System kernel fault solving method and device, equipment and storage medium

By analyzing kernel crash data, reproducing and repairing operating system kernel failures, the diagnosis difficulties of traditional tools under the kernel-state isolation layer are solved, rapid fault location and repair are achieved, and system stability in key industries is improved.

CN120371585APending Publication Date: 2025-07-25SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510624638.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-15
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

The current operating system kernel fault diagnosis is complex, traditional tools are difficult to obtain effective information through the kernel and user state isolation layers, and race conditions in multi-core concurrency environments are difficult to reproduce, resulting in long fault location and recovery time, affecting the normal operation of key industries and the security of information infrastructure.

Method used

By obtaining kernel crash data, using Crash tools and KProbe technology to analyze the address of the fault function, writing test case functions and replacing the fault function, compiling the test case kernel module, reproducing the fault using the insmod command, writing patch functions to fix the fault, and verifying the kernel data through livepatch technology.

Benefits of technology

It realizes rapid positioning and solving operating system kernel failures, improves the timeliness of fault resolution, and provides higher system stability for applications such as cloud computing, big data, databases and AI models.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120371585A_ABST
    Figure CN120371585A_ABST
Patent Text Reader

Abstract

The invention discloses a system kernel fault solving method and device, equipment and a storage medium, and relates to the field of operating systems, and the method comprises the steps: obtaining a first address of a fault function based on crash data, determining a test case function according to the fault function, and replacing the first address with a second address of the test case function to obtain test case kernel data; obtaining a KO file of a first test case kernel module based on the test case kernel data, running the KO file of the first test case kernel module to obtain test case crash data, determining a patch function based on a to-be-faulted function and a determined kernel fault reason, and replacing the fault function with the patch function to obtain to-be-inspected system kernel data; obtaining a KO file of a second test case kernel module according to the to-be-checked system kernel data, running the KO file of the second test case kernel module to obtain running data, and verifying the running data to determine target system kernel data. And the kernel fault of the operating system can be quickly and effectively positioned and solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of operating systems, and particularly to a method, device, equipment and storage medium for solving system kernel faults. Background Art

[0002] The scale of the kernel code of current mainstream operating systems has reached the order of tens of millions of lines. Each module is tightly coupled through highly optimized interfaces. While this precision improves system efficiency, it also poses a huge challenge to fault diagnosis.

[0003] The destructive impact of kernel faults has a significant amplification effect. The average fault recovery time of the core business systems in key industries such as finance and power in China is as long as 6 - 8 hours, and more than 68% of the downtime events are caused by kernel-level faults that are difficult to locate. This systemic risk not only threatens the normal operation of enterprises, but also poses a potential threat to the security of the country's critical information infrastructure.

[0004] The complexity of fault diagnosis stems from the particularity of the kernel operation mechanism. First, the strict isolation between the kernel mode and the user mode makes it difficult for traditional debugging tools to penetrate the protection layer to obtain effective information. Existing tools such as Kdump and SystemTap have obvious limitations in real-time performance and diagnostic accuracy. Second, race conditions in a multi-core concurrent environment are difficult to reproduce, and the mutual restriction between security mechanisms and performance optimization leads to limited collection of diagnostic information.

[0005] In summary, how to quickly and effectively locate and solve operating system kernel faults is an urgent problem to be solved at present. Summary of the Invention

[0006] In view of this, the purpose of the present invention is to provide a method, device, equipment and storage medium for solving system kernel faults, which can quickly and effectively locate and solve operating system kernel faults. The specific solutions are as follows:

[0007] In the first aspect, the present application provides a method for solving system kernel faults, including:

[0008] Obtain the crash data of the kernel of the system to be tested, obtain the first address of the corresponding fault function in the kernel of the system to be tested based on the crash data of the kernel of the system to be tested, determine the corresponding test case function according to the fault function in the kernel of the system to be tested, and replace the first address of the fault function in the kernel of the system to be tested with the second address of the test case function to obtain test case kernel data;

[0009] Obtain the KO file of the first test case kernel module based on the test case kernel data, run the KO file of the first test case kernel module to obtain test case crash data, so as to determine the kernel fault cause of the to-be-tested system kernel, determine the corresponding patch function based on the fault function and the kernel fault cause in the to-be-tested system kernel, and replace the fault function in the to-be-tested system kernel with the patch function to obtain the to-be-verified system kernel data;

[0010] Obtain the KO file of the second test case kernel module according to the to-be-verified system kernel data, run the KO file of the second test case kernel module to obtain the running data of the to-be-verified system kernel data, and verify the running data of the to-be-verified system kernel data to determine the target system kernel data.

[0011] Optionally, the obtaining the crash data of the to-be-tested system kernel and obtaining the first address of the corresponding fault function in the to-be-tested system kernel based on the crash data of the to-be-tested system kernel includes:

[0012] Obtain the kernel log and / or kernel crash file of the to-be-tested system kernel;

[0013] Use a preset Crash tool to analyze the kernel log or kernel crash file of the to-be-tested system kernel to obtain the crash data and kernel crash stack of the to-be-tested system kernel;

[0014] Based on the KProbe technology, analyze the crash data and kernel crash stack of the to-be-tested system kernel to obtain the first address of the corresponding fault function in the to-be-tested system kernel.

[0015] Optionally, the determining the corresponding test case function according to the fault function in the to-be-tested system kernel and replacing the first address of the fault function in the to-be-tested system kernel with the second address of the test case function to obtain the test case kernel data includes:

[0016] Determine the corresponding test case function according to the fault function in the to-be-tested system kernel;

[0017] Filter the fault function in the to-be-tested system kernel based on the preset filtering instruction function of the preset FTrace operation object instance, and use the callback function of the preset FTrace operation object instance to jump the first address of the fault function in the to-be-tested system kernel to the second address of the test case function to obtain the test case kernel data.

[0018] Optionally, the obtaining the KO file of the first test case kernel module based on the test case kernel data includes:

[0019] Perform a preset compilation and build operation on the kernel data of the test case to obtain the KO file of the first test case kernel module.

[0020] Optionally, running the KO file of the first test case kernel module to obtain test case crash data to determine the kernel failure cause of the system under test includes:

[0021] Use the preset insmod command to install and run the KO file of the first test case kernel module to obtain test case crash data;

[0022] Compare the test case crash data with the crash data of the system under test kernel;

[0023] If the obtained comparison result indicates that the test case crash data is consistent with the crash data of the system under test kernel, determine the kernel failure cause of the system under test kernel based on the test case crash data;

[0024] If the obtained comparison result indicates that the test case crash data is inconsistent with the crash data of the system under test kernel, re-jump to the step of determining the corresponding test case function according to the fault function in the system under test kernel.

[0025] Optionally, determining the corresponding patch function based on the fault function and the kernel failure cause in the system under test kernel, and replacing the fault function in the system under test kernel with the patch function to obtain the system kernel data to be verified includes:

[0026] Use the preset livepatch technology to write the corresponding patch function based on the fault function and the kernel failure cause in the system under test kernel;

[0027] Register the information of the patch function;

[0028] Based on the information of the patch function, replace the fault function in the system under test kernel with the patch function to obtain the system kernel data to be verified.

[0029] Optionally, verifying the running data of the system kernel data to be verified to determine the target system kernel data includes:

[0030] Verify whether the running data of the system kernel data to be verified meets the preset system kernel fault condition;

[0031] If the system kernel data to be verified does not meet the preset system kernel fault condition, determine the system kernel data to be verified as the target system kernel data;

[0032] If the kernel data of the system to be tested meets the preset system kernel fault condition, then jump back to the step of determining the corresponding patch function based on the fault function and the kernel fault cause in the kernel of the system to be tested.

[0033] In a second aspect, the present application provides a system kernel fault resolution device, including:

[0034] A test case kernel data acquisition module, configured to acquire the crash data of the kernel of the system to be tested, obtain the first address of the corresponding fault function in the kernel of the system to be tested based on the crash data of the kernel of the system to be tested, determine the corresponding test case function according to the fault function in the kernel of the system to be tested, and replace the first address of the fault function in the kernel of the system to be tested with the second address of the test case function to obtain test case kernel data;

[0035] A system kernel data to be tested acquisition module, configured to acquire the KO file of the first test case kernel module based on the test case kernel data, run the KO file of the first test case kernel module to obtain test case crash data to determine the kernel fault cause of the kernel of the system to be tested, determine the corresponding patch function based on the fault function and the kernel fault cause in the kernel of the system to be tested, and replace the fault function in the kernel of the system to be tested with the patch function to obtain the system kernel data to be tested;

[0036] A target system kernel data determination module, configured to acquire the KO file of the second test case kernel module according to the system kernel data to be tested, run the KO file of the second test case kernel module to obtain the running data of the system kernel data to be tested, and verify the running data of the system kernel data to be tested to determine the target system kernel data.

[0037] In a third aspect, the present application provides an electronic device, including:

[0038] A memory, configured to store a computer program;

[0039] A processor, configured to execute the computer program to implement the system kernel fault resolution method as described above.

[0040] In a fourth aspect, the present application provides a computer-readable storage medium, configured to store a computer program; wherein, when the computer program is executed by a processor, the system kernel fault resolution method as described above is implemented.

[0041] In summary, the present application first obtains the crash data of the kernel of the system to be tested, obtains the first address of the corresponding faulty function in the kernel of the system to be tested based on the crash data of the kernel of the system to be tested, determines the corresponding test case function according to the faulty function in the kernel of the system to be tested, and replaces the first address of the faulty function in the kernel of the system to be tested with the second address of the test case function to obtain test case kernel data; obtains the KO file of the first test case kernel module based on the test case kernel data, runs the KO file of the first test case kernel module to obtain test case crash data to determine the kernel fault cause of the kernel of the system to be tested, determines the corresponding patch function based on the faulty function and the kernel fault cause in the kernel of the system to be tested, and replaces the faulty function in the kernel of the system to be tested with the patch function to obtain the system kernel data to be verified; obtains the KO file of the second test case kernel module according to the system kernel data to be verified, runs the KO file of the second test case kernel module to obtain the running data of the system kernel data to be verified, and verifies the running data of the system kernel data to be verified to determine the target system kernel data. As can be seen from the above, the present application first obtains the crash data of the kernel of the system to be tested, obtains the first address of the faulty function therefrom, determines the test case function according to the faulty function, replaces the first address of the faulty function with the second address of the test case function to obtain the test case kernel data; obtains the KO file of the first test case kernel module based on this data, runs this KO file to obtain the test case crash data, thereby determining the kernel fault cause, and then determines the patch function according to the faulty function and the kernel fault cause, replaces the faulty function in the kernel of the system to be tested with the patch function to obtain the system kernel data to be verified; obtains the KO file of the second test case kernel module according to the system kernel data to be verified, runs this KO file to obtain the running data of the system kernel data to be verified, and verifies the running data to determine the target system kernel data. In this way, the present application verifies the kernel module through the test case kernel module for reproducing the fault and the solution for solving the fault, writes the test case kernel module, reproduces the kernel fault, writes the solution patch kernel module, and verifies the kernel fault solution, realizing the function of quickly reproducing and solving the operating system kernel fault, improving the timeliness of solving the operating system kernel problem, and providing higher system stability for applications such as cloud computing, big data, databases, and AI large models. Description of the Drawings

[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.

[0043] Figure 1 A flowchart of a method for solving a system kernel failure disclosed in this application;

[0044] Figure 2 A functional flow chart of a specific system kernel fault solution method disclosed in this application;

[0045] Figure 3 A schematic diagram of the structure of a system kernel fault solving device disclosed in this application;

[0046] Figure 4 This is a structural diagram of an electronic device disclosed in this application. DETAILED DESCRIPTION

[0047] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0048] At present, the scale of kernel code of mainstream operating systems has reached tens of millions of lines, and each module is tightly coupled through a highly optimized interface. This precision not only improves system efficiency, but also brings huge challenges to fault diagnosis. The destructive impact of kernel failures has a significant amplification effect. The average fault recovery time of core business systems in key industries such as finance and electricity in my country is as long as 6-8 hours, of which more than 68% of downtime events are caused by kernel-level failures that are difficult to locate. This systemic risk not only threatens the normal operation of enterprises, but also poses a potential threat to the security of national critical information infrastructure. The complexity of fault diagnosis stems from the particularity of the kernel operation mechanism. First, the strict isolation between kernel state and user state makes it difficult for traditional debugging tools to penetrate the protection layer to obtain effective information. Existing tools such as Kdump and SystemTap have obvious limitations in real-time and diagnostic accuracy. Secondly, the race condition in a multi-core concurrent environment is difficult to reproduce, and the mutual constraints of security mechanism and performance optimization lead to limited diagnostic information collection. In order to solve the above technical problems, the present application discloses a system kernel failure solution, device, equipment and storage medium, which can quickly and effectively locate and solve the kernel failure of the operating system.

[0049] See also Figure 1 As shown, the embodiment of the present invention discloses a method for solving a system kernel failure, including:

[0050] Step S11: Obtain the crash data of the kernel of the system under test, obtain the first address of the corresponding faulty function in the kernel of the system under test based on the crash data of the kernel of the system under test, determine the corresponding test case function according to the faulty function in the kernel of the system under test, and replace the first address of the faulty function in the kernel of the system under test with the second address of the test case function to obtain the test case kernel data.

[0051] In this embodiment, first, obtain the kernel log and / or kernel crash file of the kernel of the system under test; use a preset Crash tool to analyze the kernel log or kernel crash file of the kernel of the system under test to obtain the crash data of the kernel of the system under test and the kernel crash stack; analyze the crash data of the kernel of the system under test and the kernel crash stack based on the KProbe technology to obtain the first address of the corresponding faulty function in the kernel of the system under test. Specifically, by using a preset Crash tool to analyze the kernel log or kernel crash file of the kernel of the system under test, obtain the running conditions of all processes when the kernel of the system under test crashes, obtain the crash data of the kernel of the system under test, and obtain the kernel crash stack. By analyzing the crash data and the kernel crash stack, obtain the faulty function that causes the kernel of the system under test to crash and the first address of the faulty function.

[0052] Furthermore, determine the corresponding test case function according to the faulty function in the kernel of the system under test; filter the faulty function in the kernel of the system under test based on the preset filtering instruction function of the preset FTrace operation object instance, and use the callback function of the preset FTrace operation object instance to jump the first address of the faulty function in the kernel of the system under test to the second address of the test case function to obtain the test case kernel data. Specifically, for all possible conditions that cause kernel faults, write a test case kernel data to create all conditions that cause kernel faults. Obtain the address of the faulty function based on the KProbe technology, define a function link name, for example, symbol_name, as the KProbe object of the faulty function name, and register the KProbe object instance. Obtain the first address of the faulty function through the address field of the KProbe object instance. Intercept the first address of the faulty function based on the FTrace technology, filter the faulty function through the preset filtering instruction function of the preset FTrace operation object instance, and specify the callback function of FTrace. In the callback function, force a jump to the second address of the test case kernel data, so as to replace the first address of the faulty function with the second address of the test case kernel data. Finally, register the FTrace operation object instance to make FTrace take effect. Finally, call the test case kernel data to reproduce the kernel fault.

[0053] Step S12: Obtain the KO file of the first test case kernel module based on the test case kernel data, run the KO file of the first test case kernel module to obtain test case crash data, determine the kernel fault cause of the to-be-tested system kernel, determine the corresponding patch function based on the fault function and the kernel fault cause in the to-be-tested system kernel, and replace the fault function in the to-be-tested system kernel with the patch function to obtain the to-be-verified system kernel data.

[0054] In this embodiment, after obtaining the test case kernel data, compile and build the test case kernel data into a KO (Kernel Object) file of the first test case kernel module. Then, use the preset insmod command to install and run the KO file of the first test case kernel module to obtain test case crash data; compare the test case crash data with the crash data of the to-be-tested system kernel; if the comparison result indicates that the test case crash data is consistent with the crash data of the to-be-tested system kernel, determine the kernel fault cause of the to-be-tested system kernel based on the test case crash data; if the comparison result indicates that the test case crash data is inconsistent with the crash data of the to-be-tested system kernel, jump back to the step of determining the corresponding test case function according to the fault function in the to-be-tested system kernel. Specifically, use the preset insmod command to install and run the KO file of the first test case kernel module, obtain the test case crash data, and compare it with the crash data of the original to-be-tested system kernel to determine whether the kernel fault is reproduced. If the kernel fault is not reproduced, continuously modify the conditions causing the kernel crash in the test case crash data and continue the steps of reproducing the kernel fault until the test case crash data is consistent with the crash data of the to-be-tested system kernel. Once the kernel fault is reproduced, the root cause of the kernel fault, that is, the kernel fault cause of the to-be-tested system kernel, is found.

[0055] In this embodiment, after determining the cause of the kernel failure, a corresponding patch function is written based on the faulty function and the cause of the kernel failure in the kernel of the system under test by using the preset livepatch technology; the information of the patch function is registered; and the faulty function in the kernel of the system under test is replaced with the patch function based on the information of the patch function to obtain the kernel data of the system to be verified. Specifically, after finding the cause of the kernel failure in the kernel of the system under test, a patch function is rewritten based on the faulty function, and the condition that triggers the kernel failure of the kernel of the system under test is removed in the patch function. First, a patch function for implementing a kernel failure solution is realized based on the preset livepatch technology. An array of patch functions funcs is defined, the function name of the patch function and the name of the faulty function are specified. An array of patch objects objs is defined, and the patch function is specified as an object in the funcs array. The patch information is defined, the module is specified as the current module, and the patch object is specified as objs to complete the registration of the patch information. Then, the interception of the faulty function is realized, and the original faulty function is replaced with the patch function to obtain the kernel data of the system to be verified.

[0056] Step S13: Obtain the KO file of the kernel module of the second test case according to the kernel data of the system to be verified, run the KO file of the kernel module of the second test case to obtain the running data of the kernel data of the system to be verified, and verify the running data of the kernel data of the system to be verified to determine the kernel data of the target system.

[0057] In this embodiment, after writing the patch function and completing the replacement, the kernel data of the system to be verified is compiled and built to generate the KO file of the kernel module of the second test case. Subsequently, the preset insmod command is used to load the KO file of the kernel module of the second test case. After successful loading, the enabled field of the kernel failure solution patch is set to 1 to make the patch function run, and the running data of the kernel data of the system to be verified is obtained. Then, it is verified whether the running data of the kernel data of the system to be verified meets the preset system kernel failure condition; if the kernel data of the system to be verified does not meet the preset system kernel failure condition, the kernel data of the system to be verified is determined as the kernel data of the target system; if the kernel data of the system to be verified meets the preset system kernel failure condition, the process jumps back to the step of determining the corresponding patch function based on the faulty function and the cause of the kernel failure in the kernel of the system under test. Specifically, the preset insmod command is used to verify whether the kernel failure still occurs in the kernel data of the system to be verified. If the verification of the kernel data of the system to be verified passes, the kernel data of the system to be verified is determined as the kernel data of the target system; if the kernel failure still occurs in the kernel data of the system to be verified, the patch function is continuously modified until the kernel failure does not occur in the kernel data of the system to be verified, indicating that the kernel failure is resolved.

[0058] As can be seen from the above, in the embodiment of the present application, first, the kernel crash data of the system to be tested is obtained, and the first address of the faulty function is obtained therefrom. The test case function is determined according to the faulty function, and the first address of the faulty function is replaced with the second address of the test case function to obtain the test case kernel data; based on this data, the KO file of the first test case kernel module is obtained, and the KO file is run to obtain the test case crash data, so as to determine the kernel fault cause. Then, the patch function is determined according to the faulty function and the kernel fault cause, and the faulty function in the kernel of the system to be tested is replaced with the patch function to obtain the system kernel data to be verified; according to the system kernel data to be verified, the KO file of the second test case kernel module is obtained, and the KO file is run to obtain the running data of the system kernel data to be verified, and the running data is verified to determine the target system kernel data. In this way, in the embodiment of the present application, the test case kernel module for reproducing the fault and the solution for solving the fault are used to verify the kernel module, the test case kernel module is written, the kernel fault is reproduced, the solution patch kernel module is written, and the kernel fault solution is verified, realizing the function of quickly reproducing and solving the operating system kernel fault, improving the timeliness of solving the operating system kernel problem, and providing higher system stability for applications such as cloud computing, big data, databases, and AI large models.

[0059] Based on the previous embodiment, it can be known that the present application discloses a method for solving system kernel faults, which can quickly and effectively locate and solve operating system kernel faults. Next, the system kernel fault solving method as shown in Figure 2 will be described in detail.

[0060] In this embodiment, first, the kernel log or kernel crash file of the system to be tested is analyzed by a preset Crash tool to obtain the running conditions of all processes when the kernel of the system to be tested crashes, obtain the crash data of the kernel of the system to be tested, and obtain the kernel crash stack. By analyzing the crash data and the kernel crash stack, the faulty function that causes the kernel of the system to be tested to crash and the first address of the faulty function are obtained. Based on the FTrace technology, the first address of the faulty function is intercepted, the faulty function is filtered by a preset filter instruction function of the FTrace operation object instance, and the callback function of the FTrace is specified. In the callback function, a forced jump is made to the second address of the test case kernel data. Finally, the test case kernel data is called to reproduce the kernel fault. The specific code segment can be as follows:

[0061] / / Module initialization function

[0062] static int __init test case kernel module_init(void) {

[0063] / / Use KProbe to obtain the address of the faulty function

[0064] static struct kprobe kp = {.symbol_name = "Fault function name"};

[0065] register_kprobe(&kp); / / Register KProbe

[0066] Fault function address = (unsigned long)kp.addr; / / Get the fault function address

[0067] Fault function = (void*)fault function address; / / Get the fault function for new function calls

[0068] New function address = (unsigned long)new function;

[0069] / / Define the ftrace_ops structure

[0070] static struct ftrace_ops ops;

[0071] ops.func = ftrace_callback; / / Ftrace's callback function

[0072] ops.flags = FTRACE_OPS_FL_SAVE_REGS|FTRACE_OPS_FL_RECURSION|FTRACE_OPS_FL_IPMODIFY; / / Save registers, prevent recursive calls (doesn't work for calls within the new function), allow instruction modification

[0073] / / Register the ftrace hook

[0074] int ret = ftrace_set_filter_ip(&ops, fault function address, 0, 0);

[0075] ret = register_ftrace_function(&ops);

[0076] }

[0077] / / Ftrace callback function

[0078] static void notrace ftrace_callback(unsigned long ip, unsigned longparent_ip,

[0079] struct ftrace_ops *op, struct ftrace_regs *fregs) {

[0080] / / Force a jump to the new function, bypassing the faulty function

[0081] instruction_pointer_set(&fregs->regs, address of new function);

[0082] }

[0083] / / Implementation of the new function

[0084] static void new function(function parameters)

[0085] {

[0086] / / Write all conditions that cause a kernel fault, modify the parameter values of the function that calls the faulty function

[0087] / / Call the faulty function

[0088] faulty function(function parameters);

[0089] }

[0090] It should be noted that after obtaining the kernel data of the test case, the kernel data of the test case is compiled and built into a KO file for the first test case kernel module. Use the preset insmod command to install and run the KO file of the first test case kernel module, obtain the test case crash data, and compare it with the crash data of the original kernel of the system under test to determine whether the kernel fault is reproduced. If the kernel fault is not reproduced, continuously modify the conditions that cause the kernel crash in the test case crash data and continue the steps to reproduce the kernel fault until the test case crash data is consistent with the crash data of the kernel of the system under test. Once the kernel fault is reproduced, the root cause of the kernel fault is found, that is, the kernel fault cause of the kernel of the system under test. The specific code segment can be as follows:

[0091] KERNEL_DIR := / lib / modules / `uname -r` / build /

[0092] CURRENT_DIR := $(shell pwd)

[0093] obj-m := test case kernel module.o

[0094] build: kernel_modules

[0095] kernel_modules:

[0096] $(MAKE) -C $(KERNEL_DIR) M=$(CURRENT_DIR) modules

[0097] / / Run the test case kernel module

[0098] insmod test case kernel module.ko

[0099] Furthermore, after determining the cause of the kernel failure, based on the faulty function, rewrite a patch function to remove the condition that triggers the kernel failure of the system under test in the patch function. Then implement an intercepted faulty function and use the patch function to replace the original faulty function to obtain the kernel data of the system to be verified. The specific code segment can be as follows:

[0100] static int patch function(Function parameters)

[0101] {

[0102] / / Modify the faulty function logic to remove the condition that triggers the failure

[0103] }

[0104] / / Define the patch function to replace the faulty function

[0105] static struct klp_func funcs[] = {

[0106] {

[0107] .old_name = "Faulty function",

[0108] .new_func = patch function,

[0109] }, {}

[0110] };

[0111] / / Define the patch object

[0112] static struct klp_object objs[] = {

[0113] {

[0114] .funcs = funcs,

[0115] }, {}

[0116] };

[0117] / / Define the patch information

[0118] static struct klp_patch patch = {

[0119] .mod = THIS_MODULE,

[0120] .objs = objs,

[0121] };

[0122] / / Module initialization and activation of the patch

[0123] static int solution_kernel_module_init(void) {

[0124] klp_register_patch(&patch);

[0125] return 0;

[0126] }

[0127] It can be understood that after writing the patch function and completing the replacement, compile and build the kernel data of the system to be tested, and generate the KO file of the second test case kernel module. Subsequently, run the patch function to obtain the running data of the kernel data of the system to be tested, and use the preset insmod command to verify whether the kernel data of the system to be tested still has a kernel fault. If the kernel data of the system to be tested passes the verification, then the kernel data of the system to be tested is determined as the target system kernel data; if the kernel data of the system to be tested still has a fault, then continuously modify the patch function until the kernel data of the system to be tested does not have a fault, which means that the kernel fault is resolved. The specific code segment can be as follows:

[0128] KERNEL_DIR := / lib / modules / `uname -r` / build /

[0129] CURRENT_DIR := $(shell pwd)

[0130] obj-m := solution_patch_kernel_module.o

[0131] build: kernel_modules

[0132] kernel_modules:

[0133] $(MAKE) -C $(KERNEL_DIR) M=$(CURRENT_DIR) modules

[0134] / / Run the solution patch kernel module

[0135] insmod the solution patch kernel module.ko

[0136] echo 1 > / sys / kernel / livepatch / solution patch / enabled

[0137] / / Run the test case kernel module

[0138] insmod the test case kernel module.ko

[0139] This application implements a method for solving system kernel faults, which can not only reproduce system kernel faults by writing a test case kernel module, but also write a patch kernel module to repair the faults. At the same time, it verifies the kernel fault solution, so as to quickly reproduce and solve the functions of operating system kernel faults, and improves the timeliness of solving operating system kernel problems.

[0140] See Figure 3 As shown, an embodiment of the present invention discloses a device for solving system kernel faults, including:

[0141] A test case kernel data acquisition module 11, configured to acquire the crash data of the to-be-tested system kernel, obtain the first address of the corresponding fault function in the to-be-tested system kernel based on the crash data of the to-be-tested system kernel, determine the corresponding test case function according to the fault function in the to-be-tested system kernel, and replace the first address of the fault function in the to-be-tested system kernel with the second address of the test case function to obtain test case kernel data;

[0142] A to-be-verified system kernel data acquisition module 12, configured to obtain the KO file of the first test case kernel module based on the test case kernel data, run the KO file of the first test case kernel module to obtain test case crash data to determine the kernel fault cause of the to-be-tested system kernel, determine the corresponding patch function based on the fault function and the kernel fault cause in the to-be-tested system kernel, and replace the fault function in the to-be-tested system kernel with the patch function to obtain to-be-verified system kernel data;

[0143] A target system kernel data determination module 13, configured to obtain the KO file of the second test case kernel module according to the to-be-verified system kernel data, run the KO file of the second test case kernel module to obtain the running data of the to-be-verified system kernel data, and verify the running data of the to-be-verified system kernel data to determine the target system kernel data.

[0144] As can be seen from the above, the present application first obtains the kernel crash data of the system to be tested, obtains the first address of the faulty function therefrom, determines the test case function according to the faulty function, replaces the first address of the faulty function with the second address of the test case function to obtain the test case kernel data; based on this data, obtains the KO file of the first test case kernel module, runs the KO file to obtain the test case crash data, thereby determining the kernel fault cause, and then determines the patch function according to the faulty function and the kernel fault cause, replaces the faulty function in the kernel of the system to be tested with the patch function to obtain the system kernel data to be verified; obtains the KO file of the second test case kernel module according to the system kernel data to be verified, runs the KO file to obtain the running data of the system kernel data to be verified, and verifies the running data to determine the target system kernel data. In this way, the present application verifies the kernel module through the test case kernel module that reproduces the fault and the solution to solve the fault, writes the test case kernel module, reproduces the kernel fault, writes the solution patch kernel module, and verifies the kernel fault solution, realizing the function of quickly reproducing and solving the operating system kernel fault, improving the timeliness of solving the operating system kernel problem, and providing higher system stability for applications such as cloud computing, big data, databases, and AI large models.

[0145] In some specific embodiments, the test case kernel data acquisition module 11 may specifically include:

[0146] A log acquisition unit, configured to acquire the kernel log and / or the kernel crash file of the kernel of the system to be tested;

[0147] A crash data and kernel crash stack acquisition unit, configured to analyze the kernel log or the kernel crash file of the kernel of the system to be tested by using a preset Crash tool to obtain the crash data and the kernel crash stack of the kernel of the system to be tested;

[0148] A first address acquisition unit, configured to analyze the crash data and the kernel crash stack of the kernel of the system to be tested based on the KProbe technology to obtain the first address of the corresponding faulty function in the kernel of the system to be tested.

[0149] In some specific embodiments, the test case kernel data acquisition module 11 may specifically include:

[0150] A test case function determination unit, configured to determine the corresponding test case function according to the faulty function in the kernel of the system to be tested;

[0151] A test case kernel data acquisition unit is used to filter the faulty functions in the kernel of the system under test based on a preset filtering instruction function of a preset FTrace operation object instance, and use the callback function of the preset FTrace operation object instance to jump the first address of the faulty function in the kernel of the system under test to the second address of the test case function, so as to obtain test case kernel data.

[0152] In some specific embodiments, the kernel data acquisition module 12 of the system to be tested may specifically include:

[0153] A KO file acquisition unit is used to perform a preset compilation and build operation on the test case kernel data to obtain a KO file of the first test case kernel module.

[0154] In some specific embodiments, the kernel data acquisition module 12 of the system to be tested may specifically include:

[0155] A test case crash data acquisition unit is used to install and run the KO file of the first test case kernel module by using a preset insmod command to obtain test case crash data;

[0156] A data comparison unit is used to compare the test case crash data with the crash data of the kernel of the system under test;

[0157] A first comparison determination unit is used to, if the obtained comparison result indicates that the test case crash data is consistent with the crash data of the kernel of the system under test, determine the kernel fault cause of the kernel of the system under test based on the test case crash data;

[0158] A second comparison determination unit is used to, if the obtained comparison result indicates that the test case crash data is inconsistent with the crash data of the kernel of the system under test, re-jump to the step of determining the corresponding test case function according to the faulty function in the kernel of the system under test.

[0159] In some specific embodiments, the kernel data acquisition module 12 of the system to be tested may specifically include:

[0160] A patch function writing unit is used to write a corresponding patch function based on the faulty function and the kernel fault cause in the kernel of the system under test by using a preset livepatch technology;

[0161] An information registration unit is used to register the information of the patch function;

[0162] A kernel data acquisition unit of the system to be tested is used to replace the faulty function in the kernel of the system under test with the patch function based on the information of the patch function to obtain the kernel data of the system to be tested.

[0163] In some specific embodiments, the target system kernel data determination module 13 may specifically include:

[0164] An operation data judgment unit, configured to verify whether the operation data of the to-be-verified system kernel data meets a preset system kernel fault condition;

[0165] A first to-be-verified system kernel data determination unit, configured to determine the to-be-verified system kernel data as the target system kernel data if the to-be-verified system kernel data does not meet the preset system kernel fault condition;

[0166] A second to-be-verified system kernel data determination unit, configured to, if the to-be-verified system kernel data meets the preset system kernel fault condition, re-jump to the step of determining a corresponding patch function based on the fault function and the kernel fault cause in the to-be-tested system kernel.

[0167] Furthermore, an embodiment of the present application also discloses an electronic device, Figure 4 which is a structural diagram of an electronic device 20 shown according to an exemplary embodiment. The content in the figure should not be regarded as any limitation to the scope of use of the present application.

[0168] Figure 4 This is a schematic structural diagram of an electronic device 20 provided by an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the system kernel fault solution method disclosed in any of the foregoing embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0169] In this embodiment, the power supply 23 is used to provide a working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of the present application, and specific limitations are not imposed on it here; the input / output interface 25 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application needs, and specific limitations are not imposed here.

[0170] In addition, as a carrier for resource storage, the memory 22 may be a read-only memory, a random access memory, a magnetic disk, or an optical disc, etc. The resources stored thereon may include an operating system 221, a computer program 222, etc., and the storage method may be short-term storage or permanent storage.

[0171] Among them, the operating system 221 is used to manage and control each hardware device and computer program 222 on the electronic device 20, and it can be Windows Server, Netware, Unix, Linux, etc. In addition to the computer program that can be used to complete the system kernel fault resolution method executed by the electronic device 20 disclosed in any of the foregoing embodiments, the computer program 222 may further include computer programs that can be used to complete other specific tasks.

[0172] Furthermore, the present application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the system kernel fault resolution method disclosed above. For the specific steps of this method, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details will not be repeated here.

[0173] In this specification, each embodiment is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other. For the device disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple, and reference can be made to the description of the method part for related parts.

[0174] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0175] The steps of the method or algorithm described in combination with the embodiments disclosed in this article can be directly implemented by hardware, a software module executed by a processor, or a combination of the two. The software module can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, register, hard disk, removable disk, CD-ROM, or any other form of storage medium well-known in the technical field.

[0176] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, article or device comprising said element.

[0177] The technical solutions provided in this application have been introduced in detail above. Specific examples are used in this text to elaborate on the principles and implementation manners of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to this application.

Claims

1. A method for solving system kernel faults, characterized in that, Including: Obtain the crash data of the kernel of the system under test, obtain the first address of the corresponding faulty function in the kernel of the system under test based on the crash data of the kernel of the system under test, determine the corresponding test case function according to the faulty function in the kernel of the system under test, and replace the first address of the faulty function in the kernel of the system under test with the second address of the test case function to obtain test case kernel data; Obtain the KO file of the first test case kernel module based on the test case kernel data, run the KO file of the first test case kernel module to obtain test case crash data to determine the kernel fault cause of the kernel of the system under test, determine the corresponding patch function based on the faulty function and the kernel fault cause in the kernel of the system under test, and replace the faulty function in the kernel of the system under test with the patch function to obtain the system kernel data to be verified; Obtain the KO file of the second test case kernel module according to the system kernel data to be verified, run the KO file of the second test case kernel module to obtain the running data of the system kernel data to be verified, and verify the running data of the system kernel data to be verified to determine the target system kernel data.

2. The system kernel fault resolution method according to claim 1, characterized in that The obtaining the crash data of the kernel of the system under test and obtaining the first address of the corresponding faulty function in the kernel of the system under test based on the crash data of the kernel of the system under test includes: Obtain the kernel log and / or kernel crash file of the kernel of the system under test; Use a preset Crash tool to analyze the kernel log or kernel crash file of the kernel of the system under test to obtain the crash data of the kernel of the system under test and the kernel crash stack; Based on the KProbe technology, analyze the crash data of the kernel of the system under test and the kernel crash stack to obtain the first address of the corresponding faulty function in the kernel of the system under test.

3. The system kernel fault resolution method according to claim 1, wherein The determining the corresponding test case function according to the faulty function in the kernel of the system under test and replacing the first address of the faulty function in the kernel of the system under test with the second address of the test case function to obtain test case kernel data includes: Determine the corresponding test case function according to the faulty function in the kernel of the system under test; Filter the faulty function in the kernel of the system under test based on the preset filtering instruction function of the preset FTrace operation object instance, and use the callback function of the preset FTrace operation object instance to jump the first address of the faulty function in the kernel of the system under test to the second address of the test case function to obtain test case kernel data.

4. The system kernel failure resolution method according to claim 1, wherein The obtaining the KO file of the first test case kernel module based on the test case kernel data includes: Perform a preset compilation and build operation on the test case kernel data to obtain the KO file of the first test case kernel module.

5. The system kernel failure solution method according to claim 1, characterized in that The running the KO file of the first test case kernel module to obtain test case crash data to determine the kernel fault cause of the kernel of the system under test includes: Use the preset insmod command to install and run the KO file of the first test case kernel module to obtain test case crash data; Compare the test case crash data with the crash data of the kernel of the system under test; If the obtained comparison result indicates that the test case crash data is consistent with the crash data of the kernel of the system under test, determine the kernel fault cause of the kernel of the system under test based on the test case crash data; If the obtained comparison result indicates that the test case crash data is inconsistent with the crash data of the kernel of the system under test, re-jump to the step of determining the corresponding test case function according to the fault function in the kernel of the system under test.

6. The system kernel fault resolution method according to claim 1, characterized in that, The determining the corresponding patch function based on the fault function and the kernel fault cause in the kernel of the system under test, and replacing the fault function in the kernel of the system under test with the patch function to obtain the system kernel data to be verified includes: Writing a corresponding patch function based on the fault function and the kernel fault cause in the kernel of the system under test by using the preset livepatch technology; Registering the information of the patch function; Replacing the fault function in the kernel of the system under test with the patch function based on the information of the patch function to obtain the system kernel data to be verified.

7. The system kernel fault resolution method according to any one of claims 1 to 6, characterized in that The verifying the running data of the system kernel data to be verified to determine the target system kernel data includes: Verifying whether the running data of the system kernel data to be verified meets the preset system kernel fault condition; If the system kernel data to be verified does not meet the preset system kernel fault condition, determine the system kernel data to be verified as the target system kernel data; If the system kernel data to be verified meets the preset system kernel fault condition, re-jump to the step of determining the corresponding patch function based on the fault function and the kernel fault cause in the kernel of the system under test.

8. A system kernel fault resolution device, characterized in that, including: A test case kernel data acquisition module, configured to acquire the crash data of the kernel of the system under test, obtain the first address of the corresponding fault function in the kernel of the system under test based on the crash data of the kernel of the system under test, determine the corresponding test case function according to the fault function in the kernel of the system under test, and replace the first address of the fault function in the kernel of the system under test with the second address of the test case function to obtain the test case kernel data; A system kernel data to be verified acquisition module, configured to obtain the KO file of the first test case kernel module based on the test case kernel data, run the KO file of the first test case kernel module to obtain the test case crash data, determine the kernel fault cause of the kernel of the system under test, determine the corresponding patch function based on the fault function and the kernel fault cause in the kernel of the system under test, and replace the fault function in the kernel of the system under test with the patch function to obtain the system kernel data to be verified; A target system kernel data determination module, configured to obtain a KO file of a second test case kernel module according to the to-be-verified system kernel data, run the KO file of the second test case kernel module to obtain the running data of the to-be-verified system kernel data, and verify the running data of the to-be-verified system kernel data to determine the target system kernel data.

9. An electronic device, characterized in that, Comprising: A memory, configured to store a computer program; A processor, configured to execute the computer program to implement the system kernel fault resolution method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, For storing a computer program; wherein, when the computer program is executed by the processor, the system kernel fault resolution method according to any one of claims 1 to 7 is implemented.