IP Library › Granted Patent US 9,721,091
Granted Patent B2
US 9,721,091 · App. 13/407,709 · Granted Aug 1, 2017

Guest-driven host execution

Inventors: Michael Tsirkin (Yokneam Yillit, IL); Dor Laor (Tel Aviv, IL)
Assignee: Red Hat Israel, Ltd.
G06F21/53G06F9/45558G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,721,091
App. No.
13/407,709
Granted
Aug 1, 2017
Kind
B2
Abstract

A system and method by which a host computer system can run executables on behalf of a virtual machine (VM) are disclosed. In accordance with one embodiment, an executable of a guest application of a virtual machine is received by a hypervisor and is run via the host operating system on behalf of the virtual machine.

Claims (36)

1. An apparatus comprising:

a memory;

a processor coupled to the memory;

a host operating system, executed by the processor from the memory; and

a hypervisor, communicatively coupled to the host operating system, to:

manage one or more virtual machines running on top of the host operating system, each of the one or more virtual machines having a respective guest operating system to run one or more guest applications,

receive, from a first virtual machine of the one or more virtual machines, an executable of a guest application of the first virtual machine, wherein the executable of the guest application was installed to run via a guest operating system of the first virtual machine, and wherein the executable comprises a binary machine code for the guest application of the first virtual machine,

validate that commands of the executable are authorized for the first virtual machine,

in response to an arrival of a network packet and a validation that the commands of the executable are authorized for the first virtual machine, run, via the host operating system, the executable on behalf of the first virtual machine, wherein running the executable via the host operating system comprises causing the first virtual machine to be placed into a sleep mode,

in view of a result returned by the executable, perform operations comprising:

causing awakening of the first virtual machine, and

discarding the network packet, and

pass, by the hypervisor, the result returned by the executable to the first virtual machine of the one or more virtual machines.

2. The apparatus of claim 1 wherein the hypervisor is also to verify the executable.

3. The apparatus of claim 1 further comprising a hardware resource that is not available to the first virtual machine.

4. The apparatus of claim 1 wherein the running of the executable on behalf of the first virtual machine prevents the guest application from compromising security of the first virtual machine.

5. A method comprising:

managing, by a processing device of a computer system hosting a hypervisor and one or more virtual machines, the one or more virtual machines running on top of a host operating system of the computer system, each of the one or more virtual machines having a respective guest operating system to run one or more guest applications;

receiving, from a first virtual machine of the one or more virtual machines by the hypervisor, an executable of a guest application of the first virtual machine, wherein the executable of the guest application was installed to run via a guest operating system of the first virtual machine, and wherein the executable comprises a binary machine code for the guest application of the first virtual machine;

validating that commands of the executable are authorized for the first virtual machine;

in response to an arrival of a network packet and a validation that the commands of the executable are authorized for the first virtual machine, running, via the host operating system, the executable on behalf of the first virtual machine, wherein running the executable via the host operating system comprises causing the first virtual machine to be placed into a sleep mode;

in view of a result returned by the executable, performing operations comprising:

causing awakening of the first virtual machine, and

discarding the network packet; and

passing, by the hypervisor, the result returned by the executable to the first virtual machine of the one or more virtual machines.

6. A non-transitory computer readable storage medium having instructions encoded thereon which, when executed by a computer system, cause the computer system to perform operations comprising:

managing, by a hypervisor hosted by the computer system, one or more virtual machines running on top of a host operating system of the computer system, each of the one or more virtual machines having a respective guest operating system to run one or more guest applications;

receiving, from a first virtual machine of the one or more virtual machines by hypervisor, an executable of a guest application of the first virtual machine, wherein the executable of the guest application was installed to run via a guest operating system of the first virtual machine, and wherein the executable comprises a binary machine code for the guest application of the first virtual machine;

validating that commands of the executable are authorized for the first virtual machine;

in response to an arrival of a network packet and a validation that the commands of the executable are authorized for the first virtual machine, running, via the host operating system, the executable on behalf of the first virtual machine, wherein running the executable via the host operating system comprises causing the first virtual machine to be placed into a sleep mode;

in view of a result returned by the executable, performing operations comprising:

causing awakening of the first virtual machine, and

discarding the network packet; and

passing, by the hypervisor, the result returned by the executable to the first virtual machine of the one or more virtual machines.

7. The non-transitory computer readable storage medium of claim 6 , wherein the hypervisor is also to verify the executable.

8. The non-transitory computer readable storage medium of claim 6 , further comprising a hardware resource that is not available to the first virtual machine.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2012
From: TSIRKIN, MICHAEL; LAOR, DOR
To: RED HAT ISRAEL, LTD.
Reel/Frame 027779/0047 →
Continuity (1)
Related Publication 20130227556A1 · Aug 29, 2013