wpa_supplicant: drop TDLS and 802.11r, which no camera can use - #2320
Merged
Merged
Conversation
Buildroot leaves upstream's wpa_supplicant defconfig defaults for CONFIG_TDLS and CONFIG_IEEE80211R in place and offers no Kconfig switch for either, so every board that enables wpa_supplicant carries both. Neither can fire on a camera. TDLS sets up direct station-to-station data links, and a camera only ever talks to its AP; 802.11r is fast BSS transition between APs, and a fixed-mount camera does not roam. On gk7205v300_lite the binary goes 500,304 -> 455,248 and the rootfs squashfs 4924KB -> 4904KB. rootfs.cpio loses the full 45,056 bytes. Appending to the package's own CONFIG_DISABLE list rather than patching its defconfig works because Buildroot includes external.mk after package/*/*.mk and expands WPA_SUPPLICANT_CONFIGURE_CMDS when the rule runs, so there is nothing to rebase when the package is bumped. Everything else in the config was measured and left alone. CONFIG_PKCS12, CONFIG_CTRL_IFACE_DBUS_INTRO and CONFIG_IEEE80211AC each cost exactly zero bytes here -- the first two need TLS and D-Bus, which are not built, and the third is compiled unconditionally in 2.10. WEXT stays because the shipped wlan0 script asks for `-D nl80211,wext` and the wiki documents `-D wext` alone. wpa_cli stays because majestic-webui's network.cgi uses it as its primary wifi scan path.
openipc-ai
requested review from
cronyx,
flyrouter and
viktorxda
as code owners
August 27, 2026 08:07
PR Summary by QodoDisable unused TDLS and 802.11r support in wpa_supplicant
AI Description
Diagram
High-Level Assessment
Files changed (1)
|
Code Review by Qodo🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)
Great, no issues found!Qodo reviewed your code and found no material issues that require reviewTip of the day💡 Did you know, you can ask Qodo to dismiss a finding you disagree with, with your reason on record |
7 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
wpa_supplicantis 598,426 B ongk7205v300_lite— the largest non-vendor package after majesticand busybox, on a board that had 24KB of rootfs headroom before #2317.
It is already lean where such things usually are not: EAP is off, TLS is off (
tls_none.ois 165bytes), and so are WPS, WPA3/SAE, mesh, P2P, D-Bus and hotspot. No defconfig in this tree enables
any of them. What is left is two features inherited from upstream's
defconfigthat Buildrootoffers no Kconfig switch for, so every board that enables wpa_supplicant carries both:
CONFIG_TDLS— Tunneled Direct Link Setup, direct station-to-station data links. A cameraonly ever talks to its AP.
CONFIG_IEEE80211R— fast BSS transition, for roaming between APs. A fixed-mount cameradoes not roam.
Fix
One line appended to the package's own
WPA_SUPPLICANT_CONFIG_DISABLEingeneral/external.mk.That works rather than needing a patch because Buildroot includes
external.mk(Makefile:545)after
package/*/*.mk(Makefile:531) and expandsWPA_SUPPLICANT_CONFIGURE_CMDSwhen the ruleruns rather than at parse time — so there is nothing to rebase when the package is bumped.
Everything else in the config was measured, not assumed, and deliberately left alone:
CONFIG_TDLSCONFIG_IEEE80211RCONFIG_PKCS12CONFIG_CTRL_IFACE_DBUS_INTROCONFIG_IEEE80211ACCONFIG_BGSCAN_SIMPLEThree things kept on purpose:
general/overlay/etc/network/interfaces.d/wlan0asks for-D nl80211,wext, andwiki/ru/configuration.mddocuments-D wextalone. Vendor WiFidrivers that predate cfg80211 need it.
wpa_cli(67,864 B) —majestic-webui'swww/cgi-bin/j/network.cgiuses it as its primaryWiFi scan path, with
iwlistonly as fallback.wpa_passphrase(30,176 B) — used by the shippedwlan0script and by every wiki page thatdocuments WiFi setup.
Hardware tested on
Goke gk7205v200, lab camera
openipc-gk7205v200, runninggk7205v200_litebuilt from this branchand flashed over
sysupgrade.Evidence
Before —
make BOARD=gk7205v300_liteon this branch's parent:After — same tree, same output dir:
Image bytes:
Effective build config after the change —
CONFIG_TDLSandCONFIG_IEEE80211Rgone, nothing elsemoved:
Symbol check on the unstripped binary — the two features are gone and the association and PSK
paths are untouched:
On the camera, after flashing and rebooting:
Daemon start, control interface and the
wpa_cliround-trip, exercised on the camera without WiFihardware via the global control socket:
majestic still runs and serves frames on the flashed camera:
Link closure over the rebuilt rootfs is unchanged from baseline — the same 25 pre-existing
libc.so.0findings from the uClibc-built Goke vendor blobs, no new unresolved links.Repo gates:
Scope
general/package/all-patches/linux/general/overlay/or in a sharedload_<vendor>script hardcodes a value specific to my boardLD_PRELOAD, and no binaries that cannot be rebuilt from sourceci-matrix.pywidensgeneral/external.mkto the full 99-board matrix