
Five OSS authors on LLM-caught kernel bugs, a 25x CI queue, and maintainers as attack targets
Five fresh maintainer signals on what has to absorb agent-added throughput: LLM-caught kernel error paths, a CI queue that grew 25 times, Rust maintainers as attack targets, a GPU driver built with AI, and instruction changes that must not break the prompt cache.
Writing software is no longer where the delay is. The five statements this week each describe what happens further along. Linus Torvalds published Linux 7.3-rc4 and found filesystems taking a larger share of an unusually heavy cycle, much of it error-path bugs that language models are good at spotting 1. Addy Osmani put numbers on Anthropic's CI rebuild, where job volume grew 25 times in six months 2. Simon Willison warned that the targets are the people who hold publishing rights to Rust's crates, and named the one defense he thinks is worth having today 3. antirez described how parts of the open-source community greeted a Linux GPU driver for Apple's M4 written with AI assistance 4. Armin Ronacher shipped an agent-harness release that changes instructions in the middle of a conversation and told users where he expects it to break 5.
Five choices in one view
| Author | Fresh signal | Stance in the source | Design question | Question for a tech lead |
|---|---|---|---|---|
| Linus Torvalds, creator and lead maintainer of the Linux kernel | September 20 announcement of Linux 7.3-rc4 1 | Machine-found error-path cleanups are now a large share of kernel patches, and they stay invisible in normal use until one of them is yours. | How much low-severity, machine-found defect traffic can a fixed release cadence take? | At what severity does a machine-found defect delay a release in your project, and who makes that call? |
| Addy Osmani, engineer on Anthropic's Claude Code team | September 14 post on Anthropic's CI scaling and the engineering article it links 26 | Code stopped being the bottleneck; test selection and CI capacity took its place, and quick fixes now buy days where they once bought quarters. | Which part of the pipeline has to become stateless and horizontally scalable first? | What is your quarterly CI job growth, and which component still keeps its state in one process? |
| Simon Willison, co-creator of Django and author of Datasette | September 17 warning about the campaign against Rust maintainers 3 | The human network behind a dependency graph is the attack surface, and delaying new releases is the defense that works today. | How do you defend an ecosystem whose entry point is a maintainer's laptop? | Which dependencies rely on one person being hard to trick, and how long is your cooldown before taking a new version? |
| antirez (Salvatore Sanfilippo), creator of Redis and of the DwarfStar inference engine | September 16 post on the response to an AI-assisted M4 GPU driver 4 | Using these tools to open closed hardware serves the movement's own goals, and treating the author as the problem works against them. | What counts as legitimate machine-assisted work in an open-source project? | If a contributor hands you a working driver or parser built mostly by an agent, what provenance do you demand before merging it? |
| Armin Ronacher, creator of Flask and a developer of the Pi coding agent | September 19 post on Pi 0.86.0 and the release notes behind it 57 | Changing system instructions mid-conversation is the risky change in an agent harness, so the release ships a way to report what it breaks. | How do you alter an agent's instructions or tools mid-session without discarding the prompt cache? | Does your harness keep the cached prefix when instructions change, and do users have a path to report the fallout? |
Linus Torvalds: the release candidate that is quietly heavier
Linus Torvalds announced Linux 7.3-rc4 on September 20, 2026, in a message to the linux-kernel mailing list 1. A release candidate is the weekly checkpoint where the kernel tree is frozen to fix what the merge window let in; 7.3 is scheduled to ship in October, so this is roughly the middle of the cycle 8.
Torvalds opened with what he found interesting rather than with the layout of the patch:
"We all know the drill by now: "it's big, yadda yadda". What I do find a bit interesting is that filesystems continue to be quite a noticeable part of the whole "it's bigger than usual". This time around it's smb and ntfs, so it's not like it's one particular filesystem, it's just been that filesystems in general seem to have been getting more attention recently." 1
The patch splits roughly into a third drivers, a third filesystems and networking, and a third architecture fixes and tooling, and most of the individual changes are small 1. The contents include x86 and x86_64 fixes, support for several new game controllers, two Btrfs bugs, and a silent user-space data-loss bug that had survived since 2023 8.
Where the assistance shows up, according to Torvalds, is in error handling:
"There's a lot of error path cleanup stuff, which various LLM's seem to be pretty good at catching, but that typically isn't going to be all that noticeable in normal use. But hey, if any of the issues hit you, you are going to care." 1
Error paths are the branches a program takes when something fails, and they run so rarely that a wrong cleanup there can sit unnoticed for years. The kernel's problem is therefore a triage problem: a growing stream of real but low-consequence defects arriving inside a cadence that does not grow with it. Torvalds' own summary is that the volume is remarkable and the individual defects mostly are not.
Addy Osmani: the constraint moved to CI
Addy Osmani, an engineer on Anthropic's Claude Code team, described on September 14, 2026 what agent-written code did to his employer's build pipeline 2. The claims come from an engineering article Anthropic published the same day, and the numbers are unusually specific: Claude authors 80% of Anthropic's code, engineers ship eight times as much code per quarter as they did between 2021 and 2025, the number of tests in the codebase grew tenfold, and CI job volume rose 25-fold in six months 6.
Loading content card…
The component that broke is a test impact analysis service: one part listens to every CI run and records results, another reads that history and decides which tests a given pull request needs to run 6. The service was patched three times before it was rebuilt. Doubling the cores bought 70 days. Splitting the listener so each package had its own worker bought 29 days. Restarting the process daily bought less than a day, and restarts left the listener lagging far enough behind that large batches of test results were never recorded 6.
The lesson the article draws is about planning, not about any one technique:
"The point is that each of these techniques bought a fraction of the time they did a year ago." 6
The rebuild gave the service an in-memory data store, with listener workers appending results to a journal and a separate consumer folding that journal into per-test history every few seconds. Workers hold nothing in memory, so they scale horizontally. One engineer took three weeks for the redesign, against a quarter a year earlier 6. The advice that follows is to size a system for 25 times its current load within two quarters and to keep state out of the process from the start 6.
Simon Willison: the maintainer is the entry point
Simon Willison, co-creator of Django and author of Datasette, flagged a security warning on September 17, 2026, from Adam Harvey and the crates.io security team 3. The warning describes an active campaign against people who can publish to popular Rust crates, and the method runs through a video call 9.
The approach is social in both directions. Attackers build plausible company profiles, including LinkedIn presences that survive a quick check, then open a call about a job, a project, or a contract. On the call the target is asked to install something presented as a missing audio codec, or to paste a command that arrived on the clipboard 9. A June campaign of the same shape targeted prominent Rust developers, and in August the
arrayref crate was briefly compromised this way 10. The Rust team notes that the style is known to be used by the DPRK and has been reported outside the Rust community as well 9.Willison's reading of the attack is that it aims at a structural weakness rather than at a bug:
"Any piece of software that depends on open source (which is almost every piece of software) has a network of human beings who are potential attack vectors - everyone with publishing rights to any of the packages in the dependency network for that software." 3
His recommendation is to accept a delay in exchange for other people's eyes:
"I guess our best defense right now is dependency cooldowns - giving new package releases a few days before upgrading to them, in the hope that supply chain attacks like this will be spotted by someone else." 3
A cooldown policy is a small change with an awkward cost, because it also delays security fixes. Willison links a longer argument for the practice 11. The Rust team's own short-term advice is more basic: treat unsolicited outreach with suspicion, host calls on platforms you control, and re-check that multi-factor authentication is on 9.
antirez: who gets to use the tools
Salvatore Sanfilippo, known as antirez and the creator of Redis, wrote on September 16, 2026 about the reception given to a Linux graphics driver for Apple Silicon written with AI assistance 4. He put his objection in one line:
"Witch hunting level: some guy uses AI to reverse engineer an M4 GPU driver for Linux and part of the community that should be for the open source, for the hacking, for the liberation and freedom is against him." 4
Loading content card…
The work he refers to is Cody Ho and Niklas Sheth's driver for the M4 Mac Mini and MacBook Neo. They report building a fully OpenGL ES 3.0-compliant Linux driver in about a month, against a norm of years, and they wrote it against traces rather than Apple's binaries 12. Ho's account of the method is worth reading for anyone judging what these tools can do on an unfamiliar system: they captured the GPU firmware's state through a hypervisor Ho had built earlier, replayed it, and then had the model rebuild each object in code until nothing was being replayed. "Amazingly, I noticed Codex had good taste regarding when it should poke the hardware some more and when it should just run the hypervisor and capture the state itself," Ho wrote 12.
Ho also records where the model failed and how the failure was repaired: it spent over a week trying to reconstruct compute objects from a 336 MB capture before the pair changed the experiment, booting into single-user mode to capture a small, pure compute trace that the model could then take apart in hours 12. The code is not ready for end users, and the two published their reverse-engineering notes in matching repositories so that others can check how they arrived at it 12.
The question antirez raises is the one an open-source project has to answer for itself: what kind of machine-assisted work counts as contribution, and what evidence of provenance is enough. His answer is that the work of opening closed hardware is the point of the exercise, and that hostility toward the people doing it costs the movement more than it protects.
Armin Ronacher: changing instructions mid-session
Armin Ronacher, creator of the Flask web framework and a developer of the Pi coding agent, announced Pi 0.86.0 on September 19, 2026, and attached his own warning to it 5. Pi is a terminal-based coding agent built by Earendil, the company Ronacher works for 7.
The headline feature of the release is that an agent's system prompt and its tool set can now change in the middle of a session, with the change recorded in the transcript so that it survives resuming a session or navigating back to an earlier branch 7. Ronacher's post says where he expects it to hurt:
"This definitely has chances of regressions because of the mid-conversation system messages. We baked it for a while, but not many run it from main. If you discover problems, please, please let us know! (There is also /bug now)" 5
The reason this feature is delicate is prompt caching. Providers bill and run faster when the beginning of a conversation is byte-identical to the last request, and most ways of editing an agent's instructions invalidate that prefix, so the whole conversation gets reprocessed 7. The release notes state that instruction and tool changes preserve cached prefixes on models that support it, and add a second piece of cache management: warming, which refreshes a prompt cache during long tool runs and, optionally, while the session sits idle 7.
Two smaller items in the same release say something about what an agent harness now has to carry. Compaction budgets became configurable per model, with reserved and recent-token budgets set separately for each one. And
/bug collects environment, model, provider, extension and settings metadata with secrets redacted, then uploads the report or exports it as an archive 7. A harness that changes how it talks to a model is also a harness that has to help users describe what the change broke.Questions for the next design review
- Release triage: at what severity does a machine-found defect delay a release in your project, and who makes that call?
- CI headroom: what multiple of today's CI job volume could your pipeline absorb within two quarters, and which component still keeps its state in a single process?
- Publishing rights: which of your dependencies would require one person to be tricked before malware reached your build, and how long is your cooldown before you take a new version?
- Provenance: if a contributor hands you a driver, parser, or adapter built mostly by an agent, what evidence of how it was produced do you require before merging it?
- Session integrity: when your agent's instructions or tool set change mid-session, does the cached prefix survive, and do users have a path to report what broke?
References
- 1
- 2
- 3Be alert: targeted attacks on prominent Rustaceans
simonwillison.net
- 4
- 5
- 6Agentic coding is straining CI
claude.com
- 7Release: Pi 0.86.0
pi.dev
- 8
- 9Be alert: targeted attacks on prominent Rustaceans, Rust Blog
blog.rust-lang.org
- 10Supply chain attack on arrayref
blog.rust-lang.org
- 11We should all be using dependency cooldowns
blog.yossarian.net
- 12
This story was produced automatically by a channel. One sentence is all it takes for Neodrop to keep producing for you.
