Hey, i have a little problem and i would be grateful if someone would help me, my LeEco Le Max2 Bricked, the screen went blue , i turned it off and now it doesn't want to start at all or charge ( even the led is not functional)
I explored the forum and passed a few errors but i'm stuck at :
Total to be tansferd with <program> or <read> is 3.17 GB
22:18:04: INFO: Sending <configure>
_____
| ___|
| |__ _ __ _ __ ___ _ __
| __| '__| '__/ _ \| '__|
| |__| | | | | (_) | |
\____/_| |_| \___/|_|
22:18:04: {ERROR: XML not formed correctly. Expected a < character at loc 0}
_____
| ___|
| |__ _ __ _ __ ___ _ __
| __| '__| '__/ _ \| '__|
| |__| | | | | (_) | |
\____/_| |_| \___/|_|
22:18:04: {ERROR: 3. TAG not found or recognized}
_____
| ___|
| |__ _ __ _ __ ___ _ __
| __| '__| '__/ _ \| '__|
| |__| | | | | (_) | |
\____/_| |_| \___/|_|
22:18:04: {ERROR:
There is a chance your target is in SAHARA mode!!
There is a chance your target is in SAHARA mode!!
There is a chance your target is in SAHARA mode!!
This can mean
1. You forgot to send DeviceProgrammer first (i.e. QSaharaServer.exe -s 13rog_emmc_firehose_8994_lite.mbn)
2. OR, you did send DeviceProgrammer, but it has crashed and/or is not correct for this target
Regardless this program speaks FIREHOSE protocol and your target is speaking SAHARA protcol, so this will not work
}
Writing log to 'C:\Users\Aex\AppData\Roaming\Qualcomm\QFIL\port_trace.txt', might take a minute
Log is 'C:\Users\Aex\AppData\Roaming\Qualcomm\QFIL\port_trace.txt'
Download Fail:FireHose Fail FHLoader Failrocess fail
Finish Download
Thanks
do this steps :
https://www.gizmochina.com/2016/11/20/leeco-x820-max-2-super-unbrick-guide/
---------- Post added at 12:11 AM ---------- Previous post was at 12:11 AM ----------
do this steps :
https://www.gizmochina.com/2016/11/20/leeco-x820-max-2-super-unbrick-guide/
HTC-TYTN2 said:
do this steps :
https://www.gizmochina.com/2016/11/20/leeco-x820-max-2-super-unbrick-guide/
---------- Post added at 12:11 AM ---------- Previous post was at 12:11 AM ----------
do this steps :
https://www.gizmochina.com/2016/11/20/leeco-x820-max-2-super-unbrick-guide/
Click to expand...
Click to collapse
Why not this https://forum.xda-developers.com/le-max-2/how-to/guide-hard-brick-fix-qualcomm-hs-usb-t3492949 ?
valy_cta said:
Why not this https://forum.xda-developers.com/le-max-2/how-to/guide-hard-brick-fix-qualcomm-hs-usb-t3492949 ?
Click to expand...
Click to collapse
I didn't have any experience with flashing devices , when i said i didn't managed to make it work i was talking about your tutorial, i followed all your steps and i'm getting blocked by that error .
From the log I thought it was a corrupted file or something . Do you have any other idea why i'm getting that Firehose Error? I searched google and found 0 results in how i'm supposed to fix it
fratziweru said:
I didn't have any experience with flashing devices , when i said i didn't managed to make it work i was talking about your tutorial, i followed all your steps and i'm getting blocked by that error .
From the log I thought it was a corrupted file or something . Do you have any other idea why i'm getting that Firehose Error? I searched google and found 0 results in how i'm supposed to fix it
Click to expand...
Click to collapse
if the method can not unbrick your phone, you can try the firmware , hope help you .
https://www.needrom.com/download/le...ultilanguage-rom-unbrick-phone-qfil-fastboot/
Anybody know how to solve this problem?
/*invalid image type recieved*/
is_ack_succesfull : 1031 SAHARA_NAK_INVALID_IMAGE_TYPE
sahara protocol error
uploading image using sahara protocol failed
fish555 said:
Anybody know how to solve this problem?
/*invalid image type recieved*/
is_ack_succesfull : 1031 SAHARA_NAK_INVALID_IMAGE_TYPE
sahara protocol error
uploading image using sahara protocol failed
Click to expand...
Click to collapse
Its very possible that Windows security corrupted the Qfil and damaged this file, turn off antivirus, re-download Qfil and try again.
tsongming said:
Its very possible that Windows security corrupted the Qfil and damaged this file, turn off antivirus, re-download Qfil and try again.
Click to expand...
Click to collapse
Thanks for your answer
I turene off antivirus and brandmauer.
I think the problem must be in wrong image (i used kdz, img for d325 and my phone is 325f)
Also i red on forums that d325 may have two kind of processors.It's the reason why BoardDiag showed error
Anyone has 810 qfil ?
---------- Post added at 05:23 PM ---------- Previous post was at 05:19 PM ----------
Qualcomm 810 qfil which match with this methode?
leeco max x900
Hi,
I have bought a brand new LeTV (Leeco) Max 1 (x900). I installed twrp and tried to install custom rom. Unfortunately I didnt succeed and my phone is now only going into qualcomm 9008 mode. I have tried QFIL with the previous x800 service rom which supposedly puts it into a bootloop but you can still get it into fastboot mode. I have tried and tried but I constantly get the same sahara errors over and over. From what I have been reading, Qualcomms are unbrickable. So my question is where am I going wrong? The phone has a Qualcomm 810 in it. Do I need a specific file from LeEco that is currently unattainable? Please help. This is the flashest looking brick that I have ever owned...
fratziweru said:
Hey, i have a little problem and i would be grateful if someone would help me, my LeEco Le Max2 Bricked, the screen went blue , i turned it off and now it doesn't want to start at all or charge ( even the led is not functional)
I explored the forum and passed a few errors but i'm stuck at :
Total to be tansferd with <program> or <read> is 3.17 GB
22:18:04: INFO: Sending <configure>
_____
| ___|
| |__ _ __ _ __ ___ _ __
| __| '__| '__/ _ \| '__|
| |__| | | | | (_) | |
\____/_| |_| \___/|_|
22:18:04: {ERROR: XML not formed correctly. Expected a < character at loc 0}
_____
| ___|
| |__ _ __ _ __ ___ _ __
| __| '__| '__/ _ \| '__|
| |__| | | | | (_) | |
\____/_| |_| \___/|_|
22:18:04: {ERROR: 3. TAG not found or recognized}
_____
| ___|
| |__ _ __ _ __ ___ _ __
| __| '__| '__/ _ \| '__|
| |__| | | | | (_) | |
\____/_| |_| \___/|_|
22:18:04: {ERROR:
There is a chance your target is in SAHARA mode!!
There is a chance your target is in SAHARA mode!!
There is a chance your target is in SAHARA mode!!
This can mean
1. You forgot to send DeviceProgrammer first (i.e. QSaharaServer.exe -s 13rog_emmc_firehose_8994_lite.mbn)
2. OR, you did send DeviceProgrammer, but it has crashed and/or is not correct for this target
Regardless this program speaks FIREHOSE protocol and your target is speaking SAHARA protcol, so this will not work
}
Writing log to 'C:\Users\Aex\AppData\Roaming\Qualcomm\QFIL\port_trace.txt', might take a minute
Log is 'C:\Users\Aex\AppData\Roaming\Qualcomm\QFIL\port_trace.txt'
Download Fail:FireHose Fail FHLoader Failrocess fail
Finish Download
Thanks
Click to expand...
Click to collapse
fratziweru said:
Hey, i have a little problem and i would be grateful if someone would help me, my LeEco Le Max2 Bricked, the screen went blue , i turned it off and now it doesn't want to start at all or charge ( even the led is not functional)
I explored the forum and passed a few errors but i'm stuck at :
Total to be tansferd with <program> or <read> is 3.17 GB
22:18:04: INFO: Sending <configure>
_____
| ___|
| |__ _ __ _ __ ___ _ __
| __| '__| '__/ _ \| '__|
| |__| | | | | (_) | |
\____/_| |_| \___/|_|
22:18:04: {ERROR: XML not formed correctly. Expected a < character at loc 0}
_____
| ___|
| |__ _ __ _ __ ___ _ __
| __| '__| '__/ _ \| '__|
| |__| | | | | (_) | |
\____/_| |_| \___/|_|
22:18:04: {ERROR: 3. TAG not found or recognized}
_____
| ___|
| |__ _ __ _ __ ___ _ __
| __| '__| '__/ _ \| '__|
| |__| | | | | (_) | |
\____/_| |_| \___/|_|
22:18:04: {ERROR:
There is a chance your target is in SAHARA mode!!
There is a chance your target is in SAHARA mode!!
There is a chance your target is in SAHARA mode!!
This can mean
1. You forgot to send DeviceProgrammer first (i.e. QSaharaServer.exe -s 13rog_emmc_firehose_8994_lite.mbn)
2. OR, you did send DeviceProgrammer, but it has crashed and/or is not correct for this target
Regardless this program speaks FIREHOSE protocol and your target is speaking SAHARA protcol, so this will not work
}
Writing log to 'C:\Users\Aex\AppData\Roaming\Qualcomm\QFIL\port_trace.txt', might take a minute
Log is 'C:\Users\Aex\AppData\Roaming\Qualcomm\QFIL\port_trace.txt'
Download Fail:FireHose Fail FHLoader Failrocess fail
Finish Download
Thanks
Click to expand...
Click to collapse
This my be too late for you, but it can help people in the future with this same issue.
When using the QFIL program, you need to use the "prog_emmc_firehose_8994_lite.mbn" rather than the other .mbn (or elf) file as the program path, on my phone, I had 2 .elf files and use the wrong one, which caused me to have the same fault as you did. You must also use all program and patch files or you will get it to be in a state that it only gets to the point of the splash screen. The recovery/ bootloader is not available using the phones buttons and the device does not appear on the PC at all.
If somehow you got to that point. Leave your phone connected to the computer when it is stuck on the splash screen. In about 20 minutes ( yes, I know it is a long time.) the phone will reset with two options in recovery mode. The phone will also be picked up by the PC at this time.
Just enter cmd prompt in the adb file and enter "adb reboot edl" to bring your phone into edl mode. This will allow you to reinstall firmware using the QFIL program.
Related
stepw discovered a stack overflow vulnerability that affects ALL Trinity SPL versions up to now, I implemented an exploit for it, see details here.
The same bug is present in Hermes SPL versions >= 1.11, and all SPLs using HTC common base 1.51, so probably newer Breeze SPLs are vulnerable too.
Sadly for hermes users this bug can't be exploited the same way it's done on Trinity, this is the memory layout on Trinity:
Code:
0x80b00000 | xxxxxxxxxxx | \
.... | xxxxxxxxxxx | > wdata buffer
0x80b10000 | xxxxxxxxxxx | /
+-------------+
| . |
| . |
+-------------+
0x8c000000 | SPL-begins | \
.... | SPL SPL SPL | ME
.... | SPL SPL SPL | MO <--- how_far
.... | SPL SPL SPL | RY
.... | SPL SPL SPL | /
0x8c040000 | SPL-ends |
+-------------+
| . |
| . |
+-------------+
| . | \
0x8c08cb90 | . | s
.... | | t /\
.... | | a ||
.... | | c ||
.... | | k ||
0x8c08db90 | | /
| |
By doing recusrive 'ruustart' calls we can overflow the stack and set arbitrary bytes in 0x64 bytes buffer (size of command buffer in ruu mode).
We first try to detect how far the overflow should go, this varies on each SPL version. Then we put a known pattern on the stack and use the 'checksum' command to determine offsets of current stack top and size of stack frame of ruustart and normal command mode.
Then we load our unsigned code using wdata, of course we get an "invalid cert error" from bootloader, but the data we send is stored at 0x80b00000 (wdata buffer). We place here a modified IPL to skip loading SPL from NAND, and the custom SPL we want to load.
Then we calulate how many recursions we need to reach the spl end at 0x8c040000, the first recursions are padded with 0's as they are useless, only need them to overflow the stack, we put our shellcode here, the shellcode is a handler which executes the loader that resides in ram (0x80b00000) which copies patched IPL, SPL to RAM, disables ARM instruction caching and virtual addressing and branches to 0 offset to start IPL.
After placing the shellcode, we send the next ruustart calls with padding that contains branch instructions (relative jumps to the handler), we calculate how many calls we need based on target offset, initial stack offset and stack frame size.
Finally we need to jump to our patched code, to do this we call a function which has its entry point properly aligned with the overflown stack frame (we only control 0x64 bytes out of the frame size for ruustart which is tipically 0xe0), this also varies in each SPL version.
Now let's see the problem we're facing in hermes, this is the Hermes memory layout:
Code:
| . | \
| . | s /\
| | t ||
.... | | a ||
| | c ||
.... | | k
0x8c033b90 | | /
+-------------+
| . |
| . |
+-------------+
0x8c080000 | SPL-begins | \
.... | SPL SPL SPL | ME
.... | SPL SPL SPL | MO <--- how_far; we never reach here :(
.... | SPL SPL SPL | RY
.... | SPL SPL SPL | /
0x8c0c0000 | SPL-ends |
+-------------+
| . |
As you can see here, the stack grows up in the same direction as trinity, but the SPL code is placed below the stack so we can't overwrite it, thus we can't call a function that branches to our code.
So this is a call for developers & researchers, we need to find what else is between the stack and the ram top in hermes and see if there's something there that could be exploited, or if there's a pointer in ram that code branches to, we can exploit it by replacing the pointer.
You can use the Trinity exploit code with '-m hermes' hidden flag to test things on Hermes, feel free to modify / adapt the source for your tests on hermes.
Any ideas are welcome, have fun!
Damn pof your a real wacko and a genious, nice job man congrats!!
Re: spl overflow
Cool!
Congratz to stepw for this amazing research and exploit!
pof! GOOD work and nice code! Hope caffeine let you sleep some day!
Tonight we have to celebrate this with some beers!
heheh
thanks, keep up the good works, hope this software be develope as soon as posible so that our bricked phone be alive again.
I don't Understand
i'm using dopod 838 pro....where the memory layout mus edit?
Ok guys. I've started this thread to continue the technical discussion that was being carried on at @carloswii5 's thread [Guide]Unlock bootloader for Noobs P769. With that said, let's carry on...
Stock Dump Files
[ xloader dumps ]
V20H TMobile USA
[ uboot dumps ]
V20H TMobile USA
[ misc dumps and info ]
V20H TMobile USA - Stock recovery partition dump
V20H TMobile USA - omapconf tool device info dump
V20H TMobile USA - nv partition dump. IMEI and WIFI MAC address removed and replaced with markers. View 'edited_nv_README.txt' for details.
[ Links ]
LG Open Source - Source Code Download for P769
Findings
[ nv.img dump - mmcblk0p7 ]
Orange is the offset where the data starts
Blue is the data found
Code:
@ [B][COLOR=DarkOrange]0x1000[/COLOR][/B] - [COLOR=Blue]15 digit hex number[/COLOR] - IMEI number
@ [COLOR=DarkOrange][B]0x1A00[/B][/COLOR] - [COLOR=Blue]LGP769AT-01-V20h-310-260-AUG-14-2013+00[/COLOR] - Software version
@ [COLOR=DarkOrange][B]0x1C00[/B][/COLOR] - [COLOR=Blue]Series of 31 0x01's and 0x02's[/COLOR] - Unknown ATM
@ [COLOR=DarkOrange][B]0x1E00[/B][/COLOR] - [COLOR=Blue]12 digit hex number[/COLOR] - WIFI MAC address
@ [COLOR=DarkOrange][B]0x3C00[/B][/COLOR] - [COLOR=Blue]L6260_MODEM_SIC_01.1305.00\n[/COLOR] - Baseband version
@ [COLOR=DarkOrange][B]0x6403[/B][/COLOR] - [COLOR=Blue]0x69[/COLOR] - Apparently this value varies from device to device.
Compared V20H TMobile USA nv.bin with V20B EURO nv.bin.
Found differences listed below. This has been a combined effort between myself and @kuma82
At offset 0x1603:
Code:
=======================================
OFFSET | V20H | V20B | |
=======================================
0x1603 | 0x01 | 0x02 |
=======================================
Starting at offset 0x1615:
Code:
=======================================
OFFSET | V20H | V20B | |
=======================================
0x1615 | 0x02 | 0x02 |
0x161D | 0x02 | 0x01 |
0x1625 | 0x02 | 0x07 |
0x162D | 0x02 | 0x07 |
0x1635 | 0x02 | 0x07 |
0x163D | 0x02 | 0x07 |
0x1645 | 0x02 | 0x07 |
0x164D | 0x02 | 0x07 |
0x1655 | 0x02 | 0x07 |
0x165D | 0x02 | 0x07 |
0x1665 | 0x02 | 0x07 |
0x166D | 0x02 | 0x07 |
=======================================
NOTE: Each piece of data is separated by 8 bytes
Starting at offset 0x1C00:
Code:
=======================================
OFFSET | V20H | V20B | |
=======================================
0x1c00 | 0x01 | 0x01 |
0x1c01 | 0x01 | 0x01 |
0x1c02 | 0x01 | 0x01 |
0x1c03 | 0x01 | 0x02 |
0x1c04 | 0x02 | 0x02 |
0x1c05 | 0x01 | 0x01 |
0x1c06 | 0x01 | 0x01 |
0x1c07 | 0x01 | 0x01 |
0x1c08 | 0x02 | 0x02 |
0x1c09 | 0x01 | 0x02 |
0x1c0a | 0x01 | 0x01 |
0x1c0b | 0x01 | 0x01 |
0x1c0c | 0x01 | 0x01 |
0x1c0d | 0x02 | 0x02 |
0x1c0e | 0x02 | 0x02 |
0x1c0f | 0x01 | 0x01 |
0x1c10 | 0x01 | 0x01 |
0x1c11 | 0x01 | 0x01 |
0x1c12 | 0x01 | 0x02 |
0x1c13 | 0x01 | 0x01 |
0x1c14 | 0x01 | 0x01 |
0x1c15 | 0x01 | 0x01 |
0x1c16 | 0x01 | 0x01 |
0x1c17 | 0x02 | 0x02 |
0x1c18 | 0x02 | 0x02 |
0x1c19 | 0x02 | 0x02 |
0x1c1a | 0x02 | 0x02 |
0x1c1b | 0x02 | 0x02 |
0x1c1c | 0x02 | 0x02 |
0x1c1d | 0x01 | 0x01 |
0x1c1e | 0x02 | 0x02 |
=======================================
At offset 0x2200:
Code:
=======================================
OFFSET | V20H | V20B | |
=======================================
0x2200 | 0x00 | 0x01 |
=======================================
At offset 0x2202:
Code:
=======================================
OFFSET | V20H | V20B | |
=======================================
0x2202 | 0x00 | 0x10 |
=======================================
At offset 0x3400:
Code:
=======================================
OFFSET | V20H | V20B | |
=======================================
0x3400 | 0x0b | 0x00 |
=======================================
At offset 0x2600:
Code:
=======================================
OFFSET | V20H | V20B | |
=======================================
0x2600 | 0x00 | 0x94 |
=======================================
At offset 0x4800:
Code:
=======================================
OFFSET | V20H | V20B | |
=======================================
0x4800 | 0x00 | 0x11 |
0x4801 | 0x00 | 0x01 |
=======================================
At offset 0x4A01:
Code:
=======================================
OFFSET | V20H | V20B | |
=======================================
0x4A01 | 0x10 | 0x00 |
=======================================
At offset 0x6403:
Code:
=======================================
OFFSET | V20H | V20B | |
=======================================
0x6403 | 0x69 | 0x04 |
=======================================
And the last one.
Just wanted to say real quick that ill be having a 2nd shot at rooting and unlocking a co-workers l9 lets see what the real deal. My first attempt was good. Maybe it'll be one of two:
1. Like some one mentioned, maybe lg only gave a certain open time limited window and than relocked or what not.
2. Steps are being missed, rushed at highly anxious or hyped moments...lmao
Either way its worth another attempt.
Sent from my LGMS769 using XDA Premium 4 mobile app
What we need is a definitive tutorial on unlocking the bootloader. Some say wait 30 minutes while others say an hour. To root or not to root? Flash the radio.zip or paste it over while using offline flash? This is like one big hot mess...lol. :banghead:
Sent from my LG-P769 using XDA Premium 4 mobile app
---------- Post added at 11:25 PM ---------- Previous post was at 11:21 PM ----------
IMHO....LG closed that window long ago.
