| Age | Commit message (Collapse) | Author | Files | Lines |
|
Move long lambdas in getUserInfo() and onRequestRecv() into named
functions, afterGetUserInfo() and afterCompleteRequest(), per the <10
line lambda rule in docs/COMMON_ERRORS.md. No functional change.
Tested:
- Tested on AST2600 SoC.
- getUserInfo/afterGetUserInfo: sent an authenticated Basic-auth Redfish
GET and confirmed a 200 response with no "Failed to populate user
information" error in journalctl, proving populateUserInfo() succeeded
via the extracted callback.
- onRequestRecv/afterCompleteRequest: RSV's client uses HTTP/1.1, so it
does not exercise this HTTP/2-only code path. Instead, used
"curl --http2" and confirmed ALPN negotiated h2 and the request
completed as HTTP/2 200. journalctl -u bmcweb confirmed both
"onRequestRecv streamId:1" and the extracted callback's
"res.completeRequestHandler called" fired for that stream.
- Redfish Service Validator: 5830 Pass / 353 Warn / 0 Fail.
Change-Id: I0e6365c682f6acc8d39510ad5f1fe239d747154f
Signed-off-by: Yuvakumar Selvamani <yuvakumars@ami.com>
|
|
Use http_helpers::getContentType() when deciding whether to add
HTML-only security headers.
Previously this logic checked the raw Content-Type header with a
text/html prefix match. That worked for the values we emit today,
but it open-coded Content-Type handling in this path instead of using
the existing parser.
Switch this logic to getContentType() so it stays consistent with
the rest of the code and correctly handles valid variations such as
case-insensitive HTML MIME types.
Add unit coverage for getContentType() to verify HTML MIME types
with charset parameters and case-insensitive input.
Tested: unit tests passed.
Change-Id: I1cff40453ab4851cc7b24615a20fb6abcfba864b
Signed-off-by: Joel Pullokaran Jesin <joelpj@ami.com>
|
|
This regressed when the bypass was added. Fix the code for
resolver=asio to properly construct the results object using the built
in asio type instead of std::vector.
Tested: Code compiles with resolver=asio again.
Change-Id: I3d9ddc38b88a392cf82fc81bd5609f3360837393
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Mozilla publishes recommendations for TLS cipher suites to support. For
many years bmcweb selected "intermediate" because of compatibility with
clients that didn't yet support TLS1.3.
This commit adds the ability to use the Mozilla modern recommendations,
and disable TLS1.2 support through a new meson option, tls-profile.
Tested:
Loaded on qemu, and verified with testssl.sh[1] that parameters were
applied.
[1] https://github.com/testssl/testssl.sh
Change-Id: I38e915b3943b5dbe5fb31e54eb3ebda9bbaeb811
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Long lambdas have been documented as an anti-pattern for some time.[1]
Despite this being generally understood, bmcweb has a long ways to go
cleaning these up, and routinely code is submitted in violation of this
anti-pattern.
Invent an ast-grep rule that can identify when new examples of this
anti-pattern are added, and ignore the existing 200+ examples that are
in the codebase already using ast-grep ignore. These flags will give us
something to search for as we clean this up, and will help to prevent
new instances from being added unintentionally.
[1] https://github.com/openbmc/docs/blob/master/anti-patterns.md#very-long-lambda-callbacks
Tested: Comment only change. ast-grep passes. Manually removing an
ast-grep ignore flag shows as a failure in ast-grep scan
Change-Id: I77d634a393884969f184d2c39c02cc08288d5a29
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
The sdbusplus headers provide shortened aliases for many types.
Switch to using them to provide better code clarity and shorter
lines. Possible replacements are for:
* exception_t
* manager_t
* match
* match_rules
* message_t
* object_t
* slot_t
Change-Id: Iaf2a83fb67d57a6fafb664d27b349add17a96bcd
Signed-off-by: Patrick Williams <patrick@stwcx.xyz>
|
|
Even though the certificate is self signed, we should pass as many
certificate tests as possible. testssl.sh prints
```
Serial 4B32D4F0 NOT ok: length should be >= 64 bits entropy (is: 4 bytes)
```
On our default certificate. This is relatively easy to fix.
Change-Id: Ib1eb07b637ebf49ecf954b3d98ced9e9ef0f5a34
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Continue moving OpenSSL into reusable RAII classes that can be used in
unit tests and other places. This is slightly more code, but as we're
adding unit tests, it allows reuse between unit tests rather than
writing C directly. It also encapsulates the complexity of parsing
openssl output (usually in bytes) into standard types (string) that can
be compared/modified.
Functionally this adds two new classes to the "wrappers" functions,
OpenSSLSSLCtx and OpenSSLSSL, which each wrap SSL_CTX and SSL objects
respectively from openssl. These are rough approximations of the boost
equivalents.
Change-Id: Id87ac4ccde88890bd70861deffdb256188ec0e39
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
The sdbusplus headers provide shortened aliases for many types.
Switch to using them to provide better code clarity and shorter
lines. Possible replacements are for:
* bus_t
* exception_t
* manager_t
* match_t
* message_t
* object_t
* slot_t
* object_path
Change-Id: I05ee2b2cda7c4468ab4117c751ecee797121b7dd
Signed-off-by: Patrick Williams <patrick@stwcx.xyz>
|
|
PATCH /redfish/v1/AccountService/Accounts/ with {"Enabled":false}
flipped UserEnabled on D-Bus but left every active X-Auth-Token session
for that user fully usable. Subsequent token-authenticated requests
continued to succeed (200 OK) until the token's natural expiry, even
though Basic auth for the same account was correctly rejected (401).
DELETE on the same resource does not have this problem because removing
the user object emits InterfacesRemoved, and bmcweb::onUserRemoved (in
include/user_monitor.hpp) handles that signal by calling
removeSessionsByUsername.
Add onUserPropertiesChanged() in include/user_monitor.hpp that drops
the user's sessions via SessionStore::removeSessionsByUsername() when
User.Attributes.UserEnabled transitions to false.
This handles disable of user both from IPMI and Redfish
Tested :
```
Create new user
curl -k -u ${USER}:${PASSWD} -X POST
https://127.0.0.1:2443/redfish/v1/AccountService/Accounts -d '{
UserName:test_admin, Password:Shahapur#13!Shahapur, RoleId:Administrator, Enabled:true}'
{
"@Message.ExtendedInfo": [
{
"@odata.type": "#Message.v1_1_1.Message",
"Message": "The resource was created successfully.",
"MessageArgs": [],
"MessageId": "Base.1.19.Created",
"MessageSeverity": "OK",
"Resolution": "None."
}
]
}
Create a-auth-token
curl --insecure -X POST -D headers.txt https://127.0.0.1:2443/redfish/v1/SessionService/Sessions -d '{"UserName":"test_admin", "Password":"Shahapur#13!Shahapur"}'
{
"@odata.id": "/redfish/v1/SessionService/Sessions/YLMzEtANWr",
"@odata.type": "#Session.v1_7_0.Session",
"ClientOriginIPAddress": "10.0.2.2",
"Description": "Manager User Session",
"Id": "YLMzEtANWr",
"Name": "User Session",
"Roles": [
"Administrator"
],
"UserName": "test_admin"
}
$ cat headers.txt
HTTP/2 201
allow: GET, HEAD, POST
odata-version: 4.0
x-auth-token: VcufgTshiDjEn8HbGh31
location: /redfish/v1/SessionService/Sessions/YLMzEtANWr
strict-transport-security: max-age=31536000; includeSubdomains
pragma: no-cache
cache-control: no-store, max-age=0
x-content-type-options: nosniff
content-type: application/json
date: Wed, 06 May 2026 12:45:18 GMT
content-length: 305
// Test RF request with token
curl -k -H 'x-auth-token:VcufgTshiDjEn8HbGh31' https://127.0.0.1:2443/redfish/v1/AccountService/Accounts
{
"@odata.id": "/redfish/v1/AccountService/Accounts",
"@odata.type": "#ManagerAccountCollection.ManagerAccountCollection",
"Description": "BMC User Accounts",
"Members": [
{
"@odata.id": "/redfish/v1/AccountService/Accounts/test_admin"
},
{
"@odata.id": "/redfish/v1/AccountService/Accounts/root"
}
],
"Members@odata.count": 2,
"Name": "Accounts Collection"
}
// Disable the user
curl -k -u root:0penBmc https://127.0.0.1:2443/redfish/v1/AccountService/Accounts/test_admin -X PATCH -d '{"Enabled":false}'
204
// Try to use the Tokens
curl -k -H 'x-auth-token:VcufgTshiDjEn8HbGh31' https://127.0.0.1:2443/redfish/v1/AccountService/Accounts
401
```
Change-Id: I3246d3f5ec7db405c9c186a8672a9fed18259249
Signed-off-by: Chandramohan Harkude <chandramohan.harkude@gmail.com>
|
|
Previously, firmware updates via multipart/form-data stored two copies
of the entire upload in memory (200MB+ for a 100MB image). This change
reduces memory usage by incrementally processing multipart data in
chunks, running through the parser as required. This avoids a copy into
the http body. With this change, bmcweb no longer retains any duplicate
copy of the image in memory, thereby limiting memory consumption to
roughly the size of the image itself.
To accomplish this, the multipart parser is rewritten to support
incremental parsing. This should be 100% compatible with the old
parser, with one exception, bytes at the end of the payload are no
longer accepted and ignored.
Tests:
Multipart FW Update using a 114.2MB file shows bmcweb memory usage in
line with one copy of the image, not two. Unit tests pass.
Change-Id: Id18e20004059bfbc7de62f4f6c9542430c7943b0
Signed-off-by: Rajeev Ranjan <ranjan.rajeev1609@gmail.com>
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Current unit tests only covers happy path. Add more unit tests before
changing the code.
Tested: unit tests
Change-Id: Ibba5dbbc1457b59670d5d8f3c828fa9ca112f88c
Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
|
|
bmcweb openssl usage is a mess. Start cleaning it up.
1. Make RAII objects for any held memory.
2. Move methods from hostname monitor into the ssl namespace, so not all
compile units need to pull in openssl headers
3. Move methods to static where functions can be encapsulated.
Because we're now testing openssl, we need to register memory init so
that the sanitizers don't cause issues when mallocing from non
bootstrapped openssl binaries. Openssl provides a handle for this, so
use it in those unit tests.
Tested:
Unit tests pass. bmcweb launches and can open ssl with curl as it did
previously.
Change-Id: If0340692d2c56a6c45bb8d661d654a4b58ff3d2c
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Per common error #5 failing to catch thrown exceptions can lead to a
crash. It turns out that the boost::beast::http::fields::set call can
throw in extreme circumstances (large headers). There are two uses to
clean up. Port these to using an overload that returns an error code to
make sure that we don't accidentally set headers or throw an uncaught
exception.
[1] https://github.com/openbmc/bmcweb/blob/master/docs/COMMON_ERRORS.md#5-using-methods-that-throw-or-not-handling-bad-inputs
Tested: Verified unit test coverage on both of these.
Change-Id: I996b64ebb34c4ff7f4e582506d1acfabea05d72e
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
The VerifyCertificate enum has Verify=0 and NoVerify=1.
Subscription code casts the Redfish VerifyCertificate bool
directly to this enum:
static_cast<VerifyCertificate>(userSub->verifyCertificate)
This maps true(1) to NoVerify and false(0) to Verify,
inverting the intended behavior. Subscriptions that request
certificate verification (VerifyCertificate: true) get
verify_none, and subscriptions that skip verification get
verify_peer.
Swap the enum values so NoVerify=0 and Verify=1, matching
boolean semantics. All other code references the enum by
name (VerifyCertificate::Verify, ::NoVerify), so swapping
the underlying values is safe.
This bug was introduced in change 72590 and means outbound
TLS certificate chain validation has never been enforced for
Redfish Event subscriptions that request it.
Closes openbmc/bmcweb#321
Tested: Docker CI passes (format, build, all tests).
Booted OpenBMC on AST2600 (evb-ast2600-renode) in Renode 1.16,
drove Redfish subscriptions through bmcweb's outbound TLS path to
a test HTTPS server presenting a leaf signed by an external CA that
was NOT installed in the BMC trust store.
Phase 1 (upstream/master, no patch applied):
Rejects Handshake When VerifyCertificate=true FAIL
"Event was delivered despite a cert that should have caused
rejection."
Delivers When VerifyCertificate=false FAIL
marker file never created; event was not delivered.
Both failures reproduce the inversion: true -> NoVerify
(handshake succeeds against untrusted CA), false -> Verify
(handshake rejected).
Phase 2 (upstream/master + this patch):
Rejects Handshake When VerifyCertificate=true PASS
Delivers When VerifyCertificate=false PASS
true -> Verify (handshake correctly rejected), false ->
NoVerify (event delivered as requested). Both paths inverted
back to their documented semantics.
Change-Id: Iecf1d03d2caee141f6eb4a6a4f284e4e36a3b693
Signed-off-by: Gary Beihl <garybeihl@microsoft.com>
|
|
The sdbusplus headers provide shortened aliases for many types.
Switch to using them to provide better code clarity and shorter
lines. Possible replacements are for:
* bus_t
* exception_t
* manager_t
* match_t
* message_t
* object_t
* slot_t
* object_path
Change-Id: Iace20f9ad26e8d9dc234979e7a4087d599da2641
Signed-off-by: Patrick Williams <patrick@stwcx.xyz>
|
|
We should have a single entry point where we do json parsing. There are
configurations for nlohmmann that we had previously documented, but were
not well enforced. Move all uses to using the helper parse functions.
Tested: Unit tests pass.
Redfish service validator passes.
Change-Id: I2a8aed9327b6b15219dc9b4d6db146b69bcd8eb3
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
TLS session resumption allows to bypass full TLS handshake in subsequent
connections, it's enabled in OpenSSL, so clients that support it use it.
One of the optimizations is, the client passes Session ID in subsequent
request and does not pass certificates. Since client certificate is not
passed, the callback that populates user session out of the certificate
is not called, and as result, auth fails for requests sents in
subsequent connections. This change enables session ID in memory cache,
lookup of the certificate in the cache by the session ID received from
the client and constructing user session out of it for subsequent
connections.
The cache is stored in RAM [1]. According to Nginx doc [2], size of one
session is about 250 bytes. If sessions use mTLS, they will also contain
a cert which is typically up 2kb. A client establishes connections as
part of a session, so a session can be associated with multiple
connections. In the worst case, when many clients establish a single
connection at a time, or a client always uses a new session for every
established connection, there will be number of session entries in the
cache equals to the number of connections. While OpenSSL limits cache
size to SSL_SESSION_CACHE_MAX_SIZE_DEFAULT which is 20480 [3], OpenBMC
limits number of established connections to 200 [4], so in the worst
case, memory usage will be ~50kb for non mTLS clients, and ~440kb for
mTLS clients. Typically, when there are just 2-3 clients connected, even
if them maintain multiple connections within their sessions, the cache
size will be less than 10kb for mTLS. To prevent high memory usage by
the cache, the change sets cache size to 100 entries. Expired sessions
are automatically removed on every 255th session [5].
Tested:
Deployed on one of our envs and ran client that quickly sends multiple
requests to the BMC (so the client created several connections), and
make sure the 401 auth problem had been observed before gone. Also, made
sure BMCWeb logged debug messages about existing session detection.
Ran tests from the openbmc-test-automation repository, esp related to
certificate and user management. They do session auth and not
mTLS/multi-connection, so they could not detect/confirm the problem is
fixed, but they confirm the change does not break the primary use case.
[1] https://docs.openssl.org/3.6/man3/SSL_CTX_set_session_cache_mode/#notes
[2] https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache
[3] https://github.com/openssl/openssl/blob/5869303daaecf037f0d00dc33a00f9bdc1e71f2f/include/openssl/ssl.h.in#L670
[4] https://github.com/openbmc/bmcweb/blob/master/http/http_connection.hpp#L219C13-L219C28
[5] https://docs.openssl.org/3.6/man3/SSL_CTX_flush_sessions/#notes
Change-Id: Ia94d1e323cd464cc7ca5b0f9c7d6a76e4c780e9a
Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
|
|
In preparation for making the multipart parser incremental, modify the
API to explicitly call out steps of start, parsePart, and finish. This
allows the parser to support incremental per-character parsing in the
future.
This also has the benefit of dropping the dependency on the Request
struct on the multipart parser itself.
Tested: Unit tests pass. Good coverage.
Change-Id: I3359f45bb9faaea42908491a818cc4a81f257a1f
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
The webui-vue project migrated from webpack to Vite, which changes
the output filenames. Vite names entry chunks as index.[hash].js
instead of webpack's app.[hash].js. The starts_with("index.") check
in addFile() was remapping these JS/CSS files to their parent directory
path (intended only for index.html), causing 404 errors when the
browser requested the actual asset URLs.
Restrict the index file detection to only apply to .html files, so
that index.html is still correctly mapped to "/" while other files
starting with "index." are served at their actual paths.
Also broaden the etag hash detection from hex-only characters to full
alphanumeric to support Vite's base64-style content hashes alongside
webpack's hex hashes.
Add unit tests for getStaticEtag() covering both webpack and Vite hash
formats, path prefixes, edge cases, and validation of hash length and
character constraints.
Tested:
Unit tests pass
Vite-based webui-vue loads and caches etags
Change-Id: I3f7d2e062d0fd8be4ded7889b64a7228b4a6459b
Signed-off-by: Jason Westover <jwestover@nvidia.com>
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
There is nothing in the multipart spec[1] that states that a parser
should allow any bytes after a multipart payload.
Several unit tests have a \r\n after their boundary condition that
previously the parser just ignored. Testing shows this is fairly
normal, so handle both cases still, but if any other characters show up,
fail the parse.
Unit test is also simplified to be more clear.
Tested: Unit test coverage
[1] https://datatracker.ietf.org/doc/html/rfc7578#section-4.1
Change-Id: I16643c61867708886cc87c236447ec1c19bf934f
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
nlohmann::json::begin() throws an uncaught exception.
Tested: Redfish service validator passes.
Signed-off-by: Ed Tanous <ed@tanous.net>
Change-Id: I08244b0787cd4d6e592b0731196490a5160aba62
|
|
This tidy check can transform code to use std::ranges. Enable the
check, apply the fixes it proposes.
Tested: Redfish service validator passes in qemu
Change-Id: I3f21b27d3d30277f71b9c8a2c584a22bc16865e9
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Update the subtree boost to 1.89; Keep the "required" version at 1.88
because that's currently what yocto uses. Now that we don't need old
versions, the branch for boost 1.84 support is removed, and we can
universally pull in boost::process as a library.
Additionally boost::core::string_view has defined a std::formatter
nearly identical to what was done there, so there's now a conflict.
Add a version check and shift to the boost provided formatter when
it's available.
Tested: Code builds out of tree correctly.
Change-Id: I15a10da084da8f9d9460781b16a0fdc92987fc9a
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Add support for PeakReading and PeakReadingTime for sensors. This
enhancement allows sensor readings to include max observed value
information in the Redfish API, along with timestamp. It uses PDI
xyz.openbmc_project.Telemetry.Report. Property PeakReading is added if
OperationType in PDI property ReadingParameters is set to Maximum.
Current Limitation -
The ResetMetrics action is currently not supported for sensor URIs. As a
result, the ability to clear PeakReading values for GPU Power Sensors
has not been implemented.
Future Consideration -
If ResetMetrics action support is added in the future, the corresponding
functionality will also need to be implemented in the dbus-sensor
application to ensure full compatibility.
Schema:
https://redfish.dmtf.org/schemas/v1/Sensor.v1_2_0.yaml (PeakReading)
Backend implementation for reference:
https://gerrit.openbmc.org/c/openbmc/dbus-sensors/+/82479
Tested: Build an image for nvl32-obmc machine with the following patches
cherry picked.
https://gerrit.openbmc.org/c/openbmc/openbmc/+/85490
https://gerrit.openbmc.org/c/openbmc/bmcweb/+/82449.
The patch cherry-picks the following patches that are currently under
review.
```
1. device tree
https://lore.kernel.org/all/aRbLqH8pLWCQryhu@molberding.nvidia.com/
2. mctpd patches
https://github.com/CodeConstruct/mctp/pull/85
3. u-boot changes
https://lore.kernel.org/openbmc/20251121-msx4-v1-0-fc0118b666c1@nvidia.com/T/#t
4. kernel changes as specified in the openbmc patch (for espi)
5. entity-manager changes
https://gerrit.openbmc.org/c/openbmc/entity-manager/+/85455
6. platform-init changes
https://gerrit.openbmc.org/c/openbmc/platform-init/+/85456
7. spi changes
https://lore.kernel.org/all/20251121-w25q01jv_fixup-v1-1-3d175050db73@nvidia.com/
```
```
> curl -s -k -u 'root:0penBmc' https://10.137.203.137/redfish/v1/Chassis/NVIDIA_GB200_1/Sensors/power_NVIDIA_GB200_GPU_0_Power_0
{
"@odata.id": "/redfish/v1/Chassis/NVIDIA_GB200_1/Sensors/power_NVIDIA_GB200_GPU_0_Power_0",
"@odata.type": "#Sensor.v1_2_0.Sensor",
"Id": "power_NVIDIA_GB200_GPU_0_Power_0",
"Name": "NVIDIA GB200 GPU 0 Power 0",
"PeakReading": 52.671,
"PeakReadingTime": 0,
"Reading": 27.214,
"ReadingRangeMax": 5000.0,
"ReadingRangeMin": 0.0,
"ReadingType": "Power",
"ReadingUnits": "W",
"Status": {
"Health": "OK",
"State": "Enabled"
}
}%
````
Change-Id: I8c1ab6ce85f31419db4a1d931bf99722d24afbd7
Signed-off-by: Harshit Aghera <haghera@nvidia.com>
|
|
This commit adds file descriptor and temporary file management to
DuplicatableFileHandle, removing the redundant test-only
TemporaryFileHandle utility.
Changes:
- Add file descriptor constructor and setFd() method
- Add temporary file constructor with string_view content
- Add filePath member and automatic cleanup in destructor
- Add configurable temp-dir meson option (default: /tmp/bmcweb)
- Remove include/file_test_utilities.hpp
- Update all tests to use DuplicatableFileHandle
- Rename stringPath to filePath
These features will be used by the multipart parser to stream
large uploads to temporary files instead of keeping them in memory,
and by the update service to pass file descriptors over D-Bus.
Change-Id: I982f5928d453f9f0c13d91c3525006134ddc87b3
Signed-off-by: Rajeev Ranjan <ranjan.rajeev1609@gmail.com>
|
|
Currently if we don't have account in bmcweb but have valid format
certificate, we will have 500 internal server error when we send request
to bmcweb. But, if we don't have valid format certificate, we will get
401 unauthorized. This is not ideal as the http code is not appropriate.
Also, this might introduce some security risk as the user can deduce
whether their certificate format is valid or not based on the http code.
This patch is intended to solve this issue by checking whether the
username exists in the system. If not, we will return nullptr inside
verifyMtls function, which result in 401 unauthorized response if the
user have valid format of certificate, but there is no related username
inside the system
Change-Id: I479a10ed2bcce2c9969e19fa3aab9686ba4c71be
Signed-off-by: Malik Akbar Hashemi Rafsanjani <malikrafsan@meta.com>
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Rather than defining a variable and then reading it from a message,
sdbusplus also supports directly unpack-ing from the message. Use
this syntax instead as it is more efficient and succinct.
Signed-off-by: Patrick Williams <patrick@stwcx.xyz>
Change-Id: Iebf93534fb4b68ec5f37f0b81fbe3456831d5d70
|
|
There's only a couple remaining places we use json IO. Not including IO
improves compile times in a minor way, because the nlohmann stream/file
template is relatively expensive to compile.
Tested: Launched bmcweb. Observed bmcweb_persistent_data.json created.
Rebooted bmcweb with 'systemctl restart bmcweb' and observed launched
correctly with persistent file present.
Change-Id: I56f674f20fa8553dc86245a765818849aa5fa102
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
This utility function is being removed for several reasons. First, it
does not verify the full string on URIs and paths, so things like
/foo/bar/baz/valid_id would still pass this check.
Second, it is used for both URIs and dbus paths, both of which we have
better utility functions these days respectively, boost::url for urls
and sdbusplus::message::object_path for dbus paths. Neither of the two
is escaped properly when this function is used.
Therefore, remove it and replace it with the appropriate alternatives.
The existing URI functions were found to not accept fragments (given
they are rarely used in PATCH). Add support for fragments to cover the
getNthStringFromPath use cases.
Tested: Redfish service validator passes.
Change-Id: Ibc6755ad69397123d7fef0e0b764042bbb48888b
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Reading the state dir from the systemd service file gives us
flexibility to define the bmcweb state from wherever we like, rather
than just using the current directory, which might not be writable.
Tested: bmcweb boots, shows state is persisted in the same location as
previously.
Change-Id: I9c048421fe249b73b1cae2ff5204ffd357cd3123
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Now that all applications run through one CLI, names like run() don't
make a lot of sense. Update names to match the new reality, make bmcweb
with no arguments launch the webserver once again.
Tested: bmcweb boots.
Change-Id: I011b57507872a9518a9c470b58779805504c7293
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
aarch64 gcc warns on this line. Fix it.
Change-Id: Ic752cda31f27b7d68af99ca53efcdfcdf0e659a7
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Our includes haven't been enforced by tidy in a while. Run the script,
check in the result, minus the false positives.
Change-Id: I6a6da26f5ba5082d9b4aa17cdc9f55ebd8cd41a6
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
The previous commit 90cd2e1 [1] causes WebUI to fail to load and
connect. It is because a global static var (`hasWebuiRoute`) is
instantiated per compile unit and it ends up causing the inconsistency
of the value of it.
Tested:
- Verify WebUI to load successful
- Redfish Service Validator passes
[1] https://github.com/openbmc/bmcweb/commit/90cd2e1d2e2228b0c575c9a3b6b2dc75eac9eb68
Change-Id: I09c3a9a831528e25c09299b0ee15993974d94d88
Signed-off-by: Myung Bae <myungbae@us.ibm.com>
|
|
Add `#pragma once` to a header file.
Noticed this issue when trying unity build in yocto environment.
```
bbmcweblib.a.p/bmcweblib-unity0.cpp
| In file included from ../git/redfish-core/lib/network_protocol.hpp:14,
| from /home/alexander/openbmc/build/s8030/tmp/work/arm1176jzs-openbmc-linux-gnueabi/bmcweb/1.0+git/build/../git/redfish-core/src/redfish.cpp:30,
| from libbmcweblib.a.p/bmcweblib-unity0.cpp:13:
| ../git/include/identity.hpp:7:20: error: redefinition of 'std::string getHostName()'
| 7 | inline std::string getHostName()
| | ^~~~~~~~~~~
| In file included from /home/alexander/openbmc/build/s8030/tmp/work/arm1176jzs-openbmc-linux-gnueabi/bmcweb/1.0+git/build/../git/http/mutual_tls.cpp:7,
| from libbmcweblib.a.p/bmcweblib-unity0.cpp:1:
| ../git/include/identity.hpp:7:20: note: 'std::string getHostName()' previously defined here
| 7 | inline std::string getHostName()
| | ^~~~~~~~~~~
| ninja: build stopped: subcommand failed.
| INFO: autodetecting backend as ninja
```
Tested: Inspection only.
Change-Id: Ib7811ee12da763203b50fc81d39d642d2de3e212
Signed-off-by: Alexander Hansen <alexander.hansen@9elements.com>
|
|
Given the size of Redfish schemas these days, it would be nice to be
able to store them on disk in a zstd format. Unfortunately, not all
clients support zstd at this time.
This commit implements reading of zstd files from disk, as well as
decompressing zstd in the case where the client does not support zstd as
a return type.
Tested:
Implanted an artificial zstd file into the system, and observed correct
decompression both with an allow-encoding header of empty string and
zstd.
Change-Id: I8b631bb943de99002fdd6745340aec010ee591ff
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Implements GET and PATCH support for ServiceIdentification in
Managers/bmc and service root.
Tested:
- Refish Service Validator passes
- Tested on romulus:
1. GET initial value
```
curl -k "https://$BMC/redfish/v1"
{
...
}
```
ServiceIdentification is not yet present in service root,
as expected
```
curl -k -H "X-Auth-Token: $XAUTH_TOKEN" "https://$BMC/redfish/v1/Managers/bmc"
{
...
"ServiceIdentification": "",
...
}
```
2. PATCH and GET with valid value
```
curl -k -X PATCH "https://$BMC/redfish/v1/Managers/bmc" -H "X-Auth-Token: $XAUTH_TOKEN" \
-H 'Content-Type: application/json' --data-raw '{"ServiceIdentification": "foo"}'
{
"@Message.ExtendedInfo": [
{
"@odata.type": "#Message.v1_1_1.Message",
"Message": "The request completed successfully.",
"MessageArgs": [],
"MessageId": "Base.1.19.Success",
"MessageSeverity": "OK",
"Resolution": "None."
}
]
}
curl -k "https://$BMC/redfish/v1"
{
...
"ServiceIdentification": "foo",
...
}
curl -k -H "X-Auth-Token: $XAUTH_TOKEN" "https://$BMC/redfish/v1/Managers/bmc"
{
...
"ServiceIdentification": "foo",
...
}
```
3. PATCH and GET with invalid value
```
curl -k -X PATCH "https://$BMC/redfish/v1/Managers/bmc" -H "X-Auth-Token: $XAUTH_TOKEN" \
-H 'Content-Type: application/json' --data-raw '{"ServiceIdentification": "$$$"}'
{
"ServiceIdentification@Message.ExtendedInfo": [
{
"@odata.type": "#Message.v1_1_1.Message",
"Message": "The value provided for the property ServiceIdentification is not valid.",
"MessageArgs": [
"ServiceIdentification"
],
"MessageId": "Base.1.19.PropertyValueError",
"MessageSeverity": "Warning",
"Resolution": "Correct the value for the property in the request body and resubmit the request if the operation failed."
}
]
}
curl -k -X PATCH "https://$BMC/redfish/v1/Managers/bmc" -H "X-Auth-Token: $XAUTH_TOKEN" \
-H 'Content-Type: application/json' --data-raw '{"ServiceIdentification": "2222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222"}'
{
"error": {
"@Message.ExtendedInfo": [
{
"@odata.type": "#Message.v1_1_1.Message",
"Message": "The string 'ServiceIdentification' exceeds the length limit 99.",
"MessageArgs": [
"ServiceIdentification",
"99"
],
"MessageId": "Base.1.19.StringValueTooLong",
"MessageSeverity": "Warning",
"Resolution": "Resubmit the request with an appropriate string length."
}
],
"code": "Base.1.19.StringValueTooLong",
"message": "The string 'ServiceIdentification' exceeds the length limit 99."
}
}
curl -k "https://$BMC/redfish/v1"
{
...
"ServiceIdentification": "foo",
...
}
curl -k -H "X-Auth-Token: $XAUTH_TOKEN" "https://$BMC/redfish/v1/Managers/bmc"
{
...
"ServiceIdentification": "foo",
...
}
```
Change-Id: I5b71a73e947ec64cabb8d93c8503a18fb43b8937
Signed-off-by: Corey Ethington <cethington@coreweave.com>
|
|
The backends are different things compared to generic code. Today,
these are all included in the /include folder, but it's not very clear
what options control which backends, or how things map together. This
also means that we can't separate ownership between the various
companies.
This commit is a proposal to try to create a features folder,
separated by the code for the various backends, to make interacting
with this easier. It takes the form
features/<option name>/files.hpp
features/<option name>/files_test.hpp
Note, redfish-core was already at top level, and contains lots of code,
so to prevent lots of conflicts, it's simply symlinked into that folder
to make clear that it is a backend, but not to move the implementation
and cause code conflicts.
Tested: Unit tests pass. Code compiles.
Change-Id: Idcc80ffcfd99c876734ee41d53f894ca5583fed5
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
GCC 15.1 fails with the following:
```
19:18:43 | ../git/include/http_utility.hpp:50:30: error: unused using-declaration 'boost::spirit::x3::uint_' [-Werror=unused-variable]
19:18:43 | 50 | using boost::spirit::x3::uint_;
```
Fix it with a trivial removal of an unused using.
Signed-off-by: Patrick Williams <patrick@stwcx.xyz>
Change-Id: Ia24038d3146e818062dfb3f6c0c6bc84fa1ba470
|
|
Since 2020, nlohmann has recognized that implicit conversions to and
from json are an issue. Many bugs have been caused at both development
time and runtime due to unexpected implicit conversions from json to
std::string/int/bool. This commit disables implicit conversions using
JSON_USE_IMPLICIT_CONVERSIONS [1]. This option will become the default
in the future. That comment was written 3 years ago at this point, so
we should prepare.
Tested:
Redfish service validator passes.
[1] https://json.nlohmann.me/api/macros/json_use_implicit_conversions/
Change-Id: Id6cc47b9bbf8889e4777fd6d77ec992f3139962c
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
as we have successfully merged patches that enable UserPrincipalName
parse mode, we can start removing Meta only parse mode. This commit
is intended to remove MTLSCommonNameParseMode::Meta from the upstream
code
Tested:
- build bmcweb
- deploy to a device that already use UPN
- check if it works fine by sending curl request /AccountService
Change-Id: Idcf4340a2a9940f035aea41cd30ef4df7bd95530
Signed-off-by: Malik Akbar Hashemi Rafsanjani <malikrafsan@meta.com>
|
|
When BMC reboots or bmcweb restarts, the persistent subscriptions may
not be loaded properly but they may still be in the file.
Later on if BMC reboots or bmcweb restarts, those unloaded subscriptions
may potentially and unexpectedly cause the reload into the active
subscriptions.
The key cause is due to the compiler evaluation order for the function
arguments where the last argument is evaluated and pushed into the stack
first. As the result, the first argument `newSub->id` may already be
invalid after the last argument `std::make_shared<>(std::move(*newSub))`
is evaluated and pushed into the parameter stack [1].
This may cause the failure of `subscriptionsConfigMap.emplace()` and
results in the missing instantiation of the persistent subscriptions.
Tested:
- Create many subscriptions
- GET subscriptions
```
curl -k -X GET https://${bmc}/redfish/v1/EventService/Subscriptions
{
"@odata.id": "/redfish/v1/EventService/Subscriptions",
"@odata.type": "#EventDestinationCollection.EventDestinationCollection",
"Members": [
{
"@odata.id": "/redfish/v1/EventService/Subscriptions/1187258741"
},
...
{
"@odata.id": "/redfish/v1/EventService/Subscriptions/949306789"
}
],
"Members@odata.count": 6,
"Name": "Event Destination Collections"
}
```
- Restart bmcweb
- GET subscriptions again and check whether they are the same.
- Sometimes, none or only a few may be instantiated like
```
curl -k -X GET https://${bmc}/redfish/v1/EventService/Subscriptions
{
"@odata.id": "/redfish/v1/EventService/Subscriptions",
"@odata.type": "#EventDestinationCollection.EventDestinationCollection",
"Members": [
{
"@odata.id": "/redfish/v1/EventService/Subscriptions/1187258741"
}
],
"Members@odata.count": 1,
"Name": "Event Destination Collections"
}
```
- However, the file `/home/root/bmcweb_persistent_data.json` still has
the old entries.
- Also verify Redfish Service Validator to pass
[1] https://github.com/openbmc/bmcweb/blob/0c814aa604b36cff01b495f9c335f981c7be83be/include/persistent_data.hpp#L184
Change-Id: Ia8a3c1bd3d4f4e479b599077ba8f26e47f8d22ef
Signed-off-by: Myung Bae <myungbae@us.ibm.com>
|
|
I don't feel like breaking these out at the moment or writing a commit
message. This fixes the build for clang-tidy. If anyone wants to break
these out with appropriate commit messages, feel free.
Change-Id: Id0b65d238dfb9b8036c0ffddf2f32d221e5988c2
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
This commit is intended to fix the bug on bmcweb when we send patch
request to `/redfish/v1/AccountService`, especially when changing the
`CertificateMappingAttribute`. The expected behavior is that if we
send the patch request, the bmc device will update the internal state
and also update the persistent file (`bmcweb_persistent_data.json`)
to store the current `CertificateMappingAttribute`. This is done so
that after we reboot, the bmc device will retain the
`CertificateMappingAttribute`
However, currently that doesn't happen because there is mismatch on the
key on the persistent file. It should be "MTLSCommonNameParseMode",
instead of "TLSCommonNameParseMode". This commit is intended to solve
this bug
Change-Id: I38f03fd5eefa76079d76552548b411d95639b470
Signed-off-by: Malik Akbar Hashemi Rafsanjani <malikrafsan@meta.com>
|
|
is_object doesn't throw, but generally is_object is used in some kind of
pattern of.
if (x.is_object()){
x["thing"];
}
operator[] technically throws if it's the wrong type, which bloats
binary sizes.
Replace these with the equivalent get_ptr<object_t>
Change-Id: If3734d7920f0a6f81efa10b3a2d91595e9e0af5a
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Adding async_method_call in dbus utility gives us a place where we can
intercept method call requests from dbus to potentially add
logging/caching.
An example of logging is in the later commit:
https://gerrit.openbmc.org/c/openbmc/bmcweb/+/78265/
We already do this for setProperty, this moves the method calls to
follow a similar pattern.
Tested: Redfish service validator passes.
Change-Id: I6d2c96e2b6b6a023ed2138106a55faebca161592
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
d8139c68[1] added:
asyncResp->res.addHeader("Clear-Site-Data",
R"("cache","cookies","storage")");
This causes the browsers to clear the cache, cookie, and storage for
that site. [2]
Don't see where OWASP recommends Clear-Site-Data response header. [3]
This seems reasonable but breaks our server manager (HMC) when using
webui-vue from the HMC proxy. [4][5]
The HMC is also using the cookie and storage from the same URI. The
proxy works by going to a URI and the HMC proxing it forward/reverse
for webui-vue.
Also had other problems clearing headers, Clear-Site-Data seems too
strict, just remove it.
[1]: https://github.com/openbmc/bmcweb/commit/d8139c683a2f42c47ed913b731becc6cd681e2dd
[2]: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Clear-Site-Data
[3]: https://cheatsheetseries.owasp.org/cheatsheets/HTTP_Headers_Cheat_Sheet.html
[4]: https://en.wikipedia.org/wiki/IBM_Hardware_Management_Console
[5]: https://www.ibm.com/docs/en/power10?topic=asmi-accessing-by-using-hmc
Tested: Firefox and Chrome no longer logout the HMC when logging out
webui-vue.
Change-Id: I061eae9163ce5d88a3bd9f297ca5e10ff3a07984
Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
|
|
We have a use case where the GUI sits behind a Apache Tomcat proxy[1].
In this environment the cookie looks like:
```
en-US,en;q=0.9cookie:
JSESSIONIDSSO=4E999D77EF4E01CB72DE63949D5FF830;
CCFWSESSION=48A66EB93C00AD4F6327FB3FC2A338FC; LOGIN_MODE=Dashboard;
XSRF-TOKEN=Ue1La3Ik48Bn5NosyLnJ; SESSION=pCAdqApWt4Kb4IUV9vh8dnt:
```
The bmcweb code thinks the CCFWSESSION= is the SESSION. The bmcweb code
could be made smarter to differentiate "CCFWSESSION" and "SESSION" but
reading SESSION seems too generic of a name and something like
"BMCWEB-SESSION" better matches [2], [3], and [4].
[1]: https://tomcat.apache.org/tomcat-9.0-doc/proxy-howto.html
[2]: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Set-Cookie#session_cookie
[3]: https://http.dev/set-cookie
[4]: https://www.geeksforgeeks.org/http-headers-set-cookie/
Tested: The GUI works and this proxy environment now works.
Change-Id: I9b63093c1839e26602fe26313a330e337961cb81
Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
|
|
Systemd has support for enabling service level watchdog. The MR enables
this support for bmcweb daemon. Request for watchdog monitor from
systemd is added in bmcweb.service.in. From the event loop a timer is
registered to kick the watchdog periodically
The default watchdog timeout is set at 120 seconds and the timer is set
to kick it at a quarter of the interval (every 30 seconds).
This timeout is set somewhat arbitrarily based on the longest blocking
call that could occur and still give a valid HTTP response. Suspect
lower values could work equally as well.
Benefits of Service Watchdog
- Bmcweb route handlers should not make any blocking IO calls which
block the event loop for considerable amount of time and slowdown the
response of other URI requests in the queue. Watchdog can help to detect
such issues.
- Watchdog can help restart the service if any route handler code has
uncaught bugs resulting from system API errors (this is in theory,
currently we don't have any use case).
Tested
1. UT is passing
2. Service validator is passing
3. Fw upgrade POST requests are working
Change-Id: If62397d8836c942fdcbc0618810fe82a8b248df8
Signed-off-by: rohitpai <ropai@nvidia.com>
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|