Hot Patch Processing Method and Device
By loading hot patch files to the address space of multiple business processes, generating a unified jump instruction and writing to the main process of shared memory, the problem of hot patches occupying a large amount of memory during the loading of multiple business processes is solved, and memory resources are saved.
Patent Information
- Application Number
- CN202111144914.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-28
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2041-09-28
AI Technical Summary
Hot patches occupy more memory during the loading process of multi-business processes, resulting in wasted memory resources.
The hot patch file is loaded into the process address space of multiple business processes through the first interface, and the base address table of multiple business processes is determined, a unified jump instruction is generated, and it is written to the main process of the target program, and the main process and the business process share memory.
This avoids multiple business processes setting jump instructions and memory space separately, reducing the memory usage of hot patches during the loading process of multiple business processes, greatly saving memory resources.
Smart Images

Figure CN113918244B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of system updates, and in particular, to a hot patch processing method and device. Background Art
[0002] For some service providers with strict business requirements, when there are urgent problems with the software version, traditional upgrades often cannot meet their stringent upgrade conditions because of insufficient timeliness and the need to interrupt the business. Therefore, a more smooth solution with less impact on the business is needed. That is, a method to modify the problem without restarting the device and interrupting the business. The hot patch technology is a technical solution for quickly and low-costly repairing software defects. Compared with upgrading the software version, its main purpose is to modify the execution logic of the process without interrupting the business and restarting the process, so as to repair software vulnerabilities. The hot patch package is generally made and released by the software vendor, and users can conveniently and quickly solve the corresponding software problems by loading the patch package without affecting the business.
[0003] Currently, a relatively mature technical solution is to create a debugging process and directly modify the process code segment using the ptrace system call (a system call interface for debugging processes that can directly modify the process memory or directly call some interfaces existing in the process) to achieve modifying the process execution logic.
[0004] The existing solution mainly performs the following steps: 1. Create a debugging process and call ptrace to associate with the target program to be modified, making it the debugging parent process of the target program, so that functions can be called in the target program and the address space of the target program can be modified. 2. The debugging parent process calls the dlopen (a system call for the process to load dynamic libraries) interface through ptrace to make the target program load the patch dynamic library into the process address space. 3. The debugging parent process modifies the instruction at the function entry of the function to be patched in the target program code segment through ptrace, and uses a long jump instruction to jump to the function entry of the new function in the patch dynamic library. 4. The debugging parent process cancels the tracing of the target program and ends the debugging parent process.
[0005] For a multi-process program model (created by the main process calling the fork (a system call to create child processes) interface to create several business child processes), since the content of their code segments is exactly the same, the code segments of these processes actually map to the same physical memory.
[0006] However, when modifying the code segment of a certain process, due to the principle of process address space isolation, the kernel's copy-on-write mechanism will be triggered. The kernel's minimum unit for memory management is a page. Therefore, no matter how small the memory modification is, the kernel will allocate a new page of memory, completely copy the content from the shared memory page to the new memory page, and perform the modification operation.
[0007] If there are dozens of processes in this program, then modifying the code segment one by one will occupy dozens of additional memory pages, resulting in a large amount of memory waste. If this situation occurs on an embedded device with a small amount of memory that uses hugepage (a large page memory management mechanism, where one page of memory occupies 2048K or 4096K of space, which can reduce the number of memory pages in the system, reduce the page table hierarchy, and effectively reduce the probability of TLB misses, thereby improving system performance), the large amount of memory waste is unacceptable.
[0008] For the above problems, no effective solution has been proposed yet. Summary of the Invention
[0009] Embodiments of the present invention provide a hot patch processing method and device to at least solve the technical problem in the related art that hot patches occupy a large amount of memory during the loading process of multiple service processes, resulting in waste of memory resources.
[0010] According to one aspect of the embodiments of the present invention, there is provided a hot patch processing method, characterized by including: loading a hot patch file into multiple process address spaces respectively corresponding to multiple service processes through a first interface, and respectively determining multiple base address tables respectively corresponding to the multiple service processes, wherein the addresses of the multiple base address tables are the same, and the multiple service processes are all processes of a target program; generating unified jump instructions for the multiple service processes based on the address of the base address table, wherein the jump instructions are used to jump a service process from an old function to a patch function of the hot patch file; writing the jump instructions into the main process of the target program, wherein the main process and the multiple service processes share memory.
[0011] Optionally, loading the hot patch file into multiple process address spaces respectively corresponding to multiple service processes through a first interface, and respectively determining multiple base address tables respectively corresponding to the multiple service processes includes: loading the hot patch file into multiple process address spaces respectively corresponding to multiple service processes through the first interface, generating base addresses respectively corresponding to the multiple service processes, wherein the base addresses are used to call the hot patch file; each service process writes the corresponding base address into its own base address table to determine multiple base address tables respectively corresponding to the multiple service processes.
[0012] Optionally, generating a unified jump instruction for multiple said service processes based on the address in the base address table includes: obtaining the address offset of the patched function in the hot patch file; generating the jump instruction according to the address in the base address table and the address offset.
[0013] Optionally, writing the jump instruction into the main process of the target program includes: determining the target address of the hot patch file in the main process, where the target address of the main process is shared by multiple service processes sharing memory; writing the jump instruction to the target address.
[0014] Optionally, after writing the jump instruction into the main process of the target program, it further includes: when the target service process runs to the target address, in response to the jump instruction, obtaining the base address of the hot patch file relative to the target service process according to the address in the base address table, where the target service process is any one of the multiple service processes; determining the execution address of the patched function according to the base address and the address offset; executing the patched function according to the execution address.
[0015] Optionally, before writing the jump instruction to the target address, it further includes: sending a pre-modification notice to multiple said service processes through the main process, where the pre-modification notice is used to notify the service processes to stop running; activating a preset preprocessing function in the hot patch file to perform a write process on the hot patch file when receiving a successful response message from multiple said service processes to the pre-modification notice.
[0016] Optionally, before loading the hot patch file into the multiple process address spaces respectively corresponding to multiple service processes through a first interface and respectively determining multiple base address tables corresponding to multiple service processes, it further includes: verifying the hot patch file, at least including one of the following: source verification, version verification, integrity verification, target program verification.
[0017] According to another aspect of the embodiments of the present invention, there is also provided a hot patch processing device, including: a loading module, configured to load a hot patch file into multiple process address spaces respectively corresponding to multiple service processes through a first interface and respectively determine multiple base address tables corresponding to multiple service processes, where the addresses of the multiple base address tables are the same, and the multiple service processes are all processes of a target program; a generating module, configured to generate a unified jump instruction for multiple said service processes based on the address in the base address table, where the jump instruction is used to jump a service process from an old function to the patched function of the hot patch file; a writing module, configured to write the jump instruction into the main process of the target program, where the main process and the multiple service processes share memory.
[0018] According to another aspect of the embodiments of the present invention, a processor is further provided. The processor is used to run a program, and when the program runs, it executes the hot patch processing method described in any one of the above.
[0019] According to another aspect of the embodiments of the present invention, a computer storage medium is further provided. The computer storage medium includes a stored program, and when the program runs, it controls the device where the computer storage medium is located to execute the hot patch processing method described in any one of the above.
[0020] In the embodiments of the present invention, the hot patch file is loaded into the multiple process address spaces corresponding to multiple service processes respectively through the first interface, and the multiple base address tables corresponding to the multiple service processes are respectively determined. Among them, the addresses of the multiple base address tables are the same, and the multiple service processes are all processes of the target program; based on the address of the base address table, a unified jump instruction for the multiple service processes is generated. The jump instruction is used to jump the service process from the old function to the patch function of the hot patch file; the jump instruction is written into the main process of the target program. The main process and the multiple service processes share memory. By generating a unified jump instruction for the multiple services according to the base address table of the hot patch in the multiple service processes and writing the jump instruction into the main program of the shared memory, the purpose that the same jump instruction in the main process of the shared memory can be adopted by the multiple service processes to realize the jump to the hot patch function is achieved. Thus, the technical effect of avoiding that multiple service processes respectively set jump instructions and memory spaces to jump to the hot patch function is realized, the memory occupied during the loading process of the hot patch in multiple service processes is reduced, and a great deal of memory resources are saved. Furthermore, the technical problem that the hot patch in the related art occupies more memory during the loading process of multiple service processes, resulting in waste of memory resources, is solved. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The illustrative embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation to the present invention. In the drawings:
[0022] Figure 1 is a flowchart of the hot patch execution logic in the prior art;
[0023] Figure 2 is a flowchart of a hot patch processing method according to an embodiment of the present invention;
[0024] Figure 3 is a flowchart of the hot patch execution of multiple processes according to an embodiment of the present invention;
[0025] Figure 4 is a schematic diagram of the hot patch loading according to an embodiment of the present invention;
[0026] Figure 5 It is a schematic diagram of a multi-process base address table according to an embodiment of the present invention;
[0027] Figure 6 It is a flowchart of the main process loading a hot patch according to an embodiment of the present invention;
[0028] Figure 7 It is a flowchart of a service process loading a hot patch according to an embodiment of the present invention;
[0029] Figure 8 It is a schematic diagram of a hot patch processing device according to an embodiment of the present invention. Detailed implementation manners
[0030] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0031] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order different from those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0032] According to an embodiment of the present invention, a method embodiment of a hot patch processing method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that here.
[0033] Figure 2 It is a flowchart of a method for processing protocol data according to an embodiment of the present invention, as Figure 2 shown, the method includes the following steps:
[0034] Step S202: Load the hot patch file into the multiple process address spaces corresponding to multiple service processes respectively through the first interface, and respectively determine multiple base address tables corresponding to the multiple service processes. Among them, the addresses of the multiple base address tables are the same, and the multiple service processes are all processes of the target program;
[0035] Step S204: Generate unified jump instructions for the multiple service processes based on the addresses of the base address tables. The jump instructions are used to jump the service processes from the old function to the patched function of the hot patch file;
[0036] Step S206: Write the jump instructions into the main process of the target program. The main process and the multiple service processes share the memory.
[0037] Through the above steps, by loading the hot patch file into the multiple process address spaces corresponding to multiple service processes respectively through the first interface, and respectively determining multiple base address tables corresponding to the multiple service processes. Among them, the addresses of the multiple base address tables are the same, and the multiple service processes are all processes of the target program; generating unified jump instructions for the multiple service processes based on the addresses of the base address tables. The jump instructions are used to jump the service processes from the old function to the patched function of the hot patch file; writing the jump instructions into the main process of the target program. The main process and the multiple service processes share the memory. In this way, by generating unified jump instructions for multiple services according to the base address tables of the hot patch in multiple service processes and writing the jump instructions into the main program of the shared memory, the purpose that multiple service processes can all use the same jump instruction in the main process of the shared memory to implement the jump to the hot patch function is achieved. Thus, the purpose of avoiding that multiple service processes respectively set jump instructions and memory spaces to jump to the hot patch function is achieved, reducing the memory occupied during the loading process of the hot patch in multiple service processes, greatly saving memory resources, and further solving the technical problem that in the related technology, the hot patch occupies more memory during the loading process in multiple service processes, resulting in waste of memory resources.
[0038] The above hot patch file can be a patch for quickly and low - cost repairing software defects. Compared with upgrading the software version, its main purpose is to modify the execution logic of the process on the premise that the service is not interrupted and the process is not restarted, so as to repair software vulnerabilities. The above service processes are multiple and belong to multiple service processes of the target program. When there are multiple service processes, during the loading of the hot patch, their respective loading processes are independent, and physical storage spaces for caching the patch files of their respective service processes need to be created. This will result in that when multiple service processes load the hot patch file, a large amount of physical memory needs to be occupied, leading to waste of memory resources.
[0039] The above-mentioned first interface can be the dl_open interface of the target program. Through this first interface, a hot patch file, for example, a hot patch dynamic library, can be loaded into the process address spaces of multiple service processes respectively. This process address space is set in the target program for each service process and is used to store the process addresses corresponding to the respective service processes.
