Root file system construction method and device, equipment and storage medium
By dynamically maintaining the tracking task chain and target data structures, obtaining and updating the file absolute paths of all child processes, the problem of being unable to accurately build a lightweight root file system in the existing technology is solved, and efficient and accurate root file system construction is achieved.
Patent Information
- Application Number
- CN202510444642.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2025-05-09
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The prior art cannot comprehensively and accurately track the absolute path of files, resulting in the inability to accurately and efficiently build a lightweight root file system.
By creating the initial child process and target data structure, starting the tracking task chain, dynamically maintaining the tracking task chain and target data structure, obtaining and updating the file absolute paths of all child processes until the target data structure is empty, the root file system is built.
A comprehensive, accurate and efficient root file system construction is achieved, ensuring that the generated root file system only contains the actual complete file absolute path, is smaller in size, and improves the flexibility and adaptability of the system.
Smart Images

Figure CN119961218A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of operating systems, and in particular to a root file system construction method, device, equipment and storage medium. Background Art
[0002] In operating system deployment and modern containerization technology, generating an independent root file system (Root Filesystem, RootFS) is a key step. The root file system is the file system mounted when the operating system starts. It contains all the basic components required for the operating system to run, such as user space tools, library files, configuration files, etc.
[0003] With the popularization of containerization technology, the demand for lightweight root file systems has become more urgent. Containers create lightweight virtualization environments through isolation mechanisms, and each container relies on a dedicated root file system. In order to improve the startup efficiency of containers and reduce resource consumption, container images often only retain the minimum set of files required to run specific applications. This requires that the constructed root file system accurately matches the application requirements, with no redundancy and no missing key files.
[0004] However, the file tracking methods currently used in the process of building the root file system have great limitations. The existing file tracking methods only filter and track a specified single PID (Process Identification Number). This method limits the absolute file path obtained to a specific process, and the root file system can only be built based on the absolute file path of this process. Taking the daily WeChat startup scenario as an example, when WeChat is started, the WeChat detection and update service will be automatically started. In this case, it is difficult for the existing technology to fully obtain the system libraries accessed by WeChat and its related subprocesses during operation, as well as the various files read and saved. Therefore, due to the inability to fully and accurately track the absolute file path, it is impossible to accurately and efficiently build a lightweight root file system. Summary of the invention
[0005] In view of this, the present invention provides a root file system construction method, device, equipment and storage medium to solve the problem that the prior art cannot fully and accurately track the absolute path of the file, resulting in the inability to accurately and efficiently build a lightweight root file system.
[0006] In a first aspect, the present invention provides a method for constructing a root file system, the method comprising: Create the initial child process, trace the task chain and target data structures; Start the tracing task chain with the initial subprocess as the starting point, and update the target data structure based on the initial subprocess; In response to each subprocess in the tracing task chain creating a new subprocess, obtaining the absolute file path of the new subprocess, and updating the tracing task chain and target data structure; In response to each child process exiting, updating the target data structure; When the target data structure is empty, the root file system is constructed based on the absolute file paths of all child processes in the tracking task chain.
[0007] The root file system construction method provided by the embodiment of the present invention performs initialization preparation by creating an initial child process and a target data structure, starts a tracking task chain through the initial child process, and updates the target data structure, and uses the tracking task chain to track all child processes directly or indirectly created by the initial child process. Whenever any child process in the tracking task chain creates a new child process, the file absolute path of the new child process is obtained, and the tracking task chain and the target data structure are updated at the same time, so as to realize dynamic maintenance of the tracking task chain and the target data structure, ensure that all related file operations are tracked, and update the target data structure when the child process exits, so as to ensure that the target data structure always reflects the current process status, thereby improving the accuracy and reliability of tracking. When the target data structure is empty, it means that the process tracking has been completed, and at this time, all file absolute paths are summarized to build the root file system, so as to ensure that the generated root file system only contains the complete file absolute paths actually used, and has a smaller size, thereby realizing comprehensive, accurate and efficient root file system construction.
[0008] In an optional implementation, after creating the initial subprocess, the method further includes: Make the main process prepare kernel-mode services; Start the kernel mode service, open the first tracking point, the second tracking point and the third tracking point, the first tracking point and the third tracking point are used to monitor the child process, and the second tracking point is used to obtain the absolute path of the file.
[0009] The root file system construction method provided by the embodiment of the present invention prepares for the kernel state service to be started through the main process, ensures that the kernel state service can be started quickly, activates three specific tracking points after starting the kernel state service, provides support for subsequent monitoring of subprocesses and capturing file absolute paths, and is beneficial to the data integrity of the root file system. Through efficient kernel state services and lightweight tracking point mechanisms, the impact on system performance is reduced and the flexibility and adaptability of the system are improved.
[0010] In an optional implementation, updating the target data structure based on the initial subprocess includes: In response to each time the initial child process opens a file, triggering a second tracking point; Based on the second tracking point, the absolute file path of the initial child process is obtained; In response to the second tracking point returning, judging whether the file opening operation of the initial child process is successful based on the return value of the second tracking point; If the file opening operation of the initial child process is successful, determine whether the key-value pair of the initial child process exists in the target data structure; If the key-value pair of the initial child process does not exist in the target data structure, the process identifier of the initial child process is used as the key and the absolute file path of the initial child process is used as the value to construct the key-value pair corresponding to the initial child process and store it in the target data structure; or, In the case where the key-value pair of the initial child process exists in the target data structure, the value of the key-value pair is updated based on the absolute file path of the initial child process.
[0011] The root file system construction method provided by the embodiment of the present invention can monitor the file opening operation of the initial child process in real time by triggering the second tracking point, and judge whether the file opening operation is successful based on the return value of the second tracking point, thereby improving the reliability of the file absolute path collection, and avoiding repeated storage of the same data by checking whether there is a key-value pair in the target data structure, optimizing the use of storage resources, and being able to dynamically update the file absolute path when the key-value pair already exists in the target data structure.
[0012] In an optional implementation, in response to each subprocess in the tracing task chain creating a new subprocess, obtaining the absolute file path of the new subprocess, and updating the tracing task chain include: In response to each subprocess in the tracing task chain creating a new subprocess, triggering a first tracing point; Based on the first trace point, a new child process is added to the trace task chain.
[0013] The root file system construction method provided by the embodiment of the present invention triggers a preset first tracking point when any sub-process creates a new sub-process, and adds the new sub-process to the tracking task chain, so that the tracking task chain can dynamically track the creation of the new sub-process, ensuring that all sub-processes can be completely tracked, which helps to build a complete root file system.
[0014] In an optional implementation, in response to each child process exiting, updating the target data structure includes: In response to each child process exiting, triggering a third trace point; Based on the process identifier of the child process, determine whether a key-value pair of the child process exists in the target data structure; In the case that the key-value pair of the child process exists in the target data structure, the key-value pair corresponding to the child process is deleted from the target data structure based on the third tracking point and the process identifier.
[0015] The root file system construction method provided by the embodiment of the present invention ensures that each child process exit event can be captured immediately by triggering a preset third tracking point every time a child process exits. When the third tracking point is triggered, the key-value pair of the child process is deleted from the target data structure to ensure that the target data structure is consistent with the actual running state, which is convenient for accurate tracking. By using the tracking point to capture the exit event of each child process in real time, it is ensured that the state changes of all child processes can be completely tracked.
[0016] In an optional implementation, when the target data structure is empty, a root file system is constructed based on the absolute file paths of all child processes in the tracking task chain, including: When the target data structure is empty, the special file absolute path is deleted from the file absolute paths of all child processes in the tracking task chain; Build the root file system based on the absolute paths of all deleted files.
[0017] The root file system construction method provided by the embodiment of the present invention screens all file absolute paths to ensure that the file absolute paths used to construct the root file system are necessary and complete, thereby improving construction efficiency and accuracy and reducing system resource consumption.
[0018] In an optional implementation, when the target data structure is empty, the method further includes: A prompt message is sent to the user layer, which is used to indicate that the tracking of the tracking task chain has been completed.
[0019] The root file system construction method provided by the embodiment of the present invention can timely notify the user of the state change of the tracking task chain, so that the user can understand the current operation status and enhance the user experience.
[0020] In a second aspect, the present invention provides a root file system construction device, the device comprising: Creation module, used to create the initial child process, trace the task chain and target data structure; A startup module is used to start the tracking task chain with the initial subprocess as the starting point and update the target data structure based on the initial subprocess; A first updating module is used to create a new subprocess in response to each subprocess in the tracking task chain, obtain the absolute file path of the new subprocess, and update the tracking task chain and the target data structure; A second update module, for updating the target data structure in response to each child process exiting; The construction module is used to build the root file system based on the absolute file paths of all child processes in the tracking task chain when the target data structure is empty.
[0021] In a third aspect, the present invention provides a computer device, comprising: a memory and a processor, the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the root file system construction method of the first aspect or any corresponding embodiment thereof by executing the computer instructions.
[0022] In a fourth aspect, the present invention provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the root file system construction method of the first aspect or any corresponding embodiment thereof.
[0023] In a fifth aspect, the present invention provides a computer program product, including computer instructions, where the computer instructions are used to enable a computer to execute the root file system construction method of the first aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some implementation methods of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0025] Figure 1 is a flowchart of a method for constructing a root file system according to an embodiment of the present invention; Figure 2 is a flowchart of another method for constructing a file system according to an embodiment of the present invention; Figure 3 is a structural block diagram of a root file system construction device according to an embodiment of the present invention; Figure 4 It is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0026] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present invention.
[0027] At present, in the process of building a root file system, the file tracking method used cannot fully and accurately track the absolute path of the file, resulting in the inability to accurately and efficiently build a lightweight root file system. The root file system construction method provided by the embodiment of the present invention obtains the absolute path of the file based on the tracking task chain to build the root file system, ensuring that the generated root file system only contains the complete absolute path of the file actually used, and has a smaller volume, thereby achieving comprehensive, accurate and efficient root file system construction.
[0028] According to an embodiment of the present invention, an embodiment of a root file system construction method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0029] In this embodiment, a method for constructing a root file system is provided. Figure 1 is a flowchart of a method for constructing a root file system according to an embodiment of the present invention. Figure 1 As shown, the process includes the following steps: Step S101, create an initial child process, a tracing task chain and a target data structure. Specifically, when the user-mode program is started, an initial child process is created, and a tracing task chain starting from the initial child process is created to trace all child processes directly or indirectly created by the initial child process. At the same time, prepare the target data structure in the eBPF (Extended Berkeley Packet Filter) kernel-mode service, which is a hash table data structure of eBPF, used to store process identifiers and absolute file paths.
[0030] Step S102, starting the tracing task chain with the initial child process as the starting point, and updating the target data structure based on the initial child process. Specifically, the initial child process switches to the service through execve, and formally starts the tracing task chain. The initial child process serves as the task starting point of the tracing task chain, ensuring that starting from the initial child process, the file access behaviors of all child processes can be monitored and recorded, providing data support for subsequent acquisition of the absolute path of the file and construction of the root file system. The initial child process is used as the starting point, and the target data structure is updated based on the initial child process.
[0031] Step S103, in response to each subprocess in the tracking task chain creating a new subprocess, obtain the absolute file path of the new subprocess, and update the tracking task chain and the target data structure. Specifically, when a subprocess in the tracking task chain (such as WeChat) creates a new subprocess (such as WeChat detection update task), the tracking task chain and the target data structure are updated. Through this mechanism, the file opening status of the new subprocesses continuously generated in the task chain can be continuously tracked to ensure that the complete file opening record is obtained, so that the constructed root file system contains all the files required for the task to run.
[0032] Step S104, in response to each child process exiting, the target data structure is updated. Specifically, when a child process in the tracking task chain exits, the target data structure is updated. This operation ensures that the target data structure always stores the information of the currently ongoing process, which facilitates the determination of whether the task chain tracking is completed.
[0033] Step S105, when the target data structure is empty, a root file system is constructed based on the absolute file paths of all child processes in the tracing task chain. Specifically, when the target data structure is empty, it means that all child processes in the tracing task chain have completed execution. At this time, a minimum root file system that can be used for startup is created based on all the collected absolute file paths.
[0034] The root file system construction method provided by the embodiment of the present invention performs initialization preparation by creating an initial child process and a target data structure, starts a tracking task chain through the initial child process, and updates the target data structure, and uses the tracking task chain to track all child processes directly or indirectly created by the initial child process. Whenever any child process in the tracking task chain creates a new child process, the file absolute path of the new child process is obtained, and the tracking task chain and the target data structure are updated at the same time, so as to realize dynamic maintenance of the tracking task chain and the target data structure, ensure that all related file operations are tracked, and update the target data structure when the child process exits, so as to ensure that the target data structure always reflects the current process status, thereby improving the accuracy and reliability of tracking. When the target data structure is empty, it means that the process tracking has been completed, and at this time, all file absolute paths are summarized to build the root file system, so as to ensure that the generated root file system only contains the complete file absolute paths actually used, and has a smaller size, thereby realizing comprehensive, accurate and efficient root file system construction.
[0035] In this embodiment, a method for constructing a root file system is provided. Figure 2 FIG. 1 is a flowchart of another method for constructing a file system according to an embodiment of the present invention. Figure 2 As shown, the process includes the following steps: Step S201, creating an initial subprocess, a tracking task chain and a target data structure.
[0036] In some optional implementations, after the above step S201 creates the initial subprocess, the following steps are included: Step a1, make the main process prepare kernel state services. Specifically, after creating the initial child process, the main process prepares kernel state services, such as loading related program codes and configuring necessary parameters, etc., to prepare for the subsequent startup of kernel state services and opening of tracking points, ensuring that the kernel state can support the tracking function of process file access.
[0037] Step a2, start the kernel state service, open the first tracking point, the second tracking point and the third tracking point, the first tracking point and the third tracking point are used to monitor the child process, and the second tracking point is used to obtain the absolute path of the file. Specifically, the main process starts the eBPF kernel state service to open three tracking points. Among them, the first tracking point is tracepoint, such as tracepoint_sched_process_fork, which is a mark in the kernel code and is used to monitor the creation of the process; the second tracking point is kprobe, such as kprobe_vfs_open, which uses eBPF technology to obtain the absolute path of the file when the file operation occurs; the third tracking point is tracepoint, such as tracepoint_sched_process_exit, which is also a mark in the kernel code and is used to monitor the exit of the process.
[0038] Step S202, starting the tracking task chain with the initial sub-process as the starting point, and updating the target data structure based on the initial sub-process.
[0039] Specifically, the above step S202 updates the target data structure based on the initial sub-process, including: Step S2021, in response to each file opening by the initial child process, trigger the second tracking point. Specifically, using eBPF technology, the file opening function (such as vfs_open) is hooked and a specific kernel state function is mounted. When the file opening operation occurs, the mounted kernel state function will be called, and the second tracking point (kprobe_vfs_open) is triggered.
[0040] Step S2022, based on the second tracking point, obtain the absolute file path of the initial child process. Specifically, kprobe_vfs_open is used instead of the system call open or other locations because the file path and the mount point are passed in kprobe_vfs_open, and the two are combined to parse the complete absolute file path from the kernel structure using eBPF technology.
[0041] Step S2023, in response to the second tracking point returning, based on the return value of the second tracking point, determine whether the file opening operation of the initial child process is successful. Specifically, the second tracking point will have a return value after the file opening operation is completed. When it returns, obtain its return value. If the return value is 0, it indicates that the file opening operation is successful, and then continue with the subsequent steps; if the return value is not 0, it indicates that the current file opening fails, and no subsequent operations on the target data structure are performed.
[0042] Step S2024, when the file opening operation of the initial child process is successful, it is determined whether there is a key-value pair of the initial child process in the target data structure. Specifically, after the file is opened successfully, it is checked whether the key-value pair of the initial child process already exists in the target data structure. More specifically, the process identifier of the initial child process is the key of the key-value pair, and by traversing the keys of all key-value pairs in the target data structure, it can be determined whether the key-value pair of the initial child process is stored in the target data structure.
[0043] Step S2025, if the key-value pair of the initial child process does not exist in the target data structure, the process identifier of the initial child process is used as the key, and the absolute path of the file of the initial child process is used as the value to construct the key-value pair corresponding to the initial child process and store it in the target data structure. Specifically, if the key-value pair of the initial child process does not exist in the target data structure, it means that this is the first time that the initial child process successfully opens a file. At this time, the process identifier is used as the key, and the absolute path of the successfully opened file is used as the value to form a key-value pair and store it, so as to accumulate data for the subsequent construction of the minimum root file system.
[0044] Alternatively, in step S2026, if the key-value pair of the initial child process exists in the target data structure, the value of the key-value pair is updated based on the absolute file path of the initial child process. Specifically, if the key-value pair of the initial child process already exists in the target data structure, it means that the initial process has successfully opened the file before. At this time, the newly obtained successfully opened file path is added to the corresponding key-value pair in the target data structure to ensure that the target data structure records the complete file access situation, realize dynamic update, and thus provide support for building a more accurate minimum root file system.
[0045] Step S203, in response to each sub-process in the tracing task chain creating a new sub-process, obtaining the absolute file path of the new sub-process, and updating the tracing task chain and the target data structure.
[0046] Specifically, the above step S203 creates a new subprocess in response to each subprocess in the tracking task chain, obtains the absolute file path of the new subprocess, and updates the tracking task chain, including: Step S2031, in response to each subprocess in the tracing task chain creating a new subprocess, trigger the first tracing point. Specifically, when a subprocess in the tracing task chain (such as the WeChat startup process) creates a new subprocess (such as the WeChat detection update task), the first tracing point (tracepoint_sched_process_fork) is triggered, indicating that a new subprocess has joined the tracing task chain.
[0047] Step S2032: based on the first tracking point, add the new subprocess to the tracking task chain. Specifically, after the first tracking point is triggered, its processing program adds the newly created subprocess to the tracking task chain.
[0048] In some optional implementations, reference may be made to steps S2021 to S2026 to obtain the absolute file path of the new child process and update the target data structure, which will not be described in detail herein.
[0049] Step S204, in response to each child process exiting, updating the target data structure.
[0050] Specifically, the above step S204 includes: Step S2041, in response to each child process exiting, triggering a third trace point. Specifically, when a child process completes a task and exits, the third trace point (tracepoint_sched_process_exit) is triggered, indicating that the tracing of the child process ends.
[0051] Step S2042, based on the process identifier of the child process, determine whether there is a key-value pair of the child process in the target data structure. Specifically, based on the process identifier of the child process, find out from the target data structure whether there is a key-value pair with the process identifier of the child process as the key.
[0052] Step S2043, when there is a key-value pair of the sub-process in the target data structure, based on the third tracking point and the process identifier, the key-value pair corresponding to the sub-process is deleted from the target data structure. Specifically, if a key-value pair with the process identifier of the sub-process as the key can be found, it means that the key-value pair of the sub-process exists in the target data structure. When the third tracking point detects a process exit event, the key-value pair of the exited sub-process is deleted from the target data structure, ensuring that the target data structure only stores relevant data of the ongoing process in the tracking task chain, which is convenient for managing and judging the status of the tracking task chain.
[0053] Step S205, when the target data structure is empty, a root file system is constructed based on the absolute file paths of all child processes in the tracking task chain.
[0054] In some optional implementations, when the target data structure is empty, the above step S205 includes: Step b1, sending prompt information to the user layer, the prompt information is used to indicate that the tracking of the tracking task chain has been completed. Specifically, when the target data structure is empty, sending prompt information to the user layer to inform the user that the tracking operation of the entire tracking task chain has been completed.
[0055] Specifically, the above step S205 includes: Step S2051, when the target data structure is empty, delete the special file absolute path from the file absolute path of all child processes in the tracking task chain. Specifically, when the target data structure is empty, it means that all processes in the tracking task chain have completed execution and exited. At this time, the file absolute paths of all child processes in the tracking task chain are processed, and the special file absolute path is deleted. Among them, the special file absolute path refers to the file absolute path that is not required when building a minimum root file system for starting the task, such as the virtual file absolute path provided by the kernel. By screening all file absolute paths, it is ensured that the file absolute path used to build the root file system is necessary and complete, which improves the construction efficiency and accuracy, and reduces system resource consumption.
[0056] Step S2052, based on the absolute paths of all deleted files, a root file system is constructed. Specifically, after deleting the absolute paths of special files, the absolute paths of the remaining files are sorted and packaged to construct a minimum root file system. This root file system contains all the files required for the task to run.
[0057] In some optional implementations, when the root file system is built, the built root file system can be generated into a corresponding container image, and migration can be performed based on this container image to create and start a container in an environment that supports container operation. The process in the container will be initialized and run based on the root file system.
[0058] The root file system construction method provided by the embodiment of the present invention performs initialization preparation by creating an initial child process and a target data structure, starts a tracking task chain through the initial child process, and updates the target data structure, and uses the tracking task chain to track all child processes directly or indirectly created by the initial child process. Whenever any child process in the tracking task chain creates a new child process, the file absolute path of the new child process is obtained, and the tracking task chain and the target data structure are updated at the same time, so as to realize dynamic maintenance of the tracking task chain and the target data structure, ensure that all related file operations are tracked, and update the target data structure when the child process exits, so as to ensure that the target data structure always reflects the current process status, thereby improving the accuracy and reliability of tracking. When the target data structure is empty, it means that the process tracking has been completed, and at this time, all file absolute paths are summarized to build the root file system, so as to ensure that the generated root file system only contains the complete file absolute paths actually used, and has a smaller size, thereby realizing comprehensive, accurate and efficient root file system construction.
[0059] In this embodiment, a root file system construction device is also provided, which is used to implement the above embodiments and preferred implementation modes, and the descriptions that have been made will not be repeated. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.
[0060] This embodiment provides a root file system construction device, such as Figure 3 As shown, including: The creation module 301 is used to create an initial subprocess, a tracking task chain and a target data structure.
[0061] The starting module 302 is used to start the tracking task chain with the initial sub-process as the starting point, and update the target data structure based on the initial sub-process.
[0062] The first updating module 303 is used to create a new sub-process in response to each sub-process in the tracking task chain, obtain the absolute file path of the new sub-process, and update the tracking task chain and the target data structure.
[0063] The second updating module 304 is used to update the target data structure in response to each child process exiting.
[0064] The construction module 305 is used to construct a root file system based on the absolute file paths of all subprocesses in the tracking task chain when the target data structure is empty.
[0065] In some optional implementations, after creating module 301, the device further includes: The preparation module is used to enable the main process to prepare kernel-mode services.
[0066] The start module is used to start the kernel mode service and start the first tracking point, the second tracking point and the third tracking point.
[0067] In some optional implementations, the startup module 302 includes: The first trigger unit is used to trigger the second tracking point in response to each time the initial child process opens a file.
[0068] The obtaining unit is used to obtain the absolute file path of the initial child process based on the second tracking point.
[0069] The first judgment unit is used to judge whether the file opening operation of the initial child process is successful based on the return value of the second tracking point in response to the return of the second tracking point.
[0070] The second judgment unit is used to judge whether there is a key-value pair of the initial sub-process in the target data structure when the file opening operation of the initial sub-process is successful.
[0071] The storage unit is used to construct a key-value pair corresponding to the initial child process by using the process identifier of the initial child process as a key and the absolute file path of the initial child process as a value, and store it in the target data structure when the key-value pair of the initial child process does not exist in the target data structure.
[0072] Alternatively, the updating unit is used to update the value of the key-value pair based on the absolute file path of the initial child process when the key-value pair of the initial child process exists in the target data structure.
[0073] In some optional implementations, the first updating module 303 includes: The second triggering unit is used to trigger the first tracking point in response to each sub-process in the tracking task chain creating a new sub-process.
[0074] The adding unit is used to add a new subprocess to the tracing task chain based on the first tracing point.
[0075] In some optional implementations, the second updating module 304 includes: The third trigger unit is used to trigger the third tracking point in response to each child process exiting.
[0076] The third judgment unit is used to judge whether there is a key-value pair of the sub-process in the target data structure based on the process identifier of the sub-process.
[0077] The first deleting unit is used to delete the key-value pair corresponding to the sub-process from the target data structure based on the third tracking point and the process identifier when the key-value pair of the sub-process exists in the target data structure.
[0078] In some optional implementations, the construction module 305 includes: The second deleting unit is used to delete the special file absolute path from the file absolute paths of all child processes in the tracking task chain when the target data structure is empty.
[0079] The construction unit is used to build the root file system based on the absolute paths of all files after deletion.
[0080] In some optional implementations, after constructing module 305, the device further includes: The sending module is used to send prompt information to the user layer, and the prompt information is used to indicate that the tracking of the tracking task chain has been completed.
[0081] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.
[0082] The root file system construction device in this embodiment is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.
[0083] The embodiment of the present invention also provides a computer device having the above Figure 3 The root file system build device shown.
[0084] See also Figure 4 , Figure 4 is a schematic diagram of the structure of a computer device provided by an optional embodiment of the present invention, such as Figure 4 As shown, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components are connected to each other using different buses for communication, and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in or on the memory to display the graphical information of the GUI on an external input / output device (such as, a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Similarly, multiple computer devices can be connected, and each device provides some necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 4 A processor 10 is taken as an example.
[0085] The processor 10 may be a central processing unit, a network processor or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be a dedicated integrated circuit, a programmable logic device or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic or any combination thereof.
[0086] The memory 20 stores instructions executable by at least one processor 10, so that at least one processor 10 executes the method shown in the above embodiment.
[0087] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created according to the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely arranged relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0088] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid state drive; the memory 20 may also include a combination of the above types of memory.
[0089] The computer device further comprises a communication interface 30 for the computer device to communicate with other devices or a communication network.
[0090] The embodiment of the present invention also provides a computer-readable storage medium. The method according to the embodiment of the present invention can be implemented in hardware, firmware, or can be implemented as a computer code that can be recorded in a storage medium, or can be implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and will be stored in a local storage medium through a network download, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state hard disk, etc.; further, the storage medium can also include a combination of the above types of memories. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor, or hardware, the method shown in the above embodiment is implemented.
[0091] A part of the present invention may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should understand that the existence of the computer program instruction in a computer-readable medium includes, but is not limited to, a source file, an executable file, an installation package file, etc., and accordingly, the way in which the computer program instruction is executed by the computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium may be any available computer-readable storage medium or communication medium accessible to the computer.
[0092] Although the embodiments of the present invention have been described in conjunction with the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations are all within the scope defined by the appended claims.
