Interesting changes since the last release:
2026-09-25: 2712: Fix memory corruption with vclog messages (latest)
- Fix memory corruption with vclog messages
2026-09-24: 2712: Initialise SDRAM with safe/high-temeprature refresh settings (latest)
- 2712: Initialise SDRAM with safe/high-temeprature refresh settings
Update the SDRAM controller initialisation to start with the worst case
refresh rate (for high temperatures). Later on, the SDRAM temeprature
monitor will adjust the rate based on the temperature reported via the
mode register. - Set the MXL PHY LEDs in netboot mode
2026-09-23: Check MFG version when updating (latest)
- Remove trailing nulls in rpi-eeprom-config
Fix a regression in the previous bootloader where trailing nulls
characters could appear in rpi-eeprom-config. - Check target-soc in pieeprom.sig during updates
Recent versions of rpi-eeprom-digest add a "target-soc" tag to the
pieeprom.sig file containing either 2711 or 2712.
If this tag is present, then the bootloader will check that the
target-soc matches before updating SPI flash. This avoids using
the image size as the sole check for compatibility during bootloader
self-updates. - recovery: Check MFG version when updating
If the MFG version of the image to update is less than MFG version in OTP
then recovery.bin and self update will both fail to write the eeprom update.
bootloader_allow_mfg_downgrade=1 in config.txt will bypass the checks - 2712: Increment the manufacture version to v2
Update the manufacture version to v2 to indicate support for
alternate ethernet PHYs on Pi5. - usb-pd: Set USB Comms Capable and No USB Suspend for USB device mode
Set the USB comms capable and no USB suspend attributes for rpiboot
and Linux dwc gadgets.
See: raspberrypi/linux#6569 - update rp1c0fw.bin
Pull in RP1 firmware at 558c96910ac1231e107734ebe9babd7d29360218 - Version stamp file in eeprom
EEPROM contains a version file for build date, git hash, mfgver etc.
Partitioned images contain the main version file in the partition,
and a bootsys-ab version file in the read only section.
rpi-bootloader-version is the recommended way to get version details.
2026-09-15: Promote pieeprom-2026-09-12 to the default release (default)
2026-09-12: css: Move imx500 down the detection table (latest)
- css: Move imx500 down the detection table
With the increased 300ms delay, this needs to go lower to reduce the
average detection time. - css: Fix delay missing when we go through the IMX500 detection path
Also increase the IMX500 delay to 300ms to match the kernel's overlay
value. - arm_loader: Allow other PHY addresses for Pi 5
Alternative Ethernet PHYs may have a different PHY address and may
require an explicit post-reset delay.
2026-09-10: arm_loader: Reapply call to get_turbo_clocks when querying min clock (latest)
- arm_loader: Reapply call to get_turbo_clocks when querying min clock
This is needed for pixel clock when running with force_turbo=1
When we report min=max to kernel, it will never set them,
so we don't know about its clock requirements
See: raspberrypi/linux#7564 - Move crypto functions to secure RAM
All the crypto functions on 2712 now reside in the protected RAM region.
There is no change to how they are used with rpi-fw-crypto. - Fix TFTP signed booting
When TFTP booting with signed boot, resolving the prefix should
be done using the existance of boot.img rather than config.txt.
See: #857 - 2712: Add RP1 fw init fatal error handler
If the RP1 CHIP_ID is not recogized during the I2C init phase then
stop with fatal error code. Previously, the bootloader would
continue and fail with an assert intead. - Print SFDP EEPROM capacity
Print the capacity of the SPI flash chip from the SFDP table when available.
The firmware does not rely on any SFDP data, but it can be helpful to see it
when attempting to identify the SPI flash chip.
2026-08-12: Clear UV / OV PMIC power-on reset event for non-USB power supplies (latest)
- Fix USB-C cable orientation detection
Fix a typo which caused the wrong register to be read when reporting
the USB-C cable orientation in the bootloader HDMI diagnostics screen.
Previously, this would only ever report CC1 instead of CC1 or CC2. - Clear UV / OV PMIC power-on reset event for non-USB power supplies
If the Pi is powered through the 40-pin header then it's possible for
the under-voltage or under-voltage PMIC reset events to be set even
if the PMIC didn't actually reset. Mask out these bits in the
device-tree node to avoid suprious under-voltage warnings in the
desktop. - config: Switch more config string lookups to use the more effient macros
- plat_conf: Cache absent clock and pll overrides
- arm_loader_dvfs: Only update low voltage state when required
- power_2712: Cache last turbo state to avoid unneeded I2C accesses
2026-08-04: arm_mbox: Avoid slow calls every mbox message (latest)
- arm_mbox: Avoid slow calls every mbox message
They are only meant to be called every 100ms (arm_loader_update_throttled_status)
or 20ms (power_monitor_execute) but are called once per mbox message. - arm_2712: Avoid waiting for an already consumed latch
rtos_latch_try() acquires the latch if a message is already waiting
(the IRQ handler released it). - arm_dt: Store detected but unknown display ID in device tree
For DSI displays where the ID provided by the MCU is unknown,
store the value read in device tree so that userspace can do
something. - arm_loader_dvfs: Make enable request on unset clock quieter
The current kernel does trigger this path during initialisation.
Pull in RP1 firmware at d6df137696bdb672690a9f5117b332d2dc5bae47 - camera_subsystem: Account for CSS_CMD_DELAY with the read cache
Store the elapsed time of the I2C read in the cache so that we correctly
account for any CSS_CMD_DELAY commands in the read sequence and ensure
they are correcly handled if cached. - camera_subsystem: Cache the I2C transactions for efficiency where possible
Some sensors share the same I2C address and id register locations, so
we might save a few ms by caching i2c transactions in such cases. - camera_subsystem: Cull unused cameras from the table
These are never used and make the table noisy
Pull in RP1 firmware at 1facd6e6fc3a1caaa3e3a225e5b5d9eb63471e16 - camera: Add autodetect for imx355 and imx662
2026-06-29: Fix auto_initramfs take 3 (latest)
- Fix auto_initramfs take 3
The previous fix to avoid a double os_prefix in the initramfs path was
wrong in three ways:- It ignored the os_prefix when checking for the existence of the
matching initramfs file. - It didn't use any absolute path in kernel_file= when looking for the
initramfs. - It created a whole new path when one already existed.
See: https://forums.raspberrypi.com/viewtopic.php?t=399185
- It ignored the os_prefix when checking for the existence of the
- Revert "arm_ldconfig: Avoid double os_prefix on initramfs"
This reverts commit 3992d6660028925ddde17479ddd949a857ef6cd7.
See: https://forums.raspberrypi.com/viewtopic.php?t=399185 - dtoverlay: Permit writing dtb phandles
Overwriting a phandle in a base DTB is usual a bad idea, but there are
cases where doing so (or writing one into a target node that doesn't
yet have one) can be useful. Rather than trying to do something clever
and/or time-consuming, invent a magic property that enables such
overwriting on a per-fragment basis.
2026-06-17: rpi-fw-crypto fine-grained locking (latest)
- rpi-fw-crypto fine-grained locking
Crypto operations can be individually locked per key until after reboot
using rpi-fw-crypto set-key-status. Reading, signing, hmac, setting key usage
and generating a key can each individually be locked. Setting key usage and
generating a key can be locked with lock_device_key_write=1 in config.txt. - Use UTC for BUILD_DATE and BUILD_TIME
Expand BUILD_TIMESTAMP using (date -u) for the human readable
date / timestamp strings.
See: #850 - fix wrap issue with platform_stc64
It is unsafe to read lo and hi registers separately
around the wrap point (every 71m) - gencmd: Disable pmicrd and pmicwr if secure-boot is enabled
- arm_dt: Avoid incompatible overlay memory leak
Overlay loading is now aborted early if the overlay map says that it
isn't compatible. Unfortunately that error path leaked the memory used
to hold any parameters passed to the overlay. Plug the leak. - Stop the heartbeat with the watchdog
There is no reason to keep the watchdog heartbeat going when the
watchdog is stopped. Ensure the heartbeat is also stopped.
See: raspberrypi/firmware#2023 - arm_dt: Defer overlay_map loading until needed
There is no need to load the overlay map if overlays are not being used.
Defer the loading of overlay_map until it is actually needed, saving a
few tens of milliseconds. - arm_dt: Drop an overlay if remapping fails
If the process of overlay name remapping explicitly fails by returning
NULL, don't proceed to apply the overlay anyway - it has been rejected. - Avoid an unnecessary relocation
ARM64 kernels include a load address in the header, but others don't.
For those cases, treat an explicit kernel_address setting as gospel,
potentially avoiding an unnecessary relocation. - Set RP1 UART baud to the value configured in eeprom config
See: #765 - arm-loader: Restrict SET_VOLTAGE to core-voltage on Pi4 and newer.
With LPDDR4 the SDRAM is initialised by Broadcom's DPFE
firmware which does PHY training. Attempting to adjust the SDRAM
voltage independently of this will just make the system less stable
so switch off this legacy behavior on Pi4 and newer.
2026-05-27: Promote pieeprom-2026-05-26 to the default release (default)
2026-05-26: Make Pi 5 use the correct entropy source for kaslr-seed and rng-seed (latest)
- Make Pi 5 use the correct entropy source
The kernel looks to Device Tree for the rng-seed and kaslr-seed values
as sources of entropy. On Pi 5 the bootsys code enables the HWRNG, but
for historical reasons these two DT properties were not using the
resulting random data. Fix that.
2026-05-22: Allow string values to enable fragments (latest)
- Allow string values to enable fragments
It can be convenient to write a string value to a property and enable
the fragment containing the property with a single parameter. This
commit makes it possible, even when the string doesn't have an obvious
boolean value. If conditional (=,!) operators are used, a non-empty
string is true and an empty string is false.
See: raspberrypi/utils#183
2026-05-20: recovery: 2712: reboot order and reboot arg option (latest)
- recovery: 2712: reboot order and reboot arg option
Add support for set_reboot_order and set_reboot_arg1 in
recovery config.txt, so that recovery.bin can set them when
it has been loaded over rpiboot.
2026-05-17: rpi-fw-crypto can get and set key usage in otp (latest)
- rpi-fw-crypto can get and set key usage in otp
A key usage descriptor can be stored and read from otp to identify
what the key in otp is used for. The rpi-fw-crypto CLI provides
the interface to do so.
2026-05-13: 2712: Add support for A/B bootloader updates (latest)
- Add support for A/B bootloader updates.
- arm_loader_dvfs: Clock driver refactor support kernel FW clock driver improvements