xref: /freebsd/contrib/bsnmp/lib/snmpagent.c (revision 135f7de5ddb65ddb53a072113961b7d779a72f1b)
1f06ca4afSHartmut Brandt /*
2f06ca4afSHartmut Brandt  * Copyright (c) 2001-2003
3f06ca4afSHartmut Brandt  *	Fraunhofer Institute for Open Communication Systems (FhG Fokus).
4f06ca4afSHartmut Brandt  *	All rights reserved.
5f06ca4afSHartmut Brandt  *
6f06ca4afSHartmut Brandt  * Author: Harti Brandt <harti@freebsd.org>
7f06ca4afSHartmut Brandt  *
8896052c1SHartmut Brandt  * Redistribution and use in source and binary forms, with or without
9896052c1SHartmut Brandt  * modification, are permitted provided that the following conditions
10896052c1SHartmut Brandt  * are met:
11896052c1SHartmut Brandt  * 1. Redistributions of source code must retain the above copyright
12896052c1SHartmut Brandt  *    notice, this list of conditions and the following disclaimer.
13f06ca4afSHartmut Brandt  * 2. Redistributions in binary form must reproduce the above copyright
14f06ca4afSHartmut Brandt  *    notice, this list of conditions and the following disclaimer in the
15f06ca4afSHartmut Brandt  *    documentation and/or other materials provided with the distribution.
16f06ca4afSHartmut Brandt  *
17896052c1SHartmut Brandt  * THIS SOFTWARE IS PROVIDED BY AUTHOR AND CONTRIBUTORS ``AS IS'' AND
18896052c1SHartmut Brandt  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
19896052c1SHartmut Brandt  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
20896052c1SHartmut Brandt  * ARE DISCLAIMED.  IN NO EVENT SHALL AUTHOR OR CONTRIBUTORS BE LIABLE
21896052c1SHartmut Brandt  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
22896052c1SHartmut Brandt  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
23896052c1SHartmut Brandt  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
24896052c1SHartmut Brandt  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
25896052c1SHartmut Brandt  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
26896052c1SHartmut Brandt  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
27896052c1SHartmut Brandt  * SUCH DAMAGE.
28f06ca4afSHartmut Brandt  *
29165c5d31SHartmut Brandt  * $Begemot: bsnmp/lib/snmpagent.c,v 1.20 2005/10/04 11:21:33 brandt_h Exp $
30f06ca4afSHartmut Brandt  *
31f06ca4afSHartmut Brandt  * SNMP Agent functions
32f06ca4afSHartmut Brandt  */
33f06ca4afSHartmut Brandt #include <sys/types.h>
34f06ca4afSHartmut Brandt #include <sys/queue.h>
35f06ca4afSHartmut Brandt #include <stdio.h>
36f06ca4afSHartmut Brandt #include <stdlib.h>
37f06ca4afSHartmut Brandt #include <stddef.h>
38f06ca4afSHartmut Brandt #include <stdarg.h>
39165c5d31SHartmut Brandt #ifdef HAVE_STDINT_H
40896052c1SHartmut Brandt #include <stdint.h>
41165c5d31SHartmut Brandt #elif defined(HAVE_INTTYPES_H)
42165c5d31SHartmut Brandt #include <inttypes.h>
43165c5d31SHartmut Brandt #endif
44f06ca4afSHartmut Brandt #include <string.h>
45f06ca4afSHartmut Brandt 
46f06ca4afSHartmut Brandt #include "asn1.h"
47f06ca4afSHartmut Brandt #include "snmp.h"
48f06ca4afSHartmut Brandt #include "snmppriv.h"
49f06ca4afSHartmut Brandt #include "snmpagent.h"
50f06ca4afSHartmut Brandt 
51f06ca4afSHartmut Brandt static void snmp_debug_func(const char *fmt, ...);
52f06ca4afSHartmut Brandt 
53f06ca4afSHartmut Brandt void (*snmp_debug)(const char *fmt, ...) = snmp_debug_func;
54f06ca4afSHartmut Brandt 
55f06ca4afSHartmut Brandt struct snmp_node *tree;
56f06ca4afSHartmut Brandt u_int  tree_size;
57f06ca4afSHartmut Brandt 
58f06ca4afSHartmut Brandt /*
59f06ca4afSHartmut Brandt  * Structure to hold dependencies during SET processing
60f06ca4afSHartmut Brandt  * The last two members of this structure must be the
61f06ca4afSHartmut Brandt  * dependency visible by the user and the user data.
62f06ca4afSHartmut Brandt  */
63f06ca4afSHartmut Brandt struct depend {
64f06ca4afSHartmut Brandt 	TAILQ_ENTRY(depend) link;
65f06ca4afSHartmut Brandt 	size_t	len;		/* size of data part */
66f06ca4afSHartmut Brandt 	snmp_depop_t	func;
67f06ca4afSHartmut Brandt 	struct snmp_dependency dep;
68896052c1SHartmut Brandt #if defined(__GNUC__) && __GNUC__ < 3
69896052c1SHartmut Brandt 	u_char	data[0];
70896052c1SHartmut Brandt #else
71f06ca4afSHartmut Brandt 	u_char	data[];
72896052c1SHartmut Brandt #endif
73f06ca4afSHartmut Brandt };
74f06ca4afSHartmut Brandt TAILQ_HEAD(depend_list, depend);
75f06ca4afSHartmut Brandt 
76f06ca4afSHartmut Brandt /*
77f06ca4afSHartmut Brandt  * Set context
78f06ca4afSHartmut Brandt  */
79f06ca4afSHartmut Brandt struct context {
80f06ca4afSHartmut Brandt 	struct snmp_context	ctx;
81f06ca4afSHartmut Brandt 	struct depend_list	dlist;
82f06ca4afSHartmut Brandt 	const struct snmp_node	*node[SNMP_MAX_BINDINGS];
83f06ca4afSHartmut Brandt 	struct snmp_scratch	scratch[SNMP_MAX_BINDINGS];
84f06ca4afSHartmut Brandt 	struct depend		*depend;
85f06ca4afSHartmut Brandt };
86f06ca4afSHartmut Brandt 
87f06ca4afSHartmut Brandt #define	TR(W)	(snmp_trace & SNMP_TRACE_##W)
88f06ca4afSHartmut Brandt u_int snmp_trace = 0;
89f06ca4afSHartmut Brandt 
90f06ca4afSHartmut Brandt static char oidbuf[ASN_OIDSTRLEN];
91f06ca4afSHartmut Brandt 
92f06ca4afSHartmut Brandt /*
93f06ca4afSHartmut Brandt  * Allocate a context
94f06ca4afSHartmut Brandt  */
95f06ca4afSHartmut Brandt struct snmp_context *
96f06ca4afSHartmut Brandt snmp_init_context(void)
97f06ca4afSHartmut Brandt {
98f06ca4afSHartmut Brandt 	struct context *context;
99f06ca4afSHartmut Brandt 
100f06ca4afSHartmut Brandt 	if ((context = malloc(sizeof(*context))) == NULL)
101f06ca4afSHartmut Brandt 		return (NULL);
102f06ca4afSHartmut Brandt 
103f06ca4afSHartmut Brandt 	memset(context, 0, sizeof(*context));
104f06ca4afSHartmut Brandt 	TAILQ_INIT(&context->dlist);
105f06ca4afSHartmut Brandt 
106f06ca4afSHartmut Brandt 	return (&context->ctx);
107f06ca4afSHartmut Brandt }
108f06ca4afSHartmut Brandt 
109f06ca4afSHartmut Brandt /*
110f06ca4afSHartmut Brandt  * Find a variable for SET/GET and the first GETBULK pass.
111f06ca4afSHartmut Brandt  * Return the node pointer. If the search fails, set the errp to
112f06ca4afSHartmut Brandt  * the correct SNMPv2 GET exception code.
113f06ca4afSHartmut Brandt  */
114f06ca4afSHartmut Brandt static struct snmp_node *
115f06ca4afSHartmut Brandt find_node(const struct snmp_value *value, enum snmp_syntax *errp)
116f06ca4afSHartmut Brandt {
117f06ca4afSHartmut Brandt 	struct snmp_node *tp;
118f06ca4afSHartmut Brandt 
119f06ca4afSHartmut Brandt 	if (TR(FIND))
120f06ca4afSHartmut Brandt 		snmp_debug("find: searching %s",
121f06ca4afSHartmut Brandt 		    asn_oid2str_r(&value->var, oidbuf));
122f06ca4afSHartmut Brandt 
123f06ca4afSHartmut Brandt 	/*
124f06ca4afSHartmut Brandt 	 * If we have an exact match (the entry in the table is a
125f06ca4afSHartmut Brandt 	 * sub-oid from the variable) we have found what we are for.
126f06ca4afSHartmut Brandt 	 * If the table oid is higher than the variable, there is no match.
127f06ca4afSHartmut Brandt 	 */
128f06ca4afSHartmut Brandt 	for (tp = tree; tp < tree + tree_size; tp++) {
129f06ca4afSHartmut Brandt 		if (asn_is_suboid(&tp->oid, &value->var))
130f06ca4afSHartmut Brandt 			goto found;
131f06ca4afSHartmut Brandt 		if (asn_compare_oid(&tp->oid, &value->var) >= 0)
132f06ca4afSHartmut Brandt 			break;
133f06ca4afSHartmut Brandt 	}
134f06ca4afSHartmut Brandt 
135f06ca4afSHartmut Brandt 	if (TR(FIND))
136f06ca4afSHartmut Brandt 		snmp_debug("find: no match");
137f06ca4afSHartmut Brandt 	*errp = SNMP_SYNTAX_NOSUCHOBJECT;
138f06ca4afSHartmut Brandt 	return (NULL);
139f06ca4afSHartmut Brandt 
140f06ca4afSHartmut Brandt   found:
141f06ca4afSHartmut Brandt 	/* leafs must have a 0 instance identifier */
142f06ca4afSHartmut Brandt 	if (tp->type == SNMP_NODE_LEAF &&
143f06ca4afSHartmut Brandt 	    (value->var.len != tp->oid.len + 1 ||
144f06ca4afSHartmut Brandt 	     value->var.subs[tp->oid.len] != 0)) {
145f06ca4afSHartmut Brandt 		if (TR(FIND))
146f06ca4afSHartmut Brandt 			snmp_debug("find: bad leaf index");
147f06ca4afSHartmut Brandt 		*errp = SNMP_SYNTAX_NOSUCHINSTANCE;
148f06ca4afSHartmut Brandt 		return (NULL);
149f06ca4afSHartmut Brandt 	}
150f06ca4afSHartmut Brandt 	if (TR(FIND))
151f06ca4afSHartmut Brandt 		snmp_debug("find: found %s",
152f06ca4afSHartmut Brandt 		    asn_oid2str_r(&value->var, oidbuf));
153f06ca4afSHartmut Brandt 	return (tp);
154f06ca4afSHartmut Brandt }
155f06ca4afSHartmut Brandt 
156f06ca4afSHartmut Brandt static struct snmp_node *
157f06ca4afSHartmut Brandt find_subnode(const struct snmp_value *value)
158f06ca4afSHartmut Brandt {
159f06ca4afSHartmut Brandt 	struct snmp_node *tp;
160f06ca4afSHartmut Brandt 
161f06ca4afSHartmut Brandt 	for (tp = tree; tp < tree + tree_size; tp++) {
162f06ca4afSHartmut Brandt 		if (asn_is_suboid(&value->var, &tp->oid))
163f06ca4afSHartmut Brandt 			return (tp);
164f06ca4afSHartmut Brandt 	}
165f06ca4afSHartmut Brandt 	return (NULL);
166f06ca4afSHartmut Brandt }
167f06ca4afSHartmut Brandt 
168*135f7de5SShteryana Shopova static void
169*135f7de5SShteryana Shopova snmp_pdu_create_response(struct snmp_pdu *pdu, struct snmp_pdu *resp)
170*135f7de5SShteryana Shopova {
171*135f7de5SShteryana Shopova 	memset(resp, 0, sizeof(*resp));
172*135f7de5SShteryana Shopova 	strcpy(resp->community, pdu->community);
173*135f7de5SShteryana Shopova 	resp->version = pdu->version;
174*135f7de5SShteryana Shopova 	resp->type = SNMP_PDU_RESPONSE;
175*135f7de5SShteryana Shopova 	resp->request_id = pdu->request_id;
176*135f7de5SShteryana Shopova 	resp->version = pdu->version;
177*135f7de5SShteryana Shopova 
178*135f7de5SShteryana Shopova 	if (resp->version != SNMP_V3)
179*135f7de5SShteryana Shopova 		return;
180*135f7de5SShteryana Shopova 
181*135f7de5SShteryana Shopova 	snmp_pdu_init_secparams(resp, &pdu->engine, &pdu->user);
182*135f7de5SShteryana Shopova 	resp->identifier = pdu->identifier;
183*135f7de5SShteryana Shopova 	resp->security_model = pdu->security_model;
184*135f7de5SShteryana Shopova 	resp->context_engine_len = pdu->context_engine_len;
185*135f7de5SShteryana Shopova 	memcpy(resp->context_engine, pdu->context_engine,
186*135f7de5SShteryana Shopova 	    resp->context_engine_len);
187*135f7de5SShteryana Shopova 	strlcpy(resp->context_name, pdu->context_name,
188*135f7de5SShteryana Shopova 	    sizeof(resp->context_name));
189*135f7de5SShteryana Shopova }
190*135f7de5SShteryana Shopova 
191f06ca4afSHartmut Brandt /*
192f06ca4afSHartmut Brandt  * Execute a GET operation. The tree is rooted at the global 'root'.
193f06ca4afSHartmut Brandt  * Build the response PDU on the fly. If the return code is SNMP_RET_ERR
194f06ca4afSHartmut Brandt  * the pdu error status and index will be set.
195f06ca4afSHartmut Brandt  */
196f06ca4afSHartmut Brandt enum snmp_ret
197f06ca4afSHartmut Brandt snmp_get(struct snmp_pdu *pdu, struct asn_buf *resp_b,
198f06ca4afSHartmut Brandt     struct snmp_pdu *resp, void *data)
199f06ca4afSHartmut Brandt {
200f06ca4afSHartmut Brandt 	int ret;
201f06ca4afSHartmut Brandt 	u_int i;
202f06ca4afSHartmut Brandt 	struct snmp_node *tp;
203f06ca4afSHartmut Brandt 	enum snmp_syntax except;
204f06ca4afSHartmut Brandt 	struct context context;
205f06ca4afSHartmut Brandt 	enum asn_err err;
206f06ca4afSHartmut Brandt 
207f06ca4afSHartmut Brandt 	memset(&context, 0, sizeof(context));
208f06ca4afSHartmut Brandt 	context.ctx.data = data;
209f06ca4afSHartmut Brandt 
210*135f7de5SShteryana Shopova 	snmp_pdu_create_response(pdu, resp);
211f06ca4afSHartmut Brandt 
212f06ca4afSHartmut Brandt 	if (snmp_pdu_encode_header(resp_b, resp) != SNMP_CODE_OK)
213f06ca4afSHartmut Brandt 		/* cannot even encode header - very bad */
214f06ca4afSHartmut Brandt 		return (SNMP_RET_IGN);
215f06ca4afSHartmut Brandt 
216f06ca4afSHartmut Brandt 	for (i = 0; i < pdu->nbindings; i++) {
217f06ca4afSHartmut Brandt 		resp->bindings[i].var = pdu->bindings[i].var;
218f06ca4afSHartmut Brandt 		if ((tp = find_node(&pdu->bindings[i], &except)) == NULL) {
219f06ca4afSHartmut Brandt 			if (pdu->version == SNMP_V1) {
220f06ca4afSHartmut Brandt 				if (TR(GET))
221f06ca4afSHartmut Brandt 					snmp_debug("get: nosuchname");
222f06ca4afSHartmut Brandt 				pdu->error_status = SNMP_ERR_NOSUCHNAME;
223f06ca4afSHartmut Brandt 				pdu->error_index = i + 1;
224f06ca4afSHartmut Brandt 				snmp_pdu_free(resp);
225f06ca4afSHartmut Brandt 				return (SNMP_RET_ERR);
226f06ca4afSHartmut Brandt 			}
227f06ca4afSHartmut Brandt 			if (TR(GET))
228f06ca4afSHartmut Brandt 				snmp_debug("get: exception %u", except);
229f06ca4afSHartmut Brandt 			resp->bindings[i].syntax = except;
230f06ca4afSHartmut Brandt 
231f06ca4afSHartmut Brandt 		} else {
232f06ca4afSHartmut Brandt 			/* call the action to fetch the value. */
233f06ca4afSHartmut Brandt 			resp->bindings[i].syntax = tp->syntax;
234f06ca4afSHartmut Brandt 			ret = (*tp->op)(&context.ctx, &resp->bindings[i],
235f06ca4afSHartmut Brandt 			    tp->oid.len, tp->index, SNMP_OP_GET);
236f06ca4afSHartmut Brandt 			if (TR(GET))
237f06ca4afSHartmut Brandt 				snmp_debug("get: action returns %d", ret);
238f06ca4afSHartmut Brandt 
239f06ca4afSHartmut Brandt 			if (ret == SNMP_ERR_NOSUCHNAME) {
240f06ca4afSHartmut Brandt 				if (pdu->version == SNMP_V1) {
241f06ca4afSHartmut Brandt 					pdu->error_status = SNMP_ERR_NOSUCHNAME;
242f06ca4afSHartmut Brandt 					pdu->error_index = i + 1;
243f06ca4afSHartmut Brandt 					snmp_pdu_free(resp);
244f06ca4afSHartmut Brandt 					return (SNMP_RET_ERR);
245f06ca4afSHartmut Brandt 				}
246f06ca4afSHartmut Brandt 				if (TR(GET))
247f06ca4afSHartmut Brandt 					snmp_debug("get: exception noSuchInstance");
248f06ca4afSHartmut Brandt 				resp->bindings[i].syntax = SNMP_SYNTAX_NOSUCHINSTANCE;
249f06ca4afSHartmut Brandt 
250f06ca4afSHartmut Brandt 			} else if (ret != SNMP_ERR_NOERROR) {
251f06ca4afSHartmut Brandt 				pdu->error_status = SNMP_ERR_GENERR;
252f06ca4afSHartmut Brandt 				pdu->error_index = i + 1;
253f06ca4afSHartmut Brandt 				snmp_pdu_free(resp);
254f06ca4afSHartmut Brandt 				return (SNMP_RET_ERR);
255f06ca4afSHartmut Brandt 			}
256f06ca4afSHartmut Brandt 		}
257f06ca4afSHartmut Brandt 		resp->nbindings++;
258f06ca4afSHartmut Brandt 
259f06ca4afSHartmut Brandt 		err = snmp_binding_encode(resp_b, &resp->bindings[i]);
260f06ca4afSHartmut Brandt 
261f06ca4afSHartmut Brandt 		if (err == ASN_ERR_EOBUF) {
262f06ca4afSHartmut Brandt 			pdu->error_status = SNMP_ERR_TOOBIG;
263f06ca4afSHartmut Brandt 			pdu->error_index = 0;
264f06ca4afSHartmut Brandt 			snmp_pdu_free(resp);
265f06ca4afSHartmut Brandt 			return (SNMP_RET_ERR);
266f06ca4afSHartmut Brandt 		}
267f06ca4afSHartmut Brandt 		if (err != ASN_ERR_OK) {
268f06ca4afSHartmut Brandt 			if (TR(GET))
269f06ca4afSHartmut Brandt 				snmp_debug("get: binding encoding: %u", err);
270f06ca4afSHartmut Brandt 			pdu->error_status = SNMP_ERR_GENERR;
271f06ca4afSHartmut Brandt 			pdu->error_index = i + 1;
272f06ca4afSHartmut Brandt 			snmp_pdu_free(resp);
273f06ca4afSHartmut Brandt 			return (SNMP_RET_ERR);
274f06ca4afSHartmut Brandt 		}
275f06ca4afSHartmut Brandt 	}
276f06ca4afSHartmut Brandt 
277f06ca4afSHartmut Brandt 	return (snmp_fix_encoding(resp_b, resp));
278f06ca4afSHartmut Brandt }
279f06ca4afSHartmut Brandt 
280f06ca4afSHartmut Brandt static struct snmp_node *
281f06ca4afSHartmut Brandt next_node(const struct snmp_value *value, int *pnext)
282f06ca4afSHartmut Brandt {
283f06ca4afSHartmut Brandt 	struct snmp_node *tp;
284f06ca4afSHartmut Brandt 
285f06ca4afSHartmut Brandt 	if (TR(FIND))
286f06ca4afSHartmut Brandt 		snmp_debug("next: searching %s",
287f06ca4afSHartmut Brandt 		    asn_oid2str_r(&value->var, oidbuf));
288f06ca4afSHartmut Brandt 
289f06ca4afSHartmut Brandt 	*pnext = 0;
290f06ca4afSHartmut Brandt 	for (tp = tree; tp < tree + tree_size; tp++) {
291f06ca4afSHartmut Brandt 		if (asn_is_suboid(&tp->oid, &value->var)) {
292f06ca4afSHartmut Brandt 			/* the tree OID is a sub-oid of the requested OID. */
293f06ca4afSHartmut Brandt 			if (tp->type == SNMP_NODE_LEAF) {
294f06ca4afSHartmut Brandt 				if (tp->oid.len == value->var.len) {
295f06ca4afSHartmut Brandt 					/* request for scalar type */
296f06ca4afSHartmut Brandt 					if (TR(FIND))
297f06ca4afSHartmut Brandt 						snmp_debug("next: found scalar %s",
298f06ca4afSHartmut Brandt 						    asn_oid2str_r(&tp->oid, oidbuf));
299f06ca4afSHartmut Brandt 					return (tp);
300f06ca4afSHartmut Brandt 				}
301f06ca4afSHartmut Brandt 				/* try next */
302f06ca4afSHartmut Brandt 			} else {
303f06ca4afSHartmut Brandt 				if (TR(FIND))
304f06ca4afSHartmut Brandt 					snmp_debug("next: found column %s",
305f06ca4afSHartmut Brandt 					    asn_oid2str_r(&tp->oid, oidbuf));
306f06ca4afSHartmut Brandt 				return (tp);
307f06ca4afSHartmut Brandt 			}
308f06ca4afSHartmut Brandt 		} else if (asn_is_suboid(&value->var, &tp->oid) ||
309f06ca4afSHartmut Brandt 		    asn_compare_oid(&tp->oid, &value->var) >= 0) {
310f06ca4afSHartmut Brandt 			if (TR(FIND))
311f06ca4afSHartmut Brandt 				snmp_debug("next: found %s",
312f06ca4afSHartmut Brandt 				    asn_oid2str_r(&tp->oid, oidbuf));
313f06ca4afSHartmut Brandt 			*pnext = 1;
314f06ca4afSHartmut Brandt 			return (tp);
315f06ca4afSHartmut Brandt 		}
316f06ca4afSHartmut Brandt 	}
317f06ca4afSHartmut Brandt 
318f06ca4afSHartmut Brandt 	if (TR(FIND))
319f06ca4afSHartmut Brandt 		snmp_debug("next: failed");
320f06ca4afSHartmut Brandt 
321f06ca4afSHartmut Brandt 	return (NULL);
322f06ca4afSHartmut Brandt }
323f06ca4afSHartmut Brandt 
324f06ca4afSHartmut Brandt static enum snmp_ret
325f06ca4afSHartmut Brandt do_getnext(struct context *context, const struct snmp_value *inb,
326f06ca4afSHartmut Brandt     struct snmp_value *outb, struct snmp_pdu *pdu)
327f06ca4afSHartmut Brandt {
328f06ca4afSHartmut Brandt 	const struct snmp_node *tp;
329f06ca4afSHartmut Brandt 	int ret, next;
330f06ca4afSHartmut Brandt 
331f06ca4afSHartmut Brandt 	if ((tp = next_node(inb, &next)) == NULL)
332f06ca4afSHartmut Brandt 		goto eofMib;
333f06ca4afSHartmut Brandt 
334f06ca4afSHartmut Brandt 	/* retain old variable if we are doing a GETNEXT on an exact
335f06ca4afSHartmut Brandt 	 * matched leaf only */
336f06ca4afSHartmut Brandt 	if (tp->type == SNMP_NODE_LEAF || next)
337f06ca4afSHartmut Brandt 		outb->var = tp->oid;
338f06ca4afSHartmut Brandt 	else
339f06ca4afSHartmut Brandt 		outb->var = inb->var;
340f06ca4afSHartmut Brandt 
341f06ca4afSHartmut Brandt 	for (;;) {
342f06ca4afSHartmut Brandt 		outb->syntax = tp->syntax;
343f06ca4afSHartmut Brandt 		if (tp->type == SNMP_NODE_LEAF) {
344f06ca4afSHartmut Brandt 			/* make a GET operation */
345f06ca4afSHartmut Brandt 			outb->var.subs[outb->var.len++] = 0;
346f06ca4afSHartmut Brandt 			ret = (*tp->op)(&context->ctx, outb, tp->oid.len,
347f06ca4afSHartmut Brandt 			    tp->index, SNMP_OP_GET);
348f06ca4afSHartmut Brandt 		} else {
349f06ca4afSHartmut Brandt 			/* make a GETNEXT */
350f06ca4afSHartmut Brandt 			ret = (*tp->op)(&context->ctx, outb, tp->oid.len,
351f06ca4afSHartmut Brandt 			     tp->index, SNMP_OP_GETNEXT);
352f06ca4afSHartmut Brandt 		}
353f06ca4afSHartmut Brandt 		if (ret != SNMP_ERR_NOSUCHNAME) {
354f06ca4afSHartmut Brandt 			/* got something */
355f06ca4afSHartmut Brandt 			if (ret != SNMP_ERR_NOERROR && TR(GETNEXT))
356f06ca4afSHartmut Brandt 				snmp_debug("getnext: %s returns %u",
357f06ca4afSHartmut Brandt 				    asn_oid2str(&outb->var), ret);
358f06ca4afSHartmut Brandt 			break;
359f06ca4afSHartmut Brandt 		}
360f06ca4afSHartmut Brandt 
361f06ca4afSHartmut Brandt 		/* object has no data - try next */
362f06ca4afSHartmut Brandt 		if (++tp == tree + tree_size)
363f06ca4afSHartmut Brandt 			break;
36494caccb3SHartmut Brandt 
36594caccb3SHartmut Brandt 		if (TR(GETNEXT))
36694caccb3SHartmut Brandt 			snmp_debug("getnext: no data - avancing to %s",
36794caccb3SHartmut Brandt 			    asn_oid2str(&tp->oid));
36894caccb3SHartmut Brandt 
369f06ca4afSHartmut Brandt 		outb->var = tp->oid;
370f06ca4afSHartmut Brandt 	}
371f06ca4afSHartmut Brandt 
372f06ca4afSHartmut Brandt 	if (ret == SNMP_ERR_NOSUCHNAME) {
373f06ca4afSHartmut Brandt   eofMib:
374f06ca4afSHartmut Brandt 		outb->var = inb->var;
375f06ca4afSHartmut Brandt 		if (pdu->version == SNMP_V1) {
376f06ca4afSHartmut Brandt 			pdu->error_status = SNMP_ERR_NOSUCHNAME;
377f06ca4afSHartmut Brandt 			return (SNMP_RET_ERR);
378f06ca4afSHartmut Brandt 		}
379f06ca4afSHartmut Brandt 		outb->syntax = SNMP_SYNTAX_ENDOFMIBVIEW;
380f06ca4afSHartmut Brandt 
381f06ca4afSHartmut Brandt 	} else if (ret != SNMP_ERR_NOERROR) {
382f06ca4afSHartmut Brandt 		pdu->error_status = SNMP_ERR_GENERR;
383f06ca4afSHartmut Brandt 		return (SNMP_RET_ERR);
384f06ca4afSHartmut Brandt 	}
385f06ca4afSHartmut Brandt 	return (SNMP_RET_OK);
386f06ca4afSHartmut Brandt }
387f06ca4afSHartmut Brandt 
388f06ca4afSHartmut Brandt 
389f06ca4afSHartmut Brandt /*
390f06ca4afSHartmut Brandt  * Execute a GETNEXT operation. The tree is rooted at the global 'root'.
391f06ca4afSHartmut Brandt  * Build the response PDU on the fly. The return is:
392f06ca4afSHartmut Brandt  */
393f06ca4afSHartmut Brandt enum snmp_ret
394f06ca4afSHartmut Brandt snmp_getnext(struct snmp_pdu *pdu, struct asn_buf *resp_b,
395f06ca4afSHartmut Brandt     struct snmp_pdu *resp, void *data)
396f06ca4afSHartmut Brandt {
397f06ca4afSHartmut Brandt 	struct context context;
398f06ca4afSHartmut Brandt 	u_int i;
399f06ca4afSHartmut Brandt 	enum asn_err err;
400f06ca4afSHartmut Brandt 	enum snmp_ret result;
401f06ca4afSHartmut Brandt 
402f06ca4afSHartmut Brandt 	memset(&context, 0, sizeof(context));
403f06ca4afSHartmut Brandt 	context.ctx.data = data;
404f06ca4afSHartmut Brandt 
405*135f7de5SShteryana Shopova 	snmp_pdu_create_response(pdu, resp);
406f06ca4afSHartmut Brandt 
407f06ca4afSHartmut Brandt 	if (snmp_pdu_encode_header(resp_b, resp))
408f06ca4afSHartmut Brandt 		return (SNMP_RET_IGN);
409f06ca4afSHartmut Brandt 
410f06ca4afSHartmut Brandt 	for (i = 0; i < pdu->nbindings; i++) {
411f06ca4afSHartmut Brandt 		result = do_getnext(&context, &pdu->bindings[i],
412f06ca4afSHartmut Brandt 		    &resp->bindings[i], pdu);
413f06ca4afSHartmut Brandt 
414f06ca4afSHartmut Brandt 		if (result != SNMP_RET_OK) {
415f06ca4afSHartmut Brandt 			pdu->error_index = i + 1;
416f06ca4afSHartmut Brandt 			snmp_pdu_free(resp);
417f06ca4afSHartmut Brandt 			return (result);
418f06ca4afSHartmut Brandt 		}
419f06ca4afSHartmut Brandt 
420f06ca4afSHartmut Brandt 		resp->nbindings++;
421f06ca4afSHartmut Brandt 
422f06ca4afSHartmut Brandt 		err = snmp_binding_encode(resp_b, &resp->bindings[i]);
423f06ca4afSHartmut Brandt 
424f06ca4afSHartmut Brandt 		if (err == ASN_ERR_EOBUF) {
425f06ca4afSHartmut Brandt 			pdu->error_status = SNMP_ERR_TOOBIG;
426f06ca4afSHartmut Brandt 			pdu->error_index = 0;
427f06ca4afSHartmut Brandt 			snmp_pdu_free(resp);
428f06ca4afSHartmut Brandt 			return (SNMP_RET_ERR);
429f06ca4afSHartmut Brandt 		}
430f06ca4afSHartmut Brandt 		if (err != ASN_ERR_OK) {
431f06ca4afSHartmut Brandt 			if (TR(GET))
432f06ca4afSHartmut Brandt 				snmp_debug("getnext: binding encoding: %u", err);
433f06ca4afSHartmut Brandt 			pdu->error_status = SNMP_ERR_GENERR;
434f06ca4afSHartmut Brandt 			pdu->error_index = i + 1;
435f06ca4afSHartmut Brandt 			snmp_pdu_free(resp);
436f06ca4afSHartmut Brandt 			return (SNMP_RET_ERR);
437f06ca4afSHartmut Brandt 		}
438f06ca4afSHartmut Brandt 	}
439f06ca4afSHartmut Brandt 	return (snmp_fix_encoding(resp_b, resp));
440f06ca4afSHartmut Brandt }
441f06ca4afSHartmut Brandt 
442f06ca4afSHartmut Brandt enum snmp_ret
443f06ca4afSHartmut Brandt snmp_getbulk(struct snmp_pdu *pdu, struct asn_buf *resp_b,
444f06ca4afSHartmut Brandt     struct snmp_pdu *resp, void *data)
445f06ca4afSHartmut Brandt {
446f06ca4afSHartmut Brandt 	struct context context;
447f06ca4afSHartmut Brandt 	u_int i;
448f06ca4afSHartmut Brandt 	int cnt;
449f06ca4afSHartmut Brandt 	u_int non_rep;
450f06ca4afSHartmut Brandt 	int eomib;
451f06ca4afSHartmut Brandt 	enum snmp_ret result;
452f06ca4afSHartmut Brandt 	enum asn_err err;
453f06ca4afSHartmut Brandt 
454f06ca4afSHartmut Brandt 	memset(&context, 0, sizeof(context));
455f06ca4afSHartmut Brandt 	context.ctx.data = data;
456f06ca4afSHartmut Brandt 
457*135f7de5SShteryana Shopova 	snmp_pdu_create_response(pdu, resp);
458f06ca4afSHartmut Brandt 
459f06ca4afSHartmut Brandt 	if (snmp_pdu_encode_header(resp_b, resp) != SNMP_CODE_OK)
460f06ca4afSHartmut Brandt 		/* cannot even encode header - very bad */
461f06ca4afSHartmut Brandt 		return (SNMP_RET_IGN);
462f06ca4afSHartmut Brandt 
463f06ca4afSHartmut Brandt 	if ((non_rep = pdu->error_status) > pdu->nbindings)
464f06ca4afSHartmut Brandt 		non_rep = pdu->nbindings;
465f06ca4afSHartmut Brandt 
466f06ca4afSHartmut Brandt 	/* non-repeaters */
467f06ca4afSHartmut Brandt 	for (i = 0; i < non_rep; i++) {
468f06ca4afSHartmut Brandt 		result = do_getnext(&context, &pdu->bindings[i],
469f06ca4afSHartmut Brandt 		    &resp->bindings[resp->nbindings], pdu);
470f06ca4afSHartmut Brandt 
471f06ca4afSHartmut Brandt 		if (result != SNMP_RET_OK) {
472f06ca4afSHartmut Brandt 			pdu->error_index = i + 1;
473f06ca4afSHartmut Brandt 			snmp_pdu_free(resp);
474f06ca4afSHartmut Brandt 			return (result);
475f06ca4afSHartmut Brandt 		}
476f06ca4afSHartmut Brandt 
477f06ca4afSHartmut Brandt 		err = snmp_binding_encode(resp_b,
478f06ca4afSHartmut Brandt 		    &resp->bindings[resp->nbindings++]);
479f06ca4afSHartmut Brandt 
480f06ca4afSHartmut Brandt 		if (err == ASN_ERR_EOBUF)
481f06ca4afSHartmut Brandt 			goto done;
482f06ca4afSHartmut Brandt 
483f06ca4afSHartmut Brandt 		if (err != ASN_ERR_OK) {
484f06ca4afSHartmut Brandt 			if (TR(GET))
485f06ca4afSHartmut Brandt 				snmp_debug("getnext: binding encoding: %u", err);
486f06ca4afSHartmut Brandt 			pdu->error_status = SNMP_ERR_GENERR;
487f06ca4afSHartmut Brandt 			pdu->error_index = i + 1;
488f06ca4afSHartmut Brandt 			snmp_pdu_free(resp);
489f06ca4afSHartmut Brandt 			return (SNMP_RET_ERR);
490f06ca4afSHartmut Brandt 		}
491f06ca4afSHartmut Brandt 	}
492f06ca4afSHartmut Brandt 
493f06ca4afSHartmut Brandt 	if (non_rep == pdu->nbindings)
494f06ca4afSHartmut Brandt 		goto done;
495f06ca4afSHartmut Brandt 
496f06ca4afSHartmut Brandt 	/* repeates */
497f06ca4afSHartmut Brandt 	for (cnt = 0; cnt < pdu->error_index; cnt++) {
498f06ca4afSHartmut Brandt 		eomib = 1;
499f06ca4afSHartmut Brandt 		for (i = non_rep; i < pdu->nbindings; i++) {
500f06ca4afSHartmut Brandt 			if (cnt == 0)
501f06ca4afSHartmut Brandt 				result = do_getnext(&context, &pdu->bindings[i],
502f06ca4afSHartmut Brandt 				    &resp->bindings[resp->nbindings], pdu);
503f06ca4afSHartmut Brandt 			else
504f06ca4afSHartmut Brandt 				result = do_getnext(&context,
505f06ca4afSHartmut Brandt 				    &resp->bindings[resp->nbindings -
506f06ca4afSHartmut Brandt 				    (pdu->nbindings - non_rep)],
507f06ca4afSHartmut Brandt 				    &resp->bindings[resp->nbindings], pdu);
508f06ca4afSHartmut Brandt 
509f06ca4afSHartmut Brandt 			if (result != SNMP_RET_OK) {
510f06ca4afSHartmut Brandt 				pdu->error_index = i + 1;
511f06ca4afSHartmut Brandt 				snmp_pdu_free(resp);
512f06ca4afSHartmut Brandt 				return (result);
513f06ca4afSHartmut Brandt 			}
514f06ca4afSHartmut Brandt 			if (resp->bindings[resp->nbindings].syntax !=
515f06ca4afSHartmut Brandt 			    SNMP_SYNTAX_ENDOFMIBVIEW)
516f06ca4afSHartmut Brandt 				eomib = 0;
517f06ca4afSHartmut Brandt 
518f06ca4afSHartmut Brandt 			err = snmp_binding_encode(resp_b,
519f06ca4afSHartmut Brandt 			    &resp->bindings[resp->nbindings++]);
520f06ca4afSHartmut Brandt 
521f06ca4afSHartmut Brandt 			if (err == ASN_ERR_EOBUF)
522f06ca4afSHartmut Brandt 				goto done;
523f06ca4afSHartmut Brandt 
524f06ca4afSHartmut Brandt 			if (err != ASN_ERR_OK) {
525f06ca4afSHartmut Brandt 				if (TR(GET))
526f06ca4afSHartmut Brandt 					snmp_debug("getnext: binding encoding: %u", err);
527f06ca4afSHartmut Brandt 				pdu->error_status = SNMP_ERR_GENERR;
528f06ca4afSHartmut Brandt 				pdu->error_index = i + 1;
529f06ca4afSHartmut Brandt 				snmp_pdu_free(resp);
530f06ca4afSHartmut Brandt 				return (SNMP_RET_ERR);
531f06ca4afSHartmut Brandt 			}
532f06ca4afSHartmut Brandt 		}
533f06ca4afSHartmut Brandt 		if (eomib)
534f06ca4afSHartmut Brandt 			break;
535f06ca4afSHartmut Brandt 	}
536f06ca4afSHartmut Brandt 
537f06ca4afSHartmut Brandt   done:
538f06ca4afSHartmut Brandt 	return (snmp_fix_encoding(resp_b, resp));
539f06ca4afSHartmut Brandt }
540f06ca4afSHartmut Brandt 
541f06ca4afSHartmut Brandt /*
542f06ca4afSHartmut Brandt  * Rollback a SET operation. Failed index is 'i'.
543f06ca4afSHartmut Brandt  */
544f06ca4afSHartmut Brandt static void
545f06ca4afSHartmut Brandt rollback(struct context *context, struct snmp_pdu *pdu, u_int i)
546f06ca4afSHartmut Brandt {
547f06ca4afSHartmut Brandt 	struct snmp_value *b;
548f06ca4afSHartmut Brandt 	const struct snmp_node *np;
549f06ca4afSHartmut Brandt 	int ret;
550f06ca4afSHartmut Brandt 
551f06ca4afSHartmut Brandt 	while (i-- > 0) {
552f06ca4afSHartmut Brandt 		b = &pdu->bindings[i];
553f06ca4afSHartmut Brandt 		np = context->node[i];
554f06ca4afSHartmut Brandt 
555f06ca4afSHartmut Brandt 		context->ctx.scratch = &context->scratch[i];
556f06ca4afSHartmut Brandt 
557f06ca4afSHartmut Brandt 		ret = (*np->op)(&context->ctx, b, np->oid.len, np->index,
558f06ca4afSHartmut Brandt 		    SNMP_OP_ROLLBACK);
559f06ca4afSHartmut Brandt 
560f06ca4afSHartmut Brandt 		if (ret != SNMP_ERR_NOERROR) {
561f06ca4afSHartmut Brandt 			snmp_error("set: rollback failed (%d) on variable %s "
562f06ca4afSHartmut Brandt 			    "index %u", ret, asn_oid2str(&b->var), i);
563f06ca4afSHartmut Brandt 			if (pdu->version != SNMP_V1) {
564f06ca4afSHartmut Brandt 				pdu->error_status = SNMP_ERR_UNDO_FAILED;
565f06ca4afSHartmut Brandt 				pdu->error_index = 0;
566f06ca4afSHartmut Brandt 			}
567f06ca4afSHartmut Brandt 		}
568f06ca4afSHartmut Brandt 	}
569f06ca4afSHartmut Brandt }
570f06ca4afSHartmut Brandt 
571f06ca4afSHartmut Brandt /*
572f06ca4afSHartmut Brandt  * Commit dependencies.
573f06ca4afSHartmut Brandt  */
574f06ca4afSHartmut Brandt int
575f06ca4afSHartmut Brandt snmp_dep_commit(struct snmp_context *ctx)
576f06ca4afSHartmut Brandt {
577f06ca4afSHartmut Brandt 	struct context *context = (struct context *)ctx;
578f06ca4afSHartmut Brandt 	int ret;
579f06ca4afSHartmut Brandt 
580f06ca4afSHartmut Brandt 	TAILQ_FOREACH(context->depend, &context->dlist, link) {
581f06ca4afSHartmut Brandt 		ctx->dep = &context->depend->dep;
582f06ca4afSHartmut Brandt 
583f06ca4afSHartmut Brandt 		if (TR(SET))
584f06ca4afSHartmut Brandt 			snmp_debug("set: dependency commit %s",
585f06ca4afSHartmut Brandt 			    asn_oid2str(&ctx->dep->obj));
586f06ca4afSHartmut Brandt 
587f06ca4afSHartmut Brandt 		ret = context->depend->func(ctx, ctx->dep, SNMP_DEPOP_COMMIT);
588f06ca4afSHartmut Brandt 
589f06ca4afSHartmut Brandt 		if (ret != SNMP_ERR_NOERROR) {
590f06ca4afSHartmut Brandt 			if (TR(SET))
591f06ca4afSHartmut Brandt 				snmp_debug("set: dependency failed %d", ret);
592f06ca4afSHartmut Brandt 			return (ret);
593f06ca4afSHartmut Brandt 		}
594f06ca4afSHartmut Brandt 	}
595f06ca4afSHartmut Brandt 	return (SNMP_ERR_NOERROR);
596f06ca4afSHartmut Brandt }
597f06ca4afSHartmut Brandt 
598f06ca4afSHartmut Brandt /*
599f06ca4afSHartmut Brandt  * Rollback dependencies
600f06ca4afSHartmut Brandt  */
601f06ca4afSHartmut Brandt int
602f06ca4afSHartmut Brandt snmp_dep_rollback(struct snmp_context *ctx)
603f06ca4afSHartmut Brandt {
604f06ca4afSHartmut Brandt 	struct context *context = (struct context *)ctx;
605f06ca4afSHartmut Brandt 	int ret, ret1;
606f06ca4afSHartmut Brandt 	char objbuf[ASN_OIDSTRLEN];
607f06ca4afSHartmut Brandt 	char idxbuf[ASN_OIDSTRLEN];
608f06ca4afSHartmut Brandt 
609f06ca4afSHartmut Brandt 	ret1 = SNMP_ERR_NOERROR;
610f06ca4afSHartmut Brandt 	while ((context->depend =
611f06ca4afSHartmut Brandt 	    TAILQ_PREV(context->depend, depend_list, link)) != NULL) {
612f06ca4afSHartmut Brandt 		ctx->dep = &context->depend->dep;
613f06ca4afSHartmut Brandt 
614f06ca4afSHartmut Brandt 		if (TR(SET))
615f06ca4afSHartmut Brandt 			snmp_debug("set: dependency rollback %s",
616f06ca4afSHartmut Brandt 			    asn_oid2str(&ctx->dep->obj));
617f06ca4afSHartmut Brandt 
618f06ca4afSHartmut Brandt 		ret = context->depend->func(ctx, ctx->dep, SNMP_DEPOP_ROLLBACK);
619f06ca4afSHartmut Brandt 
620f06ca4afSHartmut Brandt 		if (ret != SNMP_ERR_NOERROR) {
621f06ca4afSHartmut Brandt 			snmp_debug("set: dep rollback returns %u: %s %s", ret,
622f06ca4afSHartmut Brandt 			    asn_oid2str_r(&ctx->dep->obj, objbuf),
623f06ca4afSHartmut Brandt 			    asn_oid2str_r(&ctx->dep->idx, idxbuf));
624f06ca4afSHartmut Brandt 			if (ret1 == SNMP_ERR_NOERROR)
625f06ca4afSHartmut Brandt 				ret1 = ret;
626f06ca4afSHartmut Brandt 		}
627f06ca4afSHartmut Brandt 	}
628f06ca4afSHartmut Brandt 	return (ret1);
629f06ca4afSHartmut Brandt }
630f06ca4afSHartmut Brandt 
6318eecd77aSHartmut Brandt void
6328eecd77aSHartmut Brandt snmp_dep_finish(struct snmp_context *ctx)
6338eecd77aSHartmut Brandt {
6348eecd77aSHartmut Brandt 	struct context *context = (struct context *)ctx;
6358eecd77aSHartmut Brandt 	struct depend *d;
6368eecd77aSHartmut Brandt 
6378eecd77aSHartmut Brandt 	while ((d = TAILQ_FIRST(&context->dlist)) != NULL) {
6388eecd77aSHartmut Brandt 		ctx->dep = &d->dep;
6398eecd77aSHartmut Brandt 		(void)d->func(ctx, ctx->dep, SNMP_DEPOP_FINISH);
6408eecd77aSHartmut Brandt 		TAILQ_REMOVE(&context->dlist, d, link);
6418eecd77aSHartmut Brandt 		free(d);
6428eecd77aSHartmut Brandt 	}
6438eecd77aSHartmut Brandt }
6448eecd77aSHartmut Brandt 
645f06ca4afSHartmut Brandt /*
646f06ca4afSHartmut Brandt  * Do a SET operation.
647f06ca4afSHartmut Brandt  */
648f06ca4afSHartmut Brandt enum snmp_ret
649f06ca4afSHartmut Brandt snmp_set(struct snmp_pdu *pdu, struct asn_buf *resp_b,
650f06ca4afSHartmut Brandt     struct snmp_pdu *resp, void *data)
651f06ca4afSHartmut Brandt {
652f06ca4afSHartmut Brandt 	int ret;
653f06ca4afSHartmut Brandt 	u_int i;
654f06ca4afSHartmut Brandt 	enum asn_err asnerr;
655f06ca4afSHartmut Brandt 	struct context context;
656f06ca4afSHartmut Brandt 	const struct snmp_node *np;
657f06ca4afSHartmut Brandt 	struct snmp_value *b;
658f06ca4afSHartmut Brandt 	enum snmp_syntax except;
659f06ca4afSHartmut Brandt 
660f06ca4afSHartmut Brandt 	memset(&context, 0, sizeof(context));
661f06ca4afSHartmut Brandt 	TAILQ_INIT(&context.dlist);
662f06ca4afSHartmut Brandt 	context.ctx.data = data;
663f06ca4afSHartmut Brandt 
664*135f7de5SShteryana Shopova 	snmp_pdu_create_response(pdu, resp);
665f06ca4afSHartmut Brandt 
666f06ca4afSHartmut Brandt 	if (snmp_pdu_encode_header(resp_b, resp))
667f06ca4afSHartmut Brandt 		return (SNMP_RET_IGN);
668f06ca4afSHartmut Brandt 
669f06ca4afSHartmut Brandt 	/*
670f06ca4afSHartmut Brandt 	 * 1. Find all nodes, check that they are writeable and
671f06ca4afSHartmut Brandt 	 *    that the syntax is ok, copy over the binding to the response.
672f06ca4afSHartmut Brandt 	 */
673f06ca4afSHartmut Brandt 	for (i = 0; i < pdu->nbindings; i++) {
674f06ca4afSHartmut Brandt 		b = &pdu->bindings[i];
675f06ca4afSHartmut Brandt 
676f06ca4afSHartmut Brandt 		if ((np = context.node[i] = find_node(b, &except)) == NULL) {
677f06ca4afSHartmut Brandt 			/* not found altogether or LEAF with wrong index */
678f06ca4afSHartmut Brandt 			if (TR(SET))
679f06ca4afSHartmut Brandt 				snmp_debug("set: node not found %s",
680f06ca4afSHartmut Brandt 				    asn_oid2str_r(&b->var, oidbuf));
681f06ca4afSHartmut Brandt 			if (pdu->version == SNMP_V1) {
682f06ca4afSHartmut Brandt 				pdu->error_index = i + 1;
683f06ca4afSHartmut Brandt 				pdu->error_status = SNMP_ERR_NOSUCHNAME;
684f06ca4afSHartmut Brandt 			} else if ((np = find_subnode(b)) != NULL) {
685f06ca4afSHartmut Brandt 				/* 2. intermediate object */
686f06ca4afSHartmut Brandt 				pdu->error_index = i + 1;
687f06ca4afSHartmut Brandt 				pdu->error_status = SNMP_ERR_NOT_WRITEABLE;
688f06ca4afSHartmut Brandt 			} else if (except == SNMP_SYNTAX_NOSUCHOBJECT) {
689f06ca4afSHartmut Brandt 				pdu->error_index = i + 1;
690f06ca4afSHartmut Brandt 				pdu->error_status = SNMP_ERR_NO_ACCESS;
691f06ca4afSHartmut Brandt 			} else {
692f06ca4afSHartmut Brandt 				pdu->error_index = i + 1;
693f06ca4afSHartmut Brandt 				pdu->error_status = SNMP_ERR_NO_CREATION;
694f06ca4afSHartmut Brandt 			}
695f06ca4afSHartmut Brandt 			snmp_pdu_free(resp);
696f06ca4afSHartmut Brandt 			return (SNMP_RET_ERR);
697f06ca4afSHartmut Brandt 		}
698f06ca4afSHartmut Brandt 		/*
699f06ca4afSHartmut Brandt 		 * 2. write/createable?
700f06ca4afSHartmut Brandt 		 * Can check this for leafs only, because in v2 we have
701f06ca4afSHartmut Brandt 		 * to differentiate between NOT_WRITEABLE and NO_CREATION
702f06ca4afSHartmut Brandt 		 * and only the action routine for COLUMNS knows, whether
703f06ca4afSHartmut Brandt 		 * a column exists.
704f06ca4afSHartmut Brandt 		 */
705f06ca4afSHartmut Brandt 		if (np->type == SNMP_NODE_LEAF &&
706f06ca4afSHartmut Brandt 		    !(np->flags & SNMP_NODE_CANSET)) {
707f06ca4afSHartmut Brandt 			if (pdu->version == SNMP_V1) {
708f06ca4afSHartmut Brandt 				pdu->error_index = i + 1;
709f06ca4afSHartmut Brandt 				pdu->error_status = SNMP_ERR_NOSUCHNAME;
710f06ca4afSHartmut Brandt 			} else {
711f06ca4afSHartmut Brandt 				pdu->error_index = i + 1;
712f06ca4afSHartmut Brandt 				pdu->error_status = SNMP_ERR_NOT_WRITEABLE;
713f06ca4afSHartmut Brandt 			}
714f06ca4afSHartmut Brandt 			snmp_pdu_free(resp);
715f06ca4afSHartmut Brandt 			return (SNMP_RET_ERR);
716f06ca4afSHartmut Brandt 		}
717f06ca4afSHartmut Brandt 		/*
718f06ca4afSHartmut Brandt 		 * 3. Ensure the right syntax
719f06ca4afSHartmut Brandt 		 */
720f06ca4afSHartmut Brandt 		if (np->syntax != b->syntax) {
721f06ca4afSHartmut Brandt 			if (pdu->version == SNMP_V1) {
722f06ca4afSHartmut Brandt 				pdu->error_index = i + 1;
723f06ca4afSHartmut Brandt 				pdu->error_status = SNMP_ERR_BADVALUE; /* v2: wrongType */
724f06ca4afSHartmut Brandt 			} else {
725f06ca4afSHartmut Brandt 				pdu->error_index = i + 1;
726f06ca4afSHartmut Brandt 				pdu->error_status = SNMP_ERR_WRONG_TYPE;
727f06ca4afSHartmut Brandt 			}
728f06ca4afSHartmut Brandt 			snmp_pdu_free(resp);
729f06ca4afSHartmut Brandt 			return (SNMP_RET_ERR);
730f06ca4afSHartmut Brandt 		}
731f06ca4afSHartmut Brandt 		/*
732f06ca4afSHartmut Brandt 		 * 4. Copy binding
733f06ca4afSHartmut Brandt 		 */
734f06ca4afSHartmut Brandt 		if (snmp_value_copy(&resp->bindings[i], b)) {
735f06ca4afSHartmut Brandt 			pdu->error_index = i + 1;
736f06ca4afSHartmut Brandt 			pdu->error_status = SNMP_ERR_GENERR;
737f06ca4afSHartmut Brandt 			snmp_pdu_free(resp);
738f06ca4afSHartmut Brandt 			return (SNMP_RET_ERR);
739f06ca4afSHartmut Brandt 		}
740f06ca4afSHartmut Brandt 		asnerr = snmp_binding_encode(resp_b, &resp->bindings[i]);
741f06ca4afSHartmut Brandt 		if (asnerr == ASN_ERR_EOBUF) {
742f06ca4afSHartmut Brandt 			pdu->error_index = i + 1;
743f06ca4afSHartmut Brandt 			pdu->error_status = SNMP_ERR_TOOBIG;
744f06ca4afSHartmut Brandt 			snmp_pdu_free(resp);
745f06ca4afSHartmut Brandt 			return (SNMP_RET_ERR);
746f06ca4afSHartmut Brandt 		} else if (asnerr != ASN_ERR_OK) {
747f06ca4afSHartmut Brandt 			pdu->error_index = i + 1;
748f06ca4afSHartmut Brandt 			pdu->error_status = SNMP_ERR_GENERR;
749f06ca4afSHartmut Brandt 			snmp_pdu_free(resp);
750f06ca4afSHartmut Brandt 			return (SNMP_RET_ERR);
751f06ca4afSHartmut Brandt 		}
752f06ca4afSHartmut Brandt 		resp->nbindings++;
753f06ca4afSHartmut Brandt 	}
754f06ca4afSHartmut Brandt 
7558eecd77aSHartmut Brandt 	context.ctx.code = SNMP_RET_OK;
756f06ca4afSHartmut Brandt 
757f06ca4afSHartmut Brandt 	/*
758f06ca4afSHartmut Brandt 	 * 2. Call the SET method for each node. If a SET fails, rollback
759f06ca4afSHartmut Brandt 	 *    everything. Map error codes depending on the version.
760f06ca4afSHartmut Brandt 	 */
761f06ca4afSHartmut Brandt 	for (i = 0; i < pdu->nbindings; i++) {
762f06ca4afSHartmut Brandt 		b = &pdu->bindings[i];
763f06ca4afSHartmut Brandt 		np = context.node[i];
764f06ca4afSHartmut Brandt 
765f06ca4afSHartmut Brandt 		context.ctx.var_index = i + 1;
766f06ca4afSHartmut Brandt 		context.ctx.scratch = &context.scratch[i];
767f06ca4afSHartmut Brandt 
768f06ca4afSHartmut Brandt 		ret = (*np->op)(&context.ctx, b, np->oid.len, np->index,
769f06ca4afSHartmut Brandt 		    SNMP_OP_SET);
770f06ca4afSHartmut Brandt 
771f06ca4afSHartmut Brandt 		if (TR(SET))
772f06ca4afSHartmut Brandt 			snmp_debug("set: action %s returns %d", np->name, ret);
773f06ca4afSHartmut Brandt 
774f06ca4afSHartmut Brandt 		if (pdu->version == SNMP_V1) {
775f06ca4afSHartmut Brandt 			switch (ret) {
776f06ca4afSHartmut Brandt 			  case SNMP_ERR_NO_ACCESS:
777f06ca4afSHartmut Brandt 				ret = SNMP_ERR_NOSUCHNAME;
778f06ca4afSHartmut Brandt 				break;
779f06ca4afSHartmut Brandt 			  case SNMP_ERR_WRONG_TYPE:
780f06ca4afSHartmut Brandt 				/* should no happen */
781f06ca4afSHartmut Brandt 				ret = SNMP_ERR_BADVALUE;
782f06ca4afSHartmut Brandt 				break;
783f06ca4afSHartmut Brandt 			  case SNMP_ERR_WRONG_LENGTH:
784f06ca4afSHartmut Brandt 				ret = SNMP_ERR_BADVALUE;
785f06ca4afSHartmut Brandt 				break;
786f06ca4afSHartmut Brandt 			  case SNMP_ERR_WRONG_ENCODING:
787f06ca4afSHartmut Brandt 				/* should not happen */
788f06ca4afSHartmut Brandt 				ret = SNMP_ERR_BADVALUE;
789f06ca4afSHartmut Brandt 				break;
790f06ca4afSHartmut Brandt 			  case SNMP_ERR_WRONG_VALUE:
791f06ca4afSHartmut Brandt 				ret = SNMP_ERR_BADVALUE;
792f06ca4afSHartmut Brandt 				break;
793f06ca4afSHartmut Brandt 			  case SNMP_ERR_NO_CREATION:
794f06ca4afSHartmut Brandt 				ret = SNMP_ERR_NOSUCHNAME;
795f06ca4afSHartmut Brandt 				break;
796f06ca4afSHartmut Brandt 			  case SNMP_ERR_INCONS_VALUE:
797f06ca4afSHartmut Brandt 				ret = SNMP_ERR_BADVALUE;
798f06ca4afSHartmut Brandt 				break;
799f06ca4afSHartmut Brandt 			  case SNMP_ERR_RES_UNAVAIL:
800f06ca4afSHartmut Brandt 				ret = SNMP_ERR_GENERR;
801f06ca4afSHartmut Brandt 				break;
802f06ca4afSHartmut Brandt 			  case SNMP_ERR_COMMIT_FAILED:
803f06ca4afSHartmut Brandt 				ret = SNMP_ERR_GENERR;
804f06ca4afSHartmut Brandt 				break;
805f06ca4afSHartmut Brandt 			  case SNMP_ERR_UNDO_FAILED:
806f06ca4afSHartmut Brandt 				ret = SNMP_ERR_GENERR;
807f06ca4afSHartmut Brandt 				break;
808f06ca4afSHartmut Brandt 			  case SNMP_ERR_AUTH_ERR:
809f06ca4afSHartmut Brandt 				/* should not happen */
810f06ca4afSHartmut Brandt 				ret = SNMP_ERR_GENERR;
811f06ca4afSHartmut Brandt 				break;
812f06ca4afSHartmut Brandt 			  case SNMP_ERR_NOT_WRITEABLE:
813f06ca4afSHartmut Brandt 				ret = SNMP_ERR_NOSUCHNAME;
814f06ca4afSHartmut Brandt 				break;
815f06ca4afSHartmut Brandt 			  case SNMP_ERR_INCONS_NAME:
816f06ca4afSHartmut Brandt 				ret = SNMP_ERR_BADVALUE;
817f06ca4afSHartmut Brandt 				break;
818f06ca4afSHartmut Brandt 			}
819f06ca4afSHartmut Brandt 		}
820f06ca4afSHartmut Brandt 		if (ret != SNMP_ERR_NOERROR) {
821f06ca4afSHartmut Brandt 			pdu->error_index = i + 1;
822f06ca4afSHartmut Brandt 			pdu->error_status = ret;
823f06ca4afSHartmut Brandt 
824f06ca4afSHartmut Brandt 			rollback(&context, pdu, i);
825f06ca4afSHartmut Brandt 			snmp_pdu_free(resp);
826f06ca4afSHartmut Brandt 
8278eecd77aSHartmut Brandt 			context.ctx.code = SNMP_RET_ERR;
828f06ca4afSHartmut Brandt 
829f06ca4afSHartmut Brandt 			goto errout;
830f06ca4afSHartmut Brandt 		}
831f06ca4afSHartmut Brandt 	}
832f06ca4afSHartmut Brandt 
833f06ca4afSHartmut Brandt 	/*
834f06ca4afSHartmut Brandt 	 * 3. Call dependencies
835f06ca4afSHartmut Brandt 	 */
836f06ca4afSHartmut Brandt 	if (TR(SET))
837f06ca4afSHartmut Brandt 		snmp_debug("set: set operations ok");
838f06ca4afSHartmut Brandt 
839f06ca4afSHartmut Brandt 	if ((ret = snmp_dep_commit(&context.ctx)) != SNMP_ERR_NOERROR) {
840f06ca4afSHartmut Brandt 		pdu->error_status = ret;
841f06ca4afSHartmut Brandt 		pdu->error_index = context.ctx.var_index;
842f06ca4afSHartmut Brandt 
843f06ca4afSHartmut Brandt 		if ((ret = snmp_dep_rollback(&context.ctx)) != SNMP_ERR_NOERROR) {
844f06ca4afSHartmut Brandt 			if (pdu->version != SNMP_V1) {
845f06ca4afSHartmut Brandt 				pdu->error_status = SNMP_ERR_UNDO_FAILED;
846f06ca4afSHartmut Brandt 				pdu->error_index = 0;
847f06ca4afSHartmut Brandt 			}
848f06ca4afSHartmut Brandt 		}
849f06ca4afSHartmut Brandt 		rollback(&context, pdu, i);
850f06ca4afSHartmut Brandt 		snmp_pdu_free(resp);
851f06ca4afSHartmut Brandt 
8528eecd77aSHartmut Brandt 		context.ctx.code = SNMP_RET_ERR;
853f06ca4afSHartmut Brandt 
854f06ca4afSHartmut Brandt 		goto errout;
855f06ca4afSHartmut Brandt 	}
856f06ca4afSHartmut Brandt 
857f06ca4afSHartmut Brandt 	/*
858f06ca4afSHartmut Brandt 	 * 4. Commit and copy values from the original packet to the response.
859f06ca4afSHartmut Brandt 	 *    This is not the commit operation from RFC 1905 but rather an
860f06ca4afSHartmut Brandt 	 *    'FREE RESOURCES' operation. It shouldn't fail.
861f06ca4afSHartmut Brandt 	 */
862f06ca4afSHartmut Brandt 	if (TR(SET))
863f06ca4afSHartmut Brandt 		snmp_debug("set: commiting");
864f06ca4afSHartmut Brandt 
865f06ca4afSHartmut Brandt 	for (i = 0; i < pdu->nbindings; i++) {
866f06ca4afSHartmut Brandt 		b = &resp->bindings[i];
867f06ca4afSHartmut Brandt 		np = context.node[i];
868f06ca4afSHartmut Brandt 
869f06ca4afSHartmut Brandt 		context.ctx.var_index = i + 1;
870f06ca4afSHartmut Brandt 		context.ctx.scratch = &context.scratch[i];
871f06ca4afSHartmut Brandt 
872f06ca4afSHartmut Brandt 		ret = (*np->op)(&context.ctx, b, np->oid.len, np->index,
873f06ca4afSHartmut Brandt 		    SNMP_OP_COMMIT);
874f06ca4afSHartmut Brandt 
875f06ca4afSHartmut Brandt 		if (ret != SNMP_ERR_NOERROR)
876f06ca4afSHartmut Brandt 			snmp_error("set: commit failed (%d) on"
877f06ca4afSHartmut Brandt 			    " variable %s index %u", ret,
878f06ca4afSHartmut Brandt 			    asn_oid2str_r(&b->var, oidbuf), i);
879f06ca4afSHartmut Brandt 	}
880f06ca4afSHartmut Brandt 
881f06ca4afSHartmut Brandt 	if (snmp_fix_encoding(resp_b, resp) != SNMP_CODE_OK) {
882f06ca4afSHartmut Brandt 		snmp_error("set: fix_encoding failed");
883f06ca4afSHartmut Brandt 		snmp_pdu_free(resp);
8848eecd77aSHartmut Brandt 		context.ctx.code = SNMP_RET_IGN;
885f06ca4afSHartmut Brandt 	}
886f06ca4afSHartmut Brandt 
887f06ca4afSHartmut Brandt 	/*
888f06ca4afSHartmut Brandt 	 * Done
889f06ca4afSHartmut Brandt 	 */
890f06ca4afSHartmut Brandt   errout:
8918eecd77aSHartmut Brandt 	snmp_dep_finish(&context.ctx);
892f06ca4afSHartmut Brandt 
893f06ca4afSHartmut Brandt 	if (TR(SET))
8948eecd77aSHartmut Brandt 		snmp_debug("set: returning %d", context.ctx.code);
895f06ca4afSHartmut Brandt 
8968eecd77aSHartmut Brandt 	return (context.ctx.code);
897f06ca4afSHartmut Brandt }
898f06ca4afSHartmut Brandt /*
899f06ca4afSHartmut Brandt  * Lookup a dependency. If it doesn't exist, create one
900f06ca4afSHartmut Brandt  */
901f06ca4afSHartmut Brandt struct snmp_dependency *
902f06ca4afSHartmut Brandt snmp_dep_lookup(struct snmp_context *ctx, const struct asn_oid *obj,
903f06ca4afSHartmut Brandt     const struct asn_oid *idx, size_t len, snmp_depop_t func)
904f06ca4afSHartmut Brandt {
905f06ca4afSHartmut Brandt 	struct context *context;
906f06ca4afSHartmut Brandt 	struct depend *d;
907f06ca4afSHartmut Brandt 
908f06ca4afSHartmut Brandt 	context = (struct context *)(void *)
909f06ca4afSHartmut Brandt 	    ((char *)ctx - offsetof(struct context, ctx));
910f06ca4afSHartmut Brandt 	if (TR(DEPEND)) {
911f06ca4afSHartmut Brandt 		snmp_debug("depend: looking for %s", asn_oid2str(obj));
912f06ca4afSHartmut Brandt 		if (idx)
913f06ca4afSHartmut Brandt 			snmp_debug("depend: index is %s", asn_oid2str(idx));
914f06ca4afSHartmut Brandt 	}
915f06ca4afSHartmut Brandt 	TAILQ_FOREACH(d, &context->dlist, link)
916f06ca4afSHartmut Brandt 		if (asn_compare_oid(obj, &d->dep.obj) == 0 &&
917f06ca4afSHartmut Brandt 		    ((idx == NULL && d->dep.idx.len == 0) ||
918f06ca4afSHartmut Brandt 		     (idx != NULL && asn_compare_oid(idx, &d->dep.idx) == 0))) {
919f06ca4afSHartmut Brandt 			if(TR(DEPEND))
920f06ca4afSHartmut Brandt 				snmp_debug("depend: found");
921f06ca4afSHartmut Brandt 			return (&d->dep);
922f06ca4afSHartmut Brandt 		}
923f06ca4afSHartmut Brandt 
924f06ca4afSHartmut Brandt 	if(TR(DEPEND))
925f06ca4afSHartmut Brandt 		snmp_debug("depend: creating");
926f06ca4afSHartmut Brandt 
927f06ca4afSHartmut Brandt 	if ((d = malloc(offsetof(struct depend, dep) + len)) == NULL)
928f06ca4afSHartmut Brandt 		return (NULL);
929f06ca4afSHartmut Brandt 	memset(&d->dep, 0, len);
930f06ca4afSHartmut Brandt 
931f06ca4afSHartmut Brandt 	d->dep.obj = *obj;
932f06ca4afSHartmut Brandt 	if (idx == NULL)
933f06ca4afSHartmut Brandt 		d->dep.idx.len = 0;
934f06ca4afSHartmut Brandt 	else
935f06ca4afSHartmut Brandt 		d->dep.idx = *idx;
936f06ca4afSHartmut Brandt 	d->len = len;
937f06ca4afSHartmut Brandt 	d->func = func;
938f06ca4afSHartmut Brandt 
939f06ca4afSHartmut Brandt 	TAILQ_INSERT_TAIL(&context->dlist, d, link);
940f06ca4afSHartmut Brandt 
941f06ca4afSHartmut Brandt 	return (&d->dep);
942f06ca4afSHartmut Brandt }
943f06ca4afSHartmut Brandt 
944f06ca4afSHartmut Brandt /*
945f06ca4afSHartmut Brandt  * Make an error response from a PDU. We do this without decoding the
946f06ca4afSHartmut Brandt  * variable bindings. This means we can sent the junk back to a caller
947f06ca4afSHartmut Brandt  * that has sent us junk in the first place.
948f06ca4afSHartmut Brandt  */
949f06ca4afSHartmut Brandt enum snmp_ret
950f06ca4afSHartmut Brandt snmp_make_errresp(const struct snmp_pdu *pdu, struct asn_buf *pdu_b,
951f06ca4afSHartmut Brandt     struct asn_buf *resp_b)
952f06ca4afSHartmut Brandt {
953f06ca4afSHartmut Brandt 	asn_len_t len;
954f06ca4afSHartmut Brandt 	struct snmp_pdu resp;
955f06ca4afSHartmut Brandt 	enum asn_err err;
956f06ca4afSHartmut Brandt 	enum snmp_code code;
957f06ca4afSHartmut Brandt 
958f06ca4afSHartmut Brandt 	memset(&resp, 0, sizeof(resp));
959*135f7de5SShteryana Shopova 	if ((code = snmp_pdu_decode_header(pdu_b, &resp)) != SNMP_CODE_OK)
960f06ca4afSHartmut Brandt 		return (SNMP_RET_IGN);
961f06ca4afSHartmut Brandt 
962f06ca4afSHartmut Brandt 	if (pdu_b->asn_len < len)
963f06ca4afSHartmut Brandt 		return (SNMP_RET_IGN);
964f06ca4afSHartmut Brandt 	pdu_b->asn_len = len;
965f06ca4afSHartmut Brandt 
966f06ca4afSHartmut Brandt 	err = snmp_parse_pdus_hdr(pdu_b, &resp, &len);
967f06ca4afSHartmut Brandt 	if (ASN_ERR_STOPPED(err))
968f06ca4afSHartmut Brandt 		return (SNMP_RET_IGN);
969f06ca4afSHartmut Brandt 	if (pdu_b->asn_len < len)
970f06ca4afSHartmut Brandt 		return (SNMP_RET_IGN);
971f06ca4afSHartmut Brandt 	pdu_b->asn_len = len;
972f06ca4afSHartmut Brandt 
973f06ca4afSHartmut Brandt 	/* now we have the bindings left - construct new message */
974f06ca4afSHartmut Brandt 	resp.error_status = pdu->error_status;
975f06ca4afSHartmut Brandt 	resp.error_index = pdu->error_index;
976f06ca4afSHartmut Brandt 	resp.type = SNMP_PDU_RESPONSE;
977f06ca4afSHartmut Brandt 
978f06ca4afSHartmut Brandt 	code = snmp_pdu_encode_header(resp_b, &resp);
979f06ca4afSHartmut Brandt 	if (code != SNMP_CODE_OK)
980f06ca4afSHartmut Brandt 		return (SNMP_RET_IGN);
981f06ca4afSHartmut Brandt 
982f06ca4afSHartmut Brandt 	if (pdu_b->asn_len > resp_b->asn_len)
983f06ca4afSHartmut Brandt 		/* too short */
984f06ca4afSHartmut Brandt 		return (SNMP_RET_IGN);
985f06ca4afSHartmut Brandt 	(void)memcpy(resp_b->asn_ptr, pdu_b->asn_cptr, pdu_b->asn_len);
986f06ca4afSHartmut Brandt 	resp_b->asn_len -= pdu_b->asn_len;
987f06ca4afSHartmut Brandt 	resp_b->asn_ptr += pdu_b->asn_len;
988f06ca4afSHartmut Brandt 
989f06ca4afSHartmut Brandt 	code = snmp_fix_encoding(resp_b, &resp);
990f06ca4afSHartmut Brandt 	if (code != SNMP_CODE_OK)
991f06ca4afSHartmut Brandt 		return (SNMP_RET_IGN);
992f06ca4afSHartmut Brandt 
993f06ca4afSHartmut Brandt 	return (SNMP_RET_OK);
994f06ca4afSHartmut Brandt }
995f06ca4afSHartmut Brandt 
996f06ca4afSHartmut Brandt static void
997f06ca4afSHartmut Brandt snmp_debug_func(const char *fmt, ...)
998f06ca4afSHartmut Brandt {
999f06ca4afSHartmut Brandt 	va_list ap;
1000f06ca4afSHartmut Brandt 
1001f06ca4afSHartmut Brandt 	va_start(ap, fmt);
1002f06ca4afSHartmut Brandt 	vfprintf(stderr, fmt, ap);
1003f06ca4afSHartmut Brandt 	va_end(ap);
1004f06ca4afSHartmut Brandt 	fprintf(stderr, "\n");
1005f06ca4afSHartmut Brandt }
1006