Concurrent testing method and system for protocol and interrupt program in industrial control system
By performing event sequence analysis and partial sequence relationship closure calculation of protocols and interrupt programs in the industrial control system, the problem of data competition detection is solved, and efficient and accurate data competition detection is achieved.
Patent Information
- Application Number
- CN202411904005.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-23
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2044-12-23
AI Technical Summary
The prior art is difficult to effectively detect and locate data competition problems between protocols and interrupt programs in industrial control systems, resulting in system abnormalities and crashes.
By instrumenting the test program, recording events, generating the original execution sequence, filtering irrelevant events, identifying interrupt information, constructing an event sequence that can trigger data competition, calculating the necessary event sets and partial order sets, using directed graphs to represent partial order relationships, and performing closure calculations to judge the feasibility of the event sequence.
The authenticity of potential data competition in the industrial control system is realized in polynomial time, avoid false alarms, and improve the accuracy and reliability of detection.
Smart Images

Figure CN120029902A_ABST
Abstract
Description
Technical Field
[0001] The invention belongs to the field of software testing and software reliability, and in particular relates to a concurrent testing method for a protocol and an interrupt program in an industrial control system. Background Art
[0002] Industrial control systems are widely used in aerospace, automotive electronics, medical electronics and other fields, which have extremely high requirements for system security and stability. Protocols and interrupt drivers in industrial control systems process system tasks in real time by responding to external or internal data and signals. Interrupt drivers use a large amount of shared data to implement communication and data interaction between main tasks and interrupts and different interrupts. However, due to the uncertainty of protocols and interrupt drivers, various concurrency vulnerabilities often arise, such as data competition, atomicity violation and deadlock. Such problems are difficult to detect and locate. Data competition, as one of the most common types of concurrency errors, often occurs when multiple concurrent execution flows (such as concurrent execution of protocols, alternation between main tasks and interrupts, etc.) access the same shared resource at the same time, and at least one operation is a write operation. In these cases, the execution order of the program may be uncertain, which may lead to system abnormalities or even crashes.
[0003] At present, although there are a large number of data competition detection methods for multi-threaded programs, these methods cannot be directly applied to protocol programs and interrupt drivers in embedded systems such as industrial control. Data competition detection methods for protocols and interrupt programs in industrial control systems are relatively scarce. With the increase in system complexity, effective protocol testing not only needs to verify the functionality and performance of the protocol, but also needs to ensure the accuracy and timeliness of data transmission in multi-tasking and concurrent environments. Protocol testing is the process of verifying and evaluating communication protocols to ensure that their functionality, performance and reliability meet predetermined standards, including verifying the protocol's message format, state transfer, data integrity and its behavior under different conditions. The main methods of protocol testing at present include: model-driven testing, by establishing a formal model of the communication protocol, researchers can simulate and test various message interactions and interrupt situations. This method helps to identify potential data competition and deadlock problems, but the accuracy and completeness of the model are still insufficient when dealing with interrupt driver programs; state-based testing: This method evaluates the behavior of the protocol in concurrent scenarios by tracking the changes in system state under different events, but there is a state explosion problem in applications that require frequent interrupts and switches; restricted interrupt procedures (RID) technology improves random testing by eliminating abnormal interrupts; lightweight marking technology detects data competition through synchronization rules based on interrupt switches, but it relies on virtual systems to simulate the program execution environment, frequently triggering interrupts to generate enough execution interleaving sequences, resulting in a sharp increase in the number of paths, bringing high execution overhead, blocking the main task process, and violating the timing design of the interrupt program. At the same time, these methods only consider the synchronization mechanism based on the interrupt switch, ignoring the custom synchronization mechanism that is widely present in protocols and interrupt programs in industrial control systems. For example, flag variables are often used for custom synchronization, but these variables are not uniformly declared and defined, making them difficult to identify, which greatly affects the partial order of memory access, resulting in a large number of false positives and reducing the accuracy of detection. In general, the current data competition detection methods for protocols and interrupt programs in industrial control systems still have many limitations in terms of accuracy and practicality, and further research and improvement are urgently needed to improve the detection effect. Summary of the invention
[0004] The purpose of the present invention is to provide a concurrent testing method and system for protocols and interrupt programs in an industrial control system, which can detect whether a potential event sequence that can trigger data competition can actually occur, and can obtain the detection result within polynomial time. The detected data competition is authentic and has no false alarms, which effectively solves the problem of identifying potential data competition in complex interrupt programs.
[0005] To achieve the above object, the present invention adopts the following technical solutions:
[0006] A concurrent testing method for a protocol and an interrupt program in an industrial control system comprises the following steps:
[0007] Instrument the program under test, record events, and generate the original execution sequence;
[0008] Filter irrelevant events in the original execution sequence to obtain a filtered execution sequence;
[0009] Identify interrupt information through static analysis and obtain a set of interrupt-related synchronization operations;
[0010] According to the filtered execution sequence and the set of interrupt-related synchronization operations, an event sequence that can trigger data competition is constructed;
[0011] Determine the necessary event set based on the event sequence that can trigger data competition and the filtered execution sequence;
[0012] According to the necessary event set, the necessary partial order set is calculated;
[0013] According to the necessary event set and the necessary partial order set, a directed graph is used to represent the partial order relationship, where the vertices are events and the edges are the partial order relationships between events.
[0014] A partial order closure calculation is performed based on the directed graph. If a loop occurs during the calculation process, it is determined that the event sequence that can trigger the data competition cannot actually occur; otherwise, it is determined that the event sequence that can trigger the data competition can actually occur, indicating that data competition exists in the program under test.
[0015] Furthermore, the recorded events include memory events, lock events, branch events, and synchronization events.
[0016] Furthermore, irrelevant events filtered include local variables, read-only variables, and redundant branches.
[0017] Furthermore, the steps of identifying interrupt information through static analysis include:
[0018] Parse the source code of the interrupt driver through static analysis and build a program dependency graph;
[0019] By analyzing the static information in the program dependency graph, the interruption information is accurately located and identified. The interruption information includes:
[0020] Interrupt switch operation: involves the instruction sequence of enabling or disabling interrupts, controlling the enabling and disabling of program interrupts;
[0021] Interrupt entry and exit: mark the beginning and end of the interrupt service program, and are the key nodes for program flow switching;
[0022] Flag variable operation: As a lightweight synchronization mechanism, it realizes the coordinated control between interrupts and tasks through explicit read and write operations.
[0023] Furthermore, the steps of constructing an event sequence that can trigger data competition include:
[0024] Find the read-write event pairs that belong to different threads and operate on the same shared variable, which contain at least one write operation;
[0025] The read-write event pairs are interleaved with the events before and after them in the filtered execution sequence to generate an event sequence that can trigger data contention.
[0026] Furthermore, if the filtered execution sequence contains three or more threads, the step of constructing an event sequence that can trigger data competition also includes:
[0027] Identify other thread events in a multithreaded execution sequence that may interfere with a read-write event pair;
[0028] Construct an adjacency set according to the adjacency requirements to ensure that events in other threads are not inserted between read and write event pairs;
[0029] The constructed adjacency set is combined with the event sequence that can trigger data competition as the constraint condition for event sequence generation.
[0030] Furthermore, the necessary event set satisfies four conditions at the same time: program feasibility, observation feasibility, locking feasibility and interruption feasibility.
[0031] Furthermore, the necessary partial order set includes program partial order, observation partial order, lock partial order and interrupt partial order, as well as partial order constraints including that events in the event sequence that can trigger data competition are arranged in a given order;
[0032] The necessary partial order set requires that the partial order satisfies the following asymmetric preemption relationship of the interrupt service routine:
[0033] Interrupt service routines of any priority level are allowed to preempt the running main task;
[0034] An interrupt service routine with a higher priority is allowed to preempt an executing low-priority interrupt service routine;
[0035] An interrupt service routine of any priority cannot preempt an interrupt service routine with a higher priority than itself and can only continue to run after the high-priority interrupt service routine is completed;
[0036] Interrupt service routines of the same priority cannot preempt each other and can only continue to run after the interrupt service routine that was executed first is completed.
