The new Linux 6.6 kernel is now available, integrating an array of updated capabilities that will impact workstation, server and cloud deployments.

The Linux kernel is the core foundational element of a larger Linux operating system. There are multiple vendors that provide commercially supported Linux distributions, including Red Hat, SUSE, and Canonical. The Linux kernel is developed in a collaborative process with new releases every six to ten weeks.

Among the improvements that are part of Linux 6.6 are new deployment options for the widely used server message block (SMB) networking protocol, security improvements and updated support for the latest Intel and AMD silicon.

 

KSMBD brings in-kernel file sharing to Linux

The SMB protocol is widely used to enable file sharing capabilities across Linux servers, as well as between Linux and Microsoft Windows-based systems.

Since the creation of Linux over two decades ago, SMB support has been largely implemented in subsystems of Linux that are adjacent to the main Linux kernel. For the past two years, Linux has been experimenting with an implementation of the SMBv3 protocol directly inside the Linux kernel that it calls KSMBD. The promise of KSMBD is a more optimized, faster and secure approach to sharing files over a network.

With Linux 6.6, the technology is finally being made as a stable, generally available component. "After two years, many fixes and much testing, KSMBD is no longer experimental," Linux kernel developer Steve French wrote in his code commit message.

Intel Shadow Stack support improves security

Return-oriented programming (ROP) attacks have become increasingly common in recent years. Intel-based silicon on Linux now has a way to help mitigate ROP attacks, with the Intel Shadow Stack.

The Shadow Stack stack is part of Intel's Control-flow Enforcement (CET) stack that helps provide more resiliency to a running CPU.

"CET covers several related x86 processor features that provide protection against control flow hijacking attacks," the Linux kernel documentation on the new feature states. "A shadow stack is a secondary stack allocated from memory which cannot be directly modified by applications."

New scheduler in Linux 6.6 will boost performance

A core element of any operating system are the scheduling systems, which organize and schedule how different operations will execute and in what order.

The Linux 6.6 kernel introduces the new Earliest Eligible Virtual Deadline First (EEVDF) scheduler that will replace the existing Completely Fair Scheduler (CFS) that has been the primary CPU scheduler since 2007.

EEVDF aims to improve on CFS in areas like latency handling to boost overall performance. EEVDF calculates a lag value for each process representing the difference between its allocated CPU time and how much it has actually received. Processes with positive lag are deemed "eligible" to run. It also calculates a virtual deadline for each process based on its lag and assigned time slice. The scheduler runs the process with the earliest virtual deadline first.

By assigning smaller time slices to latency-sensitive processes, EEVDF can prioritize giving them quick access to the CPU when needed.

"It completely reworks the base scheduler, placement, preemption, picking — everything," Kernel developer Peter Zijlstra wrote in a Linux kernel mailing list message comparing EEVDF to CFS. "The only thing they have in common is that they're both a virtual time-based scheduler."