Droid 2 PRL Location? - Droid 2 General

Does anyone know the location of the PRL in the file system (without having to hook it up to PST through the Serial Emulator)?

You cannot access the part of the EFS that contains the nvm directory where the PRL is stored. This has been the case for all Motorola handsets since the V3m.
The only way to pull the PRL is via DIAG mode NV access which can be done without the virtual serial port if you have the right Qualcomm diagnostic drivers.

With a bit of effort you could probably access the EFS with either cdma ws or qpst, though I haven't used either program in a couple years. Used to be able to do it with bitpim in most cases as well, though it's hard to say what kind of compatibility you'll have and i'm not even sure if they are maintaining that project anymore

You can't access the part of the EFS that contains the NVM directory.
If you haven't tried in a few years then your information is extremely dated.
You cannot read or write the PRL without NV access.
The OP wanted a method that does not involve using a virtual COM port for the modem.
All of the methods of reading/writing PRLs including QXDM, QPST and CDMA Workshop require a COM port assignment.
The one method of NV access that does not need a virtual COM port is RadioComm, but it doesn't have a specific way to read and write the PRL and must be done by pulling the raw hex data from seem 0101.
The problem is that the PRLs have grown over the years and are now larger than 4kb, which is the limit of the size of a single SEEM element that can be read using the STELEM/RDELEM module in RadioComm.
So, if you try to write the PRL as a SEEM element you dont get it all and your PRL is corrupt as a result and your phone will not boot until it's fixed.

This thread maybe a good bit of help. It helped me. http://forum.xda-developers.com/showthread.php?t=843496

Related

I can access the inner file system of my X2.

Guys and gals...
I've got a bricked X2, so things can't get any worse at present.
I took the advice which was displayed in another thread, and downloaded the Qualcomm QPST package.
x-drivers.com/catalog/flash/mobile_phones/companies/qualcomm/models/qpst/12051.html
I deleted the default comm ports in the QPST configuration tool, added both USB ports that were available, did the Volume Down + Power On keypress, connected the cable, and voila! The phone was recognised, and it was possible to browse through the phone using EFS Explorer. Using QPST Service Programming, I can view and edit a whole LOAD of stuff inside the phone. Wow.
I haven't dared change a single thing yet. I'm hoping someone can now contribute and we can begin to understand how to use this package to our advantage.
hopefully this will bring us closer to spl!!!
Great Work...
Further information
Further information...
You can configure two USB ports (called COM13 and COM15) using the QPST Configuration server.
When you do the Power On + Volume Down combination, the phone appears to enter Diagnostic mode, and shows up as being connected on COM13.
When you do the Power On + Volume Up combination, the phone appears to enter Download mode, and shows up as being connected on COM15.
I don't yet know what the significance is, or what to do about it. But again, I'm hoping that someone will be able to shed some more light on this.
I guess the main aim at this stage would be to find out how to access the WM file directories inside the phone.
Developers have disappeared in the wild
The HardSPL's project is dead and buried...
lo said:
Developers have disappeared in the wild
The HardSPL's project is dead and buried...
Click to expand...
Click to collapse
im sure it can start back now that we have this to use!
I've tried and that works.
I can backup a qcn file but I don't know what it is???

MSL/SPC for Defy XT557

I'm trying to discover the SPC/MSL for my Defy XT557 (Republic Wireless) in order to obtain root. Can flip the phone into DIAG mode using SUT LR and open a COM port, which is then recognized by CDMA WS and DFS cdmatool, but cannot even obtain a successful memory scan or dump using those programs. Radiocomm gives a green circle but no RDELEM hex readout. getprop ril.MSL readout is empty, and alogcat while entering diagnostic phone codes does not show the MSL.
Any ideas would be greatly appreciated.
So I'm thinking at this point that we should wait for the OTA in January and then we might be able to piggyback onto that... Obviously the update will be signed, so we won't be able to modify and then apply it but... we might be able to log enough of the process that we could get lucky and get the info we need to hack this sucker.
has there been any progress in the XT557...
ejlmd said:
I'm trying to discover the SPC/MSL for my Defy XT557 (Republic Wireless) in order to obtain root. Can flip the phone into DIAG mode using SUT LR and open a COM port, which is then recognized by CDMA WS and DFS cdmatool, but cannot even obtain a successful memory scan or dump using those programs. Radiocomm gives a green circle but no RDELEM hex readout. getprop ril.MSL readout is empty, and alogcat while entering diagnostic phone codes does not show the MSL.
Any ideas would be greatly appreciated.
Click to expand...
Click to collapse
How do you get the phone into diag mode using SUT LR? I have installed SUT LR and it detects a phone, but I don't see how to open a com port. I checked the device manage and it only had COM1. Thanks for your help.
How do I put my Defy XT in DIAG mode? sut lr not detects phone...
ejlmd said:
I'm trying to discover the SPC/MSL for my Defy XT557 (Republic Wireless) in order to obtain root. Can flip the phone into DIAG mode using SUT LR and open a COM port, which is then recognized by CDMA WS and DFS cdmatool, but cannot even obtain a successful memory scan or dump using those programs. Radiocomm gives a green circle but no RDELEM hex readout. getprop ril.MSL readout is empty, and alogcat while entering diagnostic phone codes does not show the MSL.
Any ideas would be greatly appreciated.
Click to expand...
Click to collapse
how you get diag mode with SUT LR???
3a4yI7aTiY said:
how you get diag mode with SUT LR???
Click to expand...
Click to collapse
Sorry, I no longer own the phone. But in any case it seemed like a dead end.
The following was posted on one of the Republic Wireless forums regarding obtaining carrier info from a rooted Defy XT 557:
For anyone trying to get information from CDMA Workshop or get info DIAG mode, you can gain access by doing the following:
change the value of /sys/class/usb_composite/diag to 1
I did this using root explorer and edited the value using text editor.
you can then connect without SPC and click read to view most settings (probably enough to cl*ne if wanted).
It also looks like data in the NV Dump file showed data connection info of:
[email protected]
hcm.sprintpcs.com

[R&D][QUALCOMM] Using QDL, EHostDL and DIAG interfaces & features

This thread is for the research, development and discussion of open source tools (initially Linux) to communicate with and utilize the various proprietary interfaces available on Qualcomm devices.
Initial development is centered around the MSM8660 and MSM8960 devices, but should be applicable to nearly any Qualcomm device which includes a modem and USB port. Older devices with a Serial port may also work. Components to be supported: DMSS Download Protocol (QDL mode), Streaming Download Protocol (EHostDL), and parts of other HDLC structured Qualcomm protocols.
An expanded description, examples, references, and test programs to follow shortly.
Goals
To provide a partial Open Source (Linux) replacement for QPST and QXDM
To enable the full recovery of various Android devices based on supported Qualcomm SoC's
To gain a better understanding of the underlying hardware in Qualcomm based Android devices
Change Log:
2013-01-06
Initial creation to consolidate OT discussions from other threads.
2013-01-07
Expanded description
Added external thread and web links
Added #QDL_Dev on IRC Freenode for open discussion
2013-01-28
Updated a few posts to correct prior mistakes.
Internal Thread Links
coming soon...
External Thread Links
[REF][R&D] MSM8960 Info, Architecture and Bootloader(s) http://forum.xda-developers.com/showthread.php?t=1856327
Lots of important information and Qualcomm PDF's. Should be considered required reading. By E:V:A
[REF][R&D] Building Bootloaders on Qualcomm Devices http://forum.xda-developers.com/showthread.php?t=1978703
By E:V:A
[DEV][REF] El Grande Partition Table Reference http://forum.xda-developers.com/showthread.php?t=1959445
The definitive resource for device partition information. By E:V:A
No JTAG [SOLVED][JTAG,BRICK]SHV-E160L Korean model http://forum.xda-developers.com/showthread.php?t=1914359
R&D for unbricking/fully recovering a SHV-E160L and various helpful utilities. By Darkspr1te
External Web Links
Code Aurora Forum https://www.codeaurora.org/
Home to various Open Source projects related to Qualcomm technologies.
Gobi https://www.codeaurora.org/contribute/projects/gobi/
A Code Aurora Forum project fueled by Qualcomm which serves as a reference for these protocol implementations.
AnyClub Blog http://www.anyclub.org/
A blog with limited yet specific information regarding Qualcomm MSM, MDM, QRD and related products. Can get technical at times and references closed source and proprietary files/programs.
Join us for live discussion in #QDL_DEV on IRC Freenode
Credits/Thanks:
E:V:A for various reference threads which both sparked my interest and fueled my initial research.
Darkspr1te for his involvement with initial and ongoing development.
Ralekdev for providing additional insight in to msm8960 PBL
.
Yarrimapirate for creation of JET (Jewel Evita Toolkit) which served as my first hands-on with QDL and led me down the path to here.
Fuses for his emmc_recover program, which gave me my first glimpse of using HDLC to communicate with a Qualcomm based phone. Also for his typically brief and discouraging posts, which in turn drives my desire to prove him wrong
Captain_Throwback for providing firmware zips, testing, and more bricked phones then anyone else I've met.
others whom I'll add as I think of them.
Knowledge Base
Definitions:
PBL = Primary Boot Loader
SBL = Secondary Boot Loader
RPM = Resource and Power Management
TZ = Trust Zone
HDLC = High-level Data Link Control
MSM = Mobile Station Modem
DMSS = Dual-Mode Subscriber Station
QDL = Qualcomm Download
QHSUSB_DLOAD = Qualcomm High Speed USB Download
EhostDL = Emergency Host Download
DCN = Document Control Number, used by Qualcomm to track their thousands of documents
Qualcomm has built in to their firmware multiple methods of communication with outside "hosts" (a computer connected to the phone). Each method serves a particular function. AT commands are used to communicate with the modem while it is "online" and their multiple diagnostic protocols communicate with the modem in "offline" mode. These diagnostic protocols use HDLC (both synchronous and asynchronous) for the framing. It is a low overhead frame/packet transport which includes a 16 bit CRC for error checking, originally used over serial connections to the phone. Today these protocols are still being used over USB. Under Linux a usb-serial connection can be established by the qcserial kernel module via a /dev/ttyUSB (ex: /dev/ttyUSB0, /dev/ttyUSB1)
HDLC: A brief overview.
The basic HDLC structure is:
Each field is a multiple of 8-bits (1 byte).
HDLC uses 0x7e for the header and flag. For AsyncHDLC the header is optional, but Qualcomm always uses it. Also, the flag of one HDLC frame is allowed to be used as the header of the next frame. It also uses 0x7d as an escape for occurrences of 0x7e and 0x7d. All escaping is done after calculating the CRC and is applied to both the packet and CRC.
The packet is further broken down in to:
The packet header consists of:
The command is a 1 byte (0x00) code that determines the layout of the packet.
The parameters vary by command and specify different command specific options and the size of any data being transferred.
The CRC is generated using the standard CRC-CCITT-16 generator polynomial of: f(x)=x^16+x^12+x^5+1
Google it for more info.
Examples:
NO-OP: 7e 06 4e 95 7e
ACK: 7e 02 6a d3 7e
Software Version Request: 7e 0c 14 3a 7e
Software Version Response: 7e 0d 0f 50 42 4c 5f 44 6c 6f 61 64 56 45 52 31 2e 30 37 41 7e
Full Documentation:
DMSS Download Protocol: DCN 80-39912-1 Revision E
Describes in detail the commands used with QHSUSB_DLOAD (both SBL and PBL)
Streaming Download Protocol: DCN 80-V5348-1 Revision J
Describes in detail the commands used with the Flash Programmer (MPRGxxxx.hex)
CDMA DMSS Serial Data: DCN 80-V1294-1 Revision YP
Describes in detail the basic commands used with the modem Diagnostic mode. This protocol supports a MASSIVE amount of extentions covered in numerous other specialized documents. There is no current plan to implement these extensions.
...more to follow...
SPECIAL NOTE ABOUT THE NEXT POST:
If you attempt to use the msimage.mbn,YOU MUST CREATE IT USING THE SAME VERSION (or newer) FIRMWARE ALREADY ON YOUR PHONE. I'm not 100% sure if this applies to older models, but at least with msm8960 and newer.
Why?
Because, in addition to checking the signature of the image, the PBL also checks the firmware version against an efuse value for rollback prevention. If the OEM enables this feature then an older firmware will cause an error and will jump back to the last successfully loaded version of QDL mode. (ie: pbl, sbl1, etc...) This behavior has been the cause of many bricks for HTC Evo 4g LTE (jewel) owners who try to downgrade their firmware via ruu or recovery (sorry captn).
The firmware images involved are:
sbl1, sbl2, sbl3, tz and rpm.
DMSS And Streaming Protocol Tool
UPDATE: Code updated as of 17-01-2013, post will update to follow new code soon - Darkspr1te
First POC, Thats Proof of concept , not piece of c**p.
The concept behind this came from Soul Shadow, who like me feel that in a world without walls and fences who need windows and gates.
The original script was pulled from some git/website i dont remember belonging to a person i only know as scotty (please step forward )
JCSullins over from rootzwiki went running with the script to give us this working concept.
What is it?
This script fire's HDLC encoded frames at the serial port, namely qcserial for a Qualcomm HS_USB QDLOAD device 05c6:9008
within these frames are commands for various functions with great names like Hello, and Open MI.
Here is a example frame
Code:
0x7e 0x0a 0x63 0x74 0x7e
0x7e start of frame
0x0a command (this one is with out data)
0x63 crc low bit
0x74 crc high bit
0x7e close of frame
HDLC is all well document around the net so i wont go over it too much just yet. the important part is knowing the commands, what they do and what the payload, if any is and how that's formatted.
Why Do We need it?
The QDLOAD and EDLOAD protocols allow further control over your device, possible debrick solutions too, thats why we are developing it, some have mentioned other possible benifits but to reduce the google crew sending eveyone here looking for off-s solution and this thread going off topic we are avoiding that.Please can you also avoid topics of that nature.
What About Windows
You already have QPST and QXDM, us poor linux users dont. I am sure cygwin can help you there, some code changes may be required.
Enough Already, Gimme
https://github.com/jcsullins/qdloader
How Do I use it?
First you need to get the hex file for your device, if it's a msm8660 then your need mrpg8660.hex, they are found elsewhere, links will be posted later but for now use the search
then you need to run hex2bin on the hex file to have mrpgXXXX.bin which you rename hex.bin
then you need your emmc payload, this normally would be xxxx_msimage.mbn which you rename hex2.bin
then perl qdload.pl while you device is plugged in, there will be some debug output showing first and second stage uploads.
It's Didnt work,my device is still bricked, Answer my PM dammit!!
As I mentioned , this is a proof of concept file for study and not really ment to be a oneclick solution. Feed back is most welcome but dont mail the developers with questions for debricking the device, this is a tool to study and develop.
I REPEAT, stay away from this tool if you are not already familiar with qualcomm boot procedures, emmc system and the like.
EDIT: We have Found the original author of the script which we based the above on.
Scotty Walker
https://github.com/tmzt/g2root-kmod/tree/master/scotty2/pbl
Credits to The Man for making his work public.
deleted
SouL Shadow said:
SPECIAL NOTE ABOUT THE NEXT POST:
If you attempt to use the msimage.mbn,YOU MUST CREATE IT USING THE SAME VERSION (or newer) FIRMWARE ALREADY ON YOUR PHONE. I'm not 100% sure if this applies to older models, but at least with msm8960 and newer.
Why?
Because, in addition to checking the signature of the image, the PBL also checks the firmware version against an efuse value for rollback prevention. If the OEM enables this feature then an older firmware will cause an error and will jump back to the last successfully loaded version of QDL mode. (ie: pbl, sbl1, etc...) This behavior has been the cause of many bricks for HTC Evo 4g LTE (jewel) owners who try to downgrade their firmware via ruu or recovery (sorry captn).
The firmware images involved are:
sbl1, sbl2, sbl3, tz and rpm.
Click to expand...
Click to collapse
I was on 1.73 firmware(older or stock) when i bricked my phone.so you mean i have create a mbn file from a device which has 1.73 firmware?
and also how do you check whether a particular mbn file belongs to particular firmware only?.please help me
i have these files which i uploaded.can you see if these can be used for this method.
also i got the same error as i got before after following the post#4 method.i will soon upload the log file to you
sorry for being a noob
thanks
saketh91 said:
I was on 1.73 firmware(older or stock) when i bricked my phone.so you mean i have create a mbn file from a device which has 1.73 firmware?
Click to expand...
Click to collapse
Yes. All you need is the image files from an update or ruu. Check your device's forum, I'm sure someone has posted full firmware zip's. Just grab the correct one and wait for instructions.
saketh91 said:
and also how do you check whether a particular mbn file belongs to particular firmware only?.please help me
i have these files which i uploaded.can you see if these can be used for this method.
Click to expand...
Click to collapse
The msimage.mbn is created from the firmware images (sbl1, sbl2, sbl3, tz, rpm) along with the partition information for that device.
Darkspr1te has been working on tools to create this file. Once he determines them to be ready, he will post them along with instructions on how to use them.
saketh91 said:
also i got the same error as i got before after following the post#4 method.i will soon upload the log file to you
sorry for being a noob
thanks
Click to expand...
Click to collapse
Thank you for your patience and support. I know it's been frustrating being without your phone for so long. We try to share information as soon as we learn it. But sometimes it takes longer than expected to develop ways to utilize our newly found knowledge.
-SLS-
Team Unlimited has (what I believe is) the stock RUU for the Evo 4g LTE for HBOOT 1.15, 1.15 and 2.09 here (EDIT: can't post links because I am a noob with under 10 posts)
Using QPST to flash MPRG8960.HEX and 8960_msimage.mbn it always fails on 'Sending Go Command 0x2A000000', which I think is the pbl authenticating sbl1? If you are right and find a way to insert the correctly signed files into the .mbn I owe you both a beer
SouL Shadow said:
Yes. All you need is the image files from an update or ruu. Check your device's forum, I'm sure someone has posted full firmware zip's. Just grab the correct one and wait for instructions.
The msimage.mbn is created from the firmware images (sbl1, sbl2, sbl3, tz, rpm) along with the partition information for that device.
Darkspr1te has been working on tools to create this file. Once he determines them to be ready, he will post them along with instructions on how to use them.
Thank you for your patience and support. I know it's been frustrating being without your phone for so long. We try to share information as soon as we learn it. But sometimes it takes longer than expected to develop ways to utilize our newly found knowledge.
-SLS-
Click to expand...
Click to collapse
thanks for the reply.i will definitely wait for you to come up with solution.I am just trying to help you by providing you with logs.I have full confidence in you.I will wait for sure.thanks for all the help.
withRandomPrecision said:
Team Unlimited has (what I believe is) the stock RUU for the Evo 4g LTE for HBOOT 1.15, 1.15 and 2.09 here (EDIT: can't post links because I am a noob with under 10 posts)
Using QPST to flash MPRG8960.HEX and 8960_msimage.mbn it always fails on 'Sending Go Command 0x2A000000', which I think is the pbl authenticating sbl1? If you are right and find a way to insert the correctly signed files into the .mbn I owe you both a beer
Click to expand...
Click to collapse
The files you refer to on Team Unlimited's site http://www.unlimited.io are the RUU's for the HTC Evo 4g LTE (jewel). For non-Htc ppl, an RUU is a windows executable that contains the full firmware and software for the given phone. Each RUU corresponds to a software release. Yes, the firmware images needed to create an msimage.mbn for jewel are contained in the RUU.
As for the mprg8960.hex:
The PBL does not perform OEM signature checking on the hex file. The hex file is built by Qualcomm before distributing the sources to the OEM's. It's sole function is to program blank or corrupted flash memory (nand, emmc, etc...) with the firmware bootloaders (sbl1, sbl2, sbl3, tz, rpm).
The address 0x2a000000 is where the mprg.hex is stored in memory. After upload the 'GO' command is used to transfer execution to the flash programmer (the hex file). The phone is supposed to acknowledge the 'GO' command before jumping to the new code. It appears that the 8960 firmware in use by HTC and Samsung has a bug and is not sending that acknowledgement. QPST waits for this acknowledgement before moving on to the next step. This is one of the reasons that prompted the creation of this thread, to develop an alternative to QPST.
Using the perl script posted above by Darkspr1te, other ppl have shown that the 'GO' command DOES transfer execution to the flash programmer and have used it to write the firmware (msimage.mbn) to emmc flash, but have not yet had success booting the loaded firmware. That is why I pointed out the need for the correct firmware version to be used to create the msimage.mbn.
-SLS-
SouL Shadow said:
Yes. All you need is the image files from an update or ruu. Check your device's forum, I'm sure someone has posted full firmware zip's. Just grab the correct one and wait for instructions.
-SLS-
Click to expand...
Click to collapse
i don't know exactly which firmware version which i was on before bricking my phone.but i definitely flashed a rooted sense rom. however i have all zips of the roms which i probably should have installed.also will this tool apply for every device(8960) even my at&t htc one x?
Great work!
SouL Shadow said:
The PBL does not perform OEM signature checking on the hex file.
Click to expand...
Click to collapse
How do you know this? (Other sources have claimed the opposite...)
...After upload the 'GO' command is used to transfer execution to the flash programmer (the hex file). The phone is supposed to acknowledge the 'GO' command before jumping to the new code. It appears that the 8960 firmware in use by HTC and Samsung has a bug and is not sending that acknowledgement. QPST waits for this acknowledgement before moving on to the next step.
Click to expand...
Click to collapse
a) This could be an effect of PBL signature check!
b) Even if not checked, they could easily have changed the acknowledgement string to anything else.
c) It could also be an effect of a blown Qfuse...
d) Are you saying that QPST is not connecting to your phone? (What QPST version are you using?)
Using the perl script posted above by Darkspr1te, other ppl have shown that the 'GO' command DOES transfer execution to the flash programmer and have used it to write the firmware (msimage.mbn) to emmc flash, ...
Click to expand...
Click to collapse
What other people? Do they even have the same phone?
E:V:A said:
Great work!
How do you know this? (Other sources have claimed the opposite...)
Click to expand...
Click to collapse
Qualcomm docs only mention verifying the hex, they say nothing about signature checking. For all we know it's simply verifying the uncorrupted download.
The hex is built by qualcomm and distributed with *other* files to the oem's/licensee's. It only needs to be changed when the actual hardware changes. The msimage.mbn is the oem specific component. There is no oem signature on the hex, however there may be a qualcomm signature or some kind of checksum to ensure it's a valid file.
E:V:A said:
a) This could be an effect of PBL signature check!
b) Even if not checked, they could easily have changed the acknowledgement string to anything else.
Click to expand...
Click to collapse
The acknowledgment does not contain any text. It's just a simple ACK reply.
E:V:A said:
c) It could also be an effect of a blown Qfuse...
d) Are you saying that QPST is not connecting to your phone? (What QPST version are you using?)
Click to expand...
Click to collapse
QPST hangs waiting for a response from the 8960 phones (htc evita, jewel, and sgs3), but other ppl (I don't know/remember who) using the above mentioned script have uploaded the hex and been able to communicate with the flash programmer. They were even able to upload the msimage.mbm. Although the .mbn used was probably the wrong build because after writing to emmc it did not boot in to the sbl. Either due to wrong files or older versions of firmware (causing a rollback error).
E:V:A said:
What other people? Do they even have the same phone?
Click to expand...
Click to collapse
This post: http://forum.xda-developers.com/showthread.php?p=36578082
Note the code part where it mentions 'openmulti' that command is only in the streaming download protocol which is used exclusively by the flash programmer.
EDIT 2013-01-28:
After a discussion with Ralekdev on IRC and reexamination of posted test results, it seems that the mprg8960.hex is NOT being executed. Will need to check the stored error code to see excatly why. Ralekdev was able to show me evidence of possible signature checking in the PBL. Again, we'll need to check the stored error code to confirm if that is the case. While this is a set back for msm8960 devices, it doesn't diminish the need for a full featured, open source, Linux replacement for QPST/QXDM.
-SLS-
SouL Shadow said:
Qualcomm docs only mention verifying the hex, they say nothing about signature checking. For all we know it's simply verifying the uncorrupted download.
Click to expand...
Click to collapse
Well, you should never trust Qualcomm documentation! By the time they write the documentation, there have been many changes.
Probably what you say is correct, but I'm not conviced since I haven't checked the code. It was a few months ago I was looking at this. Perhaps the HEX not checked for signature, since it's just the downloader. (But this doesn't make sense, since this would break the SecureBoot3 chain of trust.) But whatever is downloaded IS signature checked.
The acknowledgment does not contain any text. It's just a simple ACK reply.
Click to expand...
Click to collapse
Well, this is not how the Odin handshake looks like! There there is a short string, like "LOKE" / "ODIN" or something like that. (I don't remember it on top of my head.) So AFAIK, Odin is not working with these device, which would be an indication that they have changed the handshake. (What other kind of tools would the mobile operators use?)
QPST hangs waiting for a response from the 8960 phones (htc evita, jewel, and sgs3), but other ppl (I don't know/remember who) using the above mentioned script have uploaded the hex and been able to communicate with the flash programmer. They were even able to upload the msimage.mbm. Although the .mbn used was probably the wrong build because after writing to emmc it did not boot in to the sbl. Either due to wrong files or older versions of firmware (causing a rollback error).
Click to expand...
Click to collapse
Exactly.
Is it possible to access the bootloader output via USB UART for htc 8960 devices? Seems like this might be useful to get PBL/SBL output for a bricked device.
E:V:A said:
Well, you should never trust Qualcomm documentation! By the time they write the documentation, there have been many changes.
Probably what you say is correct, but I'm not conviced since I haven't checked the code. It was a few months ago I was looking at this. Perhaps the HEX not checked for signature, since it's just the downloader. (But this doesn't make sense, since this would break the SecureBoot3 chain of trust.) But whatever is downloaded IS signature checked.
Click to expand...
Click to collapse
Take a look at the creation date on the hex files in the source archive. They were created in November 2011. But that build is from a later date (I don't have it in front of me, but I think it's from april 2012). That source archive is directly from qualcomm. Why is that important? Because it shows that even with most changes to the source, the hex files don't need to be rebuilt. Besides, the flash programmer is fairly limited in what it can do. It's purpose is to rewrite the bootloaders to blank or corrupted nand/nor/emmc flash. Once written the phone will shut down and attempt to boot normally. Secure Boot only covers the boot process from power on to hardware initialization, security environment setup and finally loading appsbl. Everything after that is up to the oem to do whatever they choose. Although, interestingly enough, team unlimited was able to create a custom hboot (htc's appsbl) which will load normally even with signature checking...
E:V:A said:
Well, this is not how the Odin handshake looks like! There there is a short string, like "HELLO" / "ODIN" or something like that. (I don't remember it on top of my head.) So AFAIK, Odin is not working with these device, which would be an indication that they have changed the handshake. (What other kind of tools would the mobile operators use?)
Click to expand...
Click to collapse
I don't think we're in odin anymore toto!
PBL, the good bootloader of the east suddenly appears to tell us that someone dropped a brick on secure boot. Now all these little pdf's are singing, telling us to follow the HDLC road. Along the way we'll meet some interesting new people. There's QDL who lacks a brain. The Hex-man with no heart. And Streaming Download, a protocol in need of a little courage. Together we can follow the HDLC road to reach the great wizard of qualcomm and use the ruby .mbn file to return us to odin. That's when we'll awake to find Auntie ( a || h )boot and uncle recovery. Adb is there and fastboot and android too!
(don't ask, I don't know either ...)
And back in reality:
I've never used odin (in fact the first time I even heard of it was reading the Verizon SGS3 unlocking thread, which is how I discovered your thread, which lead me to here), but it's my understanding that it is a Samsung only feature that is integrated on the appsbl level, providing similar functionality to HTC's RUU mechanism. Although odin appears to be much more advanced. I've seen numerous samsung users with qualcomm hardware mention how they were stuck in qdl mode and no longer able to access odin to recover.
Now if you'll excuse me, I suddenly have the urge to listen to Dark Side of the Moon...
-SLS-
withRandomPrecision said:
Is it possible to access the bootloader output via USB UART for htc 8960 devices? Seems like this might be useful to get PBL/SBL output for a bricked device.
Click to expand...
Click to collapse
Sort of. Only JTAG can access full output. Error and other diagnostic info can be read from memory using the DMSS Download Protocol or through the DIAG interface.
Under Linux all communication is done via usb serial converter kernel module qcserial and device node /dev/ttyUSBn where n = your device number reported by the kernel dmesg. This goes for any modern qualcomm device using a usb port. Older products used a proprietary serial wiring (outlined in the DMSS Serial Data ICD document 80-V1294-1) to access these same protocols.
The pbl/sbl's all share the same qdl code base. They will transmit a "magic" string over usb, waiting only a programmed amount of time for a connection.
If you mount debugfs
Code:
mount -t debugfs none_debugfs /sys/kernel/debug
and load a kernel module usbmon
Code:
modprobe usbmon
then you can access raw usb streams, either per bus or for the entire computer. There's a raw text interface at /sys/kernel/debug/usb/usbmon
There's also raw binary interface through /dev/usbmon[N]
Also, see the kernel source docs:
<kernel source>/Documentation/usb/usbmon.txt
On a bricked phone qcserial will recognise the device and a ttyUSB will become available OR if sbl3 was successfully loaded usb mass storage will provide the enumerated emmc partitions (although using them is still a work in progress, I have an idea how to properly do it. Will post details once I can test it).
To utilize the qdl usb serial interface you need to use the DMMS Download Protocol outlined in document 80-39912-1 Revision E.
On a working phone there is a usb serial interface available as well. However the qcserial kernel module is not programmed with the oem's vid/pid, so it doesn't load. I've been able to connect to it via generic serial converter:
Code:
modprobe usbserial vender=0x<vid> product=<pid>
Then disconnect and reconnect the usb cable to the phone. dmesg will show the new ttyUSB device.
Unfortunately I haven't been able to actually do anything with it yet. On a working phone it should connect you to the modem which you can use AT commands to interact with. There is also an AT command to switch to DIAG mode. From DIAG more you would use the DMSS Serial Data protocol (doc 80-V1294-1 Revision YP), another HDLC based protocol, to interact.
I have a large number of doc's covering all the above mentioned items and much more (just over 100 pdf's). Unfortunately they are all watermarked with the actual username who had access. If someone has or can point me to a program that can remove said watermarks then I would happily share all of them.
-SLS-
SouL Shadow said:
... Unfortunately they are all watermarked with the actual username who had access. If someone has or can point me to a program that can remove said watermarks then I would happily share all of them.
Click to expand...
Click to collapse
Did you actually try to google that?
http://www.slideshare.net/linsu39/5-solutions-to-remove-pdf-watermark
http://download.cnet.com/We-PDF-Watermark-Remover/3000-18497_4-75593137.html
http://online2pdf.com/
http://www.freepdfconvert.com/#
http://foxyutils.com/splitpdf/
E:V:A said:
Did you actually try to google that?
http://www.slideshare.net/linsu39/5-solutions-to-remove-pdf-watermark
http://download.cnet.com/We-PDF-Watermark-Remover/3000-18497_4-75593137.html
http://online2pdf.com/
http://www.freepdfconvert.com/#
http://foxyutils.com/splitpdf/
Click to expand...
Click to collapse
Hah, yes I did. These pdf's are encrypted so most tools want a password to edit them. Looking for a Linux command line utility so I can strip about 100 pdf's. Found pdftk but it requires a password to work on encrypted pdf's. I was able to convert an encrypted pdf to a non-encrypted pdf using the pdftocairo tool... but that changes the raw pdf data so finding the watermark data is more difficult. Now I'm searching for a pdf editor since my linux distro didn't come with one. Unfortunately I've spent half my day off working on this when I could have been programming.
EDIT:
found qpdf on sourceforge!
qpdf + grep + sed = fully automated bash script to clean all the pdf's
EDIT2:
I now have a working script to remove the watermarks. Found a few bugs while cleaning my document archive. I will post it as soon as I can work them out.
-SLS-
E:V:A said:
Well, you should never trust Qualcomm documentation! By the time they write the documentation, there have been many changes.
Probably what you say is correct, but I'm not conviced since I haven't checked the code. It was a few months ago I was looking at this. Perhaps the HEX not checked for signature, since it's just the downloader. (But this doesn't make sense, since this would break the SecureBoot3 chain of trust.) But whatever is downloaded IS signature checked.
Well, this is not how the Odin handshake looks like! There there is a short string, like "LOKE" / "ODIN" or something like that. (I don't remember it on top of my head.) So AFAIK, Odin is not working with these device, which would be an indication that they have changed the handshake. (What other kind of tools would the mobile operators use?)
Exactly.
Click to expand...
Click to collapse
Absolutely correct. The download code itself has a mechanism to verify if it is valid. Some vendors check the download code before being executed if they are signed correctly, others leave the downloader as it is, but check the md5 signature within the downloader. However we managed to exploit the md5 verification to rewrite the msm7x bootloader to let us read full flash connected to radio. Not sure if they changed a lot regarding the msm89xx chipsets, but I'm going to have a look at that again, if needed. Regarding the flashing process, the flashed files are signed and checked for validity after uploading, rsa keys are in both amss and oemsbl.
Odin Protocol mainly belongs to samsung's own cpu/bootloader and has nothing to do with the qualcomm msm's/qsd's/qsc's.
What we speak of is the such called "QC Download Mode". Using the tty interface being in QC DM Mode you can just send the "3A" command to enter the "QC Download mode". For some mobiles, even if you have access to the radio download mode (qc) you cannot flash and repair the flash that belongs to the PDA part (most seen for those OMAP / MSM combinations). It's just because both cpu's use their own flash module for their firmware parts (means the flash isn't routed to both cpus, thus technically impossible).
WBR

my dfs progress

Received my boost aquos crystal today. Was hoping to dfs it to page plus as easy as the moto g, but was unsuccessful. I was able to read all normal values using dfs, just not write.
Process:
Entered diag mode using ##diag#.
Installed sharp drivers. (I will attach).
Updated 306sh drivers using Device Manager in windows. Select driver "I know location" or whatever. Chose "show all drivers". Scroll to Sharp Corporation. Select USB diag driver.
Open in dfs. ( I got my Spc code from boost by registering my device on their website to my account. Don't worry, they dount make you pay. Choose your plan, create a new phone number or whatever needed. Doesn't matter... They call it MSL code.)
Entered Spc in dfs and was able to read all info.... But nothing I wrote saved.
In the phone's ##diag# screen, I'd I selected the serial option, I installed the drivers... Same results.
I also force installed my moto RAZR m xt907 drivers (also msm Qualcomm) but same results.
Hope this helps someone with something.
let me know if the link works https://docs.google.com/uc?id=0B2YrFGY95PiIeklOT1VVRU5QVGs&export=download
hemanolio said:
Received my boost aquos crystal today. Was hoping to dfs it to page plus as easy as the moto g, but was unsuccessful. I was able to read all normal values using dfs, just not write.
Process:
Entered diag mode using ##diag#.
Installed sharp drivers. (I will attach).
Updated 306sh drivers using Device Manager in windows. Select driver "I know location" or whatever. Chose "show all drivers". Scroll to Sharp Corporation. Select USB diag driver.
Open in dfs. ( I got my Spc code from boost by registering my device on their website to my account. Don't worry, they dount make you pay. Choose your plan, create a new phone number or whatever needed. Doesn't matter... They call it MSL code.)
Entered Spc in dfs and was able to read all info.... But nothing I wrote saved.
In the phone's ##diag# screen, I'd I selected the serial option, I installed the drivers... Same results.
I also force installed my moto RAZR m xt907 drivers (also msm Qualcomm) but same results.
Hope this helps someone with something.
let me know if the link works https://docs.google.com/uc?id=0B2YrFGY95PiIeklOT1VVRU5QVGs&export=download
Click to expand...
Click to collapse
can't download the files could you please send to me [email protected]
what is DFS ?
you may try msm drivers.
whynot4444 said:
what is DFS ?
Click to expand...
Click to collapse
cdma tools 。。。 now I need drive for 306 so i can connect 306 to DFS but I cant find the COM drive 。。。
cairui505 said:
cdma tools 。。。 now I need drive for 306 so i can connect 306 to DFS but I cant find the COM drive 。。。
Click to expand...
Click to collapse
oh, you need drive DIAG, but what do you want with this port?
Hey guys I just found this thread. I am a CDMA Programmer and I wouldn't mind tinkering with this phone. Did it come with stock drivers embedded in the phone? Most do or sometimes you need to get adb driver packs for it. I am willing to help as I have DFS, CDMA Workshop, QPST and more. Please lmk what the current progress is on your end and I'll go ahead and share what I find when the phone arrives at my house. Let's get this rollin again!
kalanir said:
Hey guys I just found this thread. I am a CDMA Programmer and I wouldn't mind tinkering with this phone. Did it come with stock drivers embedded in the phone? Most do or sometimes you need to get adb driver packs for it. I am willing to help as I have DFS, CDMA Workshop, QPST and more. Please lmk what the current progress is on your end and I'll go ahead and share what I find when the phone arrives at my house. Let's get this rollin again!
Click to expand...
Click to collapse
yes in sharp web page have stock drivers.. also your can search bcs I saw that one guy is share diag modem driver(also here have msl unlock guide) .. most big problem is that we don't have root and other is if you can seen that phone have gsm radio..
loonbg said:
yes in sharp web page have stock drivers.. also your can search bcs I saw that one guy is share diag modem driver(also here have msl unlock guide) .. most big problem is that we don't have root and other is if you can seen that phone have gsm radio..
Click to expand...
Click to collapse
Ok I just ordered a bad esn one from eBay. Is it easy to get the msl code for it aside from activation? That's gonna be a big pain the @$$ if it's not like the Samsung or HTC.
OK guys so I just got my Sharp Aquos today and I have to say, WHAT A PIECE OF ART!!!! But I have started to work on it now. Did have some issues with it but I got it working. Managed to get into a hidden menu to do a RTN reset of it and now trying to get Diag Drivers. I got my MSL courtesy of an hour of research that surly paid off. So next step: connection to CDMA Workshop! Let me know what drivers you have found that work for this for the coms.
kalanir said:
I have to say, WHAT A PIECE OF ART!!!!
Click to expand...
Click to collapse
you r 100% right
kalanir said:
Managed to get into a hidden menu to do a RTN reset of it
Click to expand...
Click to collapse
how?
kalanir said:
trying to get Diag Drivers.
Click to expand...
Click to collapse
please share
kalanir said:
I got my MSL courtesy of an hour of research that surly paid off
Click to expand...
Click to collapse
can u tell me how?

G900P Diagnostic Mode & GSM Bands

Hi all,
I have been having some trouble following a guide on how to add GSM+LTE bands to this device. Specifically, I am struggling to connect to this device in Diagnostic Mode.
I am running Windows 7 x64. I have installed Samsung USB Driver v1.5.45.00. I have tried an updated driver but I seem to have had less issues with this version. I have also tried using Qualcomm USB Drivers For Windows (QD Loader) but when I select this folder to search for an alternative driver instead of the one Windows assignes I have to manually select an *.inf file and the options (HD-USB QDLoader 9XXX) does not make any sense to me which driver is required for my device.
I can run ##DIAG# in the Phone app and bring up PhoneUtil which brings up a menu to select CDMA MODEM / PDA and I have used both with no success. This menu allows me to access RNDIS+DM+MODEM. If I try to use other applications to switch to CP from AP in other USB settings or PDA to MODEM the phone disappears in device manager.
In QPST Configuration I have to untick "Show Serial and USB/QC Diagnostic ports only" to show the port and select the device. If I continue and use Software Download to back up the xQCN (NV memory) file it gets stuck at 12% and gives me an error "Could not Communicate in Diagnostic Mode"
If I use CDMA Workshop to do a backup the files hex just shows 00's and EFS Professionals backup is the same.
I have tried using stock Lollipop 5.0 firmware an enabling CP logging, rooted 5.0, a custom ROM including CM and I am currently running rooted 6.0.1 firmware.
I used Idoneapps paid service to find the SPC for my device but I don't believe there is any equivalent service to enable or disable the bands on my device.
All I can consider is wrong is the possibility of not having the right drivers but I have no idea where to find the right ones. I am at a bit of a dead end, any help would be appreciated.
Thanks.
tai1z said:
Hi all,
I have been having some trouble following a guide on how to add GSM+LTE bands to this device. Specifically, I am struggling to connect to this device in Diagnostic Mode.
I am running Windows 7 x64. I have installed Samsung USB Driver v1.5.45.00. I have tried an updated driver but I seem to have had less issues with this version. I have also tried using Qualcomm USB Drivers For Windows (QD Loader) but when I select this folder to search for an alternative driver instead of the one Windows assignes I have to manually select an *.inf file and the options (HD-USB QDLoader 9XXX) does not make any sense to me which driver is required for my device.
I can run ##DIAG# in the Phone app and bring up PhoneUtil which brings up a menu to select CDMA MODEM / PDA and I have used both with no success. This menu allows me to access RNDIS+DM+MODEM. If I try to use other applications to switch to CP from AP in other USB settings or PDA to MODEM the phone disappears in device manager.
In QPST Configuration I have to untick "Show Serial and USB/QC Diagnostic ports only" to show the port and select the device. If I continue and use Software Download to back up the xQCN (NV memory) file it gets stuck at 12% and gives me an error "Could not Communicate in Diagnostic Mode"
If I use CDMA Workshop to do a backup the files hex just shows 00's and EFS Professionals backup is the same.
I have tried using stock Lollipop 5.0 firmware an enabling CP logging, rooted 5.0, a custom ROM including CM and I am currently running rooted 6.0.1 firmware.
I used Idoneapps paid service to find the SPC for my device but I don't believe there is any equivalent service to enable or disable the bands on my device.
All I can consider is wrong is the possibility of not having the right drivers but I have no idea where to find the right ones. I am at a bit of a dead end, any help would be appreciated.
Thanks.
Click to expand...
Click to collapse
man, if anyone can shed some light on this, itll breathe some new life into my phone. I looked for the very same thing a while back as i switched to H2O wireless using AT&T towers and its working, but just on HSPA+ and thats because all of the LTE bands arent unlocked on my phone. QXDM and QPST are the tools we need, but the driver issues are whats stopping me too. Anyone with insight would be greatly appreciated
bump

Categories

Resources