Method and apparatus for creating a sandbox environment for plug-in operation and computing device

By creating a sandbox environment in the browser plug-in running environment, the Docker solution has been solved in terms of flexibility and isolation, modular control of plug-in process resources and dynamic access to hardware, and improved the security and flexibility of the system.

CN114816707BActive Publication Date: 2025-07-01UNIONTECH SOFTWARE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210487737.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-24
Publication Date
2025-07-01
Estimated Expiration
2041-12-24

AI Technical Summary

Technical Problem

The existing Docker solution cannot be flexibly modified after creating a container environment, cannot achieve complete environmental isolation between each plug-in, and cannot implement hot plugging and dynamic reading of hardware resources.

Method used

By creating a sandbox environment, map each plug-in's local directory and the host's device management directory, and add different resource restrictions in the sandbox environment, load plug-in process management, receive front-end messages and load corresponding plug-ins, ensuring that only one master plug-in and its dependencies are loaded in a sandbox environment.

Benefits of technology

It realizes modular control of plug-in process resources, ensures the isolation between plug-ins and hosts and the environment isolation between plug-ins, supports hot plug-ins and dynamic resource access of hardware, and improves system flexibility and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114816707B_ABST
    Figure CN114816707B_ABST
Patent Text Reader

Abstract

The present invention discloses a method, an apparatus and a computing device for creating a sandbox environment for plugin operation. The method for creating a sandbox environment for plugin operation according to the present invention includes: creating a sandbox environment, mapping the local directory for each plugin into the sandbox environment, and mapping the device management directory of the host machine into the sandbox environment; adding different resource limitations to different sandbox environments; loading plugin process management; receiving a message transmitted from the front end, the message including the ID of the plugin and the version of the plugin, and transmitting the message to the plugin process management; loading the corresponding plugin through the plugin process management, wherein only one main plugin and the slave plugins dependent on the main plugin are loaded in one sandbox environment. The solution of the present invention realizes modular control of plugin process resources, can achieve complete control throughout the entire life cycle of the sandbox, and enables dynamic access to hardware resources, and limits the disk read / write speed and the network upload / download rate.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of the invention patent application No. 2021115938518 filed on December 24, 2021. Technical Field

[0002] The present invention relates to the technical field of computer browser plugin operation, and in particular to a method and device for creating a sandbox environment for plugin operation, a computing device, and a readable storage medium. Background Art

[0003] In current practice, it is necessary to ensure the isolation of plugin process management, plugin security, and resources. The existing technical solution is to isolate plugin processes through Docker. Docker originated from Linux Container (LXC) technology and is currently the mainstream virtualization container solution. It provides a set of standardized container solutions, and the design diagram is as Figure 1 shown. As Figure 1 shown, the host can manage plugins, and Docker provides an interface for managing plugins. The local resource manager is responsible for managing the relationship between local resources and Docker containers. The plugin management and plugin service invocation parts are all run in Docker containers. In actual development projects, the backend plugin server, plugin process management, and plugins are directly deployed in Docker containers after compilation and packaging, and relevant service interfaces are exposed. The front end communicates through the service interfaces.

[0004] Since all plugins and plugin services are run inside Docker containers, the plugins can only affect the containers and will not affect the operating system. However, the above Docker solution brings three problems:

[0005] 1. As a general browser plugin solution, different plugin manufacturers and plugin developers require different resources, permissions, and environments. However, the container environment created by Docker cannot be modified after the container is created. Therefore, the Docker solution is not flexible in this context.

[0006] 2. The plugin process management and all loaded plugins are run in a container environment. Although the environment is isolated from the host, complete isolation between each plugin is not achieved.

[0007] 3. It is impossible to achieve hot plugging of hardware and dynamically read hardware resources (taking bank customers as an example, the plugin system has a need for hot plugging of USB tokens). Summary of the Invention

[0008] Therefore, the present invention provides a method and device for creating a sandbox environment for plugin operation, a computing device, and a readable storage medium, in an attempt to solve or at least alleviate at least one of the above problems.

[0009] According to one aspect of the present invention, there is provided a method for creating a sandbox environment for plugin operation, including: creating a sandbox environment, mapping the local directory for each plugin into the sandbox environment, and mapping the device management directory of the host to the sandbox environment; adding different resource limits to different sandbox environments; loading plugin process management; receiving a message transmitted by the front end, the message including the ID of the plugin and the version of the plugin, and passing it to the plugin process management; loading the corresponding plugin through the plugin process management, where only one main plugin and the slave plugins dependent on the main plugin are loaded in one sandbox environment.

[0010] According to another aspect of the present invention, there is provided a device for creating a sandbox environment for plugin operation, including: a creation module for creating a sandbox environment, mapping the local directory for each plugin into the sandbox environment, and mapping the device management directory of the host to the sandbox environment; a resource limit module for adding different resource limits to different sandbox environments; a loading module for loading plugin process management; a receiving module for receiving a message transmitted by the front end, the message including the ID of the plugin and the version of the plugin, and passing it to the plugin process management; a plugin loading module for loading the corresponding plugin through the plugin process management, where only one main plugin and the slave plugins dependent on the main plugin are loaded in one sandbox environment.

[0011] According to another aspect of the present invention, there is provided a computing device, including: at least one processor and a memory storing program instructions; when the program instructions are read and executed by the processor, the computing device is caused to execute the above method for creating a sandbox environment for plugin operation.

[0012] According to still another aspect of the present invention, there is provided a readable storage medium storing program instructions, when the program instructions are read and executed by a computing device, the computing device is caused to execute the above method for creating a sandbox environment for plugin operation.

[0013] According to the technical solution of the present invention, modular control of plugin process resources is achieved, and complete control can be realized throughout the entire life cycle of the sandbox, and it enables dynamic access to hardware resources, and limits the disk read / write speed and network upload / download rate.

[0014] The sandbox mechanism according to the technical solution of the present invention does not need to be as complex as docker, and only needs to focus on the implementation inside the sandbox. It not only makes the operation of the plugin not affect the host, but also realizes environmental isolation between plugins.

[0015] In addition, different from Docker which initializes a new process each time to set up a sandbox environment, according to the technical solution of the present invention, a plug-in process is used to manage and load plug-ins in a single sandbox environment, which also brings an advantage: each plug-in runs in a sandbox environment. When an external plug-in service needs to communicate with a plug-in, communication can be achieved through reserved ports penetrating the sandbox environment under the condition that the network and file system are isolated. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] To achieve the above and related purposes, certain illustrative aspects are described herein in connection with the following description and drawings, which indicate various ways in which the principles disclosed herein can be practiced, and all aspects and their equivalent aspects are intended to fall within the scope of the claimed subject matter. The above and other purposes, features, and advantages of the present disclosure will become more apparent by reading the following detailed description in conjunction with the drawings. Throughout the present disclosure, like reference numerals generally refer to like components or elements.

[0017] Figure 1 The design diagram of isolating plug-in processes through Docker is shown.

[0018] Figure 2 The schematic diagram of a computing device 100 according to an embodiment of the present invention is shown.

[0019] Figure 3 The overall design diagram of a sandbox creation solution according to an embodiment of the present invention is shown.

[0020] Figure 4 The flowchart of a method 400 for creating a sandbox environment for plug-in operation according to an embodiment of the present invention is shown.

[0021] Figure 5 The schematic concurrent double-thread flowchart of a method according to an embodiment of the present invention is shown.

[0022] Figure 6 The schematic block diagram of a device for creating a sandbox according to an embodiment of the present invention is shown. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0023] The exemplary embodiments of the present disclosure will be described in more detail below with reference to the drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be fully conveyed to those skilled in the art.

[0024] In view of the problems of non-customizability in the existing plug-in process management technology, inability to isolate between plug-ins, etc., which lead to non-modular control, inflexibility, etc., the present invention provides a method for creating a sandbox environment for plug-in operation, which can achieve modular control of plug-in process resources, can achieve complete control throughout the entire life cycle of the sandbox, and enables dynamic access to hardware resources, and limits the disk read / write speed and network upload / download rate.

[0025] The method for creating a sandbox environment for plug-in operation according to the present invention is executed in a computing device. The computing device can be any device with storage and computing capabilities, which can be implemented, for example, as a server, a workstation, etc., or can be implemented as a personal configured computer such as a desktop computer, a notebook computer, or can be implemented as a terminal device such as a mobile phone, a tablet computer, a smart wearable device, an Internet of Things device, etc., but is not limited thereto.

[0026] Figure 2 The schematic diagram of a computing device 100 according to an embodiment of the present invention is shown. It should be noted that, Figure 2 The shown computing device 100 is only an example. In practice, the computing device for implementing the method for creating a sandbox environment for plug-in operation according to the present invention can be a device of any model, and its hardware configuration can be the same as Figure 2 the shown computing device 100, or can be different from Figure 2 the shown computing device 100. In practice, the computing device for implementing the method for creating a sandbox environment for plug-in operation according to the present invention can add or delete hardware components of Figure 2 the shown computing device 100, and the present invention does not limit the specific hardware configuration of the computing device.

[0027] As Figure 2 shown, in the basic configuration 102, the computing device 100 typically includes a system memory 106 and one or more processors 104. A memory bus 108 can be used for communication between the processor 104 and the system memory 106.

[0028] Depending on the desired configuration, processor 104 can be any type of processor, including but not limited to: a microprocessor (μP), a microcontroller (μC), a digital signal processor (DSP), or any combination thereof. Processor 104 can include one or more levels of cache such as level 1 cache 110 and level 2 cache 112, a processor core 114, and registers 116. An example processor core 114 can include an arithmetic logic unit (ALU), a floating point unit (FPU), a digital signal processing core (DSP core), or any combination thereof. An example memory controller 118 can be used with processor 104, or in some implementations, memory controller 118 can be an internal part of processor 104.

[0029] Depending on the desired configuration, system memory 106 can be any type of memory, including but not limited to: volatile memory (such as RAM), non-volatile memory (such as ROM, flash memory, etc.), or any combination thereof. Physical memory in a computing device generally refers to volatile memory RAM, and data on a disk needs to be loaded into physical memory before it can be read by processor 104. System memory 106 can include an operating system 120, one or more applications 122, and program data 124. In some embodiments, application 122 can be arranged to execute instructions on one or more processors 104 using program data 124 on the operating system. The operating system 120 can be, for example, Linux, Windows, etc., which includes program instructions for handling basic system services and performing hardware-dependent tasks. Application 122 includes program instructions for implementing various user-desired functions. Application 122 can be, for example, a browser, instant messaging software, software development tools (such as integrated development environment IDE, compiler, etc.), but is not limited thereto. When application 122 is installed in computing device 100, a driver module can be added to operating system 120.

[0030] When computing device 100 starts running, processor 104 reads and executes the program instructions of operating system 120 from memory 106. Application 122 runs on top of operating system 120 and uses the interfaces provided by operating system 120 and the underlying hardware to implement various user-desired functions. When the user starts application 122, application 122 is loaded into memory 106, and processor 104 reads and executes the program instructions of application 122 from memory 106.

[0031] Computing device 100 further includes a storage device 132, and storage device 132 includes a removable storage 136 and a non-removable storage 138, and both removable storage 136 and non-removable storage 138 are connected to a storage interface bus 134.

[0032] The computing device 100 may also include an interface bus 140 that facilitates communication from various interface devices (e.g., output device 142, peripheral interface 144, and communication device 146) to the basic configuration 102 via the bus / interface controller 130. Example output devices 142 include a graphics processing unit 148 and an audio processing unit 150. They may be configured to facilitate communication with various external devices such as a display or speakers via one or more A / V ports 152. Example peripheral interfaces 144 may include a serial interface controller 154 and a parallel interface controller 156, which may be configured to facilitate communication with external devices such as input devices (e.g., keyboard, mouse, pen, voice input device, touch input device) or other peripherals (e.g., printer, scanner, etc.) via one or more I / O ports 158. Example communication device 146 may include a network controller 160, which may be arranged to facilitate communication with one or more other computing devices 162 via one or more communication ports 164 over a network communication link.

[0033] The network communication link may be an example of a communication medium. A communication medium can generally embody computer-readable instructions, data structures, program modules in a modulated data signal such as a carrier wave or other transmission mechanism, and can include any information delivery medium. A "modulated data signal" can be a signal in which one or more of its data sets or its changes can encode information in the signal. As a non-limiting example, the communication medium can include wired media such as a wired network or a dedicated line network, and various wireless media such as sound, radio frequency (RF), microwave, infrared (IR), or other wireless media. The term computer-readable medium as used herein can include both storage media and communication media.

[0034] In the computing device 100 according to the present invention, the application 122 includes instructions for executing the method 400 of creating a sandbox environment for plug-in operation according to the present invention, and the instructions can direct the processor 104 to execute the method 400 of creating a sandbox environment for plug-in operation according to the present invention. Before describing the method 400, first refer to Figure 3 to describe the overall design concept of the sandbox creation scheme according to the embodiments of the present invention.

[0035] When a plug-in runs on a client machine, it is necessary to ensure that the plug-in does not affect the client machine, such as operating sensitive files of the client. Therefore, a sandbox environment is designed to isolate the operation of the plug-in. The docker mentioned in the background art is a general design and cannot be customized. The sandbox scheme implemented according to the present invention can solve this problem.

[0036] As Figure 3As shown, when the system starts, the plugin service itself clones the sandbox, or starts the sandbox process. Subsequently, each time a plugin (taking SO as an example of the plugin) is called, the SO is placed into the sandbox process to achieve isolation between the plugin and the host environment as well as isolation between plugins.

[0037] This article takes the Linux operating system as an example for a detailed exemplary description. However, it should be understood that the present invention is not limited to being applied to the Linux operating system and can also be compatible with other systems such as the Windows operating system. Environmental isolation can be achieved through the Namespace of the Linux kernel. Among them, Namespaces are the ways used by the Linux kernel to isolate kernel resources. Processes in different Namespaces have independent global system resources, and changing the system resources in one Namespace only affects the processes in the current Namespace and has no impact on the processes in other Namespaces.

[0038] This sandbox solution utilizes the Linux kernel and, at the process level, uses the Namespace and Cgroups functional mechanisms to achieve secure isolation between plugin services and between plugin services and the system, enabling plugin service processes in different Namespaces to have independent global system resources and different plugin services to have different resource limitations.

[0039] Before the plugin service calls the plugin process, global system resource encapsulation isolation is performed on each plugin process, isolating the PID (chroot process tree), inter-process communication, mount points, network, and users of each plugin process, thereby completing the configuration of environmental isolation and thus completing the basic initialization. Among them, in the Linux system, each file can be mounted on the system. If isolation is performed through the Namespace, the mount points will also be isolated. For example, for folder A, after isolating the mount point through the Namespace, the mount point cannot be seen on the host machine, and it can only be seen by entering the virtual environment. This step of isolating the mount point cooperates with Changeroot (change root is to change the root directory location referred to during program execution) to map the host directory of the plugin to the home directory in the sandbox. The method is to first mount a directory and then use Changeroot to point this directory to the home directory.

[0040] As Figure 3 shown and as described above, a separate sandbox environment is created for each main plugin and its slave plugin files, such that the operation of the plugin does not affect the host machine and environmental isolation between plugins is also achieved.

[0041] Figure 4The flowchart of method 400 for creating a sandbox environment for plug-in operation according to an embodiment of the present invention is shown. Method 400 is executed in a computing device (such as the aforementioned computing device 100) for templatized management and control of the resources of the plug-in process. As Figure 4 shown, method 400 starts at step S410. The following will refer to Figure 4 method 400 for a detailed description.

[0042] In step S410, a sandbox environment is created, the local directory for each plug-in is mapped into the sandbox environment, and the device management directory of the host is mapped into the sandbox environment.

[0043] What step S410 describes is the first step of initialization, that is, cloning a process with isolated environment. Its essence is to clone a plug-in service process (sandbox process) with isolated environment through the invocation of different Namespace functions.

[0044] In this article, the Linux operating system is taken as an example for a detailed exemplary description. However, it should be understood that the present invention is not limited to being applied to the Linux operating system and can also be compatible with other systems such as the Windows operating system. Under the Linux operating system, if the backends of the plug-in interface platform solutions are all written in the GO language, the GO language can be selected to develop the sandbox here, that is, to implement a sandbox environment in the GO language. However, it should be understood that other languages such as C and C++ can also be used to write the sandbox environment, and the present invention is not limited thereto here. The technical means adopted can be to achieve environment isolation through the Namespace of the Linux Kernel. Among them, Namespaces are the ways used by the Linux kernel to isolate kernel resources. Processes in different Namespaces have independent global system resources, and changing the system resources in one Namespace will only affect the processes in the current Namespace and have no impact on the processes in other Namespaces.

[0045] In an optional example, before cloning the sandbox process, the plug-in service can be cloned, and the subsequent sandbox cloning, plug-in loading, etc. processes are run by the cloned plug-in service. In this way, there will be some initial configuration information such as environment variables and image information of the original plug-in service in the sandbox environment, and this process can be cleared. In this embodiment, the kernel's Execve system function can be used to empty the configuration information. Invoke this system function to run the specified plug-in process and replace the initial init process (because the process of the plug-in service is copied, there will be an initial init process).

[0046] In addition, the corresponding local directory needs to be mapped to the sandbox environment for each plugin. This is because the plugin may need to cache or read files during operation, so a working directory needs to be provided for the plugin to run. However, a working directory needs to be provided for the plugin in the sandbox environment. A directory is created on the host for each plugin. During the sandbox initialization process, the corresponding change root setting can also be made according to the file path rule (the plugin name is the directory name), mapping the directory on the host to the home directory in the virtual environment. The plugin service will create the corresponding directory mapping according to the plugin ID and version. Among them, the plugin ID and version information come from the message sent by the front end (such as a browser) to the plugin service. In the subsequent steps, the corresponding plugin will also be loaded according to this message.

[0047] In addition, to enable the hardware to support hot plugging, the host's " / dev" device management directory can also be mapped to the sandbox through the Mount Namespace mechanism, so that the sandbox has complete access rights to the hardware. The " / dev" directory is the management directory for all hardware in the Linux system. For example, when a USB flash drive is inserted, the information of the USB flash drive is mounted in the dev directory.

[0048] S420, different resource restrictions are added to different sandbox environments.

[0049] After completing the isolation of the sandbox environment, different resource restrictions also need to be added to different sandbox environments. Resource restriction refers to the control over the computer resources occupied by each plugin process, such as controlling so that the running memory of plugin process A does not exceed 100M, and the CPU occupied by plugin process B does not exceed 5%, etc. In this way, the resource requirements for plugin operation can be met. For example, if there are a relatively large number of plugins, there will be requirements for the resource utilization rate of each plugin, such as not allowing the memory occupancy rate of any plugin to exceed 20% of the entire system, etc. In addition, if platformization is done, restrictions also need to be imposed on different categories of plugins.

[0050] Here, the Cgroups technology of Linux can be used to restrict and control the resources of the plugin process and its spawned child processes. The Cgroups technology is described below.

[0051] Cgroups contains three components: cgroup, subsystem, and hierarchy, which assist each other to complete the resource limitation of processes. The cgroup component is a mechanism for grouping and managing processes. A cgroup contains a set of processes, which can be associated through various parameter configurations of the subsystem. The subsystem is a set of resource control modules, including access control for block device input / output and setting CPU scheduling policies, etc. The function of the hierarchy is to string a set of cgroups into a tree structure to complete the inheritance of resource limitations through the tree structure.

[0052] In actual business applications, we manage a set of processes and a set of system parameters of the subsystem by adding various parameter configurations of the Linux subsystem to the cgroup, so as to formulate different cgroup templates for different plugins. The subsystem acts on the cgroup nodes on the hierarchy to control the resource occupancy of the processes in the nodes. Therefore, when setting resource limitations, corresponding templates can be specified according to the resource usage of different plugins (such as a large number of disk I / O reads and writes, long-term high memory occupancy, etc.), such as memory limit templates, hard disk read / write limit templates, etc.

[0053] Since the hierarchy strings the cgroups through a tree structure and exposes them to users through the virtual file system. Therefore, when configuring the resource limitations of each sandbox, only read and write to the corresponding files are required to achieve it. For example, to implement a memory limit template, after obtaining the absolute path of the cgroup in the file system, create a corresponding file in the memory of the cgroup and configure the relevant fields of memory.limit_in_bytes to achieve memory limitation. Finally, the cgroups in these different subsystems need to be managed and related to the sandbox.

[0054] S430, load the plugin process management.

[0055] The plugin process management can be a pre-written functional module. After the plugin service clones a sandbox environment, it will load the plugin process management into the cloned sandbox process.

[0056] S440, receive the message transmitted by the front end. The message contains the ID of the plugin and the version of the plugin, and passes it to the plugin process management.

[0057] After initialization, an empty sandbox environment is obtained. The plugin service also needs to send a specified message to the plugin process management. This message contains information such as the ID and version of the plugin, so that the plugin process management can load the corresponding plugin according to this message.

[0058] The plugin service receives this message from the front end, which can be a browser or the like. This message can contain a message ID and message content. The message ID is used to distinguish each message, so that when the recipient returns a response, the sender knows which message the response is for.

[0059] S450, load the corresponding plugin through the plugin process management, where only one main plugin and the slave plugins dependent on the main plugin are loaded in a sandbox environment.

[0060] After creating the sandbox process, the sandbox process loads the plugin process management function module, and the plugin process management then loads the plugin (such as an SO file), thus forming a sandbox environment for the plugin process.

[0061] The significance of establishing this sandbox environment is as follows: When the operating system runs different programs, each program is a process. If they run in the same environment, they will affect each other. For example, they can all operate on local files. Establishing a sandbox is equivalent to simulating a new operating system environment similar to the original one inside the operating system, and running processes in this new operating system environment. The processes running in the sandbox environment are isolated from the processes running on the outside host and cannot affect each other. In the embodiments of the present invention, the plugin process is placed in the sandbox environment to run so that it will not affect the operation of other programs on the host.

[0062] In terms of ensuring hardware security, it is also possible to restrict sandbox hardware access. The specific implementation means can be to develop a device management program in the host and restrict it by communicating with the sandbox in the way of grpc.

[0063] Optionally, the method 400 may further include: establishing a communication port for communicating with the plugin process management, receiving the registration of the loaded plugin through the plugin process management, and obtaining the instance link of the corresponding plugin.

[0064] After the plugin process management successfully loads the plugin, the plugin can actively register with the plugin service through the plugin process management by means of communication such as grpc (that is, the plugin process management sends instance information to the plugin service), and the plugin service obtains the corresponding plugin instance link for communication. Among them, the plugin instance link means that when the plugin process runs, it will register an address with the plugin service, and calling this address can operate its methods and some functions to conduct subsequent business communication. For example, if the plugin is used for image reading, then an image reading message can be sent for corresponding processing, etc.

[0065] After successfully invoking the plugin process management in the sandbox environment, the plugin service can also obtain the process ID (PID) of the sandbox process for management purposes, such as controlling the sandbox lifecycle, such as the alive state, exiting the plugin, etc. Here, PID means that for each running plugin process, a sandbox process is created, and the system will assign an ID (PID) to this sandbox process.

[0066] Figure 5 A concurrent dual-thread schematic flowchart of the method according to an embodiment of the present invention is shown, in which the main service that creates the sandbox process and the plugin process are shown in parallel. From Figure 5 it can be seen that the left process is the main service executed by the plugin service, and the right process is the plugin process that runs the plugin after loading the plugin.

[0067] Among them, "create sandbox" means creating a sandbox module in the plugin service, and the following "create sandbox process" is a step in the operation of this module, indicating that the left column is the process of creating the sandbox process. The left column sandbox creation process includes an optional step of "null processing", in which the operation of replacing the init (initialization) process is particularly shown. Mounting the file system means mapping the device directory / dev to the sandbox environment. Configuring the namespace environment isolation means that the sandbox encapsulates and isolates the global system resources of each plugin process through the system call function of the Linux kernel, isolating the PID (chroot process tree), inter-process communication, mount point, network, and USER of each plugin process, and completing the basic initialization. Loading the policy template means loading "memory limit template, hard disk read and write limit template", etc. as described above.

[0068] The right column is the plugin process executed after loading the plugin and running the plugin. Among them, the plugin service establishes a grpc communication port, and the client (i.e., Figure 2 "plugin process management" in it) is ready for communication. Then, the client sends plugin instance information (including port number, plugin information) to the plugin service for the plugin service to call the plugin business function later.

[0069] Among them, protobuf is an efficient protocol data exchange format tool library provided by Google. In addition to protobuf, communication protocols such as http can also be used, and the present invention is not limited thereto.

[0070] Creating the sandbox process is a process executed by the plugin service. After actually running, the entire process is a two-way interaction process between the plugin service and the plugin process management.

[0071] Through the method embodiments described above, each time the plugin system starts the backend service, a sandbox process will be cloned. Each time the frontend calls the plugin service, the plugin will be loaded in this sandbox process to achieve plugin isolation. Based on project requirements, the sandbox mechanism does not need to be as complex as Docker. It only needs to focus on the implementation inside the sandbox to meet the isolation of environmental resources and controllable permissions between each plugin.

[0072] In addition, different from Docker which initializes a new process each time to set up the sandbox environment, according to the technical solution of this embodiment, in a sandbox environment, a plugin process is managed to load the plugin. In this way, another advantage can be obtained: each plugin runs in a sandbox environment. When the external plugin service needs to communicate with the plugin, under the condition that the network and file system are isolated, communication can be achieved through the reserved ports to penetrate the sandbox environment.

[0073] Next, refer to Figure 6 the schematic block diagram of the device for creating a sandbox according to an embodiment of the present invention. As Figure 6 shown, the device includes:

[0074] A creation module 610, configured to create a sandbox environment, map the local directory for each plugin to the sandbox environment, and map the device management directory of the host to the sandbox environment.

[0075] Optionally, Figure 6 the device may include: a plugin service creation module, configured to create a plugin service, and the created plugin service calls the remaining modules in the device to execute processes such as sandbox cloning and plugin loading. The device may further include: a nulling module, configured to perform a clearing process on the initial configuration information of the plugin service created in the sandbox environment. This is because, after the plugin service is created, there will be some environment variables and image information of the original plugin service in the sandbox environment. Therefore, it is necessary to perform a clearing process on this process. The nulling module may use the kernel's Execve system function to nullify the configuration information. By calling this system function, the specified plugin process is run to replace the initial initialization (init) process (because the process of the plugin service is copied, there will be an initial initialization process).

[0076] As Figure 6 shown, the device includes a resource limitation module 620, configured to add different resource limitations to different sandbox environments. This module may use Linux's Cgroups technology to perform resource limitation and control on the plugin process and its generated child processes.

[0077] As Figure 6As shown, the apparatus further includes a loading module 630 for loading plugin process management. The plugin process management can be a pre-written functional module. After the plugin service clones a sandbox environment, it will load the plugin process management into the cloned sandbox process.

[0078] As Figure 6 shown, the apparatus further includes a receiving module 640 for receiving messages transmitted by the front end. The messages include the ID and version of the plugin and are passed to the plugin process management. The apparatus further includes a plugin loading module 650 for loading the corresponding plugin through the plugin process management, where only one main plugin and the slave plugins dependent on the main plugin are loaded in a sandbox environment.

[0079] In an optional example, Figure 6 the apparatus further includes a communication module for establishing a communication port for communicating with the plugin process management, receiving the registration of the loaded plugin through the plugin process management, and obtaining the instance link of the corresponding plugin. The communication module can also obtain the process ID (PID) of the sandbox process for management. Here, PID means that for each running plugin process, a sandbox process will be created, and the system will assign an ID (PID) to this sandbox process.

[0080] Regarding the parts not detailed in the implementation manner of the apparatus, please refer to the description of the above method implementation manner, which will not be elaborated herein.

[0081] The various technologies described here can be implemented in combination with hardware or software, or a combination of them. Thus, the method and device of the present invention, or certain aspects or parts of the method and device of the present invention, can take the form of program code (i.e., instructions) embedded in a tangible medium, such as a removable hard disk, USB flash drive, floppy disk, CD-ROM, or any other machine-readable storage medium. When the program is loaded into a machine such as a computer and executed by the machine, the machine becomes a device for practicing the present invention.

[0082] In the case where the program code is executed on a programmable computer, the computing device generally includes a processor, a processor-readable storage medium (including volatile and non-volatile memories and / or storage elements), at least one input device, and at least one output device. Among them, the memory is configured to store the program code; the processor is configured to execute the method of creating a sandbox environment for plugin operation according to the instructions in the program code stored in the memory.

[0083] By way of example, and not limitation, a readable medium includes a readable storage medium and a communication medium. A readable storage medium stores information such as computer readable instructions, data structures, program modules or other data. A communication medium generally embodies computer readable instructions, data structures, program modules or other data in a modulated data signal such as a carrier wave or other transport mechanism, and includes any information delivery medium. Combinations of any of the above are also included within the scope of the readable medium.

[0084] In the specification provided herein, the algorithms and displays are not inherently related to any particular computer, virtual system, or other device. Various general purpose systems may also be used with examples of the present invention. The structure required to construct such systems will be apparent from the above description. Additionally, the present invention is not directed to any particular programming language. It should be understood that the present invention as described herein may be implemented using various programming languages, and the description of a particular language above is for the purpose of disclosing the preferred embodiments of the present invention.

[0085] In the specification provided herein, numerous specific details are set forth. However, it can be understood that embodiments of the present invention may be practiced without these specific details. In some instances, well-known methods, structures, and techniques have not been shown in detail so as not to obscure the understanding of this specification.

[0086] Similarly, it should be understood that in order to streamline the present disclosure and assist in understanding one or more of the various inventive aspects, in the foregoing description of the exemplary embodiments of the present invention, the various features of the present invention are sometimes grouped together in a single embodiment, figure, or description thereof. However, the disclosed method should not be construed as reflecting an intention that the claimed invention requires more features than are expressly recited in each claim. Those skilled in the art will appreciate that the modules or units or components of the devices in the examples disclosed herein may be arranged in the devices as described in that embodiment, or alternatively may be located in one or more devices different from those of the example. The modules in the foregoing examples may be combined into one module or further divided into multiple sub-modules.

[0087] Those skilled in the art can understand that the modules in the devices in the embodiments can be adaptively changed and arranged in one or more devices different from the embodiments. The modules or units or components in the embodiments can be combined into one module or unit or component, and in addition, they can be divided into multiple sub-modules or sub-units or sub-components. Except that at least some of such features and / or processes or units are mutually exclusive, any combination can be adopted to combine all the features disclosed in this specification (including the accompanying claims, abstract and drawings) and all the processes or units of any method or device so disclosed. Unless otherwise explicitly stated, each feature disclosed in this specification (including the accompanying claims, abstract and drawings) can be replaced by an alternative feature that provides the same, equivalent or similar purpose.

[0088] In addition, those skilled in the art can understand that although some of the embodiments described herein include certain features included in other embodiments rather than other features, the combination of features of different embodiments means that it is within the scope of the present invention and forms different embodiments. In addition, some of the embodiments are described herein as combinations of methods or method elements that can be implemented by a processor of a computer system or by other devices performing the functions. Therefore, a processor having the necessary instructions for implementing the method or method element forms a device for implementing the method or method element. In addition, the elements described herein in the device embodiments are examples of such devices: the device is used to implement the functions performed by the elements for the purpose of implementing the present invention.

[0089] As used herein, unless otherwise specified, the use of ordinal numbers "first", "second", "third", etc. to describe ordinary objects only indicates different instances of similar objects, and does not intend to imply that the objects so described must have a given order in terms of time, space, sorting, or in any other way.

[0090] Although the present invention has been described in terms of a limited number of embodiments, those skilled in the art in this technical field will understand, from the above description, that other embodiments can be conceived within the scope of the present invention thus described. In addition, it should be noted that the language used in this specification is mainly selected for the purpose of readability and teaching, rather than for the purpose of explaining or limiting the subject matter of the present invention.

Claims

1. A method for creating a sandbox environment for plugin operation, which is executed in a computing device, includes: Create a plugin service, and the plugin service is used to perform the following steps: Create a sandbox environment, map the local directory for each plugin into the sandbox environment, and map the device management directory of the host to the sandbox environment; Add different resource limits to different sandbox environments; Load plugin process management; Receive the message transmitted by the front end, where the message includes the ID of the plugin and the version of the plugin, and pass it to the plugin process management; Load the corresponding plugin through the plugin process management, where only one main plugin and the slave plugins dependent on the main plugin are loaded in one sandbox environment; Empty the sandbox environment to clear the initial configuration information left by the plugin service in the sandbox environment; And Establish a communication port for communicating with the plugin process management, receive the registration of the loaded plugin through the plugin process management, and obtain the instance link of the corresponding plugin.

2. The method for creating a sandbox environment for plugin operation according to claim 1, further includes: After loading the plugin process management, receive the ID of the sandbox process for management, where one ID of the sandbox process is generated for each running plugin process.

3. An apparatus for creating a sandbox environment for plugin operation, which is disposed in a computing device, includes: A creation module, which is used to create a sandbox environment, map the local directory for each plugin into the sandbox environment, and map the device management directory of the host to the sandbox environment; A resource limit module, which is used to add different resource limits to different sandbox environments; A loading module, which is used to load plugin process management; A receiving module, which is used to receive the message transmitted by the front end, where the message includes the ID of the plugin and the version of the plugin, and pass it to the plugin process management; A plugin loading module, which is used to load the corresponding plugin through the plugin process management, where only one main plugin and the slave plugins dependent on the main plugin are loaded in one sandbox environment; A plugin service creation module, which is used to create a plugin service, and the created plugin service calls the creation module, the resource limit module, the loading module, the receiving module, and the plugin loading module; An emptying module, which is used to empty the sandbox environment to clear the initial configuration information left by the plugin service in the sandbox environment; A communication module, which is used to establish a communication port for communicating with the plugin process management, receive the registration of the loaded plugin through the plugin process management, and obtain the instance link of the corresponding plugin.

4. The apparatus for creating a sandbox environment for plug-in operation according to claim 3, wherein, The communication module receives the ID of the sandbox process for management, where one ID of the sandbox process is generated for each running plugin process.

5. A computing device includes: At least one processor and a memory storing program instructions; When the program instructions are read and executed by the processor, the computing device executes the method for creating a sandbox environment for plugin operation according to claim 1 or 2.

6. A readable storage medium storing program instructions, which, when read and executed by a computing device, cause the computing device to execute the method for creating a sandbox environment for plug-in operation as claimed in claim 1 or 2.

Citation Information

Patent Citations

  • Android plug-in implementation method and device based on APK (Android Package) dynamic loading and interaction method

    CN104216741A

  • Plugin authority control method and device and plugin system

    CN107066872A