pbr (see Whole-Network VPN routing) requires the ip-full package, and it gets very upset if it doesn’t have it available:
# /etc/init.d/pbr start
pbr 1.2.2-r20 FAILED TO START!!!
Check the output of nft -c -f /var/run/pbr.nft
ERROR: Required binary 'ip-full' is missing!
ERROR: Errors encountered, please check https://...
This is made especially confusing when ip-full is installed:
# opkg list-installed | grep ip
...
ip-full 6.11.0-r1
...
In my case, an upgrade to the busybox kernel had caused the issue. During the update, busybox apparently retook control over the ip binary. You can check this with:
# readlink /sbin/ip
../bin/busybox
The above output indicates that the ip symlink points to busybox’s implementation, not ip-full’s. This can be fixed by reinstalling the ip-full package:
# opkg remove ip-full --force-depends
# opkg install ip-full
Now, you should see
# readlink /sbin/ip
/usr/libexec/ip-full
and /etc/init.d pbr start should start normally!
See also
I couldn’t find any documentation on this problem and figured it out by searching the
pbrcode:
- https://github.com/openwrt/packages/blob/a8b6b3b5519331ba1edde8a903050fbd362d4b9a/net/pbr/files/etc/init.d/pbr#L57
- https://github.com/openwrt/packages/blob/a8b6b3b5519331ba1edde8a903050fbd362d4b9a/net/pbr/files/etc/init.d/pbr#L866
- https://github.com/openwrt/packages/blob/a8b6b3b5519331ba1edde8a903050fbd362d4b9a/net/pbr/files/etc/init.d/pbr#L679