After a year of development, SUSE has released the SUSE Linux Enterprise 15 SP4 distribution. Products such as SUSE Linux Enterprise Server, SUSE Linux Enterprise Desktop, SUSE Manager, and SUSE Linux Enterprise High Performance Computing are based on the SUSE Linux Enterprise platform. The distribution can be downloaded and used for free, but access to updates and patches is limited to a 60-day trial period. The release is available in builds for aarch64, ppc64le, s390x, and x86_64 architectures.
SUSE Linux Enterprise 15 SP4 fully supports binary compatibility with the community-developed distribution openSUSE Leap 15.4, which is scheduled for release tomorrow. This high level of compatibility has been achieved by using a unified set of binary packages in openSUSE and SUSE Linux Enterprise, rather than rebuilding src-packages. It is expected that users can initially create and test a working solution using openSUSE and then seamlessly switch to the commercial version of SUSE Linux with full support, SLA, certification, long-term updates, and advanced tools for mass deployment.
Key Changes:
- The Linux kernel has been updated to version 5.14.
- The desktop environment has been updated to GNOME 41 and GTK4. It is now possible to use a desktop session based on the Wayland protocol in environments with proprietary NVIDIA drivers.
- A multimedia server, Pipewire, has been added, which is currently used only for screen sharing in environments based on Wayland. PulseAudio continues to be used for audio.
- Packages with Python 2 have been removed. Only the python3 package remains.
- Updated versions include PHP 8, OpenJDK 17, Python 3.10, MariaDB 10.6, PostgreSQL 14, Apparmor 3.0, Samba 4.15, OpenSSL 3.0.1, systemd 249, QEMU 6.2, Xen 4.16, libvirt 0.8.0, and virt-manager 4.0.0.
- Live patches can now be applied to update user space components such as Glibc and OpenSSL on the fly. Fixes can be applied without restarting processes by patching the libraries in memory.
- JeOS images (minimal SUSE Linux Enterprise builds for virtualization systems) have been renamed to Minimal-VM.
- SLSA Level 4 requirements have been met to protect against malicious changes during development. The Sigstore service is used for verifying applications and container images through digital signatures, maintaining a public log for authenticity confirmation (transparency log).
- Support has been provided for managing servers with SUSE Linux Enterprise using the centralized configuration management system Salt.
- Experimental support for the schedutil CPU frequency scaling governor has been added, which makes decisions about frequency changes directly using information from the task scheduler and can immediately access cpufreq drivers for real-time frequency adjustments, adapting CPU performance parameters to current load.
- An experimental feature has been added to the wicked network configurator in SLES, allowing it to decode the SMBIOS Management Controller Host Interface structure and configure the Host Network Interface in BMC using the Redfish over IP protocol, enabling the use of Redfish for remote system management.
- Support for the Intel Alderlake graphics platform has been integrated into the i915 driver. The etnaviv driver for the Vivante GPU, used in various ARM SoCs such as NXP Layerscape LS1028A/LS1018A and NXP i.MX 8M, has been included. The etnaviv_dri library for Mesa has also been added.
- A Real-Time mode activation feature in the kernel for real-time systems has been provided by setting the preempt=full parameter during the boot of the standard SUSE Linux kernel. The separate kernel-preempt package has been removed from the distribution.
- The kernel, by default, disables the ability for unprivileged users to run eBPF programs (the /proc/sys/kernel/unprivileged_bpf_disabled parameter is set) due to the risks associated with using eBPF for system attacks. Support for the BTF (BPF Type Format) mechanism has been implemented, providing type checking information in BPF pseudocode. The BPF toolset (libbpf, bcc) has been updated, and support for the bpftrace tracing mechanism has been added.
- The ability to use 64K memory pages in Btrfs when working with a file system formatted with a block size smaller than the kernel memory page size has been provided (for example, file systems with 4KB blocks can now be used not only in kernels with the same memory page size).
- The core includes support for the SVA (Shared Virtual Addressing) mechanism, enabling the sharing of virtual addresses between CPUs and peripheral devices, allowing hardware accelerators to access data structures in the main CPU.
- Improved support for NVMe drives with the addition of features such as Centralized Discovery Controller (CDC). The nvme-cli package has been updated to version 2.0. New packages libnvme 1.0 and nvme-stas 1.0 have been added.
- Official support for swap space on the zRAM block device has been provided, allowing data to be stored in memory in a compressed format.
- Support for NVIDIA vGPU versions 12 and 13 has been added.
- A universal driver, simpledrm, is introduced instead of the fbdev drivers used for framebuffer output, which utilizes the EFI-GOP or VESA output provided by UEFI firmware or BIOS.
- The OpenSSL 3.0 cryptographic library is included alongside the version used in system applications, OpenSSL 1.1.1.
- YaST has improved network disk booting, configurable via the '_netdev' option.
- The BlueZ Bluetooth stack has been updated to version 5.62. High-quality audio codecs for Bluetooth have been added to the pulseaudio package.
- Automatic conversion of System V init.d scripts to systemd services has been included via systemd-sysv-generator. In the next major branch of SUSE, support for init.d scripts will be completely discontinued, and conversion will be disabled.
- Support for a wider range of ARM SoCs has been expanded in the ARM builds.
- Support for AMD SEV technology has been added, providing hardware-level transparent memory encryption. of virtual machines (Only the current guest system has access to the decrypted data, while other virtual machines and the hypervisor receive the encrypted dataset when attempting to access this memory).
- The NTP server chrony now supports precise time synchronization based on the NTS (Network Time Security) protocol, which uses public key infrastructure (PKI) elements and allows the use of TLS and authenticated encryption AEAD (Authenticated Encryption with Associated Data) for cryptographic protection of client-server interactions over the NTP (Network Time Protocol).
- The primary LDAP server used is 389 Directory Server. Support for the OpenLDAP server has been discontinued.
- The tools for working with LXC containers (libvirt-lxc and virt-sandbox) have been removed.
- A new minimal version of the Base Container Image (BCI) is proposed, which includes the busybox package instead of bash and coreutils. The image is designed for running applications in containers that have been pre-built with all dependencies. BCI containers for Rust and Ruby have been added.
Source: opennet.ru
