Analysis method, system and storage medium for mirror components

By recombining the hierarchical information of the container image and using preset scripts and package managers to obtain component information, the problem that the existing technology cannot perform complete component analysis of the container is solved, and the accurate component analysis of the container image is achieved.

CN114780139BActive Publication Date: 2025-07-01SHANGHAI ANSHI INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210339814.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-04-01
Publication Date
2025-07-01
Estimated Expiration
2042-04-01

AI Technical Summary

Technical Problem

It is difficult to conduct complete and accurate component analysis of containers in the prior art. Traditional SCA will split the container into individual individuals for analysis, and cannot obtain component information of the entire container.

Method used

By obtaining the image file, querying the hash value in the image file, recombining the hierarchical information, using preset scripts and package managers to obtain component information, and storing it in the hierarchical directory, and finally obtaining component information through external reading.

Benefits of technology

It realizes the complete component analysis of container images, and can accurately obtain the name, license and version information of each component in the container, solving the problem that traditional technology cannot perform complete inspection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114780139B_ABST
    Figure CN114780139B_ABST
Patent Text Reader

Abstract

The present application discloses an analysis method, system and storage medium for mirror components, which relates to the field of software analysis and includes the following steps: obtaining a mirror file; querying multiple hash values arranged in the mirror file in a preset order; sequentially matching the hierarchical information of the mirror levels corresponding to the hash values from the mirror file; adding a preset script in layer 0; respectively mounting layer 0 with other levels in pairs to form multiple temporary mirrors, calling a package manager through a first query script to obtain the component information of the newly added layers in the temporary mirrors, and adding the component information to the newly added layers, where the component information includes component names, component licenses, and versions; after canceling the layer mounts, reading the component information from the newly added layers. By recombining the hierarchically information of the mirrors mounted in pairs, obtaining the component information through internal query and storing it in the hierarchical directory, and then externally reading to obtain the component information, the component analysis of the mirror is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of software analysis, and in particular, to a method, system, and storage medium for analyzing mirror components. Background Art

[0002] Containers are products that emerged under the trend of the development of the new era. Containers have the characteristics of high availability and low cost. Containers are created based on images, that is, the processes in the containers depend on the files in the images. Currently, in the context of rampant open-source risks and security risks, the main risks for containers lie in the security risks of using third-party components and the defects in the container's own components. Therefore, it is necessary to analyze the containers to obtain their components.

[0003] Currently, the commonly used detection technology is SCA (Software Composition Analysis). However, the detection objects of SCA are generally code or files. It decompresses the code and files, and then uses the objects obtained through model training based on semantics as the features of the code or files for extraction. For containers, what is actually needed is the entire container, that is, the complete component information in a virtual environment composed of multiple components rather than the code. Using traditional SCA to analyze containers will result in the situation where traditional SCA splits the container into individual entities and then analyzes each entity, making it impossible to detect the container components completely and accurately. Summary of the Invention

[0004] In order to obtain the component information in the image, the present application provides a method, system, and storage medium for analyzing mirror components.

[0005] In a first aspect, the present application provides a method for analyzing mirror components, adopting the following technical solution:

[0006] A method for analyzing mirror components includes the following steps:

[0007] Obtain an image file;

[0008] Query multiple hash values arranged in the image file in a preset order. Each hash value corresponds to an image layer in the image file, and the corresponding image layers are respectively defined as layer 0, layer 1,..., layer M according to the preset order of the arranged hash values, where M is a positive integer and at least 1;

[0009] Successively match the layer information of the image layers corresponding one-to-one with the hash values from the image file;

[0010] Add a preset script to layer 0, where the preset script includes a first query script for querying component information in the layer;

[0011] Mount the 0th layer with other layers pairwise to form multiple temporary images respectively. Among them, the 0th layer in the temporary image is the bottom layer, and the layer above the 0th layer is named the new added layer;

[0012] Call the package manager through the first query script to obtain the component information of the new added layer in the temporary image, and add the component information to the new added layer. Among them, the component information includes component name, component license, and version;

[0013] After canceling the layer mounting, read the component information from the new added layer;

[0014] Take the component information as the result information and output the result information.

[0015] By adopting the above technical solution, by recombining the layer information into pairwise-mounted images, obtaining the component information through internal query and storing it in the layer directory, and then reading it externally to obtain the component information, the component analysis of the image is realized.

[0016] Optionally, obtaining the component information of the new added layer in the temporary image includes the following steps:

[0017] Obtain all data sets of the temporary image;

[0018] Remove the preset basic data from all data sets of the temporary image, and the remaining data is used as the software information of the new added layer. Among them, the preset basic data is stored in the query script.

[0019] Optionally, before outputting the result information, it further includes the following steps:

[0020] Compare the component information of the nth layer with the component information of the (n + 1)th layer to obtain the component increase and decrease information corresponding to the (n + 1)th layer, where initially n = 0;

[0021] After obtaining the component increase and decrease information of the (n + 1)th layer, judge whether (n + 1) is equal to L,

[0022] If (n + 1) is not equal to L, then n = n + 1, and compare the component information of the nth layer with the component information of the (n + 1)th layer again to obtain the component increase and decrease information corresponding to the current (n + 1)th layer;

[0023] If (n + 1) is equal to L, then add the component increase and decrease information corresponding to all layers to the result information.

[0024] Optionally, the query script further includes a second query script for querying the dependency relationship corresponding to the input variable according to the input variable;

[0025] After reading the component information from the new added layer, it further includes the following steps:

[0026] Input the component name as a variable into the second query script, and obtain the dependencies corresponding to each component name through the second query script;

[0027] Add the dependencies corresponding to each component name to the result information.

[0028] Optionally, input the component name as a variable into the second query script, and obtain the dependencies corresponding to each component name, including the following steps:

[0029] After unmounting, transfer the variable used to represent the component name to the preset script at layer 0;

[0030] Mount layer 0 and the newly added layer pairwise again. The second query script obtains the dependencies corresponding to the component name represented by the variable by calling the package manager, and stores the dependencies in the newly added layer;

[0031] After unmounting again, read out the dependencies in the newly added layer.

[0032] Optionally, obtaining the mirror file includes the following steps:

[0033] Obtain the mirror name, and determine whether there is a mirror file in the local mirror repository with the same name as the input mirror name,

[0034] If there is a mirror file in the local mirror repository with the same name as the input mirror name, then call the mirror file;

[0035] If there is no mirror file in the local mirror repository with the same name as the input mirror name, then determine whether there is a mirror file in the remote mirror repository with the same name as the input mirror name,

[0036] If there is a mirror file in the remote mirror repository with the same name as the input mirror name, then pull the information of the corresponding mirror file to the local mirror repository;

[0037] If there is no mirror file in the remote mirror repository with the same name as the input mirror name, then report an error.

[0038] Optionally, if there is a mirror file with the same name in the local mirror repository, or there is a mirror file with the same name in the remote mirror repository, it further includes the following steps:

[0039] Obtain the identification code of the mirror file with the same name;

[0040] Determine whether the identification code is the same as the preset code,

[0041] If the identification code is not the same as the preset code, then it is considered that there is no mirror file with the same name in the corresponding mirror repository;

[0042] If the identification code is consistent with the preset code, it is considered that there is an image file with the same name in the corresponding image repository.

[0043] Optionally, after placing the preset script into layer 0, the following steps are further included:

[0044] Match multiple keywords preset in the preset script in the system basic information of layer 0, and determine the operating system of the current image according to the keywords with consistent matches. Among them, each keyword preset in the preset script corresponds to an operating system;

[0045] The preset script calls the package manager corresponding to the operating system during the combined mount.

[0046] In a second aspect, the present application provides an image component analysis system, adopting the following technical solution:

[0047] An image component analysis system includes the following modules:

[0048] A matching module, configured to match a corresponding image file from an image repository according to the image name input by a user;

[0049] A layering module, configured to query hash values corresponding to each layer from the image file, and obtain the layer information of the corresponding layer according to the hash values; among them, the layer at the bottommost layer of the image file is layer 0.

[0050] A placement module, configured to add a preset script to layer 0;

[0051] A mounting module, configured to mount the layer information of layer 0 and the layer information of other layers in pairs to form a temporary image,

[0052] An operation module, configured to operate a container formed by the temporary image;

[0053] A disassembly module, configured to cancel the mount of the temporary image that has been operated to output the newly added layer and layer 0;

[0054] A processing module, configured to read and process data of the newly added layer output by the disassembly module, and output component information.

[0055] An output module, configured to output the component information as result information.

[0056] In a third aspect, the present application provides a computer-readable storage medium, storing a computer program that can be loaded and executed by a processor to perform any one of the above image component analysis methods.

[0057] In summary, the present application includes at least one of the following beneficial technical effects: by recombining the hierarchical information of pairwise-mounted images, obtaining component information through internal queries and storing it in the hierarchical directory, and then obtaining the component information by external reading, the component analysis of the images is realized. Brief Description of the Drawings

[0058] Figure 1 is the flowchart of the steps of the embodiment of the present application.

[0059] Figure 2 is the logic diagram of obtaining the image file of the embodiment of the present application. Detailed Description of the Embodiment

[0060] The following will further elaborate on the present application in conjunction with the attached Figures 1 to 2 drawings.

[0061] A method for detecting image components, see Figure 1 , includes the following steps:

[0062] S100. Obtain the image file.

[0063] The methods for obtaining the image file include direct acquisition and indirect acquisition.

[0064] Among them, the direct acquisition method is that the user directly stores the image file to be detected in the local image repository by means of uploading, dragging, etc.

[0065] The indirect acquisition method is to obtain the image name input by the user and then match the pre-stored image file based on the image name.

[0066] In practice, the content input by the user is not limited to the image name. The user can also input the image tag or input both the image tag and the image name. However, regardless of which input content, the corresponding matching method is similar. In this embodiment, only the image name is taken as an example of the input content for specific introduction.

[0067] The operation of matching the pre-stored image file based on the image name is performed by the Docker daemon process.

[0068] After obtaining the image name input by the user, the Docker daemon process matches the image file with the same name in the image repository according to the image name.

[0069] In one embodiment, matching the pre-stored container image based on the image name, see Figure 2 , includes the following steps:

[0070] S110. Determine whether there is an image file in the local image repository with the same name as the input image name.

[0071] S120. If there is an image file in the local image repository with the same name as the input image name, then perform step 200 on the image file in the local image repository with the same name as the input image name.

[0072] S130. If there is no image file in the local image repository with the same name as the input image name, then determine whether there is an image file in the remote image repository with the same name as the input image name.

[0073] The image repository includes a local image repository and a remote image repository. When obtaining the corresponding image file according to the image name, the Docker daemon first retrieves in the local image repository whether there is an image file with the same name. And when there is no image file with the same name in the local image repository, the Docker daemon then retrieves in the remote image repository whether there is an image file with the same name.

[0074] The remote image repository is by default the public Docker repository (Docker hub). Of course, users can also define the remote image repository as other Docker repositories according to the actual situation.

[0075] S140. If there is an image file in the remote image repository with the same name as the input image name, then pull the information of the corresponding image file into the local image repository.

[0076] When there is an image file in the remote image repository with the same name as the input image name, the Docker daemon will pull the information of the corresponding image file into the local image repository.

[0077] S150. If there is no image file in the remote image repository with the same name as the input image name, then report an error.

[0078] If the Docker daemon cannot retrieve an image file with the same name from both image repositories, then the Docker daemon reports an error to remind the user to pay attention to whether the input image name is incorrect.

[0079] In addition, since after the image file is created, if the content of the image file is changed while the image name remains unchanged, then directly matching the image file by the image name, the finally obtained image file is very likely not the one actually required by the user. Therefore, on the basis of matching by the image name, it is also possible to further check whether the image file has been tampered with.

[0080] Specifically, if there is an image file with the same name in the local image repository, or there is an image file with the same name in the remote image repository, it includes the following steps:

[0081] S131. Obtain the identification code of the mirror file with the same name.

[0082] The identification code refers to the hash value corresponding to the entire mirror file. Specifically, the identification code can be the MD value obtained by calculating the entire mirror file through the MD5 / MD4 algorithm, or the sha value obtained by calculating the entire mirror file through the SHA-1 algorithm. In this embodiment, the identification code value is taken as an example of the sha value.

[0083] It should be noted that the method of obtaining the identification code of the mirror file stored in the local image repository is different from the method of obtaining the identification code of the mirror file stored in the remote image repository. For the mirror file in the local image repository, the Docker daemon will record whether the mirror file has been changed. As long as the Docker daemon does not prompt that the mirror file has been modified, the sha value recorded when the mirror file was created can be directly used as the identification code. For the mirror file stored in the remote image repository, whether it has been modified is not necessarily effectively monitored. Therefore, when the names match, the mirror file is first pulled to the local image repository, and then the corresponding sha value is calculated and used as the identification code. It is precisely because the step of verifying whether the mirror file stored in the remote image repository has been tampered with is more cumbersome that the Docker daemon is set to preferentially match the mirror file in the local image repository.

[0084] S132. Determine whether the identification code is consistent with the preset code.

[0085] The preset code refers to the sha value recorded after the mirror file is created locally.

[0086] When any change occurs in the content of the mirror file, the corresponding sha value will be adjusted accordingly. Therefore, by comparing the identification code with the preset code, it can be determined whether the mirror file has changed.

[0087] S133. If the identification code is inconsistent with the preset code, it is considered that there is no mirror file with the same name in the corresponding image repository.

[0088] When it is considered that there is no mirror file with the same name in the corresponding image repository, different steps are executed according to the different image repositories. When the image repository is the local image repository, step S140 is executed; when the image repository is the remote image repository, an error is reported in the same way as in step S150.

[0089] S200. Query multiple hash values arranged in a preset order in the image file. Each hash value corresponds to an image layer in the image file, and the corresponding image layers are respectively defined as layer 0, layer 1,..., layer M according to the preset order in which the hash values are arranged, where M is a positive integer and at least 1.

[0090] The hash value in this embodiment refers to the sha value of the file corresponding to each layer in the image file. Different layers correspond to different sha values.

[0091] The way to query the hash value is to query the main file of the image file through the Docker daemon process to obtain a manifest file recording the hash values corresponding to each layer in the image.

[0092] The manifest file stores the hash values of each layer, and the arrangement of these hash values is related to the arrangement of the layers corresponding to the hash values in the image. For example, in the image, layer 0 is the bottom layer, layer 1 is stacked above layer 0, and layer 2 is stacked above layer 1. Then in the manifest file, the hash value corresponding to layer 0 is arranged in front of the hash value corresponding to layer 1, and the hash value corresponding to layer 2 is arranged behind the hash value corresponding to layer 1.

[0093] According to the number of obtained hash values, the number of layers in the image can be determined, and these hash values also play a role in positioning the positional relationship between the image layers.

[0094] S300. Sequentially match the layer information of the image layers corresponding one by one with the hash values from the image file.

[0095] Determine the compressed packages of the corresponding layers from the container image with the hash values of different layers respectively, and then decompress and restore the compressed packages of the layers respectively to output multiple layer information, and each layer information contains all the files of the image layer corresponding to this layer.

[0096] S400. Add a preset script to layer 0.

[0097] The preset script includes a first query script for querying component information in the layer and a third query script for determining the operating system corresponding to the image.

[0098] And after the preset script is implanted into layer 0, the third query script queries the basic system information stored in the os-release file in the etc directory of layer 0. The third query script determines the operating system corresponding to the image from the os-release file by means of keyword retrieval, and the keyword is a specific system name, such as centos, redhat, etc.

[0099] The first query script is used to query the component information of each layer in step S500.

[0100] S500. Mount the 0th layer to each of the other layers pairwise to form multiple temporary images respectively.

[0101] Among them, the 0th layer in the temporary image is the bottom layer, and the layer above the 0th layer is named the newly added layer.

[0102] By mounting the newly added layer above the 0th layer to form a temporary image, running the temporary image forms the corresponding container. According to the container characteristics, the layer at the top of the container, that is, the newly added layer, has read-write functions, while the 0th layer below the newly added layer is in read-only mode.

[0103] S600. Call the package manager through the first query script to obtain the component information of the newly added layer in the temporary image, and add the component information to the newly added layer.

[0104] The component information includes the component name, the license of the component, and the version of the component.

[0105] The package manager needs to query the information in the container during the running of the image. However, the container runtime is isolated from the external environment, resulting in the inability to transfer information between the outside and inside of the container.

[0106] Therefore, during the running of the temporary image, the first query script preset in the 0th layer is required to mobilize the package manager. After the package manager queries the component information of the newly added layer, the component information is stored in the newly added layer. After canceling the union mount, the component information can be obtained by reading the newly added layer.

