Page 1 of 3 123 LastLast
Results 1 to 15 of 44
  1. #1
    Skrilax_CZ's Avatar
    offline Retired Moderator
    Join Date
    Feb 2007
    Location
    Prague
    Posts
    5,243
    Thanks
    1,881
    Thanked 3,118 Times in 1,338 Posts
    Downloads
    28
    Uploads
    29

    What is Radio.img; why downgrades fail.

    Since I see many questions about the radio.img; I'll try to explain it:

    radio.img is a image of partition table + several partitions, which are defined in the header.

    You can open the file in hex editor and see it (starting at 0x18 offset):

    MAGIC-NOTHING2DO: does nothing
    OTA-QCSBL-UPDATE: updates qcsblhd_cfgdata.mbn and qcsblsec.mbn
    OTA-OMSBL-UPDATE: updates oemsblhd.mbn and oemsblsec.mbn
    OTA-RADIO-UPDATE: updates amsshd.mbn and amsssec.mbn (the actual baseband firmware)
    OTA-APSBL-UPDATE: updates appsboothd.mbn and appsbootsec.mbn
    OTA-CEFS--UPDATE: updates cefs.mbn (on some radio.img files this is done implicitly)

    !BE AWARE THAT THE BOOTLOADERS ARE SIGNED!

    Not all have to be present in the radio.img, but so far I always found oemsblhd.mbn and oemsblsec.mbn in it.

    Oemsbl prevents downgrading by using a backup and comparing the version with the one flashed. As for other paritions, the integrity checking consists of a signature check, then if it suceeds it checks secure version (against the one stored in 0:SECURE_VERSION parititon). Thus with the new phones or phones flashed with new SBF (as RAMDLD's secure version becomes the requirement if it's higher than the actual) you won't be able to use the old amss.mbn software (cefs.mbn is not signed, therefore use at will).

    The new SBF / MBN (De)packer is also able tho extract the radio.img into the partitions. They are named as if you were extracting them from the shx / sbf.
    Last edited by Skrilax_CZ; 07-21-2010 at 02:14 PM. Reason: updated

    Thanks Semseddin for the signature and avatar.

  2. 16 Users Say Thank You to Skrilax_CZ For This Useful Post

    adlx (03-14-2010), andreban (03-13-2010), Danation (03-14-2010), devok (03-18-2010), HandlerExploit (03-14-2010), jonatasmz (03-22-2010), j_r0dd (03-13-2010), kb7sqi (03-13-2010), kileak (04-10-2010), laguillo (04-16-2012), lwhmellow (03-13-2010), mlts22 (03-17-2010), OCM (03-13-2010), sublime1184 (03-13-2010), tonymy01 (12-07-2010), zedbra (01-17-2011)

  3. #2
    offline So I Hear You Can Mod
    Join Date
    Dec 2009
    Posts
    199
    Thanks
    18
    Thanked 16 Times in 14 Posts
    Downloads
    13
    Uploads
    0
    i can help u out to test stuff on my dext

  4. #3
    kileak's Avatar
    offline Of Mice and Modders
    Join Date
    Jan 2007
    Posts
    62
    Thanks
    50
    Thanked 16 Times in 12 Posts
    Downloads
    103
    Uploads
    0
    How can i know the currently version of the bootloader in my phone, is there any comand for the virtual console to know it ?

    I got kb7sqi-cliq-V1.4.8 ROM and use RSD Lite and it says: 1446. This is correct ?

    Thanks in advance

    EDIT: I got it... Hold power + Menu on the DEXT/Cliq (blue screen) , connect to RSD Lite and there is the Bootloader version
    Last edited by kileak; 04-15-2010 at 03:54 PM. Reason: typo and more info.
    ¡Motorolo & ROKR!

    Phone: HTC Desire ROM: Stock

  5. #4
    offline So I Hear You Can Mod
    Join Date
    Dec 2009
    Posts
    199
    Thanks
    18
    Thanked 16 Times in 14 Posts
    Downloads
    13
    Uploads
    0
    there is anyway to downgrade the radio yet?

  6. #5
    Skrilax_CZ's Avatar
    offline Retired Moderator
    Join Date
    Feb 2007
    Location
    Prague
    Posts
    5,243
    Thanks
    1,881
    Thanked 3,118 Times in 1,338 Posts
    Downloads
    28
    Uploads
    29
    No (it is checked by bootloader, which is not downgradeable if not rooted).

    Thanks Semseddin for the signature and avatar.

  7. #6
    Danation's Avatar
    offline public static final boolean isEvil() { return true; }
    Join Date
    Oct 2008
    Posts
    6,880
    Thanks
    4,383
    Thanked 3,384 Times in 2,117 Posts
    Downloads
    3
    Uploads
    0
    Well, if you are rooted, how do you downgrade the bootloader?

    _.__.__._I have retired. If you PM me, I may not reply.

  8. #7
    offline Maybe Modder
    Join Date
    Dec 2009
    Posts
    31
    Thanks
    5
    Thanked 6 Times in 3 Posts
    Downloads
    6
    Uploads
    0
    Does this mean that if boot loader is downgraded, radio could be downgraded???
    (this would be useful for LA users who lost 3G services with radio update from Tmobile)

  9. #8
    Skrilax_CZ's Avatar
    offline Retired Moderator
    Join Date
    Feb 2007
    Location
    Prague
    Posts
    5,243
    Thanks
    1,881
    Thanked 3,118 Times in 1,338 Posts
    Downloads
    28
    Uploads
    29
    Quote Originally Posted by Danation View Post
    Well, if you are rooted, how do you downgrade the bootloader?
    First someone must complete the partitioning with a module for example. We need to fill the rest of the partitions, including the bootloader.

    Thanks Semseddin for the signature and avatar.

  10. #9
    offline Itty Bitty Modder
    Join Date
    Jun 2010
    Posts
    8
    Thanks
    8
    Thanked 0 Times in 0 Posts
    Downloads
    38
    Uploads
    0
    Quote Originally Posted by Skrilax_CZ View Post
    Since I see many questions about the radio.img; I'll try to explain it:

    radio.img is a image of partition table + several partitions, which are defined in the header.

    You can open the file in hex editor and see it (starting at 0x18 offset):

    MAGIC-NOTHING2DO: does nothing
    OTA-QCSBL-UPDATE: updates qcsblhd_cfgdata.mbn and qcsblsec.mbn
    OTA-OMSBL-UPDATE: updates oemsblhd.mbn and oemsblsec.mbn
    OTA-RADIO-UPDATE: updates amsshd.mbn and amsssec.mbn (the actual baseband firmware)
    OTA-APSBL-UPDATE: updates appsboothd.mbn and appsbootsec.mbn
    OTA-CEFS--UPDATE: updates cefs.mbn (on some radio.img files this is done implicitly)

    !BE AWARE THAT THE BOOTLOADERS ARE SIGNED!

    Not all have to be present in the radio.img, but so far I always found oemsblhd.mbn and oemsblsec.mbn in it.

    The oemsblhd.mbn and oemsblsec.mbn is the blue bootloader and it will prevent downgrading to a lower version. This will prevent you from flashing old radio.img. In the firmware superthread, I called these firmwares "STICKY". Bootloaders with version 05.15+ will prevent you from using the old RAMDLD with exploit and won't let you to downgrade back to 04.CC bootloader (or we have not achieved that yet (without root permissions)).

    The new Mbn (De)packer (version 1.1g) is also able tho extract the radio.img into the partitions. They are named as if you were extracting them from the shx / sbf.
    Skrilax_CZ Hello, I'm in big trouble ... I installed a ROM American, and now I dont have 3G access here in Brazil (I think due to frequencies).
    Do you have any solution for this problem?
    I tried to read the topic, but I'm very secular, and did not understand much.
    Sorry for my English I am using the "Google translator "....
    On behalf of all Brazilians who are BIG problem with that, thank you!
    Last edited by Denis_Dext; 06-09-2010 at 03:12 PM.

  11. #10
    OCM's Avatar
    OCM
    offline There is no spoon
    Join Date
    May 2009
    Location
    main()
    Posts
    3,385
    Thanks
    1,118
    Thanked 1,425 Times in 738 Posts
    Downloads
    7
    Uploads
    0
    No, If you updated the radio there is no way as of now to downgrade and therefore you are stuck without 3G.
    You see, madness, as you know, is like gravity. All it takes is a little push.

  12. #11
    adlx's Avatar
    online Maker of adlxmod
    Join Date
    Jan 2010
    Location
    Madrid, Spain
    Posts
    1,034
    Thanks
    610
    Thanked 1,485 Times in 366 Posts
    Downloads
    30
    Uploads
    0
    @Skrilax_CZ:

    Someone at my blog has just commented that Movistar is selling Dext phones in Venezuela with 76XXC-6380525-SDBALUM baseband version, and that there it operates at 850 Mhz/1900 Mhz.

    Seeing the baseband version (like 1.3.18 T-Mobile one) it may come also with a new 5.* bootloader. Do you believe there is any hope someone could "find" the radio.img or the firmware out there, so Brasilian and Mexican people (who have lost there 3g after flashing T-Mobile 1.3.18/1.4.8) could hopefully flash that new radio and recover 3g back?
    Download my 1-click Recovery Flasher to flash a custom or stock recovery to your phone: Cliq, CliqXT, Backflip, ...

    Like my work? Support me: & visit my adlxmod site and follow me on Twitter
    Tambien me puedes encontrar en Movilzona (Esp)

  13. 3 Users Say Thank You to adlx For This Useful Post

    Denis_Dext (06-16-2010), kileak (06-17-2010), OCM (06-10-2010)

  14. #12
    offline Itty Bitty Modder
    Join Date
    Jun 2010
    Posts
    8
    Thanks
    8
    Thanked 0 Times in 0 Posts
    Downloads
    38
    Uploads
    0
    Quote Originally Posted by adlx View Post
    @Skrilax_CZ:

    Someone at my blog has just commented that Movistar is selling Dext phones in Venezuela with 76XXC-6380525-SDBALUM baseband version, and that there it operates at 850 Mhz/1900 Mhz.

    Seeing the baseband version (like 1.3.18 T-Mobile one) it may come also with a new 5.* bootloader. Do you believe there is any hope someone could "find" the radio.img or the firmware out there, so Brasilian and Mexican people (who have lost there 3g after flashing T-Mobile 1.3.18/1.4.8) could hopefully flash that new radio and recover 3g back?
    Good question, Alex

  15. #13
    offline So I Hear You Can Mod
    Join Date
    Dec 2009
    Posts
    199
    Thanks
    18
    Thanked 16 Times in 14 Posts
    Downloads
    13
    Uploads
    0
    any news?

  16. #14
    kileak's Avatar
    offline Of Mice and Modders
    Join Date
    Jan 2007
    Posts
    62
    Thanks
    50
    Thanked 16 Times in 12 Posts
    Downloads
    103
    Uploads
    0
    Quote Originally Posted by adlx View Post
    @Skrilax_CZ:

    Someone at my blog has just commented that Movistar is selling Dext phones in Venezuela with 76XXC-6380525-SDBALUM baseband version, and that there it operates at 850 Mhz/1900 Mhz.

    Seeing the baseband version (like 1.3.18 T-Mobile one) it may come also with a new 5.* bootloader. Do you believe there is any hope someone could "find" the radio.img or the firmware out there, so Brasilian and Mexican people (who have lost there 3g after flashing T-Mobile 1.3.18/1.4.8) could hopefully flash that new radio and recover 3g back?
    Thanks Alex Hope this works and a developer can help us
    Last edited by kileak; 06-17-2010 at 04:38 PM. Reason: Typo, sorry
    ¡Motorolo & ROKR!

    Phone: HTC Desire ROM: Stock

  17. #15
    offline Itty Bitty Modder
    Join Date
    Jun 2010
    Posts
    6
    Thanks
    0
    Thanked 0 Times in 0 Posts
    Downloads
    2
    Uploads
    0
    what does downgrading the boot loader do for us?


    -edit-
    im a noob here i was trying to find out the boot loader version i got the following. does that mean it's v 515? does that make any sense?

    IMEI/ESN/MEID: N / A
    Technology: N / A
    Software Version: N / A
    Flex Version: N / A
    Bootloader Version: v0x000515
    DRM Version: N / A
    Phone Type: Engineering (E100000000000000000000000000)
    Last edited by faramisimo; 06-20-2010 at 08:28 AM.

Page 1 of 3 123 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •