倍可親

明大LINUX事件的反思(3)稍有好轉

作者:oneweek  於 2021-5-1 00:41 發表於 最熱鬧的華人社交網路--貝殼村

通用分類:熱點雜談


網上GREG 的twitter的回復很熱烈,轉發回復的很快上百, 大部分都覺得盧老師的研究有道德問題。 幾個小時后,技術方面的新聞紛紛揚揚, 都是人云亦云、鸚鵡學舌。

估計盧老師早上醒來,估計看了第一條消息, 應該腦袋裡翁的一聲。 往下看看, 估計應該長出一口氣。 

Greg發出禁令的之後兩個小時,可能覺得也是過分,把過去所有都剔除? 自己也覺得,過了。 改成重新審查吧。 重審之後有效的接著再用就可以了。 https://lore.kernel.org/lkml/20210421130105.1226686-1-gregkh@linuxfoundation.org/

 Wed, 21 Apr 2021 14:57:55 +0200 (這時,是明大早上8點,-0500)
 I have been meaning to do this for a while, but recent events have finally forced me to do so. 我想干這事有些時候了,最近的事件才促使我下決心

Commits from @umn.edu addresses have been found to be submitted in "bad faith" to try to test the kernel community's ability to review "known malicious" changes.  The result of these submissions can be found in a paper published at the 42nd IEEE Symposium on Security and Privacy entitled, "Open Source Insecurity: Stealthily Introducing Vulnerabilities via Hypocrite Commits" written by Qiushi Wu (University of Minnesota) and Kangjie Lu (University of Minnesota). 最近發現 通過@umn.edu 提交的補丁 屬於惡意提交, 旨在測試內核社區對已知的的惡意更改能不能鑒別出來。 這些提交寫在了42屆IEEE安全隱私大會的文章里, 文章題目「開源的不安全性:假裝好意提交 偷偷導入 弱點」 , 作者小吳和盧老師。

Because of this, all submissions from this group must be reverted from the kernel tree and will need to be re-reviewed again to determine if they actually are a valid fix.  Until that work is complete, remove this change to ensure that no problems are being introduced into the codebase. 有鑒於此, 該組所有提交的補丁要從內核樹移除, 重新審查以確定是不是真正
有效補丁。 重審完畢之前, 移除是有必要的, 我們不希望它們導入問題。 

This patchset has the "easy" reverts, there are 68 remaining ones that need to be manually reviewed.  Some of them are not able to be reverted as they  already have been reverted, or fixed up with follow-on patches as they were determined to be invalid.  Proof that these submissions were almost universally wrong. 以下是容易的部分,還有68個需要人工審查。 有些過去早被移除,或引起弱點被其後的補丁修改過了。 這也證明他們很多提交幾乎都是錯的。

I will be working with some other kernel developers to determine if any of these reverts were actually valid changes, were actually valid, and if so, will resubmit them properly later.  For now, it's better to be safe. 我將與其他一些內核開發人員一起 ,以確定這些移除是否實際上是有效 更改。如果是,稍後 重新提交。目前,最好安全第一。 

I'll take this through my tree, so no need for any maintainer to worry about this, but they should be aware that future submissions from anyone with a umn.edu address should be by default-rejected unless otherwise determined to actually be a valid fix (i.e. they provide proof and you can verify it, but really, why waste your time doing that extra work?) 我把我的樹捋一遍,其他內核維護人員不用操心,但 要注意,未來所有出自 umn.edu 地址的提交都應該默認拒絕。 除非能證明該提交是一個有效的修復。(比如:他們能提供證據,然後你可以驗證,否則為什麼浪費時間做 額外的工作?)

thanks,

greg k-h

高興

感動

同情

搞笑

難過

拍磚

支持
1

鮮花

剛表態過的朋友 (1 人)

評論 (0 個評論)

facelist doodle 塗鴉板

您需要登錄后才可以評論 登錄 | 註冊

關於本站 | 隱私權政策 | 免責條款 | 版權聲明 | 聯絡我們

Copyright © 2001-2013 海外華人中文門戶:倍可親 (http://big5.backchina.com) All Rights Reserved.

程序系統基於 Discuz! X3.1 商業版 優化 Discuz! © 2001-2013 Comsenz Inc.

本站時間採用京港台時間 GMT+8, 2024-4-26 01:40

返回頂部