[Q] How to fastboot boot (not flash) into recovery on 4.3? - One (M7) Q&A, Help & Troubleshooting

As per this thread: http://forum.xda-developers.com/showpost.php?p=43940670&postcount=1061 it is no longer possible after 4.3 to simply do "fastboot boot recovery.img" -- if you don't give a -c parameter, fastboot just hangs.
Instead, we have to give kernel parameters to fastboot with the -c option.
The thread for Nexus suggests that the contents of /proc/cmdline would be sufficient. From my install of CWM ( http://forum.xda-developers.com/showthread.php?t=2390651 ) I have:
poweron_status=1 reset_status=0 board_m7_ul.disable_uart3=0 diag.enabled=0 board_m7_ul.debug_uart=0 userdata_sel=0 androidboot.emmc=true androidboot.pagesize=2048 skuid=0 ddt=20 ats=0 dap=6 androidboot.lb=1 uif=m000 td.sf=0 td.td=0 td.ofs=328 td.prd=1 td.dly=0 td.tmo=300 hlog.ofs=628 un.ofs=696 imc_online_log=0 androidboot.efuse_info=1NSL androidboot.baseband=4A.18.3263.15 androidboot.cid=GOOGL001 androidboot.devicerev=3 androidboot.batt_poweron=good_battery androidboot.carrier=GOOGLE androidboot.mid=PN0712000 androidboot.keycaps=qwerty androidboot.dq=PASS androidboot.mode=recovery androidboot.serialno=FA34WW906464 androidboot.bootloader=1.54.0000 lscd=0x1 wificd=0x2 androidboot.nledhw=0 androidboot.ddrmid=(0x6) acpu.footprint=0B010101 abnrst=0 zygote_oneshot=on kmemleak=off rpm_debug.enable=0 console=ttyHSL0,115200,n8 androidboot.hardware=qcom user_debug=31
HOWEVER, this line is too long and fastboot gives me an overflow error when I try to give that entire line.
Any ideas?

Did you ever find out how to do this?

Related

[Q] my legend stuck htc logo my log inside

C:\android\tools>fastboot oem boot
< waiting for device >
... INFOsetup_tag addr=0x60000100 cmdline add=0x9D
078D14
INFOTAG:Ramdisk OK
INFOTAG:smi ok, size = 0
INFOTAG:hwid 0x0
INFOTAG:skuid 0x22F00
INFOTAG:hero panel = 0x0
INFOTAG:engineerid = 0x0
INFOMCP dual-die
INFOMCP dual-die
INFOTAG:mono-die = 0x0
INFODevice CID is not super CID
INFOCID is HTC__032
INFOsetting->cid::HTC__032
INFOserial number: HT07VNX01365
INFOcommandline from head: no_console_suspend=1 console=null
INFOcommand line length =446
INFOactive commandline: board_legend.disable_uart3=0 board_legen
INFOd.usb_h2w_sw=0 board_legend.disable_sdcard=0 diag.enabled=0
INFOboard_legend.debug_uart=0 smisize=0 userdata_sel=0 androidbo
INFOot.emmc=false androidboot.baseband=7.05.35.26L androidboot.
INFOcid=HTC__032 androidboot.carrier=HTC-EastEurope androidboot.
INFOmid=PB7610000 androidboot.keycaps=qwerty androidboot.mode=no
INFOrmal androidboot.serialno=HT07VNX01365 androidboot.bootloade
INFOr=0.43.0001 no_console_suspend=1 console=null
INFOaARM_Partion[0].name=misc
INFOaARM_Partion[1].name=recovery
INFOaARM_Partion[2].name=boot
INFOaARM_Partion[3].name=system
INFOaARM_Partion[4].name=cache
INFOaARM_Partion[5].name=userdata
INFOpartition number=6
INFOValid partition num=6
INFOmpu_nand_acpu_rw 8F2 1000
FAILED (status read failed (Too many links))
finished. total time: 0.875s
what can i do ??????
Hi man ! Would be nice if you edit your post in order to explain seriously your problem.
Could be useful to know what ROM you are using, what you did before your phone went in trouble...
Is it a bootloop ? Did you try to flash something ? are you rooted ?
Without the minimum to know, people won't be able to help you. I don't know how to read a logcat, but I don't think every answers are in it !
Plus some courtesy is required on this forum, like on every forum... you just throw us a log...

[Q] Help - HTC One is not charging

Hello,
I've searched the forums but I could not find a solution for the issue I have with my HTC One.
Since I left it fully discharge some weeks ago, the phone won't charge anymore unless Fastboot is disabled and the phone is off.
So far, I've tried the following:
- Factory Reset
- Re-flash the ROM (from an older ARHD to ARHD 31.6)
- Start phone in Safe Mode
- Hold down Power + Vol Up + Vol Down for 2 minutes
- Clean the USB port using compressed air to remove the dust
I don't know what else to try, I can't even tell if it's a hardware or a software issue.
Also, my phone is *not* being recognized when I plug it on my PC (Windows 7), so I can't use adb or fastboot.
My HTC One is the ATT variant, S-OFF, running ARHD 31.6 (4.3), below is the beginning of the Bug Report generated by the phone using the Developer option:
------------------------------
isShippingRom: 1
Build: JSS15J
Build fingerprint: 'htc/cingular_us/m7:4.3/JSS15J/264544.1:user/release-keys'
Bootloader: 1.44.0000
Radio: 4A.14.3250.13
Network: (unknown)
Kernel: Linux version 3.4.10-gfa33c1e ([email protected]) (gcc version 4.7 (GCC) ) #1 SMP PREEMPT Thu Oct 17 23:30:00 CST 2013
Command line: poweron_status=1 reset_status=0 board_m7_ul.disable_uart3=0 diag.enabled=0 board_m7_ul.debug_uart=0 userdata_sel=0 androidboot.emmc=true androidboot.pagesize=2048 skuid=0 ddt=20 ats=0 dap=6 androidboot.lb=1 uif=S000 td.sf=0 td.td=0 td.ofs=328 td.prd=1 td.dly=0 td.tmo=300 hlog.ofs=628 un.ofs=694 imc_online_log=0 androidboot.efuse_info=3NSL androidboot.baseband=4A.14.3250.13 androidboot.cid=CWS__001 androidboot.devicerev=3 androidboot.batt_poweron=good_battery androidboot.carrier=ATT androidboot.mid=PN0712000 androidboot.keycaps=qwerty androidboot.dq=PASS androidboot.mode=normal androidboot.serialno=HT352W900528 androidboot.bootloader=1.44.0000 lscd=0x1 wificd=0x1 androidboot.nledhw=0 androidboot.ddrmid=(0x3) acpu.footprint=FF050505 zygote_oneshot=on kmemleak=off rpm_debug.enable=0 console=ttyHSL0,115200,n8 androidboot.hardware=m7 user_debug=31
------------------------------
What else can I try?
The phone is not on warranty anymore.
Thank you!
--
Fabio
fabiolv said:
Hello,
I've searched the forums but I could not find a solution for the issue I have with my HTC One.
Since I left it fully discharge some weeks ago, the phone won't charge anymore unless Fastboot is disabled and the phone is off.
So far, I've tried the following:
- Factory Reset
- Re-flash the ROM (from an older ARHD to ARHD 31.6)
- Start phone in Safe Mode
- Hold down Power + Vol Up + Vol Down for 2 minutes
- Clean the USB port using compressed air to remove the dust
I don't know what else to try, I can't even tell if it's a hardware or a software issue.
Also, my phone is *not* being recognized when I plug it on my PC (Windows 7), so I can't use adb or fastboot.
My HTC One is the ATT variant, S-OFF, running ARHD 31.6 (4.3), below is the beginning of the Bug Report generated by the phone using the Developer option:
------------------------------
isShippingRom: 1
Build: JSS15J
Build fingerprint: 'htc/cingular_us/m7:4.3/JSS15J/264544.1:user/release-keys'
Bootloader: 1.44.0000
Radio: 4A.14.3250.13
Network: (unknown)
Kernel: Linux version 3.4.10-gfa33c1e ([email protected]) (gcc version 4.7 (GCC) ) #1 SMP PREEMPT Thu Oct 17 23:30:00 CST 2013
Command line: poweron_status=1 reset_status=0 board_m7_ul.disable_uart3=0 diag.enabled=0 board_m7_ul.debug_uart=0 userdata_sel=0 androidboot.emmc=true androidboot.pagesize=2048 skuid=0 ddt=20 ats=0 dap=6 androidboot.lb=1 uif=S000 td.sf=0 td.td=0 td.ofs=328 td.prd=1 td.dly=0 td.tmo=300 hlog.ofs=628 un.ofs=694 imc_online_log=0 androidboot.efuse_info=3NSL androidboot.baseband=4A.14.3250.13 androidboot.cid=CWS__001 androidboot.devicerev=3 androidboot.batt_poweron=good_battery androidboot.carrier=ATT androidboot.mid=PN0712000 androidboot.keycaps=qwerty androidboot.dq=PASS androidboot.mode=normal androidboot.serialno=HT352W900528 androidboot.bootloader=1.44.0000 lscd=0x1 wificd=0x1 androidboot.nledhw=0 androidboot.ddrmid=(0x3) acpu.footprint=FF050505 zygote_oneshot=on kmemleak=off rpm_debug.enable=0 console=ttyHSL0,115200,n8 androidboot.hardware=m7 user_debug=31
------------------------------
What else can I try?
The phone is not on warranty anymore.
Thank you!
--
Fabio
Click to expand...
Click to collapse
DEAR , with my experience, try these steps first:
1- change your USB-Mini USB cable and charger
2- put your phone in charger about 15m and dont remove
if still not charging, try these too :
try to bend the cable from the phone Jack , bend it up carefully (hold bending ) about 1m
then bend it down carefully (hold bend) about 1m,
if your battery charging appear , the problem is with the USB inside phone Jack
hope these help you
moha_moha20106 said:
DEAR , with my experience, try these steps first:
1- change your USB-Mini USB cable and charger
2- put your phone in charger about 15m and dont remove
if still not charging, try these too :
try to bend the cable from the phone Jack , bend it up carefully (hold bending ) about 1m
then bend it down carefully (hold bend) about 1m,
if your battery charging appear , the problem is with the USB inside phone Jack
hope these help you
Click to expand...
Click to collapse
Thanks, but it didnt work
I don't know what else to do with this phone
fabiolv said:
Thanks, but it didnt work
I don't know what else to do with this phone
Click to expand...
Click to collapse
i think you need to go to HTC service center
fabiolv said:
My HTC One is the ATT variant, S-OFF, running ARHD 31.6 (4.3)[snip]
What else can I try?
The phone is not on warranty anymore.
Click to expand...
Click to collapse
You didn't say which recovery you are using.
(There was a charging issue with some early builds of TWRP 2.7.0.0 )
Sent from my HTC One using xda app-developers app
NxNW said:
You didn't say which recovery you are using.
(There was a charging issue with some early builds of TWRP 2.7.0.0 )
Sent from my HTC One using xda app-developers app
Click to expand...
Click to collapse
Hi,
I'm using TWRP 2.6.0.1.
I dont know if I can install any other version now that the phone is not being recognized when I plug it to the computer, its like the USB doesnt work at all whilet the phone is on,
Tks
fabiolv said:
Hello,
I've searched the forums but I could not find a solution for the issue I have with my HTC One.
Since I left it fully discharge some weeks ago, the phone won't charge anymore unless Fastboot is disabled and the phone is off.
So far, I've tried the following:
- Factory Reset
- Re-flash the ROM (from an older ARHD to ARHD 31.6)
- Start phone in Safe Mode
- Hold down Power + Vol Up + Vol Down for 2 minutes
- Clean the USB port using compressed air to remove the dust
I don't know what else to try, I can't even tell if it's a hardware or a software issue.
Also, my phone is *not* being recognized when I plug it on my PC (Windows 7), so I can't use adb or fastboot.
My HTC One is the ATT variant, S-OFF, running ARHD 31.6 (4.3), below is the beginning of the Bug Report generated by the phone using the Developer option:
------------------------------
isShippingRom: 1
Build: JSS15J
Build fingerprint: 'htc/cingular_us/m7:4.3/JSS15J/264544.1:user/release-keys'
Bootloader: 1.44.0000
Radio: 4A.14.3250.13
Network: (unknown)
Kernel: Linux version 3.4.10-gfa33c1e ([email protected]) (gcc version 4.7 (GCC) ) #1 SMP PREEMPT Thu Oct 17 23:30:00 CST 2013
Command line: poweron_status=1 reset_status=0 board_m7_ul.disable_uart3=0 diag.enabled=0 board_m7_ul.debug_uart=0 userdata_sel=0 androidboot.emmc=true androidboot.pagesize=2048 skuid=0 ddt=20 ats=0 dap=6 androidboot.lb=1 uif=S000 td.sf=0 td.td=0 td.ofs=328 td.prd=1 td.dly=0 td.tmo=300 hlog.ofs=628 un.ofs=694 imc_online_log=0 androidboot.efuse_info=3NSL androidboot.baseband=4A.14.3250.13 androidboot.cid=CWS__001 androidboot.devicerev=3 androidboot.batt_poweron=good_battery androidboot.carrier=ATT androidboot.mid=PN0712000 androidboot.keycaps=qwerty androidboot.dq=PASS androidboot.mode=normal androidboot.serialno=HT352W900528 androidboot.bootloader=1.44.0000 lscd=0x1 wificd=0x1 androidboot.nledhw=0 androidboot.ddrmid=(0x3) acpu.footprint=FF050505 zygote_oneshot=on kmemleak=off rpm_debug.enable=0 console=ttyHSL0,115200,n8 androidboot.hardware=m7 user_debug=31
------------------------------
What else can I try?
The phone is not on warranty anymore.
Thank you!
--
Fabio
Click to expand...
Click to collapse
I'm having the same issue with my HTC one. Did the problem get fixed if yes then how?
fabiolv said:
Hi,
I'm using TWRP 2.6.0.1.
I dont know if I can install any other version now that the phone is not being recognized when I plug it to the computer, its like the USB doesnt work at all whilet the phone is on,
Tks
Click to expand...
Click to collapse
Because you are on HBOOT 1.44 YOU must use Windows 7 or lower, if you are using Windows 8 or higher that is why it's not working, there is a potential fix around here somewhere but I'm at work at the moment so I don't have the links available to me.

Attempting to Build Beanstalk from SkiWong's CM12 device tree

Hi all,
Moderators: If you feel this doesn't belong here, I apologize now, but based on the sticky, it feels like this is the right forum.
I have been working on a Beanstalk LP port for the Nexus 6. I am trying to figure out if anyone has seen this build error before, as Google and forum searches have found nothing relevant. I have worked through a number of issues, but am now stuck. SkiWong has been very very helpful. I have been able to build a complete image build, but when I run make bacon after selecting the device in the lunch menu, I am now getting this message at the end as it is building the ZIP file.
raceback (most recent call last):
File "./build/tools/releasetools/ota_from_target_files", line 1652, in <module>
main(sys.argv[1:])
File "./build/tools/releasetools/ota_from_target_files", line 1609, in main
WriteFullOTAPackage(input_zip, output_zip)
File "./build/tools/releasetools/ota_from_target_files", line 589, in WriteFullOTAPackage
""+input_zip.read("SYSTEM/bin/otasigcheck.sh"))
File "/usr/lib/python2.7/zipfile.py", line 935, in read
return self.open(name, "r", pwd).read()
File "/usr/lib/python2.7/zipfile.py", line 961, in open
zinfo = self.getinfo(name)
File "/usr/lib/python2.7/zipfile.py", line 909, in getinfo
'There is no item named %r in the archive' % name)
KeyError: "There is no item named 'SYSTEM/bin/otasigcheck.sh' in the archive"
build/core/Makefile:1642: recipe for target '/home/pwn3r/beanstalklp/out/target/product/shamu/aosp_shamu-ota-eng.root.zip' failed
make: *** [/home/pwn3r/beanstalklp/out/target/product/shamu/aosp_shamu-ota-eng.root.zip] Error 1
#### make failed to build some targets (02:17:52 (hh:mm:ss)) ####
I can't tell if something didn't sync some required files or if something isn't there. Based on what I see it looks like the file SYSTEM/bin/otasigcheck.sh is missing. That said, I don't know why or where to get one.
well, this has nothing to do with being a developer. like this section says, developers only. your best bet would be to post this question in q&a.
So, I've got a build that works with some help. However,the build that I have that works Data no longer comes up on. This happened after something that was changed on the 26th of December in either the Beanstalk or CM repo. Here's a logcat, basically, the modem comes up and connects to Verizon, but no data. Anyone have any idea how to fix this?
Code:
D/PackageBroadcastService( 2740): Received broadcast action=android.intent.action.PACKAGE_CHANGED and uri=com.google.android.apps.plus
I/PeopleContactsSync( 2740): CP2 sync disabled
I/UpdateIcingCorporaServi( 2512): Updating corpora: APPS=com.google.android.apps.plus, CONTACTS=MAYBE
W/Launcher( 5682): setApplicationContext called twice! [email protected] [email protected]
I/UpdateIcingCorporaServi( 2512): UpdateCorporaTask done [took 31 ms] updated apps [took 31 ms]
D/BackupManagerService( 939): Received broadcast Intent { act=android.intent.action.PACKAGE_CHANGED dat=package:com.google.android.apps.plus flg=0x4000010 (has extras) }
W/Launcher.Model( 5641): Nobody to tell about the new app. Launcher is probably loading.
I/Launcher( 5682): Deferring update until onResume
W/ResourcesManager( 5682): Asset path '/system/framework/org.cyanogenmod.hardware.jar' does not exist or contains no resources.
W/ResourcesManager( 5682): Asset path '/system/framework/com.google.android.media.effects.jar' does not exist or contains no resources.
I/Launcher( 5682): Deferring update until onResume
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: CONNECTING
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
E/WifiNative-wlan0( 939): doBoolean: disable
I/wpa_supplicant( 5273): wlan0: CTRL-EVENT-SCAN-STARTED
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: apnFailed
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
E/WifiNative-wlan0( 939): doBoolean: enable
E/WifiNative-wlan0( 939): doBoolean: disable
I/wpa_supplicant( 5273): wlan0: CTRL-EVENT-SCAN-STARTED
E/WifiNative-wlan0( 939): doBoolean: enable
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: CONNECTING
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
I/PowerManagerService( 939): Waking up from dozing (uid 1000)...
V/KeyguardServiceDelegate( 939): onScreenTurnedOn(showListener = [email protected])
I/DisplayPowerController( 939): Blocking screen on until initial contents have been drawn.
D/SurfaceFlinger( 257): Set power mode=2, type=0 flinger=0xb6a62000
D/qdhwcomposer( 257): hwc_setPowerMode: Setting mode 2 on display: 0
I/DisplayManagerService( 939): Display device changed: DisplayDeviceInfo{"Built-in Screen": 1440 x 2560, 60.0 fps, supportedRefreshRates [60.0], density 560, 494.27 x 492.606 dpi, appVsyncOff 7500000, presDeadline 12666667, touch INTERNAL, rotation 0, type BUILT_IN, state ON, FLAG_DEFAULT_DISPLAY, FLAG_ROTATES_WITH_CONTENT, FLAG_SECURE, FLAG_SUPPORTS_PROTECTED_BUFFERS}
V/ActivityManager( 939): Display changed displayId=0
D/audio_hw_primary( 2640): adev_set_parameters: enter: screen_state=on
E/audio_a2dp_hw( 2640): adev_set_parameters: ERROR: set param called even when stream out is null
D/mot_vr_audio_hw( 2640): adev_set_parameters: screen_state=on
E/WifiNative-wlan0( 939): doBoolean: disable
V/KeyguardServiceDelegate( 939): **** SHOWN CALLED ****
E/native ( 939): do suspend false
D/BrcmNfcJni( 2236): RoutingManager::nfaEeCallback: NFA_EE_SET_PROTO_CFG_EVT; status=0x0
D/BrcmNfcJni( 2236): RoutingManager::commitRouting
D/BrcmNfcJni( 2236): RoutingManager::nfaEeCallback: NFA_EE_UPDATED_EVT
I/ActivityManager( 939): Start proc com.android.deskclock for broadcast com.android.deskclock/com.android.alarmclock.DigitalAppWidgetProvider: pid=6412 uid=10036 gids={50036, 9997, 1028, 1023, 3003} abi=armeabi-v7a
I/qdhwcomposer( 257): handle_blank_event: dpy:0 panel power state: 1
I/ActivityManager( 939): Killing 5123:com.android.providers.calendar/u0a2 (adj 15): empty #17
D/qdhwcomposer( 257): hwc_setPowerMode: Done setting mode 2 on display 0
W/art ( 939): Long monitor contention event with owner method=void com.android.server.wm.WindowAnimator$1.run() from WindowAnimator.java:120 waiters=0 for 166ms
D/SurfaceControl( 939): Excessive delay in setPowerMode(): 311ms
I/DisplayPowerController( 939): Unblocked screen on after 331 ms
E/libEGL ( 939): call to OpenGL ES API with no current context (logged once per thread)
I/DreamManagerService( 939): Gently waking up from dream.
I/DreamManagerService( 939): Leaving dreamland.
I/DreamController( 939): Stopping dream: name=ComponentInfo{com.android.systemui/com.android.systemui.doze.DozeService}, isTest=false, canDoze=true, userId=0
D/WifiService( 939): acquireWifiLockLocked: WifiLock{NlpWifiLock type=2 [email protected]}
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/WifiService( 939): releaseWifiLockLocked: WifiLock{NlpWifiLock type=2 [email protected]}
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: apnFailed
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
I/wpa_supplicant( 5273): wlan0: CTRL-EVENT-SCAN-STARTED
I/wpa_supplicant( 5273): wlan0: CTRL-EVENT-SCAN-STARTED
I/PowerManagerService( 939): Going to sleep due to screen timeout (uid 1000)...
I/DisplayManagerService( 939): Display device changed: DisplayDeviceInfo{"Built-in Screen": 1440 x 2560, 60.0 fps, supportedRefreshRates [60.0], density 560, 494.27 x 492.606 dpi, appVsyncOff 7500000, presDeadline 12666667, touch INTERNAL, rotation 0, type BUILT_IN, state OFF, FLAG_DEFAULT_DISPLAY, FLAG_ROTATES_WITH_CONTENT, FLAG_SECURE, FLAG_SUPPORTS_PROTECTED_BUFFERS}
V/ActivityManager( 939): Display changed displayId=0
D/SurfaceFlinger( 257): Set power mode=0, type=0 flinger=0xb6a62000
D/qdhwcomposer( 257): hwc_setPowerMode: Setting mode 0 on display: 0
I/qdhwcomposer( 257): handle_blank_event: dpy:0 panel power state: 0
D/qdhwcomposer( 257): hwc_setPowerMode: Done setting mode 0 on display 0
D/SurfaceControl( 939): Excessive delay in setPowerMode(): 278ms
I/DreamManagerService( 939): Entering dreamland.
I/PowerManagerService( 939): Dozing...
I/DreamController( 939): Starting dream: name=ComponentInfo{com.android.systemui/com.android.systemui.doze.DozeService}, isTest=false, canDoze=true, userId=0
D/VoldCmdListener( 256): cryptfs getpwtype
D/audio_hw_primary( 2640): adev_set_parameters: enter: screen_state=off
E/audio_a2dp_hw( 2640): adev_set_parameters: ERROR: set param called even when stream out is null
D/mot_vr_audio_hw( 2640): adev_set_parameters: screen_state=off
D/VoldCmdListener( 256): cryptfs getpwtype
E/WifiNative-wlan0( 939): doBoolean: enable
E/native ( 939): do suspend true
D/VoldCmdListener( 256): cryptfs getpwtype
D/PhoneStatusBar( 1991): disable: < expand ICONS alerts SYSTEM_INFO back HOME RECENT clock SEARCH >
D/VoldCmdListener( 256): cryptfs getpwtype
I/PowerManagerService( 939): Waking up from dozing (uid 1000)...
V/KeyguardServiceDelegate( 939): onScreenTurnedOn(showListener = [email protected])
I/DisplayPowerController( 939): Blocking screen on until initial contents have been drawn.
E/WifiNative-wlan0( 939): doBoolean: disable
D/SurfaceFlinger( 257): Set power mode=2, type=0 flinger=0xb6a62000
D/qdhwcomposer( 257): hwc_setPowerMode: Setting mode 2 on display: 0
I/DisplayManagerService( 939): Display device changed: DisplayDeviceInfo{"Built-in Screen": 1440 x 2560, 60.0 fps, supportedRefreshRates [60.0], density 560, 494.27 x 492.606 dpi, appVsyncOff 7500000, presDeadline 12666667, touch INTERNAL, rotation 0, type BUILT_IN, state ON, FLAG_DEFAULT_DISPLAY, FLAG_ROTATES_WITH_CONTENT, FLAG_SECURE, FLAG_SUPPORTS_PROTECTED_BUFFERS}
E/native ( 939): do suspend false
D/audio_hw_primary( 2640): adev_set_parameters: enter: screen_state=on
E/audio_a2dp_hw( 2640): adev_set_parameters: ERROR: set param called even when stream out is null
D/mot_vr_audio_hw( 2640): adev_set_parameters: screen_state=on
V/ActivityManager( 939): Display changed displayId=0
V/KeyguardServiceDelegate( 939): **** SHOWN CALLED ****
I/qdhwcomposer( 257): handle_blank_event: dpy:0 panel power state: 1
D/qdhwcomposer( 257): hwc_setPowerMode: Done setting mode 2 on display 0
D/SurfaceControl( 939): Excessive delay in setPowerMode(): 244ms
I/DisplayPowerController( 939): Unblocked screen on after 281 ms
D/BrcmNfcJni( 2236): RoutingManager::nfaEeCallback: NFA_EE_SET_PROTO_CFG_EVT; status=0x0
D/BrcmNfcJni( 2236): RoutingManager::commitRouting
I/DreamManagerService( 939): Gently waking up from dream.
D/BrcmNfcJni( 2236): RoutingManager::nfaEeCallback: NFA_EE_UPDATED_EVT
I/DreamManagerService( 939): Leaving dreamland.
I/DreamController( 939): Stopping dream: name=ComponentInfo{com.android.systemui/com.android.systemui.doze.DozeService}, isTest=false, canDoze=true, userId=0
D/WifiService( 939): acquireWifiLockLocked: WifiLock{NlpWifiLock type=2 [email protected]}
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/WifiService( 939): releaseWifiLockLocked: WifiLock{NlpWifiLock type=2 [email protected]}
D/VoldCmdListener( 256): cryptfs getpwtype
D/VoldCmdListener( 256): cryptfs getpwtype
D/PhoneStatusBar( 1991): disable: < expand ICONS alerts SYSTEM_INFO back HOME RECENT clock SEARCH >
W/AudioTrack( 1991): AUDIO_OUTPUT_FLAG_FAST denied by client
E/AudioTrack( 1991): AudioTrack::set : Exit
D/audio_hw_primary( 2640): out_set_parameters: enter: usecase(1: low-latency-playback) kvpairs: routing=2
D/PhoneStatusBar( 1991): disable: < expand icons* alerts system_info* back HOME RECENT clock SEARCH >
D/audio_hw_primary( 2640): select_devices: out_snd_device(2: speaker) in_snd_device(0: none)
D/msm8974_platform( 2640): platform_send_audio_calibration: sending audio calibration for snd_device(2) acdb_id(15)
E/ACDB-LOADER( 2640): Error: ACDB AFE returned = -19
D/audio_hw_primary( 2640): enable_snd_device: snd_device(2: speaker)
D/audio_hw_primary( 2640): enable_audio_route: apply and update mixer path: low-latency-playback speaker
D/VoldCmdListener( 256): cryptfs getpwtype
D/VoldCmdListener( 256): cryptfs getpwtype
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/phone ( 2270): [RadioInfo] updateImsRegRequiredState isImsRegRequired()=false
D/phone ( 2270): [RadioInfo] updateSmsOverImsState isSmsOverImsEnabled()=false
D/phone ( 2270): [RadioInfo] updateLteRamDumpState isLteRamDumpEnabled()=false
D/phone ( 2270): [RadioInfo] onResume: register phone & data intents
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneStatusBar( 1991): disable: < expand icons alerts system_info back home* recent* clock search* >
D/BrcmNfcJni( 2236): RoutingManager::nfaEeCallback: NFA_EE_SET_PROTO_CFG_EVT; status=0x0
D/BrcmNfcJni( 2236): RoutingManager::commitRouting
D/BrcmNfcJni( 2236): RoutingManager::nfaEeCallback: NFA_EE_UPDATED_EVT
W/InputMethodManagerService( 939): Window already focused, ignoring focus gain of: [email protected] [email protected], token = [email protected]
D/PhoneApp( 2270): getPhone phoneId:0
D/phone ( 2270): [RadioInfo] onCellInfoChanged: arrayCi=[CellInfoLte:{mRegistered=YES mTimeStampType=java_ril mTimeStamp=445539000ns CellIdentityLte:{ mMcc=311 mMnc=480 mCi=5385986 mPci=337 mTac=5387} CellSignalStrengthLte: ss=22 rsrp=-102 rsrq=-14 rssnr=-30 cqi=2147483647 ta=2147483647}]
D/phone ( 2270): [RadioInfo] onDataConnectionRealTimeInfoChanged: dcRtInfo=mTime=9223372036854775807 mDcPowerState=2147483647
I/Timeline( 2270): Timeline: Activity_idle id: [email protected] time:447282
D/phone ( 2270): [RadioInfo] onCellInfoChanged: arrayCi=[CellInfoLte:{mRegistered=YES mTimeStampType=java_ril mTimeStamp=449579000ns CellIdentityLte:{ mMcc=311 mMnc=480 mCi=5385986 mPci=337 mTac=5387} CellSignalStrengthLte: ss=22 rsrp=-100 rsrq=-13 rssnr=34 cqi=2147483647 ta=2147483647}]
D/phone ( 2270): [RadioInfo] onCellInfoChanged: arrayCi=[CellInfoLte:{mRegistered=YES mTimeStampType=java_ril mTimeStamp=449582000ns CellIdentityLte:{ mMcc=311 mMnc=480 mCi=5385986 mPci=337 mTac=5387} CellSignalStrengthLte: ss=23 rsrp=-99 rsrq=-11 rssnr=0 cqi=2147483647 ta=2147483647}]
D/audio_hw_primary( 2640): disable_audio_route: reset and update mixer path: low-latency-playback speaker
D/audio_hw_primary( 2640): disable_snd_device: snd_device(2: speaker)
D/phone ( 2270): [RadioInfo] onCellInfoChanged: arrayCi=[CellInfoLte:{mRegistered=YES mTimeStampType=java_ril mTimeStamp=452166000ns CellIdentityLte:{ mMcc=311 mMnc=480 mCi=5385986 mPci=337 mTac=5387} CellSignalStrengthLte: ss=23 rsrp=-99 rsrq=-14 rssnr=28 cqi=2147483647 ta=2147483647}]
I/wpa_supplicant( 5273): wlan0: CTRL-EVENT-SCAN-STARTED
D/phone ( 2270): [RadioInfo] onCellInfoChanged: arrayCi=[CellInfoLte:{mRegistered=YES mTimeStampType=java_ril mTimeStamp=454724000ns CellIdentityLte:{ mMcc=311 mMnc=480 mCi=5385986 mPci=337 mTac=5387} CellSignalStrengthLte: ss=23 rsrp=-99 rsrq=-14 rssnr=28 cqi=2147483647 ta=2147483647}]
D/phone ( 2270): [RadioInfo] onCellInfoChanged: arrayCi=[CellInfoLte:{mRegistered=YES mTimeStampType=java_ril mTimeStamp=454733000ns CellIdentityLte:{ mMcc=311 mMnc=480 mCi=5385986 mPci=337 mTac=5387} CellSignalStrengthLte: ss=22 rsrp=-99 rsrq=-10 rssnr=20 cqi=2147483647 ta=2147483647}]
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: CONNECTING
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
I/wpa_supplicant( 5273): wlan0: CTRL-EVENT-SCAN-STARTED
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/phone ( 2270): [RadioInfo] onCellInfoChanged: arrayCi=[CellInfoLte:{mRegistered=YES mTimeStampType=java_ril mTimeStamp=459833000ns CellIdentityLte:{ mMcc=311 mMnc=480 mCi=5385986 mPci=337 mTac=5387} CellSignalStrengthLte: ss=22 rsrp=-99 rsrq=-10 rssnr=20 cqi=2147483647 ta=2147483647}]
D/phone ( 2270): [RadioInfo] onCellInfoChanged: arrayCi=[CellInfoLte:{mRegistered=YES mTimeStampType=java_ril mTimeStamp=459848000ns CellIdentityLte:{ mMcc=311 mMnc=480 mCi=5385986 mPci=337 mTac=5387} CellSignalStrengthLte: ss=21 rsrp=-99 rsrq=-11 rssnr=18 cqi=2147483647 ta=2147483647}]
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: apnFailed
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/phone ( 2270): [RadioInfo] onCellInfoChanged: arrayCi=[CellInfoLte:{mRegistered=YES mTimeStampType=java_ril mTimeStamp=462396000ns CellIdentityLte:{ mMcc=311 mMnc=480 mCi=5385986 mPci=337 mTac=5387} CellSignalStrengthLte: ss=21 rsrp=-100 rsrq=-12 rssnr=34 cqi=2147483647 ta=2147483647}]
D/phone ( 2270): [RadioInfo] onCellInfoChanged: arrayCi=[CellInfoLte:{mRegistered=YES mTimeStampType=java_ril mTimeStamp=467517000ns CellIdentityLte:{ mMcc=311 mMnc=480 mCi=5385986 mPci=337 mTac=5387} CellSignalStrengthLte: ss=21 rsrp=-99 rsrq=-12 rssnr=34 cqi=2147483647 ta=2147483647}]
I/wpa_supplicant( 5273): wlan0: CTRL-EVENT-SCAN-STARTED
D/phone ( 2270): [RadioInfo] onCellInfoChanged: arrayCi=[CellInfoLte:{mRegistered=YES mTimeStampType=java_ril mTimeStamp=470077000ns CellIdentityLte:{ mMcc=311 mMnc=480 mCi=5385986 mPci=337 mTac=5387} CellSignalStrengthLte: ss=21 rsrp=-99 rsrq=-11 rssnr=56 cqi=2147483647 ta=2147483647}]
D/phone ( 2270): [RadioInfo] onCellInfoChanged: arrayCi=[CellInfoLte:{mRegistered=YES mTimeStampType=java_ril mTimeStamp=472636000ns CellIdentityLte:{ mMcc=311 mMnc=480 mCi=5385986 mPci=337 mTac=5387} CellSignalStrengthLte: ss=21 rsrp=-99 rsrq=-11 rssnr=36 cqi=2147483647 ta=2147483647}]
D/phone ( 2270): [RadioInfo] onCellInfoChanged: arrayCi=[CellInfoLte:{mRegistered=YES mTimeStampType=java_ril mTimeStamp=475205000ns CellIdentityLte:{ mMcc=311 mMnc=480 mCi=5385986 mPci=337 mTac=5387} CellSignalStrengthLte: ss=21 rsrp=-99 rsrq=-11 rssnr=36 cqi=2147483647 ta=2147483647}]
D/phone ( 2270): [RadioInfo] onCellInfoChanged: arrayCi=[CellInfoLte:{mRegistered=YES mTimeStampType=java_ril mTimeStamp=475213000ns CellIdentityLte:{ mMcc=311 mMnc=480 mCi=5385986 mPci=337 mTac=5387} CellSignalStrengthLte: ss=22 rsrp=-100 rsrq=-13 rssnr=18 cqi=2147483647 ta=2147483647}]
D/phone ( 2270): [RadioInfo] onCellInfoChanged: arrayCi=[CellInfoLte:{mRegistered=YES mTimeStampType=java_ril mTimeStamp=480312000ns CellIdentityLte:{ mMcc=311 mMnc=480 mCi=5385986 mPci=337 mTac=5387} CellSignalStrengthLte: ss=24 rsrp=-100 rsrq=-12 rssnr=-38 cqi=2147483647 ta=2147483647}]
D/phone ( 2270): [RadioInfo] onCellInfoChanged: arrayCi=[CellInfoLte:{mRegistered=YES mTimeStampType=java_ril mTimeStamp=481235000ns CellIdentityLte:{ mMcc=311 mMnc=480 mCi=5385986 mPci=337 mTac=5387} CellSignalStrengthLte: ss=22 rsrp=-101 rsrq=-13 rssnr=12 cqi=2147483647 ta=2147483647}]
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: CONNECTING
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: lostDataConnection
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
I/wpa_supplicant( 5273): wlan0: CTRL-EVENT-SCAN-STARTED
D/phone ( 2270): [RadioInfo] onCellInfoChanged: arrayCi=[CellInfoLte:{mRegistered=YES mTimeStampType=java_ril mTimeStamp=485436000ns CellIdentityLte:{ mMcc=311 mMnc=480 mCi=5385986 mPci=337 mTac=5387} CellSignalStrengthLte: ss=22 rsrp=-99 rsrq=-13 rssnr=-112 cqi=2147483647 ta=2147483647}]
D/PhoneApp( 2270): getPhone phoneId:0
D/PhoneApp( 2270): mReceiver: ACTION_ANY_DATA_CONNECTION_STATE_CHANGED
D/PhoneApp( 2270): - state: DISCONNECTED
D/PhoneApp( 2270): - reason: apnFailed
D/NotificationMgr( 2270): hideDataDisconnectedRoaming()...
D/phone ( 2270): [RadioInfo] onCellInfoChanged: arrayCi=[CellInfoLte:{mRegistered=YES mTimeStampType=java_ril mTimeStamp=487996000ns CellIdentityLte:{ mMcc=311 mMnc=480 mCi=5385986 mPci=337 mTac=5387} CellSignalStrengthLte: ss=21 rsrp=-100 rsrq=-13 rssnr=-2 cqi=2147483647 ta=2147483647}]

Bootloader Unlock Ideas

Hi Guys I have been messing with Bootloader unlock ideas and wanted to share some of my thoughts on it. I really dont know much about it but here is what i have found so far
I know that if i reboot to fastboot mode with
Code:
adb reboot bootloader
I can run getvar all and see this unlock_code
Code:
fastboot getvar all
(bootloader) max-download-size: 134217728
(bootloader) partition-size:userdata: 17329be00
(bootloader) partition-type:userdata: unknown
(bootloader) partition-size:cache: fa00000
(bootloader) partition-type:cache: unknown
(bootloader) partition-size:system: 4b000000
(bootloader) partition-type:system: unknown
(bootloader) partition-size:TEE2: 500000
(bootloader) partition-type:TEE2: unknown
(bootloader) partition-size:TEE1: 500000
(bootloader) partition-type:TEE1: unknown
(bootloader) partition-size:LOGO: 380000
(bootloader) partition-type:LOGO: unknown
(bootloader) partition-size:MISC: 80000
(bootloader) partition-type:MISC: unknown
(bootloader) partition-size:recovery: 1000000
(bootloader) partition-type:recovery: unknown
(bootloader) partition-size:boot: 1000000
(bootloader) partition-type:boot: unknown
(bootloader) partition-size:UBOOT: 100000
(bootloader) partition-type:UBOOT: unknown
(bootloader) partition-size:EXPDB: 1160000
(bootloader) partition-type:EXPDB: unknown
(bootloader) partition-size:DKB: 100000
(bootloader) partition-type:DKB: unknown
(bootloader) partition-size:KB: 100000
(bootloader) partition-type:KB: unknown
(bootloader) off-mode-charge: 1
(bootloader) secure: yes
(bootloader) kernel: lk
(bootloader) product: FORD
(bootloader) version: 0.5
(bootloader) unlock_status: false
(bootloader) unlock_version: 1
(bootloader) unlock_code: 0x32c5657dd83d5139
(bootloader) prod: 1
all: Done!!
I also know that the command to unlock the bootloader
Code:
fastboot flash unlock unlock.bin
Code:
C:\Development\adt-bundle-windows-x86_64-20130729\sdk\platform-tools>fastboot fl
ash unlock "H:\Tom Stuff\Amazon Fire 7in 5th gen Ford\unlock.bin"
target reported max download size of 134217728 bytes
sending 'unlock' (0 KB)...
OKAY [ 0.015s]
writing 'unlock'...
FAILED (remote: unlock code error)
finished. total time: 0.028s
I also ran idme print with root access and got back this
Code:
[email protected]:/ $ su
[email protected]:/ # idme print
board_id: 0025001040000015
serial: G0K0H40453870FHX
mac_addr: F0272D525FE6
mac_sec: 3E9WML8GV8BJH6Z1CD88
bt_mac_addr: 00BB3A0BFFEE
product_name: 0
productid: 0
productid2: 0
bootmode: 0
postmode: 0
bootcount: 90
manufacturing:
unlock_code:
sensorcal: 480000000000000000000000000000000000000000000000000000000000000000000
0000000000000000000000000000
register_tag: 715aa2763b01f250
KB:
4b 42 50 46 18 0e 00 00 28 0e
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00
DKB:
30 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00
device_type_id: A2M4YX06LWP8WI
dev_flags: 0
fos_flags: 0
usr_flags: 0
At this point i have tried creating a couple different unlock.bin's with this unlock code and even changing it to decimal instead of hexadecimal but really i am lost here was hoping someone with a little more info and experiance might be able to help thanks.
Seems interesting but I doubt it will be this easy.
I can't wait to see what you all do with this!
You've probably tried this, but use the unlock code as a parameter, so fastboot flash unlock 0xABCD etc. Also, fastboot flash unlock isn't a stock fastboot command, it might be Amazon's , but not stock. Try fastboot oem unlock, or the new commands, fastboot flashing unlock or fastboot flashing unlock-critical.
---------- Post added at 08:41 PM ---------- Previous post was at 08:39 PM ----------
Also try fastboot flash unlocktoken unlock.bin
Koopa777 said:
You've probably tried this, but use the unlock code as a parameter, so fastboot flash unlock 0xABCD etc. Also, fastboot flash unlock isn't a stock fastboot command, it might be Amazon's , but not stock. Try fastboot oem unlock, or the new commands, fastboot flashing unlock or fastboot flashing unlock-critical.
---------- Post added at 08:41 PM ---------- Previous post was at 08:39 PM ----------
Also try fastboot flash unlocktoken unlock.bin
Click to expand...
Click to collapse
good ideas but i have already tried all of those first before this post but ideas are welcome
I don't have a Windows installation ATM. Has anyone tried sp flash tool for mediatek devices?
EDIT: I played a bit with MTK droid tools to create a scatter file, but no luck (so it seems SP tools are a no go). I also tried some shady Mediatek tools. Also with no luck. My take is that unlocking via fastboot may not work at all. Maybe look into mediatek stuff to unlock the Fire.
Keep at it guys! Apparently Android 6.0/CM13 isn't doable until bootloader unlocked. This is probably best tablet around $50 with probably fairly large sales. Worth the effort.
As far as I know, that unlock code that fastboot gives is much like Motorola's unlock setup... The device's code is hashed/SHA/etc with a master key, spits out a device unlock code that you can give fastboot.
xenokc said:
Apparently Android 6.0/CM13 isn't doable until bootloader unlocked. This is probably best tablet around $50 with probably fairly large sales. Worth the effort.
Click to expand...
Click to collapse
We should just need kexec.
Idk but I need some marshmallow love
Sent from my KFFOWI using Tapatalk
This has been discussed a bit in other threads
Amazon Fire Bootloader unlock code?? by @Awesomeslayerg
Working Bootable recovery for the KFFOWI (Ford) by @Vlasp
I have a similar thread in the HD 8 & 10 section, but nothing you have not found already.
ok so i dont really know where to post this but i am trying to adb shell dd my mmcblk0 file and i got a img that was 4ggs and now i try to dd blahblah skip=4294967295 but i get an error "dd: dev/block/mmcblk0: Invalid argument"almost 100 percent that it is the same file iwas using before all i did was exit the shell (2 times i was root) and adb pull the mmcblk0.img from the ../sdcard2/ it took a few minutes and i just went on to procede with the skip=4ggs and got the error dont want to try to reboot incase i fd it up. ok i figured it out i just changed it to skip=40049... hopefully i can still merge the two together later.
Tomsgt said:
Hi Guys I have been messing with Bootloader unlock ideas and wanted to share some of my thoughts on it. I really dont know much about it but here is what i have found so far
I know that if i reboot to fastboot mode with
Code:
adb reboot bootloader
I can run getvar all and see this unlock_code
Code:
fastboot getvar all
(bootloader) max-download-size: 134217728
(bootloader) partition-size:userdata: 17329be00
(bootloader) partition-type:userdata: unknown
(bootloader) partition-size:cache: fa00000
(bootloader) partition-type:cache: unknown
(bootloader) partition-size:system: 4b000000
(bootloader) partition-type:system: unknown
(bootloader) partition-size:TEE2: 500000
(bootloader) partition-type:TEE2: unknown
(bootloader) partition-size:TEE1: 500000
(bootloader) partition-type:TEE1: unknown
(bootloader) partition-size:LOGO: 380000
(bootloader) partition-type:LOGO: unknown
(bootloader) partition-size:MISC: 80000
(bootloader) partition-type:MISC: unknown
(bootloader) partition-size:recovery: 1000000
(bootloader) partition-type:recovery: unknown
(bootloader) partition-size:boot: 1000000
(bootloader) partition-type:boot: unknown
(bootloader) partition-size:UBOOT: 100000
(bootloader) partition-type:UBOOT: unknown
(bootloader) partition-size:EXPDB: 1160000
(bootloader) partition-type:EXPDB: unknown
(bootloader) partition-size:DKB: 100000
(bootloader) partition-type:DKB: unknown
(bootloader) partition-size:KB: 100000
(bootloader) partition-type:KB: unknown
(bootloader) off-mode-charge: 1
(bootloader) secure: yes
(bootloader) kernel: lk
(bootloader) product: FORD
(bootloader) version: 0.5
(bootloader) unlock_status: false
(bootloader) unlock_version: 1
(bootloader) unlock_code: 0x32c5657dd83d5139
(bootloader) prod: 1
all: Done!!
I also know that the command to unlock the bootloader
Code:
fastboot flash unlock unlock.bin
Code:
C:\Development\adt-bundle-windows-x86_64-20130729\sdk\platform-tools>fastboot fl
ash unlock "H:\Tom Stuff\Amazon Fire 7in 5th gen Ford\unlock.bin"
target reported max download size of 134217728 bytes
sending 'unlock' (0 KB)...
OKAY [ 0.015s]
writing 'unlock'...
FAILED (remote: unlock code error)
finished. total time: 0.028s
I also ran idme print with root access and got back this
Code:
[email protected]:/ $ su
[email protected]:/ # idme print
board_id: 0025001040000015
serial: G0K0H40453870FHX
mac_addr: F0272D525FE6
mac_sec: 3E9WML8GV8BJH6Z1CD88
bt_mac_addr: 00BB3A0BFFEE
product_name: 0
productid: 0
productid2: 0
bootmode: 0
postmode: 0
bootcount: 90
manufacturing:
unlock_code:
sensorcal: 480000000000000000000000000000000000000000000000000000000000000000000
0000000000000000000000000000
register_tag: 715aa2763b01f250
KB:
4b 42 50 46 18 0e 00 00 28 0e
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00
DKB:
30 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00
device_type_id: A2M4YX06LWP8WI
dev_flags: 0
fos_flags: 0
usr_flags: 0
At this point i have tried creating a couple different unlock.bin's with this unlock code and even changing it to decimal instead of hexadecimal but really i am lost here was hoping someone with a little more info and experiance might be able to help thanks.
Click to expand...
Click to collapse
Ok so i dont know if any of this will help but....
Code:
[email protected]:/ # idme print
board_id: 0025001050010015
serial: G000H4045445154K
mac_addr: F0272D9D13E0
mac_sec: 3ECQJN1SLTE1HRUQ770F
bt_mac_addr: 84D6D0221452
product_name: 0
productid: 0
productid2: 0
bootmode: 0
postmode: 0
bootcount: 64
manufacturing: PSN=P00082035443042S FSN=3862080402143
unlock_code:
sensorcal: 4800000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
register_tag: 715aa2763b01f250
KB:
4b 42 50 46 18 0e 00 00 28 0e
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00
DKB:
30 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00
device_type_id: A2M4YX06LWP8WI
dev_flags: 0
fos_flags: 0
usr_flags: 0
[email protected]:/ #
And
Code:
fastboot getvar all
(bootloader) max-download-size: 134217728
(bootloader) partition-size:userdata: 17329be00
(bootloader) partition-type:userdata: unknown
(bootloader) partition-size:cache: fa00000
(bootloader) partition-type:cache: unknown
(bootloader) partition-size:system: 4b000000
(bootloader) partition-type:system: unknown
(bootloader) partition-size:TEE2: 500000
(bootloader) partition-type:TEE2: unknown
(bootloader) partition-size:TEE1: 500000
(bootloader) partition-type:TEE1: unknown
(bootloader) partition-size:LOGO: 380000
(bootloader) partition-type:LOGO: unknown
(bootloader) partition-size:MISC: 80000
(bootloader) partition-type:MISC: unknown
(bootloader) partition-size:recovery: 1000000
(bootloader) partition-type:recovery: unknown
(bootloader) partition-size:boot: 1000000
(bootloader) partition-type:boot: unknown
(bootloader) partition-size:UBOOT: 100000
(bootloader) partition-type:UBOOT: unknown
(bootloader) partition-size:EXPDB: 1160000
(bootloader) partition-type:EXPDB: unknown
(bootloader) partition-size:DKB: 100000
(bootloader) partition-type:DKB: unknown
(bootloader) partition-size:KB: 100000
(bootloader) partition-type:KB: unknown
(bootloader) off-mode-charge: 1
(bootloader) secure: yes
(bootloader) kernel: lk
(bootloader) product: FORD
(bootloader) version: 0.5
(bootloader) unlock_status: false
(bootloader) unlock_version: 1
(bootloader) unlock_code: 0x444d63d061775c38
(bootloader) prod: 1
all: Done!!
finished. total time: 0.012s
if there is anything i can do/donate to help such as Raw image files or logs let me know i have Amazon Fire 5.1.1 rooted after ota, it updated overnight before i could look anything up, my wife got this for xmas, with gapps framework, hidden fireos launcher, and hidden ota's and such, can use fastboot oem append-cmdline "androidboot.unlocked_kernel=true" to run adb as root and remount my file system, and i am going to pull a full mmcblk0 raw binary image tonight hopefully it will work. going to run some file system forensics on the image and hopefully find some hidden or deleted files from when devices where manufactured.
serial console output
I bought one of these 7-inch Fire Tablets (5th generation) during the $35 sale a few weeks back. I purchased it from a big chain store, so it has model SV98LN rather than the KFFOWI reported by others in this forum, but everything else seems the same. After removing the rear panel, I looked around for test points on the motherboard. There were two conveniently labeled TX and RX. Poking around with a multimeter revealed that things were running at 1.8v. I found a good places to attach leads for VCC and GND, and connected them along with TX and RX to a spare FD232R-based serial adapter.
At 115200 baud (on-chip boot rom):
Code:
[DL] 00000000 00000000 010701
PR: 0001 01A6
F3: 0000 0000
V0: 0000 0000 [0001]
00: 1027 0002
01: 0000 0000
BP: 0000 0059
G0: 0182 0000
T0: 0000 0418
Jump to BL
Then at 921600 baud (preloader):
Code:
[USBD] USB PRB0 LineState: 0
[USBD] USB cable/ No Cable inserted!
[PLFM] Keep stay in USB Mode
Platform initialization is ok
wait for frequency meter finish, CLK26CALI = 0x81
mt_pll_post_init: mt_get_cpu_freq = 1040000Khz
wait for frequency meter finish, CLK26CALI = 0x90
mt_pll_post_init: mt_get_bus_freq = 273000Khz
wait for frequency meter finish, CLK26CALI = 0x81
mt_pll_post_init: mt_get_mem_freq = 333251Khz
[PWRAP] pwrap_init_preloader
[PWRAP] pwrap_init
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=0,rdata=2D52
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=1,rdata=800
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=2 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=3 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=4 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=5 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=6 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=7 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=8 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=9,rdata=1001
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=10,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=11,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=12,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=13,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=14,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=15,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=16,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=17,rdata=2003
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=18,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=19,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=20,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=21,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=22,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=23,rdata=6A97
[PWRAP] _pwrap_init_reg_clock
[PMIC_WRAP]wrap_init pass,the return value=0.
[pmic6323_init] Preloader Start..................
[pmic6323_init] PMIC CHIP Code = 0x2023
INT_MISC_CON: 0 TOP_RST_MISC: 0
pl pmic powerkey Release
[pmic6323_init] powerKey = 0
[pmic6323_init] is USB in = 0xB003
[pmic6323_init] Reg[0x11A]=0x1B
[pmic6323_init] Done...................
[PLFM] Init I2C: OK(0)
[PLFM] Init PWRAP: OK(0)
[PLFM] Init PMIC: OK(0)
[PLFM] chip[CA00]
[BLDR] Build Time: 20150730-164940
At this point the port switches back to 115200 baud, emits "READY", and waits briefly for input (in case the flash programming tool is connected). After a short time, it switches back to 921000 baud and continues.
Code:
==== Dump RGU Reg ========
RGU MODE: 4D
RGU LENGTH: FFE0
RGU STA: 0
RGU INTERVAL: FFF
RGU SWSYSRST: 0
==== Dump RGU Reg End ====
RGU: g_rgu_satus:0
mtk_wdt_mode_config mode value=10, tmp:22000010
PL P ON
WDT does not trigger reboot
mtk_wdt_mode_config mode value=5D, tmp:2200005D
RGU mtk_wdt_init:MTK_WDT_DEBUG_CTL(590200F3)
kpd read addr: 0x0040: data:0x4001
Enter mtk_kpd_gpio_set!
kpd debug column : -2147483612, -2147483611, 0, 0, 0, 0, 0, 0
kpd debug row : 0, 0, 0, 0, 0, 0, 0, 0
after set KP enable: KP_SEL = 0x0 !
MTK_PMIC_RST_KEY is used for this project!
[RTC] get_frequency_meter: input=0x0, ouput=5
[RTC] get_frequency_meter: input=0x0, ouput=3968
[RTC] get_frequency_meter: input=0x0, ouput=5
[RTC] get_frequency_meter: input=0x0, ouput=0
[RTC] get_frequency_meter: input=0x0, ouput=0
[RTC] bbpu = 0xE, con = 0xBFFA
rtc_first_boot_init
[RTC] get_frequency_meter: input=0x0, ouput=5
[RTC] get_frequency_meter: input=0x0, ouput=3968
[RTC] get_frequency_meter: input=0x0, ouput=5
[RTC] get_frequency_meter: input=0x0, ouput=0
[RTC] get_frequency_meter: input=0x0, ouput=0
rtc_2sec_stat_clear
rtc_2sec_reboot_check cali=1536
[RTC] irqsta = 0x0, pdn1 = 0x0, pdn2 = 0x201, spar0 = 0xC0, spar1 = 0x800
[RTC] new_spare0 = 0x0, new_spare1 = 0x1, new_spare2 = 0x1, new_spare3 = 0x1
[RTC] bbpu = 0xE, con = 0x426, cali = 0x600
pl pmic powerkey Release
hw_set_cc: 450
[0x0]=0x7B
[0x1]=0x7B
[0x2]=0xB2
[0x3]=0xB2
[0x4]=0x8C
[0x5]=0x8C
[0x6]=0x1F
[0x7]=0x1F
[0x8]=0xC
[0x9]=0xC
[0xA]=0x0
[0xB]=0x0
[0xC]=0x1
[0xD]=0x1
[0xE]=0x1
[0xF]=0x1
[0x10]=0x0
[0x11]=0x0
[0x12]=0x0
[0x13]=0x0
[0x14]=0x60
[0x15]=0x60
[0x16]=0x0
[0x17]=0x0
[0x18]=0x0
[0x19]=0x0
[0x1A]=0x10
[0x1B]=0x10
[0x1C]=0x0
[0x1D]=0x0
[0x1E]=0x1
[0x1F]=0x1
[0x20]=0x1
[0x21]=0x1
[0x22]=0x0
[0x23]=0x0
[0x24]=0x0
[0x25]=0x0
[0x26]=0x0
[0x27]=0x0
[0x28]=0x21
[0x29]=0x21
[0x2A]=0x14
[0x2B]=0x14
[0x2C]=0x44
[0x2D]=0x44
[0x2E]=0x54
[0x2F]=0x54
[0x30]=0x0
[0x31]=0x0
[0x32]=0x0
[0x33]=0x0
[0x34]=0x0
[0x35]=0x0
[0x36]=0x0
[0x37]=0x0
[0x38]=0x55
[0x39]=0x55
[0x3A]=0x0
hw_set_cc: done
[PLFM] USB/charger boot!
hw_set_cc: 450
[0x0]=0x7B
[0x1]=0x7B
[0x2]=0xB2
[0x3]=0xB2
[0x4]=0x8C
[0x5]=0x8C
[0x6]=0x1F
[0x7]=0x1F
[0x8]=0xC
[0x9]=0xC
[0xA]=0x0
[0xB]=0x0
[0xC]=0x1
[0xD]=0x1
[0xE]=0x1
[0xF]=0x1
[0x10]=0x0
[0x11]=0x0
[0x12]=0x0
[0x13]=0x0
[0x14]=0x60
[0x15]=0x60
[0x16]=0x0
[0x17]=0x0
[0x18]=0x0
[0x19]=0x0
[0x1A]=0x10
[0x1B]=0x10
[0x1C]=0x0
[0x1D]=0x0
[0x1E]=0x1
[0x1F]=0x1
[0x20]=0x1
[0x21]=0x1
[0x22]=0x0
[0x23]=0x0
[0x24]=0x0
[0x25]=0x0
[0x26]=0x0
[0x27]=0x0
[0x28]=0x21
[0x29]=0x21
[0x2A]=0x14
[0x2B]=0x14
[0x2C]=0x44
[0x2D]=0x44
[0x2E]=0x54
[0x2F]=0x54
[0x30]=0x0
[0x31]=0x0
[0x32]=0x0
[0x33]=0x0
[0x34]=0x0
[0x35]=0x0
[0x36]=0x0
[0x37]=0x0
[0x38]=0x55
[0x39]=0x55
[0x3A]=0x0
hw_set_cc: done
[RTC] Check SW Long Press RST = 0xC0
[RTC] rtc_bbpu_power_on done
[SD0] Bus Width: 1
[SD0] SET_CLK(260kHz): SCLK(259kHz) MODE(0) DDR(0) DIV(193) DS(0) RS(0)
[SD0] Switch to High-Speed mode!
[SD0] SET_CLK(260kHz): SCLK(259kHz) MODE(2) DDR(1) DIV(96) DS(0) RS(0)
[SD0] Bus Width: 8
[SD0] Size: 7456 MB, Max.Speed: 52000 kHz, blklen(512), nblks(15269888), ro(0)
[SD0] Initialized
[SD0] SET_CLK(52000kHz): SCLK(50000kHz) MODE(2) DDR(1) DIV(0) DS(0) RS(0)
msdc_ett_offline_to_pl: size<2> m_id<0x90>
msdc <0> <HYNIX > <H8G1e>
msdc <1> <xxxxxx> <H8G1e>
msdc failed to find
[EMI] mcp_dram_num:0,discrete_dram_num:1,enable_combo_dis:0
mt_get_dram_type() 0x3
[EMI] LPDDR3
[Check]mt_get_mdl_number 0x0
[EMI] eMMC/NAND ID = 90,1,4A,48,38,47,31,65,5,7,D0,C8,D4,FA,82,CB
[EMI] MDL number = 0
[EMI] emi_set eMMC/NAND ID = 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0
[EMI][Vcore]0x21E=0x48,0x220=0x48
[EMI][Vmem]0x554=0xF
[EMI] LPDDR3 DRAM Clock = 1333 MHz, MEMPLL MODE = 2
[EMI] PCDDR3 RXTDN Calibration:
Start REXTDN SW calibration...
PD 0x1e4[13]:0h
1.INTREF_SEL:0x100[17:16]:0h
2.enable P drive (initial settings),DRAMC_DLLSEL:500F0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:500F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:510F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:520F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:530F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:540F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:550F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:560F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:570F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:580F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:590F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:5A0F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:5B0F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:5C0F0h
2.2.CMPOT:0x3dc[31]:80000000h
P drive:12
3.INTREF_SEL:0x100[17:16]:0h
4.enable N drive (initial settings),DRAMC_DLLSEL:3C0FFh
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3C0FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3C1FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3C2FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3C3FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3C4FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3C5FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3C6FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3C7FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3C8FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3C9FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3CAFFh
4.2.CMPOT:0x3dc[31]:0h
N drive:9
drvp=0xC,drvn=0x9
=============================================
X-axis: DQS Gating Window Delay (Fine Scale)
Y-axis: DQS Gating Window Delay (Coarse Scale)
=============================================
0 8 16 24 32 40 48 56 64 72 80 88 96 104 112 120
--------------------------------------------------------------------------------
0006:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0007:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0008:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0009:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
000A:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
000B:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
000C:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
000D:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
000E:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
000F:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0010:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0011:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0012:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0013:| 0 0 0 0 0 0 0 0 0 1 1 1 1 1 1 1
0014:| 0 0 1 1 1 1 1 1 1 1 1 1 1 1 1 0
0015:| 1 1 1 1 1 1 1 1 0 0 0 0 0 0 0 0
0016:| 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Rank 13 coarse tune value selection : 32,
20
64
rank 0 coarse = 20
rank 0 fine = 64
00:| 0 0 0 0 1 1 1 0
opt_dle value:9
[EMI]warning:rank auto detect:==single rank==
Change CMD/ADDR output delay = 15
Change CLK output delay = 15
20
80
Change CMD/ADDR output delay = 14
Change CLK output delay = 14
20
80
Change CMD/ADDR output delay = 13
Change CLK output delay = 13
20
80
Change CMD/ADDR output delay = 12
Change CLK output delay = 12
20
80
Change CMD/ADDR output delay = 11
Change CLK output delay = 11
20
80
Change CMD/ADDR output delay = 0
Change CLK output delay = 0
20
64
byte:0, (DQS,DQ)=(8,9)
byte:1, (DQS,DQ)=(8,A)
byte:2, (DQS,DQ)=(8,8)
byte:3, (DQS,DQ)=(8,8)
[EMI] DRAMC calibration passed
[MEM] complex R/W mem test pass
0:dram_rank_size:40000000
[Dram_Buffer] dram size:1073741824
[Dram_Buffer] structure size: 1557624
[Dram_Buffer] MAX_TEE_DRAM_SIZE: 268435456
<< binary spew, perhaps signature from nvram? >>
sram(0xC10C983F) sig mismatch
RAM_CONSOLE start: 0x83F00000, size: 0x4000
RAM_CONSOLE wdt status (0x0)=0x0
[PLFM] Init Boot Device: OK(0)
Enter mtk_kpd_gpio_set!
kpd debug column : -2147483612, -2147483611, 0, 0, 0, 0, 0, 0
kpd debug row : 0, 0, 0, 0, 0, 0, 0, 0
[PART] GPT dump
[PART] 1: 00000800 00000800 'KB'
[PART] 2: 00000800 00001000 'DKB'
[PART] 3: 00008B00 00001800 'EXPDB'
[PART] 4: 00000800 0000A300 'UBOOT'
[PART] 5: 00008000 0000AB00 'boot'
[PART] 6: 00008000 00012B00 'recovery'
[PART] 7: 00000400 0001AB00 'MISC'
[PART] 8: 00001C00 0001AF00 'LOGO'
[PART] 9: 00002800 0001CB00 'TEE1'
[PART] 10: 00002800 0001F300 'TEE2'
[PART] 11: 00258000 00021B00 'system'
[PART] 12: 0007D000 00279B00 'cache'
[PART] 13: 00B994DF 002F6B00 'userdata'
[LIB] HW ENC
[platform_vusb_on] PASS
step A2 : Standard USB Host!
[PLFM] USB cable in
No Battery
[0xE]=0x1005
[TOOL] USB enum timeout (Yes), handshake timeout(Yes)
USB HW reg: index14=0x0
[USBD] USB Full Speed
[TOOL] Enumeration(Start)
[USBD] USB High Speed
[TOOL] Enumeration(End): OK 616ms
[TOOL] : usb listen timeout
[TOOL] <USB> cannot detect tools!
[TOOL] <UART> listen ended, receive size:0!
[TOOL] <UART> wait sync time 150ms->5ms
[TOOL] <UART> receieved data: ()
Device APC domain init setup:
mmc_rpmb_get_wc, mmc_set_part_config done!!
mmc_rpmb_send_command -> req_type=0x1, type=0x2, blks=0x1
mmc_rpmb_send_command -> req_type=0x2, type=0x2, blks=0x1
mmc_rpmb_get_wc, rpmb_req.result=0
[RPMB] RPMB Provisioned
mmc_rpmb_send_command -> req_type=0x1, type=0x4, blks=0x1
mmc_rpmb_send_command -> req_type=0x2, type=0x4, blks=0x1
[RPMB] Valid anti-rollback block exists
[PART] Image with part header
[PART] name : LK
[PART] addr : FFFFFFFFh mode : -1
[PART] size : 409428
[PART] magic: 58881688h
[SECURITY]: Production device
[PART] This is a production device.
[PART] Verifying LK...
[VERIFY_LK] Succeed to pass the LK verification.
[PART] load "3" from 0x0000000001460200 (dev) to 0x81E00000 (mem) [SUCCESS]
[PART] load speed: 2960KB/s, 409428 bytes, 135ms
0:dram_rank_size:40000000
DRAM size is 0x40000000
[PART] Image with part header
[PART] name : TEE
[PART] addr : FFFFFFFFh mode : -1
[PART] size : 1063936
[PART] magic: 58881688h
[PART] load "8" from 0x0000000003960200 (dev) to 0xBFF00000 (mem) [SUCCESS]
[PART] load speed: 74213KB/s, 1063936 bytes, 14ms
[PART] Image with part header
[PART] name : TEE
[PART] addr : FFFFFFFFh mode : -1
[PART] size : 1063936
[PART] magic: 58881688h
[PART] load "8" from 0x0000000003960200 (dev) to 0xB8A00000 (mem) [SUCCESS]
[PART] load speed: 79922KB/s, 1063936 bytes, 13ms
[BLMTEE] sha256 takes 6 (ms) for 1063360 bytes
[BLMTEE] rsa2048 takes 117 (ms)
[BLMTEE] verify pkcs#1 pss: 1 (ms)
[BLMTEE] aes128cbc 9 (ms) for 1063360
[ANTI-ROLLBACK] Processing anti-rollback data
mmc_rpmb_send_command -> req_type=0x1, type=0x4, blks=0x1
mmc_rpmb_send_command -> req_type=0x2, type=0x4, blks=0x1
[ANTI-ROLLBACK] PL: 2 TEE: 3002 LK: 2
[ANTI-ROLLBACK] Checksum validated
[ANTI-ROLLBACK] All checks passed
No Battery
[0xE]=0x1005
hw_set_cc: 450
[0x0]=0x6B
[0x1]=0x6B
[0x2]=0xB2
[0x3]=0xB2
[0x4]=0x8C
[0x5]=0x8C
[0x6]=0x1F
[0x7]=0x1F
[0x8]=0xC
[0x9]=0xC
[0xA]=0x0
[0xB]=0x0
[0xC]=0x1
[0xD]=0x1
[0xE]=0x1005
[0xF]=0x1005
[0x10]=0x0
[0x11]=0x0
[0x12]=0x0
[0x13]=0x0
[0x14]=0x60
[0x15]=0x60
[0x16]=0x0
[0x17]=0x0
[0x18]=0x0
[0x19]=0x0
[0x1A]=0x10
[0x1B]=0x10
[0x1C]=0x0
[0x1D]=0x0
[0x1E]=0x1
[0x1F]=0x1
[0x20]=0x1
[0x21]=0x1
[0x22]=0x0
[0x23]=0x0
[0x24]=0x3
[0x25]=0x3
[0x26]=0x0
[0x27]=0x0
[0x28]=0x21
[0x29]=0x21
[0x2A]=0x14
[0x2B]=0x14
[0x2C]=0x44
[0x2D]=0x44
[0x2E]=0x54
[0x2F]=0x54
[0x30]=0x0
[0x31]=0x0
[0x32]=0x0
[0x33]=0x0
[0x34]=0x0
[0x35]=0x0
[0x36]=0x0
[0x37]=0x0
[0x38]=0x55
[0x39]=0x55
[0x3A]=0x0
hw_set_cc: done
[PLFM] Wait for battery inserted...
pl pmic close pre-chr LED
pl charging en
hw_set_cc: 450
[0x0]=0x7B
[0x1]=0x7B
[0x2]=0xB2
[0x3]=0xB2
[0x4]=0x8C
[0x5]=0x8C
[0x6]=0x1F
[0x7]=0x1F
[0x8]=0xC
[0x9]=0xC
[0xA]=0x0
[0xB]=0x0
[0xC]=0x1
[0xD]=0x1
[0xE]=0x1005
[0xF]=0x1005
[0x10]=0x0
[0x11]=0x0
[0x12]=0x0
[0x13]=0x0
[0x14]=0x60
[0x15]=0x60
[0x16]=0x0
[0x17]=0x0
[0x18]=0x0
[0x19]=0x0
[0x1A]=0x10
[0x1B]=0x10
[0x1C]=0x0
[0x1D]=0x0
[0x1E]=0x1
[0x1F]=0x1
[0x20]=0x1
[0x21]=0x1
[0x22]=0x0
[0x23]=0x0
[0x24]=0x3
[0x25]=0x3
[0x26]=0x0
[0x27]=0x0
[0x28]=0x21
[0x29]=0x21
[0x2A]=0x14
[0x2B]=0x14
[0x2C]=0x4
[0x2D]=0x4
[0x2E]=0x54
[0x2F]=0x54
[0x30]=0x0
[0x31]=0x0
[0x32]=0x0
[0x33]=0x0
[0x34]=0x0
[0x35]=0x0
[0x36]=0x0
[0x37]=0x0
[0x38]=0x55
[0x39]=0x55
[0x3A]=0x0
hw_set_cc: done
[0x0]=0x7B
[0x1]=0x7B
[0x2]=0xB2
[0x3]=0xB2
[0x4]=0x8C
[0x5]=0x8C
[0x6]=0x1F
[0x7]=0x1F
[0x8]=0xC
[0x9]=0xC
[0xA]=0x0
[0xB]=0x0
[0xC]=0x1
[0xD]=0x1
[0xE]=0x1005
[0xF]=0x1005
[0x10]=0x0
[0x11]=0x0
[0x12]=0x0
[0x13]=0x0
[0x14]=0x60
[0x15]=0x60
[0x16]=0x0
[0x17]=0x0
[0x18]=0x0
[0x19]=0x0
[0x1A]=0x10
[0x1B]=0x10
[0x1C]=0x0
[0x1D]=0x0
[0x1E]=0x1
[0x1F]=0x1
[0x20]=0x9
[0x21]=0x9
[0x22]=0x0
[0x23]=0x0
[0x24]=0x3
[0x25]=0x3
[0x26]=0x0
[0x27]=0x0
[0x28]=0x21
[0x29]=0x21
[0x2A]=0x14
[0x2B]=0x14
[0x2C]=0x4
[0x2D]=0x4
[0x2E]=0x54
[0x2F]=0x54
[0x30]=0x0
[0x31]=0x0
[0x32]=0x0
[0x33]=0x0
[0x34]=0x0
[0x35]=0x0
[0x36]=0x0
[0x37]=0x0
[0x38]=0x55
[0x39]=0x55
[0x3A]=0x0
pl charging done
No Battery
[0xE]=0x1005
No Battery
[0xE]=0x1005
Over the next few days, I'll try various boot configurations (holding down buttons, poking various test points, using a "factory cable") and look for differences in the console output. I'll summarize those differences when I've finished the work.
NOTE: When I captured this output, it was after having written some bad data to the NVRAM partition. I believe that explains the initial "[Read Test] fail" messages as well as the later complaint "sram(0xC10C983F) sig mismatch".
---------- Post added at 12:38 AM ---------- Previous post was at 12:21 AM ----------
If anyone has a bricked or broken tablet that they'd be willing to part with, please PM me. I'd like to have at least one more device on which to experiment.
I've been poking and prodding my current device quite a bit already, and I think I may have zapped some part of the power-management curcuitry which charges the battery. (Pro tip: remember to unplug the USB cable before applying an alcohol-soaked Q-tip to the board.)
I've already found lots of test points hiding on the motherboard, but it's almost impossible to see where they're going. I'd like to use a hot-air rework station and remove the big chips so I can get to the solder pads.
serial console: no soldering!
In reading threads about other phones and tablets, I somewhere ran across a mention that perhaps the USB port can be used directly as the console. After a bit of experimentation, I got that to work on the Fire.
Code:
TTL USB A/B USB MINI/MICRO
SIGNAL PORT PIN PORT PIN
--------- --------- ---------------
+5V 1 1
RX 2 2
TX 3 3
NC 4
GND 5 4
I verified that this works with three USB/serial chipsets: FT232RL, PL-2302/X, and CP2102.
fully bricked output
Great find noelcragg!
I dumped the output of my fire that I bricked trying to downgrade, through the usb serial port.
Code:
CC¡¨HhU5%Õ‘‘É遂ÂÙ±²…±Õ•…™Ñ•É遺jj¤Ô¨HhU5%Õ‘‘É遂ÂÉÉb²…±Õ•é€‚jj¤Ô¨HhU5%Õ‘‘É遂ÂÉÉb²…±Õ•…™Ñ•É遒jj¤Ô¨HhU5%ÕE‹K—‚ÂÙáb²…±Õ•éÂjj¤Ô¨HhU5%Õ‘‘É遂ÂÙáb²…±Õ•…™Ñ•ÉéÂjj¤Ô¨HhU5%Õ‘‘É遂ÂÙ±²…±Õ•é¢jj¤Ô¨HhU5%Õ‘‘É遂ÂÙ±²…±Õ•…™Ñ•É遢jj¤ü
[USB]addr: 0x11002090 (UART1), value: 0
[USB]addr: 0x11002090 (UART1), value after: 1
Platform initialization is ok
wait for frequency meter finish, CLK26CALI = 0x81
mt_pll_post_init: mt_get_cpu_freq = 1040000Khz
wait for frequency meter finish, CLK26CALI = 0x90
mt_pll_post_init: mt_get_bus_freq = 273000Khz
wait for frequency meter finish, CLK26CALI = 0x81
mt_pll_post_init: mt_get_mem_freq = 333251Khz
[PWRAP] pwrap_init_preloader
[PWRAP] pwrap_init
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=0,rdata=2D50
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=1 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=2 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=3 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=4 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=5 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=6 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=7 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=8,rdata=5885
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=9,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=10,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=11,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=12,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=13,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=14,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=15,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=16,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=17,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=18,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=19,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=20,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=21,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=22,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=23,rdata=6A97
[PWRAP] _pwrap_init_reg_clock
[PMIC_WRAP]wrap_init pass,the return value=0.
[pmic6323_init] Preloader Start..................
[pmic6323_init] PMIC CHIP Code = 0x2023
INT_MISC_CON: 1 TOP_RST_MISC: 1
pl pmic powerkey Release
[pmic6323_init] powerKey = 0
[pmic6323_init] is USB in = 0xB003
[pmic6323_init] Reg[0x11A]=0x1B
[pmic6323_init] Done...................
[PLFM] Init I2C: OK(0)
[PLFM] Init PWRAP: OK(0)
[PLFM] Init PMIC: OK(0)
[PLFM] chip[CA00]
[BLDR] Build Time: 20150730-164940
€€€€ €€ € €€ €€ ==== Dump RGU Reg ========
RGU MODE: 55
RGU LENGTH: FFE0
RGU STA: A0000000
RGU INTERVAL: FFF
RGU SWSYSRST: 0
==== Dump RGU Reg End ====
RGU: g_rgu_satus:5
mtk_wdt_mode_config mode value=10, tmp:22000010
PL RGU RST: ??
SW reset with bypass power key flag
Find bypass powerkey flag
mtk_wdt_mode_config mode value=5D, tmp:2200005D
RGU mtk_wdt_init:MTK_WDT_DEBUG_CTL(590200F3)
kpd read addr: 0x0040: data:0x4001
Enter mtk_kpd_gpio_set!
kpd debug column : -2147483612, -2147483611, 0, 0, 0, 0, 0, 0
kpd debug row : 0, 0, 0, 0, 0, 0, 0, 0
after set KP enable: KP_SEL = 0x0 !
MTK_PMIC_RST_KEY is used for this project!
[RTC] get_frequency_meter: input=0x0, ouput=5
[RTC] get_frequency_meter: input=0x0, ouput=3967
[RTC] get_frequency_meter: input=0x0, ouput=5
[RTC] get_frequency_meter: input=0x0, ouput=0
[RTC] get_frequency_meter: input=0x0, ouput=0
[RTC] bbpu = 0xD, con = 0x426
[RTC] powerkey1 = 0xA357, powerkey2 = 0x67D2
Writeif_unlock
[RTC] RTC_SPAR0=0x40
rtc_2sec_reboot_check cali=1792
rtc_2sec_stat_clear
[RTC] irqsta = 0x0, pdn1 = 0x0, pdn2 = 0x201, spar0 = 0x40, spar1 = 0x800
[RTC] new_spare0 = 0x0, new_spare1 = 0x1, new_spare2 = 0x1, new_spare3 = 0x1
[RTC] bbpu = 0xD, con = 0x426, cali = 0x700
SW reset with bypass power key flag
SW reset with bypass power key flag
[PLFM] WDT reboot bypass power key!
hw_set_cc: 450
[0x0]=0x7B
[0x1]=0x7B
[0x2]=0xB2
[0x3]=0xB2
[0x4]=0x8C
[0x5]=0x8C
[0x6]=0x1F
[0x7]=0x1F
[0x8]=0xC
[0x9]=0xC
[0xA]=0x0
[0xB]=0x0
[0xC]=0x1
[0xD]=0x1
[0xE]=0x1
[0xF]=0x1
[0x10]=0x0
[0x11]=0x0
[0x12]=0x0
[0x13]=0x0
[0x14]=0x60
[0x15]=0x60
[0x16]=0x0
[0x17]=0x0
[0x18]=0x0
[0x19]=0x0
[0x1A]=0x10
[0x1B]=0x10
[0x1C]=0x0
[0x1D]=0x0
[0x1E]=0x1
[0x1F]=0x1
[0x20]=0x1
[0x21]=0x1
[0x22]=0x0
[0x23]=0x0
[0x24]=0x0
[0x25]=0x0
[0x26]=0x0
[0x27]=0x0
[0x28]=0x21
[0x29]=0x21
[0x2A]=0x14
[0x2B]=0x14
[0x2C]=0x44
[0x2D]=0x44
[0x2E]=0x54
[0x2F]=0x54
[0x30]=0x0
[0x31]=0x0
[0x32]=0x0
[0x33]=0x0
[0x34]=0x0
[0x35]=0x0
[0x36]=0x0
[0x37]=0x0
[0x38]=0x55
[0x39]=0x55
[0x3A]=0x0
hw_set_cc: done
[RTC] Check SW Long Press RST = 0x40
[RTC] rtc_bbpu_power_on done
[SD0] Bus Width: 1
[SD0] SET_CLK(260kHz): SCLK(259kHz) MODE(0) DDR(0) DIV(193) DS(0) RS(0)
[SD0] Switch to High-Speed mode!
[SD0] SET_CLK(260kHz): SCLK(259kHz) MODE(2) DDR(1) DIV(96) DS(0) RS(0)
[SD0] Bus Width: 8
[SD0] Size: 7456 MB, Max.Speed: 52000 kHz, blklen(512), nblks(15269888), ro(0)
[SD0] Initialized
[SD0] SET_CLK(52000kHz): SCLK(50000kHz) MODE(2) DDR(1) DIV(0) DS(0) RS(0)
msdc_ett_offline_to_pl: size<2> m_id<0x15>
msdc <0> <HYNIX > <8GND3R>
msdc <1> <xxxxxx> <8GND3R>
msdc failed to find
[EMI] mcp_dram_num:0,discrete_dram_num:1,enable_combo_dis:0
mt_get_dram_type() 0x3
[EMI] LPDDR3
[Check]mt_get_mdl_number 0x0
[EMI] eMMC/NAND ID = 15,1,0,38,47,4E,44,33,52,1,CE,17,4F,F4,B2,51
[EMI] MDL number = 0
[EMI] emi_set eMMC/NAND ID = 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0
[EMI][Vcore]0x21E=0x48,0x220=0x48
[EMI][Vmem]0x554=0xF
[EMI] LPDDR3 DRAM Clock = 1333 MHz, MEMPLL MODE = 2
[EMI] PCDDR3 RXTDN Calibration:
Start REXTDN SW calibration...
PD 0x1e4[13]:0h
1.INTREF_SEL:0x100[17:16]:0h
2.enable P drive (initial settings),DRAMC_DLLSEL:500F0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:500F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:510F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:520F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:530F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:540F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:550F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:560F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:570F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:580F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:590F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:5A0F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:5B0F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:5C0F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:5D0F0h
2.2.CMPOT:0x3dc[31]:80000000h
P drive:13
3.INTREF_SEL:0x100[17:16]:0h
4.enable N drive (initial settings),DRAMC_DLLSEL:3D0FFh
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D0FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D1FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D2FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D3FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D4FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D5FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D6FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D7FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D8FFh
4.2
CC¡¨HhU5%Õ‘‘É遂ÂÙ±²…±Õ•…™Ñ•É遺jj¤Ô¨HhU5%ÕE‹K—‚ÂÉÉb²…±Õ•é‚jj¤Ô¨HhU5%Õ‘‘É遂ÂÉÉb²…±Õ•…™Ñ•É遒jh¤Ô¨HhU5%Õ‘‘É遂ÂÙáb²…±Õ•éÂjj¤Ô¨HhU5%Õ‘‘É遂ÂÙáb²…±Õ•…™Ñ•ÉéÂjj¤Ô¨HhU5%Õ‘‘É遂ÂÙ±²…±Õ•é¢jj¤Ô¨HhU5%Õ‘‘É遂ÂÙ±²…±Õ•„™Ñ•É遢jj¤ü
[USB]addr: 0x11002090 (UART1), value: 0
[USB]addr: 0x11002090 (UART1), value after: 1
Platform initialization is ok
wait for frequency meter finish, CLK26CALI = 0x81
mt_pll_post_init: mt_get_cpu_freq = 1040000Khz
wait for frequency meter finish, CLK26CALI = 0x90
mt_pll_post_init: mt_get_bus_freq = 273000Khz
wait for frequency meter finish, CLK26CALI = 0x81
mt_pll_post_init: mt_get_mem_freq = 333251Khz
[PWRAP] pwrap_init_preloader
[PWRAP] pwrap_init
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=0,rdata=2D52
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=1 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=2 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=3 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=4 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=5 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=6 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=7 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=8 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=9,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=10,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=11,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=12,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=13,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=14,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=15,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=16,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=17,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=18,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=19,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=20,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=21,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=22,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=23,rdata=6A97
[PWRAP] _pwrap_init_reg_clock
[PMIC_WRAP]wrap_init pass,the return value=0.
[pmic6323_init] Preloader Start..................
[pmic6323_init] PMIC CHIP Code = 0x2023
INT_MISC_CON: 1 TOP_RST_MISC: 1
pl pmic powerkey Release
[pmic6323_init] powerKey = 0
[pmic6323_init] is USB in = 0xB003
[pmic6323_init] Reg[0x11A]=0x1B
[pmic6323_init] Done...................
[PLFM] Init I2C: OK(0)
[PLFM] Init PWRAP: OK(0)
[PLFM] Init PMIC: OK(0)
[PLFM] chip[CA00]
[BLDR] Build Time: 20150730-164940
€€€€ €€ € €€ €€ ==== Dump RGU Reg ========
RGU MODE: 55
RGU LENGTH: FFE0
RGU STA: A0000000
RGU INTERVAL: FFF
RGU SWSYSRST: 0
==== Dump RGU Reg End ====
RGU: g_rgu_satus:5
mtk_wdt_mode_config mode value=10, tmp:22000010
PL RGU RST: ??
SW reset with bypass power key flag
Find bypass powerkey flag
mtk_wdt_mode_config mode value=5D, tmp:2200005D
RGU mtk_wdt_init:MTK_WDT_DEBUG_CTL(590200F3)
kpd read addr: 0x0040: data:0x4001
Enter mtk_kpd_gpio_set!
kpd debug column : -2147483612, -2147483611, 0, 0, 0, 0, 0, 0
kpd debug row : 0, 0, 0, 0, 0, 0, 0, 0
after set KP enable: KP_SEL = 0x0 !
MTK_PMIC_RST_KEY is used for this project!
[RTC] get_frequency_meter: input=0x0, ouput=5
[RTC] get_frequency_meter: input=0x0, ouput=3968
[RTC] get_frequency_meter: input=0x0, ouput=5
[RTC] get_frequency_meter: input=0x0, ouput=0
[RTC] get_frequency_meter: input=0x0, ouput=0
[RTC] bbpu = 0xD, con = 0x426
[RTC] powerkey1 = 0xA357, powerkey2 = 0x67D2
Writeif_unlock
[RTC] RTC_SPAR0=0x40
rtc_2sec_reboot_check cali=1792
rtc_2sec_stat_clear
[RTC] irqsta = 0x0, pdn1 = 0x0, pdn2 = 0x201, spar0 = 0x40, spar1 = 0x800
[RTC] new_spare0 = 0x0, new_spare1 = 0x1, new_spare2 = 0x1, new_spare3 = 0x1
[RTC] bbpu = 0xD, con = 0x426, cali = 0x700
SW reset with bypass power key flag
SW reset with bypass power key flag
[PLFM] WDT reboot bypass power key!
hw_set_cc: 450
[0x0]=0x7B
[0x1]=0x7B
[0x2]=0xB2
[0x3]=0xB2
[0x4]=0x8C
[0x5]=0x8C
[0x6]=0x1F
[0x7]=0x1F
[0x8]=0xC
[0x9]=0xC
[0xA]=0x0
[0xB]=0x0
[0xC]=0x1
[0xD]=0x1
[0xE]=0x1
[0xF]=0x1
[0x10]=0x0
[0x11]=0x0
[0x12]=0x0
[0x13]=0x0
[0x14]=0x60
[0x15]=0x60
[0x16]=0x0
[0x17]=0x0
[0x18]=0x0
[0x19]=0x0
[0x1A]=0x10
[0x1B]=0x10
[0x1C]=0x0
[0x1D]=0x0
[0x1E]=0x1
[0x1F]=0x1
[0x20]=0x1
[0x21]=0x1
[0x22]=0x0
[0x23]=0x0
[0x24]=0x0
[0x25]=0x0
[0x26]=0x0
[0x27]=0x0
[0x28]=0x21
[0x29]=0x21
[0x2A]=0x14
[0x2B]=0x14
[0x2C]=0x44
[0x2D]=0x44
[0x2E]=0x54
[0x2F]=0x54
[0x30]=0x0
[0x31]=0x0
[0x32]=0x0
[0x33]=0x0
[0x34]=0x0
[0x35]=0x0
[0x36]=0x0
[0x37]=0x0
[0x38]=0x55
[0x39]=0x55
[0x3A]=0x0
hw_set_cc: done
[RTC] Check SW Long Press RST = 0x40
[RTC] rtc_bbpu_power_on done
[SD0] Bus Width: 1
[SD0] SET_CLK(260kHz): SCLK(259kHz) MODE(0) DDR(0) DIV(193) DS(0) RS(0)
[SD0] Switch to High-Speed mode!
[SD0] SET_CLK(260kHz): SCLK(259kHz) MODE(2) DDR(1) DIV(96) DS(0) RS(0)
[SD0] Bus Width: 8
[SD0] Size: 7456 MB, Max.Speed: 52000 kHz, blklen(512), nblks(15269888), ro(0)
[SD0] Initialized
[SD0] SET_CLK(52000kHz): SCLK(50000kHz) MODE(2) DDR(1) DIV(0) DS(0) RS(0)
msdc_ett_offline_to_pl: size<2> m_id<0x15>
msdc <0> <HYNIX > <8GND3R>
msdc <1> <xxxxxx> <8GND3R>
msdc failed to find
[EMI] mcp_dram_num:0,discrete_dram_num:1,enable_combo_dis:0
mt_get_dram_type() 0x3
[EMI] LPDDR3
[Check]mt_get_mdl_number 0x0
[EMI] eMMC/NAND ID = 15,1,0,38,47,4E,44,33,52,1,CE,17,4F,F4,B2,51
[EMI] MDL number = 0
[EMI] emi_set eMMC/NAND ID = 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0
[EMI][Vcore]0x21E=0x48,0x220=0x48
[EMI][Vmem]0x554=0xF
[EMI] LPDDR3 DRAM Clock = 1333 MHz, MEMPLL MODE = 2
[EMI] PCDDR3 RXTDN Calibration:
Start REXTDN SW calibration...
PD 0x1e4[13]:0h
1.INTREF_SEL:0x100[17:16]:0h
2.enable P drive (initial settings),DRAMC_DLLSEL:500F0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:500F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:510F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:520F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:530F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:540F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:550F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:560F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:570F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:580F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:590F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:5A0F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:5B0F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:5C0F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:5D0F0h
2.2.CMPOT:0x3dc[31]:80000000h
P drive:13
3.INTREF_SEL:0x100[17:16]:0h
4.enable N drive (initial settings),DRAMC_DLLSEL:3D0FFh
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D0FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D1FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D2FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D3FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D4FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D5FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D6FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D7FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D8FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D9FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3DAFFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3DBFFh
4.2.CMPOT:0x3dc[31]:0h
N drive:10
drvp=0xD,drvn=0xA
=============================================
X-axis: DQS Gating Window Delay (Fine Scale)
Y-axis: DQS Gating Window Delay (Coarse Scale)
=============================================
0 8 16 24 32 40 48 56 64 72 80 88 96 104 112 120
--------------------------------------------------------------------------------
0006:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0007:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0008:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0009:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
000A:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
000B:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
000C:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
000D:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
000E:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
000F:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0010:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0011:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0012:| 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1
0013:| 0 0 0 0 0 0 1 1 1 1 1 1 1 1 1 1
0014:| 0 1 1 1 1 1 1 1 1 1 1 1 1 0 0 0
0015:| 1 1 1 1 1 1 0 0 0 0 0 0 0 0 0 0
0016:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Rank 12 coarse tune value selection : 32,
20
56
rank 0 coarse = 20
rank 0 fine = 56
00:| 0 0 0 0 1 1 1 0
opt_dle value:9
[EMI]warning:rank auto detect:==single rank==
Change CMD/ADDR output delay = 15
Change CLK output delay = 15
20
64
Change CMD/ADDR output delay = 14
Change CLK output delay = 14
20
64
Change CMD/ADDR output delay = 0
Change CLK output delay = 0
20
48
byte:0, (DQS,DQ)=(8,8)
byte:1, (DQS,DQ)=(8,8)
byte:2, (DQS,DQ)=(8,7)
byte:3, (DQS,DQ)=(8,8)
[EMI] DRAMC calibration passed
[MEM] complex R/W mem test pass
0:dram_rank_size:40000000
[Dram_Buffer] dram size:1073741824
[Dram_Buffer] structure size: 1557624
[Dram_Buffer] MAX_TEE_DRAM_SIZE: 268435456
E~ sram(0x25007E45) sig mismatch
RAM_CONSOLE start: 0x83F00000, size: 0x4000
RAM_CONSOLE preloader last status: 0x0 0x0 0x0
RAM_CONSOLE wdt status (0x5)=0x5
[PLFM] Init Boot Device: OK(0)
Enter mtk_kpd_gpio_set!
kpd debug column : -2147483612, -2147483611, 0, 0, 0, 0, 0, 0
kpd debug row : 0, 0, 0, 0, 0, 0, 0, 0
[PART] GPT dump
[PART] 1: 00000800 00000800 'KB'
[PART] 2: 00000800 00001000 'DKB'
[PART] 3: 00008B00 00001800 'EXPDB'
[PART] 4: 00000800 0000A300 'UBOOT'
[PART] 5: 00008000 0000AB00 'boot'
[PART] 6: 00008000 00012B00 'recovery'
[PART] 7: 00000400 0001AB00 'MISC'
[PART] 8: 00001C00 0001AF00 'LOGO'
[PART] 9: 00002800 0001CB00 'TEE1'
[PART] 10: 00002800 0001F300 'TEE2'
[PART] 11: 00258000 00021B00 'system'
[PART] 12: 0007D000 00279B00 'cache'
[PART] 13: 00B994DF 002F6B00 'userdata'
[LIB] HW ENC
[platform_vusb_on] PASS
hw_set_cc: 450
[0x0]=0x7B
[0x1]=0x7B
[0x2]=0xB2
[0x3]=0xB2
[0x4]=0x8C
[0x5]=0x8C
[0x6]=0x1F
[0x7]=0x1F
[0x8]=0xC
[0x9]=0xC
[0xA]=0x0
[0xB]=0x0
[0xC]=0x1
[0xD]=0x1
[0xE]=0x1
[0xF]=0x1
[0x10]=0x0
[0x11]=0x0
[0x
[SECURITY]: Production device
[PART] This is a production device.
[PART] Verifying LK...
[VERIFY_LK] Succeed to pass the LK verification.
[PART] load "3" from 0x0000000001460200 (dev) to 0x81E00000 (mem) [SUCCESS]
[PART] load speed: 2917KB/s, 406452 bytes, 136ms
0:dram_rank_size:40000000
DRAM size is 0x40000000
[PART] Image with part header
[PART] name : TEE
[PART] addr : FFFFFFFFh mode : -1
[PART] size : 1063936
[PART] magic: 58881688h
[PART] load "8" from 0x0000000003960200 (dev) to 0xBFF00000 (mem) [SUCCESS]
[PART] load speed: 79922KB/s, 1063936 bytes, 13ms
[PART] Image with part header
[PART] name : TEE
[PART] addr : FFFFFFFFh mode : -1
[PART] size : 1063936
[PART] magic: 58881688h
[PART] load "8" from 0x0000000003960200 (dev) to 0xB8A00000 (mem) [SUCCESS]
[PART] load speed: 74213KB/s, 1063936 bytes, 14ms
[BLMTEE] sha256 takes 6 (ms) for 1063360 bytes
[BLMTEE] rsa2048 takes 118 (ms)
[BLMTEE] verify pkcs#1 pss: 0 (ms)
[BLMTEE] aes128cbc 8 (ms) for 1063360
[ANTI-ROLLBACK] Processing anti-rollback data
mmc_rpmb_send_command -> req_type=0x1, type=0x4, blks=0x1
mmc_rpmb_send_command -> req_type=0x2, type=0x4, blks=0x1
[ANTI-ROLLBACK] PL: 2 TEE: 3002 LK: 3
[ANTI-ROLLBACK] Checksum validated
[ANTI-ROLLBACK] LK version mismatch!
[ANTI-ROLLBACK] L: 3 R: 2
picture of usb-serial connected to micro usb plug
For those who are more visually-oriented, I've attached a picture showing the attachment of a FT232RL USB-to-TTL-Serial adapter to a 5-pin micro USB plug.
flaming_goat said:
Great find noelcragg!
I dumped the output of my fire that I bricked trying to downgrade, through the usb serial port.
Code:
CC¡¨HhU5%Õ‘‘É遂ÂÙ±²…±Õ•…™Ñ•É遺jj¤Ô¨HhU5%Õ‘‘É遂ÂÉÉb²…±Õ•é€‚jj¤Ô¨HhU5%Õ‘‘É遂ÂÉÉb²…±Õ•…™Ñ•É遒jj¤Ô¨HhU5%ÕE‹K—‚ÂÙáb²…±Õ•éÂjj¤Ô¨HhU5%Õ‘‘É遂ÂÙáb²…±Õ•…™Ñ•ÉéÂjj¤Ô¨HhU5%Õ‘‘É遂ÂÙ±²…±Õ•é¢jj¤Ô¨HhU5%Õ‘‘É遂ÂÙ±²…±Õ•…™Ñ•É遢jj¤ü
[USB]addr: 0x11002090 (UART1), value: 0
[USB]addr: 0x11002090 (UART1), value after: 1
Platform initialization is ok
wait for frequency meter finish, CLK26CALI = 0x81
mt_pll_post_init: mt_get_cpu_freq = 1040000Khz
wait for frequency meter finish, CLK26CALI = 0x90
mt_pll_post_init: mt_get_bus_freq = 273000Khz
wait for frequency meter finish, CLK26CALI = 0x81
mt_pll_post_init: mt_get_mem_freq = 333251Khz
[PWRAP] pwrap_init_preloader
[PWRAP] pwrap_init
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=0,rdata=2D50
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=1 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=2 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=3 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=4 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=5 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=6 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=7 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=8,rdata=5885
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=9,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=10,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=11,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=12,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=13,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=14,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=15,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=16,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=17,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=18,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=19,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=20,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=21,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=22,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=23,rdata=6A97
