Xiaomi Watch S1 Active Modding¶
An open, reproducible guide maintained by Just-Nova23 for understanding the Xiaomi Watch S1 Active M2116W1 firmware, building analysis tools, and experimenting with verifiable modifications.
This is not a ready-to-install firmware
The project does not distribute Xiaomi firmware, modified firmware, APKs, commercial RPKs, keys, or signatures. The tools operate only on copies legally obtained by the user. An incorrect modification can make the watch unusable.
Where to begin¶
| If you want to… | Read… |
|---|---|
| choose the correct route for your goal | Learning path |
| prepare Windows, WSL, or Linux from zero | Windows and Linux setup |
| understand the project with no prior knowledge | Getting started |
| see what has actually been verified | Research status |
| understand the firmware components | Architecture |
| inspect only evidence-backed diagrams | Verified concept maps |
| inspect a package without changing it | Package formats and Tools |
| follow a complete package inspection | Full-package walkthrough |
| compare two versions or mods | Firmware comparison |
| analyze native code in Ghidra | Ghidra and ARM workflow |
| study built-in system apps | Native apps |
| study installable apps | RPK apps |
| build an installable app from zero | RPK tutorial |
| understand graphics and animations | Graphics and TSCFrameImage |
| reproduce GUI-container experiments | Native GUI asset laboratory |
| develop a guarded patch | Patch development |
| reproduce the verified text-capacity patch | Assistant patch walkthrough |
| inspect measured firmware data as charts | Research data and charts |
| keep experiments reproducible | Lab notebook |
| find official specifications and tools | Resource library |
| contribute new evidence | Contributing research |
Principles¶
- Evidence before conclusions. Every fact should have an offset, hash, output, or reproducible procedure.
- Read before write. Analyze a copy; do not begin with a device test.
- One change at a time. A minimal patch is easier to verify and reverse.
- No proprietary material. The repository contains documentation, original code, and synthetic fixtures.
- Explicit uncertainty. “Observed,” “inferred,” and “hypothesized” do not mean the same thing.
Main results¶
- identified the
fullOTA container and the differential-package model; - mapped the nine components in the observed package;
- verified
runtime address = 0x08000000 + file offsetfor the main component; - located the native assistant response limit and built a guarded patch from 299 to 399 visible characters;
- decoded the outer GUI asset container, while the inner
TSCFrameImagecodec remains an active research target.
Always check the compatibility matrix before using a tool.