Hello Thomas, that's an interesting corner-case (performing an ISSU procedure and having unsafe updates to Switch's modules to be explicitly allowed too).
First, have a read to this historical thread:
https://community.arubanetworks.com/discussion/aos-cx-tech-tips-allow-unsafe-updates
I believe little has changed over time and, basically, checking and allowing unsafe updates are still manual tasks to be executed when planning an AOS-CX update (read: when planning an AOS-CX upgrade), if required.
I could be wrong (I never had the opportunity to test since working mainly with VSX I never had an AOS-CX based VSF to update using the ISSU) but I believe current implementation of ISSU doesn't take care to automatically (and autonomously) allowing unsafe updates...so the process is still manual IMHO...but...if so...the question is: what is the mutual relationship between starting an ISSU procedure (which is an automatic procedure with its checks and validations) and allowing unsafe updates - if/when required by the update/upgrade path - (which still is a manual, independent, procedure which could reboot the Switch more than once autonomously)? Will these two procedures interfere?
Cheers, Davide.
Original Message:
Sent: Apr 28, 2025 05:13 AM
From: Thomas
Subject: Non-failsafe device updates and issu update-software on CX Switches
Hello to all.
I've got a bunch of "JL659A 6300M 48SR5 CL6 PoE 4SFP56 Swch" Stacks and i want to run an issu Update. As in issu update-software written. The Update is form 10.13.1020 to 10.13.1090. But i've also seen there is a "Non-failsafe device update" open.
=================================================================
MODULE 'mc' DEVICE 'uboot_capsule' :
Current version : 'FL.01.0002'
Model info : '0x10008'
Packaged version : 'FL.01.0007'
Package name : 'uboot_talladega_capsule'
Image filename : 'FL_01_0007.uboot'
Image timestamp : 'Fri Aug 4 02:06:50 2023'
Image size : 1254612
Version upgrade needed
Non-failsafe device updates not enabled!
Would have updated 0 device(s).
Would not have updated 1 device(s).
======================================================================
Does the allow allow-unsafe-updates work or is it supposed on an issu update-software? Or is ther a reboot of the stack required to install the Non-failsafe device update
Best Regards
Thomas Odermatt