mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
Every fresh pfSense install is on FreeBSD 16 (CE 2.9.0, Plus 26.x), but CI built only the FreeBSD:15:amd64 package for CE 2.8.1, because the workflow's VM is FreeBSD 15.1 and FreeBSD 16 has no release image. The plan had been a builder on a 16.0-CURRENT snapshot. That runs FreeBSD's binary compatibility in the direction it does not promise: a snapshot is months newer than any Netgate base, and Netgate's kernels are the ones the package runs on. Package the 15.1 build twice instead. The pfsense job now runs build-pkg.sh --no-build --abi FreeBSD:16:amd64 after the ordinary build, checks both packages, install-smokes the FreeBSD 15 one (pkg refuses the 16 label on a 15 host; the binaries are the same bytes) and uploads both with their checksums in the existing artifact. Older static binaries on a newer kernel is the direction FreeBSD supports, and the relabelled package has been run on pfSense Plus 26.03.1 (osreldate 1600011) and 26.07 (1600018), Netgate's kernels, through the install smoke test, TUN, DNS through unbound, the package reload path, a reboot, teardown and removal; the README's test record has the details. The READMEs and the build script's comment now state the compatibility direction rather than "the syscall ABI is stable within a major", say that CE 2.8.1 can no longer be installed so its package is upgrade-only, and record what was measured. The relabel holds as long as the code builds on 15.1 without needing something only 16 provides; if that changes, a FreeBSD 16 build host is needed again. Closes #157.