freenode

← digests

PostgreSQL standby bugs and QEMU security backports

Databases & Infrastructure2026-09-28

PostgreSQL hackers worked through standby checksum and partition detach failures while QEMU stable trees absorbed security fixes and policy debates. Several threads advanced concrete patches for replication consistency and hypervisor hardening.

Offline checksum changes leave standbys inconsistent

PostgreSQL developers reported bugs in which offline data checksum changes can leave standbys with mismatched or unreadable checksum state. Discussion on pgsql-hackers centers on patches to correct the state machine so replicas do not silently diverge. Operators running checksum-enabled clusters should watch the outcome because incorrect standby state can block recovery or produce false integrity failures.

QEMU 9pfs FID path mutation fixed for CVE-2026-93834

A stable-11.0.5 backport moves 9pfs FID path mutation onto the main thread only, closing CVE-2026-93834. The change prevents worker-thread races that could corrupt path state. Users of 9p filesystem passthrough in QEMU guests gain a concrete security fix in the upcoming stable release.

QEMU xHCI timer reentrancy guard closes use-after-free

Another stable-11.0.5 patch sets a reentrancy guard in xHCI timer functions to address CVE-2026-17588. The guard stops use-after-free conditions that arise when timer callbacks re-enter the device model. Hosts exposing USB xHCI controllers to guests receive a targeted memory-safety correction.

QEMU drafts new AI-generated contribution policy

An RFC patch series proposes a revised policy requiring metadata for AI-generated contributions alongside the existing DCO sign-off. Debate on qemu-devel examines legal implications and practical enforcement. Project contributors and downstream packagers need clarity on how AI-assisted patches will be accepted going forward.

Crashes after unfinished concurrent partition detach

pgsql-hackers examined crashes that occur when DETACH PARTITION CONCURRENTLY is interrupted before completion, including a PostgreSQL 19 regression in publication handling. Patches aim to make the detach path robust against partial failure. Sites that rely on concurrent partition management and logical replication have a direct interest in the fix.

Replication slot invalidations must persist before publish

A patch series ensures slot invalidations are written to disk before their state is published in shared memory. The ordering change prevents restart inconsistencies that could leave replicas with stale or missing invalidation records. Replication-heavy deployments benefit from stronger durability guarantees around slot lifecycle events.

Single-binary qemu-system multi-target link proposal

Version 3 of a large patchset proposes linking multiple QEMU targets into one qemu-system binary, requiring widespread symbol, QOM, and TypeInfo adjustments. The work seeks to simplify builds and distribution at the cost of extensive internal refactoring. Embedders and distribution maintainers evaluating binary size and packaging strategies should follow the series.

QEMU stable 11.1.2 patch queue frozen

The stable-11.1.2 round-up posts ninety-two patches with freeze already in effect after 2026-09-26. The queue includes the xHCI use-after-free fix and other accumulated corrections. Users planning upgrades to the 11.1 stable line can expect the security and reliability items already discussed in the tree.