[0040] After the above-mentioned hot patch file is loaded into the process address space corresponding to the service process through the above-mentioned first interface, the base address of the hot patch file in the service process will be automatically generated, that is, the specific address where the hot patch file needs to be written into the service process. However, since the patching positions of different service processes are different, the above-mentioned first interface cannot ensure that the hot patch file is loaded into the same process address space, which will result in inconsistent jump instructions for each service process, that is, the addresses for patching through the patch function are inconsistent, and there will still be problems of each performing jumps and occupying the corresponding IoT memory.
[0041] Therefore, in this embodiment, when writing the hot patch file into the process address space of the service process, the generated base address of the hot patch file is written into the base address table of the service process. In the target program, the addresses of the base address tables of multiple service processes are the same. Thus, the addresses of the hot patch file are unified through the addresses of the base address tables.
[0042] Then, based on the addresses of the above-mentioned base address tables, unified jump instructions for multiple service processes are generated. Since the addresses of the base address tables of multiple service processes are the same, the jump instructions to the base address tables are also the same. Moreover, by using unified jump instructions for multiple service processes, when the jump instructions are triggered during operation, they can jump to the base address table to obtain the base address of the hot patch file, thereby obtaining and running the hot patch file to complete the patching process for each service process.
[0043] After the jump instructions are generated, they also need to be written into the memory of the service process so that when the service process runs to the jump instructions, it can call the stored jump instructions to complete the jump to the hot patch. However, when storing the same jump instruction in each service process, the jump instruction still needs to be copied multiple times and multiple physical memories need to be created, resulting in a problem of memory occupation. Considering that the main program and service programs of the target program can share memory, in this embodiment, the main process and multiple service processes share memory, and only one memory space is required to meet the storage requirements of the jump instructions for multiple service processes.
[0044] Optionally, load the hot patch file into multiple process address spaces corresponding to multiple service processes respectively, and determine multiple base address tables corresponding to multiple service processes respectively, including: load the hot patch file into multiple process address spaces corresponding to multiple service processes respectively through the first interface, and generate base addresses corresponding to multiple service processes respectively, where the base address is used to call the hot patch file; each service process writes the corresponding base address into its own base address table to determine multiple base address tables corresponding to multiple service processes respectively.
[0045] The above-mentioned first interface can be the dl_open interface. When loading the patch, the patch management program notifies the main process of the target program. After receiving the loading notification, the main process notifies all service processes to call dl_open to load the patch into their respective corresponding process address spaces and resolve all symbol link redirections. However, since dl_open cannot ensure that all processes load the patch dynamic library into the same process address space, this will result in inconsistent jump instructions for each process. To solve this problem, the target program requires a patch dynamic library base address table, which is a global variable of the process and has the same address in different processes. After each service process finishes loading the patch through dl_open, write the base address of the patch dynamic library into the patch dynamic library base address table.
[0046] Optionally, generate unified jump instructions for multiple service processes based on the address of the base address table, including: obtain the address offset of the patched function in the hot patch file; generate jump instructions according to the address of the base address table and the address offset.
[0047] Since the base address table is a global variable of the target program, its address is the same in all service processes; and all service processes load the same hot patch file, so the offset of the patched function in the hot patch file is the same. Thus, all processes can use exactly the same jump instructions to implement the jump from the old function to the new patched function.
[0048] Optionally, write the jump instructions into the main process of the target program, including: determine the target address of the hot patch file in the main process, where the target address of the main process is shared with multiple service processes sharing the memory; write the jump instructions to the target address.
[0049] The main process and multiple service processes in the above-mentioned target program have shared memory. Now, only need to write the unified jump instructions of multiple service processes into the main process, then store the jump instructions in the shared memory, and all service processes participating in the memory sharing can call and use them. The above-mentioned target address is also the address where the hot patch file needs to be inserted into the main process, which can be determined through the hot patch file.
[0050] It should be noted that when writing a hot patch file into the main program, the preprocessing function of the hot patch file can be activated first to make the hot patch file in a processable state, ensuring the subsequent writing process of the hot patch file.
[0051] Optionally, after writing the jump instruction into the main process of the target program, it further includes: when the target service process runs to the target address, in response to the jump instruction, obtaining the base address of the hot patch file relative to the target service process according to the address in the base address table, where the target service process is any one of multiple service processes; determining the execution address of the patch function according to the base address and the address offset; and executing the patch function according to the execution address.
