Online isolation method, device and equipment for central processing unit, and medium
By adjusting the scheduling domain mask through external drivers and hot patches, online isolation of the central processing unit is achieved, solving the problem of CPU resources being unable to be sold, reducing labor costs and improving resource sales rates.
Patent Information
- Application Number
- CN202410257656.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-06
- Publication Date
- 2025-09-09
Smart Images

Figure CN120610771A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technology, and in particular to a method, apparatus, device, and medium for online isolation of a central processing unit (CPU). Background Art
[0002] In the prior art, when a host machine starts a virtual machine, the central processing unit (CPU) allocated to the virtual machine is divided into an isolation domain (i.e., the CPU is set to the isolated state) and a scheduling domain (i.e., the CPU is not set to the isolated state). Programs running on the isolation domain are not interfered with by other processes scheduled by the scheduler, and other processes will not be scheduled to run on this CPU. The CPU resources of the scheduling domain must meet the operating requirements of regular system processes, resulting in the CPU resources in the scheduling domain being unable to be sold, resulting in a low resource sales rate.
[0003] Typically, after optimizing programs running on the allowed scheduling domain, CPU resources can be released for sale. The sold CPU resources can only achieve relatively stable performance when they are in an isolated state on a specific machine model. However, existing technologies require restarting the host machine or migrating the virtual machines of the source host machine to a new host machine that has been optimized and started. Restarting the host machine will cause the cloud host instance business to be forced to be interrupted, and migrating the virtual machines of the source host machine to the new host machine that has been optimized and started requires frequent stocking, which has high labor costs.
[0004] Therefore, a CPU online isolation method is urgently needed to solve the above problems. Summary of the Invention
[0005] In order to solve the above technical problems or at least partially solve the above technical problems, the present disclosure provides a central processing unit online isolation method, device, equipment and medium to avoid CPU resource waste, reduce labor costs, and improve CPU resource sales rate.
[0006] In a first aspect, an embodiment of the present disclosure provides a method for online isolation of a central processing unit, comprising:
[0007] Creating a virtual file system interface through an external driver, and obtaining a callback function through the virtual file system interface;
[0008] Adjusting the scheduling domain mask through the callback function and the hot patch to obtain the isolation domain target mask;
[0009] Determine a CPU to be isolated as a target CPU, determine a target process on the target CPU, and drive the target process away from the target CPU, wherein the target CPU is in the original allowed scheduling domain;
[0010] The scheduling domain is rebuilt according to the isolation domain target mask to achieve online isolation of the target central processing unit.
[0011] In some embodiments, before creating the virtual file system interface through the external driver, the method further includes: initializing a scheduling domain mask.
[0012] In some embodiments, initializing the scheduling domain mask includes:
[0013] Obtaining a target scheduling permission domain address and determining a value of the target scheduling permission domain;
[0014] Based on the value of the target allowed scheduling domain being empty, allocating space for the target allowed scheduling domain address, and assigning a value to the target allowed scheduling domain through the allowed scheduling core;
[0015] The isolation domain address and the original allowed scheduling domain address are obtained, space is allocated for the isolation domain address and the original allowed scheduling domain respectively, and a value is assigned to the original allowed scheduling domain through the allowed scheduling core.
[0016] In some embodiments, adjusting the scheduling domain mask through the callback function and the hot patch to obtain the isolation domain target mask includes:
[0017] Setting the target CPU via the callback function;
[0018] Loading the hot patch through a dynamic kernel patch mechanism tool command;
[0019] According to the callback function of the virtual file system interface, the hot patch is called to adjust the scheduling domain mask to obtain the isolation domain target mask.
[0020] In some embodiments, determining a target process on the target central processor includes:
[0021] Traversing all processes on the target CPU;
[0022] For each of the processes, determining whether the process is a kernel process;
[0023] Based on the fact that the process is a non-kernel process, a target process on the target central processing unit is determined according to the scheduling domain mask and the isolation domain target mask.
[0024] In some embodiments, determining a target process on the target central processor includes:
[0025] Traverse all processes on the system;
[0026] For each of the processes, determining whether the process is a kernel process;
[0027] Based on the fact that the process is a non-kernel process, judging, according to the scheduling domain mask, whether the allowed scheduling domain of the process is the original allowed scheduling domain;
[0028] Based on the allowed scheduling domain of the process being the original allowed scheduling domain, the process is determined to be the target process.
[0029] In a second aspect, an embodiment of the present disclosure provides a central processing unit online isolation device, comprising:
[0030] A creation module is used to create a virtual file system interface through an external driver and obtain a callback function through the virtual file system interface;
[0031] An adjustment module is used to determine a target CPU to be isolated, and to adjust the scheduling domain mask through the virtual file system interface and the hot patch to obtain an isolation domain target mask;
[0032] an expulsion module, configured to determine a CPU to be isolated as a target CPU, determine a target process on the target CPU, and expel the target process from the target CPU, wherein the target CPU is in the original allowed scheduling domain;
[0033] A reconstruction module is used to reconstruct the scheduling domain according to the isolation domain target mask to achieve online isolation of the target central processing unit.
[0034] In a third aspect, an embodiment of the present disclosure provides an electronic device, including:
[0035] Memory;
[0036] processor; and
[0037] computer programs;
[0038] The computer program is stored in the memory and is configured to be executed by the processor to implement the method as described in the first aspect.
[0039] In a fourth aspect, an embodiment of the present disclosure provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program is executed by a processor to implement the method described in the first aspect.
[0040] In a fifth aspect, an embodiment of the present disclosure further provides a computer program product, which includes a computer program or instructions, and when the computer program or instructions are executed by a processor, the method described in the first aspect is implemented.
[0041] The embodiments of the present disclosure provide a method, apparatus, device and medium for online isolation of a central processing unit. The method creates a virtual file system interface through an external driver and obtains a callback function through the virtual file system interface. The method adjusts the scheduling domain mask through the callback function and the hot patch to obtain the isolation domain target mask. The central processing unit to be isolated is determined as the target central processing unit, the target process on the target central processing unit is determined, and the target process is driven away from the target central processing unit, wherein the target central processing unit is in the original allowed scheduling domain. The scheduling domain is rebuilt according to the isolation domain target mask to achieve online isolation of the target central processing unit. Compared with the prior art of restarting the host machine or resetting the source host machine, the method of The virtual machine is migrated to a new host machine that is optimized and started. The online isolation method for the central processing unit provided by the present invention creates a callback function obtained by the virtual file system interface through an external driver and adjusts the scheduling domain mask through a hot patch. The central processing unit to be isolated is determined as the target central processing unit, the target process on the target central processing unit is determined, the target process is driven away from the target central processing unit, and the scheduling domain is rebuilt according to the isolation domain target mask. The hot patch and external driver method are used, which is applicable to the old version of the kernel that has been online, and realizes the online isolation of the target central processing unit without restarting the host machine or migrating to a new host machine, thereby reducing labor costs and improving the resource sales rate of the central processing unit. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present disclosure and, together with the description, serve to explain the principles of the present disclosure.
[0043] In order to more clearly illustrate the embodiments of the present disclosure or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0044] Figure 1 A flowchart of a method for online isolation of a central processing unit provided in an embodiment of the present disclosure;
[0045] Figure 2 A schematic diagram of an application scenario provided by an embodiment of the present disclosure;
[0046] Figure 3 A schematic diagram of the structure of a central processing unit online isolation device provided in an embodiment of the present disclosure;
[0047] Figure 4 A schematic diagram of the structure of an electronic device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0048] In order to more clearly understand the above-mentioned objectives, features and advantages of the present disclosure, the scheme of the present disclosure will be further described below. It should be noted that the embodiments of the present disclosure and the features therein can be combined with each other in the absence of conflict.
[0049] In the following description, many specific details are set forth to facilitate a full understanding of the present disclosure, but the present disclosure may also be implemented in other ways different from those described herein; it is obvious that the embodiments in the specification are only part of the embodiments of the present disclosure, rather than all of the embodiments.
[0050] When a host machine launches a virtual machine, the central processing unit (CPU) allocated to the virtual machine is divided into an isolated domain and an allowed scheduling domain. The isolated domain is used by the host machine to ensure that programs such as the virtual machine and the Storage Performance Development Kit (SPDK) used by the customer are not interfered with by other processes. This is done by isolating the isolated central processing unit (CPU) from the Linux kernel scheduler's scheduling domain creation process. Conventional schedulers such as the Completely Fair Scheduler (CFS) cannot schedule ordinary processes to run on the isolated domain CPU, thus ensuring that processes on the isolated domain CPU are not interfered with by other processes. The allowed scheduling domain is used by the host machine where the virtual machine is running, requiring CPU resources to be reserved for regular system processes. These reserved CPU resources do not require isolation settings to meet the running needs of regular processes, such as monitoring services, security services, and input / output (IO) forwarding services. This results in the reserved CPU resources being unavailable for sale, reducing the resource sale rate.
[0051] Typically, after optimizing programs running on an allowed scheduling domain, CPU resources can be released for sale. These sold CPU resources can only deliver relatively stable performance when in an isolated state on a specific machine model. However, the kernel lacks an interface for online adjustment of the allowed scheduling domain, resulting in wasted CPU resources. Modifying system kernel parameters and restarting the host machine will forcefully interrupt cloud host instance services. Migrating virtual machines from the source host machine to a new, optimized and started host machine requires frequent deployment, resulting in high labor costs. To address this issue, the present disclosure provides a method for online isolation of central processing units (CPUs), which is described below in conjunction with specific embodiments.
[0052] Figure 1A flowchart of the method for online isolation of a central processing unit (CPU) provided in an embodiment of the present disclosure. This method can be performed by an online CPU isolation device, which can be implemented using software and / or hardware. The online CPU isolation device can be configured in an electronic device, such as a server or terminal, where the terminal specifically includes a mobile phone, computer, or tablet computer. In addition, this method can be applied to the application scenario of online CPU isolation. It is understood that the online CPU isolation method provided in the embodiment of the present disclosure can also be applied in other scenarios.
[0053] Figure 1 The flowchart of the online isolation method of the central processing unit provided in the embodiment of the present disclosure is as follows: Figure 1 As shown, the method includes the following specific steps:
[0054] S101: Create a virtual file system interface through an external driver, and obtain a callback function through the virtual file system interface.
[0055] External drivers generally refer to drivers used to control and utilize hardware resources external to the microcontroller, such as external EEPROM, external watchdog timers, and external Flash memory. These drivers belong to the ECU abstraction layer and require a Microcontroller Abstraction Layer (MCAL) driver to drive these external devices. For memory-mapped external devices (such as external Flash memory), their drivers can directly access the microcontroller; these drivers belong to the MCAL. Furthermore, because drivers are closely tied to the I / O control method used by the I / O device, the commonly used I / O control methods are interrupt-driven and DMA, and the drivers for these two methods differ significantly. Furthermore, because drivers are closely tied to the hardware, a portion must be written in assembly language. Furthermore, the device driver process can be divided into two parts: the driver that drives the I / O device and the device interrupt handler (which handles post-I / O operations).
[0056] The terminal creates a virtual file system (proc) interface through an external driver and obtains the callback function through this virtual file system interface. / proc is a pseudo file system (also known as a virtual file system) that stores a series of special files that indicate the current kernel operation status. Users can use these files to view information about system hardware and currently running processes, and even change the kernel's operating status by modifying certain files.
[0057] S102: Adjust the scheduling domain mask through the callback function and the hot patch to obtain the isolation domain target mask.
[0058] A hotfix, also known as a patch, is a piece of code that can fix software vulnerabilities. It is a quick and cost-effective way to repair defects in product software versions. Users are notified of hotfixes via email or other means, and the patch is generally available as a free download from the software vendor's website. Compared to software version upgrades, a hotfix's main advantage is that it does not interrupt the device's currently running services. That is, defects in the device's current software version can be fixed without restarting the device. During the scheduling domain reconstruction process, a hotfix primarily updates a callback function. The callback function is used to return the CPU range of the external driver's target isolation domain and target permitted scheduling domain. The callback function is primarily used to define the execution range of the regular scheduling domain during the scheduling domain reconstruction process. The scheduling domain reconstruction process is executed in the external driver module.
[0059] The terminal adjusts the scheduling domain mask through the callback function and hot patch to obtain the isolation domain target mask.
[0060] S103: Determine the CPU to be isolated as the target CPU, determine the target process on the target CPU, and drive the target process away from the target CPU, wherein the target CPU is in the original allowed scheduling domain.
[0061] The terminal determines the CPU to be isolated as the target CPU, determines the target process on the target CPU, drives the target process away from the target CPU, and the target CPU is in the original allowed scheduling domain.
[0062] Figure 2 A schematic diagram of an application scenario provided by an embodiment of the present disclosure, such as Figure 2 As shown, the original scheduling domain includes the original isolation domain and the original allowed scheduling domain. According to the initial configuration of gurb, the status of the central processing unit (CPU) is divided, wherein the original isolation domain includes CPU0, CPU1, CPU2, and CPU3, and the original allowed scheduling domain includes CPU4, CPU5, CPU6, and CPU7. When the terminal isolates the CPU of the original allowed scheduling domain, the central processing unit to be isolated is determined as the target central processing unit. This embodiment will be explained with CPU4 and CPU5 as the target central processing units to determine the target process on CPU4 and CPU5. The target process refers to a process that can run on all CPUs, that is, a non-bound process. The target process is driven away from CPU4 and CPU5 to CPU6 and CPU7, that is, the target process is driven away from the target central processing unit to the allowed scheduling domain.
[0063] S104: Reconstruct the scheduling domain according to the isolation domain target mask to achieve online isolation of the target central processing unit.
[0064] The terminal reconstructs the scheduling domain according to the isolation domain target mask to achieve online isolation of the target CPU. That is, the isolation domain and the allowed scheduling domain of the scheduling domain are re-divided online, such as Figure 2 As shown, the original isolation domain includes CPU0, CPU1, CPU2, and CPU3, and the original allowed scheduling domain includes CPU4, CPU5, CPU6, and CPU7; after the scheduling domain is rebuilt, the isolation domain includes CPU0, CPU1, CPU2, CPU3, CPU4, and CPU5, and the allowed scheduling domain includes CPU6 and CPU7.
[0065] The embodiment of the present disclosure creates a virtual file system interface through an external driver, obtains a callback function through the virtual file system interface; adjusts the scheduling domain mask through the callback function and hot patch to obtain an isolation domain target mask; determines the central processing unit to be isolated as the target central processing unit, determines the target process on the target central processing unit, drives the target process away from the target central processing unit, and reconstructs the scheduling domain according to the isolation domain target mask to achieve online isolation of the target central processing unit. Compared with the prior art of restarting the host machine or migrating the virtual machine of the source host machine to a new host machine that is optimized and started, the online central processing unit isolation method provided by the present disclosure uses an external driver to create a virtual file system interface to obtain a callback function and hot patch to adjust the scheduling domain mask, determines the central processing unit to be isolated as the target central processing unit, determines the target process on the target central processing unit, drives the target process away from the target central processing unit, and reconstructs the scheduling domain according to the isolation domain target mask. The hot patch and external driver method are applicable to old versions of kernels that have been put online, and achieves online isolation of the target central processing unit without restarting the host machine or migrating a new host machine, thereby reducing labor costs and improving the resource sales rate of the central processing unit.
[0066] Based on the above embodiment, before creating the virtual file system interface through the external driver, the method further includes: initializing the scheduling domain mask.
[0067] The terminal initializes the external driver. The specific code includes insmod live_isolate_cpu.ko. It also initializes the scheduling domain mask, mainly for the original allowed scheduling domain. The purpose is to support the reentry of the external driver. For example, when the external driver has a subsequent function update, the original isolation domain and the original allowed scheduling domain of the scheduling domain can be obtained.
[0068] Optionally, the initialization scheduling domain mask includes: obtaining the target allowed scheduling domain address and determining the value of the target allowed scheduling domain; based on the value of the target allowed scheduling domain being empty, allocating space for the target allowed scheduling domain address, and assigning a value to the target allowed scheduling domain through the allowed scheduling core; obtaining the isolation domain address and the original allowed scheduling domain address, allocating space for the isolation domain address and the original allowed scheduling domain respectively, and assigning a value to the original allowed scheduling domain through the allowed scheduling core.
[0069] The terminal obtains the target allowed scheduling domain address and determines the value of the target allowed scheduling domain; based on the value of the target allowed scheduling domain being empty, allocates space for the target allowed scheduling domain address, and assigns a value to the target allowed scheduling domain through the allowed scheduling core; obtains the isolated domain address and the original allowed scheduling domain address, allocates space to the isolated domain address and the original allowed scheduling domain respectively, and assigns a value to the original allowed scheduling domain through the allowed scheduling core.
[0070] Exemplarily, the terminal obtains the target allowed scheduling domain address from the CPU kernel symbol table and determines whether the value of the target allowed scheduling domain is empty; when the value of the target allowed scheduling domain is empty, space is allocated for the target allowed scheduling domain address, and the target allowed scheduling domain is assigned a value through the allowed scheduling core (housekeeping_mask), such as the target allowed scheduling domain is CPU6, CPU7; similarly, the terminal obtains the isolation domain address and the original allowed scheduling domain address, allocates space for the isolation domain address and the original allowed scheduling domain respectively, and assigns a value to the original allowed scheduling domain through the allowed scheduling core (housekeeping_mask), such as the original allowed scheduling domain is CPU4, CPU5, CPU6, CPU7.
[0071] The disclosed embodiment determines the value of the target allowed scheduling domain by obtaining the target allowed scheduling domain address; based on the value of the target allowed scheduling domain being empty, allocates space for the target allowed scheduling domain address, and assigns a value to the target allowed scheduling domain through the allowed scheduling core; obtains the isolation domain address and the original allowed scheduling domain address, allocates space for the isolation domain address and the original allowed scheduling domain respectively, and assigns a value to the original allowed scheduling domain through the allowed scheduling core, specifically describes the initialization scheduling domain mask, lays the foundation for the online isolation of the central processing unit, and improves the accuracy of the online isolation method of the central processing unit.
[0072] In some embodiments, the scheduling domain mask is adjusted through the callback function and the hot patch to obtain the isolation domain target mask, including: setting the target central processor through the callback function; loading the hot patch through the dynamic kernel patch mechanism tool command; according to the callback function of the virtual file system interface, calling the hot patch to adjust the scheduling domain mask to obtain the isolation domain target mask.
[0073] The terminal sets the target CPU through a callback function; and loads the hot patch through the dynamic kernel patch mechanism (kpatch) tool command. The specific code is as follows:
[0074] kpatch install livepatch-0001-sched-kpatch-for-isolate-cpu.ko
[0075] kpatch load --all
[0076] The terminal calls the hot patch to adjust the scheduling domain mask according to the callback function of the virtual file system interface, which may be write_live_isolcpus, to obtain the isolation domain target mask.
[0077] For example, if the scheduling domains are CPU0, CPU1, CPU2, CPU3, CPU4, CPU5, CPU6, and CPU7, the original isolation domains are CPU0, CPU1, CPU2, and CPU3, the original permitted scheduling domains are CPU4, CPU5, CPU6, and CPU7, the target permitted scheduling domains are CPU6 and CPU7, and the target isolation domains are CPU0, CPU1, CPU2, CPU3, CPU4, and CPU5. In other words, if the target CPUs are CPU4 and CPU5, and we want to isolate them online, the specific code is as follows: echo4,5>proc / live_isolcpus. The callback function write_live_isolcpus can be used to determine if CPU4 and CPU5 are in the original permitted scheduling domains, adjust the scheduling domain mask, and obtain the isolation domain target mask.
[0078] Based on the above embodiment, determining the target process on the target central processing unit includes: traversing all processes on the target central processing unit; for each of the processes, determining whether the process is a kernel process; based on the fact that the process is a non-kernel process, determining the target process on the target central processing unit according to the scheduling domain mask and the isolation domain target mask.
[0079] The terminal first traverses all processes that can be run on the target central processor, among which processes that can only run on a fixed CPU are kernel processes, and processes that can run on any CPU in the allowed scheduling domain are non-kernel processes; for each process, determine whether the process is a kernel process. When the process is a non-kernel process, determine the target process on the target central processor based on the scheduling domain mask and the isolation domain target mask. In other words, determine whether the range of the central processor that the process is allowed to run is the original allowed scheduling domain. If so, set the range of the central processor that the process is allowed to run to the target allowed scheduling domain. This realizes the expulsion of non-bound processes on the target central processor to the target allowed scheduling domain. When the process is a kernel process, keep the process running on the CPU to which the process belongs.
[0080] Exemplarily, the processes running on the target central processor include process 1 and process 2, and the terminal traverses all processes running on the target central processor; for each process, it is determined whether the process is a kernel process, and the judgment result is that process 1 is a kernel process and process 2 is a non-kernel process. For the kernel process (process 1), process 1 is kept running on the CPU to which process 1 belongs. For the non-kernel process (process 2), based on the scheduling domain mask and the isolation domain target mask, process 2 is determined to be the target process on the target central processor. In other words, it is determined whether the range of the central processor that process 2 is allowed to run is the original allowed scheduling domain. If so, the range of the central processor that process 2 is allowed to run is set to the target allowed scheduling domain, thereby achieving the goal of driving the non-bound processes on the target central processor away from the target allowed scheduling domain.
[0081] In other embodiments, determining the target process on the target central processing unit further includes: traversing all processes on the system; for each of the processes, determining whether the process is a kernel process; based on the process being a non-kernel process, determining whether the allowed scheduling domain of the process is the original allowed scheduling domain according to the scheduling domain mask; based on the allowed scheduling domain of the process being the original allowed scheduling domain, determining that the process is the target process.
[0082] The terminal can also traverse all processes running on the system and determine for each process whether the process is a kernel process. When the process is a non-kernel process, the terminal determines whether the allowed scheduling domain of the process is the original allowed scheduling domain based on the scheduling domain mask. When the allowed scheduling domain of the process is the original allowed scheduling domain, the terminal determines that the process is the target process, drives the target process away from the target central processor, and updates the allowed scheduling domain of the target process to the target allowed scheduling domain.
[0083] The scheduling domain is rebuilt based on the isolation domain target mask, achieving online isolation of the target CPU. Subsequently, previously created processes and processes that meet the evicted conditions are scheduled according to the latest scheduling domain during system load balancing. The end result is that processes running on the isolated CPU are not affected by these evicted or newly created processes.
[0084] The disclosed embodiment sets the target central processor through a callback function; loads the hot patch through a dynamic kernel patch mechanism tool command; calls the hot patch to adjust the scheduling domain mask according to the callback function obtained by the virtual file system interface, obtains the isolation domain target mask, and traverses all processes on the target central processor; for each process, based on the process being a non-kernel process, determines the target process on the target central processor according to the scheduling domain mask and the isolation domain target mask, and realizes online isolation of the target central processor. Subsequent newly created processes and processes that meet the expulsion conditions will be scheduled according to the scheduling domain reconstructed by the isolation domain target mask when the system performs load balancing. The processes running on the target central processor will not be affected by the target process and the newly created process, the operation is simple, the labor cost is reduced, and the resource sales rate of the central processor is improved.
[0085] Figure 3 This is a schematic diagram of the structure of the online isolation device for the central processing unit provided in the embodiment of the present disclosure. The online isolation device for the central processing unit may be the terminal as described in the above embodiment, or the online isolation device for the central processing unit may be a component or assembly in the terminal. The online isolation device for the central processing unit provided in the embodiment of the present disclosure may execute the processing flow provided in the embodiment of the online isolation method for the central processing unit, such as Figure 3 As shown, the CPU online isolation device 30 includes:
[0086] A creation module 31 is configured to create a virtual file system interface through an external driver and obtain a callback function through the virtual file system interface;
[0087] An adjustment module 32 is configured to determine a target CPU to be isolated, and adjust the scheduling domain mask through the virtual file system interface and the hot patch to obtain an isolation domain target mask;
[0088] an expulsion module 33, configured to determine a target CPU to be isolated as a target CPU, determine a target process on the target CPU, and expel the target process from the target CPU, wherein the target CPU is in the original allowed scheduling domain;
[0089] The reconstruction module 34 is configured to reconstruct the scheduling domain according to the isolation domain target mask to achieve online isolation of the target central processing unit.
[0090] Optionally, the CPU online isolation device 30 further includes: an initialization module 35, configured to initialize the scheduling domain mask.
[0091] Optionally, when initializing the scheduling domain mask, the initialization module 35 is specifically used to obtain the target allowed scheduling domain address and determine the value of the target allowed scheduling domain; based on the value of the target allowed scheduling domain being empty, allocate space for the target allowed scheduling domain address, and assign a value to the target allowed scheduling domain through the allowed scheduling core; obtain the isolation domain address and the original allowed scheduling domain address, allocate space for the isolation domain address and the original allowed scheduling domain respectively, and assign a value to the original allowed scheduling domain through the allowed scheduling core.
[0092] The adjustment module 32 is also used to set the target central processor through the callback function; load the hot patch through the dynamic kernel patch mechanism tool command; call the hot patch according to the callback function of the virtual file system interface to adjust the scheduling domain mask to obtain the isolation domain target mask.
[0093] The expulsion module 33 is also used to traverse all processes on the target central processor; for each process, determine whether the process is a kernel process; based on the fact that the process is a non-kernel process, determine the target process on the target central processor according to the scheduling domain mask and the isolation domain target mask.
[0094] Figure 3 The central processing unit online isolation device of the illustrated embodiment can be used to implement the technical solution of the above-mentioned central processing unit online isolation method embodiment. Its implementation principle and technical effects are similar and will not be repeated here.
[0095] Figure 4 This is a schematic diagram of the structure of an electronic device provided by an embodiment of the present disclosure. The electronic device may be a terminal as described in the above embodiment. The electronic device provided by an embodiment of the present disclosure may execute the processing flow provided by the embodiment of the online isolation method of the central processing unit, such as Figure 4 As shown, the electronic device 40 includes: a memory 41, a processor 42, a computer program and a communication interface 43; wherein the computer program is stored in the memory 41 and is configured so that the processor 42 executes the above-mentioned central processing unit online isolation method.
[0096] In addition, an embodiment of the present disclosure further provides a computer-readable storage medium on which a computer program is stored. The computer program is executed by a processor to implement the method for online isolation of a central processing unit described in the above embodiment.
[0097] In addition, an embodiment of the present disclosure further provides a computer program product, which includes a computer program or instructions. When the computer program or instructions are executed by a processor, the above-mentioned central processing unit online isolation method is implemented.
[0098] It should be noted that the computer-readable medium mentioned above in the present disclosure may be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. A computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or component, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, device, or component. In the present disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any suitable medium, including but not limited to wires, optical cables, RF (radio frequency), etc., or any suitable combination thereof.
[0099] In some embodiments, the client and server can communicate using any currently known or future developed network protocol, such as HTTP (HyperText Transfer Protocol), and can be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or future developed network.
[0100] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device.
[0101] The computer-readable medium carries one or more programs. When the one or more programs are executed by the electronic device, the electronic device:
[0102] Creating a virtual file system interface through an external driver, and obtaining a callback function through the virtual file system interface;
[0103] Adjusting the scheduling domain mask through the callback function and the hot patch to obtain the isolation domain target mask;
[0104] Determine a CPU to be isolated as a target CPU, determine a target process on the target CPU, and drive the target process away from the target CPU, wherein the target CPU is in the original allowed scheduling domain;
[0105] The scheduling domain is rebuilt according to the isolation domain target mask to achieve online isolation of the target central processing unit.
[0106] In addition, the electronic device can also execute other steps in the above-mentioned method for isolating the central processing unit online.
[0107] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages, or a combination thereof, including, but not limited to, object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0108] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0109] The units involved in the embodiments described in this disclosure may be implemented in software or hardware, wherein the name of a unit does not necessarily limit the unit itself.
[0110] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chip (SOCs), complex programmable logic devices (CPLDs), and the like.
[0111] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in conjunction with an instruction execution system, device or equipment. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0112] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.
[0113] The foregoing description is intended only to provide specific embodiments of the present disclosure, intended to enable those skilled in the art to understand and implement the present disclosure. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present disclosure. Therefore, the present disclosure is not intended to be limited to the embodiments described herein, but rather to be construed in the broadest manner consistent with the principles and novel features disclosed herein.
Claims
1. A method for online isolation of a central processing unit, characterized in that: The method comprises: Creating a virtual file system interface through an external driver, and obtaining a callback function through the virtual file system interface; Adjusting the scheduling domain mask through the callback function and the hot patch to obtain the isolation domain target mask; Determine a CPU to be isolated as a target CPU, determine a target process on the target CPU, and drive the target process away from the target CPU, wherein the target CPU is in the original allowed scheduling domain; The scheduling domain is rebuilt according to the isolation domain target mask to achieve online isolation of the target central processing unit.
2. The method according to claim 1, characterized in that Before creating the virtual file system interface through the external driver, the method further includes: Initialize the scheduling domain mask.
3. The method according to claim 2, characterized in that The initialization scheduling domain mask includes: Obtaining a target allowed scheduling domain address and determining a value of the target allowed scheduling domain; Based on the value of the target allowed scheduling domain being empty, allocating space for the target allowed scheduling domain address, and assigning a value to the target allowed scheduling domain through the allowed scheduling core; The isolation domain address and the original allowed scheduling domain address are obtained, space is allocated for the isolation domain address and the original allowed scheduling domain respectively, and a value is assigned to the original allowed scheduling domain through the allowed scheduling core.
4. The method according to claim 1, wherein The scheduling domain mask is adjusted through the callback function and the hot patch to obtain the isolation domain target mask, including: Setting the target CPU via the callback function; Loading the hot patch through a dynamic kernel patch mechanism tool command; According to the callback function of the virtual file system interface, the hot patch is called to adjust the scheduling domain mask to obtain the isolation domain target mask.
5. The method according to claim 1, wherein Determining a target process on the target central processing unit includes: Traversing all processes on the target CPU; For each of the processes, determining whether the process is a kernel process; Based on the fact that the process is a non-kernel process, a target process on the target central processing unit is determined according to the scheduling domain mask and the isolation domain target mask.
6. The method according to claim 1, characterized in that Determining a target process on the target central processing unit includes: Traverse all processes on the system; For each of the processes, determining whether the process is a kernel process; Based on the fact that the process is a non-kernel process, judging, according to the scheduling domain mask, whether the allowed scheduling domain of the process is the original allowed scheduling domain; Based on the allowed scheduling domain of the process being the original allowed scheduling domain, the process is determined to be the target process.
7. A central processing unit online isolation device, characterized in that: The device comprises: A creation module is used to create a virtual file system interface through an external driver and obtain a callback function through the virtual file system interface; An adjustment module is used to determine a target CPU to be isolated, and to adjust the scheduling domain mask through the virtual file system interface and the hot patch to obtain an isolation domain target mask; an expulsion module, configured to determine a CPU to be isolated as a target CPU, determine a target process on the target CPU, and expel the target process from the target CPU, wherein the target CPU is in the original allowed scheduling domain; A reconstruction module is used to reconstruct the scheduling domain according to the isolation domain target mask to achieve online isolation of the target central processing unit.
8. The device according to claim 7, characterized in that Before creating the virtual file system interface through the external driver, the device further includes: Initialization module, used to initialize the scheduling domain mask.
9. An electronic device, characterized in that: include: Memory; processor; as well as computer programs; The computer program is stored in the memory and configured to be executed by the processor to implement the method according to any one of claims 1 to 5.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 5 is implemented.