Register Guidelines E-Books Today's Posts Search

Go Back   MobileRead Forums > E-Book Readers > Android Devices

Notices

Reply
 
Thread Tools Search this Thread
Old 09-20-2026, 10:42 AM   #1
zhalps
Junior Member
zhalps began at the beginning.
 
Posts: 2
Karma: 10
Join Date: Sep 2026
Device: Xiaomi Duokan Pro2
[Guide] Root the Xiaomi Duokan Pro 2 e-reader (Moaan, RK3566) — no stock firmware, no

TL;DR
The Xiaomi Duokan E-reader Pro 2 (RK3566 / Android 11) is now rooted with Magisk 30.7.
Login, shelf and data fully preserved. No disassembly, no testpoint.
Full guide + tools (bilingual): github/zhalps/Duokan-Pro2

WHY THIS DEVICE IS HARD

No official firmware exists (OTA server returns nothing) — a bad boot write has no software recovery
Rockchip Loader mode can only read the first 32 MB of flash (u-boot reports
"ReadLBA: Disable"), while boot sits past 40 MB — so "just extract boot.img" is impossible
MaskROM is unusable on this hardware (USB stack hangs after entering it)
Recovery only accepts vendor-signed sideload zips — self-signed and even AOSP
testkey-signed packages are rejected (verified by test)
user build, no adb root
No SD card slot
THE IDEA
If you can't read the boot partition, boot a system that already has root and read it
from there. Android's built-in DSU (Dynamic System Update) installs a GSI into a loop
device under /data — no read-only partition is touched — and reboots into it.

Flow: stock system -> DSU installs a userdebug GSI -> adb root in the GSI ->
dd boot_b -> Magisk CLI patch -> dd back -> stock system with Magisk.

STEPS (full detail on GitHub)

Sanity checks
adb shell getprop ro.treble.enabled # true
adb shell getprop ro.boot.dynamic_partitions # true
adb shell getprop ro.boot.flash.locked # 0
adb shell getprop ro.product.cpu.abilist # armeabi-v7a,armeabi <- decides GSI arch

Get the RIGHT GSI (the biggest pitfall of this whole project)
64-bit kernel (CONFIG_ARM64=y) + 32-bit userspace = a64 = arm32_binder64.
You must use system-roar-arm32_binder64-ab-vanilla.img.xz (Android 11, VNDK 30).
phh release: github.com/phhusson/treble_experimentations/releases/tag/v313
DO NOT use the arm GSI (that is for 32-bit kernels) — we did, and it failed
to boot three times in a row, looking exactly like "DSU doesn't work on Rockchip".
After decompressing the xz, pad the file to a 512-byte multiple, then gzip it
(DSU only accepts compressed extensions: .gz/.xz; a bare .img throws
UnsupportedFormatException).

Push and trigger DSU
adb push xxx.img.gz /storage/emulated/0/Download/
adb shell setprop persist.sys.fflag.override.settings_dynamic_system true <- hidden gate
adb shell am start-activity
-n com.android.dynsystem/com.android.dynsystem.VerificationActivity
-a android.os.image.action.START_INSTALL
-d file:///storage/emulated/0/Download/xxx.img.gz
--el KEY_SYSTEM_SIZE 1081640960
--el KEY_USERDATA_SIZE 8589934592
(KEY_SYSTEM_SIZE = the raw size from the sparse header; without the setprop above
the confirmation dialog will simply never appear.)

When installation finishes, tap Restart in the notification
(do not reboot from the power menu and do not mix in gsi_tool enable —
that rolls the whole installation back).

A black screen / stuck boot logo after the reboot is NORMAL (the GSI has no
e-ink driver) — adb still works:
adb root # userdebug GSI, straight to uid=0
dd if=/dev/block/by-name/boot_b of=/data/local/tmp/boot_b.img
(also back up boot_a, vbmeta_a/b, dtbo_a/b, misc — this is your safety net)
adb pull /data/local/tmp/boot_b.img

Magisk CLI patch (no UI needed while the screen is dead):
Extract from the Magisk APK and rename:
lib/armeabi-v7a/libmagisk.so -> magisk
lib/armeabi-v7a/libmagiskinit.so -> magiskinit
lib/armeabi-v7a/libmagiskboot.so -> magiskboot
lib/armeabi-v7a/libinit-ld.so -> init-ld
lib/armeabi-v7a/libbusybox.so -> busybox
assets/boot_patch.sh assets/util_functions.sh assets/stub.apk
adb push the folder to /data/local/tmp/magisk_kit/, then in a root shell:
export BOOTMODE=true KEEPVERITY=true KEEPFORCEENCRYPT=true
sh boot_patch.sh /data/local/tmp/boot_b.img
-> new-boot.img

Flash back and reboot:
dd if=new-boot.img of=/dev/block/by-name/boot_b
adb reboot
Install the Magisk app -> first launch asks for "additional setup" -> confirm ->
auto-reboots -> su works.

PITFALL LIST

GSI arch: a64 (= arm32_binder64) != arm; the wrong arch fails to boot 100% of the time
The DSU gate is a FeatureFlag SYSTEM PROPERTY, not a Settings key
DSU only accepts compressed extensions (.gz/.xz)
You cannot bypass VerificationActivity by starting the install service directly
After DSU install, only the notification's Restart is valid
Magisk must be in the FOREGROUND when a root request pops, otherwise it is
auto-denied ("occluded by another app")
Pro2 recovery rejects testkey-signed sideload zips (verified by test)
Never run fastboot getvar all under u-boot fastboot (it kills the USB gadget)
UNBRICK
A bad boot image drops the device into fastboot by itself (A/B boot-failure fallback):
fastboot flash boot_b stock_boot.img
fastboot continue
So do step 4's backup first.

CREDITS
qwerty12 (inkPalm 5 root), tenpurro (Moann Mix 7 root), ximin (Duokan 1st gen guide),
Magisk / phh treble GSI.

REPO
github/Duokan-Pro2
(English + Chinese guides, tools included)
zhalps is offline   Reply With Quote
Reply


Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Moaan/Xiaomi InkPlam Plus panicopticon Android Developer's Corner 0 12-29-2024 12:51 PM
Calibre not detecting Xiaomi Moaan inkPalm 5 mini cartz Devices 4 05-16-2024 10:07 PM
Xiaomi Moaan w8 user experience? marinheiro Which one should I buy? 2 04-28-2023 06:39 AM
Let's try to root the Note Pro Android 9, firmware 3.1 Markismus Onyx Boox 7 10-21-2021 10:15 AM


All times are GMT -4. The time now is 06:16 AM.


MobileRead.com is a privately owned, operated and funded community.