Commit Graph

365 Commits

Author SHA1 Message Date
Sean Khan
0ba24f4c33 nss-ecm: Ensure NSS_IPV4_RULE_CREATE_RAWIP_VALID is only checked for NSS 12.5+
It was unconditionally setting `rule_invalid = true` for FW less than 12.5.

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-06-03 04:15:14 -04:00
Sean Khan
2f4750a191 nss-drv: rework smp affinity hangling
Reworked SMP affinity handling for better balancing of PPDU and USBs

```
Pinning IRQ(46) nss_queue0               to CPU 0 (NSS Core 0)
Pinning IRQ(47) nss_queue1               to CPU 1 (NSS Core 0)
Pinning IRQ(48) nss_queue2               to CPU 2 (NSS Core 0)
Pinning IRQ(49) nss_queue3               to CPU 3 (NSS Core 0)
Pinning IRQ(57) nss_queue0               to CPU 3 (NSS Core 1)
Pinning IRQ(58) nss_queue1               to CPU 2 (NSS Core 1)
Pinning IRQ(59) nss_queue2               to CPU 1 (NSS Core 1)
Pinning IRQ(60) nss_queue3               to CPU 0 (NSS Core 1)
Pinning IRQ(43) nss_empty_buf_sos        to CPU 0 (NSS Core 0)
Pinning IRQ(44) nss_empty_buf_queue      to CPU 0 (NSS Core 0)
Pinning IRQ(53) nss_empty_buf_sos        to CPU 3 (NSS Core 1)
Pinning IRQ(55) nss_empty_buf_queue      to CPU 3 (NSS Core 1)
Pinning IRQ(41) xhci-hcd:usb1            to CPU 2
Pinning IRQ(42) xhci-hcd:usb3            to CPU 2
Pinning IRQ(79) ppdu-end-interrupts-mac1 to CPU 2
Pinning IRQ(83) ppdu-end-interrupts-mac2 to CPU 3
Pinning IRQ(81) ppdu-end-interrupts-mac3 to CPU 1
```

Primarily meant to improve performance on Arcadyan AW1000 which uses USB
based cellular modems (xhci-hcd:usb3). They are now pinned to CPU 2

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-06-01 23:40:20 -04:00
Sean Khan
370137d0bf nss-drv: nss_stats: fix gawk regex compatibility
It's not necessary to escape '#' and '=' in awk regexes, doing so
causes gawk to throw warnings.

Busybox awk is more permissive and does not throw warnings.

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-05-31 03:42:44 -04:00
Sean Khan
d845680ef2 wwan: remove all wwan related packages out of nss packages
These packages really shouldn't be in this repository as it's not the
core focus of the project. I am unable to test or maintain these since
it requires a device with a Quectel modem and cellular service, neither of
which I have access to.

For `Arcadyan AW1000` users you may be interested in trying:

https://github.com/immortalwrt/wwan-packages

All issues related to these packages will be closed and not addressed

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-05-30 20:39:36 -04:00
Sean Khan
c0bbc6f168 treewide: Remove dependency on br_netfilter
Upstream OpenWrt 24.10 and later uses nftables by default.
Bridge filtering is not really needed anymore.

This should also prevent unnecessary chain dependencies getting built
like like `kmod-ipt-ipopt`.

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-05-30 18:43:45 -04:00
Sean Khan
03f6cb25eb nss-drv: Limit arch specific NSS features
Prevent selecting or building NSS features that are ipq806x specific

These include:

- Port ID (nss_portid.c)
- OAM (nss_oam.c)
- Timestamping (nss_tstamp.c)
- Legacy WiFi Offload (nss_wifi.c)

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-05-30 14:35:29 -04:00
Sean Khan
589db1c9c8 nss-clients: GRE: Fix building on kernels < 6.10
Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-05-30 05:25:17 -04:00
Sean Khan
6b2d99511c nss-drv: Restore '-Wno-unused-variable' flag
It was accidentally removed in commit: de828e39b
("treewide: Additional fixes for kernel 6.12 + GCC 14.3")

