wifi-scripts: restore priv_key/priv_key_pwd as config aliases

The shell config generator read the client private key from the UCI
options priv_key / priv_key_pwd (and priv_key2 / priv_key2_pwd for the
inner tunnel). The ucode generator was switched to private_key /
private_key_passwd (matching the wpa_supplicant field names), and LuCI
was updated accordingly, but existing configurations still carry the old
option names.

Such configs silently lose their private key: for an EAP-TLS client this
leaves wpa_supplicant without a client key and authentication fails after
upgrading from 24.10.

The schema already lists priv_key / priv_key_pwd, but as plain strings,
so validate() never migrates them. Declare them (and the missing
priv_key2 / priv_key2_pwd) as aliases of the private_key* options so the
old names keep working.

Fixes: https://github.com/openwrt/openwrt/issues/22599
Fixes: 218f3884d2 ("wifi-scripts: add ucode based scripts")
Assisted-by: Claude:claude-opus-4-8
Link: https://github.com/openwrt/openwrt/pull/24088
(cherry picked from commit 649b42331c)
Link: https://github.com/openwrt/openwrt/pull/24116
Signed-off-by: Hauke Mehrtens <hauke@hauke-m.de>
This commit is contained in:
Hauke Mehrtens
2026-07-21 22:18:46 +02:00
parent d9a452e7cd
commit da9b1abb5f
@@ -853,10 +853,20 @@
"default": true
},
"priv_key": {
"type": "string"
"type": "alias",
"default": "private_key"
},
"priv_key_pwd": {
"type": "string"
"type": "alias",
"default": "private_key_passwd"
},
"priv_key2": {
"type": "alias",
"default": "private_key2"
},
"priv_key2_pwd": {
"type": "alias",
"default": "private_key2_passwd"
},
"private_key": {
"description": "Private key matching with the server certificate for EAP-TLS/PEAP/TTLS",