[0052] Specifically, when the jump instruction is executed, when the target service process runs to the target address, the jump instruction is triggered, and the base address of the hot patch file is read through the address in the base address table and stored in the register. The base address of the hot patch file in the register is added to the offset of the patch function in the hot patch file to obtain the address of the patch function in the process address space, that is, the execution address, and it is stored in the register. When executing the patch function according to the execution address, the jump instruction is used to jump to the execution address of the patch function in the register in the process address space, which is the address of the old function being executed by the current service process, completing the jump from the old function to the new patch function.
[0053] It should be noted that for each patch point or different programs, the address of the patch dynamic library base address table and the offset of the patch function in the dynamic library are different. Therefore, the jump instruction needs to be dynamically assembled according to the binary format of the instruction.
[0054] Optionally, before writing the jump instruction to the target address, it further includes: sending a pre-modification notice to multiple service processes through the main process, where the pre-modification notice is used to notify the service processes to stop running; and activating the preset preprocessing function in the hot patch file to perform the writing process of the hot patch file when receiving the successful response messages of multiple service processes to the pre-modification notice.
[0055] Since the main process and the service processes are in a completely shared memory state, only the main process needs to modify the code segment, and all service processes will change accordingly. However, the main process needs to stop running when modifying. Due to the reason of shared memory, the main process sends a pre-modification notice to all service processes, notifying all processes to stop at the safe point and waiting for all service processes to respond successfully, stopping multiple service processes.
[0056] The above activation of the preprocessing function is to make the hot patch function in a processable state, providing a basis for the subsequent code written into the main process, thereby ensuring that the jump instruction can be successfully written into the above main process.
[0057] Optionally, before loading the hot patch file into the multiple process address spaces corresponding to multiple service processes respectively through the first interface and determining the multiple base address tables corresponding to the multiple service processes respectively, it further includes: verifying the hot patch file, including at least one of the following: source verification, version verification, integrity verification, and target program verification.
[0058] Specifically, the above-mentioned source verification is also the patch source verification: when making and releasing the patch package, the patch package will carry the signature information of the patch provider. In the patch source verification stage, use the public key of the patch publisher to verify the patch signature to ensure the security and reliability of the patch source.
[0059] The above-mentioned version verification is also the software version verification: the patch package contains patch description information. Read the patch description information and compare it with the patch activation environment to ensure that the patch version matches the software version.
[0060] The above-mentioned integrity verification: calculate the digest of the patch dynamic library file through crc32 and compare it with the information in the patch description file to ensure that the patch dynamic library is correct and complete without damage.
[0061] The above-mentioned target program verification: calculate the digest of the executable file of the target program through crc32 and compare it with the patch description information to ensure that the patch matches the target file.
[0062] Thus, the stability and reliability of the hot patch during the loading and implementation process are guaranteed, providing a strong guarantee for the loading and implementation of the hot patch.
[0063] It should be noted that the embodiment of the present application also provides an optional implementation manner, which will be described in detail below.
[0064] This embodiment provides a hot patch implementation solution for embedded high-performance devices. According to the characteristics of limited memory and high performance requirements of embedded devices, a hot patch implementation solution is designed for the high-concurrency model of multi-process processing. The main purpose is to check the security and legality of the patch, load the patch code into the process address space, avoid wasting a large number of memory pages caused by modifying the code segment and triggering copy-on-write, and ensure that the patch jump instructions are exactly the same among all processes.
[0065] Figure 3 It is the flowchart of the hot patch execution of multiple processes according to the embodiment of the present invention. As Figure 3 shown, the complete technology of this embodiment is mainly divided into the following four parts according to the module logic:
[0066] 1. Patch verification:
[0067] The patch verification process mainly includes four parts: patch source verification, software version verification, patch dynamic library verification, and target program verification.
[0068] Patch source verification: When making and releasing a patch package, the patch package will carry the signature information of the patch provider. In the patch source verification stage, the public key of the patch publisher is used to verify the patch signature to ensure the security and reliability of the patch source.
[0069] Software version verification: The patch package contains patch description information. Read the patch description information and compare it with the patch activation environment to ensure that the patch version matches the software version.
[0070] Patch dynamic library verification: Calculate the digest of the patch dynamic library file through crc32 and compare it with the information in the patch description file to ensure that the patch dynamic library is correct and complete without damage.
[0071] Target program verification: Calculate the digest of the target program's executable file through crc32 and compare it with the patch description information to ensure that the patch matches the target file.
[0072] 2. Patch loading:
[0073] Figure 4 is a schematic diagram of hot patch loading according to an embodiment of the present invention. As Figure 4 shown, when loading the patch, the patch management program notifies the main process of the target program. After receiving the loading notification, the main process notifies all business processes to call dl_open to load the patch dynamic library into the process address space and solve all symbol link redirection problems.
[0074] However, since dl_open cannot guarantee that all processes load the patch dynamic library into the same process address space, this will cause the jump instructions of each process to be inconsistent. To solve this problem, the target program needs a patch dynamic library base address table, which is a global variable of the process and has the same address in different processes.
[0075] Figure 5 is a schematic diagram of the multi-process base address table according to an embodiment of the present invention. As Figure 5 shown, after each process completes dl_open, write the base address of the patch dynamic library into the patch dynamic library base address table and notify the main process that the loading is complete.
[0076] Figure 6 is a flowchart of the main process loading the hot patch according to an embodiment of the present invention. As Figure 6 shown, it is the process of loading the hot patch for the main process of the target program.
[0077] Figure 7It is a flowchart for loading a hot patch for a service process according to an embodiment of the present invention. As Figure 7 shown, it is a process for loading a hot patch for a service process of a target program.
[0078] 3. Dynamically generate jump instructions:
[0079] Since it is necessary to avoid triggering the copy-on-write of the kernel, which causes a large waste of memory pages, the basic requirement for jump instructions is that the jump instructions modified by each process must be exactly the same. However, since the dl_open interface cannot guarantee that the addresses of dynamically loaded libraries are the same for each process, simple long jump instructions cannot meet the requirements.
[0080] Therefore, the process of dynamically generating jump instructions is as follows:
[0081] 1) Read the base address of the patch dynamic library through the address of the patch dynamic library base address table and store it in a register.
[0082] 2) Add the base address of the patch dynamic library in the register to the offset of the patch function in the dynamic library to obtain the address of the patch function in the process address space, and store it in a register.
[0083] 3) Use a long jump instruction to jump to the address of the patch function in the process address space in the register, completing the jump from the old function to the new patch function.
[0084] Since the patch dynamic library base address table is a global variable of the target program, its address is the same in all target programs; and all processes load the same patch dynamic library, so the offset of the patch function in the dynamic library is the same. Thus, all processes can use exactly the same jump instructions to achieve the jump from the old function to the new patch function.
[0085] Taking X86_64 as an example, the dynamically generated jump instructions are as follows:
[0086] movabs $jmp_entry, %rax
[0087] movabs $offset, %r10
[0088] add %r10, %rax
[0089] jmpq *%rax
[0090] Among them, $jmp_entry is the address of the patch dynamic library base address table, and $offset is the offset of the patch function in the dynamic library. For each patch point or different programs, the address of the patch dynamic library base address table and the offset of the patch function in the dynamic library are different. Therefore, the jump instructions need to be dynamically assembled according to the binary format of the instructions.
[0091] 4. Modify the code segment:
[0092] Due to the copy-on-write mechanism of the kernel, modifying the code segment using methods such as ptrace will result in waste of memory pages. Therefore, to avoid triggering the copy-on-write mechanism, during the initialization stage of the process supporting hot patching (before calling fork to create the business process), the mmap interface needs to be used to set the process's own code segment as shared memory, and then the business process is created. In this way, the code segments among multiple processes will be in a completely shared memory state, rather than the shared memory in the copy-on-write state.
[0093] Since the processes are in a completely shared memory state, only the main process needs to modify the code segment, and all business processes will change accordingly.
[0094] The main process mainly has the following steps:
[0095] 1) Send a pre-modification notice to all business processes, notify all processes to stop at the safe point, and wait for all business processes to respond successfully.
[0096] 2) Execute the patch activation preprocessing function set in the patch dynamic library.
[0097] 3) Call the mprotect interface (a system call that can modify the page protection permissions of a process) to modify the memory page where the function to be modified is located to be readable, writable, and executable.
[0098] 4) Directly use memcpy (a memory copy function) to copy the jump instruction generated in the previous step to the function entry that needs to be modified.
[0099] 5) Call the mprotect interface to restore the memory page to the readable and executable (removing writable) protection permissions.
[0100] 6) Notify all business processes that the modification is completed and resume to the normal working state.
[0101] This embodiment can be applied to run at the critical nodes of the key services of the embedded device, and its operating environment does not allow any interruption of services such as upgrading versions and restarting. When the device detects a software fault, the hot patch solution can be used to repair the software fault without affecting the service.
[0102] This embodiment can repair software faults without affecting the service. It can solve the situation of a large amount of waste of memory pages when patching using the traditional ptrace method. Its good and careful patch verification method can ensure the security and reliability of the patch. Without the assistance of a debugging process, it greatly improves the efficiency of patching and reduces the possibility of service fluctuations. The safe code segment modification method ensures the stability of the process running environment.
[0103] This embodiment uses a patch dynamic library base address table to store the base addresses of patch dynamic libraries, which facilitates the subsequent use of unified jump instructions to modify all processes. The jump method from the old function to the new patch function is to perform the jump by dynamically reading the address and offset, rather than simply using a long jump instruction. The instruction modification method based on the process-shared code segment avoids wasting memory pages.
[0104] Figure 8 It is a schematic diagram of a hot patch processing device according to an embodiment of the present invention. As Figure 8 shown, according to another aspect of the embodiment of the present invention, a hot patch processing device is further provided, including: a loading module 82, a generating module 84, and a writing module 86. The device will be described in detail below.
[0105] The loading module 82 is configured to load a hot patch file into multiple process address spaces respectively corresponding to multiple service processes through a first interface, and respectively determine multiple base address tables respectively corresponding to the multiple service processes. Among them, the addresses of the multiple base address tables are the same, and the multiple service processes are all processes of a target program; the generating module 84 is connected to the above-mentioned loading module 82, and is configured to generate unified jump instructions for the multiple service processes based on the addresses of the base address tables, where the jump instructions are used to jump the service process from the old function to the patch function of the hot patch file; the writing module 86 is connected to the above-mentioned generating module 84, and is configured to write the jump instructions into the main process of the target program, where the main process and the multiple service processes share memory.
[0106] Through the above device, the hot patch file is loaded into multiple process address spaces respectively corresponding to multiple service processes through a first interface, and multiple base address tables respectively corresponding to the multiple service processes are determined. Among them, the addresses of the multiple base address tables are the same, and the multiple service processes are all processes of the target program; based on the addresses of the base address tables, unified jump instructions for the multiple service processes are generated, where the jump instructions are used to jump the service process from the old function to the patch function of the hot patch file; the jump instructions are written into the main process of the target program, where the main process and the multiple service processes share memory. By generating unified jump instructions for multiple services according to the base address tables of the hot patch in multiple service processes and writing the jump instructions into the main program of the shared memory, the purpose that the same jump instructions in the main process of the shared memory can be adopted by multiple service processes to implement jumping to the hot patch function is achieved, thereby realizing the purpose of avoiding that multiple service processes respectively set jump instructions and memory spaces to jump to the hot patch function, reducing the memory occupied during the loading process of the hot patch in multiple service processes, greatly saving memory resources, and further solving the technical problem that the hot patch in the related technology occupies more memory during the loading process in multiple service processes, resulting in waste of memory resources.
[0107] According to another aspect of the embodiments of the present invention, a processor is further provided, which is used to run a program. When the program runs, it executes the hot patch processing method described in any one of the above.
[0108] According to another aspect of the embodiments of the present invention, a computer storage medium is further provided. The computer storage medium includes a stored program. When the program runs, it controls the device where the computer storage medium is located to execute the hot patch processing method described in any one of the above.
[0109] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages and disadvantages of the embodiments.
[0110] In the above embodiments of the present invention, the descriptions of the various embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0111] In several embodiments provided in the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of the units can be a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of units or modules can be in an electrical or other form.
[0112] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0113] In addition, the functional units in the various embodiments of the present invention can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.
[0114] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs that can store program codes.
[0115] The foregoing are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A hot patch processing method, characterized in that, it includes: loading a hot patch file into multiple process address spaces respectively corresponding to multiple service processes through a first interface, and respectively determining multiple base address tables respectively corresponding to the multiple service processes, wherein the addresses of the multiple base address tables are the same, the multiple service processes are all processes of a target program, the base address table includes a base address corresponding to the service process, and the base address is used to call the hot patch file; generating unified jump instructions for the multiple service processes based on the address of the base address table, wherein the jump instructions are used to jump the service process from an old function to a patch function of the hot patch file; writing the jump instructions into the main process of the target program, wherein the main process and the multiple service processes share memory.
2. The method according to claim 1, characterized in that, loading a hot patch file into multiple process address spaces respectively corresponding to multiple service processes through a first interface, and respectively determining multiple base address tables respectively corresponding to the multiple service processes includes: loading the hot patch file into multiple process address spaces respectively corresponding to multiple service processes through a first interface, generating base addresses respectively corresponding to the multiple service processes, wherein the base addresses are used to call the hot patch file; each service process writes the corresponding base address into its own base address table to determine multiple base address tables respectively corresponding to the multiple service processes.
3. The method according to claim 1, characterized in that, generating unified jump instructions for the multiple service processes based on the address of the base address table includes: obtaining the address offset of the patch function in the hot patch file; generating the jump instructions according to the address of the base address table and the address offset.
4. The method according to claim 3, characterized in that, writing the jump instructions into the main process of the target program includes: determining a target address of the hot patch file in the main process, wherein the target address of the main process is shared with multiple service processes sharing memory; writing the jump instructions into the target address.
5. The method according to claim 4, characterized in that, after writing the jump instructions into the main process of the target program, it further includes: when a target service process runs to the target address, in response to the jump instructions, obtaining the base address of the hot patch file relative to the target service process according to the address of the base address table, wherein the target service process is any one of the multiple service processes; determining the execution address of the patch function according to the base address and the address offset; executing the patch function according to the execution address.
6. The method according to claim 4, characterized in that, before writing the jump instructions into the target address, it further includes: sending a pre-modification notice to the multiple service processes through the main process, wherein the pre-modification notice is used to notify the service processes to stop running; In the case of receiving reply success messages of multiple said service processes to the pre-modification notice, activate a preset preprocessing function in the hot patch file to perform a write process on the hot patch file.
7. The method according to any one of claims 1 to 6, characterized in that before loading the hot patch file into multiple process address spaces respectively corresponding to multiple service processes through a first interface and respectively determining multiple base address tables respectively corresponding to the multiple service processes, further comprising: performing verification on the hot patch file, including at least one of the following: source verification, version verification, integrity verification, target program verification.
8. A hot patch processing device, characterized in that comprising: a loading module, configured to load a hot patch file into multiple process address spaces respectively corresponding to multiple service processes through a first interface and respectively determine multiple base address tables respectively corresponding to the multiple service processes, wherein addresses of the multiple base address tables are the same, the multiple service processes are all processes of a target program, and the base address table includes a base address corresponding to the service process, and the base address is used to call the hot patch file; a generating module, configured to generate unified jump instructions for the multiple service processes based on the address of the base address table, wherein the jump instructions are used to jump a service process from an old function to a patch function of the hot patch file; a writing module, configured to write the jump instructions into a main process of the target program, wherein the main process and the multiple service processes share memory.
9. A processor, characterized in that the processor is used to run a program, wherein when the program runs, it executes the hot patch processing method according to any one of claims 1 to 7.
10. A computer storage medium, characterized in that the computer storage medium includes a stored program, wherein when the program runs, it controls a device where the computer storage medium is located to execute the hot patch processing method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Method and device for obtaining resources based on multi-process browser
CN104268229A
Hotfix repairing method used in communication system linux environment
CN106775671A