[esp32] Trim mbedTLS to client-only defaults and stub vasprintf on the C6

Linking an HTTPS client (http_request, mqtt) pulls in TLS features no
ESPHome client ever negotiates: the server-side handshake, static RSA and
static ECDH key exchange, renegotiation, session tickets, AES-CCM suites,
the EC private-key parsing extras and deterministic ECDSA. Two new esp32
advanced options, on by default, turn them off and save around 14 KB per
build; OpenThread opts back in through require hooks because its DTLS
commissioner is a server and it uses CCM and deterministic ECDSA directly.

On the ESP32-C6 the ROM exports a full-format vsnprintf but no vasprintf,
so esp_http_client's vasprintf call was the only thing dragging newlib's
printf engine (~20 KB) into the image. A linker-wrapped vasprintf built on
the ROM vsnprintf keeps it out.
This commit is contained in:
Jesse Hills
2026-09-11 16:56:08 +12:00
parent 3e3822e554
commit bfb8569636
11 changed files with 288 additions and 0 deletions
@@ -17,6 +17,8 @@ esp32:
disable_dev_null_vfs: true
disable_mbedtls_peer_cert: true
disable_mbedtls_pkcs7: true
disable_mbedtls_tls_server: true
disable_mbedtls_tls_extras: true
disable_regi2c_in_iram: true
disable_fatfs: true
sram1_as_iram: true