oss-sec mailing list archives

Re: Analysis on who is Jia Tan, and who he could work for, reading xz.git


From: Vegard Nossum <vegard.nossum () oracle com>
Date: Wed, 10 Apr 2024 21:56:47 +0200


On 10/04/2024 20:19, Alejandro Colomar wrote:> On Wed, Apr 10, 2024 at 12:10:51PM -0400, Joey Hess wrote:
That's a theory. But many of the commits with author Jia Tan in
those time zones have committer Lasse Collin, and show signs of
being eg, git-amed patch sets which may have also been rebased. In
which case it would make sense that these have Lasse Collin's usual
timezone.

Yep, I also had the feeling that some of those might be the result
of git-am(1) (TBH, I had those feelings today, after the email had
been sent).  In principle, git-am(1) respects the author date, but if
some mails (assuming patches taken via mail) were somehow malformed,
or Lasse had something misconfigured, it might have overwritten the
author date. Maybe this helps Lasse investigate his emails, and see
if this makes any sense for him.

Lasse has already hinted at the reasons for why some of these things are
the way they are. Spoiler: normal boring maintainer edits.

But I really think we ought to wait for Lasse's article before
speculating any further about timezones and commit logs: He has stated
on <https://tukaani.org/xz-backdoor/> that 1) an article is in the works
but 2) cleaning up the repository currently has priority, and 3) he
receives far more email than he can respond to.


Vegard


Current thread: