Code integration method and device, electronic equipment and storage medium

By performing difference comparison on branch codes and illegal operation detection on intermediate code files in a distributed version control system, the code integration security and efficiency issues in the existing technology are solved, and a more efficient and secure code integration process is achieved.

CN120610893APending Publication Date: 2025-09-09YUANQIXIN (SHANDONG) SEMICONDUCTOR TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510665826.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-22
Publication Date
2025-09-09

AI Technical Summary

Technical Problem

The code integration methods of existing distributed version control systems have security and efficiency issues. They cannot effectively prevent externally pushed branch codes from stealing core data or leading to malicious programs. Manual review methods are inefficient and difficult to fully detect potential illegal access.

Method used

By obtaining the branch code and the main code, performing a difference comparison to obtain the difference code, and then compiling the branch code to generate an intermediate code file. Then, based on the difference code, the intermediate code file is checked for illegal operations, and code stubs are inserted for address judgment. Finally, the code is merged after the illegal operation detection and integration test pass.

Benefits of technology

It improves the security of the code integration process, reduces reliance on manual review, improves efficiency, and makes it easier to detect potential illegal access through automated detection, ensuring the accuracy and security of code integration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120610893A_ABST
    Figure CN120610893A_ABST
Patent Text Reader

Abstract

The invention provides a code integration method and device, electronic equipment and a storage medium, and the method comprises the steps: carrying out the difference comparison of a branch code and a trunk code, and obtaining a difference code; compiling the branch code to obtain an intermediate code file, and performing illegal operation detection on the intermediate code file based on the difference code to obtain an illegal operation detection result; performing an integration test on the intermediate code file of which the illegal operation detection result is that the detection is passed to obtain an integration test operation result; and under the condition that the test is passed, combining the branch code and the trunk code to obtain a target code. According to the method, illegal operation detection is carried out on the intermediate code file based on the difference code to obtain the illegal operation detection result, compared with manual review, the efficiency is guaranteed, potential illegal access is found more easily, combination of the branch code and the trunk code is carried out after illegal operation detection is passed and integrated test operation is passed, and the method is more convenient to operate. And the code integration accuracy is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of code integration technology, and in particular to a code integration method, device, electronic device and storage medium. Background Art

[0002] A distributed version control system (DVCS) is a tool for managing project versions. It doesn't rely on a single central server to store all version information. In a DVCS, each developer maintains a complete repository on their local computer, containing all the project's history and version information. These local repositories can communicate with each other and share data, allowing developers to develop, commit, push, and pull locally without relying on a central server. Each node is equal and can independently perform version control operations, improving system reliability and stability. Each node maintains a complete project history, ensuring that even if a node fails or data is lost, data can be restored from other nodes.

[0003] Continuous integration refers to developers frequently integrating their code changes into a shared code repository, typically at least daily, and sometimes even more frequently. After each integration, the system automatically performs a series of operations, including builds and tests, to ensure that the new code changes do not disrupt the entire system. This ensures that issues arising during the integration process are promptly identified and resolved, maintaining the stability and maintainability of the codebase. However, testing the integration results inherently carries certain risks. Code submitted by different users may execute unknown code, access and send sensitive data, or jump to malicious code. Existing distributed version control systems, such as Git, employ an integration security strategy based on permission control. This strategy is characterized by the division of privileges into different groups. High-privilege groups can directly perform integration testing, while lower-privilege groups require review and approval from higher-privilege personnel before they can run tests. This impacts overall operational efficiency, and even manual review processes cannot guarantee the detection of all potential vulnerabilities. Summary of the Invention

[0004] The present invention provides a code integration method, device, electronic device and storage medium, which are used to solve the defects of the code integration method in the prior art.

[0005] The present invention provides a code integration method, comprising the following steps: Obtaining a branch code and a trunk code, performing a difference comparison between the branch code and the trunk code to obtain a difference code; Compiling the branch code to obtain an intermediate code file, and performing illegal operation detection on the intermediate code file based on the difference code to obtain an illegal operation detection result; Performing an integration test on the intermediate code file for which the illegal operation detection result is a passing result, to obtain an integration test running result; When the integration test is run as passed, in response to a merge operation by a code administrator, the branch code and the trunk code are merged to obtain a target code.

[0006] According to a code integration method provided by the present invention, performing illegal operation detection on the intermediate code file based on the difference code to obtain an illegal operation detection result includes: Determine a target intermediate code file corresponding to the difference code in the intermediate code file; In the case where the code in the target intermediate code file is an unconditional jump instruction, saving the jump address corresponding to the unconditional jump instruction to a first register, and inserting a first jump instruction before the unconditional jump instruction, and jumping the first jump instruction to the judgment function; In the case where the code in the target intermediate code file is a conditional jump instruction, a conditional judgment instruction is inserted before the conditional jump instruction, and when the conditional judgment instruction satisfies a preset condition, a jump address corresponding to the conditional jump instruction is saved in a second register, and the conditional judgment instruction is jumped to the judgment function; In a case where the code in the target intermediate code file is a storage instruction, determining a memory access mode corresponding to the storage instruction, saving a memory access address of the memory access mode to a third register, and inserting a second jump instruction before the storage instruction to cause the storage instruction to jump to the judgment function; the memory access mode includes direct addressing, indirect addressing, and register indirect addressing; Determine the illegal operation detection result at the judgment function.

[0007] According to a code integration method provided by the present invention, the illegal operation detection result is determined by the judgment function based on the distance between the target address and each cluster center address, the target address is the operation address in the register corresponding to each instruction type, and the cluster center address is the cluster center of all operation addresses in the register corresponding to each instruction type.

[0008] According to a code integration method provided by the present invention, the instruction types include the unconditional jump instruction, the conditional jump instruction and the store instruction; In the case where the instruction type is the unconditional jump instruction, the target address is the operation address in the first register; In the case where the instruction type is the conditional jump instruction, the target address is the operation address in the second register; In a case where the instruction type is the store instruction, the target address is the operation address in the third register.

[0009] According to a code integration method provided by the present invention, determining the illegal operation detection result at the judgment function includes: If the judgment function determines that the distance between the target address and the addresses of the cluster centers is less than or equal to the cluster range, the illegal operation detection result is determined to be a legal address cluster; the cluster range is the distance between the addresses of the cluster centers and the addresses of the cluster boundaries; When the judgment function determines that the distance between the target address and each cluster center is greater than the cluster range, the illegal operation detection result is determined to be illegal access.

[0010] According to a code integration method provided by the present invention, the method further includes: When the illegal operation detection result is the legal address cluster, updating the address range of each cluster or the center address of each cluster based on the target address; When the illegal operation detection result is the illegal access, the operation address in the register corresponding to each instruction type and the address of the unconditional jump instruction, the conditional jump instruction and the storage instruction in the stack before the jump are output.

[0011] According to a code integration method provided by the present invention, when the judgment function determines that the distance between the target address and the addresses of the cluster centers is less than or equal to the cluster range, determining that the illegal operation detection result is a legal address cluster, further includes: Report the illegal operation detection results to the administrator and submitter; Returning to normal execution of the unconditional jump instruction, the conditional jump execution, and the store instruction.

[0012] According to a code integration method provided by the present invention, the step of obtaining the trunk code includes: Get the original trunk code; Randomly sampling the original trunk code to obtain trunk branch code, and determining the memory access address of the trunk branch code during operation; The memory access addresses are clustered to obtain a clustering result, and the original trunk code is adjusted based on the clustering result to obtain the trunk code.

[0013] The present invention also provides a code integration device, comprising the following units: an acquiring unit, configured to acquire a branch code and a trunk code, and perform a difference comparison between the branch code and the trunk code to obtain a difference code; an illegal operation detection unit, configured to compile the branch code to obtain an intermediate code file, and perform illegal operation detection on the intermediate code file based on the difference code to obtain an illegal operation detection result; An integration test unit is used to perform an integration test on the intermediate code file for which the illegal operation detection result is a passing test, and obtain an integration test running result; The merging unit is used to merge the branch code and the trunk code to obtain the target code in response to the merging operation of the code administrator when the integration test running result is that the test passes.

[0014] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, any of the above-described code integration methods is implemented.

[0015] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which implements any of the above-mentioned code integration methods when executed by a processor.

[0016] The present invention also provides a computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements any one of the above code integration methods.

[0017] The code integration method, device, electronic device, and storage medium provided by the present invention obtain branch code and trunk code, perform a difference comparison between the branch code and trunk code to obtain a difference code; compile the branch code to obtain an intermediate code file, and perform an illegal operation detection on the intermediate code file based on the difference code to obtain an illegal operation detection result; perform an integration test on the intermediate code file for which the illegal operation detection result is a pass to obtain an integration test run result; and when the integration test run result is a pass, responding to a merge operation by a code administrator, merge the branch code and trunk code to obtain a target code. On the one hand, illegal operation detection is added to the distributed version control system to prevent externally pushed branch code from stealing core data or leading to malicious programs, thereby ensuring the security of the continuous code integration process; on the other hand, illegal operation detection is performed on the intermediate code file based on the difference code in an automatic process to obtain an illegal operation detection result. Compared with manual review, it is easier to discover potential illegal access while ensuring efficiency. Moreover, the branch code and trunk code are merged after the illegal operation detection and integration test run pass, thereby improving the accuracy of code integration. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0019] Figure 1 It is a flowchart of the code integration method provided by the present invention.

[0020] Figure 2 This is a schematic diagram of the architecture of the secure integrated distributed version control system provided by the present invention.

[0021] Figure 3 This is a workflow diagram of the distributed version control system provided by the present invention.

[0022] Figure 4 This is a schematic diagram of the illegal operation detection process of the distributed version control system provided by the present invention.

[0023] Figure 5 It is a structural diagram of the code integration device provided by the present invention.

[0024] Figure 6 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION

[0025] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0026] The terms "first," "second," and the like in the present invention are used to distinguish similar objects, and are not used to describe a particular order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and that the objects distinguished by "first," "second," and the like are generally of the same type.

[0027] Figure 1 is a flow chart of the code integration method provided by the present invention, Figure 2 This is a schematic diagram of the architecture of the secure integrated distributed version control system provided by the present invention. Figure 1 、 Figure 2As shown, the method includes step 110 , step 120 , step 130 and step 140 .

[0028] Step 110: Obtain a branch code and a trunk code, perform a difference comparison between the branch code and the trunk code, and obtain a difference code.

[0029] It should be noted that the method provided in the embodiment of the present invention is applied to a distributed version control system.

[0030] Specifically, branch code and trunk code can be obtained, where the branch code refers to the code pushed by external developers, and the trunk code refers to the code in the warehouse of the distributed version control system.

[0031] After obtaining the branch code and the trunk code, the branch code and the trunk code can be compared based on the difference module to obtain a difference code. Here, the difference code is used to reflect the code difference between the branch code and the trunk code.

[0032] Here, the steps to obtain the main code are as follows: First, the original trunk code is obtained and randomly sampled to obtain the trunk branch code, and the memory access address of the trunk branch code during operation is determined.

[0033] The memory access addresses are then clustered to obtain clustering results. Based on the clustering results, the original main code is adjusted to obtain the main code. The goal of clustering is to group similar memory access addresses into the same cluster and dissimilar addresses into different clusters. Clustering memory access addresses can be performed using the DBSCAN (Density-Based Spatial Clustering of Applications with Noise) algorithm or the K-Means algorithm, but this is not specifically limited in this embodiment of the present invention.

[0034] It can be understood that for the original trunk code, random sampling is used to obtain the trunk branch code, and the memory address access of the trunk branch code during operation is determined. The legal address range is determined by the clustering algorithm, and the legal address clustering is continuously maintained and confirmed during the continuous integration process, which improves the accuracy of abnormal address judgment.

[0035] Step 120: compile the branch code to obtain an intermediate code file, and perform illegal operation detection on the intermediate code file based on the difference code to obtain an illegal operation detection result.

[0036] Specifically, the illegal operation detection module can be used to compile the branch code to obtain an intermediate code file, and then perform illegal operation detection on the intermediate code file based on the difference code to obtain an illegal operation detection result. For example, the target intermediate code file corresponding to the difference code in the intermediate code file is first determined, and then illegal operation detection is performed on the judgment function before the unconditional jump instruction, conditional jump instruction, and store instruction in the target intermediate code file to obtain an illegal operation detection result.

[0037] Step 130: Perform integration testing on the intermediate code file that has passed the illegal operation detection result, and obtain an integration test running result; Specifically, based on the test-merged modules, integration testing is performed on the intermediate code files that pass the illegal operation detection result to obtain the integration test run results. Integration testing verifies the correctness and performance of the code results. Integration testing focuses on whether the interactions between multiple modules or components work properly when they are combined. The purpose of integration testing is to ensure that the modules can work together after integration and to identify and fix any problems that may arise when modules interact with each other.

[0038] Step 140 : When the integration test is passed, in response to a merge operation by a code administrator, the branch code and the trunk code are merged to obtain a target code.

[0039] Specifically, when the integration test is passed, the integration test merge module responds to the merge operation of the code administrator and merges the branch code with the trunk code to obtain the target code, which is the final integration code.

[0040] The method provided by the embodiment of the present invention obtains branch code and trunk code, performs a difference comparison between the branch code and the trunk code to obtain a difference code; compiles the branch code to obtain an intermediate code file, and performs an illegal operation detection on the intermediate code file based on the difference code to obtain an illegal operation detection result; performs an integration test on the intermediate code file whose illegal operation detection result is a pass to obtain an integration test run result; when the integration test run result is a pass, responds to a merge operation by a code administrator to merge the branch code and the trunk code to obtain a target code. On the one hand, illegal operation detection is added to the distributed version control system to prevent externally pushed branch code from stealing core data or leading to malicious programs, thereby ensuring the security of the continuous code integration process; on the other hand, illegal operation detection is performed on the intermediate code file based on the difference code in an automatic process to obtain an illegal operation detection result. Compared with manual review, it is easier to discover potential illegal access while ensuring efficiency. In addition, the branch code and the trunk code are merged after the illegal operation detection and the integration test are passed, thereby improving the accuracy of code integration.

[0041] Based on the above embodiment, in step 120, performing illegal operation detection on the intermediate code file based on the difference code to obtain an illegal operation detection result includes: Step 121, determining a target intermediate code file corresponding to the difference code in the intermediate code file; Step 122: If the code in the target intermediate code file is an unconditional jump instruction, save the jump address corresponding to the unconditional jump instruction to a first register, insert a first jump instruction before the unconditional jump instruction, and jump the first jump instruction to the judgment function; Step 123: If the code in the target intermediate code file is a conditional jump instruction, insert a conditional judgment instruction before the conditional jump instruction, and if the conditional judgment instruction satisfies a preset condition, save the jump address corresponding to the conditional jump instruction to a second register, and jump the conditional judgment instruction to the judgment function; Step 124: If the code in the target intermediate code file is a storage instruction, determine a memory access mode corresponding to the storage instruction, save the memory access address of the memory access mode to a third register, and insert a second jump instruction before the storage instruction to cause the storage instruction to jump to the judgment function; the memory access mode includes direct addressing, indirect addressing, and register indirect addressing; Step 125: Determine the illegal operation detection result at the judgment function.

[0042] Specifically, determine the target intermediate code file corresponding to the difference code in the intermediate code file. Then, in the case that the code in the target intermediate code file is an unconditional jump instruction, save the jump address corresponding to the unconditional jump instruction to the first register, and insert the first jump instruction before the unconditional jump instruction, and jump the first jump instruction to the judgment function. Among them, the unconditional jump instruction is used to transfer the control flow of the program directly to the specified target address without performing any conditional check. The purpose of this operation is to let the program execute the judgment function before executing the original unconditional jump instruction. In the judgment function, whether to execute the original unconditional jump instruction is determined based on the conditions.

[0043] If the code in the target intermediate code file contains a conditional jump instruction, a conditional judgment instruction is inserted before the conditional jump instruction. If the conditional judgment instruction satisfies a preset condition, the jump address corresponding to the conditional jump instruction is saved in a second register, and the conditional judgment instruction is then jumped to the judgment function. This operation is intended to cause the program to execute the judgment function before executing the original conditional jump instruction. In the judgment function, the original conditional jump instruction is determined based on the condition.

[0044] If the code in the target intermediate code file is a store instruction, a memory access method corresponding to the store instruction is determined, and the memory access address of the memory access method is saved in a third register. A second jump instruction is inserted before the store instruction to cause the store instruction to jump to a determination function. In the determination function, whether to execute the original store instruction is determined based on a condition.

[0045] Memory access methods include direct addressing, indirect addressing, and register indirect addressing. Direct addressing refers to the memory address of the operand directly given in the instruction. Indirect addressing refers to the address given in the instruction not being the direct address of the operand, but rather the address of the operand address (i.e., a pointer). An additional memory access is required to obtain the actual operand address. Register indirect addressing refers to the address given in the instruction being accessed indirectly through a third register, which stores the actual operand address.

[0046] Finally, the illegal operation detection result at the judgment function is determined. It can be understood that in the automatic process, based on differential code analysis, insertion calculation and address analysis function jump address, dynamic instrumentation is used to obtain accurate access addresses. Compared with manual review, it is easier to detect potential illegal access while ensuring efficiency.

[0047] The method provided by the embodiment of the present invention obtains difference code by analyzing the pushed branch code, performs code instrumentation on the compiled intermediate code file, and relies on the execution of the instrumented code to discover address abnormal values ​​in the difference code segment, thereby improving the security of subsequent code integration.

[0048] Based on the above embodiment, the illegal operation detection result is determined by the judgment function based on the distance between the target address and each cluster center address, the target address is the operation address in the register corresponding to each instruction type, and the cluster center address is the cluster center of all operation addresses in the register corresponding to each instruction type.

[0049] Specifically, the illegal operation detection result is determined by a judgment function based on the distance between the target address and each cluster center address. The target address is the operation address in the register corresponding to each instruction type, and the cluster center address is the cluster center of all operation addresses in the register corresponding to each instruction type.

[0050] Here, the various instruction types include an unconditional jump instruction, a conditional jump instruction, and a store instruction.

[0051] Correspondingly, when each instruction type is an unconditional jump instruction, the target address is the operation address in the first register.

[0052] In the case where the instruction type is a conditional jump instruction, the target address is the operation address in the second register.

[0053] When the instruction type is a store instruction, the target address is the operation address in the third register.

[0054] The method provided by the embodiments of the present invention addresses the drawbacks of traditional illegal operation detection methods based on fixed rules, which can lead to false positives due to overly simple or overly strict rules. The illegal operation detection result is determined by a judgment function based on the distance between the target address and the addresses of each cluster center, which can more accurately determine the legitimacy of the operation. Only when the distance between the target address and the cluster center exceeds a certain threshold is the operation considered illegal. This method can effectively reduce false positives and improve the accuracy of illegal operation detection.

[0055] Based on the above embodiment, step 125 includes: Step 1251: If the judgment function determines that the distance between the target address and the addresses of the cluster centers is less than or equal to the cluster range, determining that the illegal operation detection result is a legal address cluster; the cluster range is the distance between the addresses of the cluster centers and the addresses of the cluster boundaries; Step 1252: When the judgment function determines that the distance between the target address and each cluster center is greater than the cluster range, determine that the illegal operation detection result is an illegal access.

[0056] Specifically, when the judgment function determines that the distance between the target address and the addresses of the cluster centers is less than or equal to the cluster range, the illegal operation detection result is determined to be a legal address cluster.

[0057] Among them, the clustering range is the distance between each cluster center address and each cluster boundary address. For example, when each instruction type is an unconditional jump instruction, the target address is the operation address in the first register, and the clustering range is the distance between the cluster center of all operation addresses in the first register and the boundary address of all operation addresses in the first register.

[0058] When each instruction type is a conditional jump instruction, the target address is the operation address in the second register. For example, when each instruction type is a conditional jump instruction, the target address is the operation address in the second register, and the clustering range is the distance between the cluster center of all operation addresses in the second register and the boundary address of all operation addresses in the second register.

[0059] When each instruction type is a store instruction, the target address is the operation address in the third register. For example, when each instruction type is a store instruction, the target address is the operation address in the third register, and the clustering range is the distance between the cluster center of all operation addresses in the third register and the boundary address of all operation addresses in the third register.

[0060] If the judgment function determines that the distance between the target address and each cluster center is greater than the cluster range, the illegal operation detection result is determined to be illegal access. That is, the target address does not belong to any judgment address class and is considered to have been illegally accessed.

[0061] Based on the above embodiment, the method further includes: When the illegal operation detection result is the legal address cluster, updating the address range of each cluster or the center address of each cluster based on the target address; When the illegal operation detection result is the illegal access, the operation address in the register corresponding to each instruction type and the address of the unconditional jump instruction, the conditional jump instruction and the storage instruction in the stack before the jump are output.

[0062] Specifically, if the illegal operation detection result indicates a valid address cluster, the address range of each cluster or the center address of each cluster is updated based on the target address. This can be achieved by recalculating the center address of each cluster, for example, by adding the target address to the cluster and then recalculating the cluster center address. The address range of the cluster is also updated, for example, by expanding the address range to include the target address.

[0063] When the illegal operation detection result is illegal access, the operation address in the register corresponding to each instruction type is output, as well as the address before the unconditional jump instruction, conditional jump instruction and storage instruction in the stack are sent to jump.

[0064] The stack is used to store and manage various runtime information. It is a last-in, first-out (LIFO) data structure. Because certain register values ​​may need to be saved and restored during function calls, these register values ​​are stored in the stack frame.

[0065] Based on the above embodiment, step 1251 further includes: Step 1251-1: reporting the illegal operation detection result to the administrator and the submitter; Step 1251-2, returning to normal execution of the unconditional jump instruction, the conditional jump execution and the store instruction.

[0066] Specifically, when the judgment function determines that the distance between the target address and each cluster center address is less than or equal to the cluster range, after determining that the illegal operation detection result is a legal address cluster, the illegal operation detection result can be reported to the administrator and the submitter.

[0067] Then it returns to normal execution of unconditional jump instructions, conditional jump execution and storage instructions. This mechanism can ensure the normal operation of the system and avoid program interruption or abnormal behavior caused by false alarms.

[0068] Based on any of the above embodiments, Figure 3 This is a workflow diagram of the distributed version control system provided by the present invention, such as Figure 3 As shown, the method includes: Step S1, initialize the environment establishment, prepare test cases and data, run the trunk code, randomly sample the trunk code, obtain the trunk branch code, and determine the memory access address during the trunk branch code running process, and cluster the memory access address.

[0069] In step S2, the external developer develops in the copied repository, submits his branch code, and pushes it to the main repository. The main repository compares the submitted branch code with the main repository to obtain differential code.

[0070] Step S3: Based on the difference code, the illegal operation detection module compiles the branch code, inserts the code, and determines whether the illegal operation detection passes. If it passes, the test program continues to run; otherwise, jump to S6.

[0071] Step S4: Perform integration testing on the intermediate code files that have passed the illegal operation detection result to determine whether the program execution result is correct. If the result is incorrect, the task is terminated.

[0072] Step S5: The administrator reviews the code and merges the branch code with the trunk code.

[0073] Step S6: If the illegal operation detection fails, submit illegal operation information to external developers and administrators, including the address of the illegal access and the location of the code.

[0074] Based on any of the above embodiments, Figure 4 This is a schematic diagram of the illegal operation detection process of the distributed version control system provided by the present invention, such as Figure 4 As shown, the method includes: S1, first compile the branch code to get the intermediate code file; S2, determining a target intermediate code file corresponding to the difference code in the intermediate code file; S3 performs code stubbing for specific operations in the target intermediate code file. Code stubbing is performed for jump and store instructions in the intermediate representation. For unconditional jump instructions, the jump address is saved in the corresponding register and a jump to the judgment function is inserted before the jump. For conditional jump instructions, a conditional judgment instruction is inserted. If the condition is met, the jump address is saved and a jump to the judgment function is performed. For store instructions, the memory access address is calculated based on the memory access method and saved in the register. The call then jumps to the judgment function.

[0075] The judgment function reads the saved operation address, traverses all legal address clusters, and determines whether the distance between the target address and the cluster center is greater than the cluster range. If the distance between the target address and the cluster center is less than or equal to the cluster range, the operation address is considered to belong to the legal address cluster. If the address does not belong to any judgment address class, that is, the distance between the target address and the cluster center is greater than the cluster range, the address is considered to have been illegally accessed.

[0076] S4: Execute the compiled code after the code is instrumented to determine whether an illegal memory access is encountered. If not, the memory access address is used to update the cluster. If an illegal memory access is encountered, the address saved in the register is output, and the address before the function call is read from the stack.

[0077] The code integration device provided by the present invention is described below. The code integration device described below and the code integration method described above can be referenced to each other.

[0078] Based on any of the above embodiments, the present invention provides a code integration device, Figure 5 This is a schematic diagram of the structure of the code integration device provided by the present invention. Figure 5 As shown, the device includes: An acquiring unit 510 is configured to acquire a branch code and a trunk code, and compare the branch code with the trunk code to obtain a difference code. an illegal operation detection unit 520, configured to compile the branch code to obtain an intermediate code file, and perform illegal operation detection on the intermediate code file based on the difference code to obtain an illegal operation detection result; An integration test unit 530 is configured to perform an integration test on the intermediate code file for which the illegal operation detection result is "passed" to obtain an integration test running result; The merging unit 540 is configured to merge the branch code and the trunk code to obtain a target code in response to a merging operation by a code administrator when the integration test running result is that the test passes.

[0079] The device provided by the embodiment of the present invention obtains branch code and trunk code, performs a difference comparison between the branch code and the trunk code to obtain a difference code; compiles the branch code to obtain an intermediate code file, and performs an illegal operation detection on the intermediate code file based on the difference code to obtain an illegal operation detection result; performs an integration test on the intermediate code file whose illegal operation detection result is a pass to obtain an integration test run result; when the integration test run result is a pass, in response to a merge operation by a code administrator, merges the branch code and the trunk code to obtain a target code. On the one hand, illegal operation detection is added to the distributed version control system to prevent the externally pushed branch code from stealing core data or leading to malicious programs, thereby ensuring the security of the continuous code integration process; on the other hand, illegal operation detection is performed on the intermediate code file based on the difference code in an automatic process to obtain an illegal operation detection result. Compared with manual review, it is easier to discover potential illegal access while ensuring efficiency. In addition, the branch code and the trunk code are merged after the illegal operation detection and the integration test run are passed, thereby improving the accuracy of code integration.

[0080] Based on any of the above embodiments, the illegal operation detection unit 520 specifically includes: A determining unit, configured to determine a target intermediate code file corresponding to the difference code in the intermediate code file; A first jump unit is configured to, when the code in the target intermediate code file is an unconditional jump instruction, save the jump address corresponding to the unconditional jump instruction to a first register, insert a first jump instruction before the unconditional jump instruction, and jump the first jump instruction to a judgment function; A second jump unit is configured to, when the code in the target intermediate code file is a conditional jump instruction, insert a conditional judgment instruction before the conditional jump instruction, and when the conditional judgment instruction satisfies a preset condition, save a jump address corresponding to the conditional jump instruction to a second register, and jump the conditional judgment instruction to the judgment function; a third jump unit, configured to, when the code in the target intermediate code file is a storage instruction, determine a memory access mode corresponding to the storage instruction, save a memory access address of the memory access mode to a third register, and insert a second jump instruction before the storage instruction to cause the storage instruction to jump to the judgment function; the memory access mode includes direct addressing, indirect addressing, and register indirect addressing; The detection result determination unit is used to determine the illegal operation detection result at the judgment function.

[0081] Based on any of the above embodiments, the illegal operation detection result is determined by the judgment function based on the distance between the target address and each cluster center address, the target address is the operation address in the register corresponding to each instruction type, and the cluster center address is the cluster center of all operation addresses in the register corresponding to each instruction type.

[0082] Based on any of the above embodiments, the instruction types include the unconditional jump instruction, the conditional jump instruction and the store instruction; In the case where the instruction type is the unconditional jump instruction, the target address is the operation address in the first register; In the case where the instruction type is the conditional jump instruction, the target address is the operation address in the second register; In a case where the instruction type is the store instruction, the target address is the operation address in the third register.

[0083] Based on any of the above embodiments, the detection result determining unit is specifically configured to: If the judgment function determines that the distance between the target address and the addresses of the cluster centers is less than or equal to the cluster range, the illegal operation detection result is determined to be a legal address cluster; the cluster range is the distance between the addresses of the cluster centers and the addresses of the cluster boundaries; When the judgment function determines that the distance between the target address and each cluster center is greater than the cluster range, the illegal operation detection result is determined to be illegal access.

[0084] Based on any of the above embodiments, the further embodiment includes an output unit, wherein the output unit is specifically configured to: When the illegal operation detection result is the legal address cluster, updating the address range of each cluster or the center address of each cluster based on the target address; When the illegal operation detection result is the illegal access, the operation address in the register corresponding to each instruction type and the address of the unconditional jump instruction, the conditional jump instruction and the storage instruction in the stack before the jump are output.

[0085] Based on any of the above embodiments, the method further includes a return execution unit, wherein the return execution unit is specifically configured to: Report the illegal operation detection results to the administrator and submitter; Returning to normal execution of the unconditional jump instruction, the conditional jump execution, and the store instruction.

[0086] Based on any of the above embodiments, the system further includes a main code acquisition unit, wherein the main code acquisition unit is specifically configured to: Get the original trunk code; Randomly sampling the original trunk code to obtain trunk branch code, and determining the memory access address of the trunk branch code during operation; The memory access addresses are clustered to obtain a clustering result, and the original trunk code is adjusted based on the clustering result to obtain the trunk code.

[0087] Figure 6 Schematic diagram of the structure of the electronic device provided by the present invention, such as Figure 6 As shown, the electronic device may include: a processor 610, a communication interface 620, a memory 630, and a communication bus 640, wherein the processor 610, the communication interface 620, and the memory 630 communicate with each other via the communication bus 640. The processor 610 may call logic instructions in the memory 630 to execute a code integration method, which includes: obtaining branch code and trunk code, performing a difference comparison between the branch code and the trunk code to obtain a difference code; compiling the branch code to obtain an intermediate code file, and performing an illegal operation detection on the intermediate code file based on the difference code to obtain an illegal operation detection result; performing an integration test on the intermediate code file for which the illegal operation detection result is a passing result to obtain an integration test run result; and if the integration test run result is a passing result, merging the branch code with the trunk code in response to a merge operation by a code administrator to obtain a target code.

[0088] Furthermore, the logic instructions in the aforementioned memory 630 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0089] On the other hand, the present invention also provides a computer program product, which includes a computer program, which can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the code integration method provided by the above methods, which includes: obtaining branch code and trunk code, performing a difference comparison between the branch code and the trunk code to obtain a difference code; compiling the branch code to obtain an intermediate code file, and based on the difference code, performing an illegal operation detection on the intermediate code file to obtain an illegal operation detection result; performing an integration test on the intermediate code file whose illegal operation detection result is a passed test to obtain an integration test running result; when the integration test running result is a passed test, in response to the merge operation of the code administrator, merging the branch code and the trunk code to obtain the target code.

[0090] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to execute the code integration method provided by the above-mentioned methods, the method comprising: obtaining branch code and trunk code, performing a difference comparison between the branch code and the trunk code to obtain a difference code; compiling the branch code to obtain an intermediate code file, and based on the difference code, performing an illegal operation detection on the intermediate code file to obtain an illegal operation detection result; performing an integration test on the intermediate code file whose illegal operation detection result is a passed test to obtain an integration test running result; when the integration test running result is a passed test, in response to a merge operation of the code administrator, merging the branch code and the trunk code to obtain a target code.

[0091] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.

[0092] Through the above description of the embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a necessary general-purpose hardware platform, or of course, hardware. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for causing a computer device (such as a personal computer, server, or network device) to execute the methods described in each embodiment or certain portions of the embodiments.