[0037] Furthermore, the steps of calculating the partial order closure according to the directed graph include:
[0038] Before performing the partial order closure calculation, first add the partial orders in the necessary partial order set to the intermediate set;
[0039] Then, each partial order relation in the intermediate set is processed. If there is an edge of the partial order relation in the directed graph, a loop is formed after inserting the partial order relation, indicating that the event sequence that can trigger data competition cannot actually occur;
[0040] If the edge of the partial order relation does not exist in the directed graph, the partial order relation is added to the directed graph as a new edge, and the transitive closure, observation closure, lock closure, interruption closure and adjacency closure calculations are performed;
[0041] During the closure calculation process, if the new edge causes a loop to form in the directed graph, it means that the event sequence that can trigger data competition cannot actually occur. Otherwise, it means that the event sequence that can trigger data competition can actually occur.
[0042] A concurrent testing system for protocols and interrupt programs in an industrial control system, comprising:
[0043] The execution sequence acquisition module is used to insert the program to be tested, record events, generate the original execution sequence; filter irrelevant events in the original execution sequence to obtain the filtered execution sequence;
[0044] An interrupt information collection module is used to identify interrupt information through static analysis and obtain a set of interrupt-related synchronization operations;
[0045] An event sequence generation module is used to construct an event sequence that can trigger data competition based on the filtered execution sequence and the set of interrupt-related synchronization operations;
[0046] The sequence feasibility calculation module is used to determine the unnecessary event set and the necessary partial order set based on the event sequence that can trigger data competition and the filtered execution sequence; based on the necessary event set and the necessary partial order set, a directed graph is used to represent the partial order relationship, with the vertices being events and the edges being the partial order relationship between events; partial order closure calculation is performed based on the directed graph, and if a loop occurs during the calculation process, it is judged that the event sequence that can trigger data competition cannot actually occur; otherwise, it is judged that the event sequence that can trigger data competition can actually occur, indicating that data competition exists in the program to be tested.
[0047] The beneficial effects achieved by the present invention include:
[0048] 1. Support preemption relationship modeling of interrupt-driven programs: The present invention processes interrupt thread-related events according to the interrupt priority level in accordance with the asymmetric preemption relationship requirements, ensuring that interrupts of the same priority level cannot preempt each other. After being preempted by a high-priority interrupt, a low-priority interrupt can only continue to run after the high-priority interrupt is completed, accurately reflecting the synchronization mechanism of interrupt-driven embedded software.
[0049] 2. Accurately capture interrupt-related synchronization information: The present invention extracts a set of synchronization operations related to embedded software interrupts by identifying interrupt switch operations, interrupt entry and exit events, and flag variable operations, thereby providing accurate basic information for subsequent data contention analysis.
[0050] 3. Efficient detection of potential data contention: The present invention converts interrupt-related synchronization information into an event sequence of potential data contention, and constructs a necessary event set and a necessary partial order set, and dynamically verifies whether the event sequence can actually occur in combination with closure calculation, thereby efficiently determining whether there is data contention in the program to be tested, thereby improving the accuracy and reliability of detection.
[0051] 4. Solve the problem of concurrent analysis of multi-threads and interrupt programs: The present invention provides a systematic testing solution for the concurrent characteristics of industrial control system protocols and interrupt programs, which can take into account the synchronization relationship between threads and interrupt-driven behavior, and overcome the problem of insufficient detection accuracy of traditional methods in complex concurrent scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] Figure 1 The present invention is a flowchart of a method for concurrently testing protocols and interrupt programs in an industrial control system according to an embodiment of the present invention. DETAILED DESCRIPTION
[0053] In order to make the various technical features and advantages or technical effects in the above technical solutions of the present invention more obvious and easy to understand, they are described in detail below with reference to the accompanying drawings.
[0054] This embodiment discloses a concurrent testing method for protocols and interrupt programs in an industrial control system. Figure 1 As shown, the processing steps can be divided into four stages: execution sequence acquisition, interruption information collection, event sequence generation, and sequence feasibility calculation, which can be respectively completed by four modules of a concurrent test system for protocols and interrupt programs in an industrial control system disclosed in this embodiment: execution sequence acquisition module, interruption information collection module, event sequence generation module, and sequence feasibility calculation module. The specific descriptions of the above four stages are as follows:
[0055] 1. Execution sequence acquisition phase
[0056] The program to be tested is instrumented to record memory events, lock events (lock application events, lock acquisition events, release events), branch events (conditional judgment) and synchronization events (thread related) to obtain the original execution sequence. The execution sequence refers to the trajectory of the interleaved execution of multiple threads in a concurrent program, represented by σ. Events are elements of the execution sequence, represented by e; the relationship between events is called a partial order, represented by <. Events are composed of four attributes, represented by e=et(thrd,evnt,obj). Among them, et represents the event type; thrd represents the thread number to which the event belongs; evnt represents the sequence number of the event in the thread to which it belongs; obj represents the object acted on by the event, including memory locations and locks. Events can be divided into the following four categories according to the event type:
[0057] (1) Memory events. Read events and write events represent the read and write operations on memory location x, denoted as r(x) and w(x), respectively, and the event types are r and w.
[0058] (2) Lock events. The application event, acquisition event, and release event represent the application, holding, and release operations of lock l, which are denoted as req(l), acq(l), and rel(l), and the event types are req, acq, and rel.
[0059] (3) Branch event. A branch event indicates that there is a program path (conditional judgment) that has not been recorded in the execution sequence, denoted as br, and the event type is br.
[0060] (4) Synchronous events. Synchronous events include thread creation and merging. The number of synchronous events is relatively small and can be converted into existing concepts.
[0061] After obtaining the original execution sequence, the execution sequence acquisition phase will filter out a large number of events in the original execution sequence that do not affect other threads, including local variables, read-only variables, and redundant branches, thereby obtaining a filtered execution sequence.
[0062] 2. Interrupt Information Collection Phase
[0063] Identify the explicit and implicit interrupt switch operations in the program under test, including the standard interrupt interface and interrupt registers, and identify the interrupt exit and entry as well as the flag variables, so as to obtain the interrupt-related synchronization operation set. Specifically, the interrupt switch is usually implemented by a specific API or register, such as the standard interrupt switch API: enable_isr(-1) / disable_isr(-1) controls the switch status of all interrupts, enable_isr(i) / disable_isr(i) controls the interrupt isr iIn addition, some systems implement the implicit switch of interrupts by operating interrupt-related hardware, such as using the interrupt enable register IE to open or close the interrupt to achieve two-level control, and controlling the opening and closing of interrupts through switch interrupt control bits EA and ET. At the same time, interrupt-driven embedded software usually also uses flag variables to complete interrupt synchronization operations, that is, to release shared resources through write operations and obtain resources through check operations. Flag variables themselves do not participate in calculations and do not rely on external inputs. They either read and write only constants, or coordinate between the main task and interrupts, or interrupts and interrupts, through value transfer to complete access synchronization to shared resources.
[0064] In the interrupt information collection phase, the above interrupt information is collected through static analysis. Specifically, by establishing a program dependency graph, the key synchronization operations in the interrupt driver are accurately identified. First, the source code in the interrupt driver is parsed, and a control flow graph and a data flow graph are constructed to capture the control dependency and data dependency relationships in the program that may affect the interrupt behavior. On this basis, the control dependency and data dependency are integrated to form a program dependency graph. By analyzing the program dependency graph, the following interrupt synchronization operations can be accurately identified:
[0065] Interrupt switch operation: By identifying the interrupt enable or mask functions (such as enable_isr or disable_isr) that may appear in calling the main task or interrupt service program, the key points of controlling the interrupt status can be captured, and the context and dependencies in the program execution can be determined through program dependency graph analysis.
[0066] Interrupt entry and exit: Identify the starting point (entry) and return point (exit) of the interrupt handling function in the program dependency graph, and accurately locate it by analyzing the interrupt vector and the function call relationship in the interrupt service program.
[0067] Flag variable operation: Use data flow analysis to determine their definition and usage locations. By tracing the dependency chain of flag variables, it is possible to identify whether they are used to synchronize the interaction between interrupts and the main task. For nested flag variables, cross-function analysis is used to further confirm whether they are related to the call of the interrupt service routine.
[0068] By constructing a program dependency graph for the interrupt driver and analyzing it, the standard interrupt interface and interrupt register related operations are collected, and the interrupt exit and entry as well as the flag variable are identified, thereby obtaining a set of interrupt related synchronization operations.
[0069] 3. Event sequence generation phase
[0070] According to the filtered execution sequence and the set of interrupt-related synchronization operations, combined with the pattern requirements of data competition, a pair of events that can potentially trigger data competition is constructed. The two events belong to different threads and are memory read and write events for the same shared variable, and at least one of them is a write operation. The two events are cross-arranged with an event before and after the two events in the filtered execution sequence to construct an event sequence that can trigger data competition, represented by ρ. The event sequence construction method that can trigger data competition ensures that other events in different threads to which the two events belong will not occur between the two events. If the filtered execution sequence contains three or more threads, it is also necessary to add an adjacency set required by the adjacency relationship to ensure that events of other threads will not occur between the two events.
[0071] 4. Sequence feasibility calculation stage
[0072] After obtaining the filtered execution sequence σ and the event sequence ρ that can trigger data competition, the sequence feasibility calculation phase determines whether there is a real execution sequence σ′ such that ρ is its subsequence, and σ′ satisfies the adjacent set The adjacency relationship specified, where D ρ Represents the set of events involved in σ. First, we need to determine the necessary event set X that makes ρ occur, that is, the set of events that must be included in order for the sequence of events that can trigger data competition to actually occur, so that it satisfies program feasibility (events conform to program logic), observation feasibility (branch events after read events can correctly observe the read results), lock feasibility (including the order between all required lock release and acquisition events) and interrupt feasibility (satisfying the preemption relationship between interrupt threads and tasks). After obtaining the necessary event set X, it is necessary to determine the partial order set P that must be satisfied on X, that is, the necessary partial order set. P contains program partial order, observation partial order, lock partial order and interrupt partial order. In addition, to satisfy the adjacency set The specified adjacency relationship also needs to include the sequence partial order specified in ρ. The program partial order requires that P must include the program partial order in σ corresponding to X, and the observation partial order requires that if there is a branch event after the read event in X, then its observation partial order should belong to P. The lock partial order requires that the partial order between the lock acquisition event and the conflicting release event whose corresponding lock release event is not in X should belong to P. The interrupt partial order includes the preemption relationship partial order between the interrupt thread and the main program task and the preemption relationship partial order between the high-priority interrupt thread and the low-priority interrupt thread. The partial order corresponding to the asymmetric preemption relationship of the interrupt-driven program that meets the following requirements should belong to P:
[0073] An interrupt service routine of any priority level can preempt the running main task;
[0074] An interrupt service routine with a higher priority can preempt an executing low-priority interrupt service routine;
[0075] An interrupt service routine of any priority cannot preempt an interrupt service routine with a higher priority than itself and can only continue to run after the high-priority interrupt service routine is completed;
[0076] Interrupt service routines of the same priority cannot preempt each other and can only continue to run after the interrupt service routine that was executed first is completed.
[0077] After obtaining the necessary event set X and the necessary partial order set P, it is necessary to calculate the partial order closure of P to determine whether there is a contradiction in the process. The present invention uses a directed graph G to express the partial order, whose vertices are events and the vertex set is the event set X; the vertex e i To e j The directed edge of represents the partial order between two events. i <e j ,use <e i ,e j > indicates that the calculation process first adds the partial order in the partial order set P to the intermediate set Q, and then calculates each partial order in Q <e 1 ,e 2 >Processing. If G exists <e 2 ,e 1 > directed edges, then if we add <e 1 ,e 2 > will cause a loop in G and a contradiction. At this time, the event sequence ρ that can trigger data competition cannot actually occur. <e 1 ,e 2 >, then <e 1 ,e 2 >Add G, and process the transitive closure, observation closure, lock closure, interruption closure, and adjacency closure caused by the insertion of the new directed edge. If no contradiction is caused in the entire closure calculation process, the event sequence ρ that can trigger data competition can actually occur, that is, there is data competition in the program under test. The calculation rules for the transitive closure, observation closure, lock closure, interruption closure, and adjacency closure caused by the insertion of the new directed edge are as follows:
[0078] (1) Transitive closure: When adding <e 1 ,e 2 >, there is a directed edge <G.pred(e 1 ,t),e 1 > makes G.pred(e 1 ,t) to e 2 Therefore, the new directed edge <G.pred(e 1 ,i),e2 >Add to Q. Similarly, you also need to add <e 1 ,G.succ(e 2 ,i)> is also added to Q. Among them, pred and succ represent the predecessor event and the successor event of the event respectively, and t and i represent the thread number.
[0079] (2) Observe the closure: Check the memory location m involved in σ and find the memory location that precedes e in the same thread. 1 The write event e to m occurs w and in the same thread after e 2 Read event r For all other w Write event e′ that operates on the same memory location w , due to the addition of edge <e 1 ,e 2 >, if e′ w To e r If reachable, insert an edge <e′ w ,e w >; if e w to e′ w If reachable, insert an edge <e r ,e′ w >.
[0080] (3) Lock closure: Check all locks in σ and find the lock that precedes e in the same thread. 1 The last acquisition event e that occurred for lock l acq and in the same thread after e 2 The first release event e of lock l occurs rel . <e 1 ,e 2 >After adding G, it leads to e acq ∝e rel ∧e acq <e rel Therefore, to ensure that the two critical sections are mutually exclusive, we need to add <match σ (e acq ),match σ (e rel )>. Among them, match σ (e) represents the release or acquisition event that matches e in σ, e acq ∝e rel Indicates that these two events are conflicting events.
[0081] (4) Interrupt closure: Check the events in all interrupt synchronization operation sets in σ, and find the event that precedes e in the same thread according to the type of event. 1 The last matching event e that occurredacq and in the same thread after e 2 The first occurrence of the matching event e rel . <e 1 ,e 2 >After adding G, it leads to e acq ∝e rel ∧e acq <e rel Therefore, in order to ensure the asymmetric preemption relationship, it is necessary to add <match σ (e acq ),match σ (e rel )>. For interrupt enable event, interrupt entry event and flag variable read event, the matching events are interrupt disable event, interrupt exit event and flag variable write event respectively.
[0082] (5) Adjacency closure: For all pairs of events in the adjacency set A that require adjacency <(e 1 ,e 2 )> and all threads i are checked. The adjacency set A requires that in each thread i 1 With e 2 The predecessor and successor of G.pred(e 2 ,i) should also be e 1 , so this partial order is added to Q. Similarly, the partial orders generated by the other three cases are also added to Q.
[0083] If a loop is generated during the closure calculation, it can be concluded that ρ cannot actually occur.
[0084] Although the present invention has been disclosed as above by way of embodiments, it is not intended to limit the present invention. Appropriate modifications or equivalent substitutions of the technical solutions of the present invention made by ordinary technicians in the field should all be included in the protection scope of the present invention. The protection scope of the present invention shall be based on what is defined in the claims.
Claims
1. A concurrent testing method for protocols and interrupt programs in an industrial control system, characterized in that: The following steps are involved: Instrument the program under test, record events, and generate the original execution sequence; Filter irrelevant events in the original execution sequence to obtain a filtered execution sequence; Identify interrupt information through static analysis and obtain a set of interrupt-related synchronization operations; According to the filtered execution sequence and the set of interrupt-related synchronization operations, an event sequence that can trigger data competition is constructed; Determine the necessary event set based on the event sequence that can trigger data competition and the filtered execution sequence; According to the necessary event set, the necessary partial order set is calculated; According to the necessary event set and the necessary partial order set, a directed graph is used to represent the partial order relationship, where the vertices are events and the edges are the partial order relationships between events. Perform partial order closure calculation based on directed graphs. If a loop occurs during the calculation, it is determined that the event sequence that can trigger data competition cannot actually occur. Otherwise, it is determined that the event sequence that can trigger the data race can actually occur, indicating that data race exists in the program under test.
2. The method according to claim 1, characterized in that The recorded events include memory events, lock events, branch events, and synchronization events.
3. The method according to claim 1, characterized in that Irrelevant events that are filtered include local variables, read-only variables, and redundant branches.
4. The method according to claim 1, characterized in that The steps to identify interrupt information through static analysis include: Parse the source code of the interrupt driver through static analysis and build a program dependency graph; By analyzing the static information in the program dependency graph, the interruption information is accurately located and identified. The interruption information includes: Interrupt switch operation: involves the instruction sequence of enabling or disabling interrupts, controlling the enabling and disabling of program interrupts; Interrupt entry and exit: mark the beginning and end of the interrupt service program, and are the key nodes for program flow switching; Flag variable operation: As a lightweight synchronization mechanism, it realizes the coordinated control between interrupts and tasks through explicit read and write operations.
5. The method according to claim 1, characterized in that The steps to construct a sequence of events that can trigger a data race are: Find the read-write event pairs that belong to different threads and operate on the same shared variable, which contain at least one write operation; The read-write event pairs are interleaved with the events before and after them in the filtered execution sequence to generate an event sequence that can trigger data contention.
6. The method according to claim 5, characterized in that If the filtered execution sequence contains three or more threads, the step of constructing an event sequence that can trigger data competition also includes: Identify other thread events in a multithreaded execution sequence that may interfere with a read-write event pair; An adjacency set is constructed according to the adjacency relationship requirements to ensure that events in other threads will not be inserted between read and write event pairs; the constructed adjacency set is combined with the event sequence that can trigger data competition as a constraint condition for event sequence generation.
7. The method according to claim 1, characterized in that The necessary event set satisfies four conditions at the same time: program feasibility, observation feasibility, locking feasibility and interruption feasibility.
8. The method according to claim 1, characterized in that Necessary partial order sets include program partial order, observation partial order, lock partial order and interrupt partial order, as well as partial order constraints that events in the event sequence that can trigger data competition are arranged in a given order; The necessary partial order set requires that the partial order satisfies the following asymmetric preemption relationship of the interrupt service routine: Interrupt service routines of any priority level are allowed to preempt the running main task; An interrupt service routine with a higher priority is allowed to preempt an executing low-priority interrupt service routine; An interrupt service routine of any priority cannot preempt an interrupt service routine with a higher priority than itself and can only continue to run after the high-priority interrupt service routine is completed; Interrupt service routines of the same priority cannot preempt each other and can only continue to run after the interrupt service routine that was executed first is completed.
9. The method according to claim 1, characterized in that The steps for calculating the partial order closure based on the directed graph include: Before performing the partial order closure calculation, first add the partial orders in the necessary partial order set to the intermediate set; Then, each partial order relation in the intermediate set is processed. If there is an edge of the partial order relation in the directed graph, a loop is formed after inserting the partial order relation, indicating that the event sequence that can trigger data competition cannot actually occur; If the edge of the partial order relation does not exist in the directed graph, the partial order relation is added to the directed graph as a new edge, and the transitive closure, observation closure, lock closure, interruption closure and adjacency closure calculations are performed; During the closure calculation process, if the new edge causes a loop to form in the directed graph, it means that the event sequence that can trigger data competition cannot actually occur. Otherwise, it means that the event sequence that can trigger data competition can actually occur.
10. A concurrent testing system for protocols and interrupt programs in an industrial control system, implementing the method described in any one of claims 1 to 9, characterized in that: include: The execution sequence acquisition module is used to instrument the program under test, record events, and generate the original execution sequence; Filter irrelevant events in the original execution sequence to obtain a filtered execution sequence; An interrupt information collection module is used to identify interrupt information through static analysis and obtain a set of interrupt-related synchronization operations; An event sequence generation module is used to construct an event sequence that can trigger data competition based on the filtered execution sequence and the set of interrupt-related synchronization operations; The sequence feasibility calculation module is used to determine the unnecessary event set and the necessary partial order set according to the event sequence that can trigger data competition and the filtered execution sequence; according to the necessary event set and the necessary partial order set, a directed graph is used to represent the partial order relationship, where the vertices are events and the edges are the partial order relationship between events; partial order closure calculation is performed according to the directed graph, and if a loop occurs during the calculation process, it is determined that the event sequence that can trigger data competition cannot actually occur; Otherwise, it is determined that the event sequence that can trigger the data race can actually occur, indicating that data race exists in the program under test.
Citation Information
Patent Citations
Data race false positive reduction method based on control flow
CN103678136A
Method for bounded model checking of interrupt-driven system based on partial order reduction
CN104503837A
Automatic detection method for data competition of interrupt-driven embedded system
CN112817787A
Accurate interrupt-driven embedded software data race dynamic detection method
CN115658509A
Universal concurrent defect detection method and system compatible with control flow change and based on partial order relationship
CN116383076A