What's new

[Release] Asuswrt-Merlin 384.10 is now available

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Dirty upgrade from 384.9 to 384.10 successful.
Everything seem okay.
 
Bad experience with this 384.10. Nothing worked, re-flashed from start, don' t like it.
Super slow DL speeds wired.
Will flash back to 384.9 Keep your config file....

Update. Didn't power-cycle the router after update to 384.10 so I will do it again.
 
Last edited:
Bad experience with this 384.10. Nothing worked, reflashed from start, don' t like it.
Super slow DL speeds wired.
Will flash back to 384.9 Keep your config file....
If you are restoring a config,.....that's your problem. Reset and manually configure. No importing configs.
 
The RT-AC87U has a different architecture, most likely the new field added for other models isn't properly hidden on that model.
It looks normal only if nothing connected, the extra field appears only if something connects.
Annotation 2019-03-26 022057.png
 
If you are restoring a config,.....that's your problem. Reset and manually configure. No importing configs.
I'm restoring 384.9 configuration with 384.9 firmware, sorry for being unclear.
 
Bad experience with this 384.10. Nothing worked

You need to troubleshoot your setup first, as I highly doubt that "nothing is working" for the hundreds of other people who already upgraded.

There has been no change surrounding the core networking code, and the RT-AX88U is the only model that saw any GPL-related change.
 
Try the two Alpha builds in https://asuswrt.lostrealm.ca/test-builds/ as well as the 384.10 betas posted on Sourceforge to see if the issue started with a specific release.

I dirty flashed first alpha (build alpha2-g8bdff96906) and IPTV didnt work, so i flashed the .10 final, restored defaults with clear all config checkbox enabled, formated jffs, cleared nvram and only configured IPTV... didnt work, i flashed again .9, and it works, so i restored .9 backup.

I dont use any custom script or app. my router is AC88U.

In AX88U Movistar triple VLAN profile works correctly...

I think could be due different architecture, different implementation

Same issue here... and same solution (back to 384.9_0) :(

What model do you have?
 
I dirty flashed first alpha (build alpha2-g8bdff96906) and IPTV didnt work

Complete list of changes between 384.9 and the alpha build you tried:

Code:
8bdff96906 Merge branch 'master' into mainline
e5ecf7d04c openssl11: Enable OpenSSL 1.1.x on all models
8ac309d1e5 Merge branch 'master' into mainline
c61f03731a Bumped revision to 384.10 alpha 2
953fdb28f8 Updated documentation
f7e8aece92 tor: Update to 0.3.5.8; enable OpenSSL 1.1.x support
d414591de4 strongswan: remove version 5.2.1 from the tree
758b811b8d strongswan: switch to 5.7.2; enable OpenSSL 1.1.x support
51966ea1ff rc: strongswan: Re-enable modp1024 DH, as the built-in Android client doesn't support newer dhgroups with ikev1
8df9f4014e rc: strongswan: Update strongswan.conf content for 5.7.2
fbd510087a strongswan: kernel-netlink: Fix compilation on old kernels (< 2.6.39) (backport from upstream)
f6895a2f9a strongswan: port threading fixes for HND from Asus's 5.2.1
523777ec1a strongswan: fix 32-bit building on 64-bit HND kernel; switch strongswan to 32-bit build, with shared openssl linking
2a2ec0e577 strongswan: Add 5.7.2 to the tree (required for OpenSSL 1.1.x)
45104dbebc openssl11: email: Enable OpenSSL 1.1.x support
8c0ad421ce openssl11: acme-client: Enable OpenSSL 1.1.x support
dcfd174e87 openssl11: net-snmp: Enable OpenSSL 1.1.x support
f0f9f5d985 openssl11: vsftpd: Enable OpenSSL 1.1.x support
47b0262d42 openssl11: Enable OpenSSL 1.1.1 for httpd, mssl, libvpn, wget, inadyn
e67db647fd httpd: Fix OpenSSL 1.1.x support
2fcbe91ecd inadyn: Fix compilation without deprecated OpenSSL 1.1 APIs
0b49f44251 openssl: openssl11: Performance optimizations
8fed354c55 openssl11: priorize CHACHA over GCM for models with no AES acceleration
c00cbfe5d5 openssl11: Add OPENSSL_PREFER_CHACHA_OVER_GCM option
7d3e9174fc openssl11: Add build recipes
944bc2e3ff openssl11: add OpenSSL 1.1.1a to the tree
3fd2098b6c webui: fixed IPSEC log display, which was all shown on one single line
e255fdbba6 Updated documentation
1c4ae65240 openvpn: update to 2.4.7
67346424ae quagga: size it down and fix path
a2255cb4b1 httpd: properly use an "_" if MU-MIMO is not present on a Guest client
804e77ca22 usb-modeswitch: remove unused 1.2.3 version from the tree
30e9599651 curl: updated to 7.64.0
98b3c6630f openvpn: drop CFB ciphers from client as they are never really used
57708c7fe8 Merge branch 'master' of github.com:RMerl/asuswrt-merlin.ng
6beef0d060 openvpn: remove OFB ciphers from client, not supported by current OpenSSL build anyway
48947ded3c use sizeof in fgets to reduce risk of buffer over runs
17b451c130 Don't risk over running the buffer
46e7847441 Don't compare the pointer, compare the value
3141317540 btconfig: removed component that's not used by any of the AM supported models
19c271ed5c Make array argv the right size
af3452a561 Merge pull request #268 from dp111/patch-8
cf9c38653f Merge pull request #267 from dp111/patch-7
59b8571234 Check -C parameters correctly
a7d3a96204 Check port range correctly
24be8ee85c correct size of structure
ab0e53fb28 Correct memset parameter order
0c1e93f868 Correct order of memset parameters
ed3c77883d build: fix/optimize HND_ROUTER checks in inadyn. ncurses and ipset_arm recipes
40c24630c4 openvpn: cleanup build recipe
4d0f428c14 webui: display number of tracked connections on Classification table
7bafe66260 webui: disable automatic refresh of Classification page if more than 300 tracked connections
df25c2d41b ffmpeg: harmonize build recipes with upstream
d87ba15f6c Merge branch 'master' into mainline
1d5e7f333d Revert "ffmpeg: harmonize build recipes with upstream"
856ab96e53 zebra: strongswan: remove unused static libs
04d3f7b276 build: removed Beceem support from SDK6/SDK7 models, saving 2.3 MB of flash space
3654f63d06 Bumped revision to 384.10 alpha 1

