• Introducing XDA Computing: Discussion zones for Hardware, Software, and more!    Check it out!

[ROM][UB] February 10: JAGUAR SIRIUS LP 5.1.1 OFFICIAL HARDENED

Search This thread

optimumpro

Senior Member
Jan 18, 2013
6,793
14,314
October 17. Rom fixed: boots and works fine on Xperia Z3, which is like Z2 a Shinano device.

This is the Official Jaguar rom for Honami, which is based on AOSP with some flavors from Slim and Dirtyunicorn. The main difference from other roms is the emphasis on security and multiple features. With that in mind , let's see what Jaguar has to offer:

1. Hardened Kernel, modified M5; hardened rom built with HYPERTOOL 5.4
2. All ciphers enabled in kernel instead of just a few
3. Hardened/Fortified Bionic and Libs
4. Fstack protection strong to resist buffer overflows
5. Many System apps and processes are made read-only, to reduce elevation of privilege
6. Selinux replaced with Tomoyo Security, Yam security
7. Disc encryption, keymaster to 256 bit AES instead of 128
8. Latest TWRP with working brightness and ability to decrypt Data
9. Random number generation mixed hardware/software, as recommended by Linus Torwalds
10. Options to randomize host on every boot
11. Option to have a separate password for lock screen and boot
12. Qualcomm's Time Services disabled due to leaking on early boot (set time to automatic to get it from your carrier). Forget it. Jaguar now has Sony TimeKeep ported from MM/Nougat that sets the correct time locally without the internet or GSM signal. So, even if you are in Airplane mode, the time will be right on each reboot. All you need to do is to set it right once on a live device
13. WIFI Background Scanning disabled to prevent leaking
14. Internet disabled for both WIFI and Data until Afwall is set and activiated (Afwall included in download, install as regular app)
15. The phone is VOLTE ready and you have all network options available in Cell menu (not just LTE/WCDMA/GSM)
16. GRsecurity features, such as Sidechannel implemented
17. Some Pax Security Features
18. Option to deny USB connection: denied always; denied when locked; and allowed always
19. Hardened webview with Google and other "interesting" IPs removed
20. Prevention of bruteforcing screen pin: the phone will reboot upon 3 unsuccessful attempts
21. Perfect_Event_Paranoid ported from Grsecurity: now third party apps can't use other apps including system to elevate privileges
22. Camera hardware button works to focus, take pictures and start video recording
23. Option to disable writing to Tombstones (a lot of private info is dumped there if there is a crash)
24. Option to disable continuing writing of logcat
25. Option to disable device cameras: back; front, both or none
26. Always latest Google Security Patches
27. Always latest Code Aurora Security Patches
28. Changes ported directly from Google Android Gerrit, so most of those in MM and even N are in this rom
29. About 80% of kernel changes are ported into Jaguar kernel from 3.10 and 3.18 (not Sony AOSP 3.10 that has Down Syndrome, but Linux/Google/Code Aurora one)
30. Rom is odexed to significantly increase boot speed (under 30 seconds) and application start
31. DNS_Crypt that gives you a native option to have numerous Dns providers all encrypted (in Settings/Security
32. Seccomp/secure computing implemented and enabled in kernel
31. Many more security features ported from Linux and Copperhead OS

Other features include: Layers Theme Engine; Native Call Recording with interface integrated in Dialer with no restrictions; Privacy Guard; Native Wakelock Blocker; Native Black List; Global Menu; Slim Recents; Traffic Indicators; Advanced Reboot; Slim Pie; CPU Info on Screen; Ram Bar in Recents; Open Source Superuser included and integrated in Settings; True Offline Charging with Screen Off; Kernel Adiutor included (unzip and install as a normal app) and integrated in Settings; FM Radio and Recording plus more

Things users need to know to have smooth experience:. These are not bugs, but rather an explanation of some features

1. If you want to do data encryption, keep in mind that unlike Android, Jaguar uses 256 bit encryption. If you were encrypted on other roms, you won't be able to decrypt. So, wipe encryption and then re-encrypt on Jaguar. Also, keep in mind that if you ever did factory reset on official TWRP 3+ for honami, your data partition is screwed and have to be resized to enable encryption. This has nothing to do with the rom, but rather with the official TWRP itself. Fastboot my unofficial TWRP 3.0.2, which, by the way has working brightness, as well as ability to decrypt and mount data

2. Jaguar contains a script running on early boot, which cuts the internet access to both WIFI and Data until Afwall is running. This is done to prevent leaking, as well as having all your internet traffic routed through some interesting number of servers, including this IP: 26.147.196.22. So, install Afwall and activate it, otherwise, no Internet for you

3. If your system language is different from English and you want to make changes in Phone/Cell Network settings, switch to English first, make the changes and then return to your language. The changes you made will hold. If you try to make the changes in your language, you will have com.android.phone crash. Localization takes time and is virtually impossible to implement in Jaguar, which is a one-person-rom

4. Sony TimeKeep, which is ported from MM/N, now sets the correct time on reboot without the Internet or GSM signal. All you need to do is set it once and TimeKeep will save/recalculate/restore the same on each reboot

5. GAPPS: if you use them, you need to flash them right after the rom (or each update) and before reboot. Flashing after reboot will result in multiple f/c

6. Due to Volte implementation, you will need to flash (one time only) stock LP or MM baseband, but only if you have no GSM signal


Download: All updates and change logs are in Post #3

Instructions:

1. Be on LP, Have TWRP (fastboot my unofficial version), unlocked bootloader and root
2. In TWRP, wipe data/factory reset, then wipe System/Data/Cache/Dalvik
3. Flash the rom
4. If you use xposed, flash the latest installer
5. Reboot, install Afwall and Kernel Adiutor as normal apps; activate Afwall to have Internet
6. Enjoy the rom, say thank you, donate or do both


Warning: If your device and/or anyone in the immediate vicinity dies, don't blame me: it is all China and Russia's fault.

Credit: CM, AOSP, Slimroms, DU, Copperhead OS, Myself5 (kernel)

UPDATED KERNEL SOURCE: https://forum.xda-developers.com/devdb/project/dl/?id=23107 . Don't flash. This is not kernel, but rather sources to compile kernel

Kernel Source: https://github.com/AOSP-Jaguar/kernel_sony_msm8974


XDA:DevDB Information
Jaguar Sirus LP 5.1.1 Hardened, ROM for the Sony Xperia Z2

Contributors
optimumpro
ROM OS Version: 5.1.x Lollipop
ROM Kernel: Linux 3.4.x
ROM Firmware Required: Unlocked Bootloader
Based On: AOSP, SLIM, DU

Version Information
Status: Stable
Stable Release Date: 2016-08-02

Created 2016-08-03
Last Updated 2017-02-10

XDA:DevDB Information
JAGUAR SIRIUS LP 5.1.1 OFFICIAL HARDENED, ROM for the Sony Xperia Z2

Contributors
optimumpro
ROM OS Version: 5.1.x Lollipop

Version Information
Status: Testing

Created 2016-10-17
Last Updated 2017-02-10
 
Last edited:

optimumpro

Senior Member
Jan 18, 2013
6,793
14,314
Development update as of February 16 and some Screenshots

February 16: I broke my Z1 screen again and am not in the mood for after market screens. And I am sick and tired of Sony crappy treatment of development community.

I am now looking at Lenovo Zuk Z2 or Z2 pro. Both excellent phones with the latest CPU and made out of metal and glass by Motorola which they bought from Google a couple of years ago. Zuk is friendly to developers and their blobs don't dumb down camera and they don't seek to "unify" bugs for all their devices. I no longer wish to support a fat bastard corporation that can't make a good phone, but thinks that just by putting their logo on the phone would make it worth $700.

RE Jaguar. I will continue to maintain Jaguar mainly with security patches... for a while, but my main work will be concentrated on Zuk. There is a lot of work to be done cleaning Android N and implementing security and other features from Jaguar...



Screenshots are here: http://forum.xda-developers.com/showpost.php?p=62560391&postcount=2
 
Last edited:

optimumpro

Senior Member
Jan 18, 2013
6,793
14,314
Download/Change Log Section

February 10: New release including

1. February security patches
2. Sony TimeKeep to set the correct time on boot
3. Dns_Crypt (numerous choices of encrypted Dns providers) in Settings/Security
4. Open Source Superuser integrated in Settings
5. Seccomp/secure computing implemented and enabled in kernel
6. Twrp 3.0.X that supports data decryption, as well as TimeKeep

To install TWRP use fastboot: fastboot flash recovery recoveryZ2.img or any app that allows you to flash recoveries

To use Dns_Crypt, you must allow the Internet for 'apps run as root' in Afwall


Download Rom: https://forum.xda-developers.com/devdb/project/dl/?id=23094

Download TWRP: https://forum.xda-developers.com/devdb/project/dl/?id=23093
___________________________________________________________________
January 7: New release with January security patches from Google and Code Aurora. Also, qcom time service is back.

Download: https://forum.xda-developers.com/devdb/project/dl/?id=22460

If you were on a previous release, you may flash dirty. Otherwise - fresh install (read OP)
_______________________________________________________________________________
December 10: Rom updated to include:

1. December security patches
2. Signature Spoofing (as in Omniroms)
3. USSD fixed (maybe)


Download: http://forum.xda-developers.com/devdb/project/dl/?id=22011

________________________________________________________________________________
November 10. Rom updated to include November Security Patches. I have also removed Supersu, as the rom has a built-in root manager.

Download: http://forum.xda-developers.com/devdb/project/dl/?id=21430

________________________________________________________________________________
October 17. Rom updated to include October Google and Code Aurora security patches. Also, there is a new option to deny applications' background access to clipboard.

Rom Download: http://forum.xda-developers.com/devdb/project/dl/?id=20955

Kernel Adiutor/Afwall Download: http://forum.xda-developers.com/devdb/project/dl/?id=20954
 
Last edited:

abasba

Senior Member
May 19, 2014
66
13
Is shinano and sirius shares same components?
Wouldnt flashing shinano rom hard-brick sirius?
 

optimumpro

Senior Member
Jan 18, 2013
6,793
14,314
Is shinano and sirius shares same components?
Wouldnt flashing shinano rom hard-brick sirius?

Oh, please. Both Z2 and Z3 use shinano platform, but the roms are different for each device. This one is made specifically for Z2-Sirius... So, you won't brick your device if you flash it... :)
 

wheal

Senior Member
Apr 20, 2011
85
11
I get a FC from Camera Workaround after every reboot?

Fresh install, wiped all before.
 

r960xt

New member
Jan 8, 2011
1
0
Hello sir, i've been using this rom for a couple of days. it's been great and stable rom for me.
one little bug that i have noticed. it's that i can't do Copy-paste text on this rom.. on any app.
any solution ?
 

optimumpro

Senior Member
Jan 18, 2013
6,793
14,314
Hello sir, i've been using this rom for a couple of days. it's been great and stable rom for me.
one little bug that i have noticed. it's that i can't do Copy-paste text on this rom.. on any app.
any solution ?

You do know that you have to long press on screen and then do copy/paste? On some apps copying doesn't work, but on most it does...
 
  • Like
Reactions: SaeedMJ

SaeedMJ

Member
Jul 22, 2012
20
2
.
hi bro,
great work! this is so light and smooth in use :)
i liked minimum pre-apps on this ROM
but as you know copy/past texts not work at all! (copy function works very well but past doesn't work)

have you any solution for this?
 

SaeedMJ

Member
Jul 22, 2012
20
2
.
hi bro,
great work! this is so light and smooth in use
i liked minimum pre-apps on this ROM
but as you know copy/past texts not work at all! (copy function works very well but past doesn't work)

have you any solution for this?

/// oh!my mistake. I found it...
setting/security/allow background clipboard access
and finally past button comeback :)

thanks again for this awesome ROM , bro . everything is perfect.

and just a few more questions...
1.is Fast charging active in your kernel?

2.i've get bootloop when i flashed xposed(arm-sdk22-v86) in twrp.
Is this ROM not compatible with xposed framework?
 
Last edited:

Raspberry Pi

Member
Oct 8, 2015
27
1
Seoul
where is your unofficial TWRP?

I want to use AES 256 encryption on your rom.
In your post, you recommended using unofficial TWRP when i use encryption.
But I can't find your unofficial TWRP for SIRIUS.:crying:
Can i have a link?
 

Top Liked Posts

  • There are no posts matching your filters.
  • 15
    October 17. Rom fixed: boots and works fine on Xperia Z3, which is like Z2 a Shinano device.

    This is the Official Jaguar rom for Honami, which is based on AOSP with some flavors from Slim and Dirtyunicorn. The main difference from other roms is the emphasis on security and multiple features. With that in mind , let's see what Jaguar has to offer:

    1. Hardened Kernel, modified M5; hardened rom built with HYPERTOOL 5.4
    2. All ciphers enabled in kernel instead of just a few
    3. Hardened/Fortified Bionic and Libs
    4. Fstack protection strong to resist buffer overflows
    5. Many System apps and processes are made read-only, to reduce elevation of privilege
    6. Selinux replaced with Tomoyo Security, Yam security
    7. Disc encryption, keymaster to 256 bit AES instead of 128
    8. Latest TWRP with working brightness and ability to decrypt Data
    9. Random number generation mixed hardware/software, as recommended by Linus Torwalds
    10. Options to randomize host on every boot
    11. Option to have a separate password for lock screen and boot
    12. Qualcomm's Time Services disabled due to leaking on early boot (set time to automatic to get it from your carrier). Forget it. Jaguar now has Sony TimeKeep ported from MM/Nougat that sets the correct time locally without the internet or GSM signal. So, even if you are in Airplane mode, the time will be right on each reboot. All you need to do is to set it right once on a live device
    13. WIFI Background Scanning disabled to prevent leaking
    14. Internet disabled for both WIFI and Data until Afwall is set and activiated (Afwall included in download, install as regular app)
    15. The phone is VOLTE ready and you have all network options available in Cell menu (not just LTE/WCDMA/GSM)
    16. GRsecurity features, such as Sidechannel implemented
    17. Some Pax Security Features
    18. Option to deny USB connection: denied always; denied when locked; and allowed always
    19. Hardened webview with Google and other "interesting" IPs removed
    20. Prevention of bruteforcing screen pin: the phone will reboot upon 3 unsuccessful attempts
    21. Perfect_Event_Paranoid ported from Grsecurity: now third party apps can't use other apps including system to elevate privileges
    22. Camera hardware button works to focus, take pictures and start video recording
    23. Option to disable writing to Tombstones (a lot of private info is dumped there if there is a crash)
    24. Option to disable continuing writing of logcat
    25. Option to disable device cameras: back; front, both or none
    26. Always latest Google Security Patches
    27. Always latest Code Aurora Security Patches
    28. Changes ported directly from Google Android Gerrit, so most of those in MM and even N are in this rom
    29. About 80% of kernel changes are ported into Jaguar kernel from 3.10 and 3.18 (not Sony AOSP 3.10 that has Down Syndrome, but Linux/Google/Code Aurora one)
    30. Rom is odexed to significantly increase boot speed (under 30 seconds) and application start
    31. DNS_Crypt that gives you a native option to have numerous Dns providers all encrypted (in Settings/Security
    32. Seccomp/secure computing implemented and enabled in kernel
    31. Many more security features ported from Linux and Copperhead OS

    Other features include: Layers Theme Engine; Native Call Recording with interface integrated in Dialer with no restrictions; Privacy Guard; Native Wakelock Blocker; Native Black List; Global Menu; Slim Recents; Traffic Indicators; Advanced Reboot; Slim Pie; CPU Info on Screen; Ram Bar in Recents; Open Source Superuser included and integrated in Settings; True Offline Charging with Screen Off; Kernel Adiutor included (unzip and install as a normal app) and integrated in Settings; FM Radio and Recording plus more

    Things users need to know to have smooth experience:. These are not bugs, but rather an explanation of some features

    1. If you want to do data encryption, keep in mind that unlike Android, Jaguar uses 256 bit encryption. If you were encrypted on other roms, you won't be able to decrypt. So, wipe encryption and then re-encrypt on Jaguar. Also, keep in mind that if you ever did factory reset on official TWRP 3+ for honami, your data partition is screwed and have to be resized to enable encryption. This has nothing to do with the rom, but rather with the official TWRP itself. Fastboot my unofficial TWRP 3.0.2, which, by the way has working brightness, as well as ability to decrypt and mount data

    2. Jaguar contains a script running on early boot, which cuts the internet access to both WIFI and Data until Afwall is running. This is done to prevent leaking, as well as having all your internet traffic routed through some interesting number of servers, including this IP: 26.147.196.22. So, install Afwall and activate it, otherwise, no Internet for you

    3. If your system language is different from English and you want to make changes in Phone/Cell Network settings, switch to English first, make the changes and then return to your language. The changes you made will hold. If you try to make the changes in your language, you will have com.android.phone crash. Localization takes time and is virtually impossible to implement in Jaguar, which is a one-person-rom

    4. Sony TimeKeep, which is ported from MM/N, now sets the correct time on reboot without the Internet or GSM signal. All you need to do is set it once and TimeKeep will save/recalculate/restore the same on each reboot

    5. GAPPS: if you use them, you need to flash them right after the rom (or each update) and before reboot. Flashing after reboot will result in multiple f/c

    6. Due to Volte implementation, you will need to flash (one time only) stock LP or MM baseband, but only if you have no GSM signal


    Download: All updates and change logs are in Post #3

    Instructions:

    1. Be on LP, Have TWRP (fastboot my unofficial version), unlocked bootloader and root
    2. In TWRP, wipe data/factory reset, then wipe System/Data/Cache/Dalvik
    3. Flash the rom
    4. If you use xposed, flash the latest installer
    5. Reboot, install Afwall and Kernel Adiutor as normal apps; activate Afwall to have Internet
    6. Enjoy the rom, say thank you, donate or do both


    Warning: If your device and/or anyone in the immediate vicinity dies, don't blame me: it is all China and Russia's fault.

    Credit: CM, AOSP, Slimroms, DU, Copperhead OS, Myself5 (kernel)

    UPDATED KERNEL SOURCE: https://forum.xda-developers.com/devdb/project/dl/?id=23107 . Don't flash. This is not kernel, but rather sources to compile kernel

    Kernel Source: https://github.com/AOSP-Jaguar/kernel_sony_msm8974


    XDA:DevDB Information
    Jaguar Sirus LP 5.1.1 Hardened, ROM for the Sony Xperia Z2

    Contributors
    optimumpro
    ROM OS Version: 5.1.x Lollipop
    ROM Kernel: Linux 3.4.x
    ROM Firmware Required: Unlocked Bootloader
    Based On: AOSP, SLIM, DU

    Version Information
    Status: Stable
    Stable Release Date: 2016-08-02

    Created 2016-08-03
    Last Updated 2017-02-10

    XDA:DevDB Information
    JAGUAR SIRIUS LP 5.1.1 OFFICIAL HARDENED, ROM for the Sony Xperia Z2

    Contributors
    optimumpro
    ROM OS Version: 5.1.x Lollipop

    Version Information
    Status: Testing

    Created 2016-10-17
    Last Updated 2017-02-10
    7
    Development update as of February 16 and some Screenshots

    February 16: I broke my Z1 screen again and am not in the mood for after market screens. And I am sick and tired of Sony crappy treatment of development community.

    I am now looking at Lenovo Zuk Z2 or Z2 pro. Both excellent phones with the latest CPU and made out of metal and glass by Motorola which they bought from Google a couple of years ago. Zuk is friendly to developers and their blobs don't dumb down camera and they don't seek to "unify" bugs for all their devices. I no longer wish to support a fat bastard corporation that can't make a good phone, but thinks that just by putting their logo on the phone would make it worth $700.

    RE Jaguar. I will continue to maintain Jaguar mainly with security patches... for a while, but my main work will be concentrated on Zuk. There is a lot of work to be done cleaning Android N and implementing security and other features from Jaguar...



    Screenshots are here: http://forum.xda-developers.com/showpost.php?p=62560391&postcount=2
    7
    Download/Change Log Section

    February 10: New release including

    1. February security patches
    2. Sony TimeKeep to set the correct time on boot
    3. Dns_Crypt (numerous choices of encrypted Dns providers) in Settings/Security
    4. Open Source Superuser integrated in Settings
    5. Seccomp/secure computing implemented and enabled in kernel
    6. Twrp 3.0.X that supports data decryption, as well as TimeKeep

    To install TWRP use fastboot: fastboot flash recovery recoveryZ2.img or any app that allows you to flash recoveries

    To use Dns_Crypt, you must allow the Internet for 'apps run as root' in Afwall


    Download Rom: https://forum.xda-developers.com/devdb/project/dl/?id=23094

    Download TWRP: https://forum.xda-developers.com/devdb/project/dl/?id=23093
    ___________________________________________________________________
    January 7: New release with January security patches from Google and Code Aurora. Also, qcom time service is back.

    Download: https://forum.xda-developers.com/devdb/project/dl/?id=22460

    If you were on a previous release, you may flash dirty. Otherwise - fresh install (read OP)
    _______________________________________________________________________________
    December 10: Rom updated to include:

    1. December security patches
    2. Signature Spoofing (as in Omniroms)
    3. USSD fixed (maybe)


    Download: http://forum.xda-developers.com/devdb/project/dl/?id=22011

    ________________________________________________________________________________
    November 10. Rom updated to include November Security Patches. I have also removed Supersu, as the rom has a built-in root manager.

    Download: http://forum.xda-developers.com/devdb/project/dl/?id=21430

    ________________________________________________________________________________
    October 17. Rom updated to include October Google and Code Aurora security patches. Also, there is a new option to deny applications' background access to clipboard.

    Rom Download: http://forum.xda-developers.com/devdb/project/dl/?id=20955

    Kernel Adiutor/Afwall Download: http://forum.xda-developers.com/devdb/project/dl/?id=20954
    5
    I've not flashed it. I just say, that lollipop have a general battery problem that is fixed with 6.0

    Xperias Z1-Z3 don't have any rom related battery drain in lollipop. Some other devices had a so called radio active bug, but not Xperias...
    5
    New Release

    Rom updated to include many new features. See post #3 for download and description...