When asked for full source code they seem transparent about it:
https://forum.gl-inet.com/t/source-code-for-gl-firmware-and-...
You can't reproduce their images and they don't share the improvements.
Of course not GPL compliant but not a concern in China I believe.
This isn't entirely accurate. It absolutely is running a full OpenWRT instance. In addition to that, they have produced their own UI/shell, which is the default that you'll land on, but it's not difficult to get into LuCI.
That said, I'm not stating that it's only running OpenWRT, or that the OpenWRT instance it is running is unmodified, or trustworthy.
That said, I have struggled to get gigabit wireguard VPN throughput on other devices that support OpenWRT.
I love FOSS, I love self-hosting, I love DIY-friendly tinkerer-friendly, and I love high levels of user control, I just wish the ecosystem that prioritized these things had a stronger emphasis on high-end hardware that offers high performance.
https://www.gl-inet.com/support/firmware-versions/
You might find some sources here:
The issues regarding GPL compliance or lack thereof are worth noting, however. I made a point of asking for native OpenWrt firmware for the products I have from them, only to discover after the fact that due to closed source firmware blobs, it will likely never be available in that format, which was somewhat disappointing.
Given the fairly low/competitive price point of their hardware, I think it’s worth taking the time to make sure that the device suits your needs in that regard, if it’s important to you.
Sent from my iPhone
I’d like to run fully open source network stack if possible myself, though I’m not sure if that possible without moving the goalposts and virtualizing something or doing it in software, and even then I’d have to figure out some kind of boot attestation ideally, thought I'm not sure how that's going to pan out. Isn't Intel SGX/AMD SEV/ARM CCA required for that?
Some links I thought we interesting on that topic, as it's adjacent to the discussion:
> A comparison study of intel SGX and AMD memory encryption technology
https://dl.acm.org/doi/10.1145/3214292.3214301
> vSGX: Virtualizing SGX Enclaves on AMD SEV
https://ieeexplore.ieee.org/document/9833694
What do you suggest? How’s your hat fitting, by the way?
Here's the firmware for the OpenWrt One, if that helps you determine whether it does what you want:
https://firmware-selector.openwrt.org/?version=SNAPSHOT&targ...
If you find the answer to your/our questions, please let me/us know!
Sent from my iPhone in Lockdown Mode
I'd argue that even though by default the Flint 2 has a nicer interface for beginners, vanilla OpenWrt is much better. E.g. their old OpenWrt 21.02 build with the proprietary Mediatek SDK does not support baby jumbo frames, which are used by a bunch of providers that still use PPPoE (to get better performance).
> Of course not GPL compliant but not a concern in China I believe.
I don't believe this. There are multiple cases where GPL was enforced by Chinese courts.Example: https://www.ifross.org/?q=node/1676
With GL.inet the buyer can install their own OpenWRT images. The OEM OpenWRT fork is a means of installing the buyer's choice of OpenWRT image.
For Cudy, another Chinese OEM, OpenWRT ToH refers to this as "Intermediate Firmware". See, e.g., https://openwrt.org/toh/cudy/tr1200
An OEM OpenWRT fork ("intermediate firmware") is (pre)installed, allowing a buyer overwrite it with an open source, GPL compliant OpenWRT image of their choice downloaded from openwrt.org or one compiled from source code downloaded from openwrt.org.
OpenWRT One is a Banana Pi board. Like GL.inet or Cudy, the Chinese OEM has their own system images.^1 Can a buyer reproduce them. 1. For example, https://docs.banana-pi.org/en/BPI-R4/BananaPi_BPI-R4#_system...
I just spotted an upstream PR in the works, so it should be supported eventually.
Their GL.iNet SFT-1200 "Opal" router does NOT have ANY OSS firmware options. It's a great travel router for $35 USD, but, alas, they're basically abusing the OpenWrt trademark by advertising it as an OpenWrt router when it is not.
Luckily, I think most of the other ones do have OpenWrt builds, but, if you're going to install OpenWrt manually, might as well get a different/cheaper router from some other manufacturer, like Cudy or Dynalink, which are also supported by OpenWrt, and are very affordable for the hardware that you get.
Switching from stock to OpenWRT was incredibly easy.
I have to reboot it about once every month or two (my previous router, a Netgear R7800, only needed to be rebooted maybe once every other year.) But I hear that the nightly builds are a bit better in this respect, so I expect the stable builds will improve with time.
I installed the LibreSpeed-go package, and it can completely saturate the 2.5gbps LAN port.
Thanks for the tip. LibreSpeed-go works slick-enough to actually be useful for the kinds of things I care about at home.
And because it is apparently not cohesively documented anywhere, here's brief instructions for a semi-clued person to quickly make LibreSpeed-go work on OpenWRT:
1. Install the package. Might as well do it from CLI because we need to go there anyway. Log into the router with ssh, and do an "opkg update" and then "opkg install librespeed-go"
2. Enable it. Edit /etc/config/librespeed-go with, eg, "nano /etc/config/librespeed-go" and set "Enabled" from 0 to 1.
3. Start it. "/etc/init.d/librespeed-go restart" works.
4. Use it. Fire up a web browser somewhere on the LAN, and visit http://your.router.addy:8989
5. Clicky button. Observe speed.
Besides that it has quite a bit better CPU (quad core rather than dual core), so if you do anything that cannot be hardware-offloaded (e.g. Cake), the performance will be better.
The OpenWrt has better hackability though. USB-C serial is very handy if you manage to mess up your configuration in a way you can't access the device (though LuCI have this features where it can revert changes if a change makes the router non-responsive to the user).
The other question is whether it is worth it. As far as I understand, the Filogic in the Flint 2 has hardware support for fq_codel. When doing buffer bloat tests with the waveform test, the score would always be A, whereas on the same connection a Fritz!Box 5590 Fiber would show pretty bad buffer bloat (grade D on the waveform test).
For anyone else that's interested, I just noticed that the OpenWrt wiki has some numbers:
But as somebody doing OpenWrt package development the One is where I'm running Snapshot and trying out the new Alpine package manager.
I want something that has like actual good packages already installed for common internet standards, that are configured by experts (so they work), that supports IPv6 perfectly, and is user-friendly so I can use it for what I need without having to work on router firmware. It's like... maybe I should write my own firmware at this point. Cause everything is actually just shit.
???
Devices like Flint 2 have LuCI preinstalled. It's even linked in GL.iNets interface (IIRC on the Advanced page).
(I own some Gl.Inet products and they're reasonably good and I specifically purchased them for their OpenWRT-ness)