<?xml version="1.0" encoding="UTF-8"?>
<!--
===============================================================================

  Copyright (c) 2013-2017 Qualcomm Technologies, Inc.
  All Rights Reserved.
  Confidential and Proprietary - Qualcomm Technologies, Inc.

===============================================================================
-->

<tns:fuseblower xmlns:tns="http://www.qualcomm.com/fuseblower"
    xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    xsi:schemaLocation="http://www.qualcomm.com/fuseblower ../xsd/fuseblower_user.xsd">

    <metadata>
        <chipset>sm8250</chipset>
        <version>1.0</version>
    </metadata>

    <secdat>
        <file_info>default dat file</file_info>
        <file_version>2</file_version>
        <fuse_version>1</fuse_version>
    </secdat>

    <!-- IMPORTANT: do not remove below elf entry - it is needed to generate sec.elf file -->
    <elf>
        <elf_class>64</elf_class> <!--Elf: 32 or 64-->
        <phys_addr>0x808FF000</phys_addr> <!--sm8250 - sec.elf Physical Address-->
    </elf>
        <!--
        Default sm8250_fuseblower_USER.xml assumes that OEM_PK_HASH is blown in fuse for apps, mba and modem
        (SEC_BOOT1_PK_Hash_in_Fuse SEC_BOOT2_PK_Hash_in_Fuse, SEC_BOOT3_PK_Hash_in_Fuse are set to true). So,
        OEM public key hash below needs to be set below for root_cert_hash0. If OEM_PK_HASH is not blown in fuse
        for apps, mba and modem (that is, read from bootrom) set SEC_BOOT1_PK_Hash_in_Fuse, SEC_BOOT2_PK_Hash_in_Fuse,
        SEC_BOOT3_PK_Hash_in_Fuse to false and set ignore="true" below for root_cert_hash0.
         -->

    <module id="SECURITY_CONTROL_CORE">
        <entry ignore="false">
            <description>contains the OEM public key hash as set by OEM</description>
            <name>root_cert_hash0</name>
            <value>000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000</value>
        </entry>
        <entry ignore="true">
            <description>SHA384 hash of the root certificate used for signing</description>
            <name>root_cert_sha384_hash0_file</name>
            <value>./../../resources/data_prov_assets/Signing/Local/qti_presigned_certs-key2048_exp65537_paddingPSS/qpsa_rootca.cer</value>
        </entry>
        <entry ignore="false">
            <description>PK Hash is in Fuse for SEC_BOOT1 : Apps</description>
            <name>SEC_BOOT1_PK_Hash_in_Fuse</name>
            <value>true</value>
        </entry>
        <entry ignore="false">
            <description>If PK Hash in Fuse is 0, then this index selects which of 16 keys in ROM to use</description>
            <name>SEC_BOOT1_rom_pk_hash_index</name>
            <value>0</value>
        </entry>
        <entry ignore="false">
            <description>Use Serial Num for secure boot authentication (0: Use OEM ID (Default), 1: Use Serial Num)</description>
            <name>SEC_BOOT1_use_serial_num</name>
            <value>false</value>
        </entry>
        <entry ignore="false">
            <description>PK Hash is in Fuse for SEC_BOOT2 : MBA</description>
            <name>SEC_BOOT2_PK_Hash_in_Fuse</name>
            <value>true</value>
        </entry>
        <entry ignore="false">
            <description>PK Hash is in Fuse for SEC_BOOT3 : MPSS</description>
            <name>SEC_BOOT3_PK_Hash_in_Fuse</name>
            <value>true</value>
        </entry>
        <entry ignore="false">
            <description>The OEM hardware ID</description>
            <name>oem_hw_id</name>
            <value>0x0000</value>
        </entry>
        <entry ignore="false">
            <description>The OEM product ID</description>
            <name>oem_product_id</name>
            <value>0x0000</value>
        </entry>
        <entry ignore="false">
            <description>used to configure the number of root certificates hashed into OEM_PK_HASH (Max - 4)</description>
            <name>mrc_cert_count</name>
            <value>1</value>
        </entry>
        <entry ignore="false">
            <description>if true, disable APPS debug</description>
            <name>apps_debug_disabled</name>
            <value>true</value>
        </entry>
        <entry ignore="false">
            <description>allowing bus DCVS SW feature will require and set APPS_NIDEN_DISABLE to 0</description>
            <name>allow_bus_dcvs</name>
            <value>false</value>
        </entry>
        <entry ignore="false">
            <description>prevents the Watch Dog from being disabled by the GPIO, true: ignore GPIO, false: use GPIO</description>
            <name>watchdog_enable</name>
            <value>true</value>
        </entry>
        <!--Below Parameter is used to set SP_NVM_AR_CONFIG bit.
            NVM configuration for SP-ARI
            0: SPU ARI not configured yet (SPU ARI feature is DISABLED)
            1: Caps not connected to PM8150 Vcoin pin. SPU ARI feature is DISABLED.
            2: 5x10uF caps connected to PM8150 Vcoin pin. SPU ARI feature is ENABLED.
            3: Reserved -->
         <entry ignore="false">
            <description>Parameter to set SP_NVM_AR_CONFIG bit(0-3)</description>
            <name>sp_nvm_ar_config</name>
            <value>0</value>
        </entry>
        <entry ignore="false">
            <description>Parameter to disable SPU</description>
            <name>sp_disable</name>
            <value>false</value>
        </entry>
        <entry ignore="false">
            <description>Parameter to enable FIPS mode for SPU</description>
            <name>sp_fips_enable</name>
            <value>false</value>
        </entry>
        <entry ignore="false">
            <description>Parameter to Override TZ_SW_CRYPTO_FIPS_ENABLE fuse</description>
            <name>tz_sw_crypto_fips_enable</name>
            <value>false</value>
        </entry>
        <entry ignore="false">
            <description>Parameter to Override SPU_IAR_FEATURE_ENABLE fuse</description>
            <name>spu_iar_feature_enable</name>
            <value>false</value>
        </entry>
        <entry ignore="false">
            <description>if true, enables use of Extended Key</description>
            <name>eku_enforcement_en</name>
            <value>true</value>
        </entry>
        <entry ignore="false">
            <description>
                If true, all anti_rollback features are enabled.
                    . boot anti_rollback feature
                    . tzapps anti_rollback feature
                    . pilsubsys anti_rollback feature
                    . msa anti_rollback feature
                If false, all anti_rollback features are disabled.
            </description>
            <name>anti_rollback_feature_enable</name>
            <value>true</value>
        </entry>
    </module>
</tns:fuseblower>
