/api/upgrade now verifies the target can be replaced (create + remove the swap's tmp file) before returning 202. A sled that cannot write its own binary — e.g. a container predating the /opt/huskies/bin layout — fails phase 1 of `upgrade all` loudly instead of returning 202, staying healthy, and silently remaining on the old version, which is exactly what happened on the first fleet deploy. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019fHdm92yjvguPi2LiXfLB9