Extranet-driven internal and external network security isolation compiling system

Through the extranet-driven, securely isolated compilation system for both internal and external networks, SFTP servers and automated scripts are used to solve the problems of lengthy information transmission and manual operation errors in traditional publishing methods, achieving an efficient and secure publishing process to meet the rapid iteration needs of the software industry.

CN120669965APending Publication Date: 2025-09-19JIANGSU XINSHENG INTELLIGENT TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510803114.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-16
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

During the software development process, traditional release methods have problems such as lengthy information transmission, inconsistent releases caused by manual errors, waste of resources, and project delays. Especially in an environment with isolated internal and external networks, it is difficult to adapt to the needs of rapid iteration.

Method used

An extranet-driven, securely isolated compilation system for both internal and external networks is adopted, and an SFTP server is used to implement upload control, physical isolation, and file synchronization between the internal and external networks. Combined with automated scripts, configuration file detection modules, and intranet log modules, the front-end work is driven by data processing algorithms to achieve automated compilation and task management.

Benefits of technology

It improves the efficiency and accuracy of information transmission, reduces manual intervention, shortens the release cycle, ensures the consistency of release information and system security, and reduces the risk of resource waste and project delays.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120669965A_ABST
    Figure CN120669965A_ABST
Patent Text Reader

Abstract

The invention discloses an extranet-driven intranet and extranet security isolation compiling system, and belongs to the technical field of software development. Comprising an SFTP server, and the SFTP server is connected with an intranet and an extranet. The SFTP server is used for internal and external network upload management and control, internal and external network physical isolation and file synchronization. The intranet comprises an automatic script, a configuration file detection module, an automatic compiling module and an intranet log module; the external network comprises a front end and a rear end, the front end is used for providing a unified operation entrance for a user, and the rear end is used for driving the front end to work through a data processing algorithm; when a user initiates a request through a webpage, a system creates task groups, and each task group comprises a plurality of sub-tasks; at the moment, the extranet executes an extranet process to perform extranet legality verification, and performs task release; and meanwhile, the intranet executes an intranet process and periodically performs intranet legality detection. The method can ensure that each link masters the edition issuing key information consistently, and effectively improves the information transmission efficiency and accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of software development, and in particular to an extranet-driven, extranet- and extranet-safe isolation compilation system. Background Art

[0002] Traditional methods of releasing software development projects suffer from drawbacks such as lengthy release information transmission and manual errors. The cumbersome process of transferring release information across multiple departments and processes is prone to information loss, delays, and misunderstandings, leading to inconsistent understanding of key information such as release content and timing. Manual operations, involving extensive manual work such as filling out compilation information, configuring parameters, and transferring software packages, are prone to errors due to carelessness or improper operation. For example, incorrect compilation options can cause software package contents to differ from the final release version, while manual configuration errors can lead to parameter mismatches, causing verification failures and wasting resources. These issues can ultimately lead to inconsistent releases, wasting human and material resources and delaying project progress, creating the risk of project delays.

[0003] With the rapid development of the software industry, project iteration cycles are shrinking, and the frequency of version releases is increasing. In a development environment with isolated internal and external networks, the release process faces numerous challenges. Firstly, this isolation limits real-time information exchange. Traditional release models, which rely on step-by-step information transmission and multi-step collaboration, struggle to adapt to the rapid pace of product iteration. Secondly, the complex release process involves numerous steps and configurations, and the high error rate of manual operations becomes a key factor affecting release quality and progress.

[0004] While existing compilation and release solutions for intranet / internet interaction exist, such as one-way network communication triggering solutions and external network triggering solutions based on configuration file transmission, none of these solutions effectively address the issues associated with release information transmission and manual operation. One-way network communication triggering solutions cannot carry detailed release information, making it difficult to meet diverse release requirements. External network triggering solutions based on configuration file transmission rely on manual operation, which is not only inefficient but also prone to errors during file transmission and parsing, making it impossible to guarantee the accuracy and consistency of release information.

[0005] The existing technology has the following problems: in the one-way network communication trigger scheme, since the external network lacks the internal network compilation progress information, it is impossible to perform subsequent automated processing on the compiled code, which limits the degree of automation of the release process; the one-way transmission equipment can only transmit simple signals and cannot carry the detailed parameters required for compilation, resulting in insufficient flexibility and difficulty in meeting diversified release requirements; the external network cannot obtain the internal network compilation status and results, and there is a lack of two-way information interaction, which makes it difficult to build a complete workflow and affects the continuity of the release process.

[0006] In the external network trigger solution based on configuration file transmission, file transmission relies on manual operation or fixed channels, which is affected by human factors and channel characteristics, resulting in poor response timeliness and difficulty in adapting to the rapid iterative release rhythm; the transmission process lacks reliable encryption and verification mechanisms, and files are easily tampered with or lost, which in turn causes compilation errors and affects the accuracy and consistency of release information; if the compilation requirements change temporarily, the files need to be manually rewritten and transmitted. Due to the many manual steps involved, the operation is cumbersome, inefficient and error-prone; there are deficiencies in security detection and permission control of configuration files, and the lack of a complete security protection mechanism may cause illegal files to flow into the intranet, threatening system security.

[0007] The manual version release solution from the intranet to the extranet has a long transmission chain and involves a lot of manual operations. If information is not synchronized properly, it is easy to cause inconsistent releases. Summary of the Invention

[0008] The purpose of the present invention is to overcome the deficiencies of the prior art and provide an extranet-driven extranet- and extranet-safe isolation compilation system.

[0009] The objective of the present invention is achieved through the following technical solutions: an extranet-driven, intranet-extranet secure isolation compilation system, comprising an SFTP server connected to an intranet and an extranet; the SFTP server is used to manage and control intranet-extranet uploads, physically isolate the intranet and extranet, and synchronize files; the intranet includes an automated script, a configuration file detection module, an automatic compilation module, and an intranet log module; the extranet includes a front-end and a back-end, the front-end is used to provide a unified operation portal for users, and the back-end is used to drive the front-end operation through a data processing algorithm; When a user initiates a request through a web page, the system creates a task group, each of which includes multiple subtasks. At this time, the external network executes the external network process to verify the legitimacy of the external network and publishes the task. At the same time, the internal network executes the internal network process and periodically performs internal network legitimacy checks.

[0010] Preferably, the internal and external network upload control includes: setting permission policies and rules to only allow files that comply with security specifications and business requirements to be transmitted, and preventing illegal files or malicious programs from spreading between the internal and external networks; the internal and external network physical isolation includes: isolating the internal and external networks from a physical level to prevent direct network connection and data interaction between the internal and external networks; the file synchronization includes: using a file synchronization algorithm to hide the file during the transmission from the internal network to the external network, and then display it to the external network after all the transmissions are completed, to prevent file loss due to file asynchrony.

[0011] Preferably, the automated script is used to execute compilation tasks; the configuration file detection module is used to periodically detect the configuration file issued from the external network and verify the legality of the configuration file. If it is legal, the corresponding compilation task is triggered according to the configuration file; the automatic compilation module is used to pull the code specified by the configuration file from the code library, add the corresponding label, and automatically use the compilation parameters and macros specified in the configuration file for automatic compilation; the intranet log module is used to record the operations and events of the intranet.

[0012] Preferably, the front end includes a registration account page, a login account page, a default property setting page, a compilation request initiation page, a task management page, a user management page, and a password modification page; The Set Default Properties page is used to configure the compilation options and macro switches for the intranet code, the SDTP server for uploading configuration files from the external network to the intranet, the SFTP server for downloading the intranet firmware from the external network, the SFTP server for uploading the software package after the external network package is packaged, the URL address of the intranet git repository, the timeout period for a single software package to be compiled and transmitted from the intranet after sending the command, the server information of the sending server, and the software package rule configuration file; The initiating compilation request page is used to fill in the required information and optional information to configure the compilation options, and initiate a compilation request to the system to trigger the compilation process; The task management page is used to view the status of initiated compilation tasks and to pause, restart or delete compilation tasks.

[0013] Preferably, the backend includes a database service, a task processing module, an email service module and a backend log module; the database service is used to store user information, set properties and compilation task information; the task processing module is used to receive compilation requests initiated by front-end users, parse and pre-process them, and then add the tasks to the pending queue, monitor the task execution status in real time, and automatically perform secondary processing of the software package after detecting the compilation package transmitted from the intranet; the email service module is used to send compilation task notifications to users.

[0014] Preferably, the external network process includes the following steps: Configure the compilation options on the Initiate Compile Request page, then submit the compilation request to the system. The system will verify the validity of the compilation parameters. If they are not valid, a prompt will pop up and the compilation request will be blocked from further processing. If they are valid, the system will continue to verify the validity of the email verification code. If the verification code is invalid, a prompt will pop up and the request will be restricted. If the verification code is valid, the system will add the task group and subtasks to the database and mark the task status as pending. The main process of the back-end task processing module searches for task groups at a fixed period, starts sub-processes to process them in the order of task status, and updates the task status; When processing a task group, the backend sub-process traverses the sub-tasks one by one and uploads the sub-task configuration files to the SFTP server. The backend sub-process then periodically checks whether the expected compilation package exists on the SFTP server. If not, it determines whether the task has timed out. If so, it marks both the task group and the sub-task status as failed and terminates the sub-process. If not, it continues waiting. If the compilation package exists, it downloads it to the local backend server and marks the sub-task status as successful. Next, the backend sub-process determines whether the current sub-task is the last one. If not, it continues to traverse and process subsequent sub-tasks. If so, it begins secondary processing of the compiled package, including configuring the software package, archiving the source traceability file, comparing the software package, and packaging the task group files. If the secondary processing is complete, the task group's task status is marked as successful. If the secondary processing fails, the task group's task status is marked as failed, and the sub-process exits. When the secondary processing is successful, the child process determines whether automatic publishing is required. If so, the task status of the task group is marked as publishing, the package file is uploaded, and the publishing status is notified by email. If the publishing is completed, the task status of the task group is marked as publishing success. If the publishing is not completed, the task status of the task group is marked as publishing failure.

[0015] Preferably, the intranet process includes the following steps: The automated script performs detection tasks according to the preset cycle, obtains the configuration file from the SFTP server, and parses it to determine whether it is a new and legal configuration file. If it is not a new and legal configuration file, the automated script jumps back to the starting position and continues to perform regular detection; if it is a new and legal configuration file, the automated script creates the corresponding directory structure based on the configuration file, then clones the repository and checks out the specified version, then tags it and compiles the project; after the compilation is completed, it determines whether the editing is successful. If successful, the compiled package is packaged and uploaded to the SFTP server. If unsuccessful, the automated script jumps back to the starting position and continues to perform regular detection.

[0016] The beneficial effects of the present invention are: 1) Use the SFTP server as the hub to achieve efficient and accurate information exchange across internal and external networks, fundamentally avoiding information loss during transmission, ensuring that all links have consistent knowledge of key release information, and effectively improving the efficiency and accuracy of information transmission.

[0017] 2) Automated compilation tasks are executed using intranet scripts, while the external backend automatically handles task groups and subtasks, significantly reducing manual intervention. Automatic configuration file detection, automatic compilation, and automatic upload and download processes eliminate the risk of human error and significantly improve release success rates and stability.

[0018] 3) Through automation and efficient information transmission mechanisms, compilation requirements can be quickly responded to without repeated manual communication and confirmation, greatly shortening the release cycle and matching the rapid iteration pace of the software industry.

[0019] 4) Through the coordinated work of various system modules, it can not only achieve the complete transmission of detailed release information, but also avoid the disadvantages of manual operation, far exceeding traditional solutions in flexibility, reliability and security.

[0020] 5) Through automated processes and real-time information interaction, we ensure data consistency throughout the entire process, from compilation to release. This effectively avoids release inconsistencies caused by information asynchrony and ensures smooth project progress. Furthermore, traceability files are automatically archived during releases, facilitating subsequent issue tracking and enabling continuous system optimization and improvement.

[0021] 6) Reduce information transmission errors and manual operation errors, reduce duplication of work and rework costs, ensure on-time and high-quality completion of projects, and significantly reduce resource waste and project delay risks. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Figure 1 Schematic diagram of the extranet-driven internal and external network security isolation compilation system; Figure 2 This is a diagram of the intranet and extranet business processes. DETAILED DESCRIPTION

[0023] The following will clearly and completely describe the technical solutions of the present invention in conjunction with the embodiments. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work shall fall within the scope of protection of the present invention.

[0024] First, some definitions of terms in this invention: BRANCH: In a code repository, a relatively independent code line created to achieve specific development goals (such as function development, version maintenance, etc.), used for parallel development, isolation of functional modules, etc.

[0025] COMMITID: A unique identifier automatically generated by the system each time a commit operation is performed on the code repository. It is used to accurately locate and trace the specific code commit content and operation records.

[0026] TAG: A tag added to a specific commit point in a code repository. It is often used to identify important versions (such as release versions and milestone versions), making it easy to quickly locate and trace back to a specific state of code.

[0027] RELEASE_NOTES: A document that describes the software release content, including new feature introductions, bug fix details, known issue reminders, and other information to help users and relevant personnel understand version changes.

[0028] URL: The abbreviation of Uniform Resource Locator, which is a uniform resource locator. It is used to identify the address of resources on the Internet (such as web pages, files, etc.). It can be used to accurately find the corresponding resources on the Internet.

[0029] SFTP: Short for SSH File Transfer Protocol, it's also known as the Secure File Transfer Protocol. Based on the SSH protocol, it provides a secure, encrypted channel for file transfers. It allows for secure and reliable file transfers between the client and server, preventing data theft and tampering during transmission.

[0030] See Figure 1-Figure 2 The present invention provides a technical solution: an extranet-driven, intranet-extranet secure isolation compilation system, comprising an SFTP server connected to an intranet and an extranet; the SFTP server is used to manage and control intranet-extranet uploads, physically isolate the intranet and the extranet, and synchronize files; the intranet includes an automation script, a configuration file detection module, an automatic compilation module, and an intranet log module; the extranet includes a front-end and a back-end, the front-end is used to provide a unified operation portal for users, and the back-end is used to drive the front-end operation through a data processing algorithm; When a user initiates a request through a web page, the system creates a task group, each of which includes multiple subtasks. At this time, the external network executes the external network process to verify the legitimacy of the external network and publishes the task. At the same time, the internal network executes the internal network process and periodically performs internal network legitimacy checks.

[0031] In this embodiment, when a user initiates a request through a web page, the system will create a task group, and each task group will have multiple subtasks. The status of the task group is pending, in progress, successful, failed, publishing, publishing failed, publishing successfully, and paused. The status of the subtasks is pending, in progress, successful, and failed. In response to the problems existing in the one-way network communication triggering scheme, the present invention realizes the efficient transmission and two-way interaction of compilation information, ensuring that the external network can obtain detailed compilation parameters, and at the same time the compilation status and results of the internal network can be fed back to the external network; it improves the automation level of the publishing process, meets the diversified publishing needs, builds a complete workflow, and solves its problems of insufficient flexibility, lack of two-way information interaction, and limited automation.

[0032] In response to the problems existing in the external network triggering solution based on configuration file transmission, the present invention reduces manual participation and improves response speed through automated processes; establishes reliable encryption and verification mechanisms and a complete security detection and authority management system to ensure that the release information is accurate, consistent and the system is secure; simplifies the operational process caused by changes in compilation requirements, improves release efficiency, and solves the problems of poor response timeliness, difficulty in ensuring information accuracy, cumbersome operations and insufficient security protection.

[0033] In response to the problems existing in the manual version release scheme from the intranet to the extranet, the present invention shortens the information transmission path, reduces the manual operation links, ensures that the version release information is accurately and quickly transmitted between multiple links and multiple departments, and avoids version release inconsistencies caused by insufficient information synchronization.

[0034] In some embodiments, the internal and external network upload control includes: setting permission policies and rules to only allow files that comply with security specifications and business requirements to be transmitted, and preventing illegal files or malicious programs from spreading between the internal and external networks; the physical isolation of the internal and external networks includes: isolating the internal and external networks from a physical level to prevent direct network connection and data interaction between the internal and external networks; the file synchronization includes: using a file synchronization algorithm to hide the file during the transmission from the internal network to the external network, and then display it to the external network after all transmissions are completed, to prevent file loss due to file asynchrony.

[0035] In this embodiment, the SFTP server is the key hub connecting the internal and external networks. Internal and external network upload control: strictly control the upload operation of files between the internal and external networks, and by setting detailed permission policies and rules, only allow files that meet security specifications and business requirements to be transferred, effectively preventing illegal files or malicious programs from spreading between the internal and external networks. Physical isolation of internal and external networks: ensure the isolation of the internal and external networks from a physical level, and prevent direct network connection and data interaction between the internal and external networks. File synchronization: using advanced file synchronization algorithms, the files are hidden during the transfer from the internal network SFTP server to the external network SFTP server, and then displayed to the external network after all transfers are completed, to avoid file loss due to file asynchrony. Security advantages of SFTP servers: traditional FTP uses plain text transmission, and attackers can easily intercept sensitive information; SFTP encrypts all communications, and even if the data is intercepted, it is difficult to decrypt.

