Kernel UAF fixes, BPF unwind, and ext4 iomap
Security work dominated the day, with use-after-free hardening in filesystem pathwalks and network skbs alongside BPF exception support for Rust. Proposals also advanced ext4 iomap conversion, RISC-V cache correctness, and KVM memory providers.
RCU pathwalk UAF fixes for multiple filesystems
Christian Brauner posted an eight-patch series fixing use-after-free bugs during RCU pathwalks. The changes ensure RCU grace periods finish before freeing superblock data in ext4, afs, v9fs, tracefs, ntfs3, and the generic casefold path. These races can corrupt memory during ordinary pathname lookups, so the series matters for filesystem stability.
Portable agent skills and Fixes tag attribution
Sasha Levin proposed an agents directory plus an LLM skill aimed at producing correct Fixes tags. Greg Kroah-Hartman, Ted Ts'o, Konstantin, and others debated directory placement and mailing-list conventions across seventeen messages. Accurate Fixes tags improve stable-tree backport tracking and reduce review friction.
SKB data isolation into separate kmem buckets
Kees Cook sent version 6 of a net-next series that places skb data-area allocations into their own kmem_buckets. The patches add memcg and DMA fixes along with KUnit tests. Isolating these allocations hardens the networking stack against use-after-free attacks.
BPF exception cleanup landing pads on unwind
A twenty-four-patch bpf-next series (v10) adds verifier and JIT support so bpf_unwind can execute exception cleanup landing pads. The work enables Rust panic paths inside BPF programs. It advances safe exception handling for BPF and Rust integration.
Ext4 buffered I/O conversion to iomap
Version 7 of a thirty-one-patch series switches ext4 regular-file buffered I/O to the iomap framework. New disksize-pending handling appears, and a syzbot WARNING was reported during review. The conversion aligns ext4 with modern VFS I/O infrastructure.
RISC-V icache flush skip on shared exec folios
A patch corrects a regression in which a per-mm icache flush sets PG_dcache_clean, letting a second mm map the same executable folio with stale instructions on another hart. Proper instruction-cache maintenance is required for multi-hart correctness. The fix restores the necessary flush behavior.
get_maintainer.pl treats THE REST as fallback only
A patch changes get_maintainer.pl so THE REST (LKML) is added only as a true fallback instead of an always-present recipient. Eighteen messages from eleven participants examined the resulting address lists. Cleaner recipient selection reduces list noise for maintainers.
KVM alternative providers for guest_memfd
An RFC series proposes a generic mem_provider interface so PFNMAP drivers can back guest_memfd and iommufd mappings. Six participants discussed the design over thirty-four messages. The change would widen the ways guest memory can be supplied in virtualization setups.