The client now lives at github.com/grmrgecko/qcdm-efs2; note it in the skill so the local copy is clearly the mirror. Claude-Session: https://claude.ai/code/session_01Ctisr9uXe4H8XsscZ2exGE
6.8 KiB
| name | description |
|---|---|
| xperia-firmware-upgrade | Upgrade Sony Xperia 1 VI (XQ-EC72) firmware with newflasher without wiping data, keeping Magisk root. Use when asked to flash, upgrade, or update Xperia firmware downloaded with XperiFirm. |
Xperia firmware upgrade (keep data + Magisk root)
Device: Sony Xperia 1 VI, model XQ-EC72, region Customized SEA.
Firmware lives in /home/grmrgecko/Downloads/XperiFirm 5.8.1 (by Igor Eisberg)/ in folders named XQ-EC72_Customized_SEA_<version>.
Tools: ~/bin/newflasher (v57), ~/bin/unsin, fastboot.
1. Download firmware
XperiFirm (Windows .exe in the folder above, runs under Wine/mono) downloads the
firmware into a new XQ-EC72_Customized_SEA_<version> folder. Never downgrade —
the bootloader enforces anti-rollback (see securitypatchlevel.dat).
2. Patch init_boot with Magisk
Inside the new firmware folder:
mkdir init_boot_X-FLASH-ALL-88DF
cd init_boot_X-FLASH-ALL-88DF
unsin ../init_boot_X-FLASH-ALL-88DF.sin # produces init_boot.img
Copy init_boot.img to the phone, patch it in the Magisk app
("Install" → "Select and Patch a File"), and copy the resulting
magisk_patched-<ver>_<rand>.img back into this same directory.
3. Prepare the flash copy
newflasher flashes every .sin/.ta in its working directory, so work on a
copy with the dangerous bits removed. From the XperiFirm folder:
cp -r --reflink=auto "XQ-EC72_Customized_SEA_<version>" "XQ-EC72_Customized_SEA_<version> copy"
cd "XQ-EC72_Customized_SEA_<version> copy"
rm persist_X-FLASH-ALL-88DF.sin
cp -r "../XQ-EC72_Customized_SEA_<previous-version> copy/tadump" .
- Remove
persist_X-FLASH-ALL-88DF.sin— persist holds per-device calibration/DRM data; flashing it overwrites yours. This is the only file removed. userdata_X-FLASH-ALL-88DF.sinstays. Data is preserved by answering the "keep userdata?" prompt, not by deleting the file.- Carry the
tadump/folder forward from the previous version's copy. It accumulates trim-area dumps (tadump_N.ta, numbered upward) — hard-brick insurance. newflasher appends a new dump to it each flash.
Verify the prep by diffing against the previous prepared copy: the only
differences from a fresh download should be persist*.sin gone, the
init_boot_X-FLASH-ALL-88DF/ workspace dir, and tadump/.
4. Flash with newflasher
Power the phone off, then hold Volume-Down while plugging in USB —
green LED = flashmode (lsusb shows a 0fce: Sony device).
cd "XQ-EC72_Customized_SEA_<version> copy"
~/bin/newflasher
Prompt answers, in order:
| Prompt | Answer |
|---|---|
| "…if you understand the risk" | y |
| "dump trim area" (optional) | y — saves into tadump/ |
| "Do you want to keep userdata?" | y — this is the no-wipe step |
| "Reboot mode at the end of flashing" | f — go straight to fastboot for re-rooting |
Non-interactive equivalent: printf 'y\ny\ny\nf\n' | ~/bin/newflasher
5. Re-flash Magisk root
The flash wrote the stock init_boot, so root must be restored. With the phone
in fastboot (blue LED — it's already there if you answered f; otherwise hold
Volume-Up while plugging in USB from power-off):
fastboot flash init_boot init_boot_X-FLASH-ALL-88DF/magisk_patched-*.img
fastboot reboot
First boot after an upgrade takes a while. Open Magisk afterward to confirm root survived.
6. Re-enable US 5G (SEA firmware in the US)
Flashing includes modemst1/modemst2 .sin files, which reset the modem
EFS — any modem-side band/5G configuration is lost on every upgrade and must
be redone.
-
Old quick trick (worked through 69.2.A.4.16): dial
*#*#4636#*#*→ Phone Information → toggle "Enable DSDS" off, re-enable, reboot (some users must leave DSDS off). May only force the 5G icon rather than real NR. -
Current method: replace three RF-band policy files in the modem EFS
/policymanfolder with the versions from XDA thread 4753150 ("Enable 5G & Global RF Bands on Xperia", by htcmage) —band_set_01.xml,plmn_mcc_supported_01.xml,policies.xml(adds T-Mobile / Verizon / AT&T / Dish LTE+NR bands). The guide uses Windows QPST EFS Explorer; the Linux path below is what actually worked here and needs no Windows.Working Linux / adb procedure (done 2026-08-27, verified):
- Download the 3 attachments from the thread (Chrome navigates directly to
each
xdaforums.com/attachments/...URL — script-triggered downloads are blocked; a real navigation downloads fine). Validate each is well-formed XML with root<policy>/<policy_list>andschema_ver="1"matching the device's existing files. - Open the Qualcomm diag port:
adb shell su -c 'setprop sys.usb.config diag,serial_cdev,rmnet,adb'. Phone re-enumerates as USB05c6:9091(adb survives). Bind the serial driver (needs root on the PC):sudo modprobe option && echo 05c6 9091 | sudo tee /sys/bus/usb-serial/drivers/option1/new_id. The diag channel is USB interface 0, stable as/dev/serial/by-id/usb-Sony_XQ-EC72_*-if00-port0(maps to a ttyUSB whose number is not stable). efs2.py auto-detects it by probing each port with a DIAG version request; setDIAGPORTto override. - Talk EFS2 over DIAG. EfsTools (JohnBel) is the usual tool but its
libnserial hits EIO on the option-driver port; the reliable path was a
small pyserial EFS2 client (HDLC + FCS-16, subsys 0x4B/EFS 19). Script is
5g-policyman/efs2.pyhere; canonical copy is https://github.com/grmrgecko/qcdm-efs2 . A CLI withls,stat,pull,push(writes then reads back to verify) andbackup(recursive):python3 efs2.py backup /policyman ./policyman-backup(always first)python3 efs2.py push band_set_01.xml /policyman/band_set_01.xml(and the same for plmn_mcc_supported_01.xml and policies.xml)pushdeletes then re-creates (O_WRONLY|O_CREATperm 0777, 1 KB chunks) and confirms the read-back matches.
adb reboot. Reboot clears diag mode back to normal adb.- Verify:
dumpsys telephony.registry | grep isNrAvailable→true(stock SEA firmware shows false);settings get global preferred_network_modeshould be an NR mode (26 = NR_LTE_GSM_WCDMA).
Backups of the device's original
/policymanfiles:~/.../scratchpad/policyman_backup/. Invalid XML can stop the modem from booting — restore by writing the backups back, or reflash the modem.sinfiles with newflasher. - Download the 3 attachments from the thread (Chrome navigates directly to
each
-
Hardware limit: band n71 does not work on the 1 VI; T-Mobile users see LTE 2/12/66 and NR n41; n66 confirmed on Verizon.
7. Cleanup
Keep both the original and the " copy" folder for at least one more upgrade —
the copy is the reference for preparing the next version, and tadump/ is
carried forward from it. Older versions than the previous one can be deleted.