PE: Don't start resources until we can verify they're not still running
If we are shooting a failed node (ie. one that we have seen during the
cluster's current consciousness) but there are resources that we can't
verify are not running on that node, then we should wait until the
fencing operation is complete before starting them anywhere else.
This should allow correct recovery of failed DCs if we ever stop
syncing the status section.
Mercurial revision: 24e6e7fcb97c92362ae01ab6092e6b5844f55dd7