Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

openvpn v2.4.5 is incompatible to our current tunnel-gateways #580

Closed
pmelange opened this issue Jul 31, 2018 · 42 comments
Closed

openvpn v2.4.5 is incompatible to our current tunnel-gateways #580

pmelange opened this issue Jul 31, 2018 · 42 comments

Comments

@pmelange
Copy link
Contributor

This is happening on freshly installed and configured (through the wizard) tunnel-berlin images in "master" and "SAm0815_experimental". This is possibly also an issue in other builds/branches, although I haven't tested them.

  • Upon startup, openvpn is not started automatically (noting related to openvpn in the logfile).
  • Running "/etc/init.d/openvpn restart" the following happens.
~# /etc/init.d/openvpn restart
Command failed: Not found
  • After running the above command, openvpn does start. But it doesn't work properly.
Tue Jul 31 14:50:11 2018 authpriv.info dropbear[2942]: Child connection from fdd2:4dde:2cc1::d43:40926
Tue Jul 31 14:50:12 2018 kern.notice kernel: [  105.382314] random: crng init done
Tue Jul 31 14:50:14 2018 authpriv.notice dropbear[2942]: Password auth succeeded for 'root' from fdd2:4dde:2cc1::d43:40926
Tue Jul 31 14:51:14 2018 daemon.notice openvpn(ffuplink)[2974]: OpenVPN 2.4.5 mips-openwrt-linux-gnu [SSL (mbed TLS)] [EPOLL] [AEAD]
Tue Jul 31 14:51:14 2018 daemon.notice openvpn(ffuplink)[2974]: library versions: mbed TLS 2.11.0
Tue Jul 31 14:51:14 2018 daemon.warn openvpn(ffuplink)[2974]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Tue Jul 31 14:51:14 2018 daemon.warn openvpn(ffuplink)[2974]: WARNING: failed to personalise random
Tue Jul 31 14:51:14 2018 daemon.warn openvpn(ffuplink)[2974]: ******* WARNING *******: '--cipher none' was specified. This means NO encryption will be performed and tunnelled data WILL be transmitted in clear text over the network! PLEASE DO RECONSIDER THIS SETTING!
Tue Jul 31 14:51:14 2018 daemon.notice openvpn(ffuplink)[2974]: TCP/UDP: Preserving recently used remote address: [AF_INET]217.197.83.193:1194
Tue Jul 31 14:51:14 2018 daemon.notice openvpn(ffuplink)[2974]: UDPv4 link local (bound): [AF_INET][undef]:1194
Tue Jul 31 14:51:14 2018 daemon.notice openvpn(ffuplink)[2974]: UDPv4 link remote: [AF_INET]217.197.83.193:1194
Tue Jul 31 14:51:15 2018 daemon.warn openvpn(ffuplink)[2974]: WARNING: 'link-mtu' is used inconsistently, local='link-mtu 1525', remote='link-mtu 1526'
Tue Jul 31 14:51:15 2018 daemon.warn openvpn(ffuplink)[2974]: WARNING: 'comp-lzo' is present in remote config but missing in local config, remote='comp-lzo'
Tue Jul 31 14:51:15 2018 daemon.notice openvpn(ffuplink)[2974]: [freifunk-gw01.in-berlin.de] Peer Connection Initiated with [AF_INET]217.197.83.193:1194
Tue Jul 31 14:51:16 2018 daemon.notice netifd: Interface 'ffuplink' is enabled
Tue Jul 31 14:51:16 2018 daemon.notice netifd: Network device 'ffuplink' link is up
Tue Jul 31 14:51:16 2018 daemon.notice openvpn(ffuplink)[2974]: TUN/TAP device ffuplink opened
Tue Jul 31 14:51:16 2018 daemon.notice netifd: Interface 'ffuplink' has link connectivity
Tue Jul 31 14:51:16 2018 daemon.notice openvpn(ffuplink)[2974]: do_ifconfig, tt->did_ifconfig_ipv6_setup=0
Tue Jul 31 14:51:16 2018 daemon.notice netifd: Interface 'ffuplink' is setting up now
Tue Jul 31 14:51:16 2018 daemon.notice openvpn(ffuplink)[2974]: /sbin/ifconfig ffuplink 172.31.241.61 netmask 255.255.255.0 mtu 1500 broadcast 172.31.241.255
Tue Jul 31 14:51:16 2018 daemon.notice netifd: Interface 'ffuplink' is now up
Tue Jul 31 14:51:16 2018 daemon.notice openvpn(ffuplink)[2974]: /lib/freifunk/ffvpn-up.sh ffuplink 1500 1552 172.31.241.61 255.255.255.0 init
Tue Jul 31 14:51:16 2018 user.debug up-down-ffvpn: no route_net_gateway env var from openvpn!
Tue Jul 31 14:51:16 2018 daemon.warn openvpn(ffuplink)[2974]: WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Tue Jul 31 14:51:16 2018 daemon.notice openvpn(ffuplink)[2974]: Initialization Sequence Completed
Tue Jul 31 14:51:18 2018 daemon.info modprobe: Usage: 	modprobe [-q] filename
Tue Jul 31 14:51:18 2018 daemon.err modprobe: ifb is already loaded
Tue Jul 31 14:51:18 2018 daemon.err modprobe: cls_u32 is already loaded
Tue Jul 31 14:51:18 2018 daemon.err modprobe: em_u32 is already loaded
Tue Jul 31 14:51:18 2018 daemon.err modprobe: act_connmark is already loaded
Tue Jul 31 14:51:18 2018 daemon.err modprobe: act_mirred is already loaded
Tue Jul 31 14:51:18 2018 daemon.err modprobe: sch_ingress is already loaded
Tue Jul 31 14:51:18 2018 daemon.err modprobe: cls_fw is already loaded
Tue Jul 31 14:51:18 2018 daemon.err modprobe: sch_hfsc is already loaded
Tue Jul 31 14:51:19 2018 user.notice up-down-ffvpn: ugw: 192.168.1.1 dev: ffuplink remote: 255.255.255.0 gw: 172.31.241.1 src: 172.31.241.61 mask: 255.255.255.0
Tue Jul 31 14:51:19 2018 user.notice firewall: Reloading firewall due to ifup of ffuplink (ffuplink)
Tue Jul 31 14:51:19 2018 daemon.info olsrd_hotplug: [OK] ifup: 'ffuplink' => 'ffuplink'
Tue Jul 31 14:51:19 2018 daemon.debug olsrd_hotplug: [OK] interface 'ffuplink' => 'ffuplink' not used for olsrd
Tue Jul 31 14:51:20 2018 daemon.info olsrd_hotplug: [OK] ifup: 'ffuplink' => 'ffuplink'
Tue Jul 31 14:51:20 2018 daemon.debug olsrd_hotplug: [OK] interface 'ffuplink' => 'ffuplink' not used for olsrd6
Tue Jul 31 14:51:20 2018 user.notice ff-userlog: ffuplink interface is up
Tue Jul 31 14:51:20 2018 user.notice ff-userlog: creating ffuplink ip-rules
Tue Jul 31 14:51:20 2018 user.notice ff-userlog: UCI did not return a valid IP-net for ffuplink; querying directly with ip-tool
Tue Jul 31 14:51:20 2018 user.notice ff-userlog: ffuplink-interface is setup
Tue Jul 31 14:51:26 2018 daemon.err openvpn(ffuplink)[2974]: write to TUN/TAP : Invalid argument (code=22)
Tue Jul 31 14:51:29 2018 daemon.err odhcp6c[1414]: Failed to send DHCPV6 message to ff02::1:2 (Permission denied)
Tue Jul 31 14:51:30 2018 daemon.warn odhcpd[994]: DHCPV6 RENEW IA_NA from 00041255ae230e49244278313f53c3a1f05f on br-dhcp: ok fdd2:4dde:2cc1::d43/128
Tue Jul 31 14:51:36 2018 daemon.err openvpn(ffuplink)[2974]: write to TUN/TAP : Invalid argument (code=22)
Tue Jul 31 14:51:46 2018 daemon.err openvpn(ffuplink)[2974]: write to TUN/TAP : Invalid argument (code=22)
Tue Jul 31 14:51:56 2018 daemon.err openvpn(ffuplink)[2974]: write to TUN/TAP : Invalid argument (code=22)
Tue Jul 31 14:52:07 2018 daemon.err openvpn(ffuplink)[2974]: write to TUN/TAP : Invalid argument (code=22)
Tue Jul 31 14:52:17 2018 daemon.err openvpn(ffuplink)[2974]: write to TUN/TAP : Invalid argument (code=22)
Tue Jul 31 14:52:28 2018 daemon.err openvpn(ffuplink)[2974]: write to TUN/TAP : Invalid argument (code=22)
Tue Jul 31 14:52:38 2018 daemon.err openvpn(ffuplink)[2974]: write to TUN/TAP : Invalid argument (code=22)
Tue Jul 31 14:52:48 2018 daemon.err openvpn(ffuplink)[2974]: write to TUN/TAP : Invalid argument (code=22)
Tue Jul 31 14:52:58 2018 daemon.err openvpn(ffuplink)[2974]: write to TUN/TAP : Invalid argument (code=22)
Tue Jul 31 14:53:08 2018 daemon.err openvpn(ffuplink)[2974]: write to TUN/TAP : Invalid argument (code=22)
Tue Jul 31 14:53:42 2018 daemon.err odhcp6c[1414]: Failed to send DHCPV6 message to ff02::1:2 (Permission denied)
Tue Jul 31 14:54:00 2018 daemon.warn odhcpd[994]: DHCPV6 RENEW IA_NA from 00041255ae230e49244278313f53c3a1f05f on br-dhcp: ok fdd2:4dde:2cc1::d43/128
Tue Jul 31 14:54:08 2018 daemon.notice openvpn(ffuplink)[2974]: [freifunk-gw01.in-berlin.de] Inactivity timeout (--ping-restart), restarting
Tue Jul 31 14:54:08 2018 daemon.notice openvpn(ffuplink)[2974]: /sbin/ifconfig ffuplink 0.0.0.0
Tue Jul 31 14:54:08 2018 daemon.notice netifd: Network device 'ffuplink' link is down
Tue Jul 31 14:54:08 2018 daemon.notice netifd: Interface 'ffuplink' has link connectivity loss
Tue Jul 31 14:54:08 2018 daemon.notice netifd: Interface 'ffuplink' is now down
Tue Jul 31 14:54:08 2018 daemon.notice openvpn(ffuplink)[2974]: SIGUSR1[soft,ping-restart] received, process restarting
Tue Jul 31 14:54:08 2018 daemon.notice netifd: Interface 'ffuplink' is disabled
Tue Jul 31 14:54:08 2018 user.notice ff-userlog: ffuplink interface going down
Tue Jul 31 14:54:13 2018 daemon.warn openvpn(ffuplink)[2974]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Tue Jul 31 14:54:13 2018 daemon.notice openvpn(ffuplink)[2974]: TCP/UDP: Preserving recently used remote address: [AF_INET]217.197.83.193:1194
Tue Jul 31 14:54:13 2018 daemon.notice openvpn(ffuplink)[2974]: UDPv4 link local (bound): [AF_INET][undef]:1194
Tue Jul 31 14:54:13 2018 daemon.notice openvpn(ffuplink)[2974]: UDPv4 link remote: [AF_INET]217.197.83.193:1194
Tue Jul 31 14:54:14 2018 daemon.warn openvpn(ffuplink)[2974]: WARNING: 'link-mtu' is used inconsistently, local='link-mtu 1525', remote='link-mtu 1526'
Tue Jul 31 14:54:14 2018 daemon.warn openvpn(ffuplink)[2974]: WARNING: 'comp-lzo' is present in remote config but missing in local config, remote='comp-lzo'
Tue Jul 31 14:54:14 2018 daemon.notice openvpn(ffuplink)[2974]: [freifunk-gw01.in-berlin.de] Peer Connection Initiated with [AF_INET]217.197.83.193:1194
Tue Jul 31 14:54:15 2018 daemon.notice netifd: Interface 'ffuplink' is enabled
Tue Jul 31 14:54:15 2018 daemon.notice netifd: Network device 'ffuplink' link is up
Tue Jul 31 14:54:15 2018 daemon.notice netifd: Interface 'ffuplink' has link connectivity
Tue Jul 31 14:54:15 2018 daemon.notice openvpn(ffuplink)[2974]: TUN/TAP device ffuplink opened
Tue Jul 31 14:54:15 2018 daemon.notice netifd: Interface 'ffuplink' is setting up now
Tue Jul 31 14:54:15 2018 daemon.notice openvpn(ffuplink)[2974]: do_ifconfig, tt->did_ifconfig_ipv6_setup=0
Tue Jul 31 14:54:15 2018 daemon.notice openvpn(ffuplink)[2974]: /sbin/ifconfig ffuplink 172.31.241.61 netmask 255.255.255.0 mtu 1500 broadcast 172.31.241.255
Tue Jul 31 14:54:15 2018 daemon.notice netifd: Interface 'ffuplink' is now up
Tue Jul 31 14:54:15 2018 daemon.notice openvpn(ffuplink)[2974]: /lib/freifunk/ffvpn-up.sh ffuplink 1500 1552 172.31.241.61 255.255.255.0 init
Tue Jul 31 14:54:15 2018 user.debug up-down-ffvpn: no route_net_gateway env var from openvpn!
Tue Jul 31 14:54:15 2018 daemon.notice openvpn(ffuplink)[2974]: Initialization Sequence Completed
Tue Jul 31 14:54:17 2018 daemon.info modprobe: Usage: 	modprobe [-q] filename
Tue Jul 31 14:54:17 2018 daemon.err modprobe: ifb is already loaded
Tue Jul 31 14:54:17 2018 daemon.err modprobe: cls_u32 is already loaded
Tue Jul 31 14:54:17 2018 daemon.err modprobe: em_u32 is already loaded
Tue Jul 31 14:54:17 2018 daemon.err modprobe: act_connmark is already loaded
Tue Jul 31 14:54:17 2018 daemon.err modprobe: act_mirred is already loaded
Tue Jul 31 14:54:17 2018 daemon.err modprobe: sch_ingress is already loaded
Tue Jul 31 14:54:17 2018 daemon.err modprobe: cls_fw is already loaded
Tue Jul 31 14:54:17 2018 daemon.err modprobe: sch_hfsc is already loaded
Tue Jul 31 14:54:17 2018 user.notice up-down-ffvpn: ugw: 192.168.1.1 dev: ffuplink remote: 255.255.255.0 gw: 172.31.241.1 src: 172.31.241.61 mask: 255.255.255.0
Tue Jul 31 14:54:18 2018 user.notice firewall: Reloading firewall due to ifup of ffuplink (ffuplink)
Tue Jul 31 14:54:18 2018 daemon.info olsrd_hotplug: [OK] ifup: 'ffuplink' => 'ffuplink'
Tue Jul 31 14:54:18 2018 daemon.debug olsrd_hotplug: [OK] interface 'ffuplink' => 'ffuplink' not used for olsrd
Tue Jul 31 14:54:18 2018 daemon.info olsrd_hotplug: [OK] ifup: 'ffuplink' => 'ffuplink'
Tue Jul 31 14:54:18 2018 daemon.debug olsrd_hotplug: [OK] interface 'ffuplink' => 'ffuplink' not used for olsrd6
Tue Jul 31 14:54:18 2018 user.notice ff-userlog: ffuplink interface is up
Tue Jul 31 14:54:18 2018 user.notice ff-userlog: creating ffuplink ip-rules
Tue Jul 31 14:54:18 2018 user.notice ff-userlog: UCI did not return a valid IP-net for ffuplink; querying directly with ip-tool
Tue Jul 31 14:54:19 2018 user.notice ff-userlog: ffuplink-interface is setup
Tue Jul 31 14:54:25 2018 daemon.err openvpn(ffuplink)[2974]: write to TUN/TAP : Invalid argument (code=22)
  • The only difference in the options in /etc/config/openvpn between Hedy-1.0.1 and the master/SAm branches is that in Hedy-1.0.1 there is the following option
option local '192.168.1.4'
  • After adding the "local" option, there is no difference. Openvpn does not start automatically and manually starting has the same results as shown above.
@pmelange pmelange changed the title tunnel-berlin images in "master" and "SAm0815_experimental" not working openvpn: tunnel-berlin images in "master" and "SAm0815_experimental" not working Jul 31, 2018
pmelange referenced this issue Jul 31, 2018
Patch mbedtls to allow 1024 bits RSA
for bbb-vpn and VPN03 compatibility

fixes #489
@pmelange
Copy link
Contributor Author

pmelange commented Aug 1, 2018

Update: I have found one of the problems... The hotplug script in firmware-packages/defaults/freifunk-berlin-openvpn-files/openvpn/60-ffopenvpn declared variables with the "local" declaration. I have made commit a87f7e53259e1f588f7747a16557c895a3fe7ce8 with the needed changes.

Now OpenVPN starts at boot time and there is not longer an error when running "/etc/init.d/openvpn restart". That, at least, is step 1 of the problem.

But the rest of the problems from the description persist.

If it helps, there are errors in /tmp/ffvpn-up.log

net.ipv6.conf.ffuplink.disable_ipv6 = 1
RTNETLINK answers: No such process
RTNETLINK answers: No such process

pmelange referenced this issue in freifunk-berlin/firmware-packages Aug 1, 2018
@SvenRoederer
Copy link
Contributor

I think the problem comes from here:

Tue Jul 31 14:51:15 2018 daemon.warn openvpn(ffuplink)[2974]: WARNING: 'link-mtu' is used inconsistently, local='link-mtu 1525', remote='link-mtu 1526'
Tue Jul 31 14:51:15 2018 daemon.warn openvpn(ffuplink)[2974]: WARNING: 'comp-lzo' is present in remote config but missing in local config, remote='comp-lzo'

and a result is (check a search-engine for openvpn lzo "Invalid argument (code=22)")

openvpn(ffuplink)[2974]: write to TUN/TAP : Invalid argument (code=22)

probably related to some deprecation of the comp-lzo setting in openvpn

have you tried to build a version w/o the mbedtls-1024 patch? Did that work?

@pmelange
Copy link
Contributor Author

pmelange commented Aug 2, 2018

I have built the master branch without the 1024 patch with the same results. I also removed vpnbypass with and without the 1024 patch. Same results.

Here is the logfile. It doesn't look different from before

Thu Aug  2 22:46:39 2018 user.notice ff-vpn-hotplug: Starting OpenVPN on WAN interface
Thu Aug  2 22:46:40 2018 daemon.notice openvpn(ffuplink)[3070]: OpenVPN 2.4.5 mips-openwrt-linux-gnu [SSL (mbed TLS)] [EPOLL] [AEAD]
Thu Aug  2 22:46:40 2018 daemon.notice openvpn(ffuplink)[3070]: library versions: mbed TLS 2.8.0
Thu Aug  2 22:46:40 2018 daemon.warn openvpn(ffuplink)[3070]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Thu Aug  2 22:46:40 2018 daemon.warn openvpn(ffuplink)[3070]: WARNING: failed to personalise random
Thu Aug  2 22:46:40 2018 daemon.warn openvpn(ffuplink)[3070]: ******* WARNING *******: '--cipher none' was specified. This means NO encryption will be performed and tunnelled data WILL be transmitted in clear text over the network! PLEASE DO RECONSIDER THIS SETTING!
Thu Aug  2 22:46:40 2018 daemon.notice openvpn(ffuplink)[3070]: TCP/UDP: Preserving recently used remote address: [AF_INET]46.4.104.30:1194
Thu Aug  2 22:46:40 2018 daemon.notice openvpn(ffuplink)[3070]: UDPv4 link local (bound): [AF_INET]192.168.200.3:1194
Thu Aug  2 22:46:40 2018 daemon.notice openvpn(ffuplink)[3070]: UDPv4 link remote: [AF_INET]46.4.104.30:1194
Thu Aug  2 22:46:41 2018 daemon.err odhcp6c[1449]: Failed to send DHCPV6 message to ff02::1:2 (Permission denied)
Thu Aug  2 22:46:43 2018 kern.notice kernel: [   64.833292] random: crng init done
Thu Aug  2 22:47:00 2018 cron.err crond[2977]: time disparity of 1681 minutes detected
Thu Aug  2 22:47:18 2018 daemon.err odhcp6c[1449]: Failed to send DHCPV6 message to ff02::1:2 (Permission denied)
Thu Aug  2 22:47:40 2018 daemon.notice openvpn(ffuplink)[3070]: [UNDEF] Inactivity timeout (--ping-restart), restarting
Thu Aug  2 22:47:40 2018 daemon.notice openvpn(ffuplink)[3070]: SIGUSR1[soft,ping-restart] received, process restarting
Thu Aug  2 22:47:45 2018 daemon.warn openvpn(ffuplink)[3070]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Thu Aug  2 22:47:45 2018 daemon.notice openvpn(ffuplink)[3070]: TCP/UDP: Preserving recently used remote address: [AF_INET]217.197.83.193:1194
Thu Aug  2 22:47:45 2018 daemon.notice openvpn(ffuplink)[3070]: UDPv4 link local (bound): [AF_INET]192.168.200.3:1194
Thu Aug  2 22:47:45 2018 daemon.notice openvpn(ffuplink)[3070]: UDPv4 link remote: [AF_INET]217.197.83.193:1194
Thu Aug  2 22:47:47 2018 daemon.warn openvpn(ffuplink)[3070]: WARNING: 'link-mtu' is used inconsistently, local='link-mtu 1525', remote='link-mtu 1526'
Thu Aug  2 22:47:47 2018 daemon.warn openvpn(ffuplink)[3070]: WARNING: 'comp-lzo' is present in remote config but missing in local config, remote='comp-lzo'
Thu Aug  2 22:47:47 2018 daemon.notice openvpn(ffuplink)[3070]: [freifunk-gw01.in-berlin.de] Peer Connection Initiated with [AF_INET]217.197.83.193:1194
Thu Aug  2 22:47:48 2018 daemon.notice netifd: Interface 'ffuplink' is enabled
Thu Aug  2 22:47:48 2018 daemon.notice netifd: Network device 'ffuplink' link is up
Thu Aug  2 22:47:48 2018 daemon.notice openvpn(ffuplink)[3070]: TUN/TAP device ffuplink opened
Thu Aug  2 22:47:48 2018 daemon.notice netifd: Interface 'ffuplink' has link connectivity
Thu Aug  2 22:47:48 2018 daemon.notice openvpn(ffuplink)[3070]: do_ifconfig, tt->did_ifconfig_ipv6_setup=0
Thu Aug  2 22:47:48 2018 daemon.notice netifd: Interface 'ffuplink' is setting up now
Thu Aug  2 22:47:48 2018 daemon.notice openvpn(ffuplink)[3070]: /sbin/ifconfig ffuplink 172.31.241.61 netmask 255.255.255.0 mtu 1500 broadcast 172.31.241.255
Thu Aug  2 22:47:48 2018 daemon.notice netifd: Interface 'ffuplink' is now up
Thu Aug  2 22:47:48 2018 daemon.notice openvpn(ffuplink)[3070]: /lib/freifunk/ffvpn-up.sh ffuplink 1500 1552 172.31.241.61 255.255.255.0 init
Thu Aug  2 22:47:48 2018 user.debug up-down-ffvpn: no route_net_gateway env var from openvpn!
Thu Aug  2 22:47:48 2018 daemon.warn openvpn(ffuplink)[3070]: WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Thu Aug  2 22:47:48 2018 daemon.notice openvpn(ffuplink)[3070]: Initialization Sequence Completed
Thu Aug  2 22:47:50 2018 daemon.info modprobe: Usage: 	modprobe [-q] filename
Thu Aug  2 22:47:50 2018 daemon.err modprobe: ifb is already loaded
Thu Aug  2 22:47:50 2018 daemon.err modprobe: cls_u32 is already loaded
Thu Aug  2 22:47:50 2018 daemon.err modprobe: em_u32 is already loaded
Thu Aug  2 22:47:50 2018 daemon.err modprobe: act_connmark is already loaded
Thu Aug  2 22:47:50 2018 daemon.err modprobe: act_mirred is already loaded
Thu Aug  2 22:47:50 2018 daemon.err modprobe: sch_ingress is already loaded
Thu Aug  2 22:47:50 2018 daemon.err modprobe: cls_fw is already loaded
Thu Aug  2 22:47:50 2018 user.notice up-down-ffvpn: ugw: 192.168.200.1 dev: ffuplink remote: 255.255.255.0 gw: 172.31.241.1 src: 172.31.241.61 mask: 255.255.255.0
Thu Aug  2 22:47:50 2018 daemon.err modprobe: sch_hfsc is already loaded
Thu Aug  2 22:47:51 2018 user.notice firewall: Reloading firewall due to ifup of ffuplink (ffuplink)
Thu Aug  2 22:47:51 2018 daemon.info olsrd_hotplug: [OK] ifup: 'ffuplink' => 'ffuplink'
Thu Aug  2 22:47:51 2018 daemon.debug olsrd_hotplug: [OK] interface 'ffuplink' => 'ffuplink' not used for olsrd
Thu Aug  2 22:47:51 2018 daemon.info olsrd_hotplug: [OK] ifup: 'ffuplink' => 'ffuplink'
Thu Aug  2 22:47:51 2018 daemon.debug olsrd_hotplug: [OK] interface 'ffuplink' => 'ffuplink' not used for olsrd6
Thu Aug  2 22:47:51 2018 user.notice ff-userlog: OpenVPN connection has been established
Thu Aug  2 22:47:51 2018 user.notice ff-userlog: ffuplink interface is up
Thu Aug  2 22:47:51 2018 user.notice ff-userlog: creating ffuplink ip-rules
Thu Aug  2 22:47:52 2018 user.notice ff-userlog: UCI did not return a valid IP-net for ffuplink; querying directly with ip-tool
Thu Aug  2 22:47:52 2018 user.notice ff-userlog: ffuplink-interface is setup
Thu Aug  2 22:47:58 2018 daemon.err openvpn(ffuplink)[3070]: write to TUN/TAP : Invalid argument (code=22)
Thu Aug  2 22:48:08 2018 daemon.err openvpn(ffuplink)[3070]: write to TUN/TAP : Invalid argument (code=22)
Thu Aug  2 22:48:18 2018 daemon.err openvpn(ffuplink)[3070]: write to TUN/TAP : Invalid argument (code=22)

Here is the results from tcpdump while pinging 8.8.8.8 from a client. There are checksum errors.

root@ptest2:~# tcpdump  -nvvi br-wan host 217.197.83.193 or host 46.4.104.30
tcpdump: listening on br-wan, link-type EN10MB (Ethernet), capture size 262144 bytes
22:50:56.042355 IP (tos 0x0, ttl 64, id 3801, offset 0, flags [DF], proto UDP (17), length 136)
    192.168.200.3.1194 > 217.197.83.193.1194: [bad udp cksum 0xb6b8 -> 0x8450!] UDP, length 108
22:50:57.050206 IP (tos 0x0, ttl 64, id 3838, offset 0, flags [DF], proto UDP (17), length 136)
    192.168.200.3.1194 > 217.197.83.193.1194: [bad udp cksum 0xb6b8 -> 0xcf66!] UDP, length 108
22:50:57.059920 IP (tos 0x0, ttl 59, id 62922, offset 0, flags [DF], proto UDP (17), length 66)
    217.197.83.193.1194 > 192.168.200.3.1194: [udp sum ok] UDP, length 38
22:50:58.058255 IP (tos 0x0, ttl 64, id 3859, offset 0, flags [DF], proto UDP (17), length 136)
    192.168.200.3.1194 > 217.197.83.193.1194: [bad udp cksum 0xb6b8 -> 0x0c0a!] UDP, length 108
22:50:59.066179 IP (tos 0x0, ttl 64, id 3941, offset 0, flags [DF], proto UDP (17), length 136)
    192.168.200.3.1194 > 217.197.83.193.1194: [bad udp cksum 0xb6b8 -> 0x3675!] UDP, length 108
22:51:00.074120 IP (tos 0x0, ttl 64, id 3973, offset 0, flags [DF], proto UDP (17), length 136)
    192.168.200.3.1194 > 217.197.83.193.1194: [bad udp cksum 0xb6b8 -> 0x8ba0!] UDP, length 108
22:51:01.082085 IP (tos 0x0, ttl 64, id 4039, offset 0, flags [DF], proto UDP (17), length 136)
    192.168.200.3.1194 > 217.197.83.193.1194: [bad udp cksum 0xb6b8 -> 0x0392!] UDP, length 108

@sarumpaet
Copy link
Contributor

Perhaps 087680a ?
Test with the standard OpenWrt OpenVPN package?

@pmelange
Copy link
Contributor Author

pmelange commented Aug 5, 2018

I'm building now with these changes removed, but with the 1024 patch and vpnbypass in. I'll let you know tomorrow.

@pmelange
Copy link
Contributor Author

pmelange commented Aug 6, 2018

With the changes in 087680a removed, I still have the same problems.

@booo
Copy link
Member

booo commented Aug 6, 2018

Please check against one of the VPN03 servers.

@pmelange
Copy link
Contributor Author

pmelange commented Aug 6, 2018

With the changes in 087680a removed, and with the 1024 patch and vpnbypass in, configured to use vpn03 (with the correct certs, keys, ...), I still have the same problems.

@pmelange
Copy link
Contributor Author

pmelange commented Aug 6, 2018

I just tried out openwrt 18.06.0 with openvpn (mbedtls). I'm also getting these "code=22" errors.

@pmelange
Copy link
Contributor Author

pmelange commented Aug 6, 2018

With 17.01.5 I don't get these errors.

EDIT: Changed version number to be correct

@pmelange
Copy link
Contributor Author

pmelange commented Aug 6, 2018

https://community.openvpn.net/openvpn/ticket/952 might explain what is going on.

In Hedy 1.0.1 we use openvpn 2.4.4
In master we use openvpn 2.4.5
in 17.01.5 they use openvpn 2.4.4
in 18.06.0 they use openvpn 2.4.5

On server vpn03f.berlin.freifunk.net we use 2.3.12
On server vm02.roellig-it.de) we use 2.3.10

It would be really great if someone with more experience with openvpn took a look at this.

@SvenRoederer
Copy link
Contributor

SvenRoederer commented Aug 6, 2018

freifunk-gw01.in-berlin.de : Version: 2.4.0-6+deb9u2

"comp-lzo no" is set

@SvenRoederer SvenRoederer changed the title openvpn: tunnel-berlin images in "master" and "SAm0815_experimental" not working openvpn v2.4.5 is incompatible to our current tunnel-gateways Aug 9, 2018
@SvenRoederer SvenRoederer added this to the Hedy-1.1.0 milestone Aug 9, 2018
@pmelange
Copy link
Contributor Author

I have created a ticket with openwrt:
https://bugs.openwrt.org/index.php?do=details&task_id=1762

@SvenRoederer, could you post the server config for freifunk-gw01.in-berlin.de?

@pmelange
Copy link
Contributor Author

@lynxis As per your request, I have posted a ticket with openwrt.
https://bugs.openwrt.org/index.php?do=details&task_id=1762

@SvenRoederer
Copy link
Contributor

SvenRoederer commented Aug 10, 2018

as mentioned 11 months ago, the config-files are here: https://github.com/freifunk-berlin/puppet-files/blob/tunnel-berlin/files/tunnel-berlin

@pmelange
Copy link
Contributor Author

Thank to help from the openwrt issue tracker, I new have a configuration on the client side which successfully makes a vpn connection to freifunk-gw01.in-berlin.de. I haven't tried any vpn03 servers.

The needed extra option is:

     option compress 'lzo'

I have tried this both with and without option comp-lzo 'no' , and both setups work.

I don't have access to the server. But it would be good to know if, in the end, compression is turned off. @SvenRoederer, could you check this on the server side?

According to the man page, it should be possible to give the option compress an empty value, but this didn't work. Another possible value for this option is lz4 instead of lzo. This also didn't work.

I won't have time to make the changes to the firmware before early September. If someone else wants to make these changes, that would be great.

@pmelange
Copy link
Contributor Author

Sorry, I wrote too soon. The option compress lzo works with 18.06.01 but not with the freifunk firmware.

@SvenRoederer
Copy link
Contributor

As you can see from the sever-configs, we want no compression at all. So compression of data on the client side but no decompression on the server-side will fail logically.

according to the openvpn-ticket referenced above, one solution would be to enable lzo on both sides of the tunnel. but this requires a change on all clients.

@pmelange
Copy link
Contributor Author

Having compression on the client->server and no compression on the server->client (and visa-versa) is a totally valid configuration. The reason that it didn't work with the freifunk firmware, like I wrote above, is because of 087680a.

It is also possible to have the server push no compression to the clients after they connect.

The thing that is a problem is that I still can't figure out a way to have the clients do no compression. Simply leaving out the compress option will not work. I have tried various versions of the compress option, but I still haven't found one that works.

So, my suggestion is that we re-enable the CONFIG_OPENVPN_mbedtls_ENABLE_LZO compile option and have the server push no compression. The downside is a bigger binary and dependency on liblzo.

This will be my last post until some time early Sept. If someone else wants to take over this issue, that would be great.

https://community.openvpn.net/openvpn/wiki/DeprecatedOptions
https://community.openvpn.net/openvpn/ticket/952
https://wiki.openwrt.org/inbox/vpn.howto

@booo
Copy link
Member

booo commented Aug 21, 2018

If commit 087680a introduced the problem I'm in favour of reverting this commit or parts of the commit.

@SvenRoederer
Copy link
Contributor

SvenRoederer commented Aug 21, 2018

I just installed the openwrt-18.06-1 openVPN package (including liblzo and libmbedtls) on top of a recent SAm0815_experimental build (c48602e). And I saw the same errors as our package with the disabled options of 087680a.
@pmelange have you tried to build w/o the mentioned changes ? did it work w/o failures?

@pmelange
Copy link
Contributor Author

pmelange commented Sep 5, 2018

@SvenRoederer I installed the packages from 18.06.1 on our firmware, like you did. When I added option compress 'lzo' to /etc/config/openvpn, it worked.

Yes, the problem is still that compression is on. After all my research, it doesn't look like it is possible to have an option like 'none' 'disabled' '0' 'noop' or anything othen than 'lzo' 'lz4' and 'lz4-v2'. It would be worth trying to push the setting from the server with push compress (with no arguements) to force the clients to not use compression. The big drawback is that we still have to include liblzo in the firmware.

Since config comp-lzo 'no' is no longer just deprecated, but no longer supported. The comp-lzo option in /etc/config/openvpn is meaningless.

Not having the 'compress' option in the configuration sets up the header to a certain format which is not compatible with our setup (server and client) which have a special header with compression info. The different headers, as far as I can tell, is the reason for the code=22 errors.

@pmelange
Copy link
Contributor Author

I hacked the openvpn init script to allow for option compress '1' or option compress '0'. The former adds a line with compress in /var/etc/openvpn-ffuplink.conf. This should be what we want. The connection to the server gets established, but I am not able to send any data through. Evenutally the connection times-out and reestablishes.

See https://bugs.openwrt.org/index.php?do=details&task_id=1762

I'm not sure what to do next. Maybe we need to explicitly put compress into the server config file. I'm not sure how this will impact our current clients.

Anybody have any other ideas?
Should we just reenable compiling with liblzo support (and add option compress 'lzo'), since this method works?

@SvenRoederer
Copy link
Contributor

SvenRoederer commented Sep 12, 2018

As mentioned in my last post (#580 (comment)) I had no luck with using the original 18.06-openwrt package of openvpn. So I don't believe in enabling lzo-support will fix this.
But feel free to prove me wrong by creating a branch with enabled liblzo.

@bobster-galore
Copy link
Contributor

What is the problem?
funny options or different versions?

