Refactor build script and configuration for compatibility with cross-compiled OpenSSL and libnl versions, disabling unnecessary EAP methods and adjusting TLS settings to reduce binary size.

This commit is contained in:
2026-10-01 09:02:35 +03:00
parent 7813951ca6
commit 3739e2d6ae
4 changed files with 49 additions and 18 deletions

View File

@@ -60,7 +60,10 @@ if [ -z "${PKG_CONFIG_LIBDIR}" ]; then
die "No pkg-config directories found in SYSROOT" die "No pkg-config directories found in SYSROOT"
fi fi
export PKG_CONFIG_SYSROOT_DIR="${SYSROOT}" # Not setting PKG_CONFIG_SYSROOT_DIR: this SYSROOT's .pc files already bake
# in an absolute prefix pointing inside the sysroot itself (from how libnl
# was configured/installed), so sysroot-prefixing on top of that duplicates
# the path (.../sysroot/.../sysroot/usr/include/...) and breaks -I/-L.
export PKG_CONFIG_LIBDIR export PKG_CONFIG_LIBDIR
unset PKG_CONFIG_PATH unset PKG_CONFIG_PATH

View File

@@ -319,11 +319,21 @@ static int openssl_digest_vector(const EVP_MD *type, size_t num_elem,
#ifndef CONFIG_FIPS #ifndef CONFIG_FIPS
/*
* This target's OpenSSL was cross-built with MD4 excluded entirely
* (OPENSSL_NO_MD4, see openssl/configuration.h) - EVP_md4() doesn't exist,
* so this can't even be declared, let alone linked. Only MS-CHAP-family EAP
* methods ever call md4_vector(), and those are disabled on this board
* (WPA-PSK/SAE only), so just don't emit the function at all rather than
* leave a dangling undefined reference in every binary that links this file.
*/
#ifndef OPENSSL_NO_MD4
int md4_vector(size_t num_elem, const u8 *addr[], const size_t *len, u8 *mac) int md4_vector(size_t num_elem, const u8 *addr[], const size_t *len, u8 *mac)
{ {
openssl_load_legacy_provider(); openssl_load_legacy_provider();
return openssl_digest_vector(EVP_md4(), num_elem, addr, len, mac); return openssl_digest_vector(EVP_md4(), num_elem, addr, len, mac);
} }
#endif /* OPENSSL_NO_MD4 */
int des_encrypt(const u8 *clear, const u8 *key, u8 *cypher) int des_encrypt(const u8 *clear, const u8 *key, u8 *cypher)

View File

@@ -66,14 +66,13 @@ enum nlmsgerr_attrs {
#ifndef SOL_NETLINK #ifndef SOL_NETLINK
#define SOL_NETLINK 270 #define SOL_NETLINK 270
#endif #endif
#ifndef NLA_S8 /*
/* libnl < 3.3 does not define signed 8-bit attr helpers */ * libnl's NLA_S8 is an enum value, not a macro, so `#ifndef NLA_S8` here
#define NLA_S8 NLA_U8 * was always true regardless of libnl version and always redefined
static inline s8 nla_get_s8(struct nlattr *nla) * nla_get_s8() - conflicting with libnl's own extern declaration (which
{ * takes `const struct nlattr *`, not `struct nlattr *`). This target's
return (s8) nla_get_u8(nla); * libnl (3.9.0) has nla_get_s8()/NLA_S8 natively; no shim needed.
} */
#endif /* NLA_S8 */
#ifdef ANDROID #ifdef ANDROID

View File

@@ -91,7 +91,7 @@ CC=arm-uclinuxfdpiceabi-gcc
# Enable IEEE 802.1X Supplicant (automatically included if any EAP method or # Enable IEEE 802.1X Supplicant (automatically included if any EAP method or
# MACsec is included) # MACsec is included)
CONFIG_IEEE8021X_EAPOL=y #CONFIG_IEEE8021X_EAPOL=y
# EAP-MD5 # EAP-MD5
#CONFIG_EAP_MD5=y #CONFIG_EAP_MD5=y
@@ -100,16 +100,20 @@ CONFIG_IEEE8021X_EAPOL=y
#CONFIG_EAP_MSCHAPV2=y #CONFIG_EAP_MSCHAPV2=y
# EAP-TLS # EAP-TLS
CONFIG_EAP_TLS=y # Disabled: this board only ever does WPA-PSK/SAE, no 802.1X enterprise
# auth, and enabling it pulls in tls_openssl.c's OCSP verification code,
# which this target's OpenSSL was cross-built without (OPENSSL_NO_OCSP) -
# undeclared OCSP_basic_verify/OCSP_TRUSTOTHER/etc build errors otherwise.
#CONFIG_EAP_TLS=y
# Enable EAP-TLSv1.3 support by default (currently disabled unless explicitly # Enable EAP-TLSv1.3 support by default (currently disabled unless explicitly
# enabled in network configuration) # enabled in network configuration)
#CONFIG_EAP_TLSV1_3=y #CONFIG_EAP_TLSV1_3=y
# EAL-PEAP # EAL-PEAP
CONFIG_EAP_PEAP=y #CONFIG_EAP_PEAP=y
# EAP-TTLS # EAP-TTLS
CONFIG_EAP_TTLS=y #CONFIG_EAP_TTLS=y
# EAP-FAST # EAP-FAST
#CONFIG_EAP_FAST=y #CONFIG_EAP_FAST=y
@@ -140,7 +144,10 @@ CONFIG_EAP_TTLS=y
#CONFIG_EAP_PSK=y #CONFIG_EAP_PSK=y
# EAP-pwd (secure authentication using only a password) # EAP-pwd (secure authentication using only a password)
CONFIG_EAP_PWD=y # Disabled: not used (this board only does WPA-PSK/SAE), and it pulls in
# MS_FUNCS -> md4_vector -> EVP_md4, which this target's OpenSSL doesn't
# have (OPENSSL_NO_MD4).
#CONFIG_EAP_PWD=y
# EAP-PAX # EAP-PAX
#CONFIG_EAP_PAX=y #CONFIG_EAP_PAX=y
@@ -255,7 +262,12 @@ CONFIG_NO_STDOUT_DEBUG=y
#CONFIG_NO_WPA_PASSPHRASE=y #CONFIG_NO_WPA_PASSPHRASE=y
# Simultaneous Authentication of Equals (SAE), WPA3-Personal # Simultaneous Authentication of Equals (SAE), WPA3-Personal
CONFIG_SAE=y # Disabled: this board only does WPA2-PSK, and SAE/OWE need elliptic-curve
# crypto that only the OpenSSL/wolfssl backends provide - dragging in all of
# OpenSSL's EC/ASN.1/BIGNUM code just for that pushed the binary's .text
# past 1MB (order:9 mmap - see nl80211 rebuild's page-allocation-failure
# investigation). Internal crypto backend below has no EC support at all.
#CONFIG_SAE=y
# SAE Public Key, WPA3-Personal # SAE Public Key, WPA3-Personal
#CONFIG_SAE_PK=y #CONFIG_SAE_PK=y
@@ -331,7 +343,13 @@ CONFIG_BACKEND=file
# internal = Internal TLSv1 implementation (experimental) # internal = Internal TLSv1 implementation (experimental)
# linux = Linux kernel AF_ALG and internal TLSv1 implementation (experimental) # linux = Linux kernel AF_ALG and internal TLSv1 implementation (experimental)
# none = Empty template # none = Empty template
#CONFIG_TLS=openssl # Switched from openssl: with SAE/OWE gone we have no EAP-TLS either, so
# the only thing openssl was providing was AES/SHA1/MD5/RC4 primitives for
# the WPA2 handshake - wpa_supplicant's own internal implementations do the
# same job without dragging in the rest of libcrypto (EC/ASN.1/BIGNUM/RSA),
# which was the majority of the >1MB .text forcing exec() to need a 2MB
# contiguous block (order:9) on this noMMU board.
CONFIG_TLS=internal
# TLS-based EAP methods require at least TLS v1.0. Newer version of TLS (v1.1) # TLS-based EAP methods require at least TLS v1.0. Newer version of TLS (v1.1)
# can be enabled to get a stronger construction of messages when block ciphers # can be enabled to get a stronger construction of messages when block ciphers
@@ -355,7 +373,7 @@ CONFIG_BACKEND=file
# needed for LibTomMath. Alternatively, an integrated, minimal version of # needed for LibTomMath. Alternatively, an integrated, minimal version of
# LibTomMath can be used. See beginning of libtommath.c for details on benefits # LibTomMath can be used. See beginning of libtommath.c for details on benefits
# and drawbacks of this option. # and drawbacks of this option.
#CONFIG_INTERNAL_LIBTOMMATH=y CONFIG_INTERNAL_LIBTOMMATH=y
#ifndef CONFIG_INTERNAL_LIBTOMMATH #ifndef CONFIG_INTERNAL_LIBTOMMATH
#LTM_PATH=/usr/src/libtommath-0.39 #LTM_PATH=/usr/src/libtommath-0.39
#CFLAGS += -I$(LTM_PATH) #CFLAGS += -I$(LTM_PATH)
@@ -639,7 +657,8 @@ CONFIG_BGSCAN_SIMPLE=y
# Opportunistic Wireless Encryption (OWE) # Opportunistic Wireless Encryption (OWE)
# Experimental implementation of draft-harkins-owe-07.txt # Experimental implementation of draft-harkins-owe-07.txt
CONFIG_OWE=y # Disabled along with SAE - see the comment there (needs EC crypto too).
#CONFIG_OWE=y
# Device Provisioning Protocol (DPP) (also known as Wi-Fi Easy Connect) # Device Provisioning Protocol (DPP) (also known as Wi-Fi Easy Connect)
#CONFIG_DPP=y #CONFIG_DPP=y