Firmware switching method and device, equipment and storage medium

By performing integrity checksum memory mapping after receiving the firmware upgrade command, and jumping directly to the target firmware, the problem of low firmware switching efficiency is solved and a more efficient firmware switching process is achieved.

CN120276790AActive Publication Date: 2025-07-08INSPUR SUZHOU INTELLIGENT TECH CO LTD

Patent Information

Application Number
CN202510756908.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-07-08
Estimated Expiration
2045-06-06

AI Technical Summary

Technical Problem

The firmware switching efficiency in the prior art is inefficient because it is necessary to switch to the boot program for secondary loading and resource repetitive initialization, resulting in additional overhead.

Method used

After receiving the firmware upgrade command, the integrity of the target firmware is checked and saved to the memory preset address, stop processing the pending commands in the command queue, and remap the firmware start address through the memory management unit after the processing is completed, and jump directly to the execution of the target firmware to avoid the boot program loading.

Benefits of technology

Saves time for boot loading and resource initialization and improves firmware switching efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120276790A_ABST
    Figure CN120276790A_ABST
Patent Text Reader

Abstract

The invention discloses a firmware switching method and device, equipment and a storage medium, and relates to the technical field of computers, after an upgrading command of an operation and maintenance end is received, integrity verification is firstly carried out on target firmware, it is ensured that the target firmware to be upgraded is legal and then stored in a preset address of a memory, and then the target firmware is upgraded. After the execution of the stored to-be-processed command taken out from the command queue is finished, the firmware initial address is remapped through the memory management unit, so that the service execution of the target equipment directly jumps to the execution of the target firmware without switching to a bootstrap program, and the time for carrying out secondary firmware loading and bootstrap from a bootstrap loading program is saved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and particularly to a firmware switching method, apparatus, device, and storage medium. Background Art

[0002] The number of enterprise solid-state drives running in the customer production environment is much higher than that in the manufacturer's test environment. Therefore, some low-probability problems cannot be detected in the test environment but occur in the user scenario. After the engineer locates the problem and fixes it by modifying the firmware, in order to prevent the same problem from occurring to other users, the repaired firmware needs to be sent to the customer for firmware switching.

[0003] In the related art, after writing the new firmware into the memory, it is necessary to switch to the bootloader to reload the new firmware by the bootloader, and re-initialize the hardware resources and data to process read and write commands. This upgrade method will increase the additional overhead caused by the secondary loading of the bootloader and the repeated initialization of resources, reducing the efficiency of firmware switching. Summary of the Invention

[0004] This application provides a firmware switching method, apparatus, device, and storage medium to at least solve the problem of low firmware switching efficiency in the related art.

[0005] This application provides a firmware switching method, including: receiving a firmware upgrade command for a target device, and obtaining a target firmware according to the firmware upgrade command; verifying the target firmware, and saving the target firmware to a preset physical address in the memory after the verification passes; stopping the processing of each pending command in the command queue, and continuing to process the existing pending commands that have been taken out of the command queue; after processing the existing pending commands, deleting each running application layer task; configuring the firmware start address of the target device as the preset physical address in the memory through the memory management unit to obtain a mapping relationship between the firmware start address and the preset physical address in the memory; initializing the target firmware according to the mapping relationship, and resuming the operation of each application layer task.

[0006] This application also provides a firmware switching apparatus, including:

[0007] A target firmware obtaining module, configured to receive a firmware upgrade command for a target device, and obtain a target firmware according to the firmware upgrade command.

[0008] A target firmware verification module, configured to verify the target firmware, and save the target firmware to a preset physical address in the memory after the verification passes.

[0009] A pending command execution module, configured to stop the processing of each pending command in the command queue, and continue to process the existing pending commands that have been taken out of the command queue.

[0010] The application layer task deletion module is used to delete each currently running application layer task after processing all the existing commands to be processed.

[0011] The firmware start address configuration module is used to configure the start address of the firmware of the target device as the preset physical address of the memory through the memory management unit, so as to obtain the mapping relationship between the firmware start address and the preset physical address of the memory.

[0012] The application layer task recovery module is used to initialize the target firmware and resume the operation of each application layer task according to the mapping relationship.

[0013] This application also provides an electronic device, including: a memory for storing a computer program; a processor for implementing the steps of any one of the above firmware switching methods when executing the computer program.

[0014] This application also provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the steps of any one of the above firmware switching methods are implemented.

[0015] This application also provides a computer program product, including a computer program. When the computer program is executed by a processor, the steps of any one of the above firmware switching methods are implemented.

[0016] For the firmware switching method, device, equipment and storage medium of this application, after receiving the upgrade command from the operation and maintenance terminal, first perform integrity verification on the target firmware, ensure that the target firmware to be upgraded is legal and then store it at the preset memory address. After executing all the existing commands to be processed taken out from the command queue, remap the firmware start address through the memory management unit, so that the business execution of the target device directly jumps to execute the target firmware, without the need to switch to the bootloader, saving the time for secondary loading and booting the firmware from the bootloader. Description of the Drawings

[0017] To more clearly illustrate the embodiments of this application, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0018] Figure 1 It is a schematic diagram of the memory distribution provided by the embodiment of this application;

[0019] Figure 2 It is a schematic flowchart of the firmware switching method provided by the embodiment of this application;

[0020] Figure 3Schematic structural diagram of the firmware switching device provided by the embodiment of the present application;

[0021] Figure 4 Schematic structural diagram of the electronic device provided by the embodiment of the present application. Detailed implementation manners

[0022] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0023] It should be noted that in the description of the present application, the terms "including", "comprising" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present application are used to distinguish similar objects, rather than to describe a specific order or sequence.

[0024] To clearly understand the technical solution of the present application, the solutions of the prior art will be introduced in detail first. The number of enterprise-level solid-state drives running in the customer production environment is much higher than that in the test environment of the manufacturer. Therefore, some small-probability problems cannot be detected in the test environment, but occur in the user scenario. After the engineer locates the problem and fixes it by modifying the firmware, in order to prevent the same problem from occurring to other users, the repaired firmware needs to be sent to the customer for firmware switching. In the related art, after the new firmware is written into the memory, it is necessary to switch to the bootloader to reload the new firmware by the bootloader, and re-initialize the hardware resources and data to process read and write commands. This upgrade method will increase the additional overhead generated by the secondary loading of the bootloader and the repeated initialization of resources, reducing the efficiency of firmware switching.

[0025] To solve the above technical problems, the inventor thought that after receiving the upgrade command from the operation and maintenance terminal, first perform integrity verification on the target firmware, ensure that the target firmware to be upgraded is legal and then store it in the preset address of the memory. After the execution of the existing pending commands taken out from the command queue is completed, the starting address of the firmware is remapped through the memory management unit, so that the business execution of the target device directly jumps to execute the target firmware, without the need to switch to the bootloader, saving the time for secondary loading and booting the firmware from the bootloader.

[0026] To enable those skilled in the art of the present technology to better understand the solution of this application, the following further elaborates on this application in conjunction with the accompanying drawings and specific embodiments.

[0027] In the design stage of the target firmware, the application layer code, the underlying driver code, and the system service code are distinguished based on the functional level and operating privilege, and different parts are mapped to independent physical address spaces through a compilation tool chain to achieve the isolation of business logic and hardware operations. Among them, the application layer code stores business logic and algorithms; the system service code provides task scheduling services; the underlying driver code provides hardware interfaces and interrupt handling services.

[0028] Figure 1 It is a schematic diagram of the memory distribution provided by the embodiment of this application. As Figure 1 shown, the entire memory space is designed with data partitions to separate global variables and shared data. Region 1 stores executable code 1 and global variable 1 required by executable code 1. Region 1 can be a real-time operating system region, storing the executable code and global variables used to call the real-time operating system. The original firmware region stores business executable code 2 and global variable 2 that rely on the original firmware to run. The target firmware region stores business executable code 3 and global variable 3 that rely on the target firmware to run. The original firmware / target firmware region stores firmware shared data, where the firmware shared data refers to the data that can continue to be accessed and ensure consistency after the switch between the original firmware and the target firmware. The application layer executable code is used to implement specific business logic and algorithms based on the firmware. The global variables are used for the global data storage of the application layer executable code of the firmware. The shared data area stores the data that both the old and new firmwares need to access and ensures data consistency during the switch between the two.

[0029] Figure 2 It is a schematic flowchart of the firmware switching method provided by the embodiment of this application. As Figure 2 shown, the embodiment of this application provides a firmware switching method. The execution subject of this method can be the processor of any electronic device (i.e., the target device) that needs to perform firmware switching, or a device with similar functions. The embodiment of this application does not make specific limitations and details the method as follows:

[0030] S201: Receive a firmware upgrade command for the target device and obtain the target firmware according to the firmware upgrade command.

[0031] Specifically, when the processor of the target device receives a firmware upgrade command sent by the operation and maintenance end for the target device, the command carries the acquisition path of the target firmware. According to this acquisition command, through a specific communication protocol or interface, the target firmware is downloaded from the specified storage location to a specific memory location.

[0032] S202: Verify the target firmware, and save the target firmware to a preset physical address in the memory after the verification passes.

[0033] Specifically, after obtaining the target firmware, the processor of the target device will perform integrity and legality verification on the target firmware. After the verification passes, the target firmware will be saved at a preset physical address in the memory, where the preset physical address is a storage space reserved specifically for the target firmware.

[0034] Specifically, the process of verifying the target firmware includes:

[0035] Sa1: Obtain the version number, the first verification information, and the digital signature from the target firmware.

[0036] Among them, the first verification information is used to verify data integrity, and can be a hash value or a cyclic redundancy check code; the version number is used to determine the newness or oldness of the firmware; and the digital signature is used to confirm the legality of the firmware source.

[0037] Specifically, parse and extract the metadata for verification, including the version number, the first verification information, and the digital signature, from a specific area or the header of the target firmware file.

[0038] Sa2: Obtain the binary data of the target firmware, and calculate the second verification information of the binary data using a preset algorithm.

[0039] Specifically, read the complete binary data content of the target firmware, and perform message digest calculation on the binary data using a preset hash algorithm to generate the second verification information.

[0040] Sa3: Compare whether the first verification information is the same as the second verification information.

[0041] Specifically, perform a bit-by-bit comparison between the first verification information extracted from the target firmware and the second verification information calculated in real time. If the two are exactly the same, it initially indicates that the target firmware data is complete; if there are differences, it means that the target firmware may have been damaged or tampered with.

[0042] Sa4: If the first verification information is not the same as the second verification information, the verification fails, and the switching operation of the target firmware stops.

[0043] Specifically, when the first verification information is not the same as the second verification information, the system immediately determines that the verification fails, terminates the switching operation of the target firmware, records error logs, sends an alert to the operation and maintenance side, and keeps the current firmware running state unchanged to ensure that the device continues to work normally.

[0044] Sa5: If the first verification information is consistent with the second verification information, use the pre-stored public key to verify the digital signature to determine whether the source of the target firmware is abnormal.

[0045] Specifically, on the basis of consistent verification information, further verify the source legality of the target firmware. Use the public key pre-stored in the target device to decrypt and verify the digital signature, where this public key is issued by a trusted institution.

[0046] Sa6: If it is determined that the source of the target firmware is abnormal, the verification fails, and the switching operation of the target firmware is stopped.

[0047] Specifically, if the digital signature verification fails, it is determined that the source of the target firmware is abnormal. Similarly, the switching operation is terminated, error logs are recorded, an alarm is sent to the operation and maintenance end, and the current firmware running state remains unchanged to ensure that the device continues to work properly.

[0048] Sa7: If it is determined that the source of the target firmware is normal, check whether the version number is higher than the current firmware version.

[0049] Specifically, after confirming the firmware integrity and source legality, compare the version number of the target firmware with the current running firmware version.

[0050] Sa8: If the version number is not higher than the current firmware version, the verification fails, and the switching operation of the target firmware is stopped.

[0051] Specifically, if the version number of the target firmware is not higher than the current firmware version, it is determined that the verification fails and the firmware switching is stopped, so as to prevent firmware degradation caused by misoperation or induction, and ensure that the device always runs the latest and tested stable version.

[0052] Sa9: If the version number is higher than the current firmware version, the verification is successful.

[0053] Specifically, when the target firmware passes the integrity verification, source legality verification and the version number is higher than the current firmware, the system determines that the verification is successful.

[0054] S203: Stop processing each pending command in the command queue, and continue to process the existing pending commands that have been taken out of the command queue.

[0055] Specifically, first stop receiving and processing each pending command in the command queue of the target device to avoid interference with the switching process due to the addition of new commands during the firmware switching. However, for the existing pending commands that have been taken out of the command queue and are in the process of being processed, continue to execute until completion to ensure that the execution of these started commands will not be interrupted.

[0056] Specifically, after processing the stock of pending commands taken out from the command queue, it further includes:

[0057] Sb1: Set the timeout threshold corresponding to each stock of pending commands according to the type and complexity of the pending commands.

[0058] Among them, the type of the pending command can be data query, device control, or file transfer, and the complexity of the pending command includes the number of execution steps and the amount of resource occupation.

[0059] Specifically, when processing the stock of pending commands taken out, according to the type and complexity of each command, set a dedicated timeout threshold for it. Exemplarily, a simple status query command may set a threshold of 100 ms, while a complex batch data processing command may set a threshold of 500 ms.

[0060] Sb2: Set a timeout counter for each stock of pending commands and monitor the execution time of each stock of pending commands in real time.

[0061] Specifically, start an independent timeout counter for each stock of pending commands and accumulate time in real time from the start of command execution. At the same time, continuously monitor the execution duration of each command through a timer or event listening mechanism.

[0062] Sb3: When it is detected that the execution time of any stock of pending commands exceeds the corresponding timeout threshold, stop the firmware switching operation of the target and trigger the timeout alarm mechanism.

[0063] Specifically, when the execution time of any stock of pending commands exceeds the timeout threshold set for it, immediately interrupt the current firmware switching operation to prevent the upgrade process from stagnating due to a stuck command. At the same time, activate the timeout alarm mechanism, record the ID, type, and elapsed time of the timeout command through the log, and send an exception notification to the operation and maintenance end.

[0064] Sb4: If the execution time of each stock of pending commands does not exceed the corresponding timeout threshold, enter the firmware switching process.

[0065] Specifically, if all stocks of pending commands are executed within their respective timeout thresholds, confirm that the current business process will not cause data loss or task interruption due to firmware switching. At this time, automatically trigger the firmware switching process.

[0066] S204: After processing the stock of pending commands, delete each application layer task currently running.

[0067] Specifically, after processing all stocks of pending commands, delete each application layer task currently running. This process includes:

[0068] Sc1: calling the first interface to stop the currently running application layer tasks through the real-time operating system.

[0069] Specifically, the first interface function provided by the real-time operating system is called to send a task stop instruction to the real-time operating system. The real-time operating system orderly suspends all running application layer tasks according to the preset task priorities and dependencies. During this process, the real-time operating system saves the current execution context of the task.

[0070] Sc2: Reset each interrupt trigger flag of the target device through the real-time operating system and shield the reception of external interrupt signal sources.

[0071] Specifically, after stopping the application layer task, all interrupt trigger flags of the target device are reset through the real-time operating system. At the same time, the reception of all external interrupt signal sources is temporarily shielded, and the shield register of the interrupt controller is modified to prohibit external events from generating interrupt requests.

[0072] Sc3: Delete all currently running application layer tasks and clear the call data of the real-time operating system.

[0073] Specifically, all currently running application layer task control blocks and their related resources are deleted, and at the same time, the call history data about these tasks in the real-time operating system is cleared.

[0074] S205: configuring the firmware start address of the target device as a preset physical address of the memory through the memory management unit, and obtaining a mapping relationship between the firmware start address and the preset physical address of the memory.

[0075] Specifically, the target device's firmware start address is reconfigured through the memory management unit to point to the preset physical address of the memory where the target firmware was previously stored. Through the MMU's address translation mechanism, a mapping relationship between the firmware start address and the preset physical address of the memory is established, so that the system can accurately find the storage location of the new firmware when it is subsequently started or accessed.

[0076] S206: Initialize the target firmware according to the mapping relationship, and resume running each application layer task.

[0077] Specifically, based on the established mapping relationship, the system starts to initialize the target firmware. The initialization process includes configuring hardware parameters, initializing hardware devices, etc., so that the new firmware has the conditions for operation. After completing the firmware initialization, the application layer tasks that rely on the target firmware are executed. At this time, the application layer tasks will be given the target firmware environment to run, thereby realizing the recovery of the business logic of the target device.

[0078] Specifically, the initialization process of the target firmware includes:

[0079] Sd1: According to the mapping relationship, access the global variables stored in memory for the target firmware, and determine whether the target firmware has set the status flag for uninterrupted service.

[0080] Among them, the status flag for uninterrupted service is predefined by the firmware developer and is used to indicate whether business continuity needs to be maintained during the firmware switching process.

[0081] Specifically, based on the established mapping relationship between the starting address of the firmware and the preset physical address in memory, access the global variable area of the target firmware stored in memory, and retrieve whether there is a specific marker for identifying the uninterrupted service status. If this flag is detected, it indicates that the target firmware supports the feature of uninterrupted business during upgrade, and the system will enter a targeted initialization process; if not detected, it will be processed according to the conventional upgrade process, and the business may need to be paused.

[0082] Sd2: If the target firmware has set the status flag for uninterrupted service, then during the initialization of the target firmware, when an access operation to the hardware configuration parameters of the target firmware is detected, determine whether the storage location of the hardware configuration parameters is the shared data segment.

[0083] Specifically, when the target firmware has set the status flag for uninterrupted service, during the initialization of the target firmware, monitor the access operations to the hardware configuration parameters in real time, obtain the storage addresses of these hardware configuration parameters, and determine whether they are stored in the shared data segment.

[0084] Sd3: If the storage location of the hardware configuration parameters is the shared data segment, then skip the initialization of the hardware resources associated with the hardware configuration parameters.

[0085] Specifically, if it is determined that the storage location of the hardware configuration parameters is the shared data segment, identify the hardware resources associated with these parameters, and skip the initialization operations of these hardware resources when initializing the target firmware.

[0086] In summary, when receiving the upgrade command from the operation and maintenance terminal, first perform an integrity check on the target firmware. After ensuring that the target firmware to be upgraded is legal, store it in the preset memory address. After the execution of the stock of pending commands taken out from the command queue is completed, remap the starting address of the firmware through the memory management unit, so that the business execution of the target device directly jumps to execute the target firmware, without the need to switch to the bootloader, saving the time for secondary loading and booting the firmware from the bootloader.

[0087] In addition, when it is detected that the target firmware has set the status flag for uninterrupted service, then when an access operation to the hardware configuration parameters in the shared data segment is detected, skip the initialization of the hardware resources associated with the hardware configuration parameters, thereby saving the time for resource re-initialization and further accelerating the switching of the target firmware.

[0088] In another embodiment provided by the embodiments of the present application, if the processor of the target device is a multi-core processor, where different cores are used to process different tasks, and the multi-core processor includes a main control core and at least one slave core. After the remaining pending commands are processed based on the multi-core processor, it further includes:

[0089] S301: Stop each application layer task currently running and reset each interrupt trigger flag of the target device.

[0090] Specifically, in a multi-core processor environment, the main control core first sends a cooperative stop instruction to all slave cores, and stops each application layer task currently running in sequence according to the preset priority to ensure that the task context is completely saved. Subsequently, the main control core performs a reset operation on all interrupt trigger flags of the target device, and by accessing the status register group of the interrupt controller, clears the trigger flag bits of each interrupt source.

[0091] S302: Stop each interrupt response except the soft interrupt mechanism, where the soft interrupt mechanism is used for firmware switching synchronization between the main control core and each slave core.

[0092] Specifically, the main control core suspends all external hardware interrupt responses except the soft interrupt mechanism by configuring the mask register of the interrupt controller. Hardware interrupts such as those triggered by timers and I / O devices are temporarily disabled to prevent external events from interfering with the operation process during firmware switching. And the soft interrupt mechanism is reserved as a dedicated communication channel between the main control core and the slave cores. It is triggered based on software instructions and realizes inter-core synchronization through specific flag bits in the shared memory.

[0093] Specifically, after stopping each interrupt response except the soft interrupt mechanism, control each slave core to jump to the entry address of the predefined interrupt service routine through a hard interrupt, so that each slave core executes the interrupt service routine, where the interrupt service routine is used to ensure that each slave core is in a stable state.

[0094] S303: Delete each application layer task currently running.

[0095] Specifically, the main control core traverses the task control block linked list and performs a deep deletion operation on each application layer task. This includes releasing the heap memory space occupied by the task, closing the opened file descriptors, recycling resources such as semaphores, and clearing the task registration information in the task scheduler.

[0096] S304: Configure the starting address of the firmware of the target device as the preset physical address of the memory through the memory management unit, and obtain the mapping relationship between the starting address of the firmware and the preset physical address of the memory.

[0097] Specifically, the master core operates the translation table register of the memory management unit to remap the starting address of the firmware of the target device to a preset physical address in the memory. By setting the base address field and permission bits of the page table entry, a new mapping relationship from virtual address to physical address is established.

[0098] S305: Synchronize the mapping relationship to each slave core through the soft interrupt mechanism, so that each slave core updates the corresponding memory access context.

[0099] Specifically, the master core sends a synchronization message to each slave core through the soft interrupt mechanism, and the message content includes the new memory mapping relationship table. After receiving the soft interrupt signal, each slave core pauses the current operation, reads the updated mapping table from the shared memory, and updates the translation lookaside buffer of its own memory management unit.

[0100] S306: Initialize the target firmware, create application layer tasks of the target device, and allocate each application layer task to the corresponding slave core, so that each slave core configures the control information of the corresponding application layer task into the currently running task to resume the execution of each application layer task.

[0101] Specifically, the master core first executes the initialization code of the target firmware to complete operations such as hardware driver loading and system service startup. Subsequently, according to the task scheduling policy of the new firmware, the master core reallocates the application layer tasks, analyzes the characteristics of each task such as real-time requirements and computational intensity, and allocates them to the most suitable slave core. After the allocation is completed, the master core sends a task start instruction to each slave core, and each slave core configures the received task control block information as the currently running task and restores the execution context of the task.

[0102] In summary, through the cooperative control mechanism of the master core and the slave cores, the application layer tasks are orderly stopped and resources are deeply cleaned up to avoid conflicts between old tasks and the new firmware. At the same time, they are dynamically allocated to the slave cores based on task characteristics to ensure that the multi-core parallel processing ability is quickly rebuilt after the new firmware is loaded; only the soft interrupt is retained as the inter-core synchronization channel, which not only prevents external hardware interrupts from interfering, but also realizes real-time inter-core communication through software instructions, ensuring the atomicity of operations such as mapping relationship updates.

[0103] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation method.

[0104] Figure 3 It is a schematic structural diagram of the firmware switching device provided by the embodiment of the present application. As Figure 3As shown in the figure, an embodiment of the present application further provides a firmware switching device, including: a target firmware acquisition module 301, a target firmware verification module 302, a to-be-processed command execution module 303, an application layer task deletion module 304, a firmware start address configuration module 305, and an application layer task restoration module 306.

[0105] The target firmware acquisition module 301 is configured to receive a firmware upgrade command for a target device and acquire the target firmware according to the firmware upgrade command.

[0106] The target firmware verification module 302 is configured to verify the target firmware and save the target firmware to a preset physical address in the memory after the verification passes.

[0107] The to-be-processed command execution module 303 is configured to stop processing each to-be-processed command in the command queue and continue to process the existing to-be-processed commands that have been taken out of the command queue.

[0108] The application layer task deletion module 304 is configured to delete each currently running application layer task after processing the existing to-be-processed commands.

[0109] The firmware start address configuration module 305 is configured to configure the firmware start address of the target device as the preset physical address of the memory through the memory management unit to obtain the mapping relationship between the firmware start address and the preset physical address of the memory.

[0110] The application layer task restoration module 306 is configured to initialize the target firmware and restore the operation of each application layer task according to the mapping relationship.

[0111] In a possible implementation manner, the application layer task restoration module 306 is specifically configured to access the global variables stored in the memory of the target firmware according to the mapping relationship, and determine whether the target firmware sets a status flag for uninterrupted service; if the target firmware sets a status flag for uninterrupted service, during the initialization of the target firmware, when detecting an access operation to the hardware configuration parameters of the target firmware, determine whether the storage location of the hardware configuration parameters is a shared data segment; if the storage location of the hardware configuration parameters is a shared data segment, skip the initialization of the hardware resources associated with the hardware configuration parameters.

[0112] In a possible implementation, the firmware switching device further includes a timeout warning module. The timeout warning module is configured to set a timeout threshold corresponding to each stored pending command according to the type and complexity of each stored pending command; set a timeout counter for each stored pending command, and real-time monitor the execution time of each stored pending command; when it is detected that the execution time of any stored pending command exceeds the corresponding timeout threshold, stop the switching operation of the target firmware and trigger a timeout warning mechanism; if the execution times of all stored pending commands do not exceed the corresponding timeout thresholds, enter the firmware switching process.

[0113] In a possible implementation, the application layer task deletion module 304 is specifically configured to call a first interface to stop each currently running application layer task through a real-time operating system; reset each interrupt trigger identifier of the target device through the real-time operating system and block the reception of external interrupt signal sources; delete each currently running application layer task, and clear the call data of the real-time operating system.

[0114] In a possible implementation, the firmware switching device further includes a multi-core processing module. The multi-core processing module is configured to stop each currently running application layer task and reset each interrupt trigger identifier of the target device; stop each interrupt response except the soft interrupt mechanism, where the soft interrupt mechanism is used for firmware switching synchronization between the main core and each slave core; delete each currently running application layer task; configure the firmware start address of the target device as a preset physical address of the memory through a memory management unit to obtain a mapping relationship between the firmware start address and the preset physical address of the memory; synchronize the mapping relationship to each slave core through the soft interrupt mechanism so that each slave core updates the corresponding memory access context; initialize the target firmware, create application layer tasks of the target device, and allocate each application layer task to the corresponding slave core so that each slave core configures the control information of the corresponding application layer task as the currently running task to resume running each application layer task.

[0115] In a possible implementation, the multi-core processing module is further configured to control each slave core to jump to the entry address of a predefined interrupt service routine through a hard interrupt so that each slave core executes the interrupt service routine, where the interrupt service routine is used to ensure that each slave core is in a stable state.

[0116] In a possible implementation, the target firmware verification module 302 obtains the version number, the first verification information, and the digital signature from the target firmware; obtains the binary data of the target firmware, and calculates the second verification information of the binary data by using a preset algorithm; compares whether the first verification information is consistent with the second verification information; if the first verification information is inconsistent with the second verification information, the verification fails, and the switching operation of the target firmware is stopped; if the first verification information is consistent with the second verification information, the pre-stored public key is used to verify the digital signature to determine whether the source of the target firmware is abnormal; if it is determined that the source of the target firmware is abnormal, the verification fails, and the switching operation of the target firmware is stopped; if it is determined that the source of the target firmware is normal, it is checked whether the version number is higher than the current firmware version; if the version number is not higher than the current firmware version, the verification fails, and the switching operation of the target firmware is stopped; if the version number is higher than the current firmware version, the verification is successful.

[0117] For the descriptions of the features in the corresponding embodiments of the firmware switching device, reference can be made to the relevant descriptions in the corresponding embodiments of the firmware switching method, which will not be elaborated here one by one.

[0118] Figure 4 This is a schematic structural diagram of the electronic device provided by the embodiment of the present application. As Figure 4 shown, the electronic device provided in this embodiment includes: at least one processor 401 and a memory 402. Optionally, the electronic device further includes a communication component 403. Among them, the processor 401, the memory 402, and the communication component 403 are connected through a bus.

[0119] In a specific implementation process, at least one processor 401 executes the computer program stored in the memory 402, so that when at least one processor 401 executes the computer program, the above-mentioned firmware switching method embodiment is implemented.

[0120] For the specific implementation process of the processor 401, reference can be made to the above method embodiment, and its implementation principle and technical effects are similar, which will not be elaborated here in this embodiment.

[0121] In the above embodiment, it should be understood that the processor may be a central processing unit (Central Processing Unit, abbreviated as: CPU), or other general-purpose processors, digital signal processors (Digital Signal Processor, abbreviated as: DSP), application specific integrated circuits (Application Specific Integrated Circuit, abbreviated as: ASIC), etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the application can be directly implemented by the execution of the hardware processor, or can be implemented by the combination of the hardware and software modules in the processor.

[0122] The memory may include a random access memory (RAM), and may also include a non-volatile memory (NVM), such as at least one disk memory.

[0123] The bus may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience in representation, the buses in the drawings of this application are not limited to only one bus or one type of bus.

[0124] Embodiments of the present application further provide a computer-readable storage medium, in which a computer program is stored, and the computer program is configured to execute the steps in any one of the above firmware switching method embodiments when running.

[0125] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: various media such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk, or an optical disc that can store a computer program.

[0126] Embodiments of the present application further provide a computer program product. The above computer program product includes a computer program, and when the computer program is executed by a processor, the steps in any one of the above firmware switching method embodiments are implemented.

[0127] Embodiments of the present application further provide another computer program product, including a non-volatile computer-readable storage medium, where the non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in any one of the above firmware switching method embodiments are implemented.

[0128] Those skilled in the art may further realize that the units and algorithm steps of each example described in connection with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described according to their functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered as exceeding the scope of this application.

[0129] The above has introduced in detail a firmware switching method, device, equipment, and storage medium provided by this application. Specific examples are used herein to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of this application, several improvements and modifications can still be made to this application, and these improvements and modifications also fall within the protection scope of the claims of this application.

Claims

1. A firmware switching method, characterized in that, Including: Receiving a firmware upgrade command for a target device and obtaining target firmware according to the firmware upgrade command; Verifying the target firmware and, after the verification passes, saving the target firmware to a preset physical address in the memory; Stopping the processing of each pending command in the command queue and continuing to process the stock of pending commands that have been taken out of the command queue; After processing the stock of pending commands, deleting each currently running application layer task; Configuring the firmware start address of the target device as the preset physical address of the memory through a memory management unit to obtain a mapping relationship between the firmware start address and the preset physical address of the memory; Initializing the target firmware according to the mapping relationship and resuming the operation of each application layer task.

2. The firmware switching method according to claim 1, wherein The initializing the target firmware according to the mapping relationship includes: Accessing global variables stored in the memory by the target firmware according to the mapping relationship and determining whether the target firmware has set a status flag for uninterrupted service; If the target firmware has set a status flag for uninterrupted service, then during the initialization of the target firmware, when an access operation to the hardware configuration parameters of the target firmware is detected, determining whether the storage location of the hardware configuration parameters is a shared data segment; If the storage location of the hardware configuration parameters is a shared data segment, then skipping the initialization of the hardware resources associated with the hardware configuration parameters.

3. The firmware switching method according to claim 1, wherein After the continuing to process the stock of pending commands that have been taken out of the command queue, it further includes: Setting a timeout threshold corresponding to each stock of pending commands according to the type and complexity of each stock of pending commands; Setting a timeout counter for each stock of pending commands and monitoring the execution time of each stock of pending commands in real time; When it is detected that the execution time of any stock of pending commands exceeds the corresponding timeout threshold, stopping the firmware switching operation of the target device and triggering a timeout alarm mechanism; If the execution times of all stocks of pending commands do not exceed the corresponding timeout thresholds, then entering the firmware switching process.

4. The firmware switching method according to claim 1, wherein The deleting each currently running application layer task includes: Invoking a first interface to stop each currently running application layer task through a real-time operating system; Resetting each interrupt trigger identifier of the target device through the real-time operating system and blocking the reception of external interrupt signal sources; Deleting each currently running application layer task and clearing the call data of the real-time operating system.

5. The firmware switching method according to claim 1, wherein The processor of the target device is a multi-core processor, and the multi-core processor includes a main control core and at least one slave core; Correspondingly, after processing the stock of pending commands, it further includes: Stopping each currently running application layer task and resetting each interrupt trigger identifier of the target device; Stopping each interrupt response except for the soft interrupt mechanism, where the soft interrupt mechanism is used for firmware switching synchronization between the main control core and each slave core; Deleting each currently running application layer task; Configure the firmware start address of the target device as the preset physical address of the memory through the memory management unit, to obtain the mapping relationship between the firmware start address and the preset physical address of the memory; Synchronize the mapping relationship to each slave core through the software interrupt mechanism, so that each slave core updates the corresponding memory access context; Initialize the target firmware, and create application layer tasks of the target device, and allocate each application layer task to the corresponding slave core, so that each slave core configures the control information of the corresponding application layer task as the currently running task to resume running each application layer task.

6. The firmware switching method according to claim 5, wherein After stopping the responses of each interrupt except the software interrupt mechanism, it further includes: Control each slave core to jump to the entry address of a predefined interrupt service routine through a hard interrupt, so that each slave core executes the interrupt service routine, where the interrupt service routine is used to ensure that each slave core is in a stable state.

7. The firmware switching method according to claim 1, wherein The verification of the target firmware includes: Obtain the version number, the first verification information and the digital signature from the target firmware; Obtain the binary data of the target firmware, and calculate the second verification information of the binary data by using a preset algorithm; Compare whether the first verification information is consistent with the second verification information; If the first verification information is inconsistent with the second verification information, the verification fails, and the switching operation of the target firmware is stopped; If the first verification information is consistent with the second verification information, use the pre-stored public key to verify the digital signature to determine whether the source of the target firmware is abnormal; If it is determined that the source of the target firmware is abnormal, the verification fails, and the switching operation of the target firmware is stopped; If it is judged that the source of the target firmware is normal, check whether the version number is higher than the current firmware version; If the version number is not higher than the current firmware version, the verification fails, and the switching operation of the target firmware is stopped; If the version number is higher than the current firmware version, the verification is successful.

8. A firmware switching device, characterized in that It includes: A target firmware acquisition module, configured to receive a firmware upgrade command for a target device, and acquire a target firmware according to the firmware upgrade command; A target firmware verification module, configured to verify the target firmware, and save the target firmware to a preset physical address of the memory after the verification passes; A to-be-processed command execution module, configured to stop processing each to-be-processed command in the command queue, and continue to process the existing to-be-processed commands that have been taken out of the command queue; An application layer task deletion module, configured to delete each currently running application layer task after processing the existing to-be-processed commands; A firmware start address configuration module, configured to configure the firmware start address of the target device as the preset physical address of the memory through a memory management unit, to obtain the mapping relationship between the firmware start address and the preset physical address of the memory; An application layer task recovery module, configured to initialize the target firmware according to the mapping relationship, and resume running each application layer task.

9. An electronic device, characterized in that, It includes: A memory, configured to store a computer program; A processor, configured to implement the steps of the firmware switching method according to any one of claims 1 to 7 when executing the computer program.

10. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, wherein the computer program implements the steps of the firmware switching method according to any one of claims 1 to 7 when executed by a processor.

Citation Information

Patent Citations

  • Firmware switching method and device, equipment and medium

    CN115129619A

  • Chip firmware upgrading system

    CN116560700A

  • Firmware upgrading method and device based on dual-core DSP servo driver

    CN119127241A

  • Firmware updating method and device, electronic equipment and storage medium

    CN119493586A

  • Firmware update with logical address remapping

    US20240427588A1

Cited By

  • Server management system

    CN120973192A