Pi & hardware
Verify a downloaded OS image before writing it
A checksum answers whether your file matches a published value. It does not answer every question about the release or the hardware it will run on.
Start from the release page
Open the official Sunstead DIY page and identify the intended board, release filename, checksum and release status. Download the image linked there. Avoid choosing a similarly named file from an old bookmark or an unrelated mirror.
The current community image is for Raspberry Pi 5. An application source archive is not an operating-system image. Confirm the file type before calculating a hash so you do not successfully verify the wrong artifact.
Hash the exact file named by the checksum
If the published SHA-256 applies to the compressed .img.xz download, calculate the hash of that compressed file. A decompressed image has different bytes and therefore a different hash. Do not compare hashes for different stages of the download.
On Windows, Microsoft documents Get-FileHash for this purpose. An example with a placeholder path is:
Get-FileHash -LiteralPath 'C:\Downloads\your-image.img.xz' -Algorithm SHA256Replace the path with the actual downloaded file. This command reads the file and prints its hash; it does not write an SD card or install anything.
Compare the whole value
Compare all hexadecimal characters with the value for that exact release. Letter case is not significant, but missing or different characters are. Do not accept a match based only on the first few characters.
When the values differ
Check the filename and whether the download completed. Confirm that the release page has not changed to a newer version. Download again from the official source if necessary, then recalculate. If the mismatch remains, stop using that file and report the release, filename and both values.
A checksum from the same untrusted location as an untrusted file does not independently establish authenticity. The official source and the matching bytes are separate parts of the check.
Keep three checks distinct
- Download check: the file matches its published hash.
- Write verification: the imaging tool verifies what it wrote to the selected card.
- Boot and application check: the intended hardware starts and operates as expected.
Passing the first check does not guarantee the third. Sunstead’s current DIY release explicitly notes that physical first-boot verification is pending. Preserve that limitation in your decision even when the hash matches.
Save a compact evidence note
Record the release URL, download date, filename, published checksum and your calculated result. Include the target board and later card-write verification result. This lets another person reproduce your preparation without guessing which file you used.
Only proceed to imaging after confirming the correct target drive and backing up anything needed from it. Image writing erases that drive. The hash command above is deliberately separate from that destructive step.
If a later boot fails, this record rules out some possibilities while leaving others open. It is useful evidence, not a universal certificate that the entire installation is healthy.
Sources & further reading
Documentation checked October 10, 2026.
Your next step
Check the release and checksum