[Q] Issues locking the bootloader - G 2014 Q&A, Help & Troubleshooting

I had some problems recently and decided to unroot. I followed the instructions available in the forums and finally got it all sorted out. I didn't get any errors in the process but the bootloader is still unlocked, as evidenced by the startup warning. When I use "oem lock begin" and "oem lock" I get an "sst lock failure". I checked with a terminal app and am unrooted now. I also no longer have a custom recovery.
I don't mind working with an unlocked bootloader as long as everything else works like stock. Will I have any problems performing OTA updates if I don't have custom recovery and am unrooted? If it's a problem, then is there a way to relock the bootloader without wiping everything yet again?
Thanks for all the help. These forums have been a great resource.

ctennenh said:
I had some problems recently and decided to unroot. I followed the instructions available in the forums and finally got it all sorted out. I didn't get any errors in the process but the bootloader is still unlocked, as evidenced by the startup warning. When I use "oem lock begin" and "oem lock" I get an "sst lock failure". I checked with a terminal app and am unrooted now. I also no longer have a custom recovery.
I don't mind working with an unlocked bootloader as long as everything else works like stock. Will I have any problems performing OTA updates if I don't have custom recovery and am unrooted? If it's a problem, then is there a way to relock the bootloader without wiping everything yet again?
Thanks for all the help. These forums have been a great resource.
Click to expand...
Click to collapse
Bro, follow the steps in the following thread:
http://forum.xda-developers.com/moto-g-2014/general/restore-to-stock-t2873657
I can unlock and relock my Moto G 2014's bootloader.. Just need to follow all steps listed in the thread...

Those are the instructions I used. For some reason it doesn't want to lock.

ctennenh said:
Those are the instructions I used. For some reason it doesn't want to lock.
Click to expand...
Click to collapse
The bootloader will only lock after verifying all system files are original and un-modified, so if you made any changes to system files it won't lock.

Thanks for your reply. Since everything worked with the stock rom flash I'm not sure what system files could be modified still. Is there any way that the reflash left modified system files alone? I'm no longer rooted nor do I have a custom recovery installed. I don't know what the problem could be.

Related

[Q] Moto X VZW Developer, upgrading to 4.4.4

OK, so I've followed the newb guide to relocking my unlocked bootloader here:
http://forum.xda-developers.com/moto-x/general/noob-guide-unroot-relock-bootloader-vzw-t2571786/page4
I had issues getting the bootloader locked but found another guide here:
https://forums.motorola.com/posts/029f68b0a0
I used the command listed in the xml file listed at the bottom of the page, adapter to my phone of course.
After a few tried I got everything transferred with fastboot and the fastboot screen on my phone now says locked. My issue now is that the phone still boots up with the Bootloader Unlocked Warning screen.
Will I still be able to upgrade with the OTA? If not, what do I need to do to get rid of this warning screen on boot so that I can upgrade?
Any help is much appreciated, and I apologize if this has already been answered somewhere, but I've been looking for the past 3 hours with no success.
-----------------------------------------------
Nevermind, this has been solved.
I was able to upgrade even with the warning screen on boot. Hopefully this helps someone.
vapor100LL said:
OK, so I've followed the newb guide to relocking my unlocked bootloader here:
http://forum.xda-developers.com/moto-x/general/noob-guide-unroot-relock-bootloader-vzw-t2571786/page4
I had issues getting the bootloader locked but found another guide here:
https://forums.motorola.com/posts/029f68b0a0
I used the command listed in the xml file listed at the bottom of the page, adapter to my phone of course.
After a few tried I got everything transferred with fastboot and the fastboot screen on my phone now says locked. My issue now is that the phone still boots up with the Bootloader Unlocked Warning screen.
Will I still be able to upgrade with the OTA? If not, what do I need to do to get rid of this warning screen on boot so that I can upgrade?
Any help is much appreciated, and I apologize if this has already been answered somewhere, but I've been looking for the past 3 hours with no success.
-----------------------------------------------
Nevermind, this has been solved.
I was able to upgrade even with the warning screen on boot. Hopefully this helps someone.
Click to expand...
Click to collapse
There was absolutely no reason whatsoever to "relock" your bootloader. In fact, it was very foolish to do this.
Glad you got it solved, but for future reference, there IS NO REASON TO EVER RE-LOCK THE BOOTLOADER.
Having an unlocked BL does NOT prevent you from taking OTAs.

Upgrading rooted stock ROM to new stock OTA

My gf has HTC One with latest stock T-Mobile US ROM, unlocked bootloader, is rooted, and has TWRP. T-Mobile is about to release an OTA (source), and I am wondering how to go about installing it. AFAIK, stock recovery is required, AND the bootloader needs to be locked again. If this is the case, re-rooting will require unlocking the bootloader and thus doing factory reset? Is there a simpler way to do this?
Stock recovery and preinstalled apps needed
Bootloader locked not needed
There are many posts written about this read them first
c00ller said:
My gf has HTC One with latest stock T-Mobile US ROM, unlocked bootloader, is rooted, and has TWRP. T-Mobile is about to release an OTA (source), and I am wondering how to go about installing it. AFAIK, stock recovery is required, AND the bootloader needs to be locked again. If this is the case, re-rooting will require unlocking the bootloader and thus doing factory reset? Is there a simpler way to do this?
Click to expand...
Click to collapse
relock your bootloader
fastboot oem lock
and run this RUU
http://www.htc.com/us/support/htc-one-t-mobile/news/
instructions / Download are at the bottom of the page
Everything on the Phone will be lost ..Backup to your PC and google first !
yatindroid said:
Stock recovery and preinstalled apps needed
Bootloader locked not needed
Click to expand...
Click to collapse
FYI I have actually tried running an RUU on unlocked bootloader with stock recovery, kept failing until I relocked the bootloader...

[Q] After Update to 5.1, Re-lock Bootloader?

Due to organizational requirements the bootloader needs to be locked. So, here go the questions:
After flashing factory image (5.1.0 (LMY47E), is it safe to re-lock bootloader?
And when, after the final reboot and before setup?
And, will the command, fastboot oem lock, wipe EVERYTHING off the phone, like fastboot oem unlock does?
And does the Developer options setting, "OEM unlocking", need to be turned on prior to the lock?
Thanks
No one has proven that locking the bootloaders does not cause a "brick". We have seen people lock after 5.1 and get a bootloop. This becomes a brick because they cannot unlock to fix it. We don't know if the update causes the loop or the lock does.
By the way, this was a completely stock Nexus 6 (5.0.1), no root, no apps other than Google. Before the factory image flash, the "OEM Unlocking" setting in Developer Options was persistent during power on/off. Now, with 5.1 the setting turns itself off during power on/off.
So, should I re-lock the bootloader and satisfy organizational requirements and risk a boot loop or proceed unlocked? Kinda feel like a "deer in the headlights" !
clairez said:
By the way, this was a completely stock Nexus 6 (5.0.1), no root, no apps other than Google. Before the factory image flash, the "OEM Unlocking" setting in Developer Options was persistent during power on/off. Now, with 5.1 the setting turns itself off during power on/off.
So, should I re-lock the bootloader and satisfy organizational requirements and risk a boot loop or proceed unlocked? Kinda feel like a "deer in the headlights" !
Click to expand...
Click to collapse
Well its your choice. I recommend not locking it. However, if you do lock it and end up bricked, at least we know its the locking that causes the loop and not the flash but.... Is it worth it?
If your organization is supplying the device ( or the money for the device) you have no business unlocking it. At my organization people are fired for such things.
If they are not compensating you somehow then I don't see how they can make requirements on your device.
Sent from my Nexus 6
And if it is the unlocking/locking that causes the boot loop (hard brick) then any flashing operation that requires unlocking the bootloader will require that the system remain unlocked forever. A penalty that will afflict a portion (large?) of the Nexus 6 community. Was this an issue before 5.0? Makes one wonder if this is by design or accidental.
DebianDog said:
If they are not compensating you somehow then I don't see how they can make requirements on your device.
Click to expand...
Click to collapse
Yes we totally can. If you work for my company and decide you would rather use your own device for corporate email and data, that data is ours. You may use your own device but we will manage it. If it gets stolen, we will wipe it. You will adhere the same policies for corporate owned data as you will with a phone supplied by us. You will have lock screen, you will be unrooted. You will keep your bootloaders locked. Or you can use this sh*tty Nokia.
My hardware, but if I want to utilize it in the organization, then I must abide by their rules.
This post was not meant to be an organizational ethics discussion, just a request for guidance. If anyone can give me input on the original questions, I would greatly appreciate it. Especially the wipe side effect of the lock operation. Do not want to spend a lot of time configuring the device if it will be erased.
Thanks in advance
clairez said:
My hardware, but if I want to utilize it in the organization, then I must abide by their rules.
Click to expand...
Click to collapse
Yep. Absolutely.
rootSU said:
No one has proven that locking the bootloaders does not cause a "brick". We have seen people lock after 5.1 and get a bootloop. This becomes a brick because they cannot unlock to fix it. We don't know if the update causes the loop or the lock does.
Click to expand...
Click to collapse
Just a little thinking out loud here. Wouldn't it be safe to have OEM Unlock checked under dev options, lock the bootloader, if you happen to bootloop OEM Unlock is still checked so you could still unlock? And then upon first boot OEM Unlock would get unchecked.
Sent from my Nexus 6 using XDA Free mobile app
Konfuzion said:
Just a little thinking out loud here. Wouldn't it be safe to have OEM Unlock checked under dev options, lock the bootloader, if you happen to bootloop OEM Unlock is still checked so you could still unlock? And then upon first boot OEM Unlock would get unchecked.
Sent from my Nexus 6 using XDA Free mobile app
Click to expand...
Click to collapse
Safe? No.. The flag resets at boot. Boot loop partially boots and it could be enough to reset the flag "at first boot"
Pretty much everything is an unknown here. We do t even know where the "enable OEM unlock" flag is set. Is it in the BL or one of the various partitions? What effect would setting the flag and wiping the OS have? We just don't know.