Claims
1. A method for constructing a root file system, characterized in that: The method comprises: Create the initial child process, trace the task chain and target data structures; Starting the tracking task chain with the initial subprocess as a starting point, and updating the target data structure based on the initial subprocess; In response to each subprocess in the tracking task chain creating a new subprocess, obtaining the absolute file path of the new subprocess, and updating the tracking task chain and the target data structure; In response to each child process exiting, updating the target data structure; When the target data structure is empty, a root file system is constructed based on the absolute file paths of all subprocesses in the tracking task chain.
2. The method according to claim 1, characterized in that After creating the initial subprocess, the method further includes: Make the main process prepare kernel-mode services; The kernel state service is started, and a first tracking point, a second tracking point and a third tracking point are enabled, wherein the first tracking point and the third tracking point are used to monitor the child process, and the second tracking point is used to obtain the absolute path of the file.
3. The method according to claim 2, characterized in that The updating of the target data structure based on the initial sub-process comprises: In response to each time the initial child process opens a file, triggering the second tracking point; Based on the second tracking point, obtaining the absolute file path of the initial child process; In response to the second tracking point returning, judging whether the file opening operation of the initial child process is successful based on the return value of the second tracking point; If the file opening operation of the initial child process is successful, determining whether a key-value pair of the initial child process exists in the target data structure; In the case where the key-value pair of the initial child process does not exist in the target data structure, the process identifier of the initial child process is used as the key and the absolute file path of the initial child process is used as the value to construct the key-value pair corresponding to the initial child process and store it in the target data structure; or In a case where the key-value pair of the initial child process exists in the target data structure, the value of the key-value pair is updated based on the absolute file path of the initial child process.
4. The method according to claim 2, characterized in that: The step of creating a new subprocess in response to each subprocess in the tracking task chain, obtaining the absolute file path of the new subprocess, and updating the tracking task chain includes: In response to each subprocess in the tracing task chain creating a new subprocess, triggering the first tracing point; Based on the first tracking point, a new child process is added to the tracking task chain.
5. The method according to claim 2, characterized in that: In response to each child process exiting, updating the target data structure comprises: In response to each child process exiting, triggering the third tracking point; Based on the process identifier of the child process, determining whether a key-value pair of the child process exists in the target data structure; In a case where the key-value pair of the child process exists in the target data structure, the key-value pair corresponding to the child process is deleted from the target data structure based on the third tracking point and the process identifier.
6. The method according to claim 1, characterized in that When the target data structure is empty, building a root file system based on the absolute file paths of all subprocesses in the tracking task chain includes: When the target data structure is empty, deleting the special file absolute path from the file absolute paths of all subprocesses in the tracking task chain; The root file system is constructed based on the absolute paths of all deleted files.
7. The method according to claim 1, characterized in that After the target data structure is empty, the method further comprises: A prompt message is sent to the user layer, where the prompt message is used to indicate that the tracking of the tracking task chain has been completed.
8. A root file system construction device, characterized in that: The device comprises: Create module, which is used to create the initial child process, track the task chain and target data structure; A starting module, used for starting the tracking task chain with the initial subprocess as a starting point, and updating the target data structure based on the initial subprocess; A first updating module, configured to create a new subprocess in response to each subprocess in the tracking task chain, obtain an absolute file path of the new subprocess, and update the tracking task chain and the target data structure; A second updating module, configured to update the target data structure in response to each child process exiting; A construction module is used to construct a root file system based on the absolute file paths of all subprocesses in the tracking task chain when the target data structure is empty.
9. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the root file system construction method according to any one of claims 1 to 7 by executing the computer instructions.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the root file system construction method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Malicious process detection method and device, terminal and computer readable storage medium
CN111783091A
File processing method and device and storage medium
CN114662102A
Process monitoring method and computing device
CN119271498A
Intelligent sound system apparatus and operating method thereof
KR102218201B1