Light switch not online, still switches lights. Smoke detector not connected to wifi, still beep when detecting smoke.
The "smart" part is for convenience, not to create unnecessary dependencies. I'm a bit tired of seeing things that obviously only need access to local resources fail when the internet goes out.
1: https://en.wikipedia.org/wiki/Fallacies_of_distributed_compu...
(edit: question marks should mark the end of sentences which are questions)
(But yes, that really should be the case. It could also support elegant failures back to the previous firmware version.)
For that matter, I don't think most web developers have a proper sense of security challenges, either.
(You only need to reboot for kernel updates, and that can be reduced with kexec)
Your idea is pretty similar to having a hypervisor running two VMs and switching from one to the another. There's no need to have two separate memory banks.
Even more, while you usually can self-program the ROM memory, you can only erase it in blocks that are pretty big relative to the whole memory of the device. If you have a simple system that runs in a flat address space with no MPU and virtual memory, it gets pretty complicated for a running update.
Of course, that's from my experience with microcontrollers. SOrry if I went off-topic, but I just thought the discussion interesting. Embedded Linux computers I bet are more complex than that and probably execute code in RAM. These babies are connected to the internet so they probably have a far beefier SOC running Linux not some lightweight RTOS. It is a kettle, you need a lot of juice for that baby!