[Bug 291562] freebsd-update: 14.3-15.0 ipfw incompatibility disaster for remote system with no console access

From: <bugzilla-noreply_at_freebsd.org>
Date: Fri, 24 Apr 2026 07:52:33 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=291562

--- Comment #19 from vova@zote.me ---
Even updated 14.4 jail with vnet+ipfw - does not work:

# cbsd jrestart ns3
Stopping jail: ns3, parallel timeout=5
...
add net ::0.0.0.0: gateway ::1
ipfw: setsockopt(IP_FW_XDEL): Invalid argument
ipfw: getsockopt(IP_FW_XADD): Invalid argument
ipfw: getsockopt(IP_FW_XADD): Invalid argument
ipfw: getsockopt(IP_FW_XADD): Invalid argument
ipfw: getsockopt(IP_FW_XADD): Invalid argument
ipfw: getsockopt(IP_FW_XADD): Invalid argument
ipfw: getsockopt(IP_FW_XADD): Invalid argument
ipfw: getsockopt(IP_FW_XADD): Invalid argument
ipfw: getsockopt(IP_FW_XADD): Invalid argument
ipfw: getsockopt(IP_FW_XADD): Invalid argument
ipfw: getsockopt(IP_FW_XADD): Invalid argument
ipfw: getsockopt(IP_FW_XADD): Invalid argument
Firewall rules loaded.
```

in jail:
```
ns3# freebsd-version
14.4-RELEASE-p2
ns3# uname -UK
1404000 1404000
ns3# strings /sbin/ipfw | grep ipfw15
/sbin/ipfw15
ns3# freebsd-update IDS | fgrep -v /etc/ | fgrep -v /root/
src component not installed, skipped
Looking up update.FreeBSD.org mirrors... 3 mirrors found.
Fetching metadata signature for 14.4-RELEASE from update2.freebsd.org... done.
Fetching metadata index... done.
Inspecting system... done.
ns3#
```

in host:
```
# uname -UK
1500068 1500068
# freebsd-version
15.0-RELEASE-p6
```
```

-- 
You are receiving this mail because:
You are the assignee for the bug.