Skip to content

Commit 1588b22

Browse files
committed
Add a known issue for DEB/RPM upgrades failing when Agent tamper protection is enabled
1 parent 9058bff commit 1588b22

File tree

1 file changed

+38
-4
lines changed

1 file changed

+38
-4
lines changed

release-notes/fleet-elastic-agent/known-issues.md

Lines changed: 38 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@ navigation_title: Known issues
33
---
44

55
# {{fleet}} and {{agent}} known issues [fleet-elastic-agent-known-issues]
6+
67
Known issues are significant defects or limitations that may impact your implementation. These issues are actively being worked on and will be addressed in a future release. Review the {{fleet}} and {{agent}} known issues to help you make informed decisions, such as upgrading to a new version.
78

89
% Use the following template to add entries to this page.
@@ -17,9 +18,42 @@ Known issues are significant defects or limitations that may impact your impleme
1718

1819
% :::
1920

21+
:::{dropdown} Manual DEB/RPM upgrades fail when Agent tamper protection is enabled
22+
23+
**Applies to**: {{agent}} 8.19.2, 9.1.2
24+
25+
On August 19, 2025, a known issue was discovered where manual DEB/RPM upgrades of {{agent}} fail if the Elastic Defend integration is installed and **Agent tamper protection** is enabled in the agent policy. When this occurs, the log contains an output similar to the following:
26+
27+
```
28+
Invalid uninstall token: exit status 28
29+
```
30+
31+
This issue only impacts manual DEB/RPM upgrades to {{agent}} 8.19.2 or 9.1.2. Managed upgrades performed through {{fleet}} are not affected.
32+
33+
For more information, refer to [PR #9462](https://github.com/elastic/elastic-agent/pull/9462).
34+
35+
**Workaround**
36+
37+
You can use one of the following workarounds to resolve the issue:
38+
39+
- Stop the `elastic-agent` service before the upgrade.
40+
41+
Before installing the {{agent}} DEB/RPM package, run `systemctl stop elastic-agent`, then proceed with the installation. This solution can be used even when reinstalling the same version of {{agent}}.
42+
43+
- Temporarily remove the Elastic Defend integration.
44+
45+
Before performing the upgrade, move the agent to an agent policy without the Elastic Defend integration. Wait for the change to take effect, proceed with the upgrade, then move the agent to its previous policy.
46+
47+
- Disable **Agent tamper protection**.
48+
49+
Before performing the upgrade, disable **Agent tamper protection** in the agent policy. Wait for the change to take effect, proceed with the upgrade, then move the agent back to its previous policy.
50+
51+
**Fixed in**: {{agent}} 8.19.3, 9.1.3
52+
:::
53+
2054
:::{dropdown} [Windows] {{agent}} does not process Windows security events
2155

22-
**Applies to: {{agent}} 8.19.0, 9.1.0 (Windows only)**
56+
**Applies to**: {{agent}} 8.19.0, 9.1.0 (Windows only)
2357

2458
On August 1, 2025, a known issue was discovered where {{agent}} does not process Windows security events on hosts running Windows 10, Windows 11, and Windows Server 2022.
2559

@@ -32,7 +66,7 @@ No workaround is available at the moment, but a fix is expected to be available
3266

3367
:::{dropdown} {{agents}} remain in an "Upgrade scheduled" state
3468

35-
**Applies to: {{agent}} 8.18.0, 8.18.1, 8.18.2, 8.18.3, 8.18.4, 8.19.0, 9.0.0, 9.0.1, 9.0.2, 9.0.3, 9.1.0**
69+
**Applies to**: {{agent}} 8.18.0, 8.18.1, 8.18.2, 8.18.3, 8.18.4, 8.19.0, 9.0.0, 9.0.1, 9.0.2, 9.0.3, 9.1.0
3670

3771
On July 2, 2025, a known issue was discovered where {{agent}} remains in an `Upgrade scheduled` state when a scheduled {{agent}} upgrade is cancelled. Attempting to restart the upgrade on the UI returns an error: `The selected agent is not upgradeable: agent is already being upgraded.`.
3872

@@ -65,7 +99,7 @@ curl --request POST \
6599

66100
:::{dropdown} [Windows] {{agent}} is unable to re-enroll into {{fleet}}
67101

68-
**Applies to: {{agent}} 9.0.0, 9.0.1, 9.0.2 (Windows only)**
102+
**Applies to**: {{agent}} 9.0.0, 9.0.1, 9.0.2 (Windows only)
69103

70104
On April 9, 2025, a known issue was discovered where an {{agent}} installed on Windows and previously enrolled into {{fleet}} is unable to re-enroll. Attempting to enroll the {{agent}} fails with the following error:
71105

@@ -91,7 +125,7 @@ Until a bug fix is available in a later release, you can resolve the issue tempo
91125

92126
:::{dropdown} [macOS] Osquery integration fails to start on fresh agent installs
93127

94-
**Applies to: {{agent}} 9.0.0 and 9.0.1 (macOS only)**
128+
**Applies to**: {{agent}} 9.0.0 and 9.0.1 (macOS only)
95129

96130
On May 26th, 2025, a known issue was discovered that causes the `osquery` integration to fail on new {{agent}} installations on macOS. During the installation process, the required `osquery.app/` directory is removed, which prevents the integration from starting.
97131

0 commit comments

Comments
 (0)