Rebase to RHEL6u8 kernel 2.6.32-642.el6 (security, bug fixes, enhancements, see RHSA-2016-0855). Fixes and enhancements in KVM, UBC, ext4, networking, cpt.
Proper fix for CVE-2016-3156. Fix for kernel BUG in cfq-iosched (OVZ-6651). Fix for kernel crash inside pick_next_task_fair() (PSBM-44475). Write to CIFS share hangs (OVZ-6642). ub memcg: fake use_hierarhy file is required for KVM's libvirtd (OVZ-6660). Other fixes.
This Virtuozzo 7.0 Beta offers the following major improvements:
Unified management of containers and KVM virtual machines with the prlctl tool and SDK. You get a single universal toolset for all CT/VM management needs.
Autoballooning and kernel same-page merging that allows overcommitting memory resources in the smartest way possible with an insignificant impact on customer workloads.
Memory hotplugging for containers and VMs that allows both increasing and reducing CT/VM memory size on the fly, without the need to reboot. Your customers can now scale their workloads without any downtime. This feature also enables you to make PAYG offerings, allowing customers to change VM resources depending on workload and potentially pay less.
Memory guarantees for both containers and virtual machines.
Ability to manage containers and VMs with libvirt and virt-manager. If you used to manage VMs with libvirt, you can do it in Virtuozzo in absolutely the same way.
IPv6 link-local address was being assigned to slave interfaces in bonding which resulted in DAD and network routing issues. (PSBM-42433). kswap activity needed to be restricted in case of high-order requests (PSBM-44291). Force charge swapin readahead pages if in ub0. (PSBM-44857). Missing bounds check in ipt_entry structure in netfilter. (PSBM-45193, CVE-2016-3134). IPv6 connect could cause DoS via NULL pointer dereference (PSBM-45219, CVE-2015-8543). Pipe buffer state corruption after unsuccessful atomic read from pipe (PSBM-45328, CVE-2016-0774). hostapd was broken in early RHEL6.7 kernels (OVZ-6649).
Missing bounds check in ipt_entry structure in netfilter. (PSBM-45193, CVE-2016-3134). IPv6 connect could cause DoS via NULL pointer dereference (PSBM-45219, CVE-2015-8543). Pipe buffer state corruption after unsuccessful atomic read from pipe (PSBM-45328, CVE-2016-0774). hostapd was broken in early RHEL6.7 kernels. (OVZ-6649)
bonding: Prevent IPv6 link local address on enslaved devices (PSBM-42433). kswap activity restriction in case high-order requests (PSBM-44291). force charge swapin readahead pages if in ub0 (PSBM-44857)
Crash in restore_one_vfsmount() on restoring shared non-master mounts (PSBM-42471). Introduced FADV_DEACTIVATE flag in fadvise() to be able to move file pages from the active to the inactive list (PSBM-42664). Race between keyctl_read() and keyctl_revoke() could crash the host (PSBM-43799, CVE-2015-7550). Under certain circumstances, backup/restore via CBT interface could hang the host (PSBM-43936). Second-level quota in simfs containers was broken in 042stab113.x kernels (OVZ-6655).
Crash in restore_one_vfsmount() on restoring shared non-master mounts (PSBM-42471). Introduced FADV_DEACTIVATE flag in fadvise() to be able to move file pages from the active to the inactive list (PSBM-42664). Race between keyctl_read() and keyctl_revoke() could crash the host (PSBM-43799, CVE-2015-7550). Under certain circumstances, backup/restore via CBT interface could hang the host (PSBM-43936). Second-level quota in simfs containers was broken in 042stab113.x kernels (OVZ-6655).
Improved accounting for network-related memory objects (PCLIN-32553). Introduced a per-container limit for the number of mounts (PCLIN-32554). Introduced a per-container limit for IPv4 network interface aliases (PCLIN-32555).