The previous implementation extended `track_yaml_loads` across the entire
validation pass to catch deferred `!include` and package loads, but that also
captured framework YAML loaded internally by component validators (e.g.
LVGL's `hello_world.yaml`) and produced spurious "unresolved substitution"
warnings during the pre-validation force-load. bundle.py already had the
right pattern: a fresh post-validation re-parse plus `force_load_include_files`.
- Lift the discovery into `yaml_util.discover_user_yaml_files` and have both
`bundle.py` and `config.py` use it (DRY).
- Capture `secrets.yaml` / `secrets.yml` by the *un-resolved* listener fname
so a `secrets.yaml` symlinked to a non-secrets-named target is still
flagged for redaction.
- Add a `warn_on_unresolved` flag to `force_load_include_files` so the
discovery path (where substitutions haven't run) logs at debug instead of
warning.
- Reject `store_yaml` configs with an unencrypted API via
`FINAL_VALIDATE_SCHEMA`; an explicit `allow_unencrypted: true` opt-out
keeps lab setups working (renamed from `allow_unencrypted_api` so the
integration-test harness's naive `api:` string replacement doesn't
clobber it).
- Annotate `store_yaml_chunk_buf` with the
`cppcoreguidelines-avoid-non-const-global-variables` suppression that
matches other intentional API-side globals.
- Update unit tests to exercise the new `DiscoveredYamlFiles` shape plus a
symlink-secrets case.
Compiles a host build with `store_yaml`, drives a raw plaintext API socket
(the released aioesphomeapi does not yet know about GetYamlRequest /
GetYamlResponse and would silently drop the streamed bytes as "unknown
message type"), sends GetYamlRequest, accumulates the streamed
GetYamlResponse chunks until done=true, zstd-decompresses, and verifies
both the envelope structure and that the fixture's distinctive markers
(`store-yaml-test`, `store_yaml:`) round-trip back through the recovery
blob.
- Advertise `has_store_yaml` in DeviceInfoResponse so recovery tooling can
detect support without timing out against firmware built without
USE_STORE_YAML.
- Suppress GetYamlResponse from the proto dump path. Every chunk would
otherwise log embedded configuration (including opted-in secrets) on
builds with HAS_PROTO_MESSAGE_DUMP, and bloat logs during recovery.
- Preserve the include graph for files outside the project root: use
`os.path.relpath` instead of just the basename so e.g. two
`../common.yaml` siblings don't collide on recovery.
- Keep `track_yaml_loads` open across `validate_config` so files loaded
by remote packages and substitution-resolved includes are captured.
- Add focused unit tests for `_gather_files` (redaction, secrets.yml,
opt-in, dedupe, external-path handling, missing sources) and
`_pack_envelope` (round-trip, UTF-8 paths, overlong-path guard).
- Make the test_bundle assertion case-insensitive.
Adds a new opt-in component that compresses the on-disk YAML files with zstd
at codegen time and stores them in PROGMEM. The native API exposes a chunked
GetYaml RPC so a lost configuration can be retrieved from a running device.
Decompression happens client-side; no decompressor is shipped on-device.
Co-authored-by: pre-commit-ci-lite[bot] <117423508+pre-commit-ci-lite[bot]@users.noreply.github.com>
Co-authored-by: J. Nick Koston <nick@home-assistant.io>
Co-authored-by: pre-commit-ci-lite[bot] <117423508+pre-commit-ci-lite[bot]@users.noreply.github.com>
Co-authored-by: J. Nick Koston <nick@home-assistant.io>