)]}'
{
  "commit": "920bbd6250d6127b0cf958ceac0aa99a56817f9e",
  "tree": "10b749a572950084a01accbb3862364075447274",
  "parents": [
    "4cc19488b01618ae0194e1dc2af54516c7af8419"
  ],
  "author": {
    "name": "Tommi",
    "email": "tommi@webrtc.org",
    "time": "Tue Oct 06 11:42:07 2026"
  },
  "committer": {
    "name": "webrtc-scoped@luci-project-accounts.iam.gserviceaccount.com",
    "email": "webrtc-scoped@luci-project-accounts.iam.gserviceaccount.com",
    "time": "Tue Oct 06 13:23:57 2026"
  },
  "message": "Apply TURN server checks to UDP redirects\n\nA 300 (Try Alternate) response to a TURN allocation over UDP makes the\nport reuse its socket and send a new Allocate request to the alternate\nserver directly, without going through PrepareAddress(). That skipped\ntwo checks that apply to every other way of connecting to a TURN server:\nthe check for disallowed ports and the Local Network Access permission\nrequest.\n\n- Reject redirects to disallowed ports in SetAlternateServer(), next to\n  the loopback and unspecified address checks, so that all protocols are\n  covered. Redirects over TCP and TLS to such ports were already blocked\n  by PrepareAddress(), but are now rejected before reconnecting.\n- Request Local Network Access permission for the alternate server\n  before sending the Allocate request over UDP, using a helper shared\n  with PrepareAddress().\n\nBug: chromium:502821327\nChange-Id: Ib2f06c9bfc51fbf6dadddbd701774e33d4c77ce8\nReviewed-on: https://webrtc-review.googlesource.com/c/src/+/507220\nCommit-Queue: Tomas Gunnarsson \u003ctommi@webrtc.org\u003e\nReviewed-by: Fredrik Solenberg \u003csolenberg@webrtc.org\u003e\nCr-Commit-Position: refs/heads/main@{#48807}\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "8f97a1dd0ddf1b61f3eb35b722795ec734451ddb",
      "old_mode": 33188,
      "old_path": "p2p/BUILD.gn",
      "new_id": "3e77dcb5798a326f10f0135d0c8490ed2ee90f30",
      "new_mode": 33188,
      "new_path": "p2p/BUILD.gn"
    },
    {
      "type": "modify",
      "old_id": "77280694df5c0c92e70b8500d90ed2026e63bf75",
      "old_mode": 33188,
      "old_path": "p2p/base/turn_port.cc",
      "new_id": "2ac7c52ccfbabfd65ddfa2344af3d89bd4637650",
      "new_mode": 33188,
      "new_path": "p2p/base/turn_port.cc"
    },
    {
      "type": "modify",
      "old_id": "76ed3b4a1fda3515d021fa8bd386a76eb1b4c768",
      "old_mode": 33188,
      "old_path": "p2p/base/turn_port.h",
      "new_id": "2bc9bfba27cb0abb9566ecbd4f4f1166bff1ec5f",
      "new_mode": 33188,
      "new_path": "p2p/base/turn_port.h"
    },
    {
      "type": "modify",
      "old_id": "9a37189bf2bf44ceebe843975a43d5b7d42dbe58",
      "old_mode": 33188,
      "old_path": "p2p/base/turn_port_unittest.cc",
      "new_id": "53dcf2d924702ed2dff97664b20c4896d90be6dc",
      "new_mode": 33188,
      "new_path": "p2p/base/turn_port_unittest.cc"
    }
  ]
}
