Hi Collin,

Thanks for taking the time to write, and for the pointers. The NOTES.md
issue on the xz submission was a process mistake on my side — I've closed
that PR with an apology, and I'm cleaning the same kind of draft notes out
of other open submissions.

Appreciate you flagging the concerns for the maintainers.

Best,
Jeff

On Fri, Sep 11, 2026 07:31 PM, Collin Funk <[email protected]> wrote:

> Hi Jeff,
>
> Jeff Bindel <[email protected]> writes:
>
> > This is secure-by-design hardening (Google Patch Rewards style), not a
> > security bug report and not a PoC.
>
> Thank you for this clarification, and making me aware of this
> interesting feature. Note, that I am responding as someone who is not a
> maintainer of GNU tar.
>
> However, I would like to make Paul and Sergey, who maintain GNU tar,
> aware of Lasse Collin's review of your patch submitted to xz-utils. In
> that patch to xz-utils, an LLM-generated NOTES.md file was included in
> the commit, likely meaning the code was LLM-generated too. Some projects
> are okay with LLM-generated patches; others are not for reasons such as
> copyrightability, for example. I suspect GNU tar is in the latter camp.
> Regardless, the submission with the LLM-generated report calling out a
> bug should be a cause for concern for unrelated projects as well.
>
> On a more interesting note, you mention "Google Patch Rewards". As Lasse
> found, it turns out that Google has a list of open-source projects [2]
> they deem important enough to pay (supposedly) [3] contributors for. It
> appears the qualifications are fairly lax, e.g., any memory safety issue
> qualifies so long as it is a "vulnerability". It doesn't say what
> classifies as a vulnerability [4], but I suspect anything assigned a CVE
> will do. And CVEs are often assigned for bogus reasons. Included in that
> list are xz, gzip, GNU tar, and GNU cpio. I was wondering why GNU tar
> and cpio seem to get so many more LLM-generated "security" submissions,
> at least based on my estimation from viewing my inbox, than other GNU
> projects. I guess that answers why.
>
> Since I am a maintainer of none of those projects, I won't make too much
> of a commotion about it. But the system seems designed to encourage spam
> PRs. I struggle to think of a more charitable interpretation. If their
> goal was to improve security, I am not sure why they wouldn't fund the
> projects and longstanding maintainers directly.
>
> Collin
>
> [1] https://github.com/tukaani-project/xz/pull/245#issuecomment-5640147905
> [2] https://github.com/google/bughunters/blob/main/patch-rewards
> -program/scope.md
> [3] https://bughunters.google.com/open-source-security/patch-rewards
> [4] https://bughunters.google.com/about/rules/open-source/patch-
> rewards-program-rules#open-source-patch-rewards
>

Reply via email to