How to run the CA (hwkey-app) and TA (hwkey-agent) on target (Jetson AGX Xavier)

Continuing the discussion from How to run trusty samples on jetson Xavier?:

@JerryChang

dcapers@NUC-Ubuntu-18:~$ sudo minicom
[sudo] password for dcapers: 


Welcome to minicom 2.7.1                                                  
                                                                          
OPTIONS: I18n                                                                
Compiled on Aug 13 2017, 15:25:34.                                           
Port /dev/ttyUSB3, 14:40:18                                                  
                                                                             
Press CTRL-A Z for help on special keys                                      
                                                                             
��                                                                           
[0000.361] W> RATCHET: MB1 binary ratchet value 4 is too large than ratchet lev.
[0000.370] I> MB1 (prd-version: 1.5.1.6-t194-41334769-1740dd39)              
[0000.375] I> Boot-mode: Coldboot                                            
[0000.378] I> Chip revision : A02P                                           
[0000.381] I> Bootrom patch version : 15 (correctly patched)              
[0000.386] I> ATE fuse revision : 0x200                                   
[0000.390] I> Ram repair fuse : 0x0                                       
[0000.393] I> Ram Code : 0x2                                              
[0000.395] I> rst_source : 0x0                                            
[0000.398] I> rst_level : 0x0                                             
[0000.401] I> Boot-device: eMMC
[0000.416] I> sdmmc DDR50 mode
[0000.421] W> No valid slot number is found in scratch register
[0000.426] W> Return default slot: _a                                           
[0000.429] I> Active Boot chain : 0                                             
[0000.432] I> Boot-device: eMMC                                                 
[0000.437] W> MB1_PLATFORM_CONFIG: device prod data is empty in MB1 BCT.        
[0000.445] I> Temperature = 39000                                               
[0000.448] W> Skipping boost for clk: BPMP_CPU_NIC                              
[0000.453] W> Skipping boost for clk: BPMP_APB                                  
[0000.457] W> Skipping boost for clk: AXI_CBB                                   
[0000.460] W> Skipping boost for clk: AON_CPU_NIC                               
[0000.465] W> Skipping boost for clk: CAN1                                      
[0000.468] W> Skipping boost for clk: CAN2                                      
[0000.473] I> Boot-device: eMMC                                                 
[0000.476] I> Boot-device: eMMC                                                 
[0000.485] I> Sdmmc: HS400 mode enabled                                         
[0000.491] I> ECC region[0]: Start:0x0, End:0x0                                 
[0000.495] I> ECC region[1]: Start:0x0, End:0x0                                 
[0000.499] I> ECC region[2]: Start:0x0, End:0x0                                 
[0000.503] I> ECC region[3]: Start:0x0, End:0x0                                 
[0000.507] I> ECC region[4]: Start:0x0, End:0x0                                 
[0000.511] I> Non-ECC region[0]: Start:0x80000000, End:0x100000000              
[0000.517] I> Non-ECC region[1]: Start:0x0, End:0x0                             
[0000.522] I> Non-ECC region[2]: Start:0x0, End:0x0                             
[0000.526] I> Non-ECC region[3]: Start:0x0, End:0x0                             
[0000.530] I> Non-ECC region[4]: Start:0x0, End:0x0                             
[0000.536] E> FAILED: Thermal config                                            
[0000.543] E> FAILED: MEMIO rail config                                         
[0000.562] I> Boot-device: eMMC                                                 
[0000.573] I> sdmmc bdev is already initialized                                 
[0000.668] I> MB1 done                                                          
                                                                                
����main enter                                                                  
SPE VERSION #: R01.00.14 Created: Sep 19 2018 @ 11:03:21                        
HW Function test                                                                
Start Scheduler.                                                                
in late init                                                                    
��                                                                              
  [0000.677] I> Welcome to MB2(TBoot-BPMP) (version: 00.00.2018.32-mobile-feba5)
[0000.677] I> DMA Heap @ [0x526fa000 - 0x52ffa000]                              
[0000.678] I> Default Heap @ [0xd486400 - 0xd48a400]                            
[0000.678] E> DEVICE_PROD: Invalid value data = 70020000, size = 0.             
[0000.684] W> device prod register failed                                       
[0000.688] I> Boot-device: eMMC                                                 
[0000.691] I> Boot_device: SDMMC_BOOT instance: 3                               
[0000.697] I> sdmmc-3 params source = boot args                                 
[0000.700] I> sdmmc bdev is already initialized                                 
[0000.704] I> sdmmc-3 params source = boot args                                 
[0000.712] I> Found 17 partitions in SDMMC_BOOT (instance 3)                    
[0000.719] I> Found 42 partitions in SDMMC_USER (instance 3)                    
[0000.720] W> No valid slot number is found in scratch register                 
[0000.725] W> Return default slot: _a                                           
[0000.728] I> Active Boot chain : 0                                             
[0000.732] I> parsing oem signed section of bpmp-fw header done                 
[0000.737] I> bpmp-fw binary init read from storage                             
[0000.745] I> RSA PSS signature check: OK                                       
[0000.746] I> oem authentication of bpmp-fw header done                         
[0000.752] I> bpmp-fw binary done read from storage                             
[0000.755] I> bpmp-fw: Authentication init Done                                 
[0000.760] I> parsing oem signed section of cpubl header done                   
[0000.765] I> cpubl binary init read from storage                               
[0000.774] I> bpmp-fw: Authentication Finalize Done                             
[0000.776] I> RSA PSS signature check: OK                                       
[0000.778] I> oem authentication of cpubl header done                           
[0000.783] I> cpubl binary done read from storage                               
[0000.787] I> cpubl: Authentication init Done                                   
[0000.792] I> parsing oem signed section of rce header done                     
[0000.797] I> rce binary init read from storage                                 
[0000.801] I> Relocating BR-BCT                                                 
[0000.806] I> cpubl: Authentication Finalize Done                               
[0000.811] I> RSA PSS signature check: OK                                       
[0000.812] I> oem authentication of rce header done                             
[0000.817] I> rce binary done read from storage                                 
[0000.821] I> rce: Authentication init Done                                     
[0000.826] I> parsing oem signed section of ape header done                     
[0000.830] I> ape binary init read from storage                                 
[0000.836] I> rce: Authentication Finalize Done                                 
[0000.841] I> RSA PSS signature check: OK                                       
[0000.842] I> oem authentication of ape header done                             
[0000.847] I> ape binary done read from storage                                 
[0000.852] I> ape: Authentication init Done                                     
[0000.856] I> parsing oem signed section of tos header done                     
[0000.861] I> tos binary init read from storage                                 
[0000.866] I> ape: Authentication Finalize Done                                 
[0000.872] I> RSA PSS signature check: OK                                       
[0000.873] I> oem authentication of tos header done                             
[0000.878] I> tos binary done read from storage                                 
[0000.882] I> tos: Authentication init Done                                     
[0000.887] I> parsing oem signed section of bpmp-fw-dtb header done             
[0000.892] I> bpmp-fw-dtb binary init read from storage                         
[0000.899] I> tos: Authentication Finalize Done                                 
[0000.905] I> RSA PSS signature check: OK                                       
[0000.906] I> oem authentication of bpmp-fw-dtb header done                     
[0000.913] I> bpmp-fw-dtb binary done read from storage                         
[0000.915] I> bpmp-fw-dtb: Authentication init Done                             
[0000.920] I> parsing oem signed section of cpubl-dtb header done               
[0000.926] I> cpubl-dtb binary init read from storage                           
[0000.934] I> bpmp-fw-dtb: Authentication Finalize Done                         
[0000.970] I> RSA PSS signature check: OK                                       
[0000.971] I> oem authentication of cpubl-dtb header done                       
[0000.971] I> cpubl-dtb binary done read from storage                           
[0000.972] I> cpubl-dtb: Authentication init Done                               
[0000.974] I> parsing oem signed section of eks header done                     
[0000.974] I> eks binary init read from storage                                 
[0000.977] I> cpubl-dtb: Authentication Finalize Done                           
[0000.980] I> RSA PSS signature check: OK                                       
[0000.982] I> oem authentication of eks header done                             
[0000.986] I> eks binary done read from storage                                 
[0000.991] I> eks: Authentication init Done                                     
[0000.995] I> eks: Authentication Finalize Done                                 
[0000.999] I> EKB detected (length: 0x410) @ VA:0x5270a400                      
��NOTICE:  BL31: v1.3(release):                                                 
NOTICE:  BL31: Built : 06:18:46, Jun 22 2021                                    
ipc-unittest-main: 1519: Welcome to IPC unittest!!!                             
ipc-unittest-main: 1531: waiting forever                                        
ipc-unittest-srv: 329: Init unittest services!!!                                
hwkey-agent: 40: hwkey-agent is running!!                                       
hwkey-agent: 197: key_mgnt_processing .......                                   
hwkey-agent: 189: Setting EKB key 0 to slot 14                                  
hwkey-agent: 167: Init hweky-agent services!!                                   
luks-srv: 40: luks-srv is running!!                                             
luks-srv: 157: Init luks-srv IPC services!!                                     
platform_bootstrap_epilog: trusty bootstrap complete                            

I was able to get the same bootloader log as your JerryChang. My question is:

After flashing trusty tos.img onto the Xavier… Once booted up, can I run the hwkey-app from the command line? Or are there other steps I must do first?

hello dcapers44,

this CA, hwkey-app it provides encryption and decryption functions with the keys provided by TA, hwkey-agent.
you could compiling on host machine and copy the build to the target for testing,
if the compiler has been installed on the target, then you can move the code on the target and build it.

here’s sample command line to execute hwkey-app.
for example,
a file encryption with Trusty.
$ ./hwkey-app -e -i <input_file> -o <output_file> -t -p pkcs7
a file decryption with Trusty.
$ ./hwkey-app -d -i <input_file> -o <output_file> -t -p pkcs7

@JerryChang So every time I flash the target I have to manually copy the build from the host to the target… or move the code to the target and build it there? What method do you suggest to easily copy the build or source code to the target? It seems like this process would made easier…

hello dcapers44,

ya, the complete flash process will erase the board, overwrite the APP partition with the default system.img.
you could have build the binaries on your host machine, copy the binary to the target via ssh.
or, you could clone the system.img to back-up your root file system, perform flash script with -r options to reuse the back-up image.

@JerryChang Can I just build the binary on the host machine, copy the binary in the root file system (rootfs) under /Linux_for_Tegra, then flash the target with the copied binary on the rootfs?

Also, where is the $CROSS_COMPILERS suppose to point to? I am currently using the following:

export CROSS_COMPILER=$HOME/nvidia/l4t-gcc/gcc-linaro-7.3.1-2018.05-x86_64_aarch64-linux-gnu/bin/aarch64-linux-gnu-

hello dcapers44,

yes,
just to ensure the binary compatible with the release image,
you should make the binary file based-on the release sources as same as the JetPack release version.

please read the readme file, atf_and_trusty_README.txt
you should also refer to developer guide, Setting the CROSS_COMPILE Environment Variable.
thanks

how do you check for that. I’m using:
Tegra186_Linux_R32.5.1_aarch64.tbz2
gcc-linaro-7.3.1-2018.05-x86_64_arm-linux-gnueabihf.tar.xz
`gcc-linaro-7.3.1-2018.05-x86_64_aarch64-linux-gnu.tar.xz’

I built hwkey-app on the host machine and copy the /home/dcapers/nvidia/atf_and_trusty/trusty/trusty/app/nvidia-sample along with the binary into rootfs for target. After flashing the target, I tried to run ./hwkey-app but I’m getting an error.

dcapers@XavierAGXX01:~/app/nvidia-sample/hwkey-agent/CA_samples/out$ ./hwkey-app
bash:  ./hwkey-app:  cannot execute binary file:  Exec format error
dcapers@XavierAGXX01:~/app/nvidia-sample/hwkey-agent/CA_samples/out$ sudo ./hwkey-app
./hwkey-app: 1: ./hwkey-app:  ELF not found
./hwkey-app: 2: ./hwkey-app:  Syntax error:  word unexpected (expecting ")")

hello dcapers44,

please also refer to JetPack Archive, it shows each JetPack release and mapping to each l4t release version,
for example, JetPack-4.5.1 is using L4T version as R32.5.1.
please confirm you’re flashing with JetPack-4.5.1, while you’re building the binary with R32.5.1 sources.

instead of flashing the rootfs, you may copy the binary file to the target by ssh directly.
however, this error looks like your hwkey-app did not set as executable, please check $ ls -la hwkey-app for the file permission.

@JerryChang

dcapers@NUC-Ubuntu-18:~/nvidia/Linux_for_Tegra$ ls -lisa rootfs/home/dcapers/app/nvidia-sample/hwkey-agent/CA_sample/out/
total 896
25822785   4 drwxr-xr-x 4 root root   4096 Jun 25 13:27 .
25822891   4 drwxr-xr-x 8 root root   4096 Jun 24 16:43 ..
25822786 880 -rwxr-xr-x 1 root root 899608 Jun 25 13:27 hwkey-app
25822789   4 drwxr-xr-x 2 root root   4096 Jun 25 13:27 libtegracrypto
25822787   4 drwxr-xr-x 2 root root   4096 Jun 25 13:27 libtrusty

BTW… where is a good place to copy the binary to on the target after being flash… since all permission under “/” are set to 755? Do I need to change the permission for the the directory I copy the binary to?

hello dcapers44,

prior to copy the binary to the target, you could write the binary to /tmp/ folder on the target,
here’s commands for your reference, $ scp hwkey-app nvidia@192.168.55.1:/tmp/

usually, we don’t execute user-space application under “/” root directory.
you may consider to create the folder under “~”, it’s the path for default ubuntu user, root permission unnecessary.

@JerryChang So I was using the incorrect L4T version … I had R32.5.0. I reinstalled everything using the R32.5.1 L4T. I reinstalled the secure boot package and copy the tos.img into the /bootloader directory. I flashed my AGX Xavier and now it’s lock on the NVIDIA logo screen. I’m not sure why that is.

I did notice the at the secure boot package that I downloaded from https://developer.nvidia.com/embedded/linux-tegra is secureboot_R32.5.0_aarch64.tbz2. Should I be using secureboot_R32.5.1_aarch64.tbz2… if so where can I download it from…

hello dcapers44,

L4T 32.5.1 is identical to L4T 32.5 except for the new features to support TX2 NX and RT kernel package for Xavier.
could you please setup serial console and gather bootloader messages for booting failure.
thanks

Welcome to minicom 2.7.1

OPTIONS: I18n 
Compiled on Aug 13 2017, 15:25:34.
Port /dev/ttyUSB3, 02:14:55

Press CTRL-A Z for help on special keys

��
[0000.103] W> RATCHET: MB1 binary ratchet value 4 is too large than ratchet lev.
[0000.111] I> MB1 (prd-version: 1.5.1.6-t194-41334769-1740dd39)
[0000.117] I> Boot-mode: Coldboot
[0000.120] I> Chip revision : A02P
[0000.123] I> Bootrom patch version : 15 (correctly patched)
[0000.128] I> ATE fuse revision : 0x200
[0000.131] I> Ram repair fuse : 0x0
[0000.135] I> Ram Code : 0x2
[0000.137] I> rst_source : 0x0
[0000.140] I> rst_level : 0x0
[0000.143] I> Boot-device: eMMC
[0000.158] I> sdmmc DDR50 mode
[0000.162] W> No valid slot number is found in scratch register
[0000.168] W> Return default slot: _a                                           
[0000.171] I> Active Boot chain : 0                                             
[0000.174] I> Boot-device: eMMC                                                 
[0000.179] W> MB1_PLATFORM_CONFIG: device prod data is empty in MB1 BCT.        
[0000.187] I> Temperature = 24000                                               
[0000.190] W> Skipping boost for clk: BPMP_CPU_NIC                              
[0000.194] W> Skipping boost for clk: BPMP_APB                                  
[0000.198] W> Skipping boost for clk: AXI_CBB                                   
[0000.202] W> Skipping boost for clk: AON_CPU_NIC                               
[0000.207] W> Skipping boost for clk: CAN1                                      
[0000.210] W> Skipping boost for clk: CAN2                                      
[0000.215] I> Boot-device: eMMC                                                 
[0000.217] I> Boot-device: eMMC                                                 
[0000.227] I> Sdmmc: HS400 mode enabled                                         
[0000.232] I> ECC region[0]: Start:0x0, End:0x0                                 
[0000.237] I> ECC region[1]: Start:0x0, End:0x0                                 
[0000.241] I> ECC region[2]: Start:0x0, End:0x0                                 
[0000.245] I> ECC region[3]: Start:0x0, End:0x0                                 
[0000.249] I> ECC region[4]: Start:0x0, End:0x0                                 
[0000.253] I> Non-ECC region[0]: Start:0x80000000, End:0x100000000              
[0000.259] I> Non-ECC region[1]: Start:0x0, End:0x0                             
[0000.263] I> Non-ECC region[2]: Start:0x0, End:0x0                             
[0000.268] I> Non-ECC region[3]: Start:0x0, End:0x0                             
[0000.272] I> Non-ECC region[4]: Start:0x0, End:0x0                             
[0000.278] E> FAILED: Thermal config                                            
[0000.285] E> FAILED: MEMIO rail config                                         
[0000.303] I> Boot-device: eMMC                                                 
[0000.314] I> sdmmc bdev is already initialized                                 
[0000.410] I> MB1 done                                                          
                                                                                
����main enter                                                                  
SPE VERSION #: R01.00.14 Created: Sep 19 2018 @ 11:03:21                        
HW Function test                                                                
Start Scheduler.                                                                
in late init                                                                    
��                                                                              
  [0000.418] I> Welcome to MB2(TBoot-BPMP) (version: 00.00.2018.32-mobile-feba5)
[0000.419] I> DMA Heap @ [0x526fa000 - 0x52ffa000]                              
[0000.419] I> Default Heap @ [0xd486400 - 0xd48a400]                            
[0000.420] E> DEVICE_PROD: Invalid value data = 70020000, size = 0.             
[0000.426] W> device prod register failed                                       
[0000.429] I> Boot-device: eMMC                                                 
[0000.432] I> Boot_device: SDMMC_BOOT instance: 3                               
[0000.438] I> sdmmc-3 params source = boot args                                 
[0000.441] I> sdmmc bdev is already initialized                                 
[0000.445] I> sdmmc-3 params source = boot args                                 
[0000.454] I> Found 17 partitions in SDMMC_BOOT (instance 3)                    
[0000.460] I> Found 42 partitions in SDMMC_USER (instance 3)                    
[0000.461] W> No valid slot number is found in scratch register                 
[0000.466] W> Return default slot: _a                                           
[0000.469] I> Active Boot chain : 0                                             
[0000.473] I> parsing oem signed section of bpmp-fw header done                 
[0000.479] I> bpmp-fw binary init read from storage                             
[0000.486] I> RSA PSS signature check: OK                                       
[0000.487] I> oem authentication of bpmp-fw header done                         
[0000.494] I> bpmp-fw binary done read from storage                             
[0000.497] I> bpmp-fw: Authentication init Done                                 
[0000.501] I> parsing oem signed section of cpubl header done                   
[0000.506] I> cpubl binary init read from storage                               
[0000.515] I> bpmp-fw: Authentication Finalize Done                             
[0000.518] I> RSA PSS signature check: OK                                       
[0000.519] I> oem authentication of cpubl header done                           
[0000.524] I> cpubl binary done read from storage                               
[0000.528] I> cpubl: Authentication init Done                                   
[0000.534] I> parsing oem signed section of rce header done                     
[0000.538] I> rce binary init read from storage                                 
[0000.542] I> Relocating BR-BCT                                                 
[0000.548] I> cpubl: Authentication Finalize Done                               
[0000.552] I> RSA PSS signature check: OK                                       
[0000.553] I> oem authentication of rce header done                             
[0000.558] I> rce binary done read from storage                                 
[0000.562] I> rce: Authentication init Done                                     
[0000.567] I> parsing oem signed section of ape header done                     
[0000.572] I> ape binary init read from storage                                 
[0000.578] I> rce: Authentication Finalize Done                                 
[0000.582] I> RSA PSS signature check: OK                                       
[0000.584] I> oem authentication of ape header done                             
[0000.588] I> ape binary done read from storage                                 
[0000.593] I> ape: Authentication init Done                                     
[0000.598] I> parsing oem signed section of tos header done                     
[0000.602] I> tos binary init read from storage                                 
[0000.607] I> ape: Authentication Finalize Done                                 
[0000.613] I> RSA PSS signature check: OK                                       
[0000.614] I> oem authentication of tos header done                             
[0000.619] I> tos binary done read from storage                                 
[0000.623] I> tos: Authentication init Done                                     
[0000.628] I> parsing oem signed section of bpmp-fw-dtb header done             
[0000.633] I> bpmp-fw-dtb binary init read from storage                         
[0000.640] I> tos: Authentication Finalize Done                                 
[0000.646] I> RSA PSS signature check: OK                                       
[0000.647] I> oem authentication of bpmp-fw-dtb header done                     
[0000.655] I> bpmp-fw-dtb binary done read from storage                         
[0000.657] I> bpmp-fw-dtb: Authentication init Done                             
[0000.662] I> parsing oem signed section of cpubl-dtb header done               
[0000.667] I> cpubl-dtb binary init read from storage                           
[0000.675] I> bpmp-fw-dtb: Authentication Finalize Done                         
[0000.711] I> RSA PSS signature check: OK                                       
[0000.712] I> oem authentication of cpubl-dtb header done                       
[0000.712] I> cpubl-dtb binary done read from storage                           
[0000.713] I> cpubl-dtb: Authentication init Done                               
[0000.715] I> parsing oem signed section of eks header done                     
[0000.716] I> eks binary init read from storage                                 
[0000.718] I> cpubl-dtb: Authentication Finalize Done                           
[0000.721] I> RSA PSS signature check: OK                                       
[0000.723] I> oem authentication of eks header done                             
[0000.727] I> eks binary done read from storage                                 
[0000.732] I> eks: Authentication init Done                                     
[0000.736] I> eks: Authentication Finalize Done                                 
[0000.740] I> EKB detected (length: 0x410) @ VA:0x5270a400                      
��NOTICE:  BL31: v1.3(release):                                                 
NOTICE:  BL31: Built : 13:29:57, Jul  1 2021                                    
ipc-unittest-main: 1519: Welcome to IPC unittest!!!                             
ipc-unittest-main: 1531: waiting forever                                        
ipc-unittest-srv: 329: Init unittest services!!!                                
hwkey-agent: 40: hwkey-agent is running!!                                       
hwkey-agent: 197: key_mgnt_processing .......                                   
hwkey-agent: 162: ekb_verification: EKB_CMAC verification is not match.         
hwkey-agent: 240: key_mgnt_processing: failed (-7)                              
hwkey-agent: 44: main: Failed to verify or extract EKB (-7).                    
exit called, thread 0xffffffffea8a2d58, name trusty_app_2_92b92883-f96a-4177    
luks-srv: 40: luks-srv is running!!                                             
platform_bootstrap_epilog: trusty bootstrap complete                            
��                                                                              
                                                                                
welcome to lk                                                                   
calling constructors                                                            
initializing heap                                                               
creating bootstrap completion thread                                            
top of bootstrap2()                                                             
initializing platform                                                           
bpmp: platform_init                                                             
tag is e73a758761f0c6d24a1e69a2ac6b5035                                         
tag_show initialized                                                            
dt initialized                                                                  
mail initialized                                                                
chipid initialized                                                              
fuse initialized                                                                
sku initialized                                                                 
speedo initialized                                                              
ec_get_ec_list: found 45 ecs                                                    
ec initialized                                                                  
ec_mrq initialized                                                              
vmon_populate_monitors: found 3 monitors                                        
vmon initialized                                                                
adc initialized                                                                 
fmon_populate_monitors: found 73 monitors                                       
fmon initialized                                                                
fmon_mrq initialized                                                            
reset initialized                                                               
nvhs initialized                                                                
392 clocks registered                                                           
WARNING: pll_c4 has no dyn ramp                                                 
clk_mrq_init: mrq handler registered                                            
clk initialized                                                                 
nvlink initialized                                                              
io_dpd initialized                                                              
io_dpd initialized                                                              
thermal initialized                                                             
i2c5 controller initialized                                                     
initialized i2c mrq handling                                                    
i2c initialized                                                                 
regulator initialized                                                           
avfs_clk_platform initialized                                                   
soctherm initialized                                                            
aotag initialized                                                               
powergate initialized                                                           
dvs initialized                                                                 
pm initialized                                                                  
pg_late initialized                                                             
strap initialized                                                               
tag initialized                                                                 
emc initialized                                                                 
clk_dt initialized                                                              
avfs_ccplex_platform initialized                                                
tj_max: dt node not found                                                       
tj_init initialized                                                             
uphy_mrq_init: mrq handler registered                                           
uphy_dt initialized                                                             
uphy initialized                                                                
safereg_init: period 80 ms                                                      
ec_late initialized                                                             
��                                                                              
  [0001.242] I> Welcome to Cboot��mrq initialized                               
fmon_post initialized                                                           
��                                                                              
[0001.242] I> Cboot Version: t194-49acc5fe                                      
[0001.242] I> CPU-BL Params @ 0xf2820000                                        
[0001.243] I>  0) Base:0x00000000 Size:0x00000000                               
[0001.246] I>  1) Base:0xf1100000 Size:0x00100000                               
[0001.251] I>  2) Base:0xf2000000 Size:0x00200000                               
[0001.255] I>  3) Base:0xf1200000 Size:0x00200000                               
��clk_set_parent failed for clk i2c2, parent pll_aon (-22)                      
clk_set_parent failed for clk i2c8, parent pll_aon (-22)                        
clk_dt_late initialized                                                         
machine_check initialized                                                       
pm_post initialized                                                             
dbells initialized                                                              
avfs_clk_platform_post initialized                                              
dmce initialized                                                                
cvc initialized                                                                 
ccplex_avfs_hw_init: nafll_cluster0: not monitored                              
ccplex_avfs_hw_init: nafll_cluster1: not monitored                              
ccplex_avfs_hw_init: nafll_cluster2: not monitored                              
ccplex_avfs_hw_init: nafll_cluster3: not monitored                              
avfs_clk_mach_post initialized                                                  
regulator_post initialized                                                      
rm initialized                                                                  
sc7_diag initialized                                                            
thermal_test initialized                                                        
serial_late initialized                                                         
clk_post initialized                                                            
clk_dt_post initialized                                                         
mc_reg initialized                                                              
pg_post initialized                                                             
dyn_modules initialized                                                         
sku_debugfs initialized                                                         
speedo_debugfs initialized                                                      
adc_debugfs initialized                                                         
clk_debugfs initialized                                                         
��[0001.260] I>  4) Base:0xf1000000 Size:0x00100000                             
[0001.339] I>  5) Base:0xf0f00000 Size:0x00100000                               
[0001.344] I>  6) Base:0xf3800000 Size:0x00400000                               
[0001.348] I>  7) Base:0xf1c00000 Size:0x00400000                               
[0001.353] I>  8) Base:0xf0e00000 Size:0x00100000                               
[0001.357] I>  9) Base:0xf0d00000 Size:0x00100000                               
[0001.361] I> 10) Base:0xf3000000 Size:0x00800000                               
[0001.366] I> 11) Base:0x40000000 Size:0x00040000                               
[0001.370] I> 12) Base:0xf0c00000 Size:0x00100000                               
[0001.375] I> 13) Base:0x40046000 Size:0x00002000                               
[0001.379] I> 14) Base:0x40048000 Size:0x00002000��emc_debugfs initialized      
dvs_debugfs initialized                                                         
��                                                                              
[0001.389] I> 15) Base:0xac000000 Size:0x00004000                               
��fmon_debugfs initialized                                                      
vmon_debugfs initialized                                                        
pg_debugfs initialized                                                          
profile_fs initialized                                                          
debugfs_cons initialized                                                        
mail_fs initialized                                                             
profile initialized                                                             
cvc_debugfs initialized                                                         
dmce_debugfs initialized                                                        
ec_debugfs initialized                                                          
rm_debugfs initialized                                                          
soctherm_debug initialized                                                      
gr_reader initialized                                                           
mods initialized                                                                
dt_fs initialized                                                               
debugfs_mrq initialized                                                         
debug_mrq initialized                                                           
debug_safereg initialized                                                       
initializing target                                                             
calling apps_init()                                                             
starting app shell                                                              
entering main console loop                                                      
] ��[0001.393] I> 16) Base:0x4004a000 Size:0x00002000                           
[0001.443] I> 17) Base:0xf0b00000 Size:0x00100000                               
[0001.448] I> 18) Base:0x4004c000 Size:0x00002000                               
[0001.452] I> 19) Base:0xf2200000 Size:0x00600000                               
[0001.457] I> 20) Base:0x4004e000 Size:0x00002000                               
[0001.461] I> 21) Base:0xf0ad0000 Size:0x0000c000                               
[0001.466] I> 22) Base:0x00000000 Size:0x00000000                               
[0001.470] I> 23) Base:0xf0ae0000 Size:0x00020000                               
[0001.475] I> 24) Base:0xf6000000 Size:0x02000000                               
[0001.479] I> 25) Base:0x40050000 Size:0x00002000                               
[0001.484] I> 26) Base:0x40040000 Size:0x00006000                               
[0001.488] I> 27) Base:0xf1800000 Size:0x00400000                               
[0001.493] I> 28) Base:0xf4c00000 Size:0x01400000                               
[0001.497] I> 29) Base:0xf1400000 Size:0x00400000                               
[0001.501] I> 30) Base:0x00000000 Size:0x00000000                               
[0001.506] I> 31) Base:0x00000000 Size:0x00000000                               
[0001.510] I> 32) Base:0xf8000000 Size:0x08000000                               
[0001.515] I> 33) Base:0x00000000 Size:0x00000000                               
[0001.519] I> 34) Base:0xf3c00000 Size:0x01000000                               
[0001.524] I> 35) Base:0xab000000 Size:0x01000000                               
[0001.528] I> 36) Base:0xa0000000 Size:0x0b000000                               
[0001.533] I> 37) Base:0xf2800000 Size:0x00800000                               
[0001.537] I> 38) Base:0x80000000 Size:0x20000000                               
[0001.542] I> 39) Base:0xb0000000 Size:0x08000000                               
[0001.546] I> 40) Base:0x00000000 Size:0x00000000                               
[0001.551] I> 41) Base:0x00000000 Size:0x00000000                               
[0001.555] I> 42) Base:0x00000000 Size:0x00000000                               
[0001.559] I> 43) Base:0x00000000 Size:0x00000000                               
[0001.564] I> 44) Base:0x00000000 Size:0x00000000                               
[0001.568] I> 45) Base:0x00000000 Size:0x00000000                               
[0001.573] GIC-SPI Target CPU: 0                                                
[0001.576] Interrupts Init done                                                 
[0001.579] calling constructors                                                 
[0001.582] initializing heap                                                    
[0001.584] I> Heap: [0xa06945e8 ... 0xab000000]                                 
[0001.589] initializing threads                                                 
[0001.591] initializing timers                                                  
[0001.594] creating bootstrap completion thread                                 
[0001.599] top of bootstrap2()                                                  
[0001.601] CPU: MIDR: 0x4E0F0040, MPIDR: 0x80000000                             
[0001.606] initializing platform                                                
[0001.609] E> DEVICE_PROD: Invalid value data = 0, size = 0.                    
[0001.614] W> device prod register failed                                       
[0001.618] I> Bl_dtb @0xaaf00000                                                
[0001.625] W> "plugin-manager" doesn't exist, creating                          
[0001.626] W> "ids" doesn't exist, creating                                     
[0001.630] W> "connection" doesn't exist, creating                              
[0001.635] W> "configs" doesn't exist, creating                                 
[0001.645] I> Find /i2c@3160000's alias i2c0                                    
[0001.646] I> Reading eeprom i2c=0 address=0x50                                 
[0001.672] I> Device at /i2c@3160000:0x50                                       
[0001.673] I> Reading eeprom i2c=0 address=0x56                                 
[0001.697] I> Device at /i2c@3160000:0x56                                       
[0001.699] I> Find /i2c@3180000's alias i2c2                                    
[0001.699] I> Reading eeprom i2c=2 address=0x54                                 
[0001.701] E> I2C: slave not found in slaves.                                   
[0001.701] E> I2C: Could not write 0 bytes to slave: 0x00a8 with repeat start t.
[0001.702] E> I2C_DEV: Failed to send register address 0x00000000.              
[0001.702] E> I2C_DEV: Could not read 256 registers of size 1 from slave 0xa8 a.
[0001.711] E> eeprom: Failed to read I2C slave device                           
[0001.716] I> Eeprom read failed 0x3526070d                                     
[0001.720] I> Reading eeprom i2c=2 address=0x57                                 
[0001.724] E> I2C: slave not found in slaves.                                   
[0001.728] E> I2C: Could not write 0 bytes to slave: 0x00ae with repeat start t.
[0001.736] E> I2C_DEV: Failed to send register address 0x00000000.              
[0001.742] E> I2C_DEV: Could not read 256 registers of size 1 from slave 0xae a.
[0001.751] E> eeprom: Failed to read I2C slave device                           
[0001.756] I> Eeprom read failed 0x3526070d                                     
[0001.760] I> Reading eeprom i2c=2 address=0x52                                 
[0001.764] E> I2C: slave not found in slaves.                                   
[0001.768] E> I2C: Could not write 0 bytes to slave: 0x00a4 with repeat start t.
[0001.776] E> I2C_DEV: Failed to send register address 0x00000000.              
[0001.782] E> I2C_DEV: Could not read 256 registers of size 1 from slave 0xa4 a.
[0001.791] E> eeprom: Failed to read I2C slave device                           
[0001.796] I> Eeprom read failed 0x3526070d                                     
[0001.801] I> Find /i2c@c240000's alias i2c1                                    
[0001.804] I> Reading eeprom i2c=1 address=0x52                                 
[0001.810] E> I2C: slave not found in slaves.                                   
[0001.812] E> I2C: Could not write 0 bytes to slave: 0x00a4 with repeat start t.
[0001.820] E> I2C_DEV: Failed to send register address 0x00000000.              
[0001.826] E> I2C_DEV: Could not read 256 registers of size 1 from slave 0xa4 a.
[0001.835] E> eeprom: Retry to read I2C slave device.                           
[0001.840] E> I2C: slave not found in slaves.                                   
[0001.844] E> I2C: Could not write 0 bytes to slave: 0x00a4 with repeat start t.
[0001.852] E> I2C_DEV: Failed to send register address 0x00000000.              
[0001.858] E> I2C_DEV: Could not read 256 registers of size 1 from slave 0xa4 a.
[0001.867] E> eeprom: Failed to read I2C slave device                           
[0001.872] I> Eeprom read failed 0x3526070d                                     
[0001.876] I> Reading eeprom i2c=1 address=0x50                                 
[0001.880] E> I2C: slave not found in slaves.                                   
[0001.884] E> I2C: Could not write 0 bytes to slave: 0x00a0 with repeat start t.
[0001.892] E> I2C_DEV: Failed to send register address 0x00000000.              
[0001.898] E> I2C_DEV: Could not read 256 registers of size 1 from slave 0xa0 a.
[0001.907] E> eeprom: Retry to read I2C slave device.                           
[0001.912] E> I2C: slave not found in slaves.                                   
[0001.916] E> I2C: Could not write 0 bytes to slave: 0x00a0 with repeat start t.
[0001.924] E> I2C_DEV: Failed to send register address 0x00000000.              
[0001.930] E> I2C_DEV: Could not read 256 registers of size 1 from slave 0xa0 a.
[0001.939] E> eeprom: Failed to read I2C slave device                           
[0001.944] I> Eeprom read failed 0x3526070d                                     
[0001.948] I> create_pm_ids: id: 2888-0004-400-L, len: 15                       
[0001.953] I> config: mem-type:00,power-config:00,misc-config:00,modem-config:03
[0001.964] I> create_pm_ids: id: 2822-0000-700-K, len: 15                       
[0001.969] I> config: mem-type:00,power-config:00,misc-config:00,modem-config:03
[0001.980] I> Adding plugin-manager/ids/2888-0004-400=/i2c@3160000:module@0x50  
[0001.988] W> "i2c@3160000" doesn't exist, creating                             
[0001.992] W> "module@0x50" doesn't exist, creating                             
[0001.997] I> Adding plugin-manager/ids/2822-0000-700=/i2c@3160000:module@0x56  
[0002.004] W> "module@0x56" doesn't exist, creating                             
[0002.010] I> Adding plugin-manager/cvm                                         
[0002.012] W> "chip-id" doesn't exist, creating                                 
[0002.016] I> Adding plugin-manager/chip-id/A02P                                
[0002.021] I> Plugin-manager override starting                                  
[0002.026] I> node /plugin-manager/fragement-tegra-wdt-en matches               
[0002.034] I> node /plugin-manager/fragement-soft-wdt matches                   
[0002.041] I> node /plugin-manager/fragment-pcie-c5-rp matches                  
[0002.044] I> node /plugin-manager/fragment-tegra-ufs-lane10 matches            
[0002.057] I> Disable plugin-manager status in FDT                              
[0002.057] I> Plugin-manager override finished successfully                     
[0002.058] I> gpio framework initialized                                        
[0002.062] I> tegrabl_gpio_driver_register: register 'nvidia,tegra194-gpio' drir
[0002.070] I> tegrabl_gpio_driver_register: register 'nvidia,tegra194-gpio-aon'r
[0002.076] I> tegrabl_tca9539_init: i2c bus: 1, slave addr: 0x46                
[0002.084] W> fetch_driver_phandle_from_dt: failed to get node with compatible 9
[0002.092] W> fetch_driver_phandle_from_dt: failed to get node with compatible 9
[0002.098] W> tegrabl_tca9539_init: failed to fetch phandle from dt             
[0002.104] I> tegrabl_tca9539_init: i2c bus: 1, slave addr: 0x44                
[0002.112] W> fetch_driver_phandle_from_dt: failed to get node with compatible 9
[0002.119] W> fetch_driver_phandle_from_dt: failed to get node with compatible 9
[0002.126] W> tegrabl_tca9539_init: failed to fetch phandle from dt             
[0002.133] I> fixed regulator driver initialized                                
[0002.144] I> register 'maxim' power off handle                                 
[0002.145] I> virtual i2c enabled                                               
[0002.145] I> registered 'maxim,max20024' pmic                                  
[0002.148] I> tegrabl_gpio_driver_register: register 'max20024-gpio' driver     
[0002.155] I> Boot-device: eMMC                                                 
[0002.158] I> Boot_device: SDMMC_BOOT instance: 3                               
[0002.166] I> sdmmc-3 params source = boot args                                 
[0002.167] I> create_pm_ids: id: 2888-0004-400-L, len: 15                       
[0002.171] I> config: mem-type:00,power-config:00,misc-config:00,modem-config:03
[0002.182] I> create_pm_ids: id: 2822-0000-700-K, len: 15                       
[0002.188] I> config: mem-type:00,power-config:00,misc-config:00,modem-config:03
[0002.199] I> sdmmc bdev is already initialized                                 
[0002.203] I> sdmmc-3 params source = boot args                                 
[0002.234] I> Found 17 partitions in SDMMC_BOOT (instance 3)                    
[0002.246] I> Found 42 partitions in SDMMC_USER (instance 3)                    
[0002.256] I> enabling 'vdd-hdmi-5v0' regulator                                 
[0002.261] I> regulator 'vdd-hdmi-5v0' already enabled                          
[0002.261] I> hdmi cable connected                                              
[0002.263] W> set volts not configured for 'vdd-1v0'                            
[0002.265] W> set volts not configured for 'vdd-1v8-hs'                         
[0002.269] E> invalid display type                                              
[0002.273] E> invalid display type                                              
[0002.274] E> cannot find any other nvdisp nodes                                
[0002.289] I> edid read success                                                 
[0002.302] I> edid read success                                                 
[0002.302] I> width = 640, height = 480, frequency = 25174825                   
[0002.303] I> width = 640, height = 480, frequency = 25174825                   
[0002.303] I> width = 640, height = 480, frequency = 25174825                   
[0002.303] I> width = 640, height = 480, frequency = 25174825                   
[0002.304] I> width = 1920, height = 1080, frequency = 148500000                
[0002.308] I> width = 1920, height = 1080, frequency = 170000000                
[0002.313] I> width = 640, height = 480, frequency = 25174825                   
[0002.319] I> width = 720, height = 480, frequency = 26973026                   
[0002.324] I> width = 720, height = 480, frequency = 26973026                   
[0002.330] I> width = 720, height = 576, frequency = 26973026                   
[0002.335] I> width = 720, height = 576, frequency = 26973026                   
[0002.341] I> width = 1280, height = 720, frequency = 74175824                  
[0002.347] I> width = 1280, height = 720, frequency = 74175824                  
[0002.352] I> width = 1920, height = 1080, frequency = 148351648                
[0002.358] I> width = 1920, height = 1080, frequency = 148351648                
[0002.364] I> Best mode Width = 1920, Height = 1080, freq = 148351648           
[0002.374] I> hdmi_enable, starting HDMI initialisation                         
[0002.379] I> hdmi_enable, HDMI initialisation complete                         
[0002.389] I> Load in CBoot Boot Options partition and parse it                 
[0002.396] E> Error -9 when finding node with path /boot-configuration          
[0002.397] E> tegrabl_cbo_parse_info: "boot-configuration" not found in CBO fil.
[0002.399] I> Using default boot order                                          
[0002.403] I> boot-dev-order :-                                                 
[0002.406] I> 1.sd                                                              
[0002.407] I> 2.usb                                                             
[0002.409] I> 3.nvme                                                            
[0002.411] I> 4.emmc                                                            
[0002.413] I> 5.net                                                             
[0002.415] I> Hit any key to stop autoboot:     4       3       2       1       
[0004.423] initializing target                                                  
[0004.423] calling apps_init()                                                  
[0004.424] starting app kernel_boot_app                                         
[0004.443] I> found decompressor handler: lz4-legacy                            
[0004.444] I> decompressing BMP blob ...                                        
[0004.457] I> Kernel type = Normal                                              
[0004.457] I> Loading kernel-bootctrl from partition                            
[0004.458] I> Loading partition kernel-bootctrl at 0xa4ad0000 from device(0x1)  
[0004.464] W> tegrabl_get_kernel_bootctrl: magic number(0x00000000) is invalid  
[0004.465] W> tegrabl_get_kernel_bootctrl: use default dummy boot control data  
[0004.465] I> ########## SD (0) boot ##########                                 
[0004.466] I> No sdcard                                                         
[0004.467] I> -0 params source =                                                
[0004.470] E> Blockdev open: exit error                                         
[0004.474] E> SD boot failed, err: 724238353                                    
[0004.478] I> ########## USB (0) boot ##########                                
[0004.487] W> No valid slot number is found in scratch register                 
[0004.488] W> Return default slot: _a                                           
[0004.504] I> USB Firmware Version: 60.06 release                               
[0004.559] I> regulator of usb2-0 already enabled                               
[0004.566] I> regulator of usb2-1 already enabled                               
[0004.573] I> regulator of usb2-2 already enabled                               
[0004.582] I> enabling 'vdd-5v-sata' regulator                                  
[0005.650] I> USB 2.0 port 4 new full-speed USB device detected                 
[0005.652] W> WARNING: event and command not matching, cmd_trb_ptr = 0xa9ad00000
[0005.752] I> Start to enumerate device                                         
[0005.754] W> WARNING: event and command not matching, cmd_trb_ptr = 0xa9ad00000
[0005.758] I> This device is non-MSD, skip enumeration                          
[0005.758] E> Failed to enumerate USB device                                    
[0005.758] E> failed to start xhci controller                                   
[0005.759] E> Error in init of XUSB host driver, err: 7979000d                  
[0005.759] W> Failed to initialize device 5-0                                   
[0005.763] E> USB boot failed, err: 2037973005                                  
[0005.767] I> ########## Fixed storage boot ##########                          
[0005.778] I> Already published: 00010003                                       
[0005.779] I> Look for boot partition                                           
[0005.780] I> Fallback: assuming 0th partition is boot partition                
[0005.785] I> Detect filesystem                                                 
[0005.812] I> Loading extlinux.conf ...                                         
[0005.813] I> rootfs path: /sdmmc_user/boot/extlinux/extlinux.conf              
[0005.856] I> L4T boot options                                                  
[0005.856] I> [1]: "primary kernel"                                             
[0005.856] I> Enter choice:                                                     
[0008.857] I> Continuing with default option: 1                                 
[0008.857] I> Loading kernel sig file from rootfs ...                           
[0008.857] I> rootfs path: /sdmmc_user/boot/Image.sig                           
[0008.876] I> Loading kernel binary from rootfs ...                             
[0008.876] I> rootfs path: /sdmmc_user/boot/Image                               
[0009.100] I> overload load_size to 34338824 (from 34338832)                    
[0009.123] I> Validate kernel ...                                               
[0009.123] I> T19x: Authenticate kernel (bin_type: 37), max size 0x5000000      
[0009.124] I> RSA PSS signature check: OK                                       
[0009.437] W> keyslot 14 is zero                                                
[0009.455] I> No kernel-dtb binary path                                         
[0009.456] W> No valid slot number is found in scratch register                 
[0009.456] W> Return default slot: _a                                           
[0009.456] I> A/B: bin_type (38) slot 0                                         
[0009.457] I> Loading kernel-dtb from partition                                 
[0009.457] I> Loading partition kernel-dtb at 0x91000000 from device(0x1)       
[0009.466] I> Validate kernel-dtb ...                                           
[0009.466] I> T19x: Authenticate kernel-dtb (bin_type: 38), max size 0x400000   
[0009.469] I> RSA PSS signature check: OK                                       
[0009.474] W> keyslot 14 is zero                                                
[0009.475] I> Loading ramdisk from rootfs ...                                   
[0009.479] I> Loading initrd sig file from rootfs ...                           
[0009.483] I> rootfs path: /sdmmc_user/boot/initrd.sig                          
[0009.506] I> Loading initrd binary from rootfs ...                             
[0009.507] I> rootfs path: /sdmmc_user/boot/initrd                              
[0009.564] I> overload load_size to 7236840 (from 7236848)                      
[0009.568] I> Validate initrd ...                                               
[0009.568] I> T19x: Authenticate initrd (bin_type: 49), max size 0x4000000      
[0009.569] I> RSA PSS signature check: OK                                       
[0009.635] W> keyslot 14 is zero                                                
[0009.649] I> Kernel hdr @0xa4ad0000                                            
[0009.649] I> Kernel dtb @0x90000000                                            
[0009.649] I> decompressor handler not found                                    
[0009.649] I> Copying kernel image (34338824 bytes) from 0xa4ad0000 to 0x800800e
[0009.660] E> fdt_open_into fail (FDT_ERR_BADMAGIC)                             
[0009.660] E> Error (727449637) extracting the kernel DTB                       
[0009.678] I> Kernel EP: 0x80080000, DTB: 0x90000000                            
[0009.679]                                                                      
[0009.679] -----------------------------------------------                      
[0009.681] Synchronous Exception: UNKNOWN EXCEPTION                             
[0009.683] -----------------------------------------------                      
[0009.685]                                                                      
[0009.685] ESR 0x2000000: ec 0x0, il 0x1, iss 0x0                               
[0009.687] -----------------------------------------------                      
[0009.689]  [Stack Trace]                                                       
[0009.690]                                                                      
[0009.690] => pc:0x80080000, sp:0xA0EA3500                                      
[0009.692] => pc:0xA060F858, sp:0xA0EA3730                                      
[0009.696] => pc:0xA060F86C, sp:0xA0EA37A0                                      
[0009.700] => pc:0xA060F4EC, sp:0xA0EA37E0                                      
[0009.704] => pc:0xA060EA60, sp:0xA0EA37F0                                      
[0009.708] => pc:0xA060EA34, sp:0xA0EA3800                                      
[0009.712] -----------------------------------------------                      
[0009.717] iframe 0xa0ea3410:                                                   
[0009.720] x0  0x        90000000 x1  0x               0 x2  0x               00
[0009.729] x4  0x        80080000 x5  0x              20 x6  0x         b2001230
[0009.738] x8  0x               0 x9  0xffffffffffffffff x10 0x               62
[0009.747] x12 0x               1 x13 0x              40 x14 0x               10
[0009.756] x16 0x            1500 x17 0x             438 x18 0x               00
[0009.765] x20 0x        a0ea37b0 x21 0x               0 x22 0x               00
[0009.774] x24 0x               0 x25 0x               0 x26 0x               00
[0009.783] x28 0x               0 x29 0x        a0ea3730 lr  0x        a060f80c0
[0009.792] elr 0x        80080000                                               
[0009.796] spsr 0x        400003c9                                              
[0009.799] -----------------------------------------------                      
[0009.804] panic (caller 0xa0601238): die                                       
[0009.808] HALT: spinning forever...     

hello dcapers44,

you’re having failure of key verification,
for example,

in addition,
it seems the kernel-dtb’s magic number is also wrong.

what’s the user_key you’re using, normally, we need to use a user_key to generate the EKB image first, and then use this same user_key to flash the device.
please double confirm you’re having the same user_key in EKB generation and flashing the device.
thanks

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.