Microsoft has released the Linux distribution CBL-Mariner 2.0.

Microsoft has released the first stable update of the new branch of the CBL-Mariner 2.0 (Common Base Linux Mariner) distribution, which is being developed as a universal base platform for Linux environments used in cloud infrastructure, edge systems, and various Microsoft services. The project aims to unify Linux solutions used at Microsoft and simplify the maintenance of Linux systems of various purposes in an up-to-date state. The project contributions are released under the MIT license. Package builds are created for the aarch64 and x86_64 architectures.

The new release is notable for a significant update of software versions. This includes updates to the Linux kernel 5.15 (in branch 1.0 the kernel 5.4 was used), systemd 250, glibc 2.35, GCC 11.2, clang 12, Python 3.9, ruby 3.1.2, rpm 4.17, qemu 6.1, perl 5.34, ostree 2022.1. The base repository includes components for building graphical interfaces, such as Wayland 1.20, Mesa 21.0, GTK 3.24, and X.Org Server 1.20.10, which were previously provided in a separate coreui repository. Kernel builds with PREEMPT_RT patches for use in real-time systems have been added.

The CBL-Mariner distribution provides a small standard set of core packages, serving as a universal foundation for creating container fillings, host environments, and services that run in cloud infrastructures and on edge devices. More complex and specialized solutions can be created by adding additional packages on top of CBL-Mariner, but the foundation for all such systems remains unchanged, simplifying maintenance and update preparation. For example, CBL-Mariner is used as the basis for the mini-distribution WSLg, which provides components of the graphical stack for launching Linux GUI applications in environments based on the WSL2 (Windows Subsystem for Linux). Extended functionality in WSLg is realized through the inclusion of additional packages with a composite proxy server Weston, XWayland, PulseAudio, and FreeRDP.

The CBL-Mariner build system allows for the generation of both individual RPM packages based on SPEC files and source texts, as well as monolithic system images formed using the rpm-ostree toolkit and updated atomically without breaking into individual packages. Accordingly, two update delivery models are supported: through separate package updates and through rebuilding and updating the entire system image. A repository is available that includes about 3000 already built RPM packages, which can be used to assemble custom images based on a configuration file.

The distribution includes only the most essential components and is optimized for minimal memory and disk space consumption, as well as for high boot speed. The distribution is also notable for including various additional mechanisms for enhanced security. The project adopts a 'maximum security by default' approach. It provides the ability to filter system calls using the seccomp mechanism, disk partition encryption, and package verification through digital signatures.

Supported kernel space address randomization modes have been activated, along with mechanisms protecting against attacks related to symbolic links, mmap, /dev/mem, and /dev/kmem. For memory areas housing kernel data segments and modules, a read-only mode has been established, prohibiting code execution. Optionally, a capability to prevent kernel module loading after system initialization is available. The iptables toolkit is utilized for packet filtering. By default, stack overflow protection, buffer overflow safeguarding, and string formatting issues (_FORTIFY_SOURCE, -fstack-protector, -Wformat-security, relro) are enabled during build.

The system manager systemd is used for managing services and load. Package managers RPM and DNF are provided for package management. By default, the SSH server is not enabled. An installer is provided for installing the distribution, which can work in both text and graphical modes. The installer allows the installation of either a full or a minimal set of packages, offers an interface for selecting the disk partition, choosing the hostname, and creating users.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster