IP Library Granted Patent US 8,195,798
Granted Patent B2
US 8,195,798 · App. 13/212,142 · Granted Jun 5, 2012

Application server scalability through runtime restrictions enforcement in a distributed application execution system

Assignee: Google Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,195,798
App. No.
13/212,142
Granted
Jun 5, 2012
Kind
B2
Abstract

In an application execution system having a plurality of application servers, each application server stores a plurality of applications, and has computational resources for executing applications in response to received requests. Each application server also includes instructions for loading a respective application into volatile storage and executing the application in response to a request from a client, and for returning a result. In addition, each application server includes instructions for conditionally terminating execution of the respective application prior to returning the result if the respective application violates any execution restriction. The execution restrictions may include: a response time limit; an average response time limit over multiple executions of the application; a volatile memory usage limit; a restriction on using non-volatile storage of the application server; and a requirement limiting where state information is stored. The execution restrictions in aggregate maintain scalability of the application execution system.

Claims (96)

1. A method of operating an application server in a system having a plurality of application servers, each application server comprising memory and one or more processors, the method comprising:

storing a plurality of applications in memory;

receiving a request from a client to execute a respective application of the plurality of applications;

executing an instance of the respective application;

determining whether execution of the instance of the respective application violates any of a plurality of execution restrictions, the plurality of execution restrictions selected from the group consisting of:

a response time limit;

an average response time limit over multiple executions of the respective application;

a volatile memory usage limit that limits how much volatile memory can be used by each execution of the respective application;

a restriction on using non-volatile storage of the application server; and

a requirement that any state information to be retained after returning the result is either sent to the client for storage, or retained in a datastore accessible by all the application servers in the plurality of application servers;

when execution of the instance of the respective application does not violate any of the plurality of execution restrictions, returning a result to the client; and

when execution of the instance of the respective application does violate one or more of the plurality of execution restrictions, terminating execution of the instance of the respective application without returning a result to the client.

2. The method of claim 1 , wherein the volatile memory usage limit is the same for all of the applications in the plurality of applications.

3. The method of claim 1 , further comprising preventing subsequent execution of a respective application that has violated any of the execution restrictions.

4. The method of claim 1 , further comprising preventing subsequent loading into volatile storage of a respective application that has violated any of the execution restrictions.

5. An application server computer system, comprising:

memory;

one or more processors; and

one or more programs stored in the memory and configured for execution by the one or more processors, the one or more programs including:

instructions for storing a plurality of applications in memory;

instructions for receiving a request from a client to execute a respective application of the plurality of applications;

instructions for executing an instance of the respective application;

instructions for determining whether execution of the instance of the respective application violates any of a plurality of execution restrictions, the plurality of execution restrictions selected from the group consisting of:

a response time limit;

an average response time limit over multiple executions of the respective application;

a volatile memory usage limit that limits how much volatile memory can be used by each execution of the respective application;

a restriction on using non-volatile storage of the application server; and

a requirement that any state information to be retained after returning the result is either sent to the client for storage, or retained in a datastore accessible by all the application servers in the plurality of application servers;

instructions for returning a result to the client when execution of the instance of the respective application does not violate any of the plurality of execution restrictions, returning a result to the client; and

instructions for terminating execution of the instance of the respective application without returning a result to the client when execution of the instance of the respective application does violate one or more of the plurality of execution restrictions.

6. The application server computer system of claim 5 , wherein the volatile memory usage limit is the same for all of the applications in the plurality of applications.

7. The application server computer system of claim 5 , further comprising instructions for preventing subsequent execution of a respective application that has violated any of the execution restrictions.

8. The application server computer system of claim 5 , further comprising instructions for preventing subsequent loading into volatile storage of a respective application that has violated any of the execution restrictions.

9. A non-transitory computer readable storage medium storing one or more programs to be executed by an application server computer system, the one or more programs comprising:

instructions for storing a plurality of applications in memory;

instructions for receiving a request from a client to execute a respective application of the plurality of applications;

instructions for executing an instance of the respective application;

instructions for determining whether execution of the instance of the respective application violates any of a plurality of execution restrictions, the plurality of execution restrictions selected from the group consisting of:

a response time limit;

an average response time limit over multiple executions of the respective application;

a volatile memory usage limit that limits how much volatile memory can be used by each execution of the respective application;

a restriction on using non-volatile storage of the application server; and

a requirement that any state information to be retained after returning the result is either sent to the client for storage, or retained in a datastore accessible by all the application servers in the plurality of application servers;

instructions for returning a result to the client when execution of the respective application does not violate any of the plurality of execution restrictions, returning a result to the client; and

instructions for terminating execution of the respective application without returning a result to the client when execution of the respective application does violate one or more of the plurality of execution restrictions.

10. The non-transitory computer readable storage medium of claim 9 , wherein the volatile memory usage limit is the same for all of the applications in the plurality of applications.

11. The non-transitory computer readable storage medium of claim 9 , further comprising instructions for preventing subsequent execution of a respective application that has violated any of the execution restrictions.

12. The non-transitory computer readable storage medium of claim 9 , further comprising instructions for preventing subsequent loading into volatile storage of a respective application that has violated any of the execution restrictions.

13. A method of operating an application server in a system having a plurality of application servers, each application server comprising memory and one or more processors, the method comprising:

storing a plurality of applications in memory

receiving a request from a client to execute a respective application of the plurality of applications;

executing an instance of the respective application;

determining whether execution of the instance of the respective application violates any of a plurality of execution restrictions, the plurality of execution restrictions selected from the group consisting of:

a restriction on opening network connections;

a restriction on creating new processes by the respective application;

a restriction on making of system function calls by the respective application;

a restriction on number of requests for the respective application received per period of time;

a restrictions on number of CPU cycles used per period of time associated with the respective application;

a restriction on stack size associated with execution of the respective application;

when execution of the instance of the respective application does not violate any of the plurality of execution restrictions, returning a result to the client; and

when execution of the instance of the respective application does violate one or more of the plurality of execution restrictions, terminating execution of the instance of the respective application without returning a result to the client.

14. The method of claim 13 , further comprising preventing subsequent execution of a respective application that has violated any of the execution restrictions.

15. The method of claim 13 , further comprising preventing subsequent loading into volatile storage of a respective application that has violated any of the execution restrictions.

16. An application server computer system, comprising:

memory;

one or more processors; and

one or more programs stored in the memory and configured for execution by the one or more processors, the one or more programs including:

instructions for storing a plurality of applications in memory

instructions for receiving a request from a client to execute a respective application of the plurality of applications;

instructions for executing an instance of the respective application;

instructions for determining whether execution of the instance of the respective application violates any of a plurality of execution restrictions, the plurality of execution restrictions selected from the group consisting of:

a restriction on opening network connections;

a restriction on creating new processes by the respective application;

a restriction on making of system function calls by the respective application;

a restriction on number of requests for the respective application received per period of time;

a restrictions on number of CPU cycles used per period of time associated with the respective application;

a restriction on stack size associated with execution of the respective application;

instructions for returning a result to the client when execution of the instance of the respective application does not violate any of the plurality of execution restrictions, returning a result to the client; and

instructions for terminating execution of the instance of the respective application without returning a result to the client when execution of the instance of the respective application does violate one or more of the plurality of execution restrictions.

17. The application server computer system of claim 16 , the one or more programs further comprising instructions for preventing subsequent execution of a respective application that has violated any of the execution restrictions.

18. The application server computer system of claim 16 , the one or more programs further comprising instructions for preventing subsequent loading into volatile storage of a respective application that has violated any of the execution restrictions.

19. A non-transitory computer readable storage medium storing one or more programs to be executed by an application server computer system, the one or more programs comprising:

instructions for storing a plurality of applications in memory

instructions for receiving a request from a client to execute a respective application of the plurality of applications;

instructions for executing an instance of the respective application;

instructions for determining whether execution of the instance of the respective application violates any of a plurality of execution restrictions, the plurality of execution restrictions selected from the group consisting of:

a restriction on opening network connections;

a restriction on creating new processes by the respective application;

a restriction on making of system function calls by the respective application;

a restriction on number of requests for the respective application received per period of time;

a restrictions on number of CPU cycles used per period of time associated with the respective application;

a restriction on stack size associated with execution of the respective application;

instructions for returning a result to the client when execution of the instance of the respective application does not violate any of the plurality of execution restrictions, returning a result to the client; and

instructions for terminating execution of the instance of the respective application without returning a result to the client when execution of the instance of the respective application does violate one or more of the plurality of execution restrictions.

20. The non-transitory computer readable storage medium of claim 19 , the one or more programs further comprising instructions for preventing subsequent execution of a respective application that has violated any of the execution restrictions.

21. The non-transitory computer readable storage medium of claim 19 , the one or more programs further comprising instructions for preventing subsequent loading into volatile storage of a respective application that has violated any of the execution restrictions.

Assignments (2)
CHANGE OF NAME Recorded Oct 2, 2017
From: GOOGLE INC.
To: GOOGLE LLC
Reel/Frame 044101/0405 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2016
From: ASHCRAFT, KENNETH; MCALISTER, JON; GIBBS, KEVIN A.; BARRETT, RYAN C.
To: GOOGLE INC.
Reel/Frame 037465/0689 →
Continuity (2)
Continuation 12331351 · Dec 9, 2008
Related Publication 20110302243A1 · Dec 8, 2011