Compare commits

..

1 commit

Author SHA1 Message Date
Josef Řídký
e4058c81e4 Fix autoconf for f40 and lower 2024-03-12 13:46:23 +01:00
29 changed files with 460 additions and 918 deletions

View file

@ -1 +0,0 @@
1

1
.gitignore vendored
View file

@ -10,4 +10,3 @@ net-snmp-5.5.tar.gz
/net-snmp-5.9.1.tar.gz
/net-snmp-5.9.3.tar.gz
/net-snmp-5.9.4.tar.gz
/net-snmp-5.9.5.2.tar.gz

View file

@ -1,177 +0,0 @@
From 338d289f1e14650edf0bd7e960272871029131e1 Mon Sep 17 00:00:00 2001
From: Simo Sorce <simo@redhat.com>
Date: Fri, 17 Apr 2026 12:47:18 -0400
Subject: [PATCH] Use OpenSSL accessors for opaque structs
Replaced direct access to `ASN1_STRING` fields with OpenSSL accessor functions
(e.g., `ASN1_STRING_type`, `ASN1_STRING_length`, `ASN1_STRING_get0_data`) and
updated `X509_NAME` and `X509_EXTENSION` pointers to `const`. This is required
to maintain compatibility with newer OpenSSL versions (4.0+) where these
structures were made opaque.
Co-authored-by: Gemini <gemini@google.com>
Signed-off-by: Simo Sorce <simo@redhat.com>
---
snmplib/snmp_openssl.c | 74 ++++++++++++++++++++++--------------------
1 file changed, 39 insertions(+), 35 deletions(-)
diff --git a/snmplib/snmp_openssl.c b/snmplib/snmp_openssl.c
index 4471a7a..658841a 100644
--- a/snmplib/snmp_openssl.c
+++ b/snmplib/snmp_openssl.c
@@ -147,7 +147,7 @@ void netsnmp_init_openssl(void) {
static char *
_cert_get_name(X509 *ocert, int which, char **buf, int *len, int flags)
{
- X509_NAME *osubj_name;
+ const X509_NAME *osubj_name;
int space;
char *buf_ptr;
@@ -187,7 +187,7 @@ _cert_get_name(X509 *ocert, int which, char **buf, int *len, int flags)
char *
netsnmp_openssl_cert_get_subjectName(X509 *ocert, char **buf, int *len)
{
- X509_NAME *osubj_name;
+ const X509_NAME *osubj_name;
int space;
char *buf_ptr;
@@ -233,11 +233,11 @@ netsnmp_openssl_cert_get_commonName(X509 *ocert, char **buf, int *len)
void
netsnmp_openssl_cert_dump_names(X509 *ocert)
{
- int i, onid;
- X509_NAME_ENTRY *oname_entry;
- ASN1_STRING *oname_value;
- X509_NAME *osubj_name;
- const char *prefix_short, *prefix_long;
+ int i, onid;
+ const X509_NAME_ENTRY *oname_entry;
+ const ASN1_STRING *oname_value;
+ const X509_NAME *osubj_name;
+ const char *prefix_short, *prefix_long;
if (NULL == ocert)
return;
@@ -253,7 +253,7 @@ netsnmp_openssl_cert_dump_names(X509 *ocert)
netsnmp_assert(NULL != oname_entry);
oname_value = X509_NAME_ENTRY_get_data(oname_entry);
- if (oname_value->type != V_ASN1_PRINTABLESTRING)
+ if (ASN1_STRING_type(oname_value) != V_ASN1_PRINTABLESTRING)
continue;
/** get NID */
@@ -268,7 +268,7 @@ netsnmp_openssl_cert_dump_names(X509 *ocert)
DEBUGMSGT(("9:cert:dump:names",
"[%02d] NID type %d, ASN type %d\n", i, onid,
- oname_value->type));
+ ASN1_STRING_type(oname_value)));
DEBUGMSGT(("9:cert:dump:names", "%s/%s: '%s'\n", prefix_long,
prefix_short, ASN1_STRING_get0_data(oname_value)));
}
@@ -276,7 +276,7 @@ netsnmp_openssl_cert_dump_names(X509 *ocert)
#endif /* NETSNMP_FEATURE_REMOVE_CERT_DUMP_NAMES */
static char *
-_cert_get_extension(X509_EXTENSION *oext, char **buf, int *len, int flags)
+_cert_get_extension(const X509_EXTENSION *oext, char **buf, int *len, int flags)
{
int space;
char *buf_ptr = NULL;
@@ -327,10 +327,10 @@ out:
*/
/** instead of exposing this function, make helper functions for each
* field, like netsnmp_openssl_cert_get_subjectAltName, below */
-X509_EXTENSION *
+const X509_EXTENSION *
_cert_get_extension_at(X509 *ocert, int pos, char **buf, int *len, int flags)
{
- X509_EXTENSION *oext;
+ const X509_EXTENSION *oext;
if ((NULL == ocert) || ((buf && !len) || (len && !buf)))
return NULL;
@@ -354,7 +354,7 @@ static char *
_cert_get_extension_str_at(X509 *ocert, int pos, char **buf, int *len,
int flags)
{
- X509_EXTENSION *oext;
+ const X509_EXTENSION *oext;
if ((NULL == ocert) || ((buf && !len) || (len && !buf)))
return NULL;
@@ -374,7 +374,7 @@ _cert_get_extension_str_at(X509 *ocert, int pos, char **buf, int *len,
*/
/** instead of exposing this function, make helper functions for each
* field, like netsnmp_openssl_cert_get_subjectAltName, below */
-X509_EXTENSION *
+const X509_EXTENSION *
_cert_get_extension_id(X509 *ocert, int which, char **buf, int *len, int flags)
{
int pos;
@@ -434,27 +434,31 @@ _extract_oname(const GENERAL_NAME *oname)
break;
case GEN_IPADD:
- if (oname->d.iPAddress->length == 4) {
- sprintf(ipbuf, "%d.%d.%d.%d", oname->d.iPAddress->data[0],
- oname->d.iPAddress->data[1],
- oname->d.iPAddress->data[2],
- oname->d.iPAddress->data[3]);
- rtn = strdup(ipbuf);
- }
- else if ((oname->d.iPAddress->length == 16) ||
- (oname->d.iPAddress->length == 20)) {
- char *pos = ipbuf;
- int j;
- for(j = 0; j < oname->d.iPAddress->length; ++j) {
- *pos++ = VAL2HEX(oname->d.iPAddress->data[j]);
- *pos++ = ':';
+ {
+ int ipaddr_len = ASN1_STRING_length(oname->d.iPAddress);
+ const unsigned char *ipaddr_data = ASN1_STRING_get0_data(oname->d.iPAddress);
+ if (ipaddr_len == 4) {
+ sprintf(ipbuf, "%d.%d.%d.%d", ipaddr_data[0],
+ ipaddr_data[1],
+ ipaddr_data[2],
+ ipaddr_data[3]);
+ rtn = strdup(ipbuf);
+ }
+ else if ((ipaddr_len == 16) ||
+ (ipaddr_len == 20)) {
+ char *pos = ipbuf;
+ int j;
+ for(j = 0; j < ipaddr_len; ++j) {
+ *pos++ = VAL2HEX(ipaddr_data[j]);
+ *pos++ = ':';
+ }
+ *pos = '\0';
+ rtn = strdup(ipbuf);
}
- *pos = '\0';
- rtn = strdup(ipbuf);
+ else
+ NETSNMP_LOGONCE((LOG_WARNING, "unexpected ip addr length %d\n",
+ ipaddr_len));
}
- else
- NETSNMP_LOGONCE((LOG_WARNING, "unexpected ip addr length %d\n",
- oname->d.iPAddress->length));
break;
default:
@@ -485,7 +489,7 @@ netsnmp_openssl_cert_get_subjectAltNames(X509 *ocert, char **buf, int *len)
void
netsnmp_openssl_cert_dump_extensions(X509 *ocert)
{
- X509_EXTENSION *extension;
+ const X509_EXTENSION *extension;
const char *extension_name;
char buf[SNMP_MAXBUF], *buf_ptr = buf, *str, *lf;
int i, num_extensions, buf_len, nid;
--
2.53.0

View file

@ -1,8 +1,7 @@
diff --git a/agent/mibgroup/host/data_access/swrun.c b/agent/mibgroup/host/data_access/swrun.c
index 7b278eb..5f10ade 100644
--- a/agent/mibgroup/host/data_access/swrun.c
+++ b/agent/mibgroup/host/data_access/swrun.c
@@ -143,6 +143,10 @@ swrun_count_processes_by_name( char *name )
diff -urNp old/agent/mibgroup/host/data_access/swrun.c new/agent/mibgroup/host/data_access/swrun.c
--- old/agent/mibgroup/host/data_access/swrun.c 2017-07-18 09:44:00.626109526 +0200
+++ new/agent/mibgroup/host/data_access/swrun.c 2017-07-19 15:27:50.452255836 +0200
@@ -102,6 +102,10 @@ swrun_count_processes_by_name( char *nam
return 0; /* or -1 */
it = CONTAINER_ITERATOR( swrun_container );

View file

@ -1,8 +1,7 @@
diff --git a/snmplib/snmp_api.c b/snmplib/snmp_api.c
index ad30397..307253a 100644
--- a/snmplib/snmp_api.c
+++ b/snmplib/snmp_api.c
@@ -231,7 +231,7 @@ static const char *api_errors[-SNMPERR_MAX + 1] = {
diff -urNp a/snmplib/snmp_api.c b/snmplib/snmp_api.c
--- a/snmplib/snmp_api.c 2020-11-26 11:05:51.084788775 +0100
+++ b/snmplib/snmp_api.c 2020-11-26 11:08:27.850751397 +0100
@@ -235,7 +235,7 @@ static const char *api_errors[-SNMPERR_M
"No error", /* SNMPERR_SUCCESS */
"Generic error", /* SNMPERR_GENERR */
"Invalid local port", /* SNMPERR_BAD_LOCPORT */
@ -11,7 +10,7 @@ index ad30397..307253a 100644
"Unknown session", /* SNMPERR_BAD_SESSION */
"Too long", /* SNMPERR_TOO_LONG */
"No socket", /* SNMPERR_NO_SOCKET */
@@ -1718,7 +1718,9 @@ _sess_open(netsnmp_session * in_session)
@@ -1662,7 +1662,9 @@ _sess_open(netsnmp_session * in_session)
DEBUGMSGTL(("_sess_open", "couldn't interpret peername\n"));
in_session->s_snmp_errno = SNMPERR_BAD_ADDRESS;
in_session->s_errno = errno;
@ -22,11 +21,10 @@ index ad30397..307253a 100644
return NULL;
}
diff --git a/snmplib/transports/snmpUDPIPv4BaseDomain.c b/snmplib/transports/snmpUDPIPv4BaseDomain.c
index 1e15a2f..47ac42e 100644
--- a/snmplib/transports/snmpUDPIPv4BaseDomain.c
+++ b/snmplib/transports/snmpUDPIPv4BaseDomain.c
@@ -224,6 +224,8 @@ netsnmp_udpipv4base_transport_bind(netsnmp_transport *t,
diff -ruNp a/snmplib/transports/snmpUDPIPv4BaseDomain.c b/snmplib/transports/snmpUDPIPv4BaseDomain.c
--- a/snmplib/transports/snmpUDPIPv4BaseDomain.c 2021-01-06 12:51:51.948106797 +0100
+++ b/snmplib/transports/snmpUDPIPv4BaseDomain.c 2021-01-06 14:17:31.029745744 +0100
@@ -209,6 +209,8 @@ netsnmp_udpipv4base_transport_bind(netsn
DEBUGMSGTL(("netsnmp_udpbase",
"failed to bind for clientaddr: %d %s\n",
errno, strerror(errno)));

