carrier-explode Explode and decode carrier data GitHub About
T-Mobile
iOS 27.2 beta 3 image · build 73.0 beta iOS 27.2 beta 1–2 image · build 72.7.2 beta OTA iOS 27.0+ · build 72.1 current release iOS 27.0 – 27.0.1 image · build 72.0 iOS 27.0 beta 5–8 image · build 72.0 beta iOS 27.0 beta 3–4 image · build 71.5.27 beta iOS 27.0 beta 2 image · build 71.5.25 beta iOS 27.0 beta image · build 71.5.23 beta iOS 26.5 – 26.6.2 image · build 70.0 iOS 26.5.1 image · build 70.0 OTA iOS 26.4+ · build 69.1 iOS 26.4 – 26.4.2 image · build 69.0 iOS 26.3.1 image · build 68.0 iOS 26.3 image · build 68.0 iOS 26.2 – 26.2.1 image · build 67.0.1 iOS 26.1 image · build 66.0 iOS 26.0 – 26.0.1 image · build 65.0.2 iOS 26.0 image · build 65.0.2 iOS 18.6 – 18.6.2 image · build 64.0.2 iOS 18.5 image · build 64.0 iOS 18.4 – 18.4.1 image · build 63.0 iOS 18.3.1 – 18.3.2 image · build 62.0 iOS 18.3 – 18.3.2 image · build 62.0 iOS 18.2 – 18.2.1 image · build 61.0 iOS 18.1 – 18.1.1 image · build 60.0 iOS 18.0 – 18.0.1 image · build 59.0 OTA iOS 17.4+ · build 58.1 OTA iOS 16.4+ · build 54.1.0 OTA iOS 15.0+ · build 47.1 OTA iOS 14.3+ · build 45.1 OTA iOS 14.0+ · build 42.1 OTA iOS 13.2+ · build 39.1 OTA iOS 11.2+ · build 31.2 OTA iOS 11.1+ · build 30.3 OTA iOS 11.0+ · build 29.3 OTA iOS 10.3.2+ · build 28.6 OTA iOS 10.3+ · build 28.5 OTA iOS 10.2+ · build 27.4 OTA iOS 10.1+ · build 26.2 OTA iOS 10.0+ · build 25.3 OTA iOS 9.3+ · build 24.2 OTA iOS 9.2+ · build 23.2 OTA iOS 9.0+ · build 21.1 OTA iOS 8.3+ · build 19.1 OTA iOS 8.0+ · build 18.1 OTA iOS 7.1+ · build 16.1 OTA iOS 7.0+ · build 15.6 OTA iOS 6.1+ · build 14.2

overrides_D93_D94_D47_D48.der.pri Modem package.

Header
DialectQualcomm
PRI Revision0.2.166
Settings (66)

efs:/data (1)

APM rules = "APN_String:fast.t-mobile.com; ATTACH_TYPE_RULES:TRUE; P-CSCFRequired:4; IPAddressRequired:5; DNSAddressRequired:4; P-CSCF_OR_DNSAddressRequired:4; ON_DEMAND_TYPE_RULES:TRUE; P-CSCFRequired:4; IPAddressRequired:5; DNSAddressRequired:4; P-CSCF_OR_DNSAddressRequired:4; "
Attach PDN Manager rules (which PDN is required for attach)efs:/data/ds_dsd_apm_rules.txt

efs:/data/3gpp (1)

3GPP data dynamic config =
Per-PLMN data rules, domestic/international roaming PLMN listsefs:/data/3gpp/data_3gpp_dynamic_config.xml

efs:/nv/item_files/ims (2)

IMS enable = 2
Enables the IMS task (VoLTE, VoWiFi, SMS over IMS)efs:/nv/item_files/ims/IMS_enable
IMS media service configunverified =
IMS media (codec/RTP) service config; no public schemaefs:/nv/item_files/ims/media_service_config

efs:/nv/item_files/modem/data/3gpp/ps (1)

3gpp_rel_version = 5
3GPP release: Signalled 3GPP releaseefs:/nv/item_files/modem/data/3gpp/ps/3gpp_rel_version

efs:/nv/item_files/modem/lte/rrc (1)

PC2 whitelistunverified =
Bands allowed Power Class 2 (26 dBm)efs:/nv/item_files/modem/lte/rrc/PC2_WHITELIST.xml

efs:/nv/item_files/modem/lte/rrc/bbq (1)

Fake eNodeB mitigation = 1= On
LTE false-base-station (fake eNodeB) mitigationefs:/nv/item_files/modem/lte/rrc/bbq/bbq_mitigation

efs:/nv/item_files/modem/lte/rrc/cap (4)

max_lte_cap_sizeunverified = 7000
LTE setting: LTE RRC / L1 / L2efs:/nv/item_files/modem/lte/rrc/cap/max_lte_cap_size
whitelist_ca_combos =
CA combo list: LTE CA / EN-DC band-combination allow/deny listefs:/nv/item_files/modem/lte/rrc/cap/whitelist_ca_combos
blacklist_ca_combos =
CA combo list: LTE CA / EN-DC band-combination allow/deny listefs:/nv/item_files/modem/lte/rrc/cap/blacklist_ca_combos
whitelist_ca_combos_with_laa =
CA combo list: LTE CA / EN-DC band-combination allow/deny listefs:/nv/item_files/modem/lte/rrc/cap/whitelist_ca_combos_with_laa

efs:/nv/item_files/modem/lte/rrc/efs (4)

LTE feature disable =
LTE RRC capability feature-disable bitmapefs:/nv/item_files/modem/lte/rrc/efs/lte_feature_disable
LTE feature enable =
LTE RRC capability feature-enable bitmap; bit list unpublishedefs:/nv/item_files/modem/lte/rrc/efs/lte_feature_enable
LTE band priority list =
Prioritised band list for LFS/FFS scans (uint16 array)efs:/nv/item_files/modem/lte/rrc/efs/band_priority_list_v2
EPS fallback controlunverified = 171884591485920xfa200007530
VoNR to EPS fallback controlefs:/nv/item_files/modem/lte/rrc/efs/eps_fallback_control

efs:/nv/item_files/modem/mav (19)

LTE CA combos per PLMN = 1= On
Prune the advertised LTE CA combos per PLMN from /policyman/band_combos_per_plmn.xmlefs:/nv/item_files/modem/mav/lte_ca_xml_generation
drs_ul_check_enabled = 1
Dynamic RAT selection: Apple Dynamic RAT Selection (DRS): picks LTE, NSA or SA from measured throughputefs:/nv/item_files/modem/mav/drs_ul_check_enabled
drs_enable = 1
Dynamic RAT selection: Apple Dynamic RAT Selection (DRS): picks LTE, NSA or SA from measured throughputefs:/nv/item_files/modem/mav/drs_enable
drs_nsa_icon_via_motion = 1
Dynamic RAT selection: Apple Dynamic RAT Selection (DRS): picks LTE, NSA or SA from measured throughputefs:/nv/item_files/modem/mav/drs_nsa_icon_via_motion
drs_sa_cov_band_area_config =
Dynamic RAT selection: Apple Dynamic RAT Selection (DRS): picks LTE, NSA or SA from measured throughputefs:/nv/item_files/modem/mav/drs_sa_cov_band_area_config
drs_starting_rat = 2
Dynamic RAT selection: Apple Dynamic RAT Selection (DRS): picks LTE, NSA or SA from measured throughputefs:/nv/item_files/modem/mav/drs_starting_rat
No mmWave for FaceTime video = 1= On
Drop mmWave (FR2) during FaceTime video callsefs:/nv/item_files/modem/mav/disable_mmw_for_ftv
Disable SA on null SUCI = 1= On
Turn off 5G SA when the SUCI uses the null protection scheme (SUPI sent unconcealed)efs:/nv/item_files/modem/mav/mav_disable_sa_if_null_suci
Drop EN-DC in call hysteresis = 15
Hysteresis timer before dropping EN-DC during a callefs:/nv/item_files/modem/mav/drop_endc_call_hysteresis_tmr_val
Drop EN-DC in VoLTE hysteresis = 15
Hysteresis timer before dropping EN-DC during a VoLTE callefs:/nv/item_files/modem/mav/drop_endc_call_hysteresis_tmr_volte_val
BWP switch on screen lock = 1= On
Move to a narrower NR bandwidth part while the screen is lockedefs:/nv/item_files/modem/mav/enable_bwp_switching_screen_lock
Dynamic SA = 1= On
Turn 5G SA capability on and off with coverage (dyn_sa_* / dyn_cap_* timers and thresholds)efs:/nv/item_files/modem/mav/enable_dyn_sa
Dynamic VoNR = 1= On
Turn VoNR on and off dynamically, alongside dynamic SAefs:/nv/item_files/modem/mav/enable_dyn_vonr
enable_fblte_based_bwp_configunverified = 1
Apple modem option: Apple-only (Maverick) modem option; undocumentedefs:/nv/item_files/modem/mav/enable_fblte_based_bwp_config
enable_fr1_scell_vrlfunverified = 1
Apple modem option: Apple-only (Maverick) modem option; undocumentedefs:/nv/item_files/modem/mav/enable_fr1_scell_vrlf
mav_monitor_replace_nr5g_uc_with_nr_basic = 1
5G icon rule: Status-bar 5G / 5G UW / 5G UC / 5G+ icon override logicefs:/nv/item_files/modem/mav/mav_monitor_replace_nr5g_uc_with_nr_basic
SA coverage bands = "G"
NR bands that count as 5G SA coverage (uint8 band numbers, zero-padded)efs:/nv/item_files/modem/mav/mav_sa_coverage_band_list
sa_depri_td_bwp_thresh_val = 30
Smart data mode: Apple SDM: turns NR / SA off or deprioritises SA when it does not pay offefs:/nv/item_files/modem/mav/sa_depri_td_bwp_thresh_val
sa_depri_bw_val = 4
Smart data mode: Apple SDM: turns NR / SA off or deprioritises SA when it does not pay offefs:/nv/item_files/modem/mav/sa_depri_bw_val

efs:/nv/item_files/modem/mmode (5)

SMS domain preference listunverified =
Per-RAT/PLMN SMS domain list; layout not publicefs:/nv/item_files/modem/mmode/sms_domain_pref_list
SMS domain preference = 1= PS (IMS) SMS preferred
SMS over IMS preferenceefs:/nv/item_files/modem/mmode/sms_domain_pref
Voice domain preference = 3= IMS PS voice preferred
E-UTRAN voice domain (TS 24.301 9.9.3.44)efs:/nv/item_files/modem/mmode/voice_domain_pref
NR5G emergency supportunverified = 1= On
NR5G emergency-call supportefs:/nv/item_files/modem/mmode/nr5g_emc_support
NR5G disable modeunverified = 0= NR5G enabled
Disables NR5G SA and/or NSAefs:/nv/item_files/modem/mmode/nr5g_disable_mode

efs:/nv/item_files/modem/nas (8)

hplmn_rat_order_ctrlunverified = 2
NAS setting: NAS mobility management / PLMN selectionefs:/nv/item_files/modem/nas/hplmn_rat_order_ctrl
mav_pssi_reg_unblock_hplmn_max_reg_failure = 1
PSSI registration rule: Apple PLMN search / system-selection (PSSI) registration tuningefs:/nv/item_files/modem/nas/mav_pssi_reg_unblock_hplmn_max_reg_failure
mav_pssi_reg_unblock_hplmn_voice_not_avail_based_on_motion_st = 1
PSSI registration rule: Apple PLMN search / system-selection (PSSI) registration tuningefs:/nv/item_files/modem/nas/mav_pssi_reg_unblock_hplmn_voice_not_avail_based_on_motion_st
HPLMN RAT order = NR > LTE > WCDMA > GSM
Home-PLMN RAT search order: uint16 count, then sys_sys_mode RATsefs:/nv/item_files/modem/nas/hplmn_rat_order
mav_pssi_reg_gfnh_allowed_plmn_per_carrierunverified = 0001000136013e03
Satellite PLMN rule: Apple satellite (GFNH) PLMN / geofence ruleefs:/nv/item_files/modem/nas/mav_pssi_reg_gfnh_allowed_plmn_per_carrier
SRVCC support = 1= On
SRVCC capability indication from E-UTRAN to UTRAN (TS 23.216)efs:/nv/item_files/modem/nas/nas_srvcc_support
mav_pssi_reg_follow_rplmn_rat_order_power_up = 1
PSSI registration rule: Apple PLMN search / system-selection (PSSI) registration tuningefs:/nv/item_files/modem/nas/mav_pssi_reg_follow_rplmn_rat_order_power_up
mav_k_deep_sleep_rounds_chg_nr_bandscan2acqdbunverified = 4
Apple modem option: Apple-only (Maverick) modem option; undocumentedefs:/nv/item_files/modem/nas/mav_k_deep_sleep_rounds_chg_nr_bandscan2acqdb

efs:/nv/item_files/modem/nr5g/RRC (9)

NR band capability =
NR band feature-capability list; proprietary layoutefs:/nv/item_files/modem/nr5g/RRC/cap_feature_band_nr
cap_csi_rs_32_port_control =
NR UE capability: NR RRC UE-capability toggleefs:/nv/item_files/modem/nr5g/RRC/cap_csi_rs_32_port_control
cap_control_nrca_3x_f_plus_t_band_combos = 168430090x1010101
NR band-combo class control: Enables an NR-CA / NR-DC / MR-DC band-combination class in the UE capabilityefs:/nv/item_files/modem/nr5g/RRC/cap_control_nrca_3x_f_plus_t_band_combos
cap_control_nrca_3x_t_plus_t_band_combos = 1
NR band-combo class control: Enables an NR-CA / NR-DC / MR-DC band-combination class in the UE capabilityefs:/nv/item_files/modem/nr5g/RRC/cap_control_nrca_3x_t_plus_t_band_combos
cap_control_nrca_4x_f_plus_t_band_combos = 657930x10101
NR band-combo class control: Enables an NR-CA / NR-DC / MR-DC band-combination class in the UE capabilityefs:/nv/item_files/modem/nr5g/RRC/cap_control_nrca_4x_f_plus_t_band_combos
cap_control_nrca_f_plus_f_band_combos = 257
NR band-combo class control: Enables an NR-CA / NR-DC / MR-DC band-combination class in the UE capabilityefs:/nv/item_files/modem/nr5g/RRC/cap_control_nrca_f_plus_f_band_combos
cap_control_nrca_f_plus_t_band_combos = 1
NR band-combo class control: Enables an NR-CA / NR-DC / MR-DC band-combination class in the UE capabilityefs:/nv/item_files/modem/nr5g/RRC/cap_control_nrca_f_plus_t_band_combos
NR TDD+FDD combo control = 7
Enables NR-CA/NR-DC TDD+FDD band-combo classesefs:/nv/item_files/modem/nr5g/RRC/cap_control_t_plus_f_band_combos
cap_control_nrca_t_plus_t_band_combos = 657930x10101
NR band-combo class control: Enables an NR-CA / NR-DC / MR-DC band-combination class in the UE capabilityefs:/nv/item_files/modem/nr5g/RRC/cap_control_nrca_t_plus_t_band_combos

efs:/nv/item_files/modem/qmi/cat (1)

Block SMS-PP envelope = 0= Off
Block SIM Toolkit SMS-PP (data download) envelopes, per subscriptionefs:/nv/item_files/modem/qmi/cat/qmi_cat_block_sms_pp_env_per_sub

efs:/policyman (1)

Carrier policy =
PolicyMan rules keyed on MCC/PLMN: RAT capability, RF bands, UE modeefs:/policyman/carrier_policy.xml

nv (5)

PRI revision = 10879488= 0.2.1660xa60200
Packed PRI Revision headernv:62005
AAGPS Positioning Modes Supported = 1065
nv:1920
Delay RAU during CSFB (probable)unverified = 0= Off
nv:62025
Call Manager Feature Group
1 of 25 flags setnv:62012
0123456789101112131415161718192021222324
Feature Group (unnamed, tag 9f83e453)unverified
1 of 25 flags setnv:62035
0123456789101112131415161718192021222324

pri (3)

Legacy NV item list =
Legacy NV items the modem may take from this file; with a value here: 62012, 1920, 62025, 62005, 62035.pri:nv-list
NV path schema index =
320 NV paths the PRI format knows (MAVZ); not overrides.pri:schema
pri:9fa710 = 178
Unidentified field, 1 time, 2 bytes: small binary blob that precedes the NV item list.
Band combos

What the iOS 18.3.2 Qualcomm X71M · Mav24 package advertises on this carrier's networks.

TMO default bundle on 310-160 310-200 310-210 310-220 310-230 310-240 310-250 310-260 310-270 310-310 310-490 310-660 310-800 311-660 311-882
PlatformsCombosEN-DCNRLTENR-DCMax CCNR bandsLTE anchors
P1P4P5P6P7 30587218006n25 n41 n66 n71 n77
FR2 n258 n260 n261
B2 B12 B48 B66 B71
Modem defaults this file replaces

Files the package ships at the EFS paths this bundle's .der.pri writes.

EFS pathPackage copy
/policyman/carrier_policy.xmlbbcfg.mbn P1P4P5P6P7 Compare
/data/3gpp/data_3gpp_dynamic_config.xmlbbcfg.mbn P1P4P5P6P7 Compare

1 more XML values set paths the package leaves unset.