Virtual Machine Password Modification Method, Device, Electronic Device and Storage Medium

Through SPDK, the target disk is mapped into nbd that supports kernel operations during the virtual machine encryption process and updated the password block location information, solving the problems of wasted resources and time consumption during virtual machine encryption in the existing technology, and achieving an efficient encryption process.

CN117827369BActive Publication Date: 2025-06-17BEIJING BAIDU NETCOM SCI & TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311705211.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-12
Publication Date
2025-06-17
Estimated Expiration
2043-12-12

AI Technical Summary

Technical Problem

The existing technology requires creating new virtual machines when changing the virtual machine to be dense, resulting in a large waste of resources and time consumption.

Method used

Obtain the virtual machine's password change request through SPDK, map the target disk into an nbd that supports kernel operations in response to the password change request, and query and update the password block location information through the kernel to realize the virtual machine's password change.

Benefits of technology

This method reduces resource consumption, shortens the path to change the density, improves the density efficiency, and saves time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117827369B_ABST
    Figure CN117827369B_ABST
Patent Text Reader

Abstract

The present disclosure provides a method, apparatus, electronic device, and storage medium for changing the password of a virtual machine, which relates to the field of computer technologies, and particularly to technologies such as big data and cloud computing. The specific implementation solution is as follows: obtaining a password change request of a target virtual machine through a high-performance storage development kit SPDK; the password change request includes a target password and a disk identifier corresponding to the target virtual machine; responding to the password change request in SPDK to map the target disk corresponding to the disk identifier to a block device nbd that supports kernel operations; mapping the system files of the target virtual machine to nbd through the kernel; querying the password block position information of the target virtual machine in the system files of nbd through the kernel; and sending the password block position information to SPDK by the kernel so that SPDK updates the password block in the target disk to the target password. In the embodiments of the present disclosure, the password change path is short, which can improve the password change efficiency and also save resources.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of computer technologies, and in particular to technologies such as big data and cloud computing. Background Art

[0002] With the expansion of the scale of public clouds, the number of virtual machines used on the same physical machine is also increasing continuously. As the number of virtual machines on a physical machine increases, for any virtual machine, if the user forgets the password, another virtual machine needs to be created to change the password. Creating a new virtual machine wastes both resources and time. Summary of the Invention

[0003] This disclosure provides a method, an apparatus, an electronic device, and a storage medium for changing the password of a virtual machine.

[0004] According to one aspect of this disclosure, a method for changing the password of a virtual machine is provided, including:

[0005] Obtaining a password change request for a target virtual machine through SPDK (Storage Performance Development Kit); the password change request includes a target password and a disk identifier corresponding to the target virtual machine;

[0006] Responding to the password change request in SPDK to map the target disk corresponding to the disk identifier to an nbd (Network Block Device, a block device) that supports kernel operations;

[0007] Mapping the system file of the target virtual machine to the nbd through the kernel;

[0008] Querying, through the kernel, the password block location information in the system file of the nbd; and,

[0009] Sending the password block location information to SPDK by the kernel so that SPDK updates the password block in the target disk to the target password.

[0010] According to another aspect of this disclosure, a device for changing the password of a virtual machine is provided, including:

[0011] An obtaining module, configured to obtain a password change request for a target virtual machine through SPDK; the password change request includes a target password and a disk identifier corresponding to the target virtual machine;

[0012] A first mapping module, configured to respond to the password change request in SPDK to map the target disk corresponding to the disk identifier to an nbd that supports kernel operations;

[0013] A second mapping module, configured to map the system file of the target virtual machine to the nbd through the kernel;

[0014] A query module, configured to query the password block location information of a target virtual machine in the system file of nbd through the kernel; and,

[0015] A password modification module, configured to send the password block location information to SPDK by the kernel, so that SPDK updates the password block in the target disk to the target password.

[0016] According to another aspect of the present disclosure, there is provided an electronic device, including:

[0017] At least one processor; and

[0018] A memory communicatively connected to the at least one processor; wherein,

[0019] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor, so that the at least one processor can execute the method of any embodiment in the present disclosure.

[0020] According to another aspect of the present disclosure, there is provided a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause the computer to execute the method of any embodiment in the present disclosure.

[0021] According to another aspect of the present disclosure, there is provided a computer program product, including a computer program, and the computer program implements the method of any embodiment in the present disclosure when executed by a processor.

[0022] In the embodiments of the present disclosure, the password modification path is short, which can improve the password modification efficiency and also save resources.

[0023] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] The drawings are used to better understand the solution and do not constitute a limitation to the present disclosure. Among them:

[0025] Figure 1 is a schematic diagram of virtual machine password modification according to an embodiment of the present disclosure;

[0026] Figure 2 is a flowchart of a virtual machine password modification method according to an embodiment of the present disclosure;

[0027] Figure 3 is another schematic diagram of virtual machine password modification according to an embodiment of the present disclosure;

[0028] Figure 4Another schematic diagram of password modification for a virtual machine according to an embodiment of the present disclosure;

[0029] Figure 5 Overall flowchart of the method for modifying the password of a virtual machine according to an embodiment of the present disclosure;

[0030] Figure 6 Another overall flowchart of the method for modifying the password of a virtual machine according to an embodiment of the present disclosure;

[0031] Figure 7 Structural schematic diagram of the device for modifying the password of a virtual machine according to an embodiment of the present disclosure;

[0032] Figure 8 Block diagram of an electronic device for implementing the method for modifying the password of a virtual machine according to an embodiment of the present disclosure. Detailed implementation manners

[0033] The following describes exemplary embodiments of the present disclosure with reference to the accompanying drawings. Various details of the embodiments of the present disclosure are included to assist understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope of the present disclosure. Similarly, for clarity and conciseness, descriptions of well-known functions and structures are omitted in the following.

[0034] In addition, the terms "first" and "second" are used only for descriptive purposes and cannot be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the present disclosure, "a plurality" means two or more unless otherwise specifically defined.

[0035] In the related art, each virtual machine corresponds to a disk, and the disk is used to store the corresponding virtual machine content. As Figure 1 shown, it is a virtual machine password modification solution provided in the related art. In this solution, it is necessary to first create and start a libguestfs (virtual machine image management tool) virtual machine locally, and then communicate with the virtual machine using virsh (management tool) through libguestfs-related services to perform password modification operations. Figure 1 In, the dashed line with arrows describes the mapping relationship between the disk and the virtual machine when the virtual machine is running normally. The solid black line with arrows describes the mapping relationship between the disk and the disk to be password-modified in the libguestfs virtual machine during the password modification operation.

[0036] It can be seen that in the related art, the solution for modifying the password of a virtual machine usually relies on libguestfs. As Figure 1As shown in the figure, it is necessary to first create and start a libguestfs virtual machine, and then perform the password modification operation through the libguestfs-related services. All password modification operations need to be communicated between the physical machine and the libguestfs virtual machine through sockets. The physical machine (HOST) sends the password to be modified to the libguestfs through the socket, and then the libguestfs virtual machine parses the received password modification instruction and then executes the corresponding password modification operation, and then returns the result of the password modification to the HOST through the socket.

[0037] There are the following two problems with modifying the password of the virtual machine based on this method:

[0038] 1. It consumes a large amount of resources. Each time a password modification operation is initiated, a libguestfs virtual machine needs to be started. Since the libguestfs virtual machine is a complete virtual machine, it will occupy more CPU and memory resources.

[0039] 2. Since it is necessary to start the virtual machine and then operate on the corresponding disk, it will consume additional time and cause the password modification time to be too long.

[0040] In view of this, in the embodiments of the present disclosure, a method for modifying the password of a virtual machine is proposed by means of SPDK. SPDK is an open-source Linux-based storage performance development toolkit that provides some tools and libraries for improving the performance of storage systems. In the embodiments of the present disclosure, the target virtual machine and the chip (such as DPU (Data Processing Unit)) that need to modify the password are on the same physical machine, and this method is implemented by this physical machine, specifically, it can be implemented by the chip of this physical machine. The chip protects the kernel and SPDK. As Figure 2 shown, it can be implemented as:

[0041] S201, obtain a password modification request for the target virtual machine through SPDK; the password modification request includes the target password and the disk identifier corresponding to the target virtual machine.

[0042] For example, if a user needs to modify the password of the target virtual machine A, and the disk identifier corresponding to the target virtual machine is disk 1. Then the password modification request for the target virtual machine A includes the target password (i.e., the desired password) and disk 1.

[0043] S202, respond to the password modification request in SPDK to map the target disk corresponding to the disk identifier to an nbd that supports kernel operations.

[0044] In the embodiments of the present disclosure, when the device for executing the virtual machine password modification method of the embodiments of the present disclosure is started, a preset number of nbds can be created in advance for the kernel for subsequent password modification operations on the virtual machine. The number of created nbds can be set according to requirements. For the same physical machine, when there are multiple virtual machines, multiple nbds are created, but it is not required to be greater than the number of virtual machines. So that concurrent password modification of multiple virtual machines on the physical machine can be achieved through multiple nbds. Among them, the password modification process for each virtual machine is the same. In the embodiments of the present disclosure, a single virtual machine will be taken as an example for illustration later.

[0045] S203, map the system file of the target virtual machine to the nbd through the kernel.

[0046] S204, query the password block location information of the target virtual machine in the system file of the nbd through the kernel.

[0047] S205, the kernel sends the password block location information to the SPDK so that the SPDK updates the password block in the target disk to the target password.

[0048] Among them, the password block location information includes the address and length of the original password of the target virtual machine on its corresponding target disk, so as to facilitate updating the original password with the target password.

[0049] In the embodiments of the present disclosure, password modification of the virtual machine is implemented based on the SPDK architecture. Implementing password modification of the virtual machine inside the SPDK architecture does not require creating a complete other virtual machine, so physical machine resources can be saved and the consumption of physical machine resources can be reduced. At the same time, the overall data path proposed in the embodiments of the present disclosure is shorter, which can save time and improve the overall efficiency.

[0050] In the embodiments of the present disclosure, password modification is implemented based on the physical machine rather than a newly created virtual machine. Among them, the target disk corresponding to the target virtual machine that needs password modification can be a local disk or a cloud disk. In view of the two forms of the target disk, the password modification method proposed in the embodiments of the present disclosure will be described in detail:

[0051] 1) The target disk is a local disk

[0052] In some embodiments, when the target disk is a local disk, in response to a password modification request in the SPDK, mapping the target disk corresponding to the disk identifier to an nbd that supports kernel operations can be implemented as:

[0053] Execute the following operations through the SPDK:

[0054] Step A1, create the target disk as the first bdev device of the bdev in the block device layer of the SPDK.

