Skip to content

wpa_supplicant: drop TDLS and 802.11r, which no camera can use - #2320

Merged
openipc-ai merged 1 commit into
masterfrom
wpa-supplicant-drop-tdls-11r
Aug 27, 2026
Merged

openipc-ai merged 1 commit into
masterfrom
wpa-supplicant-drop-tdls-11r

Conversation

@openipc-ai

Copy link
Copy Markdown
Collaborator

Problem

wpa_supplicant is 598,426 B on gk7205v300_lite — the largest non-vendor package after majestic
and busybox, on a board that had 24KB of rootfs headroom before #2317.

It is already lean where such things usually are not: EAP is off, TLS is off (tls_none.o is 165
bytes), and so are WPS, WPA3/SAE, mesh, P2P, D-Bus and hotspot. No defconfig in this tree enables
any of them. What is left is two features inherited from upstream's defconfig that Buildroot
offers no Kconfig switch for, so every board that enables wpa_supplicant carries both:

  • CONFIG_TDLS — Tunneled Direct Link Setup, direct station-to-station data links. A camera
    only ever talks to its AP.
  • CONFIG_IEEE80211R — fast BSS transition, for roaming between APs. A fixed-mount camera
    does not roam.

Fix

One line appended to the package's own WPA_SUPPLICANT_CONFIG_DISABLE in general/external.mk.
That works rather than needing a patch because Buildroot includes external.mk (Makefile:545)
after package/*/*.mk (Makefile:531) and expands WPA_SUPPLICANT_CONFIGURE_CMDS when the rule
runs rather than at parse time — so there is nothing to rebase when the package is bumped.

Everything else in the config was measured, not assumed, and deliberately left alone:

symbol measured cost why it stays / goes
CONFIG_TDLS 28,860 B removed — peer-to-peer links, unusable here
CONFIG_IEEE80211R 21,940 B removed — roaming, unusable here
CONFIG_PKCS12 0 B inert — needs TLS, which is not built
CONFIG_CTRL_IFACE_DBUS_INTRO 0 B inert — needs D-Bus, which is not built
CONFIG_IEEE80211AC 0 B compiled unconditionally in 2.10
CONFIG_BGSCAN_SIMPLE 4 B noise

Three things kept on purpose:

  • WEXT — the shipped general/overlay/etc/network/interfaces.d/wlan0 asks for
    -D nl80211,wext, and wiki/ru/configuration.md documents -D wext alone. Vendor WiFi
    drivers that predate cfg80211 need it.
  • wpa_cli (67,864 B) — majestic-webui's www/cgi-bin/j/network.cgi uses it as its primary
    WiFi scan path, with iwlist only as fallback.
  • wpa_passphrase (30,176 B) — used by the shipped wlan0 script and by every wiki page that
    documents WiFi setup.

Hardware tested on

Goke gk7205v200, lab camera openipc-gk7205v200, running gk7205v200_lite built from this branch
and flashed over sysupgrade.

Evidence

Before — make BOARD=gk7205v300_lite on this branch's parent:

- rootfs.squashfs: [4924KB/5120KB]
wpa_supplicant: 500304 B

After — same tree, same output dir:

- rootfs.squashfs: [4904KB/5120KB]
wpa_supplicant: 455248 B

Image bytes:

rootfs.squashfs.gk7205v300         5042176 ->   5021696  (-20480 B)
rootfs.cpio                       13435392 ->  13390336  (-45056 B)
openipc.gk7205v300-nor-lite.tgz    6849201 ->   6829878  (-19323 B)

Effective build config after the change — CONFIG_TDLS and CONFIG_IEEE80211R gone, nothing else
moved:

CONFIG_DRIVER_WEXT=y CONFIG_DRIVER_NL80211=y CONFIG_LIBNL32=y CONFIG_PKCS12=y
CONFIG_CTRL_IFACE=y CONFIG_BACKEND=file CONFIG_TLS=internal
CONFIG_INTERNAL_LIBTOMMATH=y CONFIG_INTERNAL_LIBTOMMATH_FAST=y
CONFIG_CTRL_IFACE_DBUS_INTRO=y CONFIG_DEBUG_FILE=y CONFIG_IEEE80211AC=y
CONFIG_MATCH_IFACE=y CONFIG_BGSCAN_SIMPLE=y

Symbol check on the unstripped binary — the two features are gone and the association and PSK
paths are untouched:

tdls                 0
wpa_ft_              0
sme_                 24
wpa_pmk              1
pbkdf2               1
wpa_supplicant_init  4

On the camera, after flashing and rebooting:

OPENIPC_VERSION=2.6.08.27
 08:05:28 up 4 min,  load average: 0.46, 0.26, 0.10

/usr/sbin/wpa_supplicant  455248 B
/usr/sbin/wpa_cli          67864 B
/usr/sbin/wpa_passphrase   30176 B

wpa_supplicant v2.10
wpa_cli v2.10
network={ ssid="TestNet" psk=45c21ffa733326253794a222c4875b3e20623f1d6615916e707072d14dcd3cb1 }

Daemon start, control interface and the wpa_cli round-trip, exercised on the camera without WiFi
hardware via the global control socket:

=== daemon + global ctrl_iface + wpa_cli round-trip ===
Successfully initialized wpa_supplicant
  daemon up (pid 790)
  -- wpa_cli ping:
PONG
  -- add an interface:
FAIL              <- expected, no such netdev

=== config parser handles a real PSK network block ===
Could not read interface nosuchdev flags: No such device    <- expected
(no parse errors)

majestic still runs and serves frames on the flashed camera:

majestic: running
snapshot: http 200, 36659 B

Link closure over the rebuilt rootfs is unchanged from baseline — the same 25 pre-existing
libc.so.0 findings from the uClibc-built Goke vendor blobs, no new unresolved links.

Repo gates:

ci-matrix: self-test ok (99 boards, 132 packages, 52 cases)
ci-matrix: 99/99 boards --- general/external.mk affects every board
checked 129 shell script(s) / all parsed clean under busybox ash
All strip-shell-comments checks passed.
all run blocks parse clean
All load_hisilicon regression checks passed.
All sysupgrade verification checks passed.

Scope

  • No kernel patches under general/package/all-patches/linux/
  • No files specific to a single retail camera model
  • No probing or bring-up tooling
  • Nothing under general/overlay/ or in a shared load_<vendor> script hardcodes a value specific to my board
  • No package sources or version pins are touched by this PR
  • No LD_PRELOAD, and no binaries that cannot be rebuilt from source
  • ci-matrix.py widens general/external.mk to the full 99-board matrix

Buildroot leaves upstream's wpa_supplicant defconfig defaults for
CONFIG_TDLS and CONFIG_IEEE80211R in place and offers no Kconfig switch
for either, so every board that enables wpa_supplicant carries both.
Neither can fire on a camera. TDLS sets up direct station-to-station
data links, and a camera only ever talks to its AP; 802.11r is fast BSS
transition between APs, and a fixed-mount camera does not roam.

On gk7205v300_lite the binary goes 500,304 -> 455,248 and the rootfs
squashfs 4924KB -> 4904KB. rootfs.cpio loses the full 45,056 bytes.

Appending to the package's own CONFIG_DISABLE list rather than patching
its defconfig works because Buildroot includes external.mk after
package/*/*.mk and expands WPA_SUPPLICANT_CONFIGURE_CMDS when the rule
runs, so there is nothing to rebase when the package is bumped.

Everything else in the config was measured and left alone.
CONFIG_PKCS12, CONFIG_CTRL_IFACE_DBUS_INTRO and CONFIG_IEEE80211AC each
cost exactly zero bytes here -- the first two need TLS and D-Bus, which
are not built, and the third is compiled unconditionally in 2.10. WEXT
stays because the shipped wlan0 script asks for `-D nl80211,wext` and
the wiki documents `-D wext` alone. wpa_cli stays because
majestic-webui's network.cgi uses it as its primary wifi scan path.
@qodo-free-for-open-source-projects

Copy link
Copy Markdown

PR Summary by Qodo

Disable unused TDLS and 802.11r support in wpa_supplicant

⚙️ Configuration changes ✨ Enhancement 🕐 Less than 10 minutes

Grey Divider

AI Description

• Disables camera-inapplicable TDLS and fast-roaming support across all wpa_supplicant builds.
• Reduces the stripped daemon by approximately 45 KB without affecting required Wi-Fi paths.
• Uses the external Buildroot configuration hook to avoid maintaining a package patch.
Diagram

graph TD
  A["Buildroot package"] --> B["External config"] --> C["Feature disable list"] --> D["wpa_supplicant build"] --> E["Smaller camera image"]
Loading
High-Level Assessment

Appending to Buildroot's existing WPA_SUPPLICANT_CONFIG_DISABLE variable is the best fit: it removes only unsupported features, applies consistently across boards, and avoids a defconfig patch that would require rebasing on package upgrades. A package patch was considered but provides no compensating benefit.

Files changed (1) +17 / -0

Other (1) +17 / -0
external.mkDisable unused wpa_supplicant TDLS and fast-roaming features +17/-0

Disable unused wpa_supplicant TDLS and fast-roaming features

• Appends CONFIG_TDLS and CONFIG_IEEE80211R to Buildroot's wpa_supplicant disable list for all OpenIPC boards. Comments document the camera-specific rationale, measured size savings, and dependency on Buildroot include and expansion ordering.

general/external.mk

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can ask Qodo to dismiss a finding you disagree with, with your reason on record

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@openipc-ai
openipc-ai merged commit d32aca0 into master Aug 27, 2026
111 of 112 checks passed
@openipc-ai
openipc-ai deleted the wpa-supplicant-drop-tdls-11r branch August 27, 2026 08:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant