{"slug": "sashiko-has-reviewed-191000-linux-kernel-patches-and-463-cves-this-year-cite-it", "title": "Sashiko Has Reviewed 191,000 Linux Kernel Patches, and 463 CVEs This Year Cite It", "summary": "Google's Sashiko AI code-review system has completed more than 191,000 patch reviews across 99 Linux kernel mailing lists in under a year, and 463 Linux kernel CVEs assigned this year cite the tool, Google engineer Roman Gushchin reported at the Linux Plumbers Conference 2026 in Prague. Sashiko, written in Rust and hosted at sashiko.dev on Gemini 3.1 Pro with Google paying for compute, has drawn more than 7,600 replies from over 1,100 kernel developers, and its upstream commits total 1,277 plus another 1,567 in linux-next. Gushchin's March benchmark had Sashiko catching 53% of bugs in 1,000 recent upstream issues carrying \"Fixes:\" tags, up from a hit rate in the low 30s two months earlier.", "body_md": "**Google’s agentic kernel reviewer is closing in on its first birthday with numbers that are hard to wave away.**\n\nSashiko, the AI code-review system Google engineers built for the Linux kernel, has now worked through more than 191,000 patch reviews across 99 kernel mailing lists in less than a year of running. Google engineer Roman Gushchin gave the status update at the [Linux Plumbers Conference 2026 in Prague](https://lpc.events/event/20/contributions/2645/) this week, and [Phoronix](https://www.phoronix.com/news/Sashiko-Linux-AI-Metrics) has the figures from the talk.\n\nThe review count makes the headline, but it is not the interesting number. That would be this one: 463 Linux kernel CVEs assigned this year cite Sashiko. Add 1,277 upstream commits and another 1,567 in linux-next that reference the tool, and it stops looking like an experiment people put up with and starts looking like part of the plumbing.\n\n## What it actually does\n\nGushchin first [announced Sashiko on the kernel mailing list](https://lkml.iu.edu/hypermail/linux/kernel/2603.2/03802.html) in March. It is written in Rust, runs as a hosted service at sashiko.dev, and picks up patches posted to LKML and a growing list of subsystem lists. Each change goes through a multi-stage review that examines it from several angles, loosely modelled on how a human maintainer reads a patch. It builds on open review prompts originally written by Chris Mason, though it uses its own protocol. The public service runs on Gemini 3.1 Pro with Google paying for the compute, but the code supports other models, and the project has been handed to the Linux Foundation under the Apache 2.0 license.\n\nThe agent does not just stare at the diff. Gushchin’s numbers include more than 19 million autonomous Git lookups, which is the tool going off to dig through history and surrounding code to work out whether a change actually breaks something.\n\nBack in March, Gushchin’s own benchmark had Sashiko catching 53% of the bugs in a set of 1,000 recent upstream issues that carried “Fixes:” tags. Every one of those bugs had already slipped past human reviewers, which is rather the point. A couple of months before that, the hit rate sat in the low 30s.\n\n## Developers are talking back\n\nAdoption among maintainers is what decides whether any of this sticks, and the engagement figures are big too: more than 7,600 replies from over 1,100 kernel developers responding to Sashiko’s reports. Not all of those are thank-you notes. At launch, Gushchin was upfront that false positives had not been measured properly, and that while the reviews were rarely flat-out wrong, they could nitpick or bury a real problem under low-value remarks. Some kernel developers remain uneasy about AI-generated review traffic landing on mailing lists that are already overloaded.\n\nNext on the to-do list: a local review mode that runs from the terminal, a persistent bug database, and Sashiko reviewing changes to its own code.\n\n## Why it matters beyond the kernel\n\nThe CVE count lands at an interesting moment. The kernel became its own CVE numbering authority in 2024 and has been issuing identifiers at a pace distributions have openly grumbled about, while AI tools are now turning up bugs faster than ever, as this week’s batch of a dozen AI-assisted X.Org Server and XWayland vulnerabilities showed. A reviewer that catches problems before they are merged is the better version of that story. A flaw flagged on the mailing list is one that never ships in the kernel running on your desktop, your NAS or somebody’s cloud server.\n\nWhether the false-positive rate holds up as Sashiko spreads to more subsystems is the open question. A thousand-plus developers bothering to reply suggests that, for now, the signal is worth the noise.", "url": "https://wpnews.pro/news/sashiko-has-reviewed-191000-linux-kernel-patches-and-463-cves-this-year-cite-it", "canonical_source": "https://hwbusters.com/news/sashiko-has-reviewed-191000-linux-kernel-patches-and-463-cves-this-year-cite-it/", "published_at": "2026-10-08 12:21:27+00:00", "updated_at": "2026-10-08 13:50:28.859864+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-agents", "ai-tools", "developer-tools", "ai-safety"], "entities": ["Sashiko", "Google", "Linux kernel", "Roman Gushchin", "Linux Plumbers Conference 2026", "Gemini 3.1 Pro", "Linux Foundation", "Phoronix"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/sashiko-has-reviewed-191000-linux-kernel-patches-and-463-cves-this-year-cite-it", "markdown": "https://wpnews.pro/news/sashiko-has-reviewed-191000-linux-kernel-patches-and-463-cves-this-year-cite-it.md", "text": "https://wpnews.pro/news/sashiko-has-reviewed-191000-linux-kernel-patches-and-463-cves-this-year-cite-it.txt", "jsonld": "https://wpnews.pro/news/sashiko-has-reviewed-191000-linux-kernel-patches-and-463-cves-this-year-cite-it.jsonld"}}