Repository navigation
[Windows][FIPS] Upgrade from 9.5.0-SNAPSHOT to 9.6.0-SNAPSHOT fails because .elastic-agent.active.commit is missing. #16050
Description
Activity
- addedbugSomething isn't workingSomething isn't workingTeam:Elastic-Agent-Control-PlaneLabel for the Agent Control Plane teamLabel for the Agent Control Plane teamimpact:highShort-term priority; add to current release, or definitely next.Short-term priority; add to current release, or definitely next.
on Aug 6, 2026 infra-vault-gh-plugin-prod commented
on Aug 6, 2026 More actionsPinging @elastic/elastic-agent-control-plane (Team:Elastic-Agent-Control-Plane)
harshitgupta-qasource commented
on Aug 6, 2026 AuthorMore actions@kishorkumar-qasource Kindly review
Secondary review is done for this!!
Claude-Generated Root Cause Analysis
Primary Code Bug —
-fipsnot stripped from zipfileNamePrefixThe codebase has two separate paths for reading package metadata: one for
.tar.gz(Linux/macOS) and one for.zip(Windows). They handle the-fipsfilename substring inconsistently.For
.tar.gz—getFileNamePrefixinstep_unpack.go:662:func getFileNamePrefix(archivePath string) string { prefix := strings.TrimSuffix(filepath.Base(archivePath), ".tar.gz") + "/" prefix = strings.Replace(prefix, fipsPrefix, "", 1) // ← strips "-fips" return prefix }
For
elastic-agent-fips-9.6.0-SNAPSHOT-linux-x86_64.tar.gz→ prefix becomeselastic-agent-9.6.0-SNAPSHOT-linux-x86_64/.For
.zip—getPackageMetadataFromZip(step_unpack.go:269) andunzip(step_unpack.go:128):fileNamePrefix := strings.TrimSuffix(filepath.Base(archivePath), ".zip") + "/" // ← NO "-fips" stripping
For
elastic-agent-fips-9.6.0-SNAPSHOT-windows-x86_64.zip→ prefix becomeselastic-agent-fips-9.6.0-SNAPSHOT-windows-x86_64/.The Windows FIPS zip archive follows the same convention as tar.gz packages: the internal directory omits
-fips(i.e.,elastic-agent-9.6.0-SNAPSHOT-windows-x86_64/). The code then tries to openelastic-agent-fips-9.6.0-SNAPSHOT-windows-x86_64/.elastic-agent.active.commit, which does not exist because the actual path inside the archive iselastic-agent-9.6.0-SNAPSHOT-windows-x86_64/.elastic-agent.active.commit. This is confirmed precisely by the error message:open elastic-agent-fips-9.6.0-SNAPSHOT-windows-x86_64/.elastic-agent.active.commit: file does not existThe manifest lookup (
step_unpack.go:336–349) silently ignoresfs.ErrNotExist, so the wrong prefix for the manifest does not surface as an error. The commit file lookup (step_unpack.go:352–356) treats any error includingfs.ErrNotExistas fatal — so the wrong prefix causes a hard failure here.Why non-FIPS Windows works: the archive name
elastic-agent-9.6.0-SNAPSHOT-windows-x86_64.zipalready matches the internal directory name, so no stripping is needed and no prefix mismatch occurs.
Secondary Potential Cause — Build/packaging omission
It is also possible the FIPS Windows
.zipartifact was built without.elastic-agent.active.commitat any path (i.e., the file is absent from the archive entirely rather than present at the wrong path). This would produce the same error. It is not possible to confirm without inspecting the actual artifact, but the code asymmetry above is the more likely cause.
Contributing Factor — No FIPS zip test coverage
TestGetFileNamePrefix(step_unpack_test.go:760) only tests.tar.gzpaths. Allunziptests use non-FIPS archive names (e.g.,elastic-agent-1.2.3-SNAPSHOT-someos-x86_64.zip). There is no test forgetPackageMetadataFromZiporunzipwith a FIPS-named.zipfile, so the prefix mismatch was never caught.
Fix Direction
Apply the same
-fipsstripping to the zip code path. BothgetPackageMetadataFromZipandunzipshould strip-fipswhen computing the prefix, for example:fileNamePrefix := strings.TrimSuffix(strings.Replace(filepath.Base(archivePath), fipsPrefix, "", 1), ".zip") + "/"
Or factor the logic into a shared helper analogous to
getFileNamePrefixthat handles both.zipand.tar.gzextensions.- addedQA:Ready For TestingCode is merged and ready for QA to validateCode is merged and ready for QA to validate
on Aug 10, 2026 harshitgupta-qasource commented
on Sep 8, 2026 AuthorMore actionsHi Team,
We have validated this ticket on the latest 9.5.3 Kibana cloud environment and found it working fine.
Observations:
- Windows FIPS Elastic Agent should upgrade successfully from
9.5.2to9.5.3
Build details:
VERSION: 9.5.3 BUILD: 107530 COMMIT: 2169f1de4c917fce03905cc3110f3f523e2184d2 Artifact: https://artifacts.elastic.co/downloads/beats/elastic-agent/elastic-agent-fips-9.5.2-windows-arm64.zipScreenshot
- Before Upgrade
- After Upgrade
20260908-1014-11.3057709.mp4
Hence, we are marking this issue as QA: Validated.
ThanksReacted by Eric Beahan- Windows FIPS Elastic Agent should upgrade successfully from
- addedQA:ValidatedValidated by the QA TeamValidated by the QA Teamand removedQA:Ready For TestingCode is merged and ready for QA to validateCode is merged and ready for QA to validate
on Sep 8, 2026
Kibana Build details:
Host OS and Browser version: Windows x64, All browsers
Preconditions:
x86_64) FIPS artifact has been downloaded.Steps to reproduce:
9.6.0-SNAPSHOTas the target version.9.5.0-SNAPSHOTto9.6.0-SNAPSHOTand stuck in the Failed state.Expected Result:
9.5.0-SNAPSHOTto9.6.0-SNAPSHOT.Whats Working Fine
For NON-FIPS windows agent upgrade successfully
Screenshots:
.elastic-agent.active.commiterror in the agent logs.Agent logs:
elastic-agent-diagnostics-2026-08-06T07-27-04Z-00.zip
Ticket:
https://github.com/elastic/ingest-dev/issues/7431