A self-recovery method, system, device and medium for upgrading a vehicle automatic driving controller system after power failure

By activating and switching partitions in the partition of the car autonomous driving controller system, creating a mirror file and rolling back and recovery, the problem of self-recovery problems caused by abnormal power outage during the upgrade process and mismatch of the mirror version is solved, and the consistency of the system's self-recovery and mirror version is achieved.

CN115903722BActive Publication Date: 2025-05-16CHONGQING CHANGAN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210934306.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-04
Publication Date
2025-05-16
Estimated Expiration
2042-08-04

AI Technical Summary

Technical Problem

In the prior art, software or hardware abnormalities may occur during the upgrade process of the automotive autonomous driving controller system, resulting in the system being unable to recover itself, and the mirror versions of each partition in the system may not match after the rollback.

Method used

By activating the first partition in the partition Part_AB and writing the upgrade information to the second partition, manually switch the second partition activation after the upgrade is successful, establish a mirror file of the Part_SIG partition, write the upgrade information and judge the success, if successful, the activation is successful and the mark is deleted. Otherwise, the recovery data is rolled back and the activation is started again.

Benefits of technology

It realizes that after an abnormal power outage occurs during the upgrade process, the system can recover itself, and ensure the consistency of the mirror versions of each partition in the system, ensuring the continuity of subsequent upgrade processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115903722B_ABST
    Figure CN115903722B_ABST
Patent Text Reader

Abstract

The present invention provides a self-recovery method, system, device and medium for an automobile automatic driving controller system after power failure during upgrade, which activates the first partition in partition Part_AB, writes the upgrade information into the second partition in partition Part_AB, and determines whether the upgrade is successful; if so, manually switches the second partition to be activated and effective, otherwise rolls back and recovers the data in partition Part_AB, and restarts the activation; after manually switching the second partition to be activated and effective, marks and records it in tag Tag_RB; establishes a mirror file of Part_SIG partition in partition Part_AB, writes the upgrade information into partition Part_AB, and determines whether the upgrade is successful; if so, the activation is successful, and deletes the tag Tag_RB; if not, rolls back and recovers the data in partition Part_SIG, and manually switches the second partition to be activated and effective and starts the activation again, which solves the problem of mismatching the mirror versions of each partition in the system software after power failure and restart during upgrade, and abnormal power failure during the upgrade process does not affect the system rollback and recovery, nor does it affect the continued upgrade.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of automobile software upgrade control technology, and specifically to a self-recovery method, system, device, and medium for an automobile automatic driving controller system after a power outage during an upgrade. Background Art

[0002] With the development of control technology and information technology, more and more automobile manufacturers are beginning to use autonomous driving technology. Since autonomous driving technology is not yet fully mature, after the car is delivered to the user, it will undergo multiple system iterations and upgrades. Therefore, for software or hardware anomalies that occur during the upgrade process, the system must first be able to recover itself, and secondly, the consistency of each image version in the system must be ensured.

[0003] Some backup methods are used to reduce backup operations, reduce the space occupied by running partitions, improve software flashing efficiency, and add partition software rollback functions. However, there is a problem that the image versions of each partition in the system may not match after the rollback.

[0004] Some backup methods include version verification, upgrade package verification, backup, automatic rollback, etc. However, there is a problem that abnormal power failure during the upgrade process will cause the device to be unusable.

[0005] Some backup methods support automatic rollback when an upgrade fails. However, there is also the problem that an abnormal power outage during the upgrade process may cause the device to become unusable. Summary of the invention

[0006] In view of the shortcomings of the prior art mentioned above, the present invention provides a self-recovery method, system, device, and medium for an automobile automatic driving controller system after a power outage during an upgrade, so as to solve the problems in the prior art that the image versions of each partition in the system may not match after a rollback, and an abnormal power outage during the upgrade process may cause the device to be unusable.

[0007] The present invention provides, including:

[0008] A self-recovery method for upgrading a vehicle automatic driving control system after power failure, comprising the steps of:

[0009] Activate the first partition in Part_AB, write the upgrade information to the second partition in Part_AB, and determine whether the upgrade is successful; if so, manually switch the second partition to activate and take effect; otherwise, roll back and restore the data in Part_AB, and restart the activation;

[0010] After the manual switching of the second partition is activated and becomes effective, it is marked and recorded in the tag Tag_RB;

[0011] Create a mirror file of the Part_SIG partition in the Part_AB partition, write the upgrade information into the Part_AB partition, and determine whether the upgrade is successful; if so, the activation is successful, and the tag Tag_RB is deleted; if not, roll back the data in the Part_SIG partition, and manually switch the second partition activation to take effect and start activation again.

[0012] In one embodiment of the present invention, the steps of activating the first partition in the partition Part_AB, writing the upgrade information to the second partition in the partition Part_AB, and determining whether the upgrade is successful further include the steps of:

[0013] When the upgrade information is written to another partition in the partition Part_AB, if a power outage occurs during the upgrade, there is no need to roll back and restore the data in the partition Part_AB.

[0014] In one embodiment of the present invention, the steps of creating a mirror file of the Part_SIG partition in the Part_AB partition, writing the upgrade information into the Part_AB partition, and determining whether the upgrade is successful further include the steps of:

[0015] When writing the upgrade information into the partition Part_SIG, if a power outage occurs during the upgrade, a rollback is initiated after power is restored, and the tag Tag_RB is deleted.

[0016] In one embodiment of the present invention, the steps of creating a mirror file of the Part_SIG partition in the Part_AB partition, writing the upgrade information into the Part_AB partition, and determining whether the upgrade is successful further include the following steps:

[0017] When the system is powered on, a check is performed on the tag Tag_RB. If the tag Tag_RB does not exist, the system starts normally. If the tag Tag_RB exists, the upgrade activation is deemed incomplete, and the data in the partition Part_SIG is rolled back and the second partition activation is manually switched to take effect and activation is started again.

[0018] In one embodiment of the present invention, the steps of activating the first partition in the partition Part_AB, writing the upgrade information to the second partition in the partition Part_AB, and determining whether the upgrade is successful further include the steps of:

[0019] The partition Part_AB includes n groups of sub-partitions Part_AB1 to Part_ABn. During the upgrade, the upgrade information is written in sequence from 1 to n; if all upgrades are successful, the process proceeds to step S2; if any sub-partition fails to upgrade, the entire partition Part_AB is deemed to have failed to upgrade, the data in the partition Part_AB is rolled back, and activation is restarted.

[0020] In one embodiment of the present invention, the steps of creating a mirror file of the Part_SIG partition in the Part_AB partition, writing the upgrade information into the Part_AB partition, and determining whether the upgrade is successful further include the steps of:

[0021] The partition Part_SIG includes n groups of sub-partitions Part_SIG1~Part_SIGn. During the upgrade, a sub-tag Tag_RB=1~Tag_RB=n is established in each sub-partition Part_AB1~Part_ABn in turn; the upgrade information is written in sequence from 1 to n; if all are upgraded successfully, the sub-tags Tag_RB=1~Tag_RB=n are deleted in turn; if any sub-partition fails to upgrade, the entire partition Part_SIG is deemed to have failed to upgrade, the data in the partition Part_SIG is rolled back and restored, and the second partition is manually switched to be activated and activated again.

[0022] In one embodiment of the present invention, the step of “rolling back and restoring data in the partition Part_SIG” includes the steps of:

[0023] The image file backup of the Part_SIG partition in the Part_AB partition of the current version is rewritten into the Part_SIG partition in the reverse order of installation.

[0024] The present application also proposes a self-recovery system for upgrading a vehicle automatic driving control system after a power outage, comprising:

[0025] An activation module, used to activate the first partition and the second partition, and determine whether the upgrade information activated by the first partition successfully upgrades the second partition;

[0026] Marking module, which records the upgrade successfully;

[0027] The mirror module creates a mirror file of the Part_SIG partition in the Part_AB partition, writes the upgrade information into the Part_AB partition, and determines whether the upgrade is successful;

[0028] Check the module and mark it when the system starts. Check Tag_RB. If the tag Tag_RB does not exist, it will start normally; if the tag Tag_RB exists, it is determined that the upgrade activation is not completed, roll back the data in the partition Part_SIG, and manually switch the second partition activation to take effect and start activation again.

[0029] The present application also proposes an electronic device, the electronic device comprising:

[0030] one or more processors;

[0031] A storage device for storing one or more programs. When the one or more programs are executed by the one or more processors, the electronic device implements the self-recovery method after power failure during the upgrade of the automobile automatic driving control system as described in any one of claims 1 to 7.

[0032] The present application also proposes a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a computer processor, the computer executes the self-recovery method after power failure of an upgrade of an automobile automatic driving control system as described in any one of claims 1 to 9.

[0033] Beneficial effects of the present invention:

[0034] The present invention solves the problem of incompatibility of the mirror versions of each partition in the system software after power failure and restart during upgrading. Abnormal power failure during upgrading does not affect the system rollback and recovery, and does not affect the subsequent upgrading.

[0035] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] The drawings herein are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present application, and together with the specification, are used to explain the principles of the present application. Obviously, the drawings described below are only some embodiments of the present application, and for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative work. In the drawings:

[0037] Figure 1 Shown is a schematic diagram of the upgrade process of the automobile automatic driving control system in the present invention.

[0038] Figure 2 Shown is a flowchart of software rollback / self-recovery in the present invention.

[0039] Figure 3 Shown is a schematic diagram of the software version numbers before and after software rollback / self-recovery in the present invention.

[0040] Figure 4 It is a block diagram of a self-recovery system after power failure of an automobile automatic driving control system upgrade shown in an exemplary embodiment of the present application;

[0041] Figure 5 A schematic diagram of the structure of a computer system suitable for implementing an electronic device of an embodiment of the present application is shown. DETAILED DESCRIPTION

[0042] The following will describe the embodiments of the present invention with reference to the accompanying drawings and preferred embodiments. Those skilled in the art can easily understand other advantages and effects of the present invention from the contents disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present invention. It should be understood that the preferred embodiments are only for illustrating the present invention, not for limiting the scope of protection of the present invention.

[0043] It should be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present invention, and thus the drawings only show components related to the present invention rather than being drawn according to the number, shape and size of components in actual implementation. In actual implementation, the type, quantity and proportion of each component may be changed arbitrarily, and the component layout may also be more complicated.

[0044] In the following description, numerous details are discussed to provide a more thorough explanation of the embodiments of the present invention. However, it is obvious to those skilled in the art that the embodiments of the present invention can be implemented without these specific details. In other embodiments, well-known structures and devices are shown in the form of block diagrams rather than in detail to avoid making the embodiments of the present invention difficult to understand.

[0045] Autonomous driving includes five levels, L0-L5. L0 is no autonomous driving technology and requires manual driving operation; L1 is assisted driving, cruise control, lane keeping, automatic parking, and its operation still requires manual operation and intervention by the driver; L2 can be said to be the autonomous driving system currently equipped in most new cars on the market. L2 autonomous driving has many prototype functions of autonomous driving vehicles, such as full-speed automatic assisted driving, automatic assisted driving in congestion, automatic danger prediction braking, etc., but more often, the driver still needs to lead the vehicle's driving. Only in certain circumstances can the driver's hands temporarily leave the steering wheel; at the L3 level, the vehicle can achieve autonomous driving in most road conditions and take over a large part of the car's driving functions. However, at the L3 stage, the driver still needs to pay attention at all times so that he can take over the vehicle in time in an emergency. At this level, the importance of the driver is significantly reduced. The driver only needs to pay attention to road conditions at all times, just like an examiner watching a student to prevent him from cheating, to prevent the car's driving system from not knowing how to deal with unrecognizable road conditions. For L4 autonomous driving, the automation system in the car is already very complete. The vehicle can already take over the driver's work and reach the level of autonomous driving, but if the driver wants to drive himself, he can still take over the vehicle. For L5 level autonomous driving, fully autonomous driving can be achieved in any weather and any region.

[0046] The existing mainstream autonomous driving cars on the market are at the L2 or L3 level. The driver still needs to maintain control of the vehicle to ensure driving safety. When driving, the driver needs to hold the steering wheel or hold the steering wheel intermittently so that the car can detect that the driver is in the driving mode and maintain the driving mode. The driver can take over the driving control of the car at any time. The vehicle's autonomous driving is controlled by the vehicle's master control system to collect driving information and control the autonomous driving. A large number of sensors and controllers are required to control the various systems of the vehicle to work. The degree of intelligence of the vehicle's autonomous driving can improve the level of autonomous driving service according to the subsequent software upgrades of the vehicle manufacturer. More vehicle autonomous driving functions need to be maintained and upgraded according to the upgrade software released by the vehicle manufacturer to improve the autonomous driving service experience and autonomous driving safety. During the regular autonomous driving software upgrade process, it is easy for the vehicle system to lose power, resulting in interruptions in the software upgrade process. It is necessary to ensure the integrity of the vehicle's existing autonomous driving functions while also ensuring the security of the vehicle's autonomous driving upgrade information to ensure that the upgraded software can self-recover when the vehicle system is powered on again and continue the autonomous driving software upgrade service.

[0047] This application proposes a self-recovery method for upgrading a car's automatic driving control system after a power outage, such as Figures 1 to 3 shown. Figure 1 Shown is a schematic diagram of the upgrade process of the automobile automatic driving control system in the present invention. Figure 2 Shown is a flowchart of software rollback / self-recovery in the present invention. Figure 3 The schematic diagram showing the software version number before and after software rollback / self-recovery in the present invention includes the following steps:

[0048] Activate one partition in partition Part_AB, write upgrade information into another partition in partition Part_AB, and determine whether the upgrade is successful; if so, manually switch the other partition to make the activation effective; if not, roll back and restore the data in partition Part_AB, and restart the activation; in one embodiment, the step is also included: when writing the upgrade information into another partition in partition Part_AB, if a power outage occurs during the upgrade, there is no need to roll back and restore the data in partition Part_AB.

[0049] After the manual switching of the second partition is activated and becomes effective, it is marked and recorded in the tag Tag_RB;

[0050] Create a mirror file of the Part_SIG partition in the Part_AB partition, write the upgrade information into the Part_AB partition, and determine whether the upgrade is successful; if so, the activation is successful, and the tag Tag_RB is deleted; if not, roll back and restore the data in the Part_SIG partition, and after the manual switching of the second partition activation takes effect, mark and record in the tag Tag_RB and restart the activation. Further, the method also includes the steps of: when writing the upgrade information into the Part_SIG partition, if a power outage occurs during the upgrade, start the rollback after powering on again, and delete the tag Tag_RB.

[0051] In another embodiment, the steps of establishing a mirror file of the Part_SIG partition in the Part_AB partition, writing the upgrade information into the Part_AB partition, and determining whether the upgrade is successful further include the following steps: performing a tag Tag_RB check when the system is turned on, and if the tag Tag_RB does not exist, starting normally; if the tag Tag_RB exists, determining that the upgrade activation is incomplete, rolling back the data in the Part_SIG partition, and returning to manually switch the second partition activation to restart activation after it takes effect.

[0052] In one embodiment of the present invention, the steps of activating the first partition in the partition Part_AB, writing the upgrade information to the second partition in the partition Part_AB, and determining whether the upgrade is successful further include the steps of:

[0053] When the upgrade information is written to another partition in the partition Part_AB, if a power outage occurs during the upgrade, there is no need to roll back and restore the data in the partition Part_AB.

[0054] In one embodiment of the present invention, the steps of creating a mirror file of the Part_SIG partition in the Part_AB partition, writing the upgrade information into the Part_AB partition, and determining whether the upgrade is successful further include the steps of:

[0055] When writing the upgrade information into the partition Part_SIG, if a power outage occurs during the upgrade, a rollback is initiated after power is restored, and the tag Tag_RB is deleted.

[0056] In one embodiment of the present invention, the steps of creating a mirror file of the Part_SIG partition in the Part_AB partition, writing the upgrade information into the Part_AB partition, and determining whether the upgrade is successful further include the following steps:

[0057] When the system is powered on, a check is performed on the tag Tag_RB. If the tag Tag_RB does not exist, the system starts normally. If the tag Tag_RB exists, the upgrade activation is deemed incomplete, and the data in the partition Part_SIG is rolled back and the second partition activation is manually switched to take effect and activation is started again.

[0058] In one embodiment of the present invention, the steps of activating the first partition in the partition Part_AB, writing the upgrade information to the second partition in the partition Part_AB, and determining whether the upgrade is successful further include the steps of:

[0059] The partition Part_AB includes n groups of sub-partitions Part_AB1 to Part_ABn. During the upgrade, the upgrade information is written in sequence from 1 to n; if all upgrades are successful, the process proceeds to step S2; if any sub-partition fails to upgrade, the entire partition Part_AB is deemed to have failed to upgrade, the data in the partition Part_AB is rolled back, and activation is restarted.

[0060] In one embodiment of the present invention, the steps of creating a mirror file of the Part_SIG partition in the Part_AB partition, writing the upgrade information into the Part_AB partition, and determining whether the upgrade is successful further include the steps of:

[0061] The partition Part_SIG includes n groups of sub-partitions Part_SIG1~Part_SIGn. During the upgrade, a sub-tag Tag_RB=1~Tag_RB=n is established in each sub-partition Part_AB1~Part_ABn in turn; the upgrade information is written in sequence from 1 to n; if all are upgraded successfully, the sub-tags Tag_RB=1~Tag_RB=n are deleted in turn; if any sub-partition fails to upgrade, the entire partition Part_SIG is deemed to have failed to upgrade, the data in the partition Part_SIG is rolled back and restored, and the second partition is manually switched to be activated and activated again.

[0062] In one embodiment of the present invention, the step of “rolling back and restoring data in the partition Part_SIG” includes the steps of:

[0063] The image file backup of the Part_SIG partition in the Part_AB partition of the current version is rewritten into the Part_SIG partition in the reverse order of installation.

[0064] like Figure 4 As shown, the present application also proposes a self-recovery system after power failure of an upgrade of an automobile automatic driving control system, comprising:

[0065] An activation module, used to activate the first partition and the second partition, and determine whether the upgrade information activated by the first partition successfully upgrades the second partition;

[0066] Marking module, which records the upgrade successfully;

[0067] The mirror module creates a mirror file of the Part_SIG partition in the Part_AB partition, writes the upgrade information into the Part_AB partition, and determines whether the upgrade is successful;

[0068] Check the module and mark it when the system starts. Check Tag_RB. If the tag Tag_RB does not exist, it will start normally; if the tag Tag_RB exists, it is determined that the upgrade activation is not completed, roll back the data in the partition Part_SIG, and manually switch the second partition activation to take effect and start activation again.

[0069] It should be noted that the self-recovery method after power failure during upgrade of the automobile automatic driving controller system provided in the above embodiment belongs to the same concept as the self-recovery method after power failure during upgrade of the automobile automatic driving controller system provided in the above embodiment, and the specific manner in which each module and unit performs the operation has been described in detail in the method embodiment and will not be repeated here. In actual application, the road condition refresh device provided in the above embodiment can distribute the above functions to different functional modules as needed, that is, divide the internal structure of the device into different functional modules to complete all or part of the functions described above, and this is not limited here.

[0070] An embodiment of the present application also provides an electronic device, comprising: one or more processors; a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the electronic device implements the self-recovery method after power failure during the upgrade of the automobile automatic driving controller system provided in the above-mentioned embodiments.

[0071] Figure 5 The structure diagram of the computer system suitable for implementing the electronic device of the embodiment of the present application is shown. It should be noted that: Figure 5 The computer system 500 of the electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.

[0072] like Figure 5As shown, the computer system 500 includes a central processing unit (CPU) 501, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 502 or the program loaded from the storage part 508 to the random access memory (RAM) 503, such as executing the method described in the above embodiment. In the RAM 503, various programs and data required for system operation are also stored. The CPU 501, the ROM 502 and the RAM 503 are connected to each other through the bus 504. The input / output (I / O) interface 505 is also connected to the bus 504.

[0073] The following components are connected to the I / O interface 505: an input section 506 including a keyboard, a mouse, etc.; an output section 507 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker; a storage section 508 including a hard disk, etc.; and a communication section 509 including a network interface card such as a LAN (Local Area Network) card, a modem, etc. The communication section 509 performs communication processing via a network such as the Internet. A drive 510 is also connected to the I / O interface 505 as needed. A removable medium 511, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 510 as needed so that a computer program read therefrom is installed into the storage section 508 as needed.

[0074] In particular, according to an embodiment of the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a computer program for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication section 509, and / or installed from a removable medium 511. When the computer program is executed by a central processing unit (CPU) 501, various functions defined in the system of the present application are executed.

[0075] It should be noted that the computer-readable medium shown in the embodiment of the present application can be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium can be, for example, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, wherein a computer-readable computer program is carried. This propagated data signal can take a variety of forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium, which may send, propagate or transmit a program for use by or in conjunction with an instruction execution system, apparatus or device. A computer program contained on a computer-readable medium may be transmitted using any appropriate medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0076] The flowchart and block diagram in the accompanying drawings illustrate the possible architecture, functions and operations of the system, method and computer program product according to various embodiments of the present application. Wherein, each box in the flowchart or block diagram can represent a module, a program segment, or a part of the code, and the above-mentioned module, program segment, or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0077] The units involved in the embodiments described in this application may be implemented by software or hardware, and the units described may also be set in a processor. The names of these units do not, in some cases, constitute limitations on the units themselves.

[0078] Another aspect of the present application also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a computer processor, the computer executes the self-recovery method after power failure of the automatic driving controller system upgrade as described above. The computer-readable storage medium may be included in the electronic device described in the above embodiment, or may exist independently without being assembled into the electronic device.

[0079] Another aspect of the present application also provides a computer program product or a computer program, which includes a computer instruction stored in a computer-readable storage medium. The processor of the computer device reads the computer instruction from the computer-readable storage medium, and the processor executes the computer instruction, so that the computer device executes the self-recovery method after power failure of the upgrade of the automobile automatic driving controller system provided in the above-mentioned various embodiments.

[0080] The above embodiments are merely illustrative of the principles and effects of the present invention, and are not intended to limit the present invention. Anyone familiar with the technology may modify or change the above embodiments without violating the spirit and scope of the present invention. Therefore, all equivalent modifications or changes made by a person of ordinary skill in the art without departing from the spirit and technical ideas disclosed by the present invention shall still be covered by the claims of the present invention.

Claims

1. A self-recovery method after power failure during upgrading of an automobile automatic driving control system, characterized in that: Includes steps: Activate the first partition in the partition Part_AB, write the upgrade information to the second partition in the partition Part_AB, and determine whether the upgrade is successful; If the multiple groups of sub-partitions of the second partition in the partition Part_AB are all upgraded successfully, it is determined that the second partition is manually switched to be activated and takes effect; otherwise, the data of the second partition in the partition Part_AB is rolled back and activated again; After the manual switching of the second partition is activated and becomes effective, it is marked and recorded in the tag Tag_RB; Create a mirror file of the Part_SIG partition in the Part_AB partition, write the upgrade information into the Part_AB partition, and determine whether the upgrade is successful; if so, the activation is successful, and the tag Tag_RB is deleted; if not, roll back the data in the Part_SIG partition, and manually switch the second partition activation to take effect and start activation again; The step of activating the first partition in the partition Part_AB, writing the upgrade information into the second partition in the partition Part_AB, and judging whether the upgrade is successful further comprises the steps of: When writing the upgrade information to another partition in the partition Part_AB, if a power outage occurs during the upgrade, there is no need to roll back and restore the data in the partition Part_AB; The steps of creating a mirror file of the Part_SIG partition in the Part_AB partition, writing the upgrade information into the Part_AB partition, and determining whether the upgrade is successful also include the following steps: When writing the upgrade information into the partition Part_SIG, if a power outage occurs during the upgrade, the rollback is initiated after the power is restored, and the tag Tag_RB is deleted; The steps of creating a mirror file of the Part_SIG partition in the Part_AB partition, writing the upgrade information into the Part_AB partition, and determining whether the upgrade is successful also include the following steps: When the system is powered on, a check is performed on the tag Tag_RB. If the tag Tag_RB does not exist, the system starts normally. If the tag Tag_RB exists, the upgrade activation is deemed incomplete, and the data in the partition Part_SIG is rolled back and the second partition activation is manually switched to take effect and activation is started again.

2. The self-recovery method after power failure during upgrading of an automobile automatic driving control system according to claim 1, characterized in that: The step of activating the first partition in the partition Part_AB, writing the upgrade information into the second partition in the partition Part_AB, and judging whether the upgrade is successful further comprises the steps of: The partition Part_AB includes n groups of sub-partitions Part_AB1 to Part_ABn. During the upgrade, the upgrade information is written in sequence from 1 to n; if all upgrades are successful, the process proceeds to step S2; if any sub-partition fails to upgrade, the entire partition Part_AB is deemed to have failed to upgrade, the data in the partition Part_AB is rolled back, and activation is restarted.

3. The self-recovery method after power failure during upgrading of an automobile automatic driving control system according to claim 1, characterized in that: The steps of creating a mirror file of the Part_SIG partition in the Part_AB partition, writing the upgrade information into the Part_AB partition, and determining whether the upgrade is successful also include the following steps: The partition Part_SIG includes n groups of sub-partitions Part_SIG1~Part_SIGn. During the upgrade, a sub-tag Tag_RB=1~Tag_RB=n is established in each sub-partition Part_AB1~Part_ABn in turn; the upgrade information is written in sequence from 1 to n; if all are upgraded successfully, the sub-tags Tag_RB=1~Tag_RB=n are deleted in turn; if any sub-partition fails to upgrade, the entire partition Part_SIG is deemed to have failed to upgrade, the data in the partition Part_SIG is rolled back and restored, and the second partition is manually switched to be activated and activated again.

4. The self-recovery method after power failure during upgrading of an automatic driving control system of an automobile according to claim 3, characterized in that: The step of "rolling back and restoring data in the partition Part_SIG" includes the steps of: The image file backup of the Part_SIG partition in the Part_AB partition of the current version is rewritten into the Part_SIG partition in the reverse order of the installation.

5. A self-recovery system after power failure during the upgrade of an automatic driving control system of an automobile, used to implement the self-recovery method after power failure during the upgrade of an automatic driving control system of an automobile as claimed in claim 1, characterized in that: The system comprises: The activation module is used to activate the first partition and the second partition, and determine whether the upgrade information activated by the first partition successfully upgrades the second partition according to the upgrade results of the multiple groups of sub-partitions of the second partition in the partition Part_AB; and is also used to write the upgrade information to another partition in the partition Part_AB, so that if a power failure occurs during the upgrade, there is no need to roll back and restore the data of another partition in the partition Part_AB; Marking module, marking and recording after successful upgrade; The mirror module creates a mirror file of the Part_SIG partition in the Part_AB partition, writes the upgrade information into the Part_AB partition, and determines whether the upgrade is successful; it is also used to start a rollback after powering on again and delete the tag Tag_RB if a power failure occurs during the upgrade when writing the upgrade information into the Part_SIG partition; The inspection module performs a tag Tag_RB check when the system is turned on. If the tag Tag_RB does not exist, it starts normally; if the tag Tag_RB exists, it is determined that the upgrade activation is not completed, and the data in the partition Part_SIG is rolled back and restored, and the second partition activation is manually switched to take effect and start activation again.

6. An electronic device, characterized in that: The electronic device comprises: one or more processors; A storage device for storing one or more programs. When the one or more programs are executed by the one or more processors, the electronic device implements the self-recovery method after power failure during the upgrade of the automobile automatic driving control system as described in any one of claims 1 to 4.

7. A computer-readable storage medium, characterized in that: A computer program is stored thereon, and when the computer program is executed by a computer processor, the computer executes the self-recovery method after power failure of an upgrade of an automobile automatic driving control system as described in any one of claims 1 to 4.

Citation Information

Patent Citations

  • Method and device for upgrading operation system

    CN104918114A

  • Dual backup method containing fixed flash area and capable of rolling back

    CN113434166A