No description
Find a file
Pratyush Yadav ca971b7f8b compel: fix build on Amazon Linux 2 due to missing PTRACE_ARCH_PRCTL
Commit fc683cb01 ("compel: shstk: save CET state when CPU supports it")
started using PTRACE_ARCH_PRCTL to query shadow stack status. While
PTRACE_ARCH_PRCTL has existed in the kernel for a long time, it was only
added to glibc in version 2.27. Amazon Linux 2 (AL2) has glibc 2.26,
which does not have this definition. As a result, build on AL2 fails
with the below error:

    compel/arch/x86/src/lib/infect.c: In function ‘get_task_xsave’:
    compel/arch/x86/src/lib/infect.c:276:14: error: ‘PTRACE_ARCH_PRCTL’ undeclared (first use in this function)
    276 |   if (ptrace(PTRACE_ARCH_PRCTL, pid, (unsigned long)&features, ARCH_SHSTK_STATUS)) {
        |              ^~~~~~~~~~~~~~~~~

While the definition is present on the system via the kernel headers (in
asm/ptrace-abi.h) which can be reached by including linux/ptrace.h, the
comment in compel/include/uapi/ptrace.h says:

    We'd want to include both sys/ptrace.h and linux/ptrace.h, hoping
    that most definitions come from either one or another. Alas, on
    Alpine/musl both files declare struct ptrace_peeksiginfo_args, so
    there is no way they can be used together. Let's rely on libc one.

Since including linux/ptrace.h is not an option, define
PTRACE_ARCH_PRCTL if it doesn't already exist. An interesting point to
note is that in sys/ptrace.h, PTRACE_ARCH_PRCTL is an enum value so the
preprocessor doesn't know about it. PT_ARCH_PRCTL is the preprocessor
symbol that matches the value of PTRACE_ARCH_PRCTL. So look for
PT_ARCH_PRCTL to decide if PTRACE_ARCH_PRCTL is available or not.

Another interesting point to note is that AL2 ships with GCC 7 by
default, which does not support the -mshstk option, causing other build
failures. Luckily, it also ships GCC 10 which does have the option.
Using GCC 10 lets the build succeed.

Fixes: fc683cb01 ("compel: shstk: save CET state when CPU supports it")
Signed-off-by: Pratyush Yadav <ptyadav@amazon.de>
2024-09-11 16:02:11 -07:00
.circleci ci: silence CircleCI warning about deprecated image 2024-09-11 16:02:11 -07:00
.github ci: update actions/checkout to v4 2024-09-11 16:02:11 -07:00
compel compel: fix build on Amazon Linux 2 due to missing PTRACE_ARCH_PRCTL 2024-09-11 16:02:11 -07:00
contrib remove python-future dependency 2023-10-22 13:29:25 -07:00
coredump lib: use separate packages for pycriu and crit 2023-11-27 16:47:16 -08:00
crit make: improve check for externally managed Python 2024-09-11 16:02:11 -07:00
criu criu/plugin: Introduce new plugin hooks PAUSE_DEVICES and CHECKPOINT_DEVICES to be used during pstree collection 2024-09-11 16:02:11 -07:00
Documentation criu/plugin: Add environment variable to cap size of buffers. 2023-10-22 13:29:25 -07:00
images sk-tcp: Move TCP socket options from SkOptsEntry to TcpOptsEntry 2024-09-11 16:02:11 -07:00
include compiler: add ALIGN_DOWN macro 2024-09-11 16:02:11 -07:00
lib make: improve check for externally managed Python 2024-09-11 16:02:11 -07:00
plugins criu/plugin: Add NVIDIA CUDA plugin 2024-09-11 16:02:11 -07:00
scripts ci: upgrade to Fedora 40 Vagrant images (38 is EOL) 2024-09-11 16:02:11 -07:00
soccr soccr: Log name of socket queue that failed to restore. 2023-10-22 13:29:25 -07:00
test test/dump-crash: check code path when dump crashes 2024-09-11 16:02:11 -07:00
.cirrus.yml ci: remove CentOS Stream 8 test (EOL) 2024-09-11 16:02:11 -07:00
.clang-format clang-format: disable column limit constraint 2023-10-22 13:29:25 -07:00
.codespellrc ci: fix new codespell errors 2023-10-22 13:29:25 -07:00
.gitignore gitignore: remove historical left-over files 2024-09-11 16:02:11 -07:00
.lgtm.yml remove python-future dependency 2023-10-22 13:29:25 -07:00
.mailmap mailmap: update my email 2023-04-15 21:17:21 -07:00
.travis.yml ci: remove ccache setup 2021-09-03 10:31:00 -07:00
CONTRIBUTING.md make: replace flake8 with ruff 2024-09-11 16:02:11 -07:00
COPYING COPYING: fix a typo in a preamble 2016-08-11 16:18:43 +03:00
CREDITS Add the CREDITS file 2012-07-30 13:52:37 +04:00
INSTALL.md Makefile.install: rm unused vars/target 2017-02-06 13:48:49 +03:00
MAINTAINERS Add Alexander Mikhalitsyn to maintainers 2023-04-15 21:17:21 -07:00
MAINTAINERS_GUIDE.md Fix some codespell warnings 2022-04-28 17:53:52 -07:00
Makefile criu/plugin: Add NVIDIA CUDA plugin 2024-09-11 16:02:11 -07:00
Makefile.compel compel: Make sure the hostprog is built early 2018-10-30 19:27:56 +03:00
Makefile.config Makefile.config: fix/improve feature warnings. 2024-09-11 16:02:11 -07:00
Makefile.install criu/plugin: Add NVIDIA CUDA plugin 2024-09-11 16:02:11 -07:00
Makefile.versions criu: Version 3.19 (Bronze Peacock) 2023-11-27 16:47:16 -08:00
README.md readme: update link to FAQ page 2024-09-11 16:02:11 -07:00

X86_64 GCC Test Docker Test Podman Test CircleCI

CRIU -- A project to implement checkpoint/restore functionality for Linux

CRIU (stands for Checkpoint and Restore in Userspace) is a utility to checkpoint/restore Linux tasks.

Using this tool, you can freeze a running application (or part of it) and checkpoint it to a hard drive as a collection of files. You can then use the files to restore and run the application from the point it was frozen at. The distinctive feature of the CRIU project is that it is mainly implemented in user space. There are some more projects doing C/R for Linux, and so far CRIU appears to be the most feature-rich and up-to-date with the kernel.

CRIU project is (almost) the never-ending story, because we have to always keep up with the Linux kernel supporting checkpoint and restore for all the features it provides. Thus we're looking for contributors of all kinds -- feedback, bug reports, testing, coding, writing, etc. Please refer to CONTRIBUTING.md if you would like to get involved.

The project started as the way to do live migration for OpenVZ Linux containers, but later grew to more sophisticated and flexible tool. It is currently used by (integrated into) OpenVZ, LXC/LXD, Docker, and other software, project gets tremendous help from the community, and its packages are included into many Linux distributions.

The project home is at http://criu.org. This wiki contains all the knowledge base for CRIU we have. Pages worth starting with are:

Checkpoint and restore of simple loop process

Advanced features

As main usage for CRIU is live migration, there's a library for it called P.Haul. Also the project exposes two cool core features as standalone libraries. These are libcompel for parasite code injection and libsoccr for TCP connections checkpoint-restore.

Live migration

True live migration using CRIU is possible, but doing all the steps by hands might be complicated. The phaul sub-project provides a Go library that encapsulates most of the complexity. This library and the Go bindings for CRIU are stored in the go-criu repository.

Parasite code injection

In order to get state of the running process CRIU needs to make this process execute some code, that would fetch the required information. To make this happen without killing the application itself, CRIU uses the parasite code injection technique, which is also available as a standalone library called libcompel.

TCP sockets checkpoint-restore

One of the CRIU features is the ability to save and restore state of a TCP socket without breaking the connection. This functionality is considered to be useful by itself, and we have it available as the libsoccr library.

Licence

The project is licensed under GPLv2 (though files sitting in the lib/ directory are LGPLv2.1).

All files in the images/ directory are licensed under the Expat license (so-called MIT). See the images/LICENSE file.