A method, device, equipment and readable medium for allocating source ports
By creating a port allocation pool on a Linux server and limiting the allocation range, the problem of filtering restrictions on random allocation source ports is solved, and the stable connection between Samba service and domain controller is achieved.
Patent Information
- Application Number
- CN202111098296.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-18
- Publication Date
- 2025-05-02
- Estimated Expiration
- 2041-09-18
AI Technical Summary
When deploying Samba service on Linux servers, randomly allocated source ports are affected by non-known port filtering restrictions, resulting in restricted SMB, RPC, and LDAP connections to domain controllers.
By creating a port allocation pool, limiting the port allocation range in the firewall's whitelist, and using a bidirectional ring queue to manage port allocation, ensuring that the port resources are allocated within a fixed range and ensuring that the ports that have been released by the system can be used normally by the Samba service.
It realizes effective allocation and management of port resources to ensure that Samba service can connect and communicate with the domain controller normally, avoiding connection problems caused by port restrictions.
Smart Images

Figure CN113821343B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computers, and more particularly to a method, device, equipment and readable medium for allocating source ports. Background Art
[0002] The domain controller maintains global domain user configuration data, including domain user account names, passwords, group policy configurations, etc. Each user can be assigned different host resource access permissions. When a user logs in from a client, the domain controller first verifies whether the client belongs to the domain, and then verifies the correctness of the username and password.
[0003] The protocols for interaction between the client and the Windows domain controller mainly include SMB (a shared transmission protocol used between different network nodes), RPC (remote procedure call, used for inter-process communication in distributed operating systems), and LDAP (a lightweight directory access protocol, providing a directory access protocol). The SMB protocol uses port 445, mainly to obtain some basic information of the system through IPC shared communication; RPC calls use port 135 to connect to the domain controller Endpoint Mapper service, and the domain controller Endpoint Mapper service further allocates a dynamic random port to the client program, and the client program finally connects to the dynamic random port to complete various calls of RPC functions; the LDAP protocol uses port 389, which is mainly used to complete various configurations and queries related to the AD domain.
[0004] Samba (an application that implements the SMB protocol and is used to provide sharing services from a Linux server to a Windows client) acts as an SMB server, but when it joins an AD (Active Directory, a storage protocol for user configuration management based on LDAP) domain, it acts as a client relative to the domain controller. The source ports for SMB connections, RPC connections, or LDAP connections to the domain controller are randomly assigned. Since Samba is usually deployed on a Linux server, when filtering restrictions on non-well-known ports are enabled on the Linux server, the use of source ports for interacting with the domain controller will be affected. Summary of the invention
[0005] In view of this, the purpose of the present invention is to propose a method, device, equipment and readable medium for source port allocation. By using the technical solution of the present invention, it is possible to ensure that the allocation of port resources is limited to a fixed range, and to ensure that the ports released by the system can be used normally by the Samba service.
[0006] Based on the above purpose, one aspect of the present invention provides a method for allocating source ports, comprising the following steps:
[0007] Create a port allocation pool and initialize the port allocation pool;
[0008] In response to each connection resource being initialized, initializing the parameters of the connection resource and applying for an available port from a port allocation pool;
[0009] In response to the port allocation pool allocating an available port to the connection resource and the connection resource being successfully bound to the available port, marking the allocated port in the port allocation pool and moving a head pointer of the port allocation pool to a next unallocated port;
[0010] In response to the completion of the port connection of each connection resource, the net tool and the Winbind service initiate a connection to the domain controller so that each connection handle provides the required service.
[0011] According to one embodiment of the present invention, creating a port allocation pool and initializing the port allocation pool includes:
[0012] Create a port allocation pool consisting of a bidirectional ring queue and limit the port allocation range to the firewall's whitelist;
[0013] Create a structure array based on the set port range. The array element of each port contains the user identity and port usage status.
[0014] Create a head pointer and a tail pointer, the head pointer points to the first unallocated port, and the tail pointer points to the first allocated port.
[0015] According to an embodiment of the present invention, the user identities include NONE, SMB connection, RPC connection, LDAP connection and OTHER.
[0016] According to an embodiment of the present invention, each connection resource includes an SMB connection, an RPC connection and an LDAP connection.
[0017] According to an embodiment of the present invention, in response to each connection resource being initialized, initializing the parameters of the connection resource and applying for an available port from the port allocation pool includes:
[0018] After initializing the SMB connection parameters, apply for an available port resource from the port allocation pool;
[0019] After initializing the RPC connection parameters, apply for an available port resource from the port allocation pool;
[0020] After initializing the URL path of the LDAP connection, apply for an available port resource from the port allocation pool.
[0021] According to one embodiment of the present invention, in response to the port allocation pool allocating an available port to a connection resource and the connection resource being successfully bound to the available port, marking the allocated port in the port allocation pool and moving the head pointer of the port allocation pool to the next unallocated port includes:
[0022] The SMB connection attempts to bind the port resources allocated by the port allocation pool;
[0023] In response to the binding success, the SMB connects to the port and marks the allocated port as occupied in the port allocation pool and moves the head pointer of the port allocation pool to the next unallocated port;
[0024] The RPC connection attempts to bind the port resources allocated by the port allocation pool;
[0025] In response to the binding success, the RPC connects to the port and marks the allocated port as occupied in the port allocation pool and moves the head pointer of the port allocation pool to the next unallocated port;
[0026] The LDAP connection attempts to bind to the port resources allocated by the port allocation pool;
[0027] In response to successful binding, LDAP connects to the port and marks the allocated port as occupied in the port allocation pool and moves the head pointer of the port allocation pool to the next unallocated port.
[0028] According to one embodiment of the present invention, it also includes:
[0029] In response to the port allocation pool allocating an available port to the connection resource and the connection resource failing to bind to the available port, marking the user identity of the port that failed to bind as OTHER and setting the port state to BUSY;
[0030] Start the timer and set the timer period to 30 seconds;
[0031] In response to the timer completing a timing cycle, traversing and testing port elements in the port allocation pool whose user identity is OTHER;
[0032] In response to the port with the user identity of OTHER being released, the port element and the port element where the tail pointer is located are exchanged, and the port is marked as idle.
[0033] Another aspect of the embodiments of the present invention further provides a device for allocating source ports, the device comprising:
[0034] A creation module is configured to create a port allocation pool and initialize the port allocation pool;
[0035] An initialization module, the initialization module is configured to respond to each connection resource for initialization, initialize the parameters of the connection resource and apply for an available port from the port allocation pool;
[0036] a marking module, the marking module being configured to, in response to the port allocation pool allocating an available port to the connection resource and the connection resource being successfully bound to the available port, mark the allocated port in the port allocation pool and move a head pointer of the port allocation pool to the next unallocated port;
[0037] The connection module is configured to respond to the completion of the port connection of each connection resource, and the net tool and Winbind service initiate a connection to the domain controller so that each connection handle provides the required service.
[0038] Another aspect of the embodiments of the present invention further provides a computer device, the computer device comprising:
[0039] at least one processor; and
[0040] The memory stores computer instructions executable on the processor, and the instructions implement the steps of any one of the above methods when executed by the processor.
[0041] According to another aspect of the embodiments of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of any one of the above methods are implemented.
[0042] The present invention has the following beneficial technical effects: the source port allocation method provided by the embodiment of the present invention creates a port allocation pool and initializes the port allocation pool; in response to each connection resource being initialized, the connection resource parameters are initialized and an available port is applied to the port allocation pool; in response to the port allocation pool allocating an available port to the connection resource and the connection resource is successfully bound to the available port, the allocated port is marked in the port allocation pool and the head pointer of the port allocation pool is moved to the next unallocated port; in response to the completion of the port connection of each connection resource, the net tool and the Winbind service initiate a connection to the domain controller so that each connection handle provides the service required by each connection handle. The technical solution can ensure that the allocation of port resources can be limited within a fixed range and can ensure that the port released by the system can be normally used by the Samba service. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For ordinary technicians in this field, other embodiments can be obtained based on these drawings without paying creative work.
[0044] Figure 1 A schematic flow chart of a method for allocating source ports according to an embodiment of the present invention;
[0045] Figure 2 A schematic diagram of a source port allocation device according to an embodiment of the present invention;
[0046] Figure 3 is a schematic diagram of a computer device according to an embodiment of the present invention;
[0047] Figure 4 FIG. 1 is a schematic diagram of a computer-readable storage medium according to an embodiment of the present invention. DETAILED DESCRIPTION
[0048] In order to make the objectives, technical solutions and advantages of the present invention more clearly understood, the embodiments of the present invention are further described in detail below in combination with specific embodiments and with reference to the accompanying drawings.
[0049] Based on the above purpose, a first aspect of an embodiment of the present invention provides an embodiment of a method for allocating source ports. Figure 1 Shown is a schematic flow chart of the method.
[0050] like Figure 1 As shown in , the method may include the following steps:
[0051] S1 creates a port allocation pool and initializes the port allocation pool.
[0052] The port allocation pool consists of a bidirectional circular queue. The queue head pointer specifies the first unallocated port element, and the queue tail pointer points to the first allocated element. Whenever a port is allocated, the allocated port is automatically marked as occupied, and the head pointer automatically moves backward and points to the next unallocated port element. Whenever a port is released, the released port is automatically marked as idle, and the head pointer automatically moves backward and points to the next occupied port element. The port allocation range is limited to the firewall's whitelist. The port user identities include NONE, SMB, RPC, LDAP, and OTHER. OTHER is used to mark the current port as occupied by the system. The port usage status includes occupied and idle states.
[0053] S2 initializes the parameters of the connection resources in response to the initialization of each connection resource and applies for an available port from the port allocation pool.
[0054] Each connection resource includes an SMB connection, an RPC connection, and an LDAP connection. During the initialization of these resources, an available port will be requested from the port allocation pool respectively.
[0055] In response to the port allocation pool allocating an available port to the connection resource and the connection resource being successfully bound to the available port, S3 marks the allocated port in the port allocation pool and moves the head pointer of the port allocation pool to the next unallocated port.
[0056] S4 responds to the completion of the port connection of each connection resource, and the net tool and Winbind service initiate a connection to the domain controller so that each connection handle can provide the required services.
[0057] The interactive process involved in joining a domain using the net tool mainly includes parsing parameters such as the domain name, user name, and password when joining the domain, and then using the DNS service to query the full domain controller name relative to the domain name, and then using the full domain controller name when referencing the domain controller identifier; initiating a 445 port connection to the domain controller and requesting a $IPC shared connection, and then opening some IPC handles based on the shared connection, such as obtaining group policy information, etc.; initiating a 389 port connection to the domain controller, constructing its own NETBIOS name and the host domain name of the domain controller into a full domain name that conforms to the LDAP protocol format, and then requesting an add operation to the domain controller, thereby making the Samba server a client member of the domain controller. The Winbind service is mainly used for connection query operations with the domain controller. The main interaction process includes initiating a 445 port connection to the domain controller and requesting a $IPC shared connection, and then opening some IPC handles based on the shared connection, such as obtaining group policy information; initiating a 135 port connection to the domain controller and requesting an RPC dynamic port; after the server returns a new RPC dynamic port, Winbind initiates a new connection to the dynamic port for various remote RPC interactions; initiating a 389 port connection to the domain controller to establish an LDAP protocol channel. When the above interaction process is completed, each protocol connection is closed normally. When the connection is closed, the port resources are released and marked as idle. When the port is marked as idle, it needs to be exchanged with the position of the tail pointer to maintain the continuity of the distribution interval of occupied ports and idle ports in the port allocation pool.
[0058] Through the technical solution of the present invention, it can be ensured that the allocation of port resources can be limited within a fixed range, and it can be ensured that the ports released by the system can be normally used by the Samba service.
[0059] In a preferred embodiment of the present invention, creating a port allocation pool and initializing the port allocation pool includes:
[0060] Create a port allocation pool consisting of a bidirectional ring queue and limit the port allocation range to the firewall's whitelist;
[0061] Create a structure array based on the set port range. The array element of each port contains the user identity and port usage status.
[0062] Create a head pointer and a tail pointer, the head pointer points to the first unassigned port, and the tail pointer points to the first allocated port. If the port is bound or released, the head pointer and the tail pointer are adjusted accordingly.
[0063] In a preferred embodiment of the present invention, the user identities include NONE, SMB connection, RPC connection, LDAP connection and OTHER.
[0064] In a preferred embodiment of the present invention, each connection resource includes an SMB connection, an RPC connection and an LDAP connection.
[0065] In a preferred embodiment of the present invention, in response to each connection resource being initialized, initializing the parameters of the connection resource and applying for an available port from the port allocation pool comprises:
[0066] After initializing the SMB connection parameters, apply for an available port resource from the port allocation pool;
[0067] After initializing the RPC connection parameters, apply for an available port resource from the port allocation pool;
[0068] After initializing the URL path of the LDAP connection, apply for an available port resource from the port allocation pool.
[0069] In a preferred embodiment of the present invention, in response to the port allocation pool allocating an available port to the connection resource and the connection resource being successfully bound to the available port, marking the allocated port in the port allocation pool and moving the head pointer of the port allocation pool to the next unallocated port comprises:
[0070] The SMB connection attempts to bind the port resources allocated by the port allocation pool;
[0071] In response to the binding success, the SMB connects to the port and marks the allocated port as occupied in the port allocation pool and moves the head pointer of the port allocation pool to the next unallocated port;
[0072] The RPC connection attempts to bind the port resources allocated by the port allocation pool;
[0073] In response to the binding success, the RPC connects to the port and marks the allocated port as occupied in the port allocation pool and moves the head pointer of the port allocation pool to the next unallocated port;
[0074] The LDAP connection attempts to bind to the port resources allocated by the port allocation pool;
[0075] In response to successful binding, LDAP connects to the port and marks the allocated port as occupied in the port allocation pool and moves the head pointer of the port allocation pool to the next unallocated port.
[0076] SMB protocol connection initialization and SMB connection source port allocation, the initialization parameters mainly include TCP parameter initialization and SMB parameter initialization. TCP parameter initialization includes source port allocation, protocol version selection, etc. SMB parameter initialization includes the negotiation parameters required to establish an IPC connection with the domain controller. For SMB source port allocation, first request an available source port from the port allocation pool, then establish a socket and try to bind. If the binding is successful, set the port user to SMB and set the status to occupied. If the binding fails, it means that the current port is occupied by the system, mark its user as OTHER, and set the status to occupied. RPC protocol connection initialization and RPC connection source port allocation, this process will first connect to the domain controller port 135, wait for the domain controller to return a new random RPC dynamic port, and then connect to the RPC dynamic port again. The port user identity set in the previous and next steps is RPC, and the status is set to occupied. LDAP protocol connection initialization and LDAP connection source port allocation, the source port allocation in this process passes the SMB connection source port allocation rule, the user identity of the port element is marked as LDAP, and the status is set to occupied.
[0077] In a preferred embodiment of the present invention, it also includes:
[0078] In response to the port allocation pool allocating an available port to the connection resource and the connection resource failing to bind to the available port, marking the user identity of the port that failed to bind as OTHER and setting the port state to BUSY;
[0079] Start the timer and set the timer period to 30 seconds;
[0080] In response to the timer completing a timing cycle, traversing and testing port elements in the port allocation pool whose user identity is OTHER;
[0081] In response to the port with the user identity of OTHER being released, the port element and the port element where the tail pointer is located are exchanged, and the port is marked as idle.
[0082] When allocating a port, the port allocation pool constructs a SOCKET test handle and uses the bind mechanism to determine whether the port is occupied. If bind succeeds, it means that the port is available and the test handle is closed. If bind fails, the port user identity is marked as OTHER and the port state is set to BUSY. When the port is occupied by the system, the timer is started and the timer period is set to 30 seconds. After the timing period expires, the port elements with the user identity of OTHER in the port allocation pool are traversed and tested again. If they have been released, they are swapped with the tail pointer element and marked as IDLE. If there are still port resources in the BUSY state of OTHER users in the port allocation pool after one traversal is completed, the next timer is automatically started.
[0083] Through the technical solution of the present invention, it can be ensured that the allocation of port resources can be limited within a fixed range, and it can be ensured that the ports released by the system can be normally used by the Samba service.
[0084] It should be noted that a person of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment method can be implemented by instructing the relevant hardware through a computer program, and the above-mentioned program can be stored in a computer-readable storage medium, and when the program is executed, it can include the processes of the embodiments of the above-mentioned methods. The storage medium can be a disk, an optical disk, a read-only memory (ROM) or a random access memory (RAM), etc. The above-mentioned computer program embodiment can achieve the same or similar effect as any of the above-mentioned method embodiments corresponding thereto.
[0085] In addition, the method disclosed in the embodiment of the present invention can also be implemented as a computer program executed by a CPU, and the computer program can be stored in a computer-readable storage medium. When the computer program is executed by the CPU, the above functions defined in the method disclosed in the embodiment of the present invention are performed.
[0086] Based on the above purpose, a second aspect of the embodiment of the present invention provides a device for allocating source ports, such as Figure 2 As shown, the device 200 includes:
[0087] A creation module 201, wherein the creation module 201 is configured to create a port allocation pool and initialize the port allocation pool;
[0088] Initialization module 202, the initialization module 202 is configured to respond to each connection resource for initialization, initialize the parameters of the connection resource and apply for an available port from the port allocation pool;
[0089] The marking module 203 is configured to mark the allocated port in the port allocation pool and move the head pointer of the port allocation pool to the next unallocated port in response to the port allocation pool allocating an available port to the connection resource and the connection resource being successfully bound to the available port;
[0090] The connection module 204 is configured to initiate a connection to the domain controller via the net tool and the Winbind service in response to the completion of the port connection of each connection resource so that each connection handle provides the required service.
[0091] Based on the above purpose, a third aspect of an embodiment of the present invention provides a computer device. Figure 3 FIG. 2 is a schematic diagram of an embodiment of a computer device provided by the present invention. Figure 3 As shown, the embodiment of the present invention includes the following apparatus: at least one processor 21; and a memory 22, the memory 22 stores computer instructions 23 that can be run on the processor, and when the instructions are executed by the processor, the following method is implemented:
[0092] Create a port allocation pool and initialize the port allocation pool;
[0093] In response to each connection resource being initialized, initializing the parameters of the connection resource and applying for an available port from a port allocation pool;
[0094] In response to the port allocation pool allocating an available port to the connection resource and the connection resource being successfully bound to the available port, marking the allocated port in the port allocation pool and moving a head pointer of the port allocation pool to a next unallocated port;
[0095] In response to the completion of the port connection of each connection resource, the net tool and the Winbind service initiate a connection to the domain controller so that each connection handle provides the required service.
[0096] In a preferred embodiment of the present invention, creating a port allocation pool and initializing the port allocation pool includes:
[0097] Create a port allocation pool consisting of a bidirectional ring queue and limit the port allocation range to the firewall's whitelist;
[0098] Create a structure array based on the set port range. The array element of each port contains the user identity and port usage status.
[0099] Create a head pointer and a tail pointer, the head pointer points to the first unallocated port, and the tail pointer points to the first allocated port.
[0100] In a preferred embodiment of the present invention, the user identities include NONE, SMB connection, RPC connection, LDAP connection and OTHER.
[0101] In a preferred embodiment of the present invention, each connection resource includes an SMB connection, an RPC connection and an LDAP connection.
[0102] In a preferred embodiment of the present invention, in response to each connection resource being initialized, initializing the parameters of the connection resource and applying for an available port from the port allocation pool comprises:
[0103] After initializing the SMB connection parameters, apply for an available port resource from the port allocation pool;
[0104] After initializing the RPC connection parameters, apply for an available port resource from the port allocation pool;
[0105] After initializing the URL path of the LDAP connection, apply for an available port resource from the port allocation pool.
[0106] In a preferred embodiment of the present invention, in response to the port allocation pool allocating an available port to the connection resource and the connection resource being successfully bound to the available port, marking the allocated port in the port allocation pool and moving the head pointer of the port allocation pool to the next unallocated port comprises:
[0107] The SMB connection attempts to bind the port resources allocated by the port allocation pool;
[0108] In response to the binding success, the SMB connects to the port and marks the allocated port as occupied in the port allocation pool and moves the head pointer of the port allocation pool to the next unallocated port;
[0109] The RPC connection attempts to bind the port resources allocated by the port allocation pool;
[0110] In response to the binding success, the RPC connects to the port and marks the allocated port as occupied in the port allocation pool and moves the head pointer of the port allocation pool to the next unallocated port;
[0111] The LDAP connection attempts to bind to the port resources allocated by the port allocation pool;
[0112] In response to successful binding, LDAP connects to the port and marks the allocated port as occupied in the port allocation pool and moves the head pointer of the port allocation pool to the next unallocated port.
[0113] In a preferred embodiment of the present invention, it also includes:
[0114] In response to the port allocation pool allocating an available port to the connection resource and the connection resource failing to bind to the available port, marking the user identity of the port that failed to bind as OTHER and setting the port state to BUSY;
[0115] Start the timer and set the timer period to 30 seconds;
[0116] In response to the timer completing a timing cycle, traversing and testing port elements in the port allocation pool whose user identity is OTHER;
[0117] In response to the port with the user identity of OTHER being released, the port element and the port element where the tail pointer is located are exchanged, and the port is marked as idle.
[0118] Based on the above purpose, a fourth aspect of an embodiment of the present invention provides a computer-readable storage medium. Figure 4 FIG. 2 is a schematic diagram of an embodiment of a computer-readable storage medium provided by the present invention. Figure 4 As shown, the computer readable storage medium 31 stores a computer program 32 that performs the following method when executed by a processor:
[0119] Create a port allocation pool and initialize the port allocation pool;
[0120] In response to each connection resource being initialized, initializing the parameters of the connection resource and applying for an available port from a port allocation pool;
[0121] In response to the port allocation pool allocating an available port to the connection resource and the connection resource being successfully bound to the available port, marking the allocated port in the port allocation pool and moving a head pointer of the port allocation pool to a next unallocated port;
[0122] In response to the completion of the port connection of each connection resource, the net tool and the Winbind service initiate a connection to the domain controller so that each connection handle provides the required service.
[0123] In a preferred embodiment of the present invention, creating a port allocation pool and initializing the port allocation pool includes:
[0124] Create a port allocation pool consisting of a bidirectional ring queue and limit the port allocation range to the firewall's whitelist;
[0125] Create a structure array based on the set port range. The array element of each port contains the user identity and port usage status.
[0126] Create a head pointer and a tail pointer, the head pointer points to the first unallocated port, and the tail pointer points to the first allocated port.
[0127] In a preferred embodiment of the present invention, the user identities include NONE, SMB connection, RPC connection, LDAP connection and OTHER.
[0128] In a preferred embodiment of the present invention, each connection resource includes an SMB connection, an RPC connection and an LDAP connection.
[0129] In a preferred embodiment of the present invention, in response to each connection resource being initialized, initializing the parameters of the connection resource and applying for an available port from the port allocation pool comprises:
[0130] After initializing the SMB connection parameters, apply for an available port resource from the port allocation pool;
[0131] After initializing the RPC connection parameters, apply for an available port resource from the port allocation pool;
[0132] After initializing the URL path of the LDAP connection, apply for an available port resource from the port allocation pool.
[0133] In a preferred embodiment of the present invention, in response to the port allocation pool allocating an available port to the connection resource and the connection resource being successfully bound to the available port, marking the allocated port in the port allocation pool and moving the head pointer of the port allocation pool to the next unallocated port comprises:
[0134] The SMB connection attempts to bind the port resources allocated by the port allocation pool;
[0135] In response to the binding success, the SMB connects to the port and marks the allocated port as occupied in the port allocation pool and moves the head pointer of the port allocation pool to the next unallocated port;
[0136] The RPC connection attempts to bind the port resources allocated by the port allocation pool;
[0137] In response to the binding success, the RPC connects to the port and marks the allocated port as occupied in the port allocation pool and moves the head pointer of the port allocation pool to the next unallocated port;
[0138] The LDAP connection attempts to bind to the port resources allocated by the port allocation pool;
[0139] In response to successful binding, LDAP connects to the port and marks the allocated port as occupied in the port allocation pool and moves the head pointer of the port allocation pool to the next unallocated port.
[0140] In a preferred embodiment of the present invention, it also includes:
[0141] In response to the port allocation pool allocating an available port to the connection resource and the connection resource failing to bind to the available port, marking the user identity of the port that failed to bind as OTHER and setting the port state to BUSY;
[0142] Start the timer and set the timer period to 30 seconds;
[0143] In response to the timer completing a timing cycle, traversing and testing port elements in the port allocation pool whose user identity is OTHER;
[0144] In response to the port with the user identity of OTHER being released, the port element and the port element where the tail pointer is located are exchanged, and the port is marked as idle.
[0145] In addition, the method disclosed in the embodiment of the present invention can also be implemented as a computer program executed by a processor, and the computer program can be stored in a computer-readable storage medium. When the computer program is executed by the processor, the above functions defined in the method disclosed in the embodiment of the present invention are performed.
[0146] In addition, the above method steps and system units may also be implemented using a controller and a computer-readable storage medium for storing a computer program that enables the controller to implement the above steps or unit functions.
[0147] It will also be appreciated by those skilled in the art that various exemplary logic blocks, modules, circuits and algorithm steps described in conjunction with the disclosure herein can be implemented as electronic hardware, computer software or a combination of the two. In order to clearly illustrate this interchangeability of hardware and software, a general description has been given to the functions of various schematic components, blocks, modules, circuits and steps. Whether this function is implemented as software or hardware depends on specific applications and the design constraints imposed on the entire system. Those skilled in the art can implement the function in various ways for each specific application, but this implementation decision should not be interpreted as causing a departure from the disclosed scope of the embodiments of the present invention.
[0148] In one or more exemplary designs, the function can be implemented in hardware, software, firmware or any combination thereof. If implemented in software, the function can be stored on a computer-readable medium or transmitted by a computer-readable medium as one or more instructions or codes. Computer-readable media include computer storage media and communication media, and the communication media include any media that helps to transfer a computer program from one location to another. The storage medium can be any available medium that can be accessed by a general or special computer. As an example and not limiting, the computer-readable medium may include RAM, ROM, EEPROM, CD-ROM or other optical disk storage devices, disk storage devices or other magnetic storage devices, or any other medium that can be used to carry or store the required program code in the form of an instruction or data structure and can be accessed by a general or special computer or a general or special processor. In addition, any connection can be appropriately referred to as a computer-readable medium. For example, if a coaxial cable, optical fiber cable, twisted pair, digital subscriber line (DSL) or wireless technologies such as infrared, radio and microwaves are used to send software from a website, server or other remote source, the above-mentioned coaxial cable, optical fiber cable, twisted pair, DSL or wireless technologies such as infrared, radio and microwaves are all included in the definition of the medium. As used herein, disk and disc include compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk, Blu-ray disc, wherein disks usually reproduce data magnetically, while optical discs reproduce data optically with lasers. Combinations of the above should also be included within the scope of computer-readable media.
[0149] The above are exemplary embodiments disclosed in the present invention, but it should be noted that various changes and modifications may be made without departing from the scope disclosed in the embodiments of the present invention as defined in the claims. The functions, steps and / or actions of the method claims according to the disclosed embodiments described herein do not need to be performed in any particular order. In addition, although the elements disclosed in the embodiments of the present invention may be described or required in individual form, they may also be understood as multiple unless explicitly limited to the singular.
[0150] It should be understood that, as used herein, the singular forms "a", "an" are intended to include the plural forms as well, unless the context clearly supports an exception. It should also be understood that, as used herein, "and / or" refers to any and all possible combinations including one or more of the associated listed items.
[0151] The serial numbers of the embodiments disclosed in the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.
[0152] A person skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware or by instructing related hardware through a program, and the program may be stored in a computer-readable storage medium, and the above-mentioned storage medium may be a read-only memory, a disk or an optical disk, etc.
[0153] A person skilled in the art should understand that the discussion of any of the above embodiments is only exemplary and is not intended to imply that the scope of the disclosure of the embodiments of the present invention (including the claims) is limited to these examples; under the concept of the embodiments of the present invention, the technical features in the above embodiments or different embodiments can also be combined, and there are many other changes in different aspects of the embodiments of the present invention as above, which are not provided in detail for the sake of simplicity. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present invention should be included in the protection scope of the embodiments of the present invention.
