| Age | Commit message (Collapse) | Author | Files | Lines |
|
Currently, GenerateSecretKeyRequired is treated as 403 Forbidden, which
would incorrectly imply the session was not created, when it should be
treated as an informational message accompanying a successful session
creation (with 201 response code), exactly like PasswordChangeRequired.
According to the Redfish spec [1], page 202, 203 (Section 13.5.5):
* "Shall allow a session login without the Token property and include
the @Message.ExtendedInfo in the response containing the
GenerateSecretKeyRequired message. This indicates to the client
that their session is restricted to performing only the
GenerateSecretKey action on their ManagerAccount resource before
access is granted."
* "Shall allow a POST operation on the VerifyTimeBasedOneTimePassword"
action on the ManagerAccount resource associated with the account."
* "Shall allow a DELETE operation on Session resources representing
open sessions associated with the account."
* "May allow GET operations on unauthenticated resources, such as
the ServiceRoot resource."
* "For all other operations, the service shall respond with the HTTP
403 Forbidden status code and an error response with the
GenerateSecretKeyRequired message from the Base Message Registry."
Reference:
[1] https://www.dmtf.org/sites/default/files/standards/documents/DSP0266_1.24.0.pdf#page=202&zoom=100,0,789
Tested By:
* Enabled Multi-Factor Authentication (system-wide option)
* When user tries to login with username and password, session is
created (201 is returned), with GenerateSecretKeyRequired message
in "@Message.ExtendedInfo"
* Any operations on restricted resources returned
GenerateSecretKeyRequired with 403 Forbidden error code.
Change-Id: Iec6c925f04584b2cdd93aec743b04d6a8dbde4bc
Signed-off-by: Jishnu CM <jishnunambiarcm@duck.com>
|
|
Some of messages are not currently reported as errors, although they
are the results as Redfish request errors. Those include
- PropertyDuplicate
- ResourceAlreadyExists
- CreateFailedMissingReqProperties
- PropertyValueFormatError
- PropertyValueNotInList
- PropertyValueTypeError
- PropertyValueError
- PropertyNotWritable
- PropertyValueModified
- PropertyMissing
For example, PropertyValueFormatError is currently not treated as an
error. It shows like
```
curl -k -X PATCH "${bmc}/redfish/v1/AccountService/Accounts/admin" \
-H "Content-Type: application/json" \
-d '{ "Password": "" }'
"Password@Message.ExtendedInfo": [
{
"@odata.type": "#Message.v1_1_1.Message",
"Message": "The value 'null' for the property Password is not a format that the property can accept.",
"MessageArgs": [
"null",
"Password"
],
"MessageId": "Base.1.19.PropertyValueFormatError",
"MessageSeverity": "Warning",
"Resolution": "Correct the value for the property in the request body and resubmit the request if the operation failed."
}
]
```
After making it as an error, it will be like
```
{
"error": {
"@Message.ExtendedInfo": [
{
"@odata.type": "#Message.v1_1_1.Message",
"Message": "The value 'null' for the property Password is not a format that the property can accept.",
"MessageArgs": [
"null",
"Password"
],
"MessageId": "Base.1.19.PropertyValueFormatError",
"MessageSeverity": "Warning",
"Resolution": "Correct the value for the property in the request body and resubmit the request if the operation failed."
}
],
"code": "Base.1.19.PropertyValueFormatError",
"message": "The value 'null' for the property Password is not a format that the property can accept."
}
}
```
Tested:
- Check those response messages
Change-Id: I746c55e42e8f0cde205a3800e3da17cd78cf7e34
Signed-off-by: Myung Bae <myungbae@us.ibm.com>
|
|
One line change and rerun the script. 2026.1 includes new properties.
The overview is at [1].
[1]: https://www.dmtf.org/sites/default/files/Redfish_Release_2026.1_Overview.pdf
Tested: Inspection only.
Change-Id: I007f074128e278fb267ee4de3b9cbab22d6336df
Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
|
|
DMTF released Redfish-Publications a while ago. Recently, they've
started blocking scripts from accessing the website.
This is fully vibe coded with some review by me, but seems to produce
the same result we had previously, and if there were differences they'd
show up in review.
Change-Id: Ib3686b610ca6a60b1fae12b575042575b32f6ec5
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Previously, PayloadTooLarge errors incorrectly returned HTTP 400 Bad
Request. This change fixes the HTTP status to 413 Payload Too Large per
RFC 7231 so the response code matches the Base.PayloadTooLarge message
the service already emits.
Root cause: scripts/parse_registries.py is the generator that produces
redfish-core/src/error_messages.cpp. Its get_response_code() lookup
table did not list PayloadTooLarge, so the generator emitted the
default boost::beast::http::status::bad_request. Adding
"PayloadTooLarge": "payload_too_large" to the table fixes the
generator.
Change-Id: I6583b1156ffa4a6b4c99b8a5c82fdcb76ca3a13c
Signed-off-by: Rajeev Ranjan <ranjan.rajeev1609@gmail.com>
|
|
Change ResourceAlreadyExists from HTTP 400 Bad Request to HTTP 409
Conflict. While the Redfish specification (DSP0266 v1.23.1) does not
explicitly mandate to return 409 it makes more sense because:
- HTTP 400 implies a malformed request which this is clearly not
- HTTP 409 is defined in Table 13 of DSP0266 as Creation or update
request could not be completed because it causes a conflict in the
current state of the resource which is what happens.
Also mapping ResourceCreationConflict to 409 for the same reason even
even though its currently not used in the codebase.
Tested: POST to create a duplicate user account now returns HTTP 409
with ResourceAlreadyExists message instead of HTTP 400. The
ResourceCreationConflict message is not used in the codebase and can
not be tested.
Change-Id: Id482e5e4f7b3d6ca56228f9d763c95aa50c9856f
Signed-off-by: Christian Walter <christian.walter@9elements.com>
|
|
If target BMC image is deployed in QEMU, port is typically non std one,
and since it's being emulated, it's typically slower. As result, the
script fails trying to connect to port 443 and not all operations finish
within default 5 seconds timeout. So, add parameters which allow to
override port and timeout to accommodate tests of images running in
QEMU.
Tested: Ran this against QEMU instance, passed 8443 as port and 30.0 as
the timeout, worked fine.
Change-Id: Ib3d9fa0e9cef87dba2f35b38f33dc8186ad0b4b8
Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
|
|
httpx deprecated [1] passing CA as verify and certs as tuple and now the
code does not work as expected. Replace these values with ssl context as
suggested.
Tested: Ran the script and it worked.
[1] https://github.com/encode/httpx/blob/master/httpx/_config.py#L45-L63
Change-Id: Ifb90e8e978e63b94b7a0f149d226841ceaa20658
Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
|
|
As a comment in https://gerrit.openbmc.org/c/openbmc/bmcweb/+/86868
suggested "You might also consider moving this up a line so you catch
the scope on both sides."
This enforces just the slightest bit more clang-format.
Rerun script.
Tested: Builds. Manual changes to script only. Rest generated.
Change-Id: I8ff01befc56c576716f5d83bd90763354b1ff0c5
Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
|
|
switch is a reserved keyword in C++.. Therefore "namespace switch" is
illegal C++ code.
Add a couple lines of python code to check for keywords and then rename
with a rf_ at the front, e.g. namespace rf_switch.
Rerun the script update_schemas.py script.
This showed downstream, but probably would have upstream too.
```
switch.hpp:8:11: error: expected identifier or '{' [clang-diagnostic-error]
8 | namespace switch
| ^
.../bmcweb/redfish-core/include/generated/enums/switch.hpp:8:11: error: expected unqualified-id [clang-diagnostic-error]
...
FAILED: meson-internal__clang-tidy-fix
```
Change-Id: I58be67fc0df6e5056e63da5302724e6509b7114b
Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
|
|
One line change and rerun the script. 2025.4 includes new properties.
One use case is for Redundancy. For the complete overview see [1].
Tested: Visual and build only. In the past these have not broken things.
[1]: https://www.dmtf.org/sites/default/files/Redfish_Release_2025.4_Overview.pdf
Change-Id: Icaf710eaa99816264993a964ef9dd8a7f5e7722a
Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
|
|
Clang-format was unhappy with the new
redfish-core/include/generated/enums/switch.hpp in 2025.4
```
diff --git a/redfish-core/include/generated/enums/switch.hpp b/redfish-core/include/generated/enums/switch.hpp
index 6acf6e28..cabc8562 100644
--- a/redfish-core/include/generated/enums/switch.hpp
+++ b/redfish-core/include/generated/enums/switch.hpp
@@ -5,7 +5,7 @@
namespace switch
{
-// clang-format off
+ // clang-format off
```
Move turning clang-format off before the namespace fixes.
¯\_(ツ)_/¯
Do that in generate_schema_enums.py and rerun update_schemas.py.
Adding 4 spaces before the clang-format off broke other generated
enums. Broke out from 2025.4.
Tested: Visual and build only.
Change-Id: Ic03aa558b405957f15035570d376c46c545906c0
Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
|
|
CI is failing due to the formatting of scripts/parse_registries.py. Run
Black.
black -l 79 <filename>
Current:
Running black (black, 26.1.0 (compiled: no))
reformatted scripts/parse_registries.py
Before:
Running black (black, 25.12.0 (compiled: no))
Tested: Visual only.
Change-Id: I08051019760994a095eeedab2ae0d8c91984e979
Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
|
|
Rather than maintaining a list of arguments that are numbers (which is
error prone), update the script to just trust that the few parameters
labeled in Redfish as numbers should in fact show up in the API as
numbers.
Functionally this changes the APIs for only a few error messages, only
one of which (StringValueTooShort) is used and that usage was added
recently.
Tested: SRV passes.
Change-Id: I580523ecc0263688738bcb7f7925913e40e2a113
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
The PasswordChangeRequired error was incorrectly formatted. Per the
spec, it should be an error response and 403 on all requests except for
session creation, which is just a `@Message.ExtendedInfo` annotation.
See [1].
This is a follow-up to 1c651ee12ad55ab6626c2baf3754aecda305ba43 which
accidentally only broke out the password change logic for session
creation. This change adjusts the non-session-creation error response
for PasswordChangeRequired to return a proper error.
Tested:
- Built a romulus image
- Ran `passwd --expire root`
- curl to Managers and session creation
```
╰─○ curl -kv --user "$BMC_USER:$BMC_PASS" https: //localhost:2443/redfish/v1/Managers
< HTTP/2 403
{
"error": {
"@Message.ExtendedInfo": [
{
"@odata.type": "#Message.v1_1_1.Message",
"Message": "The password provided for this account must be changed before access is granted. PATCH the Password property for this account located at the target URI '/redfish/v1/AccountService/Accounts/root' to complete this process.",
"MessageArgs": [
"/redfish/v1/AccountService/Accounts/root"
],
"MessageId": "Base.1.19.PasswordChangeRequired",
"MessageSeverity": "Critical",
"Resolution": "Change the password for this account using a PATCH to the Password property at the URI provided."
}
],
"code": "Base.1.19.PasswordChangeRequired",
"message": "The password provided for this account must be changed before access is granted. PATCH the Password property for this account located at the target URI '/redfish/v1/AccountService/Accounts/root' to complete this process."
}
}
╰─○ curl -kv -X POST -H 'Content-Type: application/json' -d '{"UserName": "root", "Password": "..."}' https://localhost:2443/redfish/v1/SessionService/Sessions
< HTTP/2 201
{
"@Message.ExtendedInfo": [
{
"@odata.type": "#Message.v1_1_1.Message",
"Message": "The password provided for this account must be changed before access is granted. PATCH the Password property for this account located at the target URI '/redfish/v1/AccountService/Accounts/root' to complete this process.",
"MessageArgs": [
"/redfish/v1/AccountService/Accounts/root"
],
"MessageId": "Base.1.19.PasswordChangeRequired",
"MessageSeverity": "Critical",
"Resolution": "Change the password for this account using a PATCH to the Password property at the URI provided."
}
],
"@odata.id": "/redfish/v1/SessionService/Sessions/klDQdHSMME",
"@odata.type": "#Session.v1_7_0.Session",
"ClientOriginIPAddress": "0.0.0.0",
"Description": "Manager User Session",
"Id": "klDQdHSMME",
"Name": "User Session",
"Roles": [
"Administrator"
],
"UserName": "root"
}
```
[1]: https://www.dmtf.org/sites/default/files/standards/documents/DSP0266_1.22.1.html#password-change-required-handling
Change-Id: I0ab50b4e2298d13ae00f84bc7891c2a14610e1b2
Signed-off-by: Joey Berkovitz <joey@berkovitz.us>
|
|
Include cleaner helps the code review process. Add it back, by ignoring
some of the more recent boost headers.
Change-Id: I6eddd0e67cd9f469c93fbb344cc1ab46231e450f
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
1 line change in scripts/update_schemas.py to point at 2025.3 and run
the script.
See below for more info on this release [1]
Tested: Inspection only. These have not broke things in the past.
Symlinks are getting updated:
```
head -n 4 redfish-core/schema/dmtf/json-schema-installed/ComputerSystem.v1_*.json
{
"$id": "http://redfish.dmtf.org/schemas/v1/ComputerSystem.v1_26_0.json",
"$ref": "#/definitions/ComputerSystem",
"$schema": "http://redfish.dmtf.org/schemas/v1/redfish-schema-v1.json",
```
[1]: https://www.dmtf.org/sites/default/files/Redfish_Release_2025.3_Overview.pdf
Change-Id: Icc0e7b2bc775be6fa0f842670820319b79606507
Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
|
|
Generate the update registry, needed to return correct error messages
from update service.
Change-Id: Ifaa699cad8531070aea47d2476c1834df7c61e08
Signed-off-by: Alexander Hansen <alexander.hansen@9elements.com>
|
|
this commit is enhancing the gen auth cert test by using better
flag option for http2 and not flipping the value
Change-Id: I989606807ba0f286a16c1e6e3f1bfc5dbe6a430d
Signed-off-by: Malik Akbar Hashemi Rafsanjani <malikrafsan@meta.com>
|
|
with this commit, we will make the integration testing of
`generate_auth_certificate` to use http2 by default
this is aligned with previous commit to enable http2 for mutual TLS
Change-Id: I79bb95ef1ad3aaa597900c122372a06d205386f2
Signed-off-by: Malik Akbar Hashemi Rafsanjani <malikrafsan@meta.com>
|
|
SubordinateOverrides:
This commit automates the creation of SubordinateOverrides privileges
structures from the redfish privilege registry. In addition, it
enhances the function of parse_registries.py.
It reads SubordinateOverrides privilege registry from DMTF and
generates const defines SubordinateOverrides for all the privilege
registry entries in the same format that the Privileges struct
accepts.
Moreover, it generates unique const defines for all
SubordinateOverrides target levels.
Ex: EthernetInterface SubordinateOverrides has two "Targets":
["Manager", "EthernetInterfaceCollection"]. So
parse_registries.py generates two unique const
1) Subordinate override for Manager -> EthernetInterface
2) Subordinate override for Manager ->
EthernetInterfaceCollection -> EthernetInterface
Note: if SubordinateOverrides privilege gets changed, then it
automatically updates that route privilege, but if
SubordinateOverrides target gets changed, then the user needs to
update that manually.
Fix Log_services privileges:
In Log_services, some of the privileges not following the
Redfish_1.1.0_PrivilegeRegistry registry.
This commit contains the following LogServices privileges.
1) POST method
```
ComputerSystem -> LogServiceCollection -> LogService
- POST /redfish/v1/Systems/<str>/LogServices/EventLog/Actions/LogService.ClearLog/
- POST /redfish/v1/Systems/<str>/LogServices/Dump/Actions/LogService.CollectDiagnosticData/
- POST /redfish/v1/Systems/<str>/LogServices/Dump/Actions/LogService.ClearLog/
- POST /LogServices/PostCodes/Actions/LogService.ClearLog/
```
2) DELETE method
```
ComputerSystem -> LogServiceCollection -> LogService -> LogEntryCollection -> LogEntry
- DELETE /redfish/v1/Systems/<str>/LogServices/EventLog/Entries/<str>/
```
This commit also changes the current privilege
1) ConfigureManager to ConfigureComponents.
```
DELETE /redfish/v1/Systems/<str>/LogServices/EventLog/Entries/<str>
```
2) ConfigureCompnents -> ConfigureManager
```
POST /redfish/v1/Systems/<str>/LogServices/Dump/Actions/LogService.ClearLog/
POST /redfish/v1/Systems/<str>/LogServices/EventLog/Actions/LogService.ClearLog/
POST /redfish/v1/Systems/<str>/LogServices/Dump/Actions/LogService.CollectDiagnosticData/
```
Tested: manually tested on Witherspoon system, there is no change in
output. Run Redfish validator, with all different Privileges;
Error Get: UUID: String '' does not match pattern ''
this commit doesn't affect UUID
Email sent to openbmc list:
https://lists.ozlabs.org/pipermail/openbmc/2021-August/027232.html
Change-Id: I37d8a2882f1cfaa59a482083f180fdd0805e2e7d
Signed-off-by: Abhishek Patel <Abhishek.Patel@ibm.com>
Signed-off-by: Myung Bae <myungbae@us.ibm.com>
|
|
This fixes `update_schemas.py` so that the existing installed csdl and
json symlinks are to be kept and also to be updated with the matching
json schema version when DMTF schema version is upgraded.
This commit also uses the symlinks to the closed relative paths like
- `../schema/dmtf/installed/<schema>.xml -> ../csdl/<schema>.xml`
- `../schema/dmtf/json-schema-installed/<json-file>.json ->
../json-schema/<json-file>.json`
Tested:
- Change VERSION in `update_schemas.py` and verify the generated files
- CI passes
- Redfish Service Validator passes
Change-Id: Ib7fede7e4c39bdfc13da227eb1e737d96b6c2b5e
Signed-off-by: Myung Bae <myungbae@us.ibm.com>
|
|
1 line change in update_schemas.py and rerun it.
See below for more info on this release [1]
Tested: Inspection only. These have not broke things in the past.
[1]: https://www.dmtf.org/sites/default/files/Redfish_Release_2025.2_Overview.pdf
Change-Id: I641bc4285fa502a5d81318ff56eaeb75c0af4762
Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
|
|
forbidden (403) - "a 403 error means there is an authorization /
permission problem."
405 "Method Not Allowed" error means that the web server understands the
request but refuses to process it because the HTTP method (like GET,
POST, PUT, etc.) used in the request is not supported by the server or
the resource.".
Following a stackoverflow response here [1].
Dell mapped PropertyNotWritable to a 400 error. [2] A 400 would be my
2nd choice.
[1]: https://stackoverflow.com/questions/52892076/http-code-to-return-for-unsupported-patch
[2]: https://www.dell.com/support/manuals/en-in/idrac7-8-lifecycle-controller-v2.30.30.30/redfish_v2.30.30.30/managernetworkprotocol?guid=guid-b2be28b5-60a5-4782-83ac-3efb3af79ef2&lang=en-us
Change-Id: Iff3f773a1fdbea96d65f8b82fec75cfc34519ae0
Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
|
|
All the registry helper functions should return an object_t, given that
they're guaranteed to return an object. nlohmann::json as a type can
technically be string/int/bool/null/object/array, so it causes some
peculiarities in parsing.
Change-Id: If296477cb8d066d7f44ef0d12f17d94a5301e450
Signed-off-by: Ed Tanous <ed@tanous.net>
|
|
Rather than having to manually hook code for registries, add a small
registration function to the registry header and use this registration
results throughout the registry interactions.
Tested:
Confirmed registries have same behavior.
```
$ curl -s -k https://localhost:18080/redfish/v1/Registries/ | jq '.Members | map(."@odata.id")'
[
"/redfish/v1/Registries/Base",
"/redfish/v1/Registries/HeartbeatEvent",
"/redfish/v1/Registries/OpenBMC",
"/redfish/v1/Registries/ResourceEvent",
"/redfish/v1/Registries/TaskEvent",
"/redfish/v1/Registries/Telemetry"
]
```
```
$ curl -s -k https://localhost:18080/redfish/v1/Registries/TaskEvent/TaskEvent | jq ".Messages | keys"
[
"TaskAborted",
"TaskCancelled",
"TaskCompletedOK",
"TaskCompletedWarning",
"TaskPaused",
"TaskProgressChanged",
"TaskRemoved",
"TaskResumed",
"TaskStarted"
]
```
Signed-off-by: Patrick Williams <patrick@stwcx.xyz>
Change-Id: Iaa355420736a2587d9da4e995208d579443ca9b8
|
|
Currently, parse_registries.py assumes the description property exists
in every registry json it parses. However, according to the spec [1]
it is not a required property, so it may not exist, see [2].
Switch it to optional and use an empty string as a default value.
Testing:
Ran the script and made sure the generated files remain unchanged.
[1] https://redfish.dmtf.org/schemas/v1/MessageRegistry.v1_4_0.json
[2] Run: `curl https://redfish.dmtf.org/schemas/v1/MessageRegistry.v1_4_0.json | jq .definitions.MessageRegistry.required`
Change-Id: I3e9ba84bbdb9ba5e6ed8b00cde48c15a1b5abba6
Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
|
|
The script has previously stated:
> This script will be removed Q2 2024
As such, delete it.
Signed-off-by: Patrick Williams <patrick@stwcx.xyz>
Change-Id: Idb35ee22e605bd0a8f456a2eca56904936d791d2
|
|
TypeDefinition was not supported by generate_schema_enums.py, this
change is to support the 'TypeDefinition' generation from schema.
Tested:
'TypeDefinition' fields in schema can be generated in generated files
with the change
Change-Id: Ibe61f65b905f2089f9e17a26fbd27e3ff1753166
Signed-off-by: Chandramohan Harkude <chandramohan.harkude@gmail.com>
|
|
When using the --use-intermediate flag, the script generates:
1. Root CA Certificate:
- Self-signed certificate (CA-cert.cer)
- Used as the root of trust
- Signs the intermediate certificates
2. Separate intermediate CAs for client and server:
- Client intermediate: client-intermediate-cert.cer
- Server intermediate: server-intermediate-cert.cer
- Each signed by the root CA
3. End-entity certificates with their respective intermediate chains:
- Client certificate chain: client-cert.pem (includes intermediate)
- Server certificate chain: server-cert.pem (includes intermediate)
Change-Id: Ifdfd1c044d1c8745638e44debfc90cad3b5aedb7
Signed-off-by: Ben Peled <bpeled@nvidia.com>
|
|
This fixes the http error code of the operations of the restricted role
which currently result in bad_request (400) instead of forbidden (403).
Tested:
```
$ redfishtool -r ${bmc}:18080 -u ${user} -p ${pass} -S Always raw POST /redfish/v1/AccountService/Accounts -d '{"UserName":"service","Password":"newPwd1","RoleId":"Operator"}'
redfishtool: Transport: Response Error: status_code: 403 -- Forbidden--user not authorized to perform action
redfishtool: raw: Error sending POST to resource, aborting
$ redfishtool -r ${bmc}:18080 -u ${user} -p ${pass} -S Always raw PATCH /redfish/v1/AccountService/Accounts/${user} -d '{"Password":"NewTestPwd123"}'
redfishtool: Transport: Response Error: status_code: 403 -- Forbidden--user not authorized to perform action
$ redfishtool -r ${bmc}:18080 -u ${user} -p ${pass} -S Always raw PATCH /redfish/v1/AccountService/Accounts/${user} -d '{"UserName":"new-service"}'
redfishtool: Transport: Response Error: status_code: 403 -- Forbidden--user not authorized to perform action
$ redfishtool -r ${bmc}:18080 -u ${user} -p ${pass} -S Always raw PATCH /redfish/v1/AccountService/Accounts/${user} -d '{"RoleId":"Operator"}'
redfishtool: Transport: Response Error: status_code: 403 -- Forbidden--user not authorized to perform action
$ redfishtool -r ${bmc}:18080 -u ${user} -p ${pass} -S Always raw DELETE /redfish/v1/AccountService/Accounts/${user}
redfishtool: Transport: Response Error: status_code: 403 -- Forbidden--user not authorized to perform action
redfishtool: raw: Error sending DELETE to resource, aborting
```
Change-Id: I1b212ccb5a630750eb5d4197970b4fb75fceffd7
Signed-off-by: Myung Bae <myungbae@us.ibm.com>
|
|
It is better to sort get_response_code names in parse_registries.py.
Tested:
- Script run generates the same output
Change-Id: I79028c8f95c4cf6681bc4f5b12dd858188e9eff8
Signed-off-by: Myung Bae <myungbae@us.ibm.com>
|
|
1 line change in update_schemas.py and rerun it.
See below for more info on this release:
https://www.dmtf.org/content/redfish-release-20251-now-available
Tested: Inspection only. These have not broke things in the past.
Change-Id: I8d386725b364e2bc7c91c869e519e5e7bfbf11f9
Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
|
|
This commit is intended to extend existing `generate_auth_certificate`
python script that automatically test the auth functionality of bmcweb.
We extend the script by adding test for UserPrincipalName (UPN) feature.
This feature[1] allow us to use SubjectAlternativeName (SAN) extension
on X509 certificate and enable us to use the different name as username.
Previously we can only use CommonName in the certificate as username
By adding this changes, we can test the UPN feature easily using the
script. We add a new flag that enable the user to test using UPN feature
by specifying the UPN name to be tested.
UPN has OID that is specified by Microsoft[2]. The full OID path:
1 ISO
1.3 identified-organization (ISO/IEC 6523),
1.3.6 DoD,
1.3.6.1 internet,
1.3.6.1.4 private,
1.3.6.1.4.1 enterprise,
1.3.6.1.4.1.311 Microsoft,
1.3.6.1.4.1.311.20 Microsoft enrollment infrastructure,
1.3.6.1.4.1.311.20.2 Certificate Type Extension,
1.3.6.1.4.1.311.20.2.3 UserPrincipalName
Tested:
- Regress test on CommonName by running without `--upn` flag
- Test using correct UPN name
- There are two requirements for the UPN name (`username@domain`)
- `username` must exist in the BMC device accounts
- `domain` must match the domain forest of the device
- eg: malik@fb.com match macbmc1.abc.fb.com
- Test using incorrect UPN name
- Violate one of the requirements and the test should fail
[1] Patch feature: https://gerrit.openbmc.org/c/openbmc/bmcweb/+/78519
[2] OID of UPN: https://oidref.com/1.3.6.1.4.1.311.20.2.3
Change-Id: I997bea9a6662fa41c3824fde71ea4f20b606ca9c
Signed-off-by: Malik Akbar Hashemi Rafsanjani <malikrafsan@meta.com>
|
|
Added type hints to reduce possibility of mistakes caused by using wrong
types and make changes safer/faster to make. Fixed bugs related to types
in the script.
Testing:
Ran the script, made sure it did not change anything in the repo (i.e.
produces the same results as before).
Change-Id: Ia7be551705a9eeabb2dd762bf709b113f8f1405b
Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
|
|
New version includes Leak related messages we need.
Testing:
Redfish service validator passing
Change-Id: Ieca3e5a7bb785ef7fcffb05f86b88bdbf23a3d99
Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
|
|
Minor refactoring:
- Change global scope variable names to capital letters
- get_response_code method to make it more readable and pythonic.
- Now, already processed data is stored in 2 variables - registries_map
and files, use only 1 storage to avoid errors caused by missing some
entries in one storage, but presenting in another.
Testing:
Ran the script and made sure the files it generated did not change.
Change-Id: Ida35adcd3530dbd87040a12de4903eda5f1f93f7
Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
|
|
pyCrypto has removed support for the PKCS12 certificates this script
generates, so this script is broken as-is on any distro from the last
year or two.
Rewrite the script to target python-cryptography instead. While there,
implement TODOs around code formatting, using EC keys, removing the
dependency on the redfish library, using the service root to
determine the correct manager instance to update, and cleaning up the
redfish session after a crash.
Tested: running this script targeting redfish instance shows it runs
to completion and test passes.
Change-Id: Ie1ee1a6f0a548258fe7b7d4c9678a9d55c8b71d1
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Unclear when or why this changed in python, but doesn't really matter.
Fix the script.
Tested: Script now succeeds with rest option enabled.
Change-Id: I3e548aad03c6150f404d5fddc742f8baa5274a83
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
The generated registries have an imperfect handling of #include
dependencies. Update the script to ignore the misc-include-cleaner
recommendations for now. Future fixes could be done to make these
generated headers actually correctly include their dependencies, but
that is non trivial to do, and the build is broken.
Change-Id: I32c70e9f865ca7ef693c736a45b3ea59513a751d
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Update schema to the latest release 2024.4.
See below for more info on this release:
https://www.dmtf.org/standards/redfish
Tested:
- Redfish Service Validator passes
Change-Id: I1845d6afa04ee418ba3ab0bd0bc8ce59886e4376
Signed-off-by: Myung Bae <myungbae@us.ibm.com>
|
|
This code should really be in a cpp/hpp file, not in a generated python
script. The python script housed this temporarily to allow us to
generate the registries. It's time to roll it out.
Tested: Message registries generate successfully on GET. Redfish
service validator passes.
Change-Id: I7aca2d0a7fac6d530511421b667ff732617df61e
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
SPDX identifiers are simpler, and reduce the amount of cruft we have in
code files. They are recommended by linux foundation, and therefore we
should do as they allow.
This patchset does not intend to modify any intent on any existing
copyrights or licenses, only to standardize their inclusion.
[1] https://www.linuxfoundation.org/blog/blog/copyright-notices-in-open-source-software-projects
Change-Id: I935c7c0156caa78fc368c929cebd0f068031e830
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Apply black formatter to code.
Change-Id: I4a3d8426b03eeb8d71230f24788ac8caeb3618c3
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
The parse_registries.py generates base, heartbeat, resource and taskevent
registries without checking input registries list. Which causes out of range
error when input non default value.
This commit only generates above registries if they are input.
Tested:
Input only openbmc registry passes.
Input only heartbeat registry passes.
Run with default registries passes.
Change-Id: Ibb6e6ee9f241c424bb78782466eb3199b11332c3
Signed-off-by: Tam Nguyen <tamnguyenchi@os.amperecomputing.com>
|
|
Replace the message registry URL with the official GitHub raw download
URL to give the json content not a web SCM GUI.
Change-Id: I0ac800ee3803c9bef3a6a799b20887df84c3c173
Signed-off-by: Milton Miller <mdmii@outlook.com>
|
|
Generate the heartbeat registry, and adjust the #includes of the
other generated registries.
Tested: Redfish service validator succeeds.
Change-Id: Iedbf1ae8dc6559666691f1feb71af08e856d5c80
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Generate Resource event registry
Tested: On last patch of series. No behavior changes.
Change-Id: I924919db0e7fbde8ed698de6b59b86f788de9708
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Generate the task event registry.
Tested: on last patch of series
Change-Id: I55b7914978f7a1d637cad6dfae398949af0a7107
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Redfish service valitator warns:
WARNING - PublicationUri: Empty string found - Services should omit
properties if not supported
This commit adds to our registry the url to the openbmc registry file.
Tested: Redfish Service validator no longer returns a warning.
Change-Id: Ia54be175490b4e7e00e3c0c4ab8c60dce1b96863
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|