@muswellhillbilly:
It's best to remove any installed packages before upgrading and re-install afterwards.
https://doc.pfsense.org/index.php/Upgrade_Guide
One suggestion would be to build a separate, upgraded machine, restore your base config to that (without packages). Then install and configure Bind and pfBlocker and swap the machines over when you have a moment of agreed downtime.
Thank you for the link. I seemed to miss that bit. In the past the auto-upgrade 'just worked' and I wrongly assumed that'd be the case here given the upgrade was a low risk.
@dotdash:
Go to diagnostics, backup/restore and clear the package lock. Then go to system, packages and re-install any broken packages.
This worked! Thank you.