A file system permission control method and device, and a medium

CN115374475BActive Publication Date: 2026-09-29JINAN INSPUR DATA TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211026945.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-25
Publication Date
2026-09-29
Estimated Expiration
2042-08-25

AI Technical Summary

Technical Problem

但当同一服务器中使用了多种不同的存储协议时,用户需要频繁切换登录身份以访问不同文件系统中的文件

Benefits of technology

[0034]本申请提供一种文件系统权限控制方法,包括:判断是否检测到客户端发送的权限设置请求,若接收到权限设置请求,解析权限设置请求,以获取新增权限信息,以根据用户需求对文件系统的权限进行设置。根据新增权限信息创建POSIX结构体,以生成目标权限信息;其中,POSIX结构体为用于各存储协议的权限信息的结构体;将目标权限信息下刷至文件系统。由此可见,本申请所提供的技术方案,通过POSIX结构体整合文件系统中全部存储协议所对应的权限信息,并将POSIX结构体中的目标权限信息下刷至文件系统中,以便于文件系统根据POSIX结构体中的信息判断用户是否具有访问权限,从而实现不同文件系统间访问权限的互通,无需对同一用户的在多个协议中的权限进行单独校验,提高用户访问数据的效率。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115374475B_ABST
    Figure CN115374475B_ABST
Patent Text Reader

Abstract

The application relates to the storage field and discloses a file system permission control method and device and a medium, which comprises the following steps: judging whether a permission setting request sent by a client is detected, if the permission setting request is received, analyzing the permission setting request to obtain new permission information, creating a POSIX structure according to the new permission information to generate target permission information, wherein the POSIX structure is a structure for permission information of various storage protocols, and the target permission information is pushed to a file system. According to the application, the permission information corresponding to all storage protocols in the file system is integrated through the POSIX structure, and the target permission information in the structure is pushed to the file system, so that the file system can judge whether a user has access permission according to the information in the structure, the access permission between different file systems is interchanged, the permission of the same user in multiple protocols does not need to be checked separately, and the efficiency of user access to data is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of storage, and in particular to a file system permission control method, apparatus, and medium. Background Technology

[0002] With the rapid development of storage technology, the types of storage protocols used to provide storage services to users are also increasing, such as the Hadoop Distributed File System and Simple Storage Service (S3). However, when multiple different storage protocols are used on the same server, users need to frequently switch login identities to access files in different file systems.

[0003] Therefore, how to achieve permission sharing and data sharing in different file systems to improve the efficiency of users accessing file data is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention

[0004] The purpose of this application is to provide a file system access control method, apparatus, and medium, enabling users to access data stored in different file systems using the same identity, thereby achieving access control and data sharing across different file systems and improving the efficiency of user access to file data. To solve the above-mentioned technical problems, this application provides a file system access control method, including:

[0005] Determine whether a permission setting request sent by the client has been detected;

[0006] If the permission setting request is received, parse the permission setting request to obtain the new permission information;

[0007] A POSIX structure is created based on the newly added permission information to generate the target permission information; wherein, the POSIX structure is a structure for permission information of various storage protocols;

[0008] The target permission information is then flushed to the file system.

[0009] Preferably, after the step of determining whether a permission setting request sent by the client has been detected, the method further includes:

[0010] Determine whether the user who sent the permission setting request is a preset user;

[0011] If it is the preset user, then the step of parsing the permission setting request is performed.

[0012] Preferably, after the step of determining whether the user sending the permission setting request is a preset user, the method further includes:

[0013] If the user is not the preset user, then determine whether the permission setting request is an anti-leeching setting request;

[0014] If a request is made to set up anti-leeching, then anti-leeching is set up.

[0015] Preferably, the POSIX structure further includes: user information and POSIX permission version information;

[0016] After the step of creating a POSIX structure based on the newly added permission information, the method further includes:

[0017] Update the POSIX permission version information.

[0018] Preferably, creating a POSIX structure based on the newly added permission information includes:

[0019] Determine whether a historical POSIX structure exists in the file system;

[0020] If the historical POSIX structure exists, the ACL_USER permission bit is determined based on the newly added permission information and the historical POSIX structure, and the ACL_USER permission bit is filled into the historical POSIX structure.

[0021] If the historical POSIX structure does not exist, a new POSIX structure is created, and the permission bits corresponding to the newly added permission information are filled into the new POSIX structure.

[0022] Preferably, the step of flashing the target permission information to the file system includes:

[0023] Copy the POSIX structure to the file system;

[0024] The GROUP permission and OTHER permission bit in the POSIX structure are retrieved to update the mode permission of the above file system.

[0025] Preferably, the POSIX structure includes at least S3 protocol permissions and NAS protocol permissions.

[0026] To address the aforementioned technical problems, this application also provides a file system permission control device, comprising:

[0027] The judgment module is used to determine whether a permission setting request sent by the client has been detected.

[0028] The parsing module is used to parse the permission setting request upon receiving it in order to obtain the new permission information;

[0029] The generation module is used to create a POSIX structure based on the newly added permission information to generate target permission information; wherein, the POSIX structure is a structure for permission information of various storage protocols;

[0030] The flush module is used to flush the target permission information to the file system.

[0031] To address the aforementioned technical problems, this application also provides another file system permission control device, including a memory for storing computer programs;

[0032] A processor is configured to implement the file system permission control method when executing the computer program.

[0033] To address the aforementioned technical problems, this application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the file system permission control method described above.

[0034] This application provides a file system permission control method, including: determining whether a permission setting request sent by a client is detected; if a permission setting request is received, parsing the permission setting request to obtain new permission information, so as to set the permissions of the file system according to user needs; creating a POSIX structure based on the new permission information to generate target permission information; wherein, the POSIX structure is a structure for permission information of various storage protocols; and flushing the target permission information to the file system. Therefore, the technical solution provided by this application integrates the permission information corresponding to all storage protocols in the file system through a POSIX structure, and flushes the target permission information in the POSIX structure to the file system, so that the file system can determine whether the user has permission based on the information in the POSIX structure, thereby achieving interoperability of access permissions between different file systems without the need to separately verify the permissions of the same user in multiple protocols, improving the efficiency of user data access.

[0035] In addition, this application also provides a file system permission control device and medium, which correspond to the above method and have the same effect. Attached Figure Description

[0036] To more clearly illustrate the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0037] Figure 1This is a schematic diagram of a POSIX mechanism access permission provided in an embodiment of this application;

[0038] Figure 2 This is a flowchart of a file system permission control method provided in an embodiment of this application;

[0039] Figure 3 This is a schematic diagram of a POSIX structure provided in an embodiment of this application;

[0040] Figure 4 This is a structural diagram of a file system permission control device provided in an embodiment of this application;

[0041] Figure 5 This is a structural diagram of another file system permission control device provided in an embodiment of this application. Detailed Implementation

[0042] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the protection scope of this application.

[0043] The core of this application is to provide a file system permission control method, device, and medium, so that users can use the same identity to access data information stored in different file systems, thereby realizing permission sharing and data sharing in different file systems and improving the efficiency of users accessing file data.

[0044] After data is stored in a file system, different file systems use different storage protocols. Users lacking the necessary permissions for the relevant protocols cannot access data stored using other storage protocols through a particular file system, impacting data retrieval efficiency. To address this issue, this application provides a file system permission control method for S3 and NAS systems. The method includes: determining whether a permission setting request from a client is detected; if so, parsing the request to obtain new permission information for setting file system permissions according to user needs; creating a POSIX structure based on the new permission information to generate target permission information; wherein the POSIX structure is a structure for permission information for various storage protocols; and flushing the target permission information to the file system. Therefore, the technical solution provided in this application integrates the permission information corresponding to all storage protocols in the file system through a POSIX structure and flushes the target permission information from the POSIX structure to the file system. This allows the file system to determine whether a user has permission based on the information in the POSIX structure, thereby achieving interoperability of access permissions between different file systems without the need for separate verification of the same user's permissions across multiple protocols, improving the efficiency of user data access. Figure 1 This is a schematic diagram of a POSIX mechanism access permission provided in an embodiment of this application, such as... Figure 1 As shown, after adopting the solution provided by this invention, each protocol has access permissions to the file bucket1. Specifically, S3user1 grants S3user2 "read and write" permissions to bucket1, so Unix_user2, which is mapped to S3user2, also has "read and write" permissions to bucket1. Then, S3user1 grants S3user2 "read" permissions to bucket1, at which point NFSuser4 and CIFuserN, which are mapped to Unix_user3, also have "read" permissions to bucket1, thus realizing the interoperability of access permissions between the various protocols.

[0045] To enable those skilled in the art to better understand the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0046] Figure 2 This is a flowchart of a file system permission control method provided in an embodiment of this application, as shown below. Figure 2 As shown, the method includes:

[0047] S10: Determine whether a permission setting request sent by the client has been detected.

[0048] S11: If a permission setting request is received, parse the permission setting request to obtain the new permission information.

[0049] S12: Create a POSIX structure based on the newly added permission information to generate the target permission information; wherein, the POSIX structure is a structure used for permission information of various storage protocols.

[0050] S13: Fetch the target permission information to the file system.

[0051] Figure 3 This is a schematic diagram of a POSIX structure provided in an embodiment of this application. To ensure interoperability of POSIX permissions between different protocols, this embodiment uses a permission structure to record the relevant permission information of each protocol. Figure 3 As shown, this structure can be used to store permission information for commonly used communication protocols (such as S3, NAS, NFS, and SMB). For the S3 system, permission information includes: write permission (indicating whether the user can delete a file), read permission (indicating whether the user can list objects within a downloaded file), write_acp permission (indicating whether the user can set file ACLs), read_acp permission (indicating whether the user can view file ACLs), and full_control (indicating that the user has permission to perform all of the above operations on the file set). In specific implementation, the permissions of the file storage protocol are mapped to POSIX structures, and the mapping rules are as follows: (1) e_tag is mapped to ACL_USER in S3 permissions; (2) e_perm is the corresponding permission set by S3 (full_control, write, read, write_acp, read_acp, etc.); (3) e_id is the uid / gid of the Unix user mapped by the S3 user, used to identify the user identity; (4) a_version is the version number of the POSIX permission, and the value of a_version is incremented by 1 every time the version number of this permission bit is modified. It can be understood that since the file protocol may change, a_version represents the version of the protocol corresponding to the permission bit. When the versions of the protocols corresponding to different permission bits are different, the latest version of the file storage protocol can be selected, or the version protocol specified by the administrator can be selected. There is no limitation here.

[0052] In practice, a POSIX structure is created based on the newly added permission information to generate the target permission information, specifically as follows:

[0053] The system retrieves the permission information from the historical POSIX structure `old_posix` of the file collection `bucket`, extracts the `ACL_USER` permission bit from it, merges it with the permission information in the new request, and saves the merged result. In this embodiment, the merged permission information is saved to the data `POSIX_acl_map` for later use.

[0054] Create a new POSIX permission structure new_posix and move the first permission bit ACL_USER_OBJ in the old POSIX structure old_posix to the first permission bit in the new permission structure new_posix;

[0055] The POSIX_acl_map is traversed, and new_posix is ​​filled sequentially according to the filling rules. The version number of the corresponding permission bit is updated and the sum of all permissions perm is recorded.

[0056] Remove the ACL_USER_OBJ and ACL_USER permission bits from old_posix, then iterate through old_posix, update new_posix with the remaining permission bits, and update the permission of ALC_MASK to perm.

[0057] Find the ACL_GROUP_OBJ and ACL_OTHER permission bits in new_posix, then obtain the mode permission of the corresponding bucket, and update the G and O permission bits in the mode permission.

[0058] This embodiment provides a file system permission control method, including: determining whether a permission setting request sent by a client is detected; if a permission setting request is received, parsing the permission setting request to obtain new permission information, so as to set the permissions of the file system according to user needs; creating a POSIX structure based on the new permission information to generate target permission information; wherein, the POSIX structure is a structure for permission information of various storage protocols; and flushing the target permission information to the file system. Therefore, the technical solution provided in this application integrates the permission information corresponding to all storage protocols in the file system through a POSIX structure, and flushes the target permission information in the POSIX structure to the file system, so that the file system can determine whether the user has permission based on the information in the POSIX structure, thereby achieving interoperability of access permissions between different file systems without the need to separately verify the permissions of the same user in multiple protocols, improving the efficiency of user data access.

[0059] It is understandable that, in order to ensure the security of the file system's permission system and prevent excessive modifications from causing permission chaos, based on the above embodiment, after determining whether a permission setting request sent by the client is detected, the method further includes: determining whether the user sending the permission setting request is a preset user; if it is a preset user, then performing the step of parsing the permission setting request.

[0060] The file system modifies permission information based on the permission setting request sent by the client only when the user sending the permission setting request is the default user.

[0061] Furthermore, after determining whether the user sending the permission setting request is a preset user, the process also includes:

[0062] If it is not a default user, then determine whether the permission setting request is an anti-hotlinking setting request;

[0063] If a request is made to set up anti-leeching, then anti-leeching is enabled.

[0064] In a preferred embodiment, the POSIX structure also includes: user information and POSIX permission version information;

[0065] After the steps of creating a POSIX structure based on the newly added permission information, the process also includes updating the POSIX permission version information.

[0066] In practice, the POSIX structure stores the identity information of users with access permissions, enabling the system to determine whether to provide data to them. Furthermore, the POSIX structure also includes permission version number information. It's understandable that different files, created at different times, correspond to different POSIX permission versions. Therefore, the POSIX structure records the POSIX permission version number and the number of times the permission has been modified. This allows the system to determine the final POSIX permission version based on the version number, the number of version number modifications, and the user's permission setting requests when integrating POSIX permissions for different files, ensuring that the user can use the permissions.

[0067] It is understandable that, since the permission bits involved in S3 are different from those in other protocols, when implementing integration and interoperability with other protocols, it is necessary to ensure that modifications to related data do not affect the impact of non-modified positions on other protocols. Therefore, this embodiment designs a set of POSIX structure filling rules to avoid affecting the permissions set by other protocols.

[0068] Based on the above embodiments, creating a POSIX structure according to the newly added permission information includes:

[0069] Determine if a historical POSIX structure exists in the file system;

[0070] If a historical POSIX structure exists, the ACL_USER permission bit is determined based on the new permission information and the historical POSIX structure, and the ACL_USER permission bit is filled into the historical POSIX structure.

[0071] If no existing POSIX structure exists, a new POSIX structure is created, and the permission bits corresponding to the newly added permission information are filled into the new POSIX structure.

[0072] In practical implementation, the permission bits for each file in the POSIX structure can be stored as characters, arrays, or queues, or as files; no limitation is made here. This embodiment uses storing the POSIX structure in an array as an example to illustrate the method of filling file permission set rules.

[0073] Specifically, the population rules for file sets that have already been configured with relevant POSIX permissions are as follows:

[0074] Extract and merge the ACL_USER permission bits from the newly set new_posix and the existing old_posix into acl_map, retain the ACL_USER_OBJ permission bits in the already set old_posix, and record its storage position i; fill the data in acl_map sequentially after the ACL_USER_OBJ permission bits, that is, start filling from position i, and record the storage position after filling as j; fill the permission bits after ACL_USER_OBJ in old_posix starting from position j.

[0075] The rules for populating file sets for which no POSIX permissions have been set are as follows:

[0076] Set the ACL_USER_OBJ permission bit in new_posix and record it at position i; map the permission settings in the client request and fill them sequentially from position i and record them at position j; fill the ACL_GROUP, ACL_MASK, and ACL_OTHER permission bits sequentially from position j.

[0077] As a preferred embodiment, flushing the target permission information to the file system includes:

[0078] Copy the POSIX structure to the file system;

[0079] The GROUP and OTHER permissions bits in the POSIX structure are retrieved to update the mode permissions of the aforementioned file system. POSIX permission updates can be categorized under the file system xattr attribute updates. During the POSIX permission update process, parameters such as the POSIX attribute fields, the POSIX permission structure, and the size of the corresponding target permission information (new_posix) are required.

[0080] Since the S3 ACL permissions and file mode permissions are unified and interoperable in the converged and interoperable system, it is necessary to avoid affecting the S3 ACL permissions after setting POSIX permissions. Therefore, after flashing with POSIX permissions, it is also necessary to extract the ACL_GROUP_OBJ and ACL_OTHER permission bits from POSIX to update the mode permissions.

[0081] In the above embodiments, the file system permission control method has been described in detail. This application also provides embodiments corresponding to the file system permission control device. It should be noted that this application describes the embodiments of the device part from two perspectives: one is based on the functional module, and the other is based on the hardware.

[0082] Figure 4 This is a structural diagram of a file system permission control device provided in an embodiment of this application, as shown below. Figure 4 As shown, the device includes:

[0083] The judgment module 10 is used to determine whether a permission setting request sent by the client has been detected;

[0084] Parsing module 11 is used to parse the permission setting request if a permission setting request is received in order to obtain the new permission information;

[0085] The generation module 12 is used to create a POSIX structure based on the newly added permission information to generate the target permission information; wherein, the POSIX structure is a structure for permission information of various storage protocols;

[0086] The down-flush module 13 is used to down-flush the target permission information to the file system.

[0087] Since the embodiments of the apparatus and the embodiments of the method correspond to each other, please refer to the description of the embodiments of the method for the embodiments of the apparatus, which will not be repeated here.

[0088] In addition, the file system permission control device provided in this embodiment also includes a user information judgment module, an anti-hotlinking setting judgment module, and an information update module.

[0089] The user information judgment module is used to determine whether the user who sent the permission setting request is a preset user after determining whether a permission setting request sent by the client has been detected; if it is a preset user, the step of parsing the permission setting request is executed.

[0090] The anti-hotlinking setting judgment module is used to determine whether the user sending the permission setting request is a preset user after the step of determining whether the user is a preset user. If the user is not a preset user, it determines whether the permission setting request is an anti-hotlinking setting request; if it is an anti-hotlinking setting request, it sets the anti-hotlinking.

[0091] The information update module is used to update the POSIX permission version information after the step of creating a POSIX structure based on the newly added permission information.

[0092] This embodiment provides a file system permission control device, including: determining whether a permission setting request sent by a client is detected; if a permission setting request is received, parsing the permission setting request to obtain new permission information, so as to set the permissions of the file system according to user needs; creating a POSIX structure based on the new permission information to generate target permission information; wherein, the POSIX structure is a structure for permission information of various storage protocols; and flushing the target permission information to the file system. Therefore, the technical solution provided in this application integrates the permission information corresponding to all storage protocols in the file system through a POSIX structure, and flushes the target permission information in the POSIX structure to the file system, so that the file system can determine whether the user has permission based on the information in the POSIX structure, thereby realizing the interoperability of access permissions between different file systems without the need to separately verify the permissions of the same user in multiple protocols, improving the efficiency of user data access.

[0093] Figure 5 This is a structural diagram of another file system permission control device provided in an embodiment of this application, as shown below. Figure 5 As shown, the file system permission control device includes: a memory 20 for storing computer programs;

[0094] The processor 21 is used to implement the steps of the file system permission control method as described in the above embodiment when executing a computer program.

[0095] The file system permission control device provided in this embodiment may include, but is not limited to, smartphones, tablets, laptops, or desktop computers.

[0096] The processor 21 may include one or more processing cores, such as a quad-core processor or an octa-core processor. The processor 21 may be implemented using at least one of the following hardware forms: Digital Signal Processor (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). The processor 21 may also include a main processor and a coprocessor. The main processor, also known as the Central Processing Unit (CPU), is used to process data in the wake-up state; the coprocessor is a low-power processor used to process data in the standby state. In some embodiments, the processor 21 may integrate a Graphics Processing Unit (GPU), which is responsible for rendering and drawing the content to be displayed on the screen. In some embodiments, the processor 21 may also include an Artificial Intelligence (AI) processor, which is used to handle computational operations related to machine learning.

[0097] The memory 20 may include one or more computer-readable storage media, which may be non-transitory. The memory 20 may also include high-speed random access memory and non-volatile memory, such as one or more disk storage devices or flash memory devices. In this embodiment, the memory 20 is used to store at least the following computer program 201, which, after being loaded and executed by the processor 21, is capable of implementing the relevant steps of the file system permission control method disclosed in any of the foregoing embodiments. In addition, the resources stored in the memory 20 may also include an operating system 202 and data 203, and the storage method may be temporary or permanent storage. The operating system 202 may include Windows, Unix, Linux, etc. The data 203 may include, but is not limited to, permission setting requests, permission information, etc.

[0098] In some embodiments, the file system permission control device may further include a display screen 22, an input / output interface 23, a communication interface 24, a power supply 25, and a communication bus 26.

[0099] Those skilled in the art will understand that Figure 5 The structure shown does not constitute a limitation on the file system permission control device and may include more or fewer components than illustrated.

[0100] The file system permission control device provided in this application includes a memory and a processor. When the processor executes a program stored in the memory, it can implement the following method:

[0101] Determine whether a permission setting request sent by the client has been detected;

[0102] If a permission setting request is received, parse the permission setting request to obtain the new permission information;

[0103] A POSIX structure is created based on the newly added permission information to generate the target permission information; the POSIX structure is a structure used for permission information of various storage protocols.

[0104] Fetch the target permission information to the file system.

[0105] This embodiment provides a file system permission control device, including: determining whether a permission setting request sent by a client is detected; if a permission setting request is received, parsing the permission setting request to obtain new permission information, so as to set the permissions of the file system according to user needs; creating a POSIX structure based on the new permission information to generate target permission information; wherein, the POSIX structure is a structure for permission information of various storage protocols; and flushing the target permission information to the file system. Therefore, the technical solution provided by this application integrates the permission information corresponding to all storage protocols in the file system through a POSIX structure, and flushes the target permission information in the POSIX structure to the file system, so that the file system can determine whether the user has permission based on the information in the POSIX structure, thereby realizing the interoperability of access permissions between different file systems without the need to separately verify the permissions of the same user in multiple protocols, improving the efficiency of user data access.

[0106] Finally, this application also provides an embodiment corresponding to a computer-readable storage medium. The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps described in the above method embodiments.

[0107] It is understood that if the methods in the above embodiments are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and executes all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0108] The file system permission control method, apparatus, and medium provided in this application have been described in detail above. The various embodiments in the specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section. It should be noted that those skilled in the art can make several improvements and modifications to this application without departing from the principles of this application, and these improvements and modifications also fall within the protection scope of the claims of this application.

[0109] It should also be noted that, in this specification, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

Claims

1. A file system permission control method, characterized in that, include: Determine whether a permission setting request sent by the client has been detected; If the permission setting request is received, parse the permission setting request to obtain the new permission information; A POSIX structure is created based on the newly added permission information to generate target permission information. The POSIX structure is a structure for permission information of various storage protocols. The POSIX structure includes at least S3 protocol permissions and NAS protocol permissions. The POSIX structure stores the identity information of users with access permissions, records the version number of the POSIX permissions, and records the number of times the POSIX permissions have been modified. This is so that when the system integrates the POSIX permissions of different files, the final permission version of the POSIX structure can be determined based on the version number in the POSIX structure, the number of times the version number has been modified, and the user's permission setting request, ensuring that the user can use it. The target permission information is then flushed to the file system.

2. The file system permission control method according to claim 1, characterized in that, After the step of determining whether a permission setting request sent by the client has been detected, the method further includes: Determine whether the user who sent the permission setting request is a preset user; If it is the preset user, then the step of parsing the permission setting request is performed.

3. The file system permission control method according to claim 2, characterized in that, After the step of determining whether the user who sent the permission setting request is a preset user, the method further includes: If the user is not the preset user, then determine whether the permission setting request is an anti-leeching setting request; If a request is made to set up anti-leeching, then anti-leeching is set up.

4. The file system permission control method according to claim 1, characterized in that, The POSIX structure includes: user information and POSIX permission version information; After the step of creating a POSIX structure based on the newly added permission information, the method further includes: Update the POSIX permission version information.

5. The file system permission control method according to claim 1, characterized in that, The step of creating a POSIX structure based on the newly added permission information includes: Determine whether a historical POSIX structure exists in the file system; If the historical POSIX structure exists, the ACL_USER permission bit is determined based on the newly added permission information and the historical POSIX structure, and the ACL_USER permission bit is filled into the historical POSIX structure. If the historical POSIX structure does not exist, a new POSIX structure is created, and the permission bits corresponding to the newly added permission information are filled into the new POSIX structure.

6. The file system permission control method according to claim 1, characterized in that, The step of flushing the target permission information to the file system includes: Copy the POSIX structure to the file system; The mode permissions of the file system are updated by retrieving the GROUP and OTHER permissions bits from the POSIX structure.

7. A file system permission control device, characterized in that, include: The judgment module is used to determine whether a permission setting request sent by the client has been detected. The parsing module is used to parse the permission setting request upon receiving it in order to obtain the new permission information; The generation module is used to create a POSIX structure based on the newly added permission information to generate target permission information. The POSIX structure is a structure for permission information of various storage protocols. The POSIX structure includes at least S3 protocol permissions and NAS protocol permissions. The POSIX structure stores the identity information of users with access permissions, records the version number of the POSIX permissions, and records the number of times the POSIX permissions have been modified. This is to ensure that when the system integrates the POSIX permissions of different files, the final permission version of the POSIX structure is determined based on the version number in the POSIX structure, the number of times the version number has been modified, and the user's permission setting request, so as to ensure that the user can use it. The flush module is used to flush the target permission information to the file system.

8. A file system permission control device, characterized in that, Includes memory used to store computer programs; A processor, configured to implement the steps of the file system permission control method as described in any one of claims 1 to 6 when executing the computer program.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the file system permission control method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • A method and device for extending access control authority

    CN109446825A

  • ACL user mapping method and system based on network file system

    CN111259426A