Linux important process monitoring method and device

By building a process tree system and an error defense system, important Linux processes are decoupled, which solves the problem of high coupling between monitoring logic and business processes, and achieves millisecond fault response and low resource consumption monitoring effects.

CN120523686APending Publication Date: 2025-08-22HENAN ZHONGYUAN CONSUMER FINANCE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510687543.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-08-22

AI Technical Summary

Technical Problem

In the prior art, the monitoring methods of important Linux processes have problems such as excessive coupling between monitoring logic and business processes, large resource occupation of third-party monitoring tools, and delay in process status detection.

Method used

By building a process tree system, decoupling the parent process and the child process, using the waitpid system call to capture the state changes of the child process, combining the error defense system for resource leakage protection and environmental isolation, and realizing the automatic restart mechanism.

Benefits of technology

Achieves millisecond fault response, reduces resource consumption, simplifies deployment process, and enhances monitoring reliability and scalability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120523686A_ABST
    Figure CN120523686A_ABST
Patent Text Reader

Abstract

The invention relates to the field of process monitoring, in particular to a Linux important process monitoring method and device.The method comprises the steps that a process tree system is built, and a parent process and child processes are decoupled; the parent process waits for the state change of the child process through waitpid blocking, captures an exit signal of the child process, and immediately triggers an automatic restart mechanism when it is detected that the child process is abnormally terminated; and according to the error defense system, performing resource leakage protection processing and environment isolation processing on the independent operation spaces of the parent process and the child process. The method has the advantages that the real-time performance is improved, the resource consumption is reduced, the reliability is enhanced, the deployment is simplified, and the expandability is high.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of process monitoring, and in particular to a method and device for monitoring important Linux processes. Background Art

[0002] In the existing technology, scheduled task detection technology, dual-process mutual inspection technology and monitoring tools are usually used to monitor important Linux processes. Among them, the scheduled task detection technology is to detect the process status by regularly executing scripts through crontab, but there is a time window period for scheduled task detection and it cannot respond to process anomalies in real time; the dual-process mutual inspection technology is for two business processes to monitor each other's operating status, but the dual-process mutual inspection technology has the problem of increasing system complexity and may cause race conditions when the process is abnormal; monitoring tools include but are not limited to using third-party monitoring tools and process management tools to monitor important processes, but third-party monitoring tools or process management tools require additional installation and maintenance, which increases resource consumption and learning costs. In summary, the existing technology generally has the problem of excessive coupling between monitoring logic and business processes.

[0003] To this end, the present application provides a method and device for monitoring important Linux processes. Summary of the Invention

[0004] To overcome the above-mentioned shortcomings, the present invention aims to provide a lightweight, low-resource-consuming Linux important process monitoring method and device, which is used to solve the problems in the existing technology such as excessive coupling between monitoring logic and business processes, large resource usage of third-party monitoring tools, and delays in process status detection, and can achieve seamless automatic restart protection of key business processes.

[0005] According to one aspect of the present invention, a method for monitoring important Linux processes is provided, comprising: constructing a process tree system and decoupling parent processes and child processes; The parent process blocks and waits for the child process status change through waitpid, captures the child process's exit signal, and immediately triggers the automatic restart mechanism when it detects that the child process terminates abnormally; According to the error defense system, resource leakage protection and environment isolation are performed on the independent running spaces of the parent process and the child process.

[0006] In some optional implementations of some embodiments, constructing a process tree system and decoupling the parent process and the child process includes: According to the parent process creation mechanism, fork is used to create a child process, a PID assigned to the child process is established for the child process and a monitoring loop is entered. The child process executes the target program through execv to build a process tree system; the parent process executes the dual identity separation mechanism through fork, and the child process executes the process image reconstruction through execv to achieve decoupling of the parent process and the child process.

[0007] In some optional implementations of some embodiments, the parent process executes a dual identity separation mechanism through fork, including: The parent process performs branch identification detection of the parent process and the child process through triple judgment of the fork() return value to separate the execution paths of the parent process and the child process; The child process obtains a copy of the parent process and combines the Copy-On-Write technology to optimize memory usage to achieve address space isolation between the parent and child processes.

[0008] In some optional implementations of some embodiments, the child process performs process image reconstruction through execv, including: Parameter reconstruction: define argv[0] as the program name following Unix conventions and terminate argv with a NULL pointer; Environment variables: The child process inherits the environment variables of the parent process, or sets the target environment of the child process through execle; Error protection processing: Use _exit() to terminate the failed child process to avoid repeated operations on the standard library buffer.

[0009] In some optional implementations of some embodiments, the parent process blocks and waits for the child process status change through waitpid, and captures the child process exit signal, including: The process state capture matrix is ​​used to perform real-time monitoring of the state monitoring dimensions including normal exit detection, signal termination analysis, and pause state processing. For the state monitoring dimension of normal exit detection, the WIFEXITED macro is used to determine whether the child process terminates naturally. For the state monitoring dimension of signal termination analysis, the WTERMSIG is used to analyze the signal type that causes termination. For the state monitoring dimension of pause state processing, pause processing is performed for SIGSTOP or SIGTSTP signals.

[0010] In some optional implementations of some embodiments, the automatic restart mechanism includes: Progressive delay: uses an exponential backoff algorithm to avoid frequent restart storms; Fuse protection: When the maximum number of retries is reached, an alarm is triggered and monitoring is terminated; State persistence: Save the abnormal exit history of the child process for fault analysis.

[0011] In some optional implementations of some embodiments, performing resource leakage protection and environment isolation processing on the independent running spaces of the parent process and the child process according to the error defense system includes: Register the SIGCHLD signal handler to non-block the terminated child process to clear the zombie child process; Use SA_NOCLDSTOP to mask the child process's pause signal to avoid receiving the child process's pause signal; The system call is restarted through the SA_RESTART flag to ensure that the interrupted system call is automatically restored; Use unshare() to create an independent PID namespace to isolate the namespaces of the parent process and the child process; Use chroot to limit the scope of file access to implement file system protection for parent and child processes; Use setrlimit() to disable core dumps and to limit the memory resource usage of the parent and child processes.

[0012] According to a second aspect of the present invention, there is provided a monitoring device for an important Linux process, comprising: The process tree system construction and process decoupling processing module is used to build the process tree system and decouple the parent process and child process; The real-time monitoring module is used for the parent process to wait for the child process status change through waitpid blocking, capture the child process exit signal, and immediately trigger the automatic restart mechanism when the child process is detected to have terminated abnormally; The error defense system module is used to perform resource leakage protection and environment isolation processing on the independent running spaces of the parent process and the child process according to the error defense system.

[0013] According to a third aspect of the present invention, an electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above method when executing the computer program.

[0014] According to a fourth aspect of the present invention, there is provided a computer-readable storage medium storing a computer program, which implements the steps of the above method when executed by a processor.

[0015] The present application provides a method and device for monitoring important Linux processes, which have the following beneficial effects: (1) Improved real-time performance: compared with traditional minute-level detection, it can achieve millisecond-level fault response; (2) Reduced resource consumption: only a monitoring process with a memory usage of about 100KB needs to be maintained; (3) Enhanced reliability: through the waitpid system call, the problem of residual zombie processes is successfully solved; (4) Simplified deployment: no additional components need to be installed, and it is compatible with all Linux distributions; (5) Strong scalability: the monitoring of multiple key processes can be managed through configuration. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 The figure is a flowchart of a method for monitoring important Linux processes in an embodiment of the present invention.

[0017] Figure 2 This is a state transition diagram of a process in an embodiment of the present invention.

[0018] Figure 3 2 is a structural diagram of a monitoring device for important Linux processes in an embodiment of the present invention.

[0019] Figure 4 Schematic diagram of an electronic device in an embodiment of the present invention. DETAILED DESCRIPTION

[0020] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below through specific embodiments in conjunction with the accompanying drawings. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0021] Example 1 Reference Attachment Figure 1 and attached Figure 2 , this application provides a method for monitoring important Linux processes, which specifically includes the following steps.

[0022] S1: Build a process tree system and decouple the parent process and child process.

[0023] In some embodiments, constructing a process tree system and decoupling parent processes and child processes includes: According to the parent process creation mechanism, fork is used to create a child process, the PID assigned to the child process is established for the child process and enters the monitoring loop. The child process executes the target program through execv to build a process tree system; The parent process executes the dual identity separation mechanism through fork, and the child process executes process image reconstruction through execv to achieve decoupling of the parent process and the child process.

[0024] In some embodiments, the important processes involved in this application specifically refer to target programs that need to be monitored based on actual needs.

[0025] In some embodiments, the parent process executes a dual identity separation mechanism through fork, including: The parent process performs branch identification detection of the parent process and the child process through triple judgment of the fork() return value to separate the execution paths of the parent process and the child process; The child process obtains a copy of the parent process and combines the Copy-On-Write technology to optimize memory usage to achieve address space isolation between the parent and child processes.

[0026] In some embodiments, during the branch identification detection process, a triple judgment is made through the fork() return value, specifically when the fork() return value is -1, it is identified as an error handling branch, when the fork() return value is 0, it is identified as entering the child process space, and when the fork() return value is a positive number, it is identified as entering the parent process space, so as to achieve the separation of the parent and child process execution paths.

[0027] In some embodiments, during the address space isolation process, the child process obtains a copy of the parent process and uses Copy-On-Write technology to optimize memory usage.

[0028] In some embodiments, the code implementation process for decoupling the parent process and the child process is as follows: pid_t child_pid = fork(); / / Generate branch point switch(child_pid) { case -1: / / Error handling branch handle_fork_error(); break; case 0: / / child process space reconstruct_process_image(); / / Perform image replacement break; default: / / parent process space establish_monitoring_loop(); / / Enter monitoring state }.

[0029] In some embodiments, the child process performs process image reconstruction through execv, including: Parameter reconstruction: define argv[0] as the program name following Unix conventions and terminate argv with a NULL pointer; Environment variables: The child process inherits the environment variables of the parent process, or sets the target environment of the child process through execle; Error protection processing: Use _exit() to terminate the failed child process to avoid repeated operations on the standard library buffer.

[0030] In some embodiments, for the argument reconstruction rule, argv[0] is set to the program name following Unix convention, and argv is terminated with a NULL pointer.

[0031] In some embodiments, for the environment inheritance strategy, the child process inherits the environment variables of the parent process by default, and can also implement the setting of the preset environment through execle.

[0032] In some embodiments, for the error protection mechanism, _exit() is used to terminate the failed child process to avoid repeated operations on the standard library buffer.

[0033] In some embodiments, the code implementation process of the child process performing process image reconstruction through execv is as follows: void reconstruct_process_image(const char* target_path) { char* const argv[] = {basename(target_path), NULL}; / / parameter reconstruction char* const envp[] = {"LANG=en_US.UTF-8",NULL}; / / Environment variables execv(target_path, argv); / / Exact path execution execvp(target_path, argv); / / Automatic path search / / Exception handling section perror("Exec failed"); _exit(EXIT_FAILURE); / / Use _exit to avoid repeated flushing of the buffer }.

[0034] S2: The parent process blocks and waits for the child process status change through waitpid, captures the child process's exit signal, and immediately triggers the automatic restart mechanism when it detects that the child process terminates abnormally.

[0035] In some embodiments, the parent process blocks and waits for the child process status change through waitpid, and captures the child process exit signal, including: A process state capture matrix is ​​used to perform real-time monitoring of state monitoring dimensions, including normal exit detection, signal termination analysis, and pause state processing. For the normal exit detection state monitoring dimension, the WIFEXITED macro is used to determine whether the child process terminates naturally. For the signal termination analysis state monitoring dimension, WTERMSIG is used to parse the signal type that causes termination (such as SIGSEGV / SIGKILL signals). For the pause state processing state monitoring dimension, pause processing is performed for SIGSTOP or SIGTSTP signals.

[0036] In some embodiments, the code implementation process of process status monitoring is as follows: while(1) { int status; pid_t waited_pid = waitpid(child_pid,&status, WUNTRACED); if(waited_pid == -1) { / / Error handling if(errno == ECHILD) { log_error("No child processes"); break; } continue; } / / Status decoder if(WIFEXITED(status)) { record_exit_code(WEXITSTATUS(status)); } else if(WIFSIGNALED(status)) { analyze_signal(WTERMSIG(status)); } else if(WIFSTOPPED(status)) { handle_stopped_state(WSTOPSIG(status)); } }.

[0037] In some embodiments, the automatic restart mechanism includes: Progressive delay: uses an exponential backoff algorithm to avoid frequent restart storms; Fuse protection: When the maximum number of retries is reached, an alarm is triggered and monitoring is terminated; State persistence: Save the abnormal exit history of the child process for fault analysis.

[0038] In some embodiments, the code implementation process of the automatic restart mechanism is as follows: struct restart_policy { int max_retries; / / Maximum number of retries int backoff_base; / / backoff base (seconds) int current_retry = 0; }; void apply_restart_policy(struct restart_policy* policy) { if(policy->current_retry++>= policy->max_retries) { trigger_alert("Max restart attempts reached"); exit(EXIT_FAILURE); } int delay = policy->backoff_base * (1< <policy->current_retry); sleep(min(delay, MAX_BACKOFF)); / / Exponential backoff algorithm }.

[0039] S3: Based on the error defense system, resource leakage protection and environment isolation are performed on the independent running spaces of the parent process and child process.

[0040] In some embodiments, resource leakage protection processing mainly includes zombie child process clearing, signal mask setting, and system call restart.

[0041] In some embodiments, for zombie child process removal, a SIGCHLD signal handler is registered to non-blockingly recycle the terminated child process to remove the zombie child process.

[0042] In some embodiments, for signal mask setting, SA_NOCLDSTOP is used to set a mask for the pause signal of the child process to avoid receiving the child process pause signal.

[0043] In some embodiments, for system call restart, the SA_RESTART flag is used to restart the system call to ensure that the interrupted system call is automatically restored.

[0044] In some embodiments, the code implementation process of resource leak protection processing is as follows: void zombie_cleaner(int sig) { while(waitpid(-1, NULL, WNOHANG)>0); / / Non-blocking recovery } void install_signal_handlers() { struct sigaction sa; sa.sa_handler = zombie_cleaner; sigemptyset(&sa.sa_mask); sa.sa_flags = SA_RESTART | SA_NOCLDSTOP; if(sigaction(SIGCHLD,&sa, NULL) == -1) { perror("Signal handler setup failed"); } }.

[0045] In some embodiments, environment isolation processing mainly includes namespace isolation, file system protection and resource limitation.

[0046] In some embodiments, for namespace isolation, unshare() is used to create an independent PID namespace to achieve namespace isolation for the parent process and the child process.

[0047] In some embodiments, for file system protection, chroot is used to limit the scope of file access to implement file system protection for parent processes and child processes.

[0048] In some embodiments, for resource limiting, setrlimit() is used to disable core dumps to limit the memory resource usage of the parent process and the child process.

[0049] In some embodiments, the code implementation process of the environment isolation process is as follows: void create_safe_sandbox() { if(unshare(CLONE_NEWPID)<0) { / / Create an independent PID namespace perror("Namespace isolation failed"); } if(chdir(" / sandbox")<0) { / / Working directory isolation perror("Chroot failed"); } setrlimit(RLIMIT_CORE,&(struct rlimit){0,0}); / / disable core dump }.

[0050] In summary, the present application provides a monitoring method for important Linux processes, which can form an independent management relationship between the monitoring process and the business process through the decoupling design of the parent and child processes; by setting up a real-time monitoring mechanism, the exit status of the child process can be accurately captured using waitpid; by setting up an automatic restart mechanism, the resident memory of the monitoring process is used to ensure that an immediate response can be made after the child process is abnormal; by utilizing the resource isolation feature, the independent running spaces of the parent and child processes can be avoided from affecting each other.

[0051] Example 2 This embodiment provides a monitoring device 200 for important Linux processes based on the above embodiment 1. Figure 3 , used to implement the steps of a monitoring method for an important Linux process described in the above embodiment 1, the device mainly includes: a process tree system construction and process decoupling processing module 201, a real-time monitoring module 202, and an error defense system module 203.

[0052] In some embodiments, the process tree system construction and process decoupling processing module 201 is used to construct a process tree system and decouple the parent process and the child process; In some embodiments, the real-time monitoring module 202 is used for the parent process to wait for the child process status change through waitpid blocking, capture the child process's exit signal, and immediately trigger the automatic restart mechanism when detecting the abnormal termination of the child process; In some embodiments, the error defense system module 203 is used to perform resource leakage protection processing and environment isolation processing on the independent running spaces of the parent process and the child process according to the error defense system.

[0053] Example 3 This embodiment further provides an electronic device based on the above embodiment 1. Figure 4 , Figure 4 The electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.

[0054] like Figure 4 As shown, the electronic device may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 301, which can perform various appropriate actions and processes based on programs stored in a read-only memory (ROM) 302 or programs loaded from a storage device 308 into a random access memory (RAM) 303. RAM 303 also stores various programs and data required for the operation of the electronic device. Processing device 301, ROM 302, and RAM 303 are interconnected via a bus 304. An input / output (I / O) interface 305 is also connected to bus 304.

[0055] Typically, the following devices may be connected to the I / O interface 305: an input device 306 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, etc., an output device 307 including, for example, a liquid crystal display (LCD), a speaker, etc., a storage device 308 including, for example, a magnetic tape, a hard disk, etc., and a communication device 309. The communication device 309 may allow the electronic device to communicate with other devices wirelessly or by wire to exchange data. Figure 4 The electronic device is shown with various devices, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead. Figure 4 Each block shown in the figure may represent one device, or may represent multiple devices as needed.

[0056] In particular, according to some embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, some embodiments of the present disclosure include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In some such embodiments, the computer program can be downloaded and installed from a network via the communication device 309, or installed from the storage device 308, or installed from the ROM 302. When the computer program is executed by the processing device 301, the above-mentioned functions defined in the method of some embodiments of the present disclosure are performed.

[0057] Example 4 Based on the above-mentioned embodiment 1, this embodiment further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps of the above-mentioned method are implemented.

[0058] It should be noted that in some embodiments of the present disclosure, the computer-readable medium described above may be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. Computer-readable storage media may include, for example, but not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In some embodiments of the present disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device, or component. Furthermore, in some embodiments of the present disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. This propagated data signal may take a variety of forms, including, but not limited to, electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device. Program code embodied on a computer-readable medium may be transmitted using any suitable medium, including but not limited to wire, optical cable, RF (radio frequency), or any suitable combination thereof.

[0059] In this embodiment, the client and server may communicate using any currently known or later developed network protocol, such as HTTP (HyperText Transfer Protocol), and may be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or later developed network.

[0060] The computer-readable medium may be included in the apparatus or may exist independently without being incorporated into the electronic device. The computer-readable medium carries one or more programs. When executed by the electronic device, the electronic device: obtains training data and converts the training data into initial data; determines an initial rule base based on the initial data and optimizes the parameters of the initial rule base to obtain a target rule base; calculates activation weights for the rules in the target rule base according to a preset activation weight calculation formula; and determines abnormal information based on the test data and the activation weights.

[0061] Computer program code for performing the operations of some embodiments of the present disclosure may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, C++, and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0062] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0063] The units described in some embodiments of the present disclosure may be implemented in software or hardware. The units described may also be provided in a processor. For example, they may be described as follows: a processor comprising a data acquisition unit, a rule determination unit, a weight calculation unit, and an anomaly determination unit. The names of these units do not, in some cases, limit the units themselves. For example, the data acquisition unit may also be described as a "unit for acquiring training data."

[0064] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), and the like.

[0065] Obviously, those skilled in the art will appreciate that the various steps of the present invention described above can be performed in different ways than the present invention, and that simulation methods and experimental equipment include but are not limited to those described above. The various steps of the present invention described above can, in some cases, be performed in a different order than that shown here, and the steps shown or described above can be performed separately. Therefore, the present invention is not limited to any particular combination of hardware and software.

[0066] The above content is a further detailed description of the present invention in conjunction with specific embodiments, and the specific implementation of the present invention cannot be considered to be limited to these descriptions. For those skilled in the art of the present invention, without departing from the concept of the present invention, several simple deductions or substitutions can be made, which should be considered to fall within the scope of protection of the present invention.

Claims

1. A method for monitoring important Linux processes, characterized in that: include: Build a process tree system and decouple the parent process and child process; The parent process blocks and waits for the child process status change through waitpid, captures the child process's exit signal, and immediately triggers the automatic restart mechanism when it detects that the child process terminates abnormally; According to the error defense system, resource leakage protection and environment isolation are performed on the independent running spaces of the parent process and the child process.

2. A method for monitoring important Linux processes according to claim 1, characterized in that: The process tree system is constructed and the parent process and child process are decoupled, including: According to the parent process creation mechanism, fork is used to create a child process, the PID assigned to the child process is established for the child process and enters the monitoring loop. The child process executes the target program through execv to build a process tree system; The parent process executes the dual identity separation mechanism through fork, and the child process executes process image reconstruction through execv to achieve decoupling of the parent process and the child process.

3. A method for monitoring important Linux processes according to claim 2, characterized in that: The parent process executes a dual identity separation mechanism through fork, including: The parent process performs branch identification detection of the parent process and the child process through triple judgment of the fork() return value to separate the execution paths of the parent process and the child process; The child process obtains a copy of the parent process and combines the Copy-On-Write technology to optimize memory usage to achieve address space isolation between the parent and child processes.

4. A method for monitoring important Linux processes according to claim 2, characterized in that: The child process performs process image reconstruction through execv, including: Parameter reconstruction: define argv[0] as the program name following Unix conventions and terminate argv with a NULL pointer; Environment variables: The child process inherits the environment variables of the parent process, or sets the target environment of the child process through execle; Error protection processing: Use _exit() to terminate the failed child process to avoid repeated operations on the standard library buffer.

5. The method for monitoring important Linux processes according to claim 1, wherein: The parent process blocks and waits for the child process status to change through waitpid, and captures the child process's exit signal, including: The process state capture matrix is ​​used to perform real-time monitoring of the state monitoring dimensions including normal exit detection, signal termination analysis, and pause state processing. For the state monitoring dimension of normal exit detection, the WIFEXITED macro is used to determine whether the child process terminates naturally. For the state monitoring dimension of signal termination analysis, the WTERMSIG is used to analyze the signal type that causes termination. For the state monitoring dimension of pause state processing, pause processing is performed for SIGSTOP or SIGTSTP signals.

6. A method for monitoring important Linux processes according to claim 1, characterized in that: The automatic restart mechanism includes: Progressive delay: uses an exponential backoff algorithm to avoid frequent restart storms; Fuse protection: When the maximum number of retries is reached, an alarm is triggered and monitoring is terminated; State persistence: Save the abnormal exit history of the child process for fault analysis.

7. A method for monitoring important Linux processes according to claim 1, characterized in that: According to the error defense system, resource leakage protection and environment isolation processing are performed on the independent running spaces of the parent process and the child process, including: Register the SIGCHLD signal handler to non-block the terminated child process to clear the zombie child process; Use SA_NOCLDSTOP to mask the child process's pause signal to avoid receiving the child process's pause signal; The system call is restarted through the SA_RESTART flag to ensure that the interrupted system call is automatically restored; Use unshare() to create an independent PID namespace to isolate the namespaces of the parent process and the child process; Use chroot to limit the scope of file access to implement file system protection for parent and child processes; Use setrlimit() to disable core dumps and to limit the memory resource usage of the parent and child processes.

8. A monitoring device for important Linux processes, characterized in that: include: The process tree system construction and process decoupling processing module is used to build the process tree system and decouple the parent process and child process; The real-time monitoring module is used for the parent process to wait for the child process status change through waitpid blocking, capture the child process exit signal, and immediately trigger the automatic restart mechanism when the child process is detected to have terminated abnormally; The error defense system module is used to perform resource leakage protection and environment isolation processing on the independent running spaces of the parent process and the child process according to the error defense system.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.