Application program log processing method and device

By replacing the message sending function in the application as a custom function and using the hash table to judge the nature of the exception log, the problem of inability to effectively distinguish between normal business and real exception logs in the existing technology is solved, and more efficient log filtering and problem positioning is achieved.

CN120066918APending Publication Date: 2025-05-30BEIJING 58 INFORMATION TTECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510230718.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The prior art cannot effectively filter and distinguish between exception logs caused by normal business of the application and real exception logs, resulting in developers being inefficient when querying and locating problems.

Method used

By replacing the original message sending function in the application as a custom message sending function, the memory address and processing logic in the custom message sending function are used to obtain the information of the target function and save it in the hash table. When an application exception is monitored, determine whether the exception function information is in the hash table and the normal table. If it exists, it is determined to be a normal business and uploading the exception log is prohibited.

Benefits of technology

It effectively reduces the amount of data in the exception log, improves the progress and efficiency of developers querying and positioning problems, reduces unnecessary information processing, and improves the efficiency of positioning application problems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120066918A_ABST
    Figure CN120066918A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an application program log processing method and device, and the method comprises the steps: calling an original message sending function according to a memory address in a user-defined message sending function when an application program runs and executes the user-defined message sending function, calling a target function corresponding to a service for executing the application program according to the original message sending function; obtaining target function information of the target function according to processing logic in the self-defined message sending function, and storing the target function information in a preset hash table; when it is monitored that the application program is abnormal, obtaining an abnormal log corresponding to the application program; if the target function information corresponding to the abnormal function information exists in the hash table and the abnormal function information is in a preset normal table, determining the abnormality corresponding to the abnormal function information as the normal service of the application program; the abnormal log corresponding to the normal service is forbidden to be uploaded to the back-end server. According to the embodiment of the invention, the efficiency of positioning the problem of the application program is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the field of computer technologies, and particularly to an application program log processing method, an application program log processing device, an electronic device, and a computer-readable storage medium. Background Art

[0002] In specific implementation, when an application (App, Application) running on a terminal device encounters a crash or freeze, the system where the terminal device is located (such as iOS and macOS systems, etc.) will collect exception information (exception logs), including crash stacks, device information, network status, etc., and then encapsulate this exception information into an exception report and report it to a backend server through a network request. Developers query through the exception logs reported by the backend server, perform symbolic parsing on the exception logs, and then through data analysis and exception monitoring, discover and locate problems existing in the application program.

[0003] However, some exception information is exception logs caused by normal business, but the backend server will report all exception information and cannot filter out exception logs caused by normal business. Reporting exception logs caused by normal business to the backend server will affect the progress and judgment of developers in querying problems, and seriously affect the efficiency of problem location. Summary of the Invention

[0004] In view of the above problems, an application program log processing method and device are proposed to overcome the above problems or at least partially solve the above problems. The specific technical solutions are as follows:

[0005] In the first aspect of the implementation of the present invention, first, an application program log processing method is provided. The application program is to call a function provided by the programming language according to an original message sending function provided by the programming language for developing the application program; the original message sending function is replaced with a custom message sending function, and the custom message sending function at least includes the memory address and processing logic of the original message sending function. The method includes:

[0006] When the application program runs and executes the custom message sending function, call the original message sending function according to the memory address in the custom message sending function, so as to execute the target function corresponding to the business of the application program according to the call of the original message sending function;

[0007] Obtain target function information of the target function according to the processing logic in the custom message sending function, and save it in a preset hash table;

[0008] When an exception of the application is detected, obtain the exception log corresponding to the application; the exception log includes exception function information of an exception function corresponding to the exception.

[0009] If there is target function information corresponding to the exception function information in the hash table and the exception function information is in a preset normal table, determine the exception corresponding to the exception function information as a normal service of the application; the exception log corresponding to the normal service is prohibited from being uploaded to the backend server.

[0010] In an embodiment of the present invention, after obtaining the exception log corresponding to the application when an exception of the application is detected, the method further includes:

[0011] If there is target function information corresponding to the exception function information in the hash table and the exception function information is not in a preset normal table, determine the exception corresponding to the exception function information as an abnormal service of the application;

[0012] Upload the exception log corresponding to the abnormal service to the backend server;

[0013] and / or, process the abnormal service.

[0014] In an embodiment of the present invention, when the application is running and executes the custom message sending function, call the original message sending function according to the memory address in the custom message sending function, so as to call the target function to be called by the application according to the original message sending function, including:

[0015] Obtain the memory address of the original message sending function from the dynamic link library of the programming language;

[0016] Create a custom message sending function; the custom message sending function at least includes the memory address of the original message sending function;

[0017] When the application is running and executes the custom message sending function, intercept the original message sending function and replace the original message sending function with the custom message sending function;

[0018] Call the original message sending function according to the memory address in the custom message sending function, so as to call the target function to be called by the application according to the original message sending function.

[0019] In an embodiment of the present invention, after determining that the exception corresponding to the exception function information is a normal service of the application program if there is target function information corresponding to the exception function information in the hash table and the exception function information is in a preset normal table, the method further includes:

[0020] Removing the target function information corresponding to the normal service in the hash table.

[0021] In an embodiment of the present invention, when the application program is running and executing the custom message sending function, after calling the original message sending function according to the memory address in the custom message sending function to call and execute the target function corresponding to the service of the application program according to the original message sending function, the method further includes:

[0022] After the target function call ends, removing the target function information corresponding to the target function in the hash table.

[0023] In an embodiment of the present invention, after detecting an exception in the application program and obtaining the exception log corresponding to the application program, the method further includes:

[0024] Performing a symbolic processing on the exception log to obtain the symbolic information corresponding to the exception; the symbolic information includes exception function information.

[0025] In an embodiment of the present invention, the programming language at least includes Objective-C, and the original message sending function is the objc_msgSend function provided by Objective-C.

[0026] In a second aspect of the implementation of the present invention, there is also provided an application program log processing device. The application program calls a function provided by the programming language according to an original message sending function provided by the programming language for developing the application program; the original message sending function is replaced with a custom message sending function, and the custom message sending function at least includes the memory address and processing logic of the original message sending function. The device includes:

[0027] An original message function call module, configured to call the original message sending function according to the memory address in the custom message sending function when the application program is running and executing the custom message sending function, so as to call and execute the target function corresponding to the service of the application program according to the original message sending function;

[0028] A target function information acquisition module, configured to acquire the target function information of the target function according to the processing logic in the custom message sending function and save it in a preset hash table;

[0029] An exception log acquisition module, configured to acquire an exception log corresponding to the application when it is detected that the application has an exception; the exception log includes exception function information of an exception function corresponding to the exception.

[0030] A service determination module, configured to, if there is target function information corresponding to the exception function information in the hash table and the exception function information is in a preset normal table, determine the exception corresponding to the exception function information as a normal service of the application; the exception log corresponding to the normal service is prohibited from being uploaded to the backend server.

[0031] In another aspect of the implementation of the present invention, there is also provided a computer-readable storage medium, in which instructions are stored, and when it runs on a computer, it causes the computer to execute any one of the above application program log processing methods.

[0032] In another aspect of the implementation of the present invention, there is also provided a computer program product containing instructions, and when it runs on a computer, it causes the computer to execute any one of the above application program log processing methods.

[0033] Compared with the related art, the embodiments of the present invention have at least the following advantages:

[0034] In an embodiment of the present invention, an application program calls a function provided by a programming language according to an original message sending function provided for the programming language used to develop the application program. Moreover, the original message sending function is replaced with a custom message sending function, and the custom message sending function may at least include the memory address and processing logic of the original message sending function. In this way, when the application program runs and executes the custom message sending function, the original message sending function can be called according to the memory address in the custom message sending function, and thus the target function corresponding to the business of the application program can be called according to the original message sending function to complete the business. The target function information of the target function is obtained according to the processing logic in the custom message sending function and saved in a preset hash table. Then, when it is detected that the application program has an exception, the exception log corresponding to the application program can be obtained. Among them, the exception log may include the exception function information of the exception function corresponding to the exception. If there is target function information corresponding to the exception function information in the hash table and the exception function information is in a preset normal table, the exception corresponding to the exception function information can be determined as a normal business of the application program, and the exception log corresponding to the normal business is prohibited from being uploaded to the backend server. Then, only the exception log corresponding to the abnormal business will be retained on the backend server and there will be no exception log corresponding to the normal business. Therefore, the data volume of the exception log is reduced, the progress of developers in querying problems existing in the application program and the judgment efficiency are improved, and further the efficiency of locating problems existing in the application program is improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art.

[0036] Figure 1 It is a flowchart of the steps of a method for processing application program logs provided in an embodiment of the present invention;

[0037] Figure 2 It is a flowchart of a solution for filtering abnormal log reporting based on runtime technology provided in an embodiment of the present invention;

[0038] Figure 3 It is a structural block diagram of an apparatus for processing application program logs provided in an embodiment of the present invention;

[0039] Figure 4 It is a structural block diagram of an electronic device provided in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0040] The following will describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention.

[0041] During the actual use of the application, some exception logs are caused by the normal business of the application. However, the backend server reports all exception logs and cannot filter out the exception logs caused by normal business. For example:

[0042] 1) The system (such as the iOS system) needs to force the App to restart in order to update some new functions of the App. Therefore, an abnormal crash is usually deliberately designed to force the App to restart. However, although this deliberately designed abnormal crash belongs to the normal business of the application, the abnormal crash caused by this normal business will still be monitored by the system and reported to the backend server.

[0043] 2) Some abnormal lags caused by the normal business of the application. For example, when the user uses the login function or payment function of a third-party App such as a chat application or a social application in the App, the App usually pauses briefly when invoking the third-party App. The business process of this normal business with a brief pause will still be monitored by the system for lag and reported to the backend server.

[0044] It can be seen that reporting the exception logs caused by the normal business deliberately designed by developers to the backend server will affect the progress and judgment of developers in querying problems, and seriously affect the efficiency of locating problems.

[0045] In view of the above problems, the embodiment of the present invention proposes a solution for filtering exception logs of an application based on runtime. Specifically, when the application is running, the exception logs caused by normal business will be filtered in advance, so that the exception logs corresponding to normal business cannot be uploaded to the backend server, ensuring that unnecessary information confusion and other impacts are not caused to developers, and thus improving the efficiency of locating problems existing in the application.

[0046] Referring to Figure 1 , which is a flowchart of the steps of a method for processing application logs provided in the embodiment of the present invention. As Figure 1 shown, the application invokes a function provided by the programming language according to an original message sending function provided according to the programming language for developing the application; the original message sending function is replaced with a custom message sending function, and the custom message sending function at least includes the memory address and processing logic of the original message sending function. The method may specifically include the following steps:

[0047] Step 101, when the application is running and the custom message sending function is executed, call the original message sending function according to the memory address in the custom message sending function, so as to call and execute the target function corresponding to the business of the application according to the original message sending function.

[0048] Step 102: Obtain the target function information of the target function according to the processing logic in the custom message sending function, and save it in a preset hash table.

[0049] In an embodiment of the present invention, the programming language for developing an application may at least include Objective-C, and the original message sending function may be the objc_msgSend function provided by the programming language Objective-C.

[0050] Specifically, the objc_msgSend function is a core function in the runtime system of the programming language Objective-C and is used to implement the message sending mechanism. In the programming language Objective-C, method (function) calls are actually implemented by sending messages. The objc_msgSend function is responsible for parsing messages and calling the corresponding implementation. The objc_msgSend function is the basis for the dynamic features of the programming language Objective-C, enabling the dynamic modification of the class structure and behavior during the runtime of the application, and implementing functions such as function replacement and message forwarding. When calling a function in the code of the programming language Objective-C, the compiler will convert it into a call to objc_msgSend, passing in the receiver (i.e., the target object of the message sending), the selector (i.e., the function name used to identify the function to be called), and the parameters passed to the method. The objc_msgSend function will look for the implementation of the receiver class (e.g., the class of object). If found, it will call the corresponding implementation; if not found, it will perform dynamic lookup, such as looking for the superclass or calling functions like forwardInvocation.

[0051] In an embodiment of the present invention, the original message sending function provided by the programming language Objective-C in the application, that is, the objc_msgSend function, is replaced with a custom message sending function. Specifically, the custom message sending function may at least include the memory address and processing logic of the objc_msgSend function. Specifically, based on the content address, the custom message sending function can call the objc_msgSend function provided by the programming language Objective-C, thereby implementing the message sending mechanism that the objc_msgSend function can achieve, so as to obtain the functions that the application needs to call when performing business during runtime; based on the processing logic, after the custom message sending function calls the objc_msgSend function based on the memory address, the custom message sending function can filter out the exception logs caused by the normal business of the application, thereby avoiding reporting the exception logs caused by the normal business to the backend server.

[0052] For example, when the iOS system is running (Runtime), it is a core concept in the iOS system and mainly involves the dynamic features of the programming language Objective-C. In the programming language Objective-C, the running iOS system provides the ability to dynamically query classes, methods, properties, and protocols during the runtime of an application. This means that during the runtime of an application, it is possible to dynamically obtain class information, send messages to objects, and even modify the structure and behavior of classes, etc.

[0053] The running iOS system provides the following functions: 1. Dynamic message passing: Function calls in the programming language Objective-C are actually achieved by sending messages, and the running iOS system is responsible for parsing the messages and calling the corresponding implementations. 2. Dynamic query of class information: It is possible to query the inheritance relationship of classes, method lists, property lists, etc. 3. Dynamically adding methods and properties: It is possible to dynamically add methods and properties to classes during runtime. 4. Dynamically replacing method implementations: It is possible to replace the method implementations of classes for implementing AOP (Aspect Oriented Programming) and dynamic proxies.

[0054] Among them, the function information can at least include the function name corresponding to the function, and based on the function name, the corresponding function can be uniquely located. In the embodiments of the present invention, when the application is running (Runtime) and is about to execute the objc_msgSend function, a custom message sending function is used to replace the objc_msgSend function, so that the objc_msgSend function can be called according to the memory address in the custom message sending function, and the target function corresponding to the current business of the application is called according to the objc_msgSend function. Then, the target function information of the target function is obtained according to the processing logic in the custom message sending function. Then, an identifier can be created based on the target function information passed in by the objc_msgSend function and stored in the global preset hash table. When storing in the preset hash table, the key can be the function name and the value can be the identifier, that is, key: identifier; value: function name.

[0055] It should be noted that the hash table can be dynamically adjusted according to the actual situation of the application. Exemplarily, the embodiments of the present invention can monitor the performance information of the hash table in real time, including the number of identifiers in the hash table, the time corresponding to the identifiers, the business type (such as business with high real-time requirements, business with low real-time requirements), and the application type (such as Web application, mobile application, desktop application, etc.) and other performance information, so that the hash table can be dynamically adjusted according to the performance information, enabling the hash table to adapt to different application scenarios and requirements. For example, when the number of meta-identifiers in the hash table exceeds the preset threshold, an expansion operation can be performed on the hash table.

[0056] Step 103: When it is detected that the application has an exception, obtain the exception log corresponding to the application; the exception log includes the exception function information of the exception function corresponding to the exception.

[0057] Step 104: If there is target function information corresponding to the exception function information in the hash table and the exception function information is in the preset normal table, then determine the exception corresponding to the exception function information as the normal business of the application; the exception log corresponding to the normal business is prohibited from being uploaded to the backend server.

[0058] In specific implementation, during the process of an application running and executing business, exceptions sometimes occur, such as crashes or freezes. The exceptions will be monitored and captured by the iOS system and exception logs will be generated. Among them, the exception log can include the exception function information of the exception function corresponding to the exception, such as the exception function name, etc.

[0059] Among them, the function information stored in the preset normal table is deliberately designed by developers and is the function information corresponding to the functions that execute normal business, which can include function names, etc.

[0060] In the embodiment of the present invention, when it is detected that an application has an exception, the exception log corresponding to the application is obtained. If there is target function information corresponding to the exception function information in the hash table and the exception function information is in the preset normal table, it indicates that although an exception of the application is detected, this exception is actually an exception deliberately designed by developers. For example, forced restart for update, third-party login jump, etc. are actually the normal business of the application. Then, the exception corresponding to the exception function information can be determined as the normal business of the application. In addition, in the embodiment of the present invention, the exception log determined to be corresponding to the normal business will be prohibited from being uploaded to the backend server, reducing the amount of exception log data that needs to be uploaded to the backend server. Since the amount of exception log data is reduced, the progress of developers querying problems existing in the application and the judgment efficiency are also improved, thereby improving the efficiency of locating problems existing in the application.

[0061] In the above application log processing method, the application calls a function provided by the programming language using the original message sending function provided according to the programming language for developing the application. Moreover, the original message sending function is replaced with a custom message sending function, which can at least include the memory address and processing logic of the original message sending function. In this way, when the application is running and the custom message sending function is executed, the original message sending function can be called according to the memory address in the custom message sending function, so that the target function corresponding to the business of the application can be called according to the original message sending function to complete the business. The target function information of the target function is obtained according to the processing logic in the custom message sending function and saved in a preset hash table. Then, when an exception occurs in the application is detected, the exception log corresponding to the application can be obtained. Among them, the exception log can include the exception function information of the exception function corresponding to the exception. If there is target function information corresponding to the exception function information in the hash table and the exception function information is in the preset normal table, the exception corresponding to the exception function information can be determined as the normal business of the application, and the exception log corresponding to the normal business is prohibited from being uploaded to the backend server. Then, only the exception log corresponding to the abnormal business will be retained on the backend server and there will be no exception log corresponding to the normal business, thus reducing the data volume of the exception log, improving the progress of developers in querying problems existing in the application and the judgment efficiency, and further improving the efficiency of locating problems existing in the application.

[0062] In an embodiment of the present invention, after detecting that the application has an exception and obtaining the exception log corresponding to the application, the method may further include:

[0063] If there is target function information corresponding to the exception function information in the hash table and the exception function information is not in the preset normal table, the exception corresponding to the exception function information is determined as the abnormal business of the application;

[0064] Upload the exception log corresponding to the abnormal business to the backend server;

[0065] And / or, process the abnormal business.

[0066] In an embodiment of the present invention, if there is target function information corresponding to the exception function information in the hash table and the exception function information is not in the preset normal table, it indicates that it is an exception of the application. Then, the exception corresponding to the exception function information can be determined as the abnormal business of the application. In addition, in an embodiment of the present invention, the exception log determined to be an abnormal business will be uploaded to the backend server, or the abnormal business will be directly processed, so as to ensure the normal operation of the application.

[0067] In an embodiment of the present invention, when the application is running and the custom message sending function is executed, the original message sending function is called according to the memory address in the custom message sending function, so as to call the target function to be called by the application according to the original message sending function, which may include:

[0068] Obtain the memory address of the original message sending function from the dynamic link library of the programming language;

[0069] Create a custom message sending function; at least the memory address of the original message sending function is included in the custom message sending function;

[0070] When the application is running and the custom message sending function is executed, intercept the original message sending function and replace the original message sending function with the custom message sending function;

[0071] Call the original message sending function according to the memory address in the custom message sending function, so as to call the target function to be called by the application according to the original message sending function.

[0072] In an embodiment of the present invention, a hook is deployed in the application. Specifically, the hook is closely related to the Runtime. The Runtime iOS system provides the ability to dynamically query classes, methods, properties, and protocols at runtime. The hook takes advantage of these features to change its behavior or obtain its internal information by modifying or intercepting certain functions, methods, or system calls. In iOS development, the hook technology usually involves using Runtime APIs (Application Programming Interfaces), such as objc_msgSend, class_replaceMethod, method_exchangeImplementations and other APIs (core functions), to implement functions such as method replacement and message forwarding. Through these APIs, developers can dynamically modify the structure and behavior of classes when the application is running to implement the hook function. Therefore, the hook is implemented based on the dynamic features provided by the Runtime iOS system, and the Runtime iOS system provides underlying support for the hook technology.

[0073] In an embodiment of the present invention, when an application is running (Runtime) and about to execute the objc_msgSend function, the objc_msgSend function can be intercepted through hook, and the memory address of objc_msgSend can be obtained using the dynamic link library of the programming language Objective-C (such as libdlsym), so that the original message sending function can still be called after the hook. Then, a custom message sending function including the memory address of objc_msgSend is created, and the objc_msgSend function is replaced with the custom message sending function. Thus, the objc_msgSend function can be called according to the memory address in the custom message sending function, and the target function corresponding to the current business of the application can be called and executed according to the call of the objc_msgSend function. Then, the target function information of the target function is obtained according to the processing logic in the custom message sending function.

[0074] In an embodiment of the present invention, after determining that the exception corresponding to the exception function information is the normal business of the application if there is target function information corresponding to the exception function information in the hash table and the exception function information is in the preset normal table, the method further includes:

[0075] Removing the target function information corresponding to the normal business in the hash table.

[0076] In an embodiment of the present invention, if it is found in the hash table that there is target function information corresponding to the exception function information and the exception function information is in the preset normal table, it means that although an exception in the application is monitored, this exception is actually an exception deliberately designed by the developer. Then, the exception corresponding to the exception function information can be determined as the normal business of the application. At this time, the target function information corresponding to the normal business can be deleted from the hash table, thereby releasing the resources that do not need to be occupied and ensuring the running efficiency of the application.

[0077] In an embodiment of the present invention, when the application is running and executing the custom message sending function, after calling the original message sending function according to the memory address in the custom message sending function to call and execute the target function corresponding to the business of the application according to the call of the original message sending function, the method further includes:

[0078] After the call of the target function ends, removing the target function information corresponding to the target function in the hash table.

[0079] In an embodiment of the present invention, after the call of the target function of the application program ends, it indicates that the application program has completed the processing of the current service based on the target function. At this time, the target function information corresponding to the target function in the hash table can be removed, thereby releasing the resources that do not need to be occupied and ensuring the running efficiency of the application program.

[0080] In an embodiment of the present invention, when it is detected that the application program has an exception, after obtaining the exception log corresponding to the application program, the method further includes:

[0081] Perform a symbolic processing on the exception log to obtain the symbolic information corresponding to the exception; the symbolic information includes exception function information.

[0082] Among them, the debugger Symbols refers to the.dSYM file with the same name generated in the same-level directory of the compiled.app after the Xcode project of the application program is compiled. The.dSYM file is a directory that contains a hexadecimal intermediate file storing function address mapping information in the subdirectory. All Debug symbols (including file names, function names, corresponding line numbers in the source code, etc.) are in the.dSYM file, so it is also called the debug symbol information file. The symbol table is used to symbolize the crash log. There are some hexadecimal memory addresses (including start address and end address) in the crashlog, etc. Through the symbol table, the corresponding method names that can be intuitively seen can be found.

[0083] In a specific implementation, the symbol table is a mapping table of memory addresses to function names, file names, and line numbers. In a specific example, the symbol table elements can be as follows:

[0084] <Start address><End address><Function>[<File name:Line number>]

[0085] In an embodiment of the present invention, after obtaining the exception log, symbolic processing can be performed on the exception log. For example, under the iOS system, the iOS symbolic processing can be performed on the exception log, so as to obtain the symbolic information corresponding to the exception log. Among them, the symbolic information includes exception function information. Specifically, iOS symbolic processing mainly refers to the process of converting the exception log under iOS or Mac OS (usually represented by hexadecimal symbols) into human-readable symbols. In iOS development, symbolic processing is usually used to convert the memory addresses in the exception log into the corresponding function names and file names, so as to facilitate developers to locate and solve problems. The symbolic processing process usually involves using the debug symbol information file (.dSYM file) to convert the hexadecimal address into the position information in the source code (such as line number).

[0086] To enable those skilled in the art to better understand the embodiments of the present invention, specific examples are used for illustration below.

[0087] To implement the hook of the objc_msgSend function (the original message sending function) and attach an identifier named after function information such as the function name at the start and end of each function, and to determine whether the identifier exists when an exception in the application is detected, so as to determine whether the exception occurs in a specific function (i.e., whether it occurs in the functions in the preset normal table), refer to Figure 2 , which is a flowchart of a solution for filtering abnormal log reporting based on runtime technology provided in the embodiments of the present invention, and can be carried out according to the following detailed steps:

[0088] 1. Obtain the memory address of the original objc_msgSend function: Use a dynamic link library (such as libdlsym) to obtain the memory address of objc_msgSend, so that the original objc_msgSend function can still be called after the hook.

[0089] 2. Create a custom objc_msgSend function (custom message sending function): Write a new function, namely the custom message sending function, which will be used as a replacement for the objc_msgSend function and is used for the logic before calling the original objc_msgSend function.

[0090] 3. Save the memory address of the original objc_msgSend function: In the custom objc_msgSend function, save the memory address of the original objc_msgSend function so that the original objc_msgSend function can be called when needed.

[0091] 4. Call the original objc_msgSend function: In the custom objc_msgSend function, call the saved memory address of the original objc_msgSend to perform the actual objc_msgSend call.

[0092] 5. Attach an identifier: When the custom objc_msgSend function starts to execute, an identifier can be created according to the function name passed to the original objc_msgSend function by the custom objc_msgSend function and stored in a global hash table, where the key is the function name and the value is the identifier.

[0093] 6. Remove the identifier: When the original objc_msgSend function or the custom objc_msgSend function ends, remove the corresponding identifier from the hash table according to the function name.

[0094] 7. Anomaly Detection: When the application detects an anomaly, check if an identifier exists in the hash table. If the identifier exists, it indicates that the anomaly occurred in one of the monitored functions, that is, in a function within the normal table preset by the developer.

[0095] 8. Judging and Filtering Anomalies: If the detected identifier is the function identifier that the developer wants to filter, it means that an anomaly occurred in this function but was actually deliberately designed by the developer. In this case, choose not to report the anomaly and remove the identifier from the hash table.

[0096] 9. Anomaly Handling: For anomalies that are not filtered, they can be reported or other anomaly handling processes can be carried out.

[0097] Through the above steps, the embodiments of the present invention can effectively monitor the functions (methods / selectors) called by the original objc_msgSend, and determine whether an anomaly occurs in a specific function when an anomaly occurs, thereby achieving the filtering and management of anomalies, avoiding the reporting of anomaly logs caused by normal operations, and improving the efficiency of developers.

[0098] In summary, the embodiments of the present invention propose a solution for filtering anomaly log reporting based on runtime technology. Hook the objc_msgSend function, and mark a corresponding identifier in the global hash table at the start and end of each function. This identifier can be named with function names or other function information, and the identifier is removed at the end of the function. When the application detects an anomaly and the function has not ended, check if the identifier exists. If the identifier of the function that the developer wants to filter exists, it means that although an anomaly occurred in this function, it is actually a normal operation deliberately designed by the developer. At this time, choose not to report the anomaly log corresponding to this anomaly and remove the corresponding identifier from the hash table.

[0099] It should be noted that for the method embodiments, for simplicity of description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of the present invention are not limited by the described action sequence, because according to the embodiments of the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential for the embodiments of the present invention.

[0100] Refer to Figure 3, which is a structural block diagram of an application program log processing device provided in an embodiment of the present invention. The application program uses an original message sending function provided according to the programming language for developing the application program to call a function provided by the programming language; the original message sending function is replaced with a custom message sending function, and the custom message sending function at least includes the memory address and processing logic of the original message sending function, as Figure 3 shown, the device may specifically include the following modules:

[0101] The original message function call module 301 is used to, when the application program is running and executing the custom message sending function, call the original message sending function according to the memory address in the custom message sending function, so as to call and execute the target function corresponding to the business of the application program according to the original message sending function call;

[0102] The target function information acquisition module 302 is used to acquire the target function information of the target function according to the processing logic in the custom message sending function and save it in a preset hash table;

[0103] The exception log acquisition module 303 is used to acquire the exception log corresponding to the application program when it is monitored that the application program has an exception; the exception log includes the exception function information of the exception function corresponding to the exception;

[0104] The service determination module 304 is used to, if there is target function information corresponding to the exception function information in the hash table and the exception function information is in a preset normal table, determine the exception corresponding to the exception function information as the normal service of the application program; the exception log corresponding to the normal service is prohibited from being uploaded to the backend server.

[0105] In an embodiment of the present invention, the device further includes: an exception service processing module, which is used for:

[0106] If there is target function information corresponding to the exception function information in the hash table and the exception function information is not in the preset normal table, determine the exception corresponding to the exception function information as the exception service of the application program;

[0107] Upload the exception log corresponding to the exception service to the backend server;

[0108] And / or, process the exception service.

[0109] In an embodiment of the present invention, the original message function call module 301 is used for:

[0110] Obtain the memory address of the original message sending function from the dynamic link library of the programming language;

[0111] Create a custom message sending function; at least include the memory address of the original message sending function in the custom message sending function;

[0112] When the application is running and the custom message sending function is executed, intercept the original message sending function, replace the original message sending function with the custom message sending function, and call the original message sending function according to the memory address in the custom message sending function, so as to call the target function to be called by the application according to the original message sending function.

[0113] In an embodiment of the present invention, the device further includes: a first removal module, configured to:

[0114] Remove the target function information corresponding to the normal service in the hash table.

[0115] In an embodiment of the present invention, the device further includes: a second removal module, configured to:

[0116] After the call of the target function ends, remove the target function information corresponding to the target function in the hash table.

[0117] In an embodiment of the present invention, the device further includes: a symbolization processing module, configured to:

[0118] Perform symbolization processing on the exception log to obtain the symbol information corresponding to the exception; the symbol information includes exception function information.

[0119] In an embodiment of the present invention, the programming language at least includes Objective-C, and the original message sending function is the objc_msgSend function provided by Objective-C.

[0120] In an embodiment of the present invention, an application program calls a function provided by a programming language according to an original message sending function provided according to the programming language of the developed application program. Moreover, the original message sending function is replaced with a custom message sending function, and the custom message sending function may at least include the memory address and processing logic of the original message sending function. Thus, when the application program runs and executes the custom message sending function, the original message sending function can be called according to the memory address in the custom message sending function, and thus the target function corresponding to the service of the application program can be called according to the original message sending function to complete the service. The target function information of the target function is obtained according to the processing logic in the custom message sending function and saved in a preset hash table. Then, when an exception occurs in the application program, the exception log corresponding to the application program can be obtained. Among them, the exception log may include the exception function information of the exception function corresponding to the exception. If there is target function information corresponding to the exception function information in the hash table and the exception function information is in a preset normal table, the exception corresponding to the exception function information can be determined as the normal service of the application program, and the exception log corresponding to the normal service is prohibited from being uploaded to the backend server. Then, only the exception log corresponding to the abnormal service will be retained in the backend server and there will be no exception log corresponding to the normal service. Therefore, the data volume of the exception log is reduced, the progress of developers in querying problems existing in the application program and the judgment efficiency are improved, and further the efficiency of locating problems existing in the application program is improved.

[0121] For the above device embodiment, since it is basically similar to the method embodiment, the description is relatively simple. For related parts, please refer to the partial description of the method embodiment.

[0122] An embodiment of the present invention further provides an electronic device, as Figure 4 shown, including a processor 501, a communication interface 502, a memory 503, and a communication bus 504. Among them, the processor 501, the communication interface 502, and the memory 503 communicate with each other through the communication bus 504.

[0123] The memory 503 is used to store a computer program.

[0124] When the processor 501 executes the program stored in the memory 503, it implements the application program log processing method described in any one of the above embodiments.

[0125] The communication bus mentioned in the above terminal may be a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. The communication bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, only a thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.

[0126] The communication interface is used for communication between the above terminal and other devices.

[0127] The memory may include a Random Access Memory (RAM), or may also include a non-volatile memory, such as at least one disk memory. Optionally, the memory may also be at least one storage device located far from the aforementioned processor.

[0128] The above-mentioned processor may be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it may also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0129] In another embodiment provided by the present invention, there is also provided a computer-readable storage medium storing instructions, which when running on a computer, cause the computer to execute the application program log processing method described in any one of the above embodiments.

[0130] In another embodiment provided by the present invention, there is also provided a computer program product containing instructions, which when running on a computer, cause the computer to execute the application program log processing method described in any one of the above embodiments.

[0131] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that the computer can access or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)), etc.

[0132] It should be noted that in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.

[0133] Each embodiment in this specification is described in a related manner. The same or similar parts between the embodiments can be referred to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiment.

[0134] The above are only the preferred embodiments of the present invention and are not intended to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention are included in the protection scope of the present invention.

Claims

1. A method for processing application logs, characterized in that: The application program calls a function provided by a programming language according to an original message sending function provided by the programming language used to develop the application program; the original message sending function is replaced by a custom message sending function, and the custom message sending function at least includes a memory address and processing logic of the original message sending function. The method includes: When the application is running and the custom message sending function is executed, the original message sending function is called according to the memory address in the custom message sending function, so as to call and execute the target function corresponding to the business of the application according to the original message sending function; Obtaining target function information of the target function according to the processing logic in the custom message sending function, and storing it in a preset hash table; When an exception is detected in the application, an exception log corresponding to the application is obtained; the exception log includes exception function information of the exception function corresponding to the exception; If there is target function information corresponding to the abnormal function information in the hash table, and the abnormal function information is in the preset normal table, the abnormality corresponding to the abnormal function information is determined as the normal business of the application; the abnormal log corresponding to the normal business is prohibited from being uploaded to the back-end server.

2. The method according to claim 1, characterized in that When an exception occurs in the application program, after obtaining an exception log corresponding to the application program, the method further includes: If there is target function information corresponding to the abnormal function information in the hash table, and the abnormal function information is not in the preset normal table, determining the abnormality corresponding to the abnormal function information as an abnormal service of the application; Upload the abnormal log corresponding to the abnormal business to the back-end server; And / or, processing the abnormal business.

3. The method according to claim 1, characterized in that When the application is running and the custom message sending function is executed, the original message sending function is called according to the memory address in the custom message sending function, so as to call the target function to be called by the application according to the original message sending function, including: Obtaining the memory address of the original message sending function from the dynamic link library of the programming language; Creating a custom message sending function; wherein the custom message sending function at least includes the memory address of the original message sending function; When the application is running and the custom message sending function is executed, the original message sending function is intercepted and the original message sending function is replaced with the custom message sending function; The original message sending function is called according to the memory address in the custom message sending function, so as to call the target function to be called by the application according to the original message sending function.

4. The method according to claim 1, characterized in that: If there is target function information corresponding to the abnormal function information in the hash table, and the abnormal function information is in the preset normal table, after determining the abnormality corresponding to the abnormal function information as a normal service of the application, the method further includes: Remove the objective function information corresponding to the normal business in the hash table.

5. The method according to claim 1, characterized in that When the application is running and the custom message sending function is executed, after the original message sending function is called according to the memory address in the custom message sending function to call and execute the target function corresponding to the business of the application according to the original message sending function, the method further includes: After the target function call is completed, the target function information corresponding to the target function in the hash table is removed.

6. The method according to claim 1, characterized in that When an exception occurs in the application program, after obtaining an exception log corresponding to the application program, the method further includes: The exception log is symbolized to obtain symbol information corresponding to the exception; the symbol information includes abnormal function information.

7. The method according to any one of claims 1 to 6, characterized in that: The programming language includes at least Objective-C, and the original message sending function is the objc_msgSend function provided by Objective-C.

8. An application log processing device, characterized in that: The application program calls a function provided by a programming language according to an original message sending function provided by the programming language used to develop the application program; the original message sending function is replaced by a custom message sending function, and the custom message sending function at least includes a memory address and processing logic of the original message sending function. The device includes: An original message function calling module, used for calling the original message sending function according to the memory address in the custom message sending function when the application is running and the custom message sending function is executed, so as to call and execute a target function corresponding to the business of the application according to the original message sending function; An objective function information acquisition module, used to acquire the objective function information of the objective function according to the processing logic in the custom message sending function, and save it in a preset hash table; An exception log acquisition module is used to acquire an exception log corresponding to the application when an exception is detected in the application; the exception log includes exception function information of the exception function corresponding to the exception; A business determination module is used to determine the anomaly corresponding to the abnormal function information as the normal business of the application if there is target function information corresponding to the abnormal function information in the hash table and the abnormal function information is in a preset normal table; the abnormal log corresponding to the normal business is prohibited from being uploaded to the back-end server.

9. An electronic device, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus; Memory, used to store computer programs; A processor, for implementing the method steps described in any one of claims 1 to 7 when executing a program stored in a memory.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.