Old forum answers often say "run sudo rpi-update" to fix a problem. On a device that has to keep working, that's usually the wrong move.
What it actually does
rpi-update replaces the kernel, kernel modules, firmware (and, unless skipped, the bootloader EEPROM images) with the latest bleeding-edge builds. Its own README says:
- There is always the possibility of regressions.
- Use it only with a good reason: to help test, or to get a fix that has been pushed for a bug you're affected by, until it arrives through normal releases.
- It's intended only for Raspberry Pi OS. With other distributions, and especially ones that ship a custom kernel, it's almost certainly not safe.
- Back up before updating.
Fixes reach Raspberry Pi OS through sudo apt update && sudo apt full-upgrade once they're considered well tested. That's the update path for production devices.
If you really need it
sudo rpi-update # latest pre-release firmware + kernel
sudo rpi-update <git-hash> # a specific revision from raspberrypi/rpi-firmware
sudo rpi-update pulls/<PR> # build from a raspberrypi/linux pull request (kept 90 days)
Useful environment options from the README:
| Variable | Effect |
|---|---|
SKIP_BOOTLOADER=1 |
update everything except the bootloader EEPROM images |
SKIP_KERNEL=1 |
keep the kernel and modules (firmware may depend on a newer kernel, so use with care) |
ROOT_PATH=… BOOT_PATH=… |
offline update of a mounted SD card (set both or neither) |
To go back to the packaged bootloader images after an rpi-update, the README gives:
sudo rm -rf /lib/firmware/raspberrypi/bootloader-2711
sudo rm -rf /lib/firmware/raspberrypi/bootloader-2712
sudo apt reinstall rpi-eeprom
For fleets
Test a pinned rpi-update revision on a few devices, not the whole fleet. Better still, wait for the fix in apt or build it into your own image (see the custom-image item), so every device runs a known, reproducible combination.