Oracle Linux 9 dhe bërthama Unbreakable Enterprise Kernel 7 janë të disponueshme

Kompania Oracle publikoi versionet e stabilizuara të shpërndarjes Oracle Linux 9 dhe bërthamës Unbreakable Enterprise Kernel 7 (UEK R7), e cila pozicionohet për t'u përdorur në shpërndarjen Oracle Linux si një alternativë ndaj paketës standarde me bërthamë nga Red Hat Enterprise Linux. Shpërndarja Oracle Linux 9 është e ndërtuar mbi bazën paketore të Red Hat Enterprise Linux 9 dhe është plotësisht binarisht e përputhshme me të.

Për shkarkim pa kufij ofrohen imazhe të instalimit iso, me madhësi 8.6 GB dhe 840 MB, të përgatitura për arkitekturën x86_64 dhe ARM64 (aarch64). Për Oracle Linux 9, akses i pakufizuar dhe falas në depozitën yum me përditësime binarësh të paketave me rregullime të defekteve (errata) dhe çështjeve të sigurisë është hapur. Për shkarkim janë përgatitur gjithashtu depozita të mbështetur veçmas me setet e paketave Application Stream dhe CodeReady Builder.

Përveç paketës me bërthamë nga RHEL (e bazuar në bërthamën 5.14), në Oracle Linux ofrohet bërthama e saj Unbreakable Enterprise Kernel 7, e cila është e bazuar në bërthamën Linux 5.15 dhe e optimizuar për të punuar me softuer dhe pajisje industriale Oracle. Kodet burimore të bërthamës, duke përfshirë ndarjen në patches të veçanta, janë të disponueshme në depozitën publike Git të Oracle. Bërthama Unbreakable Enterprise Kernel instalohet si parazgjedhje, pozicionohet si një alternativë ndaj paketës standarte me bërthamë RHEL dhe ofron një sërë funksionalitetesh të avancuara, si integrimi DTrace dhe mbështetje e përmirësuar për Btrfs. Përveç bërthamës shtesë në funksionalitet, versionet Oracle Linux 9 dhe RHEL 9 janë plotësisht identike (lista e ndryshimeve mund të shihet në njoftimin e RHEL9).

Veçoritë kryesore të bërthamës Unbreakable Enterprise Kernel 7:

  • ËshtĂ« pĂ«rmirĂ«suar mbĂ«shtetje pĂ«r arkitekturĂ«n Aarch64. MadhĂ«sia e faqeve tĂ« memories nĂ« sistemet ARM me 64-bit Ă«shtĂ« reduktuar si parazgjedhje nga 64 KB nĂ« 4 KB, gjĂ« qĂ« pĂ«rshtatet mĂ« mirĂ« me volumet e memories dhe llojet e ngarkesave, tipike pĂ«r sistemet ARM.
  • ËshtĂ« vazhduar ofrimi i sistemit tĂ« debugging dinamik DTrace 2.0, i cili Ă«shtĂ« pĂ«rmirĂ«suar pĂ«r tĂ« pĂ«rdorur nĂ«n-sistemĂ«n e bĂ«rthamĂ«s eBPF. DTrace 2.0 funksionon sipĂ«r eBPF, siç bĂ«jnĂ« mjetet ekzistuese tĂ« gjurmimit nĂ« Linux.
  • K capabilities of the Btrfs file system have been expanded. An asynchronous implementation of the DISCARD operation has been added to Btrfs to mark freed blocks that no longer need to be physically stored. The asynchronous implementation allows the storage device to not wait for the completion of the DISCARD and to perform this operation in the background. New mounting options have been added to simplify data recovery from a damaged file system: 'rescue=ignorebadroots' for mounting despite the damage to some root trees (extent, uuid, data reloc, device, csum, free space), 'rescue=ignoredatacsums' for disabling checksum verification for data, and 'rescue=all' for simultaneously enabling the 'ignorebadroots', 'ignoredatacsums', and 'nologreplay' modes. Significant performance optimizations related to the execution of fsync() operations have been made. Support for fs-verity (file authenticity and integrity checking) and user ID mapping has been added.
  • NĂ« XFS Ă«shtĂ« implementuar mbĂ«shtetje pĂ«r operacionet DAX pĂ«r qasje tĂ« drejtpĂ«rdrejtĂ« nĂ« FS pĂ«r tĂ« anashkaluar caches e faqeve dhe pĂ«r tĂ« pĂ«rjashtuar dyfishimin e caches. JanĂ« bĂ«rĂ« ndryshime pĂ«r tĂ« zgjidhur problemet me mbingarkesĂ«n e tipit 32-bit time_t nĂ« vitin 2038, pĂ«rfshirĂ« opsionet e reja tĂ« montimit bigtime dhe inobtcount.
  • JanĂ« bĂ«rĂ« pĂ«rmirĂ«sime nĂ« sistemin e skedarĂ«ve OCFS2 (Oracle Cluster File System).
  • ËshtĂ« shtuar sistemi i skedarĂ«ve ZoneFS, i cili thjeshton punĂ«n me nivele tĂ« ulĂ«ta me pajisje ruajtjeje tĂ« zonuar. Pajisjet e zonuara janĂ« ato tĂ« disqeve magnetike ose NVMe SSD, ku hapĂ«sira pĂ«r ruajtje Ă«shtĂ« e ndarĂ« nĂ« zona, tĂ« cilat pĂ«rbĂ«jnĂ« grupe bllokesh ose sektorĂ«sh, nĂ« tĂ« cilat lejohet vetĂ«m shtimi i tĂ« dhĂ«nave nĂ« mĂ«nyrĂ« tĂ« renditur me pĂ«rditĂ«simin e pĂ«rgjithshĂ«m tĂ« gjithĂ« grupit tĂ« bllokove. FS ZoneFS lidh çdo zonĂ« nĂ« ndihmĂ«s me njĂ« skedar tĂ« veçantĂ«, i cili mund tĂ« pĂ«rdoret pĂ«r ruajtjen e tĂ« dhĂ«nave nĂ« mĂ«nyrĂ« raw pa manipuluar nĂ« nivel sektori dhe blloku, domethĂ«nĂ« lejon aplikacionet tĂ« pĂ«rdorin API-nĂ« e skedarĂ«ve nĂ« vend qĂ« tĂ« drejtohen drejtpĂ«rdrejt te pajisja bllok pĂ«rmes ioctl.
  • ËshtĂ« stabilizuar mbĂ«shtetja pĂ«r protokollin VPN WireGuard.
  • The capabilities of the eBPF subsystem have been expanded. A CO-RE (Compile Once — Run Everywhere) mechanism has been implemented, which solves the problem of portability of compiled eBPF programs and allows eBPF program code to be compiled only once and use a special universal loader that adapts the loaded program to the current kernel and BTF types (BPF Type Format). A 'BPF trampoline' mechanism has been added, which allows overheads when passing calls between the kernel and BPF programs to be virtually eliminated. Direct access to kernel functionality from BPF programs and suspension of the handler has been provided.
  • A detector for split locks, which occur when accessing unaligned data in memory due to atomic instruction execution crossing two CPU cache lines, has been integrated. The kernel can dynamically detect such locks that lead to significant performance drops and output warnings or send a SIGBUS signal to the application that caused the lock.
  • ËshtĂ« siguruar mbĂ«shtetje pĂ«r Multipath TCP (MPTCP), njĂ« zgjerim i protokollit TCP pĂ«r organizimin e funksionimit tĂ« lidhjeve TCP me dĂ«rgimin e paketimeve njĂ«kohĂ«sisht pĂ«rmes disa rrugĂ«ve pĂ«rmes interfecesh tĂ« ndryshme rrjetesh, tĂ« lidhura me IP tĂ« ndryshme. IP adresat.
  • NĂ« planifikuesin e detyrave Ă«shtĂ« implementuar njĂ« mod i planifikimit SCHED_CORE, i cili lejon menaxhimin e proceseve qĂ« mund tĂ« ekzekutohen sĂ« bashku nĂ« njĂ« bĂ«rthamĂ« CPU. Çdo proces mund t'i caktoset njĂ« identifikues cookie, i cili pĂ«rcakton fushĂ«n e besimit midis proceseve (p.sh., pĂ«rkatĂ«sia ndaj njĂ« pĂ«rdoruesi ose kontejneri). Kur organizohet ekzekutimi i kodit, planifikuesi mund tĂ« sigurojĂ« bashkĂ«punimin e njĂ« bĂ«rthame CPU vetĂ«m pĂ«r proceset qĂ« lidhen me njĂ« pronar tĂ« vetĂ«m, gjĂ« qĂ« mund tĂ« pĂ«rdoret pĂ«r tĂ« bllokuar disa sulme tĂ« klasĂ«s Spectre duke parandaluar ekzekutimin nĂ« njĂ« fisht (SMT - Hyper Threading) tĂ« detyrave besueshme dhe atyre qĂ« nuk janĂ« besuese.
  • PĂ«r cgroups Ă«shtĂ« realizuar njĂ« kontrollues i shpĂ«rndarjes sĂ« memories slab (kontrolluesi i memories slab), i cili Ă«shtĂ« i njohur pĂ«r transferimin e faturimit tĂ« slab nga niveli i faqeve tĂ« memories nĂ« nivelin e objekteve tĂ« bĂ«rthamĂ«s, duke mundĂ«suar kĂ«shtu ndarjen e faqeve slab nĂ« cgroup tĂ« ndryshme, nĂ« vend tĂ« rezervimit tĂ« cache-it tĂ« veçantĂ« tĂ« slab pĂ«r çdo cgroup. Qasja e propozuar lejon rritjen e efikasitetit tĂ« pĂ«rdorimit tĂ« slab, duke reduktuar madhĂ«sinĂ« e memories sĂ« pĂ«rdorur pĂ«r slab nga 30-45%, duke ulur ndjeshĂ«m konsumimin e pĂ«rgjithshĂ«m tĂ« memories nga bĂ«rthama dhe duke reduktuar fragmentimin e memories.
  • JanĂ« siguruar tĂ« dhĂ«na pĂ«r debug nĂ« formatin CTF (Compact Type Format), i cili ofron ruajtjen e kompakt tĂ« informacionit mbi tipet C, lidhjet midis funksioneve dhe simbolet pĂ«r debug.
  • Ka pĂ«rfunduar furnizimi i modulit DRBD (Distributive Replicated Block Device) dhe pajisjes /dev/raw (pĂ«r qasje tĂ« drejtpĂ«rdrejtĂ« nĂ« skedarĂ« duhet tĂ« pĂ«rdoret flag O_DIRECT).

Burimi: opennet.ru

Blini hosting tĂ« besueshĂ«m pĂ«r faqe interneti me mbrojtje nga DDoS, serverĂ« VPS VDS đŸ”„ Blini hosting tĂ« besueshĂ«m pĂ«r faqe interneti me mbrojtje nga DDoS, serverĂ« VPS VDS | ProHoster