Skip to content

feat(extract_rs): derive MediaTek kernel phys values from vendor_boot.img - #333

Merged
NickJi2019 merged 3 commits into
YuKongA:mainfrom
OhMyDitzzy:main
Oct 7, 2026
Merged

NickJi2019 merged 3 commits into
YuKongA:mainfrom
OhMyDitzzy:main

Conversation

@OhMyDitzzy

Copy link
Copy Markdown
Contributor

Summary

Right now, if we're on MediaTek and don't have xbl_config.img/uefi.img
(Snapdragon-only) or a rooted device to read /proc/iomem, there's no way
to get kernel_phys_load/kernel_phys_offset at all — the extractor just
fails at W1 and points at tools/mtk-phys/, which needs root.

Turns out we don't need root for this on MediaTek. vendor_boot.img's
header already has the kernel's physical load address sitting right there
in the kernel_addr field. I checked it against mtk-phys.sh (which reads
the real value live from /proc/iomem) on two different chips

The part I think matters most we can get vendor_boot.img without
touching the running OS at all. Pull it from the firmware package, Which most devices with kernel 5.10 and above have this vendor_boot.img partition, none of that requires root on the device itself. So
this ends up being genuinely useful for the exact situation where someone
can't root or unlock their device's bootloader.

Proof

I have tried testing this change on two different mediatek devices:

  • Redmi 15C (Mediatek Helio G81 Ultra) video recording:
    https://gofile.io/d/tMjLhH6v (Temp)

  • Redmi 15C 5G (tornado, Mediatek Dimensity 6300) screen shoot:

IMG_20261006_181810_440 IMG_20261006_181810_261

@NickJi2019

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The address-inference assumptions affect kernel memory translation and require human validation beyond the two reported devices.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)
What changed in this PR

Adds a vendor_boot-based path for extracting MediaTek kernel physical addresses without a rooted device.

Changes:

  • Adds header parsing, unit tests, and the --vendor-boot option.
  • Connects Android attachment selection through extraction and overwrite confirmation.
  • Updates English and Chinese recovery guidance.
File Description
tools/​extract_rs/​src/​vendor_boot.rs Parses addresses and tests header handling.
tools/​extract_rs/​src/​main.rs Integrates vendor_boot address recovery.
tools/​extract_rs/​src/​lib.rs Exposes the parser module.
app/​src/​main/​res/​values/​strings.xml Adds English attachment guidance.
app/​src/​main/​res/​values-zh/​strings.xml Adds Chinese attachment guidance.
app/​src/​main/​kotlin/​com/​ghostlock/​app/​ui/​GhostlockViewModel.kt Handles attachment selection and confirmation.
app/​src/​main/​kotlin/​com/​ghostlock/​app/​domain/​usecase/​GhostlockUseCases.kt Forwards the attachment path.
app/​src/​main/​kotlin/​com/​ghostlock/​app/​domain/​repository/​GhostlockRepository.kt Extends the extraction interface.
app/​src/​main/​kotlin/​com/​ghostlock/​app/​data/​AndroidGhostlockRepository.kt Passes the attachment to the extractor.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread tools/extract_rs/src/vendor_boot.rs Outdated
Comment thread tools/extract_rs/src/vendor_boot.rs Outdated
@OhMyDitzzy

OhMyDitzzy commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor Author

Still works
Screenshot_2026-10-06-20-23-56-891_com ghostlock app

@NickJi2019

@NickJi2019
NickJi2019 merged commit 67d519b into YuKongA:main Oct 7, 2026
5 checks passed
@NickJi2019 NickJi2019 linked an issue Oct 7, 2026 that may be closed by this pull request
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

unable to extract kernel_phys_load in some MediaTek devices

3 participants