Skip to content

Dev 1.6.9 as Next Stable Release - #617

Merged
ExtremeFiretop merged 40 commits into
mainfrom
dev
Sep 28, 2026
Merged

ExtremeFiretop merged 40 commits into
mainfrom
dev

Conversation

@ExtremeFiretop

@ExtremeFiretop ExtremeFiretop commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

Forms post update = READY
Readme update = COMPLETED
Version.txt update = COMPLETED

Dev 1.6.9 as Next Stable Release

What's Changed/Fixed?:

PR: #601 ] - Prevent mesh firmware checks from interrupting node updates

  • Fix a bug allowing the the primary router to cancel/interrupt the flash on an AiMesh node by invalidating it's session cookie..
  • This only was possible if the primary router flash and the node flash were both triggered MANUALLY within a short period of time. (There was a small window where external logins could invalidate the cookie of the node actively flashing)
  • IMAGE:
Screenshot 2026-09-25 070630

PR: [ #602 ] - Fix for 'Copy&Paste' into Password Entry

  • Fixed an issue in the CLI menu, where the user was unable to perform a "Copy&Paste" operation when entering the password string.
  • (Thanks @Martinski4GitHub )

PR: [ #603 ] - Fixes and Improvements

  • Modified and improved functions used to login to the primary router and AiMesh nodes.
  • Added code to double-check that the current login session token/cookie is still valid before proceeding to flash the F/W image. If it's not valid, a 2nd login is attempted. If that fails, the router is rebooted to make sure the router goes back to a fresh state.
  • Miscellaneous improvements and fine-tuning.
  • (Thanks @Martinski4GitHub )

PR: [ #604 ] - Account for Concurrent AiMesh Node Operations

  • Adjusted code to account for concurrent AiMesh node operations.
  • (Thanks @Martinski4GitHub )

PR: [ #606 ] - Preserve failures during MerlinAU self-update

  • Fix DownloadScriptFiles() so that a failed file download cannot be masked by a later successful download.
  • (Thanks maghuro )

PR: [ #[607] & #608 ] - General hardening and cleanup

  • Harden the pull request source-branch validation workflow while preserving automatic execution for pull requests from forks.
  • Miscellaneous improvements and fine-tuning.
  • (Thanks maghuro )

PR: [ #610 ] - Safely escape values written through sed

  • Safely escape configuration /setting values before using them in sed replacement expressions.
  • Examples such as: /tmp/a&b
  • (Thanks maghuro )

PR: [ #614 ] - Fixes and Code Improvements

  • Fixed an issue where, after setting the email format to "Plain Text" in the SSH CLI menu, the WebUI would show the selection box as empty instead of reflecting the "Plain Text" setting previously made by the user.
  • Fixed parsing issues when handling unusual but valid user input for the "Secondary Email Address" option.
  • Improved functions that set and get configuration settings, also making sure values stored as assignment statements are defined as literal strings (e.g. KeyName='KeyValue').
  • Included a fix in the WebUI from @maghuro to properly handle the colon separator in login credentials (i.e. "username:password") [Thanks @maghuro]
  • Miscellaneous code improvements.
  • (Thanks @Martinski4GitHub )
  • IMAGE:
658827362-3fa68c27-65e4-4d37-9e3d-c9c2b3a9d040

PR: #615 ] - Fix AiMesh 2nd Login Attempt

  • Fixes AiMesh node second-login failures by releasing stale WebUI sessions and restarting httpd when needed.
  • Logs out of nodes as soon as a firmware update is detected, avoiding extra status/actions while flashing.
  • Shows actively flashing nodes as busy instead of failed/unreachable in the mn menu.
  • Fixes cleanup of the merlinau_fw_update NVRAM guard, including on failed or aborted updates.
  • Includes some menu/message wording and formatting cleanup.
  • IMAGE:
Screenshot 2026-09-25 070537 659289114-a3dc2634-97cb-4a3e-84fd-80c8bae0f7b8

As always, we highly recommend you update ASAP as this includes functional improvements and little bug fixes.
Thanks!

ExtremeFiretop and others added 30 commits September 7, 2026 20:01
Fix a new bug identified and introduced by commit: bae3640
And PR: #539

This bug appears to be a concurrent firmware management collision, essentially a race while flashing a node while checking it for updates from the primary at the same time.

I accidently ran into this, the seems to be that the node had prepared for the update, authenticated to its own WebUI, and was just about to hand the beta1 image to /upgrade.cgi

When at that exact time, I started an upgrade from the primary, which logged into the node to check for updates, triggered start_webs_update, and resulted in putting the node’s ASUS firmware update system into a competing update/check state and ultimately MerlinAU rebooted the node without flashing any firmware.

This may also be related to a report from JimbobJay here:
https://www.snbforums.com/threads/merlinau-v1-6-8-the-ultimate-firmware-auto-updater.96306/post-999444
Stop logging out early, allow _GetNodeInfo_ to logout
Tightening up the Flash Order

Adjusting the flash order so we delete cron jobs before unloading Entware.
(Incase a cron tries to fire for an entware script that is unloaded)

This may also be related to a report from JimbobJay here:
https://www.snbforums.com/threads/merlinau-v1-6-8-the-ultimate-firmware-auto-updater.96306/post-999444

Also adjusted the WebUI restart to be RIGHT before we login to the router to start the flash. The vulnerable window was the gap between the WebUI restart, unloading the USB, and flashing.

Also adjusted the order so we say flashing right before we actually restart the WebUI and flash
Fixed issue in the CLI menu, where user was unable to perform a "Copy&Paste" operation when entering the password string.
Fix for 'Copy&Paste' into Password Entry
Prevent mesh firmware checks from interrupting node updates
- Fixed bug due to restarting the HTTP daemon right before starting to flash the F/W image.
  This was causing the previously authenticated login session token/cookie to become invalid.

- Modified and improved functions used to login to the primary router and AiMesh nodes.

- Added code to double-check that the current login session token/cookie is still valid before proceeding to flash the F/W image. If it's not valid, a 2nd login is attempted. If that fails, the router is rebooted to make sure the router goes back to a fresh state.

- Miscellaneous improvements and fine-tuning.
Adjusted code to account for concurrent AiMesh Node operations.
Fixed a typo which would have cause a bug!!
Fixed another typo, LOL!!!!
Account for Concurrent AiMesh Node Operations
This makes sure that dependabot always checks and submits against dev.
Checking against main works against our other workflows and architecture such as Check-PRsource.yml
Preserve failures during MerlinAU self-update
Safely escape values written through sed
Extension of PR: #590 and #610

Fix settings values that contain an = character being cut off when MerlinAU reads them back... For example, foo=bar@example.com would previously be read as foo.
- Fixed issue where setting the email format to "Plain Text" in the SSH CLI menu, the WebUI would show the selection box as empty instead of reflecting the "Plain Text" setting made previously by the user.

- Fixed parsing issues when handling unusual but valid user input for the "Secondary Email Address" option.

- Improved functions that set and get configuration settings, also making sure values stored as assignment statements are defined as literal strings (e.g. KeyName='KeyValue').

- Included fix in the WebUI from @maghuro to properly handle the colon separator in login credentials (i.e. username:password).

- Miscellaneous code improvements.
Log out of an AiMesh node immediately when merlinau_fw_update=1 is detected.
Skip all further node actions / status while that node is flashing.
Report actively flashing nodes as busy instead of failed/unreachable in mn screen.
Clean up per-run AiMesh state properly.
Preserve failed WebUI login diagnostics in JFFS.
Protect concurrent diagnostic writes.
Reuse existing log-retention mechanism for the new diagnostic logs..
Clear the firmware-update guard on failed or aborted updates.
Fix Logout Request... Standardizing node logouts
removes the ineffective 5-second wait for login_ip_str to clear...
if the existing cookie has failed and login_ip_str is still populated, restarts httpd
ExtremeFiretop and others added 10 commits September 25, 2026 10:05
@ExtremeFiretop

Copy link
Copy Markdown
Owner Author

@Martinski4GitHub

Good to go, i'll wait for your approval and post the forums post :)

@Martinski4GitHub Martinski4GitHub left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good to go live and "into the wild"!!!!

@ExtremeFiretop
ExtremeFiretop merged commit e2ce197 into main Sep 28, 2026
14 checks passed
@ExtremeFiretop

Copy link
Copy Markdown
Owner Author

Good to go live and "into the wild"!!!!

Sold! Thanks bud!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants