Files
fips/packaging/openwrt-apk
Arjen 054d17aac5 feat(openwrt): 802.11s open-mesh backhaul support
Router-to-router radio backhaul over an open 802.11s mesh interface,
with FIPS providing all encryption (Noise IK), authentication, and
routing on top of bare L2 neighbor links. The mesh runs OPEN with
mesh_fwding 0 — SAE would duplicate the Noise layer and force ath10k
raw mode, and FIPS is the routing layer — so the Noise handshake is the
real auth/encryption boundary and FIPS's spanning tree does the routing.

fips-mesh-setup: an opt-in UCI helper that creates a per-radio
mesh-point interface (radio0 -> fips-mesh0, radio1 -> fips-mesh1;
trailing-digit derivation with a free-index fallback and a collision
guard). Radio setup stays opt-in — a package must not commandeer radios
on install. 'remove' takes an optional radio and otherwise removes all
instances. Dual-band routers get one instance per radio; FIPS treats the
two backhaul paths as failover, not multipath: it keeps one active link
per peer (cross-connection resolution picks a single winner), and the
second band stands by, re-establishing the peer after keepalive timeout —
traffic never uses both bands at once.

fips.yaml ships the mesh0/mesh1 Ethernet-transport entries commented
out, so a stock install that never creates fips-mesh* logs no per-boot
"interface missing" bind warning. fips-mesh-setup uncomments the matching
meshN block when it creates the interface and re-comments it on remove,
so the flash-and-drop-in flow needs no manual config edit. The file is
rewritten 0600-first (it may hold an inline nsec) via an atomic replace.

Two field-found silent non-peering causes are surfaced by the helper and
the guide:

- Same channel: mesh points only peer on a shared channel, and 'auto'
  lets each radio pick its own. The helper prints the radio's
  band/channel and warns loudly on 'auto' with the exact uci command to
  pin one; the how-to gains an ordered no-peers triage (channel mismatch,
  on-air scan check, DFS CAC wait, regdomain).
- STA channel capture: a client (sta) interface drags the whole radio to
  its upstream AP's channel, so a mesh pinned elsewhere never joins and
  does not recover until the STA disconnects. The helper warns when the
  target radio carries a STA; the guide documents the incompatibility of a
  roaming uplink with a fixed-channel mesh on the same radio.

Both the create and remove paths run 'wifi reload', which briefly drops
every client AP on all radios; the how-to sets that expectation.

Regression test: the shipped OpenWrt fips.yaml must parse via the real
Config deserializer in both states — as shipped (mesh inactive) and after
the uncomment the helper performs.

Packaging: the helper is installed across the ipk/apk/buildroot paths
(three synced copies), with the CI structural checks and shellcheck
targets extended to cover it. Full guide in
docs/how-to/set-up-80211s-mesh-backhaul.md.
2026-07-16 05:48:04 +00:00
..

FIPS OpenWrt Package (apk)

Builds a FIPS .apk for OpenWrt 25+, where apk-tools is the mandatory package manager. apk is also available opt-in on 24.10 (where opkg remains the default). For OpenWrt 24.x and earlier, the .ipk package in ../openwrt-ipk/ still works.

Like the .ipk build, this is SDK-free: it cross-compiles with cargo-zigbuild and assembles the package directly — no OpenWrt SDK image. The .ipk format is a plain tar.gz we can hand-roll, but the .apk (apk-tools v3 ADB) container is not, so we drive the official apk mkpkg applet — the same tool OpenWrt's own include/package-pack.mk calls. The only extra requirement over the .ipk build is the apk binary.

Layout

File Purpose
build-apk.sh Cross-compile + assemble the .apk via apk mkpkg
apk-version.sh Map a release tag / commit height to an apk-tools-valid version
apk-version.test.sh Case-table test for apk-version.sh (sh apk-version.test.sh)

The installed-filesystem payload (init scripts, fips.yaml, sysctl drop-ins, hotplug, uci-defaults, …) is shared with the .ipk package — there is one canonical copy in ../openwrt-ipk/files/. build-apk.sh stages from there, so the two packages always ship the same files. Keep the staging block in build-apk.sh in sync with ../openwrt-ipk/build-ipk.sh.

Versioning

apk-tools enforces a strict version grammar (<digit>(.<digit>)*(_<suffix><digit>*)*(-r<N>)). apk-version.sh builds a valid version from structured inputs rather than rewriting an already-flattened string:

Input apk version
tag v1.2.3 1.2.3-r0
tag v1.2.3-rc1 1.2.3_rc1-r0
dev 1234 (commit height) 0.0.0_git1234-r0

The human-readable version (v1.2.3, master.123.abcdef0) is still used for the artifact filename; only the metadata embedded in the package is normalized.

Building

Prerequisites

Requirement Notes
cargo install cargo-zigbuild + zig Rust musl cross-compilation (as for .ipk)
apk-tools v3 apk binary Provides apk mkpkg; not packaged for most distros — build from source
fakeroot Optional; makes packaged files root-owned on an unprivileged build host

apk-tools is not in Debian/Ubuntu repos, so build the pinned release from source. Pin the same commit the targeted OpenWrt release ships (see package/system/apk/Makefile upstream) so the .apk is readable by the device's apk. CI builds 3.0.5 (b5a31c0d…):

sudo apt-get install -y build-essential meson ninja-build pkg-config \
  zlib1g-dev libssl-dev libzstd-dev liblzma-dev lua5.4-dev scdoc
git clone https://gitlab.alpinelinux.org/alpine/apk-tools.git
cd apk-tools && git checkout b5a31c0d865342ad80be10d68f1bb3d3ad9b0866
meson setup build && ninja -C build src/apk
export APK_BIN="$PWD/build/src/apk"

Build the package

# from the repo root
./packaging/openwrt-apk/build-apk.sh --arch aarch64    # or x86_64, mipsel, mips, arm

Output: dist/fips_<version>_<openwrt-arch>.apk. Override the version with PKG_VERSION (filename) and APK_VERSION (embedded metadata); otherwise both are derived from git.

Installing on the router

Packages are unsigned (the same posture as our .ipk), so install with --allow-untrusted:

scp -O dist/fips_<version>_<arch>.apk root@192.168.1.1:/tmp/
ssh root@192.168.1.1 apk add --allow-untrusted /tmp/fips_<version>_<arch>.apk

On OpenWrt 25.x, installing from a signed repository requires the publisher's key; a single --allow-untrusted package install does not. If we ever publish an apk feed, add ECDSA (prime256v1) signing via apk mkpkg --sign and distribute the public key to /etc/apk/keys/.

/etc/fips/fips.yaml is marked as a config file (via /lib/apk/packages/fips.conffiles), so apk preserves local edits across upgrades, and /lib/upgrade/keep.d/fips preserves /etc/fips/ across sysupgrade — the same guarantees as the .ipk package.