Understanding S1 Service mode

Can anyone help to understand S1 Service mode (not a fastboot) ?

For example, Sony device [ vid: 0FCE ; pid: ADDE ] also like [ SOMC Flash Device ]
Where I can get more information about this ? from what to start ? something about structure / commands etc. Would be great to see anything without sniffing and debugging usb traffic <_<

Can I, for example, push bootloader into RAM then access to its commands such as loading something into addrX then to start evaluation from that addrX and so on. How about without emmc (CPU + RAM only) ? How about u-boot? :)

I started from problem here (I also have trim-area (TA) backup, but...):
(phone is not mine)

Mainly I can't think of how I can inspect emmc on hardware problems without soldering at all :( because I have no Z3X or something else. So I can programming only via USB and some other related things if it's not so hard to prepare at home manually.
Anyway, would be great to solve or at least understand this problem in details.

So any suggestions for more understanding this bug or S1 Service are very welcomed!

Show Accepted Answer

Guest Quick Reply (No URL, BBcode or HTML)

Last post by yessenia.fritsch
1 hour ago
Last post by amelie.kihn
2 hours ago
Last post by savanna22
4 hours ago
Last post by kylie45
1 hour ago
Last post by emmett51
43 minutes ago
Last post by judy00
53 minutes ago
Last post by zrippin
26 minutes ago
Last post by sherwood08
1 hour ago
Last post by bmorissette
2 hours ago