Correct the OpenWrt README's upgrade commands and default settings

The README told operators to upgrade with opkg install --force-reinstall.
opkg runs that as a removal followed by a fresh install, so the removal
disabled fips-gateway and the fresh install left it off. A plain opkg install
takes the upgrade path, which stops both services and starts the gateway
again only if it was enabled. The Upgrading section now says so for OpenWrt
24.10 and earlier, notes that the first upgrade from 0.5.1 or earlier
re-enables the gateway because those packages' prerm disabled it without
recording its state, and explains when --force-downgrade is needed.

OpenWrt 25 has no opkg, so neither opkg command runs there. The section now
opens with the apk add --allow-untrusted command that upgrades the .apk
package on OpenWrt 25 and later, and points to the .apk README.

The list of what the default config enables was also out of date. The
shipped config generates an ephemeral identity on each start unless
persistent is uncommented, the DNS responder binds [::1]:5354, UDP binds
[::]:2121, TCP listens on 0.0.0.0:8443, and the ethernet: section ships
uncommented, so the text now says to edit its interface names rather than
uncomment it.
This commit is contained in:
Johnathan Corgan
2026-09-26 20:41:13 +00:00
parent 72159a911d
commit 8b9b0ed5c1
+54 -10
View File
@@ -123,13 +123,18 @@ vi /etc/fips/fips.yaml
```
The default config enables:
- Persistent identity (key generated on first start, saved to `/etc/fips/fips.key`)
- TUN interface `fips0`
- DNS responder on `127.0.0.1:5354`
- UDP transport on `0.0.0.0:2121`
For Ethernet transport, uncomment the `ethernet:` section and set the correct
physical interface names for your router. **Always use physical port names
- An ephemeral identity, generated on each start. Uncomment
`node.identity.persistent: true` to keep one; the key is then saved next to
the config, as `/etc/fips/fips.key`.
- TUN interface `fips0`
- DNS responder on `[::1]:5354`
- UDP transport on `[::]:2121`
- TCP transport on `0.0.0.0:8443`
- Ethernet transport, including the `wan`, `wwan` and `lan` entries
For Ethernet transport, edit the interface names in the `ethernet:` section to
match your router. **Always use physical port names
(`eth0`, `eth1`, or DSA port names like `wan`/`lan1`), never bridge names
(`br-lan`).** The shipped default WAN port is `eth0` (OpenWrt 24); on OpenWrt
25 (DSA) boards the WAN port is named `wan` — the `.apk` package ships that
@@ -187,12 +192,51 @@ for the full subcommand list.
## Upgrading
Install the new `.ipk` over the existing one:
OpenWrt 25 and later have no opkg. Upgrade there with the `.apk` package,
using the same command that installs it:
```bash
opkg install --force-reinstall fips_<new-version>_<arch>.ipk
apk add --allow-untrusted /tmp/fips_<new-version>_<arch>.apk
```
The `.apk` package's upgrade scripts stop `fips` and `fips-gateway`, start
`fips` again, and start `fips-gateway` only if it was enabled; see
[`../openwrt-apk/README.md`](../openwrt-apk/README.md).
On OpenWrt 24.10 and earlier, install the new `.ipk` with a plain
`opkg install`:
```bash
opkg install /tmp/fips_<new-version>_<arch>.ipk
```
opkg runs this as an upgrade. The installed package's `prerm` stops `fips` and
`fips-gateway` without disabling them, and the new package's `postinst` starts
`fips` and starts `fips-gateway` again if it was enabled.
An upgrade from 0.5.1 or earlier is the exception. The `prerm` in those
packages disables `fips-gateway` and records nothing about whether it was
enabled, so the new `postinst` enables it again. If you had the gateway
disabled, disable it again after that first upgrade:
```bash
/etc/init.d/fips-gateway stop
/etc/init.d/fips-gateway disable
```
If opkg refuses because the new file's version sorts lower than the installed
one, as it can between development builds, add `--force-downgrade`. opkg then
takes the same upgrade path.
Do not use `--force-reinstall`. opkg runs it as a removal followed by a fresh
install, so `fips-gateway` ends up disabled. To turn it back on:
```bash
/etc/init.d/fips-gateway enable
/etc/init.d/fips-gateway start
```
The config in `/etc/fips/fips.yaml` and the identity key `/etc/fips/fips.key`
are preserved by `opkg` (the yaml is installed as a conffile; the key is not a
package file). Both survive `sysupgrade` via `/lib/upgrade/keep.d/fips`.
(when persistent identity is on) are preserved by `opkg` (the yaml is installed
as a conffile; the key is not a package file). Both survive `sysupgrade` via
`/lib/upgrade/keep.d/fips`.