v2.7.7 — AdGuard removed, and the update check runs again (built RT-BE96U)
- AdGuard has been removed from the firmware entirely. Users asked for it gone whether or not
it was ever configured — an unused third-party DNS service is still a third-party data collector
sitting in the GUI, and the feature's own privacy text said your information would be collected.
All three places it appeared are gone: the AdGuard tab under Parental Controls and its page,
the AdGuard entries in the DNS Director and DNS-over-TLS provider lists, and the two
AdGuard cards in AiBoard. The per-network AdGuard switch in SDN profiles goes with them.
Nothing else changes — every other DNS provider, SDN setting and AiBoard card is untouched. - “Check for update” works again — and now says something useful when it does not. The button
could report a failed check and point at a log file that did not exist, which made it impossible
to diagnose. The cause was not the check itself: the script was being installed into the firmware
without its execute bit, so the router's service manager could not run it and gave up silently.
Run by hand it had always worked. The build now forces the executable bit on all three update
scripts, so the check runs — and a genuine failure leaves a genuine log behind. - Policy Routing: the six problems reported from the field. A WireGuard target could reboot the
router; a rule is now refused, and logged, when the hardware-acceleration bypass table is full or
the tunnel interface is down, and it is written exactly the way the vendor's own code writes it.
Apply reliably reaches the Confirm step, a confirmed change survives a reboot without leaving a
phantom “awaiting confirmation”, and the armed card now says plainly that Keep is what makes a
change outlive the timer and a reboot. The target list hides tunnels you have not configured and
flags ones that are configured but currently down.firewall-startadd-on scripts run last, so
their rules are no longer reordered underneath them. Lost routing rules now repair themselves the
way a lost firewall chain already did. - “Whole LAN” is now just “LAN”. On the Policy Routing page the acceleration-bypass note read as
a warning about something larger than it is. Reworded in all 25 languages. - The translation pass is complete. The remaining functional interface text is translated across
all 24 non-English languages; the credits and their jokes stay in English by choice. - Gatekeeper diagnostics report the real re-list count. The diagnostic counted by pattern-matching
firewall output and undercounted; it now reads the count the service itself records.
Images & checksums (RT-BE92U)
Two flashable images: + AI Advisor (default) and Standard (noMCP, all AI components compiled out entirely). Flash the *_nand_squashfs.pkgtb via Administration > Firmware Upgrade.
| Variant | File | SHA-256 |
|---|---|---|
| + AI Advisor | RT-BE92U_3006_102.8_Reaper_v2.7.7_nand_squashfs.pkgtb
| db64cccf017f78476be7fac0b7c56cf61112daed5b183cc2a2ac5b12548dfc1f
|
| Standard | RT-BE92U_3006_102.8_Reaper_v2.7.7_noMCP_nand_squashfs.pkgtb
| 660742fc3ce7ec4bf636de662bc879de12b6539db61be8be33d859d629a60779
|
Verify a download against the attached SHA256SUMS-RT-BE92U-Reaper_v2.7.7.txt.
Corresponding source & reproducibility
The RT-BE92U image for v2.7.7 is built from this repository at tag v2.7.7-RT-BE92U: the pinned Asuswrt-Merlin base (3006.102.8-beta2, a7ebfa133a) plus the complete patch series. The tag freezes the exact source that produced it.
- Patches:
patches/(0001-0541) - Provenance record:
provenance/manifest.json - Source tree hash (
release/src/router):2a61854852c57137a0a1e5325e87ba9d6b0887f9-- reproduce bygit am --keep-crof the patches onto the base, thengit rev-parse HEAD:release/src/router. - How to verify:
docs/REPRODUCIBILITY.mdanddocs/SOURCE-AVAILABILITY.md
The auto-attached Source code (zip/tar.gz) asset below is this repository at tag v2.7.7-RT-BE92U (patches + docs).