<feed xmlns='http://www.w3.org/2005/Atom'>
<title>BMC/tmp/openbmc.git/meta-supermicro, branch 2.18.0-dev</title>
<subtitle>OpenBMC Distribution (mirror)</subtitle>
<id>https://git.radix-linux.su/BMC/tmp/openbmc.git/atom?h=2.18.0-dev</id>
<link rel='self' href='https://git.radix-linux.su/BMC/tmp/openbmc.git/atom?h=2.18.0-dev'/>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/tmp/openbmc.git/'/>
<updated>2024-12-05T21:54:29+00:00</updated>
<entry>
<title>styhead: update WORKDIR usage</title>
<updated>2024-12-05T21:54:29+00:00</updated>
<author>
<name>Andrew Geissler</name>
<email>geissonator@yahoo.com</email>
</author>
<published>2024-06-26T15:06:48+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/tmp/openbmc.git/commit/?id=91a1cec28e08f949b120fe8885e87ef256ca4d93'/>
<id>urn:sha1:91a1cec28e08f949b120fe8885e87ef256ca4d93</id>
<content type='text'>
The latest yocto release(styhead,5.1) has made a significant change[1]
to the use of the WORKDIR parameter.

This is not the complete change required but gets us going in the right
direction.

[1]: https://docs.yoctoproject.org/next/migration-guides/migration-5.1.html#workdir-changes

Signed-off-by: Andrew Geissler &lt;geissonator@yahoo.com&gt;
Signed-off-by: Patrick Williams &lt;patrick@stwcx.xyz&gt;
Change-Id: I4f184b361be69e7704a0657a4a00cdad981aff8a
</content>
</entry>
<entry>
<title>treewide: remove meta-poky usage</title>
<updated>2024-03-22T11:10:32+00:00</updated>
<author>
<name>Patrick Williams</name>
<email>patrick@stwcx.xyz</email>
</author>
<published>2024-03-15T15:52:28+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/tmp/openbmc.git/commit/?id=e32643cc1d2e68eba52b00758e2d7950223ae273'/>
<id>urn:sha1:e32643cc1d2e68eba52b00758e2d7950223ae273</id>
<content type='text'>
Upstream poky made a commit that adds an `/etc/motd` with a strong
warning that meta-poky is not intended to be used for production
purposes.  There isn't anything we use directly from meta-poky anymore,
so clean up all references to it.

See poky commit a226865c8683398b5f58628ba2ec5aee1ee6c19d for additional
context.

We could potentially switch from using the `poky` subtree to picking
up OECore directly, but right now it also provides us a qualified set of
OECore + bitbake.

Tested: Built yosemite4 and confirmed `motd` output is absent when
SSHing in.

Signed-off-by: Patrick Williams &lt;patrick@stwcx.xyz&gt;
Change-Id: I9c08650d2278b3ba26794c009adad3e593767f58
</content>
</entry>
<entry>
<title>treewide: add scarthgap to LAYERSERIES_COMPAT</title>
<updated>2023-11-25T00:20:05+00:00</updated>
<author>
<name>Patrick Williams</name>
<email>patrick@stwcx.xyz</email>
</author>
<published>2023-11-25T00:20:05+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/tmp/openbmc.git/commit/?id=9d21a9409c159e4fa32c20a774337669da351413'/>
<id>urn:sha1:9d21a9409c159e4fa32c20a774337669da351413</id>
<content type='text'>
Signed-off-by: Patrick Williams &lt;patrick@stwcx.xyz&gt;
Change-Id: I28ee50fa55ae47dd7fd8c99f8f6db8f5f6dfa53d
</content>
</entry>
<entry>
<title>treewide: add nanbield to LAYERSERIES_COMPAT</title>
<updated>2023-11-24T16:24:09+00:00</updated>
<author>
<name>Patrick Williams</name>
<email>patrick@stwcx.xyz</email>
</author>
<published>2023-11-24T16:24:09+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/tmp/openbmc.git/commit/?id=1222bd457825c618c9557068a8f0d952a0ad754b'/>
<id>urn:sha1:1222bd457825c618c9557068a8f0d952a0ad754b</id>
<content type='text'>
Signed-off-by: Patrick Williams &lt;patrick@stwcx.xyz&gt;
Change-Id: I85272779478b66452acd11be93f5fea99e4c3a34
</content>
</entry>
<entry>
<title>treewide: clean up bmcweb in package groups</title>
<updated>2023-10-11T05:29:09+00:00</updated>
<author>
<name>Patrick Williams</name>
<email>patrick@stwcx.xyz</email>
</author>
<published>2023-10-06T23:43:32+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/tmp/openbmc.git/commit/?id=bac21122e90eeb4df7c70ccf19d407c2d24679e1'/>
<id>urn:sha1:bac21122e90eeb4df7c70ccf19d407c2d24679e1</id>
<content type='text'>
bmcweb is already added as a default in the meta-phosphor package
groups.  A large number of machines have mistakenly also explicitly
added a RDEPEND on assorted package groups, which is not necessary.
Clean these up.

Signed-off-by: Patrick Williams &lt;patrick@stwcx.xyz&gt;
Change-Id: Ifd3726d18aab45475f80d054a4640196ac0b71d2
</content>
</entry>
<entry>
<title>treewide: clean up webui selection</title>
<updated>2023-10-11T05:29:09+00:00</updated>
<author>
<name>Patrick Williams</name>
<email>patrick@stwcx.xyz</email>
</author>
<published>2023-10-06T23:34:43+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/tmp/openbmc.git/commit/?id=67e3b00895ed25c8dbb7bef763913a7fd17eaa27'/>
<id>urn:sha1:67e3b00895ed25c8dbb7bef763913a7fd17eaa27</id>
<content type='text'>
The webui-vue package is now enabled by default.  Clean up all the meta
layers to clean up the explicit enablement.

Signed-off-by: Patrick Williams &lt;patrick@stwcx.xyz&gt;
Change-Id: I4895be56c70d2c8666dd96cec18d2c097f0c05a3
</content>
</entry>
<entry>
<title>linux-aspeed: Move to Linux v6.5</title>
<updated>2023-09-26T12:11:34+00:00</updated>
<author>
<name>Joel Stanley</name>
<email>joel@jms.id.au</email>
</author>
<published>2023-08-11T05:19:00+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/tmp/openbmc.git/commit/?id=77b96cd848c627e5a94647496c4832d5c1ad436d'/>
<id>urn:sha1:77b96cd848c627e5a94647496c4832d5c1ad436d</id>
<content type='text'>
This moves the OpenBMC kernel to a v6.5 base for ASPEED.

The 6.5 kernel moved all 32-bit ARM device trees, so our BMC device
tress are now under an 'aspeed' subdirectory. This change means systems
must describe the KERNEL_DEVICETREE with the aspeed directory prefix.

There are 78 patches in the tree, with 40 of those patches not
yet queued for merging in v6.6.

The remaining out of tree patches include:

Andrew Jeffery (6):
      dt-bindings: hwmon: pmbus: Add Maxim MAX31785 documentation
      pmbus (max31785): Add support for devicetree configuration
      pmbus (core): One-shot retries for failure to set page
      pmbus (max31785): Wrap all I2C accessors in one-shot failure handlers
      ARM: dts: aspeed: witherspoon: Update max31785 node
      ipmi: kcs_bmc: Add a "raw" character device interface

Cédric Le Goater (1):
      /dev/mem: add a devmem kernel parameter to activate the device

Eddie James (16):
      ARM: dts: aspeed: bonnell: Add reserved memory for TPM event log
      dt-bindings: soc: Add Aspeed XDMA Engine
      soc: aspeed: Add XDMA Engine Driver
      soc: aspeed: xdma: Add user interface
      soc: aspeed: xdma: Add reset ioctl
      soc: aspeed: xdma: Add trace events
      i2c: core: Add mux root adapter operations
      iio: si7020: Lock root adapter to wait for reset
      eeprom: ee1004: Enable devices on multiple busses
      dt-bindings: trivial-devices: Add Atmel AT30TSE004A serial eeprom
      eeprom: ee1004: Add OF matching support
      leds: pca955x: Refactor with helper functions and renaming
      leds: pca955x: Use pointers to driver data rather than I2C client
      leds: pca955x: Optimize probe led selection
      leds: pca955x: Add HW blink support
      leds: Ensure hardware blinking turns off when requested

Jae Hyun Yoo (1):
      clk: ast2600: enable BCLK for PCI/PCIe bus always

Joel Stanley (14):
      net: ftgmac100: Ensure tx descriptor updates are visible
      ARM: aspeed: Add debugfs directory
      ARM: soc: aspeed: Add secure boot controller support
      dt-bindings: trivial-devices: Remove Infineon SLB9673 TPM
      ARM: dts: nuvoton: npmc750-evb: Add default console
      tpm: tis-i2c: Add more compatible strings
      leds: pca955x: Revert "Remove the unused function pca95xx_num_led_regs()"
      arm64: configs: Add Nuvoton NPCM defconfig
      ARM: configs: aspeed: Add new FSI drivers
      ARM: config: aspeed_g5: Enable SSIF BMC driver
      ARM: config: aspeed: Remove FIRMWARE_MEMMAP
      ARM: config: aspeed: Add Ampere SMPro drivers
      ARM: config: Add openbmc defconfig
      ARM: config: openbmc: Add HPE GPX and Nuvoton 7xx

Johannes Holland (1):
      dt-bindings: tpm: Add schema for TIS I2C devices

Potin Lai (1):
      mtd: spi-nor: winbond: Add support for w25q01jvq

Change-Id: Ib97af192391af6e71c96fe14e12cfc88c23d7a7d
Signed-off-by: Joel Stanley &lt;joel@jms.id.au&gt;
</content>
</entry>
<entry>
<title>Update to libpam 1.5.2</title>
<updated>2023-05-04T16:03:42+00:00</updated>
<author>
<name>Joseph Reynolds</name>
<email>joseph-reynolds@charter.net</email>
</author>
<published>2021-03-16T21:30:40+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/tmp/openbmc.git/commit/?id=fa324837ff64e44df7ee4a498ad4d298c81f1300'/>
<id>urn:sha1:fa324837ff64e44df7ee4a498ad4d298c81f1300</id>
<content type='text'>
This updates to libpam 1.5.2. This version removes support for
pam_cracklib and pam_tally2. They are replaced by pam_pwquality and
pam_faillock respectively.

Since parameters of pam_cracklb and pam_tally2 are configurable through
Redfish, it's possible that they will remain in the overlay of
/etc/pam.d with the old module names preventing PAM from working
correctly. To avoid this, this commit includes a script that will detect
if the old modules are in the overlay and update the overlay with the
new modules and configuration.

The script will allow updates from libpam 1.3.1 to libpam 1.5.2, but if there
are configured parameters during a downgrade from libpam 1.5.2 to libpam
1.3.1, it will require a factory reset before the downgrade.

pam_pwquality was selected over pam_passwdqc because of better security
and compatibility with pam_cracklib.

Note pam_faillock is necessarily configured into the pam module stack
differently than pam_tally2.

This patchset causes a BMC operational change:
- The pam_tally2 command (invoked from the BMC's command line) is no
  longer present.  If you used the "pam_tally2 -u USER -r" command
  to unlock a user after repeated authentication failures, change to
  use: faillock --user USER --reset

Compatibility note / migration issue.  If your BMC cannot authenticate
users after installing this change, the cause might be an overlayfs file
hiding the new /etc/pam.d/common-auth file.  To find out, use
`grep deny= /etc/pam.d/common-auth` on your BMC.  If it shows "tally2"
then your BMC is affected.  The recovery is to delete the overlay file,
to factory reset the BMC, or manually-install the changed files.
The convert-pam-configs service is intended to handle this problem.

Tested: as follows, for local users only (not tested with LDAP)

Note OpenBMC configuration defaults to an AccountLockoutThreshold
value of 0 which does not lock account passwords no matter how many
consecutive failed authentication attempts.  To configure this on
the BMC, for example, use:
curl -X PATCH https://${bmc}/redfish/v1/AccountService
  -d '{"AccountLockoutThreshold": 3, "AccountLockoutDuration": 60}'

Tested update scenarios:
1. Install from scratch.  Success.
2. Install over firmware which had old PAM configs.  Success.

Tested update scenarios for the convert-pam-configs service.

Tested changing the password via various interfaces:
- the passwd command
- the PATCH Refish AccountService {Password: NEW}
- SSH (accessible only when the password is expired)
- IPMI user set password (accessible for unexpired password)

Tested both good and bad (unacceptable) passwords.

Tested account lockout after N bad passwords
Tested unlock via Redfish.

Also, because its implementation changed, ensure reading and writing the
D-Bus User AccountPolicy RememberOldPasswordTimes property continues to
work.  There is no Redfish API for this.

Signed-off-by: Joseph Reynolds &lt;joseph-reynolds@charter.net&gt;
Signed-off-by: Jason M. Bills &lt;jason.m.bills@linux.intel.com&gt;
Change-Id: I7b712cf7cfbf7b0bc79da42f822540baee66ca4f
</content>
</entry>
<entry>
<title>yocto:mickledore: add support for new yocto layer</title>
<updated>2023-01-13T18:05:41+00:00</updated>
<author>
<name>Andrew Geissler</name>
<email>geissonator@yahoo.com</email>
</author>
<published>2023-01-13T15:41:33+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/tmp/openbmc.git/commit/?id=a93aa3eec17723ab4397e8578517955965748f03'/>
<id>urn:sha1:a93aa3eec17723ab4397e8578517955965748f03</id>
<content type='text'>
Signed-off-by: Andrew Geissler &lt;geissonator@yahoo.com&gt;
Change-Id: I8e54833ac78e540e9dd5011533d53ff9a3af6763
</content>
</entry>
<entry>
<title>treewide: remove obmc-op-control-host for non-openpower machines</title>
<updated>2022-10-14T09:28:28+00:00</updated>
<author>
<name>Patrick Williams</name>
<email>patrick@stwcx.xyz</email>
</author>
<published>2022-10-13T14:13:44+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/tmp/openbmc.git/commit/?id=cb01b982d034ad422436d30e6fd0fed983257162'/>
<id>urn:sha1:cb01b982d034ad422436d30e6fd0fed983257162</id>
<content type='text'>
The code for obmc-op-control-host is only useful for OpenPower
machines, but somehow it is being included in many other machines.
Remove it from all of them except meta-openpower.

Signed-off-by: Patrick Williams &lt;patrick@stwcx.xyz&gt;
Change-Id: I4e7c7365eb320c3fb9ea7a57aca2ed0b1832e85e
</content>
</entry>
</feed>
