summaryrefslogtreecommitdiff
path: root/http
AgeCommit message (Collapse)AuthorFilesLines
2025-10-02Filter http2 headersEd Tanous1-2/+4
When using aggregation with http2, :authority headers were getting forwarded to the client, which didn't know how to deal with them on http1. Filter all http2 headers. Tested: Unit tests pass. Change-Id: I6a834656b604004eeba1a2aa2f245ef211f28495 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-09-15Add check to omit `DateTime` from etag calculationCorey Ethington4-19/+49
Ignores any json property named `DateTime` when calculating the etag value of an HTTP response as per the updated Redfish Spec (section 6.5: ETags) Tested: - Redfish Service Validator passes - Tested on romulus: 1. GET resource with a "DateTime" field ``` curl -k -H "X-Auth-Token: $XAUTH_TOKEN" "https://$BMC/redfish/v1/TaskService" \ --etag-save ./etag.txt -v ... < etag: "6A4CE897" ... { "@odata.id": "/redfish/v1/TaskService", "@odata.type": "#TaskService.v1_1_4.TaskService", "CompletedTaskOverWritePolicy": "Oldest", "DateTime": "2025-07-23T17:08:20+00:00", "Id": "TaskService", "LifeCycleEventOnTaskStateChange": true, "Name": "Task Service", "ServiceEnabled": true, "Status": { "State": "Enabled" }, "Tasks": { "@odata.id": "/redfish/v1/TaskService/Tasks" } ``` 2. GET same resource again later, etag is same as before ``` curl -k -H "X-Auth-Token: $XAUTH_TOKEN" "https://$BMC/redfish/v1/TaskService" \ --etag-save ./etag.txt -v ... < etag: "6A4CE897" ... { "@odata.id": "/redfish/v1/TaskService", "@odata.type": "#TaskService.v1_1_4.TaskService", "CompletedTaskOverWritePolicy": "Oldest", "DateTime": "2025-07-23T17:10:48+00:00", "Id": "TaskService", "LifeCycleEventOnTaskStateChange": true, "Name": "Task Service", "ServiceEnabled": true, "Status": { "State": "Enabled" }, "Tasks": { "@odata.id": "/redfish/v1/TaskService/Tasks" } ``` "DateTime" is the only value to have changed, but since it is ignored the etag did not change 3. GET with if-none-match returns 304 ``` curl -k -H "X-Auth-Token: $XAUTH_TOKEN" "https://$BMC/redfish/v1/TaskService" \ --etag-save ./etag.txt --etag-compare ./etag.txt -v ... > if-none-match: "6A4CE897" ... < HTTP/2 304 < allow: GET < odata-version: 4.0 < strict-transport-security: max-age=31536000; includeSubdomains < pragma: no-cache < cache-control: no-store, max-age=0 < x-content-type-options: nosniff < etag: "6A4CE897" < date: Wed, 23 Jul 2025 17:14:39 GMT < content-length: 0 < ... ``` Change-Id: I51f7668e75719c69c55535e4a1e48c8bae7c9488 Signed-off-by: Corey Ethington <cethington@coreweave.com>
2025-08-26Fix includesEd Tanous5-5/+1
Our includes haven't been enforced by tidy in a while. Run the script, check in the result, minus the false positives. Change-Id: I6a6da26f5ba5082d9b4aa17cdc9f55ebd8cd41a6 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-08-26Remove namespace in http layerEd Tanous6-26/+25
Within this namespace, we don't need to call crow, we are already in the crow namespace. Tested: Code compiles. Change-Id: Ida57624ef1157f98f2719b5c3af536aebaca601e Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-08-18Fix 204/304 incorrectly tracing CRITICAL messageAbiola Asojo1-2/+2
Resolve tracing of CRITICAL message on 1xx, 204(no-content) and 304(not modified) when there is no body in the response. The code is changed to check that 1xx, 204 and 304 response with payloadsize of 0 will not trace the CRITICAL message. Removed setting of no_content on PATCH that was being done before other functions are called. Tested: Used the following commands to check that the CRITICAL message is no longer being traced for no-content and not modified response with no body. 204 no-content ``` curl -k -H "Content-Type: application/json" \ -d '{"PowerRestorePolicy":"LastState"}' \ -X PATCH https://${bmc_ip}/redfish/v1/Systems/system ``` ``` curl -k -H "Content-Type: application/json" \ -H "X-Auth-Token: $bmc_token" -X PATCH \ -d '{"LocationIndicatorActive":true}' \ https://${bmc_ip}/redfish/v1/Managers/bmc ``` 304 not modified ``` curl -k -i https://${bmc_ip}/redfish/ --etag-save etag.out \ -H 'If-Modified-Since: Tue, 21 Nov 2050 08:00:00 GMT' HTTP/1.1 200 OK Allow: GET . . . ETag: "B3A9EAA1" Content-Type: application/json Date: Thu, 14 Aug 2025 22:07:27 GMT Content-Length: 26 ETAG=`cat etag.out`; echo $ETAG curl -k -i https://${bmc_ip}/redfish/ -H "If-None-Match: ${ETAG}" HTTP/1.1 304 Not Modified Allow: GET . . . ETag: "B3A9EAA1" Date: Thu, 14 Aug 2025 22:16:27 GMT Content-Length: 0 ``` Change-Id: I98cc096c1f7e506687d4a6bf5a2e51b2231c0d68 Signed-off-by: Abiola Asojo <abiola.asojo@ibm.com>
2025-08-13Enable Mutual TLS for http2 connectionsEd Tanous2-7/+10
Passing the TLS-provided credentials from the HTTP connection to the http2 connection got missed, and appears to break mutual TLS for http2 connections. Pass the credentials. Tested: Mutual TLS is now functional on http2 connections as shown in the next patch. Change-Id: Ia2bbcd5383dae859baa96908b76f221b9c74632c Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-07-23Trace URI when body on 204/304Abiola Asojo3-7/+19
Trace URI on the existing CRITICAL message when a body exists but HTTP return code was Informational responses (100 – 199), no-content (204), or not_modified (304). Tested: With these changes, the URI is traced on the CRITICAL message: ``` curl --http2 -k -H "Content-Type: application/json" \ -d '{"PowerRestorePolicy":"LastState"}' \ -X PATCH https://${bmc}/redfish/v1/Systems/system root@p10bmc:~# journalctl | grep Response Jun 20 15:30:46 p10bmc bmcwebd[296]: [http_response.hpp:213] 0x1353670 Response content provided but code was no-content or not_modified, which aren't allowed to have a body for url : "/redfish/v1/Systems/system" ``` Change-Id: I1ef618600642d355fc9f935d055b011e044caf5c Signed-off-by: Abiola Asojo <abiola.asojo@ibm.com>
2025-07-14Implement zstd decompressionEd Tanous7-10/+201
Given the size of Redfish schemas these days, it would be nice to be able to store them on disk in a zstd format. Unfortunately, not all clients support zstd at this time. This commit implements reading of zstd files from disk, as well as decompressing zstd in the case where the client does not support zstd as a return type. Tested: Implanted an artificial zstd file into the system, and observed correct decompression both with an allow-encoding header of empty string and zstd. Change-Id: I8b631bb943de99002fdd6745340aec010ee591ff Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-07-09Move http2 out of experimentalEd Tanous1-2/+2
Http2 support in bmcweb has been relatively stable for a while. The http2 implementation passes all known Redfish tests (some of which require ported to httpx to support http2), the UI loads, and so far as the project is concerned, is a complete improvement over the existing http1 stack. This commit removes the experimental classification from http2, and declares it ready for production use, while enabling it by default. note, that enabling this by default only makes the server advertise that http2 is available. Http2 must still be supported by the client to enable ALPN negotiation, so existing http1 clients that only support http1 will continue to function as they did before. Tested: Enabled http option and saw http2 advertised, http2 now takes effect. Change-Id: I92843a3afc532f0b2a64904bb872e5d84a1a54fe Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-06-19Fix invalid dereference on loggingMyung Bae1-1/+1
cppcheck found a case which dereferences an invalid iterator like ``` http/logging.hpp:74:12: warning: Either the condition 'it!=mapping.end()' is redundant or there is possible dereference of an invalid iterator: it. [derefInvalidIteratorRedundantCheck] return it->second; http/logging.hpp:69:12: note: Assuming that condition 'it!=mapping.end()' is not redundant if (it != mapping.end()) ^ http/logging.hpp:74:12: note: Dereference of an invalid iterator return it->second; ^ ``` Tested: - Tries a various bmcweb loglevel. Change-Id: Ieca8c5c5ee83f0b45a82c3d7e4f19b09bf1422e6 Signed-off-by: Myung Bae <myungbae@us.ibm.com>
2025-06-11Minor cleanups in http clientEd Tanous1-12/+4
All integers in a callback should be taken by value, not reference. Fix a typo on "Async" Implement a TODO on libssl, where a macro was removed, so we can now directly call the function Tested: Unit tests pass. Change-Id: Iaccd100a6b5f0dc871ec2d2cb1f01bed3ceefde2 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-06-11Show websocket timeout log as WARNINGMyung Bae1-3/+7
When websocket is closed due to a timeout under some situations like GUI console not as responsive, itis currently logged as ERROR. This commit changes it as WARNING. ``` May 02 10:09:31 ever28bmc pldmd[836]: BIOS attribute 'hb_cap_freq_mhz_min' updated to value '2000' by BMC 'false' May 02 10:09:31 ever28bmc pldmd[836]: BIOS attribute 'hb_cap_freq_mhz_max' updated to value '3900' by BMC 'false' May 02 10:09:31 ever28bmc bmcweb[1100]: [ERROR websocket.hpp:268] doRead error The socket was closed due to a timeout [boost.beast:1 at /usr/include/boost/beast/websocket/impl/stream_impl.hpp:346:13 in function 'bool boost::beast::websocket::stream< <template-parameter-1-1>, <anonymous> >::impl_type::check_stop_now(boost::beast::error_code&)'] May 02 10:09:34 ever28bmc pldmd[836]: BIOS attribute 'hb_max_number_huge_pages' updated to value '64' by BMC 'false' ``` Tested: - Load GUI pages and kill web-browser multiple times while reading BMC journal records. Change-Id: I7e15845be7d3762ef144744ca1aedadf96e43a2f Signed-off-by: Myung Bae <myungbae@us.ibm.com>
2025-06-09Do hard close if client disobeys protocolEd Tanous1-23/+6
There are cases bmcweb might close the connection due to a violation of the protocol. Currently these are done gracefully, under the assumption that a client might attempt to recover. But this opens us up to potentially leaving sockets open for far longer than we intend if the client is completely gone, due to a disconnect or explicitly closing the socket hard. In cases where we get a protocol error, shutdown the socket hard, rather than attempt to do things "correctly". Tested: I tested this MR using a script that simulated 5,000 parallel connections simultaneously to BMC and closed them immediately without properly sending a close_notify alert Observations: The BMC became unresponsive for 30-40 seconds before recovering. After recovery, it took approximately 90 seconds to close all connections in QEMU. On real hardware, connection closure times may be slightly higher (though still within expected parameters). Conclusion: This behavior aligns with expectations. After 90 seconds observed that 1) No sockets in CLOSE_WAIT state 2) Able to make new connection. ``` curl -k -H "X-Auth-Token:$bmc_token" https://${IP}/redfish/v1/AccountService/Accounts { "@odata.id": "/redfish/v1/AccountService/Accounts", "@odata.type": "#ManagerAccountCollection.ManagerAccountCollection", "Description": "BMC User Accounts", "Members": [ { "@odata.id": "/redfish/v1/AccountService/Accounts/root" } ], "Members@odata.count": 1, "Name": "Accounts Collection" } ``` Change-Id: I6ab4347efd8fda9ae86bfbb8575666ad3eabe88c Signed-off-by: Ed Tanous <etanous@nvidia.com> Signed-off-by: Chandramohan Harkude <chandramohan.harkude@gmail.com>
2025-06-09Fix DOS attack scenarioChandramohan Harkude1-1/+22
Problem : When 201 connections made in parallel to BMC and closed them immediately without properly sending a close_notify alert it was observed that Bmcweb server was taking several minutes to close the sockets. All the 200 TCP sockets were in CLOSE_WAIT state. Journal log shows below line [CRITICAL http_connection.hpp:213] 0x29d1ef0Max connection count exceeded. ``` Not able to make new connection $ curl -k -H "X-Auth-Token:$bmc_token" -X GET https://${BMC_IP}/redfish /v1/AccountService/Accounts curl: (35) OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to 127.0.0.1:2443 Fix : The bmcweb server failed to identify the end of stream at TCP (SSL /TLS) layer, therefore added check to identify the end of stream which closes the connection and socket Test : I tested this MR using a script that simulated 5,000 parallel connections simultaneously to BMC and closed them immediately without properly sending a close_notify alert Observations: The BMC became unresponsive for 30-40 seconds before recovering. After recovery, it took approximately 90 seconds to close all connections in QEMU. On real hardware, connection closure times may be slightly higher (though still within expected parameters). Conclusion: This behavior aligns with expectations. After 90 seconds observed that 1) No sockets in CLOSE_WAIT state 2) Able to make new connection. curl -k -H "X-Auth-Token:$bmc_token" https://${IP}/redfish/v1/AccountService/Accounts { "@odata.id": "/redfish/v1/AccountService/Accounts", "@odata.type": "#ManagerAccountCollection.ManagerAccountCollection", "Description": "BMC User Accounts", "Members": [ { "@odata.id": "/redfish/v1/AccountService/Accounts/root" } ], "Members@odata.count": 1, "Name": "Accounts Collection" } ``` Change-Id: I1c277db0b774d33c656b4a2b1bd14f3575535bec Signed-off-by: Chandramohan Harkude <chandramohan.harkude@gmail.com>
2025-06-04remove meta mtls parse modeMalik Akbar Hashemi Rafsanjani3-98/+0
as we have successfully merged patches that enable UserPrincipalName parse mode, we can start removing Meta only parse mode. This commit is intended to remove MTLSCommonNameParseMode::Meta from the upstream code Tested: - build bmcweb - deploy to a device that already use UPN - check if it works fine by sending curl request /AccountService Change-Id: Idcf4340a2a9940f035aea41cd30ef4df7bd95530 Signed-off-by: Malik Akbar Hashemi Rafsanjani <malikrafsan@meta.com>
2025-05-14Fix the buildEd Tanous2-12/+14
I don't feel like breaking these out at the moment or writing a commit message. This fixes the build for clang-tidy. If anyone wants to break these out with appropriate commit messages, feel free. Change-Id: Id0b65d238dfb9b8036c0ffddf2f32d221e5988c2 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-04-29Fix more movesEd Tanous1-1/+1
This commit is fixing coverity issues reported for copy in stead of move. Tested: redfish service validator passes Change-Id: I97e755830f28390e7c4bfaba6f3f947898a21423 Signed-off-by: Ed Tanous <ed@tanous.net>
2025-04-25http_client: Fixing invalid logabhilashraju1-2/+2
The error log for connection failures previously displayed an invalid host name and port number because it retrieved these values from the endpoint argument in the afterConnect callback, which is not valid when the connection fails. This patch resolves the issue by obtaining the host name directly from the connection object. Tested By: Attempted to subscribe to an unreachable host and sent test events to verify that the error log was generated as expected. Change-Id: I33772b224eb7ab164c2de342f35ae42c34126b3d Signed-off-by: Abhilash Raju <abhilash.kollam@gmail.com>
2025-04-03Make Request copy explicitEd Tanous2-3/+9
It is currently too easy to accidentally make copies of the Request object. Ideally code would parse out the Request in the first handler, then no longer require an async copy. There is one case in the redfish query things where we actually need a copy of the request object, so we need these constructors, but we should make them explicit. This commit moves the Request constructor to be private, and adds a new method called copy() for explicitly making a copy. Ironcially, this finds one place where we were actually making a copy of the request object unintentionally, so fix that to only capture the value required,the user session. Tested: - Compiles - Run GET/PATCH related curl or If-Match like PATCH Account - Redfish Service Validator runs and passes Change-Id: I19255981f42757ed736112c003201e3f758735ac Signed-off-by: Ed Tanous <ed@tanous.net> Signed-off-by: Myung Bae <myungbae@us.ibm.com>
2025-04-03OEM Route Handling Infrastructurerohitpai2-2/+3
Goal of the MR is to provide infrastructure support in bmcweb to manage the OEM fragment handling separately. OEM schema are vendor defined and per DMTF resource we could have multiple vendor defined OEM schema to be enabled. The feature allows registration of route handler per schema per OEM namespace. Example ``` REDFISH_SUB_ROUTE<"/redfish/v1/Managers/<str>/#/Oem/OpenBmc">(service, HttpVerb::Get)(oemOpenBmcCallback); REDFISH_SUB_ROUTE<"/redfish/v1/Managers/<str>/#/Oem/Nvidia">(service, HttpVerb::Get)(oemNidiaCallback); ``` We can have separate vendor defined route handlers per resource. Each of these route handlers can populate their own vendor specific OEM data. The OEM code can be better organized and enabled/disabled as per the platform needs. The current MR has the code changes related to handling GET requests alone. The feature only supports requests where the response payload is JSON. Tests - All UT cases passes - New UT added for RF OEM router passes - Service Validator passes on qemu - GET Response on Manager/bmc resource contains the OEM fragment ``` curl -c cjar -b cjar -k -X GET https://127.0.0.1:2443/redfish/v1/Managers/bmc { "@odata.id": "/redfish/v1/Managers/bmc", "@odata.type": "#Manager.v1_14_0.Manager", "Oem": { "OpenBmc": { "@odata.id": "/redfish/v1/Managers/bmc#/Oem/OpenBmc", "@odata.type": "#OpenBMCManager.v1_0_0.Manager", "Certificates": { "@odata.id": "/redfish/v1/Managers/bmc/Truststore/Certificates" } } }, "UUID": "40575e98-90d7-4c10-9eb5-8d8a7156c9b9" } ``` Change-Id: Ic82aa5fe760eda31e2792fbdfb6884ac3ea613dc Signed-off-by: Rohit PAI <rohitpai77@gmail.com>
2025-04-03Use Node as template parameter for creating TriesRohit PAI2-44/+48
Abstracting Node can help us extend Tries for other use case like sub routes management Tested 1. Service Validator passes Change-Id: I4703af9f30107ce2bc3685683a5fd5b669341d35 Signed-off-by: Rohit PAI <ropai@nvidia.com>
2025-04-03Move router trie to its own fileEd Tanous2-307/+328
Just as the title says. Trie is useful outside of just the router (for making other routers.) Change-Id: I961927f2cea44ee78f32337e64741edad9dc542f Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-04-03Make trie a templateEd Tanous1-12/+13
This trie class would be useful to use with any arbitrary type, not just those inheriting from BaseRule. Change-Id: I325474a100e083ea36407530c6e4e8f6412718ac Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-03-26Fix 302 cache handlingEd Tanous2-2/+2
302 cache handling appears to have been broken when we went to AsyncResp in the connection class instead of using Response directly. This is because the expected hash was being written to the old response, not the new one. Resolve the issue. Tested: using curl to grab /redfish/v1 then pull the ETAG from the response then use curl to set if-none-match Shows that redfish now responds with 302 not modified. Loading a browser window shows many requests are fulfilled with 302 not modified. Change-Id: Ie1e782fd5b2c6a5bcf942849ee13ca074973bf1e Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-03-21Map debug level to infoEd Tanous1-2/+5
As the comment states, openbmc currently squashes DEBUG level messages. After ee993dc84b1e9917b545fdd7367f1127a358084a systemd can see the log levels, which has the unintended consequence of squashing DEBUG level messages when enabled. This is a temporary workaround to fix the regression. Ulimately implementing something like DEBUG_INVOCATION might be the way to go. Tested: Enabled debug logging journalctl -u bmcweb showed debug level messages. Change-Id: I3c57a47282dbcbf34c58a12d2b7da54f1082fac1 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-03-18Fix CI on generated-enumMyung Bae1-0/+1
Generated enum files include `json.hpp' which causes the CI failures like ``` /var/jenkins-openbmc/workspace/ci-repository/openbmc/bmcweb/redfish-core/include/generated/enums/acceleration_function.hpp:4:1: error: included header json.hpp is not used directly [misc-include-cleaner,-warnings-as-errors] 4 | #include <nlohmann/json.hpp> | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~ 5 | ``` So, this will treat `<nlohmann/json.hpp>` as `misc-include-cleaner` to ignore the header check. Tested: - Compiles good - CI passes Change-Id: Id1d5e981b1de37398aa02c3303357e66fe902efd Signed-off-by: Myung Bae <myungbae@us.ibm.com>
2025-03-14mtls: implement UPN parse modeMalik Akbar Hashemi Rafsanjani3-30/+164
This commit is intended to implement the UserPrincipalName (UPN) parse mode on mutual TLS (MTLS). By implementing this we can use the X509 certificate extension Subject Alternative Name (SAN), specifically UPN to be used as the username In our case, this feature is needed because we have a specific format on our Subject CN of X509 certificate. This format cannot directly mapped to the username of bmcweb because it contains special characters (`/` and `:`), which cannot exist in the username. Changing the format of our Subject CN is very risky. By enabling this feature we can use other field, which is the SAN extension to be used as the username and do not change our Subject CN on the X509 certificate In general, by implementing this feature, we can enable multiple options for the system. There might be other cases where we want to have the username of the bmcweb is not equal to the Subject CN of the certificate, instead the username is added as the UserPrincipalName field in the certificate The format of the UPN is `<username>@<domain>` [1][2]. The format is similar to email format. The domain name identifies the domain in which the user is located [3] and it should match the device name's domain (domain forest). Tested - Test using `generate_auth_certificate.py` (extended on patch [4]) - Manual testing (please see the script mentioned above for more detail) - Setup certificate with UPN inside SAN extension - Change the CertificateMappingAttribute to use UPN - Get request to `/SessionService/Sessions` - Run unit tests [1] UPN Format: https://learn.microsoft.com/en-us/windows/win32/secauthn/user-name-formats#user-principal-name [2] UPN Properties: https://learn.microsoft.com/en-us/windows/win32/ad/naming-properties#userprincipalname [3] UPN Glossary: https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-wcce/719b890d-62e6-4322-b9b1-1f34d11535b4#gt_9d606f55-b798-4def-bf96-97b878bb92c6 [4] Patch Testing Script: https://gerrit.openbmc.org/c/openbmc/bmcweb/+/78837 Change-Id: I490da8b95aee9579546971e58ab2c4afd64c5997 Signed-off-by: Malik Akbar Hashemi Rafsanjani <malikrafsan@meta.com>
2025-02-27Break out sse into a compile unitEd Tanous4-294/+347
Verify similar to beb96b0 Break out websockets Break out the SSE functions into a separate compile unit. This allows the SSE sockets in beast to be compiled separately, which significantly reduces the overall compile time by a few seconds. Code is identical with the exceptions of minor header definitions to convert header-only to compile unit. Change-Id: I5aae4f17cbd2badf75b3e0bb644a2309f6300663 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-02-23Enable port 18080Janet Adkins1-0/+10
The commit [1] altered how sockets are created and inadvertently removed the default port 18080. We use this port extensively in development. The bmcweb documentation describes the port 18080 for this use. [2] Adding back the default port 18080. The commit [1] added meson build options for adding additional ports. In attempting to enable port 18080 using that mechanism I ran into various build errors when additional-ports has a value. I've corrected the config/meson.build file to address those errors. These changes are not necessary to re-enable port 18080 but worth fixing anyway. Note: Meson defines arrays as containing strings so there is no to_string() method for the array member. [3] ``` ../../../../../../workspace/sources/bmcweb/config/meson.build:137:39: ERROR: Unknown method "to_string" in object <[StringHolder] holds [str]: '18080'> of type StringHolder. ``` Tested: - Started bmcweb from /tmp and was able to connect through port 18080. Log shows: ``` [DEBUG app.hpp:111] Got 0 sockets to open [INFO app.hpp:150] Starting webserver on port 18080 ``` [1] https://gerrit.openbmc.org/c/openbmc/bmcweb/+/35265 [2] https://github.com/openbmc/bmcweb/blob/cc67d0a0fed101c930b334a583d9ca9b222ceb77/TESTING.md?plain=1#L57 [3] https://mesonbuild.com/Build-options.html#arrays Change-Id: Ia1b326bedca808e43e73ce2b241178bc4bfab23c Signed-off-by: Janet Adkins <janeta@us.ibm.com> Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-02-18Fix tidy misc-include issueEd Tanous1-2/+3
Fix minor #include regression caused by ee993dc84b1e9917b545fdd7367f1127a358084a Change-Id: Ieda0205a4a4faf877a4f2298e6935bc3aa506fde Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-02-17Use systemd logging levelsEd Tanous1-5/+28
Systemd has an option[1] that allows it to interpret our log levels directly. This allows for journald to sort/filter/colorize our logs better than it was able to previously. Its indexes don't map perfectly to bmcwebs, so come up with a constexpr lookup table to map the two values across. Tested: Enabled logging, and dumped journal logs. Observed colorized output. [1] https://www.freedesktop.org/software/systemd/man/latest/systemd.exec.html#SyslogLevelPrefix= Change-Id: I7722ae86e114daec88709b68405498eeb8164c07 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-02-14Implement http2 TODOEd Tanous2-51/+42
To support HTTP2 simultaneously on http and https connections, the HTTP connection classes formerly took the socket as a template option, allowing passing ssl::stream<tcp::socket> or simply tcp socket. With the addition of the multiple-sockets option, this would cause two copies of the template to be instantiated, increasing both compile times and binary size. This commit applies the same logic to http2connection as was applied to HTTPConnection, adding an http type parameter to the constructor, which allows switching between adapter and adapter.next_level() on each read or write operation. In compiled code, this means that the connection classes are only specialized once. Tested: When configured for one of each http and https socket and http2 curl --http2 http://<ip>/redfish/v1 succeeds curl --http2 https://<ip>/redfish/v1 succeeds Change-Id: I8f33796edd5874d5b93d10a3f253cfadd4f6d7a4 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-02-12Break out websocketsEd Tanous4-368/+409
When running clang build analyzer it shows that one of the largest templates in the Redfish compile unit (which is also the slowest compile unit) is actually the beast websocket instantiations, taking about 6 seconds to compile on their own. Luckily, the websocket layer is already split into Websocket and WebsocketImpl classes that we inherited from crow. Unfortunately, crow puts these two classes into the same file. So. 1. Move the WebSocketImpl class into its own header. 2. Move the websocket() upgrade routes in the websocket routing rule into their own compile unit to take advantage of only needing WebsocketImpl in this compile unit. Tested: Drops build time by several seconds depending on what other level of optimizations are present (1:15 -> 1:00) [1] https://github.com/aras-p/ClangBuildAnalyzer Change-Id: Ia0445eae4a793bb4ccb28136f30d2a05662c529c Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-02-12Remove getIoContext from Request objectEd Tanous5-28/+2
At one point it was thought that we could pass the io_context object through the request object, and have the potential to run multiple io_context instances (one per connection). Given the safety refactoring we had to do in 9838eb20341568971b9543c2187372d20daf64aa that idea is on ice for the moment, and would need a major rethink of code to be viable. For the moment, and in prep for https://gerrit.openbmc.org/c/openbmc/bmcweb/+/75668 make sure all calls are pulling from the same io object. Tested: Unit tests pass. Redfish service validator passes. Change-Id: I877752005c4ce94efbc13ce815f3cd0d99cc3d51 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-02-11Move chassis and trigger to dbus utilityEd Tanous2-2/+2
Using the utility classes reduces compile times and reduces the number of template specializations that get generated. These are the last two left in the codebase for getProperty, so fix them. Tested: On Last commit. Change-Id: I0ca8411b74b58dbeb42587b88cfd66c0e674b8c8 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-02-10Enable HTTP additional socketsEd Tanous6-217/+379
This commit attempts to add the concept of an SSL detector from beast, and add the capability into bmcweb. This allows directing multiple socket files to the bmcweb instance, and bmcweb will automatically sort out whether or not they're SSL, and give the correct response. This allows users to plug in erroneous urls like "https://mybmc:80" and they will forward and work correctly. Some key design points: The HTTP side of bmcweb implements the exact same http headers as the HTTPS side, with the exception of HSTS, which is explicitly disallowed. This is for consistency and security. The above allows bmcweb builds to "select" the appropriate security posture (http, https, or both) for a given channel using the FileDescriptorName field within a socket file. Items ending in: both: Will support both HTTPS and HTTP redirect to HTTPS https: Will support HTTPS only http: will support HTTP only Given the flexibility in bind statements, this allows administrators to support essentially any security posture they like. The openbmc defaults are: HTTPS + Redirect on both ports 443 and port 80 if http-redirect is enabled And HTTPS only if http-redirect is disabled. This commit adds the following meson options that each take an array of strings, indexex on the port. additional-ports Adds additional ports that bmcweb should listen to. This is always required when adding new ports. additional-protocol Specifies 'http', 'https', or 'both' for whether or not tls is enfoced on this socket. 'both' allows bmcweb to detect whether a user has specified tls or not on a given connection and give the correct response. additional-bind-to-device Accepts values that fill the SO_BINDTODEVICE flag in systemd/linux, and allows binding to a specific device additional-auth Accepts values of 'auth' or 'noauth' that determines whether this socket should apply the normal authentication routines, or treat the socket as unauthenticated. Tested: Previous commits ran the below tests. Ran the server with options enabled. Tried: ``` curl -vvvv --insecure --user root:0penBmc http://192.168.7.2/redfish/v1/Managers/bmc * Trying 192.168.7.2:80... * Connected to 192.168.7.2 (192.168.7.2) port 80 (#0) * Server auth using Basic with user 'root' > GET /redfish/v1/Managers/bmc HTTP/1.1 > Host: 192.168.7.2 > Authorization: Basic cm9vdDowcGVuQm1j > User-Agent: curl/7.72.0 > Accept: */* > * Mark bundle as not supporting multiuse < HTTP/1.1 301 Moved Permanently < Location: https://192.168.7.2 < X-Frame-Options: DENY < Pragma: no-cache < Cache-Control: no-Store,no-Cache < X-XSS-Protection: 1; mode=block < X-Content-Type-Options: nosniff < Content-Security-Policy: default-src 'none'; img-src 'self' data:; font-src 'self'; style-src 'self'; script-src 'self'; connect-src 'self' wss: < Date: Fri, 08 Jan 2021 01:43:49 GMT < Connection: close < Content-Length: 0 < * Closing connection 0 ``` Observe above: webserver returned 301 redirect. webserver returned the appropriate security headers webserver immediately closed the connection. The same test above over https:// returns the values as expected Loaded the webui to test static file hosting. Webui logs in and works as expected. Used the scripts/websocket_test.py to verify that websockets work. Sensors report as expected. Change-Id: Ib5733bbe5473fed6e0e27c56cdead0bffedf2993 Signed-off-by: Ed Tanous <ed@tanous.net>
2025-02-10Support h2c upgradeEd Tanous3-25/+106
h2c upgrade is a mechanism for supporting http/2 on connections that might not support alpn [1]. This is done by the client specifying Connection: upgrade Upgrade: h2c This looks very similar to a websocket upgrade, which h2c replacing websocket. Because of this, the existing upgrade code needs some upgrades to avoid parsing twice. Tested: ``` curl -u root:0penBmc --http2 -k http://192.168.7.2:443/redfish/v1/SessionService/Sessions ``` Succeeds and verbose logging shows that http upgrade succeeded websocket_test.py in the scripts directory connects and reports events [1] https://datatracker.ietf.org/doc/html/rfc7540#section-11.8 Change-Id: I8f76e355f99f21337d310ef2f345e6aaa253b48b Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-02-07Implement urlsafe base64 decodeEd Tanous1-40/+44
base64 decoding comes in two flavors, "normal" which we already implement, and "url safe" which modifies the alphabet to create base64 encodings that are safe to use in filenames and urls. Functionally this just involves swapping two characters with underscore and minus in the encode/decode table. To avoid duplicating a lot of code, this commit refactors the base64 tables to be generated at compile time. Tested: Included unit tests pass. No usage until next commit. Change-Id: I71724fd2e04000f115c22a40d382d411986d7b39 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-02-04clang-format: update latest spec and reformatPatrick Williams8-27/+27
Copy the latest format file from the docs repository and apply. Change-Id: I2f0b9d0fb6e01ed36a2f34c750ba52de3b6d15d1 Signed-off-by: Patrick Williams <patrick@stwcx.xyz>
2025-01-31Move io context to singletonEd Tanous2-38/+16
The way we pass around io contexts is somewhat odd. Boost maintainers in slack recommended that we just have a method that returns an io context, and from there we can control this (context link lost years ago). The new version of clang claims the singleton pattern of passing in an io_context pattern is a potential nullptr dereference. It's technically correct, as calling the singleton without immediately initializing the io context will lead to a crash. This commit implements what the boost maintainers suggested, having a single method that returns "the context" that should be used. This also helps to maintain isolation, as some pieces are no longer tied directly to dbus to get their reactor. Tested: WIP Change-Id: Ifaa11335ae00a3d092ecfdfb26a38380227e8576 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-01-31Fix includesEd Tanous24-77/+223
Clang-tidy misc-include-cleaner appears to now be enforcing significantly more headers than previously. That is overall a good thing, but forces us to fix some issues. This commit is largely just taking the clang-recommended fixes and checking them in. Subsequent patches will fix the more unique issues. Note, that a number of new ignores are added into the .clang-tidy file. These can be cleaned up over time as they're understood. The majority are places where boost includes a impl/x.hpp and x.hpp, but expects you to use the later. include-cleaner opts for the impl, but it isn't clear why. Change-Id: Id3fdd7ee6df6c33b2fd35626898523048dd51bfb Signed-off-by: Ed Tanous <etanous@nvidia.com> Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
2025-01-20Use SPDX identifiersEd Tanous26-15/+53
SPDX identifiers are simpler, and reduce the amount of cruft we have in code files. They are recommended by linux foundation, and therefore we should do as they allow. This patchset does not intend to modify any intent on any existing copyrights or licenses, only to standardize their inclusion. [1] https://www.linuxfoundation.org/blog/blog/copyright-notices-in-open-source-software-projects Change-Id: I935c7c0156caa78fc368c929cebd0f068031e830 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-01-15Don't forward skip or only to aggregatorEd Tanous1-0/+5
These two parameters are not idempotent, and are currently being run first on the satellite, then again on the aggregator. This results in errors and unexpected results. This commit detects when we're parsing a top collection, and filters out those two parameters from being applied to the satellite request. To accomplish rewriting the URI, a new Request API needs added for non-const access to the URI object. Tested: Aggregator shows results as expected. Query params are not forwarded to satellite Change-Id: I99cbbb08da9fcd06c9ee10d371b253e32d01f59b Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-01-13Clang-tidy updates for 19Ed Tanous1-0/+5
Update to add new checks that are now available to us. Fix the minor issues we have. A few of our checks that we previously had enabled have been renamed, so remove those from the file as well. Change-Id: Idbbfc3cb7ba42ac780e557554d7ae8ab190e7551 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-01-03Move isJSONContentType to content-type parserEd Tanous1-4/+3
Previously this function was based on a basic string comparison. This is fine, but found several inconsistencies, like not handling spaces in the appropriate places. This commit creates a new function getContentType, using the new parsing infrastructure. As doing this, it showed that the existing parser functions were not handling case insensitive compares for the mime type. While this is technically not required, it's something we unit test for, and relatively easy to add. Note, that because this parser ignores charset, this moves charset=ascii from something that previously failed, to something that now succeeds. This is expected. Tested: Unit tests pass. Good coverage Change-Id: I825a72862135b62112ee504ab0d9ead9d6796354 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-01-03Clean up static analysisEd Tanous3-19/+3
Coverity marks some minor things as improvements we can make. Clean up the code to silence the errors. Tested: Unit tests coverage for http core is sufficient. Change-Id: If4efb359792bfdfe3866e843b4bbdb3f83fec0c5 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-01-02Fix SSE firing orderEd Tanous1-21/+17
When sending last-event-id, the previous events were being received before the the header was completed. This is because the open handler is being called before the connect call was in place, so you get: Connection starts open handler called sendEvent() called from open handler sendSSEHeader() called. This results in a spec violation. Tested: curl --user root:0penBmc -vvv -s --no-buffer -k -N -H 'Accept: text/event-stream' -H 'Last-Event-Id: 4' -X GET https://localhost:8000/redfish/v1/EventService/SSE Now succeeds, and wireshark dumps show the header is being sent correctly. Note that previously this command would fail unless http0.9 header was set. Unit test coverage for this path without last-event-id passes. Change-Id: I44bb6eedbcbdc727b257646ec55e808157231f75 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-12-20Fix clang-tidyEd Tanous2-17/+8
Change-Id: Iefe1b695b86a640d8dfaafd1f77f374fa34246de Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-12-20Reformat for clang-19Ed Tanous1-10/+10
Change-Id: I6d677b16219482db16c64d5d8412ca557142a597 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-10-24Explicitly set verify_noneEd Tanous1-0/+3
As reported, there are cases where a valid certificate isn't present, but a browser still prompts for an MTLS cert. Fix that by explicitly setting verify_none if strict tls isn't enabled. Unclear what impacts this will have elsewhere: Tested (not yet done on this patch): with a self-signed certificate, logging into chrome no longer prompts the certificate screen. Change-Id: Iaf7d25fec15ad547a6c741c9410995e19ba22016 Signed-off-by: Ed Tanous <etanous@nvidia.com>