Skip to content

Allow compiling out the DHCP client and UDP - #177

Merged
danielinux merged 2 commits into
wolfSSL:masterfrom
Frauschi:dhcp-optin
Sep 29, 2026
Merged

danielinux merged 2 commits into
wolfSSL:masterfrom
Frauschi:dhcp-optin

Conversation

@Frauschi

Copy link
Copy Markdown
Member

Summary

Static-address targets currently carry the whole DHCP client, and every target pays for the per-socket UDP buffers even when it never opens a UDP socket. This PR makes both removable at compile time. The defaults do not change: with no new settings, the preprocessed wolfip.c is identical to master.

  • WOLFIP_ENABLE_DHCP (default 1): set it to 0 to compile out the DHCP client, its DAD probe and conflict checks in arp_recv, and the dhcp_timer_recover() call in the poll loop. This is the macro the ports' config.h already use to decide whether to define DHCP, so a port that sets it to 0 now also drops the client from the library. DHCP keeps its meaning as the application-level switch for calling dhcp_client_init().
  • MAX_UDPSOCKETS 0 is now a supported configuration when DHCP is disabled. Every udpsockets[] access is already bounded by MAX_UDPSOCKETS, so at zero each UDP path becomes unreachable, wolfIP_sock_socket() finds no UDP slot, and DNS fails to allocate its socket. An #error rejects MAX_UDPSOCKETS 0 while DHCP is still enabled.

The DHCP declarations in wolfip.h stay ungated, so calling the API from a build that has DHCP disabled fails at link time with an unresolved symbol.

Savings

Measured on a TC4Dx TLS demo:

Configuration Flash RAM
WOLFIP_ENABLE_DHCP 0 -3012 bytes -
plus MAX_UDPSOCKETS 0 -2028 more bytes -18372 bytes

Testing

  • New Linux CI step: builds wolfip.c with WOLFIP_ENABLE_DHCP=0 and MAX_UDPSOCKETS 0 under -Wall -Werror -Wextra, and fails if any dhcp symbol is left in the object.
  • Compiled locally with -Wall -Werror -Wextra:
    • DHCP off with 2 UDP sockets
    • DHCP off with 0 UDP sockets
    • 0 UDP sockets plus IP_MULTICAST
    • 0 UDP sockets plus forwarding and loopback
    • the stm32h753 port config with DHCP off
  • With default settings, the preprocessed output is byte-identical to master, and make builds and links test-dns.
  • Unit suite not run locally; CI runs it.

Docs

  • docs/API.md: notes that the DHCP functions compile unless WOLFIP_ENABLE_DHCP is 0.
  • docs/dhcp_dns_howto.md: explains how to drop the client, and documents the no-UDP configuration.

The DHCP client was compiled into every build, and the poll loop calls
into it unconditionally, so --gc-sections could not drop it either. A
static-address target paid for a protocol it never runs.

Gate the implementation on WOLFIP_ENABLE_DHCP, defaulting to 1, so every
existing build is unchanged: with the default, the preprocessed wolfip.c
is identical to before. It is the macro the ports' config.h already use to
decide whether to define DHCP, so setting it to 0 there now also drops the
client from the library. DHCP keeps its meaning as the application-level
switch for calling dhcp_client_init().

Guarded are the client itself, the DAD probe, the two DAD conflict checks
in arp_recv, and the poll loop's dhcp_timer_recover() call. The dhcp_*
fields stay in struct wolfIP: a few dozen bytes, and keeping them lets the
DHCP_IS_RUNNING() checks stay plain runtime tests that are always false.
The declarations in wolfip.h stay ungated: an unresolved call is a clearer
error than an undeclared one.

Measured on a TC4Dx TLS demo with WOLFIP_ENABLE_DHCP 0: 3012 bytes of
flash, and no dhcp symbols in the image.
@Frauschi Frauschi self-assigned this Sep 28, 2026
With WOLFIP_ENABLE_DHCP 0, MAX_UDPSOCKETS 0 already compiles and
behaves: every udpsockets[] access is either a loop bounded by
MAX_UDPSOCKETS or preceded by its own ">= MAX_UDPSOCKETS" check, so at zero
each UDP path becomes unreachable rather than unsafe, and
wolfIP_sock_socket() finds no slot to hand out. DNS goes with it: it
cannot open its socket, and the linker drops it. The one unchecked access
was in the DHCP client, which that setting compiles out. An #error
rejects MAX_UDPSOCKETS 0 while DHCP is still enabled, since the client
needs a UDP socket.

Document the configuration so it is supported rather than accidental, and
build it in CI (with the check that no DHCP symbols are left) so it stays
that way. The zero-length array is the same GNU extension
struct dhcp_option::data already uses.

Measured on a TC4Dx TLS demo, on top of gating DHCP: 2028 more bytes of
flash and 18372 bytes of RAM, the per-socket UDP buffers that no longer
exist.
@Frauschi

Copy link
Copy Markdown
Member Author

@wolfSSL-Fenrir-bot review

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #177

Scan targets checked: wolfip-src, wolfip-bugs
Coverage: 1 of 1 in-scope changed file(s) opened by the reviewer

Fenrir result: Approved ✅

No new issues found in the changed files.

Advisory only — this automated result does not count as a GitHub approval.

Review tier: Lite

@Frauschi Frauschi assigned wolfSSL-Bot and unassigned Frauschi Sep 28, 2026
@Frauschi
Frauschi requested a review from danielinux September 28, 2026 10:45
@danielinux
danielinux merged commit 5b2b6cb into wolfSSL:master Sep 29, 2026
47 checks passed
@Frauschi
Frauschi deleted the dhcp-optin branch September 29, 2026 08:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants