Skip to content

lpac: QMI APDU support + LPAC_VERSION fix + TLS verification - #30048

Open
sch-m wants to merge 4 commits into
openwrt:masterfrom
TDT-AG:pr/20260720-lpac-version-fix
Open

sch-m wants to merge 4 commits into
openwrt:masterfrom
TDT-AG:pr/20260720-lpac-version-fix

Conversation

@sch-m

@sch-m sch-m commented Jul 20, 2026 •

Copy link
Copy Markdown
Contributor

📦 Package Details

Maintainer: @blocktrron

Description:
Let's add libqmi support to be able to use lpac together with modemmanager for QMI based modems.

Tested with Quectel RM520N-GL.

This also fixes the output of the lpac version.

Before this patch 'lpac version' showed this output:

{"type":"lpa","payload":{"code":0,"message":"success","data":"v0.0.0-unknown"}}

After applying the patch we will get the real version:

{"type":"lpa","payload":{"code":0,"message":"success","data":"2.3.0"}}

In addition, support for TLS verification will be added to the curl HTTP backend,
and the necessary certificates will be integrated into the system's ca-bundle.


🧪 Run Testing Details

  • OpenWrt Version: 25.12
  • OpenWrt Target/Subtarget: mediatek/filogic
  • OpenWrt Device: BPI-R4

✅ Formalities

  • I have reviewed the CONTRIBUTING.md file for detailed contributing guidelines.

If your PR contains a patch:

  • It can be applied using git am
  • It has been refreshed to avoid offsets, fuzzes, etc., using
    make package/<your-package>/refresh V=s
  • It is structured in a way that it is potentially upstreamable
    (e.g., subject line, commit description, etc.)
    We must try to upstream patches to reduce maintenance burden.

@openwrt-ai openwrt-ai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed 2 new commits; no blocking issues. Verified the QMI backend env var (LPAC_APDU_QMI_DEVICE, default /dev/cdc-wdm0) against upstream lpac's driver/apdu/qmi.c/docs, and both commit messages match their diffs. One minor nit inline.


Generated by Claude Code

Comment thread utils/lpac/files/lpac.uci Outdated
@sch-m
sch-m force-pushed the pr/20260720-lpac-version-fix branch from a745e53 to 412f228 Compare July 21, 2026 06:30

@openwrt-ai openwrt-ai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed 1 new commit; no new issues found. The only change since the last review removes the trailing blank line in utils/lpac/files/lpac.uci, resolving the earlier nit.


Generated by Claude Code

sch-m added 2 commits October 2, 2026 08:12
This fixes the output of the lpac version.

Before this patch 'lpac version' showed this output:

{"type":"lpa","payload":{"code":0,"message":"success","data":"v0.0.0-unknown"}}

After applying the patch we will get the real version:

{"type":"lpa","payload":{"code":0,"message":"success","data":"2.3.0"}}

Signed-off-by: Martin Schiller <ms@dev.tdt.de>
Add support for the libqmi APDU backend to be able to use the lpac
togehter with modemmanager for QMI based modems.

Tested with a Quectel RM520N-GL modem.

Signed-off-by: Martin Schiller <ms@dev.tdt.de>
@sch-m
sch-m force-pushed the pr/20260720-lpac-version-fix branch from 412f228 to 58bfbb8 Compare October 2, 2026 06:12
sch-m added 2 commits October 2, 2026 08:14
lpac needs to validate TLS connections to SM-DP+/SM-DS servers whose
certificates chain up to a GSMA RSP root CI, which is not part of the
public Mozilla/Debian CA set shipped by ca-certificates/ca-bundle.

Add a new (default-on) config option LPAC_INSTALL_GSMA_CI_CERTS that
downloads three GSMA RSP root CI certificates at build time
(M2M/Verizon, Consumer/Symantec, eSIM/CI SIG OISTE), normalizes them to
PEM and merges them into /etc/ssl/certs/ca-certificates.crt.

Source of the certificate list:
https://www.gsma.com/solutions-and-impact/technologies/internet-of-things/embedded-sim/gsma-root-certificate-issuer-remote-sim-provisioning/

Signed-off-by: Martin Schiller <ms@dev.tdt.de>
This adds support for TLS hostname certificate verification and enables
it by default.

Also fix the error reason output for some notification commands to get
usable feedback if there is sth. wrong e.g. with the HTTP transport.

Signed-off-by: Martin Schiller <ms@dev.tdt.de>
@sch-m
sch-m force-pushed the pr/20260720-lpac-version-fix branch from 58bfbb8 to cb039d8 Compare October 2, 2026 06:15
@sch-m sch-m changed the title lpac: QMI APDU support + LPAC_VERSION fix lpac: QMI APDU support + LPAC_VERSION fix + TLS verification Oct 2, 2026
Comment thread utils/lpac/Makefile
URL:=https://www.gsma.com/solutions-and-impact/technologies/esim/wp-content/uploads/2024/01/
URL_FILE:=CERT_CI_SIG_OISTE.pem_.zip
FILE:=lpac-gsma-ci-oiste.zip
SPOOF_USER_AGENT:=Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:139.0) Gecko/20100101 Firefox/139.0

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+ curl -f --connect-timeout 5 --retry 3 --location https://www.gsma.com/.../2024/01/CERT_CI_SIG_OISTE.pem_.zip
curl: (22) The requested URL returned error: 403
No more mirrors to try - giving up.
make[2]: *** [Makefile:51: /builder/dl/lpac-gsma-ci-oiste.zip] Error 2

All 10 CI build jobs fail at this download. SPOOF_USER_AGENT is not a field Download/Defaults knows about, so curl runs without it (same for the two downloads above) and gsma.com answers 403. Fetch this file from a source that works without UA tricks, or ship the certificates in files/.


Generated by Claude Code

Comment thread utils/lpac/Makefile
$(INSTALL_DIR) $(1)/usr/lib
$(INSTALL_BIN) $(PKG_INSTALL_DIR)/usr/bin/lpac $(1)/usr/lib/lpac

ifdef CONFIG_LPAC_INSTALL_GSMA_CI_CERTS

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Package/lpac/install is expanded into a recipe via $(call ...) (package-pack.mk:465), so make never parses this ifdef/endif (line 123). The shell runs them as commands and the install step fails, whether or not the option is enabled. Use $(if $(CONFIG_LPAC_INSTALL_GSMA_CI_CERTS),...) or put the cert steps in a separate define that a top-level ifdef selects.


Generated by Claude Code

Comment thread utils/lpac/Makefile

# Verizon/M2M31 Root CI is distributed as raw DER despite the
# .txt extension; convert it to PEM.
openssl x509 -inform DER -outform PEM \

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This needs an openssl binary on the build host, but prereq-build.mk does not check for one, and nothing in the build tree provides it. Ship the PEM-converted certificate in files/, or declare a host build dependency that provides openssl.


Generated by Claude Code

Comment thread utils/lpac/Makefile
echo "$$marker_begin"
cat "$$cert"
echo "$$marker_end"
} >> "$$CA_BUNDLE"

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This file belongs to ca-bundle, so the next ca-bundle upgrade replaces it and silently drops these certs, and apk will report the file as modified. Ship the certs as their own file (e.g. under /etc/ssl/certs/). Then have the patched curl backend point at them with CURLOPT_CAINFO/CURLOPT_CAPATH, instead of editing another package's file.


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants