Hot Patch Installation Method, Device, Electronic Device, and Computer Readable Medium
By installing kernel hot patches based on version and device information without restarting the host machine, the method addresses the challenge of inadequate timely kernel vulnerability repair in container environments, enhancing container security.
Patent Information
- Application Number
- CN202011547716.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-12-23
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2040-12-23
AI Technical Summary
In container deployment, when repairing kernel vulnerabilities, it is necessary to restart the host's kernel, resulting in poor repair timeliness and affecting the security of the container.
The kernel version information and device information are determined through the second container component, sent to the kernel hot patch storage terminal, and received and installed kernel hot patches to achieve vulnerability repair without restarting the host kernel.
Improves the security of the container, realizes timely repair of kernel vulnerabilities, and avoids restart delays caused by excessive host load.
Smart Images

Figure CN113721934B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present disclosure relate to the field of computer technologies, and more particularly, to a method and apparatus for installing a hot patch, an electronic device, and a computer-readable medium. Background Art
[0002] With the rapid development of computer technologies, container technologies have emerged, featuring fast startup and convenient deployment. Currently, when deploying containers, the commonly adopted approach is to deploy multiple containers on the same host, enabling the containers running on the same host to share the host's kernel.
[0003] However, when deploying containers in the above manner, the following technical problems often occur: When repairing kernel vulnerabilities, it is necessary to restart the kernel of the container host. Since there are many loads running in the container host, it is difficult to promptly restart the kernel of the container host to repair the kernel vulnerabilities, resulting in poor timeliness of kernel vulnerability repair and thus poor security of the containers. Summary of the Invention
[0004] This section of the present disclosure is used to briefly introduce concepts that will be described in detail in the subsequent detailed implementation section. This section of the present disclosure is not intended to identify the key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.
[0005] Some embodiments of the present disclosure propose a method and apparatus for installing a hot patch, an electronic device, and a computer-readable medium to solve one or more of the technical problems mentioned in the above background art section.
[0006] In a first aspect, some embodiments of the present disclosure provide a method for installing a hot patch. The method includes: in response to a hot patch request from a first container component, determining kernel version information and device information corresponding to the hot patch request through a second container component corresponding to the first container component; sending the kernel version information and the device information to a corresponding kernel hot patch storage terminal through the second container component to receive a kernel hot patch corresponding to the kernel version information; and in response to receiving the kernel hot patch, performing an installation process on the kernel hot patch through the second container component.
[0007] Optionally, before performing the installation process on the kernel hot patch, the method further includes: receiving hot patch signature information corresponding to the kernel hot patch.
[0008] Optionally, before performing the installation process on the above kernel hot patch, the above method further includes: based on the above hot patch signature information, through the above second container component, verifying the above kernel hot patch to generate a verification result, where the above verification result is used to represent verification success or verification failure.
[0009] Optionally, the above installation process on the above kernel hot patch includes: based on the above verification result, through the above second container component, performing the installation process on the above kernel hot patch.
[0010] Optionally, the above installation process on the above kernel hot patch based on the above verification result includes: in response to the above verification result indicating verification success, through the above second container component, loading the above kernel hot patch into the kernel corresponding to the above kernel version information.
[0011] Optionally, the above installation process on the above kernel hot patch based on the above verification result includes: in response to the above verification result indicating verification failure, through the above first container component, generating a hot patch request.
[0012] Optionally, after the above verification of the above kernel hot patch to generate a verification result, the above method further includes: in response to the above verification result indicating verification success, through the above second container component, storing first preset information into the above first container component.
[0013] Optionally, after the above verification of the above kernel hot patch to generate a verification result, the above method further includes: in response to the above verification result indicating verification failure, through the above second container component, storing second preset information into the above first container component.
[0014] In a second aspect, some embodiments of the present disclosure provide a hot patch installation device, the device includes: a determination unit configured to, in response to a hot patch request of a first container component, through a second container component corresponding to the above first container component, determine kernel version information and device information corresponding to the above hot patch request; a sending unit configured to send the above kernel version information and the above device information to a corresponding kernel hot patch storage terminal to receive a kernel hot patch corresponding to the above kernel version information; an installation unit configured to, in response to receiving the above kernel hot patch, through the above second container component, perform an installation process on the above kernel hot patch.
[0015] Optionally, before the installation unit, the device further includes: a receiving unit configured to receive hot patch signature information corresponding to the above kernel hot patch.
[0016] Optionally, before installing the unit, the device further includes: a verification unit configured to verify the kernel hot patch based on the above-mentioned hot patch signature information through the above-mentioned second container component to generate a verification result, where the verification result is used to indicate verification success or failure.
[0017] Optionally, the installation unit includes: an installation processing unit configured to perform an installation process on the kernel hot patch based on the above-mentioned verification result through the above-mentioned second container component.
[0018] Optionally, the installation processing unit is further configured to: in response to the verification result indicating verification success, load the kernel hot patch into the kernel corresponding to the above-mentioned kernel version information through the above-mentioned second container component.
[0019] Optionally, the installation processing unit is further configured to: in response to the verification result indicating verification failure, generate a hot patch request through the above-mentioned first container component.
[0020] Optionally, after the verification unit, the device further includes: a first storage unit configured to store first preset information into the above-mentioned first container component through the above-mentioned second container component in response to the verification result indicating verification success.
[0021] Optionally, after the verification unit, the device further includes: a second storage unit configured to store second preset information into the above-mentioned first container component through the above-mentioned second container component in response to the verification result indicating verification failure.
[0022] In a third aspect, some embodiments of the present disclosure provide an electronic device, including: one or more processors; a storage device storing one or more programs thereon, and when the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any implementation manner of the above first aspect.
[0023] In a fourth aspect, some embodiments of the present disclosure provide a computer-readable medium storing a computer program thereon, where the program implements the method described in any implementation manner of the above first aspect when executed by a processor.
[0024] The above-mentioned various embodiments of the present disclosure have the following beneficial effects: Through the hot patch installation method of some embodiments of the present disclosure, the security of the container is improved. Specifically, the reason for the poor security of the container is that when repairing the kernel vulnerability, it is necessary to restart the kernel of the container's host. Since there are many loads running in the container's host, it is difficult to restart the kernel of the container's host in a timely manner to repair the kernel vulnerability, resulting in poor timeliness of kernel vulnerability repair. Based on this, the hot patch installation method of some embodiments of the present disclosure sends the kernel version information and device information to the corresponding kernel hot patch storage terminal through the second container component to receive the kernel hot patch corresponding to the above kernel version information. In response to receiving the above kernel hot patch, the second container component is used to install and process the above kernel hot patch. Also because the second container component processes the hot patch request of the first container component, the kernel vulnerability is repaired in a timely manner without restarting the kernel of the container's host. Furthermore, the security of the container is improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In combination with the accompanying drawings and with reference to the following specific embodiments, the above and other features, advantages, and aspects of the various embodiments of the present disclosure will become more apparent. Throughout the accompanying drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic and the elements and elements are not necessarily drawn to scale.
[0026] Figure 1-2 is a schematic diagram of an application scenario of a hot patch installation method according to some embodiments of the present disclosure;
[0027] Figure 3 is a flowchart of some embodiments of the hot patch installation method according to the present disclosure;
[0028] Figure 4 is a flowchart of some other embodiments of the hot patch installation method according to the present disclosure;
[0029] Figure 5 is a schematic structural diagram of some embodiments of the hot patch installation device according to the present disclosure;
[0030] Figure 6 is a schematic structural diagram of an electronic device suitable for implementing some embodiments of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0031] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for illustrative purposes and are not used to limit the protection scope of the present disclosure.
[0032] In addition, it should be noted that for ease of description, only parts related to the relevant invention are shown in the drawings. Without conflict, the embodiments in the present disclosure and the features in the embodiments can be combined with each other.
[0033] It should be noted that the concepts such as "first", "second", etc. mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence relationship of the functions performed by these devices, modules or units.
[0034] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly specified in the context, it should be understood as "one or more".
[0035] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only for illustrative purposes and are not used to limit the scope of these messages or information.
[0036] The present disclosure will be described in detail below with reference to the drawings and in combination with embodiments.
[0037] Figure 1-2 It is a schematic diagram of an application scenario of a hot patch installation method according to some embodiments of the present disclosure.
[0038] In Figure 1In the application scenario, first, the computing device 101 can respond to the hot patch request 103 of the first container component 102 (which can be the "Docker Client container component"), and determine the kernel version information 105 (which can be "kernel version number: 2.6.0") and device information 106 (which can be "host number: 8") through the second container component 104 corresponding to the first container component 102. Then, the computing device 101 can send the kernel version information 105 and the device information 106 to the corresponding kernel hot patch storage terminal 107 through the second container component 104 to receive the kernel hot patch 108 corresponding to the kernel version information 105. Finally, the computing device 101 can respond to receiving the kernel hot patch 108 and perform an installation process on the kernel hot patch 108 through the second container component 104.
[0039] Optionally, as Figure 2 shown, the computing device 101 can receive the hot patch signature information 109 corresponding to the kernel hot patch 108. Optionally, the computing device 101 can verify the hot patch signature information 109 through the second container component 104 to generate a verification result 110. Among them, the verification result 110 is used to represent verification success or verification failure. Optionally, the computing device 101 can perform an installation process on the kernel hot patch 108 based on the verification result 110.
[0040] It should be noted that the above computing device 101 can be hardware or software. When the computing device is hardware, it can be implemented as a distributed cluster composed of multiple servers or terminal devices, or can be implemented as a single server or a single terminal device. When the computing device is embodied as software, it can be installed in the above-listed hardware devices. It can be implemented as, for example, multiple software or software modules for providing distributed services, or can be implemented as a single software or software module. No specific limitation is made here.
[0041] It should be understood that Figure 1-2 the number of computing devices in
[0042] Continuing to refer to Figure 3 , a flow 300 of some embodiments of the hot patch installation method according to the present disclosure is shown. The hot patch installation method includes the following steps:
[0043] Step 301, in response to a hot patch request of a first container component, determine kernel version information and device information corresponding to the hot patch request through a second container component corresponding to the first container component.
[0044] In some embodiments, the execution entity of the hot patch installation method (e.g., Figure 1 the computing device 101 shown) can, in response to a hot patch request from a first container component, determine kernel version information and device information corresponding to the hot patch request through a second container component corresponding to the first container component. Among them, the hot patch request can be a request for repairing a kernel vulnerability of the host of the container. The first container component can be a container for user use. For example, the first container component can be a "Docker Client container component". The second container component can be a container component for daemonizing container processes, and the first container component and the second container component exist in the same container. For example, the second container component can be a "Docker Daemon container component". The kernel version information can be the version information of the kernel corresponding to the kernel vulnerability corresponding to the hot patch request. It can include a kernel version number. For example, the kernel version number can be "2.6.0". The device information can be device-related information of the execution entity and can include a host number. For example, the host number can be "8". Thus, it can provide support for obtaining a kernel hot patch corresponding to the kernel version information from a kernel hot patch storage terminal.
[0045] Step 302, send the kernel version information and the device information to a corresponding kernel hot patch storage terminal through the second container component to receive a kernel hot patch corresponding to the kernel version information.
[0046] In some embodiments, the execution entity can send the kernel version information and the device information to a corresponding kernel hot patch storage terminal through the second container component to receive a kernel hot patch corresponding to the kernel version information. Among them, the kernel hot patch storage terminal can be a terminal for storing kernel hot patches. The kernel hot patch storage terminal can index the stored kernel hot patches through the kernel version information. Then, the kernel hot patch storage terminal can send the indexed kernel hot patch to the execution entity according to the device information. The kernel hot patch can be an installation package for repairing software functions and does not require restarting the terminal when installed.
[0047] In practice, first, the above-mentioned execution entity may send the kernel version information and the above-mentioned device information to the corresponding kernel hot patch storage terminal. Then, through a wired connection method or a wireless connection method, it may receive the kernel hot patch sent by the above-mentioned kernel hot patch storage terminal and corresponding to the above-mentioned kernel version information. It should be noted that the above-mentioned wireless connection method may include, but is not limited to, 3G / 4G / 5G connection, WiFi connection, Bluetooth connection, WiMAX connection, Zigbee connection, UWB (ultra wideband) connection, and other currently known or future-developed wireless connection methods. Thus, according to the determined kernel version information and device information, the kernel hot patch corresponding to the kernel version information can be obtained from the kernel hot patch storage terminal.
[0048] Step 303, in response to receiving the kernel hot patch, install and process the kernel hot patch through the second container component.
[0049] In some embodiments, the above-mentioned execution entity may, in response to receiving the above-mentioned kernel hot patch, install and process the above-mentioned kernel hot patch through the above-mentioned second container component. In practice, the above-mentioned execution entity may directly install the above-mentioned kernel hot patch through the above-mentioned second container component to repair the kernel vulnerability corresponding to the above-mentioned hot patch request. For example, the above-mentioned execution entity may directly execute the command "insmod" for installing the kernel module through the second container component to install the received kernel hot patch. Thus, when repairing the kernel vulnerability, it is possible to avoid restarting the kernel of the container's host machine.
[0050] The above-mentioned various embodiments of the present disclosure have the following beneficial effects: Through the hot patch installation method of some embodiments of the present disclosure, the security of the container is improved. Specifically, the reason for the poor security of the container is that when repairing the kernel vulnerability, it is necessary to restart the kernel of the container's host machine. Since there are many loads running in the container's host machine, it is difficult to restart the kernel of the container's host machine in a timely manner to repair the kernel vulnerability, resulting in poor timeliness of kernel vulnerability repair. Based on this, the hot patch installation method of some embodiments of the present disclosure sends the kernel version information and device information to the corresponding kernel hot patch storage terminal through the second container component to receive the kernel hot patch corresponding to the above-mentioned kernel version information. In response to receiving the above-mentioned kernel hot patch, install and process the above-mentioned kernel hot patch through the above-mentioned second container component. Also because the second container component processes the hot patch request of the first container component, it is possible to repair the kernel vulnerability in a timely manner without restarting the kernel of the container's host machine. Furthermore, the security of the container is improved.
[0051] Further reference Figure 4, which shows the process 400 of some other embodiments of the hot patch installation method. The process 400 of the hot patch installation method includes the following steps:
[0052] Step 401, in response to a hot patch request of a first container component, determine kernel version information and device information corresponding to the hot patch request through a second container component corresponding to the first container component.
[0053] Step 402, through the second container component, send the kernel version information and device information to a corresponding kernel hot patch storage terminal to receive a kernel hot patch corresponding to the kernel version information.
[0054] In some embodiments, the specific implementation of steps 401-402 and the technical effects brought can refer to Figure 3 steps 301-302 in the corresponding embodiments, which will not be elaborated here.
[0055] Step 403, receive hot patch signature information corresponding to the kernel hot patch.
[0056] In some embodiments, the execution subject of the hot patch installation method (such as Figure 1 the computing device 101 shown) can receive the hot patch signature information corresponding to the kernel hot patch from the above-mentioned kernel hot patch storage terminal through a wired connection method or a wireless connection method. Wherein the above-mentioned hot patch signature information can be a string generated by signing the above-mentioned kernel hot patch using a signature algorithm. For example, the above-mentioned signature algorithm can be the Rabin signature algorithm. The above-mentioned signature algorithm can also be the DSS (Digital Signature Standard) signature algorithm. The above-mentioned signature algorithm can also be the SHA256 (Secure Hash Algorithm 256) signature algorithm. It should be noted that the above-mentioned wireless connection method can include but is not limited to 3G / 4G / 5G connection, WiFi connection, Bluetooth connection, WiMAX connection, Zigbee connection, UWB (ultra wideband) connection, and other currently known or future-developed wireless connection methods. Thus, it can provide support for the security verification of the kernel hot patch.
[0057] Step 404, based on the hot patch signature information, verify the kernel hot patch through the second container component to generate a verification result.
[0058] In some embodiments, the above-mentioned execution entity may, based on the above-mentioned hot patch signature information, verify the above-mentioned kernel hot patch through the above-mentioned second container component to generate a verification result. The verification result may be used to indicate verification success or failure. In practice, the above-mentioned execution entity may, based on the above-mentioned hot patch signature information, verify the above-mentioned kernel hot patch through the above-mentioned second container component by using a verification algorithm corresponding to the signature algorithm for generating the above-mentioned hot patch signature information to generate a verification result. Thus, the received kernel hot patch can be securely verified according to the hot patch signature information.
[0059] As an example, the signature algorithm for generating the above-mentioned hot patch signature information may be the SHA256 signature algorithm. First, the above-mentioned execution entity may generate the SHA256 value of the above-mentioned kernel hot patch through the SHA256 signature algorithm. Then, in response to the SHA256 value being the same as the above-mentioned hot patch signature information, a verification result indicating verification success may be generated. In response to the SHA256 value being different from the above-mentioned hot patch signature information, a verification result indicating verification failure may be generated.
[0060] In some optional implementation manners of some embodiments, the above-mentioned execution entity may, in response to the verification result indicating verification success, store first preset information in the above-mentioned first container component through the above-mentioned second container component. The first preset information may be information indicating that the verification result of the above-mentioned kernel hot patch indicates verification success. For example, the first preset information may be "True", and "True" indicates that the verification result of the above-mentioned kernel hot patch indicates verification success.
[0061] In some optional implementation manners of some embodiments, the above-mentioned execution entity may, in response to the verification result indicating verification failure, store second preset information in the above-mentioned first container component through the above-mentioned second container component. The second preset information may be information indicating that the verification result of the above-mentioned kernel hot patch indicates verification failure. For example, the second preset information may be "False", and "False" indicates that the verification result of the above-mentioned kernel hot patch indicates verification failure.
[0062] Step 405, based on the verification result, perform an installation process on the kernel hot patch through the second container component.
[0063] In some embodiments, the above-mentioned execution entity may, based on the above-mentioned verification result, perform an installation process on the above-mentioned kernel hot patch through the above-mentioned second container component. In practice, the above-mentioned execution entity may, in response to the verification result indicating verification success, load the above-mentioned kernel hot patch into the kernel corresponding to the above-mentioned kernel version information.
[0064] In some alternative implementations of some embodiments, the above-mentioned execution entity may install the above-mentioned kernel hot patch through the following steps:
[0065] First, in response to the verification result indicating successful verification, load the above-mentioned kernel hot patch into the kernel corresponding to the above-mentioned kernel version information. For example, the above-mentioned execution entity may execute the command "insmod" for installing a kernel module through the above-mentioned second container component to load the above-mentioned kernel hot patch into the kernel corresponding to the above-mentioned kernel version information.
[0066] Second, in response to the verification result indicating failed verification, generate a hot patch request through the above-mentioned first container component. It can be understood that the generated hot patch request can be used as the latest hot patch request, enabling the above-mentioned execution entity to execute step 401.
[0067] Since the security of the kernel hot patch with successful verification is relatively high, through step 405, the kernel hot patch with successful verification can be loaded, thereby improving the security of the container.
[0068] From Figure 4 it can be seen that compared with the description of some corresponding embodiments of Figure 3 , the process 400 of the hot patch installation method in some corresponding embodiments of Figure 4 embodies the steps of expanding the installation process of the above-mentioned kernel hot patch. Thus, the solutions described in these embodiments can load the kernel hot patch with successful verification, thereby improving the security of the container.
[0069] Further referring to Figure 5 , as an implementation of the methods shown in the above figures, the present disclosure provides some embodiments of a hot patch installation device. These device embodiments correspond to those method embodiments shown in Figure 3 , and the device can be specifically applied to various electronic devices.
[0070] As shown in Figure 5 , some embodiments of the hot patch installation device 500 include: a determination unit 501, a sending unit 502, and an installation unit 503. Among them, the determination unit 501 is configured to, in response to a hot patch request of the first container component, determine the kernel version information and device information corresponding to the hot patch request through the second container component corresponding to the first container component; the sending unit 502 is configured to send the kernel version information and the device information to the corresponding kernel hot patch storage terminal to receive the kernel hot patch corresponding to the kernel version information; the installation unit 503 is configured to, in response to receiving the kernel hot patch, install the kernel hot patch through the second container component.
[0071] In an alternative implementation of some embodiments, before the installation unit 503, the hot patch installation device 500 may further include: a receiving unit (not shown in the figure), configured to receive hot patch signature information corresponding to the above-mentioned kernel hot patch.
[0072] In an alternative implementation of some embodiments, before the installation unit 503, the hot patch installation device 500 may further include: a verification unit (not shown in the figure), configured to verify the above-mentioned kernel hot patch based on the above-mentioned hot patch signature information through the above-mentioned second container component to generate a verification result, where the verification result is used to indicate verification success or failure.
[0073] In an alternative implementation of some embodiments, the installation unit 503 of the hot patch installation device 500 may include: an installation processing unit (not shown in the figure), configured to perform an installation process on the above-mentioned kernel hot patch based on the above-mentioned verification result through the above-mentioned second container component.
[0074] In an alternative implementation of some embodiments, the installation processing unit may be further configured to: in response to the above-mentioned verification result indicating verification success, load the above-mentioned kernel hot patch into the kernel corresponding to the above-mentioned kernel version information through the above-mentioned second container component.
[0075] In an alternative implementation of some embodiments, the installation processing unit may be further configured to: in response to the above-mentioned verification result indicating verification failure, generate a hot patch request through the above-mentioned first container component.
[0076] In an alternative implementation of some embodiments, after the verification unit, the hot patch installation device 500 may further include: a first storage unit (not shown in the figure), configured to store first preset information into the above-mentioned first container component through the above-mentioned second container component in response to the above-mentioned verification result indicating verification success.
[0077] In an alternative implementation of some embodiments, after the verification unit, the hot patch installation device 500 may further include: a second storage unit (not shown in the figure), configured to store second preset information into the above-mentioned first container component through the above-mentioned second container component in response to the above-mentioned verification result indicating verification failure.
[0078] It can be understood that the various units described in the device 500 correspond to the respective steps in the method described with reference to Figure 3 Therefore, the operations, features, and beneficial effects described above for the method also apply to the device 500 and the units included therein, and will not be repeated here.
[0079] Next, with reference to Figure 6, which shows a schematic structural diagram of an electronic device (such as the computing device 101 in Figure 1 ) 600 suitable for use in implementing some embodiments of the present disclosure. Figure 6 The electronic device shown is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.
[0080] As Figure 6 shown, the electronic device 600 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 601, which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage device 608 into a random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the electronic device 600 are also stored. The processing device 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0081] Generally, the following devices may be connected to the I / O interface 605: an input device 606 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 607 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 608 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 609. The communication device 609 may allow the electronic device 600 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 6 shows the electronic device 600 having various devices, it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices may be implemented or had. Figure 6 Each block shown in
[0082] may represent a device or, as needed, multiple devices.
[0083] It should be noted that the computer-readable media described in some embodiments of the present disclosure may be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In some embodiments of the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program, and this program can be used by or in conjunction with an instruction execution system, apparatus, or device. In some embodiments of the present disclosure, the computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium may also be any computer-readable medium other than the computer-readable storage medium, and this computer-readable signal medium can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
[0084] In some embodiments, the client and the server can communicate using any currently known or future-developed network protocol such as HTTP (HyperText Transfer Protocol), and can be interconnected with digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include local area networks ("LAN"), wide area networks ("WAN"), the Internet (e.g., the Internet), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed network.
[0085] The above computer-readable medium may be included in the above electronic device; or may exist independently without being assembled into the electronic device. The above computer-readable medium carries one or more programs. When the one or more programs are executed by the electronic device, the electronic device is caused to: in response to a hot patch request of a first container component, determine kernel version information and device information corresponding to the hot patch request through a second container component corresponding to the first container component; send the kernel version information and the device information to a corresponding kernel hot patch storage terminal through the second container component to receive a kernel hot patch corresponding to the kernel version information; and in response to receiving the kernel hot patch, perform an installation process on the kernel hot patch through the second container component.
[0086] Computer program code for performing the operations of some embodiments of the present disclosure may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computer, partially on the user's computer, execute as a stand-alone software package, execute partially on the user's computer and partially on a remote computer, or execute entirely on the remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).
[0087] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in an order different from that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.
[0088] The units described in some embodiments of the present disclosure can be implemented in software or in hardware. The described units can also be provided in a processor. For example, it can be described as: a processor includes a determination unit, a sending unit, and an installation unit. Among them, the names of these units do not constitute a limitation on the unit itself in some cases. For example, the determination unit can also be described as "a unit that determines the kernel version information and device information corresponding to the hot patch request by means of a second container component corresponding to the first container component in response to the hot patch request of the first container component".
[0089] The functions described above can be performed, at least in part, by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that can be used include: Field Programmable Gate Array (FPGA), Application Specific Integrated Circuit (ASIC), Application Specific Standard Product (ASSP), System on Chip (SOC), Complex Programmable Logic Device (CPLD), and so on.
[0090] The above description is only some preferred embodiments of the present disclosure and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above inventive concept. For example, the technical solutions formed by mutually replacing the above features with the (but not limited to) technical features with similar functions disclosed in the embodiments of the present disclosure.
Claims
1. A hot patch installation method, comprising: Responding to a hot patch request of a first container component, determining kernel version information and device information corresponding to the hot patch request through a second container component corresponding to the first container component, wherein the first container component is a container for user use, the second container component is a container component for daemonizing container processes, and the first container component and the second container component exist in the same container; Sending, through the second container component, the kernel version information and the device information to a corresponding kernel hot patch storage terminal to receive a kernel hot patch corresponding to the kernel version information; Responding to receiving the kernel hot patch, performing an installation process on the kernel hot patch through the second container component, wherein performing the installation process on the kernel hot patch through the second container component includes: directly executing a command for installing a kernel module through the second container component to install the received kernel hot patch.
2. The method according to claim 1, wherein, Before performing the installation process on the kernel hot patch, the method further includes: Receiving hot patch signature information corresponding to the kernel hot patch.
3. The method according to claim 2, wherein Before performing the installation process on the kernel hot patch, the method further includes: Based on the hot patch signature information, performing a verification on the kernel hot patch through the second container component to generate a verification result, wherein the verification result is used to indicate verification success or verification failure.
4. The method according to claim 3, wherein The performing the installation process on the kernel hot patch includes: Based on the verification result, performing an installation process on the kernel hot patch through the second container component.
5. The method according to claim 4, wherein The performing the installation process on the kernel hot patch based on the verification result includes: Responding to the verification result indicating verification success, loading the kernel hot patch into the kernel corresponding to the kernel version information through the second container component.
6. The method according to claim 4, wherein The performing the installation process on the kernel hot patch based on the verification result includes: Responding to the verification result indicating verification failure, generating a hot patch request through the first container component.
7. The method according to claim 3, wherein, After performing the verification on the kernel hot patch to generate a verification result, the method further includes: Responding to the verification result indicating verification success, storing first preset information into the first container component through the second container component.
8. The method according to claim 3, wherein, After performing the verification on the kernel hot patch to generate a verification result, the method further includes: Responding to the verification result indicating verification failure, storing second preset information into the first container component through the second container component.
9. A hot patch installation device, comprising: A determination unit configured to respond to a hot patch request of a first container component, and determine kernel version information and device information corresponding to the hot patch request through a second container component corresponding to the first container component, wherein the first container component is a container for user use, the second container component is a container component for daemonizing container processes, and the first container component and the second container component exist in the same container; A sending unit, configured to send the kernel version information and the device information to a corresponding kernel hot patch storage terminal to receive a kernel hot patch corresponding to the kernel version information; An installation unit, configured to, in response to receiving the kernel hot patch, perform an installation process on the kernel hot patch through the second container component, wherein the performing an installation process on the kernel hot patch through the second container component includes: directly executing a command for installing a kernel module through the second container component to install the received kernel hot patch.
10. An electronic device, comprising: One or more processors; A storage device on which one or more programs are stored; When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1-8.
11. A computer-readable medium having a computer program stored thereon, wherein, When the program is executed by the processor, the method according to any one of claims 1-8 is implemented.
Citation Information
Patent Citations
Kernel vulnerability restoration method, device, server and system
CN109409096A