summaryrefslogtreecommitdiff
path: root/scripts
AgeCommit message (Collapse)AuthorFilesLines
2026-07-17Update GenerateSecretKeyRequired response_codeJishnu CM1-1/+1
Currently, GenerateSecretKeyRequired is treated as 403 Forbidden, which would incorrectly imply the session was not created, when it should be treated as an informational message accompanying a successful session creation (with 201 response code), exactly like PasswordChangeRequired. According to the Redfish spec [1], page 202, 203 (Section 13.5.5): * "Shall allow a session login without the Token property and include the @Message.ExtendedInfo in the response containing the GenerateSecretKeyRequired message. This indicates to the client that their session is restricted to performing only the GenerateSecretKey action on their ManagerAccount resource before access is granted." * "Shall allow a POST operation on the VerifyTimeBasedOneTimePassword" action on the ManagerAccount resource associated with the account." * "Shall allow a DELETE operation on Session resources representing open sessions associated with the account." * "May allow GET operations on unauthenticated resources, such as the ServiceRoot resource." * "For all other operations, the service shall respond with the HTTP 403 Forbidden status code and an error response with the GenerateSecretKeyRequired message from the Base Message Registry." Reference: [1] https://www.dmtf.org/sites/default/files/standards/documents/DSP0266_1.24.0.pdf#page=202&zoom=100,0,789 Tested By: * Enabled Multi-Factor Authentication (system-wide option) * When user tries to login with username and password, session is created (201 is returned), with GenerateSecretKeyRequired message in "@Message.ExtendedInfo" * Any operations on restricted resources returned GenerateSecretKeyRequired with 403 Forbidden error code. Change-Id: Iec6c925f04584b2cdd93aec743b04d6a8dbde4bc Signed-off-by: Jishnu CM <jishnunambiarcm@duck.com>
2026-06-25Change a few message responses as errorsMyung Bae1-16/+1
Some of messages are not currently reported as errors, although they are the results as Redfish request errors. Those include - PropertyDuplicate - ResourceAlreadyExists - CreateFailedMissingReqProperties - PropertyValueFormatError - PropertyValueNotInList - PropertyValueTypeError - PropertyValueError - PropertyNotWritable - PropertyValueModified - PropertyMissing For example, PropertyValueFormatError is currently not treated as an error. It shows like ``` curl -k -X PATCH "${bmc}/redfish/v1/AccountService/Accounts/admin" \ -H "Content-Type: application/json" \ -d '{ "Password": "" }' "Password@Message.ExtendedInfo": [ { "@odata.type": "#Message.v1_1_1.Message", "Message": "The value 'null' for the property Password is not a format that the property can accept.", "MessageArgs": [ "null", "Password" ], "MessageId": "Base.1.19.PropertyValueFormatError", "MessageSeverity": "Warning", "Resolution": "Correct the value for the property in the request body and resubmit the request if the operation failed." } ] ``` After making it as an error, it will be like ``` { "error": { "@Message.ExtendedInfo": [ { "@odata.type": "#Message.v1_1_1.Message", "Message": "The value 'null' for the property Password is not a format that the property can accept.", "MessageArgs": [ "null", "Password" ], "MessageId": "Base.1.19.PropertyValueFormatError", "MessageSeverity": "Warning", "Resolution": "Correct the value for the property in the request body and resubmit the request if the operation failed." } ], "code": "Base.1.19.PropertyValueFormatError", "message": "The value 'null' for the property Password is not a format that the property can accept." } } ``` Tested: - Check those response messages Change-Id: I746c55e42e8f0cde205a3800e3da17cd78cf7e34 Signed-off-by: Myung Bae <myungbae@us.ibm.com>
2026-05-19Move to Redfish 2026.1Gunnar Mills1-1/+1
One line change and rerun the script. 2026.1 includes new properties. The overview is at [1]. [1]: https://www.dmtf.org/sites/default/files/Redfish_Release_2026.1_Overview.pdf Tested: Inspection only. Change-Id: I007f074128e278fb267ee4de3b9cbab22d6336df Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
2026-05-19Port update_schemas script to use gitEd Tanous1-96/+70
DMTF released Redfish-Publications a while ago. Recently, they've started blocking scripts from accessing the website. This is fully vibe coded with some review by me, but seems to produce the same result we had previously, and if there were differences they'd show up in review. Change-Id: Ib3686b610ca6a60b1fae12b575042575b32f6ec5 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2026-05-12Fix PayloadTooLarge to return HTTP 413Rajeev Ranjan1-0/+1
Previously, PayloadTooLarge errors incorrectly returned HTTP 400 Bad Request. This change fixes the HTTP status to 413 Payload Too Large per RFC 7231 so the response code matches the Base.PayloadTooLarge message the service already emits. Root cause: scripts/parse_registries.py is the generator that produces redfish-core/src/error_messages.cpp. Its get_response_code() lookup table did not list PayloadTooLarge, so the generator emitted the default boost::beast::http::status::bad_request. Adding "PayloadTooLarge": "payload_too_large" to the table fixes the generator. Change-Id: I6583b1156ffa4a6b4c99b8a5c82fdcb76ca3a13c Signed-off-by: Rajeev Ranjan <ranjan.rajeev1609@gmail.com>
2026-03-23bmcweb: Return HTTP 409 for resource conflict errorsChristian Walter1-0/+2
Change ResourceAlreadyExists from HTTP 400 Bad Request to HTTP 409 Conflict. While the Redfish specification (DSP0266 v1.23.1) does not explicitly mandate to return 409 it makes more sense because: - HTTP 400 implies a malformed request which this is clearly not - HTTP 409 is defined in Table 13 of DSP0266 as Creation or update request could not be completed because it causes a conflict in the current state of the resource which is what happens. Also mapping ResourceCreationConflict to 409 for the same reason even even though its currently not used in the codebase. Tested: POST to create a duplicate user account now returns HTTP 409 with ResourceAlreadyExists message instead of HTTP 400. The ResourceCreationConflict message is not used in the codebase and can not be tested. Change-Id: Id482e5e4f7b3d6ca56228f9d763c95aa50c9856f Signed-off-by: Christian Walter <christian.walter@9elements.com>
2026-03-06Add port and timeout args to generate_auth_certificatesIgor Kanyuka1-2/+16
If target BMC image is deployed in QEMU, port is typically non std one, and since it's being emulated, it's typically slower. As result, the script fails trying to connect to port 443 and not all operations finish within default 5 seconds timeout. So, add parameters which allow to override port and timeout to accommodate tests of images running in QEMU. Tested: Ran this against QEMU instance, passed 8443 as port and 30.0 as the timeout, worked fine. Change-Id: Ib3d9fa0e9cef87dba2f35b38f33dc8186ad0b4b8 Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
2026-02-24Replace deprecated argumentsIgor Kanyuka1-10/+18
httpx deprecated [1] passing CA as verify and certs as tuple and now the code does not work as expected. Replace these values with ssl context as suggested. Tested: Ran the script and it worked. [1] https://github.com/encode/httpx/blob/master/httpx/_config.py#L45-L63 Change-Id: Ifb90e8e978e63b94b7a0f149d226841ceaa20658 Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
2026-01-26Move clang-off / clang-on to catch scopeGunnar Mills1-3/+6
As a comment in https://gerrit.openbmc.org/c/openbmc/bmcweb/+/86868 suggested "You might also consider moving this up a line so you catch the scope on both sides." This enforces just the slightest bit more clang-format. Rerun script. Tested: Builds. Manual changes to script only. Rest generated. Change-Id: I8ff01befc56c576716f5d83bd90763354b1ff0c5 Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
2026-01-26Rename switch namespaceGunnar Mills1-0/+9
switch is a reserved keyword in C++.. Therefore "namespace switch" is illegal C++ code. Add a couple lines of python code to check for keywords and then rename with a rf_ at the front, e.g. namespace rf_switch. Rerun the script update_schemas.py script. This showed downstream, but probably would have upstream too. ``` switch.hpp:8:11: error: expected identifier or '{' [clang-diagnostic-error] 8 | namespace switch | ^ .../bmcweb/redfish-core/include/generated/enums/switch.hpp:8:11: error: expected unqualified-id [clang-diagnostic-error] ... FAILED: meson-internal__clang-tidy-fix ``` Change-Id: I58be67fc0df6e5056e63da5302724e6509b7114b Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
2026-01-23Move to Redfish 2025.4Gunnar Mills1-1/+1
One line change and rerun the script. 2025.4 includes new properties. One use case is for Redundancy. For the complete overview see [1]. Tested: Visual and build only. In the past these have not broken things. [1]: https://www.dmtf.org/sites/default/files/Redfish_Release_2025.4_Overview.pdf Change-Id: Icaf710eaa99816264993a964ef9dd8a7f5e7722a Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
2026-01-23Modify enum generation for clangGunnar Mills1-2/+2
Clang-format was unhappy with the new redfish-core/include/generated/enums/switch.hpp in 2025.4 ``` diff --git a/redfish-core/include/generated/enums/switch.hpp b/redfish-core/include/generated/enums/switch.hpp index 6acf6e28..cabc8562 100644 --- a/redfish-core/include/generated/enums/switch.hpp +++ b/redfish-core/include/generated/enums/switch.hpp @@ -5,7 +5,7 @@ namespace switch { -// clang-format off + // clang-format off ``` Move turning clang-format off before the namespace fixes. ¯\_(ツ)_/¯ Do that in generate_schema_enums.py and rerun update_schemas.py. Adding 4 spaces before the clang-format off broke other generated enums. Broke out from 2025.4. Tested: Visual and build only. Change-Id: Ic03aa558b405957f15035570d376c46c545906c0 Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
2026-01-20Fix CI: Reformat using Black 26.1.0Gunnar Mills1-31/+12
CI is failing due to the formatting of scripts/parse_registries.py. Run Black. black -l 79 <filename> Current: Running black (black, 26.1.0 (compiled: no)) reformatted scripts/parse_registries.py Before: Running black (black, 25.12.0 (compiled: no)) Tested: Visual only. Change-Id: I08051019760994a095eeedab2ae0d8c91984e979 Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
2025-11-10Parse number types from the base registryEd Tanous1-6/+2
Rather than maintaining a list of arguments that are numbers (which is error prone), update the script to just trust that the few parameters labeled in Redfish as numbers should in fact show up in the API as numbers. Functionally this changes the APIs for only a few error messages, only one of which (StringValueTooShort) is used and that usage was added recently. Tested: SRV passes. Change-Id: I580523ecc0263688738bcb7f7925913e40e2a113 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-11-03PasswordChangeRequired: Fix error messageJoey Berkovitz1-1/+0
The PasswordChangeRequired error was incorrectly formatted. Per the spec, it should be an error response and 403 on all requests except for session creation, which is just a `@Message.ExtendedInfo` annotation. See [1]. This is a follow-up to 1c651ee12ad55ab6626c2baf3754aecda305ba43 which accidentally only broke out the password change logic for session creation. This change adjusts the non-session-creation error response for PasswordChangeRequired to return a proper error. Tested: - Built a romulus image - Ran `passwd --expire root` - curl to Managers and session creation ``` ╰─○ curl -kv --user "$BMC_USER:$BMC_PASS" https: //localhost:2443/redfish/v1/Managers < HTTP/2 403 { "error": { "@Message.ExtendedInfo": [ { "@odata.type": "#Message.v1_1_1.Message", "Message": "The password provided for this account must be changed before access is granted. PATCH the Password property for this account located at the target URI '/redfish/v1/AccountService/Accounts/root' to complete this process.", "MessageArgs": [ "/redfish/v1/AccountService/Accounts/root" ], "MessageId": "Base.1.19.PasswordChangeRequired", "MessageSeverity": "Critical", "Resolution": "Change the password for this account using a PATCH to the Password property at the URI provided." } ], "code": "Base.1.19.PasswordChangeRequired", "message": "The password provided for this account must be changed before access is granted. PATCH the Password property for this account located at the target URI '/redfish/v1/AccountService/Accounts/root' to complete this process." } } ╰─○ curl -kv -X POST -H 'Content-Type: application/json' -d '{"UserName": "root", "Password": "..."}' https://localhost:2443/redfish/v1/SessionService/Sessions < HTTP/2 201 { "@Message.ExtendedInfo": [ { "@odata.type": "#Message.v1_1_1.Message", "Message": "The password provided for this account must be changed before access is granted. PATCH the Password property for this account located at the target URI '/redfish/v1/AccountService/Accounts/root' to complete this process.", "MessageArgs": [ "/redfish/v1/AccountService/Accounts/root" ], "MessageId": "Base.1.19.PasswordChangeRequired", "MessageSeverity": "Critical", "Resolution": "Change the password for this account using a PATCH to the Password property at the URI provided." } ], "@odata.id": "/redfish/v1/SessionService/Sessions/klDQdHSMME", "@odata.type": "#Session.v1_7_0.Session", "ClientOriginIPAddress": "0.0.0.0", "Description": "Manager User Session", "Id": "klDQdHSMME", "Name": "User Session", "Roles": [ "Administrator" ], "UserName": "root" } ``` [1]: https://www.dmtf.org/sites/default/files/standards/documents/DSP0266_1.22.1.html#password-change-required-handling Change-Id: I0ab50b4e2298d13ae00f84bc7891c2a14610e1b2 Signed-off-by: Joey Berkovitz <joey@berkovitz.us>
2025-10-21Add back include cleanerEd Tanous1-4/+4
Include cleaner helps the code review process. Add it back, by ignoring some of the more recent boost headers. Change-Id: I6eddd0e67cd9f469c93fbb344cc1ab46231e450f Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-10-13Redfish 2025.3Gunnar Mills1-1/+1
1 line change in scripts/update_schemas.py to point at 2025.3 and run the script. See below for more info on this release [1] Tested: Inspection only. These have not broke things in the past. Symlinks are getting updated: ``` head -n 4 redfish-core/schema/dmtf/json-schema-installed/ComputerSystem.v1_*.json { "$id": "http://redfish.dmtf.org/schemas/v1/ComputerSystem.v1_26_0.json", "$ref": "#/definitions/ComputerSystem", "$schema": "http://redfish.dmtf.org/schemas/v1/redfish-schema-v1.json", ``` [1]: https://www.dmtf.org/sites/default/files/Redfish_Release_2025.3_Overview.pdf Change-Id: Icc0e7b2bc775be6fa0f842670820319b79606507 Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
2025-08-18Generate update registryAlexander Hansen1-1/+8
Generate the update registry, needed to return correct error messages from update service. Change-Id: Ifaa699cad8531070aea47d2476c1834df7c61e08 Signed-off-by: Alexander Hansen <alexander.hansen@9elements.com>
2025-08-13flip http2 flag for generate auth cert integration testMalik Akbar Hashemi Rafsanjani1-4/+4
this commit is enhancing the gen auth cert test by using better flag option for http2 and not flipping the value Change-Id: I989606807ba0f286a16c1e6e3f1bfc5dbe6a430d Signed-off-by: Malik Akbar Hashemi Rafsanjani <malikrafsan@meta.com>
2025-08-13add integration testing for auth using http2Malik Akbar Hashemi Rafsanjani1-5/+22
with this commit, we will make the integration testing of `generate_auth_certificate` to use http2 by default this is aligned with previous commit to enable http2 for mutual TLS Change-Id: I79bb95ef1ad3aaa597900c122372a06d205386f2 Signed-off-by: Malik Akbar Hashemi Rafsanjani <malikrafsan@meta.com>
2025-07-11Add SubordinateOverrides & Fix Log_services privilegesAbhishek Patel1-0/+37
SubordinateOverrides: This commit automates the creation of SubordinateOverrides privileges structures from the redfish privilege registry. In addition, it enhances the function of parse_registries.py. It reads SubordinateOverrides privilege registry from DMTF and generates const defines SubordinateOverrides for all the privilege registry entries in the same format that the Privileges struct accepts. Moreover, it generates unique const defines for all SubordinateOverrides target levels. Ex: EthernetInterface SubordinateOverrides has two "Targets": ["Manager", "EthernetInterfaceCollection"]. So parse_registries.py generates two unique const 1) Subordinate override for Manager -> EthernetInterface 2) Subordinate override for Manager -> EthernetInterfaceCollection -> EthernetInterface Note: if SubordinateOverrides privilege gets changed, then it automatically updates that route privilege, but if SubordinateOverrides target gets changed, then the user needs to update that manually. Fix Log_services privileges: In Log_services, some of the privileges not following the Redfish_1.1.0_PrivilegeRegistry registry. This commit contains the following LogServices privileges. 1) POST method ``` ComputerSystem -> LogServiceCollection -> LogService - POST /redfish/v1/Systems/<str>/LogServices/EventLog/Actions/LogService.ClearLog/ - POST /redfish/v1/Systems/<str>/LogServices/Dump/Actions/LogService.CollectDiagnosticData/ - POST /redfish/v1/Systems/<str>/LogServices/Dump/Actions/LogService.ClearLog/ - POST /LogServices/PostCodes/Actions/LogService.ClearLog/ ``` 2) DELETE method ``` ComputerSystem -> LogServiceCollection -> LogService -> LogEntryCollection -> LogEntry - DELETE /redfish/v1/Systems/<str>/LogServices/EventLog/Entries/<str>/ ``` This commit also changes the current privilege 1) ConfigureManager to ConfigureComponents. ``` DELETE /redfish/v1/Systems/<str>/LogServices/EventLog/Entries/<str> ``` 2) ConfigureCompnents -> ConfigureManager ``` POST /redfish/v1/Systems/<str>/LogServices/Dump/Actions/LogService.ClearLog/ POST /redfish/v1/Systems/<str>/LogServices/EventLog/Actions/LogService.ClearLog/ POST /redfish/v1/Systems/<str>/LogServices/Dump/Actions/LogService.CollectDiagnosticData/ ``` Tested: manually tested on Witherspoon system, there is no change in output. Run Redfish validator, with all different Privileges; Error Get: UUID: String '' does not match pattern '' this commit doesn't affect UUID Email sent to openbmc list: https://lists.ozlabs.org/pipermail/openbmc/2021-August/027232.html Change-Id: I37d8a2882f1cfaa59a482083f180fdd0805e2e7d Signed-off-by: Abhishek Patel <Abhishek.Patel@ibm.com> Signed-off-by: Myung Bae <myungbae@us.ibm.com>
2025-06-25Fix json-schema-installed version during schema updateMyung Bae1-0/+34
This fixes `update_schemas.py` so that the existing installed csdl and json symlinks are to be kept and also to be updated with the matching json schema version when DMTF schema version is upgraded. This commit also uses the symlinks to the closed relative paths like - `../schema/dmtf/installed/<schema>.xml -> ../csdl/<schema>.xml` - `../schema/dmtf/json-schema-installed/<json-file>.json -> ../json-schema/<json-file>.json` Tested: - Change VERSION in `update_schemas.py` and verify the generated files - CI passes - Redfish Service Validator passes Change-Id: Ib7fede7e4c39bdfc13da227eb1e737d96b6c2b5e Signed-off-by: Myung Bae <myungbae@us.ibm.com>
2025-06-17Update to 2025.2Gunnar Mills1-1/+1
1 line change in update_schemas.py and rerun it. See below for more info on this release [1] Tested: Inspection only. These have not broke things in the past. [1]: https://www.dmtf.org/sites/default/files/Redfish_Release_2025.2_Overview.pdf Change-Id: I641bc4285fa502a5d81318ff56eaeb75c0af4762 Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
2025-06-06Make PropertyNotWritable 405Gunnar Mills1-1/+1
forbidden (403) - "a 403 error means there is an authorization / permission problem." 405 "Method Not Allowed" error means that the web server understands the request but refuses to process it because the HTTP method (like GET, POST, PUT, etc.) used in the request is not supported by the server or the resource.". Following a stackoverflow response here [1]. Dell mapped PropertyNotWritable to a 400 error. [2] A 400 would be my 2nd choice. [1]: https://stackoverflow.com/questions/52892076/http-code-to-return-for-unsupported-patch [2]: https://www.dell.com/support/manuals/en-in/idrac7-8-lifecycle-controller-v2.30.30.30/redfish_v2.30.30.30/managernetworkprotocol?guid=guid-b2be28b5-60a5-4782-83ac-3efb3af79ef2&lang=en-us Change-Id: Iff3f773a1fdbea96d65f8b82fec75cfc34519ae0 Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
2025-05-27Make registries return an object_tEd Tanous1-2/+2
All the registry helper functions should return an object_t, given that they're guaranteed to return an object. nlohmann::json as a type can technically be string/int/bool/null/object/array, so it causes some peculiarities in parsing. Change-Id: If296477cb8d066d7f44ef0d12f17d94a5301e450 Signed-off-by: Ed Tanous <ed@tanous.net>
2025-05-20registries: make registration dynamicPatrick Williams1-13/+29
Rather than having to manually hook code for registries, add a small registration function to the registry header and use this registration results throughout the registry interactions. Tested: Confirmed registries have same behavior. ``` $ curl -s -k https://localhost:18080/redfish/v1/Registries/ | jq '.Members | map(."@odata.id")' [ "/redfish/v1/Registries/Base", "/redfish/v1/Registries/HeartbeatEvent", "/redfish/v1/Registries/OpenBMC", "/redfish/v1/Registries/ResourceEvent", "/redfish/v1/Registries/TaskEvent", "/redfish/v1/Registries/Telemetry" ] ``` ``` $ curl -s -k https://localhost:18080/redfish/v1/Registries/TaskEvent/TaskEvent | jq ".Messages | keys" [ "TaskAborted", "TaskCancelled", "TaskCompletedOK", "TaskCompletedWarning", "TaskPaused", "TaskProgressChanged", "TaskRemoved", "TaskResumed", "TaskStarted" ] ``` Signed-off-by: Patrick Williams <patrick@stwcx.xyz> Change-Id: Iaa355420736a2587d9da4e995208d579443ca9b8
2025-05-20Make Registry description optionalIgor Kanyuka1-1/+3
Currently, parse_registries.py assumes the description property exists in every registry json it parses. However, according to the spec [1] it is not a required property, so it may not exist, see [2]. Switch it to optional and use an empty string as a default value. Testing: Ran the script and made sure the generated files remain unchanged. [1] https://redfish.dmtf.org/schemas/v1/MessageRegistry.v1_4_0.json [2] Run: `curl https://redfish.dmtf.org/schemas/v1/MessageRegistry.v1_4_0.json | jq .definitions.MessageRegistry.required` Change-Id: I3e9ba84bbdb9ba5e6ed8b00cde48c15a1b5abba6 Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
2025-05-14replace_logs: remove scripts per timeframePatrick Williams1-100/+0
The script has previously stated: > This script will be removed Q2 2024 As such, delete it. Signed-off-by: Patrick Williams <patrick@stwcx.xyz> Change-Id: Idb35ee22e605bd0a8f456a2eca56904936d791d2
2025-04-21Add TypeDefinition support for enumeration generationChandramohan Harkude1-2/+22
TypeDefinition was not supported by generate_schema_enums.py, this change is to support the 'TypeDefinition' generation from schema. Tested: 'TypeDefinition' fields in schema can be generated in generated files with the change Change-Id: Ibe61f65b905f2089f9e17a26fbd27e3ff1753166 Signed-off-by: Chandramohan Harkude <chandramohan.harkude@gmail.com>
2025-04-20Add support for intermediate certificate chains in mTLS authBen Peled1-9/+118
When using the --use-intermediate flag, the script generates: 1. Root CA Certificate: - Self-signed certificate (CA-cert.cer) - Used as the root of trust - Signs the intermediate certificates 2. Separate intermediate CAs for client and server: - Client intermediate: client-intermediate-cert.cer - Server intermediate: server-intermediate-cert.cer - Each signed by the root CA 3. End-entity certificates with their respective intermediate chains: - Client certificate chain: client-cert.pem (includes intermediate) - Server certificate chain: server-cert.pem (includes intermediate) Change-Id: Ifdfd1c044d1c8745638e44debfc90cad3b5aedb7 Signed-off-by: Ben Peled <bpeled@nvidia.com>
2025-04-10Return forbidden return code for RestrictedRole operationsMyung Bae1-0/+1
This fixes the http error code of the operations of the restricted role which currently result in bad_request (400) instead of forbidden (403). Tested: ``` $ redfishtool -r ${bmc}:18080 -u ${user} -p ${pass} -S Always raw POST /redfish/v1/AccountService/Accounts -d '{"UserName":"service","Password":"newPwd1","RoleId":"Operator"}' redfishtool: Transport: Response Error: status_code: 403 -- Forbidden--user not authorized to perform action redfishtool: raw: Error sending POST to resource, aborting $ redfishtool -r ${bmc}:18080 -u ${user} -p ${pass} -S Always raw PATCH /redfish/v1/AccountService/Accounts/${user} -d '{"Password":"NewTestPwd123"}' redfishtool: Transport: Response Error: status_code: 403 -- Forbidden--user not authorized to perform action $ redfishtool -r ${bmc}:18080 -u ${user} -p ${pass} -S Always raw PATCH /redfish/v1/AccountService/Accounts/${user} -d '{"UserName":"new-service"}' redfishtool: Transport: Response Error: status_code: 403 -- Forbidden--user not authorized to perform action $ redfishtool -r ${bmc}:18080 -u ${user} -p ${pass} -S Always raw PATCH /redfish/v1/AccountService/Accounts/${user} -d '{"RoleId":"Operator"}' redfishtool: Transport: Response Error: status_code: 403 -- Forbidden--user not authorized to perform action $ redfishtool -r ${bmc}:18080 -u ${user} -p ${pass} -S Always raw DELETE /redfish/v1/AccountService/Accounts/${user} redfishtool: Transport: Response Error: status_code: 403 -- Forbidden--user not authorized to perform action redfishtool: raw: Error sending DELETE to resource, aborting ``` Change-Id: I1b212ccb5a630750eb5d4197970b4fb75fceffd7 Signed-off-by: Myung Bae <myungbae@us.ibm.com>
2025-04-10Sort get_response_code namesMyung Bae1-28/+28
It is better to sort get_response_code names in parse_registries.py. Tested: - Script run generates the same output Change-Id: I79028c8f95c4cf6681bc4f5b12dd858188e9eff8 Signed-off-by: Myung Bae <myungbae@us.ibm.com>
2025-03-27Update to 2025.1Gunnar Mills1-1/+1
1 line change in update_schemas.py and rerun it. See below for more info on this release: https://www.dmtf.org/content/redfish-release-20251-now-available Tested: Inspection only. These have not broke things in the past. Change-Id: I8d386725b364e2bc7c91c869e519e5e7bfbf11f9 Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
2025-03-18extend test script to cover upn testingMalik Akbar Hashemi Rafsanjani1-21/+152
This commit is intended to extend existing `generate_auth_certificate` python script that automatically test the auth functionality of bmcweb. We extend the script by adding test for UserPrincipalName (UPN) feature. This feature[1] allow us to use SubjectAlternativeName (SAN) extension on X509 certificate and enable us to use the different name as username. Previously we can only use CommonName in the certificate as username By adding this changes, we can test the UPN feature easily using the script. We add a new flag that enable the user to test using UPN feature by specifying the UPN name to be tested. UPN has OID that is specified by Microsoft[2]. The full OID path: 1 ISO 1.3 identified-organization (ISO/IEC 6523), 1.3.6 DoD, 1.3.6.1 internet, 1.3.6.1.4 private, 1.3.6.1.4.1 enterprise, 1.3.6.1.4.1.311 Microsoft, 1.3.6.1.4.1.311.20 Microsoft enrollment infrastructure, 1.3.6.1.4.1.311.20.2 Certificate Type Extension, 1.3.6.1.4.1.311.20.2.3 UserPrincipalName Tested: - Regress test on CommonName by running without `--upn` flag - Test using correct UPN name - There are two requirements for the UPN name (`username@domain`) - `username` must exist in the BMC device accounts - `domain` must match the domain forest of the device - eg: malik@fb.com match macbmc1.abc.fb.com - Test using incorrect UPN name - Violate one of the requirements and the test should fail [1] Patch feature: https://gerrit.openbmc.org/c/openbmc/bmcweb/+/78519 [2] OID of UPN: https://oidref.com/1.3.6.1.4.1.311.20.2.3 Change-Id: I997bea9a6662fa41c3824fde71ea4f20b606ca9c Signed-off-by: Malik Akbar Hashemi Rafsanjani <malikrafsan@meta.com>
2025-02-27Added type hints to parse_registries.pyIgor Kanyuka1-40/+60
Added type hints to reduce possibility of mistakes caused by using wrong types and make changes safer/faster to make. Fixed bugs related to types in the script. Testing: Ran the script, made sure it did not change anything in the repo (i.e. produces the same results as before). Change-Id: Ia7be551705a9eeabb2dd762bf709b113f8f1405b Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
2025-02-27Update Environmental registry version to 1.1.0Igor Kanyuka1-1/+1
New version includes Leak related messages we need. Testing: Redfish service validator passing Change-Id: Ieca3e5a7bb785ef7fcffb05f86b88bdbf23a3d99 Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
2025-02-27Refactor parse_registries.pyIgor Kanyuka1-24/+16
Minor refactoring: - Change global scope variable names to capital letters - get_response_code method to make it more readable and pythonic. - Now, already processed data is stored in 2 variables - registries_map and files, use only 1 storage to avoid errors caused by missing some entries in one storage, but presenting in another. Testing: Ran the script and made sure the files it generated did not change. Change-Id: Ida35adcd3530dbd87040a12de4903eda5f1f93f7 Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
2025-02-18Fix generate auth certificates scriptEd Tanous1-313/+414
pyCrypto has removed support for the PKCS12 certificates this script generates, so this script is broken as-is on any distro from the last year or two. Rewrite the script to target python-cryptography instead. While there, implement TODOs around code formatting, using EC keys, removing the dependency on the redfish library, using the service root to determine the correct manager instance to update, and cleaning up the redfish session after a crash. Tested: running this script targeting redfish instance shows it runs to completion and test passes. Change-Id: Ie1ee1a6f0a548258fe7b7d4c9678a9d55c8b71d1 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-02-12Fix websocket test scriptEd Tanous1-1/+1
Unclear when or why this changed in python, but doesn't really matter. Fix the script. Tested: Script now succeeds with rest option enabled. Change-Id: I3e548aad03c6150f404d5fddc742f8baa5274a83 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-01-31Ignore header failures on registriesEd Tanous1-3/+5
The generated registries have an imperfect handling of #include dependencies. Update the script to ignore the misc-include-cleaner recommendations for now. Future fixes could be done to make these generated headers actually correctly include their dependencies, but that is non trivial to do, and the build is broken. Change-Id: I32c70e9f865ca7ef693c736a45b3ea59513a751d Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-01-22Update to 2024.4Myung Bae1-1/+1
Update schema to the latest release 2024.4. See below for more info on this release: https://www.dmtf.org/standards/redfish Tested: - Redfish Service Validator passes Change-Id: I1845d6afa04ee418ba3ab0bd0bc8ce59886e4376 Signed-off-by: Myung Bae <myungbae@us.ibm.com>
2025-01-22Roll out error message utilsEd Tanous1-129/+1
This code should really be in a cpp/hpp file, not in a generated python script. The python script housed this temporarily to allow us to generate the registries. It's time to roll it out. Tested: Message registries generate successfully on GET. Redfish service validator passes. Change-Id: I7aca2d0a7fac6d530511421b667ff732617df61e Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-01-20Use SPDX identifiersEd Tanous3-7/+15
SPDX identifiers are simpler, and reduce the amount of cruft we have in code files. They are recommended by linux foundation, and therefore we should do as they allow. This patchset does not intend to modify any intent on any existing copyrights or licenses, only to standardize their inclusion. [1] https://www.linuxfoundation.org/blog/blog/copyright-notices-in-open-source-software-projects Change-Id: I935c7c0156caa78fc368c929cebd0f068031e830 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-01-03Reformat pythonEd Tanous1-23/+32
Apply black formatter to code. Change-Id: I4a3d8426b03eeb8d71230f24788ac8caeb3618c3 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-01-03Fix out of range error when input non default registriesTam Nguyen1-24/+31
The parse_registries.py generates base, heartbeat, resource and taskevent registries without checking input registries list. Which causes out of range error when input non default value. This commit only generates above registries if they are input. Tested: Input only openbmc registry passes. Input only heartbeat registry passes. Run with default registries passes. Change-Id: Ibb6e6ee9f241c424bb78782466eb3199b11332c3 Signed-off-by: Tam Nguyen <tamnguyenchi@os.amperecomputing.com>
2024-12-27Use raw content URLMilton D. Miller II1-1/+1
Replace the message registry URL with the official GitHub raw download URL to give the json content not a web SCM GUI. Change-Id: I0ac800ee3803c9bef3a6a799b20887df84c3c173 Signed-off-by: Milton Miller <mdmii@outlook.com>
2024-12-21Generate heartbeat registryEd Tanous1-3/+8
Generate the heartbeat registry, and adjust the #includes of the other generated registries. Tested: Redfish service validator succeeds. Change-Id: Iedbf1ae8dc6559666691f1feb71af08e856d5c80 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-12-21Generate resource eventEd Tanous1-41/+28
Generate Resource event registry Tested: On last patch of series. No behavior changes. Change-Id: I924919db0e7fbde8ed698de6b59b86f788de9708 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-12-21Generate task eventEd Tanous1-106/+167
Generate the task event registry. Tested: on last patch of series Change-Id: I55b7914978f7a1d637cad6dfae398949af0a7107 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-12-16Fix URI warning in RSVEd Tanous1-1/+1
Redfish service valitator warns: WARNING - PublicationUri: Empty string found - Services should omit properties if not supported This commit adds to our registry the url to the openbmc registry file. Tested: Redfish Service validator no longer returns a warning. Change-Id: Ia54be175490b4e7e00e3c0c4ab8c60dce1b96863 Signed-off-by: Ed Tanous <etanous@nvidia.com>