)]}'
{
  "commit": "b92fcfdc17f3ad794c220a86f4ae6695d0a0fb61",
  "tree": "fa6db2e29f9434d7e4a8996f702e45034140abeb",
  "parents": [
    "e24491a09cbae08cccd1ad894455d547218d89c8"
  ],
  "author": {
    "name": "David Benjamin",
    "email": "davidben@google.com",
    "time": "Thu May 11 18:53:05 2023 -0400"
  },
  "committer": {
    "name": "Boringssl LUCI CQ",
    "email": "boringssl-scoped@luci-project-accounts.iam.gserviceaccount.com",
    "time": "Fri May 12 02:01:34 2023 +0000"
  },
  "message": "Cap the input size to the conf fuzzer\n\nTrying to fix all the places where these formats go quadratic isn\u0027t a\ngood use of time. We\u0027ve already documented that they\u0027re not safe for use\nwith untrusted inputs. Even without such DoS issues, they cannot be\nsafely used anyway. (E.g. RUSTSEC-2023-0023.)\n\nJust cap the fuzzer input. It\u0027d be nice if we could avoid this more\nsystematically in the function, but they\u0027re not structured to make this\neasy to do, and anyone concerned about DoS in this function has worse\nproblems.\n\nBug: chromium:1444420, oss-fuzz:56048, 611\nChange-Id: I53eeb346f59278ec2db3aac4a92573b927ed8003\nReviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/59785\nReviewed-by: Bob Beck \u003cbbe@google.com\u003e\nCommit-Queue: David Benjamin \u003cdavidben@google.com\u003e\nAuto-Submit: David Benjamin \u003cdavidben@google.com\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "eed87f35016ccf16cda7c37b91d50ab44cf29edb",
      "old_mode": 33188,
      "old_path": "fuzz/conf.cc",
      "new_id": "9b810e10292458f8d9b0336061e6a1765f4db9e4",
      "new_mode": 33188,
      "new_path": "fuzz/conf.cc"
    },
    {
      "type": "modify",
      "old_id": "d9c862da836781e7e72c849c8e9201132c8b1534",
      "old_mode": 33188,
      "old_path": "include/openssl/x509v3.h",
      "new_id": "f5ea41354edc2200843a1cf44322f629a688c351",
      "new_mode": 33188,
      "new_path": "include/openssl/x509v3.h"
    }
  ]
}
