Greg provided the appropriate reference, but I thought I'd add an
(interested outsider's) observation or two of my own.

The organisers of the kernel project aren't legally obliged to prove
past question that every patchset has copyright clearance, but are
aiming for being covered for 'due diligence' standards:  They require
the submitting party to certify knowledge of a permission grant by the
copyright owner, and sufficient rights to make that grant meaningful.
Thus, a _truly_ anonymous author's work cannot be accepted, as the
submitter (at least) needs to be in a position to certify knowledge of
provenance -- at minimum, that 'some other person' certified creation
or right to submit the work under 'an appropriate open source license'.

Thus, the kernel maintainers make sure they can reasonably claim 
good-faith reliance on the submitter's sign-off certifying permission
grant and sufficient rights.  That doesn't absolutely prevent copyright
infringement (hardly anything could), but should powerfully protect the
kernel maintainers.