Sent from my LG-P769 using XDA Premium 4 mobile app
LaDY Vengeance said:
What we need is a definitive tutorial on unlocking the bootloader. Some say wait 30 minutes while others say an hour. To root or not to root? Flash the radio.zip or paste it over while using offline flash? This is like one big hot mess...lol. :banghead:
Sent from my LG-P769 using XDA Premium 4 mobile app
---------- Post added at 11:25 PM ---------- Previous post was at 11:21 PM ----------
IMHO....LG closed that window long ago.
Sent from my LG-P769 using XDA Premium 4 mobile app
Click to expand...
Click to collapse
Ill try and see if i can record my process.
Sent from my LGMS769 using XDA Premium 4 mobile app
Here's one for ya... Source code for various P769's is available from LG. What I just downloaded was V20H. It also includes the sources for the kernel. Here's the link .
shinobisoft said:
And the last one.
Click to expand...
Click to collapse
Have you had a chance to compare the nv.img?
Sent from my LGMS769 using XDA Premium 4 mobile app
kuma82 said:
Have you had a chance to compare the nv.img?
Sent from my LGMS769 using XDA Premium 4 mobile app
Click to expand...
Click to collapse
No I haven't. Actually just had to re-read your PM to find the link for it. LOL. I read the the first time with TapaTalk.
When I sold my phone I left of here :
http://forum.xda-developers.com/showthread.php?t=2016628
trying to get omap flash to dump some data, Im pretty sure I had it recognizing the phone.
This is only for the P769? you should add it to the title if it is. I have a P768 (a weird variant: P778g) with an unlocked bootloader, if i can extract something useful for you guys ill be happy, i want to help with this.
I'd like that, i'm having problems unlocking my p768, maybe it would help. After all, it's not an exclusive problem of the p769 variant.
Wish you all the best of luck.
Sent from my LG-P768 using xda app-developers app
mato_d007 said:
This is only for the P769? you should add it to the title if it is. I have a P768 (a weird variant: P778g) with an unlocked bootloader, if i can extract something useful for you guys ill be happy, i want to help with this.
Click to expand...
Click to collapse
No this discussion is not limited to the P769.
Sent from my LG-P769 using Tapatalk
Glad to have a new thread finally.
i found this in init. lge. usb. rc
isnt any posibility that this make something to block the unlock method?
# adb only USB configuration
# This should only be used during device bringup
# and as a fallback if the USB manager fails to set a standard configuration
# ADB only(631F) is supported from LG driver V3.8
# Set Mass Storage because U2 LG driver is Currently 3.7
on property:sys.usb.config=adb
write /sys/class/android_usb/android0/enable 0
write /sys/class/android_usb/android0/idVendor 1004
write /sys/class/android_usb/android0/idProduct 61A6
write /sys/class/android_usb/android0/bDeviceClass 239
write /sys/class/android_usb/android0/bDeviceSubClass 2
write /sys/class/android_usb/android0/bDeviceProtocol 1
write /sys/class/android_usb/android0/functions mass_storage,adb
write /sys/class/android_usb/android0/enable 1
start adbd
setprop sys.usb.state ${sys.usb.config}
this is in the root of the phone
Sent from my LG-P760 using XDA Premium 4 mobile app
andras7008 said:
i found this in init. lge. usb. rc
isnt any posibility that this make something to block the unlock method?
# adb only USB configuration
# This should only be used during device bringup
# and as a fallback if the USB manager fails to set a standard configuration
# ADB only(631F) is supported from LG driver V3.8
# Set Mass Storage because U2 LG driver is Currently 3.7
on property:sys.usb.config=adb
write /sys/class/android_usb/android0/enable 0
write /sys/class/android_usb/android0/idVendor 1004
write /sys/class/android_usb/android0/idProduct 61A6
write /sys/class/android_usb/android0/bDeviceClass 239
write /sys/class/android_usb/android0/bDeviceSubClass 2
write /sys/class/android_usb/android0/bDeviceProtocol 1
write /sys/class/android_usb/android0/functions mass_storage,adb
write /sys/class/android_usb/android0/enable 1
start adbd
setprop sys.usb.state ${sys.usb.config}
this is in the root of the phone
Sent from my LG-P760 using XDA Premium 4 mobile app
Click to expand...
Click to collapse
Looks like it's setting up the adb daemon on the device.
Sent from my LG-P769 using Tapatalk
I've been trying like crazy to get my friends new L9s bootloader unlocked with no luck. Then my lg offline tool got uninstalled and I couldnt get it working correct again. Well in one last attempt I loaded the stuff on my neighbors laptop (xp) and gave it one last attempt except I did a few things different and it WORKED MY FIRST TRY! Now I think it may of been the steps I skipped/ changed that made it work. Now to what I did. First I flashed v10g except this time I used the 760 version. I ran the bin file in the ICS rootguide folder instead of JB. I then proceeded to flashing v20b as shown in the video how-to except I DID NOT swap the bin file for root instead I added the radio while flashing. After it was complete I ran the bin file from ICS in rootguide again. I let the phone sit for 45 mins on data followed by 45 mins on wifi. Checked adb devices and it did not reconize it so I ran the JB bin file. Checked devices again, it reconized it. Typed the command and it rebooted right to the unlock screen! I should also add my first failed attempts was on windows 8 x64. Hope this helps someone else get it done! I almost gave up on it, luckly I did that one last try!
