How to Root a Chinese Tablet: A Painful but Proven Guide

root-a-chinese-tablet-mediatek.md
title How to Root a Chinese Tablet: A Painful but Proven Guide
date
author VahaC
read 9 min read
category Smart home
tags #Android #root #SmartHome
root a Chinese tablet

When I finally decided to root a Chinese tablet of mine — an Alldocube M8 (T806K) on a MediaTek MT6797 (Helio X23/X25/X27) — I thought it would take an evening. It took most of a night. This is the unedited version: every tool I installed, every dead-end driver, and the exact wall that stopped me cold on Windows. If you want to root a Chinese tablet with a MediaTek chip, my mistakes will save you hours.

⚠️ Read this first. Unlocking the bootloader wipes all data and voids the warranty, and a wrong flash can brick the device. Back up everything and only do this on hardware you own and are happy to lose.

Why I wanted to root a Chinese tablet

My goal was very specific: turn this cheap slate into a wall panel running Fully Kiosk Browser with my Home Assistant dashboard on it. The catch is that this Chinese tablet is a flaky little thing — left running more than about two days, it would simply freeze and shut itself off. The cure is a scheduled daily reboot, and on Android that needs root. So the real reason to root a Chinese tablet here was reliability: a rooted, automated reboot every night keeps the Home Assistant panel alive around the clock. If you plan to root a Chinese tablet for a 24/7 kiosk, that nightly reboot is the entire point.

Everything you need to install first

This is the part most guides skip. Before you can root a Chinese tablet you need a full toolchain — and, as I learned the hard way, on two different machines.

On the Windows PC:

  • Google platform-tools (adb + fastboot). Unzip to something like C:\toolsplatform-tools and add it to your PATH.
  • The MediaTek USB VCOM drivers so Windows can see the tablet in its service modes.
  • Python 3.10+ — tick Add Python to PATH. Verify with python --version.
  • mtkclient — git clone it, then pip install -r requirements.txt.
  • The UsbDk driver — mtkclient needs it to grab the chip in BROM mode on Windows.
  • SP Flash Tool — my Windows fallback (spoiler: it crashed).
  • The Magisk APK — the rooting app itself.
  • The matching stock firmware for your exact model — we only need preloader.bin and the scatter file from it.

⚠️ One trap that cost me time: the mtkclient script is mtk.py. Running python mtk fails with can't open file ... mtk — always call python mtk.py ....

On a bare-metal Linux box (you will understand why soon): git, python3-venv, and libusb. Mine was a Debian-based Proxmox server. If you have flashed eMMC before — like in my BPI-R4 OpenWRT build — this part will feel familiar.

Step 1 — Unlock the bootloader (and the first driver fight)

Enable Developer Options, turn on OEM unlocking and USB debugging, then:

adb reboot bootloader
fastboot devices

The screen went black with => FASTBOOT mode..., but fastboot devices returned nothing. Classic Windows: the fastboot interface is a separate USB device with no driver. I opened Device Manager, found the tablet under Other devices with a yellow mark, and manually set its driver to Android Bootloader Interface. Only then did fastboot devices list my T806K... serial.

A quick fastboot oem device-info returned unknown command — normal for MediaTek, ignore it. Then the unlock:

fastboot flashing unlock

The tablet dropped into a Select Boot Mode menu that did not respond to the volume keys at all — mildly terrifying. But the console printed Unlock pass, so it had worked. fastboot reboot and on we go.

⚠️ This is the point of no return for your data — the device factory-resets here.

Step 2 — Trying to dump boot.img on Windows (where it fell apart)

The whole point of learning to root a Chinese tablet comes down to one file: the device’s own boot.img, which Magisk patches. On MediaTek you read it with mtkclient over the BROM interface. Powered the tablet off, then:

python mtk.py r boot boot.img

It detected the MT6797 instantly… then died:

DAXFlash - [LIB]: Stage wasn't executed. Maybe dram issue ?
DaHandler - [LIB]: Failed to upload da.

The generic loader did not know my board’s RAM timings. I tried catching preloader mode instead (plug in with no buttons held) — but without holding the volume keys the tablet would not enumerate at all. Dead end number two.

Step 3 — Hunting the stock firmware (and a confusing model number)

To root a Chinese tablet you need the board’s preloader, and mtkclient told me so directly: provide a valid one via --preloader. That preloader lives inside the stock firmware. But which firmware? This is where it got weird:

  • The sticker on the back said T801 — which is actually the Alldocube X1, a different tablet.
  • The fastboot serial started with T806K — the M8.
  • adb shell getprop ro.product.model said M8, but the fingerprint was NODROPOUT/T25 ... 8.1.0 ... test-keys — a generic, non-official build.

That mismatch is exactly why I could not just grab a stock boot.img and flash it — the official ROM is Android 8.0, my tablet runs a custom 8.1.0, and a mismatched kernel bootloops. I had to read my own boot. I downloaded the M8 (T806K) ROM only to extract preloader.bin and MT6797_Android_scatter.txt.

Step 4 — The preloader fixed DRAM, and Windows still lost the device

This is the step that should have let me root a Chinese tablet for good — and on Windows it still didn’t. With the real preloader, the read got much further:

python mtk.py r boot boot.img --preloader preloader.bin

Now the log said DRAM setup passed, read my full eMMC layout… and then, every single time:

DAXFlash - Reconnecting to stage2 with higher speed
DeviceClass - [Errno 19] No such device (it may have been disconnected)

I threw everything at it: the --crash flag, a rear USB 2.0 port straight on the motherboard, a powered USB 2.0 hub. Same crash at the exact same line. As a last Windows resort I tried SP Flash Tool Readback (boot lives at 0xB300000, length 0x1000000 per the scatter) — and SP Flash Tool crashed at Download DA 89%. Both official Windows tools were beaten by the same thing: the USB re-enumeration when the chip jumps to high speed.

Step 5 — Why Docker, WSL and VMs do not save you

My first instinct was to spin up Linux in Docker or WSL2 and pass the USB through with usbipd. Do not bother. Every one of those keeps the flaky Windows USB stack in the path:

Tablet -> Windows USB stack -> usbipd -> WSL2 / Docker

MediaTek flashing constantly detaches and re-attaches the device with changing IDs, so usbip drops it on the same reconnect — plus WSL2 needs a custom kernel for libusb anyway. The layering only adds fragility (the same reason I prefer real containers over magic, which I cover in my Docker for beginners post). To root a Chinese tablet on MediaTek, you need bare-metal Linux talking to the USB controller directly.

Step 6 — Reading boot.img on bare-metal Linux (the win)

Bare-metal Linux is what finally let me root a Chinese tablet. I had a Debian-based server sitting right there, so I used it. Install mtkclient in a venv:

apt update && apt install -y git python3-venv python3-pip libusb-1.0-0 usbutils
git clone https://github.com/bkerler/mtkclient
cd mtkclient
python3 -m venv venv && source venv/bin/activate
pip install -r requirements.txt

Copy the preloader over from Windows:

scp preloader.bin [email protected]:~/mtkclient/

Then run the exact same command that kept failing on Windows (no sudo needed — the box logs in as root):

./venv/bin/python mtk.py r boot boot.img --preloader preloader.bin

This time:

DAXFlash - Connected to stage2 with higher speed
DaHandler - Dumping partition "boot"
Progress: 100.0% Read: (0x1000000/0x1000000)
DaHandler - Dumped ... as boot.img

16 MB, magic header ANDROID! — my real, native boot image, in seconds. Windows could never. I checked the file (you can use my online hash generator to compare checksums), then pulled it back to the PC as boot_device.img and kept a boot_stock.img copy as my safety net.

Step 7 — Patch with Magisk and flash

With the patched boot in hand, the last mile to root a Chinese tablet is pure Magisk. Boot back into Android and install it:

adb install Magisk-v30.7.apk

The install said Success, but no icon appeared in the launcher. I started it manually:

adb shell monkey -p com.topjohnwu.magisk -c android.intent.category.LAUNCHER 1

Push the dumped image and patch it in the app (Install → Select and Patch a File → boot_device.img):

adb push boot_device.img /sdcard/Download/

Magisk spat out magisk_patched-30700_xxxxx.img. Pull it back, then flash — and yes, the fastboot driver vanished again, so back into Device Manager to re-assign Android Bootloader Interface before this worked:

adb reboot bootloader
fastboot flash boot magisk_patched-30700_xxxxx.img
fastboot reboot

⚠️ Flash your own patched dump, never the stock firmware’s boot.img. A mismatched kernel will bootloop.

The tablet booted normally — no bootloop, because the patched boot was native. Last check:

adb shell su -c id
# Permission denied

That Permission denied actually means su exists but access was not granted. In Magisk → Settings I set Superuser access to Apps and ADB, re-ran the command, tapped Grant on the prompt, and:

uid=0(root) gid=0(root) groups=0(root) context=u:r:magisk:s0

Rooted. 🎉 Then the actual payoff: I installed Fully Kiosk Browser, pointed it at my Home Assistant dashboard, and set a rooted nightly reboot so the panel never freezes again.

The real lesson when you root a Chinese tablet

If you take one thing away: to root a Chinese tablet on a MediaTek SoC, unlocking and the Magisk flash are trivial. The brutal part is reading the stock boot image, and that is a USB problem, not an Android problem. Keep a bare-metal Linux box around, borrow the preloader from stock firmware, and guard your original boot_stock.img so you can always roll back. Avoid OTA updates while rooted, and never re-lock the bootloader with a modified boot.

It cost me a night, but the M8 now runs a rock-solid Home Assistant wall panel. If you are about to root a Chinese tablet of your own, unlock on Windows if you like — but dump that boot image on Linux.

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.