)]}'
{
  "commit": "d0f14f3981943eb60687bc46f95546a3e1c72b9e",
  "tree": "981a2593235b12fd7bf2f0c78b5fce356f30ef91",
  "parents": [
    "c7a3c46574e7fc32357b2cc68f961c56c72b0ca4"
  ],
  "author": {
    "name": "David Benjamin",
    "email": "davidben@google.com",
    "time": "Tue Mar 08 15:55:42 2022 -0500"
  },
  "committer": {
    "name": "Boringssl LUCI CQ",
    "email": "boringssl-scoped@luci-project-accounts.iam.gserviceaccount.com",
    "time": "Fri Mar 18 19:17:52 2022 +0000"
  },
  "message": "Document and tidy up X509_alias_get0, etc.\n\nThe getters would leave the length uninitialized when empty, which is\ndangerous if the caller does not check. Instead, always fill it in.\n\nThis opens a can of worms around whether empty alias and missing alias\nare meaningfully different. Treating {NULL, 0} differently from\n{non-NULL, 0} has typically caused problems. At the PKCS#12 level,\nneither friendlyName, nor localKeyId are allowed to be empty, which\nsuggests we should not distinguish. However, X509_CERT_AUX, which is\nserialized in i2d_X509_AUX, does distinguish the two states. The getters\ntry to, but an empty ASN1_STRING can have NULL data pointer. (Although,\nwhen parsed, they usually do not because OpenSSL helpfully\nNUL-terminates it for you.)\n\nFor now, I\u0027ve just written the documentation to suggest the empty string\nis the same as the missing state. I\u0027m thinking we can make the PKCS#12\nfunctions not bother distinguishing the two and see how it goes. I\u0027ve\nalso gone ahead and grouped them with d2i_X509_AUX, although the rest of\nthe headers has not yet been grouped into sections.\n\nBug: 426, 481\nChange-Id: Ic9c21bc2b5ef3b012c2f812b0474f04d5232db06\nReviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/51745\nReviewed-by: Adam Langley \u003cagl@google.com\u003e\nCommit-Queue: David Benjamin \u003cdavidben@google.com\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "fca02a638025e92b7832d574d9e18711b0877938",
      "old_mode": 33188,
      "old_path": "crypto/x509/x_x509a.c",
      "new_id": "447a891fe415b82af319c47488ca9ce3e161cf23",
      "new_mode": 33188,
      "new_path": "crypto/x509/x_x509a.c"
    },
    {
      "type": "modify",
      "old_id": "6696988568206bc72cda268497c63361c2fabcbc",
      "old_mode": 33188,
      "old_path": "include/openssl/x509.h",
      "new_id": "1a45d7576a0ea2909dac8e6269744d70fc12c110",
      "new_mode": 33188,
      "new_path": "include/openssl/x509.h"
    }
  ]
}
