Iyo GitHub bug yaitaridza inoonekwa yekunze musana muLinux kernel

GitHub

Munguva pfupi yapfuura vamwe vanhu vakaona shanduko isinganzwisisike mukodhi yekodhi yeLinux kernel, saka kana uchiongorora kernel kodhi paGitHub Vakacherekedza kuti shanduko dzakaitwa nevechitatu mapato (avo vakaumba kana kufora iyi) vaitaridzika zvinoshamisa mune huru yekuchengetera.

Izvi zvakabata pfungwa dzevamwe paGitHub interface sezvo chinhu chinonakidza chakaratidzwa iyo inobvumidza iwe kuti uunze chero chechitatu-bato shanduko senge shanduko yakatobatanidzwa muprojekiti hombe.

Semuenzaniso, nhasi mumasocial network kutaura kune shanduko mugirazi repamutemo reiyo huru Linux kernel repository kwakatanga kupararira, zvichiratidza kutsiviwa kweshure kwemashure muHID-Samsung mutyairi.

Iyo GitHub quirk yakavhundutsa vanogadzira kernel

Tatarisana nekukonana uku vamwe vakatanga kutarisa kernel kodhi kunyanya mune Samsung mutyairi pamusoro pekuedza kuongorora kana chengetedzo yenyuchi yakanga yaiswa panjodzi.

Kuongororwa kwemamiriro ezvinhu kwakaratidza izvozvo GitHub, kugadzirisa kuchengetedza uye kudzikisira kudzokororwa kwedata pane maseva ayo, inochengetera zvinhu zvese kubva kunzvimbo huru yekuchengetera. uye maforogo ane hukama nazvo, zvine musoro kugovana muridzi wezvinhu.

Naizvozvo akati chengetedzo inobvumira chero munhu ari kubhurawuza mukati mekodhi kuti aone chero vimbiso kubva kune chero forogo mune chero chinhu chakabatana, zvinonyatsoratidza hashi yayo mu URL.

Semuenzaniso, mune kesi yekumashure demo, mumwe wevashandisi akagadzira forogo yeiyo huru Linux kernel repository mune iyo GitHub interface, ndokuwedzera chibvumirano chine backdoor-senge kodhi kune yake forogo.

Mushure meizvozvo, yakagadzira chinongedzo uko SHA1 chinongedzo chekuchinja kwekunze chakatsiviwa muiyo URL yeyakanyanya repositi.

Kana chinongedzo chakafanana chikavhurwa, chisungo chekunze chinoratidzwa mukati meGitHub interface mune mamiriro eiyo huru repositi, kunyangwe zvaiitwa paforogo uye isina chekuita neiyo huru yekuchengetera uye hapana kwakadaro kuzvipira mairi.

github kukanganisa

Uyewo, Mune iyo GitHub interface, kana uchiona iyo changelog yemunhu mafaera, iyo huru repository inoratidzawo yechitatu-bato inoita, iyo inogadzira yakawanda nyonganiso.

Izvi zvakavhundutsa vamwe pavaifunga kuti kwaive kubiridzira uye kuti ivo vaive vaunza yakaipa kodhi kune iyo kodhi kodhi yeLinux kernel.

Zvakanaka, sezvatinoona mumufananidzo pakutanga kuona, zvinoita sekunge kodhi yakaiswa chikamu chezvakachengetwa mune huru Linux Kernel repository.

Uye izvo pakutanga hazviite mareferenzi kune ekunze marekodhi pakagadziridzwa.

Yese yaive alarm yekunyepa

"Kukanganisa" uku (sekutaura) kwakanetsa vazhinji, nekuti panguva iyi ivo havana kuziva kana ivo vaitova nenjodzi kana kuvimbika kweKernel kwakakanganiswa.

Ndinopedza nguva shoma saka ivo vaizoziva kuti kana vachibvisa dhata kana kuumbiridza repositi vachishandisa git mirairo, wechitatu shanduko mune inozoitika repositi yanga isipo.

GitHub yakangoratidzira shanduko nekutarisa kana muchokwadi isiri.

Pari zvino hapana zvimwe zvinozivikanwa nezvazvo uye kana vanhu veGithub (Microsoft) vaine pfungwa yekupa mhinduro kune izvi, iyo isingabate zvakananga kuvandudza, ndoda kana uchiwana kernel kodhi kodhi.

Asi ko kana ichigona kuvhiringidza vazhinji vanosarudza kuongorora zvimwe zvikamu zvezvirongwa zvakachengetwa paGithub.

Zvakanaka, hachisi chinhu chinoratidzwa zvakananga muLinux kernel kodhi, asi ichazoratidzwawo forogo kana maforogo emamwe mapurojekiti.

Saka zvinokwanisika kuti vazhinji vanogadzira kana vashandisi veiyi chikuva vakatotumira mamwe maemail kuvanhu veGitHub.

Kana iwe uchida kuziva zvishoma pamusoro penyaya iyiunogona kushanya chinotevera chinongedzo iko kodhi yakaumba iyi mamiriro ichiri kuratidzwa uyezve zvirevo maererano nazvo nezvazvo pano.


Izvo zviri muchinyorwa zvinoomerera pamisimboti yedu ye tsika dzekunyora. Kuti utaure chikanganiso tinya pano.

Iva wekutanga kutaura

Siya yako yekutaura

Your kero e havazobvumirwi ichibudiswa. Raida minda anozivikanwa ne *

*

*

  1. Inotarisira data: AB Internet Networks 2008 SL
  2. Chinangwa cheiyo data: Kudzora SPAM, manejimendi manejimendi.
  3. Legitimation: Kubvuma kwako
  4. Kutaurirana kwedata
  5. Dhata yekuchengetedza: Dhatabhesi inobatwa neOccentus Networks (EU)
  6. Kodzero: Panguva ipi neipi iwe unogona kudzora, kupora uye kudzima ruzivo rwako