Upgrade Guide: 5.8 to 5.9
[FAQ Index] | [5.7 -> 5.8] [5.9 -> 6.0]
Note: Upgrades are only supported from one release to the release immediately following it.Boot from the install kernel, bsd.rd. This can be done by booting from an install CD, or other bootable install media. Alternatively, you can place the 5.9 version ofIt is highly recommended that you read through and fully understand this process before attempting it. Especially for critical or physically remote machines, it is recommended that you test it on an identical, local system first.
bsd.rd in the root of
your file system and instruct the boot loader to boot this kernel instead
of your usual kernel -- on amd64 and i386:
boot> boot bsd.rd
Once this kernel is booted, choose the (U)pgrade option and follow the
prompts.
The upgrade process retains all your configuration info.
If you absolutely have to, you can follow the
manual upgrade process instead.
Final steps:
-
Run sysmerge(8)
as root:
# sysmergeThe sysmerge(8) utility will compare the files that are currently on your system with those that would be installed in a fresh install. It will assist you in merging the changes into your system, using sdiff(1).
The section on configuration changes lists some important cases that need extra care.
-
Remove some files.
-
Upgrade your packages using
pkg_add(1):
# pkg_add -uIn many cases, that will be all you need to do. Check the section below to see if any of your installed packages require workarounds to upgrade.
Configuration changes
- ntpd.conf(5):
The
rtableoption was removed fromserverandservers. Users ofserver * rtable Xwill need to switch to launching ntpd with# route -T X exec /usr/sbin/ntpd - pf.conf(5):
set debugno longer accepts thenone,urgent,miscandloudarguments, which were deprecated several releases ago. Useemerg,alert,crit,err,warning,notice,infoordebuginstead. Change this before updating, or your pf.conf will not load. -
smtpd.conf(5):
The
pkikeyword no longer accepts acaparameter. Custom CA certificates must be declared using the newcakeyword:ca mail.example.org certificate "/etc/mail/CA.pem" - netstart(8):
Options
multicast_hostandmulticast_routerhave been merged into a singlemulticastoption. In order to enable multicast the following line should be added in rc.conf.local(8):
If you previously set these options to something other thanmulticast=YESYESor the interface carrying the default route, you will also need to add a static route for224.0.0.0/4. - tun(4):
This was previously a "dual mode" device.
By default it would act as a layer-3 "routed" device, but by use
of the
link0flag it would change to a layer-2 "ethernet" mode. This layer-2 mode has now been has been split off to a separate tap(4) device.For some use cases (e.g. ssh tunnel-forwarding run as a non-root user), permissions on the device nodes would have been modified; these should be applied to the new device nodes as necessary.
hostname.tun*files using thelink0flag should be moved tohostname.tap*instead, and the flag should be removed. Other configuration may need to be adjusted to use the new device name, for example for software like QEMU, OpenVPN or SIMH. Networking configuration (bridges, PF) referring to these devices may also need to change.
Files to delete
rm -f /usr/libexec/smtpd/makemap
# People requiring these backends should install the opensmtpd-extras main package.
rm -f /usr/libexec/smtpd/table-ldap
rm -f /usr/libexec/smtpd/table-passwd
rm -f /usr/libexec/smtpd/table-sqlite
rm -f /usr/share/man/man5/table_passwd.5
rm -f /usr/share/misc/termcap.db /usr/share/misc/terminfo.db
rm -f /usr/X11R6/include/intel_*.h
rm -f /usr/X11R6/include/r600_pci_ids.h
rm -f /usr/X11R6/include/radeon_*.h
rm -f /usr/include/malloc.h
rm -f /usr/libexec/auth/login_tis
rm -f /etc/rc.d/yppasswdd /usr/sbin/rpc.yppasswdd
cd /usr/X11R6/include/freetype2
rm -rf config
rm -f freetype.h ftadvanc.h ftbbox.h ftbdf.h ftbitmap.h ftbzip2.h \
ftcache.h ftcffdrv.h ftchapters.h ftcid.h fterrdef.h \
fterrors.h ftfntfmt.h ftgasp.h ftglyph.h ftgxval.h ftgzip.h \
ftimage.h ftincrem.h ftlcdfil.h ftlist.h ftlzw.h ftmac.h \
ftmm.h ftmodapi.h ftmoderr.h ftotval.h ftoutln.h ftpfr.h \
ftrender.h ftsizes.h ftsnames.h ftstroke.h ftsynth.h \
ftsystem.h fttrigon.h fttypes.h ftwinfnt.h t1tables.h \
ttnameid.h tttables.h tttags.h ttunpat.h
Special packages
- php-fpm:
To allow installing multiple versions of php-fpm on the same system,
the rc script has been renamed to include the version number.
Modify references to
php_fpmin/etc/rc.conf.localto e.g.php56_fpm. - gophernicus:
in.gophernicusmoved from/usr/local/sbin/to/usr/local/libexec. Update your/etc/inetd.confaccordingly. - puppetboard:
The default configuration file (
default_settings.py) format has changed and needs to be merged withdefault_settings.py.distbefore restarting thepuppetboardservice. - cfs:
The security/cfs port has been removed.
Users are encouraged to use another data encryption method.
Possible alternatives are:
softraid(4) crypto, encrypted vnd(4) devices or the security/encfs port.
Delete the package with
# pkg_delete cfs -
node modules:
All modules for lang/node have been removed in favor of directly using npm.
Native modules need to be built with
-std=gnu++0x, so npm internally setsCXX=eg++when building native modules. To remove any installed modules:for i in node-always node-async node-bcrypt node-bindings \ node-buffer-writer node-canvas node-cloned node-daemon \ node-expresso node-fibers node-generic-pool node-gir \ node-java node-mnm node-pg node-rmdir node-sqlite3 \ node-syslog node-typescript coffeescript; do pkg_delete $i done
Upgrade without the install kernel
This is NOT the recommended process. Use the install kernel method if at all possible!Sometimes, you need to do an upgrade of a machine for which the normal upgrade process is not possible. The most common case is a machine in a remote location and there is no easy access to the system console.
Preparation
- Place install files in a good location.
Make sure you have sufficient space!
Running out of space on a remote upgrade could be...unfortunate.
Note that using softdeps can exaggerate the situation as deleted and
overwritten files do not release their space immediately.
Consider disabling the
softdepmount option in/etc/fstaband rebooting before undertaking a manual upgrade. Having at least 200MB free on/usrwould be recommended. - Becoming root.
While using
doas(1)
before each command is generally a good practice, the command will likely
be broken by the last steps, so you should become root before starting
this process.
It might be good to verify your access to root using a method other than
doas at this point, i.e., direct login or using
su(1).
- Stop and/or disable any appropriate applications.
During this process, all the userland applications will be replaced but
may not be runnable, and strange things may happen as a result.
You may also have issues with DNS resolution during the first reboot, so
PF rules and NFS mounts dependent upon DNS may cause boot-up problems.
There may be other applications which you wish to keep from running
immediately after the upgrade, stop and disable them as well.
- Install new boot blocks.
This should actually be done at the end of any upgrade.
If this has been neglected, then failure to do this now may break serial
console or other things, depending on your platform.
Use
installboot(8),
assuming
sd0is your boot disk:installboot -v sd0
Upgrading manually
- Install new kernels.
The extra steps for copying over the primary kernel are done
to ensure that there is always a valid kernel on the disk.
If using the multiprocessor kernel:
If using the single processor kernel:cd /usr/rel # where you put the release files ln -f /bsd /obsd && cp bsd.mp /nbsd && mv /nbsd /bsd cp bsd.rd / cp bsd /bsd.spcd /usr/rel # where you put the release files ln -f /bsd /obsd && cp bsd /nbsd && mv /nbsd /bsd cp bsd.rd bsd.mp / # may give a harmless warning - Install new userland.
Save a copy of reboot(8), extract and install the release tarballs, reboot.
Install
base59.tgzlast, because the new base system, in particular tar(1) and reboot(8), will not work with the old kernel.cp /sbin/reboot /sbin/oreboot tar -C / -xzphf xserv59.tgz tar -C / -xzphf xfont59.tgz tar -C / -xzphf xshare59.tgz tar -C / -xzphf xbase59.tgz tar -C / -xzphf game59.tgz tar -C / -xzphf comp59.tgz tar -C / -xzphf man59.tgz tar -C / -xzphf base59.tgz # Install last! /sbin/oreboot - After reboot, upgrade
/dev. Run MAKEDEV(8):cd /dev ./MAKEDEV all - Upgrade boot loader.
Still assuming
sd0is your boot disk:installboot -v sd0 - Run sysmerge.
Now is a good time to do
sysmerge - Upgrade firmware.
There may be new firmware for your system.
Update it with
fw_update(1):
fw_update -v - Finish up.
Review the console output from boot (using
dmesg -s) and correct any failures as necessary. Proceed by removing some files -- don't forget/sbin/oreboot-- and upgrading packages.
[FAQ Index] | [5.7 -> 5.8] [5.9 -> 6.0]
$OpenBSD: upgrade59.html,v 1.36 2020/08/31 07:06:03 bentley Exp $