From 0aec17ce74e8550781068e7939fdb02783abaeae Mon Sep 17 00:00:00 2001 From: Dmitry Ilyin <6576495+widgetii@users.noreply.github.com> Date: Wed, 16 Sep 2026 22:34:03 +0300 Subject: [PATCH 1/3] hi3519v101: drop the USB gadget stack nothing composes hi3519v101_lite is 16KB over its 5120KB squashfs cap on master (nightly 35129237971). Nothing in this repository grew to do it -- the board was at 5112KB with an 8KB headroom warning in the previous green nightly, and the unpinned majestic/majestic-webui refs moved it the rest of the way. #2420 has the fleet-wide analysis. This removes what the board ships but cannot load. The legacy gadget drivers g_ether, g_mass_storage and g_serial were the only things selecting libcomposite, u_ether, u_serial and the f_acm/f_serial/f_obex/f_ecm/f_subset/ f_rndis/f_mass_storage functions, and nothing on the image loads any of them: usb-dual-role is the tree's sole gadget consumer, no defconfig selects it, and since #2421 it carries its own kernel symbols, so enabling it on a board brings libcomposite and configfs back. USB_CONFIGFS was already off here, so the gadget could not even be composed the modern way. mdev.conf has no $MODALIAS rule and S40network dispatches only on the wlandev U-Boot variable, so a module is loadable if and only if a script names it. None names these. USB_GADGET stays =y and USB_HISI_UDC stays: neither costs squashfs and the vendor PHY plumbing hangs off them. Only the functions go. Left alone, having checked: SCSI is live here, unlike #2410's hi3518ev300 -- USB_STORAGE=y and USB_EHCI_HCD=y give it a real transport. R8188EU stays, per the #2404 determination recorded in this same file: it is the only symbol selecting WIRELESS_EXT on this board, and the out-of-tree drivers /etc/wireless/usb modprobes need that ioctl ABI. Refs #2420 --- .../hi3519v101/hi3519v101.generic.config | 28 +++++++++---------- 1 file changed, 13 insertions(+), 15 deletions(-) diff --git a/br-ext-chip-hisilicon/board/hi3519v101/hi3519v101.generic.config b/br-ext-chip-hisilicon/board/hi3519v101/hi3519v101.generic.config index ef6e5491b9..c5179d772a 100644 --- a/br-ext-chip-hisilicon/board/hi3519v101/hi3519v101.generic.config +++ b/br-ext-chip-hisilicon/board/hi3519v101/hi3519v101.generic.config @@ -1832,27 +1832,25 @@ CONFIG_USB_HISI_UDC=m # CONFIG_USB_NET2272 is not set # CONFIG_USB_GADGET_XILINX is not set # CONFIG_USB_DUMMY_HCD is not set -CONFIG_USB_LIBCOMPOSITE=m -CONFIG_USB_F_ACM=m -CONFIG_USB_U_SERIAL=m -CONFIG_USB_U_ETHER=m -CONFIG_USB_F_SERIAL=m -CONFIG_USB_F_OBEX=m -CONFIG_USB_F_ECM=m -CONFIG_USB_F_SUBSET=m -CONFIG_USB_F_RNDIS=m -CONFIG_USB_F_MASS_STORAGE=m +# The gadget functions went with the legacy g_ether/g_mass_storage/g_serial +# drivers that were the only things selecting them. Nothing on this image +# composes a gadget: usb-dual-role is the sole consumer in the tree, no +# defconfig selects it, and it now carries its own kernel symbols, so a board +# that enables it gets libcomposite/configfs back. mdev.conf has no $MODALIAS +# rule and S40network dispatches only on the wlandev U-Boot variable, so a +# module is loadable if and only if a script names it -- and none names these. +# USB_GADGET and the HiSilicon UDC stay: they cost no squashfs and the vendor +# PHY plumbing hangs off them. Same mechanism as #2421. # CONFIG_USB_CONFIGFS is not set # CONFIG_USB_ZERO is not set # CONFIG_USB_AUDIO is not set -CONFIG_USB_ETH=m -CONFIG_USB_ETH_RNDIS=y +# CONFIG_USB_ETH is not set # CONFIG_USB_ETH_EEM is not set # CONFIG_USB_G_NCM is not set # CONFIG_USB_GADGETFS is not set # CONFIG_USB_FUNCTIONFS is not set -CONFIG_USB_MASS_STORAGE=m -CONFIG_USB_G_SERIAL=m +# CONFIG_USB_MASS_STORAGE is not set +# CONFIG_USB_G_SERIAL is not set # CONFIG_USB_G_PRINTER is not set # CONFIG_USB_CDC_COMPOSITE is not set # CONFIG_USB_G_ACM_MS is not set @@ -2081,7 +2079,7 @@ CONFIG_TMPFS=y # CONFIG_TMPFS_POSIX_ACL is not set # CONFIG_TMPFS_XATTR is not set # CONFIG_HUGETLB_PAGE is not set -CONFIG_CONFIGFS_FS=m +# CONFIG_CONFIGFS_FS is not set CONFIG_MISC_FILESYSTEMS=y # CONFIG_ADFS_FS is not set # CONFIG_AFFS_FS is not set From 053eef256004369898b56e2d80fadc63dd9d02c5 Mon Sep 17 00:00:00 2001 From: Dmitry Ilyin <6576495+widgetii@users.noreply.github.com> Date: Wed, 16 Sep 2026 22:34:03 +0300 Subject: [PATCH 2/3] gk7202v300: drop the staging r8188eu nothing can load gk7202v300_lite is 16KB over its 5120KB squashfs cap on master (nightly 35129237971). It finished the 2026-09-14 nightly at exactly 5120/5120 and #2421 bought it 32KB; upstream majestic/majestic-webui drift has since taken 48KB of that back. #2420 called this out as the largest single win left on the board. The in-tree staging r8188eu driver was never reachable. /etc/wireless/usb's profiles modprobe '8188eu', the out-of-tree rtl8188eus-openipc module, which neither gk7202v300 defconfig selects; nothing anywhere modprobes 'r8188eu'; mdev.conf has no hotplug rule and S40network dispatches only on the wlandev U-Boot variable. 431,588 B of .ko with no way to load it. No firmware blob goes with it here -- unlike #2410's hi3518ev300, this board never selected LINUX_FIRMWARE_OPENIPC_RTL_8188EU. MT7601U stays as the SoC's one in-tree USB Wi-Fi stack, and the ultimate keeps out-of-tree rtl8188fu. WIRELESS_EXT goes with it, R8188EU having been its only selector here. Safe by the same four checks as #2410: wlan0 runs wpa_supplicant -D nl80211,wext with nl80211 first; the WebUI scans via wpa_cli and reaches iwlist only behind a `command -v` guard; rtl8188fu is compiled with -DCONFIG_IOCTL_CFG80211 and registers a wiphy, verified in the driver's own Makefile; and iwconfig/iwlist/ iwpriv already did nothing for mt7601u because CFG80211_WEXT is off. This is the opposite answer to #2404 on hi3519v101, where out-of-tree drivers did need the wext ABI -- both determinations are now written into their board configs. Refs #2420 --- .../board/gk7205v200/gk7202v300.generic.config | 16 ++++++++++------ 1 file changed, 10 insertions(+), 6 deletions(-) diff --git a/br-ext-chip-goke/board/gk7205v200/gk7202v300.generic.config b/br-ext-chip-goke/board/gk7205v200/gk7202v300.generic.config index 19a6331014..6bcbfac58d 100644 --- a/br-ext-chip-goke/board/gk7205v200/gk7202v300.generic.config +++ b/br-ext-chip-goke/board/gk7205v200/gk7202v300.generic.config @@ -806,10 +806,15 @@ CONFIG_BQL=y # CONFIG_AF_KCM is not set # CONFIG_STREAM_PARSER is not set CONFIG_WIRELESS=y -CONFIG_WIRELESS_EXT=y -CONFIG_WEXT_CORE=y -CONFIG_WEXT_PROC=y -CONFIG_WEXT_PRIV=y +# Wireless extensions went with R8188EU below, which was the only symbol here +# that selected WIRELESS_EXT. Nothing on these images needs the wext ioctl ABI: +# mt7601u is a mac80211 driver and wpa_supplicant drives it over nl80211, the +# WebUI scans with wpa_cli and only falls back to iwlist behind a `command -v` +# guard, and the out-of-tree rtl8188fu the ultimate ships is compiled with +# -DCONFIG_IOCTL_CFG80211, so it registers a wiphy. iwconfig/iwlist/iwpriv +# already did nothing for mt7601u because CFG80211_WEXT is off below. Same +# determination as #2410 on hi3518ev300 -- and the opposite of #2404 on +# hi3519v101, where out-of-tree drivers did need wext and R8188EU had to stay. CONFIG_CFG80211=y # CONFIG_NL80211_TESTMODE is not set # CONFIG_CFG80211_DEVELOPER_WARNINGS is not set @@ -2013,8 +2018,7 @@ CONFIG_STAGING=y # CONFIG_COMEDI is not set # CONFIG_RTLLIB is not set # CONFIG_R8712U is not set -CONFIG_R8188EU=m -CONFIG_88EU_AP_MODE=y +# CONFIG_R8188EU is not set # CONFIG_VT6656 is not set # From 7b6d37676d0a6c5fa67a2cc62ca07541af333995 Mon Sep 17 00:00:00 2001 From: Dmitry Ilyin <6576495+widgetii@users.noreply.github.com> Date: Wed, 16 Sep 2026 22:40:03 +0300 Subject: [PATCH 3/3] gk7205v300: build the crypto modules into the kernel, off the rootfs gk7205v300_lite was 4KB over its cap on master (nightly 35129237971). The ipctool trim ahead of this brings it back to exactly 5120/5120 -- inside the cap, but at zero headroom, which is where it sat before #2421 and where the next upstream majestic bump puts it back over. Daily growth has been 12-44KB; passing by 0KB is not passing for long. The gadget lever is already spent here (#2421), and unlike gk7202v300 this board has no staging r8188eu to drop. What is left is the build-in trade from #2397: the same 17 crypto symbols move from =m to =y, off the rootfs and into the kernel partition, which has 238KB free. Nothing chooses to load these. The kernel crypto API resolves them through its own request_module(), which is why #2397 built them in rather than deleting them -- deleting would break wireguard, mac80211's CCMP/GCMP and dropbear's kernel-side AEAD. Built in, every consumer keeps working and the .ko stop occupying flash. The cost is a constant: #2397 measured +12,720 B of uImage for exactly this set on hi3518ev300, and #2420 reproduced it to the byte on gk7205v300 while surveying the levers. 12KB against 238KB of kernel headroom. Not taken here: #2420's variant D, which also builds in cfg80211/mac80211/ mt7601u for a much larger rootfs win. It leaves only 39KB of kernel headroom and makes every camera carry ~730KB of Wi-Fi stack text in RAM whether a dongle is ever plugged in or not. That is the trap the issue names, and the reason #2397 built in only the crypto helpers. Refs #2420 --- .../gk7205v200/gk7205v300.generic.config | 34 +++++++++---------- 1 file changed, 17 insertions(+), 17 deletions(-) diff --git a/br-ext-chip-goke/board/gk7205v200/gk7205v300.generic.config b/br-ext-chip-goke/board/gk7205v200/gk7205v300.generic.config index 67234e375c..4311d110e0 100644 --- a/br-ext-chip-goke/board/gk7205v200/gk7205v300.generic.config +++ b/br-ext-chip-goke/board/gk7205v200/gk7205v300.generic.config @@ -2652,26 +2652,26 @@ CONFIG_CRYPTO=y # CONFIG_CRYPTO_ALGAPI=y CONFIG_CRYPTO_ALGAPI2=y -CONFIG_CRYPTO_AEAD=m +CONFIG_CRYPTO_AEAD=y CONFIG_CRYPTO_AEAD2=y CONFIG_CRYPTO_BLKCIPHER=y CONFIG_CRYPTO_BLKCIPHER2=y CONFIG_CRYPTO_HASH=y CONFIG_CRYPTO_HASH2=y -CONFIG_CRYPTO_RNG=m +CONFIG_CRYPTO_RNG=y CONFIG_CRYPTO_RNG2=y -CONFIG_CRYPTO_RNG_DEFAULT=m +CONFIG_CRYPTO_RNG_DEFAULT=y CONFIG_CRYPTO_AKCIPHER2=y CONFIG_CRYPTO_KPP2=y # CONFIG_CRYPTO_RSA is not set # CONFIG_CRYPTO_DH is not set # CONFIG_CRYPTO_ECDH is not set -CONFIG_CRYPTO_MANAGER=m +CONFIG_CRYPTO_MANAGER=y CONFIG_CRYPTO_MANAGER2=y # CONFIG_CRYPTO_USER is not set CONFIG_CRYPTO_MANAGER_DISABLE_TESTS=y -CONFIG_CRYPTO_GF128MUL=m -CONFIG_CRYPTO_NULL=m +CONFIG_CRYPTO_GF128MUL=y +CONFIG_CRYPTO_NULL=y CONFIG_CRYPTO_NULL2=y CONFIG_CRYPTO_WORKQUEUE=y # CONFIG_CRYPTO_CRYPTD is not set @@ -2682,17 +2682,17 @@ CONFIG_CRYPTO_WORKQUEUE=y # # Authenticated Encryption with Associated Data # -CONFIG_CRYPTO_CCM=m -CONFIG_CRYPTO_GCM=m +CONFIG_CRYPTO_CCM=y +CONFIG_CRYPTO_GCM=y # CONFIG_CRYPTO_CHACHA20POLY1305 is not set -CONFIG_CRYPTO_SEQIV=m -CONFIG_CRYPTO_ECHAINIV=m +CONFIG_CRYPTO_SEQIV=y +CONFIG_CRYPTO_ECHAINIV=y # # Block modes # # CONFIG_CRYPTO_CBC is not set -CONFIG_CRYPTO_CTR=m +CONFIG_CRYPTO_CTR=y # CONFIG_CRYPTO_CTS is not set # CONFIG_CRYPTO_ECB is not set # CONFIG_CRYPTO_LRW is not set @@ -2704,7 +2704,7 @@ CONFIG_CRYPTO_CTR=m # Hash modes # # CONFIG_CRYPTO_CMAC is not set -CONFIG_CRYPTO_HMAC=m +CONFIG_CRYPTO_HMAC=y # CONFIG_CRYPTO_XCBC is not set # CONFIG_CRYPTO_VMAC is not set @@ -2712,9 +2712,9 @@ CONFIG_CRYPTO_HMAC=m # Digest # CONFIG_CRYPTO_CRC32C=y -CONFIG_CRYPTO_CRC32=m +CONFIG_CRYPTO_CRC32=y CONFIG_CRYPTO_CRCT10DIF=y -CONFIG_CRYPTO_GHASH=m +CONFIG_CRYPTO_GHASH=y # CONFIG_CRYPTO_POLY1305 is not set # CONFIG_CRYPTO_MD4 is not set CONFIG_CRYPTO_MD5=y @@ -2763,12 +2763,12 @@ CONFIG_CRYPTO_LZO=y # Random Number Generation # # CONFIG_CRYPTO_ANSI_CPRNG is not set -CONFIG_CRYPTO_DRBG_MENU=m +CONFIG_CRYPTO_DRBG_MENU=y CONFIG_CRYPTO_DRBG_HMAC=y # CONFIG_CRYPTO_DRBG_HASH is not set # CONFIG_CRYPTO_DRBG_CTR is not set -CONFIG_CRYPTO_DRBG=m -CONFIG_CRYPTO_JITTERENTROPY=m +CONFIG_CRYPTO_DRBG=y +CONFIG_CRYPTO_JITTERENTROPY=y # CONFIG_CRYPTO_USER_API_HASH is not set # CONFIG_CRYPTO_USER_API_SKCIPHER is not set # CONFIG_CRYPTO_USER_API_RNG is not set