>>> Updating repositories metadata...
Updating pfSense-core repository catalogue...
Fetching meta.conf: . done
Fetching data: . done
Processing entries: . done
pfSense-core repository update completed. 5 packages processed.
Updating pfSense repository catalogue...
Fetching meta.conf: . done
Fetching data: .......... done
Processing entries: .......... done
pfSense repository update completed. 766 packages processed.
All repositories are up to date.
>>> Setting vital flag on pfSense...done.
>>> Setting vital flag on pfSense-pkg-Nexus...done.
>>> Renaming current boot environment from default_20260325131527 to default_20260325131527_20260604183809...done.
>>> Cloning current boot environment default_20260325131527_20260604183809...done.
>>> Removing vital flag from php85...done.
>>> Fetching drm package...
The following packages will be fetched:

New packages to be FETCHED:
	drm-61-kmod: 6.1.128.1600011_8 (5 MiB: 100.00% of the 5 MiB to download)

Number of packages to be fetched: 1

The process will require 5 MiB more space.
5 MiB to be downloaded.
Fetching drm-61-kmod-6.1.128.1600011_8: .......... done
>>> Fetching if_pppoe package...
The following packages will be fetched:

New packages to be FETCHED:
	if_pppoe-kmod: 26.03.1.1600011 (48 KiB: 100.00% of the 48 KiB to download)

Number of packages to be fetched: 1

48 KiB to be downloaded.
Fetching if_pppoe-kmod-26.03.1.1600011: ... done
>>> Upgrading packages in cloned boot environment default_20260325131527...
Updating pfSense-core repository catalogue...
pfSense-core repository is up to date.
Updating pfSense repository catalogue...
pfSense repository is up to date.
All repositories are up to date.
Checking for upgrades (19 candidates): .......... done
Processing candidates (19 candidates): .......... done
The following 18 package(s) will be affected (of 0 checked):

Installed packages to be UPGRADED:
	curl: 8.17.0 -> 8.20.0 [pfSense]
	dnsmasq: 2.92_1,1 -> 2.92_2,1 [pfSense]
	expat: 2.7.3 -> 2.8.1 [pfSense]
	gettext-runtime: 0.26 -> 1.0 [pfSense]
	libnghttp2: 1.68.0 -> 1.69.0 [pfSense]
	pfSense: 26.03 -> 26.03.1 [pfSense]
	pfSense-base: 26.03 -> 26.03.1 [pfSense-core]
	pfSense-boot: 26.03 -> 26.03.1 [pfSense-core]
	pfSense-default-config: 26.03 -> 26.03.1 [pfSense]
	pfSense-kernel-pfSense: 26.03 -> 26.03.1 [pfSense-core]
	pfSense-pkg-Nexus: 26.03 -> 26.03.1 [pfSense]
	pfSense-pkg-WireGuard: 0.2.13_3 -> 0.2.13_4 [pfSense]
	pfSense-repoc: 20260508.234816 -> 20260520.151349 [pfSense]
	pfSense-system: 26.03 -> 26.03.1 [pfSense]
	php85-pfSense-module: 26.03 -> 26.03.1 [pfSense]
	python311: 3.11.14_1 -> 3.11.15_2 [pfSense]
	strongswan: 6.0.3_1 -> 6.0.6 [pfSense]
	unbound: 1.24.2_1 -> 1.25.1 [pfSense]

