Back to 4.4.4 from Lollipop

mightysween

Senior Member
Feb 18, 2011
1,548
1,287
0
Maine/USA
dont know if root can be preserved while downgrading
Answer is no, not through ODIN. One user *claims* to have downgraded and kept root by flashing a 4.4.4 image, but has not responded to numerous inquiries and PM about the method.

My feeling is that restoring a "nandroid" backup of a 4.4.4 system on top of a rooted 5.0 system *should* work. Problem is getting a proper 4.4.4 backup...need a dev edition to do that, and if we had access to those, we would probably have the bootloader unlocked anyway! :)
 

en11gma

Senior Member
Jan 18, 2013
1,001
88
68
Answer is no, not through ODIN. One user *claims* to have downgraded and kept root by flashing a 4.4.4 image, but has not responded to numerous inquiries and PM about the method.

My feeling is that restoring a "nandroid" backup of a 4.4.4 system on top of a rooted 5.0 system *should* work. Problem is getting a proper 4.4.4 backup...need a dev edition to do that, and if we had access to those, we would probably have the bootloader unlocked anyway! :)
great info there.
thought this might be true but was really hoping of a root method but doubted it from the beginning.
bummmers
really could use some CM lovin on this still great device
 

mightysween

Senior Member
Feb 18, 2011
1,548
1,287
0
Maine/USA
great info there.
thought this might be true but was really hoping of a root method but doubted it from the beginning.
bummmers
really could use some CM lovin on this still great device
This bootloader exploit is legit so it should just be a matter of time before this device is open. :)
 

en11gma

Senior Member
Jan 18, 2013
1,001
88
68
I'm already on my developer device that is running 4.4 dev bootloader and even I'm excited mainly because I was able to provide the needed files and a retail edition for testing with @beaups.

Sent from my SM-N900V using Tapatalk
they couldnt do it with out your dev edition info for sure.

so i say a big Thank-You!!! :)

cant wait to get some CM
 

wetherb67

Member
Apr 19, 2009
12
0
0
So I am currently on 5.0 PL1, SM-N900V. I just need to download the NK1 from the sammobile website, use Odin and that's all I need to do to downgrade?
 

bftb0

Senior Member
Feb 5, 2010
2,594
1,040
0
So I am currently on 5.0 PL1, SM-N900V. I just need to download the NK1 from the sammobile website, use Odin and that's all I need to do to downgrade?
It would appear that the furthest back you can go is indeed NK1.

However, rooting is an issue on NK1 (if you are after that). I know for a fact that Towelroot v3 works on NC4 (not sure about NJ6), but probably stops somewhere above there; in the past others have claimed it won't work on NK1. I think that Yemen root uses a camera library exploit, so it might be a long shot of it working on NK1. (If it had been a kernel exploit it might have been more likely to work on much older releases).

The NK1 kernel more than likely has some vulnerabilities - but afaik nobody ever released a public exploit for the SM-N900* variants.


good luck.
 
  • Like
Reactions: wetherb67

wetherb67

Member
Apr 19, 2009
12
0
0
It would appear that the furthest back you can go is indeed NK1.

However, rooting is an issue on NK1 (if you are after that). I know for a fact that Towelroot v3 works on NC4 (not sure about NJ6), but probably stops somewhere above there; in the past others have claimed it won't work on NK1. I think that Yemen root uses a camera library exploit, so it might be a long shot of it working on NK1. (If it had been a kernel exploit it might have been more likely to work on much older releases).

The NK1 kernel more than likely has some vulnerabilities - but afaik nobody ever released a public exploit for the SM-N900* variants.


good luck.
Not looking to root just go back to NK1. Thanks for the info!

UPDATE 03-01-2017: Worked like a charm with ODIN.
 
Last edited:

seadooman

Senior Member
Aug 29, 2013
131
1
38
L. A.
It would appear that the furthest back you can go is indeed NK1.

However, rooting is an issue on NK1 (if you are after that). I know for a fact that Towelroot v3 works on NC4 (not sure about NJ6), but probably stops somewhere above there; in the past others have claimed it won't work on NK1. I think that Yemen root uses a camera library exploit, so it might be a long shot of it working on NK1. (If it had been a kernel exploit it might have been more likely to work on much older releases).

The NK1 kernel more than likely has some vulnerabilities - but afaik nobody ever released a public exploit for the SM-N900* variants.


good luck.
Is this true with a dev edition running OF1?
 

bftb0

Senior Member
Feb 5, 2010
2,594
1,040
0
Is this true with a dev edition running OF1?
Should be true for either bootloader locked (retail) or bootloader unlocked (dev ed) phone.

Strictly speaking, I don't think there were any phones sold as "Developer Edition" that were on OF1 - so I suppose you mean "retail phone on OF1 converted to dev ed by rooting and unlocking the bootloader thereafter"

Just note that in either case, the bootloader will end up being locked, but the CID will not revert to the original retail CID value. And (as mentioned above) NK1 does not have an easy method of rooting* if that is a concern.



* a complicated way of achieving rooted NK1 would be to make a flashable, pre-rooted NK1 ROM and install it while still on (unlocked bootloader) OB6/OF1 firmware, and then immediately follow that up by Odin'ing just the bootloader components of NK1.

(Flash pre-rooted NK1 stock ROM using a custom recovery; boot immediately to Odin to install only the NK1 bootloader components; boot into pre-rooted stock ROM and then re-unlock the bootloader. Doing things this way avoids boot failures during the time the bootloader is temporarily locked because a Samsung-signed kernel is in place during the locked time. And pre-rooting means that you don't need to find a new exploit for NK1. Moreover, it doesn't attempt to boot a Samsung kernel that has TIMA measurements which differ from those expected by the TZ measurements stored in the bootloader: the boot takes place with bootloader firmware and kernel held in version lock-step.)


cheers


PS. As always, make full backups of everything before you begin and get copies of them off the phone. You should assume that an accident could always happen which will necessitate a full wipe of the phone.
 
  • Like
Reactions: seadooman

seadooman

Senior Member
Aug 29, 2013
131
1
38
L. A.
Should be true for either bootloader locked (retail) or bootloader unlocked (dev ed) phone.

Strictly speaking, I don't think there were any phones sold as "Developer Edition" that were on OF1 - so I suppose you mean "retail phone on OF1 converted to dev ed by rooting and unlocking the bootloader thereafter"

Just note that in either case, the bootloader will end up being locked, but the CID will not revert to the original retail CID value. And (as mentioned above) NK1 does not have an easy method of rooting* if that is a concern.



* a complicated way of achieving rooted NK1 would be to make a flashable, pre-rooted NK1 ROM and install it while still on (unlocked bootloader) OB6/OF1 firmware, and then immediately follow that up by Odin'ing just the bootloader components of NK1.

(Flash pre-rooted NK1 stock ROM using a custom recovery; boot immediately to Odin to install only the NK1 bootloader components; boot into pre-rooted stock ROM and then re-unlock the bootloader. Doing things this way avoids boot failures during the time the bootloader is temporarily locked because a Samsung-signed kernel is in place during the locked time. And pre-rooting means that you don't need to find a new exploit for NK1. Moreover, it doesn't attempt to boot a Samsung kernel that has TIMA measurements which differ from those expected by the TZ measurements stored in the bootloader: the boot takes place with bootloader firmware and kernel held in version lock-step.)


cheers


PS. As always, make full backups of everything before you begin and get copies of them off the phone. You should assume that an accident could always happen which will necessitate a full wipe of the phone.
Thanks as always.
I was a little tired when I posted last night. So yes it is a retail phone unlocked ,lucky I had the right CID. What your saying is I cannot go back to nc4?
Are there any workable roms out there for the note 3? Any you could recommend?
 

bftb0

Senior Member
Feb 5, 2010
2,594
1,040
0
What your saying is I cannot go back to nc4?
Booting any firmware from NK1 or beyond means you can not go back to NC4 bootloader firmware.

There hasn't been anybody who packaged up flashable versions of Stock ROMs (pre-rooted or otherwise), so something which is sort of untested is folks trying to boot earlier stock kernels and ROMs with later bootloader firmware. It is entirely possible that you could boot any N* or later rom from an O* or P* bootloader. The "risk" is that the attribution signature stuff (TIMA) which is enabled in the kernels will be mismatched with the signatures in the bootloader's TZ, and so maybe the kernels would never boot. I doubt that trying such a thing would create a brick though; at most the boot process would probably just wedge, and you'd still be able to use Odin to restore.

Are there any workable roms out there for the note 3? Any you could recommend?
I haven't "tried them all", so I'm no expert. I've been using CM13 which I like for it's tethering capabilities, using OTG devices, etc. But its biggest downfall is GPS, which barely works at all. (And NFC doesn't work either). And of course you give up S-pen apps as well. If CM could just get GPS working I'd consider it a nearly perfect ROM.

It's too bad it took so long to get an unlocked bootloader; I suspect the dev activity would be far stronger even now (as the Note 3 was one of the few phones with 3GB RAM at the time of it's introduction) were it not for it's past history.
 
Our Apps
Get our official app!
The best way to access XDA on your phone
Nav Gestures
Add swipe gestures to any Android
One Handed Mode
Eases uses one hand with your phone