Fault diagnosis method, device, equipment, vehicle, storage medium and program product

By intercepting and recording memory release and access operations in the driving assistance system, the time-consuming and labor-intensive software troubleshooting in the system is solved, and fast and accurate fault diagnosis and positioning are achieved.

CN119961191APending Publication Date: 2025-05-09CHONGQING CHANGAN TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510028056.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-08
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

Software failures in driving assistance systems, especially memory corruption, are time-consuming and labor-intensive to troubleshoot and difficult to find the source of the failure.

Method used

By intercepting memory release operations and memory access operations in the driving assistance system, record relevant information and set protection flags to achieve fault diagnosis and rapid location.

Benefits of technology

Without changing the driving assistance system code, we can realize the diagnosis of faults, reduce the code intrusion of the assisted driving system, quickly and accurately find the first scene of illegal access to memory, and reduce the time and manpower of troubleshooting.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119961191A_ABST
    Figure CN119961191A_ABST
Patent Text Reader

Abstract

The invention relates to a fault diagnosis method, device and equipment, a vehicle, a storage medium and a program product. The fault diagnosis method comprises the steps that in response to intercepted memory release operation of a target process in the driving assistance system, memory release information corresponding to a first address to be released is recorded into a first diagnosis information set, and a protection mark corresponding to a first memory page is set; the first address belongs to the first memory page; in response to the intercepted memory access operation for the first memory page, determining an accessed second address in the first memory page, the memory access operation being intercepted based on a protection mark corresponding to the first memory page; and under the condition that the memory release information corresponding to the second address exists in the first diagnosis information set, sending a fault signal, and recording the memory access information corresponding to the second address into the second diagnosis information set. In this way, code intrusion to the auxiliary driving system can be reduced, and the first site which illegally accesses the memory can be quickly, accurately and automatically found out.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a fault diagnosis method, apparatus, equipment, vehicle, storage medium and program product. Background Art

[0002] Driving assistance systems, such as Advanced Driving Assistance Systems (ADAS), are a general term for various systems that use sensors, communication devices, decision-making and execution devices installed on the vehicle to monitor the driver, vehicle and its driving environment in real time, and assist the driver in performing driving tasks or actively avoiding / mitigating collision hazards through information and / or motion control. The operating environment of the driving assistance system is usually limited in software and hardware resources. At the same time, the components of the driving assistance system are very complex, including software codes developed by the OEM, software codes from the open source community, software codes delivered by suppliers in white boxes, and software components delivered by suppliers in black boxes (including independent executable programs, dynamically loaded libraries, etc.). Therefore, software failures in driving assistance systems, especially memory corruption failures (such as access after release, repeated release, etc.) are time-consuming and laborious to troubleshoot, and it is difficult to find the source of the failure. Summary of the invention

[0003] The present application at least provides a fault diagnosis method, device, equipment, vehicle, storage medium and program product to improve the problem that troubleshooting of driving assistance systems in the prior art is time-consuming and labor-intensive and difficult to find the source of the fault, and can reduce code intrusion into the assisted driving system.

[0004] In order to achieve the above purpose, the technical solution adopted in this application is as follows:

[0005] A fault diagnosis method, the method comprising:

[0006] In response to intercepting a memory release operation of a target process in a driving assistance system, recording memory release information corresponding to a first address to be released into a first diagnostic information set, and setting a protection flag corresponding to a first memory page; the first address belongs to the first memory page;

[0007] In response to intercepting a memory access operation to a first memory page, determining a second address accessed in the first memory page, the memory access operation being intercepted based on a protection flag corresponding to the first memory page;

[0008] When the memory release information corresponding to the second address exists in the first diagnostic information set, a fault signal is sent, and the memory access information corresponding to the second address is recorded in the second diagnostic information set.

[0009] According to the above-mentioned technical means, in response to intercepting a memory release operation of a target process in a driving assistance system, memory release information corresponding to a first address to be released is recorded in a first diagnostic information set, and a protection flag corresponding to a first memory page to which the first address belongs is set; in response to intercepting a memory access operation to a first memory page, a second address accessed in the first memory page is determined, and the memory access operation is intercepted based on the protection flag corresponding to the first memory page; in the case where there is memory release information corresponding to the second address in the first diagnostic information set, a fault signal is sent, and the memory access information corresponding to the second address is recorded in a second diagnostic information set. In this way, on the one hand, by intercepting memory release operations and memory access operations in the driving assistance system, fault diagnosis can be achieved without changing the driving assistance system code, thereby reducing code intrusion into the assisted driving system; on the other hand, by recording the memory release information corresponding to the first address to be released into the first diagnostic information set, and sending a fault signal when there is memory release information corresponding to the second address to be accessed in the first diagnostic information set, and recording the memory access information corresponding to the second address into the second diagnostic information set, the first scene of illegal memory access can be automatically found quickly and accurately, thereby reducing the time and manpower consumed in troubleshooting the driving assistance system; on another hand, by responding to the memory release operation of the target process intercepted in the driving assistance system, setting a protection flag corresponding to the first memory page to which the first address belongs, and intercepting the memory access operation for the first memory page based on the protection flag, the memory access operation can be intercepted without relying on monitoring of a specific memory access function.

[0010] In some embodiments, setting a protection flag corresponding to a first memory page includes: determining a physical page corresponding to the first memory page; and setting a protection flag for the physical page corresponding to the first memory page.

[0011] According to the above technical means, a protection flag is set for the physical page corresponding to the first memory page, which can simplify the implementation logic and intercept the memory access operation efficiently and timely.

[0012] In some embodiments, setting a protection flag corresponding to the first memory page also includes: setting a diagnostic flag for the first memory page; the method also includes: in response to intercepting a page fault interrupt corresponding to the second address, determining whether the first memory page to which the second address belongs has a diagnostic flag; if the first memory page has the diagnostic flag, determining that a memory access operation to the first memory page is intercepted.

[0013] According to the above technical means, after intercepting the memory release operation, a diagnostic flag is set for the corresponding memory page, and by using the hardware-based page fault interrupt mechanism, by intercepting the page fault interrupt and judging whether the address where the page fault interrupt occurs belongs to a memory page with a diagnostic flag, it is possible to simply and quickly determine whether the memory access operation to the memory page to be diagnosed is intercepted. In addition, since the additional memory resources occupied during the fault diagnosis process are less, it can be better applied to application scenarios with limited memory resources.

[0014] In some embodiments, the method also includes: when there is no memory release information corresponding to the second address in the first diagnostic information set, canceling the protection flag corresponding to the first memory page and setting a diagnostic breakpoint for the next instruction in the process; when it is determined that the next instruction enters the diagnostic breakpoint, determining the third address accessed in the next instruction; when the second memory page to which the third address belongs has a diagnostic flag, setting the protection flag corresponding to the second memory page.

[0015] According to the above technical means, when there is no memory release information corresponding to the second address in the first diagnostic information set, it indicates that the memory corresponding to the second address has not undergone a memory release operation, and thus the current access is legal. Therefore, by canceling the protection flag corresponding to the first memory page, the access can be carried out normally. In addition, by setting a diagnostic breakpoint for the next instruction in the process, and when the next instruction enters the diagnostic breakpoint, it is determined whether the second memory page to which the accessed third address belongs has a diagnostic flag, and when the second memory page has a diagnostic flag, a protection flag corresponding to the second memory page is set, so that the memory access operation corresponding to the memory page to be diagnosed can be continuously intercepted, thereby reducing the omission of faults and improving the accuracy of fault diagnosis.

[0016] In some embodiments, the memory release information corresponding to the first address to be released is recorded in the first diagnostic information set, including: recording the memory release information corresponding to the first address to be released in the first diagnostic information set, and setting a corresponding aging timer for the first address; the method also includes: obtaining at least one memory page to be diagnosed that currently has a to-be-diagnosed flag; for each memory page to be diagnosed, determining at least one first target memory address with an aging timer in the memory page to be diagnosed, and when the aging timer corresponding to each first target memory address ends on time, deleting the diagnostic flag and protection flag of the memory page to be diagnosed, and releasing the memory page to be diagnosed.

[0017] According to the above technical means, a corresponding aging timer is set for the first address to be released, and when each first target memory address with an aging timer in the memory page to be diagnosed has expired on time, the diagnosis flag and protection flag of the memory page to be diagnosed are deleted, and the memory page to be diagnosed is released. In this way, the memory can be released in time, reducing the occupation of software and hardware resources during the fault diagnosis process.

[0018] In some embodiments, setting a protection flag corresponding to the first memory page includes: determining a mirrored memory page corresponding to the first memory page in a mirrored virtual memory space, the mirrored virtual memory space having a different memory addressing range from that of the target process; and setting a protection flag for a physical page corresponding to the mirrored memory page.

[0019] According to the above technical means, a mirror memory page corresponding to the first memory page is synchronously set in the mirror virtual memory space, and a protection flag is set for the physical page corresponding to the mirror memory page, which can reduce interference with the processing logic in the native memory space (referring to the memory addressing range of the target process) and interference with business operations in the driving assistance system.

[0020] In some embodiments, the method also includes: synchronizing the memory content of at least one memory page to be diagnosed to the mirrored virtual memory space at a preset synchronization time interval, and the memory page to be diagnosed has a diagnostic flag; in response to intercepting a memory access operation to the first memory page, determining the second address accessed in the first memory page, including: in response to intercepting a page fault interrupt corresponding to a fourth address in the mirrored memory page, determining that a memory access operation to the first memory page is intercepted; based on the fourth address, determining the second address accessed in the first memory page.

[0021] According to the above technical means, by periodically synchronizing the memory content of at least one memory page to be diagnosed to the mirror virtual memory space, and when a page fault interrupt corresponding to the fourth address in the mirror memory page is intercepted, it is determined that a memory access operation to the first memory page is intercepted, and the second address accessed in the first memory page is determined based on the fourth address, and whether an illegal access occurs is determined based on the second address, thereby achieving fault diagnosis. In this way, by periodically synchronizing the memory content to the mirror virtual memory space to detect whether a memory access operation to the first memory page is intercepted, there is no need to intercept the memory access operation in real time, which can reduce interference with the operation of services in the driving assistance system and reduce the occupation of processor resources during the fault diagnosis process. In addition, since the occupation of processor resources during the fault diagnosis process is less, it can be better applied to application scenarios with limited processor resources, and improve the performance of the processor in processing services in the driving assistance system.

[0022] In some embodiments, the memory release information corresponding to the first address to be released is recorded in the first diagnostic information set, including: recording the memory release information corresponding to the first address to be released in the first diagnostic information set, and setting a corresponding aging timer for the fifth address in the mirrored virtual memory space, the fifth address corresponding to the first address; the method also includes: for each memory page in the mirrored virtual memory space, determining at least one second target memory address with an aging timer in the memory page, and when the aging timer corresponding to each second target memory address expires on time, deleting the protection flag of the memory page and releasing the memory page.

[0023] According to the above technical means, a corresponding aging timer is set for the fifth address corresponding to the first address to be released in the mirror virtual memory space, and when each first target memory address with an aging timer in the memory page in the mirror virtual memory space has expired on time, the protection flag of the memory page is deleted and the memory page is released. In this way, the memory in the mirror virtual memory space can be released in time, reducing the occupation of software and hardware resources in the fault diagnosis process.

[0024] In some embodiments, in response to intercepting a memory release operation of a target process in a driving assistance system, memory release information corresponding to a first address to be released is recorded in a first diagnostic information set, including: in response to intercepting a memory release operation of a target process in a driving assistance system, determining whether the target process belongs to a list of processes to be diagnosed; if the target process belongs to the list of processes to be diagnosed, recording the memory release information corresponding to the first address to be released in the first diagnostic information set.

[0025] According to the above technical means, the process to be diagnosed is screened by using the list of processes to be diagnosed, which can better meet the fault diagnosis needs and reduce the occupation of software and hardware resources during the fault diagnosis process.

[0026] In some embodiments, the method further includes: in response to intercepting an exit operation of the target process, dumping fault diagnosis information into a set diagnosis result file, the fault diagnosis information including the first diagnostic information set and / or the second diagnostic information set.

[0027] According to the above technical means, after the target process exits, the recorded fault diagnosis information can be dumped into a diagnosis result file, thereby facilitating the investigation of the cause of the fault.

[0028] In some embodiments, the fault diagnostic information includes a first diagnostic information set, a second diagnostic information set and / or a third diagnostic information set; the method also includes: in response to intercepting a memory allocation operation of the target process, recording the memory allocation information corresponding to the sixth address to be allocated into the third diagnostic information set.

[0029] According to the above-mentioned technical means, by intercepting the memory allocation operation of the target process, the memory allocation information corresponding to the sixth address to be allocated is recorded in the third diagnostic information set, and the first diagnostic information set, the second diagnostic information set and / or the third diagnostic information set are dumped to the diagnostic result file after the target process exits. It can provide a richer and more comprehensive reference basis for troubleshooting, thereby improving the efficiency and accuracy of troubleshooting.

[0030] A fault diagnosis device, comprising:

[0031] a first interception module, configured to, in response to intercepting a memory release operation of a target process in the driving assistance system, record memory release information corresponding to a first address to be released into a first diagnostic information set, and set a protection flag corresponding to a first memory page; the first address belongs to the first memory page;

[0032] a second interception module, configured to determine a second address accessed in the first memory page in response to intercepting a memory access operation to the first memory page, the memory access operation being intercepted based on a protection flag corresponding to the first memory page;

[0033] The sending module is used to send a fault signal when there is memory release information corresponding to the second address in the first diagnostic information set, and record the memory access information corresponding to the second address into the second diagnostic information set.

[0034] According to the above technical means, on the one hand, by intercepting memory release operations and memory access operations in the driving assistance system, fault diagnosis can be achieved without changing the driving assistance system code, thereby reducing code intrusion into the assisted driving system; on the other hand, by recording the memory release information corresponding to the first address to be released into the first diagnostic information set, and sending a fault signal when there is memory release information corresponding to the second address to be accessed in the first diagnostic information set, and recording the memory access information corresponding to the second address into the second diagnostic information set, the first scene of illegal memory access can be automatically found quickly and accurately, thereby reducing the time and manpower consumed in troubleshooting the driving assistance system; on another hand, by responding to the memory release operation of the target process intercepted in the driving assistance system, setting a protection flag corresponding to the first memory page to which the first address belongs, and intercepting the memory access operation for the first memory page based on the protection flag, the memory access operation can be intercepted without relying on monitoring of a specific memory access function.

[0035] A computer device comprises a memory and a processor, wherein the memory stores a computer program that can be run on the processor, and the processor implements the steps in the above method when executing the program.

[0036] A vehicle, characterized by comprising the above-mentioned computer device.

[0037] A computer-readable storage medium stores a computer program, which implements the steps in the above method when executed by a processor.

[0038] A computer program product includes a computer program or instructions. When the computer program or instructions are executed by a processor, the steps in the method in the above embodiment are implemented.

[0039] Beneficial effects of this application:

[0040] According to the above technical means, on the one hand, by intercepting memory release operations and memory access operations in the driving assistance system, fault diagnosis can be achieved without changing the driving assistance system code, thereby reducing code intrusion into the assisted driving system; on the other hand, by recording the memory release information corresponding to the first address to be released into the first diagnostic information set, and sending a fault signal when there is memory release information corresponding to the second address to be accessed in the first diagnostic information set, and recording the memory access information corresponding to the second address into the second diagnostic information set, the first scene of illegal memory access can be automatically found quickly and accurately, thereby reducing the time and manpower consumed in troubleshooting the driving assistance system; on another hand, by responding to the memory release operation of the target process intercepted in the driving assistance system, setting a protection flag corresponding to the first memory page to which the first address belongs, and intercepting the memory access operation for the first memory page based on the protection flag, the memory access operation can be intercepted without relying on monitoring of a specific memory access function.

[0041] Setting a protection flag for the physical page corresponding to the first memory page can simplify the implementation logic and can efficiently and timely intercept the memory access operation.

[0042] After intercepting the memory release operation, a diagnostic flag is set for the corresponding memory page, and by using the hardware-based page fault interrupt mechanism, by intercepting the page fault interrupt and judging whether the address where the page fault interrupt occurs belongs to a memory page with a diagnostic flag, it is possible to simply and quickly determine whether the memory access operation to the memory page to be diagnosed is intercepted. In addition, since the additional memory resources occupied during the fault diagnosis process are less, it can be better applied to application scenarios with limited memory resources.

[0043] The memory access operations corresponding to the memory pages to be diagnosed can be continuously intercepted to reduce the omission of faults and improve the accuracy of fault diagnosis.

[0044] The memory can be released in time to reduce the usage of software and hardware resources during the fault diagnosis process.

[0045] A mirror memory page corresponding to the first memory page can be synchronously set in the mirror virtual memory space, and a protection flag can be set for the physical page corresponding to the mirror memory page to reduce interference with the processing logic in the native memory space and interference with business operations in the driving assistance system.

[0046] By periodically synchronizing memory contents to the mirrored virtual memory space to detect whether memory access operations to the first memory page are intercepted, there is no need to intercept memory access operations in real time, which can reduce interference with business operations in the driver assistance system and reduce the occupation of processor resources during the fault diagnosis process. In addition, since the occupation of processor resources during the fault diagnosis process is small, it can be better applied to application scenarios with limited processor resources and improve the performance of the processor in processing business in the driver assistance system.

[0047] The memory in the mirror virtual memory space can be released in time, reducing the usage of software and hardware resources during the fault diagnosis process.

[0048] By using the process list to be diagnosed to filter the processes for fault diagnosis, the fault diagnosis requirements can be better met and the usage of software and hardware resources can be reduced during the fault diagnosis process.

[0049] After the target process exits, the recorded fault diagnosis information can be dumped to the diagnosis result file, thereby facilitating the troubleshooting of the fault cause.

[0050] By intercepting the memory allocation operation of the target process, recording the memory allocation information corresponding to the sixth address to be allocated into the third diagnostic information set, and dumping the first diagnostic information set, the second diagnostic information set and / or the third diagnostic information set to the diagnostic result file after the target process exits, a richer and more comprehensive reference basis can be provided for troubleshooting, thereby improving the efficiency and accuracy of troubleshooting. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1 A schematic diagram of an implementation flow of a fault diagnosis method provided in an embodiment of the present application;

[0052] Figure 2 A schematic diagram of an implementation architecture of a fault diagnosis device provided in an embodiment of the present application;

[0053] Figure 3 A schematic diagram of a process flow for loading configuration information provided in an embodiment of the present application;

[0054] Figure 4 A schematic diagram of an implementation flow of a service loading process provided in an embodiment of the present application;

[0055] Figure 5 A schematic diagram of a process flow for implementing a service exit process provided in an embodiment of the present application;

[0056] Figure 6 A schematic diagram of an implementation flow of a memory allocation process based on a page fault interrupt provided in an embodiment of the present application;

[0057] Figure 7 A schematic diagram of an implementation flow of a memory allocation process based on a mirrored VMA provided in an embodiment of the present application;

[0058] Figure 8 A schematic diagram of a process flow for implementing memory release processing based on page fault interruption provided in an embodiment of the present application;

[0059] Fig. 9 A schematic diagram of an implementation flow of a memory release process based on a mirror VMA provided in an embodiment of the present application;

[0060] Fig.10 A schematic diagram of a process flow for implementing memory aging processing based on page fault interruption provided in an embodiment of the present application;

[0061] Fig.11 A schematic diagram of an implementation flow of a memory aging process based on a mirrored VMA provided in an embodiment of the present application;

[0062] Fig.12 A schematic diagram of an implementation flow of memory access processing based on page fault interruption provided in an embodiment of the present application;

[0063] Fig.13 A schematic diagram of a process flow for implementing breakpoint processing in a memory access processing process based on a page fault interrupt provided in an embodiment of the present application;

[0064] Fig.14 A schematic diagram of an implementation flow of a memory aging process based on a mirrored VMA provided in an embodiment of the present application;

[0065] Fig.15 A schematic diagram of the structure of a fault diagnosis device provided in an embodiment of the present application;

[0066] Fig.16 A schematic diagram of the structure of a vehicle provided in an embodiment of the present application. DETAILED DESCRIPTION

[0067] The following will describe the implementation of the present application with reference to the accompanying drawings and exemplary embodiments. Those skilled in the art can easily understand other advantages and effects of the present application from the contents disclosed in this specification. The present application can also be implemented or applied through other different specific implementations, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present application. It should be understood that the exemplary embodiments are only for illustrating the present application, not for limiting the scope of protection of the present application.

[0068] It should be noted that in the following description, "some embodiments" are involved, which describe a subset of all possible embodiments, but it is understood that "some embodiments" can be the same subset or different subsets of all possible embodiments, and can be combined with each other without conflict. The terms "first / second / third" involved are only used to distinguish similar objects and do not represent a specific order for the objects. It is understandable that "first / second / third" can be interchanged in a specific order or sequence where permitted, so that the embodiments of the present application described here can be implemented in an order other than that illustrated or described here.

[0069] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which this application belongs. The terms used herein are only for the purpose of describing this application and are not intended to limit this application.

[0070] An embodiment of the present application provides a fault diagnosis method, which can be executed by a processor of a computer device. Figure 1 A schematic diagram of the implementation flow of a fault diagnosis method provided in an embodiment of the present application is shown in FIG. Figure 1 As shown, the method includes the following steps S101 to S103:

[0071] Step S101, in response to intercepting a memory release operation of a target process in a driving assistance system, recording memory release information corresponding to a first address to be released into a first diagnostic information set, and setting a protection flag corresponding to a first memory page; the first address belongs to the first memory page.

[0072] Here, the target process may be any suitable process in the driving assistance system, and the embodiments of the present application are not limited thereto. The memory release operation may be an operation performed by the target process for performing memory release. The first address refers to the address at which the current memory release operation indicates that memory release is to be performed.

[0073] In some embodiments, the memory release operation may include a heap operation and / or a stack operation. For example, the memory release operation may include a heap operation such as heap memory release (free). For another example, the memory release operation may include a stack operation such as pop (pop).

[0074] The memory release information corresponding to the first address may include any appropriate operation site data corresponding to the memory release operation, which is not limited in the embodiment of the present application.

[0075] In some implementations, the memory release information may include, but is not limited to, at least one of identification information of the target process, the first address, stack information corresponding to the current memory release operation, and the like.

[0076] In some embodiments, the first address in the memory release information can be represented by a triple containing a physical page frame number, an offset, and a memory length. For example, for a free operation, the corresponding physical page frame number pfn, the offset offset, and the memory length len can be found according to the virtual address vaddr. For another example, for a pop operation, the base pointer (Base Pointer, BP) of the stack can be obtained, and the corresponding physical page frame number pfn, the offset offset, and the memory length len can be obtained according to the BP.

[0077] The protection flag corresponding to the first memory page may be a flag indicating that the first memory page needs to be diagnosed and protected. Based on the protection flag corresponding to the first memory page, the memory access operation to the first memory page may be intercepted. During implementation, any suitable method may be used to set the corresponding protection flag for the first memory page, and the embodiments of the present application are not limited to this.

[0078] Step S102: in response to intercepting a memory access operation to the first memory page, determining a second address accessed in the first memory page, wherein the memory access operation is intercepted based on a protection flag corresponding to the first memory page.

[0079] Here, the memory access operation for the first memory page may be an operation for accessing the first memory page, and may include but is not limited to at least one of a read access operation, a write access operation, and the like.

[0080] In some embodiments, the memory access operation to the first memory page may be intercepted in real time when the target process accesses the first memory page. In some embodiments, the memory access operation to the first memory page may be indirectly obtained (i.e., indirectly intercepted) after the first memory page is accessed by any suitable method.

[0081] During implementation, those skilled in the art may adopt any appropriate method according to actual circumstances to intercept the memory access operation of the first memory page based on the protection flag corresponding to the first memory page, and the embodiments of the present application are not limited to this.

[0082] In some implementations, a protection flag may be directly set on a physical page corresponding to the first memory page, so that a memory access operation to the first memory page may be intercepted based on the protection flag using a page fault interrupt mechanism.

[0083] In some embodiments, a protection flag can be set for the first memory page by utilizing a reserved field in a page flag bit set. By intercepting each memory access operation and identifying whether the page flag bit set of the accessed memory page corresponding to the memory access operation includes a protection flag, if the page flag bit set of the accessed memory page corresponding to the memory access operation includes a protection flag and the accessed memory page is the first memory page, it can be determined that the memory access operation for the first memory page is intercepted.

[0084] Step S103: When the first diagnostic information set contains memory release information corresponding to the second address, a fault signal is sent, and the memory access information corresponding to the second address is recorded in the second diagnostic information set.

[0085] Here, the fault signal may be any suitable signal indicating that a memory access fault has occurred. It is understandable that if the first diagnostic information set contains memory release information corresponding to the second address, it indicates that the second address has undergone a memory release operation, and thus the current memory access operation to the second address is illegal. Therefore, a fault signal may be sent so that the illegal access operation can be discovered or processed in a timely manner.

[0086] In some embodiments, the fault signal may include a fatal signal (SIGSEGV), which may indicate that a segmentation fault has occurred during the execution of the program. A segmentation fault is usually caused by accessing an invalid memory address or accessing released memory, which may cause the program to crash. In this way, the user may promptly discover memory access errors in the driving assistance system, which is convenient for subsequent troubleshooting of the cause of the fault.

[0087] The memory access information corresponding to the second address may include any appropriate operation field data corresponding to the memory access operation, which is not limited in the embodiments of the present application.

[0088] In some implementations, the memory access information may include, but is not limited to, at least one of identification information of the target process, the second address, stack information corresponding to the current memory access operation, and the like.

[0089] In an embodiment of the present application, in response to intercepting a memory release operation of a target process in a driving assistance system, memory release information corresponding to a first address to be released is recorded in a first diagnostic information set, and a protection flag corresponding to a first memory page to which the first address belongs is set; in response to intercepting a memory access operation directed to a first memory page, a second address accessed in the first memory page is determined, and the memory access operation is intercepted based on the protection flag corresponding to the first memory page; in the event that there is memory release information corresponding to the second address in the first diagnostic information set, a fault signal is sent, and the memory access information corresponding to the second address is recorded in a second diagnostic information set. In this way, on the one hand, by intercepting memory release operations and memory access operations in the driving assistance system, fault diagnosis can be achieved without changing the driving assistance system code, thereby reducing code intrusion into the assisted driving system; on the other hand, by recording the memory release information corresponding to the first address to be released into the first diagnostic information set, and sending a fault signal when there is memory release information corresponding to the second address to be accessed in the first diagnostic information set, and recording the memory access information corresponding to the second address into the second diagnostic information set, the first scene of illegal memory access can be automatically found quickly and accurately, thereby reducing the time and manpower consumed in troubleshooting the driving assistance system; on another hand, by responding to the memory release operation of the target process intercepted in the driving assistance system, setting a protection flag corresponding to the first memory page to which the first address belongs, and intercepting the memory access operation for the first memory page based on the protection flag, the memory access operation can be intercepted without relying on monitoring of a specific memory access function.

[0090] In some embodiments, setting the protection flag corresponding to the first memory page in step S101 may include the following steps S1011 to S1012:

[0091] Step S1011, determining the physical page corresponding to the first memory page.

[0092] Step S1012: setting the protection flag for the physical page corresponding to the first memory page.

[0093] Here, the physical page frame number corresponding to the virtual address of the first memory page may be determined according to the virtual address of the first memory page, thereby determining the physical page corresponding to the first memory page.

[0094] In the above embodiment, setting a protection flag for the physical page corresponding to the first memory page can simplify the implementation logic and can efficiently and timely intercept the memory access operation.

[0095] In some embodiments, the step S101 of setting a protection flag corresponding to the first memory page further includes the following step S1013:

[0096] Step S1013: setting a diagnostic flag for the first memory page.

[0097] Here, the diagnostic flag of the first memory page may be a flag used to characterize that the first memory page is a memory page to be diagnosed, that is, when the first memory page has the diagnostic flag, the memory access operation of the first memory page needs to be diagnosed.

[0098] During implementation, any suitable method may be used to set a diagnostic flag for the first memory page, and the embodiment of the present application is not limited to this.

[0099] In some implementations, a reserved field in a page flag bit set may be used to set a diagnostic flag for the first memory page.

[0100] The above method may further include the following steps S104 to S105:

[0101] Step S104: in response to intercepting a page fault interrupt corresponding to the second address, determining whether the first memory page to which the second address belongs has a diagnostic flag.

[0102] Step S105: When the first memory page has a diagnosis flag, determine that the memory access operation to the first memory page is intercepted.

[0103] It is understandable that when a process or thread accesses a physical address with a protection flag, a page fault interrupt corresponding to the physical address may be triggered.

[0104] When the first memory page has a diagnostic flag, it indicates that the first memory page is the memory page to be diagnosed, so that the intercepted memory access operation for the first memory page can be determined, and it is determined that the accessed address is the second address; therefore, when there is memory release information corresponding to the second address in the first diagnostic information set, a fault signal can be sent, and the memory access information corresponding to the second address can be recorded in the second diagnostic information set.

[0105] In the above embodiment, after intercepting the memory release operation, a diagnostic flag is set for the corresponding memory page, and by utilizing the hardware-based page fault interrupt mechanism, by intercepting the page fault interrupt and determining whether the address where the page fault interrupt occurs belongs to a memory page with a diagnostic flag, it is possible to simply and quickly determine whether the memory access operation to the memory page to be diagnosed is intercepted. In addition, since the additional memory resources occupied during the fault diagnosis process are less, it can be better applied to application scenarios with limited memory resources.

[0106] In some embodiments, the above method may further include the following steps S106 to S108:

[0107] Step S106, when there is no memory release information corresponding to the second address in the first diagnostic information set, cancel the protection flag corresponding to the first memory page and set a diagnostic breakpoint for the next instruction in the process.

[0108] Step S107: when it is determined that the next instruction enters the diagnosis breakpoint, determine a third address accessed in the next instruction.

[0109] Step S108: When the second memory page to which the third address belongs has a diagnosis flag, a protection flag corresponding to the second memory page is set.

[0110] Here, the second memory page is the memory page to which the third address belongs, and the second memory page may be the same as or different from the first memory page.

[0111] Since a diagnostic breakpoint is set for the next instruction in the process, when the process or the thread in the process executes the next instruction, the diagnostic breakpoint of the next instruction will be entered, and then the corresponding breakpoint processing can be performed. During the processing of the diagnostic breakpoint, the third address accessed in the next instruction can be determined, and it can be determined whether the second memory page described by the third address has a diagnostic flag. If the second memory page has a diagnostic flag, a protection flag can be set for the second memory page.

[0112] It is understandable that the second memory page has a diagnostic flag, indicating that the second memory page is a memory page to be diagnosed. The second memory page may include addresses that have not been released and can be legally accessed, and may also include addresses that have been released but cannot be legally accessed. For example, if a previous instruction has been executed before the next instruction is executed, the previous instruction indicates that other addresses in the second memory page except the third address are accessed, and there is no memory release information corresponding to the other address in the first diagnostic information set, that is, the memory access operation corresponding to the previous instruction normally accesses other addresses in the second memory page, so that the protection flag corresponding to the second memory page is cancelled. At this time, the third address included in the second memory page may be an address that has been released and cannot be legally accessed, or it may be an address that has not been released and can be legally accessed. Therefore, the corresponding protection flag can continue to be set for the second memory page, so as to continue to intercept the memory access operation for the third address (that is, the memory access operation for the second memory page) to diagnose whether the memory access operation for the third address is a legal access operation.

[0113] In the above embodiment, when there is no memory release information corresponding to the second address in the first diagnostic information set, it indicates that the memory corresponding to the second address has not undergone a memory release operation, and thus the current access is legal. Therefore, the access can be performed normally by canceling the protection flag corresponding to the first memory page. In addition, by setting a diagnostic breakpoint for the next instruction in the process, and when the next instruction enters the diagnostic breakpoint, it is determined whether the second memory page to which the accessed third address belongs has a diagnostic flag, and when the second memory page has a diagnostic flag, a protection flag corresponding to the second memory page is set, so that the memory access operation corresponding to the memory page to be diagnosed can be continuously intercepted, thereby reducing the omission of faults and improving the accuracy of fault diagnosis.

[0114] In some embodiments, the step S101 described above of recording the memory release information corresponding to the first address to be released into the first diagnostic information set includes the following step S1014:

[0115] Step S1014: record the memory release information corresponding to the first address to be released into the first diagnostic information set, and set a corresponding aging timer for the first address.

[0116] Here, the timing duration of the aging timer can be set according to actual conditions, and the embodiment of the present application does not limit this. The timing durations of the aging timers corresponding to different addresses can be the same or different.

[0117] The above method may further include the following steps S109 to S110:

[0118] Step S109, obtaining at least one memory page to be diagnosed that currently has a to-be-diagnosed flag.

[0119] Step S110, for each of the memory pages to be diagnosed, determine at least one first target memory address with an aging timer in the memory page to be diagnosed, and when the aging timer corresponding to each of the first target memory addresses ends on time, delete the diagnostic flag and the protection flag of the memory page to be diagnosed, and release the memory page to be diagnosed.

[0120] In the above embodiment, a corresponding aging timer is set for the first address to be released, and when each first target memory address with an aging timer in the memory page to be diagnosed ends on time, the diagnosis flag and protection flag of the memory page to be diagnosed are deleted, and the memory page to be diagnosed is released. In this way, the memory can be released in time, reducing the occupation of software and hardware resources during the fault diagnosis process.

[0121] In some embodiments, the step of setting a protection flag corresponding to the first memory page in step S101 includes the following steps S1015 and S1016:

[0122] Step S1015: determining a mirror memory page corresponding to the first memory page in the mirror virtual memory space, wherein the mirror virtual memory space has a different memory addressing range from that of the target process.

[0123] Step S1016, setting the protection flag for the physical page corresponding to the mirror memory page.

[0124] Here, the mirror virtual memory space may be a pre-allocated virtual storage space (Virtual Memory Area, VMA), or may be dynamically determined according to the memory addressing range of the target process, which is not limited in the embodiments of the present application.

[0125] In some embodiments, in response to intercepting a memory allocation operation of a target process, a sixth address to be allocated in a first memory page may be determined, a corresponding mirror memory page may be allocated to the first memory page in a mirror virtual memory space, a corresponding mirror address may be allocated to the sixth address in the mirror memory page, and a mapping relationship between the sixth address and the mirror address may be recorded. In some embodiments, a mapping relationship between the first memory page and the mirror memory page, and a mapping relationship between the sixth address and the mirror address may be recorded at the same time.

[0126] In the above embodiment, a mirror memory page corresponding to the first memory page is synchronously set in the mirror virtual memory space, and a protection flag is set for the physical page corresponding to the mirror memory page, which can reduce interference with the processing logic in the native memory space (referring to the memory addressing range of the target process) and interference with business operations in the driving assistance system.

[0127] In some embodiments, the above method may further include the following step S111:

[0128] Step S111: synchronizing the memory content of at least one memory page to be diagnosed to the mirror virtual memory space according to a preset synchronization time interval, wherein the memory page to be diagnosed has a diagnosis flag.

[0129] Here, the synchronization time interval can be pre-set by those skilled in the art according to actual conditions, and the embodiments of the present application are not limited to this.

[0130] The memory content of the memory page to be diagnosed refers to the content respectively stored in each memory address in the memory page to be diagnosed.

[0131] In some implementations, the memory content of the memory page to be diagnosed may be directly copied to the corresponding mirror memory page in the mirror virtual memory space to achieve synchronization of the memory content.

[0132] In some embodiments, for each memory address in the memory page to be diagnosed, the content stored in the memory address can be compared with the content stored in the mirror address corresponding to the memory address in the mirror virtual memory space to see whether they are the same; if the content stored in the memory address is different from the content stored in the mirror address corresponding to the memory address, the content stored in the memory address is copied to the mirror address corresponding to the memory address to achieve synchronization of the memory contents.

[0133] In some implementations, at least one target memory page to be diagnosed whose memory content has changed compared to the last synchronization can be determined from at least one memory page to be diagnosed, and the memory content of the at least one target memory page to be diagnosed can be synchronized to the mirrored virtual memory space.

[0134] In response to intercepting the memory access operation to the first memory page, determining the accessed second address in the first memory page in the above step S102 may include the following steps S1021 and S12022:

[0135] Step S1021, in response to intercepting a page fault interrupt corresponding to a fourth address in the mirrored memory page, determining that the memory access operation for the first memory page is intercepted;

[0136] Step S1022: determining a second address accessed in the first memory page based on the fourth address.

[0137] Here, the fourth address is a memory address in the mirrored virtual memory space corresponding to the second address, that is, the fourth address is a mirrored address of the second address in the mirrored virtual memory space.

[0138] It is understandable that in the process of synchronizing the content stored in a certain address in the memory page to be diagnosed to the corresponding mirror address in the mirror virtual memory space, if the physical page corresponding to the mirror memory page to which the mirror address belongs is set with a protection flag, a page fault interrupt corresponding to the mirror address will be triggered.

[0139] In the above embodiment, by periodically synchronizing the memory content of at least one memory page to be diagnosed to the mirror virtual memory space, and when a page fault interrupt corresponding to the fourth address in the mirror memory page is intercepted, it is determined that a memory access operation to the first memory page is intercepted, and the second address accessed in the first memory page is determined based on the fourth address, and it is determined whether an illegal access occurs according to the second address, thereby achieving fault diagnosis. In this way, by periodically synchronizing the memory content to the mirror virtual memory space to detect whether a memory access operation to the first memory page is intercepted, there is no need to intercept the memory access operation in real time, which can reduce interference with the operation of services in the driving assistance system and reduce the occupation of processor resources during the fault diagnosis process. In addition, since the occupation of processor resources during the fault diagnosis process is less, it can be better applied to application scenarios with limited processor resources, thereby improving the performance of the processor in processing services in the driving assistance system.

[0140] In some embodiments, the step S101 described above of recording the memory release information corresponding to the first address to be released into the first diagnostic information set may include the following step S1017:

[0141] Step S1017, recording memory release information corresponding to the first address to be released into the first diagnostic information set, and setting a corresponding aging timer for the fifth address in the mirror virtual memory space, the fifth address corresponding to the first address.

[0142] Here, the fifth address is a mirror address of the first address in the mirror virtual memory space.

[0143] The above method may further include the following step S112:

[0144] Step S112, for each memory page in the mirrored virtual memory space, determine at least one second target memory address with an aging timer in the memory page, and when the aging timer corresponding to each of the second target memory addresses expires on time, delete the protection flag of the memory page and release the memory page.

[0145] In the above embodiment, a corresponding aging timer is set for the fifth address corresponding to the first address to be released in the mirror virtual memory space, and when each first target memory address with an aging timer in the memory page in the mirror virtual memory space has expired on time, the protection flag of the memory page is deleted and the memory page is released. In this way, the memory in the mirror virtual memory space can be released in time, reducing the occupation of software and hardware resources in the fault diagnosis process.

[0146] In some embodiments, in response to intercepting the memory release operation of the target process in the driving assistance system, recording the memory release information corresponding to the first address to be released into the first diagnostic information set in step S101 may include the following steps S1018 and S1019:

[0147] Step S1018, in response to intercepting the memory release operation of the target process in the driving assistance system, determining whether the target process belongs to the list of processes to be diagnosed.

[0148] Step S1019, when the target process belongs to the list of processes to be diagnosed, the memory release information corresponding to the first address to be released is recorded in the first diagnostic information set.

[0149] Here, the list of processes to be diagnosed may be pre-set by those skilled in the art according to actual fault diagnosis requirements, and the embodiments of the present application are not limited to this.

[0150] In some implementations, the list of processes to be diagnosed may include a preset process whitelist.

[0151] In some embodiments, when the target process belongs to the list of processes to be diagnosed, the thread currently executing the memory release operation in the target process can also be obtained, and it is determined that the thread release belongs to the list of threads to be diagnosed; when the thread belongs to the list of threads to be diagnosed, the memory release information corresponding to the first address to be released is recorded in the first diagnostic information set. Among them, the list of threads to be diagnosed can also be set by those skilled in the art according to actual conditions, and the embodiments of the present application are not limited to this.

[0152] In the above embodiment, the process to be diagnosed is screened by using the list of processes to be diagnosed, which can better meet the fault diagnosis requirements and reduce the usage of software and hardware resources during the fault diagnosis process.

[0153] In some embodiments, the above method may further include the following step S113:

[0154] Step S113, in response to intercepting the exit operation of the target process, dumping fault diagnosis information into a set diagnosis result file, the fault diagnosis information including the first diagnosis information set and / or the second diagnosis information set.

[0155] Here, the diagnosis result file can be a default one or a user-preconfigured one.

[0156] In the above embodiment, after the target process exits, the recorded fault diagnosis information can be dumped into a diagnosis result file, thereby facilitating the investigation of the cause of the fault.

[0157] In some embodiments, the fault diagnosis information includes the first diagnostic information set, the second diagnostic information set and / or the third diagnostic information set; the above method may further include the following step S114:

[0158] Step S114, in response to intercepting the memory allocation operation of the target process, recording the memory allocation information corresponding to the sixth address to be allocated into the third diagnostic information set.

[0159] In some embodiments, the memory allocation operation may include a heap operation and / or a stack operation. For example, the memory allocation operation may include a heap operation such as heap memory allocation (malloc). For another example, the memory allocation operation may include a stack operation such as push.

[0160] The memory allocation information corresponding to the sixth address may include any appropriate operation site data corresponding to the memory allocation operation, which is not limited in this embodiment of the present application.

[0161] In some implementations, the memory allocation information may include, but is not limited to, at least one of identification information of the target process, the sixth address, stack information corresponding to the current memory allocation operation, and the like.

[0162] In some embodiments, the first address in the memory allocation information may be represented by a triple containing a physical page frame number, an offset, and a memory length. For example, for a malloc operation, the corresponding physical page frame number pfn, the offset offset, and the memory length len may be found according to the virtual address vaddr. For another example, for a push operation, the stack pointer (SP) may be obtained, and the corresponding physical page frame number pfn, the offset offset, and the memory length len may be obtained according to the SP.

[0163] In the above embodiment, by intercepting the memory allocation operation of the target process, the memory allocation information corresponding to the sixth address to be allocated is recorded in the third diagnostic information set, and the first diagnostic information set, the second diagnostic information set and / or the third diagnostic information set are dumped to the diagnostic result file after the target process exits. This can provide a richer and more comprehensive reference basis for troubleshooting, thereby improving the efficiency and accuracy of troubleshooting.

[0164] The following takes the troubleshooting of memory corruption failures in an ADAS system as an example to illustrate the application of the fault diagnosis method provided in the embodiments of the present application in actual scenarios.

[0165] If a piece of memory in the ADAS process is damaged by a thread (it may be caused by the original equipment manufacturer (OEM) self-developed code, the code delivered by the supplier black box, etc.), it will still run with the problem. During this period, this piece of memory may be changed many times. Until other threads access this piece of memory and cannot parse the address, the operating system throws a fatal signal during the page fault interrupt processing, and the process will crash. When it crashes, it is far away from the first scene where the memory has just been damaged. Only subsequent information can be obtained, such as the victim's stack, registers, etc., making it difficult to find the "source of the fault."

[0166] The operating environment of ADAS has limited software and hardware resources, and conventional debugging tools cannot run. ADAS contains a large number of software components provided by suppliers' black boxes, so some tools that require recompiling programs cannot be used. OEMs can only repeatedly test and reproduce on the car, narrow the scope, and spend a long time to locate the problem of a supplier's component code or a section of self-developed code, which seriously affects the release time of the version.

[0167] The fault diagnosis method provided by the embodiment of the present application can be used to detect both heap memory corruption and stack memory corruption; the interception of memory access operations does not depend on specific memory access functions; the stack at the first scene of memory corruption can be accurately found. When running on a resource-constrained domain controller or central computer, no code changes are required for ADAS, and on-site information of memory corruption (including heap memory and stack memory) can be obtained, thereby quickly locating ADAS software faults and shortening version release time.

[0168] On this basis, an embodiment of the present application provides a fault diagnosis device for diagnosing ADAS memory corruption, which can operate independently. Figure 2 A schematic diagram of an implementation architecture of a fault diagnosis device provided in an embodiment of the present application is shown in FIG. Figure 2 As shown, the fault diagnosis device 20 includes a control module 21 and a diagnosis module 22 .

[0169] The control module 21 is presented as a service to the outside world, automatically runs when the computer is turned on, and has the following functions: configuration information loading 211, service loading processing 212 and service exit processing 213.

[0170] Configuration information loading 211: parsing and loading configuration information, the configuration information includes a process whitelist, aging time (corresponding to the timing length of the aging timer in the above embodiment), memory diagnosis method (including the method of using page fault interrupt and the method of using mirror VMA), diagnosis result file, etc. Figure 3 As shown, the configuration information loading includes the following steps S2111 to S2114:

[0171] Step S2111, start;

[0172] Step S2112, loading configuration information;

[0173] Step S2113, setting configuration information to the diagnostic module;

[0174] Step S2114, end.

[0175] Service loading process 212: intercept the process loading operation when the ADAS service is started (the ADAS service list comes from the white list in the configuration information), and initialize the diagnostic data in the diagnostic module (corresponding to the fault diagnosis information in the above embodiment). Figure 4 As shown, the service loading process includes the following steps S2121 to S2125:

[0176] Step S2121, intercepting the process loading operation;

[0177] Step S2122, determining whether the current process belongs to the list of processes to be diagnosed;

[0178] If so, go to step S2123; if not, go to step S2125.

[0179] If the current process belongs to the list of processes to be diagnosed, the current process is a process to be diagnosed; if the current process does not belong to the list of processes to be diagnosed, the current process is not a process to be diagnosed.

[0180] Step S2123, determine whether the current thread is a thread to be diagnosed; if so, proceed to step S2124; if not, proceed to step S2125.

[0181] If the current thread belongs to the list of threads to be diagnosed, the current thread is a thread to be diagnosed; if the current thread does not belong to the list of threads to be diagnosed, the current thread is not a thread to be diagnosed.

[0182] Step S2124, initializing diagnostic data;

[0183] Step S2125, normal loading process.

[0184] Service exit processing 213: intercept the uninstallation operation when the ADAS process exits, extract the diagnostic data in the diagnostic module, and output it to a predetermined diagnostic result file. Figure 5 As shown, the service exit process includes the following steps S2131 to S2134:

[0185] Step S2131, intercepting the process exit operation;

[0186] Step S2132, determine whether the current process is a process to be diagnosed; if so, go to step S2133; if not, go to step S2134.

[0187] Step S2133, dumping fault diagnosis data;

[0188] Here, the fault diagnosis information can be dumped to the set diagnosis result file.

[0189] Step S2134, normal exit process.

[0190] The diagnosis module 22 has the following functions: initialization of diagnosis data 221 , memory allocation processing 222 , memory release processing 223 , memory access processing 224 , aging processing 225 , and acquisition of diagnosis data 226 .

[0191] Here, the diagnosis module 22 can be implemented by using a page fault interrupt method (referred to as method one), or by using a mirror VMA method (referred to as method two).

[0192] Figure 6 A schematic diagram of a memory allocation process based on a page fault interruption implementation provided in an embodiment of the present application is shown in FIG. Figure 6 As shown, the memory allocation process 222 includes the following steps S2221 to S2224:

[0193] Step S2221, intercepting memory allocation operation;

[0194] Step S2222, determine whether the current process is a process to be diagnosed; if so, go to step S2223; if not, go to step S2224.

[0195] Step S2223, recording diagnostic information 1;

[0196] The triplet corresponding to the allocated memory address and the current stack information are stored in the diagnosis module as diagnosis information 1 (corresponding to the third diagnosis information set in the aforementioned embodiment).

[0197] Step S2224, the process ends.

[0198] Figure 7 A schematic diagram of an implementation flow of a memory allocation process based on a mirror VMA provided in an embodiment of the present application is shown in FIG. Figure 7 As shown, the memory allocation process 222 includes the following steps S2225 to S2229:

[0199] Step S2225, intercepting the memory allocation operation;

[0200] Step S2226, determine whether the current process is a process to be diagnosed; if so, go to step S2227; if not, go to step S2229.

[0201] Step S2227, allocating the mirror VMA address;

[0202] The memory address allocated by the memory allocation operation is assigned a corresponding mirror VMA address.

[0203] Step S2228, recording diagnostic information 1;

[0204] The mapping relationship between the triplet corresponding to the allocated memory address and the newly allocated mirror VMA address is recorded, and the mapping relationship and the current stack information are stored in the diagnosis module as diagnosis information 1 (corresponding to the third diagnosis information set in the aforementioned embodiment).

[0205] Step S2229, the process ends.

[0206] Figure 8 A schematic diagram of a memory release process based on a page fault interruption implementation provided in an embodiment of the present application is shown in FIG. Figure 8 As shown, the memory release process 223 includes the following steps S2231 to S2235:

[0207] Step S2231, intercepting the memory release operation;

[0208] Step S2232, determine whether the current process is a process to be diagnosed; if so, go to step S2233; if not, go to step S2235.

[0209] Step S2233, recording diagnostic information 2;

[0210] The address triplet corresponding to the address to be released and the current stack information may be stored in the diagnosis module as diagnosis information 2 (corresponding to the first diagnosis information set in the aforementioned embodiment).

[0211] Step S2234, setting a protection flag and a diagnosis flag for the memory page to which the address to be released belongs;

[0212] Step S2235, the process ends.

[0213] Fig. 9 A schematic diagram of an implementation flow of a memory release process based on a mirror VMA provided in an embodiment of the present application is shown in FIG. Fig. 9 As shown, the memory release process 223 includes the following steps S2236 to S22310:

[0214] Step S2236, intercepting the memory release operation;

[0215] Step S2237, determine whether the current process is a process to be diagnosed; if so, go to step S2238; if not, go to step S22310.

[0216] Step S2238, recording diagnostic information 2;

[0217] Step S2239, setting a protection flag and a diagnostic flag for the mirrored memory page corresponding to the memory page to which the address to be released belongs in the mirrored VMA;

[0218] The mapping relationship between the address triplet corresponding to the address to be released and the corresponding mirror address, as well as the current stack information, can be stored in the diagnosis module as diagnosis information 2 (corresponding to the first diagnosis information set in the aforementioned embodiment).

[0219] Step S22310, the process ends.

[0220] Fig.10 A schematic diagram of a memory aging process based on page fault interruption provided in an embodiment of the present application is shown in FIG. Fig.10 As shown, the aging process 225 includes the following steps S2251 to S2254:

[0221] Step S2251, traversing the memory page to be diagnosed;

[0222] Here, the memory page to be diagnosed refers to a memory page with a diagnosis flag.

[0223] Step S2252, determining whether each address in the memory page to be diagnosed has reached the aging time;

[0224] Here, the address reaching the aging time refers to the timing expiration of the aging timer corresponding to the address.

[0225] If so, go to step S2253; if not, go to step S2254.

[0226] Step S2253, deleting the diagnostic flag of the memory page to be diagnosed, and releasing the memory page to be diagnosed.

[0227] Step S2254, the process ends.

[0228] Fig.11 A schematic diagram of the implementation flow of a memory aging process based on a mirror VMA provided in an embodiment of the present application is shown in FIG. Fig.11 As shown, the aging process 225 includes the following steps S2255 to S2258:

[0229] Step S2255, traverse the memory pages in the mirror VMA;

[0230] Step S2256, determining whether each address in the memory page has reached the aging time;

[0231] If so, go to step S2257; if not, go to step S2258.

[0232] Step S2257, delete the diagnostic flag of the memory page and release the memory page.

[0233] Step S2258, the process ends.

[0234] Fig.12 A schematic diagram of a memory access process based on a page fault interrupt is provided in an embodiment of the present application, such as Fig.12 As shown, the memory access process 224 includes the following steps S2241 to S2247:

[0235] Step S2241, intercepting page fault interruption;

[0236] Step S2242, determining whether the address where the page fault occurs belongs to the memory page to be diagnosed;

[0237] If so, go to step S2243; if not, go to step S2246.

[0238] Here, when the memory page to which the address belongs has a diagnostic flag, it is determined that the address belongs to the memory page to be diagnosed; when the memory page to which the address belongs does not have a diagnostic flag, it is determined that the address does not belong to the memory page to be diagnosed.

[0239] Step S2243, determining whether the memory access operation of the current address is an illegal access;

[0240] If so, go to step S2244; if not, go to step S2245.

[0241] Using the recorded diagnostic information 2, it can be determined whether the address belongs to the released memory. If the current address belongs to the released memory, the memory access operation of the current address is an illegal access; if the current address does not belong to the released memory, the memory access operation of the current address is a legal access.

[0242] Step S2244, recording diagnostic information 3, sending a fatal signal;

[0243] Here, the current address, the process identifier of the current process, and / or the stack information corresponding to the current memory access operation may be recorded as diagnostic information 3 (corresponding to the second diagnostic information set in the aforementioned embodiment).

[0244] Step S2245, cancel the protection flag and set a breakpoint;

[0245] If it is a legitimate access, the protection mark of the memory page where the current address is located is removed, and a diagnostic breakpoint is set for the next instruction of the current process. After the next instruction is executed and the diagnostic breakpoint is entered, the breakpoint processing can be performed.

[0246] Step S2246, conventional page fault interrupt processing;

[0247] Step S2247, the process ends.

[0248] Fig.13 A schematic diagram of the implementation flow of a breakpoint processing in a memory access processing process based on a page fault interrupt is provided in an embodiment of the present application, such as Fig.13 As shown, the breakpoint processing flow includes the following steps S231 to S235:

[0249] Step S231, start breakpoint processing;

[0250] Step S232, determining whether the current address belongs to a memory page to be diagnosed;

[0251] If so, go to step S233; if not, go to step S234.

[0252] Step S233, setting a protection flag for the memory page to which the current address belongs;

[0253] Step S234, conventional breakpoint processing;

[0254] Step S235, the process ends.

[0255] Fig.14 A schematic diagram of the implementation flow of a memory aging process based on a mirror VMA provided in an embodiment of the present application is shown in FIG. Fig.14 As shown, the memory access process 224 includes the following steps S2248 to S22412:

[0256] Step S2248, reaching synchronization time;

[0257] Step S2249, synchronizing the memory content of the page to be diagnosed to the mirror VMA;

[0258] Step S22410, determining whether illegal address access occurs in the mirror VMA;

[0259] If so, go to step S22411; if not, go to step S22412.

[0260] Step S22411, record diagnostic information 3, send a fatal signal;

[0261] Step S22412, the process ends.

[0262] In the embodiment of the present application, a fault diagnosis device is disclosed, which can be run on a domain controller or central computer with limited resources, and improves the problem that memory corruption is difficult to troubleshoot during the operation of the advanced driver assistance system. The fault diagnosis device runs as an independent service, and its startup time is earlier than the ADAS service, and it is decoupled from the specific services of the ADAS system; by intercepting the loading and exiting processes of the ADAS service, the diagnostic information during the operation of the ADAS is obtained, and there is no intrusion into the service code, and fault diagnosis services can be provided for more services.

[0263] In addition, the resource overhead of the fault diagnosis device provided in the embodiment of the present application is controllable. On the one hand, a configurable aging time is provided to release memory in time; on the other hand, a process whitelist and / or thread whitelist is provided to accurately control the scope of business programs to be diagnosed; on the other hand, a method of implementing a diagnostic module based on mirror VMA mirror comparison is disclosed, which can be applicable to domain controllers or central computers with sufficient memory and insufficient CPU resources; on the other hand, a method of implementing a diagnostic module based on page fault interrupt interception is disclosed, which can be applicable to domain controllers or central computers with insufficient memory and sufficient CPU resources.

[0264] The present application provides a fault diagnosis device. Fig.15 A schematic diagram of the structure of a fault diagnosis device provided in an embodiment of the present application is shown in FIG. Fig.15 As shown, the fault diagnosis device 30 includes a first interception module 31, a second interception module 32 and a sending module 33; wherein:

[0265] A first interception module 31 is configured to, in response to intercepting a memory release operation of a target process in a driving assistance system, record memory release information corresponding to a first address to be released into a first diagnostic information set, and set a protection flag corresponding to a first memory page; the first address belongs to the first memory page;

[0266] A second interception module 32, configured to determine a second address accessed in the first memory page in response to intercepting a memory access operation to the first memory page, the memory access operation being intercepted based on a protection flag corresponding to the first memory page;

[0267] The sending module 33 is used to send a fault signal when there is memory release information corresponding to the second address in the first diagnostic information set, and record the memory access information corresponding to the second address into the second diagnostic information set.

[0268] In the above implementation, on the one hand, by intercepting the memory release operation and memory access operation in the driving assistance system, fault diagnosis can be achieved without changing the driving assistance system code, thereby reducing code intrusion into the assisted driving system; on the other hand, by recording the memory release information corresponding to the first address to be released into the first diagnostic information set, and sending a fault signal when there is memory release information corresponding to the second address to be accessed in the first diagnostic information set, and recording the memory access information corresponding to the second address into the second diagnostic information set, the first scene of illegal memory access can be automatically found quickly and accurately, thereby reducing the time and manpower consumed in troubleshooting the driving assistance system; on the other hand, by responding to the memory release operation of the target process intercepted in the driving assistance system, setting a protection flag corresponding to the first memory page to which the first address belongs, and intercepting the memory access operation for the first memory page based on the protection flag, the memory access operation can be intercepted without relying on monitoring of a specific memory access function.

[0269] In some embodiments, the first interception module is further used to: determine the physical page corresponding to the first memory page; and set the protection flag for the physical page corresponding to the first memory page.

[0270] In some embodiments, the first interception module is also used to: set a diagnostic flag for the first memory page; the above-mentioned device also includes: a third interception module, used to: in response to intercepting a page fault interrupt corresponding to the second address, determine whether the first memory page to which the second address belongs has a diagnostic flag; if the first memory page has a diagnostic flag, determine that the memory access operation to the first memory page is intercepted.

[0271] In some embodiments, the above-mentioned device also includes: a first setting module, which is used to: when there is no memory release information corresponding to the second address in the first diagnostic information set, cancel the protection flag corresponding to the first memory page, and set a diagnostic breakpoint for the next instruction in the process; when it is determined that the next instruction enters the diagnostic breakpoint, determine the third address accessed in the next instruction; when the second memory page to which the third address belongs has a diagnostic flag, set the protection flag corresponding to the second memory page.

[0272] In some embodiments, the first interception module is also used to: record the memory release information corresponding to the first address to be released into the first diagnostic information set, and set the corresponding aging timer for the first address; the device also includes: a first acquisition module, used to obtain at least one memory page to be diagnosed that currently has a flag to be diagnosed; a first release module, used to determine, for each of the memory pages to be diagnosed, at least one first target memory address with an aging timer in the memory page to be diagnosed, and when the aging timer corresponding to each of the first target memory addresses ends on time, delete the diagnostic flag and protection flag of the memory page to be diagnosed, and release the memory page to be diagnosed.

[0273] In some embodiments, the first interception module is also used to: determine a mirror memory page corresponding to the first memory page in a mirror virtual memory space, the mirror virtual memory space having a different memory addressing range from that of the target process; and set the protection flag for a physical page corresponding to the mirror memory page.

[0274] In some embodiments, the device also includes: a synchronization module, used to synchronize the memory content of at least one memory page to be diagnosed to the mirrored virtual memory space in sequence according to a preset synchronization time interval, and the memory page to be diagnosed has a diagnostic flag; the second interception module is also used to: in response to intercepting a page fault interrupt corresponding to a fourth address in the mirrored memory page, determine that the memory access operation to the first memory page is intercepted; based on the fourth address, determine the second address accessed in the first memory page.

[0275] In some embodiments, the first interception module is also used to: record the memory release information corresponding to the first address to be released into the first diagnostic information set, and set a corresponding aging timer for the fifth address in the mirrored virtual memory space, and the fifth address corresponds to the first address; the above-mentioned device also includes: a second release module, which is used to determine, for each memory page in the mirrored virtual memory space, at least one second target memory address with an aging timer in the memory page, and when the aging timer corresponding to each of the second target memory addresses expires on time, delete the protection flag of the memory page and release the memory page.

[0276] In some embodiments, the first interception module is also used to: in response to intercepting a memory release operation of a target process in a driving assistance system, determine whether the target process belongs to a list of processes to be diagnosed; if the target process belongs to the list of processes to be diagnosed, record the memory release information corresponding to the first address to be released into the first diagnostic information set.

[0277] In some embodiments, the device also includes: a dump module, which is used to dump fault diagnosis information into a set diagnostic result file in response to intercepting an exit operation of the target process, and the fault diagnosis information includes the first diagnostic information set and / or the second diagnostic information set.

[0278] In some embodiments, the fault diagnostic information includes the first diagnostic information set, the second diagnostic information set and / or the third diagnostic information set; the device also includes: a recording module, which is used to record the memory allocation information corresponding to the sixth address to be allocated into the third diagnostic information set in response to intercepting the memory allocation operation of the target process.

[0279] An embodiment of the present application provides a computer device, including a memory and a processor, wherein the memory stores a computer program that can be run on the processor, and when the processor executes the program, some or all of the steps in the above method are implemented.

[0280] An embodiment of the present application provides a vehicle, comprising the above-mentioned computer device.

[0281] In some implementations, the computer device may include, but is not limited to, at least one of a domain controller, a central computer, and the like.

[0282] Fig.16 A schematic diagram of the structure of a vehicle provided in an embodiment of the present application is shown in FIG. Fig.16 As shown, the vehicle 40 includes a central computer 41 .

[0283] The embodiment of the present application provides a computer-readable storage medium on which a computer program is stored, and when the computer program is executed by a processor, some or all of the steps in the above method are implemented. The computer-readable storage medium can be transient or non-transient.

[0284] An embodiment of the present application provides a computer program product, including a computer program or instructions, which, when executed by a processor, implements the steps in the method described in the above embodiment.

[0285] The present application embodiment provides a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program, and when the computer program is read and executed by a computer, some or all of the steps in the above method are implemented. The computer program product can be implemented in hardware, software, or a combination thereof. In some embodiments, the computer program product is specifically embodied as a computer storage medium, and in other embodiments, the computer program product is specifically embodied as a software product, such as a software development kit (SDK), etc.

[0286] It should be noted here that the description of the various embodiments above tends to emphasize the differences between the various embodiments, and the same or similar aspects can be referenced to each other. The description of the above device, equipment, vehicle, storage medium and program product embodiments is similar to the description of the above method embodiment, and has similar beneficial effects as the method embodiment. For technical details not disclosed in the device, equipment, vehicle, storage medium and program product embodiments of this application, please refer to the description of the method embodiment of this application for understanding.

[0287] It should be understood that "one embodiment" or "an embodiment" mentioned throughout the specification means that specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner. It should be understood that in various embodiments of the present application, the size of the sequence number of the above-mentioned processes does not mean the order of execution, and the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application. The above-mentioned sequence numbers of the embodiments of the present application are only for description and do not represent the advantages and disadvantages of the embodiments.

[0288] It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the existence of other identical elements in the process, method, article or device including the element.

[0289] The above description is only to fully illustrate the implementation mode of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by any technician familiar with the technical field within the technical scope disclosed in the present application should be covered by the protection scope of the present application.

Claims

1. A fault diagnosis method, characterized in that: The method comprises: In response to intercepting a memory release operation of a target process in a driving assistance system, recording memory release information corresponding to a first address to be released into a first diagnostic information set, and setting a protection flag corresponding to a first memory page; the first address belongs to the first memory page; In response to intercepting a memory access operation to the first memory page, determining a second address accessed in the first memory page, the memory access operation being intercepted based on a protection flag corresponding to the first memory page; When the first diagnostic information set contains memory release information corresponding to the second address, a fault signal is sent, and the memory access information corresponding to the second address is recorded in the second diagnostic information set.

2. The method according to claim 1, characterized in that The step of setting a protection flag corresponding to the first memory page includes: Determine a physical page corresponding to the first memory page; The protection flag is set for the physical page corresponding to the first memory page.

3. The method according to claim 2, characterized in that The step of setting a protection flag corresponding to the first memory page further includes: Setting a diagnostic flag on the first memory page; The method further comprises: In response to intercepting a page fault interrupt corresponding to the second address, determining whether the first memory page to which the second address belongs has a diagnostic flag; In a case where the first memory page has a diagnostic flag, it is determined that the memory access operation to the first memory page is intercepted.

4. The method according to claim 3, characterized in that The method further comprises: In the case that there is no memory release information corresponding to the second address in the first diagnostic information set, canceling the protection flag corresponding to the first memory page, and setting a diagnostic breakpoint for the next instruction in the process; In the case where it is determined that the next instruction enters the diagnostic breakpoint, determining a third address accessed in the next instruction; In a case where the second memory page to which the third address belongs has a diagnosis flag, a protection flag corresponding to the second memory page is set.

5. The method according to claim 2, characterized in that: The step of recording the memory release information corresponding to the first address to be released into the first diagnostic information set includes: Recording memory release information corresponding to a first address to be released into a first diagnostic information set, and setting a corresponding aging timer for the first address; The method further comprises: Obtain at least one memory page to be diagnosed that currently has a to-be-diagnosed flag; For each of the memory pages to be diagnosed, determine at least one first target memory address with an aging timer in the memory page to be diagnosed, and when the aging timer corresponding to each of the first target memory addresses expires on time, delete the diagnostic flag and protection flag of the memory page to be diagnosed, and release the memory page to be diagnosed.

6. The method according to claim 1, characterized in that The step of setting a protection flag corresponding to the first memory page includes: Determine a mirror memory page corresponding to the first memory page in a mirror virtual memory space; the mirror virtual memory space and the target process have different memory addressing ranges; The protection flag is set for the physical page corresponding to the mirror memory page.

7. The method according to claim 6, characterized in that The method further comprises: According to a preset synchronization time interval, synchronizing the memory content of at least one memory page to be diagnosed to the mirror virtual memory space, wherein the memory page to be diagnosed has a diagnosis flag; In response to intercepting a memory access operation to the first memory page, determining a second address accessed in the first memory page includes: In response to intercepting a page fault interrupt corresponding to a fourth address in the mirrored memory page, determining that the memory access operation for the first memory page is intercepted; Based on the fourth address, a second address accessed in the first memory page is determined.

8. The method according to claim 7, characterized in that The step of recording the memory release information corresponding to the first address to be released into the first diagnostic information set includes: Recording memory release information corresponding to the first address to be released into the first diagnostic information set, and setting a corresponding aging timer for the fifth address in the mirror virtual memory space, the fifth address corresponding to the first address; The method further comprises: For each memory page in the mirrored virtual memory space, determine at least one second target memory address with an aging timer in the memory page, and when the aging timer corresponding to each of the second target memory addresses expires on time, delete the protection flag of the memory page and release the memory page.

9. The method according to any one of claims 1 to 8, characterized in that In response to intercepting the memory release operation of the target process in the driving assistance system, recording the memory release information corresponding to the first address to be released into the first diagnostic information set includes: In response to intercepting a memory release operation of a target process in the driving assistance system, determining whether the target process belongs to a list of processes to be diagnosed; In a case where the target process belongs to the list of processes to be diagnosed, memory release information corresponding to the first address to be released is recorded in a first diagnostic information set.

10. The method according to any one of claims 1 to 8, characterized in that The method further comprises: In response to intercepting the exit operation of the target process, dumping fault diagnosis information into a set diagnosis result file, the fault diagnosis information including the first diagnosis information set and / or the second diagnosis information set.

11. The method according to claim 10, characterized in that The fault diagnosis information includes the first diagnosis information set, the second diagnosis information set and / or the third diagnosis information set; the method further includes: In response to intercepting the memory allocation operation of the target process, the memory allocation information corresponding to the sixth address to be allocated is recorded in the third diagnostic information set.

12. A fault diagnosis device, characterized in that: include: a first interception module, configured to, in response to intercepting a memory release operation of a target process in the driving assistance system, record memory release information corresponding to a first address to be released into a first diagnostic information set, and set a protection flag corresponding to the first memory page; The first address belongs to the first memory page; a second interception module, configured to determine a second address accessed in the first memory page in response to intercepting a memory access operation to the first memory page, wherein the memory access operation is intercepted based on a protection flag corresponding to the first memory page; A sending module is used to send a fault signal when there is memory release information corresponding to the second address in the first diagnostic information set, and record the memory access information corresponding to the second address into the second diagnostic information set.

13. A computer device comprising a memory and a processor, wherein the memory stores a computer program executable on the processor, wherein: When the processor executes the program, the steps in the method according to any one of claims 1 to 11 are implemented.

14. A vehicle, characterized in that: Comprising the computer device of claim 13.

15. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 11 are implemented.

16. A computer program product comprising a computer program or instructions, characterized in that When the computer program or instruction is executed by a processor, the steps in the method according to any one of claims 1 to 11 are implemented.