[esp32] Respect user sdkconfig values in the TLS trims, keep EC key parsing

Review follow-ups: the FINAL reconcile job now uses the set-if-absent
helper so explicit sdkconfig_options win, and skips the whole TLS role
choice when the user set any of its members. The EC public-key parsing
options stay enabled because they decide whether a peer certificate with a
compressed point or explicit curve parameters parses. Adds an ESP32-C6
http_request compile test so CI links the vasprintf wrap, and suppresses
clang-tidy's no-malloc check on the allocation that vasprintf's contract
requires.
This commit is contained in:
Jesse Hills
2026-09-11 17:17:13 +12:00
parent bfb8569636
commit 72d694ddc5
5 changed files with 67 additions and 9 deletions
@@ -0,0 +1,17 @@
esphome:
name: test
esp32:
board: esp32dev
framework:
type: esp-idf
sdkconfig_options:
CONFIG_MBEDTLS_TLS_SERVER_AND_CLIENT: y
CONFIG_MBEDTLS_CCM_C: y
wifi:
ssid: "test_ssid"
password: "test_password"
http_request:
verify_ssl: true
+19
View File
@@ -1374,6 +1374,25 @@ def test_mbedtls_tls_trim_sdkconfig(
assert {sdkconfig.get(name) for name in MBEDTLS_TLS_EXTRA_OPTIONS} == {extras}
def test_mbedtls_tls_user_sdkconfig_wins(
generate_main: Callable[[str | Path], str],
component_config_path: Callable[[str], Path],
) -> None:
"""A user-set TLS role member leaves the whole choice alone; other user values are kept."""
generate_main(component_config_path("mbedtls_tls_user_sdkconfig.yaml"))
sdkconfig = CORE.data[KEY_ESP32][KEY_SDKCONFIG_OPTIONS]
assert sdkconfig.get("CONFIG_MBEDTLS_TLS_CLIENT_ONLY") is None
role = sdkconfig["CONFIG_MBEDTLS_TLS_SERVER_AND_CLIENT"]
assert isinstance(role, RawSdkconfigValue) and role.value == "y"
ccm = sdkconfig["CONFIG_MBEDTLS_CCM_C"]
assert isinstance(ccm, RawSdkconfigValue) and ccm.value == "y"
assert {
sdkconfig.get(name)
for name in MBEDTLS_TLS_EXTRA_OPTIONS
if name != "CONFIG_MBEDTLS_CCM_C"
} == {False}
def test_mbedtls_tls_openthread_requires_server_and_extras(
generate_main: Callable[[str | Path], str],
component_config_path: Callable[[str], Path],
@@ -0,0 +1,4 @@
substitutions:
verify_ssl: "true"
<<: !include common.yaml