Unbrick Lenovo Z90-7 (VIBE SHOT)

Problem SOLVED.
After a short research I have:
1. unplugged battery, and connected mainboard to PC with USB cable,
2. Short for few secs. GREEN jumper called HS_9008 (CPU powered without FLASH IC),
3. Using MiFlash started flashing S118 STOCK ROM (brake point after loading image into RAM),
4. Enabled 9006 mode using YELLOW jumper (init of PSU driver start and power up rest of HW)
5. Again started flashing the same ROM with MiFlash (previous attemp timed out – it’s ok)
6. Unplugged USB cable, connected battery, and watching UART’s output (115200,8,N,1).

Quote:

Format: Log Type – Time(microsec) – Message – Optional Info
Log Type: B – Since Boot(Power On Reset), D – Delta, S – Statistic
S – QC_IMAGE_VERSION_STRING=BOOT.BF.3.0.C8-00006
S – IMAGE_VARIANT_STRING=SAAAANAAA
S – OEM_IMAGE_VERSION_STRING=nj-bs6
S – Boot Config, 0x000000e1
S – Core 0 Frequency, 0 MHz
B – 1587 – PBL, Start
B – 3619 – bootable_media_detect_entry, Start
B – 126484 – bootable_media_detect_success, Start
B – 126490 – elf_loader_entry, Start
B – 127507 – auth_hash_seg_entry, Start
B – 127746 – auth_hash_seg_exit, Start
B – 146537 – elf_segs_hash_verify_entry, Start
B – 227142 – PBL, End
B – 233111 – SBL1, Start
B – 296551 – pm_device_init, Start
B – 296673 – row samsung 3+32 detected
B – 300730 – row_pm_ddr_ncp_buck_set_voltage
D – 14731 – pm_device_init, Delta
B – 319548 – boot_flash_init, Start
D – 30 – boot_flash_init, Delta
B – 323574 – boot_config_data_table_init, Start
D – 12261 – boot_config_data_table_init, Delta – (0 Bytes)
B – 340380 – CDT version:3,Platform ID:8,Major ID:0,Minor ID:0,Subtype:1
B – 346175 – sbl1_ddr_set_params, Start
B – 350841 – cpr_init, Start
D – 4392 – cpr_init, Delta
B – 357307 – Pre_DDR_clock_init, Start
D – 244 – Pre_DDR_clock_init, Delta
D – 0 – sbl1_ddr_set_params, Delta
B – 368958 – pm_driver_init, Start
D – 6801 – pm_driver_init, Delta
B – 385489 – clock_init, Start
D – 122 – clock_init, Delta
B – 395707 – Image Load, Start
D – 21136 – QSEE Image Loaded, Delta – (483616 Bytes)
B – 416874 – Image Load, Start
D – 427 – SEC Image Loaded, Delta – (2048 Bytes)
B – 424011 – sbl1_efs_handle_cookies, Start
D – 396 – sbl1_efs_handle_cookies, Delta
B – 431849 – Image Load, Start
D – 11804 – QHEE Image Loaded, Delta – (68336 Bytes)
B – 443683 – Image Load, Start
D – 12780 – RPM Image Loaded, Delta – (154860 Bytes)
B – 456493 – Image Load, Start
D – 20008 – APPSBL Image Loaded, Delta – (483532 Bytes)
B – 476593 – QSEE Execution, Start
D – 61 – QSEE Execution, Delta
B – 482296 – SBL1, End
D – 251473 – SBL1, Delta
S – Flash Throughput, 104000 KB/s (1195708 Bytes, 11407 us)
S – DDR Frequency, 796 MHz
Android Bootloader – UART_DM Initialized!!!
check_lcd_id status_up = 0,status_down = 0
MSENSOR_i2c_read addr 0x1 data0x5
[1460] QUP: I2C status flags :0xc1343c8
[1460] QUP: I2C status flags :0xc1343c8
[1470] QUP: I2C status flags :0xc1343c8
[1470] QUP: I2C status flags :0xc1343c8
max77819_i2c_read addr 0x18 max77819_i2c_read data 0x8c
max77819_i2c_read addr 0xe max77819_i2c_read data 0xc2
max77819_i2c_read addr 0x2 max77819_i2c_read data 0xc3
[1700] battery voltage is 3900 ocv is 3880,therhold is 1000
max77819_i2c_read addr 0x34 max77819_i2c_read data 0x62
[1710] charging status = 0x62
max77819_i2c_read addr 0x37 max77819_i2c_read data 0x5c
[1720] current 0x37 register = 0x5c
max77819_i2c_read addr 0x34 max77819_i2c_read data 0x62
[1730] charging status = 0x62
max77819_i2c_read addr 0x2 max77819_i2c_read data 0xc3
[1730] battery voltage is 3900 mv
max77819_i2c_read addr 0x40 max77819_i2c_read data 0x80
[1740] charger 0x40 = 0x80
max77819_i2c_read addr 0x34 max77819_i2c_read data 0x62
max77819_i2c_read addr 0x99 max77819_i2c_read data 0xef
max77819_i2c_read addr 0x98 max77819_i2c_read data 0xf2
max77819_i2c_read addr 0x9b max77819_i2c_read data 0x80
max77819_i2c_read addr 0x99 max77819_i2c_read data 0x0
max77819_i2c_read addr 0x98 max77819_i2c_read data 0xf2
[1780] Not able to search the panel:

panel_id = OTM1902C_1080P_CMD_PANEL
max77819_i2c_read addr 0x9b max77819_i2c_read data 0x80
[2370] KEY_VOLUMEDOWN pressed
[2740] image_decrypt_signature2
[5610] fdt end:0x21e308be rkm shadow buf base:0x21e31000 lk ptr:0x21e32000 log_buf ptr:0x21e34000
[5620] rkm_init_lk_log_buf: current_lk_log_addr=0x8f6687c4, len=0x4096
[5750] rkm find kernel log buf header at 0x21189000
[5760] rkm backup kernel log buf from 0x2120e6c0 to 0x21e34000,len=524288
[6050] rkm_log:lk buf size=4096, kernel buf size=524288
–Uart Ready–
NO SN, Please write

Credit goes to sunblade

Leave a Comment

Your email address will not be published. Required fields are marked *