rootSU said:
Safe? No.. The flag resets at boot. Boot loop partially boots and it could be enough to reset the flag "at first boot"
Pretty much everything is an unknown here. We do t even know where the "enable OEM unlock" flag is set. Is it in the BL or one of the various partitions? What effect would setting the flag and wiping the OS have? We just don't know.
Click to expand...
Click to collapse
Good point. That's why more heads are better than one. I still think my theory would work, but yet I wouldn't be willing to risk my N6 on it, wouldn't suggest others do either.
Sent from my Nexus 6 using XDA Free mobile app
clairez said:
Due to organizational requirements the bootloader needs to be locked. So, here go the questions:
After flashing factory image (5.1.0 (LMY47E), is it safe to re-lock bootloader?
And when, after the final reboot and before setup?
And, will the command, fastboot oem lock, wipe EVERYTHING off the phone, like fastboot oem unlock does?
And does the Developer options setting, "OEM unlocking", need to be turned on prior to the lock?
Thanks
Click to expand...
Click to collapse
1. Unsure at this point. If everything is stock (including recovery), I would suspect that it would be OK, but it has not been verified yet.
2. After you flash the bootloader, radio, boot, system and recovery images, and format data and cache, then would be the time to re-lock and then boot into Android.
3. Yes. But based on what I gather, the process of wiping on an N6 (when unlocking or locking the bootloader) is done via the stock recovery. So, if you have a custom recovery when you lock, I suspect that it will give you a boot loop.
4. I don't know.
Update - Success
I re-locked the bootloader and the device is working normally, no boot loop. I will continue testing over the next few days and then share what I learned.
Thanks for the help ...
Upgraded to 5.1, booted system OK
rechecked the OEM unlock option and rebooted to fastboot and locked bootloader.
No bootloop or other issues noticed.
Hope this helps.
clairez said:
I re-locked the bootloader and the device is working normally, no boot loop. I will continue testing over the next few days and then share what I learned.
Thanks for the help ...
Click to expand...
Click to collapse
Interesting. And you were 100% stock?
Perhaps the loop isn't caused by the lock itself then. Good to know, though still people need to be cautious
androiduser2011 said:
Upgraded to 5.1, booted system OK
rechecked the OEM unlock option and rebooted to fastboot and locked bootloader.
No bootloop or other issues noticed.
Hope this helps.
Click to expand...
Click to collapse
A few question, for understanding:
Rooted?
Stock or TWRP recovery?
Encrypted?
Thanks
rootSU said:
No one has proven that locking the bootloaders does not cause a "brick". We have seen people lock after 5.1 and get a bootloop. This becomes a brick because they cannot unlock to fix it. We don't know if the update causes the loop or the lock does.
Click to expand...
Click to collapse
This happened to me literally tonight. I tried to lock the boot loader which was successful, from there the device would start to root into teamwin recovery. So from there I tired to flash a fully stock rom but the bootloader was locked. And then because you need permission from the OS to unlock the bootloader I was stuck. What I did is from the locked bootloader I ran the stock oem flash from a fresh download and check from wugs with the force flash enabled (make sure everything is right) miracles of miracles it worked and came back to me.
I learned my lesson. Never shall my bootloader be relocked unless my phone is out of my possession. I'm spending the rest of the time making sure that nobody can get to my data. I love the phone, but that data is my life.
So basically, we need to confirm that being 100% stock will safely allow the relocking of the bootloader on 5.1 per official instructions from Google. If it can be determined that having TWRP recovery installed is the cause of bricks then users can be instructed to be sure stock recovery is installed before relocking. My own thoughts are that this is a bug of sorts with the new security features of lollipop and I'm sure the talented folks here will get it figured out. I'm 100% stock on LMY47D that I sideloaded. Not sure I can afford to risk my 6 but I offer any assistance I can to help get this figured out.
Evolution_Freak said:
So basically, we need to confirm that being 100% stock will safely allow the relocking of the bootloader on 5.1
Click to expand...
Click to collapse
Some of the "bricks" happened after fully flashing stock, i.e they had stock recovery. They had a locked bootloader, an OS that didn't boot and a recovery that couldn't flash anything. If they had TWRP installed, they could format data and flash a rom.zip no problem.

Help - OTA Update gave me a brick

Hey XDA,
I was rooted, unlocked and TWRP'd on I think 6.4? I realized I wanted to go back to locked and stock after seeing some of the security stuff come out. I used SPFT to flash the 6.1 Prime Rom, and everything was working great. Phone booted no problem, and seemed to work fine. I then tried to use the Wireless Update to update the phone. It looked liked it downloaded fine, but now I'm in a reboot loop, and recovery does absolutely nothing but reboot loop as well. I CAN get the phone into Fastboot mode, but fastboot flash recovery gives me a "failed to get permission" error.
I ran a getvar all, and here is what I have:
unlocked: yes
secure: yes
kernel 1k
bootloader: version-preloader 0.0.00
Version: 0.5
I've tried the SPFT tools again, but it gives me ERROR: S_BROM_DOWNLOAD_DA_FAIL.
ANY clue what I can try next to just get the dang thing to be bootable? I don't care root or recovery or what, I just want a working phone, and I'm running out of ideas.
Thanks!
brockwitting said:
Hey XDA,
I was rooted, unlocked and TWRP'd on I think 6.4? I realized I wanted to go back to locked and stock after seeing some of the security stuff come out. I used SPFT to flash the 6.1 Prime Rom, and everything was working great. Phone booted no problem, and seemed to work fine. I then tried to use the Wireless Update to update the phone. It looked liked it downloaded fine, but now I'm in a reboot loop, and recovery does absolutely nothing but reboot loop as well. I CAN get the phone into Fastboot mode, but fastboot flash recovery gives me a "failed to get permission" error.
I ran a getvar all, and here is what I have:
unlocked: yes
secure: yes
kernel 1k
bootloader: version-preloader 0.0.00
Version: 0.5
I've tried the SPFT tools again, but it gives me ERROR: S_BROM_DOWNLOAD_DA_FAIL.
ANY clue what I can try next to just get the dang thing to be bootable? I don't care root or recovery or what, I just want a working phone, and I'm running out of ideas.
Thanks!
Click to expand...
Click to collapse
don't panic. everything is as is should be in your situation.
you see when you did getvar all , it said
secure: yes.
that means it only wants to boot signed and secured partitions. Just get into fastboot and do "oem unlock".
you really cant (safely) relock the bootloader. If your boot loader was relock now, you wold be in a perminent boot loop condition not able to recover.
But you can save it with "oem unlock" from where you at now.
You rock. I thought since it said unlocked I didn't need to do it again, but that did the trick. Now I just need to figure out what to do with the phone. I wouldn't mind keeping root, but I want the B12 update.
brockwitting said:
You rock. I thought since it said unlocked I didn't need to do it again, but that did the trick. Now I just need to figure out what to do with the phone. I wouldn't mind keeping root, but I want the B12 update.
Click to expand...
Click to collapse
Here...
http://forum.xda-developers.com/r1-...om-6-5-flashed-via-twrp-t3455532/post68543624
Though if you have already updated, you're probably stuck, unless the dirtycow hack still works with newest OTA....
http://forum.xda-developers.com/r1-...irtycowed-f-amazon-root-t3490882/post69387241
kal250 said:
Here...
http://forum.xda-developers.com/r1-...om-6-5-flashed-via-twrp-t3455532/post68543624
Though if you have already updated, you're probably stuck, unless the dirtycow hack still works with newest OTA....
http://forum.xda-developers.com/r1-...irtycowed-f-amazon-root-t3490882/post69387241
Click to expand...
Click to collapse
The dirtycow thing was only needed to get to the unlocked point. He is already there, so his only issue should be the lack of sp flash tool. Until/ if he does the bootloader rollback.
Shouldn't be problem with the modded v7 to roll back either.
Because in order to install the modded version , you need to be unlocked and twrp anyway, right.?
mrmazak said:
The dirtycow thing was only needed to get to the unlocked point. He is already there, so his only issue should be the lack of sp flash tool. Until/ if he does the bootloader rollback.
Shouldn't be problem with the modded v7 to roll back either.
Because in order to install the modded version , you need to be unlocked and twrp anyway, right.?
Click to expand...
Click to collapse
Yes.... See what happens when you loose your R1, I'm out of touch lol.... I do miss the phone.....
mrmazak said:
don't panic. everything is as is should be in your situation.
you see when you did getvar all , it said
secure: yes.
that means it only wants to boot signed and secured partitions. Just get into fastboot and do "oem unlock".
you really cant (safely) relock the bootloader. If your boot loader was relock now, you wold be in a perminent boot loop condition not able to recover.
But you can save it with "oem unlock" from where you at now.
Click to expand...
Click to collapse
I presume he flashed factory original 6.1 from Colton's site.
I thought flashing original rom with SPFT should result in safely relocked bootloader, why not?
What if he relocked bootloader with 'fastboot oem relock' command after flashing 6.1 but before taking 7.4.2 OTA update? This would also leave him with:
unlocked: yes
secure: yes?
There must be some way to bring phone to original factory state with bootloader locked (meaning unlocked: no secure: yes).
BLU support also cannot do this?
kfn said:
I presume he flashed factory original 6.1 from Colton's site.
I thought flashing original rom with SPFT should result in safely relocked bootloader, why not?
What if he relocked bootloader with 'fastboot oem relock' command after flashing 6.1 but before taking 7.4.2 OTA update? This would also leave him with:
unlocked: yes
secure: yes?
There must be some way to bring phone to original factory state with bootloader locked (meaning unlocked: no secure: yes).
BLU support also cannot do this?
Click to expand...
Click to collapse
There is and I did it few times while testing my unlock script. Bit the chances of making a brick were so very high I cannot recommend doing it.
There are two other partitions that store the unlock state and they need to restored to really relock bootloader.
OEM relock does not work properly
mrmazak said:
There is and I did it few times while testing my unlock script. Bit the chances of making a brick were so very high I cannot recommend doing it.
There are two other partitions that store the unlock state and they need to restored to really relock bootloader.
OEM relock does not work properly
Click to expand...
Click to collapse
Can you tell what steps you did to relock?
I really want to bring device to original factory state because encryption does not work when bootloader is unlocked. I did first dirty cow method on original 6.6 ROM (one with newer preloader), then rolled back booloader, installed 6.1 from ColtonDRG site with SPFT and finally installed vampireinfo's 7.4.2 thru TWRP.
However when I encrypted phone, in settings it says encrypted but I can browse device on PC without entering PIN.
On factory state encrypted device (with locked bootloader) I was not able to this
kfn said:
Can you tell what steps you did to relock?
I really want to bring device to original factory state because encryption does not work when bootloader is unlocked. I did first dirty cow method on original 6.6 ROM (one with newer preloader), then rolled booloader, installed 6.1 from Coltron site with SPFT and finally installed vampireinfo's 7.4.2 thru TWRP.
However when I encrypted phone, in settings it says encrypted but I can browse device on PC without entering PIN.
On factory state encrypted device (with locked bootloader) I was not able to this
Click to expand...
Click to collapse
This will brick your phone, if you are not careful, and also if you are carefull. You can browse for help in encryption with unlocked bootloader before doing this, I'm sure there is a solution.
If you replace Seccfg.bin and Secro.bin from a backup from before unlocking bootloader you should be set to locked but I do not know of your phone will boot. You will be doing g that at your own risk.
But if you download the repair solution under the hidden tag(click to show content) in the roll back thread.
In that file it will restore you to 6.1 and it will be locked bootloader. I do not know about keeping v7 and relocked

How to relock the bootloader?

Hi,
I've searched and found how to do it but it was for Android 5.1 but I'm on 7.0 and I my recovery is TWRP 3.0.2-0 and apparently there are more steps to do if you are on TWRP, I'm wondering what are they.
Thanks
test84 said:
Hi,
I've searched and found how to do it but it was for Android 5.1 but I'm on 7.0 and I my recovery is TWRP 3.0.2-0 and apparently there are more steps to do if you are on TWRP, I'm wondering what are they.
Thanks
Click to expand...
Click to collapse
First, questions need to go in the Nexus 6 Q&A, Help & Troubleshooting Thread, not the General thread. Second, the steps to lock the bootloader have not changed. It's done from the bootloader with fastboot and the command "fastboot oem lock". It shouldn't matter what recovery you have.
Re-locking needs stock recovery(maybe full stock; boot, recovery, system) if you try to re-lock your boot loader without stock recovery you might hardbrick your phone. So just backup your apps and files, flash a stock image from google and re-lock your boot loader with "fastboot oem lock". Which probably needs wiping your phone.
Before you do anything search these forums for the many people who locked their bootloader and then when they had problems ended up with a bricked and useless device. Unless you have a very special reason for locking, leave it unlocked
dahawthorne said:
Before you do anything search these forums for the many people who locked their bootloader and then when they had problems ended up with a bricked and useless device. Unless you have a very special reason for locking, leave it unlocked
Click to expand...
Click to collapse
this right here...there is really no reason to ever re lock your bootloader
I flashed the factory image and and it went fine. But the bootloader is still unlocked. My main concern for locking the bootloader is to prevent any malicious app to root the phone and hide themselves by like installing as system app or something. And I'm not planning to flash any custom ROM. So:
1- Since I'm on stock ROM, is there still a possibility of hard bricking my phone if I relock?
2- If I leave it unlocked, will malwares be able to tamper with the phone by the means I mentioned or similar approaches?
Thanks
2. No, they don't. Bootloader is on a completly different layer.
test84 said:
I flashed the factory image and and it went fine. But the bootloader is still unlocked. My main concern for locking the bootloader is to prevent any malicious app to root the phone and hide themselves by like installing as system app or something. And I'm not planning to flash any custom ROM. So:
1- Since I'm on stock ROM, is there still a possibility of hard bricking my phone if I relock?
2- If I leave it unlocked, will malwares be able to tamper with the phone by the means I mentioned or similar approaches?
Thanks
Click to expand...
Click to collapse
I feel your concerns. I think the safest bet is to watch where you download apps and content from. And make sure "unknown sources" is turned off. That should minimize your potential for problems. I think the main thing is watching where you get apps from.

Categories

Resources