Dev 1.6.9 as Next Stable Release - #617
Merged
Merged
Conversation
Reverse Sync into Dev
Fix a new bug identified and introduced by commit: bae3640 And PR: #539 This bug appears to be a concurrent firmware management collision, essentially a race while flashing a node while checking it for updates from the primary at the same time. I accidently ran into this, the seems to be that the node had prepared for the update, authenticated to its own WebUI, and was just about to hand the beta1 image to /upgrade.cgi When at that exact time, I started an upgrade from the primary, which logged into the node to check for updates, triggered start_webs_update, and resulted in putting the node’s ASUS firmware update system into a competing update/check state and ultimately MerlinAU rebooted the node without flashing any firmware. This may also be related to a report from JimbobJay here: https://www.snbforums.com/threads/merlinau-v1-6-8-the-ultimate-firmware-auto-updater.96306/post-999444
Stop logging out early, allow _GetNodeInfo_ to logout
Tightening up the Flash Order Adjusting the flash order so we delete cron jobs before unloading Entware. (Incase a cron tries to fire for an entware script that is unloaded) This may also be related to a report from JimbobJay here: https://www.snbforums.com/threads/merlinau-v1-6-8-the-ultimate-firmware-auto-updater.96306/post-999444 Also adjusted the WebUI restart to be RIGHT before we login to the router to start the flash. The vulnerable window was the gap between the WebUI restart, unloading the USB, and flashing. Also adjusted the order so we say flashing right before we actually restart the WebUI and flash
Fixed issue in the CLI menu, where user was unable to perform a "Copy&Paste" operation when entering the password string.
Fix for 'Copy&Paste' into Password Entry
Prevent mesh firmware checks from interrupting node updates
- Fixed bug due to restarting the HTTP daemon right before starting to flash the F/W image. This was causing the previously authenticated login session token/cookie to become invalid. - Modified and improved functions used to login to the primary router and AiMesh nodes. - Added code to double-check that the current login session token/cookie is still valid before proceeding to flash the F/W image. If it's not valid, a 2nd login is attempted. If that fails, the router is rebooted to make sure the router goes back to a fresh state. - Miscellaneous improvements and fine-tuning.
Fixes and Improvements
Adjusted code to account for concurrent AiMesh Node operations.
Fixed a typo which would have cause a bug!!
Fixed another typo, LOL!!!!
Account for Concurrent AiMesh Node Operations
This makes sure that dependabot always checks and submits against dev. Checking against main works against our other workflows and architecture such as Check-PRsource.yml
Render downloaded changelog as text
Harden pull request source branch check
Preserve failures during MerlinAU self-update
Safely escape values written through sed
- Fixed issue where setting the email format to "Plain Text" in the SSH CLI menu, the WebUI would show the selection box as empty instead of reflecting the "Plain Text" setting made previously by the user. - Fixed parsing issues when handling unusual but valid user input for the "Secondary Email Address" option. - Improved functions that set and get configuration settings, also making sure values stored as assignment statements are defined as literal strings (e.g. KeyName='KeyValue'). - Included fix in the WebUI from @maghuro to properly handle the colon separator in login credentials (i.e. username:password). - Miscellaneous code improvements.
Log out of an AiMesh node immediately when merlinau_fw_update=1 is detected. Skip all further node actions / status while that node is flashing. Report actively flashing nodes as busy instead of failed/unreachable in mn screen. Clean up per-run AiMesh state properly. Preserve failed WebUI login diagnostics in JFFS. Protect concurrent diagnostic writes. Reuse existing log-retention mechanism for the new diagnostic logs.. Clear the firmware-update guard on failed or aborted updates.
Fix Logout Request... Standardizing node logouts
removes the ineffective 5-second wait for login_ip_str to clear... if the existing cookie has failed and login_ip_str is still populated, restarts httpd
improve wording
Fixes and Code Improvements
improve notes
Moving the flashing wording
wording improvements
Additional cleanup
Correct date
Fix AiMesh 2nd Login Attempt
Owner
Author
|
Good to go, i'll wait for your approval and post the forums post :) |
ExtremeFiretop
enabled auto-merge
September 27, 2026 21:24
Martinski4GitHub
approved these changes
Sep 28, 2026
Martinski4GitHub
left a comment
Collaborator
There was a problem hiding this comment.
Good to go live and "into the wild"!!!!
Owner
Author
Sold! Thanks bud! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Forms post update = READY
Readme update = COMPLETED
Version.txt update = COMPLETED
Dev 1.6.9 as Next Stable Release
What's Changed/Fixed?:
PR: #601 ] - Prevent mesh firmware checks from interrupting node updates
PR: [ #602 ] - Fix for 'Copy&Paste' into Password Entry
PR: [ #603 ] - Fixes and Improvements
PR: [ #604 ] - Account for Concurrent AiMesh Node Operations
PR: [ #606 ] - Preserve failures during MerlinAU self-update
PR: [ #[607] & #608 ] - General hardening and cleanup
PR: [ #610 ] - Safely escape values written through sed
PR: [ #614 ] - Fixes and Code Improvements
PR: #615 ] - Fix AiMesh 2nd Login Attempt
As always, we highly recommend you update ASAP as this includes functional improvements and little bug fixes.
Thanks!