<feed xmlns='http://www.w3.org/2005/Atom'>
<title>BMC/OpenBmc/bmcweb.git/src, branch master</title>
<subtitle>A do everything Redfish, KVM, GUI, and DBus webserver for OpenBMC (mirror)</subtitle>
<id>https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/atom?h=master</id>
<link rel='self' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/'/>
<updated>2026-09-25T06:23:12+00:00</updated>
<entry>
<title>ssl_key_handler: Avoid redundant c_str() call</title>
<updated>2026-09-25T06:23:12+00:00</updated>
<author>
<name>Yuvakumar Selvamani</name>
<email>yuvakumars@ami.com</email>
</author>
<published>2026-09-18T06:39:18+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=c498b1971a1225229b7c4525485c7ecfcba5aa0f'/>
<id>urn:sha1:c498b1971a1225229b7c4525485c7ecfcba5aa0f</id>
<content type='text'>
std::filesystem::remove() already accepts a std::filesystem::path
directly. Calling certPath.c_str() first converts the path to a const
char*, which is then implicitly re-converted back into a temporary path
object - an unnecessary round-trip. Pass certPath directly instead.

Found during review of Ia8cfbbc8eeefa6f6cc3bd8d291d93876cc869d47c
(https://gerrit.openbmc.org/c/openbmc/bmcweb/+/94314), raised as a
separate change per reviewer request since that change is a pure
refactor already approved.

Tested:
- Tested on AST2600 SoC. Triggered a real hostname-change D-Bus signal
  (busctl set-property .../network/config
  xyz.openbmc_project.Network.SystemConfiguration HostName s
  "&lt;NEW_HOSTNAME&gt;") to exercise installCertificate() end-to-end.
  journalctl -u bmcweb confirmed the fixed remove(certPath, ec2) call
  ran and logged "Replace HTTPs Certificate Success", and the temp file
  (/tmp/hostname_cert.tmp) was removed as expected.
- Verified the new cert was actually installed and served:

    $ curl -sk -v https://BMC_IP/redfish/v1/ -o /dev/null 2&gt;&amp;1 | \
      grep subject:
    *  subject: C=US; O=OpenBMC; CN=&lt;NEW_HOSTNAME&gt;

- Verified Redfish still healthy post-reload:

    $ curl -sk -u BMC_USER:BMC_PASS \
        -o /dev/null -w "HTTP %{http_code}\n" \
        https://BMC_IP/redfish/v1/Managers/bmc
    HTTP 200

- Redfish Service Validator: 5830 Pass / 353 Warn / 0 Fail.

Change-Id: If60533899dbbc84bb151e282e83f22ef636eb119
Signed-off-by: Yuvakumar Selvamani &lt;yuvakumars@ami.com&gt;
</content>
</entry>
<entry>
<title>Refactor installCertificate lambda</title>
<updated>2026-09-18T09:07:11+00:00</updated>
<author>
<name>Yuvakumar Selvamani</name>
<email>yuvakumars@ami.com</email>
</author>
<published>2026-08-20T07:17:46+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=64c35733b1b7f0a90de0e97cb396c78211d8aa52'/>
<id>urn:sha1:64c35733b1b7f0a90de0e97cb396c78211d8aa52</id>
<content type='text'>
Extract the long D-Bus async_method_call callback lambda in the former
installCertificate() into a named function, afterInstallCertificate(),
bound via std::bind_front() and wrapped in std::function, per the &lt;10
line lambda coding standard in docs/COMMON_ERRORS.md.

installCertificate() was a static, single-caller wrapper, so its body is
now inlined directly into its only caller,
regenerateCertificateIfHostnameChanged(), removing the redundant
indirection.

Tested:
- Tested on AST2600 SoC. Triggered a real hostname-change D-Bus signal
  (busctl set-property .../network/config
  xyz.openbmc_project.Network.SystemConfiguration HostName s "bmc-test")
  to exercise regenerateCertificateIfHostnameChanged() end-to-end.
  journalctl -u bmcweb confirmed the new afterInstallCertificate()
  callback ran and logged "Replace HTTPs Certificate Success" after the
  real Certs.Replace D-Bus call, and the temp file
  (/tmp/hostname_cert.tmp) was removed as expected.
- Verified the new cert was actually installed and served:

  $ curl -sk -v https://BMC_IP/redfish/v1/ -o /dev/null 2&gt;&amp;1 | grep \
  subject:
   *  subject: C=US; O=OpenBMC; CN=bmc-test

- Verified Redfish still healthy post-reload:

  $ curl -sk -u BMC_USER:BMC_PASS -o /dev/null -w "HTTP %{http_code}\n"\
    https://BMC_IP/redfish/v1/Managers/bmc
  HTTP 200

- Redfish Service Validator: 5830 Pass / 353 Warn / 0 Fail.

Change-Id: I8cfbbc8eeefa6f6cc3bd8d291d93876cc869d47c
Signed-off-by: Yuvakumar Selvamani &lt;yuvakumars@ami.com&gt;
</content>
</entry>
<entry>
<title>webserver_cli: Refactor setLogLevel lambda</title>
<updated>2026-09-17T14:06:21+00:00</updated>
<author>
<name>Yuvakumar Selvamani</name>
<email>yuvakumars@ami.com</email>
</author>
<published>2026-08-20T07:17:46+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=f0f7c0ead3bb69e89cc29521ea400429f5cf1b68'/>
<id>urn:sha1:f0f7c0ead3bb69e89cc29521ea400429f5cf1b68</id>
<content type='text'>
Extract the long D-Bus async_method_call callback lambda in
setLogLevel() into a named function, afterSetLogLevel(), bound via
std::bind_front() and wrapped in std::function, per the &lt;10 line lambda
coding standard in docs/COMMON_ERRORS.md. Also take the D-Bus error_code
callback parameter by const reference instead of a mutable reference,
per review comment.

Tested:
- Ran `bmcweb loglevel debug` on a running BMC against the live
  bmcweb daemon's xyz.openbmc_project.bmcweb SetLogLevel D-Bus
  method. The async_method_call completed through the new
  afterSetLogLevel() callback, printed "logging level changed to:
  DEBUG", and the CLI process exited 0.
- Confirmed the level change actually took effect on the daemon: a
  subsequent Redfish GET request produced verbose DEBUG-level trace
  lines in `journalctl -u bmcweb` (e.g. http2_connection.hpp,
  http_body.hpp entries) that are suppressed at the default INFO
  level.
- Redfish Service Validator passed with 0 failures (5822 Pass / 353
  Warn / 0 Fail).

Change-Id: I7ee42c25996cc6da98eab4af4535de0f95e110cd
Signed-off-by: Yuvakumar Selvamani &lt;yuvakumars@ami.com&gt;
</content>
</entry>
<entry>
<title>Allow setting Mozilla modern</title>
<updated>2026-07-02T18:30:22+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>etanous@nvidia.com</email>
</author>
<published>2026-05-26T20:28:59+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=917fbad478cf5db4a79944d59a4927207adf49d1'/>
<id>urn:sha1:917fbad478cf5db4a79944d59a4927207adf49d1</id>
<content type='text'>
Mozilla publishes recommendations for TLS cipher suites to support.  For
many years bmcweb selected "intermediate" because of compatibility with
clients that didn't yet support TLS1.3.

This commit adds the ability to use the Mozilla modern recommendations,
and disable TLS1.2 support through a new meson option, tls-profile.

Tested:

Loaded on qemu, and verified with testssl.sh[1] that parameters were
applied.

[1] https://github.com/testssl/testssl.sh

Change-Id: I38e915b3943b5dbe5fb31e54eb3ebda9bbaeb811
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
<entry>
<title>Flag long lambdas</title>
<updated>2026-07-01T17:10:08+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>etanous@nvidia.com</email>
</author>
<published>2026-06-22T16:53:17+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=8176ae6778015743b77e8744c046bc50edf13cc4'/>
<id>urn:sha1:8176ae6778015743b77e8744c046bc50edf13cc4</id>
<content type='text'>
Long lambdas have been documented as an anti-pattern for some time.[1]
Despite this being generally understood, bmcweb has a long ways to go
cleaning these up, and routinely code is submitted in violation of this
anti-pattern.

Invent an ast-grep rule that can identify when new examples of this
anti-pattern are added, and ignore the existing 200+ examples that are
in the codebase already using ast-grep ignore.  These flags will give us
something to search for as we clean this up, and will help to prevent
new instances from being added unintentionally.

