<feed xmlns='http://www.w3.org/2005/Atom'>
<title>BMC/OpenBmc/bmcweb.git/http, branch master</title>
<subtitle>A do everything Redfish, KVM, GUI, and DBus webserver for OpenBMC (mirror)</subtitle>
<id>https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/atom?h=master</id>
<link rel='self' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/'/>
<updated>2026-09-24T06:43:40+00:00</updated>
<entry>
<title>Refactor startAsyncWaitForSignal lambda</title>
<updated>2026-09-24T06:43:40+00:00</updated>
<author>
<name>Yuvakumar Selvamani</name>
<email>yuvakumars@ami.com</email>
</author>
<published>2026-08-20T07:17:47+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=7a0c87df067bd14032d8c18504b9df4444d9d882'/>
<id>urn:sha1:7a0c87df067bd14032d8c18504b9df4444d9d882</id>
<content type='text'>
Extract the long signal handler lambda in startAsyncWaitForSignal() into
a named member function, afterWaitForSignal(), bound via
std::bind_front(), per the &lt;10 line lambda coding standard in
docs/COMMON_ERRORS.md.

Tested on AST2600 SoC:
- `kill -HUP &lt;bmcweb pid&gt;`, then `GET /redfish/v1/`
  Expected: cert reload, service stays active, 200 OK
  Actual:   bmcweb.service remained active, GET returned HTTP 200
- `kill -TERM &lt;bmcweb pid&gt;`
  Expected: clean shutdown
  Actual:   journalctl confirmed "bmcweb.service: Deactivated
            successfully"
- RSV: 5845 Pass / 353 Warn / 0 Fail

Change-Id: Id02f26fd680ae34639b521962b0f4e3d67c534bc
Signed-off-by: Yuvakumar Selvamani &lt;yuvakumars@ami.com&gt;
</content>
</entry>
<entry>
<title>include,http: Extract getUserInfo/onRequestRecv</title>
<updated>2026-09-19T14:52:07+00:00</updated>
<author>
<name>Yuvakumar Selvamani</name>
<email>yuvakumars@ami.com</email>
</author>
<published>2026-09-01T10:12:21+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=e5fdb213cfc5e43cbf3e7d327a78ce771362edaf'/>
<id>urn:sha1:e5fdb213cfc5e43cbf3e7d327a78ce771362edaf</id>
<content type='text'>
Move long lambdas in getUserInfo() and onRequestRecv() into named
functions, afterGetUserInfo() and afterCompleteRequest(), per the &lt;10
line lambda rule in docs/COMMON_ERRORS.md. No functional change.

Tested:
- Tested on AST2600 SoC.
- getUserInfo/afterGetUserInfo: sent an authenticated Basic-auth Redfish
  GET and confirmed a 200 response with no "Failed to populate user
  information" error in journalctl, proving populateUserInfo() succeeded
  via the extracted callback.
- onRequestRecv/afterCompleteRequest: RSV's client uses HTTP/1.1, so it
  does not exercise this HTTP/2-only code path. Instead, used
  "curl --http2" and confirmed ALPN negotiated h2 and the request
  completed as HTTP/2 200. journalctl -u bmcweb confirmed both
  "onRequestRecv streamId:1" and the extracted callback's
  "res.completeRequestHandler called" fired for that stream.
- Redfish Service Validator: 5830 Pass / 353 Warn / 0 Fail.

Change-Id: I0e6365c682f6acc8d39510ad5f1fe239d747154f
Signed-off-by: Yuvakumar Selvamani &lt;yuvakumars@ami.com&gt;
</content>
</entry>
<entry>
<title>http: Refactor handleMessage lambda</title>
<updated>2026-09-11T15:46:11+00:00</updated>
<author>
<name>Yuvakumar Selvamani</name>
<email>yuvakumars@ami.com</email>
</author>
<published>2026-08-20T07:17:46+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=0eaf2bf0d0b98ed65313cc61932872b224c3694c'/>
<id>urn:sha1:0eaf2bf0d0b98ed65313cc61932872b224c3694c</id>
<content type='text'>
Extract the long completion lambda in handleMessage() into a named
member function, afterHandleMessage(), bound via std::bind_front(), per
the &lt;10 line lambda coding standard in docs/COMMON_ERRORS.md.

Tested:
- No functional change.
- Build successfully compiled.
- Redfish Service Validator passed with no new errors or warnings
  introduced.

Change-Id: I54f4cbee152c04c2bd083e5fbbf6859b8277b887
Signed-off-by: Yuvakumar Selvamani &lt;yuvakumars@ami.com&gt;
</content>
</entry>
<entry>
<title>Prevent error level prints on disconnect of http2</title>
<updated>2026-09-10T19:50:56+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>etanous@nvidia.com</email>
</author>
<published>2026-08-31T14:50:15+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=7b9cf582884b7e292ca3c1ce1676e96e17a1c646'/>
<id>urn:sha1:7b9cf582884b7e292ca3c1ce1676e96e17a1c646</id>
<content type='text'>
Previously, http2 disconnects that weren't cleanly stopped in openssl
would result in a log message like:

'''
[http2_connection.hpp:998] 0x2bba5e0 Error while reading: stream truncated
'''

While it's valid to log that a client disconnected unclealy, clients
seem to do this and clog up the logs.

Tested: Redfish Service validator passes.
I don't have a client that reproduces this;  Inspection only.

Change-Id: I9205500171912f7d82b31487b7df8d1a293d8c89
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
<entry>
<title>Add defensive callback invocation</title>
<updated>2026-07-29T16:27:17+00:00</updated>
<author>
<name>Myung Bae</name>
<email>myungbae@us.ibm.com</email>
</author>
<published>2026-06-18T12:52:33+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=a74ef929d70b9ebad9ad2c29f8f711594d7cb41b'/>
<id>urn:sha1:a74ef929d70b9ebad9ad2c29f8f711594d7cb41b</id>
<content type='text'>
We have experienced a `std::bad_function_call` exception [1].
The journal entries are showing
```
Jun 17 15:27:21.985663 bmcwebd[1995]: [http_client.hpp:391] recvMessage() failed: asio.ssl error from https://10.5.10.140:17443/redfish/events
Jun 17 15:27:22.043798 bmcwebd[1995]: [http_client.hpp:391] recvMessage() failed: stale parser from https://10.5.10.140:17443/redfish/events
Jun 17 15:27:22.085644 bmcwebd[1995]: terminate called after throwing an instance of 'std::bad_function_call'
Jun 17 15:27:22.086908 bmcwebd[1995]:   what():  bad_function_call
Jun 17 15:27:22.163520 systemd-coredump[4621]: Process 1995 (bmcwebd) of user 0 terminated abnormally with signal 6/ABRT
```

The matching line is
```
void recvMessage(const std::shared_ptr&lt;ConnectionInfo&gt;&amp; /*self*/,
                 const boost::system::error_code&amp; ec,
                 std::size_t bytesTransferred)
{
    ...
    callback(parser-&gt;keep_alive(), connId, res);
    ...
}
```

This would imply that the callback function pointer became null when it
is invoked.

```
void sendNext(bool keepAlive, uint32_t connId)
{
    ...
    conn-&gt;callback = nullptr;
    ...
}
```

This may be happening due to the race condition between multiple async
operations where the async call is waiting to be invoked but sendNext is
executed first.

This commit is to make the defensive checking of `callback` function
pointer before invoking like

```
   if (callback) {
      callback(parser-&gt;keep_alive(), connId, res);
   }
```

[1] https://en.cppreference.com/cpp/utility/functional/bad_function_call

Change-Id: Ic23e17ea486433e3bb7493e8e3c1e56b1798c8e9
Signed-off-by: Myung Bae &lt;myungbae@us.ibm.com&gt;
</content>
</entry>
<entry>
<title>Implement Response header count</title>
<updated>2026-07-22T18:29:44+00:00</updated>
<author>
<name>Joel P J</name>
<email>joelpj@ami.com</email>
</author>
<published>2026-07-03T13:10:06+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=bb662f2ad11548ec4600d651e58b205b38b43cc9'/>
<id>urn:sha1:bb662f2ad11548ec4600d651e58b205b38b43cc9</id>
<content type='text'>
Add Response::headerCount() to return the total number of
stored header fields on a response. The implementation counts
the current header entries directly from the underlying Beast
header container.

Added unit coverage to verify the method reports the full
header count after headers are added through the normal
addHeader() path.

Tested with:
meson test -C build http_response_test --print-errorlogs

This helper is used by response unit tests to verify that only
the expected headers are present and that no unexpected headers
are added to the response. See also:
https://gerrit.openbmc.org/c/openbmc/bmcweb/+/91848

Change-Id: I28432bb4fc982db44cee0688395d04ac513d6749
Signed-off-by: Joel Pullokaran Jesin &lt;joelpj@ami.com&gt;
</content>
</entry>
<entry>
<title>Fix bug in asio resolver</title>
<updated>2026-07-15T18:27:05+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>etanous@nvidia.com</email>
</author>
<published>2026-05-29T17:11:51+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=a72a21df2401924757519bd56ac1f729a87489e2'/>
<id>urn:sha1:a72a21df2401924757519bd56ac1f729a87489e2</id>
<content type='text'>
This regressed when the bypass was added.  Fix the code for
resolver=asio to properly construct the results object using the built
in asio type instead of std::vector.

Tested: Code compiles with resolver=asio again.

Change-Id: I3d9ddc38b88a392cf82fc81bd5609f3360837393
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
<entry>
<title>Updating maxValues to support roughly 200 bmcweb sessions</title>
<updated>2026-07-09T19:21:12+00:00</updated>
<author>
<name>Rick Yazwinski</name>
<email>rickyaz@meta.com</email>
</author>
<published>2026-07-06T20:08:40+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=93ec859f5d20eef343ddc3f003cc2d36ec9dcb08'/>
<id>urn:sha1:93ec859f5d20eef343ddc3f003cc2d36ec9dcb08</id>
<content type='text'>
parseStringAsJson() routes through BmcwebSaxParse, which hard-caps a
payload at 500 total JSON values to defend against malicious external
HTTP request bodies.

The most visible symptom is that bmcweb silently loses every persisted
session across a restart once ~50 sessions accumulate (each persisted
session is ~11 JSON values, so the file trips the cap and is treated
as malformed).  Tntegration testing hit this 50 session limit and
failed. (Was failing our internal but also the
openbmc-test-automation robot suite)

I had originally implemented a solution as a "trusted reader"
with no limit
( https://gerrit.openbmc.org/c/openbmc/bmcweb/+/90138 ); however,
the security implications of "no limit" weren't attractive.
This area may be refactored in the near future to represent each
session as a distinct json file.  This value bump gets us past
the immediate needs without introducing a lot of churn in code
that will be refactored.

Change-Id: Ifd3514bd8ee15c8bdf1b6c2119451a2965801671
Signed-off-by: Rick Yazwinski &lt;rickyaz@meta.com&gt;
</content>
</entry>
<entry>
<title>Flag long lambdas</title>
<updated>2026-07-01T17:10:08+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>etanous@nvidia.com</email>
</author>
<published>2026-06-22T16:53:17+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=8176ae6778015743b77e8744c046bc50edf13cc4'/>
<id>urn:sha1:8176ae6778015743b77e8744c046bc50edf13cc4</id>
<content type='text'>
Long lambdas have been documented as an anti-pattern for some time.[1]
Despite this being generally understood, bmcweb has a long ways to go
cleaning these up, and routinely code is submitted in violation of this
anti-pattern.

Invent an ast-grep rule that can identify when new examples of this
anti-pattern are added, and ignore the existing 200+ examples that are
in the codebase already using ast-grep ignore.  These flags will give us
something to search for as we clean this up, and will help to prevent
new instances from being added unintentionally.

[1] https://github.com/openbmc/docs/blob/master/anti-patterns.md#very-long-lambda-callbacks

Tested: Comment only change.  ast-grep passes.  Manually removing an
ast-grep ignore flag shows as a failure in ast-grep scan

Change-Id: I77d634a393884969f184d2c39c02cc08288d5a29
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
<entry>
<title>Fix socket reuse in HTTP server accept loop</title>
<updated>2026-06-24T22:41:58+00:00</updated>
<author>
<name>Kokilambal Varadhan</name>
<email>kokilavaradhan@gmail.com</email>
</author>
<published>2026-05-05T02:17:02+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=661dc12c540e94033a43a1a5955bbf8aaeb2889b'/>
<id>urn:sha1:661dc12c540e94033a43a1a5955bbf8aaeb2889b</id>
<content type='text'>
bmcweb HTTP server accept handling had a critical bug where a single
socket pointer was reused across multiple acceptors, causing undefined
behavior and potential crashes.

1. Move socket creation into doAcceptOne() to ensure each acceptor
   creates its own unique socket instance.
2. Pass acceptor pointer to afterAccept() callback to track which
   acceptor completed the accept operation.
3. Replace doAccept() call with doAcceptOne() in afterAccept() to
   resume accepting on only the specific acceptor that handled the
   connection, not all acceptors.

This ensures proper socket lifecycle management and prevents race
conditions from shared socket instances.

Tested:
HTTP server accepts connections correctly with multiple
acceptors (HTTP/HTTPS) without crashes or undefined behavior.

Change-Id: I0540802cdd682e8e7d7312d6edfd5651bf09378a
Signed-off-by: Kokilambal Varadhan &lt;kokilavaradhan@gmail.com&gt;
</content>
</entry>
</feed>
