A method and device for running a process

By creating functional security partitions at the kernel layer and migrating the operating function data of the target process, the performance overhead problem caused by frequent switching of functional security applications is solved, and higher processor and terminal equipment performance is achieved.

CN113867828BActive Publication Date: 2025-05-16YINWANG INTELLIGENT TECHNOLOGIES CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202010616278.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-06-30
Publication Date
2025-05-16
Estimated Expiration
2040-06-30

AI Technical Summary

Technical Problem

The frequent switching of functional security applications from the user layer to the kernel layer results in high performance overhead.

Method used

By creating a functional security partition at the kernel layer, migrating the running functional data of the target process to the functional security partition to avoid frequent user layer-to-kernel layer switching.

Benefits of technology

Reduces the performance overhead brought by privileged layer switching and improves the performance of processors and terminal devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113867828B_ABST
    Figure CN113867828B_ABST
Patent Text Reader

Abstract

The present application discloses a method for running a process, including: receiving a process start request, executing the executable file of the target process in the kernel according to the process start request, and obtaining first running function data that supports the running of the target process in the kernel; migrating the first running function data to a functional safety partition, and obtaining second running function data, wherein the functional safety partition and the kernel are located in the same privileged layer; and running the target process in the functional safety partition based on the second running function data. The functional safety partition and the kernel of the present application solution are both located in the kernel layer, so that when the process is running, it is not necessary to switch from the user layer to the kernel layer to call the kernel layer service, thereby reducing the performance overhead caused by the privileged layer switching and improving the performance of the processor and the terminal device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a method and device for running a process. Background Art

[0002] With the development of information technology and the continuous improvement of chip manufacturing technology, embedded operating systems have been widely developed and applied. The Internet of Things, automotive electronics, industrial automation, military and aerospace and other fields that have strict requirements on real-time performance and reliability are inseparable from embedded operating systems.

[0003] Applications that have strict requirements on real-time and reliability (such as autonomous driving) are usually data-driven applications or applications that are frequently triggered by events. These applications can usually be called functional safety applications. Whether functional safety applications or non-functional safety applications, they usually rely on an embedded operating system of a monolithic kernel. The embedded operating system of the monolithic kernel includes user mode and kernel mode, which can also be called user layer and kernel layer, or user state or kernel state. The application is in the user layer, and the kernel is in the kernel layer. The privilege level of the kernel layer is higher than that of the user layer. Due to the isolation of the privileged layer, the process of the application in the user layer cannot directly access the kernel service through function calls, but must trigger a mode switch through a system call (syscall) and switch from the user layer to the kernel layer to access the kernel service.

[0004] Because functional safety applications frequently switch from user mode to kernel mode, it causes a large performance overhead. Summary of the invention

[0005] The embodiment of the present application provides a method for running a process, which can avoid frequent switching from the user layer to the kernel layer when running a process of a functional safety application, thereby reducing the performance overhead caused by privileged layer switching. The embodiment of the present application also provides a corresponding device.

[0006] The first aspect of the present application provides a method for running a process, including: receiving a process start request, the process start request is used to indicate the start of a target process; according to the process start request, executing the executable file of the target process in the kernel, and obtaining first running function data that supports the target process to run in the kernel; migrating the first running function data to a functional safety partition, and obtaining second running function data, the functional safety partition and the kernel are located in the same privileged layer; based on the second running function data, running the target process in the functional safety partition. In a possible implementation, the executable file contains marking information, and the marking information is used to indicate that the target process is a process of a functional safety application.

[0007] In the first aspect above, the method can be applied to a terminal device or a computer system in a terminal device. The terminal device can be a mobile phone, a vehicle-mounted terminal or an automatic driving device (for example: an automatic driving car, an automatic driving ship, an automatic driving aircraft), etc. The automatic driving device can also be called an intelligent device, such as an automatic driving car can be called an intelligent car. The process can be an application process. The process start request can be a request triggered when the system starts, or a request triggered when the user uses the application. The process start request can carry the identifier of the target process, or the identifier of the application corresponding to the target process, so that the corresponding executable file can be found through the identifier of the process or the identifier of the corresponding application. The executable file includes a file header and a binary executable code. Each process has a corresponding executable file, and the script of the executable file can include the identifier of the process. The executable file that executes the target process in the kernel refers to the binary executable code that executes the executable file in the kernel environment. The file header of the executable file can contain tag information, and the tag information can be a special tag data, which can be a string or a value. The functional safety partition is also called the data plane environment (DPE). The functional safety partition is configured in the kernel layer. The functional safety partition can be used to run the processes of all applications, and can also be used to run the processes of functional safety applications. Functional safety applications refer to applications that have strict requirements on real-time and reliability (such as autonomous driving), which are usually data-driven applications or applications that are frequently triggered by events. Migrating the first running function data to the functional safety partition can be migrating the first running function data to the storage space that is "exclusively" owned by the functional safety partition. From this first aspect, it can be seen that the functional safety partition and the kernel are both located in the kernel layer. In this way, when the process is running, there is no need to switch from the user layer to the kernel layer to call the kernel layer service, thereby reducing the performance overhead caused by the privileged layer switching and improving the performance of the processor and terminal device.

[0008] In a possible implementation manner of the first aspect, the kernel and physical resources of the functional safety partition are isolated.

[0009] In this possible implementation, the physical resources may include computing resources of a processor or processing core and storage resources of a memory, etc. The kernel corresponds to the first physical resource, and the functional safety partition corresponds to the second physical resource. The kernel is not aware of the second physical resource, that is, the process in the kernel cannot access the second physical resource. Similarly, the functional safety partition is not aware of the first physical resource, that is, the process in the functional safety partition cannot access the first physical resource. The physical resource isolation between the kernel and the functional safety partition can ensure that the kernel and the functional safety partition are isolated from each other. In this way, even if there is an information security risk in the kernel, it will not affect the functional safety partition, thereby ensuring the security of the functional safety partition data. In addition, because the kernel and the functional safety partition are isolated from each other, when the code of the functional safety application changes, for example, due to an upgrade, there is no need to modify the kernel, which also improves the maintainability of the kernel.

[0010] In a possible implementation of the first aspect, the first operating function data includes the virtual address of the target process, the mapping relationship between the virtual address and the first physical address, and the context of the target process, the first physical address is the physical address assigned to the target process in the storage resources of the kernel; the second operating function data includes the virtual address of the target process, the mapping relationship between the virtual address and the second physical address, and the context of the target process, the second physical address is the physical address assigned to the target process in the storage resources of the functional safety partition.

[0011] In this possible implementation, the first running function data and the second running function data differ only in physical address, the first physical address is the physical address of the kernel, and the second physical address is the physical address of the functional safety partition. The first physical address corresponds to the storage resources of the kernel, and the second physical address corresponds to the storage resources of the functional safety partition. The context of the target process includes at least one of the data segment, heap, stack, and register context of the target process; the register context refers to the value of the target process in the register.

[0012] In a possible implementation of the first aspect, the above steps: migrating the first running function data to the functional safety partition to obtain the second running function data, include: triggering the virtual machine manager to migrate the virtual address to the functional safety partition, releasing the mapping relationship between the virtual address and the first physical address, and establishing a mapping relationship between the virtual address and the second physical address; passing the context of the target process to the functional safety partition through shared memory, where the shared memory is memory shared by the kernel and the functional safety partition.

[0013] In this possible implementation, in addition to the kernel layer and the user layer, the architecture may also include a privileged layer of a higher privilege level. In the ARM architecture, EL0 is usually used to represent the user layer, EL1 is used to represent the kernel layer, and EL2 is used to represent the higher privilege layer. In the X86 architecture, Ring3 is usually used to represent the user layer, Ring2 is used to represent the kernel layer, and Ring1 is used to represent the higher privilege layer. The virtual machine manager is located in a higher privilege layer, such as the EL2 layer or the Ring1 layer. The higher privilege layer can manage the lower privilege layer, so the virtual machine manager can manage the kernel and the functional safety partition. The virtual machine manager can prepare the virtual address, the first physical address, and the mapping relationship between the virtual address and the first physical address for the target process in the kernel, and then allocate the second physical address to the target process on the storage resource of the functional safety partition, and release the mapping relationship between the virtual address and the first physical address, and establish the mapping relationship between the virtual address and the second physical address, so as to prepare the storage resources for the target process to run in the functional safety partition. In addition, the context of the target process is stored in the kernel and can be passed to the functional safety partition through shared memory, so that the target process can run in the functional safety partition. This possible implementation method does not require modifying the kernel and can ensure that the process of the functional safety application runs in the functional safety partition, thus achieving ecological compatibility between the functional safety partition and the kernel.

