The CentOS Stream 9 distribution has been officially presented.

The CentOS project has officially announced the availability of the CentOS Stream 9 distribution, which serves as the foundation for the development of Red Hat Enterprise Linux 9 within a new, more open development process. CentOS Stream is categorized as a continuously updated distribution and allows earlier access to packages being developed for future RHEL releases. Builds are prepared for x86_64, Aarch64, and ppc64le (IBM Power 9+) architectures. Additionally, support for the IBM Z architecture (s390x Z14+) has been declared, but builds for it are not yet available.

CentOS Stream is positioned as the upstream project for RHEL, providing external participants the opportunity to oversee the preparation of packages for RHEL, propose changes, and influence decision-making. Previously, a snapshot from one of the Fedora releases was used as the basis for a new RHEL branch, which was refined and stabilized behind closed doors, without the ability to monitor the development process and decision-making. In the process of developing RHEL 9, based on the snapshot of Fedora 34 and with community involvement, the CentOS Stream 9 branch was formed, which involves preparatory work and lays the groundwork for a new significant RHEL branch.

The CentOS Stream 9 distribution has been officially presented.

It is noted that the same updates prepared for the yet-to-be-released upcoming RHEL point release are published for CentOS Stream, with the primary goal of developers being to achieve a level of stability for CentOS Stream equivalent to that of RHEL. Before a package is offered in CentOS Stream, it undergoes various automated and manual testing systems, and is published only if its level of stability is deemed to meet the quality standards for packages ready for publication in RHEL. Simultaneously with CentOS Stream, prepared updates are included in nightly RHEL builds.

Key changes in CentOS Stream 9 compared to the previous significant branch:

  • The system environment and build tools have been updated. GCC 11 is used for building packages. The standard C library has been upgraded to glibc 2.34. The Linux kernel package is based on the 5.14 release. The RPM package manager has been updated to version 4.16, which includes integrity checking support through fapolicyd.
  • The migration of the distribution to Python 3 has been completed. The default branch proposed is Python 3.9. Python 2 is no longer supplied.
  • The desktop is based on GNOME 40 (RHEL 8 shipped with GNOME 3.28) and the GTK 4 library. In GNOME 40, virtual desktops in the Activities Overview are transitioned to a horizontal layout, displayed as a continuously scrollable chain from left to right. Each desktop shown in the overview clearly presents the open windows, which employ dynamic panning and scaling during user interaction. Seamless transitioning is provided between the application list and virtual desktops.
  • GNOME utilizes the power-profiles-daemon handler, enabling on-the-fly switching between power-saving mode, balanced power consumption mode, and maximum performance mode.
  • All audio streams have been transitioned to the PipeWire multimedia server, which is now used by default instead of PulseAudio and JACK. The use of PipeWire allows the typical desktop edition to offer capabilities for professional audio processing, eliminate fragmentation, and unify the audio infrastructure for various applications.
  • By default, the GRUB boot menu is hidden if RHEL is the only distribution installed on the system and if the last boot was successful. To display the menu during boot, simply hold down the Shift key or press the Esc or F8 key multiple times. Changes in the bootloader also include the placement of GRUB configuration files for all architectures in one directory /boot/grub2/ (the file /boot/efi/EFI/redhat/grub.cfg is now a symbolic link to /boot/grub2/grub.cfg), meaning the same installed system can be booted using either EFI or BIOS.
  • Components supporting various languages have been separated into langpacks, allowing for varying levels of installed language support. For example, the langpacks-core-font package offers only fonts, langpacks-core includes the locale for glibc, the basic font, and input methods, while langpacks provide translations, additional fonts, and spell-checking dictionaries.
  • Components have been updated for security purposes. A new branch of the OpenSSL 3.0 cryptographic library has been implemented in the distribution. More modern and reliable cryptographic algorithms are enabled by default (for example, the use of SHA-1 in TLS, DTLS, SSH, IKEv2, and Kerberos is prohibited, and support for TLS 1.0, TLS 1.1, DTLS 1.0, RC4, Camellia, DSA, 3DES, and FFDHE-1024 has been disabled). The OpenSSH package has been updated to version 8.6p1. Cyrus SASL has switched to the GDBM backend instead of Berkeley DB. Support for the DBM (Berkeley DB) format has been discontinued in the NSS (Network Security Services) libraries. GnuTLS has been updated to version 3.7.2.
  • SELinux performance has been significantly improved, and memory consumption has been reduced. Support for the configuration "SELINUX=disabled" to disable SELinux has been removed from /etc/selinux/config (this configuration now only disables the loading of policies, and to actually disable SELinux functionality, the kernel parameter "selinux=0" must now be passed).
  • Experimental support has been added for VPN WireGuard.
  • SSH login as the root user is disabled by default.
  • The iptables-nft firewall management tools (the iptables, ip6tables, ebtables, and arptables utilities) and ipset have been deprecated. It is now recommended to use nftables for firewall management.
  • A new mptcpd daemon has been included for configuring MPTCP (MultiPath TCP), an extension of TCP protocol for establishing TCP connections with packet delivery over multiple routes through different network interfaces bound to different IP addresses. Using mptcpd allows MPTCP configuration without the usage of the iproute2 utility.
  • The network-scripts package has been removed; NetworkManager should be used for configuring network connections. Support for ifcfg configuration format has been retained, but NetworkManager now uses the keyfile-based format by default.
  • New versions of compilers and developer tools are included: GCC 11.2, LLVM/Clang 12.0.1, Rust 1.54, Go 1.16.6, Node.js 16, OpenJDK 17, Perl 5.32, PHP 8.0, Python 3.9, Ruby 3.0, Git 2.31, Subversion 1.14, binutils 2.35, CMake 3.20.2, Maven 3.6, Ant 1.10.
  • Server packages have been updated: Apache HTTP Server 2.4.48, nginx 1.20, Varnish Cache 6.5, Squid 5.1.
  • Database management systems MariaDB 10.5, MySQL 8.0, PostgreSQL 13, Redis 6.2 have been updated.
  • By default, Clang is used to build the QEMU emulator, which has allowed the KVM hypervisor to implement additional protection mechanisms, such as SafeStack to protect against return-oriented programming (ROP) exploitation methods.
  • In SSSD (System Security Services Daemon), log detail has been enhanced; for instance, completion times are now attached to events, reflecting the authentication stream. Search functions have been added for analyzing configuration and performance issues.
  • Support for IMA (Integrity Measurement Architecture) has been expanded to verify the integrity of operating system components through digital signatures and hashes.
  • A unified cgroup (cgroup v2) hierarchy is enabled by default. Cgroups v2 can be used, for example, to limit memory, CPU, and I/O usage. The key difference between cgroups v2 and v1 is the implementation of a single cgroup hierarchy for all resource types, rather than separate hierarchies for CPU distribution, memory consumption, and I/O. The separate hierarchies led to difficulties in coordinating interactions between handlers and additional kernel resource overhead when applying rules for processes mentioned across different hierarchies.
  • Support for precise time synchronization based on the NTS (Network Time Security) protocol has been added, which utilizes public key infrastructure (PKI) elements and allows for TLS and authenticated encryption AEAD (Authenticated Encryption with Associated Data) to cryptographically secure the interaction between the client and server using NTP (Network Time Protocol). The NTP server chrony has been updated to version 4.1.
  • Experimental support has been provided for KTLS (kernel-level implementation of TLS), Intel SGX (Software Guard Extensions), DAX (Direct Access) for ext4 and XFS, and support for AMD SEV and SEV-ES in the KVM hypervisor.

Meanwhile, the CentOS Stream 8 branch continues to develop, which is used for preparing new releases of RHEL 8.x and is recommended for transitioning systems using the classic distribution CentOS 8.x, whose support will end this month. To switch to CentOS Stream, simply install the centos-release-stream package ("dnf install centos-release-stream") and run the command "dnf update". The CentOS Stream 8 branch will be supported until May 31, 2024, while support for the classic CentOS 7.x will conclude on June 30, 2024.

As an alternative, users can also switch to distributions that have continued the development of the CentOS 8 branch: AlmaLinux (migration script), Rocky Linux (migration script), VzLinux (migration script), or Oracle Linux (migration script). Additionally, Red Hat has provided the opportunity (migration script) for free use of RHEL in organizations developing open source software and in environments of individual developers with up to 16 virtual or physical systems.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster