QiuSimons/YAOF: a preconfigured OpenWrt build for NanoPi R2C, R2S, R4S and x86
OpenWrt for Nanopi R2C/R2S/R4S/X86
At a glance
- What is it?
- YAOF is a Shell-driven OpenWrt 25.12 build that ships with proxy and DNS plugins already configured for four hardware targets. It is convenient and opinionated, and the README is blunt about the trade-offs.
- Who is it for?
- Adopt YAOF if you own one of the four supported boards and want a working router with proxy and DNS plugins already in place. Skip it if you need Docker (the README points Docker users at 23.05), if your hardware is not on the list, or if you want a minimal image you assemble yourself.
- Can I use it commercially?
- Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
- Is it still maintained?
- Yes. The repository last received commits 27 days ago.
- What is it written in?
- Mainly Shell, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 24, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What YAOF is, and the four boards it targets
YAOF is not a router operating system written from scratch. It is a build configuration layer on top of OpenWrt 25.12, maintained by QiuSimons, that produces firmware images for the NanoPi R2C, R2S, R4S and generic x86 machines. The repository is mostly Shell, and the top-level layout reflects that: PATCH/, SCRIPTS/, SEED/ and a SWITCH entry, with the README as the only prose documentation.
The intended user is someone who has already bought a small ARM or x86 box and wants it to route traffic without spending an evening in menuconfig. The README lists the plugins that come preinstalled: SSRP, PassWall, OpenClash, Mihomo, DAED, SQM, DNSProxy, DDNS, UPnP, FullCone, Zerotier, FRPC and FRPS, among others. That list is the product. If you want a stock OpenWrt with nothing extra, YAOF is the wrong starting point.
The default management address is 192.168.1.1. The README states that the built-in upgrade function and the physical Reset button both work, which matters on devices with no serial console.
How the build is assembled and what ships enabled
The repository layout shows a patch-and-seed model. PATCH/ holds changes applied to upstream sources, SEED/ holds configuration fragments that select packages and kernel options, and SCRIPTS/ holds the build logic. The GitHub Actions workflows named R2C-OpenWrt, R2S-OpenWrt, R4S-OpenWrt and X86-OpenWrt each produce an image for one target, so the four device families are built separately rather than from a single generic config.
Two build choices are stated in the README. The images are compiled with O2 and CFLAG optimizations, and BBRv3 plus LRNG are integrated and enabled by default. The README also notes that the ss protocol has AES hardware acceleration on armv8, with the instruction to use only aead encryption modes. That is a real constraint, not a suggestion: a non-aead cipher will not benefit from the acceleration the build was tuned for.
The DNS path is the most opinionated part. MosDNS is configured to serve as both the ad-filtering mechanism and the DNS routing mechanism. Anyone who later installs a second DNS forwarder without removing MosDNS from the chain should expect conflicts, because the README treats these as one component rather than two.
Installing YAOF and getting to the LuCI login
There is no source install. You download a firmware image and flash it. The README directs users to the releases page and says to pick the image that matches your device. The releases in this repository are tagged in the form 25.12.5 (OpenWRT-25.12.5), so the tag tells you which OpenWrt base the image was built from.
Once flashed and booted, the device answers on the default address 192.168.1.1. The README does not give a ping or SSH example, so the first confirmation step is simply opening the LuCI web interface in a browser at http://192.168.1.1 and logging in. The README does not document the default credentials, so treat the first login as a step to confirm against the release notes for your image rather than something to guess.
If something misbehaves, the README gives a specific recovery step: SSH into the device and run the command fuck, then press Enter. The README says to wait for the machine to reboot and then check whether the problem is gone. That is the documented troubleshooting path, and it is worth knowing before you start changing plugin settings.
For x86 targets, write the image to the boot disk with the tool you normally use for raw disk images, then boot the machine. The README does not describe the x86 flashing procedure in detail, so the x86 entry is the least documented of the four.
The R4S frequency note and the power supply warning
The README makes a hardware claim that is easy to skim past. R2C and R2S run at a core frequency of 1.6, and the LAN and WAN ports are swapped relative to what you might expect. R4S runs at 2.2/1.8. For the R4S, the README recommends a power supply with cable-loss compensation and states plainly that most freezes come from an inadequate power supply. It also points out that you can cap the maximum frequency using the bundled app instead.
This is a useful admission. A build that raises clocks and then tells you the failures are your power brick's fault is telling you where the operating margin sits. If you are deploying an R4S somewhere you cannot easily reach, either use the recommended supply or lower the ceiling before you put it in place.
The same paragraph is written in a casual, profane register. That tone runs through the README. It does not affect the firmware, but it does mean the documentation reads like a forum post rather than a manual, and you should calibrate your expectations for formal troubleshooting sections accordingly.
Docker is gone, and the README says so
The clearest limitation is stated outright: Docker is no longer integrated. The README tells Docker users to stay on 23.05, and says that if you want to use Docker you must first enable the "Docker - configuration - autostart" option and save the settings. There is also a bundled plugin that formats the remaining space and mounts it, aimed at Docker users who need storage for images.
That is a meaningful fork in the road. If your plan for the box involves running containers, this branch of the project is not the one to start from, and the README does not pretend otherwise. The 23.05 line is where the README points you.
Two other constraints are worth naming. First, the target list is fixed at R2C, R2S, R4S and x86. A Raspberry Pi or an R5S is not covered. Second, the README opens with a notice against commercial use. The project is GPL-3.0, so the licence and that notice are separate things, and anyone planning to resell hardware with this firmware should read both rather than assume the notice is decorative.
YAOF against building your own OpenWrt image
The real alternative is not another prebuilt firmware. It is the OpenWrt Image Builder or a full source build, where you choose every package yourself. The difference in approach is who makes the DNS and proxy decisions. YAOF makes them for you: MosDNS handles filtering and routing together, and the proxy stack is already installed and wired up. A self-built image starts empty and you add exactly what you want.
That distinction has practical consequences. A self-built image is smaller, has fewer services listening, and has no plugin whose defaults you have to audit. It also takes longer to reach a working state, and you own every integration bug. YAOF trades that time for a set of choices you did not make and now have to understand before you can safely change them.
The README's acknowledgement table credits ImmortalWrt, coolsnowwolf, Lienol and a long list of plugin authors, which is an honest picture of what the project is: an assembly of other people's work, configured and compiled for specific boards. That is a legitimate thing to be. It just means your upgrade path depends on those upstreams continuing to move.
Upgrades, maintenance and licence cost
The default branch is 25.12, and the last push was on 2026-09-04. Releases follow the OpenWrt point releases: 25.12.5 on 2026-07-10, 25.12.4 on 2026-05-14, and 25.12.3 on 2026-05-06. The cadence tracks upstream rather than being independent, so a new YAOF image generally means a new OpenWrt base.
Upgrading is where the preconfigured approach costs you. The README states that the built-in upgrade function works, but it does not document rollback, configuration migration across a base-version jump, or what happens to MosDNS rules and proxy subscriptions during an upgrade. Those are the things you would want documented before upgrading a router you depend on. Budget time to export your configuration and re-check the plugin settings afterward.
The licence is GPL-3.0, which governs redistribution and derivative works. The README's separate notice against commercial use sits alongside that licence, and the two are not the same kind of statement. If you intend to ship this firmware on hardware you sell, read the licence text and the notice together. This is not legal advice, and the repository does not resolve the question for you.
Editorial conclusion
Adopt YAOF if you own one of the four supported boards and want a working router with proxy and DNS plugins already in place. Skip it if you need Docker (the README points Docker users at 23.05), if your hardware is not on the list, or if you want a minimal image you assemble yourself. Before flashing, confirm the release tag matches your device, and read the README's note that MosDNS is used both for ad filtering and DNS routing, since that single decision shapes the whole DNS path.
Frequently asked questions
Which devices does the QiuSimons/YAOF build support?
The README names four targets: NanoPi R2C, R2S, R4S and x86. Each has its own GitHub Actions workflow, so images are built per device family rather than from one generic configuration.
Does the QiuSimons/YAOF firmware include Docker?
No. The README states that Docker is no longer integrated and tells Docker users to stay on 23.05. It also says that if you do use Docker you must first enable the "Docker - configuration - autostart" option and save the settings.
What is the default management address for a QiuSimons/YAOF router?
The README gives the default management address as 192.168.1.1, and states that the built-in upgrade function and the physical Reset button both work.
What should I do if the QiuSimons/YAOF router has a problem?
The README says to SSH into the device, type fuck and press Enter, wait for the machine to reboot, and then check whether the problem is gone. That is the documented first troubleshooting step.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/qiusimons-yaof)