My impression is that the kernel maintainers are angry they were embarrassed this way and are reverting all of the useful work that was done out of spite.
I don't think this study was fully ethical but I don't think they were being malicious and appeared to be trying to help.
Conversation
I don't think it's malicious. But the intransparency of the researchers along with the responses makes it a great deal worse. We still don't know which patches where part of the research, and that is a problem.
1
The research was unethical, but the problem goes far beyond that. Are they going to revert and review other similar patches which were not meaningfully understood, tested or reviewed? No, just these ones.
The process for accepting code does not counter bad actors well at all.
1
I don't think I agree with the revert, but I don't think you need this research to hilight the review problem with a project such as Linux either.
It just seems like cheap research to me.
1
I think it is needed as long as key people downplay the problems and try to make it seem like the status quo is fine.
Linux kernel code has very low quality and complexity far beyond a level that can be managed with the tools and processes that are being used, and they deny it.
2
I haven't gotten the impression people are downplaying it. I have seen Greg raise the lack of review as a major problem on several occasions?
The largest disappointment is how the research was conducted and presented in the end :/
1
1
The greatest disappointing to me is that I use software where random malicious people can submit patches that will be merged without any real attempt to understand the code and determine if it is correct or not.
1
1
I don't think Greg is part of that problem. He's very open and honest about the problems with the kernel. He's also very welcoming to people trying to improve it. I'm not talking about him.
Peter Zijlstra is an egregious example. Linus often qualifies too, as do many others.
1
1
I read through all of lkml.org/lkml/2021/4/14 today. I have a lot of sympathy towards both Greg KH and what the grsecurity folks say about the kernel maintainers / processes.
2
On the other hand, certain people are consistently opposed to making things better on many fronts and use underhanded tactics regularly. If someone submitted a patch tricking one of those people and published a blog post about it, would I think it was wrong? No, not really.
1
I don't agree with embarrassing random overworked maintainers. As I said, I think that's pretty rude. Do I think it's rude if you do it to someone like Linus, who has consistently been part of the problem and used disingenuous arguments, etc? No, I don't. I think that's heroic.
I think we generally agree on the issues here. I just hope something good comes out of it as opposed to random outrage towards a university and animosity towards the kernel devs 🙃

