[Q] Need help - Can´t change CID / Unable to downgrade HBoot 2.14 - AT&T, Rogers HTC One X, Telstra One XL

Hello,
i want to get S-Off and so tried severval ways to change the cid but had no luck.
My HOXL:
- Current ROM ViperXL 3.28
- Bootloader unlocked
- Recovery TWRP 2.6
(bootloader) version: 0.5
(bootloader) version-bootloader: 2.14.0000
(bootloader) version-baseband: 1.27a.32.45.15_2
(bootloader) version-cpld: None
(bootloader) version-microp: None
(bootloader) version-main: 3.17.162.7
(bootloader) version-misc: PVT SHIP S-ON
(bootloader) serialno: HTxxxxxxx
(bootloader) imei: xxxxxxxxx
(bootloader) product: evita
(bootloader) platform: HBOOT-8960
(bootloader) modelid: PJ8311000
(bootloader) cidnum: VODAP102
(bootloader) battery-status: good
(bootloader) battery-voltage: 4161mV
(bootloader) partition-layout: Generic
(bootloader) security: on
(bootloader) build-mode: SHIP
(bootloader) boot-mode: FASTBOOT
(bootloader) commitno-bootloader: dirty-97c9a06e
(bootloader) hbootpreupdate: 11
(bootloader) gencheckpt: 0
I tried:
- echo -ne "11111111" | dd of=/dev/block/mmcblk0p5 bs=1 seek=20 <- failed write protection
- Hex edit the mmcblk0p4 <- adb said ok, but cid hasn´t changed
- oneXChopper exploit (changed cid in ownage) and tried it
C:\>adb push oneXchopper /data/local/tmp/xpwn
2294 KB/s (1283460 bytes in 0.546s)
C:\>adb push busybox /data/local/tmp/busybox
2278 KB/s (811432 bytes in 0.347s)
C:\>adb push ownage /data/local/tmp/phase1.sh
96 KB/s (296 bytes in 0.003s)
C:\>adb shell chmod 755 /data/local/tmp/xpwn /data/local/tmp/busybox /data/local
/tmp/phase1.sh
C:\>adb shell ln -s /data/local/tmp/busybox /data/local/tmp/sed
link failed File exists
C:\>adb shell "/data/local/tmp/xpwn"
[+] This may take a few minutes.
[+] Success!
2+0 records in
2+0 records out
1024 bytes transferred in 0.026 secs (39384 bytes/sec)
2+0 records in
2+0 records out
1024 bytes transferred in 0.003 secs (341333 bytes/sec)
2+0 records in
2+0 records out
1024 bytes transferred in 0.002 secs (512000 bytes/sec)
C:\>adb reboot bootloader
error: device not found
C:\>fastboot oem readcid
< waiting for device >
...
(bootloader) cid: VODAP102
OKAY [ 0.027s]
finished. total time: 0.028s
If your CID is 11111111, then the exploit worked! Thanks to Dan Rosenberg for cr
eating the MotoChopper exploit and myusernam3 for modifying it for the One X!
C:\>pause
Drücken Sie eine beliebige Taste . . .
- jet (ubuntu desktop 12.04 from live CD and persitant USB stick on a Laptop and a PC)
it looks like i´m not able to brick the phone, instaed of boot into download mode the hoxl is boot right into the rom
JET - Jewel/Evita Toolkit v0.3.3beta
This tool will put backup critical partition data and then put your phone
into QHSUSB mode, where it will then downgrade your HBOOT.
Before running this script, you should have TWRP loaded onto your phone.
Plug your phone in via USB and ensure USB debugging is enabled.
Press Enter to continue...
Preparing...
This phase backs up /dev/block/mmcblk0p4 from your phone to this machine. In
addition, we will fetch your IMEI from the phone and use it to create an
additional partition 4 replacement to use as a failsafe. In the
event something goes wrong, you'll have a way to unbrick manually.
Please stand by...
Backing up mmcblk0p4 to /sdcard/bak4
Rebooting to bootloader...
Getting IMEI value...
Building failsafe P4 file...
Success. Rebooting phone.
Rebooting to recovery...
Waiting 45s for recovery...
Pulling /dev/block/mmcblk0p4 backup from phone...
Applying SuperCID mod to backup P4.
Success.
Phase 2
Now that we have backups, we're going to intentionally corrupt the
data on /dev/block/mmcblk0p4. This will cause the phone to enter
Qualcomm download mode (or QHSUSB if you prefer).
The process can't be stopped after this. Continue?
[Y]es or [N]o?y
Do NOT interrupt this process or reboot your computer.
Corrupting /dev/block/mmcblk0p4...
24 KB/s (1024 bytes in 0.041s)
Rebooting...
Success.
Your phone should now appear to be off, with no charging light on.
Press Enter to continue...
Device detection started...
Waking Device...
Even the manual way to "brick" the hoxl and downgrade the hboot failed.​
Is there any way to change the cid at this moment?
Thanks for helping.

No. That's the only way if youre not using an att or orange hoxl
Sent from my HTC One X using xda app-developers app

exad said:
No. That's the only way if youre not using an att or orange hoxl
Sent from my HTC One X using xda app-developers app
Click to expand...
Click to collapse
So i have to wait, until a new way to change cid or disable the write protection on mmcblk0p4 or S-Off without supercid

If you cant get jet tool to work, yes.
Sent from my HTC One X using xda app-developers app

Related

unable to complete RUU and resotr to its original state

hi guys...
This was my previous thread..
http://forum.xda-developers.com/showthread.php?t=1463743
Now downloaded the RUU..
RUU_Saga_hTC_Asia_India_1.47.720.1_Radio_20.28I.30.085AU_3805.06.02.03_M_release_199605_signed_4..
hwen i run the RUU boot loader says security error but RUU says error 155.. here are the shots...
now please guide me to restore it to orignal state? i have SDK tools and Fastboot...
please help me
Try to reboot phone to fastboot mode and then run RUU. That should fix it.
i tried in fastboot mode but still error 155 occurs....i dun knw why im not able to restore the origial backed up image also..here are the contents of my backed up image....
After installing WP7 of MIUI based on..im not able to restore backed up one...but i can restore CM7.1.............
Please guide me .....
When i was going to return to stock rom, I first tried to flash a 1.47-RUU without success. I am not sure why, but the 2.10-RUU worked for me (but that is no choice for you, as I don't see for Asia it in the List of Shiped ROM Collection).
I have been coming from a 6.xxx HBOOT called engHBOOToverARX.img, you will find a link somewhere in the discontinued Tutorial here. If your phone was unbranded, you will find the original tutorial in the quotes. Basically I flashed this engHBOOT in fastboot (resulting in 6.xxx-HBOOT), than I run the RUU.
Thanks for the suggestion...
i ll try with 2.10-RUU AND LET U KNOW..
im my phone platfor info it says my product is HTC_SAGA and my brand is HTC_EUROPE what does this means?
Means shipped indian ruu RUU_Saga_hTC_Asia_India_1.47.720.1_Radio_20.28I.30 .085AU_3805.06.02.03_M_release_199605_signed_4 doent work for me?
this is what i have got after i do "fastboot flash zip rom.zip which was extracted from the above said RUU i.e RUU_Saga_S_HTC_Europe_2.10.401.8_Radio_20.4801.30.0822U_3822.10.08.04_M_release_225161_signed...
Now what?
please guide me
Which bootloader version are you currently stuck with? Are you able to access recovery etc?
fastboot getvar all - paste the results from that command here.
fastboot rebootRUU - try running the RUU again when you're in this mode.
I have a workaround, but it's not very good so i didn't post before, but you seem pretty desperate. Flash a pre-rooted stock rom via recovery(there's a thread in development section). Then, run gingerbreak to unroot. Try to find a rom from your region. If not, use the latest one. You won't get any updates.
Sent from my iPod touch using Tapatalk
hboot 2.00.002......YES IM ABLE TO ACCESS CWM RECOVERY AT ANY TIME AND RESTORE ONLY CUSTOM ROM BUT NOT ORIGNAL BACK UP DONE FOR THE FIRST TIME AFTER UNLOCK.....
suprisingly after installing CM7.1 i could restore the original back up but now im not able to...
ok i ll do what u said and give u feedback
my phone platfor info it says my product is HTC_SAGA and my brand is HTC_EUROPE what does this means?
You flashed a european rom, no problem. You want to sell it? Say you bought it from spain xD
Sent from my iPod touch using Tapatalk
fastboot getvar all ....................
< waiting for device >
(bootloader) version: 0.5
(bootloader) version-bootloader: 2.00.0002
(bootloader) version-baseband: 3822.10.08.04_M
(bootloader) version-cpld: None
(bootloader) version-microp: None
(bootloader) version-main: 1.27.405.6
(bootloader) serialno: MB129TJ00690
(bootloader) imei: 355067047867643
(bootloader) product: saga
(bootloader) platform: HBOOT-7230
(bootloader) modelid: PG8810000
(bootloader) cidnum: HTC__038
(bootloader) battery-status: good
(bootloader) battery-voltage: 3795mV
(bootloader) partition-layout: Generic
(bootloader) security: on
(bootloader) build-mode: SHIP
(bootloader) boot-mode: FASTBOOT
(bootloader) commitno-bootloader: ebd3df7d
(bootloader) hbootpreupdate: 12
(bootloader) gencheckpt:0
all done!
when i did fastboot rebootRUU
C:\android>fastboot rebootRUU
usage: fastboot [ <option> ] <command>
commands:
update <filename> reflash device from update.zip
flashall flash boot + recovery + system
flash <partition> [ <filename> ] write a file to a flash partition
erase <partition> erase a flash partition
getvar <variable> display a bootloader variable
boot <kernel> [ <ramdisk> ] download and boot kernel
flash:raw boot <kernel> [ <ramdisk> ] create bootimage and flash it
devices list all connected devices
continue continue with autoboot
reboot reboot device normally
reboot-bootloader reboot device into bootloader
help show this help message
options:
-w erase userdata and cache
-s <serial number> specify device serial number
-p <product> specify product name
-c <cmdline> override kernel commandline
-i <vendor id> specify a custom USB vendor id
-b <base_addr> specify a custom kernel base address
-n <page size> specify the nand page size. default:
2048
and i had RUU but error 155
what if i want to use it for myself with internet pass through as a must option...????
i have both...RUU_Saga_S_HTC_Europe_2.10.401.8_Radio_20.4801.30.0822U_3822.10.08.04_M_release_225161_signed ...and
RUU_Saga_hTC_Asia_India_1.47.720.1_Radio_20.28I.30.085AU_3805.06.02.03_M_release_199605_signed_4
why im not able to go back to the orignal sense UI 2.5/3????
Because that would be downgrading...........
Try this - http://forum.xda-developers.com/showthread.php?t=1399331
Use the 1.47 RUU this time.
C:\android>adb push zergRush /data/local/tmp
push: zergRush/zergRush -> /data/local/tmp/zergRush
1 file pushed. 0 files skipped.
195 KB/s (23060 bytes in 0.115s)
C:\android>adb push misc_version /data/local/tmp
push: misc_version/misc_version -> /data/local/tmp/misc_version
1 file pushed. 0 files skipped.
520 KB/s (589849 bytes in 1.107s)
C:\android>adb shell chmod 777 /data/local/tmp/zergRush
C:\android>adb shell chmod 777 /data/local/tmp/misc_version
C:\android>adb shell
# cd /data/local/tmp/
cd /data/local/tmp/
# ./zergRush
./zergRush
[**] Zerg rush - Android 2.2/2.3 local root
[**] (C) 2011 Revolutionary. All rights reserved.
[**] Parts of code from Gingerbreak, (C) 2010-2011 The Android Exploid Crew.
[+] Found a GingerBread ! 0x00000118
[*] Scooting ...
[*] Sending 149 zerglings ...
[+] Zerglings found a way to enter ! 0x10
[+] Overseer found a path ! 0x000161e0
[*] Sending 149 zerglings ...
[+] Overseer found a path ! 0x000161e0
[*] Sending 149 zerglings ...
[-] Zerglings did not leave interesting stuff
# adb shell /data/local/tmp/misc_version -s 1.27.405.6
adb shell /data/local/tmp/misc_version -s 1.27.405.6
adb: not found
# /data/local/tmp/misc_version -s 1.27.405.6
/data/local/tmp/misc_version -s 1.27.405.6
--set_version set. VERSION will be changed to: 1.27.405.6
Patching and backing up partition 17...
#
after this i ran 1.47 RUU but error 155 persists....at update signature it failed
i restored back to CM7.1 now agian.......
please guide me......................
im not able to downgrade to 0.98 .im not to s-off........not able restore to original back up ..............
RUUs don't work on official HBOOT (the latest ones anyway) unlocked. Didn't for me anyway. Relock again by typing "fastboot oem lock"
If you get Carrier ID error, use a goldcard.

[Q] First timer HTC User

I give up. I have a AT&T HTC ONE X and im rooted unlocked bootloader and superCID 111111111 and I tried to get S-Off but i get a file not found error. I want to change my cid back to the original att cid so i can run a 3.18 ruu. I heard running a 3.18 ruu with s-ON and superCID will Hard Brick your phone. How can i go back to normal before I tampered anything.
----TAMPERED----
----UNLOCKED----
HBOOT 2.14
Version 3.18
S-ON
CID 1111111
Which part of the s-off process gives you the file not found error?
Sent from my Evita
The very end where you put in the chmod command for soffbin3 it says can't chmod file or directory doesn't exsist. But when I use es file explorer to look in /Data/local/tmp the soffbin3 file is there
Sent from my HTC One X using xda app-developers app
BloatedDuck404 said:
The very end where you put in the chmod command for soffbin3 it says can't chmod file or directory doesn't exsist. But when I use es file explorer to look in /Data/local/tmp the soffbin3 file is there
Sent from my HTC One X using xda app-developers app
Click to expand...
Click to collapse
Soffbin has to go in your fastboot/adb folder. That's why it's not found
Sent from my HTC One XL using xda premium
BloatedDuck404 said:
The very end where you put in the chmod command for soffbin3 it says can't chmod file or directory doesn't exsist. But when I use es file explorer to look in /Data/local/tmp the soffbin3 file is there
Sent from my HTC One X using xda app-developers app
Click to expand...
Click to collapse
Did you extract the zip before putting it into the adb folder?
Sent from my Evita
wrong folder??? I just copied and paste the commands into command prompt. Ill try moving the zip
******EDIT*******There is not fastboot adb folder on the phone.----- Oh the computer. No I did not unzip. Ill try to unzip
You didn't follow the instructions properly then. Read it carefully, and follow the instructions precisely.
Sent from my Evita
BloatedDuck404 said:
wrong folder??? I just copied and paste the commands into command prompt. Ill try moving the zip
******EDIT*******There is not fastboot adb folder on the phone.----- Oh the computer. No I did not unzip. Ill try to unzip
Click to expand...
Click to collapse
Feel like an idiot but now Operation is not permitted.
Can you copy and paste the lines from the command prompt in here? It'll give us a better idea of what's going on.
Sent from my Evita
---------- Post added at 12:00 AM ---------- Previous post was at 12:00 AM ----------
Also, do you have adb debugging enabled in developer options?
Sent from my Evita
http://forum.xda-developers.com/showthread.php?p=33189590
This should help you.
Sent from my HTC One X using xda premium
BTW now error 99 if I retry from scratch
C:\Program Files (x86)\Minimal ADB and Fastboot>adb reboot bootloader
error: device not found
C:\Program Files (x86)\Minimal ADB and Fastboot>adb reboot bootloader
C:\Program Files (x86)\Minimal ADB and Fastboot>fastboot oem rebootRUU
...
(bootloader) Start Verify: 3
OKAY [ 0.093s]
finished. total time: 0.097s
C:\Program Files (x86)\Minimal ADB and Fastboot>fastboot flash zip PJ8312000-One
X.zip
sending 'zip' (36064 KB)...
OKAY [ 2.590s]
writing 'zip'...
(bootloader) adopting the signature contained in this image...
(bootloader) zip header checking...
(bootloader) zip info parsing...
FAILED (remote: 99 unknown fail)
finished. total time: 2.858s
C:\Program Files (x86)\Minimal ADB and Fastboot>fastboot oem boot
...
(bootloader) Boot/Recovery signature checking...
(bootloader) Boot/Recovery signature checking...
(bootloader) setup_tag addr=0x80400100 cmdline add=0xC02F50C4
(bootloader) TAG:Ramdisk OK
(bootloader) TAG:skuid 0x2FD04
(bootloader) TAG:hero panel = 0x4940047
(bootloader) TAG:engineerid = 0x1
(bootloader) TAG: PS ID = 0x0
(bootloader) TAG: Gyro ID = 0x1
(bootloader) Device CID is super CID
(bootloader) CID is super CID
(bootloader) Backup CID is CWS__001
(bootloader) setting->cid::CWS__001
(bootloader) serial number: HT2ACW300425
(bootloader) command line length =719
(bootloader) active commandline: reset_status=0 board_elite.disable_uart3
(bootloader) =0 diag.enabled=0 board_elite.debug_uart=0 userdata_sel=0 an
(bootloader) droidboot.emmc=true androidboot.pagesize=2048 skuid=0 ddt=20
(bootloader) ats=0 androidboot.lb=1 td.sf=1 td.td=1 td.ofs=328 td.prd=1
(bootloader) td.dly=0 td.tmo=300 hlog.ofs=628 un.ofs=694 imc_online_log=
(bootloader) 0 androidboot.efuse_info=FFSL androidboot.baseband=0.24p.32
(bootloader) .09.06 androidboot.cid=CWS__001 androidboot.devicerev=3 andr
(bootloader) oidboot.batt_poweron=good_battery androidboot.carrier=ATT an
(bootloader) droidboot.mid=PJ8310
(bootloader) aARM_Partion[0].name=misc
(bootloader) aARM_Partion[1].name=recovery
(bootloader) aARM_Partion[2].name=boot
(bootloader) aARM_Partion[3].name=system
(bootloader) aARM_Partion[4].name=local
(bootloader) aARM_Partion[5].name=cache
(bootloader) aARM_Partion[6].name=userdata
(bootloader) aARM_Partion[7].name=devlog
(bootloader) aARM_Partion[8].name=pdata
(bootloader) aARM_Partion[9].name=fat
(bootloader) aARM_Partion[A].name=extra
(bootloader) aARM_Partion.name=reserve
(bootloader) aARM_Partion[C].name=radio
(bootloader) aARM_Partion[D].name=adsp
(bootloader) aARM_Partion[E].name=dsps
(bootloader) aARM_Partion[F].name=wcnss
(bootloader) aARM_Partion[10].name=radio_config
(bootloader) aARM_Partion[11].name=modem_st1
(bootloader) aARM_Partion[12].name=modem_st2
(bootloader) aARM_Partion[13].name=reserve
(bootloader) partition number=20
(bootloader) Valid partition num=20
(bootloader) setting_get_bootmode() = 9
(bootloader) ram size = 0
(bootloader) TZ_HTC_SVC_SET_DDR_MPU ret = 0
(bootloader) smem 90005000 (phy 90005000): TZ_HTC_SVC_UPDATE_SMEM ret = 0
(bootloader) TZ_HTC_SVC_LOG_OPERATOR ret = 0
(bootloader) TZ_HTC_SVC_ENC ret = 0
(bootloader) TZ_HTC_SVC_DISABLE ret = 474079232 (0x1C41E000)
(bootloader) Start Verify: 3
(bootloader) jump_to_kernel: machine_id(3766), tags_addr(0x80400100), ker
(bootloader) nel_addr(0x80408000)
(bootloader) -------------------hboot boot time:635526 msec
FAILED (status read failed (Too many links))
finished. total time: 6.420s
C:\Program Files (x86)\Minimal ADB and Fastboot>adb shell chmod 744 /data/local/
tmp/soffbin3
Unable to chmod /data/local/tmp/soffbin3: Operation not permitted
Have a look on page 17 (I think) of the s-off thread, there is a fix for the error 99 problem posted by Chongodroid.
Sent from my Evita
kool im downloading viperXL 3.2.7 and ill follow his steps. Htc is so confusing but I love there devices. So risky. I cant thank you enough for taking time out of your day to help me
It's no problem at all. Let us know how it all goes.
Sent from my Evita
No go but I flashed a rom and got over my fear to do that. You know I got error 92 like it was suppose to do but since I did not unzip I couldnt proceed. BUT when I unzipped it and started over I got error 99. I want s-off so I can get rid of that red text (I see now that I flashed a rom),tampered, if I ever need to ruu withe superCID since im on 3.18 and ya know s-off stuff. But I guess my phone doesn't what to s-off. This is my first HTC android phone and Its been a scary ride. Thanks for your help anyway it was greatly appreciated. If ya got anymore suggestions ill try em. I stay with viper rom ATM.
Did you let viper boot after flashing? Or did you boot to the bootloader after flashing?
Sent from my Evita
No I rebooted to the bootloader. Didn't even let viper boot at all.
Sent from my HTC One X using xda app-developers app
And you still got error 99? Another trick to try after getting error 99 is to simulate a battery pull and start again.
To simulate a battery pull on this phone, hold power and volume down keys at the same time, the cap lights will start flashing, when the screen goes blank you can let go of the power key but keep holding volume down until it boots into the bootloader. Then start the s-off process again.
Sent from my Evita
OMFG YOU ARE THE BOMB IT WORKED!!!! Thanks for your help thanks soooooo much.
Awesome :thumbup:
Glad I could help
Sent from my Evita

[Q] I cannot get S-Off no matter what I do.

I have SuperCID and rooted. What am I doing wrong?
C:\androidSDK\sdk\platform-tools>adb reboot bootloader
* daemon not running. starting it now on port 5037 *
* daemon started successfully *
C:\androidSDK\sdk\platform-tools>fastboot getvar cid
< waiting for device >
cid: 11111111
finished. total time: 0.002s
C:\androidSDK\sdk\platform-tools>fastboot oem rebootRUU
...
(bootloader) Start Verify: 3
OKAY [ 0.082s]
finished. total time: 0.082s
C:\androidSDK\sdk\platform-tools>fastboot flash zip PJ8312000-OneX.zip
sending 'zip' (36064 KB)...
OKAY [ 2.859s]
writing 'zip'...
(bootloader) adopting the signature contained in this image...
FAILED (remote: 92 supercid! please flush image again immediately)
finished. total time: 2.992s
C:\androidSDK\sdk\platform-tools>fastboot oem boot
< waiting for device >
...
(bootloader) Boot/Recovery signature checking...
(bootloader) Boot/Recovery signature checking...
(bootloader) setup_tag addr=0x80400100 cmdline add=0xC02F50C4
(bootloader) TAG:Ramdisk OK
(bootloader) TAG:skuid 0x2FD0B
(bootloader) TAG:hero panel = 0x4940047
(bootloader) TAG:engineerid = 0x2
(bootloader) TAG: PS ID = 0x0
(bootloader) TAG: Gyro ID = 0x1
(bootloader) Device CID is super CID
(bootloader) CID is super CID
(bootloader) Backup CID is O2___102
(bootloader) setting->cid:2___102
(bootloader) serial number: HT26KW307917
(bootloader) commandline from head: console=ttyHSL0,115200,n8 androidboot
(bootloader) .hardware=qcom
(bootloader) command line length =790
(bootloader) active commandline: poweron_status=1 reset_status=0 board_el
(bootloader) ite.disable_uart3=0 diag.enabled=0 board_elite.debug_uart=0
(bootloader) userdata_sel=0 androidboot.emmc=true androidboot.pagesize=20
(bootloader) 48 skuid=0 ddt=20 ats=0 androidboot.lb=1 td.sf=1 td.td=1 td
(bootloader) .ofs=328 td.prd=1 td.dly=0 td.tmo=300 hlog.ofs=628 un.ofs=69
(bootloader) 4 imc_online_log=0 androidboot.efuse_info=FFSL androidboot.
(bootloader) baseband=1.27a.32.45.28 androidboot.cid=O2___102 androidboot
(bootloader) .devicerev=0 androidboot.batt_poweron=good_battery androidbo
(bootloader) ot.carrier=O2-DE and
(bootloader) aARM_Partion[0].name=misc
(bootloader) aARM_Partion[1].name=recovery
(bootloader) aARM_Partion[2].name=boot
(bootloader) aARM_Partion[3].name=system
(bootloader) aARM_Partion[4].name=local
(bootloader) aARM_Partion[5].name=cache
(bootloader) aARM_Partion[6].name=userdata
(bootloader) aARM_Partion[7].name=devlog
(bootloader) aARM_Partion[8].name=pdata
(bootloader) aARM_Partion[9].name=fat
(bootloader) aARM_Partion[A].name=extra
(bootloader) aARM_Partion.name=reserve
(bootloader) aARM_Partion[C].name=radio
(bootloader) aARM_Partion[D].name=adsp
(bootloader) aARM_Partion[E].name=dsps
(bootloader) aARM_Partion[F].name=wcnss
(bootloader) aARM_Partion[10].name=radio_config
(bootloader) aARM_Partion[11].name=modem_st1
(bootloader) aARM_Partion[12].name=modem_st2
(bootloader) aARM_Partion[13].name=reserve
(bootloader) partition number=20
(bootloader) Valid partition num=20
(bootloader) setting_get_bootmode() = 9
(bootloader) ram size = 0
(bootloader) TZ_HTC_SVC_SET_DDR_MPU ret = 0
(bootloader) smem 90005000 (phy 90005000): TZ_HTC_SVC_UPDATE_SMEM ret = 0
(bootloader) TZ_HTC_SVC_LOG_OPERATOR ret = 0
(bootloader) TZ_HTC_SVC_ENC ret = 0
(bootloader) TZ_HTC_SVC_DISABLE ret = 474079232 (0x1C41E000)
(bootloader) Start Verify: 3
(bootloader) jump_to_kernel: machine_id(3766), tags_addr(0x80400100), ker
(bootloader) nel_addr(0x80408000)
(bootloader) -------------------hboot boot time:11787 msec
FAILED (status read failed (Too many links))
finished. total time: 6.224s
C:\androidSDK\sdk\platform-tools>adb push soffbin3 /data/local/tmp/
579 KB/s (4751 bytes in 0.008s)
C:\androidSDK\sdk\platform-tools>adb shell chmod 744 /data/local/tmp/soffbin3
C:\androidSDK\sdk\platform-tools>adb shell su -c "/data/local/tmp/soffbin3"
C:\androidSDK\sdk\platform-tools>adb reboot bootloader
C:\androidSDK\sdk\platform-tools>
Click to expand...
Click to collapse
It all looks like it's going through fine, some people have reported it taking a few tries for it to stick though.
Sent from my Evita
timmaaa said:
It all looks like it's going through fine, some people have reported it taking a few tries for it to stick though.
Sent from my Evita
