<feed xmlns='http://www.w3.org/2005/Atom'>
<title>BMC/OpenBmc/bmcweb.git/test/include, branch master</title>
<subtitle>A do everything Redfish, KVM, GUI, and DBus webserver for OpenBMC (mirror)</subtitle>
<id>https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/atom?h=master</id>
<link rel='self' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/'/>
<updated>2026-08-28T15:36:23+00:00</updated>
<entry>
<title>Add unit tests for security headers</title>
<updated>2026-08-28T15:36:23+00:00</updated>
<author>
<name>Joel P J</name>
<email>joelpj@ami.com</email>
</author>
<published>2026-06-30T05:07:48+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=43d0cb81b162832ada3969f34409ca11d6e7ba26'/>
<id>urn:sha1:43d0cb81b162832ada3969f34409ca11d6e7ba26</id>
<content type='text'>
Add unit tests for the security header helper.

Cover headers that are always added, preserve existing Cache-Control
values, and verify the HTML-only header path.

Also validate representative Content-Security-Policy and
Permissions-Policy values so future header regressions are caught by
unit test coverage.

Tested:
Passed local CI docker run for bmcweb unit tests

Change-Id: I069d203f6bc35155d17d8488ab5511aa38218f3a
Signed-off-by: Joel P J &lt;joelpj@ami.com&gt;
</content>
</entry>
<entry>
<title>Detect HTML content type with existing parser</title>
<updated>2026-07-16T17:21:50+00:00</updated>
<author>
<name>Joel Pullokaran Jesin</name>
<email>joelpj@ami.com</email>
</author>
<published>2026-07-13T13:34:58+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=d7744feb85a79ebb9069a5a0c2afa6f56c6f9f4a'/>
<id>urn:sha1:d7744feb85a79ebb9069a5a0c2afa6f56c6f9f4a</id>
<content type='text'>
Use http_helpers::getContentType() when deciding whether to add
HTML-only security headers.

Previously this logic checked the raw Content-Type header with a
text/html prefix match. That worked for the values we emit today,
but it open-coded Content-Type handling in this path instead of using
the existing parser.

Switch this logic to getContentType() so it stays consistent with
the rest of the code and correctly handles valid variations such as
case-insensitive HTML MIME types.

Add unit coverage for getContentType() to verify HTML MIME types
with charset parameters and case-insensitive input.

Tested: unit tests passed.

Change-Id: I1cff40453ab4851cc7b24615a20fb6abcfba864b
Signed-off-by: Joel Pullokaran Jesin &lt;joelpj@ami.com&gt;
</content>
</entry>
<entry>
<title>Optimize bmcweb memory usage for multipart fw update</title>
<updated>2026-04-29T19:29:07+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>etanous@nvidia.com</email>
</author>
<published>2025-04-27T07:37:55+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=2d7dc991600297d04e50d7958fe9611f9ac42bcf'/>
<id>urn:sha1:2d7dc991600297d04e50d7958fe9611f9ac42bcf</id>
<content type='text'>
Previously, firmware updates via multipart/form-data stored two copies
of the entire upload in memory (200MB+ for a 100MB image). This change
reduces memory usage by incrementally processing multipart data in
chunks, running through the parser as required.  This avoids a copy into
the http body.  With this change, bmcweb no longer retains any duplicate
copy of the image in memory, thereby limiting memory consumption to
roughly the size of the image itself.

To accomplish this, the multipart parser is rewritten to support
incremental parsing.  This should be 100% compatible with the old
parser, with one exception, bytes at the end of the payload are no
longer accepted and ignored.

Tests:
Multipart FW Update using a 114.2MB file shows bmcweb memory usage in
line with one copy of the image, not two.  Unit tests pass.

Change-Id: Id18e20004059bfbc7de62f4f6c9542430c7943b0
Signed-off-by: Rajeev Ranjan &lt;ranjan.rajeev1609@gmail.com&gt;
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
<entry>
<title>RAII OpenSSL</title>
<updated>2026-04-27T18:51:54+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>ed@tanous.net</email>
</author>
<published>2025-08-19T15:36:27+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=cdcbf1a91011a4faf5e8271db3103325a2ba139d'/>
<id>urn:sha1:cdcbf1a91011a4faf5e8271db3103325a2ba139d</id>
<content type='text'>
bmcweb openssl usage is a mess.  Start cleaning it up.
1. Make RAII objects for any held memory.
2. Move methods from hostname monitor into the ssl namespace, so not all
   compile units need to pull in openssl headers
3. Move methods to static where functions can be encapsulated.

Because we're now testing openssl, we need to register memory init so
that the sanitizers don't cause issues when mallocing from non
bootstrapped openssl binaries.  Openssl provides a handle for this, so
use it in those unit tests.

Tested:
Unit tests pass.  bmcweb launches and can open ssl with curl as it did
previously.

Change-Id: If0340692d2c56a6c45bb8d661d654a4b58ff3d2c
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
<entry>
<title>Change multipart parser API</title>
<updated>2026-03-10T20:16:20+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>etanous@nvidia.com</email>
</author>
<published>2026-01-29T02:34:12+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=bbd50497dc41502cafbf20ee02596a27c31534c6'/>
<id>urn:sha1:bbd50497dc41502cafbf20ee02596a27c31534c6</id>
<content type='text'>
In preparation for making the multipart parser incremental, modify the
API to explicitly call out steps of start, parsePart, and finish.  This
allows the parser to support incremental per-character parsing in the
future.

This also has the benefit of dropping the dependency on the Request
struct on the multipart parser itself.

Tested: Unit tests pass.  Good coverage.

Change-Id: I3359f45bb9faaea42908491a818cc4a81f257a1f
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
<entry>
<title>Fix webassets to support Vite build output</title>
<updated>2026-02-16T15:11:31+00:00</updated>
<author>
<name>Jason Westover</name>
<email>jwestover@nvidia.com</email>
</author>
<published>2026-02-12T15:15:15+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=36b5cba2d032908f7e2d5355c512c7541fad4861'/>
<id>urn:sha1:36b5cba2d032908f7e2d5355c512c7541fad4861</id>
<content type='text'>
The webui-vue project migrated from webpack to Vite, which changes
the output filenames.  Vite names entry chunks as index.[hash].js
instead of webpack's app.[hash].js.  The starts_with("index.") check
in addFile() was remapping these JS/CSS files to their parent directory
path (intended only for index.html), causing 404 errors when the
browser requested the actual asset URLs.

Restrict the index file detection to only apply to .html files, so
that index.html is still correctly mapped to "/" while other files
starting with "index." are served at their actual paths.

Also broaden the etag hash detection from hex-only characters to full
alphanumeric to support Vite's base64-style content hashes alongside
webpack's hex hashes.

Add unit tests for getStaticEtag() covering both webpack and Vite hash
formats, path prefixes, edge cases, and validation of hash length and
character constraints.

Tested:
Unit tests pass
Vite-based webui-vue loads and caches etags

Change-Id: I3f7d2e062d0fd8be4ded7889b64a7228b4a6459b
Signed-off-by: Jason Westover &lt;jwestover@nvidia.com&gt;
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
<entry>
<title>Do not allow data beyond the trailer</title>
<updated>2026-02-03T00:19:31+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>etanous@nvidia.com</email>
</author>
<published>2026-01-29T01:23:24+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=64fe8020cfd6f2b6fb25249cc42daa9550c595b9'/>
<id>urn:sha1:64fe8020cfd6f2b6fb25249cc42daa9550c595b9</id>
<content type='text'>
There is nothing in the multipart spec[1] that states that a parser
should allow any bytes after a multipart payload.

Several unit tests have a \r\n after their boundary condition that
previously the parser just ignored.  Testing shows this is fairly
normal, so handle both cases still, but if any other characters show up,
fail the parse.

Unit test is also simplified to be more clear.

Tested: Unit test coverage

[1] https://datatracker.ietf.org/doc/html/rfc7578#section-4.1

Change-Id: I16643c61867708886cc87c236447ec1c19bf934f
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
<entry>
<title>Don't use at for field access in tests</title>
<updated>2026-02-03T00:19:22+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>etanous@nvidia.com</email>
</author>
<published>2026-01-29T01:11:55+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=53154a02aed647d3f3f2409ed10808135a715097'/>
<id>urn:sha1:53154a02aed647d3f3f2409ed10808135a715097</id>
<content type='text'>
at() throws an exception when a field doesn't exist.  This is somewhat
paradoxical when using EXPECT_EQ, as that is not supposed to stop the
test on a failure.  Convert calls to use operator[] which does not
throw.

Tested: Unit test

Change-Id: I9f1af1732294f2755f0beb422cffe0eb379f4e76
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
<entry>
<title>Add temp file and FD support to TemporaryFileHandle</title>
<updated>2025-11-25T18:23:48+00:00</updated>
<author>
<name>rajeeranjan</name>
<email>ranjan.rajeev1609@gmail.com</email>
</author>
<published>2025-07-21T10:17:55+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=e5ab2df5a5c865719cf6111bea549ffa84801d7e'/>
<id>urn:sha1:e5ab2df5a5c865719cf6111bea549ffa84801d7e</id>
<content type='text'>
This commit adds file descriptor and temporary file management to
DuplicatableFileHandle, removing the redundant test-only
TemporaryFileHandle utility.

Changes:
- Add file descriptor constructor and setFd() method
- Add temporary file constructor with string_view content
- Add filePath member and automatic cleanup in destructor
- Add configurable temp-dir meson option (default: /tmp/bmcweb)
- Remove include/file_test_utilities.hpp
- Update all tests to use DuplicatableFileHandle
- Rename stringPath to filePath

These features will be used by the multipart parser to stream
large uploads to temporary files instead of keeping them in memory,
and by the update service to pass file descriptors over D-Bus.

Change-Id: I982f5928d453f9f0c13d91c3525006134ddc87b3
Signed-off-by: Rajeev Ranjan &lt;ranjan.rajeev1609@gmail.com&gt;
</content>
</entry>
<entry>
<title>fix: add account checking inside verifyMtls</title>
<updated>2025-11-10T14:53:53+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>etanous@nvidia.com</email>
</author>
<published>2025-07-10T16:30:15+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=6cbd6c41ab77ac60b8b902040e023ecf3f1391e1'/>
<id>urn:sha1:6cbd6c41ab77ac60b8b902040e023ecf3f1391e1</id>
<content type='text'>
Currently if we don't have account in bmcweb but have valid format
certificate, we will have 500 internal server error when we send request
to bmcweb. But, if we don't have valid format certificate, we will get
401 unauthorized. This is not ideal as the http code is not appropriate.
Also, this might introduce some security risk as the user can deduce
whether their certificate format is valid or not based on the http code.

This patch is intended to solve this issue by checking whether the
username exists in the system. If not, we will return nullptr inside
verifyMtls function, which result in 401 unauthorized response if the
user have valid format of certificate, but there is no related username
inside the system

Change-Id: I479a10ed2bcce2c9969e19fa3aab9686ba4c71be
Signed-off-by: Malik Akbar Hashemi Rafsanjani &lt;malikrafsan@meta.com&gt;
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
</feed>
