Computer systems, troubleshooting methods

The system addresses repeated anomalies in virtualized computer systems by switching tasks to a different virtual device, ensuring safe and continuous control without hardware resets, thereby maintaining high availability.

JP7859306B2Active Publication Date: 2026-05-15DENSO CORP
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
DENSO CORP
Filing Date
2022-12-15
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

In a virtualized computer system, repeated resets and anomalies occur when a hardware failure is detected, leading to unsafe control conditions.

Method used

A computer system comprising hardware, a hypervisor, virtual machines, a monitoring unit, and an anomaly handling unit that switches tasks from a virtual device with a detected anomaly to another virtual device providing a safe operating environment, excluding the faulty physical device.

Benefits of technology

Ensures safe and continuous control by quickly transitioning to a state where hardware resets are not required, maintaining high availability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007859306000001
    Figure 0007859306000001
  • Figure 0007859306000002
    Figure 0007859306000002
  • Figure 0007859306000003
    Figure 0007859306000003
Patent Text Reader

Abstract

To provide a virtualized computer system which ensures the availability of safely continuing control even if a device malfunctions.SOLUTION: A management task 33 switches, when a monitoring section 13 detects malfunctions in physical devices 11, 12, a task running on a first virtual device so as to run on a second virtual device. The first virtual device is a virtual device that provides an operating environment including malfunctioning physical devices which are the physical devices in which the malfunctions have been detected by the monitoring section 13. The second virtual device is a virtual device that provides an operating environment excluding the malfunctioning physical devices.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to a technique for dealing with device anomalies in a virtualized computer system.

Background Art

[0002] The following Patent Document 1 describes a technique of operating a hypervisor on hardware and operating a plurality of virtual computer systems (hereinafter referred to as virtual machines) on the hypervisor. Hereinafter, the CPU and peripheral devices included in the hardware are referred to as physical CPU and physical peripheral devices, and the CPU and peripheral devices virtualized on the virtual machine are referred to as virtual CPU and virtual peripheral devices.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] By the way, in a computer system mounted on a vehicle, for example, as described in ISO26262 Part 10-12, even if a hardware failure occurs, availability that enables control to continue safely is required.

[0005] In a virtualized computer system, it is conceivable to continue control by resetting and restarting the virtual CPU assigned to a task that uses a physical device in which an anomaly is detected, and thus the physical CPU assigned to the virtual CPU. However, in this case, there is a problem that even if the physical CPU is reset, anomaly detection and reset are repeated every time an access to a physical device in which the anomaly has not been resolved is executed.

[0006] One aspect of this disclosure is providing an available virtualized computer system that can safely continue control even if a device failure occurs. [Means for solving the problem]

[0007] One aspect of this disclosure is a computer system comprising hardware (100), a hypervisor (200), a virtual machine (300), a monitoring unit (13), and an anomaly handling unit (33). The hardware comprises a plurality of physical devices. The hypervisor is configured to operate on the hardware. The virtual machine comprises a plurality of virtual devices that virtualize physical devices and are configured to operate on the hypervisor and provide an operating environment for tasks. The monitoring unit is configured to monitor the operation of the hardware. The anomaly handling unit is configured to switch a task running on a first virtual device to run on a second virtual device when the monitoring unit detects an anomaly in a physical device. The first virtual device is a virtual device that provides an operating environment including an anomaly physical device, which is a physical device in which an anomaly has been detected by the monitoring unit. The second virtual device is a virtual device that provides an operating environment excluding the anomaly physical device.

[0008] With this configuration, even if a physical device malfunctions, the system can quickly transition to a state where safe control can continue without requiring hardware resets, thereby achieving high availability for the computer system.

[0009] One aspect of this disclosure is a computer system comprising a hypervisor (200), a virtual machine (300), a monitoring unit (13), and an anomaly handling unit (33). Except for excluding hardware from the configuration, it is the same as the computer system of the other aspect described above, and can achieve the same effects as the computer system of the other aspect.

