Task processing method and system

By coordinating the host machine and the secure operating unit to determine vCPU priority, the problem of chaotic processing of high and low priority tasks in the same secure operating unit is solved, and reasonable scheduling of tasks according to priority is achieved, thereby improving the efficiency and accuracy of task processing.

CN114168278BActive Publication Date: 2026-03-20ALIBABA (CHINA) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-05
Publication Date
2026-03-20

AI Technical Summary

Technical Problem

In existing technologies, when high-priority and low-priority tasks are deployed in the same secure operating unit, they cannot be processed according to their priority, resulting in chaotic task execution.

Method used

The host machine determines the priority of the host thread according to a preset priority policy. The secure operation unit determines the priority of the vCPU based on the priority of the host thread and allocates tasks to be processed according to the priority of the vCPU, thereby realizing the reasonable scheduling of tasks with different priorities.

Benefits of technology

This enables tasks to be processed according to their priority within the same secure operating unit, avoiding confusion during task processing and improving the efficiency and accuracy of task processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114168278B_ABST
    Figure CN114168278B_ABST
Patent Text Reader

Abstract

Embodiments of the present specification provide a task processing method and system, wherein the task processing method is applied to a task processing system, the system comprising a host and a secure running unit running on the host, wherein the method comprises: the host determining the priority of a host thread according to a preset priority strategy, wherein the host thread is a vCPU of the secure running unit; the secure running unit determining the priority of the vCPU based on the priority of the host thread determined from the host; and determining the vCPU corresponding to a to-be-processed task based on the priority of the vCPU.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present specification relate to the technical field of computer technology, and in particular to a task processing method. BACKGROUND

[0002] With the continuous development of computer technology, in order to save costs and improve CPU utilization of clusters, many institutions usually adopt a mixed deployment mode of high-priority tasks and low-priority tasks in an OS system. In order to reduce the interference of low-priority tasks on high-priority tasks, the mixed deployment mode usually runs offline tasks (such as big data processing tasks, batch processing tasks, etc.) that have more demands on resources or operating system kernels in a secure run unit.

[0003] However, there are high-priority and low-priority tasks inside the offline tasks, and the secure run unit (virtual machine or secure container) usually has only one global running priority, such as low priority, high priority or a certain specific priority. If tasks of two priorities are deployed in the same secure run unit, it will cause confusion during task running and the tasks cannot be processed according to the high and low priorities, so the tasks of two priorities cannot be deployed in the same secure run unit. SUMMARY

[0004] Therefore, the embodiments of the present specification provide a task processing method. One or more embodiments of the present specification also relate to a task processing system, a computing device, a computer readable storage medium, and a computer program to solve the technical defects in the prior art.

[0005] According to a first aspect of the embodiments of the present specification, a task processing method is provided, applied to a task processing system, the system comprising a host and a secure run unit running on the host, wherein the method comprises:

[0006] determining a priority of a host thread according to a preset priority policy, wherein the host thread is a vCPU of the secure run unit;

[0007] determining a priority of the vCPU based on the priority of the host thread determined from the host; and

[0008] determining the vCPU corresponding to a running task to be processed based on the priority of the vCPU.

[0009] According to a second aspect of the embodiments of the present specification, a task processing system is provided, the system comprising a host and a secure run unit running on the host, wherein

[0010] The host machine is configured to determine a priority of a host machine thread according to a preset priority policy, wherein the host machine thread is a vCPU of the secure running unit.

[0011] The secure running unit is configured to determine a priority of the vCPU based on the priority of the host machine thread determined from the host machine.

[0012] The vCPU corresponding to a task to be processed is determined to run based on the priority of the vCPU.

[0013] According to a third aspect of the embodiments of the present specification, a computing device is provided, comprising:

[0014] a memory and a processor;

[0015] The memory is configured to store computer executable instructions, and the processor is configured to execute the computer executable instructions, and the computer executable instructions, when executed by the processor, implement the steps of any of the task processing methods.

[0016] According to a fourth aspect of the embodiments of the present specification, a computer readable storage medium is provided, which stores computer executable instructions, and the computer executable instructions, when executed by a processor, implement the steps of the task processing method.

[0017] According to a fifth aspect of the embodiments of the present specification, a computer program is provided, and when the computer program is executed in a computer, the computer is caused to execute the steps of the task processing method.

[0018] The task processing method provided by one of the embodiments of the present specification is applied to a task processing system, and the system comprises a host machine and a secure running unit running on the host machine, wherein the method comprises: the host machine determines a priority of a host machine thread according to a preset priority policy, wherein the host machine thread is a vCPU of the secure running unit; the secure running unit determines a priority of the vCPU based on the priority of the host machine thread determined from the host machine; and the vCPU corresponding to a task to be processed is determined to run based on the priority of the vCPU.

[0019] Specifically, the method determines the priority of the host thread, i.e. the vCPU in the secure running unit, in advance based on the host of the task processing system, determines the priority of the vCPU based on the priority of the host thread, and determines the vCPU running the to-be-processed task with different priorities based on the priority of the vCPU, based on the secure running unit capable of managing multiple global priorities in the task processing system; thus avoiding the confusion in the task processing during the task running, realizing the processing of the to-be-processed task according to the priority of the to-be-processed task, and further achieving the purpose of deploying the two kinds of priority tasks in the same secure running unit. BRIEF DESCRIPTION OF DRAWINGS

[0020] Figure 1 is a flow chart of a task processing method provided by an embodiment of the present specification;

[0021] Figure 2 is a flow chart of a task processing method provided by an embodiment of the present specification;

[0022] Figure 3 is a flow chart of a task processing method provided by an embodiment of the present specification;

[0023] Figure 4 is a flow chart of a task processing method provided by an embodiment of the present specification;

[0024] Figure 5 is a flow chart of a task processing method provided by an embodiment of the present specification;

[0025] Figure 6 is a flow chart of a task processing method provided by an embodiment of the present specification;

[0026] Figure 7 is a structural diagram of a task processing system provided by an embodiment of the present specification;

[0027] Figure 8 is a structural diagram of a task processing system provided by an embodiment of the present specification; DETAILED DESCRIPTION

[0028] In the following description, many specific details are set forth in order to provide a thorough understanding of the present specification. However, the present specification can be practiced in many different ways from those described herein, and the skilled in the art can make similar substitutions without departing from the scope of the present specification.

[0029] The terminology used in one or more embodiments of this specification is for the purpose of describing particular embodiments only and is not intended to be limiting of the one or more embodiments of this specification. The singular forms “a,” “described,” and “the” as used in one or more embodiments of this specification and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used in one or more embodiments of this specification refers to and includes any or all possible combinations of one or more associated listed items.

[0030] It should be understood that although the terms first, second, etc., may be used to describe various information in one or more embodiments of this specification, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, first may also be referred to as second without departing from the scope of one or more embodiments of this specification, and similarly, second may also be referred to as first. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to a determination."

[0031] First, the terms and concepts used in one or more embodiments of this specification will be explained.

[0032] Virtual machine: refers to a complete computer system that is simulated by software, has full hardware system functions, and runs in a completely isolated environment.

[0033] Normal running unit: refers to the runc container.

[0034] Secure runtime unit: refers to a virtual machine or secure container instance with secure isolation capabilities, typically with an independent guest OS. Tasks can run in the isolated guest OS.

[0035] Online services: High-priority services, such as e-commerce and search, require real-time performance.

[0036] Offline services: Low-priority, non-real-time tasks, such as big data. However, some offline services may have both high and low priority tasks.

[0037] Mixed-unit environment: An environment in which multiple priority running units are scheduled and operated in a mixed manner.

[0038] Host: The host machine where the running unit (such as a secure running unit or a normal running unit) is located.

[0039] Guest: The independent OS environment of the secure operating unit.

[0040] vCPU: A virtual CPU within a secure operating unit, relative to the physical CPU.

[0041] Running priority: abbreviated as priority, refers to the running priority of task scheduling; in order to facilitate explanation, the running priority of task scheduling is explained as priority in this specification.

[0042] Global running priority: refers to the running priority in the global perspective range of a Host containing multiple cloud running units, that is, the scheduling priority of a task in a running unit (usually a Guest) in all running units on the entire host. A task running in a low-priority running unit may be preempted or suppressed by other high-priority running units on the host, while a task running in a high-priority running unit can preempt the tasks of other low-priority running units on the host.

[0043] Security container: also known as sandbox container, a runtime technology that can provide a complete operating system execution environment (often Linux ABI) for container applications, but isolates the execution of the application from the host operating system, avoiding direct access of the application to the host resources, thereby providing additional protection between container hosts or between containers.

[0044] Syscall: a system call function.

[0045] With the continuous development of computer technology, many enterprises or institutions will usually adopt a mixed deployment mode of high-priority tasks and low-priority tasks in an OS system in order to save costs and improve the CPU utilization of clusters. The mixed deployment mode (mixed deployment model) ensures the running time slice of high-priority tasks (and can preempt low-priority tasks at any time) through scheduling strategies and other system configurations, and low-priority tasks try to obtain CPU (central processing unit) time slice to run during the rest time of high-priority tasks. In order to reduce the interference of low-priority tasks on the kernel or syscall level of high-priority tasks, low-priority tasks are usually run in a secure running unit. An application case of this mixed deployment mode is the mixed deployment of online and offline businesses. Online businesses run in high-priority normal running units (runc), and offline applications run in secure running units (security containers or virtual machines). The secure running unit (virtual machine or security container) usually has only one global running priority, which is low-priority or high-priority or a certain specific priority. It is impossible to deploy tasks of two priorities in the same secure running unit. However, sometimes there are tasks of different priorities in some offline businesses, and sometimes there is a strong association between tasks of different priorities in some businesses (such as big data businesses), so it is necessary to deploy more than one global priority task in a secure running unit, that is, it is necessary to deploy tasks of two priorities in the same secure running unit.

[0046] Based on this, in the present specification, a task processing method is provided, and the present specification also relates to a task processing system, a computing device, a computer readable storage medium and a computer program, which are described in detail one by one in the following embodiments.

[0047] Figure 1 A flow chart of a task processing method provided according to one embodiment of the present specification is shown, the task processing method is applied to a task processing system, the system includes a host and a secure running unit running on the host, wherein the method specifically includes the following steps.

[0048] Step 102: The host determines the priority of the host thread according to a preset priority policy.

[0049] Wherein, the host thread is the vCPU of the secure running unit. The task processing system can be understood as a system capable of supporting the running of multiple global priority tasks in the same secure running unit; in actual application, the secure running unit can be understood as a virtual machine running on the host or a secure container running on the host. The host can be understood as a physical machine, and for one or more secure running units running on the physical machine, the physical machine is the host of the secure running units. The secure running unit can be understood as one or more machines (virtual machines or secure containers) virtually created on a physical machine, which is generally implemented in the form of hardware virtualization or software binary translation. The vCPU can be understood as a virtual central processing unit of the secure running unit, that is, the vCPU in the virtual machine or the secure container, and the usual implementation of a vCPU is a thread in the host operating system. In actual application, the steps in the task processing method provided by the present specification for the secure running unit in the task processing system can also be understood as steps for the virtual machine or the secure container, that is, the task processing method provided by the present specification can be implemented through a virtual machine or a secure container. The preset priority policy can be any policy that can determine the priority of the host thread, which can be set according to the actual application scenario, and the present specification does not make specific limitations thereon, for example, the preset priority policy includes but is not limited to the shares time slice in the cgroup group, the task scheduling policy, the memory access policy of rdt, etc. The host thread can be understood as a thread in the host for implementing the vCPU, and in actual application, a vCPU in the secure running unit can be understood as a thread in the host.

[0050] Specifically, in the process of determining the priority of each host thread in the host of the task processing system according to the pre-set priority policy, the specific implementation is as follows.

[0051] The host machine determines the priority of host machine threads according to a preset priority strategy, including:

[0052] The host machine's priority management program creates at least two thread groups and determines the priority of each thread group through a preset priority strategy; and

[0053] The host thread is added to each thread group, and the priority of the host thread is determined based on the priority of each thread group.

[0054] In the case where the secure running unit in the task processing method provided in this specification can be a virtual machine or a secure container, the priority management program can be understood as a program that manages the priority of the host thread, which is the vCPU in the virtual machine or secure container; the thread group can be understood as a collection containing multiple host threads. In practical applications, each thread group can have different priorities or the same priority.

[0055] Specifically, during task processing, the priority management program in the host machine creates at least two thread groups for the host machine threads. It adjusts and sets the parameters of each thread group using a preset priority strategy to determine the priority of each thread group. Each thread group's priority includes at least two types, such as high priority and low priority. Therefore, the thread groups created by the priority management program also include at least two types, such as high-priority groups and low-priority groups. After determining the priority of each thread group, host machine threads that support vCPU implementation are added to the thread groups, and the priority of each thread group is set to the priority of the host machine threads contained within that thread group, thus assigning a corresponding priority to each host machine thread.

[0056] For example, taking the task processing method provided in this manual as an example of running multiple globally prioritized tasks within a secure operating unit, we will further explain how the priority management program based on the host machine determines the priority of the host machine thread. Here, the host machine thread can be a vCPU Host thread that supports vCPU implementation within the host machine. In practical applications, a vCPU within a virtual machine or secure container is equivalent to a vCPU Host thread within the host machine.

[0057] When the priority management program in the host machine needs to determine the priority of multiple host machine threads (such as 4 host machine threads), it can first create 2 thread groups for the 4 host machine threads. The thread group can be cgroup group, rdt group group, or cgroup group and rdt group group.

[0058] After the creation of the thread group is completed, in the case that the thread group exists a cgroup group, the cgroup group that needs to be configured as high priority is configured with a high-priority shares time slice, a high-priority preemption policy (a low-priority policy that can be preempted by a high-priority policy is configured); the cgroup group that needs to be configured as low priority is configured with a low-priority shares time slice, a low-priority preemption policy (a low-priority policy that can be preempted by a high-priority policy is configured); thereby, in the host kernel, high and low priority cgroup groups are established.

[0059] Meanwhile, in the case that the thread group exists an rdt group, the rdt group that needs to be configured as high priority is configured with 11-way (usually all ways) LLC 3-level cache resources (i.e., high-priority cache resources); the rdt group that needs to be configured as low priority is configured with 4-way (usually a partial number of ways) LLC 3-level cache resources (i.e., low-priority cache resources).

[0060] Subsequently, the hypervisor places the vCPU Host thread that needs to be configured as high priority into a high-priority cgroup or a high-priority rdt group, thereby determining the priority of the vCPU Host thread as high priority. The vCPU Host thread that needs to be configured as low priority is placed into a low-priority cgroup or a low-priority rdt group. Thereby, the priority of the vCPU Host thread is determined as high priority.

[0061] In the embodiments of the present specification, the priority management program of the host determines the corresponding priority of each thread group created by the preset priority policy, and determines the priority of the host thread as the priority of each thread group by adding the host thread to each thread group, thereby determining the corresponding priority of the host thread, facilitating subsequent determination of the priority of the vCPU based on the priority of the host thread, and further running different priority tasks to be processed by the vCPU with priority.

[0062] Step 104: The secure running unit determines the priority of the vCPU based on the priority of the host thread determined from the host, and determines the vCPU corresponding to the running task to be processed based on the priority of the vCPU.

[0063] Wherein, the task to be processed can be understood as a task that needs to be run in the secure running unit, and the task to be processed has different priorities; for example, high-priority tasks and low-priority tasks included in offline services.

[0064] Specifically, after the host machine of the task processing system determines the priority of the host machine thread, the secure running unit of the task processing system can determine the priority of the host machine thread from the host machine, and then determine the priority of the vCPU in the secure running unit based on the priority of the host machine thread; after determining the priority of the vCPU, the secure running unit can determine the vCPU running the task of different priorities based on the priority of the vCPU and the priority of the task to be processed.

[0065] In a specific implementation, determining the vCPU running the task to be processed based on the priority of the vCPU can be understood as that the secure running unit determines the vCPU corresponding to the task to be processed based on the priority of the vCPU. For example, the vCPU of high priority runs the task of high priority, and the vCPU of low priority runs the task of low priority; or the vCPU of high priority runs the task of high priority and the task of low priority, and the vCPU of low priority runs the task of low priority.

[0066] In actual application, the task processing method provided by the present specification can make the task of high priority run on the vCPU of high priority and the task of low priority run on the vCPU of low priority through the corresponding relationship between the priority of the vCPU and the priority of the task to be processed.

[0067] Meanwhile, in order to avoid the waste of computing resources caused by the vCPU of high priority when it does not run the task of high priority, the task of high priority runs on the vCPU of high priority, and the task of low priority runs on the vCPU of high priority and the vCPU of low priority at the same time. That is to say, the vCPU of high priority can run the task of high priority and the task of low priority at the same time.

[0068] In addition, in the process of the task of high priority and the task of low priority running on the vCPU of high priority at the same time, in order to avoid the task of low priority preempting the computing resources of the task of high priority, causing the task of high priority to be unable to run quickly, the task processing method provided by the present specification configures the shares time slice quota for the task of high priority and the task of low priority, or configures the scheduling preemption strategy, or configures the hardware qos parameter, or any combination of the above methods, etc. so that the task of low priority can be preempted at any time when the task of high priority needs to run on the vCPU of high priority, so that the task of high priority can run quickly and without influence.

[0069] Further, the step of determining the priority of the host thread from the host can be implemented by a service management program in the secure running unit, in the following specific manner.

[0070] The priority of the vCPU is determined based on the priority of the host thread determined from the host.

[0071] The service management program of the secure running unit determines the priority of the vCPU based on the priority of the host thread determined from the host.

[0072] The service management program can be understood as a program running in the secure running unit for managing the processing procedure of the to-be-processed task; in the case where the secure running unit is a virtual machine or a secure container, the service management program can be understood as a program running in the virtual machine or the secure container for managing the processing procedure of the to-be-processed task.

[0073] In a specific implementation, the service management program running in the secure running unit can determine the priority of the host thread from the host, and the manner of determining the priority of the host includes but is not limited to: a priority management program running in the host sends the priority of the host thread to the service management program through an interface when the priority management program is initialized or needs to be updated; or the service management program acquires the priority of the host thread from the priority management program by calling an interface provided by a priority control program of the host; or the priority control program of the host stores the priority of the host thread in a storage unit when the priority control program is initialized or needs to be updated, and the service management program can acquire the priority of the host thread from the storage unit based on a specific time interval (such as 10 seconds), wherein the storage unit can be understood as a file or a cache.

[0074] In the embodiments of the present specification, the service management program of the secure running unit quickly determines the priority of the host thread from the host, and determines the priority of the vCPU based on the priority of the host thread, thereby improving the processing efficiency of the secure running unit and facilitating subsequent determination of the vCPU running the to-be-processed task based on the priority of the vCPU.

[0075] Before the secure running unit determines the vCPU running the to-be-processed task based on the priority of the vCPU, the received to-be-processed task needs to be configured or processed by a task priority strategy, so that the to-be-processed task runs at a corresponding priority, and the specific implementation manner is as follows.

[0076] The priority of the vCPU is determined based on the priority of the vCPU.

[0077] The business management program of the secure running unit receives a to-be-processed task carrying a priority label; and

[0078] Based on the priority label, the priority of the to-be-processed task is determined through a task priority strategy.

[0079] The priority label can be understood as a label representing the priority of the to-be-processed task; for example, a high-priority label, a low-priority label, etc.

[0080] The task priority strategy can be understood as a strategy for determining the priority of each to-be-processed task. The task priority strategy can be set according to the actual application scenario, and the present specification does not make specific limitations thereon. For example, system scheduling parameters (software parameters) are configured, hardware qos parameters are configured, etc. In actual applications, configuring system scheduling parameters can include allocating shares time slice quotas to each to-be-processed task, configuring scheduling preemption strategies, etc.; configuring hardware qos parameters can include configuring the number of routes for the to-be-processed task through rdt, etc.

[0081] In actual applications, after the business management program in the secure running unit receives a to-be-processed task carrying a priority label, the priority of each to-be-processed task is configured based on the to-be-processed label through a pre-set task priority strategy.

[0082] In the above example, in the case where the task priority strategy involves configuring system scheduling parameters, after the business management program of the secure running unit receives a to-be-processed task carrying a priority label, if the priority label is a high-priority label, the business management program configures a high-priority shares time slice quota for the to-be-processed task, and configures a scheduling preemption strategy for the to-be-processed task. The scheduling preemption strategy can be an attribute configured through cgroup, or configured through a syscall. After the high-priority to-be-processed task is configured with the attribute, it can preempt the low-priority to-be-processed task unconditionally when it is scheduled.

[0083] If the priority label is a low-priority label, the business management program configures a low-priority shares time slice quota for the to-be-processed task, and does not configure a scheduling preemption strategy for the to-be-processed task.

[0084] After each to-be-processed task is configured with a shares time slice and a scheduling preemption strategy, it obtains the corresponding priority, i.e., the corresponding priority capability.

[0085] In the case that the task priority strategy exists the configured hardware QoS parameter, the service management program configures the priority of RDT memory access for the to-be-processed task, such as the access of LLC, and different paths can be configured for the to-be-processed task by RDT, 11 paths can be configured for the to-be-processed task with high priority, and 4 paths can be configured for the to-be-processed task with low priority. Based on this, after the service management program of the secure running unit receives the to-be-processed task carrying the priority label, if the priority label is a high priority label, the to-be-processed task is configured with a higher priority path by RDT, such as 11 paths; if the priority label is a low priority label, the to-be-processed task is configured with a lower priority path by RDT, such as 4 paths; after the configuration of the paths of each to-be-processed task is completed, the corresponding priority is obtained, that is, the corresponding priority capability.

[0086] In actual application, the service management program can configure the hardware QoS parameter or any one of the system scheduling parameters for the to-be-processed task, or can simultaneously configure the hardware QoS parameter and the system scheduling parameter for the to-be-processed task. The present specification does not make specific limitation on this.

[0087] Further, after the service management program of the secure running unit determines the priority of the vCPU, the vCPU running the to-be-processed task can be determined based on the priority of the vCPU. The specific implementation manner is as follows.

[0088] The vCPU running the to-be-processed task is determined based on the priority of the vCPU, and the specific implementation manner is as follows.

[0089] The service management program of the secure running unit matches the priority of the vCPU with the priority of the to-be-processed task; and

[0090] The vCPU matched with the to-be-processed task is determined as the vCPU running the to-be-processed task.

[0091] In the above example, after the service management program of the secure running unit determines the priority of the vCPU and the priority of the to-be-processed task, the priorities of the two are matched, the vCPU with high priority is determined as the vCPU matched with the to-be-processed task with high priority, and the vCPU with low priority is determined as the vCPU matched with the to-be-processed task with low priority.

[0092] Alternatively, in order to avoid the waste of computing resources caused by the vCPU with high priority when the to-be-processed task with high priority is not running, the service management program of the secure running unit makes the to-be-processed task with high priority run on the vCPU with high priority, and makes the to-be-processed task with low priority run on the vCPU with high priority and the vCPU with low priority at the same time.

[0093] Meanwhile, the service management program of the secure running unit configures shares time slice quota, or configures scheduling preemption strategy, or configures hardware QoS parameter, or any combination of the above methods, etc. for the high-priority and low-priority pending tasks, so that the low-priority task can be preempted at any time when the high-priority pending task needs to run on the high-priority vCPU, so that the high-priority task can run quickly and without influence.

[0094] After the service management program of the secure running unit completes the matching of the pending task and the vCPU, the vCPU matched with the pending task is determined as the vCPU running the pending task, and the pending task is processed based on the vCPU.

[0095] In the embodiments of the present specification, the service management program of the secure running unit matches the priority of the vCPU with the priority of the pending task, and the vCPU matched with the pending task is determined as the vCPU running the pending task, so that different priority vCPUs are used to process different priority pending tasks, so that the secure running unit processes the pending tasks according to the priority of the pending tasks, avoiding confusion in the task processing process, and realizing the deployment of two priority tasks in one secure running unit.

[0096] In actual application, the task processing system including a host and a secure running unit running on the host is used to realize the process of running multiple global priority tasks in the same secure running unit, which can be seen from Figure 2 , Figure 2 is a flowchart of task management in a task processing method provided by an embodiment of the present specification; as shown in Figure 2 , the Host thread1…Host thread4 can be the vCPU Host thread of the above embodiments; the high-priority group and the low-priority group can be the thread groups of different priorities in the above embodiments; the secure container and the virtual machine management program can be the priority management program of the above embodiments. The secure running unit can be a secure container or a virtual machine; the vCPU…vCPU3 can be the virtual central processor of the secure running unit in the above embodiments. Task A…Task D can be the pending task of the above embodiments.

[0097] Among them, as shown in Figure 2The Host part is shown in the figure; the step of determining the priority of the Host thread by the Host can refer to steps ① and ②, that is, the secure container and the hypervisor create a high-priority group and a low-priority group based on the received priority determination instruction, and add Host thread 1 and Host thread 2 to the high-priority group, thereby determining the priority of Host thread 1 and Host thread 2 as high priority; add Host thread 3 and Host thread 4 to the low-priority group, thereby determining the priority of Host thread 3 and Host thread 4 as low priority.

[0098] In the Guest part, the hypervisor determines the priority of the vCPU in the following manner, which can refer to step ③. The hypervisor obtains the priority information of the vCPU Host thread having an object relationship with the vCPU according to the interface provided by the hypervisor of the secure container and the virtual machine on the Host (there are many interfaces, which are not listed one by one), thereby determining the priority of the vCPU based on the priority information of the thread. Figure 2

[0099] Meanwhile, the hypervisor of the secure unit determines the vCPU corresponding to the to-be-processed task in the following manner, which can refer to step ④. After determining the priority of the to-be-processed task Task and the priority of the vCPU, the hypervisor of the secure unit matches the two according to the priority, and determines the vCPU matched with the to-be-processed task Task as the vCPU for processing the to-be-processed task Task, thereby realizing the deployment of tasks of two priorities in one secure unit, and processing the to-be-processed tasks of different priorities by vCPUs of different priorities, so that the secure unit processes the to-be-processed tasks according to the priority of the to-be-processed tasks, avoiding confusion in the task processing process.

[0100] ​In actual applications, the task processing method provided in the specification can select a business management program in a secure running unit (a secure container or a virtual machine) to actively manage the priority of the task, thereby realizing a more flexible matching mode of the task and the vCPU. For example, the vCPUs numbered 0-9 in the vCPU of the secure running unit are high-priority vCPUs, and the vCPUs numbered 10-19 are low-priority vCPUs. However, there may be interference between task A and task B in the low-priority task. Therefore, in order to avoid the interference between task A and task B during the running of the low-priority task, the secure running unit can subdivide the vCPUs numbered 10-19 into two parts, i.e., the vCPUs numbered 10-14 are one part, and the vCPUs numbered 15-19 are another part. By placing the low-priority task A in the vCPUs numbered 10-14 and placing the low-priority task B in the vCPUs numbered 15-19, the interference between the two tasks can be avoided.

[0101] At the same time, in order to avoid the waste of computing resources caused by the high-priority vCPUs numbered 0-9 when they are not running high-priority tasks, the business management program in the secure running unit (the secure container or the virtual machine) places the high-priority task C on the vCPUs numbered 0-9 and enables the low-priority tasks (task A and task B) to run not only on the low-priority vCPUs numbered 10-19 but also on the high-priority vCPUs numbered 0-9.

[0102] In addition, in order to avoid the low-priority tasks from preempting the computing resources of the high-priority task C, the shares time slice quota, the scheduling preemption strategy, the hardware qos parameter, or any combination of the above methods is configured for the high-priority and low-priority tasks to be processed, so that the high-priority task C can preempt the low-priority tasks at any time when the high-priority task C needs to run on the high-priority vCPU, and the high-priority task can run quickly and without affecting the running.

[0103] It should be noted that in the embodiments of the specification, only the case where there is interference between tasks is taken as an example to illustrate the flexible matching of the business management program between the task and the vCPU. The business management program can flexibly match the task and the vCPU according to different actual application scenarios.

[0104] Further, the present specification provides a task processing method. When the business management program does not have much personalized configuration processing, for example, when the interference risk between tasks is low, the Guest kernel itself can be selected to regularly schedule the to-be-processed task to the vCPU for processing, thereby reducing the complexity of the business management program (for example, omitting obtaining the vCPU priority, and omitting matching the task and the vCPU). Based on this, the implementation manner of the Guest kernel for processing the to-be-processed task is as follows.

[0105] The security running unit further includes:

[0106] The kernel of the security running unit determines the priority of the vCPU based on the priority of the host thread determined from the host.

[0107] The kernel of the security running unit can be understood as a Guest kernel in the security running unit. In the case of a virtual machine or a security container, the kernel of the security running unit can be understood as a Guest kernel running in the virtual machine or the security container.

[0108] Specifically, the kernel running in the security running unit can determine the priority of the host thread from the host. The manner of determining the priority of the host includes but is not limited to: sending the priority of the host thread to the kernel of the security running unit through an interface when the priority management program running in the host is initialized or needs to be updated; or the kernel of the security running unit obtains the priority of the host thread from the priority management program by calling an interface provided by the priority control program of the host; or the priority control program of the host stores the priority of the host thread in a storage unit when it is initialized or needs to be updated, and the kernel of the security running unit can obtain the priority of the host thread from the storage unit based on a specific time interval (for example, 10 seconds), wherein the storage unit can be understood as a file, a cache, or a memory.

[0109] In the embodiments of the present specification, the kernel of the security running unit quickly determines the priority of the host thread determined from the host, and determines the priority of the vCPU based on the priority of the host thread, thereby improving the processing efficiency of the security running unit and facilitating subsequent determination of the vCPU running the to-be-processed task based on the priority of the vCPU.

[0110] Further, the kernel of the security running unit determines the vCPU for processing the received to-be-processed task based on the priority of the vCPU after determining the priority of the vCPU. The specific implementation manner is as follows.

[0111] determining the vCPU corresponding to the to-be-processed task based on the priority of the vCPU, comprising:

[0112] The kernel of the secure running unit receives the to-be-processed task carrying the priority, and matches the priority of the vCPU with the priority of the to-be-processed task.

[0113] The vCPU matched with the to-be-processed task is determined as the vCPU for processing the to-be-processed task.

[0114] The to-be-processed task is sent by a business management program running in the secure running unit.

[0115] In actual application, before the business management program of the secure running unit sends the to-be-processed task to the kernel of the secure running unit, the to-be-processed task needs to be created and managed, that is, the to-be-processed task is also created and managed by the business management program running in the secure running unit.

[0116] In the above example, after the kernel of the secure running unit determines the priority of the vCPU, it can also receive the to-be-processed task sent by the business management program running in the secure running unit and the priority of the to-be-processed task; the priorities of the two are matched, the vCPU with high priority is determined as the vCPU matched with the to-be-processed task with high priority, and the vCPU with low priority is determined as the vCPU matched with the to-be-processed task with low priority.

[0117] Alternatively, the kernel of the secure running unit avoids the waste of computing resources caused by the high-priority vCPU when it does not run the high-priority to-be-processed task, so that the high-priority to-be-processed task runs on the high-priority vCPU, and the low-priority to-be-processed task runs on the high-priority vCPU and the low-priority vCPU at the same time.

[0118] Meanwhile, the kernel of the secure running unit configures a preemption strategy for the high-priority to-be-processed task when the high-priority and low-priority to-be-processed tasks run on the high-priority vCPU at the same time, so that the low-priority task can be preempted at any time when the high-priority to-be-processed task needs to run on the high-priority vCPU, so that the high-priority task can run quickly and without influence.

