Welcome to XDA

Search to go directly to your device's forum

Register an account

Unlock full posting privileges

Ask a question

No registration required
Post Reply

DEV ONLY - NAND access + Full Unlock for Lumia 710 & 800

OP biktor_gj

19th April 2012, 03:01 PM   |  #561  
jessenic's Avatar
Senior Member
Thanks Meter: 283
 
447 posts
Join Date:Joined: Sep 2010
Donate to Me
More
Quote:
Originally Posted by biktor_gj

This is for QPST when in bootloader mode (qcsbl)
If only we could find the drivers for qualcomm diagnostics interface with windows phone running (serial mode in diagnostics app,0x319b)...


Sent from my GT-I9100 using XDA

I'm 99% sure that these drivers won't work for Nokias, but here are the Samsung Omnia 7 QPST drivers: https://hotfile.com/dl/150390665/a9c...050.0.exe.html
19th April 2012, 07:22 PM   |  #562  
Bph&co's Avatar
Senior Member
Thanks Meter: 100
 
108 posts
Join Date:Joined: Apr 2012
More
Hi,

I asked in previous posts for people to hex edit the second partition(the bootloader),
but seems better not, unless you have a recovery method.

The first 710 that felt victim to unsolicited hex editing of the bootloader code:

Code:
Init connection...Done
Enter flash mode...Done
Enter bootloader mode...Done
Boot version:	0.0.0.1
------------------------------------------
Flash File:	RM803_12w07_prod_generic_nokia_osbl.esco
Sending certificate...Done.
Sending file...Failed(err: 0x30047).
Did comment out the cert checking functions, but forgot to set this flag:
Code:
ROM:04538458 1C 08 9F E5                 LDR     R0, =unk_45DE83C
ROM:0453845C 00 00 D0 E5                 LDRB    R0, [R0]
ROM:04538460 00 00 50 E3                 CMP     R0, #0
ROM:04538464 8C 08 9F 05                 LDREQ   R0, =0x30047
ROM:04538468 7D 00 00 0A                 BEQ     bad_err
Hehe, now need to buy another phone.

I could not find an alternative restore method via test point, as suggested earlier
in the thread. The only possible pins for TP access could be GPIO35 or GPIO160
(not likely, seems WD dissable for JTAG access). Shorting to GND or Vcc will not
give different USB device.

JTAG seems to be alive, at least the RST and HOLD pins respond, did not check
actuall comm.

I am attaching the testpoints description, if somebody wants to push this further.

BR
Attached Files
File Type: zip 710_tp.zip - [Click for QR Code] (100.5 KB, 100 views)
19th April 2012, 07:52 PM   |  #563  
biktor_gj's Avatar
OP Senior Member
Thanks Meter: 235
 
665 posts
Join Date:Joined: Jan 2008
Ouch! You could have tried putting nokia's sbl on top of EMMCBOOT and boot it from there (difficult to press the key just in time but...) Does it still do something or is it dead dead?

LK Bootloader update: Well not much to update really, nothing I've done so far works... Even tried contacting the guy who wrote the panel kernel module for the n9 but I think he was fired from Nokia... or at least his mail address has disappeared (no such user). I have tried to force every gpio up, just to make it vibrate, or turn the led flash on or something but no luck so far... will keep on trying anyway

By the way, if someone's bored and wanting to look for datasheets, here's the panel: Samsung AMS391PJ01
Last edited by biktor_gj; 19th April 2012 at 08:04 PM.
The Following User Says Thank You to biktor_gj For This Useful Post: [ View ]
19th April 2012, 08:15 PM   |  #564  
Member
Thanks Meter: 2
 
38 posts
Join Date:Joined: Apr 2012
Donate to Me
Quote:
Originally Posted by Bph&co

Hi,

I asked in previous posts for people to hex edit the second partition(the bootloader),
but seems better not, unless you have a recovery method.

The first 710 that felt victim to unsolicited hex editing of the bootloader code:

Code:
Init connection...Done
Enter flash mode...Done
Enter bootloader mode...Done
Boot version:	0.0.0.1
------------------------------------------
Flash File:	RM803_12w07_prod_generic_nokia_osbl.esco
Sending certificate...Done.
Sending file...Failed(err: 0x30047).

BR

well well well...im experiencing this same problem. i opened the second partition (starting at sector 1001) and replaced everything there onwards with the contents of a new osbl and wasnt able to flash with NCS nor NSS. if you get a resolution let me know. i am trying to work on one now. what i am trying to do is extract the osbl and replace the .mbn file in there with another. i did that and now when i tried to flash with NSS it didnt fail. however the other file to be flashed failed. there is where i am stuck at the moment
19th April 2012, 08:19 PM   |  #565  
Recognized Developer
St.Petersburg
Thanks Meter: 2,044
 
1,478 posts
Join Date:Joined: May 2009
Quote:
Originally Posted by biktor_gj

Ouch! You could have tried putting nokia's sbl on top of EMMCBOOT and boot it from there (difficult to press the key just in time but...) Does it still do something or is it dead dead?

LK Bootloader update: Well not much to update really, nothing I've done so far works... Even tried contacting the guy who wrote the panel kernel module for the n9 but I think he was fired from Nokia... or at least his mail address has disappeared (no such user). I have tried to force every gpio up, just to make it vibrate, or turn the led flash on or something but no luck so far... will keep on trying anyway

By the way, if someone's bored and wanting to look for datasheets, here's the panel: Samsung AMS391PJ01

Biktor, btw, my friend with Lumia 710 built a rom with full unlock and it worked. Probably you've just missed an OSBuilder's option about XIP on "Building - 2" tab.
19th April 2012, 08:30 PM   |  #566  
Bph&co's Avatar
Senior Member
Thanks Meter: 100
 
108 posts
Join Date:Joined: Apr 2012
More
Quote:
Originally Posted by biktor_gj

Ouch! You could have tried putting nokia's sbl on top of EMMCBOOT and boot it from there (difficult to press the key just in time but...) Does it still do something or is it dead dead?

Hi,

The phone works fine, just not able to flash any file or replace the badly edited
loader.

Yes, i got the idea to include backup copy in the next partition, but too late now.

BR
19th April 2012, 08:31 PM   |  #567  
biktor_gj's Avatar
OP Senior Member
Thanks Meter: 235
 
665 posts
Join Date:Joined: Jan 2008
Quote:
Originally Posted by ultrashot

Biktor, btw, my friend with Lumia 710 built a rom with full unlock and it worked. Probably you've just missed an OSBuilder's option about XIP on "Building - 2" tab.

I'm pretty sure you're right I have yet to try your last advice and see if that at least works... but there's so much to do and have so little time (sbl unlock, make emmcboot actually boot something, build a kernel that also boots...

I wish I would have at least haRet to retrieve memory maps and lcd on sequences.. it's a shame microsoft messed it all...

Will retry the full unlock for the 800 tomorrow, see what I can do!
19th April 2012, 08:33 PM   |  #568  
Bph&co's Avatar
Senior Member
Thanks Meter: 100
 
108 posts
Join Date:Joined: Apr 2012
More
Quote:
Originally Posted by deylo

well well well...im experiencing this same problem. i opened the second partition (starting at sector 1001) and replaced everything there onwards with the contents of a new osbl and wasnt able to flash with NCS nor NSS. if you get a resolution let me know. i am trying to work on one now. what i am trying to do is extract the osbl and replace the .mbn file in there with another. i did that and now when i tried to flash with NSS it didnt fail. however the other file to be flashed failed. there is where i am stuck at the moment

Hi,

When you extract the loader from the esco file and manually put in the partition -
all works fine after restart. Editing strings or not important code does not prevent
the loader from working - nothing is checked on the loader before it gets execution
anyway.

But i just did a bad edit. In your case - maybe you haven't cut the correct part
before inserting it.

BR
19th April 2012, 08:43 PM   |  #569  
jessenic's Avatar
Senior Member
Thanks Meter: 283
 
447 posts
Join Date:Joined: Sep 2010
Donate to Me
More
Quote:
Originally Posted by biktor_gj

By the way, if someone's bored and wanting to look for datasheets, here's the panel: Samsung AMS391PJ01

That is the N9 panel. Do they have the same panel in the Lumia 800? (I've always thought that they use a 854x480 for Lumia 800 too, as there are references to that resolution in the Lumia 800 firmware)
19th April 2012, 08:50 PM   |  #570  
biktor_gj's Avatar
OP Senior Member
Thanks Meter: 235
 
665 posts
Join Date:Joined: Jan 2008
Quote:
Originally Posted by jessenic

That is the N9 panel. Do they have the same panel in the Lumia 800? (I've always thought that they use a 854x480 for Lumia 800 too, as there are references to that resolution in the Lumia 800 firmware)

Yeah user CareDood tell me he swapped them and they both worked, so I disassembled the lumia and checked it out. It seems the trick on the Lumia is they use the lower part of the display to make the stupid buttons glow. What a waste of screen.

The problem is there are no available list of gpios, and the n9 code is hardcoded for the omap DSS, so porting it over to an entirely different architecture isn't easy, at least for me... I can't even make the keys respond well maybe I can, but I have no way of debugging it without a screen...

Post Reply Subscribe to Thread

Tags
android, bootloader, full unlock, interopunlock, nand
Previous Thread Next Thread
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes