Memory access control with prohibition mapping scheme
By adopting a prohibited mapping scheme in the memory management unit, only virtual address mapping that does not allow memory access is stored, the problem that memory access control in the prior art depends on a large number of allowed list mappings is solved, and more efficient memory management and access control is achieved.
Patent Information
- Application Number
- CN202510384126.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-03-28
- Filing Date
- 2025-03-28
- Publication Date
- 2025-06-27
AI Technical Summary
The prior art relies on a "allow list" mapping from virtual addresses to physical addresses when performing memory access control, resulting in storing and searching large amounts of data, increasing computational costs and delays.
Using a prohibited mapping scheme, the conversion and associated memory access requests are permitted only when the virtual address does not exist in the prohibited mapping data structure, and the mapping of virtual addresses that are not allowed to be accessed by memory is stored.
By using a prohibited mapping scheme, virtual address mapping that needs to be stored and traversed is reduced, and the computing costs of memory management and memory access control are significantly reduced, such as in terms of memory usage, computing time, delay, power consumption, etc.
Smart Images

Figure CN120215838A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure generally relates to memory access control utilizing a prohibited mapping scheme. Background Art
[0002] This specification relates to memory access control and, more particularly, to performing memory access control using a memory management unit.
[0003] A computer can run an application by allocating and assigning addresses for use by the application from an address space managed by the computer. The computer can run multiple applications simultaneously. To ensure the security and correct execution of the applications, the computer can isolate some or all of the address space used by the applications. Specifically, the computer can only allow a certain group of applications to access a given region of the address space (e.g., reserved by the group of applications, protected by the group of applications, etc.), and the computer can prevent all other applications from accessing (e.g., reading, writing, etc.) the given region of the address space. Memory access control is the process by which the computer receives a memory access attempt by an application to a given region of the computer's address space, determines whether the application is permitted to access the given region of the address space, and only executes the attempted memory access if the application is permitted to access the given region of the address space.
[0004] A computer can use a virtual address space as part of running an application. To use the virtual address space, the application can request access to a given virtual address, and the computer can perform address translation as needed to obtain the requested data in a physical address in the computer's address space corresponding to the given virtual address. The computer can use a memory management unit to translate the virtual address into a physical address within the computer's address space. Summary of the Invention
[0005] In general, this specification describes a computing system that can perform memory access control using a prohibited mapping scheme when translating a virtual address into a corresponding physical address. Specifically, the translation and associated memory access requests are permitted only if the virtual address does not exist in a prohibited mapping data structure. This arrangement provides several technical advantages over conventional techniques that maintain a mapping of permitted access regions.
[0006] According to one aspect, a system is provided that includes a memory management unit configured to: (i) perform multi-level address translation, where a first level of the address translation performs an address translation from a virtual address to an intermediate physical address, and where a second level of the address translation performs an address translation from the intermediate physical address to a physical address, (ii) maintain a prohibited mapping between the intermediate physical address and the physical address, and (iii) operate in a prohibited mapping mode to perform multi-level address translation by performing operations including: translating the virtual address to the intermediate physical address, reading the prohibited mapping using the intermediate physical address, and if the intermediate physical address misses in the prohibited mapping, returning the physical address for the intermediate physical address.
[0007] Certain embodiments of the subject matter described in this specification can be implemented so as to realize one or more of the following advantages.
[0008] Conventional methods for performing access control on virtual addresses rely on a "permitted list" mapping from virtual addresses to physical addresses. By using the permitted list scheme, conventional methods need to store (e.g., in a page table) the mapping of each virtual address for which permission to access memory is granted. In cases where the number of protected addresses is small relative to the size of the physical address space, conventional methods may thus need to store a large amount of data describing the virtual address mapping, which must be searched each time a memory access is performed to enforce memory access control.
[0009] The system utilizes a prohibited mapping scheme to perform memory access control. By using the prohibited mapping scheme, the system stores the mapping of virtual addresses for which memory access is not permitted. In cases where the number of prohibited mappings is less than the number of permitted mappings of virtual addresses, compared to conventional methods, the system can store and traverse fewer virtual address mappings to perform memory access control. By using the prohibited mapping scheme, the system can thus require significantly less stored data and less computation time to perform virtual memory management and memory access control.
[0010] The system can switch between using the prohibited mapping scheme and a "permitted list" mapping from virtual addresses to physical addresses. This allows the system to better adapt to changes in the size of the protected regions of the address space. Thus, compared to conventional methods, the system can perform virtual memory management and memory access control at a significantly reduced computational cost (e.g., in terms of memory usage, computation time, latency, power consumption, etc.).
[0011] Details of one or more implementations of the subject matter of this specification are set forth in the accompanying drawings and the description below. Other features, aspects, and advantages of the subject matter will become apparent from the specification, the drawings, and the claims. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] Figure 1 Illustrates the memory management of a computing system using a prohibited mapping scheme.
[0013] Figure 2A Illustrates the memory management of one or more virtual machines using a prohibited mapping scheme.
[0014] Figure 2B Illustrates the memory management of software using a prohibited mapping scheme.
[0015] Figure 2C Illustrates the memory management of hardware using a prohibited mapping scheme.
[0016] Figure 3 Illustrates an example memory management unit.
[0017] Figure 4A Illustrates an example prohibited mapping system using a prohibited mapping cache operating in a prohibited mapping mode.
[0018] Figure 4B Illustrates an example prohibited mapping system using a cached page table operating in a prohibited mapping mode.
[0019] Figure 5 Is a flowchart of an example process for converting a virtual address to a corresponding physical address using a prohibited mapping scheme.
[0020] Figure 6 Is a flowchart of an example process for reading a prohibited mapping using an intermediate physical address by a prohibited mapping cache operating in a prohibited mapping mode.
[0021] Figure 7 Is a flowchart of an example process for reading a prohibited mapping using an intermediate physical address by a cached page table operating in a prohibited mapping mode.
[0022] Like reference numerals and names in the various figures indicate like elements. Detailed Description
[0023] Figure 1 Illustrates the memory management of a computing system 100 using a prohibited mapping scheme. The computing system 100 includes a memory management unit 102 that is configured to perform memory access control on the computing system 100 using a prohibited mapping scheme.
[0024] The computing system 100 may use a memory management unit 102 to manage the address space 104 (e.g., global address space) of one or more memory devices 105 of the computing system 100 (e.g., including the system memory of the computing system 100, memory devices connected to the computing system 100, memory-mapped devices connected to the computing system 100, etc.). Specifically, the memory management unit 102 may perform virtual memory management on the address space 104 by converting a virtual address 106 from a virtual address space into a corresponding physical address 108 within the address space 104.
[0025] In this specification, an address space may refer to the address space required to utilize underlying system resources. For example, an address space may define a range of memory addresses in one or more memory devices, addresses of input / output interfaces or devices, addresses of other system devices, or some combination of these addresses.
[0026] The physical address space (e.g., address space 104) is the address space required to use the underlying physical system resources themselves. For example, the address space 104 may include physical memory addresses, I / O addresses, etc. of the computing system 100.
[0027] The virtual address space is the address space used by software and / or hardware to reference corresponding underlying system resources. Software (e.g., software running on the computing system 100, software accessing the computing system 100, etc.) and / or hardware (e.g., components of the computing system 100, devices connected to the computing system 100, etc.) may use the virtual address 106 to indirectly access the address space 104 (e.g., read data from a physical address in the address space 104, write data to a physical address in the address space 104, etc.). Each virtual address 106 may identify a corresponding physical address 108 in the address space 104.
[0028] The memory management unit 102 may store the mapping of virtual addresses 106 to corresponding physical addresses 108. The system 100 may use any suitable mapping between the virtual address 106 and the physical address 108. As an example, the system 100 may map a continuous range of virtual addresses 106 to a continuous region of the address space 104. As another example, the system 100 may map a continuous range of virtual addresses 106 to a non - continuous region of the address space 104. As a further example, the system 100 may map any virtual address 106 to any physical address 108 in the address space 104.
[0029] When the memory management unit 102 receives a virtual address 106 (e.g., as part of software and / or hardware that requests to read data or write data to the virtual address 106), the memory management unit 102 can determine whether to permit memory access to the corresponding physical addresses 108 based on the stored mapping. Specifically, the memory management unit 102 can be configured to operate in a prohibited mapping mode to perform memory access control on virtual addresses 106 for which memory access is not permitted using the stored prohibited mapping 112. When operating in the prohibited mapping mode to translate a given virtual address 106, if the mapping of the given virtual address 106 is stored within the prohibited mapping 112, the memory management unit 102 can (e.g., by raising an access fault, returning an access error, etc.) deny the memory access and not provide the translated physical address 110. If the mapping of the given virtual address 106 is not stored within the prohibited mapping 112, the memory management unit 102 can allow the memory access by returning the corresponding physical address 108 for the given virtual address 106.
[0030] The prohibited mapping 112 can specify a protected or reserved region (e.g., a protected portion) of the address space 104, and the memory management unit 102 can use the prohibited mapping 112 to determine memory access permissions for software and / or hardware of the computing system 100. For example, the memory management unit 102 can use the prohibited mapping 112 to specify a protected region of the address space 104 for a given application or hardware device, and can deny access to the protected region of the given application or hardware device by other applications or hardware devices. As another example, the memory management unit 102 can use the prohibited mapping 112 to specify a protected region of the address space 104 for a group of applications and / or hardware devices with a specific permission level, and can deny access to the protected region by applications or hardware devices that do not have the specific permission level. As another example, the memory management unit 102 can use the prohibited mapping 112 to specify a globally protected region of the address space 104, and can deny access to the globally protected region by all applications and / or hardware devices.
[0031] As described below with reference to Figure 3More specifically, the memory management unit 102 can perform a two-level translation on the virtual address 106 by first translating the virtual address 106 into a corresponding intermediate physical address and then translating the intermediate physical address into a corresponding physical address 108. The prohibited mapping 112 can be a prohibited mapping between the intermediate physical address and the corresponding physical address 108. When operating in the prohibited mapping mode, the memory management unit 102 can perform memory access control when translating the intermediate physical address into the corresponding physical address 108 as follows: reject the memory access if the prohibited mapping 112 includes a mapping of the intermediate physical address and return the corresponding physical address 108 (e.g., allow the memory access) if the prohibited mapping 112 does not include a mapping of the intermediate physical address.
[0032] By operating in the prohibited mapping mode, when the protected or reserved area is smaller than the unprotected area of the address space 104 (e.g., when the protected or reserved area is less than half of the address space 104), the memory management unit 102 can store and search through fewer intermediate physical address mappings to perform memory access control. When the protected or reserved area is significantly smaller than the unprotected area of the address space 104 (e.g., when the protected area or reserved area is less than 10% of the address space 104), the memory management unit 102 can thus perform virtual memory management and memory access control on the computing system 100 using significantly less stored data and less computing time compared to using a conventional allow mapping. As a specific example, the implementation of the memory management unit 102 can use a 2MB page table storing prohibited mappings of intermediate physical addresses to perform memory management on an 8GB address space 104 with a 1GB protected area, compared to a 14MB page table storing allow mappings of intermediate physical addresses when operating in the prohibited mapping mode. As another example, the implementation of the memory management unit 102 can utilize a 200KB page table storing the prohibited mapping (the memory management unit 102 can cache the prohibited mapping using, for example, the prohibited mapping cache described with respect to Figure 4A to perform access control and memory management on a 100MB protected area of the address space 104.
[0033] After the memory management unit 102 performs memory access control on the virtual address 106, the computing system 100 may return an appropriate address access result 112. For example, when the memory management unit 102 denies access to a given virtual address 106, the computing system 100 may return a memory access error. As another example, when the memory management unit 102 permits access to a given virtual address 106, the computing system 100 may access the corresponding physical address 108 and return an address access result 112 that includes, for example, data read from the physical address 108, an acknowledgement of successfully writing data to the physical address 108, and so on.
[0034] The computing system 100 can be any of a variety of computing systems configured to perform indirect addressing of an address space using virtual addresses. For example, the computing system 100 can be a component of a mobile device, a computer, a computer networking system, and so on. For example, the computing system 100 can be a processor (e.g., a central processing unit (CPU), a graphics processing unit (GPU), a tensor processing unit (TPU), etc.), a chipset, a system-on-a-chip (SoC), and so on. As another example, the computing system 100 can be a component of a processor, a chipset, a system-on-a-chip (SoC), and so on.
[0035] In some implementations, the computing system 100 may perform memory management on an address space 104 shared by multiple processors (e.g., any combination of CPUs, GPUs, TPUs, etc.). For example, the computing system 100 can be one of multiple connected processors. As another example, the computing system 100 can be a system that includes or is connected to multiple processors (e.g., a chipset, an SoC, etc.). The computing system 100 can use a prohibit mapping scheme to manage protected or reserved regions of the address space 104 of the multiple processors (e.g., regions of the address space 104 that permit memory access only by specific associated processors).
[0036] Implementations of the system can be used to perform memory management for any of a variety of applications, such as performing memory management for one or more virtual machines, performing memory management for one or more software applications, performing memory management for one or more hardware devices, and so on. Some example applications of the system are described in more detail below with reference to Figure 2A 、 Figure 2B and Figure 2C Some example applications of the system are described in more detail.
[0037] Figure 2A Illustrates memory management for one or more virtual machines 202-A through 202-N using a prohibit mapping scheme. As Figure 2AAs shown, a computing system 100 configured as described throughout this specification (e.g., including a memory management unit 102 configured as described throughout this specification) may utilize a shadow mapping scheme as part of running one or more virtual machines 202-A through 202-N.
[0038] Each of the virtual machines 202-A through 202-N may run and manage a corresponding software application (e.g., program). For example, as Figure 2A shown, virtual machine 202-A may run applications 204-A through 204-N, and virtual machine 202-N may run applications 206-A through 206-N. Each of the virtual machines 202-A through 202-N may use a virtual address space to run the corresponding application. Specifically, the virtual machines 202-A through 202-N may simulate corresponding computing systems (e.g., having corresponding processors, memories, I / O devices, etc.), and the virtual address space may simulate the corresponding physical address spaces of each of the virtual machines 202-A through 202-N.
[0039] The computing system 100 may maintain a mapping from a virtual address 106 within the virtual address space to a corresponding physical address 108 within an address space 104 of one or more memory devices 105 of the computing system 100 (e.g., including the system memory of the computing system 100, a memory device connected to the computing system 100, a memory mapped device connected to the computing system 100, etc.). For example, the address space 104 may include the physical memory addresses, I / O addresses, etc. of the computing system 100.
[0040] An application running on the virtual machines 202-A through 202-N may initiate an access operation to a virtual address 106 within the virtual address space, such as by writing data to the virtual address 106, reading data from the virtual address 106, etc. The computing system 100 may complete the access operation to the virtual address 106 by determining whether access to the corresponding physical address 108 is permitted and returning an appropriate address access result 112 to the virtual machines 202-A through 202-N. For example, when access to a given virtual address is permitted, the computing system 100 may access the corresponding physical address (e.g., by reading data or writing data to the corresponding physical address) and return an appropriate access result. As another example, when access to a given virtual address is not permitted, the computing system 100 may return an access error or an access fault.
[0041] Applications running on virtual machines 202-A through 202-N may include corresponding operating systems for the virtual machines (e.g., applications 204-A through 204-N may include an operating system for virtual machine 202-A, and applications 206-A through 206-N may include an operating system for virtual machine 202-N). The operating systems of virtual machines 202-A through 202-N may manage the execution of the corresponding applications run by virtual machines 202-A through 202-N. The operating systems of virtual machines 202-A through 202-N may perform any of a variety of tasks to manage the execution of the corresponding applications. For example, the operating systems of virtual machines 202-A through 202-N may manage input to and output from the corresponding applications. As another example, the operating systems of virtual machines 202-A through 202-N may request that computing system 100 allocate, reserve, and / or protect memory for the corresponding applications. As another example, the operating systems of virtual machines 202-A through 202-N may prioritize the execution of these corresponding applications and may manage the load balancing of the corresponding applications. As another example, the operating systems of virtual machines 202-A through 202-N may terminate unresponsive applications.
[0042] To maintain the security and normal operation of virtual machines 202-A through 202-N (e.g., including maintaining the security and normal operation of applications running on virtual machines 202-A through 202-N) and the security and normal operation of computing system 100 itself, computing system 100 may reserve and protect certain physical addresses 108 within address space 104.
[0043] Computing system 100 may maintain a mapping (e.g., a prohibited mapping 112) from virtual addresses to such reserved and protected physical addresses 110 within address space 104. When an application running on one of virtual machines 202-A through 202-N accesses a virtual address, memory management unit 102 may operate in prohibited mapping mode to determine whether to permit access to the corresponding physical address based on whether the prohibited mapping for that virtual address is stored as one of the prohibited mappings 112 in the protected region of address space 104.
[0044] The prohibited mapping 112 may include mapping of any of a plurality of protected regions of the address space 104. For example, the prohibited mapping 112 may include mapping of a protected region of the address space 104 reserved for a specific virtual machine among virtual machines 202-A to 202-N, and an application running on the specific virtual machine has the right to access the protected region, while other applications (e.g., applications running on other virtual machines, applications running on the computer system 100, etc.) do not have the right to access the protected region. As another example, the prohibited mapping 112 may include mapping of a protected region of the address space 104 reserved for a specific application (e.g., an operating system) running on one of the virtual machines 202-A to 202-N, and the specific application has the right to access the protected region, while other applications (e.g., applications running on the same virtual machine, applications running on other virtual machines, applications running on the computer system 100, etc.) do not have the right to access the protected region. As another example, the prohibited mapping 112 may include mapping of a protected region of the address space 104 reserved for the computing system 100, and applications running on the virtual machines 202-A to 202-N do not have the right to access the protected region.
[0045] Figure 2B Illustrates memory management of the software 210 using a prohibited mapping scheme. As Figure 2B shown, a computing system 100 configured as described throughout this specification (e.g., including a memory management unit 102 configured as described throughout this specification) may utilize a prohibited mapping scheme as part of running one or more software applications 212-A to 212-N.
[0046] The applications 212-A to 212-N running on the computer system 100 may include the operating system of the computer system 100. The operating system of the computer system 100 may manage the execution of the applications 212-A to 212-N. The operating system may perform any of a variety of tasks to manage the execution of the applications 212-A to 212-N. For example, the operating system may manage input to and output from the applications 212-A to 212-N. As another example, the operating system may request the computing system 100 to allocate, reserve, and / or protect memory for the applications 212-A to 212-N. As another example, the operating system may prioritize the execution of the corresponding applications and may manage the load balancing of the applications 212-A to 212-N. As another example, the operating system may terminate unresponsive applications.
[0047] To maintain the security and proper execution of applications 212-A to 212-N, applications 212-A to 212-N may use virtual address 106 from the virtual address space to indirectly access the address space 104 of one or more memory devices 105 of computing system 100 (e.g., including the physical memory addresses, IO addresses, etc. of computing system 100). Computing system 100 may receive the virtual address 106 referenced by applications 212-A to 212-N, access the corresponding physical address 108 in address space 104, and provide an appropriate address access result 110 to applications 212-A to 212-N.
[0048] Applications 212-A to 212-N may initiate access operations to virtual address 106 within the virtual address space, such as by writing data to virtual address 106, reading data from virtual address 106, and so on. Computing system 100 may complete the access operation to virtual address 106 by determining whether access to the corresponding physical address 108 is permitted and returning an appropriate address access result 112 to applications 212-A to 212-N. For example, when access to a given virtual address is permitted, computing system 100 may access the corresponding physical address (e.g., by reading data or writing data to the corresponding physical address) and return an appropriate access result. As another example, when access to a given virtual address is not permitted, computing system 100 may return an access error or access fault.
[0049] Computing system 100 may reserve and protect certain physical addresses 108 within address space 104 for computing system 100. Computing system 100 may maintain a mapping from virtual addresses to such reserved and protected physical addresses within address space 104 (e.g., prohibited mapping 112). When applications 212-A to 212-N access virtual addresses, memory management unit 102 may operate in prohibited mapping mode to determine whether access to the corresponding physical address is permitted based on whether the prohibited mapping of the virtual address is stored as one of the prohibited mappings 112 in the protected area of address space 104.
[0050] Prohibited mapping 112 may include a mapping of any of the various protected areas of address space 104. As an example, prohibited mapping 112 may include a mapping of a protected area of address space 104 reserved for a specific application (e.g., the operating system of computer system 100), and that specific application has the right to access that protected area, while other applications do not have the right to access that protected area. As another example, it may include a mapping of a protected area of address space 104 reserved for applications with a specific permission level, and a specific application running at the specific permission level has the right to access that protected area, while applications not running at the specific permission level do not have the right to access that protected area.
[0051] Figure 2CIllustrates the memory management of hardware 220 using a prohibition mapping scheme. As Figure 2C shown, a computing system 100 configured as described throughout this specification (e.g., including a memory management unit 102 configured as described throughout this specification) can utilize a prohibition mapping scheme as part of performing memory management on one or more hardware devices 222-A through 222-N.
[0052] The hardware devices 222-A through 222-N can include any suitable combination of, for example, processors (e.g., CPUs, GPUs, TPUs, etc.), I / O devices, memory devices, and the like.
[0053] The devices 222-A through 222-N and / or software applications (e.g., software applications running on the computing system 100, software applications running on the devices 222-A through 222-N) can indirectly access the address space 104 (e.g., including the physical memory addresses, I / O addresses, etc. of the computing system 100) of one or more memory devices 105 of the computing system 100 using virtual addresses 106 from a virtual address space. In some implementations, the address space 104 can include the addresses of resources of one or more of the devices 222-A through 222-N (e.g., the physical memory addresses, I / O addresses, etc. of the devices 222-A through 222-N). The computing system 100 can receive the virtual address 106, access the corresponding physical address 108 in the address space 104, and return an appropriate address access result 110.
[0054] The computing system 100 can reserve and protect certain physical addresses 108 within the address space 104. The computing system 100 can maintain a mapping (e.g., a prohibition mapping 112) from virtual addresses to such reserved and protected physical addresses within the address space 104. When one of the devices 222-A through 222-N or a software application accesses a virtual address, the memory management unit 102 can operate in prohibition mapping mode to determine whether to permit access to the corresponding physical address based on whether the prohibition mapping of the virtual address is stored as one of the prohibition mappings 112 of the protected regions of the address space 104.
[0055] The prohibited mapping 112 may include the mapping of any of a plurality of protected regions of the address space 104. As an example, the prohibited mapping 112 may include the mapping of a protected region of the address space 104 reserved for a particular device among devices 222-A to 222-N (e.g., for use by an application running on the particular device), where the particular device has the right to access the protected region and other devices do not have the right to access the protected region. As another example, the prohibited mapping 112 may include the mapping of a protected region of the address space 104 reserved for an application with a particular permission level (e.g., an application running on the computing system 100 or one of the devices 222-A to 222-N), and a particular application running at the particular permission level has the right to access the protected region while an application not running at the particular permission level does not have the right to access the protected region.
[0056] Figure 3 An example memory management unit 102 is shown. The memory management unit 102 may receive a virtual address 106 for accessing a virtual address space and may determine whether to permit memory access to the corresponding physical addresses 108. The memory management unit 102 may return the translated physical address 108 for the permitted access to the virtual address 106.
[0057] The memory management unit 102 may use an intermediate translation system 302 and a prohibited mapping system 304 to perform a multi-level translation from the virtual address 106 to the physical address 108. The intermediate translation system 302 may translate the virtual address 106 into a corresponding intermediate physical address 306. The prohibited mapping system 304 may determine whether to permit memory access to the corresponding physical address 108 based on the intermediate physical address 306, and when access is permitted, may return the translated physical address 108 for the intermediate physical address 306.
[0058] The memory management unit 102 may receive an access identifier 308 for each of the virtual addresses 106. For each virtual address 106, the access identifier 308 may specify, for example, an application, an operating system, a device, a permission level, etc. The access identifier 308 may include, for example, a process address space ID (PASID), a virtual machine ID (VMID), a stream ID, a sub-stream ID, a device ID, etc.
[0059] The memory management unit 102 may perform address translation and memory access control based on the received access identifier 308. As an example, the memory management unit 102 may include a separate page table for the access identifier 308. When the memory management unit 102 receives the virtual address 106 and the access identifier 308 for the virtual address 106, the memory management unit 102 may use the page table indicated by the access identifier 308 when performing translation and memory access control for the virtual address 106.
[0060] The intermediate translation system 302 can translate the virtual address 106 into an intermediate physical address 306 by any suitable method. For example, the intermediate translation system 302 can maintain a page table that stores the mapping from the virtual address 106 to the intermediate physical address 306. For a given virtual address 106, the intermediate translation system 302 can perform a table lookup for the given address 106 in the page table and can return the intermediate physical address 306 for the given address 106 based on the mapping returned by the table lookup. As another example, the intermediate translation system 302 can maintain multiple page tables that store address mappings. For a given virtual address 106, the intermediate translation system 302 can perform a sequence of table lookups in the page tables, where the result of each table lookup in the sequence is used for the next table lookup in the sequence, and can return the intermediate physical address 306 for the given address 106 based on the mapping returned by the last table lookup in the sequence.
[0061] The intermediate translation system 302 can include a translation lookaside buffer for each of the page tables of the system 302. The translation lookaside buffer can cache the table lookup mappings of the page tables of the system 302. When the intermediate translation system 302 includes a translation lookaside buffer for a particular page table, the system 302 can perform a table lookup for a given address in the particular page table by: first searching for the mapping of the given address in the translation lookaside buffer; if the given address results in a cache hit in the translation lookaside buffer, returning the mapping of the given address; and if the given address results in a cache miss in the translation lookaside buffer, searching for the given address in the page table.
[0062] The prohibition mapping system 306 can receive the intermediate physical address 306 and determine whether to permit memory access to the corresponding physical address 108. When the prohibition mapping system 304 determines to permit memory access to the physical address 108, the prohibition mapping system can return the translated physical address 108 for the virtual address 106.
[0063] When the prohibition mapping system 304 determines not to permit memory access to the physical address 108, the prohibition mapping system 304 can indicate a memory access error by any of a variety of methods. For example, the prohibition mapping system 304 can output a specific memory access error signal. As another example, the prohibition mapping system 304 can modify the register of the memory management unit that indicates a memory access error. As another example, the prohibition mapping system 304 can output a predetermined value as the physical address 108 for the intermediate physical address 306, and the predetermined value indicates a memory access error.
[0064] Generally, the mapping prohibition system 304 stores no mapping from the intermediate physical address 306 to the corresponding physical address 108. The mapping prohibition system 304 can operate in a mapping prohibition mode and a mapping permission mode, and can use the stored mapping from the intermediate physical address 306 to the corresponding physical address 108 to perform memory access control in different ways depending on whether the system 304 is operating in the mapping prohibition mode or the mapping permission mode. When operating in the mapping prohibition mode, the mapping prohibition system 304 generally stores the mapping of the intermediate physical address 306 for which memory access is not permitted, and will block memory access to the intermediate physical address 306 stored together with the mapping prohibition. When operating in the mapping permission mode, the mapping prohibition system 304 generally stores the mapping of the intermediate physical address 306 for which memory access is permitted, and will allow memory access to the intermediate physical address 306 stored together with the mapping permission.
[0065] The mapping prohibition system 304 can convert the intermediate physical address 306 into the corresponding physical address 108 by any suitable method. For example, as described in more detail below with reference to Figure 4A The mapping prohibition system 304 can use a mapping prohibition cache to convert the intermediate physical address 306. As another example, as described in more detail below with reference to Figure 4B The mapping prohibition system 304 can use the cached page table to convert the intermediate physical address 306.
[0066] In some implementations, the mapping prohibition system 304 can determine whether to operate in the mapping prohibition mode or the mapping permission mode based on the intermediate physical address 306. For example, the mapping prohibition system 304 can determine whether to operate in the mapping prohibition mode or the mapping permission mode when processing a given intermediate physical address 306 based on the flag bit of the address 306. As another example, the mapping prohibition system 304 can determine whether to operate in the mapping prohibition mode or the mapping permission mode when processing a given intermediate physical address 306 based on whether the address 306 falls within a predetermined address range.
[0067] The mapping prohibition system 304 can receive the corresponding access identifier 308 for each of the intermediate physical addresses 306. The mapping prohibition system 304 can perform address conversion and memory access control based on the received access identifier 308 (e.g., by using, for example, the page table, buffer, cache, etc. specified by the access identifier 308).
[0068] In some implementations, the inhibit mapping system 304 can determine whether to operate in the inhibit mapping mode or the permit mapping mode based on the access identifier 308. For example, some access identifiers 308 can specify using the inhibit mapping mode, while other access identifiers 308 can specify using the permit mapping mode, and the inhibit mapping system 304 can switch between using the inhibit mapping mode and the permit mapping mode based on the received access identifier 308.
[0069] In some implementations, the inhibit mapping system 304 can determine whether to operate in the inhibit mapping mode or the permit mapping mode based on a combination of the intermediate physical address 306 and the corresponding access identifier 308. For example, a range of the intermediate physical address 306 can be associated with a specific access identifier (e.g., as a reserved or protected area for an application, device, permission level, etc. indicated by the specific access identifier), and the system 304 can operate in the permit mapping mode for a specific access identifier when translating an address within the range of the intermediate physical address 306 associated with the specific access identifier, and operate in the inhibit mapping mode for other access identifiers.
[0070] In some implementations, the inhibit mapping system 304 can switch between operating in the inhibit mapping mode and operating in the permit mapping mode by loading different mappings of the intermediate physical address 306 into the physical address 108. For example, the inhibit mapping system 304 can switch from the inhibit mapping mode to the permit mapping mode by loading a permit mapping into, for example, a buffer, cache, page table, etc. of the system 302. As another example, the inhibit mapping system 304 can switch from the permit mapping mode to the inhibit mapping mode by loading an inhibit mapping into, for example, a buffer, cache, page table, etc. of the system 304.
[0071] Reference is made below Figure 5 to an example process by which the memory management unit 102 can translate the virtual address 106 into the physical address 108 in more detail.
[0072] When the memory management unit 102 performs a multi-level translation from a virtual address 106 to a physical address 108, the memory management unit 102 may perform different memory access control tasks at each level of the multi-level translation. As an example, the virtual address 106 may correspond to an address referenced by an application running on one or more virtual machines (e.g., managed by the operating system of the virtual machine), the intermediate physical address 306 may correspond to an address referenced by an application running on the computing system 100 (e.g., managed by the operating system of the computing system 100), and the physical address 108 may correspond to an address in the address space 104 of a resource of the computing system 100. The memory management unit 102 may perform memory access control for the virtual machine based on the translation from the virtual address 106 to the intermediate physical address 306, and may perform global memory access control for the computing system 100 based on the translation from the intermediate physical address 306 to the physical address 110. For example, when the operating system of the virtual machine permits access to the intermediate physical address 306, the intermediate translation system 302 may return the intermediate physical address 306 for a given virtual address 106. As another example, when the computing system 100 permits access to the physical address 108, the forbidding mapping system 304 may return the physical address 108 for a given virtual address 106.
[0073] Figure 4A An example forbidding mapping system 304-A that uses a forbidding mapping cache 402 operating in a forbidding mapping mode is shown. The forbidding mapping cache 402 may store a mapping from an intermediate physical address 306-A to a physical address 108-B.
[0074] When operating in the forbidding mapping mode, the forbidding mapping system 304-A may receive an intermediate physical address 306-A and may search the forbidding mapping cache 402 for the received address 306-A. If the system 304-A finds a given intermediate physical address 306-A in the forbidding mapping cache 402 (e.g., if the given address 306-A hits in the forbidding mapping cache 402), the system 304-A may block memory access to the given address 306-A and may, for example, return a memory access error. If the given intermediate physical address 306-A misses in the forbidding mapping cache 402, the system 304-A may allow memory access to the given address 306-A and may return the corresponding translated physical address 108-A.
[0075] In some implementations, the intermediate physical address 306-A may be the physical address 108-A, and the system 304-A may return a cache miss 404 (e.g., an intermediate physical address 306-A that misses in the forbidding mapping cache 402) as the physical address 108-A.
[0076] In some implementations, the inhibit mapping system 304-A may include the cached page table 406-A. The cached page table 406-A may include a translation lookaside buffer 408-A and a page table 410-A, which may store the mapping from the intermediate physical address 306-A to the physical address 108-A.
[0077] When the inhibit mapping system 304-A operates in the permissive mapping mode, the system 304-A may use the cached page table 406-A to translate the intermediate physical address 306-A. For example, if a given intermediate physical address 306-A hits in the translation lookaside buffer 408-A, the system 304-A may return the corresponding physical address 108-A stored in the translation lookaside buffer 408-A. If a given intermediate physical address 306-A misses in the translation lookaside buffer 408-A, the system 304-A may search for the corresponding physical address 108-A within the page table 410-A and return the corresponding physical address 108-A.
[0078] When the inhibit mapping system 304-A operates in the permissive mapping mode, the system 304-A may similarly translate the received intermediate physical address 306-A and use the cached page table 406-A to perform memory access control.
[0079] In some implementations, the inhibit mapping cache 402 may be the translation lookaside buffer 408-A.
[0080] Figure 4B An example inhibit mapping system 304-B using the cached page table 406-B operating in the inhibit mapping mode is shown. The cached page table 406-B may include a translation lookaside buffer 408-B and a page table 410-B, which may store the mapping from the intermediate physical address 306-B to the physical address 108-B.
[0081] When operating in the inhibit mapping mode, the inhibit mapping system 304-B may receive the intermediate physical address 306-B and may search the translation lookaside buffer 408-B for the received address 306-B. If the system 304-B finds a given intermediate physical address 306-B within the translation lookaside buffer 408-B (e.g., if the given address 306-B hits in the translation lookaside buffer 408-B), the system 304-B permits memory access to the given address 306-B and may return the corresponding translated physical address 108-B.
[0082] If a given intermediate physical address 306-B misses in the translation lookaside buffer 408-B, the system 304-B may search the page table 410-B for a mapping for the cache miss 414 (e.g., the given intermediate physical address 306-B that misses in the translation lookaside buffer 408-B). If, when operating in the prohibited mapping mode, the system 304-B finds the given intermediate physical address 306-B within the page table 410-B, the system 304-B may block the memory access to the given address 306-B and may, for example, return a memory access error. If the system 304-B does not find the given intermediate physical address 306-B within the page table 410-B, the system 304-B may allow the memory access to the given address 306-B and may return the corresponding translated physical address 108-B.
[0083] In some implementations, in the prohibited mapping mode, when the system 304-B searches the page table 410-B for a mapping of the given intermediate physical address 306-B and does not find the mapping, the system 304-B may store the mapping of the given address 306-B to the corresponding physical address within the translation lookaside buffer 408-B.
[0084] In some implementations, the intermediate physical address 306-B may be the physical address 108-B, and the system 304-B may return a cache hit 412 (e.g., the intermediate physical address 306-B that hits in the translation lookaside buffer 408-B) and a table miss 416 (e.g., for the intermediate physical address 306-B whose mapping is not stored in the page table 410-B) as the physical address 108-B.
[0085] Figure 5 is a flowchart of an example process 500 for translating a virtual address to a corresponding physical address using a prohibited mapping scheme. For example Figure 1 a memory management unit of the memory management unit 114 may execute the process 500.
[0086] The memory management unit may receive a virtual address (step 502). As part of a memory access operation to the virtual address by, for example, a software application, a hardware device, etc., the memory management unit may receive the virtual address. The memory management unit may receive the virtual address from any of a variety of sources. For example, the memory management unit may perform memory management for a computing system (e.g., perform memory management for any combination of virtual machines running on the computing system, software applications running on the computing system, hardware devices connected to the computing system, etc.) and may receive the virtual address, for example, from a virtual machine running on the computing system, from a software application running on the computing system, from a hardware device connected to the computing system (e.g., a client device), etc.
[0087] In some implementations, a memory management unit may receive one or more access identifiers for a received virtual address. The access identifier for a virtual address may specify, for example, an application, an operating system, a device, a permission level, etc., for a software application or a hardware device accessing the received virtual address. The access identifier may include, for example, a process address space ID (PASID), a virtual machine ID (VMID), a flow ID, a sub-flow ID, a device ID, etc.
[0088] The memory management unit may convert the virtual address to an intermediate physical address (step 504). In particular, the memory management unit may use one or more virtual address page tables to store the mapping between the virtual address and the corresponding intermediate physical address, and may convert the virtual address by reading one or more virtual address page tables. In some implementations, the memory management unit may read the virtual address page table by performing a table lookup sequence in the virtual address page table - where the result of each table lookup in the sequence is used for the next table lookup in the sequence - and determining the intermediate physical address for the received virtual address based on the mapping returned by the last table lookup in the sequence. In some implementations, the memory management unit may use a translation lookaside buffer for the virtual address page table to cache the virtual address page table.
[0089] In some implementations, the memory management unit may determine whether to operate in a permissive mapping mode or a restrictive mapping mode to convert the intermediate physical address (step 506). The memory management unit may determine whether to operate in a permissive mapping mode or a restrictive mapping mode by any of a variety of methods. For example, in some implementations, the memory management unit may determine whether to operate in a restrictive mapping mode or a permissive mapping mode based on the intermediate physical address (e.g., based on a tag bit in the intermediate physical address, based on whether the intermediate physical address falls within a predetermined address range, etc.). As another example, when the memory management unit receives an access identifier, the memory management unit may determine whether to operate in a restrictive mapping mode or a permissive mapping mode based on the access identifier (e.g., where some access identifiers specify the use of the restrictive mapping mode and other access identifiers specify the use of the permissive mapping mode). As another example, the memory management unit may determine whether to operate in a restrictive mapping mode or a permissive mapping mode based on a combination of the intermediate physical address and the received access identifier (e.g., determining to operate in the permissive mapping mode when the intermediate address falls within the address range associated with the received access identifier, and otherwise determining to operate in the restrictive mapping mode).
[0090] When the memory management unit operates in the permissive mapping mode, the memory management unit can read the permitted mapping between the intermediate physical address and the physical address to perform memory access control on the received virtual address (step 508). The memory management unit can use one or more page tables for the intermediate physical address to store the permitted mapping between the intermediate physical address and the physical address (e.g., the mapping for the intermediate physical address for which memory access is permitted when the memory management unit operates in the permissive mapping mode). In some implementations, a translation lookaside buffer can be used to cache one or more page tables for the intermediate physical address. When operating in the permissive mapping mode, the memory management unit can use the intermediate physical address to read the page table for the intermediate physical address, and can allow memory access to the corresponding physical address when storing the mapping of the intermediate physical address in the page table for the intermediate physical address by returning the corresponding physical address. The memory management unit can deny memory access to the corresponding physical address (e.g., when operating in the permissive mapping mode and when the page table for the intermediate physical address does not include the mapping of the intermediate physical address) by preventing the return of the physical address for the intermediate physical address and optionally triggering a memory access fault or error (e.g., by outputting a specific memory access error signal, by modifying a register of the memory management unit indicating a memory access error, by outputting a predetermined value as the physical address indicating a memory access error, etc.).
[0091] When the memory management unit operates in the restrictive mapping mode, the memory management unit can read the restrictive mapping between the intermediate physical address and the physical address to perform memory access control on the received virtual address (step 510). The memory management unit can use the intermediate address to read the restrictive mapping (e.g., the mapping for the intermediate physical address for which memory access is prohibited when the memory management unit operates in the restrictive mapping mode), and can perform memory access control on the received virtual address based on the result of reading the restrictive mapping. If the restrictive mapping does not include the mapping of the intermediate address (e.g., if the intermediate physical address misses in the restrictive mapping), the memory management unit can allow memory access to the received virtual address and return the physical address for the intermediate physical address. Otherwise, if the restrictive mapping includes the mapping of the intermediate address (e.g., if the intermediate physical address hits in the restrictive mapping), the memory management unit can deny memory access to the received virtual address by preventing the return of the physical address for the intermediate physical address and optionally triggering a memory access fault or error (e.g., by outputting a specific memory access error signal, by modifying a register of the memory management unit indicating a memory access error, by outputting a predetermined value as the physical address indicating a memory access error, etc.).
[0092] The memory management unit can be configured to maintain (e.g., store) a prohibited mapping between intermediate physical addresses and physical addresses by any suitable means. For example, the memory management unit can use a prohibited mapping cache to store the prohibited mapping, and the memory management unit can read the prohibited mapping cache after a process 600 described in more detail below Figure 6 As another example, the memory management unit can use the cached page table to store the prohibited mapping, and the memory management unit can read the cached page table after a process 700 described in more detail below Figure 7 after the process 700 described in more detail below.
[0093] Generally, when the memory management unit allows a memory access and returns a physical address (e.g., when operating in a permitted mapping mode or a prohibited mapping mode), the returned physical address can be used to perform a memory access operation on the physical address, such as reading data from the physical address, writing data to the physical address, etc. When the memory management unit performs memory management on a computing system, the computing system can perform a memory access operation on the physical address and can provide an appropriate access result (e.g., data read from the physical address, data confirming a successful write operation to the physical address, etc.) to a software application or a hardware device accessing the received virtual address. Similarly, when the memory management unit denies a memory access, the computing system can provide an appropriate access result (e.g., data characterizing a memory access error) to a software application or a hardware device accessing the received virtual address.
[0094] Figure 6 is a flowchart of an example process of using an intermediate physical address to read a prohibited mapping using a prohibited mapping cache operating in a prohibited mapping mode. For example Figure 1 a memory management unit 114 of the memory management unit can execute the process 600.
[0095] The memory management unit can obtain an intermediate physical address (step 602). In particular, the memory management unit can obtain the intermediate physical address by translating a virtual address, such as after step 504 described above Figure 5 described.
[0096] The memory management unit can read the prohibited mapping cache using the intermediate physical address (step 604). The prohibited mapping cache can store the prohibited mapping between the intermediate physical address and the corresponding physical address.
[0097] The memory management unit may perform memory access control based on the result of reading the prohibited mapping cache using the intermediate physical address. If the intermediate physical address hits in the prohibited mapping cache (e.g., if the prohibited mapping cache stores the mapping of the intermediate physical address), memory access to the intermediate physical address is not allowed, and the memory management unit may continue with denying the memory access (e.g., continue to step 606). Otherwise, if the intermediate physical address misses in the prohibited mapping cache (e.g., if the prohibited mapping cache does not store the mapping of the intermediate physical address), memory access to the intermediate physical address is allowed, and the memory management unit may continue with returning the physical address for the intermediate physical address (e.g., continue to steps 608 and 610).
[0098] When the intermediate physical address hits in the prohibited mapping cache, the memory management unit may deny the memory access (step 606). The memory management unit may deny the memory access to the received virtual address by preventing the return of the physical address for the intermediate physical address and optionally raising a memory access fault or error (e.g., by outputting a specific memory access error signal, by modifying the register of the memory management unit indicating the memory access error, by outputting a predetermined value as the physical address indicating the memory access error, etc.).
[0099] In some implementations, when the intermediate physical address misses in the prohibited mapping cache, the memory management unit may determine the physical address for the intermediate physical address by reading the cached page table using the intermediate physical address (step 608). The cached page table may include a translation lookaside buffer and a page table. The cached page table may store the allowed mapping between the intermediate physical address and the physical address. When the memory management unit reads the cached page table, the memory management unit may determine the physical address for the intermediate physical address based on the mapping of the intermediate physical address stored in the translation lookaside buffer or the page table (e.g., by first reading the translation lookaside buffer using the intermediate physical address, and if the intermediate physical address misses in the translation lookaside buffer, then reading the page table using the intermediate physical address).
[0100] When the intermediate physical address hits in the shadow cache, the memory management unit may allow the memory access and return the physical address for the intermediate physical address (step 610). For example, when the memory management unit includes a cached page table that stores the permitted mapping from the intermediate physical address to the physical address, the memory management unit may return the physical address for the intermediate physical address determined by reading the cached page table as described above with reference to step 608. As another example, in some implementations, the physical address for the intermediate physical address may be the intermediate physical address, and the memory management unit may return the intermediate physical address as the physical address.
[0101] Figure 7 is a flowchart of an example process of using a cached page table operating in shadow mode to read the shadow using an intermediate physical address. For example Figure 1 the memory management unit 114 of may execute process 600.
[0102] The memory management unit may obtain an intermediate physical address (step 702). In particular, the memory management unit may obtain the intermediate physical address by translating a virtual address, such as after step 504 described above with reference to Figure 5 described.
[0103] The memory management unit may read the cached page table using the intermediate physical address. The cached page table may include a translation lookaside buffer and a page table. The translation lookaside buffer may store the permitted mapping from the intermediate physical address to the physical address, while the page table may store the shadow mapping from the intermediate physical address to the physical address.
[0104] As part of reading the cached page table, the memory management unit may first read the translation lookaside buffer using the intermediate physical address (step 704). If the mapping of the intermediate physical address is stored in the translation lookaside buffer, memory access to the intermediate physical address is permitted, and the memory management unit may continue to return the physical address for the intermediate physical address (e.g., continue to step 712).
[0105] If the translation lookaside buffer does not store the mapping of the intermediate physical address (e.g., if the intermediate physical address misses in the translation lookaside buffer), the memory management unit may use the intermediate physical address to read the page table (step 706). If the page table includes the mapping of the intermediate physical address, memory access to the intermediate physical address is not permitted, and the memory management unit may continue to deny the memory access (e.g., continue to step 710).
[0106] If the page table does not include a mapping of the intermediate physical address, memory access to the intermediate physical address is permitted and the memory management unit may continue to allow memory access (e.g., continue to step 712).
[0107] In some implementations, when the intermediate physical address misses in the translation lookaside buffer and when the page table does not store a mapping of the intermediate physical address, the memory management unit may store a mapping of the intermediate physical address in the translation lookaside buffer (step 708). For example, in some implementations, the physical address for the intermediate physical address may be the intermediate physical address and the memory management unit may store the intermediate physical address in the translation lookaside buffer.
[0108] When the intermediate physical address misses in the translation lookaside buffer and the page table stores a mapping of the intermediate physical address, the memory management unit may deny the memory access (step 710). The memory management unit may deny the memory access to the received virtual address by preventing the return of the physical address for the intermediate physical address and optionally raising a memory access fault or error (e.g., by outputting a specific memory access error signal, by modifying a register of the memory management unit indicating a memory access error, by outputting a predetermined value as the physical address indicating a memory access error, etc.).
[0109] When the intermediate physical address hits in the translation lookaside buffer, or when the page table does not store a mapping of the intermediate physical address, the system may allow the memory access and return the physical address for the intermediate physical address (step 712). For example, when the intermediate physical address hits in the translation lookaside buffer, the memory management unit may return the physical address for the intermediate physical address determined by reading the translation lookaside buffer as described above with reference to step 704. As another example, in some implementations, the physical address for the intermediate physical address may be the intermediate physical address and the memory management unit may return the intermediate physical address as the physical address.
[0110] Embodiments of the subject matter and the functional operations described in this specification can be implemented in digital electronic circuitry, in tangibly embodied computer software or firmware, in computer hardware including the structures disclosed in this specification and their structural equivalents, or in combinations of one or more of them. Embodiments of the subject matter described in this specification can be implemented as one or more computer programs, i.e., one or more modules of computer program instructions encoded on a tangible non-transitory storage medium for execution by, or to control the operation of, data processing apparatus. A computer storage medium may be a machine-readable storage device, a machine-readable storage substrate, a random or serial access memory device, or a combination of one or more of them. Alternatively or additionally, the program instructions may be encoded on an artificially generated propagated signal, e.g., a machine-generated electrical, optical, or electromagnetic signal, that is generated to encode information for transmission to a suitable receiver apparatus for execution by the data processing apparatus.
[0111] The term “data processing apparatus” refers to data processing hardware and includes all kinds of devices, apparatus, and machines for processing data, e.g., including programmable processors, computers, or multiple processors or computers. The apparatus may also be, or further include, special purpose logic circuitry, such as an FPGA (field programmable gate array) or an ASIC (application specific integrated circuit). In addition to hardware, the apparatus may optionally include code that creates an execution environment for the computer program, e.g., code that constitutes processor firmware, a protocol stack, a database management system, an operating system, or a combination of one or more of them.
[0112] A computer program, which may also be referred to as or described as a program, software, software application, app, module, software module, script, or code, can be written in any form of programming language (including compiled or interpreted languages, or declarative or procedural languages); and it can be deployed in any form, including as a stand-alone program or as a module, component, subroutine, or other unit suitable for use in a computing environment. A program may, but need not, correspond to a file in a file system. A program may be stored in a part of a file that holds other programs or data (e.g., one or more scripts stored in a markup language document), in a single file dedicated to the program being discussed, or in multiple coordinated files (e.g., files that store one or more modules, subroutines, or portions of code). A computer program may be deployed to execute on one computer or on multiple computers distributed at one site or across multiple sites and interconnected by a data communication network.
[0113] For a system of one or more computers configured to perform particular operations or actions, it means that the system has installed thereon software, firmware, hardware, or a combination thereof that, in operation, causes the system to perform those operations or actions. For one or more computer programs configured to perform particular operations or actions, it means that the one or more programs include instructions that, when executed by a data processing device, cause the device to perform the operation or action.
[0114] As used in this specification, an "engine" or "software engine" refers to a software-implemented input / output system that provides an output different from the input. An engine can be a functional coding block such as a library, platform, software development kit ("SDK"), or object. Each engine can be implemented on any suitable type of computing device including one or more processors and a computer-readable medium (e.g., a server, mobile phone, tablet computer, notebook computer, music player, e-book reader, laptop or desktop computer, PDA, smart phone, or other fixed or portable device). Additionally, two or more of the engines can be implemented on the same computing device or on different computing devices.
[0115] The processes and logical flows described in this specification can be performed by one or more programmable computers that execute one or more computer programs to perform functions by operating on input data and generating output. The processes and logical flows can also be performed by, for example, FPGA or ASIC dedicated logic circuitry, or by a combination of dedicated logic circuitry and one or more programmed computers.
[0116] Computers suitable for executing computer programs can be based on general or special purpose microprocessors or both, or any other kind of central processing unit. Generally, the central processing unit will receive instructions and data from a read-only memory or a random access memory or both. The basic elements of a computer are a central processing unit for performing or executing instructions and one or more memory devices for storing instructions and data. The central processing unit and the memory can be supplemented by, or incorporated in, dedicated logic circuitry. Generally, a computer will also include one or more mass storage devices for storing data, such as magnetic disks, magneto-optical disks, or optical disks, or will be operatively coupled to receive data from or transfer data to the one or more mass storage devices, or both. However, a computer need not have such devices. In addition, a computer can be embedded in another device, such as a mobile phone, personal digital assistant (PDA), mobile audio or video player, game console, global positioning system (GPS) receiver, or a portable storage device such as a universal serial bus (USB) flash drive, to name just a few.
[0117] Computer-readable media suitable for storing computer program instructions and data include all forms of non-volatile memory, media, and memory devices, including, for example, semiconductor memory devices (such as EPROM, EEPROM, and flash memory devices), magnetic disks (such as internal hard disks or removable disks), magneto-optical disks, and CD-ROM and DVD-ROM disks.
[0118] To provide for interaction with a user, embodiments of the subject matter described in this specification may be implemented on a computer having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse, trackball, or a presence-sensitive display or other surface) by which the user can provide input to the computer. Other kinds of devices may also be used to provide for interaction with the user; for example, feedback provided to the user may be any form of sensory feedback, such as visual feedback, auditory feedback, or tactile feedback; and input from the user may be received in any form, including acoustic, speech, or tactile input. Additionally, the computer may interact with the user by sending documents to and receiving documents from the devices used by the user; for example, by sending web pages to a web browser on the user device in response to requests received from the web browser. Further, the computer may interact with the user by sending text messages or other forms of messages to a personal device (e.g., a smart phone running a messaging application) and receiving responsive messages from the user in response.
[0119] Embodiments of the subject matter described in this specification may be implemented in a computing system that includes a backend component (e.g., as a data server), or includes a middleware component (e.g., an application server), or includes a frontend component (e.g., a client computer having a graphical user interface, a web browser, or an app through which a user can interact with an implementation of the subject matter described in this specification), or any combination of one or more such backend, middleware, or frontend components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN) and a wide area network (WAN), such as the Internet.
[0120] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact through a communication network. The relationship of client and server arises from computer programs running on the respective computers and having a client-server relationship to each other. In some embodiments, the server sends data (e.g., an HTML page) to a user device, for example, for displaying data to and receiving user input from a user interacting with the device acting as the client. Data generated at the user device (e.g., the results of user interaction) may be received at the server from the device.
[0121] In addition to the embodiments described above, the following embodiments are also innovative:
[0122] Embodiment 1 is a system that includes: a memory management unit configured to perform multi-level address translation, where the first level of the address translation performs an address translation from a virtual address to an intermediate physical address, and where the second level of the address translation performs an address translation from the intermediate physical address to a physical address, where the memory management unit is configured to maintain a prohibited mapping between the intermediate physical address and the physical address, and where the memory management unit is configured to operate in a prohibited mapping mode to perform multi-level address translation by performing operations including: translating the virtual address to the intermediate physical address, reading the prohibited mapping using the intermediate physical address, and if the intermediate physical address misses in the prohibited mapping, returning the physical address for the intermediate physical address.
[0123] Embodiment 2 is the system as described in Embodiment 1, where the system includes a plurality of virtual machines configured to issue virtual addresses to the memory management unit.
[0124] Embodiment 3 is the system as described in Embodiment 1, where the system includes a plurality of client devices configured to issue virtual addresses to the memory management unit.
[0125] Embodiment 4 is the system as described in any one of Embodiments 1 to 3, where the memory management unit includes: a translation lookaside buffer and a memory storing a page table, where the translation lookaside buffer and the page table store an intermediate physical address to physical address mapping.
[0126] Embodiment 5 is the system as described in Embodiment 4, where: the memory management unit further includes a prohibited mapping cache that stores an intermediate physical address to physical address mapping; reading the prohibited mapping using the intermediate physical address includes reading the prohibited mapping cache using the intermediate physical address; and returning the physical address for the intermediate physical address if the intermediate physical address misses in the prohibited mapping includes returning the physical address for the intermediate physical address if the intermediate physical address misses in the prohibited mapping cache.
[0127] Example 6 is a system as described in Example 5, wherein returning a physical address for the intermediate physical address if the intermediate physical address misses in the prohibited mapping cache includes: determining a physical address for the intermediate physical address based on the mapping of the intermediate physical address stored in the translation lookaside buffer or the page table, and if the intermediate physical address misses in the prohibited mapping cache, returning the physical address for the intermediate physical address.
[0128] Example 7 is a system as described in Example 4, wherein: reading the prohibited mapping using the intermediate physical address includes reading the translation lookaside buffer using the intermediate physical address, and if the intermediate physical address misses in the translation lookaside buffer, reading the page table using the intermediate physical address; and returning a physical address for the intermediate physical address if the intermediate physical address misses in the prohibited mapping includes: if the intermediate physical address hits in the translation lookaside buffer or if the page table does not store the intermediate physical address, returning the physical address for the intermediate physical address.
[0129] Example 8 is a system as described in Example 7, wherein returning a physical address for the intermediate physical address if the intermediate physical address misses in the prohibited mapping further includes: if the intermediate physical address misses in the translation lookaside buffer and if the page table does not store the mapping of the intermediate physical address, storing the mapping of the intermediate physical address in the translation lookaside buffer.
[0130] Example 9 is a system as described in any one of Examples 4 to 8, wherein the memory management unit is capable of operating in a permitted mapping mode to perform multi-level address translation by: converting a virtual address to an intermediate physical address, reading the translation lookaside buffer using the intermediate physical address, and if the intermediate physical address hits in the translation lookaside buffer or if the page table stores the mapping of the intermediate physical address, returning the physical address for the intermediate physical address.
[0131] Example 10 is a system as described in Example 9, wherein the memory management unit is capable of determining whether to operate in the prohibited mapping mode or the permitted mapping mode based on an access identifier.
[0132] Example 11 is a system as described in Example 9 or Example 10, wherein: the memory management unit is capable of switching from operating in the permitted mapping mode to operating in the prohibited mapping mode by loading a prohibited address translation into the translation lookaside buffer and the page table, and the memory management unit is capable of switching from operating in the prohibited mapping mode to operating in the permitted mapping mode by loading a permitted address translation into the translation lookaside buffer and the page table.
[0133] Example 12 is a system as described in any one of Examples 1 to 11, wherein the intermediate physical address is the physical address.
[0134] Example 13 is a system as described in any one of Examples 1 to 12, wherein the prohibited mapping corresponds to a protected portion of the global address space.
[0135] Example 14 is a system as described in Example 13, wherein the protected portion of the global address space has a fixed size.
[0136] Example 15 is a system as described in Example 13 or Example 14, wherein the protected portion of the global address space has a size less than 10% of the size of the global address space.
[0137] Example 16 is a method, comprising: converting a virtual address to an intermediate physical address by a memory management unit configured to maintain a prohibited mapping between the intermediate physical address and the physical address; reading the prohibited mapping by the memory management unit using the intermediate physical address; and if the intermediate physical address misses in the prohibited mapping, returning, by the memory management unit, the physical address for the intermediate physical address.
[0138] Example 17 is the method as described in Example 16, further comprising: receiving, by the memory management unit, the virtual address from one of a plurality of virtual machines.
[0139] Example 18 is the method as described in Example 16, further comprising: receiving, by the memory management unit, the virtual address from one of a plurality of client devices.
[0140] Example 19 is the method as described in any one of Examples 16 to 18, wherein the memory management unit comprises: a translation lookaside buffer and a memory storing a page table, wherein the translation lookaside buffer and the page table store an intermediate physical address to physical address mapping.
[0141] Example 20 is the method as described in Example 19, wherein the memory management unit further includes a prohibited mapping cache that stores intermediate physical address to physical address mappings; using the intermediate physical address by the memory management unit to read the prohibited mapping includes using the intermediate physical address by the memory management unit to read the prohibited mapping cache; and returning, by the memory management unit, the physical address for the intermediate physical address if the intermediate physical address misses in the prohibited mapping includes returning, by the memory management unit, the physical address for the intermediate physical address if the intermediate physical address misses in the prohibited mapping cache.
[0142] Example 21 is the method as described in Example 20, wherein returning, by the memory management unit, the physical address for the intermediate physical address if the intermediate physical address misses in the prohibited mapping cache includes: determining, by the memory management unit, the physical address for the intermediate physical address based on the mapping of the intermediate physical address stored in the translation lookaside buffer or the page table, and returning, by the memory management unit, the physical address for the intermediate physical address if the intermediate physical address misses in the prohibited mapping cache.
[0143] Example 22 is the method as described in Example 19, wherein: using the intermediate physical address by the memory management unit to read the prohibited mapping includes using the intermediate physical address by the memory management unit to read the translation lookaside buffer, and if the intermediate physical address misses in the translation lookaside buffer, then using the intermediate physical address by the memory management unit to read the page table; and returning, by the memory management unit, the physical address for the intermediate physical address if the intermediate physical address misses in the prohibited mapping includes: returning, by the memory management unit, the physical address for the intermediate physical address if the intermediate physical address hits in the translation lookaside buffer or if the page table does not store the intermediate physical address.
[0144] Example 23 is the method as described in Example 22, wherein returning, by the memory management unit, the physical address for the intermediate physical address if the intermediate physical address misses in the prohibited mapping further includes: storing, by the memory management unit, the mapping of the intermediate physical address in the translation lookaside buffer if the intermediate physical address misses in the translation lookaside buffer and if the page table does not store the mapping of the intermediate physical address.
[0145] Example 24 is the method according to any one of Examples 19 to 23, wherein the memory management unit is capable of operating in a permitted mapping mode to perform a multi-level address translation by: converting a virtual address to an intermediate physical address, reading the translation lookaside buffer using the intermediate physical address, and returning a physical address for the intermediate physical address if the intermediate physical address hits in the translation lookaside buffer or if the page table stores a mapping of the intermediate physical address.
[0146] Example 25 is the method according to Example 24, wherein the memory management unit is capable of determining whether to operate in the prohibited mapping mode or the permitted mapping mode based on an access identifier.
[0147] Example 26 is the method according to Example 24 or Example 25, wherein: the memory management unit is capable of switching from operating in the permitted mapping mode to operating in the prohibited mapping mode by loading prohibited address translations into the translation lookaside buffer and the page table, and the memory management unit is capable of switching from operating in the prohibited mapping mode to operating in the permitted mapping mode by loading permitted address translations into the translation lookaside buffer and the page table.
[0148] Example 27 is the method according to any one of Examples 16 to 26, wherein the intermediate physical address is the physical address.
[0149] Example 28 is the method according to any one of Examples 16 to 27, wherein the prohibited mapping corresponds to a protected portion of the global address space.
[0150] Example 29 is the method according to Example 28, wherein the protected portion of the global address space has a fixed size.
[0151] Example 30 is the method according to Example 28 or Example 29, wherein the protected portion of the global address space has a size less than 10% of the size of the global address space.
[0152] Example 31 is a non-transitory computer-readable storage medium encoded with instructions that, when executed by a data processing device, cause the data processing device to perform the operations of the method according to any one of Examples 16 to 30.
[0153] While this specification contains many specific implementation details, these should not be construed as limitations on the scope of any invention or of what may be claimed, but rather as descriptions of features that may be specific to particular embodiments of a particular invention. Certain features that are described in this specification in the context of separate embodiments can also be implemented in combination within a single embodiment. Conversely, various features that are described in the context of a single embodiment can also be implemented separately in multiple embodiments or in any suitable sub-combination. In addition, although the features may be described above as acting in certain combinations and even initially claimed as such, in some cases one or more features from a claimed combination can be deleted from the combination, and the claimed combination may relate to a sub-combination or a variant of a sub-combination.
[0154] Similarly, while operations are depicted in the drawings in a particular order, this should not be construed as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve a desired result. In certain circumstances, multitasking and parallel processing may be advantageous. In addition, the separation of various system modules and components in the above embodiments should not be understood as requiring such separation in all embodiments, and it should be understood that the described program components and systems can generally be integrated together in a single software product or packaged into multiple software products.
[0155] Specific embodiments of the subject matter have been described. Other embodiments are within the scope of the following claims. For example, the acts recited in the claims can be performed in a different order and still achieve a desired result. As one example, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve a desired result. In certain implementations, multitasking and parallel processing may be advantageous.
Claims
1. A system comprising: a memory management unit configured to perform multi-level address translation, wherein the first stage of the address translation performs an address translation from a virtual address to an intermediate physical address, and wherein the second stage of the address translation performs an address translation from an intermediate physical address to a physical address, wherein the memory management unit is configured to maintain an inhibit mapping between the intermediate physical address and the physical address, Wherein the memory management unit is configured to operate in a disable mapping mode to perform multi-level address translation by performing operations including: Converts a virtual address to an intermediate physical address, reading the inhibit mapping using the intermediate physical address, and If the intermediate physical address does not hit in the inhibit mapping, a physical address for the intermediate physical address is returned. 2 . The system of claim 1 , wherein the system comprises a plurality of virtual machines configured to issue virtual addresses to the memory management unit. 3 . The system of claim 1 , wherein the system comprises a plurality of client devices configured to issue virtual addresses to the memory management unit.
4. The system according to claim 1, wherein the memory management unit comprises: The memory for the translation lookaside buffer and the page tables, Wherein the translation lookaside buffer and the page table store intermediate physical address to physical address mappings.
5. The system of claim 4, wherein: The memory management unit further includes an inhibit map cache storing intermediate physical address to physical address mappings; Reading the inhibit mapping using the intermediate physical address comprises: Reading the inhibit mapping cache using the intermediate physical address; and If the intermediate physical address does not hit in the inhibit mapping, returning the physical address for the intermediate physical address comprises: If the intermediate physical address does not hit in the inhibit mapping cache, a physical address for the intermediate physical address is returned.
6. The system of claim 5, wherein returning a physical address for the intermediate physical address if the intermediate physical address misses in the inhibit mapping cache comprises: determining a physical address for the intermediate physical address based on a mapping of the intermediate physical address stored in the translation lookaside buffer or the page table, and If the intermediate physical address does not hit in the inhibit mapping cache, the physical address for the intermediate physical address is returned.
7. The system of claim 4, wherein: Reading the inhibit mapping using the intermediate physical address comprises: Reading the translation lookaside buffer using the intermediate physical address; and If the intermediate physical address does not hit in the translation lookaside buffer, reading the page table using the intermediate physical address; and If the intermediate physical address does not hit in the inhibit mapping, returning the physical address for the intermediate physical address comprises: If the intermediate physical address hits in the translation lookaside buffer or if the page table does not store the intermediate physical address, a physical address for the intermediate physical address is returned.
8. The system of claim 7, wherein returning the physical address for the intermediate physical address if the intermediate physical address does not hit in the inhibit mapping further comprises: If the intermediate physical address misses in the translation lookaside buffer and if the page table does not store a mapping of the intermediate physical address, storing a mapping of the intermediate physical address in the translation lookaside buffer.
9. The system of claim 4, wherein the memory management unit is operable in a mapping enabled mode to perform multi-level address translation by: Converts a virtual address to an intermediate physical address, reading the translation lookaside buffer using the intermediate physical address, and If the intermediate physical address hits in the translation lookaside buffer or if the page table stores a mapping of the intermediate physical address, a physical address for the intermediate physical address is returned.
10. The system of claim 9, wherein the memory management unit is capable of determining whether to operate in the disable mapping mode or the enable mapping mode based on an access identifier.
11. The system of claim 9, wherein: The memory management unit is capable of switching from operating in the enabled mapping mode to operating in the disabled mapping mode by loading disabled address translations into the translation lookaside buffer and the page table, and The memory management unit can switch from operating in the disable mapping mode to operating in the enable mapping mode by loading allowed address translations into the translation lookaside buffer and the page table.
12. The system according to any one of claims 1 to 11, wherein the intermediate physical address is the physical address.
13. The system of any one of claims 1 to 11, wherein the prohibited mapping corresponds to a protected portion of a global address space.
14. The system of claim 13, wherein the protected portion of the global address space has a fixed size.
15. The system of claim 13, wherein the protected portion of the global address space has a size that is less than 10% of a size of the global address space.
16. A method comprising: translating the virtual address to the intermediate physical address by a memory management unit configured to maintain an inhibit mapping between the intermediate physical address and the physical address; reading a inhibit mapping using the intermediate physical address by the memory management unit; as well as If the intermediate physical address does not hit in the inhibit mapping, a physical address for the intermediate physical address is returned by the memory management unit.
17. The method according to claim 16, further comprising: The virtual address is received by the memory management unit from one of a plurality of virtual machines.
18. The method according to claim 16, further comprising: The virtual address is received by the memory management unit from one of a plurality of client devices.
19. The method according to any one of claims 16 to 18, wherein the memory management unit comprises: The memory for the translation lookaside buffer and the page tables, Wherein the translation lookaside buffer and the page table store intermediate physical address to physical address mappings.
20. The method of claim 19, wherein: The memory management unit further includes an inhibit map cache storing intermediate physical address to physical address mappings; Reading the inhibit mapping using the intermediate physical address by the memory management unit includes: reading, by the memory management unit, the inhibit map cache using the intermediate physical address; and If the intermediate physical address does not hit in the inhibit mapping, returning, by the memory management unit, a physical address for the intermediate physical address comprises: If the intermediate physical address does not hit in the inhibit mapping cache, a physical address for the intermediate physical address is returned by the memory management unit.
21. The method of claim 20, wherein returning, by the memory management unit, a physical address for the intermediate physical address if the intermediate physical address misses in the inhibit mapping cache comprises: determining, by the memory management unit, a physical address for the intermediate physical address based on a mapping of the intermediate physical address stored in the translation lookaside buffer or the page table, and If the intermediate physical address misses in the inhibit mapping cache, the physical address for the intermediate physical address is returned by the memory management unit.
22. The method of claim 19, wherein: Reading the inhibit mapping using the intermediate physical address by the memory management unit includes: reading, by the memory management unit, the translation lookaside buffer using the intermediate physical address; and If the intermediate physical address does not hit in the translation lookaside buffer, reading the page table by the memory management unit using the intermediate physical address; and If the intermediate physical address does not hit in the inhibit mapping, returning, by the memory management unit, a physical address for the intermediate physical address comprises: If the intermediate physical address hits in the translation lookaside buffer or if the page table does not store the intermediate physical address, a physical address for the intermediate physical address is returned by the memory management unit.
23. The method of claim 22, wherein returning, by the memory management unit, a physical address for the intermediate physical address if the intermediate physical address does not hit in the inhibit mapping further comprises: If the intermediate physical address misses in the translation lookaside buffer and if the page table does not store a mapping of the intermediate physical address, storing a mapping of the intermediate physical address in the translation lookaside buffer by the memory management unit.
24. The method of claim 19, wherein the memory management unit is operable in a mapping enabled mode to perform multi-level address translation by: Converts a virtual address to an intermediate physical address, reading the translation lookaside buffer using the intermediate physical address, and If the intermediate physical address hits in the translation lookaside buffer or if the page table stores a mapping of the intermediate physical address, a physical address for the intermediate physical address is returned.
25. The method of claim 24, wherein the memory management unit is capable of determining whether to operate in the disable mapping mode or the enable mapping mode based on an access identifier.
26. The method of claim 24, wherein: The memory management unit is capable of switching from operating in the enabled mapping mode to operating in the disabled mapping mode by loading disabled address translations into the translation lookaside buffer and the page table, and The memory management unit can switch from operating in the disable mapping mode to operating in the enable mapping mode by loading allowed address translations into the translation lookaside buffer and the page table.
27. The method of any one of claims 16 to 26, wherein the intermediate physical address is the physical address.
28. A method according to any one of claims 16 to 26, wherein the prohibited mapping corresponds to a protected portion of a global address space.
29. The method of claim 28, wherein the protected portion of the global address space has a fixed size.
30. The method of claim 28, wherein the protected portion of the global address space has a size that is less than 10% of a size of the global address space.
31. A non-transitory computer-readable storage medium encoded with instructions that, when executed by a data processing device, cause the data processing device to perform the operations of the method of any one of claims 16 to 30.