Automatic verification method and system for consistency of operation authorities of file system
Through automated verification methods and systems, a test set is generated and executed in the file system under test through application scenarios, the problem of inability to effectively verify the permissions of multiple commands combined in the prior art is solved, and efficient permission detection and verification are achieved.
Patent Information
- Application Number
- CN202510118879.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-24
- Publication Date
- 2025-05-27
AI Technical Summary
The prior art cannot effectively verify that the file system with multiple command combinations is out of bounds or insufficient, and manual verification is cumbersome and time-consuming, making it easy to miss errors.
It provides a file system permission consistency automation verification method and system. By combining file and directory operation commands according to application scenarios, generating a test set, and executing these commands in the file system under test, analyzing the execution results to judge whether the permissions are out of bounds or insufficient.
Automatic detection and verification of file system permissions under multiple command combinations is realized, which improves testing efficiency and reduces the cumbersomeness and error rate of manual verification.
Smart Images

Figure CN120046189A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of file management, and particularly to a method and system for automatically verifying the consistency of file system operation permissions. Background Art
[0002] In modern computer systems, the operation permission management of files and directories is an important mechanism to ensure data security and system stability. Verifying the consistency of file system operation permissions can ensure the correctness of file system permission control; after setting different permission controls, verify that users are allowed and prohibited from performing operations under specific permissions to ensure the correct permission control and prevent permission overstepping or insufficient permissions when users access directories.
[0003] Different file systems have different permission management mechanisms. The Linux file system uses UGO permissions to manage file and directory access permissions, and the roles are: the owner of the directory or file (User), the group to which it belongs (Group), and other users (Other). The permissions corresponding to each role are: r for readable, w for writable, and x for executable. Linux also supports special permissions, such as setuid, setgid, and sticky bit, as well as access control lists (ACLs), allowing more refined permission control. NTFS of Windows supports detailed permission management, including the ownership of files and folders, access control lists (ACLs), and security attributes.
[0004] File system directories are exported through different protocols (NFS / CIFS / FUSE / POSIX, etc.). The permission control for Linux clients to mount and access shared directories is jointly determined by multiple factors, including Linux file system permissions (directory UGO permissions, ACL permissions, special permissions), the configurations of different protocol shared servers, and options during mounting. When users access shared resources through different protocols, whether they can read and write is jointly determined by the above factors. Permissions can be divided into read-only, read-write, read-write non-deletable, all permissions, etc. There are various command methods for Linux clients to read and write files or directories. Manually verifying the permissions of users under a single factor or a combination of multiple factors is redundant, cumbersome, time-consuming, laborious, and prone to omissions and errors, resulting in low test efficiency.
[0005] Currently, the professional open-source test tool is pjd-fstest, which is an automated test suite for testing the POSIX compatibility of file systems. It supports running on FreeBSD, Solaris, and Linux operating systems and can test various file systems such as UFS, ZFS, ext3, XFS, and NTFS-3G. It can be used to test system calls related to file permissions. The list of system calls to be tested includes chmod, chown, link, mkdir, mkfifo, open, rename, rmdir, symlink, truncate, unlink, etc.
[0006] The file system interface provides a set of limited, powerful, and hardware-close interfaces at the system call level. Pjdfstest is a test set for verifying POSIX system calls, and it pays more attention to testing the POSIX compatibility of the file system interface. The test items of Pjdfstest are for testing a single interface.
[0007] However, in actual use, more operations are at the user level, which is to execute a single command or a combination of multiple commands, and each command may use multiple system calls to implement. For example, for permission verification in an application scenario, such as: software package installation and uninstallation includes the following: 1) Make a simple runnable package and a running script, compile, compress, and package them into a bin file; 2) Create a subdirectory as a temporary directory and copy the bin file to the temporary directory; 3) Enter the temporary directory, decompress the bin package, and perform verification after decompression; 4) Modify the permissions of the script file, execute the script, and install the package; 5) Check whether the function is available after installation; 6) Delete the temporary directory; 7) Execute commands for uninstallation. If judging whether the permissions in this application scenario are insufficient or out-of-bounds, it is to execute a combination of multiple commands. The tests of Pjdfstest cannot cover more complex actual use scenarios, that is, it cannot verify the out-of-bounds and insufficiency of permissions in the scenario of combining multiple commands. When manually verifying the operation permissions, it is necessary to check the results of each common command under different permissions of multiple commands, which is cumbersome and time-consuming and prone to omissions. Summary of the Invention
[0008] Based on this, in view of the above technical problems, a method and system for automated verification of file system permission consistency are provided to solve the problems that the prior art cannot verify the out-of-bounds or insufficiency of permissions with multiple command combinations or the manual verification is cumbersome.
[0009] In a first aspect, a method for automated verification of file system permission consistency, the method includes:
[0010] Combine the single commands for the files and directories according to different application scenarios of actual operations to generate a test set; generate a test set for commands with the same type of permissions;
[0011] Send the generated multiple test sets to the file system under test of the client under test in sequence, so that the client under test executes the single command or multiple combined test commands in the test set on the test files and directories pre-constructed in the file system under test;
[0012] Receive the execution result of the file system under test of the client under test, analyze according to the execution result, judge whether there is permission overstep or insufficient permission, and output the analysis result.
[0013] In the above solution, optionally, the execution result at least includes the name of the command, execution parameters, return status code, and output content.
[0014] In the above solution, optionally, the file permission types at least include: creating a file, reading the content of a text file, editing the content of a file, modifying the file permission, modifying the file attributes, modifying the extended file attributes, deleting a file, compressing / decompressing, running an executable file.
[0015] In the above solution, optionally, the directory permission types at least include: creating a directory, reading the directory structure, modifying the directory structure, modifying the directory attributes, modifying the extended directory attributes, modifying the directory permission, creating a soft link, compressing / decompressing, deleting a directory.
[0016] In a second aspect, an automated verification system for file system operation permission consistency, the system includes:
[0017] A test set generation module: used to combine the single commands for the files and directories according to different application scenarios of actual operations to generate a test set; generate a test set for commands with the same type of permissions;
[0018] A test execution module: used to send the generated multiple test sets to the file system under test of the client under test in sequence, so that the client under test executes the single command or multiple combined test commands in the test set on the test files and directories pre-constructed in the file system under test;
[0019] An analysis module: used to receive the execution result of the file system under test of the client under test, analyze according to the execution result, judge whether there is permission overstep or insufficient permission, and output the analysis result.
[0020] In a third aspect, a computer device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, it implements the steps of the method for automated verification of file system permission consistency described in the first aspect above.
[0021] In a fourth aspect, a computer program product includes a computer program / instructions which, when executed by a processor, implement the steps of the method for automatically verifying file system permission consistency described in the first aspect above.
[0022] This application has at least the following beneficial effects:
[0023] In this application, according to the application scenario, operation commands for files and directories are combined to generate a test set. At the same time, commands with the same type of permission are grouped into a test set. A test directory and files are created in the file system under test, and the commands in the generated test set are executed on the test directory and files. Whether there is an out-of-bounds or insufficient situation is judged according to the execution results. Thus, detection can be carried out automatically. At the same time, under multiple command combinations, automatic testing can also be carried out, improving the testing efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] Figure 1 It is a schematic flowchart diagram of a method for automatically verifying file system permission consistency provided by an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0025] In order to make the objectives, technical solutions and advantages of this application clearer, the following further elaborates on this application in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not used to limit this application.
[0026] In one embodiment, as Figure 1 shown, a method for automatically verifying file system permission consistency is provided, and the method includes:
[0027] Step S1: Combine single commands for the files and directories according to different application scenarios of actual operations to generate a test set; generate a test set for commands with the same type of permission.
[0028] In step S1, the classification of commands includes the following:
[0029] 1) Create files: Create ordinary files, hidden files, device files or FIFOs, soft links and hard links;
[0030] 2) Read the content of text files: Read the content of binary files, read file attributes, read file permissions, read file extended attributes, list file information, verify md5 values, view file paths, view file ACL permissions;
[0031] 3) Edit the content of files: Editor write, append write, overwrite write, truncate write, binary file write, insert and replace content;
[0032] 4) Modify file permissions: Modify the UGO permissions of files, set / modify / delete the ACL permissions of files, set / modify / delete special permissions;
[0033] 5) Modify file attributes: Modify the user to whom the file belongs, modify the group to which the file belongs, rename, move the file location;
[0034] 6) Modify file extended attributes: Modify / delete the existing extended attributes of files;
[0035] 7) Other operations: Compress / decompress, run executable files;
[0036] 8) Delete files: Delete files;
[0037] For example, to determine whether there is permission to create a file, it is necessary to verify separately whether there is permission to create ordinary files, hidden files, device files or FIFOs, soft links and hard links. If all the permissions to create ordinary files, hidden files, device files or FIFOs, soft links and hard links are available, it means that there is permission to create files. If not, it means that the permission to create files is insufficient.
[0038] The permission classification of directories is as follows:
[0039] 1) Create directories: Create directories and multi-level directories;
[0040] 2) List the directory file list, read the directory structure, enter the directory, query the directory path, query the directory usage capacity, copy the directory data to the local directory, view the directory permissions, view the directory attributes, view the directory extended attributes, view the directory details, view the directory ACL information;
[0041] 3) Modify the directory structure: Create / delete / rename / move files and subdirectories within the directory, rename the directory, move the directory location;
[0042] 4) Modify directory attributes: Modify the user to whom the directory belongs, modify the group to which the directory belongs, recursively modify the user / group to which the directory belongs;
[0043] 5) Modify directory extended attributes: Modify / delete the existing extended attributes of directories;
[0044] 6) Modify directory permissions: Modify the UGO permissions of directories, set / modify / delete the ACL permissions of directories, set / modify / delete special permissions;
[0045] 7) Others: Create soft links, compress / decompress;
[0046] 8) Delete directories: Delete empty directories, non-empty directories.
[0047] Divided by application scenarios: for example, full read-only, write-only, read-write, all permissions, compilation, decompilation, compression, decompression, program installation and uninstallation (such as database installation and uninstallation), log file archiving and reprinting, etc. The way of simulating scenarios is convenient for subsequent expansion and supplementation of test scenarios.
[0048] In the scenario of enabling a custom service, modifying it and then starting the service, the commands required are:
[0049] 1) Create a local user and its associated group;
[0050] 2) Create a subdirectory A, set the permissions of subdirectory A, and create files and subdirectories within directory A;
[0051] 3) Modify the user and group to which subdirectory A belongs, and change them to the user and group created in step 1; modify the directory permissions to 750;
[0052] 4) View the information of subdirectory A and check whether the modification is successful;
[0053] 5) Create a systemd service unit file, specify the service path in this subdirectory A; start the service to run and check whether the service is running normally;
[0054] 6) Stop the service, move the files and subdirectories in directory A to directory B;
[0055] 7) Modify the user and group to which directory B belongs, and change them to the user and group created in step 1; modify the permissions of directory B;
[0056] 8) Create soft links in subdirectory A, respectively pointing to the files and subdirectories in directory B;
[0057] 9) Start the service and check whether the service is running normally;
[0058] 10) Stop the service, clean up the environment, and delete directory A and B, the systemd service unit file, as well as the user and group.
[0059] Step S2: Sequentially send multiple generated test sets to the file system under test of the client under test, so that the client under test executes a single command or multiple combined test commands in the test files and directories pre-constructed in the file system under test;
[0060] Step S3: Receive the execution result of the file system under test of the client under test, analyze according to the execution result, judge whether there is permission overstep or insufficient permission, and output the analysis result.
[0061] When testing on the client side, specify the mount directory, select a command set or a simulation scenario, and run the corresponding execution command. Each command classification of files / directories in the command set is a test set, and each scenario in the simulation scenario is a test set; the execution process:
[0062] 1) Test data files and directories will be generated before executing the command;
[0063] 2) If data generation fails, operate on the existing data in the directory; if there is no data, report an error and exit the test;
[0064] 3) Execute the test sets of command classifications in sequence, or execute the selected scenario tests in sequence;
[0065] 4) The return result of each command execution is recorded in the log, and the error log is also recorded in the error log;
[0066] 5) After execution is completed, print out the number of commands that executed successfully and the number of commands that executed failed in each test set.
[0067] In the above method for automatic verification of file system permission consistency, by combining the operation commands on files and directories according to the application scenario to generate test sets, and at the same time, generating a test set for commands with the same type of permissions; create test directories and files in the file system under test, execute the commands of the generated test sets on the test directories and files, and determine whether there is an overstep or insufficiency according to the execution results. Thus, detection can be automatically performed, and at the same time, under multiple command combinations, automatic testing can also be carried out to improve the testing efficiency.
[0068] In one embodiment, the execution result at least includes the name of the command, execution parameters, return status code, and output content.
[0069] In one embodiment, the file permission types at least include: creating a file, reading the content of a text file, editing the content of a file, modifying the file permission, modifying the file attributes, modifying the file extended attributes, deleting a file, compressing / decompressing, running an executable file.
[0070] In one embodiment, the directory permission types at least include: creating a directory, reading the directory structure, modifying the directory structure, modifying the directory attributes, modifying the directory extended attributes, modifying the directory permission, creating a soft link, compressing / decompressing, deleting a directory.
[0071] In one embodiment, a system for automatic verification of file system permission consistency is provided, and the system includes:
[0072] Test set generation module: used to combine individual commands of the said files and directories according to different application scenarios of actual operations to generate a test set; generate a test set for commands with the same type of permission;
[0073] Test execution module: used to sequentially send multiple generated test sets to the file system under test of the client under test, so that the client under test executes individual commands or multiple combined test commands in the test files and directories pre-constructed in the file system under test;
[0074] Analysis module: used to receive the execution result of the file system under test of the client under test, analyze according to the said execution result, judge whether there is permission overstep or insufficient permission, and output the analysis result.
[0075] For the specific limitations of a file system permission consistency automatic verification system, reference can be made to the limitations of a file system permission consistency automatic verification method in the above text, which will not be elaborated here. Each module in the above file system permission consistency automatic verification system can be implemented in whole or in part through software, hardware and their combination. The above modules can be embedded in the processor of the computer device in the form of hardware or independent of it, or stored in the memory of the computer device in the form of software, so as to facilitate the processor to call and execute the operations corresponding to the above modules.
[0076] In one embodiment, a computer device is provided. The computer device can be a server. The computer device includes a processor, a memory and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements the above file system permission consistency automatic verification method.
[0077] In one embodiment, a computer program product is further provided, including a computer program / instructions. When the computer program / instructions are executed by the processor, they involve all or part of the processes in the method of the above embodiment.
[0078] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above various methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical memory, etc. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.
[0079] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0080] The above-described embodiments merely represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.
Claims
1. A method for automatically verifying the consistency of file system operation permissions, characterized in that: The method comprises: According to different actual operation application scenarios, the single commands of the files and directories are combined to generate a test set; commands with the same type of permissions are generated into a test set; Sending the generated multiple test sets to the tested file system of the tested client in sequence, so that the tested client executes a single command or multiple combined test commands in the test set on the pre-built test files and directories in the tested file system; Receive the execution result of the tested file system of the tested user terminal, analyze according to the execution result, determine whether the permission is exceeded or insufficient, and output the analysis result.
2. The method for automatically verifying consistency of file system operation permissions according to claim 1, characterized in that: The execution result at least includes the command name, execution parameters, return status code, and output content.
3. The method for automatically verifying the consistency of file system operation permissions according to claim 1, characterized in that: The file permission types include at least: creating a file, reading text file content, editing file content, modifying file permissions, modifying file attributes, modifying file extended attributes, deleting a file, compressing / decompressing, and running an executable file.
4. The method for automatically verifying consistency of file system operation permissions according to claim 1, characterized in that: The directory permission types include at least: creating a new directory, reading a directory structure, modifying a directory structure, modifying directory attributes, modifying directory extended attributes, modifying directory permissions, creating a soft link, compressing / decompressing, and deleting a directory.
5. A file system operation permission consistency automatic verification system, characterized in that: The system comprises: Test set generation module: used to combine the single commands of the files and directories to generate a test set according to different actual operation application scenarios; generate a test set for commands with the same type of permissions; Test execution module: used to send the generated multiple test sets to the tested file system of the tested client in sequence, so that the tested client executes a single command or multiple combined test commands in the test set on the pre-built test files and directories in the tested file system; Analysis module: used for receiving the execution result of the tested file system of the tested user terminal, analyzing according to the execution result, judging whether there is a permission violation or insufficient permission, and outputting the analysis result.
6. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 4 are implemented.
7. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the steps of the method according to any one of claims 1 to 4 are implemented.