PLease HELP ! ! ! ergency! Secure boot seems do not work

we burn efuse
use the xml like below to enable secure boot
genericfuse MagicId=“0x45535546” version=“1.0.0”>
!-- fuse name=“SecureBootKey” size=“32” value=“0x123456789abcdef0fedcba987654321023456789abcdef01edcba9876543210f”/> →
fuse name=“PublicKeyHash” size=“64” value=“0xxxxxxxxxxxxx”/>
!-- →
!-- →
!-- →
fuse name=“BootSecurityInfo” size=“4” value=“0x1”/>
!-- →
/genericfuse

as you can see,we comment the “SecurityMode”
and we can see the fuse val under linux

,but we flash the unsigned image into the agx ori emmc with command flash.sh with no -u -v para specified ,then something amazing happend; the program run and hardware boot up success;
we sure the image is not signed ? is this because the “SecurityMode” flag not burned?

or is there any to see is the image we prepare to flash is signed or not?

##########update########


we enable the “SecurityMode” flag,but it still boot with the no_signed firmware

even we use wrong key to sign the image ,it still boot,the boot log below

[0000.070] W> RATCHET: MB1 binary ratchet value 1 is larger than ratchet level 0 from HW fuses.
[0000.079] I> MB1 (version: 1.4.0.4-t234-54845784-e89ea9bc)
[0000.084] I> t234-A01-0-Silicon (0x12347) Prod
[0000.088] I> Boot-mode : Coldboot
[0000.091] I> Entry timestamp: 0x00000000
[0000.095] I> last_boot_error: 0x0
[0000.098] I> BR-BCT: preprod_dev_sign: 0
[0000.102] I> rst_source: 0x0, rst_level: 0x0
[0000.106] I> Task: SE error check
[0000.109] I> Task: Bootchain select WAR set
[0000.113] I> Task: Enable SLCG
[0000.116] I> Task: CRC check
[0000.119] I> Skip FUSE records CRC check as records_integrity fuse is not burned
[0000.126] I> Task: Initialize MB2 params
[0000.130] I> MB2-params @ 0x40060000
[0000.134] I> Task: Crypto init
[0000.137] I> Task: Perform MB1 KAT tests
[0000.141] I> Task: NVRNG health check
[0000.144] I> NVRNG: Health check success
[0000.148] I> Task: MSS Bandwidth limiter settings for iGPU clients
[0000.154] I> Task: Enabling and initialization of Bandwidth limiter
[0000.160] I> No request to configure MBWT settings for any PC!
[0000.166] I> Task: Secure debug controls
[0000.170] I> Task: strap war set
[0000.173] I> Task: Initialize SOC Therm
[0000.176] I> Task: Program NV master stream id
[0000.181] I> Task: Verify boot mode
[0000.186] I> Task: Alias fuses
[0000.190] W> FUSE_ALIAS: Fuse alias on production fused part is not supported.
[0000.197] I> Task: Print SKU type
[0000.200] I> FUSE_OPT_CCPLEX_CLUSTER_DISABLE = 0x00000000
[0000.205] I> FUSE_OPT_GPC_DISABLE = 0x00000000
[0000.210] I> FUSE_OPT_TPC_DISABLE = 0x00000000
[0000.214] I> FUSE_OPT_DLA_DISABLE = 0x00000000
[0000.218] I> FUSE_OPT_PVA_DISABLE = 0x00000000
[0000.223] I> FUSE_OPT_NVENC_DISABLE = 0x00000000
[0000.227] I> FUSE_OPT_NVDEC_DISABLE = 0x00000000
[0000.231] I> FUSE_OPT_FSI_DISABLE = 0x00000000
[0000.236] I> FUSE_OPT_EMC_DISABLE = 0x00000000
[0000.240] I> FUSE_BOOTROM_PATCH_VERSION = 0x3
[0000.244] I> FUSE_PSCROM_PATCH_VERSION = 0x3
[0000.248] I> FUSE_OPT_ADC_CAL_FUSE_REV = 0x1
[0000.252] I> FUSE_SKU_INFO_0 = 0x90
[0000.256] I> FUSE_OPT_SAMPLE_TYPE_0 = 0x1 CS
[0000.260] I> FUSE_PACKAGE_INFO_0 = 0x1
[0000.264] I> SKU: Prod
[0000.266] I> Task: Boost clocks
[0000.269] I> Initializing NAFLL for BPMP_CPU_NIC.
[0000.274] I> BPMP NAFLL: fll_lock = 1, dvco_min_reached = 0
[0000.279] I> BPMP NAFLL lock success.
[0000.283] I> BPMP_CPU_NIC : src = 42, divisor = 0
[0000.287] I> Initializing PLLC2 for AXI_CBB.
[0000.291] I> AXI_CBB : src = 35, divisor = 0
[0000.296] I> Task: Voltage monitor
[0000.299] I> VMON: Vmon re-calibration and fine tuning done
[0000.304] I> Task: UPHY init
[0000.309] I> HSIO UPHY init done
[0000.312] W> Skipping GBE UPHY config
[0000.316] I> Task: Boot device init
[0000.319] I> Boot_device: QSPI_FLASH instance: 0
[0000.324] I> Qspi clock source : pllc_out0
[0000.328] I> QSPI Flash: Macronix 64MB
[0000.331] I> QSPI-0l initialized successfully
[0000.336] I> Task: TSC init
[0000.338] I> Task: Load membct
[0000.341] I> RAM_CODE 0x4000401
[0000.344] I> Loading MEMBCT
[0000.347] I> Slot: 0
[0000.349] I> Binary[0] block-3840 (partition size: 0x40000)
[0000.355] I> Binary name: MEM-BCT-0
[0000.358] I> Size of crypto header is 8192
[0000.362] I> Size of crypto header is 8192
[0000.366] I> strt_pg_num(3840) num_of_pgs(16) read_buf(0x40050000)
[0000.372] I> BCH of MEM-BCT-0 read from storage
[0000.376] I> BCH address is : 0x40050000
[0000.380] I> MEM-BCT-0 header integrity check is success
[0000.385] I> Binary magic in BCH component 0 is MEM0
[0000.390] I> component binary type is 0
[0000.394] I> strt_pg_num(3856) num_of_pgs(115) read_buf(0x40040000)
[0000.401] I> MEM-BCT-0 binary is read from storage
[0000.406] I> MEM-BCT-0 binary integrity check is success
[0000.411] I> Binary MEM-BCT-0 loaded successfully at 0x40040000 (0xe580)
[0000.417] I> RAM_CODE 0x4000401
[0000.423] I> RAM_CODE 0x4000401
[0000.427] I> Task: Load Page retirement list
[0000.431] I> Task: SDRAM params override
[0000.434] I> Task: Save mem-bct info
[0000.438] I> Task: Carveout allocate
[0000.441] I> RCM blob carveout will not be allocated
[0000.446] I> Update CCPLEX IST carveout from MB1-BCT
[0000.451] I> ECC region[0]: Start:0x0, End:0x0
[0000.455] I> ECC region[1]: Start:0x0, End:0x0
[0000.459] I> ECC region[2]: Start:0x0, End:0x0
[0000.464] I> ECC region[3]: Start:0x0, End:0x0
[0000.468] I> ECC region[4]: Start:0x0, End:0x0
[0000.472] I> Non-ECC region[0]: Start:0x80000000, End:0x880000000
[0000.478] I> Non-ECC region[1]: Start:0x0, End:0x0
[0000.483] I> Non-ECC region[2]: Start:0x0, End:0x0
[0000.487] I> Non-ECC region[3]: Start:0x0, End:0x0
[0000.492] I> Non-ECC region[4]: Start:0x0, End:0x0
[0000.503] I> allocated(CO:44) base:0x849800000 size:0x36800000 align: 0x100000
[0000.510] I> allocated(CO:31) base:0x840000000 size:0x8000000 align: 0x8000000
[0000.517] I> allocated(CO:43) base:0x83c000000 size:0x4000000 align: 0x200000
[0000.524] I> allocated(CO:39) base:0x839e00000 size:0x2200000 align: 0x10000
[0000.531] I> allocated(CO:20) base:0x836000000 size:0x2000000 align: 0x2000000
[0000.538] I> allocated(CO:24) base:0x834000000 size:0x2000000 align: 0x2000000
[0000.545] I> allocated(CO:28) base:0x832000000 size:0x2000000 align: 0x2000000
[0000.552] I> allocated(CO:29) base:0x830000000 size:0x2000000 align: 0x2000000
[0000.560] I> allocated(CO:22) base:0x848000000 size:0x1000000 align: 0x1000000
[0000.567] I> allocated(CO:35) base:0x838e00000 size:0x1000000 align: 0x100000
[0000.574] I> allocated(CO:41) base:0x82f000000 size:0x1000000 align: 0x100000
[0000.581] I> allocated(CO:02) base:0x849000000 size:0x800000 align: 0x800000
[0000.588] I> allocated(CO:03) base:0x838000000 size:0x800000 align: 0x800000
[0000.595] I> allocated(CO:06) base:0x82e800000 size:0x800000 align: 0x800000
[0000.602] I> allocated(CO:56) base:0x82e000000 size:0x800000 align: 0x200000
[0000.608] I> allocated(CO:07) base:0x838800000 size:0x400000 align: 0x400000
[0000.615] I> allocated(CO:33) base:0x82dc00000 size:0x400000 align: 0x200000
[0000.622] I> allocated(CO:19) base:0x82d980000 size:0x280000 align: 0x10000
[0000.629] I> allocated(CO:23) base:0x838c00000 size:0x200000 align: 0x200000
[0000.636] I> allocated(CO:01) base:0x82d800000 size:0x100000 align: 0x100000
[0000.643] I> allocated(CO:05) base:0x82d700000 size:0x100000 align: 0x100000
[0000.650] I> allocated(CO:08) base:0x82d600000 size:0x100000 align: 0x100000
[0000.657] I> allocated(CO:09) base:0x82d500000 size:0x100000 align: 0x100000
[0000.664] I> allocated(CO:12) base:0x82d400000 size:0x100000 align: 0x100000
[0000.671] I> allocated(CO:15) base:0x82d300000 size:0x100000 align: 0x100000
[0000.678] I> allocated(CO:17) base:0x82d200000 size:0x100000 align: 0x100000
[0000.685] I> allocated(CO:27) base:0x82d100000 size:0x100000 align: 0x100000
[0000.692] I> allocated(CO:42) base:0x82d000000 size:0x100000 align: 0x100000
[0000.699] I> allocated(CO:54) base:0x82d900000 size:0x80000 align: 0x80000
[0000.705] I> allocated(CO:34) base:0x82cff0000 size:0x10000 align: 0x10000
[0000.712] I> allocated(CO:72) base:0x82cdf0000 size:0x200000 align: 0x10000
[0000.719] I> allocated(CO:47) base:0x82c800000 size:0x400000 align: 0x200000
[0000.726] I> allocated(CO:50) base:0x82c600000 size:0x200000 align: 0x100000
[0000.733] I> allocated(CO:52) base:0x82cdc0000 size:0x30000 align: 0x10000
[0000.740] I> allocated(CO:48) base:0x82cda0000 size:0x20000 align: 0x10000
[0000.746] I> allocated(CO:69) base:0x82cd80000 size:0x20000 align: 0x10000
[0000.753] I> allocated(CO:49) base:0x82cd70000 size:0x10000 align: 0x10000
[0000.760] I> NSDRAM base: 0x80000000, end: 0x82cdf0000, size: 0x7acdf0000
[0000.767] I> Task: Thermal check
[0000.770] I> Using min_chip_limit as min_tmon_limit
[0000.774] I> Using max_chip_limit as max_tmon_limit
[0000.779] I> BCT max_tmon_limit = 105
[0000.783] I> BCT min_tmon_limit = -28
[0000.786] I> BCT max_tmon_limit = 105
[0000.790] I> BCT min_tmon_limit = -28
[0000.793] I> SKU specific max_chip_limit = 125
[0000.797] I> SKU specific min_chip_limit = -43
[0000.802] I> BCT max_chip_limit = 105
[0000.805] I> BCT min_chip_limit = -28
[0000.809] I> enable_soctherm_polling = 0
[0000.812] I> max temp read = 44
[0000.815] I> min temp read = 42
[0000.818] I> Enabling thermtrip
[0000.821] I> Task: Update FSI SCR with thermal fuse data
[0000.827] I> Task: Enable WDT 5th expiry
[0000.830] I> Task: I2C register
[0000.833] I> Task: Set I2C bus freq
[0000.837] I> Task: Reset FSI
[0000.839] I> Task: Pinmux init
[0000.843] I> Task: Prod config init
[0000.846] I> Task: Pad voltage init
[0000.849] I> Task: Prod init
[0000.852] I> Task: Program rst req config reg
[0000.856] I> Task: Common rail init
[0000.860] W> DEVICE_PROD: module = 13, instance = 4 not found in device prod.
[0000.871] I> DONE: Thermal config
[0000.876] I> DONE: SOC rail config
[0000.879] W> PMIC_CONFIG: Rail: MEMIO rail config not found in MB1 BCT.
[0000.885] I> DONE: MEMIO rail config
[0000.889] I> DONE: GPU rail info
[0000.892] I> DONE: CV rail info
[0000.895] I> Task: Mem clock src
[0000.898] I> Task: Misc. board config
[0000.902] I> PMIC_CONFIG: Platform config not found in MB1 BCT.
[0000.907] I> Task: SDRAM init
[0000.910] I> MemoryType: 4 MemBctRevision: 10
[0000.917] I> MSS CAR: PLLM/HUB programming for MemoryType: 4 and MemBctRevision: 10
[0000.924] I> MSS CAR: Init PLLM
[0000.927] I> MSS CAR: Init PLLHUB
[0000.932] I> Encryption: MTS: en, TX: en, VPR: en, GSC: en
[0000.944] I> SDRAM initialized!
[0000.947] I> SDRAM Size in Total 0x800000000
[0000.951] I> Task: Dram Ecc scrub
[0000.954] I> Task: DRAM alias check
[0000.971] I> Task: Program NSDRAM carveout
[0000.975] I> NSDRAM carveout encryption is enabled
[0000.979] I> Program NSDRAM carveout
[0000.983] I> Task: Register checker
[0000.986] I> Task: Enable clock-mon
[0001.000] I> FMON: Fmon re-programming done
[0001.005] I> Task: Mapper init
[0001.007] I> Task: SC7 Context Init
[0001.011] I> Task: CCPLEX IST init
[0001.014] I> Task: CPU WP0
[0001.017] I> Loading MCE
[0001.019] I> Slot: 0
[0001.021] I> Binary[8] block-22784 (partition size: 0x80000)
[0001.027] I> Binary name: MCE
[0001.029] I> Size of crypto header is 8192
[0001.033] I> Size of crypto header is 8192
[0001.037] I> strt_pg_num(22784) num_of_pgs(16) read_buf(0x4003e000)
[0001.044] I> BCH of MCE read from storage
[0001.047] I> BCH address is : 0x4003e000
[0001.051] I> MCE header integrity check is success
[0001.056] I> Binary magic in BCH component 0 is MTSM
[0001.061] I> component binary type is 8
[0001.064] I> Size of crypto header is 8192
[0001.068] I> strt_pg_num(22800) num_of_pgs(350) read_buf(0x40000000)
[0001.077] I> MCE binary is read from storage
[0001.081] I> MCE binary integrity check is success
[0001.086] I> Binary MCE loaded successfully at 0x40000000 (0x2baf0)
[0001.092] I> Size of crypto header is 8192
[0001.103] I> Size of crypto header is 8192
[0001.107] I> Sending WP0 mailbox command to PSC
[0001.116] I> Task: XUSB Powergate
[0001.119] I> Skipping powergate XUSB.
[0001.123] I> Task: MB1 fixed firewalls
[0001.129] W> Firewall readback mismatch
[0001.134] I> Task: Load bpmp-fw
[0001.137] I> Slot: 0
[0001.139] I> Binary[15] block-9984 (partition size: 0x180000)
[0001.145] I> Binary name: BPMP_FW
[0001.148] I> Size of crypto header is 8192
[0001.152] I> Size of crypto header is 8192
[0001.156] I> strt_pg_num(9984) num_of_pgs(16) read_buf(0x807fe000)
[0001.162] I> BCH of BPMP_FW read from storage
[0001.166] I> BCH address is : 0x807fe000
[0001.170] I> BPMP_FW header integrity check is success
[0001.175] I> Binary magic in BCH component 0 is BPMF
[0001.180] I> component binary type is 15
[0001.183] I> Size of crypto header is 8192
[0001.187] I> strt_pg_num(10000) num_of_pgs(2028) read_buf(0x80000000)
[0001.205] I> BPMP_FW binary is read from storage
[0001.212] I> BPMP_FW binary integrity check is success
[0001.216] I> Binary BPMP_FW loaded successfully at 0x80000000 (0xfd640)
[0001.223] I> Slot: 0
[0001.225] I> Binary[16] block-13056 (partition size: 0x400000)
[0001.231] I> Binary name: BPMP_FW_DTB
[0001.234] I> Size of crypto header is 8192
[0001.238] I> Size of crypto header is 8192
[0001.242] I> strt_pg_num(13056) num_of_pgs(16) read_buf(0x807fc000)
[0001.248] I> BCH of BPMP_FW_DTB read from storage
[0001.253] I> BCH address is : 0x807fc000
[0001.257] I> BPMP_FW_DTB header integrity check is success
[0001.262] I> Binary magic in BCH component 0 is BPMD
[0001.267] I> component binary type is 16
[0001.271] I> Size of crypto header is 8192
[0001.274] I> strt_pg_num(13072) num_of_pgs(736) read_buf(0x8079fff0)
[0001.285] I> BPMP_FW_DTB binary is read from storage
[0001.290] I> BPMP_FW_DTB binary integrity check is success
[0001.296] I> Binary BPMP_FW_DTB loaded successfully at 0x8079fff0 (0x5bf40)
[0001.303] I> Task: BPMP fw ast config
[0001.306] I> Task: Load psc-fw
[0001.309] I> Slot: 0
[0001.311] I> Binary[17] block-21248 (partition size: 0xc0000)
[0001.317] I> Binary name: PSC_FW
[0001.320] I> Size of crypto header is 8192
[0001.324] I> Size of crypto header is 8192
[0001.328] I> strt_pg_num(21248) num_of_pgs(16) read_buf(0x80ffe000)
[0001.334] I> BCH of PSC_FW read from storage
[0001.338] I> BCH address is : 0x80ffe000
[0001.342] I> PSC_FW header integrity check is success
[0001.347] I> Binary magic in BCH component 0 is PFWP
[0001.351] I> component binary type is 17
[0001.355] I> Size of crypto header is 8192
[0001.359] I> strt_pg_num(21264) num_of_pgs(591) read_buf(0x80fb4200)
[0001.369] I> PSC_FW binary is read from storage
[0001.374] I> PSC_FW binary integrity check is success
[0001.379] I> Binary PSC_FW loaded successfully at 0x80fb4200 (0x49df0)
[0001.385] I> Task: Load nvdec-fw
[0001.388] I> Slot: 0
[0001.390] I> Binary[7] block-6400 (partition size: 0x100000)
[0001.396] I> Binary name: NVDEC
[0001.399] I> Size of crypto header is 8192
[0001.403] I> Size of crypto header is 8192
[0001.406] I> strt_pg_num(6400) num_of_pgs(16) read_buf(0x800fe000)
[0001.413] I> BCH of NVDEC read from storage
[0001.417] I> BCH address is : 0x800fe000
[0001.421] I> NVDEC header integrity check is success
[0001.425] I> Binary magic in BCH component 0 is NDEC
[0001.430] I> component binary type is 7
[0001.434] I> Size of crypto header is 8192
[0001.438] I> strt_pg_num(6416) num_of_pgs(560) read_buf(0x80000000)
[0001.447] I> NVDEC binary is read from storage
[0001.452] I> NVDEC binary integrity check is success
[0001.457] I> Binary NVDEC loaded successfully at 0x80000000 (0x46000)
[0001.463] I> Size of crypto header is 8192
[0001.474] I> Task: Load tsec-fw
[0001.477] I> TSEC-FW load support not enabled
[0001.482] I> Task: GPIO interrupt map
[0001.485] I> Task: SC7 context save
[0001.489] I> Slot: 0
[0001.491] I> Binary[27] block-0 (partition size: 0x100000)
[0001.496] I> Binary name: BR_BCT
[0001.499] I> Size of crypto header is 8192
[0001.503] I> Size of crypto header is 8192
[0001.507] I> Size of crypto header is 8192
[0001.511] I> strt_pg_num(0) num_of_pgs(16) read_buf(0xa0000000)
[0001.517] I> BR_BCT binary is read from storage
[0001.521] I> BR_BCT binary integrity check is success
[0001.526] I> Binary BR_BCT loaded successfully at 0xa0000000 (0x2000)
[0001.532] I> Slot: 0
[0001.534] I> Binary[13] block-23808 (partition size: 0x30000)
[0001.540] I> Binary name: SC7-FW
[0001.543] I> Size of crypto header is 8192
[0001.547] I> Size of crypto header is 8192
[0001.551] I> Size of crypto header is 8192
[0001.555] I> Size of crypto header is 8192
[0001.559] I> strt_pg_num(23808) num_of_pgs(16) read_buf(0xa0002000)
[0001.565] I> BCH of SC7-FW read from storage
[0001.569] I> BCH address is : 0xa0002000
[0001.573] I> SC7-FW header integrity check is success
[0001.578] I> Binary magic in BCH component 0 is WB0B
[0001.583] I> component binary type is 13
[0001.586] I> Size of crypto header is 8192
[0001.590] I> strt_pg_num(23824) num_of_pgs(349) read_buf(0xa0004000)
[0001.599] I> SC7-FW binary is read from storage
[0001.603] I> SC7-FW binary integrity check is success
[0001.608] I> Binary SC7-FW loaded successfully at 0xa0004000 (0x2ba00)
[0001.615] I> Slot: 0
[0001.617] I> Binary[22] block-24192 (partition size: 0x30000)
[0001.622] I> Binary name: PSC_RF
[0001.625] I> Size of crypto header is 8192
[0001.629] I> Size of crypto header is 8192
[0001.633] I> Size of crypto header is 8192
[0001.637] I> Size of crypto header is 8192
[0001.641] I> strt_pg_num(24192) num_of_pgs(16) read_buf(0xa002fa00)
[0001.647] I> BCH of PSC_RF read from storage
[0001.651] I> BCH address is : 0xa002fa00
[0001.655] I> PSC_RF header integrity check is success
[0001.660] I> Binary magic in BCH component 0 is PSCR
[0001.665] I> component binary type is 22
[0001.669] I> Size of crypto header is 8192
[0001.673] I> strt_pg_num(24208) num_of_pgs(224) read_buf(0xa0031a00)
[0001.680] I> PSC_RF binary is read from storage
[0001.685] I> PSC_RF binary integrity check is success
[0001.690] I> Binary PSC_RF loaded successfully at 0xa0031a00 (0x1be60)
[0001.699] I> Task: Save WP0 payload to SC7 ctx
[0001.703] I> Task: Load MB2rf binary to SC7 ctx
[0001.708] I> Slot: 0
[0001.710] I> Binary[14] block-24576 (partition size: 0x20000)
[0001.715] I> Binary name: MB2_RF
[0001.718] I> Size of crypto header is 8192
[0001.722] I> Size of crypto header is 8192
[0001.726] I> Size of crypto header is 8192
[0001.730] I> Size of crypto header is 8192
[0001.734] I> strt_pg_num(24576) num_of_pgs(16) read_buf(0xa00d5d10)
[0001.740] I> BCH of MB2_RF read from storage
[0001.744] I> BCH address is : 0xa00d5d10
[0001.748] I> MB2_RF header integrity check is success
[0001.753] I> Binary magic in BCH component 0 is MB2R
[0001.758] I> component binary type is 14
[0001.762] I> Size of crypto header is 8192
[0001.766] I> strt_pg_num(24592) num_of_pgs(224) read_buf(0xa00d7d10)
[0001.773] I> MB2_RF binary is read from storage
[0001.778] I> MB2_RF binary integrity check is success
[0001.783] I> Binary MB2_RF loaded successfully at 0xa00d7d10 (0x1bf60)
[0001.789] I> Task: Save fuse alias data to SC7 ctx
[0001.794] I> Task: Save PMIC data to SC7 ctx
[0001.798] I> Task: Save Pinmux data to SC7 ctx
[0001.802] I> Task: Save Pad Voltage data to SC7 ctx
[0001.807] I> Task: Save controller prod data to SC7 ctx
[0001.812] I> Task: Save prod cfg data to SC7 ctx
[0001.816] I> Task: Save I2C bus freq data to SC7 ctx
[0001.821] I> Task: Save SOCTherm data to SC7 ctx
[0001.826] I> Task: Save FMON data to SC7 ctx
[0001.830] I> Task: Save VMON data to SC7 ctx
[0001.834] I> Task: Save TZDRAM data to SC7 ctx
[0001.838] I> Task: Save GPIO int data to SC7 ctx
[0001.843] I> Task: Save clock data to SC7 ctx
[0001.847] I> Task: Save debug data to SC7 ctx
[0001.851] I> Task: Save MBWT data to SC7 ctx
[0001.859] I> SC7 context save done
[0001.862] I> Task: Load MB2/Applet/FSKP
[0001.866] I> Loading MB2
[0001.868] I> Slot: 0
[0001.870] I> Binary[6] block-8448 (partition size: 0x80000)
[0001.876] I> Binary name: MB2
[0001.879] I> Size of crypto header is 8192
[0001.883] I> Size of crypto header is 8192
[0001.886] I> strt_pg_num(8448) num_of_pgs(16) read_buf(0x8007e000)
[0001.893] I> BCH of MB2 read from storage
[0001.896] I> BCH address is : 0x8007e000
[0001.900] I> MB2 header integrity check is success
[0001.905] I> Binary magic in BCH component 0 is MB2B
[0001.910] I> component binary type is 6
[0001.913] I> Size of crypto header is 8192
[0001.917] I> strt_pg_num(8464) num_of_pgs(846) read_buf(0x80000000)
[0001.928] I> MB2 binary is read from storage
[0001.933] I> MB2 binary integrity check is success
[0001.938] I> Binary MB2 loaded successfully at 0x80000000 (0x69a70)
[0001.944] I> Task: Map CCPLEX SHARED carveout
[0001.948] I> Task: Prepare MB2 params
[0001.952] I> Task: Dram ecc test
[0001.955] I> Task: Misc NV security settings
[0001.959] I> NVDEC sticky bits programming done
[0001.964] I> Successfully powergated NVDEC
[0001.968] I> Task: Disable/Reload WDT
[0001.971] I> Task: Program misc carveouts
[0001.975] I> Program IPC carveouts
[0001.979] I> Task: Disable SCPM/POD reset
[0001.982] I> SLCG Global override status := 0x0
[0001.987] I> MB1: MSS reconfig completed
I> MB2 (version: 0.0.0.0-t234-54845784-22833a33)
I> t234-A01-0-Silicon (0x12347)
I> Boot-mode : Coldboot
I> Emulation:
I> Entry timestamp: 0x001ec7b3
I> Regular heap: [base:0x40040000, size:0x10000]
I> DMA heap: [base:0x82e000000, size:0x800000]
I> Task: SE error check
I> Task: Crypto init
I> Task: MB2 Params integrity check
I> Task: Enable CCPLEX WDT 5th expiry
I> Task: ARI update carveout TZDRAM
I> Task: Configure OEM set LA/PTSA values
I> Task: Check MC errors
I> Task: SMMU external bypass disable
I> Task: Enable hot-plug capability
I> Task: TZDRAM heap init
I> Task: PSC mailbox init
I> Task: Enable clock for external modules
I> Task: Measured Boot init
I> Task: fTPM silicon identity init
I> fTPM is not enabled.
I> Task: OEM SC7 context save init
I> Task: I2C register
I> Task: Map CCPLEX_INTERWORLD_SHMEM carveout
I> Task: Program CBB PCIE AMAP regions
I> Task: Boot device init
I> Boot_device: QSPI_FLASH instance: 0
I> Qspi clock source : pllc_out0
I> QSPI Flash: Macronix 64MB
I> QSPI-0l initialized successfully
I> Secondary storage device: QSPI_FLASH instance: 0
I> Secondary storage device: SDMMC_USER instance: 3
I> sdmmc HS400 mode enabled
I> Task: Partition Manager Init
I> strt_pg_num(1) num_of_pgs(1) read_buf(0x82e001000)
I> strt_pg_num(131071) num_of_pgs(1) read_buf(0x82e001000)
I> strt_pg_num(131039) num_of_pgs(32) read_buf(0x82e001200)
I> Found 60 partitions in QSPI_FLASH (instance 0)
W> Cannot find any partition table for 00000003
W> PARTITION_MANAGER: Failed to publish partition.
I> Found 15 partitions in SDMMC_USER (instance 3)
I> Task: Pass DRAM ECC PRL Flag to FSI
I> Task: Load and authenticate registered FWs
I> Task: Load AUXP FWs
I> Successfully register SPE FW load task with MB2 loader
I> Successfully register RCE FW load task with MB2 loader
I> Successfully register DCE FW load task with MB2 loader
I> Unpowergating APE
I> Unpowergate done
I> Successfully register APE FW load task with MB2 loader
I> Skipping FSI FW load
I> Successfully register XUSB FW load task with MB2 loader
I> Successfully register PVA FW load task with MB2 loader
I> Partition name: A_spe-fw
I> Size of partition: 589824
I> Binary@ device:3/0 block-55040 (partition size: 0x90000), name: A_spe-fw
I> strt_pg_num(55040) num_of_pgs(16) read_buf(0x40067a30)
I> strt_pg_num(55056) num_of_pgs(512) read_buf(0x82d600000)
I> RSA PSS signature check: OK
I> Partition name: A_rce-fw
I> Size of partition: 1048576
I> Binary@ device:3/0 block-56192 (partition size: 0x100000), name: A_rce-fw
I> strt_pg_num(56192) num_of_pgs(16) read_buf(0x40067a30)
I> strt_pg_num(56208) num_of_pgs(880) read_buf(0x82d200000)
I> spe: Authentication Finalize Done
I> Binary spe loaded successfully at 0x82d600000
I> RSA PSS signature check: OK
I> Partition name: A_dce-fw
I> Size of partition: 5242880
I> Binary@ device:3/0 block-44800 (partition size: 0x500000), name: A_dce-fw
I> strt_pg_num(44800) num_of_pgs(16) read_buf(0x40067a30)
I> rce: Authentication Finalize Done
I> Binary rce loaded successfully at 0x82d200000
I> Successfully register RCE FW context save task with MB2 loader
I> RSA PSS signature check: OK
I> dce : oem authentication of header done
I> strt_pg_num(44816) num_of_pgs(1) read_buf(0x82e1403d8)
I> strt_pg_num(44816) num_of_pgs(8) read_buf(0x82e1403d8)
I> dce : meta-blob integrity check is success.
I> strt_pg_num(44824) num_of_pgs(512) read_buf(0x82e0003c0)
I> strt_pg_num(45336) num_of_pgs(512) read_buf(0x82e0403c0)
I> dce : will be decompressed at 0x836000000
I> version 1 Bin 1 BCheckSum 0 content_size 0 Content ChkSum 1 reserved_00 0
I> Reserved10 0 BlockMaxSize 5 Reserved11 0
I> strt_pg_num(45848) num_of_pgs(512) read_buf(0x82e0803c0)
I> dce : decompressed to 12067600 bytes
I> dce: plain binary integrity check is success
I> Partition name: A_adsp-fw
I> Size of partition: 2097152
I> Binary@ device:3/0 block-58240 (partition size: 0x200000), name: A_adsp-fw
I> strt_pg_num(58240) num_of_pgs(16) read_buf(0x40067a30)
I> strt_pg_num(58256) num_of_pgs(800) read_buf(0x838800000)
I> dce: Authentication Finalize Done
I> Binary dce loaded successfully at 0x836000000
I> RSA PSS signature check: OK
I> Partition name: A_xusb-fw
I> Size of partition: 262144
I> Binary@ device:3/0 block-9472 (partition size: 0x40000), name: A_xusb-fw
I> strt_pg_num(9472) num_of_pgs(16) read_buf(0x40067a30)
I> strt_pg_num(9488) num_of_pgs(312) read_buf(0x82d700000)
I> ape: Authentication Finalize Done
I> Binary ape loaded successfully at 0x838800000
I> Successfully register APE FW context save task with MB2 loader
I> RSA PSS signature check: OK
I> Partition name: A_pva-fw
I> Size of partition: 262144
I> Binary@ device:3/0 block-62336 (partition size: 0x40000), name: A_pva-fw
I> strt_pg_num(62336) num_of_pgs(16) read_buf(0x40067a30)
I> xusb: Authentication Finalize Done
I> Binary xusb loaded successfully at 0x82d700000
I> Successfully register XUSB FW context save task with MB2 loader
I> RSA PSS signature check: OK
I> pva-fw : oem authentication of header done
I> strt_pg_num(62352) num_of_pgs(1) read_buf(0x82e1403d8)
I> strt_pg_num(62352) num_of_pgs(8) read_buf(0x82e1403d8)
I> pva-fw : meta-blob integrity check is success.
I> strt_pg_num(62360) num_of_pgs(512) read_buf(0x82e0003c0)
I> pva-fw : will be decompressed at 0x82d980000
I> version 1 Bin 1 BCheckSum 0 content_size 0 Content ChkSum 1 reserved_00 0
I> Reserved10 0 BlockMaxSize 5 Reserved11 0
I> pva-fw : decompressed to 2156512 bytes
I> pva-fw: plain binary integrity check is success
I> pva-fw: Authentication Finalize Done
I> Binary pva-fw loaded successfully at 0x82d980000
I> Successfully register PVA FW context save task with MB2 loader
I> Task: Check MC errors
I> Task: Carveout setup
I> Program remaining OEM carveouts
I> Task: Enable FSITHERM
I> Task: Enable FSI VMON
I> FSI VMON: FSI Vmon re-calibration and fine tuning done
I> Task: Validate FSI Therm readings
I> Task: Restore XUSB sec
I> Task: Enable FSI SE clock
I> Enable FSI-SE clock…
I> Task: Initialize SBSA UART CAR
I> Task: Initialize CPUBL Params
I> CPUBL-params @ 0x832000000
I> Task: Ratchet update
W> Skip ratchet update - OPTIN fuse not set
I> Task: Prepare eeprom data
I> Task: Revoke PKC fuse
I> PKC revoke fuse burn not requested
I> Task: FSI padctl context save
I> Task: Unpowergate APE
W> mb2_unpowergate_ape: skip! APE is in unpowergated state
I> Task: Memctrl reconfig pending clients
I> Task: OEM firewalls
I> OEM firewalls configured
I> Task: Powergate APE
I> Powergating APE
I> Powergate done
I> Task: OEM firewall restore saved settings
I> Task: Unhalt AUXPs
I> Unhalting SPE..
I> Enabling combined UART
����spe: early_init
����vic initialized
�⸸��tsc initialized
����aon lic initialized
�ุ��spe: tag is 5243985d1b1eb3f06fac6d36bd7e74ac
����spe: SafeRTOS v8.4
�ุ��spe: init
����scheduler initialized
�ุ��aon hsp initialized
����tag initialized
�ุ��tcu initialized
����bpmp ipc initialized
�ุ��spe: late init
����cpu_nic clock initialized
�ุ��apb clock initialized
����pm initialized
�ุ��bpmp hsp initialized
����top1 hsp initialized
�ุ��ccplex ipc initialized
����spe: start scheduler
�ุ��
I> Task: Trigger mailbox for PSC-BL1 exit
I> Sending opcode 0x4d420802 to psc
I> Received ACK from psc
I> Task: Start secure NOR provision
I> Skip Secure NOR provisioning
I> Task: Trigger load FSI keyblob
I> Skipping FSI key blob copy
I> Task: Complete load FSI keyblob
I> Skipping FSI key blob copy
I> Task: MB2-PSC_FW Key Manager Init
I> Sending opcode OP_PSC_KEY_MANAGER to psc-fw
I> Sending opcode 0x4b45594d to psc
I> Received ACK from psc
I> Task: Unhalt FSI
I> FSI unhalt skipped
I> Task: Unhalt AUXPs
I> Unhalting RCE
I> RCE unhalt successful
I> Unhalting DCE
I> DCE unhalt successful
I> APE unhalt skipped
I> Task: Load HV/CPUBL
I> Task: Load TOS
I> Task: Trigger load TS��[ 2.539887] Camera-FW on t234-rce-safe started
��EC ��TCU early console enabled.
