)]}'
{
  "commit": "37ca5389b863e5ffba6fb7c22331bf57dbf7764a",
  "tree": "4869477a27fbd8ad91b0ce42f0b2e4b6817e5105",
  "parents": [
    "99e45eeac867d51ff3395dcf3d7aedf5ac2812c8"
  ],
  "author": {
    "name": "Stephen Smalley",
    "email": "sds@tycho.nsa.gov",
    "time": "Tue May 24 21:28:28 2005 +0100"
  },
  "committer": {
    "name": "David Woodhouse",
    "email": "dwmw2@shinybook.infradead.org",
    "time": "Tue May 24 21:28:28 2005 +0100"
  },
  "message": "AUDIT: Fix remaining cases of direct logging of untrusted strings by avc_audit\n\nPer Steve Grubb\u0027s observation that there are some remaining cases where\navc_audit() directly logs untrusted strings without escaping them, here\nis a patch that changes avc_audit() to use audit_log_untrustedstring()\nor audit_log_hex() as appropriate.  Note that d_name.name is nul-\nterminated by d_alloc(), and that sun_path is nul-terminated by\nunix_mkname(), so it is not necessary for the AVC to create nul-\nterminated copies or to alter audit_log_untrustedstring to take a length\nargument.  In the case of an abstract name, we use audit_log_hex() with\nan explicit length.\n\nSigned-off-by: Stephen Smalley \u003csds@tycho.nsa.gov\u003e\nSigned-off-by: David Woodhouse \u003cdwmw2@infradead.org\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "914d0d294fffc35298a5f5d239b13641a11543c3",
      "old_mode": 33188,
      "old_path": "security/selinux/avc.c",
      "new_id": "451502467a9b882ffda85c3626dd9a832522c880",
      "new_mode": 33188,
      "new_path": "security/selinux/avc.c"
    }
  ]
}
