v3.3.3 — USB volumes survive the boot order and a reboot, dnsmasq rides out a WAN re-home, client lists fill in Access Point mode, less background churn
- A USB volume that is late or missing no longer takes the LAN resolver down (field, RT-BE86U,
Entware). The stock boot order loads the USB storage drivers afterservices-start, so a
dnsmasq whose postconf put its log, aconf-fileor aconf-diron/optexited on every boot
and the LAN had no DNS or DHCP until the volume mounted - or for good when it did not.
start_dnsmasqnow drops such a line whose path is not there yet, logs it, and the watchdog
restarts dnsmasq once the path exists. Beside it: thepre-mountcap (now 300 s) stops the
script together with anything it started - an orphanede2fsckused to hold the device and the
mount then failed for good; a busy device is waited for up to 120 s instead of abandoned; and a
new mount watchdog (rc/reaper_usbmon.c) re-sends a lost mount event for a partition never
mounted since boot (three tries, 30 min window), gives the volumes back after a flash that never
took, and once re-enumerates a storage device that produced no disk - RT-BE96U and RT-BE86U have
no USB power control, and that last path is logged as untested. - A reboot releases the USB volumes before it unmounts them (field, RT-BE86U). v3.3.2 fixed the
flash path; a GUI reboot had the same race -initstartedservices-stopin the background and
unmounted seconds later with Entware still up (35 busy retries, a lazy detach, a dirty volume).
The reboot and halt paths now runreaper_usb_release rebootfirst:services-stopto
completion, the holder sweep, thenswapoffof every swap under/tmp/mnt- a swap file is the
one holder a process sweep cannot clear, and it kept a detached volume mounted through the final
kill. The flash path gets the swapoff too. On the RT-BE96U the volume unmounted 12 s after the
release with no busy line and the next boot mounted a clean journal. - The soft-lockup panic is held off through boot and USB mounts. This kernel is built with
BOOTPARAM_SOFTLOCKUP_PANIC=y, so a CPU stalled for 20 s - swap I/O to a USB disk through the
post-mount storm on a 1 GB box - panics and reboots with nothing kept.initwrites
softlockup_panic=0at boot andrc/usb.caround every mount; the watchdog arms it again once
the box has been up 600 s and no mount has been active for 300 s (logged; seen at 624 s on the
RT-BE96U). A truly hung box is still reset by the hardware watchdog. - LAN DNS and DHCP no longer drop for ~20 s at boot or when the WAN re-homes (RT-BE96U).
dnsmasq exited on a transient "Network is unreachable" while auto-WAN-port briefly held the WAN
address onbr0, and came back only when the watchdog respawned it. Theexit(0)in
send_from()is an ASUS addition: forENETUNREACHandEHOSTUNREACHit now logs (at most once
per 10 s) and drops the one reply, as upstream dnsmasq does; every other send failure keeps the
exit. The conf isbind-dynamic, so the address is re-tracked without a restart. - Every client list fills on a box that is not routing (GT-BE19000 tester, Access Point mode).
The Network page's cards and Clients tab, Parental Controls and the QoS pickers all read
networkmap'sget_clientlisthook, which never marks a client present without DHCP leases and
conntrack. httpd now merges Reaper's own presence scan into that hook on a non-routing box, once,
for all of them (the dashboard tiles and the AiMesh node card had each grown their own overlay);
a row networkmap produced is kept and marked present, a device it does not know is added. Each
present device is also given its network - cfg_mnt's answer, the VIF map, or the bridge the cable
was learned on; the FDB scan now walks every SDN bridge, so a guest VLAN's wired clients land on
their own card. - The Diagnostics report no longer freezes the web interface while it is collected. The
collector ran inside httpd's single thread, so every page and the login page waited for it. It
now runs as a detached worker; the page starts it, polls every 2 s and fetches the report when it
is ready (cap 5 min). Same tokens, no dictionary change. - Less background churn (from the 2026-08-28 efficiency audit). The Warden page's 30 s poll ran
oneipsetand onesedper country set inside httpd (~360 processes); it now reads one
ipset -t listlisting (7). Firewall rebuilds re-fed every Warden block list from the on-disk
cache - up to 800,000 entries into sets that were already full, on each WAN bounce or Apply;
populated sets are now skipped and the count logged (a boot still restores them). rtrafd's seven
per-queuetmctlreads every 4 s and itspingeach cost four processes through a shell
wrapper; each is now one process with apoll()deadline, and a queue that answers nothing keeps
its last reading instead of banking a zero. The firewall's fqdn set cache is rewritten to/jffs
only when the members changed, the bonding state is published only when it changes, and the
client-list refresh flag is no longer re-written on every poll. - Boot no longer dumps ~230 lines of memory statistics into syslog. Stock
rccalled a closed
Broadcom debug routine after the services started, which logged/proc/meminfo,free, the
whole/proc/slabinfoand the buffer-pool status under the tagdbgon every boot. It now runs
only with the stockdbgnvram flag set to1. - Layout: the Security Posture card, the shell on phones, the Warden list boxes, the setup box.
The dashboard's Security Posture card cut off its right column below ~1500 px (reported on
Safari, reproduced in Chromium):1frtracks cannot shrink below a row's longest unbroken label,
and the card's overflow clip hid the second column's status pills. The tracks are now
minmax(0,1fr); a long label truncates and shows its full text on hover. The shell laid every
phone out at 481 px (the topbar's minimum width) and clipped the right edge of every page; the
topbar now wraps. Warden's Manual block list and Whitelist boxes stack into one full-width column
whenever they would be narrower than 400 px side by side. The first-boot box's login rows regained
their label column and row gap, lost when v3.3.2 wrapped them in a form. - Tooling: sibling ports carry canon's added and deleted files.
git diff --name-onlypaired a
canon add with a stale branch file by rename detection, so only the branch path showed and the
add was never ported; a.binsuffix alone protected the OpenSSL test vectors; canon's deletes
were never replayed. The port now diffs--no-renames, syncs those files and removes what canon
removed (build-scripts/_port_protect.sh). Three new host suites cover the rung
(test_dnsmasq_send_exit.py,test_usb_boot_mount.py,test_usb_late_mount.py) beside the
extendedtest_usb_flash_release.pyandtest_apmode_surfaces.py.
Images & checksums (RT-BE86U)
Two flashable images: + AI Advisor (default) and Standard (noMCP, all AI components compiled out entirely). Flash the *_nand_squashfs.pkgtb via Administration > Firmware Upgrade.
This is a beta release. Its filename carries
_BETAand the router reports the same string on the dashboard and the About page, so you can always tell which channel a flashed image came from. Stable releases carry no marker.
| Variant | File | SHA-256 |
|---|---|---|
| + AI Advisor | RT-BE86U_3006_102.8_Reaper_v3.3.3_BETA_nand_squashfs.pkgtb
| c565dc271e34a9d2b8e64046bd6d2689902bcb7f6de709ff68932f95a572c337
|
| Standard | RT-BE86U_3006_102.8_Reaper_v3.3.3_BETA_noMCP_nand_squashfs.pkgtb
| c6957daeb494265fe32b9972fcab4bd6d990d9a974cfde47df989f884bd7fbb0
|
Verify a download against the attached SHA256SUMS-RT-BE86U-Reaper_v3.3.3.txt.
Corresponding source & reproducibility
The RT-BE86U image for v3.3.3-beta is built from this repository at tag v3.3.3-beta-RT-BE86U: the pinned Asuswrt-Merlin base (3006.102.8-beta2, a7ebfa133a) plus the complete patch series. The tag freezes the exact source that produced it.
- Patches:
patches/ - Provenance record:
provenance/manifest.json - How to verify:
docs/REPRODUCIBILITY.mdanddocs/SOURCE-AVAILABILITY.md
The auto-attached Source code (zip/tar.gz) asset below is this repository at tag v3.3.3-beta-RT-BE86U (patches + docs).