��leyblob
I> Sending opcode 0x53535452 to psc
I> Sent opcode to psc
I> Task: Load and authenticate registered FWs
I> Partition name: A_cpu-bootloader
I> Size of partition: 3670016
I> Binary@ device:3/0 block-24832 (partition size: ��
��0x380000), name: A_cpu-bootloader
I> strt_pg_num(24832) num_of_pgs(16) read_buf(0x40067a30)
��DCE Started
��I> RSA PSS signature check: OK
I> cpubl : oem authentication of header done
I> strt_pg_num(24848) num_of_pgs(1) read_buf(0x82e143f98)
��DCE_R5_Init
��I> strt_pg_num(24848) num_of_pgs(8) read_buf(0x82e143f98)
I> cpubl : meta-blob integrity check is success.��MPU enabled
��
I> strt_pg_num(24856) num_of_pgs(512) read_buf(0x82e003f80)
��DCE_SW_Init
��I> strt_pg_num(25368) num_of_pgs(512) read_buf(0x82e043f80)
I> cpubl : will be decompressed at 0x82c800000
I> version 1 Bin 1 BCheckSum 0 content_size 0 Content ChkSum 1 reserved_00 0
I> Reserved10 0 BlockMaxSize 5 Reserved11 0
I> strt_pg_num(25880) num_of_pgs(512) read_buf(0x82e083f80)
I> strt_pg_num(26392) num_of_pgs(512) read_buf(0x82e0c3f80)
I> strt_pg_num(26904) num_of_pgs(512) read_buf(0x82e103f80)
I> strt_pg_num(27416) num_of_pgs(512) read_buf(0x82e003f80)
I> strt_pg_num(27928) num_of_pgs(512) read_buf(0x82e043f80)
I> strt_pg_num(28440) num_of_pgs(512) read_buf(0x82e083f80)
I> strt_pg_num(28952) num_of_pgs(512) read_buf(0x82e0c3f80)
I> strt_pg_num(29464) num_of_pgs(512) read_buf(0x82e103f80)
I> strt_pg_num(29976) num_of_pgs(512) read_buf(0x82e003f80)
I> strt_pg_num(30488) num_of_pgs(512) read_buf(0x82e043f80)
I> strt_pg_num(31000) num_of_pgs(512) read_buf(0x82e083f80)
I> cpubl : decompressed to 3661952 bytes
I> cpubl: plain binary integrity check is success
I> Partition name: A_secure-os
I> Size of partition: 4194304
I> Binary@ device:3/0 block-32000 (partition size: 0x400000), name: A_secure-os
I> strt_pg_num(32000) num_of_pgs(16) read_buf(0x40067a30)
I> strt_pg_num(32016) num_of_pgs(3672) read_buf(0x83fd35000)
I> MB2-params @ 0x40060000
I> NSDRAM carveout base: 0x80000000, size: 0x7acdf0000
I> cpubl_params: nsdram: carveout: 1, encryption: 1
I> cpubl: Authentication Finalize Done
I> Binary cpubl loaded successfully at 0x82c800000
I> RSA PSS signature check: OK
I> tos: Authentication Finalize Done
I> Binary tos loaded successfully at 0x83fd35000
I> Relocating OP-TEE dtb from: 0x83feff180 to 0x83c040020, size: 0x2754
I> [0] START: 0x80000000, SIZE: 0x7acdf0000
I> [1] START: 0x832000000, SIZE: 0x2000000
I> Setting NS memory ranges to OP-TEE dtb finished.
I> Partition name: A_eks
I> Size of partition: 262144
I> Binary@ device:3/0 block-44288 (partition size: 0x40000), name: A_eks
I> strt_pg_num(44288) num_of_pgs(16) read_buf(0x40067a30)
I> strt_pg_num(44304) num_of_pgs(8) read_buf(0x83c0��[ 2.790899] Camera-FW on t234-rce-safe ready SHA1=e2238c99 (crt 12.418 ms, total boot 264.502 ms)
��20000)
I> RSA PSS signature check: OK
I> eks: Authentication Finalize Done
I> Binary eks loaded successfully at 0x83c020000
I> EKB detected (length: 0x410) @ VA:0x83c020000
I> Task: Add cpubl params integrity check
I> Added cpubl params digest.
I> Task: Prepare TOS params
I> Setting EKB blob info to OPTEE dtb finished.
I> Setting OPTEE arg3: 0x83c040020
I> NVRNG: Health check success
I> NVRNG: Health check success
I> Task: OEM SC7 context save
I> OEM sc7 context saved
I> Task: Disable MSS perf stats
I> Task: Program display sticky bits
I> Task: Storage device deinit
I> Task: SMMU init
I> Task: Program GICv3 registers
I> Task: Audit firewall settings
I> Task: Bootchain failure check
I> Current Boot-Chain Slot: 0
I> BR-BCT Boot-Chain is 0, and status is 1. Set UPDATE_BRBCT bit to 0
I> Task: Burn RESERVED_ODM0 fuse
I> Task: Lock fusing
I> Task: Clear dec source key
��Admin Task Init
Admin Task Init complete
Print Task Init
RM Task Init
SHA Task Init
Admin Task Started
DCE SC7 SHA Enabled
RM Task Started
RM Task Running
Print Task S��W> Nothing to clear as the encryption bit is not set in FUSE_BOOT_SECURITY_INF��tarted
Print Task Running
SHA Task Started
SHA Task Running
DCE: FW Boot Complete
Admin Task Running
��O fuse
I> MB2 finished

��NOTICE: BL31: v2.8(release):e12e3fa93
NOTICE: BL31: Built : 21:01:44, Sep 12 2024
I/TC:
I/TC: Non-secure external DT found
I/TC: OP-TEE version: 4.2 (gcc version 11.3.0 (Buildroot 2022.08)) #2 Fri Sep 13 04:10:17 UTC 2024 aarch64
I/TC: WARNING: This OP-TEE configuration might be insecure!
I/TC: WARNING: Please check Porting guidelines — OP-TEE documentation documentation
I/TC: Primary CPU initializing
I/TC: fTPM ID is not enabled.
I/TC: ftpm-helper PTA: fTPM DT or EKB is not available. fTPM provisioning is not supported.
I/TC: Primary CPU switching to normal world boot
��
Jetson UEFI firmware (version 36.4.0-gcid-37537400 built on 2024-09-13T04:02:39+00:00)

this is our boot log

ok we finally find secure boot do not work is because the SecurityMode fuse not burned;