dmitrik
11.02.2012, 18:03
Всем добрый вечер.
Принесли Nokia X7 RM-659 убитый после попытки прошивки в него прошивки от RM-707, несколько дней уже пытаемся его поднять...
Сделал полное стирание, залил в него родную прошивку, заказал и залил в него RPL.
Теперь выдает SECURITY_TEST : FAILED, побывал прошить 1 и 309 поле c SX4 авторизацией эффекта ноль.
PM брал с такого же телефона.
Все работы проводились с помощью ATF.
Можете поделится PM RM-659 или подсказать что делаем неправильно?
RPL
AdvanceBox SendBootCodeEx
InitialiseBootstrap_DCT5 DIR
BootFlashMode_DCT5
************************************************** ****
TIME STARTS HERE
************************************************** ****
BootFlashModeDCT5Ex Succeeded First Time
SYSTEM_ID_RESPONSE_BB5 (0xC0) - 0 (0x00) bytes returned
Number of Sub Blocks 7 (0x07)
1 SYSTEM_ASIC_ID 01
Block Length : 21 (15)
BB ASIC Index : 0 (00) CMT
ID DWORD 0 : 00000003
ID DWORD 1 : 00000226
ID DWORD 2 : 00010007
ID DWORD 3 : 600C1921
ID DWORD 4 : 02031104
2 ROM_ID 15
Block Length : 5 (05)
BB ASIC Index : 0 (00) CMT
ID DWORD 0 : 00001040
3 ROM_ID 15
Block Length : 5 (05)
BB ASIC Index : 0 (00) CMT
ID DWORD 0 : 00001030
4 PUBLIC_ID 12
Block Length : 21 (15)
BB ASIC Index : 0 (00) CMT
ID DWORD 0 : 15500201
ID DWORD 1 : B9A60344
ID DWORD 2 : 80F44BFE
ID DWORD 3 : D0F01663
ID DWORD 4 : 90A44FAD
5 ASIC_MODE_ID 13
Block Length : 2 (02)
BB ASIC Index : 0 (00) CMT
Mode Id : 00
6 ROOT_KEY_HASH 14
Block Length : 17 (11)
BB ASIC Index : 0 (00) CMT
Hash : 91 6F 75 21 7F 32 08 12 48 B1 5C 38 DF C8 E8 1B
7 ROM_ID 15
Block Length : 9 (09)
BB ASIC Index : 0 (00) CMT
CRC 0 : E693EF0D
CRC 1 : AC22615B
Checksum 07
SearchForBootstrap_DCT5..
C:\AdvanceBox Turbo Flasher\Nokia\BB5_Loader\New\RAPUv11_2nd.fg
Boot File - Version 011.034.00
Boot File - Revision 0x0003 (3)
eBB5ProtocolType == New
PrepareBootstrapFile_DCT5 replaced "SILO" with "2ND\0"
PrepareBootstrapFile_DCT5 replaced "BOOT_MEDIAX" with "BOOT_MEDIA0"
SearchForBootstrap_DCT5 : No Error - 0 (0x00)
Secondary Loader Sent...
TransmissionTypeRequest_DCT5_NewProtocol
TRANSMISSION_TYPE_REQUEST_BB5 GET_PROTOCOLS_BB5
TRANSMISSION_TYPE_REQUEST_BB5 : 59 01 3E 00 C0
TransmissionTypeRequest_DCT5_NewProtocol
FPIF_TRANSMISSION_MODE_LIST_BB5 using default mode 04 DDRand2TX
TRANSMISSION_TYPE_REQUEST_BB5 : 59 02 41 02 04 00 36 03 00 00 61 1C
Transmission Type Request Sent...
ConfigurationRequest_DCT5 (RAM_SIZE_BB5 0x0000)..
MCU_CONFIGURATION_RESPONSE_BB5:
MessageID : 06
SubBlocks : 06
1 Sub Block ID : 10 STORAGE_DEVICE_ID_BB5
Block Length : 0B
BB ASIC Index : CMT 00
Device Type : RAM 05
Device Index : 00
Manufacturer Code : 0000 -> Flash
Device ID : 0000 -> not detected
Extended/Fixed ID : 0000
Revision ID : 0000
2 Sub Block ID : 10 STORAGE_DEVICE_ID_BB5
Block Length : 0B
BB ASIC Index : CMT 00
Device Type : MMC 04
Device Index : 00
Manufacturer Code : FFFF -> Flash
Device ID : 0000 -> BAD FLASH TYPE
Extended/Fixed ID : 0000
Revision ID : 0000
3 Sub Block ID : 10 STORAGE_DEVICE_ID_BB5
Block Length : 0B
BB ASIC Index : CMT 00
Device Type : NOR 00
Device Index : 00
Manufacturer Code : 0000 -> Flash
Device ID : 0000 -> not detected
Extended/Fixed ID : 0000
Revision ID : 0000
4 Sub Block ID : 10 STORAGE_DEVICE_ID_BB5
Block Length : 0B
BB ASIC Index : CMT 00
Device Type : NOR 00
Device Index : 01
Manufacturer Code : 0000 -> SPANSION
Device ID : 0001 -> not used
Extended/Fixed ID : 0000
Revision ID : 0000
5 Sub Block ID : 10 STORAGE_DEVICE_ID_BB5
Block Length : 0B
BB ASIC Index : CMT 00
Device Type : MuxOneNAND 03
Device Index : 00
Manufacturer Code : 00EC ->
Device ID : 0068 -> Type not in database
Extended/Fixed ID : 0000
Revision ID : 0131
6 Sub Block ID : 35 NAND_DRIVER_VERSION_BB5
Block Length : 09
BB ASIC Index : CMT 00
Data : XSR 1.6
Checksum : F0
SearchForBootstrap_DCT5 : No Error - 0 (0x00)
FLS1SendAlgoCodeEx..
SendAlgoCode_DCT5..
SearchForAlgorithm_DCT5..
Looking for ALL Devices...
Searching Algorithm Files MuxOneNAND (03) ManID :00EC DevID :0068 ExtID :0000 RevID :0131
Flash Descriptor
Manufacturer Code : 00EC
Device ID : 0068
Extended/Fixed ID : 0000
Revision ID : 0000
Size : 40000000 (1024 MB)
VPP Info : 0000
Erase10s : 1E
Block1s : 32
BErase1s : 02
Reserved0 : 00
Reserved1 : 00
Reserved2 : 00
C:\AdvanceBox Turbo Flasher\Nokia\BB5_Loader\New\RAPUv11_XSR17_alg.fg
Algorithm File - Version 011.034.00
Algorithm File - Revision 0x0003 (3)
eBB5ProtocolType == New
Algo Loader Sent...
SendCodeStart_NewProtocol :
SendCodeStart_NewProtocol_DCT5 : No Error - 0 (0x00)
TransmissionTypeRequest_DCT5_NewProtocol
TRANSMISSION_TYPE_REQUEST_BB5 GET_PROTOCOLS_BB5
TRANSMISSION_TYPE_REQUEST_BB5 : 59 01 3E 00 C0
TransmissionTypeRequest_DCT5_NewProtocol
FPIF_TRANSMISSION_MODE_LIST_BB5 using default mode 04 DDRand2TX
TRANSMISSION_TYPE_REQUEST_BB5 : 59 02 41 02 04 00 36 03 00 00 61 1C
SendAlgoCodeFile_DCT5 : No Error - 0 (0x00)
FUR_Control_AddClient_BB5() ASIC_INDEX_CMT (Ready)
FUR control Ok...
VPP Enabled by Software
Using Internal VPP
VPP Enabled by Software
FLASH_VOLTAGE_INIT_BB5 : 5C 01 26 04 00 00 00 00 D4
Pabub KEY Request
PhoneInfoRequest_BB5 (Asic Index 00 )
PHONE_INFO_RESPONSE_BB5
PAPUB_KEYS_HASH_RESP_BB5 2A
BB Asic Index : 00
CMT PAPUBKEYS HASH:
9A17C4A57D80D29519AAEF45209AD2F5CF4AD9E9
VPP Enabled by Software
Using Internal VPP
VPP Enabled by Software
FLASH_VOLTAGE_INIT_BB5 : 5C 01 26 04 00 00 00 00 D4
StartErase_DCT5...
BlockLength : 0x10 (16)
ERASE Blocks : 0x01 (1)
0 ERASE_AREA_BB5 0x13
Block Length : 0x0D (13)
BB ASIC Index : 0x00 CMT
Erase_SendEraseBlock_BB5_NAND
Task in Progress... Please Wait...
Successfully erased..
Now Writing : CMT NPC Certificate 0x0200 Bytes
NPC Write Successful...
StartErase_DCT5...
BlockLength : 0x10 (16)
ERASE Blocks : 0x01 (1)
0 ERASE_AREA_BB5 0x13
Block Length : 0x0D (13)
BB ASIC Index : 0x00 CMT
Erase_SendEraseBlock_BB5_NAND
Task in Progress... Please Wait...
Successfully erased..
Now Writing : CMT CCC Certificate 0x0200 Bytes
CCC Write Successful...
StartErase_DCT5...
BlockLength : 0x10 (16)
ERASE Blocks : 0x01 (1)
0 ERASE_AREA_BB5 0x13
Block Length : 0x0D (13)
BB ASIC Index : 0x00 CMT
Erase_SendEraseBlock_BB5_NAND
Task in Progress... Please Wait...
Successfully erased..
Now Writing : CMT HWC Certificate 0x0200 Bytes
HWC Write Successful...
Write Certificates OK!
FlashInfo.RestartMode : 2
Waiting for Phone to Go Online...
Elapsed Time: 1s
Elapsed Time: 2s
Elapsed Time: 3s
Elapsed Time: 4s
Elapsed Time: 5s
Elapsed Time: 6s
Elapsed Time: 7s
Elapsed Time: 8s
Elapsed Time: 9s
Elapsed Time: 10s
================================================
Basic Phone Information
================================================
MCU Version: V 92_11w21 25-05-11 RM-659 (c) Nokia
IMEI Plain : 35789904013****
IMEI Spare : A357899040134420
IMEI SV : 33578990401344212F
Phone Model: Nokia X7-00
Category : Classic Phone
Phone Type : RM-659
Writing: SIMLOCK_DATA + SIMLOCK_KEY_DATA
SUCCESSFUL !!!
Writing: SUPERDONGLE_KEY_DATA
SUCCESSFUL !!!
Writing: CMLA_KEY_DATA
SUCCESSFUL !!!
Writing: WMDRM_PD_DATA
SUCCESSFUL !!!
RPL Upload Finished!!!
================================================
Basic Phone Information
================================================
MCU Version: V 92_11w21 25-05-11 RM-659 (c) Nokia
IMEI Plain : 35789904013****
IMEI Spare : A357899040134420
IMEI SV : 33578990401344212F
Phone Model: Nokia X7-00
Category : Classic Phone
Phone Type : RM-659
================================================
Extended Phone Information
================================================
Product Serial Number: CZF566108
Module Code : 0205042
Basic Production Code: 059J4N4
Long Production SN : 0
MCU SW Version : V 92_11w21 25-05-11 RM-659 (c) Nokia
HW Version : 1000
RFIC Version : |Alli_4.3.4
DSP Version : 92_11w21
Unknown16 : ?
Content : 022.008.241.01
APE BT Version : HCI Version 20 (rev. 64). LMP Version 44 (rev. 64). Manufacturer 2000.
AHNE Version : 11
APE SW Core Version : 022.008
Variant Version : 022.008022.008.31.01022.008.241.01
RETU Version : 40
TAHVO Version : 00
APE HW Version : 256
APE ADSP SW Version : 256
Wireless LAN ID : D8:2A:7E:4E:80:04
Bluetooth ID : D8:2A:7E:4E:31:E4
CS Type : GSM850, GSM900, GSM1800, GSM1900, WCDMA I, WCDMA II, WCDMA V
================================================
Simlock Information
================================================
CONFIG KEY : 8000000000000000
PROVIDER KEY : 3027200000000000
NETWORK NAME : Rorges Communications;Canada [GSM]
LOCK COUNTERS : KEYPRESS 0/3, FBUS 0/10
SIMLOCK TABLE :
Block [1] 1:Close
SIMLOCK STATE : LOCKED
SIMLOCK_TYPE : PA_SL3 (15-digit NCK)
SIMLOCK_TEST : PASSED
SECURITY_TEST : FAILED
> Try SX4 "PM AUTH"
> Then Write PM 1 and 309
SECURITY_CODE : ENCRYPTED
PHONE_MODE : LOCAL
DCC ID : NOT USED
Принесли Nokia X7 RM-659 убитый после попытки прошивки в него прошивки от RM-707, несколько дней уже пытаемся его поднять...
Сделал полное стирание, залил в него родную прошивку, заказал и залил в него RPL.
Теперь выдает SECURITY_TEST : FAILED, побывал прошить 1 и 309 поле c SX4 авторизацией эффекта ноль.
PM брал с такого же телефона.
Все работы проводились с помощью ATF.
Можете поделится PM RM-659 или подсказать что делаем неправильно?
RPL
AdvanceBox SendBootCodeEx
InitialiseBootstrap_DCT5 DIR
BootFlashMode_DCT5
************************************************** ****
TIME STARTS HERE
************************************************** ****
BootFlashModeDCT5Ex Succeeded First Time
SYSTEM_ID_RESPONSE_BB5 (0xC0) - 0 (0x00) bytes returned
Number of Sub Blocks 7 (0x07)
1 SYSTEM_ASIC_ID 01
Block Length : 21 (15)
BB ASIC Index : 0 (00) CMT
ID DWORD 0 : 00000003
ID DWORD 1 : 00000226
ID DWORD 2 : 00010007
ID DWORD 3 : 600C1921
ID DWORD 4 : 02031104
2 ROM_ID 15
Block Length : 5 (05)
BB ASIC Index : 0 (00) CMT
ID DWORD 0 : 00001040
3 ROM_ID 15
Block Length : 5 (05)
BB ASIC Index : 0 (00) CMT
ID DWORD 0 : 00001030
4 PUBLIC_ID 12
Block Length : 21 (15)
BB ASIC Index : 0 (00) CMT
ID DWORD 0 : 15500201
ID DWORD 1 : B9A60344
ID DWORD 2 : 80F44BFE
ID DWORD 3 : D0F01663
ID DWORD 4 : 90A44FAD
5 ASIC_MODE_ID 13
Block Length : 2 (02)
BB ASIC Index : 0 (00) CMT
Mode Id : 00
6 ROOT_KEY_HASH 14
Block Length : 17 (11)
BB ASIC Index : 0 (00) CMT
Hash : 91 6F 75 21 7F 32 08 12 48 B1 5C 38 DF C8 E8 1B
7 ROM_ID 15
Block Length : 9 (09)
BB ASIC Index : 0 (00) CMT
CRC 0 : E693EF0D
CRC 1 : AC22615B
Checksum 07
SearchForBootstrap_DCT5..
C:\AdvanceBox Turbo Flasher\Nokia\BB5_Loader\New\RAPUv11_2nd.fg
Boot File - Version 011.034.00
Boot File - Revision 0x0003 (3)
eBB5ProtocolType == New
PrepareBootstrapFile_DCT5 replaced "SILO" with "2ND\0"
PrepareBootstrapFile_DCT5 replaced "BOOT_MEDIAX" with "BOOT_MEDIA0"
SearchForBootstrap_DCT5 : No Error - 0 (0x00)
Secondary Loader Sent...
TransmissionTypeRequest_DCT5_NewProtocol
TRANSMISSION_TYPE_REQUEST_BB5 GET_PROTOCOLS_BB5
TRANSMISSION_TYPE_REQUEST_BB5 : 59 01 3E 00 C0
TransmissionTypeRequest_DCT5_NewProtocol
FPIF_TRANSMISSION_MODE_LIST_BB5 using default mode 04 DDRand2TX
TRANSMISSION_TYPE_REQUEST_BB5 : 59 02 41 02 04 00 36 03 00 00 61 1C
Transmission Type Request Sent...
ConfigurationRequest_DCT5 (RAM_SIZE_BB5 0x0000)..
MCU_CONFIGURATION_RESPONSE_BB5:
MessageID : 06
SubBlocks : 06
1 Sub Block ID : 10 STORAGE_DEVICE_ID_BB5
Block Length : 0B
BB ASIC Index : CMT 00
Device Type : RAM 05
Device Index : 00
Manufacturer Code : 0000 -> Flash
Device ID : 0000 -> not detected
Extended/Fixed ID : 0000
Revision ID : 0000
2 Sub Block ID : 10 STORAGE_DEVICE_ID_BB5
Block Length : 0B
BB ASIC Index : CMT 00
Device Type : MMC 04
Device Index : 00
Manufacturer Code : FFFF -> Flash
Device ID : 0000 -> BAD FLASH TYPE
Extended/Fixed ID : 0000
Revision ID : 0000
3 Sub Block ID : 10 STORAGE_DEVICE_ID_BB5
Block Length : 0B
BB ASIC Index : CMT 00
Device Type : NOR 00
Device Index : 00
Manufacturer Code : 0000 -> Flash
Device ID : 0000 -> not detected
Extended/Fixed ID : 0000
Revision ID : 0000
4 Sub Block ID : 10 STORAGE_DEVICE_ID_BB5
Block Length : 0B
BB ASIC Index : CMT 00
Device Type : NOR 00
Device Index : 01
Manufacturer Code : 0000 -> SPANSION
Device ID : 0001 -> not used
Extended/Fixed ID : 0000
Revision ID : 0000
5 Sub Block ID : 10 STORAGE_DEVICE_ID_BB5
Block Length : 0B
BB ASIC Index : CMT 00
Device Type : MuxOneNAND 03
Device Index : 00
Manufacturer Code : 00EC ->
Device ID : 0068 -> Type not in database
Extended/Fixed ID : 0000
Revision ID : 0131
6 Sub Block ID : 35 NAND_DRIVER_VERSION_BB5
Block Length : 09
BB ASIC Index : CMT 00
Data : XSR 1.6
Checksum : F0
SearchForBootstrap_DCT5 : No Error - 0 (0x00)
FLS1SendAlgoCodeEx..
SendAlgoCode_DCT5..
SearchForAlgorithm_DCT5..
Looking for ALL Devices...
Searching Algorithm Files MuxOneNAND (03) ManID :00EC DevID :0068 ExtID :0000 RevID :0131
Flash Descriptor
Manufacturer Code : 00EC
Device ID : 0068
Extended/Fixed ID : 0000
Revision ID : 0000
Size : 40000000 (1024 MB)
VPP Info : 0000
Erase10s : 1E
Block1s : 32
BErase1s : 02
Reserved0 : 00
Reserved1 : 00
Reserved2 : 00
C:\AdvanceBox Turbo Flasher\Nokia\BB5_Loader\New\RAPUv11_XSR17_alg.fg
Algorithm File - Version 011.034.00
Algorithm File - Revision 0x0003 (3)
eBB5ProtocolType == New
Algo Loader Sent...
SendCodeStart_NewProtocol :
SendCodeStart_NewProtocol_DCT5 : No Error - 0 (0x00)
TransmissionTypeRequest_DCT5_NewProtocol
TRANSMISSION_TYPE_REQUEST_BB5 GET_PROTOCOLS_BB5
TRANSMISSION_TYPE_REQUEST_BB5 : 59 01 3E 00 C0
TransmissionTypeRequest_DCT5_NewProtocol
FPIF_TRANSMISSION_MODE_LIST_BB5 using default mode 04 DDRand2TX
TRANSMISSION_TYPE_REQUEST_BB5 : 59 02 41 02 04 00 36 03 00 00 61 1C
SendAlgoCodeFile_DCT5 : No Error - 0 (0x00)
FUR_Control_AddClient_BB5() ASIC_INDEX_CMT (Ready)
FUR control Ok...
VPP Enabled by Software
Using Internal VPP
VPP Enabled by Software
FLASH_VOLTAGE_INIT_BB5 : 5C 01 26 04 00 00 00 00 D4
Pabub KEY Request
PhoneInfoRequest_BB5 (Asic Index 00 )
PHONE_INFO_RESPONSE_BB5
PAPUB_KEYS_HASH_RESP_BB5 2A
BB Asic Index : 00
CMT PAPUBKEYS HASH:
9A17C4A57D80D29519AAEF45209AD2F5CF4AD9E9
VPP Enabled by Software
Using Internal VPP
VPP Enabled by Software
FLASH_VOLTAGE_INIT_BB5 : 5C 01 26 04 00 00 00 00 D4
StartErase_DCT5...
BlockLength : 0x10 (16)
ERASE Blocks : 0x01 (1)
0 ERASE_AREA_BB5 0x13
Block Length : 0x0D (13)
BB ASIC Index : 0x00 CMT
Erase_SendEraseBlock_BB5_NAND
Task in Progress... Please Wait...
Successfully erased..
Now Writing : CMT NPC Certificate 0x0200 Bytes
NPC Write Successful...
StartErase_DCT5...
BlockLength : 0x10 (16)
ERASE Blocks : 0x01 (1)
0 ERASE_AREA_BB5 0x13
Block Length : 0x0D (13)
BB ASIC Index : 0x00 CMT
Erase_SendEraseBlock_BB5_NAND
Task in Progress... Please Wait...
Successfully erased..
Now Writing : CMT CCC Certificate 0x0200 Bytes
CCC Write Successful...
StartErase_DCT5...
BlockLength : 0x10 (16)
ERASE Blocks : 0x01 (1)
0 ERASE_AREA_BB5 0x13
Block Length : 0x0D (13)
BB ASIC Index : 0x00 CMT
Erase_SendEraseBlock_BB5_NAND
Task in Progress... Please Wait...
Successfully erased..
Now Writing : CMT HWC Certificate 0x0200 Bytes
HWC Write Successful...
Write Certificates OK!
FlashInfo.RestartMode : 2
Waiting for Phone to Go Online...
Elapsed Time: 1s
Elapsed Time: 2s
Elapsed Time: 3s
Elapsed Time: 4s
Elapsed Time: 5s
Elapsed Time: 6s
Elapsed Time: 7s
Elapsed Time: 8s
Elapsed Time: 9s
Elapsed Time: 10s
================================================
Basic Phone Information
================================================
MCU Version: V 92_11w21 25-05-11 RM-659 (c) Nokia
IMEI Plain : 35789904013****
IMEI Spare : A357899040134420
IMEI SV : 33578990401344212F
Phone Model: Nokia X7-00
Category : Classic Phone
Phone Type : RM-659
Writing: SIMLOCK_DATA + SIMLOCK_KEY_DATA
SUCCESSFUL !!!
Writing: SUPERDONGLE_KEY_DATA
SUCCESSFUL !!!
Writing: CMLA_KEY_DATA
SUCCESSFUL !!!
Writing: WMDRM_PD_DATA
SUCCESSFUL !!!
RPL Upload Finished!!!
================================================
Basic Phone Information
================================================
MCU Version: V 92_11w21 25-05-11 RM-659 (c) Nokia
IMEI Plain : 35789904013****
IMEI Spare : A357899040134420
IMEI SV : 33578990401344212F
Phone Model: Nokia X7-00
Category : Classic Phone
Phone Type : RM-659
================================================
Extended Phone Information
================================================
Product Serial Number: CZF566108
Module Code : 0205042
Basic Production Code: 059J4N4
Long Production SN : 0
MCU SW Version : V 92_11w21 25-05-11 RM-659 (c) Nokia
HW Version : 1000
RFIC Version : |Alli_4.3.4
DSP Version : 92_11w21
Unknown16 : ?
Content : 022.008.241.01
APE BT Version : HCI Version 20 (rev. 64). LMP Version 44 (rev. 64). Manufacturer 2000.
AHNE Version : 11
APE SW Core Version : 022.008
Variant Version : 022.008022.008.31.01022.008.241.01
RETU Version : 40
TAHVO Version : 00
APE HW Version : 256
APE ADSP SW Version : 256
Wireless LAN ID : D8:2A:7E:4E:80:04
Bluetooth ID : D8:2A:7E:4E:31:E4
CS Type : GSM850, GSM900, GSM1800, GSM1900, WCDMA I, WCDMA II, WCDMA V
================================================
Simlock Information
================================================
CONFIG KEY : 8000000000000000
PROVIDER KEY : 3027200000000000
NETWORK NAME : Rorges Communications;Canada [GSM]
LOCK COUNTERS : KEYPRESS 0/3, FBUS 0/10
SIMLOCK TABLE :
Block [1] 1:Close
SIMLOCK STATE : LOCKED
SIMLOCK_TYPE : PA_SL3 (15-digit NCK)
SIMLOCK_TEST : PASSED
SECURITY_TEST : FAILED
> Try SX4 "PM AUTH"
> Then Write PM 1 and 309
SECURITY_CODE : ENCRYPTED
PHONE_MODE : LOCAL
DCC ID : NOT USED