Release of the NetBSD 9.0 operating system

Available significant release of the operating system NetBSD 9.0, featuring yet another set of new features. Available for download are are prepared installation images sized at 470 MB. NetBSD 9.0 is officially available in builds for 57 system architectures and 15 different CPU families.

Eight primarily supported ports are highlighted, forming the core of NetBSD's development strategy: amd64, i386, evbarm, evbmips, evbppc, hpcarm, sparc64, and xen. 49 ports related to CPUs such as alpha, hppa, m68010, m68k, sh3, sparc, and vax are classified as second tier, meaning they are still supported but have become outdated or lack sufficient developer interest for further development. One port (acorn26) is included in the third category, which houses non-functional ports that are candidates for removal unless enthusiasts show interest in their development.

Key improvements NetBSD 9.0:

  • A new hypervisor has been added NVMM, supporting hardware virtualization mechanisms SVM for AMD CPUs and VMX for Intel CPUs. A distinctive feature of NVMM is that only the minimal necessary layer of wrappers around the hardware virtualization mechanisms operates at the kernel level, while all device emulation code is moved from the kernel to user space. Tools based on the libnvmm library have been prepared for managing virtual machines, as well as the qemu-nvmm package for running guest systems using NVMM. The libnvmm API covers functions such as creating and starting a virtual machine, allocating memory to the guest system, and distributing VCPU. Notably, libnvmm does not contain emulator functions but merely provides an API for integrating NVMM support into existing emulators, such as QEMU;
  • Support for the 64-bit AArch64 architecture (ARMv8-A) has been ensured, including server systems that meet the ARM ServerReady (SBBR+SBSA) standards, and big.LITTLE systems (a combination of powerful but energy-consuming cores and less powerful yet more energy-efficient cores within a single chip). Execution of 32-bit applications in a 64-bit environment is supported via COMPAT_NETBSD32. Up to 256 CPUs can be used. Support for operation in the QEMU emulator and SoC is provided for:
    • Allwinner A64, H5, H6
    • Amlogic S905, S805X, S905D, S905W, S905X
    • Broadcom BCM2837
    • NVIDIA Tegra X1 (T210)
    • Rockchip RK3328, RK3399
    • Server boards SBSA/SBBR, such as Amazon Graviton, Graviton2, AMD Opteron A1100, Ampere eMAG 8180, Cavium ThunderX, and Marvell ARMADA 8040.
  • Extended support for devices based on the ARMv7-A architecture. Added support for big.LITTLE systems and booting via UEFI. Up to 8 CPUs can be used. Added support for SoC:
    • Allwinner A10, A13, A20, A31, A80, A83T, GR8, H3, R8
    • Amlogic S805
    • Arm Versatile Express V2P-CA15
    • Broadcom BCM2836, BCM2837
    • Intel Cyclone V SoC FPGA
    • NVIDIA Tegra K1 (T124)
    • Samsung Exynos 5422
    • TI AM335x, OMAP3
    • Xilinx Zynq 7000
  • Updated graphics drivers for Intel GPUs (added support for Intel Kabylake), NVIDIA, and AMD for x86 systems. The DRM/KMS subsystem is synchronized with the Linux kernel 4.4. New drivers for GPUs used on ARM systems have been added, including DRM/KMS drivers for Allwinner DE2, Rockchip VOP, and TI AM335x LCDC, framebuffer driver for ARM PrimeCell PL111, and TI OMAP3 DSS;
  • Improved support for running NetBSD as a guest OS. Added support for fw_cfg device (QEMU Firmware Configuration), Virtio MMIO, and PCI for ARM. HyperV support for x86 has been ensured;
  • Performance monitoring counters have been implemented, allowing real-time analysis of kernel and user application performance. Management is done via the tprof command. Supported platforms include Armv7, Armv8, and x86 (AMD and Intel);
  • For the x86_64 architecture implemented the Kernel Address Space Layout Randomization (KASLR) mechanism, which increases resilience against certain types of attacks exploiting vulnerabilities in the kernel by forming a random layout of kernel code in memory at each boot;
  • Support has been added for the x86_64 architecture KLEAK, a technique for detecting kernel memory leaks that allowed for the identification and correction of more than 25 errors in the kernel;
  • For x86_64 and Aarch64 architectures, the KASan (Kernel Address Sanitizer) debugging mechanism has been implemented, allowing detection of memory operation errors, such as access to already freed memory blocks and buffer overflows;
  • The KUBSAN (Kernel Undefined Behavior Sanitizer) mechanism has been added to detect cases of undefined behavior in the kernel
  • For the x86_64 architecture, the KCOV (Kernel Coverage) driver has been implemented to analyze code coverage in the kernel;
  • A Userland Sanitizer has been added to detect errors and anomalies during the execution of applications in user space;
  • The KHH (Kernel Heap Hardening) mechanism has been added to protect the heap from certain types of memory operation errors;
  • An audit of the network stack has been conducted; Improved ptrace debugging tools;
  • The debugging tool ptrace has been improved.
  • The core has been cleaned of old and unsupported subsystems such as NETISDN (drivers daic, iavc, ifpci, ifritz, iwic, isic), NETNATM, NDIS, SVR3, SVR4, n8, vm86, and ipkdb;
  • The capabilities have been expanded and the performance of the packet filter has been optimized. NPF, which is now enabled by default;
  • The implementation of the ZFS file system has been updated to a state suitable for everyday use. Booting from ZFS and using ZFS on the root partition is not yet supported;
  • New drivers have been added, including bwfm for Broadcom wireless devices (Full-MAC), ena for Amazon Elastic Network Adapter, and mcx for Mellanox ConnectX-4 Lx EN, ConnectX-4 EN, ConnectX-5 EN, ConnectX-6 EN Ethernet adapters;
  • The SATA subsystem has been redesigned to support NCQ and improve error handling from the storage device;
  • A new usbnet framework for creating drivers for USB interface Ethernet adapters has been proposed;
  • Updated versions of third-party components, including GCC 7.4, GDB 8.3, LLVM 7.0.0, OpenSSL 1.1.1d, OpenSSH 8.0, and SQLite 3.26.0.

    Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster