mettle |
Date: Friday, 07.10.11, 17:26 | Message # 1 |
Forum posts: 10
Awards: 0
| Table of contents: 1. Hboot information about the exploit. 2. Downgrading 2.1 Notes 3. Full root(Updated 2.2 root) 4. Links
I will aim to make it so this exploit can be ported to other devices to help downgrade bootloaders and software. Please read the entire thread before flashing anything and trying this.
Hboot Hboot uses a hidden partition to check everything it flashes against, this partition is "misc", or hboot -1, or on the shift mmcblk0p17(hboot itself is at mmcblk0p18). Some raw dumps of this partition using strings to filter ascii strings brings out this type of dump. Locked bootloader for the evo shift's dump "SPCS_001 DeviceWarmBoot CE Serial InUse Debug Cable Ena CE USB InUse ClearAutoImage 2.76.651.4 FNOC FNOC"
Unlocked bootloader for the verizon thunderbolt "VZW__001 DeviceWarmBoot CE Serial InUse Debug Cable Ena CE USB InUse ClearAutoImage 1.02.605.6 FNOC FNOC"
Eng spl unlocked evo shift "FN0C FN0C FN0C"
Now the place to focus at is the version numbers, 2.76.651.4. Hboot will check all items you try to flash via hboot or ruu utility against this number and if it is lower than what you are trying to flash, it will allow you to proceed in flashing through hboot, or ruu. If the number is higher, it will reject the flash. If the number doesn't exist(like in the eng spl) it will assume it is able to flash it(ONLY TESTED ON ENG SPL, not locked bootloaders). So by dumping the TB's misc partition into our own, we made it so the locked hboot would accept flashes. Either by RUU or hboot.
We believe the package you flash still needs to be signed though so that only leaves you with official ruu's and extracted ruu zips.
same method as used on the evo part 2 thread by toastcfh at xda. only diff is shift is emmc and evo was mtd. shift emmc partitions are a bit more in number and named differnetly when compared to the evo mtd partitions. on the evo this partition was labeled as "misc" in /proc/partitions. the misc partition being flashed holds the software version number which hboot checks against to verify whether or not it will allow an RUU to be loaded.
How to downgrade your device For the shift, will be different on other devices with a bit of modding. 1. Temproot(With Fre3vo for the shift) http://forum.xda-developers.com/showthread.php?t=1185243
2. Move the file misc.img to the root of your sdcard, and PG06IMG.zip too if you plan on flashing through hboot.
3. Modify the misc partition to bypass the version check, type the following in an adb shell or a terminal emulator on your phone. Code dd if=/sdcard/misc.img of=/dev/block/mmcblk0p17 Note for other devs: misc.img is the image from the TB, could be other images as long as it has a lower version number.
4. This is up to you, you can either use the ruu utility to revert or the PG06IMG.zip in hboot. I'll include links to both. Since both utilities check the misc partition, both are able to flash =)
5. Reboot and then full root like normal on your downgraded device.
Notes 1. When flashing hboot/using this exploit it always flashes twice/stops early and recontinues. Don't worry about it, this is normal(Sometimes it looks like more than 2 but just chill out).
2. Some SDcards are not recognized by hboot, so you will either have to switch cards for this operation or use the ruu utility method.
3. Remove the PG06IMG from your sdcard after flash, or hboot will pick it up next time.
Full root for downgraded 2.2 Flash ENG bootloader
1. Download these files and extract them to the root of your sdcard: www.thebcblends.com/shift/Shift-root.zip 2. Obtain temproot from z4Root, visionary, OR CM's temproot wiki 3. Flash hboot with Engineer SPL: Code dd if=/sdcard/Shift/hboot_eng.nb0 of=/dev/block/mmcblk0p18 4. Boot into bootloader and check for S-OFF
Flashing a recovery 1. Grab latest shift recovery from: http://www.koushikdutta.com/2010/02/clockwork-recovery-image.html 2. Make sure you're temprooted(may have to temp root again) 3. Install recovery from rom manager Alternative install can be done if you grab another recovery's recovery.img and do one of the following below. a. Okay this is for those with fastboot - flash the recovery with fastboot: fastboot flash recovery recovery.img b. This is for those where fastboot doesn't work or they don't have it - 1. Place recovery.img on the root of your sdcard, then type the command below. Code dd if=/sdcard/recovery.img of=/dev/block/mmcblk0p21
Full root/Rom flashing Well I know you don't have anything you want to save from the 2.2 ruu since it's just a stock flash, so I am going to leave it off here as flash whatever rom you want over the new system via recovery and you should end up with a fully rooted android. Just remember to wipe data/factory reset after flash.
Links - MD5Sums aren't terribly important here as the files will not flash if they are not correct due to the signatures. Fre3vo temp root for GB - http://forum.xda-developers.com/showthread.php?t=1185243 misc.img for the misc partition - http://dl.dropbox.com/u/41040697/misc.img MD5Sum: c88dd947eb3b36eec90503a3525ae0de Misc.img mirror(You guys took down my second dropbox.....trying a different site now): http://www.box.net/shared/0l8ex73zne0tfr10ob69 Second mics.img mirror: http://dl.dropbox.com/u/15373824/misc.img Another mirror for misc.img: http://dev-host.org/a9dbnuzgb9qv/misc.zip (Thanks Fdxrider)
Official ruu file for downgrading to 2.2 - http://www.multiupload.com/15N2D30H6C MD5SUM: a4b880954d2ac29d5bdf0dade9dede3c PG06IMG for hboot downgrading to 2.2 - http://dl.dropbox.com/u/41040697/PG06IMG.zip MD5SUM: d20be478fd860b80f5e800c958f79077 Mirror for PG06IMG(First link went down temporarily due to generating too much traffic on my account, good job guys xD) - http://dl.dropbox.com/u/15373824/PG06IMG.zip Mirror for PG06IMG: http://dev-host.org/xmlaaco0s2ph/PG06IMG.zip
2.2 root [Bcnice guide]- http://forum.xda-developers.com/showthread.php?t=932153 Cm's rooting method(For those without z4root or visionary) - http://wiki.cyanogenmod.com/wiki/HTC_Evo_Shift_4G:_Full_Update_Guide
Credits Otaking71 - Discoverer of this exploit for the shift and working throughout the night to establish it as a working downgrade. Stuke00 - Fre3vo temp root for 2.3.3 Joeykrim - Donating that history for the curious minds.
|
|
|
|