|
|||||||
![]() |
|
|
Thread Tools | Search this Thread |
|
|
#1 |
|
Junior Member
![]() Posts: 2
Karma: 10
Join Date: Sep 2026
Device: Xiaomi Duokan Pro2
|
[Guide] Root the Xiaomi Duokan Pro 2 e-reader (Moaan, RK3566) — no stock firmware, no
TL;DR
The Xiaomi Duokan E-reader Pro 2 (RK3566 / Android 11) is now rooted with Magisk 30.7. Login, shelf and data fully preserved. No disassembly, no testpoint. Full guide + tools (bilingual): github/zhalps/Duokan-Pro2 WHY THIS DEVICE IS HARD No official firmware exists (OTA server returns nothing) — a bad boot write has no software recovery Rockchip Loader mode can only read the first 32 MB of flash (u-boot reports "ReadLBA: Disable"), while boot sits past 40 MB — so "just extract boot.img" is impossible MaskROM is unusable on this hardware (USB stack hangs after entering it) Recovery only accepts vendor-signed sideload zips — self-signed and even AOSP testkey-signed packages are rejected (verified by test) user build, no adb root No SD card slot THE IDEA If you can't read the boot partition, boot a system that already has root and read it from there. Android's built-in DSU (Dynamic System Update) installs a GSI into a loop device under /data — no read-only partition is touched — and reboots into it. Flow: stock system -> DSU installs a userdebug GSI -> adb root in the GSI -> dd boot_b -> Magisk CLI patch -> dd back -> stock system with Magisk. STEPS (full detail on GitHub) Sanity checks adb shell getprop ro.treble.enabled # true adb shell getprop ro.boot.dynamic_partitions # true adb shell getprop ro.boot.flash.locked # 0 adb shell getprop ro.product.cpu.abilist # armeabi-v7a,armeabi <- decides GSI arch Get the RIGHT GSI (the biggest pitfall of this whole project) 64-bit kernel (CONFIG_ARM64=y) + 32-bit userspace = a64 = arm32_binder64. You must use system-roar-arm32_binder64-ab-vanilla.img.xz (Android 11, VNDK 30). phh release: github.com/phhusson/treble_experimentations/releases/tag/v313 DO NOT use the arm GSI (that is for 32-bit kernels) — we did, and it failed to boot three times in a row, looking exactly like "DSU doesn't work on Rockchip". After decompressing the xz, pad the file to a 512-byte multiple, then gzip it (DSU only accepts compressed extensions: .gz/.xz; a bare .img throws UnsupportedFormatException). Push and trigger DSU adb push xxx.img.gz /storage/emulated/0/Download/ adb shell setprop persist.sys.fflag.override.settings_dynamic_system true <- hidden gate adb shell am start-activity -n com.android.dynsystem/com.android.dynsystem.VerificationActivity -a android.os.image.action.START_INSTALL -d file:///storage/emulated/0/Download/xxx.img.gz --el KEY_SYSTEM_SIZE 1081640960 --el KEY_USERDATA_SIZE 8589934592 (KEY_SYSTEM_SIZE = the raw size from the sparse header; without the setprop above the confirmation dialog will simply never appear.) When installation finishes, tap Restart in the notification (do not reboot from the power menu and do not mix in gsi_tool enable — that rolls the whole installation back). A black screen / stuck boot logo after the reboot is NORMAL (the GSI has no e-ink driver) — adb still works: adb root # userdebug GSI, straight to uid=0 dd if=/dev/block/by-name/boot_b of=/data/local/tmp/boot_b.img (also back up boot_a, vbmeta_a/b, dtbo_a/b, misc — this is your safety net) adb pull /data/local/tmp/boot_b.img Magisk CLI patch (no UI needed while the screen is dead): Extract from the Magisk APK and rename: lib/armeabi-v7a/libmagisk.so -> magisk lib/armeabi-v7a/libmagiskinit.so -> magiskinit lib/armeabi-v7a/libmagiskboot.so -> magiskboot lib/armeabi-v7a/libinit-ld.so -> init-ld lib/armeabi-v7a/libbusybox.so -> busybox assets/boot_patch.sh assets/util_functions.sh assets/stub.apk adb push the folder to /data/local/tmp/magisk_kit/, then in a root shell: export BOOTMODE=true KEEPVERITY=true KEEPFORCEENCRYPT=true sh boot_patch.sh /data/local/tmp/boot_b.img -> new-boot.img Flash back and reboot: dd if=new-boot.img of=/dev/block/by-name/boot_b adb reboot Install the Magisk app -> first launch asks for "additional setup" -> confirm -> auto-reboots -> su works. PITFALL LIST GSI arch: a64 (= arm32_binder64) != arm; the wrong arch fails to boot 100% of the time The DSU gate is a FeatureFlag SYSTEM PROPERTY, not a Settings key DSU only accepts compressed extensions (.gz/.xz) You cannot bypass VerificationActivity by starting the install service directly After DSU install, only the notification's Restart is valid Magisk must be in the FOREGROUND when a root request pops, otherwise it is auto-denied ("occluded by another app") Pro2 recovery rejects testkey-signed sideload zips (verified by test) Never run fastboot getvar all under u-boot fastboot (it kills the USB gadget) UNBRICK A bad boot image drops the device into fastboot by itself (A/B boot-failure fallback): fastboot flash boot_b stock_boot.img fastboot continue So do step 4's backup first. CREDITS qwerty12 (inkPalm 5 root), tenpurro (Moann Mix 7 root), ximin (Duokan 1st gen guide), Magisk / phh treble GSI. REPO github/Duokan-Pro2 (English + Chinese guides, tools included) |
|
|
|
![]() |
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Moaan/Xiaomi InkPlam Plus | panicopticon | Android Developer's Corner | 0 | 12-29-2024 12:51 PM |
| Calibre not detecting Xiaomi Moaan inkPalm 5 mini | cartz | Devices | 4 | 05-16-2024 10:07 PM |
| Xiaomi Moaan w8 user experience? | marinheiro | Which one should I buy? | 2 | 04-28-2023 06:39 AM |
| Let's try to root the Note Pro Android 9, firmware 3.1 | Markismus | Onyx Boox | 7 | 10-21-2021 10:15 AM |