Configuration method, device, equipment and storage medium of system memory management unit
By allocating external devices to each virtual machine and setting the initial configuration of the SMMU to an inaccessible state, combined with the virtual machine-specific page table management, the problems of device isolation and memory access security between virtual machines are solved, and secure isolation and secure memory access are achieved.
Patent Information
- Application Number
- CN202510179705.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-18
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2045-02-18
AI Technical Summary
Existing hypervisors cannot effectively achieve device isolation between virtual machines when configuring the System Memory Management Unit (SMMU), and using the second-stage address translation page tables of MMU may lead to unsafe memory access.
Assign external devices to each virtual machine by preset configuration files and set the initial configuration of the SMMU to an inaccessible state before the virtual machine starts, ensuring that external devices can only be accessed by the virtual machine. When a virtual machine accesses an external device, it obtains the physical address and obtains the target memory address from the correspondence between the physical address and the memory address recorded in the page table of the virtual machine to perform secure memory access.
It realizes secure isolation of devices of different virtual machines, reduces the probability of other virtual machines accessing external devices, and reduces the probability of incorrectly configured target memory addresses by generating page tables for virtual machines, and provides security guarantees for memory access.
Smart Images

Figure CN119645670B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of virtualization technology, and in particular to a configuration method, device, electronic device and computer-readable storage medium of a system memory management unit. Background Art
[0002] A hypervisor is used to run and manage multiple virtual machines on a single hardware platform and is often used to provide resource isolation and virtualization support.
[0003] Current hypervisors usually set the device's SMMU initialization configuration to bypass state when configuring the device's System Memory Management Unit (SMMU), and use the second-stage address translation page table of the Memory Management Unit (MMU) for address translation when the SMMU is formally configured.
[0004] However, configuring the device's SMMU initialization to the bypass state makes it impossible to securely isolate devices of different virtual machines, and using the MMU's second-stage address translation page table for address translation will cause unsafe memory access. Summary of the invention
[0005] The embodiments of the present application provide a method, device, electronic device and computer-readable storage medium for configuring a system memory management unit to solve the problems in the related art.
[0006] In a first aspect, an embodiment of the present application provides a method for configuring a system memory management unit, the method comprising:
[0007] According to the preset configuration file, corresponding external devices are allocated to each virtual machine;
[0008] Acquire, from a preset table recording information of external devices, a value of a first designated data bit of an entry corresponding to the assigned external device;
[0009] Before the virtual machine is started, the value of the first designated data bit is set to a preset value, and after the virtual machine is started, the value of the first designated data bit is adjusted from the preset value to a first value; the preset value is used to indicate that the configuration of the system memory management unit of the external device is in an inaccessible state; the first value is used to indicate that the configuration of the system memory management unit of the external device is in a preset state; the preset state is used to indicate that the external device can only be accessed by the virtual machine to which it belongs;
[0010] When the virtual machine accesses the memory through the input operation of the external device, the physical address of the input operation is obtained, and the target memory address matching the physical address of the input operation is obtained from the correspondence between the physical address and the memory address recorded in the page table corresponding to the virtual machine to which the external device belongs; the memory address recorded in the page table is the memory address allocated to the virtual machine;
[0011] The input operation is performed to access the memory according to the target memory address.
[0012] In a second aspect, an embodiment of the present application provides a configuration device for a system memory management unit, the device comprising:
[0013] A first allocation module, used to allocate a corresponding external device to each virtual machine according to a preset configuration file;
[0014] A first acquisition module, used to acquire a value of a first designated data bit of an entry corresponding to the assigned external device from a preset table recording information of the external device;
[0015] a setting module, configured to set the value of the first designated data bit to a preset value before the virtual machine is started, and to adjust the value of the first designated data bit from the preset value to a first value after the virtual machine is started; the preset value is used to indicate that the configuration of the system memory management unit of the external device is in an inaccessible state; the first value is used to indicate that the configuration of the system memory management unit of the external device is in a preset state; the preset state is used to indicate that the external device can only be accessed by the virtual machine to which it belongs;
[0016] A second acquisition module is used to obtain the physical address of the input operation when the virtual machine accesses the memory through the input operation of the external device, and obtain the target memory address matching the physical address of the input operation from the correspondence between the physical address and the memory address recorded in the page table corresponding to the virtual machine to which the external device belongs; the memory address recorded in the page table is the memory address allocated to the virtual machine;
[0017] An access module is used to perform the input operation to access the memory according to the target memory address.
[0018] In a third aspect, an embodiment of the present application further provides an electronic device, including a processor;
[0019] a memory for storing instructions executable by the processor;
[0020] The processor is configured to execute the instructions to implement the method of the first aspect.
[0021] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, which, when instructions in the computer-readable storage medium are executed by a processor of an electronic device, enables the electronic device to execute the method of the first aspect.
[0022] In the embodiment of the present application, a corresponding external device is assigned to each virtual machine according to a preset configuration file, and the value of the first designated data bit of the table item corresponding to the assigned external device is obtained from a preset table that records the information of the external device. Before the virtual machine is started, the value of the first designated data bit is set to a preset value, and the preset value is used to indicate that the system memory management unit of the external device is configured as an inaccessible state, which can reduce the probability of other virtual machines in the system accessing the external device. In addition, when the virtual machine accesses the memory through the input operation of the external device, the physical address of the input operation is obtained, and the correspondence between the physical address and the memory address recorded in the page table corresponding to the virtual machine to which the external device belongs is obtained, and the target memory address matching the physical address of the input operation is obtained. According to the target memory address, the input operation accesses the memory, and a page table that records the correspondence between the physical address and the memory address is generated for each virtual machine, and the memory area recorded in the page table is limited to the memory area that can be used when the input operation of the external device accesses the memory, which can reduce the probability of misconfigured target memory addresses and provide security for memory access.
[0023] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.
[0025] Figure 1 It is a flowchart of the steps of a method for configuring a system memory management unit provided in an embodiment of the present application;
[0026] Figure 2 It is a flowchart of the specific steps of a method for configuring a system memory management unit provided in an embodiment of the present application;
[0027] Figure 3 It is a block diagram of a configuration device of a system memory management unit provided in an embodiment of the present application;
[0028] Figure 4 is a block diagram of an electronic device provided in an embodiment of the present application;
[0029] Figure 5 It is a block diagram of another electronic device according to another embodiment of the present application. DETAILED DESCRIPTION
[0030] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0031] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described here, and the objects distinguished by "first", "second", etc. are generally a class, and the number of objects is not limited. For example, the first object can be one or more. In addition, the term "and / or" in the specification and claims is used to describe the association relationship of associated objects, indicating that three kinds of relationships can exist, for example, A and / or B can be represented: A exists alone, A and B exist at the same time, and B exists alone. The character " / " generally indicates that the front and back associated objects are a kind of "or" relationship. In the embodiment of the present application, the term "multiple" refers to two or more, and other quantifiers are similar.
[0032] Figure 1 , is a flowchart of a method for configuring a system memory management unit provided in an embodiment of the present application, such as Figure 1 As shown, the method may include:
[0033] Step 101: Allocate corresponding external devices to each virtual machine according to a preset configuration file.
[0034] For example, an external device can be a peripheral component interface (PCI) device, which refers to expansion hardware that is inserted into the PCI slot on the motherboard. The PCI slot is a design based on the PCI local bus, usually silver or milky white, located on the motherboard, above the slot. Its location is specifically designed to provide interfaces for various expansion cards, such as sound cards, network cards, and video capture cards.
[0035] For example, a virtual machine (VM) is a computing environment created through software simulation, which enables a physical computer to run multiple independent operating systems and applications. Virtual machines can provide isolated computing resources on a single hardware platform and simulate multiple independent computer systems, thereby improving hardware resource utilization and flexibility. In a virtualization scenario, a virtual machine can be understood as an operating system. From the perspective of the virtual machine hypervisor, external devices need to be assigned to the corresponding operating system.
[0036] For example, a corresponding external device is allocated to each virtual machine through the function of a tool module in a virtual machine management program, and the corresponding relationship between the virtual machine and the allocated external device is written into a preset configuration file.
[0037] For example, the virtual machines include virtual machine 1 and virtual machine 2, and the external devices include external device 1 and external device 2. If in the preset configuration file, virtual machine 1 corresponds to external device 1, and virtual machine 2 corresponds to external device 2, then the external device allocated to virtual machine 1 is external device 1, and the external device allocated to virtual machine 2 is external device 2.
[0038] Step 102: Obtain the value of the first designated data bit of the entry corresponding to the assigned external device from a preset table recording the information of the external device.
[0039] For example, the preset table is used to store information of all external devices, wherein the information of the external devices includes the preset state of the external devices and the translation method of the external devices. The preset state of the external device includes an invalid state and a valid state. The translation method of the external device includes a first-stage translation method and a second-stage translation method. The translation method of each stage includes translation and no translation. The name of the preset table may be a stream table, each table entry corresponds to the configuration content of an external device, each table entry is 512 bits, the zeroth bit represents the initial configuration of the SMMU of the external device, and the first to third bits represent the translation method of the external device, first-stage translation, second-stage translation, or nested translation, or no translation. The configuration of the corresponding external device is completed by configuring the specific fields of each table entry.
[0040] For example, the first designated data bit can be the zeroth bit of each table entry. If the value of the zeroth bit is 0, it means that in the initial configuration stage, the configuration of the SMMU of the external device should be set to an inaccessible state, that is, an invalid state, and the address translation method set by the first to third bits is not effective. If the value of the zeroth bit is 1, it means that in the initial configuration stage, the configuration of the SMMU of the external device should be set to a translation state, that is, a valid state, and the address translation method is determined by the first to third bits.
[0041] Step 103: before the virtual machine is started, the value of the first designated data bit is set to a preset value, and after the virtual machine is started, the value of the first designated data bit is adjusted from the preset value to a first value; the preset value is used to indicate that the system memory management unit of the external device is configured as an inaccessible state; the first value is used to indicate that the system memory management unit of the external device is configured as a preset state; the preset state is used to indicate that the external device can only be accessed by the virtual machine to which it belongs.
[0042] For example, taking the preset value as 0 and the first designated data as the zeroth bit as an example, the value of the zeroth bit of the preset table entry is set to 0, and the initial configuration of the SMMU of the external device is inaccessible, that is, invalid, which is used to indicate that the external device is inaccessible, and can reduce the probability of other virtual machines in the system accessing the external device. For example, if the initial configuration of the SMMU of external device 2 is set to an inaccessible state, that is, invalid, in this case, it is mostly because the virtual machine to which external device 2 belongs has not been started, and there are other virtual machines in the system, which can prevent other virtual machines from operating external device 2. Not only can the external device be securely isolated, but also the separation of external devices can be achieved on the basis of achieving PCI pass-through.
[0043] For example, before starting the virtual machine, the virtual machine hypervisor sets the initial configuration of the SMMU of external device 1 and external device 2 to invalid, that is, inaccessible. When virtual machine 1 is started, the SMMU of external device 1 has been correctly configured, and virtual machine 1 can use the functions of external device 1 normally, while external device 2 is still in an inaccessible state. If virtual machine 1 tries to use external device 2, the access will fail. If the bypass initialization method is used, virtual machine 1 can access external device 2 at this time, which is contrary to the original intention of device isolation. When the external device uses the direct memory access (DMA) mechanism to interact with the memory, the address issued by the device does not need to be translated by the SMMU address, which loses the restriction and may damage other memory spaces. Therefore, setting the initialization configuration of the SMMU of the external device to the invalid state can reduce the probability of other virtual machines in the system accessing the external device.
[0044] For example, a controller process may be registered in virtual machine 1, and the driver of the corresponding external device 1 may be replaced to reduce the possibility that virtual machine 1 accesses external device 2 assigned to virtual machine 2.
[0045] Step 104: When the virtual machine accesses the memory through the input operation of the external device, the physical address of the input operation is obtained, and the target memory address matching the physical address of the input operation is obtained from the correspondence between the physical address and the memory address recorded in the page table corresponding to the virtual machine to which the external device belongs; the memory address recorded in the page table is the memory address allocated to the virtual machine.
[0046] For example, after ensuring that each virtual machine can only access the assigned external devices, it is also necessary to ensure that the virtual machine does not maliciously use the external devices. In the existing scheme, the second-stage address translation page table of the virtual machine is directly written into the SMMU configuration. Usually, in addition to the memory area, this page table also contains other memory mapping areas. In particular, for virtual machine 1, it also includes the memory area of virtual machine 2. There is a risk that DMA behavior will damage other memory areas and memory areas of other virtual machines. The embodiment of the present application obtains the memory range accessible to the virtual machine, and according to the accessible memory range, allocates memory addresses for the input operations of the external devices corresponding to the virtual machine, establishes a corresponding relationship with the physical address, and writes the corresponding relationship into the address translation page table corresponding to the virtual machine, so as to limit the address translation page table in the SMMU configuration to the memory area provided to the virtual machine. In particular, for virtual machine 2, the part of its memory belonging to virtual machine 2 is strictly isolated, which can ensure that DMA is limited to interacting with the memory area that the virtual machine can use.
[0047] For example, after an input operation is performed on an external device, the virtual machine to which the external device belongs obtains the physical address of the input operation when accessing the memory through the input operation of the external device. From the correspondence between the physical address and the memory address recorded in the page table corresponding to the virtual machine to which the external device belongs, the target memory address that matches the physical address of the input operation is obtained to complete the address conversion. Since the memory address recorded in the page table is the memory address allocated to the virtual machine, rather than directly reusing the second-stage translation page table of the MMU, the probability of configuring an incorrect target memory address can be reduced, providing security for memory access.
[0048] Step 105: perform the input operation to access the memory according to the target memory address.
[0049] For example, after obtaining the target memory address, the external device accesses the memory through an input operation. For example, after obtaining the target memory address, the memory area corresponding to the target memory address is found, and the read and write operations related to the pre-input operation are performed in the memory area.
[0050] In summary, in the embodiment of the present application, a corresponding external device is assigned to each virtual machine according to a preset configuration file, and the value of the first designated data bit of the table item corresponding to the assigned external device is obtained from a preset table that records the information of the external device. Before the virtual machine is started, the value of the first designated data bit is set to a preset value, and the preset value is used to indicate that the configuration of the system memory management unit of the external device is inaccessible, which can reduce the probability of other virtual machines in the system accessing the external device. In addition, when the virtual machine accesses the memory through the input operation of the external device, the physical address of the input operation is obtained, and the correspondence between the physical address and the memory address recorded in the page table corresponding to the virtual machine to which the external device belongs is obtained, and the target memory address matching the physical address of the input operation is obtained. According to the target memory address, the input operation accesses the memory, and a page table that records the correspondence between the physical address and the memory address is generated for each virtual machine, and the memory area recorded in the page table is limited to the memory area that can be used when the input operation of the external device accesses the memory, which can reduce the probability of the target memory address being configured incorrectly, and provide security for memory access.
[0051] Figure 2 , is a flowchart of the specific steps of a method for configuring a system memory management unit provided in an embodiment of the present application, such as Figure 2 As shown, the method may include:
[0052] Step 201: assign corresponding external devices to each virtual machine according to a preset configuration file.
[0053] This step may specifically refer to the above step 101, and will not be described in detail here.
[0054] Step 202: Obtain the value of the first designated data bit of the entry corresponding to the assigned external device from a preset table recording the information of the external device.
[0055] This step may be specifically referred to as the above step 102, and will not be described in detail here.
[0056] Step 203: before the virtual machine is started, the value of the first designated data bit is set to a preset value, and after the virtual machine is started, the value of the first designated data bit is adjusted from the preset value to a first value; the preset value is used to indicate that the system memory management unit of the external device is configured as an inaccessible state; the first value is used to indicate that the system memory management unit of the external device is configured as a preset state; the preset state is used to indicate that the external device can only be accessed by the virtual machine to which it belongs.
[0057] This step may be specifically referred to as the above step 103, and will not be described in detail here.
[0058] Step 204: When the virtual machine accesses the memory through the input operation of the external device, the physical address of the input operation is obtained, and the target memory address matching the physical address of the input operation is obtained from the correspondence between the physical address and the memory address recorded in the page table corresponding to the virtual machine to which the external device belongs; the memory address recorded in the page table is the memory address allocated to the virtual machine.
[0059] This step may be specifically referred to as the above step 104, and will not be described in detail here.
[0060] Optionally, before step 204, the method further includes:
[0061] Step A1: when the virtual machine to which the external device belongs is started, obtaining the memory range accessible to the virtual machine from the device tree file;
[0062] Step A2: allocating a memory address for an input operation of an external device corresponding to the virtual machine according to the accessible memory range to obtain a memory address;
[0063] Step A3: establishing a correspondence between the physical address and the memory address, and writing the correspondence into a page table corresponding to the virtual machine to which the external device belongs.
[0064] For steps A1 to A3, when the SMMU is not opened to the virtual machine, that is, the SMMU is not provided in the device tree or the initial configuration is set to the disable state, the virtual machine uses the physical address of the virtual machine when configuring the DMA address of the external device. When the external device initiates DMA, the physical address of the virtual machine transmitted to the device by the virtual machine needs to be translated into the host physical memory address through the SMMU. Therefore, in this case, the page table of address translation used in the SMMU and the page table of second-stage address translation used by the MMU are functionally the same. They can be reused directly, but may cause some security issues. When performing formal configuration, the entire second-stage address translation page table of the corresponding virtual machine is written into the configuration. Although sharing the page table with the MMU can save memory space, the second-stage address translation page table of the virtual machine contains address mappings of various serial ports and others in addition to the address mapping of physical memory.
[0065] For example, when the virtual machine to which the external device belongs is started, the embodiment of the present application obtains the memory range accessible to the virtual machine from the device tree file, allocates a memory address for the input operation of the external device corresponding to the virtual machine according to the accessible memory range, obtains the memory address, establishes a correspondence between the physical address and the memory address, and writes the correspondence into the page table corresponding to the virtual machine to which the external device belongs. Instead of directly reusing the second-stage translation page table of the MMU, the probability of misconfigured target memory addresses can be reduced, providing security for memory access.
[0066] For example, the memory address range accessible by the central processing unit (CPU) is 0x00000000-0xFFFFFFFF. After obtaining the accessible memory address range, a memory address is allocated for the input operation of the external device corresponding to the virtual machine. If the allocated memory address is 0xFFFFFFFF, taking the physical address 0x1A2E352F as an example, a correspondence between 0x1A2E352F and 0xFFFFFFFF is established and written into the page table corresponding to the virtual machine to which the external device belongs.
[0067] Optionally, step 204 may specifically include:
[0068] Sub-step 2041: when the virtual machine accesses the memory through the input operation of the external device, obtaining the virtual address of the input operation;
[0069] Sub-step 2042: convert the virtual address of the input operation to generate a physical address of the input operation.
[0070] Regarding sub-steps 2041 and 2042, virtual memory is a computer memory management technology that allows a program to believe that it has a complete continuous available memory, that is, an address space. When the memory space occupied by a program is larger than the physical space capacity, the operating system can put temporarily unused data into the disk and take it out when needed. In this way, part of the disk space is used to store such data, that is, random access memory (RAM) is used in combination with the temporary space of the hard disk. This temporary space is called virtual memory. The virtual addresses used by each program are independent of each other, and different programs can use the same virtual address.
[0071] For example, address translation of external devices through SMMU is a very complicated process. First, the corresponding table entry will be found according to the identifier of the external device. The configuration information in the table entry records whether the first-stage address translation is required. Bypass means using the physical address directly. If there is no bypass, the page table that records the first-stage address translation will be found according to the identifier of the external device, and the virtual address will be translated into a physical address. Then, if the second-stage page table translation is also configured in the table entry, the physical address will be translated into the final memory address according to the page table of the second-stage address translation. If the second-stage address translation is not configured, the physical address obtained before is the final memory address.
[0072] For example, suppose that the input operation of the external device is accessing the data pointed to by a virtual address. This virtual address is 0x2A8E317F. The binary notation of 0x2A8E317F is 0010101010_0011100011_000101111111. For convenience, we divide it into three parts. First, address according to 0010101010 to find the page directory entry. Because a page directory entry is 4 kilobytes (KB, Kilobyte), first shift 0010101010 left by two bits to get 001010101000 (0x2A8), use this subscript to find the page directory entry, and then locate a page table in the next layer according to this page directory entry. Then address according to 0011100011 and find the page table entry in the page table found in the previous step. After finding the page table entry, you can find the corresponding physical memory page. Finally, we use 000101111111 to find the page offset and get the final physical address based on the page offset.
[0073] Step 205: Obtain the translation mode of the external device in the preset state.
[0074] For example, the translation method of the external device includes a first-stage translation method and a second-stage translation method. Among them, the translation method of each stage includes translation and non-translation. The first-stage translation refers to translating the virtual address of the input operation of the external device into a physical address, and the second-stage translation refers to translating the physical address of the input operation of the external device into a memory address. If the first-stage translation method is non-translation, there is no need to translate the virtual address of the input operation of the external device into a physical address. If the first-stage translation method is translation, the virtual address of the input operation of the external device is translated into a physical address. If the second-stage translation method is non-translation, there is no need to translate the physical address of the input operation of the external device into a memory address. If the second-stage translation method is translation, the physical address of the input operation of the external device is translated into a memory address. The first-stage and second-stage translation methods of the external device in the valid state are obtained, and according to whether the first-stage and second-stage translations of the external device are performed and the target memory address, the input operation accesses the memory.
[0075] Optionally, step 205 may specifically include:
[0076] Sub-step 2051: when the virtual machine to which the external device belongs is started, obtaining respective values of a plurality of second designated data bits associated with the first designated data bit in the preset table; the plurality of second designated data bits are used to indicate a translation mode of the external device;
[0077] Sub-step 2052: if the respective values of the plurality of second designated data bits constitute a first value sequence, then determining that the translation method of the first stage is not to translate, and the translation method of the second stage is also not to translate; the translation method of the first stage indicates converting the virtual address into the physical address; the translation method of the second stage indicates converting the physical address into the memory address;
[0078] Sub-step 2053: If the respective values of the plurality of second designated data bits constitute a second value sequence, determining that the translation method of the first stage is not to translate, and the translation method of the second stage is to translate.
[0079] For sub-steps 2051 to 2053, the plurality of second designated data bits may be the second designated data bit, the third designated data bit, and the fourth designated data bit of the preset table. The numerical sequence may be 100, and the second numerical sequence may be 110. For the external device 1, when the virtual machine 1 to which it belongs is started, the SMMU obtains the respective numerical values of the second designated data bit, the third designated data bit, and the fourth designated data bit associated with the zeroth designated data bit in the preset table.
[0080] For example, the numerical values of the second designated data bit, the third designated data bit, and the fourth designated data bit are each composed of a numerical sequence. If the numerical sequence composed of the second designated data bit, the third designated data bit, and the fourth designated data bit is 100, then the translation mode of the first stage is determined to be no translation, and the translation mode of the second stage is also no translation. That is to say, when the external device performs DMA access, no address translation is performed, and the physical address of the input operation is directly used to perform the input operation to access the memory. If the numerical sequence composed of the second designated data bit, the third designated data bit, and the fourth designated data bit is 110, then the translation mode of the first stage is determined to be no translation, and the translation mode of the second stage is translation. That is to say, when the external device performs DMA access, the second stage address translation is performed, and the physical address of the input operation is converted into the corresponding memory address of the input operation, and the memory address of the input operation is used to perform the input operation to access the memory.
[0081] Step 206: perform the input operation to access the memory according to the translation mode of the external device and the target memory address.
[0082] For example, when the translation mode of the external device is translation, the target memory address is obtained, and the external device accesses the memory through input operation. For example, after obtaining the target memory address, the memory area corresponding to the target memory address is found, and the read and write operations related to the pre-input operation are performed in the memory area.
[0083] Optionally, step 206 may specifically include:
[0084] Sub-step 2061: If the translation mode of the first stage is not to translate and the translation mode of the second stage is also not to translate, then the physical address of the input operation is used as the target memory address to perform the input operation to access the memory;
[0085] Sub-step 2062: If the translation mode of the first stage is no translation and the translation mode of the second stage is translation, the physical address of the input operation is converted into the target memory address, and the input operation accesses the memory.
[0086] For sub-steps 2061-2062, if the translation method of the first stage is not to translate and the translation method of the second stage is also not to translate, the physical address of the input operation is used as the target memory address, and the input operation accesses the memory. If the translation method of the first stage is not to translate and the translation method of the second stage is to translate, the physical address of the input operation is converted into the target memory address, and the input operation accesses the memory.
[0087] Optionally, the virtual machine includes a root virtual machine and a non-root virtual machine; the method further includes:
[0088] Step 207: After starting the root virtual machine, start the non-root virtual machine by executing a start command in the root virtual machine.
[0089] For example, when the hypervisor starts, it automatically starts the first virtual machine, which is the root virtual machine. The hypervisor, also known as a virtual machine monitor, manages these virtual machines as they run in parallel. It logically separates the virtual machines from each other, allocating each virtual machine its own slice of underlying computing power, memory, and storage. This prevents the virtual machines from interfering with each other. For example, if one operating system crashes or security is compromised, the other operating systems can continue to run.
[0090] By way of example, the start command may be a command for communication between the root virtual machine and the hypervisor, that is, zone-start, which is implemented by a tool module in the hypervisor.
[0091] Optionally, the method further includes:
[0092] Step 208: Obtain a memory area reserved for the non-root virtual machine in the memory area of the root virtual machine, and mark the reserved memory area as a reserved memory node, so that the root virtual machine stops operating on the reserved memory area.
[0093] With respect to step 208, the startup of the non-root virtual machine needs to rely on the root virtual machine, and the memory area of the non-root virtual machine and the memory area of the root virtual machine may overlap. In this case, if the DMA behavior of the root virtual machine is not fine-grainedly controlled, the memory area of the non-root virtual machine is likely to be damaged.
[0094] For example, the reserved memory area is a part of the memory in the MMU page table of the root virtual machine. To be precise, it refers to the memory that the non-root virtual machine needs to use as mentioned above, but due to the limitation of the startup method, this part of the memory is included in the memory area of the device tree of the root virtual machine. By making a flag, the root virtual machine is told not to use this memory in daily access. Only when the non-root virtual machine needs to be started, the corresponding resources are placed in this memory.
[0095] In summary, in the embodiment of the present application, a corresponding external device is assigned to each virtual machine according to a preset configuration file, and the value of the first designated data bit of the table item corresponding to the assigned external device is obtained from a preset table that records the information of the external device. Before the virtual machine is started, the value of the first designated data bit is set to a preset value, and the preset value is used to indicate that the configuration of the system memory management unit of the external device is inaccessible, which can reduce the probability of other virtual machines in the system accessing the external device. In addition, when the virtual machine accesses the memory through the input operation of the external device, the physical address of the input operation is obtained, and the correspondence between the physical address and the memory address recorded in the page table corresponding to the virtual machine to which the external device belongs is obtained, and the target memory address matching the physical address of the input operation is obtained. According to the target memory address, the input operation accesses the memory, and a page table that records the correspondence between the physical address and the memory address is generated for each virtual machine, and the memory area recorded in the page table is limited to the memory area that can be used when the input operation of the external device accesses the memory, which can reduce the probability of the target memory address being configured incorrectly, and provide security for memory access.
[0096] Figure 3 is a block diagram of a configuration device of a system memory management unit provided in an embodiment of the present application, the device 30 includes:
[0097] The first allocation module 301 is used to allocate a corresponding external device to each virtual machine according to a preset configuration file;
[0098] A first acquisition module 302, configured to acquire a value of a first designated data bit of an entry corresponding to an assigned external device from a preset table recording information of the external device;
[0099] The setting module 303 is used to set the value of the first designated data bit to a preset value before the virtual machine is started, and adjust the value of the first designated data bit from the preset value to a first value after the virtual machine is started; the preset value is used to indicate that the configuration of the system memory management unit of the external device is in an inaccessible state; the first value is used to indicate that the configuration of the system memory management unit of the external device is in a preset state; the preset state is used to indicate that the external device can only be accessed by the virtual machine to which it belongs;
[0100] The second acquisition module 304 is used to obtain the physical address of the input operation when the virtual machine accesses the memory through the input operation of the external device, and obtain the target memory address matching the physical address of the input operation from the correspondence between the physical address and the memory address recorded in the page table corresponding to the virtual machine to which the external device belongs; the memory address recorded in the page table is the memory address allocated to the virtual machine;
[0101] The access module 305 is used to perform the input operation to access the memory according to the target memory address.
[0102] Optionally, the device further comprises:
[0103] A third acquisition module is used to acquire a memory range accessible to the virtual machine from a device tree file when the virtual machine to which the external device belongs is started;
[0104] an allocation module, configured to allocate a memory address for an input operation of an external device corresponding to the virtual machine according to the accessible memory range, and obtain a memory address;
[0105] The writing module is used to establish a corresponding relationship between the physical address and the memory address, and write the corresponding relationship into a page table corresponding to the virtual machine to which the external device belongs.
[0106] Optionally, the device further comprises:
[0107] A fourth acquisition module, used for acquiring a translation mode of the external device in the preset state;
[0108] The access module comprises:
[0109] The access submodule is used to perform the input operation to access the memory according to the translation mode of the external device and the target memory address.
[0110] Optionally, the fourth acquisition module includes:
[0111] A first acquisition submodule is used to acquire respective values of a plurality of second designated data bits associated with the first designated data bit in the preset table when the virtual machine to which the external device belongs is started; the plurality of second designated data bits are used to indicate a translation method of the external device;
[0112] A first determination submodule is used to determine that the translation method of the first stage is not to translate, and the translation method of the second stage is also not to translate if the respective values of the plurality of second designated data bits constitute a first value sequence; the translation method of the first stage indicates converting the virtual address into the physical address; the translation method of the second stage indicates converting the physical address into the memory address;
[0113] The second determination submodule is used to determine that the translation method of the first stage is not to translate and the translation method of the second stage is to translate if the respective values of the plurality of second designated data bits constitute a second value sequence.
[0114] Optionally, the access submodule includes:
[0115] a determination unit, configured to use the physical address of the input operation as the target memory address to access the memory by the input operation if the translation mode of the first stage is not to translate and the translation mode of the second stage is also not to translate;
[0116] The conversion unit is used to convert the physical address of the input operation into the target memory address if the translation mode of the first stage is no translation and the translation mode of the second stage is translation, so as to access the memory by the input operation.
[0117] Optionally, the second acquisition module includes:
[0118] A second acquisition submodule is used to acquire a virtual address of an input operation when the virtual machine accesses the memory through an input operation of an external device;
[0119] The generating submodule is used to convert the virtual address of the input operation to generate the physical address of the input operation.
[0120] Optionally, the virtual machine includes a root virtual machine and a non-root virtual machine; and the device further includes:
[0121] The execution module is used to start the non-root virtual machine by executing a start command in the root virtual machine after starting the root virtual machine.
[0122] Optionally, the device further comprises:
[0123] The marking module is used to obtain the memory area reserved for the non-root virtual machine in the memory area of the root virtual machine, and mark the reserved memory area as a reserved memory node so that the root virtual machine stops operating on the reserved memory area.
[0124] In summary, in the embodiment of the present application, a corresponding external device is assigned to each virtual machine according to a preset configuration file, and the value of the first designated data bit of the table item corresponding to the assigned external device is obtained from a preset table that records the information of the external device. Before the virtual machine is started, the value of the first designated data bit is set to a preset value, and the preset value is used to indicate that the configuration of the system memory management unit of the external device is inaccessible, which can reduce the probability of other virtual machines in the system accessing the external device. In addition, when the virtual machine accesses the memory through the input operation of the external device, the physical address of the input operation is obtained, and the correspondence between the physical address and the memory address recorded in the page table corresponding to the virtual machine to which the external device belongs is obtained, and the target memory address matching the physical address of the input operation is obtained. According to the target memory address, the input operation accesses the memory, and a page table that records the correspondence between the physical address and the memory address is generated for each virtual machine, and the memory area recorded in the page table is limited to the memory area that can be used when the input operation of the external device accesses the memory, which can reduce the probability of the target memory address being configured incorrectly, and provide security for memory access.
[0125] As for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0126] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.
[0127] Regarding the device in the above embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated here.
[0128] An embodiment of the present application provides a configuration device for a system memory management unit, including a memory and one or more programs, wherein the one or more programs are stored in the memory and are configured to be executed by one or more processors to include methods for performing one or more of the methods described in the above-mentioned embodiments.
[0129] Figure 4 4 is a block diagram of an electronic device 400 according to an exemplary embodiment. For example, the electronic device 400 may be a mobile phone, a computer, a digital broadcast terminal, a messaging device, a game console, a tablet device, a medical device, a fitness device, a personal digital assistant, etc.
[0130] Reference Figure 4, the electronic device 400 may include one or more of the following components: a processing component 402 , a memory 404 , a power component 406 , a multimedia component 408 , an audio component 410 , an input / output (I / O) interface 412 , a sensor component 414 , and a communication component 416 .
[0131] The processing component 402 generally controls the overall operation of the electronic device 400, such as operations associated with display, phone calls, data communications, camera operations, and recording operations. The processing component 402 may include one or more processors 420 to execute instructions to complete all or part of the steps of the above-mentioned method. In addition, the processing component 402 may include one or more modules to facilitate the interaction between the processing component 402 and other components. For example, the processing component 402 may include a multimedia module to facilitate the interaction between the multimedia component 408 and the processing component 402.
[0132] The memory 404 is used to store various types of data to support the operation of the electronic device 400. Examples of such data include instructions for any application or method operating on the electronic device 400, contact data, phone book data, messages, pictures, multimedia, etc. The memory 404 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.
[0133] The power supply component 406 provides power to the various components of the electronic device 400. The power supply component 406 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to the electronic device 400.
[0134] The multimedia component 408 includes a screen that provides an output interface between the electronic device 400 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touch screen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touch, slide, and gestures on the touch panel. The touch sensor may not only sense the boundaries of the touch or slide action, but also detect the duration and pressure associated with the touch or slide operation. In some embodiments, the multimedia component 408 includes a front camera and / or a rear camera. When the electronic device 400 is in an operating mode, such as a shooting mode or a multimedia mode, the front camera and / or the rear camera may receive external multimedia data. Each front camera and rear camera may be a fixed optical lens system or have a focal length and optical zoom capability.
[0135] The audio component 410 is used to output and / or input audio signals. For example, the audio component 410 includes a microphone (MIC), and when the electronic device 400 is in an operation mode, such as a call mode, a recording mode, and a voice recognition mode, the microphone is used to receive an external audio signal. The received audio signal can be further stored in the memory 404 or sent via the communication component 416. In some embodiments, the audio component 410 also includes a speaker for outputting audio signals.
[0136] The input / output interface 412 provides an interface between the processing component 402 and the peripheral interface modules, which may be keyboards, click wheels, buttons, etc. These buttons may include but are not limited to: a home button, a volume button, a start button, and a lock button.
[0137] The sensor assembly 414 includes one or more sensors for providing various aspects of status assessment for the electronic device 400. For example, the sensor assembly 414 can detect the open / closed state of the electronic device 400, the relative positioning of the components, such as the display and keypad of the electronic device 400, and the sensor assembly 414 can also detect the position change of the electronic device 400 or a component of the electronic device 400, the presence or absence of contact between the user and the electronic device 400, the orientation or acceleration / deceleration of the electronic device 400, and the temperature change of the electronic device 400. The sensor assembly 414 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact. The sensor assembly 414 may also include an optical sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, the sensor assembly 414 may also include an acceleration sensor, a gyroscope sensor, a magnetic sensor, a pressure sensor, or a temperature sensor.
[0138] The communication component 416 is used to facilitate wired or wireless communication between the electronic device 400 and other devices. The electronic device 400 can access a wireless network based on a communication standard, such as WiFi, a carrier network (such as 2G, 3G, 4G or 5G), or a combination thereof. In an exemplary embodiment, the communication component 416 receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component 416 also includes a near field communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology and other technologies.
[0139] In an exemplary embodiment, the electronic device 400 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to implement the methods provided in the embodiments of the present application.
[0140] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 404 including instructions, and the instructions can be executed by a processor 420 of an electronic device 400 to perform the above method. For example, the non-transitory storage medium can be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, etc.
[0141] Figure 5 is a block diagram of an electronic device 500 according to an exemplary embodiment. For example, the electronic device 500 may be provided as a server. Figure 5 , the electronic device 500 includes a processing component 522, which further includes one or more processors, and a memory resource represented by a memory 532, for storing instructions that can be executed by the processing component 522, such as an application. The application stored in the memory 532 may include one or more modules, each corresponding to a set of instructions. In addition, the processing component 522 is configured to execute instructions to perform the method provided in the embodiment of the present application.
[0142] The electronic device 500 may further include a power supply component 526 configured to perform power management of the electronic device 500, a wired or wireless network interface 550 configured to connect the electronic device 500 to a network, and an input / output interface 558. The electronic device 500 may operate based on an operating system stored in the memory 532, such as Windows Server TM, Mac OS X TM, Unix TM, Linux TM, FreeBSD TM or the like.
[0143] An embodiment of the present application further provides a computer program product, including a computer program, which implements the method described in the above embodiment when executed by a processor.
[0144] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the application disclosed herein. The present application is intended to cover any variations, uses or adaptations of the present application, which follow the general principles of the present application and include common knowledge or customary techniques in the art that are not disclosed in the present application. The specification and examples are intended to be exemplary only, and the true scope and spirit of the present application are indicated by the following claims.
[0145] It should be understood that the present application is not limited to the precise structures that have been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.
Claims
1. A method for configuring a system memory management unit, characterized in that: The method comprises: According to the preset configuration file, corresponding external devices are allocated to each virtual machine; Acquire, from a preset table recording information of external devices, a value of a first designated data bit of an entry corresponding to the assigned external device; Before the virtual machine is started, the value of the first designated data bit is set to a preset value, and after the virtual machine is started, the value of the first designated data bit is adjusted from the preset value to a first value; the preset value is used to indicate that the configuration of the system memory management unit of the external device is in an inaccessible state; the first value is used to indicate that the configuration of the system memory management unit of the external device is in a preset state; the preset state is used to indicate that the external device can only be accessed by the virtual machine to which it belongs; When the virtual machine accesses the memory through the input operation of the external device, the physical address of the input operation is obtained, and the target memory address matching the physical address of the input operation is obtained from the correspondence between the physical address and the memory address recorded in the page table corresponding to the virtual machine to which the external device belongs; the memory address recorded in the page table is the memory address allocated to the virtual machine; The input operation is performed to access the memory according to the target memory address.
2. The method according to claim 1, characterized in that Before obtaining the target memory address matching the physical address of the input operation from the correspondence between the physical address and the memory address recorded in the page table corresponding to the virtual machine to which the external device belongs, the method further includes: When the virtual machine to which the external device belongs is started, obtaining a memory range accessible to the virtual machine; Allocating a memory address for an input operation of an external device corresponding to the virtual machine according to the accessible memory range to obtain a memory address; A correspondence between the physical address and the memory address is established, and the correspondence is written into a page table corresponding to the virtual machine to which the external device belongs.
3. The method according to claim 1, characterized in that The method further comprises: Acquire the translation mode of the external device in the preset state; The step of performing the input operation to access the memory according to the target memory address includes: The input operation accesses the memory according to the translation mode of the external device and the target memory address.
4. The method according to claim 3, characterized in that The obtaining of the translation mode of the external device in the preset state includes: When the virtual machine to which the external device belongs is started, obtaining respective values of a plurality of second designated data bits associated with the first designated data bit in the preset table; the plurality of second designated data bits are used to indicate a translation method of the external device; If the respective values of the plurality of second designated data bits constitute a first value sequence, then the translation method of the first stage is determined to be no translation, and the translation method of the second stage is also determined to be no translation; the translation method of the first stage indicates converting the virtual address into the physical address; the translation method of the second stage indicates converting the physical address into the memory address; If the respective values of the plurality of second designated data bits constitute a second value sequence, it is determined that the translation method of the first stage is not to translate, and the translation method of the second stage is to translate.
5. The method according to claim 4, characterized in that The step of performing the input operation to access the memory according to the translation mode of the external device and the target memory address includes: If the translation mode of the first stage is not to translate, and the translation mode of the second stage is also not to translate, then the physical address of the input operation is used as the target memory address, and the input operation accesses the memory; If the translation mode of the first stage is no translation and the translation mode of the second stage is translation, the physical address of the input operation is converted into the target memory address, and the input operation accesses the memory.
6. The method according to claim 1, characterized in that When the virtual machine accesses the memory through the input operation of the external device, obtaining the physical address of the input operation includes: When the virtual machine accesses the memory through the input operation of the external device, obtaining the virtual address of the input operation; The virtual address of the input operation is converted to generate a physical address of the input operation.
7. The method according to claim 1, characterized in that The virtual machine includes a root virtual machine and a non-root virtual machine; the method further includes: After starting the root virtual machine, the non-root virtual machine is started by executing a start command in the root virtual machine.
8. The method according to claim 7, characterized in that The method further comprises: A memory area reserved for the non-root virtual machine in the memory area of the root virtual machine is obtained, and the reserved memory area is marked as a reserved memory node, so that the root virtual machine stops operating on the reserved memory area.
9. A configuration device for a system memory management unit, characterized in that: The device comprises: A first allocation module, used to allocate a corresponding external device to each virtual machine according to a preset configuration file; A first acquisition module, used to acquire a value of a first designated data bit of an entry corresponding to the assigned external device from a preset table recording information of the external device; a setting module, configured to set the value of the first designated data bit to a preset value before the virtual machine is started, and to adjust the value of the first designated data bit from the preset value to a first value after the virtual machine is started; the preset value is used to indicate that the configuration of the system memory management unit of the external device is in an inaccessible state; the first value is used to indicate that the configuration of the system memory management unit of the external device is in a preset state; the preset state is used to indicate that the external device can only be accessed by the virtual machine to which it belongs; A second acquisition module is used to obtain the physical address of the input operation when the virtual machine accesses the memory through the input operation of the external device, and obtain the target memory address matching the physical address of the input operation from the correspondence between the physical address and the memory address recorded in the page table corresponding to the virtual machine to which the external device belongs; the memory address recorded in the page table is the memory address allocated to the virtual machine; An access module is used to perform the input operation to access the memory according to the target memory address.
10. An electronic device, characterized in that: include: processor; a memory for storing instructions executable by the processor; The processor is configured to execute the instructions to implement the method according to any one of claims 1 to 8.
11. A computer-readable storage medium, characterized in that: When the instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is enabled to perform the method as claimed in any one of claims 1 to 8.
Citation Information
Patent Citations
Direct storage access request processing method and device and related equipment
CN117632811A
Memory management method and related equipment
CN117827417A