Release Notes · Documentation · Home

OviOS Linux 6.2.0 “Polaris”

Live OS first. Run OviOS from a USB stick, an ISO or a network image and never install it. The whole node configuration lives on your storage pools and comes back by itself at every boot. 6.2 also adds CHAP authentication, thin LUNs with client discard/UNMAP, guided S3 setup and a hardened web interface.

Version 6.2.0
Codename Polaris
Released October 2026
Previous 6.0

Stateless operation: the config lives on the pools

In 6.0 a RAM-booted node started empty, and you restored its configuration by hand. In 6.2 OviOS saves its configuration automatically to a hidden dataset on every managed pool, <pool>/.ovios-system/<node-id>. At boot it imports the pools, picks the newest valid generation and applies it before the storage services start. That covers iSCSI targets, NFS exports, SMB shares and options.

Two ways to run stateless

Kernel command line: add ovios.autorestore=1 to the boot entry. Every configuration change is saved as a new snapshot generation on every pool, and the last 10 are kept. The newest valid generation is restored at boot. This is the recommended mode for USB, ISO and PXE deployments.

Options only: options auto.restore.enable on restores at boot from the newest sync-config bo archive, found in the osbackup dataset on system.backup.pool or in /tmp/osbackup. This mode needs no change to the boot entry.

Area 6.0 6.2
RAM / Live OS boot Starts with a factory configuration; restore manually Configuration restored automatically before services start
Where config is kept System disk and optional backup archives A copy on every managed pool, with 10 snapshot generations and a manifest
Node identity Tied to the installed system Hardware DMI UUID, so the same machine finds its own config on shared pools
ZFS hostid Random per install; copied by config sync Derived from the DMI UUID and stable across reboots; never replicated to partners
Restore safety Archive extracted as-is Allow-listed paths, a checksum-verified manifest, and a config-version marker that logs restores from older or newer releases
Status — sync-config persist-status lists generations per pool
🔑

New option: smb.secrets.restore

This option decides whether SMB secrets travel with the saved configuration. Those secrets are the Samba password database, machine secrets and the AD keytab. With it on, SMB users and the domain join survive a stateless reboot. With it off (the default), they are never written to the pools. After a full restore you re-create SMB passwords with smb-user and re-join the domain with smb-join. System accounts, CHAP secrets and the web password are always saved.

🧭

Boot options

ovios.autorestore=1 enables restore at boot. ovios.autorestore.force=1 restores even when the node already has local config. ovios.autorestore.anynode=1 adopts another node's config when the hardware UUID has changed. spl.spl_hostid is no longer required.

🏷️

Run mode everywhere

The version command, the login banner, the web dashboard and the PDF report all show the same version and say whether the node runs live or installed, stateless or stateful.

Full details, including what is saved, the secrets policy, all boot options and troubleshooting, are in the Live-OS & Stateless Guide.

New Features & Capabilities

The following capabilities are new since 6.0.

🔐

iSCSI CHAP Authentication

A new target chap menu adds or removes incoming, outgoing and mutual CHAP per target, with masked password prompts. Secrets are kept in /etc/tgt/chap.secrets (mode 0600, written atomically), and targets.conf only names the users. Secrets never appear on a command line or in verbose output.

🧊

Thin LUNs with Discard / UNMAP

LUNs created as thin now support SCSI UNMAP; the ovios-shell enables it automatically (a thin LUN can be opted out with the ovios:thin_provisioning=off ZFS property, then unmapped and re-mapped). When a client deletes data and issues discard/UNMAP (Linux fstrim, Windows ReTrim, VMware VMFS6 space reclamation), the freed blocks go back to the ZFS pool. How to use it.

🔗

target bind / unbind

Restrict a target to specific initiator addresses or IQNs, or open it up again, without re-creating it.

🪣

Guided S3 Setup

options s3.enable on walks you through the data volume, credentials and certificates. If you cancel or the setup fails, the option stays off and nothing half-configured is left running. The S3 console has its own s3.ui.enable option. S3 Guide.

📄

Storage Report & Backups

A one-click PDF health report covers pools, disks, LUNs, shares and ARC, with findings. sync-config list-backups and sync-config restore let you pick and restore any archive from the shell.

🐚

Shell Improvements

options is built into the shell with tab completion. Also new: service reset, service <name> logs, passwd, scanbus, InfiniBand verbs tools (ibv), pool list short output, and lun create pool/lun.

📥

Pool Import Control

The new import.src option chooses whether pools are imported by scanning devices (default) or from the cache file. Imports are safer: disk wiping and device resolution are now checked before anything is written.

🌐

Web Interface

Served over HTTPS with a self-signed certificate. The dashboard page is built into the binary, so upgrades never break reboot or shutdown. Action errors are shown instead of silently ignored, and the version is displayed.

Fixes & Hardening

Area Problem in 6.0 6.2
Config sync Concurrent syncs could clobber each other; a LUN map could push an empty targets.conf to partners Atomic targets.conf writes, serialised syncs, and the hostid is no longer replicated
Snapshots / volumes / LUNs Edge cases could lose data or break restore Safer snapshot restore, clone and delete paths
Pools Disk wipe and device resolution could pick the wrong device Explicit by-id resolution and checks before wiping
Web security Command injection, missing CSRF protection, XSS, and a concurrent-map crash All fixed. API calls with curl keep working.
Services Failed starts gave little information; multipath service issues Failures point to service <name> logs; multipath fixed
Audit auditd failed on overlay (live) root filesystems Enabling is handled correctly on overlayfs
Versioning & licence Version strings differed between components One version source (VERSION file + git commit); unified OviOS Software EULA v2.0

Upgrade Notes

⚠

For stateless boot, set skip.import to off. Autorestore can only find saved generations on pools it is allowed to import. After upgrading, make one configuration change (or run sync-config persist) so the first generation is written. Then check it with sync-config persist-status.

Using Active Directory or local SMB users on a stateless node? Decide on smb.secrets.restore before your first reboot. Turn it on to carry passwords and the domain join on the pools. Leave it off if those secrets must never leave the node. In that case, plan to run smb-user and smb-join after each full restore.

Updated & New Guides