Correct the pfSense firmware-upgrade statement in the packaging docs

packaging/README.md and the pfSense builder's header said a firmware
upgrade removes the package, and the fips-dns-setup comment said the
same of everything under /usr/local. pfSense-upgrade reinstalls only
pfSense-pkg-* packages, and a live Plus 26.03.1 to 26.07 upgrade kept
this one, as the pfSense README, the post-install banner and pkg-descr
already say. A major base change still calls for the package built for
the new base.
This commit is contained in:
Johnathan Corgan
2026-09-30 14:34:04 +00:00
parent 83cb0b49ce
commit 13c53785ad
3 changed files with 14 additions and 9 deletions
+5 -3
View File
@@ -393,9 +393,11 @@ pkg add ./fips-<version>-pfsense-ce2.8-amd64.pkg
/usr/local/libexec/fips/fips-dns-setup # edits config.xml; run deliberately
```
Not a Netgate-supported package, and a pfSense firmware upgrade removes
it. See [pfsense/README.md](pfsense/README.md) for the "Allow IPv6"
prerequisite the mesh depends on, firewall-rule notes, and removal
Not a Netgate-supported package. A pfSense firmware upgrade keeps it (it
is a plain pkg, not a `pfSense-pkg-*`); after a major base change,
reinstall the package built for the new base. See
[pfsense/README.md](pfsense/README.md) for the "Allow IPv6" prerequisite
the mesh depends on, firewall-rule notes, and upgrade and removal
behaviour.
### Windows (`.zip`)
+4 -2
View File
@@ -24,8 +24,10 @@
# This package integrates through the DNS Resolver custom options.
# - The responder's bind address, for the reason recorded in
# fips.yaml.dns.
# - Lifetime. A pfSense firmware upgrade reinstalls the base image and
# takes third-party packages with it, so post-install says so.
# - Lifetime. A firmware upgrade keeps the package (pfSense-upgrade
# reinstalls only pfSense-pkg-* packages), but a major upgrade changes
# the FreeBSD base, so post-install says to reinstall the package
# built for the new base.
#
# Ships fips, fipsctl and fipstop. fips-gateway is excluded: its NAT
# backend is nftables (Linux-only), and pfSense has pf for that anyway.
+5 -4
View File
@@ -13,10 +13,11 @@
# options" box, which unbound.inc splices into the generated config
# verbatim. It is stored base64-encoded in config.xml, which is the part
# that makes it the right home: config.xml is what survives a reboot, a
# firmware upgrade and a config restore, whereas everything this package
# installs under /usr/local does not. So the .fips zone keeps resolving
# across an upgrade that removes the daemon, which is a loud failure
# (SERVFAIL on .fips) rather than a quiet one.
# firmware upgrade and a config restore. What this package installs
# under /usr/local survives a firmware upgrade too (pfSense-upgrade
# reinstalls only pfSense-pkg-* packages), but not a removal of the
# package. So the .fips zone can outlive the daemon, which is a loud
# failure (SERVFAIL on .fips) rather than a quiet one.
#
# This edits the firewall's live configuration, so it is deliberately
# NOT run from the package's post-install: installing a package should