{"id":17800692,"url":"https://github.com/tofurky/tegra30_debrick","last_synced_at":"2025-10-13T07:33:38.640Z","repository":{"id":200455607,"uuid":"261931394","full_name":"tofurky/tegra30_debrick","owner":"tofurky","description":"fusee-gelee payload, supporting files, and guide for debricking Tegra 3 devices (2012 Nexus 7 and Ouya)","archived":false,"fork":false,"pushed_at":"2023-11-01T20:03:07.000Z","size":12182,"stargazers_count":44,"open_issues_count":8,"forks_count":16,"subscribers_count":9,"default_branch":"master","last_synced_at":"2025-04-02T06:02:04.997Z","etag":null,"topics":["debrick","fusee-gelee","nexus7","ouya","tegra"],"latest_commit_sha":null,"homepage":"","language":"C","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/tofurky.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2020-05-07T02:35:22.000Z","updated_at":"2024-12-02T03:08:08.000Z","dependencies_parsed_at":"2023-10-17T01:26:57.011Z","dependency_job_id":"4f59fba3-b238-4b8d-b53c-0fd75104b13c","html_url":"https://github.com/tofurky/tegra30_debrick","commit_stats":null,"previous_names":["tofurky/tegra30_debrick"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/tofurky/tegra30_debrick","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tofurky%2Ftegra30_debrick","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tofurky%2Ftegra30_debrick/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tofurky%2Ftegra30_debrick/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tofurky%2Ftegra30_debrick/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/tofurky","download_url":"https://codeload.github.com/tofurky/tegra30_debrick/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tofurky%2Ftegra30_debrick/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":279014107,"owners_count":26085463,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-10-13T02:00:06.723Z","response_time":61,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["debrick","fusee-gelee","nexus7","ouya","tegra"],"created_at":"2024-10-27T12:27:49.143Z","updated_at":"2025-10-13T07:33:38.622Z","avatar_url":"https://github.com/tofurky.png","language":"C","funding_links":[],"categories":[],"sub_categories":[],"readme":"# tegra30_debrick\n\n- [Disclaimer](#Disclaimer)  \n- [Thanks](#Thanks)  \n- [License](#License)  \n- [Background](#Background)  \n- [Files](#Files)  \n- [Other Methods](#Other-Methods)  \n- [Nexus 7 Debrick](#Nexus-7-2012-WiFi-Debrick)  \n- [Ouya Debrick](#Ouya-Debrick)  \n\n## Disclaimer\n\nIf you're here, there is a good chance that your Tegra 3 device is already bricked. But I am not \nresponsible for any additional issues that may arise from the (mis)use of the code/information \ncontained within this repository, nor can I provide support for it.\n\n## Thanks\n\n[@ktemkin](https://github.com/ktemkin) / [@Qyriad](https://github.com/Qyriad) for their work on \n[fusee-launcher](https://github.com/Qyriad/fusee-launcher), and [@jevinskie](https://github.com/jevinskie) \nfor their [Nexus 7 port](https://github.com/jevinskie/fusee-launcher) of the same. Also special \nthanks to [@ktemkin](https://github.com/ktemkin) and [@digetx](https://github.com/digetx) for their \nhelp/guidance/wisdom, as I almost certainly wouldn't have succeeded in debricking my Nexus 7 \nwithout it. [@pgwipeout](https://github.com/pgwipeout)'s kernel work on Ouya allowed me to keep \nusing mine (and retain interest in the device) over the years. Finally, Pyre on the OUYA Saviors \nDiscord kindly shipped me a (working) Kickstarter Ouya so that I could figure out how to debrick it.\n\n## License\n\n[GNU General Public License v2.0](https://www.gnu.org/licenses/old-licenses/gpl-2.0.en.html). \nfusee-launcher is also released under that, so it seemed fitting.\n\n## Background\n\nLast December I was gifted a bricked 2012 Nexus 7, but it did enumerate via APX mode, and I enjoy a \nchallenge :)\n\n## Files\n\nThe following files are contained within this repo:  \n\n- [README.md](/README.md): this README  \n- [LICENSE](/LICENSE): The GPLv2  \n- [fusee-launcher](https://github.com/jevinskie/fusee-launcher): jevinskie's fork, added as a submodule  \n- [nvflash\\_v1.13.87205](/utils/nvflash_v1.13.87205): unpatched nvflash utility (from [here](https://github.com/AndroidRoot/androidroot.github.io/blob/master/download/nvflash-tools-linux.tar.bz2))  \n- [nvflash\\_v1.13.87205\\_miniloader\\_patched](/utils/nvflash_v1.13.87205_miniloader_patched): as above, with patched miniloader to override security fuse checks  \n- [ipatch\\_rcm\\_sample.c](/payload/ipatch_rcm_sample.c): Tegra X1 Fusée Gelée payload to disable security fuse checks (by ktemkin)  \n- [uart\\_payload.c](/payload/uart_payload.c): as above, but tailored to Tegra 3 (Nexus 7 and Ouya)  \n- [Makefile](/payload/Makefile): Makefile to build both payloads from uart\\_payload.c  \n- [uart_payload.lds](/payload/uart_payload.lds): linker script to build payloads from uart\\_payload.c  \n**Nexus 7:**  \n- [bootloader-grouper-4.23.img](/bootloader/bootloader-grouper-4.23.img): unpatched 2012 Nexus 7 WiFi \"grouper\" bootloader  \n- [bootloader-grouper-4.23\\_uart.img](/bootloader/bootloader-grouper-4.23_uart.img): as above, with UART output patched in  \n- [uart\\_print.c](/bootloader/uart_print.c): source of UART print function patched into bootloader-grouper-4.23\\_uart.img  \n- [nexus\\_7\\_grouper\\_bct.bin](/bct/nexus_7_grouper_bct.bin): BCT dumped from \"grouper\" using nvflash  \n- [uart\\_payload\\_n7.bin](/payload/uart_payload_n7.bin): precompiled version of uart\\_payload.c  \n- [n7\\_uart.jpg](/image/n7_uart.jpg): annotated image of PCB showing UARTA pinout  \n- [n7\\_uart\\_schematic.jpg](/image/n7_uart_schematic.jpg): excerpt of ME370T schematic showing debug header pinout  \n- [n7\\_uart\\_context.jpg](/image/n7_uart_context.jpg): picture of opened tablet showing context of header location  \n- [flash.cfg](/utils/flash.cfg): partition config file for nvflash. Technically for the 16GB Nexus 7, but sufficient on Ouya for relevant steps in the Ouya Debrick section  \n**Ouya:**  \n- [ouya\\_rev\\_1.01\\_2013-06-20.bin](/bootloader/ouya_rev_1.01_2013-06-20.bin): decrypted fastboot bootloader, dumped with nvflash  \n- [ouya\\_rev\\_1.01\\_2013-06-20\\_sigcheck\\_disabled.bin](/bootloader/ouya_rev_1.01_2013-06-20_sigcheck_disabled.bin): as above, but with signature check disabled allowing flashing of unsigned bootloader to eMMC  \n- [ouya\\_rev\\_1.01\\_bct.bin](/bct/ouya_rev_1.01_bct.bin): BCT dumped via nvflash and decrypted  \n- [uart\\_payload\\_ouya.bin](/payload/uart_payload_ouya.bin): precompiled version of uart\\_payload.c  \n- [ouya\\_apx\\_glitch.jpg](/image/ouya_apx_glitch.jpg): annotated image of PCB showing how to force APX mode  \n- [ouya\\_apx\\_alternate\\_method.jpg](/image/ouya_apx_alternate_method.jpg): annotated image of PCB showing showing an alternate method to force APX mode  \n- [recovery-clockwork-6.0.4.8-ouya.img](/recovery/recovery-clockwork-6.0.4.8-ouya.img): ClockworkMod Recovery  \n\nMore detailed descriptions of the files can be found if you check their git history, for example [nvflash\\_v1.13.87205\\_miniloader\\_patched's](https://github.com/tofurky/tegra30_debrick/commits/master/utils/nvflash_v1.13.87205_miniloader_patched).\n\n## Other Methods\n\nIn the months it took me to finally put this repo together after working through this between February and March of 2020, an alternate method was posted to XDA Developers tailored to the Nexus 7.\n\nThe following are a couple guides based on this, the first link being the original:\n\n- [Unbrick Nexus 7 with another Tegra 3 Device](https://forum.xda-developers.com/nexus-7/general/unbrick-nexus-7-tegra-3-device-t4078627) by [Jirmd](https://github.com/GeorgeMato4)\n- [[TUTORIAL] How to unbrick Nexus 7 without blob.bin (REQUIRES ANOTHER NEXUS 7 2012)](https://forum.xda-developers.com/nexus-7/general/tutorial-how-to-unbrick-nexus-7-blob-bin-t4083879) by [enderzip](https://forum.xda-developers.com/member.php?u=10063311)\n\nIt also uses [@jevinskie](https://github.com/jevinskie)'s [fusee-launcher fork](https://github.com/jevinskie/fusee-launcher), but to grab the SBK using their [dump-sbk-via-usb.S](https://github.com/jevinskie/fusee-launcher/blob/n7/dump-sbk-via-usb.S) payload.\n\nThe cavaet is that at least at the moment it appears to require another working device to generate the blobs.\n\nThat method is not covered here, but is probably worth trying if the steps detailed here don't work for you.\n\n\u003c!-- sections below are best viewed rendered as HTML via e.g. /usr/bin/markdown - if you're reading this in a text editor, sorry ;-) --\u003e\n\n## Nexus 7 (2012 WiFi) Debrick\n\nBefore attempting any of this, be sure that your tablet isn't recoverable via other means. A dead/low battery can sometimes be worked around by plugging it in to a [charger and holding down the power button for 30s](https://web.archive.org/web/20200704193425/https://www.howtogeek.com/131109/the-ultimate-nexus-7-troubleshooting-guide-6-potential-problems-and-how-to-fix-them/). Leaving it hooked up to a charger for some time (30+ minutes) can also get them to respond again. Unlike the Ouya, a bad kernel flash is recoverable by forcing the tablet into fastboot recovery with a button combo. Holding the volume down + power button for several seconds can boot into fastboot recovery mode which will allow the kernel to be reflashed. The steps below are only meant as a last resort, like if your bootloader was wiped via a botched update or similar.\n\n### Prerequisites:\n\n- Linux machine with:\n\t- free USB3 port (required for fusee-launcher) (_Intel chipsets may work more reliably here_)\n\t- (if 64-bit kernel/userland) 32-bit libraries installed (_for .deb-based distros_ `dpkg --add-architecture i386; apt update \u0026\u0026 apt install libc6:i386 libstdc++6:i386`)\n\t- `pyusb` installed (_for .deb-based distros_ `apt install python3-usb`)\n\t- `fastboot` installed (_for .deb-based distros_ `apt install fastboot`)\n\t- `adb` installed (_for .deb-based distros_ `apt install adb`)\n\t- `cbootimage` installed (_for .deb-based distros_ `apt install cbootimage`)\n\t- recursive clone of this repository (`git clone --recursive https://github.com/tofurky/tegra30_debrick.git`)\n- Factory Android .zip for \"nakasi\". The latest is [nakasi-lmy47v-factory-5a0bb059.zip](https://dl.google.com/dl/android/aosp/nakasi-lmy47v-factory-5a0bb059.zip). Others can be found [here](https://developers.google.com/android/images#nakasi).\n- Some basic knowledge/familiarity with Linux command line\n- Some basic knowledge/familiarity with flashing Android (e.g. fastboot and adb)\n\n### Steps:\n\n1. Connect Nexus 7 to *USB3* port on Linux machine via Micro-USB jack.\n\t* If you have reason to believe the battery may be at less than 30% capacity, let it sit there for an hour or two before proceeding. This isn't just to play it safe - the bootloader will refuse to operate in _nvp3server_ mode if it's at \u003c= 29%.\n\n2. Check output of `dmesg` and `lsusb` commands. Take note if the tablet automatically enumerates in APX mode:\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003edmesg\u003c/code\u003e output showing enumeration in APX mode:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    [Sat Jul  4 12:12:44 2020] usb 2-3.4: new high-speed USB device number 86 using xhci_hcd\n\t\t    [Sat Jul  4 12:12:44 2020] usb 2-3.4: New USB device found, idVendor=0955, idProduct=7330, bcdDevice= 1.03\n\t\t    [Sat Jul  4 12:12:44 2020] usb 2-3.4: New USB device strings: Mfr=1, Product=2, SerialNumber=0\n\t\t    [Sat Jul  4 12:12:44 2020] usb 2-3.4: Product: APX\n\t\t    [Sat Jul  4 12:12:44 2020] usb 2-3.4: Manufacturer: NVIDIA Corp.\n\t\u003c/details\u003e\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003elsusb\u003c/code\u003e output showing device in APX mode:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    matt@aquos:~/devel/ouya/tegra30_debrick$ lsusb\n\t\t    ...\n\t\t    Bus 002 Device 086: ID 0955:7330 NVIDIA Corp. \n\t\t    ...\n\t\u003c/details\u003e\n\n3. If the tablet is not automatically entering APX mode, try the following to coerce it:\n\t* Open up a terminal window and execute `dmesg -Tw`. This is so you can see the USB enumeration happen in real time.\n\t* With the tablet plugged into the Linux machine, try holding volume up + power simultaneously for around 10-15 seconds.\n\t* If that doesn't work, it might help to unplug the internal battery connector. First, unplug the USB cable.\n\t* Follow the first few steps [here](https://www.ifixit.com/Guide/Nexus+7+Battery+Replacement/9895) to gently remove the rear cover and unplug the battery cable. If you're careful, this can be done without tools.\n\t* While pressing the volume up button, plug in the USB cable. It's a bit tricky with the cover removed - it should slightly \"click\" inwards. Using the edge of your fingernail can help. You may need to use more pressure than expected to create electrical contact. (Note: it can take several attempts to get the tablet to actually enumerate. If you continuously see USB errors in `dmesg`, maybe try sharper pressure on the volume up button.)\n\t* The tablet should then hopefully enumerate in APX mode. If it does, release the volume up button and **reconnect the battery connector** (leave the USB cable plugged in).\n\n4. From APX mode, execute fusee-launcher using [uart\\_payload\\_n7.bin](/payload/uart_payload_n7.bin). Within the `tegra30_debrick` directory, run:\n\n\t\t    sudo ./fusee-launcher/fusee-launcher.py ./payload/uart_payload_n7.bin -P 7330\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample terminal output:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    matt@aquos:~/devel/ouya/tegra30_debrick$ sudo ./fusee-launcher/fusee-launcher.py ./payload/uart_payload_n7.bin -P 7330\n\t\t    2020-07-04 12:16:54,982 INFO:usb.core:find(): using backend \"usb.backend.libusb1\"\n\t\t    ​\n\t\t    Important note: on desktop Linux systems, we currently require an XHCI host controller.\n\t\t    A good way to ensure you're likely using an XHCI backend is to plug your\n\t\t    device into a blue 'USB 3' port.\n\t\t    ​\n\t\t    Identified a Linux system; setting up the appropriate backend.\n\t\t    intermezzo_size: 0x00000078\n\t\t    target_payload_size: 0x000005ee\n\t\t    Found a Tegra with Device ID: b'05163c81bc245d01'\n\t\t    Stack snapshot: b'0000000000000000100000003c9f0040'\n\t\t    EndpointStatus_stack_addr: 0x40009f3c\n\t\t    ProcessSetupPacket SP: 0x40009f30\n\t\t    InnerMemcpy LR stack addr: 0x40009f20\n\t\t    overwrite_len: 0x00004f20\n\t\t    overwrite_payload_off: 0x00004de0\n\t\t    payload_first_length: 0x000005ee\n\t\t    overwrite_payload_off: 0x00004de0\n\t\t    payload_second_length: 0x00000000\n\t\t    b'00a0004000300040ee05000000000000'\n\t\t    Setting rcm msg size to 0x00030064\n\t\t    RCM payload (len_insecure): b'64000300'\n\t\t    ​\n\t\t    Setting ourselves up to smash the stack...\n\t\t    Payload offset of intermezzo: 0x00000074\n\t\t    overwrite_payload_off: 0x00004de0\n\t\t    overwrite_len: 0x00004f20\n\t\t    payload_overwrite_len: 0x00004e5c\n\t\t    overwrite_payload_off: 0x00004de0\n\t\t    smash_padding: 0x000047f2\n\t\t    overwrite_payload_off: 0x00004de0\n\t\t    Uploading payload...\n\t\t    txing 20480 bytes total\n\t\t    txing 4096 bytes (0 already sent) to buf[0] 0x40003000\n\t\t    txing 4096 bytes (4096 already sent) to buf[1] 0x40005000\n\t\t    txing 4096 bytes (8192 already sent) to buf[0] 0x40003000\n\t\t    txing 4096 bytes (12288 already sent) to buf[1] 0x40005000\n\t\t    txing 4096 bytes (16384 already sent) to buf[0] 0x40003000\n\t\t    Smashing the stack...\n\t\t    sending status request with length 0x00004f20\n\t\t    The USB device stopped responding-- sure smells like we've smashed its stack. :)\n\t\t    Launch complete!\n\t\u003c/details\u003e\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample output from USB serial adapter connected to the Nexus 7's UART after successfully running \u003ccode\u003euart_payload_n7.bin\u003c/code\u003e:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    ----------------------------------------------------------------------------\n\t\t    APBDEV_PMC_RST_STATUS_0: 00000000\n\t\t    BIT_BootType: 00000002\n\t\t    overriding getSecurityMode function to always return 3 (production non-secure)...\n\t\t    writing PMC_SCRATCH0 to trigger RCM mode after soft reset...\n\t\t    jumping to 0xfff01004...\n\t\u003c/details\u003e\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003edmesg\u003c/code\u003e output after successfully running \u003ccode\u003euart_payload_n7.bin\u003c/code\u003e. Note that the USB device will reset and reenumerate in APX mode:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    [Sat Jul  4 19:17:25 2020] usb 2-3.4: USB disconnect, device number 20\n\t\t    [Sat Jul  4 19:17:25 2020] usb 2-3.4: new high-speed USB device number 21 using xhci_hcd\n\t\t    [Sat Jul  4 19:17:26 2020] usb 2-3.4: New USB device found, idVendor=0955, idProduct=7330, bcdDevice= 1.03\n\t\t    [Sat Jul  4 19:17:26 2020] usb 2-3.4: New USB device strings: Mfr=1, Product=2, SerialNumber=0\n\t\t    [Sat Jul  4 19:17:26 2020] usb 2-3.4: Product: APX\n\t\t    [Sat Jul  4 19:17:26 2020] usb 2-3.4: Manufacturer: NVIDIA Corp.\n\t\u003c/details\u003e\n\n5. (Optional) Take a backup of the tablet's BCT **with the unpatched version of nvflash** for safekeeping and potential later use (i.e. use your backup instead of ./bct/nexus_7_grouper_bct.bin in subsequent steps) (Note: APX/nvflash will become unresponsive after this completes successfully - you'll need to cycle power and repeat steps 1 through 4):\n\n\t\t    sudo ./utils/nvflash_v1.13.87205 --getbct --bct BCT_READBACK_N7.BIN --configfile ./utils/flash.cfg\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003envflash\u003c/code\u003e output showing success:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    matt@aquos:~/devel/ouya/tegra30_debrick$ sudo ./utils/nvflash_v1.13.87205 --getbct --bct BCT_READBACK_N7.BIN --configfile ./utils/flash.cfg\n\t\t    Nvflash v1.13.87205 started\n\t\t    chip uid from BR is: 0x0000000000000000015d24bc813c1605\n\t\t    rcm version 0X30001\n\t\t    System Information:\n\t\t       chip name: unknown\n\t\t       chip id: 0x30 major: 1 minor: 3\n\t\t       chip sku: 0x83\n\t\t       chip uid: 0x0000000000000000015d24bc813c1605\n\t\t       macrovision: disabled\n\t\t       hdcp: enabled\n\t\t       jtag: disabled\n\t\t       sbk burned: true\n\t\t       dk burned: true\n\t\t       boot device: emmc\n\t\t       operating mode: 4\n\t\t       device config strap: 1\n\t\t       device config fuse: 17\n\t\t       sdram config strap: 0\n\t\t    ​\n\t\t    retrieving bct into: BCT_READBACK_N7.BIN\n\t\t    BCT_READBACK_N7.BIN received successfully\n\t\u003c/details\u003e\n\n\t* If you see an error like `bootloader status: Bct file not found (code: 21) message:  flags: 1073893660`, and you're _certain_ that you used the **unpatched** nvflash, it is possible that your BCT is damaged/missing. You will need to use the BCT from this repo (`./bct/nexus_7_grouper_bct.bin`) and add `--sync` to the _EBT_ nvflash command in step 7.\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003envflash\u003c/code\u003e output showing missing/corrupt BCT\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    matt@aquos:~/devel/ouya/tegra30_debrick$ sudo ./utils/nvflash_v1.13.87205 --getbct --bct BCT_READBACK_N7.BIN --configfile ./utils/flash.cfg \n\t\t    Nvflash v1.13.87205 started\n\t\t    chip uid from BR is: 0x0000000000000000015d24bc813c1605\n\t\t    rcm version 0X30001\n\t\t    System Information:\n\t\t       chip name: unknown\n\t\t       chip id: 0x30 major: 1 minor: 3\n\t\t       chip sku: 0x83\n\t\t       chip uid: 0x0000000000000000015d24bc813c1605\n\t\t       macrovision: disabled\n\t\t       hdcp: enabled\n\t\t       jtag: disabled\n\t\t       sbk burned: true\n\t\t       dk burned: true\n\t\t       boot device: emmc\n\t\t       operating mode: 4\n\t\t       device config strap: 1\n\t\t       device config fuse: 17\n\t\t       sdram config strap: 0\n\n\t\t    retrieving bct into: BCT_READBACK_N7.BIN\n\t\t    Failed sending command 2 NvError 1179650command failure: getbct failed (bad data)\n\t\t    bootloader status: Bct file not found (code: 21) message:  flags: 1073893660\n\t\u003c/details\u003e\n\n\t* Use `bct_dump` to confirm that the BCT looks OK:\n\n\t\t    bct_dump BCT_READBACK_N7.BIN\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003ebct_dump\u003c/code\u003e output:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    matt@aquos:~/devel/ouya/tegra30_debrick$ bct_dump BCT_READBACK_N7.BIN \n\t\t    Version       = 0x00030001;\n\t\t    BlockSize     = 0x00004000;\n\t\t    PageSize      = 0x00000200;\n\t\t    PartitionSize = 0x02000000;\n\t\t    OdmData       = 0x40000000;\n\t\t    # Bootloader used       = 1;\n\t\t    # Bootloaders max       = 4;\n\t\t    # BCT size              = 6128;\n\t\t    # Hash size             = 16;\n\t\t    # Crypto offset         = 16;\n\t\t    # Crypto length         = 6112;\n\t\t    # Max BCT search blocks = 64;\n\t\t    #\n\t\t    # These values are set by cbootimage using the\n\t\t    # bootloader provided by the Bootloader=...\n\t\t    # configuration option.\n\t\t    #\n\t\t    # Bootloader[0].Version      = 0x00000001;\n\t\t    # Bootloader[0].Start block  = 224;\n\t\t    # Bootloader[0].Start page   = 0;\n\t\t    # Bootloader[0].Length       = 2150992;\n\t\t    # Bootloader[0].Load address = 0x80108000;\n\t\t    # Bootloader[0].Entry point  = 0x80108000;\n\t\t    # Bootloader[0].Attributes   = 0x00000004;\n\t\t    # Bootloader[0].Bl AES Hash  = b28ebc06accf2bcd877e444bc28d00c0;\n\t\t    # Bootloader[0].RsaPssSigBl:\n\t\t    ​\n\t\t    SDRAM[0].MemoryType                         = NvBootMemoryType_Ddr3;\n\t\t    SDRAM[0].PllMChargePumpSetupControl         = 0x00000008;\n\t\t    SDRAM[0].PllMLoopFilterSetupControl         = 0x00000000;\n\t\t    SDRAM[0].PllMInputDivider                   = 0x0000000c;\n\t\t    ...\n\t\t    SDRAM[1].McEmemArbMisc1                     = 0x78000000;\n\t\t    SDRAM[1].McEmemArbRing1Throttle             = 0x001f0000;\n\t\t    SDRAM[1].McEmemArbOverride                  = 0x00000080;\n\t\t    SDRAM[1].McEmemArbRsv                       = 0xff00ff00;\n\t\t    SDRAM[1].McClkenOverride                    = 0x00000000;\n\t\u003c/details\u003e\n\n6. Boot from APX to fastboot's _nv3pserver_ mode like so:\n\n\t\t    sudo ./utils/nvflash_v1.13.87205_miniloader_patched --setbct --bct ./bct/nexus_7_grouper_bct.bin --configfile ./utils/flash.cfg --bl ./bootloader/bootloader-grouper-4.23.img --go\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003envflash\u003c/code\u003e output:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    matt@aquos:~/devel/ouya/tegra30_debrick$ sudo ./utils/nvflash_v1.13.87205_miniloader_patched --setbct --bct ./bct/nexus_7_grouper_bct.bin --configfile ./utils/flash.cfg --bl ./bootloader/bootloader-grouper-4.23.img --go\n\t\t    Nvflash v1.13.87205 started\n\t\t    chip uid from BR is: 0x0000000000000000015d24bc813c1605\n\t\t    rcm version 0X30001\n\t\t    System Information:\n\t\t       chip name: unknown\n\t\t       chip id: 0x30 major: 1 minor: 3\n\t\t       chip sku: 0x83\n\t\t       chip uid: 0x0000000000000000015d24bc813c1605\n\t\t       macrovision: disabled\n\t\t       hdcp: enabled\n\t\t       jtag: disabled\n\t\t       sbk burned: true\n\t\t       dk burned: true\n\t\t       boot device: emmc\n\t\t       operating mode: 3\n\t\t       device config strap: 1\n\t\t       device config fuse: 17\n\t\t       sdram config strap: 0\n\t\t    ​\n\t\t    sending file: ./bct/nexus_7_grouper_bct.bin\n\t\t    - 6128/6128 bytes sent\n\t\t    ./bct/nexus_7_grouper_bct.bin sent successfully\n\t\t    downloading bootloader -- load address: 0x80108000 entry point: 0x80108000\n\t\t    sending file: ./bootloader/bootloader-grouper-4.23.img\n\t\t    - 2150992/2150992 bytes sent\n\t\t    ./bootloader/bootloader-grouper-4.23.img sent successfully\n\t\t    waiting for bootloader to initialize\n\t\t    bootloader downloaded successfully\n\t\u003c/details\u003e\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample UART output (Note: this is from the patched _uart.img bootloader variant, not what is shown in the above command):\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    Starting Miniloader\n\t\t    Transferring control to Bootloader\n\t\t    hip Id: 0x30 (Handheld SOC) Major: 0x1 Minor: 0x3 SKU: 0x83\n\t\t    NVRM Initialized shmoo database\n\t\t    NVRM CLOCKS: PLLX0:      700000 Khz\n\t\t    NVRM CLOCKS: PLLM0:      667000 Khz\n\t\t    NVRM CLOCKS: PLLC0:      600000 Khz\n\t\t    NVRM CLOCKS: PLLP0:      408000 Khz\n\t\t    NVRM CLOCKS: PLLA0:      11289 Khz\n\t\t    NVRM CLOCKS: CPU:        700000 Khz\n\t\t    NVRM CLOCKS: AVP:        102000 Khz\n\t\t    NVRM CLOCKS: System Bus: 102000 Khz\n\t\t    NVRM CLOCKS: Memory Controller: 333500\n\t\t    NVRM CLOCKS: External Memory Controller: 667000\n\t\t    PMIC_detection  PINMUX_AUX_GMI_CS2_N_0 register=30\n\t\t    PMIC_detection  id_value =0 RegData=0\n\t\t    BoardInfo: 0x0f41:0x0a00:0x01:0x44:0x02\n\t\t    KaiPmuGetCapabilities(): The power rail 33 is not mapped properly\n\t\t    KaiPmuGetCapabilities(): The power rail 33 is not mapped properly\n\t\t    Max77663IsRailEnabled() Rail2 is using FPS1\n\t\t    Max77663IsRailEnabled() Rail9 is using FPS0\n\t\t    Max77663IsRailEnabled() Rail13 is using FPS1\n\t\t    Max77663IsRailEnabled() Rail13 is using FPS1\n\t\t    ADJUSTED CLOCKS:\n\t\t    MC clock is set to 333500 KHz\n\t\t    EMC clock is set to 667000 KHz (DDR clock is at 667000 KHz)\n\t\t    PLLX0 clock is set to 700000 KHz\n\t\t    PLLC0 clock is set to 600000 KHz\n\t\t    CPU clock is set to 700000 KHz\n\t\t    System and AVP clock is set to 102000 KHz\n\t\t    GraphicsHost clock is set to 163200 KHz\n\t\t    3D clock is set to 111166 KHz\n\t\t    2D clock is set to 111166 KHz\n\t\t    Epp clock is set to 111166 KHz\n\t\t    Mpe clock is set to 111166 KHz\n\t\t    Vde clock is set to 272000 KHz\n\t\t    Bootloader Start at:22222 ms\n\t\t    read_battery_register i2c_addr=aa reg=2c\n\t\t    NvOdmI2cStatus_Success\n\t\t    getbatterycapacity capacity=30 \n\t\t    Initializing Display\n\t\t    OdmPmuApGpioGetCapabilities(): The VddRail 37 is more than registered rails\n\t\t    OdmPmuApGpioGetVoltage(): The VddRail 37 is more than registered rails\n\t\t    OdmPmuApGpioGetVoltage(): The VddRail 37 is more than registered rails\n\t\t    OdmPmuApGpioSetVoltage(): The VddRail 37 is more than registered rails\n\t\t    OdmPmuApGpioSetVoltage(): The VddRail 37 is more than registered rails\n\t\t    OdmPmuApGpioSetVoltage(): The VddRail 37 is more than registered rails\n\t\t    OdmPmuApGpioSetVoltage(): The VddRail 37 is more than registered rails\n\t\t    Project value(0x0)\n\t\t    Project value(0x0)\n\t\t    Invalidate-only cache maint not supported in NvOs\n\t\t    in nvrm_clocks.c, NvRmPowerModuleClockConfig pclk, state-\u003eSourceClock=6, state-\u003eactual_freq=12000, state-\u003eDivider=1\n\t\t    Project value(0x0)\n\t\t    in nvrm_clocks.c, NvRmPowerModuleClockConfig pclk, state-\u003eSourceClock=0, state-\u003eactual_freq=408000, state-\u003eDivider=1\n\t\t    OdmPmuApGpioGetCapabilities(): The VddRail 37 is more than registered rails\n\t\t    OdmPmuApGpioSetVoltage(): The VddRail 37 is more than registered rails\n\t\t    OdmPmuApGpioSetVoltage(): The VddRail 37 is more than registered rails\n\t\t    Project value(0x0)\n\t\t    ASUS_charger_mode+\n\t\t    Project value(0x0)\n\t\t    asus: [smb347_hot_temp_setting] Hard Limit Hot Temperature set success !\n\t\t    Exit charger mode due to Nv3pServer is active. \n\t\t    Show google logo\n\t\t    show logo at 22873ms\n\t\t    ​\n\t\t    [bootloader] (built on Mar 21 2013, 17:12:55)\n\t\t    Platform Pre Boot configuration...\n\t\t    read_battery_register i2c_addr=aa reg=2c\n\t\t    NvOdmI2cStatus_Success\n\t\t    getbatterycapacity capacity=30 \n\t\t    Entering NvFlash recovery mode / Nv3p Server\n\t\t    ​\n\t\t    ​\n\t\t    Chip Uid: 015d24bc813c1605\n\t\u003c/details\u003e\n\n\t* If `nvflash` errors out with something along the lines of `bootloader failed NvError 0x0`, it is possible that the battery is not charged enough to continue. The tablet screen will clearly say \"battery is too low\". If that's the case, cycle power, let it charge, and revisit in an hour or two. The cutoff seems to be 29%.\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003envflash\u003c/code\u003e output if battery is too low (this error could happen for other reasons, too - but if your tablet has been sitting dead for a while, it's a likely culprit)\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    matt@aquos:~/devel/ouya/tegra30_debrick$ sudo ./utils/nvflash_v1.13.87205_miniloader_patched --setbct --bct ./bct/nexus_7_grouper_bct.bin --configfile ./utils/flash.cfg --bl ./bootloader/bootloader-grouper-4.23.img --go\n\t\t    Nvflash v1.13.87205 started\n\t\t    chip uid from BR is: 0x0000000000000000015d24bc813c1605\n\t\t    rcm version 0X30001\n\t\t    System Information:\n\t\t       chip name: unknown\n\t\t       chip id: 0x30 major: 1 minor: 3\n\t\t       chip sku: 0x83\n\t\t       chip uid: 0x0000000000000000015d24bc813c1605\n\t\t       macrovision: disabled\n\t\t       hdcp: enabled\n\t\t       jtag: disabled\n\t\t       sbk burned: true\n\t\t       dk burned: true\n\t\t       boot device: emmc\n\t\t       operating mode: 3\n\t\t       device config strap: 1\n\t\t       device config fuse: 17\n\t\t       sdram config strap: 0\n\t\t    ​\n\t\t    sending file: ./bct/nexus_7_grouper_bct.bin\n\t\t    - 6128/6128 bytes sent\n\t\t    ./bct/nexus_7_grouper_bct.bin sent successfully\n\t\t    downloading bootloader -- load address: 0x80108000 entry point: 0x80108000\n\t\t    sending file: ./bootloader/bootloader-grouper-4.23.img\n\t\t    - 2150992/2150992 bytes sent\n\t\t    ./bootloader/bootloader-grouper-4.23.img sent successfully\n\t\t    waiting for bootloader to initialize\n\t\t    usb read error (71): Protocol error\n\t\t    bootloader failed NvError 0x0\n\t\t    command failure: bootloader download failed \n\t\u003c/details\u003e\n\n\n7. Use the currently running _nv3pserver_ mode to reflash the bootloader to eMMC (Note: if step 5 failed due to corrupt/missing BCT, add `--sync` to this command. It will re-write the BCT.):\n\n\t\t    sudo ./utils/nvflash_v1.13.87205_miniloader_patched --resume --download EBT bootloader/bootloader-grouper-4.23.img --configfile ./utils/flash.cfg\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003envflash\u003c/code\u003e output:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    matt@aquos:~/devel/ouya/tegra30_debrick$ sudo ./utils/nvflash_v1.13.87205_miniloader_patched --resume --download EBT bootloader/bootloader-grouper-4.23.img --configfile ./utils/flash.cfg \n\t\t    Nvflash v1.13.87205 started\n\t\t    [resume mode]\n\t\t    sending file: bootloader/bootloader-grouper-4.23.img\n\t\t    - 2150992/2150992 bytes sent\n\t\t    bootloader/bootloader-grouper-4.23.img sent successfully\n\t\u003c/detail\u003e\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample UART output (from patched _uart.img)\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    BytesPerSector = 4096\n\t\t    ​\n\t\t    Start Downloading EBT\n\t\t    ​\n\t\t    End Downloading EBT\n\t\t    ​\n\t\t    !!!!!device update success!!!!!\n\t\t    ​\n\t\t    SocCpuMaxKHz = 1000000\n\t\t    SocCpuMinKHz = 32\n\t\t    PLLX0 FreqKHz = 700000\n\t\t    Project value(0x0)\n\t\t    Checking for android ota recovery \n\t\t    Key driver not found.. Booting OS\n\t\t    ​\n\t\t    Cold-booting Linux\n\t\t    ​\n\t\t    Platform Pre OS Boot configuration...\n\t\t    Project value(0x0)\n\t\t    Warning: console set to hsport (\t\t\t\tsecure world tracing won't work)\n\t\t    The proc BoardInfo: 0x0f41:0x0a00:0x01:0x44:0x02\n\t\t    Project value(0x0)\n\t\t    mping to kernel at:47975 ms\n\t\u003c/details\u003e\n\n\t* If you had a valid kernel and system image on the device, the tablet may boot into it immediately after flashing EBT. However, this does not mean that the bootloader/BCT were successfully flashed.\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003edmesg\u003c/code\u003e output if stock kernel automatically boots:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    [Sat Jul  4 23:23:00 2020] usb 2-3.4: USB disconnect, device number 66\n\t\t    [Sat Jul  4 23:23:14 2020] usb 2-3.4: new high-speed USB device number 67 using xhci_hcd\n\t\t    [Sat Jul  4 23:23:14 2020] usb 2-3.4: New USB device found, idVendor=18d1, idProduct=4e41, bcdDevice=99.99\n\t\t    [Sat Jul  4 23:23:14 2020] usb 2-3.4: New USB device strings: Mfr=2, Product=3, SerialNumber=4\n\t\t    [Sat Jul  4 23:23:14 2020] usb 2-3.4: Product: Android\n\t\t    [Sat Jul  4 23:23:14 2020] usb 2-3.4: Manufacturer: Android\n\t\t    [Sat Jul  4 23:23:14 2020] usb 2-3.4: SerialNumber: 015d24bc813c1605\n\t\u003c/details\u003e\n\n\t* At this point, it is necessary to perform a cold boot to verify the bootloader and BCT are properly flashed. This can be achieved by holding the power button for approximately 10 seconds. Eventually, you should see a Google logo and the tablet will continue booting into Android if kernel and system partitions are intact.\n\n8. Enter fastboot mode by holding the volume down and power keys for approximately 10s. While holding the buttons, the screen should go blank, briefly flash the Google logo, and then go to the screen with the Android mascot (it also says 'Start' at the top). Release the buttons:\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003edmesg\u003c/code\u003e output showing fastboot enumerating:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    [Sat Jul  4 23:27:51 2020] usb 2-3.4: USB disconnect, device number 69\n\t\t    [Sat Jul  4 23:27:51 2020] usb 2-3.4: new high-speed USB device number 70 using xhci_hcd\n\t\t    [Sat Jul  4 23:27:51 2020] usb 2-3.4: New USB device found, idVendor=18d1, idProduct=4e40, bcdDevice= 0.00\n\t\t    [Sat Jul  4 23:27:51 2020] usb 2-3.4: New USB device strings: Mfr=1, Product=2, SerialNumber=3\n\t\t    [Sat Jul  4 23:27:51 2020] usb 2-3.4: Product: Android\n\t\t    [Sat Jul  4 23:27:51 2020] usb 2-3.4: Manufacturer: Google, Inc\n\t\t    [Sat Jul  4 23:27:51 2020] usb 2-3.4: SerialNumber: 015d24bc813c1605\n\t\u003c/details\u003e\n\n\t* From here it is possible to completely restore the stock OS using a [factory .zip image](https://developers.google.com/android/images#nakasi). Run the following to confirm communication with the device:\n\n\t\t    sudo fastboot devices\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003efastboot\u003c/code\u003e output:\u003c/i\u003e\u003c/summary\u003e\n \n\t\t    matt@aquos:~/devel/ouya/tegra30_debrick$ sudo fastboot devices\n\t\t    015d24bc813c1605\tfastboot\n\t\u003c/details\u003e\n\n## Ouya Debrick\n\nBefore attempting any of this, be sure that your system isn't recoverable via other means. This could be as simple as hooking up a USB cable and running `adb`, or possibly plugging in a USB keyboard and attempting to enter [recovery mode](https://web.archive.org/web/20150502163510/https://forums.ouya.tv/discussion/comment/11742/#Comment_11742).\n\n### Prerequisites:\n\n- Linux machine with:\n\t- free USB3 port (required for fusee-launcher) (_Intel chipsets may work more reliably here_)\n\t- (if 64-bit kernel/userland) 32-bit libraries installed (_for .deb-based distros_ `dpkg --add-architecture i386; apt update \u0026\u0026 apt install libc6:i386 libstdc++6:i386`)\n\t- `pyusb` installed (_for .deb-based distros_ `apt install python3-usb`)\n\t- `fastboot` installed (_for .deb-based distros_ `apt install fastboot`)\n\t- `adb` installed (_for .deb-based distros_ `apt install adb`)\n\t- recursive clone of this repository (`git clone --recursive https://github.com/tofurky/tegra30_debrick.git`)\n- Ouya OTA update .zip (if you had a bad kernel flash, for example)\n\t- a large .7z with multiple versions can be found [here](https://archive.org/details/OuyaFirmware.7z)\n- (if Ouya isn't automatically booting to APX) low ohm resistor (I used 47 ohm) connected to ground with an e.g. wire and/or test clip\n\t- if you're brave, dextrous, and very careful you _might_ even get away with a paperclip grounded to the springy clip on the edge of the PCB\n- Some basic knowledge/familiarity with Linux command line\n- Some basic knowledge/familiarity with flashing Android (e.g. fastboot and adb)\n\n### Steps\n\n1. Connect Ouya to power, but leave powered off\n\n2. Connect Ouya to *USB3* port on Linux machine via Micro-USB jack\n\n3. Power on Ouya and check `dmesg` and/or `lsusb` output on Linux machine. Take note if the Ouya automatically enumerates in APX mode:\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003edmesg\u003c/code\u003e output showing enumeration in APX mode:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    [Thu Jul  2 16:28:11 2020] usb 2-3.3.2: new high-speed USB device number 8 using xhci_hcd\n\t\t    [Thu Jul  2 16:28:11 2020] usb 2-3.3.2: New USB device found, idVendor=0955, idProduct=7030, bcdDevice= 1.03\n\t\t    [Thu Jul  2 16:28:11 2020] usb 2-3.3.2: New USB device strings: Mfr=1, Product=2, SerialNumber=0\n\t\t    [Thu Jul  2 16:28:11 2020] usb 2-3.3.2: Product: APX\n\t\t    [Thu Jul  2 16:28:11 2020] usb 2-3.3.2: Manufacturer: NVIDIA Corp.\n\t\u003c/details\u003e\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003elsusb\u003c/code\u003e output showing device in APX mode:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    matt@aquos:~/devel/ouya/tegra30_debrick$ lsusb\n\t\t    ...\n\t\t\tBus 002 Device 055: ID 0955:7030 NVIDIA Corp. T30 [Tegra 3] recovery mode\n\t\t    ...\n\t\u003c/details\u003e\n\n4. If Ouya is *not* automatically booting to APX mode, do the following:\n\t* Disassemble Ouya by removing the 4 screws on the top and carefully sliding out PCB. [This iFixit teardown](https://www.ifixit.com/Teardown/Ouya+Teardown/14224) may be helpful.\n\t* Repeat steps 1 \u0026 2 to reconnect power and Micro-USB cable\n\t* Taking ESD precautions, connect [pin on PFET](/image/ouya_apx_glitch.jpg) to ground via low ohm resistor (~47 ohm - other values including 0 ohm probably work)\n\t\t- Power on Ouya with button\n\t\t- Leave PFET pin grounded for approximately 2s after pressing power button. This is about the time it takes for the fan to spin up.\n\t* If grounding PFET pin doesn't work. There is an alternate method. Otherwise skip to the next step.\n\t    - Short the [U33 pads](/image/ouya_apx_alternate_method.jpg)\n\t\t- Power on Ouya with button\n\t\t- Remove short from U33\n\t* Check Linux `dmesg` output on your PC to see if the Ouya enumerated in APX mode.\n\t\t- If it did, but reset afterwards, you've held the PFET to ground for too long.\n\t\t- If it didn't, try holding it a small amount longer.\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003edmesg\u003c/code\u003e output showing success:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    [Thu Jul  2 16:28:11 2020] usb 2-3.3.2: new high-speed USB device number 8 using xhci_hcd\n\t\t    [Thu Jul  2 16:28:11 2020] usb 2-3.3.2: New USB device found, idVendor=0955, idProduct=7030, bcdDevice= 1.03\n\t\t    [Thu Jul  2 16:28:11 2020] usb 2-3.3.2: New USB device strings: Mfr=1, Product=2, SerialNumber=0\n\t\t    [Thu Jul  2 16:28:11 2020] usb 2-3.3.2: Product: APX\n\t\t    [Thu Jul  2 16:28:11 2020] usb 2-3.3.2: Manufacturer: NVIDIA Corp.\n\t\u003c/details\u003e\n\n5. From APX mode, execute fusee-launcher using [uart\\_payload\\_ouya.bin](/payload/uart_payload_ouya.bin). Within the `tegra30_debrick` directory, run:\n\n\t\t    sudo ./fusee-launcher/fusee-launcher.py ./payload/uart_payload_ouya.bin -P 7030\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample terminal output:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    matt@aquos:~/devel/ouya/tegra30_debrick$ sudo ./fusee-launcher/fusee-launcher.py ./payload/uart_payload_ouya.bin -P 7030\n\t\t    2020-07-02 22:04:36,408 INFO:usb.core:find(): using backend \"usb.backend.libusb1\"\n\t\t    ​\n\t\t    Important note: on desktop Linux systems, we currently require an XHCI host controller.\n\t\t    A good way to ensure you're likely using an XHCI backend is to plug your\n\t\t    device into a blue 'USB 3' port.\n\t\t    ​\n\t\t    Identified a Linux system; setting up the appropriate backend.\n\t\t    intermezzo_size: 0x00000078\n\t\t    target_payload_size: 0x000005ee\n\t\t    Found a Tegra with Device ID: b'0210380c06495d01'\n\t\t    Stack snapshot: b'0000000000000000100000003c9f0040'\n\t\t    EndpointStatus_stack_addr: 0x40009f3c\n\t\t    ProcessSetupPacket SP: 0x40009f30\n\t\t    InnerMemcpy LR stack addr: 0x40009f20\n\t\t    overwrite_len: 0x00004f20\n\t\t    overwrite_payload_off: 0x00004de0\n\t\t    payload_first_length: 0x000005ee\n\t\t    overwrite_payload_off: 0x00004de0\n\t\t    payload_second_length: 0x00000000\n\t\t    b'00a0004000300040ee05000000000000'\n\t\t    Setting rcm msg size to 0x00030064\n\t\t    RCM payload (len_insecure): b'64000300'\n\t\t    ​\n\t\t    Setting ourselves up to smash the stack...\n\t\t    Payload offset of intermezzo: 0x00000074\n\t\t    overwrite_payload_off: 0x00004de0\n\t\t    overwrite_len: 0x00004f20\n\t\t    payload_overwrite_len: 0x00004e5c\n\t\t    overwrite_payload_off: 0x00004de0\n\t\t    smash_padding: 0x000047f2\n\t\t    overwrite_payload_off: 0x00004de0\n\t\t    Uploading payload...\n\t\t    txing 20480 bytes total\n\t\t    txing 4096 bytes (0 already sent) to buf[0] 0x40003000\n\t\t    txing 4096 bytes (4096 already sent) to buf[1] 0x40005000\n\t\t    txing 4096 bytes (8192 already sent) to buf[0] 0x40003000\n\t\t    txing 4096 bytes (12288 already sent) to buf[1] 0x40005000\n\t\t    txing 4096 bytes (16384 already sent) to buf[0] 0x40003000\n\t\t    Smashing the stack...\n\t\t    sending status request with length 0x00004f20\n\t\t    The USB device stopped responding-- sure smells like we've smashed its stack. :)\n\t\t    Launch complete!\n\t\u003c/details\u003e\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample output from USB serial adapter connected to Ouya's UART after successfully running \u003ccode\u003euart_payload_ouya.bin\u003c/code\u003e:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    ----------------------------------------------------------------------------\n\t\t    APBDEV_PMC_RST_STATUS_0: 00000000\n\t\t    BIT_BootType: 00000002\n\t\t    overriding getSecurityMode function to always return 3 (production non-secure)...\n\t\t    writing PMC_SCRATCH0 to trigger RCM mode after soft reset...\n\t\t    jumping to 0xfff01004...\n\t\u003c/details\u003e\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003edmesg\u003c/code\u003e output after successfully running \u003ccode\u003euart_payload_ouya.bin\u003c/code\u003e. Note that the USB device will reset and reenumerate in APX mode:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    [Thu Jul  2 16:35:48 2020] usb 2-3.3.2: USB disconnect, device number 8\n\t\t    [Thu Jul  2 16:35:49 2020] usb 2-3.3.2: new high-speed USB device number 9 using xhci_hcd\n\t\t    [Thu Jul  2 16:35:49 2020] usb 2-3.3.2: New USB device found, idVendor=0955, idProduct=7030, bcdDevice= 1.03\n\t\t    [Thu Jul  2 16:35:49 2020] usb 2-3.3.2: New USB device strings: Mfr=1, Product=2, SerialNumber=0\n\t\t    [Thu Jul  2 16:35:49 2020] usb 2-3.3.2: Product: APX\n\t\t    [Thu Jul  2 16:35:49 2020] usb 2-3.3.2: Manufacturer: NVIDIA Corp.\n\t\u003c/details\u003e\n\n6. Boot from APX to fastboot's _nv3pserver_ mode like so:\n\n\t\t    sudo ./utils/nvflash_v1.13.87205_miniloader_patched --setbct --bct ./bct/ouya_rev_1.01_bct.bin --configfile ./utils/flash.cfg --bl ./bootloader/ouya_rev_1.01_2013-06-20_sigcheck_disabled.bin --go\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample terminal output from \u003ccode\u003envflash\u003c/code\u003e command:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    matt@aquos:~/devel/ouya/tegra30_debrick$ sudo ./utils/nvflash_v1.13.87205_miniloader_patched --setbct --bct ./bct/ouya_rev_1.01_bct.bin --configfile ./utils/flash.cfg --bl ./bootloader/ouya_rev_1.01_2013-06-20_sigcheck_disabled.bin --go\n\t\t    Nvflash v1.13.87205 started\n\t\t    chip uid from BR is: 0x0000000000000000015d49060c381002\n\t\t    rcm version 0X30001\n\t\t    System Information:\n\t\t       chip name: unknown\n\t\t       chip id: 0x30 major: 1 minor: 3\n\t\t       chip sku: 0x80\n\t\t       chip uid: 0x0000000000000000015d49060c381002\n\t\t       macrovision: disabled\n\t\t       hdcp: enabled\n\t\t       jtag: disabled\n\t\t       sbk burned: true\n\t\t       dk burned: true\n\t\t       boot device: emmc\n\t\t       operating mode: 3\n\t\t       device config strap: 0\n\t\t       device config fuse: 0\n\t\t       sdram config strap: 0\n\t\t    ​\n\t\t    sending file: ./bct/ouya_rev_1.01_bct.bin\n\t\t    - 6128/6128 bytes sent\n\t\t    ./bct/ouya_rev_1.01_bct.bin sent successfully\n\t\t    downloading bootloader -- load address: 0x80108000 entry point: 0x80108000\n\t\t    sending file: ./bootloader/ouya_rev_1.01_2013-06-20_sigcheck_disabled.bin\n\t\t    / 1011728/1011728 bytes sent\n\t\t    ./bootloader/ouya_rev_1.01_2013-06-20_sigcheck_disabled.bin sent successfully\n\t\t    waiting for bootloader to initialize\n\t\t    bootloader downloaded successfully\n\t\u003c/details\u003e\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample Ouya UART output after \u003ccode\u003envflash\u003c/code\u003e command:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    Bootloader AVP Init\n\t\t    **********Aos DebugSemiHosting Initialized*******\n\t\t    ---------------------------------------------------\n\t\t    NVRM Initialized shmoo database\n\t\t    NVRM CLOCKS: PLLX0:      700000 Khz\n\t\t    NVRM CLOCKS: PLLM0:      800000 Khz\n\t\t    NVRM CLOCKS: PLLC0:      600000 Khz\n\t\t    NVRM CLOCKS: PLLP0:      408000 Khz\n\t\t    NVRM CLOCKS: PLLA0:      11289 Khz\n\t\t    NVRM CLOCKS: CPU:        700000 Khz\n\t\t    NVRM CLOCKS: AVP:        102000 Khz\n\t\t    NVRM CLOCKS: System Bus: 102000 Khz\n\t\t    NVRM CLOCKS: Memory Controller: 200000\n\t\t    NVRM CLOCKS: External Memory Controller: 400000\n\t\t    Fake BoardInfo: 0x0c5b:0x0b01:0x04:0x43:0x03\n\t\t    ADJUSTED CLOCKS:\n\t\t    MC clock is set to 200000 KHz\n\t\t    EMC clock is set to 400000 KHz (DDR clock is at 400000 KHz)\n\t\t    PLLX0 clock is set to 700000 KHz\n\t\t    PLLC0 clock is set to 600000 KHz\n\t\t    CPU clock is set to 700000 KHz\n\t\t    System and AVP clock is set to 102000 KHz\n\t\t    GraphicsHost clock is set to 163200 KHz\n\t\t    3D clock is set to 133333 KHz\n\t\t    2D clock is set to 133333 KHz\n\t\t    Epp clock is set to 133333 KHz\n\t\t    Mpe clock is set to 133333 KHz\n\t\t    Vde clock is set to 272000 KHz\n\t\t    Pinmux changes applied in kernel way\n\t\t    Bootloader Start at:44553 ms\n\t\t    ​\n\t\t    [bootloader] (built on Jun 20 2013, 22:10:09)\n\t\t    Initializing Display\n\t\t    Invalidate-only cache maint not supported in NvOs\n\t\t    Platform Pre Boot configuration...\n\t\t    Entering NvFlash recovery mode / Nv3p Server\n\t\u003c/details\u003e\n\n7. (Optional, but recommended) Take partition-by-partition dumps of eMMC by running:\n\n\t\t    for partition in BCT PT EBT EKS GP1 SOS LNX APP CAC UPP MSC USP MDA GPT UDA; do sudo ./utils/nvflash_v1.13.87205_miniloader_patched --resume --read $partition $partition.bin; done\n\n\t* Note that the last partition, UDA (userdata), has a decent chance of hanging. If it does, it may be necessary to power cycle the Ouya. To run it as a one-off:\n\n\t\t    sudo ./utils/nvflash_v1.13.87205_miniloader_patched --resume --read UDA UDA.bin\n\n8. If Ouya was not automatically booting to APX mode (e.g. bad kernel)\n\n\t* Reflash LNX with e.g. CWM Recovery:\n\n\t\t    sudo ./utils/nvflash_v1.13.87205_miniloader_patched --resume --download LNX ./recovery/recovery-clockwork-6.0.4.8-ouya.img --go\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003envflash\u003c/code\u003e output:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    matt@aquos:~/devel/ouya/tegra30_debrick$ sudo ./utils/nvflash_v1.13.87205_miniloader_patched --resume --download LNX ./recovery/recovery-clockwork-6.0.4.8-ouya.img --go\n\t\t    Nvflash v1.13.87205 started\n\t\t    [resume mode]\n\t\t    sending file: ./recovery/recovery-clockwork-6.0.4.8-ouya.img\n\t\t    - 8151040/8151040 bytes sent\n\t\t    ./recovery/recovery-clockwork-6.0.4.8-ouya.img sent successfully\n\t\u003c/details\u003e\n\n\t* Confirm Ouya boots into recovery (being attached to a TV via HDMI helps here):\n\n\t\t    sudo adb devices\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003eadb\u003c/code\u003e output:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    matt@aquos:~/devel/ouya/tegra30_debrick$ sudo adb devices\n\t\t    List of devices attached\n\t\t    015d49060c381002\trecovery\n\t\u003c/details\u003e\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003edmesg\u003c/code\u003e output:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    [Thu Jul  2 22:49:53 2020] usb 2-3.3.2: USB disconnect, device number 35\n\t\t    [Thu Jul  2 22:50:02 2020] usb 2-3.3.2: new high-speed USB device number 36 using xhci_hcd\n\t\t    [Thu Jul  2 22:50:02 2020] usb 2-3.3.2: New USB device found, idVendor=18d1, idProduct=d001, bcdDevice= 2.32\n\t\t    [Thu Jul  2 22:50:02 2020] usb 2-3.3.2: New USB device strings: Mfr=2, Product=3, SerialNumber=4\n\t\t    [Thu Jul  2 22:50:02 2020] usb 2-3.3.2: Product: Ouya\n\t\t    [Thu Jul  2 22:50:02 2020] usb 2-3.3.2: Manufacturer: Boxer8\n\t\t    [Thu Jul  2 22:50:02 2020] usb 2-3.3.2: SerialNumber: 015d49060c381002\n\t\u003c/details\u003e\n\n\t* From recovery, reflash stock .zip, or `adb reboot-bootloader` to get to fastboot to reflash stock\n\n9. If Ouya was automatically booting to APX mode (i.e. bad/erased bootloader/BCT):\n\n\t* Backup LNX partition if you haven't yet done so:\n\n\t\t    sudo ./utils/nvflash_v1.13.87205_miniloader_patched --resume --read LNX LNX.bin\n\n\t* Erase LNX partition via _nv3pserver_ mode by uploading all zeroes: \n\n\t\t    truncate -s 8M LNX_all_zeroes.bin\n\t\t    sudo ./utils/nvflash_v1.13.87205_miniloader_patched --resume --download LNX LNX_all_zeroes.bin --go\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003envflash\u003c/code\u003e output:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    matt@aquos:~/devel/ouya/tegra30_debrick$ truncate -s 8M LNX_all_zeroes.bin\n\t\t    matt@aquos:~/devel/ouya/tegra30_debrick$ sudo ./utils/nvflash_v1.13.87205_miniloader_patched --resume --download LNX LNX_all_zeroes.bin --go\n\t\t    Nvflash v1.13.87205 started\n\t\t    [resume mode]\n\t\t    sending file: LNX_all_zeroes.bin\n\t\t    / 8388608/8388608 bytes sent\n\t\t    LNX_all_zeroes.bin sent successfully\n\t\u003c/details\u003e\n\n\t* _nvp3server_ should then try to boot Linux, and subsequently fail back to standard _fastboot_ mode\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample UART output:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    Start Downloading LNX\n\t\t    ​\n\t\t    End Downloading LNX\n\t\t    SocCpuMaxKHz = 1000000\n\t\t    SocCpuMinKHz = 32\n\t\t    PLLX0 FreqKHz = 700000\n\t\t    Checking for android ota recovery \n\t\t    Key driver not found.. Booting OS\n\t\t    Cold-booting Linux\n\t\t     Booting failed\n\t\t    Starting Fastboot USB download protocol\n\t\t    Key driver not found.. Booting OS\n\t\u003c/details\u003e\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003edmesg\u003c/code\u003e output:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    [Thu Jul  2 20:36:55 2020] usb 2-3.3.2: USB disconnect, device number 20\n\t\t    [Thu Jul  2 20:36:55 2020] usb 2-3.3.2: new high-speed USB device number 21 using xhci_hcd\n\t\t    [Thu Jul  2 20:36:55 2020] usb 2-3.3.2: New USB device found, idVendor=0955, idProduct=7000, bcdDevice= 0.00\n\t\t    [Thu Jul  2 20:36:55 2020] usb 2-3.3.2: New USB device strings: Mfr=1, Product=2, SerialNumber=3\n\t\t    [Thu Jul  2 20:36:55 2020] usb 2-3.3.2: Product: Fastboot\n\t\t    [Thu Jul  2 20:36:55 2020] usb 2-3.3.2: Manufacturer: NVIDIA Corp.\n\t\t    [Thu Jul  2 20:36:55 2020] usb 2-3.3.2: SerialNumber: 015d49060c381002\n\t\u003c/details\u003e\n\n\t* Check to see if the device is available via fastboot (note: `sudo` isn't strictly necessary, but can workaround permissions issues):\n\n\t\t    sudo fastboot devices\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003efastboot\u003c/code\u003e output:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    matt@aquos:~/devel/ouya/tegra30_debrick$ sudo fastboot devices\n\t\t    015d49060c381002\tfastboot\n\t\u003c/details\u003e\n\n\t* Use the currently running _patched_ fastboot to reflash the _unpatched_ fastboot:\n\n\t\t    sudo fastboot flash bootloader ./bootloader/ouya_rev_1.01_2013-06-20.bin\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003efastboot\u003c/code\u003e output:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    matt@aquos:~/devel/ouya/tegra30_debrick$ fastboot flash bootloader ./bootloader/ouya_rev_1.01_2013-06-20.bin\n\t\t    target didn't report max-download-size\n\t\t    sending 'bootloader' (988 KB)...\n\t\t    OKAY [  0.212s]\n\t\t    writing 'bootloader'...\n\t\t    OKAY [  8.825s]\n\t\t    finished. total time: 9.037s\n\t\u003c/details\u003e\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample UART output:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    Cmd Rcvd: getvar:slot-count\n\t\t    Response sent: OKAY\n\t\t    Cmd Rcvd: getvar:slot-suffixes\n\t\t    Response sent: OKAY\n\t\t    Cmd Rcvd: getvar:has-slot:bootloader\n\t\t    Response sent: OKAY\n\t\t    Cmd Rcvd: getvar:partition-type:bootloader\n\t\t    Response sent: OKAYbasic\n\t\t    Cmd Rcvd: getvar:max-download-size\n\t\t    Response sent: OKAY\n\t\t    Cmd Rcvd: download:000f7010\n\t\t    Response sent: DATA000f7010\n\t\t    ​\n\t\t    Response sent: OKAY\n\t\t    Cmd Rcvd: flash:bootloader\n\t\t    ​\n\t\t    Format partition USP \n\t\t    Region=0 SD Erase start 512B-sector=2686976,512B-sector-num=65536 Response sent: OKAY\n\t\u003c/details\u003e\n\n\t* Reboot into newly flashed bootloader:\n\n\t\t    sudo fastboot reboot-bootloader\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003efastboot\u003c/code\u003e output:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    matt@aquos:~/devel/ouya/tegra30_debrick$ sudo fastboot reboot-bootloader \n\t\t    rebooting into bootloader...\n\t\t    OKAY [  0.004s]\n\t\t    finished. total time: 0.104s\n\t\u003c/details\u003e\n\n\t* Reflash the Ouya kernel with the backup that was made earlier with `nvflash`:\n\n\t\t    sudo fastboot flash boot LNX.bin\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003efastboot\u003c/code\u003e output:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    matt@aquos:~/devel/ouya/tegra30_debrick$ sudo fastboot flash boot LNX.bin\n\t\t    target didn't report max-download-size\n\t\t    sending 'boot' (8192 KB)...\n\t\t    OKAY [  2.552s]\n\t\t    writing 'boot'...\n\t\t    OKAY [  2.683s]\n\t\t    finished. total time: 5.235s\n\t\u003c/details\u003e\n\n\t* Boot into \"new\" kernel:\n\n\t\t    sudo fastboot continue\n\n\t\u003cdetails\u003e\u003csummary\u003e\u003ci\u003eExample \u003ccode\u003efastboot\u003c/code\u003e output:\u003c/i\u003e\u003c/summary\u003e\n\n\t\t    matt@aquos:~/devel/ouya/tegra30_debrick$ sudo fastboot continue\n\t\t    resuming boot...\n\t\t    OKAY [  0.004s]\n\t\t    finished. total time: 0.004s\n\t\u003c/details\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftofurky%2Ftegra30_debrick","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ftofurky%2Ftegra30_debrick","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftofurky%2Ftegra30_debrick/lists"}