)]}'
{
  "commit": "de6bd248af67f6406fe1200842e29a6a25d7acd5",
  "tree": "e8742412da6c37c65fd576815ca58806c675ac0b",
  "parents": [
    "3d1f8cef9a4293786a6e340084f15048d2e1e233"
  ],
  "author": {
    "name": "Duy Truong",
    "email": "duytruong@google.com",
    "time": "Tue May 26 01:07:39 2026 -0700"
  },
  "committer": {
    "name": "Android Build Coastguard Worker",
    "email": "android-build-coastguard-worker@google.com",
    "time": "Mon Jul 13 16:50:18 2026 -0700"
  },
  "message": "RESTRICT AUTOMERGE Camera3StreamSplitter: Add bounds check for slot index\n\nIn returnOutputBufferLocked, an app-supplied slot index was used to\nindex the outputSlots vector without any bounds check. This could\nlead to an out-of-bounds read and type confusion.\n\nThis change adds a range check for the slot index and also verifies\nthat the retrieved buffer is not null. It also ensures the buffer is\ncorrectly tracked in mBuffers before use.\n\nAdditionally, the outputSlots vector is now taken by reference to\navoid unnecessary copying and ensure that modifications to the\nslots are correctly persisted.\n\nBug: 514734206\nTest: m cameraservice_test\nFlag: EXEMPT BUGFIX\nNote: Autogenerated by MendIt (go/androidmendit)\nCherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:349203358d1b697187c79f4728388de5ebf9bebb\nMerged-In: I12684395411ff45393e724345f1cbbb870167101\nChange-Id: I12684395411ff45393e724345f1cbbb870167101\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "255b4f2ac95afa73914f7b9403c7b8b15450b2c9",
      "old_mode": 33188,
      "old_path": "services/camera/libcameraservice/device3/Camera3StreamSplitter.cpp",
      "new_id": "9d324ff58b6ecffb4674b5a2b266a386e7d1c9c8",
      "new_mode": 33188,
      "new_path": "services/camera/libcameraservice/device3/Camera3StreamSplitter.cpp"
    }
  ]
}
