Hi Jerry,
I tried the following command to perform the efuse for SBK and DK.
sudo ./odmfuse.sh -j -i 0x21 -c PKC -k rsa_priv.pem -D dk.bin -S sbk.bin
And it was successful.
The option -j is obsolete now. Jtag by default is enabled.
Please use "--disable-jtag" option if you want to burn the jtag-disable fuse.
Jtag can't be re-enabled once the jtag-disable fuse bit is burned.
*** Calculating HASH from keyfile /home/mayu/nvidia/nvidia_sdk/JetPack_4.6.4_Linux_JETSON_NANO_TARGETS/Linux_for_Tegra/rsa_priv.pem ... done
PKC HASH: 0x4b0e3186401bb2a05c063d1f866ee5524a6065f1febaa9b65ac0716cb1b46b03
*** Generating fuse configuration ... done.
*** Start fusing ...
./tegraflash.py --chip 0x21 --applet nvtboot_recovery.bin --cmd "blowfuses odmfuse_pkc.xml; reboot recovery"
Welcome to Tegra Flash
version 1.0.0
Type ? or help for help and q or quit to exit
Use ! to execute system commands
[ 0.0074 ] Parsing fuse info as per xml file
[ 0.0162 ] tegraparser --fuse_info odmfuse_pkc.xml blow_fuse_data.bin
[ 0.0182 ]
[ 0.0183 ] Generating RCM messages
[ 0.0394 ] tegrarcm --listrcm rcm_list.xml --chip 0x21 0 --download rcm nvtboot_recovery.bin 0 0
[ 0.0417 ] RCM 0 is saved as rcm_0.rcm
[ 0.0512 ] RCM 1 is saved as rcm_1.rcm
[ 0.0513 ] List of rcm files are saved in rcm_list.xml
[ 0.0513 ]
[ 0.0514 ] Signing RCM messages
[ 0.0672 ] tegrasign --key None --list rcm_list.xml --pubkeyhash pub_key.key
[ 0.0693 ] Assuming zero filled SBK key
[ 0.0941 ]
[ 0.0942 ] Copying signature to RCM mesages
[ 0.0966 ] tegrarcm --chip 0x21 0 --updatesig rcm_list_signed.xml
[ 0.0991 ]
[ 0.0992 ] Boot Rom communication
[ 0.1018 ] tegrarcm --chip 0x21 0 --rcm rcm_list_signed.xml
[ 0.1034 ] BR_CID: 0x32101001643c52c00000000002028240
[ 0.1363 ] RCM version 0X210001
[ 0.1799 ] Boot Rom communication completed
[ 1.1867 ]
[ 1.1868 ] Blowing fuses
[ 1.1912 ] tegrarcm --oem blowfuses blow_fuse_data.bin
[ 1.1938 ] Applet version 00.01.0000
[ 1.2662 ] Successfully burnt fuses as per fuse info blob
[ 1.2806 ]
[ 1.2809 ] Rebooting to recovery mode
[ 1.3088 ] tegradevflash --reboot recovery
[ 1.3116 ] Cboot is not running on device.
[ 1.3486 ]
[ 1.3488 ] Rebooting to recovery mode
[ 1.3526 ] tegrarcm --reboot recovery
[ 1.3549 ] Applet version 00.01.0000
[ 1.4348 ]
*** The fuse configuration is saved in bootloader/odmfuse_pkc.xml
*** The ODM fuse has been burned successfully.
*** done.
But in th log above it is saying that SBK is filled with zeros. Is this true?
[ 0.0693 ] Assuming zero filled SBK key
(Please note that I generated the skb.bin and dk.bin randomly. Means they are not hash values of any keys. I assumed they are symmetric keys. Also I did not add the -p option as I would like to try this first without locking the eFUSE.)
Here is the output of the odmfuse_pkc.xml
<genericfuse MagicId="0x46555345" version="1.0.0">
<fuse name="DeviceKey" size="8" value="0xddccbbaa" />
<fuse name="SecureBootKey" size="16" value="0x78563412785634127856341278563412" />
<fuse name="PublicKeyHash" size="32" value="0x4b0e3186401bb2a05c063d1f866ee5524a6065f1febaa9b65ac0716cb1b46b03" />
</genericfuse>
After that I issued the flash command and here is the output
sudo ./flash.sh BOARDID=3448 FAB=200 BOARDSKU=0002 -x 0x21 -y PKC -u rsa_priv.pem -D dk.bin -S sbk.bin jetson-nano-emmc mmcblk0p1
###############################################################################
# L4T BSP Information:
# R32 , REVISION: 7.4
###############################################################################
# Target Board Information:
# Name: jetson-nano-emmc, Board Family: t210ref, SoC: Tegra 210,
# OpMode: production, Boot Authentication: ,
# Disk encryption: disabled ,
###############################################################################
./tegraflash.py --chip 0x21 --applet "/home/mayu/nvidia/nvidia_sdk/JetPack_4.6.4_Linux_JETSON_NANO_TARGETS/Linux_for_Tegra/bootloader/nvtboot_recovery.bin" --skipuid --cmd "dump eeprom boardinfo cvm.bin"
Welcome to Tegra Flash
version 1.0.0
Type ? or help for help and q or quit to exit
Use ! to execute system commands
[ 0.0028 ] Generating RCM messages
[ 0.0040 ] tegrarcm --listrcm rcm_list.xml --chip 0x21 0 --download rcm /home/mayu/nvidia/nvidia_sdk/JetPack_4.6.4_Linux_JETSON_NANO_TARGETS/Linux_for_Tegra/bootloader/nvtboot_recovery.bin 0 0
[ 0.0049 ] RCM 0 is saved as rcm_0.rcm
[ 0.0056 ] RCM 1 is saved as rcm_1.rcm
[ 0.0056 ] List of rcm files are saved in rcm_list.xml
[ 0.0056 ]
[ 0.0056 ] Signing RCM messages
[ 0.0079 ] tegrasign --key None --list rcm_list.xml --pubkeyhash pub_key.key
[ 0.0089 ] Assuming zero filled SBK key
[ 0.0156 ]
[ 0.0156 ] Copying signature to RCM mesages
[ 0.0181 ] tegrarcm --chip 0x21 0 --updatesig rcm_list_signed.xml
[ 0.0198 ]
[ 0.0198 ] Boot Rom communication
[ 0.0222 ] tegrarcm --chip 0x21 0 --rcm rcm_list_signed.xml --skipuid
[ 0.0234 ] RCM version 0X210001
[ 0.1232 ] Boot Rom communication completed
[ 1.1303 ]
[ 1.1305 ] dump EEPROM info
[ 1.1351 ] tegrarcm --oem platformdetails eeprom /home/mayu/nvidia/nvidia_sdk/JetPack_4.6.4_Linux_JETSON_NANO_TARGETS/Linux_for_Tegra/bootloader/cvm.bin
[ 1.1379 ] Applet version 00.01.0000
[ 1.2127 ] Saved platform info in /home/mayu/nvidia/nvidia_sdk/JetPack_4.6.4_Linux_JETSON_NANO_TARGETS/Linux_for_Tegra/bootloader/cvm.bin
[ 1.2887 ]
[ 1.2933 ] tegrarcm --reboot recovery
[ 1.2960 ] Applet version 00.01.0000
[ 1.3686 ]
Board ID(3448) version(401)
copying bctfile(/home/mayu/nvidia/nvidia_sdk/JetPack_4.6.4_Linux_JETSON_NANO_TARGETS/Linux_for_Tegra/bootloader/t210ref/BCT/P3448_A00_lpddr4_204Mhz_P987.cfg)... done.
copying bootloader(/home/mayu/nvidia/nvidia_sdk/JetPack_4.6.4_Linux_JETSON_NANO_TARGETS/Linux_for_Tegra/bootloader/t210ref/cboot.bin)... done.
copying initrd(/home/mayu/nvidia/nvidia_sdk/JetPack_4.6.4_Linux_JETSON_NANO_TARGETS/Linux_for_Tegra/bootloader/l4t_initrd.img)... done.
Making Boot image... done.
Existing sosfile(/home/mayu/nvidia/nvidia_sdk/JetPack_4.6.4_Linux_JETSON_NANO_TARGETS/Linux_for_Tegra/bootloader/nvtboot_recovery.bin) reused.
copying tegraboot(/home/mayu/nvidia/nvidia_sdk/JetPack_4.6.4_Linux_JETSON_NANO_TARGETS/Linux_for_Tegra/bootloader/t210ref/nvtboot.bin)... done.
copying cpu_bootloader(/home/mayu/nvidia/nvidia_sdk/JetPack_4.6.4_Linux_JETSON_NANO_TARGETS/Linux_for_Tegra/bootloader/t210ref/cboot.bin)... done.
copying bpffile(/home/mayu/nvidia/nvidia_sdk/JetPack_4.6.4_Linux_JETSON_NANO_TARGETS/Linux_for_Tegra/bootloader/t210ref/sc7entry-firmware.bin)... done.
copying wb0boot(/home/mayu/nvidia/nvidia_sdk/JetPack_4.6.4_Linux_JETSON_NANO_TARGETS/Linux_for_Tegra/bootloader/t210ref/warmboot.bin)... done.
Existing tosfile(/home/mayu/nvidia/nvidia_sdk/JetPack_4.6.4_Linux_JETSON_NANO_TARGETS/Linux_for_Tegra/bootloader/tos-mon-only.img) reused.
Existing eksfile(/home/mayu/nvidia/nvidia_sdk/JetPack_4.6.4_Linux_JETSON_NANO_TARGETS/Linux_for_Tegra/bootloader/eks.img) reused.
./flash.sh: line 2661: [: : integer expression expected
copying dtbfile(/home/mayu/nvidia/nvidia_sdk/JetPack_4.6.4_Linux_JETSON_NANO_TARGETS/Linux_for_Tegra/kernel/dtb/tegra210-p3448-0002-p3449-0000-b00.dtb)... done.
Copying nv_boot_control.conf to rootfs
populating kernel to rootfs... done.
populating initrd to rootfs... done.
populating kernel_tegra210-p3448-0002-p3449-0000-b00.dtb to rootfs... done.
Making system.img...
populating rootfs from /home/mayu/nvidia/nvidia_sdk/JetPack_4.6.4_Linux_JETSON_NANO_TARGETS/Linux_for_Tegra/rootfs ... populating /boot/extlinux/extlinux.conf ... done.
Sync'ing system.img ... done.
Converting RAW image to Sparse image... done.
system.img built successfully.
Existing tbcfile(/home/mayu/nvidia/nvidia_sdk/JetPack_4.6.4_Linux_JETSON_NANO_TARGETS/Linux_for_Tegra/bootloader/nvtboot_cpu.bin) reused.
copying tbcdtbfile(/home/mayu/nvidia/nvidia_sdk/JetPack_4.6.4_Linux_JETSON_NANO_TARGETS/Linux_for_Tegra/kernel/dtb/tegra210-p3448-0002-p3449-0000-b00.dtb)... done.
copying cfgfile(/home/mayu/nvidia/nvidia_sdk/JetPack_4.6.4_Linux_JETSON_NANO_TARGETS/Linux_for_Tegra/bootloader/t210ref/cfg/flash_l4t_t210_emmc_p3448.xml) to flash.xml... done.
copying flasher(/home/mayu/nvidia/nvidia_sdk/JetPack_4.6.4_Linux_JETSON_NANO_TARGETS/Linux_for_Tegra/bootloader/t210ref/cboot.bin)... done.
Existing flashapp(/home/mayu/nvidia/nvidia_sdk/JetPack_4.6.4_Linux_JETSON_NANO_TARGETS/Linux_for_Tegra/bootloader/tegraflash.py) reused.
./tegraflash.py --bl cboot.bin --bct P3448_A00_lpddr4_204Mhz_P987.cfg --odmdata 0xa4000 --bldtb kernel_tegra210-p3448-0002-p3449-0000-b00.dtb --applet nvtboot_recovery.bin --cmd "flash; reboot" --cfg flash.xml --chip 0x21 --bins "EBT cboot.bin; DTB tegra210-p3448-0002-p3449-0000-b00.dtb"
saving flash command in /home/mayu/nvidia/nvidia_sdk/JetPack_4.6.4_Linux_JETSON_NANO_TARGETS/Linux_for_Tegra/bootloader/flashcmd.txt
saving Windows flash command to /home/mayu/nvidia/nvidia_sdk/JetPack_4.6.4_Linux_JETSON_NANO_TARGETS/Linux_for_Tegra/bootloader/flash_win.bat
assign_value: crc-flash.xml.bin 1 131056 1
printf '\x1' | dd of=crc-flash.xml.bin bs=1 seek=131056 count=1 conv=notrunc
1+0 records in
1+0 records out
1 byte copied, 0.000107281 s, 9.3 kB/s
assign_value: crc-flash.xml.bin 0 131057 1
printf '\x0' | dd of=crc-flash.xml.bin bs=1 seek=131057 count=1 conv=notrunc
1+0 records in
1+0 records out
1 byte copied, 0.000121686 s, 8.2 kB/s
assign_string: crc-flash.xml.bin PTHD 131064 4
echo PTHD | dd of=crc-flash.xml.bin bs=1 seek=131064 count=4 conv=notrunc
4+0 records in
4+0 records out
4 bytes copied, 6.4855e-05 s, 61.7 kB/s
*** Flashing target device started. ***
Welcome to Tegra Flash
version 1.0.0
Type ? or help for help and q or quit to exit
Use ! to execute system commands
[ 0.0206 ] tegrasign --getmode mode.txt --key None
[ 0.0222 ] Assuming zero filled SBK key
[ 0.0340 ]
[ 0.0344 ] Generating RCM messages
[ 0.0480 ] tegrarcm --listrcm rcm_list.xml --chip 0x21 0 --download rcm nvtboot_recovery.bin 0 0
[ 0.0509 ] RCM 0 is saved as rcm_0.rcm
[ 0.0593 ] RCM 1 is saved as rcm_1.rcm
[ 0.0593 ] List of rcm files are saved in rcm_list.xml
[ 0.0593 ]
[ 0.0594 ] Signing RCM messages
[ 0.0636 ] tegrasign --key None --list rcm_list.xml --pubkeyhash pub_key.key
[ 0.0658 ] Assuming zero filled SBK key
[ 0.0762 ]
[ 0.0763 ] Copying signature to RCM mesages
[ 0.0791 ] tegrarcm --chip 0x21 0 --updatesig rcm_list_signed.xml
[ 0.0811 ]
[ 0.0811 ] Parsing partition layout
[ 0.0836 ] tegraparser --pt flash.xml.tmp
[ 0.0854 ]
[ 0.0856 ] Using default ramcode: 0
[ 0.0856 ] Disable BPMP dtb trim, using default dtb
[ 0.0856 ]
[ 0.0856 ] Creating list of images to be signed
[ 0.0881 ] tegrahost --chip 0x21 0 --partitionlayout flash.xml.bin --list images_list.xml
[ 0.1739 ]
[ 0.1740 ] Generating signatures
[ 0.1788 ] tegrasign --key None --list images_list.xml --pubkeyhash pub_key.key
[ 0.1811 ] Assuming zero filled SBK key
[ 0.3089 ]
[ 0.3089 ] Generating br-bct
[ 0.3126 ] tegrabct --bct P3448_A00_lpddr4_204Mhz_P987.cfg --chip 0x21 0
[ 0.3493 ]
[ 0.3493 ] Updating boot device parameters
[ 0.3518 ] tegrabct --bct P3448_A00_lpddr4_204Mhz_P987.bct --chip 0x21 0 --updatedevparam flash.xml.bin
[ 0.3529 ] Warning: No sdram params
[ 0.3532 ]
[ 0.3533 ] Updating bl info
[ 0.3558 ] tegrabct --bct P3448_A00_lpddr4_204Mhz_P987.bct --chip 0x21 0 --updateblinfo flash.xml.bin --updatesig images_list_signed.xml
[ 0.3579 ]
[ 0.3579 ] Updating secondary storage information into bct
[ 0.3603 ] tegraparser --pt flash.xml.bin --chip 0x21 0 --updatecustinfo P3448_A00_lpddr4_204Mhz_P987.bct
[ 0.3620 ]
[ 0.3621 ] Updating Odmdata
[ 0.3647 ] tegrabct --bct P3448_A00_lpddr4_204Mhz_P987.bct --chip 0x21 0 --updatefields Odmdata =0xa4000
[ 0.3660 ] Warning: No sdram params
[ 0.3664 ]
[ 0.3664 ] Get Signed section of bct
[ 0.3692 ] tegrabct --bct P3448_A00_lpddr4_204Mhz_P987.bct --chip 0x21 0 --listbct bct_list.xml
[ 0.3711 ]
[ 0.3712 ] Signing BCT
[ 0.3769 ] tegrasign --key None --list bct_list.xml --pubkeyhash pub_key.key
[ 0.3781 ] Assuming zero filled SBK key
[ 0.3790 ]
[ 0.3790 ] Updating BCT with signature
[ 0.3816 ] tegrabct --bct P3448_A00_lpddr4_204Mhz_P987.bct --chip 0x21 0 --updatesig bct_list_signed.xml
[ 0.3831 ]
[ 0.3832 ] Copying signatures
[ 0.3859 ] tegrahost --chip 0x21 0 --partitionlayout flash.xml.bin --updatesig images_list_signed.xml
[ 0.3958 ]
[ 0.3959 ] Updating BFS information on BCT
[ 0.3984 ] tegrabct --bct P3448_A00_lpddr4_204Mhz_P987.bct --chip 0x21 0 --updatebfsinfo flash.xml.bin
[ 0.3999 ] BFS:
[ 0.4017 ] 0: [PT ] crc-flash.xml.bin (size=131072/131072)
[ 0.4025 ] 1: [TBC] nvtboot_cpu.bin.encrypt (size=80672/196608)
[ 0.4032 ] 2: [RP1] kernel_tegra210-p3448-0002-p3449-0000-b00.dtb.encrypt (size=238224/1048576)
[ 0.4043 ] 3: [EBT] cboot.bin.encrypt (size=485952/655360)
[ 0.4049 ] 4: [WB0] warmboot.bin.encrypt (size=3952/131072)
[ 0.4052 ] 5: [BPF] sc7entry-firmware.bin.encrypt (size=3376/262144)
[ 0.4056 ] BFS0: 131072 @ 2560 SUM b6ad3ead over 2883584 bytes
[ 0.4061 ] BFS:
[ 0.4062 ] 0: [PT-1] crc-flash.xml.bin (size=131072/131072)
[ 0.4068 ] 1: [TBC-1] nvtboot_cpu.bin.encrypt (size=80672/196608)
[ 0.4074 ] 2: [RP1-1] kernel_tegra210-p3448-0002-p3449-0000-b00.dtb.encrypt (size=238224/1048576)
[ 0.4082 ] 3: [EBT-1] cboot.bin.encrypt (size=485952/655360)
[ 0.4088 ] 4: [WB0-1] warmboot.bin.encrypt (size=3952/131072)
[ 0.4093 ] 5: [BPF-1] sc7entry-firmware.bin.encrypt (size=3376/262144)
[ 0.4099 ] 8: [VER_b] emmc_bootblob_ver.txt (size=102/32768)
[ 0.4365 ] 9: [VER] emmc_bootblob_ver.txt (size=102/32768)
[ 0.4378 ] BFS1: 131072 @ 8704 SUM b6ad3ead over 2981888 bytes
[ 0.4386 ] KFS:
[ 0.4782 ] 0: [DTB] kernel_tegra210-p3448-0002-p3449-0000-b00.dtb.encrypt (size=238224/1048576)
[ 0.4793 ] 1: [TOS] tos-mon-only.img.encrypt (size=54208/6291456)
[ 0.4800 ] 2: [EKS] eks.img (size=1028/81920)
[ 0.5240 ] 3: [LNX] boot.img.encrypt (size=667648/67092480)
[ 0.5259 ] KFS0: 1048576 @ 29376546 SUM c97b90a6 over 8089600 bytes
[ 0.5365 ] KFS:
[ 0.5716 ] 0: [DTB-1] kernel_tegra210-p3448-0002-p3449-0000-b00.dtb.encrypt (size=238224/1048576)
[ 0.5727 ] 1: [TOS-1] tos-mon-only.img.encrypt (size=54208/6291456)
[ 0.5733 ] 2: [EKS-1] eks.img (size=1028/81920)
[ 0.5737 ] 3: [LNX-1] boot.img.encrypt (size=667648/67092480)
[ 0.5742 ] KFS1: 1048576 @ 29522082 SUM c97b90a6 over 8089600 bytes
[ 0.5777 ]
[ 0.5777 ] Boot Rom communication
[ 0.5800 ] tegrarcm --chip 0x21 0 --rcm rcm_list_signed.xml
[ 0.5811 ] BR_CID: 0x32101001643c52c00000000002028240
[ 0.6099 ] RCM version 0X210001
[ 0.6577 ] Boot Rom communication completed
[ 1.6649 ]
[ 1.6651 ] Sending BCTs
[ 1.6695 ] tegrarcm --download bct P3448_A00_lpddr4_204Mhz_P987.bct
[ 1.6722 ] Applet version 00.01.0000
[ 1.7445 ] Sending bct
[ 1.7492 ] [................................................] 100%
[ 1.7492 ] 0000000b: Verification failed
[ 1.7493 ]
[ 1.7493 ]
Error: Return value 11
Command tegrarcm --download bct P3448_A00_lpddr4_204Mhz_P987.bct
Failed flashing t210ref.
I am getting the error code 11. Are there any explanation for this error code?
I tried multiple times and getting same error.
Any idea to solve this? I still can perform the flashing to the board and it is wornderful if you share any way to make it working again.
After checking this link it is mentioned that this SKB must be programmed when pkc_disable=0 for Nano device.
For Jetson TX1 and Jetson Nano, this key must be used along with PKC key and pkc_disable = 0. This key will not be used to encrypt Bootloaders, it can be used by the high-level application as encryption key.
is this the reason for this failure?