No description
Find a file
Andrey Vagin fa266bb0cb userns: restore per-namespace mappings of user and group IDs (v4)
In this patch we fill /proc/PID/uid_map and /proc/PID/gid_map for the
root task.

v2: initialize groups in a new namespace.
Acked-by: Serge E. Hallyn <serge.hallyn@ubuntu.com>

v3: add a helper to initialize creds in a new userns

v4: initialize userns creds in prepare_namespaces()
Signed-off-by: Andrey Vagin <avagin@openvz.org>
Signed-off-by: Pavel Emelyanov <xemul@parallels.com>
2014-11-07 17:16:40 +04:00
arch dump: get tasks ids from parasite 2014-11-07 17:14:32 +04:00
contrib Add a convenience shell script for Docker container C/R 2014-09-09 16:08:22 +04:00
Documentation cpuinfo: Add "cpuinfo [dump|check]" commands, v2 2014-10-03 13:26:58 +04:00
include dump: dump user namespaces (v2) 2014-11-07 17:16:16 +04:00
lib restore: Introduce the --restore-sibling option 2014-09-10 18:30:30 +04:00
pie dump: get tasks ids from parasite 2014-11-07 17:14:32 +04:00
protobuf userns: define protobuf messages for uid and gid maps 2014-11-07 17:00:25 +04:00
scripts travis: add compilation of tests 2014-10-14 14:22:01 +04:00
test jenkins: check page-server (v2) 2014-11-06 15:25:07 +04:00
.gitignore lib: Generate pkgconfig file 2014-08-04 13:57:18 +04:00
.mailmap repo: Add mailmap file 2012-03-25 23:31:20 +04:00
.travis.yml criu: add .travis.yml (v3) 2014-09-30 21:51:16 +04:00
action-scripts.c scripts: Add ACT_MAX limit and make @action_names being const 2014-10-27 21:30:37 +04:00
bfd.c bfd: Don't flush read-only images 2014-11-05 15:38:17 +04:00
cgroup.c cgroup: don't use fread in read_cgroup_prop() 2014-11-05 15:45:50 +04:00
COPYING Add LGPL licence for library directory 2013-04-01 12:29:06 +04:00
cr-check.c prctl: check -- Try new interface as well 2014-10-27 21:25:36 +04:00
cr-dedup.c img: Introduce the struct cr_img 2014-09-30 21:48:13 +04:00
cr-dump.c dump: dump user namespaces (v2) 2014-11-07 17:16:16 +04:00
cr-exec.c dump: remove useless arguments from seize_task() 2014-11-07 17:14:54 +04:00
cr-restore.c userns: restore per-namespace mappings of user and group IDs (v4) 2014-11-07 17:16:40 +04:00
cr-service.c cpuinfo: rpc -- Add CPUINFO_DUMP/CPUINFO_CHECK commands, v2 2014-10-03 13:27:00 +04:00
cr-show.c criu: add constants about user namespaces 2014-11-07 17:00:32 +04:00
CREDITS Add the CREDITS file 2012-07-30 13:52:37 +04:00
crtools crtools: rename binary to criu 2013-04-30 20:17:55 +04:00
crtools.c dump: pre-load kernel modules 2014-10-14 14:21:05 +04:00
eventfd.c img: Rename fdset -> imgset 2014-09-30 21:48:10 +04:00
eventpoll.c img: Rename fdset -> imgset 2014-09-30 21:48:10 +04:00
fifo.c img: Introduce the struct cr_img 2014-09-30 21:48:13 +04:00
file-ids.c files-ids: generate id-s accoding with mnt_id, st->st_dev and st->st_ino 2014-04-21 22:39:28 +04:00
file-lock.c img: Introduce the struct cr_img 2014-09-30 21:48:13 +04:00
files-ext.c img: Introduce the struct cr_img 2014-09-30 21:48:13 +04:00
files-reg.c userns: save uid-s from a target userns (v2) 2014-11-07 17:15:45 +04:00
files.c restore: don't leak a transport socket 2014-11-05 15:45:33 +04:00
fsnotify.c img: Rename fdset -> imgset 2014-09-30 21:48:10 +04:00
image-desc.c criu: add constants about user namespaces 2014-11-07 17:00:32 +04:00
image.c bfd: Don't flush read-only images 2014-11-05 15:38:17 +04:00
ipc_ns.c ipc_ns: don't leak memory 2014-11-05 15:46:46 +04:00
irmap.c irmap: Get root mntfd before releasing tasks on predump 2014-10-01 09:37:04 +04:00
kcmp-ids.c kcmp: Fix ret code comparison 2014-04-22 12:51:15 +04:00
kerndat.c kerndat: Transform kerndat_get_devpts_stat into general form 2014-10-30 15:10:31 +04:00
libnetlink.c netlink: Lower netlink error report log level 2013-07-04 15:49:02 +04:00
log.c restore: open the pidfile with O_EXCL 2014-09-03 20:58:24 +04:00
Makefile test: clean the "test" directory from test/Makefile 2014-09-02 16:10:55 +04:00
Makefile.config crtools: check for setproctitle_init 2014-09-02 16:14:39 +04:00
Makefile.crtools bfd: File-descriptors based buffered read 2014-09-23 20:48:38 +04:00
Makefile.inc install: install criu-service logrotate config 2014-02-18 12:39:50 +04:00
mem.c rst: Rework the rst_info referencing 2014-10-01 13:34:38 +04:00
mount.c mount: bind-mount root into itself if processes are restored in userns 2014-11-07 17:00:13 +04:00
namespaces.c userns: restore per-namespace mappings of user and group IDs (v4) 2014-11-07 17:16:40 +04:00
net.c net: Use ns walking helper 2014-10-14 18:01:38 +04:00
netfilter.c iptables: use cr_system instead of system 2013-10-02 20:09:37 +04:00
page-pipe.c log: Use pr_quelled helper 2014-09-03 20:56:58 +04:00
page-read.c img: Introduce the struct cr_img 2014-09-30 21:48:13 +04:00
page-xfer.c page-server: close server socket only in the parent task 2014-11-05 16:33:38 +04:00
pagemap-cache.c pagemap-cache: Use page.h helpers 2014-02-21 16:29:41 +04:00
parasite-syscall.c dump: get tasks ids from parasite 2014-11-07 17:14:32 +04:00
pipes.c img: Introduce the struct cr_img 2014-09-30 21:48:13 +04:00
plugin.c plugin: Rework plugins API, v2 2014-09-03 20:48:36 +04:00
proc_parse.c proc: delete parse_pid_stat_small() (v2) 2014-11-07 17:15:37 +04:00
protobuf-desc.c criu: add constants about user namespaces 2014-11-07 17:00:32 +04:00
protobuf.c img: Prepare to use bfd engine 2014-09-30 21:48:53 +04:00
pstree.c namespaces: take into account USERNS id 2014-10-30 16:00:33 +04:00
ptrace.c dump: move the may_dump() check in seize_task() 2014-11-07 17:15:29 +04:00
rbtree.c code: Fix spaced indentation where found 2012-08-11 21:36:03 +04:00
README Update README file so that it looks more informative on github front page 2014-01-24 20:42:08 +04:00
rst-malloc.c whitespace-at-eol cleanup 2013-12-12 10:00:45 +04:00
sd-daemon.c systemd socket activation support 2013-12-12 09:58:50 +04:00
sd-daemon.h systemd socket activation support 2013-12-12 09:58:50 +04:00
security.c dump: get tasks ids from parasite 2014-11-07 17:14:32 +04:00
shmem.c shmem: don't unmap a memrory region in restore_shmem_content() 2014-11-05 15:45:03 +04:00
sigframe.c sigframe: cast the pointer to the field ucontext::uc_sigmask to k_rtsigset_t 2014-04-08 15:36:09 +04:00
signalfd.c img: Rename fdset -> imgset 2014-09-30 21:48:10 +04:00
sk-inet.c sk-inet: don't leak sockets 2014-11-05 15:46:39 +04:00
sk-netlink.c img: Rename fdset -> imgset 2014-09-30 21:48:10 +04:00
sk-packet.c img: Rename fdset -> imgset 2014-09-30 21:48:10 +04:00
sk-queue.c img: Introduce the struct cr_img 2014-09-30 21:48:13 +04:00
sk-tcp.c img: Introduce the struct cr_img 2014-09-30 21:48:13 +04:00
sk-unix.c userns: save uid-s from a target userns (v2) 2014-11-07 17:15:45 +04:00
sockets.c dump: pre-load kernel modules 2014-10-14 14:21:05 +04:00
stats.c img: Introduce the struct cr_img 2014-09-30 21:48:13 +04:00
string.c string: Add strlcat helper 2013-11-29 15:36:07 +04:00
sysctl.c add int(CTL_32) 2014-10-08 19:23:24 +04:00
sysfs_parse.c sysfs: fix use_after_free issue 2014-11-05 15:44:34 +04:00
timerfd.c img: Rename fdset -> imgset 2014-09-30 21:48:10 +04:00
tty.c tty: Fix compilation warrning 2014-10-30 16:24:15 +04:00
tun.c tun: rename FD_TYPES__TUN to FD_TYPES__TUNF 2014-10-27 21:52:40 +04:00
util.c cg: use one path style throughout cg restore code 2014-10-07 12:56:52 +04:00
uts_ns.c ns: Factor out namespace switching call 2014-09-30 21:54:11 +04:00

criu
====

An utility to checkpoint/restore tasks. Using this tool, you can
freeze a running application (or part of it) and checkpoint it to
a hard drive as a collection of files. You can then use the files
to restore and run the application from the point it was frozen
at. The distinctive feature of the CRIU project is that it is
mainly implemented in user space.

The project home is at http://criu.org

Pages worth starting with are
* Kernel configuration, compilation, etc: http://criu.org/Installation
* A simple example of usage: http://criu.org/Simple_loop
* More sophisticated example with graphical app: http://criu.org/VNC