The Entware installer generates the secret without od -An, which BusyBox does not support: on a
router without an existing secret the install failed and rolled back.
Why
entware_new_secret built the 32 hex characters with dd if=/dev/urandom bs=16 count=1 | od -An -tx1 | tr -d ' \n'. BusyBox od has no -A, so on the routers this path exists for the generator dies:
od: invalid option -- 'A'
write_entware_config treats a failed generator as a failed install, so the run ends with
Installation failed; restoring the previous binary, init script and config.
error: service did not become ready
It went unnoticed where a secret already existed from a previous install, because an installed secret
is deliberately never replaced — which is how it survived on the box this path was developed against.
The firmware's od has no -t either (only -abcdeFfhiloxsv), so there was no od spelling to fall
back to. Entware's own /opt/bin/od is a symlink to the same BusyBox.
Fixed
- The Entware secret is generated with
tr:tr -dc 'a-f0-9' < /dev/urandom | head -c 32. Each
character it keeps is uniform over the sixteen it accepts, so the result carries the same 128 bits,
and the 32-character check below it is unchanged. Both applets are BusyBox built-ins, so nothing new
is required.
Notes
- The OpenWrt path keeps
hexdump -v -e '1/1 "%02x"': it was checked on the same BusyBox and works. - Measured on a Keenetic (MT7621, kernel 4.9, BusyBox 1.37): the old pipeline fails with the error
above, the new function returns 32 hex characters in 20 of 20 runs with nothing on stderr.