Difference between revisions of "News/updates"

From OpenVZ Virtuozzo Containers Wiki
Jump to: navigation, search
(Kernel RHEL6 042stab117.14: shortened)
Line 25: Line 25:
 
== Kernel RHEL6 042stab117.14 ==
 
== Kernel RHEL6 042stab117.14 ==
  
* Rebase to RHEL6u8 kernel 2.6.32-642.el6
+
Rebase to RHEL6u8 kernel 2.6.32-642.el6 (security, bug fixes, enhancements, see RHSA-2016-0855). Fixes and enhancements in KVM, UBC, ext4, networking, cpt.
* kvm: reporting emulation failures to userspace. (CVE-2010-5313, CVE-2014-7842)
+
 
* File descriptors passed over unix sockets are not properly accounted. (CVE-2013-4312)
 
* x86: espfix not working for 32-bit KVM paravirt guests. (CVE-2014-8134)
 
* Buffer overflow with fraglist larger than MAX_SKB_FRAGS + 2 in virtio-net. (CVE-2015-5156)
 
* Mounting ext2 fs e2fsprogs/tests/f_orphan as ext4 crashes system. (CVE-2015-7509)
 
* MTU value is not validated in IPv6 stack causing packet loss. (CVE-2015-8215)
 
* Null pointer dereference when mounting ext4. (CVE-2015-8324)
 
* IPv6 connect causes DoS via NULL pointer dereference. (CVE-2015-8543)
 
* An attacker with knowledge of a connections client IP, server IP, and server port can abuse the challenge ACK mechanism and remotely inject or control a TCP stream contents in a connection between a Linux device and its connected client/server. (CVE-2016-5696)
 
* Numabalanced acquire cgroup_mutex for a long time. (PSBM-26897)
 
* CPU hotplug improvements (PSBM-46773).
 
* cpt: incorrect restore of SKB resulting in warnings in tcp_recvmsg(). (PSBM-39332, PSBM-46741)
 
* cpt: crash in nfs_fscache_dup_uniq_id on dump of container with NFS mounts inside. (PSBM-47216)
 
* cpt: crash in svc_age_temp_xprts_now() on stop of container with NFS mount. (PSBM-47515)
 
* cpt: crash on closing restored Unix sockets. (PSBM-47529)
 
* cpt: fixed restore of shared mounts. (PSBM-47639, OVZ-6779)
 
* cpt: crash after restore of Unix sockets with in-flight file descriptors. (PSBM-51254, PSBM-51351)
 
* ext4: crash in ext4_kill_sb() on mount of non-EXT4 filesystems (042stab114.2+ are affected) (PSBM-47782).
 
* swap: forbid exceeding ub swappages limit on global memory pressure. (PSBM-47836).
 
* 25-second delays can happen while logging in to systemd-based containers after container migration or host vzreboot. (PSBM-47889)
 
* CISCO UCS eNIC driver wraps untagged traffic into vlan0. (PSBM-51149)
 
* aacraid: Crash in aac_intr_normal(). (042stab112.15+ are affected) PSBM-49814)
 
* Fixed operation of iputils-ping-20150815 (debian-9) inside containers. (OVZ-6744)
 
* module: removed warning about waiting module removal. (OVZ-6748)
 
* fs.mqueue.* sysctls can be changed inside containers. (OVZ-6757)
 
 
{{Download link|kernel/rhel6/042stab117.14}}
 
{{Download link|kernel/rhel6/042stab117.14}}
  

Revision as of 18:09, 13 September 2016


Kernel RHEL6 042stab117.14

Rebase to RHEL6u8 kernel 2.6.32-642.el6 (security, bug fixes, enhancements, see RHSA-2016-0855). Fixes and enhancements in KVM, UBC, ext4, networking, cpt.

[ Change log/downloads... ]

--VvS 15:00, 13 September 2016 (EDT)

OpenVZ 7.0 GA

OpenVZ 7.0 has been released. The new release focuses on merging OpenVZ and Virtuozzo source codebase, replacing our own hypervisor with KVM.

Key changes in comparison to the last stable OpenVZ release:

  • OpenVZ 7.0 becomes a complete Linux distribution based on our own VzLinux.
  • The main difference between the Virtuozzo (commercial) and OpenVZ (free) versions are the EULA, packages with paid features, and Anaconda installer.
  • The user documentation is publicly available.
  • EZ templates can be used instead of tarballs with template caches.
  • Additional features (see announce)

Read more...

--SergeyB (talk) 16:58, 25 July 2016 (EDT)

Kernel RHEL6 testing 042stab117.5

Fix in cpt.

[ Change log/downloads... ]

--SergeyB (talk) 05:45, 20 June 2016 (EDT)

Kernel RHEL6 testing 042stab117.4

Fixes in swap and cpt.

[ Change log/downloads... ]

--SergeyB (talk) 05:54, 14 June 2016 (EDT)

Kernel RHEL6 testing 042stab117.3

Ploop, CPT fixes and fixed crash on mount of non-EXT4 filesystems.

[ Change log/downloads... ]

--SergeyB (talk) 08:32, 3 June 2016 (EDT)

Kernel RHEL6 testing 042stab117.2

Fixes in CPT, CPU hotplug and numabalanced improvements.

[ Change log/downloads... ]

--SergeyB (talk) 01:39, 31 May 2016 (EDT)

Kernel RHEL6 testing 042stab117.1

Rebase to RHEL6u8 kernel 2.6.32-642.el6. Improved ext4 defragmentation. Fixes in CPT.

[ Change log/downloads... ]

--Kir (talk) 20:10, 25 May 2016 (EDT)

Kernel RHEL6 042stab116.1

Rebase to RHEL6 kernel 2.6.32-573.26.1.el6. Security, bug and stability fixes.

[ Change log/downloads... ]

--Kir (talk) 20:09, 25 May 2016 (EDT)

ploop 1.15

Support for e4defrag2 on compact. Docker-related fixes. Fixes for Alpine Linux and newest GCC. Many other fixes and improvements.

[ Change log/downloads... ]

--Kir (talk) 22:28, 29 April 2016 (EDT)

Kernel RHEL6 testing 042stab115.2

Rebase to RHEL6u8 beta kernel 2.6.32-621.el6.

[ Change log/downloads... ]

--SergeyB (talk) 08:33, 6 April 2016 (EDT)

Kernel RHEL6 testing 042stab114.5

Proper fix for CVE-2016-3156. Fix for kernel BUG in cfq-iosched (OVZ-6651). Fix for kernel crash inside pick_next_task_fair() (PSBM-44475). Write to CIFS share hangs (OVZ-6642). ub memcg: fake use_hierarhy file is required for KVM's libvirtd (OVZ-6660). Other fixes.

[ Change log/downloads... ]

--SergeyB (talk) 08:10, 30 March 2016 (EDT)

Virtuozzo 7 Beta

This Virtuozzo 7.0 Beta offers the following major improvements:

Unified management of containers and KVM virtual machines with the prlctl tool and SDK. You get a single universal toolset for all CT/VM management needs.

Autoballooning and kernel same-page merging that allows overcommitting memory resources in the smartest way possible with an insignificant impact on customer workloads.

Memory hotplugging for containers and VMs that allows both increasing and reducing CT/VM memory size on the fly, without the need to reboot. Your customers can now scale their workloads without any downtime. This feature also enables you to make PAYG offerings, allowing customers to change VM resources depending on workload and potentially pay less.

Memory guarantees for both containers and virtual machines.

Ability to manage containers and VMs with libvirt and virt-manager. If you used to manage VMs with libvirt, you can do it in Virtuozzo in absolutely the same way.

Guest tools for Windows and Linux VMs.

Download

--SergeyB (talk) 05:53, 29 March 2016 (EDT)

Kernel RHEL6 042stab113.21

IPv6 link-local address was being assigned to slave interfaces in bonding which resulted in DAD and network routing issues. (PSBM-42433). kswap activity needed to be restricted in case of high-order requests (PSBM-44291). Force charge swapin readahead pages if in ub0. (PSBM-44857). Missing bounds check in ipt_entry structure in netfilter. (PSBM-45193, CVE-2016-3134). IPv6 connect could cause DoS via NULL pointer dereference (PSBM-45219, CVE-2015-8543). Pipe buffer state corruption after unsuccessful atomic read from pipe (PSBM-45328, CVE-2016-0774). hostapd was broken in early RHEL6.7 kernels (OVZ-6649).

[ Change log/downloads... ]

--SergeyB (talk) 05:48, 29 March 2016 (EDT)

Kernel RHEL6 testing 042stab113.21

Missing bounds check in ipt_entry structure in netfilter. (PSBM-45193, CVE-2016-3134). IPv6 connect could cause DoS via NULL pointer dereference (PSBM-45219, CVE-2015-8543). Pipe buffer state corruption after unsuccessful atomic read from pipe (PSBM-45328, CVE-2016-0774). hostapd was broken in early RHEL6.7 kernels. (OVZ-6649)

[ Change log/downloads... ]

--SergeyB (talk) 05:47, 29 March 2016 (EDT)

Kernel RHEL6 testing 042stab113.18

bonding: Prevent IPv6 link local address on enslaved devices (PSBM-42433). kswap activity restriction in case high-order requests (PSBM-44291). force charge swapin readahead pages if in ub0 (PSBM-44857)

[ Change log/downloads... ]

--SergeyB (talk) 10:22, 14 March 2016 (EDT)

Kernel RHEL6 stable 042stab113.17

Crash in restore_one_vfsmount() on restoring shared non-master mounts (PSBM-42471). Introduced FADV_DEACTIVATE flag in fadvise() to be able to move file pages from the active to the inactive list (PSBM-42664). Race between keyctl_read() and keyctl_revoke() could crash the host (PSBM-43799, CVE-2015-7550). Under certain circumstances, backup/restore via CBT interface could hang the host (PSBM-43936). Second-level quota in simfs containers was broken in 042stab113.x kernels (OVZ-6655).

[ Change log/downloads... ]

--SergeyB (talk) 06:37, 14 March 2016 (EDT)

Kernel RHEL6 testing 042stab113.17

Crash in restore_one_vfsmount() on restoring shared non-master mounts (PSBM-42471). Introduced FADV_DEACTIVATE flag in fadvise() to be able to move file pages from the active to the inactive list (PSBM-42664). Race between keyctl_read() and keyctl_revoke() could crash the host (PSBM-43799, CVE-2015-7550). Under certain circumstances, backup/restore via CBT interface could hang the host (PSBM-43936). Second-level quota in simfs containers was broken in 042stab113.x kernels (OVZ-6655).

[ Change log/downloads... ]

--SergeyB (talk) 06:37, 14 March 2016 (EDT)

Kernel RHEL5 stable 028stab120.1

Rebase to RHEL5 kernel 2.6.32-408.el5. Fixes for CVE-2015-5364, CVE-2015-5366.

[ Change log/downloads... ]

--SergeyB (talk) 07:30, 2 February 2016 (EST)

Kernel RHEL5 testing 028stab120.1

Rebase to RHEL5 kernel 2.6.32-408.el5. Fixes for CVE-2015-5364, CVE-2015-5366.

[ Change log/downloads... ]

--SergeyB (talk) 04:30, 25 January 2016 (EST)

Kernel RHEL5 stable 028stab119.6

Improved accounting for network-related memory objects (PCLIN-32553). Introduced a per-container limit for the number of mounts (PCLIN-32554). Introduced a per-container limit for IPv4 network interface aliases (PCLIN-32555).

[ Change log/downloads... ]

--SergeyB (talk) 09:25, 3 January 2016 (EST)

Older updates