HIMALAYA ->Storage and ExtROM merged ... Dream or reality - Windows Mobile Development and Hacking General
Hello all !!
I've found some interesting things .
I've read all posts about magician bigstorage rom and it appears that the config of storage size is coded on two location in rom .
One of this location is , like buzz think , in nk.exe :
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
in red , #B801h is the size of BigStorage , like this :
code B8 01 = 01 B8 00 00 = 27.5 Mb
I've extracted the nk.exe file of the french wm2005 rom with help of itsme's utils , and i've search bytes like 74F4h (sectors) or EA0000h (size) (thank's buzz) .
However, I’ve a question to buzz :
You say the storage partition (FAT1) have 29940 sectors (#74F4h) but if I divide #EA0000h (the size) with 512 , that’s #7500h sectors ….
I've found this :
in red , maybe the number of sectors ?
in blue , maybe the size ? (like in magician rom)
code EA 00 = 00 EA 00 00 = 14.625 Mb
Who knows ....
I've search the same bytes in sd backuped rom and there is only two location , ( like in magician rom ) at offset #1423D8h and #3C138Ah
I've tried to change 74F4h in F4F4h , EA00h in EA01h (like coded in magician's rom) , but without success .
DOC in himalaya is managed with TrueFFS.dll , but we can't extract it at this time ... I think this dll is the key of problem .
ok , finally , i've tried to change in sd backuped rom , all the 0000ae00 in 0000ae10 and after all the 00ea0000 in 01ea0000 without succes .....
i examine the bootloader operation during an update of wm2003 ( Osrom + Radio rom + Ext rom ) and i think the DiskOnChip is never partitioned by bootloader or os ....
I think that the partition table is coded directly in DOC ....
during the upgrade , just before upgrading the extrom , HimaUpgradeUt.exe send an hexa code like this :
Code:
FE0300EA000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
4543454318AC0F800000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
D300A0E300F021E110099FE530A0D0E5
08099FE50110A0E31C1080E5990100EB
0E901AE21100001AF4089FE50210A0E3
081080E5EC289FE50C2083E50C2093E5
E4089FE51F10A0E3001080E5DC089FE5
0710A0E3001080E5CC089FE52810A0E3
001080E5C4089FE59710A0E3001080E5
100F10EEFF0000E2050050E3010000AA
0000A0E3000000EA0100A0E3000050E3
0200000A98189FE50020A0E3010000EA
90189FE50120A0E374089FE5001080E5
0200A0E3100E06EE102E06EE78389FE5
0020A0E3102083E5034CA0E3102093E5
020054E1FCFFFFCA1233A0E35C289FE5
082083E5082093E538289FE50C2083E5
0C2093E548289FE5102083E5102093E5
042093E53C489FE50420C2E1182082E3
042083E50A48A0E3042093E50E25C2E3
022A82E3012882E3012782E30420C2E1
042083E5042093E50125C2E3042083E5
012A82E3022982E3042083E50000A0E1
0000A0E1F0279FE5002083E5D8379FE5
0020A0E3102083E5034CA0E3102093E5
020054E1FCFFFFCA7800A0E3100F01EE
0A32A0E30820A0E3003083E5012052E2
FCFFFF1A1233A0E3002093E5032082E3
002083E50020A0E3402083E5042093E5
012682E3042083E590179FE5002091E5
022082E3002081E584179FE5002091E5
022082E3002081E578179FE5002091E5
082082E3002081E53B15A0E30020A0E3
602EC1E5642ED1E5022082E3642EC1E5
4020A0E3602EC1E5642ED1E5102082E3
642EC1E55120A0E3602EC1E5642ED1E5
042082E3642EC1E50220A0E3602EC1E5
642ED1E5802082E3642EC1E5FE1E81E2
8030A0E30C30C1E50130A0E30030C1E5
0030A0E30430C1E50330A0E30C30C1E5
0030A0E30430C1E50730A0E30830C1E5
0330A0E31030C1E50216A0E3011051E2
FDFFFF1AD0069FE5730000EB90369FE5
004093E51F4004E20010A0E3010054E3
0110A003020054E30210A003030054E3
0210A003000051E35B00000A9C369FE5
002093E5072A82E3002083E5010051E3
1000000A88369FE5003093E5083003E2
080053E30500000A78369FE578469FE5
78569FE578669FE578769FE53E0000EA
60369FE570469FE56050A0E30360A0E3
60769FE5100000EA44369FE5003093E5
083003E2080053E30500000A34369FE5
48469FE534569FE534669FE540769FE5
2D0000EA1C369FE538469FE56050A0E3
0360A0E328769FE5FFFFFFEA50069FE5
0F02C0E320169FE50680A0E3042090E4
018058E2042081E4FBFFFF1A08069FE5
30169FE50F12C1E300F0A0E10184A0E3
0000A0E3041090E4049098E4090051E1
0B00001A041090E4049098E4090051E1
0700001A041090E4049098E4090051E1
0300001A001090E5009098E5090051E1
1500000A0184A0E39090A0E3B090C8E1
B090D8E1890059E30F00001A014484E3
B050C4E1B060C4E10B0000EAB0059FE5
0F02C0E380159FE50680A0E3042090E4
018058E2042081E4FBFFFF1A68059FE5
94159FE50F12C1E300F0A0E1050000EA
005084E5006084E5007083E50000A0E1
0000A0E101F0A0E1160000EA30313233
3435363738394142434445462C759FE5
1C604FE22020A0E3042042E23052A0E1
0F5005E20510D6E70010C7E5000052E3
F8FFFF1A0D10A0E30010C7E50A10A0E3
0010C7E50218A0E3011051E20000A0E1
FCFFFF1A0EF0A0E170249FE50410D2E5
3030A0E3043082E50230A0E3043082E5
023011E22400001A0B301AE23300001A
B8149FE55720A0E30020C1E56120A0E3
0020C1E56B20A0E30020C1E56520A0E3
0020C1E50D20A0E30020C1E50A32A0E3
0300A0E13010A0E30020A0E3044093E4
014004E2844FA0E1A44084E1042082E0
011051E2F8FFFF1AF0139FE5084091E5
040032E10800001A8007B0E8000057E3
10AF03EE109F02EE170F08EE108F01EE
07F0A0E10000A0E10000A0E12C149FE5
4220A0E30020C1E56120A0E30020C1E5
7420A0E30020C1E52020A0E30020C1E5
4620A0E30020C1E50D20A0E30020C1E5
FC039FE584139FE5080081E5020000EA
0000A0E374139FE5080081E5DC139FE5
5220A0E30020C1E56520A0E30020C1E5
7320A0E30020C1E56520A0E30020C1E5
7420A0E30020C1E50D20A0E30020C1E5
B0039FE5B0139FE50C1080E5ACD39FE5
0206A0E3A8139FE5000081E5A4139FE5
000081E598139FE5000081E594139FE5
000081E502111FE2720F8FE2F01F00EB
100F01EE170F08EE170F07EE520F0FEE
74039FE5FDFFFFEA0020A0E30636A0E3
603083E3003082E50228A0E30338A0E3
033083E3003082E51223A0E33344A0E3
364784E3334C84E3D24084E3084082E5
0000A0E10000A0E10000A0E10000A0E1
00F0A0E10EF0A0E180008FE21B30A0E3
0600B0E8002081E5013053E2FBFFFF1A
0EF0A0E10F002DE900000FE104002DE5
103F1FEE04002DE5F0229FE5112F0FEE
100F12EE0000A0E104F04FE2112714EE
100F12EE0000A0E104F04FE2200012E3
0800001A04009DE4113F0FEE100F12EE
0000A0E104F04FE204009DE400F021E1
0F00BDE84A2100EA5DF900EBDE0001EA
5400E040000000985800E04010814A49
5C00E04059819A696000E040AAAA0500
6400E040000000A06800E04002000000
2400E040FFFFFFFF2800E040FFFFFFFF
2C00E040FFFFFFFF1800E040EF884F44
1C00E0400673BFD72000E04008E0FF03
2000F040EF88DF402400F0400672BF53
2800F04000E0FF030C00E04042A0E9D7
1000E040A3ABFFFC1400E040FEEF0F00
1800E040EF884F441C00E0400673BFD7
2000E04008E0FF033000E04000000000
3400E040000000003800E04000000000
3C00E040000000004000E04000000000
4400E040000000000000008000000000
20000000000000880000004401000000
00001088000000480100000000002088
0000004C010000000000308800000058
01000000000040880000005C01000000
000000890000C00E0100000000001089
0000000401000000000020890000800C
01000000000030890000800D01000000
000040890000000D0100000000005089
0000000C010000000000608900000010
040000000000008B0000000810000000
0000008C00000020010000000000108C
00000028010000000000208C0000002C
0E0000000000008D0000003001000000
0000108D00000038010000000000208D
0000003C0E0000000000008E00000040
2000000000000090000000A040000000
00000094000000A44000000000000098
000000A8400000000000009C00000014
20000000000000000000000000000000
0000F0400000304194339C7F1400000D
1800000D61010000410200000000A040
D233D833AC74A474FF0F0000C809C809
1000E0402800E0405C00E04078563412
04000048080000481C00004808D70000
6000600003000300F9600000846B0000
08970000F1600000844B0000008003A0
E00FC00E50FA000000009040FF7F2003
00A007A01800E0402400E040ADDEDEC0
FF030000301404808C1304802C140480
00000000000000000000000000000000
00000000DD68CD400000000002000000
55000000C4940000C48800000CB90480
ECF60480A4B9048064BB0480C8BB0480
4150495302060500EC19048000000000
0000000000000000410052004D000000
570069006E0064006F00770073002000
4300450020004B00650072006E006500
6C00200066006F007200200041005200
4D002000200020004200750069006C00
740020006F006E0020004A0061006E00
20002000360020003200300030003400
2000610074002000310039003A003200
33003A00350037000D000A0000000000
401B0480341B04801C1B0480181B0480
081B0480FC1A0480F81A0480EC1A0480
EC1A0480DC1A0480D01A048008000000
5B485720427265616B5D00005B537461
636B206661756C745D0000003C496E76
616C69643E0000004952510044617461
2041626F727400005072656665746368
2041626F7274000053574900556E6465
66696E656420496E737472756374696F
6E00000052657363686564756C650000
5261697365457863657074696F6E0000
0D000A00000000005200310032003D00
250038002E0038006C00780020002000
530050003D00250038002E0038006C00
7800200020004C0072003D0025003800
2E0038006C0078002000500073007200
3D00250038002E0038006C0078000D00
0A000000000000002000520038003D00
250038002E0038006C00780020002000
520039003D00250038002E0038006C00
780020005200310030003D0025003800
2E0038006C0078002000520031003100
3D00250038002E0038006C0078000D00
0A000000000000002000520034003D00
250038002E0038006C00780020002000
520035003D00250038002E0038006C00
780020002000520036003D0025003800
2E0038006C0078002000200052003700
3D00250038002E0038006C0078000D00
0A000000000000002000520030003D00
250038002E0038006C00780020002000
520031003D00250038002E0038006C00
780020002000520032003D0025003800
2E0038006C0078002000200052003300
3D00250038002E0038006C0078000D00
0A000000000000004500780063006500
7000740069006F006E00200027002500
61002700200054006800720065006100
64003D00250038002E0038006C007800
200041004B0059003D00250038002E00
38006C0078002000500043003D002500
38002E0038006C007800200042005600
41003D00250038002E0038006C007800
0D000A0000000000530070003D002500
38002E00380078000D000A0000000000
730070005F006100620074003D002500
38002E00380078002000730070005F00
6900720071003D00250038002E003800
78002000730070005F0075006E006400
650066003D00250038002E0038007800
20004F0045004D004100640064007200
6500730073005400610062006C006500
20003D002000250038002E0038006C00
78000D000A000000500072006F006300
6500730073006F007200540079007000
65003D00250034002E00340078002000
20005200650076006900730069006F00
6E003D00250064000D000A0000000000
4600410052003D00250038002E003800
6C00780020004600530052003D002500
34002E00340078000D000A0000000000
500043003D00250038002E0038006C00
780020004C0072003D00250038002E00
38006C0078002000530070003D002500
38002E0038006C007800200050007300
72003D00250034002E00340078000D00
0A00000000000000250061003A002000
5400680072006500610064003D002500
38002E0038006C007800200050007200
6F0063003D00250038002E0038006C00
7800200041004B0059003D0025003800
2E0038006C0078000D000A0000000000
210055006E007200650063006F007600
65007200610062006C00650020004500
720072006F0072003A00200045007800
630065007000740069006F006E002000
6F0072002000630061006C006C006900
6E006700200041005000490020006900
6E007300690064006500200050006F00
7700650072002000480061006E006400
6C00650072000D000A00000000000000
54004C0053004B00450052004E005F00
4E004F004600410055004C0054002000
7300650074002E002E002E0020006200
7900700061007300730069006E006700
20006B00650072006E0065006C002000
64006500620075006700670065007200
2E000D000A00000041004B0059003D00
250038002E0038006C00780020005000
43003D00250038002E0038006C007800
2000520041003D00250038002E003800
6C00780020004200560041003D002500
38002E0038006C007800200046005300
52003D00250038002E0038006C007800
0D000A0000000000250061003A002000
5400680072006500610064003D002500
38002E0038006C007800200050007200
6F0063003D00250038002E0038006C00
7800200027002500730027000D000A00
0000000000000000E4F60480ECF60480
48B80480C8ED04803CEE048094EE0480
48EF0480602A068084C506806CCA0680
48CC06801CB50680DCB30680F00B0880
1C200780A8C40580B0B1058000000000
00000000000000000000000000000000
2CC00580B02207806C410680385F0780
F060078080600780BCEF0480D80D0880
F8B40680B46B07804877078090730780
B4DE0580E4F60480E4F60480E4F60480
54100780380F0780B0F60480E4F60480
E4F60480B0AB0580F8AB0580C4B80580
405E0680F8090780F84F0780C8520780
6055078060560780F42205803C9B0580
3046058060220780AC6D05803C700580
3864058074B6058040B50580B0B50580
00B4058000B8058030B8058054510580
4C52058054B9058084B90580E4B80580
D02905809052058038C60580B8C60580
00000000CCC6058004C705806C600680
B8570580D4F704801027058080BE0580
A83F05807041068094410680E0B90580
F4B905808C7E058048C7058060C70580
24B90580145005806CAC0480E4B70480
F4C6068068F3068018E7068024E80680
E0F1068068FC048010430780A87E0780
0000000068B8058094F004804C4B0780
584D0780A44D078038F7048010F80480
7CF8048008F7048040BC048078ED0480
94A0048028BA0580F490058024930580
2C8D058034CF058004D7058090CF0580
68610680BC410680D8D8058034DE0580
2CDB0580C8DB0580186C0780E0560580
485305802CC60680E8F804802CD90580
FCD905805CDC0580C4DC0580BCFB0480
F0350680FC370680AC2A068000000000
0000000044E90680F4CB06806CB90580
DCCB0680CC260580BCC5068078ED0480
58C304807CC404802CC80580F4DE0580
443D0680D03D0680A84506802C460680
6CB1058074B105808C6D0780F0700780
04720780640A0680344706802CC80680
74C9068060C706800C3F0680D83F0680
78490780182605805C3F0580AC050680
5CD80480DCB7058004B705805C7A0780
4CB205806046068048C8058098B30580
B0570780E4FF0480584A0780576E3332
0300B900D82004800000000000000000
46494C45000700000000000000000000
0000000046494E440008000000000000
00000000000000004446494C00090000
00000000000000000000000044464E44
000A0000000000000000000000000000
534B5400000B00000000000000000000
00000000454E554D000F000000000000
0000000000000000480061006C007400
69006E00670020007300790073007400
65006D000D000A000000000043006500
4C006F0067002E0064006C006C000000
6B0063006F007600650072002E006400
6C006C00000000006B0064002E006400
6C006C00000000002000200043006100
6C006C0069006E006700200064006500
760069006300650020006D0061006E00
6100670065007200200070006F007700
650072002000700072006F0063002E00
0D000A00000000002000200043006100
6C006C0069006E006700200057004400
65007600690063006500200070006F00
7700650072002000700072006F006300
2E000D000A0000002000200043006100
6C006C0069006E006700200047005700
45005300200070006F00770065007200
2000700072006F0063002E000D000A00
000000004C9905800000000000390580
943A0580A86405802C65058074C70580
CC8405807084058028500580B8650580
F06505806C660580A4660580889A0580
000000005C4E0580D0C7058000000000
7CC80580F0C8058068CA058028960580
1CCD0580B8CE05805C27058000000000
80190580B01705800C190580A0180580
4029058000000000D8730580B0280580
00000000BC7605805448524402010E00
74250480000000000000000050524F43
02020B00AC2504800000000000000000
45564E5402040600D825048000000000
000000004D55545802050300F0250480
000000000000000053454D50020D0300
FC250480000000000000000030313233
34353637383961626364656600000000
3CD20680BCD20680E8EE068063006F00
7200650064006C006C002E0064006C00
6C0000004E004B002E00450058004500
000000006E006B002E00650078006500
00000000430065004C006F0067005A00
6F006E006500500072006F0063006500
7300730000000000430065004C006F00
67005A006F006E006500550073006500
72000000430065004C006F0067005A00
6F006E00650043004500000044006500
76006900630065000000000052006500
6C006500610073006500460053004400
000000004600530044004D0047005200
00000000460069006C00650053007900
730000004E006B000000000041006C00
6C006F00770053007900730074006500
6D004100630063006500730073000000
530079007300740065006D005C004F00
62006A00650063007400530074006F00
720065000000000049006E006A006500
6300740044004C004C00000053005900
5300540045004D005C004B0045005200
4E0045004C000000630070004C006F00
77000000630062004C006F0077000000
530059005300540045004D005C004F00
4F004D00000000005300790073007400
65006D00500061007400680000000000
4C006F00610064006500720000000000
4A004900540044006500620075006700
67006500720000004400650062007500
67000000660069006C00650073007900
73002E00650078006500000053005900
5300540045004D002F00460053005200
65006100640079000000000044006500
6200750067005A006F006E0065007300
000000005A6F6E657300000050656761
737573004E004C005300460049004C00
450000005C00770069006E0064006F00
770073005C00770069006E0063006500
2E006E006C0073000000000000000000
00000200000000010000040000000000
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
FCCF068004EE06806400770041006400
6400720020003D002000300078002500
78002C002000640077004C0065006E00
20003D00200030007800250078002C00
200064007700530074006B0042006500
670020003D0020003000780025007800
2C00200064007700530074006B004500
6E00640020003D002000300078002500
78000A00000000004B00500052004F00
4300530054004B00530049005A004500
20003D002000250038002E0038006C00
78002000280074006C00730020003D00
2000250038002E0038006C0078002C00
200074006C0073004E006F006E005300
6500630020003D002000250038002E00
38006C00780029000A00000000000000
18AC0F80000000000000000000000000
00000000000000000000000000000000
000000000000000000000000402D1880
6D00730063006F007200650065002E00
64006C006C0000002E00630070006C00
000000002E0064006C006C0000000000
5C00570069006E0064006F0077007300
5C0000006D73636F7265652E646C6C00
210021002100200050006C0065006100
73006500200043006800650063006B00
200079006F0075007200200053005900
5300470045004E002000760061007200
6900610062006C006500200021002100
21000D000A0000004500520052004F00
52003A002000660075006E0063007400
69006F006E002000400020004F007200
640069006E0061006C00200025006400
20006D0069007300730069006E006700
200069006E0020004D006F0064007500
6C006500200027002500730027000D00
0A0000002E0065007800650000000000
5F436F724578654D61696E005F436F72
446C6C4D61696E0049004F0043006F00
6E00740072006F006C00000043007200
650061007400650049006E0073007400
61006E00630065000000000044006500
7300740072006F00790049006E007300
740061006E00630065000000486C7072
53746B004E616D65000000004D656D42
6C6F636B0000000046756C6C5265662F
46534D61702F54687264546D00000000
437269742F4576742F53656D2F4D7574
2F54687264446267000000004150492F
4353746B2F436C6E4576742F53746245
76742F507278792F48446174612F4B4D
6F6400004D6F64005468726400000000
880007800000000028DF0680464D4150
020E0300802C04800000000000000000
30003100320033003400350036003700
38003900610062006300640065006600
00000000300031003200330034003500
36003700380039004100420043004400
450046000000000028004E0055004C00
4C00290000000000284E554C4C290000
80190580D873058064BB048028DF0680
2C650580A864058030E60580C0E60580
70E7058048E80580D0E8058060E90580
10FA0580F8FE0580B4FF058040010680
CC01068014080680A408068078090680
440006801C0706804005068070FF0580
E8E9058080EA058020EB0580B0EB0580
38EC0580B4EC05805CED0580ECED0580
9CEE05802CEF0580CCEF058074F00580
0CF10580C4F105804CF20580E4F20580
6CF3058020F40580FCF405809CF50580
24F60580ACF6058034F70580BCF70580
60F80580F0F8058080F90580B0FA0580
88FB058020FC0580C0FC058048FD0580
D0FD058068FE0580C4E50580A8020680
700306805C0406804D00550049000000
2E0025003000340058002E004D005500
490000005300790073004C0061006E00
670000004300750072004C0061006E00
6700000045006E00610062006C006500
000000005C00520065006C0065006100
730065005C007200650067003A000000
57004100490054005F00520045004C00
4600530044003200000000004C6F6361
6C416C6C6F6300004C6F63616C467265
65000000000000000000000001010202
03030404050506060707080809090A0A
0B0B0C0C0D0D0E0E0F0F101011111111
11111111111111111111110000000000
FEFFFFFFFFFFFFFF0000000001000000
0200000004000000060000000A000000
0E000000160000001E0000002E000000
3E0000005E0000007E000000BE000000
FE0000007E010000FE010000FE020000
FE030000FE050000FE070000FE0B0000
FE0F0000FE170000FE1F0000FE2F0000
FE3F0000FE5F0000FE7F0000FEBF0000
FEFF0000FE7F0100FEFF0100FEFF0200
FEFF0300FEFF0500FEFF0700FEFF0900
FEFF0B00FEFF0D00FEFF0F00FEFF1100
FEFF1300FEFF1500FEFF1700FEFF1900
FEFF1B00FEFF1D00FEFF1F0000010203
0405060708090A0B0C0D0E0F10000102
030405060708090A0B0C0D0E0F100000
00000000334000000141440050104009
05400000014C53005010400978200000
014C5300EC102980F0C00000014B5300
EC1029810000000004525400EC103981
0B90000004525400EC103981C9D00000
04525400EC1039814CE0000004525400
86110013BA50000004444C000B102000
CCA00000054E4700B710509008600000
06334300B71000927604000006334300
67656472783D25782C793D25782C7A3D
25780A00696370723D25782C69636970
3D25780A00000000236F736D72303D25
782C6F7363723D25780A000041534943
3320696E74737461745F433D25782069
6E74737461745F443D25780A00000000
415349433320696E74737461745F413D
257820696E74737461745F423D25780A
000000004F7468723A25780A00000000
420054005F0049004E0054000D000A00
00000000000000000000000033400000
014144005010400905400000014C5300
5010400978200000014C5300EC102980
F0C00000014B5300EC10298100000000
04525400EC1039810B90000004525400
EC103981C9D0000004525400EC103981
4CE000000452540086110013BA500000
04444C000B102000CCA00000054E4700
B71050900860000006334300B7100092
760400000633430055AA00FFFF00AA55
0055FFAAFFAA5500536C656570205265
736574202121210D0A0000004F656D20
496E697420446F6E650D0A0052006500
7300650074002E002E002E000D000A00
00000000536F66742052657365742021
21212028436F74756C6C612077686174
6368646F675F7265736574290D0A0000
48617264205265736574202121212028
436F74756C6C61206770696F5F726573
6574290D0A0000005600650072007900
200043006F006C006400200062006F00
6F0074002E002E002E000D000A000000
436F6C64626F6F74202121212028436F
74756C6C612068617264776172655F72
65736574290D0A004854432052616469
6F2056657273696F6E3A2025730D0A00
0D0A4854432043452020202056657273
696F6E3A2025730D0A00000036344D20
52414D0D000000003132384D2052414D
0D0000004D4543522020203D20307825
780D00004D5343322020203D20307825
780D00004D5343312020203D20307825
780D00004D5343302020203D20307825
780D00004D4452454652203D20307825
780D00004D44434E4647203D20307825
780D0000000000004400650062007500
670050006F00720074004D006F006400
690066007900280029002E002E002E00
2E002E002E002E002E002E002E002E00
2E002E002E00210021000D000A000000
2B0042006F0061007200640049006E00
6900740020002E002E002E0020005700
610072006D0020005300740061007200
74000D000A0000000000000044200000
32002E00300036002E00300030005700
5700450000000000420054005F004F00
4E00200030000D000A00000042005400
5F004F004E00200031000D000A000000
4E6F2047534D000047204E4F4E450000
4720000052204E4F4E45000052200000
415449206E6F742053657475702C2073
65747570204154490D0A00005741524E
494E47203A20415449206E6F74207265
616479202121210D0A00000048617264
776172652056657273696F6E203D2045
56540D0A000000004861726477617265
2056657273696F6E203D204456540D0A
00000000486172647761726520566572
73696F6E203D205056540D0A00000000
2D2D2D2053797374656D207374617274
2074797065205B4E4F524D414C5F5245
5345545D202D2D2D0D0A00002D2D2D20
53797374656D20737461727420747970
65205B434F4C445F424F4F545D202D2D
2D0D0A002D2D2D2053797374656D2073
746172742074797065205B4241545F46
41554C545F52455345545D202D2D2D0D
0A000000647750535052203D2025780D
0A000000000000000000000033400000
014144005010400905400000014C5300
5010400978200000014C5300EC102980
F0C00000014B5300EC10298100000000
04525400EC1039810B90000004525400
EC103981C9D0000004525400EC103981
4CE000000452540086110013BA500000
04444C000B102000CCA00000054E4700
B71050900860000006334300B7100092
7604000006334300646562756720420D
0A000000646562756720410D0A000000
4F0045004D0020007300650074002000
7200740063000D000A00000000000000
50006100720061006C006C0065006C00
50006F007200740049006E0069007400
690061006C0069007A00650020007700
69007400680020004800540043002000
500050005300480020000D000A000000
53006500740020004E006F0050005000
460053002000660061006C0073006500
31000D000A0000002B00500061007200
61006C006C0065006C0050006F007200
740049006E0069007400690061006C00
69007A00650020006600610069006C00
650064002C0020004E006F0074002000
660069006E0064002000530075007000
6500720049004F000D000A0000000000
2B0050006100720061006C006C006500
6C0050006F007200740049006E006900
7400690061006C0069007A0065003100
280029000D000A00000000002B005000
6100720061006C006C0065006C005000
6F007200740049006E00690074006900
61006C0069007A006500280029000D00
0A0000004E006F005000500046005300
31000D000A0000004E006F0050005000
4600530032000D000A00000000000000
4F0045004D0050006100720061006C00
6C0065006C0050006F00720074005300
65006E00640042007900740065003A00
2000740069006D00650020006F007500
7400230034000D000A00000000000000
4F0045004D0050006100720061006C00
6C0065006C0050006F00720074005300
65006E00640042007900740065003A00
2000740069006D00650020006F007500
74000D000A0000000000000033400000
014144005010400905400000014C5300
5010400978200000014C5300EC102980
F0C00000014B5300EC10298100000000
04525400EC1039810B90000004525400
EC103981C9D0000004525400EC103981
4CE000000452540086110013BA500000
04444C000B102000CCA00000054E4700
B71050900860000006334300B7100092
7604000006334300D407030001000100
0C00000000000000570061006B006500
75007000520069006E00670021002100
21000D000A00000049004F0043005400
4C005F00480041004C005F0054005000
5F0045004E00410042004C0045002000
65006E0074006500720021000D000A00
0000000049004F00430054004C005F00
480041004C005F005300430052004500
45004E005F0052004F00540041005400
45000D000A0000004400650062007500
670050006F007200740043006F006E00
740072006F006C002E002E002E002E00
2E002E002E002E002E002E002E002E00
2E002E002E002E002E002E002E002E00
0D000A000000000049004F0043005400
4C005F00480041004C005F004B004500
59005F004C004F0043004B0020006500
6E0074006500720021000D000A000000
49004F00430054004C005F0047004500
54005F0049004D00450049005F004E00
55004D004200450052000D000A000000
49004F00430054004C005F0047004500
54005F004F0045004D005F0056004500
5200530049004F004E00200021000D00
0A000000000000000000000033400000
014144005010400905400000014C5300
5010400978200000014C5300EC102980
F0C00000014B5300EC10298100000000
04525400EC1039810B90000004525400
EC103981C9D0000004525400EC103981
4CE000000452540086110013BA500000
04444C000B102000CCA00000054E4700
B71050900860000006334300B7100092
76040000063343005B42502044657465
637420496E747220656E61626C655D0D
0A0000004F574D494E5420454E0D0A00
455020454E0D0A00414320454E0D0A00
5B42502044657465637420496E747220
64697361626C655D0D0A00004F574D49
4E542044697361626C650D0A00000000
45502044697361626C650D0A00000000
4049522044697361626C652000000000
41432044697361626C650D0A00000000
4B4559494E54204453420D0A00000000
4F454D496E7465727275707444697361
626C65202D3E2025780D0A0045502064
6F6E650D0A000000414320646F6E650D
0A000000000000000000000033400000
014144005010400905400000014C5300
5010400978200000014C5300EC102980
F0C00000014B5300EC10298100000000
04525400EC1039810B90000004525400
EC103981C9D0000004525400EC103981
4CE000000452540086110013BA500000
04444C000B102000CCA00000054E4700
B71050900860000006334300B7100092
76040000063343000000000033400000
014144005010400905400000014C5300
5010400978200000014C5300EC102980
F0C00000014B5300EC10298100000000
04525400EC1039810B90000004525400
EC103981C9D0000004525400EC103981
4CE000000452540086110013BA500000
04444C000B102000CCA00000054E4700
B71050900860000006334300B7100092
76040000063343005200650073006500
7400470053004D00280029000D000A00
00000000000000000000000033400000
014144005010400905400000014C5300
5010400978200000014C5300EC102980
F0C00000014B5300EC10298100000000
04525400EC1039810B90000004525400
EC103981C9D0000004525400EC103981
4CE000000452540086110013BA500000
04444C000B102000CCA00000054E4700
B71050900860000006334300B7100092
76040000063343005800490050002000
63006800610069006E0020006C006F00
63006100740069006F006E0020006E00
6F007400200066006900780065006400
2000750070000A000000000049006E00
760061006C0069006400200058004900
5000200066006F0075006E0064000A00
00000000580049005000200072006500
670069006F006E00200066006F007500
6E0064003A002000250061000D000A00
00000000000000004500520052004F00
52003A0020004E0075006D0062006500
720020006F0066002000580049005000
73002000650078006300650065006400
730020004D00410058000A0000000000
7000640077005800490050004C006F00
63002000660069007800650064002000
75007000200063006F00720072006500
630074006C0079000A00000063686169
6E20696E666F726D6174696F6E000000
46004100540041004C00200045005200
52004F0052003A0020004D0044004400
200043006800610069006E0020006100
6E00640020004F005300200063006800
610069006E00200044004F0020004E00
4F00540020004D004100540043004800
21002100210021000D000A0000000000
00000000334000000141440050104009
05400000014C53005010400978200000
014C5300EC102980F0C00000014B5300
EC1029810000000004525400EC103981
0B90000004525400EC103981C9D00000
04525400EC1039814CE0000004525400
86110013BA50000004444C000B102000
CCA00000054E4700B710509008600000
06334300B71000927604000006334300
80000000BF010400434C4B5F50494E5F
434E544C202020202020202000000000
000000000000000084000000040D5050
504C4C5F5245465F46425F4449562020
20202020000000000000000000000000
this code is not present in nk.nba , not in Radio_.nba , and not in ms_.nba
perhaps this code is in Himaupgradeut.exe , perhaps it format the doc ....
I've seen , during the upgrade , the first comand sent to bootloader for the extrom is :
wdata 7001000 2000 and the fisrt data of extrom ....
but , the DOC start at 70000000 , isn't it ???
i've tried to send data to bootloader ... but , after typing "wdata address lenght" , how can i send the data ???
I posted about this to Buzz a while back.
I read up on the DOC chip and it has an internal partitioning structure.
You setup the partition table in the DOC itself, and it handles all the wear levelling etc within the partitions.
You can download the TrueFFS.dll source i think from the site, and get all the info you need to compile a tool to do the partitioning from within wm2k5 itself. If you can just make the dinfo tool to read the existing partition structure from the DOC it would help LOTS! maybe email the company and see if there is a compiled wince dinfo already.
it may be that its hard partitioned in the DOC, AND the partitions are referred to directly within the OS, so you would have to edit the OS rom AND repartition the DOC. not a nice task.
Just guessing though, somebody smarter than me will have to confirm.
TofClock> "DOC in Himalaya is managed with TrueFFS.dll , but we can't extract it at this time ... "
You mean the attached .dll file?
Whjere do you get this file ??
In a wm2005 rom ?
If you go to the Msystems website and look up the DOC used, there are many downloads including source code and drivers for the device.
I just downloaded this from their site, somebody who is a better programmer than me needs to look at the msystems site and get the right code to compile the DOC tools for WINCE.
When we have the dinfo tool we can see for sure if its formatted inside the DOC like I think it is.
Prrofer, TofClock:
This looks like really good stuff, are you guys in contact with Buzz about this, (I know he was also looking into merging Storage and Ext_ROM as well for WM5 1.6xx).
On the buzzdev.net site the "Disk-On-Chip Partition" is under constrution so I hope someone is tieing all the minds together.
hey guys, you ROCK!
keep it alive and don't let it die!
I will post my findings tomorrow...
meanwhile I have to go shopping... ;o)
keep it up!
buzz
he he he buzz .... )
TofClock said:
during the upgrade , just before upgrading the extrom , HimaUpgradeUt.exe send an hexa code like this
Click to expand...
Click to collapse
Yeah ;o) i took that code and passed it to WinHEx...
Here's the output.. looks like part of ROM... Note the ECEC signature at the beginning..
Open it in WinHex preferably....
buzz
TofClock said:
You say the storage partition (FAT1) have 29940 sectors (#74F4h) but if I divide #EA0000h (the size) with 512 , that’s #7500h sectors …
Click to expand...
Click to collapse
That's true... but i dont know, why the fat headers are completely ignored by the OS.... It is strange.
buzz
Maybe the other 12 (#0Ch) are used for something else?
12 = 8 + 3 + 1 = A filename & a byte
!!!!! IT IS REALITY !!!!!
!!!!! IT IS REALITY !!!!!
http://forum.xda-developers.com/viewtopic.php?p=137944#137944
buzz
GREAT )))))))))))
you're the best buzz ))
tell me your secret , i try to do this since a really long time ....
Great Work Buzz
You're a genius
Keep up the good work.
Related
Problem with unbricking Lumia 520
I have problem with unbricking Lumia 520. I've bricked it while flashing engineering SBL3 on Windows 10 with Windows 8.1 FFU. Phone was stuck on 05C6:F006 mode. I switched mode by shorting fourth JTAG pin, now it boots in QHSUSB_DLOAD (05C6:9008). But i can't flash firmware. Tried many .hex files, same effect... Log: Code: c:\Lumia>thor2 -mode emergency -hexfile hex.hex -mbnfile GPT0.bin -orig_gpt THOR2 1.8.2.18 Built for Windows @ 13:36:46 Jun 16 2015 Thor2 is running on Windows of version 6.2 thor2 -mode emergency -hexfile hex.hex -mbnfile GPT0.bin -orig_gpt Process started Sat Aug 13 20:03:36 2016 Logging to file C:\Users\gabixdev\AppData\Local\Temp\thor2_win_20160813200336_ThreadId-2248.log Debugging enabled for emergency Initiating emergency download Using default emergency protocol ALPHA EMERGENCY FLASH START Emergency Programmer V1 version 2014.10.31.001 Hex download selected Check if device in Dload Connection to DLOAD mode succeeded Get Dload parameters Sending HEX flasher to the device Sending GO command if HEX flasher successfully uploaded. Emergency Programmer V1 version 2014.10.31.001 Mbn download selected Waiting for connection to flash programmer Connecting to flash programmer Received valid HELLO_RSP Safe version=true, transfer size=15360 Received valid SECURITY_RSP Successfully connected to flash programmer Connection to flash programmer succeeded Uploading bootloader(s), UEFI, etc from MBN image to the eMMC. This will take up to 20 seconds Reading GPT from binary -- GPT STARTs-- name: DPP startLBA: 4096 endLBA: 20479 size: 0x0000000000800000 bytes attributes: 0x0 name: MODEM_FSG startLBA: 20480 endLBA: 26623 size: 0x0000000000300000 bytes attributes: 0x0 name: SSD startLBA: 28672 endLBA: 28703 size: 0x0000000000004000 bytes attributes: 0x0 name: SBL1 startLBA: 32768 endLBA: 35767 size: 0x0000000000177000 bytes attributes: 0x0 name: SBL2 startLBA: 36864 endLBA: 39863 size: 0x0000000000177000 bytes attributes: 0x0 name: SBL3 startLBA: 40960 endLBA: 45055 size: 0x0000000000200000 bytes attributes: 0x0 name: UEFI startLBA: 45056 endLBA: 50055 size: 0x0000000000271000 bytes attributes: 0x0 name: RPM startLBA: 53248 endLBA: 54247 size: 0x000000000007d000 bytes attributes: 0x0 name: TZ startLBA: 57344 endLBA: 58343 size: 0x000000000007d000 bytes attributes: 0x0 name: WINSECAPP startLBA: 61440 endLBA: 62463 size: 0x0000000000080000 bytes attributes: 0x0 name: BACKUP_SBL1 startLBA: 65536 endLBA: 68535 size: 0x0000000000177000 bytes attributes: 0x0 name: BACKUP_SBL2 startLBA: 69632 endLBA: 72631 size: 0x0000000000177000 bytes attributes: 0x0 name: BACKUP_SBL3 startLBA: 73728 endLBA: 77823 size: 0x0000000000200000 bytes attributes: 0x0 name: BACKUP_UEFI startLBA: 77824 endLBA: 82823 size: 0x0000000000271000 bytes attributes: 0x0 name: BACKUP_RPM startLBA: 86016 endLBA: 87015 size: 0x000000000007d000 bytes attributes: 0x0 name: BACKUP_TZ startLBA: 90112 endLBA: 91111 size: 0x000000000007d000 bytes attributes: 0x0 name: BACKUP_WINSECAPP startLBA: 94208 endLBA: 95231 size: 0x0000000000080000 bytes attributes: 0x0 name: UEFI_BS_NV startLBA: 98304 endLBA: 98815 size: 0x0000000000040000 bytes attributes: 0x0 name: UEFI_NV startLBA: 102400 endLBA: 102911 size: 0x0000000000040000 bytes attributes: 0x0 name: PLAT startLBA: 106496 endLBA: 122879 size: 0x0000000000800000 bytes attributes: 0x0 name: EFIESP startLBA: 131072 endLBA: 262143 size: 0x0000000004000000 bytes attributes: 0x0 name: MODEM_FS1 startLBA: 262144 endLBA: 268287 size: 0x0000000000300000 bytes attributes: 0x0 name: MODEM_FS2 startLBA: 270336 endLBA: 276479 size: 0x0000000000300000 bytes attributes: 0x0 name: UEFI_RT_NV startLBA: 278528 endLBA: 279039 size: 0x0000000000040000 bytes attributes: 0x0 name: UEFI_RT_NV_RPMB startLBA: 282624 endLBA: 282879 size: 0x0000000000020000 bytes attributes: 0x0 -- GPT ENDs -- Sending OPEN_MULTI_REQ Message send failed with error code -1 Failed to get response to OPEN_MULTI_REQ ALPHA EMERGENCY FLASH END Emergency messaging closed successfully Operation took about 18.00 seconds. THOR2_EMERGENCYFLASHV1_ERROR_MSG_SEND_RECEIVE_FAILED THOR2 1.8.2.18 exited with error code 85021 (0x14C1D) SHA-1 of HEX.hex: 868570B59B84852AFE74DEF65C166AF2EC054742
you can teamview me?
Is there a result by now?
Hello Guy, Can you use teamviewer? download it and tell me to my mail - [email protected] i will fix it. or just go to http://forum.xda-developers.com/win...nt/fix-dead-phone-bricked-bootloader-t3496232 maybe it can help you
Samsung S7 Edge Crashing - Not sure why?!
Hi guys I have a problem with my phone crashing/freezing and I have no idea why!! I cant replicate the problem either it just happens one or two times a day - And I usually dont know about it until 30mins to a few hours later when I goto use my phone and its frozen !!! (The Always on display shows the time of the crash) Have a few log files - which I looked at straight after my phone booted up Code: --------- beginning of main W/SELinux (15587): SELinux: seapp_context_lookup: seinfo=default, level=s0:c512,c768, pkgname=org.jtb.alogcat I/InjectionManager(15587): Inside getClassLibPath caller W/System (15587): ClassLoader referenced unknown path: /data/app/org.jtb.alogcat-1/lib/arm64 D/RelationGraph(15587): garbageCollect() --------- beginning of system D/ContextRelationManager(15587): ContextRelationManager() : FEATURE_ENABLED=true I/InjectionManager(15587): Inside getClassLibPath + mLibMap{0=, 1=} W/ResourcesManager(15587): getTopLevelResources: /data/app/org.jtb.alogcat-1/base.apk / 1.0 running in org.jtb.alogcat rsrc of package org.jtb.alogcat D/ResourcesManager(15587): For user 0 new overlays fetched Null D/InjectionManager(15587): InjectionManager D/InjectionManager(15587): fillFeatureStoreMap org.jtb.alogcat I/InjectionManager(15587): Constructor org.jtb.alogcat, Feature store :{} I/InjectionManager(15587): featureStore :{} D/RelationGraph(15587): garbageCollect() W/ResourcesManager(15587): getTopLevelResources: /data/app/org.jtb.alogcat-1/base.apk / 1.0 running in org.jtb.alogcat rsrc of package org.jtb.alogcat W/ResourcesManager(15587): getTopLevelResources: /data/app/org.jtb.alogcat-1/base.apk / 1.0 running in org.jtb.alogcat rsrc of package org.jtb.alogcat D/AbsListView(15587): Get MotionRecognitionManager E/MotionRecognitionManager(15587): mSContextService = [email protected] E/MotionRecognitionManager(15587): motionService = [email protected]760cf22 E/MotionRecognitionManager(15587): motionService = com.samsung.android.[email protected] D/Activity(15587): performCreate Call Injection manager I/InjectionManager(15587): dispatchOnViewCreated > Target : org.jtb.alogcat.LogActivity isFragment :false D/ViewRootImpl(15587): #1 mView = com.android.internal.policy.MultiPhoneWindow$MultiPhoneDecorView{dd0ca46 I.E...... R.....ID 0,0-0,0} D/SecWifiDisplayUtil(15587): Metadata value : SecSettings2 D/OpenGLRenderer(15587): Use EGL_SWAP_BEHAVIOR_PRESERVED: true D/ViewRootImpl(15587): #1 mView = android.widget.LinearLayout{4792934 V.E...... ......I. 0,0-0,0} D/MultiPhoneWindow(15587): performUpdateVisibility, same visibility false W/ActivityThread(15587): AppLock checkAppLockState isAppLocked = false pkgName = org.jtb.alogcat D/libEGL (15587): eglInitialize EGLDisplay = 0x7f74100178 I/OpenGLRenderer(15587): Initialized EGL, version 1.4 D/mali_winsys(15587): EGLint new_window_surface(egl_winsys_display*, void*, EGLSurface, EGLConfig, egl_winsys_surface**, egl_color_buffer_format*, EGLBoolean) returns 0x3000, [1440x2560]-format:1 I/InjectionManager(15587): dispatchCreateOptionsMenu :org.jtb.alogcat.LogActivity I/InjectionManager(15587): dispatchPrepareOptionsMenu :org.jtb.alogcat.LogActivity W/DisplayListCanvas(15587): DisplayListCanvas is started on unbinded RenderNode (without mOwningView) D/libGLESv1(15587): DTS_GLAPI : DTS is not allowed for Package : org.jtb.alogcat D/ViewRootImpl(15587): MSG_RESIZED_REPORT: ci=Rect(0, 96 - 0, 0) vi=Rect(0, 96 - 0, 0) or=1 D/ViewRootImpl(15587): MSG_RESIZED_REPORT: ci=Rect(0, 0 - 0, 0) vi=Rect(0, 0 - 0, 0) or=1 I/Timeline(15587): Timeline: Activity_idle id: [email protected] time:137109 D/ViewRootImpl(15587): #3 mView = null D/ViewRootImpl(15587): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(15587): ViewPostImeInputStage processPointer 1 I/InjectionManager(15587): dispatchPrepareOptionsMenu :org.jtb.alogcat.LogActivity D/AbsListView(15587): Get MotionRecognitionManager D/ViewRootImpl(15587): #1 mView = android.widget.PopupWindow$PopupDecorView{7fdb5fd V.E...... ......I. 0,0-0,0} D/mali_winsys(15587): EGLint new_window_surface(egl_winsys_display*, void*, EGLSurface, EGLConfig, egl_winsys_surface**, egl_color_buffer_format*, EGLBoolean) returns 0x3000, [848x841]-format:1 W/DisplayListCanvas(15587): DisplayListCanvas is started on unbinded RenderNode (without mOwningView) D/ViewRootImpl(15587): MSG_RESIZED_REPORT: ci=Rect(0, 0 - 0, 0) vi=Rect(0, 0 - 0, 0) or=1 Code: --------- beginning of main D/mali_winsys(17024): EGLint new_window_surface(egl_winsys_display*, void*, EGLSurface, EGLConfig, egl_winsys_surface**, egl_color_buffer_format*, EGLBoolean) returns 0x3000, [1440x2560]-format:1 D/ViewRootImpl(17024): #1 mView = android.widget.LinearLayout{dade76a V.E...... ......I. 0,0-0,0} D/ViewRootImpl(17024): MSG_RESIZED_REPORT: ci=Rect(0, 0 - 0, 0) vi=Rect(0, 0 - 0, 0) or=1 I/Timeline(17024): Timeline: Activity_idle id: [email protected] time:4666967 D/ViewRootImpl(17024): #3 mView = null D/mali_winsys(17024): EGLint new_window_surface(egl_winsys_display*, void*, EGLSurface, EGLConfig, egl_winsys_surface**, egl_color_buffer_format*, EGLBoolean) returns 0x3000, [1440x2560]-format:1 D/ViewRootImpl(17024): #1 mView = android.widget.LinearLayout{8a6449c V.E...... ......I. 0,0-0,0} D/ViewRootImpl(17024): MSG_RESIZED_REPORT: ci=Rect(0, 0 - 0, 0) vi=Rect(0, 0 - 0, 0) or=1 I/Timeline(17024): Timeline: Activity_idle id: [email protected] time:4829125 D/ViewRootImpl(17024): #3 mView = null D/ViewRootImpl(17024): #1 mView = android.widget.LinearLayout{bc6e0df V.E...... ......I. 0,0-0,0} D/ViewRootImpl(17024): MSG_RESIZED_REPORT: ci=Rect(0, 0 - 0, 0) vi=Rect(0, 0 - 0, 0) or=1 I/Timeline(17024): Timeline: Activity_idle id: [email protected] time:5051016 D/ViewRootImpl(17024): #3 mView = null D/ViewRootImpl(17024): #1 mView = android.widget.LinearLayout{4a7e98a V.E...... ......I. 0,0-0,0} D/ViewRootImpl(17024): MSG_RESIZED_REPORT: ci=Rect(0, 0 - 0, 0) vi=Rect(0, 0 - 0, 0) or=1 I/Timeline(17024): Timeline: Activity_idle id: [email protected] time:5053842 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): #3 mView = null D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 I/InjectionManager(17024): dispatchPrepareOptionsMenu :org.jtb.alogcat.LogActivity D/AbsListView(17024): Get MotionRecognitionManager D/ViewRootImpl(17024): #1 mView = android.widget.PopupWindow$PopupDecorView{6720ef9 V.E...... ......I. 0,0-0,0} D/mali_winsys(17024): EGLint new_window_surface(egl_winsys_display*, void*, EGLSurface, EGLConfig, egl_winsys_surface**, egl_color_buffer_format*, EGLBoolean) returns 0x3000, [848x841]-format:1 W/DisplayListCanvas(17024): DisplayListCanvas is started on unbinded RenderNode (without mOwningView) D/ViewRootImpl(17024): MSG_RESIZED_REPORT: ci=Rect(0, 0 - 0, 0) vi=Rect(0, 0 - 0, 0) or=1 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): #3 mView = null W/InputEventReceiver(17024): Attempted to finish an input event but the input event receiver has already been disposed. W/InputEventReceiver(17024): Attempted to finish an input event but the input event receiver has already been disposed. E/ViewRootImpl(17024): sendUserActionEvent() mView == null D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 I/InjectionManager(17024): dispatchOptionsItemSelected :org.jtb.alogcat.LogActivity D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 I/InjectionManager(17024): dispatchOptionsItemSelected :org.jtb.alogcat.LogActivity D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 I/InjectionManager(17024): dispatchOptionsItemSelected :org.jtb.alogcat.LogActivity D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/AbsListView(17024): Get MotionRecognitionManager D/ViewRootImpl(17024): #1 mView = com.android.internal.policy.PhoneWindow$DecorView{5303338 V.E...... R.....I. 0,0-0,0} D/mali_winsys(17024): EGLint new_window_surface(egl_winsys_display*, void*, EGLSurface, EGLConfig, egl_winsys_surface**, egl_color_buffer_format*, EGLBoolean) returns 0x3000, [1336x451]-format:1 W/DisplayListCanvas(17024): DisplayListCanvas is started on unbinded RenderNode (without mOwningView) D/ViewRootImpl(17024): MSG_RESIZED_REPORT: ci=Rect(0, 0 - 0, 0) vi=Rect(0, 0 - 0, 0) or=1 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): #3 mView = null W/InputEventReceiver(17024): Attempted to finish an input event but the input event receiver has already been disposed. E/ViewRootImpl(17024): sendUserActionEvent() mView == null D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 I/InjectionManager(17024): dispatchPrepareOptionsMenu :org.jtb.alogcat.LogActivity D/AbsListView(17024): Get MotionRecognitionManager D/ViewRootImpl(17024): #1 mView = android.widget.PopupWindow$PopupDecorView{84db9d6 V.E...... ......I. 0,0-0,0} D/mali_winsys(17024): EGLint new_window_surface(egl_winsys_display*, void*, EGLSurface, EGLConfig, egl_winsys_surface**, egl_color_buffer_format*, EGLBoolean) returns 0x3000, [848x841]-format:1 W/DisplayListCanvas(17024): DisplayListCanvas is started on unbinded RenderNode (without mOwningView) D/ViewRootImpl(17024): MSG_RESIZED_REPORT: ci=Rect(0, 0 - 0, 0) vi=Rect(0, 0 - 0, 0) or=1 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 I/InjectionManager(17024): dispatchOptionsItemSelected :org.jtb.alogcat.LogActivity I/Timeline(17024): Timeline: Activity_launch_request id:org.jtb.alogcat time:5075640 D/ViewRootImpl(17024): #3 mView = null E/ViewRootImpl(17024): sendUserActionEvent() mView == null D/RelationGraph(17024): garbageCollect() D/AbsListView(17024): Get MotionRecognitionManager E/MotionRecognitionManager(17024): mSContextService = [email protected] E/MotionRecognitionManager(17024): motionService = [email protected]eafdf27 E/MotionRecognitionManager(17024): motionService = [email protected]eafdf27 I/InjectionManager(17024): dispatchBuildHeader > Target : org.jtb.alogcat.PrefsActivity D/AbsListView(17024): Get MotionRecognitionManager D/Activity(17024): performCreate Call Injection manager I/InjectionManager(17024): dispatchPreferences > Target : org.jtb.alogcat.PrefsActivity I/InjectionManager(17024): dispatchOnViewCreated > Target : org.jtb.alogcat.PrefsActivity isFragment :false D/ViewRootImpl(17024): #1 mView = com.android.internal.policy.MultiPhoneWindow$MultiPhoneDecorView{6bc2c96 I.E...... R.....ID 0,0-0,0} W/System.err(17024): remove failed: ENOENT (No such file or directory) : /data/user/0/org.jtb.alogcat/shared_prefs/org.jtb.alogcat_preferences.xml.bak D/MultiPhoneWindow(17024): performUpdateVisibility, same visibility false D/mali_winsys(17024): EGLint new_window_surface(egl_winsys_display*, void*, EGLSurface, EGLConfig, egl_winsys_surface**, egl_color_buffer_format*, EGLBoolean) returns 0x3000, [1440x2560]-format:1 I/InjectionManager(17024): dispatchCreateOptionsMenu :org.jtb.alogcat.PrefsActivity I/InjectionManager(17024): dispatchPrepareOptionsMenu :org.jtb.alogcat.PrefsActivity W/DisplayListCanvas(17024): DisplayListCanvas is started on unbinded RenderNode (without mOwningView) D/ViewRootImpl(17024): MSG_RESIZED_REPORT: ci=Rect(0, 96 - 0, 0) vi=Rect(0, 96 - 0, 0) or=1 I/Timeline(17024): Timeline: Activity_idle id: [email protected] time:5075924 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 D/ViewRootImpl(17024): ViewPostImeInputStage processKey 0 D/ViewRootImpl(17024): ViewPostImeInputStage processKey 1 D/mali_winsys(17024): EGLint new_window_surface(egl_winsys_display*, void*, EGLSurface, EGLConfig, egl_winsys_surface**, egl_color_buffer_format*, EGLBoolean) returns 0x3000, [1440x2560]-format:1 D/ViewRootImpl(17024): #1 mView = android.widget.LinearLayout{1d8e790 V.E...... ......I. 0,0-0,0} D/ViewRootImpl(17024): MSG_RESIZED_REPORT: ci=Rect(0, 0 - 0, 0) vi=Rect(0, 0 - 0, 0) or=1 I/Timeline(17024): Timeline: Activity_idle id: [email protected] time:5078913 D/MultiPhoneWindow(17024): performUpdateVisibility, same visibility false D/ViewRootImpl(17024): #3 mView = null D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 0 D/ViewRootImpl(17024): #3 mView = null D/ViewRootImpl(17024): ViewPostImeInputStage processPointer 1 I/InjectionManager(17024): dispatchOptionsItemSelected :org.jtb.alogcat.LogActivity I/WebViewFactory(17024): Loading com.google.android.webview version 53.0.2785.124 (code 278512450) I/InjectionManager(17024): Inside getClassLibPath caller I/art (17024): Rejecting re-init on previously-failed class java.lang.Class<com.android.webview.chromium.ServiceWorkerControllerAdapter> I/art (17024): Rejecting re-init on previously-failed class java.lang.Class<com.android.webview.chromium.ServiceWorkerControllerAdapter> I/art (17024): Rejecting re-init on previously-failed class java.lang.Class<com.android.webview.chromium.TokenBindingManagerAdapter> I/art (17024): Rejecting re-init on previously-failed class java.lang.Class<com.android.webview.chromium.TokenBindingManagerAdapter> I/cr_LibraryLoader(17024): Time to load native libraries: 3 ms (timestamps 9715-9718) I/cr_LibraryLoader(17024): Expected native library version number "53.0.2785.124", actual native library version number "53.0.2785.124" V/WebViewChromiumFactoryProvider(17024): Binding Chromium to main looper Looper (main, tid 1) {48a479a} I/cr_LibraryLoader(17024): Expected native library version number "53.0.2785.124", actual native library version number "53.0.2785.124" I/chromium(17024): [INFO:library_loader_hooks.cc(151)] Chromium logging enabled: level = 0, default verbosity = 0 W/System.err(17024): remove failed: ENOENT (No such file or directory) : /data/user/0/org.jtb.alogcat/shared_prefs/WebViewChromiumPrefs.xml.bak I/cr_BrowserStartup(17024): Initializing chromium process, singleProcess=true D/libEGL (17024): eglInitialize EGLDisplay = 0x7fdc176518 W/cr_media(17024): Requires BLUETOOTH permission D/ViewRootImpl(17024): #1 mView = com.android.internal.policy.PhoneWindow$DecorView{1c08f52 V.E...... R.....I. 0,0-0,0} D/mali_winsys(17024): EGLint new_window_surface(egl_winsys_display*, void*, EGLSurface, EGLConfig, egl_winsys_surface**, egl_color_buffer_format*, EGLBoolean) returns 0x3000, [1336x1062]-format:1 W/ClipboardExManager(17024): hasData : 2, -1, null W/DisplayListCanvas(17024): DisplayListCanvas is started on unbinded RenderNode (without mOwningView) W/DisplayListCanvas(17024): DisplayListCanvas is started on unbinded RenderNode (without mOwningView) D/ViewRootImpl(17024): MSG_RESIZED_REPORT: ci=Rect(0, 0 - 0, 0) vi=Rect(0, 0 - 0, 0) or=1 W/DisplayListCanvas(17024): DisplayListCanvas is started on unbinded RenderNode (without mOwningView) D/ViewRootImpl(17024): MSG_RESIZED_REPORT: ci=Rect(0, 0 - 0, 0) vi=Rect(0, 0 - 0, 0) or=1 D/ViewRootImpl(17024): #1 mView = android.widget.LinearLayout{f7265c3 V.E...... ......I. 0,0-0,0} W/DisplayListCanvas(17024): DisplayListCanvas is started on unbinded RenderNode (without mOwningView) --------- beginning of system W/ActivityThread(17024): AppLock checkAppLockState isAppLocked = false pkgName = org.jtb.alogcat D/ViewRootImpl(17024): MSG_RESIZED_REPORT: ci=Rect(0, 0 - 0, 0) vi=Rect(0, 0 - 0, 0) or=1 V/ActivityThread(17024): updateVisibility : ActivityRecord{ada7795 [email protected] {org.jtb.alogcat/org.jtb.alogcat.LogActivity}} show : true I/Timeline(17024): Timeline: Activity_idle id: [email protected] time:5279980 D/ViewRootImpl(17024): #3 mView = null D/ViewRootImpl(17024): #1 mView = android.widget.LinearLayout{58d5c35 V.E...... ......I. 0,0-0,0} W/ActivityThread(17024): AppLock checkAppLockState isAppLocked = false pkgName = org.jtb.alogcat D/ViewRootImpl(17024): MSG_RESIZED_REPORT: ci=Rect(0, 0 - 0, 0) vi=Rect(0, 0 - 0, 0) or=1 I/Timeline(17024): Timeline: Activity_idle id: [email protected] time:5305291 W/DisplayListCanvas(17024): DisplayListCanvas is started on unbinded RenderNode (without mOwningView) D/ViewRootImpl(17024): ViewPostImeInputStage processKey 0 Hopefully someone can help me from the above log? Or give me another suggestion!?! I could be wrong but I seem to see this 'error' a bit? E/MotionRecognitionManager(17024): mSContextService = [email protected] E/MotionRecognitionManager(17024): motionService = [email protected]eafdf27 E/MotionRecognitionManager(17024): motionService = [email protected]eafdf27 Using Superman Rom v1.13.1 Baseband: G935FXXU1APD1 Android 6.0.1 Kernal 3.18.41-SuperKern_SM-G935F_V1.7.1 [email protected] #1 Build: MMB29K.G935FXXU1BPHJ
There's your problem your on another rom goto the rom thread and ask there it's probably related maybe you flashed a custom kernel as well and it's conflicting with crashes
102skysx said: There's your problem your on another rom goto the rom thread and ask there it's probably related maybe you flashed a custom kernel as well and it's conflicting with crashes Click to expand... Click to collapse I will do that - but nothing can be taken from the above logs ?
ExodusNZ said: I will do that - but nothing can be taken from the above logs ? Click to expand... Click to collapse Not me I'm not someone who can read that stuff not a developer Your best bet would be to goto the main thread and hopefully the developer is still active to respond to your issue
102skysx said: Not me I'm not someone who can read that stuff not a developer Your best bet would be to goto the main thread and hopefully the developer is still active to respond to your issue Click to expand... Click to collapse Thanks - Ive done that now , hopefully he reads its - Or hopefully someone else replies on this page
Debricking my Rockchip Device
I would like to share my experience from the weekend to help others. At first let me explain the situation: I got my A5X Max+ 64GB eMMC preinstalled with Android 8.1 but I thought that the latest firmware available on the net can maybe make a positive difference to the shipped one. Seraching the web I found 3 different firmware version I thoght it would be good to give it a try. An A5X MAX+ Android 8.1 firmware An A5X MAX+ Android 7 firmware An A5X MAX Android 9 firmware (non "+" uses a dirfferent WiFi Chipset,....) Next Step folowing the firmware upgrade guides: 1. Trying to directly flash a new firmware via a SD card and SD_Firmware_Tool_v146_eng_AndroidPC failed 2. Trying to flash with a computer using RK_Batch_tool_v1_8_AndroidPC in combination with Rockchip_DriverAssitant_v4.4 is working Ok no difference to the preinstalled one so next step flashing a different firmware. The most interesting was the Android 9.0 firmware even when I know that it is for the non "+" version using a slightly different peripheral hardware. So I use the Batch tool again and start flashing. ==> Do not flash similar firmware on any device. The flash process abort after flashing only parts of the whole image. My Box is not starting anymore, and there is no video output when booting and it is not recognized by my computer anymore via USB My process to debrick my Device: My luck when starting into Recovery it is still recognized via USB Also there a dedicated test pins marked with TX, GND and RX so I connect a Serial to USB converter and check if I can find the problem. I could not find out what kind of baud rate the serial is using neither Start/Stop Bit configuration. A oscilloscope (Red Pitaya) helped a lot to see that the serial interface is working at a abnormal high baud rate: ~1350000 baud per second / 8N1 find here the current bootloop log: normal boot Code: Wed Oct 31 06:28:55 UTC 2018 aarch64) INF [0x0] TEE-CORE:init_primary_helper:338: Release version: 1.4 INF [0x0] TEE-CORE:init_teecore:83: teecore inits done INFO: BL31: Preparing for EL3 exit to normal world INFO: Entry point address = 0x200000 INFO: SPSR = 0x3c9 U-Boot 2017.09-02211-gd8ce1d0-dirty (Nov 27 2018 - 09:57:42 +0800) Model: Rockchip RK3328 EVB DRAM: 4 GiB Relocation Offset is: fcbda000 Using default environment [email protected]: 1, [email protected]: 0 Card did not respond to voltage select! mmc_init: -95, time 10 switch to partitions #0, OK mmc0(part 0) is current device boot mode: normal bad resource image magic: oint (current EL) DTB: rk-kernel.dtb bad resource image magic: oint (current EL) Can't find file:rk-kernel.dtb init_kernel_dtb dtb in resource read fail In: serial Out: serial Err: serial Model: Rockchip RK3328 EVB rockchip_set_serialno: could not find efuse device CLK: apll 400000000 Hz dpll 664000000 Hz cpll 1200000000 Hz gpll 491009999 Hz npll 600000000 Hz armclk 600000000 Hz aclk_bus 150000000 Hz hclk_bus 75000000 Hz pclk_bus 75000000 Hz aclk_peri 150000000 Hz hclk_peri 75000000 Hz pclk_peri 75000000 Hz Net: Net Initialization Skipped No ethernet found. Hit any key to stop autoboot: 0 ca head not found ANDROID: reboot reason: "(none)" get share memory, arg0=0x0 arg1=0x9e08000 arg2=0x3f8000 arg3=0x1 read_is_device_unlocked() ops returned that device is UNLOCKED avb_slot_verify.c:637: ERROR: vbmeta: Error verifying vbmeta image: OK_NOT_SIGNE D get share memory, arg0=0x0 arg1=0x9e08000 arg2=0x3f8000 arg3=0x1 DDR version 1.13 20180428 ID:0x805 N In DDR3 333MHz Bus Width=32 Col=11 Bank=8 Row=16 CS=1 Die Bus-Width=16 Size=4096MB ddrconfig:3 OUT Boot1 Release Time: Sep 7 2018 15:49:55, version: 2.49 ChipType = 0x11, 193 mmc2:cmd19,100 SdmmcInit=2 0 BootCapSize=2000 UserCapSize=59640MB FwPartOffset=2000 , 2000 SdmmcInit=0 NOT PRESENT StorageInit ok = 286281 Raw SecureMode = 0 SecureInit read PBA: 0x4 SecureInit read PBA: 0x404 SecureInit read PBA: 0x804 SecureInit read PBA: 0xc04 SecureInit read PBA: 0x1004 SecureInit ret = 0, SecureMode = 0 GPT part: 0, name: uboot, start:0x4000, size:0x2000 GPT part: 1, name: trust, start:0x6000, size:0x2000 GPT part: 2, name: misc, start:0x8000, size:0x2000 GPT part: 3, name: baseparameter, start:0xa000, size:0x800 GPT part: 4, name: resource, start:0xa800, size:0x8000 GPT part: 5, name: kernel, start:0x12800, size:0x10000 GPT part: 6, name: dtb, start:0x22800, size:0x2000 GPT part: 7, name: dtbo, start:0x24800, size:0x2000 GPT part: 8, name: logo, start:0x26800, size:0x8000 GPT part: 9, name: vbmeta, start:0x2e800, size:0x800 GPT part: 10, name: boot, start:0x2f000, size:0x10000 GPT part: 11, name: recovery, start:0x3f000, size:0x20000 GPT part: 12, name: backup, start:0x5f000, size:0x8000 GPT part: 13, name: cache, start:0x67000, size:0x80000 GPT part: 14, name: system, start:0xe7000, size:0x400000 GPT part: 15, name: metadata, start:0x4e7000, size:0x8000 GPT part: 16, name: vendor, start:0x4ef000, size:0x60000 GPT part: 17, name: oem, start:0x54f000, size:0x20000 GPT part: 18, name: frp, start:0x56f000, size:0x400 GPT part: 19, name: security, start:0x56f400, size:0x1000 GPT part: 20, name: userdata, start:0x570400, size:0x6f0bbdf find partition:uboot OK. first_lba:0x4000. find partition:trust OK. first_lba:0x6000. LoadTrust Addr:0x6000 No find bl30.bin HashBits:256, HashData: 6cf28742 2df532aa 1ea29e7b 85e4e128 9675b550 859f84c1 c47158c4 9373e8ea CalcHash: 2a0cacfb 655bd8b6 09989b08 c0ff4464 9d525d13 47eb7212 89197119 20d1a938 bl31.bin_0:CheckImage Fail! LoadTrust Addr:0x6400 LoadTrust Addr:0x6800 LoadTrust Addr:0x6c00 LoadTrust Addr:0x7000 No find bl30.bin Load uboot, ReadLba = 4000 hdr 000000000337a380 + 0x0:0x50,0x41,0x52,0x4d,0x66,0x03,0x00,0x00,0x46,0x49,0x52,0x4d,0x57,0x41,0x52,0x45, Load OK, addr=0x200000, size=0xeb934 RunBL31 0x10000 NOTICE: BL31: v1.3(debug):9d3f591 NOTICE: BL31: Built : 14:39:02, Jan 17 2018 NOTICE: BL31:Rockchip release version: v1.3 INFO: ARM GICv2 driver initialized INFO: Using opteed sec cpu_context! INFO: boot cpu mask: 1 INFO: plat_rockchip_pmu_init: pd status 0xe INFO: BL31: Initializing runtime services INFO: BL31: Initializing BL32 ERR [0x0] TEE-CORE:atags_get_tag:146: atags_get_tag: find unknown magic(d7f5f65b) INF [0x0] TEE-CORE:init_primary_helper:337: Initializing (1.1.0-187-g3f0aafa6 #9 Wed Oct 31 06:28:55 UTC 2018 aarch64) pressing and holding reset (without connecting to USB) Code: Wed Oct 31 06:28:55 UTC 2018 aarch64) INF [0x0] TEE-CORE:init_primary_helper:338: Release version: 1.4 INF [0x0] TEE-CORE:init_teecore:83: teecore inits done INFO: BL31: Preparing for EL3 exit to normal world INFO: Entry point address = 0x200000 INFO: SPSR = 0x3c9 U-Boot 2017.09-02211-gd8ce1d0-dirty (Nov 27 2018 - 09:57:42 +0800) Model: Rockchip RK3328 EVB DRAM: 4 GiB Relocation Offset is: fcbda000 Using default environment [email protected]: 1, [email protected]: 0 Card did not respond to voltage select! mmc_init: -95, time 10 switch to partitions #0, OK mmc0(part 0) is current device boot mode: normal bad resource image magic: oint (current EL) DTB: rk-kernel.dtb bad resource image magic: oint (current EL) Can't find file:rk-kernel.dtb init_kernel_dtb dtb in resource read fail In: serial Out: serial Err: serial Model: Rockchip RK3328 EVB rockchip_set_serialno: could not find efuse device CLK: apll 400000000 Hz dpll 664000000 Hz cpll 1200000000 Hz gpll 491009999 Hz npll 600000000 Hz armclk 600000000 Hz aclk_bus 150000000 Hz hclk_bus 75000000 Hz pclk_bus 75000000 Hz aclk_peri 150000000 Hz hclk_peri 75000000 Hz pclk_peri 75000000 Hz Net: Net Initialization Skipped No ethernet found. Hit any key to stop autoboot: 0 ca head not found ANDROID: reboot reason: "(none)" get share memory, arg0=0x0 arg1=0x9e08000 arg2=0x3f8000 arg3=0x1 read_is_device_unlocked() ops returned that device is UNLOCKED avb_slot_verify.c:637: ERROR: vbmeta: Error verifying vbmeta image: OK_NOT_SIGNE D get share memory, arg0=0x0 arg1=0x9e08000 arg2=0x3f8000 arg3=0x1 DDR version 1.13 20180428 ID:0x805 N In DDR3 333MHz Bus Width=32 Col=11 Bank=8 Row=16 CS=1 Die Bus-Width=16 Size=4096MB ddrconfig:3 OUT Boot1 Release Time: Sep 7 2018 15:49:55, version: 2.49 ChipType = 0x11, 193 mmc2:cmd19,100 SdmmcInit=2 0 BootCapSize=2000 UserCapSize=59640MB FwPartOffset=2000 , 2000 SdmmcInit=0 NOT PRESENT StorageInit ok = 286281 Raw SecureMode = 0 SecureInit read PBA: 0x4 SecureInit read PBA: 0x404 SecureInit read PBA: 0x804 SecureInit read PBA: 0xc04 SecureInit read PBA: 0x1004 SecureInit ret = 0, SecureMode = 0 GPT part: 0, name: uboot, start:0x4000, size:0x2000 GPT part: 1, name: trust, start:0x6000, size:0x2000 GPT part: 2, name: misc, start:0x8000, size:0x2000 GPT part: 3, name: baseparameter, start:0xa000, size:0x800 GPT part: 4, name: resource, start:0xa800, size:0x8000 GPT part: 5, name: kernel, start:0x12800, size:0x10000 GPT part: 6, name: dtb, start:0x22800, size:0x2000 GPT part: 7, name: dtbo, start:0x24800, size:0x2000 GPT part: 8, name: logo, start:0x26800, size:0x8000 GPT part: 9, name: vbmeta, start:0x2e800, size:0x800 GPT part: 10, name: boot, start:0x2f000, size:0x10000 GPT part: 11, name: recovery, start:0x3f000, size:0x20000 GPT part: 12, name: backup, start:0x5f000, size:0x8000 GPT part: 13, name: cache, start:0x67000, size:0x80000 GPT part: 14, name: system, start:0xe7000, size:0x400000 GPT part: 15, name: metadata, start:0x4e7000, size:0x8000 GPT part: 16, name: vendor, start:0x4ef000, size:0x60000 GPT part: 17, name: oem, start:0x54f000, size:0x20000 GPT part: 18, name: frp, start:0x56f000, size:0x400 GPT part: 19, name: security, start:0x56f400, size:0x1000 GPT part: 20, name: userdata, start:0x570400, size:0x6f0bbdf find partition:uboot OK. first_lba:0x4000. find partition:trust OK. first_lba:0x6000. LoadTrust Addr:0x6000 No find bl30.bin HashBits:256, HashData: 6cf28742 2df532aa 1ea29e7b 85e4e128 9675b550 859f84c1 c47158c4 9373e8ea CalcHash: 2a0cacfb 655bd8b6 09989b08 c0ff4464 9d525d13 47eb7212 89197119 20d1a938 bl31.bin_0:CheckImage Fail! LoadTrust Addr:0x6400 LoadTrust Addr:0x6800 LoadTrust Addr:0x6c00 LoadTrust Addr:0x7000 No find bl30.bin Load uboot, ReadLba = 4000 hdr 000000000337a380 + 0x0:0x50,0x41,0x52,0x4d,0x66,0x03,0x00,0x00,0x46,0x49,0x52,0x4d,0x57,0x41,0x52,0x45, Load OK, addr=0x200000, size=0xeb934 RunBL31 0x10000 NOTICE: BL31: v1.3(debug):9d3f591 NOTICE: BL31: Built : 14:39:02, Jan 17 2018 NOTICE: BL31:Rockchip release version: v1.3 INFO: ARM GICv2 driver initialized INFO: Using opteed sec cpu_context! INFO: boot cpu mask: 1 INFO: plat_rockchip_pmu_init: pd status 0xe INFO: BL31: Initializing runtime services INFO: BL31: Initializing BL32 ERR [0x0] TEE-CORE:atags_get_tag:146: atags_get_tag: find unknown magic(d7f5f65b) INF [0x0] TEE-CORE:init_primary_helper:337: Initializing (1.1.0-187-g3f0aafa6 #9 Wed Oct 31 06:28:55 UTC 2018 aarch64) INF [0x0] TEE-CORE:init_primary_helper:338: Release version: 1.4 INF [0x0] TEE-CORE:init_teecore:83: teecore inits done INFO: BL31: Preparing for EL3 exit to normal world INFO: Entry point address = 0x200000 INFO: SPSR = 0x3c9 U-Boot 2017.09-02211-gd8ce1d0-dirty (Nov 27 2018 - 09:57:42 +0800) Model: Rockchip RK3328 EVB DRAM: 4 GiB Relocation Offset is: fcbda000 Using default environment [email protected]: 1, [email protected]: 0 Card did not respond to voltage select! mmc_init: -95, time 9 switch to partitions #0, OK mmc0(part 0) is current device boot mode: None bad resource image magic: oint (current EL) DTB: rk-kernel.dtb bad resource image magic: oint (current EL) Can't find file:rk-kernel.dtb init_kernel_dtb dtb in resource read fail In: serial Out: serial Err: serial Model: Rockchip RK3328 EVB rockchip_set_serialno: could not find efuse device CLK: apll 400000000 Hz dpll 664000000 Hz cpll 1200000000 Hz gpll 491009999 Hz npll 600000000 Hz armclk 600000000 Hz aclk_bus 150000000 Hz hclk_bus 75000000 Hz pclk_bus 75000000 Hz aclk_peri 150000000 Hz hclk_peri 75000000 Hz pclk_peri 75000000 Hz Net: Net Initialization Skipped No ethernet found. Hit any key to stop autoboot: 0 ca head not found ANDROID: reboot reason: "(none)" get share memory, arg0=0x0 arg1=0x9e08000 arg2=0x3f8000 arg3=0x1 read_is_device_unlocked() ops returned that device is UNLOCKED avb_slot_verify.c:637: ERROR: vbmeta: Error verifying vbmeta image: OK_NOT_SIGNED get share memory, arg0=0x0 arg1=0x9e08000 arg2=0x3f8000 arg3=0x1 Booting kernel at 0x207f800 with fdt at f4dcfca0... ## Booting Android Image at 0x0207f800 ... Kernel load addr 0x02080000 size 19005 KiB ## Flattened Device Tree blob at f4dcfca0 Booting using the fdt blob at 0xf4dcfca0 XIP Kernel Image ... OK Loading Device Tree to 00000000081fb000, end 00000000081ff0f8 ... OK Adding bank: 0x00200000 - 0x08400000 (size: 0x08200000) Adding bank: 0x0a200000 - 0xff000000 (size: 0xf4e00000) Starting kernel ... "Synchronous Abort" handler, esr 0x02000000 * Relocate offset = 00000000fcbda000 * ELR(PC) = ffffffff064c6000 * LR = 0000000000201f00 * SP = 00000000f4dcf2a0 * ESR_EL2 = 0000000002000000 EC[31:26] == 000000, Exception with an unknown reason IL[25] == 1, 32-bit instruction trapped * DAIF = 00000000000003c0 D[9] == 1, DBG masked A[8] == 1, ABORT masked I[7] == 1, IRQ masked F[6] == 1, FIQ masked * SPSR_EL2 = 00000000600003c9 D[9] == 1, DBG masked A[8] == 1, ABORT masked I[7] == 1, IRQ masked F[6] == 1, FIQ masked M[4] == 0, Exception taken from AArch64 M[3:0] == 1001, EL2h * SCTLR_EL2 = 0000000030c50830 I[12] == 0, Icache disabled C[2] == 0, Dcache disabled M[0] == 0, MMU disabled * HCR_EL2 = 0000000000000002 * VBAR_EL2 = 00000000fcdda800 * TTBR0_EL2 = 00000000feff0000 x0 : 00000000081fb000 x1 : 0000000000000000 x2 : 0000000000000000 x3 : 0000000000000000 x4 : 0000000002080000 x5 : 0000000000000001 x6 : 0000000000000008 x7 : 0000000000000000 x8 : 00000000f4dcf320 x9 : 0000000001008000 x10: 000000000a200023 x11: 0000000000000002 x12: 0000000000000002 x13: 00000000f4dcf36c x14: 00000000081fb000 x15: 00000000fcddb5a8 x16: 0000000000000002 x17: 00000000081ff0f9 x18: 00000000f4dd1da0 x19: 0000000000000400 x20: 00000000fcec52e0 x21: 0000000000000000 x22: 0000000000000003 x23: 00000000f4dcf630 x24: 0000000000000000 x25: 0000000002080000 x26: 00000000fcddbea4 x27: 0000000000000400 x28: 0000000002080000 x29: 00000000f4dcf480 SP: f4dcf2a0: 00000000 00000000 00000000 00000000 f4dcf2b0: 00000000 00000000 fcea3759 00000000 f4dcf2c0: 00000000 00000000 00000000 00000000 f4dcf2d0: fcea37a0 00000000 fcea37c6 00000000 f4dcf2e0: fcea3813 00000000 fcea3860 00000000 f4dcf2f0: fcea38a0 00000000 fcea38e0 00000000 f4dcf300: fcea391d 00000000 00000000 00000000 f4dcf310: 00000000 00000000 fcea395a 00000000 f4dcf320: f4dcf480 00000000 fcddaa0c 00000000 f4dcf330: 00000400 00000000 fce9d415 00000000 f4dcf340: feff0000 00000000 00000002 00000000 f4dcf350: 30c50830 00000000 f4dcf2a0 00000000 f4dcf360: 600003c9 00000000 fcdda800 00000000 f4dcf370: 000003c0 00000000 02000000 00000000 f4dcf380: 030a0000 00000000 081fb000 00000000 f4dcf390: 00000000 00000000 00000000 00000000 Resetting CPU ... WARN: PSCI sysreset is disabled DDR version 1.13 20180428 ID:0x805 N In SRX DDR3 333MHz Bus Width=32 Col=11 Bank=8 Row=16 CS=1 Die Bus-Width=16 Size=4096MB ddrconfig:3 OUT Boot1 Release Time: Sep 7 2018 15:49:55, version: 2.49 ChipType = 0x11, 261 mmc2:cmd19,100 SdmmcInit=2 0 BootCapSize=2000 UserCapSize=59640MB FwPartOffset=2000 , 2000 SdmmcInit=0 NOT PRESENT StorageInit ok = 285008 Raw SecureMode = 0 SecureInit read PBA: 0x4 SecureInit read PBA: 0x404 SecureInit read PBA: 0x804 SecureInit read PBA: 0xc04 SecureInit read PBA: 0x1004 SecureInit ret = 0, SecureMode = 0 GPT part: 0, name: uboot, start:0x4000, size:0x2000 GPT part: 1, name: trust, start:0x6000, size:0x2000 GPT part: 2, name: misc, start:0x8000, size:0x2000 GPT part: 3, name: baseparameter, start:0xa000, size:0x800 GPT part: 4, name: resource, start:0xa800, size:0x8000 GPT part: 5, name: kernel, start:0x12800, size:0x10000 GPT part: 6, name: dtb, start:0x22800, size:0x2000 GPT part: 7, name: dtbo, start:0x24800, size:0x2000 GPT part: 8, name: logo, start:0x26800, size:0x8000 GPT part: 9, name: vbmeta, start:0x2e800, size:0x800 GPT part: 10, name: boot, start:0x2f000, size:0x10000 GPT part: 11, name: recovery, start:0x3f000, size:0x20000 GPT part: 12, name: backup, start:0x5f000, size:0x8000 GPT part: 13, name: cache, start:0x67000, size:0x80000 GPT part: 14, name: system, start:0xe7000, size:0x400000 GPT part: 15, name: metadata, start:0x4e7000, size:0x8000 GPT part: 16, name: vendor, start:0x4ef000, size:0x60000 GPT part: 17, name: oem, start:0x54f000, size:0x20000 GPT part: 18, name: frp, start:0x56f000, size:0x400 GPT part: 19, name: security, start:0x56f400, size:0x1000 GPT part: 20, name: userdata, start:0x570400, size:0x6f0bbdf find partition:uboot OK. first_lba:0x4000. find partition:trust OK. first_lba:0x6000. LoadTrust Addr:0x6000 No find bl30.bin HashBits:256, HashData: 6cf28742 2df532aa 1ea29e7b 85e4e128 9675b550 859f84c1 c47158c4 9373e8ea CalcHash: 2a0cacfb 655bd8b6 09989b08 c0ff4464 9d525d13 47eb7212 89197119 20d1a938 bl31.bin_0:CheckImage Fail! LoadTrust Addr:0x6400 LoadTrust Addr:0x6800 LoadTrust Addr:0x6c00 LoadTrust Addr:0x7000 No find bl30.bin Load uboot, ReadLba = 4000 hdr 000000000337a380 + 0x0:0x50,0x41,0x52,0x4d,0x66,0x03,0x00,0x00,0x46,0x49,0x52,0x4d,0x57,0x41,0x52,0x45, Load OK, addr=0x200000, size=0xeb934 RunBL31 0x10000 NOTICE: BL31: v1.3(debug):9d3f591 NOTICE: BL31: Built : 14:39:02, Jan 17 2018 NOTICE: BL31:Rockchip release version: v1.3 INFO: ARM GICv2 driver initialized INFO: Using opteed sec cpu_context! INFO: boot cpu mask: 1 INFO: plat_rockchip_pmu_init: pd status 0xe INFO: BL31: Initializing runtime services INFO: BL31: Initializing BL32 INF [0x0] TEE-CORE:init_primary_helper:337: Initializing (1.1.0-187-g3f0aafa6 #9 Wed Oct 31 06:28:55 UTC 2018 aarch64) When connecting USB for flashing the Log shows the detection and do not loop anymore, it is waiting for the process to be initiated by the computer I try to flash the Android 8.1 firmware without luck because the automatic checks stopped the process before starting So I tried to flash with Factory Tool 1.6 but also without success, it is checking also before starting the flash process Searching all over the web I found different versions of these tools and test newer ones but also without success. After a while I found a Tool called Rockchip Android Tool 2.1 for Rockchip based single board computers. This tool has much more options to check and flash a Rockchip board over USB. Most of the checks failed and I figured out that a normal flashing process will always reboot the board into Maskrom mode It seems that my device is not able to go into Maskrom Mode anymore because after starting the flash process it is reseting and booting normal (bootloop) instead of switching to Maskrom Mode. A bit of evaluation tells me that the Maskrom Mode can also be achieved by shorting the Flash CLK to ground during boot. (I know a similar process for my Fire HD8 Tablet) I checked if I can find the CLK line on the board but it seems that it is not accessably from the surface of the PCB. After minutes of reaserch I figured out that there are also newer version of the Android Tool available and I tested all I can find. Also Device drivers shall be updated due to a problem report of an Rockchip device singel board computer owner that has also some difficulties working with the tools. My luck I found RKDevTool 2.52 (The new name of the Android Tool), in this tool a few of the tests for Rockchip devices are working and I was able to flash Android 8.1 and enter the Maskrom Mode sucessfully. Now that my Device is back alive I will also post some logs and pictures of my device to help others when trying to debrick/reacticate from an unexpected state.
@sandman01 Try this
thanks for your post. I think I was a bit to euphoric because my box is working again and I only want to share my experiance for others runnign in the same Situation. It was hard to get all the Information out of the web, from multiple places.
sandman01 said: thanks for your post. I think I was a bit to euphoric because my box is working again and I only want to share my experiance for others runnign in the same Situation. It was hard to get all the Information out of the web, from multiple places. Click to expand... Click to collapse Ok no probs
Can't find those files on Drive anymore, can you please share them? Can't find a place to download RKDevtool Thanks in advance
boot image repackaged with abootimg fails with "error boot prepare"
Device: Pixel4 Build number: QQ2A.200501.001.B2 Extracted boot.img from factory image. $ abootimg -i boot.img Android Boot Image Info: * file name = boot.img * image size = 67108864 bytes (64.00 MB) page size = 4096 bytes * Boot Name = "" * kernel size = 20975335 bytes (20.00 MB) ramdisk size = 10529977 bytes (10.04 MB) * load addresses: kernel: 0x00008000 ramdisk: 0x01000000 tags: 0x00000100 * cmdline = console=ttyMSM0,115200n8 androidboot.console=ttyMSM0 printk.devkmsg=on msm_rtb.filter=0x237 ehci-hcd.park=3 service_locator.enable=1 androidboot.memcg=1 cgroup.memory=nokmem usbcore.autosuspend=7 androidboot.usbcontroller=a600000.dwc3 swiotlb=2048 androidboot.boot_devices=soc/1d84000.ufshc buildvariant=user * id = 0x622e458e 0xec0f5ea0 0x0f7f2da1 0xf8943ad5 0xa963b0ec 0x00000000 0x00000000 0x00000000 I repackaged the boot image with $ abootimg --create myboot.img -f bootimg.cfg -k zImage -r initrd.img and I get $ abootimg -i myboot.img Android Boot Image Info: * file name = myboot.img * image size = 67108864 bytes (64.00 MB) page size = 4096 bytes * Boot Name = "" * kernel size = 20975335 bytes (20.00 MB) ramdisk size = 10513203 bytes (10.03 MB) * load addresses: kernel: 0x00008000 ramdisk: 0x01000000 tags: 0x00000100 * cmdline = console=ttyMSM0,115200n8 androidboot.console=ttyMSM0 printk.devkmsg=on msm_rtb.filter=0x237 ehci-hcd.park=3 service_locator.enable=1 androidboot.memcg=1 cgroup.memory=nokmem usbcore.autosuspend=7 androidboot.usbcontroller=a600000.dwc3 swiotlb=2048 androidboot.boot_devices=soc/1d84000.ufshc buildvariant=user * id = 0x00000000 0x00000000 0x00000000 0x00000000 0x00000000 0x00000000 0x00000000 0x00000000 I have not modified the ramdisk. I am just trying to extract and repackage the boot image, in order to test abootimg. When flashing new boot image, on boot I get "error boot prepare". Anyone knows why the abootimg tool is not working? Anything I am doing wrong?
H96 Max X4 superimage
Hi! I have some problems And sorry for my english. I bought a H96 Max X4 Android TV box from Geekbuying. I have factory firmwares for it, so i start to modify the device. It has Android TV 11 version. The device has root shell on adb, but the device not rooted itself. The problems are: I can unpack superimage from stock firmware, and able to do dd backup super from device. But i can not use fastboot flashing because of "FAILED (remote: 0ffff13c)" error. The number changes depending on which superimage I am trying to write. This is not real problem, beacuse of i can use dd for flash back the images. But... If i try to write back the backuped superimage or what extracted from stock FW, everything is okay. But the unpacked and repacked image causes bootloop. The lpdump says the device's metadata and the repacked superimage's metadata are the same: ohm:/ # lpdump Slot 0: Metadata version: 10.2 Metadata size: 1104 bytes Metadata max size: 65536 bytes Metadata slot count: 3 Header flags: virtual_ab_device Partition table: ------------------------ Name: system_a Group: amlogic_dynamic_partitions_a Attributes: readonly Extents: 0 .. 1839895 linear super 2048 ------------------------ Name: system_b Group: amlogic_dynamic_partitions_b Attributes: readonly Extents: ------------------------ Name: vendor_a Group: amlogic_dynamic_partitions_a Attributes: readonly Extents: 0 .. 357943 linear super 1843200 ------------------------ Name: vendor_b Group: amlogic_dynamic_partitions_b Attributes: readonly Extents: ------------------------ Name: product_a Group: amlogic_dynamic_partitions_a Attributes: readonly Extents: 0 .. 854999 linear super 2201600 ------------------------ Name: product_b Group: amlogic_dynamic_partitions_b Attributes: readonly Extents: ------------------------ Name: odm_a Group: amlogic_dynamic_partitions_a Attributes: readonly Extents: 0 .. 1559 linear super 3057664 ------------------------ Name: odm_b Group: amlogic_dynamic_partitions_b Attributes: readonly Extents: ------------------------ Name: system_ext_a Group: amlogic_dynamic_partitions_a Attributes: readonly Extents: 0 .. 133159 linear super 3059712 ------------------------ Name: system_ext_b Group: amlogic_dynamic_partitions_b Attributes: readonly Extents: ------------------------ Super partition layout: ------------------------ super: 2048 .. 1841944: system_a (1839896 sectors) super: 1843200 .. 2201144: vendor_a (357944 sectors) super: 2201600 .. 3056600: product_a (855000 sectors) super: 3057664 .. 3059224: odm_a (1560 sectors) super: 3059712 .. 3192872: system_ext_a (133160 sectors) ------------------------ Block device table: ------------------------ Partition name: super First sector: 2048 Size: 2415919104 bytes Flags: none ------------------------ Group table: ------------------------ Name: default Maximum size: 0 bytes Flags: none ------------------------ Name: amlogic_dynamic_partitions_a Maximum size: 1876951040 bytes Flags: none ------------------------ Name: amlogic_dynamic_partitions_b Maximum size: 1876951040 bytes Flags: none ------------------------ I use this command to repack the superimage: ./lpmake --metadata-size 65536\ --device-size=2415919104\ --metadata-slots=3\ --super-name=super\ --group=amlogic_dynamic_partitions_a:1876951040\ --group=amlogic_dynamic_partitions_b:1876951040\ --partition=system_a:readonly:942026752:amlogic_dynamic_partitions_a\ --partition=system_b:readonly:0:amlogic_dynamic_partitions_b\ --partition=vendor_a:readonly:183267328:amlogic_dynamic_partitions_a\ --partition=vendor_b:readonly:0:amlogic_dynamic_partitions_b\ --partition=product_a:readonly:437760000:amlogic_dynamic_partitions_a\ --partition=product_b:readonly:0:amlogic_dynamic_partitions_b\ --partition=odm_a:readonly:798720:amlogic_dynamic_partitions_a\ --partition=odm_b:readonly:0:amlogic_dynamic_partitions_b\ --partition=system_ext_a:readonly:68177920:amlogic_dynamic_partitions_a\ --partition=system_ext_b:readonly:0:amlogic_dynamic_partitions_b\ --image=system_a=/super/system_a.img\ --image=system_b=/super/system_b.img\ --image=vendor_a=/super/vendor_a.img\ --image=vendor_b=/super/vendor_b.img\ --image=product_a=/super/product_a.img\ --image=product_b=/super/product_b.img\ --image=odm_a=/super/odm_a.img\ --image=odm_b=/super/odm_b.img\ --image=system_ext_a=/super/system_ext_a.img\ --image=system_ext_b=/super/system_ext_b.img\ --virtual-ab\ --output /super/supernew.img The unpacked modified superimage and the unpacked stock superimage gives the same files. Any idea for what is the problem? Thanks!
For more information here are the imjtool results: Original, factory superimage: ./imjtool /mnt/rawsuper.img MMapped: 0x7f9606303000, imgMeta 0x7f9606304000 liblp dynamic partition (super.img) - Blocksize 0x1000, 3 slots LP MD Header @0x3000, version 10.2, with 10 logical partitions @0x0 on block device of 2304 GB, at partition super, first sector: 0x800 Partitions @0x3100 in 3 groups: Group 0: default Group 1: amlogic_dynamic_partitions_a Name: system_a (read-only, Linux Ext2/3/4/? Filesystem Image, @0x100000 spanning 1 extents of 898 MB) Name: vendor_a (read-only, Linux Ext2/3/4/? Filesystem Image, @0x38400000 spanning 1 extents of 174 MB) Name: product_a (read-only, Linux Ext2/3/4/? Filesystem Image, @0x43300000 spanning 1 extents of 417 MB) Name: odm_a (read-only, Linux Ext2/3/4/? Filesystem Image, @0x5d500000 spanning 1 extents of 780 KB) Name: system_ext_a (read-only, Linux Ext2/3/4/? Filesystem Image, @0x5d600000 spanning 1 extents of 65 MB) Group 2: amlogic_dynamic_partitions_b Name: system_b (read-only, empty) Name: vendor_b (read-only, empty) Name: product_b (read-only, empty) Name: odm_b (read-only, empty) Name: system_ext_b (read-only, empty) And the repacked superimage: ./imjtool /mnt/supernew.img MMapped: 0x7f3a9dc5b000, imgMeta 0x7f3a9dc5c000 liblp dynamic partition (super.img) - Blocksize 0x1000, 3 slots LP MD Header @0x3000, version 10.2, with 10 logical partitions @0x0 on block device of 2304 GB, at partition super, first sector: 0x800 Partitions @0x3100 in 3 groups: Group 0: default Group 1: amlogic_dynamic_partitions_a Name: system_a (read-only, Linux Ext2/3/4/? Filesystem Image, @0x100000 spanning 1 extents of 898 MB) Name: vendor_a (read-only, Linux Ext2/3/4/? Filesystem Image, @0x38400000 spanning 1 extents of 174 MB) Name: product_a (read-only, Linux Ext2/3/4/? Filesystem Image, @0x43300000 spanning 1 extents of 417 MB) Name: odm_a (read-only, Linux Ext2/3/4/? Filesystem Image, @0x5d500000 spanning 1 extents of 780 KB) Name: system_ext_a (read-only, Linux Ext2/3/4/? Filesystem Image, @0x5d600000 spanning 1 extents of 65 MB) Group 2: amlogic_dynamic_partitions_b Name: system_b (read-only, empty) Name: vendor_b (read-only, empty) Name: product_b (read-only, empty) Name: odm_b (read-only, empty) Name: system_ext_b (read-only, empty)
There Is no any idea?