Jarrod Johnson
0272137e94
Have custom handling for megarac initial password state
...
Initial password state demands webgui to change password.
So act like the webgui.
2026-07-09 16:42:28 -04:00
Jarrod Johnson
149ecad90e
Improvements for MegaRAC discovery
...
Some Megarac fail with Host header looking like link local.
Systems with nVidia architecture have multiple bmcs, select the actual bmc.
2026-07-09 14:12:23 -04:00
Jarrod Johnson
b724de4230
Merge pull request #223 from Obihoernchen/showsecret
...
Add server-side confluentdbutil showattrib subcommand
2026-07-08 17:53:12 -04:00
Markus Hilger
6f11dffae8
Add server-side confluentdbutil showattrib subcommand
...
Adds `confluentdbutil showattrib <noderange> <attribute>...` to print the
node attribute.
In contrast to nodeattrib it can shows secrets and crypted values with -u flag.
It's server-side only: reads the config store and master key directly, never over
the API.
It's read-only and works without confluentd running.
2026-07-08 19:55:18 +02:00
Jarrod Johnson
0d90317d1f
Merge remote-tracking branch 'xcat/master'
2026-07-08 11:57:15 -04:00
Jarrod Johnson
e41a844aa3
Further tighten routing for "special" cases
...
Mitigate risk of misdirection through more explicit routing rules.
2026-07-08 11:56:48 -04:00
Jarrod Johnson
c9adc7690a
http api fixes
...
Instead of returning a sessionless authdata if webauthn loaded and validation requested, raise a not found indicating missing webauthn module.
Fix str being passod to rsp_write for the 403 return.
Ensure the console and shell session logic triggers only for subordinates of nodes or noderange.
Fix str being passed to rsp.write for the successful console session
2026-07-08 11:27:26 -04:00
Jarrod Johnson
9e71ea6b6e
Merge pull request #225 from Obihoernchen/license
...
License naming fixes for EPEL
2026-07-08 09:46:41 -04:00
Jarrod Johnson
ec0ab527b2
Fix exception name
2026-07-07 16:56:32 -04:00
Jarrod Johnson
25a6fb82d4
Correct exception name in passkey denial
2026-07-07 16:47:50 -04:00
Jarrod Johnson
8e75585f7d
Fixes for shell session operation in select paths
...
The classic console interface is restored.
2026-07-07 16:39:35 -04:00
Jarrod Johnson
9a4653412c
Fix webauthn related issues
...
The block on user modification shorted out webauthn hooks.
Further, be more picky about the prefix before the username in webauthn registered credentials and validation.
2026-07-07 16:37:45 -04:00
Markus Hilger
dba2af71c7
Match Apache-2.0 license name with SPDX expressions
...
For EPEL the official SPDX license expressions have to be used.
Check:
- https://docs.fedoraproject.org/en-US/packaging-guidelines/LicensingGuidelines/
- https://spdx.org/licenses/
- https://docs.fedoraproject.org/en-US/legal/allowed-licenses/
2026-07-07 21:08:43 +02:00
Jarrod Johnson
c3b75f0ca1
Remove stale logging output from enlogic
2026-07-02 16:23:32 -04:00
Markus Hilger
89c710f8c3
Fix key typo dropping verified flag in enclosure discovery
2026-07-02 22:07:48 +02:00
Markus Hilger
e280651343
Fix discostatus typo hiding records from the unidentified filter
2026-07-02 22:07:38 +02:00
Markus Hilger
7727cd86fc
Fix typos in help text, errors, and log messages
2026-07-02 22:07:27 +02:00
Jarrod Johnson
98190031df
Merge pull request #221 from Obihoernchen/defaultdoc
...
Add more attribute documentation
2026-07-02 15:05:44 -04:00
Markus Hilger
0f20c709c0
Add more attribute documentation
...
- deployment.lock: add missing 'unlocked' (messages.py's
InputDeploymentLock/DeploymentLock already accept and persist it).
- hardwaremanagement.method: correct stale "ipmi is used if not
specified" claim. Was changed to null in
c14165e2bd .
- snmp.privacyprotocol: document that unset is treated as 'des'
(snmputil.py explicitly groups None with 'des').
2026-07-02 19:50:56 +02:00
Jarrod Johnson
a8cd9a24d5
Auto-restart vtbufferd on exit
...
If vtbuffer is interrupted, then restart it.
2026-07-02 12:13:24 -04:00
Jarrod Johnson
752d04939b
Merge pull request #220 from Obihoernchen/pubkeys_addpolicy
...
Fix pubkeys.addpolicy documentation to match implementation
2026-07-02 10:31:04 -04:00
Jarrod Johnson
d24359a86c
Add comments clarifying non-voting state with respect to security expectations
2026-07-02 10:27:21 -04:00
Markus Hilger
4c0b2e44f4
Fix pubkeys.addpolicy documentation to match implementation
...
validvalues listed 'automatic'/'manual', but that was outdated.
