PS C:\Users\Paterna> adb shell ls -l /vendor/bin/ total 3552 lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 acpi -> toybox_vendor -rwxr-xr-x 1 root shell 113548 2026-01-14 06:44 awk lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 base64 -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 basename -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 bc -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 blockdev -> toybox_vendor -rwxr-xr-x 1 root shell 1015688 2026-01-14 06:44 busybox -rwxr-xr-x 1 root shell 1096224 2026-01-14 06:44 busybox-smp lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 cal -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 cat -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 chcon -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 chgrp -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 chmod -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 chown -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 chroot -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 chrt -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 cksum -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 clear -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 cmp -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 comm -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 cp -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 cpio -> toybox_vendor -rwxr-xr-x 1 root shell 37360 2026-01-14 06:44 cpu_monitor -rwxr-xr-x 1 root shell 15932 2026-01-14 06:44 crda -rwxr-xr-x 1 root shell 24312 2026-01-14 06:44 crda.uevent lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 cut -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 date -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 dd -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 devmem -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 df -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 diff -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 dirname -> toybox_vendor -rwxr-xr-x 1 root shell 16548 2026-01-14 06:44 dispconfig lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 dmesg -> toybox_vendor -rwxr-xr-x 1 root shell 31004 2026-01-14 06:44 dom2reg lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 dos2unix -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 du -> toybox_vendor -rwxr-xr-x 1 root shell 41968 2026-01-14 06:44 dumpsys lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 echo -> toybox_vendor lrwxr-xr-x 1 root shell 4 2026-01-14 06:47 egrep -> grep lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 env -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 expand -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 expr -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 fallocate -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 false -> toybox_vendor lrwxr-xr-x 1 root shell 4 2026-01-14 06:47 fgrep -> grep lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 file -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 find -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 flock -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 fmt -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 free -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 fsync -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 getconf -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 getenforce -> toybox_vendor lrwxr-xr-x 1 root shell 7 2026-01-14 06:48 getevent -> toolbox lrwxr-xr-x 1 root shell 7 2026-01-14 06:48 getprop -> toolbox -rwxr-xr-x 1 root shell 28476 2026-01-14 06:47 grep lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 groups -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 gunzip -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 gzip -> toybox_vendor -rwxr-xr-x 1 root shell 16064 2026-01-14 06:44 hdcptool -rwxr-xr-x 1 root shell 32 2026-01-14 06:44 hdcptool.sh lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 head -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 hostname -> toybox_vendor drwxr-xr-x 2 root shell 4096 2026-01-14 06:46 hw lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 hwclock -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 i2cdetect -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 i2cdump -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 i2cget -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 i2cset -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 iconv -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 id -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 ifconfig -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 inotifyd -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 insmod -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 install -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 ionice -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 iorenice -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 kill -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 killall -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 ln -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 load_policy -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 log -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 logname -> toybox_vendor -rwxr-xr-x 1 root shell 15684 2026-01-14 06:44 logwrapper lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 losetup -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 ls -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 lsmod -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 lsof -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 lspci -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 lsusb -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 md5sum -> toybox_vendor -rwxr-xr-x 1 root shell 373003 2026-01-14 06:44 memtester lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 microcom -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 mkdir -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 mkfifo -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 mknod -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 mkswap -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 mktemp -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 modinfo -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 modprobe -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 more -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 mount -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 mountpoint -> toybox_vendor -rwxr-xr-x 1 root shell 19768 2026-01-14 06:44 mtop lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 mv -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 nc -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 netcat -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 netstat -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 nice -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 nl -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 nohup -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 nproc -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 nsenter -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 od -> toybox_vendor -rwxr-xr-x 1 root shell 11108 2026-01-14 06:44 parsedispconfig lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 paste -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 patch -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 pgrep -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 pidof -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 pkill -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 pmap -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 printenv -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 printf -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 ps -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 pwd -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 readlink -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 realpath -> toybox_vendor -rwxr-xr-x 1 root shell 15828 2026-01-14 06:44 regdbdump lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 renice -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 restorecon -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 rm -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 rmdir -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 rmmod -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 runcon -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 sed -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 sendevent -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 seq -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 setenforce -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 setprop -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 setsid -> toybox_vendor -rwxr-xr-x 1 root shell 217456 2026-01-14 06:44 sh lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 sha1sum -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 sha224sum -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 sha256sum -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 sha384sum -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 sha512sum -> toybox_vendor -rwxr-xr-x 1 root shell 36456 2026-01-14 06:44 slabinfo lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 sleep -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 sort -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 split -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 start -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 stat -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 stop -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 strings -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 stty -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 swapoff -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 swapon -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 sync -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 sysctl -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 tac -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 tail -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 tar -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 taskset -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 tee -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 time -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 timeout -> toybox_vendor -rwxr-xr-x 1 root shell 43036 2026-01-14 06:48 toolbox lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 top -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 touch -> toybox_vendor -rwxr-xr-x 1 root shell 376532 2026-01-14 06:48 toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 tr -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 true -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 truncate -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 tty -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 ulimit -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 umount -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 uname -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 uniq -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 unix2dos -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 unlink -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 unshare -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 uptime -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 usleep -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 uudecode -> toybox_vendor lrwxr-xr-x 1 root shell 13 2026-01-14 06:48 uuencode -> toybox_vendor ^[[30;120RTasks: 236 total, 1 running, 235 sleeping, 0 stopped, 0 zombie Mem: 16E total, 1.3G used, 16E free, 0 buffers Swap: 1.4G total, 0 used, 1.4G free, 0 cached 400%cpu 9%user 0%nice 16%sys 375%idle 0%iow 0%irq 0%sirq 0%host PID USER PR NI VIRT RES SHR S[%CPU] %MEM TIME+ ARGS 16869 root 20 0 9.4M 3.3M 2.8M R 25.0 0.1 0:00.12 top -n 1 -m 15 942 root RT 0 0 0 0 S 3.1 0.0 0:02.25 [cfinteractive] 16570 root 20 0 0 0 0 S 0.0 0.0 0:00.11 [kworker/u8:1] 16548 root 20 0 0 0 0 S 0.0 0.0 0:00.02 [kworker/0:0] 16541 root 20 0 25M 4.7M 3.9M S 0.0 0.2 0:01.67 adbd --root_sec+ 16248 root 20 0 0 0 0 S 0.0 0.0 0:00.01 [kworker/0:2] 16102 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 [kbase_event] 16068 system 10 -10 1.0G 135M 103M S 0.0 6.8 0:04.93 com.android.tv.+ 15386 root 20 0 0 0 0 S 0.0 0.0 0:00.08 [kworker/3:1] 14503 root 20 0 0 0 0 S 0.0 0.0 0:00.13 [kworker/u8:3] 14026 root 0 -20 0 0 0 S 0.0 0.0 0:00.35 [kworker/u9:3] 13745 root 20 0 0 0 0 S 0.0 0.0 0:00.37 [kworker/u8:0] 10510 u0_a24 10 -10 1.1G 143M 111M S 0.0 7.2 0:12.53 com.android.ven+ 9829 root 20 0 0 0 0 S 0.0 0.0 0:01.55 [kworker/1:0] 9792 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 [kbase_event] PS C:\Users\Paterna> adb shell cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_available_frequencies 480000 600000 792000 1008000 1200000 1296000 PS C:\Users\Paterna> adb shell cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_governor interactive PS C:\Users\Paterna> adb shell cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_cur_freq 1296000 Perfecto. Con esto ya tenemos bastante claro el hardware y, sobre todo, tenemos acceso root real mediante adb root, así que podemos hacer el backup de las particiones directamente sin depender de su. Lo que ya sabemos Tu dispositivo es un Allwinner H616 / sun50iw9p1, con eMMC: eMMC: mmcblk0 Capacidad declarada: 30,535,680 × 512 = 15,633,? MB, aproximadamente 15 GiB Modelo eMMC: R311MB manfid: 0x000015 U-Boot: 2018.05 (01/14/2026) Android: parece un userdebug, con adb root habilitado. SELinux está en permissive. La tabla de particiones está definida directamente en cmdline, y coincide con /dev/block/by-name. La correspondencia importante es: Partición Dispositivo Tamaño aprox. Función bootloader p1 16 MiB Bootloader env p2 8 MiB Entorno U-Boot boot p3 16 MiB Kernel/ramdisk super p4 2.5 GiB Sistema dinámico misc p5 8 MiB Misc/boot control recovery p6 16 MiB Recovery cache p7 320 MiB Cache vbmeta p8 8 MiB AVB vbmeta_system p9 16 MiB AVB system vbmeta_vendor p10 8 MiB AVB vendor metadata p11 8 MiB Metadata private p12 8 MiB Datos privados frp p13 256 KiB Factory Reset Protection empty p14 ~7.75 MiB Reservada media_data p15 8 MiB Media data Reserve0 p16 8 MiB Reservada UDISK p17 ~11.16 GiB /data Y esto es particularmente importante: /dev/block/by-name/UDISK /data f2fs Por tanto, todo /data está en UDISK/p17, y como has dicho que no hay nada que conservar, podemos despreocuparnos de los datos de usuario. Lo siguiente que haría Antes de tocar absolutamente nada, aprovecharía que ya tienes adb root y sacaría una copia completa de las particiones críticas. No necesitamos su. De hecho, el error: su: invalid uid/gid '-c' es irrelevante: ese su no entiende la sintaxis de su -c, pero no lo necesitamos porque adbd ya está funcionando como UID 0. Compruébalo: adb shell id y debe seguir mostrando: uid=0(root) 1. Primero: información exacta de todas las particiones Ejecuta: adb shell 'for p in /sys/class/block/mmcblk0p*; do echo -n "$(basename $p) "; cat $p/size; done' Y también: adb shell 'cat /proc/partitions' Aunque ya tenemos casi toda esa información, quiero conservar una salida limpia antes de modificar nada. 2. Comprobar que podemos leer directamente el eMMC Esta es una prueba solo de lectura, no modifica absolutamente nada: adb shell 'dd if=/dev/block/mmcblk0 of=/dev/null bs=1M count=1' Debería devolver algo parecido a: 1+0 records in 1+0 records out 1048576 bytes transferred ... Si funciona, tenemos confirmada la ruta más sencilla. 3. Hacer backup de las particiones críticas Como estás en Windows/PowerShell, yo empezaría por estas: adb exec-out "dd if=/dev/block/by-name/boot" > boot.img adb exec-out "dd if=/dev/block/by-name/recovery" > recovery.img adb exec-out "dd if=/dev/block/by-name/vbmeta" > vbmeta.img adb exec-out "dd if=/dev/block/by-name/vbmeta_system" > vbmeta_system.img adb exec-out "dd if=/dev/block/by-name/vbmeta_vendor" > vbmeta_vendor.img adb exec-out "dd if=/dev/block/by-name/env" > env.img adb exec-out "dd if=/dev/block/by-name/misc" > misc.img adb exec-out "dd if=/dev/block/by-name/bootloader" > bootloader.img No hagas todavía ningún dd de escritura hacia el dispositivo. Estos comandos solamente leen. Además, podemos sacar super, que es una de las piezas más importantes: adb exec-out "dd if=/dev/block/by-name/super" > super.img Ese archivo tendrá aproximadamente 2.5 GiB, así que tardará bastante más. 4. Y hay algo todavía mejor: backup completo del eMMC Ahora que tenemos: /sys/class/block/mmcblk0/size 30535680 eso significa: 30,535,680 sectores × 512 bytes ≈ 15.63 GB decimales, unos 14.56 GiB. Podríamos hacer una imagen completa: adb exec-out "dd if=/dev/block/mmcblk0 bs=4M" > mmcblk0_full.img Eso nos daría una copia bit a bit del eMMC completo, incluyendo: GPT bootloader env boot super recovery vbmeta metadata frp private Reserve0 UDISK espacio restante Es la copia más segura si nuestro objetivo final es experimentar con el firmware. Pero pesa ~15.6 GB, por lo que primero comprobaría que tienes espacio suficiente en C:\Users\Paterna. Puedes mirar: Get-PSDrive C Si tienes espacio de sobra, yo prefiero esta opción antes de empezar a modificar super, boot, vbmeta, etc. 5. Hay una cuestión interesante con super Tu super es: mmcblk0p4 5242880 sectores Eso da exactamente: 5242880 × 512 = 2,684,354,560 bytes ≈ 2.50 GiB. Y tienes: /dev/block/dm-0 / /dev/block/dm-1 /vendor /dev/block/dm-2 /product Todos salen de super. Por tanto, probablemente tenemos un esquema de dynamic partitions, y podremos inspeccionar el contenido de super.img en el PC sin tocar el dispositivo. Eso es mucho más interesante que modificar directamente /system, porque /system está actualmente: /dev/block/dm-0 / ext4 ro y además está protegido por el sistema de particiones dinámicas/verity. 6. También podemos identificar exactamente qué hay dentro de super Una vez tengamos super.img en Windows, podemos analizar: system vendor product tamaños asignados metadata de liblp slots grupos de particiones espacio libre dentro de super Eso nos permitirá saber qué margen real tenemos para modificar Android. Un detalle importante Veo: androidboot.secure_os_exist=0 Eso es muy interesante en un H616. También: androidboot.selinux=permissive selinux=1 buildvariant=userdebug adb root Es decir, este firmware está lejos de ser un Android comercial bloqueado convencional. Tenemos un entorno bastante favorable para analizar/modificar el sistema. Y el governor: interactive con: 480000 600000 792000 1008000 1200000 1296000 indica que el máximo expuesto actualmente por cpu0 es 1.296 GHz. No asumiría todavía que ese sea necesariamente el límite físico del H616: hay que comprobar cpuinfo_max_freq, los otros clusters/cores y el device tree. Yo no tocaría aún las frecuencias. Primero haría el backup y analizaría boot/device tree; cambiar el DVFS antes de conocer los OPP y voltajes puede provocar inestabilidad o un bootloop. Siguiente paso Ejecuta solo estos tres comandos y pásame la salida: adb shell id adb shell 'dd if=/dev/block/mmcblk0 of=/dev/null bs=1M count=1' adb shell 'cat /sys/class/block/mmcblk0/device/{name,manfid,type}' Con eso confirmamos que adbd=root puede leer el eMMC directamente y después te doy el procedimiento exacto para sacar la imagen completa de 15.6 GB y verificar su integridad antes de tocar el firmware. Perfecto. Esto cambia bastante el diagnóstico: el Device Tree contiene OPPs de 1.344 GHz y 1.512 GHz, aunque cpufreq solo está exponiendo hasta 1.296 GHz. Además, el echo 1608000 que acabas de hacer no ha creado ni activado nada peligroso por sí mismo. Si el kernel no tiene ese OPP disponible para la policy, simplemente no lo acepta como frecuencia efectiva. Hay que aprovechar la información que ya tenemos antes de tocar el DT. 1. Primero comprueba qué ha hecho realmente ese echo Ejecuta: adb shell "cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_max_freq" y: adb shell "cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_available_frequencies" y: adb shell "cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_cur_freq" 2. Ahora vamos a leer los voltajes de los OPP interesantes Ejecuta: adb shell "od -An -tu4 /sys/firmware/devicetree/base/opp_l_table/opp@1296000000-0/opp-microvolt" adb shell "od -An -tu4 /sys/firmware/devicetree/base/opp_l_table/opp@1344000000/opp-microvolt" adb shell "od -An -tu4 /sys/firmware/devicetree/base/opp_l_table/opp@1512000000/opp-microvolt" Y también sus frecuencias: adb shell "od -An -tu4 /sys/firmware/devicetree/base/opp_l_table/opp@1344000000/opp-hz" adb shell "od -An -tu4 /sys/firmware/devicetree/base/opp_l_table/opp@1512000000/opp-hz" Lo interesante Tu tabla contiene: OPP Situación 480 MHz expuesto 600 MHz expuesto 792 MHz expuesto 1008 MHz expuesto 1200 MHz expuesto 1296 MHz máximo actual 1344 MHz existe en DT 1512 MHz existe en DT Eso es una señal muy buena. No vamos a inventarnos una frecuencia ni un voltaje desde cero: aparentemente el fabricante dejó OPPs superiores en el Device Tree pero el firmware/kernel actual está limitando la policy a 1296 MHz. También explica por qué quiero mirar los opp-microvolt: necesitamos saber si 1344 y 1512 tienen voltajes definidos razonables y, sobre todo, por qué cpufreq-dt no los está incorporando a scaling_available_frequencies. Y una corrección importante No sigamos usando su -c. Ya tienes: uid=0(root) gracias a: adb root Así que todos los comandos que te dé a partir de ahora pueden ser directamente: adb shell "..." Eso nos simplifica bastante el procedimiento. No escribas todavía en boot, super, vbmeta ni en el Device Tree. Primero quiero ver esos tres voltajes y comprobar si el echo 1608000 cambió realmente scaling_max_freq. Con esos datos podremos decidir si el siguiente paso es simplemente desbloquear 1344 MHz, probar 1512 MHz, o modificar el DT/boot image. PS C:\Users\Paterna> adb shell "od -An -tx4 /sys/firmware/devicetree/base/cpus/cpu@0/operating-points-v2" d6000000 PS C:\Users\Paterna> adb shell "find /sys/firmware/devicetree/base -type f -name 'opp-hz'" /sys/firmware/devicetree/base/opp_l_table/opp@480000000-0/opp-hz /sys/firmware/devicetree/base/opp_l_table/opp@792000000-0/opp-hz /sys/firmware/devicetree/base/opp_l_table/opp@1200000000-1/opp-hz /sys/firmware/devicetree/base/opp_l_table/opp@1008000000-2/opp-hz /sys/firmware/devicetree/base/opp_l_table/opp@1296000000-0/opp-hz /sys/firmware/devicetree/base/opp_l_table/opp@1008000000-0/opp-hz /sys/firmware/devicetree/base/opp_l_table/opp@600000000-0/opp-hz /sys/firmware/devicetree/base/opp_l_table/opp@480000000-1/opp-hz /sys/firmware/devicetree/base/opp_l_table/opp@792000000-1/opp-hz /sys/firmware/devicetree/base/opp_l_table/opp@1200000000-2/opp-hz /sys/firmware/devicetree/base/opp_l_table/opp@1344000000/opp-hz /sys/firmware/devicetree/base/opp_l_table/opp@1200000000-0/opp-hz /sys/firmware/devicetree/base/opp_l_table/opp@1296000000-1/opp-hz /sys/firmware/devicetree/base/opp_l_table/opp@1008000000-1/opp-hz /sys/firmware/devicetree/base/opp_l_table/opp@600000000-1/opp-hz /sys/firmware/devicetree/base/opp_l_table/opp@1512000000/opp-hz PS C:\Users\Paterna> adb shell "find /sys/firmware/devicetree/base -type f -name 'opp-microvolt'" /sys/firmware/devicetree/base/opp_l_table/opp@480000000-0/opp-microvolt /sys/firmware/devicetree/base/opp_l_table/opp@792000000-0/opp-microvolt /sys/firmware/devicetree/base/opp_l_table/opp@1200000000-1/opp-microvolt /sys/firmware/devicetree/base/opp_l_table/opp@1008000000-2/opp-microvolt /sys/firmware/devicetree/base/opp_l_table/opp@1296000000-0/opp-microvolt /sys/firmware/devicetree/base/opp_l_table/opp@1008000000-0/opp-microvolt /sys/firmware/devicetree/base/opp_l_table/opp@600000000-0/opp-microvolt /sys/firmware/devicetree/base/opp_l_table/opp@480000000-1/opp-microvolt /sys/firmware/devicetree/base/opp_l_table/opp@792000000-1/opp-microvolt /sys/firmware/devicetree/base/opp_l_table/opp@1200000000-2/opp-microvolt /sys/firmware/devicetree/base/opp_l_table/opp@1344000000/opp-microvolt /sys/firmware/devicetree/base/opp_l_table/opp@1200000000-0/opp-microvolt /sys/firmware/devicetree/base/opp_l_table/opp@1296000000-1/opp-microvolt /sys/firmware/devicetree/base/opp_l_table/opp@1008000000-1/opp-microvolt /sys/firmware/devicetree/base/opp_l_table/opp@600000000-1/opp-microvolt /sys/firmware/devicetree/base/opp_l_table/opp@1512000000/opp-microvolt PS C:\Users\Paterna> adb shell "find /sys/firmware/devicetree/base -type d -iname '*opp*'" /sys/firmware/devicetree/base/opp_l_table /sys/firmware/devicetree/base/opp_l_table/opp@480000000-0 /sys/firmware/devicetree/base/opp_l_table/opp@792000000-0 /sys/firmware/devicetree/base/opp_l_table/opp@1200000000-1 /sys/firmware/devicetree/base/opp_l_table/opp@1008000000-2 /sys/firmware/devicetree/base/opp_l_table/opp@1296000000-0 /sys/firmware/devicetree/base/opp_l_table/opp@1008000000-0 /sys/firmware/devicetree/base/opp_l_table/opp@600000000-0 /sys/firmware/devicetree/base/opp_l_table/opp@480000000-1 /sys/firmware/devicetree/base/opp_l_table/opp@792000000-1 /sys/firmware/devicetree/base/opp_l_table/opp@1200000000-2 /sys/firmware/devicetree/base/opp_l_table/opp@1344000000 /sys/firmware/devicetree/base/opp_l_table/opp@1200000000-0 /sys/firmware/devicetree/base/opp_l_table/opp@1296000000-1 /sys/firmware/devicetree/base/opp_l_table/opp@1008000000-1 /sys/firmware/devicetree/base/opp_l_table/opp@600000000-1 /sys/firmware/devicetree/base/opp_l_table/opp@1512000000 PS C:\Users\Paterna> adb shell "cat /sys/firmware/devicetree/base/cpus/cpu@0/cpu-supply | od -An -tx4" d8000000 PS C:\Users\Paterna> adb shell "echo 1608000 > /sys/devices/system/cpu/cpu0/cpufreq/scaling_max_freq" PS C:\Users\Paterna> PS C:\Users\Paterna> PS C:\Users\Paterna> PS C:\Users\Paterna> PS C:\Users\Paterna> PS C:\Users\Paterna> adb shell "cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_max_freq" 1296000 PS C:\Users\Paterna> adb shell "cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_available_frequencies" 480000 600000 792000 1008000 1200000 1296000 PS C:\Users\Paterna> adb shell "cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_cur_freq" 1296000 PS C:\Users\Paterna> adb shell "od -An -tu4 /sys/firmware/devicetree/base/opp_l_table/opp@1296000000-0/opp-microvolt" 3771207680 PS C:\Users\Paterna> adb shell "od -An -tu4 /sys/firmware/devicetree/base/opp_l_table/opp@1344000000/opp-microvolt" 1511680 PS C:\Users\Paterna> adb shell "od -An -tu4 /sys/firmware/devicetree/base/opp_l_table/opp@1512000000/opp-microvolt" 1511680 PS C:\Users\Paterna> adb shell "od -An -tu4 /sys/firmware/devicetree/base/opp_l_table/opp@1344000000/opp-hz" 0 13638480 PS C:\Users\Paterna> adb shell "od -An -tu4 /sys/firmware/devicetree/base/opp_l_table/opp@1512000000/opp-hz" 0 4857690 PS C:\Users\Paterna> Ahora sí tenemos una pista muy clara. Lo que acabamos de confirmar El echo 1608000 no tuvo efecto: scaling_max_freq = 1296000 Eso era esperable: cpufreq-dt está construyendo la policy con solo estos OPP: 480 600 792 1008 1200 1296 MHz Pero el Device Tree sí contiene: 1344 MHz 1512 MHz y ambos tienen opp-microvolt. Hay además algo importante: los valores que te ha mostrado od están afectados por el endianness del Device Tree. Por tanto, no debemos interpretar 1511680 directamente como "1.511680 V". Hay que decodificar correctamente las propiedades de 32 bits big-endian. Antes de modificar nada: vamos a identificar por qué esos dos OPP están ocultos El siguiente paso es comprobar las propiedades completas de esos nodos, especialmente si tienen: opp-status = "disabled" opp-supported-hw opp-level clock-latency-ns alguna propiedad específica de Allwinner. Ejecuta estos comandos tal cual: adb shell "ls -la /sys/firmware/devicetree/base/opp_l_table/opp@1344000000/" adb shell "ls -la /sys/firmware/devicetree/base/opp_l_table/opp@1512000000/" Luego: adb shell "for f in /sys/firmware/devicetree/base/opp_l_table/opp@1344000000/*; do echo ==== $f; od -An -tx1 $f; done" y: adb shell "for f in /sys/firmware/devicetree/base/opp_l_table/opp@1512000000/*; do echo ==== $f; od -An -tx1 $f; done" PowerShell ya nos está respetando las comillas de adb shell, así que este formato debería funcionar. Y una comprobación especialmente importante Quiero saber qué opp-table está viendo realmente el kernel: adb shell "ls -la /sys/devices/system/cpu/cpufreq/policy0/" y: adb shell "cat /sys/devices/system/cpu/cpufreq/policy0/scaling_available_frequencies" y: adb shell "cat /sys/devices/system/cpu/cpufreq/policy0/scaling_max_freq" Por qué todavía no tocaría el DT Tenemos una situación bastante favorable: DT: 1296 MHz → activo 1344 MHz → presente 1512 MHz → presente cpufreq: 1296 MHz → máximo Esto sugiere que 1344/1512 pueden estar deshabilitados por alguna condición del OPP, pero todavía no sabemos cuál. Y hay una diferencia enorme entre: "El fabricante incluyó esos OPP pero los dejó disabled." y: "El fabricante incluyó esos OPP para otra variante/revisión del SoC y no son seguros para esta unidad." No quiero que saltemos directamente a cambiar opp-status sin averiguarlo. No necesitas hacer backup de tus datos para este paso. Tampoco estamos escribiendo en flash todavía; solo estamos leyendo el Device Tree que el kernel está utilizando actualmente. Pásame esas cuatro salidas y, si efectivamente están disabled, podremos intentar primero habilitar 1344 MHz, que es el salto conservador desde 1296, antes de meternos con 1512 MHz. PS C:\Users\Paterna> adb shell "cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_max_freq" 1296000 PS C:\Users\Paterna> adb shell "cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_available_frequencies" 480000 600000 792000 1008000 1200000 1296000 PS C:\Users\Paterna> adb shell "cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_cur_freq" 1296000 PS C:\Users\Paterna> adb shell "od -An -tu4 /sys/firmware/devicetree/base/opp_l_table/opp@1296000000-0/opp-microvolt" 3771207680 PS C:\Users\Paterna> adb shell "od -An -tu4 /sys/firmware/devicetree/base/opp_l_table/opp@1344000000/opp-microvolt" 1511680 PS C:\Users\Paterna> adb shell "od -An -tu4 /sys/firmware/devicetree/base/opp_l_table/opp@1512000000/opp-microvolt" 1511680 PS C:\Users\Paterna> adb shell "od -An -tu4 /sys/firmware/devicetree/base/opp_l_table/opp@1344000000/opp-hz" 0 13638480 PS C:\Users\Paterna> adb shell "od -An -tu4 /sys/firmware/devicetree/base/opp_l_table/opp@1512000000/opp-hz" 0 4857690 PS C:\Users\Paterna> PS C:\Users\Paterna> PS C:\Users\Paterna> PS C:\Users\Paterna> PS C:\Users\Paterna> PS C:\Users\Paterna> adb shell "ls -la /sys/firmware/devicetree/base/opp_l_table/opp@1344000000/" total 0 drwxr-xr-x 2 root root 0 2026-08-26 23:19 . drwxr-xr-x 18 root root 0 2026-08-26 23:19 .. -r--r--r-- 1 root root 4 2026-08-26 23:19 clock-latency-ns -r--r--r-- 1 root root 4 2026-08-26 23:19 name -r--r--r-- 1 root root 8 2026-08-26 23:19 opp-hz -r--r--r-- 1 root root 4 2026-08-26 23:19 opp-microvolt -r--r--r-- 1 root root 4 2026-08-26 23:19 opp-supported-hw PS C:\Users\Paterna> adb shell "ls -la /sys/firmware/devicetree/base/opp_l_table/opp@1512000000/" total 0 drwxr-xr-x 2 root root 0 2026-08-26 23:19 . drwxr-xr-x 18 root root 0 2026-08-26 23:19 .. -r--r--r-- 1 root root 4 2026-08-26 23:19 clock-latency-ns -r--r--r-- 1 root root 4 2026-08-26 23:19 name -r--r--r-- 1 root root 8 2026-08-26 23:19 opp-hz -r--r--r-- 1 root root 4 2026-08-26 23:19 opp-microvolt -r--r--r-- 1 root root 4 2026-08-26 23:19 opp-supported-hw PS C:\Users\Paterna> adb shell "for f in /sys/firmware/devicetree/base/opp_l_table/opp@1344000000/*; do echo ==== $f; od -An -tx1 $f; done" ==== PS C:\Users\Paterna> adb shell "for f in /sys/firmware/devicetree/base/opp_l_table/opp@1344000000/*; do echo ==== $f; od -An -tx1 $f; done" ==== PS C:\Users\Paterna> adb shell "for f in /sys/firmware/devicetree/base/opp_l_table/opp@1512000000/*; do echo ==== $f; od -An -tx1 $f; done" ==== PS C:\Users\Paterna> adb shell "ls -la /sys/devices/system/cpu/cpufreq/policy0/"adb shell "ls -la /sys/devices/system/cpu/cpufreq/policy0/" ls: adb: No such file or directory ls: shell: No such file or directory ls: ls: No such file or directory /sys/devices/system/cpu/cpufreq/policy0/: total 0 drwxr-xr-x 2 root root 0 2026-08-26 22:46:25.670003634 +0100 . drwxr-xr-x 4 root root 0 2026-08-26 22:46:25.670003634 +0100 .. -r--r--r-- 1 root root 4096 2026-08-26 23:17:28.523524141 +0100 affected_cpus -r-------- 1 root root 4096 2026-08-26 22:52:55.986709518 +0100 cpuinfo_cur_freq -r--r--r-- 1 root root 4096 2026-08-26 22:48:18.616681649 +0100 cpuinfo_max_freq -r--r--r-- 1 root root 4096 2026-08-26 22:48:18.636681651 +0100 cpuinfo_min_freq -r--r--r-- 1 root root 4096 2026-08-26 23:17:28.523524141 +0100 cpuinfo_transition_latency -r--r--r-- 1 root root 4096 2026-08-26 23:17:28.523524141 +0100 related_cpus -r--r--r-- 1 root root 4096 2026-08-26 23:14:19.103505108 +0100 scaling_available_frequencies -r--r--r-- 1 root root 4096 2026-08-26 23:17:28.523524141 +0100 scaling_available_governors -r--r--r-- 1 root root 4096 2026-08-26 22:48:18.656681653 +0100 scaling_cur_freq -r--r--r-- 1 root root 4096 2026-08-26 23:17:28.523524141 +0100 scaling_driver -rw-rw---- 1 system system 4096 2026-08-26 22:45:52.471351590 +0100 scaling_governor -rw-rw---- 1 system system 4096 2026-08-26 23:20:11.906873890 +0100 scaling_max_freq -rw-rw-r-- 1 system system 4096 2026-08-26 22:45:50.510277601 +0100 scaling_min_freq -rw-r--r-- 1 root root 4096 2026-08-26 23:17:28.523524141 +0100 scaling_setspeed /sys/devices/system/cpu/cpufreq/policy0/: total 0 drwxr-xr-x 2 root root 0 2026-08-26 22:46:25.670003634 +0100 . drwxr-xr-x 4 root root 0 2026-08-26 22:46:25.670003634 +0100 .. -r--r--r-- 1 root root 4096 2026-08-26 23:17:28.523524141 +0100 affected_cpus -r-------- 1 root root 4096 2026-08-26 22:52:55.986709518 +0100 cpuinfo_cur_freq -r--r--r-- 1 root root 4096 2026-08-26 22:48:18.616681649 +0100 cpuinfo_max_freq -r--r--r-- 1 root root 4096 2026-08-26 22:48:18.636681651 +0100 cpuinfo_min_freq -r--r--r-- 1 root root 4096 2026-08-26 23:17:28.523524141 +0100 cpuinfo_transition_latency -r--r--r-- 1 root root 4096 2026-08-26 23:17:28.523524141 +0100 related_cpus -r--r--r-- 1 root root 4096 2026-08-26 23:14:19.103505108 +0100 scaling_available_frequencies -r--r--r-- 1 root root 4096 2026-08-26 23:17:28.523524141 +0100 scaling_available_governors -r--r--r-- 1 root root 4096 2026-08-26 22:48:18.656681653 +0100 scaling_cur_freq -r--r--r-- 1 root root 4096 2026-08-26 23:17:28.523524141 +0100 scaling_driver -rw-rw---- 1 system system 4096 2026-08-26 22:45:52.471351590 +0100 scaling_governor -rw-rw---- 1 system system 4096 2026-08-26 23:20:11.906873890 +0100 scaling_max_freq -rw-rw-r-- 1 system system 4096 2026-08-26 22:45:50.510277601 +0100 scaling_min_freq -rw-r--r-- 1 root root 4096 2026-08-26 23:17:28.523524141 +0100 scaling_setspeed PS C:\Users\Paterna> adb shell "cat /sys/devices/system/cpu/cpufreq/policy0/scaling_available_frequencies" 480000 600000 792000 1008000 1200000 1296000 PS C:\Users\Paterna> adb shell "cat /sys/devices/system/cpu/cpufreq/policy0/scaling_max_freq" 1296000 PS C:\Users\Paterna> Sí. Con lo que acabas de sacar, ya podemos ir al grano, y además tenemos una conclusión importante: Los 4 núcleos (cpu0-3) comparten una sola policy (policy0). Driver: cpufreq-dt. Frecuencias activas: 480 / 600 / 792 / 1008 / 1200 / 1296 MHz. Máximo efectivo actual: 1296 MHz. El intento de echo 1608000 > scaling_max_freq fue rechazado silenciosamente por el kernel y volvió a quedar en 1296000. Sin embargo, el Device Tree sí contiene OPPs de 1344 MHz y 1512 MHz. Eso último es precisamente lo interesante. Pero hay una pista todavía más importante Los OPP adicionales: opp@1344000000 opp@1512000000 existen en el Device Tree, pero no aparecen en scaling_available_frequencies. Eso normalmente significa que esos OPP están presentes en la tabla DT pero no están habilitados/seleccionados para este hardware, probablemente mediante opp-supported-hw o por la lógica del proveedor/SoC. Y aquí tenemos que comprobarlo antes de tocar nada. No necesitamos hacer backup para estas comprobaciones de lectura. No vamos a modificar todavía el sistema. Siguiente paso Ejecuta exactamente estos comandos. He corregido además el problema que tuviste con el for: PowerShell está interfiriendo con $f, así que no lo vamos a usar. 1. Leer opp-supported-hw adb shell "od -An -tx1 /sys/firmware/devicetree/base/opp_l_table/opp@1344000000/opp-supported-hw" adb shell "od -An -tx1 /sys/firmware/devicetree/base/opp_l_table/opp@1512000000/opp-supported-hw" 2. Leer correctamente los voltajes adb shell "od -An -tx1 /sys/firmware/devicetree/base/opp_l_table/opp@1344000000/opp-microvolt" adb shell "od -An -tx1 /sys/firmware/devicetree/base/opp_l_table/opp@1512000000/opp-microvolt" 3. Y comprobar los OPP que SÍ están activos adb shell "od -An -tx1 /sys/firmware/devicetree/base/opp_l_table/opp@1296000000-0/opp-supported-hw" adb shell "od -An -tx1 /sys/firmware/devicetree/base/opp_l_table/opp@1296000000-0/opp-microvolt" 4. Comprobar qué governors ofrece adb shell "cat /sys/devices/system/cpu/cpufreq/policy0/scaling_available_governors" Y: adb shell "cat /sys/devices/system/cpu/cpufreq/policy0/scaling_governor" No escribas nada más en /sys todavía. Con esos resultados podremos determinar si 1344 MHz o 1512 MHz son OPP reales pero deshabilitados, y si hay una vía razonablemente segura para habilitarlos. El hecho de que el kernel rechace 1608 MHz ya nos confirma que no podemos simplemente subir scaling_max_freq desde userspace. Y sí: para esta fase no hace falta backup. Primero vamos a identificar exactamente qué nos permite el firmware/kernel; luego decidimos si merece la pena modificarlo.