Oracle Linux 9 and Unbreakable Enterprise Kernel 7 are now available.

Oracle has released stable versions of the Oracle Linux 9 distribution and the Unbreakable Enterprise Kernel 7 (UEK R7), aimed at providing an alternative to the default kernel package from Red Hat Enterprise Linux. Oracle Linux 9 is based on the package foundation of Red Hat Enterprise Linux 9 and is fully binary compatible with it.

Installation ISO images of 8.6 GB and 840 MB are available for download without restrictions, prepared for the x86_64 and ARM64 (aarch64) architectures. Oracle Linux 9 offers unlimited and free access to a yum repository with binary updates for packages addressing errors (errata) and security issues. Additionally, separate supported repositories for Application Stream and CodeReady Builder package sets have been prepared for download.

In addition to the kernel package from RHEL (based on kernel 5.14), Oracle Linux offers its own Unbreakable Enterprise Kernel 7, based on Linux kernel 5.15 and optimized for use with Oracle's industrial software and hardware. The source code of the kernel, including separate patch breakdowns, is available in Oracle's public Git repository. The Unbreakable Enterprise Kernel is installed by default, positioned as an alternative to the RHEL kernel package, and provides a range of enhanced features, such as DTrace integration and improved Btrfs support. Besides the additional kernel, the releases of Oracle Linux 9 and RHEL 9 are completely identical in functionality (the change log can be viewed in the RHEL9 announcement).

Key innovations in the Unbreakable Enterprise Kernel 7 include:

  • Improved support for the Aarch64 architecture. The default memory page size for 64-bit ARM systems has been reduced from 64 KB to 4 KB, which better aligns with the memory volumes and workloads typical for ARM systems.
  • The delivery of DTrace 2.0 dynamic debugging system has continued, which has been transitioned to use the eBPF kernel subsystem. DTrace 2.0 operates on top of eBPF, similar to how existing tracing tools in Linux operate with eBPF.
  • The capabilities of Btrfs have been expanded. An asynchronous implementation of the DISCARD operation has been added to Btrfs to mark freed blocks that no longer need to be physically stored. This asynchronous implementation enables the operation to be performed in the background without waiting for the storage device to complete the DISCARD. New mount options have been added to simplify data recovery from damaged filesystems: 'rescue=ignorebadroots' to mount despite damage to certain root trees (extent, uuid, data reloc, device, csum, free space), 'rescue=ignoredatacsums' to disable checksum verification for data, and 'rescue=all' to enable 'ignorebadroots', 'ignoredatacsums', and 'nologreplay' modes simultaneously. Significant performance optimizations have been made related to fsync() operations. Support for fs-verity (file authenticity and integrity checks) and user ID mapping has been added.
  • XFS now supports DAX operations for direct filesystem access bypassing the page cache to avoid double caching. Changes have been implemented to address the 32-bit time_t overflow issue in 2038, including the introduction of new mount options bigtime and inobtcount.
  • Improvements have been made to the OCFS2 (Oracle Cluster File System).
  • A new filesystem, ZoneFS, has been added to facilitate low-level operations with zoned storage devices. Zoned storage refers to devices on hard magnetic disks or NVMe SSDs where the storage space is divided into zones that consist of groups of blocks or sectors, allowing only sequential data additions with complete updates to the entire block group. The ZoneFS filesystem links each zone on the storage device to a separate file that can be used for raw data storage without manipulating on the sector and block level, allowing applications to use the file API instead of directly accessing the block device via ioctl.
  • Protocol support has been stabilized. VPN WireGuard.
  • The capabilities of the eBPF subsystem have been expanded. The CO-RE (Compile Once — Run Everywhere) mechanism has been implemented, which addresses the portability issue of compiled eBPF programs and allows eBPF program code to be compiled only once and utilized with a special universal loader that adapts the loaded program to the current kernel and BTF (BPF Type Format) types. A 'BPF trampoline' mechanism has been added, allowing for minimal overhead when passing calls between the kernel and BPF programs. Direct access to kernel functionality from BPF programs and the suspension of the handler has been provided.
  • A detector for split locks has been integrated, which occurs when accessing unaligned data in memory because, during the execution of an atomic instruction, the data spans two CPU cache lines. The kernel can dynamically identify such locks, which lead to significant performance degradation, and issue warnings or send a SIGBUS signal to the application that caused the lock.
  • Support for Multipath TCP (MPTCP) has been provided, an extension of the TCP protocol for establishing TCP connections that deliver packets simultaneously over multiple routes through different network interfaces linked to distinct IP addresses.
  • A SCHED_CORE scheduling mode has been implemented in the task scheduler, allowing control over which processes can run concurrently on a single CPU core. Each process can be assigned a cookie identifier that defines a trust domain among processes (e.g., belonging to the same user or container). When organizing code execution, the scheduler can ensure that a single CPU core is only shared among processes related to one owner, which can be used to block certain Spectre-class attacks by preventing the execution of both trusted and untrusted tasks within the same SMT (Hyper-Threading) thread.
  • A slab memory controller has been implemented for cgroups, noteworthy for transferring slab accounting from the memory page level to the kernel object level, allowing slab pages to be shared across different cgroups instead of allocating separate slab caches for each cgroup. This approach can increase slab usage efficiency and reduce the size of memory used for slabs by 30-45%, significantly decrease the overall memory consumption by the kernel, and reduce memory fragmentation.
  • Debug data is provided in the CTF (Compact Type Format), which ensures compact storage of information about C types, relationships between functions, and debug symbols.
  • The provision of the DRBD (Distributed Replicated Block Device) module and the device /dev/raw has been discontinued (for direct file access, use the O_DIRECT flag).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster