tryboot automatic rollback behavior after failed kernel upgrade
0 reputation · 02 Mar 2025, 09:28 UTC
Uncertainty around tryboot rollback capability
The Raspberry Pi bootloader's tryboot feature (introduced in 2022) allows switching between two bootloader configurations, but its ability to automatically roll back a failed kernel or firmware update remains unclear. The mechanism requires a pre-staged alternate boot partition and manual intervention to activate, neither of which are configured by default in Raspberry Pi OS.
Constraints and gaps
Without an A/B root filesystem scheme or snapshot support, a partially applied kernel upgrade can leave the system unbootable while the root filesystem remains on the newer, potentially incompatible package set. Documentation indicates tryboot only switches bootloader configuration—not the root filesystem—so a mismatch between kernel modules and userspace packages may persist even after reverting the boot partition.
Goal
Determine whether tryboot can be integrated into an unattended upgrade pipeline to provide genuine rollback safety, or whether it remains a manual recovery tool requiring operator presence.
- Can
trybootbe configured to automatically detect a failed boot and revert to the previous bootloader configuration without user input? - Does the current Raspberry Pi OS packaging for kernel/firmware updates populate the alternate boot partition required for
trybootto function? - What additional tooling would be needed to coordinate
trybootwithdpkgtransaction state for a complete rollback?