Rebuild the framework with smaller TLS buffers (ADR 0006)

custom_sdkconfig makes pioarduino regenerate the ESP-IDF libraries:
asymmetric TLS buffers (16 KB in, 4 KB out) and dynamic buffers that
free handshake-only data once connected. The rebuild also follows the
board: no PSRAM, 8 MB flash. The project now carries the partition
table the hybrid build needs (identical to the framework's: the app
slots must not move under updates over the air). Generated files are
ignored.

Debug Build, GNSS on, IRC on TLS: 78 KB free and a 59 KB low (M2 began
at 31 KB and 12.6 KB; the floor is 40 KB). The full stress set passes
on it: refused installs over Wi-Fi and from SD, put/get, screenshot,
core dump decode, Probation; under all of it at once, the low is 46 KB.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
2026-10-04 23:32:29 +02:00
co-authored by Claude Opus 5.5
parent 4e439410cd
commit fff28af961
6 changed files with 54 additions and 2 deletions
+10
View File
@@ -20,6 +20,16 @@ build_flags =
lib_deps =
m5stack/M5Cardputer @ 1.1.1
test_ignore = *
; Smaller TLS buffers (M2): the framework is rebuilt with these settings (pioarduino "hybrid
; compile"). Receive stays 16 KB (servers send full TLS records); send drops to 4 KB (IRC lines are
; short); buffers are allocated as needed and handshake-only data is freed once connected.
custom_sdkconfig =
CONFIG_MBEDTLS_ASYMMETRIC_CONTENT_LEN=y
CONFIG_MBEDTLS_SSL_IN_CONTENT_LEN=16384
CONFIG_MBEDTLS_SSL_OUT_CONTENT_LEN=4096
CONFIG_MBEDTLS_DYNAMIC_BUFFER=y
CONFIG_MBEDTLS_DYNAMIC_FREE_CONFIG_DATA=y
CONFIG_MBEDTLS_DYNAMIC_FREE_CA_CERT=y
; Debug Build: the same firmware plus the Debug Console on TCP 2323 (see ADR 0004). The token comes
; from ~/.config/roro9stack/debug-token, passed in by scripts/_docker.sh; it's never committed.