Install guide
Install and recover
AndroiOS does not replace Android. A host computer starts the shell over adb after each boot, and anything that goes wrong hands the screen back to Android.
Read this first.
- This is experimental software for one specific tablet, the Samsung Galaxy Tab A8 (SM-X200). Do not try it on other models.
- You need a tablet whose adbd can run as root. This guide does not cover unlocking, rooting or flashing, and a mistake there can erase the device.
- Back up the tablet first. We have already seen one factory reset, caused by an unrelated change to /system (see below).
- You use this at your own risk. There is no warranty.
Requirements
- Samsung Galaxy Tab A8 (SM-X200) with Wi-Fi, on a build where
/data/local.propis honoured at boot (an eng/userdebug style init). This is how adbd is made to start as root. - A Linux computer on the same network with
adb, Rust with theaarch64-linux-androidtarget and the Android NDK to build, and systemd for the boot watcher. - USB debugging and Wi-Fi adb enabled on the tablet.
- The project repository with its
tabhelper script. A public source link will be added here when the repository is released.
How booting works
/data/local.propcontainsservice.adb.root=1, so adbd comes up as root on every boot. The Developer page in Settings only changes the live property; the file is what survives a reboot.- Android boots normally.
- A systemd user unit on your computer,
tab-a8-boot.service, polls Wi-Fi adb. Once per new boot it runs/data/local/springboard/boot.shon the tablet. boot.shstops Android’s UI processes (zygote, surfaceflinger, hwcomposer, bootanim, wpa_supplicant) and starts the shell. When the shell exits, Android is restored.
If your computer is off, the tablet simply stays in Android. Nothing under /system, boot, vbmeta or verity is read or changed.
Steps
- Connect adb. Plug in USB, accept the debugging prompt, and confirm
adb deviceslists the tablet. Then enable Wi-Fi adb so the watcher can reach it. - Build and install the boot support.
tab boot install # pushes boot.sh, writes /data/local.prop (root adbd, Wi-Fi adb on :5555), installs the Android-mode launcher APK tab boot status # probation, heartbeat age, last exit, crash log tab boot watcher # status of tab-a8-boot.service on your computer - Start the watcher. Run
tools/boot-watcher.shfrom the repository as a systemd user unit namedtab-a8-boot.serviceon your computer. It is what starts the shell after every tablet boot. - Deploy the shell.
tab deploy --test # host unit tests, cross-build, stage springboard.newboot.shpromotes the staged binary and keeps the old one asspringboard.prev. - Verify.
tab status tab shot # screenshot to compare with what you expect tab logs - Reboot once to prove it.
adb reboot, wait about two minutes, and the watcher log (journalctl --user -u tab-a8-boot) showsstarting boot.sh.
Updates and rollback
A new binary is staged as springboard.new and promoted when the shell restarts. For 60 seconds it is on probation: if it exits during that time (other than a deliberate hand-back), or dies with an unexpected status, boot.sh restores the previous binary and starts it. If that also fails, Android takes over. The rejected binary is kept as springboard.bad.
| Exit status | Meaning |
|---|---|
| 3 | Restart requested |
| 4 | Hand back to Android (recovery chord, lost Wi-Fi for 3 minutes) |
| 5 | UI stalled; restarted at most 3 times per boot, then Android |
| other | Crash: Android takes over; three crashing boots in a row stop the loop |
A background loop also kills a shell whose heartbeat has not changed for about a minute. Roll back by hand with tab boot rollback.
From inside the shell, Settings > General > Software Update checks the update server for a newer build and installs it through the same staged path.
Recovery
- On the tabletHold Power and Volume Down for 10 seconds: the shell hands back to Android.
- At takeoverHold Volume Down while the tablet boots to skip the takeover for that boot.
- From the computer
tab androidstops the shell and keeps Android until you runtab bare. It works by creating/data/local/springboard/disabled. - Unrooted bootDelete
/data/local.propand reboot; adbd then starts unrooted and nothing can start the shell. - Computer is offThe tablet stays on the Android home screen. Nothing is wrong.
Never do this
- Do not run
adb remountor edit /system. A boot script placed under /system/etc/init this way bootlooped the tablet and ended in a factory reset. All persistence here lives in /data plus the host watcher. - Do not patch boot or vbmeta, or install Magisk-style modifications for this.
- Do not restart adbd while the shell runs. The shell is adbd’s child process and the screen goes black.
- Do not expect an app to start the shell through adbd: apps cannot connect to adbd on this ROM.