)]}'
{
  "log": [
    {
      "commit": "307d9522d6530efa73ff7b46f809031c0d639f35",
      "tree": "54d9daba1f8cde8a4c7ccacbc2d15e4715668182",
      "parents": [
        "8e20d7d9ebab09f20fa5f1af3dd5a85a5dc61c42",
        "83b5da11136b4ec6721181bc1fdf58be877bb82a"
      ],
      "author": {
        "name": "Kaushik Lingarkar",
        "email": "klingarkar@nvidia.com",
        "time": "Mon Sep 21 15:13:45 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Mon Sep 21 15:13:45 2026 -0700"
      },
      "message": "Merge \"Support filtering tasks by state\""
    },
    {
      "commit": "8e20d7d9ebab09f20fa5f1af3dd5a85a5dc61c42",
      "tree": "63ec9026d1fe60e59909a6e9cd9cbbed701bea61",
      "parents": [
        "81338fb1a904dbaaf927e9ca34d4becf9324b50f",
        "17b4818f7db1c54a5fe183bf7ccfcae37279f663"
      ],
      "author": {
        "name": "Luca Milanesio",
        "email": "luca.milanesio@gmail.com",
        "time": "Mon Sep 21 10:09:32 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Mon Sep 21 10:09:32 2026 -0700"
      },
      "message": "Merge \"Log at INFO when project_list cache warmer is disabled\""
    },
    {
      "commit": "17b4818f7db1c54a5fe183bf7ccfcae37279f663",
      "tree": "34b83077b9e0eb79e1540e7e64017065bee605b6",
      "parents": [
        "2d3965c2143a3df7c9ec52b67ad104b87dee46b9"
      ],
      "author": {
        "name": "Daniele Sassoli",
        "email": "danielesassoli@gmail.com",
        "time": "Mon Sep 21 16:57:47 2026 +0100"
      },
      "committer": {
        "name": "Daniele Sassoli",
        "email": "danielesassoli@gmail.com",
        "time": "Mon Sep 21 10:06:10 2026 -0700"
      },
      "message": "Log at INFO when project_list cache warmer is disabled\n\nWARN logging level should be used when something isn\u0027t correct in the\nGerrit setup, disabling the project_list cache warmer could be a\nlegitimate decision of the admin, therefore downgrade to info level.\n\nRelease-Notes: Log at INFO when project_list cache warmer is disabled\nChange-Id: Ic05c17f8873e3b225b3c0b9cf296c3d524cfc477\n"
    },
    {
      "commit": "81338fb1a904dbaaf927e9ca34d4becf9324b50f",
      "tree": "c0163f606dc22e6ad58c4f5db7a36b716bd7a64e",
      "parents": [
        "b63fdb7ec6c28d1dd929c9a83904ae5dc773cfdd",
        "8667b41cee876f0447228443583ce563b1a318cc"
      ],
      "author": {
        "name": "Adithya C",
        "email": "achakilam@nvidia.com",
        "time": "Mon Sep 21 09:54:24 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Mon Sep 21 09:54:24 2026 -0700"
      },
      "message": "Merge \"Route core LockManager callers through DynamicItem\""
    },
    {
      "commit": "8667b41cee876f0447228443583ce563b1a318cc",
      "tree": "62ea5759939dc172d127d2650258fc598b4128d1",
      "parents": [
        "46a5d3e8cf41c38f1f46eb68afd3c6172860f78a"
      ],
      "author": {
        "name": "Adithya Chakilam",
        "email": "achakilam@nvidia.com",
        "time": "Thu Sep 17 09:39:33 2026 -0500"
      },
      "committer": {
        "name": "Adithya C",
        "email": "achakilam@nvidia.com",
        "time": "Mon Sep 21 09:54:13 2026 -0700"
      },
      "message": "Route core LockManager callers through DynamicItem\n\nSome callers injected LockManager directly, so they did not recognize\nruntime overrides of the LockManager extension point. Use\nDynamicItem in all core callers so plugin overrides are handled\nconsistently.\n\nRelease-Notes: skip\nChange-Id: I158674e3be33a841a52e6a3dd02e43f477cfea44\n"
    },
    {
      "commit": "b63fdb7ec6c28d1dd929c9a83904ae5dc773cfdd",
      "tree": "70b31e465dc5d42db8c19f075d3c800fdb98599c",
      "parents": [
        "2d3965c2143a3df7c9ec52b67ad104b87dee46b9"
      ],
      "author": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Mon Sep 21 17:16:03 2026 +0200"
      },
      "committer": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Mon Sep 21 08:27:40 2026 -0700"
      },
      "message": "Update bazlets to d264399\n\nBazlets changelog:\n\n$ git log 4ff70fa..d264399 --oneline\nd264399 Add gerrit_plugin_library() for splitting a plugin into internal layers\n\nRelease-Notes: skip\nChange-Id: I196f4f1154238ac4fa3622ca2defedc273c4b3e3\n"
    },
    {
      "commit": "2d3965c2143a3df7c9ec52b67ad104b87dee46b9",
      "tree": "a42b4913c466fcb6ddfd70eaafb57ed2e53750ae",
      "parents": [
        "46032ae2bdca0f9d397020b4505307920591d4b3"
      ],
      "author": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Sun Sep 13 21:45:25 2026 +0200"
      },
      "committer": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Mon Sep 21 07:45:09 2026 -0700"
      },
      "message": "Install AuthModule in the sys injector under a WAR deployment\n\nWebAppInitializer installs AuthModule in the web injector, but\nAuthModule binds sys-level state: OAuthTokenCache and, once added, the\nOAuthTokenEncrypter DynamicItem whose itemOf is declared in\nGerritGlobalModule (sys). The ssh command injector that will host the\noauth-token commands is a sibling of web, not a child. Under a\nservlet-container WAR, an AuthModule in the web injector would be\ninvisible to the sys itemOf and to the ssh injector, silently disabling\nstored-token encryption and breaking the SSH commands.\n\nDaemon already installs AuthModule in createSysInjector; the WAR path\nwas the outlier. Move it there so the injector graphs match, before the\nencrypter and the oauth-token SSH commands land, so every later change\nworks under both deployments. The web injector loses nothing: web is a\nchild of sys and still resolves Realm and AuthBackend from the parent.\nThis complements declaring DynamicMap\u003cOAuthServiceProvider\u003e in sys;\nboth move OAuth wiring out of the web injector so it is reachable\neverywhere.\n\nFeature: Issue 560182135\nRelease-Notes: skip\nChange-Id: I745fa4b3bf534cf106925eebf4b9fd91117a77f5\n"
    },
    {
      "commit": "46032ae2bdca0f9d397020b4505307920591d4b3",
      "tree": "f55dca5d9fac5083d2a851df28b429964c781621",
      "parents": [
        "9136e8c9109c16664ec17c48e9e7a98c57173fed"
      ],
      "author": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Sun Sep 13 21:45:25 2026 +0200"
      },
      "committer": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Mon Sep 21 16:12:55 2026 +0200"
      },
      "message": "Declare OAuth service providers in the sys injector\n\nDeclare DynamicMap\u003cOAuthServiceProvider\u003e once in GerritGlobalModule\n(sys) instead of redundantly in the two mutually-exclusive web\nmodules (OAuthModule for auth.type\u003dOAUTH, OpenIdModule for OPENID).\nThe registry is then reachable from every injector, letting\nrefresh-aware consumers (GetOAuthToken, the oauth-token SSH command,\nOAuthTokenRefresher) resolve the issuing provider to refresh an\nexpired token. OAuth provider plugins contribute their\nOAuthServiceProvider @Exports from their Gerrit-Module (sys) rather\nthan their HttpModule.\n\nFeature: Issue 560182135\nRelease-Notes: skip\nChange-Id: Iaaa54eb2db2b35914305c30bc61d095196bd3026\n"
    },
    {
      "commit": "9136e8c9109c16664ec17c48e9e7a98c57173fed",
      "tree": "1e54fdf83b20b51682279b6b151d50d8e6bd6402",
      "parents": [
        "1a1fd51639e2a79aa0453700bdfade47da814697"
      ],
      "author": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Sun Sep 20 06:02:28 2026 +0200"
      },
      "committer": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Sun Sep 20 06:12:14 2026 +0200"
      },
      "message": "Document OAuthTokenEncrypter storage semantics\n\nOAuthTokenEncrypter is used by the core oauth_tokens cache to protect\npersisted OAuthToken values. Document the storage contract for\nimplementations: token, secret, and raw are secret payload fields, while\nexpiresAt and providerId remain cleartext metadata that Gerrit may\ninspect without decrypting.\n\nThis is a documentation-only follow-up to the in-tree AES-GCM encrypter\nchange; there is no behavior change.\n\nBug: Issue 561066231\nRelease-Notes: skip\nChange-Id: I741fe9c085603127089194d83098e7bb3b777a44\n"
    },
    {
      "commit": "1a1fd51639e2a79aa0453700bdfade47da814697",
      "tree": "2eb9ee555c533ae4b118393481c1b5ac87ee9deb",
      "parents": [
        "f9fc34045b5e6e3c9247a70633a7c513bd535af0"
      ],
      "author": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Sat Sep 12 14:47:45 2026 +0200"
      },
      "committer": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Sun Sep 20 06:12:02 2026 +0200"
      },
      "message": "Add OAuthTokenRefresher and the OAuth refresh extension point\n\nAdd OAuthServiceProvider.supportsRefresh()/refresh() (default: not\nsupported) and OAuthRevokedException so a provider can renew an expired\naccess token from its refresh token (RFC 6749 section 6) and signal a\nrevoked grant (invalid_grant). OAuthTokenRefresher owns the renew-on-\nread logic: read the possibly-expired token, refresh via the provider,\nwrite it back, with a per-account lock and a short backoff after a\nfailed refresh.\n\nOAuthTokenCache.hasExpiredToken() decides from the cleartext expiresAt\nwhether anything needs refreshing, so the common request decrypts\nnothing. OAuthSession.toString() reads via getEvenIfExpired to avoid\nevicting a still-refreshable token.\n\nFeature: Issue 560182135\nRelease-Notes: Add OAuthTokenRefresher and the OAuth token refresh extension point\nChange-Id: I26679a6700d9180414d2373f2637a51a8c1fe093\n"
    },
    {
      "commit": "f9fc34045b5e6e3c9247a70633a7c513bd535af0",
      "tree": "fc35efc8484fcebf9aea306a325e761805466448",
      "parents": [
        "b9007b432d28e494bdb7d1b23d7f20c8a5bb81af"
      ],
      "author": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Sat Sep 12 14:47:42 2026 +0200"
      },
      "committer": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Sat Sep 19 05:37:46 2026 -0700"
      },
      "message": "Add OAuthTokenCache.getEvenIfExpired for refresh-aware callers\n\nget() evicts an expired token and returns null, so its raw token\nresponse -- which may carry a refresh token -- becomes unreachable once\nthe access token expires. Add getEvenIfExpired(Account.Id): it decrypts\nand returns the cached entry without evicting, letting a refresh-aware\ncaller read the refresh token and renew the access token.\n\nRename the existing get() to getOrEvictIfExpired() so the evict-on-\nexpiry side effect is explicit at every call site; behavior is\nunchanged, and it is now implemented on top of getEvenIfExpired.\n\nFeature: Issue 560182135\nRelease-Notes: Add OAuthTokenCache.getEvenIfExpired() for token refresh\nChange-Id: I9bc7d617d9f9da9ea2578f3c4a7cf179f95ebaf4\n"
    },
    {
      "commit": "83b5da11136b4ec6721181bc1fdf58be877bb82a",
      "tree": "24cccc90a0948bdb63756d00e6b63998d10533ff",
      "parents": [
        "b9007b432d28e494bdb7d1b23d7f20c8a5bb81af"
      ],
      "author": {
        "name": "Kaushik Lingarkar",
        "email": "klingarkar@nvidia.com",
        "time": "Tue Sep 15 17:42:02 2026 -0700"
      },
      "committer": {
        "name": "Kaushik Lingarkar",
        "email": "klingarkar@nvidia.com",
        "time": "Fri Sep 18 15:50:17 2026 -0700"
      },
      "message": "Support filtering tasks by state\n\nAdd an option to the show-queue SSH command and to the REST endpoint\n\u0027/config/server/tasks/\u0027, to only show the tasks that are in one of\nthe provided states. It can be given multiple times to match any of\nseveral states.\n\nRelease-Notes: show-queue and the tasks REST endpoint can filter by state\nChange-Id: I1ada3d42f92c2b4c0b13d119c84a5b1958307dda\n"
    },
    {
      "commit": "b9007b432d28e494bdb7d1b23d7f20c8a5bb81af",
      "tree": "43718422eaf615c24824cec6f6ba9e3c14bec3c0",
      "parents": [
        "ada29b68d401a31a97684150f1a21cb6c1e8272c",
        "5e961e4ec20d18e892f10ceb9ca50154e3073960"
      ],
      "author": {
        "name": "Nasser Grainawi",
        "email": "nasser.grainawi@oss.qualcomm.com",
        "time": "Fri Sep 18 13:57:27 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Fri Sep 18 13:57:27 2026 -0700"
      },
      "message": "Merge \"ChangeField: remove static import\""
    },
    {
      "commit": "ada29b68d401a31a97684150f1a21cb6c1e8272c",
      "tree": "c8537f573fb19bb44e19a5a5b10ca966c96a7ee7",
      "parents": [
        "a356ee01e29a69a5c87fdc2fa6f694d316cb9845",
        "7a3fe7cdea2c2e916ea1ead09b4195c34d935b58"
      ],
      "author": {
        "name": "Sam Saccone",
        "email": "samccone@google.com",
        "time": "Fri Sep 18 13:37:01 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Fri Sep 18 13:37:01 2026 -0700"
      },
      "message": "Merge \"Include sender email with display name in change emails\""
    },
    {
      "commit": "5e961e4ec20d18e892f10ceb9ca50154e3073960",
      "tree": "4d0181a237f2774148ad53cae00c41b11ff9aacc",
      "parents": [
        "5c979db6b7cdd8189627ee89a11e1f0fa8bdb235"
      ],
      "author": {
        "name": "Nasser Grainawi",
        "email": "nasser.grainawi@oss.qualcomm.com",
        "time": "Fri Sep 18 10:32:04 2026 -0700"
      },
      "committer": {
        "name": "Nasser Grainawi",
        "email": "nasser.grainawi@oss.qualcomm.com",
        "time": "Fri Sep 18 13:34:07 2026 -0700"
      },
      "message": "ChangeField: remove static import\n\nOur style guide says to use the class name prefixed style, which is what\nall but one place in this file already did.\n\nRelease-Notes: skip\nForward-Compatible: checked\nChange-Id: Ifb5efcac7ec3117fb17dbb604623a93a36833cf1\n"
    },
    {
      "commit": "a356ee01e29a69a5c87fdc2fa6f694d316cb9845",
      "tree": "b7f3b7964c4afd0a22000bce29862be994f063b5",
      "parents": [
        "5c979db6b7cdd8189627ee89a11e1f0fa8bdb235"
      ],
      "author": {
        "name": "Becky Siegel",
        "email": "beckysiegel@google.com",
        "time": "Fri Sep 18 12:39:40 2026 -0700"
      },
      "committer": {
        "name": "Becky Siegel",
        "email": "beckysiegel@google.com",
        "time": "Fri Sep 18 12:39:40 2026 -0700"
      },
      "message": "Remove line length rules from gerrit_commit_message_review skill\n\nGerrit commit validators and the UI editor already enforce subject and\nbody line length limits deterministically, whereas LLM character\ncounting frequently produces false-positive line length warnings.\nRemove the 60-character subject limit and 72-character body wrapping\nrules from SKILL.md and explicitly instruct the reviewer not to flag\nline lengths.\n\nRelease-Notes: skip\nChange-Id: Ie40886bed02746eed81924968e4dbb716e438728"
    },
    {
      "commit": "7a3fe7cdea2c2e916ea1ead09b4195c34d935b58",
      "tree": "067b6b8210ce8c07fd7bc4b1aa9c455a16c9af3d",
      "parents": [
        "7f236d89ab447572cb9e00c4b329b153b03955a1"
      ],
      "author": {
        "name": "Sam Saccone",
        "email": "samccone@google.com",
        "time": "Fri Sep 18 17:19:28 2026 +0000"
      },
      "committer": {
        "name": "Sam Saccone",
        "email": "samccone@google.com",
        "time": "Fri Sep 18 18:28:42 2026 +0000"
      },
      "message": "Include sender email with display name in change emails\n\nPreviously, the fromName template variable in ChangeEmailImpl only\nused OutgoingEmail.getNameFor(from), displaying only the sender\u0027s\ndisplay name (e.g. \"Me has created a revert of this change.\"). A user\nwith a generic or deceptive display name could trigger change emails\nwhose body text appeared to attribute actions to the recipient or\nanother user.\n\nUpdate ChangeEmailImpl.populateEmailContent() to populate fromName\nusing OutgoingEmail.getNameEmailFor(from) so change action sentences\ndisplay \"Name \u003cemail@host.com\u003e\". Also pass attentionSetUserEmail to\nattention set Soy templates and use fromEmail/change.ownerEmail in\nNewChangeHtml.soy so self-action and owner comparisons continue to\nwork when fromName includes the sender\u0027s email address.\n\nGoogle-Bug-Id: b/152543165\nRelease-Notes: Include sender email address alongside display name in change emails\nChange-Id: I7d25b00b413c836f081b34c2e76bf39e6f3cadbe\n"
    },
    {
      "commit": "5c979db6b7cdd8189627ee89a11e1f0fa8bdb235",
      "tree": "2b9f867186c6888c2b7cb1c754912e371518569b",
      "parents": [
        "46a5d3e8cf41c38f1f46eb68afd3c6172860f78a",
        "7801ddcd6b10ac055ab5c81e86cc2364066aa49b"
      ],
      "author": {
        "name": "Adithya C",
        "email": "achakilam@nvidia.com",
        "time": "Fri Sep 18 10:09:07 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Fri Sep 18 10:09:07 2026 -0700"
      },
      "message": "Merge \"Support configuring index.directory in gerrit.config\""
    },
    {
      "commit": "46a5d3e8cf41c38f1f46eb68afd3c6172860f78a",
      "tree": "0ad8db6944af03a3c5bfb0ec272acaf85236794f",
      "parents": [
        "736546019c2fa270a20237e3f3ac508f7685e14a",
        "b98da906e0f526e67e26740dac65d38efa5d9770"
      ],
      "author": {
        "name": "Adithya C",
        "email": "achakilam@nvidia.com",
        "time": "Fri Sep 18 08:05:22 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Fri Sep 18 08:05:22 2026 -0700"
      },
      "message": "Merge \"Namespace LockManager keys to prevent collisions\""
    },
    {
      "commit": "b98da906e0f526e67e26740dac65d38efa5d9770",
      "tree": "6a2de5f9e84333dd0d590e9946aed7d144705afe",
      "parents": [
        "d157d5d5e977e903267b2d562cfd6fa9320fad88"
      ],
      "author": {
        "name": "Adithya Chakilam",
        "email": "achakilam@nvidia.com",
        "time": "Tue Sep 15 21:57:45 2026 -0500"
      },
      "committer": {
        "name": "Adithya C",
        "email": "achakilam@nvidia.com",
        "time": "Fri Sep 18 08:05:15 2026 -0700"
      },
      "message": "Namespace LockManager keys to prevent collisions\n\nInterface for LockManager took a single flat string, so two unrelated\ncallers could collide on the same lock (e.g. a project named\n\"change-cleanup\" would share a lock with the change-cleanup background\ntask).\n\nRelease-Notes: skip\nChange-Id: Iba5a10a1d1508b5599cf4d01541ce998ea2eb51d\n"
    },
    {
      "commit": "736546019c2fa270a20237e3f3ac508f7685e14a",
      "tree": "24964af7cf42d50fdf01a4180901d6bcd43bd69e",
      "parents": [
        "dc2e667e49e1e85bff0206f9b39db03be10c6ab7",
        "6aa597cf0e4a07903553b625bb7883122be68ab1"
      ],
      "author": {
        "name": "David Ostrovsky",
        "email": "david.ostrovsky@gmail.com",
        "time": "Fri Sep 18 04:41:53 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Fri Sep 18 04:41:53 2026 -0700"
      },
      "message": "Merge \"RefControlIT: Fix InvalidLink Error Prone error in Javadoc link\""
    },
    {
      "commit": "dc2e667e49e1e85bff0206f9b39db03be10c6ab7",
      "tree": "d9603bdf537c4b8e5d7723cade97ab06f2ed2281",
      "parents": [
        "0a43ead347ab5dce4dfacc5931900d32793ff5d5",
        "68dc848a4ccbf83276776fce6df9d66fb8d3bcda"
      ],
      "author": {
        "name": "Milutin Kristofic",
        "email": "milutin@google.com",
        "time": "Fri Sep 18 03:55:48 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Fri Sep 18 03:55:48 2026 -0700"
      },
      "message": "Merge \"Prevent rapid double-clicks and disallow revert on project.config\""
    },
    {
      "commit": "7801ddcd6b10ac055ab5c81e86cc2364066aa49b",
      "tree": "7f6bfb0ac3cbed57a2a5db091610644c95ed0b99",
      "parents": [
        "3cba610ae426803bb0098e3b275f5f6e40bfdf52"
      ],
      "author": {
        "name": "Adithya Chakilam",
        "email": "achakilam@nvidia.com",
        "time": "Mon Sep 14 18:33:42 2026 -0500"
      },
      "committer": {
        "name": "Adithya Chakilam",
        "email": "achakilam@nvidia.com",
        "time": "Fri Sep 18 01:55:24 2026 -0500"
      },
      "message": "Support configuring index.directory in gerrit.config\n\nAllow the index directory to be configured independently of\nsite_path via the new index.directory setting, defaulting to\n$site_path/index when unset.\n\nThis is a prerequisite for supporting multiple primary Gerrit\ninstances that share a single index: each instance keeps its own\nsite_path, but index.directory lets them all be pointed at the\nsame shared index directory\n\nRelease-Notes: Index location could now be changed via index.directory setting\nChange-Id: I0cf954f05f9679e5e35a38611fa25e7011590257\n"
    },
    {
      "commit": "0a43ead347ab5dce4dfacc5931900d32793ff5d5",
      "tree": "0426a34577492e30977eb14656961b30a7a28854",
      "parents": [
        "0c7f1ebec66c795b1a5ba334bd14e0b511efc5a7",
        "6009706db3c1d9047b7767d61915eef232f43837"
      ],
      "author": {
        "name": "Andrew Chang",
        "email": "andrewjc@google.com",
        "time": "Thu Sep 17 19:11:32 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Thu Sep 17 19:11:32 2026 -0700"
      },
      "message": "Merge \"Fix horizontal overflow of long unbroken strings in chat user-message\""
    },
    {
      "commit": "0c7f1ebec66c795b1a5ba334bd14e0b511efc5a7",
      "tree": "d8b372430d812c1fd0cf688a045ccad24eaa7cec",
      "parents": [
        "9ce2190304ccbfd3366c22f7af7ab7c48b0beaf3",
        "5d11072449fba76203752d78504b521c0a083063"
      ],
      "author": {
        "name": "David Ostrovsky",
        "email": "david.ostrovsky@gmail.com",
        "time": "Thu Sep 17 13:01:09 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Thu Sep 17 13:01:09 2026 -0700"
      },
      "message": "Merge \"Encrypt stored OAuth tokens\""
    },
    {
      "commit": "9ce2190304ccbfd3366c22f7af7ab7c48b0beaf3",
      "tree": "84fe0acc7a4acfaf0eec2e715dd5a343725f6084",
      "parents": [
        "7fda30c9c7a6cad98e68bee073093115edd499f1",
        "aa302b63af0666c62e03f66c50e5869ce95de5e5"
      ],
      "author": {
        "name": "David Ostrovsky",
        "email": "david.ostrovsky@gmail.com",
        "time": "Thu Sep 17 12:59:53 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Thu Sep 17 12:59:53 2026 -0700"
      },
      "message": "Merge \"Add generic AES-GCM/HKDF cipher in util/crypto\""
    },
    {
      "commit": "7fda30c9c7a6cad98e68bee073093115edd499f1",
      "tree": "b905fd6299b11bc93b153605fccc8d9b9573d327",
      "parents": [
        "d5a475a49fdf18998f41ecd4f97ef16f0638f7e9",
        "ca13cc03fc306b9c0d3835d1b9a37c2654fa6f97"
      ],
      "author": {
        "name": "Chris Povirk",
        "email": "cpovirk@google.com",
        "time": "Thu Sep 17 12:26:19 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Thu Sep 17 12:26:19 2026 -0700"
      },
      "message": "Merge \"Declare `equals` and `hashCode` on `NameKey` to document its contract.\""
    },
    {
      "commit": "ca13cc03fc306b9c0d3835d1b9a37c2654fa6f97",
      "tree": "7698a069a8b0eed45c39ed4ba5acd1d140aaaaaf",
      "parents": [
        "6a936877bef4eb1c7427fd38f45f6b131be376ea"
      ],
      "author": {
        "name": "Chris Povirk",
        "email": "cpovirk@google.com",
        "time": "Thu Sep 17 10:52:38 2026 -0400"
      },
      "committer": {
        "name": "Chris Povirk",
        "email": "cpovirk@google.com",
        "time": "Thu Sep 17 15:19:54 2026 -0400"
      },
      "message": "Declare `equals` and `hashCode` on `NameKey` to document its contract.\n\nThis prevents https://errorprone.info/bugpattern/TruthIncompatibleType\nerrors in `AllProjectsNameTest` and `AllUsersNameTest` on assertions\nlike `assertThat(allProjectsName).isEqualTo(allUsersName)` after\nhttps://github.com/google/error-prone/pull/6108.\n\nRelease-Notes: skip\nForward-Compatible: checked\nChange-Id: I0177567e09f64ae7d42fbdbeddc01b3ad5ca20fb\n"
    },
    {
      "commit": "5d11072449fba76203752d78504b521c0a083063",
      "tree": "ba6b98384a071f81f098eafee0efe2ebeea03bc5",
      "parents": [
        "aa302b63af0666c62e03f66c50e5869ce95de5e5"
      ],
      "author": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Sun Sep 13 22:19:21 2026 +0200"
      },
      "committer": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Thu Sep 17 21:01:41 2026 +0200"
      },
