Unlike older models, the Raspberry Pi 4, 400, 5, 500/500+ and Compute Modules 4/5 boot from a bootloader stored in an SPI EEPROM, not from files on the SD card. The rpi-eeprom package manages it.
How updates happen by default
- On Raspberry Pi OS the
rpi-eeprom-updatesystemd service runs at every boot. If a newer bootloader image is available, it applies it and migrates your current bootloader configuration. - By default the image is staged: it is written to the boot partition and flashed at the next reboot (by
recovery.bin, or self-update on BCM2711). - Check the state any time:
sudo rpi-eeprom-update # shows CURRENT, LATEST and the release channel
rpi-eeprom-config # shows the current bootloader configuration
sudo rpi-eeprom-config --edit # edit it; the change is applied at the next reboot
Release channels
| Channel | What it is |
|---|---|
default |
latest factory-default image; updated for critical fixes, hardware support, and features after they've been tested in latest |
latest |
updated more often with the newest fixes and features |
Switch channels with raspi-config → Advanced Options → Bootloader Version.
Fleet control
- Pin a version: set
FREEZE_VERSION=1in the bootloader config. The update service then skips automatic updates. This is useful when several OS images or swapped SD cards would otherwise update devices at different times. Undoing it later requires bootingrecovery.binfrom an SD card. - Stop the service instead:
sudo systemctl mask rpi-eeprom-update(re-enable withunmask). - Minimum bootloader version: newer boards carry a manufacturing minimum (
MFG_VER).rpi-eeprom-updaterefuses to install older images, because they can leave new hardware unable to boot. Don't override this without a very good reason.
Power loss during an update
- Staged updates are the default.
- Immediate updates (
RPI_EEPROM_IMMEDIATE_UPDATE=1in/etc/default/rpi-eeprom-update) write the EEPROM while the system runs, viaflashromor, on Pi 5 with A/B enabled,rpi-eeprom-ab. If power is lost during aflashromupdate, you must re-flash the EEPROM with Raspberry Pi Imager's bootloader-restore image. - A/B updates (Pi 5, CM5 and the Pi 5 keyboard computers only) split the EEPROM into two partitions. The committed partition stays untouched until the new image is written and checked, which protects against power loss mid-update. While A/B is enabled, tools that write the EEPROM directly (such as
flashrom) no longer work. - On Pi 4/400,
flashromneeds extraconfig.txtoverlays that move analog audio to GPIO 12/13, which may clash with HATs.
Compute Modules
rpi-eeprom-update is disabled by default on CM4/CM4S; update their bootloader with usbboot (rpiboot) during provisioning. On CM5 the normal update service applies.
Recovery
To reset the bootloader to factory defaults, write the EEPROM recovery image from Raspberry Pi Imager (Misc utility images) to a spare SD card and boot from it.