Method for handling virtualized interrupts, interrupt controller, electronic device and chip
By virtualizing hardware resources and combining them with remapping technology, the problems of resource isolation and mutual interference in virtualization interrupt handling are solved, improving system performance and hardware utilization, and simplifying system management.
Patent Information
- Application Number
- CN202210933599.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-04
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2042-08-04
AI Technical Summary
In existing technologies, virtualization interrupt handling methods result in low hardware resource utilization, CPU performance loss, and high system management complexity, making it difficult to achieve resource isolation and non-interference between different virtual functions.
By virtualizing hardware resources, each interrupt source corresponds to different virtualized hardware resources, and access virtualization is achieved at the hardware level through remapping technology, ensuring that the target virtual function can only access the target address range, thus achieving resource isolation.
It improves system performance, reduces hardware resource consumption, lowers CPU load, enhances system security and resource utilization, and simplifies system management.
Smart Images

Figure CN115202827B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of computer, in particular to the technical field of interrupt control, and specifically to a method for processing virtualized interrupt, an interrupt controller, an electronic device, a medium and a chip. BACKGROUND
[0002] Virtualization technology is the basis of modern cloud computing application, which divides the whole hardware resource to make each part of hardware resource execute different computing tasks. Interrupt is an important part of modern computer system, which is an important means for CPU and external device to communicate and execute task scheduling. Virtualization of interrupt refers to reporting interrupt in mutually independent space, so as to ensure that the task scheduling between virtual functions (VF) will not be disturbed.
[0003] The methods described in this section can not be the methods previously conceived or used. Unless otherwise indicated, nothing in this section should be assumed to be prior art merely because it is included in this section. Similarly, nothing in this section should be assumed to have been admitted to the prior art by its inclusion in this section unless otherwise indicated. SUMMARY
[0004] The present disclosure provides a method for processing virtualized interrupt, an interrupt controller, an electronic device, a medium and a chip.
[0005] According to an aspect of the present disclosure, a method for processing virtualized interrupt is provided, the method is executed by an interrupt controller, and the method comprises: in response to receiving an interrupt signal from an interrupt source, determining a target virtualized hardware resource corresponding to the interrupt source in a plurality of virtualized hardware resources based on identification information contained in the interrupt signal, and sending the interrupt signal to a target virtual function indicated by the identification information by using the target virtualized hardware resource, wherein the plurality of virtualized hardware resources are obtained by virtualizing hardware resources for processing interrupt based on a number of virtual functions running on a physical machine, and the plurality of virtualized hardware resources correspond to the plurality of virtual functions one by one, and wherein the target virtual function is one of the plurality of virtual functions; and in response to receiving an access request sent by the target virtual function based on the interrupt signal, remapping a target address of at least one interrupt information requested by the access request based on the number of virtual functions, so that the target virtual function can only access an address segment corresponding to the target virtual function in the target address.
[0006] According to another aspect of the present disclosure, an interrupt controller is provided, comprising: a sending module configured to, in response to receiving an interrupt signal from an interrupt source, determine, based on identification information contained in the interrupt signal, a target virtualized hardware resource corresponding to the interrupt source among a plurality of virtualized hardware resources, and send the interrupt signal to a target virtual function indicated by the identification information using the target virtualized hardware resource, wherein the plurality of virtualized hardware resources are obtained by virtualizing hardware resources for processing interrupts based on a number of virtual functions running on a physical machine, and the plurality of virtualized hardware resources correspond one-to-one to the plurality of virtual functions, and wherein the target virtual function is one of the plurality of virtual functions; and a remapping module configured to, in response to receiving an access request sent by the target virtual function based on the interrupt signal, remap a target address of at least one interrupt information requested by the access request based on the number of virtual functions, so that the target virtual function can only access an address segment corresponding to the target virtual function in the target address.
[0007] According to another aspect of the present disclosure, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform a method for processing virtualized interrupts.
[0008] According to another aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to cause a computer to perform a method for processing virtualized interrupts.
[0009] According to another aspect of the present disclosure, a computer program product is provided, comprising a computer program, wherein the computer program, when executed by a processor, implements a method for processing virtualized interrupts.
[0010] According to another aspect of the present disclosure, a chip is provided, comprising an interrupt controller as described above.
[0011] According to one or more embodiments of the present disclosure, a method for processing virtualized interrupts is provided, which sends an interrupt signal by means of virtualizing hardware resources in such a way that there is a corresponding virtualized hardware resource for each interrupt source, different interrupt sources correspond to different virtualized hardware resources, and resource isolation is achieved so that interrupt signals between different interrupt sources do not interfere with each other. At the same time, for an access request from a target virtual function, access virtualization at the hardware level is achieved by remapping, and resource isolation is also achieved on the downlink path from a virtual function to an interrupt controller.
[0012] It is to be understood that the details set forth herein do not limit the scope of the embodiments of the present disclosure but merely constitute illustrative examples of how the embodiments can be BRIEF DESCRIPTION OF DRAWINGS
[0013] The accompanying drawings illustrate exemplary embodiments of the present disclosure and constitute a part of the specification. The drawings together with the description of the specification serve to explain exemplary embodiments of the present disclosure. The illustrated embodiments are merely examples and do not limit the scope of the claims. In all the drawings, like reference numerals refer to like elements throughout the specification.
[0014] Figure 1 A flow diagram illustrating a method of processing virtualized interrupts according to an embodiment of the present disclosure is shown;
[0015] Figure 2 A flow diagram illustrating bit-level remapping according to an embodiment of the present disclosure is shown;
[0016] Figure 3 A flow diagram illustrating address-level remapping according to an embodiment of the present disclosure is shown;
[0017] Figure 4 A structural block diagram of an interrupt controller according to an embodiment of the present disclosure is shown;
[0018] Figure 5 A structural block diagram of a bit-level remapping unit according to an embodiment of the present disclosure is shown;
[0019] Figure 6 A structural block diagram of an address-level remapping unit according to an embodiment of the present disclosure is shown; and
[0020] Figure 7 A structural block diagram of an exemplary electronic device that can be used to implement an embodiment of the present disclosure is shown. DETAILED DESCRIPTION
[0021] Exemplary embodiments of the present disclosure are described herein with reference to the accompanying drawings, which are incorporated in and constitute a part of this specification, wherein various details of the embodiments of the present disclosure are set forth in order to assist in understanding the claimed disclosure. It will be appreciated that the embodiments described herein are merely exemplary and that a person of ordinary skill in the art will be able to make various changes and modifications without departing from the scope of the present disclosure. Also, descriptions of well-known functions and constructions are omitted in order to make the present disclosure more clear and concise.
[0022] In the present disclosure, the terms "first", "second", etc. used in the description of various described examples are not intended to limit the positional relationship, timing relationship or importance relationship of the elements, and such terms are only used to distinguish one element from another. In some examples, the first element and the second element can refer to the same instance of the element, and in some cases, based on the context of the description, they can also refer to different instances.
[0023] The terms used in the description of various described examples in the present disclosure are only for the purpose of describing the specific examples, and are not intended to be limiting. Unless the context clearly indicates otherwise, if the number of elements is not specifically limited, the element can be one or more. In addition, the term "and / or" used in the present disclosure encompasses any one of the listed items and all possible combinations.
[0024] In related technologies, the virtualization of multi-user interrupts is mainly achieved through full virtualization and semi-virtualization. However, in full virtualization, a hypervisor implemented by a software layer is needed to coordinate and schedule the underlying hardware. As a medium for software and hardware interaction, the hypervisor is responsible for translating and optimizing instructions. When the system enables virtualization, handling multi-user interrupts requires frequent intervention of the hypervisor, which consumes certain hardware resources to capture and process interrupts. This way of software virtualization of multi-user interrupts limits system performance and reduces hardware utilization.
[0025] In the process of handling interrupts based on full virtualization, the interrupt controller is responsible for collecting interrupt resources of various parts of the hardware system and sending an interrupt request to a peripheral component interconnect express (PCIe) controller. Further, the PCIe controller 102 sends a physical interrupt to the CPU. The hypervisor layer needs to pre-set the division of hardware resources of the system, capture the physical interrupt PF, and determine which VF the interrupt PF belongs to, and further drive the mapping of the physical interrupt PF to the virtual interrupt corresponding to the VF. When a physical interrupt is reported each time, the hypervisor needs to perform routing and allocation of the physical interrupt.
[0026] When the VF receives the interrupt request, it needs to interact with the interrupt controller downward, access the registers inside the interrupt controller, and determine the interrupt source and the corresponding interrupt transaction. The access of the VF to a certain physical address in the system on chip needs to be translated by the Hypervisor. Therefore, the Hypervisor needs to act as a medium in the reporting of the hardware part of the interrupt and the downward interaction of the VF when accessing the interrupt controller. This increases the hardware overhead of the CPU, and compared with the direct physical interrupt, it will lose part of the performance. And the more VFs running on the physical machine, the more obvious the speed of interrupt processing will decrease.
[0027] Semi-virtualization is based on full virtualization, and different VFs use different interrupt numbers, so that the interrupt numbers corresponding to different VFs can be distinguished from each other, and the interrupt signal can be directly transmitted to the corresponding VF without routing through the Hypervisor when the interrupt signal goes up. When the VF interacts with the device hardware downward, the driver can be modified to directly access the corresponding physical address, and the Hypervisor also avoids acting as an address translator. This releases a considerable amount of hardware resources, and the work burden of the Hypervisor is smaller, which is conducive to the improvement of system performance. However, semi-virtualization needs to be highly customized for the system kernel and the driver, and the virtual machine often needs to use multiple sets of drivers. When the number of VFs or the division scheme of hardware resources is changed, the kernel and the driver often need to be changed again, and the complexity of system management and maintenance is high. For different platforms, its universality and portability are also low.
[0028] To solve the above problems, the present disclosure provides a method for processing virtualized interrupts, which virtualizes hardware resources in such a way that there is a corresponding virtualized hardware resource for each interrupt source to send an interrupt signal. Different interrupt sources correspond to different virtualized hardware resources, which realizes the isolation of resources and makes the interrupt signals between different interrupt sources not interfere with each other. At the same time, for the access request from the virtual function, the access virtualization at the hardware level is realized by remapping, and the isolation of resources is also completed on the downward path from the virtual function to the interrupt controller.
[0029] The exemplary embodiments of the present disclosure will be described in detail below.
[0030] Figure 1 A flowchart of a method for processing virtualized interrupts according to an embodiment of the present disclosure is shown, which is performed by an interrupt controller. As shown in FIG. 1, the method comprises the following steps. Figure 1As shown, the method 100 for handling virtualization interrupts includes: step S101, in response to receiving an interrupt signal from an interrupt source, determining a target virtualized hardware resource corresponding to the interrupt source among a plurality of virtualized hardware resources based on the identification information contained in the interrupt signal, and using the target virtualized hardware resource to send the interrupt signal to the target virtual function indicated by the identification information, wherein the plurality of virtualized hardware resources are obtained by virtualizing the hardware resources for handling interrupts based on the number of a plurality of virtual functions running on the physical machine, and the plurality of virtualized hardware resources correspond one-to-one with the plurality of virtual functions, and wherein the target virtual function is one of the plurality of virtual functions; and step S102, in response to receiving an access request sent by the target virtual function based on the interrupt signal, remapping the target address where at least one interrupt information requested by the access request is located based on the number of the plurality of virtual functions, so that the target virtual function can only access the address segment corresponding to the target virtual function in the target address.
[0031] Therefore, by virtualizing hardware resources in step S101, each interrupt source has corresponding virtualized hardware resources to send its interrupt signal. Based on the identification information contained in the interrupt signal, the interrupt signal is sent to the corresponding virtual function among multiple virtual functions, i.e., the target virtual function. Different interrupt sources correspond to different virtualized hardware resources, achieving resource isolation and preventing interrupt signals from different interrupt sources from interfering with each other. Simultaneously, when the target virtual function responds to the interrupt signal sent by the interrupt controller and sends an interrupt request to the interrupt controller, the remapping in step S102 achieves hardware-level access virtualization, ensuring that the target virtual function can only access the address segment corresponding to the target virtual function in the target address. Resource isolation is also achieved on the downlink path from the virtual function to the interrupt controller. Thus, resource isolation is achieved on both the uplink path where the interrupt source accesses the virtual function through the interrupt controller and the downlink path where the virtual function accesses the registers in the interrupt controller to query the interrupt source.
[0032] For example, in step S102, the interrupt controller can determine that the access request comes from a target virtual function based on the user information contained in the received access request, wherein the user information is used to indicate the identity information of the virtual function, specifically, to indicate which virtual function among a plurality of virtual functions the access request comes from.
[0033] According to some embodiments, step S102 comprises: in response to receiving the access request sent by the target virtual function based on the interrupt signal, and the at least one interrupt information comprising first interrupt information stored inside the first physical register, performing bit-level remapping on the first physical register based on the number of the plurality of virtual functions, so that the target virtual function can only access the corresponding bit position of the target virtual function in the first physical register; and / or in response to receiving the access request sent by the target virtual function based on the interrupt signal, and the at least one interrupt information comprising second interrupt information stored on a continuous address across a first plurality of second physical registers, performing address-level remapping on the continuous address based on the number of the plurality of virtual functions, so that the target virtual function can only access the corresponding second plurality of second physical registers of the target virtual function in the continuous address.
[0034] It can be understood that, according to the location of the target address of the at least one interrupt information requested by the target virtual function, the corresponding remapping method can be determined respectively. Specifically, when the first interrupt information requested by the target virtual function is located inside the register, bit-level remapping needs to be performed accordingly to ensure resource isolation at the bit level in the process of the virtual function accessing the register of the interrupt controller; when the second interrupt information requested by the target virtual function is stored on a continuous address across a first plurality of second physical registers, address-level remapping needs to be performed accordingly to ensure resource isolation at the address level in the process of the virtual function accessing a longer address segment of the interrupt controller.
[0035] Figure 2 A flowchart of bit-level remapping according to an embodiment of the present disclosure is shown. As shown in FIG. 2, the bit-level remapping 200 comprises: step S201, in response to the at least one interrupt information comprising first interrupt information stored inside the first physical register, virtualizing the first physical register based on the number of the plurality of virtual functions to obtain a plurality of first virtualized registers corresponding to the plurality of virtual functions one-to-one; step S202, determining the number of bit positions corresponding to each virtual function in its corresponding first virtualized register as n based on the number of the plurality of virtual functions and the number of bit positions of the first interrupt information in the first physical register, wherein n is an integer greater than or equal to 1; and step S203, only allowing the target virtual function to read and write the first n bit positions of the first virtualized register corresponding to the virtual function. Figure 2
[0036] For ease of understanding, the flow of bit-level remapping will be described below with an example.
[0037] In one example, the first interrupt information related to the interrupt signal is stored in the low 6 bits, i.e. bit 0~bit 5, of the first physical register, and meanwhile, 3 VFs, i.e. VF0, VF1 and VF2, are running on the physical machine. Based on the user information contained in the received access request, it is determined that the access request comes from the target virtual function VF1. At this time, step S201 is performed to virtualize the first physical register to obtain 3 first virtualized registers corresponding to the 3 VFs. Step S201 is performed to determine, based on the 3 VFs and the 6-bit first interrupt information, that each VF corresponds to 2 bit positions in the first virtualized register corresponding to the VF. Step S203 is performed to allow only VF1 to access the first 2 bit positions of the first virtualized register corresponding to VF1. It can be understood that the 2 bit positions accessible by VF1 correspond to bit 2 and bit 3 in the first physical register. Thus, the isolation of the interrupt resource is achieved.
[0038] For example, the first interrupt information related to the interrupt signal can be the state information of the interrupt signal recorded by the interrupt status register, and accordingly, the first physical register is the interrupt status register.
[0039] According to some embodiments, the starting address of the first n bit positions of the corresponding first virtualized register accessible by the target virtual function is the same as the starting address of the first physical register. It can be seen that the access addresses of each VF when accessing the corresponding first virtualized register are the same. Thus, on the basis of achieving the isolation of the interrupt resource, the consistency of register access among multiple VFs is also maintained.
[0040] According to some embodiments, the method 100 of processing a virtualized interrupt further comprises: in response to the target virtual function performing a write operation on the first n bit positions of the corresponding first virtualized register, writing the data written in the first n bit positions of the first virtualized register into the corresponding bit positions of the first physical register corresponding to the target virtual function
[0041] In the process of virtualizing the first physical register to obtain a plurality of first virtualized registers in step S201, the content in the bit positions of the first physical register corresponding to each VF is simultaneously stored in the corresponding bit positions of the first virtualized register corresponding to the VF. Accordingly, after VF1 performs a write operation on the first virtualized register, step S203 is performed to write the data written in the corresponding first virtualized register by VF1 into the bit positions of the first physical register corresponding to VF1, so as to realize the bidirectional mapping between the first physical register and the plurality of first virtualized registers.
[0042] Figure 3 A flowchart of address-level remapping according to an embodiment of the present disclosure is shown. As shown in FIG. 2, the method comprises the following steps.Figure 3 As shown, the address-level remapping 300 comprises: step S301, in response to the second interrupt information stored in the continuous addresses across the first plurality of second physical registers included in the at least one interrupt information, virtualizing the continuous addresses based on the number of the plurality of virtual functions to obtain a plurality of virtualized continuous addresses corresponding to the plurality of virtual functions one-to-one; step S302, determining, based on the number of the plurality of virtual functions, a second plurality of second virtualized registers corresponding to each virtual function in the virtualized continuous address corresponding to the virtual function; and step S303, allowing only the target virtual function to perform read and write operations on the second plurality of second virtualized registers corresponding to the target virtual function.
[0043] Corresponding to the bit-level remapping, the flow of the address-level remapping will be described below with an example.
[0044] In one example, the second interrupt information related to the interrupt signal is stored in the continuous addresses 0x0000-0x0014 across 6 32-bit second physical registers, while 3 VFs, namely VF0, VF1 and VF2, are running on the physical machine. It is determined based on the user information included in the received access request that the access request comes from the target virtual function VF1. At this time, step S301 is performed to virtualize the continuous addresses to obtain 3 virtualized continuous addresses corresponding to the 3 VFs one-to-one. Step S302 is performed to determine, based on the 3 VFs, 2 second virtualized registers corresponding to each VF in the virtualized continuous address corresponding to the VF. Step S303 is performed to allow only VF1 to access the 2 second virtualized registers corresponding to VF1. It can be understood that the 2 second virtualized registers accessible by VF1 correspond to addresses 0x0008-0x000C in the continuous addresses. Thus, the isolation of the interrupt resources is achieved.
[0045] Exemplarily, the second interrupt information related to the interrupt signal may, for example, be configuration information of the interrupt signal, and accordingly, the second physical registers are configuration registers.
[0046] According to some embodiments, the starting address of the second plurality of second virtualized registers accessible by the target virtual function is the same as the starting address of the continuous addresses. Thus, on the basis of achieving the isolation of the interrupt resources, the consistency of the register access among the plurality of VFs is also maintained.
[0047] According to some embodiments, the method 100 of processing virtualized interrupts further comprises: in response to the target virtual function performing a write operation on the second plurality of second virtualized registers corresponding to the target virtual function, writing the data written in the second plurality of second virtualized registers into the second plurality of second physical registers corresponding to the target virtual function in the continuous addresses.
[0048] Accordingly, after VF1 writes the second plurality of second virtualized registers, step S303 is performed to write the data written by VF1 in the corresponding second plurality of second virtualized registers into the corresponding second plurality of second physical registers in the contiguous addresses, thereby achieving the bidirectional mapping between the contiguous addresses and the plurality of virtualized contiguous addresses.
[0049] According to another aspect of the present disclosure, an interrupt controller is provided. As shown in Figure 4 The interrupt controller 400 includes a sending module 401 configured to, in response to receiving an interrupt signal from an interrupt source, determine a target virtualized hardware resource corresponding to the interrupt source among a plurality of virtualized hardware resources based on identification information contained in the interrupt signal, and send the interrupt signal to a target virtual function indicated by the identification information by using the target virtualized hardware resource, wherein the plurality of virtualized hardware resources are obtained by virtualizing hardware resources for processing interrupts based on a number of virtual functions running on a physical machine, and the plurality of virtualized hardware resources correspond to the plurality of virtual functions one-to-one, and wherein the target virtual function is one of the plurality of virtual functions; and a remapping module 402 configured to, in response to receiving an access request sent by the target virtual function based on the interrupt signal, remap a target address where at least one interrupt information requested by the access request is located based on the number of virtual functions, so that the target virtual function can only access an address segment corresponding to the target virtual function in the target address.
[0050] The sending module 401 virtualizes the hardware resources in such a way that there is a corresponding virtualized hardware resource for each interrupt source to send an interrupt signal, and sends the interrupt signal to a virtual function corresponding thereto among the plurality of virtual functions, i.e., a target virtual function, based on the identification information contained in the interrupt signal. Different interrupt sources correspond to different virtualized hardware resources, which achieves isolation of resources and makes the interrupt signals between different interrupt sources not interfere with each other.
[0051] For example, the sending module 401 virtualizes the hardware resources for processing interrupts according to a hardware division scheme of the system as a whole during virtualization. Specifically, the sending module 401 virtualizes the interrupt processing module based on the number of virtual functions VF running on the physical machine to virtually obtain hardware resources corresponding to the VFs one-to-one, and sends an interrupt signal accessing a corresponding virtual function by using the corresponding virtualized hardware resource.
[0052] In one example, when there are 3 VFs running on the physical machine, the sending module 401 virtualizes the hardware resources to divide the hardware resources into 3 virtualized hardware resources for processing the interrupt signals corresponding to the 3 VFs respectively. Thus, the interrupt signals from the interrupt sources are bound to the corresponding hardware. The interrupt resources corresponding to different VFs are strictly protected and isolated by the hardware, so that the interrupts among the multiple VFs do not interfere with each other.
[0053] Exemplarily, each virtualized hardware resource can implement interrupt enable, interrupt mask and interrupt mapping for the corresponding virtual signals, to realize one-to-one separate control, so that the interrupt signals corresponding to different VFs can issue requests to the PCIe controller through different channels in the interrupt controller 400 and finally reach the corresponding VFs. Thus, the isolation and protection of the interrupt resources are realized, and the security of the system is improved.
[0054] Meanwhile, when the target virtual function sends an interrupt request to the interrupt controller in response to the interrupt signal sent by the interrupt controller, the access virtualization at the hardware level is realized through the remapping module 402, so that the target virtual function can only access the address segment corresponding to the target virtual function in the target address, and the isolation of the resources is also completed on the downlink path from the virtual function to the interrupt controller. Thus, the isolation of the resources is realized on both the uplink path where the interrupt sources access the virtual functions through the interrupt controller and the downlink path where the virtual functions access the registers in the interrupt controller to query the interrupt sources.
[0055] Exemplarily, the remapping module 402 can determine that the access request comes from the target virtual function based on user information contained in the received access request, where the user information is used to indicate the identity information of the virtual function, and specifically, is used to indicate which virtual function in the multiple virtual functions the access request comes from.
[0056] According to some embodiments, the remapping module 402 comprises: a bit-level remapping unit configured to, in response to receiving an access request sent by the target virtual function based on the interrupt signal, and the at least one interrupt information comprising first interrupt information stored inside a first physical register, perform bit-level remapping on the first physical register based on the number of the plurality of virtual functions, so that the target virtual function can only access corresponding bit positions of the target virtual function in the first physical register; and / or an address-level remapping unit configured to, in response to receiving an access request sent by the target virtual function based on the interrupt signal, and the at least one interrupt information comprising second interrupt information stored at consecutive addresses across a first plurality of second physical registers, perform address-level remapping on the consecutive addresses based on the number of the plurality of virtual functions, so that the target virtual function can only access a second plurality of second physical registers corresponding to the target virtual function in the consecutive addresses.
[0057] For example, when the target virtual function VF1 receives an interrupt request, it needs to interact with the interrupt controller 400 to carry user identity information, i.e., user ID, to access the registers inside the interrupt controller 400 to determine the interrupt source and the corresponding interrupt transaction. When the first interrupt information related to the interrupt signal is stored inside the first physical register, the bit-level remapping unit needs to perform bit-level remapping on the first physical register based on the number of VFs running on the physical machine, so that the target virtual function VF1 can only access corresponding bit positions of VF1 in the first physical register. When the second interrupt information related to the interrupt signal is stored at consecutive addresses across a first plurality of second physical registers, the consecutive addresses are remapped at the address level based on the number of VFs running on the physical machine, so that the target virtual function VF1 can only access a second plurality of second physical registers corresponding to VF1 in the consecutive addresses. Thus, the interrupt resources are strictly protected and isolated by hardware, improving the security of the system.
[0058] Figure 5 A structural block diagram of a bit-level remapping unit according to an embodiment of the present disclosure is shown. As shown in the figure, the bit-level remapping unit comprises a plurality of registers 4021, a plurality of multiplexers 4022, and a plurality of selectors 4023. Figure 5As shown, the bit-level remapping unit 500 comprises: a first virtualization subunit 501 configured to, in response to the first interrupt information stored in the interior of the first physical register being included in the at least one interrupt information, virtualize the first physical register based on the number of the plurality of virtual functions to obtain a plurality of first virtualization registers corresponding to the plurality of virtual functions one by one; a first determination subunit 502 configured to determine, based on the number of the plurality of virtual functions and the number of bit positions of the first interrupt information in the first physical register, the number of bit positions corresponding to each virtual function in the first virtualization register corresponding to the virtual function to be n, where n is an integer greater than or equal to 1; and a first access subunit 503 configured to allow only the target virtual function to read and write the first n bit positions of the first virtualization register corresponding to the virtual function.
[0059] For ease of understanding, the subunits in the bit-level remapping unit 500 will be described below with an example.
[0060] In an example, the first interrupt information related to the interrupt signal is stored in the low 6 bit positions, i.e., bit 0-bit 5, of the first physical register, and meanwhile, 3 VFs, i.e., VF0, VF1 and VF2, are running on the physical machine. Based on the user information contained in the received access request, it is determined that the access request comes from the target virtual function VF1. At this time, the first virtualization subunit 501 is configured to virtualize the first physical register to obtain 3 first virtualization registers corresponding to the 3 VFs one by one. The first determination subunit 502 is configured to determine, based on the 3 VFs and the first interrupt information of 6 bit positions, that each VF corresponds to 2 bit positions in the first virtualization register corresponding to the VF. The first access subunit 503 is configured to allow only VF1 to access the first 2 bit positions of the first virtualization register corresponding to VF1. It can be understood that the 2 bit positions accessible by VF1 correspond to bit 2 and bit 3 in the first physical register. Thus, the isolation of the interrupt resource is achieved.
[0061] For example, the first interrupt information related to the interrupt signal can be the state information of the interrupt signal recorded by the interrupt status register, and accordingly, the first physical register is the interrupt status register.
[0062] According to some embodiments, the starting address of the first n bit positions of the corresponding first virtualization register accessible by the target virtual function is the same as the starting address of the first physical register. It can be seen that the access addresses of each VF when accessing the corresponding first virtualization register are the same. Thus, on the basis of achieving the isolation of the interrupt resource, the consistency of the register access among the plurality of VFs is also maintained.
[0063] According to some embodiments, the interrupt controller 400 further comprises: a first writing module configured to, in response to the target virtual function performing a write operation on the first n bits of the corresponding first virtualized register, write the data written in the first n bits of the corresponding first virtualized register into the corresponding bits of the first physical register of the target virtual function.
[0064] In the process of virtualizing the first physical register to obtain the plurality of first virtualized registers by the first virtualization subunit 501, the content in the corresponding bits of the first physical register of each VF is simultaneously stored in the corresponding bits of the first virtualized register corresponding to the VF. Accordingly, after VF1 performs a write operation on the first virtualized register, the first writing module needs to write the data written in the corresponding first virtualized register of VF1 into the corresponding bits of the first physical register of VF1, thereby realizing the bidirectional mapping between the first physical register and the plurality of first virtualized registers.
[0065] Figure 6 A structural block diagram of an address-level remapping unit according to an embodiment of the present disclosure is shown. As shown in Figure 6 The address-level remapping unit 600 comprises: a second virtualization subunit 601 configured to, in response to the second interrupt information stored on the continuous addresses across the first plurality of second physical registers being included in the at least one interrupt information, virtualize the continuous addresses based on the number of the plurality of virtual functions to obtain a plurality of virtualized continuous addresses corresponding to the plurality of virtual functions one by one; a second determination subunit 602 configured to determine, based on the number of the plurality of virtual functions, the second plurality of second virtualized registers corresponding to each virtual function in the corresponding virtualized continuous address of the virtual function; and a second access subunit 603 configured to only allow the target virtual function to perform read and write operations on the second plurality of second virtualized registers corresponding to the target virtual function.
[0066] Corresponding to the bit-level remapping module, the units in the address-level remapping unit 600 will be described below with an example.
[0067] In one example, the second interrupt information related to the interrupt signal is stored in the continuous address 0x0000-0x0014 across 6 32-bit second physical registers, while 3 VFs, VF0, VF1 and VF2, are running on the physical machine. Based on the user information contained in the received access request, it is determined that the access request comes from the target virtual function VF1. At this time, the second virtualization subunit 601 is configured to virtualize the continuous address to obtain 3 virtualized continuous addresses corresponding to the 3 VFs. The second determination subunit 602 is configured to determine, based on the 3 VFs, that each VF corresponds to 2 second virtualization registers in the virtualized continuous address corresponding to the VF. The second access subunit 603 is configured to only allow VF1 to access the 2 second virtualization registers corresponding to VF1. It can be understood that the 2 second virtualization registers accessible by VF1 correspond to the addresses 0x0008-0x000C in the continuous address. Thus, the isolation of the interrupt resource is achieved.
[0068] For example, the second interrupt information related to the interrupt signal can be configuration information of the interrupt signal, and accordingly, the second physical registers are configuration registers.
[0069] According to some embodiments, the starting address of the second plurality of second virtualization registers accessible by the target virtual function is the same as the starting address of the continuous address. Thus, on the basis of achieving the isolation of the interrupt resource, the consistency of the register access among multiple VFs is also maintained.
[0070] According to some embodiments, the interrupt controller 400 further comprises a second writing module configured to, in response to the target virtual function performing a write operation on the second plurality of second virtualization registers corresponding to the target virtual function, write the data written in the second plurality of second virtualization registers into the second plurality of second physical registers corresponding to the target virtual function in the continuous address.
[0071] Accordingly, after VF1 performs a write operation on the second plurality of second virtualization registers, the second writing module needs to write the data written by VF1 in the corresponding second plurality of second virtualization registers into the second plurality of second physical registers corresponding to VF1 in the continuous address, thereby achieving the bidirectional mapping between the continuous address and the plurality of virtualized continuous addresses.
[0072] According to another aspect of the present disclosure, an electronic device is also provided, comprising at least one processor, and a memory connected with the at least one processor in communication; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method of processing virtualized interrupts.
[0073] According to another aspect of this disclosure, a non-transitory computer-readable storage medium storing computer instructions is also provided, wherein the computer instructions are used to cause the computer to perform a method for processing virtualization interrupts.
[0074] According to another aspect of this disclosure, a computer program product is also provided, including a computer program, wherein the computer program, when executed by a processor, implements a method for handling virtualization interrupts.
[0075] According to another aspect of this disclosure, a chip is also provided, including the interrupt controller as described above.
[0076] like Figure 7 As shown, the electronic device 700 includes a computing unit 701, which can perform various appropriate actions and processes based on a computer program stored in a read-only memory (ROM) 702 or a computer program loaded from a storage unit 708 into a random access memory (RAM) 703. The RAM 703 may also store various programs and data required for the operation of the electronic device 700. The computing unit 701, ROM 702, and RAM 703 are interconnected via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.
[0077] Multiple components in electronic device 700 are connected to I / O interface 705, including: input unit 706, output unit 707, storage unit 708, and communication unit 709. Input unit 706 can be any type of device capable of inputting information to electronic device 700. Input unit 706 can receive input digital or character information and generate key signal input related to user settings and / or function control of electronic device, and may include, but is not limited to, a mouse, keyboard, touch screen, trackpad, trackball, joystick, microphone, and / or remote control. Output unit 707 can be any type of device capable of presenting information, and may include, but is not limited to, a monitor, speaker, video / audio output terminal, vibrator, and / or printer. Storage unit 708 may include, but is not limited to, disk and optical disk. Communication unit 709 allows electronic device 700 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks, and may include, but is not limited to, modems, network cards, infrared communication devices, wireless communication transceivers, and / or chipsets, such as Bluetooth. TM Devices, 802.11 devices, WiFi devices, WiMax devices, cellular communication devices and / or the like.
