Data processing method and system

By registering a virtual machine monitoring unit outside the virtual machine and a virtual machine acquisition unit inside the virtual machine, and using task tables and configuration tables for data interaction, the system conflict problem caused by internal virtual machine monitoring tools is resolved, thereby reducing jitter and improving user experience.

CN114490273BActive Publication Date: 2025-11-04ALIBABA (CHINA) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210180242.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-02-25
Publication Date
2025-11-04
Estimated Expiration
2042-02-25

AI Technical Summary

Technical Problem

In existing technologies, virtual machine monitoring tools are installed inside virtual machines, which can lead to system call conflicts, potentially causing system lag, crashes, and project delays, thus affecting user experience.

Method used

The semi-virtualized eBPF architecture is adopted, in which the virtual machine monitoring unit is registered outside the virtual machine and the virtual machine acquisition unit is registered inside the virtual machine. Data interaction is carried out through the task table set and configuration table in the virtual machine memory, avoiding the need to run complex monitoring programs inside the virtual machine.

Benefits of technology

It reduces project jitter and runtime interference in virtual machines, improves user experience, avoids system lag and crashes, and ensures normal project processing in virtual machines.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114490273B_ABST
    Figure CN114490273B_ABST
Patent Text Reader

Abstract

The embodiment of the present specification provides a data processing method and system, the data processing method is applied to a data processing system, the system comprises a host computer, a virtual machine and a virtual machine monitoring module, the virtual machine monitoring module comprises a virtual machine monitoring unit and a virtual machine acquisition unit, the virtual machine and the virtual machine monitoring unit run in the host computer, and the virtual machine acquisition unit runs in the virtual machine; the method comprises the following steps: the virtual machine acquisition unit acquires project event information of the virtual machine, and writes the project event information into a task table set; the virtual machine monitoring unit accesses the task table set in the virtual machine memory, reads the project event information from the task table set, analyzes the project event information to generate a project processing task, and processes the project processing task.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present specification relate to the technical field of computer technology, and particularly relate to a data processing method. BACKGROUND

[0002] With the development of virtual machine technology, more and more projects rely on virtual machines to implement. In order to ensure the normal operation of the project, it is usually necessary to monitor the safe operation of the virtual machine. The current monitoring tool is usually installed in the virtual machine and collects data in the virtual machine. However, this processing method may make a large number of system calls to the virtual machine, which may conflict with the virtual machine kernel, causing system lag or even downtime. Or the monitoring tool will conflict with the project when it is called, causing project delay to increase and affecting user experience. SUMMARY

[0003] Therefore, the embodiments of the present specification provide a data processing method. One or more embodiments of the present specification also relate to a data processing system, a computing device, a computer readable storage medium and a computer program to solve the technical defects in the prior art.

[0004] According to a first aspect of the embodiments of the present specification, a data processing method is provided, applied to a data processing system, the system comprising a host machine, a virtual machine and a virtual machine monitoring module, the virtual machine monitoring module comprising a virtual machine monitoring unit and a virtual machine collection unit, the virtual machine running and the virtual machine monitoring unit running in the host machine, and the virtual machine collection unit running in the virtual machine; the method comprises:

[0005] The virtual machine collection unit collects project event information of the virtual machine and writes the project event information into a task table set, wherein the task table set is registered in a virtual machine memory;

[0006] The virtual machine monitoring unit accesses the task table set in the virtual machine memory, reads the project event information from the task table set, parses the project event information to generate a project processing task, and processes the project processing task.

[0007] According to a second aspect of the embodiments of the present specification, a data processing system is provided, the system comprising a host machine, a virtual machine and a virtual machine monitoring module, the virtual machine monitoring module comprising a virtual machine monitoring unit and a virtual machine collection unit, the virtual machine running and the virtual machine monitoring unit running in the host machine, and the virtual machine collection unit running in the virtual machine; wherein,

[0008] The virtual machine collection unit is configured to collect project event information of the virtual machine and write the project event information into a task table set, wherein the task table set is registered in a virtual machine memory;

[0009] The virtual machine monitoring unit is configured to access a task table set in the virtual machine memory, read the project event information from the task table set, parse the project event information to generate a project processing task, and process the project processing task.

[0010] According to a third aspect of an embodiment of the present specification, a computing device is provided, comprising:

[0011] a memory and a processor;

[0012] The memory is configured to store computer executable instructions, and the processor is configured to execute the computer executable instructions, which, when executed by the processor, implement the steps of the above data processing method.

[0013] According to a fourth aspect of an embodiment of the present specification, a computer readable storage medium is provided, which stores computer executable instructions, which, when executed by a processor, implement the steps of the above data processing method.

[0014] According to a fifth aspect of an embodiment of the present specification, a computer program is provided, wherein when the computer program is executed in a computer, the computer executes the steps of the above data processing method.

[0015] The data processing method of one embodiment of the present specification is applied to a data processing system, which comprises a host, a virtual machine running on the host, a virtual machine monitoring unit, and a virtual machine collection unit running on the virtual machine; the method comprises: the virtual machine collection unit collects project event information of the virtual machine and writes the project event information into a task table set, wherein the task table set is registered in a virtual machine memory; the virtual machine monitoring unit accesses the task table set in the virtual machine memory, reads the project event information from the task table set, parses the project event information to generate a project processing task, and processes the project processing task. Through the data processing method provided by the present specification, the need for running a complex monitoring program inside the virtual machine is avoided, which can effectively reduce project jitter and running interference, avoid adverse effects on normal project processing of the virtual machine, and improve the user experience. BRIEF DESCRIPTION OF DRAWINGS

[0016] Figure 1 is an architecture diagram of a semi-virtualized eBPF provided by one embodiment of the present specification;

[0017] Figure 2 is a flowchart of a data processing method provided by one embodiment of the present specification;

[0018] Figure 3is a structural schematic diagram of a data processing system provided by one embodiment of the present specification;

[0019] Figure 4 is a structural schematic diagram of a data processing system provided by another embodiment of the present specification;

[0020] Figure 5 is a structural block diagram of a computing device provided by one embodiment of the present specification. DETAILED DESCRIPTION

[0021] In the following description, numerous specific details are set forth in order to provide a thorough understanding of the present specification. However, the present specification can be practiced without the specific details, other than in the examples, set forth in this description. Those skilled in the art, in light of the description, can implement the present specification without limiting to the specific details set forth in the description below.

[0022] The terminology used in one or more embodiments of the present specification is for the purpose of describing particular embodiments only and is not intended to be limiting of one or more embodiments of the present specification. As used in one or more embodiments of the present specification and the accompanying claims, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises" and / or "comprising," when used in one or more embodiments of the present specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0023] It will be understood that, although the terms first, second, etc. can be used herein to describe various information, these terms are not intended to denote a temporal or chronological order. Rather, these terms are used solely to distinguish one from another only. For example, without departing from the scope of one or more embodiments of the present specification, first can be termed second, and similarly, second can be termed first. Depending on the context, the word "if' as used herein can be interpreted to mean "when" or "in response to determining."

[0024] First, the noun terms related to one or more embodiments of the present specification are explained.

[0025] eBPF: (extended Berkeley Packet Filter), a general-purpose execution engine that can run sandboxed programs in the Linux kernel without the need to change the kernel source code or load kernel modules, and plays an important role in the fields of system tracing, observation, performance tuning, security, and network. The standard eBPF is divided into a kernel part and a user part registered in the virtual machine. The kernel part can be associated with various system events for tracking, and is called when the system event is triggered and writes event information to the registered eBPF map (eBPF table). The eBPF map saves data in the form of Key-Value and is a bridge for data interaction between the kernel part and the user part. The user program can poll the entries in the eBPF map to read the information written by the kernel part, and achieve data collection.

[0026] In the present specification, a data processing method is provided, and the present specification also relates to a data processing system, a computing device, and a computer-readable storage medium, which are described in detail one by one in the following embodiments.

[0027] Currently, the monitoring tools for virtual machines need to be installed in the customer virtual machine, such as eBPF. The kernel part in eBPF traces system events and writes event information into the eBPF map when the system event is triggered. The user part reads information from the eBPF map to achieve data collection. The monitoring tools installed in the virtual machine will perform a large number of system operations to collect data, which may conflict with the work of the system kernel, causing system lag or even downtime, affecting customer projects. Moreover, when the monitoring tools are scheduled, they will also preempt the resources of the virtual machine, causing jitter and delay of projects in the virtual machine and affecting user experience.

[0028] To solve the above problems, the industry has set up monitoring tools outside the virtual machine to collect data of the virtual machine, which is called virtual machine introspection (VMI). However, the limitation of traditional VMI is that the system events monitored or the system data collected are limited, and some important data cannot be collected.

[0029] Therefore, the data collection method provided by the embodiments of the present specification adopts a semi-virtualized eBPF (virtio-eBPF) architecture suitable for cloud environments, as shown in Figure 1 , Figure 1 The architecture schematic diagram of the semi-virtualized eBPF provided by an embodiment of the present specification is shown.

[0030] As Figure 1As shown, the virtual machine is registered in the host computer, and the host computer allocates virtual machine memory for the virtual machine. The virtual machine monitoring module registers the kernel part (virtual machine collection unit) of eBPF in the virtual machine, and registers the user part (virtual machine monitoring unit) of eBPF outside the virtual machine, that is, in the host computer. The virtual machine collection part registers a configuration table (config map) and a task table set (task map) in the memory of the virtual machine. The config map and the task map are used for data interaction between the virtual machine collection unit and the virtual machine monitoring unit. The config map is used to transmit various configuration information, and the task map is used for the virtual machine collection part of the detection tool to write new tasks. It should be noted that the task table set in the present specification can be used to distinguish and construct different types of task data according to the type of system event, or a corresponding task map can be constructed according to the number of CPUs corresponding to the virtual machine, that is, each CPU corresponds to a task map, so that the task data on different CPUs can be written into different task maps concurrently.

[0031] In actual application, the task map can be a ring buffer for storing task data, for example, 1024 task entries can be preset and used in a ring cycle. The virtio-eBPF architecture provided in the present specification can be realized by registering eBPF. After the registration of the kernel program, the config map and the task map is completed, the user program of eBPF can be set to a sleep state, and the use of the virtual machine collection unit, the config map and the task map can be reserved.

[0032] The virtual machine monitoring unit of the virtual machine monitoring module is registered in the host computer and has access to the virtual machine memory. Using a technical solution similar to Crash Utility, the virtual machine version, symbol table information, key data structure and other information are used as input to obtain event information in the virtual machine in real time and analyze the state of the virtual machine.

[0033] In actual application, the resources required for running the virtual machine monitoring unit can be preferentially obtained from the memory, CPU and other computing resources corresponding to the virtual machine. Since the virtual machine monitoring unit registered in the virtual machine is adjusted to the host computer, the resources required for the virtual machine monitoring unit can be separated from the computing resources of the virtual machine accordingly. At this time, although the virtual machine monitoring unit also occupies the resources of the virtual machine, the computing resources occupied by the virtual machine monitoring unit are separated from the computing resources of the virtual machine, thereby avoiding the problem of resource conflict with the virtual machine caused by running the virtual machine monitoring unit. The project jitter in the virtual machine can also be reduced by controlling the running time slice. If the host computer has idle computing resources at this time, the virtual machine monitoring unit can also be run by the idle computing resources in the host computer, thereby ensuring low-latency task processing.

[0034] In addition, there are various options for the model of the virtual machine monitoring unit running in the host computer. In the first scheme, the virtual machine monitoring unit is integrated into the Hypervisor, and the memory of the virtual machine can be directly accessed by using the capability of the Hypervisor. However, since the virtual machine monitoring unit is a third-party tool, it has a large invasiveness to the Hypervisor, which affects other virtual machines in the host computer. In the second scheme, the virtual machine monitoring unit can be run as a separate process in the Host OS, and the memory of the virtual machine needs to be mapped to the process to provide access permission. However, this scheme has a high implementation difficulty. In the third scheme, the virtual machine monitoring unit can be run in the container of the Host OS, which adds one layer of project isolation compared with the second scheme, and the memory of the virtual machine also needs to be mapped to the container to provide access permission. In the fourth scheme, the virtual machine monitoring unit can be run in a separate virtual machine (such as microvm), and the fourth scheme can provide better isolation compared with the third scheme. However, the memory of the virtual machine also needs to be mapped to the virtual machine corresponding to the virtual machine monitoring unit to provide access permission. In actual application, the above four schemes can all implement the data processing method provided in the present specification. Preferably, the fourth scheme is selected as the specific implementation scheme.

[0035] Based on the above semi-virtualized eBPF architecture, see Figure 2 , Figure 2 A flowchart of a data processing method according to an embodiment of the present specification is shown, the method is applied to a data processing system including a host computer, a virtual machine running on the host computer and a virtual machine monitoring unit, a virtual machine acquisition unit running on the virtual machine, and the method specifically includes the following steps.

[0036] Step 202: The virtual machine acquisition unit acquires the project event information of the virtual machine, and writes the project event information into a task table set, wherein the task table set is registered in the virtual machine memory.

[0037] The virtual machine collection unit is registered in the virtual machine and is used to collect item event information of the virtual machine. The item event information can be an event that a user wants to monitor in advance, such as a new process, a new network connection, a new file opening action, and the like.

[0038] In actual application, when the virtual machine collection unit in the virtual machine is invoked because of triggering of a system event, item event information of the event is collected, and the item event information is written into the task table set.

[0039] The task table set is a task map registered by the virtual machine collection unit in the memory of the virtual machine. The task map is used by the virtual machine collection unit as a producer to write a new task. The task map can be a ring buffer for storing task data. For example, 1024 task entries can be preset and used in a ring. When the virtual machine collection unit collects item event information of the virtual machine, the item event information is written into a next idle entry in the task map. Specifically, the item event information includes event information and prompt information. The event information specifically refers to information related to the item event, such as event type, event name, event representation, state information, and the like. The purpose of the prompt information is to provide necessary information for event analysis for the virtual machine monitoring unit. For example, for the system event of a new process, the prompt information can be a PID of the process or an address of a kernel key data structure.

[0040] In actual application, the task table in the task table set can be one or multiple. The number of task tables in the task table set can correspond to item event types or VCPUs corresponding to the virtual machine.

[0041] In a specific embodiment provided in the present specification, the task table set includes at least one task table. The task table corresponds to an item event type.

[0042] The virtual machine collection unit writes the item event information into the task table set, including:

[0043] The virtual machine collection unit determines a target item event type corresponding to the item event information, determines a target task table according to the target item event type, and writes the item event information into the target task table.

[0044] In the embodiment, the task table can be classified according to the project event type, for example, the project event type 1 corresponds to the task table 1, the project event type 2 corresponds to the task table 2, and so on. After the virtual machine acquisition unit acquires the project event information, the target project event type corresponding to the project event information is determined, the target project event type specifically refers to the project event type of the project event information, and the target task table corresponding to the target project event type in the task table set is determined, and the project event information is written into the target task table.

[0045] For example, there are three task tables in the task table set, which are task table 1, task table 2 and task table 3. The task table 1 stores the project event information of the first type, the task table 2 stores the project event information of the second type, and the task table 3 stores the project event information of the third type. The virtual machine acquisition unit monitors the occurrence of a certain project event, acquires the project event information of the project event, determines that the project event type of the project event information is the first type, and further determines that the task table corresponding to the project event information is the task table 1. The project event information is written into the next idle entry of the task table 1.

[0046] In another specific embodiment provided in the specification, the task table set includes at least one task table, wherein the task table corresponds to the virtual machine processor;

[0047] The virtual machine acquisition unit writes the project event information into the task table set, including:

[0048] The virtual machine acquisition unit determines the target virtual machine processor corresponding to the project event information, determines the target task table according to the target virtual machine processor, and writes the project event information into the target task table.

[0049] In the embodiment, the processing capability of VCPU, that is, the virtual processor, is fully utilized. The VCPU is a virtual processor of a virtual machine, and the CPU is a physical processor of a host machine. The virtualization of the CPU is a CPU simulation of multiple CPUs in parallel, which allows a platform to run multiple virtual machines simultaneously. The application programs in the virtual machine can run in independent spaces without affecting each other, thereby significantly improving the working efficiency of the host machine. The number of VCPUs can also determine the number of task tables. By means of one task table corresponding to each VCPU, a task table set is constructed, and the effect of concurrent processing of project event information in different task tables is achieved.

[0050] For example, the virtual machine corresponds to 6 VCUPs, and the task table set corresponds to 6 task tables, namely task table 1, task table 2, task table 3, task table 4, task table 5 and task table 6. When the virtual machine acquisition unit monitors the occurrence of a certain project event, the project event information of the project event is collected, and it is determined that the VCPU corresponding to the project event information is VCPU3, so it is determined that the task table corresponding to the project event information is task table 3, and the project event information is written to the next idle entry of task table 3.

[0051] After writing the project event information into the task table set, the virtual machine monitoring unit also needs to be notified to obtain the project event information from the task table set. Specifically, after the virtual machine acquisition unit writes the project event information into the task table set, the method further comprises:

[0052] The virtual machine acquisition unit generates task table configuration information according to the project event information, and writes the task table configuration information into a configuration table, wherein the configuration table is registered in the virtual machine memory.

[0053] The configuration table (config map) is used to deliver various types of configuration information. After writing the project event information into the task table set, the identifier of the task to be completed corresponding to the task table can be updated, such as the avail_index value (such as plus 1) of the task map in the config map. avail_index is used to identify the identifier of the task to be completed in the task table.

[0054] The configuration table can also be used to deliver parameter information between the virtual machine monitoring unit and the virtual machine acquisition unit. For example, the virtual machine acquisition unit can deliver the computing resources required by the virtual machine monitoring unit to the virtual machine monitoring unit through the configuration table; the virtual machine monitoring unit can also deliver the parameter information required by itself to the virtual machine acquisition unit through the configuration table.

[0055] Step 204: The virtual machine monitoring unit accesses the task table set in the virtual machine memory, reads the project event information from the task table set, analyzes the project event information to generate a project processing task, and processes the project processing task.

[0056] The virtual machine monitoring unit is part of the virtual machine monitoring module, registered outside the virtual machine, has access to the virtual machine memory, and can analyze the kernel state and eBPF information of the virtual machine.

[0057] Further, the virtual machine monitoring unit accesses the virtual machine memory, reads the task table set in the virtual machine memory, reads the item event information written by the virtual machine collection unit from the task table set. Specifically, the item event information in the task map can be read through the form of cyclic polling task map. By reading the item event information in the task map, the virtual machine monitoring unit can know which type of system event occurs in the virtual machine. By analyzing the item event information, the corresponding item processing task can be generated, and the to-be-processed task can be executed.

[0058] In actual application, there are usually multiple item event information in the task table set, and the virtual machine monitoring unit cannot accurately know which item event information has not been processed. It can also be determined with the configuration table in the virtual machine memory which item event information in the task table set is read. Specifically, the virtual machine monitoring unit accesses the task table set in the virtual machine memory, including:

[0059] The virtual machine monitoring unit accesses the configuration table in the virtual machine memory, reads the task table configuration information in the configuration table, and accesses the task table set in the virtual machine memory based on the task table configuration information.

[0060] In actual application, the virtual machine monitoring unit reads the configuration table registered in the virtual machine memory, reads the task table configuration information in the configuration table, that is, reads the to-be-completed task identification number of the task table in the configuration table, and reads the completed task identification number of the task table in the task table set. By comparing the to-be-completed task identification number and the completed task identification number, it can be determined which task table has new tasks to be processed, and then the item event information in the task table is read.

[0061] In actual application, the item event information includes event information and prompt information. Correspondingly, the virtual machine monitoring unit analyzes the item event information to generate an item processing task, including:

[0062] The virtual machine monitoring unit analyzes the item event information to obtain event information and prompt information.

[0063] An item processing task is generated according to the event information and the prompt information.

[0064] When the virtual machine monitoring unit obtains the project event information, the project event information can be parsed. As known from the above embodiment, the project event information includes event information and prompt information. After the project event information is parsed, the event information and the prompt information are obtained. The prompt information can be further analyzed. For example, according to the PID information of the "new process" event, the kernel state of the virtual machine can be analyzed by using a technology similar to Crash Utility, more information of the new process can be obtained, and the project processing task can be generated together with the event information, so that further requirements (such as security audit and the like) of the new process can be obtained.

[0065] When the virtual machine monitoring unit processes the project processing task, the project event information needs to be marked to identify that the project event information has been processed. Specifically, after the virtual machine monitoring unit processes the project processing task, the method further includes:

[0066] The virtual machine monitoring unit updates the task table configuration information in the configuration table.

[0067] In actual application, when the virtual machine monitoring unit processes the project processing task, the task table configuration information in the configuration table needs to be updated to identify that the project processing event has been completed. For example, the used_index (completed task identifier) corresponding to the task table in the config map is updated. The used_index is used to identify the task identifier that has been processed in the task table.

[0068] The embodiment of the present specification provides a data processing method, applied to a data processing system, the system including a host, a virtual machine running on the host and a virtual machine monitoring unit, and a virtual machine acquisition unit running on the virtual machine. The method includes that the virtual machine acquisition unit acquires project event information of the virtual machine and writes the project event information into a task table set, wherein the task table set is registered in a virtual machine memory; the virtual machine monitoring unit accesses the task table set in the virtual machine memory, reads the project event information from the task table set, parses the project event information to generate a project processing task, and processes the project processing task.

[0069] The data processing method provided by the embodiment of the present specification proposes a semi-virtualized eBPF architecture (virtio eBPF), and the virtual machine monitoring module of the architecture includes a virtual machine monitoring unit and a virtual machine collection unit. The virtual machine monitoring unit is registered outside the virtual machine, and the virtual machine collection unit is registered inside the virtual machine. The virtual machine collection unit collects events inside the virtual machine, and the virtual machine monitoring unit performs event monitoring and processing outside the virtual machine, avoiding running complex monitoring programs inside the virtual machine, which can effectively reduce project jitter and running interference (such as system lag or downtime). In addition, the semi-virtualized eBPF architecture provided by the present specification refers to registering specific eBPF maps (such as config map and task map), without modifying the virtual machine kernel, which is convenient to implement.

[0070] Compared with the traditional monitoring outside the virtual machine, the semi-virtualized eBPF architecture (virtio eBPF) is adopted in the present solution, and the virtual machine collection unit registered inside the virtual machine collects various events inside the virtual machine, avoiding the problem that important data cannot be collected due to incomplete event collection. At the same time, the virtual machine monitoring unit is registered outside the virtual machine, and the kernel state of the virtual machine is analyzed outside the virtual machine, which can effectively reduce project jitter and running interference, avoid adverse effects on normal project processing of the virtual machine, and improve the user experience.

[0071] The following describes the data processing method provided by the present specification in combination with the accompanying Figure 3 The data processing method provided by the present specification is further explained and described below by taking the application of the data processing method provided by the present specification as an example. Figure 3 The structure schematic diagram of the data processing system provided by one embodiment of the present specification is shown in FIG. 1. Figure 3 As shown in FIG. 1, a Target VM (target virtual machine) is registered in the host machine, and the events in the Target VM need to be monitored. Therefore, a virtual machine collection unit is registered in the Target VM, and a Micro VM (simplified VM) is started in the host machine. A virtual machine monitoring unit is registered in the Micro VM, and the virtual machine collection unit and the virtual machine monitoring unit form a virtual machine monitoring module. At the same time, the virtual machine memory of the Target VM is mapped to the Micro VM, so that the Micro VM can access the memory of the Target VM.

[0072] The virtual machine collection unit collects the project event information of the virtual machine, writes the project event information into a task table set registered in the virtual machine memory, generates task table configuration information, and updates and registers the task table configuration information in the configuration table in the virtual machine memory.

[0073] The virtual machine monitoring unit accesses the virtual machine memory, reads task table configuration information in the configuration table, reads item event information in the task table set according to the task table configuration information, and parses the item event information to obtain event information and prompt information, generates an item processing task according to the obtained event information and prompt information, and processes the item processing task. At the same time, the task table configuration information of the configuration table in the virtual machine memory is updated, which is used to determine that the item event information has been processed.

[0074] Corresponding to the method embodiments, the present specification also provides data processing system embodiments, Figure 4 A structural schematic diagram of a data processing system provided by another embodiment of the present specification is shown. As shown in the figure, Figure 4 The system includes a host computer 402, a virtual machine 404 running on the host computer, and a virtual machine monitoring module 406, the virtual machine monitoring module 406 including a virtual machine monitoring unit 4062 and a virtual machine acquisition unit 4064, the virtual machine monitoring unit 4062 running on the virtual machine, and the virtual machine acquisition unit 4064 running on the virtual machine, wherein,

[0075] The virtual machine acquisition unit 4064 is configured to acquire item event information of the virtual machine and write the item event information into a task table set, and the task table set is registered in a virtual machine memory;

[0076] The virtual machine monitoring unit 4062 is configured to access the task table set in the virtual machine memory, read the item event information from the task table set, parse the item event information to generate an item processing task, and process the item processing task.

[0077] Optionally, the virtual machine acquisition unit 4064 is further configured to generate task table configuration information according to the item event information and write the task table configuration information into a configuration table, and the configuration table is registered in the virtual machine memory.

[0078] Optionally, the task table set includes at least one task table, and the task table corresponds to an item event type;

[0079] The virtual machine acquisition unit 4064 is further configured to determine a target item event type corresponding to the item event information, determine a target task table according to the target item event type, and write the item event information into the target task table.

[0080] Optionally, the task table set includes at least one task table, and the task table corresponds to a virtual machine processor;

[0081] The virtual machine collection unit 4064 is further configured to determine a target virtual machine processor corresponding to the project event information, determine a target task table according to the target virtual machine processor, and write the project event information into the target task table.

[0082] Optionally, the project event information includes event information and prompt information.

[0083] The virtual machine monitoring unit 4062 is further configured to parse the project event information to obtain event information and prompt information, and generate a project processing task according to the event information and the prompt information.

[0084] Optionally, the virtual machine monitoring unit 4062 is further configured to access the configuration table in the virtual machine memory, read task table configuration information in the configuration table, and access a task table set in the virtual machine memory based on the task table configuration information.

[0085] Optionally, the virtual machine monitoring unit 4062 is further configured to update the task table configuration information in the configuration table.

[0086] The data processing system provided by the embodiments of the present specification proposes a semi-virtualized eBPF architecture (virtio eBPF). The virtual machine monitoring module of the architecture includes a virtual machine monitoring unit and a virtual machine collection unit. The virtual machine monitoring unit is registered outside the virtual machine, and the virtual machine collection unit is registered inside the virtual machine. The virtual machine collection unit collects events inside the virtual machine, and the virtual machine monitoring unit performs event monitoring and processing outside the virtual machine. This avoids running complex monitoring programs inside the virtual machine, effectively reduces project jitter and running interference (such as system lag or downtime), and in addition, the semi-virtualized eBPF architecture provided by the present specification refers to registering specific eBPF maps (such as config map and task map), without the need to modify the virtual machine kernel, facilitating implementation.

[0087] Compared with traditional monitoring outside the virtual machine, the present solution adopts a semi-virtualized eBPF architecture (virtio eBPF) to collect various events inside the virtual machine through the virtual machine collection unit registered inside the virtual machine, avoiding the problem of incomplete event collection and inability to collect important data. At the same time, the virtual machine monitoring unit is registered outside the virtual machine, and the kernel state of the virtual machine is analyzed outside the virtual machine, which can effectively reduce project jitter and running interference, avoid adverse effects on normal project processing of the virtual machine, and improve user experience.

[0088] The above is a schematic scheme of the data processing system of the embodiment. It should be noted that the technical scheme of the data processing system and the technical scheme of the data processing method described above belong to the same concept, and the details of the technical scheme of the data processing system that are not described in detail can be referred to the description of the technical scheme of the data processing method.

[0089] Figure 5 A structural block diagram of a computing device 500 according to one embodiment of the present specification is shown. The components of the computing device 500 include, but are not limited to, a memory 510 and a processor 520. The processor 520 is connected to the memory 510 through a bus 530, and a database 550 is used to save data.

[0090] The computing device 500 also includes an access device 540, which enables the computing device 500 to communicate via one or more networks 560. Examples of these networks include a public switched telephone network (PSTN), a local area network (LAN), a wide area network (WAN), a personal area network (PAN), or a combination of communication networks such as the Internet. The access device 540 can include one or more of any type of network interface (e.g., network interface card (NIC)), wired or wireless, such as an IEEE 802.11 wireless local area network (WLAN) wireless interface, a Worldwide Interoperability for Microwave Access (Wi-MAX) interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth interface, a near field communication (NFC) interface, and the like.

[0091] In one embodiment of the present specification, the above-mentioned components of the computing device 500 and other components not shown in the Figure 5 may be connected to each other, for example, through a bus. It should be understood that Figure 5 The structural block diagram of the computing device shown is only for the purpose of example, and is not a limitation on the scope of the present specification. Other components can be added or replaced as needed by those skilled in the art.

[0092] The computing device 500 can be any type of stationary or mobile computing device, including a mobile computer or mobile computing device (e.g., a tablet computer, a personal digital assistant, a laptop computer, a notebook computer, a netbook, etc.), a mobile phone (e.g., a smartphone), a wearable computing device (e.g., a smartwatch, smart glasses, etc.), or other types of mobile devices, or a stationary computing device such as a desktop computer or a PC. The computing device 500 can also be a mobile or stationary server.

[0093] The processor 520 is configured to execute the following computer-executable instructions, which implement the steps of the data processing method described above when executed by the processor. The above is a schematic solution of the computing device of the embodiment. It should be noted that the technical solution of the computing device and the technical solution of the data processing method described above belong to the same concept, and the details of the technical solution of the computing device that are not described in detail can be referred to the description of the technical solution of the data processing method.

[0094] An embodiment of the present specification further provides a computer-readable storage medium storing computer-executable instructions, which implement the steps of the data processing method described above when executed by the processor.

[0095] The above is a schematic solution of the computer-readable storage medium of the embodiment. It should be noted that the technical solution of the storage medium and the technical solution of the data processing method described above belong to the same concept, and the details of the technical solution of the storage medium that are not described in detail can be referred to the description of the technical solution of the data processing method.

[0096] An embodiment of the present specification further provides a computer program, which causes a computer to execute the steps of the data processing method described above when the computer program is executed in the computer.

[0097] The above is a schematic solution of the computer program of the embodiment. It should be noted that the technical solution of the computer program and the technical solution of the data processing method described above belong to the same concept, and the details of the technical solution of the computer program that are not described in detail can be referred to the description of the technical solution of the data processing method.

[0098] The specific embodiments of the present specification are described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in a different order and still achieve desirable results. Additionally, the process depicted in the figures does not necessarily require the particular order shown, or sequential order to achieve desirable results. In some embodiments, multitasking and parallel processing can be advantageous.

[0099] The computer readable medium can include any entity or apparatus capable of carrying the computer program code, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, software distribution medium, etc. It should be noted that the computer readable medium can include appropriate additions or subtractions according to the requirements of legislation and patent practice in the jurisdiction, for example, in some jurisdictions, according to legislation and patent practice, the computer readable medium does not include electrical carrier signals and telecommunication signals.

[0100] It should be noted that for the foregoing method embodiments, the descriptions are all expressed as a combination of a series of actions for the sake of simplicity, but those skilled in the art should know that the embodiments of the present specification are not limited by the order of the described actions, because according to the embodiments of the present specification, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the embodiments of the present specification.

[0101] In the above embodiments, the description of each embodiment has its own focus, and the parts not described in detail in a certain embodiment can be referred to the related description of other embodiments.

[0102] The preferred embodiments of the present specification disclosed above are only used to help explain the present specification. The alternative embodiments do not describe all the details and limit the invention to the specific embodiments described. Obviously, according to the content of the embodiments of the present specification, many modifications and changes can be made. The present specification selects and describes these embodiments in order to better explain the principles and practical applications of the embodiments of the present specification, so that those skilled in the art can well understand and use the present specification. The present specification is limited by the claims and their entire scope and equivalents.

Claims

1. A data processing method applied to a data processing system, the system comprising a host machine, a virtual machine, and a virtual machine monitoring module, the virtual machine monitoring module comprising a virtual machine monitoring unit and a virtual machine acquisition unit, wherein the virtual machine and the virtual machine monitoring unit run within the host machine, and the virtual machine acquisition unit runs within the virtual machine; the method comprising: The virtual machine acquisition unit collects project event information of the virtual machine and writes the project event information into a task table set, wherein the task table set is registered in the virtual machine memory and is a data structure for storing task data; The virtual machine monitoring unit accesses the task table set in the virtual machine memory, reads the project event information from the task table set, parses the project event information to generate project processing tasks, and processes the project processing tasks. The project event information includes event information and prompt information. The event information refers to information related to the project event, and the prompt information provides the virtual machine monitoring unit with information for event analysis.

2. The data processing method as described in claim 1, after the virtual machine acquisition unit writes the project event information into the task table set, the method further includes: The virtual machine acquisition unit generates task table configuration information based on the project event information and writes the task table configuration information into a configuration table, wherein the configuration table is registered in the virtual machine memory.

3. The data processing method as described in claim 1, wherein the task table set includes at least one task table, wherein, The task list corresponds to the project event types; The virtual machine acquisition unit writes the project event information into a task table set, including: The virtual machine acquisition unit determines the target project event type corresponding to the project event information, determines the target task table based on the target project event type, and writes the project event information into the target task table.

4. The data processing method as described in claim 1, wherein the task table set includes at least one task table, wherein, The task table corresponds to the virtual machine processor; The virtual machine acquisition unit writes the project event information into a task table set, including: The virtual machine acquisition unit determines the target virtual machine processor corresponding to the project event information, determines the target task table based on the target virtual machine processor, and writes the project event information into the target task table.

5. The data processing method as described in claim 1, wherein the project event information includes event information and prompt information; The virtual machine monitoring unit parses the project event information to generate project processing tasks, including: The virtual machine monitoring unit parses the project event information to obtain event information and prompt information; Project processing tasks are generated based on the event information and the prompt information.

6. The data processing method as described in claim 2, wherein the virtual machine monitoring unit accesses the task table set in the virtual machine memory, comprising: The virtual machine monitoring unit accesses the configuration table in the virtual machine memory, reads the task table configuration information in the configuration table, and accesses the task table set in the virtual machine memory based on the task table configuration information.

7. The data processing method of claim 6, further comprising, after the virtual machine monitoring unit processes the project processing task: The virtual machine monitoring unit updates the task table configuration information in the configuration table.

8. A data processing system, the system comprising a host machine, a virtual machine, and a virtual machine monitoring module, the virtual machine monitoring module comprising a virtual machine monitoring unit and a virtual machine acquisition unit, wherein the virtual machine and the virtual machine monitoring unit run within the host machine, and the virtual machine acquisition unit runs within the virtual machine; wherein, The virtual machine acquisition unit is configured to acquire project event information of the virtual machine and write the project event information into a task table set, wherein the task table set is registered in the virtual machine memory and the task table set is a data structure for storing task data; The virtual machine monitoring unit is configured to access the task table set in the virtual machine memory, read the project event information from the task table set, parse the project event information to generate project processing tasks, and process the project processing tasks. The project event information includes event information and prompt information. The event information refers to information related to the project event, and the prompt information provides event analysis information for the virtual machine monitoring unit.

9. A computing device, comprising: Memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions, which, when executed by the processor, implement the steps of the data processing method according to any one of claims 1 to 7.

10. A computer-readable storage medium storing computer-executable instructions that, when executed by a processor, implement the steps of the data processing method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Virtual machine monitoring data acquisition method and device, and host machine

    CN111625319A

  • Flow collection method and device based on eBPF

    CN114006839A