[0036] In some embodiments, the automated script is used to execute compilation tasks; the configuration file detection module is used to periodically detect the configuration file issued from the external network and verify the legality of the configuration file. If it is legal, the corresponding compilation task is triggered according to the configuration file; the automatic compilation module is used to pull the code specified by the configuration file from the code library, add the corresponding label, and automatically use the compilation parameters and macros specified in the configuration file for automatic compilation; the intranet log module is used to record operations and events on the intranet.

[0037] In this embodiment, the intranet primarily includes the following functional components: An automated script: used to automate a series of compilation-related tasks. The configuration file detection module periodically checks configuration files sent from the external network and verifies their validity. If they are valid, the corresponding compilation task is triggered based on the configuration file. The automatic compilation module pulls the code specified in the configuration file from the code repository, tags it with the corresponding tags, and automatically compiles it using the compilation parameters and macros specified in the configuration file. The intranet logging module records key intranet operations and events, facilitating system maintenance and problem tracking.

[0038] In some embodiments, the front end includes a registration account page, a login account page, a default property setting page, a compilation request initiation page, a task management page, a user management page, and a password modification page; The Set Default Properties page is used to configure the compilation options and macro switches for the intranet code, the SDTP server for uploading configuration files from the external network to the intranet, the SFTP server for downloading the intranet firmware from the external network, the SFTP server for uploading the software package after the external network package is packaged, the URL address of the intranet git repository, the timeout period for a single software package to be compiled and transmitted from the intranet after sending the command, the server information of the sending server, and the software package rule configuration file; The initiating compilation request page is used to fill in the required information and optional information to configure the compilation options, and initiate a compilation request to the system to trigger the compilation process; The task management page is used to view the status of initiated compilation tasks and to pause, restart or delete compilation tasks.

[0039] In this embodiment, the front-end web interface builds a simple, easy-to-use web interface, providing users with a unified operation portal. This interface supports access across all major browsers, facilitating operations across different devices. The account registration page allows new users to register an account, enter necessary personal information (such as username, password, and email address), and ensure the authenticity and security of the account through methods such as email verification.

[0040] Login account page: provides login function for registered users.

[0041] Set the default property page: Configure the default parameters of the automatic compilation system, including: configuring the compilation options and macro switches for the intranet code. Configure the SFTP server for uploading configuration files from the external network to the intranet. Configure the SFTP server for downloading the intranet firmware from the external network. Configure the SFTP server for uploading the software package after the external network package is packaged. Configure the URL address of the intranet git repository. Configure the timeout period for a single software package to be compiled and transmitted from the intranet after the instruction is sent. Configure the address, port number, username and password of the sending server. Used in the system for email notifications such as verification codes and release progress. Configure the software package rule configuration file.

[0042] Initiate Compile Request Page: This page allows users to configure compile options and initiate a compile request to the system, triggering the entire compile process. Required information includes: branch, commit ID, tag, external version number, timeout, and verification code. Optional information includes: macro switch, repository URL, SFTP server for uploading configuration files from the external network to the internal network, SFTP server for downloading internal firmware from the external network, SFTP server for uploading the package to the external network after packaging, and release_notes.

[0043] Task management page: Users can view the status of initiated compilation tasks (task parameters, execution progress, and results) and perform operations such as pausing, restarting, and deleting tasks, making it easier for users to manage and monitor compilation tasks.

[0044] User management page: System administrators can manage user accounts on this page, including adding new users, viewing users, deleting users, resetting passwords, setting permissions, and other operations to achieve effective management and control of user groups.

[0045] Change password page: Users can change their login password on this page and ensure the security of their account password through a secure password change process (original password verification, etc.).

[0046] In some embodiments, the backend includes a database service, a task processing module, an email service module and a backend log module; the database service is used to store user information, set properties and compilation task information; the task processing module is used to receive compilation requests initiated by front-end users, and perform parsing and preprocessing, and then add the task to the pending queue, monitor the task execution status in real time, and automatically perform secondary processing of the software package after detecting the compilation package transmitted from the intranet; the email service module is used to send compilation task notifications to users.

[0047] In this embodiment, the database service is responsible for storing various data during system operation, including user information (account, password, permissions), configuration properties, and compilation task information (task parameters, execution progress, and results). It uses a reliable database management system (MySQL) to ensure data security, integrity, and efficient read and write operations.

[0048] Task Processing Module: Receives compilation requests from front-end users, parses and pre-processes them, adds tasks to the pending queue, and monitors task execution status in real time. Upon detecting a compiled package from the intranet, it automatically performs secondary processing of the package.

[0049] Email service module: used to send compilation task notifications to users (including compilation results, success and failure reports, etc.) Backend Logging Module: Similar to the intranet's logging module, this module records operations and events on the external network module, including user login and logout information, user operation records, and key information during task processing, providing strong support for system security review and troubleshooting. Through the collaborative operation of these modules, the present invention's external network-driven, securely isolated internal and external network compilation system can efficiently and accurately complete compilation tasks while ensuring secure isolation between the internal and external networks, enabling secure and reliable information exchange and business process automation between the internal and external networks.

[0050] In some embodiments, the external network process includes the following steps: Configure the compilation options on the Initiate Compile Request page, then submit the compilation request to the system. The system will verify the validity of the compilation parameters. If they are not valid, a prompt will pop up and the compilation request will be blocked from further processing. If they are valid, the system will continue to verify the validity of the email verification code. If the verification code is invalid, a prompt will pop up and the request will be restricted. If the verification code is valid, the system will add the task group and subtasks to the database and mark the task status as pending. The main process of the back-end task processing module searches for task groups at a fixed period, starts sub-processes to process them in the order of task status, and updates the task status; When processing a task group, the backend sub-process traverses the sub-tasks one by one and uploads the sub-task configuration files to the SFTP server. The backend sub-process then periodically checks whether the expected compilation package exists on the SFTP server. If not, it determines whether the task has timed out. If so, it marks both the task group and the sub-task status as failed and terminates the sub-process. If not, it continues waiting. If the compilation package exists, it downloads it to the local backend server and marks the sub-task status as successful. Next, the backend sub-process determines whether the current sub-task is the last one. If not, it continues to traverse and process subsequent sub-tasks. If so, it begins secondary processing of the compiled package, including configuring the software package, archiving the source traceability file, comparing the software package, and packaging the task group files. If the secondary processing is complete, the task group's task status is marked as successful. If the secondary processing fails, the task group's task status is marked as failed, and the sub-process exits. When the secondary processing is successful, the child process determines whether automatic publishing is required. If so, the task status of the task group is marked as publishing, the package file is uploaded, and the publishing status is notified by email. If the publishing is completed, the task status of the task group is marked as publishing success. If the publishing is not completed, the task status of the task group is marked as publishing failure.

[0051] In this embodiment, the user first enters the external network process, configures the compilation options on the "Initiate Compile Request" page, and then submits the compilation request to the system. The system immediately verifies the validity of the compilation parameters. If the parameters are invalid, a prompt will appear and the request will be blocked. If the parameters are valid, the system will then verify the validity of the email verification code. If the verification code is invalid, a prompt will also appear and the request will be blocked. If the verification code is valid, the system will add the task group and subtask to the database and mark its status as "pending."

[0052] The main process of the task processing module on the external network backend searches for task groups at a fixed interval and launches sub-processes to handle them in the order of "in progress" and "pending". When a task group with a status of "pending" is processed, its status is updated from "pending" to "in progress".

[0053] While processing a task group, the backend subprocess iterates through each subtask and uploads its configuration files to SFTP. The backend subprocess then periodically checks the SFTP server for the expected compilation package. If the compilation package is not present, the backend subprocess determines whether a timeout has occurred. If so, the task group and subtask are marked as "failed" and the subprocess is terminated. If not, the backend subprocess continues waiting. If the compilation package is present, it is downloaded to the backend server and the subtask is marked as "successful."

[0054] Next, the backend subprocess determines whether the current subtask is the last one. If not, it continues to iterate through subsequent subtasks. If so, it indicates that all subtasks have been successfully processed. At this point, secondary processing of the compiled package begins, covering operations such as configuring the package, archiving traceability files, comparing the package, and packaging the task group files. If the secondary processing completes successfully, the task group is marked as "successful." If the secondary processing fails, the task group is marked as "failed" and the subprocess exits.

[0055] After the secondary processing is successful, the child process determines whether automatic publishing is required. If so, the task group is marked as "Publishing," the packaged file is uploaded, and a successful publication notification is sent via email. If the publication operation is successful, the task group is marked as "Published Successfully"; if the publication is not complete, the task group is marked as "Published Failed."

[0056] In some embodiments, the intranet process includes the following steps: The automated script performs detection tasks according to the preset cycle, obtains the configuration file from the SFTP server, and parses it to determine whether it is a new and legal configuration file. If it is not a new and legal configuration file, the automated script jumps back to the starting position and continues to perform regular detection; if it is a new and legal configuration file, the automated script creates the corresponding directory structure based on the configuration file, then clones the repository and checks out the specified version, then tags it and compiles the project; after the compilation is completed, it determines whether the editing is successful. If successful, the compiled package is packaged and uploaded to the SFTP server. If unsuccessful, the automated script jumps back to the starting position and continues to perform regular detection.

[0057] In this embodiment, the intranet script will execute the detection task according to a fixed period and obtain the configuration file from SFTP. After obtaining it, the configuration file will be parsed to determine whether it is a new and legal configuration file. If it is not a new and legal configuration file, the script will jump back to the starting position and continue regular detection. If it is determined to be a new and legal configuration file, the script will create a corresponding directory structure based on the configuration file, then clone the repository and check out the specified version, then tag it, and then compile the project. After the compilation is completed, it is determined whether the compilation is successful: if the compilation is successful, the compiled package will be uploaded to SFTP; if the compilation is unsuccessful, the script will jump back to the starting position and continue regular detection. The entire process revolves around data processing between the internal and external networks and the flow of task status. Through a series of conditional judgments and operations, it is ensured that the task can be executed according to the predetermined logic in different network environments, and finally the task status is clarified.

[0058] Here are two examples from practical applications: Example 1: One day, a release colleague took leave, but an urgent release was needed that day for a large number of models. With this automated compilation system, simply confirming the configuration file and entering the relevant compilation parameters allowed a quick compilation request. The entire process involved automated interaction with the internal and external networks, automatic compilation, and automatic packaging. Upon completion, a successful release notification email was sent.

[0059] Example 2: One day, a tester needs the corresponding injection firmware. He can turn on the required injection macro switch on the "Initiate Request Page", cancel the automatic release, and initiate a request to compile the corresponding test firmware for testing.

[0060] The foregoing description is merely a preferred embodiment of the present invention. It should be understood that the present invention is not limited to the form disclosed herein and should not be construed as excluding other embodiments. Rather, the present invention can be used in various other combinations, modifications, and environments and can be modified within the scope of the concept described herein through the above teachings or techniques or knowledge in the relevant field. Modifications and variations made by those skilled in the art that do not depart from the spirit and scope of the present invention are intended to be protected by the appended claims.

Claims

1. An external network driven internal and external network secure isolation compilation system, characterized by: It includes an SFTP server that connects the intranet and the extranet; the SFTP server is used to manage and control uploads between the intranet and the extranet, physically isolate the intranet and the extranet, and synchronize files; the intranet includes an automated script, a configuration file detection module, an automatic compilation module, and an intranet log module; the extranet includes a front-end and a back-end, the front-end providing a unified user interface, and the back-end driving the front-end through data processing algorithms; When a user initiates a request through a web page, the system creates a task group, each of which includes multiple subtasks. At this time, the external network executes the external network process to verify the legitimacy of the external network and publishes the task. At the same time, the internal network executes the internal network process and periodically performs internal network legitimacy checks.

2. The extranet-driven, extranet- and extranet-safe isolation compilation system according to claim 1, characterized in that: The internal and external network upload control includes: setting permission policies and rules to only allow files that meet security specifications and business requirements to be transmitted, and preventing illegal files or malicious programs from spreading between the internal and external networks; the internal and external network physical isolation includes: isolating the internal and external networks from a physical level to prevent direct network connection and data interaction between the internal and external networks; the file synchronization includes: using a file synchronization algorithm to hide the file during transmission from the internal network to the external network, and then display it to the external network after all transmissions are completed, to prevent file loss caused by file asynchrony.

3. The extranet-driven, extranet- and extranet-safe isolation compilation system according to claim 1, characterized in that: The automated script is used to execute compilation tasks; the configuration file detection module is used to periodically detect configuration files issued from the external network and verify the legality of the configuration files. If they are legal, the corresponding compilation task is triggered according to the configuration file; the automatic compilation module is used to pull the code specified by the configuration file from the code library, add corresponding tags, and automatically compile using the compilation parameters and macros specified in the configuration file; the intranet log module is used to record operations and events on the intranet.

4. The extranet-driven, extranet- and extranet-safe isolation compilation system according to claim 1, characterized in that: The front end includes a registration account page, a login account page, a default property setting page, a compilation request initiation page, a task management page, a user management page, and a password modification page; The Set Default Properties page is used to configure the compilation options and macro switches for the intranet code, the SDTP server for uploading configuration files from the external network to the intranet, the SFTP server for downloading the intranet firmware from the external network, the SFTP server for uploading the software package after the external network package is packaged, the URL address of the intranet git repository, the timeout period for a single software package to be compiled and transmitted from the intranet after sending the command, the server information of the sending server, and the software package rule configuration file; The initiating compilation request page is used to fill in the required information and optional information to configure the compilation options, and initiate a compilation request to the system to trigger the compilation process; The task management page is used to view the status of initiated compilation tasks and to pause, restart or delete compilation tasks.

5. The extranet-driven, extranet- and extranet-safe isolation compilation system according to claim 1, characterized in that: The backend includes a database service, a task processing module, an email service module, and a backend log module; the database service is used to store user information, set attributes, and compile task information; the task processing module is used to receive compile requests initiated by front-end users, parse and pre-process them, then add tasks to the processing queue, monitor task execution status in real time, and automatically perform secondary processing of the software package after detecting the compiled package transmitted from the intranet; The mail service module is used to send compilation task notifications to users.

6. The extranet-driven, extranet- and extranet-safe isolation compilation system according to any one of claims 1 to 5, characterized in that: The external network process includes the following steps: Configure the compilation options on the Initiate Compile Request page, then submit the compilation request to the system. The system will verify the validity of the compilation parameters. If they are not valid, a prompt will pop up and the compilation request will be blocked from further processing. If they are valid, the system will continue to verify the validity of the email verification code. If the verification code is invalid, a prompt will pop up and the request will be restricted. If the verification code is valid, the system will add the task group and subtasks to the database and mark the task status as pending. The main process of the back-end task processing module searches for task groups at a fixed period, starts sub-processes to process them in the order of task status, and updates the task status; When processing a task group, the backend sub-process traverses the sub-tasks one by one and uploads the sub-task configuration files to the SFTP server. The backend sub-process then periodically checks whether the expected compilation package exists on the SFTP server. If not, it determines whether the task has timed out. If so, it marks both the task group and the sub-task status as failed and terminates the sub-process. If not, it continues waiting. If the compilation package exists, it downloads it to the local backend server and marks the sub-task status as successful. Next, the backend sub-process determines whether the current sub-task is the last one. If not, it continues to traverse and process subsequent sub-tasks. If so, it begins secondary processing of the compiled package, including configuring the software package, archiving the source traceability file, comparing the software package, and packaging the task group files. If the secondary processing is complete, the task group's task status is marked as successful. If the secondary processing fails, the task group's task status is marked as failed, and the sub-process exits. When the secondary processing is successful, the child process determines whether automatic publishing is required. If so, the task status of the task group is marked as publishing, the package file is uploaded, and the publishing status is notified by email. If the publishing is completed, the task status of the task group is marked as publishing success. If the publishing is not completed, the task status of the task group is marked as publishing failure.

7. The extranet-driven, extranet- and extranet-safe isolation compilation system according to any one of claims 1 to 5, characterized in that: The intranet process includes the following steps: The automated script performs detection tasks according to the preset cycle, obtains the configuration file from the SFTP server, and parses it to determine whether it is a new and legal configuration file. If it is not a new and legal configuration file, the automated script jumps back to the starting position and continues to perform regular detection; if it is a new and legal configuration file, the automated script creates the corresponding directory structure based on the configuration file, then clones the repository and checks out the specified version, then tags it and compiles the project; after the compilation is completed, it determines whether the editing is successful. If successful, the compiled package is packaged and uploaded to the SFTP server. If unsuccessful, the automated script jumps back to the starting position and continues to perform regular detection.

Citation Information

Cited By

  • Local data acquisition system and method based on handheld terminal

    CN121619576A