Skip to content

virtio-linux + virtio-kernel-raw: 6.12.43 -> 6.12.94 (latest 6.12 LTS) - #311

Merged
twitchyliquid64 merged 1 commit into
mainfrom
virtio-linux-6.12.94-lts
Jul 1, 2026
Merged

virtio-linux + virtio-kernel-raw: 6.12.43 -> 6.12.94 (latest 6.12 LTS)#311
twitchyliquid64 merged 1 commit into
mainfrom
virtio-linux-6.12.94-lts

Conversation

@bryan-minimal

Copy link
Copy Markdown
Member

Security freshness: virtio guest kernel 6.12.43 → 6.12.94 (latest 6.12 LTS)

The virtio microVM guest kernel was ~50 LTS patch releases behind the latest 6.12 longterm. We deliberately keep the kernel CVE-dark (adding linux:linux_kernel provenance would flood the digest with ~1,430 mostly-inapplicable driver/subsystem CVEs a virtio guest never compiles — see #400 for the long-term strategy), so riding the latest 6.12 LTS backport stream is the kernel's security posture. This bump is that move.

Changes

  • virtio-linux 6.12.43 → 6.12.94 (version + sha256).
    • Tarball staged at gs://minimal-staging-archives/linux-6.12.94.tar.xz.
    • sha256 = e998a232b9418db3301cb58468e291a4f41d6ab8306029b30d991f56251dc8d2verified against kernel.org's signed sha256sums.asc (not just self-computed).
  • virtio-kernel-raw version 6.12.43 → 6.12.94 — it only decompresses virtio-linux's kernel, so its version tracks in lockstep.
  • virtio-linux-detonation (6.18.36, a separate mainline detonation kernel) — unchanged.

Reviewer notes

  • This is a real kernel rebuild — the buildbot needs to confirm both packages build (a 6.12.43→6.12.94 LTS step within the same series; no config-affecting changes expected, but worth a green build before merge).
  • Related: feat(ci): use minimal check GHA workflow #400 tracks the long-term kernel-vuln strategy (config-scoping / VEX / LTS-freshness-as-signal). This PR is the interim "stay on latest LTS" action.

🤖 Generated with Claude Code

The virtio microVM guest kernel was ~50 LTS patch releases behind. We
deliberately do NOT per-CVE-track the kernel -- it's CVE-dark by design, since
linux:linux_kernel would flood the digest with ~1,430 mostly-inapplicable
driver/subsystem CVEs a virtio guest never compiles (see #400). Riding the
latest 6.12 LTS backport stream IS the kernel's security posture, so bump it.

- virtio-linux 6.12.43 -> 6.12.94. Tarball staged at
  gs://minimal-staging-archives/linux-6.12.94.tar.xz; sha256 e998a232...
  verified against kernel.org's signed sha256sums.asc.
- virtio-kernel-raw tracks virtio-linux's version (it only decompresses that
  kernel), bumped in lockstep.
- virtio-linux-detonation (6.18.36, a separate mainline detonation kernel)
  left unchanged.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You’ve reached a temporary PR review limit under our Fair Usage Limits Policy.

Your recent review volume is higher than typical usage, so adaptive limits are currently applied.

Next review available in: 7 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: af1e2a35-3243-4968-9434-3bf219f3c72b

📥 Commits

Reviewing files that changed from the base of the PR and between 4396552 and 3a352ec.

📒 Files selected for processing (2)
  • packages/virtio-kernel-raw/build.ncl
  • packages/virtio-linux/build.ncl
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch virtio-linux-6.12.94-lts

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants