1.
Disassembly unit and look for UFS153
2. Read partitions
For this procedure I am using EasyJTAG Plus 2 app with Easy JTAG Plus Tool + UFS153 adapter.
It is always a good idea to have a FULL BACKUP of your UFS, but we actually need only 4 partitions, which are
checked on photo below.
3. Write modified partitions
Write these engineering partitions from Access/Partitions/M**3/ folder to UFS
boot_a – From partitions folder
boot_b - From partitions folder
hyp_a - From partitions folder
initramfsdom0_a - From partitions folder
systemdom0_a – DM Verity OFF + PUBLIC KEY
system2dom0_a - DM Verity OFF
initramfsdomu1_a – From partitions folder
systemdomu1_a - DM Verity OFF + PUBLIC KEY
system2domu1_a - DM Verity OFF
hyp_b - From partitions folder
initramfsdom0_b - From partitions folder
systemdom0_b – Write systemdom0_a file here.
system2dom0_b – Write system2dom0_a file here.
initramfsdomu1_b - From partitions folder
systemdomu1_b – Write systemdomu1_a file here.
system2domu1_b – Write system2domu1_a file here.
NOTE! It is enough to patch only _a file and write same file to two partitions, because _a = _b, you can compare
them by yourself.
Disable DM Verity on: system2dom0_a & system2dom0_b:
Disable DM Verity on: system2domu1_a & system2domu1_b:
Disable DM Verity on: systemdom0_a & systemdom0_b and start SSHD service (OLD METHOD, NEW IS TO CHANGE
PUBLIC KEY AND USE CHALLENGE GENERATOR ! SKIP THIS, DISABLE ONLY VERITY AND READ BELOW !!):
Search for “using the shell-function and not run directly”, and remove 14 bytes which are selected below
(65206120636C65616E20656E762E)
We need to insert 14 bytes between [Link].} two dots
Type manually or paste “/usr/sbin/sshd” (2F7573722F7362696E2F73736864)
Disable DM Verity on: systemdomu1_a & systemdomu1_b and start SSHD service (OLD METHOD, NEW IS TO
CHANGE PUBLIC KEY AND USE CHALLENGE GENERATOR ! SKIP THIS, DISABLE ONLY VERITY AND READ BELOW !!):
Search for “using the shell-function and not run directly”, and remove 14 bytes which are selected below
(65206120636C65616E20656E762E)
We need to insert 14 bytes between [Link].} two dots
Type manually or paste “/usr/sbin/sshd” (2F7573722F7362696E2F73736864)
Write all these (16) partitions to UFS, and solder UFS back.
More obvious example on DM Verity OFF procedure:
New method: change PUBLIC KEY of [Link] instead of starting sshd service!
Find in systemdom0_a, systemdom0_b, systemdomu1_a & systemdomu1_b following string:
MIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEAoil72WSgtizzmxgtkTcW
And change to key from Access/Challenge/[Link]
How EasyJtag window should look like while writing:
4. Connect to SSH
Connection to unit can be done via D-Link DUB-E100. You need to change IPv4 address and mask to same as Harman
uses.
You can connect to terminal by using PuTTy
MPR/MHI3 – IVI – Challenge Telnet: [Link]:22111
MPR/MHI3 – IVI – SSH SSH: [Link]:22
MPR/MHI3 – SYS – Challenge Telnet: [Link]:22121
MPR/MHI3 – SYS – SSH SSH: [Link]:2222
Open challenge telnet (SYS/IVI) depends which you need, and copy challenge key:
Paste key to Access/Challenge/[Link] and copy response:
Paste response back to challenge telnet and press enter:
Now you started SSH server, and can login with SSH.
Or if you want to copy files directly to your PC, then you can use WinSCP
List of supported & known FEC codes
00000700 Logging
00030000 AMI (USB Enable)
00040100 Navigation
00050000 Bluetooth
00050100
00060100 Vehicle Data Interface
00060200 Infortainment Control
00060300 MirrorLink
00060400 SportHMI
00060500 Porsche SportChrono
00060600 Porsche Logbook
00060700 Porsche Mobile Online Dienste
00060800 Apple Carplay
00060900 Google Android Auto
00060A00 Porsche RaceApp
00060B00 Baidu CarLife
00060F00 DAB Full
00070100 SDS for Non-Nav units
00070200 SDS for Nav unis
00070F00
02A000F0 AUDI European maps
Patching FEC
Extract fecmanager from SYS /usr/bin/fecmanager, and patch in HEX (Or use previously prepatched file):
Find: 810A45F9E003152AA257
Replace with: 810A45F920 00 80 52A257
SWAP Code example:
12020004010003708A17C14546464646464646464646464646464646460062FCA21E0000000000000000003E5E9
54E369CB75D660F7F8FE692228CE8D040A311BE5C145B320703ABECC6929600C373C84996FE83633E732C21CAD
C9180F34F612681BAE2BF855926B226958271C3A5B76187232D6D937743BFEF752D743C6C3FFE248EB527665CBF
BE8BF71485DC3A2C806C8D59230A07F118EC3452F238FFC115B68AFB9F917A7815A56D7CFB1B5B8646EB78B1F3
0641FD9E2F93492A5914837F1977D9F33B13528C873225DDAA50CC6ED83A102E43B38A1B1F8CE3297FE9029FE5
2FA01FFA7E49EFA51F8370CC50541DB03AA3436BD2D3CC0EDAA9F176B0DA8C6F67BDBF0002D8737E581EA1022
A4179B34D4B3C52C2139D25AF7C5C6E5D929D9212CAA8A89E3BFD44AF270D80A3E692ED05B6FC6AC92BFBCA0
10F3D9006697484E62F3F5691E7B93E0AD14A328D0CE2A1F9B6364C0AD2DE27BCBF7C85F4CDB918D2875A2DCC
DC6CD6D7A10F1F054012BDB1BA5A9FA7E0358C4F1AAA349E75B1FA26B946F784CEA39702596BE58922ACF0FC2
EAD50E3F5F80900C60A9331A9BA1861F1A5B0F0BC34D7B5
Red – Version in HEX (18)
Blue – Activation code (00040100)
Green – VIN in HEX (FFFFFFFFFFFFFFFFF)
Violet – Timestamp in HEX (17-08-2022 08:09:02)
Or you can put FEC/[Link] to SYS /var/persist/fec/[Link]
Change FOD to SWaP
5F > Adaptations
Find function_configuration_swap_fod
Change enable_swap_fod to swap_active_fod_not_active
Start!
Region conversion
Write updatemanager from Conversion/updatemanager/M**3 to IVI: /sbin/updatemanager, after this open IVI
terminal and run these commands:
sync
mkdir /var/persist/swup/flags
touch /var/persist/swup/flags/skipCheckInstallerChecksum
touch /var/persist/swup/flags/skipCheckVariant
touch /var/persist/swup/flags/skipCheckMetaChecksum
touch /var/persist/swup/flags/skipCheckManifestChecksum
touch /var/persist/swup/flags/allowUserDefinedUpdate
sync
Reboot your unit.
Go to SWUP (Engineering, RED) menu by holding two fingers in top right corner.
Extract patched firmware to SD card (USB) from Firmwares/Prepatched/*
Click Update
Select your firmware from SD/USB
+ User-defined > None
And then modify these parts of update manually and set them to All:
o MMX3 > All
o MMX3_POSTCRIPT > All
o SpeechApp > All
o HmiRes > All
o SpeechResources-EUROW-AU > All
o esohwr > All
Start update
After update finished, click + Resume. (YOU WILL HAVE 2X NOK, IT IS NORMAL)
After you press + Resume, unit will boot into normal mode. Hold two fingers in top right corner to open SWUP
(RED) menu again.
Once you are in RED menu, press Update > Select Firmware (Same firmware as you used before) > + User
Defined > None > And check ONLY OpenSourceDisclaimer* (MLE, ML2, MQA, MQ2) > All
+ Start update
After OpenSourceDisclaimer update finished, boot into normal mode.
Login with SSH to IVI and execute next commands:
mkdir /var/persist/[Link]
mv /var/persist/swup/* /var/persist/[Link]/
mkdir /var/persist/swup/flags
touch /var/persist/swup/flags/skipCheckVariant
sync
Use VCP/ODIS to clear navigation storage.
Extract latest maps to SD/USB and do update from settings menu, or you can install maps from RED menu also.
Maps update from RED menu takes ~40-45 min.
NOTE: If you can’t start update due to error below, please change your power supply to more powerful one, or
increase voltage to 14-15 V.
– OR – Go to NORMAL mode, and back again to RED mode.
After maps successfully installed, we need to make region changes in adaptation channels given below:
Install Gracenote
Copy gracenotedb folder by simply drag & drop from desktop to IVI: /var/appdata/media/, login to IVI SSH, and
execute sync command few times to save changes.
sync
sync
Fix DTC: Control module Software incompatible (Control Unit Faulty)
NOTE, IF YOU ARE DOING US > EU CONVERSION, YOU ALREADY RAN THESE COMMANDS AND YOU SHOULD SKIP
EXECUTING THEM NOW.
Login with SSH to IVI and execute next commands:
mkdir /var/persist/[Link]
mv /var/persist/swup/* /var/persist/[Link]/
sync
Fix DTC: Check Softwate Version Management (SVM)
1. 5F > Adaptions > Confirmation of installation change
2. Open calc > Programmer mode > Type HEX value from „Stored value“
3. Change Bitwise to XOR, enter C9D2
4. Enter result into „New value“ value > Apply.
5. Clear fault codes.
Other commands:
Reboot unit (SYS SSH):
echo sys-reset > /tmp/ooc-debug
Fast unit reboot (SYS SSH):
echo fast-sys-reset > /tmp/ooc-debug
Reboot unit from NORMAL into SWUP mode (SYS SSH):
echo swup-start > /tmp/ooc-debug
echo swup-reset > /tmp/ooc-debug
Reboot unit from SWUP to NORMAL mode (SYS SSH):
echo swup-stop > /tmp/ooc-debug
echo swup-reset > /tmp/ooc-debug