No description
Find a file
Valeriy Vdovin 691b4a4e7e zdtm: Implemented get_current_dir_name wrapper that checks for 'x' permissions
Any filesystem syscall, that needs to navigate to inode by it's
absolute path performs successive lookup operations for each part of the
path. Lookup operation includes access rights check.
Usually but not always zdtm tests processes fall under 'other' access
category. Also, usually directories don't have 'x' bit set for other.
In case when bit 'x' is not set and user-ID and group-ID of a process
relate it to 'other', test's will not succeed in performing these
syscalls which are most of filesystem api, that has const char *path
as part of it arguments (open, openat, mkdir, bind, etc).
The observable behavior of that is that zdtm tests fail at file
creation ops on one system and pass on the other. The above is not
immediately clear to the developer by just looking at failed test's logs.
Investigation of that is also not quick for a developer due to the
complex structure of zdtm runtime where nested clones with
NAMESPACE flags take place alongside with bind-mounts.

As an additional note: 'get_current_dir_name' is documented as returning
EACCESS in case when some part of the path lacks read/list permissions.
But in fact it's not always so. Practice shows, that test processes can
get false success on this operation only to fail on later call to
something like mkdir/mknod/bind with a given path in arguments.

'get_cwd_check_perm' is a wrapper around 'get_current_dir_name'. It also
checks for permissions on the given filepath and logs the error. This
directs the developer towards the right investigation path or even
eliminates the need for investigation completely.

Signed-off-by: Valeriy Vdovin <valeriy.vdovin@virtuozzo.com>
2020-03-27 19:36:20 +03:00
compel compel: Remove compel.h 2020-03-27 19:36:20 +03:00
contrib Replace libprotobuf-c0-dev with libprotobuf-c-dev 2019-09-07 15:59:54 +03:00
coredump py: Manual fixlets of code formatting 2020-02-04 12:37:37 -08:00
crit crit: enable python2 or python3 based crit 2018-07-09 18:25:16 +03:00
criu mem/vma: set VMA_FILE_{PRIVATE,SHARED} if a vma file is borrowed 2020-03-27 19:36:20 +03:00
Documentation compel: Remove compel.h 2020-03-27 19:36:20 +03:00
images files: allow dumping opened symlinks 2020-03-27 19:36:20 +03:00
include/common compel: Remove compel.h 2020-03-27 19:36:20 +03:00
lib memfd: add seals support 2020-03-27 19:36:20 +03:00
scripts make: use cflags/ldflags for config.h detection mechanism 2020-03-27 19:36:20 +03:00
soccr style: Enforce kernel style -Wstrict-prototypes 2020-02-04 12:39:42 -08:00
test zdtm: Implemented get_current_dir_name wrapper that checks for 'x' permissions 2020-03-27 19:36:20 +03:00
.gitignore crit: enable python2 or python3 based crit 2018-07-09 18:25:16 +03:00
.mailmap mailmap: update my email 2020-03-27 19:36:20 +03:00
.travis.yml travis: add ppc64-cross test on amd64 2020-03-27 19:36:20 +03:00
COPYING COPYING: fix a typo in a preamble 2016-08-11 16:18:43 +03:00
CREDITS Add the CREDITS file 2012-07-30 13:52:37 +04:00
INSTALL.md Makefile.install: rm unused vars/target 2017-02-06 13:48:49 +03:00
MAINTAINERS MAINTAINERS: Add Dima and Adrian to maintainers 2020-03-03 11:48:47 -08:00
MAINTAINERS_GUIDE.md Maintainers: Suggest the maintainers codex (#932) 2020-02-21 18:48:41 +03:00
Makefile style: Enforce kernel style -Wstrict-prototypes 2020-02-04 12:39:42 -08:00
Makefile.compel compel: Make sure the hostprog is built early 2018-10-30 19:27:56 +03:00
Makefile.config memfd: add file support 2020-03-27 19:36:20 +03:00
Makefile.install Make the Makefile variables externally configurable. 2017-08-15 15:24:11 +03:00
Makefile.versions criu: Version 3.13 2019-09-11 11:29:31 +03:00
README.md readme: github pull-requests is the preferred way to contribute 2020-02-04 12:39:05 -08:00

master development Codacy Badge

CRIU -- A project to implement checkpoint/restore functionality for Linux

CRIU (stands for Checkpoint and Restore in Userspace) is a utility to checkpoint/restore Linux tasks.

Using this tool, you can freeze a running application (or part of it) and checkpoint it to a hard drive as a collection of files. You can then use the files to restore and run the application from the point it was frozen at. The distinctive feature of the CRIU project is that it is mainly implemented in user space. There are some more projects doing C/R for Linux, and so far CRIU appears to be the most feature-rich and up-to-date with the kernel.

The project started as the way to do live migration for OpenVZ Linux containers, but later grew to more sophisticated and flexible tool. It is currently used by (integrated into) OpenVZ, LXC/LXD, Docker, and other software, project gets tremendous help from the community, and its packages are included into many Linux distributions.

The project home is at http://criu.org. This wiki contains all the knowledge base for CRIU we have. Pages worth starting with are:

Checkpoint and restore of simple loop process

Advanced features

As main usage for CRIU is live migration, there's a library for it called P.Haul. Also the project exposes two cool core features as standalone libraries. These are libcompel for parasite code injection and libsoccr for TCP connections checkpoint-restore.

Live migration

True live migration using CRIU is possible, but doing all the steps by hands might be complicated. The phaul sub-project provides a Go library that encapsulates most of the complexity. This library and the Go bindings for CRIU are stored in the go-criu repository.

Parasite code injection

In order to get state of the running process CRIU needs to make this process execute some code, that would fetch the required information. To make this happen without killing the application itself, CRIU uses the parasite code injection technique, which is also available as a standalone library called libcompel.

TCP sockets checkpoint-restore

One of the CRIU features is the ability to save and restore state of a TCP socket without breaking the connection. This functionality is considered to be useful by itself, and we have it available as the libsoccr library.

How to contribute

CRIU project is (almost) the never-ending story, because we have to always keep up with the Linux kernel supporting checkpoint and restore for all the features it provides. Thus we're looking for contributors of all kinds -- feedback, bug reports, testing, coding, writing, etc. Here are some useful hints to get involved.

  • We have both -- very simple and more sophisticated coding tasks;
  • CRIU does need extensive testing;
  • Documentation is always hard, we have some information that is to be extracted from people's heads into wiki pages as well as some texts that all need to be converted into useful articles;
  • Feedback is expected on the github issues page and on the mailing list;
  • We accept github pull requests and this is the preferred way to contribute to CRIU. If you prefer to send patches by email, you are welcome to send them to the devel list;
  • Spread the word about CRIU in social networks;
  • If you're giving a talk about CRIU -- let us know, we'll mention it on the wiki main page;

Licence

The project is licensed under GPLv2 (though files sitting in the lib/ directory are LGPLv2.1).