Microsoft has released the Azure Linux 3.0.20260506 distribution.

Microsoft has released a monthly update for the Azure Linux distribution 3.0.20260506. This distribution is being developed as a universal base platform for Linux environments used in cloud infrastructure, edge systems, and various Microsoft services. The project’s own developments are distributed under the MIT license. Package builds are created for the aarch64 and x86_64 architectures. The installation image size is 770 MB.

Among the changes in the new version:

  • Packages ignition and rust-afterburn have been added to the repository (SPECS and SPECS-EXTENDED).
  • The network analyzer package Wireshark has been rebuilt with Lua language support.
  • When building the kernel package for the arm64 architecture, the CONFIG_IKCONFIG_PROC option has been enabled, allowing access to the current kernel's build configuration through the file /proc/config.gz.
  • Support for live migration in QEMU has been improved.
  • The PackageBuild.yml file has been updated to include the extraMacrosFiles parameter for passing additional macro files during package building.
  • Several dozen vulnerabilities in various packages have been fixed.
  • Updated versions of Linux kernel 6.6.137.1, clamav 1.5.2, cloud-hypervisor 51.1.56, containerd2 2.1.6, cups 2.4.18, erlang 26.2.5.20, golang 1.26.2-1, libpng 1.6.57, mysql 8.0.46.

The Azure Linux distribution provides a small standardized set of core packages that serve as a universal foundation for building container images, host environments, and services that run in cloud infrastructures and on edge devices. More complex and specialized solutions can be created by adding additional packages on top of Azure Linux, but the base for all such systems remains unchanged, simplifying maintenance and update preparation.

Azure Linux is used as the base for the mini-distribution WSLg, which provides components of the graphical stack for running Linux GUI applications in environments based on the WSL2 (Windows Subsystem for Linux). Enhanced functionality in WSLg is implemented by including additional packages with the composite server Weston, XWayland, PulseAudio, and FreeRDP.

The system manager systemd is used for managing services and load. Package managers RPM and DNF are provided for package management. By default, the SSH server is not enabled. An installer is provided for installing the distribution, which can work in both text and graphical modes. The installer allows the installation of either a full or a minimal set of packages, offers an interface for selecting the disk partition, choosing the hostname, and creating users.

The Azure Linux build system enables the generation of both separate RPM packages based on SPEC files and source texts, as well as monolithic system images created with the rpm-ostree tool, which can be updated atomically without breaking them into individual packages. Accordingly, two models for delivering updates are supported: through updating individual packages and through rebuilding and updating the entire system image. A repository containing approximately 3000 already built RPM packages is available, which can be used to assemble custom images based on a configuration file.

The base platform includes only the most essential components and is optimized for minimal memory and disk space usage, as well as for high boot speed. The project employs a 'maximum security by default' approach, which implies the inclusion of various additional mechanisms to enhance protection:

  • Filtering of system calls using the seccomp mechanism.
  • Encryption of disk partitions.
  • Verification of packages by digital signature.
  • Address space randomization.
  • Protection against attacks related to symbolic links, mmap, /dev/mem, and /dev/kmem.
  • Read-only mode and prohibition of code execution in areas of memory where kernel and module data segments are located.
  • Option to prohibit the loading of kernel modules after system initialization.
  • Using iptables for network packet filtering.
  • Enabling protection modes against stack overflow, buffer overflows, and string format issues (_FORTIFY_SOURCE, -fstack-protector, -Wformat-security, relro) during the build.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster