No description
Find a file
Radostin Stoyanov e2c84bfba7 mem/pagemap: Decode LZ4 pages before PIE
The PIE restorer cannot link against LZ4. Decode mappings containing
LZ4 payloads through CRIU's premap path, while retaining delayed PIE
restore for raw and zero ranges when a worker pool cannot help.

Classify image ranges as LZ4, raw, or zero. Decode LZ4 blocks while CRIU
still runs in its normal address space, read aligned raw ranges directly
into their final VMAs, and clear zero ranges in place. Omit compression
metadata for entries containing only raw blocks so they retain the
ordinary restore path.

Share one encoded-read context across each incremental parent chain and
reuse its worker pool for bounded batches, COW reads, streamed images,
and page-server chunks. Use the same jobs to fill zero runs of at least
1 MiB when two blocks and two CPUs are available. Zero-only ranges that
cannot benefit retain the PIE path, while zero blocks in an existing
encoded batch remain inline without effective parallel capacity. Hold
input buffers only while encoded work is active, and join every worker
before child restore or the PIE handoff.

Account calling restore threads and workers against a shared CPU budget.
A requested width of zero selects automatic concurrency, one keeps LZ4
decoding serial and disables zero-fill workers, and larger values cap
aggregate worker concurrency. Bound the active width by CPU affinity and
useful work. Release encoded-work leases before ordinary reads so idle
contexts cannot block ready workers.

Local payload-heavy restores otherwise alternate between reading an
encoded batch and decoding it. This leaves either storage or worker CPUs
idle. When a second encoded-input lease is immediately available,
dispatch the current batch to the pool and use the already-accounted
calling thread to read the next adjacent payload. Keep synchronous reads
for serial restore, streams, direct I/O, small batches, and contended
leases.

Select direct AIO from the ranges actually delayed for PIE. Batch
inherited COW comparisons and streamed payload reads, and align
page-server chunks to compression regions. Validate metadata and offset
arithmetic before allocation or I/O, roll back partially enqueued work,
and propagate worker, I/O, and deferred deduplication failures before
remapping.

On a 256 MiB pseudorandom workload with the worker limit set to eight
and three measured runs, median restore time was 114.5 ms uncompressed,
113.4 ms with LZ4 per page, and 116.5 ms with 64 KiB regions. The
previous compressed restore path took about 227 ms in either mode.

With automatic concurrency and 256 KiB regions, parallel zero filling
reduced median restore time over five runs from 103.1 ms to 31.7 ms for
zero-filled memory and from 89.3 ms to 60.0 ms for mixed memory.

On 512 MiB TEXT and ELF workloads with automatic concurrency and 256 KiB
regions, five-run median restore time fell from 117.0 ms to 110.7 ms and
from 115.4 ms to 109.5 ms, respectively.

