No description
Find a file
Pavel Tikhomirov 7e9a9dc342 cr-dump: fix cr_imgset leak in dump_one_task
coverity CID 389194:

1238static int dump_one_task(struct pstree_item *item, InventoryEntry *parent_ie)
1239{
...
1245        struct cr_imgset *cr_imgset = NULL;
...
    11. alloc_fn: Storage is returned from allocation function cr_task_imgset_open. [show details]
    12. var_assign: Assigning: cr_imgset = storage returned from cr_task_imgset_open(vpid(item), 577).
1355        cr_imgset = cr_task_imgset_open(vpid(item), O_DUMP);
    13. Condition !cr_imgset, taking false branch.
1356        if (!cr_imgset)
1357                goto err_cure;
1358
...
    25. Condition opts.lazy_pages, taking false branch.
1427        if (opts.lazy_pages)
1428                ret = compel_cure_remote(parasite_ctl);
1429        else
1430                ret = compel_cure(parasite_ctl);
    26. Condition ret, taking true branch.
1431        if (ret) {
1432                pr_err("Can't cure (pid: %d) from parasite\n", pid);
    27. Jumping to label err.
1433                goto err;
1434        }
...
1448        close_cr_imgset(&cr_imgset);
1449        exit_code = 0;
1450err:
1451        close_pid_proc();
1452        free_mappings(&vmas);
1453        xfree(dfds);
    CID 389194 (#1 of 1): Resource leak (RESOURCE_LEAK)28. leaked_storage: Variable cr_imgset going out of scope leaks the storage it points to.
1454        return exit_code;
1455
1456err_cure:
1457        close_cr_imgset(&cr_imgset);
1458err_cure_imgset:
1459        ret = compel_cure(parasite_ctl);
1460        if (ret)
1461                pr_err("Can't cure (pid: %d) from parasite\n", pid);
1462        goto err;
1463}

On compel_cure() error path we do not do close_cr_imgset() thich leads
to leaked cr_imgset, let's move corresponding close_cr_imgset below err
label. Also now we can merge remove close_cr_imgset() in err_cure label
as it goes to err label later anyway. Separate err_cure_imgset label is
not needed as close_cr_imgset() is ready for cr_imgset == NULL.

v2: remove excess close_cr_imgset() in label err_cure (@adrianreber)

Signed-off-by: Pavel Tikhomirov <ptikhomirov@virtuozzo.com>
2022-04-28 17:53:52 -07:00
.circleci ci: add Circle CI definition 2021-09-03 10:31:00 -07:00
.github ci: set continue-on-error for cross-compile 2022-04-28 17:53:52 -07:00
compel compel: set mxcsr during error injection to zero 2022-04-28 17:53:52 -07:00
contrib Switch to python 3 variants of dependencies on debian-based builds 2020-10-20 00:18:24 -07:00
coredump coredump: lint fix visually indented line 2022-04-28 17:53:52 -07:00
crit crit: enable python2 or python3 based crit 2018-07-09 18:25:16 +03:00
criu cr-dump: fix cr_imgset leak in dump_one_task 2022-04-28 17:53:52 -07:00
Documentation Fix formatting in criu documentation 2022-04-28 17:53:52 -07:00
images bpfmap: handle new field in fdinfo 2022-04-28 17:53:52 -07:00
include clang-format: do automatic comment fixups 2022-04-28 17:53:52 -07:00
lib lib: introduce feature check in libcriu 2022-04-28 17:53:52 -07:00
plugins/amdgpu criu/plugin: Implement dummy amdgpu plugin hooks 2022-04-28 17:53:52 -07:00
scripts test: disable rseq also on Archlinux 2022-04-28 17:53:52 -07:00
soccr clang-format: do automatic comment fixups 2022-04-28 17:53:52 -07:00
test zdtm: fix missplacement of err=True 2022-04-28 17:53:52 -07:00
.cirrus.yml ci: install libbsd dependency 2022-04-28 17:53:52 -07:00
.clang-format clang-format: enable AlignTrailingComments 2022-04-28 17:53:52 -07:00
.drone.yml ci: move Fedora Rawhide based tests away from Travis 2021-09-03 10:31:00 -07:00
.gitignore gitignore: add build directory 2021-09-17 10:42:21 -07:00
.lgtm.yml ci: install libbsd dependency 2022-04-28 17:53:52 -07:00
.mailmap mailmap: update my email 2020-03-27 19:36:20 +03:00
.travis.yml ci: remove ccache setup 2021-09-03 10:31:00 -07:00
CONTRIBUTING.md contributing: remove old badges and logo 2022-04-28 17:53:52 -07:00
COPYING COPYING: fix a typo in a preamble 2016-08-11 16:18:43 +03:00
CREDITS Add the CREDITS file 2012-07-30 13:52:37 +04:00
INSTALL.md Makefile.install: rm unused vars/target 2017-02-06 13:48:49 +03:00
MAINTAINERS MAINTAINERS: Add Pavel (myself) to maintainers 2020-04-06 23:19:57 -07:00
MAINTAINERS_GUIDE.md Maintainers: Suggest the maintainers codex (#932) 2020-02-21 18:48:41 +03:00
Makefile make: Explicitly enable FPU on ARMv7 builds 2022-04-28 17:53:52 -07:00
Makefile.compel compel: Make sure the hostprog is built early 2018-10-30 19:27:56 +03:00
Makefile.config build: respect $PKG_CONFIG settings 2021-09-03 10:31:00 -07:00
Makefile.install criu/plugin: Implement dummy amdgpu plugin hooks 2022-04-28 17:53:52 -07:00
Makefile.versions criu: Version 3.16.1 2021-10-13 22:44:30 -07:00
README.md readme: add docker test badge 2022-04-28 17:53:52 -07:00

