Method, device, equipment, medium and product for converting container image
Patent Information
- Application Number
- CN202610865007.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-15
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2046-06-15
AI Technical Summary
采用本公开的容器镜像的转换方案,可以通过提取目标容器镜像的分层信息,从预设的候选Wasm模块中确定与目标容器镜像的部分分层匹配的第一Wasm模块,而仅需将基于目标容器镜像与第一Wasm模块之间的差异数据转换为第二Wasm模块,从而可以基于第一Wasm模块和第二Wasm模块,生成与目标容器镜像对应的Wasm模块,以实现将容器镜像转换为Wasm模块,如此,可以通过复用已有的候选Wasm模块,简化转换过程,无需对整个容器镜像执行转换,提高了转换效率。
Smart Images

Figure CN122387470B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of container image conversion, and more particularly to a method, apparatus, device, medium, and product for converting container images. Background Technology
[0002] Originally designed for browsers, WebAssembly has evolved into a cross-platform runtime technology. Transformation tools such as container2wasm can convert container images into standalone Wasm modules, enabling traditional container applications to run within the Wasm runtime.
[0003] However, relevant conversion tools require packaging the container image as a whole, merging all layers in the image into a single module, without preserving the layered structure. This means that the entire image needs to be converted every time, which is not conducive to improving conversion efficiency. Summary of the Invention
[0004] In view of the problem that converting a container image to a Wasm module requires converting the entire image, which makes it difficult to improve conversion efficiency, this disclosure provides a method, apparatus, device, medium, and product for converting container images to at least solve or alleviate the above-mentioned problems. The technical solution of this disclosure is as follows: According to a first aspect of this disclosure, a method for converting a container image is provided. The method includes: determining layering information of a target container image to be converted into a Wasm module; determining a first Wasm module matching the target container image from a plurality of preset candidate Wasm modules based on the layering information; generating a second Wasm module based on difference data between the target container image and the first Wasm module; and generating a target Wasm module corresponding to the target container image based on the first Wasm module and the second Wasm module.
[0005] Optionally, determining the first Wasm module matching the target container image from a set of candidate Wasm modules based on the layering information includes: matching the layer sequence of the container image corresponding to the target container image with the layer sequence of each candidate Wasm module among the set of candidate Wasm modules to determine the target layer in the layer sequence of the container image corresponding to each candidate Wasm module that matches the layer sequence of the target container image; determining a matching score for each candidate Wasm module based on the layer size and continuity of the target layer corresponding to each candidate Wasm module, wherein the matching score characterizes the degree of matching between the candidate Wasm module and the target container image; and determining the first Wasm module from the set of candidate Wasm modules based on the matching scores of each candidate Wasm module.
[0006] Optionally, for each candidate Wasm module, the matching score is determined as follows: The matching size of the candidate Wasm module is determined based on the layer size of each target layer corresponding to the candidate Wasm module, wherein the matching size is related to the total size of all target layers; a continuity attenuation factor is determined based on the number of skipped layers between the target layers corresponding to the candidate Wasm module that are not identified as target layers, wherein the continuity attenuation factor is negatively correlated with the number of skipped layers and positively correlated with the matching score; and the matching score of the candidate Wasm module is determined based on the matching size and the continuity attenuation factor.
[0007] Optionally, determining the matching size of the candidate Wasm module based on the layer size of the target layer corresponding to the candidate Wasm module includes: determining the stability weight of each target layer based on the historical reference count of each target layer corresponding to the candidate Wasm module, wherein the historical reference count refers to the number of times the target layer has been used to generate Wasm modules in history; and determining the matching size of the candidate Wasm module based on the layer size of each target layer corresponding to the candidate Wasm module and the stability weight of each target layer.
[0008] Optionally, for each candidate Wasm module, the target layer of the candidate Wasm module is determined by the following method: performing layer-by-layer matching between the layer sequence of the target container image and the layer sequence of the container image corresponding to the candidate Wasm module, and determining the layer in the layer sequence of the container image corresponding to the candidate Wasm module that meets the preset conditions as the target layer, wherein the preset conditions include: the layer has the same unique hash identifier as the corresponding layer in the target container image; and / or, the similarity of the layer content between the layer and the corresponding layer in the target container image is greater than a preset threshold.
[0009] Optionally, the target layer of the candidate Wasm module is also determined by: during the layer-by-layer matching process, determining the number of skipped layers that have not been determined as the target layer among the identified target layers; and ending the layer-by-layer matching in response to the number of skipped layers being greater than a preset maximum number of skipped layers.
[0010] Optionally, the difference data between the target container image and the first Wasm module includes at least one of the following: added data in the target container image relative to the first Wasm module; modified data in the target container image based on the first Wasm module; and deleted data in the target container image relative to the first Wasm module.
[0011] Optionally, the difference data includes the modified data. Based on the difference data between the target container image and the first Wasm module, generating the second Wasm module includes: determining an extraction method for extracting the modified data from the target container image according to the file type of the modified data; extracting the modified data from the target container image based on the extraction method; and converting the modified data into the second Wasm module.
[0012] Optionally, generating a Wasm module corresponding to the target container image based on the first Wasm module and the second Wasm module includes: determining whether the first Wasm module exists in the locally cached Wasm modules of the container image through Wasm runtime; in response to determining that the first Wasm module exists in the locally cached Wasm modules of the container image, referencing the first Wasm module and overlaying the second Wasm module to generate the target Wasm module; and in response to determining that the first Wasm module does not exist in the locally cached Wasm modules of the container image, obtaining the first Wasm module from a preset Wasm module library and overlaying the second Wasm module onto the first Wasm module to generate the target Wasm module.
[0013] Optionally, the conversion method further includes: in response to receiving an update instruction for the target Wasm module, determining the update object of the update instruction; if the update object includes the first Wasm module, redistributing the first Wasm module according to the update instruction to update all Wasm modules referencing the first Wasm module, including the target Wasm module; if the update object includes the second Wasm module, incrementally updating the second Wasm module according to the update instruction to update the target Wasm module.
[0014] According to a second aspect of this disclosure, a container image conversion apparatus is provided, the conversion apparatus comprising: a determining unit configured to determine layering information of a target container image to be converted into a Wasm module; a matching unit configured to determine a first Wasm module matching the target container image from a plurality of preset candidate Wasm modules based on the layering information; a first generating unit configured to generate a second Wasm module based on difference data between the target container image and the first Wasm module; and a second generating unit configured to generate a target Wasm module corresponding to the target container image based on the first Wasm module and the second Wasm module.
[0015] According to a third aspect of this disclosure, a computing device is provided, the computing device comprising: a processor; and a memory for storing computer-executable instructions, wherein the computer-executable instructions, when executed by the processor, cause the processor to perform a container image conversion method according to this disclosure.
[0016] According to a fourth aspect of this disclosure, a computer-readable storage medium is provided that, when instructions in the computer-readable storage medium are executed by a processor of a computing device, enables the computing device to perform a container image conversion method according to this disclosure.
[0017] According to a fifth aspect of this disclosure, a computer program product is provided, including computer-executable instructions that, when executed by at least one processor, implement the container image conversion method according to this disclosure.
[0018] The technical solution provided in this disclosure brings at least the following beneficial effects: By employing the container image conversion scheme disclosed herein, the layering information of the target container image can be extracted to determine a first Wasm module that partially matches the layering of the target container image from a preset pool of candidate Wasm modules. Only the difference data between the target container image and the first Wasm module needs to be converted into a second Wasm module. Based on the first and second Wasm modules, a Wasm module corresponding to the target container image can be generated, thereby converting the container image into a Wasm module. In this way, the conversion process can be simplified by reusing existing candidate Wasm modules, eliminating the need to convert the entire container image and improving conversion efficiency.
[0019] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description
[0020] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure, and are not intended to unduly limit this disclosure.
[0021] Figure 1 This is a schematic flowchart of a container image conversion method according to an exemplary embodiment of the present disclosure.
[0022] Figure 2 This is a schematic flowchart illustrating the determination of a first Wasm module that matches a target container image according to an exemplary embodiment of this disclosure.
[0023] Figure 3This is an illustrative flowchart of determining the matching score of a candidate Wasm module according to an exemplary embodiment of the present disclosure.
[0024] Figure 4 This is a schematic block diagram of a container image conversion apparatus according to exemplary embodiments of the present disclosure.
[0025] Figure 5 This is a block diagram of a computing device according to exemplary embodiments of the present disclosure. Detailed Implementation
[0026] In order to enable those skilled in the art to better understand the technical solutions of this disclosure, the technical solutions in the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings.
[0027] It should be noted that the terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this disclosure described herein can be implemented in orders other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this disclosure as detailed in the appended claims.
[0028] It should be noted that the phrase "at least one of several items" in this disclosure refers to three parallel cases: "any one of the several items", "a combination of any number of the several items", and "all of the several items". For example, "including at least one of A and B" includes the following three parallel cases: (1) including A; (2) including B; (3) including A and B. Another example is "performing at least one of step one and step two", which means the following three parallel cases: (1) performing step one; (2) performing step two; (3) performing both step one and step two.
[0029] As mentioned earlier, the process of converting a container image into a Wasm module requires the entire image to be converted, which makes it difficult to improve conversion efficiency.
[0030] Specifically, WebAssembly, originally designed for browsers, has evolved into a cross-platform runtime technology. The release of WASI in 2019 enabled Wasm to run in non-browser environments, bridging the gap between Wasm and the underlying operating system. WASI Preview 2 further standardized the module interface, including core API modules such as wasi-cli, wasi-io, wasi-filesystem, and wasi-sockets.
[0031] The current mainstream Wasm runtimes include Wasmtime, WasmEdge, WAMR, and wasm3. Wasmtime is a general-purpose runtime developed by the Bytecode Consortium, fully supporting the WASI standard. WasmEdge is a lightweight, high-performance runtime that supports AOT compilation and plugin systems. WAMR is designed for resource-constrained devices, while wasm3 is suitable for embedded scenarios.
[0032] In the cloud-native domain, containerd-shim-wasm v0.9.0 and above have achieved full support for WASI workloads, enhancing container isolation and stability through a dedicated Zygote process design. Azure Kubernetes Service has provided a preview of WASI node pools, allowing users to use containerd shim as an alternative to the earlier Krustlet solution.
[0033] Tools such as container2wasm can convert container images into standalone Wasm modules, enabling traditional container applications to run within the Wasm runtime. The workflow of such tools includes four stages: image pulling and decompression, file system packaging, module generation, and runtime execution.
[0034] During the image pull and decompression phase, the tool pulls the target container image and decompresses all layers to a temporary directory. In the file system packaging phase, the entire rootfs is packaged into a Wasm-accessible file system structure using tools such as wasi-vfs. During the module generation phase, a single Wasm binary file is generated, embedding the complete rootfs data. During the runtime execution phase, the embedded file system is accessed via the WASI system call.
[0035] However, such conversion technology has a capacity overflow problem. Specifically, when converting large images, intermediate files may exhaust disk space, triggering a Rust Vec capacity overflow error. Its core flaw lies in the overall packaging method, which merges all image layers into a single module without preserving the layered structure.
[0036] Furthermore, in such transformation techniques, each Wasm module contains a complete rootfs, resulting in a large amount of duplicate data when multiple applications share the base image. The root cause is the lack of a layered referencing mechanism, which makes it impossible to identify and reuse common layers, leading to storage redundancy issues.
[0037] Furthermore, such conversion technology requires the transmission of the entire module during distribution. Even if only the application layer changes, due to the lack of incremental update capability, the entire module must be transmitted each time, resulting in a waste of network bandwidth.
[0038] Furthermore, such conversion technology requires re-converting the entire image when modifying the configuration file, which can take up to minutes. This is because it lacks the ability to extract differences, so it cannot isolate the change layer, resulting in low update efficiency.
[0039] Furthermore, since module size and loading time are linearly related, in such conversion technology, loading time for large modules increases significantly, with large images taking several seconds, thus causing startup delays.
[0040] Furthermore, such conversion techniques present challenges in security maintenance. The remediation of Common Vulnerabilities and Exposures (CVEs) of the base image requires the reconversion of all Wasm modules that depend on this base, because the base layer and the application layer are strongly coupled and cannot be updated independently.
[0041] In addition, some conversion schemes have attempted to implement a Union File System (UnionFS) within Wasm, which increases runtime burden and overhead, and lacks a host-side optimized layered merging mechanism.
[0042] To address the issues of existing container image to Wasm conversion methods failing to utilize layered reuse, resulting in module redundancy and low update efficiency, this invention provides a conversion method based on layered principles. This method separates the base layer from the application layer, reducing module size by over 90%, supports incremental updates, reduces update time from minutes to seconds, enables cross-module sharing of the base layer, improves storage efficiency by 10 to 100 times, maintains compatibility with the Open Container Initiative (OCI) ecosystem, and reuses the Dockerfile build process.
[0043] In view of this, exemplary embodiments of the present disclosure provide a method for converting a container image, a device for converting a container image, a computing device, a computer-readable storage medium, and a computer program product, which can solve or at least alleviate the above-mentioned problems.
[0044] To facilitate understanding of the exemplary embodiments of this disclosure, the relevant concepts involved herein are first explained: container2wasm: An existing open-source tool that can convert a container image into a single Wasm module.
[0045] rootfs: The root file system of the container image, which contains the application and its dependencies.
[0046] OCI image: A container image that conforms to the Open Container Initiative specification and consists of multiple read-only layers.
[0047] Wasm: Short for WebAssembly, a portable binary instruction format that can be executed in a sandbox environment.
[0048] WASI (WebAssembly System Interface): The WebAssembly system interface standard provides access to operating system functions.
[0049] WASI Preview 2: The latest version of WASI, which includes modules such as wasi-cli, wasi-io, and wasi-filesystem.
[0050] OCI Artifact: A generic artifact format defined by the OCI specification, which can be used to store non-mirror content such as Wasm modules.
[0051] runwasi (Runtime for WASI): containerd's Wasm runtime shim, enabling Wasm workloads to run in Kubernetes.
[0052] crun (Container Runtime Universal): An OCI container runtime that supports Wasm handlers.
[0053] Union File System (UnionFS): can combine multiple directories into a single view.
[0054] Ahead-of-Time (AOT) compilation: Wasm bytecode is pre-compiled into machine code to improve performance.
[0055] Nanoprocess: A security model proposed by the Bytecode Consortium for trust transfer between Wasm modules.
[0056] Zygote process: A template process used in container runtime to quickly create child processes.
[0057] wasi-vfs: WebAssembly virtual file system, which allows mapping host file system directories to the Wasm module.
[0058] WIT (WebAssembly Interface Types): WebAssembly interface types are used to define the interface description language for the interaction between Wasm components and the host environment.
[0059] In a first aspect of the exemplary embodiments of this disclosure, a method for converting a container image is provided. This method can be applied to conversion tools such as container2wasm. The container image conversion method according to embodiments of this disclosure can be mounted or added to existing conversion tools such as container2wasm, or it can be implemented as a standalone conversion tool. An example implementation scenario of the container image conversion method according to exemplary embodiments of this disclosure is given below.
[0060] The execution subject of this method may be a computing device that has deployed a conversion tool such as, but not limited to, container2wasm. For example, the computing device may, in response to a conversion instruction provided by a user, acquire or receive a target container image to be converted into a Wasm module, and convert the target container image into a Wasm module by executing the container image conversion method according to an embodiment of this disclosure.
[0061] The aforementioned computing device may be, but is not limited to, a desktop computer, laptop computer, tablet computer, personal digital assistant, smartphone, or other device capable of performing component rendering. However, the implementation scenario of the above method is only an example scenario. The container image conversion method according to the exemplary embodiments of this disclosure can also be applied to other application scenarios. For example, it may also be that a user requests an update patch from a server via a network on a user terminal (e.g., a mobile phone, desktop computer, tablet computer, etc.), and the server can implement the patch update by executing the method according to the exemplary embodiments of this disclosure. Here, the server may be a standalone server, a server cluster, a cloud computing platform, or a virtualization center.
[0062] The following will describe an example of a container image conversion method according to an embodiment of the present disclosure with reference to the accompanying drawings. Figure 1 As shown, the method for converting this container image may include the following steps: In step 110, the layering information of the target container image to be converted into a Wasm module can be determined.
[0063] Here, the target container image can be provided by the user or obtained according to the user's conversion instructions. For example, the target container image can be an OCI image.
[0064] Layering information can include the structure of the layer sequence in the target container image, as well as layer information for each layer (such as, but not limited to, the hash identifier of the layer content, the size of the layer content, and the set of file fingerprints within the layer). The set of file fingerprints within a layer includes the file fingerprint of each file within the layer, which can be generated by calculating the hash value of the file content. As an example, layering information can be obtained by parsing the target container image.
[0065] For example, a user can specify the target container image to be converted, such as `myapp latest`. The conversion tool can determine the layer information of the target container image through the following operations: pulling the image manifest of the target container image and obtaining the OCI Image Index or Image Manifest; based on the image manifest of the target container image, parsing the layer descriptors and extracting the hash identifier (digest), size, and media type (mediaType) of the content of each layer; constructing a layer dependency graph and analyzing the parent-child relationships between layers. In addition, the conversion tool can also identify configuration objects and extract metadata such as environment variables, entry points, and working directories from the configuration (e.g., the `config` field).
[0066] It should be noted that although the above describes an example process for determining the layer information of a target container image by parsing it, the embodiments of this disclosure are not limited thereto. Layer information can also be extracted in other ways or it can be provided together with the target container image. This disclosure does not impose any particular restrictions on the way of obtaining layer information.
[0067] In step 120, based on the hierarchical information, a first Wasm module that matches the target container image can be determined from a plurality of preset candidate Wasm modules.
[0068] In this step, a first Wasm module that can be used for the target container image to be converted can be matched from the existing candidate Wasm modules. Here, the candidate Wasm module can be, for example, a pre-prepared, reusable Wasm module, which can be stored in a preset Wasm module repository.
[0069] Specifically, when faced with the need to convert a target container image into a Wasm module, one or more first Wasm modules matching the target container image can be obtained from the Wasm module repository and directly used as the base layer module in the converted Wasm module of the target container image (hereinafter, the first Wasm module can also be referred to as the base layer module), without the need to perform conversion operations on this part, simplifying the conversion process from container image to Wasm module and improving conversion efficiency.
[0070] As an example, a candidate Wasm module repository (or a base layer Wasm module repository) can be created, pre-configuring candidate Wasm modules corresponding to commonly used base images. Here, the base images may include, but are not limited to: alpine 3.18 (approximately 5MB base layer), alpine latest (approximately 5MB base layer), ubuntu 22.04 (approximately 25MB base layer), ubuntu 20.04 (approximately 27MB base layer), debian bullseye-slim (approximately 30MB base layer), language-runtimepython 3.11 (based on alpine and Python runtime, approximately 15MB), and language-runtime nodejs 20 (based on alpine and Node.js, approximately 12MB).
[0071] Each candidate Wasm module may include, but is not limited to: the complete rootfs of the corresponding container image, i.e., the file system content of the corresponding container image; a metadata hash, which serves as a unique identifier, for example, it can be generated using the SHA256 function, and this metadata hash can be used for version control and integrity verification; a WASI adaptation layer, an optimized file system access interface; and an ABI compatibility flag, for example, it can declare supported WASI versions (e.g., including Preview 1 and Preview 2).
[0072] Here, the candidate Wasm module can be optimized by AOT pre-compilation, which can be reused by multiple upper-level modules, thereby reducing the runtime just-in-time (JIT) compilation overhead.
[0073] The candidate Wasm module repository can have multiple candidate Wasm modules pre-set. When performing a conversion on any one or more target container images, the first Wasm module can be matched from these candidate Wasm modules for each target container image.
[0074] As an example, for determining the first Wasm module, such as Figure 2 As shown, step 120 above may include the following steps: In step 210, the layer sequence of the target container image can be matched with the layer sequence of the container image corresponding to each of the multiple candidate Wasm modules to determine the target layer in the layer sequence of the container image corresponding to each candidate Wasm module that matches the layer sequence of the target container image.
[0075] Here, matching layer sequences can refer to matching layer sizes and / or layer contents. Specifically, each candidate Wasm module can carry layer information for its corresponding container image. This layer information may include the structure of the container image's layer sequence and the layer information for each layer (e.g., including but not limited to the hash identifier of the layer content and the size of the layer content). Matching results can be obtained by matching the layer information carried in each candidate Wasm module with the layer information of the target container image.
[0076] As an example, for each candidate Wasm module, the target layer corresponding to the candidate Wasm module can be determined in the following way: the layer sequence of the target container image is matched layer by layer with the layer sequence of the container image corresponding to the candidate Wasm module, and the layer in the layer sequence of the container image corresponding to the candidate Wasm module that meets the preset conditions is determined as the target layer.
[0077] Here, the aforementioned preset conditions may include: the unique hash identifier of the layer content is the same as that of the corresponding layer in the target container image; and / or, the similarity of the layer content of the layer to that of the corresponding layer in the target container image is greater than a preset threshold.
[0078] Specifically, the layer information can be compared layer by layer with the layer information of the container image corresponding to the candidate Wasm module being matched, according to the order of each layer in the layer sequence of the target container image. When comparing each layer, if a certain layer of the container image corresponding to the candidate Wasm module meets the above preset conditions, then that layer can be used as a target layer, and then the matching of the next layer can be carried out or the matching of the candidate Wasm module can be terminated.
[0079] For example, the list of mirror layers of the target OCI obtained from the parsing can be modeled in the following sequence. :
[0080] in, , ... This represents the image layers of the target container image, with a total of n layers.
[0081] The candidate Wasm module can be selected from the repository. The layer list of the container images corresponding to each candidate Wasm module is modeled as follows: :
[0082] in, , ... Indicates the first The container image corresponding to each candidate Wasm module has a total of m image layers.
[0083] For the above sequence and sequence Each layer can be defined as a structured object: ,in, Indicates the first Layer (or first) The unique hash identifier of the layer content is obtained by parsing the container image (e.g., obtaining the sequence by parsing the target container image in step 110 above). The Middle Layer ); Indicates the first Layer (or first) The layer size (for a sequence) , Take values from 1 to n; for the sequence , Take values from 1 to m.
[0084] Based on the above sequence, longest consecutive matching can be used to match the layer sequence of the target container image with the layer sequence of the container image corresponding to each candidate Wasm module layer by layer. Specifically, the sequence can be calculated using a dynamic programming algorithm. with sequence The longest common subsequence (LCS) (e.g., the longest consecutive matching sequence starting from the first layer) is used to further filter out the longest consecutive matching prefix, ensuring the continuity and integrity of the matching results. The matching strategy may include performing prefix matching between the layer sequence of the target image and the base layer repository, finding the longest consecutive matching sequence and allowing skipping of non-contiguous layers. This can support multiple base layer combinations (e.g., operating system (OS) layer plus language runtime layer), thus ensuring that the first Wasm module, as a base layer module, is a complete underlying environment (e.g., operating system layer).
[0085] For example, in the layer sequence of the container image corresponding to the candidate Wasm module... A layer is considered to be successfully matched if it meets at least one of the following preset conditions: Condition 1: The unique hash identifiers of the layer contents must be completely identical (i.e., ...) ,in, Represents a sequence The Middle The unique hash identifier of the layer content Represents a sequence The Middle The unique hash identifier of the layer content; Condition 2: The similarity of the layer content is greater than the threshold, i.e. ,in, Representation layer sequence of with sequence layer The similarity of the content of the layers, This indicates the preset threshold value mentioned above, which can be set according to actual needs, for example, it can be set to 0.85.
[0086] As an example, the above content similarity The similarity can be calculated based on the Jaccard similarity of the file fingerprint sets within a layer, for example, by calculating the ratio of the intersection to the union of the file fingerprint sets of two layers. However, the embodiments of this disclosure are not limited to this, and the similarity of layer content can also be calculated based on other methods. This disclosure does not impose any particular limitation on the method of calculating similarity.
[0087] The above method allows for hierarchical similarity matching between the target container image and preset candidate Wasm modules, enabling the accurate identification of the first Wasm module that can be used as the target container image, and maximizing the reuse of existing Wasm modules to achieve the conversion of the target container image.
[0088] Furthermore, as an example, in embodiments of this disclosure, the longest consecutive matching algorithm can be used to identify reusable target layers. Here, consecutive matching refers to matching layer by layer sequentially according to the layer sequence of the target container image, but it is permissible to skip a small number of discontinuous layers (e.g., lightweight configuration change layers). For example, for a sequence... When matching a candidate Wasm module, the maximum allowed is... If a preset number of layers (or "skipped layers") are not matched in the candidate Wasm module, the current match can be considered to meet the requirements of continuous matching when the number of skipped layers does not exceed the preset number. However, if the number of skipped layers exceeds the preset number, the requirement of continuous matching can be considered to be no longer met, and the matching can be terminated, with the currently matched target layer becoming the final target layer.
[0089] For example, in step 210 above, the target layer of the candidate Wasm module can also be determined in the following way: during the layer-by-layer matching process, the number of skipped layers that have not been determined as target layers among the identified target layers is determined; in response to the number of skipped layers being greater than the preset maximum number of skipped layers, the layer-by-layer matching ends.
[0090] Here, the maximum number of skips can be set according to actual needs, such as 1 or 2, or it can be determined according to the total number of layers of the target container image, such as a value in the range of 5%-10% of the total number of layers.
[0091] With the above sequence and sequence For example, it can be used for sequences The layers in the sequence are sequentially related to each other. Perform layer-by-layer matching, if layer With layers Matching, layer With layers Matching, and layers With layers If there is a mismatch, and the maximum number of skips is preset to 1, it can respond to the layer. With layers Mismatch (i.e., currently skipped layer (layer)) and layers The number of skips is 2, which is greater than the preset maximum number of skips. This ends the layer-by-layer matching process and sets the currently matched layer as 2. and layers As the target layer.
[0092] The above method allows for a small number of skipped layers, which, compared to strictly implementing absolute continuous matching without skipping, allows for more exploration of candidate Wasm modules, facilitating the discovery of better-matching candidate Wasm modules. However, the embodiments of this disclosure are not limited to this; absolute continuous matching without skipping can also be set, for example, the aforementioned preset maximum number of skips can be 0.
[0093] Furthermore, as an example, the first Wasm module determined by the aforementioned layer-by-layer matching can support multiple base layer combinations. For instance, the first Wasm module could be a runtime module, which could reference an OS module. This OS module could also be stored as a candidate Wasm module in a repository. In the layer-by-layer matching for such a runtime module, since the runtime module references the underlying OS module, the layers in the OS module are matched first, and then the layers in the runtime module are matched. The matching result between the layers in the OS module and the layers in the runtime module is taken as the final matching result. In this case, the runtime module and the OS module can be used together as the first Wasm module, where the runtime module contains a reference to the aforementioned OS module for use in subsequently generating the final target Wasm module.
[0094] Specifically, if a single base layer cannot provide a complete match, multiple base layers can be combined to construct a complete base environment. For example, multiple base layers can be matched sequentially (e.g., "OS layer + language runtime layer"), and stacked in order to form a complete base environment. The matching process adopts a layered and progressive matching strategy, matching the OS layer first, and then matching the runtime layer on top of it.
[0095] Specifically, in the OS layer matching phase, consecutive prefixes of the OS type base layer can be matched from the beginning of the layer sequence of the container image corresponding to the candidate Wasm module; in the runtime layer matching phase, consecutive prefixes of the language runtime base layer can be matched from the remaining layer sequence of the container image corresponding to the candidate Wasm module, and multiple base layers are stacked sequentially to form the final base layer combination. In this way, the target layers obtained by matching can include the OS layer and / or the language runtime layer.
[0096] The following is an example of determining the target layer in the layer sequence of the container image corresponding to the candidate Wasm module.
[0097] For example, the layer sequence of the target container image myapp:latest is: "alpine:3.18 layer (digest: sha256:abc123..., size: 5MB); Install Python layer (digest: sha256:def456..., size: 45MB).
[0098] Installation dependency layer (digest: sha256:ghi789..., size: 120MB); application code layer (digest: sha256:jkl012..., size: 5MB)).
[0099] For the target container image myapp:latest mentioned above, the matching process is as follows: "Prefix matching: The first layer matches the base layer of alpine:3.18 (5MB); the second layer partially matches the prefix of the base layer of python:3.11-alpine (the first 45MB of the approximately 15MB Python runtime is the complete Python layer); the longest continuous matching + similarity threshold strategy is adopted: when the similarity between the second layer and python:3.11-alpine is >85% (the highest value), it is determined to be a match."
[0100] The final matching results are as follows: "Base layer = alpine:3.18 + python:3.11-alpine (pre-built combination layer, 20MB); Application layer = installation dependency layer + application code layer (125MB, approximately 5MB after differential compression)."
[0101] In the example above, a possible matching result could be: "Target image myapp:latest layer sequence: alpine:3.18 → Install Python → Install dependencies → Application code".
[0102] Return to reference Figure 2In step 220, the matching score of each candidate Wasm module can be determined based on the layer size and continuity of the target layer corresponding to each candidate Wasm module.
[0103] Once the target layer corresponding to each candidate Wasm module is determined, a matching score for the target layer can be calculated for each candidate Wasm module. Here, the matching score represents the degree of matching between the candidate Wasm module and the target container image. The greater the degree of matching, the more similar the candidate Wasm module is to the target container image. Such candidate Wasm modules can be used as the first Wasm module of the target container image to achieve the conversion of the target container image.
[0104] As an example, such as Figure 3 As shown, in step 220, for each candidate Wasm module, the matching score can be determined in the following way: In step 310, the matching size of the candidate Wasm module can be determined based on the layer size of each target layer corresponding to the candidate Wasm module.
[0105] Here, the matching size can be related to the total size of all target layers, for example, it can be the total size of all target layers, or it can be a weighted sum of the layer sizes of each target layer.
[0106] In one example, in step 310, the stability weight of each target layer can be determined based on the historical reference count of each target layer corresponding to the candidate Wasm module; the matching size of the candidate Wasm module can be determined based on the layer size of each target layer corresponding to the candidate Wasm module and the stability weight of each target layer.
[0107] Here, historical citation count can refer to the number of times the target layer has been used to generate Wasm modules in history, and the matching size is used to characterize the total size of all target layers, which can be positively correlated with the matching score.
[0108] Specifically, since each candidate Wasm module can be used as a reusable Wasm module, when the conversion tool receives a container image to be converted and converts it, it can record the number of times each candidate Wasm module is used as the first Wasm module. This number can characterize the reuse rate of the corresponding candidate Wasm module. Candidate Wasm modules with high reuse rates have higher layer stability and can be given higher weights. They can be given priority or considered in subsequent container image conversions.
[0109] As an example, the above historical reference counts may include: the number of times the layer is referenced by other images (e.g., historically converted container images) in all candidate Wasm modules (e.g., candidate Wasm module repositories); and / or, the number of references of the layer that is most referenced by other images (e.g., historically converted container images) in all candidate Wasm modules (e.g., candidate Wasm module repositories).
[0110] The stability weight of each target layer can be determined based on its historical citation count. This stability weight can be used to weight the layer size of the target layer, and the matching size can be determined based on the weighted layer size.
[0111] For example, for the target layer corresponding to the current candidate Wasm module Introducing stability weights The stability weight can be based on the target layer. The historical reuse frequency in the candidate Wasm module repository can be calculated, for example, by the following formula (1): (1) in, This indicates the number of times this layer is referenced by other images in the repository; This indicates the number of times the layer in the repository is referenced most frequently by other images.
[0112] In this example, the matching size of the current candidate Wasm module can be determined based on the stability weights and layer size of each target layer, for example, it can be represented by the following equation (2): (2) in, This represents the matching size considering the stability of each target layer, and it can characterize the total size of the weighted target layers; This represents the total number of target layers corresponding to the current candidate Wasm modules, or the length of the longest consecutive prefix.
[0113] In another example, the size of the target layer can also be left unweighted; for example, the matching size of the candidate Wasm module can be expressed by the following equation (3): (3) in, This represents the matching size without considering the stability of each target layer, and it can characterize the total size of the target layer.
[0114] Return to reference Figure 3 In step 320, the continuity attenuation factor can be determined based on the number of skipped layers that are not identified as target layers between the target layers corresponding to the candidate Wasm module.
[0115] Here, the continuity decay factor can be negatively correlated with the number of skipped layers and positively correlated with the matching score.
[0116] The above describes how a small number of discontinuous layers can be skipped during continuous matching. In this example, a continuity constraint factor can be introduced based on the number of skipped layers, so that the number of skipped layers can be reflected in the final matching score calculation, thereby modulating the matching score.
[0117] For example, in the continuous matching process, a continuous decay factor can be applied to the matching score for each layer skipped, which can be expressed by the following equation (4): (4) in, Indicates the continuous decay factor; Indicates the number of layers skipped; This represents the single-layer attenuation factor, which can be preset as needed. A smaller value indicates a stricter requirement for continuity. For example, The value of can satisfy .
[0118] The steps 310 for determining the matching size and 320 for determining the continuity attenuation factor have been described above. In the embodiments of this disclosure, the execution order of steps 310 and 320 can be arbitrary. One of them can be executed first, followed by the other; or they can be executed in parallel.
[0119] return Figure 3 In step 330, the matching score of the candidate Wasm module can be determined based on the matching size and the continuity attenuation factor.
[0120] Given the matching size and the continuity attenuation factor, the matching score of the current candidate Wasm module can be determined. In one example, the matching score can be the product of the matching size and the continuity attenuation factor.
[0121] In another example, the matching score can be the ratio of the product of the matching size and the continuity decay factor to the total size of the target container image. For example, the matching score can be expressed as equation (5) or (6): (5) (6) in, Indicates the first Matching scores of candidate Wasm modules This indicates the total size of the target container image.
[0122] Using the above method, the final matching score of the module can be determined comprehensively from multiple dimensions such as the size of all matched target layers and the number of skipped layers, so as to select more suitable candidate Wasm modules.
[0123] Furthermore, in determining the matching size, the historical citation count of each target layer can be further considered to determine the stability weight of each target layer. This allows for consideration of the reuse of each target layer and modulates the value contribution of the target layer size in determining the matching score, further ensuring the availability of the first Wasm module selected subsequently.
[0124] It should be noted that the process of determining the matching score of each candidate Wasm module is not limited to the above example. As another example, only the total size of the matched target layer can be considered. For example, the matching score can be expressed by the following formula (7): (7) Furthermore, in the example above, the matching score can be expressed as a percentage.
[0125] In the above matching process, layer stability weights, continuity constraint factors and multi-stage combination strategies are introduced to improve the accuracy and robustness of the first Wasm module identification.
[0126] Return to reference Figure 2 In step 230, the first Wasm module can be determined from multiple candidate Wasm modules based on the matching scores of each candidate Wasm module.
[0127] As an example, given the matching scores of each candidate Wasm module, the candidate Wasm module with the highest matching score can be selected as the first Wasm module.
[0128] As another example, the candidate Wasm module with the highest matching score and the longest matching length (e.g., the largest number of target layers) can also be selected as the first Wasm module.
[0129] return Figure 1 In step 130, a second Wasm module can be generated based on the difference data between the target container image and the first Wasm module.
[0130] In this step, once the first Wasm module is identified, the parts of the target container image that differ from the first Wasm module are extracted to generate an application layer data package, i.e., the second Wasm module.
[0131] Here, the difference data between the target container image and the first Wasm module may include: unmatched layers in the target container image; and / or, difference data of matched layers in the target container image relative to the first Wasm module.
[0132] Specifically, the dimensions for extracting differential data in this step may include at least one of the following dimensions: file system increments (e.g., lists and contents of newly added, modified, or deleted files), metadata overwriting (e.g., appending or overwriting environment variables, modifying entry points, or changing working directories), permission changes (e.g., file permissions, differential records of owners and groups), and special files (e.g., handling of device files and symbolic links).
[0133] As an example, the difference data between the target container image and the first Wasm module may include at least one of the following: added data in the target container image relative to the first Wasm module; modified data in the target container image based on the first Wasm module; deleted data in the target container image relative to the first Wasm module.
[0134] As an example, it is not necessary to distinguish whether the data added, modified, or deleted above comes from an unmatched layer or a matched layer in the target container image. Furthermore, the terms "add data," "modify data," and "delete data" as used here can all include at least one of the dimensions mentioned above.
[0135] Here, added data can be directly extracted and converted into the second Wasm module, deleted data can be converted into the second Wasm module to delete the corresponding data in the first Wasm module, and modified data can include one or more modified files, which can be extracted and converted according to the file type of each modified file.
[0136] Specifically, in the example where the difference data includes modified data, step 130 may include: determining the extraction method for extracting the modified data from the target container image based on the file type of the modified data; extracting the modified data from the target container image based on the extraction method; and converting the modified data into a second Wasm module.
[0137] Here, for modified files included in the modified data, a type-aware partial difference extraction mechanism can be adopted. Different difference extraction methods are selected according to the file type, and only the changed data is recorded instead of the complete file content, so as to reduce the duplicate storage of unchanged data.
[0138] Specifically, for each modified file, its file type can be identified first. The file type is determined based on the file extension, file header features, and file content features, and the corresponding difference extraction strategy is executed according to different types.
[0139] For example, when modifying a file of type text, such as a source file, script file, or configuration file, a line-level difference extraction method can be used to record and convert only the added, deleted, or modified lines.
[0140] When modifying a binary file, such as an executable or dynamic library, the modified file can be divided into multiple data blocks. These blocks are then compared, and only the changed data is recorded. For executable files, which require module conversion during the subsequent generation of the second Wasm module, a content-sliding identification-based data block partitioning method can be used. This adapts to data changes caused by local offsets or structural adjustments within the executable file, avoiding duplicate storage of the entire file due to minor modifications and reducing redundant processing of unchanged areas during the subsequent generation of the second Wasm module.
[0141] When modifying a file of type Archive, such as a compressed file or a dependency file, you can first parse the internal structure of the archive, identify the changes in the internal files, and generate and convert only the changes to the internal files.
[0142] By using the type-aware partial difference extraction method described above, when a file is modified, only the data content of the changed area is saved, avoiding the duplicate storage of unchanged data caused by the traditional whole file replacement method, thereby effectively reducing the data volume of the application layer.
[0143] Furthermore, as an example, after generating the second Wasm module, compression and optimization algorithms can be used to compress it. For instance, the zstd compression algorithm can be used to optimize the compression ratio for code files. Additionally, deduplication can be performed on the second Wasm module, identifying files that are duplicated from the first Wasm module (e.g., unmodified system libraries) and retaining only the references. Furthermore, block-level differencing can be applied to the second Wasm module, using binary differencing algorithms such as bsdiff for large files to further reduce its size.
[0144] Return to reference Figure 1 In step 140, a target Wasm module corresponding to the target container image can be generated based on the first Wasm module and the second Wasm module.
[0145] In this step, the target Wasm module can be generated by loading the first Wasm module and the second Wasm module.
[0146] Furthermore, as an example, when generating a target Wasm module based on the first Wasm module and the second Wasm module, it is possible to query whether the first Wasm module exists in the locally converted Wasm module to determine whether to directly reference the local cache or obtain the first Wasm module from an external source to generate the target Wasm module.
[0147] As an example, step 140 may include: determining, via the Wasm runtime, whether a first Wasm module exists in the Wasm modules of the locally cached container image, wherein, in response to determining that a first Wasm module exists in the Wasm modules of the locally cached container image, the first Wasm module is referenced and a second Wasm module is superimposed to generate a target Wasm module; in response to determining that a first Wasm module does not exist in the Wasm modules of the locally cached container image, the first Wasm module is obtained from a preset Wasm module library, and the second Wasm module is superimposed to the first Wasm module to generate the target Wasm module.
[0148] Specifically, once the first Wasm module required to generate the final target Wasm module is determined, the Wasm runtime can first check if the module exists in the local cache, for example, if it was obtained and cached locally during the conversion of a historical target container image. If it exists, it can be loaded directly; if it does not exist, it needs to be obtained from an external source, such as pulling it from the aforementioned candidate Wasm module repository. Then, the second Wasm module, which serves as application-layer data, can be decompressed and overlaid on the first Wasm module to form a union file system view.
[0149] Here, the target Wasm module is a composite Wasm module. Each instance of the target Wasm module can have an independent file system namespace. The first Wasm module, which is the base layer module, is read-only, while the second Wasm module, which is the application layer module, is writable, for example, by using a copy-on-write mechanism.
[0150] Furthermore, as an example, the target Wasm module may include, but is not limited to, a module header (e.g., Magic plus Version), a metadata section (e.g., Metadata Section), an application layer data section (e.g., Application Layer Payload), and a checksum (e.g., Checksum).
[0151] Here, the metadata area may include, but is not limited to: a first Wasm module reference list (e.g., including the first Wasm module hash SHA256, the URL or local path to obtain the address, and the signature verification (optional)); a second Wasm module (e.g., including the compression format flag zstd or gzip or none, the size after decompression, and the difference data block); runtime configuration (e.g., including the entry point, environment variables Env Vars, working directory Working Dir, and exposed ports); and version compatibility flags (e.g., ABI Version).
[0152] Furthermore, as an example, the generated target Wasm modules support multiple storage backends. For instance, the OCI Registry solution can push the target Wasm module as an OCI artifact, reusing the Docker Registry infrastructure. The local file system solution supports local directory structure storage, facilitating offline scenarios. Additionally, the object storage solutions for the aforementioned Wasm modules are compatible with object storage protocols such as S3 and MinIO, and when distributing these Wasm modules, a P2P distribution solution can be used to integrate P2P protocols such as IPFS, improving the efficiency of large-scale distribution.
[0153] Furthermore, in embodiments of this disclosure, updating the target Wasm module is also supported after it has been generated.
[0154] As an example, the conversion method according to an embodiment of this disclosure may further include: in response to receiving an update instruction for a target Wasm module, determining the update object of the update instruction; if the update object includes a first Wasm module, redistributing the first Wasm module according to the update instruction to update all Wasm modules referencing the first Wasm module, including the target Wasm module; if the update object includes a second Wasm module, incrementally updating the second Wasm module according to the update instruction to update the target Wasm module.
[0155] Specifically, the aforementioned update mechanism can include updates to both the first and second Wasm modules. For example, when fixing a CVE using the first Wasm module, it can be redistributed. All composite Wasm modules referencing the first Wasm module will receive the update without modification, provided that runtime support for reloading the base layer is provided. The second Wasm module can be updated incrementally. Specifically, only the second Wasm module can be repackaged to generate a new composite Wasm module version. Here, the update package size for the second Wasm module is extremely small, typically ranging from a few KB to several MB.
[0156] The above method allows for independent updates to the first and second Wasm modules. Furthermore, when updating the first Wasm module, all composite Wasm modules that reference it can be updated through redistribution. This simplifies module updates and improves the maintenance efficiency of Wasm modules.
[0157] Furthermore, in embodiments of this disclosure, after generating the target Wasm module, it can also be added to the candidate Wasm module repository as a candidate Wasm module for subsequent image conversion.
[0158] According to the container image conversion method of the embodiments of this disclosure, the layered structure of the container image can be mapped to the Wasm module, and the layer concept of OCI image is introduced into the Wasm ecosystem. It includes a complete process of pre-setting candidate Wasm modules, extracting second Wasm modules, and generating composite target Wasm modules.
[0159] Furthermore, in the container image conversion method of the embodiments of this disclosure, based on the reuse mechanism of the referenced first Wasm module, the composite Wasm module references the external base layer through hash, and dynamically resolves and loads it at runtime, supporting multiple modules to share the same base layer instance.
[0160] Furthermore, in the container image conversion method of the embodiments of this disclosure, the composite Wasm module format definition can be standardized. The standardized module structure may include a metadata area and an application layer data area, which includes a reference to the first Wasm module, difference data of the second Wasm module, and a complete specification of runtime configuration.
[0161] Furthermore, in the container image conversion method of the embodiments of this disclosure, it can be implemented on the host-side union file system, merging the first Wasm module and the second Wasm module during loading, providing a unified file system view at runtime, and eliminating runtime UnionFS overhead.
[0162] As an example, the above conversion method can be integrated into the Wasm hot patching tool and implemented as a convert subcommand. An example architecture for implementing a container image conversion method according to embodiments of this disclosure will be described below.
[0163] As an example, the architecture for implementing the container image conversion method according to embodiments of this disclosure may include a base layer repository, a composite module generator, and a runtime loader.
[0164] The base layer repository can pre-configure Wasm modules for commonly used OS base images. The composite module generator can parse OCI images and generate layered Wasm modules. The runtime loader can support dynamically loading the first Wasm module and overlaying the second Wasm module.
[0165] Specifically, in the base layer repository, a set of candidate Wasm modules for the "base layer" can be pre-built. Each module corresponds to a general base image (e.g., alpine:latest, ubuntu:20.04), which contains the rootfs of that base image and the necessary runtime libraries. The candidate Wasm modules are optimized so that they can be reused by multiple upper-layer modules.
[0166] The composite module generator can pull the target container image. Specifically, it can parse the manifest file of the target OCI image, obtain its layer information, and identify the parts that overlap with the base layer (for example, if the target container image is based on alpine:latest, the candidate Wasm module corresponding to alpine:latest can be directly reused).
[0167] The composite module generator can also extract a second Wasm module. Specifically, it can extract the differentiated parts of the target container image after removing the first Wasm module (such as user-added files, modified configurations, application binaries, etc.) into "application layer" data and convert them into a second Wasm module.
[0168] The compound module generator can also generate compound target Wasm modules. Specifically, it can package a second Wasm module with a reference to a first Wasm module into a new Wasm module as the target Wasm module. At runtime, the target Wasm module first loads the first Wasm module, and then overlays the second Wasm module on top, forming a complete file system view. Here, the target Wasm module can use a custom Wasm module format, such as including metadata (e.g., base layer hashes, application layer content).
[0169] Furthermore, the composite module generator also supports referencing multiple base layers (such as the OS layer + language runtime layer), enabling more refined reuse.
[0170] In the embodiments of this disclosure, the methods of the embodiments of this disclosure are also compared with traditional overall mirror conversion methods in combination with specific scenarios.
[0171] Specifically, for a scenario of deploying 100 Python microservices, the traditional method requires 25GB (250MB x 100) of storage space, while this method only requires 750MB ((250MB for the first Wasm module + 5MB for the second Wasm module) x 100), reducing storage usage by 97%.
[0172] In the scenario of updating application configuration, the traditional method requires reconverting and transmitting a 250MB image, while this method only requires repackaging a 5MB second Wasm module and transmitting 5MB, saving 98% of bandwidth.
[0173] In the scenario of secure updates to the Alpine base image, the traditional method of re-converting 100 applications takes several hours, while this method updates the base layer instantly, improving maintenance efficiency by 100 times.
[0174] In edge device deployment scenarios, traditional methods struggle to deploy large modules, while this method only requires transmitting a few MB of application layer data, supporting edge scenarios.
[0175] Using the container image conversion method according to embodiments of this disclosure, the second Wasm module is typically only a few MB to tens of MB, which is more than 90% smaller than the hundreds of MB of the complete image. Through the layered extraction and referencing mechanism, the redundant storage of basic system files can be avoided, thereby optimizing the module size.
[0176] Furthermore, by using this method, when the base image remains unchanged, the update time is reduced from minutes to seconds, saving more than 95% of bandwidth. This is achieved through the differentiated extraction of the second Wasm module, packaging only the changes relative to the first Wasm module, and the incremental distribution mechanism of the second Wasm module.
[0177] Furthermore, by employing this method, storage efficiency can be optimized through the pre-configuration and matching reuse mechanism of candidate Wasm modules. For example, for 100 applications based on the same base image, the storage usage is reduced from 25GB to 450MB.
[0178] Furthermore, using this method, smaller modules load faster, cold start time is reduced from several seconds to hundreds of milliseconds, and the reduced application layer size directly reduces I / O and memory mapping overhead.
[0179] Furthermore, by using this method, the CVE repair for the first Wasm module can be implemented immediately through independent updates and runtime reloading of the first Wasm module, without the need to rebuild all applications, which facilitates subsequent maintenance.
[0180] Furthermore, this method reuses the Dockerfile build process, eliminates the need to modify existing CI / CD, can directly parse OCI image formats, and supports the standard container ecosystem.
[0181] In a second aspect of exemplary embodiments of this disclosure, a container image conversion apparatus is provided, such as... Figure 4 As shown, the container image conversion device 400 includes a determining unit 410, a matching unit 420, a first generating unit 430, a second generating unit 440, and an updating unit 450.
[0182] The determining unit 410 is configured to determine the layering information of the target container image to be converted into a Wasm module.
[0183] Matching unit 420 is configured to determine the first Wasm module that matches the target container image from a plurality of pre-defined candidate Wasm modules based on hierarchical information.
[0184] The first generation unit 430 is configured to generate a second Wasm module based on the difference data between the target container image and the first Wasm module.
[0185] The second generation unit 440 is configured to generate a target Wasm module corresponding to the target container image based on the first Wasm module and the second Wasm module.
[0186] As an example, the matching unit 420 is configured to: match the layer sequence of the container image corresponding to the target container image with the layer sequence of the container image corresponding to each of the multiple candidate Wasm modules, and determine the target layer in the layer sequence of each candidate Wasm module that matches the layer sequence of the target container image; determine the matching score of each candidate Wasm module based on the layer size and continuity of the target layer corresponding to each candidate Wasm module, wherein the matching score characterizes the degree of matching between the candidate Wasm module and the target container image; and determine the first Wasm module from the multiple candidate Wasm modules based on the matching scores of each candidate Wasm module.
[0187] As an example, for each candidate Wasm module, the matching unit 420 is configured to determine the matching score by: determining the matching size of the candidate Wasm module based on the layer size of each target layer corresponding to the candidate Wasm module, wherein the matching size is related to the total size of all target layers; determining a continuity attenuation factor based on the number of skipped layers between the target layers corresponding to the candidate Wasm module that are not identified as target layers, wherein the continuity attenuation factor is negatively correlated with the number of skipped layers and positively correlated with the matching score; and determining the matching score of the candidate Wasm module based on the matching size and the continuity attenuation factor.
[0188] As an example, the matching unit 420 is configured to: determine the stability weight of each target layer based on the historical reference count of each target layer corresponding to the candidate Wasm module, wherein the historical reference count refers to the number of times the target layer has been used to generate Wasm modules in history; and determine the matching size of the candidate Wasm module based on the layer size of each target layer corresponding to the candidate Wasm module and the stability weight of each target layer.
[0189] As an example, for each candidate Wasm module, the matching unit 420 is configured to determine the target layer of the candidate Wasm module by performing layer-by-layer matching between the layer sequence of the target container image and the layer sequence of the container image corresponding to the candidate Wasm module, and determining the layer in the layer sequence of the container image corresponding to the candidate Wasm module that meets the preset conditions as the target layer, wherein the preset conditions include: the layer has the same unique hash identifier as the corresponding layer in the target container image; and / or, the similarity of the layer content between the layer and the corresponding layer in the target container image is greater than a preset threshold.
[0190] As an example, the matching unit 420 is also configured to determine the target layer of the candidate Wasm module by: determining the number of skipped layers between the identified target layers that have not been identified as target layers during the layer-by-layer matching process; and ending the layer-by-layer matching in response to the number of skipped layers being greater than a preset maximum number of skipped layers.
[0191] As an example, the difference data between the target container image and the first Wasm module includes at least one of the following: added data in the target container image relative to the first Wasm module; modified data in the target container image based on the first Wasm module; and deleted data in the target container image relative to the first Wasm module.
[0192] As an example, the difference data includes modified data, and the first generation unit 430 is configured to: determine the extraction method for extracting modified data from the target container image based on the file type of the modified data; extract the modified data from the target container image based on the extraction method; and convert the modified data into a second Wasm module.
[0193] As an example, the second generation unit 440 is configured to: determine whether a first Wasm module exists in the Wasm modules of the locally cached container image through the Wasm runtime; in response to determining that a first Wasm module exists in the Wasm modules of the locally cached container image, reference the first Wasm module and overlay a second Wasm module to generate a target Wasm module; in response to determining that a first Wasm module does not exist in the Wasm modules of the locally cached container image, obtain the first Wasm module from a preset Wasm module library and overlay the second Wasm module onto the first Wasm module to generate the target Wasm module.
[0194] As an example, the update unit 450 is configured to: in response to receiving an update instruction for a target Wasm module, determine the update object of the update instruction; if the update object includes a first Wasm module, redistribute the first Wasm module according to the update instruction to update all Wasm modules that reference the first Wasm module, including the target Wasm module; if the update object includes a second Wasm module, incrementally update the second Wasm module according to the update instruction to update the target Wasm module.
[0195] According to the container image conversion apparatus of the present disclosure, by extracting the layer information of the target container image, a first Wasm module that partially matches the layer information of the target container image is determined from a preset candidate Wasm module. Only the difference data between the target container image and the first Wasm module needs to be converted into a second Wasm module. Based on the first Wasm module and the second Wasm module, a Wasm module corresponding to the target container image can be generated to realize the conversion of the container image into a Wasm module. In this way, the conversion process can be simplified by reusing the existing candidate Wasm modules, and the conversion of the entire container image is not required, thereby improving the conversion efficiency.
[0196] Regarding the apparatus in the above embodiments, the specific manner in which each unit performs the operation has been described in detail in the embodiments related to the method. Each unit in the above conversion apparatus can perform the corresponding steps in the method and achieve the corresponding beneficial effects according to the container image conversion method in the method embodiment of the first aspect above. This will not be described in detail here.
[0197] In a third aspect of exemplary embodiments of the present disclosure, a computing device is provided, the computing device comprising: a processor; and a memory for storing computer-executable instructions, wherein the computer-executable instructions, when executed by the processor, cause the processor to perform a container image conversion method according to the present disclosure.
[0198] Figure 5 This is an example block diagram of a computing device according to exemplary embodiments of the present disclosure. Figure 5 As shown, the computing device 500 may include a processor 510 and a memory 520, which may be used to store computer-executable instructions 521 and an operating system 522. Here, when the computer-executable instructions are executed by the processor 510, they cause the processor 510 to perform the container image conversion method as described in the exemplary embodiment above. The computer-executable instructions 521 may run together with the operating system 522 in the processor.
[0199] As an example, computing device 500 is not necessarily a single device, but can be a collection of any means or circuits capable of executing the aforementioned instructions (or instruction sets) individually or in combination. Computing device 500 can also be part of an integrated control system or system manager, or can be configured to interconnect with a server locally or remotely (e.g., via wireless transmission) through an interface.
[0200] In computing device 500, processor 510 may include a central processing unit (CPU), a graphics processing unit (GPU), a programmable logic device, a dedicated processor system, a microcontroller, or a microprocessor. By way of example and not limitation, processor 510 may also include analog processors, digital processors, microprocessors, multi-core processors, processor arrays, network processors, etc.
[0201] The processor 510 can execute instructions or code stored in the memory 520, which can also store data. Instructions and data can also be sent and received over a network via a network interface device, which can employ any known transmission protocol.
[0202] The memory 520 may be integrated with the processor 510, for example, by placing RAM or flash memory within an integrated circuit microprocessor. Alternatively, the memory 520 may include a separate device, such as an external disk drive, a storage array, or other storage device that can be used by any database system. The memory 520 and the processor 510 may be operatively coupled, or may communicate with each other, for example, via I / O ports, network connections, etc., enabling the processor 510 to read files stored in the memory 520.
[0203] In addition, the computing device 500 may also include a video display (such as a liquid crystal display) and a user interaction interface (such as a keyboard, mouse, touch input device, etc.). All components of the computing device 500 can be interconnected via a bus and / or network.
[0204] In an exemplary embodiment, a computer-readable storage medium may also be provided, which, when executed by a processor of a computing device, enables the computing device to perform the container image conversion method as described in the exemplary embodiment above. The computer-readable storage medium may be, for example, a memory including instructions. Optionally, the computer-readable storage medium may be: a read-only memory (ROM), a random access memory (RAM), a random access programmable read-only memory (PROM), an electrically erasable programmable read-only memory (EEPROM), a dynamic random access memory (DRAM), a static random access memory (SRAM), flash memory, non-volatile memory, a CD-ROM, a CD-R, a CD+R, a CD-RW, a CD+RW, a DVD-ROM, a DVD-R, a DVD+R, a DVD-RW, a DVD+RW, a DVD-RAM, a BD-ROM, a BD-R, or a BD-R... LTH, BD-RE, Blu-ray or optical disc storage, hard disk drive (HDD), solid-state drive (SSD), card storage (such as multimedia cards, secure digital (SD) cards, or ultra-fast digital (XD) cards), magnetic tape, floppy disk, magneto-optical data storage device, optical data storage device, hard disk, solid-state drive, and any other device configured to store a computer program and any associated data, data files, and data structures in a non-transitory manner and to provide the computer program and any associated data, data files, and data structures to a processor or computer so that the processor or computer can execute the computer program. The computer program in the aforementioned computer-readable storage medium can run in an environment deployed in computer devices such as clients, hosts, agent devices, servers, etc. Furthermore, in one example, the computer program and any associated data, data files, and data structures are distributed across a networked computer system, such that the computer program and any associated data, data files, and data structures are stored, accessed, and executed in a distributed manner through one or more processors or computers.
[0205] According to exemplary embodiments of the present disclosure, a computer program product may also be provided, the computer program product including computer-executable instructions that, when executed by at least one processor, implement a container image conversion method according to exemplary embodiments of the present disclosure.
[0206] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the claims.
[0207] Furthermore, it should be noted that although several examples of each step have been described above with reference to the specific accompanying drawings, it should be understood that the embodiments of this disclosure are not limited to the combinations given in the examples. The steps appearing in different drawings can be combined, and the execution order of each step can be changed. No exhaustive list is provided here.
[0208] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is limited only by the appended claims.
Claims
1. A method for converting a container image, characterized in that, The conversion method includes: Determine the layering information of the target container image to be converted into a Wasm module; Based on the hierarchical information, a first Wasm module matching the target container image is determined from a plurality of preset candidate Wasm modules; Based on the difference data between the target container image and the first Wasm module, a second Wasm module is generated. Based on the first Wasm module and the second Wasm module, a target Wasm module corresponding to the target container image is generated. The step of generating a Wasm module corresponding to the target container image based on the first Wasm module and the second Wasm module includes: The presence of the first Wasm module in the locally cached container image's Wasm module is determined by the Wasm runtime. In response to the determination that the first Wasm module exists in the Wasm module of the locally cached container image, the first Wasm module is referenced and the second Wasm module is superimposed to generate the target Wasm module. In response to the determination that the first Wasm module does not exist in the Wasm module of the locally cached container image, the first Wasm module is obtained from a preset Wasm module library, and the second Wasm module is superimposed on the first Wasm module to generate the target Wasm module.
2. The conversion method according to claim 1, characterized in that, The step of determining the first Wasm module matching the target container image from a set of multiple candidate Wasm modules based on the hierarchical information includes: The layer sequence of the target container image is matched with the layer sequence of the container image corresponding to each of the multiple candidate Wasm modules to determine the target layer in the layer sequence of the image corresponding to each candidate Wasm module that matches the layer sequence of the target container image. Based on the layer size of the target layer corresponding to each candidate Wasm module and the continuity of the target layer, a matching score is determined for each candidate Wasm module, wherein the matching score characterizes the degree of matching between the candidate Wasm module and the target container image. The first Wasm module is determined from the plurality of candidate Wasm modules based on the matching scores of each candidate Wasm module.
3. The conversion method according to claim 2, characterized in that, For each candidate Wasm module, the matching score is determined as follows: The matching size of the candidate Wasm module is determined based on the layer size of each target layer corresponding to the candidate Wasm module, wherein the matching size is related to the total size of all target layers; A continuity attenuation factor is determined based on the number of skipped layers between the target layers corresponding to the candidate Wasm module that are not identified as the target layer. The continuity attenuation factor is negatively correlated with the number of skipped layers and positively correlated with the matching score. The matching score of the candidate Wasm module is determined based on the matching size and the continuity attenuation factor.
4. The conversion method according to claim 3, characterized in that, The step of determining the matching size of the candidate Wasm module based on the layer size of the target layer corresponding to the candidate Wasm module includes: The stability weight of each target layer is determined based on the historical reference count of each target layer corresponding to the candidate Wasm module, wherein the historical reference count refers to the number of times the target layer has been used to generate Wasm modules in history; The matching size of the candidate Wasm module is determined based on the layer size of each target layer corresponding to the candidate Wasm module and the stability weight of each target layer.
5. The conversion method according to claim 2, characterized in that, For each candidate Wasm module, the target layer of that candidate Wasm module is determined in the following way: The layer sequence of the target container image is matched layer by layer with the layer sequence of the container image corresponding to the candidate Wasm module. The layer in the layer sequence of the container image corresponding to the candidate Wasm module that meets the preset conditions is determined as the target layer. The preset conditions include: the layer has the same unique hash identifier as the corresponding layer in the target container image; and / or, the similarity of the layer content between the layer and the corresponding layer in the target container image is greater than a preset threshold.
6. The conversion method according to claim 5, characterized in that, The target layer of the candidate Wasm module is also determined by the following method: During the layer-by-layer matching process, the number of skipped layers that were not identified as the target layer between the identified target layers is determined; If the number of skipped layers exceeds a preset maximum number of skipped layers, the layer-by-layer matching process ends.
7. The conversion method according to claim 1, characterized in that, The difference data between the target container image and the first Wasm module includes at least one of the following: added data in the target container image relative to the first Wasm module; modified data in the target container image based on the first Wasm module; and deleted data in the target container image relative to the first Wasm module.
8. The conversion method according to claim 7, characterized in that, The difference data includes the modified data. Based on the difference data between the target container image and the first Wasm module, a second Wasm module is generated, including: Based on the file type of the modified data, determine the extraction method for extracting the modified data from the target container image; Based on the extraction method, the modified data is extracted from the target container image; The modified data is then converted into the second Wasm module.
9. The conversion method according to claim 1, characterized in that, The conversion method further includes: In response to receiving an update instruction for the target Wasm module, the object to be updated by the update instruction is determined; If the object to be updated includes the first Wasm module, the first Wasm module is redistributed according to the update instruction to update all Wasm modules that reference the first Wasm module, including the target Wasm module. If the object to be updated includes the second Wasm module, the second Wasm module is incrementally updated according to the update instruction to update the target Wasm module.
10. A container image conversion device, characterized in that, The conversion device includes: The determination unit is configured to determine the layering information of the target container image to be converted into a Wasm module; The matching unit is configured to determine, based on the hierarchical information, a first Wasm module that matches the target container image from a plurality of preset candidate Wasm modules; The first generation unit is configured to generate a second Wasm module based on the difference data between the target container image and the first Wasm module. The second generation unit is configured to generate a target Wasm module corresponding to the target container image based on the first Wasm module and the second Wasm module. The second generation unit is configured as follows: The presence of the first Wasm module in the locally cached container image's Wasm module is determined by the Wasm runtime. In response to the determination that the first Wasm module exists in the Wasm module of the locally cached container image, the first Wasm module is referenced and the second Wasm module is superimposed to generate the target Wasm module. In response to the determination that the first Wasm module does not exist in the Wasm module of the locally cached container image, the first Wasm module is obtained from a preset Wasm module library, and the second Wasm module is superimposed on the first Wasm module to generate the target Wasm module.
11. A computing device, characterized in that, The computing device includes: processor; Memory used to store executable instructions for a computer. When the computer-executable instructions are executed by the processor, they cause the processor to execute the container image conversion method according to any one of claims 1 to 9.
12. A computer-readable storage medium, characterized in that, When the instructions in the computer-readable storage medium are executed by the processor of a computing device, the computing device is able to perform the container image conversion method according to any one of claims 1 to 9.
13. A computer program product comprising computer-executable instructions, characterized in that, When the computer-executable instructions are executed by at least one processor, they implement the container image conversion method according to any one of claims 1 to 9.
Citation Information
Patent Citations
Container mirror image generation method and device, storage medium and electronic equipment
CN111045783A
Mirror image processing method and device and storage medium
CN113703786A