Kernel code removals driven by LLM-created security reports
TL;DR Highlight
Linux kernel maintainers are removing legacy drivers—ISA, PCMCIA, AX.25, ATM, and ISDN—after AI-generated security bug reports overwhelmed them, demonstrating a drastic response to unmanageable code.
Who Should Read
Linux kernel contributors, open-source project maintainers, or developers utilizing or considering LLM-based automation tools for vulnerability detection.
Core Mechanics
- Linux kernel maintainers proposed patches to remove ISA/PCMCIA Ethernet drivers, parts of the PCI driver, the AX.25 and amateur radio subsystem, ATM protocols and drivers, and the ISDN subsystem.
- The removal reason isn't technical flaws, but a surge in security bug reports automatically generated by LLMs. Maintainer comments explicitly state the need to remove code to protect mental health due to the inability to process AI-generated reports.
- AX.25 (amateur radio packet communication protocol) and related HAM radio drivers already received many bug reports from syzbot (kernel automated fuzzing tool), and the influx of AI reports finalized the removal decision.
- Most of the removed code are drivers or protocols for legacy hardware primarily used before the 2010s. ATM has been replaced by MPLS/MetroE, ISDN is virtually obsolete, and laptops with PCMCIA slots haven’t been produced since 2008.
- These codes were in a ‘non-maintained state’ but were included in a large project (Linux kernel), giving the illusion of maintenance. Had they been independent projects, their inactive status would have been apparent years ago.
- The validity of bug reports generated by LLMs is debated. Some linked emails highlight the issue of ‘junk reports’ from AI increasing review burden without adding value.
- The removed code can potentially be continued as out-of-tree kernel modules or userspace implementations. The HAM radio community has already begun discussing a userspace protocol implementation written in a more modern language.
Evidence
- "HAM radio community users expressed regret over the AX.25 removal, and a thread explaining the decision’s background appeared on the linux-hams mailing list, alongside optimistic views about a modern userspace protocol becoming the new standard."
How to Apply
- When integrating LLM-based security scanners or automated bug reporting tools into open-source projects, a report quality filtering layer is essential. Failing to validate AI-generated issues can overwhelm maintainers and lead to code removal, as seen in this case.
- If your project includes legacy drivers or modules that are effectively unmaintained, assess their maintenance status before deploying LLM-based vulnerability scanners. AI tends to report more pattern-based vulnerabilities in older code, potentially flooding the issue tracker with noise.
- If you operate industrial environments requiring legacy hardware support in kernels or system software, verify whether your drivers are on the removal list (ISA, PCMCIA, ATM, AX.25, ISDN) and prepare for out-of-tree module maintenance or userspace alternatives.
Terminology
Related Papers
Show HN: Mindwalk – Replay coding-agent sessions on a 3D map of your codebase
Claude Code나 Codex 같은 AI 코딩 에이전트가 세션 중 코드베이스의 어떤 파일을 탐색하고 수정했는지를 3D 지도 형태로 시각화해서 재생해주는 로컬 도구다. 에이전트가 작업을 어떻게 이해했는지 한눈에 파악할 수 있다.
Ghost Font: A font that humans can read but AI cannot
움직임(모션)을 이용해 글자를 표현해서 AI 모델이 정적 이미지 분석으로는 메시지를 해독하지 못하게 막는 실험적 프로젝트인데, 커뮤니티에서는 이미 GPT-5.6, Claude Opus 등으로 해독에 성공한 사례가 속출해 실효성 논쟁이 뜨겁다.
GPT-5.6, Grok 4.5, Claude, and Muse Spark build the same 4 apps
12개 LLM 모델에게 레이캐스터 미로, 루빅스 큐브, 계산기, Game of Life 앱을 각각 5번씩 만들게 해서 성공률·비용·속도를 비교한 실전 벤치마크다. GPT-5.6 Sol이 전반적으로 가장 일관된 결과를 냈고, Grok 4.5는 가성비 면에서 눈에 띄었다.
Benchmarking coding agents on Databricks' multi-million line codebase
Databricks가 자사 실제 코드베이스를 기반으로 여러 AI 코딩 에이전트의 성능과 비용을 직접 측정했고, 모델 토큰 가격과 실제 태스크 비용이 전혀 다르다는 점, 그리고 오픈소스 모델이 이제 최상위 수준에 도달했다는 점을 확인했다.
Estimating Uncertainty from Reasoning: A Large-Scale Study of Multi- and Crosslingual MCQA Performance in LLMs
LLM이 저자원 언어 질문을 받을 때 영어로 추론하게 하면 불확실성 추정 성능이 고자원 언어 수준으로 올라온다.
LLM-as-a-Verifier: A General-Purpose Verification Framework
LLM의 토큰 확률 분포를 활용해 discrete 점수 대신 continuous 점수를 뽑아내면, 추가 학습 없이 코딩·로봇·의료 에이전트 평가 정확도를 SOTA로 끌어올릴 수 있다.