pbr (see Whole-Network VPN routing) requires the ip-full package, and it gets very upset if it doesn’t have it available:

# /etc/init.d/pbr start
pbr 1.2.2-r20 FAILED TO START!!!
Check the output of nft -c -f /var/run/pbr.nft
ERROR: Required binary 'ip-full' is missing!
ERROR: Errors encountered, please check https://...

This is made especially confusing when ip-full is installed:

# opkg list-installed | grep ip
...
ip-full 6.11.0-r1
...

In my case, an upgrade to the busybox kernel had caused the issue. During the update, busybox apparently retook control over the ip binary. You can check this with:

# readlink /sbin/ip
../bin/busybox

The above output indicates that the ip symlink points to busybox’s implementation, not ip-full’s. This can be fixed by reinstalling the ip-full package:

# opkg remove ip-full --force-depends
# opkg install ip-full

Now, you should see

# readlink /sbin/ip
/usr/libexec/ip-full

and /etc/init.d pbr start should start normally!

See also