      "message": "Encrypt stored OAuth tokens\n\nThe oauth_tokens cache is core: OAuthTokenCache and its H2 persistence\nhave been part of Gerrit core since the feature was introduced, so\nencrypting the stored tokens is a core data-protection concern. Add the\nencrypter in core, not in OAuth-specific plugins.\n\nThe OAuthTokenEncrypter extension point is not new. It was defined in\nI751dd5f70d (Cache for OAuth access tokens, 2015-12-15), the change that\nadded the oauth_tokens cache; it stated that \"by default, no encryption\nis applied.\" Stored tokens have been cleartext ever since unless an\nout-of-tree plugin supplied an encrypter. This change adds the first\nin-tree implementation, so tokens are encrypted by default.\n\nWhy core, when an OAuth provider plugin is always required? A provider\nplugin implements the OAuth protocol: the authorization-code flow,\ntoken acquisition, userinfo mapping, and provider-specific validation.\nIt does not own how or where Gerrit persists the token. That is the\ncore oauth_tokens cache, whose value shape (OAuthToken: token, secret,\nraw, expiresAt, providerId) and threat model (the H2 file on disk) are\nthe same for every provider. Leaving encryption to the plugin would\nrequire every provider to reimplement AES-GCM/HKDF/AAD crypto\ncorrectly, and any provider that omitted it, including a minimal\nin-house one, would silently persist tokens in cleartext, which is\ninsecure by default. This matters more now that refresh and revocation\nare core and long-lived refresh tokens are stored. One core\nimplementation protects the cache for every provider with a single\nconfig key, and it stays the OAuthTokenEncrypter extension point, so a\nplugin may still override it (for example to use a KMS or HSM).\n\nAdd OAuthTokenAesGcmEncrypter, which encrypts those fields through the\ngeneric com.google.gerrit.util.crypto.AesGcmCipher added in the\npreceding change (AES-256-GCM with an HKDF-SHA256-derived key). This\nclass holds only the OAuth-specific policy: it binds the field name,\nexpiresAt, and providerId as GCM AAD to detect metadata tampering and\nencrypted-field swaps, and it leaves pre-existing cleartext entries —\nthose written before a key was configured — readable by returning them\nunchanged instead of attempting to decrypt them.\n\nIt is bound as DynamicItem\u003cOAuthTokenEncrypter\u003e from AuthModule when\nauth.tokenEncryptionKey holds a base64 128/192/256-bit AES key.\nAuthModule installs the binding in the sys injector, co-located with\nGerritGlobalModule\u0027s DynamicItem.itemOf, so the encrypter is reachable\nfrom the web and ssh child injectors.\n\nFor sites using auth.type \u003d OAUTH, init generates this key into\nsecure.config on new installs and on upgrade, so tokens are encrypted by\ndefault; an existing key is never overwritten.\n\nBug: Issue 561066231\nRelease-Notes: Encrypt stored OAuth tokens via auth.tokenEncryptionKey\nChange-Id: Id45487e7cedcc0a305b76d905781e6a3d61d77ff\n"
    },
    {
      "commit": "aa302b63af0666c62e03f66c50e5869ce95de5e5",
      "tree": "1e800f75f4545a88264c9dd90aefb234e2b8c048",
      "parents": [
        "d5a475a49fdf18998f41ecd4f97ef16f0638f7e9"
      ],
      "author": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Tue Sep 15 14:33:43 2026 +0200"
      },
      "committer": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Thu Sep 17 21:01:18 2026 +0200"
      },
      "message": "Add generic AES-GCM/HKDF cipher in util/crypto\n\nAdd com.google.gerrit.util.crypto.AesGcmCipher, a small\nauthenticated-encryption helper: AES-256-GCM seal/open with an\nHKDF-SHA256-derived key, a fresh 96-bit IV per value, caller-supplied\nopaque AAD, and a versioned \"gcm:v1:\" envelope. open() enforces its\nown contract, rejecting an unsealed value.\n\nThis is a leaf prerequisite for encrypting stored OAuth token fields in\nthe oauth_tokens cache. The cryptographic mechanics are not OAuth\nspecific; the OAuth encrypter owns only the token-field policy, AAD\nselection, and legacy cleartext fallback.\n\nHKDF-SHA256 derivation is handled via BouncyCastle\u0027s HKDFBytesGenerator.\nThe class sits at the bottom of the dependency graph without Gerrit-core\ndependencies.\n\nRelease-Notes: skip\nChange-Id: Iede907ceacef159ded1bf6d7534966acebd0cf3f\n"
    },
    {
      "commit": "d5a475a49fdf18998f41ecd4f97ef16f0638f7e9",
      "tree": "1249ca2a7332c3df947be6004700b34da1a8e501",
      "parents": [
        "6a936877bef4eb1c7427fd38f45f6b131be376ea",
        "bb82e3cb5f95022b3babccf7b5535264407e1afc"
      ],
      "author": {
        "name": "David Ostrovsky",
        "email": "david.ostrovsky@gmail.com",
        "time": "Thu Sep 17 10:56:21 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Thu Sep 17 10:56:21 2026 -0700"
      },
      "message": "Merge \"OAuth token: honor disabled oauth_tokens cache\""
    },
    {
      "commit": "6a936877bef4eb1c7427fd38f45f6b131be376ea",
      "tree": "a6e86ffb7df5fb179aa37a13979666309b56bb71",
      "parents": [
        "c3c43c1aec52ebc961969d59d6909576dcbc41aa",
        "1b827d28128f7ed316569fef1a24f315af6e7dc5"
      ],
      "author": {
        "name": "Paladox none",
        "email": "thomasmulhall410@yahoo.com",
        "time": "Thu Sep 17 01:05:32 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Thu Sep 17 01:05:32 2026 -0700"
      },
      "message": "Merge \"Update @material/web to 2.5.0\""
    },
    {
      "commit": "c3c43c1aec52ebc961969d59d6909576dcbc41aa",
      "tree": "bfbaf594a55518e15aa47f52a12d155745929710",
      "parents": [
        "bfbe9975a37c4f27d4056e7a2c71293d8f0a353b",
        "40f54a08438b22808978df1cd07074e66a6de38a"
      ],
      "author": {
        "name": "Yash Chaturvedi",
        "email": "yash.chaturvedi@oss.qualcomm.com",
        "time": "Wed Sep 16 22:04:13 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Wed Sep 16 22:04:13 2026 -0700"
      },
      "message": "Merge \"Add minimum initial delay to scheduled jobs\""
    },
    {
      "commit": "bfbe9975a37c4f27d4056e7a2c71293d8f0a353b",
      "tree": "2221e62774d83b36d377837efcaf02d7bf7f68b9",
      "parents": [
        "3cba610ae426803bb0098e3b275f5f6e40bfdf52",
        "862e7dcace4abe29c6792cde5124a5b85fd22b3a"
      ],
      "author": {
        "name": "Yash Chaturvedi",
        "email": "yash.chaturvedi@oss.qualcomm.com",
        "time": "Wed Sep 16 22:03:45 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Wed Sep 16 22:03:45 2026 -0700"
      },
      "message": "Merge \"Fix watched project notification change detection\""
    },
    {
      "commit": "6009706db3c1d9047b7767d61915eef232f43837",
      "tree": "a03105a3657ce8547b12211d907e4b35c0c74231",
      "parents": [
        "3cba610ae426803bb0098e3b275f5f6e40bfdf52"
      ],
      "author": {
        "name": "Andrew Chang",
        "email": "andrewjc@google.com",
        "time": "Wed Sep 16 16:15:32 2026 -0700"
      },
      "committer": {
        "name": "Andrew Chang",
        "email": "andrewjc@google.com",
        "time": "Wed Sep 16 16:15:32 2026 -0700"
      },
      "message": "Fix horizontal overflow of long unbroken strings in chat user-message\n\nAdd `overflow-wrap: break-word` to `.text-content` in `user-message` (as\nwell as `.error-details` in `gemini-message`). Previously, `white-space:\npre-wrap` only wrapped at spaces or hyphens, causing long file paths\nwithout hyphens (such as\n`src/com/android/settings/supervision/EnableSupervisionActivity.kt`) to\noverflow horizontally out of the chat panel.\n\nRelease-Notes: skip\nGoogle-Bug-Id: b/525431203\nTAG\u003dagy\nCONV\u003dec88fc69-9913-44b9-af36-cd63def43e58\nChange-Id: If28e6aef1b91d05d3c8b795b41f1b80c1418c34e"
    },
    {
      "commit": "68dc848a4ccbf83276776fce6df9d66fb8d3bcda",
      "tree": "3fe1199dba84bc6de2a7fb7a8d07fbb4e14da66f",
      "parents": [
        "3cba610ae426803bb0098e3b275f5f6e40bfdf52"
      ],
      "author": {
        "name": "Milutin Kristofic",
        "email": "milutin@google.com",
        "time": "Wed Sep 16 21:19:15 2026 +0000"
      },
      "committer": {
        "name": "Milutin Kristofic",
        "email": "milutin@google.com",
        "time": "Wed Sep 16 21:19:15 2026 +0000"
      },
      "message": "Prevent rapid double-clicks and disallow revert on project.config\n\nWhen reverting a diff delta in edit mode:\n- Keep isReverting locked throughout the applyFixSuggestion call,\n  navigation, and diff reload so that rapid double-clicks or concurrent\n  reverts are ignored until reload finishes.\n- Disallow reverting on project.config or on refs/meta/config branch\n  in isRevertAllowed() to prevent failed backend edit attempts on\n  project configuration files.\n\nRelease-Notes: skip\nChange-Id: I9c7ee799d9d8e52900eb02818395739a3982873d\n"
    },
    {
      "commit": "3cba610ae426803bb0098e3b275f5f6e40bfdf52",
      "tree": "fc5948fd197c754526632312a08f5cacb46a1a08",
      "parents": [
        "b1790029eb5ed7d0f6f06cbf31c27988759fbc52"
      ],
      "author": {
        "name": "Randy Maldonado",
        "email": "randymaldonado@google.com",
        "time": "Wed Sep 16 19:40:36 2026 +0000"
      },
      "committer": {
        "name": "Randy Maldonado",
        "email": "randymaldonado@google.com",
        "time": "Wed Sep 16 20:00:54 2026 +0000"
      },
      "message": "Fix file list column misalignment for Markdown files\n\nPrevent gr-file-list table columns (Size, Delta, and dynamic plugin\ncolumns) from shifting when rendering Markdown files.\n\n- Nest richMarkdownToggle inside the show-hide gridcell container\n  instead of adding an extra top-level flex item with role\u003d\"gridcell\".\n- Style richMarkdownToggle with absolute positioning inside show-hide\n  to preserve flexbox layout and column alignment across all file rows.\n\nRelease-Notes: Fix file list column misalignment for Markdown files\nGoogle-Bug-Id: b/562557094\nBUG\u003d562557094\nChange-Id: Ife736efbf1c321f27c96ceca11b7113b0d2e1e0d\n"
    },
    {
      "commit": "862e7dcace4abe29c6792cde5124a5b85fd22b3a",
      "tree": "da6258ed65fda617997c70c19a8e8b6f56e09d2b",
      "parents": [
        "b75dea5f95c2d1b19c5671ec4d17b9e00755037b"
      ],
      "author": {
        "name": "Yash Chaturvedi",
        "email": "yash.chaturvedi@oss.qualcomm.com",
        "time": "Wed Sep 16 20:07:07 2026 +0530"
      },
      "committer": {
        "name": "Yash Chaturvedi",
        "email": "yash.chaturvedi@oss.qualcomm.com",
        "time": "Wed Sep 16 10:12:31 2026 -0700"
      },
      "message": "Fix watched project notification change detection\n\nNotification changes for watched projects leave the Save Changes button\ndisabled. Users cannot persist those updates unless they also change\nanother field.\n\nSeparate saved project state from editable state so notification changes\nare detected correctly.\n\nRelease-Notes: skip\nBug: Issue 562128303\nChange-Id: I4375defc9780787154613b33ebf9bb56cce76d33\n"
    },
    {
      "commit": "b1790029eb5ed7d0f6f06cbf31c27988759fbc52",
      "tree": "cf055e15235d895fccb78f58315d647c903da3a5",
      "parents": [
        "a74206b61cc68d4272c1f924e9fa83f962eb17f3",
        "723caeabe3db3028652734bfbe4a06064bc141f5"
      ],
      "author": {
        "name": "Luca Milanesio",
        "email": "luca.milanesio@gmail.com",
        "time": "Wed Sep 16 10:03:21 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Wed Sep 16 10:03:21 2026 -0700"
      },
      "message": "Merge \"Remove the use of DynamicSet.contains() in AllRequestFilter\""
    },
    {
      "commit": "723caeabe3db3028652734bfbe4a06064bc141f5",
      "tree": "ff4db6068adc62778bf88abaf309983effd96eb1",
      "parents": [
        "ac200867a039b66083a3ede7000e2006fdb510d0"
      ],
      "author": {
        "name": "Luca Milanesio",
        "email": "luca.milanesio@gmail.com",
        "time": "Wed Sep 16 14:46:50 2026 +0100"
      },
      "committer": {
        "name": "Luca Milanesio",
        "email": "luca.milanesio@gmail.com",
        "time": "Wed Sep 16 09:58:59 2026 -0700"
      },
      "message": "Remove the use of DynamicSet.contains() in AllRequestFilter\n\nThe AllRequestFilter still used the DynamicSet.contains() for checking\nif the filter to process was present in the DynamicSet of the registered\nfilters.\n\nIt is unclear why that check was inserted in the first place when the\nmechanism was introduced in I095ef5172, because in no circumstances\nGerrit should serve filters that are not registered via Guice.\n\nAlso, the extra check was very expensive because it caused the full scan\nof the filter receiving the call through all the list of registered\nfilters in the DynamicSet, even if the check was always returning true.\n\nRemoving the redundant check has two positive effects:\n\n1. Remove the use of the DynamicSet.contains() method\n   which is now deprecated.\n\n2. Avoid a full scan through registered filters when\n   lazily initialising an AllRequestFilter.\n\nRelease-Notes: Speed up the AllRequestFilter processing by avoiding check against the list of registered filters every time.\nChange-Id: I7e3e32d5d505744595165a3ddf74db4e1e0db5fb\n"
    },
    {
      "commit": "a74206b61cc68d4272c1f924e9fa83f962eb17f3",
      "tree": "cdfa96ee39e7b5b6b54815b7a2af54efea6ffa9c",
      "parents": [
        "805740497fd9761879eefd62eccd5182718ad6a4",
        "ac200867a039b66083a3ede7000e2006fdb510d0"
      ],
      "author": {
        "name": "Luca Milanesio",
        "email": "luca.milanesio@gmail.com",
        "time": "Wed Sep 16 09:40:14 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Wed Sep 16 09:40:14 2026 -0700"
      },
      "message": "Merge \"Warn about the slowness of DynamicSet.contains() and flag as deprecated\""
    },
    {
      "commit": "805740497fd9761879eefd62eccd5182718ad6a4",
      "tree": "22209dd0c5d607f701915edf4da4cbaa1e8d8532",
      "parents": [
        "b75dea5f95c2d1b19c5671ec4d17b9e00755037b",
        "5fef39af36ecc260f3f8187bd0da87ea719aeb09"
      ],
      "author": {
        "name": "Milutin Kristofic",
        "email": "milutin@google.com",
        "time": "Wed Sep 16 08:38:00 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Wed Sep 16 08:38:00 2026 -0700"
      },
      "message": "Merge \"polygerrit: Add experimental Stack Diff dialog\""
    },
    {
      "commit": "1b827d28128f7ed316569fef1a24f315af6e7dc5",
      "tree": "f11ba07e019335ba759d5a2a869a0b75977ddd61",
      "parents": [
        "b75dea5f95c2d1b19c5671ec4d17b9e00755037b"
      ],
      "author": {
        "name": "paladox",
        "email": "thomasmulhall410@yahoo.com",
        "time": "Wed Sep 16 15:26:11 2026 +0100"
      },
      "committer": {
        "name": "paladox",
        "email": "thomasmulhall410@yahoo.com",
        "time": "Wed Sep 16 16:30:24 2026 +0100"
      },
      "message": "Update @material/web to 2.5.0\n\nRelease-Notes: Update @material/web to 2.5.0\nChange-Id: I7bb077ce98ebb596435692e689295661e59944fe\n"
    },
    {
      "commit": "ac200867a039b66083a3ede7000e2006fdb510d0",
      "tree": "ae5521cfbd29d00eb5cc7f73859775d8628bad65",
      "parents": [
        "b75dea5f95c2d1b19c5671ec4d17b9e00755037b"
      ],
      "author": {
        "name": "Luca Milanesio",
        "email": "luca.milanesio@gmail.com",
        "time": "Wed Sep 16 14:34:33 2026 +0100"
      },
      "committer": {
        "name": "Luca Milanesio",
        "email": "luca.milanesio@gmail.com",
        "time": "Wed Sep 16 15:09:18 2026 +0100"
      },
      "message": "Warn about the slowness of DynamicSet.contains() and flag as deprecated\n\nThe DynamicSet.contains() was introduced with I095ef5172 for the sole\npurpose of checking the double-init of AllRequestFilter.\n\nThe latest implementation of the double-init check uses a plain Set\ntherefore, the use of the DynamicSet.contains() can be deprecated and\nits users warned about the inherently slow execution time.\n\nRelease-Notes: Deprecate the use of DynamicSet.contains()\nChange-Id: I0d9f4b61064a301524a5e4f9fab5432556daf7ab\n"
    },
    {
      "commit": "40f54a08438b22808978df1cd07074e66a6de38a",
      "tree": "acd6c43aaa69f369a5220524e29bf297c99c7e3d",
      "parents": [
        "76e8c765ee60c454c7a3cf341233c021d427b024"
      ],
      "author": {
        "name": "Yash Chaturvedi",
        "email": "zeref@qti.qualcomm.com",
        "time": "Fri Sep 11 10:55:17 2026 +0530"
      },
      "committer": {
        "name": "Yash Chaturvedi",
        "email": "yash.chaturvedi@oss.qualcomm.com",
        "time": "Wed Sep 16 19:32:07 2026 +0530"
      },
      "message": "Add minimum initial delay to scheduled jobs\n\nPeriodic scheduled jobs can fire almost immediately after a server\nrestart, depending on how startTime aligns with the restart moment.\nFor heavy jobs like cache pruning this is undesirable. Right after a\nrestart the server is warming caches and reconnecting clients, and\nbackground I/O contention during that window makes recovery worse.\nThe pruneOnStartup flag covers the explicit startup prune but leaves\nthe periodic schedule unprotected.\n\nstartTime alone cannot fix this because the first execution depends on\nwall-clock time at restart, which admins do not control precisely.\nIncreasing interval pushes the first run out but reduces the cadence\nfor all subsequent runs.\n\nAdd minimumInitialDelay to ScheduleConfig. It advances the first\nexecution by whole intervals until the minimum is met, preserving the\nconfigured cadence while enforcing a post-restart quiet period.\n\nRelease-Notes: Added support for \u0027minimumInitialDelay\u0027 configuration in periodic job scheduling\nChange-Id: Ic1c5f25c86ceea9ed6af9694933ac188803e809e\n"
    },
    {
      "commit": "6aa597cf0e4a07903553b625bb7883122be68ab1",
      "tree": "f1dff1bc45fda58252c789528e33467d4ac4daad",
      "parents": [
        "1ff12a23c64f9fb474e93a3f6c5a817ef649122f"
      ],
      "author": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Wed Sep 16 14:26:02 2026 +0200"
      },
      "committer": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Wed Sep 16 14:28:46 2026 +0200"
      },
      "message": "RefControlIT: Fix InvalidLink Error Prone error in Javadoc link\n\nThe newer Error Prone version pulled in with rules_java updates reports\nInvalidLink for {@link} references that do not resolve.\n\nPermissionBackend#filter fails to resolve because the filter method\nlives inside the nested PermissionBackend.WithUser class and requires\nexplicit parameter types for signature matching. Update the reference to\nPermissionBackend.WithUser#filter(ProjectPermission, Collection).\n\nRelease-Notes: skip\nChange-Id: I2ae8ac09418fbebdaf76dc52dcf527ebdfce1282\n"
    },
    {
      "commit": "b75dea5f95c2d1b19c5671ec4d17b9e00755037b",
      "tree": "ba134bbe59322ece2e8a7595ebcd4b09a2ee4879",
      "parents": [
        "596c5cd9d06b357f44aafac9e46b78cb525e8889"
      ],
      "author": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Sun Aug 16 13:42:08 2026 +0200"
      },
      "committer": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Wed Sep 16 04:56:19 2026 -0700"
      },
      "message": "Fix InvalidLink Error Prone errors in Javadoc references\n\nThe newer Error Prone pulled in with rules_java 9.8.0 reports\nInvalidLink for {@link} references that do not resolve. Render the\nunresolvable references as {@code} instead:\n\n  - FieldBundle: SearchSpec#name() (SearchSpec is the generic inner\n    type IndexedField\u003cI, T\u003e.SearchSpec, so the link does not resolve)\n  - ChangeUpdateTest: ChangeUpdate#isActiveOnChange\n\nRelease-Notes: skip\nChange-Id: I2923c54d834fa6e69b70fe84c511c58916826e00\n"
    },
    {
      "commit": "596c5cd9d06b357f44aafac9e46b78cb525e8889",
      "tree": "9d565243c9a05ce01757cad729b98a769b51b181",
      "parents": [
        "5e194bb2df19c6a26ff7625e183102f5d9787820"
      ],
      "author": {
        "name": "Luca Milanesio",
        "email": "luca.milanesio@gmail.com",
        "time": "Tue Sep 15 17:54:02 2026 +0100"
      },
      "committer": {
        "name": "Luca Milanesio",
        "email": "luca.milanesio@gmail.com",
        "time": "Wed Sep 16 00:57:10 2026 -0700"
      },
      "message": "Optimise AllRequestFilter scanning for initialised filters\n\nEvery time a request went through the AllRequestFilter, it was checking\nfor lazy initialisation, which was implemented as a full scan for all\ninitialised filters and checking for object reference equality.\n\nThe full scanning is expensive, and its costs grow as the number of\nAllRequestFilters registered. It is unclear why, in the initial\nimplementation on [1], the check for the existence of a filter was\nimplemented as object reference equality rather than simple equality.\n\nThe full scan can be totally avoided by using a regular Set\u003c\u003e which will\nuse hashCode/equals methods and speed up the whole filtering pipeline.\n\nNOTE: This introduces a minor, unsupported edge case: if two distinct\nfilters implement custom hashCode() and equals() methods that evaluate\nthem as equal, they can no longer both be initialized and used\nsimultaneously in Gerrit.\n\n[1]\nhttps://gerrit-review.googlesource.com/c/gerrit/+/70072/8/gerrit-extension-api/src/main/java/com/google/gerrit/extensions/registration/DynamicSet.java\n\nRelease-Notes: Speed up the processing of the AllRequestFilter pipeline by avoiding a full scan of filters per request. Different filters with same equality will not be supported anymore.\nChange-Id: I98304c61265e6e08b36e768e8fb49ff2ba35fb0c\n"
    },
    {
      "commit": "5e194bb2df19c6a26ff7625e183102f5d9787820",
      "tree": "c42e3b28374da94b8370be47b7457c3e75ece4a9",
      "parents": [
        "4b4d32438391be86dd4baeb049a1b825f11fe5c5",
        "dc77def1e3d846d65d44cdc98baad97306446cd7"
      ],
      "author": {
        "name": "Kaushik Lingarkar",
        "email": "klingarkar@nvidia.com",
        "time": "Wed Sep 16 00:37:54 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Wed Sep 16 00:37:54 2026 -0700"
      },
      "message": "Merge \"Make the Lucene lock factory configurable\""
    },
    {
      "commit": "4b4d32438391be86dd4baeb049a1b825f11fe5c5",
      "tree": "79c3986ce2aa7dda327604100c2f79bd7858ba08",
      "parents": [
        "c16d7c81d51c6d55f21d542d594bc6ffef7958f8",
        "4b9c82b0886655ec71ffa05b18e0521297eb3312"
      ],
      "author": {
        "name": "David Ostrovsky",
        "email": "david.ostrovsky@gmail.com",
        "time": "Tue Sep 15 23:54:57 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Tue Sep 15 23:54:57 2026 -0700"
      },
      "message": "Merge \"Bazel: Use non-stamped JGit for build and test targets\""
    },
    {
      "commit": "4b9c82b0886655ec71ffa05b18e0521297eb3312",
      "tree": "c00a5d1f9163ad2bb8f350bf3e9f9ed6f0166e39",
      "parents": [
        "1ff12a23c64f9fb474e93a3f6c5a817ef649122f"
      ],
      "author": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Mon Sep 14 19:55:35 2026 +0200"
      },
      "committer": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Wed Sep 16 08:36:17 2026 +0200"
      },
      "message": "Bazel: Use non-stamped JGit for build and test targets\n\nJGit\u0027s default Bazel target is now non-stamped, so ordinary Gerrit\ncompile and test actions no longer need the workspace-status stamped\nJGit jar.\n\nUpdate the JGit submodule to the change that makes\n//org.eclipse.jgit:jgit non-stamped by default and adds the explicit\n//org.eclipse.jgit:jgit-stamped packaging target.\n\nUpdate Gitiles to the matching change that uses stamped JGit only for\ngitiles.war packaging.\n\nTeach Gerrit\u0027s local pkg_war rule to accept additional libraries and\nper-call jar exclusions. Gerrit\u0027s WAR targets use those generic hooks to\npackage //org.eclipse.jgit:jgit-stamped and exclude the non-stamped core\nJGit jar, so gerrit.war, headless.war, release.war, and withdocs.war\nstill contain the Implementation-Version manifest entry without pulling\nthe stamped jar into normal build and test targets.\n\nThis has one visible WAR inventory side effect: the WAR now lists\nlibinsecure_cipher_factory. This is not a new external dependency and\nnot a second JGit copy. It is JGit\u0027s package-private\nInsecureCipherFactory class, compiled as a separate Bazel java_library\nonly so JGit can disable Error Prone\u0027s InsecureCryptoUsage check for\nthat file.\n\nBefore this change, the stamped JGit genrule hid that helper from\nGerrit\u0027s WAR packaging. Once //org.eclipse.jgit:jgit becomes a normal\nJava target, Bazel correctly exposes the helper as a transitive runtime\njar. The WAR still contains exactly one core JGit jar,\nWEB-INF/lib/jgit.jar.\n\nA considered alternative was to fold InsecureCipherFactory into the\nstamped JGit jar and exclude the helper jar at the Gerrit WAR boundary.\nThis change keeps the JGit target graph explicit instead: JGit exposes\nthe helper as the runtime dependency it already is, and Gerrit\u0027s WAR\ninventory records it honestly.\n\nRepin external_deps.lock.json after the JGit submodule update.\n\nFeature: Issue 561838827\nRelease-Notes: skip\nChange-Id: I8f94b140e053d44b2f6de777a361a3b16aa2872c\n"
    },
    {
      "commit": "c16d7c81d51c6d55f21d542d594bc6ffef7958f8",
      "tree": "77333161f734141d61ec872a61d9abad6fe4fbdf",
      "parents": [
        "d157d5d5e977e903267b2d562cfd6fa9320fad88",
        "66da14fccce8f034e10f5ab8f9e6b0b59fa15326"
      ],
      "author": {
        "name": "Ajay Gupta",
        "email": "ajagup@qti.qualcomm.com",
        "time": "Tue Sep 15 23:14:50 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Tue Sep 15 23:14:50 2026 -0700"
      },
      "message": "Merge \"Preserve datasource-only queries during rewrite\""
    },
    {
      "commit": "66da14fccce8f034e10f5ab8f9e6b0b59fa15326",
      "tree": "5d9f4a665fb999de9be39d2e7742e0557104eef2",
      "parents": [
        "b02f339fdf585efe39b27a69f938a7a0886045a6"
      ],
      "author": {
        "name": "Ajay Gupta",
        "email": "ajagup@qti.qualcomm.com",
        "time": "Sun Sep 13 08:33:31 2026 +0530"
      },
      "committer": {
        "name": "Ajay Gupta",
        "email": "ajagup@qti.qualcomm.com",
        "time": "Tue Sep 15 22:55:42 2026 -0700"
      },
      "message": "Preserve datasource-only queries during rewrite\n\nSome queries contain only datasource predicates but still require a\nnested expression to be rewritten. Previously, Gerrit added a match-all\nindex query for these expressions.\n\nThe match-all query could then become the query source, causing\ndatasource predicates to run as post-filters rather than fetching their\nmatching changes directly.\n\nAvoid adding the index query when no indexed predicates are present.\n\nRelease-Notes: Prevent unnecessary full-index scans for datasource-only queries with boolean subexpressions\nChange-Id: I06b62e0f4b4e8fb16a82cb7db2d9c64fd0dbafd0\n"
    },
    {
      "commit": "d157d5d5e977e903267b2d562cfd6fa9320fad88",
      "tree": "9ec87a3095f54e2c35de7981cfe2ea250696e379",
      "parents": [
        "efc4d3b8e53d13fa1d4d3230e8e3af6443ec06fd",
        "e884aca6d59746887f4fb8ccff53151c8de321e8"
      ],
      "author": {
        "name": "Adithya C",
        "email": "achakilam@nvidia.com",
        "time": "Tue Sep 15 19:41:43 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Tue Sep 15 19:41:43 2026 -0700"
      },
      "message": "Merge \"Batch H2 custom lock acquisitions across in-process callers\""
    },
    {
      "commit": "e884aca6d59746887f4fb8ccff53151c8de321e8",
      "tree": "5f94d464a55995ec1b7a9d142a5afadb7f36f782",
      "parents": [
        "a6977b0d3a82b67c05458163e4691071644f4ef2"
      ],
      "author": {
        "name": "Adithya Chakilam",
        "email": "achakilam@nvidia.com",
        "time": "Thu Sep 10 15:19:19 2026 -0500"
      },
      "committer": {
        "name": "Adithya C",
        "email": "achakilam@nvidia.com",
        "time": "Tue Sep 15 19:41:19 2026 -0700"
      },
      "message": "Batch H2 custom lock acquisitions across in-process callers\n\nUp to accountPatchReviewDb.h2LockBatchSize in-process callers can now\nshare one held lock instead of each acquiring/releasing separately. Each\nstill runs its own connection and commits independently; the lock\nreleases once all admitted callers are done.\n\nThis also restores the missing fairness guarantee by preserving caller\narrival order. Waiting threads are admitted to a held lock in the same\norder they attempted to acquire it.\n\nPerformance testing in a shared-disk MP setup showed significant\nthroughput improvements. With 10 concurrent writes, performance\nincreased from ~1,680 to ~2,500 operations per minute. With 32\nconcurrent writes, throughput more than doubled—from ~1,700 to 3,600\noperations per minute. Improved fairness also eliminated failed\nrequests, which occurred intermittently with the previous\nimplementation.\n\nRelease-Notes: skip\nChange-Id: I9bdb5aaae20f419ac1a003deadb65569a0d8eb90\n"
    },
    {
      "commit": "5fef39af36ecc260f3f8187bd0da87ea719aeb09",
      "tree": "0f33e526eb865bfc44d99692bfdcff4b60538bf8",
      "parents": [
        "1ff12a23c64f9fb474e93a3f6c5a817ef649122f"
      ],
      "author": {
        "name": "Milutin Kristofic",
        "email": "milutin@google.com",
        "time": "Tue Jun 09 13:52:48 2026 +0200"
      },
      "committer": {
        "name": "Milutin Kristofic",
        "email": "milutin@google.com",
        "time": "Tue Sep 15 20:33:52 2026 +0000"
      },
      "message": "polygerrit: Add experimental Stack Diff dialog\n\nNavigating changes across a multi-commit relation chain currently\nrequires viewing each individual change\u0027s diff in isolation. To inspect\ncumulative modifications across the entire stack, users need a unified\ncomparison against the base parent commit.\n\nThis change introduces an experimental Stack Diff tool accessible from\nthe Relation Chain section:\n- Add STACK_DIFF (\u0027UiFeature__stack_diff\u0027) feature flag.\n- Add REST client methods for querying project-level commit and file\n  diffs.\n- Create gr-stack-diff-dialog component displaying a files list with\n  line stats and diff rendering.\n- Exclude /COMMIT_MSG files from stack-level comparison.\n- Align the \"Diff\" trigger button inline next to the section title.\n\nGoogle-Bug-Id: b/407721794\nRelease-Notes: Add experimental stack diff dialog next to relation chain list.\nChange-Id: I7b77cce8446bc1b207d5a4b273397e8146b4b183\n"
    },
    {
      "commit": "efc4d3b8e53d13fa1d4d3230e8e3af6443ec06fd",
      "tree": "3a7982daaab31f8be1e409dd345e25f167af0d2e",
      "parents": [
        "38895f7d41f373afe44f04da61474849610519eb",
        "f1d97df19be964622f5315f01defad21cd81c4d7"
      ],
      "author": {
        "name": "Laura Hamelin-Owens",
        "email": "haowl@google.com",
        "time": "Tue Sep 15 10:25:44 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Tue Sep 15 10:25:44 2026 -0700"
      },
      "message": "Merge \"Allow configuring default readers and users groups in AllProjectsCreator\""
    },
    {
      "commit": "38895f7d41f373afe44f04da61474849610519eb",
      "tree": "b3e68772c28815c025a4a558d667b964f02866a9",
      "parents": [
        "5ac4228d2b9f65bd9301fc4bd46c58127fad9466"
      ],
      "author": {
        "name": "Luca Milanesio",
        "email": "luca.milanesio@gmail.com",
        "time": "Sun Sep 13 08:09:21 2026 +0100"
      },
      "committer": {
        "name": "Luca Milanesio",
        "email": "luca.milanesio@gmail.com",
        "time": "Tue Sep 15 17:45:38 2026 +0100"
      },
      "message": "Remove DynamicSet\u003c\u003e in AllRequestFilter for double-init protection\n\nAllRequestFilter has a mechanism for allowing dynamic registration\nand initialisation of plugins filters at runtime, by tracking a\nset of all filters already initialised.\n\nPreviously the tracking was performed using a local DynamicSet\u003c\u003e\nwhich is totally overkill for the simple use of tracking if\nan filter has been seen already or not.\n\nReplace the DynamicSet\u003c\u003e with a simple concurrent Set\u003c\u003e which\nachieves the same goal in a simpler way.\n\nRelease-Notes: skip\nChange-Id: I92810da5f007063a34bbe42508b2a3ee4da90a37\n"
    },
    {
      "commit": "5ac4228d2b9f65bd9301fc4bd46c58127fad9466",
      "tree": "c783ff3908d042bea52517c4046f71b194ff737d",
      "parents": [
        "7fb98c7cf72759930d68ff54cab8145d826c6877"
      ],
      "author": {
        "name": "Luca Milanesio",
        "email": "luca.milanesio@gmail.com",
        "time": "Sat Sep 12 11:10:21 2026 +0100"
      },
      "committer": {
        "name": "Luca Milanesio",
        "email": "luca.milanesio@gmail.com",
        "time": "Tue Sep 15 07:15:02 2026 -0700"
      },
      "message": "Simplify the AllRequestFilter cleanup using beforeStopPlugin()\n\nFollowing the introduction of the beforeStopPlugin() method in\nStopPluginListener, the cleanup of the filters can be simply performed\nby looking at all the filters registered by the plugin that is about to\nbe unloaded and destroyed. The initializedFilters may grow indefinitely\nfollowing a sequence of reloads of the same plugin, therefore keep\na reference to the registration handles for removing them upon\nplugin shutdown.\n\nNOTE: The complexity introduced by the use of DynamicSet\u003c\u003e for the\ninitializedFilters can be removed as a follow-up change.\n\nAlso, make the StopPluginListener backwards compatible by adding a\ndefault block to the onStopPlugin() method.\n\nEventually, the onStopPlugin() could be deprecated and removed if nobody\nwould see a valid use for it in the next releases.\n\nThe AllRequestFilterFilterProxyTest was assuming the actual\nimplementation details of the filters shutdown, therefore it needed to\nbe adapted for making it more agnostic to it.\n\nRelease-Notes: skip\nChange-Id: Id8d4254060acdd77d04d9ec23b8250894be49d5d\n"
    },
    {
      "commit": "7fb98c7cf72759930d68ff54cab8145d826c6877",
      "tree": "0d3b5a2d7f69b5f4eb3574a2c80bb64865a44e5b",
      "parents": [
        "2a81147aa9adb4b7d3aad5f09c1252665fdba577",
        "e632cffcee74b17bcaeba38655a03049adba1f79"
      ],
      "author": {
        "name": "Luca Milanesio",
        "email": "luca.milanesio@gmail.com",
        "time": "Tue Sep 15 06:45:27 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Tue Sep 15 06:45:27 2026 -0700"
      },
      "message": "Merge \"Invoke StopPluginListener.beforeStopPlugin() before the plugin unload\""
    },
    {
      "commit": "e632cffcee74b17bcaeba38655a03049adba1f79",
      "tree": "17e6a1e806a11f5cd79c07c79a4c1117c1f59bb0",
      "parents": [
        "3f3ec150d6a1e72d0bbb9a9b7f0788d49e12d633"
      ],
      "author": {
        "name": "Luca Milanesio",
        "email": "luca.milanesio@gmail.com",
        "time": "Fri Sep 11 21:03:45 2026 +0100"
      },
      "committer": {
        "name": "Luca Milanesio",
        "email": "luca.milanesio@gmail.com",
        "time": "Tue Sep 15 06:03:40 2026 -0700"
      },
      "message": "Invoke StopPluginListener.beforeStopPlugin() before the plugin unload\n\nThe StopPluginListener did not have a way to access the context of the\nplugin being stopped because all its Guice context was already destroyed\nat the time of the call of onStopPlugin(), causing the inability to\naccess any of the plugin\u0027s resources.\n\nIntroduce a new method beforeStop() to the StopPluginListener so that\nlisteners can have the right context for an orderly shutdown.\n\nPreviously, the listener was pretty much useless because the plugin\nobject passed to it was an empty box, without the ability to investigate\nits resources and performing any necessary cleanup.\n\nBy accessing the plugin\u0027s Guice environment just before the final stop\nand unload of the plugin, the listener can now effectively investigate\nwhat was the status of the plugin that is being stopped.\n\nRelease-Notes: Introduce StopPluginListener.beforeStopPlugin() method which is called immediately before the unload of the plugin, when the PluginGuiceEnvironment is still accessible and the plugin\u0027s resources still bound.\nChange-Id: Ic32d14f600a396f6a0517c739d3c7b0c37e3a2f9\n"
    },
    {
      "commit": "2a81147aa9adb4b7d3aad5f09c1252665fdba577",
      "tree": "eb187b14b15724316f05d65764ec7683ced8c44e",
      "parents": [
        "1ff12a23c64f9fb474e93a3f6c5a817ef649122f",
        "3f3ec150d6a1e72d0bbb9a9b7f0788d49e12d633"
      ],
      "author": {
        "name": "Luca Milanesio",
        "email": "luca.milanesio@gmail.com",
        "time": "Tue Sep 15 06:00:13 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Tue Sep 15 06:00:13 2026 -0700"
      },
      "message": "Merge \"Add integration test for Start/StopPluginListener\""
    },
    {
      "commit": "bb82e3cb5f95022b3babccf7b5535264407e1afc",
      "tree": "4ddb22b74f729bcc2c68fa2a93ab46b662e705f2",
      "parents": [
        "1ff12a23c64f9fb474e93a3f6c5a817ef649122f"
      ],
      "author": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Mon Sep 14 10:45:26 2026 +0200"
      },
      "committer": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Tue Sep 15 08:18:10 2026 +0200"
      },
