RUI2 - Bin | Zip
Sadly both LK works only in stock rom for now and custom roms didn't boot becuz of in-rom spoofs. If you can find a signed custom rom without these spoofs your device may also pass strong.
What works?
Both RUI3 & RUI2 patches actually spoofs "bootloader locked" state.
What doesn't work?
RUI3 patch passes strong (as expected) but,
RUI2 patch passes only basic (Even in locked bootloader it passes basic. Most probably becuz of downgrade protection mechanism that prevents users from using older versions after updating to the latest one)
How to flash?
Flash LK using custom recovery or mtk client as your wish (fastboot mode is not preferred). And you MUST wipe personal data else it won't boot.
Wipe md_udc, metadata, userdata if you use mtk client.
Precautions:
Before flashing this LK you must backup all the fw partitions (except userdata, super and cache) for safety purpose. As it may lock your device if done wrong.
You must be aware that if you flash any other LK after flashing this lock spoofed LK, you must do format data and you can't decrypt the existing data (RPMB hash mismatch). Becuz it works in such a way similar to that of real locked device.
How it works?
Normal LK: preloader > reads seccfg (unlocked) > normal LK > pushes unlocked status to RPMB > skips TEE and other security firmware > no root of trust
This lock spoofed LK: preloader > reads seccfg (unlocked) > lock spoofed LK > pushes locked status to RPMB > loads TEE and other security firmware > device gets root of trust
Any issues/bugs:
DM me @antagonizzzt with logs (dump expdb, opporeserve1 and seccfg partitions, put them in a zip and share) You may try at your own risk in custom roms (won't boot btw) if it boots by any miracle tell me.
Last but not least: Thanks @R0rt1z2 for the inspiration