General Firmware and Combination Firmware and FOTA Delta and CSC change and...

Search This thread

icecool217

Member
Oct 4, 2009
32
8
Hi @adfree
Greatly appreciate all the work and testing you have done!

I am trying to pull mps_code.dat to change region.
My watch is R890XXU1GVK4, not rooted.

I took the following steps:
1) use adb.exe to connect (adb connect IP)
2) open Komraids System Shell
3) tried to pull directly from /efs/imei/ and nothing happens.

:/efs $ cd imei
:/efs/imei $ ls -all
total 28
drwxrwxr-x 2 root radio 4096 2022-10-12 05:55:20.615999995 +0800 .
drwxrwx--x 14 system radio 4096 2022-10-12 05:44:30.607999997 +0800 ..
-rw-rw-r-- 1 radio system 3 2022-10-12 05:43:33.439999952 +0800 mps_code.dat
-rw-rw-r-- 1 radio root 3 2022-10-12 05:55:28.447999990 +0800 omcnw_code.dat
-rwxrwxr-x 1 system radio 14 2022-10-12 05:43:33.519999952 +0800 prodcode.dat
:/efs/imei $ adb pull mps_code.dat D:\platform-tools\
>

Any clues as to what I may be doing wrong?
 

adfree

Senior Member
Jun 14, 2008
10,550
6,129
Samsung Galaxy Watch 4
Samsung Galaxy S22
Hi @adfree
Greatly appreciate all the work and testing you have done!

I am trying to pull mps_code.dat to change region.
My watch is R890XXU1GVK4, not rooted.

I took the following steps:
1) use adb.exe to connect (adb connect IP)
2) open Komraids System Shell
3) tried to pull directly from /efs/imei/ and nothing happens.

:/efs $ cd imei
:/efs/imei $ ls -all
total 28
drwxrwxr-x 2 root radio 4096 2022-10-12 05:55:20.615999995 +0800 .
drwxrwx--x 14 system radio 4096 2022-10-12 05:44:30.607999997 +0800 ..
-rw-rw-r-- 1 radio system 3 2022-10-12 05:43:33.439999952 +0800 mps_code.dat
-rw-rw-r-- 1 radio root 3 2022-10-12 05:55:28.447999990 +0800 omcnw_code.dat
-rwxrwxr-x 1 system radio 14 2022-10-12 05:43:33.519999952 +0800 prodcode.dat
:/efs/imei $ adb pull mps_code.dat D:\platform-tools\
>

Any clues as to what I may be doing wrong?

No idea...

But i am doing cp command... and copy to /sdcard

So IMHO steps

Code:
adb shell

But if you have working system shell exploit shell is opened for you...

So only...

Code:
cp /efs/imei/mps_code.dat /sdcard

Something like that...

From /sdcard you can then pull via adb

Best Regards
 
  • Like
Reactions: icecool217
Added the OXA Firmware for SM-R875F...


smR860_EVB4_OXM_v1.7z



smR870_EVA8_OXM_v1.7z



smR875F_AUGC_OXA_v1.7z



smR875U_FVD4_USA_v1.7z



smR890_EVA8_OXM_v1.7z



smR895F_AUGC_OXA_v1.7z



smR895U_FVD4_USA_v1.7z



smR900_AVH6_OXM_v1.7z



smR910_AVH6_OXM_v1.7z



smR920_AVG6_OXM_v1.7z

I have SM-R875F Watch. I want to downgrade to previous (not the April 2023) security patch for SMT Exploit to work (to use SPay). Can this firmware help?
 
  • Like
Reactions: adfree

adfree

Senior Member
Jun 14, 2008
10,550
6,129
Samsung Galaxy Watch 4
Samsung Galaxy S22
A

Flashing with netOdin is NOT riskfree...


B

Because only very old Firmwares leaked...

Risk increased...

I have not tested from latest GWDA...

C

No idea which Region you need...

For instance i have NO OXX Firmware for India for instance...


D

Better try system shell exploit...

Newer way... not tested by me... no idea:

Older way with EXE is here... also Video exists... check the posts after this too...


Please try...

Feel free to post problems... then I and/or community can help....


I am at moment full focus on eToken with my tiny brain... so less time...

Sorry.


Best Regards
 
  • Like
Reactions: devaponnadsm
A

Flashing with netOdin is NOT riskfree...


B

Because only very old Firmwares leaked...

Risk increased...

I have not tested from latest GWDA...

C

No idea which Region you need...

For instance i have NO OXX Firmware for India for instance...


D

Better try system shell exploit...

Newer way... not tested by me... no idea:

Older way with EXE is here... also Video exists... check the posts after this too...


Please try...

Feel free to post problems... then I and/or community can help....


I am at moment full focus on eToken with my tiny brain... so less time...

Sorry.


Best Regards

I am trying to change CSC to MEA region.

System Shell Exploit does not work since April Security Patch. So, not working.
 

adfree

Senior Member
Jun 14, 2008
10,550
6,129
Samsung Galaxy Watch 4
Samsung Galaxy S22
System Shell Exploit does not work since April Security Patch. So, not working.

I have NO Crystal Ball nor I can smell nor see what you are doing...

WHAT exactly is not working?

Cooking, washing? Swimming?

Feel free to give more details...

Feel free to post Screenshots and/or photos...

Please remember we are here on XDA...

Bits and Bytes... Logs... some kind of usefull detailSSSSSS...

Best Regards
 
  • Like
Reactions: TheIntruder

adfree

Senior Member
Jun 14, 2008
10,550
6,129
Samsung Galaxy Watch 4
Samsung Galaxy S22
Short tested...

With my SM-R875F on GWDA Firmware...

A

Old EXE seems obsolote...

ROLLBACK FAILED

B

Is somebody able to test the other method?


Please need details... what not work...

Thanx in advance.

Best Regards
 

Jacob1004

Member
Nov 18, 2019
43
15
malmø
Short tested...

With my SM-R875F on GWDA Firmware...

A

Old EXE seems obsolote...

ROLLBACK FAILED

B

Is somebody able to test the other method?


Please need details... what not work...

Thanx in advance.

Best Regards
I tested the other method and it failed too. It doesnt allow me to downgrade the com.samsung.SMT.

adb: failed to install com.samsung.SMT_v3.0.02.2.apk: Failure [INSTALL_FAILED_VERSION_DOWNGRADE]

I also tried via shizuku and seems same issue. It doesnt allow or doesnt allow to downgrade the com.samsung.SMT.
 
  • Like
Reactions: adfree

icecool217

Member
Oct 4, 2009
32
8
I tested the other method and it failed too. It doesnt allow me to downgrade the com.samsung.SMT.

adb: failed to install com.samsung.SMT_v3.0.02.2.apk: Failure [INSTALL_FAILED_VERSION_DOWNGRADE]
Did you try to use pc to install?

adb connect IP
adb install -d com.samsung.SMT_v3.0.02.2.apk

Or is your latest patch April 2023?
 
Last edited:
I have NO Crystal Ball nor I can smell nor see what you are doing...

WHAT exactly is not working?

Cooking, washing? Swimming?

Feel free to give more details...

Feel free to post Screenshots and/or photos...

Please remember we are here on XDA...

Bits and Bytes... Logs... some kind of usefull detailSSSSSS...

Best Regards

The vulnerability used by SMTShell to exploit the system is patched by Samsung and patches are released since the April 2023 Security Patches. Thus, if you updated your system, you can no longer exploit that vulnerability and make changes to the system.


Therefore, we need to find a completely new way to modify system/change CSC.
 
  • Like
Reactions: Jacob1004

adfree

Senior Member
Jun 14, 2008
10,550
6,129
Samsung Galaxy Watch 4
Samsung Galaxy S22
@devaponnadsm

For downgrade attempt... usefull to know:

A

Firmware on your Device... easy to check with:
Code:
*#1234#


B

Usefull to know.. if No Top Secret Undercover Impossible Mission...
Your CSC of your Dream...


So we can check...

C
Firmware available for Restore

C

Firmware for CSC change attempt... aka Downgrade...

Remember...

OWN Risk!

Best Regards
 
Mar 5, 2015
13
5
31
tirupur
@devaponnadsm

For downgrade attempt... usefull to know:

A

Firmware on your Device... easy to check with:
Code:
*#1234#


B

Usefull to know.. if No Top Secret Undercover Impossible Mission...
Your CSC of your Dream...


So we can check...

C
Firmware available for Restore

C

Firmware for CSC change attempt... aka Downgrade...

Remember...

OWN Risk!

Best Regards
One doubt brother.. The adb shell will open, only if we have smt shell exploit is working?

Because i also ran into the rollback failed error.
 

LJH2022

Member
Jun 14, 2023
7
3
Not sure if this is any use, have just noticed that there appears to be a combination firmware download available for the Watch 5 LTE (SM-R915x) here.

Actually there are two there - one for SM-R915F and one for SM-R915U by the looks of the filenames, but the model they are listed against is SM-R915F
 

Ageu Meireles

New member
Jan 7, 2018
2
0
I have a gw4 sm-r860 with One UI 4.5 (Aug 1, 2022). Any idea how I can root it?
I already installed Shizuku and SMTShell, but when trying to run certain commands I get "permission denied". Thank you very much in advance.
 

adfree

Senior Member
Jun 14, 2008
10,550
6,129
Samsung Galaxy Watch 4
Samsung Galaxy S22
A

I have no way without USB cable to Root...

B

imjtool I use under Ubuntu... for extract super.img etc...

Link few posts earlier...

Best Regards
 

Top Liked Posts

  • There are no posts matching your filters.
  • 2
    Code:
    R875NKOU1CWH3/R875NOKO1CWH3/R875NKOU1CWH3

    Rooted with Magisk 26.3 on my SM-R875F...

    So I was able to dump little bit... with dd...
    For instance "super"... system ... product etc...

    Here Link for study...

    You can extract with 7Zip...


    I have also dumped first 1000 MB...


    Code:
    freshul:/sdcard # dd if=/dev/block/mmcblk0 bs=512 count=2000000 of=/sdcard/dddump1K.bin
    2000000+0 records in
    2000000+0 records out
    1024000000 bytes (977 M) copied, 49.398332 s, 20 M/s
    freshul:/sdcard # gzip -k dddump1K.bin
    freshul:/sdcard # ls -a1l
    total 1344631
    drwxrws--- 2 u0_a136  media_rw       3452 2023-09-16 07:15 Alarms
    drwxrws--x 5 media_rw media_rw       3452 2023-09-16 07:15 Android
    drwxrws--- 2 u0_a136  media_rw       3452 2023-09-16 07:15 Audiobooks
    drwxrws--- 2 u0_a136  media_rw       3452 2023-09-16 07:15 DCIM
    drwxrws--- 2 u0_a136  media_rw       3452 2023-09-16 07:15 Documents
    drwxrws--- 2 u0_a136  media_rw       3452 2023-09-16 07:15 Download
    drwxrws--- 3 u0_a136  media_rw       3452 2023-09-16 07:15 Movies
    drwxrwsr-x 4 media_rw media_rw       3452 2023-09-16 07:15 Music
    drwxrws--- 2 u0_a136  media_rw       3452 2023-09-16 07:15 Notifications
    drwxrws--- 3 u0_a136  media_rw       3452 2023-09-16 07:15 Pictures
    drwxrws--- 2 u0_a136  media_rw       3452 2023-09-16 07:15 Podcasts
    drwxrws--- 2 u0_a136  media_rw       3452 2023-09-16 07:15 Recordings
    drwxrws--- 2 u0_a136  media_rw       3452 2023-09-16 07:15 Ringtones
    -rw-rw---- 1 u0_a136  media_rw 1024000000 2023-09-18 22:43 dddump1K.bin
    -rw-rw---- 1 u0_a136  media_rw  351503765 2023-09-18 22:43 dddump1K.bin.gz



    Now need some time to pull result...

    Only as Info...


    Best Regards

    Edit 1.

    Hmmm... since I disabled Sensor(s) in Health... my WiFi is stable...

    Code:
    freshul:/sdcard # dd if=/dev/block/mmcblk0p31 of=/sdcard/mmcblk0p31.bin
    409600+0 records in
    409600+0 records out
    209715200 bytes (200 M) copied, 9.268518 s, 22 M/s
    freshul:/sdcard # dd if=/dev/block/mmcblk0p33 of=/sdcard/mmcblk0p33.bin
    409600+0 records in
    409600+0 records out
    209715200 bytes (200 M) copied, 9.153627 s, 22 M/s
    freshul:/sdcard # gzip -k mmcblk0p31.bin
    freshul:/sdcard # gzip -k mmcblk0p33.bin
    freshul:/sdcard # ls -a1l
    total 441047
    drwxrws--- 2 u0_a136  media_rw      3452 2023-09-16 07:15 Alarms
    drwxrws--x 5 media_rw media_rw      3452 2023-09-16 07:15 Android
    drwxrws--- 2 u0_a136  media_rw      3452 2023-09-16 07:15 Audiobooks
    drwxrws--- 2 u0_a136  media_rw      3452 2023-09-16 07:15 DCIM
    drwxrws--- 2 u0_a136  media_rw      3452 2023-09-16 07:15 Documents
    drwxrws--- 2 u0_a136  media_rw      3452 2023-09-16 07:15 Download
    drwxrws--- 3 u0_a136  media_rw      3452 2023-09-16 07:15 Movies
    drwxrwsr-x 4 media_rw media_rw      3452 2023-09-16 07:15 Music
    drwxrws--- 2 u0_a136  media_rw      3452 2023-09-16 07:15 Notifications
    drwxrws--- 3 u0_a136  media_rw      3452 2023-09-16 07:15 Pictures
    drwxrws--- 2 u0_a136  media_rw      3452 2023-09-16 07:15 Podcasts
    drwxrws--- 2 u0_a136  media_rw      3452 2023-09-16 07:15 Recordings
    drwxrws--- 2 u0_a136  media_rw      3452 2023-09-16 07:15 Ringtones
    -rw-rw---- 1 u0_a136  media_rw 209715200 2023-09-19 04:02 mmcblk0p31.bin
    -rw-rw---- 1 u0_a136  media_rw  30223108 2023-09-19 04:02 mmcblk0p31.bin.gz
    -rw-rw---- 1 u0_a136  media_rw 209715200 2023-09-19 04:03 mmcblk0p33.bin
    -rw-rw---- 1 u0_a136  media_rw   1486120 2023-09-19 04:03 mmcblk0p33.bin.gz

    More for study...

    As no GW6 nore Android 13 Leaks available...
    1
    Seems progress in north ... K...


    Code:
    R900XXU1BWH3/R900OXM1BWH3

    I have not seen GW4 Firmware...



    Meanwhile I have no luck with Combination Firmware on my SM-R875F...
    Absolute useless for me...


    Still no ADB over USB cable...

    AND I am tooo stupid to use WiFi...
    My Router is detected... but i can not enter Password...

    I have 2 options...

    Blabla Phone
    Blabla Watch

    And Icons are so f%&in. tiny...
    My old eyes can not see nor read...

    I can not send something to Watch nor pull files from device...

    For Flashing Stock Firmware I needed Patched Odin Version... as SHA256 Error or something like this...

    Only as info.

    Best Regards
    1
    SM-R895UUUUUUSSSSA FVD4:

    SM-R895F AUGF for OLB Region

    This is all at the moment what I have for SM-R895.

    Best Regards
    Absolute bloody legend, this helped my gw4c get off of an old R895USQU1AUGC firmware installed during refurbishment that couldn't be forced updated from, ty again
  • 6
    Screenshot_20230814_023225_cidmanager.pngScreenshot_20230814_023228_cidmanager.pngScreenshot_20230814_023231_cidmanager.pngScreenshot_20230814_023233_cidmanager.png

    @adfree

    We will feast and celebrate with the Gods, as another victory was finally found and claimed.
    5
    Looks like it could be harder since Tizen...

    A
    Stock Firmware for netOdin/Odin not available yet...

    B
    Combination Firmware not available yet

    C
    FOTA Delta File for study I have:
    Code:
    current_version=R860XXU1AUGE/R860OXM1AUGE/
    updated_version=R860XXU1BUH9/R860OXM1BUH9/

    D

    In this FOTA Delta file from SM-R860 I can see overview... from CSC... Region Code OXM:
    Code:
    csc_information=OXM
    
    ACR
    AFR
    ARO
    ASA
    ATO
    AUT
    BGL
    BNG
    BRI
    BTU
    BVO
    CAC
    CAM
    CHO
    CIS
    COO
    DBT
    DKR
    ECT
    EGY
    EUR
    EUX
    ILO
    INU
    ITV
    KOO
    KSA
    LTA
    LUX
    MEA
    MID
    MRU
    MWD
    MXO
    MYM
    NEE
    NPL
    PAK
    PEO
    PHE
    PHN
    ROM
    SEB
    SEE
    SEK
    SER
    SIO
    SKZ
    SLK
    SWA
    TGY
    THO
    TPA
    TPH
    TTT
    TUN
    TUR
    UPO
    UYO
    XAA
    XAC
    XEF
    XEH
    XEO
    XEZ
    XFA
    XJP
    XME
    XNZ
    XSA
    XSE
    XSG
    XSK
    XSP
    XTC
    XXV
    ZTO

    More things... comes... later...

    Best Regards
    5
    No idea when Full firmwares for study leak...

    Meanwhile to understand maybe more about funny Region... helpfull this Android App to check Firmware:

    It is possible to decrypt from Test Server...

    Then maybe more clear...


    OXM seems also for DBT ZTO and so on...

    A
    In theory linked FOTA Delta should work for AUGE DBT or SER or ZTO...

    Question is only how to update manually...

    B
    Roll out official could be in waves... but could be also more funny like we allready knows...

    We will see the future of GW4 support.

    Best Regards
    5
    Tiny progress...

    Searched in system.img... 3 GB File for text string:
    Code:
    sdk_gwear_x86

    27 hits... then I changed few of them and renamed...
    Now I see:
    Code:
    sdk_gwear_x05

    05 is inside:
    Code:
    # begin common build properties
    # autogenerated by build/make/tools/buildinfo_common.sh
    ro.product.build.date=Thu Dec 16 16:58:02 UTC 2021
    ro.product.build.date.utc=1639673882
    ro.product.build.fingerprint=google/sdk_gwear_x86/generic_x86_arm:11/RWD4.211013.004/8008904:userdebug/dev-keys
    ro.product.build.id=RWD4.211013.004
    ro.product.build.tags=dev-keys
    ro.product.build.type=userdebug
    ro.product.build.version.incremental=8008904
    ro.product.build.version.release=11
    ro.product.build.version.release_or_codename=11
    ro.product.build.version.sdk=30
    ro.product.product.brand=google
    ro.product.product.device=generic_x86_arm
    ro.product.product.manufacturer=unknown
    ro.product.product.model=sdk_gwear_x05
    ro.product.product.name=sdk_gwear_x06
    # end common build properties
    #
    # ADDITIONAL PRODUCT PROPERTIES
    #
    ro.build.characteristics=emulator,nosdcard,watch
    persist.traced.enable=1
    ro.com.google.ime.system_lm_dir=/product/usr/share/ime/google/wear_lms
    dalvik.vm.systemservercompilerfilter=speed-profile
    ro.product.vndk.version=30


    Okidoki:
    Code:
    ro.product.product.model=sdk_gwear_x05


    Need few attempts...

    But good I can edit system.img without crash... so no Hash check or something in this Direction...

    Edit 1.

    Step 1 done in funny riddle... puzzle...

    Need more time to correct the other props...

    Goal is to enter exact Playstore for GW4... and/or Samsung Apps...

    In Emulator on PC...
    5
    "We" have still tiny problems...

    My problemS

    A
    I have NO device nor plan to buy in near future...

    B
    + no full Firmware for Odin/netOdin nor study...
    + no Combination Firmware...

    C
    No Service Manual leak...

    D
    Community to find solution is sooooooo f. huge...
    This problem is not new... something like this I know since years...

    Feel free to find solution for us. :cowboy:


    Thanx in advance.


    No joke.

    Feel free to do something.

    Best Regards