)]}'
{
  "commit": "b1a156d86f55a8fa3f78ece5bee7748ec75e7b82",
  "tree": "d42e16fc3fb1ef6a1a0cabf1a48a823904ff3e3f",
  "parents": [
    "3f1500b384cd5aca13b517ebd4055727f35dc14f"
  ],
  "author": {
    "name": "John Levon",
    "email": "john.levon@nutanix.com",
    "time": "Mon Aug 19 11:44:36 2024 +0100"
  },
  "committer": {
    "name": "GitHub",
    "email": "noreply@github.com",
    "time": "Mon Aug 19 11:44:36 2024 +0100"
  },
  "message": "Add further sanity checking of hdr-\u003eerror_no (#805)\n\n\u003e\u003e\u003e     CID 467267:  Insecure data handling  (INTEGER_OVERFLOW)\r\n\u003e\u003e\u003e     The cast of \"hdr-\u003eerror_no\" to a signed type could result in a negative number.\r\n\r\nIndeed, if a client sends a very large -\u003eerror_no, this could end up\r\nwith a negative errno value. This doesn\u0027t seem like an issue, but\r\nnonetheless tighten up our validation.\r\n\r\nFor some reason Coverity only complained about tran_pipe.c, but the same\r\nproblem exists in tran_sock.c.\r\n\r\nSigned-off-by: John Levon \u003cjohn.levon@nutanix.com\u003e",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "e3d97b32f7b001e7c8fc9faa871412b5767ce5ca",
      "old_mode": 33188,
      "old_path": "lib/private.h",
      "new_id": "b89df8b28c5dcb01cfe084cf9475301a0b4d30c0",
      "new_mode": 33188,
      "new_path": "lib/private.h"
    },
    {
      "type": "modify",
      "old_id": "4c3dc9c16aab4ab59d7551fc41431e418587540c",
      "old_mode": 33188,
      "old_path": "lib/tran_pipe.c",
      "new_id": "48d8ea4ef944195ef39901f5bea0e6ca804b29ae",
      "new_mode": 33188,
      "new_path": "lib/tran_pipe.c"
    },
    {
      "type": "modify",
      "old_id": "024e5b0103fc86eead90761e2895784a24e39bdf",
      "old_mode": 33188,
      "old_path": "lib/tran_sock.c",
      "new_id": "5f144b29dd44cfce4bb448ccaacd2b014bcb8505",
      "new_mode": 33188,
      "new_path": "lib/tran_sock.c"
    }
  ]
}
