• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Problem after upgrading to 24.11-RC

Scheduled Pinned Locked Moved General pfSense Questions
44 Posts 6 Posters 6.1k Views 5 Watching
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M Offline
    m.d.frederiksen @stephenw10
    last edited by Nov 16, 2024, 4:15 PM

    @stephenw10

    So far all roads lead to Rome .. My best end case scenario is on 24.11-RC with all packages installed and functional (as far as I can determine), but with the "artifact" present.

    I would like to try a CLEAN install of 24.11-RC from an USB-device, such that I can eliminate the first update-round up to 24.11-RC .. This would eliminate any "spill over" from the older 24.03-STABLE (only ISO I have).

    Could you possibly provide a "newest" ISO ?

    A M 2 Replies Last reply Nov 16, 2024, 4:19 PM Reply Quote 0
    • A Offline
      Antibiotic @m.d.frederiksen
      last edited by Antibiotic Nov 16, 2024, 4:22 PM Nov 16, 2024, 4:19 PM

      @m-d-frederiksen
      Could you possibly provide a "newest" ISO ?
      netgate-installer-v1.0-RC-amd64-20240919-1435.img

      https://docs.netgate.com/pfsense/en/latest/install/download-installer-image.html

      pfSense plus 24.11 on Topton mini PC
      CPU: Intel N100
      NIC: Intel i-226v 4 pcs
      RAM : 16 GB DDR5
      Disk: 128 GB NVMe
      Brgds, Archi

      1 Reply Last reply Reply Quote 1
      • M Offline
        m.d.frederiksen @m.d.frederiksen
        last edited by m.d.frederiksen Nov 16, 2024, 5:46 PM Nov 16, 2024, 5:45 PM

        @stephenw10

        Using netgate-installer-v1.0-RC-amd64-20240919-1435.img (Thanks @Antibiotic), - I end up exactly same place .. Everything working as expected (AFAIK), but "artifact" is still present.

        Either my fairly new NetGate 4200 is developing a very local problem, or some issue exists in the XML-file exported by the version prior the new 24.11-RC

        Or my combo of packages trigger some very hidden bug, when the combo includes pfBlockerNG and Zeke .. And once the bug was triggered, and fixed (by removing Zeke and pfBlockerNG), NO other package may be installed, or the bug will return, even if Zeke and pfBlockerNG remains un-installed .. Wierd science.

        This will take a better man than me. I will ignore the issue until another update release tempts me :-)

        1 Reply Last reply Reply Quote 0
        • S Offline
          stephenw10 Netgate Administrator
          last edited by Nov 16, 2024, 5:56 PM

          About the only thing I could imagine being an issue in the config is the pkg branch setting.

          However in the new dynamic repo system the firewall cannot pull in older pkgs. The reo tree presented to 24.11-RC systems does not have the older branches available.

          And when we checked your pkgs they all looked like the correct versions... 🤔

          M 2 Replies Last reply Nov 16, 2024, 5:59 PM Reply Quote 0
          • M Offline
            m.d.frederiksen @stephenw10
            last edited by Nov 16, 2024, 5:59 PM

            @stephenw10

            Remote access for your tech staff is offered (again).

            I am pretty positive one of the devs (wizards) could trace into the failing "pkg info" command, and tell us whats up in 90 seconds flat :-)

            In any case .. I am stuck as of now.

            S 1 Reply Last reply Nov 16, 2024, 6:22 PM Reply Quote 0
            • M Offline
              m.d.frederiksen @stephenw10
              last edited by m.d.frederiksen Nov 16, 2024, 6:21 PM Nov 16, 2024, 6:19 PM

              @stephenw10

              A thought has struck me ..

              Remember at the beginning of this thread, that I tested the offending command without the "2>&1" redirect,
              and it complets with NO errors, and correctly generates the expected list directly to the console ..

              But it fails when the redirect is present ..

              Suppose this problem is not sourcing the list, but rather that target denies "entry" ?
              A priviledge-issue, insufficient rights to some ressource (the redirect target) ?

              Tried this in CLI:

              pkg clean -y
              pkg upgrade -f

              No change .. :-)

              S 1 Reply Last reply Nov 16, 2024, 6:25 PM Reply Quote 0
              • S Offline
                stephenw10 Netgate Administrator @m.d.frederiksen
                last edited by Nov 16, 2024, 6:22 PM

                @m-d-frederiksen said in Problem after upgrading to 24.11-RC:

                Remote access for your tech staff is offered (again).

                Yes, thank you. I believe they plan to do so on Monday if you're able to do that.

                M 1 Reply Last reply Nov 16, 2024, 6:25 PM Reply Quote 0
                • M Offline
                  m.d.frederiksen @stephenw10
                  last edited by Nov 16, 2024, 6:25 PM

                  @stephenw10

                  BRILLIANT !

                  Please instruct me on what environment you need / expect ?

                  Do you need a workstation running specific host-software on LAN, .. and so on.

                  Thanks in advance.

                  C 1 Reply Last reply Nov 18, 2024, 3:35 PM Reply Quote 0
                  • S Offline
                    stephenw10 Netgate Administrator @m.d.frederiksen
                    last edited by Nov 16, 2024, 6:25 PM

                    @m-d-frederiksen said in Problem after upgrading to 24.11-RC:

                    Suppose this problem is not sourcing the list, but rather that target denies "entry" ?
                    A priviledge-issue, insufficient rights to some ressource (the redirect target) ?

                    Are you not logged in as admin/root when you tried this?

                    The redirect is not expected to work at the CLI directly but it should work fine when called by repoc.

                    M 1 Reply Last reply Nov 16, 2024, 6:32 PM Reply Quote 0
                    • M Offline
                      m.d.frederiksen @stephenw10
                      last edited by m.d.frederiksen Nov 16, 2024, 6:41 PM Nov 16, 2024, 6:32 PM

                      @stephenw10

                      Yes, in my simple attempt to fathom the issue, I claim that the "2>&1" is the part that is the culprit.
                      The recieving end is unable to parse the generated list.
                      The same list that looks perfectly valid when NOT redirected, - in the console.

                      And yes, I am root ..

                      pfSense 24.03_root.jpg

                      M 1 Reply Last reply Nov 16, 2024, 8:14 PM Reply Quote 0
                      • M Offline
                        m.d.frederiksen @m.d.frederiksen
                        last edited by Nov 16, 2024, 8:14 PM

                        UPDATE:

                        Zeek has left the equation .. apparently felt the heat.
                        Now pfBlockerNG alone is keeping up the shenanigans.

                        D 1 Reply Last reply Nov 30, 2024, 8:26 PM Reply Quote 1
                        • C Offline
                          cmcdonald Netgate Developer @m.d.frederiksen
                          last edited by Nov 18, 2024, 3:35 PM

                          @m-d-frederiksen send me an email cmcdonald<at>netgate.com so we can setup a remote access session. Thanks

                          Need help fast? https://www.netgate.com/support

                          M 1 Reply Last reply Nov 18, 2024, 3:43 PM Reply Quote 2
                          • M Offline
                            m.d.frederiksen @cmcdonald
                            last edited by m.d.frederiksen Nov 18, 2024, 4:19 PM Nov 18, 2024, 3:43 PM

                            @cmcdonald

                            Mail has been sent. Thank you.

                            C 1 Reply Last reply Nov 20, 2024, 7:25 PM Reply Quote 0
                            • C Offline
                              cmcdonald Netgate Developer @m.d.frederiksen
                              last edited by Nov 20, 2024, 7:25 PM

                              We've worked it out, root cause identified and a fix proposed. Unsure yet how this will impact the 24.11-RELEASE.

                              If you are impacted by this, make sure to uninstall any packages that you are not actively using.

                              Need help fast? https://www.netgate.com/support

                              C 1 Reply Last reply Nov 21, 2024, 5:40 PM Reply Quote 2
                              • C Offline
                                cmcdonald Netgate Developer @cmcdonald
                                last edited by Nov 21, 2024, 5:40 PM

                                The fix will land in 24.11 after all :)

                                Need help fast? https://www.netgate.com/support

                                1 Reply Last reply Reply Quote 3
                                • D Offline
                                  Draco @m.d.frederiksen
                                  last edited by Nov 30, 2024, 8:26 PM

                                  @m-d-frederiksen Thank you for preserving and helping Netgate track this bug down. You've helped make pfSense better for all of us!!

                                  1 Reply Last reply Reply Quote 1
                                  • W Offline
                                    williamrolison
                                    last edited by Dec 6, 2024, 6:14 PM

                                    I hit this with 24.11 final build.

                                    Everything seemed to go fine until the reboot. 1.5 hours later system still offline. Had to power cycle to get back up then saw upgrade didn't happen.

                                    Ended up having to remove 4 packages before update would work:

                                    pfBlockerNG
                                    WireGuard
                                    Zeek
                                    Ntopng

                                    1 Reply Last reply Reply Quote 0
                                    • S Offline
                                      stephenw10 Netgate Administrator
                                      last edited by Dec 6, 2024, 8:45 PM

                                      Hmm, it still failed with that same pkg error from repoc?

                                      W 1 Reply Last reply Dec 6, 2024, 9:06 PM Reply Quote 0
                                      • W Offline
                                        williamrolison @stephenw10
                                        last edited by Dec 6, 2024, 9:06 PM

                                        I'm afraid so, but at least this post was first hit on Google so if others hit, it's easy enough to fix / workaround.

                                        Those packages I listed need updates anyway it seems, as they all give PHP errors too.

                                        I noticed they all had updates prior to the 24.11 upgrade. Meant to mention I tried that first, updating all packages, rebooting, then trying the upgrade, but same issue. It only worked after I uninstalled all four packages. Hell Ntopng was not working at all anymore, no error but the site on port 3000 never loaded, but that is a project for another day.

                                        M 1 Reply Last reply Dec 6, 2024, 9:47 PM Reply Quote 0
                                        • M Offline
                                          m.d.frederiksen @williamrolison
                                          last edited by Dec 6, 2024, 9:47 PM

                                          @williamrolison

                                          I had this issue too at one point.

                                          I finally ended up making a LAN-firewall-rule for port 3000 (HBCI) and the specific destination (this firewall), and an alias as Source. The alias holds the machines I want to allow access ..

                                          Hope it helps 🥺

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received