Number of packages to be upgraded: 18

The process will require 4 MiB more space.
297 MiB to be downloaded.
[ 1/18] Fetching unbound-1.25.1: .......... done
[ 2/18] Fetching pfSense-base-26.03.1: .......... done
[ 3/18] Fetching pfSense-pkg-WireGuard-0.2.13_4: ... done
[ 4/18] Fetching pfSense-system-26.03.1: .......... done
[ 5/18] Fetching libnghttp2-1.69.0: .......... done
[ 6/18] Fetching pfSense-default-config-26.03.1: . done
[ 7/18] Fetching dnsmasq-2.92_2,1: .......... done
[ 8/18] Fetching pfSense-26.03.1: . done
[ 9/18] Fetching pfSense-boot-26.03.1: .......... done
[10/18] Fetching pfSense-pkg-Nexus-26.03.1: .......... done
[11/18] Fetching python311-3.11.15_2: .......... done
[12/18] Fetching pfSense-kernel-pfSense-26.03.1: .......... done
[13/18] Fetching curl-8.20.0: .......... done
[14/18] Fetching gettext-runtime-1.0: .......... done
[15/18] Fetching pfSense-repoc-20260520.151349: .......... done
[16/18] Fetching strongswan-6.0.6: .......... done
[17/18] Fetching php85-pfSense-module-26.03.1: ... done
[18/18] Fetching expat-2.8.1: ....... done
Checking integrity... done (0 conflicting)
[ 1/18] Upgrading expat from 2.7.3 to 2.8.1...
[ 1/18] Extracting expat-2.8.1: .......... done
[ 2/18] Upgrading gettext-runtime from 0.26 to 1.0...
[ 2/18] Extracting gettext-runtime-1.0: .......... done
[ 3/18] Upgrading dnsmasq from 2.92_1,1 to 2.92_2,1...
[ 3/18] Extracting dnsmasq-2.92_2,1: .......... done
[ 4/18] Upgrading libnghttp2 from 1.68.0 to 1.69.0...
[ 4/18] Extracting libnghttp2-1.69.0: .......... done
[ 5/18] Upgrading curl from 8.17.0 to 8.20.0...
[ 5/18] Extracting curl-8.20.0: .......... done
[ 6/18] Upgrading pfSense-base from 26.03 to 26.03.1...
[ 6/18] Extracting pfSense-base-26.03.1: ... done
===> Keeping a copy of current version mtree
===> Removing schg flag from base files
===> Extracting new base tarball
===> Removing static obsoleted files
[ 7/18] Upgrading pfSense-boot from 26.03 to 26.03.1...
[ 7/18] Extracting pfSense-boot-26.03.1: .......... done
[ 8/18] Upgrading pfSense-default-config from 26.03 to 26.03.1...
[ 8/18] Extracting pfSense-default-config-26.03.1: .... done
[ 9/18] Upgrading pfSense-kernel-pfSense from 26.03 to 26.03.1...
[ 9/18] Extracting pfSense-kernel-pfSense-26.03.1: .......... done
[10/18] Upgrading pfSense-pkg-Nexus from 26.03 to 26.03.1...
[10/18] Extracting pfSense-pkg-Nexus-26.03.1: .......... done
[11/18] Upgrading pfSense-pkg-WireGuard from 0.2.13_3 to 0.2.13_4...
[11/18] Extracting pfSense-pkg-WireGuard-0.2.13_4: .......... done
[12/18] Upgrading pfSense-repoc from 20260508.234816 to 20260520.151349...
[12/18] Extracting pfSense-repoc-20260520.151349: .. done
[13/18] Upgrading python311 from 3.11.14_1 to 3.11.15_2...
[13/18] Extracting python311-3.11.15_2: .......... done
[14/18] Upgrading unbound from 1.24.2_1 to 1.25.1...
===> Creating groups
Using existing group 'unbound'
===> Creating users
Using existing user 'unbound'
[14/18] Extracting unbound-1.25.1: .......... done
[15/18] Upgrading strongswan from 6.0.3_1 to 6.0.6...
[15/18] Extracting strongswan-6.0.6: .......... done
[16/18] Upgrading php85-pfSense-module from 26.03 to 26.03.1...
[16/18] Extracting php85-pfSense-module-26.03.1: ....... done
[17/18] Upgrading pfSense-system from 26.03 to 26.03.1...
[17/18] Extracting pfSense-system-26.03.1: .......... done
[18/18] Upgrading pfSense from 26.03 to 26.03.1...
[18/18] Extracting pfSense-26.03.1: ....... done
=====
Message from dnsmasq-2.92_2,1:

--
To enable dnsmasq, edit /usr/local/etc/dnsmasq.conf and
set dnsmasq_enable="YES" in /etc/rc.conf[.local]

Further options and actions are documented inside
/usr/local/etc/rc.d/dnsmasq


NOTE: when using dnssec, inaccurate system clocks
can cause DNS resolution to fail
because DNSSEC signatures may then not validate.


SECURITY RECOMMENDATION
~~~~~~~~~~~~~~~~~~~~~~~
It is recommended to enable the wpad-related options
at the end of the configuration file (you may need to
copy them from the example file to yours) to fix
CERT Vulnerability VU#598349.
=====
Message from strongswan-6.0.6:

--
The default strongSwan configuration interface have been updated to vici.
To use the stroke interface by default either compile the port without the vici option or
set 'strongswan_interface="stroke"' in your rc.conf file.
>>> Removing unnecessary packages...done.
>>> Cleanup pkg cache...done.
>>> Deferring package installation scripts...done.
>>> Upgrading boot code...
System Configuration

Architecture: amd64
Boot Devices: /dev/ada0
 Boot Method: uefi
  Filesystem: zfs
    Platform: VirtualBox Virtual Machine


Updating boot code...

/usr/local/sbin/../libexec/install-boot.sh -b auto -d /tmp/be_mount.wRqK -f zfs -s gpt -u ada0
gpart bootcode -b /tmp/be_mount.wRqK/boot/pmbr -p /tmp/be_mount.wRqK/boot/gptzfsboot -i 2 ada0
partcode written to ada0p2
bootcode written to ada0
ESP /dev/ada0p1 mounted on /tmp/stand-test.lyhGdh
263440KB space remaining on ESP: renaming old bootx64.efi file /efi/boot/bootx64.efi /efi/boot/bootx64-old.efi
263440KB space remaining on ESP: renaming old loader.efi file /etc/freebsd/loader.efi /etc/freebsd/loader-old.efi
Copying loader.efi to /EFI/freebsd on ESP
Existing UEFI FreeBSD boot entry found: not creating a new one
Copying bootx64.efi to /efi/boot on ESP
Unmounting and cleaning up temporary mount point
Finished updating ESP

Done.
>>> Copying upgrade log...