@pmelange
Copy link
Contributor Author

I have created branch openvpn245. I have also installed it on my rb750gr3.

@SvenRoederer , @bobster-galore , @booo I have added your ssh keys to the router. It is reachable via the backbone. The host is ptest3.olsr

I will be gone until Sat evening. Until then, have fun. And if anyone wants to merge the changes on the openvpn245 branches in firmware and firmware-packages, then that would be really cool.

@pmelange
Copy link
Contributor Author

Oh, and I haven't done migration yet. I can do it on Sunday.

@pmelange
Copy link
Contributor Author

There are now two PR's ready for someone to take a look at and (hopefully) merge.

I saw that @SvenRoederer pushed a commit to the master branch to reeable compiling with liblzo support. I believe the PR that I created is complete and with better comments. Also, I find it better to have the compile option commented out (readability and understandability) then just simply deleting the compile options.

I would recommend deleting that commit and merging the openvpn245 branch. I

@pmelange
Copy link
Contributor Author

The system has been running for 5 days now. @SvenRoederer @booo @bobster-galore is there any reason to keep the box running? If nobody objects, I would unplug the router tomorrow evening.

@bobster-galore
Copy link
Contributor

I had no idea what to test. Let it go unplugged!

@bobster-galore
Copy link
Contributor

How do we fix this for 1.1.0?

@pmelange
Copy link
Contributor Author

There are 2 PR's ready to fix this issue. They need a review and hopefully to be merged.

@keks1337
Copy link

keks1337 commented Sep 30, 2018

have same issues. use last build.

Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] Board has DDR2
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] Analog PMU set to hw control
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] Digital PMU set to hw control
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] SoC Type: MediaTek MT7628AN ver:1 eco:2
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] bootconsole [early0] enabled
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] CPU0 revision is: 00019655 (MIPS 24KEc)
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] MIPS: machine is TP-Link TL-WR841N v13
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] Determined physical RAM map:
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000]  memory: 04000000 @ 00000000 (usable)
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] Initrd not found or empty - disabling initrd
Sun Sep 30 17:52:32 2018 kern.warn kernel: [    0.000000] Primary instruction cache 64kB, VIPT, 4-way, linesize 32 bytes.
Sun Sep 30 17:52:32 2018 kern.warn kernel: [    0.000000] Primary data cache 32kB, 4-way, PIPT, no aliases, linesize 32 bytes
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] Zone ranges:
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000]   Normal   [mem 0x0000000000000000-0x0000000003ffffff]
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] Movable zone start for each node
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] Early memory node ranges
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000]   node   0: [mem 0x0000000000000000-0x0000000003ffffff]
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] Initmem setup node 0 [mem 0x0000000000000000-0x0000000003ffffff]
Sun Sep 30 17:52:32 2018 kern.debug kernel: [    0.000000] On node 0 totalpages: 16384
Sun Sep 30 17:52:32 2018 kern.debug kernel: [    0.000000] free_area_init_node: node 0, pgdat 803c8b30, node_mem_map 81000040
Sun Sep 30 17:52:32 2018 kern.debug kernel: [    0.000000]   Normal zone: 128 pages used for memmap
Sun Sep 30 17:52:32 2018 kern.debug kernel: [    0.000000]   Normal zone: 0 pages reserved
Sun Sep 30 17:52:32 2018 kern.debug kernel: [    0.000000]   Normal zone: 16384 pages, LIFO batch:3
Sun Sep 30 17:52:32 2018 kern.notice kernel: [    0.000000] random: get_random_bytes called from 0x803cc72c with crng_init=0
Sun Sep 30 17:52:32 2018 kern.debug kernel: [    0.000000] pcpu-alloc: s0 r0 d32768 u32768 alloc=1*32768
Sun Sep 30 17:52:32 2018 kern.debug kernel: [    0.000000] pcpu-alloc: [0] 0
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] Built 1 zonelists, mobility grouping on.  Total pages: 16256
Sun Sep 30 17:52:32 2018 kern.notice kernel: [    0.000000] Kernel command line: console=ttyS0,115200 rootfstype=squashfs,jffs2
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] PID hash table entries: 256 (order: -2, 1024 bytes)
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] Dentry cache hash table entries: 8192 (order: 3, 32768 bytes)
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] Inode-cache hash table entries: 4096 (order: 2, 16384 bytes)
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] Writing ErrCtl register=00073350
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] Readback ErrCtl register=00073350
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] Memory: 60568K/65536K available (3345K kernel code, 170K rwdata, 364K rodata, 208K init, 208K bss, 4968K reserved, 0K cma-reserved)
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] SLUB: HWalign=32, Order=0-3, MinObjects=0, CPUs=1, Nodes=1
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] NR_IRQS: 256
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] intc: using register map from devicetree
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] CPU Clock: 580MHz
Sun Sep 30 17:52:32 2018 kern.crit kernel: [    0.000000] timer_probe: no matching timers found
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000000] clocksource: MIPS: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 6590553264 ns
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.000012] sched_clock: 32 bits at 290MHz, resolution 3ns, wraps every 7405115902ns
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.007535] Calibrating delay loop... 385.84 BogoMIPS (lpj=1929216)
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.073498] pid_max: default: 32768 minimum: 301
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.078187] Mount-cache hash table entries: 1024 (order: 0, 4096 bytes)
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.084537] Mountpoint-cache hash table entries: 1024 (order: 0, 4096 bytes)
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.096990] clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 19112604462750000 ns
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.106479] futex hash table entries: 256 (order: -1, 3072 bytes)
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.112432] pinctrl core: initialized pinctrl subsystem
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.118008] NET: Registered protocol family 16
Sun Sep 30 17:52:32 2018 kern.warn kernel: [    0.126160] Can't analyze schedule() prologue at 803401cc
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.145505] mt7621_gpio 10000600.gpio: registering 32 gpios
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.151102] mt7621_gpio 10000600.gpio: registering 32 gpios
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.156716] mt7621_gpio 10000600.gpio: registering 32 gpios
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.165904] clocksource: Switched to clocksource MIPS
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.171946] NET: Registered protocol family 2
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.177030] TCP established hash table entries: 1024 (order: 0, 4096 bytes)
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.183721] TCP bind hash table entries: 1024 (order: 0, 4096 bytes)
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.189906] TCP: Hash tables configured (established 1024 bind 1024)
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.196161] UDP hash table entries: 256 (order: 0, 4096 bytes)
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.201759] UDP-Lite hash table entries: 256 (order: 0, 4096 bytes)
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.208108] NET: Registered protocol family 1
Sun Sep 30 17:52:32 2018 kern.debug kernel: [    0.212282] PCI: CLS 0 bytes, default 32
Sun Sep 30 17:52:32 2018 kern.warn kernel: [    0.215247] Crashlog allocated RAM at address 0x3f00000
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.221601] workingset: timestamp_bits=30 max_order=14 bucket_order=0
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.233459] squashfs: version 4.0 (2009/01/31) Phillip Lougher
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.239080] jffs2: version 2.2 (NAND) (SUMMARY) (LZMA) (RTIME) (CMODE_PRIORITY) (c) 2001-2006 Red Hat, Inc.
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.256820] io scheduler noop registered
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.260550] io scheduler deadline registered (default)
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.266498] Serial: 8250/16550 driver, 3 ports, IRQ sharing disabled
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.273726] console [ttyS0] disabled
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.277227] 10000c00.uartlite: ttyS0 at MMIO 0x10000c00 (irq = 28, base_baud = 2500000) is a 16550A
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.285951] console [ttyS0] enabled
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.292943] bootconsole [early0] disabled
Sun Sep 30 17:52:32 2018 kern.err kernel: [    0.301570] cacheinfo: Failed to find cpu0 device node
Sun Sep 30 17:52:32 2018 kern.warn kernel: [    0.306826] cacheinfo: Unable to detect cache hierarchy for CPU 0
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.313697] spi-mt7621 10000b00.spi: sys_freq: 193333333
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.324892] m25p80 spi0.0: gd25q64 (8192 Kbytes)
Sun Sep 30 17:52:32 2018 kern.notice kernel: [    0.329691] 4 fixed-partitions partitions found on MTD device spi0.0
Sun Sep 30 17:52:32 2018 kern.notice kernel: [    0.336144] Creating 4 MTD partitions on "spi0.0":
Sun Sep 30 17:52:32 2018 kern.notice kernel: [    0.341011] 0x000000000000-0x000000020000 : "boot"
Sun Sep 30 17:52:32 2018 kern.notice kernel: [    0.346803] 0x000000020000-0x0000007c0000 : "firmware"
Sun Sep 30 17:52:32 2018 kern.notice kernel: [    0.402027] 2 tplink-fw partitions found on MTD device firmware
Sun Sep 30 17:52:32 2018 kern.notice kernel: [    0.408071] 0x000000020000-0x000000163af9 : "kernel"
Sun Sep 30 17:52:32 2018 kern.notice kernel: [    0.414023] 0x000000163afc-0x0000007c0000 : "rootfs"
Sun Sep 30 17:52:32 2018 kern.notice kernel: [    0.419918] mtd: device 3 (rootfs) set to be root filesystem
Sun Sep 30 17:52:32 2018 kern.notice kernel: [    0.427000] 1 squashfs-split partitions found on MTD device rootfs
Sun Sep 30 17:52:32 2018 kern.notice kernel: [    0.433289] 0x0000005a0000-0x0000007c0000 : "rootfs_data"
Sun Sep 30 17:52:32 2018 kern.notice kernel: [    0.439742] 0x0000007c0000-0x0000007d0000 : "config"
Sun Sep 30 17:52:32 2018 kern.notice kernel: [    0.445610] 0x0000007d0000-0x000000800000 : "factory"
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.452358] libphy: Fixed MDIO Bus: probed
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.468122] rt3050-esw 10110000.esw: link changed 0x00
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.474893] mtk_soc_eth 10100000.ethernet eth0: mediatek frame engine at 0xb0100000, irq 5
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.485140] NET: Registered protocol family 10
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.493530] Segment Routing with IPv6
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.497440] NET: Registered protocol family 17
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.502004] 8021q: 802.1Q VLAN Support v1.8
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.520241] VFS: Mounted root (squashfs filesystem) readonly on device 31:3.
Sun Sep 30 17:52:32 2018 kern.info kernel: [    0.528580] Freeing unused kernel memory: 208K
Sun Sep 30 17:52:32 2018 kern.warn kernel: [    0.533084] This architecture does not have kernel memory protection.
Sun Sep 30 17:52:32 2018 user.info kernel: [    2.195051] init: Console is alive
Sun Sep 30 17:52:32 2018 user.info kernel: [    2.198821] init: - watchdog -
Sun Sep 30 17:52:32 2018 kern.notice kernel: [    2.365912] random: fast init done
Sun Sep 30 17:52:32 2018 user.info kernel: [    3.508017] kmodloader: loading kernel modules from /etc/modules-boot.d/*
Sun Sep 30 17:52:32 2018 user.info kernel: [    3.948830] kmodloader: done loading kernel modules from /etc/modules-boot.d/*
Sun Sep 30 17:52:32 2018 user.info kernel: [    3.966704] init: - preinit -
Sun Sep 30 17:52:32 2018 kern.info kernel: [    6.205173] rt3050-esw 10110000.esw: link changed 0x00
Sun Sep 30 17:52:32 2018 kern.notice kernel: [    6.638184] random: procd: uninitialized urandom read (4 bytes read)
Sun Sep 30 17:52:32 2018 kern.info kernel: [    9.185234] rt3050-esw 10110000.esw: link changed 0x02
Sun Sep 30 17:52:32 2018 kern.info kernel: [    9.726034] rt3050-esw 10110000.esw: link changed 0x03
Sun Sep 30 17:52:32 2018 kern.notice kernel: [    9.923591] jffs2: notice: (335) jffs2_build_xattr_subsystem: complete building xattr subsystem, 9 of xdatum (2 unchecked, 7 orphan) and 87 of xref (5 dead, 14 orphan) found.
Sun Sep 30 17:52:32 2018 user.info kernel: [    9.941408] mount_root: switching to jffs2 overlay
Sun Sep 30 17:52:32 2018 kern.warn kernel: [    9.985318] overlayfs: upper fs does not support tmpfile.
Sun Sep 30 17:52:32 2018 user.warn kernel: [   10.001776] urandom-seed: Seeding with /etc/urandom.seed
Sun Sep 30 17:52:32 2018 user.info kernel: [   10.214855] procd: - early -
Sun Sep 30 17:52:32 2018 user.info kernel: [   10.219222] procd: - watchdog -
Sun Sep 30 17:52:32 2018 user.info kernel: [   10.789802] procd: - watchdog -
Sun Sep 30 17:52:32 2018 user.info kernel: [   10.793292] procd: - ubus -
Sun Sep 30 17:52:32 2018 kern.notice kernel: [   11.206396] random: ubusd: uninitialized urandom read (4 bytes read)
Sun Sep 30 17:52:32 2018 kern.notice kernel: [   11.215596] random: ubusd: uninitialized urandom read (4 bytes read)
Sun Sep 30 17:52:32 2018 kern.notice kernel: [   11.222679] random: ubusd: uninitialized urandom read (4 bytes read)
Sun Sep 30 17:52:32 2018 user.info kernel: [   11.230332] procd: - init -
Sun Sep 30 17:52:32 2018 user.info kernel: [   11.909277] kmodloader: loading kernel modules from /etc/modules.d/*
Sun Sep 30 17:52:32 2018 kern.info kernel: [   11.929097] tun: Universal TUN/TAP device driver, 1.6
Sun Sep 30 17:52:32 2018 kern.info kernel: [   11.940259] ipip: IPv4 and MPLS over IPv4 tunneling driver
Sun Sep 30 17:52:32 2018 kern.info kernel: [   11.972031] ip6_tables: (C) 2000-2006 Netfilter Core Team
Sun Sep 30 17:52:32 2018 kern.info kernel: [   11.996080] Netfilter messages via NETLINK v0.30.
Sun Sep 30 17:52:32 2018 kern.info kernel: [   12.008093] ip_set: protocol 6
Sun Sep 30 17:52:32 2018 kern.info kernel: [   12.110369] Loading modules backported from Linux version wt-2017-11-01-0-gfe248fc2c180
Sun Sep 30 17:52:32 2018 kern.info kernel: [   12.118557] Backport generated by backports.git v4.14-rc2-1-31-g86cf0e5d
Sun Sep 30 17:52:32 2018 kern.info kernel: [   12.182276] batman_adv: B.A.T.M.A.N. advanced 2018.1 (compatibility version 15) loaded
Sun Sep 30 17:52:32 2018 kern.info kernel: [   12.227116] u32 classifier
Sun Sep 30 17:52:32 2018 kern.info kernel: [   12.229871]     input device check on
Sun Sep 30 17:52:32 2018 kern.info kernel: [   12.233579]     Actions configured
Sun Sep 30 17:52:32 2018 kern.info kernel: [   12.271332] Mirror/redirect action on
Sun Sep 30 17:52:32 2018 kern.info kernel: [   12.291556] nf_conntrack version 0.5.0 (1024 buckets, 4096 max)
Sun Sep 30 17:52:32 2018 kern.info kernel: [   12.321764] ip_tables: (C) 2000-2006 Netfilter Core Team
Sun Sep 30 17:52:32 2018 kern.info kernel: [   12.440173] mt76_wmac 10300000.wmac: ASIC revision: 76280001
Sun Sep 30 17:52:32 2018 kern.info kernel: [   12.491422] mt76_wmac 10300000.wmac: Firmware Version: 20151201
Sun Sep 30 17:52:32 2018 kern.info kernel: [   12.497527] mt76_wmac 10300000.wmac: Build Time: 20151201183641
Sun Sep 30 17:52:32 2018 kern.warn kernel: [   12.515900] firmware init done
Sun Sep 30 17:52:32 2018 kern.debug kernel: [   12.685688] ieee80211 phy0: Selected rate control algorithm 'minstrel_ht'
Sun Sep 30 17:52:32 2018 kern.info kernel: [   12.979334] xt_time: kernel timezone is -0000
Sun Sep 30 17:52:32 2018 user.info kernel: [   12.991826] kmodloader: done loading kernel modules from /etc/modules.d/*
Sun Sep 30 17:52:32 2018 kern.warn kernel: [   15.027596] urandom_read: 5 callbacks suppressed
Sun Sep 30 17:52:32 2018 kern.notice kernel: [   15.027605] random: jshn: uninitialized urandom read (4 bytes read)
Sun Sep 30 17:52:32 2018 user.notice policyrouting: Starting policy routing.
Sun Sep 30 17:52:32 2018 daemon.notice procd: /etc/rc.d/S15freifunk-policyrouting: policyrouting: Starting policy routing.
Sun Sep 30 17:52:34 2018 user.notice dnsmasq: DNS rebinding protection is active, will discard upstream RFC1918 responses!
Sun Sep 30 17:52:34 2018 user.notice dnsmasq: Allowing 127.0.0.0/8 responses
Sun Sep 30 17:52:35 2018 daemon.info dnsmasq[825]: started, version 2.80test3 cachesize 150
Sun Sep 30 17:52:35 2018 daemon.info dnsmasq[825]: DNS service limited to local subnets
Sun Sep 30 17:52:35 2018 daemon.info dnsmasq[825]: compile time options: IPv6 GNU-getopt no-DBus no-i18n no-IDN DHCP no-DHCPv6 no-Lua TFTP no-conntrack no-ipset no-auth no-DNSSEC no-ID loop-detect inotify dumpfile
Sun Sep 30 17:52:35 2018 daemon.info dnsmasq[825]: using local addresses only for domain test
Sun Sep 30 17:52:35 2018 daemon.info dnsmasq[825]: using local addresses only for domain onion
Sun Sep 30 17:52:35 2018 daemon.info dnsmasq[825]: using local addresses only for domain localhost
Sun Sep 30 17:52:35 2018 daemon.info dnsmasq[825]: using local addresses only for domain local
Sun Sep 30 17:52:35 2018 daemon.info dnsmasq[825]: using local addresses only for domain invalid
Sun Sep 30 17:52:35 2018 daemon.info dnsmasq[825]: using local addresses only for domain bind
Sun Sep 30 17:52:35 2018 daemon.info dnsmasq[825]: using local addresses only for domain lan
Sun Sep 30 17:52:35 2018 daemon.warn dnsmasq[825]: no servers found in /tmp/resolv.conf.auto, will retry
Sun Sep 30 17:52:35 2018 daemon.info dnsmasq[825]: read /etc/hosts - 4 addresses
Sun Sep 30 17:52:35 2018 daemon.info dnsmasq[825]: read /tmp/hosts/dhcp.cfg01411c - 2 addresses
Sun Sep 30 17:52:37 2018 kern.info kernel: [   20.828602] rt3050-esw 10110000.esw: link changed 0x00
Sun Sep 30 17:52:37 2018 user.notice : Added device handler type: tunnel
Sun Sep 30 17:52:37 2018 user.notice : Added device handler type: Network device
Sun Sep 30 17:52:37 2018 user.notice : Added device handler type: bridge
Sun Sep 30 17:52:37 2018 user.notice : Added device handler type: veth
Sun Sep 30 17:52:37 2018 user.notice : Added device handler type: macvlan
Sun Sep 30 17:52:37 2018 user.notice : Added device handler type: 8021ad
Sun Sep 30 17:52:37 2018 user.notice : Added device handler type: 8021q
Sun Sep 30 17:52:40 2018 kern.info kernel: [   23.805397] rt3050-esw 10110000.esw: link changed 0x02
Sun Sep 30 17:52:40 2018 authpriv.info dropbear[978]: Not backgrounding
Sun Sep 30 17:52:40 2018 kern.info kernel: [   24.362838] rt3050-esw 10110000.esw: link changed 0x03
Sun Sep 30 17:52:42 2018 daemon.info modprobe: Usage: 	modprobe [-q] filename
Sun Sep 30 17:52:42 2018 daemon.err modprobe: ifb is already loaded
Sun Sep 30 17:52:42 2018 daemon.err modprobe: cls_u32 is already loaded
Sun Sep 30 17:52:42 2018 daemon.err modprobe: em_u32 is already loaded
Sun Sep 30 17:52:42 2018 daemon.err modprobe: act_connmark is already loaded
Sun Sep 30 17:52:43 2018 daemon.err modprobe: act_mirred is already loaded
Sun Sep 30 17:52:43 2018 daemon.err modprobe: sch_ingress is already loaded
Sun Sep 30 17:52:43 2018 daemon.err modprobe: cls_fw is already loaded
Sun Sep 30 17:52:43 2018 daemon.err modprobe: sch_hfsc is already loaded
Sun Sep 30 17:52:43 2018 kern.info kernel: [   27.618035] br-dhcp: port 1(eth0.1) entered blocking state
Sun Sep 30 17:52:43 2018 kern.info kernel: [   27.623613] br-dhcp: port 1(eth0.1) entered disabled state
Sun Sep 30 17:52:43 2018 kern.info kernel: [   27.629803] device eth0.1 entered promiscuous mode
Sun Sep 30 17:52:43 2018 kern.info kernel: [   27.634673] device eth0 entered promiscuous mode
Sun Sep 30 17:52:43 2018 kern.info kernel: [   27.672663] br-dhcp: port 1(eth0.1) entered blocking state
Sun Sep 30 17:52:43 2018 kern.info kernel: [   27.678299] br-dhcp: port 1(eth0.1) entered forwarding state
Sun Sep 30 17:52:43 2018 kern.info kernel: [   27.684253] IPv6: ADDRCONF(NETDEV_UP): br-dhcp: link is not ready
Sun Sep 30 17:52:43 2018 daemon.notice netifd: Interface 'dhcp' is enabled
Sun Sep 30 17:52:43 2018 daemon.notice netifd: Interface 'dhcp' is setting up now
Sun Sep 30 17:52:43 2018 daemon.notice netifd: Interface 'dhcp' is now up
Sun Sep 30 17:52:43 2018 daemon.info dnsmasq[825]: reading /tmp/resolv.conf.auto
Sun Sep 30 17:52:43 2018 daemon.info dnsmasq[825]: using local addresses only for domain test
Sun Sep 30 17:52:43 2018 daemon.info dnsmasq[825]: using local addresses only for domain onion
Sun Sep 30 17:52:43 2018 daemon.info dnsmasq[825]: using local addresses only for domain localhost
Sun Sep 30 17:52:43 2018 daemon.info dnsmasq[825]: using local addresses only for domain local
Sun Sep 30 17:52:43 2018 daemon.info dnsmasq[825]: using local addresses only for domain invalid
Sun Sep 30 17:52:43 2018 daemon.info dnsmasq[825]: using local addresses only for domain bind
Sun Sep 30 17:52:43 2018 daemon.info dnsmasq[825]: using local addresses only for domain lan
Sun Sep 30 17:52:44 2018 daemon.info dnsmasq[825]: using nameserver 85.214.20.141#53
Sun Sep 30 17:52:44 2018 daemon.info dnsmasq[825]: using nameserver 194.150.168.168#53
Sun Sep 30 17:52:44 2018 daemon.info dnsmasq[825]: using nameserver 2001:4ce8::53#53
Sun Sep 30 17:52:44 2018 daemon.info dnsmasq[825]: using nameserver 2001:910:800::12#53
Sun Sep 30 17:52:44 2018 daemon.notice netifd: Interface 'wan6' is enabled
Sun Sep 30 17:52:44 2018 kern.info kernel: [   27.814941] br-wan: port 1(eth0.2) entered blocking state
Sun Sep 30 17:52:44 2018 kern.info kernel: [   27.820515] br-wan: port 1(eth0.2) entered disabled state
Sun Sep 30 17:52:44 2018 kern.info kernel: [   27.826396] device eth0.2 entered promiscuous mode
Sun Sep 30 17:52:44 2018 kern.info kernel: [   28.056071] br-wan: port 1(eth0.2) entered blocking state
Sun Sep 30 17:52:44 2018 kern.info kernel: [   28.061564] br-wan: port 1(eth0.2) entered forwarding state
Sun Sep 30 17:52:44 2018 daemon.notice netifd: Interface 'wan' is enabled
Sun Sep 30 17:52:44 2018 daemon.notice netifd: Interface 'loopback' is enabled
Sun Sep 30 17:52:44 2018 daemon.notice netifd: Interface 'loopback' is setting up now
Sun Sep 30 17:52:44 2018 daemon.notice netifd: Interface 'loopback' is now up
Sun Sep 30 17:52:44 2018 daemon.notice netifd: Interface 'tunl0' is enabled
Sun Sep 30 17:52:44 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:44 2018 daemon.notice netifd: bridge 'br-dhcp' link is up
Sun Sep 30 17:52:44 2018 daemon.notice netifd: Interface 'dhcp' has link connectivity
Sun Sep 30 17:52:44 2018 daemon.notice netifd: Network device 'eth0' link is up
Sun Sep 30 17:52:44 2018 daemon.notice netifd: VLAN 'eth0.1' link is up
Sun Sep 30 17:52:44 2018 daemon.notice netifd: bridge 'br-wan' link is up
Sun Sep 30 17:52:44 2018 daemon.notice netifd: Interface 'wan' has link connectivity
Sun Sep 30 17:52:44 2018 daemon.notice netifd: Interface 'wan' is setting up now
Sun Sep 30 17:52:44 2018 daemon.notice netifd: VLAN 'eth0.2' link is up
Sun Sep 30 17:52:44 2018 daemon.notice netifd: Interface 'wan6' has link connectivity
Sun Sep 30 17:52:44 2018 daemon.notice netifd: Interface 'wan6' is setting up now
Sun Sep 30 17:52:44 2018 daemon.notice netifd: Network device 'lo' link is up
Sun Sep 30 17:52:44 2018 daemon.notice netifd: Interface 'loopback' has link connectivity
Sun Sep 30 17:52:44 2018 daemon.notice netifd: Network device 'tunl0' link is up
Sun Sep 30 17:52:44 2018 daemon.notice netifd: Interface 'tunl0' has link connectivity
Sun Sep 30 17:52:44 2018 daemon.notice netifd: Interface 'tunl0' is setting up now
Sun Sep 30 17:52:44 2018 daemon.notice netifd: Interface 'tunl0' is now up
Sun Sep 30 17:52:44 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:44 2018 kern.info kernel: [   28.666213] IPv6: ADDRCONF(NETDEV_CHANGE): br-dhcp: link becomes ready
Sun Sep 30 17:52:45 2018 daemon.notice netifd: wan (1278): udhcpc: started, v1.28.3
Sun Sep 30 17:52:45 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:46 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:46 2018 daemon.err odhcp6c[1287]: Failed to send RS (Permission denied)
Sun Sep 30 17:52:46 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:46 2018 daemon.err odhcp6c[1287]: Failed to send DHCPV6 message to ff02::1:2 (Permission denied)
Sun Sep 30 17:52:46 2018 daemon.notice netifd: wan (1278): udhcpc: sending discover
Sun Sep 30 17:52:46 2018 daemon.notice netifd: wan (1278): udhcpc: performing DHCP renew
Sun Sep 30 17:52:46 2018 daemon.notice netifd: wan (1278): udhcpc: sending discover
Sun Sep 30 17:52:46 2018 daemon.notice netifd: wan (1278): udhcpc: sending select for 192.168.178.31
Sun Sep 30 17:52:46 2018 daemon.notice netifd: wan (1278): udhcpc: lease of 192.168.178.31 obtained, lease time 864000
Sun Sep 30 17:52:46 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:47 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:47 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:47 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:47 2018 daemon.err odhcp6c[1287]: Failed to send DHCPV6 message to ff02::1:2 (Permission denied)
Sun Sep 30 17:52:47 2018 daemon.notice netifd: Interface 'wan' is now up
Sun Sep 30 17:52:47 2018 daemon.info dnsmasq[825]: reading /tmp/resolv.conf.auto
Sun Sep 30 17:52:47 2018 daemon.info dnsmasq[825]: using local addresses only for domain test
Sun Sep 30 17:52:47 2018 daemon.info dnsmasq[825]: using local addresses only for domain onion
Sun Sep 30 17:52:47 2018 daemon.info dnsmasq[825]: using local addresses only for domain localhost
Sun Sep 30 17:52:47 2018 daemon.info dnsmasq[825]: using local addresses only for domain local
Sun Sep 30 17:52:47 2018 daemon.info dnsmasq[825]: using local addresses only for domain invalid
Sun Sep 30 17:52:47 2018 daemon.info dnsmasq[825]: using local addresses only for domain bind
Sun Sep 30 17:52:47 2018 daemon.info dnsmasq[825]: using local addresses only for domain lan
Sun Sep 30 17:52:47 2018 daemon.info dnsmasq[825]: using nameserver 85.214.20.141#53
Sun Sep 30 17:52:47 2018 daemon.info dnsmasq[825]: using nameserver 194.150.168.168#53
Sun Sep 30 17:52:47 2018 daemon.info dnsmasq[825]: using nameserver 2001:4ce8::53#53
Sun Sep 30 17:52:47 2018 daemon.info dnsmasq[825]: using nameserver 2001:910:800::12#53
Sun Sep 30 17:52:47 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:47 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:48 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:48 2018 daemon.warn odhcpd[913]: DHCPV6 SOLICIT IA_NA from 000100012037e79fc0143dcc2a0d on br-dhcp: ok fdd7:2a6c:57a0::840/128
Sun Sep 30 17:52:48 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:49 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:49 2018 daemon.info dnsmasq[825]: exiting on receipt of SIGTERM
Sun Sep 30 17:52:49 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:49 2018 daemon.warn odhcpd[913]: DHCPV6 REQUEST IA_NA from 000100012037e79fc0143dcc2a0d on br-dhcp: ok fdd7:2a6c:57a0::840/128
Sun Sep 30 17:52:49 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:49 2018 daemon.err odhcp6c[1287]: Failed to send DHCPV6 message to ff02::1:2 (Permission denied)
Sun Sep 30 17:52:50 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:50 2018 daemon.err odhcp6c[1287]: Failed to send RS (Permission denied)
Sun Sep 30 17:52:50 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:50 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:50 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:51 2018 daemon.err modprobe: xt_multiport is already loaded
Sun Sep 30 17:52:51 2018 daemon.err modprobe: xt_connmark is already loaded
Sun Sep 30 17:52:51 2018 daemon.err modprobe: xt_comment is already loaded
Sun Sep 30 17:52:51 2018 daemon.err hostapd: Configuration file: /var/run/hostapd-phy0.conf
Sun Sep 30 17:52:51 2018 kern.info kernel: [   35.023857] IPv6: ADDRCONF(NETDEV_UP): wlan0-dhcp-2: link is not ready
Sun Sep 30 17:52:51 2018 kern.info kernel: [   35.040511] br-dhcp: port 2(wlan0-dhcp-2) entered blocking state
Sun Sep 30 17:52:51 2018 kern.info kernel: [   35.046706] br-dhcp: port 2(wlan0-dhcp-2) entered disabled state
Sun Sep 30 17:52:51 2018 kern.info kernel: [   35.053275] device wlan0-dhcp-2 entered promiscuous mode
Sun Sep 30 17:52:51 2018 daemon.err modprobe: xt_length is already loaded
Sun Sep 30 17:52:51 2018 daemon.notice hostapd: wlan0-dhcp-2: interface state UNINITIALIZED->COUNTRY_UPDATE
Sun Sep 30 17:52:51 2018 daemon.err hostapd: Using interface wlan0-dhcp-2 with hwaddr 7e:8b:ca:de:3c:68 and ssid "berlin.freifunk.net"
Sun Sep 30 17:52:51 2018 kern.info kernel: [   35.107735] IPv6: ADDRCONF(NETDEV_CHANGE): wlan0-dhcp-2: link becomes ready
Sun Sep 30 17:52:51 2018 kern.info kernel: [   35.115023] br-dhcp: port 2(wlan0-dhcp-2) entered blocking state
Sun Sep 30 17:52:51 2018 kern.info kernel: [   35.121184] br-dhcp: port 2(wlan0-dhcp-2) entered forwarding state
Sun Sep 30 17:52:51 2018 daemon.notice hostapd: wlan0-dhcp-2: interface state COUNTRY_UPDATE->ENABLED
Sun Sep 30 17:52:51 2018 daemon.notice hostapd: wlan0-dhcp-2: AP-ENABLED
Sun Sep 30 17:52:51 2018 kern.info kernel: [   35.259977] IPv6: ADDRCONF(NETDEV_UP): wlan0-adhoc-2: link is not ready
Sun Sep 30 17:52:51 2018 daemon.notice netifd: radio0 (1225): Usage:	iw [options] dev <devname> ibss join <SSID> <freq in MHz> [NOHT|HT20|HT40+|HT40-|5MHz|10MHz|80MHz] [fixed-freq] [<fixed bssid>] [beacon-interval <TU>] [basic-rates <rate in Mbps,rate2,...>] [mcast-rate <rate in Mbps>] [key d:0:abcde]
Sun Sep 30 17:52:51 2018 daemon.notice netifd: radio0 (1225):
Sun Sep 30 17:52:51 2018 daemon.notice netifd: radio0 (1225): Join the IBSS cell with the given SSID, if it doesn't exist create
Sun Sep 30 17:52:51 2018 daemon.notice netifd: radio0 (1225): it on the given frequency. When fixed frequency is requested, don't
Sun Sep 30 17:52:51 2018 daemon.notice netifd: radio0 (1225): join/create a cell on a different frequency. When a fixed BSSID is
Sun Sep 30 17:52:51 2018 daemon.notice netifd: radio0 (1225): requested use that BSSID and do not adopt another cell's BSSID even
Sun Sep 30 17:52:51 2018 daemon.notice netifd: radio0 (1225): if it has higher TSF and the same SSID. If an IBSS is created, create
Sun Sep 30 17:52:51 2018 daemon.notice netifd: radio0 (1225): it with the specified basic-rates, multicast-rate and beacon-interval.
Sun Sep 30 17:52:51 2018 daemon.notice netifd: radio0 (1225):
Sun Sep 30 17:52:51 2018 daemon.notice netifd: radio0 (1225): Options:
Sun Sep 30 17:52:51 2018 daemon.notice netifd: radio0 (1225): 	--debug		enable netlink debugging
Sun Sep 30 17:52:51 2018 daemon.notice netifd: Interface 'wireless0' is enabled
Sun Sep 30 17:52:51 2018 daemon.notice netifd: Interface 'wireless0' is setting up now
Sun Sep 30 17:52:51 2018 daemon.notice netifd: Interface 'wireless0' is now up
Sun Sep 30 17:52:51 2018 daemon.notice netifd: Network device 'wlan0-dhcp-2' link is up
Sun Sep 30 17:52:54 2018 daemon.err odhcp6c[1287]: Failed to send RS (Permission denied)
Sun Sep 30 17:52:54 2018 daemon.info modprobe: Usage: 	modprobe [-q] filename
Sun Sep 30 17:52:54 2018 daemon.err modprobe: ifb is already loaded
Sun Sep 30 17:52:54 2018 daemon.err odhcp6c[1287]: Failed to send DHCPV6 message to ff02::1:2 (Permission denied)
Sun Sep 30 17:52:54 2018 daemon.err modprobe: cls_u32 is already loaded
Sun Sep 30 17:52:54 2018 daemon.err modprobe: em_u32 is already loaded
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: started, version 2.80test3 cachesize 150
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: DNS service limited to local subnets
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: compile time options: IPv6 GNU-getopt no-DBus no-i18n no-IDN DHCP no-DHCPv6 no-Lua TFTP no-conntrack no-ipset no-auth no-DNSSEC no-ID loop-detect inotify dumpfile
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq-dhcp[1793]: DHCP, IP range 10.36.219.130 -- 10.36.219.142, lease time 5m
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: using local addresses only for domain test
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: using local addresses only for domain onion
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: using local addresses only for domain localhost
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: using local addresses only for domain local
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: using local addresses only for domain invalid
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: using local addresses only for domain bind
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: using local addresses only for domain lan
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: reading /tmp/resolv.conf.auto
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: using local addresses only for domain test
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: using local addresses only for domain onion
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: using local addresses only for domain localhost
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: using local addresses only for domain local
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: using local addresses only for domain invalid
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: using local addresses only for domain bind
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: using local addresses only for domain lan
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: using nameserver 85.214.20.141#53
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: using nameserver 194.150.168.168#53
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: using nameserver 2001:4ce8::53#53
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: using nameserver 2001:910:800::12#53
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: read /etc/hosts - 4 addresses
Sun Sep 30 17:52:54 2018 daemon.err modprobe: act_connmark is already loaded
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: read /tmp/hosts/dhcp.cfg01411c - 4 addresses
Sun Sep 30 17:52:54 2018 daemon.err dnsmasq[1793]: bad name at /tmp/hosts/odhcpd line 1
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq[1793]: read /tmp/hosts/odhcpd - 1 addresses
Sun Sep 30 17:52:54 2018 daemon.info dnsmasq-dhcp[1793]: read /etc/ethers - 0 addresses
Sun Sep 30 17:52:54 2018 daemon.err modprobe: act_mirred is already loaded
Sun Sep 30 17:52:54 2018 daemon.err modprobe: sch_ingress is already loaded
Sun Sep 30 17:52:54 2018 daemon.err modprobe: cls_fw is already loaded
Sun Sep 30 17:52:55 2018 daemon.err modprobe: sch_hfsc is already loaded
Sun Sep 30 17:52:55 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:55 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:55 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:55 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:55 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:55 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:55 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:55 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:55 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:56 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:56 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:56 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:56 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:56 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:56 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:56 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:56 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:56 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:56 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:57 2018 daemon.notice procd: /etc/rc.d/S50qos: Cannot find device "ffuplink"
Sun Sep 30 17:52:57 2018 daemon.err modprobe: xt_multiport is already loaded
Sun Sep 30 17:52:57 2018 daemon.err modprobe: xt_connmark is already loaded
Sun Sep 30 17:52:57 2018 daemon.err modprobe: xt_comment is already loaded
Sun Sep 30 17:52:57 2018 daemon.err modprobe: xt_length is already loaded
Sun Sep 30 17:52:58 2018 daemon.err odhcp6c[1287]: Failed to send RS (Permission denied)
Sun Sep 30 17:53:00 2018 user.notice firewall: Reloading firewall due to ifup of dhcp (br-dhcp)
Sun Sep 30 17:53:01 2018 user.notice policyrouting: Add route: ip route add 10.36.219.128/28 dev br-dhcp table localnets
Sun Sep 30 17:53:01 2018 user.notice policyrouting: Add route: ip route add 10.36.219.128/28 dev br-dhcp table olsr
Sun Sep 30 17:53:01 2018 user.notice policyrouting: Use mesh gateway for interface br-dhcp (IPv4)
Sun Sep 30 17:53:01 2018 daemon.info olsrd_hotplug: [OK] ifup: 'dhcp' => 'br-dhcp'
Sun Sep 30 17:53:01 2018 daemon.debug olsrd_hotplug: [OK] interface 'dhcp' => 'br-dhcp' not used for olsrd
Sun Sep 30 17:53:03 2018 daemon.err odhcp6c[1287]: Failed to send DHCPV6 message to ff02::1:2 (Permission denied)
Sun Sep 30 17:53:03 2018 daemon.info olsrd[2196]: Writing '1' (was 1) to /proc/sys/net/ipv4/ip_forward
Sun Sep 30 17:53:03 2018 daemon.info olsrd[2196]: Writing '0' (was 0) to /proc/sys/net/ipv4/conf/tunl0/rp_filter
Sun Sep 30 17:53:03 2018 daemon.info olsrd[2196]: Writing '0' (was 1) to /proc/sys/net/ipv4/conf/all/send_redirects
Sun Sep 30 17:53:03 2018 daemon.info olsrd[2196]: Writing '0' (was 0) to /proc/sys/net/ipv4/conf/all/rp_filter
Sun Sep 30 17:53:03 2018 daemon.info olsrd: /etc/rc.d/S65olsrd: olsrd_setup_smartgw_rules() Notice: Inserting firewall rules for SmartGateway
Sun Sep 30 17:53:03 2018 daemon.notice procd: /etc/rc.d/S65olsrd: olsrd: /etc/rc.d/S65olsrd: olsrd_setup_smartgw_rules() Notice: Inserting firewall rules for SmartGateway
Sun Sep 30 17:53:04 2018 daemon.info olsrd_hotplug: [OK] ifup: 'loopback' => 'lo'
Sun Sep 30 17:53:04 2018 daemon.debug olsrd_hotplug: [OK] interface 'loopback' => 'lo' not used for olsrd
Sun Sep 30 17:53:05 2018 daemon.info dnsmasq-dhcp[1793]: DHCPNAK(br-dhcp) 192.168.178.48 b8:88:e3:8b:55:c7 wrong network
Sun Sep 30 17:53:06 2018 daemon.info olsrd[2337]: Writing '1' (was 1) to /proc/sys/net/ipv6/conf/all/forwarding
Sun Sep 30 17:53:07 2018 user.notice firewall: Reloading firewall due to ifup of tunl0 (tunl0)
Sun Sep 30 17:53:08 2018 daemon.info olsrd_hotplug: [OK] ifup: 'tunl0' => 'tunl0'
Sun Sep 30 17:53:08 2018 daemon.debug olsrd_hotplug: [OK] interface 'tunl0' => 'tunl0' not used for olsrd
Sun Sep 30 17:53:08 2018 daemon.info olsrd_hotplug: [OK] ifup: 'tunl0' => 'tunl0'
Sun Sep 30 17:53:08 2018 daemon.debug olsrd_hotplug: [OK] interface 'tunl0' => 'tunl0' not used for olsrd6
Sun Sep 30 17:53:09 2018 daemon.info olsrd[2196]: olsr.org - 0.9.6.2-git_5f23d0f-hash_55241f02599264972d0bf4290dffae8d successfully started
Sun Sep 30 17:53:11 2018 daemon.info olsrd[2337]: olsr.org - 0.9.6.2-git_5f23d0f-hash_55241f02599264972d0bf4290dffae8d successfully started
Sun Sep 30 17:53:12 2018 user.notice firewall: Reloading firewall due to ifup of wan (br-wan)
Sun Sep 30 17:53:13 2018 daemon.info olsrd_hotplug: [OK] ifup: 'wan' => 'br-wan'
Sun Sep 30 17:53:13 2018 daemon.debug olsrd_hotplug: [OK] interface 'wan' => 'br-wan' not used for olsrd
Sun Sep 30 17:53:13 2018 daemon.info olsrd_hotplug: [OK] ifup: 'wan' => 'br-wan'
Sun Sep 30 17:53:13 2018 daemon.debug olsrd_hotplug: [OK] interface 'wan' => 'br-wan' not used for olsrd6
Sun Sep 30 17:53:13 2018 user.notice ucitrack: Setting up /etc/config/network reload dependency on /etc/config/dhcp
Sun Sep 30 17:53:13 2018 user.notice ff-userlog: WAN interface is up
Sun Sep 30 17:53:13 2018 user.notice ff-vpn-hotplug: Starting OpenVPN on WAN interface
Sun Sep 30 17:53:13 2018 user.notice ucitrack: Setting up /etc/config/network reload dependency on /etc/config/radvd
Sun Sep 30 17:53:14 2018 user.notice ucitrack: Setting up /etc/config/wireless reload dependency on /etc/config/network
Sun Sep 30 17:53:14 2018 user.notice ucitrack: Setting up /etc/config/firewall reload dependency on /etc/config/luci-splash
Sun Sep 30 17:53:14 2018 user.notice ucitrack: Setting up /etc/config/firewall reload dependency on /etc/config/qos
Sun Sep 30 17:53:14 2018 user.notice ucitrack: Setting up /etc/config/firewall reload dependency on /etc/config/miniupnpd
Sun Sep 30 17:53:14 2018 user.notice ucitrack: Setting up /etc/config/olsr reload trigger for non-procd /etc/init.d/olsrd
Sun Sep 30 17:53:15 2018 user.notice ucitrack: Setting up /etc/config/dhcp reload dependency on /etc/config/odhcpd
Sun Sep 30 17:53:16 2018 user.notice ucitrack: Setting up non-init /etc/config/fstab reload handler: /sbin/block mount
Sun Sep 30 17:53:16 2018 daemon.notice openvpn(ffuplink)[2638]: OpenVPN 2.4.5 mipsel-openwrt-linux-gnu [SSL (mbed TLS)] [LZO] [EPOLL] [AEAD]
Sun Sep 30 17:53:16 2018 daemon.notice openvpn(ffuplink)[2638]: library versions: mbed TLS 2.8.0, LZO 2.10
Sun Sep 30 17:53:16 2018 daemon.warn openvpn(ffuplink)[2638]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sun Sep 30 17:53:16 2018 daemon.warn openvpn(ffuplink)[2638]: WARNING: failed to personalise random
Sun Sep 30 17:53:16 2018 daemon.warn openvpn(ffuplink)[2638]: ******* WARNING *******: '--cipher none' was specified. This means NO encryption will be performed and tunnelled data WILL be transmitted in clear text over the network! PLEASE DO RECONSIDER THIS SETTING!
Sun Sep 30 17:53:16 2018 daemon.notice openvpn(ffuplink)[2638]: TCP/UDP: Preserving recently used remote address: [AF_INET]217.197.83.193:1194
Sun Sep 30 17:53:16 2018 daemon.notice openvpn(ffuplink)[2638]: UDPv4 link local (bound): [AF_INET]192.168.178.31:1194
Sun Sep 30 17:53:16 2018 daemon.notice openvpn(ffuplink)[2638]: UDPv4 link remote: [AF_INET]217.197.83.193:1194
Sun Sep 30 17:53:16 2018 user.notice ucitrack: Setting up /etc/config/system reload trigger for non-procd /etc/init.d/led
Sun Sep 30 17:53:17 2018 user.notice ucitrack: Setting up /etc/config/system reload dependency on /etc/config/luci_statistics
Sun Sep 30 17:53:17 2018 user.notice ucitrack: Setting up /etc/config/system reload dependency on /etc/config/dhcp
Sun Sep 30 17:53:17 2018 user.notice ucitrack: Setting up /etc/config/olsrd reload trigger for non-procd /etc/init.d/olsrd
Sun Sep 30 17:53:17 2018 user.notice ucitrack: Setting up /etc/config/olsrd6 reload trigger for non-procd /etc/init.d/olsrd6
Sun Sep 30 17:53:19 2018 user.notice ucitrack: Setting up /etc/config/freifunk-policyrouting reload trigger for non-procd /etc/init.d/freifunk-policyrouting
Sun Sep 30 17:53:19 2018 user.notice firewall: Reloading firewall due to ifup of wireless0 (wlan0-adhoc-2)
Sun Sep 30 17:53:20 2018 user.notice policyrouting: Add route: ip route add 10.31.40.144/32 dev wlan0-adhoc-2 table localnets
Sun Sep 30 17:53:20 2018 user.notice policyrouting: Add route: ip route add 10.31.40.144/32 dev wlan0-adhoc-2 table olsr
Sun Sep 30 17:53:20 2018 daemon.err odhcp6c[1287]: Failed to send DHCPV6 message to ff02::1:2 (Permission denied)
Sun Sep 30 17:53:20 2018 user.notice policyrouting: Use mesh gateway for interface wlan0-adhoc-2 (IPv4)
Sun Sep 30 17:53:21 2018 daemon.debug olsrd_hotplug: [OK] already_active: 'wireless0' => 'wlan0-adhoc-2'
Sun Sep 30 17:53:21 2018 daemon.debug olsrd_hotplug: [OK] already_active: 'wireless0' => 'wlan0-adhoc-2'
Sun Sep 30 17:53:21 2018 daemon.warn openvpn(ffuplink)[2638]: WARNING: 'link-mtu' is used inconsistently, local='link-mtu 1525', remote='link-mtu 1526'
Sun Sep 30 17:53:21 2018 daemon.warn openvpn(ffuplink)[2638]: WARNING: 'comp-lzo' is present in remote config but missing in local config, remote='comp-lzo'
Sun Sep 30 17:53:21 2018 daemon.notice openvpn(ffuplink)[2638]: [freifunk-gw01.in-berlin.de] Peer Connection Initiated with [AF_INET]217.197.83.193:1194
Sun Sep 30 17:53:21 2018 user.notice vpnbypass [2865]: service monitoring interfaces: wan tunl0 ✓
Sun Sep 30 17:53:21 2018 daemon.notice procd: /etc/rc.d/S96led: setting up led wlan2g
Sun Sep 30 17:53:21 2018 daemon.notice procd: /etc/rc.d/S96led: setting up led lan1
Sun Sep 30 17:53:21 2018 daemon.notice procd: /etc/rc.d/S96led: setting up led lan2
Sun Sep 30 17:53:21 2018 daemon.notice procd: /etc/rc.d/S96led: setting up led lan3
Sun Sep 30 17:53:21 2018 daemon.notice procd: /etc/rc.d/S96led: setting up led lan4
Sun Sep 30 17:53:21 2018 daemon.notice procd: /etc/rc.d/S96led: setting up led wan
Sun Sep 30 17:53:22 2018 daemon.notice netifd: Interface 'ffuplink' is enabled
Sun Sep 30 17:53:22 2018 daemon.notice netifd: Network device 'ffuplink' link is up
Sun Sep 30 17:53:22 2018 daemon.notice netifd: Interface 'ffuplink' has link connectivity
Sun Sep 30 17:53:22 2018 daemon.notice netifd: Interface 'ffuplink' is setting up now
Sun Sep 30 17:53:22 2018 daemon.notice openvpn(ffuplink)[2638]: TUN/TAP device ffuplink opened
Sun Sep 30 17:53:22 2018 daemon.notice netifd: Interface 'ffuplink' is now up
Sun Sep 30 17:53:22 2018 daemon.notice openvpn(ffuplink)[2638]: do_ifconfig, tt->did_ifconfig_ipv6_setup=0
Sun Sep 30 17:53:22 2018 daemon.notice openvpn(ffuplink)[2638]: /sbin/ifconfig ffuplink 172.31.241.61 netmask 255.255.255.0 mtu 1500 broadcast 172.31.241.255
Sun Sep 30 17:53:22 2018 daemon.notice openvpn(ffuplink)[2638]: /lib/freifunk/ffvpn-up.sh ffuplink 1500 1552 172.31.241.61 255.255.255.0 init
Sun Sep 30 17:53:22 2018 user.debug up-down-ffvpn: no route_net_gateway env var from openvpn!
Sun Sep 30 17:53:23 2018 daemon.warn openvpn(ffuplink)[2638]: WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Sun Sep 30 17:53:23 2018 daemon.notice openvpn(ffuplink)[2638]: Initialization Sequence Completed
Sun Sep 30 17:53:45 2018 user.notice up-down-ffvpn: ugw: 192.168.178.1 dev: ffuplink remote: 255.255.255.0 gw: 172.31.241.1 src: 172.31.241.61 mask: 255.255.255.0
Sun Sep 30 17:53:47 2018 daemon.info modprobe: Usage: 	modprobe [-q] filename
Sun Sep 30 17:53:47 2018 daemon.err modprobe: ifb is already loaded
Sun Sep 30 17:53:47 2018 daemon.err modprobe: cls_u32 is already loaded
Sun Sep 30 17:53:47 2018 daemon.err modprobe: em_u32 is already loaded
Sun Sep 30 17:53:47 2018 daemon.info procd: - init complete -
Sun Sep 30 17:53:47 2018 daemon.notice vnstatd[3241]: vnStat daemon 1.18 started. (pid:3241 uid:0 gid:0)
Sun Sep 30 17:53:47 2018 daemon.notice vnstatd[3241]: Monitoring: eth0.2 (1000 Mbit)
Sun Sep 30 17:53:47 2018 daemon.err modprobe: act_connmark is already loaded
Sun Sep 30 17:53:47 2018 daemon.err modprobe: act_mirred is already loaded
Sun Sep 30 17:53:47 2018 daemon.err modprobe: sch_ingress is already loaded
Sun Sep 30 17:53:47 2018 daemon.err modprobe: cls_fw is already loaded
Sun Sep 30 17:53:47 2018 daemon.err modprobe: sch_hfsc is already loaded
Sun Sep 30 17:53:48 2018 user.notice firewall: Reloading firewall due to ifup of ffuplink (ffuplink)
Sun Sep 30 17:53:48 2018 daemon.info olsrd_hotplug: [OK] ifup: 'ffuplink' => 'ffuplink'
Sun Sep 30 17:53:48 2018 daemon.debug olsrd_hotplug: [OK] interface 'ffuplink' => 'ffuplink' not used for olsrd
Sun Sep 30 17:53:48 2018 daemon.info olsrd_hotplug: [OK] ifup: 'ffuplink' => 'ffuplink'
Sun Sep 30 17:53:48 2018 daemon.debug olsrd_hotplug: [OK] interface 'ffuplink' => 'ffuplink' not used for olsrd6
Sun Sep 30 17:53:48 2018 user.notice ff-userlog: OpenVPN connection has been established
Sun Sep 30 17:53:48 2018 user.notice ff-userlog: ffuplink interface is up
Sun Sep 30 17:53:48 2018 user.notice ff-userlog: creating ffuplink ip-rules
Sun Sep 30 17:53:48 2018 user.notice ff-userlog: UCI did not return a valid IP-net for ffuplink; querying directly with ip-tool
Sun Sep 30 17:53:48 2018 user.notice ff-userlog: ffuplink-interface is setup
Sun Sep 30 17:53:52 2018 kern.notice kernel: [   75.443727] random: crng init done
Sun Sep 30 17:53:53 2018 daemon.err openvpn(ffuplink)[2638]: write to TUN/TAP : Invalid argument (code=22)
Sun Sep 30 17:54:03 2018 daemon.err openvpn(ffuplink)[2638]: write to TUN/TAP : Invalid argument (code=22)
Sun Sep 30 17:54:13 2018 daemon.err openvpn(ffuplink)[2638]: write to TUN/TAP : Invalid argument (code=22)
Sun Sep 30 17:54:14 2018 daemon.err odhcp6c[1287]: Failed to send DHCPV6 message to ff02::1:2 (Permission denied)
Sun Sep 30 17:54:23 2018 daemon.err openvpn(ffuplink)[2638]: write to TUN/TAP : Invalid argument (code=22)
Sun Sep 30 17:54:34 2018 daemon.err openvpn(ffuplink)[2638]: write to TUN/TAP : Invalid argument (code=22)
Sun Sep 30 17:54:44 2018 daemon.err openvpn(ffuplink)[2638]: write to TUN/TAP : Invalid argument (code=22)
Sun Sep 30 17:54:54 2018 daemon.err openvpn(ffuplink)[2638]: write to TUN/TAP : Invalid argument (code=22)
Sun Sep 30 17:55:00 2018 daemon.info dnsmasq[1793]: read /etc/hosts - 4 addresses
Sun Sep 30 17:55:00 2018 daemon.info dnsmasq[1793]: read /tmp/hosts/dhcp.cfg01411c - 4 addresses
Sun Sep 30 17:55:00 2018 daemon.err dnsmasq[1793]: bad name at /tmp/hosts/odhcpd line 1
Sun Sep 30 17:55:00 2018 daemon.info dnsmasq[1793]: read /tmp/hosts/odhcpd - 1 addresses
Sun Sep 30 17:55:00 2018 daemon.info dnsmasq-dhcp[1793]: read /etc/ethers - 0 addresses
Sun Sep 30 17:55:04 2018 daemon.err openvpn(ffuplink)[2638]: write to TUN/TAP : Invalid argument (code=22)
Sun Sep 30 17:55:15 2018 daemon.err openvpn(ffuplink)[2638]: write to TUN/TAP : Invalid argument (code=22)
Sun Sep 30 17:55:23 2018 daemon.err odhcp6c[1287]: Failed to send DHCPV6 message to ff02::1:2 (Permission denied)
Sun Sep 30 17:55:24 2018 daemon.err openvpn(ffuplink)[2638]: write to TUN/TAP : Invalid argument (code=22)
Sun Sep 30 17:55:35 2018 daemon.err openvpn(ffuplink)[2638]: write to TUN/TAP : Invalid argument (code=22)
Sun Sep 30 17:55:40 2018 daemon.warn odhcpd[913]: DHCPV6 RENEW IA_NA from 000100012037e79fc0143dcc2a0d on br-dhcp: ok fdd7:2a6c:57a0::840/128
Sun Sep 30 17:56:13 2018 daemon.err uhttpd[2035]: luci: accepted login on /admin for root from fdd7:2a6c:57a0::29f5:25bc:484a:29c3```



