Raspberry Pi Bootloader

Firmware

Boot EEPROM firmware for the Raspberry Pi 4 and Raspberry Pi 5.

Latest v2026.05.17-2711-0138c0 · by Raspberry PiWebsiteraspberrypi/rpi-eeprom

Release activity

Release activity — 7 releases across 5 days in the last year. Each cell is one day; darker means more releases that day. Older weeks are hidden at this screen width.
MayJunJulAug
SundayNo releases on Apr 19, 2026No releases on Apr 26, 2026No releases on May 3, 2026No releases on May 10, 2026No releases on May 17, 2026No releases on May 24, 2026No releases on May 31, 2026No releases on Jun 7, 2026No releases on Jun 14, 2026No releases on Jun 21, 2026No releases on Jun 28, 2026No releases on Jul 5, 2026No releases on Jul 12, 2026No releases on Jul 19, 2026No releases on Jul 26, 2026No releases on Aug 2, 2026
MondayNo releases on Apr 20, 2026No releases on Apr 27, 2026No releases on May 4, 20261 release on May 11, 2026No releases on May 18, 2026No releases on May 25, 2026No releases on Jun 1, 2026No releases on Jun 8, 2026No releases on Jun 15, 2026No releases on Jun 22, 2026No releases on Jun 29, 2026No releases on Jul 6, 2026No releases on Jul 13, 2026No releases on Jul 20, 2026No releases on Jul 27, 2026No releases on Aug 3, 2026
TuesdayNo releases on Apr 21, 2026No releases on Apr 28, 2026No releases on May 5, 2026No releases on May 12, 2026No releases on May 19, 2026No releases on May 26, 2026No releases on Jun 2, 2026No releases on Jun 9, 2026No releases on Jun 16, 2026No releases on Jun 23, 2026No releases on Jun 30, 2026No releases on Jul 7, 2026No releases on Jul 14, 2026No releases on Jul 21, 2026No releases on Jul 28, 2026No releases on Aug 4, 2026
WednesdayNo releases on Apr 22, 2026No releases on Apr 29, 2026No releases on May 6, 2026No releases on May 13, 2026No releases on May 20, 20261 release on May 27, 2026No releases on Jun 3, 2026No releases on Jun 10, 2026No releases on Jun 17, 2026No releases on Jun 24, 2026No releases on Jul 1, 2026No releases on Jul 8, 2026No releases on Jul 15, 2026No releases on Jul 22, 2026No releases on Jul 29, 2026No releases on Aug 5, 2026
ThursdayNo releases on Apr 23, 2026No releases on Apr 30, 2026No releases on May 7, 2026No releases on May 14, 2026No releases on May 21, 2026No releases on May 28, 2026No releases on Jun 4, 2026No releases on Jun 11, 2026No releases on Jun 18, 2026No releases on Jun 25, 2026No releases on Jul 2, 2026No releases on Jul 9, 2026No releases on Jul 16, 2026No releases on Jul 23, 2026No releases on Jul 30, 2026No releases on Aug 6, 2026
FridayNo releases on Apr 24, 2026No releases on May 1, 2026No releases on May 8, 2026No releases on May 15, 2026No releases on May 22, 2026No releases on May 29, 2026No releases on Jun 5, 2026No releases on Jun 12, 2026No releases on Jun 19, 2026No releases on Jun 26, 2026No releases on Jul 3, 2026No releases on Jul 10, 2026No releases on Jul 17, 2026No releases on Jul 24, 2026No releases on Jul 31, 2026No releases on Aug 7, 2026
SaturdayNo releases on Apr 25, 2026No releases on May 2, 2026No releases on May 9, 2026No releases on May 16, 2026No releases on May 23, 2026No releases on May 30, 2026No releases on Jun 6, 2026No releases on Jun 13, 2026No releases on Jun 20, 2026No releases on Jun 27, 2026No releases on Jul 4, 2026No releases on Jul 11, 2026No releases on Jul 18, 2026No releases on Jul 25, 2026No releases on Aug 1, 2026

7 releases in the last year, busiest day 2

Changelog

v2026.05.17-2711-0138c0

rpi-boot-eeprom-recovery-2026-05-17

Added 4
  • Record hardware board information in OTP on Pi4, reporting minimal bootloader version via device-tree as /proc/device-tree/chosen/rpi-min-boot-ver
  • Add error code for bootloader memory test, displaying 5 short flashes if DDR init firmware succeeds but memory test fails
  • Allow configuration of DPI clock from dt-blob in vcfw/plat_conf
  • Support conditional filter for eight customer OTP rows in config.txt from Pi 1 onwards
Changed 6
  • Update Broadcom DDR firmware to 2.35
  • Increase manufacturing version to 1 for 2711 to reflect Broadcom SDRAM DDR init firmware update
  • Perform preliminary clock driver refactoring in arm_loader_dvfs
  • Update Broadcom SDRAM firmware to v2.34 to support wider variety of SDRAM chips
  • Automatically reboot after displaying a fatal error three times in a row instead of waiting forever, with REBOOT_ON_FATAL_ERROR=0 option to disable
  • Assume eMMC for CM4/CM5 non-lite modules by skipping SD interface condition command timeout and enabling eMMC mode directly, saving approximately 250ms of boot time
Fixed 2
  • Fix partition walk for boot_ramdisk and secure-boot to allow retries when boot.img is not found
  • Improve argument validation in rpi-fw-crypto to prevent lock-up from bad key-id or invalid private key during HMAC operations

Interesting changes since the last release:-

2026-05-17: Update Broadcom DDR firware to 2.35 (latest)
  • 2711: Increase the manufacturing version to 1 Increase the manufacturing version to 1 to reflect the update to the Broadcom SDRAM DDR init firmware.
  • 2711: Update SDRAM FW to 2.35
  • arm_loader_dvfs: Preliminary clock driver refactoring
  • pi4: Record hardware board information in OTP On Pi4 report the minimal bootloader version (manufacturing release) in OTP and make it available via device-tree as /proc/device-tree/chosen/rpi-min-boot-ver
2026-04-14: Update Broadcom SDRAM firmware to v2.34 (latest)
  • Update the Broadcom SDRAM firmware to v2.34 to support a wider variety of SDRAM chips.
  • Add an error code for the bootloader memory test. The bootloader contains simple memory test to validate that the DDR init firmware has completed successfully. If the DDR init firmware reports an error code then continue to display 8 short flashes. However, if the DDR init firmware is successful but the memory test fails then display 5 short flashes. This is very unlikely to fail in practise but is useful debug mechanism when stress testing boards e.g. different temperatures.
  • vcfw/plat_conf: Allow configuration of DPI clock from dt-blob
  • Automatically reboot after a displaying a fatal error Change the fatal error handler to perform a hard reset after displaying the fatal error three times in a row instead of waiting forever. This change can mitigate intermittent hardware issues due e.g. power supplies, HATs or board temperature. Displaying the error pattern three times first rate limits reboots. If a faster reboot is required then the BOOT_WATCHDOG setting should be used instead. To disable this feature set REBOOT_ON_FATAL_ERROR=0 in the bootloader config.
2026-02-23: Fix partition walk for boot_ramdisk / secure-boot (latest)
  • Fix partition walk for boot_ramdisk / secure-boot If secure-boot / boot_ramdisk was enabled and boot.img was not found then the bootloader would immediately exit the boot mode instead allowing the partition walk to run. Change the logic to allow retries if partition walk was enabled.
2026-02-06: config: Add support for customer OTP rows in conditional expressions (latest)
  • config: Add support for customer OTP rows in conditional expressions Support conditional filter for eight customer OTP rows to be used by config.txt from Pi 1 onwards. (Requires updated start4.elf)
  • rpi-fw-crypto: Fix bad hmac arguments lock-up Improve argument validation so that a bad key-id or invalid private key can no longer cause a lock-up during HMAC operations.
  • Assume eMMC for CM4/CM5 non-lite Attempt the fast path by skipping the SD interface condition command timeout on CM4/CM5 (non-lite) modules and enable eMMC mode directly. This saves ~250ms of the boot time.
View originalPermalink
How v2026.05.17-2711-0138c0 went
v2026.05.11-2712

rpi-boot-eeprom-recovery-2026-05-11-2712

Added 6
  • Add MFG_VER string for rpi-eeprom-update minver check to validate minimum recommended bootloader version against hardware
  • Record hardware board information in OTP on Pi5 and report minimal bootloader version via device-tree under /proc/device-tree/chosen/rpi-min-boot-ver
  • Add an error code for the bootloader memory test to display 5 short flashes if DDR init succeeds but memory test fails
  • Add support for customer OTP rows in conditional expressions in config.txt from Pi 1 onwards
  • Copy early bootloader UART logs into vcos logging accessible via sudo vclog -m on Pi5
  • Add support for 8-bit bus width eMMC on CM5
Changed 8
  • Set bootloader mfg version id to 1 to indicate support for new SDRAM variants
  • Increase default v3d frequency on 2712d0
  • Enable turbo clocks before loading the kernel on Pi5 to reduce boot time by approximately 1 second on NVMe boot
  • Update Broadcom SDRAM firmware to 4.72 to support additional memory variants
  • Update the slow non-tuned DDR init used by recovery.bin to support more SDRAM variants
  • Automatically reboot after displaying a fatal error three times instead of waiting forever, with option to disable via REBOOT_ON_FATAL_ERROR=0
  • Assume eMMC for CM4/CM5 non-lite modules by skipping SD interface condition command timeout to save approximately 250ms of boot time
  • Apply rpifwcrypto lock permissions to GET/SET USER OTP mailboxes to prevent access to device unique private key when locked
Fixed 4
  • Correct logging message for hdmi_pixel_freq_limit in arm_display
  • Fix partition walk for boot_ramdisk and secure-boot to allow retries if partition walk was enabled
  • Fix bad hmac arguments lock-up in rpi-fw-crypto by improving argument validation for key-id and private key
  • Preserve the RTC alarm state so it can be queried by the rpi-rtc driver

Interesting changes since the last release:

2026-05-11: 2712: Set bootloader mfg verison id to 1 (latest)
  • 2712: Set bootloader mfg verison id to 1 Advance the minimum version id to 1 to indicate support for new SDRAM variants.
  • Add MFG_VER string for rpi-eeprom-update minver check On new boards, the minimum recommended version will be written to OTP. This will allow rpi-eeprom-update to check the minimum recommended version required by the hardware against the version field embedded in EEPROM image binary. strings pieeeprom.bin | grep 'MFG_VER:'
  • pi5: Record hardware board information in OTP On Pi5 report minimal bootloader version via device-tree under /proc/device-tree/chosen/rpi-min-boot-ver.
2026-04-30: 2712: arm_boot: Enable turbo clocks before loading the kernel (latest)
  • arm_display: Correct logging message hdmi_pixel_freq_limit Noticed in a raspinfo log file.
  • Increase default v3d frqeuency on 2712d0
  • pi5: arm_boot: Enable turbo clocks before loading the kernel Originally, for the entire boot ran at the idle-operating point. Subsequently, the default for intial_turbo was changed so that the kernel is started with turbo-clocks unless disabled via config.txt. This change enables the turbo-clocks as soon as it is safe as soon as the turbo voltage has been calibrated to speedup kernel loading and device-tree processing. This reduces boot time by approximately 1 second on a Pi5 booting from NVMe.
2026-04-27: Broadcom SDRAM firmware update to 4.72 (latest)

Broadcom SDRAM firmware update to 4.72

Update the Broadcom SDRAM firmware to 4.72 to support additional memory variants.

2026-04-14: Update recovery.bin to support more SDRAM variants (latest)
  • Update the slow (non tuned) DDR init used by recovery.bin to support more SDRAM variants.
  • Add an error code for the bootloader memory test. The bootloader contains simple memory test to validate that the DDR init firmware has completed successfully. If the DDR init firmware reports an error code then continue to display 8 short flashes. However, if the DDR init firmware is successful but the memory test fails then display 5 short flashes. This is very unlikely to fail in practise but is useful debug mechanism when stress testing boards e.g. different temperatures.
  • Automatically reboot after a displaying a fatal error Change the fatal error handler to perform a hard reset after displaying the fatal error three times in a row instead of waiting forever. This change can mitigate intermittent hardware issues due e.g. power supplies, HATs or board temperature. Displaying the error pattern three times first rate limits reboots. If a faster reboot is required then the BOOT_WATCHDOG setting should be used instead. To disable this feature set REBOOT_ON_FATAL_ERROR=0 in the bootloader config.
2026-02-23: Fix partition walk for boot_ramdisk / secure-boot (latest)
  • Fix partition walk for boot_ramdisk / secure-boot If secure-boot / boot_ramdisk was enabled and boot.img was not found then the bootloader would immediately exit the boot mode instead allowing the partition walk to run. Change the logic to allow retries if partition walk was enabled.
2026-02-06: config: Add support for customer OTP rows in conditional expressions (latest)
  • config: Add support for customer OTP rows in conditional expressions Support conditional filter for eight customer OTP rows to be used by config.txt from Pi 1 onwards.
  • pi5: Copy early bootloader UART logs into vcos logging Early bootloader loggings in bootmain are now available via 'sudo vclog -m'
2026-01-21: rpi-fw-crypto: Fix bad hmac arguments lock-up (latest)
  • rpi-fw-crypto: Fix bad hmac arguments lock-up Improve argument validation so that a bad key-id or invalid private key can no longer cause a lock-up during HMAC operations.
2026-01-16: Assume eMMC for CM4/CM5 non-lite (latest)
  • Assume eMMC for CM4/CM5 non-lite Attempt the fast path by skipping the SD interface condition command timeout on CM4/CM5 (non-lite) modules and enable eMMC mode directly. This saves ~250ms of the boot time.
  • Don't stomp on RTC alarm state Preserve the RTC's alarm state so that it can be queried by the rpi-rtc driver. See: https://github.com/raspberrypi/firmware/issues/2011
  • arm_loader: Apply rpifwcrypto lock permissions GET/SET USER OTP Previously, the GET/SET user OTP mailboxes would provide access to the device unique private key. Update the mailbox API to fail if the key has been locked via lock_device_private_key=1 in config.txt or the associated mailbox call. GET/SET user OTP fails by setting the result tag to the standard error code (0x80000000). The dedicate GET/SET private key continue to fail the entire mailbox operation to force vcmailbox to exit with a non-zero error code.
  • cm5: Add support for 8-bit bus width eMMC
View originalPermalink
How v2026.05.11-2712 went
v2026.01.09-2711

rpi-boot-eeprom-recovery-2026-01-09

Interesting changes since the last release:-

2026-01-09: arm_loader: Apply rpifwcrypto lock permissions GET/SET USER OTP (latest)
  • arm_loader: Apply rpifwcrypto lock permissions GET/SET USER OTP Previously, the GET/SET user OTP mailboxes would provide access to the device unique private key. Update the mailbox API to fail if the key has been locked via lock_device_private_key=1 in config.txt or the associated mailbox call. GET/SET user OTP fails by setting the result tag to the standard error code (0x80000000). The dedicate GET/SET private key continue to fail the entire mailbox operation to force vcmailbox to exit with a non-zero error code.
  • Query all sdram devices for temperature when adjusting refresh
  • Add support for more SDRAM die configurations.
View originalPermalink
How v2026.01.09-2711 went
v2025.12.08-2711-138c0

rpi-boot-eeprom-recovery-2025-12-08-2711

Interesting changes since the last release:-

2025-12-08: arm_loader: Add machine ID derived from OTP values (latest)
  • arm_loader: Add machine ID derived from OTP values Machine ID is generated and exposed in device tree as rpi-machine-id
  • arm_ldconfig: Avoid double os_prefix on initramfs When using auto_initramfs we were picking up prefix from the kernel, but also adding os_prefix later: fname = prefixed_path(initramfs_file, os_prefix, temp_path, sizeof(temp_path)); See: https://forums.raspberrypi.com/viewtopic.php?t=394238
  • recovery: Use OTP rpiboot GPIO if non-zero If an rpiboot GPIO has already been written to OTP then default to that value if C(program_rpiboot_gpio) is not specified on config.txt.
  • Manufacture test updates for SDRAM.
2025-11-27: helpers/config_loader: Also support bootvar0 eeprom config on Pi4 (latest)
  • helpers/config_loader: Also support bootvar0 eeprom config on Pi4 This allows an eeprom config setting (e.g. BOOTARG0=0x10) to be set on a board which config.txt can use as a conditional expression (e.g. [bootarg0&0x10]).
  • pi5: Write over-voltage config to the UART log Write the high level over-voltage configuration to the UART log for diagnostic purposes.
  • Stop partition-walk after boot-mode timeout/retries limit Fix a fatal assert with USB boot where the partition walk could be retried after the USB timeout/retry limit had been reached. See: https://github.com/raspberrypi/rpi-eeprom/issues/776
  • rpiboot: Extend metadata to report status of operations Report success/fail status of recovery operations based on config.txt settings
2025-11-21: recovery: Restore recovery_wait option (latest)
  • recovery: Restore recovery_wait option Restore the recovery_wait config.txt option. If this option is set then recovery.bin will not rename itself or reboot. Instead flash the activity LED on completion. This option can be useful when creating an SD card to erase the EEPROM or program the RPIBOOT gpio on multiple devices. If recovery_wait=1 and recovery.bin is run from the SD card then indicate success of erase_eeprom=1 or program_rpiboot_gpio=N was set instead of requiring the EEPROM to be updated.
  • Manufacture test updates for SDRAM.
View originalPermalink
How v2025.12.08-2711-138c0 went
v2025.12.08-2712

rpi-boot-eeprom-recovery-2025-12-08-2712

Interesting changes since the last release:-

2025-12-08: arm_loader: Add machine ID derived from OTP values (latest)
  • arm_loader: Add machine ID derived from OTP values Machine ID is generated and exposed in device tree as rpi-machine-id
  • arm_ldconfig: Avoid double os_prefix on initramfs When using auto_initramfs we were picking up prefix from the kernel, but also adding os_prefix later: fname = prefixed_path(initramfs_file, os_prefix, temp_path, sizeof(temp_path)); See: https://forums.raspberrypi.com/viewtopic.php?t=394238
2025-11-27: Stop partition-walk after boot-mode timeout/retries limit (latest)
  • pi5: Write over-voltage config to the UART log Write the high level over-voltage configuration to the UART log for diagnostic purposes.
  • Stop partition-walk after boot-mode timeout/retries limit Fix a fatal assert with USB boot where the partition walk could be retried after the USB timeout/retry limit had been reached. See: https://github.com/raspberrypi/rpi-eeprom/issues/776
  • rpiboot: Extend metadata to report status of operations Report success/fail status of recovery operations based on config.txt settings
2025-11-21: Allow longer overlay file paths (latest)
  • recovery: Restore recovery_wait option Restore the recovery_wait config.txt option. If this option is set then recovery.bin will not rename itself or reboot. Instead flash the activity LED on completion. This option can be useful when creating an SD card to erase the EEPROM or program the RPIBOOT gpio on multiple devices. If recovery_wait=1 and recovery.bin is run from the SD card then indicate success of erase_eeprom=1 or program_rpiboot_gpio=N was set instead of requiring the EEPROM to be updated.
  • Load RP1 firmware whilst DDR is initialising
  • Allow longer overlay file paths load_dtoverlay uses the variable "filename" to hold the full path to an overlay. As such it should be declared using LDFILEPATH_MAX, not LDFILENAME_MAX. See: https://github.com/raspberrypi/firmware/issues/2004
View originalPermalink
How v2025.12.08-2712 went
v2025.11.05-2711-138c0

rpi-boot-eeprom-recovery-2025-11-05-2711

Interesting changes since the last release:

2025-11-05: Add iommu_dma_numa_policy=interleave when needed (latest)
2025-10-14: recovery: Use ROM boot-mode to detect rpiboot (latest)
  • recovery: Use ROM boot-mode flag to detect rpiboot mode In recovery-mode use the bootrom register flag to detect the original boot-mode rather than looking at whether the rpiboot usb-device boot driver is initialised.
  • Manufacturing test updates.
2025-10-08: Fix accidental set of PM_RSTS bit 5 when stopping watchdog (latest)
  • Fix accidental set of PM_RSTS bit 5 when stopping watchdog Fix an issue in the watchdog code where the raw PM_RSTS value was used as partition number. If HADWRF (bit 5) was set (on reboot) this could cause bit 10 to be set. If an OS didn't clear the partition flags on reboot then this could end up being treated as request to boot from partition 32.
2025-10-03: arm_dt: Report OTP SDRAM size via device-tree (latest)
  • arm_dt: Report OTP SDRAM size via device-tree Report the SDRAM in gigabits via device-tree as /proc/device-tree/chosen/rpi-sdram-size-gbit. Scripts reporting the device-capabilities should use this value (if defined) instead of the memory-size field in the boardrev row.
  • Apply UART_BAUD in early bootsys UART init Update bootsys and fatal error handlers to use the user defined UART_BAUD rate.
  • rpifwcrypto: Add support for ECDSA P-256 key generation Also, slightly improve the entropy by passing the system timer value as the personality string.
2025-09-23: Fix network install regression on Pi4 (latest)
  • Fix network install regression on Pi4 Fix an issue with the ECDSA signature code which caused network install to fail to load on Pi4.
  • Fix TFTP to allow larger files Allow TFTP block counter to rollover to 0. See: https://github.com/raspberrypi/rpi-eeprom/issues/720
2025-09-22: Add LZ4 decompressor (latest)
  • Add LZ4 decompressor LZ4 gives a better compression ratio than the previously used CK compress. The bootloader can now decompress both LZ4 compressed files and CK compressed files.
  • rpifwcrypto: Add GET_CRYPTO_PRIVATE_KEY mailbox API For provisioning, add a new mailbox API which returns the private key in DER format. The API will return an error if the key-status for the specified key is LOCKED.
  • config: Add support for board_attributes in conditional expressions Add support for the board-attributes row in config.txt conditional expressions. This can be used to change boot behavior for Compute Module Lite / No-WiFi etc.
  • board_info: Log the OTP board revision at startup Log the board revision plus the raw OTP value at startup.
2025-08-27: Fix PARTITION property to allow default (0) partition to be overridden (latest)
  • Fix PARTITION property to allow default (0) partition to be overridden Fix the partition selection to allow the bootloader PARTITION property to override the reboot partition number if the reboot argument is 0 or > 31. Previously, it was only allowing partition numbers > 31 to be overridden. See: https://github.com/raspberrypi/rpi-eeprom/issues/743
  • Enable RPIBOOT in BOOT_ORDER / set-reboot-order Previously, rpiboot required the bootrom to have initialised rpiboot before running the firmware. Update the rpiboot initialisation so that rpiboot to be enabled after booting from SPI flash. This could be selectively enabled by setting BOOT_ORDER property (0x3) behind a GPIO conditional in the EEPROM config. On Pi5, the set_reboot_order config.txt option or mailbox property can be used to set a one-time boot-order on N.B. There is no timeout for RPIBOOT so this should only be set as the last boot mode OR used with a boot_watchdog.
2025-08-20: Fix PARTITION_WALK for missing start.elf files (latest)
  • Fix PARTITION_WALK for missing start.elf files Fix a missing call to bootloader_reset_state so that PARTITION_WALK will work if the boot-partition is FAT, contains config.txt etc but does not have valid firmware. See: https://github.com/raspberrypi/rpi-eeprom/issues/738
  • force_eeprom_read=0 disables HAT I2C Although setting force_eeprom_read=0 has always prevented the HAT EEPROM from being read, with the recent changes to support Power HAT+s it does not prevent an early scan to see if such an EEPROM exists. This can be problematic for applications where the I2C0 pins have been repurposed. Change the inhibit logic to cut all HAT I2C probing off at the knees, including any automatic settings of usb_max_current_enable, as it should always have done. See: https://github.com/raspberrypi/firmware/issues/1985
  • bootcode.bin: Add support for boot.img ramdisk on Pi3 and earlier Add support for boot.img ramdisk support, enable by adding boot_ramdisk=1 in config.txt
  • rpifwcrypto: Preliminary firmware support for rpifwcrypto API
  • Add config.txt to block GET_CUSTOMER_PRIVATE_KEY mailbox API lock_device_private_key=1
2025-08-13: Enable PARTITION_WALK property by default (latest)
  • Enable the PARTITION_WALK property by default Previously, the new PARTITION_WALK which searches for bootable partitions after a failure had to be explicitly enabled. Change the default to be enabled by default. It can be switched off by setting PARTITION_WALK=0 in the EEPROM config.
  • Optimise bootmain for size on Pi4 Pi4 only has a 512KB SPI flash EEPROM and the addition of features plus fixes is now causing contention for space between the code and the EEPROM config. Since bootmain is only responsible for loading start.elf revert to the original configuration which is optimised for size rather than speed. Pi5 continues to be optimised for speed.
2025-07-17: arm_loader: Also require the early-watchdog property (latest)
  • arm_loader: Also require the early-watchdog property The change correcting the implementation of dtoverlay_is_enabled had the unintended consequence of causing the firmware to enable the watchdog even though the user had not explicitly requested it. This is harmless on Linux because the watchdog driver takes over and disarms it, but on other operating systems this can lead to a reboot. Avoid this problem by also requiring the presence of a new property, "early-watchdog". See: https://github.com/raspberrypi/firmware/issues/1980
  • helpers/config_loader: Add bootvar0 eeprom config that can be used in config.txt section expressions This allows an eeprom config setting (e.g. BOOTVAR0=0x10) to be set on a board which config.txt can use as a conditional expression (e.g. [bootvar0&0x10]).
  • arm_loader: Fix boot-watchdog stop on Pi4 Fix a problem where the boot_watchdog heartbeat timer was not stopped correctly which could cause it to clash with the kernel watchdog driver.
2025-07-03: Check for SD card overcurrent (latest)
  • board_info: Use the Ethernet PHY address probed by the bootloader Use the Ethernet PHY address supplied by the bootloader in preference to the static configurations defined in start4.elf
  • Check for SD card overcurrent on Pi5, Pi500 and Pi4 Before booting, the bootloader now checks the SD power switch overcurrent signal. The overcurrent signal occurs if the SD card is damaged and has a short circuit which will cause it to get hot. If an over-current condition is detected the bootloader switches switches off power to the SD card and waits five seconds before probing the SD card again. This error is displayed on the diagnostic screen, the UART and the activity LED (1 long, 2 short) flashes. The check can be switched to a non-blocking warning by setting SD_OVERCURRENT_CHECK=0 in the bootloader config.
  • Add a new error code pattern for SD overcurrent Add a new error pattern (1 long, 2 short) to signal SD card overcurrent.
  • Add support for a bootloader watchdog Add support for a boot watchdog (using PM_RSTC hw wdog) which will trigger if the OS is not started within the specified amount of time. The watchdog is enabled by setting the BOOT_WATCHDOG_TIMEOUT=N (seconds) property in the bootlaoder config. The BOOT_WATCHDOG_PARTITION=P property can be set to pass a different partition number to the bootloader on reset if the watchdog is triggered. The boot watchdog is automatically cleared just before starting the OS and (optionally) enabling the kernel watchdog.
  • Skip first SD boot if no card detected On platforms with an SD Card detect signal, skip the first attempt to boot from SD if the card appears to be absent. This can save over a second on a cold boot, and a little under a second for a reboot.
2025-05-16: 2711: Automatically set revoke_devkey if program_pubkey=1 (latest)
  • 2711: (recovery) Automatically set revoke_devkey if program_pubkey=1 Previously, on BCM2711 products it was possible to program the key hash without revoking the development key. This can be useful for testing but should never be used in production because it is possible to an install an older version of the bootloader which doesn't support secure-boot. Since the secure-boot tools are stable and have improved usability (RPi secure-boot provisioner) this test feature not necessary and is just a security risk so the behaviour is changed to always revoke the development key if program_pubkey=1. This change is not relevant on BCM2712 because secure-boot requires that the second stage bootloader is counter-signed with the customer's private key.
View originalPermalink
How v2025.11.05-2711-138c0 went
v2025.11.05-2712

rpi-boot-eeprom-recovery-2025-11-05-2712

Interesting changes since the last release:

2025-11-05: arm_loader: Add iommu_dma_numa_policy=interleave when needed (latest)
  • arm_loader: Add iommu_dma_numa_policy=interleave when needed This applies a similar numa interleave for iommu dma kernel allocations. This includes buffers allocated for hevc and v3d. See: https://forums.raspberrypi.com/viewtopic.php?t=392666
  • Rebuild RP1 firmware to reduce size.
2025-10-17: Enable background refresh on 2712d0 for all SDRAM sizes (latest)
  • 2712d0: Enable background refresh on 2712d0 for all SDRAM sizes This provides a minor performance benefit.
  • Update GPT to support 4K native sectors Bootloader logic updated to correctly interpret the GPT layout format specific to 4K native sector drives.
  • recovery: Use ROM boot-mode flag to detect rpiboot mode In recovery-mode use the bootrom register flag to detect the original boot-mode rather than looking at whether the rpiboot usb-device boot driver is initialised.
2025-10-08: Fix accidental set of PM_RSTS bit 5 when stopping watchdog (latest)
  • Fix accidental set of PM_RSTS bit 5 when stopping watchdog Fix an issue in the watchdog code where the raw PM_RSTS value was used as partition number. If HADWRF (bit 5) was set (on reboot) this could cause bit 10 to be set. If an OS didn't clear the partition flags on reboot then this could end up being treated as request to boot from partition 32.
  • pi5: Preliminary support for 4K native sectors with NVMe drives Pi5 now supports 4K native sector NVMe drives. This allows booting from drives with logical block size 4096, while 512B drives remain compatible. With 4K sectors, storage density increases along with improved reliability and efficiency. N.B. USB boot still requires a 512 byte sector size and there are no RPi OS disk images with a 4K sector format. See: https://github.com/raspberrypi/rpi-eeprom/issues/577
  • arm_dt: Report OTP SDRAM size via device-tree Report the SDRAM in gigabits via device-tree as /proc/device-tree/chosen/rpi-sdram-size-gbit. Scripts reporting the device-capabilities should use this value (if defined) instead of the memory-size field in the boardrev row.
2025-09-25: Apply UART_BAUD in early bootsys UART init (latest)
  • Apply UART_BAUD in early bootsys UART init Update bootsys and fatal error handlers to use the user defined UART_BAUD rate.
  • rpifwcrypto: Add support for ECDSA P-256 key generation
2025-09-23: Fix TFTP to allow larger files (latest)
2025-09-22: Add LZ4 decompressor (latest)
  • Add LZ4 decompressor LZ4 gives a better compression ratio than the previously used CK compress. The bootloader can now decompress both LZ4 compressed files and CK compressed files.
  • rpifwcrypto: Add GET_CRYPTO_PRIVATE_KEY mailbox API For provisioning, add a new mailbox API which returns the private key in DER format. The API will return an error if the key-status for the specified key is LOCKED.
  • config: Add support for board_attributes in conditional expressions Add support for the board-attributes row in config.txt conditional expressions. This can be used to change boot behavior for Compute Module Lite / No-WiFi etc.
  • board_info: Log the OTP board revision at startup Log the board revision plus the raw OTP value at startup.
2025-08-27: Fix PARTITION property to allow default (0) partition to be overridden (latest)
  • Fix PARTITION property to allow default (0) partition to be overridden Fix the partition selection to allow the bootloader PARTITION property to override the reboot partition number if the reboot argument is 0 or > 31. Previously, it was only allowing partition numbers > 31 to be overridden. See: https://github.com/raspberrypi/rpi-eeprom/issues/743
  • Enable RPIBOOT in BOOT_ORDER / set-reboot-order Previously, rpiboot required the bootrom to have initialised rpiboot before running the firmware. Update the rpiboot initialisation so that rpiboot to be enabled after booting from SPI flash. This could be selectively enabled by setting BOOT_ORDER property (0x3) behind a GPIO conditional in the EEPROM config. On Pi5, the set_reboot_order config.txt option or mailbox property can be used to set a one-time boot-order on N.B. There is no timeout for RPIBOOT so this should only be set as the last boot mode OR used with a boot_watchdog.
2025-08-20: force_eeprom_read=0 disables HAT I2C (latest)
  • force_eeprom_read=0 disables HAT I2C Although setting force_eeprom_read=0 has always prevented the HAT EEPROM from being read, with the recent changes to support Power HAT+s it does not prevent an early scan to see if such an EEPROM exists. This can be problematic for applications where the I2C0 pins have been repurposed. Change the inhibit logic to cut all HAT I2C probing off at the knees, including any automatic settings of usb_max_current_enable, as it should always have done. See: https://github.com/raspberrypi/firmware/issues/1985
  • rpifwcrypto: Preliminary firmware support for rpifwcrypto API
  • Add config.txt to block GET_CUSTOMER_PRIVATE_KEY mailbox API lock_device_private_key=1
2025-08-13: Enable the PARTITION_WALK property by default (latest)
  • Enable the PARTITION_WALK property by default Previously, the new PARTITION_WALK which searches for bootable partitions after a failure had to be explicitly enabled. Change the default to be enabled by default. It can be switched off by setting PARTITION_WALK=0 in the EEPROM config.
  • pi5: Fix read for cached copy of PMIC sequencer status Previously, this was overwritten by the RTC event status.
2025-07-17: Fix config key search which could cause camera_autodetect to fail (latest)
  • Fix config key search which could cause camera_autodetect to fail The bootvar0 config property was added in the wrong section which could cause the config property search for some other properties to fail.
2025-07-17: arm_loader: Also require the early-watchdog property (latest)
  • arm_loader: Also require the early-watchdog property The change correcting the implementation of dtoverlay_is_enabled had the unintended consequence of causing the firmware to enable the watchdog even though the user had not explicitly requested it. This is harmless on Linux because the watchdog driver takes over and disarms it, but on other operating systems this can lead to a reboot. Avoid this problem by also requiring the presence of a new property, "early-watchdog". See: https://github.com/raspberrypi/firmware/issues/1980
  • helpers/config_loader: Add bootvar0 eeprom config that can be used in config.txt section expressions This allows an eeprom config setting (e.g. BOOTVAR0=0x10) to be set on a board which config.txt can use as a conditional expression (e.g. [bootvar0&0x10]).
  • arm_loader: Fix boot-watchdog stop on Pi4 Fix a problem where the boot_watchdog heartbeat timer was not stopped correctly which could cause it to clash with the kernel watchdog driver.
2025-07-03: Enable firmware UART output on the 40-pin header (latest)
  • rp1_uart: Allow rp1_uart to be started earlier If enabled (with enable_rp1_uart) then the existing boot uart messages are redirected to the rp1 uart.
2025-06-29: Check for SD card overcurrent on Pi5 and Pi500 (latest)
  • board_info: Use the Ethernet PHY address probed by the bootloader Use the Ethernet PHY address supplied by the bootloader in preference to the static configurations defined in start4.elf
  • pi5: Fix overwrite of cache EEPROM config in secure-boot mode See: https://github.com/raspberrypi/rpi-eeprom/issues/719
  • Check for SD card overcurrent on Pi5, Pi500 and Pi4 Before booting, the bootloader now checks the SD power switch overcurrent signal. The overcurrent signal occurs if the SD card is damaged and has a short circuit which will cause it to get hot. If an over-current condition is detected the bootloader switches off power to the SD card and waits five seconds before probing the SD card again. This error is displayed on the diagnostic screen, the UART and the activity LED (1 long, 2 short) flashes. The check can be switched to a non-blocking warning by setting SD_OVERCURRENT_CHECK=0 in the bootloader config.
  • Add a new error code pattern for SD overcurrent Add a new error pattern (1 long, 2 short) to signal SD card overcurrent.
  • Enable RTC wakeup from POWER_OFF_ON_HALT=0
  • Improve HAT+ current handling In shipping firmware, the current_supply value is only being used in the case of a normal (non-stacked) HAT+, but that is unnecessarily restrictive. Also, the presence of MODE0 and MODE1 power HATs is not reflected in the value of max_current. See: https://github.com/raspberrypi/linux/pull/6678
2025-06-20: Add support for a bootloader watchdog (latest)
  • Add support for a bootloader watchdog Add support for a boot watchdog (using PM_RSTC hw wdog) which will trigger if the OS is not started within the specified amount of time. The watchdog is enabled by setting the BOOT_WATCHDOG_TIMEOUT=N (seconds) property in the bootlaoder config. The BOOT_WATCHDOG_PARTITION=P property can be set to pass a different partition number to the bootloader on reset if the watchdog is triggered. The boot watchdog is automatically cleared just before starting the OS and (optionally) enabling the kernel watchdog.
  • pi5: Add a temperature monitor In early releases of the bootloader the fan would always be on during boot which can be distracting. Later releases switch off the fan until the OS has booted. This change adds some basic fan control from the bootloader to enable the fan if the temperature is above 85C. This may be useful if the Pi was shutdown by the OS because the temperature limit was exceeded. Since the Linux hwmon is not active at this stage the bootloader now implements the same logic to power off the Pi if the chips is more than 110C. The PMIC hardware automatically cuts power if the temperature is more than 125C.
  • Skip first SD boot if no card detected On platforms with an SD Card detect signal, skip the first attempt to boot from SD if the card appears to be absent. This can save over a second on a cold boot, and a little under a second for a reboot.
2025-06-13: Update to include production test changes (latest)
  • Update to include production test changes.
2025-06-09: NVMe: Fix loading of files > 32MB (latest)
  • NVMe: Fix loading of files > 32MB Fix an NVMe boot bug which caused large contiguous reads >= 32MB to fail.
  • Update setting alpha for 2712D0 D0 moved the alpha blend mode from CTL2 to CTL0. Update the bootloader code to follow suit for those using the simple framebuffer
  • dtoverlay: Fix node_is_enabled for implicit status The absence of a status property implies that a node is enabled. Update dtoverlay_node_is_enabled to match that behaviour. See: https://github.com/raspberrypi/firmware/issues/1970
  • arm_loader: GET_CLOCKS: Set useful response length The kernel's firmware mailbox API does not make the actual length of the response available to clients, but other implementations may care. Continue to pad the GET_CLOCKS buffer with zeroes, but set the response length to minimally contain the useful content. See: https://github.com/raspberrypi/firmware/issues/1969
View originalPermalink
How v2025.11.05-2712 went
v2025.05.08-2711-138c0

rpi-boot-eeprom-recovery-2025-05-08-vl805-000138c0

Interesting changes since the last release:

  • Signed boot and HTTP boot mode HTTP boot mode is supposed to be disabled if signed boot is enabled and a host is not specified. The code is checking the http_secure flag to enforce this. But this is valid now we support custom CA certs. Only disable HTTP mode if we're using the default HOST.
  • Implement TCP window for net boot The minimal IP stack used for https booting lacks the ability to cache packets received out of order, which can lead to severe slowdown when it happens. The problem seems to affect some ISPs more than others. The receive window implemented here copes with packet losses of 10%.
  • netboot: Correct the TCP MSS
  • Correct msecs in debug timestamps The fractional part of timestamps in UART debug output was showing the 100ths and 1000ths of a second, rather than 10ths and 100ths, causing strange sequences that appear to jump backwards.
View originalPermalink
How v2025.05.08-2711-138c0 went
v2025.05.08-2712

rpi-boot-eeprom-recovery-2025-05-08-2712

Interesting changes since the last release:

  • arm_loader: Correct some mailbox response lengths The GET_GENCMD_RESULT mailbox handler was setting the wrong response length, and GET_FIRMWARE_COMMIT_HASH and GET_FIRMWARE_VARIANT were not setting any length. See: https://github.com/raspberrypi/firmware/issues/1968
  • Signed boot and HTTP boot mode HTTP boot mode is supposed to be disabled if signed boot is enabled and a host is not specified. The code is checking the http_secure flag to enforce this. But this is valid now we support custom CA certs. Only disable HTTP mode if we're using the default HOST.
  • Implement TCP window for net boot The minimal IP stack used for https booting lacks the ability to cache packets received out of order, which can lead to severe slowdown when it happens. The problem seems to affect some ISPs more than others. The receive window implemented here copes with packet losses of 10%.
  • netboot: Correct the TCP MSS
  • rp1_net: Overwrite the length field Although concise, ORing in the packet length runs the risk of leaving some unwanted bits set. Ensure the length field is cleared before ORing in the required value.
  • Correct msecs in debug timestamps The fractional part of timestamps in UART debug output was showing the 100ths and 1000ths of a second, rather than 10ths and 100ths, causing strange sequences that appear to jump backwards.
  • Implement GET_BOARD_MAC_ADDRESS on Pi5 The Pi 5 EEPROM implements a subset of the original mailbox properties. Add GET_BOARD_MAC_ADDRESS to the subset. See: https://github.com/raspberrypi/rpi-eeprom/issues/698
  • Ensure the initramfs matches the kernel As far as is possible, both the kernel and initramfs are matched to the device. However, where multiple kernel variants can run on a device, the initramfs must be matched to the chosen kernel. Make that the sole rule for initramfs selection, rather than duplicating the device matching logic. See: https://github.com/raspberrypi/firmware/issues/1965
  • Enable logging messages from OS loader Pi 5 EEPROM builds were missing the output from the main OS loading function, including some important diagnostics. Enabling the logging output from this loader code results in some near-duplicates, but is more user friendly and is available via "sudo vclog -m".
  • arm_dt: Revert to using the max fan speed It has been reported that the presence of a cooling fan at boot time can lead to a maximum observed fan speed of ~300 but a current speed of 0. The absence of a fan results in 0s for both metrics. See: https://github.com/raspberrypi/rpi-eeprom/issues/690
  • os_check: cm5: Check for CM5 specific dtbs Check for BCM2712 support in bcm2712-rpi-cm5-cm5io.dtb or bcm2712-rpi-cm5l-cm5io.dtb on CM5 instead of bcm2712-rpi-5-b.dtb. This avoids needing to put os_check=1 or specifying device_tree in config.txt in minimal images for CM5. See: https://github.com/raspberrypi/rpi-eeprom/issues/682
  • Log the fan speed at boot Record the fan RPM (and the maximum seen) during boot, so that it is accessible using "sudo vclog -m". See: https://github.com/raspberrypi/rpi-eeprom/issues/678
  • Add current_supply to HAT+ support Refactor the HAT library to make it more self-contained, and combine the I2C address detection and the reading of the EEPROM contents. Use it to allow the earlier boot stages to check for a current_supply setting in the EEPROM of a normal (non-stackable) HAT+.
View originalPermalink
How v2025.05.08-2712 went
v2025.03.10-2712

rpi-boot-eeprom-recovery-2025-03-10-2712

Interesting changes since the last release:-

  • Log the fan speed at boot
  • Add current_supply to HAT+ support
  • Update SDRAM init timings to intermittent 8-flash SDRAM init errors on some boards. See: https://github.com/raspberrypi/rpi-eeprom/issues/67
  • config_loader: Add support [boot_partition=N] as an expression filter
  • Fix missing initialisation of selected_expr to 1 in config.txt
  • Fix BCM2712 GPIO pull configuration on 2712D0
  • Disable UARTA for CM5s without WiFi
  • recovery: Walk partitions to delete recovery.bin
View originalPermalink
How v2025.03.10-2712 went
View all

Discussion