[PWRAP] _pwrap_init_reg_clock
[PMIC_WRAP]wrap_init pass,the return value=0.
[pmic6323_init] Preloader Start..................
[pmic6323_init] PMIC CHIP Code = 0x2023
INT_MISC_CON: 1 TOP_RST_MISC: 1
pl pmic powerkey Release
[pmic6323_init] powerKey = 0
[pmic6323_init] is USB in = 0xB003
[pmic6323_init] Reg[0x11A]=0x1B
[pmic6323_init] Done...................
[PLFM] Init I2C: OK(0)
[PLFM] Init PWRAP: OK(0)
[PLFM] Init PMIC: OK(0)
[PLFM] chip[CA00]
[BLDR] Build Time: 20150730-164940
€€€€ €€ € €€ €€ ==== Dump RGU Reg ========
RGU MODE: 55
RGU LENGTH: FFE0
RGU STA: A0000000
RGU INTERVAL: FFF
RGU SWSYSRST: 0
==== Dump RGU Reg End ====
RGU: g_rgu_satus:5
mtk_wdt_mode_config mode value=10, tmp:22000010
PL RGU RST: ??
SW reset with bypass power key flag
Find bypass powerkey flag
mtk_wdt_mode_config mode value=5D, tmp:2200005D
RGU mtk_wdt_init:MTK_WDT_DEBUG_CTL(590200F3)
kpd read addr: 0x0040: data:0x4001
Enter mtk_kpd_gpio_set!
kpd debug column : -2147483612, -2147483611, 0, 0, 0, 0, 0, 0
kpd debug row : 0, 0, 0, 0, 0, 0, 0, 0
after set KP enable: KP_SEL = 0x0 !
MTK_PMIC_RST_KEY is used for this project!
[RTC] get_frequency_meter: input=0x0, ouput=5
[RTC] get_frequency_meter: input=0x0, ouput=3967
[RTC] get_frequency_meter: input=0x0, ouput=5
[RTC] get_frequency_meter: input=0x0, ouput=0
[RTC] get_frequency_meter: input=0x0, ouput=0
[RTC] bbpu = 0xD, con = 0x426
[RTC] powerkey1 = 0xA357, powerkey2 = 0x67D2
Writeif_unlock
[RTC] RTC_SPAR0=0x40
rtc_2sec_reboot_check cali=1792
rtc_2sec_stat_clear
[RTC] irqsta = 0x0, pdn1 = 0x0, pdn2 = 0x201, spar0 = 0x40, spar1 = 0x800
[RTC] new_spare0 = 0x0, new_spare1 = 0x1, new_spare2 = 0x1, new_spare3 = 0x1
[RTC] bbpu = 0xD, con = 0x426, cali = 0x700
SW reset with bypass power key flag
SW reset with bypass power key flag
[PLFM] WDT reboot bypass power key!
hw_set_cc: 450
[0x0]=0x7B
[0x1]=0x7B
[0x2]=0xB2
[0x3]=0xB2
[0x4]=0x8C
[0x5]=0x8C
[0x6]=0x1F
[0x7]=0x1F
[0x8]=0xC
[0x9]=0xC
[0xA]=0x0
[0xB]=0x0
[0xC]=0x1
[0xD]=0x1
[0xE]=0x1
[0xF]=0x1
[0x10]=0x0
[0x11]=0x0
[0x12]=0x0
[0x13]=0x0
[0x14]=0x60
[0x15]=0x60
[0x16]=0x0
[0x17]=0x0
[0x18]=0x0
[0x19]=0x0
[0x1A]=0x10
[0x1B]=0x10
[0x1C]=0x0
[0x1D]=0x0
[0x1E]=0x1
[0x1F]=0x1
[0x20]=0x1
[0x21]=0x1
[0x22]=0x0
[0x23]=0x0
[0x24]=0x0
[0x25]=0x0
[0x26]=0x0
[0x27]=0x0
[0x28]=0x21
[0x29]=0x21
[0x2A]=0x14
[0x2B]=0x14
[0x2C]=0x44
[0x2D]=0x44
[0x2E]=0x54
[0x2F]=0x54
[0x30]=0x0
[0x31]=0x0
[0x32]=0x0
[0x33]=0x0
[0x34]=0x0
[0x35]=0x0
[0x36]=0x0
[0x37]=0x0
[0x38]=0x55
[0x39]=0x55
[0x3A]=0x0
hw_set_cc: done
[RTC] Check SW Long Press RST = 0x40
[RTC] rtc_bbpu_power_on done
[SD0] Bus Width: 1
[SD0] SET_CLK(260kHz): SCLK(259kHz) MODE(0) DDR(0) DIV(193) DS(0) RS(0)
[SD0] Switch to High-Speed mode!
[SD0] SET_CLK(260kHz): SCLK(259kHz) MODE(2) DDR(1) DIV(96) DS(0) RS(0)
[SD0] Bus Width: 8
[SD0] Size: 7456 MB, Max.Speed: 52000 kHz, blklen(512), nblks(15269888), ro(0)
[SD0] Initialized
[SD0] SET_CLK(52000kHz): SCLK(50000kHz) MODE(2) DDR(1) DIV(0) DS(0) RS(0)
msdc_ett_offline_to_pl: size<2> m_id<0x15>
msdc <0> <HYNIX > <8GND3R>
msdc <1> <xxxxxx> <8GND3R>
msdc failed to find
[EMI] mcp_dram_num:0,discrete_dram_num:1,enable_combo_dis:0
mt_get_dram_type() 0x3
[EMI] LPDDR3
[Check]mt_get_mdl_number 0x0
[EMI] eMMC/NAND ID = 15,1,0,38,47,4E,44,33,52,1,CE,17,4F,F4,B2,51
[EMI] MDL number = 0
[EMI] emi_set eMMC/NAND ID = 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0
[EMI][Vcore]0x21E=0x48,0x220=0x48
[EMI][Vmem]0x554=0xF
[EMI] LPDDR3 DRAM Clock = 1333 MHz, MEMPLL MODE = 2
[EMI] PCDDR3 RXTDN Calibration:
Start REXTDN SW calibration...
PD 0x1e4[13]:0h
1.INTREF_SEL:0x100[17:16]:0h
2.enable P drive (initial settings),DRAMC_DLLSEL:500F0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:500F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:510F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:520F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:530F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:540F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:550F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:560F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:570F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:580F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:590F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:5A0F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:5B0F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:5C0F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:5D0F0h
2.2.CMPOT:0x3dc[31]:80000000h
P drive:13
3.INTREF_SEL:0x100[17:16]:0h
4.enable N drive (initial settings),DRAMC_DLLSEL:3D0FFh
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D0FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D1FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D2FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D3FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D4FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D5FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D6FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D7FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D8FFh
4.2
CC¡¨HhU5%Õ‘‘É遂ÂÙ±²…±Õ•…™Ñ•É遺jj¤Ô¨HhU5%ÕE‹K—‚ÂÉÉb²…±Õ•é‚jj¤Ô¨HhU5%Õ‘‘É遂ÂÉÉb²…±Õ•…™Ñ•É遒jh¤Ô¨HhU5%Õ‘‘É遂ÂÙáb²…±Õ•éÂjj¤Ô¨HhU5%Õ‘‘É遂ÂÙáb²…±Õ•…™Ñ•ÉéÂjj¤Ô¨HhU5%Õ‘‘É遂ÂÙ±²…±Õ•é¢jj¤Ô¨HhU5%Õ‘‘É遂ÂÙ±²…±Õ•„™Ñ•É遢jj¤ü
[USB]addr: 0x11002090 (UART1), value: 0
[USB]addr: 0x11002090 (UART1), value after: 1
Platform initialization is ok
wait for frequency meter finish, CLK26CALI = 0x81
mt_pll_post_init: mt_get_cpu_freq = 1040000Khz
wait for frequency meter finish, CLK26CALI = 0x90
mt_pll_post_init: mt_get_bus_freq = 273000Khz
wait for frequency meter finish, CLK26CALI = 0x81
mt_pll_post_init: mt_get_mem_freq = 333251Khz
[PWRAP] pwrap_init_preloader
[PWRAP] pwrap_init
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=0,rdata=2D52
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=1 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=2 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=3 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=4 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=5 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=6 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=7 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] pass,index=8 rdata=5AA5
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=9,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=10,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=11,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=12,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=13,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=14,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=15,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=16,rdata=B54B
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=17,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=18,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=19,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=20,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=21,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=22,rdata=6A97
[PWRAP] _pwrap_init_sistrobe [Read Test] fail,index=23,rdata=6A97
[PWRAP] _pwrap_init_reg_clock
[PMIC_WRAP]wrap_init pass,the return value=0.
[pmic6323_init] Preloader Start..................
[pmic6323_init] PMIC CHIP Code = 0x2023
INT_MISC_CON: 1 TOP_RST_MISC: 1
pl pmic powerkey Release
[pmic6323_init] powerKey = 0
[pmic6323_init] is USB in = 0xB003
[pmic6323_init] Reg[0x11A]=0x1B
[pmic6323_init] Done...................
[PLFM] Init I2C: OK(0)
[PLFM] Init PWRAP: OK(0)
[PLFM] Init PMIC: OK(0)
[PLFM] chip[CA00]
[BLDR] Build Time: 20150730-164940
€€€€ €€ € €€ €€ ==== Dump RGU Reg ========
RGU MODE: 55
RGU LENGTH: FFE0
RGU STA: A0000000
RGU INTERVAL: FFF
RGU SWSYSRST: 0
==== Dump RGU Reg End ====
RGU: g_rgu_satus:5
mtk_wdt_mode_config mode value=10, tmp:22000010
PL RGU RST: ??
SW reset with bypass power key flag
Find bypass powerkey flag
mtk_wdt_mode_config mode value=5D, tmp:2200005D
RGU mtk_wdt_init:MTK_WDT_DEBUG_CTL(590200F3)
kpd read addr: 0x0040: data:0x4001
Enter mtk_kpd_gpio_set!
kpd debug column : -2147483612, -2147483611, 0, 0, 0, 0, 0, 0
kpd debug row : 0, 0, 0, 0, 0, 0, 0, 0
after set KP enable: KP_SEL = 0x0 !
MTK_PMIC_RST_KEY is used for this project!
[RTC] get_frequency_meter: input=0x0, ouput=5
[RTC] get_frequency_meter: input=0x0, ouput=3968
[RTC] get_frequency_meter: input=0x0, ouput=5
[RTC] get_frequency_meter: input=0x0, ouput=0
[RTC] get_frequency_meter: input=0x0, ouput=0
[RTC] bbpu = 0xD, con = 0x426
[RTC] powerkey1 = 0xA357, powerkey2 = 0x67D2
Writeif_unlock
[RTC] RTC_SPAR0=0x40
rtc_2sec_reboot_check cali=1792
rtc_2sec_stat_clear
[RTC] irqsta = 0x0, pdn1 = 0x0, pdn2 = 0x201, spar0 = 0x40, spar1 = 0x800
[RTC] new_spare0 = 0x0, new_spare1 = 0x1, new_spare2 = 0x1, new_spare3 = 0x1
[RTC] bbpu = 0xD, con = 0x426, cali = 0x700
SW reset with bypass power key flag
SW reset with bypass power key flag
[PLFM] WDT reboot bypass power key!
hw_set_cc: 450
[0x0]=0x7B
[0x1]=0x7B
[0x2]=0xB2
[0x3]=0xB2
[0x4]=0x8C
[0x5]=0x8C
[0x6]=0x1F
[0x7]=0x1F
[0x8]=0xC
[0x9]=0xC
[0xA]=0x0
[0xB]=0x0
[0xC]=0x1
[0xD]=0x1
[0xE]=0x1
[0xF]=0x1
[0x10]=0x0
[0x11]=0x0
[0x12]=0x0
[0x13]=0x0
[0x14]=0x60
[0x15]=0x60
[0x16]=0x0
[0x17]=0x0
[0x18]=0x0
[0x19]=0x0
[0x1A]=0x10
[0x1B]=0x10
[0x1C]=0x0
[0x1D]=0x0
[0x1E]=0x1
[0x1F]=0x1
[0x20]=0x1
[0x21]=0x1
[0x22]=0x0
[0x23]=0x0
[0x24]=0x0
[0x25]=0x0
[0x26]=0x0
[0x27]=0x0
[0x28]=0x21
[0x29]=0x21
[0x2A]=0x14
[0x2B]=0x14
[0x2C]=0x44
[0x2D]=0x44
[0x2E]=0x54
[0x2F]=0x54
[0x30]=0x0
[0x31]=0x0
[0x32]=0x0
[0x33]=0x0
[0x34]=0x0
[0x35]=0x0
[0x36]=0x0
[0x37]=0x0
[0x38]=0x55
[0x39]=0x55
[0x3A]=0x0
hw_set_cc: done
[RTC] Check SW Long Press RST = 0x40
[RTC] rtc_bbpu_power_on done
[SD0] Bus Width: 1
[SD0] SET_CLK(260kHz): SCLK(259kHz) MODE(0) DDR(0) DIV(193) DS(0) RS(0)
[SD0] Switch to High-Speed mode!
[SD0] SET_CLK(260kHz): SCLK(259kHz) MODE(2) DDR(1) DIV(96) DS(0) RS(0)
[SD0] Bus Width: 8
[SD0] Size: 7456 MB, Max.Speed: 52000 kHz, blklen(512), nblks(15269888), ro(0)
[SD0] Initialized
[SD0] SET_CLK(52000kHz): SCLK(50000kHz) MODE(2) DDR(1) DIV(0) DS(0) RS(0)
msdc_ett_offline_to_pl: size<2> m_id<0x15>
msdc <0> <HYNIX > <8GND3R>
msdc <1> <xxxxxx> <8GND3R>
msdc failed to find
[EMI] mcp_dram_num:0,discrete_dram_num:1,enable_combo_dis:0
mt_get_dram_type() 0x3
[EMI] LPDDR3
[Check]mt_get_mdl_number 0x0
[EMI] eMMC/NAND ID = 15,1,0,38,47,4E,44,33,52,1,CE,17,4F,F4,B2,51
[EMI] MDL number = 0
[EMI] emi_set eMMC/NAND ID = 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0
[EMI][Vcore]0x21E=0x48,0x220=0x48
[EMI][Vmem]0x554=0xF
[EMI] LPDDR3 DRAM Clock = 1333 MHz, MEMPLL MODE = 2
[EMI] PCDDR3 RXTDN Calibration:
Start REXTDN SW calibration...
PD 0x1e4[13]:0h
1.INTREF_SEL:0x100[17:16]:0h
2.enable P drive (initial settings),DRAMC_DLLSEL:500F0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:500F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:510F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:520F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:530F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:540F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:550F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:560F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:570F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:580F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:590F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:5A0F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:5B0F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:5C0F0h
2.2.CMPOT:0x3dc[31]:0h
2.1.DRAMC_DLLSEL, CMPDRVP 0x0c0[15:12]:5D0F0h
2.2.CMPOT:0x3dc[31]:80000000h
P drive:13
3.INTREF_SEL:0x100[17:16]:0h
4.enable N drive (initial settings),DRAMC_DLLSEL:3D0FFh
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D0FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D1FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D2FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D3FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D4FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D5FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D6FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D7FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D8FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3D9FFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3DAFFh
4.2.CMPOT:0x3dc[31]:80000000h
4.1.DRAMC_DLLSEL, CMPDRVN 0x0c0[11:8]:3DBFFh
4.2.CMPOT:0x3dc[31]:0h
N drive:10
drvp=0xD,drvn=0xA
=============================================
X-axis: DQS Gating Window Delay (Fine Scale)
Y-axis: DQS Gating Window Delay (Coarse Scale)
=============================================
0 8 16 24 32 40 48 56 64 72 80 88 96 104 112 120
--------------------------------------------------------------------------------
0006:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0007:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0008:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0009:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
000A:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
000B:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
000C:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
000D:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
000E:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
000F:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0010:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0011:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0012:| 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1
0013:| 0 0 0 0 0 0 1 1 1 1 1 1 1 1 1 1
0014:| 0 1 1 1 1 1 1 1 1 1 1 1 1 0 0 0
0015:| 1 1 1 1 1 1 0 0 0 0 0 0 0 0 0 0
0016:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Rank 12 coarse tune value selection : 32,
20
56
rank 0 coarse = 20
rank 0 fine = 56
00:| 0 0 0 0 1 1 1 0
opt_dle value:9
[EMI]warning:rank auto detect:==single rank==
Change CMD/ADDR output delay = 15
Change CLK output delay = 15
20
64
Change CMD/ADDR output delay = 14
Change CLK output delay = 14
20
64
Change CMD/ADDR output delay = 0
Change CLK output delay = 0
20
48
byte:0, (DQS,DQ)=(8,8)
byte:1, (DQS,DQ)=(8,8)
byte:2, (DQS,DQ)=(8,7)
byte:3, (DQS,DQ)=(8,8)
[EMI] DRAMC calibration passed
[MEM] complex R/W mem test pass
0:dram_rank_size:40000000
[Dram_Buffer] dram size:1073741824
[Dram_Buffer] structure size: 1557624
[Dram_Buffer] MAX_TEE_DRAM_SIZE: 268435456
E~ sram(0x25007E45) sig mismatch
RAM_CONSOLE start: 0x83F00000, size: 0x4000
RAM_CONSOLE preloader last status: 0x0 0x0 0x0
RAM_CONSOLE wdt status (0x5)=0x5
[PLFM] Init Boot Device: OK(0)
Enter mtk_kpd_gpio_set!
kpd debug column : -2147483612, -2147483611, 0, 0, 0, 0, 0, 0
kpd debug row : 0, 0, 0, 0, 0, 0, 0, 0
[PART] GPT dump
[PART] 1: 00000800 00000800 'KB'
[PART] 2: 00000800 00001000 'DKB'
[PART] 3: 00008B00 00001800 'EXPDB'
[PART] 4: 00000800 0000A300 'UBOOT'
[PART] 5: 00008000 0000AB00 'boot'
[PART] 6: 00008000 00012B00 'recovery'
[PART] 7: 00000400 0001AB00 'MISC'
[PART] 8: 00001C00 0001AF00 'LOGO'
[PART] 9: 00002800 0001CB00 'TEE1'
[PART] 10: 00002800 0001F300 'TEE2'
[PART] 11: 00258000 00021B00 'system'
[PART] 12: 0007D000 00279B00 'cache'
[PART] 13: 00B994DF 002F6B00 'userdata'
[LIB] HW ENC
[platform_vusb_on] PASS
hw_set_cc: 450
[0x0]=0x7B
[0x1]=0x7B
[0x2]=0xB2
[0x3]=0xB2
[0x4]=0x8C
[0x5]=0x8C
[0x6]=0x1F
[0x7]=0x1F
[0x8]=0xC
[0x9]=0xC
[0xA]=0x0
[0xB]=0x0
[0xC]=0x1
[0xD]=0x1
[0xE]=0x1
[0xF]=0x1
[0x10]=0x0
[0x11]=0x0
[0x
[SECURITY]: Production device
[PART] This is a production device.
[PART] Verifying LK...
[VERIFY_LK] Succeed to pass the LK verification.
[PART] load "3" from 0x0000000001460200 (dev) to 0x81E00000 (mem) [SUCCESS]
[PART] load speed: 2917KB/s, 406452 bytes, 136ms
0:dram_rank_size:40000000
DRAM size is 0x40000000
[PART] Image with part header
[PART] name : TEE
[PART] addr : FFFFFFFFh mode : -1
[PART] size : 1063936
[PART] magic: 58881688h
[PART] load "8" from 0x0000000003960200 (dev) to 0xBFF00000 (mem) [SUCCESS]
[PART] load speed: 79922KB/s, 1063936 bytes, 13ms
[PART] Image with part header
[PART] name : TEE
[PART] addr : FFFFFFFFh mode : -1
[PART] size : 1063936
[PART] magic: 58881688h
[PART] load "8" from 0x0000000003960200 (dev) to 0xB8A00000 (mem) [SUCCESS]
[PART] load speed: 74213KB/s, 1063936 bytes, 14ms
[BLMTEE] sha256 takes 6 (ms) for 1063360 bytes
[BLMTEE] rsa2048 takes 118 (ms)
[BLMTEE] verify pkcs#1 pss: 0 (ms)
[BLMTEE] aes128cbc 8 (ms) for 1063360
[ANTI-ROLLBACK] Processing anti-rollback data
mmc_rpmb_send_command -> req_type=0x1, type=0x4, blks=0x1
mmc_rpmb_send_command -> req_type=0x2, type=0x4, blks=0x1
[ANTI-ROLLBACK] PL: 2 TEE: 3002 LK: 3
[ANTI-ROLLBACK] Checksum validated
[ANTI-ROLLBACK] LK version mismatch!
[ANTI-ROLLBACK] L: 3 R: 2
Click to expand...
Click to collapse
anti rollback is the problem with that brick like we all figured but still cool to see it in the output
Is it a lost cause at this point?
Sent from my LG-E980 using XDA-Developers mobile app

Flashing unlock issue, please help (Moto G6)!

Moto G6. My issue short:
Flashing is locked by mistake and I can't unlock it. Also I can't use the operating system because I installed wrong ROM (different region I guess, my SIM card is not recognized). Bootloader is unlocked in official way.
DETAILS
=====
A few years ago when I bought the phone I decided to unlock the bootloader just in case (I was NOT intended to install custom ROM at that time). Unlocking process is described on the official Motorola page. It was like:
Code:
fastboot oem unlock <UNLOCKING_CODE>
I was using Android 8 (didn't install suggested official updates) for all these years. **Once I forgot my PIN and had to wipe the whole data.**
I didn't load the phone with stock ROM (i should've done it and stop experimenting!), but instead I downloaded an official application called "Rescue and Smart Assistance". I followed the instructions and an officical Android 9 ROM has installed on my phone. Everything works, but during the system load I was seeing a banner 'your device has loaded a different operating system'. I decided to go back to Android 8, but it was impossible to do with Rescue and Smart Assistance because the one does not provide old ROM versions, only the latest.
I found an older ROM on the internet and complete flashing. Then I loaded the system, seemed to work well, but I didn't notice my SIM is not recognized. I think it is because I got a ROM for wrong region.
**Accidentally I've locked flashing** via the following command (I wanted to type `oem lock` but it was a long day and I've mistaken):
Code:
fastboot flashing lock
The output was:
Code:
Phone is locked. Rebooting phone.
OKAY [ 0.006s]
Finished. Total time: 0.007s
So... now I can't install any ROM neither from the command line (fastboot flash) nor the "Rescue and Smart Assistance" tool due to permissions.
Flashing recovery from the official stock ROM:
Code:
> fastboot flash recovery .\recovery.img
(bootloader) is-logical:recovery: not found
Sending 'recovery' (22628 KB) OKAY [ 0.711s]
Writing 'recovery' (bootloader) flash permission denied
FAILED (remote: '')
fastboot: error: Command failed
Same for flashing recovery from the TWRP (ofcourse I didn't expect different result, I'm showing it just in case):
Code:
> fastboot flash recovery .\twrp.img
(bootloader) is-logical:recovery: not found
Sending 'recovery' (14748 KB) OKAY [ 0.563s]
Writing 'recovery' (bootloader) flash permission denied
FAILED (remote: '')
fastboot: error: Command failed
The Rescue and Smart Assistance tool also gives me the error: `Flash failed. Please try again`.
Now I try to unlock flashing:
Code:
> fastboot flashing unlock
(bootloader) WARNING: This command erases all user data.
(bootloader) Please re-run this command to continue.
OKAY [ 0.007s]
Finished. Total time: 0.008s
> fastboot flashing unlock
(bootloader) Check 'Allow OEM Unlock' in Android Settings > Developer
(bootloader) Options.
OKAY [ 0.007s]
Finished. Total time: 0.008s
but... I don't have any OS installed. I formatted some directories during these experiments. I believe that I killed ROM and my phone have no OS. Can't remember for sure. I hope this does not really matter.
If I try `fastboot oem unlock` I get the following:
Code:
> fastboot oem unlock
(bootloader) invalid boot state
OKAY [ 0.003s]
Finished. Total time: 0.004s
This `invalid boot state` bothers me.
Please help, what should I do? How to install any ROM? Is it possible to unlock flashing? Can rooting help me? I really need your assistance because my phone is unusable and I'm very limited in options, can't get another device.
P.S. Here is the output of `fastboot getvar all info`:
Code:
(bootloader) version: 0.5
(bootloader) version-bootloader: MBM-2.1-ali_retail-32ffece02ed-200416
(bootloader) product: ali
(bootloader) board: ali
(bootloader) secure: yes
(bootloader) hwrev: PVT2
(bootloader) radio: 4
(bootloader) storage-type: emmc
(bootloader) emmc: 32GB SKHYNIX HBG4a2 RV=08 PV=A5 FV=00000000000000A5
(bootloader) ram: 3GB SKHYNIX LP3 DIE=8Gb M5=06 M6=04 M7=00 M8=5F
(bootloader) cpu: SDM450
(bootloader) serialno: ZY323K7CDR
(bootloader) cid: 0x0032
(bootloader) channelid: 0x00
(bootloader) uid: DEA0D37F00000000000000000000
(bootloader) securestate: flashing_locked
(bootloader) iswarrantyvoid: yes
(bootloader) max-download-size: 534773760
(bootloader) reason: UTAG "bootmode" configured as fastboot
(bootloader) imei: 351865096148177
(bootloader) meid:
(bootloader) date: 12-21-2018
(bootloader) sku: XT1925-5
(bootloader) carrier_sku: XT1925-5
(bootloader) battid: SB18C21114
(bootloader) iccid:
(bootloader) cust_md5:
(bootloader) max-sparse-size: 268435456
(bootloader) current-time: "Mon Mar 7 12: 2:52 UTC 2022"
(bootloader) ro.build.fingerprint[0]: motorola/ali_dteu_n/ali_n:8.0.0/OP
(bootloader) ro.build.fingerprint[1]: SS27.82-72-10/12:user/release-keys
(bootloader) poweroffalarm: 0
(bootloader) ro.build.version.full[0]: Blur_Version.27.281.12.ali_dteu.d
(bootloader) ro.build.version.full[1]: teu.en.US
(bootloader) ro.build.version.qcom: LA.UM.6.6.r1-04400-89xx.0
(bootloader) version-baseband: <not found>
(bootloader) kernel.version[0]: Linux version 3.18.71-perf-gece5c27 (hud
(bootloader) kernel.version[1]: [email protected]) (gcc version 4.9.x 201
(bootloader) kernel.version[2]: 50123 (prerelease) (GCC) ) #1 SMP PREEMP
(bootloader) kernel.version[3]: T Fri Jan 11 06:52:14 CST 2019
(bootloader) sbl1.git: MBM-2.1-ali_retail-0d2031d6b9-200416
(bootloader) rpm.git: MBM-2.1-ali_retail-576a4d4d-200416
(bootloader) tz.git: MBM-2.1-ali_retail-f9b266cd30-200416
(bootloader) devcfg.git: MBM-2.1-ali_retail-f9b266cd30-200416
(bootloader) keymaster.git: MBM-2.1-ali_retail-f9b266cd30-200416
(bootloader) cmnlib.git: MBM-2.1-ali_retail-f9b266cd30-200416
(bootloader) cmnlib64.git: MBM-2.1-ali_retail-f9b266cd30-200416
(bootloader) prov.git: MBM-2.1-ali_retail-f9b266cd30-200416
(bootloader) aboot.git: MBM-2.1-ali_retail-32ffece02ed-200416
(bootloader) frp-state: no protection (0)
(bootloader) ro.carrier: retru
(bootloader) current-slot:
(bootloader) slot-suffixes: _a
(bootloader) slot-count: 1
(bootloader) slot-successful:_a: INVALID
(bootloader) slot-successful:_b: INVALID
(bootloader) slot-bootable:_a: INVALID
(bootloader) slot-bootable:_b: INVALID
(bootloader) slot-retry-count:_a: unknown
(bootloader) slot-retry-count:_b: unknown
UPD 1. Looks like my device is locked.
Code:
> fastboot oem lock
(bootloader) Not in unlocked state
As I described above, `fastboot oem unlocking` throws the error: INVALID BOOT STATE. I believe fixing this will fix my original issue.
UPD 2. Is there a way to force flash unlocking with root? I have never dealt with phone rooting before (I use Linux, I know what is root for, but have no experince in phone rooting)
My applogies if the thread title does not match your naming rules. I'm a new member, haven't seen the rules. And I'm very upset about this issue
I loaded TWRP and executed the command: 'adb shell getprop'
Spoiler: OUTPUT
Code:
[dalvik.vm.appimageformat]: [lz4]
[dalvik.vm.dex2oat-Xms]: [64m]
[dalvik.vm.dex2oat-Xmx]: [512m]
[dalvik.vm.dexopt.secondary]: [true]
[dalvik.vm.image-dex2oat-Xms]: [64m]
[dalvik.vm.image-dex2oat-Xmx]: [64m]
[dalvik.vm.image-dex2oat-filter]: [verify-at-runtime]
[dalvik.vm.isa.arm.features]: [default]
[dalvik.vm.isa.arm.variant]: [cortex-a53]
[dalvik.vm.lockprof.threshold]: [500]
[dalvik.vm.stack-trace-dir]: [/data/anr]
[dalvik.vm.usejit]: [true]
[dalvik.vm.usejitprofiles]: [true]
[debug.atrace.tags.enableflags]: [0]
[init.svc.adbd]: [running]
[init.svc.recovery]: [running]
[init.svc.set_permissive]: [stopped]
[init.svc.ueventd]: [running]
[mtp.crash_check]: [0]
[net.bt.name]: [Android]
[persist.sys.dalvik.vm.lib.2]: [libart.so]
[persist.sys.usb.config]: [adb]
[pm.dexopt.ab-ota]: [speed-profile]
[pm.dexopt.bg-dexopt]: [speed-profile]
[pm.dexopt.boot]: [extract]
[pm.dexopt.first-boot]: [extract]
[pm.dexopt.inactive]: [verify]
[pm.dexopt.install]: [quicken]
[pm.dexopt.shared]: [speed]
[ro.allow.mock.location]: [1]
[ro.baseband]: [msm]
[ro.bionic.ld.warning]: [1]
[ro.board.platform]: [msm8953]
[ro.boot.baseband]: [msm]
[ro.boot.bl_state]: [3]
[ro.boot.bootdevice]: [7824900.sdhci]
[ro.boot.bootloader]: [0xC111]
[ro.boot.bootreason]: [reboot]
[ro.boot.btmacaddr]: [58:D9:C3:AD:FF:FF]
[ro.boot.carrier]: [retru]
[ro.boot.cid]: [0x32]
[ro.boot.device]: [ali]
[ro.boot.dualsim]: [true]
[ro.boot.emmc]: [true]
[ro.boot.fsg-id]: []
[ro.boot.hardware.sku]: [XT1925-5]
[ro.boot.hardware]: [qcom]
[ro.boot.hwrev]: [0xC200]
[ro.boot.mode]: [normal]
[ro.boot.poweroff_alarm]: [0]
[ro.boot.powerup_reason]: [0x00004000]
[ro.boot.radio]: [EMEA]
[ro.boot.revision]: [PVT2]
[ro.boot.secure_hardware]: [1]
[ro.boot.selinux]: [permissive]
[ro.boot.serialno]: [ZY323K7CDR]
[ro.boot.ssm_data]: [0000000004012221]
[ro.boot.uid]: [DEA0D37F00000000000000000000]
[ro.boot.verifiedbootstate]: [yellow]
[ro.boot.veritymode]: [enforcing]
[ro.boot.wifimacaddr]: [58:D9:C3:AE:00:00,58:D9:C3:AE:00:01]
[ro.boot.write_protect]: [0]
[ro.bootimage.build.date.utc]: [1637675079]
[ro.bootimage.build.date]: [Tue Nov 23 13:44:39 UTC 2021]
[ro.bootimage.build.fingerprint]: [motorola/omni_ali/ali:16.1.0/OPM8.181105.002/13:eng/test-keys]
[ro.bootloader]: [0xC111]
[ro.bootmode]: [normal]
[ro.boottime.adbd]: [3723307400]
[ro.boottime.init.cold_boot_wait]: [181]
[ro.boottime.init.selinux]: [96]
[ro.boottime.init]: [3412]
[ro.boottime.recovery]: [3722559535]
[ro.boottime.set_permissive]: [3722034535]
[ro.boottime.ueventd]: [3528207797]
[ro.build.characteristics]: [default]
[ro.build.date.utc]: [1637675079]
[ro.build.date]: [Tue Nov 23 13:44:39 UTC 2021]
[ro.build.description]: [omni_ali-eng 16.1.0 OPM8.181105.002 13 test-keys]
[ro.build.display.id]: [omni_ali-eng 16.1.0 OPM8.181105.002 13 test-keys]
[ro.build.fingerprint]: [motorola/omni_ali/ali:16.1.0/OPM8.181105.002/13:eng/test-keys]
[ro.build.flavor]: [omni_ali-eng]
[ro.build.host]: [88e37ef12c29]
[ro.build.id]: [OPM8.181105.002]
[ro.build.product]: [ali]
[ro.build.tags]: [test-keys]
[ro.build.type]: [eng]
[ro.build.user]: [jenkins]
[ro.build.version.all_codenames]: [REL]
[ro.build.version.base_os]: []
[ro.build.version.codename]: [REL]
[ro.build.version.incremental]: [13]
[ro.build.version.preview_sdk]: [0]
[ro.build.version.release_orig]: [16.1.0]
[ro.build.version.sdk]: [27]
[ro.build.version.security_patch_orig]: [2018-11-05]
[ro.carrier]: [unknown]
[ro.dalvik.vm.native.bridge]: [0]
[ro.debuggable]: [1]
[ro.hardware]: [qcom]
[ro.kernel.android.checkjni]: [1]
[ro.omni.device]: [ali]
[ro.persistent_properties.ready]: [true]
[ro.product.board]: [msm8953]
[ro.product.brand]: [motorola]
[ro.product.cpu.abi2]: [armeabi]
[ro.product.cpu.abi]: [armeabi-v7a]
[ro.product.cpu.abilist32]: [armeabi-v7a,armeabi]
[ro.product.cpu.abilist64]: []
[ro.product.cpu.abilist]: [armeabi-v7a,armeabi]
[ro.product.device]: [ali]
[ro.product.locale]: [en-US]
[ro.product.manufacturer]: [motorola]
[ro.product.model]: [moto g(6)]
[ro.product.name]: [omni_ali]
[ro.property_service.version]: [2]
[ro.recovery_id]: [0x49da0aff147082b138eeb5242292f812d64d2cb4000000000000000000000000]
[ro.revision]: [PVT2]
[ro.secure]: [0]
[ro.serialno]: [ZY323K7CDR]
[ro.treble.enabled]: [false]
[ro.twrp.boot]: [1]
[ro.twrp.sar]: [false]
[ro.twrp.version]: [3.6.0_9-0]
[ro.vendor.product.brand]: [motorola]
[ro.vendor.product.device]: [ali]
[ro.vendor.product.manufacturer]: [motorola]
[ro.vendor.product.model]: [moto g(6)]
[ro.vendor.product.name]: [omni_ali]
[ro.wifi.channels]: []
[ro.zygote]: [zygote32]
[service.adb.root]: [1]
[sys.usb.config]: [mtp,adb]
[sys.usb.controller]: [7000000.dwc3]
[sys.usb.ffs.ready]: [1]
[tombstoned.max_tombstone_count]: [50]
[twrp.action_complete]: [0]
[twrp.crash_counter]: [0]
Some people told me that my bootloader might be replaced. And it is! When I flashed a ROM I also flashed the bootloader.img file. I found a screenshot of my bootloader before changes and compared it to current bootloader info. They don't match.
Suggested solution: blankflash. I don't know how exactly it works, going to google.
I found this video which is helped me to flash an official ROM through TWRP:
I don't know how TWRP operates internally, but the facts are:
1) I have locked flashing, fastboot flash occurs 'permission denied'
2) TWRP has sucessfully flashed ROM (you need a Linux script to convert a ROM from lolinet.com to a bootable images)
I still have the message 'your device has loaded a different operating system', but at least my device is loading!
Now I need to fix lost IMEI data.
In order to fix IMEI and baseband I need to FLASH files, which is still impossible for me due to locked flashing.
Spoiler
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
So, as far as I understand, I need to find a way to fix accidentally replaced bootloader.img and unlock flashing. Have no idea how to do it right know (probably blankflash?). I keep googling it...
I rebooted the phone and tried to execute 'fastboot flashing unlock' and it has unlocked! Amazing! Now I can flash files with the fastboot utility.
That was a great journey. Glad it worked for you.
I've solved my problem. My solution is:
1. Download firmware for my device from https://mirrors.lolinet.com/firmware/moto/ali/
2. Download a script attached to the video (
). I attached the script in case the video will be unavailable. You have to use Linux OS and build the program for converting chunks into bootable images (https://github.com/anestisb/android-simg2img)
3. Convert chunks into bootable images
4. Boot TWRP recovery
5. Follow instructions from the video above
6. Now I have OS. Load it, enable OEM Unlocking and USB Debugging
7. Reboot into the bootloader. Execture 'fastboot flashing unlock'. Now it is working!
8. Run Rescue and Smart Assistance tool and flash a ROM suggested by the tool
9. Be happy! Now you have a working phone with latest official ROM and modem (IMEI)
katoomba32 said:
I've solved my problem. My solution is:
1. Download firmware for my device from https://mirrors.lolinet.com/firmware/moto/ali/
2. Download a script attached to the video (
). I attached the script in case the video will be unavailable. You have to use Linux OS and build the program for converting chunks into bootable images (https://github.com/anestisb/android-simg2img)
3. Convert chunks into bootable images
4. Boot TWRP recovery
5. Follow instructions from the video above
6. Now I have OS. Load it, enable OEM Unlocking and USB Debugging
7. Reboot into the bootloader. Execture 'fastboot flashing unlock'. Now it is working!
8. Run Rescue and Smart Assistance tool and flash a ROM suggested by the tool
9. Be happy! Now you have a working phone with latest official ROM and modem (IMEI)
Click to expand...
Click to collapse
bro in step 1 can i download the ofiicial firmware from any other place, cause i have this same issue on my moto g5s plus
katoomba32 said:
Moto G6. My issue short:
Flashing is locked by mistake and I can't unlock it. Also I can't use the operating system because I installed wrong ROM (different region I guess, my SIM card is not recognized). Bootloader is unlocked in official way.
DETAILS
=====
A few years ago when I bought the phone I decided to unlock the bootloader just in case (I was NOT intended to install custom ROM at that time). Unlocking process is described on the official Motorola page. It was like:
Code:
fastboot oem unlock <UNLOCKING_CODE>
I was using Android 8 (didn't install suggested official updates) for all these years. **Once I forgot my PIN and had to wipe the whole data.**
I didn't load the phone with stock ROM (i should've done it and stop experimenting!), but instead I downloaded an official application called "Rescue and Smart Assistance". I followed the instructions and an officical Android 9 ROM has installed on my phone. Everything works, but during the system load I was seeing a banner 'your device has loaded a different operating system'. I decided to go back to Android 8, but it was impossible to do with Rescue and Smart Assistance because the one does not provide old ROM versions, only the latest.
I found an older ROM on the internet and complete flashing. Then I loaded the system, seemed to work well, but I didn't notice my SIM is not recognized. I think it is because I got a ROM for wrong region.
**Accidentally I've locked flashing** via the following command (I wanted to type `oem lock` but it was a long day and I've mistaken):
Code:
fastboot flashing lock
The output was:
Code:
Phone is locked. Rebooting phone.
OKAY [ 0.006s]
Finished. Total time: 0.007s
So... now I can't install any ROM neither from the command line (fastboot flash) nor the "Rescue and Smart Assistance" tool due to permissions.
Flashing recovery from the official stock ROM:
Code:
> fastboot flash recovery .\recovery.img
(bootloader) is-logical:recovery: not found
Sending 'recovery' (22628 KB) OKAY [ 0.711s]
Writing 'recovery' (bootloader) flash permission denied
FAILED (remote: '')
fastboot: error: Command failed
Same for flashing recovery from the TWRP (ofcourse I didn't expect different result, I'm showing it just in case):
Code:
> fastboot flash recovery .\twrp.img
(bootloader) is-logical:recovery: not found
Sending 'recovery' (14748 KB) OKAY [ 0.563s]
Writing 'recovery' (bootloader) flash permission denied
FAILED (remote: '')
fastboot: error: Command failed
The Rescue and Smart Assistance tool also gives me the error: `Flash failed. Please try again`.
Now I try to unlock flashing:
Code:
> fastboot flashing unlock
(bootloader) WARNING: This command erases all user data.
(bootloader) Please re-run this command to continue.
OKAY [ 0.007s]
Finished. Total time: 0.008s
> fastboot flashing unlock
(bootloader) Check 'Allow OEM Unlock' in Android Settings > Developer
(bootloader) Options.
OKAY [ 0.007s]
Finished. Total time: 0.008s
but... I don't have any OS installed. I formatted some directories during these experiments. I believe that I killed ROM and my phone have no OS. Can't remember for sure. I hope this does not really matter.
If I try `fastboot oem unlock` I get the following:
Code:
> fastboot oem unlock
(bootloader) invalid boot state
OKAY [ 0.003s]
Finished. Total time: 0.004s
This `invalid boot state` bothers me.
Please help, what should I do? How to install any ROM? Is it possible to unlock flashing? Can rooting help me? I really need your assistance because my phone is unusable and I'm very limited in options, can't get another device.
P.S. Here is the output of `fastboot getvar all info`:
Code:
(bootloader) version: 0.5
(bootloader) version-bootloader: MBM-2.1-ali_retail-32ffece02ed-200416
(bootloader) product: ali
(bootloader) board: ali
(bootloader) secure: yes
(bootloader) hwrev: PVT2
(bootloader) radio: 4
(bootloader) storage-type: emmc
(bootloader) emmc: 32GB SKHYNIX HBG4a2 RV=08 PV=A5 FV=00000000000000A5
(bootloader) ram: 3GB SKHYNIX LP3 DIE=8Gb M5=06 M6=04 M7=00 M8=5F
(bootloader) cpu: SDM450
(bootloader) serialno: ZY323K7CDR
(bootloader) cid: 0x0032
(bootloader) channelid: 0x00
(bootloader) uid: DEA0D37F00000000000000000000
(bootloader) securestate: flashing_locked
(bootloader) iswarrantyvoid: yes
(bootloader) max-download-size: 534773760
(bootloader) reason: UTAG "bootmode" configured as fastboot
(bootloader) imei: 351865096148177
(bootloader) meid:
(bootloader) date: 12-21-2018
(bootloader) sku: XT1925-5
(bootloader) carrier_sku: XT1925-5
(bootloader) battid: SB18C21114
(bootloader) iccid:
(bootloader) cust_md5:
(bootloader) max-sparse-size: 268435456
(bootloader) current-time: "Mon Mar 7 12: 2:52 UTC 2022"
(bootloader) ro.build.fingerprint[0]: motorola/ali_dteu_n/ali_n:8.0.0/OP
(bootloader) ro.build.fingerprint[1]: SS27.82-72-10/12:user/release-keys
(bootloader) poweroffalarm: 0
(bootloader) ro.build.version.full[0]: Blur_Version.27.281.12.ali_dteu.d
(bootloader) ro.build.version.full[1]: teu.en.US
(bootloader) ro.build.version.qcom: LA.UM.6.6.r1-04400-89xx.0
(bootloader) version-baseband: <not found>
(bootloader) kernel.version[0]: Linux version 3.18.71-perf-gece5c27 (hud
(bootloader) kernel.version[1]: [email protected]) (gcc version 4.9.x 201
(bootloader) kernel.version[2]: 50123 (prerelease) (GCC) ) #1 SMP PREEMP
(bootloader) kernel.version[3]: T Fri Jan 11 06:52:14 CST 2019
(bootloader) sbl1.git: MBM-2.1-ali_retail-0d2031d6b9-200416
(bootloader) rpm.git: MBM-2.1-ali_retail-576a4d4d-200416
(bootloader) tz.git: MBM-2.1-ali_retail-f9b266cd30-200416
(bootloader) devcfg.git: MBM-2.1-ali_retail-f9b266cd30-200416
(bootloader) keymaster.git: MBM-2.1-ali_retail-f9b266cd30-200416
(bootloader) cmnlib.git: MBM-2.1-ali_retail-f9b266cd30-200416
(bootloader) cmnlib64.git: MBM-2.1-ali_retail-f9b266cd30-200416
(bootloader) prov.git: MBM-2.1-ali_retail-f9b266cd30-200416
(bootloader) aboot.git: MBM-2.1-ali_retail-32ffece02ed-200416
(bootloader) frp-state: no protection (0)
(bootloader) ro.carrier: retru
(bootloader) current-slot:
(bootloader) slot-suffixes: _a
(bootloader) slot-count: 1
(bootloader) slot-successful:_a: INVALID
(bootloader) slot-successful:_b: INVALID
(bootloader) slot-bootable:_a: INVALID
(bootloader) slot-bootable:_b: INVALID
(bootloader) slot-retry-count:_a: unknown
(bootloader) slot-retry-count:_b: unknown
UPD 1. Looks like my device is locked.
Code:
> fastboot oem lock
(bootloader) Not in unlocked state
As I described above, `fastboot oem unlocking` throws the error: INVALID BOOT STATE. I believe fixing this will fix my original issue.
UPD 2. Is there a way to force flash unlocking with root? I have never dealt with phone rooting before (I use Linux, I know what is root for, but have no experince in phone rooting)
Click to expand...
Click to collapse
wrong place to post
your solution is only:
fastboot flashing unlock
brunogroa said:
wrong place to post
your solution is only:
fastboot flashing unlock
Click to expand...
Click to collapse
It ain't like that.
I also have "flashing_locked" on my fastboot. I can't flash anyhing and I need to check oem for that, but it's grayed out and I have no way to change it.
I have access to system, I also can't boot twrp (by fastboot command), due to "untrusted" message.
In my case, I have no access to twrp recovery, (update), I can access the stock recovery. Any ideas for adb?
In my case, I noticed slot b wasn't flashed (same way for @katoomba32), which made me lose access to wifi and mobile data.
I can have internet access by ethernet usb cable or theter usb/bluetooth. I'm facing this issue for quite a time, and still the oem check still grayed out for me.
so, I need help here: what I can do to fix these things. I have no idea to make my phone to run edl.
I was also looking for boxes to do this job, but the maximum I got so far is the very same thing fastboot does.
katoomba32 said:
I loaded TWRP and executed the command: 'adb shell getprop'
Spoiler: OUTPUT
Code:
[dalvik.vm.appimageformat]: [lz4]
[dalvik.vm.dex2oat-Xms]: [64m]
[dalvik.vm.dex2oat-Xmx]: [512m]
[dalvik.vm.dexopt.secondary]: [true]
[dalvik.vm.image-dex2oat-Xms]: [64m]
[dalvik.vm.image-dex2oat-Xmx]: [64m]
[dalvik.vm.image-dex2oat-filter]: [verify-at-runtime]
[dalvik.vm.isa.arm.features]: [default]
[dalvik.vm.isa.arm.variant]: [cortex-a53]
[dalvik.vm.lockprof.threshold]: [500]
[dalvik.vm.stack-trace-dir]: [/data/anr]
[dalvik.vm.usejit]: [true]
[dalvik.vm.usejitprofiles]: [true]
[debug.atrace.tags.enableflags]: [0]
[init.svc.adbd]: [running]
[init.svc.recovery]: [running]
[init.svc.set_permissive]: [stopped]
[init.svc.ueventd]: [running]
[mtp.crash_check]: [0]
[net.bt.name]: [Android]
[persist.sys.dalvik.vm.lib.2]: [libart.so]
[persist.sys.usb.config]: [adb]
[pm.dexopt.ab-ota]: [speed-profile]
[pm.dexopt.bg-dexopt]: [speed-profile]
[pm.dexopt.boot]: [extract]
[pm.dexopt.first-boot]: [extract]
[pm.dexopt.inactive]: [verify]
[pm.dexopt.install]: [quicken]
[pm.dexopt.shared]: [speed]
[ro.allow.mock.location]: [1]
[ro.baseband]: [msm]
[ro.bionic.ld.warning]: [1]
[ro.board.platform]: [msm8953]
[ro.boot.baseband]: [msm]
[ro.boot.bl_state]: [3]
[ro.boot.bootdevice]: [7824900.sdhci]
[ro.boot.bootloader]: [0xC111]
[ro.boot.bootreason]: [reboot]
[ro.boot.btmacaddr]: [58:D9:C3:AD:FF:FF]
[ro.boot.carrier]: [retru]
[ro.boot.cid]: [0x32]
[ro.boot.device]: [ali]
[ro.boot.dualsim]: [true]
[ro.boot.emmc]: [true]
[ro.boot.fsg-id]: []
[ro.boot.hardware.sku]: [XT1925-5]
[ro.boot.hardware]: [qcom]
[ro.boot.hwrev]: [0xC200]
[ro.boot.mode]: [normal]
[ro.boot.poweroff_alarm]: [0]
[ro.boot.powerup_reason]: [0x00004000]
[ro.boot.radio]: [EMEA]
[ro.boot.revision]: [PVT2]
[ro.boot.secure_hardware]: [1]
[ro.boot.selinux]: [permissive]
[ro.boot.serialno]: [ZY323K7CDR]
[ro.boot.ssm_data]: [0000000004012221]
[ro.boot.uid]: [DEA0D37F00000000000000000000]
[ro.boot.verifiedbootstate]: [yellow]
[ro.boot.veritymode]: [enforcing]
[ro.boot.wifimacaddr]: [58:D9:C3:AE:00:00,58:D9:C3:AE:00:01]
[ro.boot.write_protect]: [0]
[ro.bootimage.build.date.utc]: [1637675079]
[ro.bootimage.build.date]: [Tue Nov 23 13:44:39 UTC 2021]
[ro.bootimage.build.fingerprint]: [motorola/omni_ali/ali:16.1.0/OPM8.181105.002/13:eng/test-keys]
[ro.bootloader]: [0xC111]
[ro.bootmode]: [normal]
[ro.boottime.adbd]: [3723307400]
[ro.boottime.init.cold_boot_wait]: [181]
[ro.boottime.init.selinux]: [96]
[ro.boottime.init]: [3412]
[ro.boottime.recovery]: [3722559535]
[ro.boottime.set_permissive]: [3722034535]
[ro.boottime.ueventd]: [3528207797]
[ro.build.characteristics]: [default]
[ro.build.date.utc]: [1637675079]
[ro.build.date]: [Tue Nov 23 13:44:39 UTC 2021]
[ro.build.description]: [omni_ali-eng 16.1.0 OPM8.181105.002 13 test-keys]
[ro.build.display.id]: [omni_ali-eng 16.1.0 OPM8.181105.002 13 test-keys]
[ro.build.fingerprint]: [motorola/omni_ali/ali:16.1.0/OPM8.181105.002/13:eng/test-keys]
[ro.build.flavor]: [omni_ali-eng]
[ro.build.host]: [88e37ef12c29]
[ro.build.id]: [OPM8.181105.002]
[ro.build.product]: [ali]
[ro.build.tags]: [test-keys]
[ro.build.type]: [eng]
[ro.build.user]: [jenkins]
[ro.build.version.all_codenames]: [REL]
[ro.build.version.base_os]: []
[ro.build.version.codename]: [REL]
[ro.build.version.incremental]: [13]
[ro.build.version.preview_sdk]: [0]
[ro.build.version.release_orig]: [16.1.0]
[ro.build.version.sdk]: [27]
[ro.build.version.security_patch_orig]: [2018-11-05]
[ro.carrier]: [unknown]
[ro.dalvik.vm.native.bridge]: [0]
[ro.debuggable]: [1]
[ro.hardware]: [qcom]
[ro.kernel.android.checkjni]: [1]
[ro.omni.device]: [ali]
[ro.persistent_properties.ready]: [true]
[ro.product.board]: [msm8953]
[ro.product.brand]: [motorola]
[ro.product.cpu.abi2]: [armeabi]
[ro.product.cpu.abi]: [armeabi-v7a]
[ro.product.cpu.abilist32]: [armeabi-v7a,armeabi]
[ro.product.cpu.abilist64]: []
[ro.product.cpu.abilist]: [armeabi-v7a,armeabi]
[ro.product.device]: [ali]
[ro.product.locale]: [en-US]
[ro.product.manufacturer]: [motorola]
[ro.product.model]: [moto g(6)]
[ro.product.name]: [omni_ali]
[ro.property_service.version]: [2]
[ro.recovery_id]: [0x49da0aff147082b138eeb5242292f812d64d2cb4000000000000000000000000]
[ro.revision]: [PVT2]
[ro.secure]: [0]
[ro.serialno]: [ZY323K7CDR]
[ro.treble.enabled]: [false]
[ro.twrp.boot]: [1]
[ro.twrp.sar]: [false]
[ro.twrp.version]: [3.6.0_9-0]
[ro.vendor.product.brand]: [motorola]
[ro.vendor.product.device]: [ali]
[ro.vendor.product.manufacturer]: [motorola]
[ro.vendor.product.model]: [moto g(6)]
[ro.vendor.product.name]: [omni_ali]
[ro.wifi.channels]: []
[ro.zygote]: [zygote32]
[service.adb.root]: [1]
[sys.usb.config]: [mtp,adb]
[sys.usb.controller]: [7000000.dwc3]
[sys.usb.ffs.ready]: [1]
[tombstoned.max_tombstone_count]: [50]
[twrp.action_complete]: [0]
[twrp.crash_counter]: [0]
Click to expand...
Click to collapse
How you were able to run twrp after you said you couldn't flash it?
How did you erase your system?
Do I need to erase my system to try your solution?
Galoso said:
It ain't like that.
I also have "flashing_locked" on my fastboot. I can't flash anyhing and I need to check oem for that, but it's grayed out and I have no way to change it.
I have access to system, I also can't boot twrp (by fastboot command), due to "untrusted" message.
In my case, I have no access to twrp recovery, (update), I can access the stock recovery. Any ideas for adb?
In my case, I noticed slot b wasn't flashed (same way for @katoomba32), which made me lose access to wifi and mobile data.
I can have internet access by ethernet usb cable or theter usb/bluetooth. I'm facing this issue for quite a time, and still the oem check still grayed out for me.
so, I need help here: what I can do to fix these things. I have no idea to make my phone to run edl.
I was also looking for boxes to do this job, but the maximum I got so far is the very same thing fastboot does.
Click to expand...
Click to collapse
You just need to flash right Stock bro, look on lolinet2 mirrors for the last stock for you region... stock flash without unlock bl
brunogroa said:
You just need to flash right Stock bro, look on lolinet2 mirrors for the last stock for you region... stock flash without unlock bl
Click to expand...
Click to collapse
Bruno, that's the point:
When you do flash lock, that means your device will deny any flash commands. In my case, it asks to check oem unlock (which is grayed, to remember) which is different from oem lock, as far as understood.
Surely, I went to flash by fastboot well-know commands, but no joy at all. Just to remember, flashing unlock command leads to check oem unlock as well.
I still wonder:
which box can save my soul?
is edl for blankflash will save me as well?
brunogroa said:
You just need to flash right Stock bro, look on lolinet2 mirrors for the last stock for you region... stock flash without unlock bl
Click to expand...
Click to collapse
Yes, by the way, I'm on right "evert" device. As I pointed out, the same mistake me and the guy here faced is that we missed to flash b slot. That's why we don't have wifi, baseband, mobile..
Hello.
Got some news:
I am able to run edl mode, but I got stuck at here:
< waiting for device >
[ -0.000] Opening device: \\.\COM3
Detecting device
[ -0.000] ...cpu.id = 172 (0xac)
[ -0.000] ...cpu.sn = 2652300856 (0x9e16e638)
Loading package
Loading programmer
Sending programmer
[ 7.814] ERROR: sahara_download()->general error
FAILED: qb_flash_singleimage()->sahara_download()->general error
I did use blankflash from Lolinet as well Morotola Unlock tool.
so, any ideas on this?

Categories

Resources