[0014] In a possible implementation of the first aspect, the method further includes: when the kernel executes the executable file of the target process, creating a first task structure in the kernel, the first task structure is used to store the context of the target process; adding an indication value in the first task structure, the indication value is used to indicate that the target process needs to run in the functional safety partition; when running the target process, according to the indication value, sending a first notification from the kernel to the functional safety, the first notification is used to indicate the creation of a second task structure in the functional safety partition; according to the first notification, creating a second task structure, and storing the context of the target process in the second task structure. In another possible implementation, the above step: adding an indication value in the first task structure, the indication value is used to indicate that the target process needs to run in the functional safety partition, includes: according to the tag information, adding an indication value in the first task structure, the indication value is used to indicate that the target process is a process of a functional safety application.

[0015] In this possible implementation, the first task structure (task_struct) is a structure in the kernel for storing the context of the target process, which can be in the form of a table or other forms. When the process starts, the first task structure will be created in the kernel first. Usually, if the executable file contains marking information, an indication value is set on the application identification bit (DPE APP) of the first structure. The indication value can be set to "1", for example. Of course, it can also be set to other values. The indication value indicates that the target process needs to run in a functional safety partition or that the target process is a process of a functional safety application. In this way, when the target process is executed, when the indication value in the first task structure is checked, it is known that the target process should run in a functional safety partition, thereby notifying the creation of a second task structure in the functional safety partition. This possible implementation realizes the ecological compatibility of the functional safety partition and the kernel.

[0016] In a possible implementation of the first aspect, the method also includes: reading the context of the target process from the shared memory to the functional safety partition; performing a consistency check on the context of the target process to obtain a first check value; if the first check value is the same as the second check value, determining that the context of the target process is secure data, and the second check value is a trusted value obtained by performing a consistency check on the initial configuration context of the target process.

[0017] In this possible implementation, a consistency check is performed before the context of the target process enters the functional safety partition, so as to ensure the security of the target process.

[0018] In a possible implementation of the first aspect, the method also includes: if the target process calls a system call instruction of a functional safety partition at runtime, storing the context of the system call instruction from the functional safety partition into a shared memory; sending a second notification from the functional safety partition to the kernel, the second notification being used to indicate that a system call has occurred; reading the context of the system call instruction from the shared memory, and calling the system call instruction of the kernel according to the context of the system call instruction to make a system call, and obtaining a return value of the system call; and passing the return value of the system call to the functional safety partition through the shared memory.

[0019] In this possible implementation, the context of the system call instruction can be passed between the functional safety partition and the kernel through shared memory. In this way, the system call in the functional safety partition can be implemented through the kernel's system call process, thereby ensuring the ecological compatibility of the functional safety partition and the kernel.

[0020] In a possible implementation of the first aspect, the method also includes: reading the return value of the system call from the shared memory to the functional safety partition; performing a consistency check on the return value of the system call to obtain a third check value; if the third check value is the same as the fourth check value, determining that the return value of the system call is security data, and the fourth check value is a trusted value obtained by performing a consistency check on the original file corresponding to the system call.

[0021] In this possible implementation, when a system call occurs, a consistency check must be performed on the return value returned to the functional safety partition, so as to ensure the security of the functional safety partition.

[0022] In a possible implementation of the first aspect, the method also includes: if a page fault exception occurs during the execution of the target process, storing the context of the page fault exception from the functional safety partition into the shared memory; sending a third notification from the functional safety partition to the kernel, the third notification being used to indicate that a page fault exception has occurred; reading the context of the page fault exception from the shared memory, and calling a page fault exception handling function in the kernel according to the context of the page fault exception, and performing page fault exception handling according to the page fault exception handling function to obtain a processing result; and passing the processing result to the functional safety partition through the shared memory.

[0023] In this possible implementation, when a page fault exception occurs, the context of the page fault exception can be transmitted between the functional safety partition and the kernel. In this way, the page fault exception in the functional safety partition can be implemented through the kernel's page fault exception handling process, thereby ensuring the ecological compatibility of the functional safety partition and the kernel.

[0024] In a possible implementation of the first aspect, page fault exception handling is performed according to a page fault exception handling function, including: executing the page fault exception handling function to allocate physical pages for the target process, and configuring the page table of the physical page; triggering the virtual machine manager to establish a mapping relationship between the virtual address and the third physical address, the third physical address being obtained by adding the address of the physical page to the first physical address; modifying the page table permission value of the target process according to the page table of the physical page, the page table permission value being used to indicate the range of page tables that the target process is allowed to use.

[0025] In this possible implementation, when a page fault exception occurs, the virtual machine manager adds physical pages to the storage resources corresponding to the functional security partition and modifies the page table, which can also ensure that the target process runs normally after the page fault exception occurs.

[0026] In a possible implementation of the first aspect, the target process includes threads and coroutines, the threads are created in the kernel and run in the functional safety partition, the coroutines are created in the functional safety partition and run in the functional safety partition; the functional safety partition includes a unified scheduler, and the unified scheduler is used to uniformly schedule threads and coroutines.

[0027] In this possible implementation, the coroutine is a microthread. Compared with the prior art, in which threads are scheduled by a thread scheduler, the coroutine scheduler schedules coroutines. When scheduling coroutines, it is necessary to first switch to the thread where the coroutine is located, and then switch to the coroutine progressive scheduling. Two-level switching is required, which has a large overhead, and there are many interferences in the kernel, and the determinism of scheduling cannot be guaranteed. In this possible implementation, the unified scheduling of the unified scheduler avoids two-level scheduling and reduces overhead. Moreover, the unified scheduler is located in the functional safety partition and will not be interfered with, ensuring the determinism of scheduling.

[0028] The second aspect of the present application provides a method for running a process, which is applied to a computer system, the computer system includes a first processing device and a second processing device, the method includes: the first processing device receives a process start request, the process start request is used to indicate the start of a target process; the first processing device executes the executable file of the target process in the kernel according to the process start request, and obtains first running function data that supports the target process to run in the kernel; the first processing device migrates the first running function data to a functional safety partition, obtains second running function data, the functional safety partition and the kernel are located in the same privileged layer, and the second function data is used for the target process to run in the functional safety partition. In a possible implementation, the executable file contains marking information, and the marking information is used to indicate that the target process is a process of a functional safety application.

[0029] In the second aspect, the first processing device and the second processing device may be two processors or two processing cores, and other contents are the same as those of the first aspect, and may be understood by referring to the corresponding description of the first aspect.

[0030] In a possible implementation manner of the second aspect, the kernel and physical resources of the functional safety partition are isolated.

[0031] In a possible implementation of the second aspect, the first operating function data includes the virtual address of the target process, the mapping relationship between the virtual address and the first physical address, and the context of the target process, the first physical address is the physical address assigned to the target process in the storage resources of the kernel; the second operating function data includes the virtual address of the target process, the mapping relationship between the virtual address and the second physical address, and the context of the target process, the second physical address is the physical address assigned to the target process in the storage resources of the functional safety partition.

[0032] In a possible implementation of the second aspect, the above-mentioned steps: migrating the first running function data to the functional safety partition to obtain the second running function data, include: the first processing device triggers the virtual machine manager to migrate the virtual address to the functional safety partition, releases the mapping relationship between the virtual address and the first physical address, and establishes a mapping relationship between the virtual address and the second physical address; the first processing device passes the context of the target process to the functional safety partition through shared memory, and the shared memory is the memory shared by the kernel and the functional safety partition.

[0033] In a possible implementation of the second aspect, the method further includes: when the kernel executes the executable file of the target process, the first processing device creates a first task structure in the kernel, the first task structure is used to store the context of the target process; adds an indication value in the first task structure, the indication value is used to indicate that the target process needs to run in the functional safety partition; when running the target process, according to the indication value, sends a first notification from the kernel to the functional safety, the first notification is used to indicate the creation of a second task structure in the functional safety partition. In another possible implementation, the above step: adding an indication value in the first task structure, the indication value is used to indicate that the target process needs to run in the functional safety partition, includes: according to the tag information, adding an indication value in the first task structure, the indication value is used to indicate that the target process is a process of a functional safety application.

[0034] In a possible implementation of the second aspect, the method also includes: the first processing device receives a second notification sent by the second processing device, the second notification is used to indicate that a system call has occurred; reading the context of the system call instruction from the shared memory, and calling the system call instruction of the kernel according to the context of the system call instruction to make a system call, and obtaining a return value of the system call; passing the return value of the system call to the functional safety partition through the shared memory.

[0035] In a possible implementation of the second aspect, the method also includes: the first processing device receives a third notification sent by the second processing device, the third notification is used to indicate that a page fault exception has occurred; reading the context of the page fault exception from the shared memory, and calling a page fault exception handling function in the kernel according to the context of the page fault exception, and performing page fault exception handling according to the page fault exception handling function to obtain a processing result; and passing the processing result to the functional safety partition through the shared memory.

[0036] In a possible implementation of the second aspect, the above steps: performing page fault exception handling according to a page fault exception handling function, include: a first processing device executes a page fault exception handling function to allocate a physical page for a target process, and configures a page table of the physical page; triggering a virtual machine manager to establish a mapping relationship between a virtual address and a third physical address, where the third physical address is obtained by adding the address of the physical page to the first physical address; modifying a page table permission value of the target process according to the page table of the physical page, where the page table permission value is used to indicate a range of page tables that the target process is allowed to use.

[0037] In a possible implementation of the second aspect, the target process includes threads and coroutines, the threads are created in the kernel and run in the functional safety partition, the coroutines are created in the functional safety partition and run in the functional safety partition; the functional safety partition includes a unified scheduler, and the unified scheduler is used to uniformly schedule threads and coroutines.

[0038] A third aspect of the present application provides a method for running a process, which is applied to a computer system, which includes a first processing device and a second processing device, and the method includes: the second processing device obtains second running function data, the second running function data is obtained by the first processing device migrating the first running function data to a functional safety partition, the first running function data is data supporting the running of the target process in the kernel obtained by the first processing device executing the executable file of the target process in the kernel, and the functional safety partition and the kernel are located in the same privileged layer; based on the second running function data, the target process is run in the functional safety partition.

[0039] In the third aspect, the first processing device and the second processing device may be two processors or two processing cores, and other contents are the same as those of the first aspect, and may be understood by referring to the corresponding description of the first aspect.

[0040] In a possible implementation manner of the second aspect, the kernel and physical resources of the functional safety partition are isolated.

[0041] In a possible implementation of the third aspect, the first operating function data includes the virtual address of the target process, the mapping relationship between the virtual address and the first physical address, and the context of the target process, the first physical address is the physical address assigned to the target process in the storage resources of the kernel; the second operating function data includes the virtual address of the target process, the mapping relationship between the virtual address and the second physical address, and the context of the target process, the second physical address is the physical address assigned to the target process in the storage resources of the functional safety partition.

[0042] In a possible implementation of the third aspect, the method also includes: the second processing device receives a first notification sent by the first processing device, the first notification is used to indicate the creation of a second task structure in the functional safety partition; according to the first notification, the second task structure is created, and the context of the target process is stored in the second task structure.

[0043] In a possible implementation of the third aspect, the method also includes: the second processing device reads the context of the target process from the shared memory to the functional safety partition; performs a consistency check on the context of the target process to obtain a first check value; if the first check value is the same as the second check value, it is determined that the context of the target process is secure data, and the second check value is a trusted value obtained by performing a consistency check on the initial configuration context of the target process.

[0044] In a possible implementation of the third aspect, the method also includes: if the target process calls a system call instruction of a functional safety partition during runtime, storing the context of the system call instruction from the functional safety partition into a shared memory; sending a second notification from the functional safety partition to the kernel, the second notification being used to indicate that a system call has occurred; the context of the system call instruction is used by a first processing device to read the context of the system call instruction from the shared memory, and calling the system call instruction of the kernel to perform a system call according to the context of the system call instruction to obtain a return value of the system call; and passing the return value of the system call to the functional safety partition through the shared memory.

[0045] In a possible implementation of the third aspect, the method also includes: the second processing device reads the return value of the system call from the shared memory to the functional safety partition; performs a consistency check on the return value of the system call to obtain a third check value; if the third check value is the same as the fourth check value, it is determined that the return value of the system call is safe data, and the fourth check value is a trusted value obtained by performing a consistency check on the original file corresponding to the system call.

[0046] In a possible implementation of the third aspect, the method also includes: if a page fault exception occurs during the operation of the target process, the second processing device stores the context of the page fault exception from the functional safety partition into the shared memory; a third notification is sent from the functional safety partition to the kernel, and the third notification is used to indicate that a page fault exception has occurred; the context of the page fault exception is used by the first processing device to read the context of the page fault exception from the shared memory, and call a page fault exception handling function in the kernel according to the context of the page fault exception, and perform page fault exception handling according to the page fault exception handling function to obtain a processing result; and the processing result is passed to the functional safety partition through the shared memory.

[0047] In a possible implementation of the third aspect, the target process includes threads and coroutines, the threads are created in the kernel and run in the functional safety partition, the coroutines are created in the functional safety partition and run in the functional safety partition; the functional safety partition includes a unified scheduler, and the unified scheduler is used to uniformly schedule threads and coroutines.

[0048] In a fourth aspect, the present application provides a device for running a process, which has the function of implementing the method of the first aspect or any possible implementation of the first aspect. The function can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions, for example: a receiving unit, a sending unit, a first processing unit, a second processing unit, and a third processing unit, wherein the first processing unit, the second processing unit, and the third processing unit can also be implemented by one processing unit or two processing units.

[0049] In a fifth aspect, the present application provides a processing device, which has the function of implementing the method of the second aspect or any possible implementation of the second aspect. The function can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions, for example: a receiving unit, a sending unit, a first processing unit and a second processing unit, wherein the first processing unit and the second processing unit can also be implemented by one processing unit.

[0050] In a sixth aspect of the present application, a processing device is provided, which has the function of implementing the method of the third aspect or any possible implementation of the third aspect. The function can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions, for example: a receiving unit, a sending unit, a first processing unit and a second processing unit, wherein the first processing unit and the second processing unit can also be implemented by one processing unit.

[0051] In a seventh aspect, the present application provides a computer device, which may be a terminal device, comprising at least one processor, a memory, an input / output (I / O) interface, and computer execution instructions stored in the memory and executable on the processor. When the computer execution instructions are executed by the processor, the processor executes the method of the first aspect or any possible implementation of the first aspect.

[0052] In an eighth aspect of the present application, a computer device is provided, which may be a terminal device, comprising at least one processor, a memory, an input / output (I / O) interface, and computer execution instructions stored in the memory and executable on the processor. When the computer execution instructions are executed by the processor, the processor executes the method of the second aspect or any possible implementation of the second aspect.

[0053] In a ninth aspect of the present application, a computer device is provided, which may be a terminal device, comprising at least one processor, a memory, an input / output (I / O) interface, and computer execution instructions stored in the memory and executable on the processor. When the computer execution instructions are executed by the processor, the processor executes the method of the third aspect or any possible implementation of the third aspect.

[0054] The tenth aspect of the present application provides a computer-readable storage medium storing one or more computer-executable instructions. When the computer-executable instructions are executed by a processor, the processor executes a method as described in the first aspect or any possible implementation of the first aspect.

[0055] In the eleventh aspect of the present application, a computer-readable storage medium is provided that stores one or more computer-executable instructions. When the computer-executable instructions are executed by a processor, the processor executes a method as in the second aspect or any possible implementation of the second aspect.

[0056] The twelfth aspect of the present application provides a computer-readable storage medium storing one or more computer-executable instructions. When the computer-executable instructions are executed by a processor, the processor executes a method as described in the third aspect or any possible implementation of the third aspect.

[0057] The thirteenth aspect of the present application provides a computer program product storing one or more computer-executable instructions. When the computer-executable instructions are executed by a processor, the processor executes the method of the above-mentioned first aspect or any possible implementation of the first aspect.

[0058] The fourteenth aspect of the present application provides a computer program product storing one or more computer-executable instructions. When the computer-executable instructions are executed by a processor, the processor executes the method of the above-mentioned second aspect or any possible implementation of the second aspect.

[0059] The fifteenth aspect of the present application provides a computer program product storing one or more computer-executable instructions. When the computer-executable instructions are executed by a processor, the processor executes the method of the third aspect or any possible implementation of the third aspect.

[0060] In a sixteenth aspect of the present application, a chip system is provided, the chip system comprising a processor, which is used to support a device for running a process to implement the functions involved in the above-mentioned first aspect or any possible implementation of the first aspect. In a possible design, the chip system may also include a memory, the memory being used to store program instructions and data necessary for the device for running the process. The chip system may be composed of a chip, or may include a chip and other discrete devices.

[0061] In the seventeenth aspect of the present application, a chip system is provided, the chip system includes a processor, which is used to support the device for running the process to implement the functions involved in the second aspect or any possible implementation of the second aspect. In one possible design, the chip system may also include a memory, which is used to store the necessary program instructions and data for the device for running the process. The chip system may be composed of a chip, or may include a chip and other discrete devices.

[0062] In aspect 18 of the present application, a chip system is provided, the chip system includes a processor, which is used to support a device for running a process to implement the functions involved in the third aspect or any possible implementation of the third aspect. In one possible design, the chip system may also include a memory, which is used to store program instructions and data necessary for the device for running the process. The chip system may be composed of a chip, or may include a chip and other discrete devices.

[0063] Among them, the technical effects brought about by the fourth to eighteenth aspects or any possible implementation methods thereof can refer to the technical effects brought about by the first aspect or different possible implementation methods of the first aspect, and will not be repeated here.

[0064] In the embodiment of the present application, both the functional safety partition and the kernel are located in the kernel layer, and the process of the functional safety application runs in the functional safety partition. In this way, when the process of the functional safety application is running, it is not necessary to switch from the user layer to the kernel layer to call the kernel layer service, thereby reducing the performance overhead caused by the privilege layer switching and improving the performance of the processor and terminal device. BRIEF DESCRIPTION OF THE DRAWINGS

[0065] Figure 1 is a schematic diagram of a system architecture of a terminal device provided in an embodiment of the present application;

[0066] Figure 2 is a schematic diagram of an architecture of an automatic driving device provided in an embodiment of the present application;

[0067] Figure 3 It is a schematic diagram of an embodiment of a method for running a process provided by an embodiment of the present application;

[0068] Figure 4is a schematic diagram of another embodiment of the method for running a process provided by an embodiment of the present application;

[0069] Figure 5 is a schematic diagram of another embodiment of the method for running a process provided by an embodiment of the present application;

[0070] Fig. 6A is a schematic diagram of another embodiment of the method for running a process provided by an embodiment of the present application;

[0071] Figure 6B is a schematic diagram of another embodiment of the method for running a process provided by an embodiment of the present application;

[0072] Figure 7 is a schematic diagram of another embodiment of the method for running a process provided by an embodiment of the present application;

[0073] Figure 8 It is a schematic diagram of a scenario provided by an embodiment of the present application;

[0074] Fig. 9 It is a schematic diagram of an embodiment of a device for running a process provided by an embodiment of the present application;

[0075] Fig.10 is a structural schematic diagram of a computer device provided in an embodiment of the present application;

[0076] Fig.11 It is another structural schematic diagram of the computer device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0077] The following describes the embodiments of the present application in conjunction with the accompanying drawings. Obviously, the described embodiments are only embodiments of a part of the present application, rather than all embodiments. It is known to those skilled in the art that with the development of technology and the emergence of new scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0078] The terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0079] The embodiment of the present application provides a method for running an application, which can avoid frequent switching from the user layer to the kernel layer, thereby reducing the performance overhead caused by privileged layer switching. The embodiment of the present application also provides a corresponding device. The following are detailed descriptions.

[0080] In order to facilitate understanding of the embodiments of the present application, some terms involved in the embodiments of the present application are introduced below.

[0081] An executable file is a static concept. It is a file that is a collection of pre-compiled instructions and data. An executable file includes a file header and binary execution code. Each process has a corresponding executable file. The script of the executable file can include the process identifier.

[0082] Process is a dynamic concept. A process is an operation of a program in a computer on a certain data set and is the basic unit for resource allocation and scheduling in the system.

[0083] The kernel is the most basic part of the operating system. It is a piece of software that provides secure access to the computer hardware for many applications. The kernel can be the Linux kernel.

[0084] Functional safety partitions are also called data plane environments (DPEs). Functional safety partitions are configured at the kernel layer and are located in the same privileged layer as the kernel. Functional safety partitions can be used to run processes for all applications or processes for functional safety applications.

[0085] Functional safety applications refer to applications that have strict requirements on real-time performance and reliability (such as autonomous driving), which are usually data-driven applications or applications that are frequently triggered by events.

[0086] The running function data refers to the data that supports the running of the process, including the virtual address of the process, the mapping relationship between the virtual address and the physical address, and the context of the process.

[0087] A virtual address is also called a logical address and is usually represented by an offset. If the logical space shared by all processes in the operating system is described as the entire virtual address space, then the entire virtual address space will have a starting value. The starting value and offset can be used to determine the virtual address space that the target process can use.

[0088] The physical address is the address of the corresponding storage resource, and the physical address can also be represented by an offset.

[0089] The context of a process includes at least one of a data segment, a heap, a stack, and a register context of the process.

[0090] Register context refers to the values ​​that a process writes to registers while it is running.

[0091] The task structure (task_struct) is a structure used to store the context of the process, which can be in the form of a table or other forms.

[0092] System call: The main function of the operating system is to manage hardware resources and provide a good environment for application developers to make applications more compatible. To achieve this goal, the kernel provides a series of multi-kernel functions with predetermined functions, which are presented to users through a set of interfaces called system calls. The system call transmits the application's request to the kernel, calls the corresponding kernel function to complete the required processing, and returns the processing result to the application.

[0093] A page fault exception refers to an exception caused by a page fault.

[0094] The consistency check method may be a cyclic redundancy check (CRC), which is a commonly used check method with error detection and correction capabilities.

[0095] A method for running a process provided in an embodiment of the present application can be applied to a terminal device or a computer system of a terminal device, wherein the terminal device (also referred to as user equipment (UE)) is a device with a wireless transceiver function, which can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; can also be deployed on the water surface (such as a ship, etc.); can also be deployed in the air (such as an airplane, a balloon, and a satellite, etc.). The terminal can be a mobile phone, a tablet computer (pad), a computer with a wireless transceiver function, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, an automatic driving device, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc.

[0096] The terminal device can refer to Figure 1 The system architecture shown in the figure can be understood. Figure 1As shown, the terminal device includes a user layer, a kernel layer, a management layer and a hardware layer.

[0097] There may be multiple applications (applications, APPs) in the user layer, and the multiple applications may include functional safety applications and common applications, where common applications are relative to functional safety applications. Applications other than functional safety applications may be referred to as common applications.

[0098] The kernel layer includes the kernel and functional safety partitions. The processes of ordinary applications run in the kernel, and the processes of functional safety applications run in the functional safety partitions. In order to ensure that the functional safety partitions are compatible with the kernel ecosystem, interaction can be carried out between the functional safety partitions and the kernel, and the kernel can assist in completing some operations of functional safety applications.

[0099] The management layer may include a virtual machine manager, which has higher privileges than the kernel layer and the user layer and can manage the kernel layer, for example, configuring the running function data of the process of the functional safety application to the functional safety partition.

[0100] In different architectures, the names of the user layer, kernel layer, and management layer may be slightly different. For example, in the ARM architecture, EL0 is usually used to represent the user layer, EL1 is used to represent the kernel layer, and EL2 is used to represent a higher privilege layer. In the X86 architecture, Ring3 is usually used to represent the user layer, Ring2 is used to represent the kernel layer, and Ring1 is used to represent a higher privilege layer.

[0101] The hardware layer includes resources such as computing units, memory, and communication interfaces. The hardware layer is used to provide hardware resources for the normal operation of the user layer, kernel layer, and management layer.

[0102] If the terminal device is an autonomous driving device, the hardware layer may also include hardware such as radar and camera. Because the field of autonomous driving involves more functional safety applications, the following is combined with Figure 2 The present application is described in a form in which it is applied in an automatic driving device 100.

[0103] like Figure 2As shown, the automatic driving device 100 includes a computer system 101, a display 109, an input device 117, a multimedia tray 121, a transceiver 123 (which can send and / or receive radio communication signals), a sensor 153 and a camera 155. The computer system 101 includes a processor 103, and the processor 103 is coupled to a system bus 105. The processor 103 can be one or more processors, wherein each processor can include one or more processor cores. A display adapter (video adapter) 107, the display adapter 107 can drive a display 109, and the display 109 is coupled to the system bus 105. The system bus 105 is coupled to an input / output (I / O) bus 113 via a bus bridge 111. An I / O interface 115 is coupled to the I / O bus. The I / O interface 115 communicates with a variety of I / O devices, such as an input device 117 (such as: keyboard, mouse, touch screen, etc.), a multimedia tray 121, such as a CD-ROM, a multimedia interface, etc. The transceiver 123 and the camera 155 (which can capture scene and dynamic digital video images) and the external USB interface 125. Optionally, the interface connected to the I / O interface 115 can be a USB interface.

[0104] Among them, the processor 103 can be any traditional processor, including a reduced instruction set computing ("RISC") processor, a complex instruction set computing ("CISC") processor, or a combination of the above. Optionally, the processor can be a dedicated device such as an application-specific integrated circuit ("ASIC"). Optionally, the processor 103 can be a neural-network processing unit (NPU) or a combination of a neural-network processing unit and the above-mentioned traditional processors. Optionally, the processor 103 is equipped with a neural-network processing unit.

[0105] Computer system 101 can communicate with software deployment server 149 via network interface 129. Network interface 129 is a hardware network interface, such as a network card. Network 127 can be an external network, such as the Internet, or an internal network, such as Ethernet or a virtual private network (VPN). Optionally, network 127 can also be a wireless network, such as a WiFi network, a cellular network, etc.

[0106] The hard disk drive interface is coupled to the system bus 105. The hard disk drive interface is connected to the hard disk drive. The system memory 135 is coupled to the system bus 105. The data running in the system memory 135 may include an operating system 137 and an application program 143.

[0107] The operating system 137 includes a functional safety partition (DPE) 139 and a kernel 141 .

[0108] The kernel 141 consists of those parts of the operating system that manage memory, files, peripherals, and system resources. Interacting directly with the hardware, the operating system kernel usually runs processes and provides communication between processes, provides CPU time slice management, interrupts, memory management, IO management, etc.

[0109] Application 143 includes autonomous driving related programs 147, such as positioning programs, planning programs, and perception programs, and the applications corresponding to these programs are all functional safety applications. Application 143 also exists on the system of software deployment server 149. In one embodiment, when application 143 needs to be executed, computer system 101 can download application 143 from software deployment server 149.

