IP Library Granted Patent US 11,797,357
Granted Patent B2
US 11,797,357 · App. 17/380,338 · Granted Oct 24, 2023

UID and GID shifting for containers in user namespaces

Inventor: Giuseppe Scrivano (Milan, IT)
Assignee: Red Hat, Inc.
G06F9/52G06F12/0223
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,797,357
App. No.
17/380,338
Granted
Oct 24, 2023
Kind
B2
Abstract

A request to access an image stored by a host operating system (OS) maybe received from a process running in a container. The container may run a namespace including a plurality of namespace user identifiers (UIDs). A host UID corresponding to the namespace UID of the process may be synchronized with a host UID of an owner of the image based on configuration data of the namespace.

Claims (35)

1. A method comprising:

receiving, from a process running in a container, a request to access an image file stored by a host operating system (OS), the container running a namespace including a plurality of namespace user identifiers (UIDs); and

temporarily synchronizing, by a processing device, a first host UID corresponding to a namespace UID of the process to a second host UID corresponding to an owner of the image file in view of configuration data of the namespace.

2. The method of claim 1 , wherein the configuration data of the namespace includes a mapping from each of the plurality of namespace UIDs to a corresponding host UID.

3. The method of claim 2 , wherein synchronizing the first host UID comprises:

presenting the second host UID to a kernel of the host OS as the first host UID.

4. The method of claim 1 , wherein the synchronizing is performed at a run time of the container.

5. The method of claim 1 , wherein the synchronizing is performed using a storage driver in user space without host OS root user privileges.

6. The method of claim 1 , wherein:

memory for a plurality of containers to access the image is allocated once; and

one copy of the image is stored for access by the plurality of containers.

7. The method of claim 1 , wherein the namespace UID of the process corresponds to a namespace UID of a root user of the container.

8. A system comprising:

a memory to store an image file;

a processing device to:

receive, from a process running in a container, a request to access the image file stored by a host operating system (OS), the container running a namespace including a plurality of namespace user identifiers (UIDs); and

temporarily synchronize a first host UID corresponding to a namespace UID of the process to a second host UID corresponding to an owner of the image file in view of configuration data of the namespace.

9. The system of claim 8 , wherein the configuration data of the namespace includes a mapping of each the plurality of namespace UIDs to a corresponding host UID.

10. The system of claim 9 , wherein to synchronize the first host UID, the processing device is further to present the second host UID to a kernel of the host OS as the first host UID.

11. The system of claim 8 , wherein the processing device performs the synchronizing at a run time of the container.

12. The system of claim 8 , wherein the processing device performs the synchronizing using a storage driver in user space without host OS root user privileges.

13. The system of claim 8 , wherein the processing device is further to:

allocate memory for a plurality of containers to access the image once; and

store one copy of the image for access by the plurality of containers in the memory.

14. The system of claim 8 , wherein the namespace UID of the process corresponds to a namespace UID of a root user of the container.

15. A non-transitory computer-readable storage medium including instructions that, when executed by a processing device, cause the processing device to:

receive, from a process running in a container, a request to access an image file stored by a host operating system (OS), the container running a namespace including a plurality of namespace user identifiers (UIDs); and

temporarily synchronize a first host UID corresponding to a namespace UID of the process to a second host UID corresponding to an owner of the image file in view of configuration data of the namespace.

16. The non-transitory computer-readable storage medium of claim 15 , wherein the configuration data of the namespace includes a mapping of each the plurality of namespace UIDs to a corresponding host UID.

17. The non-transitory computer-readable storage medium of claim 16 , wherein to synchronize the first host UID, the processing device is further to present the second host UID to a kernel of the host OS as the first host UID.

18. The non-transitory computer-readable storage medium of claim 15 , wherein the processing device performs the synchronizing at a run time of the container.

19. The non-transitory computer-readable storage medium of claim 15 , wherein the processing device performs the synchronizing using a storage driver in user space without host OS root user privileges.

20. The non-transitory computer-readable storage medium of claim 15 , wherein the processing device is further to:

allocate memory for a plurality of containers to access the image once; and

store one copy of the image for access by the plurality of containers in the memory.

Assignments (2)
CHANGE OF NAME Recorded Mar 3, 2026
From: RED HAT, INC.
To: RED HAT, LLC
Reel/Frame 074913/0759 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 20, 2021
From: SCRIVANO, GIUSEPPE
To: RED HAT, INC.
Reel/Frame 056918/0789 →
Continuity (2)
Continuation 16393811 · Apr 24, 2019
Related Publication 20210349768A1 · Nov 11, 2021