A thread of (ir)relevant things surrounding the Zebra TC56 (falcon/ironman) or potentially other devices based on the atlas platform. It's a quite underwhelming* Android barcode scanner shitter thingy.
To Be Filled By O.E.M. - considering that there is still ongoing experiments and work on this hardware
*it's test-keys signed and has no secure boot!
The Specification Things:
CPU: 2x ARM Cortex-A72 @ 1.8GHz, 4x ARM Cortex-A53 @ 1.2GHz
Chipset: Qualcomm Snapdragon 618 650 (MSM8956)
GPU: Adreno 510
RAM: 2GB/4GB LPDDR3
Storage: 16GB/32GB eMMC
Ports: 1x USB-C hidden behind a removable "Dock port", 3.5mm Headphone jack
Connectivity: Atheros WiFi+Bluetooth
The Chronological Things:
09.07.2026 - Bought this piece of shit on eBay
... dissociation
21.07.2026 - Ported lk1st to this literal dogshit
The Word Things:
i hate this piece of shit and the company behind it with all the passion I can ever have
The stock bootloader is somehow more stupid than Morc and likes to bring me to my limits, more on this further down in this thread.
Zebra also locks all their firmware behind a support contract paywall, so good luck getting it*
Zebra also does not seem like they are honoring the GPLv2 license in a sane way (that you can just go on their page and download stuff) for their so called touch computers... yayyy
Zebra TC56 - Android "Touch Computer"
Dealing with the (possibly worst i've ever seen) stock bootloader
...I am going to murder every single person involved on creating this annoying piece of shit bootloader.
aaanyways.. one of the problems that it has, is that it is "locked", not in the classic "you cant boot custom binaries on it until you unlock it" but rather in the sense of "you cant execute a single command until you unlock it.
How do you get to this password? well.... zebra in this moment seemingly decided to be "lazy" and have it be "zebra_$(SERIES), so in this case it is "zebra_atlas", which you thrown in an OEM command.
That would be:
After that you can proceed with your regular fastboot commands like as if you were playing with a regularly unlocked device.
Quirks:
aaanyways.. one of the problems that it has, is that it is "locked", not in the classic "you cant boot custom binaries on it until you unlock it" but rather in the sense of "you cant execute a single command until you unlock it.
How do you get to this password? well.... zebra in this moment seemingly decided to be "lazy" and have it be "zebra_$(SERIES), so in this case it is "zebra_atlas", which you thrown in an OEM command.
That would be:
Code: Select all
fastboot oem unlock zebra_atlasQuirks:
- If you try to boot a bad bootimage (say, wrong dtb), when you try to boot anything else afterward, no matter if its correct or not, it will throw you into ramdump (900e) mode
- It's an annoying piece of shit that i hate
- The "unlock" is volatile, you will need to re-unlock each time you boot to fastboot mode
- It seemingly accepts unsigned images no matter what
- Any modifications to the original boot.img from the stock ROM seem to trip some userdata encryption tripwires, forcing you to factory reset the device using the flashable factory reset ZIP.

Dumping the firmware of this annoying shitter
I wanted to dump the firmware on this, so i can have it backed up, that i can root it, and analyze it or god knows whatever people that know stuff do.
i started researching the internet to see what people have done to this device, and similar units.
I stumbled across this XDA (blergh, what happened to that place :/) thread, and decided to see if my device has something similar behind its label and BAM, a wonderful test pad array looking like in that forum picture. i shorted the 2 marked pads and... we are in!
i then ran "bkerler/edl" tool, not being very hopeful that i will get anywhere, due to the (not) available firehoses but observing it.
Until I read the following line right under all of this:
And followed with a rather successful attempt of the loader:
I printed the partition layout:
i then proceeded to run:
and was met with the following folder contents:
For completeness sake, i also dumped the entire eMMC in one go:
i started researching the internet to see what people have done to this device, and similar units.
I stumbled across this XDA (blergh, what happened to that place :/) thread, and decided to see if my device has something similar behind its label and BAM, a wonderful test pad array looking like in that forum picture. i shorted the 2 marked pads and... we are in!
i then ran "bkerler/edl" tool, not being very hopeful that i will get anywhere, due to the (not) available firehoses but observing it.
Code: Select all
Qualcomm Sahara / Firehose Client V3.62 (c) B.Kerler 2018-2025.
main - Trying with no loader given ...
main - Waiting for the device
main - Device detected :)
sahara - Protocol version: 2, Version supported: 1
main - Mode detected: sahara
sahara -
Version 0x2
------------------------
HWID: 0x009b00e100000000 (MSM_ID:0x009b00e1,OEM_ID:0x0000,MODEL_ID:0x0000)
CPU detected: "MSM8956"
PK_HASH: 0xcc3153a80293939b90d02d3bf8b23e0292e452fef662c74998421adad42a380f
Serial: 0x053895cf
Code: Select all
sahara - Possibly unfused device detected, so any loader should be fine...Code: Select all
sahara - Possible loader available: /edlclient/../Loaders/xiaomi/009b00e100000000_57158eaf1814d78f_fhprg_peek.bin
sahara - Trying loader: /edlclient/../Loaders/xiaomi/009b00e100000000_57158eaf1814d78f_fhprg_peek.bin
sahara - Protocol version: 2, Version supported: 1
sahara - Uploading loader /edlclient/../Loaders/xiaomi/009b00e100000000_57158eaf1814d78f_fhprg_peek.bin ...
sahara - 32-Bit mode detected.
sahara - Firehose mode detected, uploading...
sahara - Loader successfully uploaded.
main - Trying to connect to firehose loader ...
firehose_client
firehose_client - [LIB]: No --memory option set, we assume "eMMC" as default ..., if it fails, try using "--memory" with "UFS","NAND" or "spinor" instead !
firehose - TargetName=MSM8976
firehose - MemoryName=eMMC
firehose - Version=1
firehose - Trying to read first storage sector...
firehose - Running configure...
firehose_client - Supported functions:
-----------------
Code: Select all
edl printgptCode: Select all
Parsing Lun 0:
GPT Table:
-------------
modem: Offset 0x0000000004000000, Length 0x0000000005400000, Flags 0x1000000000000000, UUID 6b351a80-6be2-627f-3403-d4171687b8a1, Type EFI_BASIC_DATA, Active False
fsc: Offset 0x000000000c000000, Length 0x0000000000000400, Flags 0x0000000000000000, UUID eac63ae1-c98b-fb46-2177-aff61f8fa6b7, Type 0x57b90a16, Active False
ssd: Offset 0x000000000c000400, Length 0x0000000000002000, Flags 0x0000000000000000, UUID 6f0d1af1-73b3-2b47-7db0-9446e7885b47, Type 0x2c86e742, Active False
sbl1: Offset 0x000000000c002400, Length 0x0000000000080000, Flags 0x0000000000000000, UUID 8391c781-b974-3a87-73de-1fb322d6284a, Type 0xdea0ba2c, Active False
sbl1bak: Offset 0x000000000c082400, Length 0x0000000000080000, Flags 0x0000000000000000, UUID d69a6a5b-62b6-97aa-e41b-1da5a9233567, Type EFI_BASIC_DATA, Active False
rpm: Offset 0x000000000c102400, Length 0x0000000000080000, Flags 0x0000000000000000, UUID dcbb9541-1b67-363c-3f08-f3635313324a, Type 0x98df793, Active False
rpmbak: Offset 0x000000000c182400, Length 0x0000000000080000, Flags 0x0000000000000000, UUID 8ccabe98-db1c-b819-f3fa-78d7e0bf2641, Type EFI_BASIC_DATA, Active False
tz: Offset 0x000000000c202400, Length 0x0000000000200000, Flags 0x0000000000000000, UUID 7b0ef49b-216d-f024-4c53-a8e023e4cb1e, Type 0xa053aa7f, Active False
tzbak: Offset 0x000000000c402400, Length 0x0000000000200000, Flags 0x0000000000000000, UUID a55343c5-368f-9f5e-f16f-f410ae75e2af, Type EFI_BASIC_DATA, Active False
dsp: Offset 0x000000000c602400, Length 0x0000000001000000, Flags 0x0000000000000000, UUID 7117a3f5-a1e5-6b59-4007-4e049642f183, Type EFI_BASIC_DATA, Active False
modemst1: Offset 0x000000000d602400, Length 0x0000000000180000, Flags 0x0000000000000000, UUID abcf8a7f-4ebf-548f-db9c-118c109f2f6d, Type 0xebbeadaf, Active False
modemst2: Offset 0x000000000d782400, Length 0x0000000000180000, Flags 0x0000000000000000, UUID a4054499-878a-d5f7-6cae-b8c3c2c59273, Type 0xa288b1f, Active False
DDR: Offset 0x0000000010000000, Length 0x0000000000008000, Flags 0x1000000000000000, UUID 4ac0f0fa-c72a-cf8c-6933-cf9afefe67ec, Type 0x20a0c19c, Active False
fsg: Offset 0x0000000010008000, Length 0x0000000000180000, Flags 0x1000000000000000, UUID 275b6769-b8e2-0cd9-ca45-d4a0fd6df4d0, Type 0x638ff8e2, Active False
sec: Offset 0x0000000010188000, Length 0x0000000000004000, Flags 0x1000000000000000, UUID febf8581-79ab-6bcd-eaa1-b846df175aa7, Type 0x303e6ac3, Active False
logo1: Offset 0x0000000014000000, Length 0x0000000000b00000, Flags 0x0000000000000000, UUID 7cb18703-f624-36e5-fc8e-59ba64ff421d, Type 0x20117f86, Active False
logo2: Offset 0x0000000014b00000, Length 0x0000000000b00000, Flags 0x0000000000000000, UUID 00da1f8d-1019-320e-30af-db57bbb0df1f, Type 0x20117f86, Active False
aboot: Offset 0x0000000018000000, Length 0x0000000000100000, Flags 0x1000000000000000, UUID f82e02f6-d83f-ddca-0e1a-d587ac04e431, Type 0x400ffdcd, Active False
abootbak: Offset 0x0000000018100000, Length 0x0000000000100000, Flags 0x1000000000000000, UUID 5e1d0661-7e87-9db3-31ee-c7666478ea7c, Type EFI_BASIC_DATA, Active False
boot: Offset 0x0000000018200000, Length 0x0000000004000000, Flags 0x1000000000000000, UUID e12a83c9-9da5-ee99-7a9e-d996e1f6eac9, Type 0x20117f86, Active False
recovery: Offset 0x000000001c200000, Length 0x0000000004000000, Flags 0x1000000000000000, UUID afbb1a4e-6b5c-6fed-966d-bf292c2e44bf, Type 0x9d72d4e4, Active False
devinfo: Offset 0x0000000020200000, Length 0x0000000000100000, Flags 0x1000000000000000, UUID 5bb6099d-cc0d-167d-2ce1-e327850d3c46, Type 0x1b81e7e6, Active False
persist: Offset 0x0000000024000000, Length 0x0000000002000000, Flags 0x0000000000000000, UUID 2355bea3-28c9-0d32-aa4e-2af7fff1fbc9, Type 0x6c95e238, Active False
misc: Offset 0x0000000026000000, Length 0x0000000000100000, Flags 0x0000000000000000, UUID aee5cbbe-ae98-2437-9f97-1cbbe80ca587, Type 0x82acc91f, Active False
keystore: Offset 0x0000000026100000, Length 0x0000000000080000, Flags 0x0000000000000000, UUID f008b6ed-c024-c1bb-3dd1-22d578488bd6, Type 0xde7d4029, Active False
config: Offset 0x0000000026180000, Length 0x0000000000008000, Flags 0x0000000000000000, UUID b4000028-9067-c347-562c-047ec5669434, Type 0x91b72d4d, Active False
oem: Offset 0x0000000026188000, Length 0x0000000004000000, Flags 0x0000000000000000, UUID 259283ff-0b4b-7c1d-30a9-14c4fc449362, Type 0x7db6ac55, Active False
limits: Offset 0x000000002c000000, Length 0x0000000000008000, Flags 0x1000000000000000, UUID b8c5961e-12ab-d1d8-cb5b-9ca3c6afc0c2, Type 0x10a0c19c, Active False
mota: Offset 0x0000000030000000, Length 0x0000000000080000, Flags 0x0000000000000000, UUID 17247752-10c5-01eb-2b5d-7bc6b6d1e0a6, Type 0xa5872344, Active False
devcfg: Offset 0x0000000030080000, Length 0x0000000000040000, Flags 0x0000000000000000, UUID f3f90519-5136-007d-a9d9-156af96468c0, Type 0xf65d4b16, Active False
devcfgbak: Offset 0x00000000300c0000, Length 0x0000000000040000, Flags 0x0000000000000000, UUID ab5f149b-3f36-2df5-b8f3-e86a159e2863, Type 0xf65d4b16, Active False
dip: Offset 0x0000000030100000, Length 0x0000000000100000, Flags 0x0000000000000000, UUID ae627551-d8e2-b62d-6362-256e3e85f586, Type 0x4114b077, Active False
mdtp: Offset 0x0000000030200000, Length 0x0000000002000000, Flags 0x0000000000000000, UUID 102c878a-3dcd-c79c-5de6-128214651b44, Type 0x3878408a, Active False
syscfg: Offset 0x0000000032200000, Length 0x0000000000080000, Flags 0x0000000000000000, UUID 33b42bfb-e375-d02b-6832-32d658c8c89a, Type 0xfea86290, Active False
mcfg: Offset 0x0000000032280000, Length 0x0000000000400000, Flags 0x0000000000000000, UUID a25a9562-6e7f-86d4-722e-d210ffb41c26, Type 0x94b001ec, Active False
cmnlib: Offset 0x0000000034000000, Length 0x0000000000060000, Flags 0x1000000000000000, UUID c92a3c6e-c145-f54b-05e6-68a133dbec87, Type 0x73471795, Active False
cmnlibbak: Offset 0x0000000034060000, Length 0x0000000000060000, Flags 0x1000000000000000, UUID cee3de93-057a-2e18-60cf-4fce4e54f65c, Type 0x73471795, Active False
cmnlib64: Offset 0x00000000340c0000, Length 0x0000000000060000, Flags 0x1000000000000000, UUID dc998988-0a4c-6abb-f208-64a10521fc1d, Type 0x8ea64893, Active False
cmnlib64bak: Offset 0x0000000034120000, Length 0x0000000000060000, Flags 0x1000000000000000, UUID 69762adf-0370-b9b4-73d9-88f6aacde395, Type 0x8ea64893, Active False
keymaster: Offset 0x0000000034180000, Length 0x0000000000040000, Flags 0x1000000000000000, UUID 76230619-28c9-3972-e6f8-6c4d0591d2ac, Type 0xe8b7cf6e, Active False
keymasterbak: Offset 0x00000000341c0000, Length 0x0000000000040000, Flags 0x1000000000000000, UUID ab009213-be42-cb86-d74a-ad4c093dc9b1, Type 0xe8b7cf6e, Active False
apdp: Offset 0x0000000038000000, Length 0x0000000000040000, Flags 0x0000000000000000, UUID 4ef8bbb6-1f61-a8fd-909d-b6c5cae34add, Type 0xe6e98da2, Active False
msadp: Offset 0x0000000038040000, Length 0x0000000000040000, Flags 0x0000000000000000, UUID e6c88154-8f10-2abf-fec0-db25e9717995, Type 0xed9e8101, Active False
dpo: Offset 0x0000000038080000, Length 0x0000000000002000, Flags 0x0000000000000000, UUID c0026b54-02ab-53da-a8f7-5df913aba948, Type 0x11406f35, Active False
environment: Offset 0x0000000038082000, Length 0x0000000000020000, Flags 0x0000000000000000, UUID 7166e92c-56dd-e8f1-7392-94254568aa13, Type 0x2c86e742, Active False
factory: Offset 0x00000000380a2000, Length 0x0000000001400000, Flags 0x0000000000000000, UUID edc4c51c-6895-b1ac-4946-20556e8ef57a, Type EFI_LINUX_DAYA, Active False
enterprise: Offset 0x00000000394a2000, Length 0x0000000010000000, Flags 0x0000000000000000, UUID e8905c3a-f415-7a9e-61ef-79e383f43484, Type EFI_LINUX_DAYA, Active False
system: Offset 0x000000004c000000, Length 0x00000000e0000000, Flags 0x1000000000000000, UUID ca2ffc49-4efc-3e62-07ec-75ea9838216b, Type 0x97d7b011, Active False
cache: Offset 0x000000012c000000, Length 0x0000000040000000, Flags 0x0000000000000000, UUID a65d22da-e4c2-37b3-1faf-5dbbdae0a1ce, Type 0x5594c694, Active False
userdata: Offset 0x000000016c000000, Length 0x000000023f3fbe00, Flags 0x0000000000000000, UUID 96d91b68-ae28-bddf-b456-c7e4b809231e, Type 0x1b81e7e6, Active False
Total disk size:0x00000003ab400000, sectors:0x0000000001d5a000
Code: Select all
edl rl .Code: Select all
abootbak.bin cmnlib64bak.bin devcfgbak.bin enterprise.bin gpt_main0.bin logo2.bin modemst2.bin rpmbak.bin syscfg.bin
aboot.bin cmnlib64.bin devcfg.bin environment.bin keymasterbak.bin mcfg.bin mota.bin rpm.bin system.bin
apdp.bin cmnlibbak.bin devinfo.bin factory.bin keymaster.bin mdtp.bin msadp.bin sbl1bak.bin tzbak.bin
boot.bin cmnlib.bin dip.bin fsc.bin keystore.bin misc.bin oem.bin sbl1.bin tz.bin
boot.img config.bin dpo.bin fsg.bin limits.bin modem.bin persist.bin sec.bin userdata.bin
cache.bin DDR.bin dsp.bin gpt_backup0.bin logo1.bin modemst1.bin recovery.bin ssd.bin
Code: Select all
edl rf emmcdump.img