[0078] The computing unit 701 can be various general and / or special purpose processing components with processing and computing capabilities. Some examples of the computing unit 701 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 701 performs various methods and processes described above, such as the method of processing virtualized interrupts. For example, in some embodiments, the method of processing virtualized interrupts can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 708. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 700 via the ROM 702 and / or the communication unit 709. When the computer program is loaded onto the RAM 703 and executed by the computing unit 701, one or more steps of the method of processing virtualized interrupts described above can be performed. Alternatively, in other embodiments, the computing unit 701 can be configured to perform the method of processing virtualized interrupts by any other suitable means, such as by means of firmware.
[0079] Various implementations of the systems and techniques described above can be realized in digital electronic circuitry, integrated circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on a chip (SOC), a complex programmable logic device (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.
[0080] Program code for carrying out methods of the present disclosure can be written in any combination of one or more programming languages. The program code can be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the program code, when executed by the processor or controller, produces a means for implementing the functions / acts specified in the flowcharts and / or block diagrams. The program code can be executed entirely on a machine, partially on a machine, partially on a machine as a stand-alone software package, partially on a machine and partially on a remote machine or entirely on a remote machine or server.
[0081] In the context of this disclosure, a machine-readable medium can be a tangible medium that contains or stores a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include but is not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0082] To provide for interaction with a user, the systems and techniques described here can be implemented on a computer having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.
[0083] The systems and techniques described here can be implemented in a computing system that includes a back end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front end component (e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.
[0084] The computer system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. The server can be a cloud server, a server of a distributed system, or a server combined with a blockchain.
[0085] It should be understood that the various forms of flow illustrated above can be used to reorder, add, or delete steps. For example, the steps recited in the present disclosure can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technology disclosed in the present disclosure can be achieved, which is not limited herein.
[0086] While embodiments or examples of the present disclosure have been described with reference to the drawings, it should be understood that the above-described methods, systems, and devices are merely exemplary embodiments or examples, and the scope of the present disclosure is not limited by these embodiments or examples, but is only limited by the claims and their equivalents. Various elements in the embodiments or examples can be omitted or replaced by equivalent elements thereof. In addition, each step can be performed in an order different from that described in the present disclosure. Further, various elements in the embodiments or examples can be combined in various ways. It is important that many of the elements described herein can be replaced by equivalent elements that appear after the present disclosure as technology evolves.
Claims
1. A method for processing virtualized interrupts, the method being performed by an interrupt controller, the method comprising: in response to receiving an interrupt signal from an interrupt source, determining, based on identification information contained in the interrupt signal, a target virtualized hardware resource corresponding to the interrupt source among a plurality of virtualized hardware resources, and sending the interrupt signal to a target virtual function indicated by the identification information using the target virtualized hardware resource, wherein the plurality of virtualized hardware resources are obtained by virtualizing hardware resources for processing interrupts based on a number of virtual functions running on a physical machine, and the plurality of virtualized hardware resources correspond to the plurality of virtual functions one-to-one, and wherein the target virtual function is one of the plurality of virtual functions; and in response to receiving an access request sent by the target virtual function based on the interrupt signal, remapping a target address of at least one interrupt information requested by the access request based on the number of the plurality of virtual functions, so that the target virtual function can only access an address segment corresponding to the target virtual function in the target address. The response to receiving an access request sent by the target virtual function based on the interrupt signal, and the at least one interrupt information including first interrupt information stored inside a first physical register, remapping the first physical register at a bit level based on the number of the plurality of virtual functions, so that the target virtual function can only access a bit corresponding to the target virtual function in the first physical register, and / or the response to receiving an access request sent by the target virtual function based on the interrupt signal, and the at least one interrupt information including second interrupt information stored on a continuous address across a first plurality of second physical registers, remapping the continuous address at an address level based on the number of the plurality of virtual functions, so that the target virtual function can only access a second plurality of second physical registers corresponding to the target virtual function in the continuous address. The response to receiving an access request sent by the target virtual function based on the interrupt signal, and the at least one interrupt information including first interrupt information stored inside a first physical register, remapping the first physical register at a bit level based on the number of the plurality of virtual functions, so that the target virtual function can only access a bit corresponding to the target virtual function in the first physical register, comprises:
2. The method of claim 1, wherein, 3. The method of claim 2, wherein, in response to the first interrupt information being included in the at least one interrupt information and being stored in the first physical register, virtualizing the first physical register based on the number of the plurality of virtual functions to obtain a plurality of first virtualized registers corresponding to the plurality of virtual functions one-to-one; determining, based on the number of the plurality of virtual functions and the number of bit positions of the first interrupt information in the first physical register, that a number of bit positions corresponding to each virtual function in its corresponding first virtualized register is n, where n is an integer greater than or equal to 1; and only allowing the target virtual function to perform read and write operations on the first n bit positions of the corresponding first virtualized register of the target virtual function.
4. The method of claim 3, wherein, The starting address of the first n bit positions of the corresponding first virtualized register accessible by the target virtual function is the same as the starting address of the first physical register.
5. The method of claim 4, further comprising: in response to the target virtual function performing a write operation on the first n bit positions of the corresponding first virtualized register, writing data written in the first n bit positions of the corresponding first virtualized register into the corresponding bit positions of the target virtual function in the first physical register.
6. The method of any one of claims 2-5, wherein, in response to receiving an access request sent by the target virtual function based on the interrupt signal and the second interrupt information being included in the at least one interrupt information and being stored across consecutive addresses of a first plurality of second physical registers, performing address-level remapping on the consecutive addresses based on the number of the plurality of virtual functions, such that the target virtual function can only access a second plurality of second physical registers corresponding to the target virtual function in the consecutive addresses comprising: in response to the second interrupt information being included in the at least one interrupt information and being stored across consecutive addresses of a first plurality of second physical registers, virtualizing the consecutive addresses based on the number of the plurality of virtual functions to obtain a plurality of virtualized consecutive addresses corresponding to the plurality of virtual functions one-to-one; determining, based on the number of the plurality of virtual functions, that a second plurality of second virtualized registers corresponding to each virtual function in its corresponding virtualized consecutive address; and only allowing the target virtual function to perform read and write operations on the second plurality of second virtualized registers corresponding to the target virtual function.
7. The method of claim 6, wherein, The starting address of the second plurality of second virtualized registers accessible by the target virtual function is the same as the starting address of the consecutive addresses.
8. The method of claim 7, further comprising: in response to the target virtual function performing a write operation on the second plurality of second virtualized registers corresponding to the target virtual function, writing data written in the second plurality of second virtualized registers into the second plurality of second physical registers corresponding to the target virtual function in the consecutive addresses.
9. An interrupt controller, comprising: The sending module is configured to, in response to receiving an interrupt signal from an interrupt source, determine, based on identification information contained in the interrupt signal, a target virtualized hardware resource corresponding to the interrupt source among a plurality of virtualized hardware resources, and send the interrupt signal to a target virtual function indicated by the identification information by using the target virtualized hardware resource, wherein the plurality of virtualized hardware resources are obtained by virtualizing hardware resources for processing interrupts based on a number of virtual functions running on a physical machine, and the plurality of virtualized hardware resources correspond to the plurality of virtual functions one by one, and wherein the target virtual function is one of the plurality of virtual functions; and The remapping module is configured to, in response to receiving an access request sent by the target virtual function based on the interrupt signal, remap a target address where at least one interrupt information requested by the access request is located based on the number of the plurality of virtual functions, so that the target virtual function can only access an address segment corresponding to the target virtual function in the target address.
10. The interrupt controller of claim 9, wherein, The remapping module includes: The bit-level remapping unit is configured to, in response to receiving an access request sent by the target virtual function based on the interrupt signal, and the at least one interrupt information including first interrupt information stored inside a first physical register, remap the first physical register at a bit level based on the number of the plurality of virtual functions, so that the target virtual function can only access a bit corresponding to the target virtual function in the first physical register; and / or The address-level remapping unit is configured to, in response to receiving an access request sent by the target virtual function based on the interrupt signal, and the at least one interrupt information including second interrupt information stored on a continuous address across a first plurality of second physical registers, remap the continuous address at an address level based on the number of the plurality of virtual functions, so that the target virtual function can only access a second plurality of second physical registers corresponding to the target virtual function in the continuous address.
11. The interrupt controller of claim 10, wherein, The bit-level remapping unit includes: The first virtualization sub-unit is configured to, in response to the at least one interrupt information including the first interrupt information stored inside the first physical register, virtualize the first physical register based on the number of the plurality of virtual functions to obtain a plurality of first virtualized registers corresponding to the plurality of virtual functions one by one; The first determination sub-unit is configured to determine, based on the number of the plurality of virtual functions and a number of bit positions of the first interrupt information in the first physical register, that a number of bit positions corresponding to each virtual function in its corresponding first virtualized register is n, wherein n is an integer greater than or equal to 1; and The first access sub-unit is configured to only allow the target virtual function to perform read and write operations on the first n bit positions of the first virtualized register corresponding to the virtual function.
12. The interrupt controller of claim 11, wherein, The starting address of the first n-bit bit of the corresponding first virtualization register accessible by the target virtual function is the same as the starting address of the first physical register.
13. The interrupt controller of claim 12, further comprising: a first writing module configured to, in response to the target virtual function performing a write operation on the first n-bit bit of the corresponding first virtualization register, write the data written in the first n-bit bit of the corresponding first virtualization register into the corresponding bit of the target virtual function in the first physical register.
14. The interrupt controller of any of claims 10-13, wherein, The address level remapping unit comprises: a second virtualization subunit configured to, in response to the at least one interrupt information comprising second interrupt information stored on a continuous address across a first plurality of second physical registers, perform virtualization on the continuous address based on the number of the plurality of virtual functions to obtain a plurality of virtualized continuous addresses corresponding to the plurality of virtual functions one by one; a second determination subunit configured to determine, based on the number of the plurality of virtual functions, a second plurality of second virtualization registers corresponding to each virtual function in the corresponding virtualized continuous address of the virtual function; and a second access subunit configured to only allow the target virtual function to perform read and write operations on the second plurality of second virtualization registers corresponding to the target virtual function.
15. The interrupt controller of claim 14, wherein, The starting address of the second plurality of second virtualization registers accessible by the target virtual function is the same as the starting address of the continuous address.
16. The interrupt controller of claim 15, further comprising: a second writing module configured to, in response to the target virtual function performing a write operation on the second plurality of second virtualization registers corresponding to the target virtual function, write the data written in the second plurality of second virtualization registers into the corresponding second plurality of second physical registers in the continuous address of the target virtual function.
17. An electronic device, comprising: at least one processor; and a memory connected with the at least one processor in communication; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-8.
18. A non-transitory computer readable storage medium having stored thereon computer instructions, wherein, The computer instructions are used to enable the computer to perform the method of any one of claims 1-8.
19. A computer program product comprising a computer program, wherein, The computer program, when executed by a processor, implements the method of any one of claims 1-8.
20. A chip, characterized by comprising: According to claim 9 The interrupt controller as described in any one of the 16.
Citation Information
Patent Citations
PCIe equipment hardware virtualization address mapping method and device
CN117743243A