mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 11:08:25 +00:00
Correct the pfSense firmware-upgrade statement in the packaging docs
packaging/README.md and the pfSense builder's header said a firmware upgrade removes the package, and the fips-dns-setup comment said the same of everything under /usr/local. pfSense-upgrade reinstalls only pfSense-pkg-* packages, and a live Plus 26.03.1 to 26.07 upgrade kept this one, as the pfSense README, the post-install banner and pkg-descr already say. A major base change still calls for the package built for the new base.
This commit is contained in:
+5
-3
@@ -393,9 +393,11 @@ pkg add ./fips-<version>-pfsense-ce2.8-amd64.pkg
|
|||||||
/usr/local/libexec/fips/fips-dns-setup # edits config.xml; run deliberately
|
/usr/local/libexec/fips/fips-dns-setup # edits config.xml; run deliberately
|
||||||
```
|
```
|
||||||
|
|
||||||
Not a Netgate-supported package, and a pfSense firmware upgrade removes
|
Not a Netgate-supported package. A pfSense firmware upgrade keeps it (it
|
||||||
it. See [pfsense/README.md](pfsense/README.md) for the "Allow IPv6"
|
is a plain pkg, not a `pfSense-pkg-*`); after a major base change,
|
||||||
prerequisite the mesh depends on, firewall-rule notes, and removal
|
reinstall the package built for the new base. See
|
||||||
|
[pfsense/README.md](pfsense/README.md) for the "Allow IPv6" prerequisite
|
||||||
|
the mesh depends on, firewall-rule notes, and upgrade and removal
|
||||||
behaviour.
|
behaviour.
|
||||||
|
|
||||||
### Windows (`.zip`)
|
### Windows (`.zip`)
|
||||||
|
|||||||
@@ -24,8 +24,10 @@
|
|||||||
# This package integrates through the DNS Resolver custom options.
|
# This package integrates through the DNS Resolver custom options.
|
||||||
# - The responder's bind address, for the reason recorded in
|
# - The responder's bind address, for the reason recorded in
|
||||||
# fips.yaml.dns.
|
# fips.yaml.dns.
|
||||||
# - Lifetime. A pfSense firmware upgrade reinstalls the base image and
|
# - Lifetime. A firmware upgrade keeps the package (pfSense-upgrade
|
||||||
# takes third-party packages with it, so post-install says so.
|
# reinstalls only pfSense-pkg-* packages), but a major upgrade changes
|
||||||
|
# the FreeBSD base, so post-install says to reinstall the package
|
||||||
|
# built for the new base.
|
||||||
#
|
#
|
||||||
# Ships fips, fipsctl and fipstop. fips-gateway is excluded: its NAT
|
# Ships fips, fipsctl and fipstop. fips-gateway is excluded: its NAT
|
||||||
# backend is nftables (Linux-only), and pfSense has pf for that anyway.
|
# backend is nftables (Linux-only), and pfSense has pf for that anyway.
|
||||||
|
|||||||
@@ -13,10 +13,11 @@
|
|||||||
# options" box, which unbound.inc splices into the generated config
|
# options" box, which unbound.inc splices into the generated config
|
||||||
# verbatim. It is stored base64-encoded in config.xml, which is the part
|
# verbatim. It is stored base64-encoded in config.xml, which is the part
|
||||||
# that makes it the right home: config.xml is what survives a reboot, a
|
# that makes it the right home: config.xml is what survives a reboot, a
|
||||||
# firmware upgrade and a config restore, whereas everything this package
|
# firmware upgrade and a config restore. What this package installs
|
||||||
# installs under /usr/local does not. So the .fips zone keeps resolving
|
# under /usr/local survives a firmware upgrade too (pfSense-upgrade
|
||||||
# across an upgrade that removes the daemon, which is a loud failure
|
# reinstalls only pfSense-pkg-* packages), but not a removal of the
|
||||||
# (SERVFAIL on .fips) rather than a quiet one.
|
# package. So the .fips zone can outlive the daemon, which is a loud
|
||||||
|
# failure (SERVFAIL on .fips) rather than a quiet one.
|
||||||
#
|
#
|
||||||
# This edits the firewall's live configuration, so it is deliberately
|
# This edits the firewall's live configuration, so it is deliberately
|
||||||
# NOT run from the package's post-install: installing a package should
|
# NOT run from the package's post-install: installing a package should
|
||||||
|
|||||||
Reference in New Issue
Block a user