These are the changes from upstream 2.4.1 to 2.4.4
L2ARC — substantial rework
- DWPD-based rate limiting with adaptive feed intervals (protects SSD endurance)
- Per-device parallel feed threads (was single-threaded feed)
- Persistent markers with consistent tail scanning + lazy reset flags + scan-based depth cap
- Even-depth multi-sublist scanning, write budget fairness (metadata no longer monopolizes)
- Rebuild bounded by write hand on first sweep; fixed a prev_hdr use-after-free
Performance
- Predict and throttle buffers dirtied by the sync context
- Batch object reallocation syncs in zfs receive
- Parallelize metaslab_sync_done(), dedup block cloning, and brt_pending_apply() across vdevs
- RAIDZ: optimize single data column writes; avoid extra abd_t allocations in RAIDZ/dRAID
- Bridge speculative and prescient prefetchers; bound user prefetch to a fraction of ARC
New features / CLI
- zpool condense — new verb
- zpool scrub -t — thorough scrub support
- zfs bookmark -r — recursive bookmark creation
- zpool initialize -z — write zeroes
- New dedupused/dedupsaved pool properties
- zoned_uid property (Linux container/namespace delegation — not applicable to us)
- FIDEDUPERANGE via block cloning
- zstream: major rework — multithreaded, new raw/drop_record/queue subcommands, memory tracking
Data-integrity fixes (the ones that matter most)
- Fix read corruption after block-clone-after-truncate
- Fix double free for blocks cloned after DDT prune
- draid: fix data corruption after disk clear; fix checksum errors after rebuild with degraded disks; fix import
failure after disk replacement - Prevent range-tree corruption race in dnode_sync()
- z_seq now persists across znode eviction — fixes the VMware ESXi-over-NFS "file specified is not a virtual disk" bug
(Linux/FreeBSD only for now, per our earlier gap analysis) - DDT: multiple pruning bugs fixed (including negative time overflow)
- Fix off-by-one in PREVIOUSLY_REDACTED handling that dropped the last block
Security hardening
- vdev_open/zfs_file_open/vdev_file/vdev_disk: now check the calling credential instead of always using kcred (we
ported the Windows side of this yesterday) - Additional verification of size fields and strings in the receive path
- Hardened receive record validation
- secpolicy_nfs removed; secpolicy_zinject/secpolicy_sys_config restricted to global-zone credentials
Deadlock/hang fixes
- Fix deadlock on dmu_tx_assign() from vdev_rebuild()
- Fix snapshot automount deadlock during concurrent zfs recv
- Fix self-deadlock setting the vdev allocating/path property
- Fix race between device-removal completion and pool export
- zfs_ioctl: fix EBUSY race between quota queries and mount (we ported this too)
- arc: fix race between arc_release() and arc_read_done()
OpenZFS on Windows
- Add zpool create and zpool destroy to zfs_tray