User Tools

Site Tools


projects:panohax

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
projects:panohax [2026/08/14 08:41] – [RCM/TegraFlash] informaticprojects:panohax [2026/08/14 09:37] (current) – [Flash Layout] q3k
Line 11: Line 11:
 ==== TX1 ==== ==== TX1 ====
  
-Stock module, probably 4GiB LPDDR4 and 16GB eMMC?+Stock module, 4GiB LPDDR416GB eMMC. Production-fused.
  
 ==== I/O ==== ==== I/O ====
Line 39: Line 39:
  
 Jetson TX1 is SecureBoot/Production-fused. Standard CBoot (first-stage bootloader) is **unlocked** ie. it does not do any signature verification over loaded ''boot'' partition or the operating system altogether. Jetson TX1 is SecureBoot/Production-fused. Standard CBoot (first-stage bootloader) is **unlocked** ie. it does not do any signature verification over loaded ''boot'' partition or the operating system altogether.
 +
 +==== Flash Layout ====
 +
 +(in bold our current best guess for what the bootchain needs to get to CBOOT.
 +
 +^ Number ^ Start ^ Size ^ Name ^ Description ^
 +| 1 | 17.4kB | 2097kB | **BPF** | TegraBoot (a.k.a. nvtboot) for BPMP |
 +| 2 | 2115kB | 262kB | **TBC** | TegraBoot for CPU |
 +| 3 | 2377kB | 262kB | TBC-B | TegraBoot for CPU, B-partition |
 +| 4 | 2639kB | 2097kB | **EBT** | CBOOT, loaded by TegraBoot |
 +| 5 | 4736kB | 2097kB | RBL | CBOOT, B-partition |
 +| 6 | 6833kB | 2097kB | NCT | Non-volatile vital product data |
 +| 7 | 8930kB | 6291kB | WB0 | Warm Boot Firmware for device unsuspend |
 +| 8 | 15.2MB | 2097kB | DFI | all 0x00 |
 +| 9 | 17.3MB | 4194kB | **RP1** | DTB for CBOOT |
 +| 10 | 21.5MB | 4194kB | RP2 | 0x24 random bytes, then 0x00 |
 +| 11 | 25.7MB | 6291kB | **TOS** | Trusted OS/Firmware, loaded by TegraBoot |
 +| 12 | 32.0MB | 80.9kB | EKS | "Encrypted Key Storage" |
 +| 13 | 32.1MB | 2097kB | UKS | all 0x00 |
 +| 14 | 34.2MB | 2097kB | FB | all 0x00 |
 +| 15 | 36.3MB | 134MB | BMP | Splashscreen partition |
 +| 16 | 170MB | 26.7MB | SOS | Android Recovery image |
 +| 17 | 197MB | 4194kB | DTB | DTB for Kernel |
 +| 18 | 201MB | 26.7MB | LNX | Android Boot image ("boot" fastboot partition) |
 +| 19 | 228MB | 2147MB | APP | ext4 /system |
 +| 20 | 2376MB | 2147MB | CAC | ext4 /cache |
 +| 21 | 4523MB | 805MB | vendor | ext4 /vendor |
 +| 22 | 5328MB | 2097kB | MSC | all 0x00 |
 +| 23 | 5331MB | 33.6MB | USP | all 0x00 |
 +| 24 | 5364MB | 2097kB | MDA | verity metadata partition |
 +| 25 | 5366MB | 8389kB | RP3 | empty ext4 |
 +| 26 | 5375MB | 8389kB | RP4 | all 0x00 |
 +| 27 | 5383MB | 16.8MB | FCT | empty ext4 |
 +| 28 | 5400MB | 8389kB | UCB | empty ext4, "touchscreen" and "mpu" directories |
 +| 29 | 5408MB | 2147MB | FAC | ext4 with "factory_restore.zip" update image applied when touch button is pressed on boot |
 +| 30 | 7556MB | 1074MB | PLC | ext4 with some polycom config stuff |
 +| 31 | 8629MB | 262kB | CRT | public/private key pair? |
 +| 32 | 8630MB | 7128MB | UDA | ext4 /data |
  
 ===== Flashing ===== ===== Flashing =====
Line 91: Line 129:
  
   * https://yifan.lu/2022/06/17/unbricking-shield-tv-2015-with-a-bootrom-exploit/   * https://yifan.lu/2022/06/17/unbricking-shield-tv-2015-with-a-bootrom-exploit/
 +  * https://docs.nvidia.com/jetson/archives/l4t-archived/l4t-3275/index.html#page/Tegra%20Linux%20Driver%20Package%20Development%20Guide/part_config.html
projects/panohax.1786696905.txt.gz · Last modified: by informatic

Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki