Memory resource allocation method, network cloud platform, computing device, computer readable storage medium and computer program product
By obtaining the virtual machine kernel loading address and querying the scanning parameters of the target database, the idle state of the virtual machine's memory resources is determined, which solves the problem in the existing technology that memory resource allocation affects the isolation and security of user virtual machines, and realizes imperceptible memory resource reallocation.
Patent Information
- Application Number
- CN202410289612.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-13
- Publication Date
- 2025-09-16
AI Technical Summary
In the prior art, memory resources are allocated by injecting a detection module into the user virtual machine to directly detect free physical pages, which destroys the isolation and security of the user virtual machine and affects performance.
By obtaining the kernel loading address of the client operating system, the kernel version of the virtual machine's memory resources is determined, and the target scanning range and scanning parameters of the physical page are queried from the host machine's target database. Based on these parameters, the virtual machine's memory resources are scanned, the target physical page in the idle state is determined, and the memory resource reallocation is completed.
It achieves effective utilization of memory resources without intruding into the user virtual machine, ensures the isolation and security of the user virtual machine, and avoids the impact on performance.
Smart Images

Figure CN120653411A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this specification relate to the field of cloud technology, and in particular to a memory resource allocation method, a network cloud platform, a computing device, a computer-readable storage medium, and a computer program product. Background Art
[0002] With the development of cloud technology, physical memory allocation and deallocation are often required in virtualized network cloud platforms to ensure that user virtual machines (VMs) can operate independently while meeting their memory requirements and improving memory resource utilization. A commonly used memory allocation and deallocation method currently uses a specific detection module injected into the user VM to directly detect idle physical pages pre-allocated to the VM and perform memory resource reallocation.
[0003] However, due to data security and user virtual machine performance considerations, it is impossible to directly detect or invade the user virtual machine in actual application scenarios, resulting in the ineffective use of memory resources.
[0004] Therefore, a safe memory resource allocation method is needed. Summary of the Invention
[0005] In view of this, embodiments of this specification provide a memory resource allocation method. One or more embodiments of this specification also relate to a network cloud platform, a memory resource allocation apparatus, a computing device, a computer-readable storage medium, and a computer program product to address technical deficiencies in the prior art.
[0006] According to a first aspect of an embodiment of this specification, a memory resource allocation method is provided, comprising:
[0007] Get the kernel loading address of the guest operating system;
[0008] Determining a kernel version corresponding to a virtual machine memory resource based on the kernel load address, wherein the virtual machine memory resource includes a plurality of pre-allocated physical pages, and the guest operating system is used to manage the virtual machine memory resource;
[0009] Based on the kernel version, querying target scanning ranges and target scanning parameters of multiple physical pages from a target database, wherein the target database is set in the host machine and pre-stores the scanning ranges and scanning parameters of the physical pages corresponding to each kernel version;
[0010] Scanning the virtual machine memory resources based on the target scanning range and the target scanning parameters to determine a target physical page in an idle state among the multiple physical pages;
[0011] Based on the target physical page, memory resource reallocation is performed.
[0012] According to a second aspect of an embodiment of this specification, a network cloud platform is provided, comprising a virtual machine memory resource and a resource scheduler; the virtual machine memory resource comprises a plurality of pre-allocated physical pages;
[0013] A resource scheduler is used to obtain the kernel loading address of the client operating system; based on the kernel loading address, determine the kernel version corresponding to the virtual machine memory resources, wherein the virtual machine memory resources include multiple pre-allocated physical pages, and the client operating system is used to manage the virtual machine memory resources; based on the kernel version, query the target scanning range and target scanning parameters of multiple physical pages from the target database, wherein the target database is set in the host machine, and the target database pre-stores the scanning range and scanning parameters of the physical pages corresponding to each kernel version; based on the target scanning range and target scanning parameters, scan the virtual machine memory resources to determine the target physical page that is in an idle state among the multiple physical pages; based on the target physical page, perform memory resource reallocation.
[0014] According to a third aspect of an embodiment of this specification, a memory resource allocation device is provided, comprising:
[0015] an acquisition module configured to obtain a kernel loading address of a client operating system;
[0016] a determination module configured to determine a kernel version corresponding to a virtual machine memory resource based on a kernel load address, wherein the virtual machine memory resource includes a plurality of pre-allocated physical pages, and a guest operating system is used to manage the virtual machine memory resource;
[0017] a query module configured to query a target scan range and target scan parameters of a plurality of physical pages from a target database based on the kernel version, wherein the target database is provided in the host machine and pre-stores the scan range and scan parameters of the physical pages corresponding to each kernel version;
[0018] a scanning module configured to scan the virtual machine memory resources based on a target scanning range and target scanning parameters, and determine a target physical page in an idle state among the plurality of physical pages;
[0019] The allocation module is configured to perform memory resource reallocation based on the target physical page.
[0020] According to a fourth aspect of the embodiments of this specification, there is provided a computing device, including:
[0021] memory and processor;
[0022] The memory is used to store computer programs / instructions, and the processor is used to execute the computer programs / instructions. When the computer programs / instructions are executed by the processor, the steps of the above-mentioned memory resource allocation method are implemented.
[0023] According to a fifth aspect of the embodiments of this specification, a computer-readable storage medium is provided, which stores a computer program / instruction, and when the program / instruction is executed by a processor, the steps of the above-mentioned memory resource allocation method are implemented.
[0024] According to a sixth aspect of the embodiments of this specification, a computer program product is provided, comprising a computer program / instruction, which implements the steps of the above-mentioned memory resource allocation method when executed by a processor.
[0025] One embodiment of the present specification obtains a kernel load address of a guest operating system; based on the kernel load address, determines a kernel version corresponding to virtual machine memory resources, wherein the virtual machine memory resources include multiple pre-allocated physical pages used by the guest operating system to manage the virtual machine memory resources; based on the kernel version, queries a target scan range and target scan parameters for multiple physical pages from a target database, wherein the target database is provided in a host machine and pre-stores the scan range and scan parameters for physical pages corresponding to each kernel version; based on the target scan range and target scan parameters, scans the virtual machine memory resources to determine a target physical page that is idle among the multiple physical pages; and performs memory resource reallocation based on the target physical page. The embodiment implements a method of obtaining a target scan range and target scan parameters corresponding to a user virtual machine based on the kernel version corresponding to the guest operating system from a database pre-stored with the scan range and scan parameters for physical pages corresponding to each kernel version, and then scans the virtual machine memory resources to determine the target physical page that is idle. This method achieves memory resource reallocation without the user virtual machine's awareness while avoiding intrusion into the user virtual machine, ensuring the isolation and security of the user virtual machine and avoiding performance impact on the user virtual machine. There is no need to invade the virtual machine, and effective utilization of memory resources is achieved while ensuring data security. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Figure 1 It is a process architecture diagram of a memory resource allocation method;
[0027] Figure 2 This is a flowchart of a memory resource allocation method provided by one embodiment of this specification;
[0028] Figure 3 This is a schematic diagram of a process architecture for building a database provided by an embodiment of this specification;
[0029] Figure 4 This is a schematic diagram of the process architecture of a memory resource allocation method provided by an embodiment of this specification;
[0030] Figure 5 This is a flowchart of a processing process of a memory resource allocation method for public cloud memory over-allocation provided by an embodiment of this specification;
[0031] Figure 6 This is a schematic diagram of the structure of a network cloud platform provided by an embodiment of this specification;
[0032] Figure 7 This is a structural diagram of a memory resource allocation device provided by an embodiment of this specification;
[0033] Figure 8 This is a structural block diagram of a computing device provided by one embodiment of this specification. DETAILED DESCRIPTION
[0034] The following description sets forth many specific details to facilitate a thorough understanding of this specification. However, this specification can be implemented in many other ways than those described herein, and those skilled in the art can make similar generalizations without violating the scope of this specification. Therefore, this specification is not limited to the specific implementations disclosed below.
[0035] The terms used in one or more embodiments of this specification are for the purpose of describing specific embodiments only and are not intended to limit one or more embodiments of this specification. The singular forms "a," "the," and "the" used in one or more embodiments of this specification and the appended claims are also intended to include plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used in one or more embodiments of this specification refers to and includes any or all possible combinations of one or more associated listed items.
[0036] It should be understood that although the terms first, second, etc. may be used to describe various information in one or more embodiments of this specification, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of one or more embodiments of this specification, the first may also be referred to as the second, and similarly, the second may also be referred to as the first. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".
[0037] In addition, it should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in one or more embodiments of this specification are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0038] First, the terms involved in one or more embodiments of this specification are explained.
[0039] Operating System (OS): It is the core software layer of a computer system, responsible for managing and controlling computer hardware and software resources, providing services to users and executing applications.
[0040] Virtual Machine (VM): Also referred to as a user virtual machine in one or more embodiments of this specification, a software-simulated computer system that can simulate one or more complete, independently running operating system environments on a physical computer system. In a user virtual machine, hardware resources at the software level, such as the core processor (CPU), memory, hard disk, network interface, etc., are virtualized, so that each user virtual machine can run an operating system and application programs like a real physical computer without affecting each other. Through virtualization technology, a physical host can run multiple different user virtual machines at the same time, and each user virtual machine can have an independent operating system, application program, and configuration, greatly improving the utilization rate of hardware resources and the flexibility of the system.
[0041] Host operating system (Host or Host OS): In a virtualized environment, the host operating system refers to the operating system running on the actual physical hardware. It is responsible for managing and controlling physical resources and providing services to user virtual machines through virtualization technology.
[0042] Guest operating system (Guest or guest OS): In a virtualized environment, a guest operating system refers to an operating system instance that runs in a host operating system through virtualization technology. A user virtual machine is the embodiment of a guest operating system running in a virtualized environment.
[0043] Direct Memory Access (DMA): A technology that allows hardware devices (such as disk controllers, network cards, etc.) to bypass the CPU and directly read and write system memory to improve data transmission speed and CPU efficiency.
[0044] Hypervisor (resource scheduler, or virtual machine monitor): is a key component of virtualization technology. It runs under or above the host operating system, is responsible for creating and managing user virtual machines, and provides virtual hardware resources to the client operating system.
[0045] Memory over-commitment: This refers to the situation where the total amount of memory allocated to each user VM in a virtualized environment exceeds the total amount of memory resources actually provided by the host operating system. Through proper scheduling and memory reuse technology, the physical memory limit can be exceeded for a short period of time.
[0046] IO Page Fault (IO Page Fault, abbreviated as IOPF) occurs in a virtualized environment when an I / O (Input / Output) device attempts to access memory that is not in physical memory or is incorrectly mapped through DMA. This may cause problems such as memory conflicts, high complexity, and unsafe access.
[0047] Memory Management Unit (MMU): A hardware component integrated into the CPU of modern computer systems that is responsible for translating virtual memory addresses into physical memory addresses. It performs address translation by parsing and searching the memory page table, ensuring that processes can only access authorized memory areas and assisting the operating system in implementing memory protection and memory paging mechanisms.
[0048] The user virtual address (GuestVirtualAddress, referred to as GVA) is the memory address used inside the user virtual machine, which actually needs to be mapped to the host virtual address through virtualization technology.
[0049] Guest Physical Address (GPA): It is the "physical" memory address seen from the perspective of the user virtual machine, and actually needs to be mapped to the host physical address through virtualization technology.
[0050] The host virtual address (HVA) refers to the memory address used within the host operating system, which needs to be converted into the actual physical address (HPA) through the MMU before accessing the physical memory.
[0051] Host Physical Address (HPA): It is the address on the actual physical memory chip and is the only real memory location that can be directly accessed.
[0052] It's important to note that in a virtualized environment, the primary memory address translation path is GVA->GPA->HPA. This GVA->GPA translation occurs within the user VM, using the VM's own memory management unit (MMU) in conjunction with the VM's memory page tables. The guest operating system converts GVA to GPA, a process that occurs within the VM.
[0053] Physical Page: A physical page is the fundamental unit of computer memory management, a fixed-size block used by the operating system to partition and manage physical memory. In most modern computer systems, a physical page is typically 4KB or larger (e.g., 2MB, 1GB, etc.), and all physical memory is divided into a series of such pages. The operating system uses a page frame number (PFN) to identify the exact location of each physical page in physical memory.
[0054] Memory Page Table: The memory page table is a key data structure used by the operating system to implement the virtual memory system. It records the mapping between virtual address space and physical address space. Each process has its own independent page table. Each entry in the page table (called a page table entry, PTE) corresponds to a page in the virtual address space and contains the physical page address corresponding to the virtual page, as well as related permission bits and other control information. When the CPU initiates an access to a virtual address, the MMU will query the memory page table to find the corresponding physical address. This process is called address translation.
[0055] Extended Page Table (EPT): A hardware-assisted, two-level page table mechanism, particularly suitable for virtualization environments. In virtualization scenarios, EPT allows the hypervisor to maintain an independent, hardware-backed page table structure for each guest operating system (guest OS), thereby achieving efficient translation from user-physical addresses to host-physical addresses.
[0056] Executable and Linkable Format (ELF): A widely used file format, primarily used in Unix-like operating systems (including Linux, Solaris, FreeBSD, etc.), for representing executable files, object code, shared libraries, and core dumps. This file format is designed to be flexible and extensible to support a variety of processor architectures and operating system features.
[0057] Embedded kernel image file VmLinux: The executable file generated after the Linux kernel is compiled, which contains the complete kernel code and symbol table information.
[0058] MD5, or Message Digest Algorithm 5, is a widely used hash function, often used for data integrity verification and digital signatures. The MD5 algorithm converts data of any length (such as text or files) into a fixed-length 128-bit hash value (usually represented as 32 hexadecimal digits). This hash value can be used to verify data integrity.
[0059] Kernel address space layout randomization (kaslr): During the kernel startup phase, a random value is obtained and the kernel load address is randomly offset accordingly to improve the security of the kernel.
[0060] Page Middle Directory (PMD): A page table entry with a 2M granularity.
[0061] The control register containing the physical memory base address of the page directory table: that is, the Control register 3 register, referred to as the CR3 register.
[0062] At present, in order to resolve the contradiction between direct memory access and flexible memory allocation, a specific detection module is injected into the user virtual machine to directly detect the physical pages pre-allocated to the user virtual machine in an idle state and complete the reallocation of memory resources. Figure 1 As shown, Figure 1 A schematic diagram of the process architecture of a memory resource allocation method is shown below:
[0063] The detection module is pre-injected into the client operating system, and the detection module transmits the detected data to the data manager of the detection module in the host operating system through the application programming interface.
[0064] The detection module obtains the client operating system's physical page metadata (the user physical address range recorded in the physical page structure) and the parsing strategy. Based on the physical page metadata layout, the user virtual memory start and end addresses are determined and passed to the detection module's data manager via an application programming interface. The parsing strategy source code is compiled to generate binary code, which is then passed to the detection module's data manager via an application programming interface.
[0065] In the host operating system's detection module's data manager, the parsing policy's binary code is verified using the parsing policy's verifier. Once verified, storage is completed. The physical page metadata range (the user physical address range of the physical page's structure information) is converted to user physical page metadata (the host virtual address range of the physical page's structure information), completing the memory reclamation setup.
[0066] The host operating system's memory reclamation routine scans the user's physical page metadata and uses a corresponding parsing strategy to determine whether the physical page is the target, idle physical page. For the target physical page, the memory management unit's memory page table and input / output memory page table are adjusted, and the extended memory page table of the physical page metadata is adjusted to protect the target physical page.
[0067] When a system event triggers a request to access the target physical page, the physical page metadata is accessed first. This triggers a page fault in the extended memory page table to the resource scheduler. The resource scheduler simultaneously handles the page fault in the extended memory page table and swaps back the corresponding physical page, avoiding the contradiction between direct memory access and flexible memory allocation, and avoiding problems such as memory conflicts, high complexity, and non-secure access.
[0068] However, the above method injects a specific detection module into the user virtual machine and directly invades the user virtual machine, which will destroy the isolation and security of the user virtual machine in the network cloud platform. In addition, the injected detection module will affect the performance of the user virtual machine.
[0069] In response to the above problems, this specification provides a memory resource allocation method. This specification also involves a network cloud platform, a memory resource allocation device, a computing device, a computer-readable storage medium and a computer program product, which are described in detail one by one in the following embodiments.
[0070] See also Figure 2 , Figure 2 A flowchart of a memory resource allocation method provided according to an embodiment of this specification is shown, which specifically includes the following steps.
[0071] Step 202: Obtain the kernel loading address of the guest operating system.
[0072] The embodiments of this specification apply to a component unit with memory resource allocation functionality. This component unit is software that can be embedded within a network cloud platform, such as a network cloud platform resource scheduler responsible for virtual machine resource scheduling, or externally located outside the network cloud platform, such as a third-party memory resource monitoring and optimization component unit that interacts with the cloud platform via an API. This component unit can directly detect virtual machine memory resources, obtain virtual machine kernel information, and based on this, parse the virtual machine kernel information and scan the virtual machine memory resources, identify target physical pages that are in an idle state, and then redistribute memory resources to the target physical pages.
[0073] A guest operating system (GOS) is an operating system that runs on a virtual machine (VM). It allows users to manage and use computing resources within the VM. GOSs can come in various flavors, such as Linux and Unix, and interact with the host machine and manage resources within the VM environment.
[0074] The kernel load address is the address at which the guest operating system's kernel is loaded into memory. When the operating system boots, its kernel is loaded into a specific memory location known as the kernel load address. The kernel load address is crucial for system operation and memory management because, during operation, the operating system uses the kernel load address to access and execute code and data within the kernel. Normally, the kernel load address is 0xffffffff81000000.
[0075] Specifically, the kernel loading address can be obtained in the following ways: When compiling the Linux kernel, a kernel image file System.map, also called the kernel symbol table, is generated. The kernel symbol table is a mapping that maps the address in the kernel code segment to the corresponding function name or global variable name. By parsing the kernel symbol table, the kernel loading address can be obtained; parse the vmLinux file through nm (a specific file analysis tool that comes with Linux), objdump (a binary file analysis tool) or readelf (a tool for viewing ELF command lines) to obtain the kernel loading address; obtain the kernel loading address through the / proc / kallsyms command. / proc / kallsyms is a virtual file dynamically generated by the running kernel, which reflects the status of the currently running kernel; obtain the kernel loading address through the kernel interface.
[0076] For example, taking the method of parsing vmLinux files as an example, usually, the vmLinux file will carry a matching System.map file, which contains kernel symbol table information. In the System.map file, look for a symbol named _text, which usually represents the starting address of the kernel code segment, that is, the kernel loading address, which is usually 0xffffffff81000000.
[0077] Through the above steps, the kernel loading address of the guest operating system can be obtained, providing the necessary information basis for determining the kernel version of the user virtual machine.
[0078] Step 204: Based on the kernel loading address, determine the kernel version corresponding to the virtual machine memory resources, wherein the virtual machine memory resources include a plurality of pre-allocated physical pages, and the guest operating system is used to manage the virtual machine memory resources.
[0079] Virtual machine memory resources are pre-allocated to user virtual machines. These resources are allocated from the host machine's (physical machine's) memory resources and are used to create and run user virtual machines. Virtual machine memory resources consist of multiple physical pages. For example, if 2GB of the host machine's 4GB of memory is pre-allocated to a user virtual machine, this 2GB of memory is considered virtual machine memory.
[0080] The kernel version is the kernel version number, used to identify and manage the version of the virtual machine operating system kernel. Kernel version numbers typically consist of a series of numbers and periods. For example, the Linux kernel version number format is xyz, where x represents the major version number, y represents the minor version number, and z represents the revision number.
[0081] Changes in kernel version numbers typically reflect kernel code updates, feature improvements, and bug fixes. Different kernel versions may introduce new features, optimize performance, enhance security, or fix known issues. In a virtual machine environment, the kernel version number can be used to determine kernel features and supported functions, which in turn influences the management and scheduling of virtual machine memory resources. In the Linux kernel, the struct page structure represents a physical page in memory. With kernel version updates, the definition of the struct page structure may change to accommodate new features, optimize performance, or fix issues. Therefore, different kernel versions correspond to different versions of the struct page structure, which can be parsed and operated based on the specific kernel version. Generally speaking, the struct page structure contains attributes or information such as the physical page's parsed address and parsed range. Different kernel versions may introduce new member variables, modify the definitions of existing member variables, or adjust the structure's layout. These changes affect the struct page parsing strategy.
[0082] A physical page is the basic operating unit of virtual machine memory resources. It is the basic unit of independently allocated memory in memory allocation and a user physical page metadata. Physical page sizes include, but are not limited to, 4KB, 2MB, and 4MB. During the creation of a user virtual machine (i.e., during the allocation of virtual machine memory resources), each physical page is mapped to a different virtual memory address in the user virtual machine, enabling the conversion of virtual memory addresses to physical memory addresses. For example, if 2GB of virtual machine memory resources is divided into 4KB physical pages (number of physical pages = 2 * 1024 * 1024KB / 4KB), the resulting number is 524,288 physical pages.
[0083] Specifically, after the kernel is loaded into memory, the hypervisor can access the kernel load address in memory to extract the loaded kernel's specific code information. This includes the kernel's core code, such as the subsystems and submodules described in the Linux kernel's overall architecture analysis notes, as well as supporting subsystems like power management and Linux initialization; libraries, firmware collections, compilation scripts, configuration files, help documentation, copyright notices, and other auxiliary files. This kernel code information can be used to determine the current kernel version.
[0084] For example, after obtaining the kernel loading address, starting from the kernel loading address, the specific code information of the kernel is obtained. This code information may include the current kernel version number, or the update features in the kernel code information are extracted to determine which updates the current kernel has undergone and which kernel version it is in.
[0085] Different kernel versions have different physical page scanning ranges and scanning parameters. Kernel version identification provides a basis for subsequently using the kernel version as an external query identifier to obtain the target scanning range and scanning parameters recorded in the target database.
[0086] Step 206: Based on the kernel version, query the target scanning range and target scanning parameters of multiple physical pages from the target database, wherein the target database is set in the host machine and pre-stores the scanning range and scanning parameters of the physical pages corresponding to each kernel version in the target database.
[0087] The target scanning range of multiple physical pages is a parameter corresponding to the kernel version used to characterize the memory address range of multiple physical pages in the virtual memory resource, which is the kernel information of the physical page, including but not limited to: the starting address and / or the ending address. For example, in the Linux system, the starting address of the virtual memory address range used to characterize the structural information of the physical page is: VMEMMAP_START, and the ending address of the virtual memory address range used to characterize the structural information of the physical page is: VMEMMAP_END. Generally, the kernel reserves a specific virtual memory area to store the structural information of the physical page. The starting address of this area may be VMEMMAP_START, and the ending address may be VMEMMAP_END. By querying these two addresses, the resource scheduler or memory management component can determine the memory range that should be traversed and analyzed.
[0088] The target scanning parameters for multiple physical pages are parsing parameters corresponding to the kernel version used to parse and obtain the status parameters of multiple physical pages, including but not limited to: target parsing strategy and memory management mechanism parameters. The target parsing strategy is used to parse and understand the data structure of the physical page status in the kernel information. For example, the size of the structure information struct page is determined by using page to parse whether the structure information strcut page represents a free page. The memory management mechanism parameters involve the access control bits of the page table entry, the swap space strategy, the memory fragmentation handling rules, etc., which are used to determine which physical pages meet the free state criteria.
[0089] The target database is a database set up on the host machine that stores the physical page scan ranges and parameters for each kernel version. In a virtualized environment, the target database provides reference data for virtual machine management and resource allocation, enabling appropriate operations based on specific kernel versions and needs. The target database can regularly update and manage the physical page scan ranges and parameters for each kernel version to adapt to new kernel releases or changes in specific requirements.
[0090] Specifically, the hypervisor determines the kernel version of the user virtual machine kernel that needs to be queried based on the kernel version number of the virtual machine running; the hypervisor initiates a query request to the target database, and retrieves the target scanning range and target scanning parameters of the physical pages corresponding to the kernel version stored in the target database by specifying the target kernel version number as the query condition; optionally, the hypervisor receives the data returned by the target database, parses the query results, and extracts the scanning range and scanning parameters of some target physical pages for subsequent memory resource scanning and management.
[0091] For example, assuming that the kernel version number running on user virtual machine A is 3.10.0, the hypervisor initiates a query request to the target database based on the kernel version number 3.10.0 of user virtual machine A, requesting to retrieve the target scanning range and target scanning parameters of the physical pages corresponding to the kernel version; after receiving the query request, the target database retrieves the physical page target scanning range and target scanning parameter data corresponding to the kernel version stored in the database based on the provided kernel version number 3.10.0, and returns the physical page target scanning range and target scanning parameter data for kernel version 3.10.0 to the hypervisor; optionally, after receiving the data returned by the target database, the hypervisor parses the query results and extracts the scanning range and parameters of some target physical pages for subsequent memory resource management.
[0092] Through the above steps, the target scanning range and target scanning parameters of the physical page can be accurately queried from the target database based on the kernel version, avoiding intrusion into the user virtual machine, ensuring the isolation and security of the user virtual machine, and avoiding performance impact on the user virtual machine.
[0093] Step 208: Scan the virtual machine memory resources based on the target scanning range and the target scanning parameters to determine a target physical page in an idle state among the multiple physical pages.
[0094] A target physical page is a physical page that is not allocated to any process and is in an idle state. In the idle state, a physical page does not carry any process's data or instructions and is not mapped to any virtual address space in the virtual machine system. It can be reallocated to other virtual machines and their processes in the host operating system. For example, of the 1,000 physical pages pre-allocated to multiple user virtual machines, 200 physical pages are not currently occupied by any process and are the target physical pages. When a process in a virtual machine requests additional memory resources, these 200 idle target physical pages can be reallocated to the process of the virtual machine requesting additional memory resources.
[0095] Based on the scanning range and scanning parameters, the virtual machine memory resources are scanned to determine the target physical page in the idle state among multiple physical pages. The specific method is as follows: based on the scanning range and scanning parameters, the virtual machine memory resources are scanned to determine the status parameters of multiple physical pages; based on the status parameters of multiple physical pages, the target physical page in the idle state among multiple physical pages is determined.
[0096] Exemplarily, based on the scanning range and scanning parameters of the structure information structpage of 524288 physical pages, the virtual machine memory resource Guest Memory is scanned to determine the status parameters of multiple physical pages, and based on the status parameters of the 524288 physical pages, the target physical page free guestpage that is in an idle state among the 524288 physical pages is determined.
[0097] Exemplarily, based on the target scanning range and target scanning parameters, the virtual machine memory resource GuestMemory is scanned page by page, starting from the starting address where the first physical page among 524288 physical pages is mapped, and the status of each virtual memory page is checked in turn according to the step size of each physical page. For each virtual memory page, the corresponding physical page status is determined by querying the corresponding virtual memory mapping table. During the scanning process, the target physical page freeguestpage in the idle state is recorded.
[0098] Based on the scan range and scan parameters, the virtual machine memory resources are scanned to determine the target physical page that is idle among multiple physical pages. This provides support for subsequent memory resource reallocation by determining the target physical page that is idle.
[0099] Step 210: Execute memory resource reallocation based on the target physical page.
[0100] Based on the target physical page, memory resource reallocation is performed, specifically by modifying the memory page table of the target physical page based on the target physical page, wherein the memory page table includes but is not limited to: a memory page table of a memory management unit and an input / output memory page table.
[0101] Exemplarily, based on the target physical page free guestpage, a memory page table MMUPage Table and an input / output memory page table I / O Page Table of the memory management unit of the target physical page free guestpage are modified.
[0102] In an embodiment of the present specification, a kernel loading address of a guest operating system is obtained; based on the kernel loading address, a kernel version corresponding to a virtual machine memory resource is determined, wherein the virtual machine memory resource includes a plurality of pre-allocated physical pages used by the guest operating system to manage the virtual machine memory resource; based on the kernel version, a target scan range and target scan parameters for the plurality of physical pages are queried from a target database, wherein the target database is provided in a host machine and pre-stored with scan ranges and scan parameters for physical pages corresponding to each kernel version; based on the target scan range and target scan parameters, the virtual machine memory resource is scanned to determine a target physical page that is idle among the plurality of physical pages; and memory resource reallocation is performed based on the target physical page. The invention implements a method for obtaining a target scan range and target scan parameters corresponding to a user virtual machine based on the kernel version corresponding to the guest operating system from a database pre-stored with scan ranges and scan parameters for physical pages corresponding to each kernel version, and then performing a scan of the virtual machine memory resource to determine a target physical page that is idle. This method achieves memory resource reallocation without the user virtual machine being aware of the reallocation while avoiding intrusion into the user virtual machine, thereby ensuring the isolation and security of the user virtual machine and avoiding any performance impact on the user virtual machine. There is no need to invade the virtual machine, and effective utilization of memory resources is achieved while ensuring data security.
[0103] In an optional embodiment of this specification, step 202 includes the following specific steps:
[0104] Based on the guest operating system, identifying the layout pattern of the kernel address space of the guest operating system and obtaining the starting address of the page table of the kernel address space;
[0105] Based on the layout mode and the page table start address, the kernel load address is determined.
[0106] The kernel address space layout mode, namely kaslr, is designed to improve the security of the kernel by randomly loading the kernel to different physical addresses for execution. After the kernel boots and decompresses, it will determine whether to randomize the physical address where the kernel is loaded and the virtual address where the kernel is running by judging whether the kaslr command line parameter is enabled.
[0107] The starting address of the page table is the kernel loading address when kaslr is not enabled, usually 0xffffffff81000000.
[0108] Specifically, the hypervisor can determine the kernel address space layout mode by parsing the kernel symbol table and determining whether the kaslr command line parameter is enabled. If enabled, the layout mode is random; if not, the layout mode is fixed. In fixed mode, the kernel load address is typically 0xffffffff81000000, which can be obtained by parsing the symbol table. Different layout modes result in different kernel load addresses. In fixed mode, the kernel load address is the page table start address; in random mode, the kernel load address is the page table start address + offset.
[0109] Based on this, the hypervisor can accurately determine the loading address of the guest operating system kernel according to the kernel address space layout mode and page table starting address of the guest operating system, providing a basis for subsequent determination of the kernel version.
[0110] In an optional embodiment of the present specification, determining the kernel loading address based on the layout mode and the page table starting address includes the following specific steps:
[0111] When the layout mode is fixed mode, the page table start address is determined as the kernel loading address.
[0112] Fixed mode, that is, the mode of closing kaslr.
[0113] Specifically, the hypervisor parses the kernel symbol table and determines that the kaslr command line parameter is not enabled, then the layout mode is fixed. In fixed mode, the kernel load address is usually the starting address of the page table.
[0114] Exemplarily, in fixed mode, if the page table start address is 0xffffffff81000000, the kernel loading address is 0xffffffff81000000.
[0115] Based on this, the hypervisor can accurately determine the loading address of the guest operating system kernel when the kernel address space layout mode of the guest operating system is fixed, providing a basis for subsequent determination of the kernel version.
[0116] In an optional embodiment of the present specification, determining the kernel loading address based on the layout mode and the page table starting address includes the following specific steps:
[0117] When the layout mode is random mode, based on the page table starting address, the page table entry mapping check is performed according to the preset step size to obtain the target address where the target page table entry mapping exists;
[0118] Based on the target address and the page table start address, the kernel load address is determined.
[0119] The default step size is the granularity of page table construction, for example, 2MB. Every preset step size corresponds to a page table. The starting position of page table construction is the first mapped physical page of the default step size. If kaslr is enabled, the starting position of page table construction is the page table start address + kaslr offset.
[0120] Therefore, we can intercept the page table in the CR3 register in the guest operating system, and then start from the starting address of the page table and perform a page table entry mapping check according to the preset step size to find the target address where the target page table entry is mapped. The first mapped page table entry is the target page table entry, and the starting address of the target page table entry is the target address. Through the target address and the starting address of the page table, we can calculate the kaslr offset, and further calculate the kernel loading address in random mode.
[0121] For example, take the page table starting address as 0xffffffff81000000 and the preset step length as 2M as an example. Define the starting address of the page table establishment, that is, the starting address of the first mapped 2MB page as 0xffffffff81000000+KASLR_OFFSET, where KASLR_OFFSET is the offset value. By intercepting the page table in the CR3 register of the guest OS, starting from 0xffffffff81000000, the page table entry mapping is performed according to the step length of 2MB to check the first mapped PMD. The address corresponding to this PMD is then subtracted by 0xffffffff81000000 to obtain the specific value of KASLR_OFFSET: Based on KASLR_OFFSET, the kernel load address after obtaining the offset is calculated.
[0122] Based on this, the hypervisor can accurately determine the loading address of the guest operating system kernel when the kernel address space layout mode of the guest operating system is random, providing a basis for subsequent determination of the kernel version.
[0123] In an optional embodiment of this specification, step 204 includes the following specific steps:
[0124] Based on the kernel loading address, parse the virtual machine kernel image and obtain the target kernel field;
[0125] Perform encryption calculation on the target kernel field to obtain target encryption information;
[0126] Based on the target encryption information, the kernel version corresponding to the virtual machine resource is matched from the preset verification database.
[0127] A virtual machine kernel image is an image file of the operating system kernel within a virtual machine. It typically contains the kernel code, data, and related configuration information, and is a core component of the virtual machine's operation. The target kernel field contains the specific code information of the loaded kernel, including the kernel core code, such as the subsystems and submodules described in the Linux kernel overall architecture analysis notes, as well as other supporting subsystems such as power management and Linux initialization; libraries, firmware collections, and auxiliary files such as compilation scripts, configuration files, help documents, and copyright notices. This kernel code information can be used to determine the current kernel version.
[0128] The target encryption calculation is a check value or a check identifier obtained after encryption calculation is performed on the target kernel field. The encryption calculation can be performed using a method such as MD5.
[0129] Pre-set verification database: This database stores the correspondence between target encryption information and different kernel versions. This database can be the same as the target database. The pre-set verification database is constructed by performing encryption calculations based on the kernel fields of all pre-obtained kernel versions to obtain encryption information, and then associates and stores each encryption with the corresponding kernel version.
[0130] Specifically, based on the known kernel load address, the hypervisor extracts the specific code information of the loaded kernel, namely the target kernel field. After extracting the target kernel field, the hypervisor performs encryption calculations on it, processing it using a specific encryption algorithm and key to generate target encrypted information. Based on this target encrypted information, the hypervisor matches it with a preset verification database, which stores information such as signature codes and version numbers corresponding to various kernel versions. The system compares the target encrypted information with the information in the database to determine the kernel version corresponding to the virtual machine resources.
[0131] For example, based on the known kernel load address 0xffffffff81000000, the target kernel field is obtained and MD5 encryption is performed on the target kernel field, generating the MD5 hash value: 342c0b644fa388286977e01168dc0a07. The verification database is searched for an entry corresponding to "342c0b644fa388286977e01168dc0a07". If a matching MD5 hash value is found in the verification database, the corresponding kernel version number has been found, such as "Linux Kernel Version: 3.10.0".
[0132] Different kernel versions have different physical page scanning ranges and scanning parameters. Kernel version identification provides a basis for subsequently using the kernel version as an external query identifier to obtain the target scanning range and scanning parameters recorded in the target database.
[0133] In an optional embodiment of the present specification, performing encryption calculation on the target kernel field to obtain target encryption information includes the following specific steps:
[0134] When the length of the target kernel field is greater than a preset length threshold, segmenting the target kernel field to obtain a plurality of segmented fields;
[0135] Perform encryption calculation on each segment field respectively to obtain the target encryption information corresponding to each segment field;
[0136] Based on the target encryption information, the kernel version corresponding to the virtual machine resource is matched from the preset verification database, including the following specific steps:
[0137] Based on the target encryption information corresponding to each segment field, multiple initial kernel versions are matched from a preset verification database;
[0138] Based on the multiple initial kernel versions, a kernel version corresponding to the virtual machine resource is determined.
[0139] Since the length of the target kernel field is variable, matching the target encryption information of the entire target kernel field will cause large overhead.
[0140] Specifically, when the length of the target kernel field is greater than a preset length threshold, it is segmented and divided into multiple smaller fields, such as 0-4K, 4-16K, 32-64K, and 128-256K. Then, encryption calculations are performed on each segmented field to obtain respective target encryption information. The segmented processing reduces the overhead of a single encryption calculation and improves efficiency. Based on the target encryption information corresponding to each segmented field, multiple possible initial kernel versions are matched from a preset verification database. The target encryption information of each segmented field is compared with the information in the database to find all possible matching kernel versions. Based on multiple initial kernel versions, the initial kernel version that meets all target encryption information is determined to be the kernel version corresponding to the final virtual machine resource.
[0141] For example, following the above example, the first field is 0-4K, and the first target encryption information is obtained after the MD5 encryption calculation is performed on the content in the first field, which corresponds to the matching of multiple first initial kernel versions in the preset verification database. The second field is 4-16K, and the second target encryption information is obtained after the MD5 encryption calculation is performed on the content in the second field, which corresponds to the matching of multiple second initial kernel versions in the preset verification database. The third field is 32-64K, and the third target encryption information is obtained after the MD5 encryption calculation is performed on the content in the third field, which corresponds to the matching of multiple third initial kernel versions in the preset verification database. The fourth field is 128-256K, and the fourth target encryption information is obtained after the MD5 encryption calculation is performed on the content in the fourth field, which corresponds to the matching of multiple fourth initial kernel versions in the preset verification database. The intersection of the multiple first initial kernel versions, the multiple second initial kernel versions, the multiple third initial kernel versions, and the multiple fourth initial kernel versions is determined as the kernel version corresponding to the final virtual machine resource.
[0142] This reduces computational overhead when the kernel field length is large, improving computational efficiency. By comparing the kernel version corresponding to the virtual machine resource with information in a pre-set verification database, the kernel version can be determined, enabling rapid and accurate kernel version identification. This solution, combining segmentation processing with encryption algorithms, effectively simplifies the kernel version identification process when the target kernel field length is long.
[0143] In an optional embodiment of the present specification, determining the kernel version corresponding to the virtual machine resources based on multiple initial kernel versions includes the following specific steps:
[0144] For any segmentation field, determining a common feature of multiple initial kernel versions corresponding to the segmentation field;
[0145] Based on the corresponding common features of the segment fields, among all the initial kernel versions, the initial kernel version that meets all the common features is determined as the kernel version corresponding to the virtual machine resource.
[0146] For example, using the above example, the first field is 0-4KB. An MD5 encryption calculation is performed on the content within the first field to obtain first target encrypted information, which corresponds to a match in the preset verification database for multiple first initial kernel versions that support specific hardware devices. The second field is 4-16KB. An MD5 encryption calculation is performed on the content within the second field to obtain second target encrypted information, which corresponds to a match in the preset verification database for multiple second initial kernel versions that use a specific scheduling algorithm. The third field is 32-64KB. An MD5 encryption calculation is performed on the content within the third field to obtain third target encrypted information, which corresponds to a match in the preset verification database for multiple third initial kernel versions that address known security vulnerabilities. The fourth field is 128-256KB. An MD5 encryption calculation is performed on the content within the fourth field to obtain fourth target encrypted information, which corresponds to a match in the preset verification database for multiple fourth initial kernel versions that are compatible with specific applications. Among the first, second, third, and fourth initial kernel versions, the initial kernel version that simultaneously meets the requirements of supporting specific hardware devices, using a specific scheduling algorithm, addressing known security vulnerabilities, and being compatible with specific applications is determined as the kernel version corresponding to the virtual machine resource.
[0147] In an optional embodiment of this specification, step 208 includes the following specific steps:
[0148] Based on the target scanning range, the virtual machine memory resources are scanned to obtain the structure information of multiple physical pages;
[0149] Based on the target scan parameter and the structure information of the plurality of physical pages, a target physical page in an idle state among the plurality of physical pages is determined.
[0150] The physical page structure is a structure used to manage physical pages. It is defined by the kernel of the virtual machine operating system and used in memory management. It is a type of physical page metadata. The physical page structure records structural parameters that characterize key attributes of the physical page, including but not limited to: page size, idle state, page index, and reference count. For example, in Linux, the physical page structure structpage is:
[0151]
[0152] Including structure parameters such as unsigned long flags (physical page flag), atomic_t_count (reference count), pgoff_tindex (index in the page frame array), union (possible mapping information or other uses).
[0153] Based on the target scan parameters and the structure information of multiple physical pages, a target physical page in an idle state among the multiple physical pages is determined. Specifically, based on the target scan parameters, the structure information of the multiple physical pages is parsed to determine the target physical page in an idle state among the multiple physical pages.
[0154] Exemplarily, based on the target scanning range (VMEMMAP_START; VMEMMAP_END) of the structure information struct page of 524288 physical pages, the virtual machine memory resource Guest Memory is scanned to obtain the structure information struct page of 524288 physical pages. Based on the target scanning parameters of the structure information struct page of 524288 physical pages, the structure information struct page of 524288 physical pages is parsed to determine the target physical page free guest page that is in an idle state among the 524288 physical pages.
[0155] In an embodiment of the present specification, based on the target scanning range, the virtual machine memory resources are scanned to obtain the structural information of multiple physical pages, and based on the target scanning parameters and the structural information of multiple physical pages, the target physical page in the idle state is determined among the multiple physical pages, and the target physical page in the idle state is accurately determined, providing accurate target physical page support for subsequent memory resource reallocation.
[0156] In an optional embodiment of this specification, the target scanning parameters include a target resolution strategy;
[0157] Determining a target physical page in an idle state among the multiple physical pages based on a target scan parameter and structure information of the multiple physical pages includes the following specific steps:
[0158] Use the target parsing strategy to parse the structure information of each physical page and obtain the structure parameters of each physical page;
[0159] Based on the structure parameters of each physical page, a target physical page in an idle state among the plurality of physical pages is identified.
[0160] Generally, when generating the structure information of a physical page, the virtual machine operating system may compile the physical page structure information, which is physical page metadata, and convert it into binary data and store it in the virtual machine memory resources. Therefore, it needs to be parsed to obtain the structure parameters of each physical page.
[0161] The physical page structure parameters represent key attributes of the physical page, including but not limited to: page size, free state, page index, and reference count. For example, in Linux, the physical page structure information struct page includes the following structure parameters: Physical page flags (flags): Definition: unsigned long flags; Description: Used to record various status information of the physical page, such as whether the physical page is free, allocated, involved in paging, and whether it contains cached data. Reference count (count): Definition: atomic_t_count; Description: Records the number of times the current physical page is referenced, used to determine whether the page is in use. When the reference count is 0, it generally means that the page can be safely reclaimed or reallocated. Page index (index): Definition: pgoff_tindex; Description: Indicates the position of the physical page in the page frame array, allowing the kernel to quickly locate and search for a specific physical page. Union (mapping) for mapping information or other purposes: Definition: union{...}mapping Description: Depending on the usage of the physical page, the union can store different information, such as a structure pointer associated with the file system address space, or other data related to physical page mapping. In addition, in order to determine whether the physical page is in an idle state, you also need to pay attention to the following structure parameters: Status parameters: For example: You can determine whether the page is available or idle by checking specific flag bits in struct page, such as PageLRU, PageSlab, PageFree, etc. Page mapping information (mapcount): Determine whether the page is mapped to any virtual address space. If mapcount is 0, it means that the physical page is not occupied by any process and is in an idle state. Private member (private): Determine the page size of the physical page through the member variable private.
[0162] The target parsing strategy is the parsing method used to parse the physical page status in the structure information. This strategy aims to extract the structure parameters representing the physical page status from the structure information. This strategy includes, but is not limited to, helper functions. Generally, different VM operating systems have different parsing strategies, which are recorded in the VM kernel information.
[0163] Exemplarily, target parsing strategy helper functions are used to parse the structure information structpage of 524288 physical pages, obtain the structure parameters of each physical page, and identify the target physical page free guestpage in the 524288 physical pages that is in an idle state based on the structure parameters of each physical page.
[0164] In the embodiments of this specification, a target parsing strategy is utilized to parse the structural information of each physical page, obtain the structural parameters of each physical page, and identify the target physical page in an idle state among multiple physical pages based on the structural parameters of each physical page. This more accurately determines the target physical page in an idle state, and provides more accurate target physical page support for subsequent memory resource reallocation.
[0165] In an optional embodiment of this specification, step 210 includes the following specific steps:
[0166] Reclaim the page table of the target physical page;
[0167] In response to the memory allocation request sent by the target virtual machine, a page table is reallocated for the target physical page.
[0168] Page table recycling is a memory management operation that completes physical page recycling through the memory page table. The specific operation is to delete the page table entry of the target physical page in the memory page table, so that the target physical page changes to an idle state and can be reallocated to other processes or virtual machines for use. Deleting the page table entry clears the mapping relationship of the target physical page in the virtual address space.
[0169] Page table reallocation is a memory management operation that completes physical page reallocation through the memory page table. The specific operation is to rebuild the page table entry of the target physical page in the memory page table, so that the target physical page is changed to an occupied state and can be used by other processes or virtual machines. Rebuilding the page table entry newly creates a mapping relationship between the target physical page in the virtual address space.
[0170] The target virtual machine may be a virtual machine to which virtual machine memory resources are pre-allocated, which is a case of memory over-allocation, or a new virtual machine that needs to be built, which is not limited here.
[0171] The page table of the target physical page is reclaimed by deleting the page table entry of the target physical page in the memory page table.
[0172] In response to the memory allocation request sent by the target virtual machine, a page table is reallocated for the target physical page, specifically by generating a page table entry of the target physical page in the memory page table in response to the memory allocation request sent by the target virtual machine.
[0173] Exemplarily, the page table entry of the target physical page free guestpage in the memory page table MMU Page Table of the memory management unit and the input / output memory page table I / OPage Table is deleted, and in response to the memory allocation request sent by the target virtual machine, the page table entry of the target physical page free guestpage is generated in the memory page table MMUPage Table of the memory management unit and the input / output memory page table I / O PageTable.
[0174] In the embodiments of this specification, memory resource redistribution is achieved through page table management, ensuring the consistency and security of user virtual machines.
[0175] In an optional embodiment of the present specification, before reclaiming the page table of the target physical page, the following specific steps are further included:
[0176] In the virtual machine memory address translation table, the access permission of the target physical page is set to an inaccessible state, wherein the virtual machine memory access table is a physical page table used by the virtual machine to perform memory address translation when accessing memory resources.
[0177] Generally, when the I / O device of a user virtual machine uses Direct Memory Access (DMA) to access the virtual machine's memory resources, the target physical page needs to be reallocated. If it can still be accessed by the user virtual machine, a memory conflict may occur, causing a direct memory access exception. When the user virtual machine needs to access the target physical page, it must first access its structure information. If the access permission of the target physical page is set to inaccessible in the virtual machine's memory address translation table, a page fault in the virtual machine's memory address translation table will be triggered, preventing the target physical page from being accessed.
[0178] The virtual machine memory access table is a physical page table used by the virtual machine to convert memory addresses when accessing memory resources. For example, in a Linux system, the virtual machine memory access table is an extended memory page table (EPT).
[0179] Exemplarily, in the virtual machine memory address translation table EPT, the access permission of the target physical page free guest page is set to an inaccessible state.
[0180] In the embodiments of the present specification, by setting the access rights of the target physical page in the virtual machine memory address translation table to an inaccessible state before the page table of the target physical page is recycled, potential memory conflict problems are effectively prevented, the safe recycling and reallocation of the target physical page is ensured, and the stability and reliability of the virtualization environment are enhanced.
[0181] See also Figure 3In the embodiment of this specification, an OS database is constructed to record the characteristics of different user virtual machines. Figure 3 This is a schematic diagram of a process architecture for building a database provided by an embodiment of this specification. Figure 3 As shown:
[0182] In the kernel of each kernel version of the virtual machine, by obtaining kernel information such as the kernel symbol table, compiled functions, and kernel image, the corresponding kernel encryption information, structure information, and parsing strategy are obtained based on each kernel information. The OS database is constructed based on the encryption information, structure information, and parsing strategy. Specifically,
[0183] First, the kernel information acquisition operation is performed on the virtual machine through the feature extraction tool to extract the kernel's corresponding symbol table, compiled function and vmLinux kernel image file.
[0184] Then, by parsing the symbol table corresponding to the kernel, the structure information of each physical page in the virtual machine is obtained; the kernel corresponding parsing strategy is exported in the kernel corresponding compilation function; by parsing the vmLinux kernel image file, the kernel field of the kernel is obtained, and then the kernel field is encrypted with MD5 to obtain the encrypted information.
[0185] Finally, an OS database is constructed based on the structural information, parsing strategy and encryption information corresponding to each kernel.
[0186] Figure 4 FIG. 1 shows a flow diagram of a memory resource allocation method provided by an embodiment of the present specification. Figure 4 As shown:
[0187] The network cloud platform includes virtual machine memory resources, resource scheduler and host operating system. The resource scheduler includes encryption module, scanning module and recycling module.
[0188] In the resource scheduler, based on the client operating system, the kernel loading address is obtained in the virtual memory resource; the encryption module is used to determine the kernel version corresponding to the virtual machine memory resource based on the kernel loading address, specifically including encrypting the kernel code information obtained based on the kernel loading address to obtain encrypted information, sending the encrypted information to the database in the host operating system, finding the kernel version matching the encrypted information in the database as the kernel version of the virtual machine memory resource: the scanning module is used to query the target scanning range and target scanning parameters of multiple physical pages from the target database based on the kernel version, and scan the virtual machine memory resources based on the target scanning range to obtain the structural information of multiple physical pages, and then determine the target physical page in the idle state among the multiple physical pages based on the target scanning parameters and the structural information of the multiple physical pages, and finally pass the target physical page information to the recycling module; the recycling module is used to recycle the page table of the target physical page on the memory page table of the memory management unit of the host operating system and the input / output memory page table.
[0189] The following combined Figure 5 , taking the application of the memory resource allocation method provided in this specification in the public cloud memory over-scaling scenario as an example, the memory resource allocation method is further explained. Figure 5 A flowchart of a method for allocating memory resources for public cloud memory over-allocation, provided in one embodiment of this specification, is shown. The method is applied to a resource scheduler of a public cloud platform and includes the following specific steps:
[0190] Step 502: Determine the loading address (kernel loading address) of the text section (kernel field) of the guest OS (virtual machine system).
[0191] Step 504: Calculate the MD5 (encrypted information) of the current guest, match it with the MD5 verification information recorded in the OS database (preset verification database), and determine the kernel version.
[0192] Specifically: For user virtual machines with kaslr disabled, since the load address of the guest OS's text section is a fixed value (0xffffffff81000000), the hypervisor can calculate the kernel version by performing MD5 calculation on the field starting from this fixed address and matching the MD5 checksum information recorded in the OS database.
[0193] In particular, since the kernel code information is of variable length, matching the entire kernel code information field with an MD5 query would be expensive. To reduce this overhead, we can select memory segments and calculate the MD5 in segments (e.g., 0-4K, 4-16K, 32-64K, 128-256K). This generates multiple segments of checksum information for comparison with the information in the database.
[0194] For user virtual machines with kaslr enabled, the loading address of the text section of the guest OS is no longer fixed, but an offset value is added. The specific process of obtaining the offset value includes: first, obtaining the page table of the kernel space of the user virtual machine. Generally speaking, the page table of the kernel space is established according to the granularity of 2MB; secondly, defining the starting address of the page table establishment, that is, the starting address of the first mapped 2MB page is 0xffffffff81000000+KASLR_OFFSET, where KASLR_OFFSET is the offset value; then, by intercepting the page table in the CR3 register of the guest OS, starting from 0xffffffff81000000, the first mapped PMD is checked according to the step length of 2MB, and the address corresponding to this PMD is subtracted by 0xffffffff81000000 to obtain the specific value of KASLR_OFFSET: based on KASLR_OFFSET, the offset text section load address is obtained, and the MD5 calculation is performed on the field starting from the offset text section load address, matching the MD5 check information recorded in the OS database, and the kernel version is inferred.
[0195] Step 506: Based on the kernel version, query the gueststruct page range (target scanning range) and parsing method (target scanning parameter) of multiple physical pages from the OS database (target database).
[0196] Step 508: Scan the guest struct page range and determine whether each page is a free guest page (target physical page) through a corresponding parsing method.
[0197] Step 510: Find the free guest page information through the scanned struct page (structure information) and pass it to the reclaimer (reclaiming module).
[0198] Step 512: In the virtual machine memory address translation table (EPT), the access permission of the target physical page (free guest page) is set to an inaccessible state.
[0199] Step 514: Reclaim the page table of the target physical page free guestpage.
[0200] Step 516: In response to the memory over-allocation request sent by the target virtual machine, reallocate a page table for the target physical page free guestpage.
[0201] Corresponding to the above method embodiment, this specification also provides a network cloud platform embodiment, Figure 6 FIG1 shows a schematic diagram of the structure of a network cloud platform provided by an embodiment of this specification. Figure 6 As shown, the network cloud platform includes a virtual machine memory resource 602 and a resource scheduler 604; the virtual machine memory resource 602 includes a plurality of pre-allocated physical pages.
[0202] The resource scheduler 604 is used to obtain the kernel loading address of the client operating system; based on the kernel loading address, determine the kernel version corresponding to the virtual machine memory resource 602, wherein the virtual machine memory resource 602 includes multiple pre-allocated physical pages; based on the kernel version, query the target scanning range and target scanning parameters of multiple physical pages from the target database, wherein the target database is set in the host machine, and the target database pre-stores the scanning range and scanning parameters of the physical pages corresponding to each kernel version; based on the target scanning range and target scanning parameters, scan the virtual machine memory resource 602 to determine the target physical page that is in an idle state among the multiple physical pages; based on the target physical page, perform memory resource reallocation.
[0203] In an optional embodiment of the present specification, the resource scheduler 604 is further used to scan the virtual machine memory resources 602 based on the target scanning range to obtain structural information of multiple physical pages; based on the scanning parameters and the structural information of the multiple physical pages, determine the target physical page that is in an idle state among the multiple physical pages.
[0204] In an optional embodiment of the present specification, the network cloud platform further includes a host operating system 606 .
[0205] The resource scheduler 604 is also used to set the access rights of the target physical page to an inaccessible state in the virtual machine memory address translation table recorded by the host operating system 606, wherein the virtual machine memory access table is a physical page table used by the virtual machine to perform memory address translation when accessing memory resources; and delete the page table entry of the target physical page in the memory page table recorded by the host operating system 606, wherein the memory page table includes the mapping relationship between the virtual memory address of the virtual machine and multiple physical pages.
[0206] In the embodiments of this specification, a resource scheduler, based on the kernel version corresponding to the client operating system, obtains the target scan range and target scan parameters corresponding to the user virtual machine from a database pre-stored with the physical page scan ranges and scan parameters corresponding to each kernel version. Based on this, the virtual machine's memory resources are scanned, and target physical pages that are in an idle state are determined. This achieves memory resource redistribution without intrusion into the user virtual machine, ensuring the isolation and security of the user virtual machine and minimizing performance impacts on the user virtual machine. This eliminates the need to intrude into the virtual machine, effectively utilizing memory resources while ensuring data security.
[0207] The above is a schematic scheme of a network cloud platform of this embodiment. It should be noted that the technical scheme of this network cloud platform and the technical scheme of the above-mentioned memory resource allocation method are based on the same concept. For details not described in detail in the technical scheme of the network cloud platform, please refer to the description of the technical scheme of the above-mentioned memory resource allocation method.
[0208] Corresponding to the above method embodiment, this specification also provides a memory resource allocation device embodiment, Figure 7 FIG. 1 shows a schematic diagram of the structure of a memory resource allocation device provided by an embodiment of this specification. Figure 7 As shown, the device includes:
[0209] An acquisition module 702 is configured to acquire a kernel loading address of a client operating system;
[0210] The determination module 704 is configured to determine the kernel version corresponding to the virtual machine memory resources based on the kernel load address, wherein the virtual machine memory resources include a plurality of pre-allocated physical pages, and the guest operating system is used to manage the virtual machine memory resources;
[0211] A query module 706 is configured to query a target scan range and target scan parameters for a plurality of physical pages from a target database based on the kernel version, wherein the target database is provided in the host machine and pre-stores the physical page scan range and scan parameters corresponding to each kernel version;
[0212] The scanning module 708 is configured to scan the virtual machine memory resources based on the target scanning range and the target scanning parameters, and determine a target physical page in an idle state among the multiple physical pages;
[0213] The allocation module 710 is configured to perform memory resource reallocation based on the target physical page.
[0214] Optionally, the acquisition module 702 is further configured to:
[0215] Based on the guest operating system, identifying the layout pattern of the kernel address space of the guest operating system and obtaining the starting address of the page table of the kernel address space;
[0216] Based on the layout mode and the page table start address, the kernel load address is determined.
[0217] Optionally, the acquisition module 702 is further configured to:
[0218] When the layout mode is fixed mode, the page table start address is determined as the kernel loading address.
[0219] Optionally, the acquisition module 702 is further configured to:
[0220] When the layout mode is random mode, based on the page table starting address, the page table entry mapping check is performed according to the preset step size to obtain the target address where the target page table entry mapping exists;
[0221] Based on the target address and the page table start address, the kernel load address is determined.
[0222] Optionally, the determination module 704 is further configured to:
[0223] Based on the kernel loading address, parse the virtual machine kernel image and obtain the target kernel field;
[0224] Perform encryption calculation on the target kernel field to obtain target encryption information;
[0225] Based on the target encryption information, the kernel version corresponding to the virtual machine resource is matched from the preset verification database.
[0226] Optionally, the determination module 704 is further configured to:
[0227] When the length of the target kernel field is greater than a preset length threshold, segmenting the target kernel field to obtain a plurality of segmented fields;
[0228] Perform encryption calculation on each segment field respectively to obtain the target encryption information corresponding to each segment field;
[0229] Based on the target encryption information corresponding to each segment field, multiple initial kernel versions are matched from a preset verification database;
[0230] Based on the multiple initial kernel versions, a kernel version corresponding to the virtual machine resource is determined.
[0231] Optionally, the scanning module 708 is further configured to:
[0232] Based on the target scanning range, the virtual machine memory resources are scanned to obtain the structure information of multiple physical pages;
[0233] Based on the target scan parameter and the structure information of the plurality of physical pages, a target physical page in an idle state among the plurality of physical pages is determined.
[0234] Optionally, the scanning module 708 is further configured to:
[0235] Determining a target physical page in an idle state among the multiple physical pages based on a target scan parameter and structure information of the multiple physical pages includes:
[0236] Use the target parsing strategy to parse the structure information of each physical page and obtain the structure parameters of each physical page;
[0237] Based on the structure parameters of each physical page, a target physical page in an idle state among the plurality of physical pages is identified.
[0238] Optionally, the allocation module 710 is further configured to:
[0239] Reclaim the page table of the target physical page;
[0240] In response to the memory allocation request sent by the target virtual machine, a page table is reallocated for the target physical page.
[0241] Optionally, the device further comprises:
[0242] The protection module is configured to set the access rights of the target physical page to an inaccessible state in the virtual machine memory address translation table, wherein the virtual machine memory access table is a physical page table used by the virtual machine to translate memory addresses when accessing memory resources.
[0243] In the embodiment of this specification, the acquisition module 702 obtains the kernel loading address, the determination module 704 determines the kernel version corresponding to the client operating system based on the kernel record address obtained by the acquisition module 702, and the query module 706 implements, based on the kernel version corresponding to the client operating system, querying a database that pre-stores the scanning range and scanning parameters of the physical pages corresponding to each kernel version to obtain the target scanning range and target scanning parameters corresponding to the user virtual machine. On this basis, the scanning module 708 completes the scanning of the virtual machine memory resources and determines the target physical pages that are in an idle state. This achieves the goal of avoiding intrusion into the user virtual machine while completing the memory resource redistribution through the allocation module 710 without the user virtual machine being aware of it, thereby ensuring the isolation and security of the user virtual machine and avoiding any impact on the performance of the user virtual machine. Without intruding into the virtual machine, efficient utilization of memory resources is achieved while ensuring data security.
[0244] The above is a schematic diagram of a memory resource allocation device according to this embodiment. It should be noted that the technical solution of the memory resource allocation device and the technical solution of the aforementioned memory resource allocation method are based on the same concept. For details not described in detail in the technical solution of the memory resource allocation device, please refer to the description of the technical solution of the aforementioned memory resource allocation method.
[0245] Figure 8 8. The block diagram of a computing device according to one embodiment of the present disclosure is shown. Components of the computing device 800 include, but are not limited to, a memory 810 and a processor 820. The processor 820 is connected to the memory 810 via a bus 830, and a database 850 is used to store data.
[0246] The computing device 800 also includes an access device 840 that enables the computing device 800 to communicate via one or more networks 860. Examples of these networks include a public switched telephone network (PSTN), a local area network (LAN), a wide area network (WAN), a personal area network (PAN), or a combination of communication networks such as the Internet. The access device 840 may include one or more of any type of network interface (e.g., a network interface card (NIC)) of wired or wireless, such as an IEEE 802.11 wireless local area network (WLAN) wireless interface, a Worldwide Interoperability for Microwave Access (Wi-MAX) interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth interface, or a Near Field Communication (NFC). In one embodiment of the present specification, the above components of the computing device 800 and Figure 8 Other components not shown in the figure may also be connected to each other, for example, via a bus. Figure 8 The computing device structure block diagram shown is for illustrative purposes only and is not intended to limit the scope of this specification. Those skilled in the art may add or replace other components as needed.
[0247] In one embodiment of the present specification, the above components of the computing device 800 and Figure 8Other components not shown in the figure may also be connected to each other, for example, via a bus. Figure 8 The computing device structure block diagram shown is for illustrative purposes only and is not intended to limit the scope of this specification. Those skilled in the art may add or replace other components as needed.
[0248] Computing device 800 can be any type of stationary or mobile computing device, including a mobile computer or mobile computing device (e.g., a tablet computer, personal digital assistant, laptop computer, notebook computer, netbook computer, etc.), a mobile phone (e.g., a smartphone), a wearable computing device (e.g., a smartwatch, smart glasses, etc.), or other types of mobile devices, or a stationary computing device such as a desktop computer or personal computer (PC). Computing device 800 can also be a mobile or stationary server.
[0249] The processor 820 is configured to execute the following computer program / instruction, which implements the steps of the above-mentioned memory resource allocation method when executed by the processor.
[0250] The above is a schematic diagram of a computing device according to this embodiment. It should be noted that the technical solution of the computing device and the technical solution of the above-mentioned memory resource allocation method are based on the same concept. For details not described in detail in the technical solution of the computing device, please refer to the description of the technical solution of the above-mentioned memory resource allocation method.
[0251] An embodiment of the present specification further provides a computer-readable storage medium storing a computer program / instruction. When the computer program / instruction is executed by a processor, the steps of the above-mentioned memory resource allocation method are implemented.
[0252] The above is a schematic diagram of a computer-readable storage medium according to this embodiment. It should be noted that the technical solution of this storage medium and the technical solution of the aforementioned memory resource allocation method are based on the same concept. For details not described in detail in the technical solution of the storage medium, please refer to the description of the technical solution of the aforementioned memory resource allocation method.
[0253] An embodiment of the present specification further provides a computer program product, including a computer program / instruction, which implements the steps of the above-mentioned memory resource allocation method when executed by a processor.
[0254] The above is an illustrative embodiment of a computer program product. It should be noted that the technical solution of this computer program product and the technical solution of the aforementioned memory resource allocation method share the same concept. For details not described in detail in the technical solution of the computer program product, please refer to the description of the technical solution of the aforementioned memory resource allocation method.
[0255] The foregoing description of this specification describes specific embodiments. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different from that described in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order shown or the sequential order to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0256] The computer program includes computer program code, which may be in source code form, object code form, executable file, or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal, and software distribution medium. It should be noted that the content contained in the computer-readable medium may be appropriately increased or decreased according to the requirements of patent practice. For example, in some regions, according to patent practice, computer-readable media do not include electric carrier signals and telecommunication signals.
[0257] It should be noted that for the aforementioned method embodiments, for the sake of simplicity of description, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the embodiments of this specification are not limited by the order of the actions described, because according to the embodiments of this specification, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the embodiments of this specification.
[0258] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0259] The preferred embodiments disclosed above are intended only to help illustrate this specification. The optional embodiments do not exhaustively describe all details, nor do they limit the invention to the specific embodiments described. Obviously, many modifications and variations can be made based on the content of the embodiments of this specification. This specification selects and specifically describes these embodiments in order to better explain the principles and practical applications of the embodiments of this specification, so that those skilled in the art can better understand and utilize this specification. This specification is limited only by the claims and their full scope and equivalents.
Claims
1. A memory resource allocation method, comprising: Get the kernel loading address of the guest operating system; Determining a kernel version corresponding to a virtual machine memory resource based on the kernel load address, wherein the virtual machine memory resource includes a plurality of pre-allocated physical pages, and the guest operating system is used to manage the virtual machine memory resource; Based on the kernel version, querying a target scanning range and target scanning parameters of the plurality of physical pages from a target database, wherein the target database is set in a host machine and pre-stores scanning ranges and scanning parameters of physical pages corresponding to each kernel version in the target database; Scanning the virtual machine memory resources based on the target scanning range and the target scanning parameters to determine a target physical page in an idle state among the multiple physical pages; Memory resource reallocation is performed based on the target physical page.
2. The method according to claim 1, wherein obtaining the kernel loading address of the guest operating system comprises: Based on a guest operating system, identifying a layout pattern of a kernel address space of the guest operating system, and obtaining a page table start address of the kernel address space; A kernel loading address is determined based on the layout mode and the page table start address.
3. The method according to claim 2, wherein determining the kernel load address based on the layout mode and the page table start address comprises: When the layout mode is a fixed mode, the page table start address is determined as the kernel loading address.
4. The method according to claim 2, wherein determining the kernel load address based on the layout mode and the page table start address comprises: When the layout mode is a random mode, performing a page table entry mapping check based on the page table start address according to a preset step size to obtain a target address where a target page table entry mapping exists; A kernel loading address is determined based on the target address and the page table start address.
5. The method according to any one of claims 1 to 4, wherein determining the kernel version corresponding to the virtual machine memory resource based on the kernel loading address comprises: Parsing the virtual machine kernel image based on the kernel loading address to obtain the target kernel field; Performing encryption calculation on the target kernel field to obtain target encryption information; Based on the target encryption information, a kernel version corresponding to the virtual machine resource is matched from a preset verification database.
6. The method according to claim 5, wherein performing encryption calculation on the target kernel field to obtain target encryption information comprises: When the length of the target kernel field is greater than a preset length threshold, segmenting the target kernel field to obtain a plurality of segment fields; Perform encryption calculation on each segment field respectively to obtain target encryption information corresponding to each segment field; The step of matching and obtaining a kernel version corresponding to the virtual machine resource from a preset verification database based on the target encryption information includes: Based on the target encryption information corresponding to each segment field, a plurality of initial kernel versions are matched from a preset verification database; Based on the multiple initial kernel versions, a kernel version corresponding to the virtual machine resource is determined.
7. The method according to any one of claims 1 to 4, wherein the scanning of the virtual machine memory resources based on the target scanning range and the target scanning parameters to determine a target physical page in an idle state among the multiple physical pages comprises: Scanning the virtual machine memory resources based on the target scanning range to obtain structure information of the multiple physical pages; Based on the target scan parameter and the structure information of the plurality of physical pages, a target physical page in an idle state among the plurality of physical pages is determined.
8. The method according to claim 7, wherein the target scanning parameters include a target resolution strategy; The step of determining a target physical page in an idle state among the multiple physical pages based on the target scan parameter and the structural information of the multiple physical pages includes: Utilizing the target parsing strategy, parsing the structure information of each physical page to obtain the structure parameters of each physical page; Based on the structural parameters of each physical page, a target physical page in an idle state among the plurality of physical pages is identified.
9. The method according to any one of claims 1 to 4, wherein performing memory resource reallocation based on the target physical page comprises: Reclaiming the page table of the target physical page; In response to the memory allocation request sent by the target virtual machine, a page table is reallocated for the target physical page.
10. The method according to claim 9, before reclaiming the target physical page, further comprising: In a virtual machine memory address translation table, the access permission of the target physical page is set to an inaccessible state, wherein the virtual machine memory access table is a physical page table used by the virtual machine to perform memory address translation when accessing memory resources.
11. A network cloud platform comprising virtual machine memory resources and a resource scheduler; the virtual machine memory resources comprising a plurality of pre-allocated physical pages; The resource scheduler is used to obtain the kernel loading address of the client operating system; based on the kernel loading address, determine the kernel version corresponding to the virtual machine memory resource, wherein, The virtual machine memory resources include multiple pre-allocated physical pages, and the client operating system is used to manage the virtual machine memory resources; based on the kernel version, the target scanning range and target scanning parameters of the multiple physical pages are queried from the target database, wherein the target database is set in the host machine, and the target database pre-stores the scanning range and scanning parameters of the physical pages corresponding to each kernel version; based on the target scanning range and the target scanning parameters, the virtual machine memory resources are scanned to determine the target physical page in the multiple physical pages that is in an idle state; based on the target physical page, memory resource reallocation is performed.
12. According to the network cloud platform according to claim 11, the resource scheduler is specifically used to scan the virtual machine memory resources based on the target scanning range to obtain the structural information of the multiple physical pages; based on the scanning parameters and the structural information of the multiple physical pages, determine the target physical page that is in an idle state among the multiple physical pages.
13. The network cloud platform according to claim 11 or 12, further comprising a host operating system; The resource scheduler is further configured to set the access permission of the target physical page to an inaccessible state in the virtual machine memory address translation table recorded by the host operating system, wherein: The virtual machine memory access table is a physical page table used by the virtual machine to convert memory addresses when accessing memory resources; Delete the page table entry of the target physical page in the memory page table recorded by the host operating system, wherein the memory page table includes a mapping relationship between the virtual memory address of the virtual machine and the multiple physical pages.
14. A computing device comprising: memory and processor; The memory is used to store computer programs / instructions, and the processor is used to execute the computer programs / instructions. When the computer program / instructions are executed by the processor, the steps of the method according to any one of claims 1 to 10 are implemented.
15. A computer-readable storage medium storing a computer program / instruction, wherein the computer program / instruction, when executed by a processor, implements the steps of the method according to any one of claims 1 to 10.
16. A computer program product comprising a computer program / instruction, which, when executed by a processor, implements the steps of the method according to any one of claims 1 to 10.
Citation Information
Cited By
Memory control method, computing device, storage medium and program product
CN121501518A