@gamer191

0 Followers
0 Following
8 Posts
@jjtech Any plans to upload this onto GitHub? I’m very curious to see how far Swift Playgrounds can be pushed
@fr0gger I don't see any changes to the .gitignore files on the 16 feb. Are you referring to this commit (https://git.tukaani.org/?p=xz.git;a=commit;h=eb8ad59e9bab32a8d655796afd39597ea6dcc64d) on the 26 feb?
@danderson decided to credit the discovery to "someone on GitHub", but Lasse was really busy+tired, so I think he forgot to include that in the commit description

@danderson I think it's important to give credit where credit is due. Yesterday someone discovered it on Github, prior to the repo being taken down. I saved the malicious commit link, because I found it interesting.

Last night (long after all my Mastodon posts, so don't read much into them) I joined the tukaani IRC server, because I was curious if Lasse was aware yet. While I was there I mentioned the issue with that commit, and Lasse pushed the fix. We 1/2

@eb @endrift support. The linked Linux patch (https://lore.kernel.org/lkml/202403201[email protected]/) was developed by him and co-developed by Jia. It's description suggests that it requires changes to Squashfs-tools. Either he took the initiative to make that PR, or Jia suggested he make that PR. Either way, he was most likely unaware of the backdoor
[PATCH 09/11] xz: Add RISC-V BCJ filter - Lasse Collin

@eb @endrift the only thing Lasse would gain out of that is that they'll likely continue to be maintainer now that this has been discovered. I don't think that's close to enough reason for them to orchistrate all the conversations, so I'm not buying that theory tbh

It seems more likely that Lasse got bought out (or convinced) by Jia, after Jia gained his trust

That said, the most likely explanation imo is that Lasse was telling the truth in the PR description and wanted RISC-V filter 1/2

@eb Another interesting thing: https://www.mail-archive.com/xz-devel@tukaani.org/msg00570.html conflicts with the fact that, according to https://github.com/xz-mirror/xz/commits?author=JiaT75&after=74c3449d8b816a724b12ebce7417e00fb597309a+244, JiaT75 hadn't commited anything, he'd only authored stuff (I hope I'm reading that page correctly)

The linked message is definitely an attempt by Jia to request commit access

Re: [xz-devel] [PATCH] String to filter and filter to string

@eb @[email protected]

I kinda doubt Dennis Ens is either. He initially opened the thread, likely to plant the idea that xz needs a new maintainer. He then came back to guilt trip "I am sorry about your mental health issues, but...the community desires more"

EDIT: I initially misread "desires" as "deserves". I think my point still stands though