SG2100 stuck on update or package install
-
Hi
as our SG3100 went out of stock we switched over to SG2100 (with V22.05.1). Today I received my first two, set up the first and got stuck while installing (or trying to) [in webGUI] a few packages like arping. It tells me that another installation is already running. The uninstall of the unwanted default AWS and IPsec Assistent went without any failure.
I ckecked the updates and was astonished to see only 23.05 offered and not older versions [only "Current stable" is available) so there was no switching back and forth to repair small hitches. While I planned to stay at V22.x until we got a update for all our devices. After a bit of trying and finding a solution I decided to try 23.05 and got stuck on another error: hardware not detectable via CLI option 13.
I tried reseting my box in case my few changes already defected the box but to no avail.
I attached pics of the errors to give a picture of what I'm facing
Any hint?
Cheers
Michael -
@michael_samer the bad news is, if you tried installing packages for an older version it may have tried to upgrade PHP or other OS libraries/packages. In the future upgrade pfSense first, or set the branch to Previous Stable and make sure you’re on that version.(would have been 23.01)
The message about hardware detection sounds like it can’t ID it and thus may be blocking access to the Netgate hardware repo?
The fastest solution may be to reinstall: https://docs.netgate.com/pfsense/en/latest/solutions/netgate-2100/reinstall-pfsense.html. Then you have a clean OS.
-
Hi Steve
as You can see on the fourth picture: there are no other Versions offered and any install stopped with the PHP Information.I'll reinstall that one, but I'm stuck on V22.x or older. As I tried another: there seems a problem a the basic install: no packages without update.
Today I took another SG2100 brand new and tried the Version selection (which is still V23.05 only = latest stable just as in the picture above) first, after stopping the assistent on step 0. No pre Versions.
The pkg installer then reminds me to update the OS first as PHP ...
That's a broken toolchain, isn't it?As I need certain package add ons (shellcmd to be named first) and limited to our versions (V22.05 is the latest so far) it seems I'm stuck between a rock and a hard place....
Cheers
Michael -
@michael_samer ok had more coffee
22 should only allow you to get to 23.01: https://docs.netgate.com/pfsense/en/latest/releases/23-05.html#upgrade-paths
Not sure how it’s offering 23.05.
The PHP warning was added at some point to help prevent people from shooting themselves in the foot, per my sig. there’s a Redmine case I can’t find quickly but basically the package list is tied to the selected update branch not the installed version.
You could try this (the command line since your GUI is not showing other versions): https://docs.netgate.com/pfsense/en/latest/troubleshooting/upgrades.html#upgrade-not-offered-library-errors
-
Hi STeve
the OS gets its info (and limitation I guess) by the new update available feature. Since the router was "allowed on the internet" there's no moving back it seems.
I'll try your patch asap and report back.While the PHP capture is surely worth its intention the updat checker is ruining something there (as mentioned blank new box, but with INet connection).
Cheers
-
Unluckily my post is detected as SPAM (as I'm a new user since 13 years....)
-
@michael_samer The Previous choice is supposed to be visible for those who haven’t upgraded yet but there is no way to downgrade pfSense without reinstalling. It is supposed to have shown you 23.01 as Current though. Definitely an odd situation especially on two of them.
Can always reinstall to start over. It sounds more complicated than it is. On the Arm devices the “install” just copies the image to the drive as I understand it. And Netgate TAC usually responds with the image quickly.
-
@SteveITS Hi
I'm aware of how pfsense upgrade works and it's limits. So far this second box ist still 22.05.1 as all my (about 10 pieces) boxes are.
As the second is unboxed, started and tried to install the package there's no big help in reinstalling it and get the same situation as soon as I allow Inet to propose the possible update and being stuck again.
Do you think it helps to stay local and then set the "previous version" or deprecated or whatever and then allow Inet? -
@michael_samer 22.05.1 was an interstitial build that was to cover a few hardware changes on the 2100 at the point of manufacturing.
I would recommend opening a ticket to get 23.01 image if you want to do a ZFS update process or 23.05.1 for the current release and go from there. https://go.netgate.com
-
@rcoleman-netgate Hi
OK that would explain why we haven't experienced that problem with our first test issue (~10.2022) which went without any issue.As mentioned I need 22.x as 23. is not allowed in my (military) site so far. But I got an old Image of V21.02p1.gz at hand.
Will the problem resurface with the older version as pfsense often fuzzes so far when I want a surgical update (e.g. "update to V22.05") instead of whole steps. V22.x seems from the three steps (deprecated-previous-latest) already deprecated. -
@michael_samer said in SG2100 stuck on update or package install:
I'm aware of how pfsense upgrade works and its limits. So far this second box ist still 22.05.1 as all my (about 10 pieces) boxes are.
Ah, apologies, I misunderstood then. Threads tend to mix together after a while. :)
-
@michael_samer said in SG2100 stuck on update or package install:
As mentioned I need 22.x as 23. is not allowed in my (military) site so far. But I got an old Image of V21.02p1.gz at hand.
You will have issues with this newer hardware revision and any releases prior to 22.05.1 -- but we can definitely re-send 22.05.1 to you for your system to see if reinstallation will resolve the repo access issue you're experiencing.
-
@rcoleman-netgate Hi Ryan
that Might help, but as mentioned: I've ten of this boxes with the same OS version (according to the box label), so plenty to tryout. I'd help anyway as I cannot unwrap all boxes just to find a way through the "minefiled".
As I've already defected two boxes by switching them on (and allowed the box to look into the repo) it'd help to minimize the impact. Usually I'd send them back to our dealer (Voleatech or esbyte in germany) and have them solve the problem, but the problem still stays the same no matter if I solve it or the dealer after some haggling around who's to blame.
The first box must be reinstalled as the repo and OS detection isn't working anymore. I'd prove my value by doing this :-) -
@michael_samer as we have no TAC contract our usual way would be to call the distributor and have them issue a TAC call and they transfer the image to me/us. That usually took a few days. Not critical so far, but not fast either.
Have you other ways? -
A TAC subscription is not needed to get images.
-
@rcoleman-netgate I created a call (1746519090) for 22.05.1; I'll see
-
Here's the log of the updater install:
[22.05.1-RELEASE][root@pfSense.home.arpa]/root: pkg-static info -x pfSense-upgrade
pfSense-upgrade-1.0_31
[22.05.1-RELEASE][root@pfSense.home.arpa]/root:[22.05.1-RELEASE][root@pfSense.home.arpa]/root: pkg-static clean -ay; pkg-static install -fy pkg pfSense-repo pfSense-upgrade
The following package files will be deleted:
/var/cache/pkg/pkg-1.19.1_1.pkg
/var/cache/pkg/pkg-1.19.1_1~0ecbdcaaa6.pkg
The cleanup will free 8 MiB
Deleting files: 100%
All done
Updating pfSense-core repository catalogue...
pfSense-core repository is up to date.
Updating pfSense repository catalogue...
pfSense repository is up to date.
All repositories are up to date.
The following 7 package(s) will be affected (of 0 checked):New packages to be INSTALLED:
pfSense-repoc: 20230605 [pfSense]Installed packages to be UPGRADED:
libucl: 0.8.1 -> 0.8.2 [pfSense]
pfSense-repo: 22.05_13 -> 23.05 [pfSense]
pfSense-upgrade: 1.0_31 -> 1.0_68 [pfSense]Installed packages to be REINSTALLED:
netgate-ping-auth-20221121 [pfSense] (ABI changed: 'freebsd:12:aarch64:64' -> 'freebsd:14:aarch64:64')
pkg-1.19.1_1 [pfSense]
uclcmd-0.1_3 [pfSense] (ABI changed: 'freebsd:12:aarch64:64' -> 'freebsd:14:aarch64:64')Number of packages to be installed: 1
Number of packages to be upgraded: 3
Number of packages to be reinstalled: 3The process will require 17 MiB more space.
13 MiB to be downloaded.
[1/7] Fetching uclcmd-0.1_3.pkg: 100% 17 KiB 16.9kB/s 00:01
[2/7] Fetching netgate-ping-auth-20221121.pkg: 100% 10 KiB 10.1kB/s 00:01
[3/7] Fetching pfSense-repo-23.05.pkg: 100% 6 KiB 6.0kB/s 00:01
[4/7] Fetching pkg-1.19.1_1.pkg: 100% 8 MiB 1.7MB/s 00:05
[5/7] Fetching pfSense-upgrade-1.0_68.pkg: 100% 20 KiB 20.3kB/s 00:01
[6/7] Fetching pfSense-repoc-20230605.pkg: 100% 5 MiB 1.2MB/s 00:04
[7/7] Fetching libucl-0.8.2.pkg: 100% 110 KiB 112.7kB/s 00:01
Checking integrity... done (0 conflicting)
[1/7] Upgrading libucl from 0.8.1 to 0.8.2...
[1/7] Extracting libucl-0.8.2: 100%
[2/7] Reinstalling netgate-ping-auth-20221121...
[2/7] Extracting netgate-ping-auth-20221121: 100%
[3/7] Installing pfSense-repoc-20230605...
[3/7] Extracting pfSense-repoc-20230605: 100%
[4/7] Reinstalling uclcmd-0.1_3...
[4/7] Extracting uclcmd-0.1_3: 100%
[5/7] Upgrading pfSense-repo from 22.05_13 to 23.05...
[5/7] Extracting pfSense-repo-23.05: 100%
[6/7] Reinstalling pkg-1.19.1_1...
[6/7] Extracting pkg-1.19.1_1: 100%
[7/7] Upgrading pfSense-upgrade from 1.0_31 to 1.0_68...
[7/7] Extracting pfSense-upgrade-1.0_68: 100%
You may need to manually remove /usr/local/etc/pkg.conf if it is no longer needed. -
And here the fixed repo in the webgui
-
I received an 22.05 Image and this does not install on my device and ends up in an endless loop with main error of "Thoth not found and aborting" whatever this is.
I already triggered to get hands on the 22.05.1 Image to try this one. -
@SteveITS said in SG2100 stuck on update or package install:
22 should only allow you to get to 23.01: https://docs.netgate.com/pfsense/en/latest/releases/23-05.html#upgrade-paths
Not sure how it’s offering 23.05.
22.05.1 is a special case because it already has the dynamic repo components. It should be able to upgrade to 23.05/1 directly.
The logs you have there show it pulling in the correct versions of pfSense-upgrade and pfSense-repoc. Does it still show the same errors if you attempt to upgrade to 23.05 after that?
Steve