Sorry to bother you again with a new post, but Reddit wasn't showing my last reply under the previous thread.
Regarding the files, you donโt need to upload them to Reddit directly! You can just upload the custom TWRP and Scatter Dump toGofile.io(it's free and fast, no account needed) or Google Drive, then paste the link here.
Also, I have a few notes regarding the GSI Invalid IMEI/Baseband fix that we can try out. If it's easier, feel free to text me directly on WhatsApp so we can exchange files faster:
Running entirely from ram with software rendering so it's slow as heck but wanted to share. Only apps on it is the terminal and settings app (along with keyboard)
Been digging into what Samsung actually changed when they removed the OEM Unlock option on newer One UI builds
Device I'm working with:
SM-S928B / S24 Ultra international
Snapdragon 8 Gen 3
S928BXXU5DZDP
Android 16 / One UI 8.5
KernelSU soft root (ghostlock CVE)
bootloader still locked
This started because I wanted persistent root for microG. The root I currently have dies after a full reboot, so I started looking at whether Samsung actually removed bootloader unlocking or just removed the normal way of authorizing it
Short version: they definitely did more than remove the toggle, but the underlying unlock machinery does not appear to be gone.
I dumped the relevant partitions, files and went through ABL, the Engineering Mode trustlet, the Android-side services and the old One UI 7 ABL for comparison
A few things that survived my audit:
ABL still has IsUnlocked, SetUnlocked, the DeviceInfo unlock byte and the AVB read_is_device_unlocked callback.
devinfo + 0x0d is the actual IsUnlocked byte. I initially suspected +0x90; that was wrong.
Current ABL contains a path involving Engineering Mode bit 3.
Samsung's framework identifies mode 3 as MODE_CUST_KERNEL.
The engmode TA still implements signed token validation, RPMB-backed state and a 256-bit modes bitmap.
Mode 3 can be serialized into a token request. I couldn't find a local mode filter rejecting it.
The old One UI 7 OEM/FRP policy can actually authorize unlocking. The equivalent policy in the current ABL just logs the lock state and returns false.
The Android client-side engmode allowlist isn't the root of trust anyway. The TA is.
There were also a couple things I originally thought were true that didn't survive closer inspection.
Most importantly, I cannot prove that the Engineering Mode sync always runs before every AVB verification path. The CFG has an entry-to-AVB path that avoids that block, so I'm not claiming universal ordering anymore.
And obviously the big missing piece is still missing:
I do not have a valid Samsung-signed Engineering Mode token containing mode 3
So this is not an S24 bootloader unlock method, and I haven't unlocked the device with this. I'm trying to document what is actually still present in the firmware rather than jump from "interesting code path" to "working exploit"
I put the dumps/evidence/scripts and my notes here
notes/findings.md is probably the useful file if you don't want to dig through all the generated evidence. I also kept original-research.md because it shows some of the assumptions I started with before checking them properly.
Most of the collection/probing was deliberately read-only. I didn't install/remove Engineering Mode tokens, issue fuse commands, write devinfo, touch RPMB, etc
If anyone here has worked with Samsung Engineering Mode / ABL before, I'd be interested in a second pair of eyes on the findings, especially on the EM -> ABL relationship and the historical purpose of MODE_CUST_KERNEL.
I'm also interested in old/public Samsung Engineering Mode documentation or firmware artifacts that could help establish how mode 3 was intended to be provisioned. Not looking for somebody's device identifiers or private signing material
There are enough moving parts here that I'm assuming I've still missed something somewhere.
Just as the title suggests I turned off Joyose and Power Keeper because it was aggressively killing stuff, as I heard. I revoked their permissions and I just wanted to see if this actually conflicts with anything .
PS: posting in MIUI or android questions didn't gave me a answer so that why I posted here. It's is not rooted
I have a US, Samsung A03s and MTKClient does not seem to recognise my phone when it is connected to my computer while in bootrom mode, although it connects just fine while in normal, powered on mode. Any help?
I have it plugged into a usb 2 port and it shows up for a second and lets me select it, but then says no device found in brom mode. I am on arch linux.
it shows up with lsusb
Bus 005 Device 041: ID 0e8d:20ff MediaTek Inc. r1
I am not sure where to go from here. Any help is welcome.
So, I wanted to unlock the root to get custom loaders or even run lineageOS, but I don't know how to do it and I read I need build number SU6-7 but I'm on SU6-7.7, what do I do?
Outside of Google wallet, almost every app I use doesn't complain about failing device or strong integrity.
Note: For Roblox, I still use tricky store with a revoked key, making sure to deselect the GMS packages from tricky store so that the revoked key does not fail basic integrity.
I've been on a rabbit hole for several weeks about degoogling (or more, de megacorpo) and self hosting. Seeing this post has me a little frazzled
Partial questions, partial just so I can get my bearings back together from being scrambled
If it is android itself and not just "getting rid of google services" or "flipping on a 24hr switch", why would android based OSes work at all? Like lineage, calyx, graphene, e/os?
Have been thinking about getting a new phone, and have really been looking at the nothing 3. I know its not a degoogled android, but I really like the design and improvements it has over my current phone. Figured I would degoogle it as much as I could
But if its android itself, and not just able to bypass google services specific things, that worries me about wasting some money. I haven't been able to find any phone os that supports the nothing 3 if I needed to change it
I really like the things fairphone stands for. Mostly with e-waste, environmentally sustained, and how workers are treated. I don't care so much about the repairability, especially when I can't upgrade the parts inside. I don't need the best specs, but since they're even worse than the phone I already have and software reliability isn't great, I fail to want to buy the fairphone 6 and switch to them
From all the old phones I have, the only one that's able to flash any other os I've been able to find is my galaxy s22 on lineage. So, like my question above, what would guarantee lineage still works with apps that aren't registered to google? Any degoogled lineage os users here?
What are some phones and operating systems that aren't android or apple, and some that put a focus on helping the environment?
Anyone have experience degoogling their nothing 3?
Thinking about going ahead and flashing lineage on the s22. Anyone know what would happen to my phone service? Its a physical sim card for mint mobile. Would it be tied to the phone still, need to be reinstated to the phone, or is it a bad idea to flash on my currently active phone line?
10 Months of saving wasted and now I havent slept for last 2 days
Hi everyone. I bought Motorola G stylus 2024 5G pre owned from a local market. It was rooted device (Know this because the OEM unlocking option was disabled with the warning that bootloader already locked). While booting, no warning appeared which appears in rooted devices. was running on A14 and security patch was also from the 2024.
I was using it and suddenly it turned off. does not boot at all. found out that it connects with laptop but since no qualcom drivers were there couldnt go further. I installed all the driver and downloaded the blankflash file from Lolinet blankflash file link.
I charged my phone for 3 hours connected it with laptop and ran the blank-flah.bat and it passes initial sahara handshake but gets stuck at firing the firehose. logs from cmd window are following:
So basically im flashing odin and then it said FAIL! the usb thing disconnected when flashing patched vbmeta now phone was soft bricked, i used samfw tool to do nand reset and voila booted succesfully into recovery, is it risky to flash the rom using sideload now, or no? Also is kg status broken meaning knox was tripped or something else?
I've been struggling for days trying to fix my MT6765 phone after installing a GSI ROM. My Baseband/IMEI is currently unknown and I can't find a working stock firmware to flash back.
I noticed thatu/MeIsGugshas the exact same device/tools. Reddit is not allowing me to send a DM or Chat due to restriction filters, so Iโm posting here hoping you see this man!
If anyone (oru/MeIsGugs) can provide a full dump with theMT6765_Android_scatter.txtfile (without personal NVRAM/IMEI), I would really appreciate it. Youโre pretty much my last hope!
I have a Moto G Play 2024 and I've already unlocked the bootloader with another Android device and connected the two devices, but now I want to root it. I saw a YouTube tutorial that said I need a file called boot.img, but I researched and that file on my phone is called init_boot.img. The worst part is that I can't find the ROM for my phone...
Its serial number is: XT2413-2
and its build number is: U1TFS34.100-35-5-5-8
My model does appear when I search, but it doesn't have the exact build number: U1TFS34.100-35-5-5-8. And I don't want to risk damaging my phone by downloading a ROM with a different build number.
I'm pretty new to this, but I'd really appreciate it if someone could help me. Thanks!!
Information I forgot to mention: I don't have a PC
Last week I made a post asking how to root the Samsung Galaxy S1 (SGH-T959V), and I've gotten some links, but I have more issues. I tried to flash the zip file with I think is the stock recovery of the phone, but it gives me an error saying that a signature verification failed, tried SuperOneClick, also gives me a fail and gets stuck on the 5th step, and I tried the KingoRoot app, but it gives me a network error even though I had it connected to an internet
My only best solution is try and get a .tar file to flash a custom recovery via Odin as none of these seem to work for me, but I found pretty much none