sudo rpi-sb-provisioner.sh + TARGET_DEVICE_SERIAL= + DEBUG= + OPENSSL=openssl + export KEYWRITER_FINISHED=KEYWRITER-FINISHED + export KEYWRITER_ABORTED=KEYWRITER-ABORTED + export KEYWRITER_STARTED=KEYWRITER-STARTED + export PROVISIONER_FINISHED=PROVISIONER-FINISHED + export PROVISIONER_ABORTED=PROVISIONER-ABORTED + export PROVISIONER_STARTED=PROVISIONER-STARTED + : aes-xts-plain64 + echo KEYWRITER-STARTED + read_config + [ -f /etc/rpi-sb-provisioner/config ] + . /etc/rpi-sb-provisioner/config + CUSTOMER_KEY_FILE_PEM=/home/pi/SECURE-BOOT-Dependency/privatekey.pem + CUSTOMER_KEY_PKCS11_NAME= + GOLD_MASTER_OS_FILE=/home/pi/SECURE-BOOT-Dependency/2024-11-19-raspios-bookworm-arm64.img + RPI_DEVICE_STORAGE_TYPE=sd + RPI_DEVICE_STORAGE_CIPHER=aes-xts-plain64 + RPI_DEVICE_FAMILY=5 + RPI_DEVICE_BOOTLOADER_CONFIG_FILE=/var/lib/rpi-sb-provisioner/bootloader.config + RPI_DEVICE_LOCK_JTAG= + RPI_DEVICE_EEPROM_WP_SET= + RPI_DEVICE_FETCH_METADATA= + RPI_DEVICE_RETRIEVE_KEYPAIR= + DEMO_MODE_ONLY= + RPI_SB_WORKDIR= + RPI_SB_PROVISONER_MANUFACTURING_DB= + CUSTOMER_PUBLIC_KEY_FILE= + TMP_DIR= + trap cleanup EXIT + mktemp -d + FLASHING_DIR=/tmp/tmp.6hF15OkdcS + derivePublicKey + mktemp + CUSTOMER_PUBLIC_KEY_FILE=/tmp/tmp.9LWg4F4Dj0 + openssl rsa -in /home/pi/SECURE-BOOT-Dependency/privatekey.pem -pubout writing RSA key + identifyBootloaderConfig + [ ! -f /var/lib/rpi-sb-provisioner/bootloader.config ] + enforceSecureBootloaderConfig + grep -Fxq SIGNED_BOOT=1 /var/lib/rpi-sb-provisioner/bootloader.config + echo boot_ramdisk=1 + echo uart_2ndstage=1 + SOURCE_EEPROM_IMAGE= + DESTINATION_EEPROM_IMAGE= + DESTINATION_EEPROM_SIGNATURE= + BOOTCODE_BINARY_IMAGE= + BOOTCODE_FLASHING_NAME= + SOURCE_EEPROM_IMAGE=/lib/firmware/raspberrypi/bootloader-2712/latest/pieeprom-2025-01-14.bin + BOOTCODE_BINARY_IMAGE=/lib/firmware/raspberrypi/bootloader-2712/latest/recovery.bin + BOOTCODE_FLASHING_NAME=/tmp/tmp.6hF15OkdcS/bootcode5.bin + DESTINATION_EEPROM_IMAGE=/tmp/tmp.6hF15OkdcS/pieeprom.bin + DESTINATION_EEPROM_SIGNATURE=/tmp/tmp.6hF15OkdcS/pieeprom.sig + [ ! -e /tmp/tmp.6hF15OkdcS/pieeprom.sig ] + [ ! -e /lib/firmware/raspberrypi/bootloader-2712/latest/pieeprom-2025-01-14.bin ] + update_eeprom /lib/firmware/raspberrypi/bootloader-2712/latest/pieeprom-2025-01-14.bin /tmp/tmp.6hF15OkdcS/pieeprom.bin /home/pi/SECURE-BOOT-Dependency/privatekey.pem /tmp/tmp.9LWg4F4Dj0 + src_image=/lib/firmware/raspberrypi/bootloader-2712/latest/pieeprom-2025-01-14.bin + dst_image=/tmp/tmp.6hF15OkdcS/pieeprom.bin + pem_file=/home/pi/SECURE-BOOT-Dependency/privatekey.pem + public_pem_file=/tmp/tmp.9LWg4F4Dj0 + sign_args= + [ -n /home/pi/SECURE-BOOT-Dependency/privatekey.pem ] + grep -q SIGNED_BOOT=1 /var/lib/rpi-sb-provisioner/bootloader.config + mktemp + TMP_CONFIG_SIG=/tmp/tmp.eyEzJkzTO7 + keywriter_log Signing bootloader config + echo Signing bootloader config + writeSig /var/lib/rpi-sb-provisioner/bootloader.config /tmp/tmp.eyEzJkzTO7 + mktemp + SIG_TMP=/tmp/tmp.ZIepU0rHiy + IMAGE=/var/lib/rpi-sb-provisioner/bootloader.config + OUTPUT=/tmp/tmp.eyEzJkzTO7 + sha256sum /var/lib/rpi-sb-provisioner/bootloader.config + awk {print $1} + date -u +%s + echo ts: 1738596079 + get_signing_directives + [ -n ] + [ -n /home/pi/SECURE-BOOT-Dependency/privatekey.pem ] + [ -f /home/pi/SECURE-BOOT-Dependency/privatekey.pem ] + echo /home/pi/SECURE-BOOT-Dependency/privatekey.pem -keyform PEM + [ -n /home/pi/SECURE-BOOT-Dependency/privatekey.pem -keyform PEM ] + get_signing_directives + [ -n ] + [ -n /home/pi/SECURE-BOOT-Dependency/privatekey.pem ] + [ -f /home/pi/SECURE-BOOT-Dependency/privatekey.pem ] + echo /home/pi/SECURE-BOOT-Dependency/privatekey.pem -keyform PEM + openssl dgst -sign /home/pi/SECURE-BOOT-Dependency/privatekey.pem -keyform PEM -sha256 -out /tmp/tmp.ZIepU0rHiy /var/lib/rpi-sb-provisioner/bootloader.config + xxd -c 4096 -p + echo rsa2048: 6f46ef749cd06b0091cf6ea64dc8b59a9d4b0bd6889726844fa21e669fb04b332c172231d49a727207f1c765e3132f4dea42c29a074077da439338dde6aa6c91d381e48f674ded37396b214202db2fe3b7bec81188f002392bb60cb98da02e206ad5a505d9c9135268ee9b2567f70e725196d80b72f1c25dc5c016c8d05d06447b58c1da3179a67da5432c4b4e77d4970a5bf456f46b3c5eb8450ef57cc99b70dbaadc7e64abf61bd078fe2080a3985f8f08a9b67ba56fb42f361aa44b40ef1f359f828483a119638ebcd97a2f10100350c440b80f230e60afa40cb31bab173a55a7fcb8a56ff4257e9037f696644a1f06782c2720225083bde1f611685048c0 + rm /tmp/tmp.ZIepU0rHiy + cat /tmp/tmp.eyEzJkzTO7 366e9578dd27c3110100f1eb9d378937dfdc467385f8bc0853e08b7999edd893 ts: 1738596079 rsa2048: 6f46ef749cd06b0091cf6ea64dc8b59a9d4b0bd6889726844fa21e669fb04b332c172231d49a727207f1c765e3132f4dea42c29a074077da439338dde6aa6c91d381e48f674ded37396b214202db2fe3b7bec81188f002392bb60cb98da02e206ad5a505d9c9135268ee9b2567f70e725196d80b72f1c25dc5c016c8d05d06447b58c1da3179a67da5432c4b4e77d4970a5bf456f46b3c5eb8450ef57cc99b70dbaadc7e64abf61bd078fe2080a3985f8f08a9b67ba56fb42f361aa44b40ef1f359f828483a119638ebcd97a2f10100350c440b80f230e60afa40cb31bab173a55a7fcb8a56ff4257e9037f696644a1f06782c2720225083bde1f611685048c0 + sign_args=-d /tmp/tmp.eyEzJkzTO7 -p /tmp/tmp.9LWg4F4Dj0 + mktemp -d + customer_signed_bootcode_binary_workdir=/tmp/tmp.pvkDpGDFau + cd /tmp/tmp.pvkDpGDFau + rpi-eeprom-config -x /lib/firmware/raspberrypi/bootloader-2712/latest/pieeprom-2025-01-14.bin + rpi-sign-bootcode --debug -c 2712 -i bootcode.bin -o bootcode.bin.signed -k /home/pi/SECURE-BOOT-Dependency/privatekey.pem -v 0 -n 16 OFFSET TYPE: [ SIZE] DESCRIPTION 00000000 FILE: [ 73808] bootcode.bin 00012050 LEN: [ 4] 73808 00012054 KEYNUM: [ 4] 16 00012058 VERSION: [ 4] 0 0001215c RSA2048 - SHA256: [ 256] digest 2247c672cee150068188824e33fa77cdc4f3acc3d838cca3eafdcf38696d5991 signature 18ecd32211bd8d7037d64a78e6a12ab67da92c872fee17e9b1b8207e4fc1b1c89925e970e41984863a3279a793c25e8b91e2eb91afd9f2038dbc7e145cac2fd664b2b060065aafa3644a80062a81d000fb69af45ae938e7a8f77a7fe7d2a344aee893dad28b693d03e0327a6fe6c5fe9d68a409b90ebc7bb2cad5b0e19359ee2baef6b6b62a31b82b55874005677be70b485f35901e6f3332ac7da7a628e235131130c5a1578c44d60dc337dce831cc1bf505bc6a24635cc680aed21d979bc56d9f161eb4b85c1d00d112bc861a904b03fca368168d482c970f2b1824df9455379005ed7c7f20fce4f848c6441b4c44d71cd269b1247f2104e5bf1ab2c61f944 0001215c RSA: [ 264] /home/pi/SECURE-BOOT-Dependency/privatekey.pem Image size 74340 + rpi-eeprom-config --out /tmp/tmp.6hF15OkdcS/pieeprom.bin.intermediate --bootcode /tmp/tmp.pvkDpGDFau/bootcode.bin.signed /lib/firmware/raspberrypi/bootloader-2712/latest/pieeprom-2025-01-14.bin + cd - + rm -rf /tmp/tmp.pvkDpGDFau + rm -f /tmp/tmp.6hF15OkdcS/pieeprom.bin + set -x + rpi-eeprom-config --config /var/lib/rpi-sb-provisioner/bootloader.config --out /tmp/tmp.6hF15OkdcS/pieeprom.bin -d /tmp/tmp.eyEzJkzTO7 -p /tmp/tmp.9LWg4F4Dj0 /tmp/tmp.6hF15OkdcS/pieeprom.bin.intermediate + rm -f /tmp/tmp.6hF15OkdcS/pieeprom.bin.intermediate + rm -f /tmp/tmp.eyEzJkzTO7 + set +x new-image: /tmp/tmp.6hF15OkdcS/pieeprom.bin source-image: /lib/firmware/raspberrypi/bootloader-2712/latest/pieeprom-2025-01-14.bin config: /var/lib/rpi-sb-provisioner/bootloader.config RPIBOOT: build-date Jan 29 2025 version 20250129~123632 Please fit the EMMC_DISABLE / nRPIBOOT jumper before connecting the power and USB cables to the target device. If the device fails to connect then please see https://rpltd.co/rpiboot for debugging tips. Loading: /tmp/tmp.6hF15OkdcS/bootcode5.bin Waiting for BCM2835/6/7/2711/2712... losetup: NAME /dev/loop1 /dev/loop0: failed to use device: No such device