<feed xmlns='http://www.w3.org/2005/Atom'>
<title>BMC/OpenBmc/bmcweb.git/scripts, branch master</title>
<subtitle>A do everything Redfish, KVM, GUI, and DBus webserver for OpenBMC (mirror)</subtitle>
<id>https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/atom?h=master</id>
<link rel='self' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/'/>
<updated>2026-07-17T04:38:58+00:00</updated>
<entry>
<title>Update GenerateSecretKeyRequired response_code</title>
<updated>2026-07-17T04:38:58+00:00</updated>
<author>
<name>Jishnu CM</name>
<email>jishnunambiarcm@duck.com</email>
</author>
<published>2026-02-19T05:37:53+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=f9563f663e678f3b7b408dc11d75cc8b7c6af779'/>
<id>urn:sha1:f9563f663e678f3b7b408dc11d75cc8b7c6af779</id>
<content type='text'>
Currently, GenerateSecretKeyRequired is treated as 403 Forbidden, which
would incorrectly imply the session was not created, when it should be
treated as an informational message accompanying a successful session
creation (with 201 response code), exactly like PasswordChangeRequired.

According to the Redfish spec [1], page 202, 203 (Section 13.5.5):
* "Shall allow a session login without the Token property and include
  the @Message.ExtendedInfo in the response containing the
  GenerateSecretKeyRequired message. This indicates to the client
  that their session is restricted to performing only the
  GenerateSecretKey action on their ManagerAccount resource before
  access is granted."
* "Shall allow a POST operation on the VerifyTimeBasedOneTimePassword"
  action on the ManagerAccount resource associated with the account."
* "Shall allow a DELETE operation on Session resources representing
  open sessions associated with the account."
* "May allow GET operations on unauthenticated resources, such as
  the ServiceRoot resource."
* "For all other operations, the service shall respond with the HTTP
  403 Forbidden status code and an error response with the
  GenerateSecretKeyRequired message from the Base Message Registry."

Reference:
[1] https://www.dmtf.org/sites/default/files/standards/documents/DSP0266_1.24.0.pdf#page=202&amp;zoom=100,0,789

Tested By:
* Enabled Multi-Factor Authentication (system-wide option)
* When user tries to login with username and password, session is
  created (201 is returned), with GenerateSecretKeyRequired message
  in "@Message.ExtendedInfo"
* Any operations on restricted resources returned
  GenerateSecretKeyRequired with 403 Forbidden error code.

Change-Id: Iec6c925f04584b2cdd93aec743b04d6a8dbde4bc
Signed-off-by: Jishnu CM &lt;jishnunambiarcm@duck.com&gt;
</content>
</entry>
<entry>
<title>Change a few message responses as errors</title>
<updated>2026-06-25T18:51:59+00:00</updated>
<author>
<name>Myung Bae</name>
<email>myungbae@us.ibm.com</email>
</author>
<published>2026-04-29T12:40:24+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=8b0993927ede52f4a32228d955a8405805acedac'/>
<id>urn:sha1:8b0993927ede52f4a32228d955a8405805acedac</id>
<content type='text'>
Some of messages are not currently reported as errors, although they
are the results as Redfish request errors. Those include

- PropertyDuplicate
- ResourceAlreadyExists
- CreateFailedMissingReqProperties
- PropertyValueFormatError
- PropertyValueNotInList
- PropertyValueTypeError
- PropertyValueError
- PropertyNotWritable
- PropertyValueModified
- PropertyMissing

For example, PropertyValueFormatError is currently not treated as an
error. It shows like

```

curl -k -X PATCH "${bmc}/redfish/v1/AccountService/Accounts/admin" \
  -H "Content-Type: application/json" \
  -d '{ "Password": "" }'

  "Password@Message.ExtendedInfo": [
    {
      "@odata.type": "#Message.v1_1_1.Message",
      "Message": "The value 'null' for the property Password is not a format that the property can accept.",
      "MessageArgs": [
        "null",
        "Password"
      ],
      "MessageId": "Base.1.19.PropertyValueFormatError",
      "MessageSeverity": "Warning",
      "Resolution": "Correct the value for the property in the request body and resubmit the request if the operation failed."
    }
  ]
```

After making it as an error, it will be like
```
{
  "error": {
    "@Message.ExtendedInfo": [
      {
        "@odata.type": "#Message.v1_1_1.Message",
        "Message": "The value 'null' for the property Password is not a format that the property can accept.",
        "MessageArgs": [
          "null",
          "Password"
        ],
        "MessageId": "Base.1.19.PropertyValueFormatError",
        "MessageSeverity": "Warning",
        "Resolution": "Correct the value for the property in the request body and resubmit the request if the operation failed."
      }
    ],
    "code": "Base.1.19.PropertyValueFormatError",
    "message": "The value 'null' for the property Password is not a format that the property can accept."
  }
}
```

Tested:
- Check those response messages

Change-Id: I746c55e42e8f0cde205a3800e3da17cd78cf7e34
Signed-off-by: Myung Bae &lt;myungbae@us.ibm.com&gt;
</content>
</entry>
<entry>
<title>Move to Redfish 2026.1</title>
<updated>2026-05-19T19:16:28+00:00</updated>
<author>
<name>Gunnar Mills</name>
<email>gmills@us.ibm.com</email>
</author>
<published>2026-05-19T19:16:28+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=df2c4aac86d556cd3d618588ce819d63c3e01caf'/>
<id>urn:sha1:df2c4aac86d556cd3d618588ce819d63c3e01caf</id>
<content type='text'>
One line change and rerun the script. 2026.1 includes new properties.
The overview is at [1].

[1]: https://www.dmtf.org/sites/default/files/Redfish_Release_2026.1_Overview.pdf

Tested: Inspection only.

Change-Id: I007f074128e278fb267ee4de3b9cbab22d6336df
Signed-off-by: Gunnar Mills &lt;gmills@us.ibm.com&gt;
</content>
</entry>
<entry>
<title>Port update_schemas script to use git</title>
<updated>2026-05-19T16:47:29+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>etanous@nvidia.com</email>
</author>
<published>2026-04-29T22:24:19+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=7038a05f4ee20ae465d21901e6a73f11e9043ada'/>
<id>urn:sha1:7038a05f4ee20ae465d21901e6a73f11e9043ada</id>
<content type='text'>
DMTF released Redfish-Publications a while ago.  Recently, they've
started blocking scripts from accessing the website.

This is fully vibe coded with some review by me, but seems to produce
the same result we had previously, and if there were differences they'd
show up in review.

Change-Id: Ib3686b610ca6a60b1fae12b575042575b32f6ec5
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
<entry>
<title>Fix PayloadTooLarge to return HTTP 413</title>
<updated>2026-05-12T15:52:23+00:00</updated>
<author>
<name>Rajeev Ranjan</name>
<email>ranjan.rajeev1609@gmail.com</email>
</author>
<published>2026-05-12T15:13:39+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=81dbaae64b3f5ec42d16f5642165dd639032cc6c'/>
<id>urn:sha1:81dbaae64b3f5ec42d16f5642165dd639032cc6c</id>
<content type='text'>
Previously, PayloadTooLarge errors incorrectly returned HTTP 400 Bad
Request. This change fixes the HTTP status to 413 Payload Too Large per
RFC 7231 so the response code matches the Base.PayloadTooLarge message
the service already emits.

Root cause: scripts/parse_registries.py is the generator that produces
redfish-core/src/error_messages.cpp. Its get_response_code() lookup
table did not list PayloadTooLarge, so the generator emitted the
default boost::beast::http::status::bad_request. Adding
"PayloadTooLarge": "payload_too_large" to the table fixes the
generator.

Change-Id: I6583b1156ffa4a6b4c99b8a5c82fdcb76ca3a13c
Signed-off-by: Rajeev Ranjan &lt;ranjan.rajeev1609@gmail.com&gt;
</content>
</entry>
<entry>
<title>bmcweb: Return HTTP 409 for resource conflict errors</title>
<updated>2026-03-23T15:24:49+00:00</updated>
<author>
<name>Christian Walter</name>
<email>christian.walter@9elements.com</email>
</author>
<published>2026-03-19T11:30:00+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=793bce1895f015ae27a0ce5fa4c75e38c2dadfd6'/>
<id>urn:sha1:793bce1895f015ae27a0ce5fa4c75e38c2dadfd6</id>
<content type='text'>
Change ResourceAlreadyExists from HTTP 400 Bad Request to HTTP 409
Conflict. While the Redfish specification (DSP0266 v1.23.1) does not
explicitly mandate to return 409 it makes more sense because:

- HTTP 400 implies a malformed request which this is clearly not
- HTTP 409 is defined in Table 13 of DSP0266 as Creation or update
  request could not be completed because it causes a conflict in the
  current state of the resource which is what happens.

Also mapping ResourceCreationConflict to 409 for the same reason even
even though its currently not used in the codebase.

Tested: POST to create a duplicate user account now returns HTTP 409
with ResourceAlreadyExists message instead of HTTP 400. The
ResourceCreationConflict message is not used in the codebase and can
not be tested.

Change-Id: Id482e5e4f7b3d6ca56228f9d763c95aa50c9856f
Signed-off-by: Christian Walter &lt;christian.walter@9elements.com&gt;
</content>
</entry>
<entry>
<title>Add port and timeout args to generate_auth_certificates</title>
<updated>2026-03-05T23:08:28+00:00</updated>
<author>
<name>Igor Kanyuka</name>
<email>ifelmail@gmail.com</email>
</author>
<published>2026-02-24T09:02:19+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=40c288a6672019b1b4124e0a6528ebb49ddc3a52'/>
<id>urn:sha1:40c288a6672019b1b4124e0a6528ebb49ddc3a52</id>
<content type='text'>
If target BMC image is deployed in QEMU, port is typically non std one,
and since it's being emulated, it's typically slower. As result, the
script fails trying to connect to port 443 and not all operations finish
within default 5 seconds timeout. So, add parameters which allow to
override port and timeout to accommodate tests of images running in
QEMU.

Tested: Ran this against QEMU instance, passed 8443 as port and 30.0 as
the timeout, worked fine.

Change-Id: Ib3d9fa0e9cef87dba2f35b38f33dc8186ad0b4b8
Signed-off-by: Igor Kanyuka &lt;ifelmail@gmail.com&gt;
</content>
</entry>
<entry>
<title>Replace deprecated arguments</title>
<updated>2026-02-24T12:50:11+00:00</updated>
<author>
<name>Igor Kanyuka</name>
<email>ifelmail@gmail.com</email>
</author>
<published>2026-02-24T07:38:04+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=8cb23041896e5fdaf585ac0ed3b09537a6f89213'/>
<id>urn:sha1:8cb23041896e5fdaf585ac0ed3b09537a6f89213</id>
<content type='text'>
httpx deprecated [1] passing CA as verify and certs as tuple and now the
code does not work as expected. Replace these values with ssl context as
suggested.

Tested: Ran the script and it worked.

[1] https://github.com/encode/httpx/blob/master/httpx/_config.py#L45-L63

Change-Id: Ifb90e8e978e63b94b7a0f149d226841ceaa20658
Signed-off-by: Igor Kanyuka &lt;ifelmail@gmail.com&gt;
</content>
</entry>
<entry>
<title>Move clang-off / clang-on to catch scope</title>
<updated>2026-01-26T20:35:54+00:00</updated>
<author>
<name>Gunnar Mills</name>
<email>gmills@us.ibm.com</email>
</author>
<published>2026-01-26T15:54:22+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=ac69e77ea938e8c2a5bd3dad258cdafd9d3182b7'/>
<id>urn:sha1:ac69e77ea938e8c2a5bd3dad258cdafd9d3182b7</id>
<content type='text'>
As a comment in https://gerrit.openbmc.org/c/openbmc/bmcweb/+/86868
suggested "You might also consider moving this up a line so you catch
the scope on both sides."

This enforces just the slightest bit more clang-format.

Rerun script.

Tested: Builds. Manual changes to script only. Rest generated.

Change-Id: I8ff01befc56c576716f5d83bd90763354b1ff0c5
Signed-off-by: Gunnar Mills &lt;gmills@us.ibm.com&gt;
</content>
</entry>
<entry>
<title>Rename switch namespace</title>
<updated>2026-01-26T20:30:22+00:00</updated>
<author>
<name>Gunnar Mills</name>
<email>gmills@us.ibm.com</email>
</author>
<published>2026-01-26T15:42:08+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=6bb8c608e8c854fd4ff2e5b0d2908480b763746f'/>
<id>urn:sha1:6bb8c608e8c854fd4ff2e5b0d2908480b763746f</id>
<content type='text'>
switch is a reserved keyword in C++.. Therefore "namespace switch" is
illegal C++ code.

Add a couple lines of python code to check for keywords and then rename
with a rf_ at the front, e.g. namespace rf_switch.

Rerun the script update_schemas.py script.

This showed downstream, but probably would have upstream too.

```
switch.hpp:8:11: error: expected identifier or '{' [clang-diagnostic-error]
    8 | namespace switch
      |           ^
.../bmcweb/redfish-core/include/generated/enums/switch.hpp:8:11: error: expected unqualified-id [clang-diagnostic-error]

...

FAILED: meson-internal__clang-tidy-fix
```

Change-Id: I58be67fc0df6e5056e63da5302724e6509b7114b
Signed-off-by: Gunnar Mills &lt;gmills@us.ibm.com&gt;
</content>
</entry>
</feed>
