Re: Patches that require a reboot

From: Martin Paul (map_at_par.univie.ac.at)
Date: 09/21/04


Date: 21 Sep 2004 12:01:22 GMT

Dr. David Kirkby <nowhere@nowhere.com> wrote:
> Obviously is downtime can't be tolerated, and you choose to install in
> multi-user mode (based on a careful check of the README), that's a
> different issue.

I do that when deciding whether I can install single patches on
a running system. Usually the decision process is short - kernel
and driver patches wait for the next patch day (incl. a reboot).
For other patches fuser/lsof usually are enough to see whether
running processes are affected. If so, I decide whether I can
restart these processes in production - it's easy for sendmail/httpd/etc.,
but not so easy for e.g. sshd, where a restart would kill running
sessions.

> But if you are already in single-user mode, why not
> just reboot?? It must be the safest way, and the time loss is very small.

I agree.

> My original question was different and I don't think has been answered.
> If you install a lot of patches, and a large number say reboot, then
> rebooting after each patch saying this would be very time consuming. I'd
> like to think that is always unnecessary, but nobody has confirmed there
> are no instances where it would be useful (or mandatory) to reboot after
> installing a patch, even if the next thing you wish to do is install
> another patch.

I guess you won't get a definitive answer on that one. There will always
be a small chance that not doing a reboot might influence the system
in some obscure way that a reboot would be better before installing
other patches. I can see no way how Sun could test this and guarantee
that this will never be a problem. Still, I think (and in my experience)
the chance to break something is way to small to take the pain of
multiple reboots when installing multiple patches. If anything, you
could reboot after installing a kernel patch and before installing
other (driver) patches depending on this kernel patch, but I've never
done so, and have never seen a problem being caused by that.

mp.

-- 
Systems Administrator | Institute for Software Science | Univ. of Vienna


Relevant Pages

  • 9_Recommended error codes (specifically return code 5)
    ... * "return code 2" indicates patches are already installed. ... * "return code 25" means a patches requires another patch that is not yet installed. ... With or without using the save option, the patch installation process ... Installing 114008-01... ...
    (SunManagers)
  • KB835732 BSOD STOP 0x1d (detailed with debug info)
    ... Windows Update. ... Upon reboot, I noticed ... KB835732 patch. ... by uninstalling and installing the patch again. ...
    (microsoft.public.win2000.security)
  • Repost: Solaris Live Upgrade: questions about /var/sadm
    ... Newer patches will save the old files ... If the previous patch installation saved the old ... you should go back to the previous version before installing? ... Apply patch blabla-02 (BlaBla-01 saved) ...
    (comp.unix.solaris)
  • a1000 problem
    ... After installing the latest recommended ... patches, the 6.221 raid manager and some small patches and, ... reboot the machine and A1000 because the tools no longer ... There are no devices (controllers) in the system; ...
    (SunManagers)
  • Patch Check Advanced
    ... I developed my own script - Patch Check Advanced (PCA). ... downloading and installing of patches from Sunsolve. ...
    (comp.unix.solaris)