From ae7481e93f19b0138ddc1ad56fe6a12a1e109744 Mon Sep 17 00:00:00 2001 From: Python Maint Date: Fri, 7 Jun 2024 08:54:33 +0200 Subject: [PATCH 01/27] Rebuilt for Python 3.13 --- net-snmp.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/net-snmp.spec b/net-snmp.spec index 585f87d..1c63987 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -10,7 +10,7 @@ Summary: A collection of SNMP protocol tools and libraries Name: net-snmp Version: 5.9.4 -Release: 5%{?dist} +Release: 6%{?dist} Epoch: 1 License: Net-SNMP and OpenSSL @@ -513,6 +513,9 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog +* Fri Jun 07 2024 Python Maint - 1:5.9.4-6 +- Rebuilt for Python 3.13 + * Tue Mar 12 2024 Josef Ridky - 1:5.9.4-5 - Fix parsing issue for kernel 6.7+ (#2266893) From ad9d539156bcc06d55345e67822944ce09b52cbe Mon Sep 17 00:00:00 2001 From: Jitka Plesnikova Date: Wed, 12 Jun 2024 10:38:32 +0200 Subject: [PATCH 02/27] Perl 5.40 rebuild --- net-snmp.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/net-snmp.spec b/net-snmp.spec index 1c63987..53bf97f 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -10,7 +10,7 @@ Summary: A collection of SNMP protocol tools and libraries Name: net-snmp Version: 5.9.4 -Release: 6%{?dist} +Release: 7%{?dist} Epoch: 1 License: Net-SNMP and OpenSSL @@ -513,6 +513,9 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog +* Wed Jun 12 2024 Jitka Plesnikova - 1:5.9.4-7 +- Perl 5.40 rebuild + * Fri Jun 07 2024 Python Maint - 1:5.9.4-6 - Rebuilt for Python 3.13 From e1ae9a2b12c70db75e9114dd845dfd475f3c30dd Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 18 Jul 2024 19:19:29 +0000 Subject: [PATCH 03/27] Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild --- net-snmp.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/net-snmp.spec b/net-snmp.spec index 53bf97f..1c773e0 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -10,7 +10,7 @@ Summary: A collection of SNMP protocol tools and libraries Name: net-snmp Version: 5.9.4 -Release: 7%{?dist} +Release: 8%{?dist} Epoch: 1 License: Net-SNMP and OpenSSL @@ -513,6 +513,9 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog +* Thu Jul 18 2024 Fedora Release Engineering - 1:5.9.4-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + * Wed Jun 12 2024 Jitka Plesnikova - 1:5.9.4-7 - Perl 5.40 rebuild From 9c65dec8e98d826aa6dea47f329d3846e8062a4f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miroslav=20Such=C3=BD?= Date: Wed, 30 Oct 2024 19:27:54 +0000 Subject: [PATCH 04/27] Migrate to SPDX license Based on https://gitlab.com/fedora/legal/fedora-license-data/-/issues/533 This is part of https://fedoraproject.org/wiki/Changes/SPDX_Licenses_Phase_4 --- net-snmp.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/net-snmp.spec b/net-snmp.spec index 1c773e0..89a9ff4 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -13,7 +13,7 @@ Version: 5.9.4 Release: 8%{?dist} Epoch: 1 -License: Net-SNMP and OpenSSL +License: MIT-CMU AND BSD-3-Clause AND MIT URL: http://net-snmp.sourceforge.net/ Source0: https://downloads.sourceforge.net/project/net-snmp/net-snmp/%{version}/net-snmp-%{version}.tar.gz Source1: net-snmp.redhat.conf From a1c4087963210e056133737352dd01fa970d5fa3 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 17 Jan 2025 19:54:05 +0000 Subject: [PATCH 05/27] Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild --- net-snmp.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/net-snmp.spec b/net-snmp.spec index 89a9ff4..e103457 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -10,7 +10,7 @@ Summary: A collection of SNMP protocol tools and libraries Name: net-snmp Version: 5.9.4 -Release: 8%{?dist} +Release: 9%{?dist} Epoch: 1 License: MIT-CMU AND BSD-3-Clause AND MIT @@ -513,6 +513,9 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog +* Fri Jan 17 2025 Fedora Release Engineering - 1:5.9.4-9 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + * Thu Jul 18 2024 Fedora Release Engineering - 1:5.9.4-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild From d33a16352962d8dc485a7b39a227c2bb2c4ca5d0 Mon Sep 17 00:00:00 2001 From: Yaakov Selkowitz Date: Wed, 22 Jan 2025 19:03:37 -0500 Subject: [PATCH 06/27] Fix file listings for https://fedoraproject.org/wiki/Changes/Unify_bin_and_sbin After the bin-sbin merge, %_bindir and %_sbindir are the same; this glob was picking up the components that are supposed to be separated into net-snmp-perl (and hence its dependencies). --- net-snmp.spec | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/net-snmp.spec b/net-snmp.spec index e103457..0edca99 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -10,7 +10,7 @@ Summary: A collection of SNMP protocol tools and libraries Name: net-snmp Version: 5.9.4 -Release: 9%{?dist} +Release: 10%{?dist} Epoch: 1 License: MIT-CMU AND BSD-3-Clause AND MIT @@ -435,7 +435,8 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %config(noreplace) %attr(0600,root,root) %{_sysconfdir}/snmp/snmptrapd.conf %{_bindir}/snmpconf %{_bindir}/net-snmp-create-v3-user -%{_sbindir}/* +%{_sbindir}/snmpd +%{_sbindir}/snmptrapd %attr(0644,root,root) %{_mandir}/man[58]/snmp*d* %attr(0644,root,root) %{_mandir}/man5/snmp_config.5.gz %attr(0644,root,root) %{_mandir}/man5/variables* @@ -513,6 +514,9 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog +* Thu Jan 23 2025 Yaakov Selkowitz - 1:5.9.4-10 +- Fix file listings for https://fedoraproject.org/wiki/Changes/Unify_bin_and_sbin + * Fri Jan 17 2025 Fedora Release Engineering - 1:5.9.4-9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild From 74f2032ae1d4024cc07c22b294d7714323563c3f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bj=C3=B6rn=20Esser?= Date: Sat, 1 Feb 2025 19:56:00 +0100 Subject: [PATCH 07/27] Add explicit BR: libxcrypt-devel MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Björn Esser --- net-snmp.spec | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/net-snmp.spec b/net-snmp.spec index 0edca99..7d0b20e 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -10,7 +10,7 @@ Summary: A collection of SNMP protocol tools and libraries Name: net-snmp Version: 5.9.4 -Release: 10%{?dist} +Release: 11%{?dist} Epoch: 1 License: MIT-CMU AND BSD-3-Clause AND MIT @@ -66,6 +66,7 @@ Requires: %{name}-agent-libs%{?_isa} = %{epoch}:%{version}-%{release} # should fire just after this package is installed. %{?systemd_requires} BuildRequires: make +BuildRequires: libxcrypt-devel BuildRequires: systemd BuildRequires: gcc BuildRequires: openssl-devel, bzip2-devel, elfutils-devel @@ -514,6 +515,9 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog +* Sat Feb 01 2025 Björn Esser - 1:5.9.4-11 +- Add explicit BR: libxcrypt-devel + * Thu Jan 23 2025 Yaakov Selkowitz - 1:5.9.4-10 - Fix file listings for https://fedoraproject.org/wiki/Changes/Unify_bin_and_sbin From 4b676c579c102558560b6eaf391604c3ef3e7df7 Mon Sep 17 00:00:00 2001 From: Yaakov Selkowitz Date: Thu, 20 Mar 2025 16:58:31 -0400 Subject: [PATCH 08/27] Avoid Mail::Sender dependency on RHEL perl-Mail-Sender is not available in RHEL. This allows it to still be used if installed from elsewhere (e.g. CPAN or EPEL). https://gitlab.com/redhat/centos-stream/rpms/net-snmp/-/commit/4a199d0e37ad12c70bca2b534e14de181f02854e --- net-snmp-5.9-mail-sender.patch | 24 ++++++++++++++++++++++++ net-snmp.spec | 11 ++++++++++- 2 files changed, 34 insertions(+), 1 deletion(-) create mode 100644 net-snmp-5.9-mail-sender.patch diff --git a/net-snmp-5.9-mail-sender.patch b/net-snmp-5.9-mail-sender.patch new file mode 100644 index 0000000..2f6e28b --- /dev/null +++ b/net-snmp-5.9-mail-sender.patch @@ -0,0 +1,24 @@ +diff -up ./local/checkbandwidth.orig ./local/checkbandwidth +--- ./local/checkbandwidth.orig 2023-08-15 16:32:01.000000000 -0400 ++++ ./local/checkbandwidth 2025-03-20 16:31:14.062432316 -0400 +@@ -326,7 +326,6 @@ See the Net-SNMP COPYING file for licens + + use JSON; + use Data::Dumper; +-use Mail::Sender; + use SNMP; + use Fcntl ':flock'; + +@@ -744,6 +743,12 @@ sub send_rate_message($$$$$$) { + sub send_message($$$) { + my ($to, $subject, $text) = @_; + ++ if (! eval {require Mail::Sender;}) { ++ Log("Failed to send mail with error code -1: Mail::Sender is not available"); ++ return(); ++ } ++ ++ import Mail::Sender; + my $sender = new Mail::Sender { smtp => $opts{'S'} , + port => $opts{'P'}, + from => $opts{'F'}, diff --git a/net-snmp.spec b/net-snmp.spec index 7d0b20e..53bbb20 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -10,7 +10,7 @@ Summary: A collection of SNMP protocol tools and libraries Name: net-snmp Version: 5.9.4 -Release: 11%{?dist} +Release: 12%{?dist} Epoch: 1 License: MIT-CMU AND BSD-3-Clause AND MIT @@ -59,6 +59,9 @@ Patch101: net-snmp-5.8-modern-rpm-api.patch #disable this patch due compatibility issues Patch102: net-snmp-5.9-python3.patch +# make Mail::Sender optional +Patch103: net-snmp-5.9-mail-sender.patch + Requires: %{name}-libs%{?_isa} = %{epoch}:%{version}-%{release} Requires: %{name}-agent-libs%{?_isa} = %{epoch}:%{version}-%{release} # This is actually needed for the %%triggerun script but Requires(triggerun) @@ -247,6 +250,9 @@ cp %{SOURCE10} . %patch 101 -p1 -b .modern-rpm-api %patch 102 -p1 +%if 0%{?rhel} +%patch 103 -p1 +%endif # disable failing test - see https://bugzilla.redhat.com/show_bug.cgi?id=680697 rm testing/fulltests/default/T200* @@ -515,6 +521,9 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog +* Thu Mar 20 2025 Yaakov Selkowitz - 1:5.9.4-12 +- Avoid Mail::Sender dependency on RHEL + * Sat Feb 01 2025 Björn Esser - 1:5.9.4-11 - Add explicit BR: libxcrypt-devel From 7c1240fe6b6f26c4d4eb14463baa796c48e9f451 Mon Sep 17 00:00:00 2001 From: Python Maint Date: Mon, 2 Jun 2025 20:30:22 +0200 Subject: [PATCH 09/27] Rebuilt for Python 3.14 --- net-snmp.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/net-snmp.spec b/net-snmp.spec index 53bbb20..0d7c531 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -10,7 +10,7 @@ Summary: A collection of SNMP protocol tools and libraries Name: net-snmp Version: 5.9.4 -Release: 12%{?dist} +Release: 13%{?dist} Epoch: 1 License: MIT-CMU AND BSD-3-Clause AND MIT @@ -521,6 +521,9 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog +* Mon Jun 02 2025 Python Maint - 1:5.9.4-13 +- Rebuilt for Python 3.14 + * Thu Mar 20 2025 Yaakov Selkowitz - 1:5.9.4-12 - Avoid Mail::Sender dependency on RHEL From edd9638ab3ae641754e95e5919d0971b2d691144 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Luk=C3=A1=C5=A1=20Zaoral?= Date: Mon, 7 Jul 2025 14:03:33 +0200 Subject: [PATCH 10/27] tests: migrate from STI to TMT Related: https://fedoraproject.org/wiki/Changes/DisableSTI --- .fmf/version | 1 + plans/ci.fmf | 5 +++++ tests/integration-tests/Makefile | 2 +- tests/integration-tests/main.fmf | 16 ++++++++++++++++ tests/integration-tests/net-snmp-tests.py | 8 +------- tests/tests.yml | 14 -------------- 6 files changed, 24 insertions(+), 22 deletions(-) create mode 100644 .fmf/version create mode 100644 plans/ci.fmf create mode 100644 tests/integration-tests/main.fmf delete mode 100644 tests/tests.yml diff --git a/.fmf/version b/.fmf/version new file mode 100644 index 0000000..d00491f --- /dev/null +++ b/.fmf/version @@ -0,0 +1 @@ +1 diff --git a/plans/ci.fmf b/plans/ci.fmf new file mode 100644 index 0000000..c1627f9 --- /dev/null +++ b/plans/ci.fmf @@ -0,0 +1,5 @@ +summary: Basic smoke test +discover: + how: fmf +execute: + how: tmt diff --git a/tests/integration-tests/Makefile b/tests/integration-tests/Makefile index 2f27fbf..9e49696 100644 --- a/tests/integration-tests/Makefile +++ b/tests/integration-tests/Makefile @@ -27,7 +27,7 @@ $(METADATA): Makefile @echo "Type: Sanity" >> $(METADATA) @echo "TestTime: 5m" >> $(METADATA) @echo "RunFor: net-snmp" >> $(METADATA) - @echo "Requires: net=snmp" >> $(METADATA) + @echo "Requires: net-snmp net-snmp-utils iproute python3 python3-pyroute2" >> $(METADATA) @echo "Priority: Normal" >> $(METADATA) @echo "License: GPLv2" >> $(METADATA) @echo "Confidential: no" >> $(METADATA) diff --git a/tests/integration-tests/main.fmf b/tests/integration-tests/main.fmf new file mode 100644 index 0000000..64426d7 --- /dev/null +++ b/tests/integration-tests/main.fmf @@ -0,0 +1,16 @@ +summary: Test snmpd +description: '' +contact: Susant Sahani +component: + - net-snmp +test: ./runtest.sh +framework: beakerlib +recommend: + - net-snmp + - net-snmp-utils + - iproute + - python3 + - python3-pyroute2 +duration: 5m +extra-summary: /CoreOS/net-snmp +extra-task: /CoreOS/net-snmp diff --git a/tests/integration-tests/net-snmp-tests.py b/tests/integration-tests/net-snmp-tests.py index 4cb19eb..746c9d8 100755 --- a/tests/integration-tests/net-snmp-tests.py +++ b/tests/integration-tests/net-snmp-tests.py @@ -15,12 +15,10 @@ import unittest import subprocess import signal import shutil -import psutil import socket import platform import re from pyroute2 import IPRoute -from psutil import virtual_memory from collections import OrderedDict HOST='192.168.111.50' @@ -140,11 +138,7 @@ class SnmpdTests(unittest.TestCase, GenericUtilities): # 1.3.6.1.2.1.1.1 - sysDescr output=subprocess.check_output(['snmpwalk', '-v2c', '-c', 'public', HOST, '1.3.6.1.2.1.1.1']).rstrip().decode('utf-8') - self.assertRegex(output, platform.machine()) - self.assertRegex(output, platform.node()) - self.assertRegex(output, platform.processor()) - self.assertRegex(output, platform.release()) - self.assertRegex(output, platform.version()) + self.assertRegex(output, " ".join(platform.uname()).strip()) # 1.3.6.1.2.1.1.2 - sysObjectID subprocess.check_output(['snmpwalk', '-v2c', '-c', 'public', HOST, '1.3.6.1.2.1.1.2']) diff --git a/tests/tests.yml b/tests/tests.yml deleted file mode 100644 index f600628..0000000 --- a/tests/tests.yml +++ /dev/null @@ -1,14 +0,0 @@ -- hosts: localhost - roles: - - role: standard-test-beakerlib - tags: - - classic - tests: - - integration-tests - required_packages: - - python3 - - systemd - - iproute - - python3-pyroute2 - - net-snmp - - net-snmp-utils From 603f908db11d3bfece44c21322230ccfd5d4985b Mon Sep 17 00:00:00 2001 From: Jitka Plesnikova Date: Mon, 7 Jul 2025 16:26:23 +0200 Subject: [PATCH 11/27] Perl 5.42 rebuild --- net-snmp.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/net-snmp.spec b/net-snmp.spec index 0d7c531..18a914d 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -10,7 +10,7 @@ Summary: A collection of SNMP protocol tools and libraries Name: net-snmp Version: 5.9.4 -Release: 13%{?dist} +Release: 14%{?dist} Epoch: 1 License: MIT-CMU AND BSD-3-Clause AND MIT @@ -521,6 +521,9 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog +* Mon Jul 07 2025 Jitka Plesnikova - 1:5.9.4-14 +- Perl 5.42 rebuild + * Mon Jun 02 2025 Python Maint - 1:5.9.4-13 - Rebuilt for Python 3.14 From 45a2bb2eea1dfc24d7c7f4bd7c1268eabdcd2ed9 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 24 Jul 2025 22:43:37 +0000 Subject: [PATCH 12/27] Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild --- net-snmp.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/net-snmp.spec b/net-snmp.spec index 18a914d..87a43fb 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -10,7 +10,7 @@ Summary: A collection of SNMP protocol tools and libraries Name: net-snmp Version: 5.9.4 -Release: 14%{?dist} +Release: 15%{?dist} Epoch: 1 License: MIT-CMU AND BSD-3-Clause AND MIT @@ -521,6 +521,9 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog +* Thu Jul 24 2025 Fedora Release Engineering - 1:5.9.4-15 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + * Mon Jul 07 2025 Jitka Plesnikova - 1:5.9.4-14 - Perl 5.42 rebuild From a63df165470f4385227f740834aef4bd6a6ab55b Mon Sep 17 00:00:00 2001 From: Python Maint Date: Fri, 15 Aug 2025 13:01:50 +0200 Subject: [PATCH 13/27] Rebuilt for Python 3.14.0rc2 bytecode --- net-snmp.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/net-snmp.spec b/net-snmp.spec index 87a43fb..848bfbe 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -10,7 +10,7 @@ Summary: A collection of SNMP protocol tools and libraries Name: net-snmp Version: 5.9.4 -Release: 15%{?dist} +Release: 16%{?dist} Epoch: 1 License: MIT-CMU AND BSD-3-Clause AND MIT @@ -521,6 +521,9 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog +* Fri Aug 15 2025 Python Maint - 1:5.9.4-16 +- Rebuilt for Python 3.14.0rc2 bytecode + * Thu Jul 24 2025 Fedora Release Engineering - 1:5.9.4-15 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild From 0e6b0aaa6a16a47adc5af65f06f56e95534fcbd8 Mon Sep 17 00:00:00 2001 From: Python Maint Date: Fri, 19 Sep 2025 12:32:38 +0200 Subject: [PATCH 14/27] Rebuilt for Python 3.14.0rc3 bytecode --- net-snmp.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/net-snmp.spec b/net-snmp.spec index 848bfbe..3e868b5 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -10,7 +10,7 @@ Summary: A collection of SNMP protocol tools and libraries Name: net-snmp Version: 5.9.4 -Release: 16%{?dist} +Release: 17%{?dist} Epoch: 1 License: MIT-CMU AND BSD-3-Clause AND MIT @@ -521,6 +521,9 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog +* Fri Sep 19 2025 Python Maint - 1:5.9.4-17 +- Rebuilt for Python 3.14.0rc3 bytecode + * Fri Aug 15 2025 Python Maint - 1:5.9.4-16 - Rebuilt for Python 3.14.0rc2 bytecode From 6410ad3116a23c1bc5175937b7f47599838e8cdd Mon Sep 17 00:00:00 2001 From: Josef Ridky Date: Mon, 13 Oct 2025 10:05:09 +0200 Subject: [PATCH 15/27] Enable PQC in net-snmp Signed-off-by: Josef Ridky --- net-snmp-5.9.4-tls.patch | 146 +++++++++++++++++++++++++++++++++++++++ net-snmp.spec | 7 +- 2 files changed, 152 insertions(+), 1 deletion(-) create mode 100644 net-snmp-5.9.4-tls.patch diff --git a/net-snmp-5.9.4-tls.patch b/net-snmp-5.9.4-tls.patch new file mode 100644 index 0000000..2f7d16c --- /dev/null +++ b/net-snmp-5.9.4-tls.patch @@ -0,0 +1,146 @@ +diff -urNp a/include/net-snmp/library/default_store.h b/include/net-snmp/library/default_store.h +--- a/include/net-snmp/library/default_store.h 2025-09-01 10:02:06.355543487 +0200 ++++ b/include/net-snmp/library/default_store.h 2025-09-01 10:06:35.524663762 +0200 +@@ -183,6 +183,8 @@ extern "C" { + #define NETSNMP_DS_LIB_SSH_PUBKEY 33 + #define NETSNMP_DS_LIB_SSH_PRIVKEY 34 + #define NETSNMP_DS_LIB_OUTPUT_PRECISION 35 ++#define NETSNMP_DS_LIB_TLS_MIN_VERSION 36 ++#define NETSNMP_DS_LIB_TLS_MAX_VERSION 37 + #define NETSNMP_DS_LIB_MAX_STR_ID 48 /* match NETSNMP_DS_MAX_SUBIDS */ + + /* +diff -urNp a/man/snmpd.conf.5.def b/man/snmpd.conf.5.def +--- a/man/snmpd.conf.5.def 2025-09-01 10:02:06.417543463 +0200 ++++ b/man/snmpd.conf.5.def 2025-09-01 10:07:03.717037472 +0200 +@@ -203,6 +203,12 @@ HIGH:!AES128\-SHA + .RE + .IP + The default value is whatever openssl itself was configured with. ++.IP "tlsMinVersion STRING" ++The function sets the minimum supported TLS protocol version. ++OPTION can be one of < tls1 | tls1_1| tls1_2 | tls1_3 >. ++.IP "tlsMaxVersion STRING" ++The function sets the maximum supported TLS protocol version. ++OPTION can be one of < tls1 | tls1_1| tls1_2 | tls1_3 >. + .IP "[snmp] x509CRLFile" + If you are using a Certificate Authority (CA) that publishes a + Certificate Revocation List (CRL) then this token can be used to +diff -urNp a/snmplib/transports/snmpTLSBaseDomain.c b/snmplib/transports/snmpTLSBaseDomain.c +--- a/snmplib/transports/snmpTLSBaseDomain.c 2025-09-01 10:02:06.457543447 +0200 ++++ b/snmplib/transports/snmpTLSBaseDomain.c 2025-09-01 10:10:02.796751304 +0200 +@@ -479,6 +479,9 @@ SSL_CTX * + _sslctx_common_setup(SSL_CTX *the_ctx, _netsnmpTLSBaseData *tlsbase) { + char *crlFile; + char *cipherList; ++ char *tlsMinVersion; ++ char *tlsMaxVersion; ++ int tlsVersion; + X509_LOOKUP *lookup; + X509_STORE *cert_store = NULL; + +@@ -502,6 +505,63 @@ _sslctx_common_setup(SSL_CTX *the_ctx, _ + X509_V_FLAG_CRL_CHECK | X509_V_FLAG_CRL_CHECK_ALL); + } + ++#ifdef SSL_CTX_set_min_proto_version ++ tlsVersion = TLS1_2_VERSION; ++ tlsMinVersion = "tls1_2"; ++ tlsMinVersion = netsnmp_ds_get_string(NETSNMP_DS_LIBRARY_ID, ++ NETSNMP_DS_LIB_TLS_MIN_VERSION); ++ if (NULL != tlsMinVersion) { ++ if (strcmp("tls1",tlsMinVersion) == 0) { ++ tlsVersion = TLS1_VERSION; ++ } ++ else if (strcmp("tls1_1",tlsMinVersion) == 0) { ++ tlsVersion = TLS1_1_VERSION; ++ } ++ else if (strcmp("tls1_2",tlsMinVersion) == 0) { ++ tlsVersion = TLS1_2_VERSION; ++ } ++ else if (strcmp("tls1_3",tlsMinVersion) == 0) { ++ tlsVersion = TLS1_3_VERSION; ++ } ++ else { ++ LOGANDDIE("Invalid tlsMinVersion value"); ++ } ++ } ++ if (1 == SSL_CTX_set_min_proto_version(the_ctx, tlsVersion)) { ++ snmp_log(LOG_INFO,"Set tlsMinVersion to '%s'\n", tlsMinVersion); ++ } ++ else { ++ LOGANDDIE("Set tlsMinVersion failed"); ++ } ++ tlsVersion = TLS1_3_VERSION; ++ tlsMaxVersion = "tls1_3"; ++ tlsMaxVersion = netsnmp_ds_get_string(NETSNMP_DS_LIBRARY_ID, ++ NETSNMP_DS_LIB_TLS_MAX_VERSION); ++ if (NULL != tlsMaxVersion) { ++ if (strcmp("tls1",tlsMaxVersion) == 0) { ++ tlsVersion = TLS1_VERSION; ++ } ++ else if (strcmp("tls1_1",tlsMaxVersion) == 0) { ++ tlsVersion = TLS1_1_VERSION; ++ } ++ else if (strcmp("tls1_2",tlsMaxVersion) == 0) { ++ tlsVersion = TLS1_2_VERSION; ++ } ++ else if (strcmp("tls1_3",tlsMaxVersion) == 0) { ++ tlsVersion = TLS1_3_VERSION; ++ } ++ else { ++ LOGANDDIE("Invalid tlsMaxVersion value"); ++ } ++ } ++ if (1 == SSL_CTX_set_max_proto_version(the_ctx, tlsVersion)) { ++ snmp_log(LOG_INFO,"Set tlsMaxVersion to '%s'\n", tlsMaxVersion); ++ } ++ else { ++ LOGANDDIE("Set tlsMaxVersion failed"); ++ } ++#endif ++ + cipherList = netsnmp_ds_get_string(NETSNMP_DS_LIBRARY_ID, + NETSNMP_DS_LIB_TLS_ALGORITMS); + if (NULL != cipherList) { +@@ -803,6 +863,15 @@ netsnmp_tlsbase_ctor(void) { + NETSNMP_DS_LIBRARY_ID, + NETSNMP_DS_LIB_TLS_ALGORITMS); + ++ /* What TLS version should be used at least */ ++ netsnmp_ds_register_config(ASN_OCTET_STR, "snmp", "tlsMinVersion", ++ NETSNMP_DS_LIBRARY_ID, ++ NETSNMP_DS_LIB_TLS_MIN_VERSION); ++ /* What TLS version should be used at max */ ++ netsnmp_ds_register_config(ASN_OCTET_STR, "snmp", "tlsMaxVersion", ++ NETSNMP_DS_LIBRARY_ID, ++ NETSNMP_DS_LIB_TLS_MAX_VERSION); ++ + /* + * for the client + */ +diff -urNp a/snmplib/transports/snmpTLSTCPDomain.c b/snmplib/transports/snmpTLSTCPDomain.c +--- a/snmplib/transports/snmpTLSTCPDomain.c 2025-09-01 10:02:06.460543446 +0200 ++++ b/snmplib/transports/snmpTLSTCPDomain.c 2025-09-01 10:10:46.100597968 +0200 +@@ -718,10 +718,6 @@ netsnmp_tlstcp_open_client(netsnmp_trans + return NULL; + } + +-#ifdef SSL_CTX_set_max_proto_version +- SSL_CTX_set_max_proto_version(tlsdata->ssl_context, TLS1_VERSION); +-#endif +- + /* RFC5953 Section 5.3.1: Establishing a Session as a Client + 3) Using the destTransportDomain and destTransportAddress values, + the client will initiate the (D)TLS handshake protocol to +@@ -917,10 +913,6 @@ netsnmp_tlstcp_open_server(netsnmp_trans + + /* create the OpenSSL TLS context */ + tlsdata->ssl_context = sslctx_server_setup(TLS_method()); +-#ifdef SSL_CTX_set_max_proto_version +- if (tlsdata->ssl_context) +- SSL_CTX_set_max_proto_version(tlsdata->ssl_context, TLS1_VERSION); +-#endif + + t->sock = BIO_get_fd(tlsdata->accept_bio, NULL); + t->flags |= NETSNMP_TRANSPORT_FLAG_LISTEN; diff --git a/net-snmp.spec b/net-snmp.spec index 3e868b5..bf0380f 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -10,7 +10,7 @@ Summary: A collection of SNMP protocol tools and libraries Name: net-snmp Version: 5.9.4 -Release: 17%{?dist} +Release: 18%{?dist} Epoch: 1 License: MIT-CMU AND BSD-3-Clause AND MIT @@ -52,6 +52,7 @@ Patch22: net-snmp-5.9-ipv6-disable-leak.patch Patch23: net-snmp-5.9-rpmdb.patch Patch24: net-snmp-5.9.4-autoconf.patch Patch25: net-snmp-5.9.4-kernel-6.7.patch +Patch26: net-snmp-5.9.4-tls.patch # Modern RPM API means at least EL6 Patch101: net-snmp-5.8-modern-rpm-api.patch @@ -247,6 +248,7 @@ cp %{SOURCE10} . %patch 23 -p1 -b .rpmdbpatch %patch 24 -p1 %patch 25 -p1 -b .kernel-6.7 +%patch 26 -p1 -b .tls %patch 101 -p1 -b .modern-rpm-api %patch 102 -p1 @@ -521,6 +523,9 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog +* Mon Oct 13 2025 Josef Ridky - 1:5.9.4-18 +- Enable PQC in net-snmp + * Fri Sep 19 2025 Python Maint - 1:5.9.4-17 - Rebuilt for Python 3.14.0rc3 bytecode From 656ebdb2459bb3c28c37d84e4cfa52301cfb3855 Mon Sep 17 00:00:00 2001 From: Josef Ridky Date: Mon, 13 Oct 2025 10:08:37 +0200 Subject: [PATCH 16/27] Fix inverted use of -n in snmptrapd_log.c Signed-off-by: Josef Ridky --- net-snmp-5.9.4-revert-n-snmptrapd-log.patch | 12 ++++++++++++ net-snmp.spec | 3 +++ 2 files changed, 15 insertions(+) create mode 100644 net-snmp-5.9.4-revert-n-snmptrapd-log.patch diff --git a/net-snmp-5.9.4-revert-n-snmptrapd-log.patch b/net-snmp-5.9.4-revert-n-snmptrapd-log.patch new file mode 100644 index 0000000..e49d571 --- /dev/null +++ b/net-snmp-5.9.4-revert-n-snmptrapd-log.patch @@ -0,0 +1,12 @@ +diff -urNp a/apps/snmptrapd_log.c b/apps/snmptrapd_log.c +--- a/apps/snmptrapd_log.c 2025-09-03 15:15:12.510914175 +0200 ++++ b/apps/snmptrapd_log.c 2025-09-03 15:15:40.804731480 +0200 +@@ -590,7 +590,7 @@ realloc_handle_time_fmt(u_char ** buf, s + static + void convert_agent_addr(struct in_addr agent_addr, char *name, size_t size) + { +- const int numeric = !netsnmp_ds_get_boolean(NETSNMP_DS_APPLICATION_ID, ++ const int numeric = netsnmp_ds_get_boolean(NETSNMP_DS_APPLICATION_ID, + NETSNMP_DS_APP_NUMERIC_IP); + struct sockaddr_in sin; + diff --git a/net-snmp.spec b/net-snmp.spec index bf0380f..0a2d162 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -53,6 +53,7 @@ Patch23: net-snmp-5.9-rpmdb.patch Patch24: net-snmp-5.9.4-autoconf.patch Patch25: net-snmp-5.9.4-kernel-6.7.patch Patch26: net-snmp-5.9.4-tls.patch +Patch27: net-snmp-5.9.4-revert-n-snmptrapd-log.patch # Modern RPM API means at least EL6 Patch101: net-snmp-5.8-modern-rpm-api.patch @@ -249,6 +250,7 @@ cp %{SOURCE10} . %patch 24 -p1 %patch 25 -p1 -b .kernel-6.7 %patch 26 -p1 -b .tls +%patch 27 -p1 -b .revert-n-snmptrapd-log %patch 101 -p1 -b .modern-rpm-api %patch 102 -p1 @@ -525,6 +527,7 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %changelog * Mon Oct 13 2025 Josef Ridky - 1:5.9.4-18 - Enable PQC in net-snmp +- Fix inverted use of -n in snmptrapd_log.c * Fri Sep 19 2025 Python Maint - 1:5.9.4-17 - Rebuilt for Python 3.14.0rc3 bytecode From 15cedc2c45936e053ca2d66b89922baf86707280 Mon Sep 17 00:00:00 2001 From: Josef Ridky Date: Mon, 12 Jan 2026 17:58:31 +0100 Subject: [PATCH 17/27] Resolves: #2424126 - rebase to 5.9.5.2 Signed-off-by: Josef Ridky --- .gitignore | 1 + net-snmp-5.7.3-iterator-fix.patch | 9 +- net-snmp-5.8-clientaddr-error-message.patch | 20 +- net-snmp-5.8-duplicate-ipAddress.patch | 9 +- net-snmp-5.8-expand-SNMPCONFPATH.patch | 9 +- net-snmp-5.8-ipAddress-faster-load.patch | 11 +- net-snmp-5.8-man-page.patch | 36 -- net-snmp-5.8-rpm-memory-leak.patch | 28 -- net-snmp-5.9-cflags.patch | 20 +- net-snmp-5.9-coverity.patch | 22 -- net-snmp-5.9-intermediate-certs.patch | 414 +++++++++++++++++--- net-snmp-5.9-multilib.patch | 8 +- net-snmp-5.9-python3.patch | 2 +- net-snmp-5.9-rpmdb.patch | 65 --- net-snmp-5.9.1-remove-des.patch | 56 +-- net-snmp-5.9.4-autoconf.patch | 6 - net-snmp-5.9.4-kernel-6.7.patch | 120 ------ net-snmp-5.9.4-revert-n-snmptrapd-log.patch | 9 +- net-snmp-5.9.4-tls.patch | 42 +- net-snmp.spec | 22 +- sources | 2 +- 21 files changed, 465 insertions(+), 446 deletions(-) delete mode 100644 net-snmp-5.8-man-page.patch delete mode 100644 net-snmp-5.8-rpm-memory-leak.patch delete mode 100644 net-snmp-5.9-coverity.patch delete mode 100644 net-snmp-5.9-rpmdb.patch delete mode 100644 net-snmp-5.9.4-autoconf.patch delete mode 100644 net-snmp-5.9.4-kernel-6.7.patch diff --git a/.gitignore b/.gitignore index c94eb56..d358878 100644 --- a/.gitignore +++ b/.gitignore @@ -10,3 +10,4 @@ net-snmp-5.5.tar.gz /net-snmp-5.9.1.tar.gz /net-snmp-5.9.3.tar.gz /net-snmp-5.9.4.tar.gz +/net-snmp-5.9.5.2.tar.gz diff --git a/net-snmp-5.7.3-iterator-fix.patch b/net-snmp-5.7.3-iterator-fix.patch index fb34caf..0afd8bc 100644 --- a/net-snmp-5.7.3-iterator-fix.patch +++ b/net-snmp-5.7.3-iterator-fix.patch @@ -1,7 +1,8 @@ -diff -urNp old/agent/mibgroup/host/data_access/swrun.c new/agent/mibgroup/host/data_access/swrun.c ---- old/agent/mibgroup/host/data_access/swrun.c 2017-07-18 09:44:00.626109526 +0200 -+++ new/agent/mibgroup/host/data_access/swrun.c 2017-07-19 15:27:50.452255836 +0200 -@@ -102,6 +102,10 @@ swrun_count_processes_by_name( char *nam +diff --git a/agent/mibgroup/host/data_access/swrun.c b/agent/mibgroup/host/data_access/swrun.c +index 7b278eb..5f10ade 100644 +--- a/agent/mibgroup/host/data_access/swrun.c ++++ b/agent/mibgroup/host/data_access/swrun.c +@@ -143,6 +143,10 @@ swrun_count_processes_by_name( char *name ) return 0; /* or -1 */ it = CONTAINER_ITERATOR( swrun_container ); diff --git a/net-snmp-5.8-clientaddr-error-message.patch b/net-snmp-5.8-clientaddr-error-message.patch index ef851b1..8de6386 100644 --- a/net-snmp-5.8-clientaddr-error-message.patch +++ b/net-snmp-5.8-clientaddr-error-message.patch @@ -1,7 +1,8 @@ -diff -urNp a/snmplib/snmp_api.c b/snmplib/snmp_api.c ---- a/snmplib/snmp_api.c 2020-11-26 11:05:51.084788775 +0100 -+++ b/snmplib/snmp_api.c 2020-11-26 11:08:27.850751397 +0100 -@@ -235,7 +235,7 @@ static const char *api_errors[-SNMPERR_M +diff --git a/snmplib/snmp_api.c b/snmplib/snmp_api.c +index ad30397..307253a 100644 +--- a/snmplib/snmp_api.c ++++ b/snmplib/snmp_api.c +@@ -231,7 +231,7 @@ static const char *api_errors[-SNMPERR_MAX + 1] = { "No error", /* SNMPERR_SUCCESS */ "Generic error", /* SNMPERR_GENERR */ "Invalid local port", /* SNMPERR_BAD_LOCPORT */ @@ -10,7 +11,7 @@ diff -urNp a/snmplib/snmp_api.c b/snmplib/snmp_api.c "Unknown session", /* SNMPERR_BAD_SESSION */ "Too long", /* SNMPERR_TOO_LONG */ "No socket", /* SNMPERR_NO_SOCKET */ -@@ -1662,7 +1662,9 @@ _sess_open(netsnmp_session * in_session) +@@ -1718,7 +1718,9 @@ _sess_open(netsnmp_session * in_session) DEBUGMSGTL(("_sess_open", "couldn't interpret peername\n")); in_session->s_snmp_errno = SNMPERR_BAD_ADDRESS; in_session->s_errno = errno; @@ -21,10 +22,11 @@ diff -urNp a/snmplib/snmp_api.c b/snmplib/snmp_api.c return NULL; } -diff -ruNp a/snmplib/transports/snmpUDPIPv4BaseDomain.c b/snmplib/transports/snmpUDPIPv4BaseDomain.c ---- a/snmplib/transports/snmpUDPIPv4BaseDomain.c 2021-01-06 12:51:51.948106797 +0100 -+++ b/snmplib/transports/snmpUDPIPv4BaseDomain.c 2021-01-06 14:17:31.029745744 +0100 -@@ -209,6 +209,8 @@ netsnmp_udpipv4base_transport_bind(netsn +diff --git a/snmplib/transports/snmpUDPIPv4BaseDomain.c b/snmplib/transports/snmpUDPIPv4BaseDomain.c +index 1e15a2f..47ac42e 100644 +--- a/snmplib/transports/snmpUDPIPv4BaseDomain.c ++++ b/snmplib/transports/snmpUDPIPv4BaseDomain.c +@@ -224,6 +224,8 @@ netsnmp_udpipv4base_transport_bind(netsnmp_transport *t, DEBUGMSGTL(("netsnmp_udpbase", "failed to bind for clientaddr: %d %s\n", errno, strerror(errno))); diff --git a/net-snmp-5.8-duplicate-ipAddress.patch b/net-snmp-5.8-duplicate-ipAddress.patch index 075976a..8c833a7 100644 --- a/net-snmp-5.8-duplicate-ipAddress.patch +++ b/net-snmp-5.8-duplicate-ipAddress.patch @@ -1,7 +1,8 @@ -diff -urNp a/agent/mibgroup/ip-mib/data_access/ipaddress_common.c b/agent/mibgroup/ip-mib/data_access/ipaddress_common.c ---- a/agent/mibgroup/ip-mib/data_access/ipaddress_common.c 2020-06-10 13:27:03.213904398 +0200 -+++ b/agent/mibgroup/ip-mib/data_access/ipaddress_common.c 2020-06-10 13:28:41.025863050 +0200 -@@ -121,6 +121,7 @@ _remove_duplicates(netsnmp_container *co +diff --git a/agent/mibgroup/ip-mib/data_access/ipaddress_common.c b/agent/mibgroup/ip-mib/data_access/ipaddress_common.c +index 675d4ea..8d3708d 100644 +--- a/agent/mibgroup/ip-mib/data_access/ipaddress_common.c ++++ b/agent/mibgroup/ip-mib/data_access/ipaddress_common.c +@@ -120,6 +120,7 @@ _remove_duplicates(netsnmp_container *container, u_int container_flags) for (entry = ITERATOR_FIRST(it); entry; entry = ITERATOR_NEXT(it)) { if (prev_entry && _access_ipaddress_entry_compare_addr(prev_entry, entry) == 0) { /* 'entry' is duplicate of the previous one -> delete it */ diff --git a/net-snmp-5.8-expand-SNMPCONFPATH.patch b/net-snmp-5.8-expand-SNMPCONFPATH.patch index a812cf4..f9132fe 100644 --- a/net-snmp-5.8-expand-SNMPCONFPATH.patch +++ b/net-snmp-5.8-expand-SNMPCONFPATH.patch @@ -1,7 +1,8 @@ -diff -ruNp a/snmplib/read_config.c b/snmplib/read_config.c ---- a/snmplib/read_config.c 2020-06-10 09:51:57.184786510 +0200 -+++ b/snmplib/read_config.c 2020-06-10 09:53:13.257507112 +0200 -@@ -1642,7 +1642,7 @@ snmp_save_persistent(const char *type) +diff --git a/snmplib/read_config.c b/snmplib/read_config.c +index 159f4be..fa8fcba 100644 +--- a/snmplib/read_config.c ++++ b/snmplib/read_config.c +@@ -1688,7 +1688,7 @@ snmp_save_persistent(const char *type) * save a warning header to the top of the new file */ snprintf(fileold, sizeof(fileold), diff --git a/net-snmp-5.8-ipAddress-faster-load.patch b/net-snmp-5.8-ipAddress-faster-load.patch index db95998..32f9b60 100644 --- a/net-snmp-5.8-ipAddress-faster-load.patch +++ b/net-snmp-5.8-ipAddress-faster-load.patch @@ -1,7 +1,8 @@ -diff -urNp a/agent/mibgroup/mibII/ipAddr.c b/agent/mibgroup/mibII/ipAddr.c ---- a/agent/mibgroup/mibII/ipAddr.c 2020-06-10 14:14:30.113696471 +0200 -+++ b/agent/mibgroup/mibII/ipAddr.c 2020-06-10 14:27:15.345354018 +0200 -@@ -495,14 +495,16 @@ Address_Scan_Next(Index, Retin_ifaddr) +diff --git a/agent/mibgroup/mibII/ipAddr.c b/agent/mibgroup/mibII/ipAddr.c +index a89255f..ef67f5f 100644 +--- a/agent/mibgroup/mibII/ipAddr.c ++++ b/agent/mibgroup/mibII/ipAddr.c +@@ -498,14 +498,16 @@ Address_Scan_Next(Index, Retin_ifaddr) } #elif defined(linux) @@ -19,7 +20,7 @@ diff -urNp a/agent/mibgroup/mibII/ipAddr.c b/agent/mibgroup/mibII/ipAddr.c /* get info about all interfaces */ -@@ -510,28 +512,45 @@ Address_Scan_Init(void) +@@ -513,28 +515,45 @@ Address_Scan_Init(void) SNMP_FREE(ifc.ifc_buf); ifr_counter = 0; diff --git a/net-snmp-5.8-man-page.patch b/net-snmp-5.8-man-page.patch deleted file mode 100644 index dc78e14..0000000 --- a/net-snmp-5.8-man-page.patch +++ /dev/null @@ -1,36 +0,0 @@ -diff -urNp a/man/net-snmp-create-v3-user.1.def b/man/net-snmp-create-v3-user.1.def ---- a/man/net-snmp-create-v3-user.1.def 2020-06-10 13:43:18.443070961 +0200 -+++ b/man/net-snmp-create-v3-user.1.def 2020-06-10 13:49:25.975363441 +0200 -@@ -3,7 +3,7 @@ - net-snmp-create-v3-user \- create a SNMPv3 user in net-snmp configuration file - .SH SYNOPSIS - .PP --.B net-snmp-create-v3-user [-ro] [-a authpass] [-x privpass] [-X DES|AES] -+.B net-snmp-create-v3-user [-ro] [-A authpass] [-a MD5|SHA] [-X privpass] [-x DES|AES] - .B [username] - .SH DESCRIPTION - .PP -@@ -16,13 +16,16 @@ new user in net-snmp configuration file - displays the net-snmp version number - .TP - \fB\-ro\fR --create an user with read-only permissions -+creates a user with read-only permissions - .TP --\fB\-a authpass\fR --specify authentication password -+\fB\-A authpass\fR -+specifies the authentication password - .TP --\fB\-x privpass\fR --specify encryption password -+\fB\-a MD5|SHA\fR -+specifies the authentication password hashing algorithm - .TP --\fB\-X DES|AES\fR --specify encryption algorithm -+\fB\-X privpass\fR -+specifies the encryption password -+.TP -+\fB\-x DES|AES\fR -+specifies the encryption algorithm diff --git a/net-snmp-5.8-rpm-memory-leak.patch b/net-snmp-5.8-rpm-memory-leak.patch deleted file mode 100644 index d337008..0000000 --- a/net-snmp-5.8-rpm-memory-leak.patch +++ /dev/null @@ -1,28 +0,0 @@ -diff --git a/agent/mibgroup/host/data_access/swinst_rpm.c b/agent/mibgroup/host/data_access/swinst_rpm.c -index 695c469..dd0e487 100644 ---- a/agent/mibgroup/host/data_access/swinst_rpm.c -+++ b/agent/mibgroup/host/data_access/swinst_rpm.c -@@ -75,6 +75,9 @@ netsnmp_swinst_arch_init(void) - snprintf( pkg_directory, SNMP_MAXPATH, "%s/Packages", dbpath ); - SNMP_FREE(rpmdbpath); - dbpath = NULL; -+#ifdef HAVE_RPMGETPATH -+ rpmFreeRpmrc(); -+#endif - if (-1 == stat( pkg_directory, &stat_buf )) { - snmp_log(LOG_ERR, "Can't find directory of RPM packages\n"); - pkg_directory[0] = '\0'; -diff --git a/agent/mibgroup/host/hr_swinst.c b/agent/mibgroup/host/hr_swinst.c -index 1f52733..ccf1cab 100644 ---- a/agent/mibgroup/host/hr_swinst.c -+++ b/agent/mibgroup/host/hr_swinst.c -@@ -231,6 +231,9 @@ init_hr_swinst(void) - snprintf(path, sizeof(path), "%s/packages.rpm", swi->swi_dbpath); - path[ sizeof(path)-1 ] = 0; - swi->swi_directory = strdup(path); -+#ifdef HAVE_RPMGETPATH -+ rpmFreeRpmrc(); -+#endif - } - #else - # ifdef _PATH_HRSW_directory diff --git a/net-snmp-5.9-cflags.patch b/net-snmp-5.9-cflags.patch index ef8604f..a48e9ca 100644 --- a/net-snmp-5.9-cflags.patch +++ b/net-snmp-5.9-cflags.patch @@ -1,17 +1,19 @@ -diff -urNp a/perl/Makefile.PL b/perl/Makefile.PL ---- a/perl/Makefile.PL 2020-08-26 08:32:52.498909823 +0200 -+++ b/perl/Makefile.PL 2020-08-26 09:30:45.584951552 +0200 +diff --git a/perl/Makefile.PL b/perl/Makefile.PL +index 63e6333..82cedca 100644 +--- a/perl/Makefile.PL ++++ b/perl/Makefile.PL @@ -1,3 +1,4 @@ +use lib '.'; use strict; use warnings; use ExtUtils::MakeMaker; -diff -urNp a/perl/MakefileSubs.pm b/perl/MakefileSubs.pm ---- a/perl/MakefileSubs.pm 2020-08-26 08:32:52.498909823 +0200 -+++ b/perl/MakefileSubs.pm 2020-08-26 08:36:44.097218448 +0200 -@@ -116,7 +116,7 @@ sub AddCommonParams { - append($Params->{'CCFLAGS'}, $cflags); - append($Params->{'CCFLAGS'}, $Config{'ccflags'}); +diff --git a/perl/MakefileSubs.pm b/perl/MakefileSubs.pm +index 804b20e..25c5d67 100644 +--- a/perl/MakefileSubs.pm ++++ b/perl/MakefileSubs.pm +@@ -126,7 +126,7 @@ sub AddCommonParams { + # Suppress warnings about old-style function definitions. + append($Params->{'CCFLAGS'}, '-Wno-old-style-definition'); # Suppress known Perl header shortcomings. - $Params->{'CCFLAGS'} =~ s/ -W(cast-qual|write-strings)//g; + $Params->{'CCFLAGS'} =~ s/ -W(inline|strict-prototypes|write-strings|cast-qual|no-char-subscripts)//g; diff --git a/net-snmp-5.9-coverity.patch b/net-snmp-5.9-coverity.patch deleted file mode 100644 index fa3e043..0000000 --- a/net-snmp-5.9-coverity.patch +++ /dev/null @@ -1,22 +0,0 @@ -diff --git a/agent/mibgroup/disman/event/mteTrigger.c b/agent/mibgroup/disman/event/mteTrigger.c -index e9a8831..5a1d8e7 100644 ---- a/agent/mibgroup/disman/event/mteTrigger.c -+++ b/agent/mibgroup/disman/event/mteTrigger.c -@@ -1012,7 +1012,7 @@ mteTrigger_run( unsigned int reg, void *clientarg) - * Similarly, if no fallEvent is configured, - * there's no point in trying to fire it either. - */ -- if (entry->mteTThRiseEvent[0] != '\0' ) { -+ if (entry->mteTThFallEvent[0] != '\0' ) { - entry->mteTriggerXOwner = entry->mteTThObjOwner; - entry->mteTriggerXObjects = entry->mteTThObjects; - entry->mteTriggerFired = vp1; -@@ -1105,7 +1105,7 @@ mteTrigger_run( unsigned int reg, void *clientarg) - * Similarly, if no fallEvent is configured, - * there's no point in trying to fire it either. - */ -- if (entry->mteTThDRiseEvent[0] != '\0' ) { -+ if (entry->mteTThDFallEvent[0] != '\0' ) { - entry->mteTriggerXOwner = entry->mteTThObjOwner; - entry->mteTriggerXObjects = entry->mteTThObjects; - entry->mteTriggerFired = vp1; diff --git a/net-snmp-5.9-intermediate-certs.patch b/net-snmp-5.9-intermediate-certs.patch index 6b5daf7..ab5b7a0 100644 --- a/net-snmp-5.9-intermediate-certs.patch +++ b/net-snmp-5.9-intermediate-certs.patch @@ -1,8 +1,8 @@ diff --git a/include/net-snmp/library/cert_util.h b/include/net-snmp/library/cert_util.h -index 80e2a19..143adbb 100644 +index 305e367..6117b9a 100644 --- a/include/net-snmp/library/cert_util.h +++ b/include/net-snmp/library/cert_util.h -@@ -55,7 +55,8 @@ extern "C" { +@@ -48,7 +48,8 @@ extern "C" { char *common_name; u_char hash_type; @@ -12,7 +12,7 @@ index 80e2a19..143adbb 100644 } netsnmp_cert; /** types */ -@@ -100,6 +101,7 @@ extern "C" { +@@ -93,6 +94,7 @@ extern "C" { NETSNMP_IMPORT netsnmp_cert *netsnmp_cert_find(int what, int where, void *hint); @@ -35,10 +35,21 @@ index 471bb0b..ac7f69a 100644 #ifdef __cplusplus diff --git a/snmplib/cert_util.c b/snmplib/cert_util.c -index 210ad8b..b1f8144 100644 +index 5b5aaaa..7c07048 100644 --- a/snmplib/cert_util.c +++ b/snmplib/cert_util.c -@@ -100,7 +100,7 @@ netsnmp_feature_child_of(tls_fingerprint_build, cert_util_all); +@@ -42,9 +42,7 @@ netsnmp_feature_child_of(tls_fingerprint_build, cert_util_all); + + #include + +-#include +- +-#if HAVE_STDLIB_H ++#ifdef HAVE_STDLIB_H + #include + #endif + +@@ -102,7 +100,7 @@ netsnmp_feature_child_of(tls_fingerprint_build, cert_util_all); * bump this value whenever cert index format changes, so indexes * will be regenerated with new format. */ @@ -47,8 +58,28 @@ index 210ad8b..b1f8144 100644 static netsnmp_container *_certs = NULL; static netsnmp_container *_keys = NULL; -@@ -126,6 +126,8 @@ static int _cert_fn_ncompare(netsnmp_cert_common *lhs, - netsnmp_cert_common *rhs); +@@ -116,16 +114,20 @@ static netsnmp_container *_trusted_certs = NULL; + static void _setup_containers(void); + + static void _cert_indexes_load(void); +-static void _cert_free(void *cert, void *context); +-static void _key_free(void *key, void *context); +-static int _cert_compare(const void *p, const void *q); +-static int _cert_sn_compare(const void *p, const void *q); +-static int _cert_sn_ncompare(const void *p, const void *q); +-static int _cert_cn_compare(const void *p, const void *q); +-static int _cert_fn_compare(const void *p, const void *q); +-static int _cert_fn_ncompare(const void *p, const void *q); ++static void _cert_free(netsnmp_cert *cert, void *context); ++static void _key_free(netsnmp_key *key, void *context); ++static int _cert_compare(netsnmp_cert *lhs, netsnmp_cert *rhs); ++static int _cert_sn_compare(netsnmp_cert *lhs, netsnmp_cert *rhs); ++static int _cert_sn_ncompare(netsnmp_cert *lhs, netsnmp_cert *rhs); ++static int _cert_cn_compare(netsnmp_cert *lhs, netsnmp_cert *rhs); ++static int _cert_fn_compare(netsnmp_cert_common *lhs, ++ netsnmp_cert_common *rhs); ++static int _cert_fn_ncompare(netsnmp_cert_common *lhs, ++ netsnmp_cert_common *rhs); static void _find_partner(netsnmp_cert *cert, netsnmp_key *key); static netsnmp_cert *_find_issuer(netsnmp_cert *cert); +static netsnmp_void_array *_cert_reduce_subset_first(netsnmp_void_array *matching); @@ -56,7 +87,16 @@ index 210ad8b..b1f8144 100644 static netsnmp_void_array *_cert_find_subset_fn(const char *filename, const char *directory); static netsnmp_void_array *_cert_find_subset_sn(const char *subject); -@@ -345,6 +347,8 @@ _get_cert_container(const char *use) +@@ -200,7 +202,7 @@ _setup_trusted_certs(void) + return; + } + _trusted_certs->container_name = strdup("trusted certificates"); +- _trusted_certs->compare = netsnmp_str_compare; ++ _trusted_certs->compare = (netsnmp_container_compare*) strcmp; + } + + /* +@@ -345,14 +347,18 @@ _get_cert_container(const char *use) { netsnmp_container *c; @@ -65,49 +105,61 @@ index 210ad8b..b1f8144 100644 c = netsnmp_container_find("certs:binary_array"); if (NULL == c) { snmp_log(LOG_ERR, "could not create container for %s\n", use); -@@ -354,6 +358,8 @@ _get_cert_container(const char *use) - c->free_item = (netsnmp_container_obj_func*)_cert_free; - c->compare = (netsnmp_container_compare*)_cert_compare; - -+ CONTAINER_SET_OPTIONS(c, CONTAINER_KEY_ALLOW_DUPLICATES, rc); + return NULL; + } + c->container_name = strdup(use); +- c->free_item = _cert_free; +- c->compare = _cert_compare; ++ c->free_item = (netsnmp_container_obj_func*)_cert_free; ++ c->compare = (netsnmp_container_compare*)_cert_compare; + ++ CONTAINER_SET_OPTIONS(c, CONTAINER_KEY_ALLOW_DUPLICATES, rc); + return c; } - -@@ -362,6 +368,8 @@ _setup_containers(void) - { - netsnmp_container *additional_keys; - -+ int rc; -+ - _certs = _get_cert_container("netsnmp certificates"); - if (NULL == _certs) - return; -@@ -376,6 +384,7 @@ _setup_containers(void) +@@ -377,7 +383,7 @@ _setup_containers(void) + } additional_keys->container_name = strdup("certs_cn"); additional_keys->free_item = NULL; - additional_keys->compare = (netsnmp_container_compare*)_cert_cn_compare; -+ CONTAINER_SET_OPTIONS(additional_keys, CONTAINER_KEY_ALLOW_DUPLICATES, rc); +- additional_keys->compare = _cert_cn_compare; ++ additional_keys->compare = (netsnmp_container_compare*)_cert_cn_compare; + CONTAINER_SET_OPTIONS(additional_keys, CONTAINER_KEY_ALLOW_DUPLICATES, rc); netsnmp_container_add_index(_certs, additional_keys); - /** additional keys: subject name */ -@@ -389,6 +398,7 @@ _setup_containers(void) +@@ -390,8 +396,8 @@ _setup_containers(void) + } + additional_keys->container_name = strdup("certs_sn"); additional_keys->free_item = NULL; - additional_keys->compare = (netsnmp_container_compare*)_cert_sn_compare; - additional_keys->ncompare = (netsnmp_container_compare*)_cert_sn_ncompare; -+ CONTAINER_SET_OPTIONS(additional_keys, CONTAINER_KEY_ALLOW_DUPLICATES, rc); +- additional_keys->compare = _cert_sn_compare; +- additional_keys->ncompare = _cert_sn_ncompare; ++ additional_keys->compare = (netsnmp_container_compare*)_cert_sn_compare; ++ additional_keys->ncompare = (netsnmp_container_compare*)_cert_sn_ncompare; + CONTAINER_SET_OPTIONS(additional_keys, CONTAINER_KEY_ALLOW_DUPLICATES, rc); netsnmp_container_add_index(_certs, additional_keys); - /** additional keys: file name */ -@@ -402,6 +412,7 @@ _setup_containers(void) +@@ -404,8 +410,8 @@ _setup_containers(void) + } + additional_keys->container_name = strdup("certs_fn"); additional_keys->free_item = NULL; - additional_keys->compare = (netsnmp_container_compare*)_cert_fn_compare; - additional_keys->ncompare = (netsnmp_container_compare*)_cert_fn_ncompare; -+ CONTAINER_SET_OPTIONS(additional_keys, CONTAINER_KEY_ALLOW_DUPLICATES, rc); +- additional_keys->compare = _cert_fn_compare; +- additional_keys->ncompare = _cert_fn_ncompare; ++ additional_keys->compare = (netsnmp_container_compare*)_cert_fn_compare; ++ additional_keys->ncompare = (netsnmp_container_compare*)_cert_fn_ncompare; + CONTAINER_SET_OPTIONS(additional_keys, CONTAINER_KEY_ALLOW_DUPLICATES, rc); netsnmp_container_add_index(_certs, additional_keys); - _keys = netsnmp_container_find("cert_keys:binary_array"); -@@ -424,7 +435,7 @@ netsnmp_cert_map_container(void) +@@ -416,8 +422,8 @@ _setup_containers(void) + return; + } + _keys->container_name = strdup("netsnmp certificate keys"); +- _keys->free_item = _key_free; +- _keys->compare = _cert_fn_compare; ++ _keys->free_item = (netsnmp_container_obj_func*)_key_free; ++ _keys->compare = (netsnmp_container_compare*)_cert_fn_compare; + + _setup_trusted_certs(); + } +@@ -429,7 +435,7 @@ netsnmp_cert_map_container(void) } static netsnmp_cert * @@ -116,7 +168,7 @@ index 210ad8b..b1f8144 100644 int hashType, const char *fingerprint, const char *common_name, const char *subject) { -@@ -446,8 +457,10 @@ _new_cert(const char *dirname, const char *filename, int certType, +@@ -451,8 +457,10 @@ _new_cert(const char *dirname, const char *filename, int certType, cert->info.dir = strdup(dirname); cert->info.filename = strdup(filename); @@ -128,7 +180,112 @@ index 210ad8b..b1f8144 100644 if (fingerprint) { cert->hash_type = hashType; cert->fingerprint = strdup(fingerprint); -@@ -884,14 +897,86 @@ _certindex_new( const char *dirname ) +@@ -553,22 +561,20 @@ netsnmp_key_free(netsnmp_key *key) + } + + static void +-_cert_free(void *cert, void *context) ++_cert_free(netsnmp_cert *cert, void *context) + { + netsnmp_cert_free(cert); + } + + static void +-_key_free(void *key, void *context) ++_key_free(netsnmp_key *key, void *context) + { + netsnmp_key_free(key); + } + + static int +-_cert_compare(const void *p, const void *q) ++_cert_compare(netsnmp_cert *lhs, netsnmp_cert *rhs) + { +- const netsnmp_cert *lhs = p, *rhs = q; +- + netsnmp_assert((lhs != NULL) && (rhs != NULL)); + netsnmp_assert((lhs->fingerprint != NULL) && + (rhs->fingerprint != NULL)); +@@ -578,8 +584,7 @@ _cert_compare(const void *p, const void *q) + } + + static int +-_cert_path_compare(const netsnmp_cert_common *lhs, +- const netsnmp_cert_common *rhs) ++_cert_path_compare(netsnmp_cert_common *lhs, netsnmp_cert_common *rhs) + { + int rc; + +@@ -595,9 +600,8 @@ _cert_path_compare(const netsnmp_cert_common *lhs, + } + + static int +-_cert_cn_compare(const void *p, const void *q) ++_cert_cn_compare(netsnmp_cert *lhs, netsnmp_cert *rhs) + { +- const netsnmp_cert *lhs = p, *rhs = q; + int rc; + const char *lhcn, *rhcn; + +@@ -617,13 +621,13 @@ _cert_cn_compare(const void *p, const void *q) + return rc; + + /** in case of equal common names, sub-sort by path */ +- return _cert_path_compare(&lhs->info, &rhs->info); ++ return _cert_path_compare((netsnmp_cert_common*)lhs, ++ (netsnmp_cert_common*)rhs); + } + + static int +-_cert_sn_compare(const void *p, const void *q) ++_cert_sn_compare(netsnmp_cert *lhs, netsnmp_cert *rhs) + { +- const netsnmp_cert *lhs = p, *rhs = q; + int rc; + const char *lhsn, *rhsn; + +@@ -643,13 +647,13 @@ _cert_sn_compare(const void *p, const void *q) + return rc; + + /** in case of equal common names, sub-sort by path */ +- return _cert_path_compare(&lhs->info, &rhs->info); ++ return _cert_path_compare((netsnmp_cert_common*)lhs, ++ (netsnmp_cert_common*)rhs); + } + + static int +-_cert_fn_compare(const void *p, const void *q) ++_cert_fn_compare(netsnmp_cert_common *lhs, netsnmp_cert_common *rhs) + { +- const netsnmp_cert_common *lhs = p, *rhs = q; + int rc; + + netsnmp_assert((lhs != NULL) && (rhs != NULL)); +@@ -663,10 +667,8 @@ _cert_fn_compare(const void *p, const void *q) + } + + static int +-_cert_fn_ncompare(const void *p, const void *q) ++_cert_fn_ncompare(netsnmp_cert_common *lhs, netsnmp_cert_common *rhs) + { +- const netsnmp_cert_common *lhs = p, *rhs = q; +- + netsnmp_assert((lhs != NULL) && (rhs != NULL)); + netsnmp_assert((lhs->filename != NULL) && (rhs->filename != NULL)); + +@@ -674,10 +676,8 @@ _cert_fn_ncompare(const void *p, const void *q) + } + + static int +-_cert_sn_ncompare(const void *p, const void *q) ++_cert_sn_ncompare(netsnmp_cert *lhs, netsnmp_cert *rhs) + { +- const netsnmp_cert *lhs = p, *rhs = q; +- + netsnmp_assert((lhs != NULL) && (rhs != NULL)); + netsnmp_assert((lhs->subject != NULL) && (rhs->subject != NULL)); + +@@ -897,14 +897,86 @@ _certindex_new( const char *dirname ) * certificate utility functions * */ @@ -217,7 +374,7 @@ index 210ad8b..b1f8144 100644 if (NULL == cert) return NULL; -@@ -908,51 +993,33 @@ netsnmp_ocert_get(netsnmp_cert *cert) +@@ -921,51 +993,33 @@ netsnmp_ocert_get(netsnmp_cert *cert) } } @@ -277,7 +434,7 @@ index 210ad8b..b1f8144 100644 if (NULL != okey) { netsnmp_key *key; DEBUGMSGT(("cert:read:key", "found key with cert in %s\n", -@@ -979,7 +1046,7 @@ netsnmp_ocert_get(netsnmp_cert *cert) +@@ -992,7 +1046,7 @@ netsnmp_ocert_get(netsnmp_cert *cert) break; #ifdef CERT_PKCS12_SUPPORT_MAYBE_LATER case NS_CERT_TYPE_PKCS12: @@ -286,7 +443,7 @@ index 210ad8b..b1f8144 100644 PKCS12 *p12 = d2i_PKCS12_bio(certbio, NULL); if ( (NULL != p12) && (PKCS12_verify_mac(p12, "", 0) || PKCS12_verify_mac(p12, NULL, 0))) -@@ -999,46 +1066,7 @@ netsnmp_ocert_get(netsnmp_cert *cert) +@@ -1012,46 +1066,7 @@ netsnmp_ocert_get(netsnmp_cert *cert) return NULL; } @@ -320,7 +477,7 @@ index 210ad8b..b1f8144 100644 - } - - if (NULL == cert->fingerprint) { -- cert->hash_type = netsnmp_openssl_cert_get_hash_type(ocert); +- cert->hash_type = NS_HASH_SHA1; - cert->fingerprint = - netsnmp_openssl_cert_get_fingerprint(ocert, cert->hash_type); - } @@ -334,7 +491,7 @@ index 210ad8b..b1f8144 100644 return ocert; } -@@ -1048,7 +1076,6 @@ netsnmp_okey_get(netsnmp_key *key) +@@ -1061,7 +1076,6 @@ netsnmp_okey_get(netsnmp_key *key) { BIO *keybio; EVP_PKEY *okey; @@ -342,7 +499,7 @@ index 210ad8b..b1f8144 100644 if (NULL == key) return NULL; -@@ -1056,19 +1083,8 @@ netsnmp_okey_get(netsnmp_key *key) +@@ -1069,19 +1083,8 @@ netsnmp_okey_get(netsnmp_key *key) if (key->okey) return key->okey; @@ -364,7 +521,7 @@ index 210ad8b..b1f8144 100644 return NULL; } -@@ -1154,7 +1170,7 @@ netsnmp_cert_load_x509(netsnmp_cert *cert) +@@ -1167,7 +1170,7 @@ netsnmp_cert_load_x509(netsnmp_cert *cert) cert->issuer_cert = _find_issuer(cert); if (NULL == cert->issuer_cert) { DEBUGMSGT(("cert:load:warn", @@ -373,7 +530,7 @@ index 210ad8b..b1f8144 100644 cert->info.filename)); rc = CERT_LOAD_PARTIAL; break; -@@ -1163,7 +1179,7 @@ netsnmp_cert_load_x509(netsnmp_cert *cert) +@@ -1176,7 +1179,7 @@ netsnmp_cert_load_x509(netsnmp_cert *cert) /** get issuer ocert */ if ((NULL == cert->issuer_cert->ocert) && (netsnmp_ocert_get(cert->issuer_cert) == NULL)) { @@ -382,7 +539,7 @@ index 210ad8b..b1f8144 100644 cert->info.filename)); rc = CERT_LOAD_PARTIAL; break; -@@ -1184,7 +1200,7 @@ _find_partner(netsnmp_cert *cert, netsnmp_key *key) +@@ -1197,7 +1200,7 @@ _find_partner(netsnmp_cert *cert, netsnmp_key *key) return; } @@ -391,7 +548,7 @@ index 210ad8b..b1f8144 100644 if (key->cert) { DEBUGMSGT(("cert:partner", "key already has partner\n")); return; -@@ -1197,7 +1213,8 @@ _find_partner(netsnmp_cert *cert, netsnmp_key *key) +@@ -1210,7 +1213,8 @@ _find_partner(netsnmp_cert *cert, netsnmp_key *key) return; *pos = 0; @@ -401,7 +558,7 @@ index 210ad8b..b1f8144 100644 if (!matching) return; if (1 == matching->size) { -@@ -1217,7 +1234,7 @@ _find_partner(netsnmp_cert *cert, netsnmp_key *key) +@@ -1230,7 +1234,7 @@ _find_partner(netsnmp_cert *cert, netsnmp_key *key) DEBUGMSGT(("cert:partner", "%s matches multiple certs\n", key->info.filename)); } @@ -410,7 +567,7 @@ index 210ad8b..b1f8144 100644 if (cert->key) { DEBUGMSGT(("cert:partner", "cert already has partner\n")); return; -@@ -1255,76 +1272,182 @@ _find_partner(netsnmp_cert *cert, netsnmp_key *key) +@@ -1268,76 +1272,182 @@ _find_partner(netsnmp_cert *cert, netsnmp_key *key) } } @@ -646,7 +803,7 @@ index 210ad8b..b1f8144 100644 } return 0; -@@ -1338,7 +1461,8 @@ _cert_read_index(const char *dirname, struct stat *dirstat) +@@ -1351,7 +1461,8 @@ _cert_read_index(const char *dirname, struct stat *dirstat) struct stat idx_stat; char tmpstr[SNMP_MAXPATH + 5], filename[NAME_MAX]; char fingerprint[EVP_MAX_MD_SIZE*3], common_name[64+1], type_str[15]; @@ -656,7 +813,7 @@ index 210ad8b..b1f8144 100644 int count = 0, type, hash, version; netsnmp_cert *cert; netsnmp_key *key; -@@ -1381,7 +1505,8 @@ _cert_read_index(const char *dirname, struct stat *dirstat) +@@ -1394,7 +1505,8 @@ _cert_read_index(const char *dirname, struct stat *dirstat) netsnmp_directory_container_read_some(NULL, dirname, _time_filter, &idx_stat, NETSNMP_DIR_NSFILE | @@ -666,7 +823,7 @@ index 210ad8b..b1f8144 100644 if (newer) { DEBUGMSGT(("cert:index:parse", "Index outdated; files modified\n")); CONTAINER_FREE_ALL(newer, NULL); -@@ -1426,6 +1551,7 @@ _cert_read_index(const char *dirname, struct stat *dirstat) +@@ -1439,6 +1551,7 @@ _cert_read_index(const char *dirname, struct stat *dirstat) pos = &tmpstr[2]; if ((NULL == (pos=copy_nword(pos, filename, sizeof(filename)))) || (NULL == (pos=copy_nword(pos, type_str, sizeof(type_str)))) || @@ -674,7 +831,7 @@ index 210ad8b..b1f8144 100644 (NULL == (pos=copy_nword(pos, hash_str, sizeof(hash_str)))) || (NULL == (pos=copy_nword(pos, fingerprint, sizeof(fingerprint)))) || -@@ -1438,8 +1564,9 @@ _cert_read_index(const char *dirname, struct stat *dirstat) +@@ -1451,8 +1564,9 @@ _cert_read_index(const char *dirname, struct stat *dirstat) break; } type = atoi(type_str); @@ -685,7 +842,7 @@ index 210ad8b..b1f8144 100644 common_name, subject); if (cert && 0 == CONTAINER_INSERT(found, cert)) ++count; -@@ -1546,7 +1673,8 @@ _add_certdir(const char *dirname) +@@ -1559,7 +1673,8 @@ _add_certdir(const char *dirname) netsnmp_directory_container_read_some(NULL, dirname, _cert_cert_filter, NULL, NETSNMP_DIR_RELATIVE_PATH | @@ -695,7 +852,15 @@ index 210ad8b..b1f8144 100644 if (NULL == cert_container) { DEBUGMSGT(("cert:index:dir", "error creating container for cert files\n")); -@@ -1634,7 +1762,7 @@ _cert_print(netsnmp_cert *c, void *context) +@@ -1642,14 +1757,12 @@ _cert_indexes_load(void) + } + + static void +-_cert_print(void *p, void *context) ++_cert_print(netsnmp_cert *c, void *context) + { +- netsnmp_cert *c = p; +- if (NULL == c) return; @@ -704,7 +869,39 @@ index 210ad8b..b1f8144 100644 DEBUGMSGT(("cert:dump", " type %d flags 0x%x (%s)\n", c->info.type, c->info.allowed_uses, _mode_str(c->info.allowed_uses))); -@@ -1838,7 +1966,8 @@ netsnmp_cert_find(int what, int where, void *hint) +@@ -1676,10 +1789,8 @@ _cert_print(void *p, void *context) + } + + static void +-_key_print(void *p, void *context) ++_key_print(netsnmp_key *k, void *context) + { +- netsnmp_key *k = p; +- + if (NULL == k) + return; + +@@ -1691,8 +1802,8 @@ _key_print(void *p, void *context) + void + netsnmp_cert_dump_all(void) + { +- CONTAINER_FOR_EACH(_certs, _cert_print, NULL); +- CONTAINER_FOR_EACH(_keys, _key_print, NULL); ++ CONTAINER_FOR_EACH(_certs, (netsnmp_container_obj_func*)_cert_print, NULL); ++ CONTAINER_FOR_EACH(_keys, (netsnmp_container_obj_func*)_key_print, NULL); + } + + #ifdef CERT_MAIN +@@ -1726,6 +1837,8 @@ main(int argc, char** argv) + + #endif /* CERT_MAIN */ + ++static netsnmp_cert *_cert_find_fp(const char *fingerprint); ++ + void + netsnmp_fp_lowercase_and_strip_colon(char *fp) + { +@@ -1853,7 +1966,8 @@ netsnmp_cert_find(int what, int where, void *hint) netsnmp_void_array *matching; DEBUGMSGT(("cert:find:params", " hint = %s\n", (char *)hint)); @@ -714,7 +911,16 @@ index 210ad8b..b1f8144 100644 if (!matching) return NULL; if (1 == matching->size) -@@ -2281,6 +2410,124 @@ _reduce_subset_dir(netsnmp_void_array *matching, const char *directory) +@@ -2061,7 +2175,7 @@ netsnmp_cert_trust(SSL_CTX *ctx, netsnmp_cert *thiscert) + SNMPERR_GENERR); + + /* Put the certificate into the store */ +- fingerprint = netsnmp_openssl_cert_get_fingerprint(cert, NS_HASH_SHA1); ++ fingerprint = netsnmp_openssl_cert_get_fingerprint(cert, -1); + DEBUGMSGTL(("cert:trust", + "putting trusted cert %p = %s in certstore %p\n", cert, + fingerprint, certstore)); +@@ -2296,6 +2410,124 @@ _reduce_subset_dir(netsnmp_void_array *matching, const char *directory) } } @@ -839,11 +1045,95 @@ index 210ad8b..b1f8144 100644 static netsnmp_void_array * _cert_find_subset_common(const char *filename, netsnmp_container *container) { +@@ -2433,7 +2665,7 @@ _time_filter(const void *text, void *ctx) + * ***************************************************************************/ + #define MAP_CONFIG_TOKEN "certSecName" + static void _parse_map(const char *token, char *line); +-static void _map_free(void *map, void *ctx); ++static void _map_free(netsnmp_cert_map* entry, void *ctx); + static void _purge_config_entries(void); + + static void +@@ -2538,16 +2770,14 @@ netsnmp_cert_map_find(netsnmp_cert_map *map) + #endif /* NETSNMP_FEATURE_REMOVE_CERT_MAP_FIND */ + + static void +-_map_free(void *map, void *context) ++_map_free(netsnmp_cert_map *map, void *context) + { + netsnmp_cert_map_free(map); + } + + static int +-_map_compare(const void *p, const void *q) ++_map_compare(netsnmp_cert_map *lhs, netsnmp_cert_map *rhs) + { +- const netsnmp_cert_map *lhs = p, *rhs = q; +- + netsnmp_assert((lhs != NULL) && (rhs != NULL)); + + if (lhs->priority < rhs->priority) +@@ -2559,11 +2789,9 @@ _map_compare(const void *p, const void *q) + } + + static int +-_map_fp_compare(const void *p, const void *q) ++_map_fp_compare(netsnmp_cert_map *lhs, netsnmp_cert_map *rhs) + { +- const netsnmp_cert_map *lhs = p, *rhs = q; + int rc; +- + netsnmp_assert((lhs != NULL) && (rhs != NULL)); + + if ((rc = strcmp(lhs->fingerprint, rhs->fingerprint)) != 0) +@@ -2578,10 +2806,8 @@ _map_fp_compare(const void *p, const void *q) + } + + static int +-_map_fp_ncompare(const void *p, const void *q) ++_map_fp_ncompare(netsnmp_cert_map *lhs, netsnmp_cert_map *rhs) + { +- const netsnmp_cert_map *lhs = p, *rhs = q; +- + netsnmp_assert((lhs != NULL) && (rhs != NULL)); + + return strncmp(lhs->fingerprint, rhs->fingerprint, +@@ -2600,8 +2826,8 @@ netsnmp_cert_map_container_create(int with_fp) + } + + chain_map->container_name = strdup("cert_map"); +- chain_map->free_item = _map_free; +- chain_map->compare = _map_compare; ++ chain_map->free_item = (netsnmp_container_obj_func*)_map_free; ++ chain_map->compare = (netsnmp_container_compare*)_map_compare; + + if (!with_fp) + return chain_map; +@@ -2617,8 +2843,8 @@ netsnmp_cert_map_container_create(int with_fp) + return NULL; + } + fp->container_name = strdup("cert2sn_fp"); +- fp->compare = _map_fp_compare; +- fp->ncompare = _map_fp_ncompare; ++ fp->compare = (netsnmp_container_compare*)_map_fp_compare; ++ fp->ncompare = (netsnmp_container_compare*)_map_fp_ncompare; + netsnmp_container_add_index(chain_map, fp); + + return chain_map; +@@ -2769,7 +2995,7 @@ netsnmp_certToTSN_parse_common(char **line) + map->fingerprint = strdup(buf); + } else { + map->fingerprint = +- netsnmp_openssl_cert_get_fingerprint(tmpcert->ocert, NS_HASH_SHA1); ++ netsnmp_openssl_cert_get_fingerprint(tmpcert->ocert, -1); + } + + if (NULL == *line) { diff --git a/snmplib/dir_utils.c b/snmplib/dir_utils.c -index c2dd989..e7145e4 100644 +index 48c1a0f..32426f8 100644 --- a/snmplib/dir_utils.c +++ b/snmplib/dir_utils.c -@@ -107,6 +107,9 @@ netsnmp_directory_container_read_some(netsnmp_container *user_container, +@@ -105,6 +105,9 @@ netsnmp_directory_container_read_some(netsnmp_container *user_container, /** default to unsorted */ if (! (flags & NETSNMP_DIR_SORTED)) CONTAINER_SET_OPTIONS(container, CONTAINER_KEY_UNSORTED, rc); diff --git a/net-snmp-5.9-multilib.patch b/net-snmp-5.9-multilib.patch index ffd8da8..2dfd9a6 100644 --- a/net-snmp-5.9-multilib.patch +++ b/net-snmp-5.9-multilib.patch @@ -1,5 +1,5 @@ diff --git a/man/netsnmp_config_api.3.def b/man/netsnmp_config_api.3.def -index 90b20d9..bd5abe1 100644 +index d4e0c1a..9e3a166 100644 --- a/man/netsnmp_config_api.3.def +++ b/man/netsnmp_config_api.3.def @@ -295,7 +295,7 @@ for one particular machine. @@ -11,7 +11,7 @@ index 90b20d9..bd5abe1 100644 followed by \fC $HOME/.snmp\fP. This list can be changed by setting the environmental variable .I SNMPCONFPATH -@@ -367,7 +367,7 @@ A colon separated list of directories to search for configuration +@@ -367,7 +367,7 @@ A colon-separated list of directories to search for configuration files in. Default: .br @@ -34,10 +34,10 @@ index fd30873..c3437d6 100644 snmptrapd.conf, as well as snmp.local.conf, snmpd.local.conf and/or snmptrapd.local.conf. *.local.conf are always diff --git a/man/snmpd.conf.5.def b/man/snmpd.conf.5.def -index 7ce8a46..a4000f9 100644 +index 6acd8c7..0a8b9fa 100644 --- a/man/snmpd.conf.5.def +++ b/man/snmpd.conf.5.def -@@ -1593,7 +1593,7 @@ filename), and call the initialisation routine \fIinit_NAME\fR. +@@ -1609,7 +1609,7 @@ filename), and call the initialisation routine \fIinit_NAME\fR. .RS .IP "Note:" If the specified PATH is not a fully qualified filename, it will diff --git a/net-snmp-5.9-python3.patch b/net-snmp-5.9-python3.patch index 98de4ca..c7eda61 100644 --- a/net-snmp-5.9-python3.patch +++ b/net-snmp-5.9-python3.patch @@ -1,5 +1,5 @@ diff --git a/Makefile.in b/Makefile.in -index 912f6b2..862fb5f 100644 +index bb4ada9..69ce4f0 100644 --- a/Makefile.in +++ b/Makefile.in @@ -227,7 +227,7 @@ perlcleanfeatures: diff --git a/net-snmp-5.9-rpmdb.patch b/net-snmp-5.9-rpmdb.patch deleted file mode 100644 index d20d728..0000000 --- a/net-snmp-5.9-rpmdb.patch +++ /dev/null @@ -1,65 +0,0 @@ -From ed4ee14af5b83fa4a86dfaa783f841d3e8545ce4 Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Josef=20=C5=98=C3=ADdk=C3=BD?= -Date: Wed, 9 Aug 2023 16:51:28 +0200 -Subject: [PATCH] Add support for RPM SQLite DB background. - -From RPM 4.16 the SQLite support is available for RPM DB. -After https://fedoraproject.org/wiki/Changes/Sqlite_Rpmdb, rpm changed -it's background DB from Berkeley to SQLite in Fedora. -Net-SNMP is using hard coded paths to determine where RPM DB files are. - -This update is adding check for rpmdb.sqlite file in order to be able -invalidate internal cache after system package change. - -Closes #596 ---- - agent/mibgroup/host/data_access/swinst_rpm.c | 18 +++++++++++++----- - agent/mibgroup/host/hr_swinst.c | 3 +++ - 2 files changed, 16 insertions(+), 5 deletions(-) - -diff --git a/agent/mibgroup/host/data_access/swinst_rpm.c b/agent/mibgroup/host/data_access/swinst_rpm.c -index 050edff307..7ad91a3194 100644 ---- a/agent/mibgroup/host/data_access/swinst_rpm.c -+++ b/agent/mibgroup/host/data_access/swinst_rpm.c -@@ -73,15 +73,23 @@ netsnmp_swinst_arch_init(void) - #endif - - snprintf( pkg_directory, SNMP_MAXPATH, "%s/Packages", dbpath ); -+ -+ if (-1 == stat( pkg_directory, &stat_buf )) { -+ -+ /* check for SQLite DB backend */ -+ snprintf( pkg_directory, SNMP_MAXPATH, "%s/rpmdb.sqlite", dbpath ); -+ -+ if (-1 == stat( pkg_directory, &stat_buf )) { -+ snmp_log(LOG_ERR, "Can't find directory of RPM packages\n"); -+ pkg_directory[0] = '\0'; -+ } -+ } -+ - SNMP_FREE(rpmdbpath); - dbpath = NULL; - #ifdef HAVE_RPMGETPATH - rpmFreeRpmrc(); --#endif -- if (-1 == stat( pkg_directory, &stat_buf )) { -- snmp_log(LOG_ERR, "Can't find directory of RPM packages\n"); -- pkg_directory[0] = '\0'; -- } -+#endif - } - - void -diff -urNp a/agent/mibgroup/host/hr_swinst.c b/agent/mibgroup/host/hr_swinst.c ---- a/agent/mibgroup/host/hr_swinst.c 2023-07-31 11:37:44.855071535 +0200 -+++ b/agent/mibgroup/host/hr_swinst.c 2023-08-14 12:45:14.846357019 +0200 -@@ -229,6 +229,9 @@ init_hr_swinst(void) - snprintf(path, sizeof(path), "%s/Packages", swi->swi_dbpath); - if (stat(path, &stat_buf) == -1) - snprintf(path, sizeof(path), "%s/packages.rpm", swi->swi_dbpath); -+ /* check for SQLite DB backend */ -+ if (stat(path, &stat_buf) == -1) -+ snprintf(path, sizeof(path), "%s/rpmdb.sqlite", swi->swi_dbpath); - path[ sizeof(path)-1 ] = 0; - swi->swi_directory = strdup(path); - #ifdef HAVE_RPMGETPATH diff --git a/net-snmp-5.9.1-remove-des.patch b/net-snmp-5.9.1-remove-des.patch index 60fd30f..4618655 100644 --- a/net-snmp-5.9.1-remove-des.patch +++ b/net-snmp-5.9.1-remove-des.patch @@ -1,6 +1,6 @@ diff -urNp a/man/net-snmp-config.1.def b/man/net-snmp-config.1.def ---- a/man/net-snmp-config.1.def 2021-05-26 09:30:07.430790003 +0200 -+++ b/man/net-snmp-config.1.def 2021-05-26 09:35:36.703673542 +0200 +--- a/man/net-snmp-config.1.def 2026-01-12 12:42:08.018134877 +0100 ++++ b/man/net-snmp-config.1.def 2026-01-12 12:43:26.749846227 +0100 @@ -30,7 +30,7 @@ code for a list of available debug token SNMP Setup commands: .TP @@ -11,27 +11,27 @@ diff -urNp a/man/net-snmp-config.1.def b/man/net-snmp-config.1.def These options produce the various compilation flags needed when building external SNMP applications: diff -urNp a/man/net-snmp-create-v3-user.1.def b/man/net-snmp-create-v3-user.1.def ---- a/man/net-snmp-create-v3-user.1.def 2021-05-26 09:30:07.430790003 +0200 -+++ b/man/net-snmp-create-v3-user.1.def 2021-05-26 09:34:23.702034230 +0200 +--- a/man/net-snmp-create-v3-user.1.def 2026-01-12 12:42:08.017134868 +0100 ++++ b/man/net-snmp-create-v3-user.1.def 2026-01-12 12:44:16.263005034 +0100 @@ -3,7 +3,7 @@ net-snmp-create-v3-user \- create a SNMPv3 user in net-snmp configuration file .SH SYNOPSIS .PP --.B net-snmp-create-v3-user [-ro] [-A authpass] [-a MD5|SHA] [-X privpass] [-x DES|AES] -+.B net-snmp-create-v3-user [-ro] [-A authpass] [-a MD5|SHA] [-X privpass] [-x AES] +-.B net-snmp-create-v3-user [-ro] [-A authpass] [-a MD5|SHA|SHA-512|SHA-384|SHA-256|SHA-224] [-X privpass] [-x DES|AES|AES128] ++.B net-snmp-create-v3-user [-ro] [-A authpass] [-a MD5|SHA|SHA-512|SHA-384|SHA-256|SHA-224] [-X privpass] [-x AES|AES128] .B [username] .SH DESCRIPTION .PP -@@ -27,5 +27,5 @@ specifies the authentication password ha +@@ -27,5 +27,5 @@ specify authentication algorithm \fB\-X privpass\fR - specifies the encryption password + specify encryption password .TP --\fB\-x DES|AES\fR -+\fB\-x AES\fR - specifies the encryption algorithm +-\fB\-x DES|AES|AES128\fR ++\fB\-x AES|AES128\fR + specify encryption algorithm diff -urNp a/man/snmpcmd.1.def b/man/snmpcmd.1.def ---- a/man/snmpcmd.1.def 2021-05-26 09:30:07.429789994 +0200 -+++ b/man/snmpcmd.1.def 2021-05-26 09:37:51.104850500 +0200 +--- a/man/snmpcmd.1.def 2026-01-12 12:42:08.016788741 +0100 ++++ b/man/snmpcmd.1.def 2026-01-12 12:45:15.040041004 +0100 @@ -311,7 +311,7 @@ Overrides the \fIdefSecurityName\fR toke file. .TP @@ -42,8 +42,8 @@ diff -urNp a/man/snmpcmd.1.def b/man/snmpcmd.1.def .I snmp.conf file. This option is only valid if the Net-SNMP software was build diff -urNp a/man/snmp.conf.5.def b/man/snmp.conf.5.def ---- a/man/snmp.conf.5.def 2021-05-26 09:30:07.429789994 +0200 -+++ b/man/snmp.conf.5.def 2021-05-26 09:40:03.730011937 +0200 +--- a/man/snmp.conf.5.def 2026-01-12 12:42:08.018134877 +0100 ++++ b/man/snmp.conf.5.def 2026-01-12 12:47:26.967780683 +0100 @@ -221,13 +221,13 @@ The value will be used for the authentication and/or privacy pass phrases if either of the other directives are not specified. @@ -71,8 +71,8 @@ diff -urNp a/man/snmp.conf.5.def b/man/snmp.conf.5.def Sets the path of the \fBsshtosnmp\fR socket created by an application (e.g. snmpd) listening for incoming ssh connections through the diff -urNp a/man/snmpd.examples.5.def b/man/snmpd.examples.5.def ---- a/man/snmpd.examples.5.def 2021-05-26 09:30:07.429789994 +0200 -+++ b/man/snmpd.examples.5.def 2021-05-26 09:41:29.170761436 +0200 +--- a/man/snmpd.examples.5.def 2026-01-12 12:42:08.016788741 +0100 ++++ b/man/snmpd.examples.5.def 2026-01-12 12:48:02.264211991 +0100 @@ -87,8 +87,8 @@ the same authentication and encryption s .RS .nf @@ -85,8 +85,8 @@ diff -urNp a/man/snmpd.examples.5.def b/man/snmpd.examples.5.def .RE Note that this defines three \fIdistinct\fR users, who could be granted diff -urNp a/man/snmptrapd.conf.5.def b/man/snmptrapd.conf.5.def ---- a/man/snmptrapd.conf.5.def 2021-05-26 09:30:07.428789985 +0200 -+++ b/man/snmptrapd.conf.5.def 2021-05-26 09:42:02.963064029 +0200 +--- a/man/snmptrapd.conf.5.def 2026-01-12 12:42:08.018134877 +0100 ++++ b/man/snmptrapd.conf.5.def 2026-01-12 12:48:43.264773008 +0100 @@ -117,7 +117,7 @@ to trigger the types of processing liste See .IR snmpd.conf (5) @@ -97,8 +97,8 @@ diff -urNp a/man/snmptrapd.conf.5.def b/man/snmptrapd.conf.5.def .IR snmpd.conf (5) manual page for a description of how to create SNMPv3 users. This diff -urNp a/man/snmpusm.1.def b/man/snmpusm.1.def ---- a/man/snmpusm.1.def 2021-05-26 09:30:07.430790003 +0200 -+++ b/man/snmpusm.1.def 2021-05-26 09:42:24.178253990 +0200 +--- a/man/snmpusm.1.def 2026-01-12 12:42:08.018134877 +0100 ++++ b/man/snmpusm.1.def 2026-01-12 12:49:26.488017367 +0100 @@ -216,7 +216,7 @@ rwuser initial # lets add the new user we'll create too: rwuser wes @@ -109,9 +109,9 @@ diff -urNp a/man/snmpusm.1.def b/man/snmpusm.1.def .RE .PP diff -urNp a/net-snmp-create-v3-user.in b/net-snmp-create-v3-user.in ---- a/net-snmp-create-v3-user.in 2021-05-26 09:30:07.369789468 +0200 -+++ b/net-snmp-create-v3-user.in 2021-05-26 09:33:23.966511123 +0200 -@@ -10,7 +10,7 @@ if @PSCMD@ | egrep ' snmpd *$' > /dev/nu +--- a/net-snmp-create-v3-user.in 2026-01-12 12:42:08.102135636 +0100 ++++ b/net-snmp-create-v3-user.in 2026-01-12 12:50:35.760787628 +0100 +@@ -10,7 +10,7 @@ if @PSCMD@ | @EGREP@ ' snmpd *$' > /dev/ fi Aalgorithm="MD5" @@ -138,14 +138,14 @@ diff -urNp a/net-snmp-create-v3-user.in b/net-snmp-create-v3-user.in echo "" echo "Usage:" echo " net-snmp-create-v3-user [-ro] [-A authpass] [-X privpass]" -- echo " [-a MD5|SHA|SHA-512|SHA-384|SHA-256|SHA-224] [-x DES|AES] [username]" -+ echo " [-a MD5|SHA|SHA-512|SHA-384|SHA-256|SHA-224] [-x AES] [username]" +- echo " [-a MD5|SHA|SHA-512|SHA-384|SHA-256|SHA-224] [-x DES|AES|AES128] [username]" ++ echo " [-a MD5|SHA|SHA-512|SHA-384|SHA-256|SHA-224] [-x AES|AES128] [username]" echo "" exit fi diff -urNp a/README.snmpv3 b/README.snmpv3 ---- a/README.snmpv3 2021-05-26 09:30:07.352789320 +0200 -+++ b/README.snmpv3 2021-05-26 09:44:49.109551728 +0200 +--- a/README.snmpv3 2026-01-12 12:42:08.021134904 +0100 ++++ b/README.snmpv3 2026-01-12 12:51:58.767903013 +0100 @@ -4,7 +4,7 @@ How to setup SNMPv3, a very brief docume do a better job on since I suck at writing documentation and he doesn't ;-) --Wes: diff --git a/net-snmp-5.9.4-autoconf.patch b/net-snmp-5.9.4-autoconf.patch deleted file mode 100644 index f2b23a9..0000000 --- a/net-snmp-5.9.4-autoconf.patch +++ /dev/null @@ -1,6 +0,0 @@ -diff -urNp a/dist/autoconf-version b/dist/autoconf-version ---- a/dist/autoconf-version 2024-02-16 08:21:36.551729028 +0100 -+++ b/dist/autoconf-version 2024-02-16 08:24:39.035608191 +0100 -@@ -1 +1 @@ --2.71 -+2.72 diff --git a/net-snmp-5.9.4-kernel-6.7.patch b/net-snmp-5.9.4-kernel-6.7.patch deleted file mode 100644 index 089f23b..0000000 --- a/net-snmp-5.9.4-kernel-6.7.patch +++ /dev/null @@ -1,120 +0,0 @@ -From f5ae6baf0018abda9dedc368fe6d52c0d7a8ab8f Mon Sep 17 00:00:00 2001 -From: Philippe Troin -Date: Sat, 3 Feb 2024 10:30:30 -0800 -Subject: [PATCH] Add Linux 6.7 compatibility parsing /proc/net/snmp - -Linux 6.7 adds a new OutTransmits field to Ip in /proc/net/snmp. -This breaks the hard-coded assumptions about the Ip line length. -Add compatibility to parse Linux 6.7 Ip header while keep support -for previous versions. ---- - .../ip-mib/data_access/systemstats_linux.c | 46 +++++++++++++++---- - 1 file changed, 37 insertions(+), 9 deletions(-) - -diff --git a/agent/mibgroup/ip-mib/data_access/systemstats_linux.c b/agent/mibgroup/ip-mib/data_access/systemstats_linux.c -index 49e0a34d5c..f04e828a94 100644 ---- a/agent/mibgroup/ip-mib/data_access/systemstats_linux.c -+++ b/agent/mibgroup/ip-mib/data_access/systemstats_linux.c -@@ -36,7 +36,7 @@ netsnmp_access_systemstats_arch_init(void) - } - - /* -- /proc/net/snmp -+ /proc/net/snmp - Linux 6.6 and lower - - Ip: Forwarding DefaultTTL InReceives InHdrErrors InAddrErrors ForwDatagrams InUnknownProtos InDiscards InDelivers OutRequests OutDiscards OutNoRoutes ReasmTimeout ReasmReqds ReasmOKs ReasmFails FragOKs FragFails FragCreates - Ip: 2 64 7083534 0 0 0 0 0 6860233 6548963 0 0 1 286623 63322 1 259920 0 0 -@@ -49,6 +49,26 @@ netsnmp_access_systemstats_arch_init(void) - - Udp: InDatagrams NoPorts InErrors OutDatagrams - Udp: 1491094 122 0 1466178 -+* -+ /proc/net/snmp - Linux 6.7 and higher -+ -+ Ip: Forwarding DefaultTTL InReceives InHdrErrors InAddrErrors ForwDatagrams InUnknownProtos InDiscards InDelivers OutRequests OutDiscards OutNoRoutes ReasmTimeout ReasmReqds ReasmOKs ReasmFails FragOKs FragFails FragCreates OutTransmits -+ Ip: 1 64 50859058 496 0 37470604 0 0 20472980 7515791 1756 0 0 7264 3632 0 3548 0 7096 44961424 -+ -+ Icmp: InMsgs InErrors InCsumErrors InDestUnreachs InTimeExcds InParmProbs InSrcQuenchs InRedirects InEchos InEchoReps InTimestamps InTimestampReps InAddrMasks InAddrMaskReps OutMsgs OutErrors OutRateLimitGlobal OutRateLimitHost OutDestUnreachs OutTimeExcds OutParmProbs OutSrcQuenchs OutRedirects OutEchos OutEchoReps OutTimestamps OutTimestampReps OutAddrMasks OutAddrMaskReps -+ Icmp: 114447 2655 0 17589 0 0 0 0 66905 29953 0 0 0 0 143956 0 0 572 16610 484 0 0 0 59957 66905 0 0 0 0 -+ -+ IcmpMsg: InType0 InType3 InType8 OutType0 OutType3 OutType8 OutType11 -+ IcmpMsg: 29953 17589 66905 66905 16610 59957 484 -+ -+ Tcp: RtoAlgorithm RtoMin RtoMax MaxConn ActiveOpens PassiveOpens AttemptFails EstabResets CurrEstab InSegs OutSegs RetransSegs InErrs OutRsts InCsumErrors -+ Tcp: 1 200 120000 -1 17744 13525 307 3783 6 18093137 9277788 3499 8 7442 0 -+ -+ Udp: InDatagrams NoPorts InErrors OutDatagrams RcvbufErrors SndbufErrors InCsumErrors IgnoredMulti MemErrors -+ Udp: 2257832 1422 0 2252835 0 0 0 84 0 -+ -+ UdpLite: InDatagrams NoPorts InErrors OutDatagrams RcvbufErrors SndbufErrors InCsumErrors IgnoredMulti MemErrors -+ UdpLite: 0 0 0 0 0 0 0 0 0 - */ - - -@@ -101,10 +121,10 @@ _systemstats_v4(netsnmp_container* container, u_int load_flags) - FILE *devin; - char line[1024]; - netsnmp_systemstats_entry *entry = NULL; -- int scan_count; -+ int scan_count, expected_scan_count; - char *stats, *start = line; - int len; -- unsigned long long scan_vals[19]; -+ unsigned long long scan_vals[20]; - - DEBUGMSGTL(("access:systemstats:container:arch", "load v4 (flags %x)\n", - load_flags)); -@@ -126,10 +146,17 @@ _systemstats_v4(netsnmp_container* container, u_int load_flags) - */ - NETSNMP_IGNORE_RESULT(fgets(line, sizeof(line), devin)); - len = strlen(line); -- if (224 != len) { -+ switch (len) { -+ case 224: -+ expected_scan_count = 19; -+ break; -+ case 237: -+ expected_scan_count = 20; -+ break; -+ default: - fclose(devin); - snmp_log(LOG_ERR, "systemstats_linux: unexpected header length in /proc/net/snmp." -- " %d != 224\n", len); -+ " %d not in { 224, 237 } \n", len); - return -4; - } - -@@ -178,20 +205,20 @@ _systemstats_v4(netsnmp_container* container, u_int load_flags) - memset(scan_vals, 0x0, sizeof(scan_vals)); - scan_count = sscanf(stats, - "%llu %llu %llu %llu %llu %llu %llu %llu %llu %llu" -- "%llu %llu %llu %llu %llu %llu %llu %llu %llu", -+ "%llu %llu %llu %llu %llu %llu %llu %llu %llu %llu", - &scan_vals[0],&scan_vals[1],&scan_vals[2], - &scan_vals[3],&scan_vals[4],&scan_vals[5], - &scan_vals[6],&scan_vals[7],&scan_vals[8], - &scan_vals[9],&scan_vals[10],&scan_vals[11], - &scan_vals[12],&scan_vals[13],&scan_vals[14], - &scan_vals[15],&scan_vals[16],&scan_vals[17], -- &scan_vals[18]); -+ &scan_vals[18],&scan_vals[19]); - DEBUGMSGTL(("access:systemstats", " read %d values\n", scan_count)); - -- if(scan_count != 19) { -+ if(scan_count != expected_scan_count) { - snmp_log(LOG_ERR, - "error scanning systemstats data (expected %d, got %d)\n", -- 19, scan_count); -+ expected_scan_count, scan_count); - netsnmp_access_systemstats_entry_free(entry); - return -4; - } -@@ -223,6 +250,7 @@ _systemstats_v4(netsnmp_container* container, u_int load_flags) - entry->stats.HCOutFragFails.high = scan_vals[17] >> 32; - entry->stats.HCOutFragCreates.low = scan_vals[18] & 0xffffffff; - entry->stats.HCOutFragCreates.high = scan_vals[18] >> 32; -+ /* entry->stats. = scan_vals[19]; / * OutTransmits */ - - entry->stats.columnAvail[IPSYSTEMSTATSTABLE_HCINRECEIVES] = 1; - entry->stats.columnAvail[IPSYSTEMSTATSTABLE_INHDRERRORS] = 1; - diff --git a/net-snmp-5.9.4-revert-n-snmptrapd-log.patch b/net-snmp-5.9.4-revert-n-snmptrapd-log.patch index e49d571..981097b 100644 --- a/net-snmp-5.9.4-revert-n-snmptrapd-log.patch +++ b/net-snmp-5.9.4-revert-n-snmptrapd-log.patch @@ -1,7 +1,8 @@ -diff -urNp a/apps/snmptrapd_log.c b/apps/snmptrapd_log.c ---- a/apps/snmptrapd_log.c 2025-09-03 15:15:12.510914175 +0200 -+++ b/apps/snmptrapd_log.c 2025-09-03 15:15:40.804731480 +0200 -@@ -590,7 +590,7 @@ realloc_handle_time_fmt(u_char ** buf, s +diff --git a/apps/snmptrapd_log.c b/apps/snmptrapd_log.c +index 067c7f6..e6f0f1e 100644 +--- a/apps/snmptrapd_log.c ++++ b/apps/snmptrapd_log.c +@@ -596,7 +596,7 @@ realloc_handle_time_fmt(u_char ** buf, size_t * buf_len, size_t * out_len, static void convert_agent_addr(struct in_addr agent_addr, char *name, size_t size) { diff --git a/net-snmp-5.9.4-tls.patch b/net-snmp-5.9.4-tls.patch index 2f7d16c..1f46abb 100644 --- a/net-snmp-5.9.4-tls.patch +++ b/net-snmp-5.9.4-tls.patch @@ -1,6 +1,7 @@ -diff -urNp a/include/net-snmp/library/default_store.h b/include/net-snmp/library/default_store.h ---- a/include/net-snmp/library/default_store.h 2025-09-01 10:02:06.355543487 +0200 -+++ b/include/net-snmp/library/default_store.h 2025-09-01 10:06:35.524663762 +0200 +diff --git a/include/net-snmp/library/default_store.h b/include/net-snmp/library/default_store.h +index 1b1978e..dd590be 100644 +--- a/include/net-snmp/library/default_store.h ++++ b/include/net-snmp/library/default_store.h @@ -183,6 +183,8 @@ extern "C" { #define NETSNMP_DS_LIB_SSH_PUBKEY 33 #define NETSNMP_DS_LIB_SSH_PRIVKEY 34 @@ -10,9 +11,10 @@ diff -urNp a/include/net-snmp/library/default_store.h b/include/net-snmp/library #define NETSNMP_DS_LIB_MAX_STR_ID 48 /* match NETSNMP_DS_MAX_SUBIDS */ /* -diff -urNp a/man/snmpd.conf.5.def b/man/snmpd.conf.5.def ---- a/man/snmpd.conf.5.def 2025-09-01 10:02:06.417543463 +0200 -+++ b/man/snmpd.conf.5.def 2025-09-01 10:07:03.717037472 +0200 +diff --git a/man/snmpd.conf.5.def b/man/snmpd.conf.5.def +index 0a8b9fa..d9641cc 100644 +--- a/man/snmpd.conf.5.def ++++ b/man/snmpd.conf.5.def @@ -203,6 +203,12 @@ HIGH:!AES128\-SHA .RE .IP @@ -26,10 +28,11 @@ diff -urNp a/man/snmpd.conf.5.def b/man/snmpd.conf.5.def .IP "[snmp] x509CRLFile" If you are using a Certificate Authority (CA) that publishes a Certificate Revocation List (CRL) then this token can be used to -diff -urNp a/snmplib/transports/snmpTLSBaseDomain.c b/snmplib/transports/snmpTLSBaseDomain.c ---- a/snmplib/transports/snmpTLSBaseDomain.c 2025-09-01 10:02:06.457543447 +0200 -+++ b/snmplib/transports/snmpTLSBaseDomain.c 2025-09-01 10:10:02.796751304 +0200 -@@ -479,6 +479,9 @@ SSL_CTX * +diff --git a/snmplib/transports/snmpTLSBaseDomain.c b/snmplib/transports/snmpTLSBaseDomain.c +index e301de4..7ae2db7 100644 +--- a/snmplib/transports/snmpTLSBaseDomain.c ++++ b/snmplib/transports/snmpTLSBaseDomain.c +@@ -490,6 +490,9 @@ SSL_CTX * _sslctx_common_setup(SSL_CTX *the_ctx, _netsnmpTLSBaseData *tlsbase) { char *crlFile; char *cipherList; @@ -39,7 +42,7 @@ diff -urNp a/snmplib/transports/snmpTLSBaseDomain.c b/snmplib/transports/snmpTLS X509_LOOKUP *lookup; X509_STORE *cert_store = NULL; -@@ -502,6 +505,63 @@ _sslctx_common_setup(SSL_CTX *the_ctx, _ +@@ -513,6 +516,63 @@ _sslctx_common_setup(SSL_CTX *the_ctx, _netsnmpTLSBaseData *tlsbase) { X509_V_FLAG_CRL_CHECK | X509_V_FLAG_CRL_CHECK_ALL); } @@ -103,7 +106,7 @@ diff -urNp a/snmplib/transports/snmpTLSBaseDomain.c b/snmplib/transports/snmpTLS cipherList = netsnmp_ds_get_string(NETSNMP_DS_LIBRARY_ID, NETSNMP_DS_LIB_TLS_ALGORITMS); if (NULL != cipherList) { -@@ -803,6 +863,15 @@ netsnmp_tlsbase_ctor(void) { +@@ -858,6 +918,15 @@ netsnmp_tlsbase_ctor(void) { NETSNMP_DS_LIBRARY_ID, NETSNMP_DS_LIB_TLS_ALGORITMS); @@ -119,27 +122,28 @@ diff -urNp a/snmplib/transports/snmpTLSBaseDomain.c b/snmplib/transports/snmpTLS /* * for the client */ -diff -urNp a/snmplib/transports/snmpTLSTCPDomain.c b/snmplib/transports/snmpTLSTCPDomain.c ---- a/snmplib/transports/snmpTLSTCPDomain.c 2025-09-01 10:02:06.460543446 +0200 -+++ b/snmplib/transports/snmpTLSTCPDomain.c 2025-09-01 10:10:46.100597968 +0200 -@@ -718,10 +718,6 @@ netsnmp_tlstcp_open_client(netsnmp_trans +diff --git a/snmplib/transports/snmpTLSTCPDomain.c b/snmplib/transports/snmpTLSTCPDomain.c +index 0ddf023..e0133f9 100644 +--- a/snmplib/transports/snmpTLSTCPDomain.c ++++ b/snmplib/transports/snmpTLSTCPDomain.c +@@ -718,10 +718,6 @@ netsnmp_tlstcp_open_client(netsnmp_transport *t) return NULL; } -#ifdef SSL_CTX_set_max_proto_version -- SSL_CTX_set_max_proto_version(tlsdata->ssl_context, TLS1_VERSION); +- SSL_CTX_set_max_proto_version(tlsdata->ssl_context, 0); -#endif - /* RFC5953 Section 5.3.1: Establishing a Session as a Client 3) Using the destTransportDomain and destTransportAddress values, the client will initiate the (D)TLS handshake protocol to -@@ -917,10 +913,6 @@ netsnmp_tlstcp_open_server(netsnmp_trans +@@ -917,10 +913,6 @@ netsnmp_tlstcp_open_server(netsnmp_transport *t) /* create the OpenSSL TLS context */ tlsdata->ssl_context = sslctx_server_setup(TLS_method()); -#ifdef SSL_CTX_set_max_proto_version - if (tlsdata->ssl_context) -- SSL_CTX_set_max_proto_version(tlsdata->ssl_context, TLS1_VERSION); +- SSL_CTX_set_max_proto_version(tlsdata->ssl_context, 0); -#endif t->sock = BIO_get_fd(tlsdata->accept_bio, NULL); diff --git a/net-snmp.spec b/net-snmp.spec index 0a2d162..8819570 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -5,12 +5,12 @@ %global multilib_arches %{ix86} ia64 ppc ppc64 s390 s390x x86_64 sparc sparcv9 sparc64 aarch64 # actual soname version -%global soname 40 +%global soname 45 Summary: A collection of SNMP protocol tools and libraries Name: net-snmp -Version: 5.9.4 -Release: 18%{?dist} +Version: 5.9.5.2 +Release: 1%{?dist} Epoch: 1 License: MIT-CMU AND BSD-3-Clause AND MIT @@ -36,22 +36,16 @@ Patch6: net-snmp-5.9-cflags.patch Patch7: net-snmp-5.8-Remove-U64-typedef.patch Patch8: net-snmp-5.7.3-iterator-fix.patch Patch9: net-snmp-5.9-autofs-skip.patch -Patch10: net-snmp-5.9-coverity.patch Patch11: net-snmp-5.8-expand-SNMPCONFPATH.patch Patch12: net-snmp-5.8-duplicate-ipAddress.patch Patch13: net-snmp-5.9-memory-reporting.patch -Patch14: net-snmp-5.8-man-page.patch Patch15: net-snmp-5.8-ipAddress-faster-load.patch -Patch16: net-snmp-5.8-rpm-memory-leak.patch Patch17: net-snmp-5.9-aes-config.patch Patch18: net-snmp-5.8-clientaddr-error-message.patch Patch19: net-snmp-5.9-intermediate-certs.patch Patch20: net-snmp-5.9.1-remove-des.patch Patch21: net-snmp-libs-misunderstanding.patch Patch22: net-snmp-5.9-ipv6-disable-leak.patch -Patch23: net-snmp-5.9-rpmdb.patch -Patch24: net-snmp-5.9.4-autoconf.patch -Patch25: net-snmp-5.9.4-kernel-6.7.patch Patch26: net-snmp-5.9.4-tls.patch Patch27: net-snmp-5.9.4-revert-n-snmptrapd-log.patch @@ -80,6 +74,7 @@ BuildRequires: perl-devel, perl(ExtUtils::Embed), procps BuildRequires: python3-devel, python3-setuptools BuildRequires: chrpath BuildRequires: mariadb-connector-c-devel +BuildRequires: libnl3-devel # for netstat, needed by 'make test' BuildRequires: net-tools # for make test @@ -233,22 +228,16 @@ cp %{SOURCE10} . %patch 7 -p1 -b .u64-remove %patch 8 -p1 -b .iterator-fix %patch 9 -p1 -b .autofs-skip -%patch 10 -p1 -b .coverity %patch 11 -p1 -b .expand-SNMPCONFPATH %patch 12 -p1 -b .duplicate-ipAddress %patch 13 -p1 -b .memory-reporting -%patch 14 -p1 -b .man-page %patch 15 -p1 -b .ipAddress-faster-load -%patch 16 -p1 -b .rpm-memory-leak %patch 17 -p1 -b .aes-config %patch 18 -p1 -b .clientaddr-error-message %patch 19 -p1 -b .intermediate-certs %patch 20 -p1 -b .remove-des %patch 21 -p1 %patch 22 -p1 -b .ipv6-disable-leak -%patch 23 -p1 -b .rpmdbpatch -%patch 24 -p1 -%patch 25 -p1 -b .kernel-6.7 %patch 26 -p1 -b .tls %patch 27 -p1 -b .revert-n-snmptrapd-log @@ -525,6 +514,9 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog +* Mon Jan 12 2026 Josef Ridky - 1:5.9.5.2-1 +- New upstream release 5.9.5.2 + * Mon Oct 13 2025 Josef Ridky - 1:5.9.4-18 - Enable PQC in net-snmp - Fix inverted use of -n in snmptrapd_log.c diff --git a/sources b/sources index 0d272db..fb75aae 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (net-snmp-5.9.4.tar.gz) = a510fa91a21e9ddc86a12fd1d0bc6b356e63f3ea53f184d2e31439004d41d902390664134dc40b3b828eabb4282eaf3da628a07c4d480fa00eff7e700950c423 +SHA512 (net-snmp-5.9.5.2.tar.gz) = c320c90e01377651fdff3aa9c373b9013f142fab23810d821174e546716ef2fa6499a805728710c67ca7fe238679111df392754c24ea4e01768faa5535ac7db2 From f3f833915418b59f46de3074c841188c5cb61875 Mon Sep 17 00:00:00 2001 From: Yaakov Selkowitz Date: Sun, 16 Nov 2025 18:32:41 -0500 Subject: [PATCH 18/27] Enable lm_sensors on all arches Once upon a time lm_sensors was only only supported on some arches, but nowadays all are enabled, so do the same here. --- net-snmp.spec | 16 +++++----------- 1 file changed, 5 insertions(+), 11 deletions(-) diff --git a/net-snmp.spec b/net-snmp.spec index 8819570..59fb339 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -10,7 +10,7 @@ Summary: A collection of SNMP protocol tools and libraries Name: net-snmp Version: 5.9.5.2 -Release: 1%{?dist} +Release: 2%{?dist} Epoch: 1 License: MIT-CMU AND BSD-3-Clause AND MIT @@ -89,9 +89,7 @@ BuildRequires: perl(strict) BuildRequires: perl(TAP::Harness) BuildRequires: perl(vars) BuildRequires: perl(warnings) -%ifnarch s390 s390x ppc64le BuildRequires: lm_sensors-devel >= 3 -%endif BuildRequires: autoconf, automake %description @@ -124,9 +122,7 @@ Requires: %{name}-libs%{?_isa} = %{epoch}:%{version}-%{release} Requires: %{name}-agent-libs%{?_isa} = %{epoch}:%{version}-%{release} Requires: elfutils-devel, rpm-devel, elfutils-libelf-devel, openssl-devel Requires: redhat-rpm-config -%ifnarch s390 s390x ppc64le Requires: lm_sensors-devel -%endif # pull perl development libraries, net-snmp agent libraries may link to them Requires: perl-devel%{?_isa} @@ -261,12 +257,7 @@ MIBS="host agentx smux \ ip-mib/ipAddressPrefixTable/ipAddressPrefixTable \ ip-mib/ipDefaultRouterTable/ipDefaultRouterTable \ ip-mib/ipv6ScopeZoneIndexTable ip-mib/ipIfStatsTable \ - sctp-mib rmon-mib etherlike-mib" - -%ifnarch s390 s390x ppc64le -# there are no lm_sensors on s390 -MIBS="$MIBS ucd-snmp/lmsensorsMib" -%endif + sctp-mib rmon-mib etherlike-mib ucd-snmp/lmsensorsMib" %configure \ --disable-static --enable-shared \ @@ -514,6 +505,9 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog +* Mon Jan 12 2026 Yaakov Selkowitz - 1:5.9.5.2-2 +- Enable lm_sensors on all arches + * Mon Jan 12 2026 Josef Ridky - 1:5.9.5.2-1 - New upstream release 5.9.5.2 From 7f7d58eaf7cec3ce8e2a91e9b71fa2a933b4420e Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 16 Jan 2026 22:01:09 +0000 Subject: [PATCH 19/27] Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild --- net-snmp.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/net-snmp.spec b/net-snmp.spec index 59fb339..880cb40 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -10,7 +10,7 @@ Summary: A collection of SNMP protocol tools and libraries Name: net-snmp Version: 5.9.5.2 -Release: 2%{?dist} +Release: 3%{?dist} Epoch: 1 License: MIT-CMU AND BSD-3-Clause AND MIT @@ -505,6 +505,9 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog +* Fri Jan 16 2026 Fedora Release Engineering - 1:5.9.5.2-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild + * Mon Jan 12 2026 Yaakov Selkowitz - 1:5.9.5.2-2 - Enable lm_sensors on all arches From 40d9093621bf82fe66cb386f612ffbbef43f42fd Mon Sep 17 00:00:00 2001 From: Yaakov Selkowitz Date: Thu, 29 Jan 2026 12:43:41 -0500 Subject: [PATCH 20/27] Add net-snmp-devel dependency on libnl3-devel With the addition of the libnl3 build dependency in 5.9.5.2, its link flags also show up in net-snmp-config --agent-libs. --- net-snmp.spec | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/net-snmp.spec b/net-snmp.spec index 880cb40..e5e32ac 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -10,7 +10,7 @@ Summary: A collection of SNMP protocol tools and libraries Name: net-snmp Version: 5.9.5.2 -Release: 3%{?dist} +Release: 4%{?dist} Epoch: 1 License: MIT-CMU AND BSD-3-Clause AND MIT @@ -122,6 +122,7 @@ Requires: %{name}-libs%{?_isa} = %{epoch}:%{version}-%{release} Requires: %{name}-agent-libs%{?_isa} = %{epoch}:%{version}-%{release} Requires: elfutils-devel, rpm-devel, elfutils-libelf-devel, openssl-devel Requires: redhat-rpm-config +Requires: libnl3-devel Requires: lm_sensors-devel # pull perl development libraries, net-snmp agent libraries may link to them Requires: perl-devel%{?_isa} @@ -505,6 +506,9 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog +* Thu Jan 29 2026 Yaakov Selkowitz - 1:5.9.5.2-4 +- Add net-snmp-devel dependency on libnl3-devel + * Fri Jan 16 2026 Fedora Release Engineering - 1:5.9.5.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild From 0d287ccdd2dc7051949e2ebf775f67a937723fb6 Mon Sep 17 00:00:00 2001 From: Python Maint Date: Wed, 3 Jun 2026 17:44:08 +0200 Subject: [PATCH 21/27] Rebuilt for Python 3.15 --- net-snmp.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/net-snmp.spec b/net-snmp.spec index e5e32ac..2291398 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -10,7 +10,7 @@ Summary: A collection of SNMP protocol tools and libraries Name: net-snmp Version: 5.9.5.2 -Release: 4%{?dist} +Release: 5%{?dist} Epoch: 1 License: MIT-CMU AND BSD-3-Clause AND MIT @@ -506,6 +506,9 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog +* Wed Jun 03 2026 Python Maint - 1:5.9.5.2-5 +- Rebuilt for Python 3.15 + * Thu Jan 29 2026 Yaakov Selkowitz - 1:5.9.5.2-4 - Add net-snmp-devel dependency on libnl3-devel From f11e93ce096c2be03cb441869235cabd74fdcaeb Mon Sep 17 00:00:00 2001 From: Yaakov Selkowitz Date: Mon, 8 Jun 2026 12:39:06 -0400 Subject: [PATCH 22/27] Fix "Checking the Net-SNMP configure script validity" test Autoreconf is run during build, which may be a different version than upstream used, resulting in a mismatch that causes this test to fail. --- net-snmp.spec | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/net-snmp.spec b/net-snmp.spec index 2291398..f65b878 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -90,7 +90,7 @@ BuildRequires: perl(TAP::Harness) BuildRequires: perl(vars) BuildRequires: perl(warnings) BuildRequires: lm_sensors-devel >= 3 -BuildRequires: autoconf, automake +BuildRequires: autoconf, automake, libtool %description SNMP (Simple Network Management Protocol) is a protocol used for @@ -247,10 +247,14 @@ cp %{SOURCE10} . # disable failing test - see https://bugzilla.redhat.com/show_bug.cgi?id=680697 rm testing/fulltests/default/T200* +# Autoreconf is run during build, which may be a different version than upstream used, +# resulting in a mismatch during "Checking the Net-SNMP configure script validity" test +autoconf --version | awk 'NR==1 {print $4}' > dist/autoconf-version + %build # Autoreconf to get autoconf 2.69 for ARM (#926223) -autoreconf +autoreconf -fiv MIBS="host agentx smux \ ucd-snmp/diskio tcp-mib udp-mib mibII/mta_sendmail \ From 7043b422273f27ce2c43719ddcf09d6c8191d75c Mon Sep 17 00:00:00 2001 From: Simo Sorce Date: Fri, 12 Jun 2026 11:10:49 -0400 Subject: [PATCH 23/27] Openssl 4 build fixes Signed-off-by: Simo Sorce --- ...OpenSSL-accessors-for-opaque-structs.patch | 177 ++++++++++++++++++ net-snmp.spec | 9 +- 2 files changed, 185 insertions(+), 1 deletion(-) create mode 100644 0001-Use-OpenSSL-accessors-for-opaque-structs.patch diff --git a/0001-Use-OpenSSL-accessors-for-opaque-structs.patch b/0001-Use-OpenSSL-accessors-for-opaque-structs.patch new file mode 100644 index 0000000..fa1b973 --- /dev/null +++ b/0001-Use-OpenSSL-accessors-for-opaque-structs.patch @@ -0,0 +1,177 @@ +From 338d289f1e14650edf0bd7e960272871029131e1 Mon Sep 17 00:00:00 2001 +From: Simo Sorce +Date: Fri, 17 Apr 2026 12:47:18 -0400 +Subject: [PATCH] Use OpenSSL accessors for opaque structs + +Replaced direct access to `ASN1_STRING` fields with OpenSSL accessor functions +(e.g., `ASN1_STRING_type`, `ASN1_STRING_length`, `ASN1_STRING_get0_data`) and +updated `X509_NAME` and `X509_EXTENSION` pointers to `const`. This is required +to maintain compatibility with newer OpenSSL versions (4.0+) where these +structures were made opaque. + +Co-authored-by: Gemini +Signed-off-by: Simo Sorce +--- + snmplib/snmp_openssl.c | 74 ++++++++++++++++++++++-------------------- + 1 file changed, 39 insertions(+), 35 deletions(-) + +diff --git a/snmplib/snmp_openssl.c b/snmplib/snmp_openssl.c +index 4471a7a..658841a 100644 +--- a/snmplib/snmp_openssl.c ++++ b/snmplib/snmp_openssl.c +@@ -147,7 +147,7 @@ void netsnmp_init_openssl(void) { + static char * + _cert_get_name(X509 *ocert, int which, char **buf, int *len, int flags) + { +- X509_NAME *osubj_name; ++ const X509_NAME *osubj_name; + int space; + char *buf_ptr; + +@@ -187,7 +187,7 @@ _cert_get_name(X509 *ocert, int which, char **buf, int *len, int flags) + char * + netsnmp_openssl_cert_get_subjectName(X509 *ocert, char **buf, int *len) + { +- X509_NAME *osubj_name; ++ const X509_NAME *osubj_name; + int space; + char *buf_ptr; + +@@ -233,11 +233,11 @@ netsnmp_openssl_cert_get_commonName(X509 *ocert, char **buf, int *len) + void + netsnmp_openssl_cert_dump_names(X509 *ocert) + { +- int i, onid; +- X509_NAME_ENTRY *oname_entry; +- ASN1_STRING *oname_value; +- X509_NAME *osubj_name; +- const char *prefix_short, *prefix_long; ++ int i, onid; ++ const X509_NAME_ENTRY *oname_entry; ++ const ASN1_STRING *oname_value; ++ const X509_NAME *osubj_name; ++ const char *prefix_short, *prefix_long; + + if (NULL == ocert) + return; +@@ -253,7 +253,7 @@ netsnmp_openssl_cert_dump_names(X509 *ocert) + netsnmp_assert(NULL != oname_entry); + oname_value = X509_NAME_ENTRY_get_data(oname_entry); + +- if (oname_value->type != V_ASN1_PRINTABLESTRING) ++ if (ASN1_STRING_type(oname_value) != V_ASN1_PRINTABLESTRING) + continue; + + /** get NID */ +@@ -268,7 +268,7 @@ netsnmp_openssl_cert_dump_names(X509 *ocert) + + DEBUGMSGT(("9:cert:dump:names", + "[%02d] NID type %d, ASN type %d\n", i, onid, +- oname_value->type)); ++ ASN1_STRING_type(oname_value))); + DEBUGMSGT(("9:cert:dump:names", "%s/%s: '%s'\n", prefix_long, + prefix_short, ASN1_STRING_get0_data(oname_value))); + } +@@ -276,7 +276,7 @@ netsnmp_openssl_cert_dump_names(X509 *ocert) + #endif /* NETSNMP_FEATURE_REMOVE_CERT_DUMP_NAMES */ + + static char * +-_cert_get_extension(X509_EXTENSION *oext, char **buf, int *len, int flags) ++_cert_get_extension(const X509_EXTENSION *oext, char **buf, int *len, int flags) + { + int space; + char *buf_ptr = NULL; +@@ -327,10 +327,10 @@ out: + */ + /** instead of exposing this function, make helper functions for each + * field, like netsnmp_openssl_cert_get_subjectAltName, below */ +-X509_EXTENSION * ++const X509_EXTENSION * + _cert_get_extension_at(X509 *ocert, int pos, char **buf, int *len, int flags) + { +- X509_EXTENSION *oext; ++ const X509_EXTENSION *oext; + + if ((NULL == ocert) || ((buf && !len) || (len && !buf))) + return NULL; +@@ -354,7 +354,7 @@ static char * + _cert_get_extension_str_at(X509 *ocert, int pos, char **buf, int *len, + int flags) + { +- X509_EXTENSION *oext; ++ const X509_EXTENSION *oext; + + if ((NULL == ocert) || ((buf && !len) || (len && !buf))) + return NULL; +@@ -374,7 +374,7 @@ _cert_get_extension_str_at(X509 *ocert, int pos, char **buf, int *len, + */ + /** instead of exposing this function, make helper functions for each + * field, like netsnmp_openssl_cert_get_subjectAltName, below */ +-X509_EXTENSION * ++const X509_EXTENSION * + _cert_get_extension_id(X509 *ocert, int which, char **buf, int *len, int flags) + { + int pos; +@@ -434,27 +434,31 @@ _extract_oname(const GENERAL_NAME *oname) + break; + + case GEN_IPADD: +- if (oname->d.iPAddress->length == 4) { +- sprintf(ipbuf, "%d.%d.%d.%d", oname->d.iPAddress->data[0], +- oname->d.iPAddress->data[1], +- oname->d.iPAddress->data[2], +- oname->d.iPAddress->data[3]); +- rtn = strdup(ipbuf); +- } +- else if ((oname->d.iPAddress->length == 16) || +- (oname->d.iPAddress->length == 20)) { +- char *pos = ipbuf; +- int j; +- for(j = 0; j < oname->d.iPAddress->length; ++j) { +- *pos++ = VAL2HEX(oname->d.iPAddress->data[j]); +- *pos++ = ':'; ++ { ++ int ipaddr_len = ASN1_STRING_length(oname->d.iPAddress); ++ const unsigned char *ipaddr_data = ASN1_STRING_get0_data(oname->d.iPAddress); ++ if (ipaddr_len == 4) { ++ sprintf(ipbuf, "%d.%d.%d.%d", ipaddr_data[0], ++ ipaddr_data[1], ++ ipaddr_data[2], ++ ipaddr_data[3]); ++ rtn = strdup(ipbuf); ++ } ++ else if ((ipaddr_len == 16) || ++ (ipaddr_len == 20)) { ++ char *pos = ipbuf; ++ int j; ++ for(j = 0; j < ipaddr_len; ++j) { ++ *pos++ = VAL2HEX(ipaddr_data[j]); ++ *pos++ = ':'; ++ } ++ *pos = '\0'; ++ rtn = strdup(ipbuf); + } +- *pos = '\0'; +- rtn = strdup(ipbuf); ++ else ++ NETSNMP_LOGONCE((LOG_WARNING, "unexpected ip addr length %d\n", ++ ipaddr_len)); + } +- else +- NETSNMP_LOGONCE((LOG_WARNING, "unexpected ip addr length %d\n", +- oname->d.iPAddress->length)); + + break; + default: +@@ -485,7 +489,7 @@ netsnmp_openssl_cert_get_subjectAltNames(X509 *ocert, char **buf, int *len) + void + netsnmp_openssl_cert_dump_extensions(X509 *ocert) + { +- X509_EXTENSION *extension; ++ const X509_EXTENSION *extension; + const char *extension_name; + char buf[SNMP_MAXBUF], *buf_ptr = buf, *str, *lf; + int i, num_extensions, buf_len, nid; +-- +2.53.0 + diff --git a/net-snmp.spec b/net-snmp.spec index f65b878..adfab89 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -10,7 +10,7 @@ Summary: A collection of SNMP protocol tools and libraries Name: net-snmp Version: 5.9.5.2 -Release: 5%{?dist} +Release: 6%{?dist} Epoch: 1 License: MIT-CMU AND BSD-3-Clause AND MIT @@ -58,6 +58,9 @@ Patch102: net-snmp-5.9-python3.patch # make Mail::Sender optional Patch103: net-snmp-5.9-mail-sender.patch +# Openssl 4 build fixes +Patch104: 0001-Use-OpenSSL-accessors-for-opaque-structs.patch + Requires: %{name}-libs%{?_isa} = %{epoch}:%{version}-%{release} Requires: %{name}-agent-libs%{?_isa} = %{epoch}:%{version}-%{release} # This is actually needed for the %%triggerun script but Requires(triggerun) @@ -243,6 +246,7 @@ cp %{SOURCE10} . %if 0%{?rhel} %patch 103 -p1 %endif +%patch 104 -p1 # disable failing test - see https://bugzilla.redhat.com/show_bug.cgi?id=680697 rm testing/fulltests/default/T200* @@ -510,6 +514,9 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog +* Fri Jun 12 2026 Simo Sorce - 1:5.9.5.2-6 +- Openssl 4 and autoconf build fixes + * Wed Jun 03 2026 Python Maint - 1:5.9.5.2-5 - Rebuilt for Python 3.15 From 7f44925712cf462a418b73be15c79e833c1349a7 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 16 Jul 2026 09:28:09 +0000 Subject: [PATCH 24/27] Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild --- net-snmp.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/net-snmp.spec b/net-snmp.spec index adfab89..492fd44 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -10,7 +10,7 @@ Summary: A collection of SNMP protocol tools and libraries Name: net-snmp Version: 5.9.5.2 -Release: 6%{?dist} +Release: 7%{?dist} Epoch: 1 License: MIT-CMU AND BSD-3-Clause AND MIT @@ -514,6 +514,9 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog +* Thu Jul 16 2026 Fedora Release Engineering - 1:5.9.5.2-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild + * Fri Jun 12 2026 Simo Sorce - 1:5.9.5.2-6 - Openssl 4 and autoconf build fixes From baccc928a0a934cedc2e898fd071d1bb8fc0cf71 Mon Sep 17 00:00:00 2001 From: Python Maint Date: Wed, 22 Jul 2026 10:56:03 +0200 Subject: [PATCH 25/27] Rebuilt for Python 3.15.0b4 ABI change --- net-snmp.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/net-snmp.spec b/net-snmp.spec index 492fd44..42b41f1 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -10,7 +10,7 @@ Summary: A collection of SNMP protocol tools and libraries Name: net-snmp Version: 5.9.5.2 -Release: 7%{?dist} +Release: 8%{?dist} Epoch: 1 License: MIT-CMU AND BSD-3-Clause AND MIT @@ -514,6 +514,9 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog +* Wed Jul 22 2026 Python Maint - 1:5.9.5.2-8 +- Rebuilt for Python 3.15.0b4 ABI change + * Thu Jul 16 2026 Fedora Release Engineering - 1:5.9.5.2-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild From 649594e0a8fdae546da4cb53e2893d1bc4c3a34c Mon Sep 17 00:00:00 2001 From: Jitka Plesnikova Date: Thu, 23 Jul 2026 17:39:50 +0200 Subject: [PATCH 26/27] Perl 5.44 rebuild --- net-snmp.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/net-snmp.spec b/net-snmp.spec index 42b41f1..4b86b72 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -10,7 +10,7 @@ Summary: A collection of SNMP protocol tools and libraries Name: net-snmp Version: 5.9.5.2 -Release: 8%{?dist} +Release: 9%{?dist} Epoch: 1 License: MIT-CMU AND BSD-3-Clause AND MIT @@ -514,6 +514,9 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog +* Thu Jul 23 2026 Jitka Plesnikova - 1:5.9.5.2-9 +- Perl 5.44 rebuild + * Wed Jul 22 2026 Python Maint - 1:5.9.5.2-8 - Rebuilt for Python 3.15.0b4 ABI change From 28e611c95877f50f1bd9adc9bc5513f544261966 Mon Sep 17 00:00:00 2001 From: Python Maint Date: Fri, 24 Jul 2026 12:56:28 +0200 Subject: [PATCH 27/27] Rebuilt for Python 3.15.0b4 ABI change --- net-snmp.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/net-snmp.spec b/net-snmp.spec index 4b86b72..c762558 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -10,7 +10,7 @@ Summary: A collection of SNMP protocol tools and libraries Name: net-snmp Version: 5.9.5.2 -Release: 9%{?dist} +Release: 10%{?dist} Epoch: 1 License: MIT-CMU AND BSD-3-Clause AND MIT @@ -514,6 +514,9 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog +* Fri Jul 24 2026 Python Maint - 1:5.9.5.2-10 +- Rebuilt for Python 3.15.0b4 ABI change + * Thu Jul 23 2026 Jitka Plesnikova - 1:5.9.5.2-9 - Perl 5.44 rebuild