Re: [oe] [meta-networking][PATCH 2/3] net-snmp: Backport upstream fix for explicit library linking

Jaipaul Cheernam <[email protected]>
Newsgroups org.openembedded.lists.openembedded-devel
Message-ID <DU7PPF66507B2D76B0DC1B2BFBE539BBE38F3D12@DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM>
Hi Khem,

This fixes the net-snmp 5.9.5.2 do_compile failure we hit after the libtool 2.5.4 → 2.6.2 upgrade (link_all_deplibs=no exposing missing direct dependencies in libnetsnmptrapd).

 Tested-by: [email protected]

Regards,
Jaipaul
From: [email protected] <[email protected]> on behalf of Khem Raj via lists.openembedded.org <[email protected]>
Date: Wednesday, 5 August 2026 at 23:26
To: [email protected] <[email protected]>
Cc: Khem Raj <[email protected]>
Subject: [oe] [meta-networking][PATCH 2/3] net-snmp: Backport upstream fix for explicit library linking

libnetsnmptrapd uses symbols that live in libnetsnmpagent, but
apps/Makefile.in only passes $(MIBLIB) and $(USELIBS) to the link. That
works with GNU ld, which resolves symbols through the DT_NEEDED entries
of the libraries named on the command line, and libnetsnmpmibs records a
dependency on libnetsnmpagent. lld deliberately does not, so the link
fails:

| ld.lld: error: undefined symbol: init_vacm_config_tokens
| >>> referenced by snmptrapd_auth.c:51
| >>>               .libs/snmptrapd_auth.o:(init_netsnmp_trapd_auth)
| ld.lld: error: undefined symbol: send_v2trap
| >>> referenced by snmptrapd_handlers.c:886
| >>>               .libs/snmptrapd_handlers.o:(axforward_handler)

Backport upstream commit 5e66246bd994 which names $(AGENTLIB) explicitly
and additionally links libcrypto into libnetsnmpmibs and the apps, both
of which rely on the same transitive resolution. The libnetsnmptrapd.la
hunk is rebased because 5.9.5.2 still puts $(LDFLAGS) at the end of that
link command.

Verified on aarch64 for qemuarm64: do_compile fails before the change
with the errors above; after it do_compile and do_package succeed and
libnetsnmptrapd.so records DT_NEEDED on libnetsnmpmibs, libnetsnmpagent
and libnetsnmp directly.

Signed-off-by: Khem Raj <[email protected]>
---
 ...akefile.in-Link-libraries-explicitly.patch | 103 ++++++++++++++++++
 .../net-snmp/net-snmp_5.9.5.2.bb              |   1 +
 2 files changed, 104 insertions(+)
 create mode 100644 meta-networking/recipes-protocols/net-snmp/net-snmp/0012-apps-Makefile.in-Link-libraries-explicitly.patch

diff --git a/meta-networking/recipes-protocols/net-snmp/net-snmp/0012-apps-Makefile.in-Link-libraries-explicitly.patch b/meta-networking/recipes-protocols/net-snmp/net-snmp/0012-apps-Makefile.in-Link-libraries-explicitly.patch
new file mode 100644
index 0000000000..5129282ef2
--- /dev/null
+++ b/meta-networking/recipes-protocols/net-snmp/net-snmp/0012-apps-Makefile.in-Link-libraries-explicitly.patch
@@ -0,0 +1,103 @@
+From 5e66246bd994a2f693bd02773823691c8d07a070 Mon Sep 17 00:00:00 2001
+From: Bart Van Assche <[email protected]>
+Date: Fri, 24 Jul 2026 09:34:18 -0700
+Subject: [PATCH] apps/Makefile.in: Link libraries explicitly
+
+When building Net-SNMP with -no-undefined (which is used for libraries like
+libnetsnmpmibs.la and libnetsnmptrapd.la) and link_all_deplibs=no (default on
+modern systems to prevent overlinking), compilation fails due to undefined
+references to symbols from transitive dependencies.
+
+1. libnetsnmpmibs.la fails to link because it uses OpenSSL DH/BN symbols
+   (when snmp-usm-dh-objects-mib is enabled) but does not link with
+   libcrypto directly. Fix this by adding LIBCRYPTO to LMIBLIBS in
+   configure if OpenSSL is used, and exporting LIBCRYPTO.
+
+2. libnetsnmptrapd.la fails to link because it uses symbols from
+   libnetsnmpagent.la (like vacm_check_view_contents) but does not link with
+   it directly. Fix this by adding $(AGENTLIB) to libnetsnmptrapd.la link
+   line in apps/Makefile.in.
+
+3. Executables in apps/ (like snmpusm and snmptls) fail to link because
+   they use OpenSSL symbols directly but do not link with libcrypto/libssl
+   directly. Fix this by adding @LIBCRYPTO@ to LIBS in apps/Makefile.in.
+
+This makes Net-SNMP compatible with newer versions of libtool.
+
+Upstream-Status: Backport [https://github.com/net-snmp/net-snmp/commit/5e66246bd994a2f693bd02773823691c8d07a070]
+
+The libnetsnmptrapd.la hunk is rebased: 5.9.5.2 still puts $(LDFLAGS) at
+the end of that link command, upstream has since moved it before
+$(LLIBTRAPD_OBJS). The change itself is unmodified.
+
+Signed-off-by: Khem Raj <[email protected]>
+---
+ apps/Makefile.in            | 4 ++--
+ configure                   | 7 +++++++
+ configure.d/config_os_libs2 | 6 ++++++
+ 3 files changed, 15 insertions(+), 2 deletions(-)
+
+diff --git a/apps/Makefile.in b/apps/Makefile.in
+index 57b8524..252fd84 100644
+--- a/apps/Makefile.in
++++ b/apps/Makefile.in
+@@ -95,7 +95,7 @@ MYSQL_LIBS   = @MYSQL_LIBS@
+ MYSQL_INCLUDES        = @MYSQL_INCLUDES@
+
+ VAL_LIBS      = @VAL_LIBS@
+-LIBS          = $(USELIBS) $(VAL_LIBS) @LIBS@
++LIBS          = $(USELIBS) $(VAL_LIBS) @LIBS@ @LIBCRYPTO@
+ PERLLDOPTS_FOR_APPS = @PERLLDOPTS_FOR_APPS@
+ PERLLDOPTS_FOR_LIBS = @PERLLDOPTS_FOR_LIBS@
+
+@@ -235,7 +235,7 @@ snmppcap$(EXEEXT):    snmppcap.$(OSUFFIX) $(USEAGENTLIBS)
+        $(LINK) ${CFLAGS} -o $@ snmppcap.$(OSUFFIX) ${LDFLAGS} ${USEAGENTLIBS} ${LIBS} -lpcap
+
+ libnetsnmptrapd.$(LIB_EXTENSION)$(LIB_VERSION): $(LLIBTRAPD_OBJS)
+-      $(LIB_LD_CMD) $@ ${LLIBTRAPD_OBJS} $(MIBLIB) $(MYSQL_LIBS) $(USELIBS) $(PERLLDOPTS_FOR_LIBS) $(LDFLAGS)
++      $(LIB_LD_CMD) $@ ${LLIBTRAPD_OBJS} $(MIBLIB) $(AGENTLIB) $(MYSQL_LIBS) $(USELIBS) $(PERLLDOPTS_FOR_LIBS) $(LDFLAGS)
+        $(RANLIB) $@
+
+ snmpinforminstall:
+diff --git a/configure b/configure
+index 6ef0026..4270aff 100755
+--- a/configure
++++ b/configure
+@@ -683,6 +683,7 @@ PERLLDOPTS_FOR_APPS
+ PERLLDOPTS_FOR_LIBS
+ EMBEDPERLUNINSTALL
+ EMBEDPERLINSTALL
++LIBCRYPTO
+ LIBCURSES
+ HAVE_LIBCURSES
+ NETSNMP_BUILD_PCAP_PROG_FALSE
+@@ -32065,6 +32066,12 @@ printf "%s\n" "$netsnmp_cv_func_ceil_LNETSNMPLIBS" >&6; }
+  fi
+
+
++if test x$CRYPTO != x; then
++    LMIBLIBS="$LMIBLIBS $LIBCRYPTO"
++fi
++
++
++
+ cat >confcache <<\_ACEOF
+ # This file is a shell script that caches the results of configure
+ # tests run on this system so they can be shared between configure
+diff --git a/configure.d/config_os_libs2 b/configure.d/config_os_libs2
+index 5787e58..d21ea77 100644
+--- a/configure.d/config_os_libs2
++++ b/configure.d/config_os_libs2
+@@ -718,3 +718,9 @@ AC_SUBST([LIBCURSES])
+ #   libm for ceil
+ #
+ NETSNMP_SEARCH_LIBS(ceil, m,,,, LNETSNMPLIBS)
++
++if test x$CRYPTO != x; then
++    LMIBLIBS="$LMIBLIBS $LIBCRYPTO"
++fi
++
++AC_SUBST(LIBCRYPTO)
+--
+2.43.0
+
diff --git a/meta-networking/recipes-protocols/net-snmp/net-snmp_5.9.5.2.bb b/meta-networking/recipes-protocols/net-snmp/net-snmp_5.9.5.2.bb
index 00a7b50cdf..48704d020f 100644
--- a/meta-networking/recipes-protocols/net-snmp/net-snmp_5.9.5.2.bb
+++ b/meta-networking/recipes-protocols/net-snmp/net-snmp_5.9.5.2.bb
@@ -24,6 +24,7 @@ SRC_URI = "${SOURCEFORGE_MIRROR}/net-snmp/net-snmp-${PV}.tar.gz \
            file://0009-net-snmp-fix-for-disable-des.patch \
            file://0010-net-snmp-Reproducibility-Don-t-check-build-host-for.patch \
            file://0011-ac_add_search_path.m4-keep-consistent-between-32bit-.patch \
+           file://0012-apps-Makefile.in-Link-libraries-explicitly.patch \
            file://netsnmp-swinst-crash.patch \
            "
 SRC_URI[sha256sum] = "16707719f833184a4b72835dac359ae188123b06b5e42817c00790d7dc1384bf"
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.