ALL PHONES HAVE BEEN BRICKED USING THE DD METHOD, SOME WITH STL5 METHOD, NONE WITH BML5 METHOD
EDIT 22 apr 2013: use stock ROM, Helroz made this on the appstore. If you have newer Galaxy try this from Doky
EDIT 7 nov 2011: BML5 method guide: http://forum.xda-developers.com/showthread.php?t=1335548
EDIT 10 oct 2011: Relock experience?: http://forum.xda-developers.com/showpost.php?p=18294355&postcount=421
EDIT 31 aug 2011: Now Supersafe (BML5) method: http://forum.xda-developers.com/showpost.php?p=17148825&postcount=334
EDIT 18 march 2011: Unsafe (STL5) method: http://forum.xda-developers.com/showpost.php?p=12099386&postcount=6
!!! THIS IS STILL EXPERIMENTAL !!! (OLD STUFF, please disregard)
Before you do anything read the whole thread. It is still unclear why some phones were bricked
----------------------------------------------------------------------------
Hi, Can anyone help me with this question? I have never had the original SIM card in it. Does that help?
Finally i have I5500XWJJ6 rom installed, rooted the phone and used "adb shell su" to get into the shell. Now I cannot find the /efs file system? Why not?
I am looking for the nv_data.bin
Did something change with the newer firmwares?
Read somewhere that it is /dev/bml11
I copied it with dd if=/dev/bml11 of=/sdcard/bml11.img Then it only shows SER in the editor.
With getprop I get (some numbers are deleted for privacy what can be set with setprop?
Code:
# getprop
getprop
[ro.secure]: [1]
[ro.allow.mock.location]: [0]
[ro.debuggable]: [0]
[persist.service.adb.enable]: [1]
[ro.factorytest]: [0]
[ro.serialno]: []
[ro.bootmode]: [unknown]
[ro.baseband]: [unknown]
[ro.carrier]: [unknown]
[ro.bootloader]: [unknown]
[ro.hardware]: [GT-I5500]
[ro.revision]: [0]
[ro.emmc]: [0]
[wifi.interface]: [wlan0]
[ro.build.id]: [ERE27]
[ro.build.display.id]: [ERE27]
[ro.build.version.incremental]: [XWJJ6]
[ro.build.version.sdk]: [7]
[ro.build.version.codename]: [REL]
[ro.build.version.release]: [2.1-update1]
[ro.build.date]: [Thu Oct 21 18:41:03 KST 2010]
[ro.build.date.utc]: [1287654063]
[ro.build.type]: [user]
[ro.build.user]: [root]
[ro.build.host]: [SE-S611]
[ro.build.tags]: [test-keys]
[ro.product.model]: [GT-I5500]
[ro.product.brand]: [Samsung]
[ro.product.name]: [GT-I5500]
[ro.product.device]: [GT-I5500]
[ro.product.board]: [GT-I5500]
[ro.product.cpu.abi]: [armeabi]
[ro.product.manufacturer]: [Samsung]
[ro.product.locale.language]: [en]
[ro.product.locale.region]: [GB]
[ro.wifi.channels]: []
[ro.board.platform]: [msm7k]
[ro.build.PDA]: [I5500XWJJ6]
[ro.build.hidden_ver]: [I5500XWJJ6]
[ro.build.changelist]: [650697]
[ro.build.product]: [GT-I5500]
[ro.build.description]: [GT-I5500-user 2.1-update1 ERE27 XWJJ6 release-keys]
[ro.build.fingerprint]: [Samsung/GT-I5500/GT-I5500/GT-I5500:2.1-update1/ERE27/XWJJ6:user/release-keys]
[rild.libpath]: [/system/lib/libsec-ril.so]
[rild.libargs]: [-d /dev/smd0]
[persist.rild.nitz_plmn]: []
[persist.rild.nitz_long_ons_0]: []
[persist.rild.nitz_long_ons_1]: []
[persist.rild.nitz_long_ons_2]: []
[persist.rild.nitz_long_ons_3]: []
[persist.rild.nitz_short_ons_0]: []
[persist.rild.nitz_short_ons_1]: []
[persist.rild.nitz_short_ons_2]: []
[persist.rild.nitz_short_ons_3]: []
[DEVICE_PROVISIONED]: [1]
[debug.sf.hw]: [0]
[ro.sf.lcd_density]: [120]
[dalvik.vm.heapsize]: [24m]
[ro.url.legal]: [http://www.google.com/intl/%s/mobile/android/basic/phone-legal.html]
[ro.url.legal.android_privacy]: [http://www.google.com/intl/%s/mobile/android/basic/privacy.html]
[ro.com.google.locationfeatures]: [1]
[ro.setupwizard.mode]: [DISABLED]
[ro.com.google.gmsversion]: [2.1_r10]
[ro.config.alarm_alert]: [Alarm_Classic.ogg]
[ro.opengles.version]: [131072]
[net.bt.name]: [Android]
[net.change]: [net.dnschange]
[ro.config.sync]: [yes]
[dalvik.vm.stack-trace-file]: [/data/anr/traces.txt]
[ro.com.google.clientidbase]: [android-samsung]
[ro.com.google.clientidbase.yt]: [android-samsung]
[ro.com.google.clientidbase.am]: [android-samsung]
[ro.com.google.clientidbase.vs]: [android-samsung]
[ro.com.google.clientidbase.gmm]: [android-samsung]
[ro.csc.homescreen.defaultscreen]: [0]
[ro.csc.homescreen.screencount]: [7]
[ro.config.notification_sound]: [OnTheHunt.ogg]
[ro.config.ringtone]: [Club_Cubano.ogg]
[persist.sys.country]: [NL]
[persist.sys.localevar]: []
[persist.sys.timezone]: [Europe/Amsterdam]
[persist.sys.language]: [nl]
[audioflinger.bootsnd]: [0]
[ro.FOREGROUND_APP_ADJ]: [0]
[ro.VISIBLE_APP_ADJ]: [1]
[ro.SECONDARY_SERVER_ADJ]: [2]
[ro.BACKUP_APP_ADJ]: [2]
[ro.HOME_APP_ADJ]: [4]
[ro.HIDDEN_APP_MIN_ADJ]: [7]
[ro.CONTENT_PROVIDER_ADJ]: [14]
[ro.EMPTY_APP_ADJ]: [15]
[ro.FOREGROUND_APP_MEM]: [1536]
[ro.VISIBLE_APP_MEM]: [2048]
[ro.SECONDARY_SERVER_MEM]: [4096]
[ro.BACKUP_APP_MEM]: [4096]
[ro.HOME_APP_MEM]: [4096]
[ro.HIDDEN_APP_MEM]: [5120]
[ro.CONTENT_PROVIDER_MEM]: [6144]
[ro.EMPTY_APP_MEM]: [8960]
[net.tcp.buffersize.default]: [4096,87380,110208,4096,16384,110208]
[net.tcp.buffersize.wifi]: [4095,87380,110208,4096,16384,110208]
[net.tcp.buffersize.umts]: [4094,87380,110208,4096,16384,110208]
[net.tcp.buffersize.edge]: [4093,26280,35040,4096,16384,35040]
[net.tcp.buffersize.gprs]: [4092,8760,11680,4096,8760,11680]
[init.svc.playlogo]: [stopped]
[init.svc.servicemanager]: [running]
[init.svc.vold]: [running]
[init.svc.debuggerd]: [running]
[init.svc.ril-daemon]: [running]
[init.svc.DR-daemon]: [running]
[init.svc.mobex-daemon]: [running]
[init.svc.cnd]: [restarting]
[init.svc.zygote]: [running]
[init.svc.media]: [running]
[init.svc.dbus]: [running]
[init.svc.wlan_tool]: [stopped]
[init.svc.installd]: [running]
[init.svc.keystore]: [running]
[init.svc.memsicd]: [stopped]
[init.svc.adbd]: [running]
[wlan.driver.status]: [ok]
[ril.dataoff_nwk_op]: [false]
[ro.csc.country_code]: [Russia]
[ro.csc.sales_code]: [SER]
[ril.ICC_TYPE]: [2]
[ril.rildReset]: [1]
[debug.sf.nobootanimation]: [0]
[EXTERNAL_STORAGE_STATE]: [mounted]
[init.svc.bootanim]: [stopped]
[ril.lac]: [0066]
[ril.cid]: [02bd45d9]
[hw.keyboards.65537.devname]: [europa_keypad0]
[hw.keyboards.0.devname]: [europa_headset]
[sys.settings_secure_version]: [10]
[init.svc.wpa_supplicant]: [running]
[sys.settings_system_version]: [41]
[dev.bootcomplete]: [1]
[dhcp.wlan0.result]: [ok]
[init.svc.dhcpcd]: [running]
[dhcp.wlan0.pid]: [18943]
[ro.runtime.started]: [1288831305799]
[dhcp.wlan0.reason]: [BOUND]
[gsm.version.ril-impl]: [Samsung RIL(IPC) v2.0]
[dhcp.wlan0.dns1]: [192.168.1.254]
[dhcp.wlan0.dns2]: []
[gsm.sim.operator.numeric]: []
[gsm.sim.operator.alpha]: []
[gsm.sim.operator.iso-country]: []
[gsm.eons.name]: []
[dhcp.wlan0.dns3]: []
[dhcp.wlan0.dns4]: []
[gsm.sim.state]: [SIM_SERVICE_PROVIDER_LOCKED]
[gsm.current.phone-type]: [1]
[dhcp.wlan0.ipaddress]: [192.168.1.94]
[dhcp.wlan0.gateway]: [192.168.1.254]
[dhcp.wlan0.mask]: [255.255.255.0]
[dhcp.wlan0.leasetime]: [86400]
[dhcp.wlan0.server]: [192.168.1.254]
[net.dns1]: [192.168.1.254]
[net.dnschange]: [39]
[ril.prl_num]: [0]
[ril.sw_ver]: [I5500XWJG3]
[ril.hw_ver]: [MP 0.700]
[ril.rfcal_date]: [2010.09.18]
[ril.product_code]: [GT-I5500YKAVDP]
[ril.model_id]: []
[ril.bt_macaddr]: [101DC0D3380F]
[ril.wifi_macaddr]: [10:1D:C0:D3:38:10]
[ril.IMEI]: [.........263228]
[gsm.wifiConnected.active]: [true]
[dev.bootdone]: [1]
[init.svc.qcom-post-boot]: [stopped]
[gsm.version.baseband]: [I5500XWJG3]
[gsm.STK_SETUP_MENU]: [Fun & info]
[gsm.STK_USER_SESSION]: [0]
[ril.ecclist]: [112,911,112,911]
[gsm.network.type]: [UMTS]
[gsm.operator.alpha]: []
[gsm.operator.numeric]: [20404]
[gsm.operator.iso-country]: [nl]
[gsm.operator.isroaming]: [false]
[ril.rildSerial]: [..........g4kzu1ox]
[gsm.sim.state]: [SIM_SERVICE_PROVIDER_LOCKED] is what I don't want to see
Mount table:
Code:
# mount
mount
rootfs / rootfs ro 0 0
tmpfs /dev tmpfs rw,mode=755 0 0
devpts /dev/pts devpts rw,mode=600 0 0
proc /proc proc rw 0 0
sysfs /sys sysfs rw 0 0
tmpfs /sqlite_stmt_journals tmpfs rw,size=4096k 0 0
/dev/stl14 /cache rfs rw,nosuid,nodev,vfat,llw,check=no,gid/uid/rwx,iocharset=utf8 0 0
/dev/stl13 /data rfs rw,nosuid,nodev,vfat,llw,check=no,gid/uid/rwx,iocharset=utf8 0 0
/dev/stl12 /system rfs ro,vfat,log_off,check=no,gid/uid/rwx,iocharset=utf8 0 0
/dev/block//vold/179:1 /sdcard vfat rw,dirsync,nosuid,nodev,noexec,relatime,uid=1000,gid=1015,fmask=0702,dmask=0602,allow_utime=0020,codepage=cp437,iocharset=is
o8859-1,shortname=mixed,utf8 0 0
Already looked in /init.rc for some efs reference but not found.
Should I look into the ril app for some refrences to efs?
Cheers
EDIT1: Already got more http://forum.samdroid.net/f28/complete-imei-restore-how-1817/#post28598
I do have a character device (terminal?) /dev/ttyEFS0
Can one do anything with that?
With the adb logcat -b radio I got the log file for the ril/radio.
My attention was drawn to /system/etc/spn-conf.xml and after googling I found this file:
Code:
<?xml version="1.0" encoding="utf-8"?>
<spnOverrides>
<!-- @Author: HTC Shawn Ku @Date: 2010/02/23
This is a list for operator specific SPNs.
We will use below SPN for instead if numeric is matched.
Format is listed as below:
<spnOverrides
numeric="MCC+MNC"
spn="SPN Name"/>
-->
<spnOverride numeric="44020" spn="SoftBank"/>
</spnOverrides>
For my own sim that would be t-mobile NL: 20416 T-Mobile
Does that mean that I can override my locked provider?
I will try.
An interesting piece from the log radio file (also attached)
Code:
D/RILJ ( 1325): < iccIO: 0x90 0x0 0000000a2fe2040000ffff01020002
D/RILJ ( 1325): [0008]< SIM_IO IccIoResponse sw1:0x90 sw2:0x0
D/RILJ ( 1325): [0013]> iccIO: SIM_IO 0xb0 0x2fe2 path: 3F00,0,0,10
I/RILJ ( 1325): num:1 lock_type:3 lock_key:1 num_of_retry:3
D/RILJ ( 1325): [0009]< LOCK_INFO [email protected]
I/RILJ ( 1325): num:1 lock_type:9 lock_key:3 num_of_retry:3
D/RILJ ( 1325): [0010]< LOCK_INFO [email protected]
D/RILJ ( 1325): [0011]< GET_SIM_STATUS [email protected]
I/GSM ( 1325): PIN1 Status PINSTATE_ENABLED_NOT_VERIFIEDPIN2 Status PINSTATE_UNKNOWN
I/GSM ( 1325): Neither PIN2 nor PUK2 is blocked.
E/GSM ( 1325): updateStateProperty() : PIN_REQUIRED
D/RILJ ( 1325): [0014]> iccIO: SIM_IO 0xc0 0x6fb7 path: 3F007F105F3A,0,0,15
D/GSM ( 1325): [IccCard] Notify SIM pin or puk locked.
D/GSM ( 1325): [IccCard] Broadcasting intent ACTION_SIM_STATE_CHANGED LOCKED reason PIN
D/RILJ ( 1325): [0012]< QUERY_FACILITY_LOCK {1}
D/RILJ ( 1325): < iccIO: 0x90 0x0 981302360010773977ff
D/RILJ ( 1325): [0013]< SIM_IO IccIoResponse sw1:0x90 sw2:0x0
D/RILJ ( 1325): < iccIO: 0x90 0x0 0000005a6fb7040000ffff01020112
D/RILJ ( 1325): [0014]< SIM_IO IccIoResponse sw1:0x90 sw2:0x0
D/GSM ( 1325): [IccCard] Query facility lock : true
D/RILJ ( 1325): [0015]> iccIO: SIM_IO 0xb2 0x6fb7 path: 3F007F105F3A,1,4,18
D/GSM ( 1325): iccid: 893120630001779377
D/GSM ( 1325): checkSimChanged enter
I/GSM ( 1325): old iccid is 893120630001779377 current is 893120630001779377
D/RILJ ( 1325): < iccIO: 0x90 0x0 ffffffffffffffffffffffffffffffffffff
D/RILJ ( 1325): [0015]< SIM_IO IccIoResponse sw1:0x90 sw2:0x0
D/RILJ ( 1325): [0016]> iccIO: SIM_IO 0xb2 0x6fb7 path: 3F007F105F3A,2,4,18
D/RILJ ( 1325): < iccIO: 0x90 0x0 ffffffffffffffffffffffffffffffffffff
D/RILJ ( 1325): [0016]< SIM_IO IccIoResponse sw1:0x90 sw2:0x0
D/RILJ ( 1325): [0017]> iccIO: SIM_IO 0xb2 0x6fb7 path: 3F007F105F3A,3,4,18
D/RILJ ( 1325): < iccIO: 0x90 0x0 ffffffffffffffffffffffffffffffffffff
D/RILJ ( 1325): [0017]< SIM_IO IccIoResponse sw1:0x90 sw2:0x0
D/RILJ ( 1325): [0018]> iccIO: SIM_IO 0xb2 0x6fb7 path: 3F007F105F3A,4,4,18
D/RILJ ( 1325): < iccIO: 0x90 0x0 ffffffffffffffffffffffffffffffffffff
D/RILJ ( 1325): [0018]< SIM_IO IccIoResponse sw1:0x90 sw2:0x0
D/RILJ ( 1325): [0019]> iccIO: SIM_IO 0xb2 0x6fb7 path: 3F007F105F3A,5,4,18
D/RILJ ( 1325): < iccIO: 0x90 0x0 ffffffffffffffffffffffffffffffffffff
D/RILJ ( 1325): [0019]< SIM_IO IccIoResponse sw1:0x90 sw2:0x0
Anyone knows what "iccid: 893120630001779377" is. I tried it as unlock code but no avail.
Unlock codes ar always 8 numbers.
From the COM8 (in my system) I get the following info.
Code:
ATI
Manufacturer: SAMSUNG ELECTRONICS CORPORATION
Model: GT-I5500
Revision: I5500XWJG3
IMEI: 359763034......
+GCAP: +CGSM,+DS,+ES
Cheers
Okay. It is quiet here but lets continue. Now I found the service menu of the phone.
*#*#197328640#*#* (works on more phones?)
MAIN MENU
[1] DEBUG SCREEN
[2] VERSION INFORMATION
[3] UMTS RF NV
[4] GSM RF NV
[5] AUDIO
[6] COMMON
[7] QXDM LOGGING
When entering into COMMON sub menu I have
[1] FTM
[2] DEBUG INFO
[3] RF SCANNING
[4] DIAG CONFIG
[5] WCDMA SET CHANNEL
[6] NV REBUILD
[7] FACTORY TEST
[8] FORCE SLEEP
[9] GPS
NV in the menu's stand for Non Volatile RAM I suppose.
Menus control can be clicked or use the menu button for BACK
2Bcontinued...
Some codes for typing in from the firmware:
Code:
#*2886#
*#*#28346#*#*
*#0*# lcd test
*#0002*28346#
*#0002*28347#
*#0011#
*#0228#
*#0283#
*#0289#
*#03# NAND Flash uniek nummer (80590001238648)
*#0368# FM Radio test
*#0588# Proximity test
*#0589#
*#0599#
*#06#
*#0673# MelodyTest
*#07# Test History
*#0782# PDA RTC Get
*#0842# Vibration Test
*#1*#
*#1111#
*#1234# Version
*#1472365# Gps2 setup
*#147852#
*#1478963# Test app settings
*#1575# Gps setup
*#197328640# Main Menu Service Mode
*#2222#
*#2263#
*#22736224# Acc calibration
*#232331# BT Test
*#232332# BT On
*#232337# BT Mac
*#232338# WLAN Mac
*#232339# WLAN Engineering mode Tx Rx Status
*#2424#
*#2454# Ram dump mode (ARM9) take battery out
*#2580# Integrity control
*#2663# Touch screen version
*#2664# Little paint programm
*#272*
*#273283*255*3282*# Data create, fill up sms phonebook callog etc
*#273283*255*663282*# Data create, fill user/systemspace image mp3 video voice memo
*#2767*2878# servicemode nothin?
*#3214789# GcfMode settings
*#32489# Ciphering control
*#3264# Ram version
*#3282*727336*# overview data usage
*#34971539#
*#367#
*#3695147#
*#369852#
*#4238378# GCF settings
*#42663# Brightness setting
*#44336# Internal version build time changelist
*#46744674#
*#4736767*738# Acc sensor min/max
*#4986*2650468# Version
*#526# WLAN test
*#528# WLAN tes
*#6854123#
*#6984125*#
*#7263867*6633# RAM Dump mode Enable/disable
*#7284# DIAG config serial/usb
*#7298#
*#7412365#
*#742690#
*#745# Sec Ril Dump !!! log en mms settings
*#746# Debug Dump
*#7465625#
*#7594# Enable Shutdown on End call Long press
*#7780# Standaard gegevens herstellen
*#80# Factory Test
*#865625#
*#872564# USB (DM) Logging En/Disable CP AP CP+AP
*#9090# DIAG config serial/usb
*#9900# SysDump RIL Ramdump mode Off
*2767*3855# factory reset !!!
*2767*4387264636# Sellout SMS PCode Mode:Test
*2767*738767633#
*2767*73876766#
*2767*7387677763#
*2767*7387678378#
*7465625*27*#
*7465625*638*#
*7465625*77*#
*7465625*782*#
#7465625*27*#
#7465625*638*#
#7465625*77*#
#7465625*782*#
tweakradje said:
Hi, Can anyone help me with this question? I have never had the original SIM card in it. Does that help?
Finally i have I5500XWJJ6 rom installed, rooted the phone and used "adb shell su" to get into the shell. Now I cannot find the /efs file system? Why not?
I am looking for the nv_data.bin
Did something change with the newer firmwares?
Read somewhere that it is /dev/bml11
I copied it with dd if=/dev/bml11 of=/sdcard/bml11.img Then it only shows SER in the editor.
With getprop I get (some numbers are deleted for privacy what can be set with setprop?
Code:
# getprop
getprop
[ro.secure]: [1]
[ro.allow.mock.location]: [0]
[ro.debuggable]: [0]
[persist.service.adb.enable]: [1]
[ro.factorytest]: [0]
[ro.serialno]: []
[ro.bootmode]: [unknown]
[ro.baseband]: [unknown]
[ro.carrier]: [unknown]
[ro.bootloader]: [unknown]
[ro.hardware]: [GT-I5500]
[ro.revision]: [0]
[ro.emmc]: [0]
[wifi.interface]: [wlan0]
[ro.build.id]: [ERE27]
[ro.build.display.id]: [ERE27]
[ro.build.version.incremental]: [XWJJ6]
[ro.build.version.sdk]: [7]
[ro.build.version.codename]: [REL]
[ro.build.version.release]: [2.1-update1]
[ro.build.date]: [Thu Oct 21 18:41:03 KST 2010]
[ro.build.date.utc]: [1287654063]
[ro.build.type]: [user]
[ro.build.user]: [root]
[ro.build.host]: [SE-S611]
[ro.build.tags]: [test-keys]
[ro.product.model]: [GT-I5500]
[ro.product.brand]: [Samsung]
[ro.product.name]: [GT-I5500]
[ro.product.device]: [GT-I5500]
[ro.product.board]: [GT-I5500]
[ro.product.cpu.abi]: [armeabi]
[ro.product.manufacturer]: [Samsung]
[ro.product.locale.language]: [en]
[ro.product.locale.region]: [GB]
[ro.wifi.channels]: []
[ro.board.platform]: [msm7k]
[ro.build.PDA]: [I5500XWJJ6]
[ro.build.hidden_ver]: [I5500XWJJ6]
[ro.build.changelist]: [650697]
[ro.build.product]: [GT-I5500]
[ro.build.description]: [GT-I5500-user 2.1-update1 ERE27 XWJJ6 release-keys]
[ro.build.fingerprint]: [Samsung/GT-I5500/GT-I5500/GT-I5500:2.1-update1/ERE27/XWJJ6:user/release-keys]
[rild.libpath]: [/system/lib/libsec-ril.so]
[rild.libargs]: [-d /dev/smd0]
[persist.rild.nitz_plmn]: []
[persist.rild.nitz_long_ons_0]: []
[persist.rild.nitz_long_ons_1]: []
[persist.rild.nitz_long_ons_2]: []
[persist.rild.nitz_long_ons_3]: []
[persist.rild.nitz_short_ons_0]: []
[persist.rild.nitz_short_ons_1]: []
[persist.rild.nitz_short_ons_2]: []
[persist.rild.nitz_short_ons_3]: []
[DEVICE_PROVISIONED]: [1]
[debug.sf.hw]: [0]
[ro.sf.lcd_density]: [120]
[dalvik.vm.heapsize]: [24m]
[ro.url.legal]: []
[ro.url.legal.android_privacy]: []
[ro.com.google.locationfeatures]: [1]
[ro.setupwizard.mode]: [DISABLED]
[ro.com.google.gmsversion]: [2.1_r10]
[ro.config.alarm_alert]: [Alarm_Classic.ogg]
[ro.opengles.version]: [131072]
[net.bt.name]: [Android]
[net.change]: [net.dnschange]
[ro.config.sync]: [yes]
[dalvik.vm.stack-trace-file]: [/data/anr/traces.txt]
[ro.com.google.clientidbase]: [android-samsung]
[ro.com.google.clientidbase.yt]: [android-samsung]
[ro.com.google.clientidbase.am]: [android-samsung]
[ro.com.google.clientidbase.vs]: [android-samsung]
[ro.com.google.clientidbase.gmm]: [android-samsung]
[ro.csc.homescreen.defaultscreen]: [0]
[ro.csc.homescreen.screencount]: [7]
[ro.config.notification_sound]: [OnTheHunt.ogg]
[ro.config.ringtone]: [Club_Cubano.ogg]
[persist.sys.country]: [NL]
[persist.sys.localevar]: []
[persist.sys.timezone]: [Europe/Amsterdam]
[persist.sys.language]: [nl]
[audioflinger.bootsnd]: [0]
[ro.FOREGROUND_APP_ADJ]: [0]
[ro.VISIBLE_APP_ADJ]: [1]
[ro.SECONDARY_SERVER_ADJ]: [2]
[ro.BACKUP_APP_ADJ]: [2]
[ro.HOME_APP_ADJ]: [4]
[ro.HIDDEN_APP_MIN_ADJ]: [7]
[ro.CONTENT_PROVIDER_ADJ]: [14]
[ro.EMPTY_APP_ADJ]: [15]
[ro.FOREGROUND_APP_MEM]: [1536]
[ro.VISIBLE_APP_MEM]: [2048]
[ro.SECONDARY_SERVER_MEM]: [4096]
[ro.BACKUP_APP_MEM]: [4096]
[ro.HOME_APP_MEM]: [4096]
[ro.HIDDEN_APP_MEM]: [5120]
[ro.CONTENT_PROVIDER_MEM]: [6144]
[ro.EMPTY_APP_MEM]: [8960]
[net.tcp.buffersize.default]: [4096,87380,110208,4096,16384,110208]
[net.tcp.buffersize.wifi]: [4095,87380,110208,4096,16384,110208]
[net.tcp.buffersize.umts]: [4094,87380,110208,4096,16384,110208]
[net.tcp.buffersize.edge]: [4093,26280,35040,4096,16384,35040]
[net.tcp.buffersize.gprs]: [4092,8760,11680,4096,8760,11680]
[init.svc.playlogo]: [stopped]
[init.svc.servicemanager]: [running]
[init.svc.vold]: [running]
[init.svc.debuggerd]: [running]
[init.svc.ril-daemon]: [running]
[init.svc.DR-daemon]: [running]
[init.svc.mobex-daemon]: [running]
[init.svc.cnd]: [restarting]
[init.svc.zygote]: [running]
[init.svc.media]: [running]
[init.svc.dbus]: [running]
[init.svc.wlan_tool]: [stopped]
[init.svc.installd]: [running]
[init.svc.keystore]: [running]
[init.svc.memsicd]: [stopped]
[init.svc.adbd]: [running]
[wlan.driver.status]: [ok]
[ril.dataoff_nwk_op]: [false]
[ro.csc.country_code]: [Russia]
[ro.csc.sales_code]: [SER]
[ril.ICC_TYPE]: [2]
[ril.rildReset]: [1]
[debug.sf.nobootanimation]: [0]
[EXTERNAL_STORAGE_STATE]: [mounted]
[init.svc.bootanim]: [stopped]
[ril.lac]: [0066]
[ril.cid]: [02bd45d9]
[hw.keyboards.65537.devname]: [europa_keypad0]
[hw.keyboards.0.devname]: [europa_headset]
[sys.settings_secure_version]: [10]
[init.svc.wpa_supplicant]: [running]
[sys.settings_system_version]: [41]
[dev.bootcomplete]: [1]
[dhcp.wlan0.result]: [ok]
[init.svc.dhcpcd]: [running]
[dhcp.wlan0.pid]: [18943]
[ro.runtime.started]: [1288831305799]
[dhcp.wlan0.reason]: [BOUND]
[gsm.version.ril-impl]: [Samsung RIL(IPC) v2.0]
[dhcp.wlan0.dns1]: [192.168.1.254]
[dhcp.wlan0.dns2]: []
[gsm.sim.operator.numeric]: []
[gsm.sim.operator.alpha]: []
[gsm.sim.operator.iso-country]: []
[gsm.eons.name]: []
[dhcp.wlan0.dns3]: []
[dhcp.wlan0.dns4]: []
[gsm.sim.state]: [SIM_SERVICE_PROVIDER_LOCKED]
[gsm.current.phone-type]: [1]
[dhcp.wlan0.ipaddress]: [192.168.1.94]
[dhcp.wlan0.gateway]: [192.168.1.254]
[dhcp.wlan0.mask]: [255.255.255.0]
[dhcp.wlan0.leasetime]: [86400]
[dhcp.wlan0.server]: [192.168.1.254]
[net.dns1]: [192.168.1.254]
[net.dnschange]: [39]
[ril.prl_num]: [0]
[ril.sw_ver]: [I5500XWJG3]
[ril.hw_ver]: [MP 0.700]
[ril.rfcal_date]: [2010.09.18]
[ril.product_code]: [GT-I5500YKAVDP]
[ril.model_id]: []
[ril.bt_macaddr]: [101DC0D3380F]
[ril.wifi_macaddr]: [10:1D:C0:D3:38:10]
[ril.IMEI]: [.........263228]
[gsm.wifiConnected.active]: [true]
[dev.bootdone]: [1]
[init.svc.qcom-post-boot]: [stopped]
[gsm.version.baseband]: [I5500XWJG3]
[gsm.STK_SETUP_MENU]: [Fun & info]
[gsm.STK_USER_SESSION]: [0]
[ril.ecclist]: [112,911,112,911]
[gsm.network.type]: [UMTS]
[gsm.operator.alpha]: []
[gsm.operator.numeric]: [20404]
[gsm.operator.iso-country]: [nl]
[gsm.operator.isroaming]: [false]
[ril.rildSerial]: [..........g4kzu1ox]
[gsm.sim.state]: [SIM_SERVICE_PROVIDER_LOCKED] is what I don't want to see
Click to expand...
Click to collapse
Did you try the setprop on the gsm.sim.state by setting it to null/empty.
SP unlock your i5500 (probably more)
EDIT: Phones has been bricked with this stl5 method. Do use supersafe bml5 method.
http://forum.xda-developers.com/showpost.php?p=17148825&postcount=334
Since I can't give up on this one I digged a little further into my i5500 memory.
Guess what? I f.ckin did it. Big hoora. I'am good I know Thank you!
Code:
- root your phone
- adb shell
- su
- cd /
- mount -o remount,rw -t rootfs rootfs / (or do it before adb with root explorer)
- mkdir /efs
- mount -o nosuid,ro,nodev -t vfat /dev/block/stl5 /efs
- cat /efs/mits/perso.txt
- umount /efs
- reboot
EDIT: stl5 is es-tee-el-five (like STL5)
EDIT: /efs on the Galaxy the /etc/fstab says: mount rfs /dev/block/stl5 /efs nosuid nodev check=no
You will see some numbers: In my case 20404 for Vodafone NL.
Then you will see your SP unlock code followed by some 000000000 codes and another
code. Write the first one (and second just in case) down.
Shut down the phone and put it a "locked" sim. Start your phone, input the pin, and when asked for a unlock code give it the first code. Your phone is now unlocked.
Cheers
EDIT:
Rooting: http://blog.23corner.com/2010/08/30/universal-androot-1-6-2-beta-5/
Rooting newer roms: http://forum.xda-developers.com/showthread.php?t=803682. Need reboot after.
Adb and USB drivers: see attachement
EDIT: possible fix for bad imei after doing above procedure:
http://forum.xda-developers.com/showpost.php?p=15408191&postcount=4
EDIT: nice tutorial for my method - http://forum.xda-developers.com/showthread.php?p=16597429
tweakradje said:
Since I can't give up on this one I digged a little further into my i5500 memory.
Guess what? I f.ckin did it. Big hoora. I'am good I know Thank you!
- adb shell
- su
- mount root rw (did it with root explorer)
- mkdir /efs
- mount -t vfat /dev/block/stl5 /efs
- cat /efs/mits/perso.txt
You will see some numbers: In my case 20404 for Vodafone NL.
Then you will see your SP unlock code followed by some 000000000 codes and another
code. Write the first one (and second just in case) down.
Shut down the phone and put it a "locked" sim. Start your phone, input the pin, and when asked for a unlock code give it the first code. Your phone is now unlocked.
Cheers
Click to expand...
Click to collapse
Mine is a bunch of 01234567s
using dd command on stl5 is bricking the phone: UNSAFE METHOD
Ok. For good comparison I attached both perso.txt: before and after unlock.
Perhaps that helps. My network was locked to 20404 and the unlock code is 61493638
and there is another code in the file: 92427358 but I don't know what that one does.
Perhaps it is better practise to follow this road for getting the codes:
- adb shell
- su
- dd if=/dev/block/stl5 of=/sdcard/stl5.rfs bs=4096
Then use winimage or similar to examine /sdcard/stl5.rfs as FAT16 image file.
Cheers
- mount root rw (did it with root explorer)
Cannot get passed this step. It only gives me cmd line help. Please describe in more detail on how you did it. Thanks!
Root explorer is a program I installed. It has a "Mount R/W" button for the root.
But you can also use a complete other folder that is already mounted rw.
Type command mount in adb shell. Think /data is rw mounted.
So create /data/efs folder and mount -t vfat /dev/block/stl5 /data/efs
Cheers
For my problem this cmd worked:
mount -o remount,rw /data /system
Let's see if it really works for me 2.
After doing all the steps, my phone cannot turn on Phone, Wifi, cannot do any kind of format, install a new firmware (does not go to step 2 - pass the CS, even if odin reports it Passed). Half bricked it!
WARNING
Strange and sounds dangerous. Better not mount /dev/block/stl5 then and
use dd if=/dev/block/stl5 of=/sdcard/stl5.rfs and use windows program winimage (or similar)
to get the info from mits/perso.txt
But did you unlock?
Cheers
I already did that. No effect, because my WIFI, data, network connections and all audio (don't know about music) do not respond in any way, so, now, my great phone is at Vodafone Romania for repairs. Hope they did not notice any meddling with the firmware and re-flash it to it's original state. It didn't matter if i inserted another network sim or the one registered.
Thanks for this useful info, tweakradje.
Albeit I had run into the same problem as kill3r000, I managed to restore my phone back on track by simply running dd if=/sdcard/stl5.rfs of=/dev/block/stl5.
It ain't relevant at all, but when I retrieved the stl5.rfs from the phone I just did it from a root terminal on the phone, not via adb.
Anyways, thanks again for helping me unlock my phone.
kill3r000, daca aia de la vodafone iti cer bani, nu le da si ia-ti telefonu' ca si eu tot de la voda il am si aceeasi figura mi-a facut-o.
How come i didn't think of backtracking that command? ( I suppose i was too tired of trying endless methods.
Block240 - Multumesc mult de tot pentru sprijin. Asa am sa fac. Mai tii minte cam cat ti-au cerut? Niste maralni.
Pe mine m-au sunat de la Regenersis ca il mai tin pentru mai multe teste amanuntite Pe bune... Va hotarati cat sa taxeze (nici nu se mai pune problema; deja au hotarat: IESIT DIN GARANTIE scrie pe saracutul meu)!
tweakradje said:
SAFE METHOD
Ok. For good comparison I attached both perso.txt: before and after unlock.
Perhaps that helps. My network was locked to 20404 and the unlock code is 61493638
and there is another code in the file: 92427358 but I don't know what that one does.
Perhaps it is better practise to follow this road for getting the codes:
- adb shell
- su
- dd if=/dev/block/stl5 of=/sdcard/stl5.rfs
Then use winimage or similar to examine /sdcard/stl5.rfs as FAT16 image file.
Cheers
Click to expand...
Click to collapse
Worked like a charm!
Thank you very much for this. Finally, 2.2.
Thanks for the feedback.
Hy ... Block can u make a little tutorial for Romania Vodafone users ...step by step or can u contact me on PM and tell me exact steps
Multumesc,
It's better, IF he or other wants to do that, to post it on the topic so can others see it. When i'll have it back from service (if they want money for repairs) i'll try again and then i will ask somebody here for a little tutorial for all this not happend again.
(Multe) Multumiri anticipate!
kill3r000 said:
How come i didn't think of backtracking that command? ( I suppose i was too tired of trying endless methods.
Block240 - Multumesc mult de tot pentru sprijin. Asa am sa fac. Mai tii minte cam cat ti-au cerut? Niste maralni.
Pe mine m-au sunat de la Regenersis ca il mai tin pentru mai multe teste amanuntite Pe bune... Va hotarati cat sa taxeze (nici nu se mai pune problema; deja au hotarat: IESIT DIN GARANTIE scrie pe saracutul meu)!
Click to expand...
Click to collapse
Nu am ajuns in punctul in care sa trimit telefonul la garantie. Am stat o noapte sa-i scriu diferite ROM-uri si sa-i sterg efs-ul pana mi-am amintit si multumit ca aveam stl5.rfs si pe calculator si pe /sdcard. Fiind un utilizator cat de cat obisnuit cu unix-urile, mi-am dat seama ca un dd salveaza bit cu bit totul. Acum daca as sti si de ce or aparea figurile astea cand e citit efs-ul as fi un om fericit.
Nonetheless, there's nothing special regarding VF Ro users or any other network carriers. I just followed these steps:
Code:
su
dd if=/dev/block/stl5 of=/sdcard/stl5.rfs
Copied the stl5.rfs on my computer, opened it up with WinImage (obviously, any other application that can read FAT images would work just as good) and went to /mits/perso.txt.
It's full of gibberish, but do keep in mind that the 8-digit number is the unlock code. Note it down on a paper or something, power down the phone, get its sim out, power it on (don't insert any other sim). Mine went to ARM11 recovery mode (shows the samsung logo and says that on the top left). Should it do that, just throw the battery out and back in, then power it up again. The phone will boot up normally and now run
Code:
su
dd if=/sdcard/stl5.rfs of=/dev/block/stl5
wait for it to end, power down the phone, insert a sim that would send the phone in its network locked mode, and se that 8-digit number. That's all about it, you now have an unlocked gt-i5500.
Thank you again, tweakradje.
(dati o bere )
Just need a quick answer from a dev.
Situation: Got this TF300T last year, flashed stuff, wouldn't boot, got busy.
I made an nvflash backup at some point using ICS setup.
- Fastboot Accessible
- APX/NVFlash works
- Tried restoring bricksafe.img and in cmd prompt it appeared to be loading... for an hour.
I've since flashed ICS twrp 2.6.3, boot, no recovery option. Oh, at some point I wiped the data.
Big factors:
- I need to get something working prior to a trip next month
- I don't have time to do trial and error one step a day, for the next year
- I have a 3yr extended warranty through BB but thinking that'll be voided when they see "mobiroot 9.4.30etc..."
- I don't really wanna deal with this **** unless I can get it done in like an hour with someone on IRC or something. Happy to pay you a reasonable amount to avoid dealing w bb.
If the answer is, "you're an idiot, didn't you read all the threads", yes, yes I did. But I'm stubborn, so instead of reading me the riot act or telling me about the search function I'm like... SO good at using, tell me how best to ****ing destroy this heap of **** so BB just gives me a new one. Happy to make a video of outlined fraud commital providing it's creative, and actually gets me a new tablet.
DoUevenRoot said:
Just need a quick answer from a dev.
- Fastboot Accessible
Click to expand...
Click to collapse
If fastboot works as you say, try flashing the ICS blob using fastboot and you should be good.
If that doesn't work, this thread might help you out.
k1chy said:
If fastboot works as you say, try flashing the ICS blob using fastboot and you should be good.
If that doesn't work, this thread might help you out.
Click to expand...
Click to collapse
I should also point out that
Code:
fastboot getvars all
yields no results
DoUevenRoot said:
I should also point out that
Code:
fastboot getvars all
yields no results
Click to expand...
Click to collapse
and honestly, I have no clue if I flashed a JB recovery or not. My thought was that I *should* be able to flash the "bricksafe.img" and all would be right with the world, however, as I stated above, it just sits there saying it's transferring the 11 gig file. Not sure if I'm just being impatient or what but my thought was that it shouldn't take more than an hour to transfer so I just ctrl+c'd to stop it and tried other ****.
Personally, I'm wondering if the partitions are all ****ed up and I'm absolutely amazed nobody has worked out the partitions by now and that it's not as simple as recreating the file structure manually. Incidently, how can I pull the file structure to see if that's the case?
here's what I've got. It appears ADB is broken, but fastboot works. I can flash pretty much everything, except the bricksafe for whatever reason, but nothing gets reflected on reboot.
Code:
C:\Users\Owner\Downloads\BACKUPS\ANDROID BACKUPS>adb get-state
unknown
C:\Users\Owner\Downloads\BACKUPS\ANDROID BACKUPS>fastboot -i 0x0B05 flash recovery twrp263.blob
sending 'recovery' (6368 KB)...
OKAY [ 1.805s]
writing 'recovery'...
OKAY [ 2.086s]
finished. total time: 3.896s
C:\Users\Owner\Downloads\BACKUPS\ANDROID BACKUPS>fastboot -i 0x0B05 flash boot boot.blob
sending 'boot' (5212 KB)...
OKAY [ 2.319s]
writing 'boot'...
OKAY [ 2.023s]
finished. total time: 4.345s
C:\Users\Owner\Downloads\BACKUPS\ANDROID BACKUPS>fastboot devices
00000 fastboot
Pulled the partition table in fastboot, this is what I have:
pulled the partition table, this is what I have
.
Code:
PartitionId=2
Name=BCT
DeviceId=18
StartSector=0
NumSectors=768
BytesPerSector=4096
PartitionId=3
Name=PT
DeviceId=18
StartSector=768
NumSectors=128
BytesPerSector=4096
PartitionId=4
Name=EBT
DeviceId=18
StartSector=896
NumSectors=2048
BytesPerSector=4096
PartitionId=5
Name=SOS
DeviceId=18
StartSector=2944
NumSectors=2048
BytesPerSector=4096
PartitionId=6
Name=LNX
DeviceId=18
StartSector=4992
NumSectors=2048
BytesPerSector=4096
PartitionId=7
Name=CER
DeviceId=18
StartSector=7040
NumSectors=2048
BytesPerSector=4096
PartitionId=8
Name=IMG
DeviceId=18
StartSector=9088
NumSectors=2048
BytesPerSector=4096
PartitionId=9
Name=GP1
DeviceId=18
StartSector=11136
NumSectors=256
BytesPerSector=4096
PartitionId=10
Name=APP
DeviceId=18
StartSector=11392
NumSectors=196608
BytesPerSector=4096
PartitionId=11
Name=CAC
DeviceId=18
StartSector=208000
NumSectors=109568
BytesPerSector=4096
PartitionId=12
Name=MSC
DeviceId=18
StartSector=317568
NumSectors=512
BytesPerSector=4096
PartitionId=13
Name=USP
DeviceId=18
StartSector=318080
NumSectors=208896
BytesPerSector=4096
PartitionId=14
Name=PER
DeviceId=18
StartSector=526976
NumSectors=1280
BytesPerSector=4096
PartitionId=15
Name=YTU
DeviceId=18
StartSector=528256
NumSectors=128
BytesPerSector=4096
PartitionId=16
Name=CRA
DeviceId=18
StartSector=528384
NumSectors=1280
BytesPerSector=4096
PartitionId=17
Name=UDA
DeviceId=18
StartSector=529664
NumSectors=7231104
BytesPerSector=4096
PartitionId=18
Name=GPT
DeviceId=18
StartSector=7760768
NumSectors=128
BytesPerSector=4096
So... Now it claims to have flashed bricksafe. Will reboot and report back
Code:
C:\Users\Owner\Downloads\BACKUPS\ANDROID BACKUPS>nvflash --resume --rawdevicewrite 0 2944 bricksafe.img
Nvflash started
[resume mode]
sending file: bricksafe.img
/ 12058624/12058624 bytes sent
bricksafe.img sent successfully
No dice
Hy there,
(forlinks please scroll down to bottom of the post since i couldn't post them being first time poster)
I bought a few days ago a "Captiva Pad 10.1 QUAD HD" used from a friend. The battery suddenly died in the way that run
out of battery and never started again, started and worked fine if it was put on charger. In settings/Batter showed
the battery 100% charged and 0s left.
This is the smaller issue now since I managed to brick it. Have rooted few tablets and phones in the past and
installed stock or custom rooms so I'm not a complete noob but for sure a newbie. Searching for it found nothing
about, removed the back of the tablet and saw that runs on a RockChip so tried that way and managed to root it. Super
SU everything was working just fine so was time to install a new ROM on it. Since there isn't any stock ROM released
by the manufacturer tried to find one based on the chip.
This is the point where things gone bad since i didn't made any backup at all. (I know, noob mistake)
There wasn't any driver for it so I just rewrote the Google Driver and worked fine, was recognized by RKBatchTool
which is basically like Odin and works the same way only that this one is for RockChip as I understand.
So everything was set up, downloaded 3 different ROMs in the HOPE that one of them will work... Downloaded these ROMs
from various places so can't give a link to them but here they are, maybe the filenames say something:
Geekbuying_TV BOX_RK3188T_Android 4.4_official_AP6210 (which I thought that will work since is the same chip)
kasty-rkm_mk902-442-20140515-rooted4 (just a random one i stumbled upon during my searches) (can't install as
noticed later)
radxa_rock_android_upgrade_from_sdcard_140314_update (another random one)
First run was given for the "Geekbuying" since at least had the same chip, the installing went fine with RKBatchTool
but the tablet never started again and had just a blank screen and there could be heard a THICK when powering
on so there was some life in it which gave HOPE but. To enter in download mode until now you had to push Volume UP +
Plug the USB in the meantime and this was working fin until now but not after installing this new ROM.
Today after searching more after it and learning some so i can manage somehow to get it working i came across a forum
which said that putting on short two of the NAND chip connectors can get you into download mode. Tok off again the
back of the tablet, and to make things even complicated there were two identical chips both NAND as I recognize them.
Nothing to loose, I tried the first one, the thread said that you have to short circuit the 4th and 5th connectors but
wasn't working for me, so tried other and worked with 8-9 connectors. I was again in download mode so could try other
ROM's. Downloaded from various places, read a lot about them but looks like not enough.
Here are all off them: I can list them by name if there is any need: (LINK 1)
The top three ones come from the Captiva page: (LINK 2) (none of them working)
Also figured out that Captiva is a product or "Nexoc" German company so tried my luck here to:
(LINK 3) (none of them working)
The one ROOM with which i can get the best results is the third mentioned above
"radxa_rock_android_upgrade_from_sdcard_140314_update" don't even know from where but as i have to realize now, this
ROM is made TV USB stick or a Media Box. I have installed this one and with this currently I have these results:
- The screen shows some light o the front but still dark and nothing shows up
- on the back the screen is bright white: (LINK 4)
- It is recognized by RKBatchTool, and i can even "Switch" between Normal and Download mode from it
- It was recognized as "radxa rock" by my PC and different Hadware id which was strange but wrote again the Google
Driver for it and it recognized perfectly in the PC and the content of the mounted drive is completely blank which is
also strange
- I had to try if it's working at all or is a screen problem so grabbed three different android screencast JS APPS and
all three show up this screen: (LINK 5)
- In one of the screencast apps I can even open a website but nothing else works from them, i can't push any button or
anything, tried chmod 777 dalvik-cache everything i could imagine
- ADB Shell works as far as i can use it
Some more details and under the hood:
- "adb shell getprop" prints the following:
C:\android\sdk\platform-tools>adb shell
root @ android:/ # getprop
getprop
[dalvik.vm.dexopt-flags]: [m=y]
[dalvik.vm.heapgrowthlimit]: [80m]
[dalvik.vm.heapmaxfree]: [8m]
[dalvik.vm.heapminfree]: [512k]
[dalvik.vm.heapsize]: [384m]
[dalvik.vm.heapstartsize]: [8m]
[dalvik.vm.heaptargetutilization]: [0.75]
[dalvik.vm.jniopts]: [warnonly]
[dalvik.vm.stack-trace-file]: [/data/anr/traces.txt]
[dev.bootcomplete]: [1]
[dhcp.eth0.result]: [failed]
[drm.service.enabled]: [false]
[gsm.current.phone-type]: [1]
[gsm.operator.alpha]: []
[gsm.operator.iso-country]: []
[gsm.operator.isroaming]: [false]
[gsm.operator.numeric]: []
[gsm.sim.state]: [NOT_READY]
[gsm.version.ril-impl]: [ril-rk29-dataonly v2.3.00]
[init.svc.adbd]: [running]
[init.svc.bootanim]: [stopped]
[init.svc.chrome]: [stopped]
[init.svc.console]: [running]
[init.svc.debuggerd]: [running]
[init.svc.dhcpcd_eth0]: [stopped]
[init.svc.displayd]: [running]
[init.svc.drm]: [running]
[init.svc.drmservice]: [stopped]
[init.svc.installd]: [running]
[init.svc.keystore]: [running]
[init.svc.media]: [running]
[init.svc.netd]: [running]
[init.svc.preloadapp]: [stopped]
[init.svc.ril-daemon]: [running]
[init.svc.sdcard]: [stopped]
[init.svc.servicemanager]: [running]
[init.svc.surfaceflinger]: [running]
[init.svc.ueventd]: [running]
[init.svc.vold]: [running]
[init.svc.zygote]: [running]
[keyguard.no_require_sim]: [true]
[media.cfg.audio.bypass]: [false]
[media.cfg.audio.mul]: [false]
[media.sink.audio]: [
]
[net.bt.name]: [Android]
[net.change]: [net.qtaguid_enabled]
[net.hostname]: [android-1c67efcc1f2052b9]
[net.qtaguid_enabled]: [1]
[net.tcp.buffersize.default]: [4096,87380,110208,4096,16384,110208]
[net.tcp.buffersize.edge]: [4093,26280,35040,4096,16384,35040]
[net.tcp.buffersize.evdo]: [4094,87380,262144,4096,16384,262144]
[net.tcp.buffersize.gprs]: [4092,8760,11680,4096,8760,11680]
[net.tcp.buffersize.hsdpa]: [4094,87380,262144,4096,16384,262144]
[net.tcp.buffersize.hspa]: [4094,87380,262144,4096,16384,262144]
[net.tcp.buffersize.hspap]: [4094,87380,1220608,4096,16384,1220608]
[net.tcp.buffersize.hsupa]: [4094,87380,262144,4096,16384,262144]
[net.tcp.buffersize.lte]: [524288,1048576,2097152,262144,524288,1048576]
[net.tcp.buffersize.umts]: [4094,87380,110208,4096,16384,110208]
[net.tcp.buffersize.wifi]: [524288,1048576,2097152,262144,524288,1048576]
[persist.service.bdroid.bdaddr]: [02:25:90:3e:b6:55]
[persist.sys.profiler_ms]: [0]
[persist.sys.scalerate_x]: [95]
[persist.sys.scalerate_y]: [95]
[persist.sys.strictmode.visual]: [false]
[persist.sys.timezone]: [Atlantic/Azores]
[persist.sys.usb.config]: [mtp,adb]
[ril.function.dataonly]: [0]
[rild.libpath1]: [/system/lib/libreference-ril-mt6229.so]
[rild.libpath2]: [/system/lib/libreference-ril-mu509.so]
[rild.libpath4]: [/system/lib/libreference-ril-mw100.so]
[rild.libpath6]: [/system/lib/libreference-ril-sc6610.so]
[rild.libpath7]: [/system/lib/libreference-ril-m51.so]
[rild.libpath8]: [/system/lib/libreference-ril-mt6250.so]
[rild.libpath9]: [/system/lib/libreference-ril-c66a.so]
[rild1.libpath]: [/system/lib/libreference-ril-sc6610-1.so]
[rild3.libpath]: [/system/lib/libril-rk29-dataonly.so]
[ro.allow.mock.location]: [1]
[ro.baseband]: [unknown]
[ro.board.platform]: [rk30xx]
[ro.boot.console]: [ttyFIQ0]
[ro.bootloader]: [unknown]
[ro.bootmode]: [unknown]
[ro.bt.bdaddr_path]: [/data/misc/bluetoothd/bt_addr]
[ro.build.characteristics]: [tablet]
[ro.build.date.utc]: [1394762484]
[ro.build.date]: [Fri Mar 14 10:01:24 CST 2014]
[ro.build.description]: [rk31sdk-eng 4.2.2 JDQ39 eng.yao.20140314.100056 test-ke
ys]
[ro.build.display.id]: [rk31sdk-eng 4.2.2 JDQ39 eng.yao.20140314.100056 test-key
s]
[ro.build.fingerprint]: [radxa/rk31sdk/rk31sdk:4.2.2/JDQ39/eng.yao.20140314.1000
56:eng/test-keys]
[ro.build.host]: [radxa-x1]
[ro.build.id]: [JDQ39]
[ro.build.product]: [rk31sdk]
[ro.build.tags]: [test-keys]
[ro.build.type]: [eng]
[ro.build.user]: [yao]
[ro.build.version.codename]: [REL]
[ro.build.version.incremental]: [eng.yao.20140314.100056]
[ro.build.version.release]: [4.2.2]
[ro.build.version.sdk]: [17]
[ro.carrier]: [unknown]
[ro.com.android.dataroaming]: [true]
[ro.com.android.dateformat]: [MM-dd-yyyy]
[ro.config.alarm_alert]: [Alarm_Classic.ogg]
[ro.config.notification_sound]: [pixiedust.ogg]
[ro.config.ringtone]: [Ring_Synth_04.ogg]
[ro.debuggable]: [1]
[ro.default.size]: [100]
[ro.factory.storage_policy]: [0]
[ro.factory.tool]: [0]
[ro.factorytest]: [0]
[ro.hardware]: [rk30board]
[ro.kernel.android.checkjni]: [0]
[ro.opengles.version]: [131072]
[ro.product.board]: [rk31sdk]
[ro.product.brand]: [radxa]
[ro.product.cpu.abi2]: [armeabi]
[ro.product.cpu.abi]: [armeabi-v7a]
[ro.product.device]: [rk31sdk]
[ro.product.locale.language]: [en]
[ro.product.locale.region]: [US]
[ro.product.manufacturer]: [radxa]
[ro.product.model]: [radxa rock]
[ro.product.name]: [rk31sdk]
[ro.product.ota.host]: [www . rockchip . com : 2300]
[ro.product.usbfactory]: [rockchip_usb]
[ro.product.version]: [1.0.0]
[ro.revision]: [0]
[ro.ril.ecclist]: [112,911]
[ro.rk.MassStorage]: [false]
[ro.rk.bt_enable]: [true]
[ro.rk.def_brightness]: [200]
[ro.rk.homepage_base]: [(LINK 6)
oid-home]
[ro.rk.install_non_market_apps]: [false]
[ro.rk.screenoff_time]: [-1]
[ro.rk.systembar.voiceicon]: [false]
[ro.rksdk.version]: [RK30_ANDROID4.2.2-SDK-v1.00.00]
[ro.runtime.firstboot]: [1293883232732]
[ro.secure]: [0]
[ro.serialno]: [A7VFDT2TJA]
[ro.sf.fakerotation]: [true]
[ro.sf.hwrotation]: [270]
[ro.sf.lcd_density]: [160]
[ro.sf.lcdc_composer]: [0]
[ro.tether.denied]: [false]
[ro.vendor.sw.version]: [RK3188_RADXA_ANDROID4.2.2-SDK_V1.0.0_131214]
[ro.wifi.channels]: []
[service.adb.tcp.port]: [5555]
[service.bootanim.exit]: [1]
[sf.power.control]: [2073600]
[sys.boot_completed]: [1]
[sys.dts_ac3.shield]: [0]
[sys.dump]: [false]
[sys.ffmpeg_sf.switch]: [0]
[sys.ggralloc.version]: [1.000]
[sys.ghwc.version]: [1.023]
[sys.gmali.cores]: [4]
[sys.gmali.savedinstance]: [297]
[sys.gmali.version]: [4X_13_14]
[sys.grga.version]: [1.002]
[sys.gsflg.version]: [1.000]
[sys.hwc.compose_policy]: [0]
[sys.settings_global_version]: [4]
[sys.settings_secure_version]: [2]
[sys.usb.config]: [mtp,adb]
[sys.usb.state]: [mtp,adb]
[sys.yuv.rgb.format]: [1]
[sys_graphic.cam_hal.ver]: [0.3.51]
[system_init.startsurfaceflinger]: [0]
[testing.mediascanner.skiplist]: [/mnt/sdcard/Android/]
[video.use.overlay]: [1]
[wifi.interface]: [wlan0]
[wifi.supplicant_scan_interval]: [15]
root @ android:/ #
- Chip type: RockChip RK3188-T (SBAU32DY 1337)
- NAND chip types: SKhynix H27UCG8T2ATR BC 330A shorted the one marked with the arrow to enter in download mode:
(LINK 7)
I have tried basically everything i could come up, still not giving up and want to get this tablet running again at
least from charger if the battery won't work. So I would like to know what else i can try with it to get it working, i
can install other rooms and did that but had to put back this one since this is the best result I can get. Do you have
any suggestion what else i can check and what other ROM canI try, modified or stock i don't really care about it.
Looking for your help girls and guys if you have any TIP for me.
Tried to give as much details as i could but just ask if i missed anything or if you need any extra details.
Best regards,
daSSad
P.S. I couldn't post links so marked all of them as (LINK N) and all of them can be found here: http : // pastebin . com / UJM2gPwm (please remove spaces)
Hi
Thanks for writing to us at XDA Assist. You can't just flash firmware from other devices, even if the chip is the same there's much more than that to consider (the kernel is device specific, the other hardware like Bluetooth may be different, etc). Unfortunately I think your only option is to try to contact the manufacturer and get your hands on the actual stock firmware for the device.
Thank you for your reply. Already wrote them an email but no response yet.
So you say that there's basically no way to get this working without the original stock ROM from the manufacturer?
Thank you,
daSSad
Well, without a backup of the original firmware I don't see any way to repair what's been done to the device unfortunately.
Transmitted via Bacon
Thanks for your reply, but sounds really bad... Still not giving up on searching this is just a chinesse tablet to no way that all of them are different, they just re-brand it. At least I hope so...
Good luck with your searches, unfortunately there's nothing more we can do for you here.
Thread closed.
Transmitted via Bacon
Dear experts,
my Moto G (falcon 8GB) stopped working and freezes at startup for no obious reason.
Beforehand, it was working flawlessly with a recent Lineage OS and TWRP installed.
I can still connect to the phone via fastboot and adb, but it will freeze when loading LOS or TWRP.
I have been a happy CyanogenMod / LineageOS user for years now, but I am not an expert.
Your help is highly appreciated!
Here are the symptoms:
- Upon normal startup, the phone freezes at the initial Motorola splash screen ("Warning: Bootloader unlocked" ...)
- I can access the fastboot mode; fastboot devices recognizes the USB-connected phone.
- upon startup in recovery mode, TWRP freezes with the initial splash screen. I can re-flash the newest TWRP image in fastboot mode (e.g. fastboot flash recovery twrp-3.2.3-0-falcon.img) and the version number at the splash screen will change accordingly (say, from "Recovery Project 3.2.1-0" to "Recovery Project 3.2.3-0"), but it will still freeze.
I do have access to adb and adb shell, which allows me to inspect the folder structure, however, I cannot see any files.
Thank you very much in advance for your help! I would be more than happy to get my phone (and my data) back to life!
P.S.: Here is the output of
adb shell getprop: (hope that helps)
[dalvik.vm.dex2oat-Xms]: [64m]
[dalvik.vm.dex2oat-Xmx]: [512m]
[dalvik.vm.dex2oat-filter]: [verify-at-runtime]
[dalvik.vm.image-dex2oat-Xms]: [64m]
[dalvik.vm.image-dex2oat-Xmx]: [64m]
[dalvik.vm.image-dex2oat-filter]: [verify-at-runtime]
[dalvik.vm.isa.arm.features]: [default]
[dalvik.vm.isa.arm.variant]: [krait]
[dalvik.vm.lockprof.threshold]: [500]
[dalvik.vm.stack-trace-file]: [/data/anr/traces.txt]
[dalvik.vm.usejit]: [true]
[debug.atrace.tags.enableflags]: [0]
[init.svc.adbd]: [running]
[init.svc.ldconfigtxt]: [stopped]
[init.svc.recovery]: [running]
[init.svc.set_permissive]: [stopped]
[init.svc.ueventd]: [running]
[keyguard.no_require_sim]: [true]
[net.bt.name]: [Android]
[net.change]: [net.bt.name]
[persist.sys.dalvik.vm.lib.2]: [libart]
[persist.sys.root_access]: [1]
[persist.sys.usb.config]: [adb]
[recovery.perf.mode]: [0]
[ro.allow.mock.location]: [1]
[ro.baseband]: [msm]
[ro.board.platform]: [msm8226]
[ro.boot.baseband]: [msm]
[ro.boot.bootdevice]: [msm_sdcc.1]
[ro.boot.bootloader]: [0x411A]
[ro.boot.carrier]: []
[ro.boot.cid]: [0x7]
[ro.boot.device]: [falcon]
[ro.boot.emmc]: [true]
[ro.boot.fsg-id]: []
[ro.boot.hardware]: [qcom]
[ro.boot.hwrev]: [0x83C0]
[ro.boot.mode]: [normal]
[ro.boot.powerup_reason]: [0x00100000]
[ro.boot.radio]: [0x1]
[ro.boot.secure_hardware]: [1]
[ro.boot.selinux]: [permissive]
[ro.boot.serialno]: [TA92903D8Q]
[ro.boot.write_protect]: [0]
[ro.bootimage.build.date.utc]: [1532889118]
[ro.bootimage.build.date]: [Sun Jul 29 18:31:58 UTC 2018]
[ro.bootimage.build.fingerprint]: [Motorola/omni_falcon/falcon:6.0.1/MOB30M/17:eng/test-keys]
[ro.bootloader]: [0x411A]
[ro.bootmode]: [normal]
[ro.build.characteristics]: [default]
[ro.build.date.utc]: [0]
[ro.build.date]: [Sun Jul 29 18:29:39 UTC 2018]
[ro.build.description]: [omni_falcon-eng 6.0.1 MOB30M 17 test-keys]
[ro.build.display.id]: [omni_falcon-eng 6.0.1 MOB30M 17 test-keys]
[ro.build.fingerprint]: [Motorola/omni_falcon/falcon:6.0.1/MOB30M/17:eng/test-keys]
[ro.build.flavor]: [omni_falcon-eng]
[ro.build.host]: [24fbe3db73ea]
[ro.build.id]: [MOB30M]
[ro.build.product]: [falcon]
[ro.build.tags]: [test-keys]
[ro.build.type]: [eng]
[ro.build.user]: [jenkins]
[ro.build.version.all_codenames]: [REL]
[ro.build.version.base_os]: []
[ro.build.version.codename]: [REL]
[ro.build.version.incremental]: [17]
[ro.build.version.preview_sdk]: [0]
[ro.build.version.release]: [6.0.1]
[ro.build.version.sdk]: [23]
[ro.build.version.security_patch]: [2016-06-01]
[ro.carrier]: [unknown]
[ro.com.android.dataroaming]: [true]
[ro.com.android.wifi-watchlist]: [GoogleGuest]
[ro.com.google.clientidbase]: [android-google]
[ro.config.alarm_alert]: [Argon.ogg]
[ro.config.notification_sound]: [pixiedust.ogg]
[ro.config.ringtone]: [Ring_Synth_04.ogg]
[ro.dalvik.vm.native.bridge]: [0]
[ro.debuggable]: [1]
[ro.hardware]: [qcom]
[ro.kernel.android.checkjni]: [1]
[ro.modversion]: [OmniROM-6.0.1-20180729-falcon-HOMEMADE]
[ro.omni.device]: [falcon]
[ro.omni.version]: [6.0.1-20180729-falcon-HOMEMADE]
[ro.product.board]: [MSM8226]
[ro.product.brand]: [Motorola]
[ro.product.cpu.abi2]: [armeabi]
[ro.product.cpu.abi]: [armeabi-v7a]
[ro.product.cpu.abilist32]: [armeabi-v7a,armeabi]
[ro.product.cpu.abilist64]: []
[ro.product.cpu.abilist]: [armeabi-v7a,armeabi]
[ro.product.device]: [falcon]
[ro.product.locale]: [en-US]
[ro.product.manufacturer]: [Motorola]
[ro.product.model]: [Moto G]
[ro.product.name]: [omni_falcon]
[ro.revision]: [0]
[ro.secure]: [0]
[ro.serialno]: [TA92903D8Q]
[ro.setupwizard.enterprise_mode]: [1]
[ro.twrp.boot]: [1]
[ro.twrp.version]: [3.2.3-0]
[ro.wifi.channels]: []
[ro.zygote]: [zygote32]
[service.adb.root]: [1]
[twrp.crash_counter]: [0]
I have the same issue on my phone, it either hangs at "Warning: Bootloader unlocked" screen or if it proceeds further, the lineage OS logo just plays forever. It gets very hot if I leave it in that state
there is something very wrong in that build.prop, what have you flashed? i think you just need a clean flash of any known working rom
lucastracq said:
there is something very wrong in that build.prop, what have you flashed? i think you just need a clean flash of any known working rom
Click to expand...
Click to collapse
I flashed LineageOS and TWRP maybe one year ago and it only stopped working recently. I would love to re-flash, but how can I do that without access to TWRP? Any suggestions?
Thanks a lot!
Just run fastboot erase userdata. If this does not work, maybe the problem is Nand or crystal oscillator
samuel.caldas said:
Just run fastboot erase userdata. If this does not work, maybe the problem is Nand or crystal oscillator
Click to expand...
Click to collapse
Yay - fastboot erase userdata did the job - thanks a lot!
For some reason, I was looking at the wrong end for a long time and expected some sort of hardware failure