I do not think that would help. This was done on public mailing list and deceptive behavior was also against third parties (other reviewers). I do not think Linus/Greg can give consent to that.
I do not think that would help. This was done on public mailing list and deceptive behavior was also against third parties (other reviewers). I do not think Linus/Greg can give consent to that.
Get consent from the project leaders and announce publicly their intentions and a time window of a few months. Then randomly submit the patches as originally outlined.
Although this would not prove as strong of a result, it is far more ethical and similarly effective. Companies use this kind of method all the time.
So, then, it is similar with a 'secret experiment upon unwitting people' and the Linux project. The owner/operators are Linus and Greg, and as the experiment cannot be pre-announced without tainting the outcomes, they are the ultimate "go or no-go" decision makers — just as the owner/operator of the footpaths would, too, have a right to refuse an experiment upon their participants. The individual Linux contributors who participate in the Linux project have no implicit authority whatsoever in any such consideration, and would not be offered opt-in or opt-out consent prior to it being performed. If the good of the project requires pentesting the processes that contributors operate, the project has every right to do so; it's for the good of the project, and contributors' time spent will have been net valuable even if the specific contributions are felt to have been "discarded" or if the contributors feel that their time was "wasted".
This lack of individual authority in many respects is not comfortable or appealing for open source contributors to consider, but it's critical for us to confront it and learn lessons from it. We do not perfect authority over how open source projects use our contributions, whether in time, money, or code. Some percentage of our contributions will always end up being discarded or wasted, and sometimes that will be upsetting to contributors. These are real aspects of project participation regardless of whether secret experiments are approved by the project owners/operators or not. I hope that this event helps us develop better empathy for large projects, such as Linux or other operating systems, when they make decisions that benefit the project rather than contributors.
I think the thing I'm objecting to is that this is a valid or meaningful 'experiment'. Placing there, to me, is already inaccurate framing.