bkerler / mtkclient

MTK reverse engineering and flash tool
GNU General Public License v3.0
2.7k stars 528 forks source link

mt8163 gpu based unlock fails - Lenovo Tab 4 7 #183

Closed SahilSonar closed 5 months ago

SahilSonar commented 2 years ago

....Port - Device detected :) Preloader - CPU: MT6737M() Preloader - HW version: 0x0 Preloader - WDT: 0x10212000 Preloader - Uart: 0x11002000 Preloader - Brom payload addr: 0x100a00 Preloader - DA payload addr: 0x201000 Preloader - CQ_DMA addr: 0x10217c00 Preloader - Var1: 0x28 Preloader - Disabling Watchdog... Preloader - HW code: 0x335 Preloader - Target config: 0x5 Preloader - SBC enabled: True Preloader - SLA enabled: False Preloader - DAA enabled: True Preloader - SWJTAG enabled: True Preloader - EPP_PARAM at 0x600 after EMMC_BOOT/SDMMC_BOOT: False Preloader - Root cert required: False Preloader - Mem read auth: False Preloader - Mem write auth: False Preloader - Cmd 0xC8 blocked: False Preloader - Get Target info Preloader - BROM mode detected. Preloader - HW subcode: 0x8a00 Preloader - HW Ver: 0xcb00 Preloader - SW Ver: 0x0 Preloader - ME_ID: 87B9A0FD9FEA6FA647DEC4AB1F551AEE PLTools - Loading payload from mt6737_payload.bin, 0x258 bytes PLTools - Kamakiri / DA Run Kamakiri - Trying kamakiri2.. Kamakiri - Done sending payload... PLTools - Successfully sent payload: C:\Users\Sahil Sonar\Downloads\mtkclient-gui-20211204-x64\mtkclient\mtkclient\payloads\mt6737_payload.bin Port - Device detected :) DA_handler - Device is protected. DA_handler - Device is in BROM mode. Trying to dump preloader. DALegacy - Uploading da... DALegacy - Uploading legacy stage 1 from MTK_AllInOne_DA_5.2136.bin Preloader - Jumping to 0x200000 Preloader - Jumping to 0x200000: ok. DALegacy - Got loader sync ! DALegacy - Reading nand info DALegacy - Reading emmc info DALegacy - Setting stage 2 config ... DALegacy - DRAM config needed for : 510001154d33364573f3034281c000d7 DALegacy - Reading dram nand info ... DALegacy - Sending dram info ... DALegacy - M_EXT_RAM_RET : 0 DALegacy - M_EXT_RAM_TYPE : 0x2 DALegacy - M_EXT_RAM_CHIP_SELECT : 0x0 DALegacy - M_EXT_RAM_SIZE : 0x80000000 DALegacy - Uploading stage 2... DALegacy - Successfully uploaded stage 1 DALegacy - Reconnecting to preloader DALegacy - Connected to preloader DALegacy - m_int_sram_ret = 0x0 m_int_sram_size = 0x20000 m_ext_ram_ret = 0x0 m_ext_ram_type = 0x2 m_ext_ram_chip_select = 0x0 m_int_sram_ret = 0x0 m_ext_ram_size = 0x80000000 randomid = 0x60A82A569147EA9A491D324BFB3B2E30

m_emmc_ret = 0x0 m_emmc_boot1_size = 0x400000 m_emmc_boot2_size = 0x400000 m_emmc_rpmb_size = 0x400000 m_emmc_gp_size[0] = 0x0 m_emmc_gp_size[1] = 0x0 m_emmc_gp_size[2] = 0x0 m_emmc_gp_size[3] = 0x0 m_emmc_ua_size = 0x3a3e00000 m_emmc_cid = 4536334d15010051d70084814203f373 m_emmc_fwver = 0300000000000000

legacyext legacyext - [LIB]: Unknown seccfg partition header. Aborting unlock.

bkerler commented 2 years ago

That device is using gcpu, I will get a device hopefully next week for doing some tests.

bkerler commented 2 years ago

I've tested it on my Lenovo Tab 4 7 and it worked fine under Linux.