Virtualization processing method, device and storage medium

By inserting a virtualization layer between the hardware resources and the host operating system, the virtual resource provision function is realized, the resource shortage caused by unconfigured system functions is solved, the capabilities of existing operating systems are expanded, and more applications are supported.

WO2025139219A1PCT designated stage expired Publication Date: 2025-07-03HANGZHOU ALICLOUD FEITIAN INFORMATION TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/125028
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-28
Filing Date
2024-10-15
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

The existing operating systems that have been run but have not configured related system functions cannot effectively expand their capabilities, resulting in insufficient application resources and inability to run.

Method used

Insert a virtualization layer between the hardware resources and the host operating system, providing two operating modes (root mode and non-root mode), switching the host operating system from root mode to non-root mode through the virtualization layer, providing virtual resources to run applications that cannot be run due to insufficient resources.

Benefits of technology

Without reinstalling the operating system, expand the capabilities of the host operating system, support the operation of more applications, and solve the problem of insufficient resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024125028_03072025_PF_FP_ABST
    Figure CN2024125028_03072025_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the embodiments of the present disclosure are a virtualization processing method, a device and a storage medium. In the embodiments of the present application, for a host operating system in a running state, two running modes, i.e. a root mode and a non-root mode, are provided; a virtualization layer is inserted between a hardware resource and the host operating system, and a virtual resource providing function is implemented at least in the virtualization layer; the virtualization layer switches the running host operating system from the root mode to the non-root mode; in the non-root mode, a virtual resource is provided and at least an application that the host operating system cannot run in the root mode due to insufficient resources is run on the virtual resource. Without the need to reinstall the host operating system, the present disclosure can flexibly implement the virtual resource providing function for the host operating system in the running state, so as to support running of more applications, expanding the capability of the host operating system.
Need to check novelty before this filing date? Find Prior Art

Description

Virtualization processing method, device and storage medium Technical Field

[0001] The present disclosure relates to the field of virtualization technology, and in particular to a virtualization processing method, device, and storage medium. Background Art

[0002] The operating system (OS), as the foundational system software for computers, provides various system-level features, such as memory swapping. Memory swapping is a mechanism that uses free hard disk space as an extension of main memory. When the physical pages in main memory are insufficient, infrequently used memory pages are swapped to the hard disk. When a process uses these memory pages again, they are swapped from the hard disk to main memory.

[0003] Some system features, such as memory swap, require configuration during OS installation. If these features aren't configured, the operating system won't be able to use these features to provide resources to applications, causing applications that rely on these features to run abnormally or even fail. Existing operating systems that are already running but haven't configured these features face the technical challenge of expanding their capabilities.

[0004] Summary of the Invention

[0005] Various aspects of the present disclosure provide a virtualization processing method, device, and storage medium to address the capability expansion issues faced by existing operating systems that are already running but not configured with relevant functions, thereby supporting the operation of more applications.

[0006] An embodiment of the present disclosure also provides a physical machine, which includes hardware resources and a host operating system running on the hardware resources, and a virtualization layer is implemented between the hardware resources and the host operating system; the virtualization layer is used to switch the running host operating system from root mode to non-root mode, and in the non-root mode, provide at least one virtual resource and run at least one application on the at least one virtual resource; wherein the at least one application includes at least an application that the host operating system cannot run in root mode due to insufficient resources.

[0007] An embodiment of the present disclosure also provides a virtualization processing method, which is applied to a virtualization layer in a physical machine, where the virtualization layer is located between the hardware resources of the physical machine and the host operating system. The method includes: switching the running host operating system from root mode to non-root mode; in non-root mode, providing at least one virtual resource and running at least one application on the at least one virtual resource; the at least one application includes at least an application that the host operating system cannot run in root mode due to insufficient resources.

[0008] The embodiments of the present disclosure further provide a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the processor implements the steps of the virtualization processing method provided by the embodiments of the present disclosure.

[0009] In an embodiment of the present disclosure, two operating modes are provided for a host operating system in a running state, namely a root mode and a non-root mode. A virtualization layer is inserted between hardware resources and the host operating system, and the function of providing virtual resources is implemented at least in the virtualization layer. The virtualization layer switches the running host operating system from root mode to non-root mode. In the non-root mode, at least one virtual resource is provided, and at least one application that the host operating system cannot run in the root mode due to insufficient resources is run on the at least one virtual resource. Without reinstalling the host operating system, the virtual resource provision function can be flexibly implemented for the running host operating system to support the operation of more applications and expand the capabilities of the host operating system. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] The drawings described herein are used to provide a further understanding of the present disclosure and constitute a part of the present disclosure. The exemplary embodiments of the present disclosure and their descriptions are used to explain the present disclosure and do not constitute an improper limitation of the present disclosure. In the drawings:

[0011] FIG1a is a schematic structural diagram of a physical machine provided by an exemplary embodiment of the present disclosure;

[0012] FIG1b is a schematic structural diagram of another physical machine provided by an exemplary embodiment of the present disclosure;

[0013] FIG1c is a system structure diagram of the physical machine shown in FIG1b operating in root mode, provided by an exemplary embodiment of the present disclosure;

[0014] FIG1d is a system structure diagram of the physical machine shown in FIG1b operating in non-root mode, provided by an exemplary embodiment of the present disclosure;

[0015] FIG2a is a schematic diagram of a process of switching a host operating system from a root mode to a non-root mode, provided by an exemplary embodiment of the present disclosure;

[0016] FIG2 b is a schematic diagram of a process of creating a memory page table according to an exemplary embodiment of the present disclosure;

[0017] FIG2c is a schematic diagram of a process of creating an information bearing object according to an exemplary embodiment of the present disclosure;

[0018] FIG2 d is a schematic diagram of a mode switching process according to an exemplary embodiment of the present disclosure;

[0019] FIG3 is a flow chart of a virtualization processing method provided by an exemplary embodiment of the present disclosure;

[0020] FIG4 is a schematic structural diagram of a virtualization processing device provided by an exemplary embodiment of the present disclosure. DETAILED DESCRIPTION

[0021] To make the objectives, technical solutions, and advantages of the present disclosure more clear, the technical solutions of the present disclosure will be clearly and completely described below in conjunction with the specific embodiments of the present disclosure and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present disclosure.

[0022] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0023] In the embodiment of the present disclosure, as shown in FIG1a, the host machine includes hardware resources, a host operating system (host OS) runs on the hardware resources, and various application programs run on the host OS; relative to the hardware resources, the host OS and the application programs belong to the software resources of the host machine. The host OS is the most basic system software in the host machine, which is responsible for controlling and managing the hardware resources and software resources of the entire host machine, and can reasonably schedule the work and resource allocation of the host machine, and can provide a convenient interface and environment for users and other software or devices. Among them, the host OS can provide various system-level functions, such as file management, memory management, various input / output (IO) device management, etc. Based on these system functions, the host OS can provide the application with various resources required during operation to support the operation of the application.

[0024] Among these system functions, at least some of them need to be configured when installing the host operating system, such as whether to enable them, which mode to enable them, and so on. System functions that are not enabled will not be available during the operation of the host operating system. Since the system functions cannot be used, applications that rely on the system functions will run abnormally or fail to run because they cannot obtain the resources provided by the system functions. However, as the host operating system runs and application requirements change, it may be necessary to use these unenabled system functions, or upgrade the enabled system functions, that is, the host operating system faces the problem of capacity expansion. For traditional hosts, either the host operating system must be reinstalled, or some system functions must be forcibly enabled online. Reinstalling the host operating system requires interrupting the operation of all applications, which is inefficient and costly; forcing the corresponding system functions online will seriously affect the stability of the system.

[0025] In an embodiment of the present disclosure, in order to solve the capacity expansion problem faced by the host operating system without reinstalling the host operating system and without affecting the operating performance of the host operating system, a new physical machine architecture is provided, which provides two operating modes for the host operating system in a running state, namely root mode and non-root mode, inserts a virtualization layer between the hardware resources and the host operating system, implements the virtual resource provision function at least in the virtualization layer, and switches the running host operating system from root mode to non-root mode by the virtualization layer, provides at least one virtual resource in the non-root mode and runs at least an application that the host operating system cannot run in the root mode due to insufficient resources on the virtual resource, without reinstalling the operating system, and can flexibly implement the virtual resource provision function for the running host operating system, thereby solving the problem that the application cannot run due to insufficient resources due to reasons such as the failure to enable or lack of system functions, supporting the operation of more applications, and helping to expand the capabilities of the host operating system.

[0026] For example, assuming that the host operating system supports function A, function B, function C, and function D, etc., when the host operating system is installed, function A, function B, and function C are enabled, function D is not enabled, and function E is missing (i.e., the host operating system does not support function E). Using the physical machine provided by the embodiment of the present disclosure, a virtualization layer is inserted between the hardware resources and the host operating system, and the function of providing virtual resources is implemented at least in the virtualization layer. For example, if the host operating system does not enable function D and lacks function E, the virtualization layer switches the host operating system from root mode to non-root mode, and provides virtual resources corresponding to function D and function E in non-root mode. Applications that were originally unable to run due to the non-enabling function D and the lack of function E are run on the virtual resources. Without reinstalling the host operating system, the function of providing virtual resources can be flexibly implemented for the running host operating system, solving the problem of the corresponding application being unable to run due to the non-enabling function D and the lack of function E, which is conducive to expanding the capabilities of the host operating system. Furthermore, in order to compensate for the deficiencies of the host operating system, virtual resources corresponding to function D and function E can be provided preferentially in non-root mode to solve the operation problems of applications that depend on function D and function E; of course, for the compatibility of the host operating system and to avoid frequent mode switching, virtual resources corresponding to function A, function B and function C can also be provided in non-root mode to facilitate the running of corresponding applications that depend on function A, function B and function C on these resources.

[0027] For the purposes of this disclosure, the present disclosure focuses on the host operating system's switching between two modes. The virtual resources corresponding to system functions provided in non-root mode and how these virtual resources are provided are not specified. The following, combined with the accompanying figures, details the physical machine architecture and the host operating system's switching from root mode to non-root mode provided in the present disclosure.

[0028] Figure 1b is a schematic diagram of the structure of a physical machine provided by an exemplary embodiment of the present disclosure. As shown in Figure 1b, the physical machine includes hardware resources 10 and a host operating system 20 running on the hardware resources. A virtualization layer 30 is implemented between the hardware resources 10 and the host operating system 20. Furthermore, an application layer 40 is provided above the host operating system 20. Application layer 40 includes various application programs.

[0029] Optionally, hardware resources 10 include at least one physical computing resource object 101 and a physical storage medium 102, with physical storage medium 102 providing a physical address space. In addition, hardware resources 10 on a physical machine may also include other components, not shown, such as I / O devices, communication components, a display, a power supply component, and an audio component.

[0030] The physical computing resource object 101 may be a central processing unit (CPU), a graphics processing unit (GPU), a data processing unit (DPU), a tensor processing unit (TPU), a cloud infrastructure processing unit (CIPU), an application-specific integrated circuit (ASIC), or any other physical resource object with computing capabilities. The host operating system 20 may run on at least one physical computing resource object 101.

[0031] The physical storage medium 102 includes permanent and non-permanent, removable and non-removable media and can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. The physical storage medium 102 includes, but is not limited to: phase-change random access memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, read-only compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device.

[0032] Physical memory refers to the memory chips or modules actually present in a physical machine, used to store data and program code. Physical memory may include non-permanent memory in the physical storage medium 102, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash RAM.

[0033] The physical address space is the address range corresponding to physical memory. It is typically related to the hardware architecture and the host operating system, and describes the physical location and size of the actual memory banks. In virtual memory systems, the physical address space also involves mechanisms such as the memory page table, which is used to map guest physical addresses to host physical addresses.

[0034] In this embodiment, the host operating system 20 corresponds to a root mode and a non-root mode. Root mode is an operating mode in which the host operating system 20 has direct access to the hardware resources 10. Non-root mode is an operating mode in which the virtualization layer 30 virtualizes the hardware resources 10 and schedules and accesses the virtualized resources on behalf of the host operating system 20. In non-root mode, the virtualization layer 30 has limited access to the hardware resources 10. Accordingly, the host operating system 20 in non-root mode can also be referred to as a client operating system.

[0035] In this embodiment, a lightweight, powerful, and efficient virtualization layer 30 is inserted between the hardware resources 10 and the host operating system 20. The virtualization layer 30 can be pre-developed and inserted between the hardware resources 10 and the host operating system 20. The method for inserting the virtualization layer 30 is not limited. For example, the virtualization layer 30 can be inserted after the host operating system 20 is installed on the physical machine and the host operating system 20 is in normal operation.

[0036] Among them, the virtualization layer 30 has the ability to provide virtual resources, and can at least provide virtual resources corresponding to the resources that the host operating system 20 cannot provide in root mode due to unactivated or missing system functions. That is to say, the resources that the host operating system 20 cannot provide in root mode due to unactivated or missing system functions can be provided with corresponding virtual resources by the virtualization layer 30, so as to run the corresponding applications. Specifically, the virtualization layer 30 can switch the running host operating system 20 from root mode to non-root mode, and provide at least one virtual resource in non-root mode, and run at least one application on at least one virtual resource. Without reinstalling the operating system, the virtual resource provision function can be flexibly implemented for the running host operating system, solving the problem that the host operating system 20 cannot provide corresponding resources to run corresponding applications in root mode due to unactivated or missing system functions. It can support the operation of more applications and is conducive to expanding the capabilities of the host operating system. Furthermore, for the sake of compatibility with the host operating system, in order to reduce the frequent mode switching of the host operating system, in non-root mode, not only can corresponding virtual resources be provided for system functions that are not enabled or missing in the root mode of the host operating system 20, but corresponding virtual resources can also be provided for system functions that are enabled in the root mode of the host operating system 20, thereby supporting more functions of the host operating system 20.

[0037] For example, at least one target function implemented in the virtualization layer 30 includes but is not limited to: memory management function, file management function, virtualization function, scheduling optimization function, etc. The memory management function, file management function, scheduling optimization function, etc. here can be a newly expanded function that is not originally supported by the host operating system, or a function that is originally supported by the host operating system but is not enabled during the installation of the host operating system. Regardless of whether it is a newly expanded function or an unenabled function, the memory management function specifically includes but is not limited to: memory page fault management, memory swap management, memory mapping management, etc.; the file management function specifically includes but is not limited to: directory management, permission management, file backup, creation, query, deletion, modification, etc.; the virtualization function includes but is not limited to: virtualization of various elastic resources (such as CPU, GPU, memory, network, etc.); the scheduling and tuning function includes but is not limited to: scheduling of physical computing resource objects and scheduling of various virtualized resources, etc.

[0038] Furthermore, FIG1b shows a schematic diagram of the overall architecture of the physical machine. FIG1c and FIG1d illustrate the internal architecture of the physical machine operating in root mode and non-root mode, respectively. Before the mode switch, the host operating system operates in root mode. In this root mode, as shown in FIG1c , the internal architecture of the running physical machine, from bottom to top, is hardware resources 10, host operating system 20, and application layer 40. After the mode switch, the physical machine operates in non-root mode. In this non-root mode, as shown in FIG1d , the architecture of the running physical machine, from bottom to top, is hardware resources 10, virtualization layer 30, client operating system, and application layer 40. The term "client operating system" refers to the host operating system 20 operating in non-root mode.

[0039] In the embodiments of the present disclosure, two operating modes are provided for a host operating system in a running state, namely a root mode and a non-root mode. A virtualization layer is inserted between hardware resources and the host operating system, and at least the virtualization layer implements the virtual resource provision function. The virtualization layer switches the running host operating system from root mode to non-root mode, provides virtual resources in the non-root mode, and runs at least applications on the virtual resources that the host operating system cannot run in the root mode due to insufficient resources. Without reinstalling the host operating system, the virtual resource provision function can be flexibly implemented for the running host operating system, supporting the operation of more applications and expanding the capabilities of the host operating system.

[0040] It is explained here that, from the perspective of program code, the implementation codes such as "the function of providing virtual resources" and "switching from root mode to non-root mode" involved in the embodiments of the present disclosure belong to the virtualization layer 30, and these codes are located under the host operating system; however, from the perspective of the running state, before the mode switching is actually completed, at least part of the program code in the virtualization layer 30 is executed during the operation of the host operating system. In other words, at least part of the program code in the virtualization layer 30 is executed in root mode, wherein the program code executed in the root mode in the virtualization layer 30 at least includes: program code for switching from root mode to non-root mode, such as the upper half of the switching function mentioned in the following embodiments. Accordingly, after the mode switching is actually completed, part of the program code will be executed in non-root mode, such as the lower half of the switching function mentioned in the following embodiments. In addition, the program code responsible for providing virtual resources in the virtualization layer 30 also runs in root mode, but this part of the code is run after the switch is completed; the virtualization layer 30 also provides some interface codes to the outside world, some of which will run in non-root mode, and some need to be switched to root mode to run, depending on the function of the interface code.

[0041] In an optional embodiment, as shown in FIG2a , the virtualization layer 30 switches the running host operating system from the root mode to the non-root mode, including three parts:

[0042] S1. Create a memory page table to store the mapping relationship between the client physical address in non-root mode and the host physical address in root mode;

[0043] S2. Create an information-carrying object required for mode switching. The information-carrying object is used to synchronize context information between the root mode and the non-root mode.

[0044] S3. Based on the information carrying object and the memory page table, the running host operating system is switched from the root mode to the non-root mode.

[0045] The following describes the detailed implementation of the above three parts.

[0046] Step S1: Create a memory page table

[0047] In root mode, the physical address space has a host physical address, which can be represented by HPA (Host Physical Address). The host physical address is the address of the physical memory in the physical memory resource. In non-root mode, the physical address space corresponds to a virtual address space. The virtual address space has a client physical address, which can be represented by GPA (Guest Physical Address). The client physical address is the address of the virtual memory in the virtual memory resource.

[0048] In this embodiment, the virtualization layer 30 can create a memory page table, which is used to store the mapping relationship between the client physical address in non-root mode and the host physical address in root mode. The memory page table can be represented by EPT (Extended Page Tables). It should be noted that when the memory page table is initially established, since the host operating system has not yet run in non-root mode and has not performed operations such as memory recycling or memory swapping, the client physical address in non-root mode is the same as the host physical address in root mode. Subsequently, as the host operating system is used in non-root mode, for example, memory recycling or memory swapping, the client physical address may no longer be equal to the host physical address, and the memory page table can dynamically maintain the mapping relationship between the client physical address and the host physical address.

[0049] In an optional embodiment, as shown in Figure 2b, the process of creating a memory page table includes: S11, establishing a page table structure corresponding to the memory page table; S12, applying for the root page of the memory page table from the physical address space; S13, generating an entry address of the memory page table based on the host physical address of the root page, and adding it to the page table structure; S14, creating a multi-level memory page table based on the address range of the physical address space and the page granularity used to map the client physical address to the host physical address.

[0050] First, a page table structure is created. This structure stores various information related to the memory page table, such as the memory page table entry address, the address lock array (ALA) used to operate the memory page table, and the address of a special Advanced Programmable Interrupt Controller (APIC) page. The memory page table entry address is used to access the memory page table. For example, the entry address can be the first address of the memory page table. Each entry in the ALA corresponds to a page table entry and contains a lock flag that indicates whether the entry is locked. If it is not locked, the process can access the memory space corresponding to the page table entry. The address of the special APIC page is mainly used to access the special APIC page. After creating the page table structure, a physical page can be requested from the physical address space provided by the physical storage medium to serve as the root page of the memory page table. The memory page table entry address is generated based on the host physical address of the root page and added to the page table structure. The format of the memory page table entry address varies depending on the type of physical computing resource object and its manufacturer. For example, the host physical address of the root page can be directly used as the entry address of the memory page table. For another example, the host physical address of the root page plus a set offset or flag bit can be used as the entry address of the memory page table, which is not limited to this.

[0051] The physical address space has an address range. For example, the address range of the physical address space can be 0-8G or 0-16G, etc. In addition, in this embodiment, in non-root mode, the single page granularity supported by the host operating system can be broken, allowing the page granularity for address mapping to be set as needed. For example, the page granularity for address mapping can include but is not limited to: 4K (Kilobyte), 2M (Megabyte), or 1G (Gigabyte). In view of this, in an optional embodiment, the virtualization layer 30 can create a multi-level memory page table based on the address range of the physical address space and the page granularity used to map the client physical address to the host physical address. The multi-level memory page table can be a 2-level memory page table, a 4-level memory page table, or a 5-level memory page table, etc., depending on the address range and page granularity of the physical address space. For example, for the same address range, the smaller the page granularity, the more memory page table levels are required; for another example, for the same page granularity, the larger the address range, the more memory page table levels are required.

[0052] Optionally, in this embodiment, the physical address space is divided into a first address space and a second address space. The second address space is larger than the first address space, that is, the address size of the second address space is larger than the address size of the first address space. For example, if the physical address space is 8GB, the address range of the physical address space can be divided into 0GB-4GB and 4GB-8GB. The first address space can be the address space corresponding to 0GB-4GB, and the second address space can be the address space above 4GB. For another example, if the physical address space is 16GB, the physical address space can be divided into 0GB-4GB and 4GB-16GB. The first address space can be the address space corresponding to 0GB-4GB, and the second address space can be the address space above 4GB. Based on this, when creating a multi-level memory page table, corresponding multi-level memory page tables can be created for the first address space and the second address space respectively. The first address space is primarily used as a memory address space, and the second address space can at least be used as an I / O address space. The memory address space is used to describe the storage location of programs and data in memory, and the I / O address space is used to describe the address range of the physical machine's I / O devices. For example, the physical address space is usually divided into several different address ranges. The address space with an address range of 0-4GB is called the first address space, and the address space with an address range of more than 4GB is called the second address space. The first address space is usually called "basic memory" or "system memory", which includes the memory used by the host operating system, applications and basic hardware drivers, that is, the first address space is mainly used as a memory address space. The second address space is usually called "mass memory" or "extended memory". This memory capacity is usually used in high-performance computers, servers, workstations and other devices to support more complex computing tasks and multi-tasking. For example, the second address space can at least be used as an IO address space.

[0053] Among them, for the first address space, a first mapping relationship between the client physical address and the host physical address is formed at a first page granularity, that is, the client physical address and the host physical address are mapped according to the page size of the first page granularity, and a multi-level memory page table corresponding to the first address space is created according to the first mapping relationship; for the IO address space in the second address space, a second mapping relationship between the client physical address and the host physical address is formed at a second page granularity, that is, the client physical address and the host physical address are mapped according to the page size of the second page granularity, and a multi-level memory page table corresponding to the IO address space is created according to the second mapping relationship; the second page granularity is larger than the first page granularity, for example, the first page granularity is 2M and the second page granularity is 1G. Among them, using the first page granularity (small page granularity) for memory mapping can reduce internal fragmentation in memory pages, reduce memory waste, reduce the loss of page table entries in the cache, and improve address conversion efficiency; using the second page granularity (large page granularity) for memory mapping can reduce page table entry data, reduce the level of memory page tables, reduce memory management overhead, and improve the performance of physical computing resource objects.

[0054] Further, optionally, the second address space can also be used as a memory address space. Based on this, the virtualization layer 30 can also form a third mapping relationship between the client physical address and the host physical address at a third page granularity for the memory address space in the second address space. That is, the client physical address and the host physical address are mapped according to the page size of the third page granularity, and a multi-level memory page table corresponding to the memory address space is created based on the third mapping relationship; wherein the third page granularity is smaller than the second page granularity, but the size of the third page granularity is not limited.

[0055] In an optional embodiment, the third page granularity can be equal to the first page granularity. For example, the first page granularity and the third page granularity are both 2M. That is to say, for the memory address space, a smaller page granularity can be used for address space mapping, and for the IO address space, a larger page granularity can be used for address space mapping. The physical address space can be reasonably utilized to improve the performance of memory management.

[0056] Further optionally, in some application scenarios, the memory address space in the second address space includes an APIC page, and the APIC page uses a smaller page granularity, such as the fourth page granularity, and the third page granularity is larger than the fourth page granularity. For example, the third page granularity is 2M, and the fourth page granularity is 4K.

[0057] When the memory address space in the second address space contains an APIC page of a fourth page granularity, it means that the APIC page of the fourth page granularity belongs to a physical page of a third page granularity. The physical page of the third page granularity to which the APIC page of the fourth page granularity belongs is referred to as the first physical page. Then, the first physical page of the third page granularity to which the APIC page belongs and the target memory page table corresponding to the first physical page can be obtained, wherein the target memory page table corresponding to the first physical page is the last level page table in the multi-level memory page table, and the page table entry in the page table points to the address space in the first physical page; in order to adapt to the page granularity of the APIC page, the first physical page can be split into multiple sub-pages of a fourth page granularity, and the next level memory page table is further extended below the target memory page table, that is, the next level memory page table is added under the target memory page table, and the next level memory page table is used to store the host physical addresses of the multiple split sub-pages. For example, the host physical address corresponding to a sub-page is stored in each page table entry of the next level memory page table, and the host physical address is the first address of the sub-page.

[0058] In this embodiment, when creating a memory page table, a mixed mapping granularity method combining the first page granularity, the second page granularity, the third page granularity and the fourth page granularity is adopted, which not only supports small page granularity but also supports large page granularity, can meet the needs of different physical page mappings, and improve the flexibility of memory mapping.

[0059] Furthermore, in the non-root mode provided by the embodiments of the present disclosure, when creating a memory page table, the physical address space of the host machine is no longer limited, and the creation of a memory page table for the entire physical address space is allowed, that is, full memory mapping is supported. Therefore, it is possible to create a memory page table for both user-mode pages and kernel-mode pages. By supporting memory mapping of the full physical address space, a basic framework is provided for various subsequent operations based on memory mapping. For example, when performing memory swapping based on memory mapping, it not only supports swapping of user-mode pages, but also supports swapping of kernel-mode pages, that is, full memory swapping is supported.

[0060] In this embodiment, taking the first page granularity of 2M, the second page granularity of 1G, the third page granularity of 2M, the fourth page granularity of 4K, and the multi-level memory page table implemented as a four-level memory page table as an example, the specific process of creating a memory page table is exemplified.

[0061] The following is an example of a four-level memory page table, which includes: Page Global Directory (PGD), Page Upper Directory (PUD), Page Middle Directory (PMD), and Page Table Entry (PTE). Among them, PGD is the highest level directory. PGD includes multiple global page directory entries pgd_t, each pgd_t can map a 512G host physical address (HPA), and pgd_t points to the next level page directory (PUD); PUD includes multiple upper page directory entries pud_t, each pud_t can map a 1G host physical address (HPA), and pud_t points to the next level page directory (PMD); PMD includes multiple intermediate page directory entries pmd_t, each pmd_t can map a 2M host physical address (HPA), and pmd_t points to the next level page directory (PTE). PTE includes multiple direct page directory entries pte_t, each pmd_t can map a 4K host physical address (HPA), and each pte_t points to the corresponding physical page in the host physical address (HPA).

[0062] 1) For a first address space with an address range of 0G-4G, a first mapping relationship between a client physical address and a host physical address is formed with a page granularity of 2M, and a multi-level memory page table corresponding to the first address space is created according to the first mapping relationship.

[0063] a1. According to the client physical address (GPA) in the first address space, and according to the index value of PGD corresponding to the client physical address (GPA), determine the page table entry pgd_t in the PGD level page table, where pgd_t points to the PUD level page table.

[0064] b1. According to the flag bit in pgd_t, determine whether the PUD-level page table exists. If not, apply for a page as the PUD-level page table.

[0065] c1. If a PUD-level page table exists, determine whether the PUD-level page table needs to be expanded based on the first page granularity (e.g., 2M). Since each pud_t can map a 1GB host physical address (HPA), and 1GB is larger than the first page granularity (e.g., 2M), it is determined that the next-level PMD-level page table needs to be expanded to prepare for subsequent mapping.

[0066] d1. According to the index value of the PUD corresponding to the client physical address (GPA), the page table entry pud_t in the PUD level page table is determined. The pud_t points to the PMD level page table.

[0067] e1. According to the flag bit in the pud_t, determine whether the next-level PMD level page table exists. If not, apply for a page as the PMD level page table.

[0068] f1. Based on the first page granularity (e.g., 2M), determine whether the PMD-level page table needs to be expanded. Since each pmd_t can map a 2M host physical address (HPA), it is determined that there is no need to expand the next-level PTE-level page table.

[0069] g1. Determine the page table entry pmd_t in the PMD level page table based on the index value of the PMD corresponding to the client physical address (GPA).

[0070] h1. When the mapped page granularity is 2MB, a page table entry pmd_t is directly created in the PMD-level page table. pmd_t points to the physical page of the host physical address (HPA), and the physical page size is 2MB. Therefore, it is necessary to assemble a page table entry pmd_t for the PMD-level page table. pmd_t can include the physical page frame number (PFN) corresponding to the corresponding HPA, set the page table entry to be accessible, and set the large page flag to 1. For example, a large page can be a physical page of size 2MB or 1GB. A physical page of size 4KB does not belong to a large page.

[0071] i1. Fill the page table entry pmd_t of the combined PMD-level page table into the PMD-level page table, complete the mapping of the first page granularity (e.g., 2M), and record the mapping completion progress and the next client physical address that needs to be mapped, until the mapping of the first page granularity is established for the first address space.

[0072] j1. Determine whether the mapping of the first page granularity (eg, 2M) is completed. If not, return to step b. Otherwise, end.

[0073] 2) For the input / output (IO) address space in the second address space, a second mapping relationship between the client physical address and the host physical address is formed at a second page granularity, and a multi-level memory page table corresponding to the IO address space is created based on the second mapping relationship. That is, based on the address space (i.e., physical memory space and physical IO space) of the host operating system recorded in the IO memory resource (iomem_resource), a multi-level memory page table of a second page granularity (e.g., 1G granularity) is established for the IO address space in the second address space (e.g., memory address space above 4G). The process of establishing a multi-level memory page table is similar to the above-mentioned implementation method of establishing a multi-level memory page table at a first page granularity, with the difference being that: to establish a multi-level memory page table at a second page granularity (e.g., 1G granularity), it is necessary to establish pud_t in the PUD-level page table, and pud_t points to the physical page of the host physical address (HPA), and the size of the physical page is 1G.

[0074] 3) For the memory address space in the second address space, a third mapping relationship between the client physical address and the host physical address is formed at a third page granularity (e.g., 2M), and a multi-level memory page table corresponding to the memory address space is created based on the third mapping relationship; wherein the third page granularity is smaller than the second page granularity. The process of establishing the multi-level memory page table can be referred to the aforementioned implementation method of establishing the multi-level memory page table at the first page granularity, and will not be repeated here.

[0075] 4) When the memory address space includes an APIC page of a fourth page granularity, obtain a first physical page of a third page granularity to which the APIC page belongs and a target memory page table corresponding to the first physical page; split the first physical page into multiple sub-pages of a fourth page granularity, and add a next-level memory page table under the target memory page table, where the next-level memory page table is used to store the host machine physical addresses of the multiple split sub-pages.

[0076] 5) Apply for a special APIC page, the physical address of the APIC page is the client physical address.

[0077] 6) Establish a mapping between the host physical address of the APIC and the fourth page granularity (e.g., 4k granularity) of this special APIC page. The default host physical base address of the APIC (APIC_DEFAULT_PHYS_BASE) is (0xfee00000), which corresponds to the memory address space in the second memory space. This process involves splitting the already established third page granularity (e.g., 2M granularity) page. The mapping process is as follows:

[0078] a2. Execute steps a1-e1 in step 1) in sequence, and determine whether the PMD-level page table needs to be expanded based on the fourth page granularity (e.g., 4K). Since each pmd_t can map a 2M host physical address (HPA), and 2M is not equal to 4K, it is determined that the next-level PTE-level page table needs to be expanded.

[0079] b2. Based on the index value of the PTE corresponding to the client physical address (GPA), the page table entry pte_t in the PTE-level page table is determined, the contents of pte_t are combined, including the physical page frame number corresponding to the HPA, and the page table entry is set to accessible. At this time, the large page flag is not set to 1.

[0080] c2. Fill the page table entry content of the combined PTE-level page table into the corresponding pte_t to complete this mapping.

[0081] S2. Create the information-carrying object required for mode switching

[0082] In this embodiment, in order to perform mode switching for the host operating system, on the one hand, a physical descriptor structure is created for any physical computing resource object 101, as shown in step S21 in Figure 2c. In some subsequent descriptions, the physical descriptor structure may be referred to as pcpu, and the physical descriptor structure is used to save the context information of any physical computing resource object running in root mode when the mode is switched. The context information of any physical computing resource object in root mode may include but is not limited to: the values ​​of various registers used by any physical computing resource object, the status information of any physical computing resource object, the status information of the host machine, and related configuration information. Among them, the related configuration information includes but is not limited to: the frequency of the high voltage (HV) timer, etc.

[0083] In this embodiment, the implementation method of the physical descriptor structure is not limited. Any implementation structure that can save the context information of the physical computing resource object running in root mode is applicable to the embodiment of the present disclosure. In an optional embodiment, the physical descriptor structure may include but is not limited to the following parts or fields: a first register structure (regs), a field that carries the status information of the physical computing resource object, a field that carries the status information of the host machine, and a field that carries configuration information. The first register structure may include but is not limited to: a general register field, a debug register field, a stack-related register field, a floating point unit (fpu) register field, a model specific register (MSR) field, etc.

[0084] To switch modes for the host operating system, a virtualization descriptor structure is created for any physical computing resource object, as shown in step S22 in Figure 2c. This virtualization descriptor structure may be referred to as vcpu in the subsequent descriptions. This virtualization descriptor structure is used to synchronize context information in the physical descriptor structure during mode switching. This virtualization descriptor structure represents the virtual computing resource object obtained by virtualizing the physical computing resource object.

[0085] Among them, the implementation method of the virtualization descriptor structure is not limited, and any implementation structure that can synchronize the context information in the physical computing resource object is applicable to the embodiment of the present disclosure. In an optional embodiment, the vcpu may include but is not limited to the following fields: a second register structure (regs) corresponding to the first register structure. In addition, the vcpu also includes: a field that carries a virtual computing resource object identification instruction (such as cpu_id), a field that carries an interrupt vector number (apic_id), a field that carries the running status of the vcpu, a field that carries a switch mark for the state change during the vcpu switching process, a field that carries relevant configuration information of the APIC register, a field that carries configuration information of a specific model register (such as an MSR register), a field that carries configuration information of a processor opcode (such as CPUID), a field that carries a descriptor of an interrupt (Program Interruption, PI), and a field that carries configuration information related to exit events, etc.

[0086] Furthermore, in order to switch the host operating system mode, a virtualization control structure is created for each physical computing resource object, as shown in step S23 in Figure 2c. For example, the virtualization control structure can be implemented as a vmcs (Virtual Machine Control System), which is used to store the running state information and running control information of each physical computing resource object in non-root mode. For example, the running state information of the physical computing resource object in non-root mode can be the values ​​of some registers and the state of the physical computing resource object, such as active, halted (HLT), or shutdown. The operation control information mainly refers to the control information of the host operating system in non-root mode. For example, the operation control information saved in the virtualization control structure may include but is not limited to the following fields: a field carrying the exit event of the non-root mode, a field carrying the register bitmap (msr_bitmap) of a specific processor model, a field carrying APIC virtualization, a field carrying interrupt virtualization, a field carrying a preemption timer, a field carrying clock configuration or a field carrying IO control information, etc. The information in the corresponding field may be configured as needed when initializing the virtualization control structure according to actual conditions.

[0087] In an optional embodiment, the virtualization layer 30 may also create an IO bitmap (io_bitmap), as shown in step S24 of FIG2c . The IO bitmap is used to record the access rights of any physical computing resource object to various IO ports in non-root mode. The access rights are related to the IO control information in the operation control information. The access rights can default to 0, allowing access to all IO ports. If it is necessary to intercept some IO ports later, the io_bitmap can be configured as needed.

[0088] Furthermore, the virtualization layer 30 can also create a new stack. For the convenience of description and distinction, the new stack is referred to as the first stack, as shown in step S25 in Figure 2c. The new stack (i.e., the first stack) is relative to the old stack. For the convenience of description and distinction, the old stack is referred to as the second stack. The old stack (i.e., the second stack) is the stack currently used by any physical computing resource object. After switching from root mode to non-root mode, any physical computing resource object will continue to use the old stack to run in non-root mode. It is explained here that after switching from root mode to non-root mode, the physical computing resource object can be implemented as a virtual physical computing resource object. For example, the physical CPU can be implemented as a virtual CPU. The first stack is a stack prepared for the virtualization layer 30, which is used for the virtualization layer 30 to perform memory access based on the new stack (i.e., the first stack) in root mode.

[0089] In an optional embodiment, the virtualization layer 30 may also initialize the virtualization descriptor structure and the virtualization control structure separately, as shown in step S26 in FIG2c . The initialization process is the process of enabling the required functions, applying for memory pages for the required functions, and configuring initial values. Specifically, the initialization process for the virtualization descriptor structure may be to add the initialization information corresponding to the functions to be enabled to the corresponding fields of the virtualization descriptor structure. The initialization process for the virtualization control structure may be to add the initialization information corresponding to the functions to be enabled to the corresponding fields of the virtualization control structure.

[0090] Optionally, the virtualization layer 30 may configure, in the virtualization control structure, operation control information for any physical computing resource object when running in non-root mode. For example, the operation control information may include, but is not limited to, at least one of: MSR control information, PI control information, APIC control information, hardware register operation instruction information, memory page table entry address, and configuration information related to exiting non-root mode.

[0091] Further optionally, when configuring the operation control information, the virtualization layer 30 is specifically configured to perform at least one of the following configuration operations:

[0092] a3. Create a model-specific register bitmap (e.g., msr_bitmap) and allocate a second physical page to store the bitmap;

[0093] b3. Set the PI interrupt function and set the PI notification vector;

[0094] c3. Set the APIC interrupt control function, allocate the third physical page to store the APIC table from the physical address space, and save the base address of the page where the APIC table is located in the APIC field; in addition, set APIC_ID to the apic_id of the current physical computing resource object (such as the CPU), and the APIC Local Vector Register (APIC_LVR) inherits the settings of the current physical computing resource object (such as the CPU); if the APIC timer is intercepted, the timer configuration and processing function can also be configured;

[0095] d3. Set the processor opcode (e.g., CPUID) and establish a cache for virtual computing resource objects;

[0096] e3. Set the PAUSE-Loop Exiting (PLE). The PLE configuration is used to reduce the waste of virtual computing resources caused by loop waiting.

[0097] f3. Save the entry address of the multi-level memory page generated in step S1 in the virtualization control structure. At the same time, set the RIP instruction position executed after exiting the non-root mode.

[0098] g3, default configuration of general registers in root mode and non-root mode.

[0099] The process of initializing each virtualization descriptor structure and virtualization control structure is as follows:

[0100] 1) Load each virtualization descriptor structure (vcpu) in turn and initialize each vcpu structure;

[0101] 2) Load the virtualization control structure (vmcs) structure corresponding to the vcpu as the current vmcs;

[0102] 3) Configure the operation control information for the current vmcs, i.e., execute steps a3 to g3 above;

[0103] 4) Clean up the current vmcs structure;

[0104] 5) Determine whether the vCPU to be initialized has been initialized. If not, repeat steps 1) to 4); if initialization is complete, end initialization.

[0105] In summary, mode switching for the host operating system involves switching from physical computing resource objects to virtual computing resource objects, and also involves synchronization of context information, access control of IO operations, and switching of memory access. Therefore, a physical descriptor structure corresponding to the physical computing resource object and a virtualization descriptor structure corresponding to the virtual computing resource object are created to synchronize context information during the mode switching process, and an IO bitmap is created to facilitate access control of IO operations during the mode switching process, and a first stack is created to facilitate the virtualization layer 30 to switch memory access during the mode switching process.

[0106] Among them, after creating the memory page table and various information-carrying objects, it means that the foundation for mode switching is laid. On this basis, the running host operating system can be switched from root mode to non-root mode based on the information-carrying objects and memory page tables.

[0107] S3: Switch the running host operating system from root mode to non-root mode based on the information carrying object and memory page table

[0108] In this embodiment, mode switching can be performed for any physical computing resource object, and the process of mode switching for each physical computing resource object is the same. For ease of description and distinction, the following description takes mode switching for a target physical computing resource object as an example, and the target physical computing resource object can be any physical computing resource object.

[0109] As shown in FIG2d , the process of performing a mode switch on a target physical computing resource object includes the following steps: Step S31: When performing a mode switch on a target physical computing resource object, the context information of the target physical computing resource object in root mode is saved in the physical descriptor structure corresponding to the target physical computing resource object. Step S32: The values ​​of each register and the configuration information of the segment registers in the context information in the physical descriptor structure are synchronized to the virtualization descriptor structure and virtualization control structure corresponding to the target physical computing resource object. Step S33: Based on the virtualization descriptor structure, the virtualization control structure, and the memory page table, the operation of the target physical computing resource object is controlled to switch the running host operating system from root mode to non-root mode.

[0110] For example, the values ​​of each register in the context information in the physical descriptor structure are synchronized to the virtualization descriptor structure corresponding to the target physical computing resource object, and the configuration information of the segment register in the context information in the physical descriptor structure is synchronized to the virtualization control structure corresponding to the target physical computing resource object. The configuration information of the segment register may include, but is not limited to, the size of the segment, the starting address of the segment, and the management attributes of the segment. For example, the management attributes of the segment may include: write-prohibited, execute-prohibited, or system-only.

[0111] In this embodiment, steps S1 and S2 may be executed when the virtualization layer 30 is started or initialized, and step S3 may be executed on demand according to dynamic requirements (external instructions). Whether to switch the mode of the target physical computing resource object may be determined by the external instructions.

[0112] In an optional embodiment, the host operating system 20 of this embodiment provides an external symmetric multi-processing (SMP) call interface, allowing an external party to send an SMP call request to any physical computing resource object on the physical machine. The SMP call request is used to indicate that a mode switch is required for any physical computing resource object. For ease of distinction and description, the example of an external party sending an SMP call request to a target physical computing resource object is used for explanation. For example, an upper-layer application running on the host operating system 20 can initiate an SMP call request to the target physical computing resource object, or a developer can initiate an SMP call request to the target physical computing resource object through the host operating system 20.

[0113] When the target physical computing resource object receives an SMP call request, it can initiate a call request for a switching function to trigger a mode switch. Accordingly, the virtualization layer 30 provides a switching function (such as the switch_vcpu function) for the host operating system to switch the mode, which is used for the target physical computing resource object to run the switching function to switch the host operating system from root mode to non-root mode, specifically referring to the execution of the operation of saving the context information of the target physical computing resource object in root mode to the physical descriptor structure corresponding to the target physical computing resource object and subsequent operations (such as steps S32 and S33) to switch the mode of the physical computing resource object. After entering the non-root mode, the virtualization layer 30 can also control the target physical computing resource object to exit from the non-root mode to the root mode when an exit event configured in the virtualization control structure occurs.

[0114] In an optional embodiment, during the mode switching process, before saving the context information, it can be determined whether the state of the switch mark corresponding to the target physical computing resource object is in the to-be-switched state; if the judgment result is yes, the switch mark is updated to the switching state. For example, the target physical computing resource object can obtain the state of the switch mark. If the state of the switch mark is the unswitched state (such as VMX_OFF), the switch mark is updated to the switching state (such as VMX_SWITCH); if the state of the switch mark is the switching completed state (such as VMX_ON), ​​the SMP call is directly returned without executing the mode switch. Optionally, based on the return of the SMP call, some other finishing work can be done. The virtualization layer 30 can also configure the first instruction after entering the non-root mode for the first time, and the first instruction is the entry address of the switching function.

[0115] The switch function is divided into an upper half and a lower half. For example, the switch function can be entered through a function entry such as switch_vcpu. As the host operating system switches between different modes, the code path after entering the switch function will be different at different times. For the first switch from root mode to non-root mode, an SMP call can be initiated to the target physical computing resource object. This call is used to trigger the mode switch. First, the state of the switch flag is detected. If it is determined to be in the pending state, the mode switch is triggered and the upper half of the switch function is entered. In the upper half, the switch flag is first set to the switching state (e.g., VMX_SWITCH), and the first instruction to be executed after entering non-root mode is set, i.e., the entry address of the switch function. Thereafter, in the upper half of the switch function, the operation of switching the host operating system from root mode to non-root mode is executed. After the target physical computing resource object enters non-root mode, the first instruction set above is executed. This first instruction is the execution of the switch function. At this point, the flag bit has been set to the switching state, and the lower half of the switch function is entered. The switch is completed in the lower half of the switch function, and the SMP call is returned.

[0116] Optionally, for ease of distinction and description, the stack currently used by the target physical computing resource object (i.e., before switching to non-root mode) is referred to as the second stack. When the virtualization layer 30 saves the context information of the target physical computing resource object in the root mode into the physical descriptor structure corresponding to the target physical computing resource object, it is specifically used to: save the value of each register in the context information and the top and bottom addresses of the second stack into the physical descriptor structure. For example, the value of each register in the context information can be saved into the physical descriptor structure, specifically, the control register, segment register, and general register can be saved into the register structure in the physical descriptor structure, and the top and bottom addresses of the second stack can be saved into the stack corresponding fields of the host register of the physical descriptor structure (pcpu), which will be used in subsequent mode switching.

[0117] The virtualization layer 30 may also switch the second stack currently used by the target physical computing resource object to the newly created first stack, so that the virtualization layer 30 can continue to run based on the first stack in the root mode.

[0118] Further optionally, when controlling the execution of the target physical computing resource object based on the virtualization descriptor structure, the virtualization control structure, and the memory page table, the virtualization layer 30 is specifically configured to: load the values ​​of the dedicated registers in the virtualization control structure and the virtualization descriptor structure. Dedicated registers are a group of registers with specific functions and special uses that can be accessed and used by specific instructions or hardware modules. For example, PI registers, debug registers (DR) registers, MSR registers, or segment registers. Furthermore, the segment registers of the PCPU can be saved and the values ​​of the segment registers in the vCPU can be loaded. The execution control information in the virtualization control structure is injected into the target physical computing resource object, and the values ​​of the general registers in the virtualization descriptor structure are loaded. The general registers are a group of registers that can be used by developers to store general information such as data and addresses. General registers can be accessed and used by any instruction in the program. For example, pointer registers or index registers can be accessed and used. Loading the values ​​of the corresponding registers means loading the values ​​of the registers stored in the vCPU into specific hardware registers to enable the target physical computing resource object to run in non-root mode. Execute a mode switching instruction to control the target physical computing resource object to enter the non-root mode and start running from the first instruction, and perform memory management and access based on the memory page table during the running process.

[0119] Further optionally, after switching the running host operating system from root mode to non-root mode, the virtualization layer 30 may also restore the second stack to the addresses of the top and bottom of the stack saved in the physical descriptor structure, and update the switch flag to a switch completion state (e.g., VMX_ON). After switching from root mode to non-root mode, the second stack (i.e., the old stack) is restored to the addresses of the top and bottom of the stack saved in the physical descriptor structure, so that the target physical computing resource object continues to run based on the second stack in non-root mode.

[0120] The following describes the process of switching the host operating system from root mode to non-root mode using a running target physical computing resource object.

[0121] 1) An SMP call request is sent externally to the target physical computing resource object that needs to be switched. This call triggers the execution of the CPU mode switch, where the CPU mode switch is the switch from root mode to non-root mode;

[0122] 2) Upon receiving the SMP call request, the virtualization layer 30 determines the state of the switch flag corresponding to the current target physical computing resource object. If the switch flag is in the switch-completed state (VMX_ON), ​​the SMP call is directly returned; if the switch flag is in the unswitched state (VMX_OFF), a mode switch is triggered, and the process proceeds to step 3.

[0123] 3) The virtualization layer 30 enters the switching function through a function entry, such as switch_vcpu. The switching function is divided into an upper half and a lower half. Depending on whether it is the first mode switch, different code paths of the switching function can be entered. The upper half is entered for the first mode switch, and the lower half is entered for non-first mode switches.

[0124] 4) For the first entry into the switch function, the target physical computing resource object is in the unswitched root mode, and the upper half of the switch function is entered. In the upper half, the switch flag is first set to the switching state (e.g., VMX_SWITCH);

[0125] 5) Set the first instruction to be executed after entering non-root mode. Similar to the first instruction above, the first instruction is still the entry address of the switch function, but the switch mark is now in the switching state, and the second half of the switch function will be entered.

[0126] 6) Save the values ​​of registers regs of the current target physical computing resource object, including: saving registers such as KERNEL_GDTR_BASE, SYSENTER_ESP, SREG_TR_BASE, SREG_GDTR_BASE, SREG_LDTR_SEL, and REGS_CR4 on the host; saving the memory page table entry address to the REGS_CR3 register; saving segment registers such as the Data Segment Register (DS), Extra Segment Register (ES), Extra Segment Register (FS), and Extra Segment Register (GS); and saving FPU registers. The virtualization layer 30 can then use a section of assembly to directly read the values ​​of the current general registers. For example, general registers may include, but are not limited to: rax (accumulator), rbx (base register), rdx (data register), rsi (register used as source operand), rdi (register used as destination operand), rbp (register storing the stack bottom pointer), r8-r9 (registers storing function parameters), and r9-r15 (registers saved by the callee).

[0127] Among them, KERNEL_GDTR_BASE is often used as a macro to describe the base address of the operating system kernel's Global Descriptor Table Register (GDTR). SYSENTER_ESP stores the base address of the kernel's local Task State Segment (TSS) descriptor. SREG_TR_BASE is often used to obtain the descriptor of the currently executing task. This descriptor can be used to obtain the memory addresses of the current task's code and data, as well as task status information. SREG_GDTR_BASE is often used to obtain the base address of the Global Descriptor Table Register, which can be used to obtain the address of the descriptor table, thereby accessing and controlling the properties of various segments in the system. SREG_LDTR_SEL is often used to obtain the selector of the Local Descriptor Table Register, which can be used to select a specific descriptor, thereby accessing and controlling the properties of various segments in the current task. REGS_CR4 is often used to obtain the value of the CR4 (Control Register). This value can be used to query or modify certain processor features and behaviors.

[0128] 7) Save the top and bottom addresses of the second stack currently running on the target physical computing resource object to the corresponding stack fields of the host register of the pcpu, which will be used in subsequent mode switching.

[0129] 8) Switch to the new stack (ie, the first stack) created for the virtual descriptor structure (vcpu), so that the virtualization layer 30 runs based on the new stack in the root mode.

[0130] 9) Prepare the registers required to perform vCPU switching, including the following operations:

[0131] a4. First, the virtualization control structure (vmcs) corresponding to the vcpu will be loaded;

[0132] b4. Then associate the virtual descriptor structure (vcpu) with the current physical descriptor structure (pcpu);

[0133] c4. Convert the previously saved values ​​of regs in pcpu to regs in vcpu, and load the configurations of various segment registers into vmcs so that the previous instructions can be continued after entering non-root mode;

[0134] d4. Complete the vcpu register preparation and clean up the selected vmcs;

[0135] 10) Start executing vcpu switching and enter non-root mode. It should be noted that vcpu switching is executed by the virtualization layer 30, and when entering non-root mode for the first time, the virtualization layer 30 will continue to execute a period of infinite loop logic, for example: while (1) {vcpu_run(vcpu);}, which indicates that it is in a loop of executing vcpu operation to complete the switching function. When entering non-root mode later, the normal vcpu operation logic is directly executed. The switching process specifically includes:

[0136] a5. Prepare to enter non-root mode and load the corresponding vmcs;

[0137] b5. Load the PI register, DR register or MSR register of the vcpu, save the GS register of the current pcpu, and load the GS register of the vcpu at the same time;

[0138] c5. Enter the loop of non-root mode, including the following operations:

[0139] i. The entry will first set the interrupt to be injected, synchronize the interrupt of PI and set the preemption timer;

[0140] ii. Set the vcpu control field (in_guest=1);

[0141] iii. Load the previously saved general registers;

[0142] iv. Enter non-root mode by opening the (VMLAUNCH) command. Note that when switching modes for the first time, you can jump directly to step 11.

[0143] 11) At this time, the target physical computing resource object has entered the non-root mode. The first instruction after executing the non-root mode is set to execute the switching function (switch_vcpu) in step 5). At this time, the switching mark is in the switching state and will enter the lower half of the switching function. The purpose is to complete the SMP call process of initiating the switching vcpu to avoid other physical computing resource objects that have issued SMP calls waiting for the switching to complete.

[0144] The following operations can be performed in the lower half of the switching function:

[0145] i. Restore the second stack (i.e., the old stack) to the stack value last saved in the host register of the PCPU; the purpose of this is to allow the target physical computing resource object to continue to run in non-root mode based on the restored old stack;

[0146] ii. Set the switch flag to the switch completion state (VMX_ON);

[0147] iii. The switch is completed and the SMP call returns.

[0148] 12) After the SMP call returns, the target physical computing resource object can continue to run in non-root mode. When an exit event is triggered, an exit operation will be executed. This exit operation is a relatively independent operation and will only be executed when it is triggered. Specifically, it includes the following operations:

[0149] i. When exiting, the general registers will also be saved to the corresponding fields of the vcpu;

[0150] ii. Set the exit execution flag (e.g., vmx_return) to resume execution after exiting to root mode;

[0151] iii. After exiting non-root mode, reset the control field (e.g., in_guest=0) and set the launch field (e.g., launched=1);

[0152] iv. Process the exit event. If it can be processed, directly call the preset processing function; otherwise, jump out of the loop for processing;

[0153] v. If you exit the loop, the GS register of the vcpu will be saved, and then the GS register of the pcpu will be restored. At the same time, the PI register, DR register, MSR register, etc. of the current vcpu will be saved;

[0154] vi. Clear the selected vmcs and set the launch field (e.g., launched = 0);

[0155] It should be noted that operations before entering non-root mode are performed by the virtualization layer 30 in root mode. After entering non-root mode, normal vCPU operation logic is executed. A complete mode switch logic includes the process of entering non-root mode, vCPU operation, and vCPU exiting and returning to root mode. The operations of entering non-root mode and exiting and returning to root mode are also performed in root mode.

[0156] In an embodiment of the present disclosure, it is considered to utilize hardware virtualization functions to insert a lightweight virtualization layer between the host operating system and hardware resources, implement a virtual resource provision function in the virtualization layer, and have the virtualization layer switch the running host operating system from root mode to non-root mode, thereby providing at least one virtual resource in non-root mode and running at least one application on the at least one virtual resource, the at least one application including at least one application that the host operating system cannot run in root mode due to insufficient resources. Without reinstalling the host operating system, the virtual resource provision function can be flexibly implemented for the running host operating system, solving the problem of the host operating system being unable to run applications in root mode due to insufficient resources caused by the failure to enable or lack of relevant system functions, allowing the host operating system to support the operation of more applications, and facilitating the expansion of the host operating system's capabilities. Among them, after the host operating system switches from root mode to non-root mode, the at least one application that can be run on the virtual resources provided in non-root mode includes, but is not limited to, performing target functions such as memory management, file management, virtualization functions, and scheduling optimization in non-root mode.

[0157] In the following embodiments, the memory page fault management in memory management is taken as an example to explain the memory page fault management process in non-root mode in detail. It is explained here that one application scenario of memory page fault is memory swap, that is, memory page fault may occur during the memory swap process, but memory page fault is not only used in the memory swap process. In order to facilitate the embodiment of the present disclosure to reflect the advantages of memory page fault management implemented in non-root mode, the use of memory page fault for memory swap is used as an example for explanation, and memory swap is first introduced.

[0158] The memory swap function in a host operating system (e.g., Linux) is a mechanism that uses free hard disk space as memory expansion. When the main memory (e.g., RAM) runs low on memory pages, swapping out infrequently used pages is done by moving them to the hard disk to free up space for other pages. This process is called page swapping. When a process uses the swapped-out pages again, a page swap in is triggered.

[0159] The swap function of the host operating system (such as the Linux system) includes two aspects: the swap partition and the swap file. The swap partition is used to exchange hard disk space and is also called swap space. It is usually allocated when the host operating system is installed. You can also manually create a swap partition using the fdisk command or mkswap command. After dividing the free disk space into a swap partition, you can mount it as a swap partition using the swapon command. The advantages of the swap partition are high speed and high stability, but the partition size needs to be planned in advance and cannot be adjusted dynamically. Among them, the fdisk command is used to create, delete, modify, and display disk partitions. The mkswap command is used to create a swap partition. The swapon command is used to enable the swap partition on a physical machine.

[0160] A swap file is a file created on a regular file system that can be used as swap space. Use commands such as dd and fallocate to create a swap file, then use the mkswap command to format it as a swap file system, and finally use the swapon command to mount it as swap space. Both the dd and fallocate commands can be used to create files. Swap files offer the advantages of high flexibility, dynamic resizing, and ease of management, but their performance is slightly inferior to that of a swap partition.

[0161] In host operating systems (such as Linux), the swap space size is typically set to two or three times the physical memory. If physical memory is sufficient, swap space usage will be low and will not significantly impact physical machine performance. If physical memory is insufficient, swap space usage will be high, severely impacting physical machine performance. Therefore, the performance of the swap space is crucial to the stability of physical machine performance.

[0162] Furthermore, the swap function of the host operating system (e.g., Linux) kernel is for user processes and does not directly affect the swapping of kernel pages. If memory is insufficient, the kernel will attempt to reclaim some unnecessary pages and swap them to disk using the swap function to free up memory space. These unnecessary pages include user process pages, cache pages, anonymous memory pages, etc., but not kernel pages, as kernel pages are generally not swappable. Kernel code and data are typically locked in memory and not swapped to disk, so they are not affected by the swap function. Furthermore, the swap function currently only supports small 4KB pages, while large pages (e.g., 2MB or 1GB) are increasingly used in cloud computing scenarios, which do not yet support large page swap. If the running operating system does not have the swap function configured, enabling it online can only use the file method, which has very low performance and can seriously affect system stability.

[0163] Although some system functions missing from the host operating system can be implemented by loading functional modules, this is invasive and subject to the constraints of various existing structures and function functions of the operating system. It may not solve all problems, such as the kernel page swapping mentioned above. In the embodiment of the present disclosure, based on the virtualization layer, the system switches from root mode to non-root mode, and provides virtual memory resources in non-root mode, so that the memory swap function can be implemented, which is no longer limited by whether the host operating system has the memory swap function enabled. In addition, the solution provided by the embodiment of the present disclosure is more transparent, imperceptible to upper-layer applications, and can achieve more comprehensive functions.

[0164] Furthermore, in the disclosed embodiments, when creating a memory page table, a hybrid mapping granularity approach combining a first page granularity, a second page granularity, a third page granularity, and a fourth page granularity is adopted, supporting not only small page granularity but also large page granularity, thereby meeting the requirements of different physical page mappings and improving the flexibility of memory mapping. Using a small page granularity for memory mapping can reduce internal fragmentation in memory pages and reduce memory waste; using a large page granularity for memory mapping can reduce page table entry data, reduce the level of memory page tables, reduce memory management overhead, and improve the performance of physical computing resource objects.

[0165] Furthermore, in the disclosed embodiments, when creating a memory page table, the physical address space of the host machine is no longer limited. It is allowed to create a memory page table for the full physical address space, that is, to support full memory mapping. Therefore, it is possible to create a memory page table for both user-mode pages and kernel-mode pages. By supporting memory mapping of the full physical address space, a basic framework is provided for various subsequent operations based on memory mapping. For example, when performing memory swapping based on memory mapping, it not only supports swapping of user-mode pages but also supports swapping of kernel-mode pages, that is, supports full memory swapping. The following is a brief description of the process of implementing memory page fault management after switching to non-root mode:

[0166] 1) The above-mentioned memory page table (such as ept page table) prepared for the mode switching of the host operating system has a one-to-one correspondence between the client physical address (GPA) and the host physical address (HPA). Among them, normal operation will not trigger a page fault exception in non-root mode. In order to expand the memory management function of the host operating system, some memory pages (the page granularity can be 4K or 2M) can be recovered by recycling free pages, or compressing used pages, or swapping memory pages to disk, or expanding new virtual memory space, and the corresponding memory page table page table entries can be cleared. In this way, subsequent accesses in non-root mode can trigger a page fault exception. At present, the memory page table of a batch of free pages can be directly cleared to trigger a page fault exception.

[0167] 2) Since a batch of memory pages have been cleared and recycled in step 1), a simple memory management system can be used, for example, to manage memory using status bits for subsequent page fault exceptions.

[0168] 3) Before performing page fault exception processing, a processing function may be set in the exit event of the non-root mode, for example, a page fault processing function (ept_handler) associated with the exit reason EPT page fault (EXIT_REASON_EPT_VIOLATION) may be set.

[0169] 4) In the page fault handling function (ept_handler), an unused host physical page can be selected from the underlying memory management system and marked as used.

[0170] 5) Establish a mapping relationship between the physical address (HPA) of the unused host physical page and the guest physical address (GPA) where the page fault occurs, and create a corresponding page table entry in the corresponding memory page table (e.g., ept page table) so that the host operating system can implement memory management in non-root mode. The memory management here includes but is not limited to memory swapping.

[0171] In addition to providing a system embodiment, the embodiment of the present disclosure also provides a virtualization processing method. The process of the virtualization processing method provided by the embodiment of the present disclosure is described below.

[0172] FIG3 is a flow chart of a virtualization processing method provided by an exemplary embodiment of the present disclosure. The method is applied to a virtualization layer in a physical machine. The virtualization layer is located between the hardware resources of the physical machine and the host operating system. As shown in FIG3 , the method includes:

[0173] 301. Switch the running host operating system from root mode to non-root mode;

[0174] 302. In non-root mode, provide at least one virtual resource and run at least one application on the at least one virtual resource, the at least one application including at least an application that the host operating system cannot run in root mode due to insufficient resources.

[0175] In an optional embodiment, the hardware resources include at least one physical computing resource object and a physical address space, the physical address space has a host physical address, and the host operating system runs on the physical computing resource object; switching the running host operating system from root mode to non-root mode includes: creating a memory page table to store the mapping relationship between the client physical address in non-root mode and the host physical address in root mode; creating an information carrying object required for mode switching, the information carrying object is used to synchronize context information between root mode and non-root mode; based on the information carrying object and the memory page table, switching the running host operating system from root mode to non-root mode.

[0176] Optionally, creating a memory page table includes: establishing a page table structure corresponding to the memory page table, applying for the root page of the memory page table from the physical address space; generating an entry address of the memory page table based on the host physical address of the root page, and adding it to the page table structure; creating a multi-level memory page table based on the address range of the physical address space and the page granularity used to map the client physical address to the host physical address.

[0177] Further optionally, a multi-level memory page table is created based on the address range of the physical address space and the page granularity used to map the client physical address to the host physical address, including: for the first address space, forming a first mapping relationship between the client physical address and the host physical address with a first page granularity, and creating a multi-level memory page table corresponding to the first address space based on the first mapping relationship; for the input / output IO address space in the second address space, forming a second mapping relationship between the client physical address and the host physical address with a second page granularity, and creating a multi-level memory page table corresponding to the IO address space based on the second mapping relationship; wherein, the second address space is larger than the first address space, and the second page granularity is larger than the first page granularity.

[0178] Further optionally, the method provided by the embodiment of the present disclosure also includes: for the memory address space in the second address space, forming a third mapping relationship between the client physical address and the host physical address with a third page granularity, and creating a multi-level memory page table corresponding to the memory address space according to the third mapping relationship; wherein the third page granularity is smaller than the second page granularity.

[0179] Further optionally, the method provided by the embodiment of the present disclosure also includes: in a case where the memory address space contains an advanced programmable interrupt controller APIC page of the fourth page granularity, obtaining the first physical page of the third page granularity to which the APIC page belongs and the target memory page table corresponding to the first physical page; the third page granularity is larger than the fourth page granularity; the first physical page is split into multiple sub-pages of the fourth page granularity, and a next-level memory page table is added under the target memory page table, and the next-level memory page table is used to store the host machine physical addresses of the multiple split sub-pages.

[0180] In an optional embodiment, creating an information-bearing object required for mode switching includes: creating a physical descriptor structure for any physical computing resource object, the physical descriptor structure being used to save the context information of any physical computing resource in root mode when the mode is switched; creating and initializing a virtualization descriptor structure for any physical computing resource object, the virtualization descriptor structure being used to synchronize the context information in the physical descriptor structure when the mode is switched; and creating and initializing a virtualization control structure for any physical computing resource object, to save the running state information and running control information of any physical computing resource object in non-root mode.

[0181] Optionally, the method provided by the embodiment of the present disclosure also includes: creating a first stack and an IO bitmap, the first stack is used for the virtualization layer to access memory in root mode, and the IO bitmap is used to record the access rights of any physical computing resource object to each IO port in non-root mode, and the access rights are related to the IO control information in the operation control information.

[0182] Further optionally, based on the information carrying object and the memory page table, the running host operating system is switched from root mode to non-root mode, including: when the mode of the target physical computing resource object is switched, the context information of the target physical computing resource object in root mode is saved to the physical descriptor structure corresponding to the target physical computing resource object; the value of each register and the configuration information of the segment register in the context information in the physical descriptor structure are synchronized to the virtualization descriptor structure and virtualization control structure corresponding to the target physical computing resource object respectively; according to the virtualization descriptor structure, the virtualization control structure and the memory page table, the operation of the target physical computing resource object is controlled to switch the running host operating system from root mode to non-root mode.

[0183] Further optionally, the method provided by the embodiment of the present disclosure also includes: before saving the context information, determining whether the state of the switch mark corresponding to the target physical computing resource object is a to-be-switched state; if the judgment result is yes, updating the switch mark to a switching state, and configuring the first instruction after entering the non-root mode for the first time, the first instruction pointing to the entry address of the switching function.

[0184] Further optionally, the context information of the target physical computing resource object in the root mode is saved in the physical descriptor structure corresponding to the target physical computing resource object, including: saving the value of each register in the context information and the top and bottom addresses of the second stack in the physical descriptor structure, and the second stack is used for the target physical computing resource object to perform memory access after switching to the non-root mode; the method provided by the embodiment of the present disclosure also includes: switching the second stack currently used by the target physical computing resource object to the first stack, so that the virtualization layer 30 runs based on the first stack in the root mode.

[0185] Further optionally, the operation of the target physical computing resource object is controlled according to the virtualization descriptor structure, the virtualization control structure and the memory page table, including: loading the values ​​of the dedicated registers in the virtualization control structure and the virtualization descriptor structure; injecting the operation control information in the virtualization control structure into the target physical computing resource object, and loading the values ​​of the general registers in the virtualization descriptor structure; executing a mode switching instruction to control the target physical computing resource object to enter a non-root mode and start running from the first instruction, and performing memory management and access based on the memory page table during the running process.

[0186] Further optionally, the method provided by the embodiment of the present disclosure further includes: restoring the second stack to the addresses of the top and bottom of the stack saved in the physical descriptor structure, and updating the switching mark to a switching completion state.

[0187] In an optional embodiment, the method provided by the embodiment of the present disclosure also includes: receiving a function call request initiated by the target physical computing resource object to request to call a switching function in the virtualization layer to perform a mode switch, wherein the target physical computing resource object initiates a function call request to the virtualization layer when receiving an SMP call request sent externally; according to the function call request, running the switching function to execute the operation of saving the context information of the target physical computing resource object in the root mode to the physical descriptor structure corresponding to the target physical computing resource object and subsequent operations to perform a mode switch on the physical computing resource object.

[0188] In an optional embodiment, running at least one application on at least one virtual resource provided in non-root mode includes: controlling the target physical computing resource to perform at least one of memory page fault management, file management, and memory swap management in non-root mode.

[0189] The detailed implementation and beneficial effects of each step in the method shown in FIG3 provided by the embodiment of the present disclosure have been described in detail in the aforementioned embodiments and will not be elaborated on here.

[0190] It should be noted that the execution entity of each step of the method provided in the above embodiment can be the same device, or the method can be executed by different devices. For example, the execution entity of steps 301 to 302 can be device A; for another example, the execution entity of step 301 can be device A, and the execution entity of step 302 can be device B; and so on.

[0191] In addition, in some of the processes described in the above embodiments and the accompanying drawings, multiple operations that appear in a specific order are included, but it should be clearly understood that these operations may not be executed in the order in which they appear in this article or may be executed in parallel. The sequence numbers of the operations, such as 301, 302, etc., are only used to distinguish between different operations, and the sequence numbers themselves do not represent any execution order. In addition, these processes may include more or fewer operations, and these operations may be executed in sequence or in parallel. It should be noted that the descriptions of "first", "second", etc. in this article are used to distinguish different messages, devices, modules, etc., and do not represent the order of precedence, nor do they limit "first" and "second" to be different types.

[0192] Figure 4 is a structural diagram of a virtualization processing device provided by an exemplary embodiment of the present disclosure. The device corresponds to the virtualization layer in the physical machine. The virtualization layer is located between the hardware resources of the physical machine and the host operating system. As shown in Figure 4, the device includes: a switching component 41 and an execution component 42.

[0193] A switching component 41 is configured to switch the running host operating system from the root mode to the non-root mode;

[0194] The execution component 42 is configured to provide at least one virtual resource in non-root mode and run at least one application on the at least one virtual resource; wherein the at least one application includes at least an application that the host operating system cannot run in root mode due to insufficient resources.

[0195] In an optional embodiment, the hardware resources include at least one physical computing resource object and a physical address space, the physical address space has a host physical address, and the host operating system runs on the physical computing resource object; the switching component is specifically used to: create a memory page table to store the mapping relationship between the client physical address in non-root mode and the host physical address in root mode; create an information carrying object required for mode switching, the information carrying object is used to synchronize context information between root mode and non-root mode; based on the information carrying object and the memory page table, switch the running host operating system from root mode to non-root mode.

[0196] Optionally, the switching component is specifically used to: establish a page table structure corresponding to the memory page table, apply for the root page of the memory page table from the physical address space; generate the entry address of the memory page table according to the host physical address of the root page, and add it to the page table structure; create a multi-level memory page table according to the address range of the physical address space and the page granularity used to map the client physical address to the host physical address.

[0197] Further optionally, the switching component is specifically used to: for the first address space, form a first mapping relationship between the client physical address and the host physical address with a first page granularity, and create a multi-level memory page table corresponding to the first address space based on the first mapping relationship; for the input / output IO address space in the second address space, form a second mapping relationship between the client physical address and the host physical address with a second page granularity, and create a multi-level memory page table corresponding to the IO address space based on the second mapping relationship; wherein, the second address space is larger than the first address space, and the second page granularity is larger than the first page granularity.

[0198] Further optionally, the device also includes: forming a component and creating a component; the forming component is configured to form a third mapping relationship between the client physical address and the host physical address at a third page granularity for the memory address space in the second address space, and the creating component is configured to create a multi-level memory page table corresponding to the memory address space according to the third mapping relationship; wherein the third page granularity is smaller than the second page granularity.

[0199] Further optionally, the device also includes: an acquisition component, a splitting component and an adding component; the acquisition component is configured to acquire the first physical page of the third page granularity to which the APIC page belongs and the target memory page table corresponding to the first physical page when the memory address space contains an APIC page of the fourth page granularity; the third page granularity is larger than the fourth page granularity; the splitting component is configured to split the first physical page into multiple sub-pages of the fourth page granularity, and the adding component is configured to add a next-level memory page table under the target memory page table, and the next-level memory page table is used to store the host physical addresses of the multiple split sub-pages.

[0200] In an optional embodiment, the switching component is specifically used to: create a physical descriptor structure for any physical computing resource object, and the physical descriptor structure is used to save the context information of any physical computing resource in root mode when the mode is switched; create and initialize a virtualization descriptor structure for any physical computing resource object, and the virtualization descriptor structure is used to synchronize the context information in the physical descriptor structure when the mode is switched; create and initialize a virtualization control structure for any physical computing resource object, so as to save the running state information and running control information of any physical computing resource object in non-root mode.

[0201] In an optional embodiment, a component is created and further used to: create a first stack and an IO bitmap, the first stack is used for the virtualization layer to access memory in root mode, and the IO bitmap is used to record the access rights of any physical computing resource object to each IO port in non-root mode, and the access rights are related to the IO control information in the operation control information.

[0202] In an optional embodiment, the switching component is specifically used to: when switching the mode of the target physical computing resource object, save the context information of the target physical computing resource object in the root mode to the physical descriptor structure corresponding to the target physical computing resource object; synchronize the values ​​of each register and the configuration information of the segment register in the context information in the physical descriptor structure to the virtualization descriptor structure and the virtualization control structure corresponding to the target physical computing resource object; control the operation of the target physical computing resource object according to the virtualization descriptor structure, the virtualization control structure and the memory page table, so as to switch the running host operating system from root mode to non-root mode.

[0203] Further optionally, the device also includes: a judgment component, an update component and a configuration component; the judgment component is configured to judge whether the state of the switch mark corresponding to the target physical computing resource object is a to-be-switched state before saving the context information; the update component is configured to update the switch mark to a switching state if the judgment result is yes; the configuration component is configured to configure the first instruction after entering the non-root mode for the first time.

[0204] Further optionally, the switching component is specifically used to: save the values ​​of each register in the context information and the top and bottom addresses of the second stack into the physical descriptor structure, the second stack is the stack currently used by the target physical computing resource object, and is also the stack used by the target physical computing resource object after switching to non-root mode, so that the target physical computing resource object can access memory after switching to non-root mode; the switching component is also used to: switch the second stack currently used by the target physical computing resource object to the first stack, so that the virtualization layer can run based on the first stack in root mode.

[0205] Further optionally, the switching component is specifically used to: load the values ​​of the dedicated registers in the virtualization control structure and the virtualization descriptor structure; inject the operation control information in the virtualization control structure into the target physical computing resource object, and load the values ​​of the general registers in the virtualization descriptor structure; execute the mode switching instruction to control the target physical computing resource object to enter the non-root mode and start running from the first instruction, and perform memory management and access based on the memory page table during the running process.

[0206] Further optionally, the device also includes: a saving component and an updating component; the saving component is configured to restore the second stack to the addresses of the top and bottom of the stack saved in the physical descriptor structure, and the updating component is configured to update the switching mark to a switching completion state.

[0207] In an optional embodiment, the device also includes: a receiving component and a processing component; the receiving component is configured to receive a function call request initiated by the target physical computing resource object to request to call a switching function in the virtualization layer to perform a mode switch, wherein the target physical computing resource object initiates a function call request to the virtualization layer when receiving an SMP call request sent externally; the processing component is configured to run the switching function according to the function call request to execute the operation of saving the context information of the target physical computing resource object in the root mode to the physical descriptor structure corresponding to the target physical computing resource object and subsequent operations to perform a mode switch on the physical computing resource object.

[0208] In an optional embodiment, the execution component is specifically used to: control the target physical computing resource to perform at least one of memory page fault management, file management, and memory swap management in a non-root mode.

[0209] The detailed implementation and beneficial effects of each step in the device shown in FIG4 provided by the embodiment of the present disclosure have been described in detail in the aforementioned embodiment and will not be elaborated here.

[0210] Accordingly, an embodiment of the present disclosure further provides a computer-readable storage medium storing a computer program. When the computer program is executed, the steps that can be performed by the electronic device in the method embodiment shown in FIG. 3 can be implemented.

[0211] The above-mentioned memory can be implemented by any type of volatile or non-volatile memory device or a combination thereof, such as static random-access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.

[0212] The above-mentioned communication component is configured to facilitate wired or wireless communication between the device where the communication component is located and other devices. The device where the communication component is located can access a wireless network based on a communication standard, such as WiFi, 2G, 3G, 4G / LTE, 5G and other mobile communication networks, or a combination thereof. In an exemplary embodiment, the communication component receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component also includes a near field communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology and other technologies.

[0213] The above-mentioned display includes a screen, which may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touch screen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touch, slide, and gestures on the touch panel. The touch sensor can not only sense the boundary of the touch or slide action, but also detect the duration and pressure associated with the touch or slide operation.

[0214] The power supply assembly provides power to various components of the device in which the power supply assembly is located. The power supply assembly may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to the device in which the power supply assembly is located.

[0215] The above-mentioned audio component can be configured to output and / or input audio signals. For example, the audio component includes a microphone (MIC), and when the device where the audio component is located is in an operating mode, such as call mode, recording mode, and voice recognition mode, the microphone is configured to receive external audio signals. The received audio signal can be further stored in a memory or sent via a communication component. In some embodiments, the audio component also includes a speaker for outputting audio signals.

[0216] Those skilled in the art will appreciate that the embodiments of the present disclosure may be provided as methods, systems, or computer program products. Therefore, the present disclosure may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present disclosure may take the form of a computer program product implemented on one or more computer-readable storage media (including but not limited to magnetic disk storage, compact disc read-only memory (CD-ROM), optical storage, etc.) containing computer-usable program code.

[0217] The present disclosure is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present disclosure. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0218] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0219] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0220] In a typical configuration, a physical machine includes one or more processors (Central Processing Unit, CPU), input / output interfaces, network interfaces, and memory.

[0221] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.

[0222] The above are merely examples of the present disclosure and are not intended to limit the present disclosure. Various modifications and variations are possible for those skilled in the art. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present disclosure are intended to be included within the scope of the claims of the present disclosure. Industrial Applicability

[0223] The solution provided by the embodiment of the present disclosure can be applied to the process of expanding an existing operating system that is already running but has not been configured with relevant system functions. It can provide two operating modes for the host operating system in a running state, namely root mode and non-root mode, insert a virtualization layer between the hardware resources and the host operating system, and implement the virtual resource provision function at least in the virtualization layer, and the virtualization layer switches the running host operating system from root mode to non-root mode. In the non-root mode, at least one virtual resource is provided, and at least one application that the host operating system cannot run in the root mode due to insufficient resources is run on at least one virtual resource. Without reinstalling the host operating system, the virtual resource provision function can be flexibly implemented for the running host operating system to support the operation of more applications and expand the capabilities of the host operating system.

Claims

1. A virtualization processing method, wherein, Applied to the virtualization layer in a physical machine, the virtualization layer being located between the hardware resources of the physical machine and the host operating system, the method comprising: Switching the running host operating system from the root mode to the non-root mode; In the non-root mode, providing at least one virtual resource and running at least one application on the at least one virtual resource; Wherein, the at least one application at least includes the applications that the host operating system cannot run due to insufficient resources in the root mode.

2. The method according to claim 1, wherein, The hardware resources include at least one physical computing resource object and a physical address space, the physical address space having a host physical address, and the host operating system running on the physical computing resource object; Switching the running host operating system from the root mode to the non-root mode includes: Creating a memory page table for storing the mapping relationship between the guest physical address in the non-root mode and the host physical address in the root mode; Creating an information carrier object required for mode switching, the information carrier object being used to synchronize context information between the root mode and the non-root mode; Based on the information carrier object and the memory page table, switching the running host operating system from the root mode to the non-root mode.

3. The method according to claim 2, wherein Creating a memory page table includes: Establishing a page table structure corresponding to the memory page table and applying for the root page of the memory page table from the physical address space; Generating the entry address of the memory page table according to the host physical address of the root page and adding it to the page table structure; Creating a multi-level memory page table according to the address range of the physical address space and the page granularity for mapping the guest physical address and the host physical address.

4. The method according to claim 3, wherein Creating a multi-level memory page table according to the address range of the physical address space and the page granularity for mapping the guest physical address and the host physical address includes: For a first address space, forming a first mapping relationship between the guest physical address and the host physical address with a first page granularity, and creating a multi-level memory page table corresponding to the first address space according to the first mapping relationship; For the input / output (IO) address space in a second address space, forming a second mapping relationship between the guest physical address and the host physical address with a second page granularity, and creating a multi-level memory page table corresponding to the IO address space according to the second mapping relationship; Wherein, the second address space is larger than the first address space, and the second page granularity is larger than the first page granularity.

5. The method according to any one of claims 2-4, wherein, Creating an information carrier object required for mode switching includes: For any physical computing resource object, creating a physical descriptor structure for saving the context information of the any physical computing resource in the root mode during mode switching; For any physical computing resource object, creating and initializing a virtualization descriptor structure for synchronizing the context information in the physical descriptor structure during mode switching; For any physical computing resource object, create and initialize a virtualization control structure to be used for storing the running state information and running control information of the any physical computing resource object in non-root mode.

6. The method according to claim 5, wherein The method further includes: Create a first stack and an I / O bitmap. The first stack is used for the virtualization layer to access memory in root mode, and the I / O bitmap is used for recording the access permissions of the any physical computing resource object to each I / O port in non-root mode. The access permissions are related to the I / O control information in the running control information.

7. The method according to claim 6, wherein Based on the information carrier object and the memory page table, switch the running host operating system from root mode to non-root mode, including: In the case of performing a mode switch on a target physical computing resource object, save the context information of the target physical computing resource object in root mode to the physical descriptor structure corresponding to the target physical computing resource object; Synchronize the values of each register and the configuration information of the segment register in the context information in the physical descriptor structure to the virtualization descriptor structure and the virtualization control structure corresponding to the target physical computing resource object respectively; According to the virtualization descriptor structure, the virtualization control structure, and the memory page table, control the running of the target physical computing resource object to switch the running host operating system from root mode to non-root mode.

8. The method according to claim 7, wherein The method further includes: Before saving the context information, determine whether the status of the switch flag corresponding to the target physical computing resource object is the to-be-switched status; In the case where the determination result is yes, update the switch flag to the switching status and configure the first instruction after first entering the non-root mode.

9. The method according to claim 8, wherein Save the context information of the target physical computing resource object in root mode to the physical descriptor structure corresponding to the target physical computing resource object, including: Save the values of each register and the top and bottom addresses of the second stack in the context information to the physical descriptor structure. The second stack is used for the target physical computing resource object to access memory after switching to non-root mode; The method further includes: switching the second stack currently used by the target physical computing resource object to the first stack.

10. The method according to claim 9, wherein, According to the virtualization descriptor structure, the virtualization control structure, and the memory page table, control the running of the target physical computing resource object, including: Load the values of the special registers in the virtualization control structure and the virtualization descriptor structure; Inject the running control information in the virtualization control structure into the target physical computing resource object and load the values of the general registers in the virtualization descriptor structure; Execute a mode switch instruction to control the target physical computing resource object to enter non-root mode and start running from the first instruction, and perform memory management and access based on the memory page table during the running process.

11. A physical machine, wherein, The physical machine includes hardware resources and a host operating system running on the hardware resources. A virtualization layer is implemented between the hardware resources and the host operating system; The virtualization layer is used to switch the running host operating system from the root mode to the non-root mode, and in the non-root mode, provide at least one virtual resource and run at least one application on the at least one virtual resource, where the at least one application at least includes the application that cannot run due to insufficient resources in the root mode of the host operating system.

12. The physical machine according to claim 11, wherein, The hardware resources include at least one physical computing resource object and a physical address space, the physical address space has a host physical address, and the host operating system runs on the physical computing resource object; The virtualization layer switches the running host operating system from the root mode to the non-root mode, including: Creating a memory page table for storing the mapping relationship between the client physical address in the non-root mode and the host physical address in the root mode; Creating an information carrier object required for mode switching, where the information carrier object is used to synchronize context information between the root mode and the non-root mode; Based on the information carrier object and the memory page table, switching the running host operating system from the root mode to the non-root mode.

13. The physical machine according to claim 12, wherein, The virtualization layer creates a memory page table, including: Establishing a page table structure corresponding to the memory page table and applying for the root page of the memory page table from the physical address space; Generating the entry address of the memory page table according to the host physical address of the root page and adding it to the page table structure; Creating a multi-level memory page table according to the address range of the physical address space and the page granularity for mapping the client physical address and the host physical address.

14. The physical machine according to claim 12 or 13, wherein, The virtualization layer creates an information carrier object, including: For any physical computing resource object, creating a physical descriptor structure, where the physical descriptor structure is used to save the context information of the any physical computing resource in the root mode during mode switching; For any physical computing resource object, creating and initializing a virtualization descriptor structure, where the virtualization descriptor structure is used to synchronize the context information in the physical descriptor structure during mode switching; For any physical computing resource object, creating and initializing a virtualization control structure for saving the running state information and running control information of the any physical computing resource object in the non-root mode.

15. The physical machine according to claim 14, wherein, The virtualization layer is also used to: Create a first stack and an IO bitmap, where the first stack is used for the virtualization layer to access memory in the root mode, and the IO bitmap is used to record the access permissions of the any physical computing resource object to each IO port in the non-root mode, and the access permissions are related to the IO control information in the running control information.

16. The physical machine according to claim 14, wherein, The virtualization layer switches the running host operating system from the root mode to the non-root mode, including: In the case of switching the mode of the target physical computing resource object, saving the context information of the target physical computing resource object in the root mode to the physical descriptor structure corresponding to the target physical computing resource object; Synchronize the values of each register and the configuration information of the segment register in the context information in the physical descriptor structure to the virtualized descriptor structure and the virtualized control structure corresponding to the target physical computing resource object, respectively; Control the operation of the target physical computing resource object according to the virtualized descriptor structure, the virtualized control structure, and the memory page table, so as to switch the running host operating system from the root mode to the non-root mode.

17. The physical machine according to claim 16, wherein, The virtualization layer is further configured to: Before saving the context information, determine whether the status of the switching flag corresponding to the target physical computing resource object is the to-be-switched status; In the case where the determination result is yes, update the switching flag to the switching status and configure the first instruction after first entering the non-root mode.

18. A computer-readable storage medium storing a computer program, wherein, When the computer program is executed by a processor, cause the processor to implement the steps in the method according to any one of claims 1-10.

Citation Information

Patent Citations

  • Application program-oriented privileged hardware resource access method and electronic equipment

    CN111737656A

  • Virtual machine resource allocation method and device, medium and equipment

    CN113886018A

  • Management method and system for virtual machine running in host mode and user mode

    CN114489941A

  • Virtual machine operation method and device, equipment and storage medium

    CN115437751A

  • Virtual computer system control method and virtual computer system

    US20170277632A1