Release of CRIU 3.16, a system for saving and restoring the state of processes in Linux.

The release of the CRIU 3.16 (Checkpoint and Restore In Userspace) toolkit has been published, designed for saving and restoring processes in user space. The toolkit allows you to capture the state of a single process or a group of processes, and then resume work from that saved position, including after a system reboot or on another server without breaking existing network connections. The project's code is distributed under the GPLv2 license.

Applications of CRIU technology include enabling OS reboots without disrupting long-running processes, live migration of isolated containers, speeding up the launch of slow processes (you can start work from a state saved after initialization), performing kernel updates without restarting services, periodically saving the state of long-running computational tasks for resuming work in case of a crash, load balancing between nodes in clusters, duplicating processes to another machine (fork to a remote system), and creating snapshots of user applications during operation for analysis on another system or in case further actions in the program need to be canceled. CRIU is used in container management systems such as OpenVZ, LXC/LXD, and Docker. The necessary modifications for CRIU are included in the main Linux kernel.

In the new release:

  • The criu-ns command has been added, allowing for the restoration of a saved process snapshot with a new PID identifier and in a separate mount namespace. Running with a different PID may be required if the old PID is already in use in the system.
  • The ability to save and restore snapshots of nested apparmor profiles has been implemented.
  • Network resource locking and unlocking based on nftables has been implemented.
  • Support for restoring pre-created veth devices has been added.
  • Improved support for restoring containers into existing pods.
  • For RPC clients, the ability to define PID reuse has been added, implemented using the pidfd mechanism.
  • The license for all proto files in the images/ directory has been changed to MIT.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster