IP Library Granted Patent US 12,645,786
Granted Patent B2
US 12,645,786 · App. 18/241,710 · Granted Jun 2, 2026

Subsystem permission error diagnostic aid

Inventors: Eric Paris (Raleigh, NC); Giuseppe Scrivano (Milan, IT); Daniel Walsh (Augusta, GA)
Assignee: Red Hat, Inc.
G06F21/552G06F21/554
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,645,786
App. No.
18/241,710
Granted
Jun 2, 2026
Kind
B2
Abstract

Systems, methods, and apparatuses for determining a cause of an error in a computing environment, such as a permission denied error in a linux computing environment, are provided herein. An example method comprises executing an application in a linux environment, monitoring a plurality of linux subsystems and functions via an instrumentation inserted on a kernel, and responsive to a failure of the application, providing a summary of a cause of the failure based upon the monitoring of the linux subsystems and functions.

Claims (43)

1 . A method, comprising:

executing an application in a computing environment;

monitoring a plurality of computing subsystems and a plurality of functions via an instrumentation inserted on a kernel to identify a plurality of actions performed by the plurality of computing subsystems and the plurality of functions;

recording the plurality of actions performed by the plurality of computing subsystems and the plurality of functions; and

responsive to a failure of the application:

determining an action of the plurality of actions that occurred just prior to the failure of the application;

identifying a permission corresponding to the action;

based on identifying the permission corresponding to the action, determining that the permission is a denied permission that caused the failure of the application; and

providing a summary of a cause of the failure, the summary comprising the denied permission.

2 . The method of claim 1 , wherein the executing takes place in a containerized computing environment.

3 . The method of claim 2 , wherein the containerized computing environment runs in a container engine, and wherein the monitoring is responsive to a debug flag being set to active in the container engine.

4 . The method of claim 1 , wherein the failure of the application is caused by a permission denied error.

5 . The method of claim 1 , wherein the summary further includes a computing subsystem of the plurality of computing subsystems that caused the failure.

6 . The method of claim 1 , further comprising determining a computing subsystem of the plurality of computing subsystems that caused the failure based upon the action of the plurality of actions that occurred just prior to the failure of the application.

7 . The method of claim 1 , wherein the instrumentation includes an extended Berkeley Packet Filter (eBPF) implementation.

8 . A system, comprising:

a memory; and

a processing device, operatively coupled to the memory, to:

execute an application in a computing environment;

monitor a plurality of computing subsystems and a plurality of functions via an instrumentation inserted on a kernel to identify a plurality of actions performed by the plurality of computing subsystems and the plurality of functions;

record the plurality of actions performed by the plurality of computing subsystems and the plurality of functions; and

responsive to a failure of the application;

determine an action of the plurality of actions that occurred just prior to the failure of the application;

identify a permission corresponding to the action;

based on identifying the permission corresponding to the action, determine that the permission is a denied permission that caused the failure of the application; and

provide a summary of a cause of the failure, the summary comprising the denied permission.

9 . The system of claim 8 , wherein the failure of the application is caused by a permission denied error.

10 . The system of claim 8 , wherein the summary further includes a computing subsystem of the plurality of computing subsystems that caused the failure of the application.

11 . The system of claim 8 , wherein the processing device is further operatively coupled to the memory to determine a computing subsystem of the plurality of computing subsystems that caused the failure based upon the action of the plurality of actions that occurred just prior to the failure of the application.

12 . The system of claim 8 , wherein the instrumentation includes an extended Berkeley Packet Filter (eBPF) implementation.

13 . A non-transitory machine-readable medium storing instructions which, when executed by a processing device, cause the processing device to:

execute an application in a computing environment;

monitor a plurality of computing subsystems and a plurality of functions via an instrumentation inserted on a kernel to identify a plurality of actions performed by the plurality of computing subsystems and the plurality of functions;

record the plurality of actions performed by the plurality of computing subsystems and the plurality of functions; and

responsive to a failure of the application:

determine an action of the plurality of actions that occurred just prior to the failure of the application;

identify a permission corresponding to the action;

based on identifying the permission corresponding to the action, determining that the permission is a denied permission that caused the failure of the application; and

provide a summary of a cause of the failure, the summary comprising the denied permission.

14 . The non-transitory machine-readable medium of claim 13 , wherein the failure of the application is caused by a permission denied error.

15 . The non-transitory machine-readable medium of claim 13 , wherein the summary further includes a computing subsystem that caused the failure.

16 . The non-transitory machine-readable medium of claim 13 , wherein the instructions, when executed by the processing device, further cause the processing device to determine a computing subsystem of the plurality of computing subsystems that caused the failure based upon the action of the plurality of actions that occurred just prior to the failure of the application.

17 . The non-transitory machine-readable medium of claim 13 , wherein the instrumentation includes an extended Berkeley Packet Filter (eBPF) implementation.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2023
From: PARIS, ERIC S.; SCRIVANO, GIUSEPPE; WALSH, DANIEL
To: RED HAT, INC.
Reel/Frame 064793/0884 →
Continuity (1)
Related Publication 20250077652A1 · Mar 6, 2025
References Cited (14)
US 9804952B1 · Cohen et al. · 2017 [cited by applicant]
US 12267345B1 · Erlingsson · 2025 [cited by examiner]
US 20220350676A1 · Tamir et al. · 2022 [cited by applicant]
US 20230161867A1 · Feist et al. · 2023 [cited by applicant]
US 20230254330A1 · Singh · 2023 [cited by examiner]
US 20230275917A1 · Karmali · 2023 [cited by examiner]
US 20240303324A1 · Melgarejo Lermas · 2024 [cited by examiner]
US 20240340266A1 · van der Merwe · 2024 [cited by examiner]
US 20250061053A1 · Hecht · 2025 [cited by examiner]
“Troubleshooting eBPF”, extended Berkeley Packet Filter, 2016, 4 pages, accessed on: Aug. 31, 2023, accessed at: https://prototype-kernel.readthedocs.io/en/latest/bpf/troubleshooting.html. [cited by applicant]
Mauricio Vásquez Bernal, “Extending Systemd Security Features with eBPF”, Apr. 9, 2021, 13 pages. [cited by applicant]
“8.6 Release Notes—Red Hat Customer Content Services”, Red Hat, Inc., 2023, 231 pages. [cited by applicant]
“Bpf-Linux Manual Page” Linux/UNIX system programming training, accessed on Aug. 31, 2023, accessed at: https://man7.org/linux/man-pages/man2/bpf.2.html, 16 pages. [cited by applicant]
“Berkeley Packet Filter: Theory, Practice and Perspectives”, Alma Mater Studiorum—Universita di 'Bologna, 126 pages. [cited by applicant]