No description
Find a file
Andrew Vagin a1457a7b73 sysctl: restore sysctls for correct namespaces
When we don't use userns, __userns_sysctl_op is called
in context of the current process. A mount namespaces is restored
the last one, so when we restore namespaces, we see /proc from the
host pid namespace. In this case we can't use virtual pid to access
/proc/pid.

Let's open /proc/self/ns and use this descriptor to switch namespaces.

Cc: Tycho Andersen <tycho.andersen@canonical.com>
Fixes: f79f4546cf ("sysctl: move sysctl calls to usernsd")
Signed-off-by: Andrew Vagin <avagin@openvz.org>
Acked-by: Tycho Andersen <tycho.andersen@canonical.com>
Signed-off-by: Pavel Emelyanov <xemul@parallels.com>
2015-10-09 18:25:35 +03:00
arch ppc64: handle gcc memcpy optimisation 2015-10-07 14:51:23 +03:00
contrib Add OverlayFS support to docker_cr.sh 2015-08-18 18:14:32 +03:00
Documentation Add pre-dump and pre-restore action scripts 2015-10-09 18:23:41 +03:00
include Add pre-dump and pre-restore action scripts 2015-10-09 18:23:41 +03:00
lib Use strlcpy 2015-10-07 14:57:28 +03:00
pie pie: Give VDSO symbol table local scope 2015-10-05 13:21:16 +03:00
protobuf Introduce feature check via RPC 2015-10-09 18:25:00 +03:00
pycriu pycriu: Make build reproducible 2015-10-08 13:27:32 +03:00
scripts travis: add libcap-dev for arm 2015-07-24 18:57:35 +03:00
test zdtm: don't exclude ipc and uts namespaces in case of userns 2015-10-07 15:16:50 +03:00
.gitignore gitignore: ignore pie/piegen/piegen 2015-08-03 17:06:42 +03:00
.mailmap repo: Add mailmap file 2012-03-25 23:31:20 +04:00
.travis.yml travis: add libcap-dev 2015-07-23 15:12:50 +03:00
action-scripts.c Add pre-dump and pre-restore action scripts 2015-10-09 18:23:41 +03:00
aio.c aio: Fix vma->start printing format on arm 2014-12-30 15:38:25 +03:00
bfd.c Use run-time page size where it matters 2015-04-22 15:39:05 +03:00
cgroup.c cgroup: move tasks into cgroup via usernsd 2015-10-05 13:18:56 +03:00
COPYING Add LGPL licence for library directory 2013-04-01 12:29:06 +04:00
cr-check.c ns: Check ns type with type field 2015-09-21 12:15:28 +03:00
cr-dedup.c page-read: Explicitly mark ENOENT with return code 2015-03-13 14:42:11 +03:00
cr-dump.c Add pre-dump and pre-restore action scripts 2015-10-09 18:23:41 +03:00
cr-errno.c cr-errno: initial commit 2014-12-19 18:58:46 +03:00
cr-exec.c ptrace: split task_seize into seize_catch_task and seize_wait_task 2015-08-07 13:47:11 +03:00
cr-restore.c Add pre-dump and pre-restore action scripts 2015-10-09 18:23:41 +03:00
cr-service.c Introduce feature check via RPC 2015-10-09 18:25:00 +03:00
cr-show.c show: read a second magic when it's required 2015-04-21 16:15:44 +03:00
CREDITS Add the CREDITS file 2012-07-30 13:52:37 +04:00
crit crit: Introduce 'info' action 2015-09-21 11:51:39 +03:00
crtools crtools: rename binary to criu 2013-04-30 20:17:55 +04:00
crtools.c Remove multiple command validation as cpuinfo requires it 2015-09-21 11:50:05 +03:00
Dockerfile Revert "travis: install libseccomp-dev" 2015-07-14 18:28:05 +03:00
eventfd.c img: Rename fdset -> imgset 2014-09-30 21:48:10 +04:00
eventpoll.c img: Remove O_OPT and COLLECT_OPTIONAL 2015-03-13 14:42:01 +03:00
fifo.c img: Introduce the struct cr_img 2014-09-30 21:48:13 +04:00
file-ids.c kcmp: Stop showing ids tree 2015-08-18 18:17:31 +03:00
file-lock.c lock: parse the lock field in fdinfo if it's avaliable (v2) 2015-04-27 14:53:24 +03:00
files-ext.c img: Introduce the struct cr_img 2014-09-30 21:48:13 +04:00
files-reg.c check_path_remap(): fix error checks 2015-10-07 14:58:03 +03:00
files.c file: reserve one byte in a string buffer for the null byte 2015-09-01 12:25:39 +03:00
fsnotify.c fsnotify: print an error if a file can't be opened 2015-10-07 14:50:08 +03:00
image-desc.c net: dump ipv6 routes 2015-10-05 13:11:31 +03:00
image.c img: Remove empty lazy images after dump 2015-05-30 00:31:52 +03:00
ipc_ns.c sysctl: move sysctl calls to usernsd 2015-10-05 13:16:14 +03:00
irmap.c irmap: don't leak irmap objects in --irmap-scan-path 2015-09-28 22:02:51 +03:00
kcmp-ids.c kcmp: Stop showing ids tree 2015-08-18 18:17:31 +03:00
kerndat.c sysctl: move sysctl calls to usernsd 2015-10-05 13:16:14 +03:00
libnetlink.c netlink: increase the receive buffer size 2015-09-04 18:26:51 +03:00
log.c Need bigger log buffer to avoid message truncation 2015-07-13 15:19:14 +03:00