some ideas?

@pmelange
Copy link
Contributor Author

pmelange commented Sep 30, 2018

add option compress lzo to /etc/config/openvpn

@pmelange
Copy link
Contributor Author

A new commit has been added to openwrt-18-06
openwrt/openwrt@d5afaa4
This may solve this issue

@pmelange
Copy link
Contributor Author

Even the description here has changed...
https://community.openvpn.net/openvpn/wiki/DeprecatedOptions#a--comp-lzo

Contrary to prior statements --comp-lzo no is not compatible with the --compress counterpart. Therefore openvpn needs to keep supporting --comp-lzo no for backward compatibility.

pmelange referenced this issue in openwrt/openwrt Dec 12, 2018
This option is deprecated but needs to be kept for backward compatibility. [0]

[0] https://community.openvpn.net/openvpn/wiki/DeprecatedOptions#a--comp-lzo

Signed-off-by: Martin Schiller <ms@dev.tdt.de>
Signed-off-by: Hans Dedecker <dedeckeh@gmail.com> [PKG_RELEASE increase]

(cherry picked from commit 3850b41)
@SvenRoederer
Copy link
Contributor

@pmelange
Copy link
Contributor Author

The lates commit to 2.4.5 is "Latest commit 27a2e01 on Feb 28". Since 18.06 is still using 2.4.5 then we might be in luck.

@pmelange
Copy link
Contributor Author

pmelange commented Dec 13, 2018

My recommendation is the following:

  • set up an openvpn service with the new compression option on another port number
  • as of Hedy 1.1.x we change the openvpn options via mirgration script to the new port and config

We can also set up the community-tunnel openvpn service like this on all the remaining vpn03 servers.

@SvenRoederer
Copy link
Contributor

this I had done on the in-berlin gateway once

@pmelange
Copy link
Contributor Author

I have built locally and tested this issue with commit openwrt/openwrt@d5afaa4 integrated. Now OpenVpn 2.4.5 works.

Shall we close this issue? If we want to create a new setup on the server side and client side for 1.1.x or possibly 1.2.x, then I think it should go in a new issue.

@SvenRoederer
Copy link
Contributor

let's close this here. changes to the tunnel-setup should go into the tunnel-repo or better on the mailinglist

SvenRoederer added a commit that referenced this issue Jun 18, 2020
2b6a4e1 olsrd: bump to latest version
c78adaf Merge pull request #580 from PolynomialDivision/fix/olsrd
SvenRoederer added a commit to SvenRoederer/freifunk-berlin-firmware that referenced this issue Jun 22, 2020
2b6a4e1 olsrd: bump to latest version
c78adaf Merge pull request freifunk-berlin#580 from PolynomialDivision/fix/olsrd
SvenRoederer added a commit to SvenRoederer/freifunk-berlin-firmware that referenced this issue Jun 22, 2020
2b6a4e1 olsrd: bump to latest version
c78adaf Merge pull request freifunk-berlin#580 from PolynomialDivision/fix/olsrd
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

6 participants