Re: Net-SNMP 5.9.5. and 5.10.pre2 released to address snmptrapd security vulnerability
Craig Small via Net-snmp-coders <[email protected]> Fri, 2 Jan 2026 19:27:21 +1100
| Newsgroups | gmane.network.net-snmp.devel |
|---|---|
| Message-ID | <CALy8Cw5g8pSH8EFDTsbdcr5t8WKyCS8Rffx1e388hR7cfqWXMQ@mail.gmail.com> |
--===============8874265212168298087== Content-Type: multipart/alternative; boundary="0000000000001590150647637be1" --0000000000001590150647637be1 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Fri, 2 Jan 2026, 12:47=E2=80=AFpm Magnus Fromreide, <[email protected]= e> wrote: > On Thu, Dec 25, 2025 at 03:23:34PM -0800, Wes Hardaker via Net-snmp-coder= s > wrote: > > Bart Van Assche via Net-snmp-coders > > <[email protected]> writes: > > > > > One possible solution is to modify net-snmp-config such that all -W > > > flags are filtered out. There may be better solutions. > > > > IMHO, the --enable-developer was created for adding options like this > > and they should never be on anywhere in default builds. We should > > remove all warning flags everywhere by default (IMHO, but that's the > > point of a discussion: I could be alone in my thinking). > > I am stronly agreeing and wants to go further - I think all dialect optio= ns > should be removed from the net-snmp-config output, so no more > > -g > -fno-strict-aliasing > -O2 > > as that should be the the choice of the client program, not us. I would like that very much. As an example of the issue adding those options causes, syslog-ng failed to compile with 5.9.5.2 but compiled ok. What happens is one of the options triggered a compile error in the syslog-ng code itself because a previous warning was now an error. So changing the version of net-snmp a program links to caused an error so it wouldn't compile; but not due to an API change. - Craig --0000000000001590150647637be1 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"auto"><br><br><div class=3D"gmail_quote" dir= =3D"auto"><div dir=3D"ltr" class=3D"gmail_attr">On Fri, 2 Jan 2026, 12:47= =E2=80=AFpm Magnus Fromreide, <<a href=3D"mailto:[email protected]" t= arget=3D"_blank">[email protected]</a>> wrote:<br></div><blockquote c= lass=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;= padding-left:1ex">On Thu, Dec 25, 2025 at 03:23:34PM -0800, Wes Hardaker vi= a Net-snmp-coders wrote:<br> > Bart Van Assche via Net-snmp-coders<br> > <<a href=3D"mailto:[email protected]" rel=3D"no= referrer" target=3D"_blank">[email protected]</a>> w= rites:<br> > <br> > > One possible solution is to modify net-snmp-config such that all = -W<br> > > flags are filtered out. There may be better solutions.<br> > <br> > IMHO, the --enable-developer was created for adding options like this<= br> > and they should never be on anywhere in default builds.=C2=A0 We shoul= d<br> > remove all warning flags everywhere by default (IMHO, but that's t= he<br> > point of a discussion: I could be alone in my thinking).<br> <br> I am stronly agreeing and wants to go further - I think all dialect options= <br> should be removed from the net-snmp-config output, so no more<br> <br> -g<br> -fno-strict-aliasing<br> -O2<br> <br> as that should be the the choice of the client program, not us.</blockquote= ></div><div dir=3D"auto">I would like that very much. As an example of the = issue adding those options causes, syslog-ng failed to compile with 5.9.5.2= but compiled ok.</div><div dir=3D"auto"><br></div><div dir=3D"auto">What h= appens=C2=A0is one of the options triggered a compile error in the syslog-n= g code itself because a previous warning was now an error.</div><div>So cha= nging the version of net-snmp a program links to caused an error so it woul= dn't compile; but not due to an API change.</div><div><br></div><div>= =C2=A0- Craig</div></div> </div> --0000000000001590150647637be1-- --===============8874265212168298087== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============8874265212168298087== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Net-snmp-coders mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/net-snmp-coders --===============8874265212168298087==--