Stack cross-border detection method, device, equipment and system for multi-core real-time operating system

By setting independent task stack segments and interrupt stack segments in the memory space of the multi-core real-time operating system and configuring access rights for each core, the problem of difficulty in detecting stack cross-border during multi-task interaction is solved, and efficient and timely stack cross-border detection is achieved.

CN120029811APending Publication Date: 2025-05-23SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
CN202510237780.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

The prior art is difficult to perform stack-over-border detection of multi-verifiable real-time operating systems during multi-task interaction, and the detection timeliness and overhead are poor.

Method used

By setting independent task stack segments and interrupt stack segments in the memory space of the multi-core real-time operating system and configuring access rights for each core, the adjacent segment attributes of the task stack segment and interrupt stack segment are read-only, so when the kernel has a data access exception, it quickly determines whether the data address is adjacent to the stack space, thereby determining whether the stack is out of bounds.

Benefits of technology

It realizes the timely detection of stack over-boundary problems during multi-task operation, without adding additional execution programs or setting up additional storage space, reducing detection overhead and improving detection timeliness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120029811A_ABST
    Figure CN120029811A_ABST
Patent Text Reader

Abstract

The invention discloses a stack border crossing detection method, device, equipment and system of a multi-core real-time operating system, relates to the technical field of computers, and aims to solve the problems of poor timeliness and high overhead of stack border crossing detection. A memory space of the multi-core real-time operating system comprises independent task stack segments and interrupt stack segments; the attributes of the segments adjacent to the task stack segment and the interrupt stack segment are read-only, any two adjacent task stack spaces in the task stack segment belong to different cores respectively, and any two adjacent interrupt stack spaces in the interrupt stack segment belong to different cores respectively; each core only has the permission of the task stack space corresponding to the core and has the permission of the interrupt stack space corresponding to the core; acquiring a data address accessed by the core when data access abnormity occurs in the core, and determining that stack crossing occurs under the condition of determining that the data address is adjacent to the stack space according to the address of each task stack space and the address of each interrupt stack space; and the detection timeliness is high and the overhead is low.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a stack out-of-bounds detection method, device, electronic device and computer-readable storage system for a multi-core real-time operating system. Background Art

[0002] Currently, when performing stack out-of-bounds detection on a multi-core real-time operating system, one method is to load and run a stack out-of-bounds detection executable program. If the executable program exits abnormally during operation, it is determined that a memory out-of-bounds has occurred; if the executable program runs normally for the test duration, it is determined that no memory out-of-bounds has occurred. However, this method cannot detect stack out-of-bounds problems during multi-task interaction. Another method is to set up additional storage space at the front and back ends of the data storage area of ​​the stack, and to determine whether the stack has an out-of-bounds condition by continuously detecting the storage space at both ends. This can only be detected after the stack has been stepped on, and the stack out-of-bounds condition cannot be detected immediately.

[0003] In view of this, how to implement stack out-of-bounds detection for a multi-core real-time operating system during multi-task interaction, reduce detection overhead, and improve detection timeliness has become a problem that technical personnel in this field need to solve. Summary of the invention

[0004] The present application provides a stack out-of-bounds detection method, device, electronic device and computer-readable storage system for a multi-core real-time operating system, so as to at least solve the problems of poor timeliness and high overhead of stack out-of-bounds detection in the related art.

[0005] The present application provides a stack out-of-bounds detection method for a multi-core real-time operating system, comprising:

[0006] In the case where a data access exception occurs in the core, obtaining a data address accessed by the core when the data access exception occurs;

[0007] Determining whether the data address is adjacent to the stack space according to the address of each task stack space and the address of each interrupt stack space;

[0008] When the data address is adjacent to the stack space, it is determined that a stack cross-border occurs; wherein:

[0009] The memory space of the multi-core real-time operating system includes independent task stack segments and interrupt stack segments. The attributes of the segments adjacent to the task stack segment and the interrupt stack segment are both read-only. Any two adjacent task stack spaces in the task stack segment belong to different cores respectively, and any two adjacent interrupt stack spaces in the interrupt stack segment belong to different cores respectively. Each core only has access rights to the task stack space corresponding to it and has access rights to the interrupt stack space corresponding to it.

[0010] The present application also provides a stack out-of-bounds detection device for a multi-core real-time operating system, comprising:

[0011] A first acquisition module, configured to acquire, when a data access exception occurs in a core, a data address accessed by the core when the data access exception occurs;

[0012] A first determination module, used for determining whether the data address is adjacent to the stack space according to the address of each task stack space and the address of each interrupt stack space;

[0013] The second determination module is used to determine that a stack cross-border occurs when the data address is adjacent to the stack space; wherein:

[0014] The memory space of the multi-core real-time operating system includes independent task stack segments and interrupt stack segments. The attributes of the segments adjacent to the task stack segment and the interrupt stack segment are both read-only. Any two adjacent task stack spaces in the task stack segment belong to different cores respectively, and any two adjacent interrupt stack spaces in the interrupt stack segment belong to different cores respectively. Each core only has access rights to the task stack space corresponding to it and has access rights to the interrupt stack space corresponding to it.

[0015] The present application also provides an electronic device, comprising: a memory for storing a computer program; and a processor for implementing the steps of any of the above-mentioned stack out-of-bounds detection methods for a multi-core real-time operating system when executing the computer program.

[0016] The present application also provides a computer-readable storage medium, in which a computer program is stored, wherein when the computer program is executed by a processor, the steps of any of the above-mentioned stack out-of-bounds detection methods for a multi-core real-time operating system are implemented.

[0017] The present application also provides a computer program product, including a computer program, which implements the steps of any of the above-mentioned stack out-of-bounds detection methods for a multi-core real-time operating system when executed by a processor.

[0018] Through this application, since the task stack segment and the interrupt stack segment are both independent segments in the memory space, and the attributes of the two adjacent segments of the task stack segment are read-only, and the attributes of the two adjacent segments of the interrupt stack segment are also read-only, the task stack space at both ends of the task stack segment will not step on the two segments adjacent to the task stack segment, and the interrupt stack space at both ends of the interrupt stack segment will not step on the two segments adjacent to the middle stack segment. In addition, since any two adjacent task stack spaces in the task stack segment belong to different cores, and different cores only have access rights to the task stack space of the task corresponding to the core, each interrupt stack space of the interrupt stack segment corresponds to each core one by one, and each core only has access rights to the interrupt stack space corresponding to it. When the task stack space is out of bounds, or the interrupt stack space is out of bounds, the system will automatically report an error and generate a data access exception. Therefore, in this application, by determining whether the data address accessed by the core is adjacent to the stack space when determining that the core has a data access exception, it can be determined whether a stack out of bounds has occurred. Therefore, the technical problems of being unable to detect stack out-of-bounds during multi-tasking, high overhead, and poor detection timeliness can be solved, so that the stack out-of-bounds problem can be discovered in time during multi-tasking without adding additional execution programs or setting additional storage space, thereby reducing detection overhead and improving detection timeliness. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0020] Figure 1 A hardware architecture diagram of a system-level integrated circuit of a multi-core processor in the related art;

[0021] Figure 2 A flowchart of a stack out-of-bounds detection method for a multi-core real-time operating system provided in an embodiment of the present application;

[0022] Figure 3 A flowchart of another stack out-of-bounds detection method for a multi-core real-time operating system provided in an embodiment of the present application;

[0023] Figure 4 A schematic diagram of memory space distribution of a real-time operating system in the related art;

[0024] Figure 5 A schematic diagram of memory space distribution of a multi-core processor real-time operating system provided in an embodiment of the present application;

[0025] Figure 6A schematic diagram of the structure of a stack out-of-bounds detection device for a multi-core real-time operating system provided in an embodiment of the present application. DETAILED DESCRIPTION

[0026] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0027] It should be noted that, in the description of this application, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in this application are used to distinguish similar objects, and are not used to describe a specific order or sequence.

[0028] In order to enable those skilled in the art to better understand the present application, the present application is further described in detail below in conjunction with the accompanying drawings and specific implementation methods.

[0029] In conjunction with the specific application environment architecture or specific hardware architecture on which the execution of the stack out-of-bounds detection method of the multi-core real-time operating system depends, the specific application environment architecture or specific hardware architecture is described herein.

[0030] In a system-level integrated circuit using an ARM (Advanced RISC Machines, RISC (Reduced Instruction Set Computer) microprocessor) multi-core processor, the underlying hardware architecture is as follows Figure 1 As shown, the system-level integrated circuit includes an ARM multi-core processor (such as Croex-A55), on-chip memory, and various hardware IP (Internet Protocol) components. Among them, each core in the ARM multi-core processor (such as Core 0, Core 1, ..., Core n) can run its own tasks, and its internal memory access unit (Memory Management Unit, MMU) is independent of each other. The accessible address space attributes can be configured independently. The MMU unit can limit the access range of the corresponding core. If an illegal memory address is accessed, the CPU exception will be reported and related exception information will be provided.

[0031] In an embedded real-time operating system using an ARM (Advanced RISC Machines, RISC microprocessor) multi-core processor, there are multiple cores that can execute code independently, and each core runs a corresponding task. In this multi-tasking scenario, if a task has a stack out-of-bounds, it will step on the stack space of the adjacent task or the global variables used by other tasks, causing problems in the running of the task whose stack space is stepped on. After a stack out-of-bounds problem occurs, the problem symptoms vary. Sometimes the data status is inconsistent, the result of the task running is wrong, and sometimes it causes the task to crash. In addition, stack out-of-bounds problems are sporadic problems most of the time, and the problem symptoms are also different, making it particularly difficult to locate. How to detect stack out-of-bounds as soon as possible when a stack out-of-bounds problem occurs is a problem that needs to be solved in real-time operating systems.

[0032] Based on this, an embodiment of the present invention provides a stack out-of-bounds detection method for a multi-core real-time operating system that can detect stack out-of-bounds problems in a timely manner, and the method is described in detail in combination with the execution process of the stack out-of-bounds detection method for a multi-core real-time operating system. The method is applied to a multi-core real-time operating system, wherein the memory space of the multi-core real-time operating system includes independent task stack segments and interrupt stack segments, and the attributes of the segments adjacent to the task stack segment and the interrupt stack segment are both read-only, and any two adjacent task stack spaces in the task stack segment belong to different cores respectively, and any two adjacent interrupt stack spaces in the interrupt stack segment belong to different cores respectively, and each core only has access rights to the task stack space corresponding to it and has access rights to the interrupt stack space corresponding to it.

[0033] It should be noted that for the memory space of a multi-core operating system, in order to quickly detect stack bounds and reduce detection overhead, the embodiments of the present invention can be performed by setting the distribution of task stack space and interrupt stack space in the memory space and configuring the access rights of each core to the corresponding task stack space and each core to the corresponding interrupt stack space, so that stack bounds can be detected in time when the stack space occurs.

[0034] The memory space of the multi-core implementation operating system in the embodiment of the present application has independent task segments and interrupt stack segments. The task segment includes multiple task segment spaces, and the task segment is located between the other two segments with read-only attributes in the memory space, that is, the attributes of the previous segment and the next segment adjacent to the task segment are both read-only. The interrupt stack segment includes interrupt stack spaces corresponding to each core, that is, one core corresponds to an interrupt stack space, and the entire interrupt stack is also located between two segments with read-only attributes in the memory space, that is, the attribute of the previous adjacent segment of the interrupt stack is read-only, and the attribute of the next adjacent segment is also read-only. Since the attributes of the two segments adjacent to the task stack segment are read-only, and the attributes of the two segments adjacent to the interrupt stack segment are also read-only, if the stack space at both ends of the task stack segment or the interrupt stack segment has a stack out of bounds for the external adjacent segment, and the space where the adjacent segment is located is stepped on, a CPU (Central Processing Unit) exception will occur due to a space attribute error. At this time, the corresponding core will report a CPU exception, thereby protecting the first stack space and the last stack space from stack out of bounds.

[0035] In addition, for the task stack segment in the present application, including the task stack space corresponding to each task, since each core is bound to different tasks, the task stack space of each task can be determined according to at least one task bound to each core in the present application, and in order to prevent the stack from crossing the boundary between two adjacent task stack spaces and affecting the stepped task stack space, the present application rearranges each task stack space so that the two adjacent task stack spaces in each arranged task stack space belong to different cores. For the interrupt stack segment, one core corresponds to only one interrupt stack space. Then, the access rights of each core are configured so that one core only has the access rights to at least one task stack space corresponding to it and the access rights to one interrupt stack space corresponding to it. Since the adjacent task stack spaces belong to different cores, if a stack crossing occurs when one core executes a certain task, the CPU exception will be reported because the core has no right to access the adjacent task stack space. Similarly, two adjacent interrupt stack spaces also belong to different cores. Therefore, when a core interrupts and a stack crosses the boundary and steps on another adjacent interrupt stack space, the CPU will report an exception because it has no right to access the other adjacent interrupt stack space. Since a core has no right to access the task stack space and interrupt stack space of other cores, it will not change other task stack spaces or interrupt stack spaces in the event of a stack cross-border, thereby preventing the impact on other tasks.

[0036] Based on the above multi-core real-time operating system, the stack out-of-bounds detection can be implemented by the following method in the embodiment of the present invention. Please refer to Figure 2 A flowchart of a stack out-of-bounds detection method for a multi-core real-time operating system is shown, the method comprising:

[0037] S110: When a data access exception occurs in the core, obtain a data address accessed by the core when the data access exception occurs;

[0038] It should be noted that when the system detects that a core reports a CPU exception, it can determine whether the core has a data access exception based on the CPU exception. The cause of the exception can be obtained by reading the exception symptom register (ESR_ELX) of the core, and whether a data access exception has occurred can be determined based on the cause of the exception. When it is determined that a data access exception has occurred, the data address accessed by the core when the data access exception occurs can be obtained by reading the error address register (FAR_ELX) of the core.

[0039] S120: Determine whether the data address is adjacent to the stack space according to the address of each task stack space and the address of each interrupt stack space;

[0040] It is understandable that, since each task stack space in the task segment and each interrupt stack space in the interrupt stack segment are pre-configured, the addresses corresponding to each task stack space and each interrupt stack space are known. After obtaining the data address accessed by the core when a data access exception occurs, it can be further determined based on the data address whether the data address is adjacent to the task stack space or the interrupt stack space. If the data address is adjacent to the task stack space or the interrupt stack space, it means that the data address is closely adjacent to the stack space.

[0041] S130: When the data address is adjacent to the stack space, it is determined that a stack boundary crossing occurs.

[0042] Since the attribute of the segment adjacent to the task stack segment in this application is read-only, the attribute of the segment adjacent to the interrupt stack segment is also read-only, and every two adjacent task stack spaces belong to different cores, and different cores only have access rights to the task stack space corresponding to them. An interrupt stack space corresponds to a core one-to-one, and only the core corresponding to it has access rights to the interrupt stack space. Therefore, in the case of determining that a data access exception occurs in the core, the accessed data address is adjacent to the stack space, then it can be determined that the core has a stack out of bounds when operating the stack space, and the core has no right to access other spaces adjacent to it, resulting in a data access exception.

[0043] In this application, by independently setting the task stack segment, and setting the task stack segment and the interrupt stack segments between the segments with read-only attributes, and by setting the arrangement of the task stack space of different cores in the task stack segment, each core is configured to have access rights to only the task stack space and interrupt stack space corresponding to it, so as to quickly and timely discover the stack out-of-bounds problem, and in the event of a stack out-of-bounds problem, other spaces will not be trampled, and the execution of other tasks will not be affected. In addition, the present application does not need to set up additional execution programs or additional space for continuous detection, and does not cause additional space loss and performance loss. It only needs to detect stack out-of-bounds when a CPU abnormality is identified, which can greatly reduce the detection overhead, quickly realize the detection of stack out-of-bounds problems, reduce the impact of stack out-of-bounds problems on the system, and ensure code quality.

[0044] Please follow Figure 3 Based on the above embodiments, the embodiments of the present application provide a detailed description of the stack out-of-bounds detection method for a multi-core real-time operating system.

[0045] In one embodiment, in order to quickly locate the stack out-of-bounds problem when a stack out-of-bounds problem is detected, so that the staff can quickly determine the cause of the stack out-of-bounds problem and solve related problems to ensure the reliable operation of the system. After determining that a stack out-of-bounds problem occurs in the above S130, the method may also include:

[0046] Get the core stack exception level when a data access exception occurs;

[0047] According to the stack exception level, the stack where the stack out of bounds occurs is located.