Click to expand...
Click to collapse
I tried again. Now I'm getting "99 unknown fail"
What I did was to unplug at the black HTC screen after I got the error 99 and power off and started over. That was the only way I could update the firmware.
Sent from my HTC One XL using XDA Premium 4 mobile app
nickfury27 said:
I tried again. Now I'm getting "99 unknown fail"
Click to expand...
Click to collapse
When you get error 99, simulate a battery pull and start again.
Sent from my Evita
nickfury27 said:
I tried again. Now I'm getting "99 unknown fail"
Click to expand...
Click to collapse
When it originally failed did you flash again after it said failed flush image again immediately?
Sent from my HTC One XL using xda app-developers app
nickfury27 said:
I tried again. Now I'm getting "99 unknown fail"
Click to expand...
Click to collapse
I actually got that many times doing it on mine. when that came up i RUUd and tried again. got the first error then pushed it again and got it.
I think this is what happened to me. Read somewhere to wipe the cache a few times. Finally, finally it worked. Maybe for you too.
Sent from my One X using xda app-developers app
I've tried it a million times and I still can't get S-off. What am I suppose to do??
Are your subsequent attempts giving you error 92 or error 99 when flashing the zip?
Sent from my Evita
timmaaa said:
Are your subsequent attempts giving you error 92 or error 99 when flashing the zip?
Sent from my Evita
Click to expand...
Click to collapse
First it gives error 92. And every attempt after that gives error 99. I have to simulate a battery pull to get 92 again.
You've definitely extracted the soffbin zip into your fastboot folder? What ROM are you running while attempting it?
Sent from my Evita
timmaaa said:
You've definitely extracted the soffbin zip into your fastboot folder? What ROM are you running while attempting it?
Sent from my Evita
Click to expand...
Click to collapse
Yes, I extracted soffbin. And I'm using Cyanoges Mod 10.2 Nightly.
You have given root access to adb in developer options?
You could try flashing a Sense ROM purely for this exercise, some people have claimed it works better on Sense. But for the record, I've gotten s-off on two devices, one on Sense and the other on aosp.
Sent from my Evita
timmaaa said:
You have given root access to adb in developer options?
You could try flashing a Sense ROM purely for this exercise, some people have claimed it works better on Sense. But for the record, I've gotten s-off on two devices, one on Sense and the other on aosp.
Sent from my Evita
Click to expand...
Click to collapse
Holy **** it worked! I've given root access to adb and that did it. I've been going crazy over this for a week. Thank you!
Glad to see you got it done.
Sent from my Evita
nickfury27 said:
Holy **** it worked! I've given root access to adb and that did it. I've been going crazy over this for a week. Thank you!
Click to expand...
Click to collapse
Can you write here for me how you did it in detail, please?
Amanbekov said:
Can you write here for me how you did it in detail, please?
Click to expand...
Click to collapse
Here is a detailed guide on how to get S-off. >>> http://forum.xda-developers.com/showthread.php?t=2155071
My problem was that I didn't enable the root access for ADB at developer options so at the last step I didn't grant root access. After enabling root access for ADB it asked for root rights at the last step and that did it.
nickfury27 said:
Here is a detailed guide on how to get S-off. >>> http://forum.xda-developers.com/showthread.php?t=2155071
My problem was that I didn't enable the root access for ADB at developer options so at the last step I didn't grant root access. After enabling root access for ADB it asked for root rights at the last step and that did it.
Click to expand...
Click to collapse
Many thanks to you, my friend! Unfortunately, I was bricked my AT&T HTC One X before I did all of that things and it can't load to Android, but it can load only in bootloader and in TWRP recovery, so I can't to do anything else with my brick =)) So, thank you very mach again and I'm sorry for my English! =)
That's not a brick if you can get to bootloader and recovery. Just flash a ROM.
Sent from my Evita

[Q] Want to install Cyanogenmod 10.1 on my AT&T ONE X

I am new to this HTC version of rooting and installing custom recovery on phones. I previously did this to my Galaxy S3 and it all worked fine. I wanted to make sure i am following the correct instructions to root and be able to install cyanogenmod on my one x. I currently have the android version 4.0.4. Please let me know if all the links i have are correct. Really appreciate the help guys!!
1. Root the HTC one X
[ROOT] HTC One X AT&T 2.20 Firmware - X-Factor root exploit link
2. Install SuperCID
[TOOL] OneClick SuperCID for Unlocking Bootloader link
3. S-OFF
[S-Off] Facepalm S-Off for HTC Devices One S, One XL, Droid DNA link
4. Install TWRP http://forum.xda-developers.com/showthread.php?t=1677447
5. Follow the ROM installation procedure
Thanks...
hari04415 said:
I am new to this HTC version of rooting and installing custom recovery on phones. I previously did this to my Galaxy S3 and it all worked fine. I wanted to make sure i am following the correct instructions to root and be able to install cyanogenmod on my one x. I currently have the android version 4.0.4. Please let me know if all the links i have are correct. Really appreciate the help guys!!
1. Root the HTC one X
[ROOT] HTC One X AT&T 2.20 Firmware - X-Factor root exploit link
2. Install SuperCID
[TOOL] OneClick SuperCID for Unlocking Bootloader link
3. S-OFF
[S-Off] Facepalm S-Off for HTC Devices One S, One XL, Droid DNA link
4. Install TWRP http://forum.xda-developers.com/showthread.php?t=1677447
5. Follow the ROM installation procedure
Thanks...
Click to expand...
Click to collapse
Good steps but after s-off you should run the 3.18 ruu. Then flash twrp and your choosen rom.
DvineLord said:
Good steps but after s-off you should run the 3.18 ruu. Then flash twrp and your choosen rom.
Click to expand...
Click to collapse
Could you tell me how to install 3.18 RUU...any link would be much appreciated..thanks
Just download the 3.18 RUU, connect your phone to the PC in fastboot mode and run the RUU exe program. Just make sure you don't have HTC Sync Manager installed, make sure no other programs are running, and make sure screen saver/hibernation is turned off. You must have s-off before you run the RUU though.
Sent from my Evita
Thanks i will try it now!
Would I have to relock the boot loader before running the ruu? Fastboot OEM lock??
Sent from my HTC One XL using XDA Premium 4 mobile app
No, as long as you get s-off first you don't need to relock the bootloader.
Sent from my Evita
timmaaa said:
No, as long as you get s-off first you don't need to relock the bootloader.
Sent from my Evita
Click to expand...
Click to collapse
timmaaa, I am using a mac and i am in processing of finishing root method from the step 1 i posted earlier. I got the unlock_code.bin from htcdev but not sure what to do now. Do i go to terminal and use the fastboot from there or do i have to use the super CID link to unlock the bootloader?
You just need to follow the instructions at the htcdev, it's outlined pretty specifically.
Sent from my Evita
timmaaa said:
You just need to follow the instructions at the htcdev, it's outlined pretty specifically.
Sent from my Evita
Click to expand...
Click to collapse
I followed the step 1 correctly. Now in bootloader it says unlocked but when i try to run SuperCID it doesnt work. Tried both on mac and windows.
The 2.20 root exploit should give you SuperCID in order to unlock the bootloader. What does it say when you give the following command?
Code:
fastboot oem readcid
Sent from my Evita
timmaaa said:
The 2.20 root exploit should give you SuperCID in order to unlock the bootloader. What does it say when you give the following command?
Code:
fastboot oem readcid
Sent from my Evita
Click to expand...
Click to collapse
it says 1111111
I have installed the SuperSU and repeated the procedure. This time around i was able to finish the procedure but i still have S-ON. Please help me get the S-OFF
Here is my cmd prompt
C:\Program Files (x86)\Minimal ADB and Fastboot>adb devices
List of devices attached
HT28SW301846 device
C:\Program Files (x86)\Minimal ADB and Fastboot>adb reboot bootloader
C:\Program Files (x86)\Minimal ADB and Fastboot>fastboot oem rebootRUU
...
(bootloader) Start Verify: 3
OKAY [ 0.063s]
finished. total time: 0.063s
C:\Program Files (x86)\Minimal ADB and Fastboot>fastboot flash zip PJ8312000-One
X.zip
sending 'zip' (36064 KB)...
OKAY [ 2.652s]
writing 'zip'...
(bootloader) adopting the signature contained in this image...
FAILED (remote: 92 supercid! please flush image again immediately)
finished. total time: 2.753s
C:\Program Files (x86)\Minimal ADB and Fastboot>fastboot oem boot
...
(bootloader) Boot/Recovery signature checking...
(bootloader) Boot/Recovery signature checking...
(bootloader) setup_tag addr=0x80400100 cmdline add=0xC02F9E3C
(bootloader) TAG:Ramdisk OK
(bootloader) TAG:skuid 0x2FD04
(bootloader) TAG:hero panel = 0x4940047
(bootloader) TAG:engineerid = 0x1
(bootloader) TAG: PS ID = 0x0
(bootloader) TAG: Gyro ID = 0x1
(bootloader) Device CID is super CID
(bootloader) CID is super CID
(bootloader) Backup CID is CWS__001
(bootloader) setting->cid::CWS__001
(bootloader) serial number: HT28SW301846
(bootloader) commandline from head: console=ttyHSL0,115200,n8
(bootloader) command line length =699
(bootloader) active commandline: reset_status=0 board_elite.disable_uart3
(bootloader) =0 diag.enabled=0 board_elite.debug_uart=0 userdata_sel=0 an
(bootloader) droidboot.emmc=true androidboot.pagesize=2048 skuid=0 ddt=20
(bootloader) ats=0 androidboot.lb=1 td.td=1 td.sf=1 td.ofs=328 td.prd=1
(bootloader) td.dly=0 td.tmo=300 imc_online_log=0 androidboot.efuse_inf
(bootloader) o=FFSL androidboot.baseband=0.19as.32.09.11_2 androidboot.ci
(bootloader) d=CWS__001 androidboot.devicerev=3 androidboot.batt_poweron=
(bootloader) good_battery androidboot.carrier=ATT androidboot.mid=PJ83100
(bootloader) 00 androidboot.keyca
(bootloader) aARM_Partion[0].name=misc
(bootloader) aARM_Partion[1].name=recovery
(bootloader) aARM_Partion[2].name=boot
(bootloader) aARM_Partion[3].name=system
(bootloader) aARM_Partion[4].name=local
(bootloader) aARM_Partion[5].name=cache
(bootloader) aARM_Partion[6].name=userdata
(bootloader) aARM_Partion[7].name=devlog
(bootloader) aARM_Partion[8].name=pdata
(bootloader) aARM_Partion[9].name=fat
(bootloader) aARM_Partion[A].name=extra
(bootloader) aARM_Partion.name=radio
(bootloader) aARM_Partion[C].name=adsp
(bootloader) aARM_Partion[D].name=dsps
(bootloader) aARM_Partion[E].name=wcnss
(bootloader) aARM_Partion[F].name=radio_config
(bootloader) aARM_Partion[10].name=modem_st1
(bootloader) aARM_Partion[11].name=modem_st2
(bootloader) partition number=18
(bootloader) Valid partition num=18
(bootloader) TZ_HTC_SVC_SET_DDR_MPU ret = 0
(bootloader) smem 90005000 (phy 90005000): TZ_HTC_SVC_UPDATE_SMEM ret = 0
(bootloader) TZ_HTC_SVC_LOG_OPERATOR ret = 0
(bootloader) TZ_HTC_SVC_ENC ret = 0
(bootloader) TZ_HTC_SVC_DISABLE ret = 474079232 (0x1C41E000)
(bootloader) jump_to_kernel: machine_id(3766), tags_addr(0x80400100), ker
(bootloader) nel_addr(0x80408000)
(bootloader) -------------------hboot boot time:15253 msec
FAILED (status read failed (Too many links))
finished. total time: 7.362s
C:\Program Files (x86)\Minimal ADB and Fastboot>adb push soffbin3 /data/local/tm
p/
356 KB/s (4751 bytes in 0.012s)
C:\Program Files (x86)\Minimal ADB and Fastboot>adb shell chmod 744 /data/local/
tmp/soffbin3
C:\Program Files (x86)\Minimal ADB and Fastboot>adb shell su -c "/data/local/tmp
/soffbin3"
C:\Program Files (x86)\Minimal ADB and Fastboot>adb reboot bootloader
C:\Program Files (x86)\Minimal ADB and Fastboot>
You need to stop posting the same thing in multiple places, duplicating posts is against the rules. I've answered you in the other thread.
Sent from my Evita

HTC one mini - stuck in fastboot / unlock without victory

Hello ladies and gentlemen,
i got a problem with an (no surprise) HTC One Mini.
I try to fix it for a friend - but so far without victory.
problem description
The phone is constantly in Fastboot-Mode when turned on.
*** LOCKED ***
M4_UL PVT SHIP S-ON RL
HBOOT-2.22.0000
OS-4.09.206.4
eMMc-boot 1024MB
Aug 13 2015, 23:05:25.0
FASTBOOT [USB]*
<VOL UP> to previous item
<VOL DOWN> to next item
<POWER> to select item
BOOTLOADER
REBOOT
REBOOT BOOTLOADER
POWER DOWN
*when connected to the pc
The Bootloader Menu (Recovery, Factory Reset, Clear Storage) are without any function - just sending me back to fastboot.
Image CRC output:
Code:
rpm: 0x0
sbl1: 0x0
sbl2: 0x0
sbl3: 0x0
tz: 0x0
radio: 0x0
hboot: 0x0
boot: 0x0
recovery: 0x0
system: 0x0
Tries to unlock the device via htcdev did not work up to now [the popup on the screen never pops up ]
Here some Code Snippets:
*fastboot getvar all - output:
Code:
C:\adb>fastboot getvar all
(bootloader) version: 0.5
(bootloader) version-bootloader: 2.22.0000
(bootloader) version-baseband: N/A
(bootloader) version-cpld: None
(bootloader) version-microp: None
(bootloader) version-main: 4.09.206.4
(bootloader) version-misc: PVT SHIP S-ON
(bootloader) serialno: HT37W*******
(bootloader) imei: 3558********
(bootloader) meid:
(bootloader) product: m4_ul
(bootloader) platform: HBOOT-8930
(bootloader) modelid: PO5820000
(bootloader) cidnum: O2___102
(bootloader) battery-status: good
(bootloader) battery-voltage: 4237mV
(bootloader) partition-layout: Generic
(bootloader) security: on
(bootloader) build-mode: SHIP
(bootloader) boot-mode: FASTBOOT
(bootloader) commitno-bootloader: dirty-0e1af350
(bootloader) hbootpreupdate: 11
(bootloader) gencheckpt: 0
all: Done!
finished. total time: 0.131s
*fastboot flash unlocktoken Unlock_code.bin - output:
Code:
C:\adb>fastboot flash unlocktoken Unlock_code.bin
target reported max download size of 800227328 bytes
sending 'unlocktoken' (0 KB)...
OKAY [ 0.169s]
writing 'unlocktoken'...
(bootloader) unlock token check successfully
OKAY [ 0.010s]
finished. total time: 0.182s
Used tools:
PC - Windows 10
15 seconds ADB Installer v1.3
Samsung Galaxy S6 - Data/Power-Cable
Feel Free to ask for more information - ill try to provide.
Thank you in advance!
Edit: No Ideas?
got exactly the same problem here, also an HTC One Mini from O2...
I have the same problem and you cannot flash as I get error 171 anyone got any idea on how to get these phones flashed?
HTC mini one stopped working. Won't turn on or off and screen even looks like it's come away from the sides...help please
Temporary fix for the FastBoot loop problem: Search the HTC One X forums for "SOLVED: Stuck in fastboot with low battery. Use this BATCH file! by floepie" - all credit to floepie
https://forum.xda-developers.com/showthread.php?p=26212322
The script continually reboots your phone, which allows it to slowly charge (plug it directly into the motherboard, good USB cable, and non-essential USB peripherals unplugged for max amperage). Eventually it will boot normally, though in my experience, it's taken hours. Not sure if it's actually the battery charging or just random luck with the number of reboots. 80% battery and 4.1-4.2V might be the magic numbers. This probably won't work if you had a bad flash or other preexisting condition.
This ridiculous problem now happens to me every time my phone dies or I have to reboot it. I have the recommended TWRP, s-off, unlocked, no tampered message, etc but pressing recovery just reboots it into fastboot again. I'll probably try re-flashing stuff or just use this method until it's completely dead. Bought it in 2014 when it was >$200 unlocked but I excessively baby my devices; 3 years is good in cell phone years, but I was expecting more.
I really like this phone, but it's getting hard to love between this, the pink camera issues, and speakerphone problem with the older InsertCoin (my preference). Good size, snappy Sense interface, and decent battery life when used with a nice, slim kernel and rom.
Windows - Put the following into a .bat file in your adb directory:
Code:
@echo off
:start
fastboot getvar battery-voltage
fastboot reboot-bootloader
ping /n 6 localhost >nul
goto start
Linux/Mac - Put the following into a .sh file in your adb directory (untested):
Code:
#!/bin/sh
while true
do
./fastboot getvar battery-voltage
./fastboot reboot-bootloader
sleep 5
Edit: Latest numbers are 2 hours of rebooting to get to 4110mV / 82% reported battery (started sub 4V after a phone freeze/reboot)

Categories

Resources