I had posted earlier about issues going back to update U1 boxes using Update Manager. This issue was resolved by the slew of patch releases on 08/13. I can now update U1 (and prior versions) without error (using the default "Critical Host Updates" and "Non-Critical Host Updates" baselines). This results in a server being updated to 3.5.0, 110268. However, now, using the default provided baselines ("Critical Host Updates" and "Non-criticial Host Updates"), I can no longer patch any box that is 3.5.0, 103908 (the time-bombed version of U2). Installation fails on ESX350-200802301-BG stating that "A newer version of the patch is already installed".
If I create a separate baseline that only includes patches released 08/12/08 - 08/13/08... removing the Time-Bomb patch (ESX350-20086812-BG), but including ESX350-Update-02, then I can patch U2 Servers that have not yet had the "Time-Bomb patch (ESX350-20086812-BG) installed. These servers wind up as version 3.5.0, 110181
If I attempt to install all patches released from 08/12/08 - 08/13/08 onto U2 Servers (3.5.0. 103908) that have already had the "Time-Bomb" fix (ESX350-20086812-BG), then installation fails on ESX350-200806812-BG with an error that "Installation failed - higher version of patch already installed".
A quick check reveals that, following the bevy of patches released on 08/13/08, if you use the default baselines, they attempt to reinstall stuff as old as 03/04/08.... even though these patches are already installed. In addition, all servers now show "Not Compliant" in update manager for all of these old patches, dating back to 03/04/08.... even though these patches are already installed.
So it looks the like the "Critical Host Updates" and "Non-Critical Host Updates" default updates, if unedited, are no longer applicable, functional, or usable for any U2 version servers... meaning you must have a seperate "All Update" patch list for Pre-U2 servers and U2-Post servers. Which complicates matters if you have a mix of servers within a cluster or data center. In a multi-DataCenter, Multi-Cluster, hundred+ host environment, this is somewhat of an annoyance. It also leaves us without a single query capability to determine compliance of our servers.
I have not read through the remainder of the thread or KB articles thus far today so I am unsure if there is a repair in work but I am finding it difficult to get my servers at the same revision levels (3.5.0, 110286). The results described above are consistent and reproducible in my environment.
EDIT: Correction - I have managed to get U2 version 3.5.0, 103908 updated to version 110286, U2 version 110181 upgraded to 110286, and everything prior to 103908 upgraded to 110286. It's not as consistent as I would like and it is requiring 2 baselines in my environment to make this occur.