Question [HELP] Soft-bricked device after attempting to rollback to RUI - Realme GT Master Edition

So, I was in Android 13 when I installed a custom ROM. Today, I felt like trying to go back to RUI. I've successfully done it before during the Android 12 days, but this time seems like things changed. I used the same method I was using with OppoRealme-OFP-Flash_1.0.exe but this time the super.img file flashes very fast. When I attempt to update the current slot, it takes forever and then brings an error message (too many links). I have been trying everything the whole night. I also tried flashing the .img files one by one and almost hard-bricked the phone. Now, I am stuck in the bootloader. I can't power off the device or get into recovery. I am screwed and in need of your help.
My device is RMX3363

Can you shut down the phone with the menu of the bootlader? scroll with volume buttons, if not remove the back cover of the phone and unplug and plug the battery connector and look on this guide carefully and it mandatory to do backup with the qfill app before the flashing

eliran0216 said:
Can you shut down the phone with the menu of the bootlader? scroll with volume buttons, if not remove the back cover of the phone and unplug and plug the battery connector and look on this guide carefully and it mandatory to do backup with the qfill app before the flashing
Click to expand...
Click to collapse
Thanks for replying. I could not shut it down so I waited for the battery to drain. I'll try this and tell you how it goes

I followed the steps in the video but I am still unsuccessful. Here's the log I received from QFIL
2023-06-04 11:41:03.377 ***** Working Folder:C:\Users\Me\AppData\Roaming\Qualcomm\QFIL\BHI
2023-06-04 11:41:03.382 Validating Application Configuration
2023-06-04 11:41:03.385 Load APP Configuration
2023-06-04 11:41:03.395 COM:3
2023-06-04 11:41:03.395 PBLDOWNLOADPROTOCOL:0
2023-06-04 11:41:03.395 PROGRAMMER:True
2023-06-04 11:41:03.395 PROGRAMMER:C:\Users\Me\Desktop\Extra\prog_firehose_ddr.elf
2023-06-04 11:41:03.395 RESETSAHARASTATEMACHINE:True
2023-06-04 11:41:03.395 SAHARAREADSERIALNO:True
2023-06-04 11:41:03.395 SEARCHPATH:C:\Users\Me\Desktop\Extra
2023-06-04 11:41:03.395 ACKRAWDATAEVERYNUMPACKETS:False
2023-06-04 11:41:03.395 ACKRAWDATAEVERYNUMPACKETS:100
2023-06-04 11:41:03.395 MAXPAYLOADSIZETOTARGETINBYTES:False
2023-06-04 11:41:03.395 MAXPAYLOADSIZETOTARGETINBYTES:49152
2023-06-04 11:41:03.395 ACTIVEBOOTPARTITION:False
2023-06-04 11:41:03.395 ACTIVEBOOTPARTITION:0
2023-06-04 11:41:03.395 PHYPARTITIONS:True
2023-06-04 11:41:03.395 PHYPARTITIONS:0,1,2,3,4,5
2023-06-04 11:41:03.395 DEVICETYPE:ufs
2023-06-04 11:41:03.395 PLATFORM:8x26
2023-06-04 11:41:03.395 VALIDATIONMODE:0
2023-06-04 11:41:03.395 RESETAFTERDOWNLOAD:True
2023-06-04 11:41:03.395 SWITCHTOFIREHOSETIMEOUT:30
2023-06-04 11:41:03.395 RESETTIMEOUT:200
2023-06-04 11:41:03.395 RESETDELAYTIME:2
2023-06-04 11:41:03.395 METABUILD:
2023-06-04 11:41:03.395 METABUILD:
2023-06-04 11:41:03.395 FLATBUILDPATH:C:\
2023-06-04 11:41:03.395 FLATBUILDFORCEOVERRIDE:True
2023-06-04 11:41:03.395 QCNPATH:C:\Temp\00000000.qcn
2023-06-04 11:41:03.395 QCNAUTOBACKUPRESTORE:False
2023-06-04 11:41:03.395 SPCCODE:000000
2023-06-04 11:41:03.395 ENABLEMULTISIM:False
2023-06-04 11:41:03.395 AUTOPRESERVEPARTITIONS:False
2023-06-04 11:41:03.395 PARTITIONPRESERVEMODE:0
2023-06-04 11:41:03.395 PRESERVEDPARTITIONS:0
2023-06-04 11:41:03.395 PRESERVEDPARTITIONS:
2023-06-04 11:41:03.395 ERASEALL:False
2023-06-04 11:41:03.396 Load ARG Configuration
2023-06-04 11:41:03.419 Validating Download Configuration
2023-06-04 11:41:03.420 Image Search Path: C:\Users\Me\Desktop\Extra
2023-06-04 11:41:03.423 Programmer Path:C:\Users\Me\Desktop\Extra\prog_firehose_ddr.elf
2023-06-04 11:41:03.847 Process Index:0
2023-06-04 11:41:03.855 Qualcomm Flash Image Loader (QFIL) 2.0.3.5
2023-06-04 11:41:17.825 Start Download
2023-06-04 11:41:17.828 Program Path:C:\Users\Me\Desktop\Extra\prog_firehose_ddr.elf
2023-06-04 11:41:17.829 ***** Working Folder:C:\Users\Me\AppData\Roaming\Qualcomm\QFIL\COMPORT_3
2023-06-04 11:41:17.850 Binary build date: Jun 25 2019 @ 03:16:15
2023-06-04 11:41:17.850 QSAHARASERVER CALLED LIKE THIS: 'C:\Program Files (x86)\Qualcomm\QPST\bin\QSaharaServer.ex'Current working dir: C:\Users\Me\AppData\Roaming\Qualcomm\QFIL\COMPORT_3
2023-06-04 11:41:17.851 Sahara mappings:
2023-06-04 11:41:17.852 2: amss.mbn
2023-06-04 11:41:17.852 6: apps.mbn
2023-06-04 11:41:17.854 8: dsp1.mbn
2023-06-04 11:41:17.855 10: dbl.mbn
2023-06-04 11:41:17.855 11: osbl.mbn
2023-06-04 11:41:17.856 12: dsp2.mbn
2023-06-04 11:41:17.857 16: efs1.mbn
2023-06-04 11:41:17.857 17: efs2.mbn
2023-06-04 11:41:17.858 20: efs3.mbn
2023-06-04 11:41:17.858 21: sbl1.mbn
2023-06-04 11:41:17.859 22: sbl2.mbn
2023-06-04 11:41:17.859 23: rpm.mbn
2023-06-04 11:41:17.860 25: tz.mbn
2023-06-04 11:41:17.860 28: dsp3.mbn
2023-06-04 11:41:17.861 29: acdb.mbn
2023-06-04 11:41:17.861 30: wdt.mbn
2023-06-04 11:41:17.862 31: mba.mbn
2023-06-04 11:41:17.864 13: C:\Users\Me\Desktop\Extra\prog_firehose_ddr.elf
2023-06-04 11:41:17.865
2023-06-04 11:41:17.866 11:41:17: ERROR: function: sahara_rx_data:286 Command packet length 1702240364 too large to fit
2023-06-04 11:41:17.866
2023-06-04 11:41:17.867 11:41:17: ERROR: function: sahara_main:982 Sahara protocol error
2023-06-04 11:41:17.867
2023-06-04 11:41:17.868 11:41:17: ERROR: function: main:320 Uploading Image using Sahara protocol failed
2023-06-04 11:41:17.869
2023-06-04 11:41:17.869
2023-06-04 11:41:17.870 Download Fail:Sahara Fail:QSaharaServer Failrocess fail
2023-06-04 11:41:17.876 Finish Get GPT

Also getting Sahara error or FHLoader, what do i do wrong?

Related

any one know what the problem is from these logs?

It looks like StabilityTest crashed unexpectedly or your device rebooted.
The following information were gathered right before the event occured:
cores: 1
bogomips: 662.40
load: 7.83
temperature: 35.1°C
# passed test runs (core 1): 11
# passed test runs (ram): 118
runtime: 00:28:09
system log:
--------- beginning of /dev/log/system
E/ConnectivityService( 92): Network declined teardown quickly request
--------- beginning of /dev/log/main
E/lights ( 92): write ok string=0,len=1
E/lights ( 92): write ok string=0,len=1
E/lights ( 92): write ok string=0 0,len=3
E/lights ( 92): write ok string=0,len=1
E/lights ( 92): write ok string=0,len=1
E/lights ( 92): write ok string=0 0,len=3
E/lights ( 92): write ok string=0,len=1
E/lights ( 92): write ok string=0,len=1
E/lights ( 92): write ok string=0 0,len=3
E/lights ( 92): write ok string=0,len=1
E/lights ( 92): write ok string=0,len=1
E/lights ( 92): write ok string=0 0,len=3
E/Tethering( 92): attempting to remove unknown iface (usb0), ignoring
E/lights ( 92): write ok string=1,len=1
E/lights ( 92): write ok string=0,len=1
E/lights ( 92): write ok string=0 0,len=3
E/lights ( 92): write ok string=0,len=1
E/lights ( 92): write ok string=0,len=1
E/lights ( 92): write ok string=0 0,len=3
E/Tethering( 92): attempting to remove unknown iface (usb0), ignoring
E/Tethering( 92): attempting to remove unknown iface (usb0), ignoring
E/Tethering( 92): attempting to remove unknown iface (usb0), ignoring
E/Tethering( 92): attempting to remove unknown iface (usb0), ignoring
E/Tethering( 92): attempting to remove unknown iface (usb0), ignoring
E/Tethering( 92): attempting to remove unknown iface (usb0), ignoring
E/Tethering( 92): attempting to remove unknown iface (usb0), ignoring
E/Tethering( 92): attempting to remove unknown iface (usb0), ignoring
E/Tethering( 92): attempting to remove unknown iface (usb0), ignoring
E/Tethering( 92): attempting to remove unknown iface (usb0), ignoring
E/Tethering( 92): attempting to remove unknown iface (usb0), ignoring
right after this the phone restarted then restarted again then turned on, the bottom of the phone was hot. wifi was enabled. 3G was off. sound was off.
any ideas?

[Dev] Gen10 AES/MPK keys + aos-tools

Hi hackers,
aos-tools got another update.
With the help of cajl, our helpful fellow here at xda, i was able to extract the keys for Gen10 devices.
So here it is:
Code:
static unsigned char G10A_AES[] = {
0x7A, 0xDD, 0xFA, 0xB4, 0xAF, 0x05, 0x18, 0xF4,
0x02, 0x6E, 0xFE, 0x2E, 0x28, 0xFA, 0x0C, 0x71
};
static unsigned char G10A_BOOTLOADER[] = {
0xFB, 0x28, 0x97, 0x50, 0x10, 0x90, 0x9B, 0x90, 0xDD, 0xD0,
0x27, 0xC5, 0x15, 0xC5, 0xDD, 0xCE, 0xDB, 0x6E, 0xE1, 0x5C,
0xB9, 0xAA, 0x15, 0x2F, 0xE2, 0x3E, 0xB0, 0x8A, 0xB5, 0x99,
0xE1, 0x01, 0x06, 0x58, 0x0D, 0x00, 0xD3, 0xC6, 0x38, 0x67,
0x34, 0x2D, 0x31, 0x22, 0x28, 0xD3, 0x09, 0x44, 0x3D, 0xBE,
0xE8, 0x19, 0xC9, 0x23, 0x7A, 0x0A, 0x06, 0x1F, 0x5D, 0xCF,
0xAA, 0xB3, 0xC2, 0x99, 0xDA, 0xA8, 0x20, 0x50, 0x6B, 0x7A,
0x6D, 0x05, 0xFD, 0x80, 0x25, 0x52, 0x07, 0x54, 0xF5, 0xA6,
0xA1, 0x6F, 0xF9, 0xC2, 0xB4, 0x7E, 0x03, 0x17, 0xB3, 0x66,
0xA4, 0xA9, 0xBA, 0x11, 0x68, 0xC4, 0x56, 0xC3, 0x01, 0x7A,
0x4B, 0x5A, 0x30, 0x3A, 0x5F, 0xB3, 0x7A, 0x5F, 0x91, 0x34,
0xBD, 0xB1, 0x78, 0x10, 0x25, 0xE8, 0xDC, 0x59, 0x79, 0x61,
0xE9, 0x58, 0xF8, 0x8F, 0x25, 0x58, 0x3F, 0xB3, 0x01, 0x00,
0x03, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0xE1, 0x38,
0x6C, 0xCB
};
static unsigned char G10A_RELMPK[] = {
0x21, 0x54, 0x3D, 0x5F, 0x13, 0x85, 0xFC, 0xE2, 0x02, 0x75,
0xFE, 0x46, 0xC1, 0xAF, 0xBF, 0xC3, 0x91, 0x94, 0xF0, 0x2D,
0xAE, 0xF9, 0x6D, 0xEA, 0x2F, 0x2E, 0x24, 0xC7, 0x24, 0x8E,
0x6E, 0x1A, 0xB8, 0x15, 0x26, 0x40, 0xD7, 0xB1, 0xFA, 0x79,
0x60, 0xFB, 0x70, 0xEB, 0xE2, 0x77, 0x20, 0xCE, 0xAE, 0x99,
0x33, 0x25, 0x8E, 0x74, 0xA6, 0x7A, 0xD2, 0x9C, 0x15, 0x35,
0x03, 0xAF, 0xB6, 0xF9, 0x5A, 0xE2, 0xF8, 0x87, 0xF9, 0x22,
0xC1, 0x86, 0x90, 0xAD, 0x81, 0x9B, 0x44, 0x74, 0x8B, 0xD6,
0x82, 0x2E, 0x0B, 0x9F, 0x53, 0xC9, 0xD6, 0xC4, 0x03, 0xFE,
0x4F, 0xF6, 0x70, 0x35, 0x8B, 0x11, 0xCD, 0x95, 0x14, 0xA0,
0x81, 0x2A, 0x3C, 0x95, 0xC9, 0x48, 0xA0, 0x01, 0x2B, 0x99,
0x1C, 0xE0, 0x91, 0x88, 0x3A, 0x07, 0x85, 0xEA, 0x04, 0xFA,
0x3C, 0xB5, 0x76, 0x7C, 0xFF, 0xE0, 0xF0, 0xD5, 0x01, 0x00,
0x03, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x31, 0x55,
0xB1, 0x69
};
static unsigned char G10A_DEVMPK[] = {
0x33, 0x70, 0xFC, 0x74, 0x90, 0xCE, 0x2E, 0x88, 0x34, 0x8C,
0xA0, 0xE7, 0x2A, 0x3C, 0xC0, 0x96, 0x93, 0x64, 0x21, 0x2E,
0xA7, 0xB5, 0xD8, 0xB9, 0x78, 0xE7, 0xD5, 0x97, 0x9F, 0x2C,
0x98, 0xCD, 0xA6, 0x4A, 0x1C, 0xE0, 0x0A, 0x07, 0xB4, 0xFB,
0x04, 0x00, 0x93, 0xF2, 0xF4, 0xCE, 0xC2, 0x9C, 0xF5, 0xD3,
0x95, 0x37, 0x01, 0x58, 0x2D, 0xEA, 0x4C, 0x96, 0xDD, 0xD9,
0xAD, 0xA2, 0xA7, 0x7C, 0xDD, 0x69, 0x6F, 0xBA, 0xE4, 0xD5,
0x04, 0x5C, 0xD9, 0xE2, 0x14, 0xC8, 0xFF, 0xE7, 0x4C, 0x49,
0x9C, 0x0C, 0xA1, 0x92, 0x03, 0x50, 0xEE, 0x3D, 0x73, 0xED,
0x02, 0x07, 0xEF, 0xBE, 0x43, 0xE4, 0x33, 0x32, 0xBF, 0x30,
0x9E, 0xE8, 0xCD, 0xD1, 0x7C, 0x96, 0x31, 0x7C, 0xE4, 0xD0,
0x74, 0xCF, 0xD8, 0x67, 0x5D, 0x5A, 0x67, 0x63, 0x13, 0xDF,
0x71, 0x69, 0x54, 0x93, 0x2B, 0x0B, 0xA0, 0xB5, 0x01, 0x00,
0x03, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x05, 0x26,
0xF4, 0xDC
};
static unsigned char G10A_PLUGMPK[] = {
0x5F, 0x2E, 0x22, 0x66, 0x2A, 0x4F, 0x11, 0x6A, 0x9A, 0x64,
0x5D, 0xB6, 0x26, 0x1D, 0x97, 0xA8, 0x81, 0x0F, 0x18, 0x4F,
0x35, 0xC6, 0x7A, 0x6D, 0xBB, 0x80, 0x45, 0xC5, 0x61, 0x42,
0x58, 0x43, 0xBE, 0xB5, 0x1D, 0x3E, 0x6B, 0x05, 0x7F, 0x72,
0x74, 0xE4, 0x0A, 0xAF, 0x2F, 0xE0, 0xFA, 0x50, 0x84, 0xB7,
0xC0, 0x13, 0x19, 0x61, 0x42, 0xC0, 0xE6, 0x09, 0xC7, 0x08,
0xAE, 0xDB, 0x2E, 0x60, 0x72, 0xBE, 0x4C, 0x36, 0xCA, 0xA3,
0xA0, 0x81, 0x14, 0x67, 0xF6, 0xBC, 0x14, 0xD3, 0xC9, 0x4B,
0xB7, 0x03, 0x9F, 0x73, 0x20, 0xF5, 0x2F, 0x97, 0x0B, 0x41,
0x84, 0x57, 0x59, 0xBD, 0xA7, 0x68, 0x7A, 0x57, 0x38, 0xC6,
0x9C, 0x9D, 0xEC, 0x21, 0x24, 0x55, 0xAE, 0x6F, 0xF2, 0x92,
0x48, 0x00, 0x41, 0x3B, 0x55, 0xFA, 0x9D, 0xA6, 0xA3, 0xB2,
0x35, 0x0B, 0xC2, 0xF2, 0xC4, 0x11, 0x31, 0xC6, 0x01, 0x00,
0x03, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x6F, 0x96,
0xB4, 0x17
};
static unsigned char G10A_HDDMPK[] = {
0x43, 0x0A, 0x87, 0x99, 0x36, 0x79, 0xE8, 0x77, 0x4F, 0xD7,
0x15, 0xFC, 0x65, 0x14, 0xA3, 0x2F, 0x17, 0x13, 0x05, 0xB6,
0x82, 0x64, 0x40, 0x84, 0xF3, 0x16, 0xB3, 0xD1, 0x85, 0xCE,
0x4D, 0xDF, 0x6A, 0x9E, 0x3A, 0x78, 0xD0, 0xD7, 0xED, 0x7C,
0x59, 0xDC, 0x60, 0xE8, 0x99, 0x0D, 0x65, 0xE1, 0xA8, 0xFD,
0x69, 0x5F, 0x71, 0xF7, 0xD8, 0xD1, 0xD7, 0x1B, 0x67, 0xD8,
0x9C, 0xC1, 0x4B, 0x2D, 0x37, 0xFE, 0x5A, 0xDD, 0x65, 0x01,
0x52, 0x38, 0xE6, 0xC0, 0x62, 0x54, 0x11, 0x09, 0x86, 0xFD,
0x8D, 0x93, 0x1B, 0x81, 0x21, 0xB5, 0xCC, 0xE7, 0xAD, 0xBA,
0x74, 0x2C, 0x81, 0x45, 0x23, 0xD2, 0x3D, 0x59, 0xED, 0x43,
0xA8, 0x3E, 0x0C, 0x20, 0x92, 0x60, 0xF0, 0x43, 0x4B, 0x55,
0x7F, 0xD9, 0x89, 0x98, 0x66, 0x43, 0x73, 0x9C, 0xD1, 0x14,
0x7D, 0xA9, 0xE7, 0xC6, 0x94, 0x66, 0x43, 0xAA, 0x01, 0x00,
0x03, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x47, 0xA0,
0x91, 0x08
};
I could not wait and implemented the new key section to the famous aos-tools.
Just made a test run and it just worked out of the box.
Attached you'll find 32bit binaries and the sources to compile the tools yourself on a linux host.
These are the bare tools based on EiNSTeiN's work.
Not included yet, are the additonal tools from letama (e.g. aos-kernel-unpack).
The binaries are compiled with libc-2.3.6, so should work basically on every latest 32bit linux machine.
DIY for a 64bit host!
We now are able to extract Gen10 firmware files and may find a way to permanently root these tablets soon.
EDIT:
To the admins... as soon as we get a Gen10 section, this thread should be moved of course
Have fun!
scholbert
Hi !
Thanks ! ...great work ...but where can I find the source code for tools " unpack-kernel " ?
Hi surdu_petru,
thanks for appreciating!
surdu_petru said:
...but where can I find the source code for tools " unpack-kernel " ?
Click to expand...
Click to collapse
Letama just posted the sources... see this posting:
http://forum.xda-developers.com/showpost.php?p=34523637&postcount=19
Have fun!
scholbert
Hi !
Update ...
Tools for unpack Archos 101XS firmware_archos_it4x.aos !
- unpack firmware .aos -> aos-unpack-g10 ( 64bit !)
- unpack kernel -> unpack-aos-kernel-g10 (64bit !)
To enter commands from any directory , copy the both binary files in /usr/local/bin !
$ cp aos-unpack-g10 /usr/local/bin/
$ cp unpack-aos-kernel-g10 /usr/local/bin/
$ sudo chown 0.0 /usr/local/bin/aos-unpack-g10
$ sudo chown 0.0 /usr/local/bin/unpack-aos-kernel-g10
$ sudo chmod +x /usr/local/bin/aos-unpack-g10
$ sudo chmod +x /usr/local/bin/unpack-aos-kernel-g10
Download : tools-gen10.zip - 27.15 KB Mirror : tools-gen10.zip
***********
Root version for Archos 101XS Firmware 4.0.26 is out !
Will be posted soon, ... as soon as Mr. Cajl will test the new release !
Credit :
Many thanks to LeTama & Scholbert !
work in progress
scholbert said:
Hi hackers,
....
We now are able to extract Gen10 firmware files and may find a way to permanently root these tablets soon.
....
scholbert
Click to expand...
Click to collapse
Hi Scholbert and Everyone!
Thanks for the code Scholbert, saved me job! :good: I've updated my github repo [ trevd/aos-tools ] with the latest sources as no one seems to have access to update the original google code sources, If anyone wants commit permissions let me know your github user name and I'll add you to the list.
Thanks
trevd said:
Hi Scholbert and Everyone!
Thanks for the code Scholbert, saved me job! :good: I've updated my github repo [ trevd/aos-tools ] with the latest sources as no one seems to have access to update the original google code sources, If anyone wants commit permissions let me know your github user name and I'll add you to the list.
Thanks
Click to expand...
Click to collapse
Hi trevd, thanks for keeping the code uptodate for aos-tools. I added your source and a short description to the wiki on openaos http://dev.openaos.org/wiki/aos-tools
All the others involved thanks for extracting the keys.
divx118

[FireTvStick 5.2.1.1] Failed to add tun0 to VPN net

I sideloaded OpenVPNConnect and OpenVPN(blinkt.de) on my FireTvStick 5.2.1.1.
Both apps are able to connect to my vpn server and according to their own logs routes (especialle for 0.0.0.0) have been created and the sequence is completed.
But in opposite to all other my android devices where the same vpn config works the FireTvStick is not using the vpn.
The output of logcat follows for both applications.
de.blinkt.openvpn.apk:
Code:
12-20 19:59:37.588: D/VpnJni(987): Address added on tun0: 10.8.0.10/30
12-20 19:59:37.608: D/ConnectivityService(987): registerNetworkAgent NetworkAgentInfo{ ni{[type: VPN[], state: CONNECTED/CONNECTED, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: true, isConnectedToProvisioningNetwork: false]} network{null} lp{{InterfaceName: tun0 LinkAddresses: [10.8.0.10/30,] Routes: [0.0.0.0/1 -> 0.0.0.0 tun0,128.0.0.0/2 -> 0.0.0.0 tun0,192.0.0.0/9 -> 0.0.0.0 tun0,192.128.0.0/11 -> 0.0.0.0 tun0,192.160.0.0/13 -> 0.0.0.0 tun0,192.168.0.0/17 -> 0.0.0.0 tun0,192.168.128.0/19 -> 0.0.0.0 tun0,192.168.160.0/20 -> 0.0.0.0 tun0,192.168.176.0/23 -> 0.0.0.0 tun0,192.168.179.0/24 -> 0.0.0.0 tun0,192.168.180.0/22 -> 0.0.0.0 tun0,192.168.184.0/21 -> 0.0.0.0 tun0,192.168.192.0/18 -> 0.0.0.0 tun0,192.169.0.0/16 -> 0.0.0.0 tun0,192.170.0.0/15 -> 0.0.0.0 tun0,192.172.0.0/14 -> 0.0.0.0 tun0,192.176.0.0/12 -> 0.0.0.0 tun0,192.192.0.0/10 -> 0.0.0.0 tun0,193.0.0.0/8 -> 0.0.0.0 tun0,194.0.0.0/7 -> 0.0.0.0 tun0,196.0.0.0/6 -> 0.0.0.0 tun0,200.0.0.0/5 -> 0.0.0.0 tun0,208.0.0.0/4 -> 0.0.0.0 tun0,] DnsAddresses: [208.67.222.222,208.67.220.220,] Domains: MTU: 0}} nc{[ Transports: VPN Capabilities: NOT_RESTRICTED&TRUSTED]} Score{0} everValidated{false} lastValidated{false} created{false} explicitlySelected{false} }
12-20 19:59:37.608: D/ConnectivityService(987): Adding iface tun0 to network 110
12-20 19:59:37.628: I/Vpn(987): Established by de.blinkt.openvpn on tun0
12-20 19:59:37.688: E/Netd(153): failed to add interface tun0 to VPN netId 110
12-20 19:59:37.698: E/ConnectivityService(987): Exception adding interface: java.lang.IllegalStateException: command '366 network interface add 110 tun0' failed with '400 366 addInterfaceToNetwork() failed (Invalid argument)'
12-20 19:59:37.698: E/ConnectivityService(987): Unexpected mtu value: 0, tun0
12-20 19:59:37.698: E/Netd(153): interface tun0 not assigned to any netId
...
net.openvpn.openvpn.apk:
Code:
12-20 20:00:19.226: D/VpnJni(987): Address added on tun0: 10.8.0.10/30
12-20 20:00:19.246: I/Vpn(987): Established by net.openvpn.openvpn on tun0
12-20 20:00:19.246: D/ConnectivityService(987): registerNetworkAgent NetworkAgentInfo{ ni{[type: VPN[], state: CONNECTED/CONNECTED, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: true, isConnectedToProvisioningNetwork: false]} network{null} lp{{InterfaceName: tun0 LinkAddresses: [10.8.0.10/30,] Routes: [10.8.0.1/32 -> 0.0.0.0 tun0,0.0.0.0/0 -> 0.0.0.0 tun0,::/0 unreachable,] DnsAddresses: [208.67.222.222,208.67.220.220,] Domains: MTU: 0}} nc{[ Transports: VPN Capabilities: INTERNET&NOT_RESTRICTED&TRUSTED]} Score{0} everValidated{false} lastValidated{false} created{false} explicitlySelected{false} }
12-20 20:00:19.246: D/ConnectivityService(987): Adding iface tun0 to network 111
12-20 20:00:19.306: E/Netd(153): failed to add interface tun0 to VPN netId 111
12-20 20:00:19.316: E/ConnectivityService(987): Exception adding interface: java.lang.IllegalStateException: command '401 network interface add 111 tun0' failed with '400 401 addInterfaceToNetwork() failed (Invalid argument)'
12-20 20:00:19.316: E/ConnectivityService(987): Unexpected mtu value: 0, tun0
12-20 20:00:19.316: E/Netd(153): interface tun0 not assigned to any netId
12-20 20:00:19.316: E/ConnectivityService(987): Exception in addRoute for non-gateway: java.lang.IllegalStateException: command '402 network route add 111 tun0 10.8.0.1/32' failed with '400 402 addRoute() failed (No such device)'
12-20 20:00:19.316: E/Netd(153): interface tun0 not assigned to any netId
12-20 20:00:19.326: E/ConnectivityService(987): Exception in addRoute for non-gateway: java.lang.IllegalStateException: command '403 network route add 111 tun0 0.0.0.0/0' failed with '400 403 addRoute() failed (No such device)'
12-20 20:00:19.326: E/Netd(153): interface tun0 not assigned to any netId
12-20 20:00:19.396: E/ConnectivityService(987): Attempting to register duplicate agent for type 17: NetworkAgentInfo{ ni{[type: VPN[], state: CONNECTED/CONNECTED, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: true, isConnectedToProvisioningNetwork: false]} network{111} lp{{InterfaceName: tun0 LinkAddresses: [10.8.0.10/30,] Routes: [10.8.0.1/32 -> 0.0.0.0 tun0,0.0.0.0/0 -> 0.0.0.0 tun0,::/0 unreachable,] DnsAddresses: [208.67.222.222,208.67.220.220,] Domains: MTU: 0}} nc{[ Transports: VPN Capabilities: INTERNET&NOT_RESTRICTED&TRUSTED]} Score{0} everValidated{true} lastValidated{true} created{true} explicitlySelected{false} }
adding a route by hand via "route add default gw 10.8.0.1 dev tun0" is not permitted.
so is the whole thing an rooted/unrooted issue?

LG G4 Bricked Qualcomm HS-USB QDLoader 9008

Hello,
I know,I know, you will say yet another topic about LG G4 and Qualcomm 9008 problem.
you have right but this problem intrigues me.
Some people proposed a solution for reviving the phone without a box by short-cutting 2 testpoint on the motherbord before connecting to the computer.
so here is what I did, unfortunately without success, but together we can find where is the problem and find a final solution for this big problem.
1- ONLY connect Smartphone USB Side like this :
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
2- Shortcut with tweezers the two testpoints as described here :
3-On windows 10 x64 Launch QFIL V 2.0.0.5 with Admin Rights :
4- Connect USB Computer side :
5-Choose COM PORT and all settings like this :
6-Clik Download Button
7- unsuccessful operation, this is the log file
Validating Application Configuration
Load APP Configuration
COM:-1
PBLDOWNLOADPROTOCOL:0
PROGRAMMER:True
PROGRAMMER:C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\prog_emmc_firehose_8992_lite.mbn
SEARCHPATH:C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818
RAWPROGRAM:
rawprogram0.xml
PATCH:
patch0.xml
ACKRAWDATAEVERYNUMPACKETS:False
ACKRAWDATAEVERYNUMPACKETS:100
MAXPAYLOADSIZETOTARGETINBYTES:False
MAXPAYLOADSIZETOTARGETINBYTES:49152
DEVICETYPE:eMMC
PLATFORM:8x26
VALIDATIONMODE:0
RESETAFTERDOWNLOAD:False
MAXDIGESTTABLESIZE:8192
SWITCHTOFIREHOSETIMEOUT:30
RESETTIMEOUT:200
RESETDELAYTIME:2
FLATBUILDPATH:C:\
FLATBUILDFORCEOVERRIDE:True
QCNPATH:C:\Temp\00000000.qcn
QCNAUTOBACKUPRESTORE:False
SPCCODE:000000
ENABLEMULTISIM:False
Load ARG Configuration
Validating Download Configuration
Image Search Path: C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818
RAWPROGRAM file path: C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\rawprogram0.xml
PATCH file path:C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\patch0.xml
Programmer Path:C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\prog_emmc_firehose_8992_lite.mbn
Process Index:0
Start Download
Program Path:C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\prog_emmc_firehose_8992_lite.mbn
Binary build date: May 13 2015 @ 14:41:37
QSAHARASERVER CALLED LIKE THIS: 'C:\Program Files (x86)\Qualcomm\QPST\bin\QSaharaServer.exe -p \\.\COM4 -s 13:C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\prog_emmc_firehose_8992_lite.mbn 'Current working dir: C:\Users\Amine\AppData\Roaming\Qualcomm\QFIL
Sahara mappings:
2: amss.mbn
6: apps.mbn
8: dsp1.mbn
10: dbl.mbn
11: osbl.mbn
12: dsp2.mbn
16: efs1.mbn
17: efs2.mbn
20: efs3.mbn
21: sbl1.mbn
22: sbl2.mbn
23: rpm.mbn
25: tz.mbn
28: dsp3.mbn
29: acdb.mbn
30: wdt.mbn
31: mba.mbn
13: C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\prog_emmc_firehose_8992_lite.mbn
09:28:26: Requested ID 13, file: "C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\prog_emmc_firehose_8992_lite.mbn"
09:28:26: 273568 bytes transferred in 0.360000 seconds (0.7247MBps)
09:28:26: File transferred successfully
NOTE: Target requested image 13 which is DeviceProgrammer. Forcing QUIT. This is by design, ** All is well ** SUCCESS!!
09:28:26: Sahara protocol completed
Sending Programmer Finished
Switch To FireHose
Wait for 3 seconds...
Max Payload Size to Target:49152 Bytes
Device Type:eMMC
Platform:8x26
Disable Ack Raw Data Every N Packets
Skip Write:False
Always Validate:False
Use Verbose:False
Binary build date: Sep 28 2015 @ 17:28:46
Build version: 15.09.28.17.28.46
09:28:30: INFO: FH_LOADER WAS CALLED EXACTLY LIKE THIS
************************************************
C:\Program Files (x86)\Qualcomm\QPST\bin\fh_loader.exe --port=\\.\COM4 --sendxml=rawprogram0.xml --search_path=C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818 --noprompt --showpercentagecomplete --zlpawarehost=1 --memoryname=eMMC
************************************************
09:28:30: INFO: Current working dir (cwd): C:\Users\Amine\AppData\Roaming\Qualcomm\QFIL\
09:28:30: INFO: Showing network mappings to allow debugging
09:28:30: INFO:
09:28:30: INFO: Trying to store 'rawprogram0.xml' in string table
09:28:30: INFO: Looking for file 'rawprogram0.xml'
09:28:30: INFO: User wants to talk to port '\\.\COM4'
_____
| ___|
| |__ _ __ _ __ ___ _ __
| __| '__| '__/ _ \| '__|
| |__| | | | | (_) | |
\____/_| |_| \___/|_|
09:28:40: {ERROR: It took 10.00000000 seconds to open port. Which is longer than 3.000. This indicates your target is not stable}
Writing log to 'C:\Users\Amine\AppData\Roaming\Qualcomm\QFIL\port_trace.txt', might take a minute
Log is 'C:\Users\Amine\AppData\Roaming\Qualcomm\QFIL\port_trace.txt'
Download Fail:FireHose Fail FHLoader Failrocess fail
Finish Download
port_trace.txt
Validating Application Configuration
Load APP Configuration
COM:-1
PBLDOWNLOADPROTOCOL:0
PROGRAMMER:True
PROGRAMMER:C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\prog_emmc_firehose_8992_lite.mbn
SEARCHPATH:C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818
RAWPROGRAM:
rawprogram0.xml
PATCH:
patch0.xml
ACKRAWDATAEVERYNUMPACKETS:False
ACKRAWDATAEVERYNUMPACKETS:100
MAXPAYLOADSIZETOTARGETINBYTES:False
MAXPAYLOADSIZETOTARGETINBYTES:49152
DEVICETYPE:eMMC
PLATFORM:8x26
VALIDATIONMODE:0
RESETAFTERDOWNLOAD:False
MAXDIGESTTABLESIZE:8192
SWITCHTOFIREHOSETIMEOUT:30
RESETTIMEOUT:200
RESETDELAYTIME:2
FLATBUILDPATH:C:\
FLATBUILDFORCEOVERRIDE:True
QCNPATH:C:\Temp\00000000.qcn
QCNAUTOBACKUPRESTORE:False
SPCCODE:000000
ENABLEMULTISIM:False
Load ARG Configuration
Validating Download Configuration
Image Search Path: C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818
RAWPROGRAM file path: C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\rawprogram0.xml
PATCH file path:C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\patch0.xml
Programmer Path:C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\prog_emmc_firehose_8992_lite.mbn
Process Index:0
Start Download
Program Path:C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\prog_emmc_firehose_8992_lite.mbn
Binary build date: May 13 2015 @ 14:41:37
QSAHARASERVER CALLED LIKE THIS: 'C:\Program Files (x86)\Qualcomm\QPST\bin\QSaharaServer.exe -p \\.\COM4 -s 13:C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\prog_emmc_firehose_8992_lite.mbn 'Current working dir: C:\Users\Amine\AppData\Roaming\Qualcomm\QFIL
Sahara mappings:
2: amss.mbn
6: apps.mbn
8: dsp1.mbn
10: dbl.mbn
11: osbl.mbn
12: dsp2.mbn
16: efs1.mbn
17: efs2.mbn
20: efs3.mbn
21: sbl1.mbn
22: sbl2.mbn
23: rpm.mbn
25: tz.mbn
28: dsp3.mbn
29: acdb.mbn
30: wdt.mbn
31: mba.mbn
13: C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\prog_emmc_firehose_8992_lite.mbn
09:28:26: Requested ID 13, file: "C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\prog_emmc_firehose_8992_lite.mbn"
09:28:26: 273568 bytes transferred in 0.360000 seconds (0.7247MBps)
09:28:26: File transferred successfully
NOTE: Target requested image 13 which is DeviceProgrammer. Forcing QUIT. This is by design, ** All is well ** SUCCESS!!
09:28:26: Sahara protocol completed
Sending Programmer Finished
Switch To FireHose
Wait for 3 seconds...
Max Payload Size to Target:49152 Bytes
Device Type:eMMC
Platform:8x26
Disable Ack Raw Data Every N Packets
Skip Write:False
Always Validate:False
Use Verbose:False
Binary build date: Sep 28 2015 @ 17:28:46
Build version: 15.09.28.17.28.46
09:28:30: INFO: FH_LOADER WAS CALLED EXACTLY LIKE THIS
************************************************
C:\Program Files (x86)\Qualcomm\QPST\bin\fh_loader.exe --port=\\.\COM4 --sendxml=rawprogram0.xml --search_path=C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818 --noprompt --showpercentagecomplete --zlpawarehost=1 --memoryname=eMMC
************************************************
09:28:30: INFO: Current working dir (cwd): C:\Users\Amine\AppData\Roaming\Qualcomm\QFIL\
09:28:30: INFO: Showing network mappings to allow debugging
09:28:30: INFO:
09:28:30: INFO: Trying to store 'rawprogram0.xml' in string table
09:28:30: INFO: Looking for file 'rawprogram0.xml'
09:28:30: INFO: User wants to talk to port '\\.\COM4'
_____
| ___|
| |__ _ __ _ __ ___ _ __
| __| '__| '__/ _ \| '__|
| |__| | | | | (_) | |
\____/_| |_| \___/|_|
09:28:40: {ERROR: It took 10.00000000 seconds to open port. Which is longer than 3.000. This indicates your target is not stable}
Writing log to 'C:\Users\Amine\AppData\Roaming\Qualcomm\QFIL\port_trace.txt', might take a minute
Log is 'C:\Users\Amine\AppData\Roaming\Qualcomm\QFIL\port_trace.txt'
Download Fail:FireHose Fail FHLoader Failrocess fail
Finish Download
09:28:30: INFO: FH_LOADER WAS CALLED EXACTLY LIKE THIS
************************************************
C:\Program Files (x86)\Qualcomm\QPST\bin\fh_loader.exe --port=\\.\COM4 --sendxml=rawprogram0.xml --search_path=C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818 --noprompt --showpercentagecomplete --zlpawarehost=1 --memoryname=eMMC
************************************************
09:28:30: DEBUG: Binary build date: Sep 28 2015 @ 17:28:46
09:28:30: DEBUG: Build Version: 15.09.28.17.28.46
09:28:30: INFO: Current working dir (cwd): C:\Users\Amine\AppData\Roaming\Qualcomm\QFIL\
09:28:30: INFO: Showing network mappings to allow debugging
09:28:30: DEBUG: Les nouvelles connexions seront m‚moris‚es.
09:28:30: DEBUG:
09:28:30: DEBUG: La liste est vide.
09:28:30: DEBUG:
09:28:30: INFO:
09:28:30: INFO: Trying to store 'rawprogram0.xml' in string table
09:28:30: DEBUG: ==================================================================================
09:28:30: DEBUG: ==================================================================================
09:28:30: INFO: Looking for file 'rawprogram0.xml'
09:28:30: DEBUG: 1. Calling stat(C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\rawprogram0.xml')
09:28:30: DEBUG: 2. Calling fopen('C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\rawprogram0.xml') with AccessMode='rb'
09:28:30: DEBUG: Trying get filesize, calling fseek()
09:28:30: DEBUG: Found 'C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\rawprogram0.xml' (5089 bytes)
09:28:30: DEBUG: 2. Calling fopen('C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\rawprogram0.xml') with AccessMode='r'
09:28:30: DEBUG: Trying get filesize, calling fseek()
09:28:30: DEBUG: User set ZLPAWAREHOST to 1
09:28:30: INFO: User wants to talk to port '\\.\COM4'
09:28:40: DEBUG: port_fd=0xC8
_____
| ___|
| |__ _ __ _ __ ___ _ __
| __| '__| '__/ _ \| '__|
| |__| | | | | (_) | |
\____/_| |_| \___/|_|
09:28:40: {ERROR: OpenPort:5566 It took 10.00000000 seconds to open port. Which is longer than 3.000. This indicates your target is not stable
So where is the problem ? Shortcutting the two points is supposed to open the FireHose port but i tested with twezzers, cooper cable...ect nothing seem to work
any Idea ?
thank you
PS: I have the Link to the files if you want them
Hello, ¿you can share the links?, I need the files for LG H810.
Thank you in advance.
I got the same problem with my H815T. It only allows me to flash the LS991 files, but I lose the imei
serestma said:
Hello, ¿you can share the links?, I need the files for LG H810.
Thank you in advance.
Click to expand...
Click to collapse
H810: https://mega.nz/#!55tACDZC!Ci1pjEr8_wr9Ng2SrPgj42MwxnGybo60de26w2gtimg
I bought a subscription from easy-firmware hoping that they have right emmc_firehose. They are scammers. I have a bricked LG G4 too and since now I have not found a way to unbrick it. Do not waste your time. For H815 the files are wrong and we also need nonfused emmc_firehose_programmer. Also the SD Card method is not working for me tried it with 10 different images and 4 different cards. I am investigating this issue and if I find a solution I will make a tutorial for all fellas that are in trouble.
AZstyle said:
Hello,
I know,I know, you will say yet another topic about LG G4 and Qualcomm 9008 problem.
you have right but this problem intrigues me.
Some people proposed a solution for reviving the phone without a box by short-cutting 2 testpoint on the motherbord before connecting to the computer.
so here is what I did, unfortunately without success, but together we can find where is the problem and find a final solution for this big problem.
1- ONLY connect Smartphone USB Side like this :
2- Shortcut with tweezers the two testpoints as described here :
3-On windows 10 x64 Launch QFIL V 2.0.0.5 with Admin Rights :
4- Connect USB Computer side :
5-Choose COM PORT and all settings like this :
6-Clik Download Button
7- unsuccessful operation, this is the log file
Validating Application Configuration
Load APP Configuration
COM:-1
PBLDOWNLOADPROTOCOL:0
PROGRAMMER:True
PROGRAMMER:C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\prog_emmc_firehose_8992_lite.mbn
SEARCHPATH:C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818
RAWPROGRAM:
rawprogram0.xml
PATCH:
patch0.xml
ACKRAWDATAEVERYNUMPACKETS:False
ACKRAWDATAEVERYNUMPACKETS:100
MAXPAYLOADSIZETOTARGETINBYTES:False
MAXPAYLOADSIZETOTARGETINBYTES:49152
DEVICETYPE:eMMC
PLATFORM:8x26
VALIDATIONMODE:0
RESETAFTERDOWNLOAD:False
MAXDIGESTTABLESIZE:8192
SWITCHTOFIREHOSETIMEOUT:30
RESETTIMEOUT:200
RESETDELAYTIME:2
FLATBUILDPATH:C:\
FLATBUILDFORCEOVERRIDE:True
QCNPATH:C:\Temp\00000000.qcn
QCNAUTOBACKUPRESTORE:False
SPCCODE:000000
ENABLEMULTISIM:False
Load ARG Configuration
Validating Download Configuration
Image Search Path: C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818
RAWPROGRAM file path: C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\rawprogram0.xml
PATCH file path:C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\patch0.xml
Programmer Path:C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\prog_emmc_firehose_8992_lite.mbn
Process Index:0
Start Download
Program Path:C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\prog_emmc_firehose_8992_lite.mbn
Binary build date: May 13 2015 @ 14:41:37
QSAHARASERVER CALLED LIKE THIS: 'C:\Program Files (x86)\Qualcomm\QPST\bin\QSaharaServer.exe -p \\.\COM4 -s 13:C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\prog_emmc_firehose_8992_lite.mbn 'Current working dir: C:\Users\Amine\AppData\Roaming\Qualcomm\QFIL
Sahara mappings:
2: amss.mbn
6: apps.mbn
8: dsp1.mbn
10: dbl.mbn
11: osbl.mbn
12: dsp2.mbn
16: efs1.mbn
17: efs2.mbn
20: efs3.mbn
21: sbl1.mbn
22: sbl2.mbn
23: rpm.mbn
25: tz.mbn
28: dsp3.mbn
29: acdb.mbn
30: wdt.mbn
31: mba.mbn
13: C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\prog_emmc_firehose_8992_lite.mbn
09:28:26: Requested ID 13, file: "C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\prog_emmc_firehose_8992_lite.mbn"
09:28:26: 273568 bytes transferred in 0.360000 seconds (0.7247MBps)
09:28:26: File transferred successfully
NOTE: Target requested image 13 which is DeviceProgrammer. Forcing QUIT. This is by design, ** All is well ** SUCCESS!!
09:28:26: Sahara protocol completed
Sending Programmer Finished
Switch To FireHose
Wait for 3 seconds...
Max Payload Size to Target:49152 Bytes
Device Type:eMMC
Platform:8x26
Disable Ack Raw Data Every N Packets
Skip Write:False
Always Validate:False
Use Verbose:False
Binary build date: Sep 28 2015 @ 17:28:46
Build version: 15.09.28.17.28.46
09:28:30: INFO: FH_LOADER WAS CALLED EXACTLY LIKE THIS
************************************************
C:\Program Files (x86)\Qualcomm\QPST\bin\fh_loader.exe --port=\\.\COM4 --sendxml=rawprogram0.xml --search_path=C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818 --noprompt --showpercentagecomplete --zlpawarehost=1 --memoryname=eMMC
************************************************
09:28:30: INFO: Current working dir (cwd): C:\Users\Amine\AppData\Roaming\Qualcomm\QFIL\
09:28:30: INFO: Showing network mappings to allow debugging
09:28:30: INFO:
09:28:30: INFO: Trying to store 'rawprogram0.xml' in string table
09:28:30: INFO: Looking for file 'rawprogram0.xml'
09:28:30: INFO: User wants to talk to port '\\.\COM4'
_____
| ___|
| |__ _ __ _ __ ___ _ __
| __| '__| '__/ _ \| '__|
| |__| | | | | (_) | |
\____/_| |_| \___/|_|
09:28:40: {ERROR: It took 10.00000000 seconds to open port. Which is longer than 3.000. This indicates your target is not stable}
Writing log to 'C:\Users\Amine\AppData\Roaming\Qualcomm\QFIL\port_trace.txt', might take a minute
Log is 'C:\Users\Amine\AppData\Roaming\Qualcomm\QFIL\port_trace.txt'
Download Fail:FireHose Fail FHLoader Failrocess fail
Finish Download
port_trace.txt
Validating Application Configuration
Load APP Configuration
COM:-1
PBLDOWNLOADPROTOCOL:0
PROGRAMMER:True
PROGRAMMER:C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\prog_emmc_firehose_8992_lite.mbn
SEARCHPATH:C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818
RAWPROGRAM:
rawprogram0.xml
PATCH:
patch0.xml
ACKRAWDATAEVERYNUMPACKETS:False
ACKRAWDATAEVERYNUMPACKETS:100
MAXPAYLOADSIZETOTARGETINBYTES:False
MAXPAYLOADSIZETOTARGETINBYTES:49152
DEVICETYPE:eMMC
PLATFORM:8x26
VALIDATIONMODE:0
RESETAFTERDOWNLOAD:False
MAXDIGESTTABLESIZE:8192
SWITCHTOFIREHOSETIMEOUT:30
RESETTIMEOUT:200
RESETDELAYTIME:2
FLATBUILDPATH:C:\
FLATBUILDFORCEOVERRIDE:True
QCNPATH:C:\Temp\00000000.qcn
QCNAUTOBACKUPRESTORE:False
SPCCODE:000000
ENABLEMULTISIM:False
Load ARG Configuration
Validating Download Configuration
Image Search Path: C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818
RAWPROGRAM file path: C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\rawprogram0.xml
PATCH file path:C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\patch0.xml
Programmer Path:C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\prog_emmc_firehose_8992_lite.mbn
Process Index:0
Start Download
Program Path:C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\prog_emmc_firehose_8992_lite.mbn
Binary build date: May 13 2015 @ 14:41:37
QSAHARASERVER CALLED LIKE THIS: 'C:\Program Files (x86)\Qualcomm\QPST\bin\QSaharaServer.exe -p \\.\COM4 -s 13:C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\prog_emmc_firehose_8992_lite.mbn 'Current working dir: C:\Users\Amine\AppData\Roaming\Qualcomm\QFIL
Sahara mappings:
2: amss.mbn
6: apps.mbn
8: dsp1.mbn
10: dbl.mbn
11: osbl.mbn
12: dsp2.mbn
16: efs1.mbn
17: efs2.mbn
20: efs3.mbn
21: sbl1.mbn
22: sbl2.mbn
23: rpm.mbn
25: tz.mbn
28: dsp3.mbn
29: acdb.mbn
30: wdt.mbn
31: mba.mbn
13: C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\prog_emmc_firehose_8992_lite.mbn
09:28:26: Requested ID 13, file: "C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\prog_emmc_firehose_8992_lite.mbn"
09:28:26: 273568 bytes transferred in 0.360000 seconds (0.7247MBps)
09:28:26: File transferred successfully
NOTE: Target requested image 13 which is DeviceProgrammer. Forcing QUIT. This is by design, ** All is well ** SUCCESS!!
09:28:26: Sahara protocol completed
Sending Programmer Finished
Switch To FireHose
Wait for 3 seconds...
Max Payload Size to Target:49152 Bytes
Device Type:eMMC
Platform:8x26
Disable Ack Raw Data Every N Packets
Skip Write:False
Always Validate:False
Use Verbose:False
Binary build date: Sep 28 2015 @ 17:28:46
Build version: 15.09.28.17.28.46
09:28:30: INFO: FH_LOADER WAS CALLED EXACTLY LIKE THIS
************************************************
C:\Program Files (x86)\Qualcomm\QPST\bin\fh_loader.exe --port=\\.\COM4 --sendxml=rawprogram0.xml --search_path=C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818 --noprompt --showpercentagecomplete --zlpawarehost=1 --memoryname=eMMC
************************************************
09:28:30: INFO: Current working dir (cwd): C:\Users\Amine\AppData\Roaming\Qualcomm\QFIL\
09:28:30: INFO: Showing network mappings to allow debugging
09:28:30: INFO:
09:28:30: INFO: Trying to store 'rawprogram0.xml' in string table
09:28:30: INFO: Looking for file 'rawprogram0.xml'
09:28:30: INFO: User wants to talk to port '\\.\COM4'
_____
| ___|
| |__ _ __ _ __ ___ _ __
| __| '__| '__/ _ \| '__|
| |__| | | | | (_) | |
\____/_| |_| \___/|_|
09:28:40: {ERROR: It took 10.00000000 seconds to open port. Which is longer than 3.000. This indicates your target is not stable}
Writing log to 'C:\Users\Amine\AppData\Roaming\Qualcomm\QFIL\port_trace.txt', might take a minute
Log is 'C:\Users\Amine\AppData\Roaming\Qualcomm\QFIL\port_trace.txt'
Download Fail:FireHose Fail FHLoader Failrocess fail
Finish Download
09:28:30: INFO: FH_LOADER WAS CALLED EXACTLY LIKE THIS
************************************************
C:\Program Files (x86)\Qualcomm\QPST\bin\fh_loader.exe --port=\\.\COM4 --sendxml=rawprogram0.xml --search_path=C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818 --noprompt --showpercentagecomplete --zlpawarehost=1 --memoryname=eMMC
************************************************
09:28:30: DEBUG: Binary build date: Sep 28 2015 @ 17:28:46
09:28:30: DEBUG: Build Version: 15.09.28.17.28.46
09:28:30: INFO: Current working dir (cwd): C:\Users\Amine\AppData\Roaming\Qualcomm\QFIL\
09:28:30: INFO: Showing network mappings to allow debugging
09:28:30: DEBUG: Les nouvelles connexions seront m‚moris‚es.
09:28:30: DEBUG:
09:28:30: DEBUG: La liste est vide.
09:28:30: DEBUG:
09:28:30: INFO:
09:28:30: INFO: Trying to store 'rawprogram0.xml' in string table
09:28:30: DEBUG: ==================================================================================
09:28:30: DEBUG: ==================================================================================
09:28:30: INFO: Looking for file 'rawprogram0.xml'
09:28:30: DEBUG: 1. Calling stat(C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\rawprogram0.xml')
09:28:30: DEBUG: 2. Calling fopen('C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\rawprogram0.xml') with AccessMode='rb'
09:28:30: DEBUG: Trying get filesize, calling fseek()
09:28:30: DEBUG: Found 'C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\rawprogram0.xml' (5089 bytes)
09:28:30: DEBUG: 2. Calling fopen('C:\G4\8992_QFIL_signing_H818\8992_QFIL_signing_H818\8992_QFIL_signing_H818\rawprogram0.xml') with AccessMode='r'
09:28:30: DEBUG: Trying get filesize, calling fseek()
09:28:30: DEBUG: User set ZLPAWAREHOST to 1
09:28:30: INFO: User wants to talk to port '\\.\COM4'
09:28:40: DEBUG: port_fd=0xC8
_____
| ___|
| |__ _ __ _ __ ___ _ __
| __| '__| '__/ _ \| '__|
| |__| | | | | (_) | |
\____/_| |_| \___/|_|
09:28:40: {ERROR: OpenPort:5566 It took 10.00000000 seconds to open port. Which is longer than 3.000. This indicates your target is not stable
So where is the problem ? Shortcutting the two points is supposed to open the FireHose port but i tested with twezzers, cooper cable...ect nothing seem to work
any Idea ?
thank you
Click to expand...
Click to collapse
qfil needs the firehose.bin i know we dont have one for the sprint varient also have u tried any debrick imgs and sd card method?
Guys just flash the ls991 files and the problem with imei is fixable by flashing some files through fastboot
Do what this says and if you bricked your phone just flash ls991 files again
Only problem which remains is sd card read and write
But you will have a full functional phone
shamescool said:
Guys just flash the ls991 files and the problem with imei is fixable by flashing some files through fastboot
Do what this says and if you bricked your phone just flash ls991 files again
Only problem which remains is sd card read and write
But you will have a full functional phone
Click to expand...
Click to collapse
Please do not mislead other people and try not to answer questions if you didn't try the fixes yourself.
Depending on the bootstack of the CPU SD method might or might nor work.
In theory you can EMMC repair with LS991 but then you will have SecureBoot problems (Error 1006). I didn't try it yet but there is a method where you force off emmc verification by shorting EMMC CMD terminal to GND. But this requires very small soldering, opening the phone and removing the motherboard. The method is tried and working on 4PDA.
EDIT: @AZstyle The firehose are scams, the only working one is the ls991 which I think is a developer one because you will get fastboot access but I can't personally flash anything in LGUP.
When I flash all partitions but bootstack I get 1006 error. I didn't try the soldering method because I have a Medusa Box on the way. I will try USB Repair and if it does not work I will just RMA.
neutrondev said:
Please do not mislead other people and try not to answer questions if you didn't try the fixes yourself.
Depending on the bootstack of the CPU SD method might or might nor work.
In theory you can EMMC repair with LS991 but then you will have SecureBoot problems (Error 1006). I didn't try it yet but there is a method where you force off emmc verification by shorting EMMC CMD terminal to GND. But this requires very small soldering, opening the phone and removing the motherboard. The method is tried and working on 4PDA.
EDIT: @AZstyle The firehose are scams, the only working one is the ls991 which I think is a developer one because you will get fastboot access but I can't personally flash anything in LGUP.
When I flash all partitions but bootstack I get 1006 error. I didn't try the soldering method because I have a Medusa Box on the way. I will try USB Repair and if it does not work I will just RMA.
Click to expand...
Click to collapse
im not misleading anyone here im just sharing my experience
yes you will get 1006 problem by flashing partitions but at least you get a fully functioning phone
the way i mentioned is actually worked for another person here in this forum please test if you still have doubt
my phone is also a refurbished h811 which has a f500l mobo on it and flashing those ls991 files made the phone alive in h811 10n but i did nt have any imei or base band no camera too(even speaker and sensors didnt work)
so i tried flashing some partitions in fastboot and then i had my imei back and also the camera
then i edited f500 tot file with winhex and my phone bricked again(obviously)so i tried flashing ls991 again and now i have a fully functioning phone which cannot be said for sd card...my phone cant write or read any sdcard and its really pissing me of
any suggest for sd card?
H810_ARecovery
¿How to use or flash this files?, tell me please.
neutrondev said:
I bought a subscription from easy-firmware hoping that they have right emmc_firehose. They are scammers. I have a bricked LG G4 too and since now I have not found a way to unbrick it. Do not waste your time. For H815 the files are wrong and we also need nonfused emmc_firehose_programmer. Also the SD Card method is not working for me tried it with 10 different images and 4 different cards. I am investigating this issue and if I find a solution I will make a tutorial for all fellas that are in trouble.
Click to expand...
Click to collapse
u are right, i already tested all this ****, its appear that the only solution is to repair the emmc boot with octopus box or medusa box
next week i'll bring my G4 to a repair store to do this operation.
and I will keep u informed with the results
AZstyle said:
u are right, i already tested all this ****, its appear that the only solution is to repair the emmc boot with octopus box or medusa box
next week i'll bring my G4 to a repair store to do this operation.
and I will keep u informed with the results
Click to expand...
Click to collapse
I bought a medusa box and did the soldering myself. It will not work -_-. I will investigate further but it might need Emmc replacement. Did you try to flash with Qfil using LS991 programmer emmc_firehose? It is very important to know
neutrondev said:
I bought a medusa box and did the soldering myself. It will not work -_-. I will investigate further but it might need Emmc replacement. Did you try to flash with Qfil using LS991 programmer emmc_firehose? It is very important to know
Click to expand...
Click to collapse
Good Remark, I can't remember if I tested with LS911 files, I tested with H815 H818p without sucess.
Do you have the files for LS911? can u share them with me please so i'll give a try.
Thanks
What about that ?
and this
serestma said:
Hello, ¿you can share the links?, I need the files for LG H810.
Thank you in advance.
Click to expand...
Click to collapse
https://mega.nz/#F!1DhXTLAa!kH8MfkbeOKcUWt3T2R6cTQ
@AZstyle Do not flash with those files because I think you will need CPU swap. I think that programmer blows fuses for US version. I did that and now I can't repair it even with MEDUSA I can flash ls991 firmware it boots but with H815 NO.
the_naxhoo said:
I got the same problem with my H815T. It only allows me to flash the LS991 files, but I lose the imei
H810: https://mega.nz/#!55tACDZC!Ci1pjEr8_wr9Ng2SrPgj42MwxnGybo60de26w2gtimg
Click to expand...
Click to collapse
No Problem If You Loosed IMEI I Can Flash IMEI For You Just Poke Me On WhatsApp Only WhatsApp !!!
7000926368
Hope I Can Help You
Sent from my LS-4004 using Tapatalk
neutrondev said:
I bought a medusa box and did the soldering myself. It will not work -_-. I will investigate further but it might need Emmc replacement. Did you try to flash with Qfil using LS991 programmer emmc_firehose? It is very important to know
Click to expand...
Click to collapse
Yes I have flashed ls991 firehose . What do you need to know?
.
Sent from my LG-H815 using XDA Labs
neutrondev said:
I bought a medusa box and did the soldering myself. It will not work -_-. I will investigate further but it might need Emmc replacement. Did you try to flash with Qfil using LS991 programmer emmc_firehose? It is very important to know
Click to expand...
Click to collapse
Medusa Pro Box Works Like Charm !!!
I Fixed 7 LG G4 With It EMMC One
And 3 LG G4 With USB One
If Someone Have Medusa Pro Box And Unable To Fix With It Thats Sure That You Might Have Not Soldered Wire Correct Or Motherboard Has Hardware Problem
Sent from my LS-4004 using Tapatalk
steadfasterX said:
Yes I have flashed ls991 firehose . What do you need to know?
.
Sent from my LG-H815 using XDA Labs
Click to expand...
Click to collapse
Dont know where i find a ls992 firehose do you?
I bricked my g5 in a freak bad usb cord accident.

LineageOS 15 on S5 mini and SE Linux enforcement. Doesn't work well together

Hi,
I'm running LineageOS 15 (Android 8) on S5 mini. Everything is fine except one banking app that I really need. They validate on startup, whether the phone is rooted.
They in fact check if SE Linux is in enforcement mode. Here is the log snippet:
Code:
11-23 18:44:54.894 2259 2521 I ActivityManager: START u0 {act=android.intent.action.MAIN cat=[android.intent.category.LAUNCHER] flg=0x10200000 cmp=com.fidor.fsw/com.gft.fidor.views.splash.SplashScreenActivity bnds=[350,815][506,994] (has extras)} from uid 10036
11-23 18:44:54.935 2084 2084 I display : [DYNAMIC_RECOMP] HWC_2_GLES by low FPS(0)
11-23 18:44:54.969 2259 4027 I ActivityManager: Start proc 20526:com.fidor.fsw/u0a119 for activity com.fidor.fsw/com.gft.fidor.views.splash.SplashScreenActivity
11-23 18:44:55.190 2084 2084 I display : [DYNAMIC_RECOMP] GLES_2_HWC by high FPS(39)
11-23 18:44:55.229 20526 20540 I vndksupport: sphal namespace is not configured for this process. Loading /system/lib/egl/libEGL_mali.so from the current namespace instead.
11-23 18:44:55.326 20526 20540 D libEGL : loaded /system/lib/egl/libEGL_mali.so
11-23 18:44:55.339 2084 2133 W GrallocMapperPassthrough: buffer descriptor with invalid usage bits 0x400
11-23 18:44:55.356 20526 20540 I vndksupport: sphal namespace is not configured for this process. Loading /system/lib/egl/libGLESv1_CM_mali.so from the current namespace instead.
11-23 18:44:55.362 20526 20540 D libEGL : loaded /system/lib/egl/libGLESv1_CM_mali.so
11-23 18:44:55.586 20526 20540 I vndksupport: sphal namespace is not configured for this process. Loading /system/lib/egl/libGLESv2_mali.so from the current namespace instead.
11-23 18:44:55.588 20526 20540 D libEGL : loaded /system/lib/egl/libGLESv2_mali.so
11-23 18:44:56.455 20526 20526 I putmethod.latin: type=1400 audit(0.0:774): avc: denied { read } for name="/" dev="tmpfs" ino=3689 scontext=u:r:untrusted_app_25:s0:c512,c768 tcontext=u:object_r:rootfs:s0 tclass=dir permissive=1
11-23 18:44:56.455 20526 20526 W putmethod.latin: type=1300 audit(0.0:774): arch=40000028 syscall=334 per=800008 success=yes exit=0 a0=ffffff9c a1=898ca354 a2=4 a3=0 items=1 ppid=2066 auid=4294967295 uid=10119 gid=10119 euid=10119 suid=10119 fsuid=10119 egid=10119 sgid=10119 fsgid=10119 tty=(none) ses=4294967295 exe="/system/bin/app_process32" subj=u:r:untrusted_app_25:s0:c512,c768 key=(null)
11-23 18:44:56.455 1978 1978 W auditd : type=1307 audit(0.0:774): cwd="/"
11-23 18:44:56.455 1978 1978 W auditd : type=1302 audit(0.0:774): item=0 name="/sbin" inode=3689 dev=00:12 mode=040755 ouid=0 ogid=0 rdev=00:00 obj=u:object_r:rootfs:s0
11-23 18:44:56.455 1978 1978 W auditd : type=1327 audit(0.0:774): proctitle="com.google.android.inputmethod.latin"
11-23 18:44:56.455 1978 1978 W auditd : type=1320 audit(0.0:774):
11-23 18:44:56.527 2259 3192 W ActivityManager: Force finishing activity com.fidor.fsw/com.gft.fidor.views.splash.SplashScreenActivity
Since LineageOS sets SELinux by default into permissive, this check fails and the app crashes. I'm able to set it to enforced with "SE Linux mode changer" or any other app of that kind, but immediately after the change the phone starts eating 100% cpu and modem (neither internet, nor SMS/phone calls) aren't working, which makes me think LineageOS doesn't work really well in enforcement mode of SE Linux. But the app itself launches just fine with SELinux in enforced.
I'm not an expert in Android and SELinux, but would like to know if there is a way:
to workaround the check we see in the logs and work with the app in permissive mode
to make LineageOS work correctly under enforced
PS. It doesn't matter which way to set the SELinux mode. Whatever is done - through kernel, in init.d or in adb shell, the symptoms are exactly the same after the change.
Thanks
bytes85 said:
Hi,
I'm running LineageOS 15 (Android 8) on S5 mini. Everything is fine except one banking app that I really need. They validate on startup, whether the phone is rooted...
Click to expand...
Click to collapse
I don't have this device but, your best bet is to post this question within the following Unofficial LineageOS (since there's no Official LineageOS Oreo released yet) thread for your device.
https://forum.xda-developers.com/showthread.php?t=3678205
Good Luck!
~~~~~~~~~~~~~~~
I DO NOT PROVIDE SUPPORT VIA PM UNLESS ASKED/REQUESTED BY MYSELF.
PLEASE KEEP IT IN THE THREADS WHERE EVERYONE CAN SHARE

Categories

Resources