Lenovo P14s Gen 5 SVP unlock

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Syseng
    Member
    • Jun 2025
    • 10
    • Kyrgyzstan

    #1

    Lenovo P14s Gen 5 SVP unlock

    This sums up discussion related to Lenovo P14s Gen5 in this thread. Credits go to Sbaro and especially Maxpower3. The locked dump is attached.

    The device is based on NM-F871 motherboard with Nuvoton NPCK397 series controller. The motherboard also contains three BIOS chips: two different Winbond chips for main BIOS and external EC flash, and also a Gigadevice chip which purpose I do not know. The password information is contained directly in controller and thus can be manipulated by reprogramming it, so reprogramming BIOS chips is technically not required, however you may wish to make backups thereof to use them in case of unforeseen emergencies.

    To read and write NPCK397 I used Vertyanov SUCCESSOR BASE4, however other programmers may be also applicable. The supplied dicumentation suggests to remove the EC BIOS chip prior to working with the EC, however I did not find that necessary.

    The EC firmware dump is 256 KB of size, of which first 248 KB are not used. The remainder of 8 KB is split in two 4 KB sections which are used somehow in conjunction: some parts of them match between each other. The first section starts at 0x0003E000 while the second one starts at 0x0003F000. Each of the two sections starts with the 80 byte sequence of the pattern XX 00 XX 01 XX 02 ... XX 27, where XX mostly stands for FC, but can become 00 in certain (unclear) circumstances. I suppose these sequences serve as some kind of state registers, in addition to them being section dividers. In particular I observed some XX of the second section change from FC to 00 when the the laptop is started after the EC is reprogrammed.

    Another sequence of interest is located at 0x0003F050, and is of the general pattern 00 27 00 27 ... and ends generally with 0xFC. I suspect this to be some kind of restart record, because when the laptop is restarted, chunks of the pattern 00 1A are being either inserted into it or cut from it closer to the end of the sequence.

    The ending of the second section starting roughly at 0x0003FB20, and being slightly over 1 KB in size, is likely used as some form of internal log or integrity check mechanism. Initially unused, it becomes populated with data after the EC has been reprogrammed and even (although to a lesser extent) when the EC is subsequently restarted without new reprogramming.

    The "main" password-related data is supposed to be contained in the region starting at 0x0003F420.

    Lenovo continuously improves password protection, and in this new laptop model it is not sufficient to simply erase this region, because integrity check mechanism is in place. While the password-related sequences are supposed to be 32 byte long (which suggests they are SHA-256 hashes of the SVP), they are being several times repeated throughout the two 4KB sections, sometimes in a disjoint fashion. All those (or at least most of them, see below) need to be located and erased. In addition, there are one-byte sequences here and there likely being a product of CRC-16-IBM checksums of the password sequences. Hereinafter I refer to them as "checksums".

    In my case, the following was detected upon investigation.

    Password lines:

    0x0003F430-0x0003F44F
    0x0003F450-0x0003F46F
    0x0003F4A0-0x0003F4BF

    (two lines sequence repeated thrice).

    The corresponding "checksum line" is immediately preceding and starts at 0x0003F420. It runs thus:

    FF FF BE BE FF BE FF FF FF FF FF FF FF FF FF FF

    The two lines of the "password" are repeated verbatim starting at 0x0003E4A0.

    Then the two lines of the "password" are repeated in reverse starting at 0x0003E6E0 (meaning second line comes first).

    Also, the first line of the "password" is repeated at 0x0003E930 (one "checksum" is found in the preceding 0x0003E920 line), 0x0003EC70 (two "checksums" are found in the preceding 0x0003EC60 line), and 0x0003EC90 (three "checksums" are found in the preceding 0x0003EC80 line).
    And the second line of the "password" is additionally repeated at 0x0003E9A0, 0x0003FA00, 0x0003FA60 and 0x0003FAC0.

    Overall, the first password line is encountered 8 times, while twe second line is encountered 9 times throughout the entire dump.

    Basically you have to locate all those repeated password lines and associated "checksums" and erase them (substitute with 0xFF). Some "checksum" lines contain data other than checksums in question. To distinguish them, start with the 0x0003F420 and note the checksum sequence, in our case 0xBE. In all other "checksum" lines the "checksums" should be 0xBE likewise. E.g. the 0x0003EC60 line runs as:

    FF FF BE FF FE FF FF FF FF FF FF FF FF FF FF FF

    so you know that BE is the "checksum" which you need to erase, while FE is some other data which you leave intact.

    It is not clear which exactly repetitions and checksums are crucial for the SVP unlock. In my case, the 0x0003E4A0 - 0x0003E4BF lines were not erased, and neither was the 0x0003FAC0 line. On the other hand, the 0x0003F4E0 - 0x0003F4FF were erased which do not match the password lines and the purpose of which is unclear to me. I did not test the scenario where it would be vice versa, since the modifications that Maxpower3 suggested led to immediate success. Apparently, the process requires a bit of try-and-change.

    If you get "Bad SVP data" error, this most probably means that you missed some checksum somewhere. Either try to locate it and erase it, or try to leave the respective password lines (for which you're unable to locate the checksum) intact. As proven above, not all password lines act towards the actual SVP lock.

    If you had the SVP retry counter exceeded, the respective error will be displayed upon successful unlock as well, but it will have no actual effect and will go away when you turn ithe counter off in BIOS.

    After the unlock the BIOS behaves unstable, you may get write protection errors. This is solved by updating BIOS via the official update utility.

    Good luck.
    Attached Files
  • Maxpower3
    Bad Veteran
    • Feb 2018
    • 1222
    • France

    #2
    I have already mentioned these dumps with many repetitions of the password, hoping that this can help other users or models causing problems.
    https://www.badcaps.net/forum/troubl...95#post3461595


    Comment

    Related Topics

    Collapse

    • Ihandyrepair
      Samsung QN70Q6DTA Ghost or horizontal lines after tape fix horizontal line
      by Ihandyrepair
      Hi guys

      I just started fixing 4k TV few months ago. so I am still learning a lot
      I got this tv from friend complaint is ghosting or horizontal lines on image.

      never saw the original symptom but I took the tv back home. the funny part is that after bringing to home, the tv worked fine no issue for 3 weeks.
      then it started to show the ghosting white image.
      I started using the tape method, but this tv does not have a T con board and it has only 1 ribbon cable from main board to the tv panel.
      it has 3 thin small boards at the bottom of the...
      12-05-2022, 04:18 PM
    • joelz
      pin Setting parameter line or set lines menu for adding ITE5571e on RT809F programmer
      by joelz
      Hi, sorry if i here to request if anyone know number of pin to set lines for reading ITE7751e on RT809F..i try to see on schematic but i dont know how to choose it..pleasee..
      11-18-2024, 06:02 AM
    • Stanley1843
      Screen Display Vertical Multicolor Lines
      by Stanley1843
      Hello, I have a screen in where sometimes when I open it pop-up vertical multicolor lines (I would say the most of them are green). If I tun off and turn on the screen the lines dissapear or if I leave open the screen after approximately five minutes the lines gone. I measured the below voltages on the main PCB and on the T-CON board and the voltages are the same when it doesn’t display the vertical lines and when it displays the vertical lines. Also, I cleaned all the connectors very good with IPA. I moved back and forth the connectors and the COF tabs but the vertical lines didn't displayed...
      06-29-2024, 11:54 AM
    • DrvLikHell
      Sharp (Hisense) LC-55p6050u - Flashing/dimming row of pixels
      by DrvLikHell
      Hello again! I have come back for some wisdom and hopefully for some guidance with this problem I'm having. The TV is a 4k 55" Sharp LC-55p6050u and the problem is every other line of the bottom 32 lines flickers out, comes mostly back, then flickers out again, and repeats this continually. The lines on the bottom right of the screen go out completely while the lines on the bottom left are affected so slightly that it's almost impossible to see it. There is a gradual gradient from appearing almost perfectly fine on the bottom left, to an obvious problem on the bottom right.

      The...
      02-05-2025, 01:44 AM
    • cubytus
      Samsung UN50TU8000FXZC shows thin horizontal green line when warm
      by cubytus
      Hi to all,

      I was given this TV, an entry-level 4K 50" set. Some have criticized its lack of contrast and relatively poor colour rendering, but for my needs, it's very decent.

      I reset everything to factory settings, but this line keeps on fading in and out when watching a streaming channel from the Tizen firmware. Interestingly, it only happens when TV is warm, after about 1h45 of it being turned on.

      Watching a movie from an external source doesn't trigger the line as easily (needs 2 hours), and from a normal viewing distance, is hardly noticeable. It...
      01-10-2024, 01:26 AM
    • Loading...
    • No more items.
    Working...