View file

@ -1,8 +1,7 @@
diff --git a/agent/mibgroup/ip-mib/data_access/ipaddress_common.c b/agent/mibgroup/ip-mib/data_access/ipaddress_common.c
index 675d4ea..8d3708d 100644
--- a/agent/mibgroup/ip-mib/data_access/ipaddress_common.c
+++ b/agent/mibgroup/ip-mib/data_access/ipaddress_common.c
@@ -120,6 +120,7 @@ _remove_duplicates(netsnmp_container *container, u_int container_flags)
diff -urNp a/agent/mibgroup/ip-mib/data_access/ipaddress_common.c b/agent/mibgroup/ip-mib/data_access/ipaddress_common.c
--- a/agent/mibgroup/ip-mib/data_access/ipaddress_common.c 2020-06-10 13:27:03.213904398 +0200
+++ b/agent/mibgroup/ip-mib/data_access/ipaddress_common.c 2020-06-10 13:28:41.025863050 +0200
@@ -121,6 +121,7 @@ _remove_duplicates(netsnmp_container *co
for (entry = ITERATOR_FIRST(it); entry; entry = ITERATOR_NEXT(it)) {
if (prev_entry && _access_ipaddress_entry_compare_addr(prev_entry, entry) == 0) {
/* 'entry' is duplicate of the previous one -> delete it */

View file

@ -1,8 +1,7 @@
diff --git a/snmplib/read_config.c b/snmplib/read_config.c
index 159f4be..fa8fcba 100644
--- a/snmplib/read_config.c
+++ b/snmplib/read_config.c
@@ -1688,7 +1688,7 @@ snmp_save_persistent(const char *type)
diff -ruNp a/snmplib/read_config.c b/snmplib/read_config.c
--- a/snmplib/read_config.c 2020-06-10 09:51:57.184786510 +0200
+++ b/snmplib/read_config.c 2020-06-10 09:53:13.257507112 +0200
@@ -1642,7 +1642,7 @@ snmp_save_persistent(const char *type)
* save a warning header to the top of the new file
*/
snprintf(fileold, sizeof(fileold),

View file

@ -1,8 +1,7 @@
diff --git a/agent/mibgroup/mibII/ipAddr.c b/agent/mibgroup/mibII/ipAddr.c
index a89255f..ef67f5f 100644
--- a/agent/mibgroup/mibII/ipAddr.c
+++ b/agent/mibgroup/mibII/ipAddr.c
@@ -498,14 +498,16 @@ Address_Scan_Next(Index, Retin_ifaddr)
diff -urNp a/agent/mibgroup/mibII/ipAddr.c b/agent/mibgroup/mibII/ipAddr.c
--- a/agent/mibgroup/mibII/ipAddr.c 2020-06-10 14:14:30.113696471 +0200
+++ b/agent/mibgroup/mibII/ipAddr.c 2020-06-10 14:27:15.345354018 +0200
@@ -495,14 +495,16 @@ Address_Scan_Next(Index, Retin_ifaddr)
}
#elif defined(linux)
@ -20,7 +19,7 @@ index a89255f..ef67f5f 100644
/* get info about all interfaces */
@@ -513,28 +515,45 @@ Address_Scan_Init(void)
@@ -510,28 +512,45 @@ Address_Scan_Init(void)
SNMP_FREE(ifc.ifc_buf);
ifr_counter = 0;

View file

@ -0,0 +1,36 @@
diff -urNp a/man/net-snmp-create-v3-user.1.def b/man/net-snmp-create-v3-user.1.def
--- a/man/net-snmp-create-v3-user.1.def 2020-06-10 13:43:18.443070961 +0200
+++ b/man/net-snmp-create-v3-user.1.def 2020-06-10 13:49:25.975363441 +0200
@@ -3,7 +3,7 @@
net-snmp-create-v3-user \- create a SNMPv3 user in net-snmp configuration file
.SH SYNOPSIS
.PP
-.B net-snmp-create-v3-user [-ro] [-a authpass] [-x privpass] [-X DES|AES]
+.B net-snmp-create-v3-user [-ro] [-A authpass] [-a MD5|SHA] [-X privpass] [-x DES|AES]
.B [username]
.SH DESCRIPTION
.PP
@@ -16,13 +16,16 @@ new user in net-snmp configuration file
displays the net-snmp version number
.TP
\fB\-ro\fR
-create an user with read-only permissions
+creates a user with read-only permissions
.TP
-\fB\-a authpass\fR
-specify authentication password
+\fB\-A authpass\fR
+specifies the authentication password
.TP
-\fB\-x privpass\fR
-specify encryption password
+\fB\-a MD5|SHA\fR
+specifies the authentication password hashing algorithm
.TP
-\fB\-X DES|AES\fR
-specify encryption algorithm
+\fB\-X privpass\fR
+specifies the encryption password
+.TP
+\fB\-x DES|AES\fR
+specifies the encryption algorithm

View file

@ -0,0 +1,28 @@
diff --git a/agent/mibgroup/host/data_access/swinst_rpm.c b/agent/mibgroup/host/data_access/swinst_rpm.c
index 695c469..dd0e487 100644
--- a/agent/mibgroup/host/data_access/swinst_rpm.c
+++ b/agent/mibgroup/host/data_access/swinst_rpm.c
@@ -75,6 +75,9 @@ netsnmp_swinst_arch_init(void)
snprintf( pkg_directory, SNMP_MAXPATH, "%s/Packages", dbpath );
SNMP_FREE(rpmdbpath);
dbpath = NULL;
+#ifdef HAVE_RPMGETPATH
+ rpmFreeRpmrc();
+#endif
if (-1 == stat( pkg_directory, &stat_buf )) {
snmp_log(LOG_ERR, "Can't find directory of RPM packages\n");
pkg_directory[0] = '\0';
diff --git a/agent/mibgroup/host/hr_swinst.c b/agent/mibgroup/host/hr_swinst.c
index 1f52733..ccf1cab 100644
--- a/agent/mibgroup/host/hr_swinst.c
+++ b/agent/mibgroup/host/hr_swinst.c
@@ -231,6 +231,9 @@ init_hr_swinst(void)
snprintf(path, sizeof(path), "%s/packages.rpm", swi->swi_dbpath);
path[ sizeof(path)-1 ] = 0;
swi->swi_directory = strdup(path);
+#ifdef HAVE_RPMGETPATH
+ rpmFreeRpmrc();
+#endif
}
#else
# ifdef _PATH_HRSW_directory

View file

@ -1,19 +1,17 @@
diff --git a/perl/Makefile.PL b/perl/Makefile.PL
index 63e6333..82cedca 100644
--- a/perl/Makefile.PL
+++ b/perl/Makefile.PL
diff -urNp a/perl/Makefile.PL b/perl/Makefile.PL
--- a/perl/Makefile.PL 2020-08-26 08:32:52.498909823 +0200
+++ b/perl/Makefile.PL 2020-08-26 09:30:45.584951552 +0200
@@ -1,3 +1,4 @@
+use lib '.';
use strict;
use warnings;
use ExtUtils::MakeMaker;
diff --git a/perl/MakefileSubs.pm b/perl/MakefileSubs.pm
index 804b20e..25c5d67 100644
--- a/perl/MakefileSubs.pm
+++ b/perl/MakefileSubs.pm
@@ -126,7 +126,7 @@ sub AddCommonParams {
# Suppress warnings about old-style function definitions.
append($Params->{'CCFLAGS'}, '-Wno-old-style-definition');
diff -urNp a/perl/MakefileSubs.pm b/perl/MakefileSubs.pm
--- a/perl/MakefileSubs.pm 2020-08-26 08:32:52.498909823 +0200
+++ b/perl/MakefileSubs.pm 2020-08-26 08:36:44.097218448 +0200
@@ -116,7 +116,7 @@ sub AddCommonParams {
append($Params->{'CCFLAGS'}, $cflags);
append($Params->{'CCFLAGS'}, $Config{'ccflags'});
# Suppress known Perl header shortcomings.
- $Params->{'CCFLAGS'} =~ s/ -W(cast-qual|write-strings)//g;
+ $Params->{'CCFLAGS'} =~ s/ -W(inline|strict-prototypes|write-strings|cast-qual|no-char-subscripts)//g;

View file

@ -0,0 +1,22 @@
diff --git a/agent/mibgroup/disman/event/mteTrigger.c b/agent/mibgroup/disman/event/mteTrigger.c
index e9a8831..5a1d8e7 100644
--- a/agent/mibgroup/disman/event/mteTrigger.c
+++ b/agent/mibgroup/disman/event/mteTrigger.c
@@ -1012,7 +1012,7 @@ mteTrigger_run( unsigned int reg, void *clientarg)
* Similarly, if no fallEvent is configured,
* there's no point in trying to fire it either.
*/
- if (entry->mteTThRiseEvent[0] != '\0' ) {
+ if (entry->mteTThFallEvent[0] != '\0' ) {
entry->mteTriggerXOwner = entry->mteTThObjOwner;
entry->mteTriggerXObjects = entry->mteTThObjects;
entry->mteTriggerFired = vp1;
@@ -1105,7 +1105,7 @@ mteTrigger_run( unsigned int reg, void *clientarg)
* Similarly, if no fallEvent is configured,
* there's no point in trying to fire it either.
*/
- if (entry->mteTThDRiseEvent[0] != '\0' ) {
+ if (entry->mteTThDFallEvent[0] != '\0' ) {
entry->mteTriggerXOwner = entry->mteTThObjOwner;
entry->mteTriggerXObjects = entry->mteTThObjects;
entry->mteTriggerFired = vp1;

View file

@ -1,8 +1,8 @@
diff --git a/include/net-snmp/library/cert_util.h b/include/net-snmp/library/cert_util.h
index 305e367..6117b9a 100644
index 80e2a19..143adbb 100644
--- a/include/net-snmp/library/cert_util.h
+++ b/include/net-snmp/library/cert_util.h
@@ -48,7 +48,8 @@ extern "C" {
@@ -55,7 +55,8 @@ extern "C" {
char *common_name;
u_char hash_type;
@ -12,7 +12,7 @@ index 305e367..6117b9a 100644
} netsnmp_cert;
/** types */
@@ -93,6 +94,7 @@ extern "C" {
@@ -100,6 +101,7 @@ extern "C" {
NETSNMP_IMPORT
netsnmp_cert *netsnmp_cert_find(int what, int where, void *hint);
@ -35,21 +35,10 @@ index 471bb0b..ac7f69a 100644
#ifdef __cplusplus
diff --git a/snmplib/cert_util.c b/snmplib/cert_util.c
index 5b5aaaa..7c07048 100644
index 210ad8b..b1f8144 100644
--- a/snmplib/cert_util.c
+++ b/snmplib/cert_util.c
@@ -42,9 +42,7 @@ netsnmp_feature_child_of(tls_fingerprint_build, cert_util_all);
#include <ctype.h>
-#include <stddef.h>
-
-#if HAVE_STDLIB_H
+#ifdef HAVE_STDLIB_H
#include <stdlib.h>
#endif
@@ -102,7 +100,7 @@ netsnmp_feature_child_of(tls_fingerprint_build, cert_util_all);
@@ -100,7 +100,7 @@ netsnmp_feature_child_of(tls_fingerprint_build, cert_util_all);
* bump this value whenever cert index format changes, so indexes
* will be regenerated with new format.
*/
@ -58,28 +47,8 @@ index 5b5aaaa..7c07048 100644
static netsnmp_container *_certs = NULL;
static netsnmp_container *_keys = NULL;
@@ -116,16 +114,20 @@ static netsnmp_container *_trusted_certs = NULL;
static void _setup_containers(void);
static void _cert_indexes_load(void);
-static void _cert_free(void *cert, void *context);
-static void _key_free(void *key, void *context);
-static int _cert_compare(const void *p, const void *q);
-static int _cert_sn_compare(const void *p, const void *q);
-static int _cert_sn_ncompare(const void *p, const void *q);
-static int _cert_cn_compare(const void *p, const void *q);
-static int _cert_fn_compare(const void *p, const void *q);
-static int _cert_fn_ncompare(const void *p, const void *q);
+static void _cert_free(netsnmp_cert *cert, void *context);
+static void _key_free(netsnmp_key *key, void *context);
+static int _cert_compare(netsnmp_cert *lhs, netsnmp_cert *rhs);
+static int _cert_sn_compare(netsnmp_cert *lhs, netsnmp_cert *rhs);
+static int _cert_sn_ncompare(netsnmp_cert *lhs, netsnmp_cert *rhs);
+static int _cert_cn_compare(netsnmp_cert *lhs, netsnmp_cert *rhs);
+static int _cert_fn_compare(netsnmp_cert_common *lhs,
+ netsnmp_cert_common *rhs);
+static int _cert_fn_ncompare(netsnmp_cert_common *lhs,
+ netsnmp_cert_common *rhs);
@@ -126,6 +126,8 @@ static int _cert_fn_ncompare(netsnmp_cert_common *lhs,
netsnmp_cert_common *rhs);
static void _find_partner(netsnmp_cert *cert, netsnmp_key *key);
static netsnmp_cert *_find_issuer(netsnmp_cert *cert);
+static netsnmp_void_array *_cert_reduce_subset_first(netsnmp_void_array *matching);
@ -87,16 +56,7 @@ index 5b5aaaa..7c07048 100644
static netsnmp_void_array *_cert_find_subset_fn(const char *filename,
const char *directory);
static netsnmp_void_array *_cert_find_subset_sn(const char *subject);
@@ -200,7 +202,7 @@ _setup_trusted_certs(void)
return;
}
_trusted_certs->container_name = strdup("trusted certificates");
- _trusted_certs->compare = netsnmp_str_compare;
+ _trusted_certs->compare = (netsnmp_container_compare*) strcmp;
}
/*
@@ -345,14 +347,18 @@ _get_cert_container(const char *use)
@@ -345,6 +347,8 @@ _get_cert_container(const char *use)
{
netsnmp_container *c;
@ -105,61 +65,49 @@ index 5b5aaaa..7c07048 100644
c = netsnmp_container_find("certs:binary_array");
if (NULL == c) {
snmp_log(LOG_ERR, "could not create container for %s\n", use);
return NULL;
}
c->container_name = strdup(use);
- c->free_item = _cert_free;
- c->compare = _cert_compare;
+ c->free_item = (netsnmp_container_obj_func*)_cert_free;
+ c->compare = (netsnmp_container_compare*)_cert_compare;
+
+ CONTAINER_SET_OPTIONS(c, CONTAINER_KEY_ALLOW_DUPLICATES, rc);
@@ -354,6 +358,8 @@ _get_cert_container(const char *use)
c->free_item = (netsnmp_container_obj_func*)_cert_free;
c->compare = (netsnmp_container_compare*)_cert_compare;
+ CONTAINER_SET_OPTIONS(c, CONTAINER_KEY_ALLOW_DUPLICATES, rc);
+
return c;
}
@@ -377,7 +383,7 @@ _setup_containers(void)
}
@@ -362,6 +368,8 @@ _setup_containers(void)
{
netsnmp_container *additional_keys;
+ int rc;
+
_certs = _get_cert_container("netsnmp certificates");
if (NULL == _certs)
return;
@@ -376,6 +384,7 @@ _setup_containers(void)
additional_keys->container_name = strdup("certs_cn");
additional_keys->free_item = NULL;
- additional_keys->compare = _cert_cn_compare;
+ additional_keys->compare = (netsnmp_container_compare*)_cert_cn_compare;
CONTAINER_SET_OPTIONS(additional_keys, CONTAINER_KEY_ALLOW_DUPLICATES, rc);
additional_keys->compare = (netsnmp_container_compare*)_cert_cn_compare;
+ CONTAINER_SET_OPTIONS(additional_keys, CONTAINER_KEY_ALLOW_DUPLICATES, rc);
netsnmp_container_add_index(_certs, additional_keys);
@@ -390,8 +396,8 @@ _setup_containers(void)
}
additional_keys->container_name = strdup("certs_sn");
/** additional keys: subject name */
@@ -389,6 +398,7 @@ _setup_containers(void)
additional_keys->free_item = NULL;
- additional_keys->compare = _cert_sn_compare;
- additional_keys->ncompare = _cert_sn_ncompare;
+ additional_keys->compare = (netsnmp_container_compare*)_cert_sn_compare;
+ additional_keys->ncompare = (netsnmp_container_compare*)_cert_sn_ncompare;
CONTAINER_SET_OPTIONS(additional_keys, CONTAINER_KEY_ALLOW_DUPLICATES, rc);
additional_keys->compare = (netsnmp_container_compare*)_cert_sn_compare;
additional_keys->ncompare = (netsnmp_container_compare*)_cert_sn_ncompare;
+ CONTAINER_SET_OPTIONS(additional_keys, CONTAINER_KEY_ALLOW_DUPLICATES, rc);
netsnmp_container_add_index(_certs, additional_keys);
@@ -404,8 +410,8 @@ _setup_containers(void)
}
additional_keys->container_name = strdup("certs_fn");
/** additional keys: file name */
@@ -402,6 +412,7 @@ _setup_containers(void)
additional_keys->free_item = NULL;
- additional_keys->compare = _cert_fn_compare;
- additional_keys->ncompare = _cert_fn_ncompare;
+ additional_keys->compare = (netsnmp_container_compare*)_cert_fn_compare;
+ additional_keys->ncompare = (netsnmp_container_compare*)_cert_fn_ncompare;
CONTAINER_SET_OPTIONS(additional_keys, CONTAINER_KEY_ALLOW_DUPLICATES, rc);
additional_keys->compare = (netsnmp_container_compare*)_cert_fn_compare;
additional_keys->ncompare = (netsnmp_container_compare*)_cert_fn_ncompare;
+ CONTAINER_SET_OPTIONS(additional_keys, CONTAINER_KEY_ALLOW_DUPLICATES, rc);
netsnmp_container_add_index(_certs, additional_keys);
@@ -416,8 +422,8 @@ _setup_containers(void)
return;
}
_keys->container_name = strdup("netsnmp certificate keys");
- _keys->free_item = _key_free;
- _keys->compare = _cert_fn_compare;
+ _keys->free_item = (netsnmp_container_obj_func*)_key_free;
+ _keys->compare = (netsnmp_container_compare*)_cert_fn_compare;
_setup_trusted_certs();
}
@@ -429,7 +435,7 @@ netsnmp_cert_map_container(void)
_keys = netsnmp_container_find("cert_keys:binary_array");
@@ -424,7 +435,7 @@ netsnmp_cert_map_container(void)
}
static netsnmp_cert *
@ -168,7 +116,7 @@ index 5b5aaaa..7c07048 100644
int hashType, const char *fingerprint, const char *common_name,
const char *subject)
{
@@ -451,8 +457,10 @@ _new_cert(const char *dirname, const char *filename, int certType,
@@ -446,8 +457,10 @@ _new_cert(const char *dirname, const char *filename, int certType,
cert->info.dir = strdup(dirname);
cert->info.filename = strdup(filename);
@ -180,112 +128,7 @@ index 5b5aaaa..7c07048 100644
if (fingerprint) {
cert->hash_type = hashType;
cert->fingerprint = strdup(fingerprint);
@@ -553,22 +561,20 @@ netsnmp_key_free(netsnmp_key *key)
}
static void
-_cert_free(void *cert, void *context)
+_cert_free(netsnmp_cert *cert, void *context)
{
netsnmp_cert_free(cert);
}
static void
-_key_free(void *key, void *context)
+_key_free(netsnmp_key *key, void *context)
{
netsnmp_key_free(key);
}
static int
-_cert_compare(const void *p, const void *q)
+_cert_compare(netsnmp_cert *lhs, netsnmp_cert *rhs)
{
- const netsnmp_cert *lhs = p, *rhs = q;
-
netsnmp_assert((lhs != NULL) && (rhs != NULL));
netsnmp_assert((lhs->fingerprint != NULL) &&
(rhs->fingerprint != NULL));
@@ -578,8 +584,7 @@ _cert_compare(const void *p, const void *q)
}
static int
-_cert_path_compare(const netsnmp_cert_common *lhs,
- const netsnmp_cert_common *rhs)
+_cert_path_compare(netsnmp_cert_common *lhs, netsnmp_cert_common *rhs)
{
int rc;
@@ -595,9 +600,8 @@ _cert_path_compare(const netsnmp_cert_common *lhs,
}
static int
-_cert_cn_compare(const void *p, const void *q)
+_cert_cn_compare(netsnmp_cert *lhs, netsnmp_cert *rhs)
{
- const netsnmp_cert *lhs = p, *rhs = q;
int rc;
const char *lhcn, *rhcn;
@@ -617,13 +621,13 @@ _cert_cn_compare(const void *p, const void *q)
return rc;
/** in case of equal common names, sub-sort by path */
- return _cert_path_compare(&lhs->info, &rhs->info);
+ return _cert_path_compare((netsnmp_cert_common*)lhs,
+ (netsnmp_cert_common*)rhs);
}
static int
-_cert_sn_compare(const void *p, const void *q)
+_cert_sn_compare(netsnmp_cert *lhs, netsnmp_cert *rhs)
{
- const netsnmp_cert *lhs = p, *rhs = q;
int rc;
const char *lhsn, *rhsn;
@@ -643,13 +647,13 @@ _cert_sn_compare(const void *p, const void *q)
return rc;
/** in case of equal common names, sub-sort by path */
- return _cert_path_compare(&lhs->info, &rhs->info);
+ return _cert_path_compare((netsnmp_cert_common*)lhs,
+ (netsnmp_cert_common*)rhs);
}
static int
-_cert_fn_compare(const void *p, const void *q)
+_cert_fn_compare(netsnmp_cert_common *lhs, netsnmp_cert_common *rhs)
{
- const netsnmp_cert_common *lhs = p, *rhs = q;
int rc;
netsnmp_assert((lhs != NULL) && (rhs != NULL));
@@ -663,10 +667,8 @@ _cert_fn_compare(const void *p, const void *q)
}
static int
-_cert_fn_ncompare(const void *p, const void *q)
+_cert_fn_ncompare(netsnmp_cert_common *lhs, netsnmp_cert_common *rhs)
{
- const netsnmp_cert_common *lhs = p, *rhs = q;
-
netsnmp_assert((lhs != NULL) && (rhs != NULL));
netsnmp_assert((lhs->filename != NULL) && (rhs->filename != NULL));
@@ -674,10 +676,8 @@ _cert_fn_ncompare(const void *p, const void *q)
}
static int
-_cert_sn_ncompare(const void *p, const void *q)
+_cert_sn_ncompare(netsnmp_cert *lhs, netsnmp_cert *rhs)
{
- const netsnmp_cert *lhs = p, *rhs = q;
-
netsnmp_assert((lhs != NULL) && (rhs != NULL));
netsnmp_assert((lhs->subject != NULL) && (rhs->subject != NULL));
@@ -897,14 +897,86 @@ _certindex_new( const char *dirname )
@@ -884,14 +897,86 @@ _certindex_new( const char *dirname )
* certificate utility functions
*
*/
@ -374,7 +217,7 @@ index 5b5aaaa..7c07048 100644
if (NULL == cert)
return NULL;
@@ -921,51 +993,33 @@ netsnmp_ocert_get(netsnmp_cert *cert)
@@ -908,51 +993,33 @@ netsnmp_ocert_get(netsnmp_cert *cert)
}
}
@ -434,7 +277,7 @@ index 5b5aaaa..7c07048 100644
if (NULL != okey) {
netsnmp_key *key;
DEBUGMSGT(("cert:read:key", "found key with cert in %s\n",
@@ -992,7 +1046,7 @@ netsnmp_ocert_get(netsnmp_cert *cert)
@@ -979,7 +1046,7 @@ netsnmp_ocert_get(netsnmp_cert *cert)
break;
#ifdef CERT_PKCS12_SUPPORT_MAYBE_LATER
case NS_CERT_TYPE_PKCS12:
@ -443,7 +286,7 @@ index 5b5aaaa..7c07048 100644
PKCS12 *p12 = d2i_PKCS12_bio(certbio, NULL);
if ( (NULL != p12) && (PKCS12_verify_mac(p12, "", 0) ||
PKCS12_verify_mac(p12, NULL, 0)))
@@ -1012,46 +1066,7 @@ netsnmp_ocert_get(netsnmp_cert *cert)
@@ -999,46 +1066,7 @@ netsnmp_ocert_get(netsnmp_cert *cert)
return NULL;
}
@ -477,7 +320,7 @@ index 5b5aaaa..7c07048 100644
- }
-
- if (NULL == cert->fingerprint) {
- cert->hash_type = NS_HASH_SHA1;
- cert->hash_type = netsnmp_openssl_cert_get_hash_type(ocert);
- cert->fingerprint =
- netsnmp_openssl_cert_get_fingerprint(ocert, cert->hash_type);
- }
@ -491,7 +334,7 @@ index 5b5aaaa..7c07048 100644
return ocert;
}
@@ -1061,7 +1076,6 @@ netsnmp_okey_get(netsnmp_key *key)
@@ -1048,7 +1076,6 @@ netsnmp_okey_get(netsnmp_key *key)
{
BIO *keybio;
EVP_PKEY *okey;
@ -499,7 +342,7 @@ index 5b5aaaa..7c07048 100644
if (NULL == key)
return NULL;
@@ -1069,19 +1083,8 @@ netsnmp_okey_get(netsnmp_key *key)
@@ -1056,19 +1083,8 @@ netsnmp_okey_get(netsnmp_key *key)
if (key->okey)
return key->okey;
@ -521,7 +364,7 @@ index 5b5aaaa..7c07048 100644
return NULL;
}
@@ -1167,7 +1170,7 @@ netsnmp_cert_load_x509(netsnmp_cert *cert)
@@ -1154,7 +1170,7 @@ netsnmp_cert_load_x509(netsnmp_cert *cert)
cert->issuer_cert = _find_issuer(cert);
if (NULL == cert->issuer_cert) {
DEBUGMSGT(("cert:load:warn",
@ -530,7 +373,7 @@ index 5b5aaaa..7c07048 100644
cert->info.filename));
rc = CERT_LOAD_PARTIAL;
break;
@@ -1176,7 +1179,7 @@ netsnmp_cert_load_x509(netsnmp_cert *cert)
@@ -1163,7 +1179,7 @@ netsnmp_cert_load_x509(netsnmp_cert *cert)
/** get issuer ocert */
if ((NULL == cert->issuer_cert->ocert) &&
(netsnmp_ocert_get(cert->issuer_cert) == NULL)) {
@ -539,7 +382,7 @@ index 5b5aaaa..7c07048 100644
cert->info.filename));
rc = CERT_LOAD_PARTIAL;
break;
@@ -1197,7 +1200,7 @@ _find_partner(netsnmp_cert *cert, netsnmp_key *key)
@@ -1184,7 +1200,7 @@ _find_partner(netsnmp_cert *cert, netsnmp_key *key)
return;
}
@ -548,7 +391,7 @@ index 5b5aaaa..7c07048 100644
if (key->cert) {
DEBUGMSGT(("cert:partner", "key already has partner\n"));
return;
@@ -1210,7 +1213,8 @@ _find_partner(netsnmp_cert *cert, netsnmp_key *key)
@@ -1197,7 +1213,8 @@ _find_partner(netsnmp_cert *cert, netsnmp_key *key)
return;
*pos = 0;
@ -558,7 +401,7 @@ index 5b5aaaa..7c07048 100644
if (!matching)
return;
if (1 == matching->size) {
@@ -1230,7 +1234,7 @@ _find_partner(netsnmp_cert *cert, netsnmp_key *key)
@@ -1217,7 +1234,7 @@ _find_partner(netsnmp_cert *cert, netsnmp_key *key)
DEBUGMSGT(("cert:partner", "%s matches multiple certs\n",
key->info.filename));
}
@ -567,7 +410,7 @@ index 5b5aaaa..7c07048 100644
if (cert->key) {
DEBUGMSGT(("cert:partner", "cert already has partner\n"));
return;
@@ -1268,76 +1272,182 @@ _find_partner(netsnmp_cert *cert, netsnmp_key *key)
@@ -1255,76 +1272,182 @@ _find_partner(netsnmp_cert *cert, netsnmp_key *key)
}
}
@ -803,7 +646,7 @@ index 5b5aaaa..7c07048 100644
}
return 0;
@@ -1351,7 +1461,8 @@ _cert_read_index(const char *dirname, struct stat *dirstat)
@@ -1338,7 +1461,8 @@ _cert_read_index(const char *dirname, struct stat *dirstat)
struct stat idx_stat;
char tmpstr[SNMP_MAXPATH + 5], filename[NAME_MAX];
char fingerprint[EVP_MAX_MD_SIZE*3], common_name[64+1], type_str[15];
@ -813,7 +656,7 @@ index 5b5aaaa..7c07048 100644
int count = 0, type, hash, version;
netsnmp_cert *cert;
netsnmp_key *key;
@@ -1394,7 +1505,8 @@ _cert_read_index(const char *dirname, struct stat *dirstat)
@@ -1381,7 +1505,8 @@ _cert_read_index(const char *dirname, struct stat *dirstat)
netsnmp_directory_container_read_some(NULL, dirname,
_time_filter, &idx_stat,
NETSNMP_DIR_NSFILE |
@ -823,7 +666,7 @@ index 5b5aaaa..7c07048 100644
if (newer) {
DEBUGMSGT(("cert:index:parse", "Index outdated; files modified\n"));
CONTAINER_FREE_ALL(newer, NULL);
@@ -1439,6 +1551,7 @@ _cert_read_index(const char *dirname, struct stat *dirstat)
@@ -1426,6 +1551,7 @@ _cert_read_index(const char *dirname, struct stat *dirstat)
pos = &tmpstr[2];
if ((NULL == (pos=copy_nword(pos, filename, sizeof(filename)))) ||
(NULL == (pos=copy_nword(pos, type_str, sizeof(type_str)))) ||
@ -831,7 +674,7 @@ index 5b5aaaa..7c07048 100644
(NULL == (pos=copy_nword(pos, hash_str, sizeof(hash_str)))) ||
(NULL == (pos=copy_nword(pos, fingerprint,
sizeof(fingerprint)))) ||
@@ -1451,8 +1564,9 @@ _cert_read_index(const char *dirname, struct stat *dirstat)
@@ -1438,8 +1564,9 @@ _cert_read_index(const char *dirname, struct stat *dirstat)
break;
}
type = atoi(type_str);
@ -842,7 +685,7 @@ index 5b5aaaa..7c07048 100644
common_name, subject);
if (cert && 0 == CONTAINER_INSERT(found, cert))
++count;
@@ -1559,7 +1673,8 @@ _add_certdir(const char *dirname)
@@ -1546,7 +1673,8 @@ _add_certdir(const char *dirname)
netsnmp_directory_container_read_some(NULL, dirname,
_cert_cert_filter, NULL,
NETSNMP_DIR_RELATIVE_PATH |
@ -852,15 +695,7 @@ index 5b5aaaa..7c07048 100644
if (NULL == cert_container) {
DEBUGMSGT(("cert:index:dir",
"error creating container for cert files\n"));
@@ -1642,14 +1757,12 @@ _cert_indexes_load(void)
}
static void
-_cert_print(void *p, void *context)
+_cert_print(netsnmp_cert *c, void *context)
{
- netsnmp_cert *c = p;
-
@@ -1634,7 +1762,7 @@ _cert_print(netsnmp_cert *c, void *context)
if (NULL == c)
return;
@ -869,39 +704,7 @@ index 5b5aaaa..7c07048 100644
DEBUGMSGT(("cert:dump", " type %d flags 0x%x (%s)\n",
c->info.type, c->info.allowed_uses,
_mode_str(c->info.allowed_uses)));
@@ -1676,10 +1789,8 @@ _cert_print(void *p, void *context)
}
static void
-_key_print(void *p, void *context)
+_key_print(netsnmp_key *k, void *context)
{
- netsnmp_key *k = p;
-
if (NULL == k)
return;
@@ -1691,8 +1802,8 @@ _key_print(void *p, void *context)
void
netsnmp_cert_dump_all(void)
{
- CONTAINER_FOR_EACH(_certs, _cert_print, NULL);
- CONTAINER_FOR_EACH(_keys, _key_print, NULL);
+ CONTAINER_FOR_EACH(_certs, (netsnmp_container_obj_func*)_cert_print, NULL);
+ CONTAINER_FOR_EACH(_keys, (netsnmp_container_obj_func*)_key_print, NULL);
}
#ifdef CERT_MAIN
@@ -1726,6 +1837,8 @@ main(int argc, char** argv)
#endif /* CERT_MAIN */
+static netsnmp_cert *_cert_find_fp(const char *fingerprint);
+
void
netsnmp_fp_lowercase_and_strip_colon(char *fp)
{
@@ -1853,7 +1966,8 @@ netsnmp_cert_find(int what, int where, void *hint)
@@ -1838,7 +1966,8 @@ netsnmp_cert_find(int what, int where, void *hint)
netsnmp_void_array *matching;
DEBUGMSGT(("cert:find:params", " hint = %s\n", (char *)hint));
@ -911,16 +714,7 @@ index 5b5aaaa..7c07048 100644
if (!matching)
return NULL;
if (1 == matching->size)
@@ -2061,7 +2175,7 @@ netsnmp_cert_trust(SSL_CTX *ctx, netsnmp_cert *thiscert)
SNMPERR_GENERR);
/* Put the certificate into the store */
- fingerprint = netsnmp_openssl_cert_get_fingerprint(cert, NS_HASH_SHA1);
+ fingerprint = netsnmp_openssl_cert_get_fingerprint(cert, -1);
DEBUGMSGTL(("cert:trust",
"putting trusted cert %p = %s in certstore %p\n", cert,
fingerprint, certstore));
@@ -2296,6 +2410,124 @@ _reduce_subset_dir(netsnmp_void_array *matching, const char *directory)
@@ -2281,6 +2410,124 @@ _reduce_subset_dir(netsnmp_void_array *matching, const char *directory)
}
}
@ -1045,95 +839,11 @@ index 5b5aaaa..7c07048 100644
static netsnmp_void_array *
_cert_find_subset_common(const char *filename, netsnmp_container *container)
{
@@ -2433,7 +2665,7 @@ _time_filter(const void *text, void *ctx)
* ***************************************************************************/
#define MAP_CONFIG_TOKEN "certSecName"
static void _parse_map(const char *token, char *line);
-static void _map_free(void *map, void *ctx);
+static void _map_free(netsnmp_cert_map* entry, void *ctx);
static void _purge_config_entries(void);
static void
@@ -2538,16 +2770,14 @@ netsnmp_cert_map_find(netsnmp_cert_map *map)
#endif /* NETSNMP_FEATURE_REMOVE_CERT_MAP_FIND */
static void
-_map_free(void *map, void *context)
+_map_free(netsnmp_cert_map *map, void *context)
{
netsnmp_cert_map_free(map);
}
static int
-_map_compare(const void *p, const void *q)
+_map_compare(netsnmp_cert_map *lhs, netsnmp_cert_map *rhs)
{
- const netsnmp_cert_map *lhs = p, *rhs = q;
-
netsnmp_assert((lhs != NULL) && (rhs != NULL));
if (lhs->priority < rhs->priority)
@@ -2559,11 +2789,9 @@ _map_compare(const void *p, const void *q)
}
static int
-_map_fp_compare(const void *p, const void *q)
+_map_fp_compare(netsnmp_cert_map *lhs, netsnmp_cert_map *rhs)
{
- const netsnmp_cert_map *lhs = p, *rhs = q;
int rc;
-
netsnmp_assert((lhs != NULL) && (rhs != NULL));
if ((rc = strcmp(lhs->fingerprint, rhs->fingerprint)) != 0)
@@ -2578,10 +2806,8 @@ _map_fp_compare(const void *p, const void *q)
}
static int
-_map_fp_ncompare(const void *p, const void *q)
+_map_fp_ncompare(netsnmp_cert_map *lhs, netsnmp_cert_map *rhs)
{
- const netsnmp_cert_map *lhs = p, *rhs = q;
-
netsnmp_assert((lhs != NULL) && (rhs != NULL));
return strncmp(lhs->fingerprint, rhs->fingerprint,
@@ -2600,8 +2826,8 @@ netsnmp_cert_map_container_create(int with_fp)
}
chain_map->container_name = strdup("cert_map");
- chain_map->free_item = _map_free;
- chain_map->compare = _map_compare;
+ chain_map->free_item = (netsnmp_container_obj_func*)_map_free;
+ chain_map->compare = (netsnmp_container_compare*)_map_compare;
if (!with_fp)
return chain_map;
@@ -2617,8 +2843,8 @@ netsnmp_cert_map_container_create(int with_fp)
return NULL;
}
fp->container_name = strdup("cert2sn_fp");
- fp->compare = _map_fp_compare;
- fp->ncompare = _map_fp_ncompare;
+ fp->compare = (netsnmp_container_compare*)_map_fp_compare;
+ fp->ncompare = (netsnmp_container_compare*)_map_fp_ncompare;
netsnmp_container_add_index(chain_map, fp);
return chain_map;
@@ -2769,7 +2995,7 @@ netsnmp_certToTSN_parse_common(char **line)
map->fingerprint = strdup(buf);
} else {
map->fingerprint =
- netsnmp_openssl_cert_get_fingerprint(tmpcert->ocert, NS_HASH_SHA1);
+ netsnmp_openssl_cert_get_fingerprint(tmpcert->ocert, -1);
}
if (NULL == *line) {
diff --git a/snmplib/dir_utils.c b/snmplib/dir_utils.c
index 48c1a0f..32426f8 100644
index c2dd989..e7145e4 100644
--- a/snmplib/dir_utils.c
+++ b/snmplib/dir_utils.c
@@ -105,6 +105,9 @@ netsnmp_directory_container_read_some(netsnmp_container *user_container,
@@ -107,6 +107,9 @@ netsnmp_directory_container_read_some(netsnmp_container *user_container,
/** default to unsorted */
if (! (flags & NETSNMP_DIR_SORTED))
CONTAINER_SET_OPTIONS(container, CONTAINER_KEY_UNSORTED, rc);

View file

@ -1,24 +0,0 @@
diff -up ./local/checkbandwidth.orig ./local/checkbandwidth
--- ./local/checkbandwidth.orig 2023-08-15 16:32:01.000000000 -0400
+++ ./local/checkbandwidth 2025-03-20 16:31:14.062432316 -0400
@@ -326,7 +326,6 @@ See the Net-SNMP COPYING file for licens
use JSON;
use Data::Dumper;
-use Mail::Sender;
use SNMP;
use Fcntl ':flock';
@@ -744,6 +743,12 @@ sub send_rate_message($$$$$$) {
sub send_message($$$) {
my ($to, $subject, $text) = @_;
+ if (! eval {require Mail::Sender;}) {
+ Log("Failed to send mail with error code -1: Mail::Sender is not available");
+ return();
+ }
+
+ import Mail::Sender;
my $sender = new Mail::Sender { smtp => $opts{'S'} ,
port => $opts{'P'},
from => $opts{'F'},

View file

@ -1,5 +1,5 @@
diff --git a/man/netsnmp_config_api.3.def b/man/netsnmp_config_api.3.def
index d4e0c1a..9e3a166 100644
index 90b20d9..bd5abe1 100644
--- a/man/netsnmp_config_api.3.def
+++ b/man/netsnmp_config_api.3.def
@@ -295,7 +295,7 @@ for one particular machine.
@ -11,7 +11,7 @@ index d4e0c1a..9e3a166 100644
followed by \fC $HOME/.snmp\fP.
This list can be changed by setting the environmental variable
.I SNMPCONFPATH
@@ -367,7 +367,7 @@ A colon-separated list of directories to search for configuration
@@ -367,7 +367,7 @@ A colon separated list of directories to search for configuration
files in.
Default:
.br
@ -34,10 +34,10 @@ index fd30873..c3437d6 100644
snmptrapd.conf, as well as snmp.local.conf, snmpd.local.conf
and/or snmptrapd.local.conf. *.local.conf are always
diff --git a/man/snmpd.conf.5.def b/man/snmpd.conf.5.def
index 6acd8c7..0a8b9fa 100644
index 7ce8a46..a4000f9 100644
--- a/man/snmpd.conf.5.def
+++ b/man/snmpd.conf.5.def
@@ -1609,7 +1609,7 @@ filename), and call the initialisation routine \fIinit_NAME\fR.
@@ -1593,7 +1593,7 @@ filename), and call the initialisation routine \fIinit_NAME\fR.
.RS
.IP "Note:"
If the specified PATH is not a fully qualified filename, it will

View file

@ -1,5 +1,5 @@
diff --git a/Makefile.in b/Makefile.in
index bb4ada9..69ce4f0 100644
index 912f6b2..862fb5f 100644
--- a/Makefile.in
+++ b/Makefile.in
@@ -227,7 +227,7 @@ perlcleanfeatures:

65
net-snmp-5.9-rpmdb.patch Normal file
View file

@ -0,0 +1,65 @@
From ed4ee14af5b83fa4a86dfaa783f841d3e8545ce4 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Josef=20=C5=98=C3=ADdk=C3=BD?= <jridky@redhat.com>
Date: Wed, 9 Aug 2023 16:51:28 +0200
Subject: [PATCH] Add support for RPM SQLite DB background.
From RPM 4.16 the SQLite support is available for RPM DB.
After https://fedoraproject.org/wiki/Changes/Sqlite_Rpmdb, rpm changed
it's background DB from Berkeley to SQLite in Fedora.
Net-SNMP is using hard coded paths to determine where RPM DB files are.
This update is adding check for rpmdb.sqlite file in order to be able
invalidate internal cache after system package change.
Closes #596
---
agent/mibgroup/host/data_access/swinst_rpm.c | 18 +++++++++++++-----
agent/mibgroup/host/hr_swinst.c | 3 +++
2 files changed, 16 insertions(+), 5 deletions(-)
diff --git a/agent/mibgroup/host/data_access/swinst_rpm.c b/agent/mibgroup/host/data_access/swinst_rpm.c
index 050edff307..7ad91a3194 100644
--- a/agent/mibgroup/host/data_access/swinst_rpm.c
+++ b/agent/mibgroup/host/data_access/swinst_rpm.c
@@ -73,15 +73,23 @@ netsnmp_swinst_arch_init(void)
#endif
snprintf( pkg_directory, SNMP_MAXPATH, "%s/Packages", dbpath );
+
+ if (-1 == stat( pkg_directory, &stat_buf )) {
+
+ /* check for SQLite DB backend */
+ snprintf( pkg_directory, SNMP_MAXPATH, "%s/rpmdb.sqlite", dbpath );
+
+ if (-1 == stat( pkg_directory, &stat_buf )) {
+ snmp_log(LOG_ERR, "Can't find directory of RPM packages\n");
+ pkg_directory[0] = '\0';
+ }
+ }
+
SNMP_FREE(rpmdbpath);
dbpath = NULL;
#ifdef HAVE_RPMGETPATH
rpmFreeRpmrc();
-#endif
- if (-1 == stat( pkg_directory, &stat_buf )) {
- snmp_log(LOG_ERR, "Can't find directory of RPM packages\n");
- pkg_directory[0] = '\0';
- }
+#endif
}
void
diff -urNp a/agent/mibgroup/host/hr_swinst.c b/agent/mibgroup/host/hr_swinst.c
--- a/agent/mibgroup/host/hr_swinst.c 2023-07-31 11:37:44.855071535 +0200
+++ b/agent/mibgroup/host/hr_swinst.c 2023-08-14 12:45:14.846357019 +0200
@@ -229,6 +229,9 @@ init_hr_swinst(void)
snprintf(path, sizeof(path), "%s/Packages", swi->swi_dbpath);
if (stat(path, &stat_buf) == -1)
snprintf(path, sizeof(path), "%s/packages.rpm", swi->swi_dbpath);
+ /* check for SQLite DB backend */
+ if (stat(path, &stat_buf) == -1)
+ snprintf(path, sizeof(path), "%s/rpmdb.sqlite", swi->swi_dbpath);
path[ sizeof(path)-1 ] = 0;
swi->swi_directory = strdup(path);
#ifdef HAVE_RPMGETPATH

View file

@ -1,6 +1,6 @@
diff -urNp a/man/net-snmp-config.1.def b/man/net-snmp-config.1.def
--- a/man/net-snmp-config.1.def 2026-01-12 12:42:08.018134877 +0100
+++ b/man/net-snmp-config.1.def 2026-01-12 12:43:26.749846227 +0100
--- a/man/net-snmp-config.1.def 2021-05-26 09:30:07.430790003 +0200
+++ b/man/net-snmp-config.1.def 2021-05-26 09:35:36.703673542 +0200
@@ -30,7 +30,7 @@ code for a list of available debug token
SNMP Setup commands:
.TP
@ -11,27 +11,27 @@ diff -urNp a/man/net-snmp-config.1.def b/man/net-snmp-config.1.def
These options produce the various compilation flags needed when
building external SNMP applications:
diff -urNp a/man/net-snmp-create-v3-user.1.def b/man/net-snmp-create-v3-user.1.def
--- a/man/net-snmp-create-v3-user.1.def 2026-01-12 12:42:08.017134868 +0100
+++ b/man/net-snmp-create-v3-user.1.def 2026-01-12 12:44:16.263005034 +0100
--- a/man/net-snmp-create-v3-user.1.def 2021-05-26 09:30:07.430790003 +0200
+++ b/man/net-snmp-create-v3-user.1.def 2021-05-26 09:34:23.702034230 +0200
@@ -3,7 +3,7 @@
net-snmp-create-v3-user \- create a SNMPv3 user in net-snmp configuration file
.SH SYNOPSIS
.PP
-.B net-snmp-create-v3-user [-ro] [-A authpass] [-a MD5|SHA|SHA-512|SHA-384|SHA-256|SHA-224] [-X privpass] [-x DES|AES|AES128]
+.B net-snmp-create-v3-user [-ro] [-A authpass] [-a MD5|SHA|SHA-512|SHA-384|SHA-256|SHA-224] [-X privpass] [-x AES|AES128]
-.B net-snmp-create-v3-user [-ro] [-A authpass] [-a MD5|SHA] [-X privpass] [-x DES|AES]
+.B net-snmp-create-v3-user [-ro] [-A authpass] [-a MD5|SHA] [-X privpass] [-x AES]
.B [username]
.SH DESCRIPTION
.PP
@@ -27,5 +27,5 @@ specify authentication algorithm
@@ -27,5 +27,5 @@ specifies the authentication password ha
\fB\-X privpass\fR
specify encryption password
specifies the encryption password
.TP
-\fB\-x DES|AES|AES128\fR
+\fB\-x AES|AES128\fR
specify encryption algorithm
-\fB\-x DES|AES\fR
+\fB\-x AES\fR
specifies the encryption algorithm
diff -urNp a/man/snmpcmd.1.def b/man/snmpcmd.1.def
--- a/man/snmpcmd.1.def 2026-01-12 12:42:08.016788741 +0100
+++ b/man/snmpcmd.1.def 2026-01-12 12:45:15.040041004 +0100
--- a/man/snmpcmd.1.def 2021-05-26 09:30:07.429789994 +0200
+++ b/man/snmpcmd.1.def 2021-05-26 09:37:51.104850500 +0200
@@ -311,7 +311,7 @@ Overrides the \fIdefSecurityName\fR toke
file.
.TP
@ -42,8 +42,8 @@ diff -urNp a/man/snmpcmd.1.def b/man/snmpcmd.1.def
.I snmp.conf
file. This option is only valid if the Net-SNMP software was build
diff -urNp a/man/snmp.conf.5.def b/man/snmp.conf.5.def
--- a/man/snmp.conf.5.def 2026-01-12 12:42:08.018134877 +0100
+++ b/man/snmp.conf.5.def 2026-01-12 12:47:26.967780683 +0100
--- a/man/snmp.conf.5.def 2021-05-26 09:30:07.429789994 +0200
+++ b/man/snmp.conf.5.def 2021-05-26 09:40:03.730011937 +0200
@@ -221,13 +221,13 @@ The
value will be used for the authentication and/or privacy pass phrases
if either of the other directives are not specified.
@ -71,8 +71,8 @@ diff -urNp a/man/snmp.conf.5.def b/man/snmp.conf.5.def
Sets the path of the \fBsshtosnmp\fR socket created by an application
(e.g. snmpd) listening for incoming ssh connections through the
diff -urNp a/man/snmpd.examples.5.def b/man/snmpd.examples.5.def
--- a/man/snmpd.examples.5.def 2026-01-12 12:42:08.016788741 +0100
+++ b/man/snmpd.examples.5.def 2026-01-12 12:48:02.264211991 +0100
--- a/man/snmpd.examples.5.def 2021-05-26 09:30:07.429789994 +0200
+++ b/man/snmpd.examples.5.def 2021-05-26 09:41:29.170761436 +0200
@@ -87,8 +87,8 @@ the same authentication and encryption s
.RS
.nf
@ -85,8 +85,8 @@ diff -urNp a/man/snmpd.examples.5.def b/man/snmpd.examples.5.def
.RE
Note that this defines three \fIdistinct\fR users, who could be granted
diff -urNp a/man/snmptrapd.conf.5.def b/man/snmptrapd.conf.5.def
--- a/man/snmptrapd.conf.5.def 2026-01-12 12:42:08.018134877 +0100
+++ b/man/snmptrapd.conf.5.def 2026-01-12 12:48:43.264773008 +0100
--- a/man/snmptrapd.conf.5.def 2021-05-26 09:30:07.428789985 +0200
+++ b/man/snmptrapd.conf.5.def 2021-05-26 09:42:02.963064029 +0200
@@ -117,7 +117,7 @@ to trigger the types of processing liste
See
.IR snmpd.conf (5)
@ -97,8 +97,8 @@ diff -urNp a/man/snmptrapd.conf.5.def b/man/snmptrapd.conf.5.def
.IR snmpd.conf (5)
manual page for a description of how to create SNMPv3 users. This
diff -urNp a/man/snmpusm.1.def b/man/snmpusm.1.def
--- a/man/snmpusm.1.def 2026-01-12 12:42:08.018134877 +0100
+++ b/man/snmpusm.1.def 2026-01-12 12:49:26.488017367 +0100
--- a/man/snmpusm.1.def 2021-05-26 09:30:07.430790003 +0200
+++ b/man/snmpusm.1.def 2021-05-26 09:42:24.178253990 +0200
@@ -216,7 +216,7 @@ rwuser initial
# lets add the new user we'll create too:
rwuser wes
@ -109,9 +109,9 @@ diff -urNp a/man/snmpusm.1.def b/man/snmpusm.1.def
.RE
.PP
diff -urNp a/net-snmp-create-v3-user.in b/net-snmp-create-v3-user.in
--- a/net-snmp-create-v3-user.in 2026-01-12 12:42:08.102135636 +0100
+++ b/net-snmp-create-v3-user.in 2026-01-12 12:50:35.760787628 +0100
@@ -10,7 +10,7 @@ if @PSCMD@ | @EGREP@ ' snmpd *$' > /dev/
--- a/net-snmp-create-v3-user.in 2021-05-26 09:30:07.369789468 +0200
+++ b/net-snmp-create-v3-user.in 2021-05-26 09:33:23.966511123 +0200
@@ -10,7 +10,7 @@ if @PSCMD@ | egrep ' snmpd *$' > /dev/nu
fi
Aalgorithm="MD5"
@ -138,14 +138,14 @@ diff -urNp a/net-snmp-create-v3-user.in b/net-snmp-create-v3-user.in
echo ""
echo "Usage:"
echo " net-snmp-create-v3-user [-ro] [-A authpass] [-X privpass]"
- echo " [-a MD5|SHA|SHA-512|SHA-384|SHA-256|SHA-224] [-x DES|AES|AES128] [username]"
+ echo " [-a MD5|SHA|SHA-512|SHA-384|SHA-256|SHA-224] [-x AES|AES128] [username]"
- echo " [-a MD5|SHA|SHA-512|SHA-384|SHA-256|SHA-224] [-x DES|AES] [username]"
+ echo " [-a MD5|SHA|SHA-512|SHA-384|SHA-256|SHA-224] [-x AES] [username]"
echo ""
exit
fi
diff -urNp a/README.snmpv3 b/README.snmpv3
--- a/README.snmpv3 2026-01-12 12:42:08.021134904 +0100
+++ b/README.snmpv3 2026-01-12 12:51:58.767903013 +0100
--- a/README.snmpv3 2021-05-26 09:30:07.352789320 +0200
+++ b/README.snmpv3 2021-05-26 09:44:49.109551728 +0200
@@ -4,7 +4,7 @@ How to setup SNMPv3, a very brief docume
do a better job on since I suck at writing documentation and he
doesn't ;-) --Wes:

View file

@ -0,0 +1,6 @@
diff -urNp a/dist/autoconf-version b/dist/autoconf-version
--- a/dist/autoconf-version 2024-02-16 08:21:36.551729028 +0100
+++ b/dist/autoconf-version 2024-02-16 08:24:39.035608191 +0100
@@ -1 +1 @@
-2.71
+2.72

View file

@ -0,0 +1,120 @@
From f5ae6baf0018abda9dedc368fe6d52c0d7a8ab8f Mon Sep 17 00:00:00 2001
From: Philippe Troin <phil+github-commits@fifi.org>
Date: Sat, 3 Feb 2024 10:30:30 -0800
Subject: [PATCH] Add Linux 6.7 compatibility parsing /proc/net/snmp
Linux 6.7 adds a new OutTransmits field to Ip in /proc/net/snmp.
This breaks the hard-coded assumptions about the Ip line length.
Add compatibility to parse Linux 6.7 Ip header while keep support
for previous versions.
---
.../ip-mib/data_access/systemstats_linux.c | 46 +++++++++++++++----
1 file changed, 37 insertions(+), 9 deletions(-)
diff --git a/agent/mibgroup/ip-mib/data_access/systemstats_linux.c b/agent/mibgroup/ip-mib/data_access/systemstats_linux.c
index 49e0a34d5c..f04e828a94 100644
--- a/agent/mibgroup/ip-mib/data_access/systemstats_linux.c
+++ b/agent/mibgroup/ip-mib/data_access/systemstats_linux.c
@@ -36,7 +36,7 @@ netsnmp_access_systemstats_arch_init(void)
}
/*
- /proc/net/snmp
+ /proc/net/snmp - Linux 6.6 and lower
Ip: Forwarding DefaultTTL InReceives InHdrErrors InAddrErrors ForwDatagrams InUnknownProtos InDiscards InDelivers OutRequests OutDiscards OutNoRoutes ReasmTimeout ReasmReqds ReasmOKs ReasmFails FragOKs FragFails FragCreates
Ip: 2 64 7083534 0 0 0 0 0 6860233 6548963 0 0 1 286623 63322 1 259920 0 0
@@ -49,6 +49,26 @@ netsnmp_access_systemstats_arch_init(void)
Udp: InDatagrams NoPorts InErrors OutDatagrams
Udp: 1491094 122 0 1466178
+*
+ /proc/net/snmp - Linux 6.7 and higher
+
+ Ip: Forwarding DefaultTTL InReceives InHdrErrors InAddrErrors ForwDatagrams InUnknownProtos InDiscards InDelivers OutRequests OutDiscards OutNoRoutes ReasmTimeout ReasmReqds ReasmOKs ReasmFails FragOKs FragFails FragCreates OutTransmits
+ Ip: 1 64 50859058 496 0 37470604 0 0 20472980 7515791 1756 0 0 7264 3632 0 3548 0 7096 44961424
+
+ Icmp: InMsgs InErrors InCsumErrors InDestUnreachs InTimeExcds InParmProbs InSrcQuenchs InRedirects InEchos InEchoReps InTimestamps InTimestampReps InAddrMasks InAddrMaskReps OutMsgs OutErrors OutRateLimitGlobal OutRateLimitHost OutDestUnreachs OutTimeExcds OutParmProbs OutSrcQuenchs OutRedirects OutEchos OutEchoReps OutTimestamps OutTimestampReps OutAddrMasks OutAddrMaskReps
+ Icmp: 114447 2655 0 17589 0 0 0 0 66905 29953 0 0 0 0 143956 0 0 572 16610 484 0 0 0 59957 66905 0 0 0 0
+
+ IcmpMsg: InType0 InType3 InType8 OutType0 OutType3 OutType8 OutType11
+ IcmpMsg: 29953 17589 66905 66905 16610 59957 484
+
+ Tcp: RtoAlgorithm RtoMin RtoMax MaxConn ActiveOpens PassiveOpens AttemptFails EstabResets CurrEstab InSegs OutSegs RetransSegs InErrs OutRsts InCsumErrors
+ Tcp: 1 200 120000 -1 17744 13525 307 3783 6 18093137 9277788 3499 8 7442 0
+
+ Udp: InDatagrams NoPorts InErrors OutDatagrams RcvbufErrors SndbufErrors InCsumErrors IgnoredMulti MemErrors
+ Udp: 2257832 1422 0 2252835 0 0 0 84 0
+
+ UdpLite: InDatagrams NoPorts InErrors OutDatagrams RcvbufErrors SndbufErrors InCsumErrors IgnoredMulti MemErrors
+ UdpLite: 0 0 0 0 0 0 0 0 0
*/
@@ -101,10 +121,10 @@ _systemstats_v4(netsnmp_container* container, u_int load_flags)
FILE *devin;
char line[1024];
netsnmp_systemstats_entry *entry = NULL;
- int scan_count;
+ int scan_count, expected_scan_count;
char *stats, *start = line;
int len;
- unsigned long long scan_vals[19];
+ unsigned long long scan_vals[20];
DEBUGMSGTL(("access:systemstats:container:arch", "load v4 (flags %x)\n",
load_flags));
@@ -126,10 +146,17 @@ _systemstats_v4(netsnmp_container* container, u_int load_flags)
*/
NETSNMP_IGNORE_RESULT(fgets(line, sizeof(line), devin));
len = strlen(line);
- if (224 != len) {
+ switch (len) {
+ case 224:
+ expected_scan_count = 19;
+ break;
+ case 237:
+ expected_scan_count = 20;
+ break;
+ default:
fclose(devin);
snmp_log(LOG_ERR, "systemstats_linux: unexpected header length in /proc/net/snmp."
- " %d != 224\n", len);
+ " %d not in { 224, 237 } \n", len);
return -4;
}
@@ -178,20 +205,20 @@ _systemstats_v4(netsnmp_container* container, u_int load_flags)
memset(scan_vals, 0x0, sizeof(scan_vals));
scan_count = sscanf(stats,
"%llu %llu %llu %llu %llu %llu %llu %llu %llu %llu"
- "%llu %llu %llu %llu %llu %llu %llu %llu %llu",
+ "%llu %llu %llu %llu %llu %llu %llu %llu %llu %llu",
&scan_vals[0],&scan_vals[1],&scan_vals[2],
&scan_vals[3],&scan_vals[4],&scan_vals[5],
&scan_vals[6],&scan_vals[7],&scan_vals[8],
&scan_vals[9],&scan_vals[10],&scan_vals[11],
&scan_vals[12],&scan_vals[13],&scan_vals[14],
&scan_vals[15],&scan_vals[16],&scan_vals[17],
- &scan_vals[18]);
+ &scan_vals[18],&scan_vals[19]);
DEBUGMSGTL(("access:systemstats", " read %d values\n", scan_count));
- if(scan_count != 19) {
+ if(scan_count != expected_scan_count) {
snmp_log(LOG_ERR,
"error scanning systemstats data (expected %d, got %d)\n",
- 19, scan_count);
+ expected_scan_count, scan_count);
netsnmp_access_systemstats_entry_free(entry);
return -4;
}
@@ -223,6 +250,7 @@ _systemstats_v4(netsnmp_container* container, u_int load_flags)
entry->stats.HCOutFragFails.high = scan_vals[17] >> 32;
entry->stats.HCOutFragCreates.low = scan_vals[18] & 0xffffffff;
entry->stats.HCOutFragCreates.high = scan_vals[18] >> 32;
+ /* entry->stats. = scan_vals[19]; / * OutTransmits */
entry->stats.columnAvail[IPSYSTEMSTATSTABLE_HCINRECEIVES] = 1;
entry->stats.columnAvail[IPSYSTEMSTATSTABLE_INHDRERRORS] = 1;

View file

@ -1,13 +0,0 @@
diff --git a/apps/snmptrapd_log.c b/apps/snmptrapd_log.c
index 067c7f6..e6f0f1e 100644
--- a/apps/snmptrapd_log.c
+++ b/apps/snmptrapd_log.c
@@ -596,7 +596,7 @@ realloc_handle_time_fmt(u_char ** buf, size_t * buf_len, size_t * out_len,
static
void convert_agent_addr(struct in_addr agent_addr, char *name, size_t size)
{
- const int numeric = !netsnmp_ds_get_boolean(NETSNMP_DS_APPLICATION_ID,
+ const int numeric = netsnmp_ds_get_boolean(NETSNMP_DS_APPLICATION_ID,
NETSNMP_DS_APP_NUMERIC_IP);
struct sockaddr_in sin;

View file

@ -1,150 +0,0 @@
diff --git a/include/net-snmp/library/default_store.h b/include/net-snmp/library/default_store.h
index 1b1978e..dd590be 100644
--- a/include/net-snmp/library/default_store.h
+++ b/include/net-snmp/library/default_store.h
@@ -183,6 +183,8 @@ extern "C" {
#define NETSNMP_DS_LIB_SSH_PUBKEY 33
#define NETSNMP_DS_LIB_SSH_PRIVKEY 34
#define NETSNMP_DS_LIB_OUTPUT_PRECISION 35
+#define NETSNMP_DS_LIB_TLS_MIN_VERSION 36
+#define NETSNMP_DS_LIB_TLS_MAX_VERSION 37
#define NETSNMP_DS_LIB_MAX_STR_ID 48 /* match NETSNMP_DS_MAX_SUBIDS */
/*
diff --git a/man/snmpd.conf.5.def b/man/snmpd.conf.5.def
index 0a8b9fa..d9641cc 100644
--- a/man/snmpd.conf.5.def
+++ b/man/snmpd.conf.5.def
@@ -203,6 +203,12 @@ HIGH:!AES128\-SHA
.RE
.IP
The default value is whatever openssl itself was configured with.
+.IP "tlsMinVersion STRING"
+The function sets the minimum supported TLS protocol version.
+OPTION can be one of < tls1 | tls1_1| tls1_2 | tls1_3 >.
+.IP "tlsMaxVersion STRING"
+The function sets the maximum supported TLS protocol version.
+OPTION can be one of < tls1 | tls1_1| tls1_2 | tls1_3 >.
.IP "[snmp] x509CRLFile"
If you are using a Certificate Authority (CA) that publishes a
Certificate Revocation List (CRL) then this token can be used to
diff --git a/snmplib/transports/snmpTLSBaseDomain.c b/snmplib/transports/snmpTLSBaseDomain.c
index e301de4..7ae2db7 100644
--- a/snmplib/transports/snmpTLSBaseDomain.c
+++ b/snmplib/transports/snmpTLSBaseDomain.c
@@ -490,6 +490,9 @@ SSL_CTX *
_sslctx_common_setup(SSL_CTX *the_ctx, _netsnmpTLSBaseData *tlsbase) {
char *crlFile;
char *cipherList;
+ char *tlsMinVersion;
+ char *tlsMaxVersion;
+ int tlsVersion;
X509_LOOKUP *lookup;
X509_STORE *cert_store = NULL;
@@ -513,6 +516,63 @@ _sslctx_common_setup(SSL_CTX *the_ctx, _netsnmpTLSBaseData *tlsbase) {
X509_V_FLAG_CRL_CHECK | X509_V_FLAG_CRL_CHECK_ALL);
}
+#ifdef SSL_CTX_set_min_proto_version
+ tlsVersion = TLS1_2_VERSION;
+ tlsMinVersion = "tls1_2";
+ tlsMinVersion = netsnmp_ds_get_string(NETSNMP_DS_LIBRARY_ID,
+ NETSNMP_DS_LIB_TLS_MIN_VERSION);
+ if (NULL != tlsMinVersion) {
+ if (strcmp("tls1",tlsMinVersion) == 0) {
+ tlsVersion = TLS1_VERSION;
+ }
+ else if (strcmp("tls1_1",tlsMinVersion) == 0) {
+ tlsVersion = TLS1_1_VERSION;
+ }
+ else if (strcmp("tls1_2",tlsMinVersion) == 0) {
+ tlsVersion = TLS1_2_VERSION;
+ }
+ else if (strcmp("tls1_3",tlsMinVersion) == 0) {
+ tlsVersion = TLS1_3_VERSION;
+ }
+ else {
+ LOGANDDIE("Invalid tlsMinVersion value");
+ }
+ }
+ if (1 == SSL_CTX_set_min_proto_version(the_ctx, tlsVersion)) {
+ snmp_log(LOG_INFO,"Set tlsMinVersion to '%s'\n", tlsMinVersion);
+ }
+ else {
+ LOGANDDIE("Set tlsMinVersion failed");
+ }
+ tlsVersion = TLS1_3_VERSION;
+ tlsMaxVersion = "tls1_3";
+ tlsMaxVersion = netsnmp_ds_get_string(NETSNMP_DS_LIBRARY_ID,
+ NETSNMP_DS_LIB_TLS_MAX_VERSION);
+ if (NULL != tlsMaxVersion) {
+ if (strcmp("tls1",tlsMaxVersion) == 0) {
+ tlsVersion = TLS1_VERSION;
+ }
+ else if (strcmp("tls1_1",tlsMaxVersion) == 0) {
+ tlsVersion = TLS1_1_VERSION;
+ }
+ else if (strcmp("tls1_2",tlsMaxVersion) == 0) {
+ tlsVersion = TLS1_2_VERSION;
+ }
+ else if (strcmp("tls1_3",tlsMaxVersion) == 0) {
+ tlsVersion = TLS1_3_VERSION;
+ }
+ else {
+ LOGANDDIE("Invalid tlsMaxVersion value");
+ }
+ }
+ if (1 == SSL_CTX_set_max_proto_version(the_ctx, tlsVersion)) {
+ snmp_log(LOG_INFO,"Set tlsMaxVersion to '%s'\n", tlsMaxVersion);
+ }
+ else {
+ LOGANDDIE("Set tlsMaxVersion failed");
+ }
+#endif
+
cipherList = netsnmp_ds_get_string(NETSNMP_DS_LIBRARY_ID,
NETSNMP_DS_LIB_TLS_ALGORITMS);
if (NULL != cipherList) {
@@ -858,6 +918,15 @@ netsnmp_tlsbase_ctor(void) {
NETSNMP_DS_LIBRARY_ID,
NETSNMP_DS_LIB_TLS_ALGORITMS);
+ /* What TLS version should be used at least */
+ netsnmp_ds_register_config(ASN_OCTET_STR, "snmp", "tlsMinVersion",
+ NETSNMP_DS_LIBRARY_ID,
+ NETSNMP_DS_LIB_TLS_MIN_VERSION);
+ /* What TLS version should be used at max */
+ netsnmp_ds_register_config(ASN_OCTET_STR, "snmp", "tlsMaxVersion",
+ NETSNMP_DS_LIBRARY_ID,
+ NETSNMP_DS_LIB_TLS_MAX_VERSION);
+
/*
* for the client
*/
diff --git a/snmplib/transports/snmpTLSTCPDomain.c b/snmplib/transports/snmpTLSTCPDomain.c
index 0ddf023..e0133f9 100644
--- a/snmplib/transports/snmpTLSTCPDomain.c
+++ b/snmplib/transports/snmpTLSTCPDomain.c
@@ -718,10 +718,6 @@ netsnmp_tlstcp_open_client(netsnmp_transport *t)
return NULL;
}
-#ifdef SSL_CTX_set_max_proto_version
- SSL_CTX_set_max_proto_version(tlsdata->ssl_context, 0);
-#endif
-
/* RFC5953 Section 5.3.1: Establishing a Session as a Client
3) Using the destTransportDomain and destTransportAddress values,
the client will initiate the (D)TLS handshake protocol to
@@ -917,10 +913,6 @@ netsnmp_tlstcp_open_server(netsnmp_transport *t)
/* create the OpenSSL TLS context */
tlsdata->ssl_context = sslctx_server_setup(TLS_method());
-#ifdef SSL_CTX_set_max_proto_version
- if (tlsdata->ssl_context)
- SSL_CTX_set_max_proto_version(tlsdata->ssl_context, 0);
-#endif
t->sock = BIO_get_fd(tlsdata->accept_bio, NULL);
t->flags |= NETSNMP_TRANSPORT_FLAG_LISTEN;

