github raspberrypi/rpi-imager v2.0.12

6 hours ago

What's changed

  • Embedded (Raspberry Pi network installer):
    • See a network that comes up late. Imager cached "offline" and only the
      netlink monitor cleared it, which embedded mode never started, so a PHY
      slow to negotiate (the Pi 5 Rev 1.2's MXL86110) was still down at the
      first poll and the installer never saw a network at all.
    • Wait for a usable address, not just a link, before fetching the OS list:
      a link is up before DHCP answers, and the old check took a link-local
      169.254 address for an IP.
    • Hold the fetch back while the clock reads earlier than the source Imager
      was built from. With no time service and no RTC battery a board boots at
      1970, and every certificate is then not yet valid. The installer image
      now sets the clock from downloads.raspberrypi.com before Imager starts.
    • Try a failed first OS list fetch again after 30 seconds. Embedded has no
      Retry button and stops polling once the network looks ready, so a fetch
      made a moment too early was the only one there would be.
    • Sign in to Raspberry Pi Connect with a code: a QR code, the address to
      visit on any device and the short code, then wait for approval. The
      browser sign-in cannot run without a browser or the rpi-imager:// scheme.
    • Import SSH public keys from a GitHub username, since there is no
      clipboard or file picker to bring a key in any other way. Unknown users,
      accounts with no keys, network failures and replies that are not a key
      list (a captive portal's page) are each reported and add nothing.
    • Make the Done screen's Reboot button reboot. It ran /sbin/reboot, which
      the installer image does not have, and ignored the failure.
    • Fit the UI to its design canvas instead of the panel's DPI, so it is
      laid out the same on every display.
  • Raspberry Pi Connect:
    • Write the access token from the device-code sign-in as rpi-connect's
      state.json for the configured user. It is already signed in, and written
      as auth.key it would be ignored. Auth keys still go to auth.key.
    • Enable rpi-connect's units where systemctl --user enable puts them:
      the sign-in path and wayvnc are wanted by rpi-connect.service, not by
      paths.target and default.target, so is-enabled reports them correctly.
    • Keep the step configured when its token has been spent.
  • OS Customisation:
    • Store and write the Wi-Fi passphrase rather than a PBKDF2-derived key.
      A derived key cannot negotiate WPA3/SAE, so NetworkManager fell back to
      WPA2 or failed on SAE-only networks. A key saved by an earlier version is
      dropped from the settings file; a 64-hex raw key is still accepted.
    • Escape the passphrase for NetworkManager's keyfile where imager_custom
      writes it unescaped: a backslash or a leading space was lost on load.
    • Write UTF-8 into cloud-init YAML as characters, not escapes.
  • Write reliability:
    • A cancelled write no longer reports success: a cancel during
      customisation showed the done screen for a half-written device.
    • Refuse a short download, and a truncated .img.xz -- the format every
      Raspberry Pi image ships in -- instead of writing part of an image and
      calling it a success. Size an image by its content, not its name.
    • Stop an abandoned or timed-out write touching the caller's buffer or a
      descriptor closed under it, and keep a failed write's errno; a failed
      final flush no longer calls std::terminate().
    • Linux: write sequentially at the logical cursor, reap io_uring
      completions while waiting for a buffer slot, and wait for the partition
      node before mounting after a format. Recycle ring buffer slots by
      identity, and let the direct-I/O reopen fall back to a shared handle.
    • Run the post-write eject in the background with live status; on macOS,
      give slow drives time to flush, unmount off the main thread, skip queued
      writes once cancelled and wait for pending writes before cleanup.
    • Windows: record why a write failed, clear stale error codes, and detach
      a virtual disk instead of ejecting its media.
    • Trim a preallocated cache file to what was written, and replace the
      cache file rather than following a link planted at its path.
  • Security (elevated runs):
    • Create the settings file as the invoking user, and reclaim ownership
      without following links: root could be led to create it anywhere a
      symlinked settings directory pointed, then hand it to the user.
    • Read SSH keys and write exports as the invoking user, register the URI
      handler as the user, keep trusted caches root-owned, and restore the
      user's HOME under sudo and pkexec.
    • Bound the sizes, lifetimes and inputs the write path trusts; refuse
      malformed FAT, EEPROM and STP structures; on macOS, sign only a SHA-256
      digest.
  • Compute Module (rpiboot / fastboot):
    • Follow the fastboot gadget through the bootstrap handover, so a board
      part-way through it is not shown as an unrelated device; serve recovery
      files the way recovery.bin asks for them.
    • Report a bootstrap that failed and a flash that stopped part way; tell a
      transport failure from a device denial; check for cancel between erase
      stages.
  • Interface and localisation:
    • Describe internal eMMC as eMMC, not as an SD card reader, which invited
      overwriting an eMMC system drive (#1658).
    • Load the regional translation for a regional locale: Brazilian
      Portuguese and Traditional Chinese never loaded (#1572). Match each
      system language in turn, and translate the remaining Spanish strings.
    • Share one label/field grid across the customisation steps, use the
      width a resized window offers, elide rather than clip combo box text,
      let footer buttons shrink for longer translations, and keep write
      errors visible.
    • Make nested step controls reachable by keyboard, keep the OS selection
      across a list refresh, order a local OS list as its manifest does, and
      set the window icon on Linux.
  • Windows:
    • Generate secure boot keys with CNG and drop OpenSSL; build boot.img in
      process rather than through diskpart; installer improvements.
  • Build / packaging:
    • Move to Qt 6.11.2, carrying the qtbase fix for a fontconfig crash that
      segfaulted the AppImage on some systems (#1756). Qt patches now fail the
      build when they do not apply. Build testlib into every Qt.
    • Extract the Qt source without restoring ownership, which the rootless
      release chroots cannot do; fix the CLI-only build's missing include.
    • Bundle the xcb helper libraries in AppImages, drop the stale libfuse2
      dependency, and compress the macOS DMG without deprecated verbs.
    • Vendor Nayuki's qrcodegen (MIT) for the Connect sign-in QR code.
  • Testing:
    • A test suite across the write path, extraction, FAT, rpiboot, fastboot,
      the CLI, the QML wizard (QuickTest) and Windows, with opt-in coverage and
      sanitiser builds. ThreadSanitizer runs found and fixed data races in the
      CA bundle lookup, the icon fetcher and the drive list poll thread.

PRs

  • Ensure necessary submodule tags are fetched by @roliver-rpi in #1698
  • Translate remaining Spanish strings in Imager by @amah853 in #1626
  • fix(zstd): test the content-size sentinels by name by @elibosley in #1701
  • fastboot: tell a transport failure apart from a device denial by @elibosley in #1702
  • fix(io): let the direct-I/O reopen degrade to a shared handle by @elibosley in #1703
  • fix: a cancelled write no longer reports success by @elibosley in #1704
  • fix(linux): wait for the partition node before the post-format mount by @elibosley in #1705
  • feat(gui): run the post-write eject in the background with live status by @elibosley in #1685
  • 2.0.11.2: Prune bogus libfuse2 dependency by @tdewey-rpi in #1712
  • fix(locale): line up the localisation fields in one grid by @4RH1T3CT0R7 in #1714
  • Fixup 'long' translations by @tdewey-rpi in #1716
  • fix(windows): Show installer location page, check if known location is good before use by @tdewey-rpi in #1715
  • 2.0.12: Embedded mode scaling, Linux small-buffer async IO handling by @tdewey-rpi in #1717
  • Improve Windows installer by @bovirus in #1722
  • packaging: bundle the xcb helper libraries in AppImages by @tdewey-rpi in #1723
  • Dev/roliver/timeout hazards and coverage by @roliver-rpi in #1724
  • 2.0.12: Coverage grinding, bugfixes by @tdewey-rpi in #1730
  • Fix local manifest sorting for URL-encoded filenames by @phattmatt in #1728
  • 2.0.12: Fuzzing, TSAN & hardening by @tdewey-rpi in #1738
  • fix(customisation): write UTF-8 into cloud-init YAML as characters by @4RH1T3CT0R7 in #1745
  • Improve regional translation support by @tdewey-rpi in #1746
  • fix(drivelist): name internal eMMC as eMMC, not an SD card reader by @tdewey-rpi in #1750
  • Fix macOS crash when cancelling an SD card write by @tdewey-rpi in #1751
  • Replace the cache file instead of following links at its path by @tdewey-rpi in #1758
  • Do elevated file work in the user's home as the user by @tdewey-rpi in #1759
  • fix(fetch): distinguish URL normalisation from redirects by @yuefdev in #1737
  • fix(linux): reap io_uring completions while waiting for a ring buffer slot by @yuefdev in #1732
  • Turn picked file urls into paths, and build folder urls from paths by @tdewey-rpi in #1761
  • Hand back an elevated run's leftovers before ImageWriter starts by @tdewey-rpi in #1762
  • 2.0.12: macOS: cancelled write handling. by @tdewey-rpi in #1763
  • Set the window icon on Linux, resolved through PlatformQuirks by @tdewey-rpi in #1764
  • Move to Qt 6.11.2, carrying the fontconfig crash fix by @tdewey-rpi in #1765
  • Build testlib into every Qt by @tdewey-rpi in #1766
  • Fix three data races found by ThreadSanitizer by @tdewey-rpi in #1767
  • Fix the CLI-only build and Qt 6.11.2 extraction in the release chroots by @tdewey-rpi in #1769
  • Embedded: see a late link, wait for an address and a believable clock, retry the first OS list by @tdewey-rpi in #1768
  • Embedded: SSH keys from GitHub, a Reboot that reboots, and Connect sign-in with a phone by @tdewey-rpi in #1770
  • Store and write the Wi-Fi passphrase, not a derived PSK by @tdewey-rpi in #1747

New Contributors

Full Changelog: v2.0.11.1...v2.0.12

Don't miss a new rpi-imager release

NewReleases is sending notifications on new releases.