Method, computer program, and computer system (Virtualization of specific values in a guest configuration based on a lower host symbol repository)
The method addresses the limitations of existing file virtualization technologies by using a virtual guest to manage configuration files through a symbol-based file system, achieving enhanced security, reliability, and transparent access without network dependence, thereby improving system management in virtualized environments.
Patent Information
- Application Number
- JP2021183084
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-11-12
- Filing Date
- 2021-11-10
- Publication Date
- 2025-06-11
- Estimated Expiration
- 2041-11-10
AI Technical Summary
Existing file virtualization technologies struggle to efficiently manage and share configuration files across multiple virtual guest instances, relying on network sharing which is limited to directory or file system levels and lacks individual file or field-level sharing capabilities, and is dependent on network reliability and speed.
A method utilizing a virtual guest that opens a real file in a traditional file system, extracts symbols from a symbol-based file system, and uses privileged instructions to the hypervisor to obtain replacement values from a symbol table, allowing for transparent access and management of configuration files without network dependence.
This approach enables enhanced security and reliability by eliminating network dependence for configuration file management, allows for transparent access to configuration files, and facilitates global sharing of configuration parameters among virtual guests, improving system management in virtualized environments, especially in cloud implementations.
Smart Images

Figure 0007691177000001 
Figure 0007691177000002 
Figure 0007691177000003
Abstract
Description
Technical Field
[0001] Embodiments of the present invention generally relate to computer systems, and more specifically to file virtualization.
[0002] In a virtual guest environment, configuration information unique to a particular guest instance is saved to files at various locations within the guest file system. These files are locally accessed and managed by the systems and applications running within the virtual guest instance. In an environment having a number of virtual guest instances, these unique configuration files are managed individually for each of the virtual guest instances.
Summary of the Invention
Problems to be Solved by the Invention
[0003] Remote file system functionality can be utilized to share file system content across multiple systems via network sharing. However, sharing occurs based on directory or file system criteria and is not available for individual files or at the field level. Network sharing also depends on the reliability and speed of the underlying network.
Means for Solving the Problems
[0004] In particular, a method is provided. The method includes a virtual guest that opens a real file located in a traditional file system. Each symbol is extracted from a symbol-based file located in a symbol-based file system. The symbol-based file is accessed via a symbolic link in the traditional file system that links to the corresponding file in the symbol-based file system. The virtual guest issues privileged instructions to the hypervisor regarding each symbol in the symbol-based file so as to obtain a replacement value from a symbol table stored in the hypervisor storage. The replacement value for each symbol is returned to the virtual guest when the virtual guest reads the symbol-based file. In response to a file read request for a traditional file, the replacement value is obtained from the symbol-based file using the symbolic link in the traditional file system.
[0005] Embodiments further relate to a computer system and a computer program product having substantially the same features as the computer-implemented method described above.
[0006] Additional features and advantages are realized through the techniques described herein. Other embodiments and aspects are described in detail herein. For a better understanding, reference may be made to the specification and drawings.
Brief Description of the Drawings
[0007] The subject matter regarded as the invention is particularly pointed out and distinctly claimed at the end of the specification in the claims. The foregoing and other features and advantages will be apparent from the following detailed description taken in conjunction with the accompanying drawings.
[0008]
Figure 1
[0009]
Figure 2
[0010]
Figure 3
[0011]
Figure 4
[0012]
Figure 5
DETAILED DESCRIPTION OF THE INVENTION
[0013] The present disclosure generally relates to the field of virtualized computing environments. In a virtualized computing environment, a virtual machine, also referred to as a virtual guest, operates like a real computer together with an operating system and hardware devices. Similar to a real computer, each virtual guest includes a number of files that constitute the operation of the virtual guest. Such configuration information includes guest IP addresses, network configurations, DNS configurations, resolver configurations, and a wide variety of other system and application-related configurations (LDAP, Docker, registry) unique to the virtual guest instance. These files are locally accessed and managed by virtual guests and applications on the virtual guest.
[0014] In a large-scale computing environment, these unique configuration files and common files are replicated across virtual guests and managed separately. In current practice, network shares such as Network File System (NFS) can export files containing configuration information to multiple systems. However, network shares operate at the directory level and not at the individual file level or at the field level within a file. Network shares also rely on the reliability and speed of the underlying network, and since data transfers are sent in plain text by default, they are difficult to protect.
[0015] Embodiments of the present invention provide a specialized symbol - based file system that allows configuration files to be managed locally in a host environment. Thus, the configuration files do not depend on a network to replicate them across multiple virtual guest instances. A locally - protected interface between the virtual guest and the host is used to obtain or resolve values in the configuration file, or a combination thereof, thereby providing enhanced security and reliability since network access is not required. Also, the virtual guest does not depend on directory - level sharing limitations. The virtual guest has transparent access to its configuration files and configuration parameters. This means that when the configuration parameters in the configuration file are updated, the changes are reflected in the virtual guest without requiring downtime in the virtual guest at each time the configuration file is opened in the normal execution mode. The use of symbolic links in traditional file systems allows the configuration file to be located in a symbol - based file system in the virtual guest. However, the symbol - based file is located under the mount point of the symbol - based file system. Similarly, via the symbol - based file system, configuration parameters can be globally shared among all virtual guests instantiated on the host, or customized for a particular virtual guest on the host. Additionally, global sharing means that the configuration files and configuration parameters for a number of virtual guests can be centrally managed and can be an advantage in a cloud environment. Thus, embodiments of the present invention tend to improve system management techniques in a virtual guest environment, especially when it applies to cloud implementations.
[0016] Embodiments of the present invention will be described in more detail in relation to the figures.
[0017] FIG. 1 is a functional block diagram of an exemplary virtualization environment (system) 100 according to an embodiment of the present invention.
[0018] As shown, system 100 includes one or more computer systems / servers (servers) 12, one of which is shown. Server 12 can include any computer capable of including a hypervisor 10, which virtualizes the hardware of server 12 to enable support for one or more arbitrary virtual guests, such as guest 1 205 and guest 2 205.
[0019] The functions and processes of server 12 may be described in relation to computer system executable instructions such as program modules, routines, objects, data structures, and logic that perform specific tasks or implement specific abstract data types. Server 12 can be part of a distributed cloud computing environment and can enable the generation of multiple virtual guests when hypervisor 10 is installed on server 12.
[0020] As shown in FIG. 1, server 12 can include, but is not limited to, one or more processors or processing units 16, a system memory 28, and a bus 18 that couples various system components including system memory 28 to processor 16.
[0021] Bus 18 represents one or more of several types of bus structures including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, and a processor or local bus using any of various bus architectures.
[0022] Server 12 typically includes various computer system readable media. Such media can be any available media accessible by computer system / server 12 and includes both volatile and non-volatile media, removable and non-removable media.
[0023] Memory 28 may include a computer system readable medium in the form of volatile memory such as random access memory (RAM) 30 or cache memory 32 or a combination thereof. Server 12 may further include other removable / non-removable, volatile / non-volatile computer system storage media. For example, storage system 34 may include a non-removable non-volatile magnetic medium, such as a “hard drive,” and an optical disk drive for reading from / writing to removable non-volatile optical disks such as CD-ROMs, DVDs-ROMs or other optical media. Each device within storage system 34 may be connected to bus 18 via one or more data media interfaces, such as I / O interface 22 for example.
[0024] Each program 40 (one of which is shown) represents one of a plurality of programs stored in storage system 34 and is loaded into memory 28 for execution. Program 40 includes instances such as an operating system, an application, a system utility, or the like. Each program 40 includes one or more modules 42. The data of symbol table 11 may be stored on storage system 34. During operation of the virtual guest, hypervisor 10 can cause the data of symbol table 11 to be loaded into the memory of hypervisor 10 and make it available for addition to the configuration parameters of the virtual guest. It should be noted that the virtual guest is optional even if server 12 includes hypervisor 10. Other configurations are possible.
[0025] Server 12 may also communicate with one or more external devices 14 such as a keyboard, a pointing device, or any device (such as a network card, a modem, etc.) that enables server 12 to communicate with one or more other computing devices, or a combination thereof. Such communication may occur via input / output (I / O) interface 22.
[0026] The management console 24 includes specialized software that communicates with components of the hypervisor 10 of the server 12 via the I / O interface 22 to manage the configuration and state of virtual guests. Using the management console 24, an administrator with appropriate security approvals defines symbols and their corresponding replacement values, which are configuration values regarding virtual guests. The symbols and their corresponding replacement values can be stored in the storage system 34 on the server 12. The defined symbols and their corresponding replacement values are stored in the memory of the hypervisor 10 as a symbol table 11. Also, in operation, as further described with reference to FIGS. 2 through 3, a symbol-based file system and associated symbolic links are configured.
[0027] The server 12 can communicate with one or more networks via the network adapter 20. As shown, the network adapter 20 communicates with other components of the server 12 via the bus 18. Although not shown, other hardware or software or a combination of components may be used in conjunction with the server 12. Examples include, but are not limited to, microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drivers, and data archive storage systems. In the present invention, the server 12 can represent a physical hardware and software implementation. The server 12 can also represent a virtual implementation of a physical server, such as a virtual machine or virtual guest.
[0028] FIG. 2 shows a virtual guest instance having a symbol-based file system according to an embodiment of the present invention.
[0029] Figure 2 shows two virtual guests (multiple guests) 205, Guest 1 and Guest 2. Each guest 205 is instantiated on a physical server, such as server 12 in FIG. 1. Each guest 205 includes a logical file system layer 215. The logical file system presents file system data to the operating system of guest 205 or server 12 in a uniform manner, regardless of the underlying physical storage devices having different data storage architectures. The hypervisor 10 on server (host) 12 implements both a traditional file system 225 and a symbol-based file system 220 in each guest 205. The traditional file system can be considered to store data to and retrieve data from the underlying storage medium without changing the plaintext value of the data. In contrast, the symbol-based file system 220 interprets each field of the stored data as read from the storage medium and replaces it with a specially coded symbol with a value dynamically obtained from symbol table 11 via hypervisor 10. As shown in FIG. 2, hypervisor 10 stores and manages symbol table 11 compiled by guest 205. Symbol table 11 is here "&abcd.", and includes symbols shown in guest 205 file 210 and replacement values here "1.1.1.1" for Guest 1 and "2.2.2.2" for Guest 2. This example shows that symbols can have different replacement values because the symbols are compiled by the virtual guests, even if files on different virtual guests contain the same symbols. As shown at 240, the symbol-based file system 220 interprets a system call from an application or operating system to open a file 210 that contains symbols. Next, the symbol-based file system obtains symbol values from hypervisor 10 via a privileged call to hypervisor 10. The replacement value for each symbol is returned to the calling source in the virtual guest.
[0030] Figure 3 shows the relationship between the traditional file system 225 and the symbol-based file system 220 according to an embodiment of the present invention.
[0031] As shown at 310, the file tree represents the actual location of files and symbolic links in the traditional file system 225. These files include system configuration files such as " / etc / hosts" and " / etc / resolv.conf". However, the files can include other types of files such as application configuration files. The location of the files is not limited to the " / etc" directory. The files "x", "y.txt", and "z" are files stored in the symbol-based file system 220. As shown at 330, the files on the symbol-based file system 220 include parameters required by the application or the operating system. Some parameters may explicitly include things like "Parm1=local", but some parameters like "Parm2=&abcd." can be symbols. Element 340 shows the resulting state of the file after symbol resolution as if it was read through a symbolic link in the traditional file system. For example, "Parm2=&abcd." is now resolved as "Parm2=1.1.1.1". Each symbolic link in the traditional file system 225 is located in a place where the application or the operating system expects and assumes to contain the actual value regarding the parameter. Thus, the symbol and substitution processing is transparent to the application / operating system.
[0032] Figure 3 shows two symbolic links 320. The symbolic links 320 are created in the traditional file system 225 to reference appropriate files in the symbol-based file system 220. When the application / operating system issues a system call to open one of the symbolic links 320, the call is redirected to the symbol-based file system 220 that manages the linked file. When the linked symbol-based file is read from storage into memory, the symbol-based file system 220 tries the content field by field to a specific embedded symbol. For each specific symbol, the hypervisor 10 is called via a privileged instruction, and the format and content of the privileged instruction follow the architecture implementation. The privileged instruction includes a metadata operand that uniquely identifies which guest 205 item should be retrieved from the symbol table 11. When positioning the uniquely identified guest 205 item, the hypervisor 10 returns the resolved value to the symbol-based file system that replaces the symbol with the resolved value in memory. Any subsequent call to read the content of the opened symbolic link returns the resolved content to the application / operating system call origin.
[0033] Administrators with appropriate security approvals should note that they can maintain (add / update / delete) the symbol table 11 while the guest 205 is active. In that case, the next call to open a file will cause the initialization process described above to be re-executed so that the symbols are refreshed, except where existing symbolic links can be used.
[0034] Figure 4 is a flow for initializing a symbol-based file system according to an embodiment of the present invention.
[0035] At 410, the specialized software of the management console 24 receives configuration symbols and corresponding replacement values. Each virtual guest is associated with a unique profile that includes, among other data, a unique identifier and a user ID for starting and processing the virtual guest. Depending on the virtualization implementation, additional data may be associated with the unique profile, such as a unique job name and a unique process identifier.
[0036] At 415, the hypervisor 10 on the host system (server 12) generates a symbol table 11 in the hypervisor 10 memory with the corresponding replacement values. The symbol table 11 can be organized as a hash table used with a guest profile indicating how each symbol definition is resolved. The symbol table 11 persists to the system storage 34 to avoid having to re-enter the symbol table 11 each time the system starts. The persisted format can be a simple file, a table in a table of files or a relational database, or any other suitable representation.
[0037] At 420, the hypervisor 10 creates a file containing the configuration symbols in the symbol-based file system on each virtual guest. The created file can be located anywhere in the symbol-based file system.
[0038] At 430, a symbolic link is created from the file location in the traditional file system 225 to the file created in the symbol-based file system 220. The file location in the traditional file system is where the operating system or application expects the file to be, such as " / etc" for DNS "resolv.conf". The creation of the symbolic link may be automated or may be performed manually by an administrator with appropriate permissions.
[0039] FIG. 5 is a flow for resolving symbols in a virtual guest instance according to an embodiment of the present invention.
[0040] At 505, the operating system or application issues a request to open a configuration file at an expected location, for example, " / etc / resolv.conf". The request is issued using a known file system access method such as "fopen".
[0041] At 510, the file system access method, for example, "fopen", opens " / etc / resolv.conf". When "fopen" opens a symbolic link, the request is transferred to the symbol-based file system 220.
[0042] At 515, for each symbol, "fopen" in the symbol-based file system executes a privileged instruction to the hypervisor 10 to obtain a corresponding replacement value with respect to the call source in a specific guest 205.
[0043] At 520, based on a unique profile regarding the virtual guest accessing the file, the hypervisor 10 searches the symbol table 11.
[0044] At 525, the hypervisor 10 performs symbol substitution, and the replacement value is returned to the virtual guest.
[0045] At 530, the symbol substitution is completed and the "fopen" process ends. The symbol substitution is in memory and not persistent.
[0046] At 535, for example, the call source of "fopen" that opens " / etc / resolv.conf" receives a message indicating that the file has been successfully opened from the "fopen" process. In this case, subsequent read operations return the replacement value.
[0047] It should be noted that the administrator can modify symbols and replacement values without interrupting the operation of the virtual guest or the operating system. In this case, the replacement values are refreshed in the virtual guest at each point in time when the file is opened.
[0048] Various embodiments of the invention may be implemented within a data processing system suitable for storing or executing program code or a combination thereof, including at least one processor directly or indirectly coupled to a memory element through a system bus. The memory element may include, for example, local memory utilized during actual execution of program code, a mass storage device, and cache memory that provides temporary storage of at least a portion of the program code to reduce the number of times the code must be retrieved from the mass storage device during execution.
[0049] Input / output or I / O devices (including, but not limited to, keyboards, displays, pointing devices, DASDs, tapes, CDs, DVDs, thumb drives, and other memory media) may be coupled to the system directly or through an intervening I / O controller. A network adapter may also be coupled to the system through an intervening private or public network to enable the data processing system to be coupled to other data processing systems or remote printers or storage devices. Modems, cable modems, and Ethernet® cards are just a few of the types of network adapters available.
[0050] The present invention may be a system, method, or computer program product, or a combination thereof, at any possible technical detail level of integration. The computer program product may include a computer-readable storage medium (or media) having computer-readable program instructions for causing a processor to execute aspects of the present invention.
[0051] A computer-readable storage medium can be a tangible device that holds and stores instructions for use by an instruction execution device. The computer-readable storage medium can be, by way of example and not limitation, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A more specific, non-exhaustive list of computer-readable storage media includes portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital versatile discs (DVDs), memory sticks, floppy disks, punch cards, mechanically encoded devices such as a raised structure within a groove having instructions recorded thereon, and any suitable combination of the foregoing. As used herein, a computer-readable storage medium does not include a transitory signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., an optical pulse passing through a fiber optic cable), or an electrical signal transmitted through a wire.
[0052] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to respective computing / processing devices via a network, such as the Internet, a local area network, a wide area network, or a wireless network, or a combination thereof, or can be downloaded to an external computer or an external storage device. The network can comprise copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers, or edge servers, or a combination thereof. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and transfers the computer-readable program instructions for storage in a computer-readable storage medium within each respective computing / processing device.
[0053] Computer-readable program instructions for carrying out the operation of the present invention may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, configuration data for integrated circuits, or either source code or object code written in any combination of one or more programming languages. The one or more programming languages include object-oriented programming languages such as Smalltalk®, C++, etc., and procedural programming languages such as the "C" programming language or similar programming languages. The computer-readable program instructions may be executed entirely on the user's computer, or may be executed partially on the user's computer as a stand-alone software package, or may be executed partially on the user's computer and partially on a remote computer, or may be executed entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network including a local area network (LAN) or a wide area network (WAN), and the connection may be made through an external computer (e.g., through the Internet using an Internet service provider). In some embodiments, an electronic circuit including, for example, a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA) may execute the computer-readable program instructions by utilizing the state information of the computer-readable program instructions for personalizing the electronic circuit.
[0054] Aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.
[0055] These computer-readable program instructions may be provided to a computer processor or other programmable data processing apparatus to produce a machine, such that the instructions executed via the computer processor or other programmable data processing apparatus create means for implementing the functions / acts specified in the block or blocks of the flowchart and / or block diagram and combinations thereof. These computer-readable program instructions may also be stored in a computer-readable storage medium that can direct a computer, other programmable data processing apparatus, or other devices to function in a particular manner, such that the storage medium having instructions stored therein comprises an article of manufacture including instructions for implementing the functions / acts specified in the block or blocks of the flowchart and / or block diagram and combinations thereof.
[0056] The computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus, or other device to produce a computer-implemented process, such that the instructions which execute on the computer, other programmable apparatus, or other device implement the functions / acts specified in the block or blocks of the flowchart and / or block diagram and combinations thereof.
[0057] The flowcharts and block diagrams in the drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, segment, or portion of instructions that comprises one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be implemented as one step, may be executed simultaneously, substantially simultaneously, in a partially or wholly temporally overlapping manner, or these blocks may be executed in the reverse order depending on the functionality involved. It should also be noted that each block of the block diagrams or flowchart diagrams, or combinations of blocks in the block diagrams or flowchart diagrams, and combinations of blocks in the block diagrams or flowchart diagrams or combinations thereof, can be implemented by a specialized hardware-based system that performs the specified functions or acts, or a combination of specialized hardware and computer instructions.
[0058] The preferred embodiments have been illustrated and described in detail in the drawings and the specification. It is obvious to those skilled in the art that various modifications, additions, substitutions, etc. can be made without departing from the gist of the disclosure. Therefore, these are considered to be within the scope of the disclosure as defined in the following claims.
Claims
1. A method executed by a computer, comprising: the computer opening a symbolic link located in a traditional file system of a virtual guest; the computer extracting each symbol from a symbol-based file, the symbol-based file being located in a symbol-based file system and being accessed via the symbolic link in the traditional file system; the computer executing a privileged call to a hypervisor from the virtual guest for each symbol in the symbol-based file to obtain a replacement value from a symbol table, the symbol table being stored in hypervisor storage; the computer returning the replacement value for each symbol to the virtual guest, the replacement value replacing the symbol in the symbol-based file; the computer obtaining the replacement value from the symbol-based file using the symbolic link from the actual file in response to a file read request from the virtual guest for the actual file in the traditional file system; A method comprising the above steps.
2. The method according to claim 1, further comprising: the computer generating the symbol table in hypervisor storage on a host system, the symbol table including symbols and their replacement values for each virtual guest defined on the host system; the computer creating, on each virtual guest, the symbolic link in the traditional file system to the symbol-based file in the symbol-based file system; the computer inserting parameters and their corresponding replacement values into each symbol-based file. The method according to claim 1, further comprising the above steps.
3. The method according to claim 1 or 2, wherein the symbol table is a hash table.
4. The symbol table is compiled by a virtual guest profile, the symbol table includes the symbols and resolution values for each virtual guest on the host system, and the virtual guest profile includes metadata that uniquely identifies each virtual guest, the method according to claim 2.
5. The modification to the symbol table is non-destructive and transparent to the active virtual guest, the method according to any one of claims 1 to 4.
6. The symbol is not unique in the symbol table, the method according to any one of claims 1 to 5.
7. The symbol is included in more than one different symbol-based file in the virtual guest, or the symbol is included more than once in the same symbol-based file, the method according to any one of claims 1 to 6.
8. A computer program comprising program code to be implemented, the program code being executable by a processor of a computer to perform a method, the method comprising: opening a symbolic link in the traditional file system of the virtual guest; extracting each symbol from a symbol-based file, the symbol-based file being located in a symbol-based file system and the symbol-based file being accessed via a symbolic link in the traditional file system; executing a privileged call to the hypervisor from the virtual guest for each symbol in the symbol-based file to obtain a replacement value from the symbol table, the symbol table being stored in hypervisor storage; returning the replacement value from each symbol to the virtual guest, the replacement value replacing the symbol in the symbol-based file; obtaining the replacement value from the symbol-based file using the symbolic link from the actual file in response to a file read request from the virtual guest for the actual file in the traditional file system; A computer program comprising.
9. In the hypervisor storage on the host system, the step of generating the symbol table, wherein the symbol table includes symbols and their replacement values for each virtual guest defined on the host system, step; On each virtual guest, the step of creating the symbolic link in the traditional file system to the symbol-based file in the symbol-based file system; The step of inserting parameters and their corresponding replacement values into each symbol-based file; The computer program according to claim 8, further comprising.
10. The computer program according to claim 8 or 9, wherein the symbol table is a hash table.
11. The computer program according to claim 9, wherein the symbol table is compiled by a virtual guest profile, the symbol table includes the symbols and resolution values for each virtual guest on the host system, and the virtual guest profile includes metadata that uniquely identifies each virtual guest.
12. The computer program according to any one of claims 8 to 11, wherein the modification to the symbol table is non-destructive and transparent to active virtual guests.
13. The computer program according to any one of claims 8 to 12, wherein the symbol is not unique in the symbol table.
14. The computer program according to any one of claims 8 to 13, wherein the symbol is included in more than one different symbol-based file in the virtual guest, or the symbol is included more than once in the same symbol-based file.
15. One or more processors, Memory coupled to at least one of the one or more processors, and, Stored in the memory, The operation of opening a symbolic link located in the traditional file system of a virtual guest; The step of extracting each symbol from a symbol-based file, wherein the symbol-based file is located in a symbol-based file system, and the symbol-based file is accessed through a link from an actual file. Executing a privileged call from the virtual guest to the hypervisor for each symbol in the symbol-based file to obtain a replacement value from the symbol table, where the symbol table is stored in hypervisor storage; an operation, Returning the replacement value from each symbol to the virtual guest, where the replacement value replaces the symbol in the symbol-based file; an operation, Obtaining the replacement value from the symbol-based file using the symbolic link from the actual file in response to a file read request from the virtual guest for the actual file in the traditional file system; an operation, A set of computer program instructions executed by at least one of the one or more processors to perform the above, A computer system comprising.
16. Generating the symbol table in hypervisor storage on the host system, where the symbol table includes symbols and their replacement values for each virtual guest defined on the host system; a step, On each virtual guest, creating the symbolic link in the traditional file system to the symbol-based file in the symbol-based file system; a step, Inserting parameters and their corresponding replacement values into each symbol-based file; a step, The computer system according to claim 15, further comprising.
17. The computer system according to claim 15 or 16, wherein the symbol table is a hash table.
18. The symbol table is compiled by a virtual guest profile, the symbol table includes the symbols and resolution values for each virtual guest on the host system, and the virtual guest profile includes metadata that uniquely identifies each virtual guest. The computer system according to claim 16.
19. The computer system according to any one of claims 15 to 18, wherein modifications to the symbol table are non-destructive and transparent to active virtual guests.
20. The computer system according to any one of claims 15 to 19, wherein the symbol is included in more than one different symbol-base file in the virtual guest, or the symbol is included more than once in the same symbol-base file.
Citation Information
Patent Citations
File system and method for controlling file system
JP2009251760A
File management method, computer, and file management program
JP2011018206A
Virtual environment construction support device and method
JP2016062246A
File sharing device
JP2019200643A
Software-Defined Network Attachable Storage System and Method
US20140082145A1