Alex - as has been mentioned before it's risky as Xiaomi could patch to prevent downgrade (and then users would be stuck with having to wire up to the serial port). I think with the amount of product out there currently - we are likely safe for now. I've also seen some other research going on around decoding the Xiaomi FW update bin's which could lead being able to craft a Xiaomi compliant update bin.
From an exploit perspective - I think the next step would be to figure out how to modify the uboot config in order to enable RW access to all the partitions. At that point you would have similar access as to what efsg has with his serial port access. It seems to me like you could potentially do a sysupgrade to patch the currently writable partitions to get OpenWRT on there (the ax3600 does a custom process pulling various images out of the uploaded bin and then deploying directly to partitions). However, that would still require all the drivers to be in place and from my reading would only put you in a one off hack jobbed OpenWRT.
A big thank you to the people posting great information in this thread and the ax3600 DTS thread. I've ordered one and with the info posted here should get root access.
esfg - are you leverage the work done on the 8074 reference kit? I stumbled across this pastebin showing the bootlog of an IPQ8074-HK01: https://pastebin.com/j43AhxAh
But I can't seem to dig up the snapshot that is listed in the release further down in the pastebin:
That doesnt exactly map. It looks like the primary GitHub repo only added basic support for IPQ807x 4 months ago but this pastebin was pasted back in Dec and seems to indicate a full build. I suppose then that means there is a private SDK from Qualcomm floating around for OpenWRT?
it would be great to know how, for those of us that already got the device, can we help the devs.
mine should be here in couple of weeks(hopefully) and I don't plan to integrate it in my network till I can install openwrt on it. so I'm open for any test
The OpenWrt Makefiles for ipq807x does build the kernel, device tree and rootfs.
The image.mk creates the images like FIT-Image with DTB and OpenWrt rootfs as initramfs and also the squashfs image.
So the device setup script for networking and there like and probably some patches for kernel/dts customization are missing.
But IĀ“m very sure that this posted bootlog is from a official OpenWrt build.
Hey Everyone!
I'm very very interested in this one since I have a WRT3200ACM and it is the most annoying device ever (with it's buggy wireless drivers) and I'm thinking of replacing it with the AX3600 but there are some doubts I need to clarify before making that decision.
If someone with this router could confirm this for me it would be great, I have seen in a website (this one: http://www.bitswrt.com/11AX.html) that the 5ghz wireless can do 4x4 in 80mhz but when 160mhz is selected it drops to 2x2, is it true? could you test this for me?
I believe that the QSDK opensource wireless drivers you mention (at least for now) don't support the IPQ8071A, only the IPQ8074 SoC
I have found that the TP-Link Deco X60 is a device with very similar hardware, and TP-Link released the GPL source which can be useful to add openwrt support to AX3600