freenode

← digests

IPsec fixes and major kernel subsystem series

Kernel & Low-Level2026-10-01

Kernel traffic on 2026-10-01 focused on security repairs for IPsec and netfilter plus large proposal series touching filesystems, virtualization, crypto, and display. Several multi-dozen patch sets advanced through review while maintainers debated design tradeoffs.

xfrm ESP IV generation and ESN authentication

A seven-patch series posted to netdev corrects ESP IV generation and ESN authentication flaws in the xfrm subsystem. The changes target AES-GCM nonce reuse and ESN authentication errors that appear in both IPv4 and IPv6 offload paths. Correct nonce handling is essential for IPsec confidentiality and integrity on hardware-accelerated paths.

Hazard pointer updates

A four-patch hazard pointer series landed on linux-kernel and drew extended discussion among seven participants. Linus Torvalds examined the ptr_eq implementation and the handling of address dependencies. The work refines a concurrency primitive used across multiple kernel subsystems.

nf_tables netdev event UAF backport

A use-after-free fix for nf_tables_netdev_event binding-chain handling was requested for the 6.12, 6.6, and 6.1 stable trees. Testers confirmed the patches before the stable maintainers began integration. The defect affects netfilter chain lifetime management when network devices change state.

ext4 buffered I/O conversion to iomap

Version 6 of a 31-patch series converts ext4 regular-file buffered I/O from buffer_head to iomap. The patches address write ordering, i_disksize updates, and data=ordered mode correctness. Completing the migration removes a long-standing dependency on the older buffer-head path.

s390 arm64 KVM port

The s390 team posted version 8 of a 29-patch series that introduces an arm64 KVM implementation for the architecture. Shared code is marked with ARM64_S390_COMMON and extracted by awk so that arm64 sources can be reused. The approach lets s390 gain KVM features already present on arm64 without full duplication.

AMD hardware-accelerated vIOMMU

AMD submitted version 5 of a 24-patch series adding hardware-accelerated virtualized IOMMU support. The code covers guest command, event and PPR logs together with nested translation. Hardware vIOMMU reduces hypervisor overhead for IOMMU-intensive virtual machines.

AES acceleration library migration

A 20-patch series moves x86 and RISC-V accelerated AES mode implementations into lib/crypto. The relocation eliminates duplicated code and turns the optimized paths on by default. Other architectures can now share the same library entry points.

BPF-based MIPI-DSI panel driver

Maxime Ripard proposed a six-patch BPF-based MIPI-DSI panel driver modeled on HID-BPF so that panel init sequences can be loaded at runtime. Discussion among ten participants on the bpf list centered on device-tree bindings and overall design fit. The approach aims to avoid hard-coding vendor-specific sequences inside the kernel.