)]}'
{
  "commit": "5386d908a663a424d154cbae7f76f2266c60c2fe",
  "tree": "be84e65675e7c6d68fb97300a3e06239477ca6d4",
  "parents": [
    "5219abf59b071d2b7c454e5827a368d4db97691f"
  ],
  "author": {
    "name": "Bob Beck",
    "email": "bbe@google.com",
    "time": "Tue Apr 08 23:48:17 2025 +0000"
  },
  "committer": {
    "name": "Boringssl LUCI CQ",
    "email": "boringssl-scoped@luci-project-accounts.iam.gserviceaccount.com",
    "time": "Thu Apr 10 10:02:39 2025 -0700"
  },
  "message": "Fix backward check in crl_crldp_check\n\nI missed this on review and stared at it a few times\nbefore realizing because the \"score\" code is pretty obtuse.\n\nIf we don\u0027t have reasons, and we don\u0027t have a CRLissuer, we will\nhave already checked that the signer of the CRL matches the issuer\nof the cert (The \"Otherwise\" part of step b.1), and so we want\nto continue to do step b.2. If there is an issuing distribution point\nin the crl check to see if one of the names in it matches the names in the\ndistribution point in the cert.\n\nFixed: 400486977\nBug: 409778435\n\nChange-Id: I8537450094065d1d465d14e0330f2f0b26d2564f\nReviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/78368\nReviewed-by: David Benjamin \u003cdavidben@google.com\u003e\nCommit-Queue: Bob Beck \u003cbbe@google.com\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "03f4612e4ab5a60c9e4edcbc39c5e6dcb8ee368d",
      "old_mode": 33188,
      "old_path": "crypto/x509/x509_vfy.cc",
      "new_id": "92f154c8c7d66139526d5ab45c1d46221498a6c7",
      "new_mode": 33188,
      "new_path": "crypto/x509/x509_vfy.cc"
    }
  ]
}