Commit 454e1b8267 and cc70dcfa2b
implemented unset/'tofu' (trust-on-first-use, the default), 'manual', 'ca-only',
and an implicit 'ca' (any value that isn't otherwise handled falls
through to the standard CA-verification path, keying an already
pinned match without a full CA reverify).
The validvalues fix in ecaa75d967 rejected
these new values. Add new valid values with proper documentation.
2026-07-02 15:55:50 +02:00
Jarrod Johnson
ada4cb196d
Lock down non-system users to not have open ended access
2026-07-01 21:11:27 -04:00
Jarrod Johnson
0106758ceb
Prevent overwrite of existing files when saving licenses
2026-07-01 21:06:32 -04:00
Jarrod Johnson
1934b88b0d
Use basename to ensure no path traversal in license filenames
2026-07-01 20:54:36 -04:00
Jarrod Johnson
ae290c4419
Ensure the filename cannot have path traversal in XCC2 and older
2026-07-01 20:42:22 -04:00
Jarrod Johnson
57a4c840cb
Fix web shell sessions
2026-07-01 14:47:42 -04:00
Jarrod Johnson
6bcf1b73ba
Fix stale references to wsgi style env
2026-07-01 13:49:05 -04:00
Jarrod Johnson
3a6887b4b4
Provide nicer message when requested VM does not exist
2026-07-01 09:55:15 -04:00
Jarrod Johnson
d761c7e6da
Slow down reconnect attempts to powered down Proxmox VMs and better handle closed websockets.
2026-07-01 09:30:28 -04:00
Jarrod Johnson
45b392932d
Handle unreachable proxmox host more friendly
2026-07-01 09:14:07 -04:00
Jarrod Johnson
33c67db3c4
Further mitigate potential XML misbehavior
...
Since it turns out we already incurred lxml dependency, use lxml etree instead of xml and mitigate risky xml features beyond blocking the word '!entity'
2026-07-01 08:28:25 -04:00
Jarrod Johnson
fbec09c073
Fix behavior with IPMI bad user/password
2026-06-30 15:17:45 -04:00
Jarrod Johnson
5abd080ba2
Restore some sanity to redfish error handling
2026-06-30 13:56:34 -04:00
Jarrod Johnson
0383115446
Merge pull request #217 from Obihoernchen/hwplugins
...
Add missing validvalues to attributes.py
2026-06-30 08:13:21 -04:00
gosforthcross
6505810833
Improve handling of IPs with colon notation with seperate IPv4 and IPv6 paths, as well as whitespace stripping
2026-06-30 13:05:22 +02:00
gosforthcross
fbb79de786
Include EUREKA in necessary files for loading and handling redfish and autodiscovery
2026-06-30 11:30:24 +02:00
gosforthcross
6ab7d573da
Add EUREKA discovery handler
2026-06-30 11:29:19 +02:00
gosforthcross
5435acd23e
Add redfish OEM implementation for EUREKA Chassis
2026-06-30 11:28:45 +02:00
gosforthcross
cacfce214f
Add fallback for generic redfish and add specific MEGWARE code path for EUREKA
2026-06-30 11:25:11 +02:00
gosforthcross
b4882692ea
Add port discovery via colon notation
2026-06-30 11:22:30 +02:00
Markus Hilger
aed0bf0bea
Add valid_values to hardwaremanagement.method
2026-06-30 04:26:48 +02:00
Markus Hilger
ecaa75d967
Fix validvalues typo
...
valid_values is never checked and is a typo. Use validvalues instead.
Note: This can break existing scripts if invalid values are used.
2026-06-30 04:21:16 +02:00
Jarrod Johnson
3ce0988f5a
Fix -s on certutil
2026-06-29 11:30:49 -04:00
Jarrod Johnson
2c669358b3
Restore ability for certutil to run as standalone script
...
Also make days an argument
2026-06-26 12:12:25 -04:00
Jarrod Johnson
9462de42ac
Fix setboot when network not in bootorder
2026-06-25 15:56:11 -04:00
Jarrod Johnson
c1eea55610
When possible, check confluent user access to file
...
If a confluent user is a system user, do not allow them to
upload paths that their user would not have access to otherwise.
For non-system users, continue with the path based banned behavior.
2026-06-25 12:14:54 -04:00
Jarrod Johnson
d59652e0fd
Prevent staging of files from indicating path traversal
2026-06-25 10:09:28 -04:00
Jarrod Johnson
46fbc11a93
Other than skipauth type users (unix domain socket root/confluent), no longer allow confluent user addition/manipulation.
2026-06-25 09:55:09 -04:00