v3.4.0 — SMB login works on the first start, the LAN name check, the header tooltip on every page, five kernel CVE fixes
- SMB login was refused after the first Samba start of a boot (field, RT-BE96U).
start_samba()enrolled the
accounts withsmbpasswdbefore the block that creates/var/lib/samba/private. Samba 4.15'ssmbpasswd, run
as root, openssecrets.tdbthere before it touches the password file and exits 1 without a message when the
directory is missing;/varis tmpfs, so the first Samba start of every boot left/etc/samba/smbpasswdempty
(smbd logs "did not exist. File successfully created.") and every login was refused until something restarted
Samba. Reaper defaults Samba off, so for most users the first start is the GUI switch-on. The directories are
created first now, and an enrollment that fails is logged by account name. Host testtest_samba_enroll_dirs.py. - LAN name resolution is checked, and the Dashboard says so. The Internet status read "Connected" whenever the
WAN held an address, even when LAN devices could not resolve a single name.rdnshcnow asks the path LAN
devices use once a minute - the router's DNS forlocalhostand for a random name under a configurable domain,
or the servers DHCP hands out - and publishesreaper_landns_state. While it fails the Dashboard's Internet dot
and word turn amber and a tooltip on the WAN pill and the Internet card names the state, how long, and the
silent servers. Status only: nothing is moved or reloaded. Switch, domain and live state on the DNS Failover
page (reaper_landns_enable=1); Diagnostics v1.3.34 reports it. Host testtest_landns_check.py. - The header's Internet tooltip on every page. It lived on the Dashboard only; every other page is framed in the
shell, whose header had the pill but not the tooltip. The shell carries the same box, readings and colours, and
its pill now matches the Dashboard: Connected if IPv4 or IPv6 is up, the danger colour when down, the mode name
in AP / repeater / bridge mode. Host teststest_landns_check.py(the shared functions diffed verbatim),
test_shell_nettip.py(the header code run under node for five states). - Five kernel one-hunk CVE fixes from the 2026-08-30 check: CVE-2023-52881, CVE-2024-47684, CVE-2024-50154,
CVE-2023-6932, CVE-2024-50299 - the 4.19.y stable hunks, no ABI change; all LOW on this platform, three of
them reboot-class underPANIC_ON_OOPS. Host testtest_kernel_cve_onehunk_set.py. - Firewall and Policy Routing list saves are POSTed. A hosts list the CGI accepts became a 10.7 KB GET line for
CIDRs against httpd's 10 KB request-line buffer: a 400, and the page kept rows the router never stored (field,
RT-BE88U). The list travels in the request body, a failed save resyncs the page, and the whole list is
pre-checked before the save. Host testtest_fw_list_post.py. - cru adopts a crontab orphaned by a login rename. crond ignores a crontab whose name is not in
/etc/passwd,
and a login rename without a reboot rebuilds the file under the new name - every boot-registered job (rwatch,
Warden, the PBR deadline watcher) was dead until the next reboot (field, GT-BE98 v3.0.0). Host test
test_cru_adopt.py. - Navigation rail icons unified between the Dashboard and the shell: the Reaper menus (Gatekeeper, Warden,
Advisor, System Info, IPv6) no longer fall to the default glyph on framed pages. Host testtest_nav_icons.py.
Images & checksums (RT-BE96U)
Two flashable images: + AI Advisor (default) and Standard (noMCP, all AI components compiled out entirely). Flash the *_nand_squashfs.pkgtb via Administration > Firmware Upgrade.
This is a beta release. Its filename carries
_BETAand the router reports the same string on the dashboard and the About page, so you can always tell which channel a flashed image came from. Stable releases carry no marker.
| Variant | File | SHA-256 |
|---|---|---|
| + AI Advisor | RT-BE96U_3006_102.8_Reaper_v3.4.0_BETA_nand_squashfs.pkgtb
| e83aa6f6d8337126b84028c7cd03fcbc17ba93d251827b7d4b6c0cb1bce07e1e
|
| Standard | RT-BE96U_3006_102.8_Reaper_v3.4.0_BETA_noMCP_nand_squashfs.pkgtb
| 3d586943fffc806d9ec06c956d8e168b5467ab90acc9052dc01f1c3eae4c56ec
|
Verify a download against the attached SHA256SUMS-RT-BE96U-Reaper_v3.4.0.txt.
Corresponding source & reproducibility
The RT-BE96U image for v3.4.0-beta is built from this repository at tag v3.4.0-beta-RT-BE96U: the pinned Asuswrt-Merlin base (3006.102.8-beta2, a7ebfa133a) plus the complete patch series. The tag freezes the exact source that produced it.
- Patches:
patches/ - Provenance record:
provenance/manifest.json - How to verify:
docs/REPRODUCIBILITY.mdanddocs/SOURCE-AVAILABILITY.md
The auto-attached Source code (zip/tar.gz) asset below is this repository at tag v3.4.0-beta-RT-BE96U (patches + docs).