View file

@ -5,15 +5,15 @@
%global multilib_arches %{ix86} ia64 ppc ppc64 s390 s390x x86_64 sparc sparcv9 sparc64 aarch64
# actual soname version
%global soname 45
%global soname 40
Summary: A collection of SNMP protocol tools and libraries
Name: net-snmp
Version: 5.9.5.2
Release: 10%{?dist}
Version: 5.9.4
Release: 5%{?dist}
Epoch: 1
License: MIT-CMU AND BSD-3-Clause AND MIT
License: Net-SNMP and OpenSSL
URL: http://net-snmp.sourceforge.net/
Source0: https://downloads.sourceforge.net/project/net-snmp/net-snmp/%{version}/net-snmp-%{version}.tar.gz
Source1: net-snmp.redhat.conf
@ -36,18 +36,22 @@ Patch6: net-snmp-5.9-cflags.patch
Patch7: net-snmp-5.8-Remove-U64-typedef.patch
Patch8: net-snmp-5.7.3-iterator-fix.patch
Patch9: net-snmp-5.9-autofs-skip.patch
Patch10: net-snmp-5.9-coverity.patch
Patch11: net-snmp-5.8-expand-SNMPCONFPATH.patch
Patch12: net-snmp-5.8-duplicate-ipAddress.patch
Patch13: net-snmp-5.9-memory-reporting.patch
Patch14: net-snmp-5.8-man-page.patch
Patch15: net-snmp-5.8-ipAddress-faster-load.patch
Patch16: net-snmp-5.8-rpm-memory-leak.patch
Patch17: net-snmp-5.9-aes-config.patch
Patch18: net-snmp-5.8-clientaddr-error-message.patch
Patch19: net-snmp-5.9-intermediate-certs.patch
Patch20: net-snmp-5.9.1-remove-des.patch
Patch21: net-snmp-libs-misunderstanding.patch
Patch22: net-snmp-5.9-ipv6-disable-leak.patch
Patch26: net-snmp-5.9.4-tls.patch
Patch27: net-snmp-5.9.4-revert-n-snmptrapd-log.patch
Patch23: net-snmp-5.9-rpmdb.patch
Patch24: net-snmp-5.9.4-autoconf.patch
Patch25: net-snmp-5.9.4-kernel-6.7.patch
# Modern RPM API means at least EL6
Patch101: net-snmp-5.8-modern-rpm-api.patch
@ -55,12 +59,6 @@ Patch101: net-snmp-5.8-modern-rpm-api.patch
#disable this patch due compatibility issues
Patch102: net-snmp-5.9-python3.patch
# make Mail::Sender optional
Patch103: net-snmp-5.9-mail-sender.patch
# Openssl 4 build fixes
Patch104: 0001-Use-OpenSSL-accessors-for-opaque-structs.patch
Requires: %{name}-libs%{?_isa} = %{epoch}:%{version}-%{release}
Requires: %{name}-agent-libs%{?_isa} = %{epoch}:%{version}-%{release}
# This is actually needed for the %%triggerun script but Requires(triggerun)
@ -68,7 +66,6 @@ Requires: %{name}-agent-libs%{?_isa} = %{epoch}:%{version}-%{release}
# should fire just after this package is installed.
%{?systemd_requires}
BuildRequires: make
BuildRequires: libxcrypt-devel
BuildRequires: systemd
BuildRequires: gcc
BuildRequires: openssl-devel, bzip2-devel, elfutils-devel
@ -77,7 +74,6 @@ BuildRequires: perl-devel, perl(ExtUtils::Embed), procps
BuildRequires: python3-devel, python3-setuptools
BuildRequires: chrpath
BuildRequires: mariadb-connector-c-devel
BuildRequires: libnl3-devel
# for netstat, needed by 'make test'
BuildRequires: net-tools
# for make test
@ -92,8 +88,10 @@ BuildRequires: perl(strict)
BuildRequires: perl(TAP::Harness)
BuildRequires: perl(vars)
BuildRequires: perl(warnings)
%ifnarch s390 s390x ppc64le
BuildRequires: lm_sensors-devel >= 3
BuildRequires: autoconf, automake, libtool
%endif
BuildRequires: autoconf, automake
%description
SNMP (Simple Network Management Protocol) is a protocol used for
@ -125,8 +123,9 @@ Requires: %{name}-libs%{?_isa} = %{epoch}:%{version}-%{release}
Requires: %{name}-agent-libs%{?_isa} = %{epoch}:%{version}-%{release}
Requires: elfutils-devel, rpm-devel, elfutils-libelf-devel, openssl-devel
Requires: redhat-rpm-config
Requires: libnl3-devel
%ifnarch s390 s390x ppc64le
Requires: lm_sensors-devel
%endif
# pull perl development libraries, net-snmp agent libraries may link to them
Requires: perl-devel%{?_isa}
@ -228,37 +227,33 @@ cp %{SOURCE10} .
%patch 7 -p1 -b .u64-remove
%patch 8 -p1 -b .iterator-fix
%patch 9 -p1 -b .autofs-skip
%patch 10 -p1 -b .coverity
%patch 11 -p1 -b .expand-SNMPCONFPATH
%patch 12 -p1 -b .duplicate-ipAddress
%patch 13 -p1 -b .memory-reporting
%patch 14 -p1 -b .man-page
%patch 15 -p1 -b .ipAddress-faster-load
%patch 16 -p1 -b .rpm-memory-leak
%patch 17 -p1 -b .aes-config
%patch 18 -p1 -b .clientaddr-error-message
%patch 19 -p1 -b .intermediate-certs
%patch 20 -p1 -b .remove-des
%patch 21 -p1
%patch 22 -p1 -b .ipv6-disable-leak
%patch 26 -p1 -b .tls
%patch 27 -p1 -b .revert-n-snmptrapd-log
%patch 23 -p1 -b .rpmdbpatch
#patch 24 -p1
%patch 25 -p1 -b .kernel-6.7
%patch 101 -p1 -b .modern-rpm-api
%patch 102 -p1
%if 0%{?rhel}
%patch 103 -p1
%endif
%patch 104 -p1
# disable failing test - see https://bugzilla.redhat.com/show_bug.cgi?id=680697
rm testing/fulltests/default/T200*
# Autoreconf is run during build, which may be a different version than upstream used,
# resulting in a mismatch during "Checking the Net-SNMP configure script validity" test
autoconf --version | awk 'NR==1 {print $4}' > dist/autoconf-version
%build
# Autoreconf to get autoconf 2.69 for ARM (#926223)
autoreconf -fiv
autoreconf
MIBS="host agentx smux \
ucd-snmp/diskio tcp-mib udp-mib mibII/mta_sendmail \
@ -266,7 +261,12 @@ MIBS="host agentx smux \
ip-mib/ipAddressPrefixTable/ipAddressPrefixTable \
ip-mib/ipDefaultRouterTable/ipDefaultRouterTable \
ip-mib/ipv6ScopeZoneIndexTable ip-mib/ipIfStatsTable \
sctp-mib rmon-mib etherlike-mib ucd-snmp/lmsensorsMib"
sctp-mib rmon-mib etherlike-mib"
%ifnarch s390 s390x ppc64le
# there are no lm_sensors on s390
MIBS="$MIBS ucd-snmp/lmsensorsMib"
%endif
%configure \
--disable-static --enable-shared \
@ -435,8 +435,7 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test
%config(noreplace) %attr(0600,root,root) %{_sysconfdir}/snmp/snmptrapd.conf
%{_bindir}/snmpconf
%{_bindir}/net-snmp-create-v3-user
%{_sbindir}/snmpd
%{_sbindir}/snmptrapd
%{_sbindir}/*
%attr(0644,root,root) %{_mandir}/man[58]/snmp*d*
%attr(0644,root,root) %{_mandir}/man5/snmp_config.5.gz
%attr(0644,root,root) %{_mandir}/man5/variables*
@ -514,78 +513,9 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test
%{_libdir}/libnetsnmptrapd*.so.%{soname}*
%changelog
* Fri Jul 24 2026 Python Maint <python-maint@redhat.com> - 1:5.9.5.2-10
- Rebuilt for Python 3.15.0b4 ABI change
* Thu Jul 23 2026 Jitka Plesnikova <jplesnik@redhat.com> - 1:5.9.5.2-9
- Perl 5.44 rebuild
* Wed Jul 22 2026 Python Maint <python-maint@redhat.com> - 1:5.9.5.2-8
- Rebuilt for Python 3.15.0b4 ABI change
* Thu Jul 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 1:5.9.5.2-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Fri Jun 12 2026 Simo Sorce <ssorce@redhat.com> - 1:5.9.5.2-6
- Openssl 4 and autoconf build fixes
* Wed Jun 03 2026 Python Maint <python-maint@redhat.com> - 1:5.9.5.2-5
- Rebuilt for Python 3.15
* Thu Jan 29 2026 Yaakov Selkowitz <yselkowi@redhat.com> - 1:5.9.5.2-4
- Add net-snmp-devel dependency on libnl3-devel
* Fri Jan 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 1:5.9.5.2-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Mon Jan 12 2026 Yaakov Selkowitz <yselkowi@redhat.com> - 1:5.9.5.2-2
- Enable lm_sensors on all arches
* Mon Jan 12 2026 Josef Ridky <jridky@redhat.com> - 1:5.9.5.2-1
- New upstream release 5.9.5.2
* Mon Oct 13 2025 Josef Ridky <jridky@redhat.com> - 1:5.9.4-18
- Enable PQC in net-snmp
- Fix inverted use of -n in snmptrapd_log.c
* Fri Sep 19 2025 Python Maint <python-maint@redhat.com> - 1:5.9.4-17
- Rebuilt for Python 3.14.0rc3 bytecode
* Fri Aug 15 2025 Python Maint <python-maint@redhat.com> - 1:5.9.4-16
- Rebuilt for Python 3.14.0rc2 bytecode
* Thu Jul 24 2025 Fedora Release Engineering <releng@fedoraproject.org> - 1:5.9.4-15
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Mon Jul 07 2025 Jitka Plesnikova <jplesnik@redhat.com> - 1:5.9.4-14
- Perl 5.42 rebuild
* Mon Jun 02 2025 Python Maint <python-maint@redhat.com> - 1:5.9.4-13
- Rebuilt for Python 3.14
* Thu Mar 20 2025 Yaakov Selkowitz <yselkowi@redhat.com> - 1:5.9.4-12
- Avoid Mail::Sender dependency on RHEL
* Sat Feb 01 2025 Björn Esser <besser82@fedoraproject.org> - 1:5.9.4-11
- Add explicit BR: libxcrypt-devel
* Thu Jan 23 2025 Yaakov Selkowitz <yselkowi@redhat.com> - 1:5.9.4-10
- Fix file listings for https://fedoraproject.org/wiki/Changes/Unify_bin_and_sbin
* Fri Jan 17 2025 Fedora Release Engineering <releng@fedoraproject.org> - 1:5.9.4-9
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Thu Jul 18 2024 Fedora Release Engineering <releng@fedoraproject.org> - 1:5.9.4-8
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Wed Jun 12 2024 Jitka Plesnikova <jplesnik@redhat.com> - 1:5.9.4-7
- Perl 5.40 rebuild
* Fri Jun 07 2024 Python Maint <python-maint@redhat.com> - 1:5.9.4-6
- Rebuilt for Python 3.13
* Tue Mar 12 2024 Josef Ridky <jridky@redhat.com> - 1:5.9.4-5
- Fix parsing issue for kernel 6.7+ (#2266893)
- revert autoconf patch for F40 and lower
* Fri Feb 16 2024 Josef Ridky <jridky@redhat.com> - 1:5.9.4-4
- Autoconf upgrade (#2256768)

View file

@ -1,5 +0,0 @@
summary: Basic smoke test
discover:
how: fmf
execute:
how: tmt

View file

@ -1 +1 @@
SHA512 (net-snmp-5.9.5.2.tar.gz) = c320c90e01377651fdff3aa9c373b9013f142fab23810d821174e546716ef2fa6499a805728710c67ca7fe238679111df392754c24ea4e01768faa5535ac7db2
SHA512 (net-snmp-5.9.4.tar.gz) = a510fa91a21e9ddc86a12fd1d0bc6b356e63f3ea53f184d2e31439004d41d902390664134dc40b3b828eabb4282eaf3da628a07c4d480fa00eff7e700950c423

View file

@ -27,7 +27,7 @@ $(METADATA): Makefile
@echo "Type: Sanity" >> $(METADATA)
@echo "TestTime: 5m" >> $(METADATA)
@echo "RunFor: net-snmp" >> $(METADATA)
@echo "Requires: net-snmp net-snmp-utils iproute python3 python3-pyroute2" >> $(METADATA)
@echo "Requires: net=snmp" >> $(METADATA)
@echo "Priority: Normal" >> $(METADATA)
@echo "License: GPLv2" >> $(METADATA)
@echo "Confidential: no" >> $(METADATA)

View file

@ -1,16 +0,0 @@
summary: Test snmpd
description: ''
contact: Susant Sahani<susant@redhat.com>
component:
- net-snmp
test: ./runtest.sh
framework: beakerlib
recommend:
- net-snmp
- net-snmp-utils
- iproute
- python3
- python3-pyroute2
duration: 5m
extra-summary: /CoreOS/net-snmp
extra-task: /CoreOS/net-snmp

View file

@ -15,10 +15,12 @@ import unittest
import subprocess
import signal
import shutil
import psutil
import socket
import platform
import re
from pyroute2 import IPRoute
from psutil import virtual_memory
from collections import OrderedDict
HOST='192.168.111.50'
@ -138,7 +140,11 @@ class SnmpdTests(unittest.TestCase, GenericUtilities):
# 1.3.6.1.2.1.1.1 - sysDescr
output=subprocess.check_output(['snmpwalk', '-v2c', '-c', 'public', HOST, '1.3.6.1.2.1.1.1']).rstrip().decode('utf-8')
self.assertRegex(output, " ".join(platform.uname()).strip())
self.assertRegex(output, platform.machine())
self.assertRegex(output, platform.node())
self.assertRegex(output, platform.processor())
self.assertRegex(output, platform.release())
self.assertRegex(output, platform.version())
# 1.3.6.1.2.1.1.2 - sysObjectID
subprocess.check_output(['snmpwalk', '-v2c', '-c', 'public', HOST, '1.3.6.1.2.1.1.2'])

14
tests/tests.yml Normal file
View file

@ -0,0 +1,14 @@
- hosts: localhost
roles:
- role: standard-test-beakerlib
tags:
- classic
tests:
- integration-tests
required_packages:
- python3
- systemd
- iproute
- python3-pyroute2
- net-snmp
- net-snmp-utils