)]}'
{
  "log": [
    {
      "commit": "27e23d99e74a5a89ba1612e04a1e64b681c001b0",
      "tree": "3ac085fd2e448047532f2d34416258891e9c1705",
      "parents": [
        "9460df156857bf97ec046c3493f8758bd98e13e3"
      ],
      "author": {
        "name": "crosvm-luci-ci-builder",
        "email": "crosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com",
        "time": "Mon Jul 20 12:00:32 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jul 20 15:34:54 2026"
      },
      "message": "vm_tools: Uprev baguette_image version\n\nGenerated by https://cr-buildbucket.appspot.com/build/8675758664997093201.\n\nChange-Id: I3c825d94c2e8c680eef1649a04e065823e1f9bb6\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8117500\nCommit-Queue: crosvm LUCI CI \u003ccrosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com\u003e\nBot-Commit: crosvm LUCI CI \u003ccrosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com\u003e\n"
    },
    {
      "commit": "9460df156857bf97ec046c3493f8758bd98e13e3",
      "tree": "8ba6b1321bb105622db63098a63e76be6385784b",
      "parents": [
        "e2d4add557a95f111d4a73e47981a0ccbd785e14"
      ],
      "author": {
        "name": "Adrian Ratiu",
        "email": "adrian.ratiu@collabora.com",
        "time": "Sat Jul 18 13:09:32 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jul 20 15:16:57 2026"
      },
      "message": "patchpanel: allow madvise in iptables seccomp policy\n\nFurther CQ testing uncovered that patchpanel also started calling\nthe madvise syscall with the new glibc 2.43, so we need to allow\nit for its minijailed iptables invocations.\n\nThis went uncaught by the mass madvise additions in commit\n1a6612ff959b (\"seccomp: allow MADV_GUARD_INSTALL/MADV_HUGEPAGE\nmadvise for glibc 2.43\") because patchpanel had no previous call.\n\nThe CQ failure audit log shows:\ncomm\u003d\"ip6tables-resto\" exe\u003d\"/sbin/xtables-legacy-multi\" syscall\u003d233\n(madvise) sig\u003d31 arch\u003dc00000b7 UID\u003d\"patchpaneld\".\n\nBUG\u003db:491765858\nTEST\u003daudit log analysis of failed CQ run; CQ\n\nChange-Id: Ib3927a36816bf91d35de567f9ab6b45207f193b4\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8117628\nTested-by: Adrian Ratiu \u003cadrian.ratiu@collabora.corp-partner.google.com\u003e\nReviewed-by: Allen Webb \u003callenwebb@google.com\u003e\nCommit-Queue: Adrian Ratiu \u003cadrian.ratiu@collabora.corp-partner.google.com\u003e\nReviewed-by: George Burgess \u003cgbiv@chromium.org\u003e\n"
    },
    {
      "commit": "e2d4add557a95f111d4a73e47981a0ccbd785e14",
      "tree": "e55d5912fb040828101149739cf6e90466f83b88",
      "parents": [
        "5451f618634985305cca9fb6dc31a95f28fc4ffe"
      ],
      "author": {
        "name": "Adrian Ratiu",
        "email": "adrian.ratiu@collabora.com",
        "time": "Sat Jul 18 13:22:38 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jul 20 15:16:33 2026"
      },
      "message": "sepolicy: rsyslogd: allow TCGETS/TCGETS2 ioctl on log files\n\nFurther CQ testing the glibc 2.41 -\u003e 2.43 uprev revealed that\nrsyslogd probes its output files with isatty(), which on ARC\nboards now trips the Android-side global file ioctl allowlist,\nproducing AVC denials that fail the SELinux audit tast test:\n\navc: denied { ioctl } comm\u003d\"rs:main Q:Reg\" path\u003d\"/var/log/arc.log\"\nioctlcmd\u003d0x542a scontext\u003du:r:cros_rsyslogd:s0\ntcontext\u003du:object_r:cros_arc_log:s0 tclass\u003dfile permissive\u003d0\n\nSo we grant TCGETS and TCGETS2 for rsyslogd on log file types.\ncros_var_log is included because rsyslogd also writes not-yet\nsplit log files of that type and hits the same denial there.\n\nOn regular files these ioctls harmlessly return ENOTTY, which\nis the answer isatty() needs.\n\nBUG\u003db:491765858\nTEST\u003daudit log analysis of failed CQ run; CQ\n\nChange-Id: Ib36a147266b3afe709f0de3cba2b9f8e8916f907\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8118472\nReviewed-by: Allen Webb \u003callenwebb@google.com\u003e\nCommit-Queue: Adrian Ratiu \u003cadrian.ratiu@collabora.corp-partner.google.com\u003e\nTested-by: Adrian Ratiu \u003cadrian.ratiu@collabora.corp-partner.google.com\u003e\nReviewed-by: George Burgess \u003cgbiv@chromium.org\u003e\n"
    },
    {
      "commit": "5451f618634985305cca9fb6dc31a95f28fc4ffe",
      "tree": "9e2c2f3f220a3b65007b1705be3eeca6bd76bd39",
      "parents": [
        "d4891fabfe7ee28ab15c590b0e87e78e77a06af0"
      ],
      "author": {
        "name": "Jeff Lin",
        "email": "jeffulin@google.com",
        "time": "Fri Jul 17 04:30:18 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jul 20 06:47:26 2026"
      },
      "message": "login: Migrate from base::ByteCount to base::ByteSize\n\nlibchrome uprev CL:8105279 removed base::ByteCount in favor\nof base::ByteSize. Migrate login_manager\u0027s ARC DLC platform\ninfo and hardware filter to use base::ByteSize and\nbase::GiBU.\n\nBUG\u003dNone\nTEST\u003dCQ\n\nChange-Id: I675837efe4ad0e98b4695d3f162a972c5d85ca5d\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8112719\nCommit-Queue: Jeff Lin \u003cjeffulin@google.com\u003e\nTested-by: Jeff Lin \u003cjeffulin@google.com\u003e\nReviewed-by: Hidehiko Abe \u003chidehiko@chromium.org\u003e\n"
    },
    {
      "commit": "d4891fabfe7ee28ab15c590b0e87e78e77a06af0",
      "tree": "7d588b604b204aed49b04d415ebf4dd473a820a0",
      "parents": [
        "4ddcdd7beb9109cb9b541bf17e87069f040a6fe8"
      ],
      "author": {
        "name": "crosvm-luci-ci-builder",
        "email": "crosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com",
        "time": "Sun Jul 19 12:00:33 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Sun Jul 19 15:13:21 2026"
      },
      "message": "vm_tools: Uprev baguette_image version\n\nGenerated by https://cr-buildbucket.appspot.com/build/8675849262420969873.\n\nChange-Id: I2e018457a866426459f902441200fca9691c7fc4\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8121921\nBot-Commit: crosvm LUCI CI \u003ccrosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com\u003e\nCommit-Queue: crosvm LUCI CI \u003ccrosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com\u003e\n"
    },
    {
      "commit": "4ddcdd7beb9109cb9b541bf17e87069f040a6fe8",
      "tree": "e40e26eed7f343dfe17d59dd835e90935f9df541",
      "parents": [
        "5ad540672d5f0486b6e6fe18fd4a5abeb2fc0270"
      ],
      "author": {
        "name": "crosvm-luci-ci-builder",
        "email": "crosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com",
        "time": "Sat Jul 18 12:00:49 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Sat Jul 18 14:57:44 2026"
      },
      "message": "vm_tools: Uprev baguette_image version\n\nGenerated by https://cr-buildbucket.appspot.com/build/8675939860426556945.\n\nChange-Id: I063e37fd0528be9665dfc0a71008fb226b829d74\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8113976\nCommit-Queue: crosvm LUCI CI \u003ccrosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com\u003e\nBot-Commit: crosvm LUCI CI \u003ccrosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com\u003e\n"
    },
    {
      "commit": "5ad540672d5f0486b6e6fe18fd4a5abeb2fc0270",
      "tree": "e2806d4e43d769585f3caf239cc354441d810195",
      "parents": [
        "ab1b996a3c71c66858237e6586c50d4fa22a14b0"
      ],
      "author": {
        "name": "Adrian Ratiu",
        "email": "adrian.ratiu@collabora.com",
        "time": "Fri Jul 17 17:37:50 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Sat Jul 18 04:55:41 2026"
      },
      "message": "vm_tools/chunnel: allow madvise in chunneld seccomp policies\n\nFurther CQ testing uncovered that chunneld also requires the seccomp\nrules added in commit 1a6612ff959b (\"seccomp: allow MADV_GUARD_INSTALL\n/MADV_HUGEPAGE madvise for glibc 2.43\").\n\nThis was missed because chunneld has no madvise rule at all and the\ncommit above only extended it on policies which already allowed it.\n\nThe asurada CQ audit log shows 44 seccomp kills: comm\u003d\"chunneld\"\nsyscall\u003d233 (madvise) sig\u003d31 arch\u003dc00000b7.\n\nBUG\u003db:491765858\nTEST\u003daudit log analysis of failed asurada arc.Optin.vm CQ run; CQ\n\nChange-Id: Ibea38e4618061766f5ad8abb48fc372c5a071880\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8118409\nReviewed-by: George Burgess \u003cgbiv@chromium.org\u003e\nReviewed-by: Allen Webb \u003callenwebb@google.com\u003e\nTested-by: Adrian Ratiu \u003cadrian.ratiu@collabora.corp-partner.google.com\u003e\nCommit-Queue: Adrian Ratiu \u003cadrian.ratiu@collabora.corp-partner.google.com\u003e\nAuto-Submit: Adrian Ratiu \u003cadrian.ratiu@collabora.corp-partner.google.com\u003e\n"
    },
    {
      "commit": "ab1b996a3c71c66858237e6586c50d4fa22a14b0",
      "tree": "869a255e140a5833c6f62700f0ab4221e874c7a2",
      "parents": [
        "d1d2869195cc3911b103c494bb43be5fd0f09cc6"
      ],
      "author": {
        "name": "Adrian Ratiu",
        "email": "adrian.ratiu@collabora.com",
        "time": "Fri Jul 17 18:53:06 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Fri Jul 17 21:48:45 2026"
      },
      "message": "sepolicy: allow TCGETS2 ioctl xperm for glibc 2.43\n\nThis is the selinux policy counterpart to the seccomp TCGETS2\nadditions in commit 9c0a4a3f03 (\"seccomp: allow TCGETS2 ioctl\nin policies for glibc 2.43\").\n\nBoth unpriv_tty_ioctls and unpriv_unix_sock_ioctls list TCGETS\nbut not TCGETS2, so confined domains that call isatty() \u0026 co\non a pty/socket now get the ioctl denied. The common case is\na minijailed daemon calling on its stdout/stderr at startup.\n\nUnlike the seccomp case this is not fatal (the denied ioctl\njust makes isatty() report \"not a tty\", which is correct), but\nit produces AVC spam and trips SELinux audit tests.\n\nAdd TCGETS2 next to TCGETS in both macros.\n\nBUG\u003db:491765858\nTEST\u003dm4-expanded unpriv_tty_ioctls/unpriv_unix_sock_ioctls contain\n     0x802c542a (TCGETS2); CQ.\n\nChange-Id: Ief346af93ab88569aa1e9e94dc01367e36b0ea1f\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8118411\nReviewed-by: George Burgess \u003cgbiv@chromium.org\u003e\nTested-by: Adrian Ratiu \u003cadrian.ratiu@collabora.corp-partner.google.com\u003e\nCommit-Queue: Adrian Ratiu \u003cadrian.ratiu@collabora.corp-partner.google.com\u003e\nReviewed-by: Allen Webb \u003callenwebb@google.com\u003e\n"
    },
    {
      "commit": "d1d2869195cc3911b103c494bb43be5fd0f09cc6",
      "tree": "81c6e1652f5c0d23e3cad9d4811a586c81d233e6",
      "parents": [
        "6485a8d4d66e4198615490a785d60afa29cfec0d"
      ],
      "author": {
        "name": "John Admanski",
        "email": "jadmanski@google.com",
        "time": "Thu Jul 16 19:19:02 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Fri Jul 17 19:44:44 2026"
      },
      "message": "cryptohome: Fix GenerateFreshRecoveryId response\n\nThe current RPC is buggy in that it actually returns a failure in the\ncase of success and vice versa. It was probably never noticed because\nrotating recovery IDs is a rare operation and generally happens in the\nbackground, and so if it works but reports a failure you probably\nwouldn\u0027t even notice it happened.\n\nBUG\u003db:520472937\nTEST\u003dadded unit test coverage of this case\n\nChange-Id: Ib41eb1107fa81cbb40758771df4c3fbf03e975d3\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8104699\nCommit-Queue: John Admanski \u003cjadmanski@chromium.org\u003e\nTested-by: John Admanski \u003cjadmanski@chromium.org\u003e\nReviewed-by: Zi Lin \u003clziest@google.com\u003e\n"
    },
    {
      "commit": "6485a8d4d66e4198615490a785d60afa29cfec0d",
      "tree": "84f2e6a8005dd6f8ba06ad805a0557f81f4b383c",
      "parents": [
        "944e8bb59e82eb0433adbabada5f153fa66ab511"
      ],
      "author": {
        "name": "Andreea Costinas",
        "email": "acostinas@google.com",
        "time": "Fri Jul 10 20:57:42 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Fri Jul 17 11:49:44 2026"
      },
      "message": "system-proxy: Safely handle worker shutdown in ConnectNamespaceTask\n\nThis CL fixes a potential crash in ConnectNamespaceTask by binding the\ntarget SandboxedWorker as a base::WeakPtr instead of a raw pointer.\n\nBUG\u003db:514095675\nTEST\u003dcros_workon_make --board\u003damd64-generic chromeos-base/system-proxy --test\n\nChange-Id: I0399c94de97c86758415dcfdff1f13b448770ba0\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8076758\nTested-by: Andreea Costinas \u003cacostinas@google.com\u003e\nReviewed-by: Hugo Benichi \u003chugobenichi@google.com\u003e\nAuto-Submit: Andreea Costinas \u003cacostinas@google.com\u003e\nCommit-Queue: Andreea Costinas \u003cacostinas@google.com\u003e\n"
    },
    {
      "commit": "944e8bb59e82eb0433adbabada5f153fa66ab511",
      "tree": "1b756eb088d937c9438c56371c99626a1e5ea293",
      "parents": [
        "5564db88462e538816189be62285534799891ce2"
      ],
      "author": {
        "name": "Ben Reich",
        "email": "benreich@google.com",
        "time": "Tue Jul 07 23:58:49 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Thu Jul 16 10:34:16 2026"
      },
      "message": "smbfs: Fix memory usage issue during teardown\n\nA memory lifecycle issue exists in the smbfs daemon during\nteardown and unmount. When smbfs shuts down, FuseSession::~FuseSession()\nexplicitly destroys the underlying libfuse2 session and channel\nobjects. Because SmbFilesystem (which owns the background worker\nthread) was naturally destroyed after the destructor body executed,\nany pending FUSE requests actively stalled on the worker thread\ncould attempt to access the freed FUSE structures upon completion.\n\nThis patch explicitly clears the SmbFilesystem within the\nFuseSession destructor body before fuse_session_destroy() and\nfuse_chan_destroy() are invoked. This enforces that the worker\nthread is joined and drained of pending tasks before the FUSE\nstructures are dismantled.\n\nBUG\u003db:523960862\nTEST\u003dcros_workon_make --board\u003dbetty --test smbfs\n\nChange-Id: Ifdc80bd9b089402b51cb24912c0274210d9e4170\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8062204\nCommit-Queue: Ben Reich \u003cbenreich@chromium.org\u003e\nTested-by: Ben Reich \u003cbenreich@chromium.org\u003e\nReviewed-by: Alexander Bolodurin \u003calexbn@google.com\u003e\nReviewed-by: Luciano Pacheco \u003clucmult@chromium.org\u003e\n"
    },
    {
      "commit": "5564db88462e538816189be62285534799891ce2",
      "tree": "925cd2d694588401f0fe31d6536fa052a1c7eb5a",
      "parents": [
        "963b07cd5a279439fb573392a463eb93f2ae1388"
      ],
      "author": {
        "name": "Hidehiko Abe",
        "email": "hidehiko@chromium.org",
        "time": "Mon Jul 13 04:40:17 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Thu Jul 16 10:09:26 2026"
      },
      "message": "diagnostics: Use weakptr for a delayed task in PrivacyScreenRoutine\n\nCurrent base::Unretained(this) has the risk of UAF.\nUse WeakPtr to handle the case automatically.\n\nBUG\u003db:524199919\nTEST\u003dTryjob\n\nChange-Id: I00be75c5f305975d5efc8b2cb0bdc1f4a1e00139\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8083700\nReviewed-by: Meng-Huan Yu \u003cmenghuan@chromium.org\u003e\nCommit-Queue: Hidehiko Abe \u003chidehiko@chromium.org\u003e\nTested-by: Hidehiko Abe \u003chidehiko@chromium.org\u003e\n"
    },
    {
      "commit": "963b07cd5a279439fb573392a463eb93f2ae1388",
      "tree": "74585df256af0979d0b4fdd599abce4b167d08f4",
      "parents": [
        "2226280f06ecb3e7b948fc9dbd88ebeb396526fe"
      ],
      "author": {
        "name": "Zi Lin",
        "email": "lziest@google.com",
        "time": "Tue Jul 14 23:02:36 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Wed Jul 15 22:51:37 2026"
      },
      "message": "cryptohome: Remove unused ACLs\n\nMigrateLegacyFingerprints is not used and will be deprecated.\n\nFIXED\u003db:516734893\nTEST\u003dCQ\n\nChange-Id: I541911b4a3727f947bbe89f4c7185bc2de4df374\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8093828\nCommit-Queue: Zi Lin \u003clziest@google.com\u003e\nReviewed-by: John Admanski \u003cjadmanski@chromium.org\u003e\nTested-by: Zi Lin \u003clziest@google.com\u003e\n"
    },
    {
      "commit": "2226280f06ecb3e7b948fc9dbd88ebeb396526fe",
      "tree": "612c01e7efa6f408a3cd94ccd4303e06ae8eb5bc",
      "parents": [
        "09a420bfe4bcfc65285848a6470e4d51da7dfa9f"
      ],
      "author": {
        "name": "Aashay Shringarpure",
        "email": "aashay@google.com",
        "time": "Mon Jul 13 17:36:45 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Wed Jul 15 22:11:46 2026"
      },
      "message": "init: Improve BPF filesystem isolation\n\nImprove isolation of BPF filesystem subdirectories by pre-creating them\nwith restrictive permissions and assigning ownership to the respective\ndaemon users. Also ensure the bpffs mount uses the sticky bit.\n\nBUG\u003db:516667610\nTEST\u003demerge-betty chromeos-init patchpanel secagentd\n\nChange-Id: I4274da64d6f1a083b85f9bb9f54993bcd288ac8a\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8088420\nTested-by: Aashay Shringarpure \u003caashay@google.com\u003e\nReviewed-by: Sarthak Kukreti \u003csarthakkukreti@google.com\u003e\nCommit-Queue: Aashay Shringarpure \u003caashay@google.com\u003e\nReviewed-by: Jie Jiang \u003cjiejiang@chromium.org\u003e\n"
    },
    {
      "commit": "09a420bfe4bcfc65285848a6470e4d51da7dfa9f",
      "tree": "4fe950a2ac604a575e364e0a134f7ee8aa83592b",
      "parents": [
        "76828ca96c5b414726fba86e6d8340bd0ab7b169"
      ],
      "author": {
        "name": "Hidehiko Abe",
        "email": "hidehiko@chromium.org",
        "time": "Mon Jul 13 05:16:10 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Wed Jul 15 20:25:26 2026"
      },
      "message": "secagentd: Take the file stats from file descriptor.\n\nTo avoid timing issue between file read and file path based\nstat check.\n\nBUG\u003db:524117057\nTEST\u003dTryjob\n\nChange-Id: I5ac4e40a705c6d5db5e48c882fbdf5e4dd384be9\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8083880\nReviewed-by: Aashay Shringarpure \u003caashay@google.com\u003e\nCommit-Queue: Hidehiko Abe \u003chidehiko@chromium.org\u003e\nTested-by: Hidehiko Abe \u003chidehiko@chromium.org\u003e\n"
    },
    {
      "commit": "76828ca96c5b414726fba86e6d8340bd0ab7b169",
      "tree": "b7c4cc1889c1de93efb4a2c30bb6a45b58a3984a",
      "parents": [
        "f89ce560807f2b060f6d64fa46b094d329d033c7"
      ],
      "author": {
        "name": "Alain Michaud",
        "email": "alainmichaud@google.com",
        "time": "Fri Jul 10 15:40:52 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Wed Jul 15 16:52:27 2026"
      },
      "message": "kerberos: Mark config invalid before validation to prevent race\n\nBUG\u003db:516667941\nTEST\u003dcros_run_unit_tests --board\u003dbetty --packages kerberos\n\nChange-Id: Id3ffc7057fddeb21e8d019aab9c51a92f6e834d7\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8099782\nTested-by: Alain Michaud \u003calainm@chromium.org\u003e\nCommit-Queue: Alain Michaud \u003calainm@chromium.org\u003e\nReviewed-by: Felipe Andrade \u003cfsandrade@chromium.org\u003e\n"
    },
    {
      "commit": "f89ce560807f2b060f6d64fa46b094d329d033c7",
      "tree": "40817fdb143775c5bd0b5fc6a26e101a3ced349d",
      "parents": [
        "4b02d6c274a2c538fa2b1ccf654fc30566332788"
      ],
      "author": {
        "name": "Alain Michaud",
        "email": "alainmichaud@google.com",
        "time": "Fri Jul 10 15:40:46 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Wed Jul 15 16:04:40 2026"
      },
      "message": "ml: Reject undersized shared memory regions in DocumentScanner\n\nBUG\u003db:524018084\nTEST\u003dcros_run_unit_tests --board\u003dbetty --packages ml\n\nChange-Id: I4eb5039e39b3c9dd229eec341291f01884737510\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8083989\nTested-by: Alain Michaud \u003calainm@chromium.org\u003e\nCommit-Queue: Alain Michaud \u003calainm@chromium.org\u003e\nReviewed-by: Chu-Hsuan Yang \u003cchuhsuan@chromium.org\u003e\nReviewed-by: Amanda Deacon \u003camandadeacon@chromium.org\u003e\n"
    },
    {
      "commit": "4b02d6c274a2c538fa2b1ccf654fc30566332788",
      "tree": "1cf80c4ac8e894c568c1a79a063b9c23baa5440d",
      "parents": [
        "035e899c23ea1fe632a659a35df6b1b0f656080b"
      ],
      "author": {
        "name": "Alain Michaud",
        "email": "alainmichaud@google.com",
        "time": "Fri Jul 10 15:48:44 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Wed Jul 15 15:22:15 2026"
      },
      "message": "camera: Reference-count buffer IDs to prevent UAF\n\nBUG\u003db:516650986\nTEST\u003dcros_run_unit_tests --board\u003dbetty --packages cros-camera\n\nChange-Id: I368f45098e25d465af809e880d0a4b943c690a3a\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8083988\nReviewed-by: Shik Chen \u003cshik@chromium.org\u003e\nCommit-Queue: Alain Michaud \u003calainm@chromium.org\u003e\nTested-by: Alain Michaud \u003calainm@chromium.org\u003e\n"
    },
    {
      "commit": "035e899c23ea1fe632a659a35df6b1b0f656080b",
      "tree": "1feaa7e2202bfe8f0d853fd54d201e03486f36ef",
      "parents": [
        "44adfb2861f6b995585e18b78984e1de603a529c"
      ],
      "author": {
        "name": "crosvm-luci-ci-builder",
        "email": "crosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com",
        "time": "Wed Jul 15 12:00:33 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Wed Jul 15 15:09:17 2026"
      },
      "message": "vm_tools: Uprev baguette_image version\n\nGenerated by https://cr-buildbucket.appspot.com/build/8676211650894545649.\n\nChange-Id: I2de1052dab8f12c9880e83bffb7260b8cdae078d\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8097772\nCommit-Queue: crosvm LUCI CI \u003ccrosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com\u003e\nBot-Commit: crosvm LUCI CI \u003ccrosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com\u003e\n"
    },
    {
      "commit": "44adfb2861f6b995585e18b78984e1de603a529c",
      "tree": "be92252ae3dcc0c25e3459b3fd153c91fa737fe4",
      "parents": [
        "cc5f98083fce50d520e87544a4c68184cabd6360"
      ],
      "author": {
        "name": "Aleksander Morgado",
        "email": "aleksandermj@google.com",
        "time": "Mon Jul 13 11:42:27 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Wed Jul 15 12:59:58 2026"
      },
      "message": "hermes: fix qmi_{decode|encode}_message() usages in ModemQrtr\n\nFix two places where return values from qmi_decode_message() and\nqmi_encode_message() were incorrectly checked:\n  1. Use `\u003c 0` check instead of `!` to check the error condition.\n  2. Use `ssize_t` instead of `size_t` for the return value to avoid\n  unsigned conversion bug.\n\nBUG\u003db:516683853\nTEST\u003dCQ\n\nChange-Id: I1efaf131cf1daea1b17ea5435a5ddcba184ae754\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8086313\nCommit-Queue: Aleksander Morgado \u003caleksandermj@google.com\u003e\nReviewed-by: Eric Caruso \u003cejcaruso@chromium.org\u003e\nReviewed-by: Daniel Winkler \u003cdanielwinkler@google.com\u003e\nTested-by: Aleksander Morgado \u003caleksandermj@google.com\u003e\n"
    },
    {
      "commit": "cc5f98083fce50d520e87544a4c68184cabd6360",
      "tree": "dd55babd182946500bea4f9183df8fd4ba80a3ce",
      "parents": [
        "04a784ffd9250d4752653f4a9c20953cdaf03b3c"
      ],
      "author": {
        "name": "Andrea Orru",
        "email": "andreaorru@chromium.org",
        "time": "Thu Jul 09 21:36:09 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Wed Jul 15 12:18:50 2026"
      },
      "message": "camera: Make reused base::Threads restartable\n\nbase::Thread used to be restartable by default, but after\nhttps://crrev.com/c/7696887, threads must opt in via\nbase::Thread::Restartable. Restarting a non-restartable thread now\ncauses a DCHECK that crashes cros_camera_service.\n\nThis only affects DCHECK-enabled builds: DCHECKs are compiled out when\nUSE\u003d-cros-debug (release/ToT images) but enabled on cros-debug builds\nsuch as the CQ. This was surfaced by ARCVM CTS failures\n(CtsMediaRecorderTestCases, CtsMediaStressTestCases) on a debug build.\n\nFix by constructing these two threads with base::Thread::Restartable{}.\nThe fix is a no-op on release builds.\n\nBUG\u003db:359926651\nTEST\u003dCtsMediaRecorderTestCases, CtsMediaStressTestCases on ARCVM\n\nChange-Id: Ie12d8729fc529ba0e205850288c94ea6fa72c338\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8071279\nReviewed-by: Hidehiko Abe \u003chidehiko@chromium.org\u003e\nCommit-Queue: Hidehiko Abe \u003chidehiko@chromium.org\u003e\nAuto-Submit: Andrea Orru \u003candreaorru@chromium.org\u003e\nReviewed-by: Shik Chen \u003cshik@chromium.org\u003e\nTested-by: Andrea Orru \u003candreaorru@chromium.org\u003e\n"
    },
    {
      "commit": "04a784ffd9250d4752653f4a9c20953cdaf03b3c",
      "tree": "6bc65fc1699ca23eb858857e10c2b1c700be35bb",
      "parents": [
        "2aee4d1bf3d522ddd518d7b1383deb737b245316"
      ],
      "author": {
        "name": "Jae Hoon Kim",
        "email": "kimjae@google.com",
        "time": "Tue Jul 14 20:33:46 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Tue Jul 14 23:43:53 2026"
      },
      "message": "p2p: Improve robustness of HTTP server process management.\n\n- Ignore SIGPIPE in p2p-http-server to prevent unexpected crashes when clients disconnect abruptly.\n- Use MSG_NOSIGNAL flag when sending data to avoid triggering SIGPIPE.\n- Monitor child process (p2p-http-server) lifecycle in p2p-server and exit if the child terminates unexpectedly, allowing the system manager to respawn the service.\n\nBug: b/516633966\nTEST\u003dNone\n\nChange-Id: Ieafb052e90411ede2bb20c497f4e9960b8e26f1d\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8093013\nTested-by: Jae Hoon Kim \u003ckimjae@chromium.org\u003e\nReviewed-by: Jeff Xu \u003cjeffxu@google.com\u003e\nAuto-Submit: Jae Hoon Kim \u003ckimjae@chromium.org\u003e\nCommit-Queue: Jae Hoon Kim \u003ckimjae@chromium.org\u003e\n"
    },
    {
      "commit": "2aee4d1bf3d522ddd518d7b1383deb737b245316",
      "tree": "a8d5d79108b54c5811e2fff8cd4bbcf291633a48",
      "parents": [
        "b333b3b8e48cd1353369b6569fe097b6459df89e"
      ],
      "author": {
        "name": "Alain Michaud",
        "email": "alainmichaud@google.com",
        "time": "Mon Jul 13 17:41:27 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Tue Jul 14 20:42:46 2026"
      },
      "message": "shill: Gate test keys in TetheringConfig\n\nBUG\u003db:524226543\nTEST\u003dcros_run_unit_tests --board\u003dbetty --packages shill\n\nChange-Id: Ic2369a05518b6a58e9c380dde2ffdd35d6d681b1\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8085526\nTested-by: Alain Michaud \u003calainm@chromium.org\u003e\nAuto-Submit: Alain Michaud \u003calainm@chromium.org\u003e\nReviewed-by: Jintao Lin \u003cjintaolin@chromium.org\u003e\nReviewed-by: Hugo Benichi \u003chugobenichi@google.com\u003e\nCommit-Queue: Alain Michaud \u003calainm@chromium.org\u003e\n"
    },
    {
      "commit": "b333b3b8e48cd1353369b6569fe097b6459df89e",
      "tree": "c26017cec4ec20ada8fc795c03a4c397704042cf",
      "parents": [
        "dbbe77209a74fb9abcffc21383018eb04d84eaa3"
      ],
      "author": {
        "name": "Shanthanu Bhardwaj",
        "email": "xanth@google.com",
        "time": "Wed Jul 08 14:27:08 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Tue Jul 14 19:33:08 2026"
      },
      "message": "missive: close files after reading all records before advancing to next\n\nThis was causing the issue described in b/507586305 that leads to\nexhausting FDs since the files are not closed until the SingleFile\nobject is destroyed, which means that all FDs are held on to until the\nwhole upload is ACKed by server, which can be huge if there is a large\nbacklog of files.\n\nBUG\u003db:507586305\nTEST\u003dCQ\nChange-Id: I7bf6dffcf72c5faf434bb7e63c51f324328ef9c7\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8059745\nCommit-Queue: Shanthanu Bhardwaj \u003cxanth@google.com\u003e\nTested-by: Nancy Xiao \u003cnancylanxiao@google.com\u003e\nReviewed-by: Nancy Xiao \u003cnancylanxiao@google.com\u003e\n"
    },
    {
      "commit": "dbbe77209a74fb9abcffc21383018eb04d84eaa3",
      "tree": "0418e60b2cfc291f7f2c1cc38cfb5478f0d917b8",
      "parents": [
        "49250a253a7762a1fa7d50a246b8e96b689f1b29"
      ],
      "author": {
        "name": "Alain Michaud",
        "email": "alainmichaud@google.com",
        "time": "Fri Jul 10 15:40:27 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Tue Jul 14 16:37:37 2026"
      },
      "message": "chaps: Make key-usage flags read-only post-creation\n\nBUG\u003db:516631154\nTEST\u003dcros_run_unit_tests --board\u003dbetty --packages chaps\n\nChange-Id: I80d0e7dc756e74f4c7d998378405173d7c4ca413\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8087402\nTested-by: Alain Michaud \u003calainm@chromium.org\u003e\nReviewed-by: Eric Caruso \u003cejcaruso@chromium.org\u003e\nCommit-Queue: Alain Michaud \u003calainm@chromium.org\u003e\n"
    },
    {
      "commit": "49250a253a7762a1fa7d50a246b8e96b689f1b29",
      "tree": "79262c99db9f7dd338d73c7ea3317413a0964475",
      "parents": [
        "06744d5120c8dd3ba28ff237a0cbed07849a207b"
      ],
      "author": {
        "name": "crosvm-luci-ci-builder",
        "email": "crosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com",
        "time": "Tue Jul 14 12:00:30 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Tue Jul 14 15:45:13 2026"
      },