At a first glance I cannot see any of this code even remotely touching the VLAN code.

Is it just the IPTV service that stops working?
 
Complete list of changes between 384.9 and the alpha build you tried:

Code:
8bdff96906 Merge branch 'master' into mainline
e5ecf7d04c openssl11: Enable OpenSSL 1.1.x on all models
8ac309d1e5 Merge branch 'master' into mainline
c61f03731a Bumped revision to 384.10 alpha 2
953fdb28f8 Updated documentation
f7e8aece92 tor: Update to 0.3.5.8; enable OpenSSL 1.1.x support
d414591de4 strongswan: remove version 5.2.1 from the tree
758b811b8d strongswan: switch to 5.7.2; enable OpenSSL 1.1.x support
51966ea1ff rc: strongswan: Re-enable modp1024 DH, as the built-in Android client doesn't support newer dhgroups with ikev1
8df9f4014e rc: strongswan: Update strongswan.conf content for 5.7.2
fbd510087a strongswan: kernel-netlink: Fix compilation on old kernels (< 2.6.39) (backport from upstream)
f6895a2f9a strongswan: port threading fixes for HND from Asus's 5.2.1
523777ec1a strongswan: fix 32-bit building on 64-bit HND kernel; switch strongswan to 32-bit build, with shared openssl linking
2a2ec0e577 strongswan: Add 5.7.2 to the tree (required for OpenSSL 1.1.x)
45104dbebc openssl11: email: Enable OpenSSL 1.1.x support
8c0ad421ce openssl11: acme-client: Enable OpenSSL 1.1.x support
dcfd174e87 openssl11: net-snmp: Enable OpenSSL 1.1.x support
f0f9f5d985 openssl11: vsftpd: Enable OpenSSL 1.1.x support
47b0262d42 openssl11: Enable OpenSSL 1.1.1 for httpd, mssl, libvpn, wget, inadyn
e67db647fd httpd: Fix OpenSSL 1.1.x support
2fcbe91ecd inadyn: Fix compilation without deprecated OpenSSL 1.1 APIs
0b49f44251 openssl: openssl11: Performance optimizations
8fed354c55 openssl11: priorize CHACHA over GCM for models with no AES acceleration
c00cbfe5d5 openssl11: Add OPENSSL_PREFER_CHACHA_OVER_GCM option
7d3e9174fc openssl11: Add build recipes
944bc2e3ff openssl11: add OpenSSL 1.1.1a to the tree
3fd2098b6c webui: fixed IPSEC log display, which was all shown on one single line
e255fdbba6 Updated documentation
1c4ae65240 openvpn: update to 2.4.7
67346424ae quagga: size it down and fix path
a2255cb4b1 httpd: properly use an "_" if MU-MIMO is not present on a Guest client
804e77ca22 usb-modeswitch: remove unused 1.2.3 version from the tree
30e9599651 curl: updated to 7.64.0
98b3c6630f openvpn: drop CFB ciphers from client as they are never really used
57708c7fe8 Merge branch 'master' of github.com:RMerl/asuswrt-merlin.ng
6beef0d060 openvpn: remove OFB ciphers from client, not supported by current OpenSSL build anyway
48947ded3c use sizeof in fgets to reduce risk of buffer over runs
17b451c130 Don't risk over running the buffer
46e7847441 Don't compare the pointer, compare the value
3141317540 btconfig: removed component that's not used by any of the AM supported models
19c271ed5c Make array argv the right size
af3452a561 Merge pull request #268 from dp111/patch-8
cf9c38653f Merge pull request #267 from dp111/patch-7
59b8571234 Check -C parameters correctly
a7d3a96204 Check port range correctly
24be8ee85c correct size of structure
ab0e53fb28 Correct memset parameter order
0c1e93f868 Correct order of memset parameters
ed3c77883d build: fix/optimize HND_ROUTER checks in inadyn. ncurses and ipset_arm recipes
40c24630c4 openvpn: cleanup build recipe
4d0f428c14 webui: display number of tracked connections on Classification table
7bafe66260 webui: disable automatic refresh of Classification page if more than 300 tracked connections
df25c2d41b ffmpeg: harmonize build recipes with upstream
d87ba15f6c Merge branch 'master' into mainline
1d5e7f333d Revert "ffmpeg: harmonize build recipes with upstream"
856ab96e53 zebra: strongswan: remove unused static libs
04d3f7b276 build: removed Beceem support from SDK6/SDK7 models, saving 2.3 MB of flash space
3654f63d06 Bumped revision to 384.10 alpha 1

At a first glance I cannot see any of this code even remotely touching the VLAN code.

Is it just the IPTV service that stops working?

I know, i have ur github on favorites and i visit that place almost all days to see ur work progress. This .10 build changelog is to move to OpenSSL 1.1.x and none of the changes i see could affect IPTV... but my problem is real and after test .10 with totaly clean flash and didnt work im totally confused.

Idk if other services stop working because i use the router on basic options and i disable all... no ftp, no telnet, no aicloud, no vpn, only internet and iptv and internet was working.

I know u cant do nothing because u cant reproduce the issue due u cant use Movistar IPTV, so i hope more spanish guys with "Movistar Triple VLAN" come here and post if its working or not but im 99% sure its not my fault when configure the router
 
Asuswrt-Merlin 384.10 is now available for all supported models. The focus of this release was the partial migration to OpenSSL 1.1.1 (not all services can be migrated by me, as some would require Asus to recompile them against OpenSSL 1.1.1).

The highlight:
  • Added OpenSSL 1.1.1b in parallel to 1.0.2. The most relevant services linked against 1.1.1:
    o httpd (the webui)
    o OpenVPN
    o In-a-dyn
    o Strongswan
    o Netatalk
    o vsftpd
    o net-snmp
    o Tor
    o wget

    The userspace "openssl" tool is called openssl11.
  • Merged with GPL 384_5640 (RT-AX88U)
  • Updated components: OpenSSL 1.0 (1.0.2r), OpenVPN (2.4.7), curl (7.64.0), Tor (0.3.5.8), Strongswan (5.7.2). dnsmasq (2.80-g6799320)
  • Fixed Samba compatibility issue with recent Tuxera NTFS driver.
  • Fixed NFSv2 support (and enabled on HND models).
  • Enhancements to OpenVPN key/certs storage and management
  • Enhancements to Classification page, which should be faster, and offer filtering
  • Various other fixes and tweaks


Downloads are here.
Changelog is here.
Asuswrt-Merlin 384.10 is now available for all supported models. The focus of this release was the partial migration to OpenSSL 1.1.1 (not all services can be migrated by me, as some would require Asus to recompile them against OpenSSL 1.1.1).

The highlight:
  • Added OpenSSL 1.1.1b in parallel to 1.0.2. The most relevant services linked against 1.1.1:
    o httpd (the webui)
    o OpenVPN
    o In-a-dyn
    o Strongswan
    o Netatalk
    o vsftpd
    o net-snmp
    o Tor
    o wget

    The userspace "openssl" tool is called openssl11.
  • Merged with GPL 384_5640 (RT-AX88U)
  • Updated components: OpenSSL 1.0 (1.0.2r), OpenVPN (2.4.7), curl (7.64.0), Tor (0.3.5.8), Strongswan (5.7.2). dnsmasq (2.80-g6799320)
  • Fixed Samba compatibility issue with recent Tuxera NTFS driver.
  • Fixed NFSv2 support (and enabled on HND models).
  • Enhancements to OpenVPN key/certs storage and management
  • Enhancements to Classification page, which should be faster, and offer filtering
  • Various other fixes and tweaks


Downloads are here.
Changelog is here.


Have tried three times after downloading but after flashing it still shows 384.10 beta 3. Wonder if anyone else has this problem.
 
and internet was working

That's what I meant by other services.

The only thing that was changed tied to network is quagga. I'll need to check if Moviestar uses it to configure special routes.
 
You need to troubleshoot your setup first, as I highly doubt that "nothing is working" for the hundreds of other people who already upgraded.

There has been no change surrounding the core networking code, and the RT-AX88U is the only model that saw any GPL-related change.

You probably right. My RT-AC86U lost wireless intermittently at first after "dirty" upgrade, then wireless completely disappeared, wired worked but super slow and interruptions as well. Had to rework from fresh...not seeing a need to go away from 384.9 what worked great and now is again...
So for the time being its 384.9 but again, that's just me, I will upgrade with more energy from fresh on next update...
No hard feelings.
 
Have tried three times after downloading but after flashing it still shows 384.10 beta 3. Wonder if anyone else has this problem.

Reboot the router and wait for 5 to 10 minutes for it to settle and try again.

If that doesn't work, safely remove (from GUI) any USB drives, then reboot the router. Wait for 5 or 10 minutes for it to settle and try again.
 
I know, i have ur github on favorites and i visit that place almost all days to see ur work progress. This .10 build changelog is to move to OpenSSL 1.1.x and none of the changes i see could affect IPTV... but my problem is real and after test .10 with totaly clean flash and didnt work im totally confused.

Idk if other services stop working because i use the router on basic options and i disable all... no ftp, no telnet, no aicloud, no vpn, only internet and iptv and internet was working.

I know u cant do nothing because u cant reproduce the issue due u cant use Movistar IPTV, so i hope more spanish guys with "Movistar Triple VLAN" come here and post if its working or not but im 99% sure its not my fault when configure the router
I have only detected issues with iptv, other services works correctly (internet and openvpn client/server).

My router is an AC68U.
 
Coming from 384.8.2 can I update without reconfigure from scratch?
 
Coming from 384.8.2 can I update without reconfigure from scratch?

You can try. :)

If you did a full reset to factory defaults after you had flashed your current firmware version and then configured the router to secure it and connect to your ISP, then you can make a backup config file and save it with a copy of the same version's .trx file.

Now, flash the 384.10 firmware and hopefully, you have no issues. If you do, perform a full M&M Config and minimally and manually configure your router to secure it and connect to your ISP. If you do have further issues (that are show stoppers), then you can simply flash back to the saved .trx file and after doing a full reset to factory defaults, you can use your backup file and get back to where you are now.

This sounds like a lot, but in reality is only a few minutes extra. Assuming you don't run into issues, of course. ;)
 
dirty flashed my ac-5300 from 384.9 no issues so far. Thanks Eric!
 
the only significant stuff I found is the fact that the RAM used is about 85%...
with older firmwares was 50-60%...
I don´t know if this is relevant...
 
the only significant stuff I found is the fact that the RAM used is about 85%...
with older firmwares was 50-60%...
I don´t know if this is relevant...

Did you reboot the router after about an hour of flashing it? Then leave it for a little while longer after the reboot has finished?

Free RAM isn't helping anything though. ;)

You should change the setting in Tools/Other Settings:
Memory Management: Regularly flush caches (default: Yes) To 'No' for the most responsive router experience.
 

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top