Wednesday, October 7, 2026

Tunnel SSL connect vm to host

apk add openssh-client (openwrt linux)

ssh-keygen -t rsa -b 2048 -f id_rsa (windows , host)
upload to vm (openwrt) /roots/.ssh/id_rsa
paste id_rsa.pub in--> /.ssh/authorized_keys

ssh -i /root/.ssh/id_rsa -N -R 8080:localhost:80 prapop@192.168.0.86 (openwrt)

http://localhost:8080 (windows)

Cross compile busybox for openwrt from windows10 (wsl)

how to cross compile busybox 1.38.0 for openwrt 25.12.5 x86_64 from windows10
use toolchain x86_64-openwrt-linux-musl-

Setting up a cross-compile of BusyBox for OpenWrt from Windows.

Cross-compiling BusyBox 1.38.0 for OpenWrt x86_64 from Windows 10

The OpenWrt toolchain is a Linux (ELF) toolchain, so it can't run natively on Windows. The usual approach is to use WSL2 as the build host.

1. Install WSL2

In PowerShell (admin):

powershell
wsl --install -d Ubuntu

Reboot if asked, then open the Ubuntu shell. Work inside the Linux filesystem (~), not /mnt/c/.... Building on the Windows drive is slow and causes case-sensitivity and symlink problems.

2. Install build dependencies

bash
sudo apt update
sudo apt install -y build-essential libncurses-dev wget bzip2 zstd xz-utils file

3. Get the OpenWrt SDK (contains the x86_64-openwrt-linux-musl- toolchain)

Browse https://downloads.openwrt.org/releases/25.12.5/targets/x86/64/ and download the file named openwrt-sdk-25.12.5-x86-64_gcc-*_musl.Linux-x86_64.tar.zst. The gcc version in the name will vary, so check the directory listing.

bash
cd ~
wget https://downloads.openwrt.org/releases/25.12.5/targets/x86/64/<SDK-FILENAME>.tar.zst
tar --zstd -xf <SDK-FILENAME>.tar.zst   # or: zstd -d file | tar x

Find the toolchain and set up the environment:

bash
SDK=$(ls -d ~/openwrt-sdk-*/)
TC=$(ls -d $SDK/staging_dir/toolchain-*/)
export STAGING_DIR=$SDK/staging_dir
export PATH=$TC/bin:$PATH

x86_64-openwrt-linux-musl-gcc --version   # sanity check

The STAGING_DIR variable matters because the OpenWrt wrapper scripts need it, otherwise you'll see warnings or failures.

4. Get BusyBox 1.38.0

bash
cd ~
wget https://busybox.net/downloads/busybox-1.38.0.tar.bz2
tar xf busybox-1.38.0.tar.bz2
cd busybox-1.38.0

5. Configure

bash
make defconfig
make menuconfig

In menuconfig:

  • Settings → Build Options → Build static binary (no shared libs): enable (recommended; musl static builds work well and run anywhere).
  • Settings → Build Options → Cross compiler prefix: set to x86_64-openwrt-linux-musl- (optional, since you can also pass it on the command line).

6. Build

bash
make ARCH=x86_64 CROSS_COMPILE=x86_64-openwrt-linux-musl- -j$(nproc)

Verify the result:

bash
file busybox
# expect: ELF 64-bit LSB executable, x86-64, statically linked

If you want an install tree:

bash
make ARCH=x86_64 CROSS_COMPILE=x86_64-openwrt-linux-musl- CONFIG_PREFIX=$HOME/bb-install install

7. Copy it to Windows / the router

bash
cp busybox /mnt/c/Users/<you>/Desktop/

You can also browse to \\wsl$\Ubuntu\home\<you>\busybox-1.38.0 in Explorer. Then transfer to the device with scp, and run it with chmod +x busybox && ./busybox ls.

Troubleshooting

  • tc.c errors (CBQ undeclared): a known issue with newer kernel headers. Disable it with make menuconfig → Networking Utilities → uncheck tc.
  • Other failures on a specific applet: disable that applet in menuconfig. Newer musl and gcc are stricter than what BusyBox's defconfig was tested against.
  • command not found for the compiler: PATH or STAGING_DIR isn't exported in the current shell. Re-run the step 3 exports.
  • Mismatched filenames: I can't verify the exact SDK and gcc filenames for 25.12.5, so use the directory listing.

Note

OpenWrt already ships its own BusyBox, built from its package system. Don't overwrite /bin/busybox on a running router with yours, as that can break the system. Put it somewhere like /tmp or /opt, or use it as an additional binary. If you instead want a fully integrated build, use the OpenWrt buildroot (make menuconfig → Base system → busybox) rather than a standalone build.

chmod before use

Right, the executable bit matters here. Two places it comes up:

On the router (after copying)

Files copied from Windows, or through WSL's /mnt/c/... paths, don't keep a reliable execute permission, so set it on the target:

sh
chmod +x /tmp/busybox
/tmp/busybox ls

My earlier line chmod +x busybox && ./busybox ls covered this, but it's easy to miss. If you transfer with scp from WSL, run chmod on the device afterward, not before.

Inside WSL (before copying)

The built binary already has the execute bit in the Linux filesystem, so you can test it right there if you're on an x86_64 machine:

bash
chmod +x busybox
./busybox --help

Cr. Claude