From 13c53785ad6bbb73fc550b354a65d07f1d26b8ce Mon Sep 17 00:00:00 2001 From: Johnathan Corgan Date: Wed, 30 Sep 2026 13:45:22 +0000 Subject: [PATCH] Correct the pfSense firmware-upgrade statement in the packaging docs packaging/README.md and the pfSense builder's header said a firmware upgrade removes the package, and the fips-dns-setup comment said the same of everything under /usr/local. pfSense-upgrade reinstalls only pfSense-pkg-* packages, and a live Plus 26.03.1 to 26.07 upgrade kept this one, as the pfSense README, the post-install banner and pkg-descr already say. A major base change still calls for the package built for the new base. --- packaging/README.md | 8 +++++--- packaging/pfsense/build-pkg.sh | 6 ++++-- packaging/pfsense/fips-dns-setup | 9 +++++---- 3 files changed, 14 insertions(+), 9 deletions(-) diff --git a/packaging/README.md b/packaging/README.md index ae948cae..a989409c 100644 --- a/packaging/README.md +++ b/packaging/README.md @@ -393,9 +393,11 @@ pkg add ./fips--pfsense-ce2.8-amd64.pkg /usr/local/libexec/fips/fips-dns-setup # edits config.xml; run deliberately ``` -Not a Netgate-supported package, and a pfSense firmware upgrade removes -it. See [pfsense/README.md](pfsense/README.md) for the "Allow IPv6" -prerequisite the mesh depends on, firewall-rule notes, and removal +Not a Netgate-supported package. A pfSense firmware upgrade keeps it (it +is a plain pkg, not a `pfSense-pkg-*`); after a major base change, +reinstall the package built for the new base. See +[pfsense/README.md](pfsense/README.md) for the "Allow IPv6" prerequisite +the mesh depends on, firewall-rule notes, and upgrade and removal behaviour. ### Windows (`.zip`) diff --git a/packaging/pfsense/build-pkg.sh b/packaging/pfsense/build-pkg.sh index 37efbbda..4840767e 100755 --- a/packaging/pfsense/build-pkg.sh +++ b/packaging/pfsense/build-pkg.sh @@ -24,8 +24,10 @@ # This package integrates through the DNS Resolver custom options. # - The responder's bind address, for the reason recorded in # fips.yaml.dns. -# - Lifetime. A pfSense firmware upgrade reinstalls the base image and -# takes third-party packages with it, so post-install says so. +# - Lifetime. A firmware upgrade keeps the package (pfSense-upgrade +# reinstalls only pfSense-pkg-* packages), but a major upgrade changes +# the FreeBSD base, so post-install says to reinstall the package +# built for the new base. # # Ships fips, fipsctl and fipstop. fips-gateway is excluded: its NAT # backend is nftables (Linux-only), and pfSense has pf for that anyway. diff --git a/packaging/pfsense/fips-dns-setup b/packaging/pfsense/fips-dns-setup index 41b33640..04ed4a42 100755 --- a/packaging/pfsense/fips-dns-setup +++ b/packaging/pfsense/fips-dns-setup @@ -13,10 +13,11 @@ # options" box, which unbound.inc splices into the generated config # verbatim. It is stored base64-encoded in config.xml, which is the part # that makes it the right home: config.xml is what survives a reboot, a -# firmware upgrade and a config restore, whereas everything this package -# installs under /usr/local does not. So the .fips zone keeps resolving -# across an upgrade that removes the daemon, which is a loud failure -# (SERVFAIL on .fips) rather than a quiet one. +# firmware upgrade and a config restore. What this package installs +# under /usr/local survives a firmware upgrade too (pfSense-upgrade +# reinstalls only pfSense-pkg-* packages), but not a removal of the +# package. So the .fips zone can outlive the daemon, which is a loud +# failure (SERVFAIL on .fips) rather than a quiet one. # # This edits the firewall's live configuration, so it is deliberately # NOT run from the package's post-install: installing a package should