forked from twsnmp/gosnmp
-
Notifications
You must be signed in to change notification settings - Fork 0
/
trap.go
404 lines (345 loc) · 11 KB
/
trap.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
// Copyright 2012-2020 The GoSNMP Authors. All rights reserved. Use of this
// source code is governed by a BSD-style license that can be found in the
// LICENSE file.
package gosnmp
import (
"fmt"
"net"
"os"
"strings"
"sync"
"sync/atomic"
"time"
)
//
// Sending Traps ie GoSNMP acting as an Agent
//
// SendTrap sends a SNMP Trap (v2c/v3 only)
//
// pdus[0] can a pdu of Type TimeTicks (with the desired uint32 epoch
// time). Otherwise a TimeTicks pdu will be prepended, with time set to
// now. This mirrors the behaviour of the Net-SNMP command-line tools.
//
// SendTrap doesn't wait for a return packet from the NMS (Network
// Management Station).
//
// See also Listen() and examples for creating an NMS.
//
// NOTE: the trap code is currently unreliable when working with snmpv3 - pull requests welcome
func (x *GoSNMP) SendTrap(trap SnmpTrap) (result *SnmpPacket, err error) {
var pdutype PDUType
if len(trap.Variables) == 0 {
return nil, fmt.Errorf("function SendTrap requires at least 1 PDU")
}
if trap.Variables[0].Type == TimeTicks {
// check is uint32
if _, ok := trap.Variables[0].Value.(uint32); !ok {
return nil, fmt.Errorf("function SendTrap TimeTick must be uint32")
}
}
switch x.Version {
case Version2c, Version3:
// Default to a v2 trap.
pdutype = SNMPv2Trap
// If it's an inform, do that instead.
if trap.IsInform {
pdutype = InformRequest
}
if trap.Variables[0].Type != TimeTicks {
now := uint32(time.Now().Unix())
timetickPDU := SnmpPDU{"1.3.6.1.2.1.1.3.0", TimeTicks, now}
// prepend timetickPDU
trap.Variables = append([]SnmpPDU{timetickPDU}, trap.Variables...)
}
case Version1:
pdutype = Trap
if len(trap.Enterprise) == 0 {
return nil, fmt.Errorf("function SendTrap for SNMPV1 requires an Enterprise OID")
}
if len(trap.AgentAddress) == 0 {
return nil, fmt.Errorf("function SendTrap for SNMPV1 requires an Agent Address")
}
default:
err = fmt.Errorf("function SendTrap doesn't support %s", x.Version)
return nil, err
}
packetOut := x.mkSnmpPacket(pdutype, trap.Variables, 0, 0)
if x.Version == Version1 {
packetOut.Enterprise = trap.Enterprise
packetOut.AgentAddress = trap.AgentAddress
packetOut.GenericTrap = trap.GenericTrap
packetOut.SpecificTrap = trap.SpecificTrap
packetOut.Timestamp = trap.Timestamp
}
snmpOutPkts++
snmpOutTraps++
// all sends wait for the return packet, except for SNMPv2Trap
// -> wait is only for informs
return x.send(packetOut, trap.IsInform)
}
//
// Receiving Traps ie GoSNMP acting as an NMS (Network Management
// Station).
//
// GoSNMP.unmarshal() currently only handles SNMPv2Trap
//
// A TrapListener defines parameters for running a SNMP Trap receiver.
// nil values will be replaced by default values.
type TrapListener struct {
sync.Mutex
// Params is a reference to the TrapListener's "parent" GoSNMP instance.
Params *GoSNMP
// OnNewTrap handles incoming Trap and Inform PDUs.
OnNewTrap TrapHandlerFunc
// These unexported fields are for letting test cases
// know we are ready.
conn *net.UDPConn
proto string
finish int32 // Atomic flag; set to 1 when closing connection
done chan bool
listening chan bool
}
// TrapHandlerFunc is a callback function type which receives SNMP Trap and
// Inform packets when they are received. If this callback is null, Trap and
// Inform PDUs will not be received (Inform responses will still be sent,
// however). This callback should not modify the contents of the SnmpPacket
// nor the UDPAddr passed to it, and it should copy out any values it wishes to
// use instead of retaining references in order to avoid memory fragmentation.
//
// The general effect of received Trap and Inform packets do not differ for the
// receiver, and the response is handled by the caller of the handler, so there
// is no need for the application to handle Informs any different than Traps.
// Nonetheless, the packet's Type field can be examined to determine what type
// of event this is for e.g. statistics gathering functions, etc.
type TrapHandlerFunc func(s *SnmpPacket, u *net.UDPAddr)
// NewTrapListener returns an initialized TrapListener.
//
// NOTE: the trap code is currently unreliable when working with snmpv3 - pull requests welcome
func NewTrapListener() *TrapListener {
tl := &TrapListener{
finish: 0,
done: make(chan bool),
// Buffered because one doesn't have to block on it.
listening: make(chan bool, 1),
}
return tl
}
// Listening returns a sentinel channel on which one can block
// until the listener is ready to receive requests.
//
// NOTE: the trap code is currently unreliable when working with snmpv3 - pull requests welcome
func (t *TrapListener) Listening() <-chan bool {
t.Lock()
defer t.Unlock()
return t.listening
}
// Close terminates the listening on TrapListener socket
//
// NOTE: the trap code is currently unreliable when working with snmpv3 - pull requests welcome
func (t *TrapListener) Close() {
// Prevent concurrent calls to Close
if atomic.CompareAndSwapInt32(&t.finish, 0, 1) {
// TODO there's bugs here
if t.conn == nil {
return
}
if t.conn.LocalAddr().Network() == udp {
t.conn.Close()
}
<-t.done
}
}
func (t *TrapListener) listenUDP(addr string) error {
// udp
udpAddr, err := net.ResolveUDPAddr(t.proto, addr)
if err != nil {
return err
}
t.conn, err = net.ListenUDP(udp, udpAddr)
if err != nil {
return err
}
defer t.conn.Close()
// Mark that we are listening now.
t.listening <- true
for {
switch {
case atomic.LoadInt32(&t.finish) == 1:
t.done <- true
return nil
default:
var buf [4096]byte
rlen, remote, err := t.conn.ReadFromUDP(buf[:])
if err != nil {
if atomic.LoadInt32(&t.finish) == 1 {
// err most likely comes from reading from a closed connection
continue
}
t.Params.logPrintf("TrapListener: error in read %s\n", err)
continue
}
msg := buf[:rlen]
traps := t.Params.UnmarshalTrap(msg, false)
if traps != nil {
// Here we assume that t.OnNewTrap will not alter the contents
// of the PDU (per documentation, because Go does not have
// compile-time const checking). We don't pass a copy because
// the SnmpPacket type is somewhat large, but we could without
// violating any implicit or explicit spec.
t.OnNewTrap(traps, remote)
// If it was an Inform request, we need to send a response.
if traps.PDUType == InformRequest { //nolint:whitespace
// Reuse the packet, since we're supposed to send it back
// with the exact same variables unless there's an error.
// Change the PDUType to the response, though.
traps.PDUType = GetResponse
// If the response can be sent, the error-status is
// supposed to be set to noError and the error-index set to
// zero.
traps.Error = NoError
traps.ErrorIndex = 0
// TODO: Check that the message marshalled is not too large
// for the originator to accept and if so, send a tooBig
// error PDU per RFC3416 section 4.2.7. This maximum size,
// however, does not have a well-defined mechanism in the
// RFC other than using the path MTU (which is difficult to
// determine), so it's left to future implementations.
ob, err := traps.marshalMsg()
if err != nil {
return fmt.Errorf("error marshaling INFORM response: %v", err)
}
// Send the return packet back.
count, err := t.conn.WriteTo(ob, remote)
if err != nil {
return fmt.Errorf("error sending INFORM response: %v", err)
}
// This isn't fatal, but should be logged.
if count != len(ob) {
t.Params.logPrintf("Failed to send all bytes of INFORM response!\n")
}
}
}
}
}
}
func (t *TrapListener) handleTCPRequest(conn net.Conn) {
// Make a buffer to hold incoming data.
buf := make([]byte, 4096)
// Read the incoming connection into the buffer.
reqLen, err := conn.Read(buf)
if err != nil {
t.Params.logPrintf("TrapListener: error in read %s\n", err)
return
}
//fmt.Printf("TEST: handleTCPRequest:%s, %s", t.proto, conn.RemoteAddr())
msg := buf[:reqLen]
traps := t.Params.UnmarshalTrap(msg, false)
if traps != nil {
// TODO: lying for backward compatibility reason - create UDP Address ... not nice
r, _ := net.ResolveUDPAddr("", conn.RemoteAddr().String())
t.OnNewTrap(traps, r)
}
// Close the connection when you're done with it.
conn.Close()
}
func (t *TrapListener) listenTCP(addr string) error {
tcpAddr, err := net.ResolveTCPAddr(t.proto, addr)
if err != nil {
return err
}
l, err := net.ListenTCP("tcp", tcpAddr)
if err != nil {
return err
}
defer l.Close()
// Mark that we are listening now.
t.listening <- true
for {
switch {
case atomic.LoadInt32(&t.finish) == 1:
t.done <- true
return nil
default:
// Listen for an incoming connection.
conn, err := l.Accept()
fmt.Printf("ACCEPT: %s", conn)
if err != nil {
fmt.Println("error accepting: ", err.Error())
os.Exit(1)
}
// Handle connections in a new goroutine.
go t.handleTCPRequest(conn)
}
}
}
// Listen listens on the UDP address addr and calls the OnNewTrap
// function specified in *TrapListener for every trap received.
//
// NOTE: the trap code is currently unreliable when working with snmpv3 - pull requests welcome
func (t *TrapListener) Listen(addr string) error {
if t.Params == nil {
t.Params = Default
}
// TODO TODO returning an error cause the following to hang/break
// TestSendTrapBasic
// TestSendTrapWithoutWaitingOnListen
// TestSendV1Trap
_ = t.Params.validateParameters()
if t.OnNewTrap == nil {
t.OnNewTrap = t.debugTrapHandler
}
splitted := strings.SplitN(addr, "://", 2)
t.proto = udp
if len(splitted) > 1 {
t.proto = splitted[0]
addr = splitted[1]
}
if t.proto == "tcp" {
return t.listenTCP(addr)
} else if t.proto == udp {
return t.listenUDP(addr)
}
return fmt.Errorf("not implemented network protocol: %s [use: tcp/udp]", t.proto)
}
// Default trap handler
func (t *TrapListener) debugTrapHandler(s *SnmpPacket, u *net.UDPAddr) {
t.Params.logPrintf("got trapdata from %+v: %+v\n", u, s)
}
// UnmarshalTrap unpacks the SNMP Trap.
//
// NOTE: the trap code is currently unreliable when working with snmpv3 - pull requests welcome
func (x *GoSNMP) UnmarshalTrap(trap []byte, useResponseSecurityParameters bool) (result *SnmpPacket) {
result = new(SnmpPacket)
if x.SecurityParameters != nil {
err := x.SecurityParameters.initSecurityKeys()
if err != nil {
return nil
}
result.SecurityParameters = x.SecurityParameters.Copy()
}
cursor, err := x.unmarshalHeader(trap, result)
if err != nil {
x.logPrintf("UnmarshalTrap: %s\n", err)
return nil
}
if result.Version == Version3 {
if result.SecurityModel == UserSecurityModel {
err = x.testAuthentication(trap, result, useResponseSecurityParameters)
if err != nil {
x.logPrintf("UnmarshalTrap v3 auth: %s\n", err)
return nil
}
}
trap, cursor, err = x.decryptPacket(trap, cursor, result)
if err != nil {
x.logPrintf("UnmarshalTrap v3 decrypt: %s\n", err)
return nil
}
}
err = x.unmarshalPayload(trap, cursor, result)
if err != nil {
x.logPrintf("UnmarshalTrap: %s\n", err)
return nil
}
return result
}