[0107] Specifically, obtaining the component information of the newly added layer in the temporary image includes the following steps:

[0108] S510. Obtain all data sets of the temporary image.

[0109] Run the temporary image through the operating system determined in step S400. The first query script added to the 0th layer calls the package manager in this operating system. Through the package manager for software management, all data sets of the temporary image are obtained.

[0110] S520. Remove the preset basic data from all data sets of the temporary image, and the remaining data is used as the software information of the newly added layer.

[0111] The preset basic data is pre-stored in the query script. The preset basic data is the component information of the 0th layer. Since the construction of the 0th layer is basically fixed, its software information is known.

[0112] In addition, if the software information of layer 0 is unknown or uncertain, when building a temporary image, a preset base layer can also be selected to replace layer 0 identified from the image, so as to ensure the correctness of the software information of layer 0 in the temporary image.

[0113] It should be noted that the software information of the new layer is obtained by removing the original software information of layer 0 from all the acquired data sets, and the software information is not the component information of the new layer. From the software information to the component information, further processing of the software information is required. And before processing the software information, for the convenience of subsequent reading of the software information, the preset script stores the software information in the original directory of the new layer.

[0114] S700. After unmounting the layer, read the component information from the new layer.

[0115] After unmounting, read the corresponding software information from the new layer and pass the software information to the preset script for processing to obtain component information such as component name, component version, and component license.

[0116] It should be noted that when the operating system is a non-rpm management system, such as ubuntu or debian, the component license cannot be directly queried. Then, after obtaining the component name, locate the position of the corresponding license through the component name, so as to store the license information in the directory of the new layer for subsequent reading of the license information from the new layer. This operation is the same as the method for obtaining other component information.

[0117] S800. Take the component information as the result information and output the result information.

[0118] The result information is displayed to the user in a preset display manner. The preset display method can be one or more of the methods such as displaying on a specified display screen, transmitting to a specified email, sending as a short message to a specified mobile phone, etc.

[0119] Furthermore, this detection method can also query the increase and decrease information of the components corresponding to the layer to clearly show the formation process of the entire image.

[0120] The specific method for querying the increase and decrease information of the components corresponding to the layer is as follows:

[0121] S710. Compare the component information of layer n with the component information of layer n + 1 in sequence to obtain the component increase and decrease information corresponding to layer n + 1, where n = 0.

[0122] The comparison method is that the preset script calls the package manager with the component information of layer n and the component information of layer n + 1 as inputs, and the package manager outputs the component increase and decrease information corresponding to layer n + 1.

[0123] The component addition and subtraction information refers to the component information added and subtracted in the current n+1 level compared to the n level.

[0124] S720. After obtaining the component addition and subtraction information of the n+1 level, determine whether n+1 is equal to L.

[0125] S730. If n+1 is not equal to L, then n = n+1, and compare the component information of the n level with the component information of the n+1 level again.

[0126] Determining whether n+1 is equal to L is to determine whether the component addition and subtraction information of all levels has been queried. If n+1 is not equal to L, it means that there are other levels that need to query the component addition and subtraction information. Then assign the value of n+1 to n, and repeat steps S720 to S730.

[0127] S740. If n+1 = L, then add the component addition and subtraction information corresponding to all levels to the result information.

[0128] In practice, the method for querying the component addition and subtraction information in the level is not limited to the above method. It is also possible to first arrange and combine all levels in an adjacent and pairwise combination manner, and then the Docker daemon process sequentially obtains the component addition and subtraction information through the diff command. As long as the component addition and subtraction information corresponding to all levels can be finally obtained.

[0129] Furthermore, after obtaining the component information of each level, the detection method can also obtain the dependency relationship between components according to the component information. In order to implement the query of the dependency relationship, the query script also includes a second query script for querying the dependency relationship corresponding to the input variable according to the input variable.

[0130] The specific method for querying the dependency relationship is as follows:

[0131] S750. Input the component name as a variable into the second query script, and obtain the dependency relationship corresponding to each component name through the second query script.

[0132] The component name is obtained in step S700. Therefore, the query of the dependency relationship must be carried out after obtaining the component information. Each time, only one component name can be selected as a variable and input into the second query script. After obtaining the dependency relationship corresponding to the component name, select other component names to replace the variable in the second query script, so as to obtain the dependency relationship corresponding to each component.

[0133] S760. Add the dependency relationship corresponding to each component name to the result information.

[0134] In one embodiment, the component name is input as a variable into the second query script, and the dependencies corresponding to each component name are obtained through the second query script, including the following steps:

[0135] S751. After unmounting, transfer the variable used to represent the component name to the preset script in layer 0.

[0136] Unmount the mounts between the levels in the temporary container to make layer 0 independent again, and transfer the component name to be queried to the preset script in layer 0 through an external script.

[0137] S752. Mount layer 0 and the newly added layer pairwise again. The second query script obtains the dependencies corresponding to the component name represented by the variable by calling the package manager, and stores the dependencies in the newly added layer.

[0138] To avoid the situation where the first query script queries repeatedly, the preset script determines the currently executed query script based on whether there is a variable in the second query script. When there is no variable in the second query script, during the running of the temporary container, execute the first query script to obtain component information; when there is a variable in the second query script, during the running of the temporary container, execute the second query script to obtain the dependencies corresponding to the variable.

[0139] S753. After unmounting again, read out the dependencies in the newly added layer.

[0140] The embodiment of the present application also discloses an analysis system for mirror components, including the following modules:

[0141] A matching module for matching the corresponding mirror file from the mirror repository according to the mirror name input by the user;

[0142] A layering module for querying the hash values corresponding to each level from the mirror file and obtaining the level information of the corresponding level according to the hash values; among them, the level at the bottom layer of the mirror file is layer 0.

[0143] A placement module for adding the preset script to layer 0;

[0144] A mounting module for pairwise mounting the level information of layer 0 and the level information of other layers together to form a temporary mirror,

[0145] A running module for running the container formed by the temporary mirror;

[0146] A disassembly module for unmounting the running temporary mirror to output the newly added layer and layer 0.

[0147] An input module for transferring the component information as a variable to the preset script in layer 0 when it is not mounted.

[0148] A processing module, configured to read and process data of the newly added layer output by the disassembly module, and output one or more of component information, dependency relationships, license information, and component addition and deletion information.

[0149] An output module, configured to output component information, dependency relationships, component addition and deletion information, etc. as result information.

[0150] An embodiment of the present application also discloses a computer-readable storage medium, storing a computer program that can be loaded and executed by a processor to perform the above-mentioned analysis method for a mirror component.

[0151] The above are all preferred embodiments of the present application. The protection scope of the present application is not limited thereby. Therefore, all equivalent changes made according to the structure, shape, and principle of the present application should be covered within the protection scope of the present application.

Claims

1. A method for analyzing mirror components, characterized in that, including the following steps: Obtain an image file; Query multiple hash values arranged in a preset order in the image file. Each hash value corresponds to an image layer in the image file, and the corresponding image layers are respectively defined as layer 0, layer 1,..., layer M according to the preset order of the hash values, where M is a positive integer and at least 1; Successively match the layer information of the image layers corresponding one-to-one with the hash values from the image file; Add a preset script to layer 0, where the preset script includes a first query script for querying component information in the layer; Mount layer 0 with other layers pairwise to form multiple temporary images respectively, where layer 0 is the bottom layer in the temporary image, and the layer above layer 0 is named the new layer; Call the package manager through the first query script to obtain the component information of the new layer in the temporary image, and add the component information to the new layer, where the component information includes component name, component license, and version; After canceling the layer mount, read the component information from the new layer; Use the component information as the result information and output the result information; Before outputting the result information, it also includes the following steps: Compare the component information of layer n with the component information of layer n + 1 to obtain the component increase and decrease information corresponding to layer n + 1, where initially n = 0; After obtaining the component increase and decrease information of layer n + 1, determine whether n + 1 is equal to L; If n + 1 is not equal to L, then n = n + 1, and compare the component information of layer n with the component information of layer n + 1 again to obtain the component increase and decrease information corresponding to the current n + 1 layer; If n + 1 is equal to L, add the component increase and decrease information corresponding to all layers to the result information; The query script further includes a second query script for querying the dependency relationship corresponding to the input variable according to the input variable; After reading the component information from the new layer, it also includes the following steps: Input the component name as a variable into the second query script, and obtain the dependency relationship corresponding to each component name through the second query script; Add the dependency relationship corresponding to each component name to the result information; Input the component name as a variable into the second query script, and obtain the dependency relationship corresponding to each component name through the second query script, including the following steps: After unmounting, transfer the variable representing the component name to the preset script of layer 0; Mount layer 0 and the new layer pairwise again. The second query script calls the package manager to obtain the dependency relationship corresponding to the component name represented by the variable, and stores the dependency relationship in the new layer; After unmounting again, read out the dependency relationship in the new layer.

2. The analysis method of a mirror image component according to claim 1, characterized in that Obtain the component information of the new layer in the temporary image, including the following steps: Obtain all data sets of the temporary image; Remove the preset basic data from all data sets of the temporary image, and the remaining data is used as the software information of the new layer, where the preset basic data is stored in the query script.

3. The analysis method of a mirror image component according to claim 1, characterized in that Obtain the image file, including the following steps: Obtain the image name, and determine whether there is an image file in the local image repository with the same name as the input image name. If there is an image file in the local image repository with the same name as the input image name, then call the image file; If there is no image file in the local image repository with the same name as the input image name, then determine whether there is an image file in the remote image repository with the same name as the input image name, If there is an image file in the remote image repository with the same name as the input image name, then pull the information of the corresponding image file into the local image repository; If there is no image file in the remote image repository with the same name as the input image name, then report an error.

4. The analysis method of a mirror image component according to claim 1, characterized in that: If there is an image file with the same name in the local image repository, or there is an image file with the same name in the remote image repository, it also includes the following steps: Obtain the identification code of the image file with the same name; Determine whether the identification code is the same as the preset code, If the identification code is not the same as the preset code, then it is considered that there is no image file with the same name in the corresponding image repository; If the identification code is the same as the preset code, then it is considered that there is an image file with the same name in the corresponding image repository.

5. The analysis method of a mirror image component according to claim 1, characterized in that: After placing the preset script into layer 0, it also includes the following steps: Match through multiple keywords preset in the preset script in the system basic information of layer 0, and determine the operating system of the current image according to the keywords with consistent matches, where each keyword preset in the preset script corresponds to an operating system; The preset script calls the package manager corresponding to the operating system during joint mounting.

6. An analysis system for mirror components, characterized in that, It includes the following modules: A matching module, used to match the corresponding image file from the image repository according to the image name input by the user; A layering module, used to query the hash values corresponding to each layer from the image file, and obtain the layer information of the corresponding layer according to the hash values; among them, the layer at the bottom of the image file is layer 0; A placement module, used to add the preset script to layer 0, and the preset script includes a first query script for querying component information in the layer and a second query script for querying the dependency relationship corresponding to the input variable according to the input variable; A mounting module, used to mount the layer information of layer 0 and the layer information of other layers in pairs to form a temporary image, A running module, used to run the container formed by the temporary image; A disassembly module, used to cancel the mounting of the temporary image that has been run to output the new layer and layer 0; A processing module, used to read and process the data of the new layer output by the disassembly module to output component information; An output module, used to output the component information as result information; The processing module is also used to compare the component information of layer n with the component information of layer n + 1 to obtain the component increase and decrease information corresponding to layer n + 1, where initially n = 0; After obtaining the component increase and decrease information of layer n + 1, determine whether n + 1 is equal to L, If n + 1 is not equal to L, then n = n + 1, and compare the component information of layer n with the component information of layer n + 1 again to obtain the component increase and decrease information corresponding to the current layer n + 1; If n + 1 is equal to L, then add the component increase and decrease information corresponding to all layers to the result information; The processing module is further configured to input the component name as a variable into a second query script, and obtain the corresponding dependencies for each component name through the second query script; Add the dependencies corresponding to each component name to the result information; Inputting the component name as a variable into the second query script and obtaining the corresponding dependencies for each component name through the second query script includes the following steps: After unmounting, transfer the variable used to represent the component name to a preset script at layer 0; Mount the layer 0 and the newly added layer pairwise again. The second query script obtains the dependencies corresponding to the component name represented by the variable by calling the package manager, and stores the dependencies in the newly added layer; After unmounting again, read out the dependencies in the newly added layer.

7. A computer-readable storage medium, characterized in that, A computer program is stored that can be loaded and executed by a processor to perform an analysis method of an image component as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Docker mirror image analysis method and device, electronic equipment and storage medium

    CN113065125A

  • Verification method and device for mirror image file, electronic equipment and storage medium

    CN113342745A