please refer to download center for Jetson Orin Fuse Specification.
as you can see of [Table 6. Field Programmable Fuses], the bit length of ODM_Lock fuse variable is 4.
so, that’s expected you can only burn odm_lock to 0x0f.
>> Q1
please read developer guide, Secure Boot.
after the SecurityMode (also known as odm_production_mode) fuse is burned with a value of 0x1, all additional fuse write requests will be blocked.
>> Q2
you may see-also Burn Fuses with the Fuse Configuration file to program fuse variables.
please note that, once a fuse bit is set to 1, you cannot change its value back to 0.
for example, a fuse value of 1 (0x01) can be changed to 3 (0x03) or 5 (0x05), but not to 4 (0x4) because bit 0 is already programmed to 1.
there’re lots of variables with 0xFF, were they truly 0xFF, or you’re omitting fuse values?
anyways, please share the actual value of your boot_security_info fuse variable.
no, you did not understand it correctly,
for the secureboot, the root-of-trust that uses the NVIDIA SoCs fuses to authenticate boot codes ends at the Bootloader.