[0110] The sensor 153 is associated with the computer system 101. The sensor 153 is used to detect the environment around the computer system 101. For example, the sensor 153 can detect animals, cars, obstacles and crosswalks, etc., and further the sensor can detect the environment around the above-mentioned animals, cars, obstacles and crosswalks, such as: the environment around the animals, for example, other animals around the animals, weather conditions, the brightness of the surrounding environment, etc. Optionally, if the computer system 101 is located on an autonomous driving device, the sensor can be a camera, an infrared sensor, a chemical detector, a microphone, etc. When activated, the sensor 153 senses information at a preset interval and provides the sensed information to the computer system 101 in real time or near real time.

[0111] The computer system 101 is used to determine the driving state of the automatic driving device according to the sensor data collected by the sensor 153, and determine the driving operation required for the automatic driving transposition according to the driving state and the current driving task, and send the control instruction corresponding to the driving operation to the control system. The driving state of the automatic driving device may include the driving status of the automatic driving device itself, such as the direction, speed, position, acceleration, etc. of the vehicle head, and also include the state of the surrounding environment of the automatic driving device, such as the location of obstacles, the location and speed of other vehicles, the location of crosswalks, the signal of traffic lights, etc. The computer system 101 may include a task abstraction network and a shared strategy network implemented by the processor 103. Specifically, processor 103 determines the current autonomous driving task; processor 103 inputs at least one set of historical paths of the autonomous driving task into the task abstraction network for feature extraction to obtain a task feature vector that characterizes the characteristics of the autonomous driving task; processor 103 determines a state vector that characterizes the current driving state of the autonomous driving device based on the sensor data collected by sensor 153; processor 103 inputs the task feature vector and the state vector into the shared strategy network for processing to obtain the driving operation that the autonomous driving device currently needs to perform; processor 103 executes the driving operation through the control system; processor 103 repeats the previous steps of determining and executing the driving operation until the autonomous driving task is completed.

[0112] The automatic driving device 100 may be a car, a truck, a motorcycle, a bus, a ship, an airplane, a helicopter, a lawn mower, an amusement vehicle, an amusement park automatic driving device, construction equipment, a tram, a golf cart, a train, a cart, etc., and the embodiments of the present application do not make any special limitations.

[0113] Regardless of whether the above-mentioned terminal device is an autonomous driving device or other equipment, the kernel layer of the operating system will include the above-mentioned functional safety partition.

[0114] Below, in conjunction with the accompanying drawings, an embodiment of the present application provides a method for running a process performed by a device for running a process. The device for running a process may be a processor system, and the processor system includes one or more processors, such as the above-mentioned Figure 2 The processor 103 in the process can manage the kernel and functional security partitions.

[0115] like Figure 3 As shown, an embodiment of the method for running a process provided by an embodiment of the present application includes:

[0116] 201. Receive a process start request, where the process start request is used to instruct to start a target process.

[0117] The process start request may be a request triggered when the system starts, or a request triggered when a user uses an application.

[0118] 202. According to the process start request, the executable file of the target process is executed in the kernel to obtain first operation function data supporting the operation of the target process in the kernel.

[0119] The process start request may carry the identifier of the target process, and may also carry the identifier of the application corresponding to the target process, so that the corresponding executable file can be found through the identifier of the process or the identifier of the corresponding application.

[0120] An executable file includes a file header and binary execution code. Each process has a corresponding executable file. The script of the executable file may include the process identifier. The executable file that executes the target process in the kernel refers to the binary execution code that executes the executable file in the kernel environment.

[0121] The file header of an executable file may include tag information, which may be a special tag data, a string, or a numerical value.

[0122] The first running function data includes a virtual address of the target process, a mapping relationship between the virtual address and a first physical address, and a context of the target process. The first physical address is a physical address allocated to the target process in a storage resource of a kernel.

[0123] 203. Migrate the first operating function data to the functional safety partition to obtain second operating function data.

[0124] The marking information is used to indicate that the target process is a process of a functional safety application, and the functional safety partition and the kernel are located in the same privilege layer.

[0125] The second running function data includes the virtual address of the target process, the mapping relationship between the virtual address and the second physical address, and the context of the target process. The second physical address is the physical address allocated to the target process in the storage resources of the functional security partition.

[0126] In one possible implementation, the executable file includes marking information. If the executable file includes marking information, the first running function data is migrated to the functional safety partition to obtain the second running function data. The marking information is used to indicate that the target process is a process of a functional safety application.

[0127] Migrating the first running function data to the functional safety partition may be migrating the first running function data to a storage space “exclusively used” by the functional safety partition.

[0128] 204. Based on the second running function data, run the target process in the functional safety partition.

[0129] In the embodiment of the present application, because the functional safety partition and the kernel are both located at the kernel layer, when the process is running, there is no need to switch from the user layer to the kernel layer to call the kernel layer services, thereby reducing the performance overhead caused by the privileged layer switching and improving the performance of the processor and terminal device.

[0130] Optionally, in an embodiment of the present application, the physical resources of the kernel and the functional safety partition are isolated. The physical resource isolation process can configure different physical resources for the kernel and the functional safety partition respectively when the virtual machine manager is initialized to achieve physical resource isolation between the two. Physical resources may include computing resources of a processor or processing core and storage resources of a memory, etc. The kernel corresponds to a first physical resource, and the functional safety partition corresponds to a second physical resource. The kernel is not aware of the second physical resource, that is, the process in the kernel cannot access the second physical resource. Similarly, the functional safety partition is not aware of the first physical resource, that is, the process in the functional safety partition cannot access the first physical resource. Physical resource isolation between the kernel and the functional safety partition can ensure that the kernel and the functional safety partition are isolated from each other. In this way, even if there is an information security risk in the kernel, it will not affect the functional safety partition, thereby ensuring the security of the functional safety partition data. In addition, because the kernel and the functional safety partition are isolated from each other, when the code of the functional safety application changes, for example, due to an upgrade, the kernel does not need to be modified, which also improves the maintainability of the kernel.

[0131] The method for running a process provided by the embodiment of the present application may include the following three aspects: 1. Starting the target process in the kernel; 2. Migrating the running function data of the target process to the functional safety partition; 3. Running the target process in the functional safety partition. Each of them will be introduced below.

[0132] 1: Start the target process in the kernel.

[0133] The process of pulling up the target process in the kernel can be seen in Figure 4 Understand. Figure 4 As shown, the process includes:

[0134] 301. When the operating system is started, or when the target application corresponding to the target process is triggered, the device for running the process loads the executable file of the target process according to the identifier of the target process and the identifier of the process contained in the script of the executable file.

[0135] The executable file of the target process can be loaded into the memory corresponding to the kernel.

[0136] 302. The device for running the process creates a first task structure (task_struct) in the kernel during the process of executing the executable file of the target process.

[0137] The first task structure is used to store the context of the target process. The first task structure (task_struct) is a structure in the kernel used to store the context of the target process, which can be in the form of a table or other forms.

[0138] 303. If the file header of the executable file includes marking information, the device for running the process adds an indication value in the first task structure according to the marking information, where the indication value is used to indicate that the target process is a process of a functional safety application.

[0139] The indication value can be added to the identification bit of the functional safety application (DPE APP) of the first task structure. The indication value can be "1" or other numerical values. The specific value of the indication value is not limited in this application.

[0140] like Figure 4 As shown, a first task structure is created in the kernel, and the value of the functional safety application identification bit of the task structure is "1", indicating that the target process is a process of the functional safety application. In addition, the first task structure also stores the context of the target process.

[0141] 304. During the process of executing the executable file of the target process, the device for running the process will also allocate a virtual address for the target process from the virtual address space, allocate a first physical address for the target process from the storage resources of the kernel, and then establish a mapping relationship between the virtual address and the first physical address.

[0142] In this way, if the target process runs in the kernel, the virtual address space indicated by the virtual address and the physical address space indicated by the first physical address can be used, and the corresponding virtual address space and physical address space of the target process can be used for related operations such as adding, deleting, modifying or querying the target process.

[0143] In this embodiment, the target process can be passed to the functional safety partition through shared memory, so that the target process can run in the functional safety partition. It does not need to modify the kernel, and can ensure that the process of the functional safety application runs in the functional safety partition, thus achieving the ecological compatibility between the functional safety partition and the kernel. In addition, the context of the target process can also be checked for consistency in the functional safety partition, further ensuring the security of the target process when the functional safety partition is initialized.

[0144] 2: Migrate the target process's running function data to the functional safety partition.

[0145] In the process of running functional data migration, you can refer to Figure 5 Understand. Figure 5 As shown, the process includes:

[0146] Because the physical resources of the kernel and the functional safety partition are isolated, shared memory is required in the process of running functional data migration. A first proxy module can be configured in the kernel, and a second proxy module can be configured in the functional safety partition. The first proxy module and the second proxy module can be implemented by software, and the processor system can implement the proxy functions of the first proxy module and the second proxy module in the kernel and the functional safety partition by executing corresponding software.

[0147] 401. When the target process is running, the context of the target process is stored in the shared memory according to the indicated value.