Claims
1. A method for allocating source ports, characterized in that: The following steps are involved: Create a port allocation pool consisting of a bidirectional circular queue, and limit the port allocation range to the whitelist of the firewall; create a structure array according to the set port range, and the array element of each port contains the user identity and port usage status; create a head pointer and a tail pointer, the head pointer points to the first unallocated port, and the tail pointer points to the first allocated port; In response to each connection resource being initialized, initializing the parameters of the connection resource and applying for an available port from the port allocation pool; In response to the port allocation pool allocating an available port to a connection resource and the connection resource being successfully bound to the available port, marking the allocated port in the port allocation pool and moving a head pointer of the port allocation pool to a next unallocated port; In response to the completion of the port connection of each connection resource, the net tool and the Winbind service initiate a connection to the domain controller so that each connection handle provides the required service.
2. The method according to claim 1, characterized in that User identities include NONE, SMB connection, RPC connection, LDAP connection, and OTHER.
3. The method according to claim 1, characterized in that The connection resources include SMB connection, RPC connection and LDAP connection.
4. The method according to claim 3, characterized in that In response to each connection resource being initialized, initializing the parameters of the connection resource and applying for an available port from the port allocation pool includes: After initializing the SMB connection parameters, apply for an available port resource from the port allocation pool; After initializing the RPC connection parameters, apply for an available port resource from the port allocation pool; After initializing the URL path of the LDAP connection, apply for an available port resource from the port allocation pool.
5. The method according to claim 4, characterized in that In response to the port allocation pool allocating an available port to a connection resource and the connection resource being successfully bound to the available port, marking the allocated port in the port allocation pool and moving a head pointer of the port allocation pool to a next unallocated port comprises: The SMB connection attempts to bind the port resources allocated by the port allocation pool; In response to successful binding, the SMB connects to the port and marks the allocated port as occupied in the port allocation pool and moves the head pointer of the port allocation pool to the next unallocated port; The RPC connection attempts to bind the port resources allocated by the port allocation pool; In response to successful binding, the RPC connects to the port and marks the allocated port as occupied in the port allocation pool and moves the head pointer of the port allocation pool to the next unallocated port; The LDAP connection attempts to bind to the port resources allocated by the port allocation pool; In response to successful binding, LDAP connects to the port and marks the allocated port as occupied in the port allocation pool and moves the head pointer of the port allocation pool to the next unallocated port.
6. The method according to claim 1, characterized in that Also includes: In response to the port allocation pool allocating an available port to a connection resource and the connection resource failing to bind to the available port, marking the user identity of the port that failed to bind as OTHER and setting the port state to BUSY; Start the timer and set the timer period to 30 seconds; In response to the timer completing a timing cycle, traversing and testing port elements in the port allocation pool whose user identity is OTHER; In response to the port with the user identity of OTHER being released, the port element and the port element where the tail pointer is located are exchanged, and the port is marked as idle.
7. A source port allocation device, characterized in that: The device comprises: A creation module, wherein the creation module is configured to create a port allocation pool consisting of a bidirectional circular queue, and limit the port allocation range to a whitelist of the firewall; create a structure array according to the set port range, wherein the array element of each port includes a user identity and a port usage status; create a head pointer and a tail pointer, wherein the head pointer points to the first unallocated port, and the tail pointer points to the first allocated port; An initialization module, wherein the initialization module is configured to initialize the parameters of the connection resources in response to each connection resource being initialized and to apply for an available port from the port allocation pool; a marking module, wherein the marking module is configured to mark the allocated port in the port allocation pool and move a head pointer of the port allocation pool to a next unallocated port in response to the port allocation pool allocating an available port to a connection resource and the connection resource being successfully bound to the available port; The connection module is configured to initiate a connection to the domain controller by the net tool and the Winbind service in response to the completion of the port connection of each connection resource so that each connection handle provides the service required by each connection handle.
8. A computer device, characterized in that: include: at least one processor; as well as A memory storing computer instructions executable on the processor, wherein the instructions, when executed by the processor, implement the steps of the method according to any one of claims 1 to 6.
9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Allocation method and system for network address conversion port resource under distributed architecture
CN101262506A
Multi-task GPU resource scheduling method, device and apparatus and readable medium
CN111858045A