Patents by Inventor Mark M. Manning
Mark M. Manning has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12639336Abstract: A data platform for executing containers is provided. In some examples, the data platform receives an application from an application package of a provider account, the application including a setup script and a manifest of a service. The data platform activates access roles based on the manifest and creates the service and a compute pool using the setup script and a specification file accessed from the application package using an access role. The service is executed in the compute pool, accessing objects of the application package and of the data platform using the access roles.Type: GrantFiled: March 8, 2024Date of Patent: May 26, 2026Assignee: Snowflake Inc.Inventors: Brandon S. Baker, Siyuan Chen, Derek Denny-Brown, Scott C. Gray, Jaroslaw Kowalski, Mark M. Manning
-
Publication number: 20250284710Abstract: A data platform for executing containers is provided. In some examples, the data platform receives an application from an application package of a provider account, the application including a setup script and a manifest of a service. The data platform activates access roles based on the manifest and creates the service and a compute pool using the setup script and a specification file accessed from the application package using an access role. The service is executed in the compute pool, accessing objects of the application package and of the data platform using the access roles.Type: ApplicationFiled: March 8, 2024Publication date: September 11, 2025Inventors: Brandon S. Baker, Siyuan Chen, Derek Denny-Brown, Scott C. Gray, Jaroslaw Kowalski, Mark M. Manning
-
Publication number: 20240323032Abstract: Verifying signed source code using a vault device is described. An example method can include receiving, at a vault device, an object verification request, the object verification request comprising developer credentials associated with the object verification request, an object, and a first commit signature associated with the object. The method can further include determining a identity associated with the developer credentials, obtaining a signing key associated with the identity, and generating a local commit signature using the signing key. In addition, the method can include comparing the local commit signature with the first commit signature, and upon determining that the first commit signature and the local commit signature match, returning an indication of a successful verification.Type: ApplicationFiled: June 7, 2024Publication date: September 26, 2024Inventors: Mark M. Manning, Nathan A. Sfard
-
Publication number: 20240303321Abstract: A method for tracing system call execution includes instantiating, by at least one hardware processor of a compute node, a first process and a second process. The second process executes at the compute node as a child process of the first process. detecting a notification associated with a system call initiated by the child process. The child process is pause based on the notification. At least one permission associated with the system call is retrieved via the first process. A determination is made on whether to resume the child process based on the at least one permission.Type: ApplicationFiled: May 13, 2024Publication date: September 12, 2024Inventors: Brandon S. Baker, Derek Denny-Brown, Mark M. Manning, Andong Zhan
-
Patent number: 12019735Abstract: A method for tracing function execution includes instantiating, by at least one hardware processor of a computing node, a user-defined function (UDF) server associated with a plurality of configurations. A plurality of child processes of the UDF server are instantiated using the plurality of configurations. A filtering process is configured at an operating system (OS) kernel of the computing node using a child process of the plurality of child processes. The filtering process includes a set of system call categories and a corresponding set of filtering policies. A system call received at the OS kernel and associated with a system call category of the set of system call categories is detected to violate a corresponding filtering policy of the set of filtering policies. A tracing event of the system call is initiated based on the detecting.Type: GrantFiled: July 20, 2023Date of Patent: June 25, 2024Assignee: Snowflake Inc.Inventors: Brandon S. Baker, Derek Denny-Brown, Mark M. Manning, Andong Zhan
-
Patent number: 12022005Abstract: Signing source code using a vault device is described. An example method can include receiving, with a client device, source code that is to be committed to a repository. The method further can include sending, with a processing device to a vault device, a request to sign the source code. The method can further include receiving, from the vault device, a signed commit of the source code. In addition, the method can include pushing the source code and the signed commit to the repository, wherein the repository commits the source code and signed commit.Type: GrantFiled: January 27, 2023Date of Patent: June 25, 2024Assignee: Snowflake Inc.Inventors: Mark M. Manning, Nathan A. Sfard
-
Patent number: 11822645Abstract: A method for tracing function execution includes instantiating, by at least one hardware processor of a computing node, a user code runtime configured with access to an operating system (OS) kernel of the computing node. The user code runtime is configured with a first set of filtering policies associated with a first set of allowed system calls. The OS kernel is configured with a second set of filtering policies associated with a second set of allowed system calls. A system call initiated by the user code runtime is detected to violate one or both of the first set of allowed system calls and the second set of allowed system calls. A trace of the system call is initiated based on the detecting.Type: GrantFiled: January 30, 2023Date of Patent: November 21, 2023Assignee: Snowflake Inc.Inventors: Brandon S. Baker, Derek Denny-Brown, Mark M. Manning, Andong Zhan
-
Publication number: 20230359727Abstract: A method for tracing function execution includes instantiating, by at least one hardware processor of a computing node, a user-defined function (UDF) server associated with a plurality of configurations. A plurality of child processes of the UDF server are instantiated using the plurality of configurations. A filtering process is configured at an operating system (OS) kernel of the computing node using a child process of the plurality of child processes. The filtering process includes a set of system call categories and a corresponding set of filtering policies. A system call received at the OS kernel and associated with a system call category of the set of system call categories is detected to violate a corresponding filtering policy of the set of filtering policies. A tracing event of the system call is initiated based on the detecting.Type: ApplicationFiled: July 20, 2023Publication date: November 9, 2023Inventors: Brandon S. Baker, Dereck Denny-Brown, Mark M. Manning, Andong Zhan
-
Publication number: 20230275764Abstract: Signing source code using a vault device is described. An example method can include receiving, with a client device, source code that is to be committed to a repository. The method further can include sending, with a processing device to a vault device, a request to sign the source code. The method can further include receiving, from the vault device, a signed commit of the source code. In addition, the method can include pushing the source code and the signed commit to the repository, wherein the repository commits the source code and signed commit.Type: ApplicationFiled: January 27, 2023Publication date: August 31, 2023Inventors: Mark M. Manning, Nathan A. Sfard
-
Publication number: 20230177145Abstract: A method for tracing function execution includes instantiating, by at least one hardware processor of a computing node, a user code runtime configured with access to an operating system (OS) kernel of the computing node. The user code runtime is configured with a first set of filtering policies associated with a first set of allowed system calls. The OS kernel is configured with a second set of filtering policies associated with a second set of allowed system calls. A system call initiated by the user code runtime is detected to violate one or both of the first set of allowed system calls and the second set of allowed system calls. A trace of the system call is initiated based on the detecting.Type: ApplicationFiled: January 30, 2023Publication date: June 8, 2023Inventors: Brandon S. Baker, Derek Denny-Brown, Mark M. Manning, Andong Zhan
-
Patent number: 11640458Abstract: A system includes at least one hardware processor of a computing node and at least one memory storing instructions that cause the at least one hardware processor to perform operations. The operations include instantiating a user code runtime to execute within a sandbox process. The sandbox process configures access by the user code runtime to an operating system (OS) kernel of the computing node. The OS kernel is configured with one or more filtering policies. A determination is performed of whether a system call received by the OS kernel violates the one or more filtering policies. The system call is triggered by at least one operation of the user code runtime. A tracing event is instantiated to trace execution of the system call based on the determination.Type: GrantFiled: June 29, 2022Date of Patent: May 2, 2023Assignee: Snowflake Inc.Inventors: Brandon S. Baker, Derek Denny-Brown, Mark M. Manning, Andong Zhan
-
Patent number: 11632251Abstract: Signing source code using a vault device is described. An example method can include receiving, with a client device, source code that is to be committed to a repository. The method further can include sending, with a processing device to a vault device, a request to sign the source code. The method can further include receiving, from the vault device, a signed commit of the source code. In addition, the method can include pushing the source code and the signed commit to the repository, wherein the repository commits the source code and signed commit.Type: GrantFiled: February 28, 2022Date of Patent: April 18, 2023Assignee: Snowflake Inc.Inventors: Mark M. Manning, Nathan A. Sfard
-
Publication number: 20220391492Abstract: A system includes at least one hardware processor of a computing node and at least one memory storing instructions that cause the at least one hardware processor to perform operations. The operations include instantiating a user code runtime to execute within a sandbox process. The sandbox process configures access by the user code runtime to an operating system (OS) kernel of the computing node. The OS kernel is configured with one or more filtering policies. A determination is performed of whether a system call received by the OS kernel violates the one or more filtering policies. The system call is triggered by at least one operation of the user code runtime. A tracing event is instantiated to trace execution of the system call based on the determination.Type: ApplicationFiled: June 29, 2022Publication date: December 8, 2022Inventors: Brandon S. Baker, Derek Denny-Brown, Mark M. Manning, Andong Zhan
-
Patent number: 11409864Abstract: Provided herein are systems and methods for tracing and tracing supervision of UDFs in a database system. For example, a method includes receiving a user-defined function (UDF), the UDF including code related to at least one operation to be performed. A user code runtime is instantiated to execute the code of the UDF as a child process. The user code runtime includes a filtering process configured with a plurality of filtering policies. A system call of the at least one operation is detected based on a notification from an operating system (OS) manager, the notification identifying the system call. A determination is made on whether performing the system call is permitted based on the plurality of filtering policies. A report is generated based on the determining.Type: GrantFiled: July 30, 2021Date of Patent: August 9, 2022Assignee: Snowflake Inc.Inventors: Brandon S. Baker, Derek Denny-Brown, Mark M. Manning, Andong Zhan