Monitor processor operation

By leveraging the collaborative work of an external verification agent and a platform inspection module, and utilizing virtualization support and interrupt mechanisms, the signal pin access restrictions in processor operation verification in existing technologies have been resolved, enabling efficient processor operation monitoring and verification.

CN114625616BActive Publication Date: 2025-10-31INTEL CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210308352.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2015-12-17
Filing Date
2016-11-17
Publication Date
2025-10-31
Estimated Expiration
2036-11-17

AI Technical Summary

Technical Problem

Existing technologies make it difficult to effectively monitor and verify processor operation without accessing all of the processor's signal pins.

Method used

By working together with the External Verification Agent (EVA) and the Platform Inspection Module (PCM), external verification of processor operations is achieved by monitoring processor operations using hardware and software mechanisms, including virtualization support and interrupt mechanisms.

Benefits of technology

It enables effective monitoring and verification of processor operations, reduces the need for actual access to processor signal pins, and improves the efficiency and accuracy of verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114625616B_ABST
    Figure CN114625616B_ABST
Patent Text Reader

Abstract

Embodiments of the present invention for monitoring processor operation are disclosed. In one embodiment, a system includes a processor and a hardware agent located outside the processor. The processor includes virtualization logic to prepare the processor for operation in root mode and non-root mode. The hardware agent verifies the operation of the processor in the non-root mode based on tracing information to be collected by a software agent executed by the processor in the root mode.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Claiming priority

[0002] This application claims priority to U.S. non-provisional patent application No. 14 / 973,238, entitled “MONITORING THE OPERATION OF APROCESSOR”, filed on December 17, 2015. Technical Field

[0003] This disclosure relates to the field of information processing, and more specifically, to the field of verification in information processing systems. Background Technology

[0004] Verification of the correct operation of a processor in an information processing system can be important for a variety of reasons, including quality assurance, reliability, and security. Various techniques have been developed that can be useful for this purpose, such as checkpoint processing and tracing. Some of these techniques can be considered internal, for example, when the processor itself provides some form of authentication to an external agent. Other techniques can be considered external, for example, when an agent or component outside the processor monitors the processor's operation. External verification may require physical access to signal pins and / or the connection between the processor and the rest of the system. Attached Figure Description

[0005] The invention is illustrated in the accompanying drawings as an example and not as a limitation.

[0006] Figure 1 The illustration depicts a system including support for monitoring the operation of a processor, according to an embodiment of the present invention.

[0007] Figure 2 The illustration shows a processor including support for monitoring according to an embodiment of the present invention.

[0008] Figure 3 The illustration shows a system including hardware and software for monitoring the operation of a processor according to an embodiment of the present invention.

[0009] Figure 4 The illustration depicts a method for monitoring processor operation according to an embodiment of the present invention.

[0010] Figure 5 The illustration shows a method for verifying processor memory access according to an embodiment of the present invention.

[0011] Figure 6 An external verification agent according to an embodiment of the present invention is illustrated. Detailed Implementation

[0012] Embodiments of the present invention for monitoring the operation of a processor are described. In this description, numerous specific details (such as components and system configurations) may be set forth to provide a more thorough understanding of the invention. However, those skilled in the art will appreciate that the invention can be practiced without such specific details. Additionally, some well-known structures, circuits, and other features have not been shown in detail to avoid unnecessarily obscuring the invention.

[0013] In the following description, references to "an embodiment," "an embodiment," "an exemplary embodiment," "various embodiments," etc., indicate that one or more embodiments of the invention described herein may include a particular feature, structure, or characteristic, but more than one embodiment may include that particular feature, structure, or characteristic, and not every embodiment necessarily includes that particular feature, structure, or characteristic. Furthermore, some embodiments may have some, all, or none of the features described with respect to other embodiments.

[0014] As used in this description and claims, and unless otherwise specified, the use of ordinal adjectives such as “first,” “second,” “third,” etc., for the purpose of describing elements merely indicates that a particular instance of an element or a different instance of a similar element is mentioned, and is not intended to imply that the elements so described must be in a particular order in time, space, hierarchy, or any other way.

[0015] Furthermore, the terms “bit,” “mark,” “field,” “entry,” “indicator,” etc., can be used to describe any type or content of a storage location in a register, table, database, or other data structure, whether implemented in hardware or software, without intending to limit embodiments of the invention to any particular type of storage location or any particular number of bits or other elements within any particular storage location. The term “clear” can be used to indicate that a logical value of 0 is stored in a storage location, or to otherwise store a logical value of 0 in a storage location, and the term “set” can be used to indicate that a logical value of 1, all 1s, or some other specified value is stored in a storage location; however, these terms are not intended to limit embodiments of the invention to any particular logical convention, as any logical convention can be used within embodiments of the invention.

[0016] Furthermore, as used in the description of embodiments of the present invention, the " / " character between terms may mean that the embodiment may include a first term and / or a second term (and / or any other additional term), or be implemented using, utilizing, and / or based on the first term and / or the second term (and / or any other additional term).

[0017] As described in the Background section, techniques have been developed that are useful for verifying the correct operation of processors in information processing systems. Embodiments of the present invention can provide new avenues for external agents to monitor or verify processor operation, which may be desirable because they do not require access to all of the processor's signal pins.

[0018] Figure 1 The illustration shows system 100, an information processing system according to an embodiment of the present invention, including a method for monitoring the operation of a processor. System 100 can represent any type of information processing system, such as a server, desktop computer, portable computer, set-top box, handheld device (such as a tablet or smartphone), or embedded control system. System 100 includes processor 110, system memory 120, graphics processor 130, peripheral control agent 140, information storage device 150, processor 160, and external agent 170. Systems embodying the present invention may include each of these components and any number of other components or elements (such as peripheral devices and input / output devices). Any or all components or elements in this system embodiment or any system embodiment may be connected, coupled, or otherwise communicate with each other via any number of buses, point-to-point, or other wired or wireless interfaces or connections, unless otherwise specified. Any component or other part of system 100 (regardless of whether it is in Figure 1 It is shown in or not in Figure 1 (As shown in the figure) can be integrated or otherwise included on or in a single chip (system-on-chip or SOC), die, substrate or package.

[0019] System memory 120 may be dynamic random access memory (DRAM) or any other type of media readable by processor 110 and / or 160. Although in Figure 1 While shown as a single block, system memory 120 can include multiple components in various configurations. For example, in a non-uniform memory access (NUMA) architecture, system memory 120 can be logically extended across multiple processor sockets using a communication bus.

[0020] The graphics processor 130 may include any processor or other component for processing graphics data for the display 132. The peripheral control agent 140 may represent any component such as a chipset component, including peripherals, input / output (I / O) or other components or devices, such as device 142 (e.g., touchscreen, keyboard, microphone, speaker, other audio device, camera, video or other media device, network adapter, motion or other sensor, receiver for GPS or other information, etc.) and / or information storage device 150, or through which the peripheral, input / output (I / O) or other component or device may be connected or coupled to processors 110 and / or 160. The information storage device 150 may represent any one or more components including any one or more types of persistent or non-volatile memory or storage (such as flash memory and / or solid-state drives, disk drives, or optical disc drives).

[0021] Processor 110 may represent all or part of a hardware component comprising one or more processors or processor cores integrated on a single substrate or packaged within a single package in any combination, each of which may include multiple execution threads and / or multiple execution cores. Each processor represented as processor 110 or located within processor 110 may be any type of processor, including general-purpose microprocessors (such as...). Processor family or from The processor 110 may be a processor in another processor family of the same company or another company, a dedicated processor or microcontroller, or any other device or component in an information processing system in which embodiments of the present invention may be implemented. The processor 110 may be architected and designed to operate according to any instruction set architecture (ISA), either under microcode control or without microcode control.

[0022] Processor 110 may support resource virtualization in any way. Generally, the concept of virtualization in an information processing system allows multiple instances of one or more operating systems (each an “OS”) to run on a single information processing system, even if each OS is designed to have complete and direct control over the system and its resources. Typically, virtualization is implemented using software (e.g., a virtual machine monitor or “VMM”) to present each OS with a “virtual machine” (“VM”) containing virtual resources, including one or more virtual processors, which the OS has complete and direct control over. The VMM maintains a system environment (“virtual environment”) for implementing virtualization strategies (such as sharing and / or allocating physical resources among VMs).

[0023] Processors in information processing systems can support virtualization, for example, by operating in two modes: "root" mode, where software runs directly on the hardware outside of any virtualization environment; and "non-root" mode, where software runs at its intended privilege level but within a virtual environment managed by a VMM running in root mode. Within the virtual environment, certain events, operations, and conditions, such as interrupts, exceptions, and attempts to access privileged registers or resources, can be intercepted, i.e., causing the processor to exit the virtual environment ("VM exit"), allowing the VMM to operate to, for example, implement virtualization policies. The processor can support instructions for creating, entering ("VM enter"), exiting, and maintaining virtual environments, and may include register bits or other structures that indicate or control the processor's virtualization capabilities.

[0024] Additionally, support for external monitoring according to embodiments of the present invention can be provided by a processor (such as processor 110) using any combination of hardware, microcode, firmware, and / or other structures arranged as described below, or by any other means, and in Figure 1 The external verification (EV) hardware / logic 112 may include or be fully implemented in the virtualization hardware / logic 114 to support virtualization. Thus, all hardware / logic of the virtualization hardware / logic 114 and / or the EV hardware / logic 112 may exist in the processor 110 for any one or more purposes other than for external verification.

[0025] In an embodiment where system 100 represents a multiprocessor system, processor 110 may represent one or more processors and may be referred to as a first processor, and system 100 may further include components from... Figure 1 Processor 160 in the text represents a second processor and / or any number of additional processors. Processor 160 can represent any type of processor, including processors that are the same as, compatible with, in the same family, share any part of the same ISA as processor 110, and / or different in any way. Processor 160 may include EV hardware / logic 162 and / or virtualization hardware / logic 164, each of which may resemble a corresponding part of processor 110.

[0026] External Authentication Agent (EVA) 170 can represent any agent, such as a third processor, a field-programmable gate array (FPGA), or other hardware components located outside of processor 110. In various embodiments of the invention, "external" can mean one or more of the following: EVA 170 is not located within the same integrated circuit as processor 110; EVA 170 and processor 110 are located in different integrated circuits; EVA 170 is not located on the same die or substrate as processor 110; EVA 170 and processor 110 are located on different dies or substrates; EVA 170 is not located within the same package as processor 110; EVA 170 and processor 110 are located in different packages; and / or EVA 170 is located outside a boundary defined by a set of pins or connectors through which processor 110 can send signals to and receive signals from one or more agents or components outside the boundary. As an external agent, in some embodiments, EVA 170 can monitor and / or intercept transactions on the system memory bus (e.g., between processor 110 and system memory 120) and / or input / output buses (e.g., Fast Peripheral Component Interconnect (PCIe) buses to network controllers, storage devices, keyboards / mice, graphics and displays, etc.). In embodiments that include a second processor (e.g., processor 160), EVA 170 is also external to processor 160.

[0027] EVA 170 represents hardware or a hardware agent for verifying the operation of one or more processors (e.g., processors 110 and / or 160) according to embodiments of the present invention, including circuitry for executing instructions and for reading from and writing to system memory (directly or indirectly). In various embodiments, EVA 170 may represent a processor programmed or programmable to verify the operation of another one or more processors (such as processors that are the same as, compatible with, in the same family, share any part of the same ISA as, and / or different in any way from, processors 110 and / or 160) or a controller or other hardware agent configured or configurable (e.g., using firmware) to verify the operation of one or more processors.

[0028] Platform Inspection Module (PCM) 180 represents a software agent (defined below) to be executed by one or more processors to collect information reflecting and / or relating to the operation of one or more processors, which can be used by EVA to verify the operation of one or more processors. The software agent can be: any program, software module, software component, software agent, or other instruction sequence that can be executed by or translated into a sequence of instructions executable by the processor in system 100, such as stored on any non-volatile medium readable by the processor in system 100; and / or all or any part thereof, such as copied to any volatile or non-volatile medium readable by the processor in system 100, such as system memory 120 and / or any cache memory within or accessible to the processor. Therefore, in various embodiments, PCM 180 can be stored as software or firmware within any memory, storage, and / or component of system 100, and can be moved and / or copied, either wholly or in parts, to any memory of system 100 at various times and in various configurations during operation of system 100. For example, PCM 180 can be stored in information storage device 150, loaded wholly or partially into system memory 120 for execution by one or more processors such as processors 110 and / or 160, and partially copied to one or more cache memories within and / or accessible to any one or more of the processors by which it is executed. Accordingly, in various embodiments, multiple instantiations of PCM 180 can, for example, run simultaneously or concurrently on different execution cores. Furthermore, different types of PCMs can be used to monitor different modes of processor operation (e.g., host mode, system management mode) or different execution cores in a partitioned system.

[0029] Figure 2 The diagram illustrates processor 200, which can represent Figure 1 Embodiments of processors 110 and / or 160 in or Figure 1 The processor 200 is an execution core in a multi-core processor embodiment of processor 110 / 160. Processor 200 may include a storage unit 210, an instruction unit 220, an execution unit 230, a control unit 240, and a memory management unit (MMU) 250, wherein... Figure 1 The circuitry, structure, and functions of the EV hardware / logic 112 / 162 can be contained within and / or distributed across any of these units. Processor 220 may also include... Figure 1 Any other circuitry, structure, or logic not shown (e.g., performance counter hardware).

[0030] Storage unit 210 may include any combination of any type of memory that may be used within processor 200 for any purpose; for example, it may include: any number of readable, writable, and / or read-write registers, buffers, and / or caches implemented using any memory or storage technology, wherein storage capacity information, configuration information, control information, status information, performance information, instructions, data, and any other information that may be used in the operation of processor 200; and circuitry that may be used to access such memory and / or cause or support various operations and / or configurations associated with access to such memory. In various embodiments of the invention, storage unit 210 may include one or more registers or other state storage locations (state register 212) whose contents may be copied or moved to system memory 120 in connection with saving the state of processor 200 (e.g., using state save instruction 224), and whose contents may be loaded or written from system memory 120 in connection with restoring the state of processor 200.

[0031] Instruction unit 220 may include any circuitry, logic, structure, and / or other hardware (such as an instruction decoder) for acquiring, receiving, decoding, interpreting, scheduling, and / or disposing of instructions (such as VM entry instruction 222 and state saving instruction 224) to be executed by processor 200. Any instruction format may be used within the scope of this invention; for example, an instruction may include an opcode and one or more operands, wherein the opcode may be decoded into one or more microinstructions or microoperations for execution by execution unit 230. Operands or other parameters may be associated with instructions implicitly, directly, indirectly, or by any other means. VM entry instruction 222 may represent any one or more instructions from any instruction set that can be used to transfer control to a VM (e.g., by the VMM for an initial entry into a newly created VM or for a subsequent entry into a previously created VM (i.e., after a previous VM entry and VM exit)).

[0032] Execution unit 230 may include any circuitry, logic, structure, and / or other hardware for processing data and executing instructions, microinstructions, and / or microoperations, such as an arithmetic unit, logic unit, floating-point unit, shifter, etc. Execution unit 230 may represent any one or more physically or logically distinct execution units.

[0033] Control unit 240 may include any microcode, firmware, circuitry, logic, architecture, and / or hardware for controlling the operation of units and other components of processor 200 and the transfer of data within, to, and from processor 200. Control unit 240 may enable processor 200 to execute or participate in the execution of method embodiments of the invention, such as those described below, for example, by using execution unit 230 and / or any other resources to enable processor 200 to execute instructions received by instruction unit 220 and microinstructions or microoperations derived from those instructions. The execution of instructions by execution unit 230 may vary based on control and / or configuration information stored in storage unit 210. Control unit 240 may include virtualization unit 242 to prepare processor 200 to intercept certain events occurring in the VM and cause the VM to exit.

[0034] MMU 250 may include any circuitry, logic, architecture, and / or other hardware for managing system memory, such as preparing for the virtualization of physical memory according to any desired approach and for the protection of system memory. In embodiments, MMU 250 supports the use of virtual memory to provide software (including software running in a VM) with a larger address space for storing and accessing code and data than the address space of the physical memory in the system (e.g., system memory 120). The virtual memory space of processor 200 may be limited only by the number of address bits available to the software running on the processor, while the physical memory space of processor 200 may be limited to the size of system memory 120. MMU 250 supports memory management schemes (such as paging) to exchange code and data executing software in and out of system memory 120 on an on-demand basis. As part of this scheme, software may access the processor's virtual memory space using untranslated addresses translated into translated addresses by the processor, which the processor can use to access the processor's physical memory space.

[0035] Accordingly, MMU 250 may include a translation back buffer 252, wherein translations of virtual, logical, linear, or other untranslated addresses to physical or other translated addresses are stored according to any known memory management technique (such as paging). To perform these address translations, MMU 250 may include page-walking hardware 254 for querying the processor 200, system memory 120, ... Figure 1One or more data structures are stored in storage locations and / or any combination of such locations in system 100, not shown. These data structures may include page directories, page tables, and other paging data structures according to any known paging architecture. Each such page data structure and TLB 252 may include (or be associated with an individual or group of entries) one or more bits or other indicators for indicating and enforcing various permissions (e.g., read, write, or execute) that may define or restrict access to pages (or other areas) of memory.

[0036] Figure 3 This illustration shows another view of a system including hardware and software that monitors the processor's operation. Figure 3 In the system 300, there are representations Figure 1 The system 100 in the system contains bare platform hardware 310. Bare platform hardware 310 is shown as including components respectively with... Figure 1 The processors 110, 160 and EVA 170 in the above are processors 320, 330 and EVA 340 respectively, but may include any number of processors.

[0037] Figure 3 System memory space 350 is also shown, representing the memory space in the system architecture of system 300, addressable by any one or more processors in system 300. System memory space 350 may be represented by memory virtualization technology based on, for example... Figure 1 The system memory space 350 is a virtual system memory space provided by physical system memory such as system memory 120. Thus, system memory space 350 is an abstraction of physical memory and can store various combinations of data, instructions, code, programs, software and / or other information in various memories and / or other storage locations within system 300 at various times during the operation of system 300.

[0038] Despite Figure 3 Not shown in the text, but except as shown in the example Figure 3 In addition to the system memory space shown, the system according to embodiments of the present invention may further include one or more memory spaces. For example, to support processor operation in System Management Mode (SMM), the system may include an SMM memory space (SMRAM) separate from the system memory space. Therefore, embodiments of the present invention can prepare a second PCM to reside in the SMRAM and / or monitor access to the SMRAM.

[0039] For convenience, Figure 3The system memory space 350 is represented as a single contiguous memory space. However, the system memory space 350 may be logically organized, addressable, and / or otherwise partitioned (e.g., using memory partitioning / protection techniques provided by MMU250) into one or more uniformly sized regions. In various embodiments, such a region may be a 4KB page, and therefore, for convenience, such a region may be referred to as a page in this description; thus, the use of the term "page" in this description may refer to any size region of memory.

[0040] Furthermore, any number of such areas in any combination can be protected such that some portions of system memory space 350 are accessible to certain software, components, and / or VMs, but inaccessible to others. For example, system memory space 350 may include PCM memory 360 and general software stack (OSS) memory 370, wherein PCM memory 360 includes and is accessible to PCM 362, and OSS memory 370 includes and is accessible to other software (OSS 372, such as an operating system and application software) being executed by and / or being executable by one or more processors in system 300. PCM memory 360 is accessible to one or more processors in the system (e.g., processors 320 and / or 330), such that PCM 362 can be executed by one or more processors (e.g., processors 320 and / or 330), but the PCM memory is protected from OSS 372 and is inaccessible to OSS 372. Furthermore, the PCM memory 360 includes a tracking information memory 364 and a tracked page memory 366, both of which are accessible to the EVA 350 and store tracking information and tracked pages respectively, as described below; and the OSS memory 370 includes untracked pages 376, as described below.

