Compare commits
8 Commits
v2.11
...
a7e671cb2d
| Author | SHA1 | Date | |
|---|---|---|---|
| a7e671cb2d | |||
| 3739e2d6ae | |||
| 7813951ca6 | |||
| 60d5a08d4c | |||
| 890cb816ea | |||
| f599ea1cac | |||
| a46dc47ef9 | |||
| f0f001dc43 |
89
build.sh
Executable file
89
build.sh
Executable file
@@ -0,0 +1,89 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
# Build wpa_supplicant for ARM toolchain with nl80211/libnl from sysroot.
|
||||
#
|
||||
# Usage:
|
||||
# ./build.sh [SYSROOT]
|
||||
#
|
||||
# Example:
|
||||
# ./build.sh /home/stargazer/arm-uclinuxfdpiceabi/sysroot
|
||||
|
||||
TOOLCHAIN_PREFIX="${TOOLCHAIN_PREFIX:-arm-uclinuxfdpiceabi}"
|
||||
CC_BIN="${CC_BIN:-${TOOLCHAIN_PREFIX}-gcc}"
|
||||
STRIP_BIN="${STRIP_BIN:-${TOOLCHAIN_PREFIX}-strip}"
|
||||
JOBS="${JOBS:-$(nproc)}"
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
WPA_DIR="${SCRIPT_DIR}/wpa_supplicant"
|
||||
SYSROOT_DEFAULT="/home/stargazer/arm-uclinuxfdpiceabi/sysroot"
|
||||
SYSROOT="${1:-${SYSROOT:-$SYSROOT_DEFAULT}}"
|
||||
|
||||
PKGCFG_LIBDIR_CANDIDATES=(
|
||||
"${SYSROOT}/usr/lib/pkgconfig"
|
||||
"${SYSROOT}/usr/lib64/pkgconfig"
|
||||
"${SYSROOT}/usr/share/pkgconfig"
|
||||
)
|
||||
|
||||
die() {
|
||||
echo "ERROR: $*" >&2
|
||||
exit 1
|
||||
}
|
||||
|
||||
if ! command -v "${CC_BIN}" >/dev/null 2>&1; then
|
||||
die "Compiler not found in PATH: ${CC_BIN}"
|
||||
fi
|
||||
if ! command -v "${STRIP_BIN}" >/dev/null 2>&1; then
|
||||
die "Strip tool not found in PATH: ${STRIP_BIN}"
|
||||
fi
|
||||
|
||||
if [ ! -d "${WPA_DIR}" ]; then
|
||||
die "wpa_supplicant directory not found: ${WPA_DIR}"
|
||||
fi
|
||||
|
||||
if [ ! -d "${SYSROOT}" ]; then
|
||||
die "SYSROOT not found: ${SYSROOT}"
|
||||
fi
|
||||
|
||||
PKG_CONFIG_LIBDIR=""
|
||||
for d in "${PKGCFG_LIBDIR_CANDIDATES[@]}"; do
|
||||
if [ -d "${d}" ]; then
|
||||
if [ -z "${PKG_CONFIG_LIBDIR}" ]; then
|
||||
PKG_CONFIG_LIBDIR="${d}"
|
||||
else
|
||||
PKG_CONFIG_LIBDIR="${PKG_CONFIG_LIBDIR}:${d}"
|
||||
fi
|
||||
fi
|
||||
done
|
||||
|
||||
if [ -z "${PKG_CONFIG_LIBDIR}" ]; then
|
||||
die "No pkg-config directories found in SYSROOT"
|
||||
fi
|
||||
|
||||
# Not setting PKG_CONFIG_SYSROOT_DIR: this SYSROOT's .pc files already bake
|
||||
# in an absolute prefix pointing inside the sysroot itself (from how libnl
|
||||
# was configured/installed), so sysroot-prefixing on top of that duplicates
|
||||
# the path (.../sysroot/.../sysroot/usr/include/...) and breaks -I/-L.
|
||||
export PKG_CONFIG_LIBDIR
|
||||
unset PKG_CONFIG_PATH
|
||||
|
||||
if ! pkg-config --exists libnl-3.0; then
|
||||
die "libnl-3.0.pc not found via pkg-config. Checked: ${PKG_CONFIG_LIBDIR}"
|
||||
fi
|
||||
|
||||
if ! pkg-config --exists libnl-genl-3.0; then
|
||||
die "libnl-genl-3.0.pc not found via pkg-config. Checked: ${PKG_CONFIG_LIBDIR}"
|
||||
fi
|
||||
|
||||
echo "Compiler: ${CC_BIN}"
|
||||
echo "SYSROOT: ${SYSROOT}"
|
||||
echo "PKG_CONFIG_LIBDIR: ${PKG_CONFIG_LIBDIR}"
|
||||
echo "libnl-3.0 version: $(pkg-config --modversion libnl-3.0)"
|
||||
echo "libnl-genl-3.0 version: $(pkg-config --modversion libnl-genl-3.0)"
|
||||
|
||||
cd "${WPA_DIR}"
|
||||
make clean
|
||||
make -j"${JOBS}" CC="${CC_BIN}"
|
||||
"${STRIP_BIN}" wpa_supplicant wpa_cli wpa_passphrase
|
||||
|
||||
echo "Build completed successfully."
|
||||
@@ -319,11 +319,21 @@ static int openssl_digest_vector(const EVP_MD *type, size_t num_elem,
|
||||
|
||||
#ifndef CONFIG_FIPS
|
||||
|
||||
/*
|
||||
* This target's OpenSSL was cross-built with MD4 excluded entirely
|
||||
* (OPENSSL_NO_MD4, see openssl/configuration.h) - EVP_md4() doesn't exist,
|
||||
* so this can't even be declared, let alone linked. Only MS-CHAP-family EAP
|
||||
* methods ever call md4_vector(), and those are disabled on this board
|
||||
* (WPA-PSK/SAE only), so just don't emit the function at all rather than
|
||||
* leave a dangling undefined reference in every binary that links this file.
|
||||
*/
|
||||
#ifndef OPENSSL_NO_MD4
|
||||
int md4_vector(size_t num_elem, const u8 *addr[], const size_t *len, u8 *mac)
|
||||
{
|
||||
openssl_load_legacy_provider();
|
||||
return openssl_digest_vector(EVP_md4(), num_elem, addr, len, mac);
|
||||
}
|
||||
#endif /* OPENSSL_NO_MD4 */
|
||||
|
||||
|
||||
int des_encrypt(const u8 *clear, const u8 *key, u8 *cypher)
|
||||
|
||||
@@ -66,6 +66,13 @@ enum nlmsgerr_attrs {
|
||||
#ifndef SOL_NETLINK
|
||||
#define SOL_NETLINK 270
|
||||
#endif
|
||||
/*
|
||||
* libnl's NLA_S8 is an enum value, not a macro, so `#ifndef NLA_S8` here
|
||||
* was always true regardless of libnl version and always redefined
|
||||
* nla_get_s8() - conflicting with libnl's own extern declaration (which
|
||||
* takes `const struct nlattr *`, not `struct nlattr *`). This target's
|
||||
* libnl (3.9.0) has nla_get_s8()/NLA_S8 natively; no shim needed.
|
||||
*/
|
||||
|
||||
|
||||
#ifdef ANDROID
|
||||
|
||||
@@ -26,10 +26,10 @@
|
||||
# replacement for WEXT and its use allows wpa_supplicant to properly control
|
||||
# the driver to improve existing functionality like roaming and to support new
|
||||
# functionality.
|
||||
CONFIG_DRIVER_WEXT=y
|
||||
#CONFIG_DRIVER_WEXT=y
|
||||
|
||||
# Driver interface for Linux drivers using the nl80211 kernel interface
|
||||
#CONFIG_DRIVER_NL80211=y
|
||||
CONFIG_DRIVER_NL80211=y
|
||||
|
||||
# QCA vendor extensions to nl80211
|
||||
#CONFIG_DRIVER_NL80211_QCA=y
|
||||
@@ -100,6 +100,10 @@ CC=arm-uclinuxfdpiceabi-gcc
|
||||
#CONFIG_EAP_MSCHAPV2=y
|
||||
|
||||
# EAP-TLS
|
||||
# Disabled: this board only ever does WPA-PSK/SAE, no 802.1X enterprise
|
||||
# auth, and enabling it pulls in tls_openssl.c's OCSP verification code,
|
||||
# which this target's OpenSSL was cross-built without (OPENSSL_NO_OCSP) -
|
||||
# undeclared OCSP_basic_verify/OCSP_TRUSTOTHER/etc build errors otherwise.
|
||||
#CONFIG_EAP_TLS=y
|
||||
# Enable EAP-TLSv1.3 support by default (currently disabled unless explicitly
|
||||
# enabled in network configuration)
|
||||
@@ -140,7 +144,10 @@ CC=arm-uclinuxfdpiceabi-gcc
|
||||
#CONFIG_EAP_PSK=y
|
||||
|
||||
# EAP-pwd (secure authentication using only a password)
|
||||
CONFIG_EAP_PWD=y
|
||||
# Disabled: not used (this board only does WPA-PSK/SAE), and it pulls in
|
||||
# MS_FUNCS -> md4_vector -> EVP_md4, which this target's OpenSSL doesn't
|
||||
# have (OPENSSL_NO_MD4).
|
||||
#CONFIG_EAP_PWD=y
|
||||
|
||||
# EAP-PAX
|
||||
#CONFIG_EAP_PAX=y
|
||||
@@ -241,7 +248,10 @@ CONFIG_CTRL_IFACE=y
|
||||
# This can be used to reduce the size of the wpa_supplicant considerably
|
||||
# if debugging code is not needed. The size reduction can be around 35%
|
||||
# (e.g., 90 kB).
|
||||
#CONFIG_NO_STDOUT_DEBUG=y
|
||||
CONFIG_NO_STDOUT_DEBUG=y
|
||||
# With NO_STDOUT_DEBUG wpa_printf() expands to nothing, so variables and
|
||||
# helpers used only for debug output become "unused". Silence that noise.
|
||||
CFLAGS += -Wno-unused-variable -Wno-unused-but-set-variable -Wno-unused-function
|
||||
|
||||
# Remove WPA support, e.g., for wired-only IEEE 802.1X supplicant, to save
|
||||
# 35-50 kB in code size.
|
||||
@@ -255,6 +265,11 @@ CONFIG_CTRL_IFACE=y
|
||||
#CONFIG_NO_WPA_PASSPHRASE=y
|
||||
|
||||
# Simultaneous Authentication of Equals (SAE), WPA3-Personal
|
||||
# Disabled: this board only does WPA2-PSK, and SAE/OWE need elliptic-curve
|
||||
# crypto that only the OpenSSL/wolfssl backends provide - dragging in all of
|
||||
# OpenSSL's EC/ASN.1/BIGNUM code just for that pushed the binary's .text
|
||||
# past 1MB (order:9 mmap - see nl80211 rebuild's page-allocation-failure
|
||||
# investigation). Internal crypto backend below has no EC support at all.
|
||||
#CONFIG_SAE=y
|
||||
|
||||
# SAE Public Key, WPA3-Personal
|
||||
@@ -331,7 +346,13 @@ CONFIG_BACKEND=file
|
||||
# internal = Internal TLSv1 implementation (experimental)
|
||||
# linux = Linux kernel AF_ALG and internal TLSv1 implementation (experimental)
|
||||
# none = Empty template
|
||||
#CONFIG_TLS=openssl
|
||||
# Switched from openssl: with SAE/OWE gone we have no EAP-TLS either, so
|
||||
# the only thing openssl was providing was AES/SHA1/MD5/RC4 primitives for
|
||||
# the WPA2 handshake - wpa_supplicant's own internal implementations do the
|
||||
# same job without dragging in the rest of libcrypto (EC/ASN.1/BIGNUM/RSA),
|
||||
# which was the majority of the >1MB .text forcing exec() to need a 2MB
|
||||
# contiguous block (order:9) on this noMMU board.
|
||||
CONFIG_TLS=internal
|
||||
|
||||
# TLS-based EAP methods require at least TLS v1.0. Newer version of TLS (v1.1)
|
||||
# can be enabled to get a stronger construction of messages when block ciphers
|
||||
@@ -355,7 +376,7 @@ CONFIG_BACKEND=file
|
||||
# needed for LibTomMath. Alternatively, an integrated, minimal version of
|
||||
# LibTomMath can be used. See beginning of libtommath.c for details on benefits
|
||||
# and drawbacks of this option.
|
||||
#CONFIG_INTERNAL_LIBTOMMATH=y
|
||||
CONFIG_INTERNAL_LIBTOMMATH=y
|
||||
#ifndef CONFIG_INTERNAL_LIBTOMMATH
|
||||
#LTM_PATH=/usr/src/libtommath-0.39
|
||||
#CFLAGS += -I$(LTM_PATH)
|
||||
@@ -639,6 +660,7 @@ CONFIG_BGSCAN_SIMPLE=y
|
||||
|
||||
# Opportunistic Wireless Encryption (OWE)
|
||||
# Experimental implementation of draft-harkins-owe-07.txt
|
||||
# Disabled along with SAE - see the comment there (needs EC crypto too).
|
||||
#CONFIG_OWE=y
|
||||
|
||||
# Device Provisioning Protocol (DPP) (also known as Wi-Fi Easy Connect)
|
||||
|
||||
Reference in New Issue
Block a user