[0048] It should be noted that when a multi-core real-time system (such as an ARM multi-core real-time system) is running, tasks and operating systems are usually run at different exception levels, with tasks running at EL0 and operating systems, interrupts, and exceptions running at EL1. When a stack cross-border occurs and causes the core to access an illegal memory address, a CPU exception is triggered, and the EL level switches from EL0 to EL1. The status of a series of system registers is recorded through the program status register (SPSR_ELX), providing exception-related information to facilitate quick location of the cause of the stack cross-border.

[0049] It can be understood that in the embodiment of the present application, after determining that a stack out-of-bounds problem has occurred, the program status register of the core can be read to obtain the stack exception level used by the core when a data access exception occurs, that is, whether the exception level used is EL0 or EL1. If the core is executing a task when a data access exception occurs, the stack exception level used is EL0. If the core is performing an interrupt operation when a data access exception occurs, the stack exception level used is EL1. The stack out-of-bounds problem can be located based on the determined stack exception level.

[0050] The above process of locating the stack that has exceeded the stack limit according to the stack exception level can be achieved by the following methods:

[0051] According to the stack exception level, combined with the pre-established correspondence between the stack exception level and the stack type, the stack type where the data access exception occurs is determined.

[0052] It should be noted that, in the embodiment of the present invention, the stack type may include a task stack and an interrupt stack, and the stack exception level corresponding to the task stack may be pre-set as Sp_EL0, and the stack exception level corresponding to the interrupt stack may be pre-set as Sp_EL1, so when the stack exception level is obtained, the corresponding stack type may be determined according to the correspondence between the stack exception level and the pre-set stack type and stack exception level. That is, if the stack exception level is Sp_EL0, it means that the task stack is abnormal; if the stack exception level is Sp_EL1, it means that the interrupt stack is abnormal.

[0053] When the stack type is determined to be a task stack, it indicates that the task stack is abnormal. At this time, the task pointer of the task executed by the core when the data access exception occurs can be obtained through the current task acquisition interface provided by the real-time operating system (that is, the task pointer of the task executed before the data access exception occurs is obtained). Further, the corresponding task stack information and task information can be obtained based on the task pointer, wherein the task stack information includes the stack base address and stack size of the task stack, and the task information includes the task name.

[0054] The task stack pointer information is obtained from the core stack pointer register (SP_ELX); the task stack pointer information includes the stack position information of the task stack. It is understandable that the core stack pointer register can be used to identify the position of the stack pointer in different exception levels (SP_EL0 and SP_EL1), and the stack pointer information of the task and the stack pointer information of the interrupt will be automatically maintained when an exception occurs in the core. Therefore, in the embodiment of the present application, when it is determined that the task stack is abnormal, the saved task stack pointer information can be obtained from the stack pointer register.

[0055] Perform stack backtracking according to task stack information and task stack pointer information to obtain first function call stack information when data access exception occurs; generate stack out-of-bounds positioning information according to task information, first function call stack information and data address.

[0056] That is, after obtaining the task stack information and the task stack pointer information, stack backtracing can be performed based on the stack base address in the task stack information and the stack position in the task stack pointer information, so as to obtain the function call stack information when the data access problem occurs, and then further generate the stack out-of-bounds positioning information based on the task name task stack information (such as stack size and stack base address, etc.), the first function call stack information and the data address (the data address obtained in S110) in the task information.

[0057] In the embodiment of the present application, when it is determined that the task stack is abnormal through the stack exception level, the task pointer can be obtained through the current task acquisition interface, so as to quickly and accurately obtain the stack base address and stack size of the task stack, and obtain the task name, and obtain the task stack pointer information in combination with the stack pointer register, and further, the stack backtracking can be realized according to the task stack information and the task stack pointer information, and the corresponding first function call stack information can be obtained, and then the stack out-of-bounds positioning information can be obtained in combination with the task information, the first function call stack information and the data address. The present application can quickly and accurately realize the positioning of the stack out-of-bounds, provide an accurate basis for subsequent operation and maintenance work, and facilitate improving the efficiency of system maintenance.

[0058] In addition, when the stack type is determined to be an interrupt stack, it indicates that the interrupt stack is abnormal. At this time, the interrupt stack information corresponding to the core can be determined from the pre-established correspondence between the core and the interrupt stack space; the interrupt stack information includes the stack base address and stack size of the interrupt stack space. In actual applications, a correspondence between the core number and the interrupt stack space can be established, where the core number and the core are the only corresponding relationship, so that the corresponding interrupt stack space can be determined according to the core number of the core, and the interrupt stack information corresponding to the interrupt stack space can be obtained.

[0059] The interrupt stack pointer information is obtained from the core stack pointer register; the interrupt stack pointer information includes the stack position information of the interrupt stack. That is, since the stack pointer register will automatically maintain the task stack pointer information and the interrupt stack pointer information when the core is abnormal, the interrupt stack pointer information can be obtained from the stack pointer register when it is determined that the interrupt stack is abnormal.

[0060] Perform stack backtracking based on interrupt stack information and interrupt stack pointer information to obtain second function call stack information when data access exception occurs; generate stack out-of-bounds positioning information based on core information, interrupt processing information, second function call stack information and data address.

[0061] It can be understood that after obtaining the interrupt stack information and the interrupt stack pointer information, the stack backtrace can be performed based on the stack base address in the interrupt stack information and the stack position in the interrupt stack pointer information, so as to obtain the second function call stack information when the data access problem occurs, and then further generate the stack out-of-bounds positioning information based on the interrupt processing information, core information (such as core number, etc.), second function call stack information and data address (data address obtained in S110) in the interrupt information.

[0062] This application can quickly and accurately locate the stack out of bounds when an interrupt stack out of bounds occurs, providing an accurate basis for subsequent operation and maintenance work, and facilitating the improvement of system maintenance efficiency.

