Compare commits

...

8 Commits

Author SHA1 Message Date
a7e671cb2d Suppress unused variable warnings in CFLAGS to reduce noise when NO_STDOUT_DEBUG is enabled 2026-10-01 09:36:29 +03:00
3739e2d6ae Refactor build script and configuration for compatibility with cross-compiled OpenSSL and libnl versions, disabling unnecessary EAP methods and adjusting TLS settings to reduce binary size. 2026-10-01 09:02:35 +03:00
7813951ca6 Enable EAP methods in wpa_supplicant configuration by uncommenting CONFIG_IEEE8021X_EAPOL, CONFIG_EAP_TLS, CONFIG_EAP_PEAP, and CONFIG_EAP_TTLS for enhanced authentication support. 2026-04-07 12:27:13 +03:00
60d5a08d4c Enhance build script to include strip tool verification and update wpa_supplicant configuration to enable stdout debug reduction for smaller binary size. 2026-04-06 16:44:29 +03:00
890cb816ea Enable CONFIG_SAE and CONFIG_OWE in wpa_supplicant configuration while disabling CONFIG_DRIVER_WEXT for improved driver compatibility. 2026-04-06 16:16:14 +03:00
f599ea1cac Update nla_get_s8 function signature to accept non-const struct nlattr pointer for improved compatibility 2026-04-06 15:36:06 +03:00
a46dc47ef9 Add support for signed 8-bit attribute helpers in nl80211 driver for compatibility with older libnl versions 2026-04-06 15:30:20 +03:00
f0f001dc43 Add build script for ARM toolchain and enable nl80211 driver in wpa_supplicant configuration 2026-04-06 15:27:24 +03:00
4 changed files with 134 additions and 6 deletions

89
build.sh Executable file
View File

@@ -0,0 +1,89 @@
#!/usr/bin/env bash
set -euo pipefail
# Build wpa_supplicant for ARM toolchain with nl80211/libnl from sysroot.
#
# Usage:
# ./build.sh [SYSROOT]
#
# Example:
# ./build.sh /home/stargazer/arm-uclinuxfdpiceabi/sysroot
TOOLCHAIN_PREFIX="${TOOLCHAIN_PREFIX:-arm-uclinuxfdpiceabi}"
CC_BIN="${CC_BIN:-${TOOLCHAIN_PREFIX}-gcc}"
STRIP_BIN="${STRIP_BIN:-${TOOLCHAIN_PREFIX}-strip}"
JOBS="${JOBS:-$(nproc)}"
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
WPA_DIR="${SCRIPT_DIR}/wpa_supplicant"
SYSROOT_DEFAULT="/home/stargazer/arm-uclinuxfdpiceabi/sysroot"
SYSROOT="${1:-${SYSROOT:-$SYSROOT_DEFAULT}}"
PKGCFG_LIBDIR_CANDIDATES=(
"${SYSROOT}/usr/lib/pkgconfig"
"${SYSROOT}/usr/lib64/pkgconfig"
"${SYSROOT}/usr/share/pkgconfig"
)
die() {
echo "ERROR: $*" >&2
exit 1
}
if ! command -v "${CC_BIN}" >/dev/null 2>&1; then
die "Compiler not found in PATH: ${CC_BIN}"
fi
if ! command -v "${STRIP_BIN}" >/dev/null 2>&1; then
die "Strip tool not found in PATH: ${STRIP_BIN}"
fi
if [ ! -d "${WPA_DIR}" ]; then
die "wpa_supplicant directory not found: ${WPA_DIR}"
fi
if [ ! -d "${SYSROOT}" ]; then
die "SYSROOT not found: ${SYSROOT}"
fi
PKG_CONFIG_LIBDIR=""
for d in "${PKGCFG_LIBDIR_CANDIDATES[@]}"; do
if [ -d "${d}" ]; then
if [ -z "${PKG_CONFIG_LIBDIR}" ]; then
PKG_CONFIG_LIBDIR="${d}"
else
PKG_CONFIG_LIBDIR="${PKG_CONFIG_LIBDIR}:${d}"
fi
fi
done
if [ -z "${PKG_CONFIG_LIBDIR}" ]; then
die "No pkg-config directories found in SYSROOT"
fi
# Not setting PKG_CONFIG_SYSROOT_DIR: this SYSROOT's .pc files already bake
# in an absolute prefix pointing inside the sysroot itself (from how libnl
# was configured/installed), so sysroot-prefixing on top of that duplicates
# the path (.../sysroot/.../sysroot/usr/include/...) and breaks -I/-L.
export PKG_CONFIG_LIBDIR
unset PKG_CONFIG_PATH
if ! pkg-config --exists libnl-3.0; then
die "libnl-3.0.pc not found via pkg-config. Checked: ${PKG_CONFIG_LIBDIR}"
fi
if ! pkg-config --exists libnl-genl-3.0; then
die "libnl-genl-3.0.pc not found via pkg-config. Checked: ${PKG_CONFIG_LIBDIR}"
fi
echo "Compiler: ${CC_BIN}"
echo "SYSROOT: ${SYSROOT}"
echo "PKG_CONFIG_LIBDIR: ${PKG_CONFIG_LIBDIR}"
echo "libnl-3.0 version: $(pkg-config --modversion libnl-3.0)"
echo "libnl-genl-3.0 version: $(pkg-config --modversion libnl-genl-3.0)"
cd "${WPA_DIR}"
make clean
make -j"${JOBS}" CC="${CC_BIN}"
"${STRIP_BIN}" wpa_supplicant wpa_cli wpa_passphrase
echo "Build completed successfully."

View File

@@ -319,11 +319,21 @@ static int openssl_digest_vector(const EVP_MD *type, size_t num_elem,
#ifndef CONFIG_FIPS
/*
* This target's OpenSSL was cross-built with MD4 excluded entirely
* (OPENSSL_NO_MD4, see openssl/configuration.h) - EVP_md4() doesn't exist,
* so this can't even be declared, let alone linked. Only MS-CHAP-family EAP
* methods ever call md4_vector(), and those are disabled on this board
* (WPA-PSK/SAE only), so just don't emit the function at all rather than
* leave a dangling undefined reference in every binary that links this file.
*/
#ifndef OPENSSL_NO_MD4
int md4_vector(size_t num_elem, const u8 *addr[], const size_t *len, u8 *mac)
{
openssl_load_legacy_provider();
return openssl_digest_vector(EVP_md4(), num_elem, addr, len, mac);
}
#endif /* OPENSSL_NO_MD4 */
int des_encrypt(const u8 *clear, const u8 *key, u8 *cypher)

View File

@@ -66,6 +66,13 @@ enum nlmsgerr_attrs {
#ifndef SOL_NETLINK
#define SOL_NETLINK 270
#endif
/*
* libnl's NLA_S8 is an enum value, not a macro, so `#ifndef NLA_S8` here
* was always true regardless of libnl version and always redefined
* nla_get_s8() - conflicting with libnl's own extern declaration (which
* takes `const struct nlattr *`, not `struct nlattr *`). This target's
* libnl (3.9.0) has nla_get_s8()/NLA_S8 natively; no shim needed.
*/
#ifdef ANDROID

View File

@@ -26,10 +26,10 @@
# replacement for WEXT and its use allows wpa_supplicant to properly control
# the driver to improve existing functionality like roaming and to support new
# functionality.
CONFIG_DRIVER_WEXT=y
#CONFIG_DRIVER_WEXT=y
# Driver interface for Linux drivers using the nl80211 kernel interface
#CONFIG_DRIVER_NL80211=y
CONFIG_DRIVER_NL80211=y
# QCA vendor extensions to nl80211
#CONFIG_DRIVER_NL80211_QCA=y
@@ -100,6 +100,10 @@ CC=arm-uclinuxfdpiceabi-gcc
#CONFIG_EAP_MSCHAPV2=y
# EAP-TLS
# Disabled: this board only ever does WPA-PSK/SAE, no 802.1X enterprise
# auth, and enabling it pulls in tls_openssl.c's OCSP verification code,
# which this target's OpenSSL was cross-built without (OPENSSL_NO_OCSP) -
# undeclared OCSP_basic_verify/OCSP_TRUSTOTHER/etc build errors otherwise.
#CONFIG_EAP_TLS=y
# Enable EAP-TLSv1.3 support by default (currently disabled unless explicitly
# enabled in network configuration)
@@ -140,7 +144,10 @@ CC=arm-uclinuxfdpiceabi-gcc
#CONFIG_EAP_PSK=y
# EAP-pwd (secure authentication using only a password)
CONFIG_EAP_PWD=y
# Disabled: not used (this board only does WPA-PSK/SAE), and it pulls in
# MS_FUNCS -> md4_vector -> EVP_md4, which this target's OpenSSL doesn't
# have (OPENSSL_NO_MD4).
#CONFIG_EAP_PWD=y
# EAP-PAX
#CONFIG_EAP_PAX=y
@@ -241,7 +248,10 @@ CONFIG_CTRL_IFACE=y
# This can be used to reduce the size of the wpa_supplicant considerably
# if debugging code is not needed. The size reduction can be around 35%
# (e.g., 90 kB).
#CONFIG_NO_STDOUT_DEBUG=y
CONFIG_NO_STDOUT_DEBUG=y
# With NO_STDOUT_DEBUG wpa_printf() expands to nothing, so variables and
# helpers used only for debug output become "unused". Silence that noise.
CFLAGS += -Wno-unused-variable -Wno-unused-but-set-variable -Wno-unused-function
# Remove WPA support, e.g., for wired-only IEEE 802.1X supplicant, to save
# 35-50 kB in code size.
@@ -255,6 +265,11 @@ CONFIG_CTRL_IFACE=y
#CONFIG_NO_WPA_PASSPHRASE=y
# Simultaneous Authentication of Equals (SAE), WPA3-Personal
# Disabled: this board only does WPA2-PSK, and SAE/OWE need elliptic-curve
# crypto that only the OpenSSL/wolfssl backends provide - dragging in all of
# OpenSSL's EC/ASN.1/BIGNUM code just for that pushed the binary's .text
# past 1MB (order:9 mmap - see nl80211 rebuild's page-allocation-failure
# investigation). Internal crypto backend below has no EC support at all.
#CONFIG_SAE=y
# SAE Public Key, WPA3-Personal
@@ -331,7 +346,13 @@ CONFIG_BACKEND=file
# internal = Internal TLSv1 implementation (experimental)
# linux = Linux kernel AF_ALG and internal TLSv1 implementation (experimental)
# none = Empty template
#CONFIG_TLS=openssl
# Switched from openssl: with SAE/OWE gone we have no EAP-TLS either, so
# the only thing openssl was providing was AES/SHA1/MD5/RC4 primitives for
# the WPA2 handshake - wpa_supplicant's own internal implementations do the
# same job without dragging in the rest of libcrypto (EC/ASN.1/BIGNUM/RSA),
# which was the majority of the >1MB .text forcing exec() to need a 2MB
# contiguous block (order:9) on this noMMU board.
CONFIG_TLS=internal
# TLS-based EAP methods require at least TLS v1.0. Newer version of TLS (v1.1)
# can be enabled to get a stronger construction of messages when block ciphers
@@ -355,7 +376,7 @@ CONFIG_BACKEND=file
# needed for LibTomMath. Alternatively, an integrated, minimal version of
# LibTomMath can be used. See beginning of libtommath.c for details on benefits
# and drawbacks of this option.
#CONFIG_INTERNAL_LIBTOMMATH=y
CONFIG_INTERNAL_LIBTOMMATH=y
#ifndef CONFIG_INTERNAL_LIBTOMMATH
#LTM_PATH=/usr/src/libtommath-0.39
#CFLAGS += -I$(LTM_PATH)
@@ -639,6 +660,7 @@ CONFIG_BGSCAN_SIMPLE=y
# Opportunistic Wireless Encryption (OWE)
# Experimental implementation of draft-harkins-owe-07.txt
# Disabled along with SAE - see the comment there (needs EC crypto too).
#CONFIG_OWE=y
# Device Provisioning Protocol (DPP) (also known as Wi-Fi Easy Connect)