do_configure built wpa_supplicant's .config by sed-ing upstream's
defconfig and echoing CONFIG lines onto it, this is both fragile and
makes handling anything not covered by PACKAGECONFIG tricky.

wpa_supplicant has no configure script and no kconfig - it's just make,
so switch do_configure to build the configuration from a base file and
.cfg fragments, which matches what CML1 recipes do (though this isn't
CML1).

This should have no functional change; the effective configuration
should be identical.

AI-Generated: Claude Opus 5 (Claude Code)
Signed-off-by: Alex Kiernan <[email protected]>
---
 .../wpa-supplicant/wpa-supplicant/mbo.cfg     |  2 +
 .../wpa-supplicant/wpa-supplicant/suiteb.cfg  |  4 ++
 .../wpa-supplicant/tls-gnutls.cfg             | 23 ++++++++++
 .../wpa-supplicant/tls-openssl.cfg            |  7 +++
 .../wpa-supplicant/wpa-supplicant/wnm.cfg     |  2 +
 .../wpa-supplicant/wpa-supplicant_2.12.bb     | 46 +++++++------------
 6 files changed, 55 insertions(+), 29 deletions(-)
 create mode 100644 
meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/mbo.cfg
 create mode 100644 
meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/suiteb.cfg
 create mode 100644 
meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/tls-gnutls.cfg
 create mode 100644 
meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/tls-openssl.cfg
 create mode 100644 
meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/wnm.cfg

diff --git a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/mbo.cfg 
b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/mbo.cfg
new file mode 100644
index 000000000000..d869f79d722a
--- /dev/null
+++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/mbo.cfg
@@ -0,0 +1,2 @@
+# Support Multi Band Operation
+CONFIG_MBO=y
diff --git a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/suiteb.cfg 
b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/suiteb.cfg
new file mode 100644
index 000000000000..ca752a9730d9
--- /dev/null
+++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/suiteb.cfg
@@ -0,0 +1,4 @@
+# Suite B cryptography support. Not offered by upstream's defconfig; the
+# symbols are read directly by wpa_supplicant/Makefile.
+CONFIG_SUITEB=y
+CONFIG_SUITEB192=y
diff --git 
a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/tls-gnutls.cfg 
b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/tls-gnutls.cfg
new file mode 100644
index 000000000000..f3f2f8eed8c8
--- /dev/null
+++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/tls-gnutls.cfg
@@ -0,0 +1,23 @@
+# Select TLS implementation
+# openssl = OpenSSL (default)
+# gnutls = GnuTLS
+# internal = Internal TLSv1 implementation (experimental)
+# linux = Linux kernel AF_ALG and internal TLSv1 implementation (experimental)
+# none = Empty template
+CONFIG_TLS=gnutls
+
+# The following need functionality the GnuTLS backend does not provide, so they
+# are turned back off here. "undefine" rather than an empty assignment leaves
+# exactly the state the previous approach of commenting the lines out produced.
+
+# Device Provisioning Protocol (DPP) (also known as Wi-Fi Easy Connect)
+undefine CONFIG_DPP
+
+# EAP-pwd (secure authentication using only a password)
+undefine CONFIG_EAP_PWD
+
+# Simultaneous Authentication of Equals (SAE), WPA3-Personal
+undefine CONFIG_SAE
+
+# Opportunistic Wireless Encryption (OWE)
+undefine CONFIG_OWE
diff --git 
a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/tls-openssl.cfg 
b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/tls-openssl.cfg
new file mode 100644
index 000000000000..542c4bcb5007
--- /dev/null
+++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/tls-openssl.cfg
@@ -0,0 +1,7 @@
+# Select TLS implementation
+# openssl = OpenSSL (default)
+# gnutls = GnuTLS
+# internal = Internal TLSv1 implementation (experimental)
+# linux = Linux kernel AF_ALG and internal TLSv1 implementation (experimental)
+# none = Empty template
+CONFIG_TLS=openssl
diff --git a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/wnm.cfg 
b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/wnm.cfg
new file mode 100644
index 000000000000..5d07b15cdf72
--- /dev/null
+++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/wnm.cfg
@@ -0,0 +1,2 @@
+# Wireless Network Management (IEEE Std 802.11v-2011)
+CONFIG_WNM=y
diff --git a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant_2.12.bb 
b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant_2.12.bb
index df0585f1f3c4..df46535043cc 100644
--- a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant_2.12.bb
+++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant_2.12.bb
@@ -14,6 +14,7 @@ SRC_URI = "http://w1.fi/releases/wpa_supplicant-${PV}.tar.gz \
            file://wpa-supplicant.sh \
            file://wpa_supplicant.conf-sane \
            file://99_wpa_supplicant \
+           ${PACKAGECONFIG_CONFARGS} \
            "
 SRC_URI[sha256sum] = 
"08e23937e16d0155e55cab2b51f51fbe10d80a1aa91c4e15442645059b737ef6"
 
@@ -21,12 +22,22 @@ S = "${UNPACKDIR}/wpa_supplicant-${PV}"
 
 inherit pkgconfig systemd
 
+# There is no configure script, so use PACKAGECONFIG_CONFARGS to deliver
+# additional fragments
 PACKAGECONFIG ?= "openssl"
-PACKAGECONFIG[gnutls] = ",,gnutls libgcrypt"
-PACKAGECONFIG[openssl] = ",,openssl"
-PACKAGECONFIG[suiteb] = ",,"
-PACKAGECONFIG[wnm] = ",,"
-PACKAGECONFIG[mbo] = ",,"
+PACKAGECONFIG[gnutls] = "file://tls-gnutls.cfg,,gnutls libgcrypt,,,openssl"
+PACKAGECONFIG[openssl] = "file://tls-openssl.cfg,,openssl,,,gnutls"
+PACKAGECONFIG[suiteb] = "file://suiteb.cfg"
+PACKAGECONFIG[wnm] = "file://wnm.cfg"
+PACKAGECONFIG[mbo] = "file://mbo.cfg"
+
+# The base wpa-supplicant config from the upstream recipe
+WPA_SUPPLICANT_CONFIG ?= "${S}/wpa_supplicant/defconfig"
+
+# The same selection cml1.bbclass makes with find_cfgs(); we don't inherit cml1
+# because we don't support menuconfig etc.
+def wpa_supplicant_cfgs(d):
+    return [s for s in src_patches(d, True) if s.endswith('.cfg')]
 
 CVE_PRODUCT = "wpa_supplicant"
 
@@ -36,30 +47,7 @@ EXTRA_OEMAKE = "'LIBDIR=${libdir}' 'INCDIR=${includedir}' 
'BINDIR=${sbindir}'"
 
 do_configure () {
        ${MAKE} -C wpa_supplicant clean
-       sed -e '/^CONFIG_TLS=/d' <wpa_supplicant/defconfig 
>wpa_supplicant/.config
-
-       if ${@ bb.utils.contains('PACKAGECONFIG', 'openssl', 'true', 'false', 
d) }; then
-               echo 'CONFIG_TLS=openssl' >>wpa_supplicant/.config
-       elif ${@ bb.utils.contains('PACKAGECONFIG', 'gnutls', 'true', 'false', 
d) }; then
-               echo 'CONFIG_TLS=gnutls' >>wpa_supplicant/.config
-               sed -i -e 's/\(^CONFIG_DPP=\)/#\1/' \
-                   -e 's/\(^CONFIG_EAP_PWD=\)/#\1/' \
-                   -e 's/\(^CONFIG_SAE=\)/#\1/' \
-                   -e 's/\(^CONFIG_OWE=\)/#\1/' wpa_supplicant/.config
-       fi
-
-       if ${@ bb.utils.contains('PACKAGECONFIG', 'suiteb', 'true', 'false', d) 
}; then
-               echo 'CONFIG_SUITEB=y' >>wpa_supplicant/.config
-               echo 'CONFIG_SUITEB192=y' >>wpa_supplicant/.config
-       fi
-
-       if ${@ bb.utils.contains('PACKAGECONFIG', 'wnm', 'true', 'false', d) }; 
then
-               echo 'CONFIG_WNM=y' >>wpa_supplicant/.config
-       fi
-
-       if ${@ bb.utils.contains('PACKAGECONFIG', 'mbo', 'true', 'false', d) }; 
then
-               echo 'CONFIG_MBO=y' >>wpa_supplicant/.config
-       fi
+       cat ${WPA_SUPPLICANT_CONFIG} ${@" ".join(wpa_supplicant_cfgs(d))} > 
wpa_supplicant/.config
 
        # For rebuild
        rm -f wpa_supplicant/*.d wpa_supplicant/dbus/*.d
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#244729): 
https://lists.openembedded.org/g/openembedded-core/message/244729
Mute This Topic: https://lists.openembedded.org/mt/121009603/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to