R52 Server upgrade integrity
R52 makes Server upgrades deterministic across clean machines and systems with different prior MSI histories.
Before the MSI runs, setup records installed Server and Server Administration file metadata and Windows Installer product/component state. It stops the MSP Server service and any Server Administration process or matching service that could hold an executable open. The current package manifest is embedded in Server Setup and is the source of truth for expected hashes and file versions.
After installation, setup records the same metadata again and verifies both executables and the installed manifest. A mismatch triggers one full MSI repair pass when replacement is not blocked. If validation still fails, the setup transcript identifies whether the prior file remained, an executable is locked, Windows has a pending reboot/file replacement, or MSI product/component state is inconsistent. Expected and actual hashes and versions are included.
Setup never continues to service startup or Administration launch unless both installed binaries exactly match the embedded current-package manifest. Administration processes and services stopped by setup restart only after that validation succeeds.
When Windows Installer returns 3010 or 1641, or a mismatch coincides with a Windows pending-replacement signal, setup reports Windows restart required. PostgreSQL/database content, NIC configuration, API keys, TLS/security artifacts, encryption/vault keys, server settings, and backup configuration remain preserved. Restart Windows and run the same R52 setup again to complete validation.
The user confirmed on 2026-09-23 that this R52 build passed Windows validation. R52 is therefore the current confirmed-working baseline. The unchanged R51 package remains available as the rollback baseline.
Guide basis
R68 package: Docs/R52-Server-Upgrade-Integrity.md
Published as a website guide on 1 October 2026. Where a bundled reference is older, the version-specific guide and installed interface take precedence.