I did an upgrade from R77 to R77.30 today myself, and policy installed without any issues on both cluster members too (R77 and R77.30). I think this is due to R77.X versions being pretty similar, although it wouldn't work like that we previous versions, as I remember. For example, you can manage R77.30 gateways from R77.20 management server.
If you had the setting for policy installation checked and it installed successfully, then nothing went wrong on that step. You would just get a message that policy installation failed on both cluster members, as it failed to be installed on one of them. So then you would disable the parameter and try to install policy again. This is not a problem.
I didn't really used cphacu commands during my upgrade, I just checked that status of upgraded node is Ready, checked connections number with fw tab -t connections -s and that was it. But I didn't have very strict requirements.
I suspect that some sessions were not synched in your case because of enabled SecureXL.
I believe it was not a VSX setup in your case, was it?