"Full disclosure" from the University of Minnesota
The researchers at the University of Minnesota have posted adescription of the work they did [PDF] as part of their "hypocritecommits" project. It includes a list of the buggy commits they posted andhow they were handled.
In the following we will show two parts: (1)the message log of our disclosure of the findings to the community, and (2)the patches we submitted. By showing the details of the patches and theexchange of messages, we wish to help the community to confirm that thebuggy patches were "stopped" during message exchanges and not merged intothe actual Linux code. No other interactions with the Linux Kernel teamhas involved intentional deception or intentionally misleading or badpatches. This misguided behavior on our part was limited to the patchesdescribed and clarified in this document.
Amusingly, one of their attempts to submit a buggy commit was, itself,buggy, yielding a valid change overall.