IP Library › Granted Patent US 12,585,578
Granted Patent B1
US 12,585,578 · App. 18/760,682 · Granted Mar 24, 2026

System and method for virtualization-assisted debugging

Inventor: Andrey Stupachenko (Moscow, RU)
Assignee: Parallels International GmbH
G06F11/3698G06F9/45558G06F11/3624G06F2009/45591
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,585,578
App. No.
18/760,682
Granted
Mar 24, 2026
Kind
B1
Abstract

Disclosed are systems and methods for debugging program code using a computing system. The disclosed method includes designating a control point in a software application subject to a debugging procedure, and then executing the program code for the software application as a guest application executing within a virtual machine. Upon detection of a virtualization event, the hardware processor transfers program control to a hypervisor which then determines whether the virtualization event corresponds to the designated control point based on an execution state of the guest application. If so, the virtualization event handler may generate a debugging event that is used by a debugger.

Claims (53)

1 . A method comprising:

executing a specially configured hypervisor (hypervisor) upon a computer system which manages execution upon the computer system of a guest application within a virtual machine (VM);

establishing an occurrence of a virtualization event relating to the VM with a virtual event handler forming part of the hypervisor during execution of the guest application;

determining whether the occurrence of the virtualization event relates to a normal virtualization event associated with the guest application or whether the occurrence of the virtualization event corresponds to a virtualization event to be handled by debugging program code (debugger);

upon a determination that the occurrence of the virtualization event corresponds to a normal virtualization event handling the virtualization event with the hypervisor or a virtual machine monitor of the VM; and

upon a determination that the occurrence of the virtualization event corresponds to a virtualization event to be handled by the debugger handling the virtualization event with the debugger; wherein

the virtual event handler exploits nested page table (NPT) faults; and

the virtual event handler clears or changes access rights to one or more entries within an NPT associated with the VM to establish a control point to suspend execution of the guest application to trigger a VM-EXIT and upon a VM-ENTRY back into the guest application the virtual event handler restores the cleared or changed access rights to one or more entries within an NPT.

2 . The method according to claim 1 , wherein

the hypervisor is configured to hook the virtualization event when the virtualization event corresponds to a virtualization event to be handled by the debugger to support debugging of the guest application executing within the VM in combination with another debugging method; and

the another debugging method is selected from the group comprising a software breakpoint method, a hardware breakpoint method, a watchpoint method and a hardware-assisted tracing method.

3 . The method according to claim 1 , wherein

the determination that the occurrence of the virtualization event corresponds to a virtualization event to be handled by the debugger is established in dependence upon determining that a control point within the guest application matches a designated control point of a set of designated control points established by a user via the debugger; and

each designated control point of the set of designated control points established by the user is defined by one of an indication of a label or identifier within code instructions of the guest application, a line number within the code instructions of the guest application, a function name defined by the user within code instructions of the guest application and a condition relating to an internal variable of the guest application established by the user.

4 . The method according to claim 1 , wherein

the determination that the occurrence of the virtualization event corresponds to a virtualization event to be handled by the debugger is established in dependence upon analyzing another virtualization event triggered by a transition by the guest application or the VM from a non-root operation to a root operation (VM-EXIT).

5 . The method according to claim 1 , wherein

the determination that the occurrence of the virtualization event corresponds to a virtualization event to be handled by the debugger is established in dependence upon analyzing another virtualization event triggered by a transition by the guest application or the VM from a non-root operation to a root operation (VM-EXIT); and

the VM-EXIT is associated with a model-specific register (MSR) of a model of a microprocessor forming part of the computer system; and

the MSR is conditional in triggering the VM-EXIT.

6 . The method according to claim 1 , wherein

the determination that the occurrence of the virtualization event corresponds to a virtualization event to be handled by the debugger is established in dependence upon analyzing another virtualization event triggered by a transition by the guest application or the VM from a non-root operation to a root operation (VM-EXIT); and

the VM-EXIT is associated with a model-specific register (MSR) of a model of a microprocessor forming part of the computer system; and

the MSR is unconditional in triggering the VM-EXIT.

7 . The method according to claim 1 , wherein

the determination that the occurrence of the virtualization event corresponds to a virtualization event to be handled by the debugger is established in dependence upon analyzing another virtualization event triggered by a transition by the guest application or the VM from a non-root operation to a root operation (VM-EXIT); and

the determination that the occurrence of the virtualization event corresponds to a virtualization event to be handled by the debugger causes a VM virtual processor state to be saved into a guest state area of the computer system which comprises contents of one or more virtual registers (VRs) and one or more model specific registers (MSRs).

8 . The method according to claim 1 , wherein

the hypervisor enables tracing of all events within the execution of the guest application.

9 . The method according to claim 1 , wherein

the hypervisor enables tracing of one or more events within the execution of the guest application; and

each event of the one or more events relates to a debugging exception.

10 . The method according to claim 1 , wherein

the hypervisor enables tracing of one or more events within the execution of the guest application; and

each event of the one or more events is traced independent of any dependency upon a trace flag.

11 . The method according to claim 1 , wherein

the hypervisor enables tracing of one or more events within the execution of the guest application; and

the guest application comprises program code employing one or more techniques which prevent reverse engineering or debugging of the guest application.

12 . The method according to claim 1 , wherein

the virtual event handler enables or disables a single-stepping execution configuration of a processor executing a software application whilst the software application is in execution by modifying a setting of a VM control data structure associated with the VM; and

the VM control data structure is employed by a logical processor of the VM to manage at least one of transitions in and out of non-root operations and behaviour of the logical processor during non-root operations.

13 . The method according to claim 1 , wherein

the virtual event handler enables or disables a single-stepping execution configuration of a processor executing a software application whilst the software application is in execution by modifying a setting of a VM control data structure associated with the VM.

14 . A method comprising:

executing a specially configured hypervisor (hypervisor) upon a computer system which manages execution upon the computer system of a guest application within a virtual machine (VM);

establishing an occurrence of a virtualization event relating to the VM with a virtual event handler forming part of the hypervisor during execution of the guest application;

determining whether the occurrence of the virtualization event relates to a normal virtualization event associated with the guest application or whether the occurrence of the virtualization event corresponds to a virtualization event to be handled by debugging program code (debugger);

upon a determination that the occurrence of the virtualization event corresponds to a normal virtualization event handling the virtualization event with the hypervisor or a virtual machine monitor of the VM; and

upon a determination that the occurrence of the virtualization event corresponds to a virtualization event to be handled by the debugger handling the virtualization event with the debugger; wherein

the virtualization event is a nested page table fault;

the virtualization event is generated by clearing an access right for a page of code;

the debugger modifies a nested page table in dependence upon a selection made by a user; and

the virtual event handler VMM resets the access right upon completion of a debugging process applied by the debugger.

Continuity (2)
Continuation 17236336 · Apr 21, 2021
Continuation 16352106 · Mar 13, 2019
References Cited (48)
US 7398421B1 · Limaye et al. · 2008 [cited by applicant]
US 7647589B1 · Dobrovolskiy · 2010 [cited by examiner]
US 8261047B2 · Moyer et al. · 2012 [cited by applicant]
US 8671405B2 · Nicholas et al. · 2014 [cited by applicant]
US 9170922B1 · Lachwani et al. · 2015 [cited by applicant]
US 9454461B1 · Bates et al. · 2016 [cited by applicant]
US 10108446B1 · Steinberg · 2018 [cited by examiner]
US 10162665B1 · Eidelman · 2018 [cited by applicant]
US 10447728B1 · Steinberg · 2019 [cited by examiner]
US 10740217B1 · Stupachenko et al. · 2020 [cited by applicant]
US 20010032305A1 · Barry · 2001 [cited by applicant]
US 20030014738A1 · Dawkins et al. · 2003 [cited by applicant]
US 20030131039A1 · Bajoria · 2003 [cited by examiner]
US 20040078784A1 · Bates et al. · 2004 [cited by applicant]
US 20040123288A1 · Bennett · 2004 [cited by examiner]
US 20050091022A1 · Levit-Gurevich et al. · 2005 [cited by applicant]
US 20060122821A1 · Hildner · 2006 [cited by examiner]
US 20090037936A1 · Serebrin · 2009 [cited by applicant]
US 20090083735A1 · Kimura · 2009 [cited by applicant]
US 20090182976A1 · Agesen · 2009 [cited by applicant]
US 20090254883A1 · Munson · 2009 [cited by examiner]
US 20100199040A1 · Schnapp et al. · 2010 [cited by applicant]
US 20100313061A1 · Huth et al. · 2010 [cited by applicant]
US 20100333090A1 · Wright et al. · 2010 [cited by applicant]
US 20110072309A1 · Sakai et al. · 2011 [cited by applicant]
US 20110225458A1 · Zuo et al. · 2011 [cited by applicant]
US 20110225459A1 · Fahrig et al. · 2011 [cited by applicant]
US 20110252271A1 · Frenkel et al. · 2011 [cited by applicant]
US 20130007729A1 · Sirotkin · 2013 [cited by applicant]
US 20130055206A1 · Dudek et al. · 2013 [cited by applicant]
US 20130117849A1 · Golshan et al. · 2013 [cited by applicant]
US 20130132776A1 · Hou · 2013 [cited by applicant]
US 20130159999A1 · Chiueh et al. · 2013 [cited by applicant]
US 20140281730A1 · Chazan · 2014 [cited by examiner]
US 20150082305A1 · Hepkin · 2015 [cited by examiner]
US 20150347220A1 · Hermany · 2015 [cited by examiner]
US 20160070630A1 · Williams et al. · 2016 [cited by applicant]
US 20160140052A1 · Waldspurger · 2016 [cited by examiner]
US 20160292108A1 · Konishi et al. · 2016 [cited by applicant]
US 20170123960A1 · Pechanec et al. · 2017 [cited by applicant]
US 20170364379A1 · Warkentin et al. · 2017 [cited by applicant]
US 20170371769A1 · Merten · 2017 [cited by examiner]
US 20180113764A1 · Bhandari et al. · 2018 [cited by applicant]
US 20190020559A1 · Cao et al. · 2019 [cited by applicant]
US 20190319863A1 · Gupta et al. · 2019 [cited by applicant]
US 20200042698A1 · Urias et al. · 2020 [cited by applicant]
US 20200050364A1 · Gilbert et al. · 2020 [cited by applicant]
US 20200167180A1 · Tsirkin · 2020 [cited by examiner]