)]}'
{
  "commit": "e5a214a259892b5b9b9384a69d2beb61fb8c3521",
  "tree": "dadbda10a1aae58b2d10943ccdd737497a6334d4",
  "parents": [
    "f53c8ff1a32f280a62bd65b6c9b70f2fcabb970a"
  ],
  "author": {
    "name": "David Benjamin",
    "email": "davidben@google.com",
    "time": "Thu Jul 09 18:09:03 2026 -0400"
  },
  "committer": {
    "name": "boringssl-scoped@luci-project-accounts.iam.gserviceaccount.com",
    "email": "boringssl-scoped@luci-project-accounts.iam.gserviceaccount.com",
    "time": "Wed Aug 12 15:33:30 2026 -0700"
  },
  "message": "Separate serial number validity from serial number length\n\nIn practice it seems everyone ends up tolerating serials of the wrong\nlength, so having that flag seems questably worth it. But no one should\nbe tolerating inputs that aren\u0027t even INTEGERs (they cannot even\nround-trip through crypto/asn1).\n\nTo help separate them, downgrade the 20-byte check to a warning. From\nhere, we\u0027ll histogram validity (and length while we\u0027re at it) in\nChromium just as a sanity check and, if all goes well, retire this flag.\nI don\u0027t expect the length histograms to be fruitful, but we can check\nthat too.\n\nBug: 533048005\nChange-Id: I11154dc759a8a8ccbeed8f658b1c8896d5ad0d52\nReviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/98667\nCommit-Queue: David Benjamin \u003cdavidben@google.com\u003e\nReviewed-by: Matt Mueller \u003cmattm@google.com\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "cbbca0f38dc3807078d3b3d638ec6efb52de16c5",
      "old_mode": 33188,
      "old_path": "pki/certificate.cc",
      "new_id": "daa1a68656fc597ee49149264a13eed78d9b4236",
      "new_mode": 33188,
      "new_path": "pki/certificate.cc"
    },
    {
      "type": "modify",
      "old_id": "a67352836d9af9efa6f2b7a99bde0a13d36fbcdb",
      "old_mode": 33188,
      "old_path": "pki/parse_certificate.cc",
      "new_id": "7d1a9481fa9d8a16c7882b1d32da409620d82d98",
      "new_mode": 33188,
      "new_path": "pki/parse_certificate.cc"
    },
    {
      "type": "modify",
      "old_id": "aedf583f579777fe8f01287e9ec9b52d48cb24cb",
      "old_mode": 33188,
      "old_path": "pki/parse_certificate.h",
      "new_id": "b56092b42f6cc57648e42d4191d6cd7355b65a1c",
      "new_mode": 33188,
      "new_path": "pki/parse_certificate.h"
    },
    {
      "type": "modify",
      "old_id": "0e50f7b4133b1ff56ddf8d2c34a0de544100b451",
      "old_mode": 33188,
      "old_path": "pki/parsed_certificate_unittest.cc",
      "new_id": "43c9812488e99126b5a0c11a7b1e128d7fa3f70f",
      "new_mode": 33188,
      "new_path": "pki/parsed_certificate_unittest.cc"
    },
    {
      "type": "modify",
      "old_id": "766f6b32cd20e592f588b6896495626d8e2e4f8d",
      "old_mode": 33188,
      "old_path": "pki/testdata/parse_certificate_unittest/serial_37_bytes.pem",
      "new_id": "c5f9c1a44f9fb0b34edc49b07962b00823287822",
      "new_mode": 33188,
      "new_path": "pki/testdata/parse_certificate_unittest/serial_37_bytes.pem"
    },
    {
      "type": "modify",
      "old_id": "d90fd3f5ca753660b2fbffd158c8e33f4c663c1e",
      "old_mode": 33188,
      "old_path": "pki/testdata/parse_certificate_unittest/serial_zero_padded_21_bytes.pem",
      "new_id": "0fa1b1ec74821978f28a5ccfc599ff3b88fd18a9",
      "new_mode": 33188,
      "new_path": "pki/testdata/parse_certificate_unittest/serial_zero_padded_21_bytes.pem"
    },
    {
      "type": "modify",
      "old_id": "1a03854a1c49a12a2fee53421cd497c3893f1250",
      "old_mode": 33188,
      "old_path": "pki/verify.cc",
      "new_id": "02bb247300b1733e30ce01881f3d9786ddd47c81",
      "new_mode": 33188,
      "new_path": "pki/verify.cc"
    }
  ]
}
