dummy_out_repair_action — Will allow the hotspare manager to determine which actions to perform for replacing a bad disk (and log those setup parameters) but will disable the actual swapping of the disk(s).
tf_hotspare_debug_dump_pool_status — Will allow debug-level storage pool status output to the log.
tf_hotspare_management.disable — Will disable any and all automated hotspare management. Registered but read nowhere in this release, so creating it has no effect.
tf_hotspare_offline_disk_repair.enable — Will allow automated hotspare management to treat disks in the OFFLINE state to be treated as bad disks.
tf_hw_configfile_rescan_repeat.enable — Will allow the hwAdapter Manager to re-read its configuration file on every hardware rescan cycle, instead of only once after startup.
tf_hw_correlation_summary_repeat.enable — Will allow the disk/hwdisk/hwunit correlation summary in the log to repeat on every cycle, instead of only once after startup.
tf_hw_perccli.disable — Disables the hardware adapter Dell perccli64 cli.
tf_hw_storcli.disable — Disables the hardware adapter storcli64 cli.
tf_hw_storcli2.disable — Disables the hardware adapter storcli2 cli.
tf_impimon.disable /etc/qs_disable_ipmi Blocks the gathering of information from ipmitool.
tf_ledmon_monitoring.enable — Prevents led mon service from being disabled and masked.
tf_limited_hw_discovery.enable — Marks a system to perform only limited hw discovery, for systems such as Seagate CORVAULT.
tf_lower_temp_threshold.enable — This touch file will allow lower temperature threshold to be set via the config file. Without the touch file the lowest limit is 50 C.
tf_miscabled_warning.disable — Will disable warnings associated with questionable redundant HBA-to-JBOD cabling.
tf_multipath_flush.disable /etc/qs_multipath_flush.disable (debug only) Blocks all calls to 'multipath -F'.
tf_nvme_secure_erase.disable — Disables the execution of the secure/crypto erase action during the formatting of nvme storage devices.
tf_nvme_smartlog.disable — Disables NVME smart-log checks.
tf_partition_sync.disable /etc/qs_partition_sync.disable Disables call to 'sync' after formatting devices to ensure IO is flushed to stable media.
tf_redetect_hw_layout.enable /etc/qs_redetect_hw_layout.enable Redetects the hardware layout configuration even if the enclosureLayoutId is already set on the storage system.
tf_sg_ses_concurrency.disable — Disables parallelized sg_ses disk ident/blink operations, allows only one-at-a-time serial mode.
tf_smartctl.disable /etc/qs_disable_smartctl Blocks the gathering of SMARTCTL information.
tf_startup_vgchange.enable — Adds a vgchange check at startup needed by some media types including SAS media from Seagate CORVAULT and Seagate Exos X.
tf_udev_rescan.disable /etc/qs_udev_rescan.disable Blocks udevadm trigger of scsi_host devices during disk rescan.

Security, encryption and self-encrypting drives

Touch file Legacy path Effect when the file is present
none -- legacy path only /etc/qs_enablesslv3 (debug only) SOAP default settings require SOAP_TLSv1, with this option SSLv3 and TLSv1 are allowed.
tf_allow_admin_perm_lock.disable — Disables the password manager from locking the 'admin' user account due to bad password attempts, short term lockouts still apply.
tf_clear_admin_perm_lock.enable — Clears the 'admin' user account lock.
tf_disable_mfa_for_ldap_users — Disable multi factor auth for ldap users.
tf_enforce_httpsecure.enable_once — Enables enforcement of HTTP secure mode once, doesn't reapply if the tf_enforce_httpsecure.applied exists.
tf_fips.enable — Enables FIPS 140-2 Level 1 security checks and enforcement.
tf_fips_entropy.enable — Enables FIPS entropy checks with output to /var/log/qs/qs_fips_entropy.NNN.
tf_force_des.enable — Forces legacy DES mode. Registered but read nowhere in this release, so creating it has no effect.
tf_import_xml_roles.disable /etc/qs_importxmlroles.disable Block import of new roles defined in the security XML configuration file.
tf_ldapsearch.disable — Will bypass ldapsearch and only use wbinfo to search for specific user/group.
tf_override_sed_locking_check.enable — Overrides the SED locking check.
tf_security_cache.disable — Disables security manager user cache in favor of sqlite database.
tf_sedOpal12.enable — Enable the use of self-encrypting disks with support for Opal version 1.2.
tf_sed_allow_nonsed_drives.enable — Enable the use of non-self-encrypting disks in the creation of ceph resources.
tf_sed_log_passphrase_hint.enable — Enable the logging of a small piece of the SED passphrase for debug logging.
tf_sed_threads_query.enable — Enable the use of threads when querying self-encrypting disks.
tf_sedutil_disable_unlocking.enable — Disable the boot-time unlocking of LOCKED self-encrypting devices.
tf_sedutil_force_unlocking.enable — Force the boot-time unlocking of self-encrypting devices, even if they are UNLOCKED.
tf_sedutil_logging.enable — Enable the logging of the sedutil-cli output to it's own dedicated log file.
tf_show_bad_passwords.enable /etc/qs_showbadpass.enable Shows bad password attempts in the log.

Alerting, statistics, logging and diagnostics

Touch file Legacy path Effect when the file is present
none -- legacy path only /etc/qs_disablelogrotate Blocks the rotation of the service log file.
none -- legacy path only /etc/qs_enablediag Enables diagnostic traces used for special debugging scenarios to get focused log output.
none -- legacy path only /etc/qs_securitydiag.enable Enables security diagnostic traces (DEBUG BUILD ONLY).
tf_command_timers.enable — Enables report of executed shell commands at various stages such as at startup and HA failover.
tf_drop_baskets.enable /etc/qs_dropbaskets (debug only) Drops a basket of events.
tf_drop_events.enable /etc/qs_dropevents (debug only) Drops all events. Registered but read nowhere in this release, so creating it has no effect.
tf_filtering.disable /etc/qs_disablefiltering Default task/alert enumeration behavior for the WUI was to get only the most recent 100, this touch file makes them all get sent. Still honoured by the service despite being tagged deprecated in the registry.
tf_influxdb_remote_access.enable — Allows InfluxDB (port 8086) to bind all interfaces for direct remote client access; default binds localhost only. Authentication still applies.
tf_optimized_stats.enabled — Only send stats to InfluxDB for capacity stats when the capacity changes.
tf_send_log_report.enable — Sends a log report then clears the touch file.
tf_sendlogs_ping_check.disable — Disables ping checks before sending logs which is necessary if the system cannot route ICMP packets.
tf_swapcheck.disable /etc/qs_swapcheck.disable Blocks the checking of the swap device for heavy utilization.
tf_telemetry.enable — Enables telemetry for the system.
tf_volume_session_log.disable /etc/qs_disablevolsessionlog Disables logging storage volume session activity.

Database, grid and system identity

Touch file Legacy path Effect when the file is present
tf_all_ids.reset /etc/qs_reset_ids Resets the QuanatStor Storage System ID.
tf_esm.disable /etc/qs_esmdisable Blocks the use of grid communication session IDs.
tf_force_db_backup.enable /etc/qs_forcedbbackup Force a backup of the osn.db.
tf_implicit_eject_node.enable /etc/qs_implicitejectnode.enable (debug only) A mode of operation where the grid implicity ejects nodes under certain conditions which it should not on normal operation.
tf_obj_cache.disable /etc/qs_disableobjcache Blocks the use of the in-memory object cache. It's now disabled by default as we're getting the benefits of read caching in the DB layer. Registered but read nowhere in this release, so creating it has no effect. The in-memory object cache it suppressed is off by default in any case.
tf_system_id.reset /etc/qs_reset_sysid Resets the storage system ID back to the default which is derived from eth0 MAC address.

Platform services and packaging

Touch file Legacy path Effect when the file is present
tf_container_mgmt.disable — Disables docker container management. Registered but read nowhere in this release, so creating it has no effect.
tf_internal_repo.redhat — Use internal quantastor package repository for redhat upgrades.
tf_keep_mlocate.enable /etc/qs_keep_mlocate By default the linux 'locate' command just slows things down so it is disabled. This will prevent the service from disabling it again.
tf_ntp.disable /etc/qs_ntp.disable Blocks updating the clock via NTP.
tf_vm_customize.enable — Required to enable VM OVF customization.

Simulation and test modes

Touch file Legacy path Effect when the file is present
tf_dev_disable_default_pass_check — Disable the default passphrase check on login.
tf_hwsim_adaptec.enable — Enable mode for hw simulation using outside acquired cli data files for the Adaptec hw adapter.
tf_hwsim_all.enable — Enable mode for hw simulation using outside acquired cli data files for all hw adapters.
tf_hwsim_dellboss.enable — Enable mode for hw simulation using outside acquired cli data files for the Dell Boss hw adapter.
tf_hwsim_graid.enable — Enable mode for hw simulation using outside acquired cli data files for the SupremeRAID GRAID hw adapter.
tf_hwsim_hpe.enable — Enable mode for hw simulation using outside acquired cli data files for the HPE hw adapter.
tf_hwsim_nvme.enable — Enable mode for hw simulation using outside acquired cli data files for the NVME hw adapter.
tf_hwsim_perccli.enable — Enable mode for hw simulation using outside acquired cli data files for the Dell perccli hw adapter.
tf_hwsim_sashba.enable — Enable mode for hw simulation using outside acquired cli data files for the SAS-HBA hw adapter.
tf_hwsim_storcli.enable — Enable mode for hw simulation using outside acquired cli data files for the LSI storcli hw adapter.
tf_hwsim_storcli2.enable — Enable mode for hw simulation using outside acquired cli data files for the LSI storcli2 hw adapter.
tf_iscsi_extsys_sim.enable — Enables (minimal) simulation of external systems/pools/volumes for imported iSCSI devices on VMs.
tf_iscsi_hwraid_sim.enable — Enables simulation of hw controllers/enclosures/disks for imported iSCSI devices on VMs.
tf_renew_lease_test.enable /etc/qs_renewlease.test Enables a special test mode for lease based license keys to renew more frequently.
tf_sedutil_simulator.enable — Enables the SEDUTIL simulator mode for debug/triage purposes.
tf_service_simulator.enable — Enables the service's 'simulator' mode, for analyzing foreign db files.
tf_simmode_special_operations.enable — Allows special testing operations in database simulation mode.

State markers written by the product

Touch file Legacy path Effect when the file is present
none -- legacy path only /etc/qs_inst_leavemaintmode Message from the postinst stage of the service package to leave maintenance mode at service startup.
none -- legacy path only /run/qs_reboot_required Indicates the system requires a reboot.
none -- legacy path only /run/swadapter_logout_shutdown Placed during system shutdown to prevent sw adapter target logins after logouts have run.
tf_ceph_sigv4_insecure.set — Written by the Ceph upgrade preflight when it sets rgw_sigv4_insecure=true for a multisite upgrade (CVE-2026-54330). The service clears the option and this marker once every zone in the grid is at Ceph 20.2.4+.
tf_cephfsmon.enable — This file is dynamically created by the service to enable CephFS ceph-fuse mount point monitoring. If a ceph-fuse mount becomes a zombie process it will try to auto-repair.
tf_cleanshutdown /etc/qs_cleanshutdown Indicates that the system completed a clean shutdown. Used by the service at startup to indicate the state of the last service shutdown task.
tf_enforce_httpsecure.applied — Indicates that HTTP secure mode enforcement has been applied.
tf_loadbalancer.created — Signifies that the load balancer is present on this system.
tf_loadbalancer.deleted — Signifies that the load balancer is not present on this system.
tf_vm_customize.completed — File exists after the one time customization of the platform has been applied using properties stored int the VM OVF 'CustomProperties' fields.
tf_vm_pwd_customize.completed — File exists after the one time customization of the password has been applied using the password property stored int the VM OVF 'CustomProperties' fields.

Deprecated touch files

Four registrations carry a deprecation tag in the registry, and they do not all mean the same thing:

Touch file Status
tf_obj_cache.disable Inert. Nothing reads it. The in-memory object cache it suppressed is off by default regardless.
tf_ha_callouts.enable Inert. HA callout scripts are no longer invoked.
/etc/rratelimit Still acted on, once. At service startup an older system-wide replication rate limit is carried onto the individual Storage System Links and the file is then deleted. Set a bandwidth limit on the link instead -- see Remote-replication / Disaster Recovery Setup.
tf_filtering.disable Still honoured. The tag is stale: the service continues to check it when the web interface enumerates tasks and alerts.

Separately, twelve registrations -- the two inert ones above among them -- are registered with a description but are not read by any shipped code in this release. They are flagged in the reference tables, and creating one has no effect. tf_hotspare_management.disable is the one most likely to mislead: its description says it disables all automated hotspare management, and it does not.

Touch files outside the registry

A handful of touch files live in the same directory but are read by the startup scripts, the installer, the shell utilities or the filesystem-monitor daemon rather than by the core service. They are not in the service registry, so they do not appear in the touchfiles trace dump -- if you are trying to account for a file in the directory and the dump does not list it, look here.

Touch file Read by Effect when the file is present
tf_rdrand.enable Service startup scripts Records that the CPU provides the RDRAND instruction. The FIPS crypto library and its OpenSSL runtime are selected only when this and tf_fips.enable are both present, because the FIPS build requires the CPU capability. Written automatically; see FIPS Mode.
tf_multipath_autoconf.enable — Written by the installer on a new system. Not read anywhere in this release.
tf_fscheck.disabled qs-fscheck Processes holding an open file handle to a pool are logged rather than killed, which makes a clean pool export less likely to succeed.
tf_apc_ups_monitoring.enable qs-util APC UPS monitoring is enabled. Created and removed by qs-util apcupsenable and qs-util apcupsdisable -- use those rather than creating it by hand.
tf_chksum_tiering.enable Backup and tiering policy engine Adds an explicit checksum pass to the rclone copy used by an outbound tiering policy that removes the tiered source. rclone already checksums by default, so this is an additional verification.
tf_cloud_init_support.enabled qs-upgrade Keeps cloud-init enabled. An upgrade otherwise disables cloud-init.
tf_pcs_unbind_localhost.enable qs-crm Guards the pcsd bind address so that it is not rebound to 127.0.0.1. Created by qs-crm itself when the bind is removed.
qs_logs.no_upload qs-sendlogs Permanently disables uploading log bundles to OSNEXUS, for secure-site installations. Log reports are still collected locally -- see Send System Log Report.
qs_dkms_build_drivers.enable, qs_dkms_skip_download.enable, qs_dkms_debug.enable qs-dkms-install Build drivers locally, skip the driver download, and enable debug output during a DKMS driver install.
tf_fsmon_verbose.enable, qs_anomaly_fastcalibration.enable Filesystem monitor daemon Verbose logging, and an accelerated clock for anomaly-detection auto-calibration so a multi-day calibration completes in minutes. The daemon keeps its own small registry, separate from the service's.
fc_initiatormode_<wwpn>.enabled Fabric manager Marks one Fibre Channel port as being in initiator rather than target mode. One file per port, named for the port WWPN with the colons removed. Managed by the service -- see Fibre Channel Target Port Management.

Related pages


Verified against QuantaStor 6.9.0.