| Age | Commit message (Collapse) | Author | Files | Lines |
|
Add coverage for dbusToRfBootType() and dbusToRfBootMode(), which
translate D-Bus boot configuration values into Redfish enum values.
Verify the supported boot type values Legacy and EFI map to
BootSourceOverrideMode::Legacy and BootSourceOverrideMode::UEFI. Verify
the supported boot mode values Regular, Safe, and Setup map to
BootSource::None, BootSource::Diags, and BootSource::BiosSetup.
Also verify that unknown D-Bus values return the corresponding Invalid
enum value instead of being silently interpreted as a valid setting.
Tested:
- meson test -C builddir system_test -v
- All 6 system_test tests passed, including both new tests
Change-Id: I926187c3e87abc4baf2af22a6ca6f689c03dcd77
Signed-off-by: Vinothkumar Shanmugavel <vinothkumars@ami.com>
|
|
Similar to how other log services got broken out into own header files,
do the same for dump / faultlog.
A new dump utility header has been created, request handler and route
register function went into manager / systems log service header files
respectively.
Code logic stays untouched in this patch.
Tested: Code compiles. Unit test runs through.
Validator was run on romulus in qemu with phosphor-debug-collector ibm
extension enabled to get access to /xyz/openbmc_project/dump/system.
Via the 'CreateDump' method empty dump entries were manually created
for:
/xyz/openbmc_project/dump/system
/xyz/openbmc_project/dump/bmc
/xyz/openbmc_project/dump/faultlog
```
busctl call xyz.openbmc_project.Dump.Manager \
/xyz/openbmc_project/dump/bmc \
xyz.openbmc_project.Dump.Create \
CreateDump a{sv} 0
> o "/xyz/openbmc_project/dump/bmc/entry/1"
busctl tree xyz.openbmc_project.Dump.Manager
`- /xyz
`- /xyz/openbmc_project
`- /xyz/openbmc_project/dump
|- /xyz/openbmc_project/dump/bmc
| `- /xyz/openbmc_project/dump/bmc/entry
| |- /xyz/openbmc_project/dump/bmc/entry/1
| |- /xyz/openbmc_project/dump/bmc/entry/2
| |- /xyz/openbmc_project/dump/bmc/entry/3
| |- /xyz/openbmc_project/dump/bmc/entry/4
| |- /xyz/openbmc_project/dump/bmc/entry/5
| `- /xyz/openbmc_project/dump/bmc/entry/6
|- /xyz/openbmc_project/dump/faultlog
| `- /xyz/openbmc_project/dump/faultlog/entry
| `- /xyz/openbmc_project/dump/faultlog/entry/1
|- /xyz/openbmc_project/dump/resource
`- /xyz/openbmc_project/dump/system
`- /xyz/openbmc_project/dump/system/entry
`- /xyz/openbmc_project/dump/system/entry/1
```
Overwrite OperationStatus of /xyz/openbmc_project/dump/system/entry/1
for the entry to be added to the collection:
```
busctl set-property xyz.openbmc_project.Dump.Manager \
/xyz/openbmc_project/dump/system/entry/1 \
xyz.openbmc_project.Common.Progress Status \
s xyz.openbmc_project.Common.Progress.OperationStatus.Completed \
```
Systems/Dump
Validating /redfish/v1/Systems/system/LogServices/Dump...
- Pass: 14, Warn: 0, Fail: 0, Skip: 9
Validating /redfish/v1/Systems/system/LogServices/Dump/Entries...
- Pass: 17, Warn: 0, Fail: 0, Skip: 30
Validating /redfish/v1/Systems/system/LogServices/Dump/Entries/1...
- Pass: 10, Warn: 0, Fail: 0, Skip: 26
+--------------+--------------+--------------+--------------+
| PASS | WARN | FAIL | NOT TESTED |
+--------------+--------------+--------------+--------------+
| 41 | 0 | 0 | 65 |
+--------------+--------------+--------------+--------------+
Managers/Dump
Validating /redfish/v1/Managers/bmc/LogServices/Dump...
- Pass: 14, Warn: 0, Fail: 0, Skip: 9
Validating /redfish/v1/Managers/bmc/LogServices/Dump/Entries...
- Pass: 70, Warn: 0, Fail: 0, Skip: 162
Validating /redfish/v1/Managers/bmc/LogServices/Dump/Entries/1...
- Pass: 11, Warn: 0, Fail: 0, Skip: 25
Validating /redfish/v1/Managers/bmc/LogServices/Dump/Entries/2...
- Pass: 11, Warn: 0, Fail: 0, Skip: 25
Validating /redfish/v1/Managers/bmc/LogServices/Dump/Entries/3...
- Pass: 9, Warn: 0, Fail: 0, Skip: 27
Validating /redfish/v1/Managers/bmc/LogServices/Dump/Entries/4...
- Pass: 9, Warn: 0, Fail: 0, Skip: 27
Validating /redfish/v1/Managers/bmc/LogServices/Dump/Entries/5...
- Pass: 9, Warn: 0, Fail: 0, Skip: 27
Validating /redfish/v1/Managers/bmc/LogServices/Dump/Entries/6...
- Pass: 9, Warn: 0, Fail: 0, Skip: 27
+--------------+--------------+--------------+--------------+
| PASS | WARN | FAIL | NOT TESTED |
+--------------+--------------+--------------+--------------+
| 142 | 0 | 0 | 329 |
+--------------+--------------+--------------+--------------+
Managers/FaultLog
Validating /redfish/v1/Managers/bmc/LogServices/FaultLog...
- Pass: 12, Warn: 0, Fail: 0, Skip: 9
Validating /redfish/v1/Managers/bmc/LogServices/FaultLog/Entries...
- Pass: 13, Warn: 0, Fail: 0, Skip: 34
Validating /redfish/v1/Managers/bmc/LogServices/FaultLog/Entries/1...
- Pass: 6, Warn: 0, Fail: 0, Skip: 30
+--------------+--------------+--------------+--------------+
| PASS | WARN | FAIL | NOT TESTED |
+--------------+--------------+--------------+--------------+
| 31 | 0 | 0 | 73 |
+--------------+--------------+--------------+--------------+
Change-Id: I6379f877149c545b3b3bfcda8510c6ee1085dcf9
Signed-off-by: Oliver Brewka <oliver.brewka@9elements.com>
|
|
Cover dbusToRfPowerState() and the callbacks introduced by the Fabric
Switch PowerState change: afterGetSwitchPowerState and
afterGetSwitchPowerStateService. The tests assert each branch's
externally visible behavior: known PowerState decorator values map to
the matching resource::PowerState and unmapped values yield nullopt; a
property read error or an unmapped value leaves PowerState omitted
without failing the request; EBADR, io_error and an empty mapper
object leave PowerState omitted; any other mapper error sets an
internal server error.
Change-Id: Id488f88b8d7784a4f195fcf7c832fbecfdb0b513
Signed-off-by: JY Voon <jvoon@nvidia.com>
|
|
Add optional support for UUID property for PCIeDevice.
Tested: Build an image for nvl32-obmc machine with the following patch
cherry picked.
```
1. Align with upstream u-boot dts tree:
https://gerrit.openbmc.org/c/openbmc/openbmc/+/89932
2. mctpd configuration:
https://gerrit.openbmc.org/c/openbmc/openbmc/+/87390
3. Enable nvidia-gpu sensor:
https://gerrit.openbmc.org/c/openbmc/openbmc/+/89933
```
PCIeDevice with Common.UUID published (GPU path):
$ busctl get-property xyz.openbmc_project.GpuSensor \
/xyz/openbmc_project/inventory/Nvidia_GPU_10 \
xyz.openbmc_project.Common.UUID UUID
s "68174e99-daf4-02d1-ba39-4ed2bf8a0f21"
$ curl -sk https://{BMC_IP}/redfish/v1/Systems/system/\
PCIeDevices/Nvidia_GPU_10
{
"@odata.id": "/redfish/v1/Systems/system/PCIeDevices/Nvidia_GPU_10",
"@odata.type": "#PCIeDevice.v1_19_0.PCIeDevice",
"Id": "Nvidia_GPU_10",
"Manufacturer": "NVIDIA",
"Model": "RTXPRO6000BlackwellDC",
"Name": "PCIe Device",
"PartNumber": "900-2G153-0000-000",
"SerialNumber": "1792425045093",
"Status": {
"Health": "OK",
"State": "Enabled"
},
"UUID": "68174e99-daf4-02d1-ba39-4ed2bf8a0f21"
}
PCIeDevice without Common.UUID published (ConnectX path):
$ busctl get-property xyz.openbmc_project.GpuSensor \
/xyz/openbmc_project/inventory/Nvidia_ConnectX_24_PCIe \
xyz.openbmc_project.Common.UUID UUID
Failed to get property UUID on interface
xyz.openbmc_project.Common.UUID: Unknown interface
xyz.openbmc_project.Common.UUID or property UUID.
$ curl -sk https://{BMC_IP}/redfish/v1/Systems/system/\
PCIeDevices/Nvidia_ConnectX_24_PCIe | jq 'has("UUID")'
false
Change-Id: I38cf972f03f0dd0299b708ea8203872c73c8e224
Signed-off-by: JY Voon <jvoon@nvidia.com>
|
|
Add unit tests for the security header helper.
Cover headers that are always added, preserve existing Cache-Control
values, and verify the HTML-only header path.
Also validate representative Content-Security-Policy and
Permissions-Policy values so future header regressions are caught by
unit test coverage.
Tested:
Passed local CI docker run for bmcweb unit tests
Change-Id: I069d203f6bc35155d17d8488ab5511aa38218f3a
Signed-off-by: Joel P J <joelpj@ami.com>
|
|
- State `Available` will be mapped to `UnavailableOffline` for
Status.State for resources that are present but unavailable
- Added a utility function to reduce code duplication for retrieving
resource's Status.State (`getResourceState`) and Status.Health
(`getResourceHealth`)
Tested:
- Compiles and builds
- Unit tests pass
Change-Id: I1164a9412cbd4e1ab8938366ffc7ea9c7fe58786
Signed-off-by: Justin Nguyen <justinnanguyen@gmail.com>
|
|
Recently, oss-fuzz added support for bmcweb, but did it by checking in
a number of code patches. This commit should get similar coverage by
hooking into the HTTP connection class, and using the unit test
code to inject bytes directly into a stream. This can be improved over
time, but this is a good start.
Change-Id: I20b5d536cff1588a8387f2770c022516e1cd62d0
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
IWYU is not a tool we have seen results from in some time. I very much
suspect that these few comments are not enough to get a clean build.
Clean them up. If we want to turn this tool back on in the future,
this patch can be reverted.
Tested: Comment only change. Review only.
Change-Id: I45ff737800f9d8b1b63db2f482e59f815d7126a2
Signed-off-by: Ed Tanous <ed@tanous.net>
|
|
The xyz.openbmc_project.Software.Version interface marks the Purpose
property as deprecated in favor of Compatible strings and inventory
associations, so a conforming object may publish only Version. The
FirmwareInventory handler treated a missing Purpose as an internal
error and returned HTTP 500 for every such object. Added this patch\
to skip the optional Description and RelatedItem links rather
than failing the resource. Objects that publish Purpose keep their
existing output.
Tested: Build an image for nvl32-obmc machine with the following
patches cherry-picked:
1. Align with upstream u-boot dts tree:
https://gerrit.openbmc.org/c/openbmc/openbmc/+/89932
2. mctpd configuration:
https://gerrit.openbmc.org/c/openbmc/openbmc/+/87390
3. Enable nvidia-gpu sensor:
https://gerrit.openbmc.org/c/openbmc/openbmc/+/89933
4. dbus-sensors expose GPU inventory interfaces:
https://gerrit.openbmc.org/c/openbmc/dbus-sensors/+/88990
$ curl -sk https://{BMC_IP}/redfish/v1/UpdateService/\
FirmwareInventory/Nvidia_GPU_10_Firmware
{
"@odata.id":
"/redfish/v1/UpdateService/FirmwareInventory/\
Nvidia_GPU_10_Firmware",
"@odata.type": "#SoftwareInventory.v1_1_0.SoftwareInventory",
"Id": "Nvidia_GPU_10_Firmware",
"Name": "Software Inventory",
"Status": {
"HealthRollup": "OK",
"State": "Enabled"
},
"Updateable": false,
"Version": "98.02.AF.00.01"
}
Depends-On: Id0c09f4ced40dbe505ca7cbd99f6de0e847afe3b
Change-Id: I2a9562e461ffd39fcbdc176413a1bf2cb6fdbc22
Signed-off-by: JY Voon <jvoon@nvidia.com>
|
|
Cover the callbacks introduced by the GPU Processor FirmwareVersion
change. The tests assert each branch's externally visible behavior:
unexpected D-Bus errors, an ambiguous subtree, and a missing owning
service set an internal server error, while EBADR, an empty subtree,
and an empty version leave FirmwareVersion omitted.
Change-Id: Ic00549fe7513651a139ebb8a4e7b36c95b3f453c
Signed-off-by: JY Voon <jvoon@nvidia.com>
|
|
Add Response::headerCount() to return the total number of
stored header fields on a response. The implementation counts
the current header entries directly from the underlying Beast
header container.
Added unit coverage to verify the method reports the full
header count after headers are added through the normal
addHeader() path.
Tested with:
meson test -C build http_response_test --print-errorlogs
This helper is used by response unit tests to verify that only
the expected headers are present and that no unexpected headers
are added to the response. See also:
https://gerrit.openbmc.org/c/openbmc/bmcweb/+/91848
Change-Id: I28432bb4fc982db44cee0688395d04ac513d6749
Signed-off-by: Joel Pullokaran Jesin <joelpj@ami.com>
|
|
Use http_helpers::getContentType() when deciding whether to add
HTML-only security headers.
Previously this logic checked the raw Content-Type header with a
text/html prefix match. That worked for the values we emit today,
but it open-coded Content-Type handling in this path instead of using
the existing parser.
Switch this logic to getContentType() so it stays consistent with
the rest of the code and correctly handles valid variations such as
case-insensitive HTML MIME types.
Add unit coverage for getContentType() to verify HTML MIME types
with charset parameters and case-insensitive input.
Tested: unit tests passed.
Change-Id: I1cff40453ab4851cc7b24615a20fb6abcfba864b
Signed-off-by: Joel Pullokaran Jesin <joelpj@ami.com>
|
|
parseStringAsJson() routes through BmcwebSaxParse, which hard-caps a
payload at 500 total JSON values to defend against malicious external
HTTP request bodies.
The most visible symptom is that bmcweb silently loses every persisted
session across a restart once ~50 sessions accumulate (each persisted
session is ~11 JSON values, so the file trips the cap and is treated
as malformed). Tntegration testing hit this 50 session limit and
failed. (Was failing our internal but also the
openbmc-test-automation robot suite)
I had originally implemented a solution as a "trusted reader"
with no limit
( https://gerrit.openbmc.org/c/openbmc/bmcweb/+/90138 ); however,
the security implications of "no limit" weren't attractive.
This area may be refactored in the near future to represent each
session as a distinct json file. This value bump gets us past
the immediate needs without introducing a lot of churn in code
that will be refactored.
Change-Id: Ifd3514bd8ee15c8bdf1b6c2119451a2965801671
Signed-off-by: Rick Yazwinski <rickyaz@meta.com>
|
|
Long lambdas have been documented as an anti-pattern for some time.[1]
Despite this being generally understood, bmcweb has a long ways to go
cleaning these up, and routinely code is submitted in violation of this
anti-pattern.
Invent an ast-grep rule that can identify when new examples of this
anti-pattern are added, and ignore the existing 200+ examples that are
in the codebase already using ast-grep ignore. These flags will give us
something to search for as we clean this up, and will help to prevent
new instances from being added unintentionally.
[1] https://github.com/openbmc/docs/blob/master/anti-patterns.md#very-long-lambda-callbacks
Tested: Comment only change. ast-grep passes. Manually removing an
ast-grep ignore flag shows as a failure in ast-grep scan
Change-Id: I77d634a393884969f184d2c39c02cc08288d5a29
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
This change adds user password expiration date time mgmt via REST
API provided by bmcweb. Password expiration date time is managed as
string in 'YYYY-MM-DDTHH:MM:SS±hh:mm' format and internally operates as
Epoch time. When set password expiration date time can be specified in
any format supported by 'dateStringToEpoch' function in
'redfish::time_utils'. Value 'null' is used to make password not to
expire.
Unit tests checking correct password expiration value conversion were
added.
This change depends on corresponding change in phosphor-dbus-interfaces
[1] and in phospor-user-manager [2].
Password expiration management:
- create user with password expiration
```
curl -k -X POST -H 'Content-Type: application/json' \
"https://<bmc>/redfish/v1/AccountService/Accounts" \
-d '{"UserName":"<user>", "Password":"<password>", "RoleId":"<role>", "PasswordExpiration": "<YYYY-MM-DDTHH:MM:SS>"}'
```
- modify user password expiration
```
curl -k -X PATCH -H 'Content-Type: application/json' \
https://<bmc>/redfish/v1/AccountService/Accounts/<user> \
-d '{"PasswordExpiration": "<YYYY-MM-DDTHH:MM:SS>"}'
```
- get user password expiration
```
curl -k -X GET https://<bmc>/redfish/v1/AccountService/Accounts/<user>
```
- modify user password not to expire
```
curl -k -X PATCH -H 'Content-Type: application/json' \
https://<bmc>/redfish/v1/AccountService/Accounts/<user> \
-d '{"PasswordExpiration": null}'
```
Tested:
Functionality of this change was tested via curl utility. Also, it was
checked that proper value was set on dbus for'PasswordExpiration'
attribute of the specified user.
- create user account without password expiration, verify that password
expiration is not set
- create user account with password expiration specified, verify that it
is correct
- create user account with null password expiration which makes password
not to expire, verify that it is correct
- try to create user account with various invalid password expiration
values(incorrect type, invalid format), verify that user is not
created and appropriate error is returned in response
- modify user password expiration to specific time, verify that is is
correct
- make user password not to expiry, verify that it is correct
- try to set password expiration to an invalid value (incorrect type,
invalid format), verify that is does not change and appropriate error
is returned in response
Redfish service validation on /redfish/v1/AccountService/Accounts tree
containing both user accounts with and without password expiration has
passed successfully.
[1] https://gerrit.openbmc.org/c/openbmc/phosphor-dbus-interfaces/+/75236
[2] https://gerrit.openbmc.org/c/openbmc/phosphor-user-manager/+/75237
Change-Id: Idf5e4356eaa8866dd4a10664996117e2cdba0684
Signed-off-by: Ivan Moiseev <moiseev.ivan4w@yandex.com>
Signed-off-by: Ivan Mikhaylov <fr0st61te@gmail.com>
|
|
`redfish-core/schema/oem/openbmc/` oem schema defines 'Chassis' property
for fan zones but the implementation forms invalid chassis links.
Affected options: redfish-oem-manager-fan-data=enabled (default)
Using following configuration, plus a few fans and pid controller
(a typical single-host 2U server with 3 fans, Tyan S8030 board)
```
{
"FailSafePercent": 100,
"MinThermalOutput": 10,
"Name": "Zone0",
"Type": "Pid.Zone"
},
```
It is straightforward to get a response like below
```
...
"FanZones": {
"@odata.id": "/redfish/v1/Managers/bmc#/Oem/OpenBmc/Fan/FanZones",
"@odata.type": "#OpenBMCManager.v1_0_0.Manager.FanZones",
"Zone0": {
"@odata.id": "/redfish/v1/Managers/bmc#/Oem/OpenBmc/Fan/FanZones/Zone0",
"@odata.type": "#OpenBMCManager.v1_0_0.Manager.FanZone",
"Chassis": {
"@odata.id": "/redfish/v1/Chassis/Zone0"
},
"FailSafePercent": 100.0,
"MinThermalOutput": 10.0
}
},
...
```
when querying
```
curl --insecure --user root:root https://${bmc}/redfish/v1/Managers/bmc#/Oem/OpenBmc/Fan
```
For reference, the chassis collection
```
{
"@odata.id": "/redfish/v1/Chassis",
"@odata.type": "#ChassisCollection.ChassisCollection",
"Members": [
{
"@odata.id": "/redfish/v1/Chassis/MBX_1_57_Chassis"
},
{
"@odata.id": "/redfish/v1/Chassis/Tyan_S8030_Baseboard"
}
],
"Members@odata.count": 2,
"Name": "Chassis Collection"
}
```
Since that configuration is representative of various boards and the bug
has been seen by others before [1] (in terms of a fan zone and chassis
sharing the same name, suggesting ill-formed link), fix the
implementation to use the result of GetManagedObjects call and find
valid chassis path there.
This is to allow redfish validator to pass with default meson options
and a common system configuration. Since it's a config dependent failure
it would be great for others to test and share their result.
Inspection of the code causing validation failure:
```
auto pids = std::make_shared<GetPIDValues>(asyncResp);
pids->run();
then run(); returns and `~GetPIDValues()` is called
which calls processingComplete
which calls asyncPopulatePid
```
Inside `asyncPopulatePid` it does `dbus::utility::getManagedObjects`
and iterates over the results
```
112 for (const auto& pathPair : managedObj)
113 {
114 for (const auto& intfPair : pathPair.second)
```
then checks for an interface
```
180 if (intfPair.first == pidZoneConfigurationIface)
181 {
182 sdbusplus::message::object_path pidPath(
183 pathPair.first.str);
184 std::string chassis = pidPath.filename();
185 if (chassis.empty())
186 {
187 chassis = "#IllegalValue";
188 }
```
and simply uses the object path from PID Zone config interface to
extract the leaf and insert that as the chassis link.
It can only work in case the Board/Chassis interface is on the same
object path which is unlikely.
Tested: on Tyan S8030.
Result after the change, the optional property now contains the correct
chassis link.
```
...
"FanZones": {
"@odata.id": "/redfish/v1/Managers/bmc#/Oem/OpenBmc/Fan/FanZones",
"@odata.type": "#OpenBMCManager.v1_0_0.Manager.FanZones",
"Zone0": {
"@odata.id": "/redfish/v1/Managers/bmc#/Oem/OpenBmc/Fan/FanZones/Zone0",
"@odata.type": "#OpenBMCManager.v1_0_0.Manager.FanZone",
"Chassis": {
"@odata.id": "/redfish/v1/Chassis/MBX_1_57_Chassis"
},
"FailSafePercent": 100.0,
"MinThermalOutput": 10.0
}
},
...
```
```
/tmp/rsv-venv/bin/rf_service_validator \
--auth Session -i https://${bmc}:443 \
-u ${username} -p ${password} --payload 'Tree' /redfish/v1/Managers/bmc
...
Elapsed time: 0:00:32
Listing any warnings and errors:
Results Summary:
Pass: 766, Fail: 0, Warning: 0
Validation has succeeded.
```
RF validator Tree validation errors are reduced compared to previous.
References:
[1] https://discordapp.com/channels/775381525260664832/1449737223493910559/1450273124804333598
Change-Id: I2a2db456f42c5dafa451f69362b1d9c8a094e86e
Signed-off-by: Alexander Hansen <alexander.hansen@9elements.com>
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Some of messages are not currently reported as errors, although they
are the results as Redfish request errors. Those include
- PropertyDuplicate
- ResourceAlreadyExists
- CreateFailedMissingReqProperties
- PropertyValueFormatError
- PropertyValueNotInList
- PropertyValueTypeError
- PropertyValueError
- PropertyNotWritable
- PropertyValueModified
- PropertyMissing
For example, PropertyValueFormatError is currently not treated as an
error. It shows like
```
curl -k -X PATCH "${bmc}/redfish/v1/AccountService/Accounts/admin" \
-H "Content-Type: application/json" \
-d '{ "Password": "" }'
"Password@Message.ExtendedInfo": [
{
"@odata.type": "#Message.v1_1_1.Message",
"Message": "The value 'null' for the property Password is not a format that the property can accept.",
"MessageArgs": [
"null",
"Password"
],
"MessageId": "Base.1.19.PropertyValueFormatError",
"MessageSeverity": "Warning",
"Resolution": "Correct the value for the property in the request body and resubmit the request if the operation failed."
}
]
```
After making it as an error, it will be like
```
{
"error": {
"@Message.ExtendedInfo": [
{
"@odata.type": "#Message.v1_1_1.Message",
"Message": "The value 'null' for the property Password is not a format that the property can accept.",
"MessageArgs": [
"null",
"Password"
],
"MessageId": "Base.1.19.PropertyValueFormatError",
"MessageSeverity": "Warning",
"Resolution": "Correct the value for the property in the request body and resubmit the request if the operation failed."
}
],
"code": "Base.1.19.PropertyValueFormatError",
"message": "The value 'null' for the property Password is not a format that the property can accept."
}
}
```
Tested:
- Check those response messages
Change-Id: I746c55e42e8f0cde205a3800e3da17cd78cf7e34
Signed-off-by: Myung Bae <myungbae@us.ibm.com>
|
|
Add test case for handleTelemetryServiceGet function to verify the
static attributes returned by the TelemetryService endpoint
The test validates the following response fields:
- @odata.type and @odata.id
- Id and Name
- Navigation properties: MetricReportDefinitions, MetricReports and
Triggers
Tested
- All assertions passed
Change-Id: Ibc71ad9ff1796b90fed19d25be1525204919fa04
Signed-off-by: Ramya Sivakumar <sramya@ami.com>
|
|
The comment from 'getEventLogParams()' says:
The redfish log format is "<Timestamp> <MessageId>,<MessageArgs>"
And in the OpenBMC main tree, the 'rsyslog.conf' from vendor defines:
# Template for Redfish messages
# "<timestamp> <MessageId>,<MessageArgs>"
template(name="RedfishTemplate" type="list") {
property(name="timereported" dateFormat="rfc3339")
constant(value=" ")
property(name="$!REDFISH_MESSAGE_ID")
constant(value=",")
property(name="$!REDFISH_MESSAGE_ARGS")
constant(value="\n")
}
# If the journal entry has a Redfish MessageId, save as a Redfish
# event
if ($!REDFISH_MESSAGE_ID != "") then {
action(type="omfile"
file="/var/log/redfish"
template="RedfishTemplate")
}
The commit aa2dfd26a514 ("Remove static variables") removed extraction
of timestamp data from the whole event log entry, 'dateStringToEpoch()'
will reject this kind of timestamp with trailing text.
Fixes: aa2dfd26a514 ("Remove static variables")
Change-Id: Id59af476e56a913a02a9f56a8c5f38c4ada7ccbf
Signed-off-by: Haiyue Wang <haiyuewa@163.com>
|
|
The aggregator forwards every method (GET, POST, PATCH, DELETE) to a
singular satellite resource, as described in the "Aggregating a
Resource" section of docs/AGGREGATION.md. createNewRequest() builds
the request that is forwarded, so it must preserve the original
method, target, and body -- otherwise Actions (e.g.
ComputerSystem.Reset) and PATCH updates would not reach the owning
satellite intact. It must also drop the client's X-Auth-Token while
keeping Host/Content-Type and setting Accept.
createNewRequest() had no unit-test coverage. Add tests that pin down
this contract:
- a non-GET (POST) request preserves method, target, and body
- a PATCH request preserves its body
- the client X-Auth-Token is filtered out while Host and
Content-Type are forwarded and Accept is set
No functional change.
Tested: clean build + full unit-test suite pass in the official
openbmc/ubuntu-unit-test container; the createNewRequest tests added
here pass (3/3).
Signed-off-by: Gary Beihl <garybeihl@microsoft.com>
Change-Id: If82cffe0f47523fc05af8e36892629e273ba865e
|
|
Extend the OpenBMCManager OEM fan configuration to cover the two
additional PID parameters already supported by phosphor-pid-control:
* DCoefficient (derivative term of the PID loop)
* CheckHysteresisWithSetpoint (boolean indicating whether input
hysteresis is applied around the setpoint)
These fields are now exposed through the Oem/OpenBmc/Fan/PidControllers
Redfish interface and correctly mapped to the underlying D-Bus
PidConfiguration objects.
To keep the OEM schema backwards compatible, introduce a new
version OpenBMCManager.v1_1_0 that adds the two properties to the
PidController definition, and update bmcweb to reference the new
schema version.
Test(qemu evb-ast2600):
Load Fantable via entity-manager
/var/configuration/system.json content:
https://github.com/YouPengWu/ToReviewer/blob/main/85785
/Test_case/Bmcweb(my_commit)/system.txt
Verify OEM properties in Manager resource
GET /redfish/v1/Managers/bmc:
https://github.com/YouPengWu/ToReviewer/blob/main/85785
/Test_case/Bmcweb(my_commit)/Managers-bmc-oem.png
Verify OpenBMCManager OEM schema exposure
GET /redfish/v1/JsonSchemas/OpenBMCManager:
https://github.com/YouPengWu/ToReviewer/blob/main/85785
/Test_case/Bmcweb(my_commit)/redfish-oem-schema.png
Run Redfish Service Validator (RSV)
Summary:
https://github.com/YouPengWu/ToReviewer/blob/main/85785
/Test_case/Bmcweb(my_commit)/redfish-validator-summary.png
Details:
https://github.com/YouPengWu/ToReviewer/blob/main/85785
/Test_case/Bmcweb(my_commit)/redfish-validator-details.png
Full log:
https://github.com/YouPengWu/ToReviewer/blob/main/85785
/Test_case/Bmcweb(my_commit)/ConformanceLog_12_14_2025_180449.txt
Baseline (community/original) RSV log
for comparison (no new failures introduced):
https://github.com/YouPengWu/ToReviewer/blob/main/85785
/Test_case/Bmcweb(57d41)/ConformanceLog_12_14_2025_174610.txt
Change-Id: Ide1a118f9fd27eb94e911997d99e5934fe3e1095
Signed-off-by: You Peng Wu <twpeng50606@gmail.com>
|
|
This lambda needs to go away. There's no way it should've been accepted
in the first place, but it was written in a different time.
Tested: Functional in next commit. Unit tests in patch.
Change-Id: I81360460c23329169f441b6bea02d28a8b410eca
Signed-off-by: Ed Tanous <ed@tanous.net>
|
|
HTTP/2 connections were not passing the resolved client IP into
the per-request ipAddress field, causing sessions to report
0.0.0.0 instead of the actual client address.
Additionally, authentication::authenticate() was called with an
empty IP, resulting in Basic Auth sessions being created with
an incorrect clientIp in the session store.
Pass the IP through the HTTP2Connection constructor, use it in
the authenticate() call, and assign it to req->ipAddress during
request dispatch in onRequestRecv.
Tested:
- Client IP correctly displayed in Redfish SessionService
on HTTP/2 connections.
- Before patch: ClientOriginIPAddress showed "0.0.0.0"
- After patch: ClientOriginIPAddress shows actual client IP
- Redfish Service Validator (v3.1.4) passed on
/redfish/v1/SessionService tree:
PASS: 44, WARN: 0, FAIL: 0, NOT TESTED: 41
Before:
curl -k https://127.0.0.1:2443/redfish/v1/\
SessionService/Sessions/O9gUpSoxbe -u root:0penBmc
{
"@odata.id": "/redfish/v1/SessionService/Sessions/O9gUpSoxbe",
"@odata.type": "#Session.v1_7_0.Session",
"ClientOriginIPAddress": "0.0.0.0",
"Description": "Manager User Session",
"Id": "O9gUpSoxbe",
"Name": "User Session",
"Roles": [
"Administrator"
],
"UserName": "root"
}
After this patch:
curl -k https://172.31.216.225/redfish/v1/\
SessionService/Sessions/LuttjprSGD -u root:0penBmc
{
"@odata.id": "/redfish/v1/SessionService/Sessions/LuttjprSGD",
"@odata.type": "#Session.v1_7_0.Session",
"ClientOriginIPAddress": "10.0.136.165",
"Description": "Manager User Session",
"Id": "LuttjprSGD",
"Name": "User Session",
"Roles": [
"Administrator"
],
"UserName": "root"
}
Change-Id: I223e5c90448419ba87b690de38cc5e69ffb6a0c3
Signed-off-by: Vijaysankar Ravi <vijaysankarr@ami.com>
|
|
Continue moving OpenSSL into reusable RAII classes that can be used in
unit tests and other places. This is slightly more code, but as we're
adding unit tests, it allows reuse between unit tests rather than
writing C directly. It also encapsulates the complexity of parsing
openssl output (usually in bytes) into standard types (string) that can
be compared/modified.
Functionally this adds two new classes to the "wrappers" functions,
OpenSSLSSLCtx and OpenSSLSSL, which each wrap SSL_CTX and SSL objects
respectively from openssl. These are rough approximations of the boost
equivalents.
Change-Id: Id87ac4ccde88890bd70861deffdb256188ec0e39
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Add ChargeAh ReadingType and Ah units mapping for
charge sensors exposed under /sensors/charge/ D-Bus
path. This enables battery backup unit remaining and
full charge sensors to appear in Redfish. Unit test
added for charge sensor type.
Tested:
1. Sensor Query using curl -
```
{
"@odata.id": "/redfish/v1/Chassis/BBU_SHELF_1/Sensors/charge_BBU_SHELF_1_BBU5_REMAINING_CHARGE_AH",
"@odata.type": "#Sensor.v1_11_1.Sensor",
"Id": "charge_BBU_SHELF_1_BBU5_REMAINING_CHARGE_AH",
"Name": "BBU SHELF 1 BBU5 REMAINING CHARGE AH",
"Reading": 10477.0,
"ReadingType": "ChargeAh",
"ReadingUnits": "Ah",
"Status": {
"Health": "OK",
"State": "Enabled"
},
...
}
```
2. Redfish Validation passed using Redfish Validator.
Signed-off-by: Jagpal Singh Gill <paligill@gmail.com>
Change-Id: I9b7180cb8597378a1b42f9da73335ca96b20d55a
|
|
Move the LocationCode D-Bus callback out of getCpuLocationCode() and
rename the request helper to getProcessorLocationCode(), because the
helper handles all processor inventory types and not only CPUs.
This is a no-functional-change cleanup. Processor GET responses continue
to expose Location/PartLocation/ServiceLabel from the existing
xyz.openbmc_project.Inventory.Decorator.LocationCode interface.
Redfish.md is unchanged because this refactor does not add or remove any
Redfish schema fields. No phosphor-dbus-interfaces change is required;
the patch continues to use the existing Decorator.LocationCode API.
The D-Bus to Redfish mapping remains:
- Inventory.Decorator.LocationCode/LocationCode
-> Location/PartLocation/ServiceLabel
Key changes:
- redfish-core/lib/processor.hpp: add afterGetProcessorLocationCode();
rename getCpuLocationCode() to getProcessorLocationCode(); switch the
getProperty callback to std::bind_front; log LocationCode D-Bus errors
with the ec value
- test/redfish-core/lib/processor_test.cpp: add unit tests for the
success and error paths in afterGetProcessorLocationCode()
- test/meson.build: register processor_test.cpp in the unit-test source
list
Tested: Built an image for nvl32-obmc machine with the following
patches cherry-picked:
1. Align with upstream u-boot dts tree:
https://gerrit.openbmc.org/c/openbmc/openbmc/+/89932
2. U-Boot change phy mode (in-flight on mailing list):
```
https://lore.kernel.org/openbmc/20260504044702.2613879-1-andhsieh@nvidia.com/T/#t
```
3. Kernel device tree add mac mode (in-flight on mailing list):
```
https://lore.kernel.org/linux-aspeed/20260505050541.3031447-1-andhsieh@nvidia.com/T/#t
```
4. platform-init enable LCLK and espiCLK:
https://gerrit.openbmc.org/c/openbmc/platform-init/+/89900
5. mctpd configuration:
https://gerrit.openbmc.org/c/openbmc/openbmc/+/87390
6. Enable nvidia-gpu sensor:
https://gerrit.openbmc.org/c/openbmc/openbmc/+/89933
$ curl -sk https://{BMC_IP}/redfish/v1/Systems/system/Processors/GPU_0_0
{
"@odata.id": "/redfish/v1/Systems/system/Processors/GPU_0_0",
"@odata.type": "#Processor.v1_18_0.Processor",
"Id": "GPU_0_0",
"Manufacturer": "NVIDIA",
"Model": "RTXPRO6000BlackwellDC",
"Name": "Processor",
"PartNumber": "900-2G153-0000-000",
"ProcessorType": "Accelerator",
"SerialNumber": "1792425045048",
"Status": {
"Health": "OK",
"State": "Enabled"
},
"UUID": "48b2ad9f-afb1-47ed-a1f0-01c610da73af",
"Version": "2BB5-895-A1"
}
1. Verified no regression: Processor GET responses remain correct after
the rename to getProcessorLocationCode().
2. Ran Redfish Service Validator:
Summary - PASS: 10797, WARN: 370, FAIL: 1, NOT TESTED: 17149
Validating /redfish/v1/Managers/bmc...
- Pass: 45, Warn: 0, Fail: 1, Skip: 27
The FAIL is Oem/OpenBmc/Certificates, an unknown OEM property in the
schema that is pre-existing and unrelated to this change.
Change-Id: I346265d1e90024266fb23221e54705cbd3ae286c
Signed-off-by: JY Voon <jvoon@nvidia.com>
|
|
Commit 2d7dc991 changed the body storage from being saved in a separate
field to a std::variant. Calling str() calls emplace<std::string>(),
which destroys the active FileBody in-place on file-backed bodies (e.g.
the Web UI) and closes the FD.
Any subsequent action now tries to access a non-existing FD (dummy
handle returning -1 as FD.)
Fix by returning early from `attemptZstdCompression` when the body is
file-backed, as file-backed bodies are already handled by the streaming
zstdCompressor in the writer.
Tested: cURL with "Accept-Encoding: zstd" to favicon.ico, ensuring that
it returns data again.
Fixes: 2d7dc991 ("Optimize bmcweb memory usage for multipart fw
update")
Change-Id: Ia54712f89d8c5f7dc9ce7c5d040aed06e8f6fded
Signed-off-by: Tan Siewert <tan.siewert@9elements.com>
|
|
After RAII change code accepts UTF8 only, so the code doesn't use
non-UTF8. This test uses ASCII that is UTF8 and duplicates other tests,
so remove NonUTF8UPNSubjectAlternativeName test.
Tested:
Unit tests
Change-Id: I48b8f0cbf644abce99a864e9dccd23f308693908
Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
|
|
There was a regression on json parsing due to a merge conflict
resolution on 2d7dc991600297d04e50d7958fe9611f9ac42bcf. Update the
connection unit tests to test the body catching this case, and fix the
error.
Tested: Unit tests pass. Redfish service validator passes
Change-Id: I4ad8802b7c75001ca7a2b1619af2f368bfe448ee
Signed-off-by: Ed Tanous <etanous@nvidia.com>
Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
|
|
Previously, firmware updates via multipart/form-data stored two copies
of the entire upload in memory (200MB+ for a 100MB image). This change
reduces memory usage by incrementally processing multipart data in
chunks, running through the parser as required. This avoids a copy into
the http body. With this change, bmcweb no longer retains any duplicate
copy of the image in memory, thereby limiting memory consumption to
roughly the size of the image itself.
To accomplish this, the multipart parser is rewritten to support
incremental parsing. This should be 100% compatible with the old
parser, with one exception, bytes at the end of the payload are no
longer accepted and ignored.
Tests:
Multipart FW Update using a 114.2MB file shows bmcweb memory usage in
line with one copy of the image, not two. Unit tests pass.
Change-Id: Id18e20004059bfbc7de62f4f6c9542430c7943b0
Signed-off-by: Rajeev Ranjan <ranjan.rajeev1609@gmail.com>
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Current unit tests only covers happy path. Add more unit tests before
changing the code.
Tested: unit tests
Change-Id: Ibba5dbbc1457b59670d5d8f3c828fa9ca112f88c
Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
|
|
bmcweb openssl usage is a mess. Start cleaning it up.
1. Make RAII objects for any held memory.
2. Move methods from hostname monitor into the ssl namespace, so not all
compile units need to pull in openssl headers
3. Move methods to static where functions can be encapsulated.
Because we're now testing openssl, we need to register memory init so
that the sanitizers don't cause issues when mallocing from non
bootstrapped openssl binaries. Openssl provides a handle for this, so
use it in those unit tests.
Tested:
Unit tests pass. bmcweb launches and can open ssl with curl as it did
previously.
Change-Id: If0340692d2c56a6c45bb8d661d654a4b58ff3d2c
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
To do this, refactor the date string function to a single method that
can be unit tested easily. While we're here, deprecate our usage of
time_t and move to std::chrono
Tested: Redifsh service validator passes
Change-Id: I67d4fe66d40b06ed0a0b60286adc75394c34ea1e
Signed-off-by: Ed Tanous <ed@tanous.net>
|
|
Domain names are case-insensitive per RFC standards [1]. Update
isUPNMatch() to perform case-insensitive comparison of domain
labels.
This ensures UPNs like user@DOMAIN.COM match hostnames like
host.domain.com, as per DNS standards.
Tested:
1. Unit tests
2. Built an image, flashed to real BMC, made sure curl requests that use
mTLS auth with certs that use UPN work
3. Redfish service validator
[1] https://datatracker.ietf.org/doc/html/rfc4343
Change-Id: Ibf5715fdddace4263d0aeef54e518457cf03dfcc
Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
The location_util::getLocation is used to find the `LocationCode`
interface used for `ServiceLabel`. Also added logic to look for the
Inventory.Connector.X interfaces to populate `LocationType`.
The helper function is added to serve as the common location helper
and remove the same method call in each individual resource files.
For example, `Inventory.Connector.Embedded` means LocationType of
Embedded type.
Currently only support LocationType of
- Slot
- Embedded
Tested: No changes to redfish tree yet
Added unit tests
Change-Id: I7f2a8d6172e37dd72881fbfb5a9dfeaf83b2db09
Signed-off-by: Zhenwei Chen <zhenweichen0207@gmail.com>
Signed-off-by: Willy Tu <wltu@google.com>
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
These static variables have the potential to cause reentrancy issues.
In practice, the conditions to cause issues would require someone to
basically write incorrect code, but it makes sense to wrap this into a
state tracker anyway to clean up the code. While we're here, convert to
using std::chrono.
Note, this changes the behavior such that the values produced are now no
longer dependent on timezone. Functionally, Redfish only recently got
the ability to set a timezone, so this is not expected to have any user
facing impact, even though the unit tests need to change.
Tested: RSV Passes
Change-Id: Icb7cff1d289ae23790a5fb1db6604abd73dd68fd
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
time_t is less specific than using the equivalents in std::chono. In
practice, most of the time we end up converting the time_t to some
std::chrono class anyway. Avoid the intermediate conversion and just
use the std::chrono version of time.
Tested: Unit tests pass. Good Coverage
Change-Id: I2e3eca78760e158feaaf4b91793631343e417f15
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
This should be doing exact matching, not partial matching. This failed
to catch a bug in a later change.
Note, this unit test will currently only pass on the UTC timezone.
Later in the series the backend is fixed to produce consistent results
regardless of timezone
Tested: unit test
Change-Id: Ie5652c0f9503b4de926addcfc292c76b59682b12
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
BMC now exposes DateTime property under the Manager/<ID> in timezone
configured on the BMC (local TZ) and not in UTC, but the other date
time properties are still in UTC.
Convert date time fields to local timezone.
Tested:
1. Redfish service validator
2. Built Facebook's Catalina image with this change, ran in QEMU and
checked manually varioius endpoints.
3. Ran automated tests [1] from openbmc-test-automation repo.
4. Unit tests
[1] https://gerrit.openbmc.org/c/openbmc/openbmc-test-automation/+/88659
Change-Id: I8e587c7a1030deff8e6a550651c5e62719fe5299
Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
Signed-off-by: Ed Tanous <ed@tanous.net>
|
|
Not a lot we can do here, but at least we can check the regex matches.
Tested: Unit test passes
Change-Id: Ib6058042c725169e90b971bd15851f16d621ac0e
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
In certain debug scenarios, there were cases where we would hit
recursion depth limits. These do not appear in conventional scenarios,
but could pop up in debug builds while running fuzzing. To fix this,
implement two checks.
First, limit $filter expressions to 1000 characters or less. This is
largely arbitrary.
Second, implement a depth checker to ensure that stack depth doesn't
exceed 10 frames. 10 is intended to be an order of magnitude more than
anyone will ever use. Most examples use 1 or 2 parens.
Tested: Unit tests pass. New unit tests added for this case.
Change-Id: I2c95e2fc8c0a3b94ab2a7f882ac6e1805bb7ebd5
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
We should have a single entry point where we do json parsing. There are
configurations for nlohmmann that we had previously documented, but were
not well enforced. Move all uses to using the helper parse functions.
Tested: Unit tests pass.
Redfish service validator passes.
Change-Id: I2a8aed9327b6b15219dc9b4d6db146b69bcd8eb3
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
It would be better if the larger compile units didn't have to pull in
the sd-journal header. At the same time, there's C handling of a number
of resources that could be moved to an RAII class, and unit tests that
we can add. This commit does all those things.
Note, vacuum.journal is a file created with
```
journalctl --rotate && sleep 1 && journalctl --rotate
````
And contains a few log entries. Note, while this file is 8MB, the
majority are zeros, so git should compress it just fine.
Tested: Unit tests updated.
Redfish service validator passes
Change-Id: If578316bcd1d0162b7ecdcca27c1c7818ce2b6fa
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
docs/COMMON_ERRORS.md documents patterns that are easy to introduce
and hard to catch in review. This adds machine-enforceable ast-grep
rules for those patterns so they get caught in CI instead of review.
Rules cover unsafe integer parsing, throwing JSON APIs, throwing
filesystem APIs, wildcard lambda captures, blocking calls, missing
trailing slashes on routes, and route string concatenation.
Tested: ast-grep scan --error exits 0.
Change-Id: I7ae24b52ac5b120826d29bb3ac6fce8f30199c15
Signed-off-by: Davy Marrero <dmarrero@nvidia.com>
|
|
Current code always return Date time in UTC, despite local timezone may
differ. This change allows to set manager timezone via redfish and show
manager's TZ and offset in manager's local timezone. When the DateTime
is being patched, the provided date time gets converted from the
provided TZ to the local timezone, but configured TZ does not get
changed. A user must explicitly patch TimeZoneName to change Manager's
TZ.
Tested:
1. Built an image, ran in QEMU, changed TZ to PST8PDT (negative offset),
UTC (0 offset), and Tokyo (positive offset). Made sure the patch works
and all the touched fields have correct values. See [1].
2. Unit tests
3. Redfish validator
[1]
```
$ curl -s -k -H 'Content-type: application/json' -u root:0penBmc https://localhost:8443/redfish/v1/Managers/bmc | jq '.DateTime, .DateTimeLocalOffset, .TimeZoneName'
"2026-03-19T11:03:16-07:00"
"-07:00"
"PST8PDT"
$ curl -i -k -H 'Content-type: application/json' -u root:0penBmc -d '{"TimeZoneName": "UTC"}' -X PATCH https://localhost:8443/redfish/v1/Managers/bmc
HTTP/1.1 204 No Content
Allow: GET, PATCH
OData-Version: 4.0
Strict-Transport-Security: max-age=31536000; includeSubdomains
Pragma: no-cache
Cache-Control: no-store, max-age=0
X-Content-Type-Options: nosniff
Date: Thu, 19 Mar 2026 18:03:28 GMT
Content-Length: 0
$ curl -s -k -H 'Content-type: application/json' -u root:0penBmc https://localhost:8443/redfish/v1/Managers/bmc | jq '.DateTime, .DateTimeLocalOffset, .TimeZoneName'
"2026-03-19T18:03:53+00:00"
"+00:00"
"UTC"
$ curl -i -k -H 'Content-type: application/json' -u root:0penBmc -d '{"TimeZoneName": "Asia/Tokyo"}' -X PATCH https://localhost:8443/redfish/v1/Managers/bmc
HTTP/1.1 204 No Content
Allow: GET, PATCH
OData-Version: 4.0
Strict-Transport-Security: max-age=31536000; includeSubdomains
Pragma: no-cache
Cache-Control: no-store, max-age=0
X-Content-Type-Options: nosniff
Date: Thu, 19 Mar 2026 18:04:20 GMT
Content-Length: 0
$ curl -s -k -H 'Content-type: application/json' -u root:0penBmc https://localhost:8443/redfish/v1/Managers/bmc | jq '.DateTime, .DateTimeLocalOffset, .TimeZoneName'
"2026-03-20T03:04:32+09:00"
"+09:00"
"Asia/Tokyo"
$ curl -i -k -H 'Content-type: application/json' -u root:0penBmc -d '{"DateTime": "2026-01-02T11:03:16-07:00"}' -X PATCH https://localhost:8443/redfish/v1/Managers/bmc
HTTP/1.1 204 No Content
Allow: GET, PATCH
OData-Version: 4.0
Strict-Transport-Security: max-age=31536000; includeSubdomains
Pragma: no-cache
Cache-Control: no-store, max-age=0
X-Content-Type-Options: nosniff
Date: Fri, 02 Jan 2026 18:03:16 GMT
Content-Length: 0
$ curl -s -k -H 'Content-type: application/json' -u root:0penBmc https://localhost:8443/redfish/v1/Managers/bmc | jq '.DateTime, .DateTimeLocalOffset, .TimeZoneName'
"2026-01-03T03:03:21+09:00"
"+09:00"
"Asia/Tokyo"
$ curl -s -k -H 'Content-type: application/json' -u root:0penBmc https://localhost:8443/redfish/v1/Managers/bmc/LogServices/Journal/Entries | jq '.Members[0]'
{
"@odata.id": "/redfish/v1/Managers/bmc/LogServices/Journal/Entries/cz0zNTMzMTVkMTBjYWQ0ZTg5ODJiYjliZGVmOTc2NDE2MDtpPTE7Yj00YzU5NzY1NzQ0M2M0N2IzOWZjYTZiNzU1ZWVlY2NjOTttPTFlZjc1Yzg7dD02MzY0OGQxOTFhZTE0O3g9ZDU5MjYwNzJkZTgzMWYzYw==",
"@odata.type": "#LogEntry.v1_9_0.LogEntry",
"Created": "2025-05-29T16:30:41.794580+00:00",
"EntryType": "Oem",
"Id": "cz0zNTMzMTVkMTBjYWQ0ZTg5ODJiYjliZGVmOTc2NDE2MDtpPTE7Yj00YzU5NzY1NzQ0M2M0N2IzOWZjYTZiNzU1ZWVlY2NjOTttPTFlZjc1Yzg7dD02MzY0OGQxOTFhZTE0O3g9ZDU5MjYwNzJkZTgzMWYzYw==",
"Message": "kernel: Booting Linux on physical CPU 0xf00",
"Name": "BMC Journal Entry",
"OemRecordFormat": "BMC Journal Entry",
"Severity": "OK"
}
```
Change-Id: I5a4567b9ca6a0f56dd9d1b971d418a19bf625a10
Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
|
|
TLS session resumption allows to bypass full TLS handshake in subsequent
connections, it's enabled in OpenSSL, so clients that support it use it.
One of the optimizations is, the client passes Session ID in subsequent
request and does not pass certificates. Since client certificate is not
passed, the callback that populates user session out of the certificate
is not called, and as result, auth fails for requests sents in
subsequent connections. This change enables session ID in memory cache,
lookup of the certificate in the cache by the session ID received from
the client and constructing user session out of it for subsequent
connections.
The cache is stored in RAM [1]. According to Nginx doc [2], size of one
session is about 250 bytes. If sessions use mTLS, they will also contain
a cert which is typically up 2kb. A client establishes connections as
part of a session, so a session can be associated with multiple
connections. In the worst case, when many clients establish a single
connection at a time, or a client always uses a new session for every
established connection, there will be number of session entries in the
cache equals to the number of connections. While OpenSSL limits cache
size to SSL_SESSION_CACHE_MAX_SIZE_DEFAULT which is 20480 [3], OpenBMC
limits number of established connections to 200 [4], so in the worst
case, memory usage will be ~50kb for non mTLS clients, and ~440kb for
mTLS clients. Typically, when there are just 2-3 clients connected, even
if them maintain multiple connections within their sessions, the cache
size will be less than 10kb for mTLS. To prevent high memory usage by
the cache, the change sets cache size to 100 entries. Expired sessions
are automatically removed on every 255th session [5].
Tested:
Deployed on one of our envs and ran client that quickly sends multiple
requests to the BMC (so the client created several connections), and
make sure the 401 auth problem had been observed before gone. Also, made
sure BMCWeb logged debug messages about existing session detection.
Ran tests from the openbmc-test-automation repository, esp related to
certificate and user management. They do session auth and not
mTLS/multi-connection, so they could not detect/confirm the problem is
fixed, but they confirm the change does not break the primary use case.
[1] https://docs.openssl.org/3.6/man3/SSL_CTX_set_session_cache_mode/#notes
[2] https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache
[3] https://github.com/openssl/openssl/blob/5869303daaecf037f0d00dc33a00f9bdc1e71f2f/include/openssl/ssl.h.in#L670
[4] https://github.com/openbmc/bmcweb/blob/master/http/http_connection.hpp#L219C13-L219C28
[5] https://docs.openssl.org/3.6/man3/SSL_CTX_flush_sessions/#notes
Change-Id: Ia94d1e323cd464cc7ca5b0f9c7d6a76e4c780e9a
Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
|
|
Keep existing Members on local I/O failures in the generic
collection path, and ensure empty collections still return
mandatory Members and Members@odata.count properties.
Add a reusable JSON array helper and use it in both
collection building and aggregator merge logic to avoid
clearing the response on transient failures.
Fixes common error #13.[1]
[1] https://github.com/openbmc/bmcweb/blob/master/docs/COMMON_ERRORS.md#13-complete-replacement-of-the-response-object
Tested: unit test passed; validator passed on empty collection URIs.
Change-Id: I8e144f55b99e3f8017abcebb11c409fffebf38ad
Signed-off-by: Tony Ao <tao@nvidia.com>
|
|
The generic collection path could clear the "Members" array on a local
I/O error, which breaks aggregated responses and can trigger Common
Error #13 [1].
The aggregator merge logic also needed a small reusable helper to ensure
a JSON value is an array.
Add a generic JSON array "ensure" helper in utils/collection.hpp and use
it from both the local collection builder and the aggregator merge path.
This avoids resetting Members on transient failures and avoids relying
on transitive includes for the helper.
[1] https://github.com/openbmc/bmcweb/blob/master/docs/COMMON_ERRORS.md#13-complete-replacement-of-the-response-object
Tested: Unit tests passed.
Change-Id: Iddaa608916af661f75989b4aeae9b557d09eebe3
Signed-off-by: Tony Ao <tao@nvidia.com>
|
|
This patch enable support for following properties for Port Metrics URI
of a PCIe Switch. [1]
- PCIeErrors.CorrectableErrorCount
- PCIeErrors.NonFatalErrorCount
- PCIeErrors.FatalErrorCount
- PCIeErrors.L0ToRecoveryCount
- PCIeErrors.ReplayCount
- PCIeErrors.ReplayRolloverCount
- PCIeErrors.NAKSentCount
- PCIeErrors.NAKReceivedCount
- PCIeErrors.UnsupportedRequestCount
The patch uses "xyz.openbmc_project.Metric.Value" Interface for PCIe
Port Metrics properties. Association between a Metric and a Port is
`measuring` and `measured_by`.
PDI patch -
https://gerrit.openbmc.org/c/openbmc/phosphor-dbus-interfaces/+/84839
dbus-sensors patches -
https://gerrit.openbmc.org/c/openbmc/dbus-sensors/+/84132
Tested: Build an image for nvl32-obmc machine with the following patch
cherry picked.
https://gerrit.openbmc.org/c/openbmc/dbus-sensors/+/84132
https://gerrit.openbmc.org/c/openbmc/openbmc/+/85490
The openbmc patch cherry-picks the following patches that are currently
under review.
```
1. device tree
https://lore.kernel.org/all/aRbLqH8pLWCQryhu@molberding.nvidia.com/
2. mctpd patches
https://github.com/CodeConstruct/mctp/pull/85
3. u-boot changes
https://lore.kernel.org/openbmc/20251121-msx4-v1-0-fc0118b666c1@nvidia.com/T/#t
4. kernel changes as specified in the openbmc patch (for espi)
5. entity-manager changes
https://gerrit.openbmc.org/c/openbmc/entity-manager/+/85455
6. platform-init changes
https://gerrit.openbmc.org/c/openbmc/platform-init/+/85456
7. spi changes
https://lore.kernel.org/all/20251121-w25q01jv_fixup-v1-1-3d175050db73@nvidia.com/
```
redfish service validator is passing.
```
$ curl -k -u 'root:0penBmc' https://${bmc_ip}/redfish/v1/Fabrics/fabric/Switches/Nvidia_ConnectX_0/Ports/UP_0/Metrics/
{
"@odata.id": "/redfish/v1/Fabrics/fabric/Switches/Nvidia_ConnectX_0/Ports/UP_0/Metrics",
"@odata.type": "#PortMetrics.v1_3_0.PortMetrics",
"Id": "Metrics",
"Name": "Nvidia_ConnectX_0 UP_0 Port Metrics",
"PCIeErrors": {
"CorrectableErrorCount": 0,
"FatalErrorCount": 0,
"L0ToRecoveryCount": 1,
"NAKReceivedCount": 0,
"NAKSentCount": 0,
"NonFatalErrorCount": 0,
"ReplayCount": 0,
"ReplayRolloverCount": 0,
"UnsupportedRequestCount": 0
}
}%
```
[1]: https://redfish.dmtf.org/schemas/v1/PortMetrics_v1.xml
Change-Id: I7cca75fa5d4c77a4b02d35f7ce0b024f325ceff0
Signed-off-by: Harshit Aghera <haghera@nvidia.com>
|
|
In preparation for making the multipart parser incremental, modify the
API to explicitly call out steps of start, parsePart, and finish. This
allows the parser to support incremental per-character parsing in the
future.
This also has the benefit of dropping the dependency on the Request
struct on the multipart parser itself.
Tested: Unit tests pass. Good coverage.
Change-Id: I3359f45bb9faaea42908491a818cc4a81f257a1f
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|