Computer systems, troubleshooting methods
The system addresses repeated resets in virtualized computer systems by switching tasks to a safety-oriented environment when anomalies occur, ensuring continuous and safe operation.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- DENSO CORP
- Filing Date
- 2022-12-15
- Publication Date
- 2026-05-26
AI Technical Summary
In virtualized computer systems, particularly in vehicles, hardware failures require continuous control to ensure safety, but existing methods of resetting and restarting virtual CPUs lead to repeated anomaly detection and resets, compromising system availability.
A computer system comprising hardware, a hypervisor, virtual machines, a monitoring unit, and an anomaly handling unit that switches the operating environment of a task using an abnormal physical device from a normal to a safety-oriented environment, ensuring function safety even with device anomalies.
This configuration allows continuous processing without compromising safety, enhancing system availability by restricting or replacing malfunctioning devices with alternatives, thus maintaining functional integrity.
Smart Images

Figure 0007865189000001 
Figure 0007865189000002 
Figure 0007865189000003
Abstract
Description
Technical Field
[0001] This disclosure relates to a technique for handling device anomalies in a virtualized computer system.
Background Art
[0002] The following Patent Document 1 describes a technique of operating a hypervisor on hardware and operating a plurality of virtual computer systems (hereinafter, virtual machines) on the hypervisor. Hereinafter, the CPU and peripheral devices included in the hardware are referred to as physical CPU and physical peripheral devices, and the CPU and peripheral devices virtualized on the virtual machine are referred to as virtual CPU and virtual peripheral devices.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] By the way, in a computer system mounted on a vehicle, for example, as described in ISO26262 Part 10-12, even if a hardware failure occurs, availability that enables continuous control safely is required.
[0005] In a virtualized computer system, it is conceivable to continue control by resetting and restarting the virtual CPU allocated to a task that uses a physical device in which an anomaly has been detected, and thus the physical CPU allocated to the virtual CPU. However, in this case, there is a problem that even if the physical CPU is reset, anomaly detection and reset are repeated every time an access to a physical device in which the anomaly has not been resolved is executed.
[0006] One aspect of this disclosure is providing an available virtualized computer system that can safely continue control even if a device failure occurs. [Means for solving the problem]
[0007] One aspect of this disclosure is a computer system comprising hardware (100), a hypervisor (200), a virtual machine (300), a monitoring unit (13), and an anomaly handling unit (33). The hardware comprises a plurality of physical devices. The hypervisor is configured to operate on the hardware. The virtual machine comprises a plurality of virtual devices that virtualize physical devices and are configured to operate on the hypervisor and provide an operating environment for tasks. The monitoring unit is configured to monitor the operation of the hardware. The anomaly handling unit is configured to switch the operating environment of a target task, which is a task using the abnormal physical device (the physical device in which the anomaly was detected), from a first operating environment to a second operating environment when the monitoring unit detects an anomaly in a physical device. The first operating environment is an operating environment set on the premise that the target task operates normally. The second operating environment is an operating environment set so that the safety of the functions realized by the target task is ensured even if there is an anomaly in the operation of the target task.
[0008] With this configuration, if a physical device malfunctions, the operating environment can be switched, allowing the processing of the target task to continue without compromising the safety of the functions implemented by that task. As a result, the availability of the computer system can be improved.
[0009] One aspect of this disclosure is a computer system comprising a hypervisor (200), a virtual machine (300), a monitoring unit (13), and an anomaly handling unit (33). Except for excluding hardware from the configuration, it is the same as the computer system of the other aspect described above, and can achieve the same effects as the computer system of the other aspect.
[0010] One aspect of this disclosure is an anomaly handling method in a computer system. The computer system comprises hardware (100), a hypervisor (200), a virtual machine (300), and a monitoring unit (31). The hardware comprises multiple physical devices. The hypervisor operates on the hardware. The virtual machine operates on the hypervisor and comprises multiple virtual devices that virtualize physical devices, configured to provide an operating environment for tasks. The monitoring unit is configured to monitor the operation of the hardware. In the anomaly handling method, if the monitoring unit detects an anomaly in a physical device, the operating environment of the target task, which is the task using the anomaly physical device, is switched from a first operating environment to a second operating environment. The first operating environment is an operating environment set on the premise that the target task operates normally. The second operating environment is an operating environment set so that even if there is an anomaly in the operation of the target task, the safety of the functions realized by the target task is ensured. By using this method, the same effects as the computer system described above can be achieved.
[0011] One aspect of this disclosure is an anomaly handling method in a computer system. The computer system comprises a hypervisor (200), a virtual machine (300), and a monitoring unit (31). The hypervisor operates on hardware comprising multiple physical devices. The virtual machine operates on the hypervisor and comprises multiple virtual devices that virtualize physical devices, configured to provide an operating environment for tasks. The monitoring unit is configured to monitor the operation of the hardware. In the anomaly handling method, if the monitoring unit detects an anomaly in a physical device, the operating environment of the target task, which is the task using the anomaly physical device, is switched from a first operating environment to a second operating environment. The first operating environment is an operating environment set on the premise that the target task operates normally. The second operating environment is an operating environment set so that even if there is an anomaly in the operation of the target task, the safety of the functions realized by the target task is ensured.
[0012] By this method, the same effects as the abnormality handling method of the other embodiment described above can be obtained. [Brief explanation of the drawing]
[0013] [Figure 1] This is a block diagram showing the configuration of a computer system. [Figure 2] This is a flowchart of the error handling process performed by the management task. [Figure 3] This is a timing diagram illustrating the general operation of a computer system. [Figure 4] This is an explanatory diagram showing the correspondence between tasks, virtual devices, and physical devices during normal operation. [Figure 5] This diagram illustrates the correspondence between tasks, virtual devices, and physical devices when a device anomaly is detected. [Modes for carrying out the invention]
[0014] Embodiments of this disclosure will be described below with reference to the drawings. [1. Structure] The computer system 1 shown in Figure 1 constitutes, for example, an electronic control unit (ECU) mounted on a vehicle. The computer system 1 comprises hardware 10, a hypervisor 20, and a plurality of virtual machines 30.
[0015] The hardware 10 comprises multiple CPUs (hereinafter referred to as physical CPUs) 11, various peripheral devices (hereinafter referred to as physical peripheral devices) 12, and a monitoring unit 13. The physical CPUs 11 and physical peripheral devices 12 are collectively referred to as physical devices 11 and 12.
[0016] The hardware 10 may include a multi-core CPU that houses a plurality of CPU cores in a single package. In this case, the plurality of CPU cores belonging to the multi-core CPU each correspond to an individual physical CPU. Hereinafter, an individual physical CPU is also denoted as pCPU1, pCPU2, pCPU3, …, and when collectively referring to physical CPUs, it is simply denoted as pCPU.
[0017] The physical peripheral device 12 includes a normal-use device 121 and an abnormal-use device 122. The normal-use device 121 is a device used for normal-time control. The normal-use device 121 may include a graphics processing unit, a programmable interrupt controller, a timer, a storage device, a communication device, and various actuators used for vehicle control, etc. The abnormal-use device 122 may include a device for restricting some functions and operations of the normal-use device 121, and an alternative device that provides functions equivalent to or similar to those of the normal-use device 121 and can be used in place of the normal-use device 121.
[0018] The monitoring unit 13 individually monitors the operations of the plurality of physical devices 11 and 12, and when detecting an abnormality such as a failure, it sends an abnormality notification to the virtual machine 30 to which the abnormal physical device, which is the physical device 11 or 12 where the abnormality is detected, is assigned.
[0019] The types of failures detected by the monitoring unit 13 may include arithmetic unit abnormality, memory abnormality, memory controller / bus abnormality, and device abnormality. The arithmetic unit abnormality is an operation abnormality of the physical CPU 11. The arithmetic unit abnormality may be determined using, for example, a method using a lockstep that causes the same processing to be executed on a plurality of physical CPUs and compares the processing results, or a method of individually diagnosing the physical CPU by a separately provided self-diagnosis mechanism.
[0020] Memory abnormality refers to an abnormality in the memory where the program executed by the physical CPU is stored or the physical CPU uses it as a work area. As a method for determining memory abnormality, a method of detecting bit errors using error correction codes or parity data stored in the memory together with data may be used.
[0021] Memory controller - bus abnormality may be determined by detecting unauthorized access to a memory area other than the memory area permitted to access by the physical CPU. Device abnormality refers to an abnormality in the physical peripheral device 12. Device abnormality may be determined by monitoring the response content from the physical peripheral device 12 when accessing the physical peripheral device 12. For example, when the physical peripheral device 12 is a sensor, it may be determined based on whether the sensor value is within an allowable range. Also, when the physical peripheral device 12 is an actuator, it may be determined based on the notification content such as normal end or abnormal end returned after operation.
[0022] The hypervisor 20 is software that operates a plurality of virtual machines 30 by virtualizing the hardware 10. In the present embodiment, a hypervisor called a bare - metal type or native type is assumed, and the hypervisor 20 operates directly on the hardware 10, and the virtual machine 30 operates on the hypervisor 20.
[0023] The hypervisor 20 includes a hypervisor scheduler (hereinafter, HV scheduler) 21 and a virtual device driver 22. The HV scheduler 21 is software that performs scheduling and the like for each virtual machine 30. The virtual device driver 22 is driver software for realizing a virtual peripheral device 32 on the virtual machine 30. The virtual device driver 22 controls so that the physical peripheral device 12 is correctly used by processing access requests to each individual physical peripheral device 12 shared by the plurality of virtual machines 30 one by one in an exclusive manner.
[0024] Multiple virtual machines 30 are virtual computer systems that run on the hypervisor 20. Each virtual machine 30 includes multiple virtual CPUs 31, multiple virtual peripheral devices 32, and management tasks 33.
[0025] Multiple virtual CPUs 31 are virtualized physical CPUs 11. Each virtual CPU 31 is assigned by the hypervisor 20 one of the multiple physical CPUs 11 belonging to the hardware 10. Multiple virtual peripheral devices 32 are all virtualized physical peripheral devices 12. The virtual peripheral devices 32 include a normal virtual device 321 associated with a normal device 121 and an abnormal virtual device 322 associated with an abnormal device 122.
[0026] The virtual machine 30 runs a virtual operating system (hereinafter referred to as the virtual OS) on the virtual CPU 31 and runs multiple tasks on the virtual OS. Access to the virtual peripheral device 32 from the started tasks is performed using system calls to the virtual OS.
[0027] Each virtual CPU 31 is configured with a cpumask that indicates the available physical CPUs 11. This cpumask contains identification information for the available physical CPUs 11, for example, as a bit string. Each virtual machine 30 is allocated multiple physical CPUs 11 by the hypervisor 20, ensuring that there is no overlap between virtual machines 30.
[0028] Note that cpumask is a value that identifies the assignable physical CPU 11, and which physical CPU 11 is actually assigned to each virtual CPU 31 is managed by the HV scheduler 21. Therefore, the cpumask of each virtual CPU 31 belonging to the same virtual machine 30 may all be set in the same way.
[0029] The management task 33 starts, stops, and schedules tasks according to the system status of computer system 1. Task scheduling means assigning one of multiple virtual CPUs 31 to each task. The system status of computer system 1 includes receiving abnormality notifications from the monitoring unit 13.
[0030] Management task 33 and hypervisor 20 run on a single physical CPU 11, which will be referred to as pCPUx below. The tasks initiated by the management task 33 include one or more normal tasks Ti (i=0,1,2,…) and a safety task T_SF. Normal tasks Ti are tasks that implement various functions using physical devices 11 and 12. When an abnormality is detected by the monitoring unit 13, the safety task T_SF executes a process to switch the operating environment of normal tasks Ti so that the safety of vehicle control is ensured even if processing by normal tasks Ti continues.
[0031] For example, a physical peripheral device 12 that has the function of changing the behavior of a vehicle is called a behavior device, and a physical peripheral device 12 that is accessed to obtain information used to determine the control amount of the behavior device is called a sensor device. In a normal task Ti that generates instructions for the behavior device, if there is an abnormality in the sensor device, an abnormal control amount may be calculated as an instruction for the behavior device.
[0032] Therefore, the processing of the safety task T_SF may include processing to limit the operating range and operating speed of the behavioral device so that even if an abnormal instruction is given to the behavioral device, the vehicle's behavior remains within a range that the driver can handle. Processing to limit the operating range and operating speed of the behavioral device may be achieved, for example, by accessing an actuator (i.e., one of the abnormality devices 122) configured to physically restrict the operation of the behavioral device. This processing is equivalent to partially restricting the functions and operations of the behavioral device included in the operating environment.
[0033] The processing of the safety task T_SF may include a process to switch the operation of the virtual device driver 22 so that when the normal task Ti accesses the sensor device, the value obtained from the sensor device is within a range that allows the normal task Ti to calculate a safe control variable. This process is equivalent to partially restricting the functions and operation of the sensor device included in the operating environment.
[0034] The processing of safety task T_SF may include switching the operation of the virtual device driver 22 so that access requests from normal task Ti to an abnormal physical device are converted into access requests to an alternative device that provides equivalent or similar functionality to the abnormal physical device. This process is equivalent to replacing the abnormal physical device included in the operating environment with an alternative device.
[0035] [2. Operation] Next, we will explain the general operation of computer system 1, which employs hypervisor 20. [2-1.Basic operation] The hypervisor 20 runs virtual machines 30 in parallel, utilizing the HV scheduler 21, physical CPUs 11, physical peripheral devices 12, etc. In this case, in order to maximize the real-time performance of each virtual machine 30, cpumask is configured to distribute multiple physical CPUs 11 to each virtual machine 30 without overlap between them.
[0036] The hypervisor 20 assigns a physical CPU 11 to a virtual CPU 31 that has become operational. Here, a virtual CPU 31 being operational means that some kind of processing (i.e., a task) has been assigned to it. When a physical CPU 11 is assigned to an operational virtual CPU 31, that virtual CPU 31 becomes operational.
[0037] The hypervisor 20 allocates the physical CPUs 11 as evenly as possible to each of the active virtual CPUs 31 so that the computer system 1 can operate efficiently. [2-2. Abnormal operation] In computer system 1, the abnormality handling process executed by management task 33 when an abnormality notification is received from monitoring unit 13 will be explained using the flowchart shown in Figure 2. Note that management task 33, which executes the abnormality handling process, corresponds to the abnormality handling unit in this disclosure. In the following, physical devices 11 and 12, in which an abnormality is detected by monitoring unit 13, will be referred to as abnormal physical devices, and normal tasks Ti, which operate on virtual devices 31 and 32 associated with abnormal physical devices, will be referred to as target tasks.
[0038] When the abnormality handling process is activated, as shown in Figure 2, in S110, pCPUx determines whether it is possible to ensure the safety of the vehicle control provided by the target task by activating the safety task T_SF. This determination is made, for example, using a pre-prepared determination table. The determination table indicates whether it is possible to continue processing based on the combination of the content of the abnormality notification from the monitoring unit 13 and the type of task.
[0039] If pCPUx determines that it is possible to ensure the safety of vehicle control by activating safety task T_SF, it proceeds to S120; if it determines that it is not possible to ensure the safety of vehicle control, it proceeds to S140.
[0040] In S120, pCPUx makes the assigned virtual CPU 31 operational by assigning it to the safety task T_SF. In the subsequent S130, pCPUx requests the HV scheduler 21 to allocate the physical CPU 11 to the virtual CPU 31 that was assigned to the safety task T_SF in the processing of S120, and then terminates the process.
[0041] In response to a request from management task 33 to allocate a physical CPU, the HV scheduler 21 refers to cpumask and allocates the physical CPU to the virtual CPU 31 assigned to safety task T_SF. This initiates the restriction control by safety task T_SF.
[0042] In S140, pCPUx executes ECU fail-safe processing and terminates the process. ECU fail-safe processing may, for example, involve stopping the entire ECU. [2-3. Example of Operation] A typical example of the operation of computer system 1 will be explained using the timing diagram in Figure 3.
[0043] Figure 3 assumes the following situation: The hypervisor 20 allocates three physical CPUs, pCPU1, pCPU2, and pCPUx, to a virtual machine 30 (hereinafter referred to as VM0). The management task 33 for VM0 is executed on pCPUx.
[0044] As shown in Figure 3, when a normal task T0 is started on VM0, the management task 33 assigns a virtual CPU 31 to the normal task T0. Let's assume that vCPU1 is assigned. As a result, vCPU1 becomes operational. The management task 33 requests the HV scheduler 21 to assign a physical CPU to vCPU1. In response to this request, the HV scheduler 21 refers to cpumask and assigns one physical CPU 11 to vCPU1. Let's assume that pCPU1 is assigned.
[0045] As a result, as shown in Figure 4, the normal task T0 operates on the pCPU1 assigned to vCPU1. Furthermore, the normal task T0 accesses the physical peripheral device 12 via the virtual peripheral device 32 and utilizes the physical peripheral device 12 to perform various functions.
[0046] Returning to Figure 3, during the execution of normal task T0, if the monitoring unit 13 detects an anomaly in the physical devices 11 and 12 used by normal task T0, it sends an anomaly notification to the management task 33. Upon receiving the anomaly notification, the management task 33 executes anomaly handling processing and assigns a virtual CPU 31 to safety task T_SF. Here, let's assume that vCPU2 is assigned. As a result, vCPU2 becomes operational. The management task 33 also requests the HV scheduler 21 to assign a physical CPU 11 to vCPU2. The HV scheduler 21 refers to cpumask and assigns a physical CPU 11 other than pCPU1 to vCPU2. Here, let's assume that pCPU2 is assigned.
[0047] As a result, as shown in Figure 5, the running normal task T0 continues processing while a separate safety task T_SF starts processing. The safety task T_SF executes a process to switch the operating environment of the normal task T0 so that the safety of the vehicle control provided by the normal task T0 is not compromised due to an anomaly detected by the monitoring unit 13. In other words, when the safety task T_SF is executed, the functions and operating range of the physical devices 11 and 12 used by the normal task T0 are restricted, or the malfunctioning physical peripheral device 12 is replaced with an alternative device.
[0048] In other words, the operating environment of the normal task Ti before the start of the safety task T_SF corresponds to the first operating environment in this disclosure, and the operating environment of the normal task Ti after the start of the safety task T_SF corresponds to the second operating environment in this disclosure.
[0049] Furthermore, if the abnormality detected by the monitoring unit 13 is such that the safety of vehicle control provided by the normal task T0 cannot be ensured by simply limiting the functions of physical devices 11 and 12 or replacing them with alternative devices as performed by the safety task T_SF, the management task 33 executes ECU fail-safe processing to shut down the entire ECU equipped with the computer system 1.
[0050] [3. Effects] The embodiments described in detail above produce the following effects. In computer system 1, if an abnormality is detected in physical devices 11 and 12 that constitute the operating environment of normal task Ti, safety task T_SF is activated to switch the operating environment of normal task Ti, and processing of normal task Ti continues in the switched operating environment. The switched operating environment is one in which some functions of physical devices 11 and 12 are restricted or replaced with alternative devices in order to ensure the safety of vehicle control provided by normal task Ti even if there is an abnormality in the operation of normal task Ti. Therefore, according to computer system 1, processing of normal task Ti can continue despite abnormalities in physical devices 11 and 12. As a result, the availability of computer system 1 can be achieved.
[0051] [4. Other Embodiments] Although embodiments of the present disclosure have been described above, the present disclosure is not limited to the embodiments described above and can be implemented in various modified forms.
[0052] (4a) In the above embodiment, the monitoring unit 13 notifies the management task 33 of the abnormality notification. However, assuming that multiple normal tasks Ti are always running, the abnormality notification may also be transmitted to normal tasks Ti other than the task involved in the abnormality. In this case, the normal task Ti that receives the abnormality notification may be configured to execute abnormality handling processing and start the safety task T_SF.
[0053] (4b) In the above embodiment, one safety task T_SF is used regardless of the content of the abnormality notification and the type of target task Ti. However, multiple safety tasks T_SF with different processing contents may be prepared depending on the content of the abnormality notification and the type of target task Ti. In other words, the physical peripheral devices 12 that are subject to functional restriction and replacement with alternative devices may differ depending on the content of the abnormality notification and the type of target task Ti.
[0054] (4c) In the above embodiment, when allocating a physical CPU 11 to the safety task T_SF, it is selected and allocated from among the physical CPUs 11 permitted for use by cpumask. However, it is also possible to allocate a physical CPU 11 that has been predetermined for use by the safety task T_SF.
[0055] (4d) Multiple functions of one component in the above embodiment may be realized by multiple components, or one function of one component may be realized by multiple components. Also, multiple functions of multiple components may be realized by one component, or one function realized by multiple components may be realized by one component. Furthermore, some of the configuration of the above embodiment may be omitted. Also, at least some of the configuration of the above embodiment may be added to or replaced with the configuration of other above embodiments.
[0056] (4e) In addition to the computer system described above, this disclosure can also be implemented in various forms, such as a system that uses the computer system as a component, or a method for dealing with device abnormalities.
[0057] [5. The technical concept disclosed herein] [Item 1] Hardware (100) with multiple physical devices, A hypervisor (200) configured to run on the aforementioned hardware, A virtual machine (300) which operates on the hypervisor and is configured to provide an operating environment for tasks, and which has multiple virtual devices that virtualize the physical devices, A monitoring unit (13) configured to monitor the operation of the aforementioned hardware, When the monitoring unit detects an abnormality in the physical device, the abnormality handling unit (33) is configured to switch the operating environment of the target task, which is the task using the abnormal physical device (the physical device in which the abnormality was detected), from the first operating environment to the second operating environment. Equipped with, The first operating environment is an operating environment that is set up on the premise that the target task operates normally, The second operating environment is an operating environment configured such that the safety of the functions implemented by the target task is ensured even if there is an abnormality in the operation of the target task. Computer system.
[0058] [Item 2] A hypervisor (200) configured to run on hardware (100) with multiple physical devices, A virtual machine (300) which operates on the hypervisor and is configured to provide an operating environment for tasks, and which has multiple virtual devices that virtualize the physical devices, A monitoring unit (13) configured to monitor the operation of the aforementioned hardware, When the monitoring unit detects an abnormality in the physical device, the abnormality handling unit (33) is configured to switch the operating environment of the target task, which is the task using the abnormal physical device (the physical device in which the abnormality was detected), from the first operating environment to the second operating environment. Equipped with, The first operating environment is an operating environment that is set up on the premise that the target task operates normally, The second operating environment is an operating environment configured such that the safety of the functions implemented by the target task is ensured even if there is an abnormality in the operation of the target task. Computer system.
[0059] [Item 3] A computer system as described in item 1 or item 2, The anomaly handling unit is configured to start a pre-prepared safety task on the virtual machine, thereby causing the safety task to perform the switching of the operating environment. Computer system.
[0060] [Item 4] The computer system described in item 3, The second operating environment includes the physical device, whose functions are partially restricted by the processing of the safety task, Computer system.
[0061] [Item 5] A computer system as described in item 3 or item 4, The second operating environment includes, in the processing of the safety task, a substitute physical device provided in place of the abnormal physical device, which provides equivalent or similar functionality to the abnormal physical device. Computer system. [Explanation of Symbols]
[0062] 1...Computer system, 10...Hardware, 11...Physical CPU, 12...Physical peripheral device, 13...Monitoring unit, 20...Hypervisor, 21...HV scheduler, 22...Virtual device driver, 30...Virtual machine, 31...Virtual CPU, 32...Virtual peripheral device, 33...Management task, 121...Normal device, 122...Abnormal device, 321...Normal virtual device, 321...Abnormal virtual device, Ti...Normal task, T_SF...Safety task.
Claims
1. Hardware (100) comprising multiple physical devices, A hypervisor (200) configured to operate on the aforementioned hardware, A virtual machine (300) which operates on the hypervisor and is configured to provide an operating environment for tasks, and which has multiple virtual devices that virtualize the physical devices, A monitoring unit (13) configured to monitor the operation of the aforementioned hardware, When the monitoring unit detects an abnormality in the physical device, the abnormality handling unit (33) is configured to switch the operating environment of the target task, which is the task using the abnormal physical device (the physical device in which the abnormality was detected), from the first operating environment to the second operating environment. Equipped with, The first operating environment is an operating environment that is set up on the premise that the target task operates normally, The second operating environment is an operating environment configured such that the safety of the functions implemented by the target task is ensured even if there is an abnormality in the operation of the target task. Computer system.
2. A hypervisor (200) configured to run on hardware (100) comprising multiple physical devices, A virtual machine (300) which operates on the hypervisor and is configured to provide an operating environment for tasks, and which has multiple virtual devices that virtualize the physical devices, A monitoring unit (13) configured to monitor the operation of the aforementioned hardware, When the monitoring unit detects an abnormality in the physical device, the abnormality handling unit (33) is configured to switch the operating environment of the target task, which is the task using the abnormal physical device (the physical device in which the abnormality was detected), from the first operating environment to the second operating environment. Equipped with, The first operating environment is an operating environment that is set up on the premise that the target task operates normally, The second operating environment is an operating environment configured such that the safety of the functions implemented by the target task is ensured even if there is an abnormality in the operation of the target task. Computer system.
3. A computer system according to claim 1 or claim 2, The anomaly handling unit is configured to start a pre-prepared safety task on the virtual machine, thereby causing the safety task to perform the switching of the operating environment. Computer system.
4. The computer system according to claim 3, The second operating environment includes the physical device, whose functions are partially restricted by the processing of the safety task, Computer system.
5. The computer system according to claim 3, The second operating environment includes a physical device provided in place of the abnormal physical device by processing the safety task, which is an alternative device that provides equivalent or similar functionality to the abnormal physical device. Computer system.
6. An abnormality handling method in a computer system comprising: hardware (100) having multiple physical devices; a hypervisor (200) operating on the hardware; a virtual machine (300) operating on the hypervisor and configured to provide a task operating environment, having multiple virtual devices that virtualize the physical devices; and a monitoring unit (31) configured to monitor the operation of the hardware, wherein If the monitoring unit detects an abnormality in the physical device, the operating environment of the target task, which is the task using the abnormal physical device (the physical device in which the abnormality was detected), is switched from the first operating environment to the second operating environment. The first operating environment is an operating environment that is set up on the premise that the target task operates normally, The second operating environment is an operating environment configured such that the safety of the functions implemented by the target task is ensured even if there is an abnormality in the operation of the target task. Troubleshooting methods.
7. An abnormality handling method in a computer system comprising: a hypervisor (200) operating on hardware (100) having multiple physical devices; a virtual machine (300) operating on the hypervisor and configured to provide a task operating environment, having multiple virtual devices that virtualize the physical devices; and a monitoring unit (31) configured to monitor the operation of the hardware, wherein If the monitoring unit detects an abnormality in the physical device, the operating environment of the target task, which is the task using the abnormal physical device (the physical device in which the abnormality was detected), is switched from the first operating environment to the second operating environment. The first operating environment is an operating environment that is set up on the premise that the target task operates normally, The second operating environment is an operating environment configured such that the safety of the functions implemented by the target task is ensured even if there is an abnormality in the operation of the target task. Troubleshooting methods.