diff --git a/.fmf/version b/.fmf/version deleted file mode 100644 index d00491f..0000000 --- a/.fmf/version +++ /dev/null @@ -1 +0,0 @@ -1 diff --git a/.gitignore b/.gitignore index d358878..c94eb56 100644 --- a/.gitignore +++ b/.gitignore @@ -10,4 +10,3 @@ net-snmp-5.5.tar.gz /net-snmp-5.9.1.tar.gz /net-snmp-5.9.3.tar.gz /net-snmp-5.9.4.tar.gz -/net-snmp-5.9.5.2.tar.gz diff --git a/0001-Use-OpenSSL-accessors-for-opaque-structs.patch b/0001-Use-OpenSSL-accessors-for-opaque-structs.patch deleted file mode 100644 index fa1b973..0000000 --- a/0001-Use-OpenSSL-accessors-for-opaque-structs.patch +++ /dev/null @@ -1,177 +0,0 @@ -From 338d289f1e14650edf0bd7e960272871029131e1 Mon Sep 17 00:00:00 2001 -From: Simo Sorce -Date: Fri, 17 Apr 2026 12:47:18 -0400 -Subject: [PATCH] Use OpenSSL accessors for opaque structs - -Replaced direct access to `ASN1_STRING` fields with OpenSSL accessor functions -(e.g., `ASN1_STRING_type`, `ASN1_STRING_length`, `ASN1_STRING_get0_data`) and -updated `X509_NAME` and `X509_EXTENSION` pointers to `const`. This is required -to maintain compatibility with newer OpenSSL versions (4.0+) where these -structures were made opaque. - -Co-authored-by: Gemini -Signed-off-by: Simo Sorce ---- - snmplib/snmp_openssl.c | 74 ++++++++++++++++++++++-------------------- - 1 file changed, 39 insertions(+), 35 deletions(-) - -diff --git a/snmplib/snmp_openssl.c b/snmplib/snmp_openssl.c -index 4471a7a..658841a 100644 ---- a/snmplib/snmp_openssl.c -+++ b/snmplib/snmp_openssl.c -@@ -147,7 +147,7 @@ void netsnmp_init_openssl(void) { - static char * - _cert_get_name(X509 *ocert, int which, char **buf, int *len, int flags) - { -- X509_NAME *osubj_name; -+ const X509_NAME *osubj_name; - int space; - char *buf_ptr; - -@@ -187,7 +187,7 @@ _cert_get_name(X509 *ocert, int which, char **buf, int *len, int flags) - char * - netsnmp_openssl_cert_get_subjectName(X509 *ocert, char **buf, int *len) - { -- X509_NAME *osubj_name; -+ const X509_NAME *osubj_name; - int space; - char *buf_ptr; - -@@ -233,11 +233,11 @@ netsnmp_openssl_cert_get_commonName(X509 *ocert, char **buf, int *len) - void - netsnmp_openssl_cert_dump_names(X509 *ocert) - { -- int i, onid; -- X509_NAME_ENTRY *oname_entry; -- ASN1_STRING *oname_value; -- X509_NAME *osubj_name; -- const char *prefix_short, *prefix_long; -+ int i, onid; -+ const X509_NAME_ENTRY *oname_entry; -+ const ASN1_STRING *oname_value; -+ const X509_NAME *osubj_name; -+ const char *prefix_short, *prefix_long; - - if (NULL == ocert) - return; -@@ -253,7 +253,7 @@ netsnmp_openssl_cert_dump_names(X509 *ocert) - netsnmp_assert(NULL != oname_entry); - oname_value = X509_NAME_ENTRY_get_data(oname_entry); - -- if (oname_value->type != V_ASN1_PRINTABLESTRING) -+ if (ASN1_STRING_type(oname_value) != V_ASN1_PRINTABLESTRING) - continue; - - /** get NID */ -@@ -268,7 +268,7 @@ netsnmp_openssl_cert_dump_names(X509 *ocert) - - DEBUGMSGT(("9:cert:dump:names", - "[%02d] NID type %d, ASN type %d\n", i, onid, -- oname_value->type)); -+ ASN1_STRING_type(oname_value))); - DEBUGMSGT(("9:cert:dump:names", "%s/%s: '%s'\n", prefix_long, - prefix_short, ASN1_STRING_get0_data(oname_value))); - } -@@ -276,7 +276,7 @@ netsnmp_openssl_cert_dump_names(X509 *ocert) - #endif /* NETSNMP_FEATURE_REMOVE_CERT_DUMP_NAMES */ - - static char * --_cert_get_extension(X509_EXTENSION *oext, char **buf, int *len, int flags) -+_cert_get_extension(const X509_EXTENSION *oext, char **buf, int *len, int flags) - { - int space; - char *buf_ptr = NULL; -@@ -327,10 +327,10 @@ out: - */ - /** instead of exposing this function, make helper functions for each - * field, like netsnmp_openssl_cert_get_subjectAltName, below */ --X509_EXTENSION * -+const X509_EXTENSION * - _cert_get_extension_at(X509 *ocert, int pos, char **buf, int *len, int flags) - { -- X509_EXTENSION *oext; -+ const X509_EXTENSION *oext; - - if ((NULL == ocert) || ((buf && !len) || (len && !buf))) - return NULL; -@@ -354,7 +354,7 @@ static char * - _cert_get_extension_str_at(X509 *ocert, int pos, char **buf, int *len, - int flags) - { -- X509_EXTENSION *oext; -+ const X509_EXTENSION *oext; - - if ((NULL == ocert) || ((buf && !len) || (len && !buf))) - return NULL; -@@ -374,7 +374,7 @@ _cert_get_extension_str_at(X509 *ocert, int pos, char **buf, int *len, - */ - /** instead of exposing this function, make helper functions for each - * field, like netsnmp_openssl_cert_get_subjectAltName, below */ --X509_EXTENSION * -+const X509_EXTENSION * - _cert_get_extension_id(X509 *ocert, int which, char **buf, int *len, int flags) - { - int pos; -@@ -434,27 +434,31 @@ _extract_oname(const GENERAL_NAME *oname) - break; - - case GEN_IPADD: -- if (oname->d.iPAddress->length == 4) { -- sprintf(ipbuf, "%d.%d.%d.%d", oname->d.iPAddress->data[0], -- oname->d.iPAddress->data[1], -- oname->d.iPAddress->data[2], -- oname->d.iPAddress->data[3]); -- rtn = strdup(ipbuf); -- } -- else if ((oname->d.iPAddress->length == 16) || -- (oname->d.iPAddress->length == 20)) { -- char *pos = ipbuf; -- int j; -- for(j = 0; j < oname->d.iPAddress->length; ++j) { -- *pos++ = VAL2HEX(oname->d.iPAddress->data[j]); -- *pos++ = ':'; -+ { -+ int ipaddr_len = ASN1_STRING_length(oname->d.iPAddress); -+ const unsigned char *ipaddr_data = ASN1_STRING_get0_data(oname->d.iPAddress); -+ if (ipaddr_len == 4) { -+ sprintf(ipbuf, "%d.%d.%d.%d", ipaddr_data[0], -+ ipaddr_data[1], -+ ipaddr_data[2], -+ ipaddr_data[3]); -+ rtn = strdup(ipbuf); -+ } -+ else if ((ipaddr_len == 16) || -+ (ipaddr_len == 20)) { -+ char *pos = ipbuf; -+ int j; -+ for(j = 0; j < ipaddr_len; ++j) { -+ *pos++ = VAL2HEX(ipaddr_data[j]); -+ *pos++ = ':'; -+ } -+ *pos = '\0'; -+ rtn = strdup(ipbuf); - } -- *pos = '\0'; -- rtn = strdup(ipbuf); -+ else -+ NETSNMP_LOGONCE((LOG_WARNING, "unexpected ip addr length %d\n", -+ ipaddr_len)); - } -- else -- NETSNMP_LOGONCE((LOG_WARNING, "unexpected ip addr length %d\n", -- oname->d.iPAddress->length)); - - break; - default: -@@ -485,7 +489,7 @@ netsnmp_openssl_cert_get_subjectAltNames(X509 *ocert, char **buf, int *len) - void - netsnmp_openssl_cert_dump_extensions(X509 *ocert) - { -- X509_EXTENSION *extension; -+ const X509_EXTENSION *extension; - const char *extension_name; - char buf[SNMP_MAXBUF], *buf_ptr = buf, *str, *lf; - int i, num_extensions, buf_len, nid; --- -2.53.0 - diff --git a/net-snmp-5.7.3-iterator-fix.patch b/net-snmp-5.7.3-iterator-fix.patch index 0afd8bc..fb34caf 100644 --- a/net-snmp-5.7.3-iterator-fix.patch +++ b/net-snmp-5.7.3-iterator-fix.patch @@ -1,8 +1,7 @@ -diff --git a/agent/mibgroup/host/data_access/swrun.c b/agent/mibgroup/host/data_access/swrun.c -index 7b278eb..5f10ade 100644 ---- a/agent/mibgroup/host/data_access/swrun.c -+++ b/agent/mibgroup/host/data_access/swrun.c -@@ -143,6 +143,10 @@ swrun_count_processes_by_name( char *name ) +diff -urNp old/agent/mibgroup/host/data_access/swrun.c new/agent/mibgroup/host/data_access/swrun.c +--- old/agent/mibgroup/host/data_access/swrun.c 2017-07-18 09:44:00.626109526 +0200 ++++ new/agent/mibgroup/host/data_access/swrun.c 2017-07-19 15:27:50.452255836 +0200 +@@ -102,6 +102,10 @@ swrun_count_processes_by_name( char *nam return 0; /* or -1 */ it = CONTAINER_ITERATOR( swrun_container ); diff --git a/net-snmp-5.8-clientaddr-error-message.patch b/net-snmp-5.8-clientaddr-error-message.patch index 8de6386..ef851b1 100644 --- a/net-snmp-5.8-clientaddr-error-message.patch +++ b/net-snmp-5.8-clientaddr-error-message.patch @@ -1,8 +1,7 @@ -diff --git a/snmplib/snmp_api.c b/snmplib/snmp_api.c -index ad30397..307253a 100644 ---- a/snmplib/snmp_api.c -+++ b/snmplib/snmp_api.c -@@ -231,7 +231,7 @@ static const char *api_errors[-SNMPERR_MAX + 1] = { +diff -urNp a/snmplib/snmp_api.c b/snmplib/snmp_api.c +--- a/snmplib/snmp_api.c 2020-11-26 11:05:51.084788775 +0100 ++++ b/snmplib/snmp_api.c 2020-11-26 11:08:27.850751397 +0100 +@@ -235,7 +235,7 @@ static const char *api_errors[-SNMPERR_M "No error", /* SNMPERR_SUCCESS */ "Generic error", /* SNMPERR_GENERR */ "Invalid local port", /* SNMPERR_BAD_LOCPORT */ @@ -11,7 +10,7 @@ index ad30397..307253a 100644 "Unknown session", /* SNMPERR_BAD_SESSION */ "Too long", /* SNMPERR_TOO_LONG */ "No socket", /* SNMPERR_NO_SOCKET */ -@@ -1718,7 +1718,9 @@ _sess_open(netsnmp_session * in_session) +@@ -1662,7 +1662,9 @@ _sess_open(netsnmp_session * in_session) DEBUGMSGTL(("_sess_open", "couldn't interpret peername\n")); in_session->s_snmp_errno = SNMPERR_BAD_ADDRESS; in_session->s_errno = errno; @@ -22,11 +21,10 @@ index ad30397..307253a 100644 return NULL; } -diff --git a/snmplib/transports/snmpUDPIPv4BaseDomain.c b/snmplib/transports/snmpUDPIPv4BaseDomain.c -index 1e15a2f..47ac42e 100644 ---- a/snmplib/transports/snmpUDPIPv4BaseDomain.c -+++ b/snmplib/transports/snmpUDPIPv4BaseDomain.c -@@ -224,6 +224,8 @@ netsnmp_udpipv4base_transport_bind(netsnmp_transport *t, +diff -ruNp a/snmplib/transports/snmpUDPIPv4BaseDomain.c b/snmplib/transports/snmpUDPIPv4BaseDomain.c +--- a/snmplib/transports/snmpUDPIPv4BaseDomain.c 2021-01-06 12:51:51.948106797 +0100 ++++ b/snmplib/transports/snmpUDPIPv4BaseDomain.c 2021-01-06 14:17:31.029745744 +0100 +@@ -209,6 +209,8 @@ netsnmp_udpipv4base_transport_bind(netsn DEBUGMSGTL(("netsnmp_udpbase", "failed to bind for clientaddr: %d %s\n", errno, strerror(errno))); diff --git a/net-snmp-5.8-duplicate-ipAddress.patch b/net-snmp-5.8-duplicate-ipAddress.patch index 8c833a7..075976a 100644 --- a/net-snmp-5.8-duplicate-ipAddress.patch +++ b/net-snmp-5.8-duplicate-ipAddress.patch @@ -1,8 +1,7 @@ -diff --git a/agent/mibgroup/ip-mib/data_access/ipaddress_common.c b/agent/mibgroup/ip-mib/data_access/ipaddress_common.c -index 675d4ea..8d3708d 100644 ---- a/agent/mibgroup/ip-mib/data_access/ipaddress_common.c -+++ b/agent/mibgroup/ip-mib/data_access/ipaddress_common.c -@@ -120,6 +120,7 @@ _remove_duplicates(netsnmp_container *container, u_int container_flags) +diff -urNp a/agent/mibgroup/ip-mib/data_access/ipaddress_common.c b/agent/mibgroup/ip-mib/data_access/ipaddress_common.c +--- a/agent/mibgroup/ip-mib/data_access/ipaddress_common.c 2020-06-10 13:27:03.213904398 +0200 ++++ b/agent/mibgroup/ip-mib/data_access/ipaddress_common.c 2020-06-10 13:28:41.025863050 +0200 +@@ -121,6 +121,7 @@ _remove_duplicates(netsnmp_container *co for (entry = ITERATOR_FIRST(it); entry; entry = ITERATOR_NEXT(it)) { if (prev_entry && _access_ipaddress_entry_compare_addr(prev_entry, entry) == 0) { /* 'entry' is duplicate of the previous one -> delete it */ diff --git a/net-snmp-5.8-expand-SNMPCONFPATH.patch b/net-snmp-5.8-expand-SNMPCONFPATH.patch index f9132fe..a812cf4 100644 --- a/net-snmp-5.8-expand-SNMPCONFPATH.patch +++ b/net-snmp-5.8-expand-SNMPCONFPATH.patch @@ -1,8 +1,7 @@ -diff --git a/snmplib/read_config.c b/snmplib/read_config.c -index 159f4be..fa8fcba 100644 ---- a/snmplib/read_config.c -+++ b/snmplib/read_config.c -@@ -1688,7 +1688,7 @@ snmp_save_persistent(const char *type) +diff -ruNp a/snmplib/read_config.c b/snmplib/read_config.c +--- a/snmplib/read_config.c 2020-06-10 09:51:57.184786510 +0200 ++++ b/snmplib/read_config.c 2020-06-10 09:53:13.257507112 +0200 +@@ -1642,7 +1642,7 @@ snmp_save_persistent(const char *type) * save a warning header to the top of the new file */ snprintf(fileold, sizeof(fileold), diff --git a/net-snmp-5.8-ipAddress-faster-load.patch b/net-snmp-5.8-ipAddress-faster-load.patch index 32f9b60..db95998 100644 --- a/net-snmp-5.8-ipAddress-faster-load.patch +++ b/net-snmp-5.8-ipAddress-faster-load.patch @@ -1,8 +1,7 @@ -diff --git a/agent/mibgroup/mibII/ipAddr.c b/agent/mibgroup/mibII/ipAddr.c -index a89255f..ef67f5f 100644 ---- a/agent/mibgroup/mibII/ipAddr.c -+++ b/agent/mibgroup/mibII/ipAddr.c -@@ -498,14 +498,16 @@ Address_Scan_Next(Index, Retin_ifaddr) +diff -urNp a/agent/mibgroup/mibII/ipAddr.c b/agent/mibgroup/mibII/ipAddr.c +--- a/agent/mibgroup/mibII/ipAddr.c 2020-06-10 14:14:30.113696471 +0200 ++++ b/agent/mibgroup/mibII/ipAddr.c 2020-06-10 14:27:15.345354018 +0200 +@@ -495,14 +495,16 @@ Address_Scan_Next(Index, Retin_ifaddr) } #elif defined(linux) @@ -20,7 +19,7 @@ index a89255f..ef67f5f 100644 /* get info about all interfaces */ -@@ -513,28 +515,45 @@ Address_Scan_Init(void) +@@ -510,28 +512,45 @@ Address_Scan_Init(void) SNMP_FREE(ifc.ifc_buf); ifr_counter = 0; diff --git a/net-snmp-5.8-man-page.patch b/net-snmp-5.8-man-page.patch new file mode 100644 index 0000000..dc78e14 --- /dev/null +++ b/net-snmp-5.8-man-page.patch @@ -0,0 +1,36 @@ +diff -urNp a/man/net-snmp-create-v3-user.1.def b/man/net-snmp-create-v3-user.1.def +--- a/man/net-snmp-create-v3-user.1.def 2020-06-10 13:43:18.443070961 +0200 ++++ b/man/net-snmp-create-v3-user.1.def 2020-06-10 13:49:25.975363441 +0200 +@@ -3,7 +3,7 @@ + net-snmp-create-v3-user \- create a SNMPv3 user in net-snmp configuration file + .SH SYNOPSIS + .PP +-.B net-snmp-create-v3-user [-ro] [-a authpass] [-x privpass] [-X DES|AES] ++.B net-snmp-create-v3-user [-ro] [-A authpass] [-a MD5|SHA] [-X privpass] [-x DES|AES] + .B [username] + .SH DESCRIPTION + .PP +@@ -16,13 +16,16 @@ new user in net-snmp configuration file + displays the net-snmp version number + .TP + \fB\-ro\fR +-create an user with read-only permissions ++creates a user with read-only permissions + .TP +-\fB\-a authpass\fR +-specify authentication password ++\fB\-A authpass\fR ++specifies the authentication password + .TP +-\fB\-x privpass\fR +-specify encryption password ++\fB\-a MD5|SHA\fR ++specifies the authentication password hashing algorithm + .TP +-\fB\-X DES|AES\fR +-specify encryption algorithm ++\fB\-X privpass\fR ++specifies the encryption password ++.TP ++\fB\-x DES|AES\fR ++specifies the encryption algorithm diff --git a/net-snmp-5.8-rpm-memory-leak.patch b/net-snmp-5.8-rpm-memory-leak.patch new file mode 100644 index 0000000..d337008 --- /dev/null +++ b/net-snmp-5.8-rpm-memory-leak.patch @@ -0,0 +1,28 @@ +diff --git a/agent/mibgroup/host/data_access/swinst_rpm.c b/agent/mibgroup/host/data_access/swinst_rpm.c +index 695c469..dd0e487 100644 +--- a/agent/mibgroup/host/data_access/swinst_rpm.c ++++ b/agent/mibgroup/host/data_access/swinst_rpm.c +@@ -75,6 +75,9 @@ netsnmp_swinst_arch_init(void) + snprintf( pkg_directory, SNMP_MAXPATH, "%s/Packages", dbpath ); + SNMP_FREE(rpmdbpath); + dbpath = NULL; ++#ifdef HAVE_RPMGETPATH ++ rpmFreeRpmrc(); ++#endif + if (-1 == stat( pkg_directory, &stat_buf )) { + snmp_log(LOG_ERR, "Can't find directory of RPM packages\n"); + pkg_directory[0] = '\0'; +diff --git a/agent/mibgroup/host/hr_swinst.c b/agent/mibgroup/host/hr_swinst.c +index 1f52733..ccf1cab 100644 +--- a/agent/mibgroup/host/hr_swinst.c ++++ b/agent/mibgroup/host/hr_swinst.c +@@ -231,6 +231,9 @@ init_hr_swinst(void) + snprintf(path, sizeof(path), "%s/packages.rpm", swi->swi_dbpath); + path[ sizeof(path)-1 ] = 0; + swi->swi_directory = strdup(path); ++#ifdef HAVE_RPMGETPATH ++ rpmFreeRpmrc(); ++#endif + } + #else + # ifdef _PATH_HRSW_directory diff --git a/net-snmp-5.9-cflags.patch b/net-snmp-5.9-cflags.patch index a48e9ca..ef8604f 100644 --- a/net-snmp-5.9-cflags.patch +++ b/net-snmp-5.9-cflags.patch @@ -1,19 +1,17 @@ -diff --git a/perl/Makefile.PL b/perl/Makefile.PL -index 63e6333..82cedca 100644 ---- a/perl/Makefile.PL -+++ b/perl/Makefile.PL +diff -urNp a/perl/Makefile.PL b/perl/Makefile.PL +--- a/perl/Makefile.PL 2020-08-26 08:32:52.498909823 +0200 ++++ b/perl/Makefile.PL 2020-08-26 09:30:45.584951552 +0200 @@ -1,3 +1,4 @@ +use lib '.'; use strict; use warnings; use ExtUtils::MakeMaker; -diff --git a/perl/MakefileSubs.pm b/perl/MakefileSubs.pm -index 804b20e..25c5d67 100644 ---- a/perl/MakefileSubs.pm -+++ b/perl/MakefileSubs.pm -@@ -126,7 +126,7 @@ sub AddCommonParams { - # Suppress warnings about old-style function definitions. - append($Params->{'CCFLAGS'}, '-Wno-old-style-definition'); +diff -urNp a/perl/MakefileSubs.pm b/perl/MakefileSubs.pm +--- a/perl/MakefileSubs.pm 2020-08-26 08:32:52.498909823 +0200 ++++ b/perl/MakefileSubs.pm 2020-08-26 08:36:44.097218448 +0200 +@@ -116,7 +116,7 @@ sub AddCommonParams { + append($Params->{'CCFLAGS'}, $cflags); + append($Params->{'CCFLAGS'}, $Config{'ccflags'}); # Suppress known Perl header shortcomings. - $Params->{'CCFLAGS'} =~ s/ -W(cast-qual|write-strings)//g; + $Params->{'CCFLAGS'} =~ s/ -W(inline|strict-prototypes|write-strings|cast-qual|no-char-subscripts)//g; diff --git a/net-snmp-5.9-coverity.patch b/net-snmp-5.9-coverity.patch new file mode 100644 index 0000000..fa3e043 --- /dev/null +++ b/net-snmp-5.9-coverity.patch @@ -0,0 +1,22 @@ +diff --git a/agent/mibgroup/disman/event/mteTrigger.c b/agent/mibgroup/disman/event/mteTrigger.c +index e9a8831..5a1d8e7 100644 +--- a/agent/mibgroup/disman/event/mteTrigger.c ++++ b/agent/mibgroup/disman/event/mteTrigger.c +@@ -1012,7 +1012,7 @@ mteTrigger_run( unsigned int reg, void *clientarg) + * Similarly, if no fallEvent is configured, + * there's no point in trying to fire it either. + */ +- if (entry->mteTThRiseEvent[0] != '\0' ) { ++ if (entry->mteTThFallEvent[0] != '\0' ) { + entry->mteTriggerXOwner = entry->mteTThObjOwner; + entry->mteTriggerXObjects = entry->mteTThObjects; + entry->mteTriggerFired = vp1; +@@ -1105,7 +1105,7 @@ mteTrigger_run( unsigned int reg, void *clientarg) + * Similarly, if no fallEvent is configured, + * there's no point in trying to fire it either. + */ +- if (entry->mteTThDRiseEvent[0] != '\0' ) { ++ if (entry->mteTThDFallEvent[0] != '\0' ) { + entry->mteTriggerXOwner = entry->mteTThObjOwner; + entry->mteTriggerXObjects = entry->mteTThObjects; + entry->mteTriggerFired = vp1; diff --git a/net-snmp-5.9-intermediate-certs.patch b/net-snmp-5.9-intermediate-certs.patch index ab5b7a0..6b5daf7 100644 --- a/net-snmp-5.9-intermediate-certs.patch +++ b/net-snmp-5.9-intermediate-certs.patch @@ -1,8 +1,8 @@ diff --git a/include/net-snmp/library/cert_util.h b/include/net-snmp/library/cert_util.h -index 305e367..6117b9a 100644 +index 80e2a19..143adbb 100644 --- a/include/net-snmp/library/cert_util.h +++ b/include/net-snmp/library/cert_util.h -@@ -48,7 +48,8 @@ extern "C" { +@@ -55,7 +55,8 @@ extern "C" { char *common_name; u_char hash_type; @@ -12,7 +12,7 @@ index 305e367..6117b9a 100644 } netsnmp_cert; /** types */ -@@ -93,6 +94,7 @@ extern "C" { +@@ -100,6 +101,7 @@ extern "C" { NETSNMP_IMPORT netsnmp_cert *netsnmp_cert_find(int what, int where, void *hint); @@ -35,21 +35,10 @@ index 471bb0b..ac7f69a 100644 #ifdef __cplusplus diff --git a/snmplib/cert_util.c b/snmplib/cert_util.c -index 5b5aaaa..7c07048 100644 +index 210ad8b..b1f8144 100644 --- a/snmplib/cert_util.c +++ b/snmplib/cert_util.c -@@ -42,9 +42,7 @@ netsnmp_feature_child_of(tls_fingerprint_build, cert_util_all); - - #include - --#include -- --#if HAVE_STDLIB_H -+#ifdef HAVE_STDLIB_H - #include - #endif - -@@ -102,7 +100,7 @@ netsnmp_feature_child_of(tls_fingerprint_build, cert_util_all); +@@ -100,7 +100,7 @@ netsnmp_feature_child_of(tls_fingerprint_build, cert_util_all); * bump this value whenever cert index format changes, so indexes * will be regenerated with new format. */ @@ -58,28 +47,8 @@ index 5b5aaaa..7c07048 100644 static netsnmp_container *_certs = NULL; static netsnmp_container *_keys = NULL; -@@ -116,16 +114,20 @@ static netsnmp_container *_trusted_certs = NULL; - static void _setup_containers(void); - - static void _cert_indexes_load(void); --static void _cert_free(void *cert, void *context); --static void _key_free(void *key, void *context); --static int _cert_compare(const void *p, const void *q); --static int _cert_sn_compare(const void *p, const void *q); --static int _cert_sn_ncompare(const void *p, const void *q); --static int _cert_cn_compare(const void *p, const void *q); --static int _cert_fn_compare(const void *p, const void *q); --static int _cert_fn_ncompare(const void *p, const void *q); -+static void _cert_free(netsnmp_cert *cert, void *context); -+static void _key_free(netsnmp_key *key, void *context); -+static int _cert_compare(netsnmp_cert *lhs, netsnmp_cert *rhs); -+static int _cert_sn_compare(netsnmp_cert *lhs, netsnmp_cert *rhs); -+static int _cert_sn_ncompare(netsnmp_cert *lhs, netsnmp_cert *rhs); -+static int _cert_cn_compare(netsnmp_cert *lhs, netsnmp_cert *rhs); -+static int _cert_fn_compare(netsnmp_cert_common *lhs, -+ netsnmp_cert_common *rhs); -+static int _cert_fn_ncompare(netsnmp_cert_common *lhs, -+ netsnmp_cert_common *rhs); +@@ -126,6 +126,8 @@ static int _cert_fn_ncompare(netsnmp_cert_common *lhs, + netsnmp_cert_common *rhs); static void _find_partner(netsnmp_cert *cert, netsnmp_key *key); static netsnmp_cert *_find_issuer(netsnmp_cert *cert); +static netsnmp_void_array *_cert_reduce_subset_first(netsnmp_void_array *matching); @@ -87,16 +56,7 @@ index 5b5aaaa..7c07048 100644 static netsnmp_void_array *_cert_find_subset_fn(const char *filename, const char *directory); static netsnmp_void_array *_cert_find_subset_sn(const char *subject); -@@ -200,7 +202,7 @@ _setup_trusted_certs(void) - return; - } - _trusted_certs->container_name = strdup("trusted certificates"); -- _trusted_certs->compare = netsnmp_str_compare; -+ _trusted_certs->compare = (netsnmp_container_compare*) strcmp; - } - - /* -@@ -345,14 +347,18 @@ _get_cert_container(const char *use) +@@ -345,6 +347,8 @@ _get_cert_container(const char *use) { netsnmp_container *c; @@ -105,61 +65,49 @@ index 5b5aaaa..7c07048 100644 c = netsnmp_container_find("certs:binary_array"); if (NULL == c) { snmp_log(LOG_ERR, "could not create container for %s\n", use); - return NULL; - } - c->container_name = strdup(use); -- c->free_item = _cert_free; -- c->compare = _cert_compare; -+ c->free_item = (netsnmp_container_obj_func*)_cert_free; -+ c->compare = (netsnmp_container_compare*)_cert_compare; -+ -+ CONTAINER_SET_OPTIONS(c, CONTAINER_KEY_ALLOW_DUPLICATES, rc); +@@ -354,6 +358,8 @@ _get_cert_container(const char *use) + c->free_item = (netsnmp_container_obj_func*)_cert_free; + c->compare = (netsnmp_container_compare*)_cert_compare; ++ CONTAINER_SET_OPTIONS(c, CONTAINER_KEY_ALLOW_DUPLICATES, rc); ++ return c; } -@@ -377,7 +383,7 @@ _setup_containers(void) - } + +@@ -362,6 +368,8 @@ _setup_containers(void) + { + netsnmp_container *additional_keys; + ++ int rc; ++ + _certs = _get_cert_container("netsnmp certificates"); + if (NULL == _certs) + return; +@@ -376,6 +384,7 @@ _setup_containers(void) additional_keys->container_name = strdup("certs_cn"); additional_keys->free_item = NULL; -- additional_keys->compare = _cert_cn_compare; -+ additional_keys->compare = (netsnmp_container_compare*)_cert_cn_compare; - CONTAINER_SET_OPTIONS(additional_keys, CONTAINER_KEY_ALLOW_DUPLICATES, rc); + additional_keys->compare = (netsnmp_container_compare*)_cert_cn_compare; ++ CONTAINER_SET_OPTIONS(additional_keys, CONTAINER_KEY_ALLOW_DUPLICATES, rc); netsnmp_container_add_index(_certs, additional_keys); -@@ -390,8 +396,8 @@ _setup_containers(void) - } - additional_keys->container_name = strdup("certs_sn"); + /** additional keys: subject name */ +@@ -389,6 +398,7 @@ _setup_containers(void) additional_keys->free_item = NULL; -- additional_keys->compare = _cert_sn_compare; -- additional_keys->ncompare = _cert_sn_ncompare; -+ additional_keys->compare = (netsnmp_container_compare*)_cert_sn_compare; -+ additional_keys->ncompare = (netsnmp_container_compare*)_cert_sn_ncompare; - CONTAINER_SET_OPTIONS(additional_keys, CONTAINER_KEY_ALLOW_DUPLICATES, rc); + additional_keys->compare = (netsnmp_container_compare*)_cert_sn_compare; + additional_keys->ncompare = (netsnmp_container_compare*)_cert_sn_ncompare; ++ CONTAINER_SET_OPTIONS(additional_keys, CONTAINER_KEY_ALLOW_DUPLICATES, rc); netsnmp_container_add_index(_certs, additional_keys); -@@ -404,8 +410,8 @@ _setup_containers(void) - } - additional_keys->container_name = strdup("certs_fn"); + /** additional keys: file name */ +@@ -402,6 +412,7 @@ _setup_containers(void) additional_keys->free_item = NULL; -- additional_keys->compare = _cert_fn_compare; -- additional_keys->ncompare = _cert_fn_ncompare; -+ additional_keys->compare = (netsnmp_container_compare*)_cert_fn_compare; -+ additional_keys->ncompare = (netsnmp_container_compare*)_cert_fn_ncompare; - CONTAINER_SET_OPTIONS(additional_keys, CONTAINER_KEY_ALLOW_DUPLICATES, rc); + additional_keys->compare = (netsnmp_container_compare*)_cert_fn_compare; + additional_keys->ncompare = (netsnmp_container_compare*)_cert_fn_ncompare; ++ CONTAINER_SET_OPTIONS(additional_keys, CONTAINER_KEY_ALLOW_DUPLICATES, rc); netsnmp_container_add_index(_certs, additional_keys); -@@ -416,8 +422,8 @@ _setup_containers(void) - return; - } - _keys->container_name = strdup("netsnmp certificate keys"); -- _keys->free_item = _key_free; -- _keys->compare = _cert_fn_compare; -+ _keys->free_item = (netsnmp_container_obj_func*)_key_free; -+ _keys->compare = (netsnmp_container_compare*)_cert_fn_compare; - - _setup_trusted_certs(); - } -@@ -429,7 +435,7 @@ netsnmp_cert_map_container(void) + _keys = netsnmp_container_find("cert_keys:binary_array"); +@@ -424,7 +435,7 @@ netsnmp_cert_map_container(void) } static netsnmp_cert * @@ -168,7 +116,7 @@ index 5b5aaaa..7c07048 100644 int hashType, const char *fingerprint, const char *common_name, const char *subject) { -@@ -451,8 +457,10 @@ _new_cert(const char *dirname, const char *filename, int certType, +@@ -446,8 +457,10 @@ _new_cert(const char *dirname, const char *filename, int certType, cert->info.dir = strdup(dirname); cert->info.filename = strdup(filename); @@ -180,112 +128,7 @@ index 5b5aaaa..7c07048 100644 if (fingerprint) { cert->hash_type = hashType; cert->fingerprint = strdup(fingerprint); -@@ -553,22 +561,20 @@ netsnmp_key_free(netsnmp_key *key) - } - - static void --_cert_free(void *cert, void *context) -+_cert_free(netsnmp_cert *cert, void *context) - { - netsnmp_cert_free(cert); - } - - static void --_key_free(void *key, void *context) -+_key_free(netsnmp_key *key, void *context) - { - netsnmp_key_free(key); - } - - static int --_cert_compare(const void *p, const void *q) -+_cert_compare(netsnmp_cert *lhs, netsnmp_cert *rhs) - { -- const netsnmp_cert *lhs = p, *rhs = q; -- - netsnmp_assert((lhs != NULL) && (rhs != NULL)); - netsnmp_assert((lhs->fingerprint != NULL) && - (rhs->fingerprint != NULL)); -@@ -578,8 +584,7 @@ _cert_compare(const void *p, const void *q) - } - - static int --_cert_path_compare(const netsnmp_cert_common *lhs, -- const netsnmp_cert_common *rhs) -+_cert_path_compare(netsnmp_cert_common *lhs, netsnmp_cert_common *rhs) - { - int rc; - -@@ -595,9 +600,8 @@ _cert_path_compare(const netsnmp_cert_common *lhs, - } - - static int --_cert_cn_compare(const void *p, const void *q) -+_cert_cn_compare(netsnmp_cert *lhs, netsnmp_cert *rhs) - { -- const netsnmp_cert *lhs = p, *rhs = q; - int rc; - const char *lhcn, *rhcn; - -@@ -617,13 +621,13 @@ _cert_cn_compare(const void *p, const void *q) - return rc; - - /** in case of equal common names, sub-sort by path */ -- return _cert_path_compare(&lhs->info, &rhs->info); -+ return _cert_path_compare((netsnmp_cert_common*)lhs, -+ (netsnmp_cert_common*)rhs); - } - - static int --_cert_sn_compare(const void *p, const void *q) -+_cert_sn_compare(netsnmp_cert *lhs, netsnmp_cert *rhs) - { -- const netsnmp_cert *lhs = p, *rhs = q; - int rc; - const char *lhsn, *rhsn; - -@@ -643,13 +647,13 @@ _cert_sn_compare(const void *p, const void *q) - return rc; - - /** in case of equal common names, sub-sort by path */ -- return _cert_path_compare(&lhs->info, &rhs->info); -+ return _cert_path_compare((netsnmp_cert_common*)lhs, -+ (netsnmp_cert_common*)rhs); - } - - static int --_cert_fn_compare(const void *p, const void *q) -+_cert_fn_compare(netsnmp_cert_common *lhs, netsnmp_cert_common *rhs) - { -- const netsnmp_cert_common *lhs = p, *rhs = q; - int rc; - - netsnmp_assert((lhs != NULL) && (rhs != NULL)); -@@ -663,10 +667,8 @@ _cert_fn_compare(const void *p, const void *q) - } - - static int --_cert_fn_ncompare(const void *p, const void *q) -+_cert_fn_ncompare(netsnmp_cert_common *lhs, netsnmp_cert_common *rhs) - { -- const netsnmp_cert_common *lhs = p, *rhs = q; -- - netsnmp_assert((lhs != NULL) && (rhs != NULL)); - netsnmp_assert((lhs->filename != NULL) && (rhs->filename != NULL)); - -@@ -674,10 +676,8 @@ _cert_fn_ncompare(const void *p, const void *q) - } - - static int --_cert_sn_ncompare(const void *p, const void *q) -+_cert_sn_ncompare(netsnmp_cert *lhs, netsnmp_cert *rhs) - { -- const netsnmp_cert *lhs = p, *rhs = q; -- - netsnmp_assert((lhs != NULL) && (rhs != NULL)); - netsnmp_assert((lhs->subject != NULL) && (rhs->subject != NULL)); - -@@ -897,14 +897,86 @@ _certindex_new( const char *dirname ) +@@ -884,14 +897,86 @@ _certindex_new( const char *dirname ) * certificate utility functions * */ @@ -374,7 +217,7 @@ index 5b5aaaa..7c07048 100644 if (NULL == cert) return NULL; -@@ -921,51 +993,33 @@ netsnmp_ocert_get(netsnmp_cert *cert) +@@ -908,51 +993,33 @@ netsnmp_ocert_get(netsnmp_cert *cert) } } @@ -434,7 +277,7 @@ index 5b5aaaa..7c07048 100644 if (NULL != okey) { netsnmp_key *key; DEBUGMSGT(("cert:read:key", "found key with cert in %s\n", -@@ -992,7 +1046,7 @@ netsnmp_ocert_get(netsnmp_cert *cert) +@@ -979,7 +1046,7 @@ netsnmp_ocert_get(netsnmp_cert *cert) break; #ifdef CERT_PKCS12_SUPPORT_MAYBE_LATER case NS_CERT_TYPE_PKCS12: @@ -443,7 +286,7 @@ index 5b5aaaa..7c07048 100644 PKCS12 *p12 = d2i_PKCS12_bio(certbio, NULL); if ( (NULL != p12) && (PKCS12_verify_mac(p12, "", 0) || PKCS12_verify_mac(p12, NULL, 0))) -@@ -1012,46 +1066,7 @@ netsnmp_ocert_get(netsnmp_cert *cert) +@@ -999,46 +1066,7 @@ netsnmp_ocert_get(netsnmp_cert *cert) return NULL; } @@ -477,7 +320,7 @@ index 5b5aaaa..7c07048 100644 - } - - if (NULL == cert->fingerprint) { -- cert->hash_type = NS_HASH_SHA1; +- cert->hash_type = netsnmp_openssl_cert_get_hash_type(ocert); - cert->fingerprint = - netsnmp_openssl_cert_get_fingerprint(ocert, cert->hash_type); - } @@ -491,7 +334,7 @@ index 5b5aaaa..7c07048 100644 return ocert; } -@@ -1061,7 +1076,6 @@ netsnmp_okey_get(netsnmp_key *key) +@@ -1048,7 +1076,6 @@ netsnmp_okey_get(netsnmp_key *key) { BIO *keybio; EVP_PKEY *okey; @@ -499,7 +342,7 @@ index 5b5aaaa..7c07048 100644 if (NULL == key) return NULL; -@@ -1069,19 +1083,8 @@ netsnmp_okey_get(netsnmp_key *key) +@@ -1056,19 +1083,8 @@ netsnmp_okey_get(netsnmp_key *key) if (key->okey) return key->okey; @@ -521,7 +364,7 @@ index 5b5aaaa..7c07048 100644 return NULL; } -@@ -1167,7 +1170,7 @@ netsnmp_cert_load_x509(netsnmp_cert *cert) +@@ -1154,7 +1170,7 @@ netsnmp_cert_load_x509(netsnmp_cert *cert) cert->issuer_cert = _find_issuer(cert); if (NULL == cert->issuer_cert) { DEBUGMSGT(("cert:load:warn", @@ -530,7 +373,7 @@ index 5b5aaaa..7c07048 100644 cert->info.filename)); rc = CERT_LOAD_PARTIAL; break; -@@ -1176,7 +1179,7 @@ netsnmp_cert_load_x509(netsnmp_cert *cert) +@@ -1163,7 +1179,7 @@ netsnmp_cert_load_x509(netsnmp_cert *cert) /** get issuer ocert */ if ((NULL == cert->issuer_cert->ocert) && (netsnmp_ocert_get(cert->issuer_cert) == NULL)) { @@ -539,7 +382,7 @@ index 5b5aaaa..7c07048 100644 cert->info.filename)); rc = CERT_LOAD_PARTIAL; break; -@@ -1197,7 +1200,7 @@ _find_partner(netsnmp_cert *cert, netsnmp_key *key) +@@ -1184,7 +1200,7 @@ _find_partner(netsnmp_cert *cert, netsnmp_key *key) return; } @@ -548,7 +391,7 @@ index 5b5aaaa..7c07048 100644 if (key->cert) { DEBUGMSGT(("cert:partner", "key already has partner\n")); return; -@@ -1210,7 +1213,8 @@ _find_partner(netsnmp_cert *cert, netsnmp_key *key) +@@ -1197,7 +1213,8 @@ _find_partner(netsnmp_cert *cert, netsnmp_key *key) return; *pos = 0; @@ -558,7 +401,7 @@ index 5b5aaaa..7c07048 100644 if (!matching) return; if (1 == matching->size) { -@@ -1230,7 +1234,7 @@ _find_partner(netsnmp_cert *cert, netsnmp_key *key) +@@ -1217,7 +1234,7 @@ _find_partner(netsnmp_cert *cert, netsnmp_key *key) DEBUGMSGT(("cert:partner", "%s matches multiple certs\n", key->info.filename)); } @@ -567,7 +410,7 @@ index 5b5aaaa..7c07048 100644 if (cert->key) { DEBUGMSGT(("cert:partner", "cert already has partner\n")); return; -@@ -1268,76 +1272,182 @@ _find_partner(netsnmp_cert *cert, netsnmp_key *key) +@@ -1255,76 +1272,182 @@ _find_partner(netsnmp_cert *cert, netsnmp_key *key) } } @@ -803,7 +646,7 @@ index 5b5aaaa..7c07048 100644 } return 0; -@@ -1351,7 +1461,8 @@ _cert_read_index(const char *dirname, struct stat *dirstat) +@@ -1338,7 +1461,8 @@ _cert_read_index(const char *dirname, struct stat *dirstat) struct stat idx_stat; char tmpstr[SNMP_MAXPATH + 5], filename[NAME_MAX]; char fingerprint[EVP_MAX_MD_SIZE*3], common_name[64+1], type_str[15]; @@ -813,7 +656,7 @@ index 5b5aaaa..7c07048 100644 int count = 0, type, hash, version; netsnmp_cert *cert; netsnmp_key *key; -@@ -1394,7 +1505,8 @@ _cert_read_index(const char *dirname, struct stat *dirstat) +@@ -1381,7 +1505,8 @@ _cert_read_index(const char *dirname, struct stat *dirstat) netsnmp_directory_container_read_some(NULL, dirname, _time_filter, &idx_stat, NETSNMP_DIR_NSFILE | @@ -823,7 +666,7 @@ index 5b5aaaa..7c07048 100644 if (newer) { DEBUGMSGT(("cert:index:parse", "Index outdated; files modified\n")); CONTAINER_FREE_ALL(newer, NULL); -@@ -1439,6 +1551,7 @@ _cert_read_index(const char *dirname, struct stat *dirstat) +@@ -1426,6 +1551,7 @@ _cert_read_index(const char *dirname, struct stat *dirstat) pos = &tmpstr[2]; if ((NULL == (pos=copy_nword(pos, filename, sizeof(filename)))) || (NULL == (pos=copy_nword(pos, type_str, sizeof(type_str)))) || @@ -831,7 +674,7 @@ index 5b5aaaa..7c07048 100644 (NULL == (pos=copy_nword(pos, hash_str, sizeof(hash_str)))) || (NULL == (pos=copy_nword(pos, fingerprint, sizeof(fingerprint)))) || -@@ -1451,8 +1564,9 @@ _cert_read_index(const char *dirname, struct stat *dirstat) +@@ -1438,8 +1564,9 @@ _cert_read_index(const char *dirname, struct stat *dirstat) break; } type = atoi(type_str); @@ -842,7 +685,7 @@ index 5b5aaaa..7c07048 100644 common_name, subject); if (cert && 0 == CONTAINER_INSERT(found, cert)) ++count; -@@ -1559,7 +1673,8 @@ _add_certdir(const char *dirname) +@@ -1546,7 +1673,8 @@ _add_certdir(const char *dirname) netsnmp_directory_container_read_some(NULL, dirname, _cert_cert_filter, NULL, NETSNMP_DIR_RELATIVE_PATH | @@ -852,15 +695,7 @@ index 5b5aaaa..7c07048 100644 if (NULL == cert_container) { DEBUGMSGT(("cert:index:dir", "error creating container for cert files\n")); -@@ -1642,14 +1757,12 @@ _cert_indexes_load(void) - } - - static void --_cert_print(void *p, void *context) -+_cert_print(netsnmp_cert *c, void *context) - { -- netsnmp_cert *c = p; -- +@@ -1634,7 +1762,7 @@ _cert_print(netsnmp_cert *c, void *context) if (NULL == c) return; @@ -869,39 +704,7 @@ index 5b5aaaa..7c07048 100644 DEBUGMSGT(("cert:dump", " type %d flags 0x%x (%s)\n", c->info.type, c->info.allowed_uses, _mode_str(c->info.allowed_uses))); -@@ -1676,10 +1789,8 @@ _cert_print(void *p, void *context) - } - - static void --_key_print(void *p, void *context) -+_key_print(netsnmp_key *k, void *context) - { -- netsnmp_key *k = p; -- - if (NULL == k) - return; - -@@ -1691,8 +1802,8 @@ _key_print(void *p, void *context) - void - netsnmp_cert_dump_all(void) - { -- CONTAINER_FOR_EACH(_certs, _cert_print, NULL); -- CONTAINER_FOR_EACH(_keys, _key_print, NULL); -+ CONTAINER_FOR_EACH(_certs, (netsnmp_container_obj_func*)_cert_print, NULL); -+ CONTAINER_FOR_EACH(_keys, (netsnmp_container_obj_func*)_key_print, NULL); - } - - #ifdef CERT_MAIN -@@ -1726,6 +1837,8 @@ main(int argc, char** argv) - - #endif /* CERT_MAIN */ - -+static netsnmp_cert *_cert_find_fp(const char *fingerprint); -+ - void - netsnmp_fp_lowercase_and_strip_colon(char *fp) - { -@@ -1853,7 +1966,8 @@ netsnmp_cert_find(int what, int where, void *hint) +@@ -1838,7 +1966,8 @@ netsnmp_cert_find(int what, int where, void *hint) netsnmp_void_array *matching; DEBUGMSGT(("cert:find:params", " hint = %s\n", (char *)hint)); @@ -911,16 +714,7 @@ index 5b5aaaa..7c07048 100644 if (!matching) return NULL; if (1 == matching->size) -@@ -2061,7 +2175,7 @@ netsnmp_cert_trust(SSL_CTX *ctx, netsnmp_cert *thiscert) - SNMPERR_GENERR); - - /* Put the certificate into the store */ -- fingerprint = netsnmp_openssl_cert_get_fingerprint(cert, NS_HASH_SHA1); -+ fingerprint = netsnmp_openssl_cert_get_fingerprint(cert, -1); - DEBUGMSGTL(("cert:trust", - "putting trusted cert %p = %s in certstore %p\n", cert, - fingerprint, certstore)); -@@ -2296,6 +2410,124 @@ _reduce_subset_dir(netsnmp_void_array *matching, const char *directory) +@@ -2281,6 +2410,124 @@ _reduce_subset_dir(netsnmp_void_array *matching, const char *directory) } } @@ -1045,95 +839,11 @@ index 5b5aaaa..7c07048 100644 static netsnmp_void_array * _cert_find_subset_common(const char *filename, netsnmp_container *container) { -@@ -2433,7 +2665,7 @@ _time_filter(const void *text, void *ctx) - * ***************************************************************************/ - #define MAP_CONFIG_TOKEN "certSecName" - static void _parse_map(const char *token, char *line); --static void _map_free(void *map, void *ctx); -+static void _map_free(netsnmp_cert_map* entry, void *ctx); - static void _purge_config_entries(void); - - static void -@@ -2538,16 +2770,14 @@ netsnmp_cert_map_find(netsnmp_cert_map *map) - #endif /* NETSNMP_FEATURE_REMOVE_CERT_MAP_FIND */ - - static void --_map_free(void *map, void *context) -+_map_free(netsnmp_cert_map *map, void *context) - { - netsnmp_cert_map_free(map); - } - - static int --_map_compare(const void *p, const void *q) -+_map_compare(netsnmp_cert_map *lhs, netsnmp_cert_map *rhs) - { -- const netsnmp_cert_map *lhs = p, *rhs = q; -- - netsnmp_assert((lhs != NULL) && (rhs != NULL)); - - if (lhs->priority < rhs->priority) -@@ -2559,11 +2789,9 @@ _map_compare(const void *p, const void *q) - } - - static int --_map_fp_compare(const void *p, const void *q) -+_map_fp_compare(netsnmp_cert_map *lhs, netsnmp_cert_map *rhs) - { -- const netsnmp_cert_map *lhs = p, *rhs = q; - int rc; -- - netsnmp_assert((lhs != NULL) && (rhs != NULL)); - - if ((rc = strcmp(lhs->fingerprint, rhs->fingerprint)) != 0) -@@ -2578,10 +2806,8 @@ _map_fp_compare(const void *p, const void *q) - } - - static int --_map_fp_ncompare(const void *p, const void *q) -+_map_fp_ncompare(netsnmp_cert_map *lhs, netsnmp_cert_map *rhs) - { -- const netsnmp_cert_map *lhs = p, *rhs = q; -- - netsnmp_assert((lhs != NULL) && (rhs != NULL)); - - return strncmp(lhs->fingerprint, rhs->fingerprint, -@@ -2600,8 +2826,8 @@ netsnmp_cert_map_container_create(int with_fp) - } - - chain_map->container_name = strdup("cert_map"); -- chain_map->free_item = _map_free; -- chain_map->compare = _map_compare; -+ chain_map->free_item = (netsnmp_container_obj_func*)_map_free; -+ chain_map->compare = (netsnmp_container_compare*)_map_compare; - - if (!with_fp) - return chain_map; -@@ -2617,8 +2843,8 @@ netsnmp_cert_map_container_create(int with_fp) - return NULL; - } - fp->container_name = strdup("cert2sn_fp"); -- fp->compare = _map_fp_compare; -- fp->ncompare = _map_fp_ncompare; -+ fp->compare = (netsnmp_container_compare*)_map_fp_compare; -+ fp->ncompare = (netsnmp_container_compare*)_map_fp_ncompare; - netsnmp_container_add_index(chain_map, fp); - - return chain_map; -@@ -2769,7 +2995,7 @@ netsnmp_certToTSN_parse_common(char **line) - map->fingerprint = strdup(buf); - } else { - map->fingerprint = -- netsnmp_openssl_cert_get_fingerprint(tmpcert->ocert, NS_HASH_SHA1); -+ netsnmp_openssl_cert_get_fingerprint(tmpcert->ocert, -1); - } - - if (NULL == *line) { diff --git a/snmplib/dir_utils.c b/snmplib/dir_utils.c -index 48c1a0f..32426f8 100644 +index c2dd989..e7145e4 100644 --- a/snmplib/dir_utils.c +++ b/snmplib/dir_utils.c -@@ -105,6 +105,9 @@ netsnmp_directory_container_read_some(netsnmp_container *user_container, +@@ -107,6 +107,9 @@ netsnmp_directory_container_read_some(netsnmp_container *user_container, /** default to unsorted */ if (! (flags & NETSNMP_DIR_SORTED)) CONTAINER_SET_OPTIONS(container, CONTAINER_KEY_UNSORTED, rc); diff --git a/net-snmp-5.9-mail-sender.patch b/net-snmp-5.9-mail-sender.patch deleted file mode 100644 index 2f6e28b..0000000 --- a/net-snmp-5.9-mail-sender.patch +++ /dev/null @@ -1,24 +0,0 @@ -diff -up ./local/checkbandwidth.orig ./local/checkbandwidth ---- ./local/checkbandwidth.orig 2023-08-15 16:32:01.000000000 -0400 -+++ ./local/checkbandwidth 2025-03-20 16:31:14.062432316 -0400 -@@ -326,7 +326,6 @@ See the Net-SNMP COPYING file for licens - - use JSON; - use Data::Dumper; --use Mail::Sender; - use SNMP; - use Fcntl ':flock'; - -@@ -744,6 +743,12 @@ sub send_rate_message($$$$$$) { - sub send_message($$$) { - my ($to, $subject, $text) = @_; - -+ if (! eval {require Mail::Sender;}) { -+ Log("Failed to send mail with error code -1: Mail::Sender is not available"); -+ return(); -+ } -+ -+ import Mail::Sender; - my $sender = new Mail::Sender { smtp => $opts{'S'} , - port => $opts{'P'}, - from => $opts{'F'}, diff --git a/net-snmp-5.9-multilib.patch b/net-snmp-5.9-multilib.patch index 2dfd9a6..ffd8da8 100644 --- a/net-snmp-5.9-multilib.patch +++ b/net-snmp-5.9-multilib.patch @@ -1,5 +1,5 @@ diff --git a/man/netsnmp_config_api.3.def b/man/netsnmp_config_api.3.def -index d4e0c1a..9e3a166 100644 +index 90b20d9..bd5abe1 100644 --- a/man/netsnmp_config_api.3.def +++ b/man/netsnmp_config_api.3.def @@ -295,7 +295,7 @@ for one particular machine. @@ -11,7 +11,7 @@ index d4e0c1a..9e3a166 100644 followed by \fC $HOME/.snmp\fP. This list can be changed by setting the environmental variable .I SNMPCONFPATH -@@ -367,7 +367,7 @@ A colon-separated list of directories to search for configuration +@@ -367,7 +367,7 @@ A colon separated list of directories to search for configuration files in. Default: .br @@ -34,10 +34,10 @@ index fd30873..c3437d6 100644 snmptrapd.conf, as well as snmp.local.conf, snmpd.local.conf and/or snmptrapd.local.conf. *.local.conf are always diff --git a/man/snmpd.conf.5.def b/man/snmpd.conf.5.def -index 6acd8c7..0a8b9fa 100644 +index 7ce8a46..a4000f9 100644 --- a/man/snmpd.conf.5.def +++ b/man/snmpd.conf.5.def -@@ -1609,7 +1609,7 @@ filename), and call the initialisation routine \fIinit_NAME\fR. +@@ -1593,7 +1593,7 @@ filename), and call the initialisation routine \fIinit_NAME\fR. .RS .IP "Note:" If the specified PATH is not a fully qualified filename, it will diff --git a/net-snmp-5.9-python3.patch b/net-snmp-5.9-python3.patch index c7eda61..98de4ca 100644 --- a/net-snmp-5.9-python3.patch +++ b/net-snmp-5.9-python3.patch @@ -1,5 +1,5 @@ diff --git a/Makefile.in b/Makefile.in -index bb4ada9..69ce4f0 100644 +index 912f6b2..862fb5f 100644 --- a/Makefile.in +++ b/Makefile.in @@ -227,7 +227,7 @@ perlcleanfeatures: diff --git a/net-snmp-5.9-rpmdb.patch b/net-snmp-5.9-rpmdb.patch new file mode 100644 index 0000000..d20d728 --- /dev/null +++ b/net-snmp-5.9-rpmdb.patch @@ -0,0 +1,65 @@ +From ed4ee14af5b83fa4a86dfaa783f841d3e8545ce4 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Josef=20=C5=98=C3=ADdk=C3=BD?