<feed xmlns='http://www.w3.org/2005/Atom'>
<title>BMC/OpenBmc/bmcweb.git/test/http, branch master</title>
<subtitle>A do everything Redfish, KVM, GUI, and DBus webserver for OpenBMC (mirror)</subtitle>
<id>https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/atom?h=master</id>
<link rel='self' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/'/>
<updated>2026-07-24T17:31:51+00:00</updated>
<entry>
<title>Add Fuzz target</title>
<updated>2026-07-24T17:31:51+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>etanous@nvidia.com</email>
</author>
<published>2026-04-24T18:06:16+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=e05fbc05005db284f418f8517d215c97b9b189f4'/>
<id>urn:sha1:e05fbc05005db284f418f8517d215c97b9b189f4</id>
<content type='text'>
Recently, oss-fuzz added support for bmcweb, but did it by checking in
a number of code patches.  This commit should get similar coverage by
hooking into the HTTP connection class, and using the unit test
code to inject bytes directly into a stream.  This can be improved over
time, but this is a good start.

Change-Id: I20b5d536cff1588a8387f2770c022516e1cd62d0
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
<entry>
<title>Remove final IWYU hints</title>
<updated>2026-07-24T17:21:42+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>ed@tanous.net</email>
</author>
<published>2026-07-07T03:00:03+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=11e88573dd314feae0e01643b2708d46356293d9'/>
<id>urn:sha1:11e88573dd314feae0e01643b2708d46356293d9</id>
<content type='text'>
IWYU is not a tool we have seen results from in some time.  I very much
suspect that these few comments are not enough to get a clean build.

Clean them up.  If we want to turn this tool back on in the future,
this patch can be reverted.

Tested: Comment only change.  Review only.

Change-Id: I45ff737800f9d8b1b63db2f482e59f815d7126a2
Signed-off-by: Ed Tanous &lt;ed@tanous.net&gt;
</content>
</entry>
<entry>
<title>Implement Response header count</title>
<updated>2026-07-22T18:29:44+00:00</updated>
<author>
<name>Joel P J</name>
<email>joelpj@ami.com</email>
</author>
<published>2026-07-03T13:10:06+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=bb662f2ad11548ec4600d651e58b205b38b43cc9'/>
<id>urn:sha1:bb662f2ad11548ec4600d651e58b205b38b43cc9</id>
<content type='text'>
Add Response::headerCount() to return the total number of
stored header fields on a response. The implementation counts
the current header entries directly from the underlying Beast
header container.

Added unit coverage to verify the method reports the full
header count after headers are added through the normal
addHeader() path.

Tested with:
meson test -C build http_response_test --print-errorlogs

This helper is used by response unit tests to verify that only
the expected headers are present and that no unexpected headers
are added to the response. See also:
https://gerrit.openbmc.org/c/openbmc/bmcweb/+/91848

Change-Id: I28432bb4fc982db44cee0688395d04ac513d6749
Signed-off-by: Joel Pullokaran Jesin &lt;joelpj@ami.com&gt;
</content>
</entry>
<entry>
<title>Updating maxValues to support roughly 200 bmcweb sessions</title>
<updated>2026-07-09T19:21:12+00:00</updated>
<author>
<name>Rick Yazwinski</name>
<email>rickyaz@meta.com</email>
</author>
<published>2026-07-06T20:08:40+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=93ec859f5d20eef343ddc3f003cc2d36ec9dcb08'/>
<id>urn:sha1:93ec859f5d20eef343ddc3f003cc2d36ec9dcb08</id>
<content type='text'>
parseStringAsJson() routes through BmcwebSaxParse, which hard-caps a
payload at 500 total JSON values to defend against malicious external
HTTP request bodies.

The most visible symptom is that bmcweb silently loses every persisted
session across a restart once ~50 sessions accumulate (each persisted
session is ~11 JSON values, so the file trips the cap and is treated
as malformed).  Tntegration testing hit this 50 session limit and
failed. (Was failing our internal but also the
openbmc-test-automation robot suite)

I had originally implemented a solution as a "trusted reader"
with no limit
( https://gerrit.openbmc.org/c/openbmc/bmcweb/+/90138 ); however,
the security implications of "no limit" weren't attractive.
This area may be refactored in the near future to represent each
session as a distinct json file.  This value bump gets us past
the immediate needs without introducing a lot of churn in code
that will be refactored.

Change-Id: Ifd3514bd8ee15c8bdf1b6c2119451a2965801671
Signed-off-by: Rick Yazwinski &lt;rickyaz@meta.com&gt;
</content>
</entry>
<entry>
<title>http2: pass client IP address to HTTP/2 requests</title>
<updated>2026-06-15T23:55:11+00:00</updated>
<author>
<name>Vijaysankar Ravi</name>
<email>vijaysankarr@ami.com</email>
</author>
<published>2026-06-11T10:36:30+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=c91086487c8215cfd9eaa4b7a3b699430d9c25d4'/>
<id>urn:sha1:c91086487c8215cfd9eaa4b7a3b699430d9c25d4</id>
<content type='text'>
HTTP/2 connections were not passing the resolved client IP into
the per-request ipAddress field, causing sessions to report
0.0.0.0 instead of the actual client address.

Additionally, authentication::authenticate() was called with an
empty IP, resulting in Basic Auth sessions being created with
an incorrect clientIp in the session store.

Pass the IP through the HTTP2Connection constructor, use it in
the authenticate() call, and assign it to req-&gt;ipAddress during
request dispatch in onRequestRecv.

Tested:
- Client IP correctly displayed in Redfish SessionService
  on HTTP/2 connections.
- Before patch: ClientOriginIPAddress showed "0.0.0.0"
- After patch: ClientOriginIPAddress shows actual client IP
- Redfish Service Validator (v3.1.4) passed on
  /redfish/v1/SessionService tree:
  PASS: 44, WARN: 0, FAIL: 0, NOT TESTED: 41

Before:
curl -k https://127.0.0.1:2443/redfish/v1/\
SessionService/Sessions/O9gUpSoxbe -u root:0penBmc
{
  "@odata.id": "/redfish/v1/SessionService/Sessions/O9gUpSoxbe",
  "@odata.type": "#Session.v1_7_0.Session",
  "ClientOriginIPAddress": "0.0.0.0",
  "Description": "Manager User Session",
  "Id": "O9gUpSoxbe",
  "Name": "User Session",
  "Roles": [
    "Administrator"
  ],
  "UserName": "root"
}

After this patch:
curl -k https://172.31.216.225/redfish/v1/\
SessionService/Sessions/LuttjprSGD -u root:0penBmc
{
  "@odata.id": "/redfish/v1/SessionService/Sessions/LuttjprSGD",
  "@odata.type": "#Session.v1_7_0.Session",
  "ClientOriginIPAddress": "10.0.136.165",
  "Description": "Manager User Session",
  "Id": "LuttjprSGD",
  "Name": "User Session",
  "Roles": [
    "Administrator"
  ],
  "UserName": "root"
}

Change-Id: I223e5c90448419ba87b690de38cc5e69ffb6a0c3
Signed-off-by: Vijaysankar Ravi &lt;vijaysankarr@ami.com&gt;
</content>
</entry>
<entry>
<title>OpenSSL cleanup</title>
<updated>2026-06-12T16:01:54+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>etanous@nvidia.com</email>
</author>
<published>2026-04-27T21:12:01+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=048cb1125f42cf748218a3258faeb2e868d1e3cb'/>
<id>urn:sha1:048cb1125f42cf748218a3258faeb2e868d1e3cb</id>
<content type='text'>
Continue moving OpenSSL into reusable RAII classes that can be used in
unit tests and other places.  This is slightly more code, but as we're
adding unit tests, it allows reuse between unit tests rather than
writing C directly.  It also encapsulates the complexity of parsing
openssl output (usually in bytes) into standard types (string) that can
be compared/modified.

Functionally this adds two new classes to the "wrappers" functions,
OpenSSLSSLCtx and OpenSSLSSL, which each wrap SSL_CTX and SSL objects
respectively from openssl.  These are rough approximations of the boost
equivalents.

Change-Id: Id87ac4ccde88890bd70861deffdb256188ec0e39
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
<entry>
<title>http: zstd: do not attempt compressing already opened files</title>
<updated>2026-06-01T22:28:11+00:00</updated>
<author>
<name>Tan Siewert</name>
<email>tan.siewert@9elements.com</email>
</author>
<published>2026-05-21T08:53:48+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=5f15b5f014bf778f22431935db4fa486e18efe96'/>
<id>urn:sha1:5f15b5f014bf778f22431935db4fa486e18efe96</id>
<content type='text'>
Commit 2d7dc991 changed the body storage from being saved in a separate
field to a std::variant. Calling str() calls emplace&lt;std::string&gt;(),
which destroys the active FileBody in-place on file-backed bodies (e.g.
the Web UI) and closes the FD.
Any subsequent action now tries to access a non-existing FD (dummy
handle returning -1 as FD.)

Fix by returning early from `attemptZstdCompression` when the body is
file-backed, as file-backed bodies are already handled by the streaming
zstdCompressor in the writer.

Tested: cURL with "Accept-Encoding: zstd" to favicon.ico, ensuring that
        it returns data again.

Fixes: 2d7dc991 ("Optimize bmcweb memory usage for multipart fw
                  update")
Change-Id: Ia54712f89d8c5f7dc9ce7c5d040aed06e8f6fded
Signed-off-by: Tan Siewert &lt;tan.siewert@9elements.com&gt;
</content>
</entry>
<entry>
<title>Remove unneeded test</title>
<updated>2026-05-17T18:02:09+00:00</updated>
<author>
<name>Igor Kanyuka</name>
<email>ifelmail@gmail.com</email>
</author>
<published>2026-04-29T14:07:24+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=988497880d3e5de891edd4394d221c5df6ac7487'/>
<id>urn:sha1:988497880d3e5de891edd4394d221c5df6ac7487</id>
<content type='text'>
After RAII change code accepts UTF8 only, so the code doesn't use
non-UTF8. This test uses ASCII that is UTF8 and duplicates other tests,
so remove NonUTF8UPNSubjectAlternativeName test.

Tested:
Unit tests

Change-Id: I48b8f0cbf644abce99a864e9dccd23f308693908
Signed-off-by: Igor Kanyuka &lt;ifelmail@gmail.com&gt;
</content>
</entry>
<entry>
<title>Fix bad merge resolution</title>
<updated>2026-05-13T17:51:06+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>etanous@nvidia.com</email>
</author>
<published>2026-05-12T23:45:48+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=86a6fab2b029bc72f14b6b63973fd1ed3a20e745'/>
<id>urn:sha1:86a6fab2b029bc72f14b6b63973fd1ed3a20e745</id>
<content type='text'>
There was a regression on json parsing due to a merge conflict
resolution on 2d7dc991600297d04e50d7958fe9611f9ac42bcf.  Update the
connection unit tests to test the body catching this case, and fix the
error.

Tested: Unit tests pass.  Redfish service validator passes

Change-Id: I4ad8802b7c75001ca7a2b1619af2f368bfe448ee
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
Signed-off-by: Gunnar Mills &lt;gmills@us.ibm.com&gt;
</content>
</entry>
<entry>
<title>Add more unit tests for UPN functionality</title>
<updated>2026-04-27T18:51:54+00:00</updated>
<author>
<name>Igor Kanyuka</name>
<email>ikanyuka@fb.com</email>
</author>
<published>2026-04-10T10:46:15+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=5d4a41fa7b46d7badbde21b9f76b4cdcff7d4c64'/>
<id>urn:sha1:5d4a41fa7b46d7badbde21b9f76b4cdcff7d4c64</id>
<content type='text'>
Current unit tests only covers happy path. Add more unit tests before
changing the code.

Tested: unit tests

Change-Id: Ibba5dbbc1457b59670d5d8f3c828fa9ca112f88c
Signed-off-by: Igor Kanyuka &lt;ifelmail@gmail.com&gt;
</content>
</entry>
</feed>
