FORUMS
Remove All Ads from XDA

[H918|US996|H830] recowvery, unlock your V20/G5 potential - now with TWRP!

1,462 posts
Thanks Meter: 5,832
 
Post Reply Email Thread
If you are not an H918, H830, or US996 (Unlocked, NOT US Cellular) user, kindly leave this thread, this will not do anything for your device, exchange it if you're so desperate. Thank you.

Note for US996: It's probably easier for you guys just to flash TWRP the normal way and pull your battery then do the factory reset dance to get in!

Team Win Recovery Project 3.0.2-1



Alright, so you guys have probably heard about me working on this project for a week now. Sorry it's been taking so long, there's been so many variables and hurdles to go through!

I don't own the device myself, so it was all done over TeamViewer thanks to @slayerh4x and @Darriousx who stayed around in the #twrp channel on freenode to assist with their devices.

This will allow you to install TWRP and flash SuperSU!

Step 1: Unlocking your bootloader

You will need to unlock your bootloader first. For this you'll probably need LG's drivers.

Windows: http://tool.lime.gdms.lge.com/dn/dow...=UW00120120425
Mac: http://tool.lime.gdms.lge.com/dn/dow...=UW00320110909

You will also need adb and fastboot. You can download them in a portable small form factor here:
http://forum.xda-developers.com/andr...tools-t3402497

Start by turning on developer options in Settings -> About device -> Software info -> Build number. (tap 7 times until it's enabled)

Now navigate to Settings -> Developer options -> OEM unlock. (turn it on)

Don't ever turn OEM unlock or Developer options off when using a custom ROM or recovery. This could lose to loss of all your data.

For your computer to see ADB, you will need to put the phone in PTP mode (for transferring images). I don't know why this is, a misconfiguration in LG's kernel gadget drivers maybe?

Extract adb and fastboot to a folder on your PC.

Type adb start-server and make sure to check the notification on your phone to accept debugging authorization.
You can reboot into fastboot mode with adb reboot bootloader once authorized.
If it fails to authorize or show the notification on your phone, you may need to try other USB ports.

H918/H830 users only:
To unlock your bootloader, use fastboot oem unlock once the phone boots into fastboot mode.
Warning: This step will wipe all your data and factory reset your phone!

You can check the status of your bootloader lock with the fastboot getvar all command.
ex. (bootloader) unlocked:yes

You should now boot back into your phone (fastboot reboot).

You will probably need to complete the Android setup wizard at this point to get access to ADB again.

US996 users only:
To unlock your bootloader, follow the unlock instructions on LG's site (I can't really help you there):
https://developer.lge.com/resource/m...yTypeCode=ANRS

Once you're finished with unlocking your bootloader, continue on to step 2.

Step 2: Running recowvery

You can find the recowvery binaries (you need to download all of these) at:
https://build.nethunter.com/android-...irtycow/arm64/

You're now ready to follow the recowvery installation instructions.
See here: https://github.com/jcadduono/android...rtycow#running (running section)

Bonus: There's also a full write up on that page on how recowvery works if you're into that kind of stuff.

Step 3: Flashing TWRP & Rooting

Notice: There is currently no decryption support, just the same as the LG G5, I'm running into the exact same scenario (unable to start rpmb device).
Due to this, I have disabled hardware decryption in this build to keep it stable. If you wish to have your data work in TWRP, you will need to disable decryption.
If you're coming from the Note 7 or S7, this will be a familiar scenario for you.

Once you've got your permissive shell in adb, you will have access to your partitions via dd.
You should transfer TWRP to your internal storage (name in twrp.img) using MTP, you can also just use adb push. (mentioned here)

Download TWRP: (official builds, V20 is waiting for TWRP 3.1.0 for twrp.me download)
H918: https://build.nethunter.com/test-bui...0.2-1-h918.img
US996: https://build.nethunter.com/test-bui....2-1-us996.img
H830: https://twrp.me/devices/lgg5h830.html

This step requires that you've used dirtycow to replace /system/bin/run-as with recowvery-run-as. If you've rebooted since doing that, you will need to go back and do that again.
Code:
adb push twrp-3.0.2-x-xxxx.img /sdcard/twrp.img
adb shell
$ run-as exec dd if=/sdcard/twrp.img of=/dev/block/bootdevice/by-name/recovery
"<wait for it to complete>"
$ reboot recovery
You should be inside TWRP now. It will ask you if you want to enable system modifications. You should swipe yes, otherwise your OS will replace TWRP on next boot.

Flash the latest zip from https://build.nethunter.com/android-...y-opt-encrypt/ to turn off forced encryption at boot and allow you to boot a modified system. If you're flashing SuperSU.zip, it will also do this for you so this won't be necessary.
Warning: If you don't flash either no-verity-opt-encrypt or SuperSU, you will probably end up in a horrifying never-ending boot loop of "corruption"!

Latest SuperSU: https://download.chainfire.eu/supersu

To disable encryption after flashing SuperSU or the no-verity-opt-encrypt zip, you must use the [Format Data] button on the Wipe page in TWRP. No other options will work.
Back up all your internal storage and apps data that you can to your PC. You can use Titanium Backup with SuperSU before doing this step if you like.
Warning: Using [Format Data] will wipe all your apps and data (including internal storage) off the phone, giving you the out-of-the-box experience of a new phone!
Once this is done, you should be able to backup/restore/use any function of TWRP without any issues.

Flashed SuperSU? You're done! Boot up (it will reboot a few times) and set up your SuperSU Manager to your liking and give this post a thanks!

Step 4: Have fun!

I know a few people have mentioned donating, there is a button right on this post under my username. :P
Sorry, I don't keep a list as I prefer to keep people's information confidential, but if you do send any money my way, you can request that I mention you at the bottom of this post with any details.

I ask that people please not attach files in this thread, everything required is mentioned in this post, and should be stable in its present state. Thank you.
The Following 191 Users Say Thank You to jcadduono For This Useful Post: [ View ]
 
 
30th October 2016, 07:44 PM |#2  
slayerh4x's Avatar
Senior Member
Thanks Meter: 66
 
More
Thanks for testing on my phone! =]
The Following 6 Users Say Thank You to slayerh4x For This Useful Post: [ View ] Gift slayerh4x Ad-Free
30th October 2016, 07:53 PM |#3  
justthefacts's Avatar
Senior Member
Thanks Meter: 846
 
More
Does This wipe data on the phone?
30th October 2016, 08:00 PM |#4  
slayerh4x's Avatar
Senior Member
Thanks Meter: 66
 
More
Quote:
Originally Posted by justthefacts

Does This wipe data on the phone?

Unlocking the bootloader does.
The Following User Says Thank You to slayerh4x For This Useful Post: [ View ] Gift slayerh4x Ad-Free
30th October 2016, 09:14 PM |#5  
jinkerz9430's Avatar
Senior Member
Flag Miami, FL
Thanks Meter: 303
 
Donate to Me
More
Quote:
Originally Posted by jcadduono

Alright, so you guys have probably heard about me working on this project for a week now. Sorry it's been taking so long, there's been so many variables and hurdles to go through!

I don't own the device myself, so it was all done over TeamViewer thanks to @slayerh4x and @Darriousx who stayed around in the #twrp channel on freenode to assist with their devices.

Understand that I'm still working on getting TWRP to boot, there seems to be something about the stock kernel sources that doesn't want TWRP to be a part of it. :P

This will not get you SuperSU or app root access, this is only a root shell allowing you to flash TWRP when it's ready and do other things.
This does however open up some methods of installing SuperSU without TWRP. @Chainfire might have some ideas if he wishes to show up here and stir up some noise.
We do have the ability to do a full ramdisk unpack, edit, repack, and flash within the confines of /data/local while booted into the permissive system using recowvery-applypatch.
This should bring some opportunities, but it's still more sane to just wait for TWRP.

For the instructions on using recowvery, you should read the README.md on the GitHub page:
https://github.com/jcadduono/android_external_dirtycow

You can find the recowvery binaries prebuilt at:
https://build.nethunter.com/android-...irtycow/arm64/

You will need to unlock your bootloader first. For this you'll probably need LG's drivers.

Windows: http://tool.lime.gdms.lge.com/dn/dow...=UW00120120425
Mac: http://tool.lime.gdms.lge.com/dn/dow...=UW00320110909

You will also need adb and fastboot. You can download them in a portable small form factor here:
http://forum.xda-developers.com/andr...tools-t3402497

Start by turning on developer options in Settings -> About device -> Software info -> Build number. (tap 7 times until it's enabled)

Now navigate to Settings -> Developer options -> OEM unlock. (turn it on)

Don't ever turn OEM unlock or Developer options off when using a custom ROM or recovery. This could lose to loss of all your data.

For your computer to see ADB, you will need to put the phone in PTP mode (for transferring images). I don't know why this is, a misconfiguration in LG's kernel gadget drivers maybe?

Extract adb and fastboot to a folder on your PC.

Type adb start-server and make sure to check the notification on your phone to accept debugging authorization.
You can reboot into fastboot mode with adb reboot bootloader once authorized.
If it fails to authorize or show the notification on your phone, you may need to try other USB ports.

To unlock your bootloader, use fastboot oem unlock once the phone boots into fastboot mode.
Warning: This step will wipe all your data and factory reset your phone!

You can check the status of your bootloader lock with the fastboot getvar all command.
ex. (bootloader) unlocked:yes

You should now boot back into your phone (fastboot reboot).

You're now ready to follow the recowvery installation instructions.
See here: https://github.com/jcadduono/android_external_dirtycow

There's also a full write up on that page on how recowvery works if you're into that kind of stuff.
I probably need to proof read it though, I'm really tired.

Thank you for taking the time to begin with the first step to develop on this device! (although i will have to do a replacement tomorrow for 2 defects that emerged on my phone) I always had in mind that this device had only a 50% of chances to get rooted, and that it might actually never get rooted . But now chances have increased even more thanks to your hard work. and also thanks to the others you previously mentioned. Let us see if Chainfire takes an interest on adding the final details
30th October 2016, 09:35 PM |#6  
NotATreoFan's Avatar
Developer Committee and More
Wrong Side of Heaven, Righteous Side of Hell
Thanks Meter: 7,531
 
More
I've got ADB working fine, but get nothing with fastboot. Just a blank line when I type 'fastboot devices'. Tried 3 different USB ports also. Windows 10 x64.

I did grab the ADB/fastboot files linked in the first post, but the older files I had don't work either, and they have no issues with my Nexus 7 2013 and HTC 10.
The Following User Says Thank You to NotATreoFan For This Useful Post: [ View ]
30th October 2016, 10:24 PM |#7  
mrtruckincowboy's Avatar
Senior Member
Thanks Meter: 208
 
Donate to Me
More
Promising stuff ,I just upgraded to this phone yesterday ,and was hoping to eventually get custom roms on it

Sent from my VS995 using Tapatalk

---------- Post added at 03:24 PM ---------- Previous post was at 03:21 PM ----------

Quick question should I wait or take the ota updates?

Sent from my VS995 using Tapatalk
30th October 2016, 10:55 PM |#8  
bambam126's Avatar
Senior Member
Flag Norwalk CA
Thanks Meter: 135
 
More
So Idk what to do or how to get the file to flash it.. Any help?
30th October 2016, 11:17 PM |#9  
Senior Member
Flag Fort Wayne
Thanks Meter: 424
 
More
Quote:
Originally Posted by mrtruckincowboy

Promising stuff ,I just upgraded to this phone yesterday ,and was hoping to eventually get custom roms on it

Sent from my VS995 using Tapatalk

---------- Post added at 03:24 PM ---------- Previous post was at 03:21 PM ----------

Quick question should I wait or take the ota updates?

Sent from my VS995 using Tapatalk

My advice? Never, ever take an update until the developers say that they are sure they can exploit it. From what I can see, this process uses the "dirty cow" exploit which will assuredly be fixed on the next security update.

---------- Post added at 05:11 PM ---------- Previous post was at 05:10 PM ----------

Quote:
Originally Posted by bambam126

So Idk what to do or how to get the file to flash it.. Any help?

Why not wait until they can get full root and TWRP? As I see it, this process is to help other developers and people that know what they're doing refine and advance the move to full root. I don't think it's quite ready for prime time yet. It does nothing but get the foot in the door for rooting.

---------- Post added at 05:17 PM ---------- Previous post was at 05:11 PM ----------

And, we're off to the races. Let the "I bricked my phone" threads begin!
The Following 5 Users Say Thank You to douger1957 For This Useful Post: [ View ] Gift douger1957 Ad-Free
30th October 2016, 11:39 PM |#10  
jinkerz9430's Avatar
Senior Member
Flag Miami, FL
Thanks Meter: 303
 
Donate to Me
More
Quote:
Originally Posted by douger1957

[/COLOR]And, we're off to the races. Let the "I bricked my phone" threads begin!

LOL! YASSSSSS i can imagine that already. There will be some who will get it hard bricked .

---------- Post added at 05:39 PM ---------- Previous post was at 05:34 PM ----------

Quote:
Originally Posted by mrtruckincowboy

Promising stuff ,I just upgraded to this phone yesterday ,and was hoping to eventually get custom roms on it

Sent from my VS995 using Tapatalk

---------- Post added at 03:24 PM ---------- Previous post was at 03:21 PM ----------

Quick question should I wait or take the ota updates?

Sent from my VS995 using Tapatalk

Isn't your model the verizon model? If it is... I havent heard any Verizon user to have unlocked the bootloader for their LG V20's. Not to be a downer, but the methods on this thread are only possible for the H918 (Tmobile variant). unless someone found a way to unlock Verizon's bootloader.
The Following User Says Thank You to jinkerz9430 For This Useful Post: [ View ] Gift jinkerz9430 Ad-Free
31st October 2016, 12:06 AM |#11  
mrtruckincowboy's Avatar
Senior Member
Thanks Meter: 208
 
Donate to Me
More
Quote:
Originally Posted by joseguillen1994

LOL! YASSSSSS i can imagine that already. There will be some who will get it hard bricked .

---------- Post added at 05:39 PM ---------- Previous post was at 05:34 PM ----------



Isn't your model the verizon model? If it is... I havent heard any Verizon user to have unlocked the bootloader for their LG V20's. Not to be a downer, but the methods on this thread are only possible for the H918 (Tmobile variant). unless someone found a way to unlock Verizon's bootloader.

They discuss unlocking in the first post so I'm optimistic. Even if not there has been custom stuff done around locked bootloader.I came from s4 and that was possible with the loki method so im optimistic

Sent from my VS995 using Tapatalk
Post Reply Subscribe to Thread

Tags
dirtycow, h918, recowvery, root, v20

Guest Quick Reply (no urls or BBcode)
Message:
Previous Thread Next Thread
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes