My HMUF02-V05 struggling

New here? Say hello and tell us about your device
Post Reply
Sergey
Posts: 1
Joined: Fri Jun 12, 2026 11:35 am

My HMUF02-V05 struggling

Post by Sergey »

Hello folks,
My name is Sergey, and I'm alcoholic :)
Got stuck with my HMUF02-V05 at LTE and Wi-Fi firmware files extraction from original android.
My modem partition has NON-HLOS.bin file inside, and I have no clue how to grab necessary firmware files out of it.
@felix, will appreciate your help for that.
Thank you in advance.
Sergey
Posts: 1
Joined: Fri Jun 12, 2026 11:35 am

Re: My HMUF02-V05 struggling

Post by Sergey »

Finally I managed to get 56 files from Android modem partition :D
Next step - flash Debian and put that bloody files at their place
felix
Site Admin
Posts: 17
Joined: Sat Oct 04, 2025 4:48 pm

Re: My HMUF02-V05 struggling

Post by felix »

how did it worked?
do you still need any help?
Sergey
Posts: 1
Joined: Fri Jun 12, 2026 11:35 am

Re: My HMUF02-V05 struggling

Post by Sergey »

Hello Felix,
I managed to put all original firmware files from android modem.img to \lib\firmware folder of Openstick.
Looks like Openstick sees a new firmware, but sim-missing error is still exist.
Here are mmcli results:
1. Before
root@openstick:/# mmcli -m 0
-----------------------------
General | path: /org/freedesktop/ModemManager1/Modem/0
| device id: a14605598dcc94f2dc5017e3a2200a4d899cb8bf
-----------------------------
Hardware | manufacturer: QUALCOMM INCORPORATED
| model: 0
| firmware revision: UFI001CT 20211106 1 [Nov 04 2016 02:00:00]
| carrier config: default
| h/w revision: 10000
| supported: gsm-umts
| current: gsm-umts
-----------------------------
System | device: qcom-soc
| drivers: qcom-q6v5-mss, bam-dmux
| plugin: qcom-soc
| primary port: wwan0qmi0
| ports: wwan0 (net), wwan0at0 (at), wwan0qmi0 (qmi), wwan1 (net),
| wwan2 (net), wwan3 (net), wwan4 (net), wwan5 (net), wwan6 (net),
| wwan7 (net)
-----------------------------
Status | state: failed
| failed reason: sim-missing
| signal quality: 0% (cached)
-----------------------------
Modes | supported: allowed: 3g; preferred: none
| current: allowed: any; preferred: none
-----------------------------
Bands | supported: utran-1
-----------------------------
IP | supported: ipv4, ipv6, ipv4v6

2. After
root@openstick:/# mmcli -m /org/freedesktop/ModemManager1/Modem/0
-----------------------------------
General | path: /org/freedesktop/ModemManager1/Modem/0
| device id: 094230c665d72a10fcfe6f634c521aeb2f583290
-----------------------------------
Hardware | manufacturer: 1
| model: 0
| firmware revision: HIMI_U01_MODEM_V2.0 1 [May 13 2022 13:00:00]
| carrier config: ROW_Generic_3GPP
| carrier config revision: 02010801
| h/w revision: 10000
| supported: gsm-umts, lte
| current: gsm-umts, lte
| equipment id: 000000000000000
-----------------------------------
System | device: qcom-soc
| drivers: qcom-q6v5-mss, bam-dmux
| plugin: qcom-soc
| primary port: wwan0qmi0
| ports: wwan0 (net), wwan0at0 (at), wwan0qmi0 (qmi), wwan1 (net),
| wwan2 (net), wwan3 (net), wwan4 (net), wwan5 (net), wwan6 (net),
| wwan7 (net)
-----------------------------------
Status | state: failed
| failed reason: sim-missing
| signal quality: 0% (cached)
-----------------------------------
Modes | supported: allowed: 3g; preferred: none
| allowed: 4g; preferred: none
| allowed: 3g, 4g; preferred: 4g
| allowed: 3g, 4g; preferred: 3g
| current: allowed: any; preferred: none
-----------------------------------
Bands | supported: utran-1, utran-5, utran-8, eutran-1, eutran-3, eutran-5,
| eutran-8
-----------------------------------
IP | supported: ipv4, ipv6, ipv4v6

Looks like modem firmware is newer than it is in original openstick image.

But I don't know what to do further to fix sim-missing error. Will appreciate for hints/ideas.
Sergey
Posts: 1
Joined: Fri Jun 12, 2026 11:35 am

Re: My HMUF02-V05 struggling

Post by Sergey »

Found a guy who went further with my board, but stuck at right dts.
https://forum.openwrt.org/t/help-adding ... v05/225828

Looks like physical sim slot (esims are not soldered in) is not set as "active" by default.

Felix, do you have any idea how to swith physical sim slot on?

P.S. Original dts for HMUF02-V05 lays here:
https://gist.github.com/hotfur/b4b6db67 ... f3094e774a
felix
Site Admin
Posts: 17
Joined: Sat Oct 04, 2025 4:48 pm

Re: My HMUF02-V05 struggling

Post by felix »

Get the reference from stock EDL Android.
Boot stock, insert a physical SIM, confirm it registers, then "cat /sys/kernel/debug/gpio".
That dump is the exact known-good state of esim1/2/3_en + sim_hotplug.
Replicate those states under Handsomes Mobian, then compare.

Under Mobian:
install gpiod
gpiodetect # find chips, e.g. gpiochip0
gpioinfo # lines + names + who's using them ("used"/"unused")
gpioget gpiochip0 119 # read line 119 (= esim1_en offset)
gpioset gpiochip0 119=1 # drive HIGH

set gpio the same as android
or use claude code to do this
Sergey
Posts: 1
Joined: Fri Jun 12, 2026 11:35 am

Re: My HMUF02-V05 struggling

Post by Sergey »

Hi Felix,

Just did the first part of my homework. Sorry, but I'm as dumb as Donald Trump :(

Here comes the results of "cat /sys/kernel/debug/gpio" command:

1. Stock Android
shell@UFI:/ $ cat /sys/kernel/debug/gpio
GPIOs 577-608, platform/qcom,smp2pgpio-ssr-smp2p-4-out.19, master-kernel:

GPIOs 609-640, platform/qcom,smp2pgpio-ssr-smp2p-4-in.18, slave-kernel:

GPIOs 641-672, platform/qcom,smp2pgpio-ssr-smp2p-1-out.13, master-kernel:

GPIOs 673-704, platform/qcom,smp2pgpio-ssr-smp2p-1-in.12, slave-kernel:

GPIOs 705-736, platform/qcom,smp2pgpio-smp2p-4-out.16, smp2p:

GPIOs 737-768, platform/qcom,smp2pgpio-smp2p-4-in.14, smp2p:

GPIOs 769-800, platform/qcom,smp2pgpio-smp2p-1-out.10, smp2p:

GPIOs 801-832, platform/qcom,smp2pgpio-smp2p-1-in.8, smp2p:

GPIOs 833-864, platform/qcom,smp2pgpio-smp2p-7-out.6, smp2p:

GPIOs 865-896, platform/qcom,smp2pgpio-smp2p-7-in.4, smp2p:

GPIOs 897-900, spmi/qpnp-pin-de6e4c00, pm8916-gpio:

GPIOs 901-901, spmi/qpnp-pin-de6e4a00, pm8916-mpp:

GPIOs 902-1023, platform/1000000.pinctrl, msm_tlmm_v4_gpio:
gpio-914 (esim3_en ) out lo
gpio-916 (esim2_en ) out lo
gpio-938 (bat1 ) out lo
gpio-939 (key_freset ) in lo
gpio-940 (exvus ) out lo
gpio-973 (4g_1 ) out lo
gpio-974 (4g_type ) out lo
gpio-975 (wifistatus ) out hi
gpio-1008 (ftest ) out lo
gpio-1012 (USB_ID_GPIO ) in hi
gpio-1016 (sim_hotplug ) out lo
gpio-1018 (disp_dc ) in hi
gpio-1019 (disp_rst_n ) in hi
gpio-1021 (esim1_en ) out hi

2. Debian
root@openstick:/# cat /sys/kernel/debug/gpio
gpiochip2: GPIOs 382-385, parent: platform/200f000.spmi:pmic@0:gpios@c000, 200f000.spmi:pmic@0:gpios@c000:
gpio1 : in low normal vin-0 pull-down 10uA push-pull high atest-0 dtest-0
gpio2 : in low normal vin-0 pull-down 10uA push-pull high atest-0 dtest-0
gpio3 : out low normal vin-0 pull-down 10uA push-pull high atest-0 dtest-0
gpio4 : out low normal vin-0 pull-down 10uA push-pull high atest-0 dtest-0

gpiochip1: GPIOs 386-389, parent: platform/200f000.spmi:pmic@0:mpps@a000, 200f000.spmi:pmic@0:mpps@a000:
mpp1 : out analog vin-2 0 high
mpp2 : ---
mpp3 : ---
mpp4 : ---
gpiochip0: GPIOs 390-511, parent: platform/1000000.pinctrl, 1000000.pinctrl:
gpio0 : out low func0 2mA pull down
gpio1 : out low func0 2mA pull down
gpio2 : out high func0 2mA pull down
gpio3 : out low func0 2mA pull down
gpio4 : out low func2 16mA no pull
gpio5 : out low func2 16mA no pull
gpio6 : in low func0 2mA pull down
gpio7 : in low func0 2mA pull down
gpio8 : in low func0 2mA pull down
gpio9 : in low func0 2mA pull down
gpio10 : in low func0 2mA pull down
gpio11 : in low func0 2mA pull down
gpio12 : in low func0 2mA pull down
gpio13 : in low func0 2mA pull down
gpio14 : in low func0 2mA pull down
gpio15 : in low func0 2mA pull down
gpio16 : in low func0 2mA pull down
gpio17 : in low func0 2mA pull down
gpio18 : in low func0 2mA pull down
gpio19 : in low func0 2mA pull down
gpio20 : out low func0 2mA pull up
gpio21 : out low func0 2mA pull down
gpio22 : out low func0 2mA pull down
gpio23 : in low func0 2mA pull down
gpio24 : in low func0 2mA pull down
gpio25 : in low func0 2mA pull down
gpio26 : in low func0 2mA pull down
gpio27 : in low func0 2mA pull down
gpio28 : in low func0 2mA pull down
gpio29 : in low func0 2mA pull down
gpio30 : in low func0 2mA pull down
gpio31 : in low func0 2mA pull down
gpio32 : in low func0 2mA pull down
gpio33 : in low func0 2mA pull down
gpio34 : in low func0 2mA pull down
gpio35 : in low func0 2mA pull down
gpio36 : in low func0 2mA pull down
gpio37 : in high func0 8mA pull up
gpio38 : in low func0 2mA pull down
gpio39 : in low func0 2mA pull down
gpio40 : in low func1 6mA pull down
gpio41 : in high func1 6mA pull down
gpio42 : in low func1 6mA pull down
gpio43 : in low func1 6mA pull down
gpio44 : in low func1 6mA pull down
gpio45 : in low func0 2mA pull down
gpio46 : in low func0 2mA pull down
gpio47 : in low func0 2mA pull down
gpio48 : in low func0 2mA pull down
gpio49 : in low func0 2mA pull down
gpio50 : in low func0 2mA pull down
gpio51 : in low func0 2mA pull down
gpio52 : in low func0 2mA pull down
gpio53 : in low func0 2mA pull down
gpio54 : in low func0 2mA pull down
gpio55 : in low func0 2mA pull down
gpio56 : in low func0 2mA pull down
gpio57 : out low func0 16mA no pull
gpio58 : out low func0 16mA no pull
gpio59 : out low func0 2mA no pull
gpio60 : in high func1 2mA pull up
gpio61 : out low func1 2mA no pull
gpio62 : in low func0 2mA pull down
gpio63 : in low func0 2mA pull down
gpio64 : in low func0 2mA pull down
gpio65 : in low func0 2mA pull down
gpio66 : in low func0 2mA pull down
gpio67 : in low func0 2mA pull down
gpio68 : in low func0 2mA pull down
gpio69 : in low func0 2mA pull down
gpio70 : in low func0 2mA pull down
gpio71 : in low func0 2mA pull down
gpio72 : in low func0 2mA pull down
gpio73 : in low func0 2mA pull down
gpio74 : in low func0 2mA pull down
gpio75 : in low func0 2mA pull down
gpio76 : in low func0 2mA pull down
gpio77 : in low func0 2mA pull down
gpio78 : in low func0 2mA pull down
gpio79 : in low func0 2mA pull down
gpio80 : in low func0 2mA pull down
gpio81 : in low func0 2mA pull down
gpio82 : in low func0 2mA pull down
gpio83 : in low func0 2mA pull down
gpio84 : in low func0 2mA pull down
gpio85 : in low func0 2mA pull down
gpio86 : in low func0 2mA pull down
gpio87 : in low func0 2mA pull down
gpio88 : in low func0 2mA pull down
gpio89 : in low func0 2mA pull down
gpio90 : in low func0 2mA pull down
gpio91 : in low func0 2mA pull down
gpio92 : in low func0 2mA pull down
gpio93 : in low func0 2mA pull down
gpio94 : in low func0 2mA pull down
gpio95 : in low func0 2mA pull down
gpio96 : in low func0 2mA pull down
gpio97 : in low func0 2mA pull down
gpio98 : in low func0 2mA pull down
gpio99 : in low func0 2mA pull down
gpio100 : in low func0 2mA pull down
gpio101 : in low func0 2mA pull down
gpio102 : in low func0 2mA pull down
gpio103 : in low func0 2mA pull down
gpio104 : in low func0 2mA pull down
gpio105 : in low func0 2mA pull down
gpio106 : in low func0 2mA pull down
gpio107 : in high func0 2mA pull up
gpio108 : in low func0 2mA pull down
gpio109 : in low func0 2mA pull down
gpio110 : in low func0 2mA pull down
gpio111 : in low func0 2mA pull down
gpio112 : in low func0 2mA pull down
gpio113 : in low func0 2mA pull down
gpio114 : in low func0 2mA pull down
gpio115 : in low func0 2mA pull down
gpio116 : in low func0 2mA pull down
gpio117 : in low func0 2mA pull down
gpio118 : in low func0 2mA pull down
gpio119 : in low func0 2mA pull down
gpio120 : in low func0 2mA pull down
gpio121 : in high func0 8mA pull up
felix
Site Admin
Posts: 17
Joined: Sat Oct 04, 2025 4:48 pm

Re: My HMUF02-V05 struggling

Post by felix »

Hi :)
try:
# esim1_en = 509, esim2_en = 404, esim3_en = 402, sim_hotplug = 504
for g in 509 404 402 504; do echo $g > /sys/class/gpio/export 2>/dev/null; done

# match stock Android EXACTLY — direction first, then value
echo out > /sys/class/gpio/gpio509/direction; echo 1 > /sys/class/gpio/gpio509/value # esim1_en HIGH <-- the one that matters
echo out > /sys/class/gpio/gpio404/direction; echo 0 > /sys/class/gpio/gpio404/value # esim2_en LOW
echo out > /sys/class/gpio/gpio402/direction; echo 0 > /sys/class/gpio/gpio402/value # esim3_en LOW
echo out > /sys/class/gpio/gpio504/direction; echo 0 > /sys/class/gpio/gpio504/value # sim_hotplug LOW

# verify — esim1_en should now read "out hi"
cat /sys/kernel/debug/gpio | grep -E '119|509|esim1'

then:
mmcli -m any --reset # or: systemctl restart ModemManager
sleep 8
mmcli -m 0 # look for state leaving "sim-missing"


then tell me the output
Sergey
Posts: 1
Joined: Fri Jun 12, 2026 11:35 am

Re: My HMUF02-V05 struggling

Post by Sergey »

root@openstick:/# gpioget gpiochip0 119
0

root@openstick:/# for g in 509 404 402 504; do echo $g > /sys/class/gpio/export 2>/dev/null; done
root@openstick:/# echo out > /sys/class/gpio/gpio509/direction
root@openstick:/# echo 1 > /sys/class/gpio/gpio509/value
root@openstick:/# echo out > /sys/class/gpio/gpio404/direction
root@openstick:/# echo 0 > /sys/class/gpio/gpio404/value
root@openstick:/# echo out > /sys/class/gpio/gpio402/direction
root@openstick:/# echo 0 > /sys/class/gpio/gpio402/value
root@openstick:/# echo out > /sys/class/gpio/gpio504/direction
root@openstick:/# echo 0 > /sys/class/gpio/gpio504/value
root@openstick:/# cat /sys/kernel/debug/gpio | grep -E '119|509|esim1'
gpio119 : out high func0 2mA pull down
root@openstick:/# systemctl restart ModemManager
root@openstick:/# sleep 8
root@openstick:/# mmcli -m 0
-----------------------------------
General | path: /org/freedesktop/ModemManager1/Modem/0
| device id: 094230c665d72a10fcfe6f634c521aeb2f583290
-----------------------------------
Hardware | manufacturer: 1
| model: 0
| firmware revision: HIMI_U01_MODEM_V2.0 1 [May 13 2022 13:00:00]
| carrier config: ROW_Generic_3GPP
| carrier config revision: 02010801
| h/w revision: 10000
| supported: gsm-umts, lte
| current: gsm-umts, lte
| equipment id: 000000000000000
-----------------------------------
System | device: qcom-soc
| drivers: bam-dmux, qcom-q6v5-mss
| plugin: qcom-soc
| primary port: wwan0qmi0
| ports: wwan0 (net), wwan0at0 (at), wwan0qmi0 (qmi), wwan1 (net),
| wwan2 (net), wwan3 (net), wwan4 (net), wwan5 (net), wwan6 (net),
| wwan7 (net)
-----------------------------------
Status | state: failed
| failed reason: sim-missing
| signal quality: 0% (cached)
-----------------------------------
Modes | supported: allowed: 3g; preferred: none
| allowed: 4g; preferred: none
| allowed: 3g, 4g; preferred: 4g
| allowed: 3g, 4g; preferred: 3g
| current: allowed: any; preferred: none
-----------------------------------
Bands | supported: utran-1, utran-5, utran-8, eutran-1, eutran-3, eutran-5,
| eutran-8
-----------------------------------
IP | supported: ipv4, ipv6, ipv4v6

root@openstick:/# gpioget gpiochip0 119
gpioget: error reading GPIO values: Device or resource busy
Last edited by Sergey on Wed Jun 24, 2026 8:57 pm, edited 1 time in total.
felix
Site Admin
Posts: 17
Joined: Sat Oct 04, 2025 4:48 pm

Re: My HMUF02-V05 struggling

Post by felix »

Hi Sergey,
Good news, your GPIO part worked perfectly.
gpio119 : out high confirms esim1_en is HIGH.
The gpioget ... Device or resource busy is harmless: the legacy sysfs export claimed the line, so the char-device gpioget can't grab it. Ignore it.

The reason it's still sim-missing: the modem DSP samples the SIM-enable lines when the modem firmware boots.
Restarting ModemManager only restarts userspace, the DSP keeps its old state.
hotfur hit the exact same wall setting gpio509 HIGH at runtime. So we need the line HIGH before the modem comes up.

#####
Step 1 — prove it without recompiling (restart the modem DSP, not ModemManager):
#####
--------
# esim1_en (509) is still exported & HIGH from before — keep it
grep -H . /sys/class/remoteproc/remoteproc*/name # find the modem/mss one
# say it's remoteproc1:
echo stop > /sys/class/remoteproc/remoteproc1/state
sleep 2
echo start > /sys/class/remoteproc/remoteproc1/state
sleep 10
systemctl restart ModemManager
sleep 8
mmcli -L
mmcli -m 0 # state should leave "sim-missing"
The TLMM line stays HIGH across the DSP restart (it's on the AP, not the DSP), so the modem now boots seeing esim1_en HIGH.
--------
If the state leaves sim-missing → hypothesis confirmed.

#####
Step 2 — make it permanent in the DT.
Your stock dts already has these as gpio-leds.
Just change the default states so the line is driven at kernel boot (offset 119 on TLMM = esim1_en):
dtsesim1_en { ... default-state = "on"; }; /* was "keep" -> HIGH */
esim2_en { ... default-state = "off"; }; /* LOW, matches stock */
esim3_en { ... default-state = "off"; }; /* LOW */
sim_hotplug{ ... default-state = "off"; }; /* LOW */

That reuses the existing nodes, so no GPIO-busy conflict. (Alternatively a gpio-hog on &tlmm with gpios = <119 GPIO_ACTIVE_HIGH>; output-high;
but then you must remove esim1_en from gpio-leds first, or the hog fails with -EBUSY.)
Rebuild the dtb, reboot, modem should come up with the physical SIM detected.

Post the mmcli -m 0 output either way and we'll take it from there.

Greetings :)

also i send you an private message
Post Reply