logoalt Hacker News

yjftsjthsd-hyesterday at 8:46 PM2 repliesview on HN

> 3. Some of these patches are accepted

> 4. They intervene at this point and reveal that the patches are malicious

> 5. The patches are then not merged

It's not clear to me that they revealed anything, just that they did fix the problems:

> In their paper, Lu and Wu claimed that none of their bugs had actually made it to the Linux kernel — in all of their test cases, they’d eventually pulled their bad patches and provided real ones. Kroah-Hartman, of the Linux Foundation, contests this — he told The Verge that one patch from the study did make it into repositories, though he notes it didn’t end up causing any harm.

(I'm only working from this article, though, so feel free to correct me)


Replies

arjieyesterday at 9:34 PM

You know there's a lot of he-said she-said here. The truth is that I was repeating there what they claimed in the paper which is that they intervened prior to merge to mainline.

show 1 reply
jovial_cavalieryesterday at 9:13 PM

I don't believe they revealed that they were hypocrite commits at the time of their acceptance, that was only revealed when the paper was put on a preprint server. But they did point out the problems to maintainers before the changes were mainlined.