Conversation
openwrt-ai
left a comment
There was a problem hiding this comment.
Reviewed 2 new commits; no blocking issues. Verified the QMI backend env var (LPAC_APDU_QMI_DEVICE, default /dev/cdc-wdm0) against upstream lpac's driver/apdu/qmi.c/docs, and both commit messages match their diffs. One minor nit inline.
Generated by Claude Code
a745e53 to
412f228
Compare
openwrt-ai
left a comment
There was a problem hiding this comment.
Reviewed 1 new commit; no new issues found. The only change since the last review removes the trailing blank line in utils/lpac/files/lpac.uci, resolving the earlier nit.
Generated by Claude Code
This fixes the output of the lpac version.
Before this patch 'lpac version' showed this output:
{"type":"lpa","payload":{"code":0,"message":"success","data":"v0.0.0-unknown"}}
After applying the patch we will get the real version:
{"type":"lpa","payload":{"code":0,"message":"success","data":"2.3.0"}}
Signed-off-by: Martin Schiller <ms@dev.tdt.de>
Add support for the libqmi APDU backend to be able to use the lpac togehter with modemmanager for QMI based modems. Tested with a Quectel RM520N-GL modem. Signed-off-by: Martin Schiller <ms@dev.tdt.de>
412f228 to
58bfbb8
Compare
lpac needs to validate TLS connections to SM-DP+/SM-DS servers whose certificates chain up to a GSMA RSP root CI, which is not part of the public Mozilla/Debian CA set shipped by ca-certificates/ca-bundle. Add a new (default-on) config option LPAC_INSTALL_GSMA_CI_CERTS that downloads three GSMA RSP root CI certificates at build time (M2M/Verizon, Consumer/Symantec, eSIM/CI SIG OISTE), normalizes them to PEM and merges them into /etc/ssl/certs/ca-certificates.crt. Source of the certificate list: https://www.gsma.com/solutions-and-impact/technologies/internet-of-things/embedded-sim/gsma-root-certificate-issuer-remote-sim-provisioning/ Signed-off-by: Martin Schiller <ms@dev.tdt.de>
This adds support for TLS hostname certificate verification and enables it by default. Also fix the error reason output for some notification commands to get usable feedback if there is sth. wrong e.g. with the HTTP transport. Signed-off-by: Martin Schiller <ms@dev.tdt.de>
58bfbb8 to
cb039d8
Compare
| URL:=https://www.gsma.com/solutions-and-impact/technologies/esim/wp-content/uploads/2024/01/ | ||
| URL_FILE:=CERT_CI_SIG_OISTE.pem_.zip | ||
| FILE:=lpac-gsma-ci-oiste.zip | ||
| SPOOF_USER_AGENT:=Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:139.0) Gecko/20100101 Firefox/139.0 |
There was a problem hiding this comment.
+ curl -f --connect-timeout 5 --retry 3 --location https://www.gsma.com/.../2024/01/CERT_CI_SIG_OISTE.pem_.zip
curl: (22) The requested URL returned error: 403
No more mirrors to try - giving up.
make[2]: *** [Makefile:51: /builder/dl/lpac-gsma-ci-oiste.zip] Error 2
All 10 CI build jobs fail at this download. SPOOF_USER_AGENT is not a field Download/Defaults knows about, so curl runs without it (same for the two downloads above) and gsma.com answers 403. Fetch this file from a source that works without UA tricks, or ship the certificates in files/.
Generated by Claude Code
| $(INSTALL_DIR) $(1)/usr/lib | ||
| $(INSTALL_BIN) $(PKG_INSTALL_DIR)/usr/bin/lpac $(1)/usr/lib/lpac | ||
|
|
||
| ifdef CONFIG_LPAC_INSTALL_GSMA_CI_CERTS |
There was a problem hiding this comment.
Package/lpac/install is expanded into a recipe via $(call ...) (package-pack.mk:465), so make never parses this ifdef/endif (line 123). The shell runs them as commands and the install step fails, whether or not the option is enabled. Use $(if $(CONFIG_LPAC_INSTALL_GSMA_CI_CERTS),...) or put the cert steps in a separate define that a top-level ifdef selects.
Generated by Claude Code
|
|
||
| # Verizon/M2M31 Root CI is distributed as raw DER despite the | ||
| # .txt extension; convert it to PEM. | ||
| openssl x509 -inform DER -outform PEM \ |
There was a problem hiding this comment.
This needs an openssl binary on the build host, but prereq-build.mk does not check for one, and nothing in the build tree provides it. Ship the PEM-converted certificate in files/, or declare a host build dependency that provides openssl.
Generated by Claude Code
| echo "$$marker_begin" | ||
| cat "$$cert" | ||
| echo "$$marker_end" | ||
| } >> "$$CA_BUNDLE" |
There was a problem hiding this comment.
This file belongs to ca-bundle, so the next ca-bundle upgrade replaces it and silently drops these certs, and apk will report the file as modified. Ship the certs as their own file (e.g. under /etc/ssl/certs/). Then have the patched curl backend point at them with CURLOPT_CAINFO/CURLOPT_CAPATH, instead of editing another package's file.
Generated by Claude Code
📦 Package Details
Maintainer: @blocktrron
Description:
Let's add libqmi support to be able to use lpac together with modemmanager for QMI based modems.
Tested with Quectel RM520N-GL.
This also fixes the output of the lpac version.
Before this patch 'lpac version' showed this output:
{"type":"lpa","payload":{"code":0,"message":"success","data":"v0.0.0-unknown"}}After applying the patch we will get the real version:
{"type":"lpa","payload":{"code":0,"message":"success","data":"2.3.0"}}In addition, support for TLS verification will be added to the curl HTTP backend,
and the necessary certificates will be integrated into the system's ca-bundle.
🧪 Run Testing Details
✅ Formalities
If your PR contains a patch:
git am(e.g., subject line, commit description, etc.)
We must try to upstream patches to reduce maintenance burden.