[0093] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A code integration method, characterized in that: include: Obtaining a branch code and a trunk code, performing a difference comparison between the branch code and the trunk code to obtain a difference code; Compiling the branch code to obtain an intermediate code file, and performing illegal operation detection on the intermediate code file based on the difference code to obtain an illegal operation detection result; Performing an integration test on the intermediate code file for which the illegal operation detection result is a passing result, to obtain an integration test running result; When the integration test is run as passed, in response to a merge operation by a code administrator, the branch code and the trunk code are merged to obtain a target code.

2. The code integration method according to claim 1, characterized in that: The performing illegal operation detection on the intermediate code file based on the difference code to obtain an illegal operation detection result includes: Determine a target intermediate code file corresponding to the difference code in the intermediate code file; In the case where the code in the target intermediate code file is an unconditional jump instruction, saving the jump address corresponding to the unconditional jump instruction to a first register, and inserting a first jump instruction before the unconditional jump instruction, and jumping the first jump instruction to the judgment function; In the case where the code in the target intermediate code file is a conditional jump instruction, a conditional judgment instruction is inserted before the conditional jump instruction, and when the conditional judgment instruction satisfies a preset condition, a jump address corresponding to the conditional jump instruction is saved in a second register, and the conditional judgment instruction is jumped to the judgment function; In a case where the code in the target intermediate code file is a storage instruction, determining a memory access mode corresponding to the storage instruction, saving a memory access address of the memory access mode to a third register, and inserting a second jump instruction before the storage instruction to cause the storage instruction to jump to the judgment function; the memory access mode includes direct addressing, indirect addressing, and register indirect addressing; Determine the illegal operation detection result at the judgment function.

3. The code integration method according to claim 2, characterized in that: The illegal operation detection result is determined by the judgment function based on the distance between the target address and each cluster center address, the target address is the operation address in the register corresponding to each instruction type, and the cluster center address is the cluster center of all operation addresses in the register corresponding to each instruction type.

4. The code integration method according to claim 3, characterized in that: The instruction types include the unconditional jump instruction, the conditional jump instruction and the store instruction; In the case where the instruction type is the unconditional jump instruction, the target address is the operation address in the first register; In the case where the instruction type is the conditional jump instruction, the target address is the operation address in the second register; In a case where the instruction type is the store instruction, the target address is the operation address in the third register.

5. The code integration method according to claim 4, characterized in that: Determining the illegal operation detection result at the judgment function includes: If the judgment function determines that the distance between the target address and the addresses of the cluster centers is less than or equal to the cluster range, the illegal operation detection result is determined to be a legal address cluster; the cluster range is the distance between the addresses of the cluster centers and the addresses of the cluster boundaries; When the judgment function determines that the distance between the target address and each cluster center is greater than the cluster range, the illegal operation detection result is determined to be illegal access.

6. The code integration method according to claim 5, characterized in that: The method further comprises: When the illegal operation detection result is the legal address cluster, updating the address range of each cluster or the center address of each cluster based on the target address; When the illegal operation detection result is the illegal access, the operation address in the register corresponding to each instruction type and the address before the unconditional jump instruction, the conditional jump instruction and the storage instruction in the stack are output.

7. The code integration method according to claim 5, characterized in that: When the judgment function determines that the distance between the target address and the addresses of the cluster centers is less than or equal to the cluster range, determining that the illegal operation detection result is a legal address cluster, further comprising: Report the illegal operation detection results to the administrator and submitter; Returning to normal execution of the unconditional jump instruction, the conditional jump execution, and the store instruction.

8. The code integration method according to any one of claims 1 to 7, characterized in that: The step of obtaining the trunk code includes: Get the original trunk code; Randomly sampling the original trunk code to obtain trunk branch code, and determining the memory access address of the trunk branch code during operation; The memory access addresses are clustered to obtain a clustering result, and the original trunk code is adjusted based on the clustering result to obtain the trunk code.

9. A code integration device, characterized in that: include: an acquiring unit, configured to acquire a branch code and a trunk code, and perform a difference comparison between the branch code and the trunk code to obtain a difference code; an illegal operation detection unit, configured to compile the branch code to obtain an intermediate code file, and perform illegal operation detection on the intermediate code file based on the difference code to obtain an illegal operation detection result; An integration test unit is used to perform an integration test on the intermediate code file for which the illegal operation detection result is a passing test, and obtain an integration test running result; The merging unit is used to merge the branch code and the trunk code to obtain the target code in response to the merging operation of the code administrator when the integration test running result is that the test passes.

10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the code integration method according to any one of claims 1 to 8 is implemented.

11. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the code integration method according to any one of claims 1 to 8 is implemented.