Question about upgrading packages and firmware

Hello,
I got a little paranoid when reading the following article:

I do not think I use that specific package (Attended Sysupgrade ([ASU])...I have an R7800 running [OpenWrt 23.05.3 r23809-234f1a2efa] with nothing other than adblock and Wireshark.

I started to manually upgrade each of my packages through the LUCI interface, but then wondered what the best approach to ensuring that my firmware/router/packages were up-to-date.

  1. I see several posts on this forum indicating that its not ideal to upgrade everything...either manually or all at once via ssh.
  2. Should I just plan on upgrading the firmware when new releases come out?
  3. If I use the sysupgrade will it preserve my wireshark settings and profiles?

Thanks!

First thing if you suspect damage would be to upgrade to clean 23.05.5 sysupgrade, then add your packages.

luci-app-attendedsysupgrade ?

This CVE does not apply to you, then. In fact, while it was a serious potential vulnerability, it's mostly academic in that it is believed that nobody would have actually been affected.

do not do this...

Upgrading packages (via the CLI opkg upgrade command or the LuCI Upgrade... button) can result in major problems. It is generally highly discouraged, unless you know what you are doing or if there is specific instruction to do so.

Correct, per the above information.

Yes.

Yes.

Thank you for your quick reply (and brada4).

I don't think I have been hacked or anything...thought I did notice that some devices on my network were having issues connecting and resolving DNS. I will need to do a fresh install then, since I have manually upgraded under a dozen of the packages via LUCI.

Question:
Is there a way to save my settings (and wireshark) but not the package upgrades I have just pushed?

Just create a backup.

https://openwrt.org/docs/guide-user/troubleshooting/backup_restore

Then reset to defaults.

When that is complete, install any necessary packages and then restore the backup.

Thanks again.

Does restoring a backup pull in packages?

No, the backups only contain the configurations/settings. That's why I specifically mentioned that you'll install any necessary packages after resetting to defaults.

  1. Backup
  2. Reset
  3. Install packages
  4. Restore backup.
1 Like

Thank you, I performed the upgrade this way and can confirm everything looks to be working!

1 Like

This topic was automatically closed 10 days after the last reply. New replies are no longer allowed.