<feed xmlns='http://www.w3.org/2005/Atom'>
<title>staging/stintel, branch master</title>
<subtitle>Staging tree of Stijn Tintel</subtitle>
<id>https://git.openwrt.org/openwrt/staging/stintel/atom?h=master</id>
<link rel='self' href='https://git.openwrt.org/openwrt/staging/stintel/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/stintel/'/>
<updated>2026-10-07T05:56:52Z</updated>
<entry>
<title>realtek: l3: trap IPv4 routes for one DSCP value</title>
<updated>2026-10-07T05:56:52Z</updated>
<author>
<name>Gennaro Cimmino</name>
</author>
<published>2026-10-06T18:35:42Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/stintel/commit/?id=60461330279f2ab0828ae704e4d7d9c0e73cd507'/>
<id>urn:sha1:60461330279f2ab0828ae704e4d7d9c0e73cd507</id>
<content type='text'>
An IPv4 route can be for one DSCP value (ip route add ... tos), and the
kernel then routes only packets that carry that value through it. The
switch's entry matches on the destination alone, so an offloaded route
of that kind took every packet for the destination, whatever its DSCP.
Treat it like a multipath route: it gets a trapping entry and the CPU
routes its traffic. otto_l3_fib_del_v4() takes it through the same
branch. The overview at the top of l3.c is updated to match. RTL839x,
which routes through PIE rules and has no trapping entries, no longer
offloads such a route, though an offloaded shorter prefix still forwards
its destination there whatever the DSCP; not tested there.

Of the routes for one destination the kernel notifies only the first,
and one for a DSCP value comes before the one without, so the
destination traps for as long as a DSCP route for it exists, and the
other one arrives as a replace when it goes.

Tested on a Hasivo S1100W-8XGT-SE (RTL9303) with 10.99.0.0/16 via one
gateway, 10.99.70.0/24 tos 0x10 via another, and 8 echoes to the /24
with each TOS value. On main the /24 forwards in hardware and 8 of 8
echoes with TOS 0 and 8 of 8 with TOS 0x10 reach its gateway. With this
change it traps: TOS 0 reaches the /16's gateway and TOS 0x10 the /24's,
8 of 8 each, and adding the /24 without tos, which the kernel does not
notify, keeps it so; on main it stays as before. Deleting the tos route
brings the other one in as a replace, and on both the /24 forwards all
16 to its own gateway. The round on trap rows passes, 46 of 46.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Gennaro Cimmino &lt;gcimmino@rayonra.net&gt;
Link: https://github.com/openwrt/openwrt/pull/25683
Signed-off-by: Markus Stockhausen &lt;markus.stockhausen@gmx.de&gt;
</content>
</entry>
<entry>
<title>nvram: bound the variable parser to the nvram partition</title>
<updated>2026-10-07T00:34:33Z</updated>
<author>
<name>Hauke Mehrtens</name>
</author>
<published>2026-09-17T19:25:02Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/stintel/commit/?id=d09134f6edeff8d445cb96ed3689f4d072a9666f'/>
<id>urn:sha1:d09134f6edeff8d445cb96ed3689f4d072a9666f</id>
<content type='text'>
The "name=value\0 ... \0\0" walk over the mmap()ed nvram used strchr()
and strlen() without a bound, so an nvram without the terminating
double NUL made it run past the end of the mapping.

Search with memchr() up to the length from the nvram header, or up to
the end of the mapping when that length does not fit, so a broken
header is still readable. A variable that is not terminated in this
area ends the parsing.

Map a regular file, like the /tmp staging file, only as far as it is
backed, rounded down to 4 bytes for the padding in nvram_commit(),
instead of the partition size which raised SIGBUS. Only search the
start of a mapping smaller than NVRAM_MIN_SPACE for the magic instead
of underflowing the loop boundary; bcm47xxpart creates such nvram
partitions on flashes with 4 KiB erase blocks.

"nvram info" clamps the header length before the CRC8, it read beyond
the mapping or underflowed into a 4 GB read before.

This is reachable with a crafted nvram partition or staging file, on
bcm47xx the nvram partition is also parsed while booting.

Reported by @tonoyx91 and @0xROI.

Link: https://github.com/openwrt/openwrt/security/advisories/GHSA-5m25-qmhm-crr4
Fixes: 400c1a7fbfad ("Add unvram, a nvram manipulation tool suitable for brcm-2.4 and bcm47xx platforms")
Assisted-by: Claude:claude-opus-5
Link: https://github.com/openwrt/openwrt/pull/25240
Signed-off-by: Hauke Mehrtens &lt;hauke@hauke-m.de&gt;
</content>
</entry>
<entry>
<title>mediatek: filogic: add Adtran SDG-9000</title>
<updated>2026-10-06T23:03:51Z</updated>
<author>
<name>Daniel Golle</name>
</author>
<published>2025-03-03T13:29:42Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/stintel/commit/?id=6b84ce8a51310fe6600e10567ba405a6b8f45266'/>
<id>urn:sha1:6b84ce8a51310fe6600e10567ba405a6b8f45266</id>
<content type='text'>
The Adtran SDG-9000 is a 10G PoE router in a white steel case with
optional 19" rackmount brackets.

Specifications:
 * MediaTek MT7988A (4x Cortex-A73)
 * 32 GB eMMC
 * 4 GiB DDR4 RAM
 * 1x 10000M/5000M/2500M/1000M/100M combo WAN: RJ45 (Marvell
   CUX3410 PHY) or SFP+ cage, selected at boot
 * 1x 10000M/5000M/2500M/1000M/100M LAN port (Marvell CUX3410 PHY)
 * 8x 2500M/1000M/100M/10M LAN ports with PoE+ (MaxLinear MxL86282
   switch with built-in PHYs), 200 W total PoE budget, two Skyworks
   Si3474 PSE controllers
 * 1x 1000M/100M/10M management port (MT7988 built-in PHY)
 * 240x240 TFT touchscreen (ST7789 SPI LCD with CST816S touch)
 * 1 button (Reset)
 * uC-controlled RGB LED via I2C
 * RGBW LED for each PoE LAN port, 2x LED for the management port,
   3x LED for each 10G port, 2x LED for the SFP+ cage
 * 2x PWM fan (mainboard, power supply)
 * USB 3.0 type A port
 * USB-C console port, 115200 baud, Holtek HT42B534 USB-UART bridge
 * 100-240V AC 50-60Hz power input, IEC 60320 C14 inlet

The WAN port is selected by a GPIO-controlled mux that has no runtime
control, so it is chosen by one of two device tree overlays, wan-phy
and wan-sfp, carried as configurations of the FIT image. The mux is
selected by setting boot_default_config in the U-Boot environment:

 config-1                                       no WAN port
 config-1#mt7988a-smartrg-sdg-9000-wan-phy      RJ45 (CUX3410)
 config-1#mt7988a-smartrg-sdg-9000-wan-sfp      SFP+ cage

MAC addresses (base MFG_MAC from the mfginfo partition; the nvmem
cell index in the DTS is added to the base):

 wan        xx:xx:xx:xx:xx:x0  MFG_MAC
 aux        xx:xx:xx:xx:xx:x0  MFG_MAC
 lan1-lan9  xx:xx:xx:xx:xx:x1  MFG_MAC + 0x1
 br-lan     xx:xx:xx:xx:xx:x1  MFG_MAC + 0x1

The label shows MFG_MAC. aux is the only port present when netifd
starts, as lan1-lan9 appear once the mxl862xx driver has loaded, so
br-lan would take the MAC of aux. board.d sets the MAC of br-lan to
that of lan1-lan9.

Installation:

1. Prepare a TFTP server at 192.168.1.254 and serve the OpenWrt
   initramfs image, renamed to "openwrt.500".
2. Connect to the Management/Auxilary port.
3. Connect to the USB-C console port (USB CDC-ACM, 115200 8n1)
4. Power on the device and type "st" to enter the U-Boot command
   line. The window to do that might be very short, so type it as
   soon as the "U-Boot ..." string appears.
5. Run "setenv boot_mode openwrt; saveenv" to boot from OpenWrt
   partition by default.
6. Run "bootmenu" and select option 6 (TFTP openwrt image and
   boot); "run boot5" is a shortcut for the same. This downloads
   openwrt.500 from the TFTP server and boots it.
7. After OpenWrt finishes booting, download the OpenWrt sysupgrade
   image and write it to eMMC using "sysupgrade".
8. After sysupgrade finishes writing, the device reboots into
   OpenWrt. When the System LED is solid white the device is ready
   for configuration.
9. To use the WAN port, set boot_default_config to one of the values
   above, e.g. from OpenWrt with
   "fw_setenv boot_default_config config-1#mt7988a-smartrg-sdg-9000-wan-sfp".

Signed-off-by: Daniel Golle &lt;daniel@makrotopia.org&gt;
</content>
</entry>
<entry>
<title>mediatek: filogic: rename netdevs on hotplug</title>
<updated>2026-10-06T23:03:51Z</updated>
<author>
<name>Daniel Golle</name>
</author>
<published>2026-10-04T11:44:33Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/stintel/commit/?id=c244bf6e867ef6c01a8f1376656b3a396b2bc70d'/>
<id>urn:sha1:c244bf6e867ef6c01a8f1376656b3a396b2bc70d</id>
<content type='text'>
The preinit hook that applies the label and openwrt,netdev-name DT
properties only sees the netdevs registered before it runs. The ethernet
driver of the SDG-9000 registers its netdevs about two seconds after
preinit has started, so they keep their ethN names.

Move the rename into a shared helper and call it from a hotplug net rule
as well, which handles netdevs registered once userland is up.

Also register the netdev rename for the preinit_netdev boot hook so that
netdevs registered while preinit is running get their DT name before the
preinit interface is configured.

Signed-off-by: Daniel Golle &lt;daniel@makrotopia.org&gt;
</content>
</entry>
<entry>
<title>base-files: configure the preinit interface on hotplug</title>
<updated>2026-10-06T23:03:51Z</updated>
<author>
<name>Daniel Golle</name>
</author>
<published>2026-10-04T16:06:11Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/stintel/commit/?id=ac0b20dbcec63e6b2d6ad2e8a36c97f6d07075a6'/>
<id>urn:sha1:ac0b20dbcec63e6b2d6ad2e8a36c97f6d07075a6</id>
<content type='text'>
preinit_ip runs once when preinit starts and configures the preinit
interface only if its driver has already registered it. Drivers that
probe while preinit is running leave failsafe without a network.

Run procd's preinit hotplug daemon on net add events, as the rule in
hotplug-preinit.json.d does, and have it start /sbin/preinit-netdev.
The script runs the new preinit_netdev boot hook, which targets use to
rename the new netdev, and then calls preinit_ip_event, which
configures the preinit interface unless it already carries the
preinit address.

Signed-off-by: Daniel Golle &lt;daniel@makrotopia.org&gt;
</content>
</entry>
<entry>
<title>generic: add LED triggers for SFP module state and faults</title>
<updated>2026-10-06T23:03:51Z</updated>
<author>
<name>Daniel Golle</name>
</author>
<published>2026-10-04T19:26:42Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/stintel/commit/?id=60043441a006395f3d3865d9d30bd89423ba2a1b'/>
<id>urn:sha1:60043441a006395f3d3865d9d30bd89423ba2a1b</id>
<content type='text'>
Register LED triggers for each SFP cage representing module state:

 - present: the module is detected.

 - los: loss of signal, using the module's own declared polarity. I
   split that logic out of the link check into sfp_los_asserted() so
   both use the same code.

 - tx-fault: the state machine reports a transmit fault (init fault,
   fault, re-init, or persistently disabled).

 - error: the module is in error, covering an unreadable EEPROM or I2C
   failure, an unsupported module, or a failed power-up, plus the
   failed-PHY state.

 - fault: either tx-fault or error.

Refresh target patches affected by the generic addition.

Signed-off-by: Daniel Golle &lt;daniel@makrotopia.org&gt;
</content>
</entry>
<entry>
<title>generic: pse-pd: add fault LED trigger and Si3474 IRQ</title>
<updated>2026-10-06T23:03:51Z</updated>
<author>
<name>Daniel Golle</name>
</author>
<published>2026-10-04T08:12:45Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/stintel/commit/?id=b2a6ce658df63b21da2b8a759a7076e1da70a875'/>
<id>urn:sha1:b2a6ce658df63b21da2b8a759a7076e1da70a875</id>
<content type='text'>
Add a per-PI fault LED trigger to the PSE core, an interrupts
property to the Si3474 binding, and INTb handling to the Si3474
driver. Over-current events latch a fault state that the driver
reports as FAULT, which lights the fault trigger. Power good and
power enable changes update the delivering and enabled triggers
without waiting for a regulator operation.

Signed-off-by: Daniel Golle &lt;daniel@makrotopia.org&gt;
</content>
</entry>
<entry>
<title>kernel: video: load MIPI DBI panel and PWM backlight early</title>
<updated>2026-10-06T23:03:51Z</updated>
<author>
<name>Daniel Golle</name>
</author>
<published>2026-10-04T21:52:52Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/stintel/commit/?id=6e55a3c331d40b49b713921d0cbf14f53dd27d21'/>
<id>urn:sha1:6e55a3c331d40b49b713921d0cbf14f53dd27d21</id>
<content type='text'>
AutoProbe places a module in etc/modules.d, which kmodloader loads
from /etc/init.d/boot once preinit has finished, so a MIPI DBI panel
only lights up late in the boot. With the boot flag the module is
linked into etc/modules-boot.d as well, which is loaded before the
preinit scripts, together with its dependencies.

Set the flag on the panel driver and on pwm_bl, because the panel
defers its probe until the backlight it references has registered.

Signed-off-by: Daniel Golle &lt;daniel@makrotopia.org&gt;
</content>
</entry>
<entry>
<title>kernel: modules: package driver for Hynitron CST816x touch sensor</title>
<updated>2026-10-06T23:03:51Z</updated>
<author>
<name>Daniel Golle</name>
</author>
<published>2025-03-18T14:52:16Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/stintel/commit/?id=2bba9c1ba527dc21e810de019d415c10dd4e2ef4'/>
<id>urn:sha1:2bba9c1ba527dc21e810de019d415c10dd4e2ef4</id>
<content type='text'>
Package kernel driver for the Hynitron CST816x touch sensor, found on
ST7789V-based 240x240 px MIPI-DBI display of the Adtran SmartRG SDG-9000.
Import pending patches improving the driver.

Signed-off-by: Daniel Golle &lt;daniel@makrotopia.org&gt;
</content>
</entry>
<entry>
<title>mipi-dbi: depend on kmod-drm-panel-mipi-dbi</title>
<updated>2026-10-06T23:03:51Z</updated>
<author>
<name>Daniel Golle</name>
</author>
<published>2026-10-03T22:01:29Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/stintel/commit/?id=dc7acc188815285d3f0aa9e49cf1b33d3fc313dd'/>
<id>urn:sha1:dc7acc188815285d3f0aa9e49cf1b33d3fc313dd</id>
<content type='text'>
Apply the established OpenWrt packaging pattern of a firmware package
depending on its only consumer.

Signed-off-by: Daniel Golle &lt;daniel@makrotopia.org&gt;
</content>
</entry>
</feed>
