From 3739e2d6aee480643dabce926fb3d8164144b42a Mon Sep 17 00:00:00 2001 From: Egor Tsyganchuk Date: Thu, 1 Oct 2026 09:02:35 +0300 Subject: [PATCH] Refactor build script and configuration for compatibility with cross-compiled OpenSSL and libnl versions, disabling unnecessary EAP methods and adjusting TLS settings to reduce binary size. --- build.sh | 5 ++++- src/crypto/crypto_openssl.c | 10 ++++++++++ src/drivers/driver_nl80211.c | 15 +++++++-------- wpa_supplicant/.config | 37 +++++++++++++++++++++++++++--------- 4 files changed, 49 insertions(+), 18 deletions(-) diff --git a/build.sh b/build.sh index 98cebd2..a5cf240 100755 --- a/build.sh +++ b/build.sh @@ -60,7 +60,10 @@ if [ -z "${PKG_CONFIG_LIBDIR}" ]; then die "No pkg-config directories found in SYSROOT" fi -export PKG_CONFIG_SYSROOT_DIR="${SYSROOT}" +# Not setting PKG_CONFIG_SYSROOT_DIR: this SYSROOT's .pc files already bake +# in an absolute prefix pointing inside the sysroot itself (from how libnl +# was configured/installed), so sysroot-prefixing on top of that duplicates +# the path (.../sysroot/.../sysroot/usr/include/...) and breaks -I/-L. export PKG_CONFIG_LIBDIR unset PKG_CONFIG_PATH diff --git a/src/crypto/crypto_openssl.c b/src/crypto/crypto_openssl.c index 2d8ff60..02d15d7 100644 --- a/src/crypto/crypto_openssl.c +++ b/src/crypto/crypto_openssl.c @@ -319,11 +319,21 @@ static int openssl_digest_vector(const EVP_MD *type, size_t num_elem, #ifndef CONFIG_FIPS +/* + * This target's OpenSSL was cross-built with MD4 excluded entirely + * (OPENSSL_NO_MD4, see openssl/configuration.h) - EVP_md4() doesn't exist, + * so this can't even be declared, let alone linked. Only MS-CHAP-family EAP + * methods ever call md4_vector(), and those are disabled on this board + * (WPA-PSK/SAE only), so just don't emit the function at all rather than + * leave a dangling undefined reference in every binary that links this file. + */ +#ifndef OPENSSL_NO_MD4 int md4_vector(size_t num_elem, const u8 *addr[], const size_t *len, u8 *mac) { openssl_load_legacy_provider(); return openssl_digest_vector(EVP_md4(), num_elem, addr, len, mac); } +#endif /* OPENSSL_NO_MD4 */ int des_encrypt(const u8 *clear, const u8 *key, u8 *cypher) diff --git a/src/drivers/driver_nl80211.c b/src/drivers/driver_nl80211.c index 0d52ea5..4a94c47 100644 --- a/src/drivers/driver_nl80211.c +++ b/src/drivers/driver_nl80211.c @@ -66,14 +66,13 @@ enum nlmsgerr_attrs { #ifndef SOL_NETLINK #define SOL_NETLINK 270 #endif -#ifndef NLA_S8 -/* libnl < 3.3 does not define signed 8-bit attr helpers */ -#define NLA_S8 NLA_U8 -static inline s8 nla_get_s8(struct nlattr *nla) -{ - return (s8) nla_get_u8(nla); -} -#endif /* NLA_S8 */ +/* + * libnl's NLA_S8 is an enum value, not a macro, so `#ifndef NLA_S8` here + * was always true regardless of libnl version and always redefined + * nla_get_s8() - conflicting with libnl's own extern declaration (which + * takes `const struct nlattr *`, not `struct nlattr *`). This target's + * libnl (3.9.0) has nla_get_s8()/NLA_S8 natively; no shim needed. + */ #ifdef ANDROID diff --git a/wpa_supplicant/.config b/wpa_supplicant/.config index d75a1a1..4659e54 100644 --- a/wpa_supplicant/.config +++ b/wpa_supplicant/.config @@ -91,7 +91,7 @@ CC=arm-uclinuxfdpiceabi-gcc # Enable IEEE 802.1X Supplicant (automatically included if any EAP method or # MACsec is included) -CONFIG_IEEE8021X_EAPOL=y +#CONFIG_IEEE8021X_EAPOL=y # EAP-MD5 #CONFIG_EAP_MD5=y @@ -100,16 +100,20 @@ CONFIG_IEEE8021X_EAPOL=y #CONFIG_EAP_MSCHAPV2=y # EAP-TLS -CONFIG_EAP_TLS=y +# Disabled: this board only ever does WPA-PSK/SAE, no 802.1X enterprise +# auth, and enabling it pulls in tls_openssl.c's OCSP verification code, +# which this target's OpenSSL was cross-built without (OPENSSL_NO_OCSP) - +# undeclared OCSP_basic_verify/OCSP_TRUSTOTHER/etc build errors otherwise. +#CONFIG_EAP_TLS=y # Enable EAP-TLSv1.3 support by default (currently disabled unless explicitly # enabled in network configuration) #CONFIG_EAP_TLSV1_3=y # EAL-PEAP -CONFIG_EAP_PEAP=y +#CONFIG_EAP_PEAP=y # EAP-TTLS -CONFIG_EAP_TTLS=y +#CONFIG_EAP_TTLS=y # EAP-FAST #CONFIG_EAP_FAST=y @@ -140,7 +144,10 @@ CONFIG_EAP_TTLS=y #CONFIG_EAP_PSK=y # EAP-pwd (secure authentication using only a password) -CONFIG_EAP_PWD=y +# Disabled: not used (this board only does WPA-PSK/SAE), and it pulls in +# MS_FUNCS -> md4_vector -> EVP_md4, which this target's OpenSSL doesn't +# have (OPENSSL_NO_MD4). +#CONFIG_EAP_PWD=y # EAP-PAX #CONFIG_EAP_PAX=y @@ -255,7 +262,12 @@ CONFIG_NO_STDOUT_DEBUG=y #CONFIG_NO_WPA_PASSPHRASE=y # Simultaneous Authentication of Equals (SAE), WPA3-Personal -CONFIG_SAE=y +# Disabled: this board only does WPA2-PSK, and SAE/OWE need elliptic-curve +# crypto that only the OpenSSL/wolfssl backends provide - dragging in all of +# OpenSSL's EC/ASN.1/BIGNUM code just for that pushed the binary's .text +# past 1MB (order:9 mmap - see nl80211 rebuild's page-allocation-failure +# investigation). Internal crypto backend below has no EC support at all. +#CONFIG_SAE=y # SAE Public Key, WPA3-Personal #CONFIG_SAE_PK=y @@ -331,7 +343,13 @@ CONFIG_BACKEND=file # internal = Internal TLSv1 implementation (experimental) # linux = Linux kernel AF_ALG and internal TLSv1 implementation (experimental) # none = Empty template -#CONFIG_TLS=openssl +# Switched from openssl: with SAE/OWE gone we have no EAP-TLS either, so +# the only thing openssl was providing was AES/SHA1/MD5/RC4 primitives for +# the WPA2 handshake - wpa_supplicant's own internal implementations do the +# same job without dragging in the rest of libcrypto (EC/ASN.1/BIGNUM/RSA), +# which was the majority of the >1MB .text forcing exec() to need a 2MB +# contiguous block (order:9) on this noMMU board. +CONFIG_TLS=internal # TLS-based EAP methods require at least TLS v1.0. Newer version of TLS (v1.1) # can be enabled to get a stronger construction of messages when block ciphers @@ -355,7 +373,7 @@ CONFIG_BACKEND=file # needed for LibTomMath. Alternatively, an integrated, minimal version of # LibTomMath can be used. See beginning of libtommath.c for details on benefits # and drawbacks of this option. -#CONFIG_INTERNAL_LIBTOMMATH=y +CONFIG_INTERNAL_LIBTOMMATH=y #ifndef CONFIG_INTERNAL_LIBTOMMATH #LTM_PATH=/usr/src/libtommath-0.39 #CFLAGS += -I$(LTM_PATH) @@ -639,7 +657,8 @@ CONFIG_BGSCAN_SIMPLE=y # Opportunistic Wireless Encryption (OWE) # Experimental implementation of draft-harkins-owe-07.txt -CONFIG_OWE=y +# Disabled along with SAE - see the comment there (needs EC crypto too). +#CONFIG_OWE=y # Device Provisioning Protocol (DPP) (also known as Wi-Fi Easy Connect) #CONFIG_DPP=y