X86_64 GCC Test Docker Test Podman Test CircleCI

CRIU -- A project to implement checkpoint/restore functionality for Linux

CRIU (stands for Checkpoint and Restore in Userspace) is a utility to checkpoint/restore Linux tasks.

Using this tool, you can freeze a running application (or part of it) and checkpoint it to a hard drive as a collection of files. You can then use the files to restore and run the application from the point it was frozen at. The distinctive feature of the CRIU project is that it is mainly implemented in user space. There are some more projects doing C/R for Linux, and so far CRIU appears to be the most feature-rich and up-to-date with the kernel.

CRIU project is (almost) the never-ending story, because we have to always keep up with the Linux kernel supporting checkpoint and restore for all the features it provides. Thus we're looking for contributors of all kinds -- feedback, bug reports, testing, coding, writing, etc. Please refer to CONTRIBUTING.md if you would like to get involved.

The project started as the way to do live migration for OpenVZ Linux containers, but later grew to more sophisticated and flexible tool. It is currently used by (integrated into) OpenVZ, LXC/LXD, Docker, and other software, project gets tremendous help from the community, and its packages are included into many Linux distributions.

The project home is at http://criu.org. This wiki contains all the knowledge base for CRIU we have. Pages worth starting with are:

Checkpoint and restore of simple loop process

Advanced features

As main usage for CRIU is live migration, there's a library for it called P.Haul. Also the project exposes two cool core features as standalone libraries. These are libcompel for parasite code injection and libsoccr for TCP connections checkpoint-restore.

Live migration

True live migration using CRIU is possible, but doing all the steps by hands might be complicated. The phaul sub-project provides a Go library that encapsulates most of the complexity. This library and the Go bindings for CRIU are stored in the go-criu repository.

Parasite code injection

In order to get state of the running process CRIU needs to make this process execute some code, that would fetch the required information. To make this happen without killing the application itself, CRIU uses the parasite code injection technique, which is also available as a standalone library called libcompel.

TCP sockets checkpoint-restore

One of the CRIU features is the ability to save and restore state of a TCP socket without breaking the connection. This functionality is considered to be useful by itself, and we have it available as the libsoccr library.

Licence

The project is licensed under GPLv2 (though files sitting in the lib/ directory are LGPLv2.1).

All files in the images/ directory are licensed under the Expat license (so-called MIT). See the images/LICENSE file.