<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LS1021a - Secure Debug and BOOT_HO setting in QorIQ</title>
    <link>https://community.nxp.com/t5/QorIQ/LS1021a-Secure-Debug-and-BOOT-HO-setting/m-p/2121380#M12349</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have a LS1021a setup, where I implemented secure boot and it is working fine. The board is booting from QSPI flash.&lt;/P&gt;&lt;P&gt;I have done this by programming OTPMK, using BOOT_HO and SB_EN in the RCW, and writing SRKH with the help of the debugger.&lt;/P&gt;&lt;P&gt;Once this was OK, i started programming the SRKH and setting ITS fuse.&lt;/P&gt;&lt;P&gt;Additionally, JTAG was closed by setting it to&amp;nbsp;conditionally open via challenge/response, without notification.&lt;/P&gt;&lt;P&gt;The secure debug feature works too, I can use the debugger to perform debugging once the SDCR has been read and the SDDR has been written.&lt;/P&gt;&lt;P&gt;So far, everything works as expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I was trying to hold the CPU again in boot, so setting BOOT_HO in the RCW again, with secure debug enabled.&lt;/P&gt;&lt;P&gt;But now I'm seeing that the CPU is not even fetching the RCW as before (where secure debug was not enabled yet).&lt;/P&gt;&lt;P&gt;The strange thing is that in this scenario reading or writing other registers via DAP/SAP2 does not work.&lt;/P&gt;&lt;P&gt;A CCS console trace of this behavior:&lt;/P&gt;&lt;P&gt;(bin) 687 % ccs::config_chain {ls1020a dap sap2}&lt;BR /&gt;LS1020A: Secure debug violation&lt;BR /&gt;(bin) 687 % display ccs::read_reg 0 sdcr 1 8&lt;BR /&gt;sdcr=0xC0C0C0C0 D0D0D0D0&lt;BR /&gt;(bin) 688 % ccs::write_reg 0 sdrr 8 {0xXXXXXXXX 0xXXXXXXXX}&lt;BR /&gt;(bin) 689 % ccs::config_chain {ls1020a dap sap2}&lt;BR /&gt;(bin) 690 % ccs::config_chain {ls1020a dap sap2}&lt;BR /&gt;(bin) 690 % display ccs::get_config_chain&lt;BR /&gt;Chain Position 0: LS1020A&lt;BR /&gt;Chain Position 1: CoreSight ATB Funnel&lt;BR /&gt;Chain Position 2: CoreSight TMC&lt;BR /&gt;Chain Position 3: CoreSight TMC&lt;BR /&gt;Chain Position 4: CoreSight TMC&lt;BR /&gt;Chain Position 5: CoreSight CTI&lt;BR /&gt;Chain Position 6: CoreSight CTI&lt;BR /&gt;Chain Position 7: CoreSight CTI&lt;BR /&gt;Chain Position 8: CoreSight ATB Funnel&lt;BR /&gt;Chain Position 9: Cortex-A7&lt;BR /&gt;Chain Position 10: Cortex-A7 PMU&lt;BR /&gt;Chain Position 11: Cortex-A7&lt;BR /&gt;Chain Position 12: Cortex-A7 PMU&lt;BR /&gt;Chain Position 13: CoreSight CTI&lt;BR /&gt;Chain Position 14: CoreSight CTI&lt;BR /&gt;Chain Position 15: Cortex-A7 ETM&lt;BR /&gt;Chain Position 16: Cortex-A7 ETM&lt;BR /&gt;Chain Position 17: DAP&lt;BR /&gt;Chain Position 18: SAP2&lt;BR /&gt;(bin) 691 % disp ccs::read_mem 18 0x1e90014 4 0 1&lt;BR /&gt;+0 +4 +8 +C&lt;BR /&gt;[0x01E90014] 00000000&lt;BR /&gt;(bin) 692 % disp ccs::read_reg 0 rcw0 15&lt;BR /&gt;rcw0=0x00000000 rcw1=0x00000000 rcw2=0x00000000 rcw3=0x00000000&lt;BR /&gt;rcw4=0x00000000 rcw5=0x00000000 rcw6=0x00000000 rcw7=0x00000000&lt;BR /&gt;rcw8=0x00000000 rcw9=0x00000000 rcw10=0x00000000 rcw11=0x00000000&lt;BR /&gt;rcw12=0x00000000 rcw13=0x00000000 rcw14=0x00000000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again, the exact same sequence (setting BOOT_HO=1) works without having secure debug in place:&lt;/P&gt;&lt;P&gt;(bin) 696 % ccs::config_chain {ls1020a dap sap2}&lt;BR /&gt;(bin) 697 % disp ccs::read_mem 18 0x1e90014 4 0 1&lt;BR /&gt;+0 +4 +8 +C&lt;BR /&gt;[0x01E90014] 80002900&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any additional step I need to perform to be able to read/write registers with secure debug in place?&lt;/P&gt;</description>
    <pubDate>Mon, 23 Jun 2025 11:03:28 GMT</pubDate>
    <dc:creator>stefanhauser</dc:creator>
    <dc:date>2025-06-23T11:03:28Z</dc:date>
    <item>
      <title>LS1021a - Secure Debug and BOOT_HO setting</title>
      <link>https://community.nxp.com/t5/QorIQ/LS1021a-Secure-Debug-and-BOOT-HO-setting/m-p/2121380#M12349</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have a LS1021a setup, where I implemented secure boot and it is working fine. The board is booting from QSPI flash.&lt;/P&gt;&lt;P&gt;I have done this by programming OTPMK, using BOOT_HO and SB_EN in the RCW, and writing SRKH with the help of the debugger.&lt;/P&gt;&lt;P&gt;Once this was OK, i started programming the SRKH and setting ITS fuse.&lt;/P&gt;&lt;P&gt;Additionally, JTAG was closed by setting it to&amp;nbsp;conditionally open via challenge/response, without notification.&lt;/P&gt;&lt;P&gt;The secure debug feature works too, I can use the debugger to perform debugging once the SDCR has been read and the SDDR has been written.&lt;/P&gt;&lt;P&gt;So far, everything works as expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I was trying to hold the CPU again in boot, so setting BOOT_HO in the RCW again, with secure debug enabled.&lt;/P&gt;&lt;P&gt;But now I'm seeing that the CPU is not even fetching the RCW as before (where secure debug was not enabled yet).&lt;/P&gt;&lt;P&gt;The strange thing is that in this scenario reading or writing other registers via DAP/SAP2 does not work.&lt;/P&gt;&lt;P&gt;A CCS console trace of this behavior:&lt;/P&gt;&lt;P&gt;(bin) 687 % ccs::config_chain {ls1020a dap sap2}&lt;BR /&gt;LS1020A: Secure debug violation&lt;BR /&gt;(bin) 687 % display ccs::read_reg 0 sdcr 1 8&lt;BR /&gt;sdcr=0xC0C0C0C0 D0D0D0D0&lt;BR /&gt;(bin) 688 % ccs::write_reg 0 sdrr 8 {0xXXXXXXXX 0xXXXXXXXX}&lt;BR /&gt;(bin) 689 % ccs::config_chain {ls1020a dap sap2}&lt;BR /&gt;(bin) 690 % ccs::config_chain {ls1020a dap sap2}&lt;BR /&gt;(bin) 690 % display ccs::get_config_chain&lt;BR /&gt;Chain Position 0: LS1020A&lt;BR /&gt;Chain Position 1: CoreSight ATB Funnel&lt;BR /&gt;Chain Position 2: CoreSight TMC&lt;BR /&gt;Chain Position 3: CoreSight TMC&lt;BR /&gt;Chain Position 4: CoreSight TMC&lt;BR /&gt;Chain Position 5: CoreSight CTI&lt;BR /&gt;Chain Position 6: CoreSight CTI&lt;BR /&gt;Chain Position 7: CoreSight CTI&lt;BR /&gt;Chain Position 8: CoreSight ATB Funnel&lt;BR /&gt;Chain Position 9: Cortex-A7&lt;BR /&gt;Chain Position 10: Cortex-A7 PMU&lt;BR /&gt;Chain Position 11: Cortex-A7&lt;BR /&gt;Chain Position 12: Cortex-A7 PMU&lt;BR /&gt;Chain Position 13: CoreSight CTI&lt;BR /&gt;Chain Position 14: CoreSight CTI&lt;BR /&gt;Chain Position 15: Cortex-A7 ETM&lt;BR /&gt;Chain Position 16: Cortex-A7 ETM&lt;BR /&gt;Chain Position 17: DAP&lt;BR /&gt;Chain Position 18: SAP2&lt;BR /&gt;(bin) 691 % disp ccs::read_mem 18 0x1e90014 4 0 1&lt;BR /&gt;+0 +4 +8 +C&lt;BR /&gt;[0x01E90014] 00000000&lt;BR /&gt;(bin) 692 % disp ccs::read_reg 0 rcw0 15&lt;BR /&gt;rcw0=0x00000000 rcw1=0x00000000 rcw2=0x00000000 rcw3=0x00000000&lt;BR /&gt;rcw4=0x00000000 rcw5=0x00000000 rcw6=0x00000000 rcw7=0x00000000&lt;BR /&gt;rcw8=0x00000000 rcw9=0x00000000 rcw10=0x00000000 rcw11=0x00000000&lt;BR /&gt;rcw12=0x00000000 rcw13=0x00000000 rcw14=0x00000000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again, the exact same sequence (setting BOOT_HO=1) works without having secure debug in place:&lt;/P&gt;&lt;P&gt;(bin) 696 % ccs::config_chain {ls1020a dap sap2}&lt;BR /&gt;(bin) 697 % disp ccs::read_mem 18 0x1e90014 4 0 1&lt;BR /&gt;+0 +4 +8 +C&lt;BR /&gt;[0x01E90014] 80002900&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any additional step I need to perform to be able to read/write registers with secure debug in place?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2025 11:03:28 GMT</pubDate>
      <guid>https://community.nxp.com/t5/QorIQ/LS1021a-Secure-Debug-and-BOOT-HO-setting/m-p/2121380#M12349</guid>
      <dc:creator>stefanhauser</dc:creator>
      <dc:date>2025-06-23T11:03:28Z</dc:date>
    </item>
    <item>
      <title>Re: LS1021a - Secure Debug and BOOT_HO setting</title>
      <link>https://community.nxp.com/t5/QorIQ/LS1021a-Secure-Debug-and-BOOT-HO-setting/m-p/2127713#M12356</link>
      <description>&lt;P&gt;I discussed with the AE team.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If I get customer's idea, when they set BOOT_HO=0, secure debug can't work any more? please help confirm.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;when set BOOT_HO=1, both secure boot and secure debug can work well?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2025 03:25:50 GMT</pubDate>
      <guid>https://community.nxp.com/t5/QorIQ/LS1021a-Secure-Debug-and-BOOT-HO-setting/m-p/2127713#M12356</guid>
      <dc:creator>yipingwang</dc:creator>
      <dc:date>2025-07-03T03:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: LS1021a - Secure Debug and BOOT_HO setting</title>
      <link>https://community.nxp.com/t5/QorIQ/LS1021a-Secure-Debug-and-BOOT-HO-setting/m-p/2128053#M12357</link>
      <description>&lt;P&gt;The issue is like this:&lt;/P&gt;&lt;P&gt;I enabled secure debug and programmed OTPMK as a first step.&lt;/P&gt;&lt;P&gt;Then I wanted to test the SRKH via JTAG by enabling BOOT_HO and SB_EN in the RCW.&lt;/P&gt;&lt;P&gt;But somehow the CPU does not even load the RCW with secure debug in place (or I'm missing some step after doing the challenge/response via JTAG, which works).&lt;/P&gt;&lt;P&gt;The issue is not really important anymore to me, because I used a 2nd CPU module to test the SRKH via JTAG, where I did not enable secure JTAG.&lt;/P&gt;&lt;P&gt;Thanks anyway,&lt;BR /&gt;Stefan&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2025 11:07:17 GMT</pubDate>
      <guid>https://community.nxp.com/t5/QorIQ/LS1021a-Secure-Debug-and-BOOT-HO-setting/m-p/2128053#M12357</guid>
      <dc:creator>stefanhauser</dc:creator>
      <dc:date>2025-07-03T11:07:17Z</dc:date>
    </item>
  </channel>
</rss>

