unable to complete RUU and resotr to its original state - HTC Desire S

hi guys...
This was my previous thread..
http://forum.xda-developers.com/showthread.php?t=1463743
Now downloaded the RUU..
RUU_Saga_hTC_Asia_India_1.47.720.1_Radio_20.28I.30.085AU_3805.06.02.03_M_release_199605_signed_4..
hwen i run the RUU boot loader says security error but RUU says error 155.. here are the shots...
now please guide me to restore it to orignal state? i have SDK tools and Fastboot...
please help me

Try to reboot phone to fastboot mode and then run RUU. That should fix it.

i tried in fastboot mode but still error 155 occurs....i dun knw why im not able to restore the origial backed up image also..here are the contents of my backed up image....
After installing WP7 of MIUI based on..im not able to restore backed up one...but i can restore CM7.1.............
Please guide me .....

When i was going to return to stock rom, I first tried to flash a 1.47-RUU without success. I am not sure why, but the 2.10-RUU worked for me (but that is no choice for you, as I don't see for Asia it in the List of Shiped ROM Collection).
I have been coming from a 6.xxx HBOOT called engHBOOToverARX.img, you will find a link somewhere in the discontinued Tutorial here. If your phone was unbranded, you will find the original tutorial in the quotes. Basically I flashed this engHBOOT in fastboot (resulting in 6.xxx-HBOOT), than I run the RUU.

Thanks for the suggestion...
i ll try with 2.10-RUU AND LET U KNOW..
im my phone platfor info it says my product is HTC_SAGA and my brand is HTC_EUROPE what does this means?
Means shipped indian ruu RUU_Saga_hTC_Asia_India_1.47.720.1_Radio_20.28I.30 .085AU_3805.06.02.03_M_release_199605_signed_4 doent work for me?

this is what i have got after i do "fastboot flash zip rom.zip which was extracted from the above said RUU i.e RUU_Saga_S_HTC_Europe_2.10.401.8_Radio_20.4801.30.0822U_3822.10.08.04_M_release_225161_signed...
Now what?
please guide me

Which bootloader version are you currently stuck with? Are you able to access recovery etc?
fastboot getvar all - paste the results from that command here.
fastboot rebootRUU - try running the RUU again when you're in this mode.

I have a workaround, but it's not very good so i didn't post before, but you seem pretty desperate. Flash a pre-rooted stock rom via recovery(there's a thread in development section). Then, run gingerbreak to unroot. Try to find a rom from your region. If not, use the latest one. You won't get any updates.
Sent from my iPod touch using Tapatalk

hboot 2.00.002......YES IM ABLE TO ACCESS CWM RECOVERY AT ANY TIME AND RESTORE ONLY CUSTOM ROM BUT NOT ORIGNAL BACK UP DONE FOR THE FIRST TIME AFTER UNLOCK.....
suprisingly after installing CM7.1 i could restore the original back up but now im not able to...
ok i ll do what u said and give u feedback

my phone platfor info it says my product is HTC_SAGA and my brand is HTC_EUROPE what does this means?

You flashed a european rom, no problem. You want to sell it? Say you bought it from spain xD
Sent from my iPod touch using Tapatalk

fastboot getvar all ....................
< waiting for device >
(bootloader) version: 0.5
(bootloader) version-bootloader: 2.00.0002
(bootloader) version-baseband: 3822.10.08.04_M
(bootloader) version-cpld: None
(bootloader) version-microp: None
(bootloader) version-main: 1.27.405.6
(bootloader) serialno: MB129TJ00690
(bootloader) imei: 355067047867643
(bootloader) product: saga
(bootloader) platform: HBOOT-7230
(bootloader) modelid: PG8810000
(bootloader) cidnum: HTC__038
(bootloader) battery-status: good
(bootloader) battery-voltage: 3795mV
(bootloader) partition-layout: Generic
(bootloader) security: on
(bootloader) build-mode: SHIP
(bootloader) boot-mode: FASTBOOT
(bootloader) commitno-bootloader: ebd3df7d
(bootloader) hbootpreupdate: 12
(bootloader) gencheckpt:0
all done!
when i did fastboot rebootRUU
C:\android>fastboot rebootRUU
usage: fastboot [ <option> ] <command>
commands:
update <filename> reflash device from update.zip
flashall flash boot + recovery + system
flash <partition> [ <filename> ] write a file to a flash partition
erase <partition> erase a flash partition
getvar <variable> display a bootloader variable
boot <kernel> [ <ramdisk> ] download and boot kernel
flash:raw boot <kernel> [ <ramdisk> ] create bootimage and flash it
devices list all connected devices
continue continue with autoboot
reboot reboot device normally
reboot-bootloader reboot device into bootloader
help show this help message
options:
-w erase userdata and cache
-s <serial number> specify device serial number
-p <product> specify product name
-c <cmdline> override kernel commandline
-i <vendor id> specify a custom USB vendor id
-b <base_addr> specify a custom kernel base address
-n <page size> specify the nand page size. default:
2048
and i had RUU but error 155

what if i want to use it for myself with internet pass through as a must option...????

i have both...RUU_Saga_S_HTC_Europe_2.10.401.8_Radio_20.4801.30.0822U_3822.10.08.04_M_release_225161_signed ...and
RUU_Saga_hTC_Asia_India_1.47.720.1_Radio_20.28I.30.085AU_3805.06.02.03_M_release_199605_signed_4
why im not able to go back to the orignal sense UI 2.5/3????

Because that would be downgrading...........
Try this - http://forum.xda-developers.com/showthread.php?t=1399331
Use the 1.47 RUU this time.

C:\android>adb push zergRush /data/local/tmp
push: zergRush/zergRush -> /data/local/tmp/zergRush
1 file pushed. 0 files skipped.
195 KB/s (23060 bytes in 0.115s)
C:\android>adb push misc_version /data/local/tmp
push: misc_version/misc_version -> /data/local/tmp/misc_version
1 file pushed. 0 files skipped.
520 KB/s (589849 bytes in 1.107s)
C:\android>adb shell chmod 777 /data/local/tmp/zergRush
C:\android>adb shell chmod 777 /data/local/tmp/misc_version
C:\android>adb shell
# cd /data/local/tmp/
cd /data/local/tmp/
# ./zergRush
./zergRush
[**] Zerg rush - Android 2.2/2.3 local root
[**] (C) 2011 Revolutionary. All rights reserved.
[**] Parts of code from Gingerbreak, (C) 2010-2011 The Android Exploid Crew.
[+] Found a GingerBread ! 0x00000118
[*] Scooting ...
[*] Sending 149 zerglings ...
[+] Zerglings found a way to enter ! 0x10
[+] Overseer found a path ! 0x000161e0
[*] Sending 149 zerglings ...
[+] Overseer found a path ! 0x000161e0
[*] Sending 149 zerglings ...
[-] Zerglings did not leave interesting stuff
# adb shell /data/local/tmp/misc_version -s 1.27.405.6
adb shell /data/local/tmp/misc_version -s 1.27.405.6
adb: not found
# /data/local/tmp/misc_version -s 1.27.405.6
/data/local/tmp/misc_version -s 1.27.405.6
--set_version set. VERSION will be changed to: 1.27.405.6
Patching and backing up partition 17...
#
after this i ran 1.47 RUU but error 155 persists....at update signature it failed

i restored back to CM7.1 now agian.......

please guide me......................

im not able to downgrade to 0.98 .im not to s-off........not able restore to original back up ..............

RUUs don't work on official HBOOT (the latest ones anyway) unlocked. Didn't for me anyway. Relock again by typing "fastboot oem lock"
If you get Carrier ID error, use a goldcard.

Related

[Q] [HELP] finding for HELP! my DS has been bricked, very hard and hard [HELP]

I tried flashing a new rom for my DS
on this forum:
update-saga-runnymede-s-v5.zip
unluckily
my phone just can turn on once, then it lagged for a long time.
i took out the battery and insert again. turn on again.
badly it lagged again. i repeated
then the third time it stucked at HTC white screen for about an hour
then i tried many times but failed
i try to updated the recovery
'updating recovery' <- this screen has been showing for mayb few hours ( i fell asleep while waiting, when i woke up it's out of battery. then i reboot again but in bootloader NO 'RECOVERY' option!
now my phone has this option but when i choose it it disappears!
so i couldn't flash new recovery through phone
HELP HELP I AM REALLY GETTING CRAZY OF THIS!
can anyone help?
Ok. It seems that your recovery is gone by some reason.
Since you are using adb, I suppose that you have fastboot command also.
Download this file, rename it to recovery.img. Reboot your phone to bootloader (vol down + power), connect it to PC. It should be "FASTBOOT USB" written on the screen. Then open command prompt and type:
Code:
fastboot flash recovery {path to the file}\recovery.img
It should take less than a second to flash it (if longer than you may have troubles with the eMMC chip). If ok reboot to recovery and flash a custom ROM.
If not OK, connect to PC again as described above and type:
Code:
fastboot getvar all
and post the output here.
firstly i haven't tried
Code:
fastboot getvar all
yet since i am still waiting for <waiting for device>
so mayb it has failed.
what should i do to end this and try another method?
close adb directly ?
here is the details when i try fastboot getover all
environmental variables:
ADB_TRACE - Print debug information. A comma separated list
of the following values
1 or all, adb, sockets, packets, rwx, usb, sync
, sysdeps, transport, jdwp
ANDROID_SERIAL - The serial number to connect to. -s takes prior
ity over this if given.
ANDROID_LOG_TAGS - When used with the logcat option, only these de
bug tags are printed.
C:\Users\Chris>fastboot getover all
usage: fastboot [ <option> ] <command>
commands:
update <filename> reflash device from update.zip
flashall flash boot + recovery + system
flash <partition> [ <filename> ] write a file to a flash partition
erase <partition> erase a flash partition
getvar <variable> display a bootloader variable
boot <kernel> [ <ramdisk> ] download and boot kernel
flash:raw boot <kernel> [ <ramdisk> ] create bootimage and flash it
devices list all connected devices
continue continue with autoboot
reboot reboot device normally
reboot-bootloader reboot device into bootloader
options:
-w erase userdata and cache
-s <serial number> specify device serial number
-p <product> specify product name
-c <cmdline> override kernel commandline
-i <vendor id> specify a custom USB vendor id
-b <base_addr> specify a custom kernel base address
-n <page size> specify the nand page size. default:
2048
C:\Users\Chris>
not getover, but getvar
copy the command from my post and paste it to your command prompt to avoid mistakes
EDIT: have you managed to flash the recovery?? the text in the brackets {} has to be replaced with the path to your file - e.g. C:\android
then the command will look like this:
fastboot flash recovery C:\android\recovery.img
sorry for that i missed the word
C:\Users\Chris>fastboot getvar all
(bootloader) version: 0.5
(bootloader) version-bootloader: 6.98.1002
(bootloader) version-baseband: 3805.06.02.03_M
(bootloader) version-cpld: None
(bootloader) version-microp: None
(bootloader) version-main: 1.47.832.1
(bootloader) serialno: SH14MTJ01449
(bootloader) imei: 355067046266979
(bootloader) product: saga
(bootloader) platform: HBOOT-7230
(bootloader) modelid: PG8810000
(bootloader) cidnum: HTC__622
(bootloader) battery-status: good
(bootloader) battery-voltage: 3805mV
(bootloader) partition-layout: Generic
(bootloader) security: off
(bootloader) build-mode: SHIP
(bootloader) boot-mode: FASTBOOT
(bootloader) commitno-bootloader: 361a7ba6
(bootloader) hbootpreupdate: 12
(bootloader) gencheckpt: 0
all: Done!
finished. total time: 0.031s
here's the result
is it possible that the chip fried while "all done"?
all seems ok. Have you managed to flash the recovery image. My previous post is updated, check it
sorry what do you mean your previous post? which is it?
cckwan said:
sorry what do you mean your previous post? which is it?
Click to expand...
Click to collapse
amidabuddha said:
EDIT: have you managed to flash the recovery??
Click to expand...
Click to collapse
the text in the brackets {} has to be replaced with the path to your file - e.g. C:\android
then the command will look like this:
fastboot flash recovery C:\android\recovery.img
oh now when i type
Code:
fastboot flash recovery C:\Users\Chris\Downloads\recovery.img
it shows:
Code:
sending 'recovery' <6000 kb>
OKAY [0.995s]
writing recovery...
then no continue action
staying here
what should i do the next?
Your next step is to go to the [GUIDE] Read this before going for eMMC replacement in my signature and follow point 4.1
Use this RUU
You will lose S-OFF and root, but eventually your phone will work again
how about my flash recovery still not yet complete...?
btw i am still trying to understand that post step 4.1
but i wanna know is it ok that recovery not yet finished?
4.1 If you have a 6.98.xxxx hboot
You probably already have the adb properly configured on your PC
Change your hboot with this one There are 3 ways:
i should download "this one" right? there are <Eng S-Off.rar> and <PG88IMG.zip> inside.
1) use the one click - it will flash it for you
what means by the 'one click"?
2) put PG88IMG.zip on your SDcard and rebot to bootloader. It will flash automatically. After flashing delete PG88IMG.zip from the SDcard
i can't see my sd card on PC, should i pull out the sd card to another phone and put in the files required then insert back to my phone ?
3) extract the image from PG88IMG.zip, rename it to hboot.img, connect the device to PC, reboot it to bootloader (it should be written "FASTBOOT USB" on the phone, open a command prompt on the PC and type:
sorry...
when i am installing ruu
error occurs: usb connection may lost
so wht can i do><
totally lost now
sorry... now i found i haven't flash hboot.img completely
as it showed: image update is bypassed!
so what should i do?
***updates***
i tried 'fastboot flash hboot G:\a1\hboot.img'
(tried:
http://forum.xda-developers.com/showthread.php?t=1236890
&
http://forum.xda-developers.com/showthread.php?t=1113820
then it showed
Code:
C:\Users\Chris>fastboot flash hboot G:\a1\hboot.img
sending 'hboot' (1024 KB)...
OKAY [ 0.201s]
writing 'hboot'...
(bootloader) image update is bypassed!
OKAY [ 0.029s]
finished. total time: 0.231s
---------------------------------------------------
cannot flash hboot to 0.98.2000 or what
----------------------------------------------------
i can see my serial no. on PC cmd by using 'fastboot devices'
but adb devices shows nothing
---------------------------------------------------
-Revolutionary-
SAGA PUT SHIP S-OFF RL
HBOOT-6.98.1002
RADIO- 3805.06.02.03_M
eMMC-boot
Mar 10 2011, 14:58:38
---------------------------------------------------
WHEN I choose 'recovery' option on fastboot it blacked for 0.1s then fastboot screen again without 'recovery' option
---------------------------------------------------
sleep time now 2:15am here
thank you very much amidabuddha reli so much!
you have done a lot i know but i just need some more help getting my DS turn on again...or there will be a murder news here which parents killed their son sosad
thank you. hope you can reply me ASAP when you are convenient!
--------------------------------------------------
i tried tpbklake'sadvice to flash a cwm recovery but the cmd stayed at writing recovery...
cckwan said:
***updates***
i tried 'fastboot flash hboot G:\a1\hboot.img'
(tried:
http://forum.xda-developers.com/showthread.php?t=1236890
&
http://forum.xda-developers.com/showthread.php?t=1113820
then it showed
Code:
C:\Users\Chris>fastboot flash hboot G:\a1\hboot.img
sending 'hboot' (1024 KB)...
OKAY [ 0.201s]
writing 'hboot'...
(bootloader) image update is bypassed!
OKAY [ 0.029s]
finished. total time: 0.231s
---------------------------------------------------
cannot flash hboot to 0.98.2000 or what
----------------------------------------------------
i can see my serial no. on PC cmd by using 'fastboot devices'
but adb devices shows nothing
---------------------------------------------------
-Revolutionary-
SAGA PUT SHIP S-OFF RL
HBOOT-6.98.1002
RADIO- 3805.06.02.03_M
eMMC-boot
Mar 10 2011, 14:58:38
---------------------------------------------------
WHEN I choose 'recovery' option on fastboot it blacked for 0.1s then fastboot screen again without 'recovery' option
---------------------------------------------------
sleep time now 2:15am here
thank you very much amidabuddha reli so much!
you have done a lot i know but i just need some more help getting my DS turn on again...or there will be a murder news here which parents killed their son sosad
thank you. hope you can reply me ASAP when you are convenient!
Click to expand...
Click to collapse
The Revolutionary HBOOT 6.98.1002 will not allow you to overwrite it. You can only overwrite it using a special version from Revolutionary/AlphaRevX for removing S-OFF and returning to S-ON. Search for Revolutionary return to S-ON.
sorry i am quite new in android
can u tell me how to find revolutionary?
i even dunno what type of file i should search
or can you give me the download link? please
tpbklake said:
The Revolutionary HBOOT 6.98.1002 will not allow you to overwrite it. You can only overwrite it using a special version from Revolutionary/AlphaRevX for removing S-OFF and returning to S-ON. Search for Revolutionary return to S-ON.
Click to expand...
Click to collapse
cckwan said:
sorry i am quite new in android
can u tell me how to find revolutionary?
i even dunno what type of file i should search
or can you give me the download link? please
Click to expand...
Click to collapse
Use the search function of this forum using the key word 'revolutionary s-on'
It should turn up a few threads that address the topic.

[Q] Stuck downgrading from Super CID

I have a Sensation I need to get back to stock. I ran an RUU and everything seems fine, but when I perform the steps in fastboot to change my CID back to HTC__001 it refuses to stick. It always comes back with 11111111.
Here's the log:
Code:
C:\Android>adb devices
* daemon not running. starting it now on port 5037 *
* daemon started successfully *
List of devices attached
XXXXXXXXXXXX device
C:\Android>adb reboot bootloader
C:\Android>fastboot getvar all
(bootloader) version: 0.5
(bootloader) version-bootloader: 1.27.0000
(bootloader) version-baseband: 11.24A.3504.31_M
(bootloader) version-cpld: None
(bootloader) version-microp: None
(bootloader) version-main: 3.33.401.6
(bootloader) serialno: XXXXXXXXXXXX
(bootloader) imei: XXXXXXXXXXXXXXX
(bootloader) product: pyramid
(bootloader) platform: HBOOT-8260
(bootloader) modelid: PG5813000
(bootloader) cidnum: 11111111
(bootloader) battery-status: good
(bootloader) battery-voltage: 4187mV
(bootloader) partition-layout: Generic
(bootloader) security: off
(bootloader) build-mode: SHIP
(bootloader) boot-mode: FASTBOOT
(bootloader) commitno-bootloader: 617f0a98
(bootloader) hbootpreupdate: 11
(bootloader) gencheckpt: 0
all: Done!
finished. total time: 0.550s
C:\Android>fastboot oem writecid HTC__001
...
(bootloader) Start Verify: -1
(bootloader) erase sector 65504 ~ 65535 (32)
OKAY [ 0.050s]
finished. total time: 0.050s
C:\Android>fastboot reboot
rebooting...
finished. total time: 1.738s
C:\Android>adb reboot bootloader
C:\Android>fastboot getvar cid
cid: 11111111
finished. total time: 0.003s
Sorry if this has been answered before. I searched but all I found was questions about achieving Super CID.
Cheers
-Bizwax
Run the RUU again.. Then try the cid change.
And use fastboot reboot-bootloader
After cid change to verify it.. Instead of fastboot reboot
Sent from my pyramid.. Through blazing fast sonic waves
Thanks ganeshp. Here's the new log. Fresh RUU install as instructed.
Code:
C:\adb>adb devices
* daemon not running. starting it now on port 5037 *
* daemon started successfully *
List of devices attached
XXXXXXXXXXXX device
C:\adb>adb reboot bootloader
C:\adb>fastboot getvar cid
cid: 11111111
finished. total time: 0.003s
C:\adb>fastboot oem writecid HTC__001
... INFOStart Verify: -1
INFOerase sector 65504 ~ 65535 (32)
OKAY [ 1.542s]
finished. total time: 1.542s
C:\adb>fastboot reboot-bootloader
rebooting into bootloader... OKAY [ 0.285s]
finished. total time: 0.286s
C:\adb>fastboot getvar cid
cid: 11111111
finished. total time: 0.004s
I've also tried using a different RUU but get the same result.
Hmm, just tried it myself, I'm on HBOOT 1.27.1100 if that make a difference and it seemed to work fine.
Bizwax said:
Thanks ganeshp. Here's the new log. Fresh RUU install as instructed.
Code:
C:\adb>adb devices
* daemon not running. starting it now on port 5037 *
* daemon started successfully *
List of devices attached
XXXXXXXXXXXX device
C:\adb>adb reboot bootloader
C:\adb>fastboot getvar cid
cid: 11111111
finished. total time: 0.003s
C:\adb>fastboot oem writecid HTC__001
... INFOStart Verify: -1
INFOerase sector 65504 ~ 65535 (32)
OKAY [ 1.542s]
finished. total time: 1.542s
C:\adb>fastboot reboot-bootloader
rebooting into bootloader... OKAY [ 0.285s]
finished. total time: 0.286s
C:\adb>fastboot getvar cid
cid: 11111111
finished. total time: 0.004s
I've also tried using a different RUU but get the same result.
Click to expand...
Click to collapse
cid will be stored at 3 partitions afaik ..and somehow one partition is not letting it changed ...
the error " ... INFOStart Verify: -1" kind of says that
there is some high level solution (dd and dumping images ) ..let me check on that first and then Ill let you know ..the method
hey
i need some info
first you need to root your device (you can reflash the RUU after cid change ..that will remove the root)
to root your device ..try my one click root tool (soff guide link in my signature) ...
then i want the output of these commands
from adb folder
adb shell
su (make sure the prompt is # not $)
strings -n 8 /dev/block/mmcblk0p4 (paste the output of this command)
strings -n 8 /dev/block/mmcblk0p5 (paste the output of this command too)
then based on this output i will give you further instructions
Just to confirm, you want me to follow the rooting procedure from scratch even though I'm already rooted and currently running Elegancia?
Bizwax said:
Just to confirm, you want me to follow the rooting procedure from scratch even though I'm already rooted and currently running Elegancia?
Click to expand...
Click to collapse
No no not required if you are already rooted.. Just give me that information from Elegance itself
Sent from my HTC Sensation 4G using xda premium
I have the same problem. That is not able to downgrade from Super CID. I have tried to run the command as per your suggestion and found “HTC__044” for both commands. But when I type “fastboot getvar cid” it is showing my CID is 11111111. Pls suggest on this.
Subin khan said:
I have the same problem. That is not able to downgrade from Super CID. I have tried to run the command as per your suggestion and found “HTC__044” for both commands. But when I type “fastboot getvar cid” it is showing my CID is 11111111. Pls suggest on this.
Click to expand...
Click to collapse
Then mostly it got changed but it's not being reflected from bootloader correctly
Post the output of this command
fastboot oem readcid
Also try an older RUU like that of GB one and then check the cid again..
Sent from my HTC Sensation 4G using xda premium
Actually, this problem is starting after I have applied below command by a mistake:
fastboot oem writePid HTC__044
that is instead of CID I typed pid
and I think some info are overwritten.
---------- Post added at 12:42 PM ---------- Previous post was at 12:37 PM ----------
Subin khan said:
Actually, this problem is starting after I have applied below command by a mistake:
fastboot oem writePid HTC__044
that is instead of CID I typed pid
and I think some info are overwritten.
Click to expand...
Click to collapse
BTW, fastboot oem readcid command showing below:
D:\My Mobile\Android\Tools\ADB_Fastboot_Windows>fastboot oem readcid
... INFOfake cid: 11111111
INFOcid: 11111111
OKAY [ 0.000s]
finished. total time: 0.000s
Subin khan said:
Actually, this problem is starting after I have applied below command by a mistake:
fastboot oem writePid HTC__044
that is instead of CID I typed pid
and I think some info are overwritten.
---------- Post added at 12:42 PM ---------- Previous post was at 12:37 PM ----------
BTW, fastboot oem readcid command showing below:
D:\My Mobile\Android\Tools\ADB_Fastboot_Windows>fastboot oem readcid
... INFOfake cid: 11111111
INFOcid: 11111111
OKAY [ 0.000s]
finished. total time: 0.000s
Click to expand...
Click to collapse
One more partition where cid is stored is missing then.. I'll dig into that.. Might take some time.. May be in few hours I can come to conclusion
Sent from my HTC Sensation 4G using xda premium
ganeshp said:
One more partition where cid is stored is missing then.. I'll dig into that.. Might take some time.. May be in few hours I can come to conclusion
Sent from my HTC Sensation 4G using xda premium
Click to expand...
Click to collapse
Ok then pls help me to restore my missing partition's CID..
ganeshp said:
adb shell
su (make sure the prompt is # not $)
strings -n 8 /dev/block/mmcblk0p4 (paste the output of this command)
strings -n 8 /dev/block/mmcblk0p5 (paste the output of this command too)
then based on this output i will give you further instructions
Click to expand...
Click to collapse
I don't get any output from those commands. I switched from Elegancia to Insertcoin to double check and still the same.
Code:
C:\adb>adb shell
[email protected]/# su
su
[email protected]/# strings -n 8 /dev/block/mmcblk0p4
strings -n 8 /dev/block/mmcblk0p4
[email protected]/# strings -n 8 /dev/block/mmcblk0p5
strings -n 8 /dev/block/mmcblk0p5
[email protected]/#
I'll try reflashing the RUU first instead.
Bizwax said:
I don't get any output from those commands. I switched from Elegancia to Insertcoin to double check and still the same.
Code:
C:\adb>adb shell
[email protected]/# su
su
[email protected]/# strings -n 8 /dev/block/mmcblk0p4
strings -n 8 /dev/block/mmcblk0p4
[email protected]/# strings -n 8 /dev/block/mmcblk0p5
strings -n 8 /dev/block/mmcblk0p5
[email protected]/#
I'll try reflashing the RUU first instead.
Click to expand...
Click to collapse
Pls use GB base ROM and unlocked bootloader.
any help regarding this issue?
Subin khan said:
any help regarding this issue?
Click to expand...
Click to collapse
Likewise
Subin khan said:
any help regarding this issue?
Click to expand...
Click to collapse
Bizwax said:
Likewise
Click to expand...
Click to collapse
i PM'd one dev for some help ..no reply from him yet ..will try talking to him again today (fingers crossed)
Well it looks like this one is going nowhere fast. ganeshp, I believe we have you stumped, my good man
So anyways, I've been playing around in the meantime and I got those adb shell commands working. I flashed the RUU, then flashed 4extRecovery via PG58IMG, then installed superuser using 4ext...and now I can actually get outputs for the commands you mentioned earlier:
adb shell
su (make sure the prompt is # not $)
strings -n 8 /dev/block/mmcblk0p4 (paste the output of this command)
strings -n 8 /dev/block/mmcblk0p5 (paste the output of this command too)
then based on this output i will give you further instructions
Click to expand...
Click to collapse
Here's the bad news, I get strings: not found for both of them. Not much of an improvement, eh?
Code:
C:\Android>adb shell
[email protected]:/ $ su
su
[email protected]:/ # strings -n 8 /dev/block/mmcblk0p4
strings -n 8 /dev/block/mmcblk0p4
sh: strings: not found
127|[email protected]:/ # strings -n 8 /dev/block/mmcblk0p5
strings -n 8 /dev/block/mmcblk0p5
sh: strings: not found
Did the RUU install OK ? Did you also install Superuser/SuperSU ?
If so install a Terminal Emulator from Play Store (the one I use is from Jack Palevich). Then install BusyBox. Then try directly on the phone in the Terminal Emulator.
When that works try the ADB method again.

[Q] bad CID - stuck in bootloader

In my quest to upgrade the hboot of my HTC One XL (evita), I accidentally used a tool intended for the the HTC One X (JFW Tool), and overwrote my CID to HTC__621. Now I'm stuck in the bootloader. Any help would be much appreciated (especially with the steps, I'm still a bit fuzzy on SuperCID, S-Off, bootloaders, roms and recovery). I think I was previously unlocked, running an unofficial CyanogenMod (because updates stopped coming around), and then I wanted to get on the OTA CM train, but needed to update hboot, which got me in my current situation:
Here's what my bootloader screen says:
Code:
*** TAMPERED ***
*** RELOCKED ***
EVITA PVT SHIP S-ON RL
HBOOT-1.09.0000
RADIO-0.17.32.09.12
OpenDSP-v28.1.0.32.0504
eMMC-boot
Apr 2 2012,21:08:24
FASTBOOT (or FASTBOOT USB)
<VOL UP> to previous item
<VOL DOWN> to next item
<POWER> to select item
BOOTLOADER
REBOOT
REBOOT BOOTLOADER
POWER DOWN
And here's what I've tried:
tried setting CID to 11111111
tried flashing recovery (my TWRP recovery is not present anymore)
tried flashing hboot
tried running X-Factor exploits
ran the all-in-one tool to try and exploit and unlock
I cannot seem to get anything to work. Flashing anything generates a remote signature fail id error.
Please help me to get my phone back up again!
Thanks,
Dave
You tried all those things without knowing what you're doing? You must love to live life dangerously!
Your bootloader is locked.
In bootloader, use volume down to scroll to reboot and hit power button to select it. Then read forums on how to unlock bootloader.
Sent from my HTC One X using xda premium
Venomtester said:
In bootloader, use volume down to scroll to reboot and hit power button to select it. Then read forums on how to unlock bootloader.
Click to expand...
Click to collapse
Perfect, that's what I needed (I didn't know bootloaders could become "relocked".
So, I'm now back to where I was before, with a phone I cannot update to the latest CM10, because my hboot is too old (=1.09)
I've tried to follow all the instructions on these forums for updating hboot to 2.14, without any success:
Using Hassoon2000's all-in-one kit for the HTC One X (evita) and also from the command line, I've tried to directly install:
hboot 2.14
OTA_EVITA_UL_JB_45_S_Cingular_US_3.18.502.6_0.24p.32.09.06_10.130.32.34_release_3061616bcty3drvawwo01k (which contains 2.14)
It fails on signature or hangs. I tried this with bootloader locked and unlocked (thanks to Venomtester, I can now do this without difficulty), and from the bootloader, fastboot and htc screens (gold htc logo).
So any hints on how to get hboot 2.14 installed on this device? Failing that, (or perhaps instead of) I could even go back to a factory ROM and settings, if I could get some hints on this.
Thanks again,
Dave
PS: I have a feeling it may be malfunctioning due to that CID change I did. I tried to change CID back using the regular tool, and then used the instructions for hex editing the CID, all without success (adb shell doesn't work)
boulder_dave said:
Perfect, that's what I needed (I didn't know bootloaders could become "relocked".
So, I'm now back to where I was before, with a phone I cannot update to the latest CM10, because my hboot is too old (=1.09)
I've tried to follow all the instructions on these forums for updating hboot to 2.14, without any success:
Using Hassoon2000's all-in-one kit for the HTC One X (evita) and also from the command line, I've tried to directly install:
hboot 2.14
OTA_EVITA_UL_JB_45_S_Cingular_US_3.18.502.6_0.24p.32.09.06_10.130.32.34_release_3061616bcty3drvawwo01k (which contains 2.14)
It fails on signature or hangs. I tried this with bootloader locked and unlocked (thanks to Venomtester, I can now do this without difficulty), and from the bootloader, fastboot and htc screens (gold htc logo).
So any hints on how to get hboot 2.14 installed on this device? Failing that, (or perhaps instead of) I could even go back to a factory ROM and settings, if I could get some hints on this.
Thanks again,
Dave
PS: I have a feeling it may be malfunctioning due to that CID change I did. I tried to change CID back using the regular tool, and then used the instructions for hex editing the CID, all without success (adb shell doesn't work)
Click to expand...
Click to collapse
What is your CID right now still the same?
use fastboot oem readcid to find out if you're not sure.
exad said:
What is your CID right now still the same?
use fastboot oem readcid to find out if you're not sure.
Click to expand...
Click to collapse
Code:
C:\Users\dkabal\Downloads\android\sdk\platform-tools>fastboot getvar all
(bootloader) version: 0.5
(bootloader) version-bootloader: 1.09.0000
(bootloader) version-baseband: 0.17.32.09.12
(bootloader) version-cpld: None
(bootloader) version-microp: None
(bootloader) version-main: 1.85.502.3
(bootloader) serialno: HT249W300070
(bootloader) imei: 359691042133556
(bootloader) product: evita
(bootloader) platform: HBOOT-8960
(bootloader) modelid: PJ8310000
(bootloader) cidnum: HTC__621
(bootloader) battery-status: good
(bootloader) battery-voltage: 3747mV
(bootloader) partition-layout: Generic
(bootloader) security: on
(bootloader) build-mode: SHIP
(bootloader) boot-mode: FASTBOOT
(bootloader) commitno-bootloader: e964c535
(bootloader) hbootpreupdate: 11
(bootloader) gencheckpt: 0
all: Done!
finished. total time: 0.089s
boulder_dave said:
Code:
C:\Users\dkabal\Downloads\android\sdk\platform-tools>fastboot getvar all
(bootloader) version: 0.5
(bootloader) version-bootloader: 1.09.0000
(bootloader) version-baseband: 0.17.32.09.12
(bootloader) version-cpld: None
(bootloader) version-microp: None
(bootloader) version-main: 1.85.502.3
(bootloader) serialno: HT249W300070
(bootloader) imei: 359691042133556
(bootloader) product: evita
(bootloader) platform: HBOOT-8960
(bootloader) modelid: PJ8310000
(bootloader) cidnum: HTC__621
(bootloader) battery-status: good
(bootloader) battery-voltage: 3747mV
(bootloader) partition-layout: Generic
(bootloader) security: on
(bootloader) build-mode: SHIP
(bootloader) boot-mode: FASTBOOT
(bootloader) commitno-bootloader: e964c535
(bootloader) hbootpreupdate: 11
(bootloader) gencheckpt: 0
all: Done!
finished. total time: 0.089s
Click to expand...
Click to collapse
Okie dokie, so, your bootloader is unlocked at this point right?
If so, flash twrp 2.6: fastboot flash recovery recoveryfilename.img
Your CID shouldn't matter for right now, you should at least be able to flash a Rom at this point (obv. not cm10.1 3.4 kernel). Then we can work on SuperCID and S-OFF.
exad said:
Okie dokie, so, your bootloader is unlocked at this point right?
If so, flash twrp 2.6: fastboot flash recovery recoveryfilename.img
Your CID shouldn't matter for right now, you should at least be able to flash a Rom at this point (obv. not cm10.1 3.4 kernel). Then we can work on SuperCID and S-OFF.
Click to expand...
Click to collapse
Thanks for all the help!
2.6 TWRP installed and working. Still running (extremely poorly, all kinds of flakiness: loses cellular data connection constantly) the 10.1 CM I was running before I embarked upon this upgrade.
What should I do next?
Cheers,
Dave
If I'm not wrong, you're gonna need to s-off to get to the newest cm nightlies because of RUU. So first you're gonna need SuperCID. Someone correct me of I'm wrong but I'm gonna say you need to
fastboot oem writecid 11111111
and then head over to the S-Off thread. I wouldn't do this just yet, because I'm not 100% sure, but if someone could confirm that'd be wonderful.
RollTribe said:
If I'm not wrong, you're gonna need to s-off to get to the newest cm nightlies because of RUU. So first you're gonna need SuperCID. Someone correct me of I'm wrong but I'm gonna say you need to
fastboot oem writecid 11111111
and then head over to the S-Off thread. I wouldn't do this just yet, because I'm not 100% sure, but if someone could confirm that'd be wonderful.
Click to expand...
Click to collapse
That command may or may not work.
The good news is, if it doesn't, since you have root and aren't on a 2.14 hboot it's still super easy
If that command doesn't work, boot to the rom you're using, make sure usb debugging is enabled. If you're using CyanogenMod, you'll also have to give ADB root access in developer settings.
Open command prompt in the folder you have ADB and do
adb shell
su
echo -ne "11111111" | dd of=/dev/block/mmcblk0p5 bs=1 seek=20
then you should have superCID and should be able to S-OFF using the sticky in original android dev. section
when you type the su command, it may prompt you on your phone to allow su through adb so keep that in mind.
exad said:
That command may or may not work.
The good news is, if it doesn't, since you have root and aren't on a 2.14 hboot it's still super easy
If that command doesn't work, boot to the rom you're using, make sure usb debugging is enabled. If you're using CyanogenMod, you'll also have to give ADB root access in developer settings.
Open command prompt in the folder you have ADB and do
adb shell
su
echo -ne "11111111" | dd of=/dev/block/mmcblk0p5 bs=1 seek=20
then you should have superCID and should be able to S-OFF using the sticky in original android dev. section
when you type the su command, it may prompt you on your phone to allow su through adb so keep that in mind.
Click to expand...
Click to collapse
Excellent, you guys are the best! So, I have CID = 11111111, S-OFF.
What's the next step to getting back on the CM10 bandwagon? Or updating hboot? Or whatever I need to do next?
Cheers,
Dave
Run your carrier 3.17/3.18 ruu
Then flash twrp then flash cm10.1
Sent from my One X using xda app-developers app
exad said:
Run your carrier 3.17/3.18 ruu
Then flash twrp then flash cm10.1
Sent from my One X using xda app-developers app
Click to expand...
Click to collapse
Here's how I tried to flash the RUU (failing):
Code:
C:\Users\dkabal\Downloads\android\sdk\platform-tools>adb reboot-bootloader
* daemon not running. starting it now on port 5037 *
* daemon started successfully *
C:\Users\dkabal\Downloads\android\sdk\platform-tools>fastboot oem lock
...
(bootloader) Lock successfully...
(bootloader) TZ_HTC_SVC_DISABLE ret = -2228225 (0xFFDDFFFF)
FAILED (status read failed (Too many links))
finished. total time: 0.945s
This booted me into CM unexpectedly
Code:
C:\Users\dkabal\Downloads\android\sdk\platform-tools>adb reboot-bootloader
C:\Users\dkabal\Downloads\android\sdk\platform-tools>fastboot oem rebootRUU
...
(bootloader) Start Verify: 0
OKAY [ 0.059s]
finished. total time: 0.062s
C:\Users\dkabal\Downloads\android\sdk\platform-tools>fastboot flash zip OTA_EVIT
A_UL_JB_45_S_Cingular_US_3.18.502.6_0.24p.32.09.06_10.130.32.34_release_3061616b
cty3drvawwo01k.zip
sending 'zip' (645841 KB)...
OKAY [ 24.835s]
writing 'zip'...
(bootloader) zip header checking...
(bootloader) zip info parsing...
FAILED (remote: 24 parsing android-info fail)
finished. total time: 34.936s
C:\Users\dkabal\Downloads\android\sdk\platform-tools>fastboot flash zip OTA_EVIT
A_UL_JB_45_S_Cingular_US_3.18.502.6_0.24p.32.09.06_10.130.32.34_release_3061616b
cty3drvawwo01k.zip
sending 'zip' (645841 KB)...
FAILED (remote: 02 data length is too large)
finished. total time: 0.020s
C:\Users\dkabal\Downloads\android\sdk\platform-tools>fastboot flash zip OTA_EVIT
A_UL_JB_45_S_Cingular_US_3.18.502.6_0.24p.32.09.06_10.130.32.34_release_3061616b
cty3drvawwo01k.zip
sending 'zip' (645841 KB)...
FAILED (remote: 02 data length is too large)
finished. total time: 0.020s
C:\Users\dkabal\Downloads\android\sdk\platform-tools>fastboot flash zip OTA_EVIT
A_UL_JB_45_S_Cingular_US_3.18.502.6_0.24p.32.09.06_10.130.32.34_release_3061616b
cty3drvawwo01k.zip
sending 'zip' (645841 KB)...
FAILED (remote: 02 data length is too large)
finished. total time: 0.020s
For some reason, if I didn't reissue the below command, subsequent flashes would fail, even though I was still in the black screen with HTC logo mode
Code:
C:\Users\dkabal\Downloads\android\sdk\platform-tools>fastboot oem rebootRUU
...
(bootloader) Start Verify: 0
OKAY [ 0.060s]
finished. total time: 0.063s
C:\Users\dkabal\Downloads\android\sdk\platform-tools>fastboot flash zip OTA_EVIT
A_UL_JB_45_S_Cingular_US_3.18.502.6_0.24p.32.09.06_10.130.32.34_release_3061616b
cty3drvawwo01k.zip
sending 'zip' (645841 KB)...
OKAY [ 24.421s]
writing 'zip'...
(bootloader) zip header checking...
(bootloader) zip info parsing...
FAILED (remote: 24 parsing android-info fail)
finished. total time: 34.514s
C:\Users\dkabal\Downloads\android\sdk\platform-tools>fastboot flash zip OTA_EVIT
A_UL_JB_45_S_Cingular_US_3.18.502.6_0.24p.32.09.06_10.130.32.34_release_3061616b
cty3drvawwo01k.zip
sending 'zip' (645841 KB)...
FAILED (remote: 02 data length is too large)
finished. total time: 0.024s
C:\Users\dkabal\Downloads\android\sdk\platform-tools>fastboot oem rebootRUU
...
(bootloader) Start Verify: 0
OKAY [ 0.059s]
finished. total time: 0.060s
C:\Users\dkabal\Downloads\android\sdk\platform-tools>fastboot flash zip OTA_EVIT
A_UL_JB_45_S_Cingular_US_3.18.502.6_0.24p.32.09.06_10.130.32.34_release_3061616b
cty3drvawwo01k.zip
sending 'zip' (645841 KB)...
OKAY [ 24.132s]
writing 'zip'...
(bootloader) zip header checking...
(bootloader) zip info parsing...
FAILED (remote: 24 parsing android-info fail)
finished. total time: 34.234s
C:\Users\dkabal\Downloads\android\sdk\platform-tools>fastboot oem rebootRUU
...
(bootloader) Start Verify: 0
OKAY [ 0.059s]
finished. total time: 0.063s
C:\Users\dkabal\Downloads\android\sdk\platform-tools>fastboot flash zip OTA_EVIT
A_UL_JB_45_S_Cingular_US_3.18.502.6_0.24p.32.09.06_10.130.32.34_release_3061616b
cty3drvawwo01k.zip
sending 'zip' (645841 KB)...
OKAY [ 24.144s]
writing 'zip'...
(bootloader) zip header checking...
(bootloader) zip info parsing...
FAILED (remote: 24 parsing android-info fail)
finished. total time: 34.232s
C:\Users\dkabal\Downloads\android\sdk\platform-tools>fastboot reboot-bootloader
rebooting into bootloader...
OKAY [ 0.065s]
finished. total time: 0.070s
C:\Users\dkabal\Downloads\android\sdk\platform-tools>
So I'm not sure what to do next. Flashing RUU doesn't seem to work. bootloader says I'm still S-OFF (whatever that means), now "RELOCKED", CID still 11111111, and hboot still 1.09.
Thanks again for taking me through this,
Dave
All you need to do is run the RUU as was intended. It's an exe file. Plug in your phone and start the program.
Use RUU not OTA, it is easier.
OTA would require stock recovery to complete and much more care with how stock things are.
RollTribe said:
All you need to do is run the RUU as was intended. It's an exe file. Plug in your phone and start the program.
Click to expand...
Click to collapse
Thanks everyone! I'm back on the CM10.1 bandwagon (with OTA updates!) and this HTC One X is working better than ever.
For other folks, here were my mistakes and stumbling blocks:
Don't use utilities intended for the HTC One X (Tegra 3) on the HTC One XL (evita). This is how I accidentally changed my CID. This might seem obvious, but when you're checking around these forums, you can frequently end up in the wrong forum.
ADB commands work when the phone is in its OS.
If the setcid command line doesn't work, use the line from exad.
Don't try and use the RUU flashing procedure (with the OTA .zip file) to flash the firmware, use the .exe file, and just execute it.
I did not (and still don't really) understand the difference and utility of RUUs, S-On/S-Off, unlocking the bootloader, hboot, ROMs, SuperCID, radios, ADB and fastboot commands.
Back to using my now very functional HTC One X (it was on the verge of a tragic high-velocity intentional disassembly).
Cheers,
Dave
boulder_dave said:
[*]I did not (and still don't really) understand the difference and utility of RUUs, S-On/S-Off, unlocking the bootloader, hboot, ROMs, SuperCID, radios, ADB and fastboot commands.
Click to expand...
Click to collapse
There's a link in my signature that I took time to write up just for explaining these.
Fixed
And how will his hboot go to 2.14?
Sent from my HTC One XL using xda app-developers app
---------- Post added at 01:42 AM ---------- Previous post was at 01:39 AM ----------
Cause I'm confused to where you got the exe file from? Thanks
Sent from my HTC One XL using xda app-developers app
ZayedQamer.zq said:
And how will his hboot go to 2.14?
Sent from my HTC One XL using xda app-developers app
---------- Post added at 01:42 AM ---------- Previous post was at 01:39 AM ----------
Cause I'm confused to where you got the exe file from? Thanks
Sent from my HTC One XL using xda app-developers app
Click to expand...
Click to collapse
by running the RUU :silly: http://forum.xda-developers.com/showthread.php?t=1671237

VomerGuides [M7]: S-OFF, SuperCID, Firmware Upgrade & Custom Recovery

Welcome to VomerGuides: [M7 Edition]
Have an M8? There's a guide for that!
Hey folks!
Many of you will find this post similar to the ARHD posts I have made.
Based on several suggestions and PM's - I decided to make a separate thread in the hope that this will stop some repeated questions asked in multiple threads.
Following this guide will allow you to (in this sequence):
- Achieve S-OFF using revone
- Change your CID to SuperCID (allowing you to bypass regional ROM restrictions)
- Upgrade to the latest firmware (UL edition) without loosing any data on your SD card
- Install the latest TWRP recovery
Donations:
I do not believe that I should be charging for information sharing. However, having the physical hardware helps me improve this content and support you better as I do require hardware to test/work on for all my content and it's not always possible for me to find someone to borrow devices from.
If you would like to support my work donate to me via:
Thank you
Disclaimer & Copyrights:
I test everything before I share these guides - thus I know they work as intended. However, please proceed at your own risk as I do not take any liability for your devices.
Please do not copy contents of this guide without explicit permission from me. I like to maintain a set standard and quality of the information I share.
Please refrain from posting mirrors as I like to track downloads - I primarily use AndroidFileHost and they mirror files on multiple servers automatically.
I like to track downloads - so please use the official links provided in this guide.
Here is a mirror for all the files in case main links down:
- Firmwares
- Everything Else
Other useful files:
These files can be used to replace/add features in the latest firmware zips posted in this thread.
- Hboot v1.44: http://d-h.st/1zJ
- Touch panel Driver from firmware 2.24.401.1: http://d-h.st/lL4
- Flash-able Radio Collection: http://forum.xda-developers.com/showthread.php?t=2419699
- Going back to stock ROM: http://forum.xda-developers.com/showthread.php?t=2265618
Click to expand...
Click to collapse
Windows Users: It's a good idea to install the HTC drivers on your pc: http://d-h.st/4LL or use this toolkit to install the drivers.
READING & FOLLOWING EACH STEP IS KEY TO SUCCESS.
SECTION 0: SYSTEM PREPARATION:
First we need to get you ADB and fastboot
Windows Users, download this file and extract the folder called "adb" to your C: drive. Your path should look like this:
Code:
C:\adb\
Also, you will need to open a command prompt window using this method:
Code:
Go to the C:\adb\ folder - hold down SHIFT key and RIGHT-CLICK and select "Open command window here".
Mac/Linux users install ADB & fastboot using: Download
1. Extract the downloaded zip to your desktop
2. Open Terminal and type in:
Code:
su
cd Desktop/Android/ (note: Android is the directory extracted from zip file)
3. Now type
Code:
./ADB-Install-Mac.sh
Note: By using the method above, your adb and fastboot files are stored at this location on your Mac: /usr/bin/
SECTION 1: S-OFF & SUPERCID
Downloads Required:
- revone (hboot 1.44)
- rumrunner (hboot 1.5x)
Note: If you are running a 4.4 based ROM and do not want to downgrade to a lower version to use revone or rumrunner - try this tool to S-OFF
Note: revone (used for s-off) has been reported to work best with 4.2.2 roms. Please install a 4.2.2 ROM before attempting S-OFF.
Note: If you are using rumrunner - please follow the instructions to s-off provided on the rumrunner link above. Steps below are for revone only.
Note: Read these useful tips before attempting S-OFF
Mac/Linux users: Save this file to your Desktop
Windows users: Save this file to the C:/adb/ folder
Also, before continuing - make sure you have USB Debugging enabled on your phone (Settings -> Developer Options -> USB Debugging)
If you do not see "Developer Options", Go to Settings > About phone > Software > More > click on build number 10 times. This should enable that section.
Part 1
1. Push revone to your device:
Code:
Mac/Linux: adb push /Users/vomer/Desktop/revone /data/local/tmp/
Windows: adb push C:/adb/revone /data/local/tmp/
2. Open adb shell by writing:
Code:
adb shell
su
3. Write in the shell:
Code:
cd /data/local/tmp
4. Then write this:
Code:
chmod 755 revone
5. Next, write the following command:
Code:
./revone -P
6. Revone reported that I needed to reboot and try again. So I wrote :
Code:
reboot
[COLOR=Red][B]Note:[/B][/COLOR]
[B]Stuck with error: -1?[/B]
When initiating a reboot after "./revone -P" please press and hold the power button for 15 seconds.
To start the entire process from scratch please power off the device and wait 30 seconds, turn it on and continue to ."/revone -P".
7. Close your Command Prompt/Terminal window. Open it again and type:
Code:
adb shell
su
8. Write (to change directory in the phone):
Code:
cd /data/local/tmp
8a. Write the following command:
Code:
./revone -P (it will now say success and ask to reboot phone - do it by typing: reboot)
8b. Once rebooted - repeat steps 7 & 8
9. To get S-OFF & unlock, write the following command:
Code:
./revone -s 0 -u
10. revone will report success. Exit the shell:
Code:
exit (or just close terminal and open a new one)
11. Reboot into bootloader:
Code:
adb reboot bootloader
12. Check if the bootloader screen show's you as S-OFF (it should be in the in the first line under the "pink" highlighted text)
13. Reboot the phone
14. Start the adb shell, again:
Code:
adb shell
15. Change to the folder where revone is stored by typing:
Code:
cd /data/local/tmp
16. Request revone to reset tampered flag by typing:
Code:
./revone -t
17. Exit the adb shell by writing: exit (or just close terminal and open a new one)
18. Reboot to the bootloader by writing:
Code:
adb reboot bootloader
19. Phone should now be S-OFF and tampered flag should be gone
Now stay at this bootloader screen with your phone plugged in to the PC - and follow the steps in Part 2 below.
Part 2
Now lets get you SuperCID:
1. Open terminal/command prompt and type (copy paste command below or make sure there a eight 1's):
Code:
fastboot oem writecid 11111111
2. Reboot phone into bootloader mode (by typing: adb reboot bootloader) and verify CID#. It should look similar to this:
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
SECTION 2: FIRMWARE UPGRADE
FIRMWARE FAQ:
Q: Do I need S-OFF for firmware flashing?
A: YES!
Q: Do I NEED to update my firmware?
A: NO! But doing so ensures optimal phone performance.
Q: Does it matter when I flash the firmware (before or after new ROM install)
A: NO!
Q: Will updating the firmware erase my SD card or Apps?
A: NO! The firmware files provided in this guide take care of this for you so none of those get erased.
Q: If I only flash the ROM, will I get updated to the latest firmware?
A: NO!
Q: Can I install a U edition firmware on a UL edition phone?
A: YES, but you might loose the ability to connect to LTE or have some other incompatibilities.
FIRMWARE FLASHING:
Firmware Downloads (SD card will not be wiped using these files):
4.2.2 Base Firmwares:
- 2.17.401.1: http://d-h.st/PJv (Rename to firmware.zip after downloading)
- 2.24.401.1: http://d-h.st/WO9 (Rename to firmware.zip after downloading)
- 2.24.401.8: http://d-h.st/qPT (Rename to firmware.zip after downloading) *LATEST*
4.3 Base Firmwares:
- 3.06.1700.10: http://d-h.st/maA (Rename to firmware.zip after downloading)
- 3.09.401.1: http://d-h.st/PSE (Rename to firmware.zip after downloading)
- 3.17.401.2: http://d-h.st/bgE (Rename to firmware.zip after downloading)
- 3.22.1540.1: http://d-h.st/LLO (Rename to firmware.zip after downloading)
- 3.57.401.500 : http://d-h.st/z6g (Rename to firmware.zip after downloading)
- 3.62.401.1 : http://d-h.st/in6 (Rename to firmware.zip after downloading) *LATEST*
4.4 Base
- 4.06.1540.2 (Rename to firmware.zip after downloading)
- 4.06.1540.3 (Rename to firmware.zip after downloading)
- 4.19.401.8 (Rename to firmware.zip after downloading)
- 4.19.401.9 (Rename to firmware.zip after downloading)
- 4.19.401.11 (Rename to firmware.zip after downloading)
- 5.11.1540.9 (Rename to firmware.zip after downloading)
- 5.11.401.10 (Rename to firmware.zip after downloading)
- 6.06.401.1 (Rename to firmware.zip after downloading)
- 6.09.401.5 (Rename to firmware.zip after downloading)
- 6.09.401.10 (Rename to firmware.zip after downloading) *LATEST*
-----
Windows users, you need to do these steps first:
- move the file you downloaded and renamed (firmware.zip) to the C:\adb\ folder.
- next, in the C:\adb\ folder hold down SHIFT key and RIGHT-CLICK and select "Open command window here".
-----
First, plug in phone to PC and type this in terminal/command prompt:
Code:
adb reboot bootloader
-----
Let's start by checking current system details. Type:
Code:
fastboot getvar all
(bootloader) version: 0.5
(bootloader) version-bootloader: 1.44.0000 [COLOR=Red][B]< This is your bootloader version[/B][/COLOR]
(bootloader) version-baseband: 4A.16.3250.24 [COLOR=Red][B]< This is your radio version[/B][/COLOR]
(bootloader) version-cpld: None
(bootloader) version-microp: None
(bootloader) version-main: 1.29.666.17 [COLOR=Red][B]< This is your firmware version[/B][/COLOR]
(bootloader) version-misc: PVT SHIP S-OFF
(bootloader) serialno: <you don't need to know my serial#>
(bootloader) imei: <you don't need to know my IMEI>
(bootloader) meid: 00000000000000
(bootloader) product: m7_ul
(bootloader) platform: HBOOT-8064
(bootloader) modelid: PN0712000
(bootloader) cidnum: 11111111 [COLOR=Red][B]< This is your CID[/B][/COLOR]
(bootloader) battery-status: good
(bootloader) battery-voltage: 4077mV
(bootloader) partition-layout: Generic
(bootloader) security: off
(bootloader) build-mode: SHIP
(bootloader) boot-mode: FASTBOOT
Now type:
Code:
fastboot reboot-bootloader
After that, type:
Code:
fastboot oem rebootRUU
Note: You should see a silver HTC logo come up on your phone after executing this command.
Note: if this command freezes, just disconnect the USB cable and hold the power and volume down buttons until the device reboots. Then, repeat the steps above again.
Finally:
Code:
fastboot flash zip /Users/vomer/Desktop/firmware.zip
Windows users: your command will look something like this: fastboot flash zip C:\adb\firmware.zip
Got this:
Code:
sending 'zip' (71868 KB)...
OKAY [ 4.936s]
writing 'zip'...
(bootloader) zip header checking...
(bootloader) zip info parsing...
(bootloader) checking model ID...
(bootloader) checking custom ID...
(bootloader) start image[hboot] unzipping for pre-update check...
(bootloader) start image[hboot] flushing...
(bootloader) [RUU]WP,hboot,0
(bootloader) [RUU]WP,hboot,99
(bootloader) [RUU]WP,hboot,100
(bootloader) ...... Successful
FAILED (remote: 90 hboot pre-update! please flush image again immediately)
finished. total time: 6.410s
Repeated same command:
Code:
fastboot flash zip /Users/vomer/Desktop/firmware.zip
Got this:
Code:
sending 'zip' (71868 KB)...
OKAY [ 4.884s]
writing 'zip'...
(bootloader) zip header checking...
(bootloader) zip info parsing...
(bootloader) checking model ID...
(bootloader) checking custom ID...
(bootloader) start image[adsp] unzipping & flushing...
(bootloader) [RUU]WP,adsp,0
(bootloader) [RUU]WP,adsp,100
(bootloader) ...... Successful
(bootloader) start image[cir] unzipping & flushing...
(bootloader) ...... Successful
(bootloader) start image[rpm] unzipping & flushing...
(bootloader) [RUU]WP,rpm,0
(bootloader) [RUU]WP,rpm,100
(bootloader) ...... Successful
(bootloader) start image[sbl1-1] unzipping & flushing...
(bootloader) signature checking...
(bootloader) verified fail
(bootloader) ..... Bypassed
(bootloader) start image[sbl1-2] unzipping & flushing...
(bootloader) signature checking...
(bootloader) verified fail
(bootloader) ..... Bypassed
(bootloader) start image[sbl1-3] unzipping & flushing...
(bootloader) signature checking...
(bootloader) [RUU]WP,sbl1-3,0
(bootloader) [RUU]WP,sbl1-3,100
(bootloader) ...... Successful
(bootloader) start image[sbl2] unzipping & flushing...
(bootloader) [RUU]WP,sbl2,0
(bootloader) [RUU]WP,sbl2,100
(bootloader) ...... Successful
(bootloader) start image[sbl3] unzipping & flushing...
(bootloader) [RUU]WP,sbl3,0
(bootloader) [RUU]WP,sbl3,100
(bootloader) ...... Successful
(bootloader) start image[tp] unzipping & flushing...
(bootloader) ...... Successful
(bootloader) start image[tz] unzipping & flushing...
(bootloader) [RUU]WP,tz,0
(bootloader) [RUU]WP,tz,100
(bootloader) ...... Successful
(bootloader) start image[radio] unzipping & flushing...
(bootloader) [RUU]WP,radio,0
(bootloader) [RUU]WP,radio,26
(bootloader) [RUU]WP,radio,53
(bootloader) [RUU]WP,radio,79
(bootloader) [RUU]WP,radio,100
(bootloader) ...... Successful
OKAY [ 39.601s]
finished. total time: 44.485s
Note: On my phone's screen the green bar did not go to 100% of the bar ... but everything seemed ok so I moved on.
Last Step:
Code:
fastboot reboot
Then I went back to the bootloader mode (after the phone reboots successfully):
Code:
adb reboot bootloader
Checked if the update worked:
Code:
fastboot getvar all
(bootloader) version: 0.5
(bootloader) version-bootloader: 1.54.0000 [COLOR=Red][B]< Looks New![/B][/COLOR]
(bootloader) version-baseband: 4A.17.3250.14 [COLOR=Red][B]< Looks New![/B][/COLOR]
(bootloader) version-cpld: None
(bootloader) version-microp: None
(bootloader) version-main: 2.24.401.1 [COLOR=Red][B]< Looks New![/B][/COLOR]
(bootloader) version-misc: PVT SHIP S-OFF
(bootloader) serialno: you don't need to know my serial#
(bootloader) imei: you don't need to know my IMEI#
(bootloader) meid: 00000000000000
(bootloader) product: m7_ul
(bootloader) platform: HBOOT-8064
(bootloader) modelid: PN0712000
(bootloader) cidnum: 11111111 [COLOR=Red][B]< Oh Look! I'm Superman :) [/B][/COLOR]
(bootloader) battery-status: good
(bootloader) battery-voltage: 4331mV
(bootloader) partition-layout: Generic
(bootloader) security: off
(bootloader) build-mode: SHIP
(bootloader) boot-mode: FASTBOOT
(bootloader) commitno-bootloader: dirty-d16dc66985
(bootloader) hbootpreupdate: 11
(bootloader) gencheckpt: 0
all: Done!
finished. total time: 0.061s
SECTION 3: RECOVERY
Note: I personally prefer TWRP - so my guide below points to using TWRP.
If you like CWM, you can follow the same steps but with the latest CWM file.
----
Get latest TWRP: http://techerrata.com/browse/twrp2/m7ul
With your phone plugged into your PC, type in:
Code:
adb reboot bootloader
Once in bootloader mode, type:
Code:
Mac/Linux: fastboot flash recovery /Users/vomer/Desktop/openrecovery-twrp-2.6.1.0-m7.img
Windows: fastboot flash recovery C:\adb\openrecovery-twrp-2.6.1.0-m7.img
Then:
Code:
fastboot reboot
You are now the the latest version of TWRP.
----
That's it! Enjoy your new found freedom
finally you made own thread
descenpet said:
finally you made own thread
Click to expand...
Click to collapse
haha yes sir! got so many PM's to do it but I didn't want to half-ass it. Had some time today so decided to get it done the proper way!
It is necessary to have bootloader unlocked?
Sent from my HTC One using xda premium
Omg thank you so much I hope this will fix my sleep of death on cm roms issue.
Amazing and easy to follow. Thanks OP
vengadorhq said:
It is necessary to have bootloader unlocked?
Sent from my HTC One using xda premium
Click to expand...
Click to collapse
Yes, bootloader must be unlocked if your looking to do any customization!
STICKY THIS THREAD!!!
Great guide!
Wait... I need to re-lock my bootloader and remove root and go back to stock to get S-OFF? o.o?
aulterra said:
Wait... I need to re-lock my bootloader and remove root and go back to stock to get S-OFF? o.o?
Click to expand...
Click to collapse
What?
Sent from my HTC One using xda premium
Wonderful thread. It's of no use to me, but I tossed you a Thanks because when it concerns S-OFF, the simplest and most easy-to-follow guides make all the difference for frightened users.
Thanks!
descenpet said:
What?
Sent from my HTC One using xda premium
Click to expand...
Click to collapse
Well i'm rooted and have my bootloader unlocked from htcdev but i'm S-ON so do I need to relock to use revone to get S-OFF? Or not? Or relock and un root? Or?
aulterra said:
Well i'm rooted and have my bootloader unlocked from htcdev but i'm S-ON so do I need to relock to use revone to get S-OFF? Or not? Or relock and un root? Or?
Click to expand...
Click to collapse
No relock needed
Sent from my HTC One using xda premium
Devaster said:
No relock needed
Sent from my HTC One using xda premium
Click to expand...
Click to collapse
So I can Go ahead now and get S-OFF right now using revone even with an already unlocked bootloader?
aulterra said:
So I can Go ahead now and get S-OFF right now using revone even with an already unlocked bootloader?
Click to expand...
Click to collapse
Yes
Sent from my Nexus 7
vomer said:
Yes
Sent from my Nexus 7
Click to expand...
Click to collapse
Ok sounds great. Do you think that once I have S-OFF and Super CID that the Firmware update will fix my Sleep of Death issues on CM roms? codeworkx said the issue is from what he said a KGSL derp or something. The firmware update would update the gpu driver or update stuff that would effect the gpu driver?
Just wondering, thanks for the amazing guide btw, easiest i've seen so far to follow. Will be doing it tonight after work. Wanted to do it now but I decided not to since I need my phone charged as much as possible before I go to work today (have to get into work early and I didn't know until before so My phone was nearly flat xD)
aulterra said:
Ok sounds great. Do you think that once I have S-OFF and Super CID that the Firmware update will fix my Sleep of Death issues on CM roms? codeworkx said the issue is from what he said a KGSL derp or something. The firmware update would update the gpu driver or update stuff that would effect the gpu driver?
Just wondering, thanks for the amazing guide btw, easiest i've seen so far to follow. Will be doing it tonight after work. Wanted to do it now but I decided not to since I need my phone charged as much as possible before I go to work today (have to get into work early and I didn't know until before so My phone was nearly flat xD)
Click to expand...
Click to collapse
I am not sure on gpu drivers, but this should solve the issue if it is firmware related.
Sent from my Nexus 7
Superb guide! Thanks a lot bro!
Do you no how to get rid of the red writing in boot up splash screen. One thread I read is very confusing. Do I just flash the modified hboot zip?
Sent from my HTC One
Excellent guide, should definitely be stickied. Thanks Vomer :beer: :beer: :beer:
Sent from my HTC One using Tapatalk 2

[Q] Need help - Can´t change CID / Unable to downgrade HBoot 2.14

Hello,
i want to get S-Off and so tried severval ways to change the cid but had no luck.
My HOXL:
- Current ROM ViperXL 3.28
- Bootloader unlocked
- Recovery TWRP 2.6
(bootloader) version: 0.5
(bootloader) version-bootloader: 2.14.0000
(bootloader) version-baseband: 1.27a.32.45.15_2
(bootloader) version-cpld: None
(bootloader) version-microp: None
(bootloader) version-main: 3.17.162.7
(bootloader) version-misc: PVT SHIP S-ON
(bootloader) serialno: HTxxxxxxx
(bootloader) imei: xxxxxxxxx
(bootloader) product: evita
(bootloader) platform: HBOOT-8960
(bootloader) modelid: PJ8311000
(bootloader) cidnum: VODAP102
(bootloader) battery-status: good
(bootloader) battery-voltage: 4161mV
(bootloader) partition-layout: Generic
(bootloader) security: on
(bootloader) build-mode: SHIP
(bootloader) boot-mode: FASTBOOT
(bootloader) commitno-bootloader: dirty-97c9a06e
(bootloader) hbootpreupdate: 11
(bootloader) gencheckpt: 0
I tried:
- echo -ne "11111111" | dd of=/dev/block/mmcblk0p5 bs=1 seek=20 <- failed write protection
- Hex edit the mmcblk0p4 <- adb said ok, but cid hasn´t changed
- oneXChopper exploit (changed cid in ownage) and tried it
C:\>adb push oneXchopper /data/local/tmp/xpwn
2294 KB/s (1283460 bytes in 0.546s)
C:\>adb push busybox /data/local/tmp/busybox
2278 KB/s (811432 bytes in 0.347s)
C:\>adb push ownage /data/local/tmp/phase1.sh
96 KB/s (296 bytes in 0.003s)
C:\>adb shell chmod 755 /data/local/tmp/xpwn /data/local/tmp/busybox /data/local
/tmp/phase1.sh
C:\>adb shell ln -s /data/local/tmp/busybox /data/local/tmp/sed
link failed File exists
C:\>adb shell "/data/local/tmp/xpwn"
[+] This may take a few minutes.
[+] Success!
2+0 records in
2+0 records out
1024 bytes transferred in 0.026 secs (39384 bytes/sec)
2+0 records in
2+0 records out
1024 bytes transferred in 0.003 secs (341333 bytes/sec)
2+0 records in
2+0 records out
1024 bytes transferred in 0.002 secs (512000 bytes/sec)
C:\>adb reboot bootloader
error: device not found
C:\>fastboot oem readcid
< waiting for device >
...
(bootloader) cid: VODAP102
OKAY [ 0.027s]
finished. total time: 0.028s
If your CID is 11111111, then the exploit worked! Thanks to Dan Rosenberg for cr
eating the MotoChopper exploit and myusernam3 for modifying it for the One X!
C:\>pause
Drücken Sie eine beliebige Taste . . .
- jet (ubuntu desktop 12.04 from live CD and persitant USB stick on a Laptop and a PC)
it looks like i´m not able to brick the phone, instaed of boot into download mode the hoxl is boot right into the rom
JET - Jewel/Evita Toolkit v0.3.3beta
This tool will put backup critical partition data and then put your phone
into QHSUSB mode, where it will then downgrade your HBOOT.
Before running this script, you should have TWRP loaded onto your phone.
Plug your phone in via USB and ensure USB debugging is enabled.
Press Enter to continue...
Preparing...
This phase backs up /dev/block/mmcblk0p4 from your phone to this machine. In
addition, we will fetch your IMEI from the phone and use it to create an
additional partition 4 replacement to use as a failsafe. In the
event something goes wrong, you'll have a way to unbrick manually.
Please stand by...
Backing up mmcblk0p4 to /sdcard/bak4
Rebooting to bootloader...
Getting IMEI value...
Building failsafe P4 file...
Success. Rebooting phone.
Rebooting to recovery...
Waiting 45s for recovery...
Pulling /dev/block/mmcblk0p4 backup from phone...
Applying SuperCID mod to backup P4.
Success.
Phase 2
Now that we have backups, we're going to intentionally corrupt the
data on /dev/block/mmcblk0p4. This will cause the phone to enter
Qualcomm download mode (or QHSUSB if you prefer).
The process can't be stopped after this. Continue?
[Y]es or [N]o?y
Do NOT interrupt this process or reboot your computer.
Corrupting /dev/block/mmcblk0p4...
24 KB/s (1024 bytes in 0.041s)
Rebooting...
Success.
Your phone should now appear to be off, with no charging light on.
Press Enter to continue...
Device detection started...
Waking Device...
Even the manual way to "brick" the hoxl and downgrade the hboot failed.​
Is there any way to change the cid at this moment?
Thanks for helping.
No. That's the only way if youre not using an att or orange hoxl
Sent from my HTC One X using xda app-developers app
exad said:
No. That's the only way if youre not using an att or orange hoxl
Sent from my HTC One X using xda app-developers app
Click to expand...
Click to collapse
So i have to wait, until a new way to change cid or disable the write protection on mmcblk0p4 or S-Off without supercid
If you cant get jet tool to work, yes.
Sent from my HTC One X using xda app-developers app

Categories

Resources