)]}'
{
  "log": [
    {
      "commit": "9e41bec8d335c4adb4ae41e449461d8b3c69eeef",
      "tree": "3de995f2d9dbb2aaf681a57659335348bd45a5f0",
      "parents": [
        "5c57e911b4d5c146d03129b4c9d8b02bd5fd736a",
        "b4d9e1b41301b11bf4e4d7c9cfef27850e518b0c"
      ],
      "author": {
        "name": "Lajos Molnar",
        "email": "lajos@google.com",
        "time": "Tue Aug 15 23:03:50 2017 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Tue Aug 15 23:03:50 2017 +0000"
      },
      "message": "Merge \"stagefright: avoid buffer overflow in base64 decoder\" into klp-dev"
    },
    {
      "commit": "5c57e911b4d5c146d03129b4c9d8b02bd5fd736a",
      "tree": "c7189f47504b9b74be23f978c6260c7ef9efe004",
      "parents": [
        "804632afcdda6e80945bf27c384757bda50560cb"
      ],
      "author": {
        "name": "Wei Jia",
        "email": "wjia@google.com",
        "time": "Fri Mar 24 14:04:05 2017 -0700"
      },
      "committer": {
        "name": "Wei Jia",
        "email": "wjia@google.com",
        "time": "Mon Aug 14 22:22:04 2017 +0000"
      },
      "message": "MPEG4Source: fix fragmented read.\n\nTest: passed CTS test DecoderTest#testDecodeFragmented\nBug: 64314728\nBug: 36571704\nChange-Id: I71ad6aaae473b03483f8405899d3178148597bba\n(cherry picked from commit ba9af7792dfed6e9b1b216aab91a97e713eec891)\n(cherry picked from commit 6b401a337674f2f22b7589534700a33187899869)\n"
    },
    {
      "commit": "804632afcdda6e80945bf27c384757bda50560cb",
      "tree": "2daec5cf329096edd4be3595b54cb16c766ba167",
      "parents": [
        "ab2c5046efeafcf819ac04acf864e32dc10a8403"
      ],
      "author": {
        "name": "Mikhail Naganov",
        "email": "mnaganov@google.com",
        "time": "Mon Jul 24 17:25:47 2017 -0700"
      },
      "committer": {
        "name": "Mikhail Naganov",
        "email": "mnaganov@google.com",
        "time": "Fri Aug 11 18:51:34 2017 +0000"
      },
      "message": "Add EFFECT_CMD_SET_PARAM parameter checking to Downmix and Reverb\n\nBug: 63662938\nBug: 63526567\nTest: Added CTS tests\n\nChange-Id: I8ed398cd62a9f461b0590e37f593daa3d8e4dbc4\n"
    },
    {
      "commit": "ab2c5046efeafcf819ac04acf864e32dc10a8403",
      "tree": "70b1557d39349b30c6a75e2d60308cf34ecbb2ef",
      "parents": [
        "d371d08bcc6762a522132fb0ba8c0495306a8f24",
        "8082425b96901c0469a81a896d07a69fcb1e9d2f"
      ],
      "author": {
        "name": "TreeHugger Robot",
        "email": "treehugger-gerrit@google.com",
        "time": "Fri Aug 04 22:28:18 2017 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Fri Aug 04 22:28:18 2017 +0000"
      },
      "message": "Merge \"Skip track if verification fails\" into klp-dev"
    },
    {
      "commit": "8082425b96901c0469a81a896d07a69fcb1e9d2f",
      "tree": "8f96c2af16626f7f7834caf1c885c8efb2c15977",
      "parents": [
        "502c2f405355c3253990ac4edae345ac1907f916"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Tue Jul 18 14:57:11 2017 -0700"
      },
      "committer": {
        "name": "Dongwon Kang",
        "email": "dwkang@google.com",
        "time": "Fri Aug 04 22:26:12 2017 +0000"
      },
      "message": "Skip track if verification fails\n\nBug: 62187433\nTest: ran poc, CTS\nMerged-In: Ib9b0b6de88d046d8149e9ea5073d6c40ffec7b0c\nChange-Id: Ib9b0b6de88d046d8149e9ea5073d6c40ffec7b0c\n"
    },
    {
      "commit": "d371d08bcc6762a522132fb0ba8c0495306a8f24",
      "tree": "e7d341307cec0815d693bc9b3d76043410b5f22b",
      "parents": [
        "502c2f405355c3253990ac4edae345ac1907f916",
        "6e2bcf40e4083be3a0fbb13d03293a78301e66ef"
      ],
      "author": {
        "name": "Chong Zhang",
        "email": "chz@google.com",
        "time": "Tue Jul 18 22:14:50 2017 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Tue Jul 18 22:14:50 2017 +0000"
      },
      "message": "Merge \"stagefright: check aac_frame_length to prevent infinite loop\" into klp-dev"
    },
    {
      "commit": "502c2f405355c3253990ac4edae345ac1907f916",
      "tree": "71cb549d0c161a299ad8b3ab4832501963bfbd5b",
      "parents": [
        "da84963c1f4482be7570b68293906e6cc61200bd"
      ],
      "author": {
        "name": "Wei Jia",
        "email": "wjia@google.com",
        "time": "Thu Jul 13 17:47:56 2017 -0700"
      },
      "committer": {
        "name": "Wei Jia",
        "email": "wjia@google.com",
        "time": "Mon Jul 17 23:26:10 2017 +0000"
      },
      "message": "MediaPlayerService: fix access of mPlayer in client\n\nTest: poc doesn\u0027t crash\nBug: 38234812\nChange-Id: I6f9be046ff66d2d5bed27bd712287e4ead550830\n"
    },
    {
      "commit": "da84963c1f4482be7570b68293906e6cc61200bd",
      "tree": "866ef152289b367400e45f5a3059f98639ec9817",
      "parents": [
        "f57dc8b72fc16d170b17d55608f07648855257f3",
        "e94149ea039b25af7c2dd3bcedbde4bc176f281c"
      ],
      "author": {
        "name": "Wei Jia",
        "email": "wjia@google.com",
        "time": "Fri Jul 14 23:25:32 2017 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Fri Jul 14 23:25:32 2017 +0000"
      },
      "message": "Merge \"DO NOT MERGE : MPEG4Extractor: ensure returned status is checked.\" into klp-dev"
    },
    {
      "commit": "f57dc8b72fc16d170b17d55608f07648855257f3",
      "tree": "737cf4e43879c7e3e577e3474cb62bafd3d24f27",
      "parents": [
        "cf39f0e67ab16d96b9b862641194e226d35afb79",
        "0882414c30cbe31dfe69fa261e3286fa04c553ba"
      ],
      "author": {
        "name": "TreeHugger Robot",
        "email": "treehugger-gerrit@google.com",
        "time": "Mon Jul 10 19:52:17 2017 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Mon Jul 10 19:52:17 2017 +0000"
      },
      "message": "Merge \"audio effects: filter reserved effect commands\" into klp-dev"
    },
    {
      "commit": "6e2bcf40e4083be3a0fbb13d03293a78301e66ef",
      "tree": "1b1cec1dfa4b56dd9a2a0822a2747bf2618cbaba",
      "parents": [
        "cf39f0e67ab16d96b9b862641194e226d35afb79"
      ],
      "author": {
        "name": "Chong Zhang",
        "email": "chz@google.com",
        "time": "Fri Jul 07 18:25:16 2017 -0700"
      },
      "committer": {
        "name": "Chong Zhang",
        "email": "chz@google.com",
        "time": "Mon Jul 10 10:42:27 2017 -0700"
      },
      "message": "stagefright: check aac_frame_length to prevent infinite loop\n\nbug: 62673179\nChange-Id: I5da44822ad2ff59d396d1df42f34cd0a5620e134\n"
    },
    {
      "commit": "e94149ea039b25af7c2dd3bcedbde4bc176f281c",
      "tree": "2e2d81f958c4cb5256d703034e334d8735a9cc7c",
      "parents": [
        "cf39f0e67ab16d96b9b862641194e226d35afb79"
      ],
      "author": {
        "name": "Wei Jia",
        "email": "wjia@google.com",
        "time": "Tue Feb 14 17:07:24 2017 -0800"
      },
      "committer": {
        "name": "Wei Jia",
        "email": "wjia@google.com",
        "time": "Fri Jun 30 11:56:37 2017 -0700"
      },
      "message": "DO NOT MERGE : MPEG4Extractor: ensure returned status is checked.\n\nAlso fix handling of zero atom size in MPEG4Source::parseChunk.\nIDataSource: ensure readAt returns correct status.\nTest: manually test with mediaplayer.\nBug: 34718515\nChange-Id: I1219ec579aa0876dc1230e36af46b158b84c6d77\n\n(cherry picked from commit ff1fb4d5cdd3b2b28c69edd8cd3021e335ca381a)\n"
    },
    {
      "commit": "b4d9e1b41301b11bf4e4d7c9cfef27850e518b0c",
      "tree": "a45480c79e657207003812407b577fd490a7507d",
      "parents": [
        "cf39f0e67ab16d96b9b862641194e226d35afb79"
      ],
      "author": {
        "name": "Lajos Molnar",
        "email": "lajos@google.com",
        "time": "Tue Jun 27 13:58:07 2017 -0700"
      },
      "committer": {
        "name": "Lajos Molnar",
        "email": "lajos@google.com",
        "time": "Tue Jun 27 13:59:30 2017 -0700"
      },
      "message": "stagefright: avoid buffer overflow in base64 decoder\n\nBug: 62673128\nChange-Id: Id5f04b772aaca3184879bd5bca453ad9e82c7f94\n"
    },
    {
      "commit": "0882414c30cbe31dfe69fa261e3286fa04c553ba",
      "tree": "5559abaf90754b43d118e1962d9569fa5cb9638d",
      "parents": [
        "1159ffd5e3f832206982d45a7b030b943cc4775e"
      ],
      "author": {
        "name": "Eric Laurent",
        "email": "elaurent@google.com",
        "time": "Thu Jun 15 18:43:46 2017 -0700"
      },
      "committer": {
        "name": "Eric Laurent",
        "email": "elaurent@google.com",
        "time": "Sat Jun 17 21:47:52 2017 +0000"
      },
      "message": "audio effects: filter reserved effect commands\n\nBlock effect commands reserved for framework use when\nreceived on server side IAudioEffect. Applications have no reason\nto use these commands and they present a unnecessary attack surface.\n\nBug: 62019992\nTest: run CTS tests for audio effects\nChange-Id: Ie680d5d5650f99dbabf93891703e1cde2c2e852d\n"
    },
    {
      "commit": "cf39f0e67ab16d96b9b862641194e226d35afb79",
      "tree": "6f0700eee053d88429fc5cbf59aecf8de79019a8",
      "parents": [
        "1159ffd5e3f832206982d45a7b030b943cc4775e"
      ],
      "author": {
        "name": "Andy Hung",
        "email": "hunga@google.com",
        "time": "Mon Jun 12 17:22:46 2017 -0700"
      },
      "committer": {
        "name": "Andy Hung",
        "email": "hunga@google.com",
        "time": "Thu Jun 15 18:10:10 2017 -0700"
      },
      "message": "Track: Check buffer size of static tracks\n\nMerged-In: Ia7edd9a802905214a27961dbcec6352f6ef98f73\nMerged-In: I633caf563d3607dbe4b9be10be1687efce33469c\nTest: Native POC\nBug: 38340117\nChange-Id: I633caf563d3607dbe4b9be10be1687efce33469c\n"
    },
    {
      "commit": "1159ffd5e3f832206982d45a7b030b943cc4775e",
      "tree": "aef16a6e9d49e0d1b59bef3b487f21244e1ab8ee",
      "parents": [
        "ef3a4aead0eb4d6b0615159489d4a187ce90de2c"
      ],
      "author": {
        "name": "Andy Hung",
        "email": "hunga@google.com",
        "time": "Mon Feb 13 18:50:48 2017 -0800"
      },
      "committer": {
        "name": "Andy Hung",
        "email": "hunga@google.com",
        "time": "Mon Jun 12 17:52:06 2017 -0700"
      },
      "message": "AudioFlinger: Fix memory allocation for client-less tracks\n\nTest: Ringtone with BT\nBug: 35350587\nBug: 38340117\nChange-Id: If247d319d58f8f4d18b49f58ec950491871ebb2d\n(cherry picked from commit afb31487f3156a7284d2f0d06646c7bc00d99537)\n"
    },
    {
      "commit": "ef3a4aead0eb4d6b0615159489d4a187ce90de2c",
      "tree": "d7dba055a7c35d6775e24b5984d6675adaae60f6",
      "parents": [
        "d050902155d820e0bbba48ec1a7764b939bdba9c",
        "68b9e0f5d69d3b1e7b7628037696ce32f032e819"
      ],
      "author": {
        "name": "Ricardo Garcia",
        "email": "rago@google.com",
        "time": "Wed Jun 07 13:19:48 2017 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Wed Jun 07 13:19:48 2017 +0000"
      },
      "message": "Merge \"Fix security vulnerability: Equalizer setParameter memory overflow\" into klp-dev"
    },
    {
      "commit": "d050902155d820e0bbba48ec1a7764b939bdba9c",
      "tree": "1514e4e7aaee2f5d30c0ed6d9dadf1d4fd202a9a",
      "parents": [
        "f5d6e98996f28ae54df876f3e657058c7c7dae7c",
        "fc609407050deb43ec5f0bc8e234c9896eaccbb4"
      ],
      "author": {
        "name": "TreeHugger Robot",
        "email": "treehugger-gerrit@google.com",
        "time": "Wed Jun 07 04:51:35 2017 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Wed Jun 07 04:51:36 2017 +0000"
      },
      "message": "Merge \"Check the buffer index from acquireBuffer\" into klp-dev"
    },
    {
      "commit": "68b9e0f5d69d3b1e7b7628037696ce32f032e819",
      "tree": "451ab7ee32fcb07da1289e83a62eb3725073fe29",
      "parents": [
        "5136b7436f98b53cbca3891e0763584f1c94b442"
      ],
      "author": {
        "name": "rago",
        "email": "rago@google.com",
        "time": "Mon Jun 05 12:15:05 2017 -0700"
      },
      "committer": {
        "name": "rago",
        "email": "rago@google.com",
        "time": "Tue Jun 06 18:05:31 2017 -0700"
      },
      "message": "Fix security vulnerability: Equalizer setParameter memory overflow\n\nBug: 37563371\n\nTest: use POC on bug or cts security test\nChange-Id: I9c9453a222b53fd5ef821330a34cb9e938e4d9c5\n"
    },
    {
      "commit": "f5d6e98996f28ae54df876f3e657058c7c7dae7c",
      "tree": "55e72cae66618af6f0df429eb4a1f3f024eb73a1",
      "parents": [
        "021575025c132594e69acac882cdce1f3e0a57ed",
        "fa5c6c97ee86ff038979cedea5c449be4e2b9899"
      ],
      "author": {
        "name": "Andy Hung",
        "email": "hunga@google.com",
        "time": "Tue Jun 06 20:50:11 2017 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Tue Jun 06 20:50:12 2017 +0000"
      },
      "message": "Merge \"EffectBundle: Check value size for get preset name\" into klp-dev"
    },
    {
      "commit": "021575025c132594e69acac882cdce1f3e0a57ed",
      "tree": "54ae2170513c7fc205266e601173fedecca59a95",
      "parents": [
        "2da03f40eb1c8a135c0f64fc572ee0a0869a678e",
        "90d2dd403bc8faa421cfc6b26930e5aa69879943"
      ],
      "author": {
        "name": "TreeHugger Robot",
        "email": "treehugger-gerrit@google.com",
        "time": "Tue Jun 06 20:10:08 2017 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Tue Jun 06 20:10:10 2017 +0000"
      },
      "message": "Merge \"better manage buffer for libstagefright_soft_mpeg4enc\" into klp-dev"
    },
    {
      "commit": "2da03f40eb1c8a135c0f64fc572ee0a0869a678e",
      "tree": "1b76752e9bcf166b5e0b4d01214758b8ffa1fb44",
      "parents": [
        "da924b45e19ebe195f0f9a281527bb39b9c667b6",
        "0b5726782d5f9764325057870cef2750853f286a"
      ],
      "author": {
        "name": "TreeHugger Robot",
        "email": "treehugger-gerrit@google.com",
        "time": "Tue Jun 06 20:05:05 2017 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Tue Jun 06 20:05:06 2017 +0000"
      },
      "message": "Merge \"m4v_h263: update width/height only when they are valid.\" into klp-dev"
    },
    {
      "commit": "da924b45e19ebe195f0f9a281527bb39b9c667b6",
      "tree": "2911e9aec344421fa5ff8b1951b92f3bfedc6db7",
      "parents": [
        "2f9eacc3ae01d17745f8da6ecc198474ecdb4555",
        "677010098a3451960654be6f7649b38fa14760f3"
      ],
      "author": {
        "name": "Wei Jia",
        "email": "wjia@google.com",
        "time": "Tue Jun 06 18:39:58 2017 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Tue Jun 06 18:39:59 2017 +0000"
      },
      "message": "Merge \"DO NOT MERGE - m4v_h263: check header first before decoding a frame.\" into klp-dev"
    },
    {
      "commit": "90d2dd403bc8faa421cfc6b26930e5aa69879943",
      "tree": "7968bdf14093dcd6751a73fd3f3e22065db6dae7",
      "parents": [
        "5136b7436f98b53cbca3891e0763584f1c94b442"
      ],
      "author": {
        "name": "Ray Essick",
        "email": "essick@google.com",
        "time": "Fri Jun 02 13:07:19 2017 -0700"
      },
      "committer": {
        "name": "Ray Essick",
        "email": "essick@google.com",
        "time": "Fri Jun 02 13:07:19 2017 -0700"
      },
      "message": "better manage buffer for libstagefright_soft_mpeg4enc\n\nExisting code allocated buffer, adjusted pointer to use it, and would\nadjust the pointer back when it came time to free the space. The problem\nwas that the adjustment was based on user-supplied values and if the\nuser changed those values between alloc and free (which was possible),\nthe code ended up free()ing the wrong address.\n\nWe fix this by keeping an extra pointer -- the unmodified allocation --\nwhich we use for the subsequent free() calls. This makes the free()\nindependent of any changes to values that the user provides.\n\nBug: 36075363\nTest: ran poc against patched nyc-mr2-dev tree\nChange-Id: I7013ff5883a945c4647517b2980c76a6558f23d2\n"
    },
    {
      "commit": "2f9eacc3ae01d17745f8da6ecc198474ecdb4555",
      "tree": "5a91cde655518aae3a11529df3a332f8d0dce343",
      "parents": [
        "5136b7436f98b53cbca3891e0763584f1c94b442",
        "e077beb91686c4b7e9d645664da59b7b25bd3978"
      ],
      "author": {
        "name": "TreeHugger Robot",
        "email": "treehugger-gerrit@google.com",
        "time": "Fri Jun 02 04:02:09 2017 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Fri Jun 02 04:02:10 2017 +0000"
      },
      "message": "Merge \"Fix potential leak\" into klp-dev"
    },
    {
      "commit": "fc609407050deb43ec5f0bc8e234c9896eaccbb4",
      "tree": "c6502a3b97ad0a29bf27a617b722fbda7dddfefe",
      "parents": [
        "5136b7436f98b53cbca3891e0763584f1c94b442"
      ],
      "author": {
        "name": "Pawin Vongmasa",
        "email": "pawin@google.com",
        "time": "Mon May 22 18:24:30 2017 -0700"
      },
      "committer": {
        "name": "Pawin Vongmasa",
        "email": "pawin@google.com",
        "time": "Mon May 22 20:12:54 2017 -0700"
      },
      "message": "Check the buffer index from acquireBuffer\n\nTest: Run the POC\nTest: Small CtsMediaTestCases\nBug: 37563942\nMerged-In: I8ddfbc91a08d96de1f732e6776d6f90997042f6b\nChange-Id: I8ddfbc91a08d96de1f732e6776d6f90997042f6b\n"
    },
    {
      "commit": "677010098a3451960654be6f7649b38fa14760f3",
      "tree": "4ebeccc9fa2773528138419076498cfd43c72780",
      "parents": [
        "5136b7436f98b53cbca3891e0763584f1c94b442"
      ],
      "author": {
        "name": "Wei Jia",
        "email": "wjia@google.com",
        "time": "Fri May 19 14:34:10 2017 -0700"
      },
      "committer": {
        "name": "Wei Jia",
        "email": "wjia@google.com",
        "time": "Mon May 22 14:58:11 2017 -0700"
      },
      "message": "DO NOT MERGE - m4v_h263: check header first before decoding a frame.\n\nTest: fix the file in the bug\nBug: 37660827\nChange-Id: I9d6919f96c0c9f29221be1e8e852ecb21062bad9\n"
    },
    {
      "commit": "0b5726782d5f9764325057870cef2750853f286a",
      "tree": "d40565a9fe4af241263423dec164ac9230ba37ca",
      "parents": [
        "5136b7436f98b53cbca3891e0763584f1c94b442"
      ],
      "author": {
        "name": "Wei Jia",
        "email": "wjia@google.com",
        "time": "Thu May 18 12:43:12 2017 -0700"
      },
      "committer": {
        "name": "Wei Jia",
        "email": "wjia@google.com",
        "time": "Thu May 18 19:46:56 2017 +0000"
      },
      "message": "m4v_h263: update width/height only when they are valid.\n\nTest: the file in the bug doesn\u0027t crash\nBug: 37079296\nChange-Id: Ie092971dda568119ca38ec67d65ccfc00df93185\n"
    },
    {
      "commit": "fa5c6c97ee86ff038979cedea5c449be4e2b9899",
      "tree": "79f76f898ff2ecbca024fdf71a63935b0f9bab67",
      "parents": [
        "5136b7436f98b53cbca3891e0763584f1c94b442"
      ],
      "author": {
        "name": "Andy Hung",
        "email": "hunga@google.com",
        "time": "Tue May 16 12:04:50 2017 -0700"
      },
      "committer": {
        "name": "Andy Hung",
        "email": "hunga@google.com",
        "time": "Tue May 16 22:03:24 2017 +0000"
      },
      "message": "EffectBundle: Check value size for get preset name\n\nTest: CTS testAllEffectsEqualizer_CVE_2017_0401\nBug: 37536407\nChange-Id: I347af04677fc49a01efb549f06ff81d1a00dc4d0\n"
    },
    {
      "commit": "5136b7436f98b53cbca3891e0763584f1c94b442",
      "tree": "e9d565324b0bf03ad10a7cf23059c1e67e58bfe2",
      "parents": [
        "bf928560aca13c5a615cb3ffc3b6aad16cdf3824",
        "ab34612a31e82b713ca0ac043e14f68f3788fbda"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Tue May 16 15:20:59 2017 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Tue May 16 15:21:00 2017 +0000"
      },
      "message": "Merge \"Fix memory leak in error case\" into klp-dev"
    },
    {
      "commit": "bf928560aca13c5a615cb3ffc3b6aad16cdf3824",
      "tree": "50656b5c35461513e816499b91d897395bb87860",
      "parents": [
        "922ad6183e1524c06abc4bcc60b8748a45b8bd70"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Fri May 12 15:35:30 2017 -0700"
      },
      "committer": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Fri May 12 22:38:29 2017 +0000"
      },
      "message": "Limit ogg packet size\n\nA malformed ogg file might lace together a very large packet, which\ncould lead to out of memory conditions. Limit the packet size to\navoid this.\n\nBug: 36592202\nChange-Id: I8650b3ec54a0de9ec302a7cbac296bb85efcfb3d\n"
    },
    {
      "commit": "ab34612a31e82b713ca0ac043e14f68f3788fbda",
      "tree": "e532e184f504d199ce998929de1c4571b51bc2bc",
      "parents": [
        "922ad6183e1524c06abc4bcc60b8748a45b8bd70"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Fri May 12 10:45:14 2017 -0700"
      },
      "committer": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Fri May 12 10:45:14 2017 -0700"
      },
      "message": "Fix memory leak in error case\n\nBug: 37239013\nChange-Id: Ic33e0f7ed946d0729efa46f69aff1a5d35e81b1e\n"
    },
    {
      "commit": "e077beb91686c4b7e9d645664da59b7b25bd3978",
      "tree": "72154598e1f5204b31974ca862e81c27be768ec1",
      "parents": [
        "922ad6183e1524c06abc4bcc60b8748a45b8bd70"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Tue May 09 14:17:06 2017 -0700"
      },
      "committer": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Tue May 09 14:17:06 2017 -0700"
      },
      "message": "Fix potential leak\n\nFix potential memory leak introduced with bugfix for bug 31449945.\n\nBug: 36389123\nChange-Id: I5a9a3551692d6cba385b45c4c7a465aa377a62b1\n"
    },
    {
      "commit": "922ad6183e1524c06abc4bcc60b8748a45b8bd70",
      "tree": "9382274447c05302a78d7f65cee4acb73b094a1a",
      "parents": [
        "5c364997a3191cb4e8a288befae87e811a723256",
        "45060d62f6ac2a6661809a1696bd007a64b93e64"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Mon Apr 10 19:57:08 2017 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Mon Apr 10 19:57:08 2017 +0000"
      },
      "message": "Merge \"Don\u0027t allow using or allocating a buffer after the first state transition\" into klp-dev"
    },
    {
      "commit": "5c364997a3191cb4e8a288befae87e811a723256",
      "tree": "263b0eade1b86cc767abaa1df6608c6b7509efe6",
      "parents": [
        "13c77f4fe063ad38d90502651ce545e1ed3ba888"
      ],
      "author": {
        "name": "Roger1 Jonsson",
        "email": "roger1.jonsson@sonymobile.com",
        "time": "Wed Oct 26 09:20:00 2016 +0200"
      },
      "committer": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Tue Apr 04 19:40:02 2017 +0000"
      },
      "message": "Avoid crash for stss sync sample number 0\n\nA sample number value of 0 means that the value stored in\nthe mSyncSamples array, would become negative (-1),\nwhen converted to index value. This causes a crash.\n\nMake sure that stss sample numbers are bigger\nthan 0 before converting sample number to index value.\n\nBug: 32423862\nbug: 35645051\nTest: Playback video that triggers stss sync sample number 0\nChange-Id: I35bee7c718e01b086d7e05deda13b38083f509f5\n"
    },
    {
      "commit": "45060d62f6ac2a6661809a1696bd007a64b93e64",
      "tree": "4629768c7a9f06e0005f075a6dc7f09d477ea533",
      "parents": [
        "13c77f4fe063ad38d90502651ce545e1ed3ba888"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Mon Mar 27 15:04:25 2017 -0700"
      },
      "committer": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Tue Mar 28 17:16:49 2017 +0000"
      },
      "message": "Don\u0027t allow using or allocating a buffer after the first state transition\n\nBug: 35467458\nChange-Id: Ia76c8cec8ad2abb95ca29b2a89075f7acab4b174\n"
    },
    {
      "commit": "13c77f4fe063ad38d90502651ce545e1ed3ba888",
      "tree": "360cc8a57e7f9e25c8f682680e7c9ce685de188d",
      "parents": [
        "19b91af75247f5d78bb705541ce4fb56400bd275"
      ],
      "author": {
        "name": "Robert Shih",
        "email": "robertshih@google.com",
        "time": "Mon Oct 24 11:38:31 2016 -0700"
      },
      "committer": {
        "name": "Wonsik Kim",
        "email": "wonsik@google.com",
        "time": "Tue Mar 14 14:04:28 2017 -0700"
      },
      "message": "DO NOT MERGE FLACExtractor: copy protect mWriteBuffer\n\nBug: 30895578\nBug: 34970788\nChange-Id: I4cba36bbe3502678210e5925181683df9726b431\n"
    },
    {
      "commit": "19b91af75247f5d78bb705541ce4fb56400bd275",
      "tree": "e1921084716176e841cf7dc15d7ea82f1f69dd17",
      "parents": [
        "2076915c5f16f9f1a036cb70eb5d708f77fd8ff2",
        "6231243626b8b9c57593b1f0ee417f2c4af4c0aa"
      ],
      "author": {
        "name": "Ray Essick",
        "email": "essick@google.com",
        "time": "Mon Mar 13 22:38:40 2017 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Mon Mar 13 22:38:40 2017 +0000"
      },
      "message": "Merge \"Add bounds check in SoftAACEncoder2::onQueueFilled()\" into klp-dev"
    },
    {
      "commit": "2076915c5f16f9f1a036cb70eb5d708f77fd8ff2",
      "tree": "3ee9b17a95fdadf1b883c0abe895a3d560a005e2",
      "parents": [
        "b264ece2c02b97226a28df55dfe80ea0593421e3",
        "0495c029bd51bcfc1cca8c943ab4ce2f201dbe98"
      ],
      "author": {
        "name": "Ray Essick",
        "email": "essick@google.com",
        "time": "Mon Mar 13 22:35:43 2017 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Mon Mar 13 22:35:43 2017 +0000"
      },
      "message": "Merge \"Fix TOCTOU problem in libstagefright_soft_aacenc\" into klp-dev"
    },
    {
      "commit": "b264ece2c02b97226a28df55dfe80ea0593421e3",
      "tree": "b413372d709392ea10254ca9c3430ed4a97db3cd",
      "parents": [
        "012e5fd39e36f69c11fbfaba3c801685895b1747",
        "8538a603ef992e75f29336499cb783f3ec19f18c"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Mon Mar 13 22:31:24 2017 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Mon Mar 13 22:31:25 2017 +0000"
      },
      "message": "Merge \"Fix integer overflow and divide-by-zero\" into klp-dev"
    },
    {
      "commit": "012e5fd39e36f69c11fbfaba3c801685895b1747",
      "tree": "9669ff23a7fbe6f8c903e863dfee55ea9b28de15",
      "parents": [
        "360cbbd72c4448fc7125a8f0f7a87d28ba41152d",
        "2ad2a92318a3b9daf78ebcdc597085adbf32600d"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Mon Mar 13 22:30:25 2017 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Mon Mar 13 22:30:25 2017 +0000"
      },
      "message": "Merge \"Fix NPDs in h263 decoder\" into klp-dev"
    },
    {
      "commit": "360cbbd72c4448fc7125a8f0f7a87d28ba41152d",
      "tree": "32c094eadc9fc7d695ee2b7277d52579c669394e",
      "parents": [
        "e0da30dc577a6c36d66345d00c47045a3d2f6490",
        "d1c19c57f66d91ea8033c8fa6510a8760a6e663b"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Mon Mar 13 22:28:40 2017 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Mon Mar 13 22:28:41 2017 +0000"
      },
      "message": "Merge \"Fix out of bounds access\" into klp-dev"
    },
    {
      "commit": "6231243626b8b9c57593b1f0ee417f2c4af4c0aa",
      "tree": "35fa83242e3770be830339d8165faa004fea1d94",
      "parents": [
        "0495c029bd51bcfc1cca8c943ab4ce2f201dbe98"
      ],
      "author": {
        "name": "Ray Essick",
        "email": "essick@google.com",
        "time": "Mon Mar 13 11:59:57 2017 -0700"
      },
      "committer": {
        "name": "Ray Essick",
        "email": "essick@google.com",
        "time": "Mon Mar 13 11:59:57 2017 -0700"
      },
      "message": "Add bounds check in SoftAACEncoder2::onQueueFilled()\n\nOriginal code blindly copied some header information into the\nuser-supplied buffer without checking for sufficient space.\nThe code does check when it gets to filling the data -- it\u0027s\njust the header copies that weren\u0027t checked.\n\nBug: 34617444\nTest: ran POC before/after\nChange-Id: I6e80ec90616f6cd02bb8316cd2d6e309b7e4729d\n"
    },
    {
      "commit": "2ad2a92318a3b9daf78ebcdc597085adbf32600d",
      "tree": "5b65ae5338ec0b38d27b249517384e1264ce636a",
      "parents": [
        "e0da30dc577a6c36d66345d00c47045a3d2f6490"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Fri Mar 03 13:37:27 2017 -0800"
      },
      "committer": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Mon Mar 13 16:04:33 2017 +0000"
      },
      "message": "Fix NPDs in h263 decoder\n\nBug: 35269635\nTest: decoded PoC with and without patch\nChange-Id: I636a14360c7801cc5bca63c9cb44d1d235df8fd8\n"
    },
    {
      "commit": "0495c029bd51bcfc1cca8c943ab4ce2f201dbe98",
      "tree": "3236686da1f60dfa5788d6d62b15078f49915f20",
      "parents": [
        "dd447c354eb6b2a99d67fd787cafe91e07e1fce6"
      ],
      "author": {
        "name": "Ray Essick",
        "email": "essick@google.com",
        "time": "Fri Mar 10 16:03:40 2017 -0800"
      },
      "committer": {
        "name": "Ray Essick",
        "email": "essick@google.com",
        "time": "Fri Mar 10 16:03:40 2017 -0800"
      },
      "message": "Fix TOCTOU problem in libstagefright_soft_aacenc\n\nFixes a configuration error where we sized a buffer initially based\non the configuration at the time and held onto the buffer through the\nrest of our lifetime. If the configuration was changed in a way that\nresulted in needing a different size buffer, the code did not make\nthis happen.\n\nPatch keeps the buffer around but also stores the \u0027current allocation\nsize\u0027.  This allows the later code that preps the buffer to query if\nthe buffer size is same or changed.  If changed, we discard the old\nbuffer and allocate a new one of the appropriate size.\n\nsafetynet logging added so we can tell how often this happens in the\nfield.\n\nTesting was done on nyc-mr2 (where poc was built). Patch applies\nwithout change to k/l/m/n/master.\n\nBug: 34621073\nTest: run POC, saw new diagnostics saying it caught the size change.\nChange-Id: Ia95aadc8c727434b7ba9628deeae327c405336d3\n"
    },
    {
      "commit": "d1c19c57f66d91ea8033c8fa6510a8760a6e663b",
      "tree": "beb7721f7fffb3ffbd7c686f37ade633f8909ba6",
      "parents": [
        "dd447c354eb6b2a99d67fd787cafe91e07e1fce6"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Fri Mar 10 11:28:44 2017 -0800"
      },
      "committer": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Fri Mar 10 22:56:38 2017 +0000"
      },
      "message": "Fix out of bounds access\n\nBug: 34618607\nChange-Id: I84f0ef948414d0b2d54e8948b6c30b8ae4da2b36\n"
    },
    {
      "commit": "e0da30dc577a6c36d66345d00c47045a3d2f6490",
      "tree": "a0571916c873298005f8802294a10702f7e06d4c",
      "parents": [
        "dd447c354eb6b2a99d67fd787cafe91e07e1fce6",
        "64e843f1c312382e3e1a6f6e17f8d895e9c6efe8"
      ],
      "author": {
        "name": "Andy Hung",
        "email": "hunga@google.com",
        "time": "Fri Mar 10 22:29:51 2017 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Fri Mar 10 22:29:51 2017 +0000"
      },
      "message": "Merge \"DO NOT MERGE AudioFlinger: Check framecount overflow when creating track\" into klp-dev"
    },
    {
      "commit": "8538a603ef992e75f29336499cb783f3ec19f18c",
      "tree": "ab01a054e6eacb3a06ef1388faa9c523cce12e43",
      "parents": [
        "dd447c354eb6b2a99d67fd787cafe91e07e1fce6"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Thu Mar 09 15:01:55 2017 -0800"
      },
      "committer": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Thu Mar 09 23:10:08 2017 +0000"
      },
      "message": "Fix integer overflow and divide-by-zero\n\nBug: 35763994\nTest: ran CTS with and without fix\nChange-Id: If835e97ce578d4fa567e33e349e48fb7b2559e0e\n"
    },
    {
      "commit": "dd447c354eb6b2a99d67fd787cafe91e07e1fce6",
      "tree": "86332d92fa61305d14f52440859d71754cd25e8b",
      "parents": [
        "b6aa3901ceb4b51ca1e51799e8cc95f630d49c33"
      ],
      "author": {
        "name": "Wonsik Kim",
        "email": "wonsik@google.com",
        "time": "Fri Feb 10 14:29:40 2017 +0900"
      },
      "committer": {
        "name": "Wonsik Kim",
        "email": "wonsik@google.com",
        "time": "Wed Feb 15 13:09:50 2017 +0900"
      },
      "message": "DO NOT MERGE codecs: handle onReset() for a few encoders\n\nTest: Run PoC binaries\nBug: 34749392\nBug: 34705519\nChange-Id: I3356eb615b0e79272d71d72578d363671038c6dd\n"
    },
    {
      "commit": "64e843f1c312382e3e1a6f6e17f8d895e9c6efe8",
      "tree": "ef414eb6b5d745aba49a9bb3823470ace97265e6",
      "parents": [
        "b6aa3901ceb4b51ca1e51799e8cc95f630d49c33"
      ],
      "author": {
        "name": "Andy Hung",
        "email": "hunga@google.com",
        "time": "Mon Feb 13 18:48:39 2017 -0800"
      },
      "committer": {
        "name": "Andy Hung",
        "email": "hunga@google.com",
        "time": "Tue Feb 14 16:39:50 2017 -0800"
      },
      "message": "DO NOT MERGE AudioFlinger: Check framecount overflow when creating track\n\nTest: Native POC\nBug: 34749571\nChange-Id: I7529658e52ac7e64d162eb5338f10fb25eaa8fe7\n"
    },
    {
      "commit": "b6aa3901ceb4b51ca1e51799e8cc95f630d49c33",
      "tree": "5dd7e7131b41c3fc122c80833b4f03f0d625eb0b",
      "parents": [
        "65433ff04d9b0d8aa02d9ab8f87b5598c7b4a979",
        "9667e3eff2d34c3797c3b529370de47b2c1f1bf6"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Mon Feb 13 21:36:48 2017 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Mon Feb 13 21:36:48 2017 +0000"
      },
      "message": "Merge \"Fix overflow check and check read result\" into klp-dev"
    },
    {
      "commit": "65433ff04d9b0d8aa02d9ab8f87b5598c7b4a979",
      "tree": "dc86b8ced0ccffbf953a6a1073ab21ffebb425d5",
      "parents": [
        "fdf64bab960ec1d0effab8dd8ea67e46d120a45b",
        "9b6b81d366e3f37bfe1ad3fc3d5bfd96f901fb96"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Mon Feb 13 21:35:18 2017 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Mon Feb 13 21:35:18 2017 +0000"
      },
      "message": "Merge \"stagefright: parseApp check data boundary conditions\" into klp-dev"
    },
    {
      "commit": "9667e3eff2d34c3797c3b529370de47b2c1f1bf6",
      "tree": "cddf3b6ae1401bed68a831c735c71319340447cc",
      "parents": [
        "fdf64bab960ec1d0effab8dd8ea67e46d120a45b"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Mon Feb 06 14:12:30 2017 -0800"
      },
      "committer": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Mon Feb 06 22:31:24 2017 +0000"
      },
      "message": "Fix overflow check and check read result\n\nBug: 33861560\nTest: build\nChange-Id: Ia85519766e19a6e37237166f309750b3e8323c4e\n"
    },
    {
      "commit": "fdf64bab960ec1d0effab8dd8ea67e46d120a45b",
      "tree": "c0e73d122ec6691384ef8f0b16debb3a1c60fdb3",
      "parents": [
        "2dd1d5e02ef7f3a10db86dc2455d5bb9d35998c2",
        "4b49489c12e6862e9a320ebcb53872e809ed20ec"
      ],
      "author": {
        "name": "Eino-Ville Talvala",
        "email": "etalvala@google.com",
        "time": "Thu Feb 02 23:42:07 2017 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Thu Feb 02 23:42:08 2017 +0000"
      },
      "message": "Merge \"CameraBase: Don\u0027t return an sp\u003c\u003e by reference\" into klp-dev"
    },
    {
      "commit": "2dd1d5e02ef7f3a10db86dc2455d5bb9d35998c2",
      "tree": "1716a6c4990b908c6f9981f0dc01f1668fd63b2e",
      "parents": [
        "cbf5e6915c42c691a6ccb9a5d249e450f9e67467"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Thu Feb 02 20:53:17 2017 +0000"
      },
      "committer": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Thu Feb 02 20:53:17 2017 +0000"
      },
      "message": "Revert \"Turn off overflow protection for various math functions\"\n\nThis reverts commit cbf5e6915c42c691a6ccb9a5d249e450f9e67467.\n\nChange-Id: I0a81c26d22fee36485b21c285dcc91fbd518e1dd\n"
    },
    {
      "commit": "4b49489c12e6862e9a320ebcb53872e809ed20ec",
      "tree": "c0e73d122ec6691384ef8f0b16debb3a1c60fdb3",
      "parents": [
        "c2f0c73bfcf36219f446e3eef9effe49a3a415a5"
      ],
      "author": {
        "name": "Eino-Ville Talvala",
        "email": "etalvala@google.com",
        "time": "Wed Feb 01 15:27:41 2017 -0800"
      },
      "committer": {
        "name": "Eino-Ville Talvala",
        "email": "etalvala@google.com",
        "time": "Thu Feb 02 11:40:56 2017 -0800"
      },
      "message": "CameraBase: Don\u0027t return an sp\u003c\u003e by reference\n\nIf the server dies, the binder death callback clears out\nthe global camera service sp\u003c\u003e, and any current references to it\nwill become quite unhappy.\n\nTest: Camera CTS passes\nBug: 31992879\nChange-Id: I2966bed35d0319e3f26e3d4b1b8dc08006a22348\n"
    },
    {
      "commit": "cbf5e6915c42c691a6ccb9a5d249e450f9e67467",
      "tree": "fdc5b8e48fe23556c02ecf2fc046d860ecf3695c",
      "parents": [
        "c2f0c73bfcf36219f446e3eef9effe49a3a415a5"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Wed Feb 01 15:35:35 2017 -0800"
      },
      "committer": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Thu Feb 02 00:10:58 2017 +0000"
      },
      "message": "Turn off overflow protection for various math functions\n\nThese functions also exist as arm assembly files, where the overflows\njust wrap around, and this makes their plain C equivalents behave\nthe same.\n\nBug: 32577290\nBug: 33071964\nTest: ran PoC for bug 32577290 using plain C source code\nChange-Id: I73c2609589e7a89d36f6c44391548312259daf14\n"
    },
    {
      "commit": "9b6b81d366e3f37bfe1ad3fc3d5bfd96f901fb96",
      "tree": "38b3dc2050589ca29d23d8d977fd9b1f19f997e2",
      "parents": [
        "c2f0c73bfcf36219f446e3eef9effe49a3a415a5"
      ],
      "author": {
        "name": "Mark Salyzyn",
        "email": "salyzyn@google.com",
        "time": "Mon Jun 23 14:13:22 2014 -0700"
      },
      "committer": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Thu Jan 19 14:06:57 2017 -0800"
      },
      "message": "stagefright: parseApp check data boundary conditions\n\nTest: compile, no poc for boundary violation.\nBug: 34056274\nChange-Id: I23f5ccba8f211e01d9a3a741c8ea537b55aab4e2\n"
    },
    {
      "commit": "c2f0c73bfcf36219f446e3eef9effe49a3a415a5",
      "tree": "1716a6c4990b908c6f9981f0dc01f1668fd63b2e",
      "parents": [
        "b47a5ab10732758aa84a064a0729314f3897d802"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Fri Jan 06 13:57:51 2017 -0800"
      },
      "committer": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Fri Jan 13 08:34:43 2017 -0800"
      },
      "message": "Don\u0027t CHECK when buffer is too large\n\nBug: 31647370\nTest: ran CTS test with and without patch\nChange-Id: I4e3a37aabc9387432671c1c0c469241142612cc4\n"
    },
    {
      "commit": "b47a5ab10732758aa84a064a0729314f3897d802",
      "tree": "e199df1695a26ec44920c5f7336a25f8160bd56a",
      "parents": [
        "1576f5968c4458af357065bf0f10acf71754cc21"
      ],
      "author": {
        "name": "Eric Laurent",
        "email": "elaurent@google.com",
        "time": "Thu Dec 01 15:28:29 2016 -0800"
      },
      "committer": {
        "name": "Eric Laurent",
        "email": "elaurent@google.com",
        "time": "Thu Dec 15 17:43:51 2016 -0800"
      },
      "message": "DO NOT MERGE - improve audio effect framwework thread safety\n\n- Reorganize handle effect creation code to make sure the effect engine\nis created with both thread and effect chain mutex held.\n- Reorganize handle disconnect code to make sure the effect engine\nis released with both thread and effect chain mutex held.\n- Protect IEffect interface methods in EffectHande with a Mutex.\n- Only pin effect if the session was acquired first.\n- Do not use strong pointer to EffectModule in EffectHandles:\nonly the EffectChain has a single strong reference to the EffectModule.\n- Check reply size before writing status in EffectHandle::command()\n\nBug: 32707507\nBug: 32095713\n\nChange-Id: Ia1098cba2cd32cc2d1c9dfdff4adc2388dfed80e\n"
    },
    {
      "commit": "1576f5968c4458af357065bf0f10acf71754cc21",
      "tree": "656627902f4f2db291620bee9b17c251b9fa164f",
      "parents": [
        "e275907e576601a3579747c3a842790bacf111e2",
        "dd79ccda92c1e9b982b2d0f8877d98e5258fbb73"
      ],
      "author": {
        "name": "Andy Hung",
        "email": "hunga@google.com",
        "time": "Sat Dec 03 00:32:27 2016 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Sat Dec 03 00:32:27 2016 +0000"
      },
      "message": "Merge \"Effect: Use local cached data for Effect commit\" into klp-dev"
    },
    {
      "commit": "e275907e576601a3579747c3a842790bacf111e2",
      "tree": "6a6550b1636a64348b4d53d38fdb3039482f5c98",
      "parents": [
        "501aee7a542a8c461d48c27cb1148a0936e3a9e5"
      ],
      "author": {
        "name": "rago",
        "email": "rago@google.com",
        "time": "Tue Nov 22 18:02:48 2016 -0800"
      },
      "committer": {
        "name": "rago",
        "email": "rago@google.com",
        "time": "Tue Nov 29 12:17:49 2016 -0800"
      },
      "message": "Fix security vulnerability: potential OOB write in audioserver\n\nBug: 32705438\nBug: 32703959\nTest: cts security test\nChange-Id: I8900c92fa55b56c4c2c9d721efdbabe6bfc8a4a4\n"
    },
    {
      "commit": "dd79ccda92c1e9b982b2d0f8877d98e5258fbb73",
      "tree": "eb7a2f14f528ad018d570b1412fcdcf3c03d57ea",
      "parents": [
        "501aee7a542a8c461d48c27cb1148a0936e3a9e5"
      ],
      "author": {
        "name": "Andy Hung",
        "email": "hunga@google.com",
        "time": "Tue Nov 15 17:19:58 2016 -0800"
      },
      "committer": {
        "name": "Andy Hung",
        "email": "hunga@google.com",
        "time": "Wed Nov 16 02:33:53 2016 +0000"
      },
      "message": "Effect: Use local cached data for Effect commit\n\nTest: POC, Cts Effect, BassBoost, EnvReverb, Equalizer,\nTest: LoudnessEnhancer, PresetReverb, Virtualizer, Visualizer\nBug: 32220769\nChange-Id: Iea96ba0daf71691ee8954cca4ba1c10fe827626e\n"
    },
    {
      "commit": "501aee7a542a8c461d48c27cb1148a0936e3a9e5",
      "tree": "ba628c7925434b9c01104055a61d5603f986cdb0",
      "parents": [
        "7fdd36418e945cf6a500018632dfb0ed8cb1a343",
        "01183402d757f0c28bfd5e3b127b3809dfd67459"
      ],
      "author": {
        "name": "Ricardo Garcia",
        "email": "rago@google.com",
        "time": "Tue Nov 15 23:19:20 2016 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Tue Nov 15 23:19:21 2016 +0000"
      },
      "message": "Merge \"Fix security vulnerability: Effect command might allow negative indexes\" into klp-dev"
    },
    {
      "commit": "01183402d757f0c28bfd5e3b127b3809dfd67459",
      "tree": "ef981ab16da5bb89eee7dca621c875aca0b4b571",
      "parents": [
        "c5768d0921a35c2f0de924168d14cb3da87d674d"
      ],
      "author": {
        "name": "rago",
        "email": "rago@google.com",
        "time": "Mon Nov 14 14:58:34 2016 -0800"
      },
      "committer": {
        "name": "rago",
        "email": "rago@google.com",
        "time": "Tue Nov 15 10:59:00 2016 -0800"
      },
      "message": "Fix security vulnerability: Effect command might allow negative indexes\n\nBug: 32448258\nBug: 32095626\n\nTest: Use POC bug or cts security test\nChange-Id: I69f24eac5866f8d9090fc4c0ebe58c2c297b63df\n"
    },
    {
      "commit": "7fdd36418e945cf6a500018632dfb0ed8cb1a343",
      "tree": "87d020714b9e6e309c35ccc4f1f2ed6fbdfa487d",
      "parents": [
        "c5768d0921a35c2f0de924168d14cb3da87d674d"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Fri Nov 11 09:20:00 2016 -0800"
      },
      "committer": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Fri Nov 11 09:20:00 2016 -0800"
      },
      "message": "Make VBRISeeker more robust\n\nBug: 32577290\nChange-Id: I9bcc9422ae7dd3ae4a38df330c9dcd7ac4941ec8\n"
    },
    {
      "commit": "c5768d0921a35c2f0de924168d14cb3da87d674d",
      "tree": "ccbb6d38dcc1b12bdbfbdfc148a13400ca17723a",
      "parents": [
        "f89590d00951b9fd04fcf70b40e1160989491265",
        "3d34cc76e315dfa8c3b1edf78835b0dab4980505"
      ],
      "author": {
        "name": "Andy Hung",
        "email": "hunga@google.com",
        "time": "Thu Nov 10 19:16:40 2016 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Thu Nov 10 19:16:41 2016 +0000"
      },
      "message": "Merge \"Effects: Check get parameter command size\" into klp-dev"
    },
    {
      "commit": "f89590d00951b9fd04fcf70b40e1160989491265",
      "tree": "89f5f06c697210150ed6e5058901e7a640c7e60b",
      "parents": [
        "fc6faebb083cca660b9c67171fe7925d70005e8f",
        "86cbc180f4cab6f02472f95f8d4bcae67aaabe8e"
      ],
      "author": {
        "name": "Andy Hung",
        "email": "hunga@google.com",
        "time": "Thu Nov 10 19:13:24 2016 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Thu Nov 10 19:13:24 2016 +0000"
      },
      "message": "Merge \"DO NOT MERGE: Visualizer: Check capture size and latency parameters\" into klp-dev"
    },
    {
      "commit": "fc6faebb083cca660b9c67171fe7925d70005e8f",
      "tree": "a78f3e89f07c36601e248f053dd89b819d9cf3f2",
      "parents": [
        "2ff80538b7063545e5e006f3eca96115175e7c82",
        "e981cca9fff3608af22bdf8fc1acef5470e25663"
      ],
      "author": {
        "name": "Ricardo Garcia",
        "email": "rago@google.com",
        "time": "Wed Nov 09 19:14:34 2016 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Wed Nov 09 19:14:35 2016 +0000"
      },
      "message": "Merge \"Fix security vulnerability: Equalizer command might allow negative indexes\" into klp-dev"
    },
    {
      "commit": "3d34cc76e315dfa8c3b1edf78835b0dab4980505",
      "tree": "fb24b34565049a9208769dc0424aba9d0cd666fd",
      "parents": [
        "2c28e5b1266a12163fed8236d34830f69f8216a2"
      ],
      "author": {
        "name": "Andy Hung",
        "email": "hunga@google.com",
        "time": "Fri Nov 04 19:40:53 2016 -0700"
      },
      "committer": {
        "name": "Andy Hung",
        "email": "hunga@google.com",
        "time": "Sat Nov 05 02:52:49 2016 +0000"
      },
      "message": "Effects: Check get parameter command size\n\nTest: Custom test.\nBug: 32438594\nBug: 32624850\nBug: 32635664\nChange-Id: I9b1315e2c02f11bea395bfdcf5c1ccddccbad8a6\n"
    },
    {
      "commit": "2ff80538b7063545e5e006f3eca96115175e7c82",
      "tree": "e2363b4eff58351d06e76cd80ea70f32458db644",
      "parents": [
        "2c28e5b1266a12163fed8236d34830f69f8216a2"
      ],
      "author": {
        "name": "Ray Essick",
        "email": "essick@google.com",
        "time": "Wed Nov 02 14:15:43 2016 -0700"
      },
      "committer": {
        "name": "Ray Essick",
        "email": "essick@google.com",
        "time": "Wed Nov 02 14:15:43 2016 -0700"
      },
      "message": "DO NOT MERGE: defensive parsing of mp3 album art information\n\nseveral points in stagefrights mp3 album art code\nused strlen() to parse user-supplied strings that may be\nunterminated, resulting in reading beyond the end of a buffer.\n\nThis changes the code to use strnlen() for 8-bit encodings and\nstrengthens the parsing of 16-bit encodings similarly. It also\nreworks how we watch for the end-of-buffer to avoid all over-reads.\n\nBug: 32377688\nTest: crafted mp3\u0027s w/ good/bad cover art. See what showed in play music\nChange-Id: Idbaf221fa2283b33e83f399562a3323dd095cc2c\n"
    },
    {
      "commit": "e981cca9fff3608af22bdf8fc1acef5470e25663",
      "tree": "cd45983c1392da6206b2e54775ccbf860619d310",
      "parents": [
        "2c28e5b1266a12163fed8236d34830f69f8216a2"
      ],
      "author": {
        "name": "rago",
        "email": "rago@google.com",
        "time": "Mon Oct 31 12:50:20 2016 -0700"
      },
      "committer": {
        "name": "Ricardo Garcia",
        "email": "rago@google.com",
        "time": "Tue Nov 01 17:40:37 2016 +0000"
      },
      "message": "Fix security vulnerability: Equalizer command might allow negative indexes\n\nBug: 32247948\nBug: 32438598\nBug: 32436341\n\nTest: use POC on bug or cts security test\n\nChange-Id: I91bd6aadb6c7410163e03101f365db767f4cd2a3\n(cherry picked from commit 0872b65cff9129633471945431b9a5a28418049c)\n"
    },
    {
      "commit": "86cbc180f4cab6f02472f95f8d4bcae67aaabe8e",
      "tree": "9afb0972f0596bd12b0dba51ffc77203e4a3c5cc",
      "parents": [
        "2c28e5b1266a12163fed8236d34830f69f8216a2"
      ],
      "author": {
        "name": "Andy Hung",
        "email": "hunga@google.com",
        "time": "Tue Oct 18 17:13:09 2016 -0700"
      },
      "committer": {
        "name": "Andy Hung",
        "email": "hunga@google.com",
        "time": "Wed Oct 19 12:41:37 2016 -0700"
      },
      "message": "DO NOT MERGE: Visualizer: Check capture size and latency parameters\n\nBug: 31781965\nChange-Id: I1c439a0d0f6aa0057b3c651499f28426e1e1f5e4\n"
    },
    {
      "commit": "2c28e5b1266a12163fed8236d34830f69f8216a2",
      "tree": "b5ac9922623cafe649946d742cf84c3ffdeb2667",
      "parents": [
        "eee86b009eb1a5e4fea5ca22df18408a76749c8d",
        "febbd52cd9f8394b113c3771e6a4403e86844e82"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Thu Oct 13 23:19:54 2016 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Thu Oct 13 23:19:55 2016 +0000"
      },
      "message": "Merge \"DO NOT MERGE Fix divide by zero\" into klp-dev"
    },
    {
      "commit": "eee86b009eb1a5e4fea5ca22df18408a76749c8d",
      "tree": "6d075d0e1337ba1ba5e307d05be32e5e88b3b0c7",
      "parents": [
        "8caef852351b04b69e0962277f97166142535867",
        "874f9e0b8eb0cbe508d15c8c03796c863851f21f"
      ],
      "author": {
        "name": "Ricardo Garcia",
        "email": "rago@google.com",
        "time": "Thu Oct 13 01:13:46 2016 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Thu Oct 13 01:13:46 2016 +0000"
      },
      "message": "Merge \"Fix potential NULL dereference in Visualizer effect\" into klp-dev"
    },
    {
      "commit": "8caef852351b04b69e0962277f97166142535867",
      "tree": "25e207fae5dd287495642c43ae0fb9fab30dbf96",
      "parents": [
        "afb20c310207aa4380f0578545ffce993ded23da",
        "de84a76b865d1061cfa9012f91b0aed4595f42cf"
      ],
      "author": {
        "name": "Pawin Vongmasa",
        "email": "pawin@google.com",
        "time": "Thu Oct 13 00:47:33 2016 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Thu Oct 13 00:47:33 2016 +0000"
      },
      "message": "Merge \"DO NOT MERGE - MPEG4Extractor: Check mLastTrack before dereferencing.\" into klp-dev"
    },
    {
      "commit": "874f9e0b8eb0cbe508d15c8c03796c863851f21f",
      "tree": "9d5c6c632acc0190d7be0fb5fe87a7d75f21d98d",
      "parents": [
        "afb20c310207aa4380f0578545ffce993ded23da"
      ],
      "author": {
        "name": "rago",
        "email": "rago@google.com",
        "time": "Fri Oct 07 18:16:09 2016 -0700"
      },
      "committer": {
        "name": "rago",
        "email": "rago@google.com",
        "time": "Wed Oct 12 12:19:06 2016 -0700"
      },
      "message": "Fix potential NULL dereference in Visualizer effect\n\nBug: 30229821\n\nTest: fixing CL. Existing unit tests still pass.\n\nChange-Id: I6e4abd759d5d2abc3b391e92e2e18f060cab7af0\n"
    },
    {
      "commit": "afb20c310207aa4380f0578545ffce993ded23da",
      "tree": "6f8df405941d3cc451d19a6bf0d271bb910e3cdb",
      "parents": [
        "610a9222d6426b386f2ab895ad5df5d393d6b210"
      ],
      "author": {
        "name": "Lajos Molnar",
        "email": "lajos@google.com",
        "time": "Tue Oct 11 08:41:51 2016 -0700"
      },
      "committer": {
        "name": "Lajos Molnar",
        "email": "lajos@google.com",
        "time": "Tue Oct 11 08:45:32 2016 -0700"
      },
      "message": "stagefright: don\u0027t fail MediaCodec.configure if clients use store-meta key\n\nEven though storing metadata is not supported in MediaCodec.configure and\nis only meant to be used by Stagefright recorder, don\u0027t fail configure.\n\nBug: 31986922\nChange-Id: Id9f083be6e857e7a0d8d4a74159be5b8894e28be\n"
    },
    {
      "commit": "febbd52cd9f8394b113c3771e6a4403e86844e82",
      "tree": "0c518af953ab82808b939dd72956a2cfa4053c11",
      "parents": [
        "610a9222d6426b386f2ab895ad5df5d393d6b210"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Thu Oct 06 15:31:52 2016 -0700"
      },
      "committer": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Thu Oct 06 15:40:05 2016 -0700"
      },
      "message": "DO NOT MERGE Fix divide by zero\n\nand be stricter about the layout of various boxes in mp4 files.\n\nBug: 31318219\nChange-Id: I50034d5b6b1967ca6e88aabeacf49f26ba3c0d32\n"
    },
    {
      "commit": "de84a76b865d1061cfa9012f91b0aed4595f42cf",
      "tree": "f30464735366552c1af9d8899498e2cea2fb26ef",
      "parents": [
        "610a9222d6426b386f2ab895ad5df5d393d6b210"
      ],
      "author": {
        "name": "Pawin Vongmasa",
        "email": "pawin@google.com",
        "time": "Fri Sep 30 00:45:52 2016 -0700"
      },
      "committer": {
        "name": "Pawin Vongmasa",
        "email": "pawin@google.com",
        "time": "Fri Sep 30 02:45:38 2016 -0700"
      },
      "message": "DO NOT MERGE - MPEG4Extractor: Check mLastTrack before dereferencing.\n\nBug: 31449945\nChange-Id: If2708b3006c22393e80a2557f93d8a71e4e7bf16\n"
    },
    {
      "commit": "610a9222d6426b386f2ab895ad5df5d393d6b210",
      "tree": "31feb054d14cdcb42b27aae04fd2085399d71755",
      "parents": [
        "9af51c59dce5cf61a0ded9936e7ba8cbe60c1b44",
        "03237ce0f9584c98ccda76c2474a4ae84c763f5b"
      ],
      "author": {
        "name": "Robert Shih",
        "email": "robertshih@google.com",
        "time": "Thu Sep 22 00:25:48 2016 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Thu Sep 22 00:25:48 2016 +0000"
      },
      "message": "Merge \"SampleIterator: clear members on seekTo error\" into klp-dev"
    },
    {
      "commit": "9af51c59dce5cf61a0ded9936e7ba8cbe60c1b44",
      "tree": "58cf8b1a291c06dc111b437da84461187f94a5b1",
      "parents": [
        "866c800c0624bb13eee44973cc8a2ecd0012de6e",
        "638c99bad693a8586a065d93b3d30017208e3067"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Wed Sep 21 20:35:16 2016 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Wed Sep 21 20:35:17 2016 +0000"
      },
      "message": "Merge \"Limit mp4 atom size to something reasonable\" into klp-dev"
    },
    {
      "commit": "638c99bad693a8586a065d93b3d30017208e3067",
      "tree": "f429b923212245e1d74d79db223240bc2b1bd249",
      "parents": [
        "b602286952fc68e614a27902a6c9fd0ac390f450"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Mon Sep 19 16:22:56 2016 -0700"
      },
      "committer": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Wed Sep 21 10:50:57 2016 -0700"
      },
      "message": "Limit mp4 atom size to something reasonable\n\nBug: 28615448\nChange-Id: I5916f6839b4a9bbee4388a106e7373bcd4154f5a\n"
    },
    {
      "commit": "03237ce0f9584c98ccda76c2474a4ae84c763f5b",
      "tree": "67d40d09141531aed5eeb9fac897ce23920e6eca",
      "parents": [
        "b602286952fc68e614a27902a6c9fd0ac390f450"
      ],
      "author": {
        "name": "Robert Shih",
        "email": "robertshih@google.com",
        "time": "Tue Sep 20 17:37:55 2016 -0700"
      },
      "committer": {
        "name": "Robert Shih",
        "email": "robertshih@google.com",
        "time": "Tue Sep 20 17:40:24 2016 -0700"
      },
      "message": "SampleIterator: clear members on seekTo error\n\nBug: 31091777\nChange-Id: Iddf99d0011961d0fd3d755e57db4365b6a6a1193\n"
    },
    {
      "commit": "866c800c0624bb13eee44973cc8a2ecd0012de6e",
      "tree": "6c280f4333d41e3355c84ecc1b9635d805993b30",
      "parents": [
        "b602286952fc68e614a27902a6c9fd0ac390f450"
      ],
      "author": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Tue Sep 20 13:36:40 2016 -0700"
      },
      "committer": {
        "name": "Marco Nelissen",
        "email": "marcone@google.com",
        "time": "Tue Sep 20 13:54:21 2016 -0700"
      },
      "message": "Check mprotect result\n\nmprotect can theoretically fail, which could then let one exploit\na vulnerable codec if one exists on the device.\n\nBug: 31350239\nChange-Id: I7b99c190619f0fb2eb93119596e6da0d2deb8ba5\n"
    },
    {
      "commit": "b602286952fc68e614a27902a6c9fd0ac390f450",
      "tree": "59eee4405cc78ee500036d771cdacc98f8a412ae",
      "parents": [
        "ea76573aa276f51950007217a97903c4fe64f685",
        "46dc714d523a41a4f886eecbe5b9947a4c900510"
      ],
      "author": {
        "name": "Ricardo Garcia",
        "email": "rago@google.com",
        "time": "Tue Sep 20 00:27:26 2016 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Tue Sep 20 00:27:27 2016 +0000"
      },
      "message": "Merge \"Fix potential overflow in Visualizer effect\" into klp-dev"
    },
    {
      "commit": "ea76573aa276f51950007217a97903c4fe64f685",
      "tree": "03bb464af8caa7523aec84028407ce17c6c9dd4f",
      "parents": [
        "c13904014bfeb56b8a3cc372190bb3a2dd8f1e0d"
      ],
      "author": {
        "name": "Chong Zhang",
        "email": "chz@google.com",
        "time": "Mon Sep 19 15:29:04 2016 -0700"
      },
      "committer": {
        "name": "Lajos Molnar",
        "email": "lajos@google.com",
        "time": "Mon Sep 19 23:25:15 2016 +0000"
      },
      "message": "IOMX: do not clear buffer if it\u0027s allocated by component\n\nThe component might depends on their buffers to be initialized\nin certain ways to work. Don\u0027t clear unless we\u0027re allocating it.\n\nbug: 31586647\nChange-Id: Ia0a125797e414998ef0cd8ce03672f5b1e0bbf7a\n"
    },
    {
      "commit": "c13904014bfeb56b8a3cc372190bb3a2dd8f1e0d",
      "tree": "2a2251150f8ad899b0f6608c141ababe65087574",
      "parents": [
        "425cc025a114692b3bad2262f2549d48b8cea6d7"
      ],
      "author": {
        "name": "Lajos Molnar",
        "email": "lajos@google.com",
        "time": "Wed Sep 14 10:01:37 2016 -0700"
      },
      "committer": {
        "name": "Lajos Molnar",
        "email": "lajos@google.com",
        "time": "Wed Sep 14 10:15:49 2016 -0700"
      },
      "message": "IOMX: allow configuration after going to loaded state\n\nThis was disallowed recently but we still use it as MediaCodcec.stop\nonly goes to loaded state, and does not free component.\n\nBug: 31450460\nChange-Id: I72e092e4e55c9f23b1baee3e950d76e84a5ef28d\n"
    },
    {
      "commit": "425cc025a114692b3bad2262f2549d48b8cea6d7",
      "tree": "e8d4e41a848865b88ebcd285ae82b6852cf9c976",
      "parents": [
        "282841278723166e74039329ca56e444ad472daf",
        "807e827d4c1196754faaf138cb93c57c5b137e69"
      ],
      "author": {
        "name": "Lajos Molnar",
        "email": "lajos@google.com",
        "time": "Fri Sep 09 16:52:06 2016 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Fri Sep 09 16:52:06 2016 +0000"
      },
      "message": "Merge \"DO NOT MERGE: IOMX: work against metadata buffer spoofing\" into klp-dev"
    },
    {
      "commit": "282841278723166e74039329ca56e444ad472daf",
      "tree": "aeba49f6b7078c00da85d76de6a0c4c8f260ccd9",
      "parents": [
        "4fb531e2627a0bb5109de2aa6096a972f40dad72"
      ],
      "author": {
        "name": "Wei Jia",
        "email": "wjia@google.com",
        "time": "Tue Aug 30 13:49:06 2016 -0700"
      },
      "committer": {
        "name": "Wei Jia",
        "email": "wjia@google.com",
        "time": "Tue Aug 30 22:02:44 2016 +0000"
      },
      "message": "MediaPlayerService: allow next player to be NULL\n\nBug: 31155917\nBug: 30204103\nChange-Id: I9a2a59ddb900fc942e7c19b31b53a110d790474c\n"
    },
    {
      "commit": "46dc714d523a41a4f886eecbe5b9947a4c900510",
      "tree": "dec8a194b1f84803d674c9a0ec6c6c6ad337d719",
      "parents": [
        "4fb531e2627a0bb5109de2aa6096a972f40dad72"
      ],
      "author": {
        "name": "rago",
        "email": "rago@google.com",
        "time": "Mon Aug 22 17:20:26 2016 -0700"
      },
      "committer": {
        "name": "Ricardo Garcia",
        "email": "rago@google.com",
        "time": "Wed Aug 24 01:28:32 2016 +0000"
      },
      "message": "Fix potential overflow in Visualizer effect\n\nBug: 30229821\nChange-Id: Idd3c1563dc9d3261e6e168e945005bf133ab2cdb\n(cherry picked from commit 099ab280775946e7c36c73fde47f2ee5a2579f53)\n"
    },
    {
      "commit": "4fb531e2627a0bb5109de2aa6096a972f40dad72",
      "tree": "9ea17398351ed14dd7f81c7e7581f1dede8710e1",
      "parents": [
        "9665548a421446d181b84cb97fc08163552d2d3b",
        "c159a5ae12af671d0fe0c134a27e676ed86c9874"
      ],
      "author": {
        "name": "Robert Shih",
        "email": "robertshih@google.com",
        "time": "Mon Aug 22 17:53:09 2016 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Mon Aug 22 17:53:09 2016 +0000"
      },
      "message": "Merge \"DO NOT MERGE MediaPlayerService: avoid invalid static cast\" into klp-dev"
    },
    {
      "commit": "9665548a421446d181b84cb97fc08163552d2d3b",
      "tree": "6ae3b1ecb8e4d4763bd1427aacfaa5dd3b3f68cd",
      "parents": [
        "ad929db743806aa55b2b8f795be61d21224b0f05",
        "e4a1d91501d47931dbae19c47815952378787ab6"
      ],
      "author": {
        "name": "Andy Hung",
        "email": "hunga@google.com",
        "time": "Fri Aug 19 18:49:14 2016 +0000"
      },
      "committer": {
        "name": "Android (Google) Code Review",
        "email": "android-gerrit@google.com",
        "time": "Fri Aug 19 18:49:14 2016 +0000"
      },
      "message": "Merge \"Add EFFECT_CMD_SET_PARAM parameter checking\" into klp-dev"
    },
    {
      "commit": "ad929db743806aa55b2b8f795be61d21224b0f05",
      "tree": "44215f66ee2e5dd36a75cb5a587cf45c85b80c58",
      "parents": [
        "940829f69b52d6038db66a9c727534636ecc456d"
      ],
      "author": {
        "name": "Pawin Vongmasa",
        "email": "pawin@google.com",
        "time": "Fri Aug 19 01:45:39 2016 -0700"
      },
      "committer": {
        "name": "Pawin Vongmasa",
        "email": "pawin@google.com",
        "time": "Fri Aug 19 02:13:58 2016 -0700"
      },
      "message": "DO NOT MERGE - Fix build breakage caused by commit\n940829f69b52d6038db66a9c727534636ecc456d.\n\nChange-Id: Ic55a9ab25ddb57f270c21d78ffcb556f3e11dd5d\n"
    },
    {
      "commit": "e4a1d91501d47931dbae19c47815952378787ab6",
      "tree": "427ee53e773dbdbb8b60f10ac9c8ae068bd30fdd",
      "parents": [
        "17a10c50e20d934c1ac5956fe9019d3013e3f8b3"
      ],
      "author": {
        "name": "Andy Hung",
        "email": "hunga@google.com",
        "time": "Wed Aug 17 14:11:13 2016 -0700"
      },
      "committer": {
        "name": "Andy Hung",
        "email": "hunga@google.com",
        "time": "Thu Aug 18 15:56:23 2016 -0700"
      },
      "message": "Add EFFECT_CMD_SET_PARAM parameter checking\n\nBug: 30204301\nChange-Id: Ib9c3ee1c2f23c96f8f7092dd9e146bc453d7a290\n"
    },
    {
      "commit": "807e827d4c1196754faaf138cb93c57c5b137e69",
      "tree": "af2fecd37fa95b1dfa1aaff16d6789d7f3131e33",
      "parents": [
        "17a10c50e20d934c1ac5956fe9019d3013e3f8b3"
      ],
      "author": {
        "name": "Lajos Molnar",
        "email": "lajos@google.com",
        "time": "Tue Aug 02 07:07:05 2016 -0700"
      },
      "committer": {
        "name": "Lajos Molnar",
        "email": "lajos@google.com",
        "time": "Thu Aug 18 14:16:15 2016 -0700"
      },
      "message": "DO NOT MERGE: IOMX: work against metadata buffer spoofing\n\n- Prohibit direct set/getParam/Settings for extensions meant for\n  OMXNodeInstance alone. This disallows enabling metadata mode\n  without the knowledge of OMXNodeInstance.\n- Do not share metadata mode buffers cross process.\n- Disallow setting up metadata mode/input surface\n  after first sendCommand (except to Idle for OMXCodec quirk).\n- Disallow store-meta for input cross process.\n- Disallow emptyBuffer for surface input (via IOMX).\n- Fix checking for input surface.\n\n[backported from L]\n\nBug: 29422020\nChange-Id: I801c77b80e703903f62e42d76fd2e76a34e4bc8e\n"
    },
    {
      "commit": "c159a5ae12af671d0fe0c134a27e676ed86c9874",
      "tree": "4860c98a1115c7cd7c2c30ecc80ec8bd1d6b65e1",
      "parents": [
        "17a10c50e20d934c1ac5956fe9019d3013e3f8b3"
      ],
      "author": {
        "name": "Robert Shih",
        "email": "robertshih@google.com",
        "time": "Tue Aug 16 16:50:54 2016 -0700"
      },
      "committer": {
        "name": "Robert Shih",
        "email": "robertshih@google.com",
        "time": "Wed Aug 17 15:17:34 2016 -0700"
      },
      "message": "DO NOT MERGE MediaPlayerService: avoid invalid static cast\n\nBug: 30204103\nChange-Id: Ie0dd3568a375f1e9fed8615ad3d85184bcc99028\n"
    },
    {
      "commit": "940829f69b52d6038db66a9c727534636ecc456d",
      "tree": "c7c79de964e565c3e8f4d0dad81aa1fd68a5544f",
      "parents": [
        "17a10c50e20d934c1ac5956fe9019d3013e3f8b3"
      ],
      "author": {
        "name": "Pawin Vongmasa",
        "email": "pawin@google.com",
        "time": "Mon Jul 18 20:12:02 2016 -0700"
      },
      "committer": {
        "name": "Pawin Vongmasa",
        "email": "pawin@google.com",
        "time": "Wed Aug 17 12:43:37 2016 +0000"
      },
      "message": "DO NOT MERGE - SoftMPEG4: Check the buffer size before writing the reference frame.\n\nAlso prevent overflow in SoftMPEG4 and division by zero in SoftMPEG4Encoder.\n\nBug: 30033990\nChange-Id: I7701f5fc54c2670587d122330e5dc851f64ed3c2\n(cherry picked from commit 695123195034402ca76169b195069c28c30342d3)\n"
    },
    {
      "commit": "17a10c50e20d934c1ac5956fe9019d3013e3f8b3",
      "tree": "8345b0aae2d50a442a6900b4e428242b8c556630",
      "parents": [
        "2b94fa82778cef72f810035840dd60db189be341"
      ],
      "author": {
        "name": "Wonsik Kim",
        "email": "wonsik@google.com",
        "time": "Thu Jul 21 14:43:38 2016 +0900"
      },
      "committer": {
        "name": "Pawin Vongmasa",
        "email": "pawin@google.com",
        "time": "Fri Jul 29 17:37:19 2016 -0700"
      },
      "message": "DO NOT MERGE - stagefright: fix integer overflow error\n\nBug: 30103394\nChange-Id: If449d3e30a0bf2ebea5317f41813bfed094f7408\n(cherry picked from commit 2c74a3cd5d1d66b9a35424b9c4443dafa6db5bef)\n"
    },
    {
      "commit": "2b94fa82778cef72f810035840dd60db189be341",
      "tree": "fafac7b159ce25f41568af4c3f061e8548799633",
      "parents": [
        "bf835e452528600052fa5607c7bc8ae85bd81d67"
      ],
      "author": {
        "name": "Wonsik Kim",
        "email": "wonsik@google.com",
        "time": "Thu Jul 07 12:57:02 2016 +0900"
      },
      "committer": {
        "name": "Wonsik Kim",
        "email": "wonsik@google.com",
        "time": "Tue Jul 19 04:04:43 2016 +0000"
      },
      "message": "omx: prevent input port enable/disable for software codecs\n\nBug: 29421804\nChange-Id: Iba1011e9af942a6dff7f659af769a51e3f5ba66f\n"
    },
    {
      "commit": "bf835e452528600052fa5607c7bc8ae85bd81d67",
      "tree": "d4a8e5149a4d07e7c674251591aa279bdd470ae6",
      "parents": [
        "3242dcf6e9f5e01fa2e4fd78feb5db7ec385469d"
      ],
      "author": {
        "name": "Robert Shih",
        "email": "robertshih@google.com",
        "time": "Thu Jul 14 15:32:08 2016 -0700"
      },
      "committer": {
        "name": "Robert Shih",
        "email": "robertshih@google.com",
        "time": "Thu Jul 14 22:33:41 2016 +0000"
      },
      "message": "DO NOT MERGE - Fix build\n\nChange-Id: Iff47bb735778fb275abeee573c636856b839feb5\n"
    }
  ],
  "next": "3242dcf6e9f5e01fa2e4fd78feb5db7ec385469d"
}
