Watch queue race, pathwalk UAFs, and low-level proposals
Security patches for a watch queue race and filesystem RCU pathwalk use-after-frees led the day's kernel traffic. Networking, BPF, memory management, and architecture series also advanced through multiple revisions.
Missing lock in watch_queue_set_size()
A patch fixes racy stores in watch_queue_set_size() that let post_one_notification() dereference NULL. The race is reachable from unprivileged keyctl and ioctl paths and can trigger an oops. Systems that expose key notification watches should treat the fix as a priority once it lands.
RCU pathwalk UAFs across filesystems
Christian Brauner posted an eight-patch series that closes use-after-free windows during RCU pathwalks. The changes cover ext4, afs, v9fs, tracefs, ntfs3, and the generic casefold path by requiring RCU grace periods before superblock data is freed. Concurrent path lookup on those filesystems is the practical exposure.
fwnode PCS support for phylink
Version 18 of a twelve-patch net-next series adds a fwnode producer-consumer API for PCS devices. It also introduces an internal phylink PCS list and late attach and remove handling. Drivers that bind PCS through firmware nodes gain a cleaner registration model.
bnxt_en DMA faults after LL_RESERVED_SPACE change
A bisected regression from commit 447cbe95ebb9 causes IOMMU DMA faults on macvlan and vlan configurations with bnxt_en. A fix that switches to skb_put_padto() has been posted and tested. Operators of Broadcom NICs in virtualized or stacked networking setups should watch for the merge.
AF_XDP zero-copy via page-pool providers
An RFC fifteen-patch series proposes integrating AF_XDP UMEM as a page-pool memory provider. The aim is to drop duplicated RX paths that page_pool drivers currently maintain for zero-copy. High-throughput packet processing stacks stand to simplify their receive side if the approach sticks.
BPF exception cleanup on bpf_unwind()
Version 10 of a twenty-four-patch bpf-next series adds verifier and JIT support for exception cleanup landing pads when bpf_unwind() runs. The work enables Rust panic paths inside BPF programs. BPF and Rust-for-Linux developers gain structured cleanup on unwind rather than abrupt termination.
PMD-level swap entries for anonymous THPs
Version 8 of a thirty-patch series introduces PMD-level swap entries for anonymous transparent huge pages. Swapped THPs can retain huge mappings across swap-out and swap-in instead of being split to PTEs. Memory-heavy workloads that rely on THP contiguity should track the series.
seccomp filter support on sparc64
A two-patch v2 series adds SECCOMP_FILTER to sparc64. The architecture was one of the last major ones still lacking the feature, aside from alpha. Distributors and users still maintaining sparc64 kernels obtain the standard syscall filtering interface.