Microsoft has released the Azure Linux distribution 3.0.20241101.

Microsoft has released an update for the Azure Linux distribution 3.0.20241101, continuing the development of the stable branch 3.0 established in August. The distribution serves as a universal base platform for Linux environments used in cloud infrastructure, edge systems, and various Microsoft services. The project's developments are licensed under the MIT license. Package builds are created for aarch64 and x86_64 architectures. The size of the installation image is 751 MB.

Among the changes in the new version:

  • Support for the FF-A (Firmware Framework for Arm A-profile) specification has been added for ARM-based systems.
  • The intel_ifs (In-Field Scan) kernel module has been included, allowing low-level CPU diagnostic tests on Intel processors that can detect issues not identified by standard error correction code (ECC) tools or parity bits.
  • SBAT entries for Fedora Linux have been added to the GRUB2 bootloader.
  • During the kernel build, the CONFIG_X86_AMD_PLATFORM_DEVICE setting has been enabled, which processes AMD chip-specific ACPI devices as standard platform devices such as I2C, UART, and GPIO.
  • Iptables commands are now operational through the translation of rules into nftables bytecode (in addition to iptables-legacy, the iptables-nft package is utilized).
  • Package versions have been updated, including Linux kernel 6.6.57, Go 1.23, OpenIPMI 2.0.36, libpcap 1.10.5, vim 9.1.0791, mysql 8.0.40, clamav 1.0.7, cloud-init 24.3.1, php 8.3.12, mdadm 4.3, and libarchive 3.7.7.

The Azure Linux distribution provides a small standardized set of core packages that serve as a universal foundation for building container images, host environments, and services that run in cloud infrastructures and on edge devices. More complex and specialized solutions can be created by adding additional packages on top of Azure Linux, but the base for all such systems remains unchanged, simplifying maintenance and update preparation.

Azure Linux serves as the base for the mini-distribution WSLg, which provides components of the graphical stack to run Linux GUI applications in WSL2 (Windows Subsystem for Linux) environments. Extended functionality in WSLg is achieved by enabling additional packages with composite. proxy server Weston, XWayland, PulseAudio, and FreeRDP.

The system manager systemd is used for managing services and load. Package managers RPM and DNF are provided for package management. By default, the SSH server is not enabled. An installer is provided for installing the distribution, which can work in both text and graphical modes. The installer allows the installation of either a full or a minimal set of packages, offers an interface for selecting the disk partition, choosing the hostname, and creating users.

The Azure Linux build system enables the generation of both separate RPM packages based on SPEC files and source texts, as well as monolithic system images created with the rpm-ostree tool, which can be updated atomically without breaking them into individual packages. Accordingly, two models for delivering updates are supported: through updating individual packages and through rebuilding and updating the entire system image. A repository containing approximately 3000 already built RPM packages is available, which can be used to assemble custom images based on a configuration file.

The base platform includes only the most essential components and is optimized for minimal memory and disk space usage, as well as for high boot speed. The project employs a 'maximum security by default' approach, which implies the inclusion of various additional mechanisms to enhance protection:

  • Filtering of system calls using the seccomp mechanism.
  • Encryption of disk partitions.
  • Verification of packages by digital signature.
  • Address space randomization.
  • Protection against attacks related to symbolic links, mmap, /dev/mem, and /dev/kmem.
  • Read-only mode and prohibition of code execution in areas of memory where kernel and module data segments are located.
  • Option to prohibit the loading of kernel modules after system initialization.
  • Using iptables for network packet filtering.
  • Enabling protection modes against stack overflow, buffer overflows, and string format issues (_FORTIFY_SOURCE, -fstack-protector, -Wformat-security, relro) during the build.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster