What this family covers
Fifty-nine named faults, all raised by Update\UpdateError, all reachable only when a signed-in administrator opens this module's Update page and presses the button — see "How Updating Works" in this category for the eight-step process itself. There is no scheduled task and no unattended path anywhere in this vocabulary; every one of these fires inside a single admin-initiated run, and every one of them says, in its own words, exactly what was and was not changed before it stopped.
The single rule that makes this family safe to read quickly: a refusal here is always a decision to stop before doing something unproven, never evidence that something has already gone wrong on its own. If a sentence below does not explicitly say something was moved, downloaded, extracted or swapped, assume it was not.
The manifest and the release it names (16 codes)
Before anything is downloaded, this module fetches and verifies a signed manifest describing the release. manifest_unreachable and manifest_malformed are ordinary network and publishing hiccups — retry. manifest_signature_invalid, manifest_signature_missing and manifest_signature_error are all refused before anything downloads, but they are not the same event: the first two mean do not install anything and check for a proxy or TLS intercept, while the signature-error case means this build's own key material could not answer the question at all — it is not an accusation against the manifest. manifest_key_unknown means the vendor rotated signing keys; install the current release by hand once to pick up the new key. artifact_sha_disagreement is the one that matters most: the manifest contradicting itself about a file's checksum is what a tampered manifest looks like, and re-fetching is exactly what that would want you to do — report it instead. The remaining eleven (manifest_schema_unknown, manifest_field_missing, artifact_no_match_for_runtime, artifact_slot_set_refused, loader_too_old, loader_version_unknown, whmcs_too_old, whmcs_above_maximum, php_above_maximum, php_below_minimum) are all "this build is not offered to your environment" and name exactly which requirement your installation fails.
The downloaded archive itself (9 codes)
entry_traversal, entry_absolute, entry_nul_byte, entry_symlink, entry_not_relative and entry_not_in_module_tree are all the same finding wearing six names: something in the archive is not a plain file inside this product's own two module directories, and none of it was extracted. These should never fire against a genuine vendor release; if one does, report it and do not retry. archive_unreadable is an ordinary damaged download — retry. archive_unjudgeable means this server's own zip library could not identify every member's type, which is a property of the server, not the download; retrying gets the same answer. archive_extract_incomplete means every member passed inspection and the unpacking still did not match what was checked, which this module treats as seriously as a bad member: everything it wrote is removed and nothing is left behind.
Fetching the file (7 codes)
download_scheme_refused and download_redirect_refused are both refusals to fetch from anywhere other than a plain HTTPS address the vendor controls directly. download_size_exceeded, download_http_status, download_write_failed and download_transport_failed are ordinary transfer failures — a size ceiling, a bad status, a local disk problem and a network problem respectively — each naming which of the four it was rather than a generic "download failed". download_sha_mismatch is the one worth pausing on: try it once more, because a damaged transfer looks exactly like this, but do not install the file by hand if it repeats.
Proving the staged build actually loads (7 codes)
Before anything is swapped into place, this module fetches its own newly-staged code over HTTPS and checks for a sentinel response — the "decode probe". probe_token_invalid, probe_token_expired and probe_token_reused are all about the single-use token that guards that request; none of them means the staged build is bad. probe_path_outside_staging and probe_http_status should not occur against this module's own code and are worth reporting if seen. probe_unreachable almost always means this server cannot reach its own public HTTPS address — check that path, not the release. probe_sentinel_mismatch is the one that matters: the new build genuinely would not load, usually because the ionCube loader cannot read it, and nothing was swapped.
The swap itself, and what happens when a step of it fails (10 codes)
swap_cross_device, swap_staging_incomplete and swap_ownership_wrong are all pre-flight refusals: nothing was moved. swap_live_foreign means something not put there by this module already occupies its own directory — look at it by hand before doing anything else; nothing was moved or deleted. swap_rename_failed means a step of the install genuinely did not take, and everything that had already moved was moved straight back — nothing was deleted either way. swap_aside_unavailable and swap_aside_inside_docroot are both about where the previous version is kept: the first means this install has nowhere off the web to put it, the second means the location found is on the web and unguarded. Both refuse rather than risk publishing your program files, and the Update page names the storage location either way. swap_rollback_failed is the one genuine emergency in this entire vocabulary: the update failed and putting the previous version back also failed. If you ever see it, act immediately — the message names the backup directory to restore by hand.
The run as a whole: locking, permission and outcome (9 codes)
update_already_running and update_lock_stale both concern one lock file guarding one run at a time; the first means wait, the second means a previous run was interrupted and the message names the exact file to remove by hand — this module will never break its own lock automatically. update_requires_admin is Locked Decision 2's enforcement point: there is no cron path and no setting that creates one. probe_unavailable means this particular build shipped with no decode probe at all and refuses to install anything sight-unseen. update_not_needed is not a failure — you are already current. update_post_swap_check_failed means a release installed, then failed its own live loadability check, and was put straight back with nothing deleted; keep the failed release on disk as evidence and report it. update_stage_fault and update_lock_unwritable both name a step or a directory rather than repeating another system's error text, on purpose.
Where the previous version and the download are kept (3 codes)
storage_path_relative, storage_inside_docroot_unguarded and storage_reachable_over_http are three escalating findings about the same directory. The last one is not a guess: this module actually fetched that directory over HTTP before raising it, because a previous version left reachable in the open web root would publish this product's source code.