What’s New in openEuler 24.03 LTS SP4
Security Upgrades
Confidential computing and security see major upgrades in SP4 with enhanced Arm Confidential Compute Architecture (CCA), Kunpeng virtCCA, Hygon architecture security, and GTA remote attestation and resource distribution.
Enhanced CCA: In confidential-computing scenarios, SP4's enhanced CCA now supports PCIPC-protected PCIe and device pass-through into the Realm domain, eliminating intermediate data copies to guarantee confidentiality of the device data link.
Enhanced Kunpeng virtCCA: It now supports UEFI boot and accelerates instance startup and elastic scaling via parallel hardware initialization. Using the GPT partition table, it breaks the 2TB disk limit to support hundred-TB-class cloud disks for big data and AI workloads.
Hygon Architecture Security: Enhancements to the Hygon Crytographic Coprocessor (CCP) driver and the Linux Kernel Crypto API in SP4 provide hardware-accelerated encryption for local disks on the server and cloud disks to meet Data at Rest (DAR) security requirements. Hygon uses an authenticated encryption mode and its Authenticated Encryption with Associated Data (AEAD) capability to provide both confidentiality and integrity for transaction data, logs, and message queues. Hygon also offers Chinese cryptographic algorithm support for Kubernetes persistent volumes as well as container image-layer encryption, making Hygon a comprehensive solution for databases, financial businesses, and cloud-native environments.
GTA Remote Attestation: Global Trust Authority (GTA) Remote Attestation Service in SP4 now supports Huawei Kunpeng Confidential Computing CCA and the BMC DICE-based remote-attestation capability. SP4 also adds the corresponding GTA Resource Broker Service (RBS) resource-distribution service. The GTA Remote Attestation Service verifies and authenticates the runtime environment using remote attestation and then GTA RBS securely releases and distributes pre-provisioned resources (e.g., keys) into the trusted execution environment. These keys can be used for disk encryption, transmission encryption, mutual authentication, and more. Using GTA Remote Attestation Service with GTA RBS offers support for most upper-layer confidential computing application scenarios (e.g., confidential AI inference).
Compiler and Runtime Enhancements
SP4 introduces new compiler and runtime enhancements in LLVM for openEuler, Go for openEuler, BiSheng JDK, and AI Compiler ANNC.
LLVM for openEuler: Based on open source LLVM software, LLVM for openEuler offers a high-performance, multi-architecture compiler for compute-intensive scenarios. Three new compiler features in SP4 improve compilation-build efficiency, reduce debug info bloat, and enable the full Triton CPU support for FlagGems operators. Multi-stream parallel compilation improves the ThinLTO process by using call graph file splitting to take advantage of the Kunpeng CPU’s multi-core capabilities, shortening compilation time and improving efficiency. The new Dwarfutils enhancement reduces debug info bloat. Finally, Triton CPU now offers full support for FlagGems operators with AArch64 SVE/SME affinity.
Go for openEuler: IT is a cloud-native-optimized Go distribution based on open source Golang that also receives targeted updates in SP4 for cloud-native and microservice container scenarios. This compiler optimization resolves performance issues that result from insufficient native Golang capabilities in business scenarios.
BiSheng JDK: A downstream fork of OpenJDK that adds Kunpeng affinity instruction enhancements and optimizes VM startup speed to improve big data scenario performance.
ANNC: Accelerated Neural Network Compiler (ANNC), an AI compiler built into openEuler, focuses on compute graph optimization, high performance fused operators, and efficient code generation. By supporting mainstream open source inference frameworks along with multi-hardware back-end integration, ANNC improves small model inference performance for CPU recommendation.
New for Cloud Native Scenarios
To address the difficulty of deploying, scaling, and implementing enterprise AI agents, openEuler introduces a lightweight agent sandbox runtime in SP4 that features low token consumption and full link security. By optimizing the hardware-software collaboration of image snapshots and adding remote lazy loading and layered on-demand loading, the agent sandbox shortens the agent cold start time. Additionally, SP4 uses Kunpeng SuperPoDs for shared snapshot distribution to avoid repeated pulling. Together, these two optimizations accelerate multi-sandbox startup, while balancing quick response times with the need for security assurance. By providing a secure runtime for code execution, tool invocation, workflow automation, and lightweight extensible cloud IDEs, this new sandbox allows enterprises to efficiently deploy agents at scale.
« Previous 1 2 3 Next »
Buy Linux Magazine
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters
Support Our Work
Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.
News
-
Linux Mint Shares a Possible Kernel Cleanup Solution
For those on Linux Mint who like to keep multiple kernels around but don't want them to take up too much space, you might be getting a new automated tool.
-
CachyOS Gets an Update
CachyOS August 2026 release is now available with the latest version of KDE, some new features, and plenty of improvements.
-
The Linux Kernel Dev Staging Area Now Rejects AI-Generated Patches
Unless a kernel patch is a valid security fix, it will be rejected if it was created using AI.
-
Linux Surpasses Double-Digit Market Share
According to two sources, the Linux operating system has hit a major milestone in market share that naysayers thought would never happen.
-
AI Helped Develop a Linux Exploit
A use-after-free race exploit was discovered and exploited on CentOS Stream 9.
-
Yet Another Linux Kernel Vulnerability Discovered
Affecting millions of systems, a kernel flaw discovered by Qualys could allow users to gain root privileges.
-
Ubuntu 26.10 to Include Ubuntu Certified Hardware Check
If you've ever wondered if your laptop or PC is officially certified to run Ubuntu, that curiosity will soon be met.
-
Substantial Update to IPFire Now Available
The lastest version of IPFire features a fundamental change to how the system handles DNS.
-
Gnome Working on Test Center App to Make Testing Easier
It's now possible to test experimental features on the Gnome desktop without worrying that you'll break things.
-
New Vulnerability Discovered in Linux Kernel
Hiding out for nearly 15 years, the Ghostlock vulnerability allows a standard logged-in user to gain root privileges.
