Release of QEMU 6.0 emulator

The release of QEMU 6.0 has been announced. As an emulator, QEMU allows you to run programs built for one hardware platform on a system with a completely different architecture, for example, running an ARM application on an x86-compatible PC. In virtualization mode, the performance of code execution in an isolated environment is close to that of a hardware system due to direct execution of instructions on the CPU and the involvement of the Xen hypervisor or KVM module.

The project was originally created by Fabrice Bellard to enable the execution of Linux executable files built for the x86 platform on architectures different from x86. Over the years of development, support for full emulation of 14 hardware architectures has been added, and the number of emulated hardware devices has exceeded 400. For version 6.0, more than 3,300 changes have been made by 268 developers.

Key improvements added in QEMU 6.0:

  • The NVMe controller emulator has been updated to comply with the NVMe 1.4 specification and equipped with experimental support for zoned namespaces, multipath I/O, and end-to-end data encryption on storage.
  • Experimental options '-machine x-remote' and '-device x-pci-proxy-dev' have been added for offloading device emulation to external processes. Currently, only the emulation of the SCSI adapter lsi53c895 is supported in this mode.
  • Experimental support for creating snapshots of RAM contents has been added.
  • A FUSE module has been added to export block devices, allowing a snapshot of the state of any block device used in the guest system to be mounted. Export is done via the QMP command block-export-add or through the '--export' option in the qemu-storage-daemon utility.
  • Support for ARMv8.1-M ‘Helium’ architecture and Cortex-M55 processors has been added to the ARM emulator, as well as extended instructions ARMv8.4 TTST, SEL2, and DIT. Support for ARM boards mps3-an524 and mps3-an547 has also been added. Additionally, for xlnx-zynqmp, xlnx-versal, sbsa-ref, npcm7xx, and sabrelite boards, enhanced emulation of devices has been implemented.
  • For ARM in system-level and user environment emulation modes, support for the ARMv8.5 MTE (Memory Tagging Extension) has been implemented, allowing tags to be associated with each memory allocation operation and enabling pointer checks during memory access that must be linked to the correct tag. This extension can be used to block exploitation of vulnerabilities caused by accessing already freed memory blocks, buffer overflows, accesses before initialization, and use outside the current context.
  • The 68k architecture emulator has added support for a new type of emulated machines called 'virt', which use virtio for performance optimization.
  • The x86 architecture emulator has introduced the capability to apply AMD SEV-ES (Secure Encrypted Virtualization) technology for encrypting processor registers used in the guest system, making the contents of the registers inaccessible to the host environment unless the guest system explicitly grants access to them.
  • The classic TCG (Tiny Code Generator) code generator has added support for the PKS (Protection Keys Supervisor) mechanism during x86 system emulation, which can be used to protect access to privileged memory pages.
  • The MIPS architecture emulator has introduced a new type of emulated machines called 'virt' with support for the Chinese Loongson-3 processors.
  • The PowerPC architecture emulator has added support for external BMC controllers for 'powernv' emulated machines. For 'pseries' emulated machines, it provides notification of failures during attempts to hot unplug memory and CPU.
  • Support for emulating Qualcomm Hexagon processors with DSP has been added.
  • The classic TCG (Tiny Code Generator) has added support for macOS host environments on systems with the new Apple M1 ARM chip.
  • The RISC-V architecture emulator now supports QSPI NOR flash for Microchip PolarFire boards.
  • The Tricore emulator has added support for a new model of TriBoard boards, emulating the Infineon TC27x SoC.
  • In the ACPI emulator, it is now possible to assign network adapter names in guest systems that are independent of the connection order to the PCI bus.
  • Support for the FUSE_KILLPRIV_V2 option has been added to virtiofs to enhance the performance of guest systems.
  • VNC now supports cursor transparency and screen resolution scaling via virtio-vga, based on the window size.
  • QMP (QEMU Machine Protocol) has added support for asynchronous parallel access when performing backup tasks.
  • The USB emulator now allows saving traffic generated while working with USB devices into a separate pcap file for later inspection in Wireshark.
  • New QMP commands load-snapshot, save-snapshot, and delete-snapshot have been added for managing qcow2 snapshots.
  • Vulnerabilities CVE-2020-35517 and CVE-2021-20263 have been fixed in virtiofs. The first issue allows access to the host environment from the guest system by a privileged user creating a special device file in a directory shared with the host. The second issue arises from a mistake in handling extended attributes in the 'xattrmap' option and may lead to the ignoring of write permission resets and privilege escalation within the guest system.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster