)]}'
{
  "commit": "4b1d95a4bf351a4edb1879550817ea00c5f475c1",
  "tree": "895e6e645f49dfa4ce60a6f4e54684f35991e508",
  "parents": [
    "ce5d53470717be932f192ff360e24e2627bd66d6"
  ],
  "author": {
    "name": "Stefano Duo",
    "email": "stefanoduo@google.com",
    "time": "Wed Jul 22 16:02:19 2026 +0000"
  },
  "committer": {
    "name": "Adam Langley",
    "email": "agl@google.com",
    "time": "Thu Aug 06 10:00:51 2026 -0700"
  },
  "message": "fips-20260721: cherry-pick Make BoringSSL handling of \"unusable\" EchConfigLists configurable\n\n(cherry picked from commit 59e89e9132799b287fea2b5c95988621a1365130)\n\nCurrently, BoringSSL will silently ignore EchConfigsLists it considers\n\"unusable\". An EchConfigList is considered \"unusable\" if we are in one\nof the following scenarios:\n1. The max TLS version supported by the client is \u003c 1.3\n2. No EchConfig provided in the EchConfigList is supported by BoringSSL.\n   This happens when every EchConfig provided contains an\n   unsupported/unrecognized cyphers/parameters (e.g., an unknown HPKE\n   Key Encapsulation Mechanism).\n\nIn these scenarios, instead of falling back onto GREASE ECH (if\nenabled), return an error to the caller. The caller can then decide to\neither retry with an empty EchConfigList or fail the connection.\n\nBug: 542983348, b:450001346\nChange-Id: Ie6fbaf19c2eff3541309e9de60f2ce500a20a0f9\nReviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/100387\nReviewed-by: Xiangfei Ding \u003cxfding@google.com\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "4f1d77a0f9fd47df2137e1a333538c4db08159d1",
      "old_mode": 33188,
      "old_path": "crypto/err/ssl.errordata",
      "new_id": "0ee34ae786f72bd8e2c69468b1c0ee41a11123af",
      "new_mode": 33188,
      "new_path": "crypto/err/ssl.errordata"
    },
    {
      "type": "modify",
      "old_id": "e20e7e7a23c53ac9e5f99331d6a090420f44c910",
      "old_mode": 33188,
      "old_path": "gen/crypto/err_data.cc",
      "new_id": "006aa941c82d2bf217a2bc4da6f4abb5ad913bf0",
      "new_mode": 33188,
      "new_path": "gen/crypto/err_data.cc"
    },
    {
      "type": "modify",
      "old_id": "d46dc701b401ed3be213bff1bb63dd84e02dc949",
      "old_mode": 33188,
      "old_path": "include/openssl/prefix_symbols.h",
      "new_id": "efa6f1d3efc3757b9335dfdab703c84ab4230747",
      "new_mode": 33188,
      "new_path": "include/openssl/prefix_symbols.h"
    },
    {
      "type": "modify",
      "old_id": "56682da6ab421ca11b5e6fcfb8afc14d1ec7bfd6",
      "old_mode": 33188,
      "old_path": "include/openssl/ssl.h",
      "new_id": "e450fad5ae25fd5c4dd2dbffa12ef45dbbdb4177",
      "new_mode": 33188,
      "new_path": "include/openssl/ssl.h"
    },
    {
      "type": "modify",
      "old_id": "46ba196f1895ec3b7be8fcc799f7bbddff5ce2c6",
      "old_mode": 33188,
      "old_path": "ssl/encrypted_client_hello.cc",
      "new_id": "0cf1fc3ab901e933941f53acc8e9f3f5bce0c6cd",
      "new_mode": 33188,
      "new_path": "ssl/encrypted_client_hello.cc"
    },
    {
      "type": "modify",
      "old_id": "74c6c2e9c3b2709dad3b6bdb589e849550cef93e",
      "old_mode": 33188,
      "old_path": "ssl/internal.h",
      "new_id": "c5dd0fb7953c832f821132a127ff40f70d87535c",
      "new_mode": 33188,
      "new_path": "ssl/internal.h"
    },
    {
      "type": "modify",
      "old_id": "e05f91bd913e78b848728aec0c76ad34f32ea6b4",
      "old_mode": 33188,
      "old_path": "ssl/ssl_lib.cc",
      "new_id": "eb55f7a28acde9763d9bdf30fb30a91d89a57fc2",
      "new_mode": 33188,
      "new_path": "ssl/ssl_lib.cc"
    },
    {
      "type": "modify",
      "old_id": "22ee8ecdb64228fe23ccf6be319d03fa072c8818",
      "old_mode": 33188,
      "old_path": "ssl/test/runner/ech_tests.go",
      "new_id": "48382e41ad58dff791ecba8941f3e95c09d27847",
      "new_mode": 33188,
      "new_path": "ssl/test/runner/ech_tests.go"
    },
    {
      "type": "modify",
      "old_id": "c15b2ab550e9a89f45b6bb79305c568f03ad7832",
      "old_mode": 33188,
      "old_path": "ssl/test/test_config.cc",
      "new_id": "9e094919830d1fb7d1842ec908d76e00e7349a1a",
      "new_mode": 33188,
      "new_path": "ssl/test/test_config.cc"
    },
    {
      "type": "modify",
      "old_id": "f781a599eac46c73126993aeccad8a636bcfa9bf",
      "old_mode": 33188,
      "old_path": "ssl/test/test_config.h",
      "new_id": "56d347c6d6b648e8fc5d27e494a9d7c4b679eeba",
      "new_mode": 33188,
      "new_path": "ssl/test/test_config.h"
    }
  ]
}
