What happens when I update?
First stop the board and its maintenance tools. For a board already adopted into a managed D1 installation, spitfire update checks the proposed release, storage and compatibility, creates and verifies a pre-upgrade recovery checkpoint, and tests the changed board before making the new runtime active. The runtime is the executable that runs your BBS. Start the board yourself after a successful update.
Check, rehearse, then update
Use the installed launcher, not a loose executable:
spitfire update --check
spitfire update --dry-run
spitfire update
The release comes from a configured local directory, with a trusted signing key enrolled separately. This is an authenticated update foundation, not a public remote update service. New boards need the one-time installation adoption procedure before these launcher commands apply.
Three different recovery actions
| Action | What it changes | What happens to later board activity? |
|---|---|---|
| Pre-upgrade recovery | Returns an unsuccessful, uncommitted update to its verified starting point. | After commit, update recovery finishes cleanup; it does not rewind later messages. |
| Compatible runtime rollback | Chooses an earlier executable that can safely use the current data layout and features. | Current users, messages, files and network evidence are preserved. Incompatible runtimes are refused. |
| Explicit backup restore | Replaces ordinary board state with a chosen verified snapshot. | Later ordinary activity may be lost. Network recovery protections still apply. |
A schema is the version of the board's stored data layout. Schema 37 does not mean every older executable can read it. Never force an older program to open incompatible data.
spitfire rollback --list
spitfire rollback
Read Backup and Restore before using a restore command. Keep the old runtime, installation and verified backups together in your recovery plan.
If maintenance stops or the host reboots
An interrupted update can be recovered with spitfire update --recover. If recovery evidence is missing or corrupt, preserve it and keep the board stopped. An interrupted manual restore is a separate case and can require reviewed intervention; an update recovery command is not a cure for it.
Current limits
Updates are cold: every process using the board must be stopped. D1 does not install services, restart the board, provide cloud or whole-host recovery, downgrade the database, or prune backups automatically. Large managed file libraries may take time to validate even when their bytes are not copied. Plan a maintenance window and enough free storage.
Advanced: exact operator commands, interrupted manual restore.
Technical reference: release trust, staging and activation contract.