[0010] One aspect of this disclosure is a method for handling an anomaly in a computer system comprising: hardware (100) having a plurality of physical devices; a hypervisor (200) operating on the hardware; a virtual machine (300) operating on the hypervisor and configured to provide an operating environment for tasks, having a plurality of virtual devices that virtualize the physical devices; and a monitoring unit (31) that monitors the operation of the hardware. The method involves switching a task running on a first virtual device to run on a second virtual device when the monitoring unit detects an anomaly in a physical device. The first virtual device is a virtual device that provides an operating environment including the anomaly physical device, which is the physical device in which the monitoring unit detected an anomaly. The second virtual device is a virtual device that provides an operating environment excluding the anomaly physical device. By using this method, the same effects as the computer system described above can be achieved.

[0011] One aspect of this disclosure is a method for handling an anomaly in a computer system comprising: a hypervisor (200) operating on hardware having multiple physical devices; a virtual machine (300) operating on the hypervisor and configured to provide an operating environment for tasks, having multiple virtual devices that virtualize the physical devices; and a monitoring unit (31) that monitors the operation of the hardware. The method involves switching a task running on a first virtual device to run on a second virtual device when the monitoring unit detects an anomaly in a physical device. The first virtual device is a virtual device that provides an operating environment including the anomaly in a physical device, which is the physical device in which the monitoring unit detected an anomaly. The second virtual device is a virtual device that provides an operating environment excluding the anomaly in a physical device.

[0012] By this method, the same effects as the abnormality handling method of the other embodiment described above can be obtained. [Brief explanation of the drawing]

[0013] [Figure 1] This is a block diagram showing the configuration of a computer system. [Figure 2] This is a flowchart of the error handling process performed by the management task. [Figure 3] This is a timing diagram illustrating the general operation of a computer system. [Figure 4] This is an explanatory diagram showing the correspondence between tasks, virtual devices, and physical devices during normal operation. [Figure 5] This diagram illustrates the correspondence between tasks, virtual devices, and physical devices when a device anomaly is detected. [Modes for carrying out the invention]

[0014] Embodiments of this disclosure will be described below with reference to the drawings. [1. Structure] The computer system 1 shown in Figure 1 constitutes, for example, an electronic control unit (ECU) mounted on a vehicle. The computer system 1 comprises hardware 10, a hypervisor 20, and a plurality of virtual machines 30.

[0015] The hardware 10 comprises multiple CPUs (hereinafter referred to as physical CPUs) 11, various peripheral devices (hereinafter referred to as physical peripheral devices) 12, and a monitoring unit 13. The physical CPUs and physical peripheral devices are collectively referred to as physical devices 11 and 12.

[0016] Hardware 10 may include a multi-core CPU that houses multiple CPU cores in a single package. In this case, each of the multiple CPU cores belonging to the multi-core CPU corresponds to an individual physical CPU. Hereinafter, individual physical CPUs will be denoted as pCPU1, pCPU2, pCPU3, ..., and when referring to physical CPUs collectively, they will simply be referred to as pCPU.

[0017] The physical peripheral devices 12 may include a graphics processing unit (GPU), a programmable interrupt controller (PIC), a timer, a storage device, and a communication device, etc.

[0018] The monitoring unit 13 individually monitors the operations of a plurality of physical devices 11 and 12, and when detecting an abnormality such as a failure, notifies the virtual machine 30 to which the abnormal physical device, which is the physical device 11 or 12 in which the abnormality is detected, is assigned of the physical device abnormality.

[0019] The types of failures detected by the monitoring unit 13 may include an arithmetic unit abnormality and a device abnormality. The arithmetic unit abnormality is an operation abnormality of the physical CPU 11. The arithmetic unit abnormality may be determined using, for example, a method using a lock step that executes the same process on a plurality of physical CPUs and compares the processing results, or a method of individually diagnosing the physical CPU by a separately provided self-diagnosis mechanism.

[0020] The device abnormality is an abnormality of the physical peripheral device 12. The device abnormality may be determined by monitoring the response content from the physical peripheral device 12 when accessing the physical peripheral device 12. For example, when the physical peripheral device 12 is a sensor, it may be determined based on whether the sensor value is within an allowable range. Also, when the physical peripheral device 12 is an actuator, it may be determined based on the notification content such as normal end or abnormal end returned after the operation.

[0021] The hypervisor 20 is software that operates a plurality of virtual machines 30 by virtualizing the hardware 10. In the present embodiment, a hypervisor called a bare-metal type or a native type is assumed, and the hypervisor 20 directly operates on the hardware 10, and the virtual machine 30 operates on the hypervisor 20.

[0022] The hypervisor 20 includes a hypervisor scheduler (hereinafter, HV scheduler) 21, a virtual device driver 22, and a proxy response unit 23. The HV scheduler 21 is software that performs scheduling for each virtual machine 30. The virtual device driver 22 is driver software for realizing virtual peripheral devices 32 on the virtual machine 30. The virtual device driver 22 controls the physical peripheral devices 12 to be used correctly by processing access requests for each physical peripheral device 12, which are shared by multiple virtual machines 30, exclusively, one by one. The proxy response unit 23 is software that sends a pseudo-response to access requests from tasks on behalf of physical peripheral devices 12 that are prohibited from accessing.

[0023] Multiple virtual machines 30 are virtual computer systems that run on the hypervisor 20. Each virtual machine 30 includes multiple virtual CPUs 31, multiple virtual peripheral devices 32, and management tasks 33.

[0024] The multiple virtual CPUs 31 are virtualized physical CPUs 11. Each virtual CPU 31 is assigned by the hypervisor 20 one of the multiple physical CPUs 11 belonging to the hardware 10. The multiple virtual peripheral devices 32 are all virtualized physical peripheral devices 12. Each virtual peripheral device 32 is assigned by the hypervisor 20 one of the multiple physical peripheral devices 12 belonging to the hardware 10.

[0025] The virtual machine 30 runs a virtual operating system (hereinafter referred to as the virtual OS) on the virtual CPU 31 and runs multiple tasks on the virtual OS. Access to the virtual peripheral device 32 from the started tasks is performed using system calls to the virtual OS.

[0026] Each virtual CPU 31 is configured with a cpumask that indicates the available physical CPUs 11. This cpumask contains identification information for the available physical CPUs 11, for example, as a bit string. Each virtual machine 30 is allocated multiple physical CPUs 11 by the hypervisor 20, ensuring that there is no overlap between virtual machines 30.

[0027] Note that cpumask is a value that identifies the assignable physical CPU 11, and which physical CPU 11 is actually assigned to each virtual CPU 31 is managed by the HV scheduler 21. Therefore, the cpumask of each virtual CPU 31 belonging to the same virtual machine 30 may all be set in the same way.

[0028] The management task 33 starts, stops, and schedules tasks according to the system status of computer system 1. Task scheduling means assigning one of multiple virtual CPUs 31 to each task. The system status of computer system 1 includes receiving abnormality notifications from the monitoring unit 13.

[0029] Management task 33 and hypervisor 20 run on a single physical CPU 11, which will be referred to as pCPUx below. Management task 33 starts one abnormal normal task Ti (i=0,1,2,…). Normal task Ti is a task that uses physical devices 11 and 12 to implement various functions.

[0030] [2. Operation] Next, we will explain the general operation of computer system 1, which employs hypervisor 20. [2-1.Basic operation] The hypervisor 20 runs virtual machines 30 in parallel, utilizing the HV scheduler 21, physical CPUs 11, physical peripheral devices 12, etc. In this case, in order to maximize the real-time performance of each virtual machine 30, cpumask is configured to distribute multiple physical CPUs 11 to each virtual machine 30 without overlap between them.

[0031] The hypervisor 20 assigns a physical CPU 11 to a virtual CPU 31 that has become operational. Here, a virtual CPU 31 being operational means that some kind of processing (i.e., a task) has been assigned to it. When a physical CPU 11 is assigned to an operational virtual CPU 31, that virtual CPU 31 becomes operational.

[0032] The hypervisor 20 allocates the physical CPUs 11 as evenly as possible to each of the active virtual CPUs 31 so that the computer system 1 can operate efficiently. [2-2. Abnormal operation] In computer system 1, the abnormality handling process executed by management task 33 when an abnormality notification is received from monitoring unit 13 will be explained using the flowchart shown in Figure 2. Note that management task 33, which executes the abnormality handling process, corresponds to the abnormality handling unit in this disclosure. In the following, physical devices 11 and 12, in which an abnormality is detected by monitoring unit 13, will be referred to as abnormal physical devices, and normal tasks Ti, which operate on virtual devices 31 and 32 associated with abnormal physical devices, will be referred to as target tasks.

[0033] When the abnormality handling process is activated, as shown in Figure 2, in S110, pCPUx determines whether it is possible to continue processing the target task using the remaining physical devices, which are physical devices 11 and 12 excluding the abnormal physical device. This determination is made, for example, using a pre-prepared determination table. The determination table indicates whether processing can be continued based on the combination of the content of the abnormality notification from the monitoring unit 13 and the type of task. For example, if the abnormal physical device is the physical CPU 11, or if the abnormal physical device is the physical peripheral device 12 and safety can be ensured even with degraded control by the remaining physical devices, it is determined that processing can be continued. If the abnormal physical device is essential for the execution of the process and safety cannot be ensured with degraded control, it is determined that processing cannot be continued.

[0034] If pCPUx determines that the remaining physical devices can continue processing the target task, it proceeds to S120. If it determines that the remaining physical devices cannot continue processing the target task, it proceeds to S180.

[0035] In S120, pCPUx determines whether the abnormal physical device is the physical CPU 11 or the physical peripheral device 12. If it is the physical CPU 11, it proceeds to S130; if it is the physical peripheral device 12, it proceeds to S170.

[0036] In S130, pCPUx interrupts the processing of the target task by stopping the allocation of virtual CPU 31 to the target task. In the subsequent S140, pCPUx requests the HV scheduler 21 to detach the abnormal physical CPU. In response to the detachment request, the HV scheduler 21 stops assigning the abnormal physical CPU to the virtual CPU 31 that was assigned to the target task. In addition, in the virtual machine 30 to which the target task belongs, the cpumask of each virtual CPU 31 is rewritten so that the abnormal physical CPU cannot be assigned to the virtual CPU 31 belonging to the virtual machine 30.

[0037] In the subsequent S150, pCPUx reassigns virtual CPU 31 to the target task, thereby putting the target task into an operational state. In the subsequent S160, pCPUx requests the HV scheduler 21 to allocate the physical CPU 11 to the virtual CPU 31 that was assigned to the target task in the S150 process, and then terminates the process.

[0038] In response to a request from management task 33 to allocate physical CPU 11, the HV scheduler 21 refers to cpumask and allocates physical CPU 11 to the virtual CPU 31 assigned to the target task. However, since cpumask has already been rewritten to prevent the selection of an abnormal physical CPU, a physical CPU 11 to be assigned to the virtual CPU 31 is selected from among the other normally functioning physical CPUs 11 (i.e., the remaining physical CPUs). As a result, the operation of the suspended target task resumes.

[0039] In S170, pCPUx requests the HV scheduler 21 to disconnect the abnormal physical device and terminates the process. In response to a request to disconnect an abnormal physical device, the HV scheduler 21 prohibits access to the abnormal physical peripheral device 12 and activates the proxy response unit 23. When the proxy response unit 23 receives an access request from the virtual peripheral device 32 to the physical peripheral device 12, which has been denied access, it returns a pseudo-response with predetermined content to the requesting task without actually accessing the physical peripheral device 12. The pseudo-response is configured so that no dangerous situation occurs even if control continues according to the content of the pseudo-response. If the physical peripheral device 12 is a sensor, the content of the pseudo-response is a value that simulates the detected value, and if the physical peripheral device 12 is an actuator, it is a notification indicating that the operation of the actuator has been completed, etc. In other words, the target task will execute degraded control according to the content of these pseudo-responses.

[0040] In S180, pCPUx executes ECU fail-safe processing and terminates the process. ECU fail-safe processing may, for example, involve stopping the entire ECU. [2-3. Example of Operation] A typical example of the operation of computer system 1 will be explained using the timing diagram in Figure 3.

[0041] Figure 3 assumes the following situation: The hypervisor 20 allocates three physical CPUs, pCPU1, pCPU2, and pCPUx, to a virtual machine 30 (hereinafter referred to as VM0). The management task 33 for VM0 is executed on pCPUx.

[0042] As shown in Figure 3, when task T0 is started on VM0, the management task 33 assigns a virtual CPU 31 to task T0. Let's assume that vCPU1 is assigned. As a result, vCPU1 becomes operational. The management task 33 requests the HV scheduler 21 to assign a physical CPU to vCPU1. In response to this request, the HV scheduler 21 refers to cpumask and assigns one physical CPU to vCPU1. Let's assume that pCPU1 is assigned.

[0043] As a result, as shown in Figure 4, task T0 runs on the pCPU1 assigned to vCPU1. Task T0 also accesses the physical peripheral device 12 via the virtual peripheral device 32 and performs processing using the physical peripheral device 12.

[0044] Returning to Figure 3, if the monitoring unit 13 detects an abnormality in pCPU1 while task T0 is running, it sends an abnormality notification to the management task 33. Since the abnormal physical device indicated in the abnormality notification is the physical CPU 11, the management task 33 stops allocating vCPU1 to task T0 and requests the HV scheduler 21 to stop allocating pCPU1 to vCPU1. As a result, vCPU1 becomes active and the operation of task T0 is interrupted. At this time, the HV scheduler 21 rewrites cpumask so that the abnormal physical device pCPU1 cannot be allocated to VM0.

[0045] Next, management task 33 reassigns virtual CPU 31 to task T0. Let's assume vCPU2 is assigned here. As a result, vCPU2 becomes operational. Management task 33 also requests HV scheduler 21 to assign a physical CPU to vCPU2. HV scheduler 21 refers to cpumask and assigns a physical CPU other than pCPU1 to vCPU2. In this case, pCPU2 is assigned.

[0046] As a result, as shown in Figure 5, the interrupted task T0 resumes operation on the pCPU2, which is functioning normally. Although not shown in the diagram, if the abnormal physical device indicated in the abnormality notification is the physical peripheral device 12, and safety can be ensured even with degraded control that isolates the abnormal physical device, the management task 33 requests the HV scheduler 21 to isolate the physical peripheral device 12, which is the abnormal physical device. Upon receiving the request, the HV scheduler 21 prohibits access to the abnormal physical device and enables the proxy response unit 23 to operate.

[0047] As a result, as shown in Figure 5, even if the virtual peripheral device 32 receives an access request from task T0 to the physical peripheral device 12, which is prohibited from accessing, access to the physical peripheral device 12 is not performed, and a pseudo-response is sent back to task T0, the source of the access request, from the proxy response unit 23. Task T0 continues to perform degraded control with functional limitations according to the content of the pseudo-response.

[0048] Furthermore, if the physical device detected as abnormal by the monitoring unit 13 (i.e., the abnormal physical device) is a physical peripheral device 12 and safety cannot be ensured by degraded control, the management task 33 executes ECU fail-safe processing to shut down the ECU equipped with the computer system 1 so as not to endanger the vehicle's control.

[0049] [3. Effects] The embodiments described in detail above produce the following effects. In computer system 1, if an abnormality is detected in physical devices 11 and 12, a new virtual device is configured to provide a new operating environment using the remaining physical devices, excluding the abnormal physical device, instead of the virtual devices 31 and 32 that provide the operating environment including the abnormal physical device. The operation of the target task is then continued on the newly configured virtual device. Therefore, even if an abnormality occurs in a physical device, the system can quickly transition to a state where safe control can be continued without resetting hardware 10, thereby ensuring the availability of computer system 1.

[0050] [4. Other Embodiments] Although embodiments of this disclosure have been described above, this disclosure is not limited to the embodiments described above and can be implemented in various modified forms.

[0051] (4a) In the above embodiment, the proxy response unit 23 returns a pseudo-response in response to an access request to the physical peripheral device 12, which is prohibited from accessing. However, instead of a pseudo-response, for example, a notification indicating that access is prohibited may be returned. In this case, the processing of the task that receives this notification may be configured to switch from normal control to degraded control.

[0052] (4b) In the above embodiment, the monitoring unit 13 detects the device abnormality, but for example, instead of the monitoring unit 13, the requesting task that issued the access request to the physical peripheral device 12 may detect the device abnormality by monitoring the response from the physical peripheral device 12.

[0053] (4c) Multiple functions of one component in the above embodiment may be realized by multiple components, or one function of one component may be realized by multiple components. Also, multiple functions of multiple components may be realized by one component, or one function realized by multiple components may be realized by one component. Furthermore, some of the configuration of the above embodiment may be omitted. Also, at least some of the configuration of the above embodiment may be added to or replaced with the configuration of other above embodiments.

[0054] (4d) In addition to the computer system described above, this disclosure can also be implemented in various forms, such as a system that uses the computer system as a component, or a method for dealing with device abnormalities.

[0055] [5. The technical concept disclosed herein] [Item 1] Hardware (100) with multiple physical devices, A hypervisor (200) configured to run on the aforementioned hardware, A virtual machine (300) which operates on the hypervisor and is configured to provide an operating environment for tasks, and which has multiple virtual devices that virtualize the physical devices, A monitoring unit (13) configured to monitor the operation of the aforementioned hardware, When the monitoring unit detects an abnormality in the physical device, an abnormality handling unit (33) is configured to switch the task running on the first virtual device to run on the second virtual device, Equipped with, The first virtual device is a virtual device that provides the operating environment including the abnormal physical device, which is the physical device in which an abnormality has been detected by the monitoring unit. The second virtual device is the virtual device that provides the operating environment excluding the abnormal physical device. Computer system.

[0056] [Item 2] A hypervisor (200) configured to run on hardware (100) with multiple physical devices, A virtual machine (300) which operates on the hypervisor and is configured to provide an operating environment for tasks, and which has multiple virtual devices that virtualize the physical devices, A monitoring unit (13) configured to monitor the operation of the aforementioned hardware, When the monitoring unit detects an abnormality in the physical device, an abnormality handling unit (33) is configured to switch the task running on the first virtual device to run on the second virtual device, Equipped with, The first virtual device is a virtual device that provides the operating environment including the abnormal physical device, which is the physical device in which an abnormality has been detected by the monitoring unit. The second virtual device is the virtual device that provides the operating environment excluding the abnormal physical device. Computer system.

[0057] [Item 3] A computer system as described in item 1 or item 2, The abnormal physical device includes a CPU (11), The anomaly handling unit interrupts the task running on the first virtual device to configure the second virtual device, and then resumes the interrupted task on the configured second virtual device. Computer system.

[0058] [Item 4] A computer system as described in any one of items 1 through 3, The aforementioned abnormal physical device includes peripheral devices (12) other than the CPU, The anomaly handling unit instructs the hypervisor to prohibit access to the anomaly physical device. The hypervisor includes a proxy response unit (20) configured to, when the second virtual device receives an access request from the task for the peripheral device that has been instructed to be denied access, to return a pseudo-response to the task that made the access request, which simulates the response of the peripheral device that is the target of the access. Computer system. [Explanation of Symbols]

[0059] 1...Computer system, 10...Hardware, 11...CPU / Physical CPU, 12...Peripheral device / Physical peripheral device, 13...Monitoring unit, 20...Hypervisor, 21...HV scheduler, 22...Virtual device driver, 23...Proxy response unit, 30...Virtual machine, 31...Virtual CPU, 32...Virtual peripheral device, 33...Management task.

Claims

1. Hardware (100) comprising multiple physical devices, A hypervisor (200) configured to operate on the aforementioned hardware, A virtual machine (300) which operates on the hypervisor and is configured to provide an operating environment for tasks, and which has multiple virtual devices that virtualize the physical devices, A monitoring unit (13) configured to monitor the operation of the aforementioned hardware, When the monitoring unit detects an abnormality in the physical device, an abnormality handling unit (33) is configured to switch the task running on the first virtual device to run on the second virtual device, Equipped with, The first virtual device is a virtual device that provides the operating environment including the abnormal physical device, which is the physical device in which an abnormality has been detected by the monitoring unit. The second virtual device is the virtual device that provides the operating environment excluding the abnormal physical device, The abnormal physical device includes peripheral devices (12) other than the CPU, The anomaly handling unit instructs the hypervisor to prohibit access to the anomaly physical device. The hypervisor includes a proxy response unit (20) configured to, when the second virtual device receives an access request from the task for the peripheral device that has been instructed to be denied access, to return a pseudo-response to the task that originated the access request, which simulates the response of the peripheral device that is the target of the access. Computer system.

2. A hypervisor (200) configured to run on hardware (100) comprising multiple physical devices, A virtual machine (300) which operates on the hypervisor and is configured to provide an operating environment for tasks, and which has multiple virtual devices that virtualize the physical devices, A monitoring unit (13) configured to monitor the operation of the aforementioned hardware, When the monitoring unit detects an abnormality in the physical device, an abnormality handling unit (33) is configured to switch the task running on the first virtual device to run on the second virtual device, Equipped with, The first virtual device is a virtual device that provides the operating environment including the abnormal physical device, which is the physical device in which an abnormality has been detected by the monitoring unit. The second virtual device is the virtual device that provides the operating environment excluding the abnormal physical device, The abnormal physical device includes peripheral devices (12) other than the CPU, The anomaly handling unit instructs the hypervisor to prohibit access to the anomaly physical device. The hypervisor includes a proxy response unit (20) configured to, when the second virtual device receives an access request from the task for the peripheral device that has been instructed to be denied access, to return a pseudo-response to the task that originated the access request, which simulates the response of the peripheral device that is the target of the access. Computer system.

3. A computer system according to claim 1 or claim 2, The abnormal physical device includes a CPU (11), The anomaly handling unit interrupts the task running on the first virtual device to configure the second virtual device, and then resumes the interrupted task on the configured second virtual device. Computer system.

4. An abnormality handling method in a computer system comprising: hardware (100) having multiple physical devices; a hypervisor (200) operating on the hardware; a virtual machine (300) operating on the hypervisor and configured to provide a task operating environment, having multiple virtual devices that virtualize the physical devices; and a monitoring unit (31) that monitors the operation of the hardware, wherein If the monitoring unit detects an abnormality in the physical device, it switches the task running on the first virtual device to run on the second virtual device, and instructs the hypervisor to prohibit access to the abnormal physical device. When the hypervisor receives an access request from the task for the peripheral device that has been instructed to be denied access, the second virtual device sends back a pseudo-response to the task that made the access request, which simulates the response of the peripheral device that is the target of the access. The abnormal device is a physical device in which an abnormality has been detected by the monitoring unit, and includes peripheral devices (12) other than the CPU. The first virtual device is the virtual device that provides the operating environment including the abnormal physical device, The second virtual device is the virtual device that provides the operating environment excluding the abnormal physical device. Troubleshooting methods.

5. An abnormality handling method in a computer system comprising: a hypervisor (200) operating on hardware (100) having multiple physical devices; a virtual machine (300) operating on the hypervisor and configured to provide a task operating environment, having multiple virtual devices that virtualize the physical devices; and a monitoring unit (31) that monitors the operation of the hardware, wherein If the monitoring unit detects an abnormality in the physical device, it switches the task running on the first virtual device to run on the second virtual device, and instructs the hypervisor to prohibit access to the abnormal physical device. When the hypervisor receives an access request from the task for the peripheral device that has been instructed to be denied access, the second virtual device sends back a pseudo-response to the task that made the access request, which simulates the response of the peripheral device that is the target of the access. The abnormal physical device is a physical device in which an abnormality has been detected by the monitoring unit, and includes peripheral devices (12) other than the CPU. The first virtual device is the virtual device that provides the operating environment including the abnormal physical device, The second virtual device is the virtual device that provides the operating environment excluding the abnormal physical device. Troubleshooting methods.