Parallel processing and virtual machines · 并行处理和虚拟机
| English | 中文 | Pinyin · 拼音 |
|---|---|---|
| virtual machines/ˈvɜːtʃuːəl məˈʃiːnz/ | 虚拟机 | xū nǐ jī |
| parallelism/ˈpærəlelɪzəm/ | 并行 | bìng xíng |
| SIMD/ˈsɪmdiː/ | 单指令多数据 | dān zhǐ lìng duō shù jù |
| MIMD/ˈmɪmdiː/ | 多指令多数据 | duō zhǐ lìng duō shù jù |
| massively parallel/ˈmæsɪvli ˈpærəlel/ | 大规模并行 | dà guī mó bìng xíng |
| distributed memory/ˈdɪstrɪbjuːtɪd ˈmeməri/ | 分布式内存 | fēn bù shì nèi cún |
| hypervisor/ˌhaɪpəˈvaɪzə/ | 虚拟机监控器 | xū nǐ jī jiān kòng qì |
| sandboxing/ˈsændbɒksɪŋ/ | 沙箱 | shā xiāng |
| bytecode/ˈbaɪtkəʊd/ | 字节码 | zì jié mǎ |
| just-in-time compilation/dʒʌst ɪn taɪm ˌkɒmpɪˈleɪʃn/ | 即时编译 | jí shí biān yì |
One computer pretending to be forty
- A company used to buy one physical server per application: one for mail, one for the website, one for accounts. Each ran at about 8% of its capacity, and each drew full power in a rack that had to be cooled.
- Then the servers stopped being machines and became files. Forty virtual machines 虚拟机 now run on three physical hosts, each one convinced it has a processor, memory and disks of its own.
- The saving is not only electricity. A virtual machine can be snapshotted before a risky change, copied to another host while running, and destroyed if it is compromised.
- This lesson is parallelism 并行 and the virtual machine: how the two system architectures differ, and what a VM costs and buys.
一台计算机假装成四十台
- 一家公司过去每个应用买一台物理服务器:邮件一台、网站一台、财务一台。每台跑在大约 8% 的利用率上,却在必须制冷的机柜里满功率耗电。
- 后来服务器不再是机器,而成了文件。四十台虚拟机(virtual machines)现在跑在三台物理主机上,每一台都确信自己有独立的处理器、内存和磁盘。
- 省下的不只是电。虚拟机可以在有风险的改动前拍快照、在运行中被复制到另一台主机、被攻陷后直接销毁。
- 这一课讲并行(parallelism)和虚拟机:两种系统架构有何不同,以及虚拟机的代价和收益。
Parallel architectures, briefly
- Parallelism means many processing elements working at once. Flynn's taxonomy names the shapes: SIMD 单指令多数据 runs one instruction over many data items, and MIMD 多指令多数据 runs different instructions on different data.
- A massively parallel 大规模并行 machine takes MIMD to thousands of processors, each with its own distributed memory 分布式内存, communicating by messages.
- Speed no longer comes from raising the clock, which is limited by heat, but from doing more things at once. Every architecture on this page is an answer to that.
Different instructions, different data, at the same time
并行架构,简述
- 并行意味着许多处理单元同时工作。弗林分类给出了这些形态:SIMD(单指令多数据)让一条指令作用于许多数据项,MIMD(多指令多数据)对不同数据运行不同指令。
- 大规模并行(massively parallel)机器把 MIMD 推到数千个处理器,每个有自己的分布式内存(distributed memory),靠消息通信。
- 速度不再来自提高时钟频率——那受发热限制——而来自同时做更多的事。这一页上的每种架构都是对此的回答。

不同的指令、不同的数据,同时进行
SIMD means: · SIMD意为:
Single Instruction, Multiple Data — e.g. a GPU running the same operation on thousands of pixels. · 单指令多数据 — 例如GPU在同一操作下处理数千个像素。
Match each of Flynn's categories to an example. · 将Flynn分类的每一项与示例匹配。
Flynn classifies by how many instruction and data streams run at once: SISD, SIMD, MIMD (and the rare MISD). · Flynn根据同时运行的指令和数据流数量进行分类:SISD、SIMD、MIMD(以及罕见的MISD)。
A massively parallel computer uses: · 大规模并行计算机使用:
Massively parallel systems (supercomputers) link thousands of processors with distributed memory over a fast network. · 大规模并行系统(超级计算机)通过高速网络连接成千上万带有分布式内存的处理器。
What a virtual machine is
- A virtual machine is a software emulation of a whole computer. The software running inside it sees a processor, memory and disks that look real but are provided and managed by host software.
- There are two kinds, and the exam distinguishes them: a system VM runs a complete guest operating system, and a process VM runs one program's portable code.
- Neither is an emulator of a faster machine. A VM's purpose is isolation and portability, not speed.
什么是虚拟机
- 虚拟机是对整台计算机的软件模拟。在它里面运行的软件看到的处理器、内存和磁盘看起来是真的,实际上由宿主软件提供和管理。
- 有两种,考试会区分它们:系统虚拟机运行完整的客户操作系统,进程虚拟机运行一个程序的可移植代码。
- 两者都不是对更快机器的模拟。虚拟机的目的是隔离和可移植性,不是速度。
Computing concept lab · 计算概念实验
Classify concrete examples by the computing idea they demonstrate. · 根据它们所演示的计算概念对具体示例进行分类。
What is a virtual machine? · 什么是虚拟机?
The point is emulation and isolation, not speed. A system VM runs a whole guest OS; a process VM runs one program's bytecode. · 重点在于模拟和隔离,而非速度。系统VM运行完整的客户操作系统;进程VM运行单个程序的字节码。
System virtual machines
- A hypervisor 虚拟机监控器 is the software that creates and manages virtual machines, dividing the host's real processor, memory and disks between them and keeping each one isolated from the others.
- Each VM boots its own guest operating system, so one host can run Windows, Linux and an old legacy system side by side.
- Uses: running different operating systems on one machine; server consolidation, replacing many under-used physical servers with one host; sandboxing 沙箱, so risky or untrusted software runs isolated and cannot reach the host; and snapshots, so a machine can be rolled back to a known state.
A rack of hosts, each carrying many virtual machines
系统虚拟机
- 虚拟机监控器(hypervisor)是创建和管理虚拟机的软件,它把宿主真实的处理器、内存和磁盘分给各个虚拟机,并让它们彼此隔离。
- 每台虚拟机启动自己的客户操作系统,所以一台主机可以并排跑 Windows、Linux 和一个老旧的遗留系统。
- 用途:在一台机器上运行不同的操作系统;服务器整合,用一台主机取代许多利用率很低的物理服务器;沙箱(sandboxing),让有风险或不受信任的软件隔离运行、无法触及宿主;以及快照,让机器可以回滚到已知状态。

一柜主机,每台承载许多虚拟机
A hypervisor is used to: · hypervisor用于:
A hypervisor manages system VMs, letting several guest operating systems share one physical machine. · hypervisor管理系统VM,使多个客户操作系统共享一台物理机。
A system VM (managed by a hypervisor) runs a whole guest operating system, whereas a process VM like the JVM just runs one program's portable bytecode. · 系统VM(由hypervisor管理)运行完整的客户操作系统,而像JVM这样的进程VM仅运行单个程序的便携字节码。
System VMs share one physical machine among several guest OSes; process VMs give "write once, run anywhere" for a single program. · 系统VM在多客户OS之间共享一台物理机;进程VM为单个程序提供“一次编写,到处运行”。
The software that creates and manages several system VMs on one host is called a . · 在一台主机上创建和管理多个系统VM的软件称为。
It divides the host's real hardware between the guests and keeps each isolated, which is what makes sandboxing and consolidation possible. · 它将主机的真实硬件分配给客户机并保持各自隔离,这正是沙盒和整合成为可能的原因。
Process virtual machines
- A process VM, also called a language VM, runs one program written in portable bytecode 字节码 rather than the host's machine code. The Java Virtual Machine and the .NET CLR are the examples.
- Benefits: portability, since the same bytecode runs anywhere a VM exists, which is "write once, run anywhere"; runtime safety, since the VM checks what the code does; and just-in-time compilation 即时编译 of hot code to native instructions, so long-running programs approach native speed.
- Costs: an extra layer between the program and the hardware, and the VM must be installed before the program will run at all.
进程虚拟机
- 进程虚拟机,也叫语言虚拟机,运行一个程序,它写成可移植的字节码(bytecode)而不是宿主的机器码。Java 虚拟机和 .NET CLR 就是例子。
- 好处:可移植性,因为同一份字节码在任何有虚拟机的地方都能运行,即"一次编写,到处运行";运行时安全,因为虚拟机检查代码在做什么;以及对热点代码的即时编译(just-in-time compilation),让长时间运行的程序接近本机速度。
- 代价:在程序和硬件之间多了一层,而且必须先安装虚拟机程序才能运行。
Which are benefits of a process (language) VM such as the JVM? Select all · 所有 that apply. · 进程(语言)VM如JVM的优势有哪些?选择所有适用项。
The VM must be present; that is the cost of the portability. Portability, safety and JIT are the benefits. · VM必须存在;这是便携性的代价。便携性、安全性和JIT是优势。
Worked example: which kind of VM
- A security team wants to open suspicious email attachments without risking the company network. A system VM: the guest OS is isolated by the hypervisor, so malware cannot reach the host, and the snapshot is restored afterwards to discard anything it did.
- A developer wants one compiled program to run on Windows, macOS and Linux without recompiling. A process VM: the program is compiled to bytecode and each platform's VM runs it.
- Name the kind, then the property, isolation or portability, that the situation needs.
例题:用哪种虚拟机
- 一个安全团队想打开可疑的邮件附件,又不想让公司网络冒险。 系统虚拟机:客户操作系统被虚拟机监控器隔离,所以恶意软件够不到宿主,事后再恢复快照丢弃它做过的一切。
- 一位开发者希望一个编译好的程序在 Windows、macOS 和 Linux 上都能运行而不必重新编译。 进程虚拟机:程序被编译成字节码,每个平台的虚拟机运行它。
- 说出种类,再说出情境需要的那条性质——隔离,还是可移植性。
Put the consequences of one physical host failing, in order. · 请将一台物理主机发生故障的后果按顺序排列。
Consolidation concentrates the risk: one host is a single point of failure for everything it carries. That is the limitation to state. · 整合会集中风险:一台主机承载一切,成为单点故障。这就是状态层面的局限性。
Worked example: benefits and limitations
- Explain two benefits and two limitations of using virtual machines to replace a company's physical servers. [4]
- Benefits: several servers run on one physical host, so hardware, power and cooling costs fall; and each VM is isolated, so a compromised or crashed server does not affect the others, and can be restored from a snapshot.
- Limitations: the VMs share the host's real processor, memory and disks, so performance is lower than dedicated hardware and one busy VM can starve the others; and if the host fails, every VM on it fails at once.
- Two of each, and each one a consequence, not just a label.
例题:好处与局限
- 解释用虚拟机取代公司物理服务器的两个好处和两个局限。[4]
- 好处:几台服务器跑在一台物理主机上,所以硬件、电力和制冷成本下降;每台虚拟机彼此隔离,所以一台被攻陷或崩溃的服务器不影响其他,而且可以从快照恢复。
- 局限:各虚拟机共享宿主真实的处理器、内存和磁盘,所以性能低于专用硬件,一台繁忙的虚拟机会饿死其他的;而且如果宿主故障,它上面的每一台虚拟机同时故障。
- 各两条,而且每条都要是后果,不能只是一个标签。
Marks that slip away
- A hypervisor manages system VMs; it is not the guest operating system and not the host's own OS.
- A process VM runs bytecode, which is not machine code. That is what makes it portable.
- The limitation of a VM is shared resources and a single point of failure, not "it is complicated".
- "Sandboxing" needs its consequence: the risky software is isolated from the host, so it cannot damage or reach it.
容易丢掉的分
- 虚拟机监控器管理系统虚拟机;它不是客户操作系统,也不是宿主自己的操作系统。
- 进程虚拟机运行字节码,那不是机器码。正是这一点让它可移植。
- 虚拟机的局限是资源共享和单点故障,不是"它很复杂"。
- "沙箱"要带上它的后果:有风险的软件与宿主隔离,所以够不到也损害不了宿主。
You've got it
- parallelism answers the clock-speed limit: SIMD for one instruction over many data, MIMD for many instructions, massively parallel for thousands of processors with distributed memory
- a virtual machine is a software emulation of a whole computer
- a system VM runs a full guest OS under a hypervisor: different operating systems on one machine, server consolidation, sandboxing, snapshots
- a process VM runs portable bytecode with runtime safety and just-in-time compilation; the costs are an extra layer, shared host resources and one host failing takes every VM with it
你掌握了
- 并行回应了时钟频率的极限:SIMD 一条指令作用于多数据,MIMD 多条指令,大规模并行是数千处理器加分布式内存
- 虚拟机是对整台计算机的软件模拟
- 系统虚拟机在虚拟机监控器下运行完整的客户操作系统:一台机器上的不同操作系统、服务器整合、沙箱、快照
- 进程虚拟机运行可移植的字节码,带运行时安全和即时编译;代价是多一层、共享宿主资源,以及宿主一故障就带走上面所有虚拟机