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-05-30 03:21:05 -04:00
Sean Khan
de828e39b2 treewide: Additional fixes for kernel 6.12 + GCC 14.3+
Fixes for:

  incompatible-pointer-types: (nss gre)
  int-conversion

And ignore warnings for:
  empty-body

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-05-28 21:06:50 -04:00
Sean Khan
54d105f7ca nss-drv: additional fixes for kernel 6.12
Fixes the following sysctl table check failures:

[Tue May 27 17:37:40 2025] sysctl table check failed: dev/nss/ppe_vp/(null) procname is null
[Tue May 27 17:37:40 2025] sysctl table check failed: dev/nss/ppe_vp/(null) No proc_handler
[Tue May 27 17:37:40 2025] sysctl table check failed: dev/nss/pppoe/(null) procname is null
[Tue May 27 17:37:40 2025] sysctl table check failed: dev/nss/pppoe/(null) No proc_handler

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-05-27 19:13:10 -04:00
Sean Khan
9762fbaabe nss-drv: Fix GCC empty-body error in GCC 14.3+
Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-05-27 15:47:10 -04:00
Sean Khan
25086fbac3 treewide: Additional fixes for kernel 6.12 + GCC 15.1
Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-05-25 15:36:03 -04:00
Sean Khan
061e717e06 treewide: fix nss-crypto and qca-nss-cfi patches for kernel 6.12
Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-05-09 14:53:17 -04:00
Sean Khan
6f823a2b34 treewide: Initial support for kernel 6.12 + GCC 15.1
Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-05-08 23:12:18 -04:00
Sean Khan
aeca10fbca nss-drv: [11.4] Fix empty line always appearing
Fixes the weird empty line that always appears in dmesg when loading

```
[Thu May  1 15:07:40 2025] hotplug: symlinking qca-nss0.bin to /lib/firmware/qca-nss0-retail.bin
[Thu May  1 15:07:40 2025] qca-nss 39000000.nss: NSS FW Version: NSS.HK.11.4.0.5-6-R
[Thu May  1 15:07:40 2025] qca-nss 39000000.nss: fw of size 835960 bytes copied to addr: 40000000, nss_id: 0

[Thu May  1 15:07:40 2025] qca-nss 39000000.nss: NSS core 0 booted successfully
[Thu May  1 15:07:40 2025] hotplug: symlinking qca-nss1.bin to /lib/firmware/qca-nss1-retail.bin
[Thu May  1 15:07:40 2025] qca-nss 39400000.nss: fw of size 292296 bytes copied to addr: 40800000, nss_id: 1

[Thu May  1 15:07:40 2025] qca-nss 39400000.nss: NSS core 1 booted successfully
```

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-05-01 19:14:04 -04:00
Sean Khan
7180ade5ca nss-firmware: ipq5018: Add 12.2-156-R
Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-05-01 16:48:07 -04:00
Sean Khan
2ffd5034a6 treewide: mark various qca-nss modules as BROKEN
Several QCA NSS modules compile successfully but do not
function properly at runtime. This is due to either faulty
implementation or deliberate disabling of certain features in the NSS
firmware by Qualcomm.

Based on extensive testing with NSS firmware 11.4:
- Only 22 out of 64 dynamic interface types succeed in creation.
- All others return NACK, indicating lack of support or broken
  implementation.

Modules affected include DTLS, IPSEC, TLS, CAPWAP, GRE redirect paths,
VXLAN, CLMAP and more.

OpenVPN support is partially enabled on crypto core, but requires patching
userspace OpenVPN to function — outside scope here. Wireguard is preferred
as it already achieves line-rate performance without relying on NSS offload.

Marking these kernel packages as BROKEN to prevent false expectations
and discourage their use, though they're available should Qualcomm
ever release a firmware that supports them. (NOT GOING TO HAPPEN...)

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-30 03:18:00 -04:00
Sean Khan
df691901d4 wwan: limit building to IPQ807x/IPQ50xx platforms
IPQ60xx platforms do not support `rmnet_nss`, so
limit to IPQ807x and IPQ50xx.

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-29 23:54:20 -04:00
Sean Khan
17c99d8b48 nss-crypto: fix unnecessary build when not selected
Recent changes in nss-clients enabled unconditional evaluation
of the `qca-nss-drv-dtlsmgr` and `qca-nss-drv-tlsmgr` packages,
which always pulled in their dependencies, including `qca-nss-cfi`
and `qca-nss-crypto`, even if these packages were not selected.

This caused build failures due to missing symbols when the
required NSS crypto components were not enabled.

This commit updates the Makefiles for `qca-nss-crypto` and `qca-nss-cfi`
to ensure that their build and install steps are only executed
if the corresponding package is selected.

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-29 21:02:17 -04:00
qosmio
9f0011aacd
Create config.yml
Signed-off-by: qosmio <datapronix@protonmail.com>
2025-04-29 03:40:41 -04:00
Sean Khan
19f0fefbeb nss-crypto: fix target dependency logic
"@" symbol implies "CONFIG_SOME_SYMBOL" whereas without implies
"CONFIG_PACKAGE_some-package". The later is what we want here since
nss-eip-firmware is a package.

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-29 03:00:49 -04:00
Sean Khan
2b273dbbd8 (chore): add issues template 2025-04-29 02:24:17 -04:00
Sean Khan
0a07b0c6b0 nss-clients: tun6rd: partial revert of commit 7a0c508
commit 7a0c508 `treewide: rework handling platform specific features`
accidently set tun6rd and tlsmgr to 'y' vs. 'm' causing them to be built
if selected.

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-28 11:48:16 -04:00
Sean Khan
43eaccf698 nss-crypto: only select nss-eip-firmware for IPQ807x/60xx
IPQ50xx does not have EIP hardware

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-28 00:18:55 -04:00
Sean Khan
7a0c508dec treewide: rework handling platform specific features
Overhaul the way platform-specific requirements are handled since
IPQ60xx and IPQ50xx don't support all the same features as IPQ807x.

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-27 21:52:50 -04:00
Sean Khan
25bb2ac73b treewide: fix SHA hashes in Makefiles
Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-27 13:55:38 -04:00
Sean Khan
062ae3a501 qca-mcs: fix header-guard error for gcc 15
GCC 15 has stricter checks for header macros where
mismatches between `#ifndef` and `#define` are flagged as errors.

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-27 13:45:02 -04:00
Sean Khan
18a9e76182 nss-drv: backport 12.5 ipq50xx fixes
First attempt at backporting the 12.5 ipq50xx fixes to 11.4.

Fixes compilation errors, but not tested on hardware yet.

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-26 03:30:21 -04:00
Sean Khan
709ddc324a nss-ecm: fix compilation undefined dev when tunipip6 is enabled
Resolves the following error

```
'dev' undeclared (first use in this function)
```

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-25 16:20:19 -04:00
Evgeniy Nikulov
6895d8bb10 nss-ecm: add ppp_generic dependencies (#44)
can`t compile qca-nss-ecm packages in case 'l2tp' I got issue that there is no ppp_generic package.

So, this change will fix building for l2tp case and will not broke pppoe case

EDIT: Fix whitespace
2025-04-25 16:18:53 -04:00
Sean Khan
bb4d4c9a25 nss-clients: [12.5] fix failure to apply 0030-fixup-compiler-errors patch
Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-18 05:28:10 -04:00
Sean Khan
3584692072 nss-firmware: bugfix empty packages due to incorrect inheritance
The previous refactor (32dd47ec) attempted to use a common definition
block (`nss-firmware-common`) for package metadata and builds.
However, the way it was referenced (`$(nss-firmware-common)`) didn't
work for inheriting properties like TITLE, SECTION, CATEGORY, or
the install logic via `$(call ...)` within the sub-package definitions.

This resulted in the platform-specific packages
(`ipq807x`, `ipq60xx`, `ipq50xx`) being built without any firmwares
leading to empty `.ipk` files and failure to boot.

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-18 02:29:23 -04:00
Sean Khan
a3692762e9 nss-clients: nss_match fix read/write procfs files
More fixes to read/write procfs files in nss_match.

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-17 22:55:00 -04:00
Sean Khan
0eb92d185e nss-clients: treewide fixup compiler errors
Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-17 22:42:16 -04:00
Sean Khan
8ae73bb2c6 nss-drv: treewide fix compiler warnings
Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-17 22:41:30 -04:00
Sean Khan
387698c63b nss-drv: nss_rps/dscp fix read/write procfs files
Another fix for reading procfs files.

This fixes a long time bug where reading/writing to
ipv4_dscp_map, ipv6_dscp_map, pri_map would result in a 'Bad Memory'
error

Should now look like this when reading the following:

```
dev.nss.ipv4cfg.ipv4_dscp_map = priority: 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
dev.nss.ipv4cfg.ipv4_dscp_map = action:   0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
dev.nss.ipv6cfg.ipv6_dscp_map = priority: 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
dev.nss.ipv6cfg.ipv6_dscp_map = action:   0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
dev.nss.rps.pri_map = Cores: -1 -1 -1 -1
```

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-17 12:01:06 -04:00
Sean Khan
32dd47ec01 nss-firmware: Rework platform dependancy and version string
- Added proper CONFLICTS which should allow building multiple
  firmwares in the same build tree.
- Updated version string for 11.4 (it was 5 when it's been 6 for a while)
- Adjusted nss-eip-firmware dependency to match IPQ807x/IPQ60xx since
  'TARGET_qualcommax` included IPQ50xx which does not have EIP hardware.
- PKG_RELEASE bumped to 2

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-17 12:00:18 -04:00
Sean Khan
51300e4df4 nss-cfi: fix issue with kernel reporting duplicate driver
Kernel 6.1+ expects the driver to be registered with a unique name.

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-17 00:46:12 -04:00
Sean Khan
c5fd1f6430 nss-clients: use patches vs. compiler overrides to fix warnings
Remove '-Wno-enum-conversion -Wno-unused-variable -Wno-int-conversion' from CFLAGS
and instead patch the code to fix the warnings.

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-15 12:04:45 -04:00
Sean Khan
cd4db9aa4e nss-clients: [12.5] sync release from latest QSDK 12.5
This commit updates 12.5 version of the nss-drv from:

1bcef16 -> 51be82d (2024-07-08)

Bringing in the following changes:

```
2024-07-08 - 26ed7e6 - [qca-nss-clients] Added a flag to check if HW UDP checksum is supported
2024-06-16 - 5514683 - [nss-qdisc] Replace add_timer() to mod_timer()
2024-06-11 - 3a567e0 - [qca-nss-clients] udp_st: Add a new mode to handle unsynchronized time
```

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-15 12:04:45 -04:00
Sean Khan
f3318298a7 nss-drv: [11.4] sync more kernel 6.6 changes from 12.5
Mostly cosmetic changes, but also:

* Extend kernel version handling so kernels 6.1–6.14
  are supported (untested on > 6.6)
* Replace various `NSS_SUCCESS`/`NSS_FAILURE` return codes with
  `NSS_TX_SUCCESS`/`NSS_TX_FAILURE`
* Change di_data.response initialization in the dynamic interface
  to use NSS_CMN_RESPONSE_ACK.

Primary affects `0016-nss-drv-add-support-for-kernel-6.6.patch`, while
other patches were refreshed.

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-15 12:04:45 -04:00
Sean Khan
8660c6d6e5 nss-ecm: fix read/write UDP/TCP denied ports
In Linux kernel 6.6, the sysctl infrastructure changed
how it handles user/kernel memory boundaries.

The sysctl handlers now take a regular void *buffer instead
of void __user *buffer because the sysctl core now handles
the user-to-kernel copy/validation automatically.

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-15 12:04:35 -04:00
Sean Khan
991bc745ac nss-ecm: remove compiler warning overrides
Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-09 14:16:15 -04:00
Sean Khan
022a11234e nss-ecm: dynamically set frontend based on selection
Only build frontend based on selected acceleration engine.

ECM can build frontends for NSS/SFE/PPE, but for now only include option
for NSS.

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-09 14:15:10 -04:00
Sean Khan
a8d4f99c91 nss-ecm: bump 12.5 release and refresh patches
Brings in the following commits from 12.5 branch:

2024-11-06 - 30fbfa4 - Fix for null dev entries in emesh-sawf.
2024-08-28 - 0718f48 - Add interface num to identify vlan device

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-09 13:56:37 -04:00
Sean Khan
1bed8dab31 nss-ecm: Improve ECM module configuration handling
This commit fixes two issues with how ECM module options are configured:

1. `/etc/modules.conf` was modified on every ECM start/restart,
   even when no changes were needed.

2. If any other ECM parameters were set in `/etc/modules.conf` it would
   overwrite them as the entire line was replaced.

The solution extracts configuration logic into a dedicated function that
only modifies what's necessary, properly handling all cases (updating existing
parameters, appending to existing options, or creating new options).

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-08 12:53:42 -04:00
Sean Khan
e4bfbb7986 qca-mcs: Flush the mdb tables in the event of NETDEV_DOWN
Bump to latest 12.5 branch to bring in the following:

* Flush the mdb tables in the event of NETDEV_DOWN

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-08 12:39:49 -04:00
Sean Khan
5e977b3eae nss-drv: [11.4] fix undefined GRE stats_ctx for non IPQ807x
When building NSS GRE feature for non IPQ807x targets, the GRE `stats_ctx`
was not being properly defined.

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-08 03:10:22 -04:00
Sean Khan
e991bc1429 nss-drv: [12.5] bump to latest and refresh patches
This commit updates 12.5 version of the nss-drv from:

30fbfa4 -> 4dfab93

Bringing in the following changes:

```
2024-11-13 - d5ee67b - Add support for clearing N2H stats
2024-11-13 - 4850be3 - Add support for clearing DRV stats
2024-11-13 - 3d7c16d - Add support for clearing capwap stats
2024-11-13 - 163fbf4 - Add support clearing Crypto CMN stats
2024-11-13 - 084b475 - Add support for clearing DTLS CMN stats
2024-11-13 - e32f844 - Add support clearing PVxLAN stats
2024-11-13 - 2f54141 - Add support for clearing ipv6 stats
2024-11-13 - 702b14c - Add support for clearing C2C TX stats
2024-11-13 - 201dbc5 - Add support for clearing ipv4 stats
2024-11-13 - 24b6f1a - Add support for clearing eth_rx stats
2024-11-05 - 6e242de - Add support for clearing C2C RX stats
2024-11-05 - 942593c - Added a flag to identify if HW UDP checksum is supported for udp_st
2024-11-05 - e11eb4e - Add support for clearing Trustsec TX stats
2024-11-05 - 4f01399 - Add support for clearing EDMA Lite stats
2024-11-05 - 45b9a31 - Add support for clearing Trustsec RX stats
2024-11-05 - 57b338d - Add baseline stats write functionality
2024-10-16 - b671190 - Fix dtsi parameter that controls enabling UBI
2024-10-08 - 9514a99 - Enabling qca-nss-drv on 6.6 kernel
2024-07-16 - e96972f - udp_st: Add a new mode to handle unsynchronized time.
2024-05-16 - 1db9e55 - Add missing error code for wifili pkg.
```

Stats can be cleared by echoing `0` to the corresponding stats file.

For example, to clear the N2H stats, you can run:

```
echo 0 > /sys/kernel/debug/qca-nss-drv/stats/n2h
```
2025-04-08 03:10:05 -04:00
Sean Khan
760e07e740 nss-ecm: only set reload trigger to disable packet steering
Previous change was reloading ECM on client DHCP requests causing
temporary packet loss. Change reload trigger to instead just disable
packet steering (the original intent of this feature).

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-03-02 15:10:31 -05:00