Marcin Hernik
Created: September 29, 2026
Product: Stratusphere FIT/UX
Product Version: 6.7.x
Expires on: 365 days from publish date
Updated: Sep 29, 2026
Problem:
After an in-place upgrade and reboot, one or both of the following occur:
Upgrade image will not mount and collectors will fail to upgrade. Web UI reports "Invalid Parameters" — CLI reports:
mount: /tmp/tmp.XXXXXXX: unknown filesystem type 'squashfs' /opt/lwl/bin//lwl-upgrade-image: line 119: [: too many arguments
The line 119 error is a result of the failed mount, not a separate fault.
Appliance status page reports System Modules "NO":
Module xt_AUDITLWL is not loaded into kernel. Module xt_ruleid is not loaded into kernel.
Capturing Traffic reports WARN with no connections captured, while Services, Key Material and Policy Loaded all report OK.
Both faults originate from the kernel. The upgrade installs a new kernel but does not always advance the GRUB default, so the appliance reboots on the old kernel and squashfs support is unavailable. Separately, the upgrade may fail to populate the new kernel's weak-updates/netfilter/ directory, leaving the Liquidware netfilter modules unreachable. The second fault is often masked by the first and only appears once the kernel is corrected. Check for both.
On a HUB, a failed image mount also stops /var/www/html/upgrades/latest from being served, which blocks the Database and Collector upgrades.
Solution:
Replace the kernel version strings below with the values from the appliance being worked on.
Part 1 — Correct the booted kernel
- Logon to the appliance using Putty as friend and elevate to root shell with "sudo bash"
- Compare the running kernel against the installed kernel:
[root@hub friend]# uname -r 4.18.0-553.34.1.el8_10.x86_64 [root@hub friend]# rpm -q kernel kernel-4.18.0-553.117.1.el8_10.x86_64 [root@hub friend]# grubby --default-kernel /boot/vmlinuz-4.18.0-553.34.1.el8_10.x86_64
A running kernel older than the installed kernel confirms the fault.
- Set the GRUB default to the new kernel and reboot:
grubby --set-default=/boot/vmlinuz-4.18.0-553.117.1.el8_10.x86_64 reboot
- After reboot, confirm
uname -rnow matchesrpm -q kernel, then install the image:
/opt/lwl/bin/lwl-upgrade-image -i -o -f /opt/lwl/upgrades/images/stratusphere-6.7.0-5.img ls -l /var/www/html/upgrades/latest df -h | grep loop curl -k -I https://127.0.0.1/upgrades/latest/repodata/repomd.xml
A loop device at 100% and HTTP 200 confirm success. If the image is not present on the appliance, upload it to /var/tmp using WinSCP and install from there.
- If the squashfs error persists after the kernel is correct:
find /lib/modules/$(uname -r) -name "squashfs*" lsmod | grep squashfs modprobe squashfs
Part 2 — Restore the netfilter modules
Run on every upgraded appliance, including any where Part 1 was not required.
- Confirm the fault:
lsmod | grep -E 'AUDITLWL|ruleid' ls -la /lib/modules/$(uname -r)/weak-updates/netfilter/ find /lib/modules -name "xt_AUDITLWL*" -o -name "xt_ruleid*"
An empty weak-updates/netfilter/ with the .ko files present under an older kernel's extra/netfilter/ confirms the fault. Symlinks pointing to kernels no longer installed may also be present from earlier upgrade cycles.
- Link the modules to the running kernel and load them:
cd /lib/modules/$(uname -r)/weak-updates/netfilter/ ls -la rm -f *.ko ln -s /lib/modules/4.18.0-553.34.1.el8_10.x86_64/extra/netfilter/*.ko . ls -la depmod -a modprobe xt_AUDITLWL modprobe xt_ruleid lsmod | grep -E 'AUDITLWL|ruleid'
Only symlinks exist in this directory. Confirm with ls -la before removing.
- Reload the network policy:
/opt/tnt/bin/clearall /opt/tnt/bin/policy
- Click Update Status on the appliance status page. System Modules should report OK and Capturing Traffic should begin incrementing.