Fix CA cert loading failure with buffer-based certs when filesystem is disabled #1813
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Problem
Buffer-based CA certificates (
COAP_PKI_KEY_DEF_PEM_BUF,COAP_PKI_KEY_DEF_DER_BUF)fail to load when
MBEDTLS_FS_IOis not defined, even after successful parsing.The code unconditionally enters the root CA block (line 892) which returns
COAP_DEFINE_FAIL_NOT_SUPPORTEDwhen filesystem support is unavailable,failing the entire setup.
Solution
Added
done_ca_cert_bufflag to skip the root CA block when a CA certificatehas already been loaded from a buffer, preventing spurious failures in
non-filesystem environments.