skills/xperia-firmware-upgrade/SKILL.md
James Coleman 2ac55231d1 Point efs2.py to its canonical github repo
The client now lives at github.com/grmrgecko/qcdm-efs2; note it in the
skill so the local copy is clearly the mirror.

Claude-Session: https://claude.ai/code/session_01Ctisr9uXe4H8XsscZ2exGE
2026-08-27 16:36:22 -05:00

6.8 KiB

name description
xperia-firmware-upgrade Upgrade Sony Xperia 1 VI (XQ-EC72) firmware with newflasher without wiping data, keeping Magisk root. Use when asked to flash, upgrade, or update Xperia firmware downloaded with XperiFirm.

Xperia firmware upgrade (keep data + Magisk root)

Device: Sony Xperia 1 VI, model XQ-EC72, region Customized SEA. Firmware lives in /home/grmrgecko/Downloads/XperiFirm 5.8.1 (by Igor Eisberg)/ in folders named XQ-EC72_Customized_SEA_<version>. Tools: ~/bin/newflasher (v57), ~/bin/unsin, fastboot.

1. Download firmware

XperiFirm (Windows .exe in the folder above, runs under Wine/mono) downloads the firmware into a new XQ-EC72_Customized_SEA_<version> folder. Never downgrade — the bootloader enforces anti-rollback (see securitypatchlevel.dat).

2. Patch init_boot with Magisk

Inside the new firmware folder:

mkdir init_boot_X-FLASH-ALL-88DF
cd init_boot_X-FLASH-ALL-88DF
unsin ../init_boot_X-FLASH-ALL-88DF.sin   # produces init_boot.img

Copy init_boot.img to the phone, patch it in the Magisk app ("Install" → "Select and Patch a File"), and copy the resulting magisk_patched-<ver>_<rand>.img back into this same directory.

3. Prepare the flash copy

newflasher flashes every .sin/.ta in its working directory, so work on a copy with the dangerous bits removed. From the XperiFirm folder:

cp -r --reflink=auto "XQ-EC72_Customized_SEA_<version>" "XQ-EC72_Customized_SEA_<version> copy"
cd "XQ-EC72_Customized_SEA_<version> copy"
rm persist_X-FLASH-ALL-88DF.sin
cp -r "../XQ-EC72_Customized_SEA_<previous-version> copy/tadump" .
  • Remove persist_X-FLASH-ALL-88DF.sin — persist holds per-device calibration/DRM data; flashing it overwrites yours. This is the only file removed.
  • userdata_X-FLASH-ALL-88DF.sin stays. Data is preserved by answering the "keep userdata?" prompt, not by deleting the file.
  • Carry the tadump/ folder forward from the previous version's copy. It accumulates trim-area dumps (tadump_N.ta, numbered upward) — hard-brick insurance. newflasher appends a new dump to it each flash.

Verify the prep by diffing against the previous prepared copy: the only differences from a fresh download should be persist*.sin gone, the init_boot_X-FLASH-ALL-88DF/ workspace dir, and tadump/.

4. Flash with newflasher

Power the phone off, then hold Volume-Down while plugging in USB — green LED = flashmode (lsusb shows a 0fce: Sony device).

cd "XQ-EC72_Customized_SEA_<version> copy"
~/bin/newflasher

Prompt answers, in order:

Prompt Answer
"…if you understand the risk" y
"dump trim area" (optional) y — saves into tadump/
"Do you want to keep userdata?" y — this is the no-wipe step
"Reboot mode at the end of flashing" f — go straight to fastboot for re-rooting

Non-interactive equivalent: printf 'y\ny\ny\nf\n' | ~/bin/newflasher

5. Re-flash Magisk root

The flash wrote the stock init_boot, so root must be restored. With the phone in fastboot (blue LED — it's already there if you answered f; otherwise hold Volume-Up while plugging in USB from power-off):

fastboot flash init_boot init_boot_X-FLASH-ALL-88DF/magisk_patched-*.img
fastboot reboot

First boot after an upgrade takes a while. Open Magisk afterward to confirm root survived.

6. Re-enable US 5G (SEA firmware in the US)

Flashing includes modemst1/modemst2 .sin files, which reset the modem EFS — any modem-side band/5G configuration is lost on every upgrade and must be redone.

  • Old quick trick (worked through 69.2.A.4.16): dial *#*#4636#*#* → Phone Information → toggle "Enable DSDS" off, re-enable, reboot (some users must leave DSDS off). May only force the 5G icon rather than real NR.

  • Current method: replace three RF-band policy files in the modem EFS /policyman folder with the versions from XDA thread 4753150 ("Enable 5G & Global RF Bands on Xperia", by htcmage) — band_set_01.xml, plmn_mcc_supported_01.xml, policies.xml (adds T-Mobile / Verizon / AT&T / Dish LTE+NR bands). The guide uses Windows QPST EFS Explorer; the Linux path below is what actually worked here and needs no Windows.

    Working Linux / adb procedure (done 2026-08-27, verified):

    1. Download the 3 attachments from the thread (Chrome navigates directly to each xdaforums.com/attachments/... URL — script-triggered downloads are blocked; a real navigation downloads fine). Validate each is well-formed XML with root <policy> / <policy_list> and schema_ver="1" matching the device's existing files.
    2. Open the Qualcomm diag port: adb shell su -c 'setprop sys.usb.config diag,serial_cdev,rmnet,adb'. Phone re-enumerates as USB 05c6:9091 (adb survives). Bind the serial driver (needs root on the PC): sudo modprobe option && echo 05c6 9091 | sudo tee /sys/bus/usb-serial/drivers/option1/new_id. The diag channel is USB interface 0, stable as /dev/serial/by-id/usb-Sony_XQ-EC72_*-if00-port0 (maps to a ttyUSB whose number is not stable). efs2.py auto-detects it by probing each port with a DIAG version request; set DIAGPORT to override.
    3. Talk EFS2 over DIAG. EfsTools (JohnBel) is the usual tool but its libnserial hits EIO on the option-driver port; the reliable path was a small pyserial EFS2 client (HDLC + FCS-16, subsys 0x4B/EFS 19). Script is 5g-policyman/efs2.py here; canonical copy is https://github.com/grmrgecko/qcdm-efs2 . A CLI with ls, stat, pull, push (writes then reads back to verify) and backup (recursive):
      • python3 efs2.py backup /policyman ./policyman-backup (always first)
      • python3 efs2.py push band_set_01.xml /policyman/band_set_01.xml (and the same for plmn_mcc_supported_01.xml and policies.xml) push deletes then re-creates (O_WRONLY|O_CREAT perm 0777, 1 KB chunks) and confirms the read-back matches.
    4. adb reboot. Reboot clears diag mode back to normal adb.
    5. Verify: dumpsys telephony.registry | grep isNrAvailabletrue (stock SEA firmware shows false); settings get global preferred_network_mode should be an NR mode (26 = NR_LTE_GSM_WCDMA).

    Backups of the device's original /policyman files: ~/.../scratchpad/policyman_backup/. Invalid XML can stop the modem from booting — restore by writing the backups back, or reflash the modem .sin files with newflasher.

  • Hardware limit: band n71 does not work on the 1 VI; T-Mobile users see LTE 2/12/66 and NR n41; n66 confirmed on Verizon.

7. Cleanup

Keep both the original and the " copy" folder for at least one more upgrade — the copy is the reference for preparing the next version, and tadump/ is carried forward from it. Older versions than the previous one can be deleted.