Release of Hypervisor Xen 4.21

After 8 months of development, the release of the open-source hypervisor Xen 4.21 has been published. Companies such as Amazon, Arm, EPAM Systems, and AMD participated in the development of this release. The project's code is written in C and is distributed under the GPLv2+ license. Development is carried out under the Linux Foundation organization.

Key changes in Xen 4.21:

  • Full support for the Linux stubdomain device model has been provided, allowing components to be executed for device emulation under a separate unprivileged user. The Linux stubdomains model is developed by the QUBES OS project and supports the use of emulation drivers from recent QEMU releases, as well as related features available in QEMU for guest systems.
  • Changes for x86 architecture-based systems:
    • Support for a new PDX (Page inDeX) compression algorithm has been added, which improves Xen's operation on Intel Sierra Forest and Granite Rapids processors when dealing with non-linear mapping of physical memory (sparse memory map), allowing for the presence of empty areas.
    • The ability to control the caching attribute in MTRR (Memory Type Range Registers) for the BAR (Base Address Register) of the base PCI device of the Xen platform, used by guest systems in HVM mode, has been added. By default, the caching attribute for reflected memory of PCI devices is set to UC (uncacheable), which makes sense for real PCI devices but only reduces performance for PCI devices on the Xen platform.
    • For AMD processors, a new driver amd-cppc/amd-cppc-epp has been added, managing CPU frequency changes for optimal performance. The driver utilizes the CPPC (Collaborative Processor Performance Control) mechanism, which, unlike acpi-cpufreq, is not limited to three performance levels and allows for a more responsive reaction to state changes.
    • In the xenstore-stubdom layer, used to run xenstored without privileges in Dom0, support for live updates has been implemented for paravirtualized environments in PVH mode.
    • In Dom0 in PVH mode, support for the Resizable BAR (Resizable Base Address Register) technology has been implemented, allowing immediate access to all memory of a PCI Express device, rather than only in blocks.
    • The ability to pass through PCI devices to domU environments in HVM mode (full hardware virtualization) has been implemented in configurations where dom0 operates in PVH mode (a hybrid of hardware virtualization and paravirtualization).
  • Changes for ARM architecture-based systems:
    • Support has been added for enabling the stack protection mechanism (compiled with the flag "-fstack-protector"), which is based on adding canary tags—random sequences—to the stack. In the event of a buffer overflow during vulnerability exploitation, the canary tag gets overwritten by other data, triggering the subsequent integrity check of the tag and causing the application to crash.
    • Support has been added for the eSPI (Extended Shared Peripheral Interrupts) mechanism provided by GICv3.1 interrupt controllers.
    • SMMU (System Memory Management Unit) handling has been implemented when passing through PCIe devices.
    • Support has been added for PCI host controllers used in the fourth generation of Renesas R-Car SoCs.
    • Initial support has been added for Cortex-R52 and Cortex-R82 processors with MPU (Memory Protection Unit).
  • Basic support for UART and external interrupt handling (APLIC/IMSIC) in hypervisor mode has been implemented in the Xen port for RISC-V architecture.
  • The implementation of requirements for developing safe and reliable programs in C, outlined in the MISRA-C specifications for critical systems, has continued.
  • Support for older versions of GCC and Clang has been discontinued; at least GCC 5.1, Clang 11, Binutils 2.25, and GNU Make 3.80 are now required for building.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster