Kernel networking fixes and memory path proposals
Security and networking patches led the day, with fixes for IPsec ESP nonce handling and a regression in bnxt_en DMA paths. Memory management work continued around huge-page swap entries, cgroup swap semantics, and ext4 buffered I/O conversion to iomap.
xfrm ESP IV and ESN authentication fixes
A seven-patch series posted to netdev addresses AES-GCM nonce reuse and ESN sequence bugs in the Linux kernel xfrm ESP offload paths for IPv4 and IPv6. The changes correct IV generation and authentication handling that could undermine IPsec confidentiality and integrity. Readers running encrypted tunnels or hardware offload should track the series for correctness under concurrent traffic.
QUIC transport infrastructure in net-next
Version 16 of a fifteen-patch set introduces core QUIC infrastructure into the kernel networking stack, covering sockets, crypto, streams, connection IDs, multipath, and congestion control. The series carries acknowledgments from netdev maintainers. Adoption would give in-kernel consumers a native transport without userspace QUIC stacks for every flow.
AF_XDP zero-copy via page-pool providers
An RFC on bpf proposes integrating AF_XDP UMEM as a page-pool memory provider so drivers can drop duplicated RX allocation paths. The design aims to let page_pool users feed zero-copy sockets directly. High-throughput packet processing stacks stand to reduce copy overhead and driver complexity if the approach lands.
bnxt_en IOMMU DMA fault regression
A bisected regression from commit 447cbe95ebb9 triggers IOMMU DMA faults on macvlan and vlan setups with the bnxt_en driver after an LL_RESERVED_SPACE change. A fix using skb_put_padto() has been posted and tested by participants. Operators of Broadcom NICs in virtualized or tagged environments need the correction to avoid silent DMA failures.
PMD-level swap for anonymous THPs
Version 8 of a thirty-patch mm series adds PMD-level swap entries so anonymous transparent huge pages keep huge mappings across swap-out and swap-in instead of splitting to PTEs. The work reduces fragmentation and TLB pressure for large anonymous regions. Workloads that thrash under memory pressure benefit from preserving huge-page contiguity.
kobject_uevent OOB read fix
A patch corrects an out-of-bounds read in kobject_action_type() caused by a strncmp length mismatch on a user buffer that may contain an embedded NUL. The bug sits in the uevent path used for hotplug and device notifications. The change closes a straightforward bounds error reachable from userspace triggers.
Debate on virtualized swap cgroup semantics
Kernel mm developers continue a heated discussion on redefining memory.swap cgroup accounting for virtualized and zswap entries. Google engineers warn that semantic changes risk breakage for existing v1 and v2 deployments. Container and cloud operators relying on precise swap charge behavior have a direct stake in the outcome.
ext4 buffered I/O conversion to iomap
Version 6 of a thirty-one-patch series moves ext4 regular-file buffered I/O from buffer_head to iomap, tackling ordering, i_disksize, and data=ordered edge cases. The conversion aligns ext4 with modern filesystem I/O paths already used elsewhere in the tree. Filesystem and storage developers gain cleaner writeback semantics once the remaining ordering issues are settled.