Fire 7 tablet unlock: host tools and brltty
Why: We wanted to turn an old Fire 7 (2015, "ford") into a single-purpose kiosk, and its bootloader exploit has to run from a Linux host over USB, so this server became the flashing station.
Over a few sessions (Oct 5–8) we unlocked the tablet with k4y0z's amonet exploit, installed TWRP, and flashed LineageOS 14.1. The only lasting change to the server is one new package; the brltty masking was temporary and is reverted. The project itself lives in /home/plex/dev/fire, with a running log in NOTES.md.
1. Packages
- Action: I installed
fastboot(apt install fastboot).adbandpython3-serialwere already present.
2. brltty, masked and restored
brltty is known to claim MediaTek bootrom serial ports (/dev/ttyACM*) during the exploit, so I masked brltty-udev.service and brltty.service for the duration. Once the tablet was unlocked I unmasked both; they're back to their original state (static / disabled). ModemManager was already inactive and wasn't touched.
3. Lessons for next time
- Don't run amonet's
bootrom-step.shin the background: it stops at an Enter prompt, and the half-finished run disables the SoC watchdog and leaves the bootrom wedged until the battery fully drains (that cost us about three days). - Backups of the stock partitions live in
/home/plex/dev/fire/backups/stock-20261008(1.3 GB, with MD5SUMS).
Net effect: one extra package on the server; the tablet now runs LineageOS 14.1.
← Back to Admin Hub