usb tether using Linux PC fails after Android 8.1 update on OnePlus 5 - OnePlus 5 Questions & Answers

I updated a OnePlus 5 from Android 8.0 to Android 8.1 and lost the ability to USB tether. Hotspot works fine. I've verified that some other users have this problem on the OnePlus subreddit. I'm on Opensuse 42.3.
Linux 4.4.126-48-default #1 SMP Sat Apr 7 05:22:50 UTC 2018 (f24992c) x86_64 x86_64 x86_64 GNU/Linux
This link indicates a "fix" similar to one on a Lineage forum. It doesn't solve the problem, but figured I would put it here to prevent similar posts from showing up in this thread.
https://forums.oneplus.com/threads/hotspot-not-working.769592/
At least this fix didn't break anything.
There are suggestions regarding changing the APN, but I no joy.
Using lsusb, it is clear that the phone is seen by the PC. However the phone doesn't show up when I run ifconfig.
This is the lsusb verbose output when usb tether is selected.
Code:
lsusb -s8:10 -v
Bus 008 Device 010: ID 2a70:f00e
Couldn't open device, some information will be missing
Device Descriptor:
bLength 18
bDescriptorType 1
bcdUSB 2.00
bDeviceClass 0 (Defined at Interface level)
bDeviceSubClass 0
bDeviceProtocol 0
bMaxPacketSize0 64
idVendor 0x2a70
idProduct 0xf00e
bcdDevice 4.04
iManufacturer 1
iProduct 2
iSerial 3
bNumConfigurations 1
Configuration Descriptor:
bLength 9
bDescriptorType 2
wTotalLength 75
bNumInterfaces 2
bConfigurationValue 1
iConfiguration 4
bmAttributes 0x80
(Bus Powered)
MaxPower 500mA
Interface Association:
bLength 8
bDescriptorType 11
bFirstInterface 0
bInterfaceCount 2
bFunctionClass 239 Miscellaneous Device
bFunctionSubClass 4
bFunctionProtocol 1
iFunction 7
Interface Descriptor:
bLength 9
bDescriptorType 4
bInterfaceNumber 0
bAlternateSetting 0
bNumEndpoints 1
bInterfaceClass 239 Miscellaneous Device
bInterfaceSubClass 4
bInterfaceProtocol 1
iInterface 5
** UNRECOGNIZED: 05 24 00 10 01
** UNRECOGNIZED: 05 24 01 00 01
** UNRECOGNIZED: 04 24 02 00
** UNRECOGNIZED: 05 24 06 00 01
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x81 EP 1 IN
bmAttributes 3
Transfer Type Interrupt
Synch Type None
Usage Type Data
wMaxPacketSize 0x0008 1x 8 bytes
bInterval 9
Interface Descriptor:
bLength 9
bDescriptorType 4
bInterfaceNumber 1
bAlternateSetting 0
bNumEndpoints 2
bInterfaceClass 10 CDC Data
bInterfaceSubClass 0 Unused
bInterfaceProtocol 0
iInterface 6
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x8e EP 14 IN
bmAttributes 2
Transfer Type Bulk
Synch Type None
Usage Type Data
wMaxPacketSize 0x0200 1x 512 bytes
bInterval 0
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x0f EP 15 OUT
bmAttributes 2
Transfer Type Bulk
Synch Type None
Usage Type Data
wMaxPacketSize 0x0200 1x 512 bytes
bInterval 0
For completelness, this is the lsusb verbose output when tether is NOT selected.
Code:
lsusb -s8:13 -v
Bus 008 Device 013: ID 2a70:f003
Device Descriptor:
bLength 18
bDescriptorType 1
bcdUSB 2.00
bDeviceClass 0 (Defined at Interface level)
bDeviceSubClass 0
bDeviceProtocol 0
bMaxPacketSize0 64
idVendor 0x2a70
idProduct 0xf003
bcdDevice 4.04
iManufacturer 1 OnePlus
iProduct 2 OnePlus
iSerial 3 (redacted)
bNumConfigurations 1
Configuration Descriptor:
bLength 9
bDescriptorType 2
wTotalLength 62
bNumInterfaces 2
bConfigurationValue 1
iConfiguration 4 mtp
bmAttributes 0x80
(Bus Powered)
MaxPower 500mA
Interface Descriptor:
bLength 9
bDescriptorType 4
bInterfaceNumber 0
bAlternateSetting 0
bNumEndpoints 3
bInterfaceClass 255 Vendor Specific Class
bInterfaceSubClass 255 Vendor Specific Subclass
bInterfaceProtocol 0
iInterface 5 MTP
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x81 EP 1 IN
bmAttributes 2
Transfer Type Bulk
Synch Type None
Usage Type Data
wMaxPacketSize 0x0200 1x 512 bytes
bInterval 0
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x01 EP 1 OUT
bmAttributes 2
Transfer Type Bulk
Synch Type None
Usage Type Data
wMaxPacketSize 0x0200 1x 512 bytes
bInterval 0
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x82 EP 2 IN
bmAttributes 3
Transfer Type Interrupt
Synch Type None
Usage Type Data
wMaxPacketSize 0x001c 1x 28 bytes
bInterval 6
Interface Descriptor:
bLength 9
bDescriptorType 4
bInterfaceNumber 1
bAlternateSetting 0
bNumEndpoints 2
bInterfaceClass 8 Mass Storage
bInterfaceSubClass 6 SCSI
bInterfaceProtocol 80 Bulk-Only
iInterface 6 Mass Storage
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x83 EP 3 IN
bmAttributes 2
Transfer Type Bulk
Synch Type None
Usage Type Data
wMaxPacketSize 0x0200 1x 512 bytes
bInterval 0
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x02 EP 2 OUT
bmAttributes 2
Transfer Type Bulk
Synch Type None
Usage Type Data
wMaxPacketSize 0x0200 1x 512 bytes
bInterval 1
Device Qualifier (for other device speed):
bLength 10
bDescriptorType 6
bcdUSB 2.00
bDeviceClass 0 (Defined at Interface level)
bDeviceSubClass 0
bDeviceProtocol 0
bMaxPacketSize0 64
bNumConfigurations 1
Device Status: 0x0000
(Bus Powered)

Related

Leaked Android/G1 romdump

Okay, so i hear that pretty much beta-g1's are given to call centers and support points etcetera. What keeps the romdumps?
It's time to port this little bastard!
FYI: Sorry for the dissapointment from the topic title
awh man! you got me all excited. whatever its not like my little wing would handle android anyway.
im pretty sure nobody wants to speak up because of what happen to black93300zx. he got a pre-release att fuze and everyone was going crazy.
kidnamedAlbert said:
awh man! you got me all excited. whatever its not like my little wing would handle android anyway.
im pretty sure nobody wants to speak up because of what happen to black93300zx. he got a pre-release att fuze and everyone was going crazy.
Click to expand...
Click to collapse
well, i would suggest, make a new username, just dump the rom. and then don't log in to that account anymore.
kidnamedAlbert said:
awh man! you got me all excited. whatever its not like my little wing would handle android anyway.
im pretty sure nobody wants to speak up because of what happen to black93300zx. he got a pre-release att fuze and everyone was going crazy.
Click to expand...
Click to collapse
Heh, I think the only pre-release phone I'll buy from now on is something for AT&T with Android. Despite the last reaction, you can bet if I get my hands on something I'll leak info. Maybe THIS TIME someone will believe me. ;-)
Very good , Dump dump dump it
I'm also interested in seeing a rom dump!.... and also buying a device if someone is selling it yet
what are the chances of putting the android rom on my tilt?
thodge21 said:
what are the chances of putting the android rom on my tilt?
Click to expand...
Click to collapse
Android has already been run on a Tilt, it's far from stable but they're working on it.
http://www.youtube.com/watch?v=Q2rByiug8LU
G1 for Sale
pof said:
I'm also interested in seeing a rom dump!.... and also buying a device if someone is selling it yet
Click to expand...
Click to collapse
I actually ordered the G1 and am going to sell it. It is currently on ebay or you can contact me with a pm for the price.
Black93300ZX said:
Android has already been run on a Tilt, it's far from stable but they're working on it.
http://www.youtube.com/watch?v=Q2rByiug8LU
Click to expand...
Click to collapse
so is the sdk package released with a non-beta version or is it just an sdk-package?
http://code.google.com/android/download.html
thodge21 said:
so is the sdk package released with a non-beta version or is it just an sdk-package?
http://code.google.com/android/download.html
Click to expand...
Click to collapse
Hell if I know, I just knew it was on the Tilt and nothing more than that.
lol. okay. i'll download and see if i can figure it out. let you know what i find.
looks like the programing language is java...which i haven't learned yet... but it does have an android emulator aswell as the android structure, but no straight forward rom. someone could probably pull out the platform and cook a rom with the proper know how though.
I'll give it a try when I get mine Oct. 22. Although, I'm sure someone will have dumped it and uploaded it here by then. It might be tricky to copy from the device itself. This will be a totally different experience than WM. I am not too good with Linux...especially the mobile version, lol! I'll definitely give it a try. Does anyone know how to get the OS from the device itself?
sino8r said:
Does anyone know how to get the OS from the device itself?
Click to expand...
Click to collapse
IMHO the contents of /lib/modules/* will be the most interesting
thing to look at.
bumping
This deserves a bump.. camera+power gets me to the rom on the G1, but I'm not seeing anything in HTCFlasher, as usbserial isn't detecting my g1. pof, you around?
galtoid said:
I'm not seeing anything in HTCFlasher, as usbserial isn't detecting my g1. pof, you around?
Click to expand...
Click to collapse
Can you post the 'lsusb' and 'lsusb -vvv' output ?
cr2 said:
Can you post the 'lsusb' and 'lsusb -vvv' output ?
Click to expand...
Click to collapse
I can adb to it fine, here's a lsusb -vvv diff:
Code:
--- lsusb-unplugged 2008-10-25 18:06:42.000000000 -0700
+++ lsusb-plugged 2008-10-25 18:26:02.000000000 -0700
@@ -1,4 +1,93 @@
+Bus 004 Device 004: ID 0bb4:0c02 High Tech Computer Corp.
+Device Descriptor:
+ bLength 18
+ bDescriptorType 1
+ bcdUSB 1.02
+ bDeviceClass 0 (Defined at Interface level)
+ bDeviceSubClass 0
+ bDeviceProtocol 0
+ bMaxPacketSize0 64
+ idVendor 0x0bb4 High Tech Computer Corp.
+ idProduct 0x0c02
+ bcdDevice 1.00
+ iManufacturer 3 HTC
+ iProduct 2 Android Phone
+ iSerial 1 HT839GZ00000
+ bNumConfigurations 1
+ Configuration Descriptor:
+ bLength 9
+ bDescriptorType 2
+ wTotalLength 55
+ bNumInterfaces 2
+ bConfigurationValue 1
+ iConfiguration 0
+ bmAttributes 0x80
+ (Bus Powered)
+ MaxPower 256mA
+ Interface Descriptor:
+ bLength 9
+ bDescriptorType 4
+ bInterfaceNumber 0
+ bAlternateSetting 0
+ bNumEndpoints 2
+ bInterfaceClass 8 Mass Storage
+ bInterfaceSubClass 6 SCSI
+ bInterfaceProtocol 80 Bulk (Zip)
+ iInterface 0
+ Endpoint Descriptor:
+ bLength 7
+ bDescriptorType 5
+ bEndpointAddress 0x01 EP 1 OUT
+ bmAttributes 2
+ Transfer Type Bulk
+ Synch Type None
+ Usage Type Data
+ wMaxPacketSize 0x0200 1x 512 bytes
+ bInterval 0
+ Endpoint Descriptor:
+ bLength 7
+ bDescriptorType 5
+ bEndpointAddress 0x81 EP 1 IN
+ bmAttributes 2
+ Transfer Type Bulk
+ Synch Type None
+ Usage Type Data
+ wMaxPacketSize 0x0200 1x 512 bytes
+ bInterval 0
+ Interface Descriptor:
+ bLength 9
+ bDescriptorType 4
+ bInterfaceNumber 1
+ bAlternateSetting 0
+ bNumEndpoints 2
+ bInterfaceClass 255 Vendor Specific Class
+ bInterfaceSubClass 66
+ bInterfaceProtocol 1
+ iInterface 0
+ Endpoint Descriptor:
+ bLength 7
+ bDescriptorType 5
+ bEndpointAddress 0x02 EP 2 OUT
+ bmAttributes 2
+ Transfer Type Bulk
+ Synch Type None
+ Usage Type Data
+ wMaxPacketSize 0x0200 1x 512 bytes
+ bInterval 0
+ Endpoint Descriptor:
+ bLength 7
+ bDescriptorType 5
+ bEndpointAddress 0x82 EP 2 IN
+ bmAttributes 2
+ Transfer Type Bulk
+ Synch Type None
+ Usage Type Data
+ wMaxPacketSize 0x0200 1x 512 bytes
+ bInterval 0
+Device Status: 0x0000
+ (Bus Powered)
+
Bus 004 Device 001: ID 0000:0000
Device Descriptor:
bLength 18
@@ -62,7 +151,7 @@
Port 1: 0000.0100 power
Port 2: 0000.0100 power
Port 3: 0000.0000
- Port 4: 0000.0100 power
+ Port 4: 0000.0503 highspeed power enable connect
Port 5: 0000.0000
Port 6: 0000.0100 power
Device Status: 0x0003
Second interface ("Vendor Specific Class") should be something usefull.

An I9000 that really needs to be rescued from a brick

I don't normally used the word brick to describe this guy's situation, but it won't boot, it won't turn on, at least visually to my knowledge. He tried making a USB Jig and it still won't go into download mode for an odin flash.
I'm not sure if he built it right, I suggested to him buying a pre-made one to make sure.
Here is his story:
TITLE: Will an USB-JIG save my bricked SGS?
I have an SGS I9000 (international) which I have flashed at least a dozen times without any issues. Today I tried out the CM9 nightly and got stuck in a boot loop.
I tried flashing a new kernel with Odin. Everything seemed fine with Odin, the download completed without issues and the phone rebooted so I unplugged it and pulled the battery to start in in recovery.
Now it won't turn on at all, no Samsung Logo and no battery on the display when plugging it into the charger. Windows is playing sounds when I plug it into my computer though, sometimes it plays the connect/disconnect sounds almost at the same time and sometimes a few seconds apart.
Can I save my phone by building an USB JIG or do I have to send it to Samsung to get it fixed?
Edit: Built a JIG, didn't work =(
From A Thread in /r/Android on Reddit
_____________________________________________
My response
Yes, it should, the SGS is extremely hard to "actually" brick.
http://www.amazon.com/Aftermarket-D...CT0Y/ref=sr_1_2?ie=UTF8&qid=1334438748&sr=8-2
Invest in one of these. Make one yourself or get one fast and easy for $5 on Amazon.
Pull the battery. Pop back in. With out turning it on, place the USB Jig into it and it should load into Download mode.
It takes 2 seconds for it to load into it. You may see the Download mode, you may see this as the screen , you may see NOTHING. It could still be in download mode even if it shows nothing.
Now take out the jig and plug the phone into the computer with the stock Odin flasher already open (started as an Admin (Run as Administrator))
Flash it, should work fine.
_____________________________________________
His Response
Sadly, it didn't work. Nothing happens and odin doesn't find anything if I plug it into the computer after plugging in the JIG.
I'm not getting any notification sounds in Windows when I plug it in anymore either, so it looks like it's really dead now =(
[Comments]
_____________________________________________
I really don't want to give up on his Galaxy S I9000. Could anyone offer any advice from a similar situation? Link to XDA threads, web articles, I'm having a hard time finding information.
I'm the one with the bricked I9000 and here's the latest updates.
I've measured the resistors I used to create the JIG (3x100K + 1K) and they add upp to 300.1K - it seems the resistors I bought aren't of the best quality. From all the info I've gotten on building your own JIG this should be fine, which leaves the pins I've connected it to.
The USB micro B plug I've used is taken from a cable, I can reach pin 5 and 1 in the male plug so I've verified that it's connected to pin 5, I canẗ reach pin 2, 3 and 4 with my multimeter though. If viewed from above, the plug looks like this:
Code:
5 ? 1
---------
? ?
which makes me quite certain the pins are configured like this:
Code:
5 3 1
---------
4 2
If u get on eBay and search i-9000 jig I brought 4 USB jigs for $5. Once they come pull out ur battery put it back in an insert jig wich will put u in download mode. Once bricked u need to go back and install a 3file stock rom then install a cf+root. Once done u should be all good to go back and flash your cm9 thru recovery
Sent from my GT-I9000 using xda premium
I've ordered a JIG from amazon since I can't verify that it's my JIG and not my phone. It'll be here in a week or so (I'm in Sweden) so I guess I'll have to live without my phone until then.
If the JIG doesn't work, it's completely bricked, right?
I've tested some again and I do get notification sounds in windows when plugging the phone in now, so I really hope the JIG from Amazon does the trick!
All the galaxy s series are the hardest phones to completely "brick" it is virtually impossible. Iv recovered my phone from being bricked about 5 times now. The part that is a pain is finding the 3file rom. I wish I had a link for you but I have the files saved on my computer. It doesn't matter if its not an English stock rom you use as long as u get your phone started and install cf+root, then you can get back where u started and install cm9. If u get stuck in boot loop again use 3button combo up+power+home and reboot again this has happened and worked for me on several occasions. I hope this helps
Sent from my GT-I9000 using xda premium
as far as i think this is a problem with ur computer drivers ,had this problem before and resolved it by reinstalling kies ,try it and then connect ur fone in download mode ,should do the trick.i had the problem once also if possible try another computer ,i think if ur phone enters download mode ,ur phone is not dead...the jig should work did a little research earlier for my own phone ,had soft bricked it earlier ,plug in the jig ,enter the download mode flash a stock firmware .the list of stock firmwares is here ,http://forum.xda-developers.com/showthread.php?t=1011901&highlight=stock+rom,just search your region and best of luck
I recieved the JIG from Amazon today and I just tried it without luck =(
Nothing happens when I insert the JIG and Odin doesn't see the phone if I plug it in after trying the JIG.
It seems it is bricked for real, how much do you think it'll cost to have Samsung fix it?
---------- Post added at 05:24 PM ---------- Previous post was at 05:07 PM ----------
I've switched to Linux for some better USB info.
If I insert the battery into the phone and then plug it into my computer I get a message about a new USB device, after about 5 seconds it disconnects again. This only happens on my USB 2.0 ports, not on the USB 3.0 ports.
Code:
Apr 20 17:12:08 galvatron kernel: usb 2-1.8: new high-speed USB device number 7 using ehci_hcd
Apr 20 17:12:13 galvatron kernel: usb 2-1.8: USB disconnect, device number 7
Apr 20 17:12:26 galvatron kernel: usb 2-1.8: new high-speed USB device number 8 using ehci_hcd
Apr 20 17:12:32 galvatron kernel: usb 2-1.8: USB disconnect, device number 8
Apr 20 17:13:27 galvatron kernel: usb 2-1.8: new high-speed USB device number 9 using ehci_hcd
Apr 20 17:13:32 galvatron kernel: usb 2-1.8: USB disconnect, device number 9
I removed and inserted the cord between the connections here, if I leave it in nothing happens after it has disconnected.
If I plug in the JIG before plugging it into the computer however, nothing shows up in my message log.
If I run lsusb -v while it's connected I get this:
Code:
Bus 002 Device 011: ID 04e8:1234 Samsung Electronics Co., Ltd
Device Descriptor:
bLength 18
bDescriptorType 1
bcdUSB 2.00
bDeviceClass 255 Vendor Specific Class
bDeviceSubClass 0
bDeviceProtocol 0
bMaxPacketSize0 64
idVendor 0x04e8 Samsung Electronics Co., Ltd
idProduct 0x1234
bcdDevice 1.00
iManufacturer 1 System MCU
iProduct 2 SEC S5PC110 Test B/D
iSerial 0
bNumConfigurations 1
Configuration Descriptor:
bLength 9
bDescriptorType 2
wTotalLength 32
bNumInterfaces 1
bConfigurationValue 1
iConfiguration 0
bmAttributes 0xc0
Self Powered
MaxPower 50mA
Interface Descriptor:
bLength 9
bDescriptorType 4
bInterfaceNumber 0
bAlternateSetting 0
bNumEndpoints 2
bInterfaceClass 255 Vendor Specific Class
bInterfaceSubClass 0
bInterfaceProtocol 0
iInterface 0
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x81 EP 1 IN
bmAttributes 2
Transfer Type Bulk
Synch Type None
Usage Type Data
wMaxPacketSize 0x0200 1x 512 bytes
bInterval 0
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x02 EP 2 OUT
bmAttributes 2
Transfer Type Bulk
Synch Type None
Usage Type Data
wMaxPacketSize 0x0200 1x 512 bytes
bInterval 0
Device Qualifier (for other device speed):
bLength 10
bDescriptorType 6
bcdUSB 2.00
bDeviceClass 255 Vendor Specific Class
bDeviceSubClass 0
bDeviceProtocol 0
bMaxPacketSize0 64
bNumConfigurations 1
Device Status: 0x0001
Self Powered
Since it actually connects and can communicate with my computer over USB it seems there is some life left in it, but since it completely refuses to communicate when inserting the JIG I guess I won't get it into download mode and will have to send it to Samsung to be fixed.
Edit: If I start it with the JIG, plug it into the USB, unplug it and then plug it in again I get the 5s connect/disconnect.
did you ever have it fixed ? I have asimilar problem tried everything I can find from xda , still cant get Odin to detect the phone...
You seem knowledgeable, but I noticed you didn't mention Heimdall after you ran Linux, only that you'd tried odin. Try it if you haven't.
Edit: didn't notice the post times.
Using GT-I9000 my sent Tapatalk 2 from.
I sent it in for service and got an answer after 3 weeks that it was fubar and that I got store credit towards a new phone - ended paying €130 for a Galaxy Nexus instead.
adytum said:
You seem knowledgeable, but I noticed you didn't mention Heimdall after you ran Linux, only that you'd tried odin. Try it if you haven't.
Edit: didn't notice the post times.
Click to expand...
Click to collapse
I never considered trying heimdall since the phone disconnected from the computer after 5s, in retrospect I should perhaps have given it a shot, but I'm quite happy with how everything turned out =)
same problem
HI
I have the same problem and i try the same, but my phone still dead.
My dog disconnect USB cable then i flashing pda, csc and phone files on my phone after this i have same problem..
If somebody now how to fix this, please help me.
Sorry for my english
Nekronomika said:
HI
I have the same problem and i try the same, but my phone still dead.
My dog disconnect USB cable then i flashing pda, csc and phone files on my phone after this i have same problem..
If somebody now how to fix this, please help me.
Sorry for my english
Click to expand...
Click to collapse
Hi new here, but been looking around for awhile.
I have just unbricked my phone that died after I flashed a different phones pit file, totally dead.
Got it back in working condition using Unbrickable Mod by AdamOutler in the Developers forum, have a look at that

[Q] Blurry output when power cycling TV

Hey folks,
Recently picked up a Nexus Player and having an unusual problem when switching the TV off and on. If I turn the TV on, and then turn the Nexus Player on, the output looks normal. But if I switch the TV off and on while leaving the Nexus Player on, the output of the Nexus Player becomes blurry. Not horribly so, everything is still legible, but it's still noticeable. It's comparable to showing 720p output on a 1080p screen, however, the Nexus Player is still outputting in 1080p according to 'dmesg' and 'dumpsys display'.
I have a Sony KDL-46Z5500. Here's the EDID dump from dmesg:
Code:
*********** Print EDID block 0 start **********
00 ff ff ff ff ff ff 00 4d d9 01 ba 01 01 01 01
01 13 01 03 80 a0 5a 78 0a 0d c9 a0 57 47 98 27
12 48 4c 21 08 00 81 80 01 01 01 01 01 01 01 01
01 01 01 01 01 01 02 3a 80 18 71 38 2d 40 58 2c
45 00 40 84 63 00 00 1e 01 1d 00 72 51 d0 1e 20
6e 28 55 00 40 84 63 00 00 1e 00 00 00 fc 00 53
4f 4e 59 20 54 56 20 58 56 0a 20 20 00 00 00 fd
00 30 3e 0e 46 0f 00 0a 20 20 20 20 20 20 01 85
*********** Print EDID block 0 end ************
*********** Print EDID block 1 start **********
02 03 30 f0 50 1f 10 14 05 13 04 12 11 16 15 03
02 07 06 01 20 26 09 07 07 15 07 50 83 01 00 00
68 03 0c 00 30 00 b8 2d 0f e3 05 03 01 e2 00 7b
02 3a 80 d0 72 38 2d 40 10 2c 45 80 40 84 63 00
00 1e 01 1d 00 bc 52 d0 1e 20 b8 28 55 40 40 84
63 00 00 1e 01 1d 80 18 71 1c 16 20 58 2c 25 00
40 84 63 00 00 9e 01 1d 80 d0 72 1c 16 20 10 2c
25 80 40 84 63 00 00 9e 00 00 00 00 00 00 00 fe
*********** Print EDID block 1 end ************
I've compared dumpsys display outputs with a diff tool from when the screen is sharp and when it's blurry and there are no meaningful differences (just PIDs and what looks like a hash on android.os.BinderProxy). Here's the dmesg output from when I turn the TV back on (excluding the EDID which I've already shown above):
Code:
<6>[ 602.079619] [otm_hdmi]: __hdmi_irq_handler_bottomhalf: hdmi state switched to 0
EDID SHOWN HERE
EDID SHOWN HERE AGAIN
<6>[ 603.043781] [drm] setting fifo size, arb2:0xc0300, arb: 0x20080100
<6>[ 603.043800] [drm] dsp stride=7680 bpp=32
<6>[ 603.046468] request_suspend_state: wakeup (3->0) at 602839491618 (2015-05-27 13:05:29.417151656 UTC)
<6>[ 603.067435] it8566_hdmi_cec 1-0068: cec tx bus err
<6>[ 603.097477] it8566_hdmi_cec 1-0068: cec tx bus err
<6>[ 603.138095] it8566_hdmi_cec 1-0068: cec tx bus err
<6>[ 603.144209] [otm_hdmi]: android_hdmi_encoder_dpms: hdmi state switched to 1
<6>[ 603.167878] it8566_hdmi_cec 1-0068: cec tx bus err
<3>[ 603.188058] had: had is not in suspended state
<4>[ 603.188098] dhd_set_suspend: Remove extra suspend setting
EDID SHOWN HERE
<6>[ 603.208366] it8566_hdmi_cec 1-0068: cec tx bus err
<6>[ 603.238509] it8566_hdmi_cec 1-0068: cec tx bus err
<6>[ 603.278478] it8566_hdmi_cec 1-0068: cec tx bus err
<6>[ 603.307996] it8566_hdmi_cec 1-0068: cec tx bus err
<6>[ 603.347109] it8566_hdmi_cec 1-0068: cec tx bus err
<6>[ 603.376730] it8566_hdmi_cec 1-0068: cec tx bus err
<6>[ 603.438371] it8566_hdmi_cec 1-0068: cec tx direct nack / bcst reject
<6>[ 603.489896] it8566_hdmi_cec 1-0068: cec tx direct nack / bcst reject
<6>[ 603.676647] it8566_hdmi_cec 1-0068: cec tx bus err
<6>[ 603.706179] it8566_hdmi_cec 1-0068: cec tx bus err
At this point I'm stumped about how to resolve this - I just restart the NP every time I turn the TV on. Has anyone had any experience with this issue and know of any fixes I can try?
Thanks for the help!
I am seeing the same exact issue with my Nexus Player after I power cycle my Panasonic VT60 TV or receiver. I assumed the picture was 720p being upscaled internally by the NP at first as well, since the TV indicated a 1080p/60Hz signal.
The slight blurriness that causes me to be unable to distinguish individual pixels looks almost identical to upscaled 720p input on this and other TVs.
As in your case, power cycling the player gets the correct, non-blurry output back, and it appears the NP still believes it is rendering a 1080p picture in either case.
So it's not just me then!
For what it's worth, I upgraded to Android M but the problem remained. I've now switched to a Nvidia Shield which works perfectly, suggesting that the issue is specific to the NP and not Android TV.
Hope you find a fix.

usb tether packet frame errors under linux

On usb tether to my linux notebook, I get about 1Mbps down and 14Mbps up. Using the speedtest on the phone, I get 16Mbps down and 6MBPS up. Yes I know these results are not repeatable, but I consistently can't break 1Mbps download on tether. Further down I will show this is related to packet framing errors.
But first, device data. The OnePlus5 is running Android 7.1.1 Oxygen 4.5.10 Oneplus A5000. This is the 128G flash/ 8G ram version.
Notebook data:
Code:
Linux linux-0u81 4.4.79-19-default #1 SMP Thu Aug 10 20:28:47 UTC 2017 (2dd03e8) x86_64 x86_64 x86_64 GNU/Linux
Output of lsusb for the phone follows, but note this message:
iInterface 5 RNDIS Communications Control
** UNRECOGNIZED: 05 24 00 10 01
** UNRECOGNIZED: 05 24 01 00 01
** UNRECOGNIZED: 04 24 02 00
** UNRECOGNIZED: 05 24 06 00 01
Click to expand...
Click to collapse
Code:
Device Descriptor:
bLength 18
bDescriptorType 1
bcdUSB 2.10
bDeviceClass 0 (Defined at Interface level)
bDeviceSubClass 0
bDeviceProtocol 0
bMaxPacketSize0 64
idVendor 0x2a70
idProduct 0xf00e
bcdDevice 4.04
iManufacturer 1 OnePlus
iProduct 2 OnePlus
iSerial 3 (censored)
bNumConfigurations 1
Configuration Descriptor:
bLength 9
bDescriptorType 2
wTotalLength 75
bNumInterfaces 2
bConfigurationValue 1
iConfiguration 4 rndis
bmAttributes 0x80
(Bus Powered)
MaxPower 500mA
Interface Association:
bLength 8
bDescriptorType 11
bFirstInterface 0
bInterfaceCount 2
bFunctionClass 224 Wireless
bFunctionSubClass 1 Radio Frequency
bFunctionProtocol 3 RNDIS
iFunction 7 RNDIS
Interface Descriptor:
bLength 9
bDescriptorType 4
bInterfaceNumber 0
bAlternateSetting 0
bNumEndpoints 1
bInterfaceClass 224 Wireless
bInterfaceSubClass 1 Radio Frequency
bInterfaceProtocol 3 RNDIS
iInterface 5 RNDIS Communications Control
** UNRECOGNIZED: 05 24 00 10 01
** UNRECOGNIZED: 05 24 01 00 01
** UNRECOGNIZED: 04 24 02 00
** UNRECOGNIZED: 05 24 06 00 01
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x81 EP 1 IN
bmAttributes 3
Transfer Type Interrupt
Synch Type None
Usage Type Data
wMaxPacketSize 0x0008 1x 8 bytes
bInterval 9
Interface Descriptor:
bLength 9
bDescriptorType 4
bInterfaceNumber 1
bAlternateSetting 0
bNumEndpoints 2
bInterfaceClass 10 CDC Data
bInterfaceSubClass 0 Unused
bInterfaceProtocol 0
iInterface 6 RNDIS Ethernet Data
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x8e EP 14 IN
bmAttributes 2
Transfer Type Bulk
Synch Type None
Usage Type Data
wMaxPacketSize 0x0200 1x 512 bytes
bInterval 0
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x0f EP 15 OUT
bmAttributes 2
Transfer Type Bulk
Synch Type None
Usage Type Data
wMaxPacketSize 0x0200 1x 512 bytes
bInterval 0
Binary Object Store Descriptor:
bLength 5
bDescriptorType 15
wTotalLength 12
bNumDeviceCaps 1
USB 2.0 Extension Device Capability:
bLength 7
bDescriptorType 16
bDevCapabilityType 2
bmAttributes 0x00000006
Link Power Management (LPM) Supported
Device Status: 0x0000
(Bus Powered)
Test Data (for nitpickers):
(removed due to forum rules but available on request.)
Note only the RX path has frame errors:
Code:
usb0 Link encap:Ethernet HWaddr (censored)
inet addr:192.168.42.215 Bcast:192.168.42.255 Mask:255.255.255.0
inet6 addr: 2607:fb90:8635:67b8:78a2:7bff:febe:7afb/128 Scope:Global
inet6 addr: fe80::78a2:7bff:febe:7afb/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:12497 errors:1062 dropped:0 overruns:0 frame:1058
TX packets:22595 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:4121815 (3.9 Mb) TX bytes:27795493 (26.5 Mb)
I have run this on Opensuse, Fedora, Mint, and Ubuntu with similar results.
It would be useful if someone could duplicate this. I don't think the flavor of linux matters. I don't have a problem on windows.
Using the google on the interwebs, there is some chatter about RNDIS being dropped on "later" versions of Android. Reality? Perhaps OnePlus has attempted to add it back and didn't do it correctly.
I should also point out I'm using Tmobile, which is a IPV6 system. I'm using the Linux "network manager", but using "wicked" produced the same error.
I'm encountering the same issue.
Any hint on how to resolve it?
Sorry about the late reply. I'm not a regular here.
If you are on a OnePlus, please complain to them. I still have no solution.
This appears to be fixed on Oxygen OS rev 4.5.14
usb0 Link encap:Ethernet
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:13690 errors:0 dropped:0 overruns:0 frame:0
TX packets:11644 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:15616702 (14.8 Mb) TX bytes:8406490 (8.0 Mb)
yes 4.5.14 worked for me another thread here
https://forum.xda-developers.com/oneplus-5/help/slow-tether-usb-t3649501

G4H Kids smartwatch ?

hi
I got my hands on this smartwatch
https://www.amazon.com/gp/product/B07XTCGD7B
It seems to be a "G4H" kids smartwatch, which seems to be available from multiple vendors.
It seems to be running Android...
It has a pogopin based charging adapter, where the middle 3 pins are not usually connected but seem to be "USB pins"
I opened this up and I was able to find a ribbon cable G4E-USB-FPC-V0.1. / F6-2C connecting those pins to the PCB.
I bet someone make a USB data cable which also has connections to those middle pins.
[ Perhaps this one https://www.alibaba.com/product-detail/high-quality-custom-male-gold-plating_62427401556.html ]
Has anyone tried to hack this one yet ? Anyone knows what those middle 3 pins are ?
Any hints on putting this device into recovery mode or fastboot mode ?
G
Update: 2020-09-26
I got a 4 pin smartwatch fast charging cable
from EBAY. This now Charges and also gets me to connect to the watch as USB... I can do a lsusb on the device from my Rpi Linux.
lsusb -v
Code:
Bus 001 Device 065: ID 1782:5d03 Spreadtrum Communications Inc.
Couldn't open device, some information will be missing
Device Descriptor:
bLength 18
bDescriptorType 1
bcdUSB 2.00
bDeviceClass 0
bDeviceSubClass 0
bDeviceProtocol 0
bMaxPacketSize0 64
idVendor 0x1782 Spreadtrum Communications Inc.
idProduct 0x5d03
bcdDevice 4.04
iManufacturer 1
iProduct 2
iSerial 3
bNumConfigurations 1
Configuration Descriptor:
bLength 9
bDescriptorType 2
wTotalLength 0x0020
bNumInterfaces 1
bConfigurationValue 1
iConfiguration 4
bmAttributes 0xc0
Self Powered
MaxPower 500mA
Interface Descriptor:
bLength 9
bDescriptorType 4
bInterfaceNumber 0
bAlternateSetting 0
bNumEndpoints 2
bInterfaceClass 8 Mass Storage
bInterfaceSubClass 6 SCSI
bInterfaceProtocol 80 Bulk-Only
iInterface 5
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x81 EP 1 IN
bmAttributes 2
Transfer Type Bulk
Synch Type None
Usage Type Data
wMaxPacketSize 0x0200 1x 512 bytes
bInterval 0
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x01 EP 1 OUT
bmAttributes 2
Transfer Type Bulk
Synch Type None
Usage Type Data
wMaxPacketSize 0x0200 1x 512 bytes
bInterval 1
PS: India based dev's, (we cannot really stop made-in-china, but we can at-least reflash all the made-in-china with AOSP)
[PS => Political Statement :cyclops: )
Some more Info:
https://omg-solutions.com/gps-tracker/latest-singapore-waterproof-video-call-gps-kids-watch-gps033w/
https://riseofsmart.com/smartwatche...ch-display-camera-take-video-smartwatch-kids/
https://www.flipkart.com/arroha-kids-smart-watch-gps-wifi-4g-smartwatch/p/itm40654c01873c8
https://naijarom.com/infinity-chinese-miracle-2-spd-v124
https://forum.hovatek.com/thread-21776.html
https://www.gadgetvictims.com/2017/07/diy-magnetic-charger-for-kingwear-lemfo.html
LEMFO is one of the manufacturers/brand names
Its using SC9820E from http://www.unisoc.com/sc9820e
https://sc9820e-datasheet.com/
The Wireless MAC on the device starts with
"40-45-DA" which is for...
Spreadtrum Communications (Shanghai) Co., Ltd.
Building 1, Spreadtrum Center, No.2288, Zuchongzhi Rd
Shanghai 201203
The build number seems to be G4H_EMMC_OVERSEA_240_5M_akq_IPS_w_2020.07.09_09.55.00, on the watch depicted in the pictures.
I also have another similar device whish has build number as G4H_EMMC_240_5M_YDE_A36H_OVERSEA_LINE_20200506_10.35.00
Looks like the Nokia 3310-4G is also powered by the same chipset
https://www.gizmochina.com/2018/03/26/nokia-3310-4g-packs-spreadtrum-sc9820-chipset/
The phone seems to be using "YunOS" which is some version of AOSP, also called AliOS (Alibaba version)
Does anyone have the Nokia 3310-4G model #TA-1077
ghatothkach said:
hi
I got my hands on this smartwatch
https://www.amazon.com/gp/product/B07XTCGD7B
It seems to be a "G4H" kids smartwatch, which seems to be available from multiple vendors.
It seems to be running Android...
It has a pogopin based charging adapter, where the middle 3 pins are not usually connected but seem to be "USB pins"
I opened this up and I was able to find a ribbon cable G4E-USB-FPC-V0.1. / F6-2C connecting those pins to the PCB.
I bet someone make a USB data cable which also has connections to those middle pins.
[ Perhaps this one https://www.alibaba.com/product-detail/high-quality-custom-male-gold-plating_62427401556.html ]
Has anyone tried to hack this one yet ? Anyone knows what those middle 3 pins are ?
Any hints on putting this device into recovery mode or fastboot mode ?
G
Update: 2020-09-26
I got a 4 pin smartwatch fast charging cable
from EBAY. This now Charges and also gets me to connect to the watch as USB... I can do a lsusb on the device from my Rpi Linux.
lsusb -v
Code:
Bus 001 Device 065: ID 1782:5d03 Spreadtrum Communications Inc.
Couldn't open device, some information will be missing
Device Descriptor:
bLength 18
bDescriptorType 1
bcdUSB 2.00
bDeviceClass 0
bDeviceSubClass 0
bDeviceProtocol 0
bMaxPacketSize0 64
idVendor 0x1782 Spreadtrum Communications Inc.
idProduct 0x5d03
bcdDevice 4.04
iManufacturer 1
iProduct 2
iSerial 3
bNumConfigurations 1
Configuration Descriptor:
bLength 9
bDescriptorType 2
wTotalLength 0x0020
bNumInterfaces 1
bConfigurationValue 1
iConfiguration 4
bmAttributes 0xc0
Self Powered
MaxPower 500mA
Interface Descriptor:
bLength 9
bDescriptorType 4
bInterfaceNumber 0
bAlternateSetting 0
bNumEndpoints 2
bInterfaceClass 8 Mass Storage
bInterfaceSubClass 6 SCSI
bInterfaceProtocol 80 Bulk-Only
iInterface 5
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x81 EP 1 IN
bmAttributes 2
Transfer Type Bulk
Synch Type None
Usage Type Data
wMaxPacketSize 0x0200 1x 512 bytes
bInterval 0
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x01 EP 1 OUT
bmAttributes 2
Transfer Type Bulk
Synch Type None
Usage Type Data
wMaxPacketSize 0x0200 1x 512 bytes
bInterval 1
PS: India based dev's, (we cannot really stop made-in-china, but we can at-least reflash all the made-in-china with AOSP)
[PS => Political Statement :cyclops: )
Some more Info:
https://omg-solutions.com/gps-tracker/latest-singapore-waterproof-video-call-gps-kids-watch-gps033w/
https://riseofsmart.com/smartwatche...ch-display-camera-take-video-smartwatch-kids/
https://www.flipkart.com/arroha-kids-smart-watch-gps-wifi-4g-smartwatch/p/itm40654c01873c8
https://naijarom.com/infinity-chinese-miracle-2-spd-v124
https://forum.hovatek.com/thread-21776.html
https://www.gadgetvictims.com/2017/07/diy-magnetic-charger-for-kingwear-lemfo.html
LEMFO is one of the manufacturers/brand names
Its using SC9820E from http://www.unisoc.com/sc9820e
https://sc9820e-datasheet.com/
The Wireless MAC on the device starts with
"40-45-DA" which is for...
Spreadtrum Communications (Shanghai) Co., Ltd.
Building 1, Spreadtrum Center, No.2288, Zuchongzhi Rd
Shanghai 201203
The build number seems to be G4H_EMMC_OVERSEA_240_5M_akq_IPS_w_2020.07.09_09.55.00, on the watch depicted in the pictures.
I also have another similar device whish has build number as G4H_EMMC_240_5M_YDE_A36H_OVERSEA_LINE_20200506_10.35.00
Looks like the Nokia 3310-4G is also powered by the same chipset
https://www.gizmochina.com/2018/03/26/nokia-3310-4g-packs-spreadtrum-sc9820-chipset/
The phone seems to be using "YunOS" which is some version of AOSP, also called AliOS (Alibaba version)
Does anyone have the Nokia 3310-4G model #TA-1077
Click to expand...
Click to collapse
Hi, can you pull the system os using adb?
That can help you to get the drivers, if you want to port another watch os.
hi
I cannot get ADB to work yet
G
Hello, Have you connected with adb? I opened the system engineer mode with dial *#*#83781#*#* But under Debug&Log tab, there is no enable debug mode. I think, If I can open debug mode, I can connect with adb.
Thanks you all for those useful info. I have a watch like this. One of the things I am interested is to turn the watch's LTE to a wifi hotspot for other devices, and I found a way to do so, though not very convenience. I am posting the instruction here. Hopefully it is useful to others, and maybe there is a better way to do so:
From Phone, dial *#*#83781#*#* to enter Engineer Mode
Under Connectivity tab, “Start Services”, the go to “Sfatap Wifi Channel”, toggle Auto (off->on->off), then “OK” when seeing “Auto Close Warning”. Optionally choose a 2.4GHz Wifi Channel
Back to the top/root screen, slide from the screen top, and choose the little blue icon at the upper-left most corner to setup Wifi hotspot’s name, security mode (open, WPA PSK, WPA2 PSK) and password.
Note that enabling hotspot will disable the watch's wifi to internet. Any change such as, reboot, turning off hotspot in 3), or enabling wifi will shutdown the hotspot. To enable again, repeat step 1-2 (settings in 3 is saved)
I have same watch. After changing one parameter in Engineer mode, shartwatch doesn't recognize the SIM card and restarts automatically 1 min after boot.
Can you please support how to fix this issue? is there any possibility to do a factory reset using the button on Watch?
Or restore Engineer Mode to default?
THX a lot in advance
ghatothkach said:
hi
I got my hands on this smartwatch
https://www.amazon.com/gp/product/B07XTCGD7B
It seems to be a "G4H" kids smartwatch, which seems to be available from multiple vendors.
It seems to be running Android...
It has a pogopin based charging adapter, where the middle 3 pins are not usually connected but seem to be "USB pins"
I opened this up and I was able to find a ribbon cable G4E-USB-FPC-V0.1. / F6-2C connecting those pins to the PCB.
I bet someone make a USB data cable which also has connections to those middle pins.
[ Perhaps this one https://www.alibaba.com/product-detail/high-quality-custom-male-gold-plating_62427401556.html ]
Has anyone tried to hack this one yet ? Anyone knows what those middle 3 pins are ?
Any hints on putting this device into recovery mode or fastboot mode ?
G
Update: 2020-09-26
I got a 4 pin smartwatch fast charging cable
from EBAY. This now Charges and also gets me to connect to the watch as USB... I can do a lsusb on the device from my Rpi Linux.
lsusb -v
Code:
Bus 001 Device 065: ID 1782:5d03 Spreadtrum Communications Inc.
Couldn't open device, some information will be missing
Device Descriptor:
bLength 18
bDescriptorType 1
bcdUSB 2.00
bDeviceClass 0
bDeviceSubClass 0
bDeviceProtocol 0
bMaxPacketSize0 64
idVendor 0x1782 Spreadtrum Communications Inc.
idProduct 0x5d03
bcdDevice 4.04
iManufacturer 1
iProduct 2
iSerial 3
bNumConfigurations 1
Configuration Descriptor:
bLength 9
bDescriptorType 2
wTotalLength 0x0020
bNumInterfaces 1
bConfigurationValue 1
iConfiguration 4
bmAttributes 0xc0
Self Powered
MaxPower 500mA
Interface Descriptor:
bLength 9
bDescriptorType 4
bInterfaceNumber 0
bAlternateSetting 0
bNumEndpoints 2
bInterfaceClass 8 Mass Storage
bInterfaceSubClass 6 SCSI
bInterfaceProtocol 80 Bulk-Only
iInterface 5
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x81 EP 1 IN
bmAttributes 2
Transfer Type Bulk
Synch Type None
Usage Type Data
wMaxPacketSize 0x0200 1x 512 bytes
bInterval 0
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x01 EP 1 OUT
bmAttributes 2
Transfer Type Bulk
Synch Type None
Usage Type Data
wMaxPacketSize 0x0200 1x 512 bytes
bInterval 1
PS: India based dev's, (we cannot really stop made-in-china, but we can at-least reflash all the made-in-china with AOSP)
[PS => Political Statement :cyclops: )
Some more Info:
https://omg-solutions.com/gps-tracker/latest-singapore-waterproof-video-call-gps-kids-watch-gps033w/
https://riseofsmart.com/smartwatche...ch-display-camera-take-video-smartwatch-kids/
https://www.flipkart.com/arroha-kids-smart-watch-gps-wifi-4g-smartwatch/p/itm40654c01873c8
https://naijarom.com/infinity-chinese-miracle-2-spd-v124
https://forum.hovatek.com/thread-21776.html
https://www.gadgetvictims.com/2017/07/diy-magnetic-charger-for-kingwear-lemfo.html
LEMFO is one of the manufacturers/brand names
Its using SC9820E from http://www.unisoc.com/sc9820e
https://sc9820e-datasheet.com/
The Wireless MAC on the device starts with
"40-45-DA" which is for...
Spreadtrum Communications (Shanghai) Co., Ltd.
Building 1, Spreadtrum Center, No.2288, Zuchongzhi Rd
Shanghai 201203
The build number seems to be G4H_EMMC_OVERSEA_240_5M_akq_IPS_w_2020.07.09_09.55.00, on the watch depicted in the pictures.
I also have another similar device whish has build number as G4H_EMMC_240_5M_YDE_A36H_OVERSEA_LINE_20200506_10.35.00
Looks like the Nokia 3310-4G is also powered by the same chipset
https://www.gizmochina.com/2018/03/26/nokia-3310-4g-packs-spreadtrum-sc9820-chipset/
The phone seems to be using "YunOS" which is some version of AOSP, also called AliOS (Alibaba version)
Does anyone have the Nokia 3310-4G model #TA-1077
Click to expand...
Click to collapse
Have you tried to send a text message to turn on debug mode? try this (no space): pw,123456,DEVELOP,1#
ghatothkach said:
hi
I got my hands on this smartwatch
https://www.amazon.com/gp/product/B07XTCGD7B
It seems to be a "G4H" kids smartwatch, which seems to be available from multiple vendors.
It seems to be running Android...
It has a pogopin based charging adapter, where the middle 3 pins are not usually connected but seem to be "USB pins"
I opened this up and I was able to find a ribbon cable G4E-USB-FPC-V0.1. / F6-2C connecting those pins to the PCB.
I bet someone make a USB data cable which also has connections to those middle pins.
[ Perhaps this one https://www.alibaba.com/product-detail/high-quality-custom-male-gold-plating_62427401556.html ]
Has anyone tried to hack this one yet ? Anyone knows what those middle 3 pins are ?
Any hints on putting this device into recovery mode or fastboot mode ?
G
Update: 2020-09-26
I got a 4 pin smartwatch fast charging cable
from EBAY. This now Charges and also gets me to connect to the watch as USB... I can do a lsusb on the device from my Rpi Linux.
lsusb -v
Code:
Bus 001 Device 065: ID 1782:5d03 Spreadtrum Communications Inc.
Couldn't open device, some information will be missing
Device Descriptor:
bLength 18
bDescriptorType 1
bcdUSB 2.00
bDeviceClass 0
bDeviceSubClass 0
bDeviceProtocol 0
bMaxPacketSize0 64
idVendor 0x1782 Spreadtrum Communications Inc.
idProduct 0x5d03
bcdDevice 4.04
iManufacturer 1
iProduct 2
iSerial 3
bNumConfigurations 1
Configuration Descriptor:
bLength 9
bDescriptorType 2
wTotalLength 0x0020
bNumInterfaces 1
bConfigurationValue 1
iConfiguration 4
bmAttributes 0xc0
Self Powered
MaxPower 500mA
Interface Descriptor:
bLength 9
bDescriptorType 4
bInterfaceNumber 0
bAlternateSetting 0
bNumEndpoints 2
bInterfaceClass 8 Mass Storage
bInterfaceSubClass 6 SCSI
bInterfaceProtocol 80 Bulk-Only
iInterface 5
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x81 EP 1 IN
bmAttributes 2
Transfer Type Bulk
Synch Type None
Usage Type Data
wMaxPacketSize 0x0200 1x 512 bytes
bInterval 0
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x01 EP 1 OUT
bmAttributes 2
Transfer Type Bulk
Synch Type None
Usage Type Data
wMaxPacketSize 0x0200 1x 512 bytes
bInterval 1
PS: India based dev's, (we cannot really stop made-in-china, but we can at-least reflash all the made-in-china with AOSP)
[PS => Political Statement :cyclops: )
Some more Info:
https://omg-solutions.com/gps-tracker/latest-singapore-waterproof-video-call-gps-kids-watch-gps033w/
https://riseofsmart.com/smartwatche...ch-display-camera-take-video-smartwatch-kids/
https://www.flipkart.com/arroha-kids-smart-watch-gps-wifi-4g-smartwatch/p/itm40654c01873c8
https://naijarom.com/infinity-chinese-miracle-2-spd-v124
https://forum.hovatek.com/thread-21776.html
https://www.gadgetvictims.com/2017/07/diy-magnetic-charger-for-kingwear-lemfo.html
LEMFO is one of the manufacturers/brand names
Its using SC9820E from http://www.unisoc.com/sc9820e
https://sc9820e-datasheet.com/
The Wireless MAC on the device starts with
"40-45-DA" which is for...
Spreadtrum Communications (Shanghai) Co., Ltd.
Building 1, Spreadtrum Center, No.2288, Zuchongzhi Rd
Shanghai 201203
The build number seems to be G4H_EMMC_OVERSEA_240_5M_akq_IPS_w_2020.07.09_09.55.00, on the watch depicted in the pictures.
I also have another similar device whish has build number as G4H_EMMC_240_5M_YDE_A36H_OVERSEA_LINE_20200506_10.35.00
Looks like the Nokia 3310-4G is also powered by the same chipset
https://www.gizmochina.com/2018/03/26/nokia-3310-4g-packs-spreadtrum-sc9820-chipset/
The phone seems to be using "YunOS" which is some version of AOSP, also called AliOS (Alibaba version)
Does anyone have the Nokia 3310-4G model #TA-1077
Click to expand...
Click to collapse
Try this tutorial to enable adb/root: https://github.com/eisaev/SuperSUInstaller
Hi! I got a G4H(KGG KG70) watch as well for my kid, problem is that touch does work, every second time I turn on/off the screen. It worked perfectly before, but now it only works every second time I turn on/off the screen. I think that might be a software issue.
I've just started to research so haven't got far, any things I might could try?
The watch works perfectly other then that, but sometimes have trouble get the location.
Hello there. I bought this watch for my child, but when I want to use another tracking program other than the se tracker program, I cannot change the ip number. Can you help me with this?
aşağıdaki kod çalışmıyor.
Find my kids application server: pw,123456,ip,tcp.findmykids.org,8001#
afyden2018 said:
when I want to use another tracking program other than the se tracker program, I cannot change the ip number.
Click to expand...
Click to collapse
Protocols for "SeTracker" and "Где мои дети" are different. It is not the matter of changing IP, findmykids.org won't understand data sent by SeTracker service from watch.
Also "Где мои дети" is compiled only for Android 5.0+ while this watch runs Android 4.4. So event with watch rooted (described in this thread) you cannot install proper service on watch that will report location to findmykids.org. Maybe they had some Android 4.4 compatible version in the past, but it is highly unlikely this will still work today.
bbkr said:
Protocols for "SeTracker" and "Где мои дети" are different. It is not the matter of changing IP, findmykids.org won't understand data sent by SeTracker service from watch.
Also "Где мои дети" is compiled only for Android 5.0+ while this watch runs Android 4.4. So event with watch rooted (described in this thread) you cannot install proper service on watch that will report location to findmykids.org. Maybe they had some Android 4.4 compatible version in the past, but it is highly unlikely this will still work today.
Click to expand...
Click to collapse
Since I couldn't find any more resources about g4h, I asked for help under this topic. The link to the watch I actually bought is below. If I can change the server of the watch with the sms sent to the watch, maybe I can switch to an application other than tracker. Engineering mode opens but I don't know how to do it.
https://tr.aliexpress.com/item/1005002878573395.html?spm=a2g0s.9042311.0.0.1cc04c4dVwpHt3
I hope someone here can help me out. I recently purchased this watch for my daughter and have purchased a Lucky Mobile SIM card to use with it. I’ve not been able to get the watch to connect to the mobile network. The person that is trying to help me from their end has been less than helpful lol. He’s now insisting that I’m putting the SIM card in wrong and I have had to send a video to prove to him that isn’t the case.
I went into the network portions and noticed they had only set up an APN for Bell, so now I have set up the APN for lucky mobile. Yet still no luck (groan)
Can anyone give me some suggestions on how to get this thing to work. Or tell me what provider you went with (in Canada) to get this thing to work?
I really appreciate any help I can get at this point.
I sent pw,123456,DEVELOP,1# to my device and I can connect to it via adb. Once 'adb -d shell', I am in the system but don't know what to do. On the watch's system, process 'adbd' runs under user 'shell'.
A bit more info of the watch (I am not an Android expert)
# ./adb -d shell
[email protected]:/ $ cat /proc/version
Linux version 4.4.83+ ([email protected]) (gcc version 4.8 (GCC) ) #1 SMP PREEMPT Thu Aug 22 16:00:23 CST 2019
[email protected]:/ $ cat /proc/cpuinfo
processor : 0
model name : ARMv8 Processor
BogoMIPS : 30.72
Features : half thumb fastmult vfp edsp neon vfpv3 tls vfpv4 idiva idivt vfpd32 lpae aes pmull sha1 sha2 crc32
CPU implementer : 0x41
CPU architecture: 8
CPU variant : 0x0
CPU part : 0xd03
CPU revision : 4
processor : 1
model name : ARMv8 Processor
BogoMIPS : 30.72
Features : half thumb fastmult vfp edsp neon vfpv3 tls vfpv4 idiva idivt vfpd32 lpae aes pmull sha1 sha2 crc32
CPU implementer : 0x41
CPU architecture: 8
CPU variant : 0x0
CPU part : 0xd03
CPU revision : 4
Hardware : Spreadtrum SC9820e
Revision : 0000
Serial : 0000000000000000
[email protected]:/ $ cat /proc/meminfo
MemTotal: 438400 kB
MemFree: 102396 kB
MemAvailable: 257892 kB
Buffers: 5124 kB
Cached: 130896 kB
SwapCached: 4052 kB
...
[email protected]:/ $ df
Filesystem Size Used Avail Free Blksize
/dev 214.1M 128.0K 213.9M 213.9M 4096
/sys/fs/cgroup 214.1M 12.0K 214.1M 214.1M 4096
/mnt/asec 214.1M 0.0K 214.1M 214.1M 4096
/mnt/obb 214.1M 0.0K 214.1M 214.1M 4096
/system 484.3M 294.0M 180.3M 190.3M 4096
/data 2.7G 9.6M 2.7G 2.7G 4096
/cache 143.6M 168.0K 140.5M 143.5M 4096
/productinfo 928.0K 96.0K 732.0K 832.0K 4096
/mnt/shell/emulated 2.7G 9.6M 2.7G 2.7G 4096
Also, I found some useful tools like "am" and "pm"
Found a useful thread: https://forum.xda-developers.com/t/...-and-rebrands-kinyo-garett-lemfo-etc.4332727/
Hi
ghatothkach said:
hi
I got my hands on this smartwatch
https://www.amazon.com/gp/product/B07XTCGD7B
It seems to be a "G4H" kids smartwatch, which seems to be available from multiple vendors.
It seems to be running Android...
It has a pogopin based charging adapter, where the middle 3 pins are not usually connected but seem to be "USB pins"
I opened this up and I was able to find a ribbon cable G4E-USB-FPC-V0.1. / F6-2C connecting those pins to the PCB.
I bet someone make a USB data cable which also has connections to those middle pins.
[ Perhaps this one https://www.alibaba.com/product-detail/high-quality-custom-male-gold-plating_62427401556.html ]
Has anyone tried to hack this one yet ? Anyone knows what those middle 3 pins are ?
Any hints on putting this device into recovery mode or fastboot mode ?
G
Update: 2020-09-26
I got a 4 pin smartwatch fast charging cable
from EBAY. This now Charges and also gets me to connect to the watch as USB... I can do a lsusb on the device from my Rpi Linux.
lsusb -v
Code:
Bus 001 Device 065: ID 1782:5d03 Spreadtrum Communications Inc.
Couldn't open device, some information will be missing
Device Descriptor:
bLength 18
bDescriptorType 1
bcdUSB 2.00
bDeviceClass 0
bDeviceSubClass 0
bDeviceProtocol 0
bMaxPacketSize0 64
idVendor 0x1782 Spreadtrum Communications Inc.
idProduct 0x5d03
bcdDevice 4.04
iManufacturer 1
iProduct 2
iSerial 3
bNumConfigurations 1
Configuration Descriptor:
bLength 9
bDescriptorType 2
wTotalLength 0x0020
bNumInterfaces 1
bConfigurationValue 1
iConfiguration 4
bmAttributes 0xc0
Self Powered
MaxPower 500mA
Interface Descriptor:
bLength 9
bDescriptorType 4
bInterfaceNumber 0
bAlternateSetting 0
bNumEndpoints 2
bInterfaceClass 8 Mass Storage
bInterfaceSubClass 6 SCSI
bInterfaceProtocol 80 Bulk-Only
iInterface 5
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x81 EP 1 IN
bmAttributes 2
Transfer Type Bulk
Synch Type None
Usage Type Data
wMaxPacketSize 0x0200 1x 512 bytes
bInterval 0
Endpoint Descriptor:
bLength 7
bDescriptorType 5
bEndpointAddress 0x01 EP 1 OUT
bmAttributes 2
Transfer Type Bulk
Synch Type None
Usage Type Data
wMaxPacketSize 0x0200 1x 512 bytes
bInterval 1
PS: India based dev's, (we cannot really stop made-in-china, but we can at-least reflash all the made-in-china with AOSP)
[PS => Political Statement :cyclops: )
Some more Info:
https://omg-solutions.com/gps-tracker/latest-singapore-waterproof-video-call-gps-kids-watch-gps033w/
https://riseofsmart.com/smartwatche...ch-display-camera-take-video-smartwatch-kids/
https://www.flipkart.com/arroha-kids-smart-watch-gps-wifi-4g-smartwatch/p/itm40654c01873c8
https://naijarom.com/infinity-chinese-miracle-2-spd-v124
https://forum.hovatek.com/thread-21776.html
https://www.gadgetvictims.com/2017/07/diy-magnetic-charger-for-kingwear-lemfo.html
LEMFO is one of the manufacturers/brand names
Its using SC9820E from http://www.unisoc.com/sc9820e
https://sc9820e-datasheet.com/
The Wireless MAC on the device starts with
"40-45-DA" which is for...
Spreadtrum Communications (Shanghai) Co., Ltd.
Building 1, Spreadtrum Center, No.2288, Zuchongzhi Rd
Shanghai 201203
The build number seems to be G4H_EMMC_OVERSEA_240_5M_akq_IPS_w_2020.07.09_09.55.00, on the watch depicted in the pictures.
I also have another similar device whish has build number as G4H_EMMC_240_5M_YDE_A36H_OVERSEA_LINE_20200506_10.35.00
Looks like the Nokia 3310-4G is also powered by the same chipset
https://www.gizmochina.com/2018/03/26/nokia-3310-4g-packs-spreadtrum-sc9820-chipset/
The phone seems to be using "YunOS" which is some version of AOSP, also called AliOS (Alibaba version)
Does anyone have the Nokia 3310-4G model #TA-1077
Click to expand...
Click to collapse
You can putting that device to recovery mode or fastboot mode like this with a application name power toggles *required root
i have the samw watches, i have installed shotcut creator, but when i'm starting "settings" app it launching an ROM settings and i could not enable ADB to root and then flash my watches, i have tried to use engineer mode but it isn't doing anything really useful
wait, i know a way, i think i can enable ADB via "Hidden MIUI settings" and it's not for MIUI only, i tesetd it works on custom roms

Categories

Resources