v3.3.8 — a kernel TCP race fixed, no world-writable files from rc, Traffic Analyzer tables to 50 rows, the sibling builds link again
- First image with the v3.3.7 changes. v3.3.7 produced no fleet images: v3.3.7 removed the
rc/Makefile
line that compilesreaper_chanlist_shim.c, so the GT-BE98, GT-BE19000, BQ16 and BQ16 Pro failed to linkrc
(their closed rc objects lackwl_scb,backup_eth_ob_logandis_wan_port_ext_switch, which the shim stubs).
Separately, every noMCP image failedreaper_verifyon markers for MCP-only files. The line is restored;
verify_markers.txttakes an optional variant field (|MCP/|noMCP). Host tests
test_sibling_rc_units.py,test_verify_markers_variant.py. - Kernel: CVE-2026-43198 (audit V8). An IPv4 client connecting to a dual-stack listener gets a v6-mapped
child socket, which was published in the established hash while itspinet6still pointed at the listener's
ipv6_pinfo; another CPU could use it in that window. Port of upstream 858d2a4f67ff (5.10.y aef4a9ae):
__tcp_v4_syn_recv_sock()runs a child-init hook before the child is hashed. The exported
tcp_v4_syn_recv_sock()and the af_ops signature are unchanged. Host testtest_kernel_tcp6_mapped_race.py. - rc runs with umask 022 (field, GT-BE98). rc ran with umask 0, so a file any rc-started process created
without an explicit mode was 0666 - writable by the non-root services (dnsmasq and tftpd asnobody,
Entware daemons). ASUS's own commented-outumask(022)is switched on after sysinit's directory block, so the
directories ASUS creates 0777 keep their mode; vsftpd, Samba and tftpd set their own. Behaviour change: such
files are now 0644; an add-on that wrote into one as a non-root user must set its own mode. Host test
test_rc_umask.py. - Traffic Analyzer: Top Devices and Top Talkers show 10, 20, 30 or 50 rows. A selector per table (remembered
in the browser), fixed column layout and padded rows so the table does not jump;rtrafdkeeps 64 top-talker
slots (was 20).
Images & checksums (BQ16_PRO)
Two flashable images: + AI Advisor (default) and Standard (noMCP, all AI components compiled out entirely). Flash the *_nand_squashfs.pkgtb via Administration > Firmware Upgrade.
This is a beta release. Its filename carries
_BETAand the router reports the same string on the dashboard and the About page, so you can always tell which channel a flashed image came from. Stable releases carry no marker.
| Variant | File | SHA-256 |
|---|---|---|
| + AI Advisor | BQ16_PRO_3006_102.8_Reaper_v3.3.8_BETA_nand_squashfs.pkgtb
| 2ce3575e04a3d1940a0dda47c1243bc2482d252ec2ec761e75d0debe28fe7643
|
| Standard | BQ16_PRO_3006_102.8_Reaper_v3.3.8_BETA_noMCP_nand_squashfs.pkgtb
| 0412213f7447235e260af4960e0f02e7e90e1b59b1033c046a50db0ab7447860
|
Verify a download against the attached SHA256SUMS-BQ16_PRO-Reaper_v3.3.8.txt.
Corresponding source & reproducibility
The BQ16_PRO image for v3.3.8-beta is built from this repository at tag v3.3.8-beta-BQ16_PRO: the pinned Asuswrt-Merlin base (3006.102.8-beta2, a7ebfa133a) plus the complete patch series. The tag freezes the exact source that produced it.
- Patches:
patches/ - Provenance record:
provenance/manifest.json - How to verify:
docs/REPRODUCIBILITY.mdanddocs/SOURCE-AVAILABILITY.md
The auto-attached Source code (zip/tar.gz) asset below is this repository at tag v3.3.8-beta-BQ16_PRO (patches + docs).