[0041] In various embodiments, PCM 362 can be implemented as a VMM or hypervisor, or a software or firmware module or component of a VMM or hypervisor, within a single VMM or hierarchical or multi-VMM virtualization architecture (therefore, PCM can be referred to as "host" or "host" software), and thus may be able to partition system memory 340 into PCM areas and create and maintain VMs to contain OSS memory area 370 (therefore, OSS 372 can be referred to as "guest" or "guest" software, since OSS is a guest in the virtualization environment hosted by PCM). Accordingly, interrupts generated by EVA 340 can be used to cause VM exit from the VM operating in OSS and the transfer of processor control from the software within OSS 372 to PCM 362.

[0042] In various embodiments, EVA 340 may generate a first interrupt for starting a sampling interval and a second interrupt for ending a sampling interval. As further described below, PCM 362 may collect information at the start, at the end, and / or during the sampling interval, which may be used by EVA 340 in conjunction with other information from OSS memory 370 to verify the operation of one or more processors (e.g., processors 320 and / or 330).

[0043] Figure 4 The illustration shows a method 400 for monitoring processor operation according to an embodiment of the present invention. While the method embodiments of the present invention are not limited in this respect, reference may be made to... Figure 1 , 2 The elements of 3 and 4 help to describe Figure 4 Method embodiments. Various parts of method 400 can be executed by the user of hardware, firmware, software and / or systems such as system 100 and / or 300.

[0044] In block 410 of method 400, the information processing system (e.g., system 300) can operate with or without the virtualization environment being maintained by a PCM (e.g., PCM 362).

[0045] In block 420, the EVA (e.g., EVA 340) sends a first interrupt to one or more processors in the system (e.g., processors 320 and / or 330) to initiate a sampling interval. In various embodiments, other means of initiating (and / or terminating) the sampling interval may be used. For example, the EVA may specify a specific time or condition (a specific physical memory location is accessed, a specific interrupt or other event is observed, etc.) at which the PCM begins the sampling interval and / or configures the system (e.g., paging structures, debug registers, VMCS, system timers, etc.) so that it can subsequently intercept various events and perform checkpoints as the EVA may instruct.

[0046] In block 422, the delivery of the first interrupt to the processor causes processor control (via any combination of VM exit, interrupt vectors, interrupt handling routines, etc.) to be transferred to the PCM. In block 424, the PCM creates an initial checkpoint by (e.g., using a save state instruction) storing the state of certain registers or other storage locations (e.g., status register 212) in a first data structure in a region of system memory reserved for use by the PCM (e.g., trace information memory 364). In block 426, the PCM transfers processor control (e.g., using a VM enter instruction) to the software in the OSS (e.g., OSS372) running on the VM.

[0047] In box 430, the software in OSS operates within the VM and can be intercepted by the PCM at various times, at each of which the PCM can record trace information in the trace information memory. The trace information may include information collected by tracing transactions on the memory bus, I / O bus, and multiprocessor socket interconnects. Various events (such as interrupts, attempts to access privileged or designated registers and / or memory and / or memory locations, I / O operations initiated by OSS, etc.) can be intercepted, traced, and emulated, or allowed to be handled, completed, and / or executed by OSS.

[0048] For example, in box 440, a second interrupt can be sent from an input / output device (e.g., device 142) or other source to one or more processors. In box 442, the delivery of the second interrupt to the processor causes control of the processor (via VM exit) to be transferred to the PCM. In box 444, the PCM records trace information (e.g., interrupt vector) in a second data structure in trace information memory. In box 446, the PCM transfers control of the processor (e.g., using VM entry instructions) back to the software in the OSS running on the VM and delivers the second interrupt to the OSS (e.g., in connection with VM entry, injecting a virtual interrupt corresponding to the second interrupt into the VM). In box 448, the software in the OSS can handle the second interrupt and then continue operating within the VM.

[0049] In various embodiments, the tracking information recorded by the PCM during the sampling interval may include information for preparing the EVA to simulate and / or verify the operation of the one or more processors. This information may include instruction counts and / or any other information to indicate the point in the sampling interval and / or instruction sequence where each interrupt and / or other event occurs, so that the EVA can accurately simulate the execution of the instruction sequence.

[0050] In one embodiment, a counter (e.g., a performance counter provided by the processor) can be used by the PCM to count the number of instructions executed / retired during the sampling interval. Trace information may include interrupt traces (e.g., a list of interrupts occurring during the sampling interval, identified by their interrupt vectors) or other event traces, where each interrupt or event is annotated with an instruction count value to indicate the number of instructions executed / retired before the corresponding interrupt or event occurred or was delivered to the OSS (e.g., delivered by the PCM after the PCM intercepted the interrupt or event). Therefore, as the EVA emulates instructions, the EVA can count the instructions to accurately determine the instruction boundaries where interrupts or other events are emulated. In an embodiment, an interrupt trace may include a list of pairs, with an instruction count value as the first member and an interrupt vector as the second member.

[0051] In block 450, the EVA sends a third interrupt to the one or more processors to end the sampling interval. In various embodiments, other methods of terminating the sampling interval may be used. For example, the EVA may specify a particular time or condition (a specific physical memory location being accessed, a specific interrupt or other event being observed, etc.) for the PCM to begin the sampling interval there.

[0052] In block 452, the delivery of a third interrupt to the processor causes control of the processor (via VM exit) to be transferred to the PCM. In block 454, the PCM creates the final checkpoint by storing the state of certain registers or other storage locations (e.g., status register 212) in a third data structure in the trace information memory (or alternatively, storing only the state that differs from the state at the beginning of the sampling interval) using a save state instruction.

[0053] In box 460, EVA reads initial checkpoint information, tracking information, and / or final checkpoint information from the tracking information memory and uses it by any known means to check whether the one or more processors are operating during the sampling interval in accordance with the specifications of the correct and / or expected operation and / or behavior of the one or more processors.

[0054] In box 470, the system can continue to operate with or without the virtualized environment being maintained by PCM.

[0055] In various embodiments of the invention, various approaches are possible for collecting and verifying checkpoints and trace information. For example, EVA's simulation of the processor may include: using specified locations in the trace information memory for various processor registers; starting with the state recorded by the PCM at the initial checkpoint; simulating each instruction executed during the sampling interval (including loading and storing the trace information memory instead of the specified locations in the actual processor registers); and comparing the contents of the specified locations in the trace information memory with the state recorded by the PCM at the final checkpoint. Any mismatch will indicate a verification failure.

[0056] As another example, Figure 5 The illustration depicts a method 500 for verifying processor memory access according to an embodiment of the present invention. Method 500 may be used in connection with method 400 or any other method for initiating and ending a sampling interval according to an embodiment of the present invention; therefore, without further details, method 500 may refer to the initiation and end of a sampling interval.

[0057] In block 510 of method 500, the EVA signals the initiation of the sampling interval. In block 512, in connection with the initiation of the sampling interval, the PCM (e.g., using MMU 250) marks all pages in and / or accessible to the OSS as read-only. In block 514, the PCM transfers control to the OSS operating within a VM on one or more processors.

[0058] In box 520, OSS attempts to access the first page in memory that is marked as read-only. In box 522, the attempted access results in a page fault, VM exit, and a transfer of control back to PCM.

[0059] In block 530, the PCM records the address of the first page in the first entry of the memory trace data structure in the trace information memory. In block 532, the PCM stores a copy of the initial value / content of the first page (e.g., before any changes made by OSS during the sampling interval) in memory reserved for the PCM and inaccessible to OSS (e.g., the traced page memory 366), and / or associates the initial value / content with the first entry. In embodiments, the memory trace may include a list of pairs, with the address used by OSS to access the page (e.g., the passenger physical address of the page in OSS memory) as the first member of the pair and the corresponding address to which the PCM copies the page's value / content (e.g., the host physical address in the traced page memory) as the second member of the pair. Thus, both the page's value / copy and the address where EVA can access the value / copy are stored in the PCM memory, which can be accessed by EVA for simulation but not by OSS.

[0060] In box 534, the PCM marks the first page as read / write. In box 536, the PCM transfers control back to the OSS in the VM. Therefore, in box 538, the OSS continues to operate and can now modify (if desired, more than once) the value / content of the first page without causing another page failure, VM exit, or a transfer of control back to the PCM. Similarly, each first attempt by the OSS to modify a different page during the sampling interval could result in a page failure, VM exit, and / or a transfer of control back to the PCM to allow the PCM to record the address and initial value / content.

[0061] In block 540, the EVA signals the end of the sampling interval. In block 542, in relation to the end of the sampling interval, the PCM makes the memory trace data structure and the traced page available to the EVA.

[0062] In block 552, during the preparation for simulation, EVA logically partitions the OSS memory into groups of pages whose PCM is written into the traced page memory (and thus detected by EVA as being in the traced page memory) and groups of pages whose PCM is not written into the memory trace data structure (and thus not detected by EVA as being in the memory trace data structure) (e.g., untraced page 376). In block 554, EVA begins simulating the operation of one or more processors, including instructions executed during the sampling interval using the contents of the memory trace data structure and the traced pages.

[0063] In box 560, EVA determines whether the processor has performed a memory read access. If so, in box 562, EVA attempts to simulate the read. If, in box 564, EVA determines that the page is a tracked page, in box 566, EVA performs a read of a copy of the page's value / content from the tracked page's memory (this will reflect the page's initial value / content before EVA simulates any writes to the page). Instead, if, in box 564, EVA determines that the page is an untracked page, in box 568, EVA performs a read of the page directly from OSS memory.

[0064] In box 570, EVA determines whether the processor has performed a memory write access. If so, in box 572, EVA attempts to simulate the write. If, in box 574, EVA determines that the page is a traced page, in box 576, EVA performs a write operation to copy the value / content of the page in the traced page's memory. Instead, if, in box 574, EVA determines that the page is an untraceable page, EVA determines that the write operation indicates a verification failure and method 500 terminates in box 586.

[0065] In box 580, EVA determines whether the simulation of the sampling interval (or the instruction stream or all memory accesses) is complete. If not, EVA returns to box 564 to continue the simulation at least until all memory reads and writes have been simulated.

[0066] In box 582, after the simulation of the sampling interval is completed, EVA compares the value / content of each page in the traced page memory with the value / content of the corresponding page in the OSS memory. If EVA finds a mismatch between the value / content of the traced page in the OSS memory and the traced page memory in box 584, EVA determines that the verification has failed in box 586. Instead, if EVA finds that the values / content of all traced pages in the traced page memory match those in the OSS memory in box 584, EVA determines that the verification of the processor's memory access has passed in box 588.

[0067] In various embodiments of the present invention Figure 4 and 5 The method illustrated in the diagram can be performed in different orders, with illustrated boxes being combined or omitted, with additional boxes being added, or with reordered, combined, omitted, or added boxes being combined. For example, the sampling interval can begin or end based on a predetermined time, event, and / or duration rather than an interruption from the EVA. Furthermore, the method embodiments of the present invention are not limited to method 400, method 500, or variations thereof.

[0068] As an alternative to (or other than) page-based memory tracing of method 500, PCM can use a subpage policy (SPP) to provide more granular indication of when specific areas of a page are written and, consequently, when the emulation should be performed. For example, SPP can provide cache line granularity, which would correspond to the granularity of the memory tracing logic that intercepts the memory bus.

[0069] In various embodiments, performance counters and performance monitor interrupts can also be used to monitor TLB misses. For example, performance counter thresholds can be used to indicate when page browsing is in progress, enabling EVA to emulate pagination structure access, access / dirty bit assistance, etc.

[0070] In various embodiments, memory access to graphics and / or other devices can be monitored by restricting read / write access to trigger an interrupt that can be intercepted by the PCM.

[0071] Many other method embodiments (as well as apparatuses, systems, and other embodiments) not described herein are possible within the scope of this invention.

[0072] Various embodiments of the present invention may include a variety of techniques for monitoring the operation of multiple processors / cores (e.g., processor 110 and processor 160). In various embodiments, the EVA and / or PCM can monitor and / or verify each processor / core separately by having an OSS instruction stream executed by a first processor / core during a first sampling interval, or by having the same or different OSS instruction streams executed by a second processor / core during a second sampling interval, etc. For example, at the initiation of a sampling interval, the EVA can synchronize the processor / thread with an interrupt so that control of each processor is transferred to the PCM, or the PCM can synchronize the processor / thread with an inter-processor interrupt. Other processors / threads can be kept idle (e.g., in a low-power state) during each sampling interval.

[0073] Alternatively, in various embodiments, the PCM may cause a VM exit at a specific instruction boundary in the OSS instruction stream during the sampling interval (e.g., using performance counters to count the executed / retired instructions) to partition or partition the instruction stream into different threads between or within processors / cores, or partition or partition the instruction stream based on different threads between or within processors / cores, wherein the path defining the point where the instruction stream is to be partitioned and / or the portion of the instruction stream to be executed by each processor / core (a list of scheduling, threads, and instruction count pairs, etc.) is deterministic, determined by the EVA and pre-transmitted to the PCM, and / or determined by the PCM and subsequently transmitted to the EVA. Similarly, interrupts and other events involved in the monitoring may be associated with one or more processors / cores in the trace information based on deterministic, pre-planned, and / or pre- / post-interval communication techniques (e.g., which processor / core handles one or more lists of which interrupts / events). Therefore, initial checkpoints, final checkpoints, interrupt traces, memory traces, and any other desired trace information can be created for each processor / core during a single sampling interval, and these can be used by EVA to verify the operation of each processor during that single sampling interval.

[0074] Figure 6 An EVA 600 according to an embodiment of the present invention is illustrated. The EVA 600 may include hardware for simulating and / or verifying the operation of one or more processors (as described in or otherwise in method 400, method 500, or otherwise). For example, the EVA 600 may include: an interrupt generation circuit 610 for generating interrupts to initiate and / or terminate sampling intervals; an execution circuit 620 for simulating the execution of instructions by the processor; a memory read circuit 630 for performing reads from system memory; a memory write circuit 640 for performing writes to system memory; one or more comparator circuits 650 for performing comparisons (such as comparing simulated state information with state information provided by the PCM, comparing the value / content of a page in a memory trace data structure with a page in OSS memory); and control logic 660 for controlling the operation of the EVA 600.

[0075] As described above, embodiments or portions of the present invention can be stored on any form of machine-readable medium. For example, all or part of method 400 or 500 can be embodied in software or firmware instructions stored on a processor-readable medium, which, when executed by the processor, cause the processor to perform embodiments of the present invention. Furthermore, aspects of the present invention can be embodied in data stored on a machine-readable medium, wherein the data represents design or other information that can be used to manufacture all or part of the processor.

