Method for extracting page information in kernel LRU linked list

By defining the showlru command in the crash tool, the page information of the LRU linked list in the Linux kernel is automatically extracted and displayed, which solves the problem that existing debugging tools cannot directly and clearly display the status of the LRU linked list, improves debugging efficiency and provides intuitive display tools.

CN120104524APending Publication Date: 2025-06-06KIRIN SOFTWARE (BEIJING) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510057828.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-14
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

Existing kernel debugging tools cannot directly and clearly display the status of LRU linked lists, and the analysis is complex and time-consuming. Especially after the system crashes, it is necessary to manually traverse the complex linked list structure, which is cumbersome and prone to errors.

Method used

By writing crash plug-in code, defining showlru commands, using crash tool to load kernel dump files and symbol tables, automatically extract page information from LRU linked lists, and output them to the console in a structured form or save them as files.

Benefits of technology

It realizes the automatic extraction and display of page information in the LRU linked list in the Linux kernel, significantly improving debugging efficiency, reducing misoperation, and providing an intuitive visual display tool.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure SMS_1
    Figure SMS_1
  • Figure SMS_2
    Figure SMS_2
Patent Text Reader

Abstract

The invention relates to the field of memory page management, and particularly provides a method for extracting page information in a kernel LRU linked list, which comprises the following steps of: compiling a showlru.h file and a showlru.c file which comprise showlru commands, and compiling into a shared library; loading a kernel dump file and a kernel symbol table through a crash tool when the system crashes, and obtaining a complete data structure of a kernel when the system crashes; using an extension command to import the shared library into a crash context; the page information in the kernel is obtained through analysis of the imported showlru command; and outputting the page information to a crash console in a structured form or storing the page information as a file for analysis. By means of the scheme, the technical problems that a kernel debugging tool cannot directly and clearly display the state of the LRU linked list, analysis is complex, and time is consumed are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to the field of memory page management, and specifically provides a method for extracting page information in a kernel LRU linked list. Background Art

[0002] In the design and implementation of Linux operating systems, memory management is one of the important factors affecting operating system performance, resource utilization and stability. Modern operating systems usually use a variety of algorithms to efficiently manage memory, among which the LRU (Least Recently Used) algorithm is a commonly used page replacement algorithm, which is widely used to manage the recycling and replacement of virtual memory pages.

[0003] In the Linux kernel, the memory management subsystem uses an LRU linked list to track and manage the status of memory pages. Specifically, memory pages are not only divided into active pages and inactive pages based on access frequency, but also need to be further divided into file pages (file-backed pages) and anonymous pages (anonymous pages) based on their types. File pages refer to memory pages associated with disk files, which can be written back to the file system; anonymous pages are memory pages dynamically allocated by processes, such as stack and heap memory, which are not associated with the file system.

[0004] The Linux kernel uses the lruvec structure to manage these memory pages. There are five main linked lists in the lruvec structure, among which the active linked list of anonymous pages (lru_active_anon) is used to store the most recently active anonymous pages; the inactive linked list of anonymous pages (lru_inactive_anon) is used to store inactive anonymous pages; the active linked list of file pages (lru_active_file) is used to store the most recently active file pages; the inactive linked list of file pages (lru_inactive_file) is used to store inactive file pages; and the unmovable page linked list (lru_unevictable) is used to store unmovable pages.

[0005] When a system crashes, developers need to debug the kernel dump file (vmcore) to determine the cause of the crash and check whether there is a memory leak or page management failure in the kernel. In this case, debuggers often need to analyze the state of the LRU list to understand the management of memory pages when the kernel crashed.

[0006] Existing debugging tools, such as crash, can view the status of the kernel crash by loading the kernel dump file, but the analysis of the data structure related to memory management is not intuitive enough. Debuggers need to manually traverse the LRU list in the lruvec data structure to check the status of each page. This manual method has the following defects:

[0007] Complexity: The data structure of the LRU linked list is relatively complex, requiring debuggers to have deep kernel knowledge to effectively extract and analyze relevant information. Traversing the linked list involves multiple complex kernel data structures, which is cumbersome and error-prone.

[0008] Inefficiency: Manually traversing and analyzing linked lists takes a lot of time, especially when the number of memory pages is huge after a system crash. It is difficult for debuggers to obtain valid information in a short time, resulting in low troubleshooting efficiency.

[0009] Unintuitive: The linked list data output by existing debugging methods is relatively primitive, usually just low-level information such as memory addresses or flags. Debuggers need to parse this information by themselves and manually deduce the page status, lacking intuitive visualization tools.

[0010] Therefore, traditional kernel debugging tools and methods cannot directly and clearly display the status of the LRU list, and the analysis is complex and time-consuming. Developing a method that can automatically extract the LRU list and clearly display the list structure and page status has become an urgent problem to be solved. Summary of the invention

[0011] In order to overcome the above defects, the present invention is proposed to provide a technical solution to the problem that the kernel debugging tool cannot directly and clearly display the status of the LRU linked list, and the analysis is complex and time-consuming.

[0012] The present invention provides a method for extracting page information in a kernel LRU linked list, comprising the following steps:

[0013] S1: Write the crash plug-in code, define the showlru command used to extract the page information in the LRU list, and compile the showlru.h file and showlru.c file containing the showlru command into a shared library;

[0014] S2: Use the crash tool to load the kernel dump file and kernel symbol table when the system crashes, and obtain the complete data structure of the kernel when the system crashes;

[0015] S3: Use the extend command to import the shared library into the crash context;

[0016] S4: Obtain the page information in the kernel by parsing the imported showlru command;

[0017] S5: Output the page information in a structured form to the crash console or save it as a file for analysis.

[0018] Furthermore, the method further comprises the steps of: providing a graphical interface or script tool to display the page information in a chart or graphical manner.

[0019] Furthermore, the page information output to the crash console includes the virtual address, physical address, status flag and reference count of each memory page, and the status flag includes whether the page is dirty, locked, or being written back.

[0020] Further, the step S1 comprises:

[0021] Create a showlru.h file, define a page_data_t structure in the showlru.h file, and declare a sub-function implemented by the showlru.c file in the showlru.h file. The page_data_t structure is used to save the extracted page information;

[0022] Create the showlru.c file, reference the showlru.h and crash / defs.h header files in the showlru.c file, use command_table_entry to define the showlru command, and implement the parsing and help functions of the showlru command;

[0023] Compile the showlru.c file and the showlru.h file into a shared library.

[0024] Further, the implementation process of the showlru command includes:

[0025] Use symbol_value to extract the address and content of root_mem_cgroup in the kernel;

[0026] According to the content of root_mem_cgroup, extract the address and content of all mem_cgroup;

[0027] According to the content of mem_cgroup, extract the address and content of all mem_cgroup_per_node;

[0028] According to the content of mem_cgroup_per_node, extract the address and content of all lruvec structures;

[0029] According to the content of the lruvec structure, extract the starting address and content of all LRU linked lists;

[0030] According to the first node in the LRU linked list content, extract all the page information.

[0031] Furthermore, the lruvec structure includes five linked lists, namely, LRU_INACTIVE_ANON, LRU_ACTIVE_ANON, LRU_INACTIVE_FILE, LRU_ACTIVE_FILE and LRU_UNEVICTABLE, which are used to store inactive anonymous pages, active anonymous pages, inactive file pages, active file pages and unmovable pages respectively.

[0032] Working principle and beneficial effects of the present invention:

[0033] In the technical solution of the present invention, based on the extensibility of the crash tool, the automatic extraction and display of page information in the LRU linked list in the Linux kernel is realized by utilizing its ability to parse the kernel symbol table and data structure. This helps developers to quickly analyze the memory management status after the system crashes. Through the present invention, debuggers do not need to manually traverse the complex linked list structure, and can directly view the LRU linked list information, which significantly improves debugging efficiency and reduces misoperation. DETAILED DESCRIPTION

[0034] Some embodiments of the present invention are described below. It should be understood by those skilled in the art that these embodiments are only used to explain the technical principles of the present invention and are not intended to limit the protection scope of the present invention.

[0035] The present invention is based on the extensibility of the crash tool, utilizes its ability to parse kernel symbol tables and data structures, and combines scripts to realize automatic extraction and display of the LRU linked list in the Linux kernel. A method for extracting page information in a kernel LRU linked list in this embodiment mainly includes the following steps S1-S5.

[0036] Step S1: Use C language to write crash plug-in code, define the showlru command for extracting page information in the LRU list, and compile the showlru.h file and showlru.c file containing the showlru command into a shared library.

[0037] In one embodiment, step S1 includes the following steps:

[0038] S11: Create the showlru.h file, define the page_data_t structure in the showlru.h file and declare the sub-function implemented by the showlru.c file in the showlru.h file. The page_data_t structure is used to save the extracted page information.

[0039] S12: Create the showlru.c file, and reference the showlru.h and crash / defs.h header files in the showlru.c file. The crash / defs.h header file is the public header file of the crash plug-in. Use command_table_entry to define the showlru command, and implement the parsing and help functions of the showlru command. By executing the showlru command, extract the page information in the LRU list.

[0040] In one implementation, the showlru command line parameters are as shown in Table 1:

[0041] Table 1

[0042]

[0043]

[0044] In one embodiment, the implementation process of the showlru command includes: using symbol_value to extract the address and content of the root_mem_cgroup in the kernel; based on the content of the root_mem_cgroup, extracting the addresses and contents of all mem_cgroups; based on the content of the mem_cgroup, extracting the addresses and contents of all mem_cgroup_per_nodes; based on the content of the mem_cgroup_per_node, extracting the addresses and contents of all lruvec structures; based on the content of the lruvec structure, extracting the starting addresses and contents of all LRU linked lists; based on the first node in the LRU linked list content, extracting all page information therein.

[0045] S13: Compile the showlru.c file and the showlru.h file into a shared library.

[0046] Among them, -shared means generating a dynamic shared library, -fPIC means generating address-independent code, and -I / path / to / crash / headers means specifying the header file path of the crash tool.

[0047] S2: Use the crash tool to load the kernel dump file (vmcore) and kernel symbol table (vmlinux) when the system crashes, and obtain the complete data structure of the kernel when the system crashes.

[0048] This step is a necessary process required by the crash framework. It obtains the complete data structure of the kernel when the system crashes before continuing to execute subsequent steps.

[0049] S3: Use the extend command to correctly import the shared library into the crash context and make sure that the showlru command is loaded correctly.

[0050] S4: Parse the lruvec structure in the kernel through the showlru command imported in the crash, and obtain the starting address of the LRU list and related page information from it.

[0051] In one implementation, lruvec includes five linked lists, namely, LRU_INACTIVE_ANON, LRU_ACTIVE_ANON, LRU_INACTIVE_FILE, LRU_ACTIVE_FILE, and LRU_UNEVICTABLE, which store inactive anonymous pages, active anonymous pages, inactive file pages, active file pages, and unmovable pages, respectively.

[0052] S5: Output the extracted page information in a structured form to the crash console, or save it as a file for further analysis. The output page information includes the virtual address, physical address, status flag (whether it is a dirty page, whether it is locked, whether it is being written back, etc.), reference count and other information of each memory page.

[0053] Furthermore, based on the above steps S1-S5, a graphical interface or script tool is provided to display the page information in a chart or graphical form, so as to facilitate the debugger to intuitively analyze the distribution and status of the memory page.

[0054] Based on the above steps S1 to S5, based on the extensibility of the crash tool and utilizing its ability to parse the kernel symbol table and data structure, the automatic extraction and display of page information in the LRU list in the Linux kernel is achieved.

[0055] It should be pointed out that although the various steps in the above embodiments are described in a specific order, those skilled in the art can understand that in order to achieve the effects of the present invention, different steps do not have to be performed in such an order. They can be performed simultaneously (in parallel) or in other orders. These changes are within the scope of protection of the present invention.

[0056] Here are some terms involved in the present invention.

[0057] CRASH: In Linux systems, crash is a command-line tool used to analyze vmcore dump files. When a system crashes, the generated vmcore file records the contents of the memory, including kernel state data structures, process status, etc. With the help of the crash tool, system administrators and developers can deeply analyze the cause of the crash and obtain information such as kernel thread stacks, memory usage, and active processes.

[0058] vmcore: is a memory dump file generated when a kernel crash occurs in a Linux system. It contains the memory contents at the time of the system crash and is used to diagnose and debug kernel problems. The vmcore file can be analyzed by tools (such as crash, gdb) to help system administrators or developers determine the cause of the crash.

[0059] vmlinux: vmlinux is an uncompressed executable file of the Linux kernel that contains debugging symbols. It is one of the final products generated after the kernel source code is compiled, and usually contains kernel code, data segments, symbol tables, and debugging information. This file can be used directly for kernel debugging and analysis. The file uses the standard ELF (Executable and Linkable Format) format.

[0060] LRU (Least Recently Used): LRU is a common cache replacement algorithm, which means "Least Recently Used". In the cache system, the LRU algorithm will give priority to eliminating the cache items that have been least recently accessed to make room for new data. This algorithm is widely used in memory management, page replacement, CPU cache and other fields.

[0061] mem_cgroup (Memory Control Group): mem_cgroup is a part of Linux control groups (cgroups) and is responsible for managing and limiting the memory usage of processes. Through mem_cgroup, system administrators can set memory limits for processes or process groups to prevent certain processes from exhausting system memory resources. It supports functions such as setting memory usage limits and monitoring memory usage, and is used for isolation and management of system resources.

[0062] Page: In the Linux kernel, page is a key data structure used to describe and manage physical memory pages in the system. Each physical memory page corresponds to a struct page structure, and the kernel uses this structure to track the state and properties of the page.

[0063] So far, the technical solutions of the present invention have been described in conjunction with the preferred embodiments shown, but it is easy for those skilled in the art to understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present invention.

Claims

1. A method for extracting page information from a kernel LRU list, characterized in that: The following steps are involved: S1: Write the crash plug-in code, define the showlru command used to extract the page information in the LRU list, and compile the showlru.h file and showlru.c file containing the showlru command into a shared library; S2: Use the crash tool to load the kernel dump file and kernel symbol table when the system crashes, and obtain the complete data structure of the kernel when the system crashes; S3: Use the extend command to import the shared library into the crash context; S4: Obtain the page information in the kernel by parsing the imported showlru command; S5: Output the page information in a structured form to the crash console or save it as a file for analysis.

2. The method for extracting page information from a kernel LRU linked list according to claim 1, characterized in that: The method also includes the steps of providing a graphical interface or a script tool to display the page information in a chart or graphical form.

3. The method for extracting page information from a kernel LRU linked list according to claim 1, characterized in that: The page information output to the crash console includes the virtual address, physical address, status flag and reference count of each memory page, and the status flag includes whether the page is dirty, locked, or being written back.

4. The method for extracting page information from a kernel LRU linked list according to claim 1, characterized in that: The step S1 comprises: Create a showlru.h file, define a page_data_t structure in the showlru.h file, and declare a sub-function implemented by the showlru.c file in the showlru.h file. The page_data_t structure is used to save the extracted page information; Create the showlru.c file, reference the showlru.h and crash / defs.h header files in the showlru.c file, use command_table_entry to define the showlru command, and implement the parsing and help functions of the showlru command; Compile the showlru.c file and the showlru.h file into a shared library.

5. The method for extracting page information from a kernel LRU linked list according to claim 4, characterized in that: The implementation process of the showlru command includes: Use symbol_value to extract the address and content of root_mem_cgroup in the kernel; According to the content of root_mem_cgroup, extract the address and content of all mem_cgroup; According to the content of mem_cgroup, extract the address and content of all mem_cgroup_per_node; According to the content of mem_cgroup_per_node, extract the address and content of all lruvec structures; According to the content of the lruvec structure, extract the starting address and content of all LRU linked lists; According to the first node in the LRU linked list content, extract all the page information.

6. The method for extracting page information from a kernel LRU linked list according to claim 5, characterized in that: The lruvec structure includes five linked lists, namely, LRU_INACTIVE_ANON, LRU_ACTIVE_ANON, LRU_INACTIVE_FILE, LRU_ACTIVE_FILE and LRU_UNEVICTABLE, which are respectively used to store inactive anonymous pages, active anonymous pages, inactive file pages, active file pages and unmovable pages.