Inkampani ye-Red Hat ikhithi yokuhambisa . Iindibano zokufakela zilungiselelwe x86_64, s390x (IBM System z), ppc64le kunye ne-Aarch64 izakhiwo, kodwa kuba ΡΠΎΠ»ΡΠΊΠΎ Π·Π°ΡΠ΅Π³ΠΈΡΡΡΠΈΡΠΎΠ²Π°Π½Π½ΡΠΌ ΠΏΠΎΠ»ΡΠ·ΠΎΠ²Π°ΡΠ΅Π»ΡΠΌ Red Hat Customer Portal. ΠΡΡ ΠΎΠ΄Π½ΡΠ΅ ΡΠ΅ΠΊΡΡΡ rpm-ΠΏΠ°ΠΊΠ΅ΡΠΎΠ² Red Hat Enterprise Linux 8 ΡΠ°ΡΠΏΡΠΎΡΡΡΠ°Π½ΡΡΡΡΡ ΡΠ΅ΡΠ΅Π· CentOS. ΠΠ΅ΡΠΊΠ° RHEL 8.x Π±ΡΠ΄Π΅Ρ ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΈΠ²Π°ΡΡΡΡ ΠΊΠ°ΠΊ ΠΌΠΈΠ½ΠΈΠΌΡΠΌ Π΄ΠΎ 2029 Π³ΠΎΠ΄Π°.
Ekuqaleni, isaziso se-RHEL 8.2 sasi kwiwebhusayithi ye-Red Hat nge-21 ka-Epreli, kodwa isibhengezo senziwe ngaphambi kwexesha kunye nogcino lokufaka uhlaziyo. , kodwa eneneni ukukhululwa kuphume namhlanje kuphela. Isebe le-8.x liphuhliswa ngokuhambelana nomjikelo omtsha wophuhliso oluqikelelwayo, obandakanya ukuqulunqwa kokukhutshwa rhoqo kwiinyanga ezintandathu ngexesha elimisiweyo. Entsha Iimveliso ze-RHEL zithatha iileya ezininzi, kubandakanya i-Fedora njengebhodi yobuchule obutsha, ukufikelela kwiipakethe ezenzelwe ukukhutshwa okuphakathi okulandelayo kwe-RHEL (uguqulelo oluqengqelekayo lwe-RHEL), umfanekiso osisiseko wehlabathi jikelele (UBI, uMfanekiso weSiseko seSiseko seHlabathi) ukulungiselela usetyenziso olukwizikhongozeli ezizimeleyo kwaye ukusetyenziswa kwamahhala kwe-RHEL kwinkqubo yophuhliso.
Isitshixo :
- inkxaso epheleleyo yolawulo lwezibonelelo kusetyenziswa ulawulo olumanyeneyo , ebikade ikwinqanaba lokulinga ukwenzeka. Amaqela v2 anokusetyenziswa, umzekelo, ukunciphisa inkumbulo, i-CPU kunye nokusetyenziswa kwe-I/O. Umahluko ophambili phakathi kwe-cgroups v2 kunye ne-v1 kukusetyenziswa kweqela eliqhelekileyo loluhlu lwazo zonke iintlobo zemithombo, endaweni yoluhlu oluhlukeneyo lokwabiwa kwezixhobo ze-CPU, zokulawula ukusetyenziswa kwememori, kunye ne-I / O. Uluhlu olwahlukileyo lukhokelele kubunzima ekuququzeleleni intsebenziswano phakathi kwabaphathi kunye neendleko ezongezelelweyo zemithombo ye-kernel xa kusetyenziswa imithetho yenkqubo ekubhekiselwa kuyo kwii-hierarchies ezahlukeneyo.
- ΠΈΠ½ΡΡΡΡΠΌΠ΅Π½Ρ Convert2RHEL Π΄Π»Ρ ΠΏΡΠ΅ΠΎΠ±ΡΠ°Π·ΠΎΠ²Π°Π½ΠΈΡ Π² RHEL ΡΠΈΡΡΠ΅ΠΌ Π½Π° ΠΊΠΎΡΠΎΡΡΡ ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡΡΡΡ RHEL-ΠΏΠΎΠ΄ΠΎΠ±Π½ΡΠ΅ Π΄ΠΈΡΡΡΠΈΠ±ΡΡΠΈΠ²Ρ, ΡΠ°ΠΊΠΈΠ΅ ΠΊΠ°ΠΊ CentOS ΠΈ Oracle Linux.
- ΠΠΎΠ±Π°Π²Π»Π΅Π½Π° Π²ΠΎΠ·ΠΌΠΎΠΆΠ½ΠΎΡΡΡ ΠΊΠ°ΡΡΠΎΠΌΠΈΠ·Π°ΡΠΈΠΈ ΠΎΠ±ΡΠ΅ΡΠΈΡΡΠ΅ΠΌΠ½ΡΡ ΠΏΠΎΠ»ΠΈΡΠΈΠΊ ΠΊΡΠΈΠΏΡΠΎΠ³ΡΠ°ΡΠΈΡΠ΅ΡΠΊΠΈΡ ΠΏΠΎΠ΄ΡΠΈΡΡΠ΅ΠΌ (crypto-policies), ΠΎΡ Π²Π°ΡΡΠ²Π°ΡΡΠΈΠ΅ ΠΏΡΠΎΡΠΎΠΊΠΎΠ»Ρ TLS, IPSec, SSH, DNSSec ΠΈ Kerberos. ΠΠ΄ΠΌΠΈΠ½ΠΈΡΡΡΠ°ΡΠΎΡ ΡΠ΅ΠΏΠ΅ΡΡ ΠΌΠΎΠΆΠ΅Ρ ΠΎΠΏΡΠ΅Π΄Π΅Π»ΠΈΡΡ ΡΠΎΠ±ΡΡΠ²Π΅Π½Π½ΡΡ ΠΏΠΎΠ»ΠΈΡΠΈΠΊΡ ΠΈΠ»ΠΈ ΠΈΠ·ΠΌΠ΅Π½ΠΈΡΡ ΠΎΠΏΡΠ΅Π΄Π΅Π»ΡΠ½Π½ΡΠ΅ ΠΏΠ°ΡΠ°ΠΌΠ΅ΡΡΡ ΡΡΡΠ΅ΡΡΠ²ΡΡΡΠΈΡ . ΠΠΎΠ±Π°Π²Π»Π΅Π½Ρ Π΄Π²Π° Π½ΠΎΠ²ΡΡ ΠΏΠ°ΠΊΠ΅ΡΠ° setools-gui ΠΈ setools-console-analyses Π΄Π»Ρ Π°Π½Π°Π»ΠΈΠ·Π° ΠΏΠΎΠ»ΠΈΡΠΈΠΊ SELinux ΠΈ ΠΈΠ½ΡΠΏΠ΅ΠΊΡΠΈΡΠΎΠ²Π°Π½ΠΈΡ ΠΏΠΎΡΠΎΠΊΠΎΠ² Π΄Π°Π½Π½ΡΡ . ΠΠΎΠ±Π°Π²Π»Π΅Π½ ΠΏΡΠΎΡΠΈΠ»Ρ Π±Π΅Π·ΠΎΠΏΠ°ΡΠ½ΠΎΡΡΠΈ, ΡΠΎΠΎΡΠ²Π΅ΡΡΡΠ²ΡΡΡΠΈΠΉ ΡΠ΅ΠΊΠΎΠΌΠ΅Π½Π΄Π°ΡΠΈΡΠΌ DISA STIG (Defense Information Systems Agency). ΠΠΎΠ±Π°Π²Π»Π΅Π½Π° Π½ΠΎΠ²Π°Ρ ΡΡΠΈΠ»ΠΈΡΠ° oscap-podman Π΄Π»Ρ ΡΠΊΠ°Π½ΠΈΡΠΎΠ²Π°Π½ΠΈΡ ΡΠΎΠ΄Π΅ΡΠΆΠΈΠΌΠΎΠ³ΠΎ ΠΊΠΎΠ½ΡΠ΅ΠΉΠ½Π΅ΡΠΎΠ² Π½Π° ΠΏΡΠ΅Π΄ΠΌΠ΅Ρ ΠΈΡΠΏΠΎΠ»ΡΠ·ΠΎΠ²Π°Π½ΠΈΡ ΡΡΠ·Π²ΠΈΠΌΡΡ Π²Π΅ΡΡΠΈΠΉ ΠΏΡΠΎΠ³ΡΠ°ΠΌΠΌ.
- Izixhobo zolawulo lwesazisi ngoku zibandakanya into entsha ye-Healthcheck ekuvumela ukuba uchonge iingxaki kwindawo ye-IDM (Ulawulo lwesazisi). Ibonelela ngenkxaso kwiindima eziBalulekileyo kunye neemodyuli ukwenza lula ufakelo nolawulo lwe-IDM.
- Uyilo lwekhonsoli yewebhu luye lwatshintshwa, oluye lwatshintshwa ekusebenziseni i-PatternFly 4 interface, efana noyilo lwe-OpenShift interface 4. Ixesha lokungasebenzi komsebenzisi longezwe, emva koko iseshoni kunye ne-console yewebhu iphelile. Inkxaso eyongeziweyo yokuqinisekisa usebenzisa isatifikethi somthengi. Amacandelo okulawula ukugcinwa kunye noomatshini benyani baye bahlaziywa.
- Ujongano lokutshintsha iidesktop ezinenyani kwimeko-bume yeGNOME yeClassic itshintshiwe; iqhosha lokutshintsha lisusiwe lasiwa kwikona esezantsi ekunene kwaye iyilwe njengoluhlu olunezithonjana.
- ΠΡΠ°ΡΠΈΡΠ΅ΡΠΊΠ°Ρ ΠΏΠΎΠ΄ΡΠΈΡΡΠ΅ΠΌΠ° DRM (Direct Rendering Manager) ΡΠΈΠ½Ρ ΡΠΎΠ½ΠΈΠ·ΠΈΡΠΎΠ²Π°Π½Π° Ρ Π²Π΅ΡΡΠΈΠ΅ΠΉ ΡΠ΄ΡΠ° Linux 5.1. ΠΠ±Π½ΠΎΠ²Π»Π΅Π½Ρ Π³ΡΠ°ΡΠΈΡΠ΅ΡΠΊΠΈΠ΅ Π΄ΡΠ°ΠΉΠ²Π΅ΡΡ, Π² ΠΊΠΎΡΠΎΡΡΡ ΠΏΠΎΡΠ²ΠΈΠ»Π°ΡΡ ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΠ° Intel Intel Comet Lake H ΠΈ U (HD Graphics 610, 620, 630), Intel Ice Lake U (HD Graphics 910, Iris Plus Graphics 930, 940, 950), AMD Navi 10, Nvidia Turing TU116,
- Iseshoni ye-GNOME esekwe kwi-Wayland yenziwe ngokungagqibekanga kwiinkqubo ezine-GPU ezininzi (ngaphambili i-X11 yayisetyenziswa kwiinkqubo ezinemizobo exutyiweyo).
- ΠΠΎΠ±Π°Π²Π»Π΅Π½Π° ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΠ° Π½ΠΎΠ²ΡΡ
ΠΏΠ°ΡΠ°ΠΌΠ΅ΡΡΠΎΠ² ΡΠ΄ΡΠ° Linux, ΡΠ²ΡΠ·Π°Π½Π½ΡΡ
Ρ ΡΠΏΡΠ°Π²Π»Π΅Π½ΠΈΠ΅ΠΌ Π²ΠΊΠ»ΡΡΠ΅Π½ΠΈΠ΅ΠΌ Π·Π°ΡΠΈΡΡ ΠΎΡ Π½ΠΎΠ²ΡΡ
Π°ΡΠ°ΠΊ Π½Π° ΠΌΠ΅Ρ
Π°Π½ΠΈΠ·ΠΌ ΡΠΏΠ΅ΠΊΡΠ»ΡΡΠΈΠ²Π½ΠΎΠ³ΠΎ Π²ΡΠΏΠΎΠ»Π½Π΅Π½ΠΈΡ CPU: mds, tsx, mitigations. ΠΠΎΠ±Π°Π²Π»Π΅Π½ ΠΏΠ°ΡΠ°ΠΌΠ΅ΡΡ
mem_encrypt ukulawula usetyenziso lwe-AMD SME (uKhuseleko lweMemori yokuFihla) izandiso. Kongezwe iparameter ye-cpuidle.governor ukukhetha i-CPU i-idle state handler (irhuluneli ye-cpuidle). Yongezwe /proc/sys/kernel/panic_print parameter ukuqwalasela imveliso yolwazi kwimeko yokuwa kwenkqubo (imeko yoloyiko). Iparamitha eyongeziweyo
/proc/sys/kernel/threads-max ukuchaza inani eliphezulu lemisonto enokwenziwa yifolokhwe () umsebenzi. Ukongeza /proc/sys/net/bpf_jit_enable ukhetho lokulawula ukuba iJIT compiler yenziwe ukuba iBPF. - I-algorithm yokuqaliswa kwe-dnf-automatic.timer iye yatshintshwa ukubiza inkqubo yofakelo lohlaziyo oluzenzekelayo. Endaweni yokusebenzisa isibali-xesha esinemonotonous esikhokelela ekusebenzeni ngexesha elingalindelekanga emva kokuqalisa, iyunithi echaziweyo ngoku iqala phakathi kwe-6 kunye ne-7 am. Ukuba ngeli xesha inkqubo icinyiwe, kodwa iqala ngeyure emva kokuyivula.
- Iimodyuli ezinamasebe amatsha ePython 3.8 (yayiyi-3.6) kunye ne-Maven 3.6 yongezwe kwindawo yokugcina i-AppStream. Iiphakheji ezihlaziyiweyo nge-GCC 9.2.1, Clang/LLVM 9.0.1, Rust 1.41 kunye neGo 1.13.
- Iinguqulelo zephakheji ezihlaziyiweyo powertop 2.11 (ngenkxaso EHL, TGL, ICL/ICX amaqonga), opencv 3.4.6, tuned 2.13.0, rsyslog 8.1911.0, audit 3.0-0.14, fapolicyd 0.9.1-2, sudo 1.8.29 - 3.el8,
firewalld 0.8, tpm2-izixhobo 3.2.1, mod_md (ngenkxaso ACMEv2), grafana 6.3.6, pcp 5.0.2, elfutils 0.178, SystemTap 4.2, 389-ds-base 1.4.2.4,
isamba 4.11.2. - ΠΠΎΠ±Π°Π²Π»Π΅Π½Ρ Π½ΠΎΠ²ΡΠ΅ ΠΏΠ°ΠΊΠ΅ΡΡ whois, graphviz-python3 (ΡΠ°ΡΠΏΡΠΎΡΡΡΠ°Π½ΡΠ΅ΡΡΡ ΡΠ΅ΡΠ΅Π· ΠΎΡΠΈΡΠΈΠ°Π»ΡΠ½ΠΎ Π½Π΅ ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΈΠ²Π°Π΅ΠΌΡΠΉ ΡΠ΅ΠΏΠΎΠ·ΠΈΡΠΎΡΠΈΠΉ CRB (CodeReady Linux Builder)), perl-LDAP, perl-Convert-ASN1.
- Iseva ye-BIND ye-DNS ihlaziywe kuguqulelo 9.11.13 kwaye yatshintshelwa ekusebenziseni i-database ebophelelayo yendawo ye-GeoIP2 kwifomathi ye-libmaxminddb endaweni ye-GeoIP yakudala, engasaxhaswanga. Yongeza i-service-stale (stale-answer) setting, ekuvumela ukuba ubuyisele iirekhodi zeDNS zakudala ukuba akunakwenzeka ukufumana ezintsha.
- Iplagi ye-omhttp yongezwe kwi-rsyslog ngonxibelelwano ngojongano lwe-HTTP REST.
- Π ΠΏΠΎΠ΄ΡΠΈΡΡΠ΅ΠΌΡ Π°ΡΠ΄ΠΈΡΠ° ΠΏΠ΅ΡΠ΅Π½Π΅ΡΠ΅Π½Ρ ΠΈΠ·ΠΌΠ΅Π½Π΅Π½ΠΈΡ, ΡΠΎΠΎΡΠ²Π΅ΡΡΡΠ²ΡΡΡΠΈΠ΅ ΡΠ΄ΡΡ Linux 5.5.
- I-plugin ye-setroubleshoot yongeze inkxaso yokuhlalutya ukungaphumeleli kokufikelela ngenxa yokuphuma kwimemori kwaye iphendule ngokuzenzekelayo ukusombulula iingxaki ezinjalo.
- ΠΠΎΠ»ΡΠ·ΠΎΠ²Π°ΡΠ΅Π»ΡΠΌ, ΠΎΠ³ΡΠ°Π½ΠΈΡΠ΅Π½Π½ΡΠΌ ΠΏΡΠΈ ΠΏΠΎΠΌΠΎΡΠΈ SELinux, ΠΏΡΠ΅Π΄ΠΎΡΡΠ°Π²Π»Π΅Π½Π° Π²ΠΎΠ·ΠΌΠΎΠΆΠ½ΠΎΡΡΡ ΡΠΏΡΠ°Π²Π»Π΅Π½ΠΈΡ ΡΠ΅ΡΠ²ΠΈΡΠ°ΠΌΠΈ, ΡΠ²ΡΠ·Π°Π½Π½ΡΠΌΠΈ c ΠΏΠΎΠ»ΡΠ·ΠΎΠ²Π°ΡΠ΅Π»ΡΡΠΊΠΈΠΌ ΡΠ΅Π°Π½ΡΠΎΠΌ. Π semanage Π΄ΠΎΠ±Π°Π²Π»Π΅Π½Π° ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΠ° ΠΎΡΠ΅Π½ΠΊΠΈ ΠΈ ΠΈΠ·ΠΌΠ΅Π½Π΅Π½ΠΈΡ ΡΠ΅ΡΠ΅Π²ΡΡ ΠΏΠΎΡΡΠΎΠ² SCTP ΠΈ DCCP (ΡΠ°Π½Π΅Π΅ ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΈΠ²Π°Π»ΠΈΡΡ TCP ΠΈ UDP). ΠΠ±Π΅ΡΠΏΠ΅ΡΠ΅Π½Π° ΠΎΠ±ΡΠ°Π±ΠΎΡΠΊΠ° ΠΏΠΎΠ΄ ΡΠ²ΠΎΠΈΠΌΠΈ Π΄ΠΎΠΌΠ΅Π½Π°ΠΌΠΈ SELinux ΡΠ΅ΡΠ²ΠΈΡΠΎΠ² lvmdbusd (D-Bus API Π΄Π»Ρ LVM), lldpd, rrdcached, stratisd, timedatex.
- I-Firewalld ihanjiswe kwi-libnftables JSON interface xa isebenzisana ne-nftables, ebangele ukunyuka komsebenzi kunye nokuthembeka. i-nftables yongeza inkxaso kwiindidi ezininzi kwiseti ye-IP, enokubandakanya iimanyano kunye noluhlu. Imithetho yeFirewalld ngoku ingasebenzisa iziphatho ukujonga uqhakamshelwano lweenkonzo ezisebenza kumazibuko othungelwano olungelulo oluqhelekileyo.
- Inkqubo esezantsi yekernel ye-tc (Traffic Control) ibonelela ngenkxaso epheleleyo
I-eBPF, ekuvumela ukuba usebenzise i-tc utility ukuncamathisela iiprogram ze-eBPF ukuhlela iipakethi nokulungisa imigca engenayo naphumayo. - Inkxaso ezinzileyo yezinye ii-subsystems ze-eBPF iphunyeziwe: i-BCC (BPF Compiler Collection) isixhobo kunye nethala leencwadi lokudala iinkqubo zokulandela umkhondo kunye nokulungiswa kwe-BPF, inkxaso ye-eBPF kwi-tc. I-bpftrace kunye ne-eXpress Data Path (XDP) amacandelo ahlala kwi-Technology Preview stage.
- Amacandelo exesha langempela (i-kernel-rt) ilungelelaniswa kunye nesethi yeepatches kwi-5.2.21-rt13 kernel.
- Ngoku kuyenzeka ukuqhuba inkqubo ye-rngd (i-daemon yokondla i-entropy kwi-pseudo-random number generator) ngaphandle kwamalungelo engcambu.
- I-LVM yongeze inkxaso yendlela ye-dm-writecache caching ukongeza kwi-dm-cache ekhoyo ngaphambili. I-Dm-cache igcina eyona misebenzi isetyenziswa rhoqo yokubhala nokufunda, kunye ne-dm-writecache cache ibhala imisebenzi ngokuyibeka kuqala kwi-SSD ekhawulezayo okanye kwimidiya ye-PMEM kwaye emva koko ihambise kwidiski ecothayo ngasemva.
- I-XFS yongeze inkxaso kwimowudi yokubhala yolwazi lweqela.
- I-FUSE yongeze inkxaso ye-copy_file_range () yokusebenza, ekuvumela ukuba ukhawuleze ukukopisha idatha ukusuka kwifayile enye ukuya kwenye ngokwenza umsebenzi kuphela kwicala le-kernel ngaphandle kokuqala ukufunda idatha kwimemori yenkqubo. Ukulungiswa kubonakala ngokucacileyo kwi-GlusterFS.
- Yongeza i "--preload" ukhetho kwikhonkco eliguquguqukayo, elikuvumela ukuba ucacise ngokucacileyo amathala eencwadi ukuba anyanzelwe ukuba alayishwe ngesicelo. Olu khetho lwenza kube lula ukuphepha ukusebenzisa i-LD_PRELOAD eguquguqukayo yemeko-bume, ezuzwe njengeenkqubo zomntwana.
- I-hypervisor ye-KVM ibonelela ngenkxaso epheleleyo yokusebenza kwendlwane koomatshini ababonakalayo.
- Abaqhubi abatsha bongeziwe, kuquka
gVNIC, Broadcom UniMAC MDIO, Software iWARP, DRM VRAM, cpuidle-haltpoll, stm_ftrace, stm_console,
Intel Trace Hub, PMEM DAX,
I-Intel PMC Core,
Intel RAPL
Intel Runtime Average Power Limit (RAPL). - I-DSA eyehliweyo, i-TLS 1.0 kunye ne-TLS 1.1 zivaliwe ngokungagqibekanga kwaye zifumaneka kuphela kwi-LEGACY suite.
- ΠΠ±Π΅ΡΠΏΠ΅ΡΠ΅Π½Π° ΡΠΊΡΠΏΠ΅ΡΠΈΠΌΠ΅Π½ΡΠ°Π»ΡΠ½Π°Ρ (Technology Preview) ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΠ° nmstate, AF_XDP, XDP, KTLS, dracut, kexec fast reboot, eBPF, libbpf, igc, NVMe over TCP/IP, DAX Π² ext4 ΠΈ xfs, OverlayFS, Stratis, DNSSEC, GNOME Π½Π° ΡΠΈΡΡΠ΅ΠΌΠ°Ρ ARM, AMD SEV Π΄Π»Ρ KVM, Intel vGPU
umthombo: opennet.ru