[0076] Therefore, embodiments of the invention for monitoring processor operation have been described. Although certain embodiments have been described and shown in the accompanying drawings, it should be understood that these embodiments are merely illustrative and not limiting of the broader invention, and the invention is not limited to the specific constructions and arrangements shown and described, as various other modifications will occur to those skilled in the art upon studying this disclosure. In such technical fields where rapid growth and further advancements are not easily foreseen, the disclosed embodiments can be readily modified in arrangement and detail, as facilitated by achieving technical improvements, without departing from the principles of this disclosure or the scope of the appended claims.

Claims

1. An apparatus for monitoring a processor, comprising: An external hardware agent is used to interrupt the processor, causing it to exit the virtual machine (VM) and initiate a sampling interval. During this interval, a software agent executed by the processor in root mode collects trace information used by the hardware agent to verify the processor's operation in non-root mode. The trace information will be stored in one or more of a number of memory areas that are accessible to the hardware but not to the virtual machine. The VM will run guest software in non-root mode and will be managed by the virtual machine monitor (VMM), while the VMM will run in root mode, in which the host software will directly control system resources.

2. The apparatus according to claim 1, wherein, The processor's operation in non-root mode includes the virtual machine executing a normal software stack.

3. The apparatus according to claim 2, wherein, The tracking information should include the initial checkpoint of the processor's state memory and the final checkpoint of the processor's state memory.

4. The apparatus according to claim 3, wherein, The hardware agent simulates the execution of the ordinary software stack by the processor from the initial state based on the initial checkpoint to the final state, and compares the final state with the final checkpoint.

5. The apparatus according to claim 4, wherein, The software agent records initial checkpoint information in relation to the initiation of the sampling interval and final checkpoint information in relation to the termination of the sampling interval.

6. The apparatus of claim 5, wherein the hardware agent further interrupts the processor to terminate the sampling interval.

7. A method for monitoring a processor, comprising: The standard software stack is executed by a virtual machine (VM). The processor is interrupted by a hardware proxy outside the processor, causing the processor to exit the VM and initiate a sampling interval; The execution of the normal software stack is monitored by a software agent during the sampling interval; The software agent stores the tracking information in the system memory; The sampling interval is terminated by a hardware-interrupted processor. and The processor's operation is verified by a hardware agent, where verification includes using trace information to compare the actual final state with the simulated final state.

8. The method of claim 7, wherein the software agent executes in the root mode of the processor.

9. The method of claim 8, further comprising storing a copy of the actual initial state by a software agent.

10. The method of claim 9, further comprising modifying a copy of the actual initial state by a hardware agent based on a simulation of the processor's execution of the ordinary software stack, to generate the final state of the simulation.

11. The method of claim 10, further comprising marking a plurality of memory regions as read-only in relation to the initiation of a sampling interval by the software agent, so as to cause a virtual machine to exit in relation to an attempt made by the ordinary software stack to modify a memory region among the plurality of memory regions.

12. The method of claim 11, further comprising the software agent adding the memory region to a list of tracked memory regions in response to the virtual machine exiting.

13. The method of claim 12, wherein the copy of the actual initial state includes a copy of the memory region prior to modification by a normal software stack executed on the virtual machine during the sampling interval.

14. A processor, comprising: The instruction decoder is used to decode the virtual machine (VM) entry instruction. The execution of the VM entry instruction causes the processor to enter non-root mode. In non-root mode, the client software will run on the VM hosted by the virtual machine monitor (VMM). The VMM will run in root mode, in which the host software will directly control system resources. The memory management unit is used to divide the system memory into multiple memory areas; The virtualization unit is used to provide the processor with the ability to intercept interrupts occurring in the VM and to cause the processor to exit the VM, where the interrupt originates from a hardware agent outside the processor, and will initiate a sampling interval; and The execution unit is used to execute the software agent in root mode to collect tracking information during the sampling interval.

15. The processor of claim 14, wherein the tracing information is stored in one or more of a plurality of memory areas accessible to the hardware agent but inaccessible to the VM.

16. The processor of claim 15, wherein the trace information is used by the hardware agent to verify the operation of the processor in the non-root mode.

17. The processor of claim 16, wherein operation of the processor in non-root mode includes execution of a normal software stack by a VM.

18. The processor of claim 17, wherein the processor further comprises a state store, and the tracking information includes an initial checkpoint of the state store and a final checkpoint of the state store.

19. The processor of claim 18, wherein the hardware agent simulates the execution of the ordinary software stack by the processor from an initial state based on the initial checkpoint to a final state, and compares the final state with the final checkpoint.

20. The processor of claim 19, wherein, The software agent records initial checkpoint information in relation to the initiation of the sampling interval and final checkpoint information in relation to the termination of the sampling interval.

21. The processor of claim 20, wherein the hardware agent further interrupts the processor to terminate the sampling interval.

22. An apparatus for monitoring a processor, comprising components for performing the method of any one of claims 7-13.

23. A computer-readable medium having instructions stored thereon that, when executed, cause a computing device to perform the method according to any one of claims 7-13.

Citation Information

Patent Citations

  • Random verification method and device for verifying processor chip after manufacturing

    CN101826050A

  • System and method for secure execution of program code

    US20060047958A1