That was remarkably unnecessary.
Phoronix: Vandalizing Open-Source Drivers?
Somebody with root access to the FreeDesktop.org server decided to vandalize the RadeonHD graphics driver in this Git commit. The make files were deleted and replaced with "It's dead, Jim" and a Git commit message line of "PERHAPS BONGHITS WILL FIX MY MAKEFILE." The supplied email address was "root@jerkcity.com."..
http://www.phoronix.com/vr.php?view=ODgxNw
That was remarkably unnecessary.
I lol'd. Should've kept it.
Interestingly, the email address comes from the website of Jerkcity. Jerkcity is a webcomic notable enough to have a Wikipedia page. One of the characters is named Spigot (the name of the committer). Spigot is even based on one of the authors of the strip.
Of course, it's likely that the vandal has nothing to do with Jerkcity, and simply spoofed his name and email address as a bad joke. He's already shown he's very good at covering up his tracks - as Luc noted, he disabled the update hook before his commit and re-enabled it afterward so that no email would be sent to the mailing list.
And even if rebasing published repositories is not recommended, in this case it is probably a good idea, there is no need to tolerate vandalism even if the project is not thriving.
This is not a security thing, it is a trust thing here. Those people with root access to the fd.o servers should be fully trusted, if not, they should not have such access rights. This event here clearly shows that one person should not have been given access rights, even when this person might have had this since right after the xfree86 fork.