I-Linux 6.6 ifika ne-Shadow Stac, uphuculo lwe-FS, ukulungiswa kunye nokunye

Linux Kernel

I-Linux yi-kernel esimahla kakhulu efana ne-Unix kernel.Ngomnye wemizekelo ephambili yesoftware esimahla kunye nevulelekileyo.

Kutshanje uLinus Torvalds, umdali kunye nomgcini weLinux kernel, ibhengeze ukukhutshwa kwenguqulo 6.6, emva kokudinwa zonke izizathu zokulibazisa umsebenzi. Le nguqulo entsha izisa amanqaku amatsha kunye nophuculo, ngakumbi malunga nokhuseleko, inkxaso yehardware kunye nokusebenza. Enye yezona zinto ziphawuleka kakhulu ezintsha kwiLinux 6.6 ngumcwangcisi weEEVDF, ethatha indawo yomcwangcisi weCFS.

Phakathi kweempawu eziphambili zeLinux 6.6 kukuphunyezwa kwe-Intel Shadow Stack (ethi nangona igama layo likwanceda iichips ezithile ze-AMD), itekhnoloji yokhuseleko lwehardware ekhusela uhlaselo lwenkqubo ejolise ekubuyiseleni (ROP). kwi-Intel Tiger Lake processors kwaye kamva.

Iimpawu ezintsha eziphambili zeLinux 6.6

Kolu guqulelo lutsha lweLinux 6.6 oluthi thaca, se wongeze ulungelelwaniso olongezelelweyo lwemigca yomsebenzi ozimeleyo ukuphucula ukusebenza kakuhle kokusetyenziswa kwakhona kwecache yeprosesa kwiinkqubo ezinkulu ezinenqanaba lesithathu lesithathu (L3) cache. Ukhozo ikwabandakanya izixhobo eziluncedo/umgca wokusebenzela/wq_dump.py ukujonga uqwalaselo lwangoku lwemigca yomsebenzi.

Olunye utshintsho olwahlukileyo kukuba ukongeza inkxaso yeeparamitha zamanani kwizicwangciso /sys/izixhobo/inkqubo/cpu/smt/ ulawulo olumisela inani lemisonto ekhoyo yondoqo we-CPU nganye (ngaphambili kuphela "kwi-" kunye "nokucima" amaxabiso ayexhaswa ukwenza okanye ukuvala inkxaso ye-symmetrical multithreading). I into entsha inokusetyenziswa kwezinye iiprosesa zePowerPC ezixhasa i-hotplug symmetric multithreading ("SMT hotplug") ukwenzela ukuba i-SMT isebenze kwiicores ezithile ngexesha lokusebenza.

Kwicala lenkqubo yefayile, I-Linux 6.6 izisa uphuculo kwinkxaso yesixhobo sendawo kunye noxinzelelo lwe-F2FS, inkxaso yeemmaps ekwabelwana ngazo kwimowudi engeyiyo ye-cache yeFUSE, ukulungiswa kwesihluzi se-net kunye ne-BPF, ukulungiswa okuninzi kumqhubi we-AMDGPU, ukulungiswa kwe-regression ye-MIDI 2.0 inkxaso kunye nolawulo olungcono lwe-Intel RAPL.

Linux 6.6 yongeza i-compiler ye-BPF kanye ngexesha loyilo lwe-PA-RISC, Inkxaso yeplagi eshushu ye-SMT yolwakhiwo lwe-PowerPC, iflegi entsha ye-API yentaba ethintela intaba ekwabelaneni ngee-superblocks kwimemori kunye nezinye ii-mounts, inkxaso ye-SEV-IiNdwendwe ze-SNP kunye ne-TDX kwi-Hyper-V kunye nemisebenzi yenkxaso yamaxabiso okuqala womnatha ye io_uring inkqubo esezantsi. Inkxaso ye-defragmenting IPv4 kunye ne-IPv6 iipakethi, kunye nokukwazi ukucoca iipakethi eziqhekezayo, zongezwe kwi-subsystem ye-BPF. Umphathi omtsha, i-update_socket_protocol, yongezwa kwi-BPF ukuvumela iinkqubo ze-BPF ukuba zitshintshe iprothokholi eceliweyo yeesokethi ezintsha.

Ngaphandle koko, ulwazi longeziwe kwifayile /proc/pid/smaps ukuxilonga ukusebenza kwendlela yokudibanisa amaphepha enkumbulo afanayo (KSM: I-Kernel Samepage Ukudibanisa).

Isusiwe i-Frontswap API, ivumela ulwahlulo lokutshintsha ukuba lubekwe kwimemori engenakulungiswa ngokuthe ngqo kwaye ayiboneleli ngolwazi lokusebenza malunga nokufumaneka kwendawo yamahhala. Le API isetyenziswe kuphela kwi-zswap, ngoko ke kwagqitywa ukuba kusetyenziswe lo msebenzi ngokuthe ngqo kwi-zswap, ukuphelisa iileya ezingeyomfuneko.

I-XFS ilungiselelwe ukuba nokwenzeka kokusetyenziswa kwe-fsck eluncedo ukujonga kunye nokulungisa iingxaki ezichongiweyo kwi-intanethi, ngaphandle kokunganyuki inkqubo yefayile. Ukongeza, i-XFS iphumeze amandla okusebenzisa izithuba ezinkulu kwi-cache yephepha kwaye yongeza ulungelelwaniso oluhambelanayo oluphucule kakhulu ukusebenza kwezinye iintlobo zomthwalo womsebenzi.

Inkqubo yefayile I-tmpfs yongeze inkxaso yeempawu zomsebenzisi ezongeziweyo (i-xattrs yomsebenzisi), i-I/O ngqo, kunye nenani labasebenzisi kunye neqela. Uhlaziyo oluzinzisiweyo lolawulo, olusombulule imiba ngokuthumela ngaphandle ii-tmpfs ngaphezulu kwe-NFS.

Ukongeza koku, yongezwa ukuphunyezwa komatshini wokupakisha isithunzi, evumelayo thintela ukusebenza kwezinto ezininzi zokuxhaphaza, usebenzisa ubunakho behardware yee-Intel processors ukukhusela ekubhaleni ngaphezulu idilesi yokubuyisela yomsebenzi kwimeko yokuphuphuma kwebuffer kwisitaki.

Umongo yokhuselo yileyo Emva kokudlula ulawulo kumsebenzi, iprosesa igcina iidilesi zokubuya kungekuphela nje kwisitaki esiqhelekileyo, kodwa nakwindawo eyahlukileyo "yeSithunzi", engenakuguqulwa ngokuthe ngqo. Phambi kokuba umsebenzi uphume, idilesi yokubuyisela iyavela kwisitaki esifihliweyo kwaye ithelekiswe nedilesi yokubuyisela kwisitaki esingundoqo. Iidilesi ezingangqinelaniyo zibangela ukuba kubekho umkhethe ophakanyisiweyo, ukuvala iimeko apho i-exploit ikwazile ukubhala phezu kwedilesi kwisitaki esingundoqo. Isitaki somthunzi wehardware sixhaswa kuphela kulwakhiwo lwe-64-bit kwaye ukulinganisa kwesoftware kusetyenziswa kwi-32-bit yokwakha.

Ye- Olunye utshintsho olwahlukileyo kolu hlobo lutsha:

  • Inkxaso yokuqala eyongeziweyo ye-ARM SME (Scalable Matrix Extension) imiyalelo.
  • Izakhono ze-perf utility zandisiwe.
  • Kongezwe ujongano olutsha lomlinganiswa (/dev/vfio/devices/vfioX) kwisistim esezantsi yeVFIO yokulawula izixhobo zeVFIO, evumela umsebenzisi ukuba avule ngokuthe ngqo ifayile yesixhobo ngaphandle kokufikelela kwilifa /dev/vfio/$ ujongano lweqela groupID.
  • Iseva ye-NFS ayisaxhasi ilifa leentlobo zoguqulelo oluntsonkothileyo lwe-Kerberos ezisebenzisa i-DES kunye ne-3DES algorithms.
  • Ukuphunyezwa kwe-AF_XDP (i-eXpress Data Path) usapho lwandisiwe ukuze lusebenze kunye neepakethi ezigcinwe kwii-buffers ezininzi.
  • Iinkqubo ezisebenzisa iisokethi ze-AF_XDP ngoku zinokufumana kwaye zithumele iipakethi ezivela kwizithinteli ezininzi ngaxeshanye.
  • Iflegi yophuhliso lovavanyo isusiwe kwimodyuli ye-ksmbd, ebonelela ngokuphunyezwa komgangatho wekernel weseva yefayile esekwe kwiprotocol ye-SMB3.
  • Inkxaso eyongeziweyo yokudibanisa imisebenzi yokufunda (imibuzo "ye-compound read").

Okokugqibela, ukuba unomdla wokwazi ngakumbi ngayo, ungajongana neenkcukacha kwi ukulandela ikhonkco.


Shiya uluvo lwakho

Idilesi yakho ye email aziyi kupapashwa. ezidingekayo ziphawulwe *

*

*

  1. Inoxanduva lwedatha: I-AB Internet Networks 2008 SL
  2. Injongo yedatha: Ulawulo lwe-SPAM, ulawulo lwezimvo.
  3. Umthetho: Imvume yakho
  4. Unxibelelwano lwedatha: Idatha ayizukuhanjiswa kubantu besithathu ngaphandle koxanduva lomthetho.
  5. Ukugcinwa kweenkcukacha
  6. Amalungelo: Ngalo naliphi na ixesha unganciphisa, uphinde uphinde ucime ulwazi lwakho.