News: 1621621931

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

It took 'over 80 different developers' to review and fix 'mess' made by students who sneaked bad code into Linux

(2021/05/21)


Linux maintainer Greg Kroah-Hartman has sent in a pull request for Linux 5.13 aimed at dealing with grief caused by the antics of some students at the University of Minnesota.

The fixes, for rc3 of version 5.13 of the kernel, included a terse [1]note from Kroah-Hartman:

The majority here is the fallout of the umn.edu re-review of all prior submissions. That resulted in a bunch of reverts along with the "correct" changes made, such that there is no regression of any of the potential fixes that were made by those individuals. I would like to thank the over 80 different developers who helped with the review and fixes for this mess.

That's right. It took more than 80 developers to deal with the fallout from the work of the University of Minnesota compsci students. The ill-judged attempt to subvert the Linux kernel [2]last month resulted in a blanket ban for contributions from anyone with a University of Minnesota email address and a bulk reversion of the commits.

[3]University duo thought it would be cool to sneak bad code into Linux as an experiment. Of course, it absolutely backfired

[4]Yep, the 'Who owns Linux?' case is back from the dead

[5]Lessons have not been learned: Microsoft's Modern Comments leave users reaching for the rollback button

[6]When software depends on a project thanklessly maintained by a random guy in Nebraska, is open source sustainable?

[7]Phoronix noted that out of the 150 or so patches [8]submitted by umn.edu developers over the years, only 37 ended up being reverted in this pull request. Most were either unneeded or " [9]incorrect ."

The request brings to an end the reviewing and cleaning up of the umn.edu patches to the kernel, and we're sure the time of those "over 80 different developers" could have better been used elsewhere.

However, questions remain over processes behind the scenes, such as those posed by Filipo Valsorda, a cryptographer and software engineer, over making trust decisions based on email domains. A month on, and his point remains valid:

Possibly unpopular opinion, but I feel like "only merge things after verifying they are valid" should maybe be the default policy of the most used piece of software in the world. [10]pic.twitter.com/79AT1b3lxQ — Filippo Valsorda 💉💉🎉 (@FiloSottile) [11]April 21, 2021

®

Get our [12]Tech Resources



[1] https://lore.kernel.org/lkml/YKZCPyufaCjGMZL7@kroah.com/

[2] https://www.theregister.com/2021/04/21/minnesota_linux_kernel_flaws_update/

[3] https://www.theregister.com/2021/04/21/minnesota_linux_kernel_flaws_update/

[4] https://www.theregister.com/2021/04/06/xinuous/

[5] https://www.theregister.com/2021/05/20/word_modern_comment/

[6] https://www.theregister.com/2021/05/10/untangling_open_sources_sustainability_problem/

[7] https://www.phoronix.com/scan.php?page=news_item&px=Linux-5.13-UMN-Fixes

[8] https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/log/?qt=grep&q=umn.edu

[9] https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4667a6fc1777ce071504bab570d3599107f4790f

[10] https://t.co/79AT1b3lxQ

[11] https://twitter.com/FiloSottile/status/1384880884562726912?ref_src=twsrc%5Etfw

[12] https://whitepapers.theregister.com/

not just umn.edu

Sparkus

the suspect students and their faculty advisors list multiple affiliations, and most likely multiple email addresses and personae.

Given the 'open' activity from their umn.edu accounts, it's likely prudent to look at potential submissions from ALL of their IDs and persona, those that can be identified anyway.......

The only sane thing to do

oiseau

... "only merge things after verifying they are valid" should maybe be the default policy of the most used piece of software in the world.

Indeed ...

It is the only sane thing to do.

I was unpleasantly surprised (very) to learn that pull requests to the Linux kernel code were accepted solely on the basis of its provenance.

And I have an odd feeling that this was just an exercise to test the waters, so to speak.

The next time (if it has not happened already) it may well go unnoticed.

Like Doctor Syntax said when this was news here at ElReg:

"... remember that Linux gets used in a lot of places these days. It's critical infrastructure."

You. Do. Not. Fuck. Around. With. Critical. Infrastructure.

O.

Re: The only sane thing to do

Anonymous Coward

"You. Do. Not. Fuck. Around. With. Critical. Infrastructure."

The someone should tell Red Hat to have a sit down with Lennart and have the big boy pants talk again. The world relies on Linux as a server OS, he needs to stop treating it like his own personal desktop OS.

If you are thinking about introducing major breaking changes, ask first, then LISTEN. Building is the last step, not the first.

How to deal with Lennert Poettering

DS999

1) take up a collection of Linux users who hate systemd (i.e. 99% of us)

2) use the money to bribe Microsoft to hire him away from Redhat, he produces the kind of bloated crap they like anyway

3) have a team at Redhat tasked with deconstructing systemd and replacing it with modular scriptlets

Re: The only sane thing to do

oiseau

... someone should tell Red Hat ...

... to stop screwing up Linux.

Poettering does as he is told.

Or do you by chance actually think that he has any sort of autonomy?

There is a saying in Spanish speaking countries which basically translates thus:

It's not about the pig, it's about the one who feeds it.

O.

@DS999: do you actually think that Microsoft and RedHat have different agendas?

Re: The only sane thing to do

Gene Cash

Poettering does as he is told.

You obviously haven't ever seen his posts. His "nyah, nyah, nyah, not hearing you!" is more renowned than Linus' swearing.

Re: The only sane thing to do

sloanrb

So the Linux patch validation infrastructure was so bad that a bunch of dippy college students was able to upload bad patches into the kernel.

Yes, what they did was bad, but why has no one called the Linux maintainers onto the carpet? Instead of them looking at their processes and find out what needed to change, they decided to come down on the entire University of Minnesota and punish them.

If this had been Microsoft that had punished the University everyone would be screaming bloody murder.

But apparently the Linux guys are held to the same standard.

Re: The only sane thing to do

Anonymous Coward

I still have an active umn.edu account. I find it bemusing that thanks to this event, any submissions I make to the kernel will be rejected. I'm inept enough of a programmer that any of my submissions should be rejected anyway.

There appears to be irrefutable evidence that the mere fact of overcrowding
induces violence.
-- Harvey Wheeler