Skip to content
AI Box Fix

ADB, root & tinkeringReviewed

Root a Carlinkit TBox With Magisk via QFIL

Root a Carlinkit TBox Ultra or Ambient: back up boot_a/boot_b (init_boot on Ambient) with QFIL, patch in Magisk, write back, and how to undo it fully.

Quick answer

Read the box's boot_a and boot_b partitions to your PC with QFIL in EDL mode (init_boot_a and init_boot_b on a TBox Ambient 6225), patch both copies with the official Magisk app on the box, write the patched images back with QFIL, then open Magisk with internet to finish setup. Six owners reported rooting TBox Ultra and Ambient units this way, and the community FAQ recommends the procedure. Keep the original dumps: writing them back with QFIL is the complete undo.

Before you start

  • A box that boots normally, on the firmware you want to keep
  • A Windows PC with QFIL set up as in the QFIL recovery guide
  • The firehose programmer for your chip (Ultra: SM6350, Ambient: 6225), from Carlinkit support
  • The official recovery package for your model, in case something goes wrong
  • A microSD card and an internet connection for the box

Time: about 60 minutes. Tools: Windows PC, QPST / QFIL, Qualcomm USB driver, Magisk app (official repository only), microSD card, USB-C data cable.

Applies to

Connection to the car
CarPlay and Android Auto
Firmware in confirmed reports
Carlinkit TBox Ambient: 2025-07-09; Carlinkit TBox Ambient: 2024-11-14
Highest risk on this page
Brick risk

Should you root at all?

Root gives apps full control of the system. On an AI box, owners root for three reasons: Magisk modules (system-wide sound processing, apps installed as system apps), multitouch on older firmware, and settings Android otherwise locks.

It is the riskiest change on this site. You write to the boot partitions with a low-level tool; a mistake leaves a box that does not start, and a firmware update removes root again. Some banking and streaming apps also refuse to run on rooted devices, and a seller or manufacturer may decline warranty service for a box that has been modified.

Check first whether you need it:

  • For multitouch alone, the no-root method is shorter, and the 16 Jun 2026 Ultra 3 firmware already includes it.
  • For removing bloat or changing settings, ADB is usually enough.

How rooting with Magisk works

Android boots from a boot image that contains the kernel and a small starting file system (the ramdisk). Magisk adds itself to that ramdisk, so it starts before the rest of Android and can grant root to apps you approve. Nothing else on the box changes.

Carlinkit boxes use A/B slots: there are two copies of each boot partition, boot_a and boot_b, and the box can start from either. That is why you patch both. On the TBox Ambient 6225 with Android 13 the ramdisk lives in a separate partition, so you patch init_boot_a and init_boot_b instead.

QFIL reads and writes these partitions over USB while the box is in EDL mode. Reading is harmless; writing is the step that can brick the box.

PC with QFILfirehose loaderUSB, EDL modeAI box storage (UFS / eMMC)boot_aboot_bsystem, vendor, userdata … (do not touch)
The box keeps two boot slots, A and B. QFIL in EDL mode reads both to your PC, and later writes the Magisk-patched copies back to the same slots.

Which partitions for which box?

BoxProgrammerStorage typePartitions to dump and patch
TBox Ultra 1–4SM6350 firehoseUFSboot_a, boot_b
TBox Ambient / UHD 6225 (Android 13)6225 firehoseas in its recovery packageinit_boot_a, init_boot_b
TBox Plus 61256125 firehoseas in its recovery packageboot_a, boot_b

Owners confirmed the Ultra and Ambient rows. The TBox Plus row comes from the community FAQ; follow your model’s recovery package instructions for storage type. If you are unsure of your model, check which TBox do I have.

Steps

Confirm QFIL can see the partition table

  • Brick risk
  • Time: 15 minutes
  • Recommended in the community FAQ

Warranty warning: this changes system partitions. A wrong file or an interrupted step can leave the box unbootable, and manufacturers treat it as outside warranty. Back up first and keep the undo steps open.

  1. Set up the PC as in the QFIL recovery guide: QPST’s QFIL, Qualcomm driver, administrator account with a Latin-only name.
  2. Hold the EDL button and connect the box to the PC; Device Manager shows Qualcomm HS-USB QDLoader 9008.
  3. In QFIL choose the port, Flat Build, the firehose programmer for your chip, and the storage type (UFS on the Ultra).
  4. Open Tools → Partition Manager. The partition table must appear.

If the table does not appear, stop here and fix QFIL first; the recovery guide’s troubleshooting covers Sahara errors and Windows 11 profile problems.

Back up the boot partitions

  • Brick risk
  • Time: 10 minutes
  • Recommended in the community FAQ

Warranty warning: this changes system partitions. A wrong file or an interrupted step can leave the box unbootable, and manufacturers treat it as outside warranty. Back up first and keep the undo steps open.

  1. In Partition Manager, right-click boot_a (Ambient: init_boot_a) → Manage Partition Data → Read Data.
  2. Open the folder QFIL saved it to, shown below. A file named like ReadData_ufs_Lun0_...bin appears.
  3. Rename it boot_a.bin (Ambient: init_boot_a.bin).
  4. Repeat for boot_b (Ambient: init_boot_b) and rename that file too.
  5. Copy both files to a folder named Original on the PC and to a second safe place, such as cloud storage. These are your undo.
  6. Write the box’s firmware date (Settings → About) next to them.
C:\Users\<your user>\AppData\Roaming\Qualcomm\QFIL\COMPORT_<n>\

The dumps belong to this exact firmware build. Never write them back after a firmware update, and never use another owner’s dumps or patched images.

Patch both images in the Magisk app

  • Brick risk
  • Time: 10 minutes
  • Worked for 1 of 1 report
  • Recommended in the community FAQ

Warranty warning: this changes system partitions. A wrong file or an interrupted step can leave the box unbootable, and manufacturers treat it as outside warranty. Back up first and keep the undo steps open.

  1. Download the Magisk app (Magisk-vXX.apk) only from the Releases section of Magisk’s official repository, github.com/topjohnwu/Magisk. Never take the APK from a forum, a file host or another owner.
  2. Copy the APK and both .bin dumps to a microSD card and put it in the box.
  3. Boot the box, install the APK with a file manager and open Magisk.
  4. In the Magisk card tap Install → Select and Patch a File → pick boot_a.bin (Ambient: init_boot_a.bin) → Let’s go.
  5. The result appears in internal storage under Download as magisk_patched-XXXXX_XXXXX.img. Rename it boot_a.img.
  6. Patch boot_b.bin the same way and rename the result boot_b.img.
  7. Copy both .img files to a Patched folder on the PC.

If Magisk offers to update itself, decline; keep the version you patched with until setup is done. On one Ambient build Magisk patched init_boot_a but stopped with an error on init_boot_b. The owner flashed only the patched A image and left B untouched, and root worked; keep the original B dump in that case.

Write the patched images with QFIL

  • Brick risk
  • Time: 10 minutes
  • Worked for 6 of 6 reports
  • Recommended in the community FAQ

Warranty warning: this changes system partitions. A wrong file or an interrupted step can leave the box unbootable, and manufacturers treat it as outside warranty. Back up first and keep the undo steps open.

  1. Put the box in EDL mode again and open Partition Manager as before.
  2. Right-click boot_a (Ambient: init_boot_a) → Manage Partition Data → Load Image → choose Patched\boot_a.img.
  3. Wait for QFIL to report the write as successful.
  4. Do the same for boot_b with boot_b.img.
  5. Close QFIL, unplug, and start the box normally.

The community Ultra guide notes that boot_a and boot_b are identical on the Ultra, so the patched A image can be loaded into both slots.

Owners reported success on both families. Two Ultra owners had root running, one of them on the factory August 2025 and 21 Oct 2025 builds together with multitouch. On the Ambient 6225, three owners rooted through init_boot: one also got multitouch and sound processing working without having to restore anything, one rooted after first restoring the box with its recovery image, and one on the 9 Jul 2025 build reported it all went through.

Finish Magisk setup on the box

  • Brick risk
  • Time: 5 minutes
  • Worked for 1 of 1 report
  • Recommended in the community FAQ

Warranty warning: this changes system partitions. A wrong file or an interrupted step can leave the box unbootable, and manufacturers treat it as outside warranty. Back up first and keep the undo steps open.

  1. Give the box internet (SIM, Wi-Fi or a phone hotspot).
  2. Open Magisk. When it asks for additional setup, accept; the box reboots.
  3. Open Magisk again. The Magisk card should show an installed version.
  4. If your modules need it, open Settings (gear icon) → switch on Zygisk → reboot.
  5. Optionally turn on Enforce DenyList and add apps that refuse to run on rooted devices.
  6. Install modules from Modules → Install from storage, choosing the .zip through the system picker.

An Ambient owner’s modules would not install while a third-party file manager opened the zip; picking it through the system picker in Magisk’s own Install from storage worked. Install modules only from sources you trust; this site does not link third-party modules.

Verify it worked

  1. Magisk’s home screen shows an installed version, not “N/A”.
  2. Install a root-check app or run su from an ADB shell; Magisk asks you to grant access.
  3. Connect to the car and check video, sound and SIM as usual. Root should change nothing visible.
  4. Reboot twice. The box must boot reliably before you add modules, one at a time, with a reboot after each.
adb shell
su
id

The last command should print uid=0(root) once you grant the request on the box.

Undo / rollback

There are two levels of undo, and the second one always works as long as you kept your dumps:

  1. From Magisk: Uninstall → Complete uninstall. Magisk removes its modules, tries to restore the stock boot image and reboots; if it has no backup of the original, it tells you, and you use the QFIL route below. The community FAQ advises this step before every firmware update.
  2. From QFIL: write Original\boot_a.bin and Original\boot_b.bin (or the init_boot pair) back as in the undo block of the write step. This restores the boot partitions bit for bit, even if Magisk is broken.
  3. Uninstall the Magisk app itself afterwards.

If you updated the firmware since making the dumps, do not write the old dumps back; they would not match the new system. Use Magisk’s uninstall, a FOTA local update of the same build, or the full recovery package instead.

Keeping root through firmware updates

Root lives in the boot partitions, and every firmware update replaces them. Owners settled on one routine:

  1. Note which modules you use and export any app settings you care about.
  2. In Magisk choose Uninstall → Complete uninstall and let the box reboot unrooted.
  3. Install the new build with the FOTA local update.
  4. Dump the new boot_a and boot_b (or init_boot) partitions with QFIL and keep them as your new undo set, labelled with the new firmware date.
  5. Patch them in Magisk, write them back, finish setup and reinstall your modules.

Some experienced owners skip the uninstall and flash the update over a rooted box, then re-patch; the Magisk app and its modules survive in the data area. It works for them, but one owner who forgot to uninstall ended up with a factory reset, so the routine above is the safer default.

Two things never carry across builds: dumps and patched images. An image patched from the 21 Oct 2025 build does not belong on the 4 Jan 2026 build, even on the same model.

Troubleshooting this guide

Partition Manager does not open. QFIL is not talking to the box. Use the QFIL inside QPST, check the 9008 port, programmer and storage type, and see the Sahara section of the recovery guide.

Magisk cannot patch the image on the box. An Ultra 1 owner had repeated errors with the Magisk version he had. Another owner suggested a current Magisk release (30 or newer) and patching the same .bin on an Android phone instead; both are sound, because patching does not depend on the device that runs it. Do not fall back to images another owner patched.

Only one of the two images patches. Write the patched A image only and leave B as it was; that worked for an Ambient owner.

The box does not boot after writing. Write the original dumps back. If that fails, flash the full recovery package as described in the QFIL recovery guide, which collects the owners who brought an unbootable Ultra back that way.

A firmware update fails, or the box resets after one. An Ultra owner forgot to remove Magisk before updating and had to factory reset afterwards. Run Magisk’s Complete uninstall first, update with FOTA, then dump and patch the new build’s images. If you also disabled verity for other mods, see firmware update fails after disabling verity.

Modules install but do nothing. Check that Zygisk is on if the module needs it, and that the box runs in the protocol the module expects. Multitouch modules work only in Android Auto mode; see enable multitouch.

Did this work for you?

Tell us which fix worked (or didn't), with your box, firmware date and car. Reports are how fixes get confirmed and re-ranked.

Send a report

Changelog

  • Last reviewed against new community reports:
  • Confirmed by 8 community reports on Carlinkit TBox Ambient.
  • Page updated:

"Confirmed" means a community member reported that the fix worked on their unit. We have not tested it on our own hardware. How we verify.