What’s New in openEuler 24.03 LTS SP4

Security Upgrades

Confidential computing and security see major upgrades in SP4 with enhanced Arm Confidential Compute Architecture (CCA), Kunpeng virtCCA, Hygon architecture security, and GTA remote attestation and resource distribution.

Enhanced CCA: In confidential-computing scenarios, SP4's enhanced CCA now supports PCIPC-protected PCIe and device pass-through into the Realm domain, eliminating intermediate data copies to guarantee confidentiality of the device data link.

Enhanced Kunpeng virtCCA: It now supports UEFI boot and accelerates instance startup and elastic scaling via parallel hardware initialization. Using the GPT partition table, it breaks the 2TB disk limit to support hundred-TB-class cloud disks for big data and AI workloads.

Hygon Architecture Security: Enhancements to the Hygon Crytographic Coprocessor (CCP) driver and the Linux Kernel Crypto API in SP4 provide hardware-accelerated encryption for local disks on the server and cloud disks to meet Data at Rest (DAR) security requirements. Hygon uses an authenticated encryption mode and its Authenticated Encryption with Associated Data (AEAD) capability to provide both confidentiality and integrity for transaction data, logs, and message queues. Hygon also offers Chinese cryptographic algorithm support for Kubernetes persistent volumes as well as container image-layer encryption, making Hygon a comprehensive solution for databases, financial businesses, and cloud-native environments.

GTA Remote Attestation: Global Trust Authority (GTA) Remote Attestation Service in SP4 now supports Huawei Kunpeng Confidential Computing CCA and the BMC DICE-based remote-attestation capability. SP4 also adds the corresponding GTA Resource Broker Service (RBS) resource-distribution service. The GTA Remote Attestation Service verifies and authenticates the runtime environment using remote attestation and then GTA RBS securely releases and distributes pre-provisioned resources (e.g., keys) into the trusted execution environment. These keys can be used for disk encryption, transmission encryption, mutual authentication, and more. Using GTA Remote Attestation Service with GTA RBS offers support for most upper-layer confidential computing application scenarios (e.g., confidential AI inference).

Compiler and Runtime Enhancements

SP4 introduces new compiler and runtime enhancements in LLVM for openEuler, Go for openEuler, BiSheng JDK, and AI Compiler ANNC.

LLVM for openEuler: Based on open source LLVM software, LLVM for openEuler offers a high-performance, multi-architecture compiler for compute-intensive scenarios. Three new compiler features in SP4 improve compilation-build efficiency, reduce debug info bloat, and enable the full Triton CPU support for FlagGems operators. Multi-stream parallel compilation improves the ThinLTO process by using call graph file splitting to take advantage of the Kunpeng CPU’s multi-core capabilities, shortening compilation time and improving efficiency. The new Dwarfutils enhancement reduces debug info bloat. Finally, Triton CPU now offers full support for FlagGems operators with AArch64 SVE/SME affinity.

Go for openEuler: IT is a cloud-native-optimized Go distribution based on open source Golang that also receives targeted updates in SP4 for cloud-native and microservice container scenarios. This compiler optimization resolves performance issues that result from insufficient native Golang capabilities in business scenarios.

BiSheng JDK: A downstream fork of OpenJDK that adds Kunpeng affinity instruction enhancements and optimizes VM startup speed to improve big data scenario performance.

ANNC: Accelerated Neural Network Compiler (ANNC), an AI compiler built into openEuler, focuses on compute graph optimization, high performance fused operators, and efficient code generation. By supporting mainstream open source inference frameworks along with multi-hardware back-end integration, ANNC improves small model inference performance for CPU recommendation.

New for Cloud Native Scenarios

To address the difficulty of deploying, scaling, and implementing enterprise AI agents, openEuler introduces a lightweight agent sandbox runtime in SP4 that features low token consumption and full link security. By optimizing the hardware-software collaboration of image snapshots and adding remote lazy loading and layered on-demand loading, the agent sandbox shortens the agent cold start time. Additionally, SP4 uses Kunpeng SuperPoDs for shared snapshot distribution to avoid repeated pulling. Together, these two optimizations accelerate multi-sandbox startup, while balancing quick response times with the need for security assurance. By providing a secure runtime for code execution, tool invocation, workflow automation, and lightweight extensible cloud IDEs, this new sandbox allows enterprises to efficiently deploy agents at scale.

Buy Linux Magazine

Related content

  • OpenAtom openEuler

    The versatile Linux system known as OpenAtom openEuler is equally at home in the server room, cloud, or edge. With a huge developer community and strong corporate support, openEuler is ready to step into the foreground as a leading enterprise Linux.

  • NEWS

    In the news: Kubuntu Focus Laptop Is Now Ready for Preorder; Dell Adds a Much-Requested Feature to the New XPS Developer Edition Laptop; Bonsai Promises to Make Syncing Gnome Devices Easier; and Huawei Releases CentOS-Based openEuler as Open Source.

comments powered by Disqus
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters

Support Our Work

Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.

Learn More

News