Following the new branch of RHEL 10, Red Hat has released the Red Hat Enterprise Linux 9.6 distribution. Ready-to-use installation images are available for registered users of the Red Hat Customer Portal (functional evaluation can also use the iso images of CentOS Stream 9 and free RHEL developer builds). The release has been built for x86_64, s390x (IBM System z), ppc64le, and Aarch64 (ARM64) architectures. In accordance with the 10-year support cycle, RHEL 9 will be supported until 2032.
The source texts of the RHEL 9.6 rpm packages are provided to company clients only through a restricted section of the website, where a user agreement (EULA) is in effect that prohibits the redistribution of data, preventing these packages from being used to create derivative distributions. The source texts remain available in the CentOS Stream repository, but it is not fully synchronized with RHEL, and the package versions do not always match those from RHEL. Rocky Linux, Oracle, and SUSE reproduce the source texts of RHEL rpm package releases as part of the OpenELA project.
Key changes in RHEL 9.6:
- Updated developer packages: GCC 11.5, Node.js 22, mysql 8.4, PHP 8.3, GDB 14.2, Valgrind 3.24.0, SystemTap 5.2, elfutils 0.192, libabigail 2.6, GCC Toolset 14, LLVM Toolset 19.1.7, Rust Toolset 1.84.1, Go Toolset 1.23, Maven 3.9, Git 2.47.1.
- Updated system package versions: Rsyslog 8.2412.0, OpenSSL 3.2.2, NSS 3.101, nettle 3.10.1, OpenSCAP 1.3.12, Clevis 21, openCryptoki 3.24.0, libva 2.22.0, Buildah 1.39.0, Skopeo 1.18.0, Podman 5.4, NetworkManager 1.52.0, QEMU 9.1.0, libvirt 10.10.0.
- Updated server packages: Apache httpd 2.4.62, nginx 1.26, wpa_supplicant 2.11, xdp-tools 1.5.1, iproute2 6.11.0, PCP 6.3.2, Grafana 10.2.6, 389-ds-base 2.6.1, openldap 2.6.8.
- Support for the Landlock module has been added, which provides unprivileged programs with the means to restrict the use of Linux kernel objects, such as file hierarchies, network sockets, and ioctl. Unlike namespaces and system call filtering, the isolated environment is formed by the Linux kernel in the form of an additional layer over existing access control mechanisms.
- Support for the EROFS (Extendable Read-Only File System) has been added, designed for use on partitions accessible in read-only mode.
- A new snapm (Snapshot Manager) utility has been added to manage system state snapshots (for example, in case of issues after an update installation, the system can be rolled back to a previous state).
- For new users created through the Anaconda installer interface, administrator privileges are provided by default (there's a specific setting available to disable this behavior). The installer also features a new interface for selecting the time zone. The RDP protocol is used for remote access to the installer instead of VNC.
- The linker ld now provides warnings if an application uses a stack located in a region of memory that allows code execution.
- TLS support has been added for encrypting administrative RPC traffic in the NFS network file system.
- Support for Unified Kernel Images (UKI) generated in the distribution's infrastructure and signed with the distribution's digital signature has been stabilized. The UKI image combines in a single file the handler for loading the kernel from UEFI (UEFI boot stub), the Linux kernel image, and the initial RAM disk environment initrd. When invoking the UKI image from UEFI, integrity and authenticity verification is possible not only for the kernel but also for the contents of initrd, whose authenticity is crucial, since key extraction for decrypting the root filesystem is performed in this environment.
- Support for the Composefs file system has been added.
- The CIFS (Common Internet File System) client has been enhanced to create special files in SMB shares, such as symbolic links, Unix sockets, and named pipes.
- The toolkit for creating custom boot images has been expanded. It now supports creating disk images with a custom partition layout and mounting options. There is also the ability to substitute Kickstart files when building ISO images. For disk images in systems like AWS and KVM, the creation of a separate /boot partition has been removed.
- System roles have been added for managing and configuring sudo, tracking file changes using the aide package, and managing user unit files in systemd. The metric role has been enhanced to use the Valkey database instead of Redis.
- The OpenTelemetry framework is now available for collecting and sending logs and telemetry data to analytics systems, such as AWS CloudWatch.
- A new utility, keylime-policy, has been added to manage Keylime policies for authentication and continuous integrity monitoring of external systems.
- The services iio-sensor-proxy, power-profiles-daemon, switcheroo-control, and samba-bgqd have been transitioned under SELinux protection. Support for executing commands under SELinux protection via the QEMU Guest Agent has also been added.
- The implementation of the eBPF subsystem is synchronized with the Linux kernel 6.12 (in the previous release, the eBPF implementation from the Linux kernel 6.8 was used). The implementation of TPM_TIS (Trusted Platform Module Integration Services) is synchronized with kernel 6.7, while kdump is synchronized with kernel 6.10.
- The Ethernet driver ice has added support for the E825C network interface, used in the Intel Granite Rapids-D platform.
- NetworkManager has added support for FEC (Forward Error Correction) mode. Automatic addition of routes to DNS servers has been implemented using the properties 'ipv4.routed-dns' and 'ipv6.routed-dns'. The sending of the hostname via DHCP has been disabled by default (the ipv4.dhcp-send-hostname parameter is set to false). Support for the DHCPv4 option 'IPv6-only preferred' (RFC 8925) has been added, indicating that the host can operate without IPv4 and only needs to transmit an IPv6 address if the network supports IPv6. The nmstate utility has added the ability to configure IPvLAN.
- Support ensured of virtual machines in systems with a realtime kernel.
- For host systems using ARM64 processors, support for migrating virtual machines between ARM64 hosts has been added, a virtualized TPM (Trusted Platform Module) interface has been implemented, and the virtio-iommu device has been realized.
- The virt-install utility has added support for creating virtual machines using AMD SEV-SNP (Secure Encrypted Virtualization - Secure Nested Paging) for memory encryption.
- Support for Intel TDX (Trust Domain Extension) technology for protecting guest systems has been added.
- Support for migrating virtual machines that use virtiofs for sharing directories or virtual functions of Mellanox CX-7 network adapters has been added.
- Drivers for Intel XMM 7360 LTE Advanced modems (Intel IOSM - IPC over Shared Memory), Fibocom FM350GL (Mediatek t7xx), Fibocom L860GL (Intel IOSM), and Qualcomm have been added.
- Experimental support (Technology Preview) for encrypting DNS traffic using DNS-over-TLS (DoT) has been added.
- Continued provision of experimental (Technology Preview) support:
- kTLS (TLS at the kernel level),
- asynchronous I/O interface io_uring,
- DAX (Direct Access) for ext4 and XFS,
- AMD SEV and SEV-ES in the KVM hypervisor,
- systemd-resolved service,
- the Sigstore mechanism for container verification via digital signatures,
- VPN WireGuard,
- PRP (Parallel Redundancy Protocol) and HSR (High-availability Seamless Redundancy) protocols,
- hardware acceleration of IPsec by offloading packet encapsulation operations to the network card,
- the ACME certificate management protocol used in Let's Encrypt,
- SRv6 (Segment Routing over IPv6)
- package with the GIMP image editor 2.99.8,
- MPTCP (Multipath TCP) settings via NetworkManager,
- DNSSEC in IdM,
- virtio-mem,
- Socket API for TuneD,
- Soft-iWARP (Internet Wide-area RDMA Protocol),
- GNOME for ARM64 and IBM Z.
Source: opennet.ru