[1] https://github.com/openbmc/docs/blob/master/anti-patterns.md#very-long-lambda-callbacks

Tested: Comment only change.  ast-grep passes.  Manually removing an
ast-grep ignore flag shows as a failure in ast-grep scan

Change-Id: I77d634a393884969f184d2c39c02cc08288d5a29
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
<entry>
<title>Generate 64 bit serial numbers</title>
<updated>2026-06-12T16:01:54+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>ed@tanous.net</email>
</author>
<published>2026-05-26T21:29:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=e5cd5009b23255637dd7f11701a65d8c8fa09b88'/>
<id>urn:sha1:e5cd5009b23255637dd7f11701a65d8c8fa09b88</id>
<content type='text'>
Even though the certificate is self signed, we should pass as many
certificate tests as possible.  testssl.sh prints
```
 Serial 4B32D4F0   NOT ok: length should be &gt;= 64 bits entropy (is: 4 bytes)
```

On our default certificate.  This is relatively easy to fix.

Change-Id: Ib1eb07b637ebf49ecf954b3d98ced9e9ef0f5a34
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
<entry>
<title>OpenSSL cleanup</title>
<updated>2026-06-12T16:01:54+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>etanous@nvidia.com</email>
</author>
<published>2026-04-27T21:12:01+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=048cb1125f42cf748218a3258faeb2e868d1e3cb'/>
<id>urn:sha1:048cb1125f42cf748218a3258faeb2e868d1e3cb</id>
<content type='text'>
Continue moving OpenSSL into reusable RAII classes that can be used in
unit tests and other places.  This is slightly more code, but as we're
adding unit tests, it allows reuse between unit tests rather than
writing C directly.  It also encapsulates the complexity of parsing
openssl output (usually in bytes) into standard types (string) that can
be compared/modified.

Functionally this adds two new classes to the "wrappers" functions,
OpenSSLSSLCtx and OpenSSLSSL, which each wrap SSL_CTX and SSL objects
respectively from openssl.  These are rough approximations of the boost
equivalents.

Change-Id: Id87ac4ccde88890bd70861deffdb256188ec0e39
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
<entry>
<title>account_service: invalidate sessions when account is disabled</title>
<updated>2026-06-08T15:23:04+00:00</updated>
<author>
<name>Chandramohan Harkude</name>
<email>chandramohan.harkude@gmail.com</email>
</author>
<published>2026-05-18T07:30:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=430b30bd5f800b5c7dc0b2bd856f71f72b93c785'/>
<id>urn:sha1:430b30bd5f800b5c7dc0b2bd856f71f72b93c785</id>
<content type='text'>
PATCH /redfish/v1/AccountService/Accounts/ with {"Enabled":false}
flipped UserEnabled on D-Bus but left every active X-Auth-Token session
for that user fully usable. Subsequent token-authenticated requests
continued to succeed (200 OK) until the token's natural expiry, even
though Basic auth for the same account was correctly rejected (401).
DELETE on the same resource does not have this problem because removing
the user object emits InterfacesRemoved, and bmcweb::onUserRemoved (in
include/user_monitor.hpp) handles that signal by calling
removeSessionsByUsername.

Add onUserPropertiesChanged() in include/user_monitor.hpp that drops
the user's sessions via SessionStore::removeSessionsByUsername() when
User.Attributes.UserEnabled transitions to false.
This handles disable of user both from IPMI and Redfish

Tested :

```
Create new user

curl -k -u ${USER}:${PASSWD} -X POST
https://127.0.0.1:2443/redfish/v1/AccountService/Accounts -d '{
UserName:test_admin, Password:Shahapur#13!Shahapur, RoleId:Administrator, Enabled:true}'
{
  "@Message.ExtendedInfo": [
    {
      "@odata.type": "#Message.v1_1_1.Message",
      "Message": "The resource was created successfully.",
      "MessageArgs": [],
      "MessageId": "Base.1.19.Created",
      "MessageSeverity": "OK",
      "Resolution": "None."
    }
  ]
}

Create a-auth-token
curl --insecure -X POST -D headers.txt https://127.0.0.1:2443/redfish/v1/SessionService/Sessions -d '{"UserName":"test_admin", "Password":"Shahapur#13!Shahapur"}'
{
  "@odata.id": "/redfish/v1/SessionService/Sessions/YLMzEtANWr",
  "@odata.type": "#Session.v1_7_0.Session",
  "ClientOriginIPAddress": "10.0.2.2",
  "Description": "Manager User Session",
  "Id": "YLMzEtANWr",
  "Name": "User Session",
  "Roles": [
    "Administrator"
  ],
  "UserName": "test_admin"
}
$ cat headers.txt
HTTP/2 201
allow: GET, HEAD, POST
odata-version: 4.0
x-auth-token: VcufgTshiDjEn8HbGh31
location: /redfish/v1/SessionService/Sessions/YLMzEtANWr
strict-transport-security: max-age=31536000; includeSubdomains
pragma: no-cache
cache-control: no-store, max-age=0
x-content-type-options: nosniff
content-type: application/json
date: Wed, 06 May 2026 12:45:18 GMT
content-length: 305

// Test RF request with token
curl -k -H 'x-auth-token:VcufgTshiDjEn8HbGh31' https://127.0.0.1:2443/redfish/v1/AccountService/Accounts
{
  "@odata.id": "/redfish/v1/AccountService/Accounts",
  "@odata.type": "#ManagerAccountCollection.ManagerAccountCollection",
  "Description": "BMC User Accounts",
  "Members": [
    {
      "@odata.id": "/redfish/v1/AccountService/Accounts/test_admin"
    },
    {
      "@odata.id": "/redfish/v1/AccountService/Accounts/root"
    }
  ],
  "Members@odata.count": 2,
  "Name": "Accounts Collection"
}

// Disable the user
curl -k -u root:0penBmc https://127.0.0.1:2443/redfish/v1/AccountService/Accounts/test_admin -X PATCH  -d '{"Enabled":false}'
204

// Try to use the Tokens
curl -k -H 'x-auth-token:VcufgTshiDjEn8HbGh31' https://127.0.0.1:2443/redfish/v1/AccountService/Accounts
401

```
Change-Id: I3246d3f5ec7db405c9c186a8672a9fed18259249
Signed-off-by: Chandramohan Harkude &lt;chandramohan.harkude@gmail.com&gt;
</content>
</entry>
<entry>
<title>conversion cast to fix build</title>
<updated>2026-04-30T15:51:16+00:00</updated>
<author>
<name>Alexander Hansen</name>
<email>alexander.hansen@9elements.com</email>
</author>
<published>2026-04-29T12:39:39+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=d6a9e09897b5ed8524e0d6533e6dab80d612dfdc'/>
<id>urn:sha1:d6a9e09897b5ed8524e0d6533e6dab80d612dfdc</id>
<content type='text'>
The compile error was also mentioned here: [1]

```
| ../sources/bmcweb-1.0+git/src/ssl_key_handler.cpp:293:61: error: conversion from 'std::chrono::duration&lt;long long int&gt;::rep' {aka 'long long int'} to 'long int' may change value [-Werror=conversion]
|   293 |     X509_gmtime_adj(X509_getm_notAfter(x509), duration.count());
|       |                                               ~~~~~~~~~~~~~~^~
| cc1plus: all warnings being treated as errors
```

The relevant function signature only accepts 'long' anyways, so assuming
that is what the authors intention was.

```
ASN1_TIME *X509_gmtime_adj(ASN1_TIME *s, long adj);
```

Looking at the value of `duration.count()` it is `315569520`
which is representable by a 32-bit signed integer type.

References:
[1] https://gerrit.openbmc.org/c/openbmc/openbmc/+/89780/comments/d1fbedfb_3eca650e

Change-Id: Idecb18acc4c7862d0ca56efd090736cacbdd8164
Signed-off-by: Alexander Hansen &lt;alexander.hansen@9elements.com&gt;
</content>
</entry>
<entry>
<title>Add more unit tests for UPN functionality</title>
<updated>2026-04-27T18:51:54+00:00</updated>
<author>
<name>Igor Kanyuka</name>
<email>ikanyuka@fb.com</email>
</author>
<published>2026-04-10T10:46:15+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=5d4a41fa7b46d7badbde21b9f76b4cdcff7d4c64'/>
<id>urn:sha1:5d4a41fa7b46d7badbde21b9f76b4cdcff7d4c64</id>
<content type='text'>
Current unit tests only covers happy path. Add more unit tests before
changing the code.

Tested: unit tests

Change-Id: Ibba5dbbc1457b59670d5d8f3c828fa9ca112f88c
Signed-off-by: Igor Kanyuka &lt;ifelmail@gmail.com&gt;
</content>
</entry>
</feed>