      "message": "vm_tools: Uprev baguette_image version\n\nGenerated by https://cr-buildbucket.appspot.com/build/8676302251311664881.\n\nChange-Id: I36afffe22bd35e7c01d19fe7b718b10a62364af9\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8091928\nBot-Commit: crosvm LUCI CI \u003ccrosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com\u003e\nCommit-Queue: crosvm LUCI CI \u003ccrosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com\u003e\n"
    },
    {
      "commit": "06744d5120c8dd3ba28ff237a0cbed07849a207b",
      "tree": "eac4680e79747bf9165d78bacb873fd5d55b099a",
      "parents": [
        "7b8aae1e53b13bac947ef5629d95db68b6e0c034"
      ],
      "author": {
        "name": "Alain Michaud",
        "email": "alainmichaud@google.com",
        "time": "Mon Jul 13 17:56:00 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Tue Jul 14 14:06:53 2026"
      },
      "message": "concierge: Prevent BOREALIS VM spoofing via caller-supplied images\n\nBUG\u003db:524016668\nTEST\u003dcros_run_unit_tests --board\u003dbetty --packages vm_host_tools\n\nChange-Id: I35087d2d07fb0079438c3c90d60aad3bbe1030aa\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8085525\nReviewed-by: maciek swiech \u003cdrmasquatch@google.com\u003e\nTested-by: Alain Michaud \u003calainm@chromium.org\u003e\nCommit-Queue: Alain Michaud \u003calainm@chromium.org\u003e\n"
    },
    {
      "commit": "7b8aae1e53b13bac947ef5629d95db68b6e0c034",
      "tree": "f6d09930202868d287c9f094d68a67dd6148c2e6",
      "parents": [
        "2542957dea4322a31312c8196ee35803a691a6dc"
      ],
      "author": {
        "name": "Jeff Lin",
        "email": "jeffulin@google.com",
        "time": "Tue Jul 14 09:47:46 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Tue Jul 14 13:59:51 2026"
      },
      "message": "common-mk: Add `-Wl,-rpath-link\u003d.` to test config\n\nAdd -Wl,-rpath-link\u003d. alongside -Wl,-rpath-link\u003dlib/ to ensure ld.lld\nsearches the root build output directory (.) for shared library\ndependencies during link-time validation before falling back to\n/usr/lib64.\n\nThis prevents transient stale sysroot library mismatches when running\nunit tests on postsubmit builders (e.g., host-packages-snapshot).\n\nBUG\u003db:534185124\nTEST\u003dCQ\n\nChange-Id: Ie20e0e4ae814d4f46f557ee37fcac519d7451cab\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8084222\nReviewed-by: Mike Frysinger \u003cvapier@chromium.org\u003e\nCommit-Queue: chromeos-auto-runner@chromeos-bot.iam.gserviceaccount.com \u003cchromeos-auto-runner@chromeos-bot.iam.gserviceaccount.com\u003e\nCommit-Queue: Jeff Lin \u003cjeffulin@google.com\u003e\nTested-by: Jeff Lin \u003cjeffulin@google.com\u003e\n"
    },
    {
      "commit": "2542957dea4322a31312c8196ee35803a691a6dc",
      "tree": "9f36117309c5f55520ba89b70e984c166b3a711d",
      "parents": [
        "3ffbb743194882a2bc286c309c3846e3f883a4a7"
      ],
      "author": {
        "name": "Alain Michaud",
        "email": "alainmichaud@google.com",
        "time": "Fri Jul 10 15:31:15 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Tue Jul 14 13:16:40 2026"
      },
      "message": "shill: Prevent plaintext credential extraction via Task.getsec\n\nBUG\u003db:514097531\nTEST\u003dcros_run_unit_tests --board\u003dbetty --packages shill\n\nChange-Id: I859044669ff108131d5052a551a057a6938400a8\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8086554\nTested-by: Alain Michaud \u003calainm@chromium.org\u003e\nReviewed-by: Hugo Benichi \u003chugobenichi@google.com\u003e\nCommit-Queue: Alain Michaud \u003calainm@chromium.org\u003e\n"
    },
    {
      "commit": "3ffbb743194882a2bc286c309c3846e3f883a4a7",
      "tree": "22930598246c1e365084bd5d228ee6bc63bfa806",
      "parents": [
        "1a6612ff959b21d162fcfddaffb826301f1e0c3e"
      ],
      "author": {
        "name": "Aida Zolic",
        "email": "aidazolic@chromium.org",
        "time": "Fri Jul 10 09:24:25 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Tue Jul 14 10:39:53 2026"
      },
      "message": "oobe_config: allow unlink and unlinkat in save\n\nAllow unlink and unlinkat syscalls in oobe_config_save seccomp policies.\nThese syscalls are needed for file deletion and cleaning up temporary\nstate during config saving, which now also attempts to start metrics\ntracking in the device migration case, preventing minijail policy\nviolations.\n\nBUG\u003db:533299601\nTEST\u003dmanual\n\nChange-Id: Ib77ffd367feb51ea6576d938052b914f24331b14\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8074538\nReviewed-by: Igor \u003cigorcov@chromium.org\u003e\nTested-by: Aida Zolic \u003caidazolic@chromium.org\u003e\nCommit-Queue: Aida Zolic \u003caidazolic@chromium.org\u003e\n"
    },
    {
      "commit": "1a6612ff959b21d162fcfddaffb826301f1e0c3e",
      "tree": "c190d467a16f3c7a98177d754a08d5528fa63e15",
      "parents": [
        "779605a27edfc5de243de1c91f86692185985ee8"
      ],
      "author": {
        "name": "Adrian Ratiu",
        "email": "adrian.ratiu@collabora.com",
        "time": "Tue Jun 23 13:38:28 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Tue Jul 14 10:16:55 2026"
      },
      "message": "seccomp: allow MADV_GUARD_INSTALL/MADV_HUGEPAGE madvise for glibc 2.43\n\nThe glibc 2.41-\u003e2.43 uprev makes libc issue madvise() in paths that\npreviously did not, tripping minijail seccomp policies:\n\n- madvise(MADV_GUARD_INSTALL): glibc commit a6fbe36b7f (\"nptl: Add\n  support for setup guard pages with MADV_GUARD_INSTALL\", first released\n  in glibc 2.42) makes pthread_create install thread stack guard pages\n  via madvise(MADV_GUARD_INSTALL) instead of mprotect(PROT_NONE). The\n  mprotect fallback only runs if madvise returns an error, so under\n  seccomp the SIGSYS kills the process before it can fall back.\n- madvise(MADV_HUGEPAGE): glibc commit 321e1fc73f (\"malloc: Enable 2MB\n  THP by default on Aarch64\", first released in glibc 2.43) makes malloc\n  call madvise(MADV_HUGEPAGE) on arm64.\n\nBroaden the existing arg-filtered madvise rules to allow the new flags\n(MADV_HUGEPAGE only on arm64, where THP is enabled by default).\n\nrmad had no madvise rule and was killed at runtime in CQ, so allow madvise\nin its policy.\n\nBUG\u003db:491765858\nTEST\u003dVerified seccomp fixes against a glibc 2.43 build \u0026 boot; CQ.\n\nChange-Id: I657f672e7bcd2b47bc4b65081ad95bb5dd0ae1cd\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/7986208\nReviewed-by: George Burgess \u003cgbiv@chromium.org\u003e\nCommit-Queue: Adrian Ratiu \u003cadrian.ratiu@collabora.corp-partner.google.com\u003e\nReviewed-by: Allen Webb \u003callenwebb@google.com\u003e\nTested-by: Adrian Ratiu \u003cadrian.ratiu@collabora.corp-partner.google.com\u003e\n"
    },
    {
      "commit": "779605a27edfc5de243de1c91f86692185985ee8",
      "tree": "535d9be575072535d7b2feedcc47c15f90e5c5fd",
      "parents": [
        "86028d105bc1bfd55edcd6d68ade930519451c48"
      ],
      "author": {
        "name": "Georg Neis",
        "email": "neis@chromium.org",
        "time": "Tue Jul 07 00:35:10 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Tue Jul 14 06:07:48 2026"
      },
      "message": "Add missing includes of base file_path.h\n\nBUG\u003db:465651491\nTEST\u003dcq\n\nChange-Id: I009b4dde1d77d6ce0591837f0cdfe207f4d964fd\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8049980\nAuto-Submit: Georg Neis \u003cneis@chromium.org\u003e\nTested-by: Georg Neis \u003cneis@chromium.org\u003e\nReviewed-by: Aashay Shringarpure \u003caashay@google.com\u003e\nReviewed-by: Hidehiko Abe \u003chidehiko@chromium.org\u003e\nCommit-Queue: Georg Neis \u003cneis@chromium.org\u003e\n"
    },
    {
      "commit": "86028d105bc1bfd55edcd6d68ade930519451c48",
      "tree": "689de11b1a3bd10f058cc800e6fbfd8d826538cd",
      "parents": [
        "9ff65bc06b1500a988ba5f532bce45ee1dfeea40"
      ],
      "author": {
        "name": "Alain Michaud",
        "email": "alainmichaud@google.com",
        "time": "Fri Jul 10 16:02:38 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jul 13 23:13:29 2026"
      },
      "message": "device_management: Use sticky bit for /run/lockbox\n\nBUG\u003db:516678221\nTEST\u003dcros_run_unit_tests --board\u003dbetty --packages device_management\n\nChange-Id: I2b1d86b416dbe9b53dabbb066ae76feef7471a91\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8087215\nTested-by: Alain Michaud \u003calainm@chromium.org\u003e\nReviewed-by: Allen Webb \u003callenwebb@google.com\u003e\nCommit-Queue: Alain Michaud \u003calainm@chromium.org\u003e\n"
    },
    {
      "commit": "9ff65bc06b1500a988ba5f532bce45ee1dfeea40",
      "tree": "2ff3524d7e6249822494a9c2ef883af920f5a496",
      "parents": [
        "de556dab3cc78196652709925c6b9a37911d6d85"
      ],
      "author": {
        "name": "Firas Sammoura",
        "email": "fsammoura@google.com",
        "time": "Thu Jul 09 20:16:03 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jul 13 20:15:13 2026"
      },
      "message": "libec: Require max_packet_size to exceed flash write header\n\nEnforce a lower bound on max_packet_size in FlashWriteCommand::Create to\nensure it is strictly greater than sizeof(flash_write::Header). This\nprevents an integer underflow when calculating max_data_chunk in Run(),\nwhich could otherwise cause logic errors or heap buffer overflows.\n\nAdd boundary validation test cases to verify the enforcement.\n\nBUG\u003db:524303346\nTEST\u003dFEATURES\u003d\"test\" emerge-rex libec\n\nChange-Id: I0035ae4a63cc63c10bcbf98b44788615367bf6ca\nDisallow-Recycled-Builds: test-failures\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8071444\nCommit-Queue: Firas Sammoura \u003cfsammoura@google.com\u003e\nReviewed-by: Tom Hughes \u003ctomhughes@chromium.org\u003e\nTested-by: Firas Sammoura \u003cfsammoura@google.com\u003e\n"
    },
    {
      "commit": "de556dab3cc78196652709925c6b9a37911d6d85",
      "tree": "73c9fbe61da5efb73ea9c0b722c00c285a5fe5d2",
      "parents": [
        "6ea15bece09d0b565eae5498c27db46c1f6a539f"
      ],
      "author": {
        "name": "Firas Sammoura",
        "email": "fsammoura@google.com",
        "time": "Thu Jul 09 20:02:59 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jul 13 20:15:09 2026"
      },
      "message": "libec: Require max_write_size to exceed fingerprint template header\n\nEnforce a lower bound on max_write_size in FpTemplateCommand::Create to\nensure it is strictly greater than sizeof(fp_template::Header). This\nprevents an integer underflow when calculating max_data_chunk in Run(),\nwhich could otherwise lead to a heap buffer overflow.\n\nAdd boundary validation test cases to verify the enforcement.\n\nBUG\u003db:524303346\nTEST\u003dFEATURES\u003d\"test\" emerge-rex libec\n\nChange-Id: Id62400e66d753ed5042da6b8305de568ac57fa05\nDisallow-Recycled-Builds: test-failures\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8071277\nReviewed-by: Tom Hughes \u003ctomhughes@chromium.org\u003e\nTested-by: Firas Sammoura \u003cfsammoura@google.com\u003e\nCommit-Queue: Firas Sammoura \u003cfsammoura@google.com\u003e\n"
    },
    {
      "commit": "6ea15bece09d0b565eae5498c27db46c1f6a539f",
      "tree": "665a3461e5caa9ccc79953b3a03c5f949a533583",
      "parents": [
        "a014d10cca47cb8a30f33f81b0c238b298df0a1e"
      ],
      "author": {
        "name": "Firas Sammoura",
        "email": "fsammoura@google.com",
        "time": "Thu Jul 09 17:25:12 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jul 13 20:13:50 2026"
      },
      "message": "libec: Clamp num_capture_types loop bounds in FpInfoCommand\n\nThe num_capture_types field in the EC_CMD_FP_INFO response is untrusted\ndata supplied by the FPMCU. Lacking validation, a malicious or buggy\nco-processor could provide an out-of-bounds count value, driving a heap\nout-of-bounds read vulnerability in the sensor_image() parser.\n\nMitigate this by clamping the target loop iteration count against the\nprotocol maximum constant (FP_MAX_CAPTURE_TYPES) in both version 2 and\nversion 3 command variants. Add corresponding mock regression test\ncoverages.\n\nBUG\u003db:524020410\nTEST\u003dFEATURES\u003d\"test\" emerge-rex libec\n\nChange-Id: I74ccb7431311e13826d187b92e013ebe4dbd67ac\nDisallow-Recycled-Builds: test-failures\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8071020\nCommit-Queue: Firas Sammoura \u003cfsammoura@google.com\u003e\nReviewed-by: Tom Hughes \u003ctomhughes@chromium.org\u003e\nTested-by: Firas Sammoura \u003cfsammoura@google.com\u003e\n"
    },
    {
      "commit": "a014d10cca47cb8a30f33f81b0c238b298df0a1e",
      "tree": "d0254259db6fc6cfac4169776b531eb11f948953",
      "parents": [
        "315303203d783c628cbe81b54fba7b9976777931"
      ],
      "author": {
        "name": "George Burgess IV",
        "email": "gbiv@google.com",
        "time": "Thu Jul 09 16:48:40 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jul 13 19:30:05 2026"
      },
      "message": "arc-setup: upgrade quick-xml\n\nquick-xml 0.30 is impacted by RUSTSEC-2026-0194 and RUSTSEC-2026-0195.\n\n0.41 has a few API changes; seems `cargo fmt` also wanted a diff here.\n\nBUG\u003db:530513076\nTEST\u003dNone\n\nCq-Depend: chromium:8071019\nChange-Id: I346713985758ffd815685f0d3b0069095c34b9ed\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8069763\nReviewed-by: Long Cheng \u003clgcheng@google.com\u003e\nReviewed-by: Jordan Abrahams-Whitehead \u003cajordanr@google.com\u003e\nCommit-Queue: George Burgess \u003cgbiv@chromium.org\u003e\nTested-by: George Burgess \u003cgbiv@chromium.org\u003e\n"
    },
    {
      "commit": "315303203d783c628cbe81b54fba7b9976777931",
      "tree": "b200079eb463db5bbec6d989e868ec89b93e1de6",
      "parents": [
        "3e90116d0be4ab0fd3d4261477ce9f3519eb851c"
      ],
      "author": {
        "name": "Firas Sammoura",
        "email": "fsammoura@google.com",
        "time": "Tue Jul 07 19:08:09 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jul 13 18:25:55 2026"
      },
      "message": "biod: Move default SetContext success behavior to test fixture\n\nMigrate the default successful `SetContext` expectation from individual\ntests into the `CrosFpBiometricsManagerTest` fixture setup using\n`ON_CALL`. This reduces repetitive mock configuration across standard\nsuccess paths while keeping explicit `EXPECT_CALL` assertions intact\nfor failure contexts and strict cardinality checks.\n\nBUG\u003db:516683084\nTEST\u003dFEATURES\u003d\"test\" emerge-brya biod\n\nChange-Id: I6e1a47a9ec29a7df47cae3cde62c4eef00cfda52\nDisallow-Recycled-Builds: test-failures\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8057966\nReviewed-by: Tom Hughes \u003ctomhughes@chromium.org\u003e\nCommit-Queue: Firas Sammoura \u003cfsammoura@google.com\u003e\nTested-by: Firas Sammoura \u003cfsammoura@google.com\u003e\n"
    },
    {
      "commit": "3e90116d0be4ab0fd3d4261477ce9f3519eb851c",
      "tree": "16f2ee83ef0f10fa39dde693cef19e8828fdeb2e",
      "parents": [
        "9c0a4a3f0337e597fea92cefd27457a515ad95bf"
      ],
      "author": {
        "name": "Firas Sammoura",
        "email": "fsammoura@google.com",
        "time": "Tue Jun 02 22:42:26 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jul 13 18:25:51 2026"
      },
      "message": "biod: Handle SetContext failure in ReadRecordsForSingleUser\n\nAdd a check for the return value of cros_dev_-\u003eSetContext() in\nReadRecordsForSingleUser to ensure the function bails out if the\nhardware context fails to set. Update associated unit tests to reflect\nthis change and add a new test case for the failure path.\n\nBUG\u003db:516683084\nTEST\u003dFEATURES\u003d\"test\" emerge-brya biod\n\nChange-Id: I366d8660817882ae0b76714f8eb7c1811b838d0c\nDisallow-Recycled-Builds: test-failures\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8057965\nReviewed-by: Tom Hughes \u003ctomhughes@chromium.org\u003e\nCommit-Queue: Firas Sammoura \u003cfsammoura@google.com\u003e\nTested-by: Firas Sammoura \u003cfsammoura@google.com\u003e\n"
    },
    {
      "commit": "9c0a4a3f0337e597fea92cefd27457a515ad95bf",
      "tree": "0d371f1d692367596d3f688e58677a0c5bc0ab21",
      "parents": [
        "d5453465565bc4b6a940a75c23c5dbb5fc2f8b13"
      ],
      "author": {
        "name": "Adrian Ratiu",
        "email": "adrian.ratiu@collabora.com",
        "time": "Tue Jun 23 12:57:49 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jul 13 17:54:03 2026"
      },
      "message": "seccomp: allow TCGETS2 ioctl in policies for glibc 2.43\n\nGlibc 2.43 reworked termios in commit 5cf101a85a (\"linux: implement\narbitrary and split speeds in termios\") to issue ioctl(TCGETS2)\ninstead of ioctl(TCGETS).\n\nThe stdio buffer setup calls isatty() on stdout/stderr at process\nstartup, which in turn calls ioctl(TCGETS), so seccomp policies that\nonly allowed TCGETS now get a SIGSYS on TCGETS2 after the glibc uprev.\n\nAdd TCGETS2 alongside the existing TCGETS in the affected ioctl rules.\nThe addition is backward compatible and can land before the glibc uprev.\n\nBUG\u003db:491765858\nTEST\u003dverified seccomp fixes against a glibc 2.43 build \u0026 boot\n\nChange-Id: I77a7ed1b2919b565414d249db8b7486e9e8288d8\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/7985651\nAuto-Submit: Adrian Ratiu \u003cadrian.ratiu@collabora.corp-partner.google.com\u003e\nTested-by: Adrian Ratiu \u003cadrian.ratiu@collabora.corp-partner.google.com\u003e\nReviewed-by: Allen Webb \u003callenwebb@google.com\u003e\nReviewed-by: George Burgess \u003cgbiv@chromium.org\u003e\nCommit-Queue: Adrian Ratiu \u003cadrian.ratiu@collabora.corp-partner.google.com\u003e\nSLSA-Policy-Verified: SLSA Policy Verification Service \u003cdevtools-gerritcodereview-exitgate@google.com\u003e\n"
    },
    {
      "commit": "d5453465565bc4b6a940a75c23c5dbb5fc2f8b13",
      "tree": "ac545eec6e8f8d0295221120406c953a45ffb03c",
      "parents": [
        "e0662e5f4dd84b2c88b9c5f2904885b7f5f6337e"
      ],
      "author": {
        "name": "Aida Zolic",
        "email": "aidazolic@chromium.org",
        "time": "Wed Jul 08 16:41:34 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jul 13 14:42:32 2026"
      },
      "message": "login: Correct clobber cmd for preserve_device_cfg\n\nWhen a remote powerwash command with preserve_device_config set to true\nis sent, we generate some marker files that trigger the save. To\nactually preserve that data, we need to pass the `rollback` argument\nto clobber-state.\n\nThe CL changes the SessionManagerInterface::InitiateDeviceWipe() to take\nan enum instead of a string. The enum value is mapped to the correct\nclobber parameters and the (sanitized) reason to be persisted in clobber.log.\n\nBUG\u003db:532559669\nTEST\u003dFEATURES\u003dtest emerge-${BOARD} chromeos-base/chromeos-login\n\nChange-Id: Ibdf04dabdc8f022b70c716525eb22c19eeb57fa7\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8066024\nReviewed-by: Hidehiko Abe \u003chidehiko@chromium.org\u003e\nTested-by: Aida Zolic \u003caidazolic@chromium.org\u003e\nCommit-Queue: Aida Zolic \u003caidazolic@chromium.org\u003e\n"
    },
    {
      "commit": "e0662e5f4dd84b2c88b9c5f2904885b7f5f6337e",
      "tree": "eab2bbaf103df2130c01e5c1bba5784217b217fc",
      "parents": [
        "d1db4334248961afab4c462cabff9058ce040944"
      ],
      "author": {
        "name": "Hidehiko Abe",
        "email": "hidehiko@chromium.org",
        "time": "Mon Jul 13 07:20:34 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jul 13 13:08:03 2026"
      },
      "message": "login: Check PID for HandleLockScreenDismissed\n\nFor better restriction of callers.\n\nBUG\u003db:524105760\nTEST\u003dTryjob\n\nChange-Id: Ibbd23d9f8145f8c048a1962a3b99acf30426e3ca\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8084301\nReviewed-by: Jun Ishiguro \u003cjunis@google.com\u003e\nTested-by: Hidehiko Abe \u003chidehiko@chromium.org\u003e\nCommit-Queue: Hidehiko Abe \u003chidehiko@chromium.org\u003e\n"
    },
    {
      "commit": "d1db4334248961afab4c462cabff9058ce040944",
      "tree": "44debc51f96b44bdfa38910d1eba390e0b5aa247",
      "parents": [
        "ee6074820516087a091047f1b4e8d6d05ec7fe18"
      ],
      "author": {
        "name": "Hidehiko Abe",
        "email": "hidehiko@chromium.org",
        "time": "Fri Jul 10 10:24:52 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jul 13 06:46:16 2026"
      },
      "message": "dns-proxy: Fix UAF in shill dbus client.\n\nIn case of VPN, default device is taken and its network config\nis used. However, its actual use, because of the C++ scope,\nthe returned default device object, including the network config,\nis destroyed.\nThis CL makes a small refactor to avoid the UAF.\n\nBUG\u003db:524046212\nTEST\u003dTryjob\n\nChange-Id: I86639ca18d2f95684266da4be3fff52f0fd191b0\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8061334\nReviewed-by: Hugo Benichi \u003chugobenichi@google.com\u003e\nCommit-Queue: Hidehiko Abe \u003chidehiko@chromium.org\u003e\nTested-by: Hidehiko Abe \u003chidehiko@chromium.org\u003e\n"
    },
    {
      "commit": "ee6074820516087a091047f1b4e8d6d05ec7fe18",
      "tree": "ef433079d738d42ea595b38ca8440795aa050e3a",
      "parents": [
        "a4f3dc2ad7da2059219e9a68bab6fbb5a0e8f903"
      ],
      "author": {
        "name": "Athira Palliprath",
        "email": "palliprath@google.com",
        "time": "Thu Jul 02 12:00:21 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jul 13 06:13:45 2026"
      },
      "message": "debugd: Fix argument array bounds checking\n\nEnsure that arguments requiring trailing values are parsed safely when\npositioned at the end of the input vector.\n\nBUG\u003db:528873748\nTEST\u003dcros_workon_make --board\u003ddedede --test chromeos-base/debugd\n\nChange-Id: Ie02cfef080614186c4e9d48af87fb50a865c7c5c\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8039380\nReviewed-by: Mike Frysinger \u003cvapier@chromium.org\u003e\nCommit-Queue: Athira Palliprath (xWF) \u003cpalliprath@google.com\u003e\nTested-by: Athira Palliprath (xWF) \u003cpalliprath@google.com\u003e\nReviewed-by: Ryo Hashimoto \u003chashimoto@chromium.org\u003e\n"
    },
    {
      "commit": "a4f3dc2ad7da2059219e9a68bab6fbb5a0e8f903",
      "tree": "9a0ae5c0c93df0e147b72c9d051f29f11fbcd9b4",
      "parents": [
        "2b1ca967091bf704b87ff05717ce2402f20d1657"
      ],
      "author": {
        "name": "Georg Neis",
        "email": "neis@chromium.org",
        "time": "Fri Jul 10 06:17:04 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jul 13 05:35:34 2026"
      },
      "message": "Migrate CreateAndOpenFdForTemporaryFileInDir\n\nThe function is receiving an additional parameter in\nhttps://crrev.com/c/7792479.\n\nMutual Cq-Depend with libchrome uprev.\n\nBUG\u003dNone\nTEST\u003dCq\n\nCq-Depend: chromium:8068355\nChange-Id: Ib74ef815518bee5de22f27dc0abfe8fd73541261\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8068358\nTested-by: Georg Neis \u003cneis@chromium.org\u003e\nReviewed-by: Po-Heng Chen \u003cpohengchen@google.com\u003e\nReviewed-by: Jae Hoon Kim \u003ckimjae@chromium.org\u003e\nCommit-Queue: Georg Neis \u003cneis@chromium.org\u003e\nReviewed-by: Sergey Poromov \u003cporomov@chromium.org\u003e\nReviewed-by: Nathan Muggli \u003cnmuggli@google.com\u003e\nReviewed-by: Byron Lee \u003cbyronlee@chromium.org\u003e\n"
    },
    {
      "commit": "2b1ca967091bf704b87ff05717ce2402f20d1657",
      "tree": "0b2f9e792946135c1cef1f4f85bcade072f9d413",
      "parents": [
        "f673dd8cede5404ca4e919e491ea441d9f2526c2"
      ],
      "author": {
        "name": "Hidehiko Abe",
        "email": "hidehiko@chromium.org",
        "time": "Fri Jul 10 10:43:12 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jul 13 04:39:33 2026"
      },
      "message": "patchpanel: Write config file atomically.\n\nTo avoid accidental failure in the middle of writing.\nSee the linked bug for the details.\n\nBUG\u003db:524069728\nTEST\u003dTryjob\n\nChange-Id: Ib02df8690a43c928843d3eb0fcd17f337a70d615\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8062411\nReviewed-by: Hugo Benichi \u003chugobenichi@google.com\u003e\nCommit-Queue: Hidehiko Abe \u003chidehiko@chromium.org\u003e\nTested-by: Hidehiko Abe \u003chidehiko@chromium.org\u003e\n"
    },
    {
      "commit": "f673dd8cede5404ca4e919e491ea441d9f2526c2",
      "tree": "a52126bd86d36252c92d14d7dd578072221b143a",
      "parents": [
        "448b4e307d429bf2cbf46d9ba81b76b4000038ac"
      ],
      "author": {
        "name": "Hidehiko Abe",
        "email": "hidehiko@chromium.org",
        "time": "Fri Jul 10 11:02:25 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jul 13 02:35:40 2026"
      },
      "message": "shill: Write VPN config file atomically.\n\nTo avoid potential timing issue in the middle of writing.\nSee the linked bug for the details.\n\nBUG\u003db:524205527\nTEST\u003dTryjob\n\nChange-Id: I4f8deebb40c14b4afcc3e831fc6a82634d84b3df\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8066958\nReviewed-by: Hugo Benichi \u003chugobenichi@google.com\u003e\nCommit-Queue: Hidehiko Abe \u003chidehiko@chromium.org\u003e\nTested-by: Hidehiko Abe \u003chidehiko@chromium.org\u003e\n"
    },
    {
      "commit": "448b4e307d429bf2cbf46d9ba81b76b4000038ac",
      "tree": "2b7572d0434da96ce5f237d3e8b32179001928a1",
      "parents": [
        "d2e4c30f7ec8bf10b4f277aaacfdae4c243fca19"
      ],
      "author": {
        "name": "Hidehiko Abe",
        "email": "hidehiko@chromium.org",
        "time": "Tue Jul 07 10:43:56 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Sun Jul 12 21:18:29 2026"
      },
      "message": "update_engine: Block ResetStatus from chronos.\n\nIt looks like there\u0027s no need to allow the method for chronos user.\n\nBUG\u003db:523986513\nTEST\u003dTryjob\n\nChange-Id: Ib03dc76347b1abbb9d1340bb7c6cdca8ed9d44f6\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8053964\nReviewed-by: Jae Hoon Kim \u003ckimjae@chromium.org\u003e\nCommit-Queue: Hidehiko Abe \u003chidehiko@chromium.org\u003e\nTested-by: Hidehiko Abe \u003chidehiko@chromium.org\u003e\n"
    },
    {
      "commit": "d2e4c30f7ec8bf10b4f277aaacfdae4c243fca19",
      "tree": "a57582b7314c30d767a4913919eebe324591a622",
      "parents": [
        "a453c45403a550e68ea96169df0774af59d8e2e9"
      ],
      "author": {
        "name": "crosvm-luci-ci-builder",
        "email": "crosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com",
        "time": "Sun Jul 12 12:00:40 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Sun Jul 12 15:18:21 2026"
      },
      "message": "vm_tools: Uprev baguette_image version\n\nGenerated by https://cr-buildbucket.appspot.com/build/8676483443162529297.\n\nChange-Id: I925357dec744f65ab5e4aef38977f48b53dfca36\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8080411\nCommit-Queue: crosvm LUCI CI \u003ccrosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com\u003e\nBot-Commit: crosvm LUCI CI \u003ccrosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com\u003e\n"
    },
    {
      "commit": "a453c45403a550e68ea96169df0774af59d8e2e9",
      "tree": "6d5c4b5da6ed3cc55089265d4970887763734802",
      "parents": [
        "02162d28838cbb29e952f36f6bfbfaad632729f1"
      ],
      "author": {
        "name": "Firas Sammoura",
        "email": "fsammoura@google.com",
        "time": "Sat Jul 11 12:33:07 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Sat Jul 11 17:19:00 2026"
      },
      "message": "Revert \"init: chromeos-boot-alert: display boot messages in a minijail\"\n\nThis reverts commit 7bebefd1c12978178fafa430012178c2865ef815.\n\nReason for revert: (b/532664660) This CL caused firmware.FpUpdater tast test to fail\n\nFailure Link: https://cros-test-analytics.appspot.com/p/chromeos/search?filters\u003dsuite_scheduler_config%7Efingerprint-nightly+build_version%3AR152-16748.0.0+test%3Atast.firmware.FpUpdater+is_known_failure%3Afalse+-status%3APASS\u0026exclude_cts\u003dfalse\u0026exclude_non_critical\u003dfalse\u0026exclude_non_production\u003dfalse\u0026exclude_non_release\u003dfalse\u0026exclude_not_run\u003dfalse\u0026exclude_tauto_sub_test\u003dfalse\u0026statusAggregation\u003dRAW\u0026union\u003dAND\u0026viewMode\u003dList\u0026accountId\u003d1\u0026days\u003d7\n\nOriginal change\u0027s description:\n\u003e init: chromeos-boot-alert: display boot messages in a minijail\n\u003e\n\u003e Since this command processes graphics, put it in a minijail.\n\u003e\n\u003e BUG\u003db:516656892\n\u003e TEST\u003dCQ passes\n\u003e\n\u003e Change-Id: I6b75cb60195c7b772a1f29c5d8b27d664fa52421\n\u003e Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/7989833\n\u003e Reviewed-by: Sarthak Kukreti \u003csarthakkukreti@google.com\u003e\n\u003e Tested-by: Mike Frysinger \u003cvapier@chromium.org\u003e\n\u003e Commit-Queue: Mike Frysinger \u003cvapier@chromium.org\u003e\n\nBUG\u003db:516656892\n\nChange-Id: Ib0dcc1cf47741c54831c84a092cf9812182360b6\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8079141\nTested-by: Firas Sammoura \u003cfsammoura@google.com\u003e\nBot-Commit: rubber-stamper@appspot.gserviceaccount.com \u003crubber-stamper@appspot.gserviceaccount.com\u003e\nReviewed-by: Sarthak Kukreti \u003csarthakkukreti@google.com\u003e\nCommit-Queue: Firas Sammoura \u003cfsammoura@google.com\u003e\nReviewed-by: Jae Hoon Kim \u003ckimjae@chromium.org\u003e\n"
    },
    {
      "commit": "02162d28838cbb29e952f36f6bfbfaad632729f1",
      "tree": "fbaac6d153c735e26284177fb98bddbe20d1dbe9",
      "parents": [
        "3a05b0ffbca1e5601cfd4db5d3581e3adb6d95c9"
      ],
      "author": {
        "name": "Hugo Benichi",
        "email": "hugobenichi@google.com",
        "time": "Fri Jul 03 07:44:44 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Sat Jul 11 02:22:14 2026"
      },
      "message": "shill: tethering: always clear state in OnNetworkDestroyed\n\nBUG\u003db:514101159\nTEST\u003dFEATURES\u003dtest emerge-$BOARD chromeos-base/shill\n\nChange-Id: Ib65c7561a79549cf0fc89918828296f555e35b1f\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8036867\nAuto-Submit: Hugo Benichi \u003chugobenichi@google.com\u003e\nReviewed-by: Jintao Lin \u003cjintaolin@chromium.org\u003e\nReviewed-by: Aleksander Morgado \u003caleksandermj@google.com\u003e\nTested-by: Hugo Benichi \u003chugobenichi@google.com\u003e\nCommit-Queue: Hugo Benichi \u003chugobenichi@google.com\u003e\n"
    },
    {
      "commit": "3a05b0ffbca1e5601cfd4db5d3581e3adb6d95c9",
      "tree": "a62869bfceececd24fd64dc15f1928bea91fe7a4",
      "parents": [
        "1a890c07b6488cad9fcaae1c40966e67d7b8b2c6"
      ],
      "author": {
        "name": "Daniel Winkler",
        "email": "danielwinkler@google.com",
        "time": "Thu Jul 09 17:29:08 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Fri Jul 10 16:25:46 2026"
      },
      "message": "modemfwd: Only allow dbus requests to ForceFlash in debug mode\n\nWe call the ForceFlash dbus endpoint in many manual and automated\ntesting flows to verify firmware update capabilities. However, on\nproduction images in users\u0027 hands, there is no reason for an entity\noutside of modemfwd to request firmware update. This change ensures the\nForceFlash dbus endpoint will return failure if the device is not in\ncros_debug mode.\n\nBUG\u003db:524100564\nTEST\u003dEnsured force flash on test images still works\n\nCq-Depend: chromium:8071855\nChange-Id: Ic64f099eecc86c563e4ee9444da4b1c53f95242b\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8071445\nTested-by: Daniel Winkler \u003cdanielwinkler@google.com\u003e\nCommit-Queue: Daniel Winkler \u003cdanielwinkler@google.com\u003e\nReviewed-by: Andrew Lassalle \u003candrewlassalle@chromium.org\u003e\n"
    },
    {
      "commit": "1a890c07b6488cad9fcaae1c40966e67d7b8b2c6",
      "tree": "6724a5e5c3a902f5ee626fbe8da3a4598409bf2a",
      "parents": [
        "1455710f3d91d4390396402d29c427908fcd829d"
      ],
      "author": {
        "name": "Hugo Benichi",
        "email": "hugobenichi@google.com",
        "time": "Fri Jul 03 06:42:05 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Fri Jul 10 15:14:27 2026"
      },
      "message": "shill: wifi: clear delegates when removing P2P dev\n\nBUG\u003db:514100069\nTEST\u003dFEATURES\u003dtest emerge-$BOARD chromeos-base/shill\n\nChange-Id: I8d9797c05a8ad94bc4c51cda51cc384254eebb4c\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8038663\nTested-by: Hugo Benichi \u003chugobenichi@google.com\u003e\nCommit-Queue: Hugo Benichi \u003chugobenichi@google.com\u003e\nAuto-Submit: Hugo Benichi \u003chugobenichi@google.com\u003e\nReviewed-by: Jintao Lin \u003cjintaolin@chromium.org\u003e\n"
    },
    {
      "commit": "1455710f3d91d4390396402d29c427908fcd829d",
      "tree": "b11edc403e0618455b870ea3123234849f52ec8c",
      "parents": [
        "b194e6dfd02971e7fc88eff898ca0a8710ea98e2"
      ],
      "author": {
        "name": "Georg Neis",
        "email": "neis@chromium.org",
        "time": "Thu Jul 09 08:25:44 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Fri Jul 10 02:15:45 2026"
      },
      "message": "printscanmgr: Allow \u0027shutdown\u0027 syscall\n\nI\u0027m seeing seccomp violations of printscanmgr due to \u0027shutdown\u0027 syscalls\nin builder logs (no test failures though). This is most likely due to\nhttps://crrev.com/c/8011349 which was recently included in libchrome.\n\nBUG\u003dNone\nTEST\u003dcq\n\nChange-Id: If0ba63f9756e75b65b8beef9e51acd1c42c78693\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8062999\nReviewed-by: Nathan Muggli \u003cnmuggli@google.com\u003e\nCommit-Queue: Georg Neis \u003cneis@chromium.org\u003e\nTested-by: Georg Neis \u003cneis@chromium.org\u003e\n"
    },
    {
      "commit": "b194e6dfd02971e7fc88eff898ca0a8710ea98e2",
      "tree": "e47edefd5855d94d25e8cf6a7624be48efa2be68",
      "parents": [
        "9f07109f420995638229f2794f698922bf178888"
      ],
      "author": {
        "name": "Daniel Winkler",
        "email": "danielwinkler@google.com",
        "time": "Mon Jul 06 22:50:45 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Fri Jul 10 00:09:24 2026"
      },
      "message": "patchmaker: Validate paths in manifest on load\n\nEnsure all file paths specified in the patch manifest (original_file_name,\nbase_file_name, patch_file_name) are valid relative paths before\nproceeding with encode/decode operations. Manifests containing paths\nthat are absolute or attempt to reference parent directories (escaping\nthe managed directory) will be rejected.\n\nBUG\u003db:516687069\nTEST\u003d\u0027cros_workon_make --board\u003dskywalker --test patchmaker\u0027 and CQ\n\nChange-Id: I39d77e1f5c458fe81482e0d593e7409cbddf0482\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8049260\nCommit-Queue: Daniel Winkler \u003cdanielwinkler@google.com\u003e\nTested-by: Daniel Winkler \u003cdanielwinkler@google.com\u003e\nReviewed-by: Rukun Mao \u003crmao@google.com\u003e\n"
    },
    {
      "commit": "9f07109f420995638229f2794f698922bf178888",
      "tree": "4f244e0cb6a1debf6baaede313edb1a2863f96a4",
      "parents": [
        "20e6f930bfc274b7fb776004db201ea01b7f11d3"
      ],
      "author": {
        "name": "Aashay Shringarpure",
        "email": "aashay@google.com",
        "time": "Wed Jun 10 19:30:54 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Thu Jul 09 21:49:50 2026"
      },
      "message": "secagentd: Check resolve_path_to_string return value in all callsites\n\nCheck the return value of resolve_path_to_string in all callsites in file_bpf.c.\nIf it fails, handle the error appropriately (delete map entry, discard ringbuf, or return early).\n\nThis fixes a bug where we would pass NULL to bpf_probe_read_str/bpf_core_read_str on\nfailure, and also reduces verifier complexity by avoiding verifying\nunneeded paths on failure.\n\nBUG\u003db:527154796\nTEST\u003dcros_workon_make --board\u003dbetty --test chromeos-base/secagentd\nTEST\u003dtast run localhost:9222 secagentd.ProcessEvents secagentd.FileEventsRootfs\nTEST\u003dManually verified path truncation on betty VM (depth \u003e 32).\n\nChange-Id: I74393a70f24fc597d93ace643eec2fcf341dc6cb\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/7920042\nCommit-Queue: Aashay Shringarpure \u003caashay@google.com\u003e\nTested-by: Aashay Shringarpure \u003caashay@google.com\u003e\nReviewed-by: Princy Agrawal \u003cprincya@google.com\u003e\n"
    },
    {
      "commit": "20e6f930bfc274b7fb776004db201ea01b7f11d3",
      "tree": "c28af8254c29bed098651ce5ec7421b0e2c9198b",
      "parents": [
        "80e41ed22a482d873691590dc9e3bfc1f1a877c9"
      ],
      "author": {
        "name": "Josie Nordrum",
        "email": "josienordrum@google.com",
        "time": "Thu Jul 09 19:12:26 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Thu Jul 09 19:44:42 2026"
      },
      "message": "init: Add fingerprint_cq.star to DIR_METADATA\n\nInclude the fingerprint_cq.star test plan in the DIR_METADATA\nconfiguration to require fingerprint tests to run before submit.\n\nBUG\u003d532664660\nTEST\u003dFingerprint Cq runs\n\nChange-Id: Ic88957d145358d5f15a4968a7e8dfa7979203405\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8067361\nAuto-Submit: Josie Nordrum \u003cjosienordrum@google.com\u003e\nReviewed-by: Mike Frysinger \u003cvapier@chromium.org\u003e\nCommit-Queue: Josie Nordrum \u003cjosienordrum@google.com\u003e\nTested-by: Josie Nordrum \u003cjosienordrum@google.com\u003e\n"
    },
    {
      "commit": "80e41ed22a482d873691590dc9e3bfc1f1a877c9",
      "tree": "c57fc05947cc1703a45c32afb94b69d6f21b2c03",
      "parents": [
        "76816f8d652f86b1c367be157518bc6c36f4cf7e"
      ],
      "author": {
        "name": "crosvm-luci-ci-builder",
        "email": "crosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com",
        "time": "Thu Jul 09 12:00:33 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Thu Jul 09 16:12:53 2026"
      },
      "message": "vm_tools: Uprev baguette_image version\n\nGenerated by https://cr-buildbucket.appspot.com/build/8676755235411503713.\n\nChange-Id: I1a16dde537407aecb11d85e8c6c2ca169f8fd3eb\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8070316\nBot-Commit: crosvm LUCI CI \u003ccrosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com\u003e\nCommit-Queue: chromeos-auto-retry@chromeos-bot.iam.gserviceaccount.com \u003cchromeos-auto-retry@chromeos-bot.iam.gserviceaccount.com\u003e\n"
    },
    {
      "commit": "76816f8d652f86b1c367be157518bc6c36f4cf7e",
      "tree": "71a6dda405752d5a4ea98f44782092df58b39f52",
      "parents": [
        "c3d3069c38614783b815897aac8c84b288bca363"
      ],
      "author": {
        "name": "Satoshi Niwa",
        "email": "niwa@google.com",
        "time": "Thu Jul 09 07:47:28 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Thu Jul 09 12:05:49 2026"
      },
      "message": "patchpanel: Reject ArcVm D-Bus calls on non-ARCVM devices\n\nThis CL adds a check to patchpanel to reject ArcVmStartup and ArcVmShutdown D-Bus requests on devices built without ARCVM (USE_ARCVM\u003d0).\n\nSince only ARCVM endpoints utilize these specific D-Bus methods, patchpaneld should proactively drop the requests if kArcType is not configured as kVM.\n\nBUG\u003db:524027281\nTEST\u003dcros_workon_make --board\u003dbrya --test patchpanel\n\nChange-Id: I50832e8b46b0ff8d72f08dc9db4de1bac3f18fcc\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8061381\nCommit-Queue: Satoshi Niwa \u003cniwa@chromium.org\u003e\nReviewed-by: Hugo Benichi \u003chugobenichi@google.com\u003e\nTested-by: Satoshi Niwa \u003cniwa@chromium.org\u003e\n"
    },
    {
      "commit": "c3d3069c38614783b815897aac8c84b288bca363",
      "tree": "090980cf6f172e98dc02c980288b97979e50703b",
      "parents": [
        "3370d7f8eddfeceeea2e4aa9ddc338825bf1b2ec"
      ],
      "author": {
        "name": "Ben Reich",
        "email": "benreich@chromium.org",
        "time": "Thu Jul 09 02:19:23 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Thu Jul 09 07:58:45 2026"
      },
      "message": "Revert \"cros-disks: Restrict smbfs daemon-store bind mount to user hash\"\n\nThis reverts commit 8f0501d204ec5e9b4267564751b566abd1cc1ab0.\n\nReason for revert: Broken the SMB tast tests.\n\nFailure Link: https://cros-test-analytics.appspot.com/p/chromeos/search?filters\u003dtest%7E%22%28tast.filemanager.SMB%7Ctast.kerberos.*FileSystem%29%22\u0026exclude_cts\u003dfalse\u0026exclude_non_critical\u003dfalse\u0026exclude_non_production\u003dfalse\u0026exclude_not_run\u003dfalse\u0026exclude_tauto_sub_test\u003dfalse\u0026rowAxes\u003dtest\u0026columnAxes\u003dbuild\u0026statusAggregation\u003dRAW\u0026union\u003dAND\u0026viewMode\u003dMatrix\u0026accountId\u003d1\u0026startDate\u003d2026-07-03\u0026endDate\u003d2026-07-09\n\nBUG\u003db:516664366\n\nOriginal change\u0027s description:\n\u003e cros-disks: Restrict smbfs daemon-store bind mount to user hash\n\u003e\n\u003e Currently cros-disks recursively bind-mounts the entire global\n\u003e /run/daemon-store/smbfs directory into the minijail sandbox because it\n\u003e isn\u0027t aware which user is initiating the mount. This is overly permissive\n\u003e as it could allow lateral access to other users\u0027 stores information.\n\u003e\n\u003e This change extracts the account_hash parameter from the D-Bus mount\n\u003e options provided by Chrome. It ensures the corresponding user\u0027s\n\u003e directory actively exists in the daemon-store and strictly restricts the\n\u003e bind-mount to only that specific daemon-store directory.\n\u003e\n\u003e BUG\u003db:516664366\n\u003e TEST\u003dFEATURES\u003dtest emerge-brya chromeos-base/cros-disks\n\u003e\n\u003e Change-Id: Ie3d3caa3c49985fb9094c0a9734fd67be21b587c\n\u003e Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8027429\n\u003e Reviewed-by: Luciano Pacheco \u003clucmult@chromium.org\u003e\n\u003e Reviewed-by: Alexander Bolodurin \u003calexbn@google.com\u003e\n\u003e Tested-by: Ben Reich \u003cbenreich@chromium.org\u003e\n\u003e Reviewed-by: Ben Reich \u003cbenreich@chromium.org\u003e\n\u003e Commit-Queue: Ben Reich \u003cbenreich@chromium.org\u003e\n\nBUG\u003db:516664366\n\nChange-Id: I4bb290e49f0cdc62b66d7bca9a270412e8154f45\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8061269\nTested-by: Ben Reich \u003cbenreich@chromium.org\u003e\nReviewed-by: Luciano Pacheco \u003clucmult@chromium.org\u003e\nCommit-Queue: rubber-stamper@appspot.gserviceaccount.com \u003crubber-stamper@appspot.gserviceaccount.com\u003e\nCommit-Queue: Ben Reich \u003cbenreich@chromium.org\u003e\nAuto-Submit: Ben Reich \u003cbenreich@chromium.org\u003e\nBot-Commit: rubber-stamper@appspot.gserviceaccount.com \u003crubber-stamper@appspot.gserviceaccount.com\u003e\n"
    },
    {
      "commit": "3370d7f8eddfeceeea2e4aa9ddc338825bf1b2ec",
      "tree": "bba68d3aee44eefda460a78a09041c57b31bdeb7",
      "parents": [
        "6520b47f719c9578860c86ed8cc179a960c06086"
      ],
      "author": {
        "name": "Aida Zolic",
        "email": "aidazolic@chromium.org",
        "time": "Tue Jul 07 07:19:04 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Wed Jul 08 10:59:05 2026"
      },
      "message": "oobe_config: Skip HID and update screens\n\nSets two new OOBE config options to skip the HID and update\nscreens after a rollback or device migration. Following each,\nthe device should automatically enroll, so we are skipping\nany OOBE steps that require manual input if possible.\n\nBUG\u003db:531690126, b:530427463\nTEST\u003dcros_sdk FEATURES\u003dtest emerge-${BOARD} oobe_config\n\nChange-Id: I7b3cef14c39f2a8f23b829f9ff65258da26c5420\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8052584\nTested-by: Aida Zolic \u003caidazolic@chromium.org\u003e\nReviewed-by: Igor \u003cigorcov@chromium.org\u003e\nCommit-Queue: Aida Zolic \u003caidazolic@chromium.org\u003e\n"
    },
    {
      "commit": "6520b47f719c9578860c86ed8cc179a960c06086",
      "tree": "06d3b937339adbd51b0a67f970bacde140fe7335",
      "parents": [
        "77b867f945dfe9fc0aadd54218c28020b113192a"
      ],
      "author": {
        "name": "Georg Neis",
        "email": "neis@chromium.org",
        "time": "Tue Jul 07 07:27:31 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Wed Jul 08 04:37:53 2026"
      },
      "message": "mojo_service_manager: Allow \u0027shutdown\u0027 syscall\n\nlibchrome will soon include https://crrev.com/c/8011349, which makes\nthis necessary.\n\nBUG\u003dNone\nTEST\u003dcq\n\nChange-Id: Ib04adb78d75f00945e0e60a78f3fecd205fa935c\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8052304\nTested-by: Georg Neis \u003cneis@chromium.org\u003e\nCommit-Queue: Georg Neis \u003cneis@chromium.org\u003e\nReviewed-by: Ryo Hashimoto \u003chashimoto@chromium.org\u003e\n"
    },
    {
      "commit": "77b867f945dfe9fc0aadd54218c28020b113192a",
      "tree": "0a38f729e0eeff45bb24d7b49a3e186b790e3626",
      "parents": [
        "67f52511a069a32ae8f967495c2f08d3b83ec460"
      ],
      "author": {
        "name": "maciek swiech",
        "email": "drmasquatch@google.com",
        "time": "Wed Jul 01 18:54:59 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Tue Jul 07 19:35:39 2026"
      },
      "message": "permission_broker: patch keyboard hidraw bypass\n\na potential bypass was identified where the permission_broker parser\ndiverges in behavior from the in-kernel one.\n\nBUG\u003db:524103869\nTEST\u003dpoc code, cq\n\nChange-Id: Ie025f1b56eed3f18f6ef86cba19eacb7ccc66c97\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8030768\nReviewed-by: Aashay Shringarpure \u003caashay@google.com\u003e\nCommit-Queue: maciek swiech \u003cdrmasquatch@google.com\u003e\nTested-by: maciek swiech \u003cdrmasquatch@google.com\u003e\n"
    },
    {
      "commit": "67f52511a069a32ae8f967495c2f08d3b83ec460",
      "tree": "1e39b3a70c79d2c3a770af22872b41e9d53b5ad1",
      "parents": [
        "6a5fd1e0ab159c2f49e00d5831c4efdae056e2c8"
      ],
      "author": {
        "name": "maciek swiech",
        "email": "drmasquatch@google.com",
        "time": "Mon Jul 06 16:13:18 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Tue Jul 07 17:36:07 2026"
      },
      "message": "vm_tools: baguette_image: uprev to M152\n\nbranch-tasks\n\nBUG\u003db:531687584\nTEST\u003dcq\n\nChange-Id: I8c194867c82dc915bd41ac273512b89bfb1eef05\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8044857\nReviewed-by: Zihan Chen \u003czihanchen@google.com\u003e\nCommit-Queue: maciek swiech \u003cdrmasquatch@google.com\u003e\nTested-by: maciek swiech \u003cdrmasquatch@google.com\u003e\n"
    },
    {
      "commit": "6a5fd1e0ab159c2f49e00d5831c4efdae056e2c8",
      "tree": "23b842b455c43524f1820f64dca128471ae3253b",
      "parents": [
        "8f0501d204ec5e9b4267564751b566abd1cc1ab0"
      ],
      "author": {
        "name": "Brett Brotherton",
        "email": "bbrotherton@google.com",
        "time": "Thu May 28 18:52:41 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Tue Jul 07 16:42:52 2026"
      },
      "message": "smbprovider: Migrate NOTREACHED_IN_MIGRATION to NOTREACHED\n\nBUG\u003db:379735176\nTEST\u003dCQ\n\nChange-Id: I2c869957fdf65bb50453238e9d0659a9453efc36\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/7881989\nAuto-Submit: Brett Brotherton \u003cbbrotherton@google.com\u003e\nTested-by: Brett Brotherton \u003cbbrotherton@google.com\u003e\nCommit-Queue: chromeos-auto-retry@chromeos-bot.iam.gserviceaccount.com \u003cchromeos-auto-retry@chromeos-bot.iam.gserviceaccount.com\u003e\nReviewed-by: François Degros \u003cfdegros@chromium.org\u003e\n"
    },
    {
      "commit": "8f0501d204ec5e9b4267564751b566abd1cc1ab0",
      "tree": "986c4411da3ccf890c1cf1c879e1023410a31b0d",
      "parents": [
        "99173a34453c94e4a9a07b0717f49a455622c52f"
      ],
      "author": {
        "name": "Ben Reich",
        "email": "benreich@google.com",
        "time": "Tue Jun 30 19:45:18 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Tue Jul 07 08:39:51 2026"
      },
      "message": "cros-disks: Restrict smbfs daemon-store bind mount to user hash\n\nCurrently cros-disks recursively bind-mounts the entire global\n/run/daemon-store/smbfs directory into the minijail sandbox because it\nisn\u0027t aware which user is initiating the mount. This is overly permissive\nas it could allow lateral access to other users\u0027 stores information.\n\nThis change extracts the account_hash parameter from the D-Bus mount\noptions provided by Chrome. It ensures the corresponding user\u0027s\ndirectory actively exists in the daemon-store and strictly restricts the\nbind-mount to only that specific daemon-store directory.\n\nBUG\u003db:516664366\nTEST\u003dFEATURES\u003dtest emerge-brya chromeos-base/cros-disks\n\nChange-Id: Ie3d3caa3c49985fb9094c0a9734fd67be21b587c\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8027429\nReviewed-by: Luciano Pacheco \u003clucmult@chromium.org\u003e\nReviewed-by: Alexander Bolodurin \u003calexbn@google.com\u003e\nTested-by: Ben Reich \u003cbenreich@chromium.org\u003e\nReviewed-by: Ben Reich \u003cbenreich@chromium.org\u003e\nCommit-Queue: Ben Reich \u003cbenreich@chromium.org\u003e\n"
    },
    {
      "commit": "99173a34453c94e4a9a07b0717f49a455622c52f",
      "tree": "9c5ebf107cc60a97dbff0b36a488b063a4f5490e",
      "parents": [
        "7bebefd1c12978178fafa430012178c2865ef815"
      ],
      "author": {
        "name": "Jae Hoon Kim",
        "email": "kimjae@chromium.org",
        "time": "Thu Jun 11 01:42:27 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Tue Jul 07 08:22:55 2026"
      },
      "message": "update_engine: Move update success preference updates into ProcessingDoneUpdate\n\nThe preferences related to a successful full OS update (e.g., clearing\ndelta update failures, setting previous version) are now updated only\nwithin the `ProcessingDoneUpdate` method, which is called when the\n`ProcessMode` is `UPDATE`. This prevents these preferences from being\nmodified during DLC installs or partition migrations.\n\nBUG\u003db:506232287\nTEST\u003dbuilders/CQ\nChange-Id: I53895c35fa6a9835cd377ae344fd50a7d60494dc\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/7921159\nAuto-Submit: Jae Hoon Kim \u003ckimjae@chromium.org\u003e\nReviewed-by: Nitin Lakra \u003cnitinlakra@google.com\u003e\nCommit-Queue: Jae Hoon Kim \u003ckimjae@chromium.org\u003e\nTested-by: Jae Hoon Kim \u003ckimjae@chromium.org\u003e\n"
    },
    {
      "commit": "7bebefd1c12978178fafa430012178c2865ef815",
      "tree": "8e02ee5dd2b362b1b4a40d17d1ce837491bebf50",
      "parents": [
        "9f90e33b5a9e432bd5948710095866c07af0b230"
      ],
      "author": {
        "name": "Mike Frysinger",
        "email": "vapier@chromium.org",
        "time": "Tue Jun 23 03:02:38 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jul 06 14:04:56 2026"
      },
      "message": "init: chromeos-boot-alert: display boot messages in a minijail\n\nSince this command processes graphics, put it in a minijail.\n\nBUG\u003db:516656892\nTEST\u003dCQ passes\n\nChange-Id: I6b75cb60195c7b772a1f29c5d8b27d664fa52421\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/7989833\nReviewed-by: Sarthak Kukreti \u003csarthakkukreti@google.com\u003e\nTested-by: Mike Frysinger \u003cvapier@chromium.org\u003e\nCommit-Queue: Mike Frysinger \u003cvapier@chromium.org\u003e\n"
    },
    {
      "commit": "9f90e33b5a9e432bd5948710095866c07af0b230",
      "tree": "fc18d0d0d2df156bf8699215b9292c10dcdc490c",
      "parents": [
        "783ff00509cefde3d6c9a762dc616286be306a93"
      ],
      "author": {
        "name": "Zoraiz Naeem",
        "email": "zoraiznaeem@google.com",
        "time": "Wed Jul 01 01:10:20 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jul 06 06:30:05 2026"
      },
      "message": "login: Remove --ash-clear-fast-ink-buffer argument\n\nBUG\u003db:513393001\nTEST\u003dlocal\n\nChange-Id: Ia9d9fd13ffc26b56125de21420bbae4a0968983a\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8027510\nReviewed-by: Hidehiko Abe \u003chidehiko@chromium.org\u003e\nTested-by: Zoraiz Naeem \u003czoraiznaeem@chromium.org\u003e\nCommit-Queue: Zoraiz Naeem \u003czoraiznaeem@chromium.org\u003e\n"
    },
    {
      "commit": "783ff00509cefde3d6c9a762dc616286be306a93",
      "tree": "6f2d3e7a18489eb455c46a475145bc75c71ebb57",
      "parents": [
        "682b05fa04bc4e93ab64bd5c72d42aea797c93a6"
      ],
      "author": {
        "name": "Bo Majewski",
        "email": "majewski@google.com",
        "time": "Mon Jun 29 00:36:42 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jul 06 05:50:53 2026"
      },
      "message": "smbfs: URL-encode path components in SMB share paths.\n\nThis Change updates smbfs to URL-encode path components in SMB share\npaths by integrating base::EscapePath into RecursiveDeleteOperation\nand SmbFilesystem. This ensures that absolute paths are correctly\nformatted before being appended to the base share URL, with new\nunit tests added to smb_filesystem_test.cc to verify the handling of\nspecial characters and backslashes.\n\nBUG\u003db:516637902\nTEST\u003dchromeos-base/smbfs\n\nChange-Id: Idf7f874368c7d7689ce64aca54375e4894772238\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8028480\nReviewed-by: Josh Simmons \u003csimmonsjosh@google.com\u003e\nReviewed-by: Luciano Pacheco \u003clucmult@chromium.org\u003e\nCommit-Queue: Bo Majewski \u003cmajewski@google.com\u003e\nReviewed-by: Ben Reich \u003cbenreich@chromium.org\u003e\nTested-by: Bo Majewski \u003cmajewski@google.com\u003e\n"
    },
    {
      "commit": "682b05fa04bc4e93ab64bd5c72d42aea797c93a6",
      "tree": "c6e6615bb5d366e7bf7e64bb06a2e2d027c979ec",
      "parents": [
        "3401ecb45ec88e957803aa1ac019f6f05aa10fa2"
      ],
      "author": {
        "name": "crosvm-luci-ci-builder",
        "email": "crosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com",
        "time": "Sat Jul 04 12:00:48 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Sat Jul 04 15:25:09 2026"
      },
      "message": "vm_tools: Uprev baguette_image version\n\nGenerated by https://cr-buildbucket.appspot.com/build/8677208220317782897.\n\nChange-Id: I3a549f645429bb53abe5cb3fd8350340f5a94097\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8041688\nCommit-Queue: crosvm LUCI CI \u003ccrosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com\u003e\nBot-Commit: crosvm LUCI CI \u003ccrosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com\u003e\n"
    },
    {
      "commit": "3401ecb45ec88e957803aa1ac019f6f05aa10fa2",
      "tree": "ebe6d25f38736731f0f041ae1732640ff5e47eaa",
      "parents": [
        "5ef294d643521096b393cf1db9d8606ad81aad58"
      ],
      "author": {
        "name": "Aida Zolic",
        "email": "aidazolic@chromium.org",
        "time": "Tue Jun 30 08:23:55 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Fri Jul 03 07:23:22 2026"
      },
      "message": "oobe_config: Track device migration started metric\n\nAdd migration started event to Enterprise Rollback structured\nmetrics. The event is reported when the rollback data save is\ntriggered due to device migration between domains, rather than\na version downgrade.\n\nBUG\u003db:476315366\nTEST\u003dUSE\u003d\"chrome_internal -cros-debug\" cros_workon_make\n--board\u003dnissa metrics oobe_config session_manager --test\n\nChange-Id: Ia8163c70554599b198bcb3e38063a961e41afa8b\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8023842\nReviewed-by: Igor \u003cigorcov@chromium.org\u003e\nTested-by: Aida Zolic \u003caidazolic@chromium.org\u003e\nReviewed-by: Hidehiko Abe \u003chidehiko@chromium.org\u003e\nReviewed-by: Tony Yeoman \u003ctby@chromium.org\u003e\nCommit-Queue: Aida Zolic \u003caidazolic@chromium.org\u003e\n"
    },
    {
      "commit": "5ef294d643521096b393cf1db9d8606ad81aad58",
      "tree": "90ea450eb6668f900b35a7f0fa4391aba413599f",
      "parents": [
        "df7db11a5d8525d361fcf1d227722b447c3adb0c"
      ],
      "author": {
        "name": "Zikai Chen",
        "email": "chenzikai@google.com",
        "time": "Tue Jun 30 05:41:47 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Fri Jul 03 06:30:14 2026"
      },
      "message": "shill: DHCP: Fix leftover dhcpcd cleanup on shill startup\n\nOn shill startup, DHCPCDProxyFactory attempts to clean up leftover\ndhcpcd processes from the previous run. However, this cleanup was\nincorrectly implemented due to the following reasons:\n\n1. base::NamedProcessIterator was used. This iterator relies on reading\n   the \u0027proc/\u003cpid\u003e/exe\u0027 symlink to identify process names. Since shill\n   does not have CAP_SYS_PTRACE and runs as the \u0027shill\u0027 user while\n   dhcpcd runs as a different user \u0027dhcp\u0027, the kernel blocks reading\n   this symlink, causing it to find 0 processes.\n2. It kills processes using StopProcessAndBlock, which can cause startup\n   delays due to waitpid() returning ECHILD for non-child processes\n   (leftover dhcpcd processes were reparented to init).\n\nTo fix these, we:\n1. Use base::ProcessIterator instead of base::NamedProcessIterator.\n   We filter dhcpcd processes based on the first argument. Since dhcpcd\n   rewrites its command line via setproctitle() during runtime, we\n   match processes whose first argument starts with \"dhcpcd: \" and\n   ends with \" [ip4]\" or \" [ip6]\" (e.g., \"dhcpcd: eth0 [ip4]\"). This\n   identifies dhcpcd instances while avoiding helper processes (like\n   \"dhcpcd-script\") or unrelated processes.\n2. Send SIGKILL directly to leftover processes.\n\nBUG\u003db:522072729\nTEST\u003dtast run ${DUT} network.ResolvConfCrash*\n\nChange-Id: Iccccfbe80df9fd928136c02108270866eb3eb229\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8022743\nReviewed-by: Chih-Yu Huang \u003cakahuang@chromium.org\u003e\nReviewed-by: Jie Jiang \u003cjiejiang@chromium.org\u003e\nCommit-Queue: Zikai Chen \u003cchenzikai@google.com\u003e\nTested-by: Zikai Chen \u003cchenzikai@google.com\u003e\n"
    },
    {
      "commit": "df7db11a5d8525d361fcf1d227722b447c3adb0c",
      "tree": "61f7cf44a808ebf47f63799e543314aed159080c",
      "parents": [
        "c5d48b92d9a091fc25cf2d6b93d25135fa31e4c9"
      ],
      "author": {
        "name": "Vishwa Kalubowila",
        "email": "vishwa.kalubowila@codimite.com",
        "time": "Wed Jul 01 02:58:52 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Thu Jul 02 20:08:52 2026"
      },
      "message": "system_api: Add kCkaBrowserEnterpriseClientCertKey attribute\n\nIntroduce the kCkaBrowserEnterpriseClientCertKey PKCS#11 custom\nattribute to identify keys generated by the enterprise managed\nclient certificate (CA Connector) provisioning flow.\n\nThis allows the browser enterprise certificate stack to identify the\nkeys it owns for later cleanup and auditing. This constant is\nrequired to unblock browser-side changes in HighLevelChapsClient.\n\nBUG\u003db:517117656\nTEST\u003dNone\n\nChange-Id: I8fbd4b09f364a3b402fbdf2302f186beb1399e1f\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8029080\nReviewed-by: Eric Caruso \u003cejcaruso@chromium.org\u003e\nCommit-Queue: Siarhei Amelianiuk \u003comse@google.com\u003e\nTested-by: Siarhei Amelianiuk \u003comse@google.com\u003e\nReviewed-by: Siarhei Amelianiuk \u003comse@google.com\u003e\nReviewed-by: Michael Ershov \u003cmiersh@google.com\u003e\n"
    },
    {
      "commit": "c5d48b92d9a091fc25cf2d6b93d25135fa31e4c9",
      "tree": "5dba9051293f7ec5d75d8f4f690a5934794445b2",
      "parents": [
        "ef069627c7a89fe4dd4007bbf113e3cedcc6332e"
      ],
      "author": {
        "name": "crosvm-luci-ci-builder",
        "email": "crosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com",
        "time": "Thu Jul 02 12:00:47 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Thu Jul 02 15:03:34 2026"
      },
      "message": "vm_tools: Uprev baguette_image version\n\nGenerated by https://cr-buildbucket.appspot.com/build/8677389411411886353.\n\nChange-Id: I5ec9583ed8aa052ccb650a60a82b251552f8236e\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8035587\nCommit-Queue: crosvm LUCI CI \u003ccrosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com\u003e\nBot-Commit: crosvm LUCI CI \u003ccrosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com\u003e\n"
    },
    {
      "commit": "ef069627c7a89fe4dd4007bbf113e3cedcc6332e",
      "tree": "f24f43bf9c9c9b79953efcb8ffddc9bb1c88090c",
      "parents": [
        "7a8bee2a3bbec67cf327c0ffc7c9aed65837421c"
      ],
      "author": {
        "name": "Aida Zolic",
        "email": "aidazolic@chromium.org",
        "time": "Wed Jul 01 09:13:27 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Thu Jul 02 12:02:14 2026"
      },
      "message": "oobe_config: Don\u0027t retain EULA when moving device\n\nDuring device migration (domain transfer), do not auto-accept EULA\nand UMA statistics. For rollbacks, after which the device auto-enrolls\ninto the same domain, the acceptance is still preserved.\n\nBUG\u003db:530072225\nTEST\u003dcros_workon_make --board\u003d$BOARD oobe_config --test\n\nChange-Id: I6c6de6eeae02c838ca457f1504d1dfc3037f099d\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8024714\nReviewed-by: Igor \u003cigorcov@chromium.org\u003e\nCommit-Queue: Aida Zolic \u003caidazolic@chromium.org\u003e\nTested-by: Aida Zolic \u003caidazolic@chromium.org\u003e\n"
    },
    {
      "commit": "7a8bee2a3bbec67cf327c0ffc7c9aed65837421c",
      "tree": "6550b840dc58a5f3216931b0daeccd5fc69851e0",
      "parents": [
        "f6e2157ce3acba0329aeeaaec4aeb30bd242d33d"
      ],
      "author": {
        "name": "Roland Bock",
        "email": "rbock@google.com",
        "time": "Thu Jun 18 16:02:15 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Thu Jul 02 06:41:05 2026"
      },
      "message": "login: Allow ClearBlockDevmodeVpd only during OOBE\n\ninstall_attributes are locked at the end of OOBE.\n\nThe only legitimate call of ClearBlockDevmodeVpd happens during OOBE.\nWith this change, we block any attempt to call it outside of OOBE, i.e.\nwhen install_attributes are locked.\n\nBUG\u003db:524007151\nTEST\u003dNew and existing unit tests\n\nChange-Id: Ia5aec61a956a566ef1437db97a191ac8eafb909e\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/7962955\nCommit-Queue: Roland Bock \u003crbock@google.com\u003e\nReviewed-by: Igor \u003cigorcov@chromium.org\u003e\nTested-by: Roland Bock \u003crbock@google.com\u003e\nReviewed-by: Hidehiko Abe \u003chidehiko@chromium.org\u003e\n"
    },
    {
      "commit": "f6e2157ce3acba0329aeeaaec4aeb30bd242d33d",
      "tree": "7acca9141068ce8d0f37784eb048ac5eaa80bf51",
      "parents": [
        "51f2b5e5b7ff8dee01f1626213b04ba6f2227f82"
      ],
      "author": {
        "name": "Aashay Shringarpure",
        "email": "aashay@google.com",
        "time": "Wed Jul 01 17:06:31 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Wed Jul 01 20:06:27 2026"
      },
      "message": "debugd: Reland default Minijail runtime environment\n\nReland the default Minijail runtime environment for debugd calls.\nThis reverts the mitigation introduced for b/267050115 where\n--no-default-runtime-environment was added because of crashes on jacuzzi.\nVerified that BackupArcBugReport now works with the default runtime\non skywalker (ARM64) and does not crash nsenter.\n\nBUG\u003db:267050115\nBUG\u003db:516698947\nTEST\u003dVerified BackupArcBugReport on skywalker DUT\n\nChange-Id: I7c52c3236a8c05012adfb4f1a7cd7b0c427dd7ea\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8032081\nTested-by: Aashay Shringarpure \u003caashay@google.com\u003e\nReviewed-by: Ben Scarlato \u003cakhna@google.com\u003e\nCommit-Queue: Aashay Shringarpure \u003caashay@google.com\u003e\n"
    },
    {
      "commit": "51f2b5e5b7ff8dee01f1626213b04ba6f2227f82",
      "tree": "d5e9facebe69e4a38e2bfd29f50107063ad34e4e",
      "parents": [
        "b6866f7d75404691024911f1589534f45bf439ca"
      ],
      "author": {
        "name": "Xiyuan Xia",
        "email": "xiyuan@google.com",
        "time": "Tue Jun 30 17:43:36 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Wed Jul 01 01:05:16 2026"
      },
      "message": "Remove xiyuan from OWNERS\n\nChange-Id: If807094a4c498d9068baed7f1ed6b948d207c2cc\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8026750\nTested-by: Xiyuan Xia \u003cxiyuan@chromium.org\u003e\nReviewed-by: Hidehiko Abe \u003chidehiko@chromium.org\u003e\nAuto-Submit: Xiyuan Xia \u003cxiyuan@chromium.org\u003e\nCommit-Queue: Hidehiko Abe \u003chidehiko@chromium.org\u003e\n"
    },
    {
      "commit": "b6866f7d75404691024911f1589534f45bf439ca",
      "tree": "f2fd1b7b3708e50a42191e0e128c792fb110e6f6",
      "parents": [
        "7089ac04490b28f2477722bedcaae07bd1d921ec"
      ],
      "author": {
        "name": "Allen Webb",
        "email": "allenwebb@google.com",
        "time": "Tue Jun 30 14:57:29 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Tue Jun 30 23:15:24 2026"
      },
      "message": "ferrochrome: Remove experimental code\n\nBUG\u003db:524350608\nTEST\u003dCQ passes\n\nChange-Id: Id9ec7c13ee9c8494cc77113eb3807dd4090358a5\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8025629\nCommit-Queue: Jiyong Park \u003cjiyong@google.com\u003e\nAuto-Submit: Allen Webb \u003callenwebb@google.com\u003e\nReviewed-by: Jiyong Park \u003cjiyong@google.com\u003e\nTested-by: Allen Webb \u003callenwebb@google.com\u003e\n"
    },
    {
      "commit": "7089ac04490b28f2477722bedcaae07bd1d921ec",
      "tree": "bbb8ad1074f104d3bffc29cdd258985e1409eda2",
      "parents": [
        "32a6fa8ffc6ef82b66a547d518afc80bf19d523d"
      ],
      "author": {
        "name": "Nathan Muggli",
        "email": "nmuggli@google.com",
        "time": "Mon Jun 29 19:54:13 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Tue Jun 30 15:33:36 2026"
      },
      "message": "power: Add necessary include\n\nThis was depending on a transitive include, which is getting\nre-organized upstream.  Instead, add the explicit include here.\n\nBUG\u003db:465651491\nTEST\u003dCQ\n\nChange-Id: I9dc8a33573f031e3782c73e3fb5086c0ea6acfb6\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8020025\nReviewed-by: Mengqi Guo \u003cmqg@chromium.org\u003e\nAuto-Submit: Nathan Muggli \u003cnmuggli@google.com\u003e\nCommit-Queue: Nathan Muggli \u003cnmuggli@google.com\u003e\nTested-by: Nathan Muggli \u003cnmuggli@google.com\u003e\n"
    },
    {
      "commit": "32a6fa8ffc6ef82b66a547d518afc80bf19d523d",
      "tree": "f33c984176832e12630b2ca5680750810e89eca6",
      "parents": [
        "5f835a3f33f7f31e55fa78971fe5d21108bd5b38"
      ],
      "author": {
        "name": "kkimdev",
        "email": "kkimdev@chromium.org",
        "time": "Mon Jun 22 14:21:08 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Tue Jun 30 10:00:57 2026"
      },
      "message": "garcon: add XDG data directories pixmaps fallback\n\nWhen no icon is found in the theme directories, check\n$XDG_DATA_DIRS/pixmaps/ for the icon before falling back to the\nhardcoded /usr/share/pixmaps/ path. This ensures installs under\nprefixes managed by tools like Nix are discovered.\n\nBUG\u003db:526074805\nTEST\u003demerge-amd64-generic vm_tools \u0026\u0026 FEATURES\u003dtest emerge-amd64-generic vm_tools\n\nChange-Id: I5d79a10afc493a058c282d4329ab28ef1599a9a2\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/7979878\nTested-by: Kibeom Kim \u003ckkimdev@chromium.org\u003e\nAuto-Submit: Kibeom Kim \u003ckkimdev@chromium.org\u003e\nCommit-Queue: Kibeom Kim \u003ckkimdev@chromium.org\u003e\nReviewed-by: Dmitry Torokhov \u003cdtor@chromium.org\u003e\nReviewed-by: Junichi Uekawa \u003cuekawa@chromium.org\u003e\n"
    },
    {
      "commit": "5f835a3f33f7f31e55fa78971fe5d21108bd5b38",
      "tree": "0787921d1272e53cd5e5074b3b7b4e6f4b0a6e9f",
      "parents": [
        "7c483fd438b588f20212df3072385653da4057df"
      ],
      "author": {
        "name": "Aida Zolic",
        "email": "aidazolic@chromium.org",
        "time": "Tue Jun 16 15:07:28 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Tue Jun 30 07:34:47 2026"
      },
      "message": "oobe_config: Add device migration config save\n\nExtends the RollbackData proto to contain a flag that will\nbe used to distinguish the rollback flow from the data save\ntriggered by the device migration tool, as well as the\nlogic surrounding writing and reading of this flag before\nand after the device wipe respectfully.\n\nBUG\u003db:524627797\nTEST\u003dcros_workon_make --board\u003dbetty oobe_config --test\n\nCq-Depend: chromium:7951198\nChange-Id: I9b6e206f7d0a5c2b94cd0d3e36792d9832329825\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/7951199\nReviewed-by: Igor \u003cigorcov@chromium.org\u003e\nTested-by: Aida Zolic \u003caidazolic@chromium.org\u003e\nCommit-Queue: Aida Zolic \u003caidazolic@chromium.org\u003e\n"
    },
    {
      "commit": "7c483fd438b588f20212df3072385653da4057df",
      "tree": "2f9c255fc3209adf6259c672e58d3bba231c3479",
      "parents": [
        "89c222db6ff80649d426265260c3b14a32268264"
      ],
      "author": {
        "name": "Aida Zolic",
        "email": "aidazolic@chromium.org",
        "time": "Tue Jun 16 13:48:28 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Tue Jun 30 07:34:43 2026"
      },
      "message": "login: Add payload to StartRemoteDeviceWipe method\n\nExtends the `StartRemoteDeviceWipe()` method to support a payload.\n\nIf the payload is passed and valid, it will contain a bool param\nthat will indicate whether certain device configs should be saved\nand reapplied after the wipe. If set to true, SessionManagerImpl\nwrites two marker files:\n- `.save_rollback_data` which triggers oobe_config_save\n- `.save_device_migration_data` that marks this is a device migration,\nand not a OS version rollback flow\n\nThe latter file skips some rollback specific flows, such as the auto\nre-enrollment into the same domain after boot.\n\nIf the payload is empty, invalid, or false, the standard, full wipe\nis applied.\n\nBUG\u003db:522643246\nTEST\u003ddbus_unittest\n--gtest_filter\u003d\"SessionManagerImplTest.StartRemoteDeviceWipeWithDeviceConfigSave*\"\nTAG\u003dagy\n\nChange-Id: I5df407cf83ce1e92306004cf055a90e8ed3e02ab\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/7951198\nCommit-Queue: Aida Zolic \u003caidazolic@chromium.org\u003e\nTested-by: Aida Zolic \u003caidazolic@chromium.org\u003e\nReviewed-by: Hidehiko Abe \u003chidehiko@chromium.org\u003e\nAuto-Submit: Aida Zolic \u003caidazolic@chromium.org\u003e\nReviewed-by: Sergey Poromov \u003cporomov@chromium.org\u003e\n"
    },
    {
      "commit": "89c222db6ff80649d426265260c3b14a32268264",
      "tree": "ef62d12b6c8be0e3ee3c1661ba9bc8efbfc90021",
      "parents": [
        "303b4b4663614e309d60c2f24e2d83c6d4e01414"
      ],
      "author": {
        "name": "Jae Hoon Kim",
        "email": "kimjae@google.com",
        "time": "Tue Jun 23 07:17:55 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jun 29 21:53:12 2026"
      },
      "message": "imageloader: Restrict root helper to mounting under /run/imageloader/\n\nThe imageloader root helper process was unconditionally trusting the\nmount_path provided by the unprivileged parent process. This allowed\na compromised sandboxed daemon to overmount arbitrary host directories\nwith attacker-controlled images, leading to sandbox escape and privilege\nescalation.\n\nThis CL adds path validation to the root helper, ensuring that all\nmount and unmount operations are restricted to paths under the trusted\nbase directory (/run/imageloader/).\n\nBUG\u003db:523976092\nTEST\u003dManual verification of path validation logic.\n\nChange-Id: I0d2cbcbb7bd929c5a3108fca5bf9f865300a62c3\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/7983007\nReviewed-by: Alain Michaud \u003calainm@chromium.org\u003e\nReviewed-by: Sarthak Kukreti \u003csarthakkukreti@google.com\u003e\nCommit-Queue: Sarthak Kukreti \u003csarthakkukreti@google.com\u003e\nAuto-Submit: Jae Hoon Kim \u003ckimjae@chromium.org\u003e\nTested-by: Jae Hoon Kim \u003ckimjae@chromium.org\u003e\n"
    },
    {
      "commit": "303b4b4663614e309d60c2f24e2d83c6d4e01414",
      "tree": "faf876fd3053a10323865caa02b76daa8d7cc716",
      "parents": [
        "ac7bc3be0616c31cf5ccb2002fbee943b5dc88ca"
      ],
      "author": {
        "name": "Kevin Lin",
        "email": "kevinptt@google.com",
        "time": "Mon Jun 29 06:28:27 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jun 29 18:11:58 2026"
      },
      "message": "run_oci: Alias OciEnvironment to base::EnvironmentMap\n\nUpstream libchrome CL:7399558 updated base::EnvironmentMap to use\nstd::less\u003c\u003e as its comparator for transparent lookups:\n  std::map\u003cstd::string, std::string, std::less\u003c\u003e\u003e\n\nOciEnvironment was defined as std::map\u003cstd::string, std::string\u003e (using\nstd::less\u003cstd::string\u003e). Because the comparator types differ, direct\nassignment via operator\u003d to base::LaunchOptions::environment fails to\ncompile.\n\nAlias OciEnvironment to base::EnvironmentMap. Format run_oci.cc.\n\nBUG\u003dNone\nTEST\u003demerge-cros run_oci\n\nChange-Id: I32e26fd513e1f340336359d881eb031fb071433c\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8016534\nAuto-Submit: Kevin Lin \u003ckevinptt@chromium.org\u003e\nCommit-Queue: Nathan Muggli \u003cnmuggli@google.com\u003e\nReviewed-by: Ryo Hashimoto \u003chashimoto@chromium.org\u003e\nTested-by: Kevin Lin \u003ckevinptt@chromium.org\u003e\n"
    },
    {
      "commit": "ac7bc3be0616c31cf5ccb2002fbee943b5dc88ca",
      "tree": "dd037e4e5a8ee735e5231c4201db439fb99e4aa7",
      "parents": [
        "9b344b8ec8bd395cc1169a7a9d63994428697478"
      ],
      "author": {
        "name": "crosvm-luci-ci-builder",
        "email": "crosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com",
        "time": "Mon Jun 29 12:00:37 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jun 29 15:31:51 2026"
      },
      "message": "vm_tools: Uprev baguette_image version\n\nGenerated by https://cr-buildbucket.appspot.com/build/8677661201365775217.\n\nChange-Id: I7ad7db64f40981182a4642a72ddbe0cea8e490bb\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8018871\nCommit-Queue: crosvm LUCI CI \u003ccrosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com\u003e\nBot-Commit: crosvm LUCI CI \u003ccrosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com\u003e\n"
    },
    {
      "commit": "9b344b8ec8bd395cc1169a7a9d63994428697478",
      "tree": "8c1b973340e98db9bfe9ccae61603c4c09a9236c",
      "parents": [
        "87144e1a5d4e8810b6ccde48b45c955099a74584"
      ],
      "author": {
        "name": "Bartłomiej Wiśniewski",
        "email": "wisniewskib@google.com",
        "time": "Mon Jun 29 09:24:03 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jun 29 13:20:02 2026"
      },
      "message": "tpm2-simulator: Add pinweaver_eal_clear_keys implementation\n\nImplement pinweaver_eal_clear_keys to satisfy EAL interface requirements.\n\nBUG\u003db:518008693\nTEST\u003demerge-$BOARD tpm2-simulator\n\nChange-Id: Ib3544f3f4081d71165bf1dca883476f89158a7ad\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8019182\nTested-by: Bartłomiej Wiśniewski \u003cwisniewskib@google.com\u003e\nAuto-Submit: Bartłomiej Wiśniewski \u003cwisniewskib@google.com\u003e\nCommit-Queue: Bartłomiej Wiśniewski \u003cwisniewskib@google.com\u003e\nReviewed-by: Adrian Barnaś \u003cabarnas@google.com\u003e\n"
    },
    {
      "commit": "87144e1a5d4e8810b6ccde48b45c955099a74584",
      "tree": "29135210333e7693aab9cdc7c31b87f2977abf30",
      "parents": [
        "a826681fb55be2c3a769ca67876b7c55306610cc"
      ],
      "author": {
        "name": "Bartłomiej Wiśniewski",
        "email": "wisniewskib@google.com",
        "time": "Mon Jun 29 08:17:48 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jun 29 13:19:59 2026"
      },
      "message": "tpm2-simulator: Reorder include order in pinweaver_eal.cc\n\nRun `cros format` on pinweaver_eal.cc to\nsatisfy formatter to allow future changes in\nthis file to pass pre-upload validation hooks.\n\nBUG\u003dNone\nTEST\u003dCQ\n\nChange-Id: I6fb696ad966ea02f42b9ac839fac34f836811bca\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8014743\nAuto-Submit: Bartłomiej Wiśniewski \u003cwisniewskib@google.com\u003e\nReviewed-by: Adrian Barnaś \u003cabarnas@google.com\u003e\nTested-by: Bartłomiej Wiśniewski \u003cwisniewskib@google.com\u003e\nCommit-Queue: Bartłomiej Wiśniewski \u003cwisniewskib@google.com\u003e\n"
    },
    {
      "commit": "a826681fb55be2c3a769ca67876b7c55306610cc",
      "tree": "8abc45ae68158f289b9194a8d906a3e7a00ca64a",
      "parents": [
        "abd90d55ee21d870cbd5cafa975bf9a5bab4e759"
      ],
      "author": {
        "name": "Kevin Lin",
        "email": "kevinptt@chromium.org",
        "time": "Wed Jun 24 02:54:26 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jun 29 05:06:12 2026"
      },
      "message": "Replace deprecated MemoryMappedFile methods with bytes()\n\nThis change updates usages of base::MemoryMappedFile::data() and\nbase::MemoryMappedFile::length() to use the new bytes() method, which\nreturns a base::span\u003cconst uint8_t\u003e. For mutable access, mutable_bytes()\nis used. This aligns with modern C++ practices and improves type safety.\n\nBUG\u003db:527892622\nTEST\u003dCQ\n\nChange-Id: Ic2019177ededc0b0b628dcca0dba14367b13f9c4\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/7980899\nCommit-Queue: Kevin Lin \u003ckevinptt@chromium.org\u003e\nReviewed-by: Howard Yang \u003chcyang@google.com\u003e\nReviewed-by: Yoshiki IGUCHI \u003cyoshiki@chromium.org\u003e\nTested-by: Di Wu \u003cdiwux@google.com\u003e\nReviewed-by: Adrian Barnaś \u003cabarnas@google.com\u003e\nReviewed-by: Dawid Niedźwiecki \u003cdawidn@google.com\u003e\nReviewed-by: Rob Barnes \u003crobbarnes@google.com\u003e\nReviewed-by: Amanda Deacon \u003camandadeacon@chromium.org\u003e\nReviewed-by: Di Wu \u003cdiwux@google.com\u003e\nAuto-Submit: Kevin Lin \u003ckevinptt@chromium.org\u003e\n"
    },
    {
      "commit": "abd90d55ee21d870cbd5cafa975bf9a5bab4e759",
      "tree": "042ca2845a6870a400a50e5b591f35ba81686e71",
      "parents": [
        "3b8dbfb0ba6bca3032dcbf78c12f609ed6a8df89"
      ],
      "author": {
        "name": "Hugo Benichi",
        "email": "hugobenichi@google.com",
        "time": "Fri Jun 19 05:21:11 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jun 29 00:15:17 2026"
      },
      "message": "shill: net: strict ifname validation in Throttler\n\nBUG\u003db:514468689\nTEST\u003dFEATURES\u003dtest emerge-$BOARD shill\n\nChange-Id: I737a9e60de7ee7e14b3829fe8186b99af61efcd2\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/7962280\nReviewed-by: Chih-Yu Huang \u003cakahuang@chromium.org\u003e\nAuto-Submit: Hugo Benichi \u003chugobenichi@google.com\u003e\nCommit-Queue: Hugo Benichi \u003chugobenichi@google.com\u003e\nTested-by: Hugo Benichi \u003chugobenichi@google.com\u003e\n"
    },
    {
      "commit": "3b8dbfb0ba6bca3032dcbf78c12f609ed6a8df89",
      "tree": "2d5f7b849199db4fce91f4ae99a1b15cde41d597",
      "parents": [
        "c5febd36d0ae5294cd465148a992962eadca7edc"
      ],
      "author": {
        "name": "Roland Bock",
        "email": "rbock@google.com",
        "time": "Thu Jun 18 15:39:19 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Sat Jun 27 16:29:44 2026"
      },
      "message": "login: Block owner key clobbering on the login screen\n\nThis enforces that clobbering the owner key happens only in consumer\ndevices and only when the owner is signed in.\n\nBUG\u003db:514025193\nTEST\u003dAdjusted and new unit tests\n\nChange-Id: I34ca9378178cb1fd782ce974bd20fececa00210d\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/7965278\nCommit-Queue: Roland Bock \u003crbock@google.com\u003e\nTested-by: Roland Bock \u003crbock@google.com\u003e\nReviewed-by: Hidehiko Abe \u003chidehiko@chromium.org\u003e\n"
    },
    {
      "commit": "c5febd36d0ae5294cd465148a992962eadca7edc",
      "tree": "bfca82908afc0ddd37b51a51a7e49d5f16c068d0",
      "parents": [
        "38272f61162fa7fa1b6dfa7a6afc1ac8d2f9650b"
      ],
      "author": {
        "name": "crosvm-luci-ci-builder",
        "email": "crosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com",
        "time": "Sat Jun 27 12:00:28 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Sat Jun 27 15:07:58 2026"
      },
      "message": "vm_tools: Uprev baguette_image version\n\nGenerated by https://cr-buildbucket.appspot.com/build/8677842399415361921.\n\nChange-Id: Ide51c5dba6caca7b4e61b85e2063ff2093d8a6f2\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8014464\nCommit-Queue: crosvm LUCI CI \u003ccrosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com\u003e\nBot-Commit: crosvm LUCI CI \u003ccrosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com\u003e\n"
    },
    {
      "commit": "38272f61162fa7fa1b6dfa7a6afc1ac8d2f9650b",
      "tree": "b94f84c38c4c79dbc38bb62262d36a8c6763a70f",
      "parents": [
        "02fbb11247d4a942f624ad2aea24f22dcf53303f"
      ],
      "author": {
        "name": "Nathan Muggli",
        "email": "nmuggli@google.com",
        "time": "Wed May 06 18:23:34 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Sat Jun 27 06:02:40 2026"
      },
      "message": "biod: Update logging include files\n\nSome of the logging framework has moved from base/logging.h to\nbase/logging/logging_settings.h.  Update the appropriate includes.\n\nBUG\u003db:465651491\nTEST\u003dCQ\n\nDisallow-Recycled-Builds: all\nChange-Id: I18440d966a02112b8cef0d1dc5116b12d9d421df\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/7822268\nTested-by: Nathan Muggli \u003cnmuggli@google.com\u003e\nReviewed-by: Josie Nordrum \u003cjosienordrum@google.com\u003e\nCommit-Queue: Nathan Muggli \u003cnmuggli@google.com\u003e\n"
    },
    {
      "commit": "02fbb11247d4a942f624ad2aea24f22dcf53303f",
      "tree": "2a7e1bd26d4e26ad6808f489d3287fc335d9d48b",
      "parents": [
        "07ce9deec28cdb32cf2f2f5083871bec301123e1"
      ],
      "author": {
        "name": "crosvm-luci-ci-builder",
        "email": "crosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com",
        "time": "Fri Jun 26 12:00:35 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Fri Jun 26 15:36:32 2026"
      },
      "message": "vm_tools: Uprev baguette_image version\n\nGenerated by https://cr-buildbucket.appspot.com/build/8677932995170255153.\n\nChange-Id: I4a310ea9172689d693ab7a34ce8c1f2b0554422d\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/8008210\nCommit-Queue: crosvm LUCI CI \u003ccrosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com\u003e\nBot-Commit: crosvm LUCI CI \u003ccrosvm-luci-ci-builder@crosvm-infra.iam.gserviceaccount.com\u003e\n"
    },
    {
      "commit": "07ce9deec28cdb32cf2f2f5083871bec301123e1",
      "tree": "e2cf2775d985c51b6634bccc5f226e2b92532e22",
      "parents": [
        "07b61a540e05cce5d46618c78b32842d334b05d5"
      ],
      "author": {
        "name": "kkimdev",
        "email": "kkimdev@chromium.org",
        "time": "Mon Jun 22 14:20:34 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Fri Jun 26 14:08:08 2026"
      },
      "message": "garcon: expand icon fallback size list to include 1024 and 512\n\nWhen no index.theme is present, garcon falls back to searching for PNG\nicons in a hardcoded list of sizes. Add 1024 and 512 to this list so\nthat icons shipped only at high resolutions (e.g. Nix\u0027s VS Code at\n1024x1024) are found.\n\nBUG\u003db:526074805\nTEST\u003demerge-amd64-generic vm_tools \u0026\u0026 FEATURES\u003dtest emerge-amd64-generic vm_tools\n\nChange-Id: Idbff6818bbdd5ff353de863963ef2bec73f7a700\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/7979877\nReviewed-by: Dmitry Torokhov \u003cdtor@chromium.org\u003e\nCommit-Queue: Kibeom Kim \u003ckkimdev@chromium.org\u003e\nReviewed-by: Kibeom Kim \u003ckkimdev@chromium.org\u003e\nAuto-Submit: Kibeom Kim \u003ckkimdev@chromium.org\u003e\nReviewed-by: Junichi Uekawa \u003cuekawa@chromium.org\u003e\nTested-by: Kibeom Kim \u003ckkimdev@chromium.org\u003e\n"
    },
    {
      "commit": "07b61a540e05cce5d46618c78b32842d334b05d5",
      "tree": "a107024a8cef5f1932edab62dd00e4b6c93f931b",
      "parents": [
        "8ea3af2134687a3c1a13767edbf649412bd26e3f"
      ],
      "author": {
        "name": "Hidehiko Abe",
        "email": "hidehiko@chromium.org",
        "time": "Mon Jun 22 22:23:51 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Fri Jun 26 12:36:46 2026"
      },
      "message": "login: PID check for SetFlagsForUser D-Bus method.\n\nBUG\u003db:516662733\nTEST\u003dTryjob\n\nChange-Id: Ibc57f906240155ac2d43aea9c0a4404fc301a361\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/7981637\nCommit-Queue: Hidehiko Abe \u003chidehiko@chromium.org\u003e\nTested-by: Hidehiko Abe \u003chidehiko@chromium.org\u003e\nReviewed-by: Jun Ishiguro \u003cjunis@google.com\u003e\nReviewed-by: Pavol Marko \u003cpmarko@chromium.org\u003e\n"
    },
    {
      "commit": "8ea3af2134687a3c1a13767edbf649412bd26e3f",
      "tree": "d7e25216d401d0e21ab6979a5650fa72610498de",
      "parents": [
        "362404e596160add78f63bc42ff2081b91941af5"
      ],
      "author": {
        "name": "Junichi Uekawa",
        "email": "uekawa@google.com",
        "time": "Thu Jun 25 00:16:47 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Fri Jun 26 06:12:21 2026"
      },
      "message": "cicerone: Remove container upgrade code\n\nRemove code related to upgrading Crostini container from cicerone and\ntremplin. This feature is no longer supported/needed.\n\nChrome builds with the .h changes. 4kB vm_guest_tools and 13kB\nvm_host_tools savings.\n\nBUG\u003db:434008323\nTEST\u003demerge-brya vm_host_tools \u0026\u0026 cros_run_unit_tests \\\n  --board\u003dbrya --packages vm_host_tools\n\nTAG\u003dagy CONV\u003d56c4585e-eba6-47c6-bd3c-c9f6272cdca3\n\nCq-Depend: chromium:7999910, chromium:8003157\nChange-Id: Ic10278e32844e41681bdcb14b97f52424b3488f9\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/7999356\nReviewed-by: maciek swiech \u003cdrmasquatch@google.com\u003e\nTested-by: Junichi Uekawa \u003cuekawa@chromium.org\u003e\nReviewed-by: Georg Neis \u003cneis@chromium.org\u003e\nCommit-Queue: Junichi Uekawa \u003cuekawa@chromium.org\u003e\n"
    },
    {
      "commit": "362404e596160add78f63bc42ff2081b91941af5",
      "tree": "b1bbbe9cbcb0c1ddba7cd9d3d7b0110ec533cf0c",
      "parents": [
        "076909133fa52d40c21d4822b0c2b14919998d44"
      ],
      "author": {
        "name": "Surbhi Kadam",
        "email": "surbhikadam@google.com",
        "time": "Wed Jun 24 17:06:19 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Thu Jun 25 20:27:27 2026"
      },
      "message": "metrics: Fix DBus connection leak in MetricsLibrary::IsGuestMode()\n\nThe dbus::Bus connection created in IsGuestMode() was never explicitly\nshut down before returning. This caused DBus connections to leak, eventually\nexhausting the UID 0 limit (256 max connections) when called repeatedly by\ncrash_sender.\n\nThis CL adds a call to bus-\u003eShutdownAndBlock() before returning.\n\nBUG\u003db:524616941\nTEST\u003demerge-amd64-generic metrics\n\nChange-Id: If8fae6dcfb32a7e6949f21bebdba2b2be7a34e52\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/7994582\nReviewed-by: Troy Wang \u003ctroywang@google.com\u003e\nReviewed-by: Stefan Reinauer \u003creinauer@google.com\u003e\nTested-by: Surbhi Kadam \u003csurbhikadam@google.com\u003e\nCommit-Queue: Surbhi Kadam \u003csurbhikadam@google.com\u003e\n"
    },
    {
      "commit": "076909133fa52d40c21d4822b0c2b14919998d44",
      "tree": "1edafc1346de429c39d81bd3cd188ee9d31e77ed",
      "parents": [
        "7609d0db6516dbfb9db2b65ea00be0d6dbd0466e"
      ],
      "author": {
        "name": "Aashay Shringarpure",
        "email": "aashay@google.com",
        "time": "Mon Jun 22 23:44:02 2026"
      },
      "committer": {
        "name": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Thu Jun 25 18:35:30 2026"
      },
      "message": "permission_broker: Use secure flags when opening paths\n\nApply O_CLOEXEC and O_NOFOLLOW to open() calls to align with secure\ncoding practices for system daemons.\n\nBUG\u003db:514095286\nTEST\u003dcros_workon_make --board\u003dbetty --test permission_broker\n\nChange-Id: I29445c520495458e70d7733f094335652a92d47d\nReviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/7980165\nTested-by: maciek swiech \u003cdrmasquatch@google.com\u003e\nReviewed-by: maciek swiech \u003cdrmasquatch@google.com\u003e\nCommit-Queue: Aashay Shringarpure \u003caashay@google.com\u003e\n"
    }
  ],
  "next": "7609d0db6516dbfb9db2b65ea00be0d6dbd0466e"
}
