What Is MaskROM Mode? Rockchip Recovery and Loader Mode Explained
MaskROM is the Rockchip BootROM's USB recovery mode, the reason Rockchip boards are nearly unbrickable. Learn how to enter it, how it differs from Loader mode, and how to flash from it.
Applies to: All Rockchip SoCs
Every Rockchip SoC contains a small, read-only program called the BootROM. On power-up it looks for a valid bootloader on the boot media. If it finds none, or if you force it, it exposes a USB device and waits for a host to send it code. That USB state is MaskROM mode.
Because the BootROM cannot be erased, you can almost always recover a Rockchip board, even with completely empty or corrupted flash.
MaskROM vs Loader mode
| MaskROM mode | Loader mode | |
|---|---|---|
| Who is running | BootROM inside the SoC | Rockchip loader / U-Boot (from flash) |
| DDR initialised? | No | Yes |
| How you enter | No valid loader, MaskROM button, or eMMC CLK shorted to GND at power-on | reboot loader, or holding the Recovery key while booting |
| First flashing step | Download a loader into RAM (rkdeveloptool db) | Write directly |
How to enter MaskROM mode
- Board has a MaskROM button: hold it, apply power (or press reset), release after about 2 seconds.
- No button: short the eMMC clock test point (or the SPI flash CLK/CS) to GND while powering on. The BootROM fails to read flash and falls back to USB. Remove the short straight after power-up.
- Blank board: a board with empty flash boots straight into MaskROM.
Connect the board's USB OTG port (often a USB-C port marked OTG or the upper USB 3 port on some SBCs) to your PC.
Confirming the mode
On Linux:
$ lsusb | grep 2207
Bus 001 Device 012: ID 2207:350b Fuzhou Rockchip Electronics Company
$ rkdeveloptool ld
DevNo=1 Vid=0x2207,Pid=0x350b,LocationID=104 Maskrom
The vendor ID is always 0x2207. The product ID identifies the SoC family. Common values are 0x350b for RK3588/RK3588S, 0x350a for RK3568/RK3566 and 0x330c for RK3399. On Windows, RKDevTool shows "Found One MASKROM Device".
Flashing from MaskROM
# 1. Load the SPL loader into RAM (it initialises DDR)
rkdeveloptool db rk3588_spl_loader_v1.xx.xxx.bin
# 2. Write a raw disk image from sector 0
rkdeveloptool wl 0 your-image.img
# 3. Reboot
rkdeveloptool rd
The loader file comes from rkbin or from your board vendor. It must match the SoC. For update.img firmware packages, use RKDevTool on Windows or upgrade_tool uf update.img on Linux.
Troubleshooting
- No USB device appears: wrong USB port (it must be the OTG port), a charge-only cable, or the board still boots from SD. Remove the SD card.
- Device appears then disconnects: weak power. Use a proper supply, not the PC USB port alone, for RK3588 boards.
- "Creating Comm Object failed": permissions. Add a udev rule (see our rkdeveloptool guide).
Designing your own board? Always bring out a MaskROM button (or test pad) and the debug UART. It costs almost nothing and saves days in bring-up and in the field.
¿Encontraste un error o quieres añadir algo? Sugerir una mejora.