How is security taken care of when contributions are being done by Huawei (backdoors in 41k lines of sourcode?)? But I am guessing there is no real fight between open source software and state actors - perhaps someone who knows more about the security of the kernel can comment.
If a state actor really wants to do it and someone could get it past reviews, I am sure they could bribe any contributor from any country (including US). Why single out China? We never raised concerns with Russian contributors.
[0] https://freedom-to-tinker.com/2013/10/09/the-linux-backdoor-...
[1] https://www.omgubuntu.co.uk/2013/11/nsa-ask-linus-torvalds-i...