Re: Тестирование Новых возможностей BEST'a -II
#552
Пытаюсь восстановить ST_SECURITY => DAMAGED
в RM-133 N-73 с помощью новой функции в 1.24.2. (- Added Variant cert recover (N73 security repair) on Restore CCC/HWC)
ТА восстановлен после воды, но: нормально шьётся, стирается. SDD, Simlock repair без проблем.
Вот его Selftest
Код:
Initializing Tests...
IMEI : 352916022020292 , Phone : RM-133 Nokia N73
Get keys...
PASSED | ST_TAHVOINT_TEST
PASSED | ST_UEM_CBUS_IF_TEST
PASSED | ST_EAR_DATA_LOOP_TEST
PASSED | ST_SIM_CLK_LOOP_TEST
PASSED | ST_SIM_IO_CTRL_LOOP_TEST
PASSED | ST_SIM_LOCK_TEST
MINOR | ST_SECURITY_TEST
PASSED | ST_PWR_KEY_TEST
PASSED | ST_CURRENT_CONS_TEST
PASSED | ST_BACKUP_BATT_TEST
PASSED | ST_CMT_APE_WAKEUP_TEST
PASSED | ST_SLEEPCLK_FREQ_TEST
PASSED | ST_RADIO_TEST
PASSED | ST_HOOKINT_TEST
PASSED | ST_BTEMP_TEST
PASSED | ST_VIBRA_TEST
->ERROR | ST_MBUS_RX_TX_LOOP_TEST
PASSED | ST_EXT_DEVICE_TEST
PASSED | ST_IR_LOOP_TEST
PASSED | ST_KEYBOARD_STUCK_TEST
PASSED | ST_LPRF_IF_TEST
PASSED | ST_CAMERA_IF_TEST
PASSED | ST_CAMERA_ACCELERATOR_TEST
PASSED | ST_SEC_CAMERA_IF_TEST
PASSED | ST_CAMERA_AUTOFOCUS_TEST
PASSED | ST_LPRF_AUDIO_LINES_TEST
PASSED | ST_MAIN_LCD_IF_TEST
PASSED | ST_BT_WAKEUP_TEST
SelfTests end
Read Info:
Код:
Phone found!
Series 60 Device detected!
read info... - Ok
Reading Phone Info....
Connected phone - Nokia N73
Software ver : V 05wk47v61.1 09-07-08 RM-133 (c) Nokia.
IMEI : 352916022020292
Ape Ver :
APE Var :
APE ADSP:
DSP Ver : scarfe_mc.05wk46v50p2
APE Test:
PPM :
CNT :
Product SN : SBH144666
Product code : 0563983
Base Prd.code: 0527006
Module code : 0202855
Long Prod.SN :
Hardware info=======
HWID : 6000
Retu : 15
Tahvo : 22
Batery: 4191 mV
Camera:
CMT BT:
APE BT:
APE HW:
LCDVer:
RF ic : 17211721
Lock info ===========
IMEI : 352916022020292
IMEI spNet :
IMEI svNet :
Conf key : 0000000000000000
Provider key : 2440700000000000
Provider : AT&T;U.S.A. (3650)
Counters : Key 0 [3] , Fbus 0 [10]
Blocks : 7
LOCK STATUS :
=============================
BLK : 1
Lock1:Open Lock2:Open Lock3:Open Lock4:Open Lock5:Open
BLK : 2
Lock1:Open Lock2:Open Lock3:Open Lock4:Open Lock5:Open
BLK : 3
Lock1:Open Lock2:Open Lock3:Open Lock4:Open Lock5:Open
BLK : 4
Lock1:Open Lock2:Open Lock3:Open Lock4:Open Lock5:Open
BLK : 5
Lock1:Open Lock2:Open Lock3:Open Lock4:Open Lock5:Open
BLK : 6
Lock1:Open Lock2:Open Lock3:Open Lock4:Open Lock5:Open
BLK : 7
Lock1:Open Lock2:Open Lock3:Open Lock4:Open Lock5:Open
=============================
LOCKS : All Open
=============================
User Code : 12345
UserDataExLevel : Full [PhoneBook, Calendar, PWD, SMS, Gallery]
Done!
Check:
Код:
Connect phone on selected interface...
Read and Check phone data...
Checking BUS...
Switch jaf to FlashMode...
FlashMode set Ok
Booting phone...
BOOT 1ST : C0
APE part info :
APE ASICID : 17100708
APE MODE ID : 00
APE PUB ID : 737A24E08BE12AC7442EE56F8F02D39F3A782F52
APE R_HASH : 49A97E826B93BA20B7ED0B082475C005
APE ROM ID : 1DFD66132C872FD4
CMT part info :
CMT ASICID : 000000010000022600010006010C192101003000
CMT EM0 ID : 00000295
CMT EM1 ID : 00000B22
CMT PUB ID : 1F200106FD5D025443452F4AE2339FC2BCAFA9C7
CMT MODE ID : 00
CMT R_HASH : BAF3A9C3DBFA8454937DB77F2B8852B1
CMT ROM ID : 273F6D55DFAAF68F
CMT : Sending 2nd loader...
Use : RAP3Gv3_2nd.fg , Rev : 0.0 Ver : 10.42.0
CMT Loader sent, Boot Ok
MCU configuration
CMT Flash ID : 22E800EC < SAMSUNG [SEC] => K5G2829ATC
FLASHID : 22E800EC , CMT , NOR
FLCNT : 00000000000000000000000000000000000000
CMT Flash ID : 0000FFFF < Bad Flash Type , if MMC - It Ok
FLASHID : 0000FFFF , CMT , MMC , EXT
TransmissionReq : 16 bit, Single
TransmissionReq : Accepted, 16 bit, Single
Sending ALGO....
Use : RAP3Gv3_algo.fg , Rev : 0.0 Ver : 10.40.0
CMT Algo sent!
TransmissionReq : 32 bit, Dual
TransmissionReq : Accepted, 32 bit, Dual
PAPUBKeys : 5E8D0D504A0902E261268C14FCD8A2C9093523BCBD
APE : Sending 2nd loader...
Use : helen3_2nd.fg , Rev : 0.0 Ver : 1.35.0
APE Loader sent, Boot Ok
MCU configuration
APE Flash ID : 00A100EC < SAMSUNG [SEC] => K5E1G12ACM [NAND]
FLASHID : 00A100EC , APE , NAND
FLCNT : 010100FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
Sending ALGO....
Use : h3_xsr15_flash_alg.fg , Rev : 0.0 Ver : 1.49.0
APE Algo sent!
TransmissionReq : 32 bit, Dual
TransmissionReq : Accepted, 32 bit, Dual
PAPUBKeys : 5E8D0D504A0902E261268C14FCD8A2C9093523BCBD
Boot done!
Switch jaf to FBUS...
FbusMode set Ok
SimLock status : SimLock is Ok
Security status : Security Damaged!!!!! :(
SDD Key status : SD Data is Ok
Лог стирания, затем прошивки:
Код:
Switch jaf to FBUS...
FbusMode set Ok
User ACCEPTED FULL ERASE
Checking BUS...
Switch jaf to FlashMode...
FlashMode set Ok
Booting phone...
BOOT 1ST : C0
APE part info :
APE ASICID : 17100708
APE MODE ID : 00
APE PUB ID : 737A24E08BE12AC7442EE56F8F02D39F3A782F52
APE R_HASH : 49A97E826B93BA20B7ED0B082475C005
APE ROM ID : 1DFD66132C872FD4
CMT part info :
CMT ASICID : 000000010000022600010006010C192101003000
CMT EM0 ID : 00000295
CMT EM1 ID : 00000B22
CMT PUB ID : 1F200106FD5D025443452F4AE2339FC2BCAFA9C7
CMT MODE ID : 00
CMT R_HASH : BAF3A9C3DBFA8454937DB77F2B8852B1
CMT ROM ID : 273F6D55DFAAF68F
CMT : Sending 2nd loader...
Use : RAP3Gv3_2nd.fg , Rev : 0.0 Ver : 10.42.0
CMT Loader sent, Boot Ok
MCU configuration
CMT Flash ID : 22E800EC < SAMSUNG [SEC] => K5G2829ATC
FLASHID : 22E800EC , CMT , NOR
FLCNT : 00000000000000000000000000000000000000
CMT Flash ID : 0000FFFF < Bad Flash Type , if MMC - It Ok
FLASHID : 0000FFFF , CMT , MMC , EXT
TransmissionReq : 16 bit, Single
TransmissionReq : Accepted, 16 bit, Single
Sending ALGO....
Use : RAP3Gv3_algo.fg , Rev : 0.0 Ver : 10.40.0
CMT Algo sent!
TransmissionReq : 32 bit, Dual
TransmissionReq : Accepted, 32 bit, Dual
PAPUBKeys : 5E8D0D504A0902E261268C14FCD8A2C9093523BCBD
APE : Sending 2nd loader...
Use : helen3_2nd.fg , Rev : 0.0 Ver : 1.35.0
APE Loader sent, Boot Ok
MCU configuration
APE Flash ID : 00A100EC < SAMSUNG [SEC] => K5E1G12ACM [NAND]
FLASHID : 00A100EC , APE , NAND
FLCNT : 010100FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
Sending ALGO....
Use : h3_xsr15_flash_alg.fg , Rev : 0.0 Ver : 1.49.0
APE Algo sent!
TransmissionReq : 32 bit, Dual
TransmissionReq : Accepted, 32 bit, Dual
PAPUBKeys : 5E8D0D504A0902E261268C14FCD8A2C9093523BCBD
Boot done!
Full Erase started...
Asic : CMT , Sub : NOR
Erase Area 0x00000000-0x00FFFFFF
Init Erase Mode Ok
Using TimeOut : 10 min ( 600 sec )
Erasing, wait.....
Erase CMT : erase Ok
Switch jaf to FBUS...
FbusMode set Ok
Phone disconected!
Connect phone on selected interface...
-> Phone not found.. :(
Fetching failed!
Connect phone on selected interface...
Read fail...!
Read and Check phone data...
Checking BUS...
Switch jaf to FlashMode...
FlashMode set Ok
Booting phone...
BOOT 1ST : C0
APE part info :
APE ASICID : 17100708
APE MODE ID : 00
APE PUB ID : 737A24E08BE12AC7442EE56F8F02D39F3A782F52
APE R_HASH : 49A97E826B93BA20B7ED0B082475C005
APE ROM ID : 1DFD66132C872FD4
CMT part info :
CMT ASICID : 000000010000022600010006010C192101003000
CMT EM0 ID : 00000295
CMT EM1 ID : 00000B22
CMT PUB ID : 1F200106FD5D025443452F4AE2339FC2BCAFA9C7
CMT MODE ID : 00
CMT R_HASH : BAF3A9C3DBFA8454937DB77F2B8852B1
CMT ROM ID : 273F6D55DFAAF68F
CMT : Sending 2nd loader...
Use : RAP3Gv3_2nd.fg , Rev : 0.0 Ver : 10.42.0
CMT Loader sent, Boot Ok
MCU configuration
CMT Flash ID : 22E800EC < SAMSUNG [SEC] => K5G2829ATC
FLASHID : 22E800EC , CMT , NOR
FLCNT : 000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
CMT Flash ID : 0000FFFF < Bad Flash Type , if MMC - It Ok
FLASHID : 0000FFFF , CMT , MMC , EXT
TransmissionReq : 16 bit, Single
TransmissionReq : Accepted, 16 bit, Single
Sending ALGO....
Use : RAP3Gv3_algo.fg , Rev : 0.0 Ver : 10.40.0
CMT Algo sent!
TransmissionReq : 32 bit, Dual
TransmissionReq : Accepted, 32 bit, Dual
PAPUBReq : Blank (Erased or HW error)
APE : Sending 2nd loader...
Use : helen3_2nd.fg , Rev : 0.0 Ver : 1.35.0
APE Loader sent, Boot Ok
MCU configuration
APE Flash ID : 00A100EC < SAMSUNG [SEC] => K5E1G12ACM [NAND]
FLASHID : 00A100EC , APE , NAND
FLCNT : 010100FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
Sending ALGO....
Use : h3_xsr15_flash_alg.fg , Rev : 0.0 Ver : 1.49.0
APE Algo sent!
TransmissionReq : 32 bit, Dual
TransmissionReq : Accepted, 32 bit, Dual
PAPUBReq : Blank (Erased or HW error)
Boot done!
Switch jaf to FBUS...
FbusMode set Ok
Phone not found :(
Connect phone on selected interface...
Connect phone on selected interface...
Core version : 1.24.2 , Rev : 2.1
Selected FlashSettings : Manual
Files Set for Flashing :
MCU : N73_4.0839.42.2.1_western_C00_PRD_cc.fpsx
PPM : N73_rofx_4.0839.42.2.1_PRD.V01
CNT : N73_userarea_4.0839.42.2.1.U01
Checking BUS...
Switch jaf to FlashMode...
FlashMode set Ok
Booting phone...
BOOT 1ST : C0
APE part info :
APE ASICID : 17100708
APE MODE ID : 00
APE PUB ID : 737A24E08BE12AC7442EE56F8F02D39F3A782F52
APE R_HASH : 49A97E826B93BA20B7ED0B082475C005
APE ROM ID : 1DFD66132C872FD4
CMT part info :
CMT ASICID : 000000010000022600010006010C192101003000
CMT EM0 ID : 00000295
CMT EM1 ID : 00000B22
CMT PUB ID : 1F200106FD5D025443452F4AE2339FC2BCAFA9C7
CMT MODE ID : 00
CMT R_HASH : BAF3A9C3DBFA8454937DB77F2B8852B1
CMT ROM ID : 273F6D55DFAAF68F
CMT : Sending 2nd loader...
Use : RAP3Gv3_2nd.fg , Rev : 0.0 Ver : 10.42.0
CMT Loader sent, Boot Ok
MCU configuration
CMT Flash ID : 22E800EC < SAMSUNG [SEC] => K5G2829ATC
FLASHID : 22E800EC , CMT , NOR
FLCNT : 000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
CMT Flash ID : 0000FFFF < Bad Flash Type , if MMC - It Ok
FLASHID : 0000FFFF , CMT , MMC , EXT
TransmissionReq : 16 bit, Single
TransmissionReq : Accepted, 16 bit, Single
Sending ALGO....
Use : RAP3Gv3_algo.fg , Rev : 0.0 Ver : 10.40.0
CMT Algo sent!
TransmissionReq : 32 bit, Dual
TransmissionReq : Accepted, 32 bit, Dual
PAPUBReq : Blank (Erased or HW error)
APE : Sending 2nd loader...
Use : helen3_2nd.fg , Rev : 0.0 Ver : 1.35.0
APE Loader sent, Boot Ok
MCU configuration
APE Flash ID : 00A100EC < SAMSUNG [SEC] => K5E1G12ACM [NAND]
FLASHID : 00A100EC , APE , NAND
FLCNT : 010100FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
Sending ALGO....
Use : h3_xsr15_flash_alg.fg , Rev : 0.0 Ver : 1.49.0
APE Algo sent!
TransmissionReq : 32 bit, Dual
TransmissionReq : Accepted, 32 bit, Dual
PAPUBReq : Blank (Erased or HW error)
Boot done!
Partitioning....
Partitioning Ok...
TransmissionReq : 32 bit, Dual
TransmissionReq : Accepted, 32 bit, Dual
Erase : Processing N73_4.0839.42.2.1_western_C00_PRD_cc.fpsx
Init Erase Mode Ok
Found 4 areas to erase, erase group
Asic : CMT , Sub : NOR
CMT , NOR , Area : 0x00080000 - 0x00731951
CMT , NOR , Area : 0x00000000 - 0x0005FFFF
CMT , NOR , Area : 0x001E0000 - 0x001FFFFF
CMT , NOR , Area : 0x00880000 - 0x00FEFFFF
Using TimeOut : 7 min ( 430 sec )
Erasing, wait.....
CMT : Group erase Ok
Found 4 areas to erase, erase group
Asic : APE , Sub : NAND
APE , NAND , Area : 0x00000000 - 0x0007FFFF
APE , NAND , Area : 0x00080000 - 0x000FFFFF
APE , NAND , Area : 0x00100000 - 0x0025FFFF
APE , NAND , Area : 0x003C0000 - 0x04E1FFFF
Erasing, wait.....
APE : Group erase Ok
TIME : Erase time : 00:00:06
PrReq : NOR, 00
PrReq : NAND, 010300000000000000000000000000
TransmissionReq : 32 bit, Dual
TransmissionReq : Accepted, 32 bit, Dual
Write : Processing N73_4.0839.42.2.1_western_C00_PRD_cc.fpsx
Init Write Mode Ok
CMT: Writing Hash CERT [NOLO]
CMT: Writing Hash CERT [KEYS]
CMT: Writing Hash CERT [PRIMAPP]
CMT: Writing Hash CERT [PASUBTOC]
CMT: Writing Hash CERT [PAPUBKEYS]
CMT: Writing Hash CERT [UPDAPP]
CMT: Writing Hash CERT [ADL]
CMT: Writing Hash CERT [DSP0]
CMT: Writing Hash CERT [MCUSW]
APE: Writing Hash CERT [KEYS]
APE: Writing Hash CERT [X-LOADER]
APE: Writing Hash CERT [PRIMAPP]
APE: Writing Hash CERT [SOS+LOADER]
APE: Writing Hash CERT [SOS*UPDAPP]
APE: Writing Hash CERT [SOS+UZIP]
APE: Writing Hash CERT [PAPUBKEYS]
APE: Writing Hash CERT [PASUBTOC]
APE: Writing Hash CERT [ADL]
APE: Writing Hash CERT [SOS+XZIP]
APE: Writing Hash CERT [SOS*CORE]
APE: Writing Hash CERT [SOS+ROFS]
APE: Writing Hash CERT [SOS+ROFX]
Total writen 1770 blocks
TIME : Write time : 00:04:37
PrReq : NOR, 00
PrReq : NAND, 010300000000000000000000000000
Partitioning....
Partitioning Ok...
TransmissionReq : 32 bit, Dual
TransmissionReq : Accepted, 32 bit, Dual
Erase : Processing N73_rofx_4.0839.42.2.1_PRD.V01
Init Erase Mode Ok
Found 1 areas to erase, erase group
Asic : APE , Sub : NAND
APE , NAND , Area : 0x03920000 - 0x04E1FFFF
Erasing, wait.....
APE : Group erase Ok
TIME : Erase time : 00:00:01
PrReq : NOR, 00
PrReq : NAND, 010300000000000000000000000000
TransmissionReq : 32 bit, Dual
TransmissionReq : Accepted, 32 bit, Dual
Write : Processing N73_rofx_4.0839.42.2.1_PRD.V01
Init Write Mode Ok
APE: Writing Hash CERT [SOS+ROFX]
Total writen 2052 blocks
TIME : Write time : 00:02:43
PrReq : NOR, 00
PrReq : NAND, 010300000000000000000000000000
TransmissionReq : 32 bit, Dual
TransmissionReq : Accepted, 32 bit, Dual
Erase : Processing N73_userarea_4.0839.42.2.1.U01
Init Erase Mode Ok
Found 1 areas to erase, erase group
Asic : APE , Sub : NAND
APE , NAND , Area : 0x04E20000 - 0x07C9FFFF
Erasing, wait.....
APE : Group erase Ok
TIME : Erase time : 00:00:01
PrReq : NOR, 00
PrReq : NAND, 010300000000000000000000000000
TransmissionReq : 32 bit, Dual
TransmissionReq : Accepted, 32 bit, Dual
Write : Processing N73_userarea_4.0839.42.2.1.U01
Init Write Mode Ok
Total writen 367 blocks
TIME : Write time : 00:01:02
PrReq : NOR, 00
PrReq : NAND, 010300000000000000000000000000
Switch jaf to FBUS...
FbusMode set Ok
Phone connected
Reading Phone Info....
Connected phone - Nokia N73
Software Info: V 05wk47v61.1
09-07-08
RM-133
(c) Nokia.
IMEI: 12345610654321?
Product code:
Checking...
SimLock status : SimLock is Ok
Security status : Security is Ok
Read Info Done!
Resetting LifeTimer
Reset Done!
AfterFlash operations done... Reconnect, wait...
Flashing done
Лог восстановления NPC, SDD,Simlock, SX4, Upload Tune:
Код:
Connect phone on selected interface...
Phone found!
Series 60 Device detected!
read info... - Ok
Will Write RPL keys now...
Check RPL file...
NPC Data found! (CMT)
CCC Data found! (APE)
Checking BUS...
Switch jaf to FlashMode...
FlashMode set Ok
Booting phone...
BOOT 1ST : C0
APE part info :
APE ASICID : 17100708
APE MODE ID : 00
APE PUB ID : 737A24E08BE12AC7442EE56F8F02D39F3A782F52
APE R_HASH : 49A97E826B93BA20B7ED0B082475C005
APE ROM ID : 1DFD66132C872FD4
CMT part info :
CMT ASICID : 000000010000022600010006010C192101003000
CMT EM0 ID : 00000295
CMT EM1 ID : 00000B22
CMT PUB ID : 1F200106FD5D025443452F4AE2339FC2BCAFA9C7
CMT MODE ID : 00
CMT R_HASH : BAF3A9C3DBFA8454937DB77F2B8852B1
CMT ROM ID : 273F6D55DFAAF68F
CMT : Sending 2nd loader...
Use : RAP3Gv3_2nd.fg , Rev : 0.0 Ver : 10.42.0
CMT Loader sent, Boot Ok
MCU configuration
CMT Flash ID : 22E800EC < SAMSUNG [SEC] => K5G2829ATC
FLASHID : 22E800EC , CMT , NOR
FLCNT : 00000000000000000000000000000000000000
CMT Flash ID : 0000FFFF < Bad Flash Type , if MMC - It Ok
FLASHID : 0000FFFF , CMT , MMC , EXT
TransmissionReq : 16 bit, Single
TransmissionReq : Accepted, 16 bit, Single
Sending ALGO....
Use : RAP3Gv3_algo.fg , Rev : 0.0 Ver : 10.40.0
CMT Algo sent!
TransmissionReq : 32 bit, Dual
TransmissionReq : Accepted, 32 bit, Dual
PAPUBKeys : 5E8D0D504A0902E261268C14FCD8A2C9093523BCBD
APE : Sending 2nd loader...
Use : helen3_2nd.fg , Rev : 0.0 Ver : 1.35.0
APE Loader sent, Boot Ok
MCU configuration
APE Flash ID : 00A100EC < SAMSUNG [SEC] => K5E1G12ACM [NAND]
FLASHID : 00A100EC , APE , NAND
FLCNT : 010100FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
Sending ALGO....
Use : h3_xsr15_flash_alg.fg , Rev : 0.0 Ver : 1.49.0
APE Algo sent!
TransmissionReq : 32 bit, Dual
TransmissionReq : Accepted, 32 bit, Dual
PAPUBKeys : 5E8D0D504A0902E261268C14FCD8A2C9093523BCBD
Boot done!
Preparing for write certificates...
Switching to CMT...
Erase NPC... Ok
Writing NPC... Ok
CMT cert write done!
Done!
Connect phone on selected interface...
Switch jaf to FBUS...
FbusMode set Ok
Phone found!
Series 60 Device detected!
read info... - Ok
Repair SD procedure started...
Phone Imei: 352916022020292
Key file exists, no need to read...
Operating mode is OK, no need change...
Writing Super Dongle Key... Ok
Done!
Local SX4 procedure started...
Phone Imei: 352916022020292
Key file exists, no need to read...
Step 1...
Step 2...
Step 3...
SX4 Auth - Ok
Upload PM checked
Uploading RF/Battery tune to phone...
Using : RM-133.pm
Operating mode is OK, no need change...
Field 1
Record 0 write - Ok
Record 2 write - Ok
Record 4 write - Ok
Record 6 write - Ok
Record 8 write - Ok
Record 13 write - Ok
Record 16 write - Ok
Record 18 write - Ok
Record 20 write - Ok
Record 22 write - Ok
Record 23 write - Ok
Record 24 write - Ok
Record 25 write - Ok
Record 26 write - Ok
Record 28 write - Ok
Record 29 write - Ok
Record 31 write - Ok
Record 33 write - Ok
Record 34 write - Ok
Record 44 write - Ok
Field 309
Record 0 write - Ok
Record 1 write - Ok
Record 2 write - Ok
Record 4 write - Ok
Record 5 write - Ok
Record 7 write - Ok
Record 8 write - Ok
Record 17 write - Ok
Record 22 write - Ok
Check ST_SECURITY now...
Security status : ST_SECURITY => DAMAGED :(
Done!
Elapsed: 00:01:04
Upload done
А вот самый интересный момент Restore CCC\HWR не срабатывает:
Код:
Checking StartUp data ...
-----------------------
SDD Key status : SD Data is Ok
SimLock status : SimLock is Ok
Will Write CCC/HWC keys now...
Using : RM-133.rpl
Variant Data found!
Checking BUS...
Switch jaf to FlashMode...
FlashMode set Ok
Booting phone...
BOOT 1ST : C0
APE part info :
APE ASICID : 17100708
APE MODE ID : 00
APE PUB ID : 737A24E08BE12AC7442EE56F8F02D39F3A782F52
APE R_HASH : 49A97E826B93BA20B7ED0B082475C005
APE ROM ID : 1DFD66132C872FD4
CMT part info :
CMT ASICID : 000000010000022600010006010C192101003000
CMT EM0 ID : 00000295
CMT EM1 ID : 00000B22
CMT PUB ID : 1F200106FD5D025443452F4AE2339FC2BCAFA9C7
CMT MODE ID : 00
CMT R_HASH : BAF3A9C3DBFA8454937DB77F2B8852B1
CMT ROM ID : 273F6D55DFAAF68F
CMT : Sending 2nd loader...
Use : RAP3Gv3_2nd.fg , Rev : 0.0 Ver : 10.42.0
CMT Loader sent, Boot Ok
MCU configuration
CMT Flash ID : 22E800EC < SAMSUNG [SEC] => K5G2829ATC
FLASHID : 22E800EC , CMT , NOR
FLCNT : 00000000000000000000000000000000000000
CMT Flash ID : 0000FFFF < Bad Flash Type , if MMC - It Ok
FLASHID : 0000FFFF , CMT , MMC , EXT
TransmissionReq : 16 bit, Single
TransmissionReq : Accepted, 16 bit, Single
Sending ALGO....
Use : RAP3Gv3_algo.fg , Rev : 0.0 Ver : 10.40.0
CMT Algo sent!
TransmissionReq : 32 bit, Dual
TransmissionReq : Accepted, 32 bit, Dual
PAPUBKeys : 5E8D0D504A0902E261268C14FCD8A2C9093523BCBD
APE : Sending 2nd loader...
Use : helen3_2nd.fg , Rev : 0.0 Ver : 1.35.0
APE Loader sent, Boot Ok
MCU configuration
APE Flash ID : 00A100EC < SAMSUNG [SEC] => K5E1G12ACM [NAND]
FLASHID : 00A100EC , APE , NAND
FLCNT : 010100FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
Sending ALGO....
Use : h3_xsr15_flash_alg.fg , Rev : 0.0 Ver : 1.49.0
APE Algo sent!
TransmissionReq : 32 bit, Dual
TransmissionReq : Accepted, 32 bit, Dual
PAPUBKeys : 5E8D0D504A0902E261268C14FCD8A2C9093523BCBD
Boot done!
Preparing for write certificates...
CMT : Read NPC certificate...
Repair Data Check Error :(
CMT cert write done!
Done!
Не могу понять ТА не восстановлен по HW до конца, или новая фишка в 1.24.2 не работает?
Пробовал сделать Recovery CERT с помощью MX-Key в связке с UFS, не получилось. При буте выдаёт ошибку, HTI интерфейса у меня нет:
Код:
Using device: UFS_USB V2.8 (c) SarasSoft 2007.
Driver: usbohci:usbhub:usbhub:UFS2XX, ver: 3.6.0.0 , NTMP ver: 2.6.0.0
Module ver: 1.0.0.17841(12-07-2011), Library ver: 1.0.0.11875(12-07-2011)
APE Data :
SYSTEM ASIC ID: 17100708 [OMAP1710 ver: 2.0]
ASIC MODE ID: 00
PUBLIC ID: 737A24E08BE12AC7442EE56F8F02D39F3A782F52
ROOT KEY HASH: 49A97E826B93BA20B7ED0B082475C00500000000
ROM ID: 1DFD66132C872FD4
CMT Data :
SYSTEM ASIC ID: 000000010000022600010006010C192101003000 [RAP3G ver: PA 3.0]
EM0 ID: 00000295
EM1 ID: 00000B22
PUBLIC ID: 1F200106FD5D025443452F4AE2339FC2BCAFA9C7
ASIC MODE ID: 00
ROOT KEY HASH: BAF3A9C3DBFA8454937DB77F2B8852B1
ROM ID: 273F6D55DFAAF68F
SecondaryBoot: rap3gv3_2nd.fg [BB5] version: 9.11.1 revision: 0.0 size: 0x3C00
Supported Ids: 0103192101003000, 010C192101003000, 0103192101013000, 010C192101013000, 0103192101003100, 010C192101003100, 0303192101023000, 030C192101023000, 0303192101033000, 030C192101033000, 0103192101001101, 010C192101001101, 0003192101001002, 000C192101001002, 0013192101001002, 001C192101001002
Storage0: 00EC 22E8 - 0000 6921 [Samsung K8S2815ETB,128 Mbits] type: FLASH,NOR, asic:CMT
Storage content: 0000 0000 0000 0000 0000 0000 0000 0000
Storage1: FFFF 0000 - 0000 0000 type: MMC, asic:CMT
TransmissionMode: 16Bit
Algorithm: RAP3Gv3_algo.fg [BB5 ALGORITHM] version: 9.50.0 revision: 0.0 size: 0x23010
Supported Ids: 0103192101003000, 010C192101003000, 0103192101013000, 010C192101013000, 0103192101003100, 010C192101003100, 0303192101023000, 030C192101023000, 0303192101033000, 030C192101033000, 0003192101002000, 000C192101002000, 0003192101002100, 000C192101002100, 0003192101002200, 000C192101002200, 0003192101012200, 000C192101012200, 0103192101001101, 010C192101001101, 0003192101001002, 000C192101001002, 0013192101001002, 001C192101001002
CMT PAPUBKEYS HASH: 5E8D0D504A0902E261268C14FCD8A2C9093523BC
TransmissionMode: DDR&TX2
SecondaryBoot: helen3_2nd.fg [BB5] version: 1.35.0 revision: 0.0 size: 0x3500
Supported Ids: 17100700, 17100701, 17100702, 17100703, 17100704, 17100708
loader not responding (0910000000B172)
P.S. нашёл в мастерской ещё одну N73, всё рабочее, кроме камеры:
Код:
Phone found!
Series 60 Device detected!
read info... - Ok
Read and Check phone data...
Checking BUS...
Switch jaf to FlashMode...
FlashMode set Ok
Booting phone...
BOOT 1ST : C0
APE part info :
APE ASICID : 17100708
APE MODE ID : 00
APE PUB ID : DD7F4FC6A6314137C43E0C452511F20FEB356ADA
APE R_HASH : 49A97E826B93BA20B7ED0B082475C005
APE ROM ID : 1DFD66132C872FD4
CMT part info :
CMT ASICID : 000000010000022600010006010C192101003000
CMT EM0 ID : 00000295
CMT EM1 ID : 00000B22
CMT PUB ID : 2060010C5375025476EDE34D3D9D947CC2292ACC
CMT MODE ID : 00
CMT R_HASH : BAF3A9C3DBFA8454937DB77F2B8852B1
CMT ROM ID : 273F6D55DFAAF68F
CMT : Sending 2nd loader...
Use : RAP3Gv3_2nd.fg , Rev : 0.0 Ver : 10.42.0
CMT Loader sent, Boot Ok
MCU configuration
CMT Flash ID : 22E800EC < SAMSUNG [SEC] => K5G2829ATC
FLASHID : 22E800EC , CMT , NOR
FLCNT : 00000000000000000000000000000000000000
CMT Flash ID : 0000FFFF < Bad Flash Type , if MMC - It Ok
FLASHID : 0000FFFF , CMT , MMC , EXT
TransmissionReq : 16 bit, Single
TransmissionReq : Accepted, 16 bit, Single
Sending ALGO....
Use : RAP3Gv3_algo.fg , Rev : 0.0 Ver : 10.40.0
CMT Algo sent!
TransmissionReq : 32 bit, Dual
TransmissionReq : Accepted, 32 bit, Dual
PAPUBKeys : 5E8D0D504A0902E261268C14FCD8A2C9093523BCBD
APE : Sending 2nd loader...
Use : helen3_2nd.fg , Rev : 0.0 Ver : 1.35.0
APE Loader sent, Boot Ok
MCU configuration
APE Flash ID : 00A100EC < SAMSUNG [SEC] => K5E1G12ACM [NAND]
FLASHID : 00A100EC , APE , NAND
FLCNT : 010100FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
Sending ALGO....
Use : h3_xsr15_flash_alg.fg , Rev : 0.0 Ver : 1.49.0
APE Algo sent!
TransmissionReq : 32 bit, Dual
TransmissionReq : Accepted, 32 bit, Dual
PAPUBKeys : 5E8D0D504A0902E261268C14FCD8A2C9093523BCBD
Boot done!
Switch jaf to FBUS...
FbusMode set Ok
SimLock status : SimLock is Ok
Security status : Security is Ok
SDD Key status : SD Data is Ok
PA_SimLock Version :
PA_SL phone detected
Done!
Connect phone on selected interface...
Connect phone on selected interface...
Phone found!
Series 60 Device detected!
read info... - Ok
Reading Phone Info....
Connected phone - Nokia N73
Software ver : V 05wk47v61.1 09-07-08 RM-133 (c) Nokia.
IMEI : 352916026955634
Ape Ver :
APE Var :
APE ADSP:
DSP Ver : scarfe_mc.05wk46v50p2
APE Test:
PPM :
CNT :
Product SN : MYH507911
Product code : 0539284
Base Prd.code: 0537044
Module code : 0202855
Long Prod.SN :
Hardware info=======
HWID : 7600
Retu : 15
Tahvo : 22
Batery: 4621 mV
Camera:
CMT BT:
APE BT:
APE HW:
LCDVer:
RF ic : 17211721
Lock info ===========
IMEI : 352916026955634
IMEI spNet :
IMEI svNet :
Conf key : 0000000000000000
Provider key : 2440700000000000
Provider : AT&T;U.S.A. (3650)
Counters : Key 0 [3] , Fbus 0 [10]
Blocks : 7
LOCK STATUS :
=============================
BLK : 1
Lock1:Open Lock2:Open Lock3:Open Lock4:Open Lock5:Open
BLK : 2
Lock1:Open Lock2:Open Lock3:Open Lock4:Open Lock5:Open
BLK : 3
Lock1:Open Lock2:Open Lock3:Open Lock4:Open Lock5:Open
BLK : 4
Lock1:Open Lock2:Open Lock3:Open Lock4:Open Lock5:Open
BLK : 5
Lock1:Open Lock2:Open Lock3:Open Lock4:Open Lock5:Open
BLK : 6
Lock1:Open Lock2:Open Lock3:Open Lock4:Open Lock5:Open
BLK : 7
Lock1:Open Lock2:Open Lock3:Open Lock4:Open Lock5:Open
=============================
LOCKS : All Open
=============================
User Code : 00000
UserDataExLevel : Full [PhoneBook, Calendar, PWD, SMS, Gallery]
Done!
Попробовал на ней повторить процедуру восстановления CCC/HWC, тоже не сработало:
Код:
Will Write CCC/HWC keys now...
Using : RM-133.rpl
Variant Data found!
Checking BUS...
Switch jaf to FlashMode...
FlashMode set Ok
Booting phone...
BOOT 1ST : C0
APE part info :
APE ASICID : 17100708
APE MODE ID : 00
APE PUB ID : DD7F4FC6A6314137C43E0C452511F20FEB356ADA
APE R_HASH : 49A97E826B93BA20B7ED0B082475C005
APE ROM ID : 1DFD66132C872FD4
CMT part info :
CMT ASICID : 000000010000022600010006010C192101003000
CMT EM0 ID : 00000295
CMT EM1 ID : 00000B22
CMT PUB ID : 2060010C5375025476EDE34D3D9D947CC2292ACC
CMT MODE ID : 00
CMT R_HASH : BAF3A9C3DBFA8454937DB77F2B8852B1
CMT ROM ID : 273F6D55DFAAF68F
CMT : Sending 2nd loader...
Use : RAP3Gv3_2nd.fg , Rev : 0.0 Ver : 10.42.0
CMT Loader sent, Boot Ok
MCU configuration
CMT Flash ID : 22E800EC < SAMSUNG [SEC] => K5G2829ATC
FLASHID : 22E800EC , CMT , NOR
FLCNT : 00000000000000000000000000000000000000
CMT Flash ID : 0000FFFF < Bad Flash Type , if MMC - It Ok
FLASHID : 0000FFFF , CMT , MMC , EXT
TransmissionReq : 16 bit, Single
TransmissionReq : Accepted, 16 bit, Single
Sending ALGO....
Use : RAP3Gv3_algo.fg , Rev : 0.0 Ver : 10.40.0
CMT Algo sent!
TransmissionReq : 32 bit, Dual
TransmissionReq : Accepted, 32 bit, Dual
PAPUBKeys : 5E8D0D504A0902E261268C14FCD8A2C9093523BCBD
APE : Sending 2nd loader...
Use : helen3_2nd.fg , Rev : 0.0 Ver : 1.35.0
APE Loader sent, Boot Ok
MCU configuration
APE Flash ID : 00A100EC < SAMSUNG [SEC] => K5E1G12ACM [NAND]
FLASHID : 00A100EC , APE , NAND
FLCNT : 010100FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
Sending ALGO....
Use : h3_xsr15_flash_alg.fg , Rev : 0.0 Ver : 1.49.0
APE Algo sent!
TransmissionReq : 32 bit, Dual
TransmissionReq : Accepted, 32 bit, Dual
PAPUBKeys : 5E8D0D504A0902E261268C14FCD8A2C9093523BCBD
Boot done!
Preparing for write certificates...
CMT : Read NPC certificate...
Repair Data Check Error :(
CMT cert write done!
Done!
Switch jaf to FBUS...
FbusMode set Ok
Elapsed: 00:01:17
Connect phone on selected interface...
Phone found!
Series 60 Device detected!
read info... - Ok
На MX_key 3.5 rev 1.2 через UFS на этой N-73 выдаёт такую же ошибку при буте. Видимо всё сделано специально, чтобы покупали HTI.