Runnymede S-OFF

Search This thread

Lexmazter

Retired Recognized Developer
Aug 7, 2011
1,082
870
Timisoara
ASUS ZenFone 7/7 Pro
I am S-OFF since day 1 i bought this phone, had no problems with it, and also, because many threads out there are old and things can be difficult to get by, i made a tool that i can see nobody tries to use it, the tool can be found in my signature.

It S-OFF's your phone, installs the right recovery, you can even upgrade or downgrade the baseband/radio if you are s-off, so i really don't know from where everybody get this huge amount of problems with S-OFF, as it was meant to be the best way to go in order to have a seamless experience with custom ROM development/testing.

Don't know if this helps or not, but this is what i think right now :)
 

rlamba

Senior Member
Oct 8, 2011
254
20
Varna
I am S-OFF since day 1 i bought this phone, had no problems with it, and also, because many threads out there are old and things can be difficult to get by, i made a tool that i can see nobody tries to use it, the tool can be found in my signature.

It S-OFF's your phone, installs the right recovery, you can even upgrade or downgrade the baseband/radio if you are s-off, so i really don't know from where everybody get this huge amount of problems with S-OFF, as it was meant to be the best way to go in order to have a seamless experience with custom ROM development/testing.

Don't know if this helps or not, but this is what i think right now :)

I have tried your multi tool. Not good enough for my problem. S-OFF is real pain in backside with unlimited.io hboot.Flash their hboot and find a recovery which works with their protected/unprotected ics hboot.
 

Lexmazter

Retired Recognized Developer
Aug 7, 2011
1,082
870
Timisoara
ASUS ZenFone 7/7 Pro
I have tried your multi tool. Not good enough for my problem. S-OFF is real pain in backside with unlimited.io hboot.Flash their hboot and find a recovery which works with their protected/unprotected ics hboot.

Well, if you really want to have everything fully working, the best way to go is to flash an Upnprotected S-OFF, flash a RUU and unlock/S-OFF again, in order to have everything working, install a ICS RUU and so on. This should work!
 

rlamba

Senior Member
Oct 8, 2011
254
20
Varna
Well, if you really want to have everything fully working, the best way to go is to flash an Upnprotected S-OFF, flash a RUU and unlock/S-OFF again, in order to have everything working, install a ICS RUU and so on. This should work!

Thank you for your help. I had tried this before and it did not work,

Used Unprotected S-OFF for ICS from unlimited.io
Flashed ICS Hboot 1.28 (this was extracted from rom.zip from ICS RUU
This just made S-Off back to S-On

I will try the steps you have suggested and let you know.
 
Last edited:

drupad2drupad

Senior Member
Apr 11, 2010
1,612
625
When I try the adb,

It gives me error saying can't find su.

I am rooted, unlocked bootloader with CMW recovery 5.5.0.4!

---------- Post added at 11:22 PM ---------- Previous post was at 10:51 PM ----------

Ok so I can reach up to SU now but when I do the # dd ...... command, it can't find it. No directory error?!

What am I doing wrong here? Anyone?
 

Lexmazter

Retired Recognized Developer
Aug 7, 2011
1,082
870
Timisoara
ASUS ZenFone 7/7 Pro
try flashing fardjadb hboot so that u can excute that command u r talking about

Sent from my HTC Sensation XL with Beats Audio X315e using Tapatalk 2

To avoid any problems of S-OFF-ing, use the tool proided by me, this is the last time i say this!

Also, you need to be fully booted not from recovery, not from fastoot, booted and rooted, hit the tool and press S-OFF and wait for the magic!
[Why does people kill their heads when i killed mine to make a tool to get things done?]
 

rlamba

Senior Member
Oct 8, 2011
254
20
Varna
Guys please be careful when playing with HBOOT, Radio, etc.

Here is the easy way to unbrick:

1. Flash your unlock token on 1.28 if it's (re)locked.
2. Boot into a working recovery.
3. Download this and push it to /tmp (adb push fardjadb_runnymede.nb0 /tmp)
4. get into adb shell and execute dd if=/tmp/fardjadb_runnymede.nb0 of=/dev/block/mmcblk0p18
5. reboot bootloader
6. Download this and flash it to the misc partition (fastboot flash misc supermisc)
7. fastboot reboot-bootloader
8. Install a stock RUU
* As alfchin said, if you want to flash RUUs with different CIDs, extract the zip, open android-info.txt, change CID, repack and flash with fastboot flash zip ...

Your links do not work.
 

nsnobel2

Senior Member
Sep 27, 2011
425
24

Thanks for sharing,
Which one I have to download , my phone details are as follow

Android version
4.0.3
Baseband version
20.5101.30.0822U_3822.10.10.12_M

Build number
3 Musketeers Total sensless

Hboot deatils is as follow

UNLOCKED
RUNNYMEDE PVT SHIP S-ON
HBOOT 1.25-0004
RADIO-3822.10.10.12_M
eMMC-boot

My problem is that my phone always asked for pin code when its restart although there is no pin code on sim. I try different sims but same.
 

nsnobel2

Senior Member
Sep 27, 2011
425
24
all you have to do is flash protected JB(JellyBean) hboot and you r gud to go

Sent from my HTC Sensation XL with Beats Audio X315e using Tapatalk 2

There is no Protected JB hboot. there are hboot for GB and ICS. Sorry me newbie and afraid to brick this phone so I am taking so much care.

thanks

---------- Post added at 02:39 PM ---------- Previous post was at 02:33 PM ----------

Sir, you mean GB protected hboot?
 

abusseemkh

Senior Member
May 9, 2012
145
27
Beirut
Samsung Galaxy S21 FE
http://unlimited.io/runnymede.htm go here.. look under "downloads" heading in the upper right corner .. u'll find four hboots , choose protected ICS NOT JB.. sorry my mistake

Sent from my HTC Sensation XL with Beats Audio X315e using Tapatalk 2

---------- Post added at 04:45 PM ---------- Previous post was at 04:42 PM ----------

By the way thr isnt anything called "bricking a phone" unless you hit it with a hammer.

Sent from my HTC Sensation XL with Beats Audio X315e using Tapatalk 2
 

nsnobel2

Senior Member
Sep 27, 2011
425
24
http://unlimited.io/runnymede.htm go here.. look under "downloads" heading in the upper right corner .. u'll find four hboots , choose protected ICS NOT JB.. sorry my mistake

Sent from my HTC Sensation XL with Beats Audio X315e using Tapatalk 2

---------- Post added at 04:45 PM ---------- Previous post was at 04:42 PM ----------

By the way thr isnt anything called "bricking a phone" unless you hit it with a hammer.

Sent from my HTC Sensation XL with Beats Audio X315e using Tapatalk 2

sir I am thankful for you support.

I flash 1st step succesfully. I write hboot in normal phone ON with adb command "adb push hboot_7230ddr2_Runnymede_6.25.4444.nb0 /data/local/tmp"

but when i do 2nd step adb shell in fastboot mode result in "error: device not found"

:( any idea?
 
Last edited:

abusseemkh

Senior Member
May 9, 2012
145
27
Beirut
Samsung Galaxy S21 FE
cd u plz tell wht r the tools u r using e.g. adb tools etc

Sent from my HTC Sensation XL with Beats Audio X315e using Tapatalk 2

---------- Post added at 05:38 PM ---------- Previous post was at 05:35 PM ----------

i think u shd flash by accessing fastboot not with the phone in normal homescreen on.. if u dont know how its by pressing power + volume down simultaneously.

Sent from my HTC Sensation XL with Beats Audio X315e using Tapatalk 2
 

abusseemkh

Senior Member
May 9, 2012
145
27
Beirut
Samsung Galaxy S21 FE
ok .. download hboot flash it but from the recovery screen not normal homescreen and tell me wht happens

Sent from my HTC Sensation XL with Beats Audio X315e using Tapatalk 2

---------- Post added at 08:23 PM ---------- Previous post was at 08:20 PM ----------

P.S. make sure u flash the unlimited.io recovery first from the same webpage.. gud luck :)

Sent from my HTC Sensation XL with Beats Audio X315e using Tapatalk 2
 

Top Liked Posts

  • There are no posts matching your filters.
  • 27
    Runnymede S-OFF

    Since we didn't have S-OFF on Runnymede, I decided to work on it, and here is the result:

    attachment.php


    It's basically a patched bootloader that pretends S-OFF (not to be confused with Radio S-OFF.)

    The following commands have been tested and working correctly:

    erase (system, recovery, boot)
    flash (zip, system, recovery, boot, hboot, radio)
    boot
    It also by passes the CID check (See the next post for a workaround.)
    and here is the flash "zip", "hboot", and "recovery" demo:


    It's still under development; since many people asked me to release it, I decided to release a public beta:

    Download (Windows Only) (link removed, see below)

    Open the attached file and follow the instructions.
    You'll need to install a stock RUU (or if not available, you can flash this stock recovery posted by fshami on an unlocked device) and install HTC Sync Drivers.

    Note that this is not guaranteed to work and I won't take any responsibilities if something bad happened to your device.

    My farewells

    I had lots of fun modifying Runnymede HBOOT and it was a great experience. I want to say thanks to all of the testers for their feedback and also for being nice and patient (maybe I should have released this after my exams, so I'd have enough time to work on it), and I'm sorry for the problems you may have faced because of the incompleteness of my work.

    Recently unlimited.io guys (known for Juopunutbear S-OFF) provided their patched HBOOTs. Apparently these are available for GB and ICS, by-pass CID check and have optional update protection:
    http://unlimited.io/runnymede said:
    It was identified by XDA memeber fardjad that the hboot partition on the runnymede is not protected and can be written to with a rooted phone. One of the members of unlimited had for a short period of time the occasion to use a Sensation XL. Having seen the discovery made by fardjad and due to some limitations in the procedure, this memeber created hboots which provide more complete S-OFF functionality as well as providing overwrite protection. Almost immediately afterwards the European Sensation XL obtained an ICS update. Unfortunately for may users this meant that a new and backward incompatible hboot was introduced. The unlimited member again created modified hboots for his own use. It was not originally intended that these hboots would be released for general use, however we are aware that many users are unhappy with the limitations of unlock but have had to do this in order to make full use of ICS. We have therefore decided to release the GB and ICS versions of these hboots.

    See this post.
    14
    How to install RUUs with different CIDs

    You won't get Radio S-OFF with flashing this HBOOT. Having this said, even if you enable writeCID function in HBOOT you can't change the CID.

    I thought people prefer to install one of the custom ROMs floating around in Development Section and flashing the Radio separately rather than upgrading to ICS using RUUs... well I thought wrong :)
    And for those having problems with CID, here is a workaround:

    First thing you need to do is to extract the rom.zip file from the RUU. I believe Shen posted a video on XDA-TV showing this, here is a quick how-to however:

    1. Open the RUU.
    2. After the Welcome screen has shown up, open %temp% in explorer (ie. Meta/Win-Key + R, type %temp% and press enter)
    3. Sort items by Date modified and open the most recent modified folder having a name like {3F99782F-1E57-40F2-9F33-D48C3DC171C5}
    4. Search for rom.zip and move/copy it to somewhere else.
    5. Close the RUU.

    Now download SigTool (link removed, see the first post) and place it beside the rom.zip file. Open Command-Prompt, navigate to the relevant directory and execute the following:

    Code:
    SigTool rip rom.zip
    the expected output is:

    Code:
    Creating backup...
    Ripping signature...
    Done.
    Extract the signature-ripped rom.zip file.
    Open android-info.txt in a *nix end of line aware text editor (ex. Notepad++). You should see something like the following:

    Code:
    modelid: PI3920000
    cidnum: HTC__001
    cidnum: HTC__E11
    cidnum: HTC__203
    cidnum: HTC__102
    cidnum: HTC__405
    cidnum: HTC__Y13
    cidnum: HTC__A07
    cidnum: HTC__304
    cidnum: HTC__032
    cidnum: HTC__J15
    cidnum: HTC__016
    mainver: 1.05.111.8
    hbootpreupdate:12
    Add your phone CID

    If you don't know your CID you can get it this way:
    While your phone is in bootloader mode and connected in FASTBOOT-USB mode, execute this:

    Code:
    fastboot getvar cid
    it should output something like cid: T-MOB101

    then add a new line (cidnum: <YOURCIDNUM>) below the modelid in android-info.txt so it looks like:

    HTML:
    modelid: PI3920000cidnum: T-MOB101...
    Save changes and close the editor.

    This is very important:
    In extracted contents you should see a file with hboot name prefix, exclude/take it away and repack other files. I assume you'll choose rom-new.zip for the archive name.

    Now you should null sign (that's how I like to call it) the file:

    Code:
    SigTool nullsign rom-new.zip
    and flash the null-signed rom zip file:

    Code:
    fastboot flash zip rom-new.zip
    when finished, flash the 1.28 hboot you moved away before:

    Code:
    fastboot flash hboot hboot_*.nb0
    Reboot your device.

    I know this is not the easiest guide ever but I really don't have enough time to create a one-click tool for this. Needless to say that this is not guaranteed to work and I won't take any responsibilities if you bricked your phone.

    Take care :)
    7
    Yes older 1.25 as my phone is soft brick too. Unlike you I can't flash ruu as no Europe ics ruu file as yet. Hboot 1.28 can't be downgraded as when flash it replaces fard patch. Cid errors on official ruu and my old ruu won't flash as I now have newer hboot. Can we have a patched 1.28 hboot so I can downgrade back to 1.25 and bring phone back lol.

    Sent from my HTC One X using xda premium

    Guys please be careful when playing with HBOOT, Radio, etc.

    Here is the easy way to unbrick:

    1. Flash your unlock token on 1.28 if it's (re)locked.
    2. Boot into a working recovery.
    3. Download this and push it to /tmp (adb push fardjadb_runnymede.nb0 /tmp)
    4. get into adb shell and execute dd if=/tmp/fardjadb_runnymede.nb0 of=/dev/block/mmcblk0p18
    5. reboot bootloader
    6. Download this and flash it to the misc partition (fastboot flash misc supermisc)
    7. fastboot reboot-bootloader
    8. Install a stock RUU
    * As alfchin said, if you want to flash RUUs with different CIDs, extract the zip, open android-info.txt, change CID, repack and flash with fastboot flash zip ...
    6
    What don't you understand? S-Off means security off, the standard way of acheiving S-Off is by switching off the security flag held on the radio partition. This is commonly known as Radio S-Off. There is also another type of S-Off called engeneering S-Off, this is acheived by flashing a special engeering bootloader (hboot) after you already have standard S-Off.

    Now this is neither, This is a special modifed version of the standard HTC hboot by fardjab, this hboot tricks the device into thinking it is S-Off and allows end users to perform security protected actions. But unlike "real" S-Off this is not perm, flashing a stock HTC hboot or RUU will return you back to S-On status.

    Sent from my HTC Sensation XL with Beats Audio X315e using Tapatalk 2
    3
    What the hell are you on about?
    I don't even know who you, or this paul.robo are.
    Sorry, you fail to make any sense.

    mmhh..sorry ieftm...but i have a similiar thinking...maybe you can clear this..

    i had maked a donation thread...and some of us and also i maked a donation...but all response what i got from you guys was you kicked me from chat and say "read through the lines" this is not friendly....so maybe you can clear this situation...i also write emails and got no response...with kind regards...Alex