this post was submitted on 24 Oct 2024
36 points (74.3% liked)

Linux

8193 readers
185 users here now

Welcome to c/linux!

Welcome to our thriving Linux community! Whether you're a seasoned Linux enthusiast or just starting your journey, we're excited to have you here. Explore, learn, and collaborate with like-minded individuals who share a passion for open-source software and the endless possibilities it offers. Together, let's dive into the world of Linux and embrace the power of freedom, customization, and innovation. Enjoy your stay and feel free to join the vibrant discussions that await you!

Rules:

  1. Stay on topic: Posts and discussions should be related to Linux, open source software, and related technologies.

  2. Be respectful: Treat fellow community members with respect and courtesy.

  3. Quality over quantity: Share informative and thought-provoking content.

  4. No spam or self-promotion: Avoid excessive self-promotion or spamming.

  5. No NSFW adult content

  6. Follow general lemmy guidelines.

founded 1 year ago
MODERATORS
 

Official statement regarding recent Greg' commit 6e90b675cf942e from Serge Semin

Hello Linux-kernel community,

I am sure you have already heard the news caused by the recent Greg' commit 6e90b675cf942e ("MAINTAINERS: Remove some entries due to various compliance requirements."). As you may have noticed the change concerned some of the Ru-related developers removal from the list of the official kernel maintainers, including me.

The community members rightly noted that the quite short commit log contained very vague terms with no explicit change justification. No matter how hard I tried to get more details about the reason, alas the senior maintainer I was discussing the matter with haven't given an explanation to what compliance requirements that was. I won't cite the exact emails text since it was a private messaging, but the key words are "sanctions", "sorry", "nothing I can do", "talk to your (company) lawyer"... I can't say for all the guys affected by the change, but my work for the community has been purely volunteer for more than a year now (and less than half of it had been payable before that). For that reason I have no any (company) lawyer to talk to, and honestly after the way the patch has been merged in I don't really want to now. Silently, behind everyone's back, bypassing the standard patch-review process, with no affected developers/subsystem notified - it's indeed the worse way to do what has been done. No gratitude, no credits to the developers for all these years of the devoted work for the community. No matter the reason of the situation but haven't we deserved more than that? Adding to the GREDITS file at least, no?..

I can't believe the kernel senior maintainers didn't consider that the patch wouldn't go unnoticed, and the situation might get out of control with unpredictable results for the community, if not straight away then in the middle or long term perspective. I am sure there have been plenty ways to solve the problem less harmfully, but they decided to take the easiest path. Alas what's done is done. A bifurcation point slightly initiated a year ago has just been fully implemented. The reason of the situation is obviously in the political ground which in this case surely shatters a basement the community has been built on in the first place. If so then God knows what might be next (who else might be sanctioned...), but the implemented move clearly sends a bad signal to the Linux community new comers, to the already working volunteers and hobbyists like me.

Thus even if it was still possible for me to send patches or perform some reviews, after what has been done my motivation to do that as a volunteer has simply vanished. (I might be doing a commercial upstreaming in future though). But before saying goodbye I'd like to express my gratitude to all the community members I have been lucky to work with during all these years.

you are viewing a single comment's thread
view the rest of the comments
[–] goffy59 12 points 1 month ago

Infosec reasons, allegedly.

Saying "Infosec reasons, allegedly" is not only dismissive but also incredibly irresponsible given the current global security climate. There’s nothing “alleged” about the cyber threats posed by Russia. The evidence is overwhelming, documented, and spans decades of hostile actions across Europe and the U.S.

Russia has engaged in full-scale cyber warfare against Western infrastructure, ranging from the NotPetya attacks that caused billions in damages, to election interference in multiple countries, and the continuous disinformation campaigns meant to destabilize democratic institutions. In the cybersecurity world, you don’t wait around for damage to occur before addressing vulnerabilities—prevention is key. It’s not "alleged" when we have mountains of evidence of Russian cyber operations targeting everything from defense industries to healthcare systems.

Your dismissal of the very real "infosec reasons" undermines a fundamental understanding of modern cybersecurity. Espionage, sabotage, and cyberattacks aren't just hypothetical scenarios; they are ongoing, constant threats. By brushing off legitimate concerns with a sarcastic "allegedly," you're either willfully ignoring these realities or grossly underestimating the scale of the issue. Russia has weaponized the digital space, and whether you like it or not, contributions to critical open-source projects like the Linux kernel are absolutely a potential vector for compromise.

When you throw around "allegedly" as if these are mere conspiracy theories, you demonstrate a lack of understanding about how covert operations work. They don’t come with red flags and announcements—they rely on subtlety, deception, and exploiting weaknesses in systems, both technological and human.

Infosec concerns are serious. They aren't alleged. They are proven, documented, and ongoing. If you don't see the logic in taking proactive steps to secure critical infrastructure projects from a country that has made espionage and cyber warfare a cornerstone of its foreign policy, then you're missing the bigger picture entirely. The Linux kernel is too important to global infrastructure to take any risks, and infosec reasons are very much real, not some "alleged" excuse.