i saw the same upgrading just a normal forwarder, where noexec was set. have created a support case for it, hopefully they will check it for existing systems being upgraded. since they changed in the logic as you also point out: 10.2.6 if [ -x "$SPLUNK_HOME/bin/splunk" ] ; then
echo "This looks like an upgrade of an existing Splunk Server. Checking to see what component we are installing"
echo "extracting splunk_preinstall_base64 into splunk/bin directory"
printf '%s' "$ENCODED_PREINSTALL" | base64 -d > "$SPLUNK_HOME/bin/temp_splunk-preinstall"
echo "Adding execution bit"
chmod +x "$SPLUNK_HOME/bin/temp_splunk-preinstall"
"$SPLUNK_HOME/bin/temp_splunk-preinstall" --splunk-home "$SPLUNK_HOME"
result=$?
echo "result: $result"
rm -f "$SPLUNK_HOME/bin/temp_splunk-preinstall" || echo "failed to remove temp_splunk-preinstall"
if [[ "$result" != 0 ]]; then
echo "splunk-preinstall upgrade check failed, exit"
exit 1
fi
else
echo "no need to run the splunk-preinstall upgrade check"
fi VS 10.2.7 if [ -x "$SPLUNK_HOME/bin/splunk" ] ; then
echo "This looks like an upgrade of an existing Splunk Server. Checking to see what component we are installing"
echo "extracting splunk_preinstall_base64 into a temporary directory"
# Prefer /var/tmp because some hardened hosts mount /tmp noexec.
splunk_execution_owner="$(resolve_splunk_execution_owner || true)"
preinstall_tmpdir=""
for preinstall_tmpbase in /var/tmp /tmp; do
preinstall_tmpdir="$(mktemp -d "$preinstall_tmpbase/splunk-preinstall.XXXXXX" 2>/dev/null)" && break
done
preinstall_tmp="$preinstall_tmpdir/temp_splunk-preinstall"
if [ -z "$splunk_execution_owner" ]; then
echo "could not determine safe execution owner for splunk-preinstall"
result=1
elif [ -z "$preinstall_tmpdir" ]; then
echo "failed to create temporary directory for splunk-preinstall"
result=1
else
chmod 700 "$preinstall_tmpdir"
printf '%s' "$ENCODED_PREINSTALL" | base64 -d > "$preinstall_tmp"
result=$?
if [ "$result" = 0 ]; then
if [ "$splunk_execution_owner" = "root" ]; then
chmod 500 "$preinstall_tmp"
else
chmod 555 "$preinstall_tmp" && chmod 755 "$preinstall_tmpdir"
fi
result=$?
fi
if [ "$result" = 0 ]; then
run_command_as_owner "splunk-preinstall" "$splunk_execution_owner" "$preinstall_tmp" --splunk-home "$SPLUNK_HOME"
result=$?
fi
fi
echo "result: $result"
if [ -n "$preinstall_tmpdir" ]; then
rm -rf "$preinstall_tmpdir" || echo "failed to remove $preinstall_tmpdir"
fi
if [[ "$result" != 0 ]]; then
echo "splunk-preinstall upgrade check failed, exit"
exit 1
fi
else
echo "no need to run the splunk-preinstall upgrade check"
fi (found using) rpm -qp --scripts splunkforwarder-10.2.6-bcdcf0552e0c.x86_64.rpm > /tmp/1026-scripts.txt rpm -qp --scripts splunkforwarder-10.2.7-c0bff5b0fac3.x86_64.rpm > /tmp/1027-scripts.txt
... View more