lsm.c don't assume the kernel has CONFIG_SECCOMP 2015-07-13 14:50:35 +03:00
Makefile piegen: Allow to compile piegen tool in cross environment 2015-10-05 13:09:33 +03:00
Makefile.config build: get rid of vestigial Makefile.config test 2015-07-15 17:34:14 +03:00
Makefile.crtools vdso: merge per arch vdso.c file in a common one 2015-09-10 14:07:20 +03:00
Makefile.inc make: Allow to install in custom dirs 2015-10-05 13:24:23 +03:00
mem.c Pass task_size to vma_area_is_private() 2015-08-03 17:14:18 +03:00
mount.c mnt: Don't treat ns roots as special when restoring 2015-10-08 13:18:47 +03:00
namespaces.c mnt: Read mount images early 2015-09-28 22:00:36 +03:00
net.c Use strlcpy 2015-10-07 14:57:28 +03:00
netfilter.c iptables: use cr_system instead of system 2013-10-02 20:09:37 +04:00
page-pipe.c log: Use pr_quelled helper 2014-09-03 20:56:58 +04:00
page-read.c img: Introduce empty images 2015-03-13 14:42:54 +03:00
page-xfer.c page-server: wait when a socket will be closed only if it isn't external 2015-09-28 22:02:18 +03:00
pagemap-cache.c Replace remaining hard-coded TASK_SIZE use 2015-08-03 17:14:19 +03:00
parasite-syscall.c Replace remaining hard-coded TASK_SIZE use 2015-08-03 17:14:19 +03:00
pipes.c pipe: add ability to restore both ends of inhereted pipes 2015-07-15 17:35:59 +03:00
plugin.c plugin: Rework plugins API, v2 2014-09-03 20:48:36 +04:00
proc_parse.c parse_pid_stat(): minor optimization 2015-10-07 14:58:14 +03:00
protobuf-desc.c criu: add constants about user namespaces 2014-11-07 17:00:32 +04:00
protobuf.c img: Don't create empty images 2015-03-16 15:58:32 +03:00
pstree.c ns: Introduce ns type 2015-09-21 12:14:07 +03:00
ptrace.c ptrace: don't stop a process if it was not in the stopped state (v2) 2015-10-05 13:12:48 +03:00
rbtree.c code: Fix spaced indentation where found 2012-08-11 21:36:03 +04:00
README.md Updated README 2015-05-19 22:38:06 +03:00
rst-malloc.c Use run-time page_size() for mremap 2015-07-28 13:38:30 +03:00
sd-daemon.c systemd socket activation support 2013-12-12 09:58:50 +04:00
sd-daemon.h systemd socket activation support 2013-12-12 09:58:50 +04:00
security.c security: add cr_fchown 2015-02-10 16:54:31 +03:00
seize.c seize: Add missing newline 2015-09-24 13:11:18 +03:00
shmem.c page-read: Explicitly mark ENOENT with return code 2015-03-13 14:42:11 +03:00
sigframe.c sigframe: cast the pointer to the field ucontext::uc_sigmask to k_rtsigset_t 2014-04-08 15:36:09 +04:00
signalfd.c img: Remove O_OPT and COLLECT_OPTIONAL 2015-03-13 14:42:01 +03:00
sk-inet.c inet: Check for supported protocol earlier 2015-09-28 22:01:13 +03:00
sk-netlink.c img: Remove O_OPT and COLLECT_OPTIONAL 2015-03-13 14:42:01 +03:00
sk-packet.c img: Remove O_OPT and COLLECT_OPTIONAL 2015-03-13 14:42:01 +03:00
sk-queue.c img: Introduce the struct cr_img 2014-09-30 21:48:13 +04:00
sk-tcp.c tcp: disable the repair mode only for sockets of a current process (v3) 2015-07-15 17:35:21 +03:00
sk-unix.c sk-unix: Don't affect cwd for relative named sockets 2015-10-08 13:18:10 +03:00
sockets.c sk: Print socket protocol when searching 2015-09-25 18:31:22 +03:00
stats.c img: Introduce the struct cr_img 2014-09-30 21:48:13 +04:00
string.c string: Add strlcat helper 2013-11-29 15:36:07 +04:00
sysctl.c sysctl: restore sysctls for correct namespaces 2015-10-09 18:25:35 +03:00
sysfs_parse.c Ignore mnt_id value for AUFS file descriptors. 2015-02-09 14:07:40 +03:00
timerfd.c rst: Fix timerfd rst memory management 2015-07-14 13:59:39 +03:00
tty.c usernsd: also pass pid of process that made the req 2015-09-21 12:01:01 +03:00
tun.c tunfile_open(): don't leak fd on error path 2015-05-08 15:32:17 +03:00
util.c util: don't chop off last element in buffer 2015-10-07 15:53:42 +03:00
uts_ns.c sysctl: move sysctl calls to usernsd 2015-10-05 13:16:14 +03:00
vdso.c vdso: merge per arch vdso.c file in a common one 2015-09-10 14:07:20 +03:00

CRIU (Checkpoint and Restore in Userspace)

An utility to checkpoint/restore tasks. Using this tool, you can freeze a running application (or part of it) and checkpoint it to a hard drive as a collection of files. You can then use the files to restore and run the application from the point it was frozen at. The distinctive feature of the CRIU project is that it is mainly implemented in user space.

The project home is at http://criu.org.

Pages worth starting with are:

How to contribute