View Issue Details

IDProjectCategoryView StatusLast Update
0001147K18X001.00 SKB SWANSWpublic2022-08-16 09:16
Reporter(ALTech) Wooshin Kang Assigned To(ALTech) Wooshin Kang Due Date2021-02-19 17:16
PriorityurgentSeveritys6-featureReproducibilityalways
Status closedResolutionfixed 
Summary0001147: [SWAN] The ND(SD) image must not be updated in the secured(none secured) box.
DescriptionI write it for monitoring
<Synaptics jira>
https://synaextjira.atlassian.net/jira/software/c/projects/SKBSBALT/issues/SKBSBALT-121
TagsNo tags attached.
Attach Tags

Users monitoring this issue

User List (ALTech) SH Son

Activities

(ALTech) Wooshin Kang

2021-02-22 14:19

developer   ~0006121

Any update ..?

(SW) Jacky Chiang

2021-02-22 19:47

manager   ~0006126

Synaptics owner told us that they need to discuss this request internally because it's not supported in current code base.
We already asked him to reply their evaluation result in JIRA-121 directly.

(SW) Bcan Yeh

2021-02-24 09:00

developer   ~0006139

Hi Wooshin,
Synaptics replied that they have no plan to support this feature.
Please check it on jira.

(ALTech) Wooshin Kang

2021-03-03 12:48

developer   ~0006205

Hi Bcan Yeh

We have 7-8 secured B/D which is flashed non-secure image.
How can we recovery it ?
Please give a guide.

Thanks.

(SW) Jerry Lin

2021-03-03 13:51

developer   ~0006206

Last edited: 2021-03-03 15:03

Hi Wooshin,
You can only update firmware via secured SPI Card.
So you need to disassemble and update firmware via secured SPI card.

1. You can download recovery firmware from the following link.
https://drive.google.com/file/d/1bNHVU9B1VP8OZTNxGFnHF4iPQc9xF-B1/view?usp=sharing
2. unzip recovery firmware firmware.
3. copy eMMCimg_Recovery to USB Storage
4. Upgrade this firmware via secured SPI Card.

Jerry

(SW) River Wong

2021-03-03 15:20

developer   ~0006209

Last edited: 2021-03-03 15:20

Hi Wooshin,

As for secured SPI card.
Jim gave you a secure SPI image in WeChat which can be burned into SPI card.
You can use the following steps to burn it to SPI card. (I assume the file is "spi_uboot_en_signed.bin")
1.Put the "spi_uboot_en_signed.bin" file in usb storage and plug it to SWAN board.
2.Plug the SPI card in to SWAN board and reboots. Wait for it show "Berlin>" in console.
3.Type the following two commands to burn this SPI image into SPI card. Please do not turn off power or unplug the SPI card.
usb start; fatload usb 0 0x10000000 spi_uboot_en_signed.bin; spinit;
protect off f0000000 f00fffff; erase f0000000 f00fffff; cp.b 0x10000000 0xf0000000 0x100000;
4. After these commands finishes, reboot SWAN again. It will boot with new SPI image.

If you have any problem is doing this, please also consult Synaptics Kail. I think he can teach you directly.

(ALTech) SH Son

2021-03-04 17:10

developer   ~0006224

Hi River
I proceeded as I told you, but it's still not booting.
we ask to Synaptics Kail, and he want to check below
 3. Did this Uboot image has been resigned by OEM keys?

Please check and let us know

Thanks
SON

(SW) River Wong

2021-03-04 19:51

developer   ~0006229

Last edited: 2021-03-05 16:52

Hi SH.

I think it is yes for 3. But I need to ask Jim who is taking one day off today.

If you have problem in doing update SPI Card in my steps, Please note the nonsecure SPI card can only boots with non-secure SWAN baord. So I list more details of the SPI card update steps(from non-secure SPI image to secure SPI image):
1.Put the "spi_uboot_en_signed.bin" file in usb storage and plug it to "Non-Secure" SWAN board.
2.Plug the SPI card into a "Non-Secure" SWAN board and reboots. Wait for it show "Berlin>" in console.
3.Type the following two commands to burn this SPI image into SPI card. Please do not turn off power or unplug the SPI card.
usb start; fatload usb 0 0x10000000 spi_uboot_en_signed.bin; spinit;

protect off f0000000 f00fffff; erase f0000000 f00fffff; cp.b 0x10000000 0xf0000000 0x100000;

4. After these commands finishes (show "Berlin>"), take the SPI Card to a "Secure" SWAN board.
    Make sure it can boots on Secure SWAN board with this secure SPI Card.
    Then you can use "usb2emmc" command and secure eMMCimg to rescue the rescue Secure SWAN board.

(SW) River Wong

2021-03-05 16:53

developer   ~0006244

Hi SH,

I confirm with Jim that our SPI image is signed by our OEM key.
Are you able to rescue those SWAN Boards?
Please let us know your progress and then we can help you. Thanks.

(ALTech) Wooshin Kang

2021-03-06 08:26

developer   ~0006248

Hi river,

SH was trying to rescue but he got a fail. Secure spi b/d was made by your comment and can see only below string in terminal when power on.

|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||

Thanks.

(SW) River Wong

2021-03-08 08:58

developer   ~0006250

Hi Wooshin and SH,

I can also see the |||||||||| when I use "Secure SWAN board" + "NonSecure SPI card".
So, I think the SPI card is not programmed successfully.
You can try to use the SH programmed SPI card on "NonSecure SWAN board". If you can boot it to show prompt "Berlin>" then it means it is "NonSecure SPI card". Then you have to program SPI card again. (Please note the 0001147:0006229 step3 are two commands and the filename must match the file in your usb storage).
For make sure we are using the same secure SPI image, I reattached it here again.

Please note, "Non secure SPI card" can only be used to boot "NonSecure SWAN board". "Secure SPI card" can only be used to boot "Secure SWAN board"
If you use "Non secure SPI card" + "Secure SWAN board", You will see "|||||||||||||||".
If you use "Secure SPI card" + "NonSecure SWAN board", you will see the following messages repeatedly:
init cpupll 800MHz
init mempll 2400MHz
init 3GB DDR, lib version r63074
hw_init done
custom table done
asking BCM to load miniloader.
spi_uboot_en_signed.bin (697,344 bytes)

(ALTech) Wooshin Kang

2021-03-09 16:03

developer   ~0006273

Hi River,

We were successful to rescue using spi b/d but you have to check writing command for secure image.
Used command is below.
usb start; fatload usb 0 0x10000000 spi_uboot_en_signed.bin; spinit; erase f0000000 f03fffff; cp.b 0x10000000 0xf0000000 0x100000;

(SW) River Wong

2021-03-11 09:19

developer   ~0006298

Hi Wooshin,

Good to know you can rescue the secured board.
The command I gave you is what we used for programming SPI card and we tested it several times and it works.
And I think your command is also OK.

(SW) River Wong

2021-12-22 15:03

developer   ~0009021

We add a protection code to avoid ND and SD image upgrade by following commit.

Author: Jason Ling <jason.tf.ling@fii-foxconn.com>
Date: Wed May 5 14:29:33 2021 +0800

    Aborting the upgrade process when the type of secure boot is inconsistent

(SW) River Wong

2021-12-22 15:04

developer   ~0009022

Hi Wooshin,

If no problem found, please Close it.

(SW) Jacky Chiang

2022-08-16 09:16

manager   ~0010628

Already fixed and close it.

Issue History

Date Modified Username Field Change
2021-02-18 16:23 (ALTech) Wooshin Kang New Issue
2021-02-18 16:23 (ALTech) Wooshin Kang Status new => assigned
2021-02-18 16:23 (ALTech) Wooshin Kang Assigned To => (SW) Jacky Chiang
2021-02-22 14:19 (ALTech) Wooshin Kang Note Added: 0006121
2021-02-22 19:47 (SW) Jacky Chiang Note Added: 0006126
2021-02-22 19:47 (SW) Jacky Chiang Assigned To (SW) Jacky Chiang => (SW) Bcan Yeh
2021-02-24 09:00 (SW) Bcan Yeh Note Added: 0006139
2021-02-24 09:00 (SW) Bcan Yeh Assigned To (SW) Bcan Yeh => (ALTech) Wooshin Kang
2021-03-02 19:51 (SW) Jacky Chiang Status assigned => acknowledged
2021-03-03 12:48 (ALTech) Wooshin Kang Note Added: 0006205
2021-03-03 13:51 (SW) Jerry Lin Note Added: 0006206
2021-03-03 15:03 (SW) Jerry Lin Note Edited: 0006206
2021-03-03 15:20 (SW) River Wong Note Added: 0006209
2021-03-03 15:20 (SW) River Wong Note Edited: 0006209
2021-03-04 17:10 (ALTech) SH Son Note Added: 0006224
2021-03-04 19:51 (SW) River Wong Note Added: 0006229
2021-03-05 16:49 (SW) River Wong Issue Monitored: (ALTech) SH Son
2021-03-05 16:52 (SW) River Wong Note Edited: 0006229
2021-03-05 16:53 (SW) River Wong Note Added: 0006244
2021-03-06 08:26 (ALTech) Wooshin Kang Note Added: 0006248
2021-03-06 08:27 (ALTech) Wooshin Kang Assigned To (ALTech) Wooshin Kang => (SW) River Wong
2021-03-08 08:58 (SW) River Wong File Added: spi_uboot_en_signed.bin
2021-03-08 08:58 (SW) River Wong Note Added: 0006250
2021-03-09 16:03 (ALTech) Wooshin Kang Note Added: 0006273
2021-03-11 09:19 (SW) River Wong Note Added: 0006298
2021-03-15 10:38 (SW) River Wong Assigned To (SW) River Wong => (ALTech) Wooshin Kang
2021-12-22 15:03 (SW) River Wong Status acknowledged => resolved
2021-12-22 15:03 (SW) River Wong Resolution open => fixed
2021-12-22 15:03 (SW) River Wong Note Added: 0009021
2021-12-22 15:04 (SW) River Wong Note Added: 0009022
2021-12-24 16:37 (SW) River Wong Severity s2-severe => s4-minor
2022-01-07 09:02 (SW) River Wong Severity s4-minor => s6-feature
2022-08-16 09:16 (SW) Jacky Chiang Status resolved => closed
2022-08-16 09:16 (SW) Jacky Chiang Note Added: 0010628