[How-to] Rooted stock SGP621 firmware with DRM keys - Xperia Z3 Tablet Compact General

Note: Since lowtraxx's guide has included how to get back to stock rom since the time this post was made, I strongly suggest to follow his guide instead.
==========================
Disclaimer:
I make no claims to any of the codes, scripts and programs listed in this post. Credit goes to the creators.
This serves as a extension of lowtraxx's guide (which left your device on a rooted SGP621 on a D6603 system).
These are what I did to get stock rooted firmware on my SGP621 while keeping the bootloader locked and most importantly, the DRM keys intact. I make no guarantees that you will not brick your device, but I did quite a lot of trial and error flashing without messing things up, so if you know what you are doing, these steps should be relatively safe.
Files/Tools Required:
Backup TA by DevShaft
Flashtool by Androxyde
Stock SGP621 FTF (I compiled my own by downloading the firmware using XperiFirm by laguCool and bundling the FTF using Flashtool. Alternatively, you can just use the one provided in lowtraxx's guide.)
Advanced Stock Kernel by krabappel2548
PRFCreator by zxz0O0
SuperSU by Chainfire
SonyRICDefeat by dosomder
Prerequisite:
Follow lowtraxx's guide to completion.
Steps:
Backup TA partition using Backup TA.
Return to stock unrooted by flashing the SGP621 FTF using Flashtool.
Unlock the bootloader (You'll lose the DRM keys here, but it doesn't matter anymore since you already have them backed up using Backup TA).
Flash the Advanced Stock Kernel using Flashtool in FastBoot mode. At this point your device will be unlocked, with DRM keys lost, and rooted with custom recovery.
Using PRFCreator on the SGP621 FTF and the SuperSU zip, create a rooted stock firmware flashable zip. Note: Be sure to check all the checkboxes under the "Include" section.
Copy the resulting zip onto your device's internal storage or external SD card.
Also copy the SonyRICDefeat zip to the same location.
Boot into TWRP on your device (Boot up the device and press the Volume down key when the purple LED lights up on the Sony boot screen).
Flash the rooted stock firmware zip followed by the SonyRICDefeat zip.
Once complete, reboot into system and set up the device for USD Debugging.
Restore the TA partition using Backup TA.
Reboot the device again and you now have the device on rooted stock firmware, with DRM keys intact.

CubicU07 said:
Disclaimer:
I make no claims to any of the codes, scripts and programs listed in this post. Credit goes to the creators.
This serves as a extension of lowtraxx's guide (which left your device on a rooted SGP621 on a D6603 system).
These are what I did to get stock rooted firmware on my SGP621 while keeping the bootloader locked and most importantly, the DRM keys intact. I make no guarantees that you will not brick your device, but I did quite a lot of trial and error flashing without messing things up, so if you know what you are doing, these steps should be relatively safe.
Files/Tools Required:
Backup TA by DevShaft
Flashtool by Androxyde
Stock SGP621 FTF (I compiled my own by downloading the firmware using XperiFirm by laguCool and bundling the FTF using Flashtool. Alternatively, you can just use the one provided in lowtraxx's guide.)
Advanced Stock Kernel by krabappel2548
PRFCreator by zxz0O0
SuperSU by Chainfire
SonyRICDefeat by dosomder
Prerequisite:
Follow lowtraxx's guide to completion.
Steps:
Backup TA partition using Backup TA.
Return to stock unrooted by flashing the SGP621 FTF using Flashtool.
Unlock the bootloader (You'll lose the DRM keys here, but it doesn't matter anymore since you already have them backed up using Backup TA).
Flash the Advanced Stock Kernel using Flashtool in FastBoot mode. At this point your device will be unlocked, with DRM keys lost, and rooted with custom recovery.
Using PRFCreator on the SGP621 FTF and the SuperSU zip, create a rooted stock firmware flashable zip.
Copy the resulting zip onto your device's internal storage or external SD card.
Also copy the SonyRICDefeat zip to the same location.
Boot into TWRP on your device (Boot up the device and press the Volume down key when the purple LED lights up on the Sony boot screen).
Flash the rooted stock firmware zip followed by the SonyRICDefeat zip.
Once complete, reboot into system and set up the device for USD Debugging.
Restore the TA partition using Backup TA.
Reboot the device again and you now have the device on rooted stock firmware, with DRM keys intact.
Click to expand...
Click to collapse
Hey, How did you manage to avoid soft bricking your tablet?
i followed your instructions but i still get softbricks.

frostmore said:
Hey, How did you manage to avoid soft bricking your tablet?
i followed your instructions but i still get softbricks.
Click to expand...
Click to collapse
At which point did you get softbricks? Try to do a data wipe from recovery and see if it helps.

CubicU07 said:
At which point did you get softbricks? Try to do a data wipe from recovery and see if it helps.
Click to expand...
Click to collapse
Step 9.

For me, I got soft brick after restoring the TA partition. Ended up repeating the whole process flashing stock firmware again. After that, I found that I need to tick all the checkbox in the PRFCreator when creating the flashable zip. After the flash and restore, I am able to boot smoothly.

Pingpoi said:
For me, I got soft brick after restoring the TA partition. Ended up repeating the whole process flashing stock firmware again. After that, I found that I need to tick all the checkbox in the PRFCreator when creating the flashable zip. After the flash and restore, I am able to boot smoothly.
Click to expand...
Click to collapse
I guess I wasn't too clear on how to use PRFCreator, apologies for that. Added a note in to reflect that in the original post.

Can i do it on unlocked bootloder?
Which step should i skip? Thanks

zalaz said:
Can i do it on unlocked bootloder?
Which step should i skip? Thanks
Click to expand...
Click to collapse
Start from Step 4 since your bootloader is unlocked.

Since lowtraxx's guide now also include guides to flash rooted stock or CM, so that means both guides do the same thing now? Since I was a little confused while reading the instruction:
Prerequisite:
Follow lowtraxx's guide to completion.
Anyway, thanks both for the great works!!

Please,i have the same confuse as ultima888 with "Prerequisite:
Follow lowtraxx's guide to completion.".
Should i only follow that guide,from this topic? (as it describe full way to get root and stock rooted FW,
or i understand some wrong?) Or i must to go all through lowtrack's guide and THEN do in ptactice the same steps from this guide?
Pls understand me, here are some confusings her, i don't like to softbrick my device and ask just to be sure...
Thanks in advance!!!

ValVK said:
Please,i have the same confuse as ultima888 with "Prerequisite:
Follow lowtraxx's guide to completion.".
Should i only follow that guide,from this topic? (as it describe full way to get root and stock rooted FW,
or i understand some wrong?) Or i must to go all through lowtrack's guide and THEN do in ptactice the same steps from this guide?
Pls understand me, here are some confusings her, i don't like to softbrick my device and ask just to be sure...
Thanks in advance!!!
Click to expand...
Click to collapse
Do lowtraxx's post first.
Then follow this post.

i am little bit confused by all of those steps to get root. (described in this and related threads)
if i understood the whole procedure right then we have to get root first
via flashing a vulnerable firmware made for another device, to be able to backup the drm keys right?
but then we lose root again while flashing back latest stock rom.
now we have to proceed with unlocking the bootloader to get root and recovery.
finally we restore drm keys and doing so bootloader is locked again ?
is this basically what all those steps are for and do i have to go through all of them
if i "just" want to get root on latest stock (no custom roms) to install xposed framework?
thanx in advance and keep up the good work.

sorry, I only speak Spanish, I used google translate:
The original firmware is not vulnerable. The only way get root is opening the bootloader (and put a custom recovery to install SuperSU) but that the drm keys are lost. To keep the drm keys have to get to backup the partition TA without opening the bootloader. To make the backup you need to root and to achieve this must be mixed before 2 firmwares.
Restoring the TA partition relock the bootloader
You should only restore the TA partition with an original kernel

Bundling the FTF question
[*]Stock SGP621 FTF (I compiled my own by downloading the firmware using XperiFirm by laguCool and bundling the FTF using Flashtool. Alternatively, you can just use the one provided in lowtraxx's guide.)
Click to expand...
Click to collapse
Thanks for the guide!
Just a newbie question. What Sony device did you select in Flashtool when you bundled the firmware? I can not find SGP621 anywhere.
/kusk

SO i made a lollipo ftf pre rooted but when i tried to flash RICDefeat it would give me an error. I rebooted the system and everything seems fine, what exactly did that zip file do. What problems im i going to have with the divice and is there any way of fixing it.
thx

Dear CubicU07.
I have a question for u. I have a z3 tablet but it's SGP641 so if i follow this guide for my z3t 641 , have any problems with this ?
Ty for reading

Works on SPG611
Thank you for the guide. Was redirected from http://forum.xda-developers.com/z3-...t-rooting-sgp611-giefroot-bootloader-t3017314 and your guide was perfect. Thank you for your effort.

Same for me
Sony RIC protection not work on Lolipop. A new Version would be nice.

Hi everyone,
In step 5,
1. do I have to check the checkbox in "Sign zip"?
2. do I have to put any recovery file under "recovery zip" section?
Thanks.

waichai said:
Hi everyone,
In step 5,
1. do I have to check the checkbox in "Sign zip"?
2. do I have to put any recovery file under "recovery zip" section?
Thanks.
Click to expand...
Click to collapse
1. no
2.no

Related

[GUIDE][ROOT]How to root Xperia Z KitKat (10.5.A.0.230) and regain Locked Bootloader

I know rooting Sony devices is pain in arse. But believe me, it's fun. Follow the steps to root your beloved Sony Xperia Z.
1. Downgrade to 4.2.2 (10.3.1.A.2.67) by flashing the ftf file of your region. Search the thread to find ftf corresponding to your region.
for C6502 India
http://forum.xda-developers.com/xperia-z/general/xz-c6602-stock-indian-4-2-2-fw-67-ftf-t2573610
2. Root this firmware by cubeundcube method.
http://forum.xda-developers.com/showthread.php?t=2559009
3. Take a TA partition backup using DevShaft's method. This is necessary for relocking your bootloader later.
http://forum.xda-developers.com/showthread.php?t=2292598
4. Upgrade to Kitkat using PCC or SUS (or flash a Kitkat ftf which is meant for your region). Don't panic that you've lost root. Read further.
5. Make a ftf file of the update files that has been downloaded to your computer using flashtool (if you upgraded via PCC or SUS).
http://forum.xda-developers.com/xperia-u/general/guide-how-make-ftf-stock-firmware-sus-t2075736 OR
http://forum.xda-developers.com/xperia-z/development/noobs-guide-create-stock-firmware-ftf-t2188129
6. Unlock bootloader by visiting this link (take a backup of all your data before unlocking bootloader). (Unlocking bootloader voids warranty. But don't worry you can relock it if you have backup of TA)
http://unlockbootloader.sonymobile.com
7. Download the latest update super su.zip from Chainfire's website. Save it in external micro SD card of your phone.
http://download.chainfire.eu/supersu
8. Flash a custom kernel by DooMLoRD. This is a modified stock kernel with CWM recovery built-in. Enter into the CWM recovery and flash the super su.zip you downloaded earlier to root your phone and turn off the phone in recovery itself.
http://forum.xda-developers.com/xperia-z/development/cwm-based-recovery-6-0-4-5-xperia-z-t2167381
9. To get back to stock recovery, use the ftf file you downloaded (or created) at step 4. above and Flash only the kernel and fotakernel.
10. Now relock your bootloader by restoring the TA partition backup you made at step 3. Your phone is rooted now with locked bootloader.
P.S.
>Users who already have a backup of TA, unlock your bootloader and follow steps from 7.
>Users whose bootloader can't be unlocked, follow first two steps, visit this thread to install [NUT]'s dual recovery.
http://forum.xda-developers.com/showthread.php?t=2261606
and flash this pre-rooted zip
http://forum.xda-developers.com/xperia-z/development/stock-update-to-10-5-0-230-t2761629
There already is a guide about this here:
http://forum.xda-developers.com/xperia-z/development/guide-how-to-root-101-firmware-lb-t2656698
Thread closed.

[STOCK][ROOT] Step-by-Step to rooted Lollipop 14.5.A.0.270 (locked bootloader)

Hey guys,
I jumped through several threads here until i found all steps needed to get my Z1 compact D5503 from my rooted KitKat 14.4.A.0.108 to a rooted 14.5.A.0.270,
[paranoia] without the need to install a firmware that someone manipulated for evil purposes[/paranoia]
In the end it was quite easy. I documented the steps - mostly for myself - and maybe someone can benefit from that.
No warranty, that it works the same flawless way for you or for any other Xperia model than Z1 compact D5503 (though it should...).
So just proceed with the steps if you know about the possible risks of killing your phone
If you find any mistakes please drop me a line...
For a cleaned up version go here - thanks
This brings your Z1 compact D5503 from a rooted 14.5.A.0.108 to a rooted 14.5.A.0.270 without any dataloss
User @codified also successfully updated a 14.4.A.0.157 with these steps (see here)
Just upgraded to 14.6.A.0.368 from 14.5.A.0.270 with these steps. Works like charm. And @JarrB reports success on upgrading from 14.4.A.0.157 to 14.6.A.0.368
Pre-requs:
- MS Windows - sorry, I don't do linuxes
- Xperia (Z1 compact) device stock(?) KitKat rooted (Newroot worked just fine without unlocking the boot loader )
- some custom recovery, the fancy dual recovery works just fine, install from rooted kitkat (dual recovery from http://nut.xperia-files.com/) - the installer.zip! not the flashable.zip
Tools needed:
- FlashTool: http://www.flashtool.net/index.php
- XPeriFirm: http://forum.xda-developers.com/cro...xperifirm-xperia-firmware-downloader-t2834142 ahh no longer needed as separate download, as it's integrated in FlashTool now
- PRFCreator: http://forum.xda-developers.com/crossdevice-dev/sony/tool-prfcreator-easily-create-pre-t2859904
Part 1: get a FTF file of the desired firmware
See also: http://www.xperiablog.net/2014/08/1...re-files-using-xperifirm-and-flashtool-guide/
UPDATED THIS PART - thanks to user codified
Open FlashTool and start XperiFirm (XF-button)
Download .270 (or .283/.368 if available) firmware with XperiFirm with auto-unpack (I chose to use the same carrier branded version that .108 was - USE Generic LAM for an unbranded version)
Have two cups of coffee - or tea if you prefer that
The .ftf is now in your .flashtool\firmwares subfolder
Original steps
Open FlashTool and start XperiFirm (XF-button)
Download .270 firmware with XperiFirm () with auto-unpack (I chose to use the same carrier branded version that .108 was)
Use FlashTool Bundle->Create
Select unpacked firmware path
Select Device From list
Add your branding info: Vodafone DE
add firmware version: 14.5.A.0.270
add all but the .ta files to the right listview
DELETE the fwinfo.xml in unpacked firmware folder THIS SEEMS TO BE ESSENTIAL - didn't dare to keep it
create
done. --> ftf file is in configured user home: C:\Users\USERNAME\.flashTool
Part 2: get your pre-rooted ftf file
Download latest SuperSU: http://download.chainfire.eu/supersu or the also as well/better working reported beta 2.49
Open PRFCreator
add D5503_14.5.A.0.270_Vodafone DE.ftf the .tft file you just created in part 1 as ftf file
add UPDATE-SuperSU-v2.46.zip as supersu zip
not needed, but also not wrong: add Z1C-lockeddualrecovery2.8.21-RELEASE.flashable.zip as recovery (dual recovery from http://nut.xperia-files.com/)
check all checkboxes, but the "sign zip"
maybe add extra zip
create
done. --> find flashable-prerooted.zip in PRFCreator folder
Part 3: flash your zip
nandroid-backup your phone
have 3 big cups of coffee - please, no tea at this step
get really nervous
wipe dalvik and cache only to get a better feeling
try dirty flash the new firmware with the pre-rooted zip via Recovery, not using Flashtool (OTA is also applied dirty, isn't it?)
whoa, flashing was fast
wipe dalvik and cache again. Could help prevent the unpredicted... could it?
AAAAHHH! booting takes so looohoooooong
Yeah! 386 Apps getting optimized...
looks good
hu? NFC firware update? OK. Go on.
Update for Google play services? YES. Go on.
done. --> be a happy Z1-compact-with-rooted-Android-5.0.2-user
totally optional part 4: Xposed
Now go on and install Xposed for Lollipop v69+ and hope for the best
rubbish! forget it for now, as it is bootlooping :/
done. --> still be a happy Z1-compact-with-rooted-Android-5.0.2-user with Xposed
regards!
done exactly this... rocking LP now
good to read, ltcdata! Happy I could provide sth. useful
While it optimizes the 327 apps in my case, I am wondering at what stage of the process does the firmware get rooted? Or is what is downloaded by Xperifirm already rooted? Very good guide BTW. Seems to go okay as long as you read everything carefully and in the right order. Thanks.
@nagusia thanks for liking my very first guide
Basically the root magic happens in part2 no 8 (pressing the create button in PRFCreator ):
PRFCreator unpacks the unrooted original stock fimrware that XPeriFirm downloaded and stuffs it into a new archive together with SuperSu and the other ZIPs you maybe added.
Code for that can be review in Job.cs at the projects GitHub repo: github.com/dosomder/PRFCreator (I'm still not allow to post outside-links here).
Pretty simple in the end...
I had a problem with charging reaching 89% and then the led randomly blinking. I did a restore to KitKat and there wasn't a problem. Then I thought I'd try flashing another of the DE generic pre-rooted roms posted on this forum. Here is where my problems started. It would get a upgrading - starting apps and then reboot. I tried making my own DE customized rom and the same problem. Then I went back to my orginal UK customized rom and ..... same problem. Finally did a factory reset in recovery and now it seems all good. I don't don't if I still have the charging issue yet. I have a theory that a dirty flash is OK the firs time, but a clean flash or factory reset after subsequent flashes may be necessary.
Dirty flashed from .242 to .270, without losing data. Only had to re-flash the Xposed alpha 4 zip (xposed-sdk21-arm-20150430.zip). It probably saves more time to just add this zip during part 2, step 7...
Thanks a lot for the guide.
Sweet guide dude. but I had trouble finding my region's KitKat firmware and downloading then rooting again seems like so much of a hassle so I did it the dirty way. Beware that this is very RISKY! I first downloaded Kingroot and rooted my device successfully, then installed NUT Recovery Installer version and installed TWRP via PC, then try to remove Kingroot using this guide. Thereafter, I followed your guide sans the flash KitKat step. And it works, Bootloader is still Unlocked. Thanks a lot dude!
uchihakurtz said:
Sweet guide dude. but I had trouble finding my region's KitKat firmware and downloading then rooting again seems like so much of a hassle so I did it the dirty way. Beware that this is very RISKY! I first downloaded Kingroot and rooted my device successfully, then installed NUT Recovery Installer version and installed TWRP via PC, then try to remove Kingroot using this guide. Thereafter, I followed your guide sans the flash KitKat step. And it works, Bootloader is still Unlocked. Thanks a lot dude!
Click to expand...
Click to collapse
The method is not at all risky, as long as You use the proper files!
Also, many people don't prefer using Kingroot as it is said that it shares Your phone information (like IMEI number) to some servers.
Hopefully You meant locked bootloader in last sentence!
Mirhawk said:
The method is not at all risky, as long as You use the proper files!
Also, many people don't prefer using Kingroot as it is said that it shares Your phone information (like IMEI number) to some servers.
Hopefully You meant locked bootloader in last sentence!
Click to expand...
Click to collapse
Actually by risky, I meant that part, you'll never know what Kingroot does, lol. Oh right, I meant the bootloader stays locked.
I already have updated to .270 via sony companion. Can I follow these same steps and replace current .270 with rooted .270?
@jooxxo
No, you need a custom recovery (root) to flash the resulting .zip file.
jooxxo said:
I already have updated to .270 via sony companion. Can I follow these same steps and replace current .270 with rooted .270?
Click to expand...
Click to collapse
No, but You can do this.
ok... well I took a nandroid backup of my kitkat (rooted & recovery obviously) before updating to .270 lollipop. If I restore that backup, will it restore recovery as well?
edit: I just dont want to lose all my apps & settings.
Any way to root if 5.0 is already on my phone?
Locked bootloader.
jooxxo said:
ok... well I took a nandroid backup of my kitkat (rooted & recovery obviously) before updating to .270 lollipop. If I restore that backup, will it restore recovery as well?
edit: I just dont want to lose all my apps & settings.
Click to expand...
Click to collapse
If You restore Your KitKat nandroid over backup (assuming the backup consists of system and data partitions), then it will cause You problems. The easiest way to keep Your apps and data is backing up them with an app since You are rooted, and then restoring them using the same app to restore apps and data on Lollipop. Don't use the Sony backup app, KitKat backups don't work on Lollipop. ALso to get a recovery after Lollipop, just simply install the XDualZRecovery.
EZY-E said:
Any way to root if 5.0 is already on my phone?
Locked bootloader.
Click to expand...
Click to collapse
Refer My post just 1 post before You.
Did it with latest 14.5.A.0.283 on my Z1C ... all good.
Thank you
Easy to follow tutorial for rooting your Z1's latest firmware Thanks!
@kalaja: 283? When did that happen?
sunbeam906 said:
Easy to follow tutorial for rooting your Z1's latest firmware Thanks!
@kalaja: 283? When did that happen?
Click to expand...
Click to collapse
from xperiablog net:
Xperia Z1 Compact sees new firmware (14.5.A.0.283) for carriers in Austria and Germany
by XB on 16/06/2015
in FIRMWARE, XPERIA Z1
Xperia Z1 Compact. A new firmware update with build number 14.5.A.0.283 has been released for the Sony Xperia Z1 Compact (D5503). The update has so far only been released for T-Mobile Austria and Telekom.de in Germany. However, users on these carriers were still rocking Android KitKat (14.4.A.0.157), so this update brings them a first taste of Android Lollipop. It is unclear whether this ‘283’ firmware will see a global release, the same build number has also been certified for the Xperia Z1 and Xperia Z Ultra, although those updates are not live right now.
Thanks for the info, kalaja Much appreciated.

[HOW-TO][Root+TWRP Recovery][LB]Stock Marshmallow 6.0.1 (23.5.A.0.575/.291)

Hello everyone,
Update 27.08.2016: It also works for version 23.5.A.1.291 (OS update that includes STAMINA). The procedure is identical, you just have to use the latest firmware available and create a pre-rooted .zip to update your tablet device.
I am pretty sure that I couldn't find a how-to guide anywhere that explains how rooting our precious Xperia Z3 Tablet Compact on Android 6.0.1 with locked bootloader works. This post simply shows the process of how I got root on my device (SGP611) and I am going to write the steps only in moderate detail so that hopefully everyone can follow without hassle. There are some steps that I'm not going to explain too much in detail but instead I highly recommend you to look around a bit on XDA to find theses already explained steps (I just want to get to the point on how to get root so that's why it may not be super noob friendly).
Edit: A little bit more info and additional steps that might help you further can be read in post #5.
Standard disclaimer:
Your warranty is now void.
I am not responsible for bricked devices, dead SD cards, or any other issues that may arise from not following the steps correctly/carefully.
Click to expand...
Click to collapse
Also, I am not a developer so I am very sorry if I can't give you an answer to questions relating to problems with the tools we are going to use in this tutorial. It's better to ask the developers directly( I will link you to the needed threads).
Steps:
1. Downgrade device if necessary
2. Root using KingRoot exploit
3. Install XZDualRecovery custom recovery
4.1 Get the latest Marshmallow firmware and create FTF file
4.2 Create the pre-rooted .zip file
5. Flashing the pre-rooted .zip file correctly
Extra: Already created pre-rooted .zip file download for the lazy ones (At the very bottom)
1. First thing you need to know is that if you're device is currently bootloader locked and on Android Marshmallow 6.0.1 (23.5.A.0.575), as of the time I am writing this, you will not be able to achieve root directly through some kind of rooting tool. What you need to do now is to downgrade your device to an older version of Android, e.g. Android 5.0.2 or KitKat are good enough.
To do this you need to find the older firmware:
-Try this link to look for it: http://xperiafirmware.com/ (If you can't find Android 5.0.2 for example, use Google or look around XDA)
-Downgrading the device will wipe data/factory reset, so BACK UP YOUR STUFF before downgrading.
-Use flashtool to flash the firmware and downgrade: http://www.flashtool.net/index.php (I will expect you to know how to use flsahtool to flash ftf. files, there are many tutorials on how to do this)
2. Why you have to downgrade is because older firmwares have an exploit that can be used to root the device even when the bootloader is locked. So yes, something like a one-click root method is possible now.
-You may use this tool called KingRoot to root your tablet: http://forum.xda-developers.com/android/apps-games/one-click-root-tool-android-2-x-5-0-t3107461
Read the info carefully before doing anything.
3. Now, you should have managed to root your device with Android version other than 6.0.1. That is when another great tool comes in which is called XZDualrecovery. XZDualRecovery is "a" custom recovery that you'll need to be able to proceed from here.
-Install XZDualRecovery using the root method. That's the only way to get it onto the device.
-Link: http://forum.xda-developers.com/showthread.php?t=2261606 (Read the instruction there carefully)
4. Great! Now you should have root and custom recovery. If not, you did something wrong.
This is when you can create something called a "pre-rooted" firmware which is basically all you need to get root on Marshmallow 6.0.1.
4.1
-Use the tool called Xperifirm to download the Android 6.0.1: http://forum.xda-developers.com/cro...xperifirm-xperia-firmware-downloader-t2834142
-Launch Xperifirm and on the left hand side browse to "Xperia Z3 Tablet Compact -> the model number of your device (look under settings on your device to find out model number)"
-On the right side top you'll see "Check all", click it to let it check for latest firmware number
-Android 6.0.1 would be 23.5.A.0.575 23.5.A.1.291 (latest firmware). You can choose any Market or Operator you want (Tip: Use "Customized XXX" and avoid carriers)
-After downloading you'll need flashtool again to convert those downloaded files to .ftf format (Again, there are instrutions on the internet that you can look for)
4.2
-Make sure you have the .ftf file
-Get two .zip files
--1) RecRoot: http://forum.xda-developers.com/z3/general/wip-sony-android-6-0-mm-t3337357
--2) A dummy flashable file: http://forum.xda-developers.com/z3/...oid-6-0-mm-t3337357/post66569699#post66569699
-Get PRFCreator: http://forum.xda-developers.com/crossdevice-dev/sony/tool-prfcreator-easily-create-pre-t2859904
-Open PRFCreator and put the .ftf file to FTF, the RecRoot .zip file to RECOVERY, and the dummy_flashable.zip to SUPERSU. Don't do any other way!
-Tick Kernel, FOTAKernel, Modem, LTALable and Sign Zip
-Click "Create" to create the pre-rooted Marshmallow firmware
5. You should have created the pre-rooted Android 6.0.1 firmware now.
-Put the pre-rooted .zip file and the RecRoot .zip file onto your device's SD card/storage (anywhere where you can find them later)
-Reboot your tablet into TWRP recovery. (XZDualRecovery even provides you an app to choose and reboot to recovery) Don't reboot into any other recovery!
-Now, in TWRP recovery, erase dalvik cache, cache and system just to be clean.
-FIRSTLY, flash the pre-rooted.zip that you have put on your device. After flashing successfully, DON'T REBOOT YET!
-SECONDLY, flash the RecRoot.zip file
-Now you can reboot and if you did everything correctly, your Z3 Tablet Compact should boot up with Chainfire's SuperSU root and TWRP recovery (to access TWRP recovery, you have to reboot the device and while a green LED light appears for a moment, press and hold the volume down button. Then you will enter TWRP recovery. As for now, you cannot access the recovery any other way like using a reboot app, it will not work!).
CONGRATULATIONS! You have a rooted Z3 tablet with locked bootloader and you haven't lost Sony features. :laugh::good:
Thank you for reading this tutorial. And don't forget to thank all these devs that provided us the needed tools.
Extra: I will also put a link here where you can download my created pre-rooted Marshmallow firmware. It's build 23.5.A.0.575 Customized Germany and for SGP611 only!
https://mega.nz/#!TQ4AwbSZ!LNw11quAWurER_Tl9zHDyX_TiwZnzeVM1M0s10eyt4g
Just followed your instructions with my SGP621, worked great!
Teella said:
Just followed your instructions with my SGP621, worked great!
Click to expand...
Click to collapse
Great!
Would you be so kind and share your pre-rooted SGP621 ROM?
janla said:
Great!
Would you be so kind and share your pre-rooted SGP621 ROM?
Click to expand...
Click to collapse
I would love too, but my upload is very very slow and would take week to upload. Follow the instructions it's very easy, it was the first time I've ever touched and FTF or made a prerooted rom. Well not really made, just clicked a few buttons in flashtool and waited.
SGP621 additions
Hey man,
thanks for this concise guide to unroot our beloved tablet! I tried a few times before, but always gave up under the flood of outdated info available. With your guide, I successfully rooted my SGP621 (= Sony Z3 Tablet Compact with LTE).
Since you refer to "available info on the net" quite often, I had a few moments where I was unsure what to do exactly. Maybe the following hints can help others like me who are new to the world of Sony android devices.
Step 1:
You could probably also downgrade to 5.1, but to be safe, I chose 5.0.2. The needed ftf files for SGP621 as well as the SGP611 and SGP612 are avilable here.
I used the most current version of the flashtool, which is 0.9.22.3 as of this posting. I followed this (German) guide for installing and using the flashtool. To install the needed drivers, you'll have to navigate to wherever you installed the Flashtool to, there to the subfolder drivers, and execute the driver installer you find there. In the driver selection dialog install the first two, and of course the Z3TC driver you find somewhere in the list. Got two errors during the driver installs, ignored them, all went well.
Step 2:
Kingroot is a one-click-rooting solution you install directly on the phone, no pc connection necessary. After the tool is installed, you have to start it, swipe up a couple of times, and then tap on "Purify". The description in the xda thread made me think "Purify" is just an ad for an additional app, but it does start the rooting process.
Step 3:
After downloading and extracting XZDualRecovery, start the install.bat (under Windows, obviously). Connect your tablet, then choose menu item 1 (Install with SuperSU).
Step 4.1:
Many guides describe a decrypt / unpack step, you don't need this. The files are already unpacked after the download through XperiFirm. I did, however, delete the file "fwinfo.xml" from the downloaded files. No idea if that's needed, but it didn't hurt either.
To convert the downloaded files into an ftf file in the flashtool, select "Tools > Bundles > Create".
As "Source Folder" select the folder that XperiFirm created in the download path you specified. You'll then see a bunch of files in the "folder list" - select everything but the ".ta"-files (there were 5 ta-files in my case).
Doubleclick the empty "Device:" line, select the correct device.
I guess you can enter whatever in Branding and Version, I entered "German" and "23.5.A.1.291".
Step 4.2:
The "RecRoot"-File mentioned is indeed called "RecRoot_combined.zip". If you download that file, you're good to go. The PRFCreator tool needs to have Java installed for the last step (signing the prerooted rom). The file with the prerooted rom is saved in the PRFCreator dir itself.
Hoping this'll help someone!
@pull.me.under I am glad that I could help. Also, I'll thank you for your time extending my guide a bit with more detailed steps. That'll help users who are new to this stuff for sure. ?
Gesendet von meinem SGP611 mit Tapatalk
Hi,
If I follow this way, can I restore my tablet in stock settings if I have any trouble?
cheers
bozo13 said:
Hi,
If I follow this way, can I restore my tablet in stock settings if I have any trouble?
cheers
Click to expand...
Click to collapse
For restoring your tablet to stock, you only need flashtool with Xperifirm. It's like the first step where you have to download the stock firmware from Xperifirm and flash it with flashtool. Then you only have stock and clean operating system on your device. Unless, I'm not sure what you mean with stock settings?
Sent from my Sony E6553 using XDA Labs
Thanks for the guide. Using this guide, how can i install xposed on prerooted MM.
Shud i flash it after flashing recroot. Or shud i enter the system and then do it.
Following these steps will i lose recovery once i reboot to the system?
worked for me but god i kept soft bricking it. twrp kept wanting to reboot after wiping. now to wait and see if it will charge above 49%
Thank you for your efforts and detailed instructions. I did it smoothly on my 612. In my case the RecRoot was named as RecRootV4_combined.
Oddly, MobileUncle does not restart device to TWRP recovery, although it is doable the hard way
tzitzi2 said:
Thank you for your efforts and detailed instructions. I did it smoothly on my 612. In my case the RecRoot was named as RecRootV4_combined.
Oddly, MobileUncle does not restart device to TWRP recovery, although it is doable the hard way
Click to expand...
Click to collapse
Yes.
SGP612, can not enter TWRP recovery.
Sgp612 enters TWRP just fine, it does not do so thru mobileuncle
tzitzi2 said:
Sgp612 enters TWRP just fine, it does not do so thru mobileuncle
Click to expand...
Click to collapse
steps in details?
just did it with 23.5.A.1.291_R2D. seems ok
thanks!
Thanks for the Guide.
Post #5 is almost as important. It goes through a lot of details and problems I encountered (like the no neede to decrypt or the need to install Java to sign it).
For those who like the shortest path, here's a pre-rooted flashable zip:
Customized IBE Version 23.5.A.0.575 R8D for the SGP621
Decrypt key is:
!8G97O9eDtnF-_PntdsGh8uoRo7KQFpS7_D2c_FNaI-I
(edit) Lost root and I can't figure out why.
One moment I had 5.0.2 rooted with XZDualRecovery the next moment after step 5, I had 6.0.1 but root was lost.
XZDualRecovery is still there. I tried booting into TWRP and re-flashing RecRootV4_combined.zip to no avail. I had already done it according to the instructions right after the pre rooted ROM.
Anyone has an idea of what I could have missed?
For those who like the shortest path said:
Customized IBE Version 23.5.A.0.575 R8D for the SGP621 [/URL]
Click to expand...
Click to collapse
Tnx for pre-rooted rom
Your link need Decryption key.
WanderMax said:
steps in details?
Click to expand...
Click to collapse
Sorry for late answer.
Nothing fancy, just the usual way. Power off, power on, when led is green press volume -. TWRP is there
blue8 said:
Tnx for pre-rooted rom
Your link need Decryption key.
Click to expand...
Click to collapse
Updated on OP. But beware that something isn't probably right. I lost root as soon as I flashed MM.
Thanks for this wonderful guide:good:. I was able to install MM .291 to my SGP612 without any issues. I am attaching a picture of the PRF creator instruction followed if it might help others.
The install process after creating the prf zip file was quick. Also I noticed that I still have small apps after upgrading

Root Xperia Z5 Compact Android 6.01 (Tested and Working)

I rooted my phone following the guide from user "smartphone-tester". I wanted to update his post as there were 1 or 2 mistakes, and shorten in to make rooting seem a little less scary. His original post is here: http://forum.xda-developers.com/z5-compact/general/summary-tutorial-root-sony-xperia-z5-t3360515
STEP 1 Backup your device
Move everything you want to keep onto the SD card or your PC. Your phone will be completely wiped.
STEP 2 Downgrade to exploitable firmware release
2.1 Download XperiFirm from http://forum.xda-developers.com/crossdevice-dev/sony/pc-xperifirm-xperia-firmware-downloader-t2834142
2.2 In XperiFirm - download firmware build 32.0.A.6.200 with XperiaFirm (E5823_StoreFront_1299-6910_32.0.A.6.200_R2B)
2.3 Download flashtool from http://www.flashtool.net/index.php(get latest version)
2.4 In Flashtool - Create FTF file. Select Tools->Bundles->Create
2.5 In FlashTool - Flash the FTF in flashmode. Make sure to select the checkboxes under Wipe. (Takes 10 minutes)
STEP 3 TA / DRM Keys Backup and root current firmware
3.1 Download Ivy Root http://forum.xda-developers.com/crossdevice-dev/sony/iovyroot-temp-root-tool-t3349597
3.2 Connect your phone in ADB mode, in a command window run:
adb push "root/iovyroot" "/data/local/tmp/iovyroot"
adb push "root/backup.sh" "/data/local/tmp/backup.sh"
open shell: adb shell
chmod 777 /data/local/tmp/iovyroot
chmod 777 /data/local/tmp/backup.sh
mkdir /data/local/tmp/tabackup
/data/local/tmp/iovyroot /data/local/tmp/backup.sh
exit
adb pull "/data/local/tmp/tabackup/"
STEP 4 UPGRADE TO LASTEST ANDROID (6.01)
4.1 In XperiFirm - download firmware 32.2.A.6.224 (get the build for your model, mine is E5823_Customized TW_1298-7315_32.2.A.0.224_R9C)
4.2 In Flashtool - create FTF file from E5823_Customized TW_1298-7315_32.2.A.0.224_R9C and flash in flashmode.
4.3 In your phones setting, under develop options - select "Enable OEM Unlock"
4.4 Unlock your bootloader by following these steps excactly :http://developer.sonymobile.com/unlockbootloader/unlock-yourboot-loader/
STEP 5 ROOT ANDROID 6.01
5.1 Download SuperSu 2.74 or greater. Copy the zip file onto your Z5 Compacts internal storage https://download.chainfire.eu/964/SuperSU/BETA-SuperSU-v2.74-2-20160519174328.zip
5.2 In Flashtool -> Tools -> SIN Editor , then extract the kernel from kernel.sin in the directory created by XperiFirm when you downloaded 32.2.A.6.224. It creates an .elf file
5.3 Download rootkernal tool from http://forum.xda-developers.com/xperia-z5/development/root-automatic-repack-stock-kernel-dm-t3301605 extract the zip into a folder, then copy the .elf file into the folder
5.4 In a cmd window go into your extracted rootkernal folder, run the command: rootkernel kernel.elf kernel-patched.elf
5.5 When rootkernel is running, select Disable Sony RIC, install TWRP, install busybox, install DRM fix
5.6 Put your phone into fastboot mode (Turn off phone, hold volume up and plug in USB)
5.7 Flash your patched Kernel to your phone with this command: fastboot flash boot kernel-patched.elf
5.8 Go Into TWRP(unplug usb, turn phone on, then keep hitting volume up until phone goes into TWRP)
5.9 Install SuperSu : Select Install, Select SuperSU zip --> systemless mode
STEP 6
6.1 Restart your Device and your done!
DRM KEYS: While we did make a backup for the TA partition containing the DRM keys, this tutorial did not explain how to restore that because in STEP 5 when patching the kernel we selected to use the DRM Fix. This DRM Fix should be good enough - as everything on my phone is working 100%, but should you ever need to restore your TA partition in the future you have your backup.
nice
you should make a video on how to do this (this is my 1st time rooting and i am completely lost)
I'm an occasional user of all those rooting methods. Here I'm fairly stuck at the Iovyroot step.
I was able to unlock bootload, to flashboot the thing, to even revert to 5.1.1, but then, at the Iovyroot step, I can no long see where to open the cmd. Even when I enter adb devices or android devices, nothing is shown. Although I changed the path in the variables.
I'm getting frustrated big time with the lack of user friendly infos on those tutos. Half of the stuff I had to search for third party tutos to understand how I should go to the next step. Please, help someone who doesn't have his translator on.
EDIT: Well, in the end I couldn't do the backup part, but I just did the rooting and the phone seems all good. Powerful and versatile tool in my pocket, I'm pretty satisfied. Thank you for the tuto, be more user friendly though next time. Some people come here with little knowledge, they need to find their way properly.
Why so many steps when all you have to do is unlock the bootloader, flash twrp and that's it? I rooted on lollipop so I'm confused where it git so complicated.
civicsr2cool said:
Why so many steps when all you have to do is unlock the bootloader, flash twrp and that's it? I rooted on lollipop so I'm confused where it git so complicated.
Click to expand...
Click to collapse
The tutorial covers backing up the TA partition that holds the Sony DRM stuff that's used by the camera (and maybe some other stuff).
This is "just in case" the DRM work around stops working, or if something in the future requires the actual TA partition to have the data there.
If you don't care about anything that is affected by the DRM stuff and don't care that not having a backup could prove to be detrimental in the future, you do only need the few steps of 1) unlock bootloader, 2) flash twrp, 3) flash supersu.
what are those step exactly (sorry new to this)
---------- Post added at 03:47 PM ---------- Previous post was at 03:31 PM ----------
I am stuck on "2.5 In FlashTool - Flash the FTF in flashmode. Make sure to select the checkboxes under Wipe. (Takes 10 minutes)" all i get is a window with source folder, device, branding, version. and I don't see the word wipe at all
greenkabbage said:
The tutorial covers backing up the TA partition that holds the Sony DRM stuff that's used by the camera (and maybe some other stuff).
This is "just in case" the DRM work around stops working, or if something in the future requires the actual TA partition to have the data there.
If you don't care about anything that is affected by the DRM stuff and don't care that not having a backup could prove to be detrimental in the future, you do only need the few steps of 1) unlock bootloader, 2) flash twrp, 3) flash supersu.
Click to expand...
Click to collapse
Gotcha. I see no reason to worry about backing up ta, the fix has been working for nearly 7 months and no reported troubles
ISO_Metric said:
you should make a video on how to do this (this is my 1st time rooting and i am completely lost)
Click to expand...
Click to collapse
If this rooting turortial is too difficult try this: http://forum.xda-developers.com/android/software/debloater-remove-carrier-bloat-t2998294
With this app, you can fully debloat your phone on a completely stock firmware, locked bootloader etc. Because its your phone is not rooted though, you cannot get Xposed framework or CM13, or other advanced stuff - but for those of us who wanted root just to clean up our devices - this method is definitly the best!
1|[email protected]:/ $ /data/local/tmp/iovyroot /data/local/tmp/backup.sh
iovyroot by zxz0O0
poc by idler1984
Error: Device not supported
Someone knows ho to solve this error in step 3.2? Thank you in advance for the help
can I do this tutorial with 32.0.A.6.152 in step 2 and 32.2.A.0.256 in step 5 ?
sheraro said:
can I do this tutorial with 32.0.A.6.152 in step 2 and 32.2.A.0.256 in step 5 ?
Click to expand...
Click to collapse
There is a .256 firmware?
flopower1996 said:
There is a .256 firmware?
Click to expand...
Click to collapse
sorry .253 , I found that iovyroot works only with .200 for E5823 so never mind
Hi all, sorry for the dumb question, but is there any hope for a root without the bootloader unlocked?
gabbodj95 said:
Hi all, sorry for the dumb question, but is there any hope for a root without the bootloader unlocked?
Click to expand...
Click to collapse
No
Thank you
Hi @Dean F , I appreciate your effort to simplify the steps here as it's a bit messy from the original post.
I've been rooting from Xperia Ray to Xperia Z1 but Z5 have been very challenging for me probably due to the lack of understanding from "How to root post" before you actually made this one.
Thank you my friend :good:
Pardon me for being an idiot
Hello Dean F!
Thanks for this tutoial. But before I'll try this, I have two quetions:
1) How do I use your steps WITH restoring the backuped TA-partition?
2) Is the descriped process also usable with a Xperia Z3 Tablet?
Thanks and greetings from GErmany
"klausstoertebeker"
hi,
i cannot download 32.0.A.6.200_R2B from XperiFirm,
"unable to read data from the transport connection: The connection was closed."
i tried like 10 times, and always same i cannot download until done,
are you or member in here know where i can download firmware 32.0.A.6.200_R2B (E5803) for unlock and rooting my phone?
thankyou very much
nb: sorry for my bad english.
bintangsofyan said:
hi,
i cannot download 32.0.A.6.200_R2B from XperiFirm,
"unable to read data from the transport connection: The connection was closed."
i tried like 10 times, and always same i cannot download until done,
are you or member in here know where i can download firmware 32.0.A.6.200_R2B (E5803) for unlock and rooting my phone?
thankyou very much
nb: sorry for my bad english.
Click to expand...
Click to collapse
Hi, you should download the AU Telstra. That's the only working one for that firmware. You can check the firmware of AU Telstra to double confirm if it's the right firmware.
How to root 32.0.A.6.200 please?

Help me to twrp/root/xposed/kernel my XC

Hi,
I'll received my XC this week, and I'd like to root it.
I don't want a custom ROM, but just a stock one with xposed and remove some bloatwares.
Here are my needs:
keep DRM
latest stock rom
twrp
untouched system partition
easy OTA
XC Genesis kernel
xposed + module
Do you think it possible to achieve such a configuration?
How-to?
Thanks
EDIT: I'll update this post to make it an HOW-To for futures users with same questions.
Assuming you're unable to unlock your BL the steps are as follows...
Flash back to 198.
Backup your TA.
Unlock your BL
Update to 311
Extract kernel - ftf/sin/elf
Run elf through Rootkernel_v5.23 - (In cmd prompt window - rootkernel kernel.elf boot.img)
Create DK ftf with Rootkernel_v5.23 (In cmd prompt window - flash_dk TA-19022017.img DK.ftf)
Flash new boot.img
Flash TWRP.img
Flash Super User zip
Flash DK.ftf with Flashtool 9.22
...and that should be it.
Latest stock Rom + xposed will not be possible...
mika91 said:
Hi,
I'll received my XC this week, and I'd like to root it.
I don't want a custom ROM, but just a stock one with xposed and remove some bloatwares.
Here are my needs:
keep DRM
latest stock rom
twrp
untouched system partition
easy OTA
XC Genesis kernel
xposed + module
Do you think it possible to achieve such a configuration?
How-to?
Thanks
EDIT: I'll update this post to make it an HOW-To for futures users with same questions.
Click to expand...
Click to collapse
Forget about OTA when rooted...
I though that using xposed leave the system partition untouched, so OTA updates are possible...
mika91 said:
I though that using xposed leave the system partition untouched, so OTA updates are possible...
Click to expand...
Click to collapse
OTA is not possible once bootloader is unlocked. System partition touched or not played no role.
ok.
So if I want root the XC, I have to unlock the bootloader, loose DRM and ota?
How is the camera quality without the drm keys?
Thanks
mika91 said:
ok.
So if I want root the XC, I have to unlock the bootloader, loose DRM and ota?
Click to expand...
Click to collapse
See my post to get a rooted stock with DRM.
mika91 said:
ok.
So if I want root the XC, I have to unlock the bootloader, loose DRM and ota?
How is the camera quality without the drm keys?
Thanks
Click to expand...
Click to collapse
You HAVE to unlock. There is NO root on LOCKED bootloader.
Unlocking bootloader deletes TA partition, containing DRM keys. You should BACKUP your TA partition BEFORE unlocking using DirtyCow Backup tool from Sony Cross Devices forum.
After unlocking, you can either flash kernel that supports DRM patching either by using fake DRM libraries, or your real DRM keys, either flashed in alternative location (see RootKernel tool in Z5 forums, works on almost all modern Xperias) or PoC TA tool from Sony Cross devices, that mounts your TA backup as TA partition, therefore your phone looks as having DRM keys and locked.
XperienceD said:
Assuming you're unable to unlock your BL the steps are as follows...
Flash back to 198.
Backup your TA.
[*]Unlock your BL
[*]Update to 311
[*]Extract kernel - ftf/sin/elf
[*]Run elf through Rootkernel_v5.23 - (In cmd prompt window - rootkernel kernel.elf boot.img)
[*]Create DK ftf with Rootkernel_v5.23 (In cmd prompt window - flash_dk TA-19022017.img DK.ftf)
[*]Flash new boot.img
[*]Flash TWRP.img
[*]Flash Super User zip
[*]Flash DK.ftf with Flashtool 9.22
...and that should be it.
Click to expand...
Click to collapse
Would you mind detailing a bit more those steps, especially the first 2? Im coming from a really old phone so im still a bit lost. (where can i learn about ftf/sin/elf?)
How can we flash back to 198? Flashing doesnt require an unlocked BL, wich to be achieved deletes your TA?
im on a brand new X Compact, 7.0 (34.2.A.0.292), secure patch 01/01/17
managed to get flashtool, adb/fastboot and Universal TA Backup v2 on my pc but no dice on TA backup yet
fredsky2 said:
Would you mind detailing a bit more those steps, especially the first 2? Im coming from a really old phone so im still a bit lost. (where can i learn about ftf/sin/elf?)
Click to expand...
Click to collapse
Sure. You don't really need to learn about those stuff but is handy to know, you'll pick stuff up along the way. They are basically firmware files.
fredsky2 said:
How can we flash back to 198? Flashing doesnt require an unlocked BL, wich to be achieved deletes your TA?
Click to expand...
Click to collapse
Open the flashtool and run Xperifirm (icon with XI) on it, then browse to the XC, then click on F5321 and it will load up the different regions and available firmware. If you click on "check all" it will then show which FW is available to download, Central Europe 5 still shows as 198, so you need to select it on the right of the screen under the picture of the phone, it will then download and it's simply a matter of following the instructions to flash it.
fredsky2 said:
im on a brand new X Compact, 7.0 (34.2.A.0.292), secure patch 01/01/17
managed to get flashtool, adb/fastboot and Universal TA Backup v2 on my pc but no dice on TA backup yet
Click to expand...
Click to collapse
When you get 198 on your phone then you'll be able to back your TA. If you get stuck give us a shout.
XperienceD said:
Sure. You don't really need to learn about those stuff but is handy to know, you'll pick stuff up along the way. They are basically firmware files.
Open the flashtool and run Xperifirm (icon with XI) on it, then browse to the XC, then click on F5321 and it will load up the different regions and available firmware. If you click on "check all" it will then show which FW is available to download, Central Europe 5 still shows as 198, so you need to select it on the right of the screen under the picture of the phone, it will then download and it's simply a matter of following the instructions to flash it.
When you get 198 on your phone then you'll be able to back your TA. If you get stuck give us a shout.
Click to expand...
Click to collapse
Thank you, i was able to successfully backup my TA earlier yesterday. But now im struggling with how to restore it in MM 6.0.1 (34.1.A.1.198).
I've read that i'll need a custom kernel for that (and to get TWRP+supersu+magisk+xposed) but im unsure if i should use Genesis (probably unsuported but the only one that says it'll restore MY TA) or Advanced Stock Kernel from Androplus. Ive read that messing with TA can hardbrick my phone so im trying to be extra careful.
atm im following ondrejvaroscak's quickrecap to make sure everything goes smooth with my TA keys and then i plan to downgrade to 6.0, install Advanced Stock Kernel, supersu 2.79 and magisk and then pray for the best (without reflashing my own DK.ftf?)
fredsky2 said:
Thank you, i was able to successfully backup my TA earlier yesterday. But now im struggling with how to restore it in MM 6.0.1 (34.1.A.1.198).
Click to expand...
Click to collapse
Download Flashtool 9.22.3 and flash your DK.ftf, flashing with a newer version doesn't work, you should then be able to verify it's worked in the service menu.
fredsky2 said:
I've read that i'll need a custom kernel for that (and to get TWRP+supersu+magisk+xposed) but im unsure if i should use Genesis (probably unsuported but the only one that says it'll restore MY TA) or Advanced Stock Kernel from Androplus. Ive read that messing with TA can hardbrick my phone so im trying to be extra careful.
Click to expand...
Click to collapse
You can use the RootKernel tool to modify your own kernel, extract the kernel.sin from the ftf with a zip program, then use the flashtool to extract the kernel.elf, Tools-Sin Editor-Extract Data then run it through the RootKernel tool and flash the boot.img it creates, then flash TWRP separately to the recovery partition which will allow you then to flash SuperSU.
SuperSU and BusyBox are the only options I didn't include when creating my kernel. Others will have to help with the other two things you want as I refuse to use them.
XperienceD said:
Download Flashtool 9.22.3 and flash your DK.ftf, flashing with a newer version doesn't work, you should then be able to verify it's worked in the service menu.
You can use the RootKernel tool to modify your own kernel, extract the kernel.sin from the ftf with a zip program, then use the flashtool to extract the kernel.elf, Tools-Sin Editor-Extract Data then run it through the RootKernel tool and flash the boot.img it creates, then flash TWRP separately to the recovery partition which will allow you then to flash SuperSU.
SuperSU and BusyBox are the only options I didn't include when creating my kernel. Others will have to help with the other two things you want as I refuse to use them.
Click to expand...
Click to collapse
Thanks again. I was worried that the drm-fix from the kernel editing tool could corrupt my TA partition but thankfully i was wrong on that .
Im now at MM 6.0, original DRM keys, TWRP, xposed, rooted with magisk and im almost sure that with busybox. Why do you refuse to use them? Just curious!
Thanks a lot for your help, cheers
fredsky2 said:
Thanks again. I was worried that the drm-fix from the kernel editing tool could corrupt my TA partition but thankfully i was wrong on that .
Click to expand...
Click to collapse
I flashed a kernel I made with the Rootkernel tool without the drm fix but it showed some mumbo jumbo where it should say ok and provisioned, included the drm fix in the next one and it worked fine then.
fredsky2 said:
Im now at MM 6.0, original DRM keys, TWRP, xposed, rooted with magisk and im almost sure that with busybox. Why do you refuse to use them? Just curious!
Thanks a lot for your help, cheers
Click to expand...
Click to collapse
You're welcome. I refuse because I prefer to know how to mod apks directly and I found Xposed to be quite buggy. I can see the benefits, it's just not for me.

Categories

Resources