[0148] 402. Send a first notification from the kernel to the functional safety partition, where the first notification is used to instruct to create a second task structure in the functional safety partition.

[0149] The notification between the kernel and the functional safety partition can be sent through the first agent module and the second agent module. Figure 5 As shown, the first agent module sends a first notification to the second agent module.

[0150] 403. Create a second task structure according to the first notification.

[0151] 404. Read the context of the target process from the shared memory, perform consistency check on the context of the target process to obtain a first check value; if the first check value is the same as the second check value, store the context of the target process in the second task structure.

[0152] If the first check value is the same as the second check value, the context of the target process is determined to be secure data, and the second check value is a credible value obtained by performing a consistency check on the initial configuration context of the target process.

[0153] 405. The first proxy module triggers the virtual machine manager to migrate the virtual address to the functional safety partition and release the mapping relationship between the virtual address and the first physical address.

[0154] 406. The first proxy module triggers the virtual machine manager to establish a mapping relationship between the virtual address and the second physical address.

[0155] 3: Run the target process in the functional safety partition.

[0156] The process of running the target process in the functional safety partition may include: the process of handling system calls and the process of handling page fault exceptions, which are introduced below.

[0157] 1. The processing of system calls.

[0158] The system call processing process can be found in Fig. 6A Understand. Fig. 6AAs shown, the process may include:

[0159] 501. The second agent module runs the target process in the functional safety partition and calls the system call instruction of the functional safety partition.

[0160] 502. The second proxy module stores the context of the system call instruction from the functional security partition into the shared memory.

[0161] This step may be to store the context of the system call instruction into the shared memory through the second proxy module.

[0162] 503. The second agent module sends a second notification from the functional security partition to the kernel, where the second notification is used to indicate that a system call occurs.

[0163] 504. The first proxy module reads the context of the system call instruction from the shared memory.

[0164] 505. The first proxy module calls the system call instruction of the kernel according to the context of the system call instruction to perform a system call and obtain a return value of the system call.

[0165] 506. The first proxy module puts the return value into the shared memory.

[0166] 507. The second proxy module reads the return value of the system call from the shared memory to the functional safety partition; performs a consistency check on the return value of the system call to obtain a third check value; if the third check value is the same as the fourth check value, it is determined that the return value of the system call is safe data, and the fourth check value is a trusted value obtained by performing a consistency check on the original file corresponding to the system call.

[0167] 508. The second proxy module uses the return value to complete the system call process of the functional security partition.

[0168] This embodiment can transfer the context of system call instructions between the functional safety partition and the kernel through shared memory, so that the system call in the functional safety partition can be implemented through the system call process of the kernel, thereby ensuring the ecological compatibility of the functional safety partition and the kernel.

[0169] 2. The process of handling page fault exceptions.

[0170] The page fault exception handling process can be found in Figure 6B Understand. Figure 6B As shown, the process may include:

[0171] 601. A page fault exception occurs when the second proxy module runs a target process in a functional safety partition.

[0172] 602. The second proxy module stores the context of the page fault exception from the functional security partition into the shared memory.

[0173] This step may be to store the context of the page fault exception into the shared memory through the second agent module.

[0174] 603. The second agent module sends a third notification from the functional security partition to the kernel, where the third notification is used to indicate that a page fault exception occurs.

[0175] The second notification may be sent to the first agent module through the second agent module.

[0176] 604. The first agent module reads the context of the page fault exception from the shared memory.

[0177] 605. The first proxy module calls a page fault exception processing function in the kernel according to the context of the page fault exception, and performs page fault exception processing according to the page fault exception processing function to obtain a processing result.

[0178] This step includes: executing a page fault exception handling function to allocate a physical page for the target process and configuring a page table of the physical page; the first proxy module triggers the virtual machine manager to establish a mapping relationship between the virtual address and the third physical address, where the third physical address is obtained by adding the address of the physical page to the first physical address; and modifying the page table permission value of the target process according to the page table of the physical page, where the page table permission value is used to indicate the range of the page table that the target process is allowed to use. This ensures that the target process runs normally after a page fault exception occurs.

[0179] 606. The first proxy module writes the processing result into the shared memory.

[0180] 607. The second proxy module reads the processing result of the page fault exception from the shared memory and verifies the processing result. If the verification passes, the processing result is returned to the target process for continued execution.

[0181] The verification process of this step is the same as that of the above step 507 and will not be repeated here.

[0182] 608. The second proxy module uses the processing result to complete the page fault exception processing process of the functional security partition.

[0183] In this embodiment, when a page fault exception occurs, the context of the page fault exception can be transmitted between the functional safety partition and the kernel. In this way, the page fault exception in the functional safety partition can be implemented through the page fault exception handling process of the kernel, thereby ensuring the ecological compatibility of the functional safety partition and the kernel.

[0184] In addition, in the above embodiment, the return value or the processing result may be checked for consistency, thus further ensuring the security of the data.

[0185] In addition, the target process in the above embodiment may include threads and coroutines. The solution provided in the embodiment of the present application can perform unified scheduling on threads and coroutines. The process can be referred to in Figure 7 To understand, such as Figure 7 As shown, the process may include:

[0186] 701. The thread entity in the kernel creates a thread.

[0187] 702. The coroutine entity in the functional safety partition creates a coroutine.

[0188] Coroutines are microthreads.

[0189] 703. Transfer the thread from the kernel to the functional safety partition through the first proxy module and the second proxy module.

[0190] 704. Put the thread into the unified scheduler.

[0191] Functional safety partitions include a unified scheduler.

[0192] 705. Put the coroutine into a unified scheduler.

[0193] The unified scheduler can schedule threads and coroutines in a unified manner.

[0194] Compared with the prior art, in which threads are scheduled by thread schedulers, coroutine schedulers schedule coroutines. When scheduling coroutines, it is necessary to first switch to the thread where the coroutine is located, and then switch to the coroutine progressive scheduling. Two-level switching is required, which has high overhead, and there are many interferences in the kernel, and the determinism of scheduling cannot be guaranteed. In this possible implementation method, unified scheduling by a unified scheduler avoids two-level scheduling and reduces overhead. Moreover, the unified scheduler is located in the functional safety partition and will not be interfered with, ensuring the determinism of scheduling.

[0195] above Figures 3 to 7 The multiple embodiments of the present invention describe the process from process startup to process running in a functional safety partition. Figure 8 Taking the map scene in the autonomous driving vehicle platform shown as an example, the method of running the process in the embodiment of the present application is further introduced.

[0196] like Figure 8 As shown, the autonomous driving vehicle platform includes functional safety applications, middleware, operating system and hardware layers.

[0197] Functional safety applications may include map engine applications, localization applications, perception applications, prediction applications, and planning applications.

[0198] The middleware includes corresponding configuration files for starting and running the processes of various functional safety applications.

[0199] The operating system consists of a kernel and functional safety partitions.

[0200] The hardware layer includes a computer unit, a camera, a memory and a sensor. The computer unit may be a processor, and the sensor may include a lidar.

[0201] The above process to realize the functions of the map engine application includes:

[0202] S1. Respond to the map loading request of the map engine application and read the map file in the middleware.

[0203] After the map engine application process is started, it listens for positioning events and issues a map loading request when a positioning event occurs.

[0204] The positioning event may be a global positioning system (GPS) event.

[0205] S2. The middleware processes the map loading request, loads the corresponding map file into the memory according to the GPS parameters, and triggers the mmap system call in the functional safety partition.

[0206] S3. The functional safety partition passes the context of the mmap system call to the kernel through an agent (eg, the second agent module in the above embodiment) and shared memory.

[0207] S4. The kernel processes the mmap system call request and reads the map file through the file system in the read-only memory segment.

[0208] S5. The kernel maps the map file to the address space of the map engine application in the functional safety partition and passes the return value to the functional safety partition.

[0209] S6. The agent in the functional safety partition (for example, the second agent module in the above embodiment) obtains the consistency check value according to the map path, and calculates the consistency check value of the map file in the memory. After comparison, if the two are found to be consistent, the check passes and the return value is passed to the middleware.

[0210] S7. After the system call processing is completed, the middleware issues a map reading success event, which is called back by the map engine for reading.

[0211] This scenario is described by taking the running process making a system call as an example. Other related running process processes (for example, page fault exception) can also be combined with the description in the above embodiment and the present invention. Figure 8 Understand the process of the scene.

[0212] Overall, the above steps 201 to 204, steps 301 to 304, steps 401 to 406, steps 501 to 507, steps 601 to 607, and steps 701 to 705, as well as the processes S1 to S7 in the above scenario example, can be executed by the device running the application. Because the physical resources of the kernel and the functional safety partition are isolated, if the kernel is managed by the first processing device and the functional safety partition is managed by the second processing device, from the perspective of the first processing device and the second processing device, the above steps 201 to 203 can be executed by the first processing device, and step 204 can be executed by the second processing device. The above steps 301, 302, 303 and 304 can be executed by the first processing device. The above steps 401 and 402 can be executed by the first processing device, steps 403 and 404 can be executed by the second processing device, and the above steps 405 and 406 can be executed by the first processing device. The above steps 501 and 502 may be performed by the second processing device, steps 503, 504 and 505 may be performed by the first processing device, and steps 506 and 507 may be performed by the second processing device. The above steps 601 and 602 may be performed by the second processing device, steps 603, 604, 605 and 606 may be performed by the first processing device, and step 607 may be performed by the second processing device. The above steps 701 and 703 may be performed by the first processing device, and steps 702, 704 and 705 may be performed by the second processing device. The first processing device and the second processing device are included in the terminal device.

[0213] The above describes the method for running a process provided by an embodiment of the present application. The following describes the device for running a process provided by an embodiment of the present application in conjunction with the accompanying drawings.

[0214] like Fig. 9 As shown, an embodiment of the device 80 for running a process provided by an embodiment of the present application includes: a receiving unit 801, a first processing unit 802, a second processing unit 803, a third processing unit 804 and a sending unit 805.

[0215] The receiving unit 801 is used to receive a process start request, where the process start request is used to instruct to start a target process.

[0216] The first processing unit 802 is used to execute the executable file of the target process in the kernel according to the process start request received by the receiving unit 801, and obtain the first running function data supporting the running of the target process in the kernel.

[0217] The second processing unit 803 is used to migrate the first operating function data obtained by the first processing unit 802 to the functional safety partition to obtain second operating function data. The functional safety partition and the kernel are located in the same privileged layer.

[0218] The third processing unit 804 is used to run the target process in the functional safety partition based on the second running function data obtained by the second processing unit 803.

[0219] In the solution provided by the embodiment of the present application, both the functional safety partition and the kernel are located in the kernel layer. In this way, when the process is running, there is no need to switch from the user layer to the kernel layer to call the kernel layer service, thereby reducing the performance overhead caused by the privileged layer switching and improving the performance of the processor and terminal equipment.

[0220] Optionally, the first operating function data includes the virtual address of the target process, the mapping relationship between the virtual address and the first physical address, and the context of the target process, the first physical address being the physical address assigned to the target process in the storage resources of the kernel; the second operating function data includes the virtual address of the target process, the mapping relationship between the virtual address and the second physical address, and the context of the target process, the second physical address being the physical address assigned to the target process in the storage resources of the functional safety partition.

[0221] Optionally, the second processing unit 803 is used to trigger the virtual machine manager to migrate the virtual address to the functional safety partition, release the mapping relationship between the virtual address and the first physical address, and establish a mapping relationship between the virtual address and the second physical address; pass the context of the target process to the functional safety partition through shared memory, and the shared memory is the memory shared by the kernel and the functional safety partition.

[0222] Optionally, the first processing unit 802 is also used to create a first task structure in the kernel when the kernel executes the executable file of the target process, and the first task structure is used to store the context of the target process; and add an indication value in the first task structure, and the indication value is used to indicate that the target process needs to run in the functional safety partition.

[0223] The sending unit 805 is used to send a first notification from the kernel to the functional safety according to the indication value when running the target process, where the first notification is used to instruct to create a second task structure in the functional safety partition.

[0224] The third processing unit 804 is used to create a second task structure according to the first notification, and store the context of the target process in the second task structure.

[0225] Optionally, the third processing unit 804 is also used to read the context of the target process from the shared memory to the functional safety partition; perform a consistency check on the context of the target process to obtain a first check value; if the first check value is the same as the second check value, it is determined that the context of the target process is secure data, and the second check value is a trusted value obtained by performing a consistency check on the initial configuration context of the target process.

[0226] Optionally, the third processing unit 804 is configured to store the context of the system call instruction from the functional security partition into the shared memory if the target process calls the system call instruction of the functional security partition during runtime.

[0227] The sending unit 805 is used to send a second notification from the functional safety partition to the kernel, where the second notification is used to indicate that a system call occurs.

[0228] The second processing unit 803 is also used to read the context of the system call instruction from the shared memory, and call the system call instruction of the kernel according to the context of the system call instruction to make a system call to obtain the return value of the system call; and pass the return value of the system call to the functional safety partition through the shared memory.

[0229] Optionally, the third processing unit 804 is also used to read the return value of the system call from the shared memory to the functional safety partition; perform a consistency check on the return value of the system call to obtain a third check value; if the third check value is the same as the fourth check value, it is determined that the return value of the system call is safe data, and the fourth check value is a trusted value obtained by performing a consistency check on the original file corresponding to the system call.

[0230] Optionally, the third processing unit 804 is further configured to store the context of the page fault exception from the functional security partition into the shared memory if a page fault exception occurs during the operation of the target process.

[0231] The sending unit 805 is used to send a third notification from the functional safety partition to the kernel, where the third notification is used to indicate that a page fault exception occurs.

[0232] The second processing unit 803 is also used to read the context of the page fault exception from the shared memory, call the page fault exception handling function in the kernel according to the context of the page fault exception, and perform page fault exception handling according to the page fault exception handling function to obtain a processing result; and pass the processing result to the functional safety partition through the shared memory.

[0233] It should be noted that the above-mentioned sending unit 805 can be the first sending unit, the second sending unit or the third sending unit. The first processing unit 802, the second processing unit 803 and the third processing unit 804 can also be implemented by one processing unit or two processing units. If the device for running the function is a terminal device or a computer system in the terminal device, then the first processing unit 802 and the second processing unit 803 can be included in the first processing device, and the first processing device can be implemented by a processor or a processing core, and the third processing unit 804 can be included in the second processing device, and the second processing device can be implemented by another processor or processing core. The first processing device and the second processing device can have their own independent receiving unit and sending unit. This can ensure that the computing resources of the kernel are isolated from the computing resources of the functional safety partition.

[0234] The device 80 of the above-mentioned motion process can be understood by referring to the embodiment of the method part of the above-mentioned motion process, and will not be described in detail here.

[0235] Fig.10 As shown, a possible logical structure diagram of a computer device 90 provided in an embodiment of the present application. The computer device may be the terminal device described in the aforementioned embodiment. The computer device 90 includes: a processor system 901, a communication interface 902, a memory 903 and a bus 904. The processor system 901 may include a first processor and a second processor, the first processor corresponding to the kernel, and the second processor corresponding to the functional safety partition. If the processor system is a processor, then the first processor is a processor core. The second processor is another processor core. The memory 903 may include a first memory and a second memory, the first memory corresponding to the kernel, and the second memory corresponding to the functional safety partition. The processor system 901, the communication interface 902 and the memory 903 are interconnected via a bus 904. In an embodiment of the present application, the processor system 901 is used to control and manage the actions of the computer device 90. For example, the processor system 901 is used to execute Figure 3 Steps 202 to 204 of Figure 4 Steps 301 to 304 in Figure 5 Steps 401 to 406 in Fig. 6A Steps 501 to 507 in Figure 6B Steps 601 to 607 in Figure 7 The steps 701 to 705 in the embodiment and / or other processes for the technology described herein. The specific steps performed by the first processor and the second processor can be understood by referring to the steps of the first processing device and the second processing device described above. The communication interface 902 is used to support the computer device 90 to communicate. The memory 903 is used to store the program code and data of the computer device 90.

[0236] Among them, the processor system 901 can be a central processing unit system unit, a general-purpose processor system, a digital signal processor system, an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a transistor logic device, a hardware component or any combination thereof. It can implement or execute various exemplary logic blocks, modules and circuits described in conjunction with the contents disclosed in this application. The processor system can also be a combination that implements computing functions, such as a combination of one or more microprocessor systems, a combination of a digital signal processor system and a microprocessor system, and so on. The bus 904 can be a peripheral component interconnect standard (Peripheral Component Interconnect, PCI) bus or an extended industry standard architecture (Extended Industry Standard Architecture, EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Fig.10 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.

[0237] like Fig.11 As shown, a possible logical structure diagram of a computer device 1000 provided in an embodiment of the present application. The computer device may be the terminal device described in the above embodiment. The computer device 1000 includes: a hardware layer 1001 and a virtual machine (VM) layer 1002, and the VM layer may include one or more VMs. The hardware layer 1001 provides hardware resources for the VM to support the operation of the VM. The functions of the VM and the processes related to the present application can be referred to in the above Figures 1 to 8 The hardware layer 1001 includes hardware resources such as a processor, a communication interface, and a memory.

[0238] In another embodiment of the present application, a computer-readable storage medium is further provided, wherein the computer-readable storage medium stores computer-executable instructions. When at least one processor of the device executes the computer-executable instructions, the device executes the above Figures 1 to 8 Methods for running processes described in some embodiments.

[0239] In another embodiment of the present application, a computer program product is also provided. The computer program product includes computer-executable instructions, which are stored in a computer-readable storage medium; at least one processor of the device can read the computer-executable instructions from the computer-readable storage medium, and at least one processor executes the computer-executable instructions so that the device performs the above Figures 1 to 8 Some embodiments describe a method for running a process.

[0240] In another embodiment of the present application, a chip system is also provided, the chip system includes a processor, which is used to support the device for running the process to implement the above Figures 1 to 8 Methods for running processes described in some embodiments. In one possible design, the chip system may also include a memory, which is used to store program instructions and data necessary for the device running the process. The chip system may be composed of a chip or may include a chip and other discrete devices.

[0241] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the embodiments of the present application.

[0242] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0243] In the several embodiments provided in the embodiments of the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0244] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0245] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0246] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or the part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (Read-Only Memory, ROM), random access memory (Random Access Memory, RAM), disk or optical disk and other media that can store program codes.

[0247] The above are only specific implementations of the embodiments of the present application, but the protection scope of the embodiments of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or replacements within the technical scope disclosed in the embodiments of the present application, which should be included in the protection scope of the embodiments of the present application. Therefore, the protection scope of the embodiments of the present application shall be based on the protection scope of the claims.

Claims

1. A method for running a process, characterized in that: include: Receiving a process start request, wherein the process start request is used to instruct to start a target process; According to the process start request, executing the executable file of the target process in the kernel to obtain first operation function data supporting the operation of the target process in the kernel, wherein the first operation function data includes a virtual address of the target process, a mapping relationship between the virtual address and a first physical address, and a context of the target process, wherein the first physical address is a physical address allocated to the target process in the storage resources of the kernel; Migrating the first running function data to a functional safety partition to obtain second running function data, wherein the functional safety partition and the kernel are located at the same privileged layer, the second running function data including a virtual address of the target process, a mapping relationship between the virtual address and a second physical address, and a context of the target process, wherein the second physical address is a physical address allocated to the target process in a storage resource of the functional safety partition; Based on the second running function data, the target process is run in the functional safety partition.

2. The method according to claim 1, characterized in that: The step of migrating the first operation function data to the functional safety partition to obtain the second operation function data includes: Triggering the virtual machine manager to migrate the virtual address to the functional safety partition, release the mapping relationship between the virtual address and the first physical address, and establish a mapping relationship between the virtual address and the second physical address; The context of the target process is passed to the functional safety partition through a shared memory, where the shared memory is a memory shared by the kernel and the functional safety partition.

3. The method according to claim 2, characterized in that The method further comprises: When the kernel executes the executable file of the target process, a first task structure is created in the kernel, where the first task structure is used to store the context of the target process; Adding an indication value in the first task structure, wherein the indication value is used to indicate that the target process needs to run in the functional safety partition; When the target process is running, according to the indication value, sending a first notification from the kernel to the functional safety partition, wherein the first notification is used to instruct the creation of a second task structure in the functional safety partition; According to the first notification, a second task structure is created, and the context of the target process is stored in the second task structure.

4. The method according to claim 2 or 3, characterized in that: The method further comprises: Reading the context of the target process from the shared memory to the functional security partition; Performing a consistency check on the context of the target process to obtain a first check value; If the first check value is the same as the second check value, it is determined that the context of the target process is secure data, and the second check value is a credible value obtained by performing a consistency check on the initial configuration context of the target process.

5. The method according to claim 2 or 3, characterized in that: The method further comprises: If the target process calls the system call instruction of the functional security partition during runtime, storing the context of the system call instruction from the functional security partition into the shared memory; Sending a second notification from the functional security partition to the kernel, the second notification being used to indicate that a system call has occurred; Reading the context of the system call instruction from the shared memory, and calling the system call instruction of the kernel according to the context of the system call instruction to perform a system call, and obtaining a return value of the system call; The return value of the system call is passed to the functional safety partition through the shared memory.

6. The method according to claim 5, characterized in that The method further comprises: Reading the return value of the system call from the shared memory to the functional safety partition; Performing a consistency check on the return value of the system call to obtain a third check value; If the third check value is the same as the fourth check value, it is determined that the return value of the system call is safe data, and the fourth check value is a credible value obtained by performing a consistency check on the original file corresponding to the system call.

7. The method according to claim 2 or 3, characterized in that: The method further comprises: If a page fault exception occurs in the target process during operation, storing the context of the page fault exception from the functional security partition into the shared memory; Sending a third notification from the functional security partition to the kernel, the third notification being used to indicate that a page fault exception occurs; Reading the context of the page fault exception from the shared memory, calling a page fault exception processing function in the kernel according to the context of the page fault exception, and performing page fault exception processing according to the page fault exception processing function to obtain a processing result; The processing result is transmitted to the functional safety partition through the shared memory.

8. The method according to any one of claims 1 to 3, characterized in that: The target process includes a thread and a coroutine, the thread is created in the kernel and runs in the functional safety partition, and the coroutine is created in the functional safety partition and runs in the functional safety partition; The functional safety partition includes a unified scheduler, and the unified scheduler is used to uniformly schedule the threads and the coroutines.

9. A device for running a process, characterized in that: include: A receiving unit, configured to receive a process start request, wherein the process start request is used to instruct to start a target process; a first processing unit, configured to execute the executable file of the target process in the kernel according to the process start request received by the receiving unit, and obtain first operation function data supporting the operation of the target process in the kernel, wherein the first operation function data includes a virtual address of the target process, a mapping relationship between the virtual address and a first physical address, and a context of the target process, wherein the first physical address is a physical address allocated to the target process in the storage resources of the kernel; a second processing unit, configured to migrate the first running function data obtained by the first processing unit to a functional safety partition to obtain second running function data, wherein the functional safety partition and the kernel are located at the same privileged layer, and the second running function data includes a virtual address of the target process, a mapping relationship between the virtual address and a second physical address, and a context of the target process, and the second physical address is a physical address allocated to the target process in a storage resource of the functional safety partition; The third processing unit is configured to run the target process in the functional safety partition based on the second operating function data obtained by the second processing unit.

10. The device according to claim 9, characterized in that The second processing unit is used to trigger the virtual machine manager to migrate the virtual address to the functional safety partition, release the mapping relationship between the virtual address and the first physical address, and establish a mapping relationship between the virtual address and the second physical address; pass the context of the target process to the functional safety partition through shared memory, and the shared memory is the memory shared by the kernel and the functional safety partition.

11. The device according to claim 10, characterized in that The device further includes a first sending unit, The first processing unit is further configured to create a first task structure in the kernel when the kernel executes the executable file of the target process, wherein the first task structure is used to store the context of the target process; and add an indication value in the first task structure, wherein the indication value is used to indicate that the target process needs to run in the functional safety partition; The first sending unit is used to send a first notification from the kernel to the functional safety partition according to the indication value when running the target process, wherein the first notification is used to instruct to create a second task structure in the functional safety partition; The third processing unit is used to create a second task structure according to the first notification, and store the context of the target process in the second task structure.

12. The device according to claim 10 or 11, characterized in that The third processing unit is also used to read the context of the target process from the shared memory to the functional safety partition; perform a consistency check on the context of the target process to obtain a first check value; if the first check value is the same as the second check value, it is determined that the context of the target process is secure data, and the second check value is a trusted value obtained by performing a consistency check on the initial configuration context of the target process.

13. The device according to claim 10 or 11, characterized in that The device further comprises a second sending unit, The third processing unit is configured to store the context of the system call instruction from the functional security partition into the shared memory if the target process calls the system call instruction of the functional security partition during runtime; The second sending unit is used to send a second notification from the functional safety partition to the kernel, where the second notification is used to indicate that a system call occurs; The second processing unit is also used to read the context of the system call instruction from the shared memory, and call the system call instruction of the kernel according to the context of the system call instruction to perform a system call to obtain a return value of the system call; and pass the return value of the system call to the functional safety partition through the shared memory.

14. The device according to claim 13, characterized in that The third processing unit is also used to read the return value of the system call from the shared memory to the functional security partition; perform a consistency check on the return value of the system call to obtain a third check value; if the third check value is the same as the fourth check value, determine that the return value of the system call is security data, and the fourth check value is a trusted value obtained by performing a consistency check on the original file corresponding to the system call.

15. The device according to claim 10 or 11, characterized in that The device further comprises a third sending unit, The third processing unit is further configured to store the context of the page fault exception from the functional safety partition into the shared memory if a page fault exception occurs during the operation of the target process; The third sending unit is used to send a third notification from the functional safety partition to the kernel, where the third notification is used to indicate that a page fault exception occurs; The second processing unit is further configured to read the context of the page fault exception from the shared memory, call a page fault exception processing function in the kernel according to the context of the page fault exception, and perform page fault exception processing according to the page fault exception processing function to obtain a processing result; The processing result is transmitted to the functional safety partition through the shared memory.

16. A computing device, characterized in that: comprising a processor and a computer-readable storage medium storing a computer program; The processor is coupled to the computer-readable storage medium, and when the computer program is executed by the processor, the method according to any one of claims 1 to 8 is implemented.

17. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.

18. A chip system, characterized in that: The method comprises a processor, wherein the processor is called to execute the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Method, device and system for accessing safety world

    CN108959916A

  • Web services in secure execution environments

    US9754116B1