Red Hat has released Red Hat Enterprise Linux 8.7. Installation builds are prepared for x86_64, s390x (IBM System z), ppc64le, and Aarch64 architectures, but are available for download only to registered users of the Red Hat Customer Portal. The source code for the RPM packages of Red Hat Enterprise Linux 8 is distributed through the CentOS Git repository. The 8.x branch is maintained alongside the RHEL 9.x branch and will be supported at least until 2029.
New releases are prepared according to a development cycle that involves creating releases every six months at a predetermined time. Until 2024, the 8.x branch will be in full support, which includes new functional improvements. After that, it will transition to maintenance mode, where priorities will shift to fixing bugs and security issues, with only minor enhancements related to support for important hardware systems.
Key changes:
- The toolkit for preparing system images has been expanded, now supporting the booting of images in GCP (Google Cloud Platform), placing images directly into the container registry, adjusting the /boot partition size, and modifying parameters (Blueprint) during image generation (e.g., adding packages and creating users).
- Support is provided for using the Clevis client (clevis-luks-systemd) for the automatic unlocking of disk partitions encrypted with LUKS and mounted late in the boot process, without the need to use the command 'systemctl enable clevis-luks-askpass.path'.
- A new package xmlstarlet is proposed, which includes utilities for parsing, transforming, validating, extracting data, and editing XML files.
- A preliminary (Technology Preview) feature for user authentication using external providers (IdP, identity provider) that support the OAuth 2.0 extension "Device Authorization Grant" for providing OAuth access tokens to devices without using a browser has been added.
- System roles have been expanded. For example, the network role now includes support for configuring routing rules and using the nmstate API. The logging role adds support for filtering based on regular expressions (startmsg.regex, endmsg.regex). The storage role now supports partitions with dynamically allocated space ('thin provisioning'). The sshd role can now be managed via /etc/ssh/sshd_config. The metrics role has added export capabilities for Postfix performance statistics, and the firewall role supports rewriting past configurations and enables the addition, updating, and removal of services based on their state.
- Server and system packages have been updated: chrony 4.2, unbound 1.16.2, opencryptoki 3.18.0, powerpc-utils 1.3.10, libva 2.13.0, PCP 5.3.7, Grafana 7.5.13, SystemTap 4.7, NetworkManager 1.40, samba 4.16.1.
- The package includes new versions of compilers and developer tools: GCC Toolset 12, LLVM Toolset 14.0.6, Rust Toolset 1.62, Go Toolset 1.18, Ruby 3.1, java-17-openjdk (java-11-openjdk and java-1.8.0-openjdk are still supplied), Maven 3.8, Mercurial 6.2, Node.js 18, Redis 6.2.7, Valgrind 3.19, Dyninst 12.1.0, and elfutils 0.187.
- The configuration handling of sysctl has been aligned with the directory parsing order in systemd — configuration files in the /etc/sysctl.d directory now take precedence over those in /run/sysctl.d.
- The ReaR (Relax-and-Recover) toolkit now includes the ability to execute arbitrary commands before and after recovery.
- Support for RSA keys smaller than 1023 bits has been discontinued in the NSS libraries.
- The time required to save very large sets of iptables rules with the iptables-save utility has been significantly reduced.
- The protection mode against SSBD (spec_store_bypass_disable) and STIBP (spectre_v2_user) has been switched from 'seccomp' to 'prctl', positively impacting the performance of containers and applications that limit access to system calls using the seccomp mechanism.
- Support for iWARP and RoCE protocols has been implemented in the driver for Intel E800 Ethernet adapters.
- The nfsrahead utility, which can be used to modify prefetching parameters in NFS, has been included.
- In Apache httpd settings, the LimitRequestBody parameter value has been changed from 0 (no limit) to 1 GB.
- A new package make-latest has been added, which includes the latest version of the make utility.
- Support for performance monitoring on systems with AMD Zen 2 and Zen 3 processors has been added in libpfm and papi.
- In SSSD (System Security Services Daemon), support for caching SID queries (e.g., GID/UID checks) in RAM has been added, which has sped up file copying operations over Samba. Integration with Windows Server 2022 has been ensured. server Support for the graphical API Vulkan has been added for 64-bit IBM POWER systems (ppc64le).
- Support for new AMD Radeon RX 6[345]00 and AMD Ryzen 5/7/9 6[689]00 GPUs has been implemented. Default support for Intel Alder Lake-S and Alder Lake-P GPUs has been enabled, which previously required setting the parameter i915.alpha_support=1 or i915.force_probe=*.
- The web console has added support for configuring crypto policies, the ability to download and install RHEL on a virtual machine, a button for separate installation of only kernel patches, expanded diagnostic reporting, and an option to reboot after completing updates installation.
- The web console now supports configuring cryptographic policies, enables the upload and installation of RHEL in a virtual machine, includes a button for separate installation of only Linux kernel patches, extends reports with diagnostics, and adds an option to reboot after completing updates.
- Support for the ap-check command in mdevctl has been added to configure forwarding in virtual machines access to crypto accelerators.
- Full support for the VMware ESXi hypervisor and SEV-ES (AMD Secure Encrypted Virtualization-Encrypted State) extensions has been implemented. Support for Azure cloud environments with processors based on the Ampere Altra architecture has been added.
- The toolkit for managing isolated containers has been updated, including packages such as Podman, Buildah, Skopeo, crun, and runc. Support for GitLab Runner in containers with Podman runtime has been added. The netavark utility and Aardvark DNS server are provided for configuring the container networking subsystem.
- To manage the enabling of vulnerability protection in the MMIO (Memory Mapped Input Output) mechanism, a kernel boot parameter "mmio_stale_data" has been implemented, which can accept the values "full" (enabling buffer cleanup when transitioning to user space and in VM), "full,nosmt" (like "full" + additionally disables SMT/Hyper-Threads), and "off" (protection is disabled).
- To manage the activation of the Retbleed vulnerability protection, a kernel boot parameter "retbleed" has been implemented, which allows you to disable protection ("off") or choose a vulnerability blocking algorithm (auto, nosmt, ibpb, unret).
- The kernel boot parameter acpi_sleep now supports new options for managing sleep mode transitions: s3_bios, s3_mode, s3_beep, s4_hwsig, s4_nohwsig, old_ordering, nonvs, sci_force_enable, and nobl.
- New drivers have been added for Maxlinear Ethernet GPY (mxl-gpy), Realtek 802.11ax 8852A (rtw89_8852a), Realtek 802.11ax 8852AE (rtw89_8852ae), Modem Host Interface (MHI), AMD PassThru DMA (ptdma), Cirrus Logic DSP (cs_dsp), DRM DisplayPort (drm_dp_helper), Intel® Software Defined Silicon (intel_sdsi), Intel PMT (pmt_*), and AMD SPI Master Controller (spi-amd).
- Support for the eBPF kernel subsystem has been expanded.
- The experimental (Technology Preview) support for AF_XDP, XDP hardware offloading, Multipath TCP (MPTCP), MPLS (Multi-protocol Label Switching), DSA (Data Streaming Accelerator), KTLS, dracut, kexec fast reboot, nispor, DAX in ext4 and xfs, systemd-resolved, accel-config, igc, OverlayFS, Stratis, Software Guard Extensions (SGX), NVMe/TCP, DNSSEC, and GNOME on ARM64 and IBM Z systems, AMD SEV for KVM, Intel vGPU, Toolbox has been continued.
Source: opennet.ru
