No, but currently I got ~working nand driver (photon_nand.c) ... will try with mtd_utils to write to nand again. Also I implemented one code to kernel (using spl base) and I can write to device memory but after restarting phone all go back to previous state, it mean writing is only temporaly becouse it is not real adress (it is "after boot temp addr")! But I dumped whole nand, when opened nand in hex I see where is real "on chip" offset to spl, cid...etc addresses, so I will try again "but with mtd utils from photon Debian linux" to write to real address of the spl (to change rsa modulus inside). If I change rsa modulus inside spl we will be able signing own image and uploading to phone using gold card method but will not be able uploading original htc image!