Kernel task execution method, electronic equipment, readable storage medium and program product

Through multi-layer nested eBPF Map structure, the problem that eBPF Map cannot be nested in multiple layers is solved, and storage and container access control of complex rulesets are realized, which improves kernel task execution performance.

CN120386587AActive Publication Date: 2025-07-29LANGCHAO ELECTRONIC INFORMATION IND CO LTD

Patent Information

Application Number
CN202510874361.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-27
Publication Date
2025-07-29
Estimated Expiration
2045-06-27

AI Technical Summary

Technical Problem

eBPF Map cannot be nested in multiple layers, resulting in the inability to meet the storage requirements of complex rulesets and the inability to implement effective access control in container scenarios.

Method used

A multi-layer nested eBPF Map structure is designed to decompose complex task control rules into multiple levels, each level corresponds to an eBPF Map, and the overall eBPF Map is formed through inter-layer mapping relationships, and constructed and sent to the kernel state in the user state for layer-by-layer control.

Benefits of technology

While maintaining eBPF efficiency, it provides the ability to build complex rulesets, reduces the number of invalid rules traversals, improves kernel task execution performance, and realizes access control in container scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120386587A_ABST
    Figure CN120386587A_ABST
Patent Text Reader

Abstract

The invention discloses a kernel task execution method, electronic equipment, a readable storage medium and a program product, and relates to the technical field of computers. The method comprises the following steps: creating at least three layers of nested mapping table structures; the first layer of mapping table stores a task identifier and a nesting relationship between the task identifier and a lower layer, and the other layers of mapping tables store control rules and corresponding nesting relationships. Target task control rule information extracted from the resource strategy file is divided into task execution control rules with the corresponding number, the task execution control rules are correspondingly stored in mapping tables of corresponding layers, and the task execution control rules serve as task execution control rule storage tables to be issued to a kernel mode; and the kernel mode performs layer-by-layer control on kernel task operation according to the task execution control rule storage table. According to the method and the device, the problem that the container scene cannot store the service requirement of the access control rule due to the fact that the eBPF Map cannot be nested in multiple layers in the related technology can be solved, and container access control can be realized in the container scene.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technologies, and more particularly to a method for executing kernel tasks, an electronic device, a computer-readable storage medium, and a computer program product. Background Art

[0002] eBPF (Extended Berkeley Packet Filter) allows users to run custom programs in the kernel and can efficiently process data with minimal impact on system performance. The eBPF Map is a data structure used for data sharing between eBPF programs and between eBPF programs and user-space application programs.

[0003] The eBPF Map in related technologies cannot match complex rules and cannot implement access control in container scenarios based on eBPF technology. Summary of the Invention

[0004] The present invention provides a method for executing kernel tasks, an electronic device, a computer-readable storage medium, and a computer program product. By using a multi-layer nested eBPF Map to match a complex rule set, it meets the business requirements of storing complex task control rules, can implement data processing in complex business scenarios, and realizes access control in container scenarios based on eBPF technology.

[0005] To solve the above technical problems, the present invention provides the following technical solutions: On the one hand, the present invention provides a method for executing kernel tasks, including: Creating at least a three-layer nested mapping table structure for the extended Berkeley packet filter in the user state environment; the first-layer mapping table stores task identifiers and their mapping relationships with the next-layer mapping table, and the other layers of mapping tables store corresponding task control rules and their mapping relationships with other layers; extracting target task control rule information from a resource policy file, dividing the target task control rule information into multiple task execution control rules, and storing them in the corresponding layers of mapping tables accordingly as a task execution control rule storage table; and sending the task execution control rule storage table to the kernel state so that the kernel state controls kernel task operations layer by layer according to the task execution control rule storage table.

[0006] The present invention also provides an electronic device, including a memory and a processor. When the processor executes a computer program stored in the memory, it implements the steps of any one of the above methods for executing kernel tasks.

[0007] The present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of any one of the above-mentioned kernel task execution methods are implemented.

[0008] Finally, the present invention also provides a computer program product, including a computer program / instructions. When the computer program / instructions are executed by a processor, the steps of any one of the above-mentioned kernel task execution methods are implemented.

[0009] The advantages of the technical solution provided by the present invention are as follows: By designing a multi-layer nested eBPF Map structure, there is a mapping relationship between different layers of eBPF Maps. The complex task control rules corresponding to the kernel tasks that need to control the execution process are decomposed into multiple levels, each level corresponding to an eBPF Map. These Maps are associated through the inter-layer mapping relationship to form an overall eBPF Map. While maintaining the high efficiency of eBPF, it can provide the ability to construct and process complex rule sets, thereby meeting the higher requirements for data processing in fields such as cloud computing, edge computing, and security. It is sent to the kernel state, and the kernel state filters the kernel tasks layer by layer through the task execution control rule storage table, which can reduce the number of traversals of invalid rules and improve the overall kernel task execution performance. Thus, it solves the business requirement that the eBPF Map in the eBPF program cannot be multi-layer nested in the container scenario, making it impossible to store access control rules. It can realize data processing in complex kernel business scenarios and can implement container access control based on eBPF technology in the container scenario.

[0010] In addition, the present invention also provides corresponding implementation electronic devices, computer-readable storage media, and computer program products for the kernel task execution method, further making the method more practical. The electronic devices, computer-readable storage media, and computer program products have corresponding advantages. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] In order to more clearly illustrate the technical solutions of the present invention or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0012] Figure 1 It is a schematic diagram of the hardware composition framework applicable to the kernel task execution method provided by the present invention; Figure 2 It is a schematic flowchart of a kernel task execution method provided by the present invention; Figure 3Schematic diagram of the multi-layer nested mapping table structure provided by the present invention in an exemplary application scenario; Figure 4 Schematic diagram of a mapping table structure update process provided by the present invention; Figure 5 Schematic diagram of another mapping table structure update process provided by the present invention; Figure 6 Structure framework diagram of the kernel task execution device provided by the present invention under an exemplary implementation manner; Figure 7 Structural diagram of an exemplary implementation manner of the electronic device provided by the present invention. Detailed implementation manners

[0013] In order to enable those skilled in the art to better understand the technical solutions of the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific implementation manners. Among them, the terms "first", "second", "third", "fourth", etc. in the specification and the above drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. The term "exemplary" means "serving as an example, embodiment, or illustration". Any embodiment described herein as "exemplary" is not necessarily to be construed as superior to or better than other embodiments.

[0014] With the development of cloud computing, edge computing, information security, and artificial intelligence technologies, electronic data processing and analysis have become increasingly complex. To address these challenges, eBPF allows users to run custom code in the kernel. Programs running in the kernel mode can perform real-time, efficient network and system monitoring, security auditing, performance analysis, etc. on the system, such as processing network packets, tracking system calls, and monitoring kernel events. It is widely used because it has powerful data processing capabilities while having a minimal impact on system performance and being tightly integrated with the Linux (operating system name) kernel.

[0015] When sharing data between eBPF programs and between eBPF programs and user-space applications, the eBPF Map data structure is adopted. The eBPF Map is oriented towards simple key-value pair storage. Although it provides an efficient data storage and retrieval mechanism and supports multiple data types and multiple operations, such as hash tables, arrays, stacks, etc. Since eBPF programs need to pass the static checks of the kernel Verifier to ensure there are no risks such as memory out-of-bounds and circular references. Directly nesting hash tables may cause the verifier to be unable to track complex memory relationships, resulting in a security rejection. In addition, eBPF restricts that only eBPF Maps of the HASH_OF_Map (hash map) type can achieve two-layer nesting, and currently does not support multi-layer nesting. For the above technical reasons for the eBPF nesting restrictions, it cannot be as flexible as in high-level languages such as Java (programming language name) / Go (Golang, programming language name) to flexibly nest and combine collections to meet business requirements, such as the storage business of matching rules. This leads to extremely limited expressive power and flexibility for complex rule sets involving multiple levels of logical relationships and cannot meet the requirements for building complex rule sets. For some complex business scenarios, in order to enable the kernel to implement security scenarios such as access control and network traffic control through the matching rule set, it has to be restricted by the limitations of the eBPF program itself and sacrifice functionality or performance to ensure the normal operation of the program.

[0016] To implement the matching of complex rule sets based on eBPF Map to execute complex business scenarios, related technologies establish BPF hash tables in the four-level architecture of international top-level nodes, secondary nodes, enterprise nodes, and product nodes respectively, for storing the industrial Internet identification resolution address caches at the corresponding levels, filtering the industrial Internet identifications to be resolved hierarchically, forming corresponding node data, and concurrently comparing the data at each level with the BPF hash table at the corresponding level to query whether there is a hit result. If a hit result exists, the resolution result is directly returned. If no hit result is found, an identification resolution query is initiated to the upper-level resolution node. The returned resolution result is filled in and supplemented into the hash table. This method constructs a BPF table through four types of business nodes that match the logical architecture. Since these four nodes just match its logical architecture, the four nodes are distinguished through a specific expression method of the IP (Internet Protocol Address) in the Key value of the Map, achieving the purpose of logical association. However, the eBPF Map of this method is 4 independent eBPF Maps. Through the characteristics of the business itself, a logical relationship is established, but 4-layer nesting is not achieved. It can only be applied to scenarios that are the same as or related to this type of business and cannot be extended to other business scenarios, lacking generality.

[0017] In view of this, the present invention designs a multi-layer nested eBPF Map structure, where there is a corresponding relationship between different layers of eBPF Maps. The complex task control rules corresponding to the kernel tasks that need to control the execution process are decomposed into multiple levels, with each level corresponding to an eBPF Map. An overall eBPF Map is formed through the inter-layer mapping relationship to meet the business requirements of storing complex control rules, enabling data processing in complex kernel business scenarios and realizing container access control based on eBPF technology in the container scenario. Combining with the specific application environment architecture or specific hardware architecture on which the execution of the kernel task execution method depends, the specific application environment architecture or specific hardware architecture is described herein. Next, in combination with Figure 1 Some possible application scenarios related to the technical solution of the present invention are introduced by way of example, which may include the following contents: In this embodiment, when the server needs to execute services such as control, detection, and monitoring by the kernel, the operating system of the server will switch between the kernel mode and the user mode during operation according to the task type and operation requirements, and use the eBPF Map as the data structure for interchanging data between the kernel mode and the user mode. The user mode creates at least a three-layer nested mapping table structure for the eBPF; the first-layer mapping table stores the task identifier and its mapping relationship with the next-layer mapping table, and the other-layer mapping tables store the corresponding task control rules and the mapping relationships with other layers. The user mode extracts the target task control rule information from the resource policy file, divides the target task control rule information according to the number of layers of the mapping table structure, and stores it correspondingly in the mapping tables of the corresponding layers to obtain the task execution control rule storage table. The user mode sends the task execution control rule storage table to the kernel mode, and the kernel mode controls the kernel task operations layer by layer according to the task execution control rule storage table. The server expands the application scope of the eBPF technology by introducing a multi-layer eBPF Map structure, improves its ability and flexibility in processing complex rule set services, and can provide rule storage management support for the container access control function.

[0018] Schematically, assuming the server includes multiple containers, the process of implementing container access control based on the kernel-level three-layer eBPF Map structure is as follows: Create the first layer of Map, initialize the third layer of Map array. When updating the container access control rules, insert the container identifier into the Key of the first layer of Map, and at the same time dynamically generate the second layer of Map. Insert the corresponding rule data into the Key of the second layer of Map, and at the same time apply for the usage permission of the third layer of Map, and insert the rule data into the third layer of Map. When it is necessary to delete the container access control rules, the Key of the first layer of Map is deleted, and the second layer of Map and the third layer of Map with nested relationships are released synchronously. When the Key of the second layer of Map is deleted, the third layer of Map with nested relationships is released synchronously. When the third layer of Map is insufficient, dynamically create and add it to the Map array for waiting to be used. When the available quantity of the third layer of Map is sufficient, release the redundant Map. When performing rule matching on process data in the kernel state, match layer by layer according to the levels of the eBPF Map, and if any layer fails to match, no further matching will be continued. After all match successfully, determine the next action according to the content of the Value of the third layer of Map, such as interception, passing, etc. By constructing a three-layer Map structure used in the eBPF program to store the container control access rule set, the requirements for rule storage in complex business scenarios such as container access control are met, the business scenarios of the eBPF program are extended. Further, by dynamically creating and destroying the second layer of Map, the overall performance is improved; by dynamically managing the third layer of Map array, both the business requirements are met and not too much system resources are occupied.

[0019] It should be noted that the above application scenarios are only shown for the convenience of understanding the ideas and principles of the present invention, and the embodiments of the present invention are not limited in this regard. On the contrary, the embodiments of the present invention can be applied to any applicable scenario. After introducing the technical solutions of the present invention, the various non-limiting embodiments of the present invention will be described in detail below with reference to the accompanying drawings and specific implementation manners. First, please refer to Figure 2 , Figure 2 which is a schematic flowchart of a kernel task execution method provided in this embodiment. This embodiment may include the following content: S201: Create at least a three-layer nested mapping table structure for the extended Berkeley packet filter in the user state environment.

[0020] Among them, the eBPF Map is a data structure in the Linux kernel, usually used in scenarios where data is shared between user space and kernel space to achieve efficient data exchange between user space programs and kernel modules. Currently, the eBPF Map supports at most a two-layer mapping table structure, which cannot meet the storage requirements of complex rules. In this step, a multi-layer nested eBPF Map structure, such as M layers, that is, Layer1→Layer2→Layer3→……LayerM, will be constructed to solve the limitation of traditional single-layer or double-layer Maps in implementing complex business requirements. The first-layer mapping table stores task identifiers and their mapping relationships with the next-layer mapping table through its key-value pairs, and the mapping tables of other layers store corresponding task control rules and their mapping relationships with other layers through their key-value pairs. Exemplarily, one Key of each layer of Map can correspond to an independent Map of the next layer. Passing layer by layer in this way, a complex rule tree can be constructed. Each layer of Map can store a filtering condition. By storing eBPF Map rules from three layers to N layers, the needs of various business scenarios can be met. Of course, increasing the number of layers will increase performance loss, and those skilled in the art can determine the appropriate number of layers according to the actual situation. For example, the eBPF Map structure includes three layers of Maps, which can support filtering in 3 dimensions. Then the rules in the 3-dimensional space are related. In this way, fast matching can be achieved. With a three-layer eBPF Map structure, it can implement at least 1-N-N² rule association relationships. One record in the first-layer Map corresponds to a Map in the second layer. When the second-layer Map structure contains N Maps, one record in the first layer corresponds to N records in the second layer. Similarly, one record in the second layer corresponds to a Map in the third layer. If there are N records in the second layer, then there are N*N records in the third layer. In this way, the rule association relationship by layer is: one task control rule in the first layer→N task control rules in the second layer→N*N task control rules in the third layer, so that the eBPF program can meet the storage requirements of access control rules in the container scenario. Further, to improve the overall system performance, when constructing a multi-layer eBPF Map structure, the second-layer Map is only created when it is used and can be destroyed when it is not used. In addition, each layer of Map entries in the eBPF Map structure can be dynamically expanded according to actual needs to adapt to the rule management requirements in scenarios such as a large number of Pods (containers), containers, and services in the cloud-native environment.

[0021] S202: Extract the target task control rule information from the resource policy file, divide the target task control rule information into multiple task execution control rules, and store them in the corresponding layer of the mapping table as the task execution control rule storage table.

[0022] Among them, the resource policy file is a configuration file that defines various resources, such as Pods, Deployments (deployment resources), Services (service resources), etc. The configuration content includes resource limits, restart policies, update policies, rules, behaviors, or parameter settings. The target task can be any task running in the kernel mode that requires rule matching, such as some services in security fields like access control, such as container access control tasks, container-based network access control tasks, kernel monitoring tasks, kernel control execution tasks, kernel detection tasks, network traffic control tasks, etc. The target task control rule information is the restrictions or rules that the target task needs to abide by during its execution in the kernel mode. The target task control rule information can be decomposed into multiple task execution control rules that can be matched. The number of layers of the mapping table structure is the same as the total number of task execution control rules. When the mapping table structure is constructed first, the target task control rule information is divided into multiple task execution control rules. If the mapping table structure is dynamically constructed during the process of filling the task execution control rules, the total number of task execution control rules can be determined according to the resource and performance conditions, and then divided according to this number, and the number of layers of the mapping table structure is continuously increased according to the total number of task execution control rules. Each layer of the multi-layer nested eBPF Map structure in the previous step is a Map, and the quantity can be flexibly determined according to the actual business, system resources, and system performance. Each layer of Map entries includes the key-value pairs of all Maps in that layer. The Map stores content using key-value pairs. The Key and Value in the key-value pair can store numbers, strings, or even a complex object or structure, which can be determined according to the target task type. Taking container access control as an example: One of the first-layer Maps in the first-layer Map structure has a Key: container identifier, which is used to identify a container; the Value points to a Map in the second-layer Map structure. The Key of the second-layer Map is the object path, that is, the path of the object being accessed or operated on, such as / tmp / syslog.log); the Value points to a Map in the third-layer Map structure. The third-layer Map: Key: subject path, that is, the path of the subject process performing the operation, such as / usr / bin / cat, and the Value is the access permission, such as read, write, execute, delete, rename.

[0023] To store the complex rule set of the target task in the eBPF Map structure, the complex rule set extracted from the resource policy file can be decomposed into multiple levels. Each level corresponds to one of the Map structures in one layer of the eBPF Map structure, and these Maps are associated through program logic to form an organic whole. Taking the three-layer eBPF Map structure as an example, when parsing the control rule information of the target task, when inserting a Key into the first-layer Map (i.e., one of the matching conditions), a second-layer Map is dynamically created and used as the Value of the first-layer Map. After the first-layer rule filtering is completed, the second-layer rule matching can be performed in the second-layer Map: when inserting a Key data into the second-layer Map, an index of the third-layer Map array is applied as the Value, and this Map is used as the corresponding third-layer Map to record the third-layer matching rules. The idea of using the storage of three-layer container access rules can be extended to any eBPF program, and an N-layer eBPF Map structure is used to store a complex rule set that can be decomposed into N-layer matching rules.

[0024] S203: Send the task execution control rule storage table to the kernel state so that the kernel state can control the kernel task operations layer by layer according to the task execution control rule storage table.

[0025] The above steps S201 and S202 are implemented in the user state. After the control rule information of the target task corresponding to the target task is split and stored in the N-layer eBPF Map structure in the user state, the N-layer eBPF Map structure is sent to the kernel state. The kernel state monitors the task process information. Every time a task process information is captured, the task control rule corresponding to the task process information is obtained and matched layer by layer with the task control rules stored in each layer of the Map in the task execution control rule storage table. If any layer fails to match, the matching will not continue, that is, as long as one layer fails to match, the matching will be aborted in the kernel. By filtering layer by layer, the number of traversals of invalid rules can be reduced.

[0026] In the technical solution provided in this embodiment, by designing a multi-layer nested eBPF Map structure, there is a mapping relationship between different layers of eBPF Maps, and the complex task control rules corresponding to the kernel tasks that need to control the execution process are decomposed into multiple levels, each level corresponding to an eBPF Map. These Maps are associated through the inter-layer mapping relationship to form an overall eBPF Map, which can, while maintaining the high efficiency of eBPF, provide the ability to construct and process complex rule sets, so as to meet the higher requirements for data processing in fields such as cloud computing, edge computing, and security. It is sent to the kernel state, and the kernel state filters the kernel tasks layer by layer through the task execution control rule storage table, which can reduce the number of traversals of invalid rules and improve the overall kernel task execution performance, thereby solving the business requirement that access control rules cannot be stored in the container scenario due to the inability to multi-layer nest eBPF Maps in the eBPF program, enabling data processing in complex kernel business scenarios, and enabling container access control based on eBPF technology in the container scenario.

[0027] In the above embodiment, there is no limitation on how to store the target task control rule information corresponding to the multi-layer nested eBPF Map structure. Based on the above embodiment, the present invention also provides an exemplary implementation method, which may include the following content: Divide the target container access control rule set into a target container identifier, a second-layer filtering rule for screening the executed object, and a third-layer filtering rule for screening the execution subject; the third-layer filtering rule at least includes the subject location information and the subject permission information; insert the target container identifier into the key of the first-layer mapping table to generate a first sub-mapping table, and use the first sub-mapping table as the value of the first-layer mapping table. The first sub-mapping table is the target second-layer mapping table in the second-layer mapping table structure to construct the corresponding nested relationship between the first-layer mapping table structure and the second-layer mapping table structure; insert the second-layer filtering rule into the key of the target second-layer mapping table to generate a second sub-mapping table, and use the second sub-mapping table as the value of the target second-layer mapping table. The second sub-mapping table is the target third-layer mapping table in the third-layer mapping table structure to construct the corresponding nested relationship between the second-layer mapping table structure and the third-layer mapping table structure; insert the third-layer filtering rule into the key-value pairs of the target third-layer mapping table respectively, such as inserting the third-layer filtering rule into the key of the target third-layer mapping table, and the value of the target third-layer mapping table is the subject permission information, and the subject permission information such as the subject location information and the subject permission, such as read permission, write permission, etc.

[0028] In this embodiment, the target task is a container access control task, and the target task control rule information is the target container access control rule set. Correspondingly, the task identifier is the container identifier. In the container scenario, a host may include multiple containers. For the convenience of storing and matching rules in the container, such asFigure 3 As shown in Figure 3 , a 3-layer eBPF Map can be constructed. The first-layer Map filters containers, with its Key being the container identifier. The second-layer Map filters the object paths, and the third-layer Map filters the subject paths. The target task is a network access control task under the container. The first-layer Map can also filter containers, with its Key being the container identifier. The second-layer Map filters IP addresses and can store source IP information. The third-layer Map can filter access permissions, such as storing the accessed port information and operation permissions. Exemplarily, the target container access control rule set can be divided into the target container identifier, the object path of the accessed or operated object, the subject object path of the operating subject process, and the subject operation permissions; the target container identifier is used as the key of the first-layer mapping table, and the value of the first-layer mapping table is the corresponding relationship with the target second-layer mapping table in the second-layer mapping table structure; the object path is used as the key of the target second-layer mapping table, and the value of the target second-layer mapping table is the corresponding relationship with the target third-layer mapping table in the third-layer mapping table structure; the subject object path is used as the key of the target third-layer mapping table, and the value of the target third-layer mapping table is the subject operation permissions.

[0029] Among them, for the access control task based on containers, the resource configuration file can be a yaml (a format for expressing data serialization) file, and the corresponding target task control rule information can be obtained by parsing the yaml file. For example, an exemplary yaml file is as follows: Name: access-control-container-policy; Module: access_control; Scope: container; Action: Monitor (intercept, monitor); -selector: intersection, all conditions need to be met to be considered a match; labelsSelector (labels used to match containers): -ksec / container.name (label of container name): lb*, a, b; -namespace_Name (namespace); -k: v (form of label); Container matching conditions (which containers the following policies apply to based on this matching file); fileProtectList (file protection list): -path file protection; processProtectList (process protection list): -path process protection; processBlackList (process blacklist): -path process blacklist; -selector.

[0030] Among them, for the container name ksec, its Value is lb*, a, b, which means it is separated by commas and represents three values: lb*, a, b. a and b are exact matches, that is, the container name must be equal to a or b, and lb* is a wildcard match, as long as the container name starts with lb, it can be matched, such as lb123, lbabc, lbdf1d. Parse the policies in the yaml file and match them with the current container list. If the match is successful, add the corresponding rules for the container. The rule content is the content of file and process access. For example, container A matches the policy. Then it is necessary to parse the yaml into the records in the Map: The first layer of Map: Key = the identifier of container A (pid = xx, mnt = xxx), Value = reference to the second layer of Map; The second layer of Map: Key = the object path (such as the file path to be protected: / opt / mysql), Value is the identifier of the third layer of Map; The third layer of Map: Key = the subject path, Value is the operation permission.

[0031] Among them, the processes of different users are isolated by the pid (a name of a namespace), and the same pid can exist in different namespaces. Among them, xx represents the corresponding content. Placing a process in a specific directory for execution, the mnt (a name of a namespace) namespace allows the file structures seen by processes in different namespaces to be different. Among them, xxx represents the corresponding content.

[0032] For the container access control task, when the kernel mode receives the access control rule set, the process of layer-by-layer matching can be as follows: when obtaining the container access process information, obtain the container information and access information to which it belongs from the container access process information; when the container identifier of the container information matches the key of the first-layer mapping table of the container access control rule storage table, locate the target second-layer mapping table according to the value of the first-layer mapping table; when the object information to be executed in the access information matches the key of the target second-layer mapping table, locate the target third-layer mapping table according to the value of the target second-layer mapping table; when the subject information in the access information matches the key-value pair of the target third-layer mapping table, allow the container access process information to be executed in the kernel mode. Among them, when the container identifier of the container information does not match the target container identifier of the first-layer mapping table of the container access control rule storage table, allow the container access process information to be executed; when the object path in the access information does not match the object path of the target second-layer mapping table, or the subject path and access permission in the access information do not match the key-value pair of the target third-layer mapping table, do not allow the container access process information to access the target container.

[0033] In this embodiment, the target second-layer mapping table is located in the second-layer Map structure, which is a mapping table nested by the first-layer mapping table that matches the key. The target third-layer mapping table is located in the third-layer Map structure, which is a mapping table nested by the target second-layer mapping table. When a certain access action occurs, the kernel can capture the corresponding process information, and obtain the corresponding container information, subject path (that is, the subject process path of the operating object), object path (that is, the file or process path to be accessed and operated), and permission (such as read, write, execute, rename, delete) from the captured process information. The layer-by-layer matching process is as follows: First layer Map: Match the Key of this layer according to the container identifier of the captured process. If not, directly allow execution. If the match is successful, this container needs to follow the access control rules and perform the second layer Map match. Second layer Map: Match the object path of the captured process with the Key of this layer. If not, abort the match. If the match is successful, it proves that there are rules for the file or process with this object path of this container, and perform the third layer Map match. Third layer Map: Match the subject path of the captured process with the Key of this layer, and also match whether the operation permission is the same as the Value of this layer, that is, compare whether the current operation matches the restricted access permission. If not, intercept; otherwise, let it pass.

[0034] As can be seen from the above, this embodiment stores the container access control rule set through a three-layer Map structure, solves the implementation of complex business requirements restricted by traditional single-layer or double-layer Maps, can implement container access control based on the eBPF technology in the container scenario, reduces the number of invalid rule traversals through a layer-by-layer filtering mechanism, and improves the overall performance.

[0035] The present invention also provides another implementation process for storing the target task control rule information corresponding to a multi-layer nested eBPF Map structure. Parallel to the above method, it may include the following content: Divide the network access control rule set into source IP address, destination IP address, source port, destination port, and protocol; insert the source IP address as the key of the first-layer mapping table, and dynamically generate an innerMap (sub-mapping table) as the value of the first-layer mapping table, where the innerMap is the target second-layer mapping table; use the destination IP address as the key of the target second-layer mapping table, and apply for a third-layer mapping table array from a pre-constructed mapping table array, and use the index of the third-layer mapping table array as the value of the target second-layer mapping table; insert the source port into the key of the target third-layer mapping table, and apply for a fourth-layer mapping table array from the mapping table array again, and use the index of the fourth-layer mapping table array as the value of the target third-layer mapping table; insert the destination port into the key of the target fourth-layer mapping table, and apply for a fifth-layer mapping table array from the mapping table array again, and use the index of the fifth-layer mapping table array as the value of the target fourth-layer mapping table; insert the protocol type into the key of the target fifth-layer mapping table, and insert the access permission into the value of the fifth-layer mapping table.

[0036] In this embodiment, the target task control rule information is the network access control rule set, the task identifier is the source IP address, the kernel state obtains the network access process information, sequentially obtains the source IP address, destination IP address, source port, destination port, and protocol to which it belongs from the network process information, and sequentially matches them with each layer of the network access control rule set. After successful matching, the network access process information is allowed to execute.

[0037] As can be seen from the above, this embodiment stores the network access control rule set through a five-layer Map structure, solves the limitation of traditional single-layer or double-layer Maps in implementing complex service requirements, can implement network access control based on the eBPF technology in the container scenario, prevent virus intrusion, effectively improve the system security, reduce the number of invalid rule traversals through a layer-by-layer filtering mechanism, and improve the overall performance.

[0038] The above embodiments do not make any limitations on how to create a multi-layer nested eBPF Map structure. Based on the above embodiments, the present invention also gives an exemplary implementation method, which may include the following content: Initialize the first-layer mapping table structure of the extended Berkeley Packet Filter's mapping table as a nested hash table, and construct an array of mapping tables of the nested hash table type; after filling the content of the keys of the first-layer mapping table in the first-layer mapping table structure, automatically create a sub-mapping table located in the second-layer mapping table structure for the first-layer mapping table, and at the same time, apply for usage permission for the lower-level nested mapping table of the sub-mapping table from the mapping table array; fill the array subscript corresponding to the lower-level nested mapping table in the mapping table array as an index into the value of the sub-mapping table.

[0039] In this embodiment, the sub-mapping table is the value of the first-layer mapping table, and the lower-level nested mapping table of the sub-mapping table is located in the third-layer mapping table structure. In user space, when the program starts, the first-layer Map can be initialized as Hash OF Map (BPF_Map_TYPE_HASH_OF_MapS, nested hash table), and an innerMap is specified as the Value for the first-layer Map, that is, it points to another eBPF Map, but nesting is restricted. Hash OF Map is a special Map type in eBPF, belonging to the Map-in-Map structure, which natively supports a 2-layer Map, does not allow nesting, and permits storing references to other Maps in the key-value pairs of the parent Map. innerMap is the nested structure in BPF_Map_TYPE_HASH_OF_MapS and is the "value" stored in the outer hash table, that is, another eBPF Map. Using this Value, another eBPF Map can be operated on, such as reading or editing the content inside. Inner Map is a file descriptor fd pointing to another eBPF Map in user space and is a pointer to the eBPF Map in kernel space.

[0040] Among them, the mapping table array is an array of the Hash Of Map type. The mapping table array can include multiple nested hash tables. That is, during the initialization process, some Maps can be stored in it. For example, 512 Hash Of Maps can be created by default. When building Maps for the third layer and below, they can be directly retrieved from this array. Each Hash Of Map has an array subscript that can locate its position in the mapping table array. This array subscript can be used as the Index of this Hash Of Map. That is, when retrieving, the array subscript Index is used. When matching rules in the kernel mode, first match through the Key of the first-layer Map. If the match is successful, the second-layer Map is obtained. Then match through the Key of the second-layer Map. If the match is successful, the array subscript of the third-layer Map is obtained. The third-layer Map is obtained from the array through the subscript. Then perform rule matching again through the Key of the third-layer Map. If the match is successful, the value saved in the Value is read. This value may represent permissions or further actions, etc. After the kernel obtains this value, corresponding processing can be performed.

[0041] In this embodiment, the first-layer Map and the second-layer Map of the multi-layer nested eBPF Map structure are implemented using Hash Of Map. The subsequent levels can be completed by combining Hash Of Map and a dynamic mapping table array. After that, for each additional layer, an array is applied from the mapping table array as the Map of the currently added layer. The Value of the previous layer of the newly added layer records the Index of the next-layer dynamic array. For example, when the target task control rule information is divided into four layers: container - subject - object - user, and the corresponding mapping table structure is also four layers, then 2 Maps in the mapping table array are used to store the content after the third layer. When the target task control rule information is divided into five layers: source IP - destination IP - source port - destination port - protocol, and the corresponding mapping table structure is also five layers, then 3 Maps in the mapping table array are used to store the content after the third layer.

[0042] As can be seen from the above, in this embodiment, the mapping table structure is constructed in a dynamic manner, and the mapping table array is used as the third-layer Map, which can simply and conveniently achieve dynamic expansion of each layer of Map entries, enabling the eBPF program to meet the storage requirements of various complex matching rules and having better practicability.

[0043] Based on the above embodiment, the present invention also provides an implementation method for dynamically updating the mapping table array, which may include the following content: When the total number of nested hash tables in the mapping table array is less than the first preset number of tables, a request for expanding the mapping table array is generated; when the current total number of nested hash tables in the mapping table array is greater than or equal to the first preset number of tables, a target nested hash table is selected from the mapping table array as the lower-level nested mapping table, and the array subscript value of the target nested hash table in the mapping table array is fed back to the sub-mapping table. When the total number of nested hash tables in the mapping table array is greater than or equal to the second preset number of tables, a request for shrinking the mapping table array is generated; when the current total number of nested hash tables in the mapping table array is less than the second preset number of tables, a target nested hash table is selected from the mapping table array as the lower-level nested mapping table, and the array subscript value of the target nested hash table in the mapping table array is fed back to the sub-mapping table.

[0044] Among them, the first preset number of tables and the second preset number of tables can be determined according to actual resources and performance. When applying for permission to use the Map for the third time, if the number of mapping tables included in the mapping table array is insufficient, dynamic expansion of the array size is supported, that is, expansion processing. If the number of mapping tables included in the mapping table array exceeds the initial number and the available quantity is sufficient, in order to save resource occupancy and improve performance, shrinking processing is also supported. The shrinking processing in this embodiment includes two methods. One method is to reset a new array size and shrink it to the new array size. Another method is to delete those Maps that exceed the initial number, such as the initialization default number.

[0045] As can be seen from the above, in this embodiment, by flexibly adjusting the number of mapping tables included in the mapping table array according to requirements, not only too many resources are not occupied, but also business requirements can be met and system performance can be guaranteed.

[0046] Based on the above embodiment, the present invention also provides an implementation method for adding and deleting operations on the mapping table structure, which may include the following content: For the rule deletion scenario: when a target key deletion request is detected, determine the target mapping table structure to which the target key corresponding to the target key deletion request belongs; when the target key is located in the first-layer target mapping table of the target mapping table structure, determine the target sub-mapping table created by the first-layer target mapping table, delete the target sub-mapping table, and clear the content and usage permission of the lower-level target mapping table nested in the target sub-mapping table; when the target key is located in the second-layer target mapping table of the target mapping table structure, clear the content and usage permission of the lower-level target mapping table nested in the second-layer target mapping table, and delete the target key of the second-layer target mapping table; when the target key is located in the third-layer target mapping table of the target mapping table structure, update the content of the third-layer target mapping table accordingly.

[0047] In this embodiment, when controlling rules for user-state deletion processing tasks, it starts querying from the first-layer Map to check if there is a task control rule to be deleted. For example Figure 4As shown, first query whether the Key of the first-layer Map needs to be deleted. For ease of description, it is defined as the target key. If it needs to be deleted, then the entire second-layer Map corresponding to it is deleted, that is, the target sub-map table. And when deleting the second-layer Map, check the third-layer Map used, clear the content of the third-layer Map, and release the usage permission. If the Key in the first-layer Map does not need to be deleted and there is a situation where the Key in the second-layer Map needs to be deleted, then similarly clear the content of the corresponding third-layer Map, and after releasing the usage permission, delete the Key in the second-layer Map. If only the content of the third Map is deleted, then only the third-layer Map needs to be updated.

[0048] For the scenario of rule addition: When a target key addition request is detected, determine the target map table structure to which the target key corresponding to the target key addition request belongs; when the target key is in the first-layer target map table of the target map table structure, automatically generate a target sub-map table for the first-layer target map table, and apply for the corresponding usage permission for the third target map table nested by the target sub-map table; when the target key is in the second-layer target map table of the target map table structure, apply for the corresponding usage permission for the third target map table nested by the second-layer target map table.

[0049] As Figure 5 shown, when there is an increase in the task control rule, if a Key is added to the first-layer Map, then a second-layer Map needs to be dynamically generated synchronously, such as dynamically creating an innerMap, and applying for the usage permission of the third-layer Map. If the third-layer Map is insufficient, if the Map is not enough, 50 Maps are dynamically applied for, then dynamic expansion processing is performed according to the method of the above embodiment and put into an array for the program to use. If the third-layer Map is sufficient, such as the available quantity is greater than 50 and the total number exceeds the initial 512 Maps, then the excess ones are deleted and the map table array is updated synchronously.

[0050] As can be seen from the above, this embodiment supports the addition and deletion of task rules, and timely clears the content and usage permission of the third-layer Map, which can not only improve the business application scope, enabling the eBPF program to meet the storage requirements of more business scenarios that need to match rules, but also improve the overall performance.

[0051] Based on the above embodiment, after the user state sends the task execution control rule set to the kernel state, the kernel state will generate log information during the task control process based on the task execution control rule set. The kernel state stores the log information in the task execution control rule storage table and returns it to the user state. When the log information of the task execution control rule storage table sent by the kernel state is received, the user state obtains the log printing configuration information; according to the log printing configuration information, the log information is printed in the user state, such as printing the log to a file, console, or https (Hypertext Transfer Protocol Secure) according to the configuration, which is convenient for tracing, troubleshooting, and maintenance.

[0052] It should be noted that there is no strict order in which the steps in the present invention are performed. As long as they conform to a logical order, the steps can be performed simultaneously or in a predetermined order. Figure 2 、 Figure 4 and Figure 5 This is just a schematic and does not mean that this is the only execution order.

[0053] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus the necessary general hardware platform, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method.

[0054] The present invention also provides a corresponding device for the kernel task execution method, which further makes the method more practical. Among them, the device can be described from the perspective of functional modules and hardware. The kernel task execution device provided by the present invention is introduced below. The device is used to implement the kernel task execution method provided by the present invention. In this embodiment, the kernel task execution device may include or be divided into one or more program modules. The one or more program modules are stored in a storage medium and executed by one or more processors to complete the kernel task execution method disclosed in Example 1. The program module referred to in this embodiment refers to a series of computer program instruction segments that can complete specific functions, which is more suitable for describing the execution process of the kernel task execution device in the storage medium than the program itself. The following description will specifically introduce the functions of each program module of this embodiment. The kernel task execution device described below and the kernel task execution method described above can be referenced to each other.

[0055] From the perspective of functional modules, see Figure 6 , Figure 6 This is a structural diagram of a kernel task execution device provided in this embodiment under a specific implementation mode. The device may include: The multi-layer nested mapping table structure construction module 601 is used to create a mapping table structure with at least three layers of nesting for the extended Berkeley packet filter in the user state environment; the first-layer mapping table stores task identifiers and their mapping relationships with the next-layer mapping table, and the mapping tables of other layers store corresponding task control rules and mapping relationships with other layers.

[0056] The multi-layer nested mapping table structure generation module 602 is used to extract target task control rule information from the resource policy file, divide the target task control rule information into multiple task execution control rules, and store them correspondingly in the mapping tables of the corresponding layers as the task execution control rule storage tables.

[0057] The task hierarchical control module 603 is used to send the task execution control rule storage table to the kernel state, so that the kernel state controls the kernel task operations layer by layer according to the task execution control rule storage table.

[0058] Exemplarily, in some embodiments of this embodiment, the above multi-layer nested mapping table structure generation module 602 can also be used to: divide the target container access control rule set into a target container identifier, a second-layer filtering rule for screening the executed object, and a third-layer filtering rule for screening the execution subject; the third-layer filtering rule at least includes subject location information and subject permission information; insert the target container identifier into the key of the first-layer mapping table to generate a first sub-mapping table, and use the first sub-mapping table as the value of the first-layer mapping table. The first sub-mapping table is the target second-layer mapping table in the second-layer mapping table structure to construct the corresponding nesting relationship between the first-layer mapping table structure and the second-layer mapping table structure; insert the second-layer filtering rule into the key of the target second-layer mapping table to generate a second sub-mapping table, and use the second sub-mapping table as the value of the target second-layer mapping table. The second sub-mapping table is the target third-layer mapping table in the third-layer mapping table structure to construct the corresponding nesting relationship between the second-layer mapping table structure and the third-layer mapping table structure; insert the third-layer filtering rule into the key-value pairs of the target third-layer mapping table respectively; where the target task control rule information is the target container access control rule set, and the task identifier is the container identifier.

[0059] As an exemplary implementation of the above embodiment, the above task hierarchical control module 603 may further be configured to: when obtaining container access process information, obtain the container information and access information to which the container access process information belongs; when the container identifier in the container information matches the key of the first-layer mapping table in the container access control rule storage table, locate the target second-layer mapping table according to the value of the first-layer mapping table; when the executed object information in the access information matches the key of the target second-layer mapping table, locate the target third-layer mapping table according to the value of the target second-layer mapping table; when the subject information in the access information matches the key-value pair of the target third-layer mapping table, allow the container access process information to be executed in the kernel state.

[0060] Exemplarily, in some other embodiments of this embodiment, the above multi-layer nested mapping table structure generation module 602 may further be configured to: the target task control rule information is the target container access control rule set, and the task identifier is the container identifier, and divide the target container access control rule set into a target container identifier, an object path of an object to be accessed or operated, a subject path of a subject process of an operation, and a subject operation permission; use the target container identifier as the key of the first-layer mapping table, and the value of the first-layer mapping table is the corresponding relationship with the target second-layer mapping table in the second-layer mapping table structure; use the object path as the key of the target second-layer mapping table, and the value of the target second-layer mapping table is the corresponding relationship with the target third-layer mapping table in the third-layer mapping table structure; use the subject path as the key of the target third-layer mapping table, and the value of the target third-layer mapping table is the subject operation permission.

[0061] As an exemplary implementation of the above embodiment, the above task hierarchical control module 603 may further be configured to: when obtaining container access process information, obtain the container information and access information to which the container access process information belongs; match the container identifier in the container information with the target container identifier in the first-layer mapping table of the container access control rule storage table; when the container identifier in the container information is consistent with the target container identifier, locate the target second-layer mapping table according to the value of the first-layer mapping table; match the object path in the access information with the key of the target second-layer mapping table; when the object path in the access information is consistent with the object path of the target second-layer mapping table, locate the target third-layer mapping table according to the value of the target second-layer mapping table; match the subject path and access permission in the access information with the key-value pair of the target third-layer mapping table respectively, and after successful matching, allow the container access process information to be executed.

[0062] As another exemplary implementation of the above embodiment, the above task hierarchical control module 603 may further be configured to: if the container identifier in the container information does not match the target container identifier in the first-layer mapping table of the container access control rule storage table, allow the container access process information to execute; if the object object path in the access information does not match the object object path in the target second-layer mapping table, or the subject object path and access permission in the access information do not match the key-value pair in the target third-layer mapping table, do not allow the container access process information to access the target container.

[0063] Exemplarily, in some other embodiments of this embodiment, the above device may further include a deletion module, which is configured to: when detecting a target key deletion request, determine the target mapping table structure to which the target key corresponding to the target key deletion request belongs; when the target key is located in the first-layer target mapping table of the target mapping table structure, determine the target sub-mapping table created by the first-layer target mapping table, delete the target sub-mapping table, and clear the content and usage permissions of the lower-layer target mapping table nested in the target sub-mapping table; when the target key is located in the second-layer target mapping table of the target mapping table structure, clear the content and usage permissions of the lower-layer target mapping table nested in the second-layer target mapping table, and delete the target key of the second-layer target mapping table; when the target key is located in the third-layer target mapping table of the target mapping table structure, correspondingly update the content of the third-layer target mapping table.

[0064] Exemplarily, in some other embodiments of this embodiment, the above device may further include an addition module, which is configured to: when detecting a target key addition request, determine the target mapping table structure to which the target key corresponding to the target key addition request belongs; when the target key is located in the first-layer target mapping table of the target mapping table structure, automatically generate a target sub-mapping table for the first-layer target mapping table, and apply for corresponding usage permissions for the third target mapping table nested in the target sub-mapping table; when the target key is located in the second-layer target mapping table of the target mapping table structure, apply for corresponding usage permissions for the third target mapping table nested in the second-layer target mapping table.

[0065] Exemplarily, in some other embodiments of this embodiment, the above device may further include a log printing module, which is configured to: when receiving the log information of the task execution control rule storage table sent in the kernel state, obtain the log printing configuration information in the user state; print the log information in the user state according to the log printing configuration information.

[0066] Exemplarily, in some other embodiments of this embodiment, the above-mentioned multi-layer nested mapping table structure construction module 601 can also be used to: initialize the first-layer mapping table structure of the mapping table of the extended Berkeley packet filter as a nested hash table, and construct an array of mapping tables of the nested hash table type; the array of mapping tables includes multiple nested hash tables; after the key filling content of the first-layer mapping table in the first-layer mapping table structure, automatically create a sub-mapping table for the first-layer mapping table in the second-layer mapping table structure, and at the same time, apply for usage permission from the array of mapping tables for the lower-level nested mapping table of the sub-mapping table; use the array subscript corresponding to the lower-level nested mapping table in the array of mapping tables as an index and fill it into the value of the sub-mapping table; wherein, the sub-mapping table is the value of the first-layer mapping table, and the lower-level nested mapping table of the sub-mapping table is located in the third-layer mapping table structure.

[0067] As an exemplary implementation manner of the above embodiment, the above-mentioned multi-layer nested mapping table structure construction module 601 can further be used to: when the total number of nested hash tables in the array of mapping tables is less than the first preset number of tables, generate a request for expanding the array of mapping tables; when the current total number of nested hash tables in the array of mapping tables is greater than or equal to the first preset number of tables, select a target nested hash table from the array of mapping tables as the lower-level nested mapping table, and feedback the array subscript value of the target nested hash table in the array of mapping tables to the sub-mapping table.

[0068] As another exemplary implementation manner of the above embodiment, the above-mentioned multi-layer nested mapping table structure construction module 601 can further be used to: when the total number of nested hash tables in the array of mapping tables is greater than or equal to the second preset number of tables, generate a request for shrinking the array of mapping tables; when the current total number of nested hash tables in the array of mapping tables is less than the second preset number of tables, select a target nested hash table from the array of mapping tables as the lower-level nested mapping table, and feedback the array subscript value of the target nested hash table in the array of mapping tables to the sub-mapping table.

[0069] The kernel task execution device mentioned above is described from the perspective of functional modules. Further, the present invention also provides an electronic device, which is described from the perspective of hardware. Figure 7 It is a schematic structural diagram of the electronic device provided by the embodiment of the present invention in an implementation manner. The electronic device includes a memory 701 and a processor 702. A computer program is stored in the memory 701, and the processor 702 is configured to run the computer program to execute the steps in any one of the above-mentioned kernel task execution method embodiments.

[0070] An embodiment of the present application also provides a computer-readable storage medium, in which a computer program is stored. Wherein, the computer program is configured to execute the steps in any one of the above-mentioned kernel task execution method embodiments when running.

[0071] In one exemplary embodiment, the above computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as USB flash drives, read-only memory (ROM for short), random access memory (RAM for short), external hard drives, magnetic disks, or optical discs.

[0072] The embodiments of the present application also provide a computer program product. The above computer program product includes a computer program, and when the computer program is executed by a processor, the steps in any of the above embodiments of the kernel task execution method are implemented.

[0073] The embodiments of the present application also provide another computer program product, including a non-volatile computer-readable storage medium. The non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in any of the above embodiments of the kernel task execution method are implemented.

[0074] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Skilled professionals can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0075] The above has introduced in detail a kernel task execution method, an electronic device, a computer-readable storage medium, and a computer program product provided by the present application. Specific examples are used herein to elaborate on the principles and implementation manners of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application. It should be noted that for those of ordinary skill in the art in the technical field, without departing from the principle of the present application, several improvements and modifications can be made to the present application, and these improvements and modifications also fall within the protection scope of the present application.

Claims

1. A method for executing a kernel task, characterized in that Including: Creating at least three levels of nested mapping table structures for the extended Berkeley Packet Filter in the user-mode environment; The first-level mapping table stores task identifiers and their mapping relationships with the next-level mapping table, and the mapping tables of other levels store corresponding task control rules and mapping relationships with other levels; Extracting target task control rule information from the resource policy file, dividing the target task control rule information into multiple task execution control rules, and storing them correspondingly in the mapping tables of the corresponding levels as a task execution control rule storage table; the number of levels of the mapping table structure is the same as the total number of task execution control rules; Sending the task execution control rule storage table to the kernel mode so that the kernel mode controls the kernel task operations layer by layer according to the task execution control rule storage table.

2. The kernel task execution method according to claim 1, wherein The target task control rule information is a target container access control rule set, and the task identifier is a container identifier. Dividing the target task control rule information into multiple task execution control rules and storing them correspondingly in the mapping tables of the corresponding levels as a task execution control rule storage table includes: Dividing the target container access control rule set into a target container identifier, a second-layer filtering rule for screening the object to be executed, and a third-layer filtering rule for screening the execution subject; the third-layer filtering rule includes at least subject location information and subject permission information; Inserting the target container identifier into the key of the first-level mapping table to generate a first sub-mapping table, and using the first sub-mapping table as the value of the first-level mapping table to construct the corresponding nested relationship between the first-level mapping table structure and the second-level mapping table structure; the first sub-mapping table is the target second-level mapping table in the second-level mapping table structure; Inserting the second-layer filtering rule into the key of the target second-level mapping table to generate a second sub-mapping table, and using the second sub-mapping table as the value of the target second-level mapping table to construct the corresponding nested relationship between the second-level mapping table structure and the third-level mapping table structure; the second sub-mapping table is the target third-level mapping table in the third-level mapping table structure; Inserting the third-layer filtering rules into the key-value pairs of the target third-level mapping table respectively.

3. The kernel task execution method according to claim 2, wherein The task execution control rule storage table is a container access control rule storage table, and controlling the access operations of the target container kernel tasks according to the task execution control rule storage table includes: When obtaining container access process information, obtaining the container information and access information to which it belongs from the container access process information; When the container identifier of the container information matches the key of the first-level mapping table of the container access control rule storage table, locating the target second-level mapping table correspondingly according to the value of the first-level mapping table; When the information of the object to be executed in the access information matches the key of the target second-level mapping table, locating the target third-level mapping table correspondingly according to the value of the target second-level mapping table; When the subject information in the access information matches the key-value pair of the target third-level mapping table, allowing the container access process information to be executed in the kernel mode.

4. The kernel task execution method according to claim 1, wherein The target task control rule information is a target container access control rule set, and the task identifier is a container identifier. The target task control rule information is divided into multiple task execution control rules and stored in the mapping tables of the corresponding layers respectively to serve as a task execution control rule storage table, including: Dividing the target container access control rule set into a target container identifier, an object path of an object to be accessed or operated on, a subject object path of a subject operation process, and subject operation permissions; Using the target container identifier as the key of the first-layer mapping table, and the value of the first-layer mapping table being the corresponding relationship with the target second-layer mapping table in the second-layer mapping table structure; Using the object path as the key of the target second-layer mapping table, and the value of the target second-layer mapping table being the corresponding relationship with the target third-layer mapping table in the third-layer mapping table structure; Using the subject object path as the key of the target third-layer mapping table, and the value of the target third-layer mapping table being the subject operation permissions.

5. The kernel task execution method according to claim 4, wherein The task execution control rule storage table is a container access control rule storage table, and the kernel task operations are controlled layer by layer according to the task execution control rule storage table, including: When obtaining container access process information, obtaining the container information and access information to which it belongs from the container access process information; Matching the container identifier in the container information with the target container identifier in the first-layer mapping table of the container access control rule storage table; When the container identifier in the container information is consistent with the target container identifier, locating the target second-layer mapping table according to the value of the first-layer mapping table; Matching the object path in the access information with the key of the target second-layer mapping table; When the object path in the access information is consistent with the object path in the target second-layer mapping table, locating the target third-layer mapping table according to the value of the target second-layer mapping table; Matching the subject object path and access permissions in the access information with the key-value pairs of the target third-layer mapping table respectively, and after successful matching, allowing the container access process information to execute.

6. The kernel task execution method according to claim 5, wherein After obtaining the container information and access information to which it belongs from the container access process information, it further includes: When the container identifier in the container information does not match the target container identifier in the first-layer mapping table of the container access control rule storage table, allowing the container access process information to execute; When the object path in the access information does not match the object path in the target second-layer mapping table, or the subject object path and access permissions in the access information do not match the key-value pairs of the target third-layer mapping table, the container access process information is not allowed to access the target container.

7. The kernel task execution method according to claim 1, wherein After creating at least three layers of nested mapping table structures for the extended Berkeley packet filter in the user-mode environment, it further includes: When detecting a target key deletion request, determining the target mapping table structure to which the target key corresponding to the target key deletion request belongs; When the target key is located in the first - layer target mapping table of the target mapping table structure, determine the target sub - mapping table created by the first - layer target mapping table, delete the target sub - mapping table, and clear the content and usage permissions of the lower - layer target mapping table nested in the target sub - mapping table; When the target key is located in the second - layer target mapping table of the target mapping table structure, clear the content and usage permissions of the lower - layer target mapping table nested in the second - layer target mapping table, and delete the target key of the second - layer target mapping table; When the target key is located in the third - layer target mapping table of the target mapping table structure, correspondingly update the content of the third - layer target mapping table.

8. The kernel task execution method according to claim 1, wherein, After creating a mapping table structure with at least three layers of nesting for the extended Berkeley packet filter in the user - mode environment, it further includes: When a target key addition request is detected, determine the target mapping table structure to which the target key corresponding to the target key addition request belongs; When the target key is located in the first - layer target mapping table of the target mapping table structure, automatically generate a target sub - mapping table for the first - layer target mapping table, and apply for corresponding usage permissions for the third - layer target mapping table nested in the target sub - mapping table; When the target key is located in the second - layer target mapping table of the target mapping table structure, apply for corresponding usage permissions for the third - layer target mapping table nested in the second - layer target mapping table.

9. The kernel task execution method according to claim 1, wherein After sending the task execution control rule storage table to the kernel - mode, it further includes: When receiving the log information of the task execution control rule storage table sent by the kernel - mode, obtain the log printing configuration information in the user - mode environment; According to the log printing configuration information, print the log information in the user - mode environment.

10. The method for performing a kernel task according to any one of claims 1 to 9, characterized in that, Creating a mapping table structure with at least three layers of nesting for the extended Berkeley packet filter in the user - mode environment includes: Initialize the first - layer mapping table structure of the mapping table of the extended Berkeley packet filter as a nested hash table, and construct a mapping table array of the type of the nested hash table; the mapping table array includes multiple nested hash tables; After filling the content of the key of the first - layer mapping table in the first - layer mapping table structure, automatically create a sub - mapping table for the first - layer mapping table located in the second - layer mapping table structure, and at the same time, apply for usage permissions for the lower - layer nested mapping table of the sub - mapping table from the mapping table array; Use the array sub - script of the mapping table array corresponding to the lower - layer nested mapping table as an index and fill it into the value of the sub - mapping table; Among them, the sub - mapping table is the value of the first - layer mapping table, and the lower - layer nested mapping table of the sub - mapping table is located in the third - layer mapping table structure.

11. The kernel task execution method according to claim 10, characterized in that, Applying for usage permissions for the lower - layer nested mapping table of the sub - mapping table from the mapping table array includes: When the total number of nested hash tables in the mapping table array is less than the first preset number of tables, generate an expansion request for the mapping table array; When the current total number of nested hash tables in the mapping table array is greater than or equal to the first preset number of tables, select a target nested hash table from the mapping table array as the lower - layer nested mapping table, and feedback the array sub - script value of the target nested hash table in the mapping table array to the sub - mapping table.

12. The kernel task execution method according to claim 10, wherein Apply for the usage permission for the lower-level nested mapping table of the sub-mapping table from the mapping table array, including: When the total number of nested hash tables in the mapping table array is greater than or equal to the second preset number of tables, generate a request for reducing the capacity of the mapping table array; When the current total number of nested hash tables in the mapping table array is less than the second preset number of tables, select a target nested hash table from the mapping table array as the lower-level nested mapping table, and feedback the array subscript value of the target nested hash table in the mapping table array to the sub-mapping table.

13. An electronic device, characterized in that, Including: A memory for storing a computer program; A processor for implementing the steps of the kernel task execution method according to any one of claims 1 to 12 when executing the computer program.

14. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the kernel task execution method according to any one of claims 1 to 12 are implemented.

15. A computer program product, comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by a processor, the steps of the kernel task execution method according to any one of claims 1 to 12 are implemented.

Citation Information

Patent Citations

  • EBPF memory isolation method and system based on kernel mode memory isolation hardware characteristics

    CN116127445A

  • Operating command intercepting method, device and system and computer storage medium

    CN117113334A

  • Kernel mode and user mode joint optimization high-performance network processing method and device

    CN118301090A

  • Hash table-based multilayer embedded table updating method and device, equipment and medium

    CN118885488A

  • Equipment security protection method under eBPF, equipment, program product and medium

    CN119939554A

Cited By

  • Container hierarchical network control method and device, storage medium and program product

    CN121356908A

  • Wildcard association array data storage method, electronic equipment and medium

    CN121635820A

  • Wildcard associative array data storage method, electronic device and medium

    CN121635820B