Repository navigation
Expand file tree
/
Copy pathsdkconfig.defaults
More file actions
86 lines (72 loc) · 4.67 KB
/
Copy pathsdkconfig.defaults
File metadata and controls
86 lines (72 loc) · 4.67 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
# Tick rate. Originally raised for Arduino-as-IDF-component; kept because the existing
# timing code assumes a 1 ms tick.
CONFIG_FREERTOS_HZ=1000
# Keep the main task large enough for the init chain.
CONFIG_ESP_MAIN_TASK_STACK_SIZE=16384
# WiFi/IP event handlers (WiFiManager, GatewayConnectionManager) now run directly
# on the default event loop task instead of Arduino's separate 4096-byte event
# task. They do flatbuffer serialization + websocket broadcast, so restore that
# headroom here (default is 2304).
CONFIG_ESP_SYSTEM_EVENT_TASK_STACK_SIZE=4096
# Arduino expects these selected via ENABLE_ARDUINO_DEPENDS, but be explicit
CONFIG_LWIP_SO_RCVBUF=y
# Let application use exceptions-free C++ (matches build_flags -fno-exceptions)
CONFIG_COMPILER_CXX_EXCEPTIONS=n
# Arduino NetworkClientSecure (pulled in transitively by WebSockets/WiFiClientSecure)
# refuses to compile its ssl_client.cpp body unless at least one PSK exchange is
# enabled, otherwise all ssl_* symbols become unresolved at link time. We don't
# actually use PSK, but we need MBEDTLS_KEY_EXCHANGE_SOME_PSK_ENABLED to be defined.
CONFIG_MBEDTLS_PSK_MODES=y
CONFIG_MBEDTLS_KEY_EXCHANGE_PSK=y
# Captive portal serves HTTP + WebSocket from a single esp_http_server. WebSocket
# support is compiled out of esp_http_server by default; enable it or the httpd_ws_*
# symbols don't exist.
CONFIG_HTTPD_WS_SUPPORT=y
# The URI handler is not called for the handshake itself, so greeting a new client (the Ready message with the config
# and valid GPIO pins) needs the post-handshake callback.
CONFIG_HTTPD_WS_POST_HANDSHAKE_CB_SUPPORT=y
# TLS server-cert verification uses the mbedTLS certificate bundle. We compile in
# our own curated trust store (certificates/cacert-merged.pem) instead of IDF's built-in
# Mozilla list, so DEFAULT_NONE + a custom bundle. esp_http_client and
# esp_websocket_client attach it via config.crt_bundle_attach = esp_crt_bundle_attach.
#
# cacert-merged.pem is generated by certificates/cert_bundle.py: the verbatim curl/Mozilla
# base (certificates/cacert-curl.pem, checksum-verified on download) followed by
# certificates/pinned_certs/*.pem. Pinned roots cover anchors the Mozilla base has retired
# but our infra still chains through (e.g. GlobalSign Root CA R1, which cross-signs GTS
# Root R4). `cert_bundle.py audit` (the pinned-cert-audit CI workflow) monitors their
# expiry and relevance.
CONFIG_MBEDTLS_CERTIFICATE_BUNDLE=y
CONFIG_MBEDTLS_CERTIFICATE_BUNDLE_DEFAULT_NONE=y
CONFIG_MBEDTLS_CUSTOM_CERTIFICATE_BUNDLE=y
CONFIG_MBEDTLS_CUSTOM_CERTIFICATE_BUNDLE_PATH="certificates/cacert-merged.pem"
# Partition table: OpenShock uses a custom one; existing partitions stay valid
# (leave PARTITION_TABLE_* at IDF defaults; per-env sdkconfigs can override)
# The CONFIG_ARDUINO_SELECTIVE_* block that used to live here is gone. Arduino is no
# longer a component of this project - it is in neither dependencies.lock nor any
# idf_component.yml - so kconfgen reported every one of those symbols as unknown and
# discarded it. They were fourteen lines that did nothing.
#
# Still to review as part of finishing the de-Arduino migration: CONFIG_MBEDTLS_PSK_MODES
# and CONFIG_MBEDTLS_KEY_EXCHANGE_PSK above were only needed to make Arduino's
# NetworkClientSecure link, and CONFIG_LWIP_SO_RCVBUF was an Arduino dependency. All
# three are real settings that still take effect, so they are left alone here rather
# than changed as a side effect of a build-caching pass.
# Boot a freshly flashed OTA image as PENDING_VERIFY so otaSetup() validates it and a
# broken image rolls back to the previous slot instead of boot-looping. Needs the
# bootloader built with this option; devices that only receive OTA app updates keep
# their old bootloader and boot new images without the verify step.
CONFIG_BOOTLOADER_APP_ROLLBACK_ENABLE=y
# Parse JSON as RFC 8259 only. In lenient mode jsmn accepts input like {a:1} or {"x":{"a"},"b":1} and the
# navigation code can then return the wrong value for a key.
CONFIG_JSMN_STRICT=y
# Keep crash dumps in the (otherwise unused) coredump partition so field crashes can be read back over serial.
CONFIG_ESP_COREDUMP_ENABLE_TO_FLASH=y
# Captive portal httpd uses max_open_sockets (8) + 3 internal sockets, plus DNS server, HTTP client and gateway
# websocket sockets; the default of 10 would make httpd_start fail.
CONFIG_LWIP_MAX_SOCKETS=16
# The gateway websocket and the kept-alive HTTP client each hold a TLS session. With static
# buffers every session keeps a 16 KB input + 4 KB output record buffer for its whole life;
# dynamic buffers allocate them per record and shrink while idle, lowering the heap peak
# (e.g. while the captive portal links an account). Verify heap and throughput on a device.
CONFIG_MBEDTLS_DYNAMIC_BUFFER=y