Virtualization processing method and device and storage medium

By inserting a virtualization layer between the hardware resources and the host operating system, virtual resources are provided to solve the problem of insufficient resources caused by unconfigured functions, and the capabilities of the host operating system are expanded and stable.

CN120234091APending Publication Date: 2025-07-01HANGZHOU ALICLOUD FEITIAN INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311853122.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-28
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

The existing operating systems that have been run but have not configured related functions cannot expand their capabilities, resulting in insufficient application resources, and the efficiency of reinstalling the operating system in the existing technology is inefficient and affects system stability.

Method used

Insert a virtualization layer between the hardware resources and the host operating system to provide virtual resources, and run applications with unconfigured functions in non-root mode through mode switching to avoid reinstalling the operating system.

Benefits of technology

Without affecting the performance of the host operating system, expand its capabilities, support the operation of more applications, solve the problem of insufficient resources, and improve system stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120234091A_ABST
    Figure CN120234091A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a virtualization processing method and device and a storage medium. In the embodiment of the invention, two running modes, namely a root mode and a non-root mode, are provided for a host machine operating system in a running state, a virtualization layer is inserted between hardware resources and the host machine operating system, and a function of providing virtual resources is at least realized in the virtualization layer; the running host machine operating system is switched from a root mode to a non-root mode by the virtualization layer, virtual resources are provided in the non-root mode, and at least applications, which cannot be run due to insufficient resources in the root mode, of the host machine operating system are run on the virtual resources. The virtual resource providing function can be flexibly achieved for the host machine operating system in the running state, running of more applications is supported, and the capacity of the host machine operating system is expanded.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of virtualization technology, and in particular, to a virtualization processing method, device, and storage medium. Background Art

[0002] The operating system (OS), as the basic system software of a computer device, can provide various system-level functions, such as memory swapping (swap). Memory swapping is an extended mechanism that uses free hard disk space as memory space; when the physical pages in the main memory are insufficient, a part of the infrequently used memory pages are swapped to the hard disk; when the process uses these memory pages again, these memory pages are swapped from the hard disk to the main memory.

[0003] Among them, some system functions represented by the memory swapping function need to be configured when installing the operating system; if not configured during the installation of the operating system, the corresponding system functions cannot be used to provide resources for applications during the operation of the operating system, resulting in abnormal operation or inability to run of the applications that rely on the system functions. For the existing operating systems that have been running but have not configured the relevant system functions, there are technical problems in how to expand their capabilities. Summary of the Invention

[0004] Multiple aspects of this application provide a virtualization processing method, device, and storage medium to solve the problem of capacity expansion faced by existing operating systems that have been running but have not configured relevant functions, thereby supporting the operation of more applications.

[0005] An embodiment of this application also provides a physical machine, which includes hardware resources and a host operating system running on the hardware resources, and a virtualization layer is implemented between the hardware resources and the host operating system; the virtualization layer is used to switch the running host operating system from the root mode to the non-root mode, and in the non-root mode, provide at least one virtual resource and run at least one application on the at least one virtual resource; where the at least one application at least includes the applications that the host operating system cannot run due to insufficient resources in the root mode.

[0006] An embodiment of this application also provides a virtualization processing method, which is applied to the virtualization layer in a physical machine. The virtualization layer is located between the hardware resources and the host operating system of the physical machine. The method includes: switching the running host operating system from the root mode to the non-root mode; in the non-root mode, providing at least one virtual resource and running at least one application on the at least one virtual resource; the at least one application at least includes the applications that the host operating system cannot run due to insufficient resources in the root mode.

[0007] The embodiment of the present application further provides a computer-readable storage medium storing a computer program, which, when executed by a processor, causes the processor to implement the steps in the virtualization processing method provided by the embodiment of the present application.

[0008] In the embodiment of the present application, two operating modes, namely, the root mode and the non-root mode, are provided for the running host operating system. A virtualization layer is inserted between the hardware resources and the host operating system. At least the function of providing virtual resources is implemented in the virtualization layer, and the virtualization layer switches the running host operating system from the root mode to the non-root mode. In the non-root mode, at least one virtual resource is provided, and at least one application that cannot run due to insufficient resources in the root mode of the host operating system is run on at least one virtual resource. Without reinstalling the host operating system, the function of providing virtual resources can be flexibly implemented for the running host operating system, supporting the running of more applications and expanding the capabilities of the host operating system. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] The drawings described herein are used to provide a further understanding of the present application and form a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:

[0010] Figure 1a is a schematic structural diagram of a physical machine provided by an exemplary embodiment of the present application;

[0011] Figure 1b is a schematic structural diagram of another physical machine provided by an exemplary embodiment of the present application;

[0012] Figure 1c is provided by an exemplary embodiment of the present application Figure 1b The system structure diagram of the physical machine shown working in the root mode;

[0013] Figure 1d is provided by an exemplary embodiment of the present application Figure 1b The system structure diagram of the physical machine shown working in the non-root mode;

[0014] Figure 2a is a schematic flow diagram of switching the host operating system from the root mode to the non-root mode provided by an exemplary embodiment of the present application;

[0015] Figure 2b is a schematic flow diagram of creating a memory page table provided by an exemplary embodiment of the present application;

[0016] Figure 2c is a schematic flow diagram of creating an information-bearing object provided by an exemplary embodiment of the present application;

[0017] Figure 2d A schematic flowchart of a mode switch is provided for an exemplary embodiment of the present application;

[0018] Figure 3 A schematic flowchart of a virtualization processing method is provided for an exemplary embodiment of the present application;

[0019] Figure 4 A schematic structural diagram of a virtualization processing device is provided for an exemplary embodiment of the present application. Detailed implementation manners

[0020] To make the objectives, technical solutions, and advantages of the present application clearer, the technical solutions of the present application will be clearly and completely described below in conjunction with specific embodiments of the present application and the corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0021] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or fully authorized by all parties. Moreover, the collection, use, and processing of relevant data need to comply with relevant laws, regulations, and standards of relevant countries and regions, and corresponding operation entrances are provided for users to select authorization or rejection.

[0022] In the embodiments of the present application, as Figure 1a shown, the host computer includes hardware resources. The host operating system (host OS) runs on the hardware resources, and various application programs run on the host operating system. Relative to the hardware resources, the host operating system and application programs belong to the software resources of the host computer. The host operating system is the most basic system software in the host computer. It is responsible for controlling and managing the entire hardware resources and software resources of the host computer, and can reasonably schedule the work and resource allocation of the host computer, and can provide convenient interfaces and environments for users and other software or devices. Among them, the host operating system can provide various system-level functions, such as file management, memory management, and management of various input / output (IO) devices. Based on these system functions, the host operating system can provide various resources required during the running process for application programs to support the running of application programs.

[0023] Among these system functions, at least some of them need to be configured when installing the host operating system, such as whether to enable it and which mode to enable. For system functions that are not enabled, they cannot be used during the operation of the host operating system. Since these system functions cannot be used, the application programs that depend on these system functions may run abnormally or cannot run because they cannot obtain the resources provided by these system functions. However, with the operation of the host operating system and the change of application requirements, it may be necessary to use these unenabled system functions, or to upgrade the enabled system functions, that is, the host operating system faces the problem of capacity expansion. For traditional hosts, either reinstall the host operating system or forcibly enable some system functions online. For the method of reinstalling the host operating system, it is necessary to interrupt the operation of all applications, with low efficiency and high cost; for the method of forcibly enabling the corresponding system functions online, it will seriously affect the stability of the system.

[0024] In the embodiments of the present application, in order to solve the problem of capacity expansion faced by the host operating system without reinstalling the host operating system and without affecting the operating performance of the host operating system, a new physical machine architecture is provided. Two operating modes, namely the root mode and the non-root mode, are provided for the running host operating system. A virtualization layer is inserted between the hardware resources and the host operating system. At least the virtual resource providing function is implemented in the virtualization layer, and the virtualization layer switches the running host operating system from the root mode to the non-root mode. At least one virtual resource is provided in the non-root mode, and at least the application that cannot run due to insufficient resources in the root mode of the host operating system runs on the virtual resource. Without reinstalling the operating system, the virtual resource providing function can be flexibly implemented for the running host operating system, solve the problem that application programs cannot run due to insufficient resources caused by reasons such as unenabled or missing system functions, support the running of more applications, and is beneficial to expanding the capabilities of the host operating system.

[0025] For example, assuming that the host operating system supports function A, function B, function C, and function D, etc., when installing the host operating system, function A, function B, and function C are enabled, function D is not enabled, and function E is missing (i.e., the host operating system does not support function E). Using the physical machine provided by the embodiment of the present application, a virtualization layer is inserted between the hardware resources and the host operating system, and the function of providing virtual resources is implemented at least in the virtualization layer. For example, if the host operating system does not enable function D and lacks function E, the virtualization layer switches the host operating system from the root mode to the non-root mode, and provides virtual resources corresponding to function D and function E in the non-root mode. Applications that were originally unable to run due to the non-enablement of function D and the lack of function E are run on the virtual resources. Without the need to reinstall the host operating system, the function of providing virtual resources can be flexibly implemented for the running host operating system, solving the problem that the corresponding application cannot run due to the non-enablement of function D and the lack of function E, which is conducive to expanding the capabilities of the host operating system. Furthermore, in order to compensate for the deficiencies of the host operating system, virtual resources corresponding to function D and function E can be provided preferentially in non-root mode to solve the operation problems of applications that depend on function D and function E; of course, for the compatibility of the host operating system and to avoid frequent mode switching, virtual resources corresponding to function A, function B and function C can also be provided in non-root mode to facilitate running of corresponding applications that depend on function A, function B and function C on these resources.

[0026] It is to be noted that in the embodiments of the present application, the focus is on the switching process of the host operating system between the two modes, and no limitation is made as to which system functions are provided in the non-root mode and how the virtual resources corresponding to these system functions are provided. The following, in conjunction with the accompanying drawings, describes in detail the physical machine architecture provided in the embodiments of the present application and the process of the host operating system switching from the root mode to the non-root mode.

[0027] Figure 1b A schematic diagram of the structure of a physical machine provided by an exemplary embodiment of the present application. Figure 1b As shown, the physical machine includes: hardware resources 10 and a host operating system 20 running on the hardware resources, and a virtualization layer 30 is implemented between the hardware resources 10 and the host operating system 20. Furthermore, an application layer 40 is also included above the host operating system 20. The application layer 40 includes various application programs.

[0028] Optionally, the hardware resources 10 include: at least one physical computing resource object 101 and a physical storage medium 102, and the physical storage medium 102 is responsible for providing a physical address space. In addition, the hardware resources 10 on the physical machine may also include: IO devices, communication components, displays, power components, audio components and other components, which are not shown in the figure.

[0029] Among them, the physical computing resource object 101 can be various physical resource objects with computing capabilities such as a Central Processing Unit (CPU), a Graphics Processing Unit (GPU), a Data Processing Unit (DPU), a Tensor Processing Unit (TPU), a Cloud Infrastructure Processing Unit (CIPU), and an Application Specific Integrated Circuit (ASIC). The host operating system 20 can run on at least one physical computing resource object 101.

[0030] Among them, the physical storage medium 102 includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. The physical storage medium 102 includes but is not limited to: Phase-change Random Access Memory (PRAM), Static Random Access Memory (SRAM), Dynamic Random Access Memory (DRAM), other types of Random Access Memory (RAM), Read Only Memory (ROM), Electrically Erasable Programmable Read Only Memory (EEPROM), flash memory or other memory technologies, Compact Disc Read Only Memory (CD-ROM), Digital Video Disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device.

[0031] Among them, the physical memory is the actual memory chips or modules in a physical machine, used to store data and program code. The physical memory may include non-permanent memory in the physical storage medium 102, in the form of Random Access Memory (RAM) and / or non-volatile memory, such as Read Only Memory (ROM) or flash RAM (flash memory).

[0032] Among them, the physical address space is the address range corresponding to physical memory. The physical address space is usually related to the hardware architecture and the host operating system, and it describes the physical location and size of the actual memory module. In a virtual memory system, the physical address space also involves mechanisms such as memory page tables, and the memory page table mechanism is used to implement the mapping from the guest physical address to the host physical address.

[0033] In this embodiment, the host operating system 20 corresponds to a root mode and a non-root mode. The root mode is a working mode in which the host operating system 20 has direct access rights to the hardware resources 10, and the non-root mode is a working mode in which the virtualization layer 30 virtualizes the hardware resources 10 and replaces the host operating system 20 to schedule and access the virtualized resources. The access of the virtualization layer 30 to the hardware resources 10 is restricted in the non-root mode. Correspondingly, the host operating system 20 can also be referred to as a guest operating system in the non-root mode.

[0034] In this embodiment, a lightweight, powerful and efficient virtualization layer 30 is inserted between the hardware resources 10 and the host operating system 20. The virtualization layer 30 can be pre-developed and inserted between the hardware resources 10 and the host operating system 20. Among them, the way of inserting the virtualization layer 30 is not limited. For example, after installing the host operating system 20 on a physical machine, the virtualization layer 30 can be inserted when the host operating system 20 is in a normal running state.

[0035] Among them, the virtualization layer 30 has the ability to provide virtual resources, and can at least provide virtual resources corresponding to the resources that the host operating system 20 cannot provide due to unopened or missing system functions in the root mode. That is to say, in the root mode, the resources that the host operating system 20 cannot provide due to unopened or missing system functions can be provided with corresponding virtual resources by the virtualization layer 30, so as to run the corresponding applications. Specifically, the virtualization layer 30 can switch the running host operating system 20 from the root mode to the non-root mode, and provide at least one virtual resource in the non-root mode, and run at least one application on at least one virtual resource. Without reinstalling the operating system, the virtual resource providing function can be flexibly implemented for the running host operating system, solving the problem that the host operating system 20 cannot provide corresponding resources to run corresponding applications due to unopened or missing system functions in the root mode, supporting the running of more applications, and being beneficial to expanding the capabilities of the host operating system. Further, considering the compatibility of the host operating system, to reduce the frequent mode switching of the host operating system, in the non-root mode, not only can corresponding virtual resources be provided for the system functions that the host operating system 20 did not open or was missing in the root mode, but also corresponding virtual resources can be provided for the system functions that the host operating system 20 has opened in the root mode, realizing the support for more functions of the host operating system 20.

[0036] For example, at least one target function implemented in the virtualization layer 30 includes but is not limited to: memory management function, file management function, virtualization function, scheduling optimization function, etc. The memory management function, file management function, scheduling optimization function, etc. here can be functions that the newly extended host operating system originally does not support, or functions that the host operating system originally supports but are not enabled during the installation of the host operating system. Whether it is a newly extended or unenabled function, the memory management function specifically includes but is not limited to: memory page fault management, memory swap management, memory mapping management, etc.; the file management function specifically includes but is not limited to: directory management, permission management, file backup, creation, query, deletion, modification, etc.; the virtualization function includes but is not limited to: virtualization of various elastic resources (such as CPU, GPU, memory, network, etc.); the scheduling and optimization function includes but is not limited to: scheduling of physical computing resource objects and scheduling of various virtualized resources.

[0037] Further, Figure 1b The following shows the overall architecture diagram of the physical machine. Relative to Figure 1b As shown, Figure 1c and Figure 1d show the internal architectures of the physical machine working in the root mode and the non-root mode. Before the mode switch, the host operating system works in the root mode. In this root mode, as Figure 1cAs shown, the internal architecture of a running physical machine from bottom to top is hardware resource 10, host operating system 20, and application layer 40; after mode switching, it operates in non-root mode. In this non-root mode, as Figure 1d shown, the architecture of a running physical machine from bottom to top is hardware resource 10, virtualization layer 30, guest operating system, and application layer 40. Among them, the guest operating system is the name for the host operating system 20 when it operates in non-root mode.

[0038] In the embodiments of the present application, two operating modes, namely root mode and non-root mode, are provided for the running host operating system. A virtualization layer is inserted between the hardware resource and the host operating system, and at least the function of providing virtual resources is implemented in the virtualization layer. The virtualization layer switches the running host operating system from root mode to non-root mode, provides virtual resources in non-root mode, and runs at least the applications that cannot run due to resource shortage in root mode on the virtual resources. Without reinstalling the host operating system, the function of providing virtual resources can be flexibly implemented for the running host operating system, supporting the running of more applications and expanding the capabilities of the host operating system.

[0039] Here it should be noted that from the perspective of program code, the implementation codes such as "the function of providing virtual resources" and "switching from root mode to non-root mode" involved in the embodiments of the present application belong to the virtualization layer 30, and these codes are located under the host operating system; however, from the perspective of the running state, before the mode switching is truly completed, at least part of the program code in the virtualization layer 30 is executed during the running process of the host operating system. In other words, at least part of the program code in the virtualization layer 30 is executed in root mode. Among them, the program code in the virtualization layer 30 executed in root mode at least includes: the program code for switching from root mode to non-root mode, such as the upper half of the switching function mentioned in the following embodiments. Correspondingly, after the mode switching is truly completed, part of the program code will be executed in non-root mode, such as the lower half of the switching function mentioned in the following embodiments. In addition, the program code in the virtualization layer 30 responsible for providing virtual resources also runs in root mode, but this part of the code is run after the switching is completed; the virtualization layer 30 also provides some interface codes, and some of these interface codes run in non-root mode, and some need to switch to root mode to run, depending on the function of the interface codes.

[0040] In an optional embodiment, as Figure 2a shown, the virtualization layer 30 switching the running host operating system from root mode to non-root mode includes three parts:

[0041] S1. Create a memory page table for storing the mapping relationship between the guest physical address in non-root mode and the host physical address in root mode;

[0042] S2. Create an information-bearing object required for mode switching, which is used to synchronize context information between root mode and non-root mode;

[0043] S3. Based on the information-bearing object and the memory page table, switch the running host operating system from root mode to non-root mode.

[0044] The detailed implementation of the above three parts will be described below.

[0045] Step S1: Create a memory page table

[0046] In root mode, the physical address space has host physical addresses, which can be represented by HPA (Host Physical Address). The host physical address is the address of physical memory in physical memory resources; in non-root mode, the physical address space corresponds to a virtual address space, which has guest physical addresses, which can be represented by GPA (Guest Physical Address). The guest physical address is the address of virtual memory in virtual memory resources.

[0047] In this embodiment, the virtualization layer 30 can create a memory page table for storing the mapping relationship between the guest physical address in non-root mode and the host physical address in root mode. The memory page table can be represented by EPT (Extended Page Tables). It should be noted that when initially establishing the memory page table, since the host operating system has not yet run in non-root mode and no memory reclamation or memory swapping operations have been performed, the guest physical address in non-root mode is the same as the host physical address in root mode. Subsequently, with the use of the host operating system in non-root mode, for example, memory reclamation or memory swapping, the guest physical address may no longer be equal to the host physical address, and the memory page table can dynamically maintain the mapping relationship between the guest physical address and the host physical address.

[0048] In an alternative embodiment, as Figure 2b shown, the creation process of the memory page table includes: S11. Establish a page table structure corresponding to the memory page table; S12. Apply for the root page of the memory page table from the physical address space; S13. Generate the entry address of the memory page table based on the host physical address of the root page and add it to the page table structure; S14. Create a multi-level memory page table according to the address range of the physical address space and the page granularity for mapping the guest physical address and the host physical address.

[0049] First, create a page table structure. The function of this page table structure is to store various information related to the memory page table, such as the entry address of the memory page table, the address lock array (Address Lock Array) for operating on the memory page table, and the address of the special Advanced Programmable Interrupt Controller (APIC) page, etc. Among them, the entry address of the memory page table is used to access the memory page table. For example, the entry address can be the starting address of the memory page table. Each entry in the address lock array corresponds to a page table entry and contains a lock flag bit, which is used to indicate whether the entry is locked. In the case of not being locked, the process can access the memory space corresponding to the page table entry. The address of the special APIC page is mainly used to access the special APIC page. After creating the page table structure, a physical page can be applied for from the physical address space provided by the physical storage medium as the root page of the memory page table; the entry address of the memory page table is generated based on the physical host physical address of this root page and added to the page table structure. Among them, according to the type of physical computing resource object and different manufacturers, the form of the entry address of the memory page table is also different. For example, the physical host physical address of the root page can be directly used as the entry address of the memory page table. Another example is that the physical host physical address of the root page plus a set offset or flag bit can be used as the entry address of the memory page table, and this is not limited.

[0050] Among them, the physical address space has an address range. For example, the address range of the physical address space can be 0 - 8G or 0 - 16G, etc. In addition, in this embodiment, in non-root mode, the single page granularity supported by the host operating system can be broken, and the page granularity for address mapping can be set as needed. For example, the page granularity for address mapping can include but is not limited to: 4K (Kilobyte), 2M (Megabyte), or 1G (Gigabyte), etc. In view of this, in an optional embodiment, the virtualization layer 30 can create a multi-level memory page table according to the address range of the physical address space and the page granularity used for mapping the guest physical address and the host physical address. Among them, the multi-level memory page table can be a 2-level memory page table, a 4-level memory page table, or a 5-level memory page table, etc., which is specifically determined according to the address range of the physical address space and the page granularity. For example, for the same address range, the smaller the page granularity, the more levels of memory page tables are required; another example is that for the same page granularity, the larger the address range, the more levels of memory page tables are required.

[0051] Optionally, in this embodiment, the physical address space is divided into a first address space and a second address space. The second address space is larger than the first address space, that is, the address size of the second address space is larger than the address size of the first address space. For example, when the size of the physical address space is 8G, the address range of the physical address space can be divided into 0G - 4G and 4G - 8G. The first address space can be the address space corresponding to 0G - 4G, and the second address space can be the address space above 4G. Another example, if the size of the physical address space is 16G, the physical address space can be divided into 0G - 4G and 4G - 16G. The first address space can be the address space corresponding to 0G - 4G, and the second address space can be the address space above 4G. Based on this, during the process of creating a multi-level memory page table, respective multi-level memory page tables can be created for the first address space and the second address space. Among them, the first address space is mainly used as the memory address space, and the second address space can be used as at least the IO address space. Among them, the memory address space is used to describe the storage location of programs and data in the memory, and the IO address space is used to describe the address range of the I / O devices of the physical machine. For example, the physical address space is usually divided into several different address ranges. The address space with an address range of 0 - 4GB is called the first address space, and the address space with an address range above 4GB is called the second address space. The first address space is usually called "basic memory" or "system memory", which includes the memory used by the host operating system, application programs, and basic hardware drivers, that is, the first address space is mainly used as the memory address space. The second address space is usually called "large memory" or "extended memory". This memory capacity is usually used in devices such as high-performance computers, servers, and workstations to support more complex computing tasks and multitasking. For example, the second address space can be used as at least the IO address space.

[0052] Among them, for the first address space, a first mapping relationship between the guest physical address and the host physical address is formed at the first page granularity, that is, the guest physical address and the host physical address are mapped according to the page size at the first page granularity, and a multi-level memory page table corresponding to the first address space is created according to the first mapping relationship; for the IO address space in the second address space, a second mapping relationship between the guest physical address and the host physical address is formed at the second page granularity, that is, the guest physical address and the host physical address are mapped according to the page size at the second page granularity, and a multi-level memory page table corresponding to the IO address space is created according to the second mapping relationship; the second page granularity is greater than the first page granularity. For example, the first page granularity is 2M, and the second page granularity is 1G. Among them, using the first page granularity (small page granularity) for memory mapping can reduce the internal fragmentation in the memory page, reduce memory waste, and reduce the loss of page table entries in the cache, improving the address translation efficiency; using the second page granularity (large page granularity) for memory mapping can reduce the page table entry data, reduce the levels of the memory page table, reduce the memory management overhead, and improve the performance of the physical computing resource object.

[0053] Further optionally, the second address space can also be used as a memory address space. Based on this, the virtualization layer 30 can also form a third mapping relationship between the guest physical address and the host physical address at the third page granularity for the memory address space in the second address space, that is, the guest physical address and the host physical address are mapped according to the page size at the third page granularity, and a multi-level memory page table corresponding to the memory address space is created according to the third mapping relationship; among them, the third page granularity is smaller than the second page granularity, but the size of the third page granularity is not limited.

[0054] In an optional embodiment, the third page granularity can be equal to the first page granularity. For example, both the first page granularity and the third page granularity are 2M. That is to say, for the memory address space, a smaller page granularity can be used for address space mapping, and for the IO address space, a larger page granularity can be used for address space mapping, which can reasonably utilize the physical address space and improve the performance of memory management.

[0055] Further optionally, in some application scenarios, the memory address space in the second address space includes an APIC page, and the APIC page uses a smaller page granularity, such as the fourth page granularity, and the third page granularity is greater than the fourth page granularity. For example, the third page granularity is 2M, and the fourth page granularity is 4K.

[0056] In the case where the memory address space in the second address space contains an APIC page with a fourth page granularity, which means that the APIC page with the fourth page granularity belongs to a certain physical page with a third page granularity. The physical page with the third page granularity to which the APIC page with the fourth page granularity belongs is simply referred to as the first physical page. Then, the first physical page with the third page granularity to which the APIC page belongs and the target memory page table corresponding to the first physical page can be obtained. Among them, the target memory page table corresponding to the first physical page is the last-level page table in the multi-level memory page table, and the page table entries in this page table point to the address space in the first physical page. To adapt to the page granularity of the APIC page, the first physical page can be split into multiple sub-pages with the fourth page granularity, and the next-level memory page table can be further extended under the target memory page table, that is, the next-level memory page table is added under the target memory page table. The next-level memory page table is used to store the host physical addresses of the split multiple sub-pages. For example, the host physical address corresponding to a sub-page is stored in each page table entry of the next-level memory page table, and the host physical address is the start address of the sub-page.

[0057] In this embodiment, when creating a memory page table, a hybrid mapping granularity method combining the first page granularity, the second page granularity, the third page granularity, and the fourth page granularity is adopted, which not only supports small page granularity but also large page granularity, can meet the requirements of different physical page mappings, and improves the flexibility of memory mapping.

[0058] Furthermore, in the non-root mode provided by the embodiments of the present application, when creating a memory page table, the physical address space of the host is no longer limited, and it is allowed to create a memory page table for the full physical address space, that is, support full physical memory mapping. Therefore, a memory page table can be created for both user-mode pages and kernel-mode pages. By supporting the memory mapping of the full physical address space, a basic framework is provided for various subsequent operations based on memory mapping. For example, when performing memory swapping based on memory mapping, it not only supports the swapping of user-mode pages but also the swapping of kernel-mode pages, that is, supports full physical memory swapping.

[0059] In this embodiment, taking the first page granularity as 2M, the second page granularity as 1G, the third page granularity as 2M, the fourth page granularity as 4K, and the multi-level memory page table implemented as a four-level memory page table as an example, the specific process of creating a memory page table is exemplarily described.

[0060] The following gives an example of a four - level memory page table. The four - level memory page table includes: Page Global Directory (PGD), Page Upper Directory (PUD), Page Middle Directory (PMD), and Page Table Entry (PTE). Among them, PGD is the highest - level directory. PGD includes multiple global page directory entries pgd_t, and each pgd_t can map a host physical address (HPA) of 512G in size. pgd_t points to the next - level page directory (PUD); PUD includes multiple upper - level page directory entries pud_t, and each pud_t can map a host physical address (HPA) of 1G in size. pud_t points to the next - level page directory (PMD); PMD includes multiple middle - level page directory entries pmd_t, and each pmd_t can map a host physical address (HPA) of 2M in size. pmd_t points to the next - level page directory (PTE). PTE includes multiple direct - level page directory entries pte_t, and each pmd_t can map a host physical address (HPA) of 4K in size. Each pte_t points to the corresponding physical page in the host physical address (HPA).

[0061] 1) For the first address space with an address range of 0G - 4G, a first mapping relationship between the guest physical address and the host physical address is formed at a page granularity of 2M. A multi - level memory page table corresponding to the first address space is created according to the first mapping relationship.

[0062] a1. According to the guest physical address (GPA) in the first address space, and based on the index value of the PGD corresponding to the guest physical address (GPA), determine the page table entry pgd_t in the PGD - level page table. This pgd_t points to the PUD - level page table.

[0063] b1. According to the flag bit in pgd_t, determine whether the PUD - level page table exists. If it does not exist, apply for a page as the PUD - level page table.

[0064] c1. If the PUD - level page table exists, then according to the first page granularity (e.g., 2M), determine whether the PUD - level page table needs to be extended. Since each pud_t can map a host physical address (HPA) of 1G in size, and 1G is greater than the first page granularity (e.g., 2M), it is determined that the next - level PMD - level page table needs to be extended to prepare for subsequent mapping.

[0065] d1. According to the index value of the PUD corresponding to the guest physical address (GPA), determine the page table entry pud_t in the PUD - level page table. This pud_t points to the PMD - level page table.

[0066] e1. Determine whether the next-level PMD-level page table exists according to the flag bit in the pud_t. If it does not exist, apply for a page as the PMD-level page table.

[0067] f1. Determine whether the PMD-level page table needs to be extended according to the first page granularity (e.g., 2M). Since each pmd_t can map a 2M-sized host physical address (HPA), it is determined that there is no need to extend the next-level PTE-level page table.

[0068] g1. Determine the page table entry pmd_t in the PMD-level page table according to the index value of the PMD corresponding to the guest physical address (GPA).

[0069] h1. In the case where the mapped page granularity is 2m, directly establish the page table entry pmd_t in the PMD-level page table. The pmd_t points to the physical page of the host physical address (HPA), and the size of the physical page is 2M. Therefore, it is necessary to combine the page table entry pmd_t of the PMD-level page table. The pmd_t can include the physical page frame number (Page Frame Number, PFN) corresponding to the corresponding HPA, set the page table entry to be accessible, and set the large page flag bit to 1. For example, a large page can be a physical page with a size of 2M or 1G, etc. A physical page with a size of 4K does not belong to a large page.

[0070] i1. Fill the combined page table entry pmd_t of the PMD-level page table into the PMD-level page table, complete a mapping of the first page granularity (e.g., 2M), and record the mapping completion progress and the next guest physical address to be mapped until a mapping of the first page granularity is established for the first address space.

[0071] j1. Determine whether the mapping of the first page granularity (e.g., 2M) is completed. If not, go back to step b; otherwise, end.

[0072] 2) For the input / output (IO) address space in the second address space, a second mapping relationship between the guest physical address and the host physical address is formed at the second page granularity, and a multi-level memory page table corresponding to the IO address space is created according to the second mapping relationship. That is, according to the address space (i.e., physical memory space and physical IO space) of the host operating system recorded in the IO memory resource (iomem_resource), a multi-level memory page table with a second page granularity (e.g., 1G granularity) is established for the IO address space (such as the memory address space above 4G) in the second address space. Among them, the process of establishing the multi-level memory page table is similar to the above-mentioned implementation manner of establishing the multi-level memory page table at the first page granularity, the difference is that: to establish a multi-level memory page table with a second page granularity (e.g., 1G granularity), it is necessary to establish a pud_t in the PUD-level page table, and pud_t points to the physical page of the host physical address (HPA), and the size of the physical page is 1G.

[0073] 3) For the memory address space in the second address space, a third mapping relationship between the guest physical address and the host physical address is formed at the third page granularity (e.g., 2M), and a multi-level memory page table corresponding to the memory address space is created according to the third mapping relationship; among them, the third page granularity is smaller than the second page granularity. Among them, the process of establishing the multi-level memory page table can refer to the above-mentioned implementation manner of establishing the multi-level memory page table at the first page granularity, and will not be elaborated here.

[0074] 4) When the memory address space contains an APIC page with a fourth page granularity, obtain the first physical page of the third page granularity to which the APIC page belongs and the target memory page table corresponding to the first physical page; split the first physical page into multiple sub-pages with the fourth page granularity, and add a next-level memory page table under the target memory page table, and the next-level memory page table is used to store the host physical addresses of the split multiple sub-pages.

[0075] 5) Apply for a special APIC page, and the physical address of the APIC page is the guest physical address.

[0076] 6) Establish a mapping between the host physical address of the APIC and the fourth page granularity (e.g., 4k granularity) of this special APIC page. The default host physical base address (APIC_DEFAULT_PHYS_BASE) of the APIC is (0xfee00000), and this physical address corresponds to the memory address space in the second memory space. In this process, the splitting of the already established third page granularity (e.g., 2M granularity) page is involved, and the mapping process is as follows:

[0077] a2. Sequentially execute steps a1 - e1 in step 1). According to the fourth page granularity (e.g., 4K), determine whether the PMD - level page table needs to be extended. Since each pmd_t can map a 2M - sized host physical address (HPA), and 2M is not equal to 4K, it is determined that the next - level PTE - level page table needs to be extended.

[0078] b2. According to the index value of the PTE corresponding to the guest physical address (GPA), determine the page - table entry pte_t in the PTE - level page table, combine the content of pte_t, including the physical page - frame number corresponding to the HPA, and set this page - table entry to be accessible. At this time, the large - page flag bit is not set to 1.

[0079] c2. Fill the content of the page - table entry of the combined PTE - level page table into the corresponding pte_t to complete this mapping.

[0080] S2. Create an information-carrying object required for mode switching

[0081] In this embodiment, in order to perform mode switching for the host operating system, on the one hand, for any physical computing resource object 101, create a physical descriptor structure, such as Figure 2c step S21 in. In some subsequent descriptions, the physical descriptor structure can be abbreviated as pcpu. This physical descriptor structure is used to save the context information of any physical computing resource object running in the root mode during mode switching. The context information of any physical computing resource object in the root mode may include, but is not limited to: the values of various registers used by any physical computing resource object, the state information of any physical computing resource object, the state information of the host, and relevant configuration information, etc. Among them, the relevant configuration information includes, but is not limited to: the frequency of the high - voltage (hv) timer, etc.

[0082] In this embodiment, the implementation manner of the physical descriptor structure is not limited. Any implementation structure that can save the context information of the physical computing resource object running in the root mode is applicable to the embodiments of this application. In an alternative embodiment, the physical descriptor structure may include, but is not limited to, the following parts or fields: the first register structure (regs), the field carrying the state information of the physical computing resource object, the field carrying the state information of the host, and the field carrying the configuration information. The first register structure may include, but is not limited to: the general - purpose register field, the debug register field, the stack - related register field, the floating - point (Floating Point Unit, fpu) register field, the model - specific register (Model - Specific Register, MSR) field, etc.

[0083] To perform mode switching for the host operating system, on the other hand, for any physical computing resource object, a virtualization descriptor structure is created, such as Figure 2c in step S22 of. In the subsequent description, the virtualization descriptor structure can be abbreviated as vcpu. The virtualization descriptor structure is used to synchronize the context information in the physical descriptor structure during mode switching. The virtualization descriptor structure represents a virtual computing resource object obtained by virtualizing the physical computing resource object.

[0084] Among them, the implementation manner of the virtualization descriptor structure is not limited, and any implementation structure that can synchronize the context information in the physical computing resource object is applicable to the embodiments of the present application. In an optional embodiment, the vcpu may include, but is not limited to, the following fields: a second register structure (regs) corresponding to the first register structure. In addition, the vcpu further includes: a field carrying the virtual computing resource object identification instruction (such as, cpu_id), a field carrying the interrupt vector number (apic_id), a field carrying the running state of the vcpu, a field carrying the switching flag of the state change during the vcpu switching process, a field carrying the relevant configuration information of the APIC register, a field carrying the configuration information of the specific model register (such as, the MSR register), a field carrying the configuration information of the processor opcode (such as, CPUID), a field carrying the descriptor of the interrupt (ProgramInterruption, PI), and a field carrying the relevant configuration information of the exit event, etc.

[0085] Further, to perform mode switching for the host operating system, for any physical computing resource object, a virtualization control structure is created, such as Figure 2cStep S23 in []. For example, the virtualization control structure can be implemented as a vmcs (Virtual Machine Control System), which is used to save the running state information and running control information of any physical computing resource object in non-root mode. For example, the running state information of a physical computing resource object in non-root mode can be the values of some registers and the state of the physical computing resource object, such as active, halted (HLT), or shutdown states. The running control information mainly refers to the control information for the host operating system in non-root mode. For example, the running control information saved in the virtualization control structure can include but is not limited to the following fields: a field for carrying the exit event of non-root mode, a field for carrying the bitmap of specific processor model registers (msr_bitmap), a field for carrying APIC virtualization, a field for carrying interrupt virtualization, a field for carrying a preemptive timer, a field for carrying clock configuration, or a field for carrying IO control information, etc. The information in the corresponding fields can be configured as needed when initializing the virtualization control structure according to the actual situation.

[0086] In an alternative embodiment, the virtualization layer 30 can also create an IO bitmap (io_bitmap), as Figure 2c in Step S24 in []. The IO bitmap is used to record the access permissions of any physical computing resource object to each IO port in non-root mode, and the access permissions are related to the IO control information in the running control information. Among them, the access permissions can default to 0, that is, all IO ports are allowed to be accessed. Subsequently, if it is necessary to intercept some IOs, the io_bitmap can be configured as needed.

[0087] Furthermore, the virtualization layer 30 can also create a new stack. For the convenience of description and distinction, this new stack is called the first stack, as Figure 2c in Step S25 in []. The new stack (i.e., the first stack) is relative to the old stack. For the convenience of description and distinction, the old stack is called the second stack. The old stack (i.e., the second stack) is the stack currently used by any physical computing resource object. After switching from root mode to non-root mode, any physical computing resource object will continue to use the old stack to run in non-root mode. Here, it should be noted that after switching from root mode to non-root mode, the physical computing resource object can be implemented as a virtual physical computing resource object. For example, a physical CPU can be implemented as a virtual CPU. The first stack is a stack prepared for the virtualization layer 30 and is used for the virtualization layer 30 to access memory based on the new stack (i.e., the first stack) in root mode.

[0088] In an alternative embodiment, the virtualization layer 30 can also initialize the virtualization descriptor structure and the virtualization control structure respectively, as Figure 2cStep S26 in []. The initialization process is a process of enabling required functions, applying memory pages for required functions, and configuring initial values. Among them, the initialization process of the virtualization descriptor structure may be to add initialization information corresponding to the functions to be enabled to the corresponding fields of the virtualization descriptor structure. The initialization process of the virtualization control structure may be to add initialization information corresponding to the functions to be enabled to the corresponding fields of the virtualization control structure.

[0089] Optionally, the virtualization layer 30 may configure, in the virtualization control structure, the operation control information of any physical computing resource object when running in the non-root mode. For example, the operation control information may include, but is not limited to, at least one of MSR control information, PI control information, APIC control information, hardware register operation instruction information, the entry address of the memory page table, and relevant configuration information for exiting the non-root mode.

[0090] Further optionally, when configuring the operation control information, the virtualization layer 30 is specifically used to perform at least one of the following configuration operations:

[0091] a3. Establish a specific model register bitmap (such as, msr_bitmap), and allocate a second physical page to save the bitmap;

[0092] b3. Set the PI interrupt function and set the PI notification vector;

[0093] c3. Set the APIC interrupt control function, allocate a third physical page from the physical address space to save the APIC table, and save the base address of the page where the APIC table is located in the APIC field; in addition, it is also necessary to set the APIC_ID to the apic_id of the current physical computing resource object (such as, CPU), and the APIC Local Vector Register (APIC_LVR) inherits the settings of the current physical computing resource object (such as, CPU); if the apic timer is intercepted, the configuration and processing function of the timer can also be configured;

[0094] d3. Set the processor opcode (such as, CPUID), and establish a cache for the virtual computing resource object;

[0095] e3. Set the PAUSE-Loop Exiting (PLE), and the PLE configuration is used to reduce the waste of virtual computing resources caused by loop waiting.

[0096] f3. Save the entry address of the multi-level memory page generated in step S1 in the virtualization control structure, and at the same time, it is also necessary to set the position of the RIP instruction executed after exiting the non-root mode;

[0097] g3, Configuration of general registers in the default root mode and non-root mode.

[0098] Among them, the process of initializing each virtualization descriptor structure and virtualization control structure is as follows:

[0099] 1) Load each virtualization descriptor structure (vcpu) in sequence, and perform initialization settings on each vcpu structure;

[0100] 2) Load the virtualization control structure (vmcs) corresponding to the vcpu as the current vmcs;

[0101] 3) Configure the running control information for the current vmcs, that is, execute the above steps a3 to g3;

[0102] 4) Clear the current vmcs structure;

[0103] 5) Determine whether the vcpus to be initialized are all initialized. If not, repeat steps 1) to 4); if all are initialized, end the initialization.

[0104] In summary, for the host operating system to perform mode switching, it involves the switching from physical computing resource objects to virtual computing resource objects, and also involves the synchronization of context information, access control of IO operations, and switching of memory access. Therefore, create a physical descriptor structure corresponding to the physical computing resource object and a virtualization descriptor structure corresponding to the virtual computing resource object to be responsible for the synchronization of context information during the mode switching process, and create an IO bitmap to facilitate the access control of IO operations during the mode switching process, and create a first stack to facilitate the switching of memory access by the virtualization layer 30 during the mode switching process.

[0105] Among them, after creating the memory page table and various information-bearing objects, it means that the foundation for mode switching is ready. On this basis, based on the information-bearing objects and the memory page table, the running host operating system can be switched from the root mode to the non-root mode.

[0106] S3. Based on the information-carrying object and the memory page table, switch the running host operating system from root mode to non-root mode

[0107] In this embodiment, mode switching can be performed for any physical computing resource object, and the process of mode switching for each physical computing resource object is the same. For the convenience of description and distinction, the following takes the mode switching for the target physical computing resource object as an example for illustration, and the target physical computing resource object can be any physical computing resource object.

[0108] Such as Figure 2dAs shown in the figure, the process of performing mode switching on a target physical computing resource object includes: Step S31: When performing mode switching on the target physical computing resource object, save the context information of the target physical computing resource object in the root mode to the physical descriptor structure corresponding to the target physical computing resource object. Step S32: Synchronize the values of each register and the configuration information of the segment register in the context information in the physical descriptor structure to the virtualization descriptor structure and the virtualization control structure corresponding to the target physical computing resource object, respectively. Step S33: Control the target physical computing resource object to run according to the virtualization descriptor structure, the virtualization control structure, and the memory page table, so as to switch the running host operating system from the root mode to the non-root mode.

[0109] For example, synchronize the values of each register in the context information in the physical descriptor structure to the virtualization descriptor structure corresponding to the target physical computing resource object, and synchronize the configuration information of the segment register in the context information in the physical descriptor structure to the virtualization control structure corresponding to the target physical computing resource object. Among them, the configuration information of the segment register may include, but is not limited to: the size of the segment, the starting address of the segment, and the management attributes of the segment. For example, the management attributes of the segment include: prohibit writing, prohibit execution, or system-specific, etc.

[0110] In this embodiment, Step S1 and Step S2 can be executed when the virtualization layer 30 is started or initialized, and Step S3 can be executed on demand according to dynamic requirements (external instructions). Among them, whether to perform mode switching on the target physical computing resource object can be determined by external instructions.

[0111] In an alternative embodiment, the host operating system 20 of this embodiment provides a Symmetrical Multi-Processing (SMP) call interface externally, allowing an external party to send an SMP call request for any physical computing resource object on the physical machine, and this SMP call request is used to indicate that mode switching needs to be performed on this any physical computing resource object. For the convenience of distinction and description, an example of an external party sending an SMP call request for the target physical computing resource object is used for illustration. For example, an upper-layer application running on the host operating system 20 can initiate an SMP call request to the target physical computing resource object, or a developer can initiate an SMP call request to the target physical computing resource object through the host operating system 20.

[0112] When the target physical computing resource object receives an SMP call request, it can initiate a call request to the switching function to trigger mode switching. Correspondingly, the virtualization layer 30 provides a switching function (such as the switch_vcpu function) for the host operating system to perform mode switching, which is used for the target physical computing resource object to run the switching function to switch the host operating system from the root mode to the non-root mode. Specifically, it refers to the operation of saving the context information of the target physical computing resource object in the root mode to the physical descriptor structure corresponding to the target physical computing resource object and subsequent operations (such as steps S32 and S33) to perform mode switching on the physical computing resource object. After entering the non-root mode, the virtualization layer 30 can also control the target physical computing resource object to exit from the non-root mode to the root mode when an exit event configured in the virtualization control structure occurs.

[0113] In an optional embodiment, during the mode switching process, before saving the context information, it can be determined whether the status of the switching flag corresponding to the target physical computing resource object is the to-be-switched status; if the determination result is yes, the switching flag is updated to the switching status. For example, the target physical computing resource object can obtain the status of the switching flag. If the status of the switching flag is the non-switched status (such as VMX_OFF), the switching flag is updated to the switching status (such as VMX_SWITCH); if the status of the switching flag is the switched status (such as VMX_ON), the SMP call is directly returned without performing mode switching. Optionally, based on returning the SMP call, some other cleanup work can be done. The virtualization layer 30 can also configure the first instruction after the first entry into the non-root mode, and this first instruction is the entry address of the switching function.

[0114] Among them, the switching function is divided into an upper part and a lower part. For example, the switching function can be entered through a function entry such as switch_vcpu. Among them, as the host operating system switches between different modes, the code paths after entering the switching function at different times will be different. For the first switch from the root mode to the non-root mode, an SMP call can be initiated to the target physical computing resource object. This call is used to trigger the mode switch. First, the status of the switching flag is detected. In the case of determining that it is in the to-be-switched state, the mode switch is triggered and the upper part of the switching function is entered. In the upper part, the switching flag is first set to the switching state (e.g., VMX_SWITCH), and the first instruction to be executed after entering the non-root mode, that is, the entry address of the switching function, is set. Thereafter, in the upper part of the switching function, the operation of switching the host operating system from the root mode to the non-root mode is performed. After the target physical computing resource object enters the non-root mode, the above-set first instruction is executed. The first instruction is to execute the switching function. At this time, the flag bit has been set to the switching state, so the lower part of the switching function is entered. In the lower part of the switching function, the switch is completed and the SMP call is returned.

[0115] Optionally, for the convenience of distinction and description, the stack currently used by the target physical computing resource object (i.e., the stack used before switching to the non-root mode) is referred to as the second stack. When the virtualization layer 30 saves the context information of the target physical computing resource object in the root mode to the physical descriptor structure corresponding to the target physical computing resource object, it is specifically used for: saving the values of each register in the context information and the top and bottom addresses of the second stack to the physical descriptor structure. For example, the values of each register in the context information can be saved to the physical descriptor structure. Specifically, the control register, segment register, and general-purpose register can be saved to the register structure in the physical descriptor structure, and the top and bottom addresses of the second stack are saved to the stack corresponding fields of the host register of the physical descriptor structure (pcpu), which will be used during subsequent mode switching.

[0116] The virtualization layer 30 can also switch the currently used second stack of the target physical computing resource object to the newly created first stack for the virtualization layer 30 to continue running based on the first stack in the root mode.

[0117] Further optionally, when the virtualization layer 30 controls the operation of the target physical computing resource object according to the virtualization descriptor structure, the virtualization control structure, and the memory page table, it is specifically used for: loading the values of the special registers in the virtualization control structure and the virtualization descriptor structure. The special registers are a set of registers with specific functions, having special purposes, and can be accessed and used by specific instructions or hardware modules. For example, PI register, Debug Register (DR) register, MSR register, or segment register, etc. Further, it can also save the segment registers of the pcpu and load the values of the segment registers in the vcpu. Inject the operation control information in the virtualization control structure into the target physical computing resource object, and load the values of the general registers in the virtualization descriptor structure. The general registers are a set of registers that can be used by developers, used to store general information such as data and addresses. The general registers can be accessed and used by any instruction in the program. For example, pointer register or index register, etc. Among them, loading the values of the corresponding registers means loading the values of the registers stored in the vcpu to the specific hardware registers, so that the target physical computing resource object can operate in non-root mode. Execute the mode switch instruction to control the target physical computing resource object to enter the non-root mode and start running from the first instruction, and perform memory management and access based on the memory page table during the running process.

[0118] Further optionally, after switching the running host operating system from the root mode to the non-root mode, the virtualization layer 30 can also restore the second stack to the stack top and stack bottom addresses saved in the physical descriptor structure, and update the switch flag to the switch completion state (e.g., VMX_ON). Among them, after switching from the root mode to the non-root mode, restoring the second stack (i.e., the old stack) to the stack top and stack bottom addresses saved in the physical descriptor structure facilitates the target physical computing resource object to continue running based on the second stack in the non-root mode.

[0119] The following describes the process of switching the host operating system of the running target physical computing resource object from the root mode to the non-root mode.

[0120] 1) Externally send an SMP call request to the target physical computing resource object that needs to be switched. This call will trigger the switching of the cpu mode, and here the switching of the cpu mode is the switching from the root mode to the non-root mode;

[0121] 2) The virtualization layer 30 receives the SMP call request and determines the status of the switch flag corresponding to the current target physical computing resource object. If the status of the switch flag is the switch completion state (VMX_ON), it directly returns the SMP call; if the status of the switch flag is the unswitched state (VMX_OFF), it triggers the mode switch and enters step 3.

[0122] 3) The virtualization layer 30 enters the switching function through a function entry such as switch_vcpu. The switching function is divided into an upper half and a lower half. Depending on whether it is the first mode switch, different code paths of the switching function can be entered. When it is the first mode switch, it enters the upper half, and when it is not the first mode switch, it enters the lower half.

[0123] 4) For the first time entering the switching function, the target physical computing resource object is in the unswitched root mode and enters the upper half of the switching function. In the upper half, first set the switching flag to the switching state (e.g., VMX_SWITCH);

[0124] 5) Set the first instruction to be executed after entering the non-root mode. Similar to the first instruction in the above text, this first instruction is still the entry address of the switching function, but at this time the switching flag is in the switching state, and it will enter the lower half of the switching function.

[0125] 6) Save the values of the registers regs of the current target physical computing resource object, including: saving registers such as KERNEL_GDTR_BASE, SYSENTER_ESP, SREG_TR_BASE, SREG_GDTR_BASE, SREG_LDTR_SEL, REGS_CR4 on the host, saving the entry address of the memory page table to the REGS_CR3 register, saving segment registers such as the Data Segment Register (DS), Extra Segment Register (ES), Extra Segment Register (FS), Extra Segment Register (GS), and saving the FPU registers. Then the virtualization layer 30 can directly read the values of the current general registers using a section of assembly. For example, the general registers can include but are not limited to: rax (accumulator), rbx (base register), rdx (data register), rsi (register used as a source operand), rdi (register used as a destination operand), rbp (register storing the stack bottom pointer), r8 - r9 (registers storing function parameters), r9 - r15 (caller-saved registers).

[0126] Among them, KERNEL_GDTR_BASE is a macro commonly used to describe the base address of the Global Descriptor Table Register (GDTR) of the operating system kernel. SYSENTER_ESP stores the base address of the Task State Segment (TSS) descriptor that can be obtained in the kernel. SREG_TR_BASE is usually used to obtain the descriptor of the currently executing task. This descriptor can be used to obtain the memory addresses of the code and data of the current task, as well as the status information of the task. SREG_GDTR_BASE is usually used to obtain the base address of the Global Descriptor Table Register. This base address can be used to obtain the address of the descriptor table, thereby accessing and controlling the attributes of each segment in the system. SREG_LDTR_SEL is usually used to obtain the selector of the Local Descriptor Table Register. This selector can be used to select a specific descriptor, thereby accessing and controlling the attributes of each segment in the current task. REGS_CR4 is usually used to obtain the value of the CR4 (Control Register) register. This value can be used to query or modify some characteristics and behaviors of the processor.

[0127] 7) Save the stack top and stack bottom addresses of the second stack where the target physical computing resource object is currently running to the corresponding stack fields of the host register of the pcpu, which will be used during subsequent mode switching.

[0128] 8) Switch to the new stack created by the virtual descriptor structure (vcpu), that is, the first stack, so that the virtualization layer 30 can run based on this new stack in the root mode.

[0129] 9) Prepare the registers required for vcpu switching, including the following operations:

[0130] a4. First, load the virtualization control structure (vmcs) corresponding to this vcpu;

[0131] b4. Then associate the virtual descriptor structure (vcpu) with the current physical descriptor structure (pcpu);

[0132] c4. Convert the value of regs in the previously saved pcpu to regs in the vcpu, and load the configurations of various segment registers into the vmcs so that after entering the non-root mode, the previous instructions can continue to run;

[0133] d4. Complete the register preparation of the vcpu and clean the selected vmcs;

[0134] 10) Start executing the vcpu switch and enter the non-root mode. It is explained here that the vcpu switch is executed by the virtualization layer 30, and when entering the non-root mode for the first time, the virtualization layer 30 will continue to execute a logic of infinite loop operation, for example: while (1) {vcpu_run (vcpu);}, indicating that it is in the loop of executing the vcpu operation, so that the switching function is completed, and the normal vcpu operation logic is directly executed when entering the non-root mode later; the switching process specifically includes:

[0135] a5. Prepare to enter non-root mode and load the corresponding vmcs;

[0136] b5, load the PI register, DR register or MSR register of the vcpu, save the GS register of the current pcpu, and load the GS register of the vcpu at the same time;

[0137] c5. Enter the loop operation of non-root mode, including the following operations:

[0138] i. The entry will first set the interrupt to be injected, synchronize the PI interrupt, and set the preemption timer;

[0139] ii. Set the vcpu control field (in_guest=1);

[0140] iii. Load the previously saved general registers;

[0141] iv. Enter non-root mode by opening the (VMLAUNCH) command; here, it is noted that when actually switching modes for the first time, you can jump directly to step 11 from here;

[0142] 11) At this time, the target physical computing resource object has entered the non-root mode and executed the first instruction after the non-root mode. In step 5), it is set to execute the switching function (switch_vcpu). At this time, the switching mark is in the switching state and will enter the lower half of the switching function. The purpose is to complete the SMP call process of initiating the switching vcpu to avoid other physical computing resource objects that issue SMP calls from waiting for the switching to be completed.

[0143] Among them, the following operations can be performed in the lower half of the switching function:

[0144] i. Restore the second stack (i.e., the old stack) to the stack value last saved in the host register of the pcpu; the purpose of this is to allow the target physical computing resource object to continue to run in non-root mode by relying on the restored old stack;

[0145] ii. Set the switch mark to the switch completion state (VMX_ON);

[0146] iii. The switch is completed and the SMP call returns.

[0147] 12) After the SMP call returns, the target physical computing resource object can keep running in the non-root mode. When an exit event is triggered, an exit operation will be executed. This exit operation is a relatively independent operation and will only be executed when triggered. The specific operations include the following:

[0148] i. At the time of exit, the general registers will also be saved to the corresponding fields of the vcpu;

[0149] ii. Set the exit execution flag (e.g., vmx_return) for the place to resume execution after exiting to the root mode;

[0150] iii. Reset the control fields (e.g., in_guest = 0) and set the startup fields (e.g., launched = 1) after exiting the non-root mode;

[0151] iv. Process the exit event. If it can be processed, directly call the preset processing function; otherwise, perform a jump outside the loop for processing;

[0152] v. If exiting from the loop, the GS register of the vcpu will be saved, then the GS register of the pcpu will be restored, and at the same time, the PI register, DR register, MSR register, etc. of the current vcpu will be saved;

[0153] vi. Clear the selected vmcs and set the startup field (e.g., launched = 0);

[0154] Here it is noted that the operations before entering the non-root mode are completed by the virtualization layer 30 running in the root mode; after entering the non-root mode, the normal running logic of the vcpu is executed. A complete mode switch logic includes: the process of entering the non-root mode, the vcpu running, and the vcpu exiting back to the root mode. Among them, the operations of entering the non-root mode and exiting back to the root mode are also completed by running in the root mode.

[0155] In the embodiments of the present application, it is considered to insert a lightweight virtualization layer between the host operating system and the hardware resources by means of the hardware virtualization function, implement the virtual resource providing function in the virtualization layer, and switch the running host operating system from the root mode to the non-root mode by the virtualization layer, so as to provide at least one virtual resource in the non-root mode and run at least one application on at least one virtual resource. The at least one application includes at least the application that cannot run due to insufficient resources in the root mode of the host operating system. Without reinstalling the host operating system, the virtual resource providing function can be flexibly implemented for the running host operating system, solve the problem that the application cannot run due to insufficient resources caused by the non-opening or lack of relevant system functions in the root mode of the host operating system, enable the host operating system to support the running of more applications, and is beneficial to expanding the capabilities of the host operating system. Among them, after the host operating system is switched from the root mode to the non-root mode, the at least one application that can run on the virtual resources provided in the non-root mode includes but is not limited to: performing target functions such as memory management, file management, virtualization function, and scheduling optimization in the non-root mode.

[0156] In the following embodiments, taking the memory page fault management in memory management as an example, the memory page fault management process in the non-root mode will be described in detail. It should be noted here that an application scenario of the memory page fault is memory swap, that is, a memory page fault may occur during the memory swap process, but the memory page fault is not only used for the memory swap process. To facilitate reflecting the advantages of the memory page fault management implemented in the non-root mode in the embodiments of the present application, taking the memory page fault used for memory swap as an example for description, and the relevant introduction to the memory swap will be made first.

[0157] The memory swap function in the host operating system (such as the Linux system) is a mechanism that uses free hard disk space as an extension of the memory. When there are insufficient memory pages in the main memory (such as RAM), the swap function can move a part of the infrequently used memory pages to the hard disk to free up space for other pages to use, and this process is called swapout. When the process uses this part of the swapped-out content again, it will trigger swap in.

[0158] The swap function of the host operating system (e.g., Linux system) includes two aspects: swap partition and swap file. The swap partition is used to swap hard disk space and is also called swap space. It is usually allocated when installing the host operating system or can be manually created through commands such as the fdisk command or the mkswap command. After dividing the free disk space into a swap partition, it can be mounted as a swap partition through the swapon command. The advantage of the swap partition is its high speed and stability, but the partition size needs to be planned in advance and cannot be dynamically adjusted. Among them, the fdisk command is used to create, delete, modify, and display disk partitions. The mkswap command is used to create a swap partition. The swapon command is used to enable the swap partition on a physical machine.

[0159] A swap file is a file created on a common file system and can be used as swap space. Create a swap file through commands such as dd and fallocate, then format it as a swap file system using the mkswap command, and finally mount it as swap space through the swapon command. Among them, both the dd command and the fallocate command can be used to create files. The advantage of the swap file is its high flexibility, which can be dynamically resized and is convenient to manage, but its performance is slightly inferior to that of the swap partition.

[0160] In the host operating system (e.g., Linux system), the size of the swap space is usually set to twice or three times the physical memory. If the physical memory is sufficient, the utilization rate of the swap space will be very low and will not have an obvious impact on the performance of the physical machine. If the physical memory is insufficient, the utilization rate of the swap space will be very high and will seriously affect the performance of the physical machine. Therefore, the performance of the swap space is also crucial for the stability of the physical machine's performance.

[0161] In addition, the swap function of the host operating system (e.g., Linux) kernel is for user processes and will not directly affect the swapping in and out of kernel pages. If the memory is insufficient, the kernel will try to reclaim some unnecessary pages and swap them to the disk through the swap function to free up memory space. These unnecessary pages include user process pages, cache pages, anonymous memory pages, etc., but do not include kernel pages because kernel pages are usually not swappable. Kernel code and data are usually locked in memory and will not be swapped to the disk, so they will not be affected by the swap function. Moreover, the swap function currently only supports small 4K pages, while in current cloud computing, there are more and more scenarios using large pages (e.g., 2M or 1G), and the swap function for large pages is not supported yet. If the running operating system is not configured with the swap function, enabling it online can only use the file method, with very low performance and will seriously affect the system's stability.

[0162] Although some system functions missing in the host operating system can be implemented by loading functional modules, it will be invasive and subject to the constraints of various existing structures and function capabilities of the operating system, and may not necessarily solve all problems, such as the swapping of kernel-mode pages mentioned above. In the embodiments of the present application, based on the virtualization layer, switching from the root mode to the non-root mode, providing virtual memory resources in the non-root mode, so that the memory swapping function can be implemented, and it is no longer limited by whether the host operating system enables the memory swapping function; in addition, the solution provided by the embodiments of the present application is more transparent and imperceptible to upper-layer application programs, and can implement more comprehensive functions.

[0163] Furthermore, in the embodiments of the present application, when creating a memory page table, a hybrid mapping granularity method combining a first page granularity, a second page granularity, a third page granularity, and a fourth page granularity is adopted, which not only supports small page granularity but also large page granularity, can meet the requirements of different physical page mappings, and improves the flexibility of memory mapping. Using a small page granularity for memory mapping can reduce internal fragmentation in the memory page and reduce memory waste; using a large page granularity for memory mapping reduces page table entry data, reduces the levels of the memory page table, reduces memory management overhead, and improves the performance of physical computing resource objects.

[0164] Furthermore, in the embodiments of the present application, when creating a memory page table, the physical address space of the host is no longer limited, and it is allowed to create a memory page table for the entire physical address space, that is, support full memory mapping. Therefore, a memory page table can be created for both user-mode pages and kernel-mode pages. By supporting the memory mapping of the entire physical address space, a basic framework is provided for various subsequent operations based on memory mapping. For example, when performing memory swapping based on memory mapping, it not only supports the swapping of user-mode pages but also the swapping of kernel-mode pages, that is, supports full memory swapping. The following briefly describes the process of implementing memory page fault management after switching to the non-root mode:

[0165] 1) The memory page table (such as, ept page table) prepared for the mode switch of the host operating system above, its guest physical address (GPA) and host physical address (HPA) are in one-to-one correspondence. Among them, normal operation in the non-root mode will not trigger a page fault exception. In order to expand the memory management function of the host operating system, some memory pages can be reclaimed by methods such as reclaiming free pages, compressing used pages, swapping memory pages to disk, or expanding new virtual memory space, etc. (the page granularity can be 4K or 2M), and the page table entries of the corresponding memory page table are cleared. In this way, subsequent accesses in the non-root mode can trigger a page fault exception. Currently, a page fault exception can be triggered by directly clearing the memory page table of a batch of free pages.

[0166] 2) Since a batch of memory pages have been cleared and recycled in step 1), a simple memory management system can be used, for example, using status bits for memory management for subsequent page fault exceptions.

[0167] 3) Before handling a page fault exception, a handler can be set in the exit event of the non-root mode. For example, set the page fault handler (ept_handler) for the exit reason EPT page fault association (EXIT_REASON_EPT_VIOLATION).

[0168] 4) In the page fault handler (ept_handler), an unused host physical page can be selected from the underlying memory management system and marked as used.

[0169] 5) Establish a mapping relationship between the physical address (HPA) of the unused host physical page and the guest physical address (GPA) where the page fault occurs, and establish a corresponding page table entry in the corresponding memory page table (such as, the ept page table), so that the host operating system can implement memory management in non-root mode. Here, the memory management includes but is not limited to memory swapping, etc.

[0170] In addition to providing system embodiments, the embodiments of the present application also provide a virtualization processing method. The process of the virtualization processing method provided by the embodiments of the present application will be described below.

[0171] Figure 3 FIG. is a schematic flowchart of a virtualization processing method provided by an exemplary embodiment of the present application. This method is applied to the virtualization layer in a physical machine. The virtualization layer is located between the hardware resources of the physical machine and the host operating system, such as Figure 3 shown, and the method includes:

[0172] 301. Switch the running host operating system from the root mode to the non-root mode;

[0173] 302. In the non-root mode, provide at least one virtual resource, and run at least one application on the at least one virtual resource. The at least one application includes at least the applications that cannot run due to resource shortage in the root mode of the host operating system.

[0174] In an optional embodiment, the hardware resources include at least one physical computing resource object and a physical address space having a host physical address, and the host operating system runs on the physical computing resource object; switching the running host operating system from the root mode to the non-root mode includes: creating a memory page table for storing the mapping relationship between the guest physical address in the non-root mode and the host physical address in the root mode; creating an information carrier object required for mode switching, where the information carrier object is used to synchronize context information between the root mode and the non-root mode; and based on the information carrier object and the memory page table, switching the running host operating system from the root mode to the non-root mode.

[0175] Optionally, creating a memory page table includes: establishing a page table structure corresponding to the memory page table, and applying for a root page of the memory page table from the physical address space; generating an entry address of the memory page table according to the host physical address of the root page and adding it to the page table structure; and creating a multi-level memory page table according to the address range of the physical address space and the page granularity for mapping the guest physical address and the host physical address.

[0176] Further optionally, creating a multi-level memory page table according to the address range of the physical address space and the page granularity for mapping the guest physical address and the host physical address includes: for a first address space, forming a first mapping relationship between the guest physical address and the host physical address with a first page granularity, and creating a multi-level memory page table corresponding to the first address space according to the first mapping relationship; for an input / output (IO) address space in a second address space, forming a second mapping relationship between the guest physical address and the host physical address with a second page granularity, and creating a multi-level memory page table corresponding to the IO address space according to the second mapping relationship; where the second address space is larger than the first address space and the second page granularity is larger than the first page granularity.

[0177] Further optionally, the method provided in the embodiment of the present application further includes: for a memory address space in the second address space, forming a third mapping relationship between the guest physical address and the host physical address with a third page granularity, and creating a multi-level memory page table corresponding to the memory address space according to the third mapping relationship; where the third page granularity is smaller than the second page granularity.

[0178] Further optionally, the method provided by the embodiments of the present application further includes: when the memory address space includes the Advanced Programmable Interrupt Controller (APIC) page with the fourth page granularity, obtaining the first physical page with the third page granularity to which the APIC page belongs and the target memory page table corresponding to the first physical page; the third page granularity is greater than the fourth page granularity; splitting the first physical page into multiple sub-pages with the fourth page granularity, and adding a next-level memory page table under the target memory page table, where the next-level memory page table is used to store the host physical addresses of the split multiple sub-pages.

[0179] In an optional embodiment, creating the information-bearing object required for mode switching includes: for any physical computing resource object, creating a physical descriptor structure, which is used to save the context information of any physical computing resource in the root mode during mode switching; for any physical computing resource object, creating and initializing a virtualization descriptor structure, which is used to synchronize the context information in the physical descriptor structure during mode switching; for any physical computing resource object, creating and initializing a virtualization control structure to save the running state information and running control information of any physical computing resource object in the non-root mode.

[0180] Optionally, the method provided by the embodiments of the present application further includes: creating a first stack and an I / O bitmap, where the first stack is used for the virtualization layer to access memory in the root mode, and the I / O bitmap is used to record the access permissions of any physical computing resource object to each I / O port in the non-root mode, and the access permissions are related to the I / O control information in the running control information.

[0181] Further optionally, based on the information-bearing object and the memory page table, switching the running host operating system from the root mode to the non-root mode includes: when performing mode switching on the target physical computing resource object, saving the context information of the target physical computing resource object in the root mode to the physical descriptor structure corresponding to the target physical computing resource object; synchronizing the values of each register and the configuration information of the segment register in the context information in the physical descriptor structure to the virtualization descriptor structure and the virtualization control structure corresponding to the target physical computing resource object respectively; controlling the operation of the target physical computing resource object according to the virtualization descriptor structure, the virtualization control structure, and the memory page table to switch the running host operating system from the root mode to the non-root mode.

[0182] Further optionally, the method provided by the embodiments of the present application further includes: before saving the context information, determining whether the status of the switching flag corresponding to the target physical computing resource object is the to-be-switched status; in the case where the determination result is yes, updating the switching flag to the switching status, and configuring the first instruction after entering the non-root mode for the first time, where the first instruction points to the entry address of the switching function.

[0183] Further optionally, saving the context information of the target physical computing resource object in the root mode to the physical descriptor structure corresponding to the target physical computing resource object includes: saving the values of each register in the context information and the top and bottom addresses of the second stack to the physical descriptor structure, where the second stack is used for the target physical computing resource object to access memory after switching to the non-root mode; the method provided by the embodiments of the present application further includes: switching the second stack currently used by the target physical computing resource object to the first stack, so that the virtualization layer 30 runs based on the first stack in the root mode.

[0184] Further optionally, controlling the operation of the target physical computing resource object according to the virtualization descriptor structure, the virtualization control structure, and the memory page table includes: loading the values of the dedicated registers in the virtualization control structure and the virtualization descriptor structure; injecting the operation control information in the virtualization control structure into the target physical computing resource object, and loading the values of the general registers in the virtualization descriptor structure; executing a mode switching instruction to control the target physical computing resource object to enter the non-root mode and start running from the first instruction, and performing memory management and access based on the memory page table during the running process.

[0185] Further optionally, the method provided by the embodiments of the present application further includes: restoring the second stack to the top and bottom addresses saved in the physical descriptor structure, and updating the switching flag to the switched status.

[0186] In an optional embodiment, the method provided by the embodiments of the present application further includes: receiving a function call request initiated by the target physical computing resource object to request to call the switching function in the virtualization layer for mode switching, where the target physical computing resource object initiates a function call request to the virtualization layer when receiving an SMP call request sent externally; according to the function call request, running the switching function to perform the operation of saving the context information of the target physical computing resource object in the root mode to the physical descriptor structure corresponding to the target physical computing resource object and subsequent operations, so as to perform mode switching on the physical computing resource object.

[0187] In an optional embodiment, running at least one application on at least one virtual resource provided in the non-root mode includes: controlling the target physical computing resource in the non-root mode to perform at least one of memory page fault management, file management, and memory swapping management.

[0188] Regarding the detailed implementation manners and beneficial effects of each step in the method provided in the embodiments of the present application Figure 3 have been described in detail in the foregoing embodiments, and will not be elaborated herein.

[0189] It should be noted that the execution subject of each step of the method provided in the above embodiments can be the same device, or the method can also be executed by different devices as the execution subject. For example, the execution subject of steps 301 to 302 can be a device; for another example, the execution subject of step 301 can be a device, and the execution subject of step 302 can be device B; and so on.

[0190] In addition, in some processes described in the above embodiments and the accompanying drawings, there are multiple operations that appear in a specific order. However, it should be clearly understood that these operations can be executed not in the order in which they appear in this document or in parallel. The operation numbers such as 301 and 302 are only used to distinguish different operations, and the numbers themselves do not represent any execution order. In addition, these processes can include more or fewer operations, and these operations can be executed in sequence or in parallel. It should be noted that the descriptions such as "first" and "second" in this document are used to distinguish different messages, devices, modules, etc., and do not represent a sequence, nor do they limit that "first" and "second" are different types.

[0191] Figure 4 is a schematic structural diagram of a virtualization processing device provided for an exemplary embodiment of the present application. The device corresponds to the virtualization layer in a physical machine. The virtualization layer is located between the hardware resources of the physical machine and the host operating system, as Figure 4 shown, the device includes: a switching module 41 and an execution module 42.

[0192] The switching module 41 is used to switch the running host operating system from the root mode to the non-root mode;

[0193] The execution module 42 is used to provide at least one virtual resource in the non-root mode and run at least one application on the at least one virtual resource; wherein, the at least one application at least includes the application that cannot run due to insufficient resources in the root mode of the host operating system.

[0194] In an alternative embodiment, the hardware resources include at least one physical computing resource object and a physical address space having a host physical address, and the host operating system runs on the physical computing resource object; the switching module is specifically configured to: create a memory page table for storing the mapping relationship between the guest physical address in the non-root mode and the host physical address in the root mode; create an information carrier object required for mode switching, where the information carrier object is used to synchronize context information between the root mode and the non-root mode; and based on the information carrier object and the memory page table, switch the running host operating system from the root mode to the non-root mode.

[0195] Optionally, the switching module is specifically configured to: establish a page table structure corresponding to the memory page table, and apply for a root page of the memory page table from the physical address space; generate an entry address of the memory page table according to the host physical address of the root page, and add it to the page table structure; and create a multi-level memory page table according to the address range of the physical address space and the page granularity for mapping the guest physical address and the host physical address.

[0196] Further optionally, the switching module is specifically configured to: form a first mapping relationship between the guest physical address and the host physical address with a first page granularity for the first address space, and create a multi-level memory page table corresponding to the first address space according to the first mapping relationship; form a second mapping relationship between the guest physical address and the host physical address with a second page granularity for the input / output (I / O) address space in the second address space, and create a multi-level memory page table corresponding to the I / O address space according to the second mapping relationship; where the second address space is larger than the first address space, and the second page granularity is larger than the first page granularity.

[0197] Further optionally, the apparatus further includes: a forming module and a creating module; the forming module is configured to form a third mapping relationship between the guest physical address and the host physical address with a third page granularity for the memory address space in the second address space, and the creating module is configured to create a multi-level memory page table corresponding to the memory address space according to the third mapping relationship; where the third page granularity is smaller than the second page granularity.

[0198] Further optionally, the apparatus further includes: an obtaining module, a splitting module, and an adding module; the obtaining module is configured to, when the memory address space includes an APIC page with a fourth page granularity, obtain a first physical page with a third page granularity to which the APIC page belongs and a target memory page table corresponding to the first physical page; the third page granularity is larger than the fourth page granularity; the splitting module is configured to split the first physical page into multiple sub-pages with the fourth page granularity, and the adding module is configured to add a next-level memory page table under the target memory page table, where the next-level memory page table is used to store the host physical addresses of the split multiple sub-pages.

[0199] In an optional embodiment, the switching module is specifically configured to: for any physical computing resource object, create a physical descriptor structure for saving the context information of any physical computing resource in the root mode during mode switching; for any physical computing resource object, create and initialize a virtualization descriptor structure for synchronizing the context information in the physical descriptor structure during mode switching; for any physical computing resource object, create and initialize a virtualization control structure for saving the running state information and running control information of any physical computing resource object in the non-root mode.

[0200] In an optional embodiment, the creation module is further configured to: create a first stack and an IO bitmap, where the first stack is used for the virtualization layer to access memory in the root mode, and the IO bitmap is used to record the access permissions of any physical computing resource object to each IO port in the non-root mode, and the access permissions are related to the IO control information in the running control information.

[0201] In an optional embodiment, the switching module is specifically configured to: in the case of performing mode switching on a target physical computing resource object, save the context information of the target physical computing resource object in the root mode to the physical descriptor structure corresponding to the target physical computing resource object; synchronize the values of the registers and the configuration information of the segment registers in the context information in the physical descriptor structure to the virtualization descriptor structure and the virtualization control structure corresponding to the target physical computing resource object respectively; control the target physical computing resource object to run according to the virtualization descriptor structure, the virtualization control structure, and the memory page table, so as to switch the running host operating system from the root mode to the non-root mode.

[0202] Further optionally, the device further includes: a judgment module, an update module, and a configuration module; the judgment module is configured to judge whether the status of the switching flag corresponding to the target physical computing resource object is a to-be-switched status before saving the context information; the update module is configured to update the switching flag to a switching status when the judgment result is yes; the configuration module is configured to configure the first instruction after first entering the non-root mode.

[0203] Further optionally, the switching module is specifically configured to: save the values of the registers in the context information and the top and bottom addresses of the second stack to the physical descriptor structure, where the second stack is the stack currently used by the target physical computing resource object and is also the stack used by the target physical computing resource object after switching to the non-root mode, for the target physical computing resource object to access memory after switching to the non-root mode; the switching module is further configured to: switch the second stack currently used by the target physical computing resource object to the first stack for the virtualization layer to run based on the first stack in the root mode.

[0204] Further optionally, the switching module is specifically configured to: load the values of the special registers in the virtualization control structure and the virtualization descriptor structure; inject the operation control information in the virtualization control structure into the target physical computing resource object, and load the values of the general registers in the virtualization descriptor structure; execute a mode switching instruction to control the target physical computing resource object to enter the non-root mode and start running from the first instruction, and perform memory management and access based on the memory page table during the running process.

[0205] Further optionally, the apparatus further includes: a saving module and an updating module; the saving module is configured to restore the second stack to the addresses of the stack top and the stack bottom saved in the physical descriptor structure, and the updating module is configured to update the switching flag to the switching completed state.

[0206] In an optional embodiment, the apparatus further includes: a receiving module and a processing module; the receiving module is configured to receive a function call request initiated by the target physical computing resource object to request to call a switching function in the virtualization layer for mode switching, where the target physical computing resource object initiates a function call request to the virtualization layer when receiving an SMP call request sent externally; the processing module is configured to run the switching function according to the function call request to perform operations such as saving the context information of the target physical computing resource object in the root mode to the physical descriptor structure corresponding to the target physical computing resource object and subsequent operations to perform mode switching on the physical computing resource object.

[0207] In an optional embodiment, the execution module is specifically configured to: control the target physical computing resource in the non-root mode to perform at least one of memory page fault management, file management, and memory swapping management.

[0208] Regarding the Figure 4 detailed implementation manners and beneficial effects of the steps in the apparatus provided in the embodiments of the present application have been described in detail in the foregoing embodiments, and will not be elaborated herein.

[0209] Correspondingly, the embodiments of the present application further provide a computer-readable storage medium storing a computer program, and when the computer program is executed, it can implement each step executable by an electronic device in the foregoing Figure 3 method embodiments shown.

[0210] The above-mentioned memory can be implemented by any type of volatile or non-volatile storage device, or a combination thereof, such as Static Random-Access Memory (SRAM), Electrically Erasable Programmable Read Only Memory (EEPROM), Erasable Programmable Read Only Memory (EPROM), Programmable Read-Only Memory (PROM), Read-Only Memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.

[0211] The above-mentioned communication component is configured to facilitate communication between the device where the communication component is located and other devices in a wired or wireless manner. The device where the communication component is located can access a wireless network based on a communication standard, such as WiFi, 2G, 3G, 4G / LTE, 5G and other mobile communication networks, or a combination thereof. In an exemplary embodiment, the communication component receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component further includes a Near Field Communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on Radio Frequency Identification (RFID) technology, Infrared Data Association (IrDA) technology, Ultra Wide Band (UWB) technology, Bluetooth (BT) technology and other technologies.

[0212] The above-mentioned display includes a screen, and the screen can include a Liquid Crystal Display (LCD) and a Touch Panel (TP). If the screen includes a touch panel, the screen can be implemented as a touch screen to receive input signals from a user. The touch panel includes one or more touch sensors to sense touches, swipes and gestures on the touch panel. The touch sensors can sense not only the boundaries of touch or swipe actions, but also detect the duration and pressure associated with the touch or swipe operation.

[0213] The above power supply component provides power for various components of the device where the power supply component is located. The power supply component may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power for the device where the power supply component is located.

[0214] The above audio component can be configured to output and / or input audio signals. For example, the audio component includes a microphone (MIC). When the device where the audio component is located is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode, the microphone is configured to receive external audio signals. The received audio signals can be further stored in a memory or transmitted via a communication component. In some embodiments, the audio component further includes a speaker for outputting audio signals.

[0215] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-readable storage media (including but not limited to disk memories, compact disc read-only memories (CD-ROMs), optical memories, etc.) containing computer-usable program code.

[0216] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in one or more flows in the flowchart and / or one or more blocks in the block diagram.

[0217] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that implements the functions specified in one or more flows in the flowchart and / or one or more blocks in the block diagram.

[0218] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one process or multiple processes in the flowchart and / or one block or multiple blocks in the block diagram.

[0219] In a typical configuration, a physical machine includes one or more processors (Central Processing Unit, CPU), input / output interfaces, network interfaces, and memory.

[0220] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent in such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the presence of additional identical elements in the process, method, commodity or device comprising the element.

[0221] The above are only embodiments of the present application and are not used to limit the present application. For those skilled in the art, the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.

Claims

1. A virtualization processing method, characterized in that, Applied to the virtualization layer in a physical machine, the virtualization layer being located between the hardware resources of the physical machine and the host operating system, the method includes: Switch the running host operating system from root mode to non-root mode; In non-root mode, provide at least one virtual resource and run at least one application on the at least one virtual resource; Wherein, the at least one application at least includes the applications that the host operating system cannot run in root mode due to insufficient resources.

2. The method according to claim 1, wherein The hardware resources include at least one physical computing resource object and a physical address space, the physical address space having a host physical address, and the host operating system runs on the physical computing resource object; Switching the running host operating system from root mode to non-root mode includes: Create a memory page table for storing the mapping relationship between the guest physical address in non-root mode and the host physical address in root mode; Create an information-bearing object required for mode switching, the information-bearing object being used to synchronize context information between the root mode and the non-root mode; Based on the information-bearing object and the memory page table, switch the running host operating system from root mode to non-root mode.

3. The method according to claim 2, wherein Creating a memory page table includes: Establish a page table structure corresponding to the memory page table and apply for the root page of the memory page table from the physical address space; Generate the entry address of the memory page table according to the host physical address of the root page and add it to the page table structure; Create a multi-level memory page table according to the address range of the physical address space and the page granularity for mapping the guest physical address and the host physical address.

4. The method according to claim 3, wherein Creating a multi-level memory page table according to the address range of the physical address space and the page granularity for mapping the guest physical address and the host physical address includes: For the first address space, form a first mapping relationship between the guest physical address and the host physical address with a first page granularity, and create a multi-level memory page table corresponding to the first address space according to the first mapping relationship; For the input / output (IO) address space in the second address space, form a second mapping relationship between the guest physical address and the host physical address with a second page granularity, and create a multi-level memory page table corresponding to the IO address space according to the second mapping relationship; Wherein, the second address space is larger than the first address space, and the second page granularity is larger than the first page granularity.

5. The method according to any one of claims 2-4, characterized in that, Creating the information-bearing object required for mode switching includes: For any physical computing resource object, create a physical descriptor structure, the physical descriptor structure being used to save the context information of the any physical computing resource in root mode during mode switching; For any physical computing resource object, create and initialize a virtualization descriptor structure, the virtualization descriptor structure being used to synchronize the context information in the physical descriptor structure during mode switching; For any physical computing resource object, a virtualization control structure is created and initialized to store the running state information and running control information of the any physical computing resource object in non-root mode.

6. The method according to claim 5, wherein The method further includes: Creating a first stack and an I / O bitmap, where the first stack is used for the virtualization layer to access memory in root mode, and the I / O bitmap is used to record the access permissions of the any physical computing resource object to each I / O port in non-root mode, and the access permissions are related to the I / O control information in the running control information.

7. The method according to claim 6, wherein Based on the information carrier object and the memory page table, switching the running host operating system from root mode to non-root mode includes: When performing a mode switch on a target physical computing resource object, saving the context information of the target physical computing resource object in root mode to the physical descriptor structure corresponding to the target physical computing resource object; Synchronizing the values of each register and the configuration information of the segment register in the context information in the physical descriptor structure to the virtualization descriptor structure and the virtualization control structure corresponding to the target physical computing resource object respectively; Controlling the operation of the target physical computing resource object according to the virtualization descriptor structure, the virtualization control structure, and the memory page table to switch the running host operating system from root mode to non-root mode.

8. The method according to claim 7, wherein The method further includes: Before saving the context information, determining whether the status of the switch flag corresponding to the target physical computing resource object is the to-be-switched status; When the determination result is yes, updating the switch flag to the switching status and configuring the first instruction after first entering the non-root mode.

9. The method according to claim 8, characterized in that Saving the context information of the target physical computing resource object in root mode to the physical descriptor structure corresponding to the target physical computing resource object includes: Saving the values of each register in the context information and the top and bottom addresses of the second stack to the physical descriptor structure, where the second stack is used for the target physical computing resource object to access memory after switching to non-root mode; The method further includes: switching the second stack currently used by the target physical computing resource object to the first stack.

10. The method according to claim 9, characterized in that, Controlling the operation of the target physical computing resource object according to the virtualization descriptor structure, the virtualization control structure, and the memory page table includes: Loading the values of the special registers in the virtualization control structure and the virtualization descriptor structure; Injecting the running control information in the virtualization control structure into the target physical computing resource object and loading the values of the general registers in the virtualization descriptor structure; Executing a mode switch instruction to control the target physical computing resource object to enter non-root mode and start running from the first instruction, and performing memory management and access based on the memory page table during the running process.

11. A physical machine, characterized in that, The physical machine includes hardware resources and a host operating system running on the hardware resources, and a virtualization layer is implemented between the hardware resources and the host operating system; The virtualization layer is used to switch the running host operating system from the root mode to the non-root mode, and in the non-root mode, provide at least one virtual resource and run at least one application on the at least one virtual resource, where the at least one application at least includes the applications that cannot run due to insufficient resources in the root mode of the host operating system.

12. The physical machine according to claim 11, wherein The hardware resources include at least one physical computing resource object and a physical address space, the physical address space has a host physical address, and the host operating system runs on the physical computing resource object; The virtualization layer switches the running host operating system from the root mode to the non-root mode, including: Creating a memory page table for storing the mapping relationship between the guest physical address in the non-root mode and the host physical address in the root mode; Creating an information-bearing object required for mode switching, where the information-bearing object is used to synchronize context information between the root mode and the non-root mode; Based on the information-bearing object and the memory page table, switching the running host operating system from the root mode to the non-root mode.

13. The physical machine according to claim 12, wherein The virtualization layer creates a memory page table, including: Establishing a page table structure corresponding to the memory page table and applying for the root page of the memory page table from the physical address space; Generating the entry address of the memory page table according to the host physical address of the root page and adding it to the page table structure; Creating a multi-level memory page table according to the address range of the physical address space and the page granularity for mapping the guest physical address and the host physical address.

14. The physical machine according to claim 12 or 13, characterized in that, The virtualization layer creates an information-bearing object, including: For any physical computing resource object, creating a physical descriptor structure, where the physical descriptor structure is used to save the context information of the any physical computing resource in the root mode during mode switching; For any physical computing resource object, creating and initializing a virtualization descriptor structure, where the virtualization descriptor structure is used to synchronize the context information in the physical descriptor structure during mode switching; For any physical computing resource object, creating and initializing a virtualization control structure for saving the running state information and running control information of the any physical computing resource object in the non-root mode.

15. The physical machine according to claim 14, wherein The virtualization layer is further used for: Creating a first stack and an IO bitmap, where the first stack is used for the virtualization layer to access memory in the root mode, and the IO bitmap is used to record the access permissions of the any physical computing resource object to each IO port in the non-root mode, and the access permissions are related to the IO control information in the running control information.

16. The physical machine according to claim 14, characterized in that, The virtualization layer switches the running host operating system from the root mode to the non-root mode, including: In the case of switching the mode of the target physical computing resource object, saving the context information of the target physical computing resource object in the root mode to the physical descriptor structure corresponding to the target physical computing resource object; Synchronize the values of each register and the configuration information of the segment register in the context information in the physical descriptor structure to the virtualized descriptor structure and the virtualized control structure corresponding to the target physical computing resource object respectively; Control the operation of the target physical computing resource object according to the virtualized descriptor structure, the virtualized control structure, and the memory page table, so as to switch the running host operating system from the root mode to the non-root mode.

17. The physical machine according to claim 16, characterized in that, The virtualization layer is further configured to: Before saving the context information, determine whether the status of the switching flag corresponding to the target physical computing resource object is the to-be-switched status; In the case where the determination result is yes, update the switching flag to the switching status and configure the first instruction after first entering the non-root mode.

18. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, cause the processor to implement the steps in the method according to any one of claims 1-10.