52

General - OK ... PSA: Stay away from T-Mobile variant of 10T 5g - Details | Page...

 2 years ago
source link: https://forum.xda-developers.com/t/ok-psa-stay-away-from-t-mobile-variant-of-10t-5g-details.4515835/page-3#post-87727857
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
neoserver,ios ssh client

Top Liked Posts

This is just a PSA for anyone currently with T-Mobile, looking to upgrade or purchase from the carrier.

The T-Mobile exclusive model of the 10T 5G is CPH-2419 ... This is a T-Mobile model ONLY. It can be SIM unlocked through regular methods, ie. paying the full contract off, but that is ALL!

There is absolutely NO WAY to unlock the bootloader of this model, because FASTBOOT is completely disabled, and unable to be re-enabled through any method which is currently available!

This is a software level block, which is specific to this model number.

AFAIK the chipset, board, and all internals are the exact same in respect to the 2413 (india) , 2415 (global) , and 2417 (EU) variants , so there is a SLIM possibility that if you stay BELOW the current A.11 build, you MIGHT be able to force a sideways shift to one of the other regions listed above via the Local Update, and Oxygen Updater combination, but i cannot confirm this due to my accidental mistake of not blocking updates! Mine is now on A.11 which is not available in any other region as of yet on the Oxygen Updater.

I really dont know whether changing regions will actually bring back FASTBOOT or not, except that when attempting to reach FASTBOOT via ADB or other methods, there is a brief, 1 second delay that does indeed make the "Fastboot Mode" screen appear, right before it automatically kicks out and reboots into normal mode. But even then with FASTBOOT running on my pc, and <waiting for devices>, it does not make the connection during the sequence. So this may just be remnants of the bootloader screen!

Also FASTBOOTD does work, and you can send commands regularly via command line, or Fastboot Enhance in that mode, but unlocking, and oem commands either fail or report unrecognized.

ANYONE proficient with probing ADB, Fastbootd, or EDL modes would be highly appreciated, in investigating any possibilities to exploit this restriction, because as with ALL android OS devices, I am almost 100% sure there is a way to mitigate this block, and flash a STOCK payload from one of the other variants. But EVERY cph2419 no matter what build, is shipped with FASTBOOT disabled at the factory level. It is an OPPO block, and has nothing to do with T-mobile other than the fact that they are the ONLY carrier listed in this model's designation.
I had a feeling that this was coming. First it starts with T-Mobile variants and then it starts trickling out to everything else. Keep in mind that Oppo disables fastboot on their devices too. The MSM Tool being locked down behind a technician login was the first hint of what's to come.
I had a feeling that this was coming. First it starts with T-Mobile variants and then it starts trickling out to everything else. Keep in mind that Oppo disables fastboot on their devices too. The MSM Tool being locked down behind a technician login was the first hint of what's to come.

Yup man... see i never read much into the OPPO acquisition of OnePlus, or i would have researched affected devices further. But in all honesty i wouldn't have suspected that a phone such as the 10 series, which is reportedly going to be on all the major carriers in the next 3-4 months, would take such a drastic step BACKWARDS like this! One plus has ALWAYS been known as "Developer Friendly", and rivaled the Google Pixel series in ease of unlocking bootloader, and rooting! But even stranger is how for so long back in the early days of android, devices were model specific to each carrier, (samsung s2, 3, 4... Moto Z... etc.) then the manufacturers wised up and went to universal hardware that was only sim locked, and could be bought outright unlocked. THEN COMES THIS LEFT TURN, in OnePlus taking a flagship device, and going back to Carrier specific models!

Finally the MOST SHOCKING notion comes with the realization that (for a fee) you can get your Samsung devices bootloader unlocked, (s10 and newer, possibly others thru same service) but this OPPO/Oneplus trainwreck looks to be the possible path coming for even more models like you said!

I just dont understand the war on unlockable bootloaders?! Especially Oneplus... they had the PERFECT system in place. (US models) You had to PHYSICALLY submit a Bootloader Unlock request... Acknowledge that you are aware that you are giving up warranty... wait a week (buyers remorse)... Then if still committed, you have to flash the unlock token. Why go all DICTATOR on us and start moving the devices STILL BRANDED with OnePlus, to a locked down format? Maybe 3 in 10 customers unlock & mod their phones! It takes MORE effort to disable functions and remove them, while at the same time alienating those 3 in 10 thus ensuring LESS SALES!! I fail to understand the logic. I just pray someone always keeps probing these A-hole companies products, for vulnerabilities and exploits that circumvent all their overbearing attempts to control what we can do with OUR devices!

<rant... sorry, this crap just makes my blood boil. cuz i DID demo the 10T at a T-mobile store and they had CPH-2417 models as demo, which were fine. Come to find out that they always planned on only SHIPPING or SELLING these 2419 models to the public!>

So I was just in the 10 Pro section and I would be very cautious trying the downgrade package conversion. There have been a few bricks and a few successes converting T-Mobile to another variant and without an MSM Tool to use, I don't know that I would risk a $650 paperweight.

Ok... I KINDA followed part of what they did in the 10pro forums.. opening the zip 1st, I edited 1 line:. "Oplus_update_engine_verify_disable=1" it WAS 0 which I understand had something to do with it verifying something on either the device or in the package to be identical before allowing.
Using a 1 disabled that verification. Now whoever tries this MUST be patient! When you start this via local updater app, you need to be above 40% , AND it will look like it is frozen and not processing at 0% for close to 5 min ... Then it will just start ticking off about 1% every 15-30sec til it gets to 60-70... Then it is about 2 percent per 15 sec... Finally when it hits 99% it will again look like it's stuck, but just wait, cuz it will hit 100% about 3-4 min later.
Whole process went seamlessly smooth! I advise not doing ANYTHING on your device while running. But I successfully went from Android 12.1 A.11 to Android 12.0 A.08 2419 to 2015.
Don't know if it matters but I did enable OEM unlocking in dev options 1st. And it persisted thru the whole wipe/flash process.!

You would need to try the downgrade package. I would be surprised if it works but it is worth a shot with the APK.

That's the global/US package.

So sorry for the delay... But yes your rollback package worked in getting me off the T-Mobile 2419 , and now I'm on the 2415. A.08 (yay . KINDA...)
Unfortunately this did not have the intended outcome. I mean yes the phone works properly and all... But I'm sure you knew that fastboot did not come back. (Wouldn't be that easy huh?).
Now, here's the next phase.... After repeatedly beating on OP via their chat, and yelling at person after person, I got one of them to slip up and let a few MINOR things leak verbally.
(Bear with me cuz I might be stating something that might be slightly off from him... I could tell English wasn't his 1st language... Or even 2nd)

"Sir what you are requesting is a file authorization to unlock the bootloader on your device, correct" --- OP
"No, because even if I HAD a special file, I would not be able to flash it, because I have NO fastboot mode accessible on my phone. YOU removed or disabled it yourselves!" ---- Me
"Ok after reviewing your previous words sent, I think I know what it is you seek. There is a program called MSM, do you know of, yes?"-OP
"YES I know exactly of that, and you guys made it password restricted so I cannot log in to get what I need, so is it possible you can refer me to get an access account for the tool?"-Me
"Unfortunately sir that is department not of ours, but I will forward your request to them for email response by 24hrs."-OP
"Ok... So what then, you or them will get back to me with info on how to get an account?" -Me
"Well it yes, sir I do not know if that is how they resolve, or maybe they just give you factory fastboot ROM which can be use with the updater application, for local flash. It is my knowledge that other devices we have sold have had this ROM load special fastboot to allow unlock/lock/flash/wipe commands to be sent from your PC, but it was special tool for devices that not have it already!" - OP ...
BINGO!!
I'll spare you the rest of the chat, but of course no one has contacted me....
SOOO... here's my thoughts...
1. This phone is like Samsung in that there is NOT a permanent bootloader lock, and instead there's just a custom ROM (like the old "Combination FW" that restores permissions for higher level functions aka 'Fastboot ROM"
2. This ROM could TECHNICALLY be created or the fastboot portion extracted from another one that already is out for one of these older devices, and we swap it into one of these rollback packages, cuz I did edit the payload properties file to test if simple changes can be made and it still flash... (Answer : yes... It worked!)
3. One of you GURUs who have found TEMP ROOT access on so many other 'unrootable' devices, discover a way in to these, in which we can access the partition where the bootloader exists, and turn it back on with a hex edit, or flip it to UNLOCKED, then I can use Qfil or an EDL prog to flash custom recovery!?!

The reason I say turn it back on is because I am fairly confident it is still functional, primarily because it shows for a half a second, then reboots back into normal mode if 'adb reboot bootloader' is used. How can it be GONE, If the OS still recognizes it. (This suggests there's a script or init command being triggered once that command is sent, and it forces reboot before fastboot can connect to your PC! ... There is still a splash screen triggered from the command... AND all the updates and rollback packages are using something other than EDL to flash all the partitions as .img files, cuz EDL can't communicate with a device while running, but those packages loaded via local update are prepped while running, and processed only by a reboot, which almost confirms that it's fastboot being used. Fastbootd will not process ANY img files, but it does recognize every reg fastboot command!

(Sorry again for long post but I figured detail is needed to solve this.)

I have 48 hours to completely brick this device and still return it, so I am up for ANY actions that you all might suggest, with no regrets! If I get it AT LEAST rooted, I'll take it! Or if we get fastboot enabled again even better. I will monitor this thread for your replies.

Thanks for all input!


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK