IP Library › Granted Patent US 12,190,181
Granted Patent B2
US 12,190,181 · App. 18/429,367 · Granted Jan 7, 2025

Invoking specified functionality within a sandbox process

Inventors: Isaac Kunen (Seattle, WA); Srinath Shankar (Belmont, CA); Zihan Li (Mountain View, CA); Khushboo Bhatia (Belmont, CA); Edward Ma (San Jose, CA)
Assignee: Snowflake Inc.
G06F9/547G06F16/2455G06F16/289G06F21/53
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,190,181
App. No.
18/429,367
Granted
Jan 7, 2025
Kind
B2
Abstract

A database system configured to manage and execute stored procedures within a secure sandbox process. The system receives a response to a database query and, through an Application Programming Interface (API) executing within the sandbox process, converts the response into a remote procedure call. The sandbox process is modified to restrict communication with external networks while enabling communication with a designated execution node, which facilitates interaction between the stored procedure and database system components. The stored procedure, executing within the confines of the sandbox process, directs the API to communicate with the execution node. The execution node, in turn, submits the database query to the database system component.

Claims (55)

1. A method comprising:

receiving, via an execution node, a response to a database query;

converting, via an Application Programming Interface (API) executing within a sandbox process, the response into a remote procedure call;

modifying, by at least one hardware processor, the sandbox process to restrict communication with an external network and to enable communication with the execution node, the execution node facilitating communication between a stored procedure and a component of a database system;

providing, to the stored procedure executing within the sandbox process, the remote procedure call as the response to the database query, the stored procedure executing within the sandbox process causing the API to communicate with the execution node; and

submitting, by the execution node, the database query to the component of the database system.

2. The method of claim 1 , wherein the stored procedure is configured to perform file operations including reading from stages and uploading to the stages within the database system, wherein the stored procedure is a subroutine stored within the database system to invoke specified functionality.

3. The method of claim 1 , further comprising:

loading the sandbox process with a JAVA database connectivity instance, the JAVA database connectivity instance being modified to limit communication abilities of the stored procedure.

4. The method of claim 3 , further comprising:

modifying the JAVA database connectivity instance to limit communications to a single execution node process that facilitates communication between the stored procedure and additional services and components of the database system.

5. The method of claim 1 , further comprising:

submitting, via the execution node, the database query to a compute service manager on behalf of the stored procedure, wherein the execution node issues the database query to a specific endpoint of the compute service manager being designated to process the database query from the stored procedure.

6. The method of claim 5 , further comprising:

receiving, via the execution node, a response from the compute service manager; and

converting the response, from the compute service manager, into a response remote procedure call, wherein the response remote procedure call is a result of the database query.

7. The method of claim 6 , further comprising:

returning, via the execution node, the result of the database query the relay back to the stored procedure within the sandbox process.

8. A system comprising:

one or more hardware processors of a machine; and

at least one memory storing instructions that, when executed by the one or more hardware processors, cause the system to perform operations comprising:

receiving, via an execution node, a response to a database query;

converting, via an Application Programming Interface (API) executing within a sandbox process, the response into a remote procedure call;

modifying, by at least one hardware processor, the sandbox process to restrict communication with an external network and to enable communication with the execution node, the execution node facilitating communication between a stored procedure and a component of a database system;

providing, to the stored procedure executing within the sandbox process, the remote procedure call as the response to the database query, the stored procedure executing within the sandbox process causing the API to communicate with the execution node; and

submitting, by the execution node, the database query to the component of the database system.

9. The system of claim 8 , wherein the stored procedure is configured to perform file operations including reading from stages and uploading to the stages within the database system, wherein the stored procedure is a subroutine stored within the database system to invoke specified functionality.

10. The system of claim 8 , the operations further comprising:

loading the sandbox process with a JAVA database connectivity instance, the JAVA database connectivity instance being modified to limit communication abilities of the stored procedure.

11. The system of claim 10 , the operations further comprising:

modifying the JAVA database connectivity instance to limit communications to a single execution node process that facilitates communication between the stored procedure and additional services and components of the database system.

12. The system of claim 8 , the operations further comprising:

submitting, via the execution node, the database query to a compute service manager on behalf of the stored procedure, wherein the execution node issues the database query to a specific endpoint of the compute service manager being designated to process the database query from the stored procedure.

13. The system of claim 12 , the operations further comprising:

receiving, via the execution node, a response from the compute service manager; and

converting the response, from the compute service manager, into a response remote procedure call, wherein the response remote procedure call is a result of the database query.

14. The system of claim 13 , the operations further comprising:

returning, via the execution node, the result of the database query for relay back to the stored procedure within the sandbox process.

15. A machine-readable medium embodying instructions that, when executed by a machine, cause the machine to perform operations comprising:

receiving, via an execution node, a response to a database query;

converting, via an Application Programming Interface (API) executing within a sandbox process, the response into a remote procedure call;

modifying, by at least one hardware processor, the sandbox process to restrict communication with an external network and to enable communication with the execution node, the execution node facilitating communication between a stored procedure and a component of a database system;

providing, to the stored procedure executing within the sandbox process, the remote procedure call as the response to the database query, the stored procedure executing within the sandbox process causing the API to communicate with the execution node; and

submitting, by the execution node, the database query to the component of the database system.

16. The machine-readable medium of claim 15 , wherein the stored procedure is configured to perform file operations including reading from stages and uploading to the stages within the database system, wherein the stored procedure is a subroutine stored within the database system to invoke specified functionality.

17. The machine-readable medium of claim 15 , the operations further comprising:

loading the sandbox process with a JAVA database connectivity instance, the JAVA database connectivity instance being modified to limit communication abilities of the stored procedure.

18. The machine-readable medium of claim 17 , the operations further comprising:

modifying the JAVA database connectivity instance to limit communications to a single execution node process that facilitates communication between the stored procedure and additional services and components of the database system.

19. The machine-readable medium of claim 15 , the operations further comprising:

submitting, via the execution node, the database query to a compute service manager on behalf of the stored procedure, wherein the execution node issues the database query to a specific endpoint of the compute service manager being designated to process the database query from the stored procedure.

20. The machine-readable medium of claim 19 , the operations further comprising:

receiving, via the execution node, a response from the compute service manager;

converting the response, from the compute service manager, into a response remote procedure call, wherein the response remote procedure call is a result of the database query; and

returning, via the execution node, the result of the database query for relay back to the stored procedure within the sandbox process.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2024
From: KUNEN, ISAAC; SHANKAR, SRINATH; LI, ZIHAN; BHATIA, KHUSHBOO; MA, EDWARD
To: SNOWFLAKE INC.
Reel/Frame 066326/0602 →
Continuity (7)
Continuation 18326905 · May 31, 2023
Continuation 18051075 · Oct 31, 2022
Continuation 17658530 · Apr 8, 2022
Continuation 17536173 · Nov 29, 2021
Continuation 17390930 · Jul 31, 2021
Provisional Application 63197760 · Jun 7, 2021
Related Publication 20240168834A1 · May 23, 2024
References Cited (29)
US 6016495A · Mckeehan et al. · 2000 [cited by applicant]
US 10628244B1 · Cseri et al. · 2020 [cited by applicant]
US 10997286B1 · Brossard et al. · 2021 [cited by applicant]
US 11138192B1 · Chintala et al. · 2021 [cited by applicant]
US 11216322B1 · Kunen et al. · 2022 [cited by applicant]
US 11321154B1 · Kunen et al. · 2022 [cited by applicant]
US 11487597B1 · Kunen et al. · 2022 [cited by applicant]
US 11704176B2 · Kunen et al. · 2023 [cited by applicant]
US 11948025B2 · Kunen et al. · 2024 [cited by applicant]
US 20030033517A1 · Rutherglen et al. · 2003 [cited by applicant]
US 20150242502A1 · Chadha · 2015 [cited by examiner]
US 20200177476A1 · Agarwal et al. · 2020 [cited by applicant]
US 20230082040A1 · Kunen et al. · 2023 [cited by applicant]
US 20230305910A1 · Kunen et al. · 2023 [cited by applicant]
CN 106233253 · 2016 [cited by applicant]
CN 109952564 · 2019 [cited by applicant]
CN 117441162 · 2024 [cited by applicant]
WO WO2017023236A1 · 2017 [cited by examiner]
WO 2022261617 · 2022 [cited by applicant]
“Chinese Application Serial No. 202280040984.9, Voluntary Amendment filed Jun. 1, 2024”, With English Claims, 40 pgs. [cited by applicant]
“Chinese Application Serial No. 202280040984.9, Office Action mailed Jun. 9, 2024”, with English translation, 11 pages. [cited by applicant]
“U.S. Appl. No. 17/390,930, Notice of Allowance mailed Nov. 1, 2021”, 8 pgs. [cited by applicant]
“U.S. Appl. No. 17/536,173, Notice of Allowance mailed Feb. 24, 2022”, 9 pgs. [cited by applicant]
“U.S. Appl. No. 17/658,530, Notice of Allowance mailed Jul. 5, 2022”, 8 pgs. [cited by applicant]
“International Application Serial No. PCT US2022 72772, International Search Report mailed Jul. 11, 2022”, 2 pgs. [cited by applicant]
“International Application Serial No. PCT US2022 72772, Written Opinion mailed Jul. 11, 2022”, 3 pgs. [cited by applicant]
“U.S. Appl. No. 18/051,075, Notice of Allowance mailed Mar. 9, 2023”, 12 pgs. [cited by applicant]
“International Application Serial No. PCT US2022 072772, International Preliminary Report on Patentability mailed Dec. 21, 2023”, 5 pgs. [cited by applicant]
“U.S. Appl. No. 18/326,905, Notice of Allowance mailed Jan. 11, 2024”, 7 pgs. [cited by applicant]