summaryrefslogtreecommitdiff
path: root/include
AgeCommit message (Collapse)AuthorFilesLines
11 daysinclude,http: Extract getUserInfo/onRequestRecvYuvakumar Selvamani1-9/+17
Move long lambdas in getUserInfo() and onRequestRecv() into named functions, afterGetUserInfo() and afterCompleteRequest(), per the <10 line lambda rule in docs/COMMON_ERRORS.md. No functional change. Tested: - Tested on AST2600 SoC. - getUserInfo/afterGetUserInfo: sent an authenticated Basic-auth Redfish GET and confirmed a 200 response with no "Failed to populate user information" error in journalctl, proving populateUserInfo() succeeded via the extracted callback. - onRequestRecv/afterCompleteRequest: RSV's client uses HTTP/1.1, so it does not exercise this HTTP/2-only code path. Instead, used "curl --http2" and confirmed ALPN negotiated h2 and the request completed as HTTP/2 200. journalctl -u bmcweb confirmed both "onRequestRecv streamId:1" and the extracted callback's "res.completeRequestHandler called" fired for that stream. - Redfish Service Validator: 5830 Pass / 353 Warn / 0 Fail. Change-Id: I0e6365c682f6acc8d39510ad5f1fe239d747154f Signed-off-by: Yuvakumar Selvamani <yuvakumars@ami.com>
2026-07-16Detect HTML content type with existing parserJoel Pullokaran Jesin1-2/+4
Use http_helpers::getContentType() when deciding whether to add HTML-only security headers. Previously this logic checked the raw Content-Type header with a text/html prefix match. That worked for the values we emit today, but it open-coded Content-Type handling in this path instead of using the existing parser. Switch this logic to getContentType() so it stays consistent with the rest of the code and correctly handles valid variations such as case-insensitive HTML MIME types. Add unit coverage for getContentType() to verify HTML MIME types with charset parameters and case-insensitive input. Tested: unit tests passed. Change-Id: I1cff40453ab4851cc7b24615a20fb6abcfba864b Signed-off-by: Joel Pullokaran Jesin <joelpj@ami.com>
2026-07-15Fix bug in asio resolverEd Tanous1-11/+16
This regressed when the bypass was added. Fix the code for resolver=asio to properly construct the results object using the built in asio type instead of std::vector. Tested: Code compiles with resolver=asio again. Change-Id: I3d9ddc38b88a392cf82fc81bd5609f3360837393 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2026-07-02Allow setting Mozilla modernEd Tanous1-6/+50
Mozilla publishes recommendations for TLS cipher suites to support. For many years bmcweb selected "intermediate" because of compatibility with clients that didn't yet support TLS1.3. This commit adds the ability to use the Mozilla modern recommendations, and disable TLS1.2 support through a new meson option, tls-profile. Tested: Loaded on qemu, and verified with testssl.sh[1] that parameters were applied. [1] https://github.com/testssl/testssl.sh Change-Id: I38e915b3943b5dbe5fb31e54eb3ebda9bbaeb811 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2026-07-01Flag long lambdasEd Tanous1-0/+1
Long lambdas have been documented as an anti-pattern for some time.[1] Despite this being generally understood, bmcweb has a long ways to go cleaning these up, and routinely code is submitted in violation of this anti-pattern. Invent an ast-grep rule that can identify when new examples of this anti-pattern are added, and ignore the existing 200+ examples that are in the codebase already using ast-grep ignore. These flags will give us something to search for as we clean this up, and will help to prevent new instances from being added unintentionally. [1] https://github.com/openbmc/docs/blob/master/anti-patterns.md#very-long-lambda-callbacks Tested: Comment only change. ast-grep passes. Manually removing an ast-grep ignore flag shows as a failure in ast-grep scan Change-Id: I77d634a393884969f184d2c39c02cc08288d5a29 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2026-06-19sdbusplus: use shorter type aliasesPatrick Williams2-9/+7
The sdbusplus headers provide shortened aliases for many types. Switch to using them to provide better code clarity and shorter lines. Possible replacements are for: * exception_t * manager_t * match * match_rules * message_t * object_t * slot_t Change-Id: Iaf2a83fb67d57a6fafb664d27b349add17a96bcd Signed-off-by: Patrick Williams <patrick@stwcx.xyz>
2026-06-12Generate 64 bit serial numbersEd Tanous1-2/+2
Even though the certificate is self signed, we should pass as many certificate tests as possible. testssl.sh prints ``` Serial 4B32D4F0 NOT ok: length should be >= 64 bits entropy (is: 4 bytes) ``` On our default certificate. This is relatively easy to fix. Change-Id: Ib1eb07b637ebf49ecf954b3d98ced9e9ef0f5a34 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2026-06-12OpenSSL cleanupEd Tanous1-36/+401
Continue moving OpenSSL into reusable RAII classes that can be used in unit tests and other places. This is slightly more code, but as we're adding unit tests, it allows reuse between unit tests rather than writing C directly. It also encapsulates the complexity of parsing openssl output (usually in bytes) into standard types (string) that can be compared/modified. Functionally this adds two new classes to the "wrappers" functions, OpenSSLSSLCtx and OpenSSLSSL, which each wrap SSL_CTX and SSL objects respectively from openssl. These are rough approximations of the boost equivalents. Change-Id: Id87ac4ccde88890bd70861deffdb256188ec0e39 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2026-06-09sdbusplus: use shorter type aliasesPatrick Williams1-1/+1
The sdbusplus headers provide shortened aliases for many types. Switch to using them to provide better code clarity and shorter lines. Possible replacements are for: * bus_t * exception_t * manager_t * match_t * message_t * object_t * slot_t * object_path Change-Id: I05ee2b2cda7c4468ab4117c751ecee797121b7dd Signed-off-by: Patrick Williams <patrick@stwcx.xyz>
2026-06-08account_service: invalidate sessions when account is disabledChandramohan Harkude1-0/+55
PATCH /redfish/v1/AccountService/Accounts/ with {"Enabled":false} flipped UserEnabled on D-Bus but left every active X-Auth-Token session for that user fully usable. Subsequent token-authenticated requests continued to succeed (200 OK) until the token's natural expiry, even though Basic auth for the same account was correctly rejected (401). DELETE on the same resource does not have this problem because removing the user object emits InterfacesRemoved, and bmcweb::onUserRemoved (in include/user_monitor.hpp) handles that signal by calling removeSessionsByUsername. Add onUserPropertiesChanged() in include/user_monitor.hpp that drops the user's sessions via SessionStore::removeSessionsByUsername() when User.Attributes.UserEnabled transitions to false. This handles disable of user both from IPMI and Redfish Tested : ``` Create new user curl -k -u ${USER}:${PASSWD} -X POST https://127.0.0.1:2443/redfish/v1/AccountService/Accounts -d '{ UserName:test_admin, Password:Shahapur#13!Shahapur, RoleId:Administrator, Enabled:true}' { "@Message.ExtendedInfo": [ { "@odata.type": "#Message.v1_1_1.Message", "Message": "The resource was created successfully.", "MessageArgs": [], "MessageId": "Base.1.19.Created", "MessageSeverity": "OK", "Resolution": "None." } ] } Create a-auth-token curl --insecure -X POST -D headers.txt https://127.0.0.1:2443/redfish/v1/SessionService/Sessions -d '{"UserName":"test_admin", "Password":"Shahapur#13!Shahapur"}' { "@odata.id": "/redfish/v1/SessionService/Sessions/YLMzEtANWr", "@odata.type": "#Session.v1_7_0.Session", "ClientOriginIPAddress": "10.0.2.2", "Description": "Manager User Session", "Id": "YLMzEtANWr", "Name": "User Session", "Roles": [ "Administrator" ], "UserName": "test_admin" } $ cat headers.txt HTTP/2 201 allow: GET, HEAD, POST odata-version: 4.0 x-auth-token: VcufgTshiDjEn8HbGh31 location: /redfish/v1/SessionService/Sessions/YLMzEtANWr strict-transport-security: max-age=31536000; includeSubdomains pragma: no-cache cache-control: no-store, max-age=0 x-content-type-options: nosniff content-type: application/json date: Wed, 06 May 2026 12:45:18 GMT content-length: 305 // Test RF request with token curl -k -H 'x-auth-token:VcufgTshiDjEn8HbGh31' https://127.0.0.1:2443/redfish/v1/AccountService/Accounts { "@odata.id": "/redfish/v1/AccountService/Accounts", "@odata.type": "#ManagerAccountCollection.ManagerAccountCollection", "Description": "BMC User Accounts", "Members": [ { "@odata.id": "/redfish/v1/AccountService/Accounts/test_admin" }, { "@odata.id": "/redfish/v1/AccountService/Accounts/root" } ], "Members@odata.count": 2, "Name": "Accounts Collection" } // Disable the user curl -k -u root:0penBmc https://127.0.0.1:2443/redfish/v1/AccountService/Accounts/test_admin -X PATCH -d '{"Enabled":false}' 204 // Try to use the Tokens curl -k -H 'x-auth-token:VcufgTshiDjEn8HbGh31' https://127.0.0.1:2443/redfish/v1/AccountService/Accounts 401 ``` Change-Id: I3246d3f5ec7db405c9c186a8672a9fed18259249 Signed-off-by: Chandramohan Harkude <chandramohan.harkude@gmail.com>
2026-04-29Optimize bmcweb memory usage for multipart fw updateEd Tanous1-222/+148
Previously, firmware updates via multipart/form-data stored two copies of the entire upload in memory (200MB+ for a 100MB image). This change reduces memory usage by incrementally processing multipart data in chunks, running through the parser as required. This avoids a copy into the http body. With this change, bmcweb no longer retains any duplicate copy of the image in memory, thereby limiting memory consumption to roughly the size of the image itself. To accomplish this, the multipart parser is rewritten to support incremental parsing. This should be 100% compatible with the old parser, with one exception, bytes at the end of the payload are no longer accepted and ignored. Tests: Multipart FW Update using a 114.2MB file shows bmcweb memory usage in line with one copy of the image, not two. Unit tests pass. Change-Id: Id18e20004059bfbc7de62f4f6c9542430c7943b0 Signed-off-by: Rajeev Ranjan <ranjan.rajeev1609@gmail.com> Signed-off-by: Ed Tanous <etanous@nvidia.com>
2026-04-27Add more unit tests for UPN functionalityIgor Kanyuka1-3/+32
Current unit tests only covers happy path. Add more unit tests before changing the code. Tested: unit tests Change-Id: Ibba5dbbc1457b59670d5d8f3c828fa9ca112f88c Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
2026-04-27RAII OpenSSLEd Tanous4-109/+833
bmcweb openssl usage is a mess. Start cleaning it up. 1. Make RAII objects for any held memory. 2. Move methods from hostname monitor into the ssl namespace, so not all compile units need to pull in openssl headers 3. Move methods to static where functions can be encapsulated. Because we're now testing openssl, we need to register memory init so that the sanitizers don't cause issues when mallocing from non bootstrapped openssl binaries. Openssl provides a handle for this, so use it in those unit tests. Tested: Unit tests pass. bmcweb launches and can open ssl with curl as it did previously. Change-Id: If0340692d2c56a6c45bb8d661d654a4b58ff3d2c Signed-off-by: Ed Tanous <etanous@nvidia.com>
2026-04-21Use methods that don't throwEd Tanous1-2/+10
Per common error #5 failing to catch thrown exceptions can lead to a crash. It turns out that the boost::beast::http::fields::set call can throw in extreme circumstances (large headers). There are two uses to clean up. Port these to using an overload that returns an error code to make sure that we don't accidentally set headers or throw an uncaught exception. [1] https://github.com/openbmc/bmcweb/blob/master/docs/COMMON_ERRORS.md#5-using-methods-that-throw-or-not-handling-bad-inputs Tested: Verified unit test coverage on both of these. Change-Id: I996b64ebb34c4ff7f4e582506d1acfabea05d72e Signed-off-by: Ed Tanous <etanous@nvidia.com>
2026-04-20ssl: Fix inverted VerifyCertificate enum valuesGary Beihl1-2/+2
The VerifyCertificate enum has Verify=0 and NoVerify=1. Subscription code casts the Redfish VerifyCertificate bool directly to this enum: static_cast<VerifyCertificate>(userSub->verifyCertificate) This maps true(1) to NoVerify and false(0) to Verify, inverting the intended behavior. Subscriptions that request certificate verification (VerifyCertificate: true) get verify_none, and subscriptions that skip verification get verify_peer. Swap the enum values so NoVerify=0 and Verify=1, matching boolean semantics. All other code references the enum by name (VerifyCertificate::Verify, ::NoVerify), so swapping the underlying values is safe. This bug was introduced in change 72590 and means outbound TLS certificate chain validation has never been enforced for Redfish Event subscriptions that request it. Closes openbmc/bmcweb#321 Tested: Docker CI passes (format, build, all tests). Booted OpenBMC on AST2600 (evb-ast2600-renode) in Renode 1.16, drove Redfish subscriptions through bmcweb's outbound TLS path to a test HTTPS server presenting a leaf signed by an external CA that was NOT installed in the BMC trust store. Phase 1 (upstream/master, no patch applied): Rejects Handshake When VerifyCertificate=true FAIL "Event was delivered despite a cert that should have caused rejection." Delivers When VerifyCertificate=false FAIL marker file never created; event was not delivered. Both failures reproduce the inversion: true -> NoVerify (handshake succeeds against untrusted CA), false -> Verify (handshake rejected). Phase 2 (upstream/master + this patch): Rejects Handshake When VerifyCertificate=true PASS Delivers When VerifyCertificate=false PASS true -> Verify (handshake correctly rejected), false -> NoVerify (event delivered as requested). Both paths inverted back to their documented semantics. Change-Id: Iecf1d03d2caee141f6eb4a6a4f284e4e36a3b693 Signed-off-by: Gary Beihl <garybeihl@microsoft.com>
2026-04-15sdbusplus: use shorter type aliasesPatrick Williams2-11/+11
The sdbusplus headers provide shortened aliases for many types. Switch to using them to provide better code clarity and shorter lines. Possible replacements are for: * bus_t * exception_t * manager_t * match_t * message_t * object_t * slot_t * object_path Change-Id: Iace20f9ad26e8d9dc234979e7a4087d599da2641 Signed-off-by: Patrick Williams <patrick@stwcx.xyz>
2026-03-31Port nlohmann::json::parse uses to saxEd Tanous1-3/+4
We should have a single entry point where we do json parsing. There are configurations for nlohmmann that we had previously documented, but were not well enforced. Move all uses to using the helper parse functions. Tested: Unit tests pass. Redfish service validator passes. Change-Id: I2a8aed9327b6b15219dc9b4d6db146b69bcd8eb3 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2026-03-19Add TLS session resumption support to mTLSIgor Kanyuka1-0/+4
TLS session resumption allows to bypass full TLS handshake in subsequent connections, it's enabled in OpenSSL, so clients that support it use it. One of the optimizations is, the client passes Session ID in subsequent request and does not pass certificates. Since client certificate is not passed, the callback that populates user session out of the certificate is not called, and as result, auth fails for requests sents in subsequent connections. This change enables session ID in memory cache, lookup of the certificate in the cache by the session ID received from the client and constructing user session out of it for subsequent connections. The cache is stored in RAM [1]. According to Nginx doc [2], size of one session is about 250 bytes. If sessions use mTLS, they will also contain a cert which is typically up 2kb. A client establishes connections as part of a session, so a session can be associated with multiple connections. In the worst case, when many clients establish a single connection at a time, or a client always uses a new session for every established connection, there will be number of session entries in the cache equals to the number of connections. While OpenSSL limits cache size to SSL_SESSION_CACHE_MAX_SIZE_DEFAULT which is 20480 [3], OpenBMC limits number of established connections to 200 [4], so in the worst case, memory usage will be ~50kb for non mTLS clients, and ~440kb for mTLS clients. Typically, when there are just 2-3 clients connected, even if them maintain multiple connections within their sessions, the cache size will be less than 10kb for mTLS. To prevent high memory usage by the cache, the change sets cache size to 100 entries. Expired sessions are automatically removed on every 255th session [5]. Tested: Deployed on one of our envs and ran client that quickly sends multiple requests to the BMC (so the client created several connections), and make sure the 401 auth problem had been observed before gone. Also, made sure BMCWeb logged debug messages about existing session detection. Ran tests from the openbmc-test-automation repository, esp related to certificate and user management. They do session auth and not mTLS/multi-connection, so they could not detect/confirm the problem is fixed, but they confirm the change does not break the primary use case. [1] https://docs.openssl.org/3.6/man3/SSL_CTX_set_session_cache_mode/#notes [2] https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache [3] https://github.com/openssl/openssl/blob/5869303daaecf037f0d00dc33a00f9bdc1e71f2f/include/openssl/ssl.h.in#L670 [4] https://github.com/openbmc/bmcweb/blob/master/http/http_connection.hpp#L219C13-L219C28 [5] https://docs.openssl.org/3.6/man3/SSL_CTX_flush_sessions/#notes Change-Id: Ia94d1e323cd464cc7ca5b0f9c7d6a76e4c780e9a Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
2026-03-10Change multipart parser APIEd Tanous1-8/+30
In preparation for making the multipart parser incremental, modify the API to explicitly call out steps of start, parsePart, and finish. This allows the parser to support incremental per-character parsing in the future. This also has the benefit of dropping the dependency on the Request struct on the multipart parser itself. Tested: Unit tests pass. Good coverage. Change-Id: I3359f45bb9faaea42908491a818cc4a81f257a1f Signed-off-by: Ed Tanous <etanous@nvidia.com>
2026-02-16Fix webassets to support Vite build outputJason Westover1-6/+10
The webui-vue project migrated from webpack to Vite, which changes the output filenames. Vite names entry chunks as index.[hash].js instead of webpack's app.[hash].js. The starts_with("index.") check in addFile() was remapping these JS/CSS files to their parent directory path (intended only for index.html), causing 404 errors when the browser requested the actual asset URLs. Restrict the index file detection to only apply to .html files, so that index.html is still correctly mapped to "/" while other files starting with "index." are served at their actual paths. Also broaden the etag hash detection from hex-only characters to full alphanumeric to support Vite's base64-style content hashes alongside webpack's hex hashes. Add unit tests for getStaticEtag() covering both webpack and Vite hash formats, path prefixes, edge cases, and validation of hash length and character constraints. Tested: Unit tests pass Vite-based webui-vue loads and caches etags Change-Id: I3f7d2e062d0fd8be4ded7889b64a7228b4a6459b Signed-off-by: Jason Westover <jwestover@nvidia.com> Signed-off-by: Ed Tanous <etanous@nvidia.com>
2026-02-03Do not allow data beyond the trailerEd Tanous1-0/+26
There is nothing in the multipart spec[1] that states that a parser should allow any bytes after a multipart payload. Several unit tests have a \r\n after their boundary condition that previously the parser just ignored. Testing shows this is fairly normal, so handle both cases still, but if any other characters show up, fail the parse. Unit test is also simplified to be more clear. Tested: Unit test coverage [1] https://datatracker.ietf.org/doc/html/rfc7578#section-4.1 Change-Id: I16643c61867708886cc87c236447ec1c19bf934f Signed-off-by: Ed Tanous <etanous@nvidia.com>
2026-01-30Remove usages of nlohmann::json::begin()Ed Tanous1-2/+18
nlohmann::json::begin() throws an uncaught exception. Tested: Redfish service validator passes. Signed-off-by: Ed Tanous <ed@tanous.net> Change-Id: I08244b0787cd4d6e592b0731196490a5160aba62
2025-12-18Implement modernize-use-rangesEd Tanous1-1/+2
This tidy check can transform code to use std::ranges. Enable the check, apply the fixes it proposes. Tested: Redfish service validator passes in qemu Change-Id: I3f21b27d3d30277f71b9c8a2c584a22bc16865e9 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-12-15Update to boost 1.89Ed Tanous1-12/+0
Update the subtree boost to 1.89; Keep the "required" version at 1.88 because that's currently what yocto uses. Now that we don't need old versions, the branch for boost 1.84 support is removed, and we can universally pull in boost::process as a library. Additionally boost::core::string_view has defined a std::formatter nearly identical to what was done there, so there's now a conflict. Add a version check and shift to the boost provided formatter when it's available. Tested: Code builds out of tree correctly. Change-Id: I15a10da084da8f9d9460781b16a0fdc92987fc9a Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-12-05sensor_utils: Add PeakReading propertyHarshit Aghera1-0/+1
Add support for PeakReading and PeakReadingTime for sensors. This enhancement allows sensor readings to include max observed value information in the Redfish API, along with timestamp. It uses PDI xyz.openbmc_project.Telemetry.Report. Property PeakReading is added if OperationType in PDI property ReadingParameters is set to Maximum. Current Limitation - The ResetMetrics action is currently not supported for sensor URIs. As a result, the ability to clear PeakReading values for GPU Power Sensors has not been implemented. Future Consideration - If ResetMetrics action support is added in the future, the corresponding functionality will also need to be implemented in the dbus-sensor application to ensure full compatibility. Schema: https://redfish.dmtf.org/schemas/v1/Sensor.v1_2_0.yaml (PeakReading) Backend implementation for reference: https://gerrit.openbmc.org/c/openbmc/dbus-sensors/+/82479 Tested: Build an image for nvl32-obmc machine with the following patches cherry picked. https://gerrit.openbmc.org/c/openbmc/openbmc/+/85490 https://gerrit.openbmc.org/c/openbmc/bmcweb/+/82449. The patch cherry-picks the following patches that are currently under review. ``` 1. device tree https://lore.kernel.org/all/aRbLqH8pLWCQryhu@molberding.nvidia.com/ 2. mctpd patches https://github.com/CodeConstruct/mctp/pull/85 3. u-boot changes https://lore.kernel.org/openbmc/20251121-msx4-v1-0-fc0118b666c1@nvidia.com/T/#t 4. kernel changes as specified in the openbmc patch (for espi) 5. entity-manager changes https://gerrit.openbmc.org/c/openbmc/entity-manager/+/85455 6. platform-init changes https://gerrit.openbmc.org/c/openbmc/platform-init/+/85456 7. spi changes https://lore.kernel.org/all/20251121-w25q01jv_fixup-v1-1-3d175050db73@nvidia.com/ ``` ``` > curl -s -k -u 'root:0penBmc' https://10.137.203.137/redfish/v1/Chassis/NVIDIA_GB200_1/Sensors/power_NVIDIA_GB200_GPU_0_Power_0 { "@odata.id": "/redfish/v1/Chassis/NVIDIA_GB200_1/Sensors/power_NVIDIA_GB200_GPU_0_Power_0", "@odata.type": "#Sensor.v1_2_0.Sensor", "Id": "power_NVIDIA_GB200_GPU_0_Power_0", "Name": "NVIDIA GB200 GPU 0 Power 0", "PeakReading": 52.671, "PeakReadingTime": 0, "Reading": 27.214, "ReadingRangeMax": 5000.0, "ReadingRangeMin": 0.0, "ReadingType": "Power", "ReadingUnits": "W", "Status": { "Health": "OK", "State": "Enabled" } }% ```` Change-Id: I8c1ab6ce85f31419db4a1d931bf99722d24afbd7 Signed-off-by: Harshit Aghera <haghera@nvidia.com>
2025-11-25Add temp file and FD support to TemporaryFileHandlerajeeranjan2-43/+58
This commit adds file descriptor and temporary file management to DuplicatableFileHandle, removing the redundant test-only TemporaryFileHandle utility. Changes: - Add file descriptor constructor and setFd() method - Add temporary file constructor with string_view content - Add filePath member and automatic cleanup in destructor - Add configurable temp-dir meson option (default: /tmp/bmcweb) - Remove include/file_test_utilities.hpp - Update all tests to use DuplicatableFileHandle - Rename stringPath to filePath These features will be used by the multipart parser to stream large uploads to temporary files instead of keeping them in memory, and by the update service to pass file descriptors over D-Bus. Change-Id: I982f5928d453f9f0c13d91c3525006134ddc87b3 Signed-off-by: Rajeev Ranjan <ranjan.rajeev1609@gmail.com>
2025-11-10fix: add account checking inside verifyMtlsEd Tanous1-8/+36
Currently if we don't have account in bmcweb but have valid format certificate, we will have 500 internal server error when we send request to bmcweb. But, if we don't have valid format certificate, we will get 401 unauthorized. This is not ideal as the http code is not appropriate. Also, this might introduce some security risk as the user can deduce whether their certificate format is valid or not based on the http code. This patch is intended to solve this issue by checking whether the username exists in the system. If not, we will return nullptr inside verifyMtls function, which result in 401 unauthorized response if the user have valid format of certificate, but there is no related username inside the system Change-Id: I479a10ed2bcce2c9969e19fa3aab9686ba4c71be Signed-off-by: Malik Akbar Hashemi Rafsanjani <malikrafsan@meta.com> Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-11-07use sdbusplus unpack syntaxPatrick Williams1-2/+2
Rather than defining a variable and then reading it from a message, sdbusplus also supports directly unpack-ing from the message. Use this syntax instead as it is more efficient and succinct. Signed-off-by: Patrick Williams <patrick@stwcx.xyz> Change-Id: Iebf93534fb4b68ec5f37f0b81fbe3456831d5d70
2025-10-14Set json no IOEd Tanous1-4/+21
There's only a couple remaining places we use json IO. Not including IO improves compile times in a minor way, because the nlohmann stream/file template is relatively expensive to compile. Tested: Launched bmcweb. Observed bmcweb_persistent_data.json created. Rebooted bmcweb with 'systemctl restart bmcweb' and observed launched correctly with persistent file present. Change-Id: I56f674f20fa8553dc86245a765818849aa5fa102 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-10-03Remove getNthStringFromPath functionEd Tanous1-5/+0
This utility function is being removed for several reasons. First, it does not verify the full string on URIs and paths, so things like /foo/bar/baz/valid_id would still pass this check. Second, it is used for both URIs and dbus paths, both of which we have better utility functions these days respectively, boost::url for urls and sdbusplus::message::object_path for dbus paths. Neither of the two is escaped properly when this function is used. Therefore, remove it and replace it with the appropriate alternatives. The existing URI functions were found to not accept fragments (given they are rarely used in PATCH). Add support for fragments to cover the getNthStringFromPath use cases. Tested: Redfish service validator passes. Change-Id: Ibc6755ad69397123d7fef0e0b764042bbb48888b Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-10-03Read state directory from systemd fileEd Tanous1-6/+21
Reading the state dir from the systemd service file gives us flexibility to define the bmcweb state from wherever we like, rather than just using the current directory, which might not be writable. Tested: bmcweb boots, shows state is persisted in the same location as previously. Change-Id: I9c048421fe249b73b1cae2ff5204ffd357cd3123 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-10-02Clean up CLI namingEd Tanous1-1/+1
Now that all applications run through one CLI, names like run() don't make a lot of sense. Update names to match the new reality, make bmcweb with no arguments launch the webserver once again. Tested: bmcweb boots. Change-Id: I011b57507872a9518a9c470b58779805504c7293 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-10-01Fix arm BUILDEd Tanous1-1/+1
aarch64 gcc warns on this line. Fix it. Change-Id: Ic752cda31f27b7d68af99ca53efcdfcdf0e659a7 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-08-26Fix includesEd Tanous4-4/+0
Our includes haven't been enforced by tidy in a while. Run the script, check in the result, minus the false positives. Change-Id: I6a6da26f5ba5082d9b4aa17cdc9f55ebd8cd41a6 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-08-12Fix handling of ssl_key_handler for WebUIMyung Bae2-4/+7
The previous commit 90cd2e1 [1] causes WebUI to fail to load and connect. It is because a global static var (`hasWebuiRoute`) is instantiated per compile unit and it ends up causing the inconsistency of the value of it. Tested: - Verify WebUI to load successful - Redfish Service Validator passes [1] https://github.com/openbmc/bmcweb/commit/90cd2e1d2e2228b0c575c9a3b6b2dc75eac9eb68 Change-Id: I09c3a9a831528e25c09299b0ee15993974d94d88 Signed-off-by: Myung Bae <myungbae@us.ibm.com>
2025-08-07identity.hpp: add header guardAlexander Hansen1-0/+2
Add `#pragma once` to a header file. Noticed this issue when trying unity build in yocto environment. ``` bbmcweblib.a.p/bmcweblib-unity0.cpp | In file included from ../git/redfish-core/lib/network_protocol.hpp:14, | from /home/alexander/openbmc/build/s8030/tmp/work/arm1176jzs-openbmc-linux-gnueabi/bmcweb/1.0+git/build/../git/redfish-core/src/redfish.cpp:30, | from libbmcweblib.a.p/bmcweblib-unity0.cpp:13: | ../git/include/identity.hpp:7:20: error: redefinition of 'std::string getHostName()' | 7 | inline std::string getHostName() | | ^~~~~~~~~~~ | In file included from /home/alexander/openbmc/build/s8030/tmp/work/arm1176jzs-openbmc-linux-gnueabi/bmcweb/1.0+git/build/../git/http/mutual_tls.cpp:7, | from libbmcweblib.a.p/bmcweblib-unity0.cpp:1: | ../git/include/identity.hpp:7:20: note: 'std::string getHostName()' previously defined here | 7 | inline std::string getHostName() | | ^~~~~~~~~~~ | ninja: build stopped: subcommand failed. | INFO: autodetecting backend as ninja ``` Tested: Inspection only. Change-Id: Ib7811ee12da763203b50fc81d39d642d2de3e212 Signed-off-by: Alexander Hansen <alexander.hansen@9elements.com>
2025-07-14Implement zstd decompressionEd Tanous1-1/+6
Given the size of Redfish schemas these days, it would be nice to be able to store them on disk in a zstd format. Unfortunately, not all clients support zstd at this time. This commit implements reading of zstd files from disk, as well as decompressing zstd in the case where the client does not support zstd as a return type. Tested: Implanted an artificial zstd file into the system, and observed correct decompression both with an allow-encoding header of empty string and zstd. Change-Id: I8b631bb943de99002fdd6745340aec010ee591ff Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-07-07Add ServiceIdentificationCorey Ethington1-0/+11
Implements GET and PATCH support for ServiceIdentification in Managers/bmc and service root. Tested: - Refish Service Validator passes - Tested on romulus: 1. GET initial value ``` curl -k "https://$BMC/redfish/v1" { ... } ``` ServiceIdentification is not yet present in service root, as expected ``` curl -k -H "X-Auth-Token: $XAUTH_TOKEN" "https://$BMC/redfish/v1/Managers/bmc" { ... "ServiceIdentification": "", ... } ``` 2. PATCH and GET with valid value ``` curl -k -X PATCH "https://$BMC/redfish/v1/Managers/bmc" -H "X-Auth-Token: $XAUTH_TOKEN" \ -H 'Content-Type: application/json' --data-raw '{"ServiceIdentification": "foo"}' { "@Message.ExtendedInfo": [ { "@odata.type": "#Message.v1_1_1.Message", "Message": "The request completed successfully.", "MessageArgs": [], "MessageId": "Base.1.19.Success", "MessageSeverity": "OK", "Resolution": "None." } ] } curl -k "https://$BMC/redfish/v1" { ... "ServiceIdentification": "foo", ... } curl -k -H "X-Auth-Token: $XAUTH_TOKEN" "https://$BMC/redfish/v1/Managers/bmc" { ... "ServiceIdentification": "foo", ... } ``` 3. PATCH and GET with invalid value ``` curl -k -X PATCH "https://$BMC/redfish/v1/Managers/bmc" -H "X-Auth-Token: $XAUTH_TOKEN" \ -H 'Content-Type: application/json' --data-raw '{"ServiceIdentification": "$$$"}' { "ServiceIdentification@Message.ExtendedInfo": [ { "@odata.type": "#Message.v1_1_1.Message", "Message": "The value provided for the property ServiceIdentification is not valid.", "MessageArgs": [ "ServiceIdentification" ], "MessageId": "Base.1.19.PropertyValueError", "MessageSeverity": "Warning", "Resolution": "Correct the value for the property in the request body and resubmit the request if the operation failed." } ] } curl -k -X PATCH "https://$BMC/redfish/v1/Managers/bmc" -H "X-Auth-Token: $XAUTH_TOKEN" \ -H 'Content-Type: application/json' --data-raw '{"ServiceIdentification": "2222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222"}' { "error": { "@Message.ExtendedInfo": [ { "@odata.type": "#Message.v1_1_1.Message", "Message": "The string 'ServiceIdentification' exceeds the length limit 99.", "MessageArgs": [ "ServiceIdentification", "99" ], "MessageId": "Base.1.19.StringValueTooLong", "MessageSeverity": "Warning", "Resolution": "Resubmit the request with an appropriate string length." } ], "code": "Base.1.19.StringValueTooLong", "message": "The string 'ServiceIdentification' exceeds the length limit 99." } } curl -k "https://$BMC/redfish/v1" { ... "ServiceIdentification": "foo", ... } curl -k -H "X-Auth-Token: $XAUTH_TOKEN" "https://$BMC/redfish/v1/Managers/bmc" { ... "ServiceIdentification": "foo", ... } ``` Change-Id: I5b71a73e947ec64cabb8d93c8503a18fb43b8937 Signed-off-by: Corey Ethington <cethington@coreweave.com>
2025-06-27Rearrange featuresEd Tanous10-5250/+0
The backends are different things compared to generic code. Today, these are all included in the /include folder, but it's not very clear what options control which backends, or how things map together. This also means that we can't separate ownership between the various companies. This commit is a proposal to try to create a features folder, separated by the code for the various backends, to make interacting with this easier. It takes the form features/<option name>/files.hpp features/<option name>/files_test.hpp Note, redfish-core was already at top level, and contains lots of code, so to prevent lots of conflicts, it's simply symlinked into that folder to make clear that it is a backend, but not to move the implementation and cause code conflicts. Tested: Unit tests pass. Code compiles. Change-Id: Idcc80ffcfd99c876734ee41d53f894ca5583fed5 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-06-13http_utility: removed unused usingPatrick Williams1-2/+0
GCC 15.1 fails with the following: ``` 19:18:43 | ../git/include/http_utility.hpp:50:30: error: unused using-declaration 'boost::spirit::x3::uint_' [-Werror=unused-variable] 19:18:43 | 50 | using boost::spirit::x3::uint_; ``` Fix it with a trivial removal of an unused using. Signed-off-by: Patrick Williams <patrick@stwcx.xyz> Change-Id: Ia24038d3146e818062dfb3f6c0c6bc84fa1ba470
2025-06-04Remove implicit conversionsEd Tanous1-3/+23
Since 2020, nlohmann has recognized that implicit conversions to and from json are an issue. Many bugs have been caused at both development time and runtime due to unexpected implicit conversions from json to std::string/int/bool. This commit disables implicit conversions using JSON_USE_IMPLICIT_CONVERSIONS [1]. This option will become the default in the future. That comment was written 3 years ago at this point, so we should prepare. Tested: Redfish service validator passes. [1] https://json.nlohmann.me/api/macros/json_use_implicit_conversions/ Change-Id: Id6cc47b9bbf8889e4777fd6d77ec992f3139962c Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-06-04remove meta mtls parse modeMalik Akbar Hashemi Rafsanjani1-11/+1
as we have successfully merged patches that enable UserPrincipalName parse mode, we can start removing Meta only parse mode. This commit is intended to remove MTLSCommonNameParseMode::Meta from the upstream code Tested: - build bmcweb - deploy to a device that already use UPN - check if it works fine by sending curl request /AccountService Change-Id: Idcf4340a2a9940f035aea41cd30ef4df7bd95530 Signed-off-by: Malik Akbar Hashemi Rafsanjani <malikrafsan@meta.com>
2025-05-15Fix inconsistent persistent subscription loadMyung Bae1-7/+7
When BMC reboots or bmcweb restarts, the persistent subscriptions may not be loaded properly but they may still be in the file. Later on if BMC reboots or bmcweb restarts, those unloaded subscriptions may potentially and unexpectedly cause the reload into the active subscriptions. The key cause is due to the compiler evaluation order for the function arguments where the last argument is evaluated and pushed into the stack first. As the result, the first argument `newSub->id` may already be invalid after the last argument `std::make_shared<>(std::move(*newSub))` is evaluated and pushed into the parameter stack [1]. This may cause the failure of `subscriptionsConfigMap.emplace()` and results in the missing instantiation of the persistent subscriptions. Tested: - Create many subscriptions - GET subscriptions ``` curl -k -X GET https://${bmc}/redfish/v1/EventService/Subscriptions { "@odata.id": "/redfish/v1/EventService/Subscriptions", "@odata.type": "#EventDestinationCollection.EventDestinationCollection", "Members": [ { "@odata.id": "/redfish/v1/EventService/Subscriptions/1187258741" }, ... { "@odata.id": "/redfish/v1/EventService/Subscriptions/949306789" } ], "Members@odata.count": 6, "Name": "Event Destination Collections" } ``` - Restart bmcweb - GET subscriptions again and check whether they are the same. - Sometimes, none or only a few may be instantiated like ``` curl -k -X GET https://${bmc}/redfish/v1/EventService/Subscriptions { "@odata.id": "/redfish/v1/EventService/Subscriptions", "@odata.type": "#EventDestinationCollection.EventDestinationCollection", "Members": [ { "@odata.id": "/redfish/v1/EventService/Subscriptions/1187258741" } ], "Members@odata.count": 1, "Name": "Event Destination Collections" } ``` - However, the file `/home/root/bmcweb_persistent_data.json` still has the old entries. - Also verify Redfish Service Validator to pass [1] https://github.com/openbmc/bmcweb/blob/0c814aa604b36cff01b495f9c335f981c7be83be/include/persistent_data.hpp#L184 Change-Id: Ia8a3c1bd3d4f4e479b599077ba8f26e47f8d22ef Signed-off-by: Myung Bae <myungbae@us.ibm.com>
2025-05-14Fix the buildEd Tanous2-3/+2
I don't feel like breaking these out at the moment or writing a commit message. This fixes the build for clang-tidy. If anyone wants to break these out with appropriate commit messages, feel free. Change-Id: Id0b65d238dfb9b8036c0ffddf2f32d221e5988c2 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-05-07fix: resolve incorrect key on bmcweb persistent fileMalik Akbar Hashemi Rafsanjani1-1/+1
This commit is intended to fix the bug on bmcweb when we send patch request to `/redfish/v1/AccountService`, especially when changing the `CertificateMappingAttribute`. The expected behavior is that if we send the patch request, the bmc device will update the internal state and also update the persistent file (`bmcweb_persistent_data.json`) to store the current `CertificateMappingAttribute`. This is done so that after we reboot, the bmc device will retain the `CertificateMappingAttribute` However, currently that doesn't happen because there is mismatch on the key on the persistent file. It should be "MTLSCommonNameParseMode", instead of "TLSCommonNameParseMode". This commit is intended to solve this bug Change-Id: I38f03fd5eefa76079d76552548b411d95639b470 Signed-off-by: Malik Akbar Hashemi Rafsanjani <malikrafsan@meta.com>
2025-04-29Remove is_objectEd Tanous2-16/+27
is_object doesn't throw, but generally is_object is used in some kind of pattern of. if (x.is_object()){ x["thing"]; } operator[] technically throws if it's the wrong type, which bloats binary sizes. Replace these with the equivalent get_ptr<object_t> Change-Id: If3734d7920f0a6f81efa10b3a2d91595e9e0af5a Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-04-10Add async_method_call to utilityEd Tanous8-19/+42
Adding async_method_call in dbus utility gives us a place where we can intercept method call requests from dbus to potentially add logging/caching. An example of logging is in the later commit: https://gerrit.openbmc.org/c/openbmc/bmcweb/+/78265/ We already do this for setProperty, this moves the method calls to follow a similar pattern. Tested: Redfish service validator passes. Change-Id: I6d2c96e2b6b6a023ed2138106a55faebca161592 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-03-20Remove cookie clearGunnar Mills1-1/+0
d8139c68[1] added: asyncResp->res.addHeader("Clear-Site-Data", R"("cache","cookies","storage")"); This causes the browsers to clear the cache, cookie, and storage for that site. [2] Don't see where OWASP recommends Clear-Site-Data response header. [3] This seems reasonable but breaks our server manager (HMC) when using webui-vue from the HMC proxy. [4][5] The HMC is also using the cookie and storage from the same URI. The proxy works by going to a URI and the HMC proxing it forward/reverse for webui-vue. Also had other problems clearing headers, Clear-Site-Data seems too strict, just remove it. [1]: https://github.com/openbmc/bmcweb/commit/d8139c683a2f42c47ed913b731becc6cd681e2dd [2]: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Clear-Site-Data [3]: https://cheatsheetseries.owasp.org/cheatsheets/HTTP_Headers_Cheat_Sheet.html [4]: https://en.wikipedia.org/wiki/IBM_Hardware_Management_Console [5]: https://www.ibm.com/docs/en/power10?topic=asmi-accessing-by-using-hmc Tested: Firefox and Chrome no longer logout the HMC when logging out webui-vue. Change-Id: I061eae9163ce5d88a3bd9f297ca5e10ff3a07984 Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
2025-03-18Change Session Cookie nameGunnar Mills2-4/+4
We have a use case where the GUI sits behind a Apache Tomcat proxy[1]. In this environment the cookie looks like: ``` en-US,en;q=0.9cookie: JSESSIONIDSSO=4E999D77EF4E01CB72DE63949D5FF830; CCFWSESSION=48A66EB93C00AD4F6327FB3FC2A338FC; LOGIN_MODE=Dashboard; XSRF-TOKEN=Ue1La3Ik48Bn5NosyLnJ; SESSION=pCAdqApWt4Kb4IUV9vh8dnt: ``` The bmcweb code thinks the CCFWSESSION= is the SESSION. The bmcweb code could be made smarter to differentiate "CCFWSESSION" and "SESSION" but reading SESSION seems too generic of a name and something like "BMCWEB-SESSION" better matches [2], [3], and [4]. [1]: https://tomcat.apache.org/tomcat-9.0-doc/proxy-howto.html [2]: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Set-Cookie#session_cookie [3]: https://http.dev/set-cookie [4]: https://www.geeksforgeeks.org/http-headers-set-cookie/ Tested: The GUI works and this proxy environment now works. Change-Id: I9b63093c1839e26602fe26313a330e337961cb81 Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
2025-03-17Add support for systemd service watchdogrohitpai1-0/+76
Systemd has support for enabling service level watchdog. The MR enables this support for bmcweb daemon. Request for watchdog monitor from systemd is added in bmcweb.service.in. From the event loop a timer is registered to kick the watchdog periodically The default watchdog timeout is set at 120 seconds and the timer is set to kick it at a quarter of the interval (every 30 seconds). This timeout is set somewhat arbitrarily based on the longest blocking call that could occur and still give a valid HTTP response. Suspect lower values could work equally as well. Benefits of Service Watchdog - Bmcweb route handlers should not make any blocking IO calls which block the event loop for considerable amount of time and slowdown the response of other URI requests in the queue. Watchdog can help to detect such issues. - Watchdog can help restart the service if any route handler code has uncaught bugs resulting from system API errors (this is in theory, currently we don't have any use case). Tested 1. UT is passing 2. Service validator is passing 3. Fw upgrade POST requests are working Change-Id: If62397d8836c942fdcbc0618810fe82a8b248df8 Signed-off-by: rohitpai <ropai@nvidia.com> Signed-off-by: Ed Tanous <etanous@nvidia.com>