# ESP32-S3-WROOM-1-N16R8 hardware configuration CONFIG_ESPTOOLPY_FLASHSIZE_16MB=y CONFIG_SPIRAM=y CONFIG_SPIRAM_MODE_OCT=y CONFIG_SPIRAM_SPEED_80M=y CONFIG_SPIRAM_BOOT_INIT=y CONFIG_SPIRAM_USE_CAPS_ALLOC=y # Preserve internal DMA/task memory by placing Wi-Fi and lwIP payload buffers in PSRAM first. CONFIG_SPIRAM_TRY_ALLOCATE_WIFI_LWIP=y # Retain the previously validated bounded Wi-Fi/lwIP capacities explicitly; # ESP-IDF changes their defaults when PSRAM-first allocation is enabled. CONFIG_ESP_WIFI_STATIC_RX_BUFFER_NUM=10 CONFIG_ESP_WIFI_RX_BA_WIN=6 CONFIG_LWIP_TCP_OOSEQ_MAX_PBUFS=4 # Keep concurrent HTTPS handshakes from exhausting scarce internal DRAM. # Active TLS material remains unencrypted in PSRAM until the hardening phase. CONFIG_MBEDTLS_EXTERNAL_MEM_ALLOC=y # CONFIG_MBEDTLS_INTERNAL_MEM_ALLOC is not set # Hardware AES can hang in the PSRAM DMA path and cannot be shared safely with # wolfSSL's independently locked ESP32 acceleration. Software AES is fast enough # at 240 MHz for bounded serial traffic and leaves ESP-IDF's SHA/MPI paths intact. # CONFIG_MBEDTLS_HARDWARE_AES is not set # CONFIG_MBEDTLS_AES_USE_INTERRUPT is not set # HTTPS remains on ESP-IDF's mbedTLS backend; wolfSSL is linked only for wolfSSH. CONFIG_ESP_TLS_USING_MBEDTLS=y # Native USB OTG presents one CDC-ACM interface on the ESP32-S3 USB port. CONFIG_TINYUSB_CDC_ENABLED=y CONFIG_TINYUSB_CDC_COUNT=1 CONFIG_TINYUSB_CDC_RX_BUFSIZE=1024 CONFIG_TINYUSB_CDC_TX_BUFSIZE=1024 CONFIG_TINYUSB_CDC_EP_BUFSIZE=512 # Enable the TLS-only administration server; no plaintext HTTP listener is created. CONFIG_ESP_HTTPS_SERVER_ENABLE=y CONFIG_HTTPD_WS_SUPPORT=y # Reserve capacity for HTTPS/WebSocket clients plus two bounded SSH sessions. CONFIG_LWIP_MAX_SOCKETS=16 # Keep work submission bounded; one-second socket timeouts limit shared-task stalls. # CONFIG_HTTPD_QUEUE_WORK_BLOCKING is not set # Certificate generation and HTTPS startup use nested cryptographic buffers. CONFIG_ESP_MAIN_TASK_STACK_SIZE=8192 # Build wolfSSH and wolfCrypt without replacing the HTTPS TLS implementation. CONFIG_ESP_ENABLE_WOLFSSH=y # The managed component emits a generic RSA stack warning although this target disables RSA. CONFIG_ESP_WOLFSSL_NO_STACK_SIZE_BUILD_WARNING=y # Support WPA3-SAE for station profiles and the WPA2/WPA3 fallback AP. CONFIG_ESP_WIFI_ENABLE_WPA3_SAE=y CONFIG_ESP_WIFI_ENABLE_SAE_H2E=y CONFIG_ESP_WIFI_SOFTAP_SAE_SUPPORT=y # Keep diagnostic and interactive-console logging concise but useful. CONFIG_LOG_DEFAULT_LEVEL_INFO=y