Assisted-by: Codex:GPT-5
Assisted-by: Claude:claude-fable-5
Signed-off-by: Radostin Stoyanov <rstoyanov@fedoraproject.org>
2026-07-14 10:17:01 +01:00
.circleci ci: silence CircleCI warning about deprecated image 2024-09-11 16:02:11 -07:00
.github make: Add optional LZ4 support 2026-07-14 10:17:01 +01:00
compel compel/arm64: rename gcs_context to avoid conflicts with system headers 2026-07-08 20:27:12 -07:00
contrib make: Add optional LZ4 support 2026-07-14 10:17:01 +01:00
coredump coredump: fix file handle leak in _gen_mem_chunk 2026-07-07 15:02:33 +01:00
crit crit: fix file handle leaks in inf/outf/dinf helpers 2026-07-07 15:02:33 +01:00
criu mem/pagemap: Decode LZ4 pages before PIE 2026-07-14 10:17:01 +01:00
Documentation criu: add --image-io-mode option to gate O_DIRECT reads of the pages image 2026-07-08 09:52:16 +01:00
images images: Add compressed page metadata 2026-07-14 10:17:01 +01:00
include compel: fix heap alignment for structs with xsave state 2026-03-25 04:31:18 +01:00
lib images: Add compressed page metadata 2026-07-14 10:17:01 +01:00
plugins plugins/amdgpu: Use original fd to export dmabuf 2026-06-20 23:38:16 -07:00
scripts scripts: add magic-gen.py to ruff linting 2026-07-09 10:32:19 +01:00
soccr soccr/test: remove redundant p1.stdout.read() 2026-07-08 09:51:25 +01:00
test apparmor: fix write check, and implement runtime fallback 2026-07-08 20:27:12 -07:00
.clang-format clang-format: disable column limit constraint 2023-10-22 13:29:25 -07:00
.codespellrc codespell: skip amdgpu kernel headers 2025-11-14 18:31:37 +00:00
.gitignore Keep images/google/protobuf directory 2025-11-02 07:48:22 -08:00
.lgtm.yml images: remove symlink for descriptor.proto 2025-11-02 07:48:22 -08:00
.mailmap mailmap: update my email 2023-04-15 21:17:21 -07:00
CLAUDE.md docs: add developer overviews for AI assistants 2025-11-02 07:48:23 -08:00
CONTRIBUTING.md contributing: document AI-assisted contribution guidelines 2026-03-19 16:44:10 +00:00
COPYING COPYING: fix a typo in a preamble 2016-08-11 16:18:43 +03:00
CREDITS Add the CREDITS file 2012-07-30 13:52:37 +04:00
docs docs: create symlink for GitHub Pages 2026-06-04 18:58:00 +00:00
flake.lock feat: specify ourselves as Nix flake source 2026-03-15 21:04:43 +00:00
flake.nix feat: remove build-time patches from Nixpkgs 2026-03-15 21:04:43 +00:00
GEMINI.md contributing: document AI-assisted contribution guidelines 2026-03-19 16:44:10 +00:00
INSTALL.md docs: mark make commands with same format as elsewhere 2025-03-21 12:40:31 -07:00
MAINTAINERS MAINTAINERS: Update maintainer roles 2026-02-22 15:23:04 -08:00
MAINTAINERS_GUIDE.md Fix some codespell warnings 2022-04-28 17:53:52 -07:00
Makefile make: Add optional LZ4 support 2026-07-14 10:17:01 +01:00
Makefile.compel Remove travis-ci leftovers 2025-11-02 07:48:23 -08:00
Makefile.config make: Add optional LZ4 support 2026-07-14 10:17:01 +01:00
Makefile.install make: don't install external dependencies 2025-11-05 15:41:34 -08:00
Makefile.versions criu: Version 4.2 (CRIUTIBILITY) 2025-11-13 08:40:46 -08:00
README.md readme: update reference to consolidated workflows 2026-03-09 10:29:57 +00:00

CI CircleCI

CRIU -- A project to implement checkpoint/restore functionality for Linux

CRIU (stands for Checkpoint and Restore in Userspace) is a utility to checkpoint/restore Linux tasks.

Using this tool, you can freeze a running application (or part of it) and checkpoint it to a hard drive as a collection of files. You can then use the files to restore and run the application from the point it was frozen at. The distinctive feature of the CRIU project is that it is mainly implemented in user space. There are some more projects doing C/R for Linux, and so far CRIU appears to be the most feature-rich and up-to-date with the kernel.

CRIU project is (almost) the never-ending story, because we have to always keep up with the Linux kernel supporting checkpoint and restore for all the features it provides. Thus we're looking for contributors of all kinds -- feedback, bug reports, testing, coding, writing, etc. Please refer to CONTRIBUTING.md if you would like to get involved.

The project started as the way to do live migration for OpenVZ Linux containers, but later grew to more sophisticated and flexible tool. It is currently used by (integrated into) OpenVZ, LXC/LXD, Docker, and other software, project gets tremendous help from the community, and its packages are included into many Linux distributions.

The project home is at http://criu.org. This wiki contains all the knowledge base for CRIU we have. Pages worth starting with are:

Checkpoint and restore of simple loop process

Advanced features

As main usage for CRIU is live migration, there's a library for it called P.Haul. Also the project exposes two cool core features as standalone libraries. These are libcompel for parasite code injection and libsoccr for TCP connections checkpoint-restore.

Live migration

True live migration using CRIU is possible, but doing all the steps by hands might be complicated. The phaul sub-project provides a Go library that encapsulates most of the complexity. This library and the Go bindings for CRIU are stored in the go-criu repository.

Parasite code injection

In order to get state of the running process CRIU needs to make this process execute some code, that would fetch the required information. To make this happen without killing the application itself, CRIU uses the parasite code injection technique, which is also available as a standalone library called libcompel.

TCP sockets checkpoint-restore

One of the CRIU features is the ability to save and restore state of a TCP socket without breaking the connection. This functionality is considered to be useful by itself, and we have it available as the libsoccr library.

Licence

The project is licensed under GPLv2 (though files sitting in the lib/ directory are LGPLv2.1).

All files in the images/ directory are licensed under the Expat license (so-called MIT). See the images/LICENSE file.