LuCI Attended Sysupgrade support thread

No, ASU does not disable anything, it merely assembles images from the images and packages it finds on downloads.openwrt.org.

The WR9500N has been a tiny device since it was added two years ago, https://github.com/openwrt/openwrt/commit/bafd1aa18349e0c67dae1ca0c66fccb5c23e32db, and combined with below, has never had ed25519 support.

But I still don't understand the rationale behind this choice.

If the goal is to save space on SMALL_FLASH devices, why was Ed25519 disabled instead of RSA?

According to Config.in (see lines L59 old-version and L916/L926 new-version), disabling Ed25519 saves only about 12 kB. However, Ed25519 is generally considered a modern and preferred SSH public key algorithm, while RSA is much larger and older.

Was RSA kept enabled mainly for compatibility reasons with existing devices and users? Or was there another technical reason for keeping RSA and disabling Ed25519?

Unless there are other technical reasons I am not aware of, I would still be interested in understanding the rationale behind choosing Ed25519 as the algorithm to disable on SMALL_FLASH devices. (and that's why I deleted the original message I thought there was something I missed ...)

I find this choice a bit surprising.

old_revision:

Good reasons to change, you should create an issue on the main repo. (Good luck getting RSA deprecated though, there are probably about a billion users on OpenWrt alone... :slightly_smiling_face:)

2 Likes

Thanks for the clarification. I understand the compatibility concern with RSA, especially considering the huge number of existing OpenWrt installations.

My point was mostly about the current balance: Ed25519 is now widely supported and only costs around 12 kB, so I was curious about the reasoning behind the original choice.

I don't have a real issue with my device or a practical problem to solve, so I don't think opening an issue would be appropriate in my case. I was mainly interested in understanding the design decision, and I completely understand the constraints and the reasoning behind the original choice.

It's always nice to discuss with you, thanks :grinning_face:

2 Likes

Thank you for your reply.
Where should I raise the ed25519 request?

That would be on the main repo's issues list: https://github.com/openwrt/openwrt/issues

You should probably cite that commit that @ncompact found: https://github.com/openwrt/openwrt/commit/d0f295837a03f7f52000ae6d395827bdde7996a4

The concept of "small flash" has been creeping upward over the years, so it may be the case that 12KB is no longer considered an issue. For background reading on why size matters, see
https://openwrt.org/supported_devices/864_warning
https://openwrt.org/supported_devices/openwrt_on_432_devices
https://openwrt.org/supported_devices/openwrt_on_864_devices

1 Like

When checking with owut check --verbose on my Netgear Wax206 (AP) everything seems fine but when trying to upgrade using Attended sysupgrade 25.12.4 -> 25.12.5 this happens :

Server response: Error: Impossible package selection

Request Data
{
    "system_board": {
        "kernel": "6.12.87",
        "hostname": "OpenWrt-Wax206",
        "system": "ARMv8 Processor rev 4",
        "model": "Netgear WAX206",
        "board_name": "netgear,wax206",
        "rootfs_type": "squashfs",
        "release": {
            "distribution": "OpenWrt",
            "version": "25.12.4",
            "firmware_url": "https://downloads.openwrt.org/",
            "revision": "r32933-4ccb782af7",
            "target": "mediatek/mt7622",
            "description": "OpenWrt 25.12.4 r32933-4ccb782af7",
            "builddate": "1778712129"
        }
    },
    "advanced_mode": "1",
    "url": "https://sysupgrade.openwrt.org",
    "branch": "25.12",
    "revision": "r32933-4ccb782af7",
    "efi": false,
    "request_hash": "d57d9f6f4be5f7f6f287e95b62032009fcdae51caeb27d46c24f63b2e870583c",
    "sha256_unsigned": "",
    "client": "luci/26.158.67103~e99e132",
    "packages": {
        "apk-mbedtls": "3.0.5-r3",
        "attendedsysupgrade-common": "10",
        "base-files": "1707~4ccb782af7",
        "ca-bundle": "20260223-r1",
        "dnsmasq": "2.91-r3",
        "dropbear": "2025.89-r1",
        "firewall4": "2025.03.17~b6e51575-r2",
        "fitblk": "2",
        "hostapd-common": "2025.08.26~ca266cc2-r1",
        "kernel": "6.12.87~af105e8ec257f0b61fed2bdaab2460ae-r1",
        "kmod-gpio-button-hotplug": "6.12.87-r5",
        "kmod-leds-gpio": "6.12.87-r1",
        "kmod-mt7622-firmware": "6.12.87.2026.03.19~39c960c3-r2",
        "kmod-mt7915-firmware": "6.12.87.2026.03.19~39c960c3-r2",
        "libc": "1.2.5-r5",
        "libmbedtls": "3.6.6-r2",
        "libustream-mbedtls": "2026.03.01~99f1c0db-r1",
        "logd": "2025.10.30~6f78fa49-r1",
        "luci": "26.158.67103~e99e132",
        "luci-app-attendedsysupgrade": "26.158.67103~e99e132",
        "luci-app-firewall": "26.158.67103~e99e132",
        "luci-app-package-manager": "26.158.67103~e99e132",
        "luci-base": "26.158.67103~e99e132",
        "luci-light": "26.158.67103~e99e132",
        "luci-mod-admin-full": "26.158.67103~e99e132",
        "luci-mod-network": "26.158.67103~e99e132",
        "luci-mod-status": "26.158.67103~e99e132",
        "luci-mod-system": "26.158.67103~e99e132",
        "luci-proto-ipv6": "26.158.67103~e99e132",
        "luci-proto-ppp": "26.158.67103~e99e132",
        "luci-theme-bootstrap": "26.158.67103~e99e132",
        "mtd": "27",
        "odhcp6c": "2026.01.25~ee2949e3-r1",
        "odhcpd-ipv6only": "2026.03.16~edf2e523-r1",
        "owut": "2026.04.09~5d6760b5-r1",
        "ppp": "2.5.2-r3",
        "ppp-mod-pppoe": "2.5.2-r3",
        "procd-ujail": "2026.03.13~58eb263d-r1",
        "uboot-envtools": "2025.10-r2",
        "uci": "2025.12.02~66127cd7-r1",
        "urandom-seed": "3",
        "urngd": "2025.10.03~f17e33d9-r1",
        "wpad-basic-mbedtls": "2025.08.26~ca266cc2-r1"
    },
    "profile": "netgear,wax206",
    "target": "mediatek/mt7622",
    "version": "25.12.4",
    "diff_packages": true,
    "filesystem": "squashfs"
}
STDERR
Generate local signing keys...
WARNING: can't open config file: /builder/shared-workdir/build/staging_dir/host/etc/ssl/openssl.cnf
WARNING: can't open config file: /builder/shared-workdir/build/staging_dir/host/etc/ssl/openssl.cnf
read EC key
writing EC key
WARNING: opening /builder/packages/packages.adb: No such file or directory
Package list missing or not up-to-date, generating it.

Building package index...
ERROR: wget: exited with error 3
ERROR: luci-base-26.187.49110~99464ec: ADB integrity error
ERROR: luci-app-package-manager-26.187.49110~99464ec: ADB integrity error
ERROR: luci-app-firewall-26.187.49110~99464ec: ADB integrity error
ERROR: luci-lib-uqr-26.187.49110~99464ec: ADB integrity error
ERROR: wget: exited with error 3
ERROR: luci-mod-network-26.187.49110~99464ec: ADB integrity error
ERROR: wget: exited with error 3
ERROR: luci-mod-status-26.187.49110~99464ec: ADB integrity error
ERROR: luci-mod-system-26.187.49110~99464ec: ADB integrity error
ERROR: luci-proto-ipv6-26.187.49110~99464ec: ADB integrity error
ERROR: luci-proto-ppp-26.187.49110~99464ec: ADB integrity error
ERROR: luci-theme-bootstrap-26.187.49110~99464ec: ADB integrity error
ERROR: luci-app-attendedsysupgrade-26.187.49110~99464ec: ADB integrity error
make[2]: *** [Makefile:254: package_install] Error 11
make[1]: *** [Makefile:193: _call_manifest] Error 2
make: *** [Makefile:369: manifest] Error 2

Traceback (most recent call last):
  File "/app/.venv/lib/python3.14/site-packages/rq/worker/base.py", line 1550, in perform_job
    return_value = job.perform()
  File "/app/.venv/lib/python3.14/site-packages/rq/job.py", line 1368, in perform
    self._result = self._execute()
                   ~~~~~~~~~~~~~^^
  File "/app/.venv/lib/python3.14/site-packages/rq/job.py", line 1428, in _execute
    result = self.func(*self.args, **self.kwargs)
  File "/app/asu/build.py", line 500, in build
    result = _build(build_request, job)
  File "/app/asu/build.py", line 302, in _build
    report_error(job, check_package_errors(job.meta["stderr"]))
    ~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/app/asu/util.py", line 338, in report_error
    raise RuntimeError(msg)
RuntimeError: Impossible package selection

and I cannot find any solution in the list - can someone lead me in the right direction please?

Since you already have owut installed, could you try running the upgrade directly from the command line?

owut upgrade --verbose

This may provide some additional details compared to running the upgrade from LuCI/Attended Sysupgrade.

If owut fails, could you please post the complete output?

Also, before upgrading, you could run:

owut list

to see which additional packages are being included in the ASU request.

Here's owut list - before I try to upgrade :thinking:

owut list
attendedsysupgrade-common hostapd-common libmbedtls luci luci-app-attendedsysupgrade luci-app-firewall luci-app-package-manager luci-base luci-light luci-mod-admin-full luci-mod-network luci-mod-status luci-mod-system luci-proto-ipv6 luci-proto-ppp luci-theme-bootstrap owut -nftables

to check if a valid image is created (pre-test ...):

1 Like

owut upgrade --verbose is run and my Netgear Wax206 is up running with 25.12.5

It went smooth (though my heart flipped when "no connection" popped up :sweat_smile: )

Thank You so much - later on will move forward updating my Router (BPI-R3 and my Zyxel 1900)

If your router(s) have USB storage, I also recommend customizing the "/etc/owut.d/pre-install.sh" file to save the image, configuration, etc. (adapted to your needs).

example:

https://github.com/compact21/openwrt-script/blob/main/pre-install.sh
1 Like

No I do not use the USB on my routers, but I will attach Your helpfull link in to my OpenWrt folder for future changes.

Thanx / grazie molto


1 Like

are you Italian? :+1:

I'm Italian too...

Nope, just wanted to thank You in Your lingo :wink:

2 Likes

Error 3 usually indicates that storage is full, so it looks like maybe the ASU server has hit its storage limit. You'll have to wait a while for your build request to expire out of the cache (an hour?), and try again, see if it's cleaned up.

1 Like

Hi efahl.

Thanks for the reply - I did as ncompact suggested and did the upgrade using owut -

went smooth without any issues