- 瑞典旅游-伤心之旅 [2018/09]
- 从张成泽被处决的事情看,有三个方面的意义 [2013/12]
- 鞋子落下来了;MD安德森谢教授不光是裸照 [2018/10]
- --从温家宝家族贪污传闻想起赵紫阳儿子倒彩电 ZT [2012/11]
- 加入混战 【少儿不宜】 [2011/02]
- 终于知道了一点艾未未 [2011/04]
- 男性更年期的臭事 [2013/05]
- 牢骚 多了 [2014/03]
- 庄则栋的故事中俺看到的日本 [2013/02]
- 体味和口臭 [2014/09]
- 雾霾的原因: 风力发电 [2016/12]
- 明大LINUX事件的反思(1)小P点燃导火线 [2021/04]
- 无稽之谈之芦花鸡 [2011/11]
- 铊毒案 后面的评论 ZT [2011/02]
- 瞎说几句薛峰的事情 [2010/07]
- 韩寒 方舟子 和解滨 [2012/01]
- 『自己做事(Do it yourself)可真难啊』学习体会--running title 我的一个星期六 [2010/12]
- 少吃饭、多买名牌 [2011/12]
- 和谐的线; 顺便和稀泥 [2012/01]
- 拿到桌子上 [2012/05]
- 家有闺女初长成 [2011/10]
- 好男人的标准 [2012/06]
- 俺父亲节这一天 [2012/06]
- 为夫为妇当如63 [2011/06]
- 不是一般地高 [2011/03]
- 能说会道 多么美妙 [2011/09]
- 鸡蛋碰石头 [2010/10]
网上GREG 的twitter的回复很热烈,转发回复的很快上百, 大部分都觉得卢老师的研究有道德问题。 几个小时后,技术方面的新闻纷纷扬扬, 都是人云亦云、鹦鹉学舌。
估计卢老师早上醒来,估计看了第一条消息, 应该脑袋里翁的一声。 往下看看, 估计应该长出一口气。
Greg发出禁令的之后两个小时,可能觉得也是过分,把过去所有都剔除? 自己也觉得,过了。 改成重新审查吧。 重审之后有效的接着再用就可以了。 https://lore.kernel.org/lkml/20210421130105.1226686-1-gregkh@linuxfoundation.org/
Wed, 21 Apr 2021 14:57:55 +0200 (这时,是明大早上8点,-0500)I have been meaning to do this for a while, but recent events have finally forced me to do so. 我想干这事有些时候了,最近的事件才促使我下决心Commits from @umn.edu addresses have been found to be submitted in "bad faith" to try to test the kernel community's ability to review "known malicious" changes. The result of these submissions can be found in a paper published at the 42nd IEEE Symposium on Security and Privacy entitled, "Open Source Insecurity: Stealthily Introducing Vulnerabilities via Hypocrite Commits" written by Qiushi Wu (University of Minnesota) and Kangjie Lu (University of Minnesota). 最近发现 通过@umn.edu 提交的补丁 属于恶意提交, 旨在测试内核社区对已知的的恶意更改能不能鉴别出来。 这些提交写在了42届IEEE安全隐私大会的文章里, 文章题目“开源的不安全性:假装好意提交 偷偷导入 弱点” , 作者小吴和卢老师。Because of this, all submissions from this group must be reverted from the kernel tree and will need to be re-reviewed again to determine if they actually are a valid fix. Until that work is complete, remove this change to ensure that no problems are being introduced into the codebase. 有鉴于此, 该组所有提交的补丁要从内核树移除, 重新审查以确定是不是真正有效补丁。 重审完毕之前, 移除是有必要的, 我们不希望它们导入问题。This patchset has the "easy" reverts, there are 68 remaining ones that need to be manually reviewed. Some of them are not able to be reverted as they already have been reverted, or fixed up with follow-on patches as they were determined to be invalid. Proof that these submissions were almost universally wrong. 以下是容易的部分,还有68个需要人工审查。 有些过去早被移除,或引起弱点被其后的补丁修改过了。 这也证明他们很多提交几乎都是错的。I will be working with some other kernel developers to determine if any of these reverts were actually valid changes, were actually valid, and if so, will resubmit them properly later. For now, it's better to be safe. 我将与其他一些内核开发人员一起 ,以确定这些移除是否实际上是有效 更改。如果是,稍后 重新提交。目前,最好安全第一。I'll take this through my tree, so no need for any maintainer to worry about this, but they should be aware that future submissions from anyone with a umn.edu address should be by default-rejected unless otherwise determined to actually be a valid fix (i.e. they provide proof and you can verify it, but really, why waste your time doing that extra work?) 我把我的树捋一遍,其他内核维护人员不用操心,但 要注意,未来所有出自 umn.edu 地址的提交都应该默认拒绝。 除非能证明该提交是一个有效的修复。(比如:他们能提供证据,然后你可以验证,否则为什么浪费时间做 额外的工作?)thanks,greg k-h