nss-packages-qosmio/qca-nss-clients
Sean Khan 2ffd5034a6 treewide: mark various qca-nss modules as BROKEN
Several QCA NSS modules compile successfully but do not
function properly at runtime. This is due to either faulty
implementation or deliberate disabling of certain features in the NSS
firmware by Qualcomm.

Based on extensive testing with NSS firmware 11.4:
- Only 22 out of 64 dynamic interface types succeed in creation.
- All others return NACK, indicating lack of support or broken
  implementation.

Modules affected include DTLS, IPSEC, TLS, CAPWAP, GRE redirect paths,
VXLAN, CLMAP and more.

OpenVPN support is partially enabled on crypto core, but requires patching
userspace OpenVPN to function — outside scope here. Wireguard is preferred
as it already achieves line-rate performance without relying on NSS offload.

Marking these kernel packages as BROKEN to prevent false expectations
and discourage their use, though they're available should Qualcomm
ever release a firmware that supports them. (NOT GOING TO HAPPEN...)

Signed-off-by: Sean Khan <datapronix@protonmail.com>
2025-04-30 03:18:00 -04:00
..
files Move non-upstream NSS packages back into repo 2024-02-19 01:35:04 -05:00
patches nss-clients: [12.5] fix failure to apply 0030-fixup-compiler-errors patch 2025-04-18 05:28:10 -04:00
patches-11.4 nss-clients: nss_match fix read/write procfs files 2025-04-17 22:55:00 -04:00
Makefile treewide: mark various qca-nss modules as BROKEN 2025-04-30 03:18:00 -04:00