[LS1046A] Fuse Provisioning Image Fails on OTPMK

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

[LS1046A] Fuse Provisioning Image Fails on OTPMK

Jump to solution
4,276 Views
james_browning
Contributor III

Hello,

I'm trying to create a working fuse provisioning image for programming the fuses of our LS1046A SOCs. I'm following these guides:

The issue I'm hitting is that after enabling POVDD and running the provisioning image, the fuses never get blown. I can see the mirror registers contain the correct expected values when I probe with the codewarrior TAP, but they disappear after a reboot since the fuses are never blown.

When the fuse provisioner, runs I'm getting value 0x19 in the SCRATCHRW4 register. This value indicates an error in writing to the OTPMK (as per include/drivers/nxp/sfp/sfp_error_codes.h

#define ERROR_OTPMK_WRITE		0x19

 

I found that it is getting set by prog_otpmk() as the result of a write failure (drivers/nxp/sfp/fuse_prov.c):

ret = write_fuses(sfp_ccsr_regs->otpmk, fuse_hdr->otpmk, 8);

	if (ret != 0) {
		ret = (ret == ERROR_ALREADY_BLOWN) ?
			ERROR_OTPMK_ALREADY_BLOWN
			: ERROR_OTPMK_WRITE;
	} else {
		 /* Check for DRV hamming error */
		if ((sfp_read32((void *)(get_sfp_addr() + SFP_SVHESR_OFFSET))
			& SFP_SVHESR_OTPMK_MASK) != 0) {
			ret = ERROR_OTPMK_HAMMING_ERROR;
		}
	}

The error code returned from write_fuses() is ERROR_WRITE which indicates the read back failed:

static int write_fuses(uint32_t *fuse_addr, uint32_t *fuse_hdr_val, uint8_t len)
{
	int i;

	 /* Check if fuse already blown or not */
	for (i = 0; i < len; i++) {
		if (sfp_read32(&fuse_addr[i]) != 0) {
			return ERROR_ALREADY_BLOWN;
		}
	}

	 /* Write fuse in mirror registers */
	for (i = 0; i < len; i++) {
		sfp_write32(&fuse_addr[i], fuse_hdr_val[i]);
	}

	 /* Read back to check if write success */
	for (i = 0; i < len; i++) {
		if (sfp_read32(&fuse_addr[i]) != fuse_hdr_val[i]) {
			return ERROR_WRITE;
		}
	}

	return 0;
}

 

This aligns with what I would expect to happen, based on the fact that OTPMK cannot be read back by design. This is explicitly mentioned in several documents:

"For obvious reasons, the SFP does not allow the value written to the OTPMK registers to
be read out. Once a non-zero value is written to any of the OTPMK registers, any read
will return all 1s"

Based on this, I'm not sure how this code is intended to work? The write_fuses() function will always fail on OTPMK because the read back will always return all 1's. I also verified this by reading the OTPMK registers in u-boot and observing they only return 1's. Am I misunderstanding or doing something wrong? OTPMK is required to enable secure boot, so surely this must have worked at some point, but it seems to me in the current state this code cannot be used to enable secure boot on Qoriq Trust platforms (although the documentation mentions support for LS1046A).  We are using the nxp-qoriq atf v2.6 source code by the way. I checked other source versions and it seems this code hasn't really changed.

0 Kudos
Reply
1 Solution
4,107 Views
yipingwang
NXP TechSupport
NXP TechSupport

I checked LLDPUG 5.15 to build Fuse Provisioning ATF image.

Added DISTRO_FEATURES:append = " fuse" in build_ls1046ardb/conf/local.conf, then rebuild atf image.

$ bitbake qoriq-atf -c cleansstate

$ bitbake qoriq-atf

I encountered the error "create: unrecognized option '--fuse-prov'", so there is defect in atf source code to build Fuse Provisioning image in LLDPUG 5.15.

Please use LSDK 21.08 release to build Fuse Provisioning ATF image.

 

View solution in original post

0 Kudos
Reply
7 Replies
4,247 Views
yipingwang
NXP TechSupport
NXP TechSupport

After blow OTPMK fuse, register 0x1e80234-0x1e80250 should be displayed as "ffffffff", before fuse blowing, it should be all "0".

At the U-Boot prompt, verify that the SNVS registers for OTPMK are correctly written.
Check if OPTMK is fused.
=> md $SNVS_HPSR_REG (byte swap)
80000900
OTPMK_ZERO_BIT (second nibble) is 0, indicating that OTPMK is fused.

=>md 1e90014(byte swap)

              80000900

Now you will see ‘0’ in second nibble. No parity errors, i.e. bits marked in read would be all 0’s.

=> md 1e80024

00000000

0 Kudos
Reply
4,233 Views
james_browning
Contributor III

Thank you @yipingwang, but we would specifically like to rely on the fuse provisioning image built by the qoriq atf repo so we can quickly and automatically program the fuses. All of the documents I shared above describe the fuse provisioning feature and explicitly state that it is supported by this SOC, but it seems the source code incorrectly handles reading the OTPMK, and cannot blow the fuses as a result. I'm confused as to how NXP was able to use this to enable secure boot, it seems the source code is incorrect?

0 Kudos
Reply
4,228 Views
yipingwang
NXP TechSupport
NXP TechSupport

Please provide the result of the following command on your custom board.

=>md 1e90014

0 Kudos
Reply
4,217 Views
james_browning
Contributor III

=> md 1e90014
01e90014: 002b0088 00000080 00000000 00000000

0 Kudos
Reply
4,108 Views
yipingwang
NXP TechSupport
NXP TechSupport

I checked LLDPUG 5.15 to build Fuse Provisioning ATF image.

Added DISTRO_FEATURES:append = " fuse" in build_ls1046ardb/conf/local.conf, then rebuild atf image.

$ bitbake qoriq-atf -c cleansstate

$ bitbake qoriq-atf

I encountered the error "create: unrecognized option '--fuse-prov'", so there is defect in atf source code to build Fuse Provisioning image in LLDPUG 5.15.

Please use LSDK 21.08 release to build Fuse Provisioning ATF image.

 

0 Kudos
Reply
4,088 Views
james_browning
Contributor III

Thank you for investigating this @yipingwang. Based on your suggestion, I got fuse fuse provisioning to work by taking the fuse provisioning and sfp code from 21.08 and integrating it into the v2.6 branch (used by lf5.15.71). Since fuse provisioning is not properly supported in lf5.15.71, I think either the code should be patched or the documentation should be updated since it incorrectly states that fuse provisioning is supported.  

0 Kudos
Reply
4,122 Views
james_browning
Contributor III
=> md 1e90014
01e90014: 002b0088 00000080 00000000 00000000 ..+.............
01e90024: 00000000 00000000 00000000 00000000 ................
01e90034: 00000000 00000000 00000000 00000000 ................
01e90044: 00000000 00000000 08000000 00000000 ................
01e90054: 00000000 00000000 00000000 00000000 ................
01e90064: 00000000 00000000 00000000 00000000 ................
01e90074: 00000000 00000000 00000000 00000000 ................
01e90084: 00000000 00000000 00000000 00000000 ................
01e90094: 00000000 00000000 00000000 00000000 ................
01e900a4: 00000000 00000000 00000000 00000000 ................
01e900b4: 00000000 00000000 00000000 00000000 ................
01e900c4: 00000000 00000000 00000000 00000000 ................
01e900d4: 00000000 00000000 00000000 00000000 ................
01e900e4: 00000000 00000000 00000000 00000000 ................
01e900f4: 00000000 00000000 00000000 00000000 ................
01e90104: 00000000 00000000 00000000 00000000 ................
0 Kudos
Reply
%3CLINGO-SUB%20id%3D%22lingo-sub-1976529%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%5BLS1046A%5D%20Fuse%20Provisioning%20Image%20Fails%20on%20OTPMK%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1976529%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3EI'm%20trying%20to%20create%20a%20working%20fuse%20provisioning%20image%20for%20programming%20the%20fuses%20of%20our%20LS1046A%20SOCs.%20I'm%20following%20these%20guides%3A%3C%2FP%3E%3CUL%3E%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fwww.nxp.com%2Fwebapp%2FDownload%3FcolCode%3DLLDPUG_RevL5.15.71-2.2.0%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3ELLDPUG%205.15%3C%2FA%3E%3C%2FLI%3E%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Fpwmxy87654%2Fattachments%2Fpwmxy87654%2FLayerscape%2540tkb%2F158%2F1%2FFuse%2520Provisioning%2520on%2520LS1046ARDB.pdf%22%20target%3D%22_self%22%3EFuse%20Provisioning%20on%20LS1046ARDB%3C%2FA%3E%3C%2FLI%3E%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Ftrustedfirmware-a.readthedocs.io%2Fen%2Flatest%2Fplat%2Fnxp%2Fnxp-ls-fuse-prov.html%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3ETF-A%20Fuse%20Provisioning%3C%2FA%3E%3C%2FLI%3E%3C%2FUL%3E%3CP%3EThe%20issue%20I'm%20hitting%20is%20that%20after%20enabling%20POVDD%20and%20running%20the%20provisioning%20image%2C%20the%20fuses%20never%20get%20blown.%20I%20can%20see%20the%20mirror%20registers%20contain%20the%20correct%20expected%20values%20when%20I%20probe%20with%20the%20codewarrior%20TAP%2C%20but%20they%20disappear%20after%20a%20reboot%20since%20the%20fuses%20are%20never%20blown.%3C%2FP%3E%3CP%3EWhen%20the%20fuse%20provisioner%2C%20runs%20I'm%20getting%20value%200x19%20in%20the%20SCRATCHRW4%20register.%20This%20value%20indicates%20an%20error%20in%20writing%20to%20the%20OTPMK%20(as%20per%26nbsp%3B%3CSTRONG%3Einclude%2Fdrivers%2Fnxp%2Fsfp%2Fsfp_error_codes.h%3C%2FSTRONG%3E%3CLI-EMOJI%20id%3D%22lia_disappointed-face%22%20title%3D%22%3Adisappointed_face%3A%22%3E%3C%2FLI-EMOJI%3E%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-c%22%3E%3CCODE%3E%23define%20ERROR_OTPMK_WRITE%09%090x19%3C%2FCODE%3E%3C%2FPRE%3E%3CBR%20%2F%3E%3CP%3EI%20found%20that%20it%20is%20getting%20set%20by%3CSTRONG%3E%26nbsp%3Bprog_otpmk()%26nbsp%3B%3C%2FSTRONG%3Eas%20the%20result%20of%20a%20write%20failure%20%3CSTRONG%3E(drivers%2Fnxp%2Fsfp%2Ffuse_prov.c)%3A%3CBR%20%2F%3E%3C%2FSTRONG%3E%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-c%22%3E%3CCODE%3Eret%20%3D%20write_fuses(sfp_ccsr_regs-%26gt%3Botpmk%2C%20fuse_hdr-%26gt%3Botpmk%2C%208)%3B%0A%0A%09if%20(ret%20!%3D%200)%20%7B%0A%09%09ret%20%3D%20(ret%20%3D%3D%20ERROR_ALREADY_BLOWN)%20%3F%0A%09%09%09ERROR_OTPMK_ALREADY_BLOWN%0A%09%09%09%3A%20ERROR_OTPMK_WRITE%3B%0A%09%7D%20else%20%7B%0A%09%09%20%2F*%20Check%20for%20DRV%20hamming%20error%20*%2F%0A%09%09if%20((sfp_read32((void%20*)(get_sfp_addr()%20%2B%20SFP_SVHESR_OFFSET))%0A%09%09%09%26amp%3B%20SFP_SVHESR_OTPMK_MASK)%20!%3D%200)%20%7B%0A%09%09%09ret%20%3D%20ERROR_OTPMK_HAMMING_ERROR%3B%0A%09%09%7D%0A%09%7D%3C%2FCODE%3E%3C%2FPRE%3E%3CP%3EThe%20error%20code%20returned%20from%26nbsp%3B%3CSTRONG%3Ewrite_fuses()%3C%2FSTRONG%3E%20is%26nbsp%3B%3CSTRONG%3EERROR_WRITE%3C%2FSTRONG%3E%20which%20indicates%20the%20read%20back%20failed%3A%3CBR%20%2F%3E%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-c%22%3E%3CCODE%3Estatic%20int%20write_fuses(uint32_t%20*fuse_addr%2C%20uint32_t%20*fuse_hdr_val%2C%20uint8_t%20len)%0A%7B%0A%09int%20i%3B%0A%0A%09%20%2F*%20Check%20if%20fuse%20already%20blown%20or%20not%20*%2F%0A%09for%20(i%20%3D%200%3B%20i%20%26lt%3B%20len%3B%20i%2B%2B)%20%7B%0A%09%09if%20(sfp_read32(%26amp%3Bfuse_addr%5Bi%5D)%20!%3D%200)%20%7B%0A%09%09%09return%20ERROR_ALREADY_BLOWN%3B%0A%09%09%7D%0A%09%7D%0A%0A%09%20%2F*%20Write%20fuse%20in%20mirror%20registers%20*%2F%0A%09for%20(i%20%3D%200%3B%20i%20%26lt%3B%20len%3B%20i%2B%2B)%20%7B%0A%09%09sfp_write32(%26amp%3Bfuse_addr%5Bi%5D%2C%20fuse_hdr_val%5Bi%5D)%3B%0A%09%7D%0A%0A%09%20%2F*%20Read%20back%20to%20check%20if%20write%20success%20*%2F%0A%09for%20(i%20%3D%200%3B%20i%20%26lt%3B%20len%3B%20i%2B%2B)%20%7B%0A%09%09if%20(sfp_read32(%26amp%3Bfuse_addr%5Bi%5D)%20!%3D%20fuse_hdr_val%5Bi%5D)%20%7B%0A%09%09%09return%20ERROR_WRITE%3B%0A%09%09%7D%0A%09%7D%0A%0A%09return%200%3B%0A%7D%3C%2FCODE%3E%3C%2FPRE%3E%3CBR%20%2F%3E%3CP%3EThis%20aligns%20with%20what%20I%20would%20expect%20to%20happen%2C%20based%20on%20the%20fact%20that%20OTPMK%20cannot%20be%20read%20back%20by%20design.%20This%20is%20explicitly%20mentioned%20in%20several%20documents%3A%3C%2FP%3E%3CP%20class%3D%22lia-indent-padding-left-30px%22%20style%3D%22padding-left%20%3A%2030px%3B%22%20style%3D%22padding-left%20%3A%2030px%3B%22%3E%3CSTRONG%3E%22For%20obvious%20reasons%2C%20the%20SFP%20does%20not%20allow%20the%20value%20written%20to%20the%20OTPMK%20registers%20to%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CSTRONG%3Ebe%20read%20out.%20Once%20a%20non-zero%20value%20is%20written%20to%20any%20of%20the%20OTPMK%20registers%2C%20any%20read%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CSTRONG%3Ewill%20return%20all%201s%22%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3EBased%20on%20this%2C%20I'm%20not%20sure%20how%20this%20code%20is%20intended%20to%20work%3F%20The%20write_fuses()%20function%20will%20always%20fail%20on%20OTPMK%20because%20the%20read%20back%20will%20always%20return%20all%201's.%20I%20also%20verified%20this%20by%20reading%20the%20OTPMK%20registers%20in%20u-boot%20and%20observing%20they%20only%20return%201's.%20Am%20I%20misunderstanding%20or%20doing%20something%20wrong%3F%20OTPMK%20is%20required%20to%20enable%20secure%20boot%2C%20so%20surely%20this%20must%20have%20worked%20at%20some%20point%2C%20but%20it%20seems%20to%20me%20in%20the%20current%20state%20this%20code%20cannot%20be%20used%20to%20enable%20secure%20boot%20on%20Qoriq%20Trust%20platforms%20(although%20the%20documentation%20mentions%20support%20for%20LS1046A).%26nbsp%3B%20We%20are%20using%20the%20nxp-qoriq%20atf%20v2.6%20source%20code%20by%20the%20way.%20I%20checked%20other%20source%20versions%20and%20it%20seems%20this%20code%20hasn't%20really%20changed.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1982286%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3ERe%3A%20%5BLS1046A%5D%20Fuse%20Provisioning%20Image%20Fails%20on%20OTPMK%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1982286%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EThank%20you%20for%20investigating%20this%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F52411%22%20target%3D%22_blank%22%3E%40yipingwang%3C%2FA%3E.%20Based%20on%20your%20suggestion%2C%20I%20got%20fuse%20fuse%20provisioning%20to%20work%20by%20taking%20the%20fuse%20provisioning%20and%20sfp%20code%20from%2021.08%20and%20integrating%20it%20into%20the%20v2.6%20branch%20(used%20by%20lf5.15.71).%20Since%20fuse%20provisioning%20is%20not%20properly%20supported%20in%20lf5.15.71%2C%20I%20think%20either%20the%20code%20should%20be%20patched%20or%20the%20documentation%20should%20be%20updated%20since%20it%20incorrectly%20states%20that%20fuse%20provisioning%20is%20supported.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1980937%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3ERe%3A%20%5BLS1046A%5D%20Fuse%20Provisioning%20Image%20Fails%20on%20OTPMK%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1980937%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EI%20checked%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fwww.nxp.com%2Fwebapp%2FDownload%3FcolCode%3DLLDPUG_RevL5.15.71-2.2.0%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3ELLDPUG%205.15%20%3C%2FA%3Eto%20build%20Fuse%20Provisioning%20ATF%20image.%3C%2FP%3E%0A%3CP%3EAdded%20DISTRO_FEATURES%3Aappend%20%3D%20%22%20fuse%22%20in%26nbsp%3Bbuild_ls1046ardb%2Fconf%2Flocal.conf%2C%20then%20rebuild%20atf%20image.%3C%2FP%3E%0A%3CP%3E%24%20bitbake%20qoriq-atf%20-c%20cleansstate%3C%2FP%3E%0A%3CP%3E%24%20bitbake%20qoriq-atf%3C%2FP%3E%0A%3CP%3EI%20encountered%20the%20error%20%22create%3A%20unrecognized%20option%20'--fuse-prov'%22%2C%20so%20there%20is%20defect%20in%20atf%20source%20code%20to%20build%26nbsp%3BFuse%20Provisioning%20image%20in%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fwww.nxp.com%2Fwebapp%2FDownload%3FcolCode%3DLLDPUG_RevL5.15.71-2.2.0%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3ELLDPUG%205.15%3C%2FA%3E.%3C%2FP%3E%0A%3CP%3EPlease%20use%20LSDK%2021.08%20release%20to%20build%26nbsp%3BFuse%20Provisioning%20ATF%20image.%3C%2FP%3E%0A%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1976833%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3ERe%3A%20%5BLS1046A%5D%20Fuse%20Provisioning%20Image%20Fails%20on%20OTPMK%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1976833%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EPlease%20provide%20the%20result%20of%20the%20following%20command%20on%20your%20custom%20board.%3C%2FP%3E%0A%3CP%3E%3CSPAN%3E%3D%26gt%3Bmd%201e90014%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1976810%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3ERe%3A%20%5BLS1046A%5D%20Fuse%20Provisioning%20Image%20Fails%20on%20OTPMK%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1976810%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EThank%20you%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F52411%22%20target%3D%22_blank%22%3E%40yipingwang%3C%2FA%3E%2C%20but%20we%20would%20specifically%20like%20to%20rely%20on%20the%20fuse%20provisioning%20image%20built%20by%20the%20qoriq%20atf%20repo%20so%20we%20can%20quickly%20and%20automatically%20program%20the%20fuses.%20All%20of%20the%20documents%20I%20shared%20above%20describe%20the%20fuse%20provisioning%20feature%20and%20explicitly%20state%20that%20it%20is%20supported%20by%20this%20SOC%2C%20but%20it%20seems%20the%20source%20code%20incorrectly%20handles%20reading%20the%20OTPMK%2C%20and%20cannot%20blow%20the%20fuses%20as%20a%20result.%20I'm%20confused%20as%20to%20how%20NXP%20was%20able%20to%20use%20this%20to%20enable%20secure%20boot%2C%20it%20seems%20the%20source%20code%20is%20incorrect%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1976706%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3ERe%3A%20%5BLS1046A%5D%20Fuse%20Provisioning%20Image%20Fails%20on%20OTPMK%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1976706%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EAfter%20blow%26nbsp%3BOTPMK%20fuse%2C%20register%200x1e80234-0x1e80250%20should%20be%20displayed%20as%20%22ffffffff%22%2C%20before%20fuse%20blowing%2C%20it%20should%20be%20all%20%220%22.%3C%2FP%3E%0A%3CP%3EAt%20the%20U-Boot%20prompt%2C%20verify%20that%20the%20SNVS%20registers%20for%20OTPMK%20are%20correctly%20written.%3CBR%20%2F%3ECheck%20if%20OPTMK%20is%20fused.%3CBR%20%2F%3E%3D%26gt%3B%20md%20%24SNVS_HPSR_REG%26nbsp%3B(byte%20swap)%3CBR%20%2F%3E80000900%3CBR%20%2F%3EOTPMK_ZERO_BIT%20(second%20nibble)%20is%200%2C%20indicating%20that%20OTPMK%20is%20fused.%3C%2FP%3E%0A%3CP%3E%3D%26gt%3Bmd%201e90014(byte%20swap)%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%208%3CSTRONG%3E0%3C%2FSTRONG%3E000900%3C%2FP%3E%0A%3CP%3ENow%20you%20will%20see%20%E2%80%980%E2%80%99%20in%20second%20nibble.%20No%20parity%20errors%2C%20i.e.%20bits%20marked%20in%20read%20would%20be%20all%200%E2%80%99s.%3C%2FP%3E%0A%3CP%3E%3D%26gt%3B%20md%201e80024%3C%2FP%3E%0A%3CP%3E00000000%3C%2FP%3E%3C%2FLINGO-BODY%3E