)]}'
{
  "commit": "aee323eb910bd07aa2a7a28134e3981336c7bbd1",
  "tree": "fb6e5b298440be4b51feb2492fa29fdedf188a59",
  "parents": [
    "3d3129f6a0fd42e74a8b2905c8b463205e36a1ae"
  ],
  "author": {
    "name": "Carlos Llamas",
    "email": "cmllamas@google.com",
    "time": "Sat Mar 30 19:01:14 2024 +0000"
  },
  "committer": {
    "name": "mdb:android-git",
    "email": "superproject-auto-update@invalid",
    "time": "Fri Apr 19 16:26:11 2024 +0000"
  },
  "message": "FROMLIST: binder: check offset alignment in binder_get_object()\n\nCommit 6d98eb95b450 (\"binder: avoid potential data leakage when copying\ntxn\") introduced changes to how binder objects are copied. In doing so,\nit unintentionally removed an offset alignment check done through calls\nto binder_alloc_copy_from_buffer() -\u003e check_buffer().\n\nThese calls were replaced in binder_get_object() with copy_from_user(),\nso now an explicit offset alignment check is needed here. This avoids\nlater complications when unwinding the objects gets harder.\n\nIt is worth noting this check existed prior to commit 7a67a39320df\n(\"binder: add function to copy binder object from buffer\"), likely\nremoved due to redundancy at the time.\n\nFixes: 6d98eb95b450 (\"binder: avoid potential data leakage when copying txn\")\nCc:  \u003cstable@vger.kernel.org\u003e\nAcked-by: Todd Kjos \u003ctkjos@google.com\u003e\nSigned-off-by: Carlos Llamas \u003ccmllamas@google.com\u003e\n\nBug: 334156990\nBug: 320661088\nLink: https://lore.kernel.org/all/20240330190115.1877819-1-cmllamas@google.com/\nSigned-off-by: Carlos Llamas \u003ccmllamas@google.com\u003e\n(cherry picked from https://android-review.googlesource.com/q/commit:d76a750f6ffe72431a2c467e85a5ac69366287d1)\nMerged-In: Iaddabaa28de7ba7b7d35dbb639d38ca79dbc5077\nChange-Id: Iaddabaa28de7ba7b7d35dbb639d38ca79dbc5077\n(cherry picked from commit 0379ec545054248181a798ef46bb2acc3b71d570)\nSigned-off-by: Lee Jones \u003cjoneslee@google.com\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "68c69afeb2accb69ded49d583c816e87f31fa4d1",
      "old_mode": 57344,
      "old_path": "common",
      "new_id": "9e27cba3fb694d85db7e511cff9454988103bffb",
      "new_mode": 57344,
      "new_path": "common"
    }
  ]
}
