That type of reality is not natural and it's not human and it's not the one I live in.
Be pissed at the stupid research paper all you want. It doesn't justify treating some tertiary human like utter shit.
And for the record nobody is trying to "cancel" Greg or the kernel here. The project is great and Greg is probably a super chill dude on most occasions. But people aren't perfect and fuck up. You can act rashly under stress and later be wrong. That's understandable and that is human. The whole point is how you respond in light of new information. That's the test of character.
We don't need to sit here and sweep Greg's BS under the rug because he's a kernel celebrity. I honestly think some form of apology would go a long way to rectifying the slander, and cool down the whole thing and most importantly, might be enough to make Aditya feel welcome again in the community. Greg was wrong, his behavior rash, and the example should not be emulated by others in our community. Period.
Recommended reading: All Hallows Eve by Charles Williams, a meditation on where stupidity and selfishness lead.
And for the record I don’t think there is even level headed consensus formed yet on the whole paper thing. It’s arguably unethical, but it is also arguably simply inconsiderate. And it has certainly provided some degree of utility, although it’s unclear how much. I think most of the impressions have been molded by Greg’s response during the “kernel peeps are pissed” phase of the whole affair.
The paper has been withdrawn because consensus is clear: for experiments on human subjects informed consent is required in advance. The institution recognizes that much: "We acknowledge our responsibility to do this to prevent situations like this incident in the future."
> for experiments on human subjects informed consent is required in advance
By such simple logic A/B testing is unethical. And that may be the case. Still, it's not exactly clear in this case where to draw the line and who/what the subject is.
There's a comment elsewhere in this thread that sums the situation up better than I can: https://news.ycombinator.com/item?id=26985631. I've read the paper and honestly I have a mixed impression. It certainly is respectful and doesn't come off as "we're going to be super malicious and mega waste everyone's time and fuck with the kernel maintainers for fun and science". It does not aim to experiment with humans in order to study how humans socially react to a breach of trust in a high trust collaboration. That was not their goal at all. Arguably, as laid out pretty explicitly in the paper, the experiment is not on human subjects but rather on a system of collaboration used primarily by open source projects. It happens that the system is operated by humans. Are you testing the humans, or stressing the system?
Is making crafted investments in the market for the sole purpose of studying the validity of a hypothetical model unethical? Is it research on humans because the market is a human endeavor operated by humans? These are genuine questions.
There are also different ethical frameworks. No harm was caused by this research. In fact, the only real harm to humans has been Greg berating a person (because of their proximity to past research and perceived sloppy patches) who offered legitimate patches some of which actually fixed bugs in the kernel. Clearly Greg didn't even take the time to understand the patches he just categorically dismissed them all because he had a bone to pick. Now the kernel is down a contributor who's contributions clearly have utility.
Back to the paper, even if it presents the obvious for people working on open source projects, it, like is the status quo in security research, is the working example of the exploit. In my experience people don't give a shit about perceived vulnerabilities until they become real vulnerabilities. As a kernel user, I actually value this research more than the alleged waste of time it may have caused for maintainers. I'm not the only one who feels this way. Sometimes to effect change you need to light a fire under somebody's ass.
So the paper is valuable to some subset of people. It provides utility. It did no harm to computer system or humans. You see what I'm getting at.. there are ethical frameworks under which this paper is clearly ethical (even if you concede it directly and explicitly aimed to experiment on humans, which I debate). Ideally the researchers would have asked Linus and Greg if they could perform the research on their project so they wouldn't feel out of the loop and attacked/culpable when the research was published. I do hope everyone's learned their lesson in that regard.
Anyway back to Greg, you're really moving the goal posts. We can agree 100% that the paper is unethical. The fact is simply irrelevant when considering whether it's right to piss on some student at UMN who presented valid albeit sloppy patches to the kernel in a gesture of good faith in order to try and improve the state of security. It's a breach of the kernel's own community guidelines, at the very least!
> and that there was some agreement in place with the University which must have stipulated "no more bogus patches"
This is baseless.
> Then Aditya went and posted another bogus patch
Not bogus. Aditya's analyzer did in fact find plenty of bugs - do your research, this is confirmed by many other maintainers.
> to further his career, even though he should have known how that would be received
Why should he have known that? I would never expect to receive the kind of feedback given by Greg, followed by a total university ban, over a student submitting subpar commits. It's an insane overreaction.
There was behind-the-scenes talk that the student chose to ignore, it's impossible to interpret in any other way.
Greg was assuming these were patches coming from some new "hypocrite patch" project at UMN and "AGAIN" refers to the previous incident in Aug2020 regarding the paper. I don't think the student was ignoring anything. Greg categorically dismissed legitimate contributions to the kernel because of his rash perception that UMN was up to no good AGAIN. So that's why he referenced the previous event and said AGAIN.
In reality, this isn't some conspiracy where UMN was attempting to add hypocrite patches for a 2nd time. Greg was dead wrong in that regard. You need to read: https://www-users.cs.umn.edu/%7Ekjlu/papers/full-disclosure.....
So - no more free research support for the University of Minnesota. That's fair because the reviewers did not choose to spend time on the University of Minnesota's research output.
But the commit in question was bogus, and it looks like Aditya did not properly check the output of his tool. Maybe he did not send bogus patches on purpose, but the fact that he used the Linux kernel as a playground for testing his experimental static analysis tool (without disclosing it in the commits) is still problematic and he should be called out for that.
Are you saying that Aditya was not involved in the hypocrite commits research? He’s not cited in the paper but his name is on the open letter [1].
If this is the case, would you please provide a citation? I feel like I’m missing something or being misled.
[1] https://lwn.net/ml/linux-kernel/CAK8KejpUVLxmqp026JY7x5GzHU2...
But here you go if you want to read more about the research. You'll notice that the messages/ patches are all attributed to those cited in the paper.
https://www-users.cs.umn.edu/~kjlu/papers/full-disclosure.pd...
And yes, you are being misled. That's why Greg needs to publicly retract his accusation and apologize. That's why it's so frustrating that LWN did not clearly explain that Greg was flat out wrong.
Edit: To clarify, I don’t think you’ve made enough of a case to prove Aditya’s innocence or justified your attack on Greg.
Greg overreacted. Linus agrees, other kernel maintainers agree. The only person who won't come out and admit it is Greg himself, and his overreaction has cost the kernel a valuable asset as well as the reputation of an innocent researcher, who now gets comments like "they're disgusting" from people who took Greg's accusations at face value.
https://www.kernel.org/doc/html/latest/process/code-of-condu...