Sent from my LGMS769 using XDA Premium 4 mobile app
lwg45714 said:
I've been trying like crazy to get my friends new L9s bootloader unlocked with no luck. Then my lg offline tool got uninstalled and I couldnt get it working correct again. Well in one last attempt I loaded the stuff on my neighbors laptop (xp) and gave it one last attempt except I did a few things different and it WORKED MY FIRST TRY! Now I think it may of been the steps I skipped/ changed that made it work. Now to what I did. First I flashed v10g except this time I used the 760 version. I ran the bin file in the ICS rootguide folder instead of JB. I then proceeded to flashing v20b as shown in the video how-to except I DID NOT swap the bin file for root instead I added the radio while flashing. After it was complete I ran the bin file from ICS in rootguide again. I let the phone sit for 45 mins on data followed by 45 mins on wifi. Checked adb devices and it did not reconize it so I ran the JB bin file. Checked devices again, it reconized it. Typed the command and it rebooted right to the unlock screen! I should also add my first failed attempts was on windows 8 x64. Hope this helps someone else get it done! I almost gave up on it, luckly I did that one last try!
Sent from my LGMS769 using XDA Premium 4 mobile app
Click to expand...
Click to collapse
What root guide are you referring to?
lwg45714 said:
I've been trying like crazy to get my friends new L9s bootloader unlocked with no luck. Then my lg offline tool got uninstalled and I couldnt get it working correct again. Well in one last attempt I loaded the stuff on my neighbors laptop (xp) and gave it one last attempt except I did a few things different and it WORKED MY FIRST TRY! Now I think it may of been the steps I skipped/ changed that made it work. Now to what I did. First I flashed v10g except this time I used the 760 version. I ran the bin file in the ICS rootguide folder instead of JB. I then proceeded to flashing v20b as shown in the video how-to except I DID NOT swap the bin file for root instead I added the radio while flashing. After it was complete I ran the bin file from ICS in rootguide again. I let the phone sit for 45 mins on data followed by 45 mins on wifi. Checked adb devices and it did not reconize it so I ran the JB bin file. Checked devices again, it reconized it. Typed the command and it rebooted right to the unlock screen! I should also add my first failed attempts was on windows 8 x64. Hope this helps someone else get it done! I almost gave up on it, luckly I did that one last try!
Sent from my LGMS769 using XDA Premium 4 mobile app
Click to expand...
Click to collapse
You see! im almost completely positive some people are missing steps lol... Cant wait to get my hands on my coworkers l9 and try a 2nd time.
Sent from my LGMS769 using XDA Premium 4 mobile app
After CM12.1 install I'm unable to install the gapps pico. Here's the log from gapps install.
Notice the Total System Size is only 12mb... Using tk_gapps-modular-pico-5.1.1-20150920-signed.zip
Is there any way to increase the partition size or a quick fix? The smallest pico is about 50mb and it's still going to fail with only 12mb size.
# Begin TK GApps Install Log
--------------------------------------------------------------------------------
ROM Android Version |
ROM ID |
ROM Version | non-standard build.prop
Device Recovery | TWRP 2.8.6.0
Device Name | meliuslte
Device Model |
Device Type | phone
Device CPU |
getprop Density | 240
default.prop Density | 240
build.prop Density |
Display Density Used | 240dpi [default]
Install Type | Clean[Data Wiped]
Google Camera Installedπ | Clean
Google Keyboard Installedπ | Clean
FaceUnlock Compatible | false
Google Camera Compatible | true
Google Webview Compatible | true
Current GApps Version | NO GApps Installed
Curent TK GApps Package | NO GApps Installed
Installing GApps Version | 20150920
Installing GApps Type | pico
Config Type | exclude
Using gapps-config | /external_sd/Download/gapps-config.txt
Remove Stock/AOSP Browser | false[NO_Chrome]
Remove Stock/AOSP Email | false[NO_Gmail]
Remove Stock/AOSP Gallery | false[NO_Photos]
Remove Stock/AOSP Launcher | false[NO_GoogleNow]
Remove Stock/AOSP MMS App | false[NO_Hangouts]
Remove Stock/AOSP Pico TTS | false[NO_GoogleTTS]
Total System Size (KB) | 12052
Used System Space (KB) | 4108
Current Free Space (KB) | 7944
Additional Space Required (KB) | 74904 << See Calculations Below
--------------------------------------------------------------------------------
π Previously installed with TK GApps
# End TK GApps Install Log
INSTALLATION FAILURE: Your device does not have sufficient space available in
the system partition to install this GApps package as currently configured.
You will need to switch to a smaller GApps package or use gapps-config to
reduce the installed size.
# Begin GApps Size Calculations
---------------------------------------------------------
TYPE | DESCRIPTION | SIZE | TOTAL
| Current Free Space | 7944 | 7944
Remove | Existing GApps | + 0 | 7944
Remove | Obsolete Files | + 0 | 7944
Install | Core≤ | - 28744 | -20800
Install | GMSCore≤ | - 43656 | -64456
Install | calsync≥ | - 1232 | -65688
| Buffer Space≤ | - 9216 | -74904
---------------------------------------------------------
Additional Space Required | 74904
---------------------------------------------------------
≤ Required (ALWAYS Installed)
≥ Optional (may be removed)
# End GApps Size Calculations
# Begin User's gapps-config
Books
Chrome
ClooudPrint
Docs
Earth
ExchangeGoogle
Slides
Sheets
# End User's gapps-config
NOTE-1:
I'm not a developer or something even near to that. All information provided here is copied from different internet sources and according to best of my knowledge.
I have tried this on QMobile Z8 only. It's similar to Wiko Ridge 4G and Blu Life One (2015) in hardware specifications.
I'll not be responsible for any harm to you or your device. It works perfectly for me. You may try it on your own risk.
Save / backup your data before continuing. Whole device will be wiped.
NOTE-2:
If you have a custom recovery, install Stock ROM instead.
If you don't have a custom recovery, get here.
If your device is bricked and can't boot into recovery or bootloader mode(read here what it is), proceed.
REQUIREMENTS:
A PC with Windows and uninterrupted power supply. (I used Dell Inspiron 15R with Windows 8.1 and 10). Microsoft Visual C++ 2010 x86 Redistributable must also be installed.
A USB data cable.
Fully charged phone, soft-bricked at maximum i.e. no recovery, no boot accessible
STEPS:
Download QMobile Z8 Factory Firmware KitKat 4.4.4 (QMobile Z8_MP_KK_QMB_PK_07) or Lollipop 5.0.2 (QMobileZ8_MP_5.0_QMB_PK_06). Extract files to some easily accessible folder, say Stock Firmware.
Download and Install Qualcomm USB Drivers to your PC
Download and Install QPST (QFIL Flasher) to your PC. Official flasher from Wiko also works fine with all firmware. Just need to replace firmware folder.
Run QFIL. No Port Available should be displayed on UI top.
Select Build Type: Flat Build
Click on Load XML. Navigate to Stock Firmware folder and select rawprogram xml (1 or 2) file/s.
On next window, select patch xml file from Stock Firmware folder.
On Select Programmer, click on Browse and select prog_emmc_firehouse mbn file from Stock Firmware folder.
Power off your phone. (Re-insert battery being on safe side)
Press Upper and Lower Volume buttons and hold (key combinations for Download mode / Emergency mode on QMobile Z8; may differ for other devices)
Connect phone to PC through USB cable. Hold volume keys. Driver installation may take some time on first connect. No Port Available will be replaced by Qualcomm HS-USB QDLoader 9008 (COM XX). Now phone is connected to PC in Download Mode.
You may also check device connectivity in Device Manager. Qualcomm HS-USB QDLoader 9008 (COM4) will appear under COM PORTS section. If it doesn't, try reinstalling drivers or uninstall any drivers installed for other devices. Reinstall given drivers and then reboot PC.
Keep HOLDing keys.
Click on Download and wait for download progress to start. Then release keys and wait for installation to complete. DO NOT INTERRUPT FLASHING PROCESS OR IT MAY HARD BRICK YOUR PHONE LEAVING IT USELESS.
Once Download is finished, Exit QFIL, disconnect phone from PC and press power button to reboot if it doesn't reboot on its own.
Done. You have a newly purchased phone in your hands if all goes well.
i have an issue when i am flashing it
11:56:58: INFO: =======================================================
11:56:58: INFO: TARGET SAID: '[email protected] [email protected]'
11:56:58: INFO: TARGET SAID: 'start 131072, num 97347'
11:57:00: INFO: Overall to target 2.016 seconds (12.32 MBps)
11:57:00: INFO: {percent files transferred 1.32%}
11:57:02: INFO: Overall to target 4.000 seconds (11.88 MBps)
11:57:02: INFO: {percent files transferred 2.54%}
11:57:02: INFO: TARGET SAID: 'Read back verify failed at sector 1036513896,num sectors 131072'
11:57:02: INFO: TARGET SAID: 'Finished sector address 131072'
_____
| ___|
| |__ _ __ _ __ ___ _ __
| __| '__| '__/ _ \| '__|
| |__| | | | | (_) | |
\____/_| |_| \___/|_|
11:57:02: {ERROR: Please see log}
Writing log to 'C:\Users\umair\AppData\Roaming\Qualcomm\QFIL\COMPORT_4\port_trace.txt', might take a minute
Log is 'C:\Users\umair\AppData\Roaming\Qualcomm\QFIL\COMPORT_4\port_trace.txt'
Download Fail:FireHose Fail:FHLoader Failrocess fail
Finish Download
here is the log of the error
ayyaroayyas said:
11:56:58: INFO: =======================================================
11:56:58: INFO: TARGET SAID: '[email protected] [email protected]'
11:56:58: INFO: TARGET SAID: 'start 131072, num 97347'
11:57:00: INFO: Overall to target 2.016 seconds (12.32 MBps)
11:57:00: INFO: {percent files transferred 1.32%}
11:57:02: INFO: Overall to target 4.000 seconds (11.88 MBps)
11:57:02: INFO: {percent files transferred 2.54%}
11:57:02: INFO: TARGET SAID: 'Read back verify failed at sector 1036513896,num sectors 131072'
11:57:02: INFO: TARGET SAID: 'Finished sector address 131072'
_____
| ___|
| |__ _ __ _ __ ___ _ __
| __| '__| '__/ _ \| '__|
| |__| | | | | (_) | |
\____/_| |_| \___/|_|
11:57:02: {ERROR: Please see log}
Writing log to 'C:\Users\umair\AppData\Roaming\Qualcomm\QFIL\COMPORT_4\port_trace.txt', might take a minute
Log is 'C:\Users\umair\AppData\Roaming\Qualcomm\QFIL\COMPORT_4\port_trace.txt'
Download Fail:FireHose Fail:FHLoader Failrocess fail
Finish Download
here is the log of the error
Click to expand...
Click to collapse
any solutions for this???
Antarez96 said:
any solutions for this???
Click to expand...
Click to collapse
Most probably eMMC is dead. See this.
Hi, If this is a stupid noob question, then sorry.
I've got an xt1941-3 Motorola One. Figured out how to put LineageOS 17.1 on, and was looking at opengapps for the play store and google maps only. Since I literally only want the play store app and google play services for the location services, I wrote an exclude file for gapps that looks like this
Code:
# .gapps-config-deen
# Exclude all extras from pico package
# Pico+
CalSync # Install Google Calendar Sync (if Google Calendar is being installed)
DialerFramework # Install Dialer Framework (Android 6.0+)
GoogleTTS # Install Google Text-to-Speech Engine (Micro+ on 5.0-, Pico+ on 6.0+)
PackageInstallerGoogle # Install Package Installer (Android 6.0 only & Android 8.0+)
This results in all the packages except for the Google DialerFramework to be excluded. Looking at the gapps logs, I see That gapps is claiming that the AOSP DialerFramework "is not available on your ROM (anymore)"
The device was factory reset prior to having lineage flashed to ensure a clean install of gapps.
dalvik, system, data was all wiped before the lineage install, so not understanding how the aosp version is not there (anymore).
Code:
# Begin Open GApps Install Log
------------------------------------------------------------------
ROM Android version | 10
ROM Build ID | lineage_deen-eng 10 QQ3A.200605.001 eng.root.20200710.200251 test-keys
ROM Version increment | eng.root.20200710.200251
ROM SDK version | 29
ROM/Recovery modversion | 17.1-20200711-UNOFFICIAL-deen
Device Recovery | TWRP 3.2.3-0-08ee1e2f
Device Name | deen
Device Model | motorola one
Device Type | phone
Device CPU | arm64-v8a,armeabi-v7a,armeabi
Device A/B-partitions | true
Installer Platform | arm
ROM Platform | arm64
Display Density Used | unknown
Install Type | Clean[Data Wiped]
Google Camera already installed | Clean
VRMode Compatible | false
Google Camera Compatible | true
New Camera API Compatible | false
Google Pixel Features | false
Current GApps Version | No GApps Installed
Google Camera version | Legacy
Installing GApps Zipfile | /external_sd/Packages/open_gapps-arm64-10.0-pico-20201110.zip
Installing GApps Version | 20201110
Installing GApps Type | pico
Config Type | exclude
Using gapps-config | /external_sd/Packages/.gapps-config-deen
Remove Stock/AOSP Browser | false[NO_Chrome]
Remove Stock/AOSP Camera | false[NO_CameraGoogle]
[B] Remove Stock/AOSP Dialer | false[NO_DialerGoogle][/B]
Remove Stock/AOSP Email | false[NO_Gmail]
Remove Stock/AOSP Gallery | false[NO_Photos]
Remove Stock/AOSP Launcher | false[NO_GoogleNow/PixelLauncher]
Remove Stock/AOSP MMS App | false[NO_Messenger]
Remove Stock/AOSP Pico TTS | false[NO_GoogleTTS]
Ignore Google Contacts | false
[B] Ignore Google Dialer | true[NoRemove][/B]
Ignore Google Keyboard | false
Ignore Google Package Installer | false
Ignore Google NFC Tag | false
Ignore Google WebView | false
Total System Size (KB) | 2580272
Used System Space (KB) | 1338072
Current Free Space (KB) | 1225816
Post Install Free Space (KB) | 1064544 << See Calculations Below
------------------------------------------------------------------
# End Open GApps Install Log
[B]NOTE: The Stock/AOSP Dialer is not available on your
ROM (anymore), the Google equivalent will not be removed.[/B]
# Begin GApps Size Calculations
------------------------------------------------------------------
TYPE | DESCRIPTION | SIZE | TOTAL
| Current Free Space | 1225816 | 1225816
Remove | Existing GApps | + 0 | 1225816
Remove | Obsolete Files | + 0 | 1225816
Remove | cmsetupwizard | + 0 | 1225816
Remove | extservicesstock | + 96 | 1225912
Remove | extsharedstock | + 24 | 1225936
Remove | provision | + 0 | 1225936
Install | Core | - 152176 | 1073760
| Buffer Space | - 9216 | 1064544
------------------------------------------------------------------
Post Install Free Space | 1064544
------------------------------------------------------------------
# End GApps Size Calculations
# Begin User's gapps-config
CalSync
DialerFramework
GoogleTTS
PackageInstallerGoogle
# End User's gapps-config
What am I missing? Please help understand!
Edit: this may be related to this other problem encountered that I wrote about here: https://forum.xda-developers.com/motorola-one/how-to/problems-google-apps-infecting-fresh-t4191039