[0055] Step A2, export the device identifier of the first bdev device in the block device layer.

[0056] Step A3, in the first block device driver within SPDK, based on the device identifier of the first bdev device, associate the first bdev device with the nbd managed by the kernel.

[0057] During implementation, as Figure 3 shown, during implementation, the kernel may first receive the password change request and then send the password change request to SPDK.

[0058] In the case where SPDK on the DPU receives the password change request of virtual machine A, SPDK creates virtual machine A as the first bdev device of the bdev in the block device layer of SPDK. The device identifier of this first bdev device is the first bdev device 1. Based on the first block device driver (NBD driver), associate the first bdev device 1 with the nbd device 1 managed by the kernel. This association operation is used to generate a sub-device in the nbd device 1. For example, a device / dev / nbd0p1 is generated based on the nbd device / dev / nbd0. Thus, the password change operation is subsequently performed through the nbd device 1.

[0059] In the embodiments of the present disclosure, using SPDK to create the target disk as the first bdev device of the bdev in the block device layer of SPDK and exporting the device identifier of the first bdev device in the block device layer to associate the first bdev device with the nbd device managed by the kernel can save time costs and lay a foundation for subsequent password change operations on the virtual machine in the nbd device.

[0060] In some embodiments, after the first bdev device is associated with the nbd device, map the file system of the target disk to the nbd device through file system mapping so that read and write operations can be performed on the nbd device. Querying the password block location information of the target virtual machine in the system file of the nbd through the kernel can be implemented as:

[0061] Step B1, through the kernel, identify the root partition of the target disk in the specified directory of the system file.

[0062] Among them, the specified directory is the directory corresponding to the target virtual machine. For example, the specified directory can be / mnt / vm-id / , the mnt directory is used for users to temporarily mount file systems, such as optical drives, etc., and vm-id is the number of the target virtual machine, which is generated when the target virtual machine is created.

[0063] In some embodiments, the password block location information is stored in the root partition of the target disk to facilitate password modification of the target disk. Based on the characteristics of the root partition, identifying the root partition of the target disk can be implemented as follows:

[0064] Step B11, based on the kernel, find the target directory containing the configuration file in the specified directory;

[0065] Step B12, when the target directory is found in the internal check and the following conditions are met, it is determined that the root partition is found:

[0066] Condition 1, there is a bin folder (i.e., the folder storing the basic command directory), or when bin is processed using readlink (a computer function to obtain the current path), the output is the running script directory;

[0067] Condition 2, there is file system information and / or there is a file that maps the host name to the IP address.

[0068] In implementation, in some simple scenarios, the default partition can be determined as the root partition. For example, the first partition can be determined as the root partition. In complex scenarios, there are multiple partitions, and it is possible that the first partition is not the root partition. For example, in a system based on EFI (Extensible Firmware Interface) boot, the nbd device in this system has multiple partitions. In view of this, in order to improve the accuracy of root partition identification, all partitions under the nbd device can be traversed. For example, partition 1 can be expressed as / dev / nbd0p1, partition 2 can be expressed as / dev / nbd0p2, and partition n can be expressed as / dev / nbd0pn. The content of each of these partitions is identified, and based on the satisfaction of Condition 1 and Condition 2, this partition is determined as the root partition. In the case where either Condition 1 or Condition 2 is not satisfied, it is determined that this partition is not the root partition.

[0069] In the embodiments of the present disclosure, the root partition is determined based on the content stored in the root partition. By identifying the root partition, the password block location information can be accurately and quickly located, providing data support for completing the password modification operation.

[0070] Step B2, mount the root partition to the specified directory through the kernel.

[0071] Step B3, obtain the password block location information of the target virtual machine in the specified directory through the kernel.

[0072] Among them, the password block location information includes the address and the length. Among them, the address represents the starting position of the password block, and the length represents the data volume of the password block. Based on the address and the length, the password block can be read and written.

[0073] In the embodiments of the present disclosure, since the password data is stored in the root partition, the root partition storing the password data is identified to obtain the password block location information of the target virtual machine, which is convenient for password modification in the later stage.

[0074] In some embodiments, based on obtaining the password block location information of the target virtual machine, the kernel updates the password block in the target disk to the target password through SPDK, which can be implemented as follows:

[0075] Step C1, the second block device driver of the kernel notifies SPDK to initiate a read request for the target disk. The read request includes the password block location information.

[0076] Step C2, based on the response of SPDK, the password data to be verified returned by the target disk for the read request is obtained.

[0077] The password data to be verified is the password before update.

[0078] Step C3, the kernel performs a verification operation on the password data to be verified.

[0079] Step C4, when the kernel determines that the password data to be verified passes the verification, the second block device driver of the kernel notifies SPDK to send a write request to the target disk; so that the target disk executes the write request; the write request includes the target password and the password block location information, so that the target disk executes the write request and finally updates the password to the target password.

[0080] Specifically, the second block device driver of the kernel notifies the first block device driver of SPDK to initiate a read request for the target disk; the read request includes the password block location information; the first block device driver of SPDK sends the read request to the second bdev device; the second bdev device encapsulates the read request into a format recognizable by the local disk and sends it to the local disk; SPDK receives the password data to be verified returned by the local disk; the kernel performs a verification operation on the password data to be verified; when the kernel determines that the password data to be verified passes the verification, based on the second block device driver, it notifies the first block device driver of SPDK to initiate a write request for the target disk; the write request includes the password block location information and the target password, so as to update the password in the target disk through the write request.

[0081] In the embodiments of the present disclosure, the password block of the target disk is determined to be normally updatable through the read request and the verification operation, and then the write request is initiated, so as to improve the efficiency of password update.

[0082] In some embodiments, after the password change is successful, the mapping relationship with the target disk can also be released in the nbd.

[0083] During implementation, the mapping relationship between the block device nbd and the first bdev device is removed, and the first bdev device is destroyed in SPDK.

[0084] In the embodiments of the present disclosure, after the password change operation is completed, the mapping relationship with the target disk is removed in nbd, realizing the release of the access right to the target disk, so that the user can access the target disk through the target virtual machine.

[0085] In some embodiments, the password change request is sent by the physical machine where the target virtual machine is located through a specified browser control page.

[0086] Among them, the password change request can be sent by the physical machine where the target virtual machine is located through a specified browser control page. For example, when the virtual machine user forgets the password, the browser can be started, the corresponding virtual machine password change page can be accessed, and then operations can be performed on this page to send a password change request.

[0087] In the embodiments of the present disclosure, through the password change request of the specified browser control page, the password change operation can be realized when the user forgets the password.

[0088] 2) The target disk is a cloud disk

[0089] In some embodiments, in order to be able to communicate with the target virtual machine, a console client can be added to the DPU in the embodiments of the present disclosure. Of course, in the case where the target is a local disk, this console client can also be used to receive the password change request of the target virtual machine. In the case where the target disk is a cloud disk, obtaining the password change request of the target virtual machine through SPDK can be implemented as: receiving the password change request sent by the console client, and the password change request is sent by the physical machine where the target virtual machine is located to the console client.

[0090] Among them, the password change request can be sent by the physical machine where the target virtual machine is located through a specified browser control page to the console client.

[0091] In the embodiments of the present disclosure, the transmission of the password change request of the virtual machine based on the console client provides a data transmission path for the password change operation.

[0092] Such as Figure 4 As shown, during implementation, the console client can first receive the password change request, and then send the device connection request and the device creation request to SPDK.

[0093] In some embodiments, in order to communicate with the target disk at the remote end, the client of the target virtual machine can be integrated into SPDK. The client of the target virtual machine includes a cloud disk service connection module and a virtio blk (semi-virtualized disk) device emulation module. These two modules need to be split out, and the cloud disk service connection module is integrated into SPDK to facilitate communication with the cloud disk. In addition, the virtio blk module needs to be rewritten as a cloud disk bdev module suitable for SPDK. The rewritten cloud disk bdev module is implemented based on the spdk bdev framework, and then docked to the SPDK bdev device of SPDK using the original framework of SPDK to provide cloud disk services.

[0094] When the target virtual machine can be used normally, the cloud disk connection service module (i.e., the module for reading and writing data with the server side) can be registered as an SPDK poller using the polling model of SPDK. There are multiple pollers in SPDK, including the first block device driver (nbd poller). The poller for the cloud disk and the nbd poller will run on each CPU, and these two tasks will be executed alternately. The nbd poller will batch-convert the requests of the virtual machine into the request types required by the cloud disk. Then, when the cloud disk client executes the requests, the requests processed by the nbd poller will be batch-converted into the requests required by the cloud disk server side and sent to the server side. In the whole processing process, compared with an independent virtual machine client, the hardware resources of SPDK are reused, the resources are not wasted, no additional resources are required, and there is no need to notify the chip to execute the requests of the cloud disk through interrupts or other means.

[0095] As described above, when the target disk is a cloud disk, a cloud disk client for the remote cloud disk is integrated in SPDK. The cloud disk client includes the original cloud disk service connection module and the rewritten virtual disk device module. The virtual disk device module is responsible for encapsulating the requests into a format that the cloud disk service connection module can recognize, and the virtual disk device module is responsible for encapsulating the requests into a format that the remote cloud disk can recognize and process, and is responsible for establishing a connection and communicating with the remote cloud disk.

[0096] During the process of changing the password, only the cloud disk client can be used to establish communication with the cloud disk. And in the case of creating the second bdev device, the subsequent password-changing operation is completed.

[0097] In SPDK, in response to the password-changing request, mapping the target disk corresponding to the disk identifier to an nbd that supports kernel operations can be implemented as:

[0098] Step D1, the cloud disk client of SPDK responds to the password-changing request sent by the console client to establish a connection with the cloud disk.

[0099] Step D2: After the cloud disk client of SPDK successfully establishes a connection with the cloud disk, it notifies the console client through SPDK, so that the console client notifies the kernel to initiate a second bdev device creation request.

[0100] Step D3: The first block device driver of SPDK responds to the second bdev device creation request to create the target disk as the second bdev device in the block device layer of SPDK.

[0101] As Figure 4 shown, when the console client receives the password change request, it establishes a connection with the cloud disk, and the client sends a request to the cloud disk client to create a second bdev device.

[0102] Step D4: The first block device driver of SPDK exports the device identifier of the second bdev device.

[0103] Step D5: Based on the device identifier of the second bdev device in the first block device driver of SPDK, the second bdev device is associated with the nbd managed by the kernel.

[0104] During implementation, as Figure 4 shown, when the console client receives the password change instruction for the target virtual machine A, it establishes a connection with the cloud disk, and the client sends a request to the cloud disk client to create a second bdev device. The device identifier exported by the first block device driver of SPDK for the second bdev device is the second bdev device 1, and the first block device driver of SPDK associates the second bdev device 1 with the nbd device 1 managed by the kernel. This association operation is used to generate a sub-device in the nbd device 1. For example, a device of / dev / nbd0p1 is generated based on the nbd device / dev / nbd0. Thus, the password change operation is subsequently performed through the nbd device 1.

[0105] In the embodiments of the present disclosure, using SPDK to create the target disk as the second bdev device in the block device layer bdev of SPDK and exporting the device identifier of the second bdev device in the block device layer to associate the second bdev device with the nbd device managed by the kernel can save time costs and lay a foundation for subsequent password change operations on the virtual machine in the nbd device.

[0106] In some embodiments, after the second bdev device is associated with the nbd device, the file system of the target disk is mapped to the nbd device through file system mapping to facilitate read and write operations on the nbd device. The password block location information of the target virtual machine can be obtained based on the foregoing steps B1 - B3.

[0107] On the basis of obtaining the password block location information of the target virtual machine, the kernel updates the password block in the target disk to the target password through the SPDK, which can be implemented as follows:

[0108] Step E1, the second block device driver of the kernel notifies the first block device driver of the SPDK to initiate a read request for the target disk; the read request includes the password block location information.

[0109] Step E2, the first block device driver of the SPDK sends the read request to the second bdev device.

[0110] Step E3, the second bdev device encapsulates the read request into a format recognizable by the cloud disk and sends it to the cloud disk through the integrated cloud disk client.

[0111] During implementation, when the nbd poller detects a password change request issued in the target virtual machine during execution, it will actively obtain the password change request from the socket of the virtual machine, convert the password change request into a bdev request, and each request corresponds to one or more iovs. An iov contains the address and length of a data block, and then this iov is sent to the cloud disk client to wait to be processed. Among them, a password change request corresponds to multiple iovs, indicating that a password change request has multiple data blocks and the data blocks are not continuous. Each iov represents a block of data, and the address and length of this data block are the elements of the iov.

[0112] The cloud disk client detects an iov that has been processed by the nbd poller, and then converts this iov into an iobuf format and sends it to the cloud disk client to wait to be encapsulated into a format recognizable by the cloud disk server. The specific conversion method can be to apply for a new iobuf and then pass the address and length in the iov to the iobuf.

[0113] The cloud disk client needs to detect the type of the current request and make corresponding processing according to different types. If it is a write request, all the data in the iov needs to be converted into the iobuf through zero-copy; if it is a read request, memory needs to be prepared for reading the data block content when the read request is completed.

[0114] Step E4, the cloud disk client of the SPDK receives the password data to be verified returned by the cloud disk.

[0115] Step E5, the kernel performs a verification operation on the password data to be verified.

[0116] Step E6. When the kernel determines that the password data to be verified passes the verification, the second block device driver of the kernel notifies the first block device driver of SPDK to initiate a write request for the target disk, so that the target disk executes the write request. The write request includes password block position information.

[0117] In some embodiments, after the password modification operation is completed, the mapping relationship with the target disk is released in NBD.

[0118] During implementation, the mapping relationship between the NBD device and the second bdev device is released, and the second bdev device is destroyed in SPDK.

[0119] In the embodiments of the present disclosure, after the password modification operation is completed, the mapping relationship with the target disk is released in NBD to release the access permission to the target disk, so that the user can access the target disk through the target virtual machine.

[0120] Among them, the password modification request can be sent by the physical machine where the target virtual machine is located through a specified browser control page. For example, when the virtual machine user forgets the password, the browser can be started, the corresponding virtual machine password modification page can be accessed, and then operations can be performed on this page to send a password modification request.

[0121] In the embodiments of the present disclosure, through the password modification request of the specified browser control page, the password modification operation can be realized when the user forgets the password.

[0122] In the virtual machine password modification method proposed in the embodiments of the present disclosure, taking the target disk as a local disk as an example, the overall flowchart of the method is as Figure 5 shown, including:

[0123] S501. Create a preset number of NBD devices.

[0124] S502. In response to the password modification request of the target virtual machine, create the target disk as the first bdev device of the block device layer bdev of SPDK.

[0125] S503. SPDK associates the first bdev device with the NBD device managed by the kernel based on the device identifier of the first bdev device through the first block device driver.

[0126] S504. After the kernel maps the file system of the target disk to the NBD device, identify the root partition of the target disk in the specified directory of the mapped system file.

[0127] S505. Mount the root partition to the specified directory.

[0128] S506. Update the password block in the target disk to the target password through SPDK.

[0129] S507, determining whether the password change is successful. If it is determined that the password change has failed, retry three times based on the target password and execute S508; if the three retries fail, it is determined that the password change has failed.

[0130] S508, release the mapping relationship between the nbd device and the first bdev device, and destroy the first bdev device in SPDK.

[0131] A virtual machine encryption method is proposed in the embodiment of the present disclosure. Taking the target disk as a cloud disk as an example, the overall flow chart of the method is as follows: Figure 6 As shown, including:

[0132] S601, creating a preset number of nbd devices.

[0133] S602, the cloud disk client through SPDK responds to the encryption request sent by the console client to establish a connection with the cloud disk.

[0134] S603, after the cloud disk client of SPDK successfully establishes a connection with the cloud disk, the console client is notified through SPDK, so that the console client notifies the kernel to initiate a second bdev device creation request.

[0135] S604: Respond to the second bdev device creation request through the first block device driver of SPDK to create the target disk as a second bdev device of the block device layer of SPDK.

[0136] S605, SPDK associates the second bdev device with the nbd device managed by the kernel based on the device identifier of the second bdev device driven by the first block device.

[0137] S606, after mapping the file system of the target disk to the nbd device, the kernel identifies the root partition of the target disk in the designated directory of the mapped system file.

[0138] S607, mount the root partition to the specified directory.

[0139] S608: Update the password block in the target disk to the target password through SPDK.

[0140] S609, determining whether the password change is successful. If it is determined that the password change has failed, retry three times based on the target password and execute S610; if the three retries fail, it is determined that the password change has failed.

[0141] S610: Release the mapping relationship between the nbd device and the second bdev device, and destroy the second bdev device in the SPDK.

[0142] Based on the same technical concept, in an embodiment of the present disclosure, a virtual machine password modification device 700 is proposed, as Figure 7 shown, including:

[0143] An acquisition module 701, configured to obtain a password modification request of a target virtual machine through a high-performance storage development kit SPDK; the password modification request includes a target password and a disk identifier corresponding to the target virtual machine;

[0144] A first mapping module 702, configured to respond to the password modification request in SPDK to map the target disk corresponding to the disk identifier to a block device nbd that supports kernel operations;

[0145] A second mapping module 703, configured to map the system files of the target virtual machine into nbd through the kernel;

[0146] A query module 704, configured to query the password block position information of the target virtual machine in the system files of nbd through the kernel; and,

[0147] A password modification module 705, configured to send the password block position information to SPDK by the kernel, so that SPDK updates the password block in the target disk to the target password.

[0148] In some embodiments, when the target disk is a local disk, the first mapping module is configured to:

[0149] Perform the following operations through SPDK:

[0150] Create the target disk as a first bdev device of the block device layer bdev of SPDK;

[0151] Export the device identifier of the first bdev device of the block device layer;

[0152] Associate the first bdev device to the nbd managed by the kernel based on the device identifier of the first bdev device in the first block device driver within SPDK.

[0153] In some embodiments, when the target disk is a cloud disk, the acquisition module is configured to:

[0154] Receive the password modification request sent by the console client, and the password modification request is sent by the physical machine where the target virtual machine is located to the console client.

[0155] In some embodiments, when the target disk is a cloud disk, a cloud disk client of a remote cloud disk is integrated in SPDK; the first mapping module is configured to:

[0156] Respond to the password modification request sent by the console client through the cloud disk client of SPDK to establish a connection with the cloud disk;

[0157] After the cloud disk client of SPDK successfully establishes a connection with the cloud disk, it notifies the console client through SPDK, so that the console client notifies the kernel to initiate a second bdev device creation request;

[0158] The first device driver of SPDK responds to the second bdev device creation request to create the target disk as the second bdev device in the block device layer of SPDK;

[0159] The first device driver of SPDK exports the device identifier of the second bdev device;

[0160] In the first device driver of SPDK, based on the device identifier of the second bdev device, the second bdev device is associated with the nbd managed by the kernel.

[0161] In some embodiments, the query module includes:

[0162] An identification unit for identifying the root partition of the target disk by the kernel in the specified directory of the system file;

[0163] A mounting unit for mounting the root partition to the specified directory by the kernel;

[0164] An acquisition unit for acquiring the password block location information of the target virtual machine by the kernel in the specified directory.

[0165] In some embodiments, the identification unit is used for:

[0166] Based on the kernel, find the target directory containing the configuration file in the specified directory;

[0167] When the target directory is found in the kernel check and the following conditions are met, it is determined that the root partition is found:

[0168] Condition 1: There is a bin folder for storing basic command directories, or the output of processing bin using the computer function readlink is the running script directory;

[0169] Condition 2: There is file system information and / or there is a file mapping the hostname to the IP address.

[0170] In some embodiments, the password modification module is used for:

[0171] Based on the second device driver of the kernel, notify SPDK to initiate a read request for the target disk; the read request includes the password block location information;

[0172] Based on the password data to be verified returned by SPDK in response to the read request for the target disk;

[0173] Based on the kernel, perform a verification operation on the password data to be verified;

[0174] When the kernel determines that the password data to be verified has been verified, the second block device driver based on the kernel notifies SPDK to send a write request to the target disk, so that the target disk executes the write request; the write request includes the target password and the password block location information.

[0175] In some embodiments, a release module is further included, which is used to:

[0176] Release the mapping relationship with the target disk in nbd.

[0177] In some embodiments, the password change request is sent by the physical machine where the target virtual machine is located through a designated browser control page.

[0178] Of course, in the technical solution of the present disclosure, the acquisition, storage and application of user personal information involved are in compliance with the provisions of relevant laws and regulations and do not violate public order and good morals.

[0179] For the description of specific functions and examples of each module, sub-module\unit of the device in the embodiment of the present disclosure, please refer to the relevant description of the corresponding steps in the above method embodiment, which will not be repeated here.

[0180] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium and a computer program product.

[0181] Figure 8 A schematic block diagram of an example electronic device 800 that can be used to implement an embodiment of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or required herein.

[0182] like Figure 8 As shown, the device 800 includes a computing unit 801, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 802 or a computer program loaded from a storage unit 808 into a random access memory (RAM) 803. In the RAM 803, various programs and data required for the operation of the device 800 can also be stored. The computing unit 801, the ROM 802, and the RAM 803 are connected to each other via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.

[0183] Multiple components in device 800 are connected to I / O interface 805, including: input unit 806, such as a keyboard, mouse, etc.; output unit 807, such as various types of displays, speakers, etc.; storage unit 808, such as a disk, optical disc, etc.; and communication unit 809, such as a network card, modem, wireless communication transceiver, etc. Communication unit 809 allows device 800 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0184] Computing unit 801 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of computing unit 801 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Computing unit 801 executes the various methods and processes described above, such as the virtual machine password change method. For example, in some embodiments, the virtual machine password change method can be implemented as a computer software program that is tangibly contained in a machine-readable medium, such as storage unit 808. In some embodiments, part or all of the computer program can be loaded and / or installed onto device 800 via ROM 802 and / or communication unit 809. When the computer program is loaded into RAM 803 and executed by computing unit 801, one or more steps of the virtual machine password change method described above can be executed. Alternatively, in other embodiments, computing unit 801 can be configured to execute the virtual machine password change method by any other suitable means (e.g., by means of firmware).

[0185] The various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGA), application-specific integrated circuits (ASIC), application-specific standard products (ASSP), system-on-a-chip systems (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor, and can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0186] The program code for implementing the methods of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor or controller, the program codes cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The program codes can be executed entirely on the machine, partially on the machine, executed partially on the machine as an independent software package and partially on a remote machine, or executed entirely on a remote machine or server.

[0187] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0188] In order to provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) through which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).

[0189] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), and the Internet.

[0190] A computer system can include a client and a server. The client and the server are generally far from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, a server of a distributed system, or a server incorporating blockchain.

[0191] It should be understood that various forms of the processes shown above can be used, steps can be reordered, added, or deleted. For example, the steps recited in this disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and this is not limited herein.

[0192] The above specific embodiments do not constitute a limitation on the protection scope of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the principles of this disclosure shall be included within the protection scope of this disclosure.

Claims

1. A method for changing the password of a virtual machine, comprising: Obtain the password change request of the target virtual machine through the high-performance storage development kit SPDK; the password change request includes the target password and the disk identifier corresponding to the target virtual machine; In the SPDK, respond to the password change request to map the target disk corresponding to the disk identifier to a block device nbd that supports kernel operations; Map the system files of the target virtual machine to the nbd through the kernel; Query the password block location information of the target virtual machine in the system files of the nbd through the kernel; and, The kernel sends the password block location information to the SPDK, so that the SPDK updates the password block in the target disk to the target password, including: notifying the SPDK to send a write request to the target disk based on the second block device driver of the kernel, so that the target disk executes the write request; The write request includes the target password and the password block location information.

2. The method according to claim 1, wherein, When the target disk is a local disk, in the SPDK, respond to the password change request to map the target disk corresponding to the disk identifier to an nbd that supports kernel operations, including: Execute the following operations through the SPDK: Create the target disk as the first bdev device of the block device layer bdev of the SPDK; Export the device identifier of the first bdev device of the block device layer; Based on the device identifier of the first bdev device in the first block device driver in the SPDK, associate the first bdev device with the nbd managed by the kernel.

3. The method according to claim 1, wherein, When the target disk is a cloud disk, obtaining the password change request of the target virtual machine through the SPDK includes: Receive the password change request sent by the console client, and the password change request is sent by the physical machine where the target virtual machine is located to the console client.

4. The method according to claim 1 or 3, wherein, When the target disk is a cloud disk, a cloud disk client of the remote cloud disk is integrated in the SPDK; in the SPDK, respond to the password change request to map the target disk corresponding to the disk identifier to an nbd that supports kernel operations, including: The cloud disk client of the SPDK responds to the password change request sent by the console client to establish a connection with the cloud disk; After the cloud disk client of the SPDK successfully establishes a connection with the cloud disk, notify the console client through the SPDK, so that the console client notifies the kernel to initiate a second bdev device creation request; Respond to the second bdev device creation request through the first block device driver of the SPDK to create the target disk as the second bdev device of the block device layer of the SPDK; Export the device identifier of the second bdev device through the first block device driver of the SPDK; Based on the device identifier of the second bdev device in the first block device driver of the SPDK, associate the second bdev device with the nbd managed by the kernel.

5. The method according to claim 1, wherein, Querying, by the kernel, the password block location information of the target virtual machine in the system file of the NBD includes: Identifying, by the kernel, the root partition of the target disk in the specified directory of the system file; Mounting, by the kernel, the root partition to the specified directory; Obtaining, by the kernel, the password block location information of the target virtual machine in the specified directory; 6. The method according to claim 5, wherein, Identifying, by the kernel, the root partition of the target disk in the specified directory of the system file of the NBD device includes: Searching, based on the kernel, for a target directory containing a configuration file in the specified directory; Determining that the root partition is found when the target directory is found in the kernel and the following conditions are met: Condition 1: There is a bin folder storing basic command directories, or the output of processing the bin using the computer function readlink is the running script directory; Condition 2: There is file system information and / or there is a file mapping the host name to the IP address.

7. The method according to claim 1, further comprising: Notifying, based on the second block device driver of the kernel, the SPDK to initiate a read request for the target disk; The read request includes the password block location information; Responding, based on the SPDK, to the password data to be verified returned by the target disk for the read request; Performing, based on the kernel, a verification operation on the password data to be verified; When the kernel determines that the password data to be verified passes the verification, executing, based on the second block device driver of the kernel, notifying the SPDK to send a write request to the target disk so that the target disk executes the write request; the write request includes the target password and the password block location information.

8. The method according to any one of claims 1 further comprises: Unmapping the target disk in the NBD.

9. The method according to claim 1 or 2, wherein The password change request is sent by the physical machine where the target virtual machine is located through a specified browser control page.

10. A virtual machine password modification device, comprising: An acquisition module for acquiring, through the Storage Performance Development Kit (SPDK), a password change request of a target virtual machine; the password change request includes a target password and a disk identifier corresponding to the target virtual machine; A first mapping module for responding to the password change request in the SPDK to map the target disk corresponding to the disk identifier to a block device NBD supporting kernel operations; A second mapping module for mapping, through the kernel, the system file of the target virtual machine to the NBD; A query module for querying, by the kernel, the password block location information of the target virtual machine in the system file of the NBD; And, A password change module for sending, by the kernel, the password block location information to the SPDK so that the SPDK updates the password block in the target disk to the target password, including: notifying, based on the second block device driver of the kernel, the SPDK to send a write request to the target disk so that the target disk executes the write request; The write request includes the target password and the password block location information.

11. The device according to claim 10, wherein When the target disk is a local disk, the first mapping module is used for: Performing the following operations through the SPDK: Create the target disk as the first bdev device of the block device layer bdev of the SPDK; Export the device identifier of the first bdev device of the block device layer; Based on the device identifier of the first bdev device in the first block device driver within the SPDK, associate the first bdev device with the nbd managed by the kernel; 12. The device according to claim 10, wherein When the target disk is a cloud disk, the acquisition module is used for: Receive the password change request sent by the console client, where the password change request is sent by the physical machine where the target virtual machine is located to the console client; 13. The device according to claim 10 or 12, wherein When the target disk is a cloud disk, a cloud disk client for a remote cloud disk is integrated in the SPDK; the first mapping module is used for: Respond to the password change request sent by the console client through the cloud disk client of the SPDK to establish a connection with the cloud disk; After the cloud disk client of the SPDK successfully establishes a connection with the cloud disk, notify the console client through the SPDK so that the console client notifies the kernel to initiate a second bdev device creation request; Respond to the second bdev device creation request through the first block device driver of the SPDK to create the target disk as the second bdev device of the block device layer of the SPDK; Export the device identifier of the second bdev device through the first block device driver of the SPDK; Based on the device identifier of the second bdev device in the first block device driver of the SPDK, associate the second bdev device with the nbd managed by the kernel; 14. The device according to claim 10, wherein The query module includes: An identification unit for identifying the root partition of the target disk by the kernel in the specified directory of the system file; A mounting unit for mounting the root partition to the specified directory by the kernel; An acquisition unit for acquiring the password block location information of the target virtual machine by the kernel in the specified directory; 15. The device according to claim 14, wherein The identification unit is used for: Search for the target directory containing the configuration file in the specified directory based on the kernel; When the target directory is found by the kernel and the following conditions are met, it is determined that the root partition is found: Condition 1: There exists a bin folder for storing basic command directories, or the output of processing the bin using the computer function readlink is the running script directory; Condition 2: There exists file system information and / or there exists a file mapping the hostname to the IP address; 16. The device according to claim 10, wherein The password change module is used for: Notify the SPDK to initiate a read request for the target disk based on the second block device driver of the kernel; the read request includes the password block location information; Based on the SPDK's response to the password data to be verified returned by the target disk for the read request; Perform a verification operation on the password data to be verified based on the kernel; When the kernel determines that the password data to be verified passes the verification, execute the second block device driver based on the kernel to notify the SPDK to send a write request to the target disk, so that the target disk executes the write request; the write request includes the target password and the password block position information.

17. The apparatus according to any one of claims 10 further comprises a release module for: Releasing the mapping relationship with the target disk in the nbd.

18. The apparatus according to claim 10 or 11, wherein, The password change request is sent by the physical machine where the target virtual machine is located through a specified browser control page.

19. An electronic device, comprising: At least one processor; And A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method according to any one of claims 1-9.

20. A non-transitory computer-readable storage medium storing computer instructions, wherein, The computer instructions are used to cause the computer to execute the method according to any one of claims 1-9.

21. A computer program product comprising a computer program which, when executed by a processor, implements the method according to any one of claims 1-9.

Citation Information

Patent Citations

  • Network block device storage system and method for virtual machine

    CN104636077A

  • Virtual machine VNC password control method and device, equipment and storage medium

    CN116737316A