[GUIDE][17.06.2019] RMM/KG bypass - Root/Install TWRP on Exynos Samsung after 2018

Search This thread

corsicanu

Recognized Developer
UPDATE 17.06.2019 - NEW RMM/KG bypass patch

UPDATE 23.02.2019 - Pie and more

Please take some time and read carefully the whole post. I am not and i won`t be responsable for anything.

Disclaimer
I am not responsible for bricked devices, dead SD cards, thermonuclear war, or you getting fired because the alarm app failed.
Please do some research if you have any concerns about this guide!
YOU are choosing to make these modifications, and if you point the finger at me for messing up your device, I will laugh at you.
Flashing any custom binary will trigger knox and you may lose your warranty. Make sure you know what you do to your device.

Introduction
December 2017 update (for some even older) brought us a different lock, that creates panic among users as usual. As described here by my friend @BlackMesa123, this is not a lock to developement, rather an advanced lock for theft or scams. This has a bypass too, specially when you`re the owner of the device.

How it works
This lock is in bootloader, but the trigger to it is inside the system, it`s hard to reproduce, but usually happens when you plug another country sim than your firmware country, because changing the country might not seem as a traveling guy and more like a thief. If you are on stock rom all this time, you might not feel the change, as the device reboots and wipes data, but it will eventually boot. The nice thing comes if you already have custom binary installed (rooted kernel or twrp), as you can`t boot anymore because bootloader is preventing you to boot on custom binaries and alter the system.

Devices confirmed to have the lock:
  • Any other Samsung device manufactured after 2017
  • Samsung Galaxy S9 & S9+ - SM-G960F & SM-G965F
  • Samsung Galaxy Note 8 - SM-N950F
  • Samsung Galaxy S8 & S8+ - SM-G950F & SM-G955F
  • Samsung Galaxy A8 & A8+(2018) - SM-A530F & SM-A730F
  • Samsung Galaxy A Series (2017) - SM-A320F/FL, SM-A520F & SM-A720F
  • Samsung Galaxy Note FE - N935F

How to know if you are locked
There are 3 things at this chapter:
1. "Only official released binaries are allowed to be flashed" message shows up and now you know for sure you got locked outside your phone
2. Missing OEM unlock toggle in developer settings, if your device has FRP
3. "RMM state = Prenormal" in download mode

How to unlock
1. As i personally did, and other users reported, if you face any of the things above, flash latest full stock fw of your country with Odin, boot up, don`t reboot, don`t unplug the sim and don`t disconnect the network connection for 7 full days (168h). It seems that after 7 days of uptime, RMM state resets and you can flash TWRP again without issues. You can see uptime in settings/about device/status.
2. Some users reported this guide was working in first Oreo fw releases, can't guarantee it still works.

How to avoid getting locked again
Unfortunately bootloader can`t be reverted to older revisions, so we need to live with this. My friend @BlackMesa123 made some investigation and found out how to disable this lock. After waiting those 7 days, go to settings/developer option and enable OEM unlock. In order to never get locked again, flash TWRP for your device (install instructions below), boot into TWRP (do not boot into rom yet as you might get locked again), download and flash his fix from here (don`t forget to thank him too for his findings).
You can keep this zip near and flash it after flashing any custom rom, to be sure you don`t get locked again. The zip contains an universal script that disables the services responsable. Can be flashed on any device, if the device has the lock, won`t get locked again, if not, nothing will happend. I like to say "better safe than sorry".

How to safely install TWRP
Considering you are already unlocked (waited those 7 days), follow the next steps carefully:
  1. Make sure you downloaded latest Odin, samsung usb drivers installed, latest RMM-State_Bypass fix (download links are in #2 post) and latest TWRP available for your device
  2. Put RMM-State_Bypass.zip in external sdcard
  3. Go to settings/Developer options and enable OEM unlock (If you don't see developer settings, go into Settings/About phone/Software info and tap "Build number" 10 times to show Developer options menu)
  4. Reboot the phone into download mode and connect the usb cable
  5. Open Odin, go into options and untick Auto-reboot and put the TWRP tar file in AP tab of odin, hit Start and wait
  6. When Odin shows "PASS", take your device in hands, disconnect the usb cable and press simultaneously the "Power" + "Vol. Down" + "Vol. Up" buttons until the downoad mode disappears
  7. At the precise moment the screen becomes black, immediately release the "Vol.Down" button and press the "Vol. Up" + "Power" buttons during 10 to 15sec to forcefully enter TWRP
    ***Don't boot into rom because it will lock your device again!!!!
  8. Once the custom recovery booted, swipe to "Allow modification" and flash RMM-State_Bypass.zip as normal zip
Now you can reboot into rom and hopefully never get locked again.
If any of above steps fail, redo from step 1, more carefully this time.


How to safely root
Considering you already unlocked (waited those 7 days) and you have TWRP installed, follow the next steps carefully:
  1. Download root zip and no-verity-opt-encrypt-6.0 (download links are in #2 post) and drop the zips into external sdcard
  2. Boot into TWRP and swipe "Allow modifications"
  3. Go into Wipe menu and select "Format data" - note that this will erase all your data including internal storage
  4. Reboot recovery, swipe to "Allow modification" and flash RMM-State_Bypass.zip
  5. Flash no-verity-opt-encrypt-6.0 zip downloaded at step #1 to disable data partition encryption
  6. Flash root zip downloaded at step #1
  7. Reboot the phone into system
  8. After booting up in setting wizard make sure to uncheck diagnostic data
If any of above steps fail, redo from step 1, more carefully this time.


You can read more about it here here, here, here, here or here.

Credits
@BlackMesa123
@RicePlay33
@Yahia Angelo
@TaifAljaloo
@ananjaser1211
 
Last edited:

corsicanu

Recognized Developer
Useful links

FAQ
Q: TWRP can't mount data partition, what to do?
A: Make sure you formatted data partition.

Q: Phone is not booting even after 20 minutes?
A: Try to reboot. If still not booting, make sure you formatted data partition.

Q: How to format data partition?
A:
ymlnQUE.jpg


Q: Why do i need to format data partition?
A: Because old rom encrypted your data partition and new rom can't decrypt and use that content / root needs access to data partition to place misc files / phone not booting after flashing root until data partition gets formatted.

Q: Why not formatting data at twrp install?
A: Phone will boot even if data is encrypted if you don't root. Also system partition is not encrypted meaning you can flash RMM-State_Bypass anyway.
 
Last edited:

costafabiof

Senior Member
Mar 4, 2018
92
14
Jales
Please take some time and read carefully the whole post. I am not and i won`t be responsable for anything.

[*]After booting up in setting wizard make sure to uncheck diagnostic data
[/LIST]

The above item, diagnostic data, may have been the reason for blocking again the RMM STATE, since it was the only thing I did not do?
 

corsicanu

Recognized Developer
Perfect... Merci (bien suivre les indications et aucun problèmes...)

In Odin Mode:
FRP unlock
OEM unlock
If you read again first post you'll see i already mentioned to make sure you have the OEM unlock toggle as On.
The toggle reflects the state of OEM unlock:
Toggle ON - phone unlocked, OEM off, FRP off.
Toggle OFF - phone locked, OEM on, FRP on.


Sent from my SM-A530F using Tapatalk
 
  • Like
Reactions: extended84

mchlbenner

Senior Member
Jul 1, 2008
3,381
842
If you read again first post you'll see i already mentioned to make sure you have the OEM unlock toggle as On.
The toggle reflects the state of OEM unlock:
Toggle ON - phone unlocked, OEM off, FRP off.
Toggle OFF - phone locked, OEM on, FRP on.


Sent from my SM-A530F using Tapatalk

Question does twrp get flashed permanent ?

Sent from my LEX720 using xda premium
 

c@meleon

Senior Member
Mar 9, 2009
73
10
Near The French Border
Update?

If you read again first post you'll see i already mentioned to make sure you have the OEM unlock toggle as On.
The toggle reflects the state of OEM unlock:
Toggle ON - phone unlocked, OEM off, FRP off.
Toggle OFF - phone locked, OEM on, FRP on.


Sent from my SM-A530F using Tapatalk

Hello can you tell me how install official firmware update? The best way?
- With Flashfire and keep root etc... (maybe too TWRP)
- Or Odin and reroot?
Thanks for your response...
 

corsicanu

Recognized Developer
Hello can you tell me how install official firmware update? The best way?
- With Flashfire and keep root etc... (maybe too TWRP)
- Or Odin and reroot?
Thanks for your response...
Personally i'd recommend flashing using odin. Flash the FW in odin, force it reboot in download mode, flash twrp, force the phone in twrp, flash again rmm bypass and you'll have updated fw with lock disabled.
Regards.

Sent from my SM-A530F using Tapatalk
 
Last edited:
  • Like
Reactions: extended84

c@meleon

Senior Member
Mar 9, 2009
73
10
Near The French Border
Personally i'd recommend flashing using odin. Flash the FW in odin, force it reboot in download mode, flash twrp, force the phone in twrp, flash again rmm bypass and you'll have updated fw with lock disabled.
Regards.

Sent from my SM-A530F using Tapatalk

Install via Odin andOK but lose all... After the problemis impossible install TWRP (Little red line in (Odin) Download Mode who said "Only official released binaries are allowed to be flashed (RECOVERY)"), and my FRP and my OEM always OFF ...
Or waiting like describe here: https://xdaforums.com/galaxy-note-8/help/official-released-binaries-allowed-to-t3681883
 
Last edited:

mchlbenner

Senior Member
Jul 1, 2008
3,381
842
Install via Odin andOK but lose all... After the problemis impossible install TWRP (Little red line in (Odin) Download Mode who said "Only official released binaries are allowed to be flashed (RECOVERY)"), and my FRP and my OEM always OFF ...
Or waiting like describe here: https://xdaforums.com/galaxy-note-8/help/official-released-binaries-allowed-to-t3681883

You have to developers in settings and click on about 7 times enable OEM unlock.

I hear what been happening idea!
Zips you need make sure you get them and flash all.
SuperSU.zip.
RMM-state-by pass mesa.zip
NO-verity-no-encrypt ashyx.zip


Don't put sim card in then boot up go to developers setting enable OEM unlock.
Make sure all your drivers are installed.
Setup Odin next put your phone in download mode next flash twrp.
Then hold volume up and down +power when screen turn black hold power+ volume+.
You will go into twrp flash all your zips then reformat data and reboot.
Make sure you swipe to allow modifications.

You should boot up fine but slow.


Sent from my LEX727 using xda premium
 

c@meleon

Senior Member
Mar 9, 2009
73
10
Near The French Border
You have to developers in settings and click on about 7 times enable OEM unlock.

I hear what been happening idea!
Zips you need make sure you get them and flash all.
SuperSU.zip.
RMM-state-by pass mesa.zip
NO-verity-no-encrypt ashyx.zip


Don't put sim card in then boot up go to developers setting enable OEM unlock.
Make sure all your drivers are installed.
Setup Odin next put your phone in download mode next flash twrp.
Then hold volume up and down +power when screen turn black hold power+ volume+.
You will go into twrp flash all your zips then reformat data and reboot.
Make sure you swipe to allow modifications.

You should boot up fine but slow.


Sent from my LEX727 using xda premium

Thanks for your help...
I'll remove my sim card in then boot up go to developers setting, but i've not enable OEM unlock line.
My drivers are OK.
The first time for the root it was easy, now problem persist with OEM....(maybe due update with latest A730FXXU2ARC9).
I'm waiting a few days to see if OEM unlock reappears... :rolleyes:
 

mchlbenner

Senior Member
Jul 1, 2008
3,381
842
Thanks for your help...
I'll remove my sim card in then boot up go to developers setting, but i've not enable OEM unlock line.
My drivers are OK.
The first time for the root it was easy, now problem persist with OEM....(maybe due update with latest A730FXXU2ARC9).
I'm waiting a few days to see if OEM unlock reappears... :rolleyes:

Are you locked out?

Sent from my LEX727 using xda premium
 

c@meleon

Senior Member
Mar 9, 2009
73
10
Near The French Border
Are you locked out?

Sent from my LEX727 using xda premium

Sorry for my bad English, i don't understand this???
It does remove lock code or Bootloader? (i'll remove all code who work with this phone...)
I'm not locked to any carrier...

I read this:
Firmware to last version and this update blocked the bootloader.
In Europe latest firmware's are locked so you can't flash TWRP via Odin.
But countries like India, Turkey etc.... there isn't any problem.

https://xdaforums.com/samsung-a-series-2017/help/help-flash-twrp-t3715529
 
Last edited:

c@meleon

Senior Member
Mar 9, 2009
73
10
Near The French Border
Sorry for my bad English, i don't understand this???
It does remove lock code or Bootloader? (i'll remove all code who work with this phone...)
I'm not locked to any carrier...

I read this:
Firmware to last version and this update blocked the bootloader.
In Europe latest firmware's are locked so you can't flash TWRP via Odin.
But countries like India, Turkey etc.... there isn't any problem.

https://xdaforums.com/samsung-a-series-2017/help/help-flash-twrp-t3715529

Actually after 7-9 days the OEM Unlock reappears in developer settings...
And you can again via Odin reinstall TWRP and SuperSU...
But don't forget erase data (factory reset), otherwise you may have some problems...
:laugh:
 

mchlbenner

Senior Member
Jul 1, 2008
3,381
842
Actually after 7-9 days the OEM Unlock reappears in developer settings...
And you can again via Odin reinstall TWRP and SuperSU...
But don't forget erase data (factory reset), otherwise you may have some problems...
:laugh:

Make sure you do all your installs with twrp before you reformat your device.
Keep in mind after reformat all you had on your sdcard is gone mtp doest work on twrp.
If you reboot without those zips you will be locked out for around 168 hours again.


Sent from my LEX727 using xda premium
 

c@meleon

Senior Member
Mar 9, 2009
73
10
Near The French Border
Make sure you do all your installs with twrp before you reformat your device.
Keep in mind after reformat all you had on your sdcard is gone mtp doest work on twrp.
If you reboot without those zips you will be locked out for around 168 hours again.


Sent from my LEX727 using xda premium

Thank you that happened to me ... And wait again ...
Because the first time it worked, but i'll erase some applications like knox ... (with root uninstaller), and after reboot black screen and red message, and nothing... Require to install the firmware via Odin and wait 168h.:fingers-crossed:
 

mchlbenner

Senior Member
Jul 1, 2008
3,381
842
Thank you that happened to me ... And wait again ...
Because the first time it worked, but i'll erase some applications like knox ... (with root uninstaller), and after reboot black screen and red message, and nothing... Require to install the firmware via Odin and wait 168h.:fingers-crossed:


this what did with and it worked I did this with no SIM card in you will have to reformat first.
make sure you have a micro sdcard for device.
install usb driver for device and download odin and set it up.
download twrp and root,mesascustom kernel v1.zip, no verify no encrypt.ashy yx. zip.
flash recovery with odin in ap after pass unplug hold power and volume up down at the same time.
when right when download leaves then push on power and volume up you will boot into twrp then make sure you have put in micro sdcard and swipe to allow modifications and then reformat device.
I chose to reboot to recovery.
go to micro sdcard and do your install.
then reboot phone after check your phone root and you check everything turn of your phone.
put in SIM card and turn on phone.
the no SIM will work that is what I did.



Sent from my SM-A730F using xda premium
 

c@meleon

Senior Member
Mar 9, 2009
73
10
Near The French Border
Hello, Need precision my english is limited ...

this what did with and it worked I did this with no SIM card in you will have to reformat first.
make sure you have a micro sdcard for device.
install usb driver for device and download odin and set it up.
download twrp and root,mesascustom kernel v1.zip, no verify no encrypt.ashy yx. zip.
flash recovery with odin in ap after pass unplug hold power and volume up down at the same time.
when right when download leaves then push on power and volume up you will boot into twrp then make sure you have put in micro sdcard and swipe to allow modifications and then reformat device.
I chose to reboot to recovery.
go to micro sdcard and do your install.
then reboot phone after check your phone root and you check everything turn of your phone.
put in SIM card and turn on phone.
the no SIM will work that is what I did.

------------------------------------------------------------------------------------------------
I have a problem to translate your message, if I understand I proceed like this:

I've Odin already installed and drivers...
I remove my sim card, and insert a Micro-SD card on my device,

1. I'll reformat my phone (return stock via settings).
2. i'll install TWRP recovery via Odin and i'll reboot directly to Recovery mode and swipe to allow
modifications and then reformat device.
3. I'll reboot in recovery mode and install "mesascustom kernel v1.zip" and "no verify no encrypt.ashy yx.zip"
from my SD-card.
4. Then i'll reboot phone after check your phone root and you check everything turn off your phone.
I'll put my SIM card and turn on phone.
The no SIM will work that is what I did.

What does mean the no SIM will work ? (no band active?) and Should i install "RMM-State_Bypass" too...? in step 3.

Thank you for correcting me if I made a mistake and it will be perfect...
Thank you in advance.

Gil:eek:
 

Top Liked Posts

  • There are no posts matching your filters.
  • 10
    UPDATE 17.06.2019 - NEW RMM/KG bypass patch

    UPDATE 23.02.2019 - Pie and more

    Please take some time and read carefully the whole post. I am not and i won`t be responsable for anything.

    Disclaimer
    I am not responsible for bricked devices, dead SD cards, thermonuclear war, or you getting fired because the alarm app failed.
    Please do some research if you have any concerns about this guide!
    YOU are choosing to make these modifications, and if you point the finger at me for messing up your device, I will laugh at you.
    Flashing any custom binary will trigger knox and you may lose your warranty. Make sure you know what you do to your device.

    Introduction
    December 2017 update (for some even older) brought us a different lock, that creates panic among users as usual. As described here by my friend @BlackMesa123, this is not a lock to developement, rather an advanced lock for theft or scams. This has a bypass too, specially when you`re the owner of the device.

    How it works
    This lock is in bootloader, but the trigger to it is inside the system, it`s hard to reproduce, but usually happens when you plug another country sim than your firmware country, because changing the country might not seem as a traveling guy and more like a thief. If you are on stock rom all this time, you might not feel the change, as the device reboots and wipes data, but it will eventually boot. The nice thing comes if you already have custom binary installed (rooted kernel or twrp), as you can`t boot anymore because bootloader is preventing you to boot on custom binaries and alter the system.

    Devices confirmed to have the lock:
    • Any other Samsung device manufactured after 2017
    • Samsung Galaxy S9 & S9+ - SM-G960F & SM-G965F
    • Samsung Galaxy Note 8 - SM-N950F
    • Samsung Galaxy S8 & S8+ - SM-G950F & SM-G955F
    • Samsung Galaxy A8 & A8+(2018) - SM-A530F & SM-A730F
    • Samsung Galaxy A Series (2017) - SM-A320F/FL, SM-A520F & SM-A720F
    • Samsung Galaxy Note FE - N935F

    How to know if you are locked
    There are 3 things at this chapter:
    1. "Only official released binaries are allowed to be flashed" message shows up and now you know for sure you got locked outside your phone
    2. Missing OEM unlock toggle in developer settings, if your device has FRP
    3. "RMM state = Prenormal" in download mode

    How to unlock
    1. As i personally did, and other users reported, if you face any of the things above, flash latest full stock fw of your country with Odin, boot up, don`t reboot, don`t unplug the sim and don`t disconnect the network connection for 7 full days (168h). It seems that after 7 days of uptime, RMM state resets and you can flash TWRP again without issues. You can see uptime in settings/about device/status.
    2. Some users reported this guide was working in first Oreo fw releases, can't guarantee it still works.

    How to avoid getting locked again
    Unfortunately bootloader can`t be reverted to older revisions, so we need to live with this. My friend @BlackMesa123 made some investigation and found out how to disable this lock. After waiting those 7 days, go to settings/developer option and enable OEM unlock. In order to never get locked again, flash TWRP for your device (install instructions below), boot into TWRP (do not boot into rom yet as you might get locked again), download and flash his fix from here (don`t forget to thank him too for his findings).
    You can keep this zip near and flash it after flashing any custom rom, to be sure you don`t get locked again. The zip contains an universal script that disables the services responsable. Can be flashed on any device, if the device has the lock, won`t get locked again, if not, nothing will happend. I like to say "better safe than sorry".

    How to safely install TWRP
    Considering you are already unlocked (waited those 7 days), follow the next steps carefully:
    1. Make sure you downloaded latest Odin, samsung usb drivers installed, latest RMM-State_Bypass fix (download links are in #2 post) and latest TWRP available for your device
    2. Put RMM-State_Bypass.zip in external sdcard
    3. Go to settings/Developer options and enable OEM unlock (If you don't see developer settings, go into Settings/About phone/Software info and tap "Build number" 10 times to show Developer options menu)
    4. Reboot the phone into download mode and connect the usb cable
    5. Open Odin, go into options and untick Auto-reboot and put the TWRP tar file in AP tab of odin, hit Start and wait
    6. When Odin shows "PASS", take your device in hands, disconnect the usb cable and press simultaneously the "Power" + "Vol. Down" + "Vol. Up" buttons until the downoad mode disappears
    7. At the precise moment the screen becomes black, immediately release the "Vol.Down" button and press the "Vol. Up" + "Power" buttons during 10 to 15sec to forcefully enter TWRP
      ***Don't boot into rom because it will lock your device again!!!!
    8. Once the custom recovery booted, swipe to "Allow modification" and flash RMM-State_Bypass.zip as normal zip
    Now you can reboot into rom and hopefully never get locked again.
    If any of above steps fail, redo from step 1, more carefully this time.


    How to safely root
    Considering you already unlocked (waited those 7 days) and you have TWRP installed, follow the next steps carefully:
    1. Download root zip and no-verity-opt-encrypt-6.0 (download links are in #2 post) and drop the zips into external sdcard
    2. Boot into TWRP and swipe "Allow modifications"
    3. Go into Wipe menu and select "Format data" - note that this will erase all your data including internal storage
    4. Reboot recovery, swipe to "Allow modification" and flash RMM-State_Bypass.zip
    5. Flash no-verity-opt-encrypt-6.0 zip downloaded at step #1 to disable data partition encryption
    6. Flash root zip downloaded at step #1
    7. Reboot the phone into system
    8. After booting up in setting wizard make sure to uncheck diagnostic data
    If any of above steps fail, redo from step 1, more carefully this time.


    You can read more about it here here, here, here, here or here.

    Credits
    @BlackMesa123
    @RicePlay33
    @Yahia Angelo
    @TaifAljaloo
    @ananjaser1211
    5
    Useful links

    FAQ
    Q: TWRP can't mount data partition, what to do?
    A: Make sure you formatted data partition.

    Q: Phone is not booting even after 20 minutes?
    A: Try to reboot. If still not booting, make sure you formatted data partition.

    Q: How to format data partition?
    A:
    ymlnQUE.jpg


    Q: Why do i need to format data partition?
    A: Because old rom encrypted your data partition and new rom can't decrypt and use that content / root needs access to data partition to place misc files / phone not booting after flashing root until data partition gets formatted.

    Q: Why not formatting data at twrp install?
    A: Phone will boot even if data is encrypted if you don't root. Also system partition is not encrypted meaning you can flash RMM-State_Bypass anyway.
    4
    Reserved for later use [emoji16]
    2
    Question does twrp get flashed permanent ?

    Sent from my LEX720 using xda premium
    Yes.

    Sent from my SM-A530F using Tapatalk
    2
    Slightly updated the guide for Oreo, added FAQ, no-verity-opt-encrypt-6.0 patch, hope i covered all misunderstandings.
    Let me know if i missed something else and will be added. Regards