• Introducing XDA Computing: Discussion zones for Hardware, Software, and more!    Check it out!

Moto E6 Twrp and Root

Search This thread

eluallen

Member
Mar 20, 2017
19
11
Moto E6
I only lost IMEI while booted into Magisk via recovery mode. Restart phone regularly and should get IMEI back. If not rooted and no IMEI you may try rescue via LMSA in order to recover from lost IMEI.

Then if you want root flash one of phhusson's arm32-binder64-ab or a64 GSI's. Android 9 root works fine but Android 10i had to download phh superuser apk to from apk mirror. After updating app root works fine with Android 10 as well.
 

franco619

Member
Nov 26, 2015
34
2
I only lost IMEI while booted into Magisk via recovery mode. Restart phone regularly and should get IMEI back. If not rooted and no IMEI you may try rescue via LMSA in order to recover from lost IMEI.

Then if you want root flash one of phhusson's arm32-binder64-ab or a64 GSI's. Android 9 root works fine but Android 10i had to download phh superuser apk to from apk mirror. After updating app root works fine with Android 10 as well.
How can I know what is the best gsi for this device?
 
Last edited:

eluallen

Member
Mar 20, 2017
19
11
Moto E6
I've tried testing several Developer Luke's/Express Luke's GSI's. Some either didn't boot or nav buttons didn't work properly. If you don't mind not having root I think Resurrection Remix is the most customizable and therefore is the GSI I'll be using for now.
 

franco619

Member
Nov 26, 2015
34
2
I've tried testing several Developer Luke's/Express Luke's GSI's. Some either didn't boot or nav buttons didn't work properly. If you don't mind not having root I think Resurrection Remix is the most customizable and therefore is the GSI I'll be using for now.
sorry for asking so many questions I am new at this
but what boot.img can i use to install magisk in gsi roms?Thank you
 

franco619

Member
Nov 26, 2015
34
2
I managed to unlock the bootloader on my moto e6 plus 4gb 64rom and it freezes on the twrp screen, any solutions?
install the old firmware again with lmsa when finished And don't let it start normally
Start fastboot mode and put the command to unlock bootloader again after that start fastboot mode again and run bat file to install twrp
So I fixed it I have version 2 / 32gb
 
  • Like
Reactions: blxk23

blxk23

New member
May 22, 2020
3
0
install the old firmware again with lmsa when finished And don't let it start normally
Start fastboot mode and put the command to unlock bootloader again after that start fastboot mode again and run bat file to install twrp
So I fixed it I have version 2 / 32gb

when installing the old firmware, it restarts only. I remove the battery so that it does not? could it be twrp not working?
 

Top Liked Posts

  • There are no posts matching your filters.
  • 6
    Root is possible. The way I achieved it is first to follow the official bootloader unlock method given by Motorola. Then install Magisk Manager V 7.5.1 (latest as of today). After that have magisk patch the boot image and recovery image, and flash them both through fastboot. It will say the boot partition is signed but when you Flash it to the recovery partition it will tell you the image is either not signed or corrupt. Don't worry about this, it does not affect loading back into system or back into the bootloader or recovery. Remember, after this you will have to boot through recovery every time you reboot or you will not have root until you do. Unfortunately I am still trying to work on TWRP, and it is going rather slow as this is my first attempt at compiling a custom recovery and I am no developer, and am learning as I go... Hope I helped!!!
    4
    I had to flash it in a very specific way, because with sp flash tool you need to have the auth file and the specific Download agent to write to this phone and I looked everywhere how to flash this thing and I couldn't make it flash any file in any way.

    But then I discovered that the official Lenovo tool uses SPFlashTool to flash mediatek devices, so I messed around with it for a while and found out how to flash files to this phone

    What I did was download the Lenovo MOTO Smart Assistant for Windows, went into the flash tab, selected rescue; then selected MOTO device, i chose my specific device model (which is Moto E6 Plus XT2025-1 4G/64G) and clicked in the download button to download the latest firmware.

    After it finishes downloading, you can go into the software's downloaded tab, and in the bottom there's an option to open the default download directory. In there are all the files for rescuing the smartphone (Full ROM, Lenovo's provided spflashtool (which i guess is the one Lenovo MOTO Smart Assistant uses to flash this phone), Some Download Agents for SPFlashtool, and among other things).

    So, what i did at this point is I closed the tool, got into the Firmware's folder, grabbed the Boot.img and modified it with Magisk's android app (there is no root needed if you don't intend to flash the file to the actual device) and afterwards, replaced the old boot.img in the tool's download folder with the new one generated by Magisk (of course, after renaming it to boot.img) and opened the tool again and went into the same tab, selected again my device, clicked in the rescue button instead of the download one, and followed instructions on screen. It seemed like everything went fine, but when I started the phone, bootloader stated that the system integrity was changed (because I wrote to flash that new boot.img) that's when i realised that the dm-verity is not disabled in boot.img on Oreo -> + devices, but at least i knew that we could flash files to the device.

    At that point I tried everything to disable DM verity and other verification: Using kitchens (In windows and in Linux) , using python scripts, Manually searching where to disable it, but i couldn't get any software to correctly disable it and /or to unpack any of the img files of the Firmware (system.img and some others unpacked but i didn't find anything there) so if anyone can help with this it would be very appreciated.

    After doing some research, I found that this device has AVB 1.1.0 (Android Verified Boot) enabled. What this means is that the boot.img is linked to another partition called vbmeta.img, which verifies the signature of the boot.img at boot time. The kernel searchs this verifications keys in vbmeta.img, if the key is OK the phone will boot.
    I think we need to find a way to disable AVB in boot.img, or patch vbmeta.img so the kernel thinks that it has the right signature hence the phone will boot.
    I found some information in some forums of xiaomi, and oneplus devices and what they do is patch the vbmeta.img so they can boot a customized boot image (https://miui.blog/redmi-note-7/patched-vbmeta-redmi-note-7-lavender/).

    For the root on this device, I've tried this exploit found in this thread https://forum.xda-developers.com/android/development/amazing-temp-root-mediatek-armv8-t3922213 with no positive results. After running the exploit it shows me the message "This platform cannot be supported". Tomorrow I'll try downgrading to a older build to see if the exploit works there. (don't know if it can be achieved though I have the link of a older one https://drive.google.com/file/d/1v7yfNuxsMYHgJKlPVqsDAJtF9AycVxfS/view).
    4
    How did you flash the boot.img? via sp flash tool or fastboot?

    I had to flash it in a very specific way, because with sp flash tool you need to have the auth file and the specific Download agent to write to this phone and I looked everywhere how to flash this thing and I couldn't make it flash any file in any way.

    But then I discovered that the official Lenovo tool uses SPFlashTool to flash mediatek devices, so I messed around with it for a while and found out how to flash files to this phone

    What I did was download the Lenovo MOTO Smart Assistant for Windows, went into the flash tab, selected rescue; then selected MOTO device, i chose my specific device model (which is Moto E6 Plus XT2025-1 4G/64G) and clicked in the download button to download the latest firmware.

    After it finishes downloading, you can go into the software's downloaded tab, and in the bottom there's an option to open the default download directory. In there are all the files for rescuing the smartphone (Full ROM, Lenovo's provided spflashtool (which i guess is the one Lenovo MOTO Smart Assistant uses to flash this phone), Some Download Agents for SPFlashtool, and among other things).

    So, what i did at this point is I closed the tool, got into the Firmware's folder, grabbed the Boot.img and modified it with Magisk's android app (there is no root needed if you don't intend to flash the file to the actual device) and afterwards, replaced the old boot.img in the tool's download folder with the new one generated by Magisk (of course, after renaming it to boot.img) and opened the tool again and went into the same tab, selected again my device, clicked in the rescue button instead of the download one, and followed instructions on screen. It seemed like everything went fine, but when I started the phone, bootloader stated that the system integrity was changed (because I wrote to flash that new boot.img) that's when i realised that the dm-verity is not disabled in boot.img on Oreo -> + devices, but at least i knew that we could flash files to the device.

    At that point I tried everything to disable DM verity and other verification: Using kitchens (In windows and in Linux) , using python scripts, Manually searching where to disable it, but i couldn't get any software to correctly disable it and /or to unpack any of the img files of the Firmware (system.img and some others unpacked but i didn't find anything there) so if anyone can help with this it would be very appreciated.
    2
    It was added, it's hidden away in developer options,
    May require an unlock code from Motorola though,

    Indeed, there is an OEM unlock option inside developer options, but it makes no difference if it is enabled or disabled when you go to the bootloader and try either fastboot oem get_unlock_data or flashing unlock, it always returns "unknown command" , and even trying to get any oem command to work, it returns "unknown command". I'm sure that my device is installed correctly because any other command for fastboot works, like erasing data and cache partitions.
    2
    Yes! please upload the oficial ROM if you can. It will be always be very helpful have that files here in the forum.

    I've been trying to make a full backup of this device, but I couldn't figure out how to do it properly. I've found a possible root solution here https://forum.xda-developers.com/android/development/amazing-temp-root-mediatek-armv8-t3922213/amp/ but I don't want to take any risks without backups.

    This is for XT-2025-1: https://mega.nz/file/WYghESTL#sQiQzUmsVsTy3s9EPliH0SuoJhKUgF9J06BAcgh42JM

    All the files can be downloaded officially and flashed with Lenovo MOTO Smart Assistant, there are some other models in there