= +Date: Wed, 9 Aug 2023 16:51:28 +0200 +Subject: [PATCH] Add support for RPM SQLite DB background. + +From RPM 4.16 the SQLite support is available for RPM DB. +After https://fedoraproject.org/wiki/Changes/Sqlite_Rpmdb, rpm changed +it's background DB from Berkeley to SQLite in Fedora. +Net-SNMP is using hard coded paths to determine where RPM DB files are. + +This update is adding check for rpmdb.sqlite file in order to be able +invalidate internal cache after system package change. + +Closes #596 +--- + agent/mibgroup/host/data_access/swinst_rpm.c | 18 +++++++++++++----- + agent/mibgroup/host/hr_swinst.c | 3 +++ + 2 files changed, 16 insertions(+), 5 deletions(-) + +diff --git a/agent/mibgroup/host/data_access/swinst_rpm.c b/agent/mibgroup/host/data_access/swinst_rpm.c +index 050edff307..7ad91a3194 100644 +--- a/agent/mibgroup/host/data_access/swinst_rpm.c ++++ b/agent/mibgroup/host/data_access/swinst_rpm.c +@@ -73,15 +73,23 @@ netsnmp_swinst_arch_init(void) + #endif + + snprintf( pkg_directory, SNMP_MAXPATH, "%s/Packages", dbpath ); ++ ++ if (-1 == stat( pkg_directory, &stat_buf )) { ++ ++ /* check for SQLite DB backend */ ++ snprintf( pkg_directory, SNMP_MAXPATH, "%s/rpmdb.sqlite", dbpath ); ++ ++ if (-1 == stat( pkg_directory, &stat_buf )) { ++ snmp_log(LOG_ERR, "Can't find directory of RPM packages\n"); ++ pkg_directory[0] = '\0'; ++ } ++ } ++ + SNMP_FREE(rpmdbpath); + dbpath = NULL; + #ifdef HAVE_RPMGETPATH + rpmFreeRpmrc(); +-#endif +- if (-1 == stat( pkg_directory, &stat_buf )) { +- snmp_log(LOG_ERR, "Can't find directory of RPM packages\n"); +- pkg_directory[0] = '\0'; +- } ++#endif + } + + void +diff -urNp a/agent/mibgroup/host/hr_swinst.c b/agent/mibgroup/host/hr_swinst.c +--- a/agent/mibgroup/host/hr_swinst.c 2023-07-31 11:37:44.855071535 +0200 ++++ b/agent/mibgroup/host/hr_swinst.c 2023-08-14 12:45:14.846357019 +0200 +@@ -229,6 +229,9 @@ init_hr_swinst(void) + snprintf(path, sizeof(path), "%s/Packages", swi->swi_dbpath); + if (stat(path, &stat_buf) == -1) + snprintf(path, sizeof(path), "%s/packages.rpm", swi->swi_dbpath); ++ /* check for SQLite DB backend */ ++ if (stat(path, &stat_buf) == -1) ++ snprintf(path, sizeof(path), "%s/rpmdb.sqlite", swi->swi_dbpath); + path[ sizeof(path)-1 ] = 0; + swi->swi_directory = strdup(path); + #ifdef HAVE_RPMGETPATH diff --git a/net-snmp-5.9.1-remove-des.patch b/net-snmp-5.9.1-remove-des.patch index 4618655..60fd30f 100644 --- a/net-snmp-5.9.1-remove-des.patch +++ b/net-snmp-5.9.1-remove-des.patch @@ -1,6 +1,6 @@ diff -urNp a/man/net-snmp-config.1.def b/man/net-snmp-config.1.def ---- a/man/net-snmp-config.1.def 2026-01-12 12:42:08.018134877 +0100 -+++ b/man/net-snmp-config.1.def 2026-01-12 12:43:26.749846227 +0100 +--- a/man/net-snmp-config.1.def 2021-05-26 09:30:07.430790003 +0200 ++++ b/man/net-snmp-config.1.def 2021-05-26 09:35:36.703673542 +0200 @@ -30,7 +30,7 @@ code for a list of available debug token SNMP Setup commands: .TP @@ -11,27 +11,27 @@ diff -urNp a/man/net-snmp-config.1.def b/man/net-snmp-config.1.def These options produce the various compilation flags needed when building external SNMP applications: diff -urNp a/man/net-snmp-create-v3-user.1.def b/man/net-snmp-create-v3-user.1.def ---- a/man/net-snmp-create-v3-user.1.def 2026-01-12 12:42:08.017134868 +0100 -+++ b/man/net-snmp-create-v3-user.1.def 2026-01-12 12:44:16.263005034 +0100 +--- a/man/net-snmp-create-v3-user.1.def 2021-05-26 09:30:07.430790003 +0200 ++++ b/man/net-snmp-create-v3-user.1.def 2021-05-26 09:34:23.702034230 +0200 @@ -3,7 +3,7 @@ net-snmp-create-v3-user \- create a SNMPv3 user in net-snmp configuration file .SH SYNOPSIS .PP --.B net-snmp-create-v3-user [-ro] [-A authpass] [-a MD5|SHA|SHA-512|SHA-384|SHA-256|SHA-224] [-X privpass] [-x DES|AES|AES128] -+.B net-snmp-create-v3-user [-ro] [-A authpass] [-a MD5|SHA|SHA-512|SHA-384|SHA-256|SHA-224] [-X privpass] [-x AES|AES128] +-.B net-snmp-create-v3-user [-ro] [-A authpass] [-a MD5|SHA] [-X privpass] [-x DES|AES] ++.B net-snmp-create-v3-user [-ro] [-A authpass] [-a MD5|SHA] [-X privpass] [-x AES] .B [username] .SH DESCRIPTION .PP -@@ -27,5 +27,5 @@ specify authentication algorithm +@@ -27,5 +27,5 @@ specifies the authentication password ha \fB\-X privpass\fR - specify encryption password + specifies the encryption password .TP --\fB\-x DES|AES|AES128\fR -+\fB\-x AES|AES128\fR - specify encryption algorithm +-\fB\-x DES|AES\fR ++\fB\-x AES\fR + specifies the encryption algorithm diff -urNp a/man/snmpcmd.1.def b/man/snmpcmd.1.def ---- a/man/snmpcmd.1.def 2026-01-12 12:42:08.016788741 +0100 -+++ b/man/snmpcmd.1.def 2026-01-12 12:45:15.040041004 +0100 +--- a/man/snmpcmd.1.def 2021-05-26 09:30:07.429789994 +0200 ++++ b/man/snmpcmd.1.def 2021-05-26 09:37:51.104850500 +0200 @@ -311,7 +311,7 @@ Overrides the \fIdefSecurityName\fR toke file. .TP @@ -42,8 +42,8 @@ diff -urNp a/man/snmpcmd.1.def b/man/snmpcmd.1.def .I snmp.conf file. This option is only valid if the Net-SNMP software was build diff -urNp a/man/snmp.conf.5.def b/man/snmp.conf.5.def ---- a/man/snmp.conf.5.def 2026-01-12 12:42:08.018134877 +0100 -+++ b/man/snmp.conf.5.def 2026-01-12 12:47:26.967780683 +0100 +--- a/man/snmp.conf.5.def 2021-05-26 09:30:07.429789994 +0200 ++++ b/man/snmp.conf.5.def 2021-05-26 09:40:03.730011937 +0200 @@ -221,13 +221,13 @@ The value will be used for the authentication and/or privacy pass phrases if either of the other directives are not specified. @@ -71,8 +71,8 @@ diff -urNp a/man/snmp.conf.5.def b/man/snmp.conf.5.def Sets the path of the \fBsshtosnmp\fR socket created by an application (e.g. snmpd) listening for incoming ssh connections through the diff -urNp a/man/snmpd.examples.5.def b/man/snmpd.examples.5.def ---- a/man/snmpd.examples.5.def 2026-01-12 12:42:08.016788741 +0100 -+++ b/man/snmpd.examples.5.def 2026-01-12 12:48:02.264211991 +0100 +--- a/man/snmpd.examples.5.def 2021-05-26 09:30:07.429789994 +0200 ++++ b/man/snmpd.examples.5.def 2021-05-26 09:41:29.170761436 +0200 @@ -87,8 +87,8 @@ the same authentication and encryption s .RS .nf @@ -85,8 +85,8 @@ diff -urNp a/man/snmpd.examples.5.def b/man/snmpd.examples.5.def .RE Note that this defines three \fIdistinct\fR users, who could be granted diff -urNp a/man/snmptrapd.conf.5.def b/man/snmptrapd.conf.5.def ---- a/man/snmptrapd.conf.5.def 2026-01-12 12:42:08.018134877 +0100 -+++ b/man/snmptrapd.conf.5.def 2026-01-12 12:48:43.264773008 +0100 +--- a/man/snmptrapd.conf.5.def 2021-05-26 09:30:07.428789985 +0200 ++++ b/man/snmptrapd.conf.5.def 2021-05-26 09:42:02.963064029 +0200 @@ -117,7 +117,7 @@ to trigger the types of processing liste See .IR snmpd.conf (5) @@ -97,8 +97,8 @@ diff -urNp a/man/snmptrapd.conf.5.def b/man/snmptrapd.conf.5.def .IR snmpd.conf (5) manual page for a description of how to create SNMPv3 users. This diff -urNp a/man/snmpusm.1.def b/man/snmpusm.1.def ---- a/man/snmpusm.1.def 2026-01-12 12:42:08.018134877 +0100 -+++ b/man/snmpusm.1.def 2026-01-12 12:49:26.488017367 +0100 +--- a/man/snmpusm.1.def 2021-05-26 09:30:07.430790003 +0200 ++++ b/man/snmpusm.1.def 2021-05-26 09:42:24.178253990 +0200 @@ -216,7 +216,7 @@ rwuser initial # lets add the new user we'll create too: rwuser wes @@ -109,9 +109,9 @@ diff -urNp a/man/snmpusm.1.def b/man/snmpusm.1.def .RE .PP diff -urNp a/net-snmp-create-v3-user.in b/net-snmp-create-v3-user.in ---- a/net-snmp-create-v3-user.in 2026-01-12 12:42:08.102135636 +0100 -+++ b/net-snmp-create-v3-user.in 2026-01-12 12:50:35.760787628 +0100 -@@ -10,7 +10,7 @@ if @PSCMD@ | @EGREP@ ' snmpd *$' > /dev/ +--- a/net-snmp-create-v3-user.in 2021-05-26 09:30:07.369789468 +0200 ++++ b/net-snmp-create-v3-user.in 2021-05-26 09:33:23.966511123 +0200 +@@ -10,7 +10,7 @@ if @PSCMD@ | egrep ' snmpd *$' > /dev/nu fi Aalgorithm="MD5" @@ -138,14 +138,14 @@ diff -urNp a/net-snmp-create-v3-user.in b/net-snmp-create-v3-user.in echo "" echo "Usage:" echo " net-snmp-create-v3-user [-ro] [-A authpass] [-X privpass]" -- echo " [-a MD5|SHA|SHA-512|SHA-384|SHA-256|SHA-224] [-x DES|AES|AES128] [username]" -+ echo " [-a MD5|SHA|SHA-512|SHA-384|SHA-256|SHA-224] [-x AES|AES128] [username]" +- echo " [-a MD5|SHA|SHA-512|SHA-384|SHA-256|SHA-224] [-x DES|AES] [username]" ++ echo " [-a MD5|SHA|SHA-512|SHA-384|SHA-256|SHA-224] [-x AES] [username]" echo "" exit fi diff -urNp a/README.snmpv3 b/README.snmpv3 ---- a/README.snmpv3 2026-01-12 12:42:08.021134904 +0100 -+++ b/README.snmpv3 2026-01-12 12:51:58.767903013 +0100 +--- a/README.snmpv3 2021-05-26 09:30:07.352789320 +0200 ++++ b/README.snmpv3 2021-05-26 09:44:49.109551728 +0200 @@ -4,7 +4,7 @@ How to setup SNMPv3, a very brief docume do a better job on since I suck at writing documentation and he doesn't ;-) --Wes: diff --git a/net-snmp-5.9.4-revert-n-snmptrapd-log.patch b/net-snmp-5.9.4-revert-n-snmptrapd-log.patch deleted file mode 100644 index 981097b..0000000 --- a/net-snmp-5.9.4-revert-n-snmptrapd-log.patch +++ /dev/null @@ -1,13 +0,0 @@ -diff --git a/apps/snmptrapd_log.c b/apps/snmptrapd_log.c -index 067c7f6..e6f0f1e 100644 ---- a/apps/snmptrapd_log.c -+++ b/apps/snmptrapd_log.c -@@ -596,7 +596,7 @@ realloc_handle_time_fmt(u_char ** buf, size_t * buf_len, size_t * out_len, - static - void convert_agent_addr(struct in_addr agent_addr, char *name, size_t size) - { -- const int numeric = !netsnmp_ds_get_boolean(NETSNMP_DS_APPLICATION_ID, -+ const int numeric = netsnmp_ds_get_boolean(NETSNMP_DS_APPLICATION_ID, - NETSNMP_DS_APP_NUMERIC_IP); - struct sockaddr_in sin; - diff --git a/net-snmp-5.9.4-tls.patch b/net-snmp-5.9.4-tls.patch deleted file mode 100644 index 1f46abb..0000000 --- a/net-snmp-5.9.4-tls.patch +++ /dev/null @@ -1,150 +0,0 @@ -diff --git a/include/net-snmp/library/default_store.h b/include/net-snmp/library/default_store.h -index 1b1978e..dd590be 100644 ---- a/include/net-snmp/library/default_store.h -+++ b/include/net-snmp/library/default_store.h -@@ -183,6 +183,8 @@ extern "C" { - #define NETSNMP_DS_LIB_SSH_PUBKEY 33 - #define NETSNMP_DS_LIB_SSH_PRIVKEY 34 - #define NETSNMP_DS_LIB_OUTPUT_PRECISION 35 -+#define NETSNMP_DS_LIB_TLS_MIN_VERSION 36 -+#define NETSNMP_DS_LIB_TLS_MAX_VERSION 37 - #define NETSNMP_DS_LIB_MAX_STR_ID 48 /* match NETSNMP_DS_MAX_SUBIDS */ - - /* -diff --git a/man/snmpd.conf.5.def b/man/snmpd.conf.5.def -index 0a8b9fa..d9641cc 100644 ---- a/man/snmpd.conf.5.def -+++ b/man/snmpd.conf.5.def -@@ -203,6 +203,12 @@ HIGH:!AES128\-SHA - .RE - .IP - The default value is whatever openssl itself was configured with. -+.IP "tlsMinVersion STRING" -+The function sets the minimum supported TLS protocol version. -+OPTION can be one of < tls1 | tls1_1| tls1_2 | tls1_3 >. -+.IP "tlsMaxVersion STRING" -+The function sets the maximum supported TLS protocol version. -+OPTION can be one of < tls1 | tls1_1| tls1_2 | tls1_3 >. - .IP "[snmp] x509CRLFile" - If you are using a Certificate Authority (CA) that publishes a - Certificate Revocation List (CRL) then this token can be used to -diff --git a/snmplib/transports/snmpTLSBaseDomain.c b/snmplib/transports/snmpTLSBaseDomain.c -index e301de4..7ae2db7 100644 ---- a/snmplib/transports/snmpTLSBaseDomain.c -+++ b/snmplib/transports/snmpTLSBaseDomain.c -@@ -490,6 +490,9 @@ SSL_CTX * - _sslctx_common_setup(SSL_CTX *the_ctx, _netsnmpTLSBaseData *tlsbase) { - char *crlFile; - char *cipherList; -+ char *tlsMinVersion; -+ char *tlsMaxVersion; -+ int tlsVersion; - X509_LOOKUP *lookup; - X509_STORE *cert_store = NULL; - -@@ -513,6 +516,63 @@ _sslctx_common_setup(SSL_CTX *the_ctx, _netsnmpTLSBaseData *tlsbase) { - X509_V_FLAG_CRL_CHECK | X509_V_FLAG_CRL_CHECK_ALL); - } - -+#ifdef SSL_CTX_set_min_proto_version -+ tlsVersion = TLS1_2_VERSION; -+ tlsMinVersion = "tls1_2"; -+ tlsMinVersion = netsnmp_ds_get_string(NETSNMP_DS_LIBRARY_ID, -+ NETSNMP_DS_LIB_TLS_MIN_VERSION); -+ if (NULL != tlsMinVersion) { -+ if (strcmp("tls1",tlsMinVersion) == 0) { -+ tlsVersion = TLS1_VERSION; -+ } -+ else if (strcmp("tls1_1",tlsMinVersion) == 0) { -+ tlsVersion = TLS1_1_VERSION; -+ } -+ else if (strcmp("tls1_2",tlsMinVersion) == 0) { -+ tlsVersion = TLS1_2_VERSION; -+ } -+ else if (strcmp("tls1_3",tlsMinVersion) == 0) { -+ tlsVersion = TLS1_3_VERSION; -+ } -+ else { -+ LOGANDDIE("Invalid tlsMinVersion value"); -+ } -+ } -+ if (1 == SSL_CTX_set_min_proto_version(the_ctx, tlsVersion)) { -+ snmp_log(LOG_INFO,"Set tlsMinVersion to '%s'\n", tlsMinVersion); -+ } -+ else { -+ LOGANDDIE("Set tlsMinVersion failed"); -+ } -+ tlsVersion = TLS1_3_VERSION; -+ tlsMaxVersion = "tls1_3"; -+ tlsMaxVersion = netsnmp_ds_get_string(NETSNMP_DS_LIBRARY_ID, -+ NETSNMP_DS_LIB_TLS_MAX_VERSION); -+ if (NULL != tlsMaxVersion) { -+ if (strcmp("tls1",tlsMaxVersion) == 0) { -+ tlsVersion = TLS1_VERSION; -+ } -+ else if (strcmp("tls1_1",tlsMaxVersion) == 0) { -+ tlsVersion = TLS1_1_VERSION; -+ } -+ else if (strcmp("tls1_2",tlsMaxVersion) == 0) { -+ tlsVersion = TLS1_2_VERSION; -+ } -+ else if (strcmp("tls1_3",tlsMaxVersion) == 0) { -+ tlsVersion = TLS1_3_VERSION; -+ } -+ else { -+ LOGANDDIE("Invalid tlsMaxVersion value"); -+ } -+ } -+ if (1 == SSL_CTX_set_max_proto_version(the_ctx, tlsVersion)) { -+ snmp_log(LOG_INFO,"Set tlsMaxVersion to '%s'\n", tlsMaxVersion); -+ } -+ else { -+ LOGANDDIE("Set tlsMaxVersion failed"); -+ } -+#endif -+ - cipherList = netsnmp_ds_get_string(NETSNMP_DS_LIBRARY_ID, - NETSNMP_DS_LIB_TLS_ALGORITMS); - if (NULL != cipherList) { -@@ -858,6 +918,15 @@ netsnmp_tlsbase_ctor(void) { - NETSNMP_DS_LIBRARY_ID, - NETSNMP_DS_LIB_TLS_ALGORITMS); - -+ /* What TLS version should be used at least */ -+ netsnmp_ds_register_config(ASN_OCTET_STR, "snmp", "tlsMinVersion", -+ NETSNMP_DS_LIBRARY_ID, -+ NETSNMP_DS_LIB_TLS_MIN_VERSION); -+ /* What TLS version should be used at max */ -+ netsnmp_ds_register_config(ASN_OCTET_STR, "snmp", "tlsMaxVersion", -+ NETSNMP_DS_LIBRARY_ID, -+ NETSNMP_DS_LIB_TLS_MAX_VERSION); -+ - /* - * for the client - */ -diff --git a/snmplib/transports/snmpTLSTCPDomain.c b/snmplib/transports/snmpTLSTCPDomain.c -index 0ddf023..e0133f9 100644 ---- a/snmplib/transports/snmpTLSTCPDomain.c -+++ b/snmplib/transports/snmpTLSTCPDomain.c -@@ -718,10 +718,6 @@ netsnmp_tlstcp_open_client(netsnmp_transport *t) - return NULL; - } - --#ifdef SSL_CTX_set_max_proto_version -- SSL_CTX_set_max_proto_version(tlsdata->ssl_context, 0); --#endif -- - /* RFC5953 Section 5.3.1: Establishing a Session as a Client - 3) Using the destTransportDomain and destTransportAddress values, - the client will initiate the (D)TLS handshake protocol to -@@ -917,10 +913,6 @@ netsnmp_tlstcp_open_server(netsnmp_transport *t) - - /* create the OpenSSL TLS context */ - tlsdata->ssl_context = sslctx_server_setup(TLS_method()); --#ifdef SSL_CTX_set_max_proto_version -- if (tlsdata->ssl_context) -- SSL_CTX_set_max_proto_version(tlsdata->ssl_context, 0); --#endif - - t->sock = BIO_get_fd(tlsdata->accept_bio, NULL); - t->flags |= NETSNMP_TRANSPORT_FLAG_LISTEN; diff --git a/net-snmp.spec b/net-snmp.spec index c762558..6103067 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -5,15 +5,15 @@ %global multilib_arches %{ix86} ia64 ppc ppc64 s390 s390x x86_64 sparc sparcv9 sparc64 aarch64 # actual soname version -%global soname 45 +%global soname 40 Summary: A collection of SNMP protocol tools and libraries Name: net-snmp -Version: 5.9.5.2 -Release: 10%{?dist} +Version: 5.9.4 +Release: 1%{?dist} Epoch: 1 -License: MIT-CMU AND BSD-3-Clause AND MIT +License: Net-SNMP and OpenSSL URL: http://net-snmp.sourceforge.net/ Source0: https://downloads.sourceforge.net/project/net-snmp/net-snmp/%{version}/net-snmp-%{version}.tar.gz Source1: net-snmp.redhat.conf @@ -36,18 +36,20 @@ Patch6: net-snmp-5.9-cflags.patch Patch7: net-snmp-5.8-Remove-U64-typedef.patch Patch8: net-snmp-5.7.3-iterator-fix.patch Patch9: net-snmp-5.9-autofs-skip.patch +Patch10: net-snmp-5.9-coverity.patch Patch11: net-snmp-5.8-expand-SNMPCONFPATH.patch Patch12: net-snmp-5.8-duplicate-ipAddress.patch Patch13: net-snmp-5.9-memory-reporting.patch +Patch14: net-snmp-5.8-man-page.patch Patch15: net-snmp-5.8-ipAddress-faster-load.patch +Patch16: net-snmp-5.8-rpm-memory-leak.patch Patch17: net-snmp-5.9-aes-config.patch Patch18: net-snmp-5.8-clientaddr-error-message.patch Patch19: net-snmp-5.9-intermediate-certs.patch Patch20: net-snmp-5.9.1-remove-des.patch Patch21: net-snmp-libs-misunderstanding.patch Patch22: net-snmp-5.9-ipv6-disable-leak.patch -Patch26: net-snmp-5.9.4-tls.patch -Patch27: net-snmp-5.9.4-revert-n-snmptrapd-log.patch +Patch23: net-snmp-5.9-rpmdb.patch # Modern RPM API means at least EL6 Patch101: net-snmp-5.8-modern-rpm-api.patch @@ -55,12 +57,6 @@ Patch101: net-snmp-5.8-modern-rpm-api.patch #disable this patch due compatibility issues Patch102: net-snmp-5.9-python3.patch -# make Mail::Sender optional -Patch103: net-snmp-5.9-mail-sender.patch - -# Openssl 4 build fixes -Patch104: 0001-Use-OpenSSL-accessors-for-opaque-structs.patch - Requires: %{name}-libs%{?_isa} = %{epoch}:%{version}-%{release} Requires: %{name}-agent-libs%{?_isa} = %{epoch}:%{version}-%{release} # This is actually needed for the %%triggerun script but Requires(triggerun) @@ -68,7 +64,6 @@ Requires: %{name}-agent-libs%{?_isa} = %{epoch}:%{version}-%{release} # should fire just after this package is installed. %{?systemd_requires} BuildRequires: make -BuildRequires: libxcrypt-devel BuildRequires: systemd BuildRequires: gcc BuildRequires: openssl-devel, bzip2-devel, elfutils-devel @@ -77,7 +72,6 @@ BuildRequires: perl-devel, perl(ExtUtils::Embed), procps BuildRequires: python3-devel, python3-setuptools BuildRequires: chrpath BuildRequires: mariadb-connector-c-devel -BuildRequires: libnl3-devel # for netstat, needed by 'make test' BuildRequires: net-tools # for make test @@ -92,8 +86,10 @@ BuildRequires: perl(strict) BuildRequires: perl(TAP::Harness) BuildRequires: perl(vars) BuildRequires: perl(warnings) +%ifnarch s390 s390x ppc64le BuildRequires: lm_sensors-devel >= 3 -BuildRequires: autoconf, automake, libtool +%endif +BuildRequires: autoconf, automake %description SNMP (Simple Network Management Protocol) is a protocol used for @@ -125,8 +121,9 @@ Requires: %{name}-libs%{?_isa} = %{epoch}:%{version}-%{release} Requires: %{name}-agent-libs%{?_isa} = %{epoch}:%{version}-%{release} Requires: elfutils-devel, rpm-devel, elfutils-libelf-devel, openssl-devel Requires: redhat-rpm-config -Requires: libnl3-devel +%ifnarch s390 s390x ppc64le Requires: lm_sensors-devel +%endif # pull perl development libraries, net-snmp agent libraries may link to them Requires: perl-devel%{?_isa} @@ -228,37 +225,31 @@ cp %{SOURCE10} . %patch 7 -p1 -b .u64-remove %patch 8 -p1 -b .iterator-fix %patch 9 -p1 -b .autofs-skip +%patch 10 -p1 -b .coverity %patch 11 -p1 -b .expand-SNMPCONFPATH %patch 12 -p1 -b .duplicate-ipAddress %patch 13 -p1 -b .memory-reporting +%patch 14 -p1 -b .man-page %patch 15 -p1 -b .ipAddress-faster-load +%patch 16 -p1 -b .rpm-memory-leak %patch 17 -p1 -b .aes-config %patch 18 -p1 -b .clientaddr-error-message %patch 19 -p1 -b .intermediate-certs %patch 20 -p1 -b .remove-des %patch 21 -p1 %patch 22 -p1 -b .ipv6-disable-leak -%patch 26 -p1 -b .tls -%patch 27 -p1 -b .revert-n-snmptrapd-log +%patch 23 -p1 -b .rpmdbpatch %patch 101 -p1 -b .modern-rpm-api %patch 102 -p1 -%if 0%{?rhel} -%patch 103 -p1 -%endif -%patch 104 -p1 # disable failing test - see https://bugzilla.redhat.com/show_bug.cgi?id=680697 rm testing/fulltests/default/T200* -# Autoreconf is run during build, which may be a different version than upstream used, -# resulting in a mismatch during "Checking the Net-SNMP configure script validity" test -autoconf --version | awk 'NR==1 {print $4}' > dist/autoconf-version - %build # Autoreconf to get autoconf 2.69 for ARM (#926223) -autoreconf -fiv +autoreconf MIBS="host agentx smux \ ucd-snmp/diskio tcp-mib udp-mib mibII/mta_sendmail \ @@ -266,7 +257,12 @@ MIBS="host agentx smux \ ip-mib/ipAddressPrefixTable/ipAddressPrefixTable \ ip-mib/ipDefaultRouterTable/ipDefaultRouterTable \ ip-mib/ipv6ScopeZoneIndexTable ip-mib/ipIfStatsTable \ - sctp-mib rmon-mib etherlike-mib ucd-snmp/lmsensorsMib" + sctp-mib rmon-mib etherlike-mib" + +%ifnarch s390 s390x ppc64le +# there are no lm_sensors on s390 +MIBS="$MIBS ucd-snmp/lmsensorsMib" +%endif %configure \ --disable-static --enable-shared \ @@ -435,8 +431,7 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %config(noreplace) %attr(0600,root,root) %{_sysconfdir}/snmp/snmptrapd.conf %{_bindir}/snmpconf %{_bindir}/net-snmp-create-v3-user -%{_sbindir}/snmpd -%{_sbindir}/snmptrapd +%{_sbindir}/* %attr(0644,root,root) %{_mandir}/man[58]/snmp*d* %attr(0644,root,root) %{_mandir}/man5/snmp_config.5.gz %attr(0644,root,root) %{_mandir}/man5/variables* @@ -514,88 +509,6 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog -* Fri Jul 24 2026 Python Maint - 1:5.9.5.2-10 -- Rebuilt for Python 3.15.0b4 ABI change - -* Thu Jul 23 2026 Jitka Plesnikova - 1:5.9.5.2-9 -- Perl 5.44 rebuild - -* Wed Jul 22 2026 Python Maint - 1:5.9.5.2-8 -- Rebuilt for Python 3.15.0b4 ABI change - -* Thu Jul 16 2026 Fedora Release Engineering - 1:5.9.5.2-7 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild - -* Fri Jun 12 2026 Simo Sorce - 1:5.9.5.2-6 -- Openssl 4 and autoconf build fixes - -* Wed Jun 03 2026 Python Maint - 1:5.9.5.2-5 -- Rebuilt for Python 3.15 - -* Thu Jan 29 2026 Yaakov Selkowitz - 1:5.9.5.2-4 -- Add net-snmp-devel dependency on libnl3-devel - -* Fri Jan 16 2026 Fedora Release Engineering - 1:5.9.5.2-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild - -* Mon Jan 12 2026 Yaakov Selkowitz - 1:5.9.5.2-2 -- Enable lm_sensors on all arches - -* Mon Jan 12 2026 Josef Ridky - 1:5.9.5.2-1 -- New upstream release 5.9.5.2 - -* Mon Oct 13 2025 Josef Ridky - 1:5.9.4-18 -- Enable PQC in net-snmp -- Fix inverted use of -n in snmptrapd_log.c - -* Fri Sep 19 2025 Python Maint - 1:5.9.4-17 -- Rebuilt for Python 3.14.0rc3 bytecode - -* Fri Aug 15 2025 Python Maint - 1:5.9.4-16 -- Rebuilt for Python 3.14.0rc2 bytecode - -* Thu Jul 24 2025 Fedora Release Engineering - 1:5.9.4-15 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild - -* Mon Jul 07 2025 Jitka Plesnikova - 1:5.9.4-14 -- Perl 5.42 rebuild - -* Mon Jun 02 2025 Python Maint - 1:5.9.4-13 -- Rebuilt for Python 3.14 - -* Thu Mar 20 2025 Yaakov Selkowitz - 1:5.9.4-12 -- Avoid Mail::Sender dependency on RHEL - -* Sat Feb 01 2025 Björn Esser - 1:5.9.4-11 -- Add explicit BR: libxcrypt-devel - -* Thu Jan 23 2025 Yaakov Selkowitz - 1:5.9.4-10 -- Fix file listings for https://fedoraproject.org/wiki/Changes/Unify_bin_and_sbin - -* Fri Jan 17 2025 Fedora Release Engineering - 1:5.9.4-9 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild - -* Thu Jul 18 2024 Fedora Release Engineering - 1:5.9.4-8 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild - -* Wed Jun 12 2024 Jitka Plesnikova - 1:5.9.4-7 -- Perl 5.40 rebuild - -* Fri Jun 07 2024 Python Maint - 1:5.9.4-6 -- Rebuilt for Python 3.13 - -* Tue Mar 12 2024 Josef Ridky - 1:5.9.4-5 -- Fix parsing issue for kernel 6.7+ (#2266893) - -* Fri Feb 16 2024 Josef Ridky - 1:5.9.4-4 -- Autoconf upgrade (#2256768) - -* Thu Jan 25 2024 Fedora Release Engineering - 1:5.9.4-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild - -* Sun Jan 21 2024 Fedora Release Engineering - 1:5.9.4-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild - * Wed Aug 16 2023 Josef Ridky - 1:5.9.4-1 - New upstream release 5.9.4 (#2184202) diff --git a/plans/ci.fmf b/plans/ci.fmf deleted file mode 100644 index c1627f9..0000000 --- a/plans/ci.fmf +++ /dev/null @@ -1,5 +0,0 @@ -summary: Basic smoke test -discover: - how: fmf -execute: - how: tmt diff --git a/sources b/sources index fb75aae..0d272db 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (net-snmp-5.9.5.2.tar.gz) = c320c90e01377651fdff3aa9c373b9013f142fab23810d821174e546716ef2fa6499a805728710c67ca7fe238679111df392754c24ea4e01768faa5535ac7db2 +SHA512 (net-snmp-5.9.4.tar.gz) = a510fa91a21e9ddc86a12fd1d0bc6b356e63f3ea53f184d2e31439004d41d902390664134dc40b3b828eabb4282eaf3da628a07c4d480fa00eff7e700950c423 diff --git a/tests/integration-tests/Makefile b/tests/integration-tests/Makefile index 9e49696..2f27fbf 100644 --- a/tests/integration-tests/Makefile +++ b/tests/integration-tests/Makefile @@ -27,7 +27,7 @@ $(METADATA): Makefile @echo "Type: Sanity" >> $(METADATA) @echo "TestTime: 5m" >> $(METADATA) @echo "RunFor: net-snmp" >> $(METADATA) - @echo "Requires: net-snmp net-snmp-utils iproute python3 python3-pyroute2" >> $(METADATA) + @echo "Requires: net=snmp" >> $(METADATA) @echo "Priority: Normal" >> $(METADATA) @echo "License: GPLv2" >> $(METADATA) @echo "Confidential: no" >> $(METADATA) diff --git a/tests/integration-tests/main.fmf b/tests/integration-tests/main.fmf deleted file mode 100644 index 64426d7..0000000 --- a/tests/integration-tests/main.fmf +++ /dev/null @@ -1,16 +0,0 @@ -summary: Test snmpd -description: '' -contact: Susant Sahani -component: - - net-snmp -test: ./runtest.sh -framework: beakerlib -recommend: - - net-snmp - - net-snmp-utils - - iproute - - python3 - - python3-pyroute2 -duration: 5m -extra-summary: /CoreOS/net-snmp -extra-task: /CoreOS/net-snmp diff --git a/tests/integration-tests/net-snmp-tests.py b/tests/integration-tests/net-snmp-tests.py index 746c9d8..4cb19eb 100755 --- a/tests/integration-tests/net-snmp-tests.py +++ b/tests/integration-tests/net-snmp-tests.py @@ -15,10 +15,12 @@ import unittest import subprocess import signal import shutil +import psutil import socket import platform import re from pyroute2 import IPRoute +from psutil import virtual_memory from collections import OrderedDict HOST='192.168.111.50' @@ -138,7 +140,11 @@ class SnmpdTests(unittest.TestCase, GenericUtilities): # 1.3.6.1.2.1.1.1 - sysDescr output=subprocess.check_output(['snmpwalk', '-v2c', '-c', 'public', HOST, '1.3.6.1.2.1.1.1']).rstrip().decode('utf-8') - self.assertRegex(output, " ".join(platform.uname()).strip()) + self.assertRegex(output, platform.machine()) + self.assertRegex(output, platform.node()) + self.assertRegex(output, platform.processor()) + self.assertRegex(output, platform.release()) + self.assertRegex(output, platform.version()) # 1.3.6.1.2.1.1.2 - sysObjectID subprocess.check_output(['snmpwalk', '-v2c', '-c', 'public', HOST, '1.3.6.1.2.1.1.2']) diff --git a/tests/tests.yml b/tests/tests.yml new file mode 100644 index 0000000..f600628 --- /dev/null +++ b/tests/tests.yml @@ -0,0 +1,14 @@ +- hosts: localhost + roles: + - role: standard-test-beakerlib + tags: + - classic + tests: + - integration-tests + required_packages: + - python3 + - systemd + - iproute + - python3-pyroute2 + - net-snmp + - net-snmp-utils