summaryrefslogtreecommitdiff
path: root/include
AgeCommit message (Collapse)AuthorFilesLines
2025-03-14mtls: implement UPN parse modeMalik Akbar Hashemi Rafsanjani2-6/+26
This commit is intended to implement the UserPrincipalName (UPN) parse mode on mutual TLS (MTLS). By implementing this we can use the X509 certificate extension Subject Alternative Name (SAN), specifically UPN to be used as the username In our case, this feature is needed because we have a specific format on our Subject CN of X509 certificate. This format cannot directly mapped to the username of bmcweb because it contains special characters (`/` and `:`), which cannot exist in the username. Changing the format of our Subject CN is very risky. By enabling this feature we can use other field, which is the SAN extension to be used as the username and do not change our Subject CN on the X509 certificate In general, by implementing this feature, we can enable multiple options for the system. There might be other cases where we want to have the username of the bmcweb is not equal to the Subject CN of the certificate, instead the username is added as the UserPrincipalName field in the certificate The format of the UPN is `<username>@<domain>` [1][2]. The format is similar to email format. The domain name identifies the domain in which the user is located [3] and it should match the device name's domain (domain forest). Tested - Test using `generate_auth_certificate.py` (extended on patch [4]) - Manual testing (please see the script mentioned above for more detail) - Setup certificate with UPN inside SAN extension - Change the CertificateMappingAttribute to use UPN - Get request to `/SessionService/Sessions` - Run unit tests [1] UPN Format: https://learn.microsoft.com/en-us/windows/win32/secauthn/user-name-formats#user-principal-name [2] UPN Properties: https://learn.microsoft.com/en-us/windows/win32/ad/naming-properties#userprincipalname [3] UPN Glossary: https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-wcce/719b890d-62e6-4322-b9b1-1f34d11535b4#gt_9d606f55-b798-4def-bf96-97b878bb92c6 [4] Patch Testing Script: https://gerrit.openbmc.org/c/openbmc/bmcweb/+/78837 Change-Id: I490da8b95aee9579546971e58ab2c4afd64c5997 Signed-off-by: Malik Akbar Hashemi Rafsanjani <malikrafsan@meta.com>
2025-02-13Break out dbus utilities into compile unitEd Tanous2-210/+62
ClangBuildAnalyzer shows that each of these dbus calls is relatively expensive to compile, so put them in their own compile unit so they can be compiled separately. Tested: Redfish service validator passes Change-Id: Ia383611182d8bc93c125248c4196898cb51fd807 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-02-12Remove getIoContext from Request objectEd Tanous4-12/+10
At one point it was thought that we could pass the io_context object through the request object, and have the potential to run multiple io_context instances (one per connection). Given the safety refactoring we had to do in 9838eb20341568971b9543c2187372d20daf64aa that idea is on ice for the moment, and would need a major rethink of code to be viable. For the moment, and in prep for https://gerrit.openbmc.org/c/openbmc/bmcweb/+/75668 make sure all calls are pulling from the same io object. Tested: Unit tests pass. Redfish service validator passes. Change-Id: I877752005c4ce94efbc13ce815f3cd0d99cc3d51 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-02-10Add missing pragma onceEd Tanous1-0/+2
This was found when running gcc -ftime-report, which at the end flags this as possibly missing include header. This appears to have been missed in f51d863523b7bfec5c45b0a847178b5d853404d9 where this was initially added. Add it. Tested: code compiles Change-Id: I31e0ea55c080c239edcd366627ce0829ef9ac41b Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-02-04clang-format: update latest spec and reformatPatrick Williams11-67/+67
Copy the latest format file from the docs repository and apply. Change-Id: I2f0b9d0fb6e01ed36a2f34c750ba52de3b6d15d1 Signed-off-by: Patrick Williams <patrick@stwcx.xyz>
2025-02-04Use specific misc-include-cleaner statementMyung Bae3-13/+4
There are a few places that which clang-tidy seems reporting false-positives and which can be suppressed either via using `modernize-deprecated-headers` or more targeted inline `misc-include-cleaner` statement. Tested: Compiles Change-Id: Ib609adbe8619f4b9a84e08388eea1e7cee58aa54 Signed-off-by: Myung Bae <myungbae@us.ibm.com>
2025-01-31Move io context to singletonEd Tanous1-0/+11
The way we pass around io contexts is somewhat odd. Boost maintainers in slack recommended that we just have a method that returns an io context, and from there we can control this (context link lost years ago). The new version of clang claims the singleton pattern of passing in an io_context pattern is a potential nullptr dereference. It's technically correct, as calling the singleton without immediately initializing the io context will lead to a crash. This commit implements what the boost maintainers suggested, having a single method that returns "the context" that should be used. This also helps to maintain isolation, as some pieces are no longer tied directly to dbus to get their reactor. Tested: WIP Change-Id: Ifaa11335ae00a3d092ecfdfb26a38380227e8576 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-01-31Fix includesEd Tanous35-58/+275
Clang-tidy misc-include-cleaner appears to now be enforcing significantly more headers than previously. That is overall a good thing, but forces us to fix some issues. This commit is largely just taking the clang-recommended fixes and checking them in. Subsequent patches will fix the more unique issues. Note, that a number of new ignores are added into the .clang-tidy file. These can be cleaned up over time as they're understood. The majority are places where boost includes a impl/x.hpp and x.hpp, but expects you to use the later. include-cleaner opts for the impl, but it isn't clear why. Change-Id: Id3fdd7ee6df6c33b2fd35626898523048dd51bfb Signed-off-by: Ed Tanous <etanous@nvidia.com> Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
2025-01-20Use SPDX identifiersEd Tanous40-31/+82
SPDX identifiers are simpler, and reduce the amount of cruft we have in code files. They are recommended by linux foundation, and therefore we should do as they allow. This patchset does not intend to modify any intent on any existing copyrights or licenses, only to standardize their inclusion. [1] https://www.linuxfoundation.org/blog/blog/copyright-notices-in-open-source-software-projects Change-Id: I935c7c0156caa78fc368c929cebd0f068031e830 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-01-20openbmc_dbus_rest: Allow empty interfacesLei YU1-6/+3
In mapper, there is a change to remove the default interfaces for parent objects that not implement any interfaces. So there will be the case to get an object that implements no interfaces from mapper. Handle the case in `handleGet()` so that it does not give error response. Signed-off-by: Lei YU <yulei.sh@bytedance.com> Change-Id: Ia246ff2e65bd25ec2e1c58e191b34892343ecac7
2025-01-13Clang-tidy updates for 19Ed Tanous1-2/+1
Update to add new checks that are now available to us. Fix the minor issues we have. A few of our checks that we previously had enabled have been renamed, so remove those from the file as well. Change-Id: Idbbfc3cb7ba42ac780e557554d7ae8ab190e7551 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-01-06Don't use template for callbackEd Tanous1-5/+4
Using template params for callbacks isn't worth the extra generated code, and reduces our ability to make sure that function callbacks are consistent. In short order after this patchset, std::move_only_function will be supported by gcc, which is the best of both worlds. Change to std::function. Tested: AccountService PATCH Password works properly. No GET usages of this function. Change-Id: I94dd99e5cfb65fabed7e569e04251bec4faf2fc3 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-01-03Move isJSONContentType to content-type parserEd Tanous1-3/+42
Previously this function was based on a basic string comparison. This is fine, but found several inconsistencies, like not handling spaces in the appropriate places. This commit creates a new function getContentType, using the new parsing infrastructure. As doing this, it showed that the existing parser functions were not handling case insensitive compares for the mime type. While this is technically not required, it's something we unit test for, and relatively easy to add. Note, that because this parser ignores charset, this moves charset=ascii from something that previously failed, to something that now succeeds. This is expected. Tested: Unit tests pass. Good coverage Change-Id: I825a72862135b62112ee504ab0d9ead9d6796354 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-01-02Replace unique ptrs with concrete classesEd Tanous1-21/+17
Static analysis notes that these constructors should be using make_unique. While it's right, these don't need to be pointers at all. Tested: No tests for this code available. Change-Id: Ia7383da573e8ffeed7542c94556f59b1e4022d16 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-01-01Transition to simpler trigger interfaceEd Tanous2-20/+2
Using this simpler interface allows us to simplify the unpacking code, and remove the use of a variant containing a variant, which has caused bugs in the past. Splitting these apart allows us to replicate the Redfish interfaces with less code. Tested: Discrete and Numeric triggers both create correctly ``` curl -k --user "root:0penBmc" -H "Content-Type: application/json" -X POST https://192.168.7.2/redfish/v1/TelemetryService/Triggers -d '{"Name": "eds", "NumericThresholds": {"LowerCritical": {"Reading": 1.0, "Activation": "Increasing", "DwellTime": "P1S"}}}' curl -k --user "root:0penBmc" -H "Content-Type: application/json" -X POST https://192.168.7.2/redfish/v1/TelemetryService/Triggers -d '{"Name": "eds", "DiscreteTriggers": [{"DwellTime": "P1S", "Severity": "OK", "Value": "1234"}]} ``` Change-Id: If898e2285f90f78b22e47cc670e4206ba4368665 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-01-01Make trigger use common typesEd Tanous2-16/+24
Trigger having its own variant causes us to duplicate code. This was left out of the original refactoring because it was complex given the variant of a variant status. This commit finally does the port. Tested: Unclear what tests exist for triggers that would use this code ``` curl -k --user "root:0penBmc" -H "Content-Type: application/json" -X POST https://192.168.7.2/redfish/v1/TelemetryService/Triggers -d '{"Name": "eds", "NumericThresholds": {"LowerCritical": {"Reading": 1.0, "Activation": "Increasing", "DwellTime": "P1S"}}}' ``` Succeeds. GET on the resource results in: { "@odata.id": "/redfish/v1/TelemetryService/Triggers/eds", "@odata.type": "#Triggers.v1_2_0.Triggers", "Id": "eds", "Links": { "MetricReportDefinitions": [] }, "MetricProperties": [], "MetricType": "Numeric", "Name": "eds", "NumericThresholds": { "LowerCritical": { "Activation": "Increasing", "DwellTime": "PT1.000S", "Reading": 1.0 } }, "TriggerActions": [] } Change-Id: I8f683cc9423ee2ba111d3ca1889e78f7d33433c9 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-12-28Handle all possible subtypesEd Tanous1-2/+3
Accept header allows any possible parameter value, and expects that unknown property subtypes are simply ignored. We were previously enforcing that things either match q=<number> or have no params. bmcweb has no usage of the params, but allow them to parse silently per the spec in case someone sends them. [1] https://developer.mozilla.org/en-US/docs/Web/HTTP/MIME_types#structure_of_a_mime_type This more meets the intent. In theory we could parse only q and charset values, but allowing any key/values here makes us more resilient against new mime types being added. Tested: Unit tests included and passing Change-Id: I1500be0da4c0c72185ee5bda5dfc31885dc6102d Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-12-17Move getProperty calls to utilityEd Tanous3-8/+52
Having all dbus calls run through the same utility reduces the amount of generated code, and more importantly, gives us a place where we can log the requests and responses to help with debugging. Tested: Redfish service validator passes. Change-Id: Ic1bf45130b5069cd57f7af26e12c8d3159c87c67 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-12-09Add content-encoding parserEd Tanous1-3/+71
Similar to content-type, add an http content-encoding parser. Tested: Unit tests pass. Change-Id: Ic62809934f84804c910458184de19ca9a4207ce5 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-12-07Add Persistent Heartbeat subscription propertiesMyung Bae2-0/+27
This adds Heartbeat parameters to subscriptions so that the future heartbeat implementation can use those parameters specified by the schema [1][2][3]. - SendHeartbeat - HeartbeatIntervalMinutes Tested: 1. POST Subscription - Create a subscription (e.g. via Redfish-Event-Listener) or like ``` curl -k -H "Content-Type: application/json" -X POST https://${bmc}/redfish/v1/EventService/Subscriptions \ -d '{ "Context": "Public", "DeliveryRetryPolicy": "TerminateAfterRetries", "Destination": "https://DESTINATION-IPADDR/Redfish-Evt-Listener", "EventFormatType": "Event", "HeartbeatIntervalMinutes": 2, "HttpHeaders": [], "MessageIds": [], "MetricReportDefinitions": [], "Protocol": "Redfish", "RegistryPrefixes": [], "ResourceTypes": [], "SendHeartbeat": true, "SubscriptionType": "RedfishEvent", "VerifyCertificate": true }' ``` 2. GET the subscription and check the content ``` SUBID=<id> curl -k -X GET https://${bmc}/redfish/v1/EventService/Subscriptions/${SUBID} ``` 3. PATCH Subscription - PATCH with various SendHeartbeat & HeartbeatIntervalMinutes For example, ``` curl -k -X PATCH https://${bmc}/redfish/v1/EventService/Subscriptions/${SUBID} \ -H "Content-Type: application/json" \ -d '{"SendHeartbeat":true, "HeartbeatIntervalMinutes":10}' ``` - Restart bmcweb or reboot BMC - Get the subscription data and see whether the heartbeat properties are persistent. 4. Redfish Validator Service passes [1] https://github.com/openbmc/bmcweb/blob/d109e2b60f7bb367dc8115475c6cb86bca6e1914/redfish-core/schema/dmtf/json-schema/EventDestination.v1_15_0.json#L356 [2] https://github.com/openbmc/bmcweb/blob/d109e2b60f7bb367dc8115475c6cb86bca6e1914/redfish-core/schema/dmtf/json-schema/EventDestination.v1_15_0.json#L222 [3] https://www.dmtf.org/sites/default/files/standards/documents/DSP2046_2022.3.html Change-Id: I9e7feadb2e851ca320147df2231f65ece58ddf25 Signed-off-by: Myung Bae <myungbae@us.ibm.com>
2024-12-03Make accepts a real parserEd Tanous1-54/+35
We somewhat copped out a little with regards to this originally, because writing parsers is hard, and we don't have to implement the full field of what the Accepts header allows. We should aim to be correct where we can, so implement a real parser that parses values, including the floats. Tested: Unit tests pass, good coverage. Change-Id: I1b4232929367d230641be9f41f5af6e6dbcea037 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-11-05Make UserSubscription as shared_ptr in SubscriptionMyung Bae2-19/+11
Currently UserSubscription are used as value in Subscription. This causes the copy of the object between subscriptionsMap and subscriptionConfigMap when doing PATCH. Using a shared_ptr for UserSubscription avoids the memory copy of it. Tested: - Using Redfish Event Listener, test subscriptions and eventing. - Redfish Service Validator passes Change-Id: I5821b72f28ba737a5c9b75288d377766c84c6a6a Signed-off-by: Myung Bae <myungbae@us.ibm.com>
2024-10-23Fix persistent data directory creationMyung Bae1-6/+9
The commit c282e8b6c7f7f4e4ec94e4d1f1a380803e13da08 [1] causes an error like ``` Oct 23 16:46:25 p10bmc bmcwebd[8985]: [CRITICAL persistent_data.hpp:220] Can't create persistent folders Invalid argument ``` It is because the given persistent data filename does not contain the directory name. Tested: - Update subscription data like ``` curl -k -X PATCH https://${bmc}/redfish/v1/EventService/Subscriptions/${SUBID} \ -H "Content-Type: application/json" \ -d '{"VerifyCertificate": false}' ``` - And check the above error. - Restart bmcweb and check whether it is stored [1] https://gerrit.openbmc.org/c/openbmc/bmcweb/+/75314 Change-Id: I0aa4768bbdb195b5247fd30c5078ada60187a4b3 Signed-off-by: Myung Bae <myungbae@us.ibm.com>
2024-10-22Remove annoying logEd Tanous1-2/+0
This log logs for every file on startup, and doesn't really add a lot of value. Remove. Tested: static files are no longer logged on startup. Change-Id: I9394c2c28457b6e846733dde7712aa97bb5a96fc Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-10-22Make sure directory existsEd Tanous1-3/+35
Handle cases where the persistent data directory might not exist, or might not be writable (as would be the case in unit tests) by ignoring the error. This allows unit tests to fail gracefully Tested: Unit tests pass when persistent data dir isn't writable. bmcweb boots and restores file session file normally when manually restarted. Change-Id: Idbd5155bed8be20738a85a55f0d4f876344a2439 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-10-18Fix Persistent Subscription PATCHMyung Bae1-0/+16
The `RedfishEvent` subscription is expected to be persistent over bmc reboot or bmcweb restart. However, the properties on PATCH are currently not persistent after reboot or bmcweb restart. This commit is to sync those properties to the persistent store after PATCH. In addition, this commit fixes a missing `id` copy when a new UserSubscription is created in [1] (introduced by [2]). As a result, it may cause the following messages during bmcweb start after subscription POST or PATCH like ``` Oct 16 14:37:34 p10bmc systemd[1]: Started Start bmcwebd server. Oct 16 14:37:34 p10bmc bmcwebd[15320]: [ERROR event_service_store.hpp:253] Subscription missing required field information, refusing to restore Oct 16 14:37:34 p10bmc bmcwebd[15320]: [ERROR persistent_data.hpp:166] Problem reading subscription from persistent store ``` After this, those subscriptions become lost. Tested: 1. Subscription PATCH - Create a subscription (e.g. use Redfish-Service-Validator). - GET subscription and check the properties ``` SUBID=<id> curl -k -X GET https://${bmc}/redfish/v1/EventService/Subscriptions/${SUBID} ``` - PATCH subscription with a different value. ``` curl -k -X PATCH https://${bmc}/redfish/v1/EventService/Subscriptions/${SUBID} \ -H "Content-Type: application/json" -d '{"DeliveryRetryPolicy":"RetryForever"}' ``` - Reboot BMC or restart bmcweb - GET subscription and check the properties ``` curl -k -X GET https://${bmc}/redfish/v1/EventService/Subscriptions/${SUBID} ```` Before the fix, the property values are the same as before PATCH. After the fix, the last patched property values will be kept. 2. Redfish Service Validator passes [1] https://github.com/openbmc/bmcweb/blob/21a94d5cd4be74a85c978c0cd63e4c633093c531/redfish-core/include/event_service_manager.hpp#L812 [2] https://gerrit.openbmc.org/c/openbmc/bmcweb/+/65720 Change-Id: If5d2f622cc945faa6999d1e3e70211e881e19a79 Signed-off-by: Myung Bae <myungbae@us.ibm.com>
2024-10-14Move UserSubscription to compositionEd Tanous2-32/+33
This allows for two very important simplifying changes. First, we can use the default copy operators on the UserSubscription class, which is far less error prone than writing it manually, which we have two copies of in code already. Second, it allows the Subscription class to move to using values rather than shared_ptr everywhere, which cleans up a significant amount of code. Tested: Ran Redfish-Event-Listener, subscription created and destroyed correctly. Calling POST SubmitTestEvent showed events propagating to server. Change-Id: I6d258cfe3594edddf3960ae2d4559d70acca1bf8 Signed-off-by: Ed Tanous <ed@tanous.net>
2024-10-14Reformat with Never-AlignTrailingComments styleMyung Bae2-5/+5
clang-format currently formats the codes to align the trailing comments of the consecutive lines via `AlignTrailingComments/Kind` as `Always` in `.clang-format` file. This could shift the comment lines by the neighboring code changes and also potentially mislead the `diff` of code changes. This commit is to keep the existing trailing comments as they were. Tested: - Check whitespace only - Code compiles & CI passes. Change-Id: I1c64d53572a81d5012aa748fe44478f80c271c5f Signed-off-by: Myung Bae <myungbae@us.ibm.com>
2024-09-23Add extra subscription params supportEd Tanous2-0/+21
OriginResource allows filtering messages on a per-device basis. This was already listed as supported in our docs. RegistryPrefixes is also added. Tested: Unit tests pass. Change-Id: Idfde8416f2f466ce11957177e052b540fc669888 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-09-16Fix status for non-existent JsonSchema FileGetMyung Bae2-2/+3
This will fix the incorrect status 500 to status 404 for the non-eixstent JsonSchema FileGet. ``` % redfishtool raw GET -r ${bmc} -u root -p 0penBmc -S Always /redfish/v1/JsonSchemas/ComputerSystem/ComputerSystem.v1_99_1.json redfishtool: Transport: Response Error: status_code: 500 -- Internal Server Error redfishtool: raw: Error getting response ``` This commit also refactor `Response::openFile()` to return `ec` so that the caller can check the reason of the failure. Tested: - Verify redfishtool result for the non-existent JsonSchema file like ``` % redfishtool raw GET -r ${bmc} -u root -p 0penBmc -S Always /redfish/v1/JsonSchemas/<schema>/<non-existent-schema>.json redfishtool: Transport: Response Error: status_code: 404 -- Not Found redfishtool: raw: Error getting response ``` - Redfish Service validator passes Change-Id: I98927c076bb6e7dfb3742183b4b3545e328d2657 Signed-off-by: Myung Bae <myungbae@us.ibm.com>
2024-09-11Remove duplicated block commentsEd Tanous2-26/+28
Static analysis flags that these two comments are redundant[1], which seem to be duplicated a lot in copyright headers. Although there is a larger discussion that can likely be had. [1] https://sonarcloud.io/project/issues?issueStatuses=OPEN%2CCONFIRMED&id=edtanous_bmcweb&open=AY9_HYjgKXKyw1ZFwgVP Tested: Comment change only. Code compiles. Change-Id: Ia960317761f558a87842347ca0b5f3da63f8e730 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-09-11dbus_utility: Support new ObjectMapper methodsLakshmi Yadlapati1-0/+38
The new ObjectMapper methods are added as part of https://gerrit.openbmc.org/c/openbmc/phosphor-objmgr/+/70699 - GetAssociatedSubTreeById - GetAssociatedSubTreePathsById The two methods are meant to be used to replace places where two dbus calls are used to get associated objects Change-Id: Ia6dc198ea3c63b9d5a49ba09f1fa999381de8a7c Signed-off-by: Lakshmi Yadlapati <lakshmiy@us.ibm.com>
2024-09-10Fix static analysis issuesEd Tanous1-4/+4
[1] https://sonarcloud.io/project/issues?impactSeverities=HIGH&issueStatuses=OPEN%2CCONFIRMED&tags=since-c%2B%2B11&types=CODE_SMELL&id=edtanous_bmcweb&open=AY9_HYhXKXKyw1ZFwgTE Change-Id: If3d42dd1afed1abe8e4a7db02da9c3b26c4508c2 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-09-04Pam refactoring: To support multiple promptsAbhilash Raju1-95/+50
The commit refactors pam_authenticated.cpp to support newer prompts which may come in future for various MFA options. Now the support restricted to unix Password and google authenticator Verification Code. Tested by: 1: Successful session creation 2: Successful patch operation for password change using below curl -k -H "Content-Type: application/json" -H "X-Auth-Token: $bmc_token" -X PATCH https://${bmc}/redfish/v1/AccountService/Accounts/root -d '{"Password":"xxxxxxxx"}' Change-Id: Iea8696c8a28adefcd5bf62e22978010f38ce8084 Signed-off-by: Abhilash Raju <abhilash.kollam@gmail.com>
2024-09-04Move response creation into PasswordData classEd Tanous1-36/+52
No functional changes. Tested: WIP Change-Id: Ia306322e08690375f170ae82a82cde2aa8ce850d Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-09-04Remove IWYU pragmasEd Tanous3-16/+1
These were added as part of d5c80ad9c07b94465d8ea62d2b6f87c30cac765e: test treewide: iwyu Since then, Nan hasn't been very active on the project, and to my knowledge, since the initial run, we've never used IWYU again. clang-include-cleaner seems to work well without needing these pragmas, and is what we're using, even if it's less useful than IWYU. Remove all mention of IWYU. Tested: Code compiles. Change-Id: I06feedeeac9a114f5bdec81d59ca83223efd8aa7 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-08-28Fix password updateEd Tanous1-2/+66
There is a regression issue found with this commit in password update https://gerrit.openbmc.org/c/openbmc/bmcweb/+/73605 This commit fixes PAM conversation for password update Tested by: PATCH https://${bmc}/redfish/v1/AccountService/Accounts/root -d '{"Password":"0penBmc1"}' Change-Id: Ifcede67364c35ced899a3f726f67253cdb51002e Signed-off-by: Ed Tanous <etanous@nvidia.com> Signed-off-by: Ravi Teja <raviteja28031990@gmail.com>
2024-08-23Redfish Session: Implement MFA "Token" propertyRavi Teja3-19/+39
This commit implements multi-factor authentication "Token" property to create redfish sessions when multi-factor token authentication enabled. Tested by: Verified redfish session and login redfish commands with or without TOTP token for MFA enabled/disabled users. User authentication with MFA token: POST https://${bmc}/redfish/v1/SessionService/Sessions -d '{"UserName" :"root", "Password": "0penBmc","Token":"510760"}' User authentication without MFA token: POST https://${bmc}/login -d '{"username" : "newuser", "password" :"0penBmc"}' POST https://${bmc}/redfish/v1/SessionService/Sessions -d '{"UserName" :"newuser", "Password": "0penBmc"}' In case of invalid MFA token or password then authentication fails and returns "ResourceAtUriUnauthorized" error message. Change-Id: I639163dd3d49ff8ed886f72c99ad264317d59c34 Signed-off-by: Ravi Teja <raviteja28031990@gmail.com>
2024-08-23Fix NOLINT in pam moduleEd Tanous1-50/+42
There's a number of places in the pam module where we do pointer manipulation by hand. This is because pam relies on passing pointers. This commit updates to at least using unqiue_ptr with release(), as well as std::span, rather than using raw pointers. Tested: Tested in token commit. Will merge at same time. Change-Id: Ie49f7e6eeaa5c7ac1798b9a123e3ab5439a4ab28 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-08-17clang-format: re-format for clang-18Patrick Williams21-1418/+1475
clang-format-18 isn't compatible with the clang-format-17 output, so we need to reformat the code with the latest version. The way clang-18 handles lambda formatting also changed, so we have made changes to the organization default style format to better handle lambda formatting. See I5e08687e696dd240402a2780158664b7113def0e for updated style. See Iea0776aaa7edd483fa395e23de25ebf5a6288f71 for clang-18 enablement. Change-Id: Iceec1dc95b6c908ec6c21fb40093de9dd18bf11a Signed-off-by: Patrick Williams <patrick@stwcx.xyz>
2024-08-06Remove inline operatorEd Tanous1-2/+2
Clang-18 flags this as a redundant inline operator, which is correct. Remove it. Tested: Code compiles. Change-Id: I89d808f05cfc123b7884d1e0652cdd3912e2a674 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-08-06Add missing nullptr checkEd Tanous1-0/+5
Static analysis flags two missing nullptr checks. Add them. Tested: dbus-rest is a deprecated option, so unit testing is the only difference there. Log services notify was added recently. Need help testing, otherwise inspection only. Change-Id: If92153ffa9c9fdf8903ce386f025ceebcf7510eb Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-07-30Break out SSL key handler into a compile unitEd Tanous4-600/+26
This commit allows for no code to have to pull in openssl headers directly. All openssl code is now included in compile units, or transitively from boost. Because http2 is optional, no-unneeded-internal-declaration is needed to prevent clang from marking the functions as unused. Chromium has disabled this as well[1] Tested: Redfish service validator passes. [1] https://issues.chromium.org/issues/40340369 Change-Id: I327e8ffa45941c2282db804d0be56cf64155e67d Signed-off-by: Ed Tanous <ed@tanous.net>
2024-07-30Combine cipher suite listsEd Tanous1-26/+15
It's better to not have to update this in two places. Tested: Inspection only. Change-Id: I5c81e50806fe71dd251c22132d93ecbc55fc3865 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-07-30Update client ciphers to mozilla intermediateEd Tanous1-4/+2
Our client cipher suites are out of date with what mozilla recommends. Update them to the latest. https://ssl-config.mozilla.org/guidelines/5.7.json Functionally, this only removes the two remaining AES cipher suites. TLS_AES_128_GCM_SHA256 TLS_AES_256_GCM_SHA384 And replaces TLS_CHACHA20_POLY1305_SHA256 with DHE-RSA-CHACHA20-POLY1305 Functionally this should have no impact on any system. Change-Id: I7680b06ea34c2a3c0bfd747aa3c3500c0f30151e Signed-off-by: Ed Tanous <ed@tanous.net>
2024-07-25Remove support for openssl < 3.0Ed Tanous1-73/+0
OpenSSL 3.0+ has technically been required since e79239970c3701f12903e8ac1574b9210b69aebc checked in 7 months ago. We don't seem to be going backwards, so remove code support for <3.0. OpenSSL 1.1.1 was declared EOL 10 months ago [1] [1] https://endoflife.date/openssl Change-Id: I54f0d475dfa79ee7959f1b4278d3790c988de0af Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-07-24Support reading zstd filesEd Tanous1-0/+7
Similar to how we already support gzip files, allow reading zstd files from disk, under their non zstd name. Files ending in .zstd will now be treated as zstd compressed. Tested: Manually loaded a zstd core dump into the folder; Curl succeeds in getting file. Change-Id: I49a92b823117f89fcaebd3b54f0ad93582b3bbdf Signed-off-by: Ed Tanous <ed@tanous.net>
2024-07-23EventDestination: Implement VerifyCertificateEd Tanous3-2/+26
VerifyCertificate is a property on the Redfish EventDestination schema. It specifies that this property is: ``` An indication of whether the service will verify the certificate of the server referenced by the `Destination` property prior to sending the event ``` To keep prior behavior, and to ensure behavior that's secure by default, if the user omits the property, it is assumed to be true. This property is also persisted and restored. Tested: Redfish-Event-Listener succeeds with the following procedure Start Redfish-Event-Listener PATCH /redfish/v1/Subscriptions/<subid> VerifyCertificate: false POST /redfish/v1/EventService/Actions/EventService.SubmitTestEvent Redfish-Event-Listener then hits an internal error, due to an encoding compatibility unrelated to this patch, but is documented in the receiver [1] POST of a subscription with VerifyCertificate: false set, succeeds. [1] https://github.com/DMTF/Redfish-Event-Listener/blob/6f3f98beafc89fa9bbf86aa4f8cac6c1987390fb/RedfishEventListener_v1.py#L61 Change-Id: I27e0a3fe87b4dbd0432bfaa22ebf593c3955db11 Signed-off-by: Ravi Teja <raviteja28031990@gmail.com> Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-07-16Fix coredump when restart service if created subscriptionswenlitao1-14/+14
When multiple subscriptions are created using the redfish url: /redfish/v1/EventService/Subscriptions/, a coredump occurs during the bmcweb restart process. The problem was found when saving the subscription configuration during the service stop process, remove the newly created shared pointer 'subValue' and use the pointer in the map directly, this problem was solved. Tested: Create 18 subscriptions and restart the service 300 times without coredump generation. Change-Id: Ide90abdbc4c6e88215049783b88d9e91902c554d Signed-off-by: wenlitao <w_litao@linux.alibaba.com>
2024-07-14Break out DuplicatableFileHandleEd Tanous1-0/+27
Static analysis notes that writing non-trivial move constructors and move operator= handlers is non trivial [1]. Funnily enough, we actually already had bugs on this that were fixed in 06fc9be. Simplify the code. Tested: Redfish service validator passes. [1] https://sonarcloud.io/project/issues?issues=AY9_HYiwKXKyw1ZFwgUG%2CAY9_HYiwKXKyw1ZFwgUF&id=edtanous_bmcweb&open=AY9_HYiwKXKyw1ZFwgUG Change-Id: If96383d8c669ae9e5a8cc13304071b2dfe1ff2d2 Signed-off-by: Ed Tanous <ed@tanous.net>