freenode

← digests

Kernel: hazard pointers, ESP crypto, SCSI bounds

Kernel & Low-Level2026-10-07

Kernel traffic on 2026-10-07 focused on concurrency primitives, IPsec and virtio security fixes, and a bnxt_en regression, with further work on IOMMU live update and arm64 confidential compute. Several series moved from proposal toward review or merge on the core and netdev lists.

Hazard pointer series under review

A four-patch series updating hazard pointers landed on the linux-kernel list. Linus Torvalds examined the ptr_eq implementation and address-dependency handling across the thirty-message thread. Lock-free algorithm maintainers have concrete review feedback to track.

SCSI target keeps command bytes in SG

An eight-patch series for the SCSI target core confines command bytes inside the scatter-gather list. The changes close out-of-bounds SG accesses that KASAN flagged as use-after-free under vhost-scsi page-per-SG layouts. Hosts that export SCSI targets over virtio gain tighter bounds checking.

XFRM ESP IV generation and ESN fixes

A seven-patch xfrm series corrects ESP IV generation and ESN authentication. It addresses AES-GCM nonce reuse and ESN sequence bugs in the IPv4 and IPv6 offload paths. IPsec deployments that rely on hardware offload should treat the series as a security-relevant correction.

bnxt_en DMA faults after LL_RESERVED_SPACE change

A bisected regression from commit 447cbe95ebb9 triggers IOMMU DMA faults on macvlan and vlan configurations with bnxt_en. A fix that switches to skb_put_padto() has been posted and tested in the thirteen-message thread. Broadcom NIC users and macvlan operators are the immediate audience.

Virtio-net always dissects untrusted GSO

A three-patch v3 series forces GSO packet dissection inside __virtio_net_hdr_to_skb(). It closes a bypass of untrusted GSO flow dissection and repairs a u16 truncation bug in __skb_flow_dissect; the work has already merged to net.git. Virtualization and container networking paths receive the hardened behavior.

IOMMU state preservation for live update

Version 5 of an eighteen-patch series adds live-update state preservation to the IOMMU layer. The patches cover Intel VT-d and devices attached through iommufd. Kexec-based live kernel updates that must retain DMA mappings gain the missing plumbing.

KVM arm64 Realm CCA plumbing

Version 22 of a twenty-three-patch KVM arm64 series supplies basic Realm and CCA plumbing. It introduces VM-type abstractions needed for confidential-compute guests. Arm CCA implementers following KVM integration have a new baseline to review.

skbuff converts BUG_ONs to warnings

A nine-patch net-next series turns most BUG_ON() checks in skbuff.c into WARN_ON_ONCE() plus error returns. Seventeen assertions are relaxed, together with two minor accompanying fixes. The change lowers the severity of skbuff invariant failures under production load.