I might be wrong, but I believe the "patching after root" refers to the instance where a vendor (e.g. Samsung) removes a vulnerability that was used as a basis for rooting the device, thus requiring developers to find another method. This is possible, but I don't know if it's happened recently.