SM-T295 - Finally rooted tablet!! (updated 19-May-2020)

KRAZZIEBOY

Member
Mar 29, 2014
41
22
28
indore
In answer to your question, basically, yes.
I only flash the 3 files in the .tar file

I am on a Windows 10 laptop. Only 3 files need to be modified by Magisk: boot.img, recovery.img, vbmeta.img
I use Hex Editor Neo for overlaying the modified kernel and recovery files..
At the end of these 2 stock files is code that needs to be there, thus the 65 MB file size.
So I open the stock .img files (boot, recovery) in Hex Editor Neo, and copy the modded boot, recovery code into each stock .img file..
I use cygwin to create the .tar file, then flash with ODIN 3.1.14
copied the modded code to existing code or delete existing code? if just copy where you copied at the start and at the end?
 

J.Michael

Senior Member
Jan 20, 2018
306
113
43
copied the modded code to existing code or delete existing code? if just copy where you copied at the start and at the end?
Magisk replaces original-image with patched-image. patched-image is shorter than original-image. Copy original-image to patched-and-padded-image. Then, overwrite the beginning of patched-and-padded-image with patched-image. Use something like "dd" with conv=notrunc, which will copy what there is of the source file, without erasing the extra of the destination file.
 
  • Like
Reactions: KRAZZIEBOY

KRAZZIEBOY

Member
Mar 29, 2014
41
22
28
indore
Magisk replaces original-image with patched-image. patched-image is shorter than original-image. Copy original-image to patched-and-padded-image. Then, overwrite the beginning of patched-and-padded-image with patched-image. Use something like "dd" with conv=notrunc, which will copy what there is of the source file, without erasing the extra of the destination file.
ok what is the exact procedure to boot into recovery after flashing files?
 

J.Michael

Senior Member
Jan 20, 2018
306
113
43
Recovery: vol up + pwr key => when see logo release power key
What about the hiccup screen warning that the bootloader is unlocked? Do you let go of both buttons? Do you press the power button to dismiss the warning? Do you hold the Volume Up while releasing and re-pressing Power?
 

zabro19

New member
Apr 21, 2020
1
0
0
Hello, please i'm not familiar with this , can you please help me to root my tablet sm-t295 and i will pay you . my skype : SoufMeez
 

gcrutchr

Senior Member
Jun 11, 2009
1,094
520
113
Bangkok
Hello, please i'm not familiar with this , can you please help me to root my tablet sm-t295 and i will pay you . my skype : SoufMeez
PLEASE READ ALL OF THIS BEFORE STARTING!! VERY IMPORTANT!!

Here are the steps to root your tablet:
Make a backup of you apps & data before doing this. This procedure will
wipe all you data.

Go to settings.
Select software info
Tap build number 7 times to get into developer mode
Go back to main settings page.
Scroll to bottom and select developer mode
In middle of page find OEM unlocking
Make sure slider is all the way to the right (should say allow bootloader to be unlocked)

Unlock bootloader:
1. turn off tablet
2. press and hold down vol up & vol down keys together
3. insert usb cable (should already be connected to computer)
4. when bootloader screen appears, release all keys
5. press and hold vol up key for 5 seconds, then release
6. read instructions on screen to unlock bootloader (this will wipe all your data)

After reboot, go through normal setup.

Now for the hard part.

You need to download the complete ROM you have installed on your Tablet.
It will be better if you have the same ROM version as I do in post #1.
You need to unzip the ROM so you can flash it in ODIN.

If you are on the same ROM version as in my post #1, then you can just download my rooted files. You also need to download the complete stock ROM to be flashed.

Unzip my downloaded root files zip file.

In the AP* file, you need to replace my files in the zip in post #1: system.img, recovery.img & vbmeta.img

Start ODIN. Select files for BL*, AP*, CSC* & CP*
For CSC file, select HOME_CSC*
Uncheck auto reboot

Flash ROM.
Press vol dn + pwr key
As soon as screen goes blank press vol up key and hold
When get into recovery, select data wipe, the reboot
Set up phone as you normally would.
After setup, go to Play store and install Magisk Manager. Run Magisk Manager to see if you have root.

Additional info from Magisk web site:

Important: Uncheck “Auto Reboot” in Options!
Magisk is now successfully flashed to your device! But there are still several steps before you can properly use the device.
We now want to boot into the stock recovery to factory reset our device.
Full data wipe is mandatory! Do not skip this step.
Press Power + Volume Down to exit download mode. As soon as the screen turns off, immediately press the combo key to boot to recovery (e.g. on the S10 it is Power + Bixby + Volume Up). Since we want to boot into stock recovery, continue pressing the volume up button until you see the stock recovery screen.
Use volume buttons to navigate through the stock recovery menu, and the power button to select an option. Choose Wipe data/factory reset to wipe the data of the device.
This time, we can finally boot to the system with Magisk. Select Reboot system now, and immediately press the combo key to recovery. After seeing the bootloader warning screen, release all buttons so it can boot to the system.
 
Last edited:

LittleTivor

New member
Apr 9, 2019
2
0
0
Organizing instructions

PLEASE READ ALL OF THIS BEFORE STARTING!! VERY IMPORTANT!!

Here are the steps to root your tablet:
Make a backup of you apps & data before doing this. This procedure will
wipe all you data.
Hello gcrutchr, is it okay to ask you to merge those instructions to the start of the thread? That would make it easier to follow the guide and avoid mistakes. Since I've never rooted any device after KitKat I feel a bit insecure to do so. It'd really help me to see all of the instructions clearly on the first post and in the correct order.

Thanks in advance, and sorry about the trouble.
 
Last edited:

tiago156

Member
Nov 1, 2007
11
0
0
Santiago
Trouble flashing T295

Hello,

i'm trying for the last few days to be able to flash the magisk tar file on my T295 (firmware XXS3ATB2), but I'm stuck with this error:

Custom Binary (vbmeta) Blocked By OEM LOCK (attached images)

IMG_1512.jpg

Was that caused by the OEM LOCK: ON? On your tablet do you have OEM LOCK: ON as well? Im not sure if I get it right on the bootloader unlock procedure, I have the "OEM Unlocking" option activated.

IMG_1511.jpg



Thanks!
 

tiago156

Member
Nov 1, 2007
11
0
0
Santiago
Hello,

i'm trying for the last few days to be able to flash the magisk tar file on my T295 (firmware XXS3ATB2), but I'm stuck with this error:

Custom Binary (vbmeta) Blocked By OEM LOCK (attached images)

View attachment 5023125

Was that caused by the OEM LOCK: ON? On your tablet do you have OEM LOCK: ON as well? Im not sure if I get it right on the bootloader unlock procedure, I have the "OEM Unlocking" option activated.

View attachment 5023127



Thanks!
Found a way to unlock the bootloader, I did several tries and the timing of pressing the VOL+/VOL- and connecting the USB cable was the issue, now I Have the bootloader unlocked! :victory:

Buuut, I got this error:

IMG_1517.jpg

and on Odin I got PASS

View attachment 5024431

Anyone with this error message?
 

Tianhe

Senior Member
Mar 16, 2011
648
144
73
I have root on my SM-T295 A8 tablet!!

Attached AP.tar file is for XXU2ASL3 only.

T295-Magisk-AP.tar

In the AP* file, you need to replace my files in the zip: system.img, recovery.img & vbmeta.img

Noob question - which program did you use to replace the files in original AP .tar.md5 with your patched files ? Also, will it affect md5 integrity and cause flashing failure or do we need patched Odin?

Pardon my ignorance, i am more familiar with fastboot commands / TWRP and never used Samsung.
 

J.Michael

Senior Member
Jan 20, 2018
306
113
43
Found a way to unlock the bootloader, I did several tries and the timing of pressing the VOL+/VOL- and connecting the USB cable was the issue, now I Have the bootloader unlocked! :victory:

Buuut, I got this error:

View attachment 5024429

and on Odin I got PASS

View attachment 5024431

Anyone with this error message?
This is exactly what I got when I finally succeeded: tablet says "SECURE CHECK FAIL: vbmeta", Odin says pass, if I manage to go directly from download screen to recovery to wipe data, and then manage to boot towards recovery without actually getting to recovery mode, I finally have Magisk installed.

I'm surprised you got Odin to say pass. I thought that the reason I got it was because, on my last try, the AP.tar I used only had three files in it. I've been assuming that Odin finished downloading before the tablet got around to telling Odin that the tablet didn't like the vbmeta.
 

gcrutchr

Senior Member
Jun 11, 2009
1,094
520
113
Bangkok
Noob question - which program did you use to replace the files in original AP .tar.md5 with your patched files ? Also, will it affect md5 integrity and cause flashing failure or do we need patched Odin?

Pardon my ignorance, i am more familiar with fastboot commands / TWRP and never used Samsung.
You can use winzip, 7-zip or rar. Do no worry about MD5.
 

star.k

New member
May 11, 2020
2
0
0
Sm-t295n a 8.0 TWRP,Rooting

Can you convert it to SM-T295N TWRP, ROOT file? If not, can you convert T295N to the T295 file you provided?

Can you convert it to SM-T295N TWRP, ROOT file? If not, can you convert T295N to the T295 file you provided?:):)

T295N I have a full version of Android 9.0. Is it possible to ROOT?
 

Tianhe

Senior Member
Mar 16, 2011
648
144
73
You can use winzip, 7-zip or rar. Do no worry about MD5.
Thank you, i couldn't delete/replace files with 7-zip (error) but used another program to unzip .tar, replace files and rezip to .tar without adding .md5. Couldn't reboot to recovery so i couldn't wipe data but since the tablet was already factory reset before this process, it didn't matter much i guess. Interestingly, even adb command for rebooting to recovery only takes me to BL unlock warning screen and then reboots to system.

Some questions, if you don't mind:

1) How to apply OTA's in absence of full ROM file while keeping Magisk intact?

2) This is not an A/B device but SAR-A only; no custom recovery as yet but will applying OTA be affected if i alter some system files which compromises system integrity ?

NOTE: If somebody tries to repeatedly flash the modified files through Odin, KG Status changes to pre-normal and you are pretty much locked out.

Also, internal memory decreases from 32 GB to 8GB (even after nand erase and flashing .pit file) unless you flash stock.
 
Last edited:

Tianhe

Senior Member
Mar 16, 2011
648
144
73
@gcrutchr

<In the AP* file, you need to replace my files in the zip: system.img, recovery.img & vbmeta.img>

1) Doesn't your magisk_patched.tar contain modified boot, recovery & vbmeta ? If yes, then how can it replace system.img ?

2) On XXS3ATB2 (INS) update, the relevant magisk_patched.tar fails to flash in Odin. Do we need to flash the entire modified AP file or only the magisk_patched.tar in AP ?
 

J.Michael

Senior Member
Jan 20, 2018
306
113
43
Thank you, i couldn't delete/replace files with 7-zip (error) but used another program to unzip .tar, replace files and rezip to .tar without adding .md5. Couldn't reboot to recovery so i couldn't wipe data but since the tablet was already factory reset before this process, it didn't matter much i guess. Interestingly, even adb command for rebooting to recovery only takes me to BL unlock warning screen and then reboots to system.

Some questions, if you don't mind:

1) How to apply OTA's in absence of full ROM file while keeping Magisk intact?


2) This is not an A/B device but SAR-A only; no custom recovery as yet but will applying OTA be affected if i alter some system files which compromises system integrity ?

NOTE: If somebody tries to repeatedly flash the modified files through Odin, KG Status changes to pre-normal and you are pretty much locked out.

Also, internal memory decreases from 32 GB to 8GB (even after nand erase and flashing .pit file) unless you flash stock.
@gcrutchr

<In the AP* file, you need to replace my files in the zip: system.img, recovery.img & vbmeta.img>

1) Doesn't your magisk_patched.tar contain modified boot, recovery & vbmeta ? If yes, then how can it replace system.img ?

2) On XXS3ATB2 (INS) update, the relevant magisk_patched.tar fails to flash in Odin. Do we need to flash the entire modified AP file or only the magisk_patched.tar in AP ?
Device: SM-T295 (gtoxx)
Firmware: T295XXS3ATB2 (9.0 Pie)
BL status: Unlocked

No custom recovery is available for this device, hell it's difficult to even access stock recovery. Since it's a Samsung Tab launched in 2019, I am reasonably sure that it's SAR A-only.


Edit: Finally managed to obtain magisk_patched.tar
But when flashing it to AP slot through Odin3 v3.14.1 (alongwith other files), it fails at the last step.
_XmitData_Write
Complete(Write) operation failed.

I believe it is because of Secure check fail:vbmeta error.

Note: Samsung Kies not installed, using original USB Cable ( I can flash stock firmware all right)

Any guidance @Didgeridoohan or anybody else ? Samsung is a mess !!
I'm not sure what state you're in now. I think your best bet is to start from scratch: Download the stock firmware to your tablet. Make sure it boots. Make sure the bootloader is unlocked. Remove any accounts (Google or Samsung). Make sure you can boot to recovery. Pick a Magisk, put it on the tablet, use it to patch the AP file of the firmware you just flashed to the tablet, drag the patched AP file back to a PC, perform @gcrutchr's magic, and build a new tar file with just three files in it: boot.img, recovery.img, vbmeta.img. Run Odin again, using your new, tiny, tar file for AP, and using the stock firmware files for the other three slots. (Use HOME_CSC in the CSC slot.)

Wu's instructions make it sound like it's important to go straight, from flashing the magisk_patched files, to recovery to wipe data / factory reset. I don't know why it's important, but do it. If you fumble it, don't even try to boot, go back to the "flash the tiny tar" step.

If you manage to get from flashing to wiping, then keep trying to boot towards but not quite to recovery to give Magisk a chance to run. Try it a dozen times before you give up.

Once you have Magisk installed, I don't think you can install an OTA update. There's lots of talk about how to install the latest firmware, but I think if you want to have Magisk when you're done, you have to find a copy of the firmware -- you can't do an OTA update of a modified system, and you can't install Magisk without a copy of the firmware for Magisk to patch.

Finally, I think you should stick to this thread. It's where you're most likely to get the attention of people who have successfully installed Magisk on a SM-T295.