)]}'
{
  "commit": "ac5870a01010ad24a187ec4653d1d1504878dd4e",
  "tree": "b4546479ab2b9e7f089225f40c1e1f0ee4b3e674",
  "parents": [
    "d5a1f57b8f3336a06bad75aa8f61a0d82c54abb2"
  ],
  "author": {
    "name": "Jessica Ambrosio",
    "email": "jeambrosio@google.com",
    "time": "Wed Sep 30 21:22:55 2026 +0000"
  },
  "committer": {
    "name": "Jessica Ambrosio",
    "email": "jeambrosio@google.com",
    "time": "Tue Oct 06 15:08:18 2026 -0700"
  },
  "message": "libcrypta master: SRCREV bump 41f6a791e8..7ed2546ceb\n\nAlina Sbirlea (1):\n      Align command_buf in TctiSetLocality to ec_request_tpm_control.\n\nNicholas Noonarby (5):\n      Install crypto_types.h header\n      Reorganize libcrypta to separate google3 and native meson.builds\n      Prepare meson.build for migrating rules relevant to google3 meson.build\n      fix(havend): include \u003cfmt/ranges.h\u003e for fmt::join\n      Implement HavendEcCommandService in libcrypta.\n\ngBMC Team (81):\n      fix(crypta): initialize stack memory in InsertProtoBytes\n      Fix 12 ClangTidyLegacy findings: * inclusion of forwarding header \u0027util/task/status_macros.h\u0027; use \u0027third_party/gloop/util/status/status_macros.h\u0027 instead. For more info, see go/clang_tidy/checks/google3-legacy-forwarding-headers (6 times) * inclusion of forwarding header \u0027base/file_toc.h\u0027; use \u0027third_party/gloop/base/file_toc.h\u0027 instead. For more info, see go/clang_tidy/checks/google3-legacy-forwarding-headers (3 times) * inclusion of forwarding header \u0027util/random/acmrandom.h\u0027; use \u0027third_party/gloop/util/random/acmrandom.h\u0027 instead. For more info, see go/clang_tidy/checks/google3-legacy-forwarding-headers (2 times) * inclusion of forwarding header \u0027util/task/status.h\u0027; use \u0027third_party/gloop/util/status/status.h\u0027 instead. For more info, see go/clang_tidy/checks/google3-legacy-forwarding-headers\n      fix(crypta): Add early bounds checks before std::equal to prevent OOB reads\n      Remove MBM capping from TPM event log\n      fix(crypta): Fix authPolicy bypass and stack buffer overflow in SealData\n      Fix 1 ClangTidyLegacy finding: * inclusion of forwarding header \u0027util/task/status_macros.h\u0027; use \u0027third_party/gloop/util/status/status_macros.h\u0027 instead. For more info, see go/clang_tidy/checks/google3-legacy-forwarding-headers\n      Project import generated by Copybara.\n      Add bounds checking for PCR index in PopulatePcrBanks.\n      Add a check for minimum TPM response size in Haven TCTI.\n      Add meson.build and update copybara to export files to a google3 subdirectory.\n      Implements the build-firmware, build-payload, and inspect logic for the mauv tool.\n      Update response size in Haven TCTI Receive.\n      Fix DoS via unregulated vector::resize in TctiTransmit\n      Fix 3 ClangTidyLegacy findings: * inclusion of forwarding header \u0027util/task/status_macros.h\u0027; use \u0027third_party/gloop/util/status/status_macros.h\u0027 instead. For more info, see go/clang_tidy/checks/google3-legacy-forwarding-headers (2 times) * inclusion of forwarding header \u0027util/task/status_builder.h\u0027; use \u0027third_party/gloop/util/status/status_builder.h\u0027 instead. For more info, see go/clang_tidy/checks/google3-legacy-forwarding-headers\n      Fix uninitialized stack memory leak in DPE client.\n      Modernize Tpm2ClientBuilder API and add CreateAndAcquire helpers\n      Change representation for command code of `EC_PRV_CMD_HAVEN_TPM`\n      Fix 1 ClangTidyLegacy finding: * inclusion of forwarding header \u0027util/task/status_macros.h\u0027; use \u0027third_party/gloop/util/status/status_macros.h\u0027 instead. For more info, see go/clang_tidy/checks/google3-legacy-forwarding-headers\n      Fix 1 IncludeCleaner finding: * Used header \"security/crypta/tpm/client/tpm2_client_builder.h\" is not included directly\n      Fix TPM transient handle leak in `TpmHandle` move assignment\n      [Upkeep] Remove obsolete TODOs in crypta_portable_blob_key_fetcher.h\n      Removed the obsolete TODO.\n      Add ForwardTpmCommand to the TPM2 Client API\n      Install all exported headers in libcrypta.\n      Remove deprecated functions in Tpm2ClientBuilder\n      Align crypta_export copy.bara.sky transforms with securityd\n      Add ForwardTpmCommand function to ProdIdV3RotEnv\n      Fix 1 IncludeCleaner finding: * Used header \"third_party/absl/container/flat_hash_map.h\" is not included directly\n      mldsa_perso: Implement loading of ML-DSA public key into flash\n      Initialize (zeroize) TPM2B structures that are allocated on the stack to avoid leaking information from the stack when the content of the structures is copied to the caller.\n      Fix DpeStatus ToString formatting in C++ client\n      Reserve EC_PRV_CMD_UNIQUE_CHIP_ID host command.\n      Add raw TPM2 marshal/unmarshal helpers to tpm2_marshal.\n      Migrate legacy util/task/status.h C++ includes to gloop in Crypta.\n      Add SetLocality to ProdIdV3RotEnvInterface\n      Implement SetLocality in ProdIdV3RotEnv\n      [Upkeep] Migrate legacy util/task/status_macros.h C++ includes to gloop in Crypta\n      Refactor TPM attestation proto and implementation for compatibility\n      Add DpeClientArbiter to guard DpeClient usage in ProdIdV3RotEnv.\n      Update platforms/gbmc/crypta_export Copybara config to use standardized external header include paths\n      Cache DPE leaf public key and certificates in ProdIdV3RotEnv.\n      Automated g4 rollback of changelist 949674133.\n      Fix buffer size and alignment in GenVersionedCak.\n      Update Tpm2ClientBuilder to use GetEcCommandServicePlatformCandidates\n      Add overload GetOrCreateClient that accepts a list of cache keys\n      Validate coordinate sizes in PubKeyToTss and return absl::Status.\n      Update GetOrCreateClient that accepts single key to use overload\n      Migrate ABSL_ARRAYSIZE() to std::size() where possible\n      Migrate deprecated HexStringToBytes C++ function calls to Abseil.\n      Add PerformRtm to Tpm2Client\n      Rename absl::Cleanup variables in tpm2_client.cc to be more descriptive.\n      Fix platforms/gbmc/crypta_export Copybara config to rewrite tpm_types proto include\n      Add ResetDrtmPcrs to ProdIdV3RotEnvInterface\n      Evict unhealthy TPM clients from the registry.\n      Fix Copybara transformations in crypta_export for arbiter and haven proto headers\n      Remediate security findings in TCTI and Marshaling.\n      Remove Tpm2Client::PcrExtend in favor of PcrEvent\n      Reorganize and document methods in Tpm2Client.\n      Improve error messages and debugging context in TPM client and attestation flows.\n      [Crypta] Document CryptaClient method preconditions.\n      Remove [REDACTED] BIOS ABI incompatibility warning from DPE error messages.\n      Fix securityd build.\n      Enable automatic self-healing in ProdIdV3RotEnv when Tpm2Client becomes unhealthy.\n      Use more specific TSS2 TCTI return codes in haven_tcti.cc.\n      Reserve HostCommand enum.\n      Release TPM lock before acquiring DPE lock in GetProdIdV3Info and CapMbmPcr.\n      Decouple TPM and DPE lock acquisition in policy calculation and key/sealing flows.\n      Add RoT-mediated I2C device update session host commands and stubs.\n      Reserve host command for notify target boot.\n      Fix 1 IncludeCleaner findings:\n      Fix field comment for key rotation payload key and hash chunks\n      Fix 7 ClangTidyReadability findings: * function \u0027operator[]\u0027 has inline specifier but is implicitly inlined. For more info, see go/clang_tidy/checks/readability-redundant-inline-specifier (2 times) * function \u0027size\u0027 has inline specifier but is implicitly inlined. For more info, see go/clang_tidy/checks/readability-redundant-inline-specifier * function \u0027begin\u0027 has inline specifier but is implicitly inlined. For more info, see go/clang_tidy/checks/readability-redundant-inline-specifier * function \u0027empty\u0027 has inline specifier but is implicitly inlined. For more info, see go/clang_tidy/checks/readability-redundant-inline-specifier * function \u0027end\u0027 has inline specifier but is implicitly inlined. For more info, see go/clang_tidy/checks/readability-redundant-inline-specifier * function \u0027operator\u003d\u003d\u0027 has inline specifier but is implicitly inlined. For more info, see go/clang_tidy/checks/readability-redundant-inline-specifier\n      Refactor GetCounterDefiningIfNeeded to use a named struct and improve NV index initialization.\n      Migrate security::crypta SHA*_lite implementations to DigestView().\n      Rename NOTIFY_TARGET_BOOT host command to PET_TARGET_WATCHDOG\n      Propagate EC command errors through Haven TCTI and TPM client layers.\n      libcrypta: Add Nanopb proto generation and dependencies to exported meson.build\n      Fix 13 ViewTypeMigrations findings: * This is a change required to migrate proto string accessors to return absl::string_view instead of const std::string\u0026.  See ​go/proto-string-view-accessors-cpp-lsc for more details. (8 times) * This is a change required to migrate function parameters to absl::Span from const std::vector (3 times) * This is a change required to migrate function parameters to absl::string_view from const std::string\u0026 (2 times)\n      Migrate MerkleDamgaard override in security/crypta/tpm to string_view Update\n      platforms/gbmc/crypta_export: fix header includes and compile 14 Crypta sources into libcrypta.\n      Automated g4 rollback of changelist 989691908.\n\nFusion-Link: fusion2 N/A\nTested: N/A\nGoogle-Bug-Id: b/396407868\nChange-Id: I3e36ca181483f814581ee14a0dce2bdd3f8ee9e5\nSigned-off-by: Jessica Ambrosio \u003cjeambrosio@google.com\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "7190e22f1faf82f925c7d29c1cd98a3efe3adbec",
      "old_mode": 33188,
      "old_path": "recipes-google/libcrypta/libcrypta_git.bb",
      "new_id": "57ed3aa9db6c4bca6f8d941faecd9c0981207cba",
      "new_mode": 33188,
      "new_path": "recipes-google/libcrypta/libcrypta_git.bb"
    }
  ]
}
