freenode

← digests

PostgreSQL data-loss fixes, kubectl CVE, QEMU APX and policy

Databases & Infrastructure2026-09-29

PostgreSQL developers circulated patches for silent update loss during concurrent repack and for safer replication slot invalidation ordering. Kubernetes disclosed a Windows kubectl path traversal CVE while QEMU advanced APX emulation, an AI contribution policy, RISC-V board support, and a websocket buffer bound.

Silent update loss in REPACK CONCURRENTLY

A bug report and patch series on the pgsql-hackers list fix silent loss of updates when REPACK CONCURRENTLY rewrites the toast table during logical decoding setup. Committed changes can disappear without error under that race. Operators who combine concurrent table reorganization with logical replication have a concrete data-integrity risk until the series is applied.

kubectl cp path traversal on Windows

Kubernetes published CVE-2026-19444, a medium-severity path-traversal flaw in the Windows kubectl cp implementation that permits arbitrary file writes from untrusted containers. Crafted paths supplied by a container can escape the intended destination. Windows cluster administrators should treat the advisory as actionable and deploy the fixed builds.

QEMU policy on AI-generated contributions

An RFC v3 patch series on qemu-devel proposes a new policy that requires metadata for AI-generated contributions in addition to the usual DCO sign-off. Seven participants debated the legal implications of the disclosure rules. Maintainers and external contributors need clear obligations before machine-assisted patches become routine.

APX support added to QEMU x86 TCG

Paolo Bonzini posted a 17-patch v2 series that implements Advanced Performance Extensions in the QEMU x86 TCG decoder, covering EVEX prefix handling and new instructions such as CCMP, CFCMOV and PUSH2. A separate 30-patch pull request bundles the same APX work with assorted x86 TCG fixes. Once merged, the emulator gains fuller coverage of recent Intel instruction sets.

Safer replication slot invalidation ordering

A patch discussed on pgsql-hackers persists slot invalidations to disk before publishing them in shared memory. The prior ordering could leave shared-memory state ahead of durable storage and produce inconsistencies after a restart. Replication deployments gain more predictable slot recovery behavior.

RISC-V server platform reference board

A v12 five-patch series adds a riscv-server-ref machine to QEMU that emulates the RISC-V server platform specification. Three developers iterated on the board model. Server-class RISC-V bring-up and testing obtain a concrete reference target inside the emulator.

Bound on QEMU websocket client reads

A patch limits growth of the rawinput buffer inside QIOChannelWebsock so that client data cannot expand it without bound. Unchecked growth enabled memory exhaustion through a chardev websocket. Deployments that expose websocket chardevs reduce a straightforward denial-of-service vector by applying the change.