Xen hypervisor release 4.14

After eight months of development has been published release of the open hypervisor Xen 4.14. Companies involved in the development of the new release include Alibaba, Amazon, AMD, Arm, Bitdefender, Citrix, EPAM Systems, Huawei, and Intel. The release updates for the Xen 4.14 branch will continue until January 24, 2022, and the publication of vulnerability fixes will extend until July 24, 2023.

Key changes in Xen 4.14:

  • Support for a new device model has been added Linux stubdomain, allowing execution under a separate unprivileged user, separating the components for device emulation from Dom0. Previously, only the 'qemu-traditional' device model could be used in stubdomain mode, which limited the range of emulated hardware. The new model Linux stubomains was developed by the QUBES OS project and supports the use of emulation drivers from the latest QEMU releases, as well as the available QEMU features for guest systems.
  • For systems supporting Intel EPT, support has been implemented for creating lightweight forks of virtual machines for rapid introspection, such as for malware analysis or fuzz testing. In such forks, memory sharing is utilized and device model cloning is not performed.
  • The live patch system has been enhanced with binding to hypervisor build identifiers and accounting for the order of patch application to avoid applying patches to the wrong build or in the wrong order.
  • Support for CET extensions (Intel Control-flow Enforcement Technology) has been added to protect against exploits built using return-oriented programming (ROP) techniques.
  • The CONFIG_PV32 setting has been added to disable support for 32-bit para-virtualized (PV) guest systems in the hypervisor while maintaining support for 64-bit.
  • Support for Hypervisor FS, a pseudo-FS in the style of sysfs, has been added for structured access to internal hypervisor data and settings without the need to parse logs or write hypercalls.
  • Xen can now be run as a guest system under the Hyper-V hypervisor used in Microsoft Azure's cloud platform. Running Xen inside Hyper-V allows the familiar virtualization stack to be used in Azure cloud environments and enables the migration of virtual machines between different cloud systems.
  • The ability to generate random guest system IDs has been added (previously, IDs were generated sequentially). IDs can now also be preserved across save, restore, and VM state migration operations.
  • Automatic binding generation for the Go language based on libxl structures has been implemented.
  • Support for KDD, a utility for interfacing with the WinDbg (Windows Debugger), has been added for Windows 7, 8.x, and 10, allowing for debugging Windows environments without enabling debugging in the guest OS.
  • Support for all variants of the Raspberry Pi 4 equipped with 4GB and 8GB of RAM has been added.
  • Support for AMD EPYC processors with the codename 'Milan' has been introduced.
  • The performance of nested virtualization, where Xen runs inside guest systems based on Xen or Viridian, has been improved.
  • Support for AVX512_BF16 instructions has been implemented in emulation mode.
  • The hypervisor build process has been transitioned to using Kbuild.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster