Memory resource allocation method, network cloud platform, computing device, computer-readable storage medium and computer program product
By obtaining the kernel loading address and querying the target scanning range, non-intrusive scanning is used to determine the free physical pages, which solves the problem of low memory resource utilization in the virtualized network cloud platform and realizes safe and efficient memory resource reallocation.
Patent Information
- Application Number
- PCT/IB2025/051454
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-13
- Filing Date
- 2025-02-12
- Publication Date
- 2025-09-18
AI Technical Summary
Existing technologies cannot effectively utilize memory resources in virtualized network cloud platforms because they cannot directly detect the physical page status of user virtual machines, resulting in data security and performance issues.
By obtaining the kernel loading address of the client operating system, determining the kernel version of the virtual machine's memory resources, and querying the target scanning range and parameters from the host database, a non-intrusive scan is performed to determine the free physical pages and realize memory resource reallocation.
Without intruding into the user's virtual machine, it achieves effective utilization of memory resources, ensures the isolation and security of the user's virtual machine, and avoids performance impact.
Smart Images

Figure IB2025051454_18092025_PF_FP_ABST
Abstract
Description
[0001] Memory Resource Allocation Method, Network Cloud Platform, Computing Device, Computer-Readable Storage Medium, and Computer Program Product. This disclosure claims priority to Chinese Patent Application No. 202410289612.0, filed with the China Patent Office on March 13, 2024, and entitled "Memory Resource Allocation Method, Network Cloud Platform, Computing Device, Computer-Readable Storage Medium, and Computer Program Product," the entire contents of which are incorporated herein by reference. Technical Field: Embodiments of the present disclosure relate to the field of cloud technology, and more particularly to a memory resource allocation method, network cloud platform, computing device, computer-readable storage medium, and computer program product. Background: With the development of cloud technology, in virtualized network cloud platforms, physical memory allocation and deallocation are often required to ensure that user virtual machines can operate independently and meet their memory requirements while improving memory resource utilization. A commonly used memory allocation and deallocation method currently implements memory resource reallocation by injecting a specific detection module into a user virtual machine to directly detect idle physical pages pre-allocated to the user virtual machine. However, due to concerns about data security and user VM performance, in actual application scenarios, it's impossible to directly detect or intrude into user VMs, resulting in an inability to effectively utilize memory resources. Therefore, a secure memory resource allocation method is needed. In view of this, embodiments of the present disclosure provide a memory resource allocation method. One or more embodiments of the present disclosure also relate to a network cloud platform, a memory resource allocation apparatus, a computing device, a computer-readable storage medium, and a computer program product to address technical deficiencies in the prior art. According to a first aspect of an embodiment of the present disclosure, a memory resource allocation method is provided, comprising: obtaining a kernel loading address of a client operating system; determining, based on the kernel loading address, a kernel version corresponding to a virtual machine memory resource, wherein the virtual machine memory resource includes a plurality of pre-allocated physical pages, and the client operating system is used to manage the virtual machine memory resource; based on the kernel version, querying a target scan range and target scan parameters for the plurality of physical pages from a target database, wherein the target database is provided in a host machine and pre-stores scan ranges and scan parameters for physical pages corresponding to respective kernel versions; scanning the virtual machine memory resource based on the target scan range and target scan parameters to determine a target physical page that is idle among the plurality of physical pages; and performing memory resource reallocation based on the target physical page.According to a second aspect of an embodiment of the present disclosure, a network cloud platform is provided, comprising virtual machine memory resources and a resource scheduler; the virtual machine memory resources include a plurality of pre-allocated physical pages; the resource scheduler is configured to obtain a kernel load address of a client operating system; based on the kernel load address, a kernel version corresponding to the virtual machine memory resources is determined, wherein the virtual machine memory resources include a plurality of pre-allocated physical pages, and the client operating system is configured to manage the virtual machine memory resources; based on the kernel version, a target scan range and target scan parameters for the plurality of physical pages are queried from a target database, wherein the target database is provided in a host machine and pre-stores scan ranges and scan parameters for physical pages corresponding to respective kernel versions; based on the target scan range and target scan parameters, the virtual machine memory resources are scanned to determine a target physical page in an idle state among the plurality of physical pages; and memory resource reallocation is performed based on the target physical page. According to a third aspect of an embodiment of the present disclosure, a memory resource allocation apparatus is provided, comprising: an acquisition module configured to acquire a kernel load address of a guest operating system; a determination module configured to determine, based on the kernel load address, a kernel version corresponding to a virtual machine memory resource; wherein the virtual machine memory resource comprises a plurality of pre-allocated physical pages, and the guest operating system is used to manage the virtual machine memory resources; a query module configured to query a target database for a target scan range and target scan parameters for the plurality of physical pages, based on the kernel version; wherein the target database is provided in a host machine and pre-stores the scan range and scan parameters for the physical pages corresponding to each kernel version; a scanning module configured to scan the virtual machine memory resources based on the target scan range and target scan parameters, and determine a target physical page that is idle among the plurality of physical pages; and an allocation module configured to perform memory resource reallocation based on the target physical page. According to a fourth aspect of an embodiment of the present disclosure, a computing device is provided, comprising: a memory and a processor; the memory being configured to store a computer program / instruction; and the processor being configured to execute the computer program / instruction. When executed by the processor, the computer program / instruction implements the steps of the aforementioned memory resource allocation method. According to a fifth aspect of embodiments of the present disclosure, a computer-readable storage medium is provided, storing a computer program / instructions. When executed by a processor, the program / instructions implement the steps of the aforementioned memory resource allocation method. According to a sixth aspect of embodiments of the present disclosure, a computer program product is provided, including a computer program / instructions. When executed by a processor, the computer program / instructions implement the steps of the aforementioned memory resource allocation method.One embodiment of the present disclosure obtains a kernel load address of a guest operating system; determines a kernel version corresponding to virtual machine memory resources based on the kernel load address, wherein the virtual machine memory resources include multiple pre-allocated physical pages used by the guest operating system to manage the virtual machine memory resources; queries a target database for target scan ranges and target scan parameters for multiple physical pages based on the kernel version, wherein the target database is provided in a host machine and pre-stores scan ranges and scan parameters for physical pages corresponding to various kernel versions; scans the virtual machine memory resources based on the target scan ranges and target scan parameters to determine a target physical page that is idle among the multiple physical pages; and performs memory resource reallocation based on the target physical page. Based on the kernel version of the guest operating system, this system obtains the target scan range and parameters for the user virtual machine from a database pre-stored with the physical page scan ranges and scan parameters for each kernel version. Based on this, it scans the virtual machine's memory resources and identifies the target idle physical pages. This system achieves memory resource redistribution without intrusion into the user virtual machine, ensuring the isolation and security of the user virtual machine and minimizing performance impacts. This system eliminates the need to intrude into the virtual machine and effectively utilizes memory resources while ensuring data security. BRIEF DESCRIPTION OF THE DRAWINGS Figure 1 is a schematic diagram of the process architecture of a memory resource allocation method; Figure 2 is a flow chart of a memory resource allocation method provided in one embodiment of the present disclosure; Figure 3 is a schematic diagram of the process architecture of a database construction method provided in one embodiment of the present disclosure; Figure 4 is a schematic diagram of the process architecture of a memory resource allocation method provided in one embodiment of the present disclosure; Figure 5 is a flowchart of the processing process of a memory resource allocation method for public cloud memory over-resolution provided in one embodiment of the present disclosure; Figure 6 is a schematic diagram of the structure of a network cloud platform provided in one embodiment of the present disclosure; Figure 7 is a schematic diagram of the structure of a memory resource allocation apparatus provided in one embodiment of the present disclosure; and Figure 8 is a block diagram of the structure of a computing device provided in one embodiment of the present disclosure. The following description sets forth numerous specific details to facilitate a thorough understanding of the present disclosure. However, the present disclosure can be implemented in many other ways than those described herein, and those skilled in the art may make similar generalizations without departing from the scope of the present disclosure. Therefore, the present disclosure is not limited to the specific implementations disclosed below. The terminology used in one or more embodiments of the present disclosure is for the purpose of describing specific embodiments only and is not intended to limit the present disclosure.As used in one or more embodiments of the present disclosure and the appended claims, the singular forms "a," "an," "the," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used in one or more embodiments of the present disclosure refers to and encompasses any and all possible combinations of one or more of the associated listed items. It should be understood that although the terms first, second, etc. may be employed in one or more embodiments of the present disclosure to describe various information, such information should not be limited to these terms. These terms are merely used to distinguish information of the same type from one another. For example, the first could be referred to as the second, and similarly, the second could be referred to as the first, without departing from the scope of one or more embodiments of the present disclosure. Depending on the context, the word "if," as used herein, could be interpreted as "when," "when," or "in response to determining." Furthermore, it should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, storage, and display) involved in one or more embodiments of this disclosure are all information and data authorized by the user or fully authorized by all parties. The collection, use, and processing of relevant data must comply with the relevant laws, regulations, and standards of the relevant countries and regions, and corresponding operation portals are provided for users to choose to authorize or deny. First, the terms used in one or more embodiments of this disclosure are explained. Operating System (OS): This is the core software layer of a computer system, responsible for managing and controlling computer hardware and software resources, providing user services, and executing applications. Virtual Machine (VM): This is also referred to as a user virtual machine in one or more embodiments of this disclosure. It is a software-emulated computer system that can simulate one or more complete, independently running operating system environments on a physical computer system. In a user VM, software-level hardware resources such as the central processing unit (CPU), memory, hard disk, and network interfaces are virtualized, allowing each VM to run an operating system and applications just like a real physical computer, without interfering with each other. Through virtualization technology, a single physical host can simultaneously run multiple user VMs, each with its own independent operating system, applications, and configuration, significantly improving hardware resource utilization and system flexibility.Host Operating System (Host or Host OS): In a virtualized environment, the host operating system is the operating system running on the actual physical hardware. It is responsible for managing and controlling physical resources and providing services to user virtual machines (VMs) through virtualization technology. Guest Operating System (Guest or Guest OS): In a virtualized environment, the guest operating system is an operating system instance running within the host operating system through virtualization technology. A user VM is the embodiment of the guest operating system running in the virtualized environment. Direct Memory Access (DMA): A technology that allows hardware devices (such as disk controllers and network cards) to directly read and write system memory, bypassing the CPU, thereby improving data transfer speeds and CPU efficiency.
[0002] Hypervisor (resource scheduler, or virtual machine monitor): A key component of virtualization technology, it runs under or above the host operating system, responsible for creating and managing user virtual machines and providing virtual hardware resources to guest operating systems. Memory over-commitment: This occurs when the total amount of memory allocated to each user virtual machine in a virtualized environment exceeds the actual total amount of user virtual machine memory resources provided by the host operating system. Through appropriate scheduling and memory reuse techniques, physical memory limits can be exceeded for a short period of time. Page faults (IOPFs) during input and output: In a virtualized environment, this occurs when an I / O (Input / Output) device attempts to access memory that is not in physical memory or is incorrectly mapped via DMA. This can lead to memory conflicts, high complexity, and unsafe access. Memory Management Unit (MMU): A hardware component integrated within the CPU of modern computer systems that is responsible for translating virtual memory to physical memory addresses. It performs address translation by parsing and searching the memory page table, ensuring that processes can only access authorized memory areas and assisting the operating system in implementing memory protection and memory paging mechanisms. The Guest Virtual Address (GVA) is the memory address used within the user virtual machine and must be mapped to the host virtual address through virtualization technology. The Guest Physical Address (GPA) is the "physical" memory address seen from within the user virtual machine and must be mapped to the host physical address through virtualization technology. The Host Virtual Address (HVA) is the memory address used within the host operating system and must be translated by the MMU into the actual physical address (HPA) before physical memory can be accessed. The Host Physical Address (HPA) is the address on the actual physical memory chip and is the only real memory location that can be directly accessed. It should be noted that in a virtualized environment, the main path of memory address translation is GVA -> GPA -> HPA. Among them, the GVA -> GPA translation occurs inside the user virtual machine and is completed by the user virtual machine's own memory management unit (MMU) in conjunction with the user virtual machine's memory page table.The guest operating system converts GVA to GPA, which is the address translation process within the virtual machine. Physical Page: A physical page is the fundamental unit of computer memory management, a fixed-size block used by the operating system to divide and manage physical memory. In most modern computer systems, a physical page is typically 4KB or larger (for example, 2MB, 1GB, etc.), and all physical memory is divided into a series of such pages. The operating system uses a page frame number (PFN) to identify the exact location of each physical page in physical memory. Memory Page Table: The memory page table is a key data structure used by the operating system to implement the virtual memory system. It records the mapping between virtual address space and physical address space. Each process has its own independent page table. Each entry in the page table (called a page table entry, PTE) corresponds to a page in the virtual address space and contains the corresponding physical page address, as well as related permission bits and other control information. When the CPU initiates an access to a virtual address, the MMU searches the memory page table to find the corresponding physical address. This process is called address translation. Extended Page Tables (EPT): A hardware-assisted, two-level page table mechanism particularly suited for virtualized environments. In virtualized scenarios, EPT allows the hypervisor to maintain an independent, hardware-supported page table structure for each guest operating system (guest OS), enabling efficient translation from user-physical addresses to host-physical addresses. Executable and Linkable Format (ELF): A widely used file format primarily used in Unix-like operating systems (including Linux, Solaris, FreeBSD, etc.) to represent executable files, object code, shared libraries, and core dumps. This file format is designed to be flexible and extensible to support a variety of processor architectures and operating system features. Embedded kernel image file VmLinux: The executable file generated after the Linux kernel is compiled, which contains the complete kernel code and symbol table information.
[0003] MD5, or Message Digest Algorithm 5, is a widely used hash function, commonly used in areas such as data integrity verification and digital signatures. The MD5 algorithm converts data of any length (such as text or files) into a fixed-length 128-bit hash value (typically represented as 32 hexadecimal digits). This hash value can be used to verify data integrity. Kernel address space layout randomization (KASSIR): During kernel bootup, a random value is obtained and a corresponding random offset is applied to the kernel load address to improve kernel security. Page Middle Directory (PMD): A page table entry with a 2M granularity. Control register 3 (CR3), which contains the physical memory base address of the page directory. Currently, to resolve the conflict between direct memory access and flexible memory allocation, a specific detection module is injected into the user VM to directly detect idle physical pages pre-allocated to the user VM, thereby achieving memory resource reallocation. Specifically, Figure 1 shows a schematic diagram of the process architecture of a memory resource allocation method: The detection module is pre-injected into the guest operating system. The detection module transmits the detected data to the detection module's data manager in the host operating system via an application programming interface (API). The detection module obtains the guest operating system's physical page metadata (the user physical address range recorded in the physical page structure) and the parsing policy. Based on the physical page metadata layout, the user virtual memory start and end addresses are determined and transmitted to the detection module's data manager via an API. The parsing policy source code is compiled to generate the parsing policy binary code, which is then transmitted to the detection module's data manager via an API. The parsing policy's data manager in the host operating system verifies the parsing policy binary code using the parsing policy verifier. Once verified, the parsing policy is stored. The memory reclamation setup is completed by converting the physical page metadata range (the user physical address range of the physical page structure information) into user physical page metadata (the host virtual address range of the physical page structure information). The host operating system's memory reclamation routine scans this user physical page metadata and uses the appropriate parsing strategy to determine whether the physical page is the target physical page in an idle state.For the target physical page, the memory management unit's memory page table and input / output memory page table are adjusted, and the extended memory page table of the physical page metadata is adjusted to protect the target physical page. When a system event triggers a request to access the target physical page, the physical page metadata is first accessed, triggering an extended memory page table fault to the resource scheduler. The resource scheduler simultaneously handles the extended memory page table fault and swaps back the corresponding physical page, thus avoiding the conflict between direct memory access and flexible memory allocation, and avoiding issues such as memory conflicts, high complexity, and insecure access. However, the above method injects a specific detection module into the user virtual machine, directly intruding into the user virtual machine. This compromises the isolation and security of the user virtual machine in the network cloud platform, and the injected detection module can affect the performance of the user virtual machine. To address the above issues, the present disclosure provides a memory resource allocation method, which also relates to a network cloud platform, a memory resource allocation apparatus, a computing device, a computer-readable storage medium, and a computer program product, each of which is described in detail in the following embodiments. Referring to Figure 2, a flowchart of a memory resource allocation method provided according to an embodiment of the present disclosure is shown, specifically including the following steps. Step 202: Obtain the kernel load address of the guest operating system. This embodiment of the present disclosure is applied to a component unit with memory resource allocation functionality. This component unit is a piece of software that can be built into a network cloud platform, such as the network cloud platform's resource scheduler responsible for virtual machine resource scheduling, or it can be external to the network cloud platform, such as a third-party memory resource monitoring and optimization component unit that interacts with the cloud platform via an API. This component unit can directly detect virtual machine memory resources, obtain virtual machine kernel information, and based on this, parse the virtual machine kernel information and scan the virtual machine's memory resources, identify target physical pages in an idle state, and redistribute memory resources to the target physical pages. A guest operating system is an operating system that runs for users in a virtual machine. Through the guest operating system, users can manage and use computing resources through the virtual machine. Guest operating systems can be of different formats, such as Linux and Unix, and interact with the host machine and manage resources in a virtual machine environment. The kernel load address is the address where the guest operating system's kernel is loaded into memory. When an operating system boots, its kernel is loaded into a specific memory location called the kernel load address. The kernel load address is crucial for system operation and memory management because it allows the operating system to access and execute code and data in the kernel based on the kernel load address.Under normal circumstances, the kernel loading address is 0xffffffff81000000. o Specifically, the kernel load address can be obtained in the following ways: When compiling the Linux kernel, a kernel image file System map, also called the kernel symbol table, is generated. The kernel symbol table is a mapping that maps addresses in the kernel code segment to corresponding function names or global variable names. By parsing the kernel symbol table, the kernel load address can be obtained; the kernel load address can be obtained by parsing the vmLinux file using nm (a specific file analysis tool that comes with Linux), objdump (a binary file analysis tool), or readeIf (a tool for viewing ELF command lines); the kernel load address can be obtained through the / proc / kaIIsyms command. / proc / kaIIsyms is a virtual file dynamically generated by the running kernel, which reflects the status of the currently running kernel; the kernel load address can be obtained through the kernel interface. For example, taking the method of parsing vmL inux files as an example, usually, vmL inux files will carry a matching System map file, which contains kernel symbol table information. In the System map file, search for the symbol named _text, which usually represents the starting address of the kernel code segment, that is, the kernel loading address, which is usually 0xffffffff81000000 oThrough the above steps, the kernel load address of the guest operating system can be obtained, providing the necessary information foundation for determining the kernel version of the user virtual machine. Step 204: Based on the kernel load address, determine the kernel version corresponding to the virtual machine memory resources. The virtual machine memory resources include multiple pre-allocated physical pages, which the guest operating system uses to manage the virtual machine memory resources. Virtual machine memory resources are memory resources pre-allocated to user virtual machines. Virtual machine memory resources are allocated from the host machine's (i.e., physical machine) memory resources and are used to create and run user virtual machines. Virtual machine memory resources include multiple physical pages. For example, 2GB of the host machine's 4GB of memory resources are pre-allocated to the user virtual machine. This 2GB of memory resources is the virtual machine memory resource. The kernel version is the kernel version number, which is a method for identifying and managing the version of the virtual machine operating system kernel. The kernel version number is typically composed of a series of numbers and periods. For example, the Linux kernel version number format is xyz, where x represents the major version number, y represents the minor version number, and z represents the revision number. Changes in kernel version numbers typically reflect kernel code updates, feature improvements, and bug fixes. Different kernel versions may introduce new features, optimize performance, enhance security, or fix known issues. In a virtual machine environment, the kernel version number can be used to determine kernel features and supported functions, which in turn influences the management and scheduling of virtual machine memory resources. In the Linux kernel, the struct page structure represents physical pages in memory. With kernel version updates, the definition of the struct page structure may change to accommodate new features, optimize performance, or fix issues. Therefore, different kernel versions correspond to different versions of the struct page structure, which can be parsed and operated based on the specific kernel version. Generally speaking, the struct page structure contains attributes or information such as the physical page's parsed address and parsed range. Different kernel versions may introduce new member variables, modify the definitions of existing member variables, or adjust the structure's layout. These changes affect the struct page parsing strategy. A physical page is the basic unit of virtual machine memory resources and the fundamental unit of independently allocable memory. It is a user physical page metadata. Physical page sizes include, but are not limited to, 4KB, 2MB, and 4MB. During the creation of a user virtual machine (i.e., during the allocation of virtual machine memory resources), each physical page is mapped to a different virtual memory address within the user virtual machine, translating virtual memory addresses into physical memory addresses.For example, if 2GB of virtual machine memory resources are divided into 4KB physical pages (number of physical pages = 2 * 1024 * 1024 KB / 4 KB), 524,288 physical pages are obtained. Specifically, after the kernel is loaded into memory, Hypervisor can access the kernel load address in memory to extract the specific code information of the loaded kernel. This includes the kernel core code, such as the subsystems and submodules described in the Linux kernel overall architecture analysis notes, and other supporting subsystems such as power management and Linux initialization; and auxiliary files such as library files, firmware collections, compilation scripts, configuration files, help documents, and copyright notices. This kernel specific code information can be used to determine the specific kernel version of the current kernel. For example, after obtaining the kernel load address, starting from the kernel load address, the kernel specific code information is obtained. This code information may include the current kernel version number, or update features in the kernel code information can be extracted to determine which updates the current kernel has undergone and the kernel version it is in. Different kernel versions have different physical page scan ranges and scan parameters. Kernel version identification provides a basis for subsequently using the kernel version as an external query identifier to obtain the target scan ranges and scan parameters recorded in the target database. Step 206: Based on the kernel version, query the target database for target scan ranges and target scan parameters for multiple physical pages. The target database is located in the host machine and pre-stores the physical page scan ranges and scan parameters corresponding to each kernel version. The target scan ranges for multiple physical pages are parameters corresponding to the kernel version that represent the memory address ranges of multiple physical pages in the virtual memory resource. These parameters are kernel information about the physical pages, including but not limited to the start address and / or end address. For example, in a Linux system, the virtual memory address range used to represent the structure information of the physical page has a start address of VMEMMAP_START, and the virtual memory address range used to represent the structure information of the physical page has an end address of VMEMMAP_END. O Generally, the kernel reserves a specific virtual memory area to store the structure information of the physical page. The starting address of this area may be VMEMMAP_START and the ending address may be VMEMMAP_END. OBy querying these two addresses, the resource scheduler or memory management component can determine the memory range to be traversed and analyzed. The target scan parameters for multiple physical pages are parsing parameters corresponding to the kernel version used to parse and obtain the status parameters of multiple physical pages. These parameters include, but are not limited to, target parsing strategies and memory management mechanism parameters. The target parsing strategy is used to parse and understand the data structure related to the physical page status in kernel information. For example, it uses the page parameter to determine the size of the struct page structure and to determine whether the strcut page structure represents a free page. Memory management mechanism parameters, such as the access control bits of page table entries, swap space policies, and memory fragmentation handling rules, are used to determine which physical pages meet the free state criteria. The target database is a database set up in the host machine that stores the physical page scan ranges and scan parameters for each kernel version. In a virtualized environment, the target database provides reference data for virtual machine management and resource allocation, enabling appropriate operations based on specific kernel versions and requirements. The target database can regularly update and manage the physical page scan ranges and parameter data for each kernel version to adapt to new kernel releases or changes in specific requirements. Specifically, the Hypervisor determines the kernel version of the user virtual machine kernel to be queried based on the kernel version number of the virtual machine; the Hypervisor initiates a query request to the target database, and retrieves the target scanning range and target scanning parameters of the physical pages corresponding to the kernel version stored in the target database by specifying the target kernel version number as a query condition; optionally, the Hypervisor receives data returned by the target database, parses the query results, and extracts the scanning range and scanning parameters of some target physical pages for subsequent memory resource scanning and management.For example, assuming that user virtual machine A is running kernel version 3.10.0, Hypervisor initiates a query request to the target database based on kernel version 3.10.0 of user virtual machine A, requesting to retrieve the target scanning range and target scanning parameters of the physical pages corresponding to the kernel version. After receiving the query request, the target database retrieves the physical page target scanning range and target scanning parameter data corresponding to the kernel version stored in the database based on the provided kernel version 3.10.0, and returns the physical page target scanning range and target scanning parameter data for kernel version 3.10.0 to Hypervisor. Optionally, after receiving the data returned by the target database, Hypervisor parses the query result and extracts the scanning range and parameters of some target physical pages for subsequent memory resource management. Through the above steps, the target scan range and target scan parameters for physical pages can be accurately queried from the target database based on the kernel version, avoiding intrusion into the user virtual machine, ensuring the isolation and security of the user virtual machine, and minimizing performance impacts on the user virtual machine. Step 208: Based on the target scan range and target scan parameters, the virtual machine memory resources are scanned to determine target physical pages that are idle among multiple physical pages. A target physical page is a physical page that is not allocated to any process and is in an idle state. In the idle state, a physical page does not carry data or instructions from any process and is not mapped to any virtual address space in the virtual machine system. It can be reallocated to other virtual machines and their processes in the host operating system. For example, among 1000 physical pages pre-allocated to multiple user virtual machines, 200 physical pages are currently unoccupied by any process and are the target physical pages. When a process in a particular virtual machine requests additional memory resources, these 200 idle target physical pages can be reallocated to the process of the virtual machine requesting additional memory resources. Based on a scan range and scan parameters, memory resources of the virtual machine are scanned to determine a target physical page in an idle state among multiple physical pages. Specifically, the target physical page in an idle state is determined based on the scan range and scan parameters.Illustratively, based on a scan range and scan parameters of structure information struct page of 524,288 physical pages, a virtual machine memory resource Guest Memory is scanned to determine status parameters of multiple physical pages. Based on the status parameters of the 524,288 physical pages, a target physical page (free guest page) in an idle state is determined among the 524,288 physical pages. o For example, based on the target scan range and target scan parameters, the virtual machine's guest memory resources are scanned page by page. Starting from the start address where the first physical page is mapped among 524,288 physical pages, the status of each virtual memory page is checked in sequence according to the step size of each physical page. For each virtual memory page, the corresponding physical page status is determined by querying the corresponding virtual memory mapping table. During the scanning process, the target physical page in the free state is recorded as a free guest page. o Based on the scan range and scan parameters, the virtual machine memory resources are scanned to determine a target physical page in an idle state among multiple physical pages. For subsequent memory resource reallocation, the target physical page in an idle state is determined, providing support for the target physical page. Step 210: Memory resource reallocation is performed based on the target physical page. Memory resource reallocation is performed based on the target physical page, specifically by: modifying the memory page table of the target physical page based on the target physical page, wherein the memory page table includes but is not limited to: a memory page table of a memory management unit and an input / output memory page table. Exemplarily, based on the target physical page free guest page, the memory page table MMU Page Table le of the memory management unit and the input / output memory page table I / O Page Table le of the target physical page free guest page are modified. oIn an embodiment of the present disclosure, a kernel load address of a guest operating system is obtained; based on the kernel load address, a kernel version corresponding to virtual machine memory resources is determined, wherein the virtual machine memory resources include multiple pre-allocated physical pages, and the guest operating system is used to manage the virtual machine memory resources; based on the kernel version, a target scan range and target scan parameters for the multiple physical pages are queried from a target database, wherein the target database is provided in a host machine and pre-stores scan ranges and scan parameters for physical pages corresponding to each kernel version; based on the target scan range and target scan parameters, the virtual machine memory resources are scanned to determine a target physical page that is idle among the multiple physical pages; and memory resource reallocation is performed based on the target physical page. Based on the kernel version corresponding to the guest operating system, a database pre-stored with physical page scan ranges and scan parameters corresponding to each kernel version is used to obtain the target scan range and target scan parameters corresponding to the user virtual machine. Based on this, the virtual machine's memory resources are scanned and target physical pages that are idle are identified. This achieves memory resource redistribution without intrusion into the user virtual machine, ensuring the isolation and security of the user virtual machine and minimizing performance impacts on the user virtual machine. This eliminates the need to intrude into the virtual machine, effectively utilizing memory resources while ensuring data security. In an optional embodiment of the present disclosure, step 202 includes the following specific steps: identifying the layout mode of the guest operating system's kernel address space and obtaining the kernel address table start address based on the guest operating system; and determining the kernel load address based on the layout mode and the page table start address. The kernel address space layout mode, or kas lr, is designed to improve kernel security by randomly loading the kernel into different physical addresses. After the kernel boots and decompresses, it determines whether to randomize the physical address where the kernel is loaded and the virtual address where the kernel runs by checking whether the kas lr command line parameter is enabled. The page table starting address is the kernel load address when kas lr is not enabled, usually 0xffffffff81000000. oSpecifically, Hypervisor can determine the kernel address space layout mode by parsing the kernel symbol table and determining whether the KAS 1R command line parameter is enabled. If enabled, the layout mode is random; if not, the layout mode is fixed. In fixed mode, the kernel load address is typically 0xffffffff81000000, which can be obtained by parsing the symbol table. Different layout modes result in different kernel load addresses. In fixed mode, the kernel load address is the page table start address; in random mode, the kernel load address is the page table start address + an offset. Based on this, Hypervisor can accurately determine the kernel load address of the client operating system based on the kernel address space layout mode and page table start address of the client operating system, providing a basis for subsequent kernel version determination. In an optional embodiment of the present disclosure, determining the kernel load address based on the layout mode and page table start address includes the following specific steps: If the layout mode is fixed, determining the page table start address as the kernel load address. Fixed mode refers to a mode in which KAS 1R is disabled. Specifically, Hypervisor parses the kernel symbol table and determines that the kasIr command line parameter is not enabled, and then sets the layout mode to fixed mode. In fixed mode, the kernel load address is usually the page table start address. For example, in fixed mode, if the page table start address is 0xffffffff81000000, the kernel load address is 0xffffffff81000000. oBased on this, Hypervisor can accurately determine the guest operating system kernel load address when the guest operating system's kernel address space layout mode is fixed, providing a basis for subsequent kernel version determination. In an optional embodiment of the present disclosure, determining the kernel load address based on the layout mode and the page table starting address includes the following specific steps: When the layout mode is random, performing a page table entry mapping check based on the page table starting address at a preset step size to obtain a target address with a target page table entry mapping; and determining the kernel load address based on the target address and the page table starting address. The preset step size is the page table construction granularity, for example, 2MB. Every preset step size corresponds to a page table. The starting position of page table construction is the first mapped physical page of the preset step size. When KASILR is enabled, the starting position of page table construction is the page table starting address + KASILR offset. Therefore, by intercepting the page table in the CR3 register of the guest operating system, we can then check the page table entry mappings starting from the page table starting address at a preset step size to find the target address mapped to the target page table entry. The first mapped page table entry is the target page table entry, and the starting address of the target page table entry is the target address. Using the target address and the page table starting address, we can calculate the kas lr offset, and further calculate the kernel load address in random mode. For example, let's assume the page table starting address is 0xffffffff81000000 and the preset step size is 2M. The starting address for page table creation is defined as 0xffffffff81000000 + KASLR_OFFSET, where KASLR_OFFSET is the offset value. By intercepting the page table in the guest OS's CR3 register, starting at 1000000, page table entries are mapped in 2MB increments. The first mapped PMD is checked, and the address corresponding to this PMD is subtracted by 1000000 to obtain the specific value of KASLR_OFFSET. Based on KASLR_OFFSET, the kernel load address after obtaining the offset is calculated. Based on this, Hypervisor can accurately determine the guest OS kernel load address when the guest OS kernel address space layout mode is random, providing a basis for subsequent kernel version determination.In an optional embodiment of the present disclosure, step 204 includes the following specific steps: parsing the virtual machine kernel image based on the kernel load address to obtain a target kernel field; performing encryption calculations on the target kernel field to obtain target encryption information; and matching the kernel version corresponding to the virtual machine resources from a preset verification database based on the target encryption information. The virtual machine kernel image is the image file of the operating system kernel in the virtual machine. It typically contains the operating system kernel code, data, and related configuration information, and is a core component for virtual machine operation. The target kernel field refers to the specific code information of the loaded kernel, including the kernel core code, such as the various subsystems and submodules described in the Linux kernel overall architecture analysis notes, as well as other supporting subsystems such as power management and Linux initialization; auxiliary files such as library files, firmware collections, compilation scripts, configuration files, help documents, and copyright notices. This kernel code information can be used to determine the specific kernel version of the current kernel. The target encryption calculation refers to the checksum or verification identifier obtained after performing encryption calculations on the target kernel field. The encryption calculation can be performed using methods such as MD5. Pre-set verification database: This database pre-stores the correspondence between target encryption information and different kernel versions. This database can be the same as the target database. The pre-set verification database encrypts and calculates the encrypted information based on the kernel fields of all pre-obtained kernel versions, then associates and stores each encryption with the corresponding kernel version. Specifically, based on the known kernel load address, Hypervisor extracts the specific code information of the loaded kernel, namely the target kernel field. After extracting the target kernel field, Hypervisor performs encryption calculations on it, processing it using a specific encryption algorithm and key to generate the target encrypted information. Based on the obtained target encrypted information, Hypervisor matches it with the pre-set verification database, which stores information such as signature codes and version numbers corresponding to various kernel versions. The system compares the target encrypted information with the information in the database to determine the kernel version corresponding to the virtual machine resources. For example, according to the known kernel loading address 0xffffffff81000000, the target kernel field is obtained, and MD5 encryption calculation is performed on the target kernel field to generate an MD5 hash value: 342c0b644f a388286977e01 168dc0a07. oSearch the verification database for the entry corresponding to "342c0b644fa388286977e01 168dc0a07". If a matching MD5 hash value is found in the verification database, the corresponding kernel version number is found, such as "L i nux Kernel Version: 3.10.0" oDifferent kernel versions have different physical page scanning ranges and scanning parameters. Kernel version identification provides a basis for subsequently using the kernel version as an external query identifier to obtain the target scanning range and scanning parameters recorded in the target database. In an optional embodiment of the present disclosure, performing encryption calculations on a target kernel field to obtain target encryption information includes the following specific steps: if the length of the target kernel field exceeds a preset length threshold, segmenting the target kernel field to obtain multiple segmented fields; performing encryption calculations on each segmented field to obtain target encryption information corresponding to each segmented field; and matching the kernel version corresponding to the virtual machine resource from a preset verification database based on the target encryption information. This includes the following specific steps: matching the target encryption information corresponding to each segmented field from a preset verification database to obtain multiple initial kernel versions; and determining the kernel version corresponding to the virtual machine resource based on the multiple initial kernel versions. Because the length of the target kernel field is variable, matching the target encryption information of the entire target kernel field results in significant overhead. Specifically, if the length of the target kernel field exceeds a preset length threshold, it is segmented into multiple smaller fields, such as 0-4K, 4-16K, 32-64K, and 128-256K. An encryption calculation is then performed on each segmented field to obtain its own target encryption information. This segmented processing reduces the overhead of a single encryption calculation and improves efficiency. Based on the target encryption information corresponding to each segmented field, multiple possible initial kernel versions are matched from a preset verification database. The target encryption information for each segmented field is compared with the information in the database to identify all possible matching kernel versions. Based on the multiple initial kernel versions, the initial kernel version that matches all target encryption information is determined as the kernel version corresponding to the final virtual machine resource. For example, using the above example, the first field is 0-4K. MD5 encryption is performed on the content within the first field to obtain the first target encryption information, corresponding to the multiple first initial kernel versions matched in the preset verification database. The second field contains 4-16 KB. An MD5 encryption calculation is performed on the content in the second field to obtain the second target encrypted information, which corresponds to multiple second initial kernel versions matched in the preset verification database. The third field contains 32-64 KB. An MD5 encryption calculation is performed on the content in the third field to obtain the third target encrypted information, which corresponds to multiple third initial kernel versions matched in the preset verification database. The fourth field contains 128-256 KB. An MD5 encryption calculation is performed on the content in the fourth field to obtain the fourth target encrypted information, which corresponds to multiple fourth initial kernel versions matched in the preset verification database.The intersection of multiple first initial kernel versions, multiple second initial kernel versions, multiple third initial kernel versions, and multiple fourth initial kernel versions is determined as the kernel version corresponding to the final virtual machine resource. This reduces computational overhead when the kernel field length is large, improving computational efficiency. By comparing the kernel version corresponding to the virtual machine resource with information in a preset verification database, the kernel version corresponding to the virtual machine resource can be determined, thereby achieving rapid and accurate kernel version identification. This solution combines segmentation processing with the application of an encryption algorithm, effectively simplifying the kernel version identification process when the target kernel field is long. In an optional embodiment of the present disclosure, determining the kernel version corresponding to the virtual machine resource based on multiple initial kernel versions includes the following specific steps: for any segment field, determining the common characteristics of the multiple initial kernel versions corresponding to the segment field; and based on the corresponding common characteristics of each segment field, determining the initial kernel version that meets all the common characteristics among all the initial kernel versions as the kernel version corresponding to the virtual machine resource. For example, using the above example, the first field is 0-4K. MD5 encryption is performed on the content of the first field to obtain first target encrypted information, which corresponds to multiple first initial kernel versions supporting specific hardware devices obtained by matching in the preset verification database. The second field is 4-16KB. An MD5 encryption calculation is performed on the content in the second field to obtain second target encrypted information, which corresponds to multiple second initial kernel versions that use a specific scheduling algorithm and are matched in a preset verification database. The third field is 32-64KB. An MD5 encryption calculation is performed on the content in the third field to obtain third target encrypted information, which corresponds to multiple third initial kernel versions that fix known security vulnerabilities and are matched in a preset verification database. The fourth field is 128-256KB. An MD5 encryption calculation is performed on the content in the fourth field to obtain fourth target encrypted information, which corresponds to multiple fourth initial kernel versions compatible with specific applications and are matched in a preset verification database. Among the first, second, third, and fourth initial kernel versions, the initial kernel version that simultaneously supports specific hardware devices, uses a specific scheduling algorithm, fixes known security vulnerabilities, and is compatible with specific applications is determined as the kernel version corresponding to the virtual machine resource. In an optional embodiment of the present disclosure, step 208 includes the following specific steps: scanning virtual machine memory resources based on a target scan range to obtain structure information of multiple physical pages; and determining a target physical page that is idle among the multiple physical pages based on target scan parameters and the structure information of the multiple physical pages. The structure information of the physical page is structure information data used to manage the physical page, defined by the kernel of the virtual machine operating system and used in memory management, and is a type of physical page metadata.The physical page structure contains structure parameters that represent key attributes of the physical page, including but not limited to: page size, idle state, page index, and reference count. For example, in Linux, the physical page structure struct page is as follows: struct page { unsigned long f I ags; / / physical page flag atomi c_t _count; / / reference count pgoff_t index; / / index in the page frame array. struct address_space ^mapp i ng ;
[0004] } ;
[0005] / / Other status, cache, and I / O information}; including structure parameters such as unsigned long f I ags (physical page flags), atomi c_t _count (reference count), pgoff_t index (index in the page frame array), and unity (possible mapping information or other uses). Based on the target scan parameters and the structure information of multiple physical pages, a target physical page in an idle state is determined among the multiple physical pages. The specific method is as follows: Based on the target scan parameters, the structure information of the multiple physical pages is parsed to determine the target physical page in an idle state among the multiple physical pages. For example, based on a target scan range (VMEMMAP_START; VMEMMAP_END) of the structure information struct page of 524288 physical pages, the virtual machine memory resource Guest Memory is scanned to obtain the structure information struct page of 524288 physical pages. Based on the target scan parameters of the structure information struct page of 524288 physical pages, the structure information struct page of 524288 physical pages is parsed to determine a target physical page (free guest page) in an idle state among the 524288 physical pages. oIn an embodiment of the present disclosure, virtual machine memory resources are scanned based on a target scan range to obtain structure information of multiple physical pages. Based on target scan parameters and the structure information of the multiple physical pages, target physical pages that are in an idle state are determined from the multiple physical pages. This accurate determination of the idle target physical pages provides accurate target physical page support for subsequent memory resource reallocation. In an optional embodiment of the present disclosure, the target scan parameters include a target parsing strategy. Determining the idle target physical pages from the multiple physical pages based on the target scan parameters and the structure information of the multiple physical pages includes the following specific steps: parsing the structure information of each physical page using the target parsing strategy to obtain structure parameters for each physical page; and identifying the idle target physical page from the multiple physical pages based on the structure parameters of each physical page. Generally, when generating the structure information of the physical page, the virtual machine operating system may compile the physical page structure information, which is physical page metadata, and convert it into binary data for storage in the virtual machine memory resources. Therefore, parsing the binary data is required to obtain the structure parameters of each physical page. The physical page structure parameters represent key attributes of the physical page, including but not limited to: page size, free state, page index, and reference count. For example, in Linux, the physical page structure (struct page) includes the following structure parameters: Physical page flags (flags): Definition: unsigned_long_flags; Description: Used to record various status information of the physical page, such as whether the physical page is free, allocated, involved in paging, and whether it contains cached data. Reference count (count): Definition: atomic_t_count; Description: Records the number of times the current physical page has been referenced, used to determine whether the page is in use. When the reference count is 0, it generally means that the page can be safely reclaimed or reallocated. Page index (index): Definition: pgoff_t_index; Description: Indicates the position of the physical page in the page frame array, allowing the kernel to quickly locate and search for a specific physical page. A union for mapping information or other purposes (mapping): Definition: un i on {. . .} mapping Description: Depending on the usage of physical pages, this union can store different information, such as a structure pointer associated with the file system address space, or other data related to physical page mapping.In addition, to determine whether a physical page is in an idle state, the following structure parameters must also be considered: Status parameters: For example, specific flags in the struct page, such as PageLRU, PageSlab, and PageFree, can be checked to determine whether a page is available or idle. Page mapping information (mapcount): Determines whether the page is mapped to any virtual address space. If mapcount is 0, the physical page is not occupied by any process and is in an idle state. Private member (pr i vate): The member variable p i vate is used to determine the page size of the physical page. The target parsing strategy is a parsing method strategy for parsing the physical page status in the structure information. The target parsing strategy is designed to parse the structure parameters representing the physical page status in the structure information. The target parsing strategy includes, but is not limited to, the following per functions. o Generally, different virtual machine operating systems have different parsing strategies, which are recorded in the virtual machine kernel information. For example, using the target parsing strategy hel per functions, the structure information struct page of 524288 physical pages is parsed to obtain the structure parameters of each physical page. Based on the structure parameters of each physical page, the target physical page free guest page in the 524288 physical pages is identified. oIn an embodiment of the present disclosure, a target parsing strategy is utilized to parse the structure information of each physical page, obtain the structure parameters of each physical page, and identify the target physical page in an idle state among multiple physical pages based on the structure parameters of each physical page. This more accurately determines the target physical page in an idle state, providing more accurate target physical page support for subsequent memory resource reallocation. In an optional embodiment of the present disclosure, step 210 includes the following specific steps: reclaiming the page table for the target physical page; and reallocating the page table for the target physical page in response to a memory allocation request sent by the target virtual machine. Page table reclaim is a memory management operation that reclaims physical pages through the memory page table. Specifically, the page table entry for the target physical page is deleted from the memory page table, causing the target physical page to become idle and available for reallocation to other processes or virtual machines. Deleting the page table entry clears the mapping relationship of the target physical page in the virtual address space. Page table reallocation is a memory management operation that uses the memory page table to reallocate physical pages. Specifically, the page table entry for the target physical page is rebuilt in the memory page table, changing the target physical page to an occupied state and making it available for use by other processes or virtual machines. Rebuilding the page table entry creates a new mapping relationship between the target physical page and the virtual address space. The target virtual machine can be a virtual machine with pre-allocated virtual machine memory resources, which is considered memory over-allocation, or a newly built virtual machine, without limitation. Page table reclaiming is performed on the target physical page by deleting the page table entry for the target physical page from the memory page table. In response to a memory allocation request sent by the target virtual machine, a page table is reallocated for the target physical page by generating a page table entry for the target physical page in the memory page table. Exemplarily, the page table entry for the target physical page, free guest page, is deleted from the memory management unit's MMU Page Table and the input / output (I / O) Page Table. In response to a memory allocation request sent by the target virtual machine, a page table entry for the target physical page, free guest page, is generated in the memory management unit's MMU Page Table and the input / output (I / O) Page Table. In the disclosed embodiments, memory resource reallocation is achieved through page table management, ensuring consistency and security of user virtual machines.In an optional embodiment of the present disclosure, before reclaiming the page table for the target physical page, the following specific step is further included: setting the access rights of the target physical page to inaccessible in the virtual machine memory address translation table. The virtual machine memory access table is the physical page table used by the virtual machine to perform memory address translation when accessing memory resources. Generally, when a user virtual machine's I / O device uses direct memory access (DMA) to access virtual machine memory resources, the target physical page needs to be reallocated. If it is still accessible to the user virtual machine, a memory conflict may occur, causing a direct memory access exception. When the user virtual machine needs to access the target physical page, it must first access its structure information. If the access rights of the target physical page are set to inaccessible in the virtual machine memory address translation table, a page fault in the virtual machine memory address translation table will be triggered, preventing the target physical page from being accessed. The virtual machine memory access table is the physical page table used by the virtual machine to perform memory address translation when accessing memory resources. For example, in a Linux system, the virtual machine memory access table is the extended memory page table (EPT). Exemplarily, in the virtual machine's memory address translation table (EPT), the access rights of the target physical page, the free guest page, are set to inaccessible. In the disclosed embodiment, by setting the access rights of the target physical page in the virtual machine's memory address translation table to inaccessible before reclaiming the page table, potential memory conflicts are effectively prevented, ensuring the safe reclamation and reallocation of the target physical page, and enhancing the stability and reliability of the virtualization environment. Referring to FIG3 , in the disclosed embodiment, an OS database is constructed to record the characteristics of different user virtual machines. FIG3 is a schematic diagram of a process architecture for constructing the database provided by one embodiment of the disclosed embodiment. As shown in FIG3 , in the kernels of virtual machines of various kernel versions, kernel information such as the kernel's symbol table, compiled functions, and kernel image are obtained. Based on this kernel information, encryption information, structure information, and parsing strategies corresponding to the kernel are obtained. The OS database is constructed based on the encryption information, structure information, and parsing strategies. Specifically, the following steps are performed: First, a feature extraction tool is used to perform kernel information acquisition operations on the virtual machine to extract the kernel's symbol table, compiled functions, and VMLINux kernel image file. Then, by parsing the symbol table corresponding to the kernel, the structure information of each physical page in the virtual machine is obtained; the kernel-specific parsing strategy is exported in the kernel-specific compilation function; by parsing the vmLinux kernel image file, the kernel's kernel field is obtained, and then the kernel field is encrypted with MD5 to obtain encrypted information.Finally, an OS database is constructed based on the structure information, parsing strategy, and encryption information corresponding to each core. Figure 4 shows a schematic diagram of the process architecture of a memory resource allocation method provided by one embodiment of the present disclosure. As shown in Figure 4, the network cloud platform includes virtual machine memory resources, a resource scheduler, and a host operating system. The resource scheduler includes an encryption module, a scanning module, and a recycling module. In the resource scheduler, a kernel load address is obtained from the virtual memory resources based on the client operating system; an encryption module is used to determine the kernel version corresponding to the virtual machine memory resource based on the kernel load address, specifically encrypting the kernel code information obtained based on the kernel load address to obtain encrypted information, sending the encrypted information to a database in the host operating system, and finding the kernel version in the database that matches the encrypted information as the kernel version for the virtual machine memory resource; the scanning module is used to query the target scanning range and target scanning parameters of multiple physical pages from the target database based on the kernel version, and scan the virtual machine memory resources based on the target scanning range to obtain structural information of the multiple physical pages, and then determine the target physical page in the multiple physical pages that is in an idle state based on the target scanning parameters and the structural information of the multiple physical pages, and finally pass the target physical page information to the recycling module; the recycling module is used to reclaim the target physical page in the memory page table and input / output memory page table of the memory management unit of the host operating system. The following, combined with Figure 5, further illustrates the memory resource allocation method provided by the present disclosure, using its application in a public cloud memory over-scaling scenario as an example. Figure 5 shows a flowchart of the processing process of a memory resource allocation method for public cloud memory over-scaling, provided by one embodiment of the present disclosure. This method, applied to a resource scheduler on a public cloud platform, includes the following specific steps: Step 502: Determine the load address (kernel load address) of the text section (kernel field) of the guest OS (virtual machine system). Step 504: Calculate the MD5 (encrypted information) of the current guest and match it with the MD5 checksum information recorded in the OS database (pre-set verification database) to determine the kernel version. Specifically: For user virtual machines with KasIr disabled, since the loading address of the guest OS's text section is a fixed value (0xffffffff81000000), Hypervisor can calculate the kernel version by performing MD5 calculation on the field starting from this fixed address and matching the MD5 checksum information recorded in the OS database.In particular, because kernel code information is variable in length, matching the entire kernel code information field with an MD5 checksum is expensive. To reduce this overhead, MD5 checks can be performed on selected memory segments (e.g., 0-4K, 4-16K, 32-64K, 128-256K). This generates multiple segments of checksum information for comparison with the information in the database. For user VMs with Kas Ir enabled, the load address of the guest OS's text section is no longer fixed; instead, an offset value is added. The specific process of obtaining the offset value includes: first, obtaining the page table of the kernel space of the user virtual machine. Generally speaking, the page table of the kernel space is established according to the granularity of 2MB; second, defining the starting address of the page table establishment, that is, the starting address of the first mapped 2MB page is 0xffffffff81000000+KASLR_OFFSET, where KASLR_OFFSET is the offset value; then, by intercepting the page table in the CR3 register of the guest OS, starting from 0xffffffff81000000, the first mapped PMD is checked according to the step length of 2MB, and the address corresponding to this PMD is subtracted by 1000000 to obtain the specific value of KASLR_OFFSET; based on KASLR_OFFSET, the offset text sect i on load address is obtained, and the MD5 calculation is performed on the field starting from the offset text sect i on load address, and the MD5 check information recorded in the OS database is matched to infer the kernel version. Step 506: Based on the kernel version, query the OS database (target database) for the guest struct page range (target scan range) and parsing method (target scan parameter) for multiple physical pages. Step 508: Scan the guest struct page range and determine whether each page is a free guest page (target physical page) using the corresponding parsing method. Step 510: Find the free guest page information using the scanned struct page (structure information) and pass it to the reclamation module. Step 512: Set the access permission of the target physical page, free guest page, to inaccessible in the virtual machine memory address translation table (EPT).Step 514: Reclaim the page table for the target physical page, the free guest page. Step 516: In response to the memory over-allocation request sent by the target virtual machine, reallocate the page table for the target physical page, the free guest page. Corresponding to the above method embodiments, the present disclosure also provides a network cloud platform embodiment. FIG6 shows a schematic structural diagram of a network cloud platform provided by one embodiment of the present disclosure. As shown in FIG6 , the network cloud platform includes virtual machine memory resources 602 and a resource scheduler 604; the virtual machine memory resources 602 include multiple pre-allocated physical pages. The resource scheduler 604 is configured to obtain the kernel load address of the guest operating system; determine the kernel version corresponding to the virtual machine memory resources 602 based on the kernel load address, wherein the virtual machine memory resources 602 include multiple pre-allocated physical pages; query a target scan range and target scan parameters for the multiple physical pages from a target database, which is provided on the host machine and pre-stores the physical page scan ranges and scan parameters corresponding to each kernel version; scan the virtual machine memory resources 602 based on the target scan range and target scan parameters to determine target physical pages that are idle among the multiple physical pages; and perform memory resource reallocation based on the target physical pages. In an optional embodiment of the present disclosure, the resource scheduler 604 is further configured to scan the virtual machine memory resources 602 based on the target scan range to obtain structure information of the multiple physical pages; and determine target physical pages that are idle among the multiple physical pages based on the scan parameters and the structure information of the multiple physical pages. In an optional embodiment of the present disclosure, the network cloud platform also includes a host operating system 606. oThe resource scheduler 604 is further configured to set the access rights of the target physical page in the virtual machine memory address translation table recorded by the host operating system 606 to an inaccessible state. The virtual machine memory access table is a physical page table used by the virtual machine to perform memory address translation when accessing memory resources. The resource scheduler is also configured to delete the page table entry for the target physical page in the memory page table recorded by the host operating system 606. The memory page table includes mappings between the virtual memory address of the virtual machine and multiple physical pages. In this embodiment, the resource scheduler obtains the target scanning range and target scanning parameters corresponding to the user virtual machine based on the kernel version of the guest operating system. The database pre-stores the scanning range and scanning parameters for physical pages corresponding to each kernel version. Based on this, the resource scheduler scans the virtual machine's memory resources and determines the target physical page in an idle state. This achieves memory resource reallocation without intrusion into the user virtual machine, ensuring the isolation and security of the user virtual machine and minimizing performance impacts on the user virtual machine. This eliminates the need to intrude into the virtual machine and effectively utilizes memory resources while ensuring data security. The above is a schematic diagram of a network cloud platform according to this embodiment. It should be noted that the technical solution of this network cloud platform shares the same concept as the technical solution of the aforementioned memory resource allocation method. For details not described in detail in the technical solution of the network cloud platform, please refer to the description of the technical solution of the aforementioned memory resource allocation method. Corresponding to the aforementioned method embodiment, the present disclosure also provides an embodiment of a memory resource allocation device. Figure 7 shows a schematic diagram of the structure of a memory resource allocation device according to one embodiment of the present disclosure. As shown in FIG7 , the apparatus includes: an acquisition module 702 configured to acquire a kernel loading address of a client operating system; a determination module 704 configured to determine a kernel version corresponding to a virtual machine memory resource based on the kernel loading address, wherein the virtual machine memory resource includes a plurality of pre-allocated physical pages, and the client operating system is used to manage the virtual machine memory resource; a query module 706 configured to query a target scan range and target scan parameters of a plurality of physical pages from a target database based on the kernel version, wherein the target database is provided in a host machine and pre-stores scan ranges and scan parameters of physical pages corresponding to each kernel version in the target database; a scanning module 708 configured to scan the virtual machine memory resource based on the target scan range and target scan parameters, and determine a target physical page that is idle among the plurality of physical pages; and an allocation module 710 configured to perform memory resource reallocation based on the target physical page.Optionally, the acquisition module 702 is further configured to: identify the layout mode of the kernel address space of the guest operating system based on the guest operating system, and obtain the page table starting address of the kernel address space; determine the kernel load address based on the layout mode and the page table starting address. Optionally, the acquisition module 702 is further configured to: determine the page table starting address as the kernel load address when the layout mode is fixed. Optionally, the acquisition module 702 is further configured to: perform a page table entry mapping check based on the page table starting address at a preset step size to obtain a target address with a target page table entry mapping when the layout mode is random; and determine the kernel load address based on the target address and the page table starting address. Optionally, the determination module 704 is further configured to: parse the virtual machine kernel image based on the kernel load address to obtain a target kernel field; perform encryption calculation on the target kernel field to obtain target encryption information; and match the kernel version corresponding to the virtual machine resource from a preset verification database based on the target encryption information. Optionally, the determination module 704 is further configured to: if the length of the target kernel field is greater than a preset length threshold, segment the target kernel field to obtain multiple segment fields; perform encryption calculations on each segment field to obtain target encryption information corresponding to each segment field; match multiple initial kernel versions from a preset verification database based on the target encryption information corresponding to each segment field; and determine the kernel version corresponding to the virtual machine resources based on the multiple initial kernel versions. Optionally, the scanning module 708 is further configured to: scan the virtual machine memory resources based on a target scan range to obtain structure information of multiple physical pages; and determine a target physical page that is idle among the multiple physical pages based on the target scan parameters and the structure information of the multiple physical pages. Optionally, the scanning module 708 is further configured to: determine a target physical page in an idle state among the multiple physical pages based on the target scanning parameter and the structure information of the multiple physical pages, including: parsing the structure information of each physical page using a target parsing strategy to obtain structure parameters of each physical page; and identifying the target physical page in an idle state among the multiple physical pages based on the structure parameters of each physical page. Optionally, the allocation module 710 is further configured to: reclaim a page table for the target physical page; and reallocate a page table for the target physical page in response to a memory allocation request sent by the target virtual machine.Optionally, the apparatus further includes a protection module configured to set the access rights of the target physical page in the virtual machine memory address translation table to an inaccessible state. The virtual machine memory access table is a physical page table used by the virtual machine to perform memory address translation when accessing memory resources. In the disclosed embodiment, the acquisition module 702 acquires the kernel load address, and the determination module 704 determines the kernel version corresponding to the guest operating system based on the kernel address acquired by the acquisition module 702. The query module 706 retrieves the target scanning range and target scanning parameters corresponding to the user virtual machine based on the kernel version corresponding to the guest operating system from a database pre-stored with scanning ranges and scanning parameters for physical pages corresponding to each kernel version. Based on this, the scanning module 708 scans the virtual machine's memory resources and determines the target physical page in an idle state. This achieves memory resource redistribution by the allocation module 710 without the user virtual machine's awareness, while avoiding intrusion into the user virtual machine. This ensures the isolation and security of the user virtual machine and avoids any performance impact on the user virtual machine. This eliminates the need to intrude into the virtual machine and effectively utilizes memory resources while ensuring data security. The above is a schematic diagram of a memory resource allocation device according to this embodiment. It should be noted that the technical solution of this memory resource allocation device and the technical solution of the aforementioned memory resource allocation method share the same concept. For details not described in detail in the technical solution of the memory resource allocation device, please refer to the description of the technical solution of the aforementioned memory resource allocation method. Figure 8 shows a block diagram of a computing device according to one embodiment of the present disclosure. Components of computing device 800 include, but are not limited to, a memory 810 and a processor 820. oThe processor 820 is connected to the memory 810 via a bus 830, and a database 850 is used to store data. The computing device 800 also includes an access device 840, which enables the computing device 800 to communicate via one or more networks 860. Examples of these networks include the Public Switched Telephone Network (PSTN), a Local Area Network (LAN), a Wide Area Network (WAN), a Personal Area Network (PAN), or a combination of communication networks such as the Internet. The access device 840 may include one or more of any type of wired or wireless network interface (e.g., a network interface card (NIC)), such as an IEEE 802.11 wireless local area network (WLAN) wireless interface, a World Wide Interoperability for Microwave Access (Wi-MAX) interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth interface, or a near field communication (NFC) interface. In one embodiment of the present disclosure, the above components of the computing device 800 and other components not shown in FIG. 8 may also be connected to each other, for example, via a bus. It should be understood that the computing device structure block diagram shown in FIG. 8 is for illustrative purposes only and does not limit the scope of the present disclosure. Those skilled in the art may add or replace other components as needed. In one embodiment of the present disclosure, the aforementioned components of computing device 800 and other components not shown in FIG. 8 may also be connected to each other, for example, via a bus. It should be understood that the computing device structure block diagram shown in FIG. 8 is for illustrative purposes only and does not limit the scope of the present disclosure. Those skilled in the art may add or replace other components as needed.The computing device 800 can be any type of stationary or mobile computing device, including a mobile computer or mobile computing device (e.g., a tablet computer, personal digital assistant, laptop computer, notebook computer, netbook, etc.), a mobile phone (e.g., a smartphone), a wearable computing device (e.g., a smartwatch, smart glasses, etc.), or other types of mobile devices, or a stationary computing device such as a desktop computer or a personal computer (PC). The computing device 800 can also be a mobile or stationary server. The processor 820 is configured to execute the following computer program / instructions, which, when executed by the processor, implement the steps of the above-described memory resource allocation method. The above is a schematic diagram of a computing device in this embodiment. It should be noted that the technical solution of this computing device and the technical solution of the above-described memory resource allocation method are based on the same concept. For details not described in detail in the technical solution of the computing device, please refer to the description of the technical solution of the above-described memory resource allocation method. One embodiment of the present disclosure further provides a computer-readable storage medium storing a computer program / instructions that, when executed by a processor, implement the steps of the aforementioned memory resource allocation method. The above is an illustrative embodiment of a computer-readable storage medium according to this embodiment. It should be noted that the technical solution of this storage medium and the technical solution of the aforementioned memory resource allocation method are based on the same concept. For details not described in detail in the technical solution of the storage medium, please refer to the description of the technical solution of the aforementioned memory resource allocation method. Another embodiment of the present disclosure further provides a computer program product, including a computer program / instructions that, when executed by a processor, implement the steps of the aforementioned memory resource allocation method. The above is an illustrative embodiment of a computer program product according to this embodiment. It should be noted that the technical solution of this computer program product and the technical solution of the aforementioned memory resource allocation method are based on the same concept. For details not described in detail in the technical solution of the computer program product, please refer to the description of the technical solution of the aforementioned memory resource allocation method. The above describes specific embodiments of the present disclosure. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different from that described in the embodiments and still achieve the desired results. In addition, the processes depicted in the accompanying drawings do not necessarily require the specific order shown or the sequential order to achieve the desired results. In some embodiments, multi-tasking and parallel processing are also possible or may be advantageous.The computer program includes computer program code, which may be in source code form, object code form, an executable file, or some intermediate form. The computer-readable medium may include any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a mobile hard drive, a magnetic disk, an optical disk, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electric carrier signal, a telecommunications signal, and a software distribution medium. It should be noted that the content of the computer-readable medium may be appropriately increased or decreased based on the requirements of patent practice. For example, in some regions, according to patent practice, computer-readable media do not include electric carrier signals and telecommunications signals. It should be noted that, for ease of description, the aforementioned method embodiments are described as a series of actions. However, those skilled in the art should understand that the embodiments of the present disclosure are not limited by the order of the actions described, as certain steps may be performed in a different order or simultaneously according to the embodiments of the present disclosure. Secondly, those skilled in the art should also be aware that the embodiments described in this disclosure are preferred embodiments, and the actions and modules described are not necessarily required for the embodiments of this disclosure. In the above embodiments, the descriptions of each embodiment have their own specific focus. For portions not described in detail in a particular embodiment, reference should be made to the relevant descriptions of other embodiments. The preferred embodiments disclosed above are merely intended to help illustrate this disclosure. The alternative embodiments do not describe all details in detail, nor do they limit the invention to the specific implementations described. Obviously, many modifications and variations are possible based on the content of the embodiments of this disclosure. This disclosure selects and describes these embodiments in detail to better explain the principles and practical applications of the embodiments of this disclosure, thereby enabling those skilled in the art to better understand and utilize this disclosure. This disclosure is limited only by the claims and their full scope and equivalents.
Claims
Claims 1. A memory resource allocation method, comprising: Get the kernel loading address of the guest operating system; Based on the kernel load address, a kernel version corresponding to the virtual machine memory resources is determined, wherein the virtual machine memory resources include a plurality of pre-allocated physical pages, and the client operating system is used to manage the virtual machine memory resources; based on the kernel version, a target scanning range and a target scanning parameter of the plurality of physical pages are queried from a target database, wherein the target database is set in a host machine and pre-stores scanning ranges and scanning parameters of physical pages corresponding to each kernel version in the target database; based on the target scanning range and the target scanning parameter, the virtual machine memory resources are scanned to determine a target physical page in an idle state among the plurality of physical pages; and based on the target physical page, memory resource reallocation is performed.
2. The method according to claim 1, wherein obtaining the kernel loading address of the guest operating system comprises: Based on the guest operating system, identifying a layout pattern of a kernel address space of the guest operating system, and obtaining a page table start address of the kernel address space; Based on the layout mode and the page table start address, a kernel load address is determined.
3. The method according to claim 2, wherein determining the kernel loading address based on the layout mode and the page table starting address comprises: When the layout mode is a fixed mode, the page table start address is determined as the kernel loading address.
4. The method according to claim 2, wherein determining a kernel loading address based on the layout mode and the page table starting address comprises: When the layout mode is random mode, a page table entry mapping check is performed based on the page table starting address according to a preset step size to obtain a target address where a target page table entry mapping exists; and a kernel loading address is determined based on the target address and the page table starting address.
5. The method according to any one of claims 1 to 4, wherein determining the kernel version corresponding to the virtual machine memory resource based on the kernel loading address comprises: Parsing the virtual machine kernel image based on the kernel loading address to obtain a target kernel field; Performing encryption calculation on the target kernel field to obtain target encryption information; Based on the target encryption information, a kernel version corresponding to the virtual machine resource is matched from a preset verification database.
6. The method according to claim 5, wherein performing encryption calculation on the target kernel field to obtain target encryption information comprises: When the length of the target kernel field is greater than a preset length threshold, segmenting the target kernel field to obtain a plurality of segment fields; Perform encryption calculation on each segment field respectively to obtain target encryption information corresponding to each segment field; The matching and obtaining a kernel version corresponding to the virtual machine resource from a preset verification database based on the target encryption information includes: matching and obtaining a plurality of initial kernel versions from a preset verification database based on the target encryption information corresponding to each segment field; Based on the multiple initial kernel versions, a kernel version corresponding to the virtual machine resource is determined.
7. The method according to any one of claims 1 to 6, wherein scanning the virtual machine memory resources based on the target scanning range and the target scanning parameters to determine a target physical page in an idle state among the multiple physical pages comprises: Scanning the virtual machine memory resources based on the target scanning range to obtain structure information of the multiple physical pages; Based on the target scan parameter and the structure information of the multiple physical pages, a target physical page in an idle state among the multiple physical pages is determined.
8. The method according to claim 7, wherein the target scan parameter comprises a target parsing strategy; and determining a target physical page in an idle state among the plurality of physical pages based on the target scan parameter and the structure information of the plurality of physical pages comprises: parse the structure information of each physical page using the target parsing strategy to obtain the structure parameters of each physical page; Based on the structural parameters of each physical page, a target physical page in an idle state among the multiple physical pages is identified.
9. The method according to any one of claims 1 to 8, wherein the performing memory resource reallocation based on the target physical page comprises: Reclaiming the page table of the target physical page; In response to the memory allocation request sent by the target virtual machine, a page table is reallocated for the target physical page.
10. The method according to claim 9, before reclaiming the target physical page, further comprising: setting the access permission of the target physical page to an inaccessible state in a virtual machine memory address translation table, wherein the virtual machine memory access table is a physical page table used by the virtual machine to perform memory address translation when accessing memory resources.
11. A network cloud platform comprising virtual machine memory resources and a resource scheduler; the virtual machine memory resources comprising a plurality of pre-allocated physical pages; The resource scheduler is used to obtain the kernel loading address of the guest operating system; based on the kernel loading address, determine the kernel version corresponding to the virtual machine memory resource, wherein, The virtual machine memory resources include a plurality of pre-allocated physical pages, and the guest operating system is used to manage the virtual machine memory resources; based on the kernel version, querying a target scan range and target scan parameters for the plurality of physical pages from a target database, wherein the target database is provided in a host machine and pre-stores scan ranges and scan parameters for physical pages corresponding to respective kernel versions; based on the target scan range and the target scan parameters, scanning the virtual machine memory resources to determine a target physical page that is in an idle state among the plurality of physical pages; Memory resource reallocation is performed based on the target physical page.
12. The network cloud platform according to claim 11, wherein the resource scheduler is specifically configured to scan the virtual machine memory resources based on the target scan range to obtain the structural information of the multiple physical pages; and determine the target physical page in the multiple physical pages that is in an idle state based on the scan parameters and the structural information of the multiple physical pages.
13. The network cloud platform according to claim 11 or 12, further comprising a host operating system; the resource scheduler is further configured to set the access permission of the target physical page to an inaccessible state in the virtual machine memory address translation table recorded by the host operating system, wherein The virtual machine memory access table is a physical page table used by the virtual machine to convert memory addresses when accessing memory resources; the page table entry of the target physical page in the memory page table recorded by the host operating system is deleted, wherein the memory page table includes a mapping relationship between the virtual memory address of the virtual machine and the multiple physical pages.
14. A computing device, comprising: memory and processor; The memory is used to store computer programs / instructions, and the processor is used to execute the computer programs / instructions. When the computer program / instructions are executed by the processor, the steps of the method according to any one of claims 1 to 10 are implemented.
15. A computer-readable storage medium storing a computer program / instruction, wherein the computer program / instruction, when executed by a processor, implements the steps of the method according to any one of claims 1 to 10.
16. A computer program product, comprising a computer program / instructions, which, when executed by a processor, implements the steps of the method according to any one of claims 1 to 10.
Citation Information
Patent Citations
Memory recovery method and device
CN103593298A
Method and device for managing physical memories
CN103793331A
Memory recovery method and device and control equipment
CN114840330A
Virtual machine live migration method and device, storage medium and electronic equipment
CN116909689A
Lightweight virtual machine creation method and device, electronic equipment and storage medium
CN117193942A
Cited By
Memory depletion OOM emergency processing method and device, equipment and storage medium
CN121187846A
SaaS intelligent concurrent pushing system
CN121547497A