      "message": "OAuth token: honor disabled oauth_tokens cache\n\nTreat cache.oauth_tokens.memoryLimit \u003d 0 as disabling OAuth token\nstorage. OAuthSession still hands the token to OAuthTokenCache, but the\ncache drops it instead of allowing a persistent H2 cache to write it\nwhen diskLimit remains positive.\n\nReturn 409 Conflict from GET /accounts/{id}/oauthtoken when token\nstorage is disabled, preserving 404 for the normal \"no token for this\naccount\" case.\n\nDocument the oauth_tokens cache, including the memory-only workaround\nwith cache.oauth_tokens.diskLimit \u003d 0 and the full disablement mode.\n\nBug: Issue 561066231\nRelease-Notes: Document and handle disabling the OAuth token cache\nChange-Id: I4d11225dd83070477a3b24e8cfed343fe514a9c8\n"
    },
    {
      "commit": "f1d97df19be964622f5315f01defad21cd81c4d7",
      "tree": "b346bc567c3ee410838b08c0bb9ed0b1167f8bb3",
      "parents": [
        "e96ad21b5878eec0c53182459d7cb4b9451a2bd3"
      ],
      "author": {
        "name": "Josh Brown",
        "email": "sjoshbrown@google.com",
        "time": "Thu Aug 20 15:02:19 2026 -0700"
      },
      "committer": {
        "name": "Josh Brown",
        "email": "sjoshbrown@google.com",
        "time": "Mon Sep 14 11:45:34 2026 -0700"
      },
      "message": "Allow configuring default readers and users groups in AllProjectsCreator\n\nAllow callers of AllProjectsCreator to supply custom GroupReference\ndefinitions for the default readers and default users groups when\ncreating All-Projects during site initialization.\n\nSpecifically:\n- Add optional `defaultReadersGroup()` and `defaultUsersGroup()` to\n  AllProjectsInput.\n- In AllProjectsCreator, use the configured default reader and user\n  groups from AllProjectsInput if present, falling back to the\n  systemGroupBackend anonymous and registered groups.\n- Add helper methods in AllProjectsCreatorTestUtil and unit tests in\n  AllProjectsCreatorTest verifying custom groups and fallback behavior.\n\nBug: Google b/454122021\nRelease-Notes: Allow custom default groups during All-Projects creation\nChange-Id: I24276ee47c953b0a98b094e8a47137a798d7a5f3\n"
    },
    {
      "commit": "1ff12a23c64f9fb474e93a3f6c5a817ef649122f",
      "tree": "7acf88e43738b42be3032d520ed2c7c57d20057d",
      "parents": [
        "8003c646c45ed53f45282695a5c6886a837cf053",
        "fe06138df4f6f0e0f46ba9bf558269bbcaf160b7"
      ],
      "author": {
        "name": "James Hawkins",
        "email": "jhawkins@google.com",
        "time": "Mon Sep 14 09:02:30 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Mon Sep 14 09:02:30 2026 -0700"
      },
      "message": "Merge \"ReceiveCommits: Support \u0027:silent\u0027 for reviewer and CC options\""
    },
    {
      "commit": "8003c646c45ed53f45282695a5c6886a837cf053",
      "tree": "1e3fb29459457244a332700e3492dbb33ac4f4f3",
      "parents": [
        "b482999404021ce0f015be7a8fc9bbbbb8790e7f",
        "5ca309c6dae31fd3b3ab434427c72765d1d8bdcd"
      ],
      "author": {
        "name": "James Hawkins",
        "email": "jhawkins@google.com",
        "time": "Mon Sep 14 08:59:00 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Mon Sep 14 08:59:00 2026 -0700"
      },
      "message": "Merge \"[server] Disable rename detection in FileCountValidator\""
    },
    {
      "commit": "b482999404021ce0f015be7a8fc9bbbbb8790e7f",
      "tree": "5c2d9333aba713062f9e2deca407690bb5353da1",
      "parents": [
        "a2432805cea3e45d2bca9b968c7a7765f24fe7b9",
        "cedd8da719edbde10fc9a1d517e5fb7fce6a4e92"
      ],
      "author": {
        "name": "Hitesh Chaudhari",
        "email": "hitesh.chaudhari@sap.com",
        "time": "Mon Sep 14 07:21:51 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Mon Sep 14 07:21:51 2026 -0700"
      },
      "message": "Merge \"Add submit-requirement-template for Submit requirement creation.\""
    },
    {
      "commit": "a2432805cea3e45d2bca9b968c7a7765f24fe7b9",
      "tree": "3bef33db7d4e9037f7d50bb965f592321595295d",
      "parents": [
        "b02f339fdf585efe39b27a69f938a7a0886045a6",
        "4a9c86199ab6339fa6f19ea0e71b939c41479c40"
      ],
      "author": {
        "name": "Hitesh Chaudhari",
        "email": "hitesh.chaudhari@sap.com",
        "time": "Mon Sep 14 05:28:41 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Mon Sep 14 05:28:41 2026 -0700"
      },
      "message": "Merge \"Add metric for Submit Requirement evaluation latency\""
    },
    {
      "commit": "4a9c86199ab6339fa6f19ea0e71b939c41479c40",
      "tree": "a48fe356a466777a2559a5dbeb8551bb5d2ed5c5",
      "parents": [
        "57d3dc2622beae463b2327b6ba8906ad747013b1"
      ],
      "author": {
        "name": "Hitesh Chaudhari",
        "email": "hitesh.chaudhari@sap.com",
        "time": "Thu Sep 10 14:55:50 2026 +0200"
      },
      "committer": {
        "name": "Hitesh Chaudhari",
        "email": "hitesh.chaudhari@sap.com",
        "time": "Mon Sep 14 13:46:53 2026 +0200"
      },
      "message": "Add metric for Submit Requirement evaluation latency\n\nFor example:\n```\n{\n  \"description\": \"Latency for the submit requirement evaluator in SubmitRequirementsEvaluatorImpl\",\n  \"unit\": \"milliseconds\",\n  \"cumulative\": true,\n  \"count\": 8,\n  \"rate_1m\": 0.0016789046614529425,\n  \"rate_5m\": 0.011116449186324146,\n  \"rate_15m\": 0.006640164097612964,\n  \"p50\": 0.785541,\n  \"p75\": 0.9905,\n  \"p95\": 8.147584,\n  \"p98\": 8.147584,\n  \"p99\": 8.147584,\n  \"p99_9\": 8.147584,\n  \"min\": 0.223084,\n  \"max\": 8.147584,\n  \"std_dev\": 2.4863356362481737\n}\n```\n\nRelease-Notes: Add metric for Submit Requirement evaluation latency\nChange-Id: I68f9abcb55318df0ac3e933330c39ec5c7049209\n"
    },
    {
      "commit": "3f3ec150d6a1e72d0bbb9a9b7f0788d49e12d633",
      "tree": "0af1a712469d085b5f4e48acb736e00b8506690c",
      "parents": [
        "dc19b7af9aa1b2803715aed4ce530a324231f1a6"
      ],
      "author": {
        "name": "Luca Milanesio",
        "email": "luca.milanesio@gmail.com",
        "time": "Fri Sep 11 23:51:37 2026 +0100"
      },
      "committer": {
        "name": "Luca Milanesio",
        "email": "luca.milanesio@gmail.com",
        "time": "Mon Sep 14 03:54:17 2026 -0700"
      },
      "message": "Add integration test for Start/StopPluginListener\n\nVerify that Start/StopPluginListener is actually invoked upon plugin\nloading and unloading end-to-end with a proper integration test.\n\nPrevious test coverage heavily used mocks, which was fine for component\nverification, but did not give peace of mind that the whole\nfunctionality worked when used in conjunction with the plugin loader.\n\nRelease-Notes: skip\nChange-Id: Id69e21371a0131ad856540968e2f847f8032885f\n"
    },
    {
      "commit": "5ca309c6dae31fd3b3ab434427c72765d1d8bdcd",
      "tree": "e42b8e72e4abc574c2bc5394b8d201ff9b11c6f7",
      "parents": [
        "b02f339fdf585efe39b27a69f938a7a0886045a6"
      ],
      "author": {
        "name": "James Hawkins",
        "email": "jhawkins@google.com",
        "time": "Sat Sep 12 16:55:05 2026 +0000"
      },
      "committer": {
        "name": "James Hawkins",
        "email": "jhawkins@google.com",
        "time": "Sat Sep 12 17:31:00 2026 +0000"
      },
      "message": "[server] Disable rename detection in FileCountValidator\n\nEmpirical benchmark on 1,229-file commit (chromium/src commit ba50b5fc16):\n- With rename detection (enableRenameDetection\u003dtrue):    212.40 ms\n- Without rename detection (enableRenameDetection\u003dfalse): 51.30 ms\n- Validation latency saved:                             -161.11 ms (-75.8%, 4.1x faster)\n\nIn 2021 (commit 429c91b6d49), rename detection in FileCountValidator was\nexplicitly disabled because detecting renames requires reading file contents\nand computing pairwise similarity, which is a significant performance\nbottleneck when pushing changes with many files (e.g. library rolls with\nhundreds or thousands of deleted and added files).\n\nIn commit 69c194d92bcf (Sept 2023), FileCountValidator was migrated to\nDiffOperations to compare against auto-merge for merge commits, which\nre-introduced rename detection via default options.\n\nThis change sets `enableRenameDetection\u003dfalse`, eliminating the expensive\nO(N * M) pairwise similarity computations during pre-receive validation.\nIn addition, this aligns the pre-receive cache key with ChangeData\u0027s\ncurrentFilePaths() lookup (which also disables rename detection).\n\nIn countChangedFiles(), the vestigial Patch.isMagic() stream filter is\nalso removed, as loadModifiedFilesAgainstParentIfNecessary() operates\ndirectly on Git tree walks and never contains synthetic magic files,\neliminating intermediate stream and list heap allocation.\n\nNote that without rename detection, a file rename counts as two changed\nfiles (1 deletion + 1 addition) against change.maxFiles.\n\nRelease-Notes: Disable rename detection in FileCountValidator; renaming a file now counts as two changed files (1 deletion + 1 addition) against change.maxFiles.\nBUG\u003d558718422\nTEST\u003dbazel test //javatests/com/google/gerrit/acceptance/server/git/receive:receive\nChange-Id: Ic691ccdb30b43fd2c0779ce5dc527cbdbae450a3\n"
    },
    {
      "commit": "b02f339fdf585efe39b27a69f938a7a0886045a6",
      "tree": "9adc04b1e0d3af6f7b0bcc0d806ec575c11664d2",
      "parents": [
        "dc19b7af9aa1b2803715aed4ce530a324231f1a6",
        "e3985c09bd335845645084af57016e8555131744"
      ],
      "author": {
        "name": "David Ostrovsky",
        "email": "david.ostrovsky@gmail.com",
        "time": "Sat Sep 12 01:29:25 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Sat Sep 12 01:29:25 2026 -0700"
      },
      "message": "Merge \"Update h2 to 2.5.250\""
    },
    {
      "commit": "dc19b7af9aa1b2803715aed4ce530a324231f1a6",
      "tree": "c31dd1482eeb6ed82db7b49eca9de4cdc89b095f",
      "parents": [
        "76e8c765ee60c454c7a3cf341233c021d427b024",
        "1579779e1973c1a04d702bdd2125b27721f5bcf6"
      ],
      "author": {
        "name": "James Hawkins",
        "email": "jhawkins@google.com",
        "time": "Fri Sep 11 09:54:25 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Fri Sep 11 09:54:25 2026 -0700"
      },
      "message": "Merge \"[server] Preserve AccessPath and PropertyMap in IdentifiedUser.materializedCopy()\""
    },
    {
      "commit": "76e8c765ee60c454c7a3cf341233c021d427b024",
      "tree": "9ac31293192b4baec8c604eb31cdb3fc44b7b7a4",
      "parents": [
        "57d3dc2622beae463b2327b6ba8906ad747013b1",
        "a6977b0d3a82b67c05458163e4691071644f4ef2"
      ],
      "author": {
        "name": "Adithya C",
        "email": "achakilam@nvidia.com",
        "time": "Thu Sep 10 12:38:12 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Thu Sep 10 12:38:12 2026 -0700"
      },
      "message": "Merge \"Use java.util.concurrent.locks.Lock for custom H2 locking\""
    },
    {
      "commit": "a6977b0d3a82b67c05458163e4691071644f4ef2",
      "tree": "bf2e4deacf0f85e77d7c1c81677e71d260f153c6",
      "parents": [
        "95ef49b86dc410ab08f8654c7fdcfc0886ffd195"
      ],
      "author": {
        "name": "Adithya Chakilam",
        "email": "achakilam@nvidia.com",
        "time": "Thu Sep 03 16:36:06 2026 -0500"
      },
      "committer": {
        "name": "Adithya Chakilam",
        "email": "achakilam@nvidia.com",
        "time": "Thu Sep 10 14:20:06 2026 -0500"
      },
      "message": "Use java.util.concurrent.locks.Lock for custom H2 locking\n\nThe custom H2 lock types previously returned a plain Runnable as an\nunlock handle, with H2CustomLockAccountPatchReviewStore owning a\nsingle shared retry/backoff loop on top of it. That loop didn\u0027t fit\nwell: it forced every lock type through the same retry policy even\nthough only the jgit-style lock actually needs one, and a bare\nRunnable doesn\u0027t say anything about the acquire/release contract it\u0027s\npart of.\n\nRelease-Notes: skip\nChange-Id: Ida40b184f842d6a8fa28a603b9ed0e2c5df3326f\n"
    },
    {
      "commit": "dc77def1e3d846d65d44cdc98baad97306446cd7",
      "tree": "f2f1f73aacb57239d3e214375683356cffce2947",
      "parents": [
        "57d3dc2622beae463b2327b6ba8906ad747013b1"
      ],
      "author": {
        "name": "Kaushik Lingarkar",
        "email": "klingarkar@nvidia.com",
        "time": "Wed Sep 09 11:53:08 2026 -0700"
      },
      "committer": {
        "name": "Kaushik Lingarkar",
        "email": "klingarkar@nvidia.com",
        "time": "Thu Sep 10 09:53:04 2026 -0700"
      },
      "message": "Make the Lucene lock factory configurable\n\nGerrit opens its on-disk Lucene indexes with FSDirectory.open(Path),\nwhich implicitly uses NativeFSLockFactory. OS-level file locks are\nunreliable on some filesystems, notably NFS, for which Lucene\nrecommends SimpleFSLockFactory since it only relies on the atomicity\nof file creation.\n\nAdd an index.lockFactory option to choose between the two. It defaults\nto NATIVE, so behavior is unchanged for existing sites.\n\nRelease-Notes: Allow selecting Lucene lock implementation using index.lockFactory\nChange-Id: Ia001d473ba2f6f5082161da7fd7448e6fff51624\n"
    },
    {
      "commit": "e3985c09bd335845645084af57016e8555131744",
      "tree": "6357278554706b56a0902b091ba4b05b79a9e000",
      "parents": [
        "57d3dc2622beae463b2327b6ba8906ad747013b1"
      ],
      "author": {
        "name": "Nasser Grainawi",
        "email": "nasser.grainawi@oss.qualcomm.com",
        "time": "Thu Sep 10 08:58:47 2026 -0700"
      },
      "committer": {
        "name": "Nasser Grainawi",
        "email": "nasser.grainawi@oss.qualcomm.com",
        "time": "Thu Sep 10 08:58:47 2026 -0700"
      },
      "message": "Update h2 to 2.5.250\n\nIncludes fixes for errors commonly reported with Gerrit usage, such as:\n* PR #4374 (https://github.com/h2database/h2database/pull/4374)\n  Fixed: Data race causing spurious \"Position 0\" during chunk rewriting\n\nFull h2 release notes:\nhttps://github.com/h2database/h2database/releases/tag/version-2.5.250\n\nRelease-Notes: Update h2 to 2.5.250\nChange-Id: Ic7322d54484bd374b6437797a2c59589baa87dd7\n"
    },
    {
      "commit": "cedd8da719edbde10fc9a1d517e5fb7fce6a4e92",
      "tree": "9a41bfcb91a855e849399543b73874c5a40c9edf",
      "parents": [
        "ef22f0462b34d98a7b9d00dcafad48db4782b528"
      ],
      "author": {
        "name": "Hitesh Chaudhari",
        "email": "hitesh.chaudhari@sap.com",
        "time": "Wed May 06 10:02:32 2026 +0200"
      },
      "committer": {
        "name": "Hitesh Chaudhari",
        "email": "hitesh.chaudhari@sap.com",
        "time": "Thu Sep 10 16:43:42 2026 +0200"
      },
      "message": "Add submit-requirement-template for Submit requirement creation.\n\nMotivation: The change adds reusable submit requirement templates\n(SR template) so administrators can define common policies once in\nproject.config\nand let project owners create submit requirements from those predefined\nconfigurations in the UI.\n\nBefore this, every project owner had to manually create submit\nrequirements from scratch, which leads to:\n- duplicated configurations across repositories,\n- more chances for minor mistakes in expressions.\n- and slower onboarding for common workflows.\n\nThis change addresses these issues with the following implementation:\n\nIntroduce support for parsing [submit-requirement-template \"\u003cname\u003e\"]\nsections in project.config via ProjectConfig and expose them through\ngetSubmitRequirementTemplateSections().\nThe SR Template can be added/modified in the project.config file in\nthe refs/meta/config branch.\n\nImplement GET /projects/{project}/submit_requirements_templates\nusing direct, on-demand loading of current Project and its parents\nSR template from `project.config`.\n\nNote: The SR templates will not be cached, since accessing them is\nnot a very frequent operation.\n\nUsers can select templates from the Gerrit Submit requirement UI.\nThis will display the configured templates of the current repo\nincluding the ones inherited from parent projects.\n\nSS: https://imgur.com/a/B6H0Qm5\n\nRelease-Notes: Add submit-requirement-template for Submit requirement creation.\nChange-Id: I8c7dc64585a3d2d148368d9533fef2cd45868f68\n"
    },
    {
      "commit": "57d3dc2622beae463b2327b6ba8906ad747013b1",
      "tree": "5c0e7921739851a249871bdab8dab67e00c57d6a",
      "parents": [
        "c2b85ad657cd49f104068600c0adbc498f64e48b",
        "3c6b1b63a59e2f40bc1b9551f2aad1403ae2a722"
      ],
      "author": {
        "name": "Milutin Kristofic",
        "email": "milutin@google.com",
        "time": "Thu Sep 10 02:53:28 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Thu Sep 10 02:53:28 2026 -0700"
      },
      "message": "Merge changes I35730e75,Iff92485a\n\n* changes:\n  Avoid force reloading change view when reverting delta in edit mode\n  Resolve base patchset for revert delta in edit mode\n"
    },
    {
      "commit": "c2b85ad657cd49f104068600c0adbc498f64e48b",
      "tree": "401aac470fd365cbc223ecccea9ae0a80487ef5b",
      "parents": [
        "3b9e9bc3a1770dca3e0eeb34ce39682dcfc59bb3",
        "0759e521398dc24efc9f9aa065c513be78226eb9"
      ],
      "author": {
        "name": "Thomas Draebing",
        "email": "thomas.draebing@sap.com",
        "time": "Wed Sep 09 23:44:23 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Wed Sep 09 23:44:23 2026 -0700"
      },
      "message": "Merge \"Add integration tests to increase coverage for ACL behaviour\""
    },
    {
      "commit": "0759e521398dc24efc9f9aa065c513be78226eb9",
      "tree": "954cb8f4a42280b56344af68dd5fba3eaa33dcd3",
      "parents": [
        "84d47c3f0495a38a2e14821bb569a1e2d328ff16"
      ],
      "author": {
        "name": "Thomas Dräbing",
        "email": "thomas.draebing@sap.com",
        "time": "Fri Sep 04 09:15:05 2026 +0200"
      },
      "committer": {
        "name": "Thomas Draebing",
        "email": "thomas.draebing@sap.com",
        "time": "Wed Sep 09 23:28:16 2026 -0700"
      },
      "message": "Add integration tests to increase coverage for ACL behaviour\n\nRelease-Notes: skip\nChange-Id: I310fc72b732ce410cb30926ac80021d275405290\n"
    },
    {
      "commit": "3c6b1b63a59e2f40bc1b9551f2aad1403ae2a722",
      "tree": "1182dc265ce497ef37e5012843bf5a036b804e73",
      "parents": [
        "47644c5ea8e33d801c1aeceb721b78dcf7a4878c"
      ],
      "author": {
        "name": "Milutin Kristofic",
        "email": "milutin@google.com",
        "time": "Wed Sep 09 20:59:50 2026 +0000"
      },
      "committer": {
        "name": "Milutin Kristofic",
        "email": "milutin@google.com",
        "time": "Wed Sep 09 22:58:29 2026 -0700"
      },
      "message": "Avoid force reloading change view when reverting delta in edit mode\n\nWhen reverting a diff delta while a change edit already exists,\nhardcoding forceReload: true into createApplyFixUrl caused\ngr-change-view to re-render, resetting expandedFiles in gr-file-list\nand collapsing all expanded diffs on the change overview page.\n\nUse forceReload: !hasEdit (consistent with gr-suggestion-diff-preview\nand gr-apply-fix-dialog) so that existing open diffs are preserved\nwhen reverting hunks in edit mode.\n\nRelease-Notes: skip\nChange-Id: I35730e758076d3228b37a2810f6fb9e220cd2679\n"
    },
    {
      "commit": "47644c5ea8e33d801c1aeceb721b78dcf7a4878c",
      "tree": "17cb202a52de6bd7396172b01fd1fbe8f391b654",
      "parents": [
        "3b2d5efb6c513c4ab28590e8a095c26ffaed3328"
      ],
      "author": {
        "name": "Milutin Kristofic",
        "email": "milutin@google.com",
        "time": "Wed Sep 09 20:55:33 2026 +0000"
      },
      "committer": {
        "name": "Milutin Kristofic",
        "email": "milutin@google.com",
        "time": "Wed Sep 09 22:42:00 2026 -0700"
      },
      "message": "Resolve base patchset for revert delta in edit mode\n\nWhen reverting a diff delta while viewing EDIT mode (where\npatchRange.patchNum is EDIT), applyFixSuggestion was invoked with\npatchNum \u003d EDIT (\u0027edit\u0027). On the Gerrit backend, \u0027edit\u0027 resolves to\na synthetic revision patchset with ID 0, which fails in\nModificationTarget with HTTP 409:\n\"Only the patch set \u003cbase\u003e on which the existing change edit is based\nmay be modified (specified patch set: 0)\".\n\nResolve patchNum to the numeric base patchset number of the edit\nrevision if present, or fallback to latestPatchNum /\ncomputeLatestPatchNum.\n\nRelease-Notes: skip\nChange-Id: Iff92485afb5675965643597b4ff83c678a97b1e5\n"
    },
    {
      "commit": "1579779e1973c1a04d702bdd2125b27721f5bcf6",
      "tree": "c07635e1dae6b202f85e66edf6a27cb01136f43f",
      "parents": [
        "539218dc0d28a91df541439da075416df42ec1d1"
      ],
      "author": {
        "name": "James Hawkins",
        "email": "jhawkins@google.com",
        "time": "Sat Sep 05 05:38:50 2026 +0000"
      },
      "committer": {
        "name": "James Hawkins",
        "email": "jhawkins@google.com",
        "time": "Thu Sep 10 05:37:38 2026 +0000"
      },
      "message": "[server] Preserve AccessPath and PropertyMap in IdentifiedUser.materializedCopy()\n\nBackground \u0026 Problem:\nCL 825466127 (\"Do change indexing asynchronously if the caller is\nnot a service user\", b/455791982, b/455794278) intended to make\ngit push faster for human users by indexing asynchronously when\n`index.indexChangesAsync\u003dtrue`.\n\nHowever, during a Git push, GitOverHttpServlet sets AccessPath.GIT,\nbut ReceiveCommits creates BatchUpdate via `user.materializedCopy()`.\n\nPreviously, IdentifiedUser.materializedCopy() dropped:\n1. `CurrentUser.accessPath`, resetting to AccessPath.UNKNOWN. Downstream\n   BatchUpdate checks lost the git push origin, preventing async\n   indexing from taking effect.\n2. `CurrentUser.properties` (`PropertyMap`), losing request properties.\n3. Passed `this.realUser` into the copy constructor, retaining a\n   reference to the original request-scoped user and leaving\n   impersonated real users unmaterialized.\n4. Passed raw `state`, risking NPE if state() had not yet been loaded.\n\nIn addition, documentation retained stale references to \"(WEB_BROWSER\nrequests only)\" and an obsolete experiment flag, and unit test coverage\nverifying indexAsync() behavior across access paths was missing.\n\nThis change:\n1. Preserves AccessPath and forwards PropertyMap in materializedCopy().\n2. Unbinds self-referencing realUser and recursively materializes\n   impersonated real users.\n3. Safely accesses state() in materializedCopy() and marks state volatile.\n4. Updates index.indexChangesAsync docs and BatchUpdate comments for git push.\n5. Removes obsolete experiment flag reference in access-control.txt.\n6. Adds unit tests for materializedCopy() and BatchUpdate.indexAsync().\n\nCost/Benefit:\nEnables the intended ~150-300ms server-side latency reduction on git push\nby correctly routing interactive pushes to asynchronous change indexing.\n\nRelease-Notes: skip\nBug: Google b/455791982\nBug: Google b/455794278\nChange-Id: I9947f0d47707c06305c3cf884b2c65f919c2dd10\n"
    },
    {
      "commit": "3b9e9bc3a1770dca3e0eeb34ce39682dcfc59bb3",
      "tree": "ffd8307dce086dd0759c32ff2b9fe507970965a7",
      "parents": [
        "84b82b05c0cfa454c818b8cec99308639b15499a",
        "05ff487cb87a971334c1fa1fd1129da43daed978"
      ],
      "author": {
        "name": "Yash Chaturvedi",
        "email": "yash.chaturvedi@oss.qualcomm.com",
        "time": "Wed Sep 09 21:55:27 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Wed Sep 09 21:55:27 2026 -0700"
      },
      "message": "Merge \"Fix Jetty acceptor/selector thread config defaults\""
    },
    {
      "commit": "84b82b05c0cfa454c818b8cec99308639b15499a",
      "tree": "b52008bb638e9a8ededf1254a8edc6cb0e53a007",
      "parents": [
        "e39fb28ce8d242a5a801365f57a9ac1c6a60fc46",
        "cf2c7ca14b9934db97c0497571d4fb29f772fc57"
      ],
      "author": {
        "name": "Nasser Grainawi",
        "email": "nasser.grainawi@oss.qualcomm.com",
        "time": "Wed Sep 09 17:02:01 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Wed Sep 09 17:02:01 2026 -0700"
      },
      "message": "Merge changes I1e039b63,Id1500d2b,I17ee5d50\n\n* changes:\n  docs: Fix old bugs.chromium.org references\n  README: Point to website contact page\n  Note spam prevention requirements\n"
    },
    {
      "commit": "cf2c7ca14b9934db97c0497571d4fb29f772fc57",
      "tree": "d7b1ed4759e955d4ba157530b7d3cfc8af90be91",
      "parents": [
        "e3328de29fce835c70c2c0d545670b21e2475bf5"
      ],
      "author": {
        "name": "Nasser Grainawi",
        "email": "nasser.grainawi@oss.qualcomm.com",
        "time": "Wed Sep 09 16:22:48 2026 -0700"
      },
      "committer": {
        "name": "Nasser Grainawi",
        "email": "nasser.grainawi@oss.qualcomm.com",
        "time": "Wed Sep 09 16:23:44 2026 -0700"
      },
      "message": "docs: Fix old bugs.chromium.org references\n\nUpdate the links and clarify that only Googlers can create new\ncomponents in the new issue tracker.\n\nRelease-Notes: skip\nChange-Id: I1e039b63b7bbcd814761dbf2d291b1c647c59622\n"
    },
    {
      "commit": "e3328de29fce835c70c2c0d545670b21e2475bf5",
      "tree": "6c0cef49092020eac3af198b45db0a162aa67a73",
      "parents": [
        "0fa1089c85ca4e2038de22cff936c63a744f0fb7"
      ],
      "author": {
        "name": "Nasser Grainawi",
        "email": "nasser.grainawi@oss.qualcomm.com",
        "time": "Wed Sep 09 16:16:44 2026 -0700"
      },
      "committer": {
        "name": "Nasser Grainawi",
        "email": "nasser.grainawi@oss.qualcomm.com",
        "time": "Wed Sep 09 16:23:44 2026 -0700"
      },
      "message": "README: Point to website contact page\n\nWe have a full contact page on the website with more details. Instead of\nduplicating that content, point the README to the website page.\n\nRelease-Notes: skip\nChange-Id: Id1500d2b89e0ee4486a7a7b0a87376dbab28ad94\n"
    },
    {
      "commit": "0fa1089c85ca4e2038de22cff936c63a744f0fb7",
      "tree": "18133767b23c7b84a8d8ebcacb0195bce280056f",
      "parents": [
        "20757cad58b5301b09fa130ceb6c5339543c45a0"
      ],
      "author": {
        "name": "Nasser Grainawi",
        "email": "nasser.grainawi@oss.qualcomm.com",
        "time": "Wed Sep 09 16:12:54 2026 -0700"
      },
      "committer": {
        "name": "Nasser Grainawi",
        "email": "nasser.grainawi@oss.qualcomm.com",
        "time": "Wed Sep 09 16:23:29 2026 -0700"
      },
      "message": "Note spam prevention requirements\n\nUsers must join repo-discuss before creating issues or code reviews.\n\nAlso note the dev-contributing doc in SUBMITTING_PATCHES and fix the\noutdated bugs.chromium.org link.\n\nRelease-Notes: skip\nChange-Id: I17ee5d5043a8370d33b14103cb3d8ed32d45ec37\n"
    },
    {
      "commit": "e39fb28ce8d242a5a801365f57a9ac1c6a60fc46",
      "tree": "f5e06f82155a9d153e5aee5c87aa9bea774ef62c",
      "parents": [
        "20757cad58b5301b09fa130ceb6c5339543c45a0",
        "27351327f1e5735a6bff266fbcf24f550ce2b20f"
      ],
      "author": {
        "name": "Kaushik Lingarkar",
        "email": "klingarkar@nvidia.com",
        "time": "Wed Sep 09 16:14:09 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Wed Sep 09 16:14:09 2026 -0700"
      },
      "message": "Merge \"WorkQueue: Invoke CancelableRunnable#cancel for tasks waiting to start\""
    },
    {
      "commit": "20757cad58b5301b09fa130ceb6c5339543c45a0",
      "tree": "5126d96de4aba5f3e5c8eb06c5e37e7dcc3e54cf",
      "parents": [
        "a91d20dc56f3b3ba41c0c8e085e19ab803d044ea",
        "2c7335e40f6cb8d1820a3634b216be69b62e54d5"
      ],
      "author": {
        "name": "Nasser Grainawi",
        "email": "nasser.grainawi@oss.qualcomm.com",
        "time": "Wed Sep 09 16:04:30 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Wed Sep 09 16:04:30 2026 -0700"
      },
      "message": "Merge \"Documentation: correct typo in `GitHub`\""
    },
    {
      "commit": "a91d20dc56f3b3ba41c0c8e085e19ab803d044ea",
      "tree": "8c3eeecfc4f68f0c0df3e3b6de6fbc9d9cc84084",
      "parents": [
        "9ad9ee63a9faea07d38af39d2608b0770ebca2a0",
        "1d82ae56b834b05ac370124b405dab265097a29a"
      ],
      "author": {
        "name": "Nasser Grainawi",
        "email": "nasser.grainawi@oss.qualcomm.com",
        "time": "Wed Sep 09 13:58:03 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Wed Sep 09 13:58:03 2026 -0700"
      },
      "message": "Merge \"Clarify review push ACL ref names\""
    },
    {
      "commit": "1d82ae56b834b05ac370124b405dab265097a29a",
      "tree": "0d21a5d890f54e7c5182b2223682560ca4160dfa",
      "parents": [
        "d60cdde4ae8131c6f89015f29911495c1cb97000"
      ],
      "author": {
        "name": "Nasser Grainawi",
        "email": "nasser.grainawi@oss.qualcomm.com",
        "time": "Tue Sep 08 13:05:04 2026 -0700"
      },
      "committer": {
        "name": "Nasser Grainawi",
        "email": "nasser.grainawi@oss.qualcomm.com",
        "time": "Wed Sep 09 13:40:21 2026 -0700"
      },
      "message": "Clarify review push ACL ref names\n\nProject owners could configure Push on the short magic-push syntax,\nwhich is not normalized when ACL sections are evaluated. Explain that\nrefs/for/\u003cbranch\u003e is a push shorthand, while ACLs must use the canonical\nrefs/for/refs/heads/\u003cbranch\u003e form. Also correct the project owner guide.\n\nRelease-Notes: skip\nChange-Id: I11417caaf0f0545b10f8be8f2cf488beb4a29100\n"
    },
    {
      "commit": "9ad9ee63a9faea07d38af39d2608b0770ebca2a0",
      "tree": "1ee04dfa5503ee4d32e19e6c0b8ed961a4946ea7",
      "parents": [
        "3b2d5efb6c513c4ab28590e8a095c26ffaed3328"
      ],
      "author": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Wed Sep 09 22:02:48 2026 +0200"
      },
      "committer": {
        "name": "David Ostrovsky",
        "email": "david@ostrovsky.org",
        "time": "Wed Sep 09 22:05:18 2026 +0200"
      },
      "message": "Bazel: Upgrade protobuf to 36.1\n\nUpdate the Bzlmod protobuf dependency from 35.1 to 36.1 and\nthe Maven Central protobuf-java dependency from 4.35.1 to 4.36.1.\n\nRefresh MODULE.bazel.lock and external_deps.lock.json for the new\nversions.\n\nRelease-Notes: Update protobuf to 36.1 and protobuf-java to 4.36.1.\nChange-Id: I105ada9e9ae02a22ae577896abeb2538811f7183\n"
    },
    {
      "commit": "3b2d5efb6c513c4ab28590e8a095c26ffaed3328",
      "tree": "53fdcae20c8f2373cfa46c947578bb84c20cd3bf",
      "parents": [
        "1a98b2d93f16c7184ec9f90d2d1c96eec83705aa",
        "a07f47c516d90131095d6e25e181491a29597640"
      ],
      "author": {
        "name": "Sam Saccone",
        "email": "samccone@google.com",
        "time": "Wed Sep 09 12:50:50 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Wed Sep 09 12:50:50 2026 -0700"
      },
      "message": "Merge \"Optimize CommentJson and CommentContextCache performance\""
    },
    {
      "commit": "fe06138df4f6f0e0f46ba9bf558269bbcaf160b7",
      "tree": "7dde486200579c04dc9d4f87ed3ffc55f0448fa5",
      "parents": [
        "48f79e2c974b35dfea9abed3583bb134a96af707"
      ],
      "author": {
        "name": "James Hawkins",
        "email": "jhawkins@google.com",
        "time": "Sat Sep 05 17:30:20 2026 +0000"
      },
      "committer": {
        "name": "James Hawkins",
        "email": "jhawkins@google.com",
        "time": "Wed Sep 09 16:28:50 2026 +0000"
      },
      "message": "ReceiveCommits: Support \u0027:silent\u0027 for reviewer and CC options\n\nBenchmarks (chromium-review.googlesource.com):\n- Post-push AddReviewers REST call: 1.23s median (1.09s - 2.11s)\n- Push options folding: 0.00s (in git-receive-pack transaction)\n- Latency savings: ~1.23s saved per upload\n\nAdding reviewers or CCs on git push automatically includes them in\nnotification emails. Currently, the only push-level notification\ncontrol is the change-wide \u0027--notify\u0027 option; omitting it emails new\nreviewers, while \u0027notify\u003dNONE\u0027 mutes the entire push, including patch\nset updates to existing reviewers.\n\nSupport appending \u0027:silent\u0027 via push options (e.g. -o r\u003d\u003cemail\u003e:silent,\n-o cc\u003d\u003cemail\u003e:silent) to add reviewers or CCs to NoteDb while\nsuppressing email notifications to those accounts for that push. If an\nexisting CC is promoted to reviewer with \u0027:silent\u0027, patch set emails\nto that account are also muted. Other existing reviewers continue to\nreceive patch set updates per the active notification policy.\n\nThis allows client tools like depot_tools\u0027 \u0027git cl upload\u0027 to fold\nsilent reviewer additions directly into the git push transaction\ninstead of issuing a sequential REST call, saving ~1.2s per upload.\n\nRelease-Notes: Added :silent support for reviewer and CC push options\nChange-Id: Iab370d1c1916ddcb3f9b281d76fe102ba8b4a4c5\n"
    },
    {
      "commit": "27351327f1e5735a6bff266fbcf24f550ce2b20f",
      "tree": "0eda6899172645a7fbeffe8fc4b0b739f1d00256",
      "parents": [
        "1a98b2d93f16c7184ec9f90d2d1c96eec83705aa"
      ],
      "author": {
        "name": "Kaushik Lingarkar",
        "email": "klingarkar@nvidia.com",
        "time": "Wed Sep 09 00:46:12 2026 -0700"
      },
      "committer": {
        "name": "Kaushik Lingarkar",
        "email": "klingarkar@nvidia.com",
        "time": "Wed Sep 09 00:46:15 2026 -0700"
      },
      "message": "WorkQueue: Invoke CancelableRunnable#cancel for tasks waiting to start\n\nTask#cancel only invokes CancelableRunnable#cancel when it can move\nrunningState from null to RUNNING. A task canceled while READY or\nPARKED therefore invokes neither the Runnable nor #cancel. The inner\nfuture is canceled, so run() returns without invoking the Runnable,\nand the CAS fails, so #cancel is skipped.\n\nRunnables rely on #cancel to clean up and report the outcome to their\nclient. Without it an SSH fetch never receives an exit status on a\nchannel that is never closed, so it blocks forever (as sshd.idleTimeout\ndefaults to 0). Over HTTP the suspended request is never resumed and\nstalls until httpd.maxwait instead of getting a 503. So, invoke #cancel\nfor READY and PARKED tasks too.\n\nRelease-Notes: skip\nChange-Id: Id4aae560ca0145268ab1d7f109f90eb53e2b8631\n"
    },
    {
      "commit": "1a98b2d93f16c7184ec9f90d2d1c96eec83705aa",
      "tree": "ab5c788a8ab62258aa9c522896dfac40720d9491",
      "parents": [
        "068d38b693cc395906f737f779f5fe482bf69102",
        "022cee2b5a3d4aea12190cd9c9b1afc7c78d7baa"
      ],
      "author": {
        "name": "Sam Saccone",
        "email": "samccone@google.com",
        "time": "Tue Sep 08 11:00:12 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Tue Sep 08 11:00:12 2026 -0700"
      },
      "message": "Merge \"Add rich rendered markdown diff preview\""
    },
    {
      "commit": "068d38b693cc395906f737f779f5fe482bf69102",
      "tree": "2010ea47f7cb138a17a2739146162bb91306d4cb",
      "parents": [
        "48f79e2c974b35dfea9abed3583bb134a96af707"
      ],
      "author": {
        "name": "Kaushik Lingarkar",
        "email": "klingarkar@nvidia.com",
        "time": "Tue Sep 08 10:17:10 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Tue Sep 08 10:17:10 2026 -0700"
      },
      "message": "Update git submodules\n\n* Update plugins/replication from branch \u0027master\u0027\n  to 36581c07b5fc46b6ab7811b14af0aa308ad398d3\n  - ProjectRepairer: Rsync from a hardlink snapshot\n    \n    rsync fails when a file it is transferring is unlinked underneath it,\n    which can happen on repositories that repack often. Link the files to\n    copy into a snapshot dir next to the repository\u0027s objects dir, then\n    rsync from there. A hardlink keeps the inode alive after the original\n    name is gone, so the transfer always sees a stable set of files. The\n    snapshot is deleted once the transfer for that action finishes.\n    \n    Change-Id: I47ddf03c63180542dbfe47582941284d3f691f9e\n    "
    },
    {
      "commit": "48f79e2c974b35dfea9abed3583bb134a96af707",
      "tree": "7b2f322fc527fbbffab84e269ce25cbbc17f5a0b",
      "parents": [
        "539218dc0d28a91df541439da075416df42ec1d1"
      ],
      "author": {
        "name": "Becky Siegel",
        "email": "beckysiegel@google.com",
        "time": "Fri Sep 04 19:37:20 2026 -0700"
      },
      "committer": {
        "name": "Becky Siegel",
        "email": "beckysiegel@google.com",
        "time": "Fri Sep 04 19:37:20 2026 -0700"
      },
      "message": "polygerrit: export SubmittedTogetherInfo in plugin REST API\n\nPlugins querying the /changes/{id}/submitted_together REST\nendpoint need SubmittedTogetherInfo to accurately type responses.\nExport this entity in the public plugin rest-api definitions.\n\nGoogle-Bug-Id: b/555825308\nRelease-Notes: skip\nChange-Id: I177cd8378f9bf1c89b0f3466a596bbd84f9a012f"
    }
  ],
  "next": "022cee2b5a3d4aea12190cd9c9b1afc7c78d7baa"
}
