Invention Grant
- Patent Title: System call policies for containers
-
Application No.: US15417955Application Date: 2017-01-27
-
Publication No.: US10650138B2Publication Date: 2020-05-12
- Inventor: Michela D'Errico , Leon Frank Ehrenhart , Chris I. Dalton , Michael John Wray , Siani Pearson , Dennis Heinze
- Applicant: Hewlett Packard Enterprise Development LP
- Applicant Address: US TX Houston
- Assignee: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
- Current Assignee: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
- Current Assignee Address: US TX Houston
- Agency: Hewlett Packard Enterprise Patent Department
- Main IPC: G06F21/53
- IPC: G06F21/53 ; G06F16/245

Abstract:
Examples relate to system call policies for containers. In an example, a method includes receiving, by a container platform, a container for running an application. The container has a metadata record that specifies an application type of the application. The container platform receives a data structure that specifies a set of system call policies for a set of application types and queries the data structure to determine a policy of the set of system call policies to apply to the container based on the application type in the metadata record. A kernel implements the policy for the container to allow or deny permission for a system call by the application running in the container based on a comparison of the system call to the policy.
Public/Granted literature
- US20180218148A1 SYSTEM CALL POLICIES FOR CONTAINERS Public/Granted day:2018-08-02
Information query