<feed xmlns='http://www.w3.org/2005/Atom'>
<title>BMC/Intel-BMC/virtual-media.git/src/state, branch main</title>
<subtitle>Adds possibility to inject virtual installation media to the platform via browser, HTTPS or CIFS. (mirror)</subtitle>
<id>https://git.radix-linux.su/BMC/Intel-BMC/virtual-media.git/atom?h=main</id>
<link rel='self' href='https://git.radix-linux.su/BMC/Intel-BMC/virtual-media.git/atom?h=main'/>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/Intel-BMC/virtual-media.git/'/>
<updated>2022-03-14T21:20:54+00:00</updated>
<entry>
<title>Make mount/unmount dbus calls asynchronous</title>
<updated>2022-03-14T21:20:54+00:00</updated>
<author>
<name>Przemyslaw Czarnowski</name>
<email>przemyslaw.hawrylewicz.czarnowski@intel.com</email>
</author>
<published>2022-03-14T21:20:54+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/Intel-BMC/virtual-media.git/commit/?id=ed2aceab6ee059a40d939ea21364bc18ec80d94b'/>
<id>urn:sha1:ed2aceab6ee059a40d939ea21364bc18ec80d94b</id>
<content type='text'>
Change the default behavior of mount/umount dbus calls from blocking to
unblocking ones.

Once mount/unmount is triggered, appropriate action is running in the
background moving handling of operation result to async event. At the
end of processing dbus completion signal is sent to client with uint
value of operation status (identical with errno code).

Tested:
Manual scheduling of mount and unmount operations with monitoring dbus
communication of virtual-media service - matching api calls with
completion signal.

Signed-off-by: Przemyslaw Czarnowski &lt;przemyslaw.hawrylewicz.czarnowski@intel.com&gt;</content>
</entry>
<entry>
<title>Switch the build system to meson</title>
<updated>2022-02-14T09:26:50+00:00</updated>
<author>
<name>Przemyslaw Czarnowski</name>
<email>przemyslaw.hawrylewicz.czarnowski@intel.com</email>
</author>
<published>2022-02-14T09:26:50+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/Intel-BMC/virtual-media.git/commit/?id=1fb7beae5e97aadf8471ae7b6e07f5c2e5f33c78'/>
<id>urn:sha1:1fb7beae5e97aadf8471ae7b6e07f5c2e5f33c78</id>
<content type='text'>
Due to requirements from community, new projects have to be built with
meson.

To unify with other projects some additional warnings has been enabled,
so appropriate code updates has been implemented.

This commit makes both meson and CMake available to simplyfy transition
in openbmc. CMake support will be removed after switching to meson in
openbmc will be accepted.

Tested:
Compiled and smoke tested.

Signed-off-by: Przemyslaw Czarnowski &lt;przemyslaw.hawrylewicz.czarnowski@intel.com&gt;</content>
</entry>
<entry>
<title>Force udev change event on init (#6)</title>
<updated>2022-02-07T15:13:02+00:00</updated>
<author>
<name>Michal Orzel</name>
<email>michalx.orzel@intel.com</email>
</author>
<published>2022-02-07T15:13:02+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/Intel-BMC/virtual-media.git/commit/?id=6df74a76eeacc5240d36fa7e62717cd1cdd238a7'/>
<id>urn:sha1:6df74a76eeacc5240d36fa7e62717cd1cdd238a7</id>
<content type='text'>
* Force udev change event on init

This change provides temporary workaround for HSD HSD18020136609 ("Can not mount image using Virtual media and CIFS protocol"). When in initial state, additional udev change event is triggered for all NBD devices, which prevents from disconnection on first mount attempt after reboot. The actual issue is a regression, introduced after kernel update from 5.10.67 to 5.14.11. The exact source in kernel is yet to be located; after that an actual fix shall be provided and this change will be reverted.
Abstracts echoToFile to a separate class, that may be used by other classes through inheritance. This way, writing to udev files can be handled by different object than UsbGadget.

Tested:
Successful mounts after reboot for all supported methods (Proxy, Legacy HTTPS, Legacy CIFS).

Change-Id: I2ceb826c73b6e46938397060877d35a9fa1c0e03
Signed-off-by: MichalX Orzel &lt;michalx.orzel@intel.com&gt;</content>
</entry>
<entry>
<title>Add -Wextra, remove warnings (#1)</title>
<updated>2022-01-26T15:51:08+00:00</updated>
<author>
<name>Przemyslaw Czarnowski</name>
<email>przemyslaw.hawrylewicz.czarnowski@intel.com</email>
</author>
<published>2022-01-26T15:51:08+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/Intel-BMC/virtual-media.git/commit/?id=8542fa62c13306e8e8cc623183f105a868a36b6c'/>
<id>urn:sha1:8542fa62c13306e8e8cc623183f105a868a36b6c</id>
<content type='text'>
Removed all -Wextra warnings in VM sources.
-Wno-unused-parameter has to be disabled due to lots of such warnings in
sdbusplus.

Tested:
Compilation generates no warnings

Signed-off-by: Przemyslaw Czarnowski &lt;przemyslaw.hawrylewicz.czarnowski@intel.com&gt;</content>
</entry>
<entry>
<title>Cleanup mounted resources after application crash.</title>
<updated>2021-10-28T14:21:37+00:00</updated>
<author>
<name>Krzysztof Richert</name>
<email>krzysztof.richert@intel.com</email>
</author>
<published>2021-10-27T12:07:45+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/Intel-BMC/virtual-media.git/commit/?id=90e0e1648c3ee168deb7615450f3a2771c04b8eb'/>
<id>urn:sha1:90e0e1648c3ee168deb7615450f3a2771c04b8eb</id>
<content type='text'>
On initial state application cleans mounted resources which
were allocated by user befor application crashed.
Without that busy slot is not avaialble anymore for user.

Tested:
1. Mount CIFS share.
2. Send terminate signal to virtual-media (kill -9).
3. Mount CIFS share on the same slot as during step 1.

Change-Id: I7088e94832fb7bec171a56f73bd66cd29e9b246f
Signed-off-by: Krzysztof Richert &lt;krzysztof.richert@intel.com&gt;
</content>
</entry>
<entry>
<title>Override default libcurl CAInfo with empty string.</title>
<updated>2021-08-27T17:19:10+00:00</updated>
<author>
<name>Golgowski, Wiktor</name>
<email>wiktor.golgowski@intel.com</email>
</author>
<published>2021-08-27T17:01:54+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/Intel-BMC/virtual-media.git/commit/?id=b54c42c6c1ef6c2b58a6728317cbaedc8a3552ae'/>
<id>urn:sha1:b54c42c6c1ef6c2b58a6728317cbaedc8a3552ae</id>
<content type='text'>
This change allows virtual-media to pass a zero-length string to
nbdkit curl plugin cainfo parameter, which will allow for capath
to be used.

Tested:
Manually, with Virtual-Media HTTPS test in ATF.

Change-Id: I14ffa2ecbb2bd6cadee3bb8929ef2e1b8bbbf157
Signed-off-by: Golgowski, Wiktor &lt;wiktor.golgowski@intel.com&gt;
</content>
</entry>
<entry>
<title>Restricted TLS cipher suites to preferred ones</title>
<updated>2021-08-25T16:11:28+00:00</updated>
<author>
<name>Karol Niczyj</name>
<email>karol.niczyj@intel.com</email>
</author>
<published>2021-08-17T18:09:42+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/Intel-BMC/virtual-media.git/commit/?id=2f81f80acc0e34cfad3d250b60f0ceba17bddbf0'/>
<id>urn:sha1:2f81f80acc0e34cfad3d250b60f0ceba17bddbf0</id>
<content type='text'>
Updated TLS 1.2 cipher list and added TLS1.3 cipher list.

Tested by Oleksandr Shulzhenko on local setup.

Change-Id: I218c245d8ddf7e54dae258a39cd78c3255027b6e
Signed-off-by: Karol Niczyj &lt;karol.niczyj@intel.com&gt;
</content>
</entry>
<entry>
<title>Forbid ECDHE-RSA-CHACHA20-POLY1305 with TLSv1.2</title>
<updated>2021-05-24T21:57:27+00:00</updated>
<author>
<name>Czarnowski, Przemyslaw</name>
<email>przemyslaw.hawrylewicz.czarnowski@intel.com</email>
</author>
<published>2021-05-24T21:57:27+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/Intel-BMC/virtual-media.git/commit/?id=71520e886f7edcc7eb2b91b959a512883b684910'/>
<id>urn:sha1:71520e886f7edcc7eb2b91b959a512883b684910</id>
<content type='text'>
According to the latest recommendations obsolete cipher suites shall be
forbidden.

Tested:
Python HTTP server configured TLSv1.2 with ECDHE-RSA-CHACHA20-POLY1305
cipher can't be reached.

Change-Id: I370c125b28c4df4bba744ec63536aa8fdebb961d
Signed-off-by: Czarnowski, Przemyslaw &lt;przemyslaw.hawrylewicz.czarnowski@intel.com&gt;
</content>
</entry>
<entry>
<title>Forbid redirection of https resources</title>
<updated>2021-05-24T13:38:40+00:00</updated>
<author>
<name>Czarnowski, Przemyslaw</name>
<email>przemyslaw.hawrylewicz.czarnowski@intel.com</email>
</author>
<published>2021-05-19T10:28:03+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/Intel-BMC/virtual-media.git/commit/?id=a0bcbd873a067958da13aa881446913ba6c83762'/>
<id>urn:sha1:a0bcbd873a067958da13aa881446913ba6c83762</id>
<content type='text'>
Due to security reasons (by security researcher recommendation) remote
source redirections shouldn't be allowed in order to disallow connection
downgrading

Tested:
Tested with python server script forcing redirection

Change-Id: Ia68884dbcc399abc685dcbcf4e205aa62356478f
Signed-off-by: Czarnowski, Przemyslaw &lt;przemyslaw.hawrylewicz.czarnowski@intel.com&gt;
</content>
</entry>
<entry>
<title>Legacy HTTPs: Set minimum tls version to 1.2</title>
<updated>2021-05-07T08:22:46+00:00</updated>
<author>
<name>Czarnowski, Przemyslaw</name>
<email>przemyslaw.hawrylewicz.czarnowski@intel.com</email>
</author>
<published>2021-05-06T12:39:22+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/Intel-BMC/virtual-media.git/commit/?id=0315081e9ea897772f3db6946364a2018a27d649'/>
<id>urn:sha1:0315081e9ea897772f3db6946364a2018a27d649</id>
<content type='text'>
Due to change of recommendation of minimum TLS version from 1.1 to 1.2,
version passed to CURL plugin of Nbdkit is changed appropriately.

Tested:
Manually; TLSv1.1 server is rejected for Legacy/HTTPs.

Change-Id: Ifc8848817deb9f73a44f551d85f1fe9ba20b3e10
Signed-off-by: Czarnowski, Przemyslaw &lt;przemyslaw.hawrylewicz.czarnowski@intel.com&gt;
</content>
</entry>
</feed>
