Abnormality analysis method and device of system process, terminal equipment and storage medium
By listening and analyzing the status of system processes in Linux system, identifying and processing zombie processes, the memory leak problem caused by the parent process's inability to release child process resources in time is solved, and system stability is improved.
Patent Information
- Application Number
- CN202311483176.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-08
- Publication Date
- 2025-05-09
Smart Images

Figure CN119961107A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of software management, and in particular to a method, device, terminal device and storage medium for analyzing abnormalities in a system process. Background Art
[0002] In Linux systems, instances of running programs are called processes. When a process calls a function to generate another process, the original process is called the parent process, and the newly generated process is called the child process. When a process creates a child process, they run asynchronously, that is, the parent process cannot predict when the child process will end. When the child process ends, the parent process releases the resources occupied by the child process by calling a function. If the parent process is too busy and cannot process the child process in time, the child process will continue to occupy resources after it ends, forming a zombie process. Too many zombie processes will cause memory leaks in the system. How to analyze zombie processes has become an urgent problem to be solved. Summary of the invention
[0003] The main purpose of this application is to provide a method, device, equipment and computer storage medium for analyzing abnormalities in a system process, aiming to improve the stability of the system.
[0004] In a first aspect, the present application provides a method for analyzing anomalies of a system process, the method comprising the following steps:
[0005] Monitoring the process status of multiple system processes in the operating system of the terminal device to obtain process monitoring results;
[0006] Determine a target process in an abnormal state from the plurality of system processes according to the process monitoring result;
[0007] Obtaining process log information corresponding to the target process, and analyzing the process log information to obtain a process analysis result;
[0008] The abnormal reason of the target process is output according to the analysis result.
[0009] In a second aspect, the present application further provides a system process anomaly analysis device, the system process anomaly analysis device comprising:
[0010] The process monitoring module is used to monitor the process status of multiple system processes in the operating system of the terminal device and obtain the process monitoring result;
[0011] A target process determination module, used for determining an abnormal target process from a plurality of system processes according to the process monitoring result;
[0012] An information analysis module, used to obtain process log information corresponding to the target process, and analyze the process log information to obtain a process analysis result;
[0013] The root cause output module is used to output the abnormal cause of the target process according to the analysis result.
[0014] In a third aspect, the present application also provides a terminal device, comprising a processor, a memory, and a computer program stored in the memory and executable by the processor, wherein when the computer program is executed by the processor, the method for analyzing the abnormality of the system process as described above is implemented.
[0015] In a fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored, wherein when the computer program is executed by a processor, the method for analyzing anomalies of a system process as described above is implemented.
[0016] The present application provides a method, device, equipment and computer storage medium for analyzing the abnormality of a system process. The present application obtains a process monitoring result by monitoring the process status of multiple system processes in the operating system of the terminal device; determines a target process in an abnormal state from the multiple system processes according to the process monitoring result; obtains process log information corresponding to the target process, and analyzes the process log information to obtain a process analysis result; and outputs the abnormal cause of the target process according to the analysis result. The abnormal process in the system can be analyzed in time to improve the stability of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0018] Figure 1 A flowchart of a method for analyzing anomalies in a system process provided by an embodiment of the present application;
[0019] Figure 2 A schematic flow chart of sub-steps of step S103 provided in one embodiment of the present application;
[0020] Figure 3 A schematic flow chart of sub-steps of step S103 provided in another embodiment of the present application;
[0021] Figure 4A schematic block diagram of a system process abnormality analysis device provided in one embodiment of the present application;
[0022] Figure 5 This is a schematic block diagram of the structure of a terminal device involved in one embodiment of the present application. DETAILED DESCRIPTION
[0023] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0024] The flowcharts shown in the accompanying drawings are only examples and do not necessarily include all the contents and operations / steps, nor must they be executed in the order described. For example, some operations / steps may also be decomposed, combined or partially merged, so the actual execution order may change according to actual conditions.
[0025] Embodiments of the present application provide a method, apparatus, terminal device, and computer-readable storage medium for analyzing anomalies in a system process.
[0026] In conjunction with the accompanying drawings, some embodiments of the present application are described in detail below. In the absence of conflict, the following embodiments and features in the embodiments can be combined with each other.
[0027] Please refer to Figure 1 , Figure 1 A flowchart of a method for analyzing anomalies in a system process provided in an embodiment of the present application. The method for analyzing anomalies in a system process can be used in a terminal or a server to timely analyze abnormal processes in the system and improve the stability of the system. The terminal can be an electronic device such as a mobile phone, a tablet computer, a laptop computer, a desktop computer, smart glasses, a personal digital assistant, and a wearable device.
[0028] like Figure 1 As shown, the abnormality analysis method of the system process includes steps S101 to S104.
[0029] Step S101: monitor the process status of multiple system processes in the operating system of the terminal device to obtain process monitoring results.
[0030] Taking the Linux operating system of the terminal device as an example, the state of the system process can be any one of the following six states: executable state, interruptible sleep state, uninterruptible sleep state, paused state, zombie state, and dead state. Among them, each process state will be reflected in the process list in the form of a state identifier, for example, R represents executable state, S represents interruptible sleep state, D represents uninterruptible sleep state, T represents paused state, Z represents zombie state, and X represents dead state.
[0031] Exemplarily, the process status of each system process in the operating system is read every preset monitoring period, which may be 1 minute, for example. The status identifier of each system process is obtained every 1 minute so that the process status of the system process can be monitored according to the status identifier, and problems existing in each process in the operating system can be promptly checked to improve the stability of the system.
[0032] In some embodiments, the monitoring of the process status of multiple system processes in the operating system of the terminal device includes: determining the system type of the operating system of the terminal device, and determining a monitoring strategy for monitoring the process status based on the system type; monitoring multiple system processes in the operating system based on the monitoring strategy to obtain the process monitoring results.
[0033] Exemplarily, the process identifiers used in different system types are different, and the logic for monitoring the process status is different. Therefore, when executing step S101, it is necessary to first determine the system type of the operating system. The system type of the operating system is not limited here. For example, it can be a Linux system, or a Windows system, a Mac system, etc., which is not limited here.
[0034] For example, the monitoring strategies for identifying abnormal processes in operating systems of different system types are different. In Unix-like systems such as Linux, abnormal processes are monitored by identifying processes with status identification Z. In other systems, abnormal processes can be identified in different ways. In Windows systems, whether a process is abnormal can be determined by monitoring the size of memory occupied by the process. This is not limited here.
[0035] Exemplarily, by matching the monitoring strategy according to the system type, the method for analyzing the anomaly of the system process provided in the embodiment of the present application can be applied to different types of operating systems, thereby improving the flexibility of the anomaly analysis.
[0036] Step S102: determining a target process in an abnormal state from the plurality of system processes according to the process monitoring result.
[0037] Exemplarily, in order to identify and analyze zombie processes in the operating system, the system process with process ID Z is determined as the target process in an abnormal state. Specifically, the target process with process ID Z or Z+ is determined from the system processes through the ps aux|grep'Z' instruction.
[0038] For example, in Linux systems, processes are managed by a Process Control Block (PCB). When a child process ends, the parent process needs to release the resources occupied by the child process by calling the wait function or the waitpid function. If the parent process does not have time to release the resources occupied by the child process in time when the child process ends, the PCB will continue to maintain the child process that has ended, and the child process becomes a zombie process. In addition, since the zombie process is a process that has ended, it is impossible to release the resources occupied by it by calling the kill function like a normal process.
[0039] Therefore, if there are many zombie processes in the operating system, a large amount of system resources will be wasted, affecting the stability of the system. Through the abnormal analysis method of the system process provided by the embodiment of the present application, the zombie process is analyzed and processed in time to prevent too many zombie processes in the system from affecting the normal operation of the system.
[0040] Step S103: Obtain process log information corresponding to the target process, and analyze the process log information to obtain a process analysis result.
[0041] It is understandable that the child process becomes a zombie process because the parent process cannot call the function to release system resources in time, which reflects that there may be problems with the operation of the parent process. In order to prevent the same problem from causing more zombie processes, the corresponding parent process can be analyzed based on the currently existing zombie processes.
[0042] In some embodiments, obtaining the process log information corresponding to the target process includes at least one of the following: when the number of target processes whose process status is abnormal is greater than or equal to a preset number, filtering the log information according to the abnormal target processes to obtain the process log information; when the ratio of the number of target processes whose process status is abnormal to the total number of processes is greater than or equal to a preset ratio, filtering the log information according to the abnormal target processes to obtain the process log information; when the duration of the process status of the target process being in an abnormal state is greater than or equal to a preset duration, filtering the log information according to the abnormal target processes to obtain the process log information.
[0043] For example, after the child process ends and waits for the parent process to call the wait or waitpid function to release system resources, the child process will be in a zombie state until the parent process calls the corresponding function, and the process state of the child process returns to normal. Therefore, any terminated process may be in a zombie state for a short time. Only when the duration of the process in the zombie state is greater than or equal to a certain preset time, it is necessary to analyze the target process in the zombie state.
[0044] Exemplarily, whether it is necessary to analyze the target process in the zombie state may also be determined based on the number of target processes in the zombie state or the proportion of the target processes in all processes.
[0045] By determining whether it is necessary to analyze the target process in the zombie state through certain preset conditions, it is avoided to analyze the process log information too frequently, the amount of calculation is reduced, and the rationality of the abnormal analysis method of the system process provided in the embodiment of the present application is improved.
[0046] In some embodiments, obtaining the process log information corresponding to the target process includes: determining a target moment when the process state of the target process switches to the abnormal state; and determining the log information between a first preset moment before the target moment and a second preset moment after the target moment as the process log information.
[0047] For example, the log information of the Linux system (including syslog, dmesg, messages and other log information in the system) records various operations and events in the system, including but not limited to system startup, shutdown, restart, process start, stop, etc. Therefore, the amount of data in the log information in the system may be very large.
[0048] In order to improve the relevance of the log information to the abnormal target process, the log information for a period of time before and after the target time is determined as the process log information related to the target process.
[0049] Specifically, the first preset time may be a time 1 minute before the target time, and the second preset time may be a time 1 minute after the target time, and the log information between 1 minute before and after the process state of the target process switches to the abnormal state is determined as the process log information through the catch log function. Of course, it is not limited to this, and the first preset time and the second preset time may also be other times before and after the target time, respectively, which is not limited here.
[0050] Please refer to Figure 2 , Figure 2 A flowchart of sub-steps of step S103 is provided for one embodiment of the present application.
[0051] like Figure 2 As shown, in some embodiments, the process log information is analyzed to obtain a process analysis result, including: step S1031, identifying preset keywords in the process log information to obtain the target parent process of the target process; step S1032, executing a preset test program for the target parent process; step S1033, outputting the health status of the target parent process according to the execution result of the test program.
[0052] For example, the parent process cannot handle the end of the child process in time, which may be due to an abnormality in the parent process itself, and cannot respond to the message of the child process ending in time. In order to identify this situation, the target parent process corresponding to the target process can be tested to determine the health status of the target parent process, and then determine the cause of the zombie process, so as to avoid the emergence of more zombie processes due to the abnormality of the parent process.
[0053] Among them, the preset keywords in the process log information are identified to obtain the target parent process of the target process. For example, the parent-child relationship between processes can be checked through the pstree -p command to determine which process is the parent process of the target process in the zombie state.
[0054] In some embodiments, executing a preset test program for the target parent process includes: sending socket information to the target parent process based on the process identifier of the target parent process; and determining the health status of the target parent process according to response information generated by the target parent process based on the socket information.
[0055] Exemplarily, by sending socket information to the target parent process, it is determined whether the health status of the target parent process is normal. If the target parent process can return correct response information according to the received socket information, the health status of the target parent process is considered normal; conversely, if the target parent process does not respond after receiving the socket information, or the returned response is abnormal, the health status of the target parent process is considered abnormal.
[0056] Specifically, the received response information may be compared with the preset response information. If the two match, it is considered that the health status of the target parent process is normal.
[0057] Exemplarily, by testing the target parent process corresponding to the zombie process, the abnormal parent process can be promptly detected to avoid the generation of more zombie processes due to the abnormality of the parent process, thereby improving the stability of the system.
[0058] Please refer to Figure 3 , Figure 3A flowchart of sub-steps of step S103 is provided for another embodiment of the present application.
[0059] like Figure 3 As shown, in some embodiments, the process log information is analyzed to obtain a process analysis result, and further includes: step S1131, determining, based on the process log information, a target task that occupies the target parent process during the period when the target process switches to an abnormal state; step S1132, determining the task information related to the target task as the process analysis result.
[0060] Exemplarily, the target parent process did not process the terminated child process in time, which may also be because the target parent process was busy at the time and could not instruct the PCB to release the resources of the terminated child process, causing the terminated child process to become a zombie process. In order to investigate this situation, the task that the target parent process was processing at the time, such as interaction with other processes, interaction with the PCB, etc., can be identified based on the process log information when the child process changes to the zombie state, and the task information of the task can be output for further analysis by the user. Specifically, the task information can be the task name, the name of the target object of the interaction, etc., which is not limited here.
[0061] Exemplarily, identifying the target task that occupies the target parent process during the period when the target process switches to an abnormal state makes it easier for the user to confirm the rationality of the target task and improves the efficiency of the user in performing abnormal analysis.
[0062] Step S104: output the abnormal reason of the target process according to the analysis result.
[0063] Exemplarily, the output abnormal reason may be that there is a problem with the health status of the target parent process, or the target parent process is occupied by other tasks. Furthermore, task information of the target task occupying the target parent process may also be output, which is not limited here.
[0064] Exemplarily, by outputting the abnormal reason according to the analysis result, the user can clearly and intuitively understand the reason for the emergence of the zombie process, thereby improving the user experience.
[0065] The method for analyzing the abnormality of the system process provided in the above embodiment monitors the process status of multiple system processes in the operating system of the terminal device to obtain the process monitoring result; determines the target process in the abnormal state from the multiple system processes according to the process monitoring result; obtains the process log information corresponding to the target process, and analyzes the process log information to obtain the process analysis result; outputs the abnormal reason of the target process according to the analysis result. It can timely analyze the abnormal processes in the system and improve the stability of the system.
[0066] See also Figure 4 , Figure 4 It is a schematic diagram of a system process anomaly analysis device provided in an embodiment of the present application. The system process anomaly analysis device can be configured in a server or a terminal to execute the aforementioned system process anomaly analysis method.
[0067] like Figure 4 As shown, the abnormal analysis device of the system process includes: a process monitoring module 110, a target process determination module 120, an information analysis module 130, and a root cause output module 140.
[0068] The process monitoring module 110 is used to monitor the process status of multiple system processes in the operating system of the terminal device to obtain the process monitoring result;
[0069] A target process determination module 120, configured to determine an abnormal target process from a plurality of system processes according to the process monitoring result;
[0070] The information analysis module 130 is used to obtain the process log information corresponding to the target process, and analyze the process log information to obtain a process analysis result;
[0071] The root cause output module 140 is used to output the abnormal cause of the target process according to the analysis result.
[0072] It should be noted that those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described devices and modules and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0073] The method and apparatus of the present application can be used in many general or special computing system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronic devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, etc. The present application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application can also be practiced in distributed computing environments, in which tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
[0074] Exemplarily, the above method and apparatus may be implemented in the form of a computer program. The computer program may be implemented in Figure 5 Run on the terminal device shown.
[0075] See also Figure 5 , Figure 5 A schematic block diagram of the structure of a terminal device provided in an embodiment of the present application. The terminal device may be a server or a terminal.
[0076] like Figure 5 As shown, the terminal device includes a processor, a memory and a network interface connected via a system bus, wherein the memory may include a storage medium and an internal memory.
[0077] The storage medium can store an operating system and a computer program. The computer program includes program instructions, and when the program instructions are executed, the processor can execute any system process abnormality analysis method.
[0078] The processor is used to provide computing and control capabilities to support the operation of the entire terminal device.
[0079] The internal memory provides an environment for the operation of the computer program in the storage medium. When the computer program is executed by the processor, the processor can execute any abnormality analysis method of the system process.
[0080] The network interface is used for network communication, such as sending assigned tasks, etc. Those skilled in the art will understand that Figure 5 The structure shown in the figure is only a block diagram of a partial structure related to the scheme of the present application, and does not constitute a limitation on the terminal device to which the scheme of the present application is applied. The specific terminal device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0081] It should be understood that the processor may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0082] In one embodiment, the processor is used to run a computer program stored in the memory to implement the following steps:
[0083] Monitoring the process status of multiple system processes in the operating system of the terminal device to obtain process monitoring results;
[0084] Determine a target process in an abnormal state from the plurality of system processes according to the process monitoring result;
[0085] Obtaining process log information corresponding to the target process, and analyzing the process log information to obtain a process analysis result;
[0086] The abnormal reason of the target process is output according to the analysis result.
[0087] It should be noted that technical personnel in the relevant field can clearly understand that, for the convenience and conciseness of description, the specific working process of the above-mentioned description of the abnormal analysis of the system process can refer to the corresponding process in the aforementioned system process abnormal analysis control method embodiment, and will not be repeated here.
[0088] An embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored. The computer program includes program instructions. The method implemented when the program instructions are executed can refer to the various embodiments of the method for analyzing the abnormality of the system process of the present application.
[0089] The computer-readable storage medium may be an internal storage unit of the terminal device described in the foregoing embodiment, such as a hard disk or memory of the terminal device. The computer-readable storage medium may also be an external storage device of the terminal device, such as a plug-in hard disk, a smart memory card (Smart Media Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (Flash Card), etc., equipped on the terminal device.
[0090] It should be understood that the terms used in this application specification are only for the purpose of describing specific embodiments and are not intended to limit the application. As used in this application specification and the appended claims, unless the context clearly indicates otherwise, the singular forms "a", "an" and "the" are intended to include plural forms.
[0091] It should also be understood that the term "and / or" used in the specification of this application and the appended claims refers to any combination of one or more of the associated listed items and all possible combinations, including these combinations. It should be noted that, in this article, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or system including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or system. In the absence of further restrictions, an element defined by the sentence "including a..." does not exclude the presence of other identical elements in the process, method, article or system including the element.
[0092] The serial numbers of the embodiments of the present application are for description only and do not represent the advantages and disadvantages of the embodiments. The above description is only a specific implementation mode of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of various equivalent modifications or replacements within the technical scope disclosed in the present application, and these modifications or replacements should be included in the protection scope of the present application. Therefore, the protection scope of the present application shall be based on the protection scope of the claims.
Claims
1. A method for analyzing abnormality of a system process, characterized in that: Applied to a terminal device, the method comprises: Monitoring the process status of multiple system processes in the operating system of the terminal device to obtain process monitoring results; Determine a target process in an abnormal state from the plurality of system processes according to the process monitoring result; Obtaining process log information corresponding to the target process, and analyzing the process log information to obtain a process analysis result; The abnormal reason of the target process is output according to the analysis result.
2. The method for analyzing abnormality of a system process according to claim 1, characterized in that: The monitoring of the process status of multiple system processes in the operating system of the terminal device includes: Determining a system type of an operating system of the terminal device, and determining a monitoring strategy for monitoring the process status according to the system type; Based on the monitoring strategy, multiple system processes in the operating system are monitored to obtain the process monitoring result.
3. The method for analyzing abnormality of a system process according to claim 1, characterized in that: The obtaining of process log information corresponding to the target process includes at least one of the following: When the number of target processes in the abnormal process state is greater than or equal to a preset number, filtering the log information according to the abnormal target processes to obtain the process log information; When the ratio of the number of target processes in abnormal process status to the total number of processes is greater than or equal to a preset ratio, filtering the log information according to the abnormal target processes to obtain the process log information; When the duration of the process state of the target process being in an abnormal state is greater than or equal to a preset duration, the log information is filtered according to the abnormal target process to obtain the process log information.
4. The method for analyzing abnormality of a system process according to claim 1, characterized in that: The obtaining process log information corresponding to the target process includes: Determine a target time at which the process state of the target process switches to the abnormal state; The log information between a first preset time before the target time and a second preset time after the target time is determined as the process log information.
5. The method for analyzing abnormality of a system process according to claim 1, characterized in that: The analyzing the process log information to obtain a process analysis result includes: Identify preset keywords in the process log information to obtain a target parent process of the target process; Executing a preset test program for the target parent process; According to the execution result of the test program, the health status of the target parent process is output.
6. The method for analyzing abnormality of a system process according to claim 5, characterized in that: The executing a preset test program for the target parent process includes: Based on the process identifier of the target parent process, sending socket information to the target parent process; The health status of the target parent process is determined according to the response information generated by the target parent process based on the socket information.
7. The method for analyzing abnormality of a system process according to claim 5, characterized in that: The analyzing the process log information to obtain the process analysis result also includes: Determine, according to the process log information, a target task occupying the target parent process during the period when the target process switches to an abnormal state; The task information related to the target task is determined as the process analysis result.
8. A system process abnormality analysis device, characterized in that: The abnormality analysis device of the system process includes: The process monitoring module is used to monitor the process status of multiple system processes in the operating system of the terminal device and obtain the process monitoring result; A target process determination module, used for determining an abnormal target process from a plurality of system processes according to the process monitoring result; An information analysis module, used to obtain process log information corresponding to the target process, and analyze the process log information to obtain a process analysis result; The root cause output module is used to output the abnormal cause of the target process according to the analysis result.
9. A terminal device, characterized in that: The terminal device includes a processor, a memory, and a computer program stored in the memory and executable by the processor, wherein when the computer program is executed by the processor, the steps of the method for analyzing the abnormality of the system process as described in any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein when the computer program is executed by a processor, the steps of the method for analyzing anomalies of a system process according to any one of claims 1 to 7 are implemented.