v3.3.6 — the WAN port stays out of the LAN, WAN Ports replaces the Dual WAN tab, a quieter Traffic Analyzer, real Site Survey security names
- Auto WAN port detection no longer bridges the internet port into the LAN at every boot and link
drop (owner). Stock detection finds the port by adding every candidate tobr0and running a DHCP
client on the bridge; the closedrestore_auto_wanport()redid that at each boot and each WAN link
loss, so the ISP port carried LAN traffic for ~35-45 s every time (only DHCP and RS/RA were
filtered). Now the first port that carries the WAN is pinned (reaper_wanport): the restore calls
are skipped, wanduck stops relaunching the search, and_evalrefuses abrctl addifof that port
while Auto is on and Dual WAN is off. A fixed port clears the pin; Detect again (or
service start_reaper_wanredetect) runs one search. Dual WAN, AP mode, IPTV, bonding, static WAN and
MAC clone are untouched (stockis_auto_wanport_enabled()gate); a new or reset router still
starts on Auto. Host testtest_wan_pin.py. - WAN > WAN Ports replaces the Dual WAN tab. The only place to pick the WAN port was the Dual WAN
tab, and nothing said Auto searches several ports even with Dual WAN off. The native page shows the
ports (Auto with its explainer and the pinned port), Dual WAN, monitoring, Load Balance rules and the
ISP profile; the stock page redirects to it and is unchanged. Its apply is a port of the stock
applyRule(): a mock parity harness drives both pages through 28 scenarios (incl. three refusals)
and finds the same nvram changes. One deliberate difference: a legacy single-WANlanon the combo
port shows that port instead of silently selecting Auto.RWAN_1..22in all 25 packs. - Traffic Analyzer stays quiet on a busy conntrack table (field, RT-BE88U: rtrafd at about one core
with ~10.7k entries from a LAN DHT crawler). The conntrack pass is paced by its own measured cost
(near 3% of one core, 2 s floor, 30 s ceiling, one log line per change), every rate and staleness
figure uses the measured interval, and the connection health probe counts inside the same pass
instead of a second full read. Host testtest_rtrafd_pacing.py. - Site Survey shows real security names (field: WPA2/WPA3 networks read "WEP"). This platform's
wlprints the privacy bit asWEPon every protected network and the RSN header as
RSN (WPA2):; the parser matched onlyRSN:. Both forms are read now and the AKM suites fold into
one name: WPA2-Personal, WPA2/WPA3-Personal, WPA3-Personal, WPA/WPA2-Personal, WPA2-Enterprise, OWE.
An empty band (6 GHz with no network in range) reads as empty, not as a refused scan, and the list's
heading row stays in view while it scrolls. - Audit 2026-10-06 fixes. The stock download row for the WireGuard client configuration image
(wgs_client.png) needs a login (it carried a client's private key); rdnsmapd accepts DNS replies
from LAN bridges only, so nothing on the WAN side can plant Flow Explorer names; strongSwan carries
the 6.0.6 security set. SeeREAPER-FIXES.md. - Flow Explorer: the Advanced detail panel glides to the reader with one measurement per frame
instead of jumping on every scroll event.
Images & checksums (GT-BE98)
Two flashable images: + AI Advisor (default) and Standard (noMCP, all AI components compiled out entirely). Flash the *_nand_squashfs.pkgtb via Administration > Firmware Upgrade.
This is a beta release. Its filename carries
_BETAand the router reports the same string on the dashboard and the About page, so you can always tell which channel a flashed image came from. Stable releases carry no marker.
| Variant | File | SHA-256 |
|---|---|---|
| + AI Advisor | GT-BE98_3006_102.8_Reaper_v3.3.6_BETA_nand_squashfs.pkgtb
| 9fa8f93f077f9ca05796e2d28e596c1df2bf41e182826dabb63091be056bd643
|
| Standard | GT-BE98_3006_102.8_Reaper_v3.3.6_BETA_noMCP_nand_squashfs.pkgtb
| 55d551cff4b32b2160e09f8a3962e9042b49f0819da200e88afc2b53cbce99fd
|
Verify a download against the attached SHA256SUMS-GT-BE98-Reaper_v3.3.6.txt.
Corresponding source & reproducibility
The GT-BE98 image for v3.3.6-beta is built from this repository at tag v3.3.6-beta-GT-BE98: the pinned Asuswrt-Merlin base (3006.102.8-beta2, a7ebfa133a) plus the complete patch series. The tag freezes the exact source that produced it.
- Patches:
patches/ - Provenance record:
provenance/manifest.json - How to verify:
docs/REPRODUCIBILITY.mdanddocs/SOURCE-AVAILABILITY.md
The auto-attached Source code (zip/tar.gz) asset below is this repository at tag v3.3.6-beta-GT-BE98 (patches + docs).