Release of Xen Hypervisor 4.15

After eight months of development, the release of the open-source Xen Hypervisor 4.15 has been published. Companies such as Amazon, Arm, Bitdefender, Citrix, and EPAM Systems participated in the development of this release. Updates for the Xen 4.15 branch will continue until October 8, 2022, while vulnerability fixes will be published until April 8, 2024.

Key changes in Xen 4.15:

  • Experimental support for live patches has been implemented in the Xenstored and oxenstored processes, allowing vulnerabilities to be delivered and applied without restarting the host environment.
  • Support for unified boot images has been added, enabling the creation of system images that include Xen components. Such images are formatted as a single binary file for EFI, which can be used to boot an operational Xen system directly from the EFI boot manager without intermediary loaders like GRUB. The image includes Xen components such as the hypervisor, kernel for the host environment (dom0), initrd, Xen KConfig, XSM settings, and Device Tree.
  • For the ARM platform, experimental support for running device models on the dom0 host system has been implemented, allowing arbitrary hardware devices to be emulated for guest systems based on the ARM architecture. Support for SMMUv3 (System Memory Management Unit) has also been implemented for ARM, enhancing the security and reliability of device passthrough on ARM systems.
  • The ability to use the hardware tracing mechanism IPT (Intel Processor Trace), available starting with Intel Broadwell CPUs, has been added to export data from guest systems to debugging tools running on the host system. For example, VMI Kernel Fuzzer or DRAKVUF Sandbox can be utilized.
  • Support for Viridian environments (Hyper-V) has been added for running Windows guest systems using more than 64 VCPUs.
  • The PV Shim layer has been modernized, used to run unmodified paravirtualized guest systems (PV) in PVH and HVM environments (ensuring the operation of older guest systems in more secure environments that provide stricter isolation). In the new version, support for running PV guest systems in environments supporting only HVM mode has been improved. The size of the shim has been reduced by cutting down on HVM-specific code.
  • The capabilities of VirtIO drivers on ARM systems have been expanded. An implementation of IOREQ has been proposed for ARM systems, which is planned to be used to enhance input/output virtualization utilizing VirtIO protocols. A reference implementation of the VirtIO block device for ARM has been added, allowing the transmission of VirtIO block devices to guest systems based on the ARM architecture. Support for PCIe virtualization for ARM is being incorporated. server Work is ongoing to implement a port of Xen for RISC-V processors. Currently, there is development underway for code to manage virtual memory on both the host and guest systems, as well as the creation of architecture-specific code for RISC-V.
  • In collaboration with the Zephyr project, based on the MISRA_C standard, a set of requirements and guidelines is being developed to reduce the risks of security issues. Static analyzers are being used to identify discrepancies with the established rules.
  • The Hyperlaunch initiative has been introduced, aimed at providing flexible tools for configuring the launch of a static set during system boot. The initiative proposes the domB (boot domain, dom0less) concept, allowing for the deployment of virtual machines at an early stage of server boot without the need for a dom0 environment.
  • Continuous integration has been implemented to test Xen on Alpine Linux and Ubuntu 20.04. Testing on CentOS 6 has been discontinued. Tests for dom0/domU based on QEMU have been added to the continuous integration environment for ARM. of virtual machines The release of the Sway 1.6 user environment, which uses Wayland, has been announced.
  • An initiative has been launched to develop open projects for FPGA.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster