欢迎来到淘文阁 - 分享文档赚钱的网站! | 帮助中心 好文档才是您的得力助手!
淘文阁 - 分享文档赚钱的网站
全部分类
  • 研究报告>
  • 管理文献>
  • 标准材料>
  • 技术资料>
  • 教育专区>
  • 应用文书>
  • 生活休闲>
  • 考试试题>
  • pptx模板>
  • 工商注册>
  • 期刊短文>
  • 图片设计>
  • ImageVerifierCode 换一换

    高级操作系统高级操作系统 (21).pdf

    • 资源ID:57971740       资源大小:1.23MB        全文页数:28页
    • 资源格式: PDF        下载积分:8金币
    快捷下载 游客一键下载
    会员登录下载
    微信登录下载
    三方登录下载: 微信开放平台登录   QQ登录  
    二维码
    微信扫一扫登录
    下载资源需要8金币
    邮箱/手机:
    温馨提示:
    快捷下载时,用户名和密码都是您填写的邮箱或者手机号,方便查询和重复下载(系统自动生成)。
    如填写123,账号就是123,密码也是123。
    支付方式: 支付宝    微信支付   
    验证码:   换一换

     
    账号:
    密码:
    验证码:   换一换
      忘记密码?
        
    友情提示
    2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
    3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
    4、本站资源下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。
    5、试题试卷类文档,如果标题没有明确说明有答案则都视为没有答案,请知晓。

    高级操作系统高级操作系统 (21).pdf

    第 4 讲:Optimization of Virtual Machine Monitor第三节:Dune:Safe User-level Access to Privileged CPU FeaturesRequirement of DUNEFor MORE performance&featuresSafe User-level Access to Privileged CPU FeaturesDune:Safe User-level Access to Privileged CPU Features,Adam Belay,etc.,OSDI12.Requirement of DUNEFor MORE performance&featuresSpeed up garbage collection(Azul C4)pagetablePrivilege separation within a process(Palladium)MMUSafe native code in web browsers(Xax)Syscall handler.Some thoughts of DUNE Change kernelProblem:stability concerns,challenging to Optimization analysisdistribute,composability concerns.Some thoughts of DUNE exokernelProblem:must replace entire OS stack.Some thoughts of DUNE VMMProblem:virtual machines have strict partitioning.Some thoughts of DUNE Dune in a NutshellProvide safe user-level access to privileged CPU featuresStill a normal process in all ways(POSIX API,etc)Key idea:leverage existing virtualization hardware(VTx).Some thoughts of DUNE Dune Simple ArchHost mode-VMX root mode on IntelNormally used for hypervisorsIn Dune,we run the kernel here,for access VT-x instructions.Some thoughts of DUNE Dune Simple ArchGuest mode-VMX non-root mode on IntelNormally used by the guest kernelIn Dune,we run ordinary processes here,for access to privileged features.Some thoughts of DUNE Dune Simple ArchConfigures and manages virtualization hardwareProvides integration with the rest of the kernel in order to support a process abstractionUses Intel VTx.Some thoughts of DUNE Dune Simple ArchA uAlity library to help applicaAons manage privileged hardware featuresCompletely untrustedException handling,syscall handling,page allocator,page table management,ELF loader.Diff Between VMM&DUNEDUNE:using virtualization hardware to providea process.Contributions of DUNEDUNEa design that uses hardware-assisted virtualizationto safely and efficiently expose privileged hardwarefeatures to user programs while preserving standardOS abstractions.Memory managementSystem callsPOSIX Signals.Supported Hardware FeaturesHardware features exposed by Dune and theircorresponding privileged x86 instructions.Supported Hardware Features ExceptionsHardware features exposed by DuneNormally,reporting an exception to a user programrequires privilege mode transitions and an upcallmechanism(e.g.,signals)Dune can reduce exception overhead because it usesVT-x to deliver exceptions directly in hardware.proves the speed of delivering page fault exceptionsby more than 4 X.Supported Hardware Features Virtual MemoryHardware features exposed by Dunegives user programs the ability to manually controlTLB invalidations.page table updates can be performed in batcheswhen permitted by the application.Dune exposes TLB tagging by providing access toIntels recently added process-context identifier(PCID)or virtual-processor identifiers(VPID)featureDune results in a 7 speedup over Linux in the Appeland Li user-level virtual memory benchmarks.Supported Hardware Features Virtual Memory.Supported Hardware Features Privilege ModesHardware features exposed by DuneTwo motivating use cases for privilege modes areprivilege separation and sandboxing of untrustedcode.page table updates can be performed in batcheswhen permitted by the application.system call instructions trap to the process itself,rather than to the kernel,can be used for system call interposition and toprevent untrusted code from directly accessing thekernel.Compared to ptrace in Linux,we show that Dunecan intercept a system call with 25 X less overhead.Supported Hardware Features Privilege ModesSYSCALL will only trap back into the processUse VMCALL(i.e.a hypercall)to perform normal kernel system calls.Supported Hardware Features Privilege ModesIsolate untrusted code by running it in a less privileged mode(i.e.ring 3 on x86)Leverage the supervisorbit in the page table to protect memory.Implementation ChallengesReducing VM exit and VM entry overheadPthread and fork were tricky to integrate with theLinux kernelEPT does not support enough address spaceSignals should only be delivered to ring 0,butprocess is in ring 3.Implementation ChallengesReducing VM exit and VM entry overhead.Implementation ChallengesApplication:garbage collection.Implementation ChallengesApplication:sandbox.PerformanceOverhead analysis:VMX trans,EPT transOptimization analysis:Faster system call,Virt Mem manipulation.PerformanceSandbox:SPEC2000 performanceEPT overhead:use of large pages.PerformanceSandbox:Lighttpd performanceSlight reduction in throughput(less than 2%)due to VMCALL overhead.ConclusionsApplications can benefit from access to privilegedCPU featuresVirtualization hardware allows us to provide suchaccess safelyDune creates new opportunities to build andimprove applications without kernel changesDune has modest performance overhead.

    注意事项

    本文(高级操作系统高级操作系统 (21).pdf)为本站会员(刘静)主动上传,淘文阁 - 分享文档赚钱的网站仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知淘文阁 - 分享文档赚钱的网站(点击联系客服),我们立即给予删除!

    温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。




    关于淘文阁 - 版权申诉 - 用户使用规则 - 积分规则 - 联系我们

    本站为文档C TO C交易模式,本站只提供存储空间、用户上传的文档直接被用户下载,本站只是中间服务平台,本站所有文档下载所得的收益归上传人(含作者)所有。本站仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。若文档所含内容侵犯了您的版权或隐私,请立即通知淘文阁网,我们立即给予删除!客服QQ:136780468 微信:18945177775 电话:18904686070

    工信部备案号:黑ICP备15003705号 © 2020-2023 www.taowenge.com 淘文阁 

    收起
    展开