# QFPROM fuses
Source: [https://docs.qualcomm.com/doc/80-70015-11/topic/appendix-fuse-configurations.html](https://docs.qualcomm.com/doc/80-70015-11/topic/appendix-fuse-configurations.html)
The QFPROM fuse values and details are captured in the following table, which can be
blown to enable secure boot.
| Fuse name | Start address | Bit number | Fuse blow value | Description |
| --- | --- | --- | --- | --- |
| **Read permissions** | **Read permissions** | **Read permissions** | **Read permissions** | **Read permissions** |
| Secondary Key derivation Key Read disable | 7801A8 | 24 | 1 | After provisioning the SKDK, blow this bit to secure the secondary
key from being read back. A secure path hardware exists from SKDK to the
crypto engine. |
| **Write permissions** | **Write permissions** | **Write permissions** | **Write permissions** | **Write permissions** |
| Read permissions write disable | 7801B0 | 6 | 1 | Blow this bit after the region has been provisioned to disable
further QFPROM changes to this region. |
| FEC enables write disable | 7801B0 | 8 | 1 | Blow this bit after the region has been provisioned to disable
further QFPROM changes to this region. |
| OEM configuration write disable | 7801B0 | 9 | 1 | Blow this bit after the region has been provisioned to disable
further QFPROM changes to this region. |
| Public key hash 0 write disable | 7801B0 | 17 | 1 | Blow this bit after the region has been provisioned to disable
further QFPROM changes to this region. |
| OEM secure boot write disable | 7801B0 | 23 | 1 | Blow this bit after the region has been provisioned to disable
further QFPROM changes to this region. |
| Secondary key derivation key write disable | 7801B0 | 24 | 1 | Blow this bit after the region has been provisioned to disable
further QFPROM changes to this region. |
| **FEC enable** | **FEC enable** | **FEC enable** | **FEC enable** | **FEC enable** |
| OEM secure boot FEC enable | 7801B8 | 23 | 1 | To enable FEC for OEM secure boot region, blow this bit. Ensure that
the complete region is provisioned before FEC is enabled. |
| Secondary key derivation key FEC enable | 7801B8 | 24 | 1 | To enable FEC for the secondary KDF key, blow this bit. Ensure that
the complete region is provisioned before FEC is enabled. |
| **OEM Config** | **OEM Config** | **OEM Config** | **OEM Config** | **OEM Config** |
| `WDOG_EN` | 7801C0 | 14 | 1 | Prevents the `WDOG_DISABLE` GPIO from disabling WDOG,
freeing up the GPIO and preventing potential abuse by an
attacker. |
| `SHARED_QSEE_SPIDEN_DISABLE` | 7801C0 | 30 | 1 | A shared Qualcomm TEE secure invasive debug disable bucket. A
corresponding Qualcomm fuse can override this OEM‑controlled
fuse. |
| `SHARED_QSEE_SPNIDEN_DISABLE` | 7801C0 | 31 | 1 | A shared Qualcomm TEE secure non-invasive debug disable bucket. A
corresponding Qualcomm fuse can override this OEM‑controlled
fuse. |
| `SHARED_MSS_DBGEN_DISABLE` | 7801C4 | 32 | 1 | A shared MSS invasive debug disable bucket. A corresponding Qualcomm
fuse can override this OEM‑controlled fuse. |
| `SHARED_MSS_NIDEN_DISABLE` | 7801C4 | 33 | 1 | A shared MSS non-invasive debug disable bucket. A corresponding
Qualcomm fuse can override this OEM-controlled fuse. |
| `SHARED_CP_DBGEN_DISABLE` | 7801C4 | 34 | 1 | A shared CP invasive debug disable bucket. A corresponding Qualcomm
fuse can override this OEM‑controlled fuse. |
| `SHARED_CP_NIDEN_DISABLE` | 7801C4 | 35 | 1 | A shared CP non-invasive debug disable bucket. A corresponding
Qualcomm fuse can override this OEM-controlled fuse. |
| `SHARED_NS_DBGEN_DISABLE` | 7801C4 | 36 | 1 | A shared CP non-invasive debug disable bucket. A corresponding
Qualcomm fuse can override this OEM‑controlled fuse. |
| `SHARED_NS_NIDEN_DISABLE` | 7801C4 | 37 | 1 | A shared CP non-invasive debug disable bucket. A corresponding
Qualcomm fuse can override this OEM‑controlled fuse. |
| `APPS_DBGEN_DISABLE` | 7801C4 | 38 | 1 | Blow this bit for a secure solution. This configuration disables the
application processor global invasive debug capabilities (JTAG and
monitor mode). The `OVERRIDE` registers can override this
configuration. |
| `APPS_NIDEN_DISABLE` | 7801C4 | 39 | 1 | Blow this bit for a secure solution. This configuration disables the
application processor global non-invasive debug capabilities (trace and
performance monitoring). This configuration can be overridden with the
`OVERRIDE` registers. |
| `SHARED_MISC_DEBUG_DISABLE` | 7801C4 | 40 | 1 | A shared miscellaneous debug disable bucket. A corresponding Qualcomm
fuse can override this OEM-controlled fuse. |
| `EKU_ENFORCEMENT_EN` | 7801C8 | 30 | 1 | To enable enforcement of the EKU field in the certificate, blow this
device. |
| `OEM_HW_ID[0:15]` | 7801CC | [32:47] | 0 | Represents the OEM hardware ID. Bits 15:0. |
| `OEM_PRODUCT_ID[0:15]` | 7801CC | [48:63] | 0 | Represents the OEM product ID. Bits 15:0. |
| `ANTI_ROLLBACK_FEATURE_EN[0]` | 7801D4 | 32 | 1 |
BOOT_ANTI_ROLLBACK_ENTZAPPS_ANTI_ROLLBACK_EN PILSUBSYS_ANTI_ROLLBACK_ENMSA_ANTI_ROLLBACK_ENBOOT_ANTI_ROLLBACK_ENTZAPPS_ANTI_ROLLBACK_EN PILSUBSYS_ANTI_ROLLBACK_ENMSA_ANTI_ROLLBACK_ENBOOT_ANTI_ROLLBACK_ENTZAPPS_ANTI_ROLLBACK_EN PILSUBSYS_ANTI_ROLLBACK_ENMSA_ANTI_ROLLBACK_ENBOOT_ANTI_ROLLBACK_ENTZAPPS_ANTI_ROLLBACK_EN PILSUBSYS_ANTI_ROLLBACK_ENMSA_ANTI_ROLLBACK_EN