[0063] In addition, it should be noted that in the present application, the function address information in the call stack can be used according to the stack out-of-bounds location information, and the function call path can be obtained by combining the memory dump file used when the target code corresponding to the function address information is generated.

[0064] The following is a detailed description of how to arrange and set access permissions for each task stack space in the task stack segment and each interrupt stack space in the interrupt stack segment in the memory space of the multi-core real-time operating system in this application:

[0065] like Figure 4 The memory space distribution of the multi-core real-time operating system in the related technology shown in the figure, the memory space in the related technology contains multiple segments, including an exception vector table, a code segment, a read-only data segment, a Bss (Block Started by Symbol, a memory area used to store global variables and static variables that are not initialized or initialized to 0 in the program) segment, a Data segment, an interrupt stack segment, and an operating system heap, etc. Figure 4 The exception vector table in the memory space stores the relevant codes for various CPU exceptions and interrupt processing (the attribute is read-only), the code segment stores all the codes (the attribute is read-only), the read-only data segment stores read-only data (the attribute is read-only), the Bss segment and the Data segment store global data, the interrupt stack segment is the stack space used by each core interrupt processing, and the operating system heap is the space segment used by various tasks and dynamic space applications. That is, in the related art, the task stack space of each task is located in the operating system heap, and all are randomly arranged, among which the size of the general task stack space is an integer multiple of 4KB.

[0066] Determine the binding relationship between tasks and cores based on the task resources in the system, such as the number of tasks to be run and the size of the stack space required by the tasks. Figure 4For example, there are 8 tasks in a multi-core implementation operating system in the related art. Task 1, Task 2, and Task 8 are bound to core 0, Task 4 is bound to core 1, Task 3 and Task 6 are bound to core 2, and Task 5 and Task 7 are bound to core 3. The stack space size of each task is an integer multiple of 4KB. The stack spaces of the original 8 tasks are randomly distributed in the operating system heap space. The task stack spaces used by multiple tasks are applied for in real time in the operating system heap. All task stack spaces are within the operating system heap space, so each core needs to be configured with full access rights to this operating system heap space. In the related art, because each core has access rights to the operating system heap, it also has access rights to the task stack spaces belonging to other tasks within the operating system heap space. When a task has a stack overflow and tramples on the task stack space of other tasks, it cannot be detected by the CPU.

[0067] Based on this, in order to achieve rapid detection of stack overflow and prevent trampling on other spaces when a stack overflow occurs, the present application can arrange the task stack spaces in each task stack segment and the interrupt stack spaces in each interrupt stack segment in the memory space of a multi-core real-time operating system and set access rights for each core in the following manner. This method may further include:

[0068] Set a task stack segment in the memory space of the multi-core implementation operating system, and the attributes of the two segments adjacent to the task stack segment are both read-only;

[0069] Determine at least one task corresponding to each core;

[0070] Arrange the task stack spaces corresponding to each task in an interleaved manner in the task stack segment, so that the tasks corresponding to any two adjacent task stack spaces belong to different cores;

[0071] Configure the task stack access right of each core so that each core only has access rights to the task stack spaces corresponding to itself;

[0072] Move the position of the interrupt stack segment in the memory space between two segments with both attributes being read-only; wherein, the interrupt stack segment is not adjacent to the task stack segment, and each interrupt stack space in the interrupt stack segment corresponds to each core one by one;

[0073] Configure the interrupt stack access right of each core so that each core only has access rights to the interrupt stack space corresponding to itself.

[0074] It should be noted that in the embodiments of the present invention, the task stack spaces originally located in the operating system heap in the memory space can be removed from the operating system heap. These removed task stack spaces can form an independent task stack segment, and this task stack segment can be set between two segments with read-only attributes originally adjacent in the memory space, such as Figure 5As shown, the task stack segment can be set between the code segment and the read-only data segment. The interrupt stack segment is also moved between two adjacent segments with read-only attributes, for example, the interrupt stack segment is moved between the exception vector table and the code segment. Since the memory attributes of the exception vector table, code segment, and read-only data segment are all read-only, if a stack cross-border occurs and steps on the space where these two segments are located, a CPU exception will occur due to a space attribute error, thereby preventing the first stack space and the last stack space of the task stack segment or the interrupt stack segment from stacking out of bounds.

[0075] Furthermore, different cores are bound to at least one task, so the tasks bound to each core can be determined, and then these tasks can be placed in each task stack space in the task stack segment respectively. The task stack spaces corresponding to different cores can be arranged in an interlaced manner, that is, the tasks corresponding to two adjacent task stack spaces belong to different cores.

[0076] In practical applications, the task stack spaces corresponding to each task can be arranged alternately in the task stack segment in the following way to better ensure that the tasks corresponding to two adjacent task stack spaces belong to different cores:

[0077] Determine the unscheduled tasks corresponding to each core;

[0078] Sort the cores from largest to smallest according to the number of unscheduled tasks;

[0079] Determine the first preset number of target cores with the largest number of unscheduled tasks from the sorting, obtain a task from each target core in turn according to the arrangement order of each target core, and place the tasks in different task stack spaces in turn starting from the first task stack space of the task stack segment where no task is placed;

[0080] Return to the step of determining the unscheduled tasks corresponding to each core, until each task of each core is placed in the corresponding task stack space, so that the tasks corresponding to two adjacent task stack spaces belong to different cores.

[0081] For example, core 0 is bound to three tasks: task 1, task 2, and task 8, core 2 is bound to two tasks: task 3 and task 6, core 3 is bound to two tasks: task 5 and task 7, and core 1 is bound to one task: task 4. Before scheduling, all tasks are not scheduled. These tasks that have not been scheduled in the task stack segment are called unscheduled tasks. Then, the number of unscheduled tasks is in the order of core 0>core 2>core 3>core 1 from large to small. If there are multiple cores with the same number of unscheduled tasks, they can be sorted according to the principle of the smaller core number being in the front.

[0082] According to the sorted cores, a task is taken from each of the first two cores (core 0 and core 2) with the largest number of unassigned tasks and placed in different task stack spaces in the task stack segment in order. Figure 5 As shown, that is, task 1 is taken out from core 0 and placed in the first task stack space of the task segment stack, and task 3 is taken out from core 2 and placed in the second task stack space of the task segment stack;

[0083] After the above arrangement of taking one task from each of the first two cores with the largest number of unscheduled tasks, the number of unscheduled tasks corresponding to each core has changed. Considering that some cores have more tasks bound to them and some cores have fewer tasks bound to them, in order to make the two adjacent tasks in each finally arranged task stack space belong to different cores, the present application can further reorder the unscheduled tasks according to the changed number of tasks of each core. For example, at this time, core 0 has two tasks: task 2 and task 8, core 3 has two tasks: task 5 and task 7, core 2 has one task: task 6, and core 1 has one task: task 4, so the order of the number of unscheduled tasks from large to small is core 0>core 3>core 2>core 1. Then repeat the steps of taking one task from each of the first two cores with the largest number of unscheduled tasks according to the sorted cores and placing them in order in different task stack spaces of the task stack segment.

[0084] Repeat the above steps until all tasks are placed in the corresponding task stack space, so that any two adjacent task stack spaces in the arranged task stack spaces belong to different cores, such as Figure 5 As shown, any two adjacent tasks belong to different cores.

[0085] That is, in a multi-core simultaneous operating system, the number of tasks bound to each core is different. In order to achieve mutual protection between different tasks of different cores, the present application proposes to arrange the tasks from most to least according to the number of unscheduled tasks bound to each core, and each time, one of the two cores with the largest number of unscheduled tasks is taken for arrangement, so that the tasks corresponding to two adjacent task stack spaces belong to different cores, providing a basis for mutual protection of task stack spaces.

[0086] In addition, it should be noted that in the process of interleaving the task stack space corresponding to each task in the task stack segment, after the tasks of other cores have been arranged, if there are multiple unarranged tasks on the remaining core, an error prompt will be given so as to determine the load imbalance of each core based on the error prompt and readjust the binding relationship between each task and the core.

[0087] It is understandable that if in the process of scheduling tasks, there is still one core left with multiple unscheduled tasks, it means that the loads of the cores in the system are extremely unbalanced and the utilization of multiple cores is too low. In order to improve the utilization of cores and improve system performance, error prompts can be used to prompt staff to adjust the binding relationship between cores and tasks in a timely manner, so that the tasks bound to each core are more reasonable, thereby improving core utilization and improving system performance.

[0088] It should also be noted that after the arrangement is completed, the access rights of each core can be further configured, and the page table of the task stack space corresponding to the task bound to the core can be configured. For example, the page table of the task stack space corresponding to task 1, task 2 and task 8 is configured for core 0, the page table of the task stack space corresponding to task 4 is configured for core 1, the page table of the task stack space corresponding to task 3 and task 6 is configured for core 2, and the page table of the task stack space corresponding to task 5 and task 7 is configured for core 3. The core can only locate the corresponding task stack space according to the configured page table, so that the first and second address spaces of each task are inaccessible to the core corresponding to the task. If a stack out-of-bounds occurs, the core where the task is located will report the CPU exception immediately when the out-of-bounds occurs. Therefore, the stack out-of-bounds detection method of the multi-core real-time operating system provided above can detect the stack out-of-bounds immediately.

[0089] It is understandable that in a real-time operating system, each core needs to handle interrupts. When an interrupt is executed, a corresponding interrupt stack space is required. Since one core only corresponds to one interrupt stack space, it is possible to configure a page table for each core only with the interrupt stack space corresponding to it, so that each core only has access rights to the interrupt stack space corresponding to it. Once an interrupt stack crosses the boundary, the CPU exception will be reported immediately.

[0090] That is, the present application rearranges the positions of the task stack segments and the interrupt stack segments in the memory space in the multi-core real-time operating system, sets the space of the system's task stack segments and the interrupt stack segments in the middle of the two read-only segments in the memory space, and implements cross-boundary protection between memory segments through the read-only segments. Then, by utilizing the characteristics of the ARM multi-core processor, the access permissions of the task stack space and interrupt stack space that each core needs to access are separately configured, thereby realizing mutual protection of each stack space, which is conducive to improving the timeliness of stack cross-boundary detection.

[0091] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method.

[0092] The embodiment of the present application also provides a stack out-of-bounds detection device for a multi-core real-time operating system, please refer to Figure 6 , the device comprises:

[0093] A first acquisition module 11 is used to acquire the data address accessed by the core when the data access exception occurs;

[0094] A first determination module 12, used to determine whether the data address is adjacent to the stack space according to the address of each task stack space and the address of each interrupt stack space;

[0095] The second determination module 13 is used to determine that a stack cross-border occurs when the data address is adjacent to the stack space; wherein:

[0096] The memory space of a multi-core real-time operating system includes independent task stack segments and interrupt stack segments. The attributes of the segments adjacent to the task stack segment and the interrupt stack segment are read-only. Any two adjacent task stack spaces in the task stack segment belong to different cores, and any two adjacent interrupt stack spaces in the interrupt stack segment belong to different cores. Each core only has access rights to the corresponding task stack space and the corresponding interrupt stack space.

[0097] In one embodiment, the device further comprises:

[0098] A second acquisition module is used to acquire a stack exception level of the core when a data access exception occurs;

[0099] The positioning module is used to locate the stack where the stack crosses the boundary according to the stack exception level.

[0100] In one embodiment, the positioning module includes:

[0101] A first determining unit, configured to determine the type of stack where the data access exception occurs according to the stack exception level and a pre-established correspondence between the stack exception level and the stack type;

[0102] A first acquisition unit is used to acquire a task pointer of a task executed by the core when a data access exception occurs through a current task acquisition interface provided by the real-time operating system when the stack type is a task stack;

[0103] A second acquisition unit is used to acquire corresponding task stack information and task information according to the task pointer; the task stack information includes a stack base address and a stack size of the task stack, and the task information includes a task name;

[0104] A third acquisition unit is used to acquire task stack pointer information from the core stack pointer register; the task stack pointer information includes stack position information of the task stack;

[0105] A fourth acquisition unit, used for performing stack backtracing according to the task stack information and the task stack pointer information, and acquiring the first function call stack information when the data access exception occurs;

[0106] The first generating unit is used to generate stack out-of-bounds positioning information according to the task information, the first function call stack information and the data address.

[0107] In one embodiment, the device may further include:

[0108] A second determining unit is used to determine the interrupt stack information corresponding to the core from the pre-established correspondence between the core and the interrupt stack space when the stack type is an interrupt stack; the interrupt stack information includes a stack base address and a stack size of the interrupt stack space;

[0109] A fifth acquisition unit, used to acquire interrupt stack pointer information from the stack pointer register of the core; the interrupt stack pointer information includes stack position information of the interrupt stack;

[0110] A sixth acquisition unit, configured to perform stack backtracing according to the interrupt stack information and the interrupt stack pointer information, and acquire the second function call stack information when the data access exception occurs;

[0111] The second generating unit is used to generate stack out-of-bounds positioning information according to the core information, interrupt processing information, second function call stack information and data address of the core.

[0112] In one embodiment, the method may further include:

[0113] A setting module is used to set a task stack segment in the memory space of the multi-core implementation operating system, and the attributes of two segments adjacent to the task stack segment are both read-only;

[0114] A third determination module is used to determine at least one task corresponding to each core;

[0115] An arrangement module is used to arrange the task stack spaces corresponding to each task in an interlaced manner in the task stack segment, so that the tasks corresponding to any two adjacent task stack spaces belong to different cores;

[0116] A first configuration module is used to configure the task stack access rights of each core so that each core only has access rights to each task stack space corresponding to itself;

[0117] A moving module is used to move the position of the interrupt stack segment of the memory space to between two segments whose attributes are both read-only; wherein the interrupt stack segment is not adjacent to the task stack segment, and each interrupt stack space in the interrupt stack segment corresponds to each core one by one;

[0118] The second configuration module is used to configure the interrupt stack access rights of each core so that each core only has access rights to the interrupt stack space corresponding to itself.

[0119] In one embodiment, the arrangement module includes:

[0120] A third determining unit is used to determine the unscheduled tasks corresponding to each core;

[0121] The sorting unit is used to sort the cores from large to small according to the number of unscheduled tasks;

[0122] an arrangement unit, for determining a preset number of target cores with the largest number of unarranged tasks from the sorting, obtaining a task from each target core in sequence according to the arrangement sequence of each target core, and placing the tasks in different task stack spaces in sequence starting from the first task stack space of the task stack segment where no task is placed;

[0123] The returning unit is used to trigger the third determining unit until each task of each core is placed in the corresponding task stack space, so that the tasks corresponding to two adjacent task stack spaces belong to different cores.

[0124] In one implementation, the interrupt stack segment is located between the exception vector table and the code segment, and the task stack segment is located between the code segment and the read-only data segment.

[0125] It should be noted that the stack out-of-bounds detection device for a multi-core real-time operating system provided in the present application has the same beneficial effects as the stack out-of-bounds detection method for a multi-core real-time operating system provided in the above-mentioned embodiments. For the description of the features in the embodiments corresponding to the stack out-of-bounds detection device for a multi-core real-time operating system, please refer to the relevant description of the embodiments corresponding to the stack out-of-bounds detection method for a multi-core real-time operating system, which will not be repeated here one by one.

[0126] An embodiment of the present application also provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to execute the steps in any of the above-mentioned stack out-of-bounds detection method embodiments for a multi-core real-time operating system.

[0127] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored, wherein the computer program is configured to execute the steps of any of the above-mentioned stack out-of-bounds detection method embodiments for a multi-core real-time operating system when running.

[0128] In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media that can store computer programs, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.

[0129] An embodiment of the present application further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the steps in any of the above-mentioned stack out-of-bounds detection method embodiments for a multi-core real-time operating system are implemented.

[0130] An embodiment of the present application also provides another computer program product, including a non-volatile computer-readable storage medium, the non-volatile computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, implementing the steps of any of the above-mentioned stack out-of-bounds detection method embodiments of a multi-core real-time operating system.

[0131] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0132] The above is a detailed introduction to a stack out-of-bounds detection method, device, electronic device and computer-readable storage medium for a multi-core real-time operating system provided by the present application. Specific examples are used herein to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea. It should be pointed out that for ordinary technicians in this technical field, without departing from the principles of the present application, several improvements and modifications can be made to the present application, and these improvements and modifications also fall within the scope of protection of the claims of the present application.

Claims

1. A stack out-of-bounds detection method for a multi-core real-time operating system, characterized in that: include: In the case where a data access exception occurs in the core, obtaining a data address accessed by the core when the data access exception occurs; Determining whether the data address is adjacent to the stack space according to the address of each task stack space and the address of each interrupt stack space; When the data address is adjacent to the stack space, it is determined that a stack cross-border occurs; wherein: The memory space of the multi-core real-time operating system includes independent task stack segments and interrupt stack segments. The attributes of the segments adjacent to the task stack segment and the interrupt stack segment are both read-only. Any two adjacent task stack spaces in the task stack segment belong to different cores respectively, and any two adjacent interrupt stack spaces in the interrupt stack segment belong to different cores respectively. Each core only has access rights to the task stack space corresponding to it and has access rights to the interrupt stack space corresponding to it.

2. The stack out-of-bounds detection method for a multi-core real-time operating system according to claim 1, characterized in that: After determining that a stack out of bounds occurs, the method further includes: Obtaining a stack exception level of the core when the data access exception occurs; According to the stack exception level, the stack where the stack cross-border occurs is located.

3. The stack out-of-bounds detection method for a multi-core real-time operating system according to claim 1, characterized in that: The step of locating the stack that has crossed the stack boundary according to the stack exception level includes: According to the stack exception level, combined with a pre-established correspondence between the stack exception level and the stack type, determining the stack type where the data access exception occurs; In the case where the stack type is a task stack, obtaining a task pointer of the task executed by the core when the data access exception occurs through a current task acquisition interface provided by the real-time operating system; Acquire corresponding task stack information and task information according to the task pointer; the task stack information includes the stack base address and stack size of the task stack, and the task information includes the task name; Acquire task stack pointer information from the stack pointer register of the core; the task stack pointer information includes stack position information of the task stack; Perform stack backtracing according to the task stack information and the task stack pointer information to obtain the first function call stack information when the data access exception occurs; Stack out-of-bounds location information is generated according to the task information, the first function call stack information and the data address.

4. The stack out-of-bounds detection method for a multi-core real-time operating system according to claim 3, characterized in that: Also includes: In the case where the stack type is an interrupt stack, determining interrupt stack information corresponding to the core from a pre-established correspondence between the core and the interrupt stack space; The interrupt stack information includes a stack base address and a stack size of the interrupt stack space; Obtaining interrupt stack pointer information from a stack pointer register of the core; the interrupt stack pointer information includes stack position information of the interrupt stack; Perform stack backtracing according to the interrupt stack information and the interrupt stack pointer information to obtain the second function call stack information when the data access exception occurs; Stack out-of-bounds location information is generated according to the core information of the core, the interrupt processing information, the second function call stack information and the data address.

5. The stack out-of-bounds detection method for a multi-core real-time operating system according to any one of claims 1 to 4, characterized in that: Also includes: Setting a task stack segment in the memory space of the multi-core implementation operating system, wherein the attributes of two segments adjacent to the task stack segment are both read-only; Determine at least one task corresponding to each core; The task stack spaces corresponding to the tasks are arranged alternately in the task stack segment, so that the tasks corresponding to any two adjacent task stack spaces belong to different cores; Configuring the task stack access rights of each core so that each core only has access rights to each task stack space corresponding to itself; The interrupt stack segment of the memory space is moved between two segments both of which have read-only attributes; wherein the interrupt stack segment is not adjacent to the task stack segment, and each interrupt stack space in the interrupt stack segment corresponds to each core one by one; The interrupt stack access rights of each core are configured so that each core only has access rights to the interrupt stack space corresponding to itself.

6. The stack out-of-bounds detection method for a multi-core real-time operating system according to claim 5, characterized in that: The step of arranging the task stack spaces corresponding to the tasks in the task stack segment in an interlaced manner so that the tasks corresponding to any two adjacent task stack spaces belong to different cores includes: Determining unscheduled tasks corresponding to each of the cores; Sort the cores from largest to smallest according to the number of unscheduled tasks; Determine the first preset number of target cores with the largest number of unscheduled tasks from the sorting, obtain a task from each target core in sequence according to the arrangement order of each target core, and sequentially place the tasks in different task stack spaces starting from the first task stack space in the task stack segment where no task is placed; Return to the step of determining the unscheduled tasks corresponding to each of the cores until each task of each of the cores is placed in the corresponding task stack space, so that the tasks corresponding to two adjacent task stack spaces belong to different cores.

7. The stack out-of-bounds detection method for a multi-core real-time operating system according to claim 5, characterized in that: The interrupt stack segment is located between the exception vector table and the code segment, and the task stack segment is located between the code segment and the read-only data segment.

8. A stack out-of-bounds detection device for a multi-core real-time operating system, characterized in that: include: A first acquisition module, configured to acquire, when a data access exception occurs in a core, a data address accessed by the core when the data access exception occurs; A first determination module, used for determining whether the data address is adjacent to the stack space according to the address of each task stack space and the address of each interrupt stack space; The second determination module is used to determine that a stack cross-border occurs when the data address is adjacent to the stack space; wherein: The memory space of the multi-core real-time operating system includes independent task stack segments and interrupt stack segments. The attributes of the segments adjacent to the task stack segment and the interrupt stack segment are both read-only. Any two adjacent task stack spaces in the task stack segment belong to different cores respectively, and any two adjacent interrupt stack spaces in the interrupt stack segment belong to different cores respectively. Each core only has access rights to the task stack space corresponding to it and has access rights to the interrupt stack space corresponding to it.

9. An electronic device, characterized in that: include: Memory for storing computer programs; A processor, configured to implement the steps of the stack out-of-bounds detection method for a multi-core real-time operating system as described in any one of claims 1 to 7 when executing the computer program.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the steps of the stack out-of-bounds detection method for a multi-core real-time operating system as claimed in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Method for monitoring task stack overflow

    CN101154180A

  • Tasks stack overflow detection method, device and computer system thereof

    CN101183331A

  • Multi-core parallel system processing method based on hardware protection

    CN107357666A

  • Task stack management method and apparatus

    CN107643943A

  • Stack overflow detection system and method

    CN108268770A