[0119] After the kernel of the secure running unit completes the matching of the to-be-processed task and the vCPU, the vCPU matched with the to-be-processed task is determined as the vCPU for running the to-be-processed task, and the to-be-processed task is processed based on the vCPU.

[0120] In the embodiments of the present specification, the kernel of the secure running unit matches the priority of the vCPU with the priority of the to-be-processed task, and determines the vCPU matched with the to-be-processed task as the vCPU running the to-be-processed task, so as to realize the processing of the to-be-processed tasks with different priorities by the vCPUs with different priorities, and make the secure running unit process the to-be-processed tasks according to the priority of the to-be-processed tasks, so as to avoid the confusion in the task processing process and realize the deployment of the tasks with two kinds of priorities in the same secure running unit.

[0121] In actual application, the process of running multiple global priority tasks in the same secure running unit is realized by the task processing system including the host and the secure running unit running on the host, and the process can also be referred to Figure 3 , Figure 3 is another flow diagram of task processing in a task processing method provided by an embodiment of the present specification; as shown in Figure 3 , the Guest kernel can be the kernel of the secure running unit in the above embodiments.

[0122] As shown in the Host part in Figure 3 , the step of determining the priority of the host thread by the host can be referred to steps ① and ②, that is, the secure container and the virtual machine management program create the high priority group and the low priority group based on the received priority determination instruction, and add the Host thread 1 and the Host thread 2 into the high priority group, so as to determine the priority of the Host thread 1 and the Host thread 2 as high priority, and add the Host thread 3 and the Host thread 4 into the low priority group, so as to determine the priority of the Host thread 3 and the Host thread 4 as low priority.

[0123] As shown in the Guest part in Figure 3 , the way of determining the priority of the vCPU by the Guest kernel of the secure running unit can be referred to step ③. The secure container and the virtual machine management program send the priority information of the vCPU Host thread to the Guest kernel at a specific frequency. The Guest kernel determines the priority of the vCPU based on the received priority information of the vCPU Host thread.

[0124] Meanwhile, the Guest kernel determines the vCPU corresponding to the task to be processed in the following way, see step ④. After determining the priority of the task to be processed and the priority of the vCPU, the Guest kernel matches the two according to the priority and determines the vCPU that matches the task to be processed as the vCPU to process the task to be processed. This realizes the deployment of tasks with two priorities in one secure running unit, and the processing of tasks with different priorities by vCPUs with different priorities. This makes the secure running unit process tasks according to their priority, avoiding confusion during task processing.

[0125] Furthermore, the host machine's priority management program determines the priority of the host machine threads by adding them to a pre-determined priority thread group. After that, the host machine's priority management program can also adjust the priority of the host machine threads, as shown in the following specific implementation method.

[0126] After the host machine determines the priority of the host machine threads according to a preset priority strategy, it also includes:

[0127] The host machine's priority management program receives a priority adjustment instruction sent by the priority control object, and adjusts the priority of the host machine threads according to the priority adjustment information carried in the priority adjustment instruction.

[0128] In this context, the priority control object can be understood as an object that instructs the priority management program to adjust the priority of host threads, such as the priority control program or device within the host machine. Correspondingly, the priority adjustment instruction can be understood as an instruction that instructs the priority management program to adjust the priority of host threads. Priority adjustment information can be understood as information that helps the priority management program quickly adjust the priority of host threads. This information includes, but is not limited to, the thread group identifier, the host thread identifier, the priority to which the thread group needs to be adjusted, and the priority information to which the host thread needs to be adjusted.

[0129] Specifically, the host machine's priority management program can receive priority adjustment instructions sent by the priority control object. After receiving the priority adjustment instructions, the priority management program can determine the host machine thread whose priority needs to be adjusted based on the priority adjustment information carried in the priority adjustment instructions, such as the host machine thread's identifier; and adjust the priority of the host machine thread according to the priority adjustment information, such as the priority information that the host machine thread needs to be adjusted to.

[0130] In the above example, the priority adjustment instruction can be a priority adjustment event. Specifically, the hypervisor of the host machine can receive a priority adjustment event sent by the priority control device, and the priority adjustment event carries priority adjustment information, which includes the identifier of the vCPU Host thread, the priority to which the vCPU Host thread needs to be adjusted, the identifier of the thread group, and the like.

[0131] Based on the identifier of the thread group included in the priority adjustment information, the hypervisor of the host machine determines the corresponding thread group, determines the thread corresponding to the identifier of the vCPU Host thread from the thread group, and determines the thread as the thread to be adjusted. Then, the hypervisor of the host machine determines the thread group corresponding to the priority to which the vCPU Host thread needs to be adjusted, and adds the thread to be adjusted to the thread group, thereby completing the adjustment of the priority of the vCPU Host thread.

[0132] In actual application, the kernel of the secure running unit can provide an interface (for example, a newly added file of a cgroup) to the business management program (this component is necessarily present in the task processing system provided in the specification), and the business management program can select to perform matching processing of the to-be-processed task and the vCPU by itself when creating a task, so as to implement running of tasks of two priorities in the same secure running unit; or the business management program can select to perform matching processing of the to-be-processed task and the vCPU by the kernel of the secure running unit automatically. If the business management program selects automatic matching processing by the Guest, the business management program tells the kernel of the secure running unit the priority of the to-be-processed task by means of a cgroup or a syscall, and the kernel of the secure running unit itself determines the vCPU on which the task is placed for processing according to the priority of the task.

[0133] Referring to Figure 4 , Figure 4 is a flowchart of priority adjustment in a task processing method provided in an embodiment of the specification, wherein, as shown in the Host (host machine) part in Figure 2 , the steps of adjusting the priority of the host machine thread by the host machine can be referred to steps ① and ②, that is, the secure container and the hypervisor can receive a priority adjustment event sent by the priority control device; the priority adjustment information carried in the priority adjustment event is the priority adjustment information in Figure 4 , vCPU1: high priority→low priority; wherein "vCPU1" can be the identifier of the vCPU corresponding to the vCPU Host thread; "high priority→low priority" can be the priority to which the vCPU Host thread needs to be adjusted, that is, from high priority to low priority.

[0134] The secure container and the virtual machine manager determine the thread corresponding to the vCPU1 carried in the priority adjustment event, i.e., the Host thread2, based on the priority, and move the thread Host thread2 to the low priority group based on "high priority to low priority", so as to adjust the high priority of the Host thread2 thread to the low priority.

[0135] Based on this, the process of adjusting the priority of the host thread by the host can be specifically: the secure container and the virtual machine manager receive a priority adjustment request (i.e., a priority adjustment event), the secure container and the virtual machine manager adjust the Host thread priority, the secure container and the virtual machine manager update the vCPU priority information and provide a query interface, the guest kernel or the service manager obtains the vCPU priority information and makes the task binding relationship effective.

[0136] In the step ③ and ④ in the above Figure 4 The steps ③ and ④ in the above Figure 3 The description of determining the vCPU priority by the guest kernel of the secure running unit in the above is not repeated here.

[0137] In the embodiments of the present specification, after the priority management program of the host receives the priority adjustment instruction sent by the priority control object, the priority of the host thread is flexibly adjusted according to the priority adjustment information carried in the priority adjustment instruction, so as to flexibly adjust the priority of the host thread based on the actual running situation of the host.

[0138] In the embodiments provided in the present specification, the priority of the vCPU is determined based on the priority of the host thread determined from the host, including:

[0139] The secure running unit obtains the priority of the host thread from the priority management program by calling the object interface of the priority management program; and

[0140] The priority of the vCPU is determined based on the priority of the host thread;

[0141] The priority management program runs on the host.

[0142] Specifically, the priority management program running on the host provides an object interface, and the secure running unit can obtain the priority of the host thread from the priority management program by calling the object interface of the priority management program, so as to determine the priority of the vCPU based on the priority of the host thread.

[0143] In actual application, the secure running unit can obtain the priority of the host thread from the priority management program by calling the object interface of the priority management program, and the priority of the host thread can be obtained by a service management program running in the secure running unit.

[0144] The service management program can obtain the priority of the host thread from the host in the following manner: the service management program can obtain the priority of the host thread according to a specific frequency by calling the interface provided by the priority management program. For example, after the priority management program running on the host determines the priority of the vCPU Host thread, the priority management program can provide an interface for the service management program running on the secure running unit, and the service management program running on the secure running unit can obtain the priority of each vCPU Host thread in the host according to a specific frequency by calling the interface; for example, the priority of the vCPU Host thread can be obtained once per minute. This facilitates subsequent determination of the priority of the vCPU corresponding to the vCPU Host thread based on the priority of the vCPU Host thread.

[0145] In actual application, the secure running unit can obtain the priority of the host thread from the priority management program by calling the object interface of the priority management program, and the priority of the host thread can be obtained by a service management program running in the secure running unit.

[0146] The kernel of the secure running unit can obtain the priority of the host thread from the host in the following manner: the kernel of the secure running unit can obtain the priority of the host thread according to a specific frequency by calling the interface provided by the priority management program. For example, after the priority management program running on the host determines the priority of the vCPU Host thread, the priority management program can provide an interface for the kernel of the secure running unit, and the kernel of the secure running unit can obtain the priority of each vCPU Host thread in the host according to a specific frequency by calling the interface; for example, the priority of the vCPU Host thread can be obtained once per minute. This facilitates subsequent determination of the priority of the vCPU corresponding to the vCPU Host thread based on the priority of the vCPU Host thread.

[0147] In the embodiments of the present specification, the secure running unit can quickly obtain the priority of the host thread from the priority management program by calling the object interface of the priority management program, so as to determine the priority of the vCPU based on the priority of the host thread, and facilitate subsequent determination of the vCPU processing the to-be-processed task based on the priority of the vCPU.

[0148] Further, in the task processing method provided by the present specification, the host virtual machine control object can adjust the priority of the host thread in the following manner: the priority of the host thread can be adjusted by adjusting the priority of a thread group to which the host thread belongs. The specific manner is as follows.

[0149] The adjusting the priority of the host thread according to the priority adjustment information carried in the priority adjustment instruction comprises:

[0150] The priority management program of the host adjusts the priority of each thread group according to the priority adjustment information carried in the priority adjustment instruction; and

[0151] The adjusted priority of each thread group is determined as the adjusted priority of the host thread.

[0152] In the above example, after the priority management program of the host receives the priority adjustment event sent by the priority control device, the corresponding thread group is determined based on the identification of the thread group carried in the priority adjustment event, the thread group being the thread group to which the vCPU Host thread needing priority adjustment belongs; the priority of the thread group is adjusted based on the priority of the vCPU Host thread needing adjustment carried in the priority adjustment event; and the adjusted priority of the thread group is determined as the priority of the vCPU Host thread included in the thread group, thereby achieving the adjustment of the priority of the vCPU Host thread.

[0153] In the embodiments of the present specification, the priority management program of the host adjusts the priority of each thread group according to the priority adjustment information carried in the priority adjustment instruction; and the adjusted priority of each thread group is determined as the adjusted priority of the host thread, thereby achieving flexible adjustment of the priority of the host thread.

[0154] The task processing method provided in the present specification is applied to a task processing system, and the priority of the host thread corresponding to the vCPU of the safe running unit is determined in advance based on the host of the task processing system. According to the priority of the host thread and the priority of the to-be-processed task, the vCPU for processing the to-be-processed task is determined based on the safe running unit capable of managing multiple global priorities in the task processing system, so that different priority vCPUs process different priority to-be-processed tasks, the to-be-processed tasks are processed according to the priority of the to-be-processed tasks, the confusion in the task processing process is avoided, and the two priority tasks are deployed in the same safe running unit.

[0155] The following will be described in detail with reference to the accompanying drawings. Figure 5 The task processing method provided in the present specification is applied to a task processing system, and the priority of the host thread corresponding to the vCPU of the safe running unit is determined in advance based on the host of the task processing system. According to the priority of the host thread and the priority of the to-be-processed task, the vCPU for processing the to-be-processed task is determined based on the safe running unit capable of managing multiple global priorities in the task processing system, so that different priority vCPUs process different priority to-be-processed tasks, the to-be-processed tasks are processed according to the priority of the to-be-processed tasks, the confusion in the task processing process is avoided, and the two priority tasks are deployed in the same safe running unit. Figure 5A first process flow chart of a task processing method provided by an embodiment of the present specification is shown, the task processing method is applied to a task processing system, the task processing system comprises a host and a secure running unit running on the host, and specifically comprises the following steps.

[0156] Step 502: The secure container and the virtual machine management program of the host determine the priority of the host thread.

[0157] Specifically, the secure container and the virtual machine management program on the Host can create a high-priority thread group and a low-priority thread group, i.e. a high-priority group and a low-priority group, for the host thread according to the shares in the cgroup group, the task scheduling strategy, the memory access strategy of the rdt, etc. And add the host thread of the host to the high-priority group and the low-priority group, so as to determine the priority of the host thread corresponding to the vCPU of the secure running unit.

[0158] Among them, during the running of the host, the vCPU in the secure running unit is a vCPU Host thread in the host, and the secure running unit can be understood as a virtual machine or a secure container.

[0159] Therefore, when the priority of the host thread corresponding to the vCPU of the secure running unit is determined, different vCPUs correspond to different priority capabilities.

[0160] Step 504: The service management program of the secure running unit determines the priority of the vCPU based on the priority of the host thread.

[0161] Specifically, the service management program obtains the priority information of the host thread corresponding to the vCPU from the secure container and the virtual machine management program on the Host according to the interface provided by the secure container and the virtual machine management program (there are many kinds of interfaces, not listed one by one), so as to determine the priority of the vCPU, that is, the corresponding relationship between the vCPU and the priority capability.

[0162] Step 506: The service management program of the secure running unit determines the vCPU for processing the task based on the priority of the vCPU and the priority of the task.

[0163] Specifically, the business management program of the secure operation unit binds the task to a vCPU with the corresponding global priority based on the pre-configured global priority of the task. The task is then processed based on that vCPU. Since a vCPU is typically implemented as a thread or coroutine on the host, it is scheduled by the host scheduler and runs on a pCPU (host central processing unit). Therefore, when a task with a different priority is processed by a vCPU with the same priority, the task with the different priority acquires the global priority attribute of its host machine.

[0164] Step 508: The host machine's security container and hypervisor adjust the priority of vCPUs.

[0165] Specifically, for high-priority or low-priority vCPUs, the priority control device on the host can notify the host's security container and hypervisor of the priority adjustment event, which adjusts the priority of the vCPU. The security container and hypervisor then perform dynamic priority switching of the vCPU host thread based on the priority adjustment event.

[0166] The business management program periodically obtains the latest vCPU priority information through the interfaces provided by the security container and virtual machine hypervisor. Based on the latest vCPU priority information, it adjusts the vCPU where the running task is located and guides the processing and creation of subsequent tasks with different priorities.

[0167] The task processing method provided in this manual assigns different priorities to the host machine threads corresponding to different vCPUs within a secure runtime unit. Simultaneously, it informs the Guest's business management program of the vCPU-priority mapping through a standard interface, and the business management program then binds tasks of different priorities within the Guest to vCPUs of different priorities. This achieves the goal of running multiple priority tasks within the same secure runtime unit. Furthermore, it enables precise static and dynamic management of multiple priorities for Guest tasks.

[0168] The following is in conjunction with the appendix Figure 6 Taking the application scenario of running multiple globally prioritized tasks within the same secure operating unit using the task processing method provided in this specification as an example, the task processing method will be explained again. Among other things, Figure 6 The present specification illustrates a second processing flowchart of a task processing method according to an embodiment of the present specification. The task processing method is applied to a task processing system, which includes a host machine and a secure operating unit running on the host machine, and specifically includes the following steps.

[0169] Step 602: The security container and the virtual machine manager of the host machine determine the priority of the host machine thread.

[0170] Specifically, the security container and the virtual machine manager of the Host can create a high-priority thread group and a low-priority thread group for the host machine thread according to the shares in the cgroup group, the task scheduling strategy, the memory access strategy of the rdt, and other methods, that is, the high-priority group and the low-priority group. And add the host machine thread of the host machine to the high-priority group and the low-priority group, so as to determine the priority of the vCPU corresponding to the host machine thread of the security running unit.

[0171] Among them, during the running of the host machine, the vCPU in the security running unit is a vCPU Host thread in the host machine, and the security running unit can be understood as a virtual machine or a security container.

[0172] Therefore, when the priority of the vCPU corresponding to the security running unit is determined, different vCPUs correspond to different priority capabilities.

[0173] Step 604: The Guest kernel of the security running unit determines the priority of the vCPU based on the priority of the host machine thread.

[0174] Specifically, the security container and the virtual machine manager of the Host will send the priority information of the host machine thread corresponding to the vCPU to the Guest kernel of the security running unit when initializing or changing the priority. After receiving the priority information of the host machine thread corresponding to the vCPU, the Guest kernel of the security running unit can determine the priority of the vCPU based on the priority information, that is, the corresponding relationship between the vCPU and the priority capability.

[0175] Step 606: The Guest kernel of the security running unit determines the vCPU for processing the task based on the priority of the vCPU and the priority of the task.

[0176] Specifically, the Guest kernel of the security running unit schedules the task to the vCPU corresponding to the global priority of the task according to the global priority of the task pre-configured by the task. And process the task based on the vCPU; since the vCPU is usually implemented as a thread or coroutine on the Host, the vCPU will be scheduled and run on a pCPU (host central processing unit) by the Host scheduler when running, so that the task with different priorities has the global priority attribute of the host machine when the task with different priorities is processed by the vCPU with the same priority.

[0177] Step 608: The security container and the virtual machine manager of the host machine adjust the priority of the vCPU.

[0178] Specifically, for the vCPU with high or low priority, the priority adjustment event of adjusting the priority of the vCPU can be notified to the security container and the virtual machine manager of the host through the priority control device on the host, and the security container and the virtual machine manager can perform dynamic priority conversion of the vCPU Host thread based on the priority adjustment event.

[0179] After adjusting the priority of the vCPU Host thread, the security container and the virtual machine manager can send the adjusted priority information to the Guest kernel of the security running unit, and the security running unit can adjust the vCPU where the running task is located and guide the processing and creation of subsequent tasks with different priorities based on the received latest priority information of the vCPU.

[0180] The task processing method provided in the specification assigns different priorities to the threads of the host corresponding to different vCPUs of one security running unit. Meanwhile, the correspondence between the vCPU and the priority is notified to the Guest kernel through a standard interface, and the Guest kernel binds the tasks with different priorities in the Guest to the vCPUs with different priorities. Thus, the same security running unit can run tasks with multiple priorities, and the static and dynamic precise management of the multiple priorities of the Guest tasks is further realized.

[0181] Corresponding to the method embodiments described above, the specification also provides task processing system embodiments, Figure 7 A structure diagram of a task processing system according to an embodiment of the specification is shown. As shown in the figure, Figure 7 The system includes a host 702 and a security running unit 704 running on the host, wherein

[0182] The host 702 is configured to determine the priority of the host thread according to a preset priority policy, wherein the host thread is a vCPU of the security running unit.

[0183] The security running unit 704 is configured to determine the priority of the vCPU based on the priority of the host thread determined by the host.

[0184] Based on the priority of the vCPU, the vCPU corresponding to the to-be-processed task is determined to be run.

[0185] Optionally, the host 702 is further configured to:

[0186] The priority management program of the host machine creates at least two thread groups, and determines the priority of each thread group through a preset priority strategy; and

[0187] The host machine thread is added to each thread group, and the priority of the host machine thread is determined based on the priority of each thread group.

[0188] Optionally, the secure running unit 704 is further configured to:

[0189] The service management program of the secure running unit determines the priority of the vCPU based on the priority of the host machine thread determined from the host machine.

[0190] Optionally, the secure running unit 704 is further configured to:

[0191] The service management program of the secure running unit receives a to-be-processed task carrying a priority label; and

[0192] The priority of the to-be-processed task is determined through a task priority strategy based on the priority label.

[0193] Optionally, the secure running unit 704 is further configured to:

[0194] The service management program of the secure running unit matches the priority of the vCPU with the priority of the to-be-processed task; and

[0195] The vCPU matched with the to-be-processed task is determined as the vCPU running the to-be-processed task.

[0196] Optionally, the secure running unit 704 is further configured to:

[0197] The kernel of the secure running unit determines the priority of the vCPU based on the priority of the host machine thread determined from the host machine.

[0198] Optionally, the secure running unit 704 is further configured to:

[0199] The kernel of the secure running unit receives a to-be-processed task carrying a priority, and matches the priority of the vCPU with the priority of the to-be-processed task; and

[0200] The vCPU matched with the to-be-processed task is determined as the vCPU processing the to-be-processed task.

[0201] The to-be-processed task is sent by the service management program of the secure running unit.

[0202] Optionally, the host computer 702 is further configured to:

[0203] The priority management program of the host computer receives the priority adjustment instruction sent by the priority control object, and adjusts the priority of the host computer thread according to the priority adjustment information carried in the priority adjustment instruction.

[0204] Optionally, the host computer 702 is further configured to:

[0205] The priority management program of the host computer adjusts the priority of each thread group according to the priority adjustment information carried in the priority adjustment instruction; and

[0206] The adjusted priority of each thread group is determined as the adjusted priority of the host computer thread.

[0207] Optionally, the secure running unit 704 is further configured to:

[0208] The secure running unit obtains the priority of the host computer thread from the priority management program by calling the object interface of the priority management program; and

[0209] The priority of the vCPU is determined based on the priority of the host computer thread.

[0210] The priority management program runs on the host computer.

[0211] Optionally, the secure running unit is a virtual machine running on the host computer, or

[0212] A secure container running on the host computer.

[0213] The task processing system provided in the specification determines the priority of the host computer thread in advance based on the host computer of the task processing system, the host computer thread being the vCPU in the secure running unit, determines the priority of the vCPU based on the priority of the host computer thread through the secure running unit capable of managing multiple global priorities in the task processing system, and determines the vCPU running the to-be-processed tasks with different priorities based on the priority of the vCPU; thereby avoiding confusion in the task processing during task running, achieving processing of to-be-processed tasks according to the priority of the to-be-processed tasks, and further achieving the purpose of deploying tasks with two priorities in the same secure running unit.

[0214] The above is a schematic solution of the task processing system of the embodiment. It should be noted that the technical solution of the task processing system and the technical solution of the task processing method described above belong to the same concept, and the details of the technical solution of the task processing system that are not described in detail can be referred to the description of the technical solution of the task processing method.

[0215] Figure 8 A structural block diagram of a computing device 800 according to one embodiment of the present specification is shown. The components of the computing device 800 include, but are not limited to, a memory 810 and a processor 820. The processor 820 is connected to the memory 810 through a bus 830, and a database 850 is used to save data.

[0216] The computing device 800 also includes an access device 840, which enables the computing device 800 to communicate via one or more networks 860. Examples of these networks include a public switched telephone network (PSTN), a local area network (LAN), a wide area network (WAN), a personal area network (PAN), or a combination of communication networks such as the Internet. The access device 840 can include one or more of any type of network interface (e.g., network interface card (NIC)), wired or wireless, such as an IEEE 802.11 wireless local area network (WLAN) wireless interface, a Worldwide Interoperability for Microwave Access (Wi-MAX) interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth interface, a near field communication (NFC) interface, and the like.

[0217] In one embodiment of the present specification, the above-mentioned components of the computing device 800 and other components not shown in the Figure 8 may be connected to each other, for example, through a bus. It should be understood that Figure 8 The structural block diagram of the computing device shown is only for the purpose of example, and is not a limitation on the scope of the present specification. Those skilled in the art can add or replace other components as needed.

[0218] The computing device 800 can be any type of stationary or mobile computing device, including a mobile computer or mobile computing device (e.g., a tablet computer, a personal digital assistant, a laptop computer, a notebook computer, a netbook, etc.), a mobile phone (e.g., a smartphone), a wearable computing device (e.g., a smartwatch, smart glasses, etc.), or other types of mobile devices, or a stationary computing device such as a desktop computer or a PC. The computing device 800 can also be a mobile or stationary server.

[0219] The processor 820 is configured to execute computer-executable instructions, which, when executed by the processor 820, implement the steps of the task processing method described above.

[0220] The above is a schematic solution of the computing device of the embodiment. It should be noted that the technical solution of the computing device and the technical solution of the task processing method described above belong to the same concept, and the details of the technical solution of the computing device that are not described in detail can be referred to the description of the technical solution of the task processing method.

[0221] An embodiment of the present specification further provides a computer readable storage medium, which stores computer executable instructions, and the computer executable instructions are executed by a processor to implement the steps of the task processing method.

[0222] The above is a schematic solution of the computer readable storage medium of the embodiment. It should be noted that the technical solution of the storage medium and the technical solution of the task processing method described above belong to the same concept, and the details of the technical solution of the storage medium that are not described in detail can be referred to the description of the technical solution of the task processing method.

[0223] An embodiment of the present specification further provides a computer program, which causes a computer to execute the steps of the task processing method when the computer program is executed in the computer.

[0224] The above is a schematic solution of the computer program of the embodiment. It should be noted that the technical solution of the computer program and the technical solution of the task processing method described above belong to the same concept, and the details of the technical solution of the computer program that are not described in detail can be referred to the description of the technical solution of the task processing method.

[0225] The above describes specific embodiments of the present specification. Other embodiments are within the scope of the appended claims. In some cases, the acts or steps recited in the claims can be performed in a different order than the order described in the embodiments and still achieve desirable results. In addition, the processes depicted in the figures do not necessarily require the particular order shown or sequential order in order to achieve the desired results. In some implementations, multitasking and parallel processing can be advantageous.

[0226] The computer readable medium can include any entity or apparatus capable of carrying the computer program code, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, software distribution medium, etc. It should be noted that the computer readable medium can include appropriate additions or subtractions according to the requirements of legislation and patent practice in the jurisdiction, for example, in some jurisdictions, according to legislation and patent practice, the computer readable medium does not include electrical carrier signals and telecommunication signals.

[0227] It should be noted that for the foregoing method embodiments, the descriptions are each simply a combination of a series of acts for the sake of brevity, but those skilled in the art should know that the present application is not limited by the order of the acts described, because some steps can be performed in other orders or at the same time in accordance with the present application. In addition, those skilled in the art should know that the embodiments described in the specification are all preferred embodiments, and the acts and modules involved are not necessarily essential to the present application.

[0228] In the above embodiments, the description of each embodiment has its own focus, and the parts not described in detail in a certain embodiment can be referred to the relevant description of other embodiments.

[0229] The preferred embodiments of the present application disclosed above are only used to help explain the present application. The alternative embodiments do not describe all the details and limit the present application to the specific embodiments described. Obviously, according to the content of the present application, many modifications and changes can be made. The present application selects and specifically describes these embodiments in order to better explain the principles and practical applications of the present application, so that those skilled in the art can well understand and use the present application. The present application is limited only by the claims and their full scope and equivalents.

Claims

1. A task processing method applied to a task processing system, the system comprising a host machine and a secure operating unit running on the host machine, wherein, The method includes: The host machine determines the priority of the host machine thread according to a preset priority strategy, wherein the host machine thread is the thread of the host machine that implements the vCPU of the secure operation unit; The secure operation unit determines the priority of the vCPU based on the priority of the host machine threads determined from the host machine; and Based on the priority of the vCPU, the priority of the task to be processed is matched, and the vCPU that matches the task to be processed is determined as the vCPU that runs the task to be processed, wherein the task to be processed refers to the task to be processed in offline services.

2. The task processing method according to claim 1, wherein the host machine determines the priority of host machine threads according to a preset priority strategy, including: The host machine's priority management program creates at least two thread groups and determines the priority of each thread group through a preset priority strategy. as well as The host thread is added to each thread group, and the priority of the host thread is determined based on the priority of each thread group.

3. The task processing method according to claim 1, wherein determining the priority of the vCPU based on the priority of the host machine thread determined from the host machine further includes: The service management program of the secure operation unit determines the priority of the vCPU based on the priority of the host machine thread determined from the host machine.

4. The task processing method according to claim 1, before determining the vCPU that matches the priority of the task to be processed based on the priority of the vCPU and the priority of the task to be processed, the method further includes: The business management program of the security operation unit receives pending tasks carrying priority tags; as well as Based on the priority label, the priority of the task to be processed is determined by a task priority strategy.

5. The task processing method according to claim 3, wherein determining the vCPU matching the priority of the task to be processed based on the priority of the vCPU to be processed is the vCPU corresponding to running the task to be processed, includes: The business management program of the security operation unit matches the priority of the vCPU with the priority of the task to be processed. as well as The vCPU that matches the task to be processed is determined as the vCPU that runs the task to be processed.

6. The task processing method according to claim 1, wherein the secure operation unit determines the priority of the vCPU based on the priority of the host machine thread determined from the host machine, further comprising: The kernel of the secure operation unit determines the priority of the vCPU based on the priority of the host thread determined from the host machine.

7. The task processing method according to claim 6, wherein determining the vCPU matching the priority of the task to be processed based on the priority of the vCPU to be processed is the vCPU corresponding to running the task to be processed, comprises: The kernel of the secure operation unit receives tasks to be processed carrying priorities, and matches the priority of the vCPU with the priority of the tasks to be processed; and The vCPU that matches the task to be processed is determined as the vCPU that processes the task to be processed; The task to be processed is sent by the business management program running in the security operation unit.

8. The task processing method according to claim 2, further comprising, after the host machine determines the priority of the host machine thread according to a preset priority strategy: The host machine's priority management program receives a priority adjustment instruction sent by the priority control object, and adjusts the priority of the host machine threads according to the priority adjustment information carried in the priority adjustment instruction.

9. The task processing method according to claim 8, wherein adjusting the priority of the host thread according to the priority adjustment information carried in the priority adjustment instruction includes: The host machine's priority management program adjusts the priority of each thread group according to the priority adjustment information carried in the priority adjustment instruction; as well as The adjusted priority of each thread group is determined as the adjusted priority of the host thread.

10. The task processing method according to any one of claims 1 to 9, wherein determining the priority of the vCPU based on the priority of the host machine thread determined from the host machine comprises: The secure operation unit obtains the priority of the host thread from the priority management program by calling the object interface of the priority management program; as well as The priority of the vCPU is determined based on the priority of the host thread; The priority management program runs on the host machine.

11. The task processing method according to any one of claims 1 to 9, wherein the secure operation unit is a virtual machine running on the host machine, or A secure container running on the host machine.

12. A task processing system, the system comprising a host machine and a secure operating unit running on the host machine, wherein, The host machine is configured to determine the priority of the host machine threads according to a preset priority policy, wherein the host machine threads are the vCPUs of the host machine that implement the secure operation unit; The secure operation unit is configured to determine the priority of the vCPU based on the priority of the host thread determined from the host machine; and Based on the priority of the vCPU, the priority of the task to be processed is matched, and the vCPU that matches the task to be processed is determined as the vCPU that runs the task to be processed, wherein the task to be processed refers to the task to be processed in offline services.

13. A computing device, comprising: Memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions, which, when executed by the processor, implement the steps of the task processing method according to any one of claims 1 to 11.

14. A computer-readable storage medium storing computer-executable instructions that, when executed by a processor, implement the steps of the task processing method according to any one of claims 1 to 11.

Citation Information

Patent Citations

  • Virtual machine task scheduling method and device, computer equipment and storage medium

    CN112130963A

  • Resource allocation method of virtual machine, server and computer readable storage medium

    CN113032101A