AU2005292418B2

Method and apparatus for moving processes between isolation environments

Abstract

A method for moving an executing process from a source isolation scope to a target isolation scope includes the step of determining that the process is in a state suitable for moving. The association of the process changes from a source isolation scope to a target isolation scope. A rule loads in association with the target isolation scope.

Term

Term ended

Expired 23 September 2025, 1 year ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

24 claims: 23 independent, 1 dependent

  1. 1
    CLAIMS What is claimed is:1. A method for moving an executing process from a first isolation scope to a second isolation scope, the method comprising the steps of: (a) determining that a process executing in a first isolation environment comprising a first application isolation layer and a user isolation layer is in a state 10 suitable for moving;(b) monitoring whether the process is processing a request and queuing requests to the process;(c) suspending execution of the process in the first isolation environment;(d) changing, by a rules engine, an association of the process from a first 15 application isolation scope provided by the first application isolation layer to a second application isolation scope provided by a second application isolation layer;(e) changing the association of the process from the first isolation scope to the second isolation scope in a file system filter driver;20 (f) loading, by the rules engine, at least one rule associated with the second application isolation scope;(g) moving the process into the second isolation scope;and (h) resuming execution of the process in the second isolation scope. 25 2. The method of claim 1 wherein step (a) further comprises putting a process in a state suitable for moving. 3. The method of claim 2 further comprising putting the process in the state suitable for moving via one of a user interface and an administration program. 4. The method of claim 2 further comprising the step of prohibiting new 115 ο (Μ 2005292418 18 Apr requests to the process. 5. The method of claim 2 further comprising processing the queued requests after associating the process with the second isolation scope. 6. The method of claim 1 wherein step (d) further comprises writing, to the rules engine, information associating the process with the second application isolation scope. 10 7. The method of claim 1 further comprising changing an association of the process from the first application isolation scope to the second application isolation scope in a file system filter driver. 8. The method of claim 1 further comprising changing an association of the 15 process from the first application isolation scope to the second application isolation scope in one of a kernel hooking function and a user mode hooking function. 9. A method for moving an executing process into an isolation scope, the 20 method comprising: (a) determining that a process is in a state suitable for moving;(b) monitoring whether the process is processing a request, and queuing requests to the process;(c) suspending execution of the process;25 (d) associating, by a rules engine, the process with a first application isolation scope provided by an application isolation layer to a second application isolation scope, provided by a second application isolation layer, wherein the second application isolation scope and a user isolation layer, together comprise an isolation environment;30 (e) associating the process to the second application isolation scope in a file system filter driver;116 T 2005292418 11 May 2011 (f) loading, by the rules engine, at least one rule associated with the second application isolation scope of the isolation environment;(g) moving the process into the isolation scope;and (h) resuming execution of the process in the isolation scope. 10. The method of claim 9 wherein step (a) further comprises putting a process in a state suitable for moving. 11. The method of claim 10 further comprising putting the process in the state 10 suitable for moving via one of a user interface and an administration program. 12. The method of claim 10 further comprising prohibiting new requests to the process. 15 13. The method of claim 10 further comprising processing the queued requests after associating the process with the isolation scope. 14. The method of claim 9 wherein step (d) further comprises writing, to the rules engine, information associating the process with the second application 20 isolation scope. 15. The method of claim 9 further comprising the step of associating the process to the second application isolation scope in a file system filter driver. 25 16. The method of claim 9 further comprising the step of associating the process to the second application isolation scope in one of a kernel hooking function and user mode hooking function. 117 WO 2006/039181 PCT/US2005/033994 1/24 Ν» ο (Prior Art) WO 2006/039181 PCT/US2005/033994
  2. 2
    2/24 (Prior Art) WO 2006/039181 PCT/US2005/033994
  3. 3
    3/24 100 Fig. 2A WO 2006/039181 PCT/US2005/033994
  4. 4
    4/24 ο ο CM WO 2006/039181 PCT/US2005/033994
  5. 5
    5/24 Fig. 2C WO 2006/039181 PCT/US2005/033994
  6. 6
    6/24 Fig. 3 A WO 2006/039181 PCT/US2005/033994
  7. 7
    7/24 From 305 To 306 J WO 2006/039181 PCT/US2005/033994
  8. 8
    8/24 From 305 WO 2006/039181 PCT/US2005/033994
  9. 9
    9/24 From 305 Identify application-scoped instance as literal instance To 306 Fig. 3D WO 2006/039181 PCT/US2005/033994
  10. 10
    10/24 434 WO 2006/039181 PCT/US2005/033994
  11. 11
    11/24 Fie. 5 WO 2006/039181 PCT/US2005/033994
  12. 12
    12/24 602 Intercept/receive request to enumerate a directory If virtual child specified by rule exists, merge child into working data store yes r Flush working data store - Enumerate application scope and merge results into working data store for each such rule \r630 Determine set of rules applicable to immediate children f Enumerate user scope and merge results into working data store ^-618 Fig. 6 \ v_ Flush working data store WO 2006/039181 PCT/US2005/033994
  13. 13
    13/24 Fig. 7 WO 2006/039181 PCT/US2005/033994
  14. 14
    14/24 short filename Fig. 7A WO 2006/039181 PCT/US2005/033994
  15. 15
    15/24 Key not found error WO 2006/039181 PCT/US2005/033994
  16. 16
    16/24 to 's— WO 2006/039181 PCT/US2005/033994
  17. 17
    17/24 1006 no 1 yes Enumerate system scope and store results in working data store 1 r x—- 1014 1020 Return result 1012 Enumerate literal key and store results in working data store 1015 Application _ ^scope candidate has negative^ existence? no 1016 no more rules ^-1032 If virtual child specified by rule exists, merge child into working data store 1042 yes Flush working data store -►« Enumerate application scope candidate and merge results into working data store for each such rule 1030 -► Determine set of rules applicable to L immediate children t Enumerate user scope candidate and merge results into working data store 1017 1044 \ v_ Flush working data store 1018 WO 2006/039181 PCT/US2005/033994
  18. 18
    18/24 WO 2006/039181 PCT/US2005/033994
  19. 19
    19/24 Fig. 12 WO 2006/039181 PCT/US2005/033994
  20. 20
    20/24 WO 2006/039181 PCT/US2005/033994
  21. 21
    21/24 C From 1324 ▼ To 1328 Fig. 13A WO 2006/039181 PCT/US2005/033994
  22. 22
    22/24 WO 2006/039181 PCT/US2005/033994
  23. 23
    23/24 Fig. 15 WO 2006/039181 PCT/US2005/033994
  24. 24
    24/24 Fig. 16
Independent claims24