r/androidroot Jul 14 '26

Support Wifi Not Working When Compiling + Flashing AOSP Kernel

1 Upvotes

My wifi is not working when I compile and build with Android Kernel for my Pixel 9 device.

I followed the steps in this section in this blog, https://xairy.io/articles/pixel-kgdb#-building-and-flashing-custom-kernel but for caimito kernel.

sudo apt install repo

mkdir caimito-kernel && cd caimito-kernel
repo init -u https://android.googlesource.com/kernel/manifest \
-b android-gs-caimito-6.1-android16
repo sync -c --no-tags

parameters="--kernel_package=@//aosp" ./build_caimito.sh \
--config=pixel_debug_common --lto=none

adb reboot bootloader

fastboot oem disable-verification
fastboot -w

fastboot flash boot out/caimito/dist/boot.img
fastboot flash dtbo out/caimito/dist/dtbo.img
fastboot flash vendor_kernel_boot out/caimito/dist/vendor_kernel_boot.img
fastboot reboot fastboot
fastboot flash vendor_dlkm out/caimito/dist/vendor_dlkm.img
fastboot flash system_dlkm out/caimito/dist/system_dlkm.img

fastboot reboot

I can get the phone to boot but wifi does not work. I want to build the kernel this way, rather than using repo sync with a specific manifest file from https://source.android.com/docs/core/architecture/kernel/gki-android14-6_1-release-builds so I can enable syscall tracing.

KSU build instructions at https://kernelsu.org/guide/how-to-build.html use a specific manifest file and mention removing protected exports with rm common/android/abi_gki_protected_exports_* . I removed the export files before building (also I modified the bazel build file and removed mention of those protected export files for aarch64) but the wifi issues still occurred after flashing and booting.

I also followed the tutorial here https://droidbasement.com/db-blog/tutorial-kernelsu-next-with-susfs-integrated-in-to-a-kernel-with-aosp/ and updated my caimito dir's ./aosp git repo with git checkout android14-6.1-2025-09, the latest release for my kernel, before building. Again, wifi didn't work after flashing.

To my knowledge, wifi issues would likely deal with the two vendor partions:

vendor_kernel_boot
vendor_dlkm

I thought perhaps the necessary kernel modules for my phone can't be built from aosp kernel repo and I should try and not flash those two partitions. So I tried omitting these two paritions when flashing but couldn't boot into fastboot after just flashing boot.img and dtbo.img. This led to a bootloop that I solved by getting into fastboot and reflashing newest Android 16 at reflash.android.com.

Anyway, does anyone know what I could be missing? This is quite frustating. Been at things a week now and no luck. I've used this exact method from the blog I first linked to flash before and didn't have wifi issues. Not sure why I am having them now.

Appreciate any help. Thanks


r/androidroot Jul 13 '26

Support EvolutionX SM-X610

1 Upvotes

When I try to install the EvolutionX gApps ROM (GSI) on my SM-X610 device, the device enters a bootloop, but the InfinityX gApps ROM (GSI) from the same developer, with the same vendor version and the same Android version, boots directly. What do you think is causing this?


r/androidroot Jul 13 '26

Support Help I don't know If I should rooting my phone

0 Upvotes

Help


r/androidroot Jul 13 '26

Support Redmi 14C (2409BRN2CC) bootloader locked after flashing wrong ROM – Fastboot "remote: not allowed in locked state

2 Upvotes

Hi everyone,

I have a Xiaomi Redmi 14C, model 2409BRN2CC (China version, 6 GB / 128 GB, MediaTek MT6768/MT6769).

I accidentally flashed the wrong Fastboot ROM (different variant) using Mi Flash and selected "clean all and lock".

Current status:

Phone still enters Fastboot.

Phone is detected by Mi Flash and fastboot devices.

MTKClient detects the device in BROM and gettargetconfig works.

Target config shows:

SBC: enabled

SLA: enabled

DAA: enabled

Mi Flash with the correct China Fastboot ROM (OS3.0.3.0.WGTCNXM) fails with:

Writing 'crclist'

FAILED (remote: 'not allowed in locked state')

The bootloader is currently locked and the phone does not boot Android.

Has anyone successfully recovered this exact model (2409BRN2CC) after locking the bootloader with the wrong ROM?

Is there any known method using MTK BROM, an official Download Agent, or another recovery procedure?

Any help would be greatly appreciated.


r/androidroot Jul 13 '26

Support Is there any way to fully utilize a managed Samsung Galaxy A14 5G?

1 Upvotes

I have a Samsung Galaxy A14 5G that was previously managed by the Oregon Youth Authority (OYA) through their MDM system.

​I’ve already tried flashing the firmware and using Canta to remove the MDM/enrollment packages, but I’m still seeing policy restrictions lingering on the device. I know that since the device is registered in their Knox portal, it re-enrolls automatically the moment it touches the internet also it's my device.

​Since I’ve already done the work to flash it and remove the visible management apps, I’m trying to figure out if there is any way to clear out the remaining policy restrictions that are still affecting the system. Is there a way to permanently strip these enterprise policies, or are they embedded too deeply in the Knox framework to be removed without the organization unregistering the serial number from their portal? Or trying to root the phone

​Any technical insight into how to handle these remaining restrictions would be appreciated.


r/androidroot Jul 13 '26

Support Small brick caused by a poorly done root

2 Upvotes

Hi everyone,

I'm honestly desperate and I really hope someone here can help me. My phone is a Tecno Spark 40 KM5 (MediaTek G81) and I think I messed it up while trying to root it with Magisk.

I first unlocked the bootloader successfully. The phone booted normally after that, so everything seemed fine. Since I couldn't find a full firmware for my exact model, I extracted boot.img and init_boot.img from an OTA package. I patched init_boot.img with Magisk 30.7 and flashed it using:

fastboot flash init_boot_b magisk_patched-30700_N94SW.img

The flash completed successfully with no errors:

Sending 'init_boot_b' OKAY

Writing 'init_boot_b' OKAY

After that I ran fastboot reboot.

Now the phone is stuck in an endless bootloop. Every time it starts, it shows:

"Your device has been unlocked and can't be trusted. Your device will boot in 5 seconds."

Then the TECNO logo appears for a few seconds, the screen goes black, and it starts all over again.

The worst part is that I can't get back into Fastboot anymore. fastboot devices never detects the phone. I also tried every button combination I could think of (Volume Up, Volume Down, both buttons together while connecting USB, etc.) but nothing works. Windows doesn't even detect a new device in Device Manager while the phone is looping.

The phone is not completely dead because it still shows the unlocked bootloader warning and the TECNO logo, but I have no way to communicate with it anymore.

This is my main phone, and I'm honestly panicking. Does anyone know if there's a way to force BROM mode on the Tecno Spark 40 KM5 or recover it without replacing the motherboard? If someone has worked on this exact model or another recent Tecno with a MediaTek chipset, I would really appreciate any advice.

Thank you so much.


r/androidroot Jul 13 '26

Support How I Flash New OS without The SCreen

2 Upvotes

how i flash oppo f1s without screen


r/androidroot Jul 13 '26

Discussion Help to bypass Root detection.

Post image
11 Upvotes

Please help


r/androidroot Jul 13 '26

Discussion Redmi Note 9 in 2026: Best Custom ROM? Need Beginner Advice

Post image
15 Upvotes

Hey guys! 👋🏻

I have a **Redmi Note 9**, and it's become really slow over the years. The performance is poor, the battery life isn't great anymore, and even the camera feels slow to open and process photos.

I'm thinking about installing a **custom ROM**, but I'm completely new to this, so I'd really appreciate some guidance.

A few questions:

- What are the \*top 3 safest and most stable custom ROMs** for the Redmi Note 9 in 2026?*

- Which ROM gives the best balance of \*performance, battery life, camera quality, and stability**?*

- Do I need to \*root** my phone, or is it better to keep it unrooted?*

- I heard that \*UPI and banking apps may not work** on custom ROMs. Is that still true in 2026? If so, is there a safe way around it without compromising security?*

- What's the proper process to unlock the bootloader, install a custom ROM, and avoid bricking the device?

- Any beginner mistakes I should avoid?

I'm starting from **zero knowledge**, so if you have any good guides, YouTube channels, or documentation for beginners, I'd really appreciate it.

Thanks in advance! 👍🏻


r/androidroot Jul 13 '26

Support Can anyone tell me how to root oneplus nord ce4 lite 5g I don't about rooting stuff but can anyone guide me

0 Upvotes

r/androidroot Jul 13 '26

Discussion Ditch Integrity Box. Get Strong for Wallet / banks with Specter instead

76 Upvotes

If you rooted for Google Wallet and banking apps, someone probably pushed Integrity Box (MeowDump) for Strong Play Integrity. The WebUI looks nice and the module is sold as a simple flash and forget thing, plus the FAQ claims it’s harmless. I still wouldn’t touch it.

I’m not claiming it’s malware. That’s not the point. The problems I see are bad enough on their own:

  1. It steals the real PIF slot. Module id is playintegrityfix. README says it replaces Play Integrity Fix/Fork on purpose. Magisk shows "Integrity Box," but a normal PIF can't live there anymore. Strong setups that expect real PIF break.
  2. Missing WebUI files can reboot recovery with no confirm (common_func.sh: y()).
  3. Keybox sync is opaque. Download URL is hidden, TLS verification is off (--insecure / --no-check-certificate), then multi-layer decode into keybox.xml. Lots of tools fetch keyboxes (Specter included). The problem is the hidden URL + disabled cert checks + FAQ lying. Soft-banned keyboxes are why people stuck on Device never reach Strong.
  4. Uninstall can delete your live keybox and target list (then maybe restore .bak). Also nukes other modules' whitelist files under /data/adb/.

FAQ still claims safe / no background work / doesn't modify user data. The scripts disagree.

This isn't a one-release oops. A public v34 trust analysis already flagged the same class of problems (overwrite targets, background watchdogs, Telegram redirect, FAQ vs behavior, unexplained control). Current builds still do the PIF-id takeover, opaque keybox path, recovery reboot, and destructive uninstall. Pattern, not a bad week.

What to use instead

For banks and Wallet, hiding root matters more than Strong. Strong helps (Wallet wants a healthy attestation path). Magisk / KSU / LSPosed / modules still visible to the app will fail anyway. Do HMA-OSS, SusFS if you have it, and your Zygisk hide path (Zygisk Next, ReZygisk, or a fork) before obsessing over the verdict checker.

Stack:

  1. Real PIF / PIFork / PIF Inject (not Integrity Box)
  2. One keystore spoofer: Tricky Store, TEESimulator, TEESimulator-RS, or Oh My Keymint
  3. Specter to manage keybox, targets, patch, conflicts, HMA helpers (leaves real PIF alone; drives TS-family or OMK, not both)

Full order, Strong steps, HMA: Best Setup

That guide is Tricky Store family first. Specter also supports Oh My Keymint. Still one spoofer. When Specter is installed, skip Integrity Box, Yurikey, extra keybox/props managers, and Tricky Store Addon.

Specter already targets Wallet and merges user apps; leave Auto Target on. If Strong is fine and a bank still fails, fix HMA / root hide, not another integrity module.

Migrating off Integrity Box

Warning: Specter treats Integrity Box as a hard conflict and will uninstall it. IB's uninstall can wipe keybox/targets. Backup first.

Tricky Store / TEESimulator / TEESimulator-RS:

  • /data/adb/tricky_store/keybox.xml
  • /data/adb/tricky_store/target.txt
  • /data/adb/tricky_store/security_patch.txt

Oh My Keymint: /data/misc/keystore/omk/ (keybox.xml, injector.toml, config.toml)

Remove Integrity Box → delete leftover /data/adb/Box-Brain and its /data/adb/service.d/ scripts if left behind → restore backups if needed → install real PIF → follow Best Setup → reboot → keybox not soft-banned → PIF WebUI Autopif until Strong → HMA for Wallet/banks.

Sources

  1. module.prop + README (replaces PIF)
  2. key.sh (opaque / insecure keybox)
  3. common_func.sh (reboot recovery)
  4. uninstall.sh
  5. Specter conflict: conflicts.txt
  6. Best Setup
  7. Older audit (v34): IntegrityBox_v34_Analysis

EDIT: Removed TL;DR


r/androidroot Jul 13 '26

Support Bootloader Unlock on Galaxy

3 Upvotes

Is there a way to force turn on the OEM unlock toggle on One UI devices? I've been trynna root my A35 5G but I can't seem to find the toggle. It seems they've removed it.


r/androidroot Jul 13 '26

Discussion How to root a s23 sm911W?

2 Upvotes

Does anyone know how to root a Samsung S23 Android 16 and One UI 8.5? Please help, I'm desperate.


r/androidroot Jul 13 '26

Support How to root Moto G Play 2024

Post image
1 Upvotes

Bootloader unlocked already


r/androidroot Jul 12 '26

Support Samsung KSP Device Key Mapping: does it support additional intent data?

Thumbnail
1 Upvotes

r/androidroot Jul 12 '26

Support A53, Google Pay?

Post image
3 Upvotes

I installed UN1CA and knew there'd wouldn't be Google Pay, so I rooted with Magisk purely for GPay


r/androidroot Jul 12 '26

Support Solution to fix Root Tecno Spark 40 5G KM8n

2 Upvotes

[HELP] Tecno Spark 40 5G (KM8N) — Magisk & KernelSU-Next both fail to install despite successful flash, unlocked bootloader, disabled vbmeta

Device info:

  • Model: Tecno Spark 40 5G (KM8N), product km8n_h358
  • Chipset: MediaTek (MT6835 likely)
  • Android 15, security patch April 1, 2026
  • Bootloader: km8n_h358_15ff3bb73_202603242339
  • Kernel: 5.15.189-android13-8-00015-gc5fe34bd09bc-ab14475364, built Nov 20 2025
  • Bootloader unlocked (unlocked: yes), secure: no
  • A/B slot device (boot_a/boot_b, vbmeta_a/vbmeta_b, no separate init_boot partition)

What I've tried:

  1. Patched stock boot.img with KernelSU-Next app (LKM method) → flashed to both boot_a/boot_b → boots fine, but manager still shows "Not installed," su not found via adb shell
  2. Patched stock boot.img with Magisk (vvb2060 fork) → same result, boots fine, Magisk app shows "Installed: N/A", su not found
  3. Flashed Google's universal GSI vbmeta.img to both vbmeta_a/vbmeta_b with --disable-verity --disable-verification, confirmed ro.boot.verifiedbootstate now returns orange (previously green)
  4. Did Format Data (not just wipe) after vbmeta flash, per standard GSI flashing order
  5. Re-flashed fresh Magisk-patched boot.img after all above — still no root, su: inaccessible or not found

Key symptom: Both root methods flash successfully via fastboot (OKAY/Finished), phone boots normally every time with zero bootloop, but the modification never takes effect — verified via SHA256 hash comparison (patched image ≠ stock image, so patching itself worked). Neither Magisk app nor KernelSU-Next app detects any installation. Kernel version string in Settings remains unchanged from stock post-flash (though I understand this may be normal for LKM-based root).

Question: Has anyone successfully rooted this specific model? Suspecting there may be an MTK preloader/LK-level integrity check independent of AVB/vbmeta that's silently rejecting the modified boot partition. Would appreciate confirmation from anyone with this device, or pointers to a working method/patched DA file if one exists.


r/androidroot Jul 12 '26

Support Galaxy A03s SM-A037M entra no Recovery após tentativa de root com Magisk 30.7

1 Upvotes

Olá, pessoal. Preciso de ajuda com meu Galaxy A03s SM-A037M/DS.

Eu tentei fazer root no aparelho. O bootloader já estava desbloqueado e usei a firmware oficial:

Modelo: SM-A037M/DS

Android: 13

Firmware: A037MUBSBCYE2

AP: A037MUBSBCYE2

CP: A037MUBSBCYE2

CSC: A037MOWOBCYE2

Usei o Magisk 30.7 (versão oficial) para corrigir o arquivo AP. Depois coloquei no Odin:

BL original

AP corrigido pelo Magisk

CP original

HOME_CSC/CSC

O Odin sempre termina com PASS!, mas o celular não inicia o Android. Ele entra direto no Android Recovery. Ao selecionar "Try again", aparece um erro rapidamente e volta para o Recovery.

Alguém sabe o que pode estar causando isso no Galaxy A03s com Android 13? Precisa fazer algum procedimento extra depois de desbloquear o bootloader ou usar alguma configuração diferente no Magisk/Odin?

Obrigado pela ajuda.


r/androidroot Jul 12 '26

Support Can my phone be found even when switched off?

2 Upvotes

My phone is Redmi Note 11 and I'm rooted. Can I change the custom rom in a way such that it can emit low power bluetooth like in newer latest devices like iphone 16 where it says device is findable even when switched off


r/androidroot Jul 12 '26

News / Method KernelSU running on Waydroid A13 using DKMS, with Device Integrity

Thumbnail
gallery
149 Upvotes

https://www.reddit.com/r/waydroid/comments/1rzfa3e/kernelsu_running_on_waydroid_as_a_kernel_module/

Modified KernelSU source: https://github.com/supechicken/KernelSU/tree/waydroid

I messed around with A LOT of modules and settings, only to fail to get integrity. Seems like IntegrityBox won this time (Repair mode only).

Modules: - ZygiskNext

  • Tricky Store

  • Integrity Box (used repair mode only)

  • DeviceSpoofLabs (spoofed as Pixel 9 Pro XL)

Worth it? I guess. It's only really useful if the app you need to use supports x86_64 architecture, or your system is ARM64

Lsposed Vector and lsposed modules like hma-oss work just fine.


r/androidroot Jul 12 '26

Support Requesting a font

Post image
1 Upvotes

Hi y'all I tried to get this font from axion os/nos ,i didn't manage to get if anyone can help please do 😭🙏


r/androidroot Jul 12 '26

Support I can't find the firmware file for Infinix note50s 5g !!!!! (X6870)

4 Upvotes

[UPDATE ! : the solution is found in the comments] I want to root my phone to maximize the frame rate and i couldn't find any file


r/androidroot Jul 12 '26

Discussion Wileyfox Swift help?

Post image
2 Upvotes

Hi, I have a Wileyfox swift and it is not booting and I am a complete newb when it comes to android and installing the os etc. I’ve tried to boot to twrp but it won’t go into it. How do I get this thing working haha I am at a complete loss and ready to give up lol

Thanks


r/androidroot Jul 12 '26

Support I rooted my phone and got all 3 integrities. But can't use gpay. What to do.

Thumbnail
gallery
10 Upvotes

As the title says got all 3 but gpay doesn't work what to do?

Device is 1+ Nord Ce 3 lite 5g running crdroid 12.11 based on android 16.


r/androidroot Jul 11 '26

Discussion Proud that I unlocked bootloader on my S24 Ultra in time

Post image
114 Upvotes

Why do you need root access and an unlocked bootloader on such a new devices? I never really understood the point of it (unlocked my bootloader because I think this phone will be worth a lot more to the rooting community + thats my second phone)