v2.7.1 — security review, every page translatable, the master guide
Built on RT-BE96U. Cut with v2.6.6–v2.7.1 as one rung (patches 0502–0517); not yet published.
Security review (three independent adversarial passes over everything changed since 2026-07-31,
plus a regression check of ~40 earlier findings — none regressed). Fixed in this release:
- Cross-site requests against Reaper's own pages (HIGH). The token Reaper's controls check on
every request turned out to be ASUS's factory constant — identical on every router ever made — so
a web page you happened to visit while logged in could, in principle, switch Gatekeeper off,
approve a device, tear down the firewall engine or push a routing list. Two layers now: the token
is generated fresh on every boot, and every Reaper control also refuses a request whose browser
Referer names another site. Stock pages are untouched. (Tools that drive the router from scripts
keep working: a request without a Referer passes on the token alone.) - Firewall: editing during the confirm countdown (MEDIUM). A list saved while a change was
awaiting Keep would have been written as the confirmed config without ever having been compiled or
run. Saves and settings imports are refused until you Keep or Revert — the routing page already did
this. - Firewall: an over-long rule field silently widened the rule (MEDIUM, admin-only data). The guard
meant to drop such a rule had become dead code on 2026-08-21; restored. - Diagnostics report: a device named
HOST-hung the router's web server (MEDIUM). The
sanitizer's hostname pass could match its own replacement and loop forever; any LAN device could
plant the name. Rewritten so no literal can match inside a token. Also: hostnames are now masked
when they appear only in the syslog tail or are cut to 32 characters by Gatekeeper's log line,
and the lease dump prints fields only. - Smaller hardening: the generated firewall / routing scripts, the Gatekeeper teardown and the
watchdog's heal snippet no longer call barenvram get(the v2.6.1 hang guard); a routing
candidate that fails to run is rolled back at once; a draft staged before the very first confirm
can no longer be promoted to "confirmed" by the migration; settings import accepts Warden's CIDR
and feed lists again and snapshots the Gatekeeper baseline when it turns Gatekeeper on. - Recorded, not changed: the firmware update check verifies the download over TLS against the
published hash but carries no author signature (a compromised repository could offer an image —
nothing flashes without your click); see BACKLOG. The watchdog's routing self-heal runs the
idempotent script without the firewall lock (transient at worst).
Translations. Every Reaper page is now fully tokenized for the language packs: 26 remaining
English literals tokenized and 66 tokens moved out of quoted script strings, where a translation
containing an apostrophe would have broken the page. Two stale texts corrected (the Storage note that
said policy "lives in nvram"; the Wireless Auto Scan text that said it pins the channel — it reports,
Pin best commits).
Documentation. docs/REAPER-GUIDE.md — the master guide: what Reaper is, the requirements and
rules for running it properly (the /jffs store, the two backups, USB and filesystems, Apply and Keep,
the sanitized report), every feature page, good practice, troubleshooting and a glossary.
docs/VPN-ROUTING-GUIDE.md brought up to v2.6.7+ (WireGuard, IPv6, apply-and-keep, address lists).
Images & checksums (GT-BE98)
Two flashable images: + AI Advisor (default) and Standard (noMCP, all AI components compiled out entirely). Flash the *_nand_squashfs.pkgtb via Administration > Firmware Upgrade.
| Variant | File | SHA-256 |
|---|---|---|
| + AI Advisor | GT-BE98_3006_102.8_Reaper_v2.7.1_nand_squashfs.pkgtb
| 19ba4c553a3ad3a81f4d2d09c1419e2c22bc3e87245a3e4f60ae9ebe9f0fc56a
|
| Standard | GT-BE98_3006_102.8_Reaper_v2.7.1_noMCP_nand_squashfs.pkgtb
| 91fa95a2419200057dd8f88675074d444217554177c71ab9e0aa2af86955730c
|
Verify a download against the attached SHA256SUMS-GT-BE98-Reaper_v2.7.1.txt.
Corresponding source & reproducibility
The GT-BE98 image for v2.7.1 is built from this repository at tag v2.7.1-GT-BE98: the pinned Asuswrt-Merlin base (3006.102.8-beta2, a7ebfa133a) plus the complete patch series. The tag freezes the exact source that produced it.
- Patches:
patches/(0001-0517) - Provenance record:
provenance/manifest.json - Source tree hash (
release/src/router):2de8941adfbecb88225b956709043c65ee2d5dee-- reproduce bygit am --keep-crof the patches onto the base, thengit rev-parse HEAD:release/src/router. - How to verify:
docs/REPRODUCIBILITY.mdanddocs/SOURCE-AVAILABILITY.md
The auto-attached Source code (zip/tar.gz) asset below is this repository at tag v2.7.1-GT-BE98 (patches + docs).