UMIDIGI G7 Tab Pro - TrebleDroid/treble_experimentations GitHub Wiki
UMIDIGI G7 Tab Pro (TG2403GBA)
- MediaTek MT6789 (Helio G99), TrustKernel TEE
- Ships with Android 13 on a vendor frozen at API level 31
- A/B, dynamic partitions, no recovery partition (recovery lives in
vendor_boot)
Which GSIs need patching
These boot without patching:
- AndyYan's LineageOS 20, TrebleDroid-based (Android 13): Download / XDA
- Peter Cai's PeterGSI (Android 14, 16 and 17 builds tested): Download / Source
Other Android 14+ GSIs hang at the boot splash. The TrustKernel TEE refuses KeyMint when the Android version a GSI reports differs from the one the TEE was provisioned under, so /data never mounts. Patch the image with GSI KeyMint Patcher before installing it. It runs on the tablet, and it also fixes the two other known blockers:
- Infinity-X, crDroid, Lunaris: their init overwrites the verified-boot properties before KeyMint reads them. The app's init fix, on by default, handles this.
- AxionOS: its SELinux policy conflicts with this vendor's and cannot compile, so it reboots with no boot animation. Tick Use root before patching and the app removes exactly the conflicting rules.
Prepare for Flashing
- Enable Developer options by tapping Build number in Settings > About tablet
- In Developer options, enable OEM unlocking and USB debugging
- Remove the screen lock (set it to None)
- Keep the stock firmware package on hand so you can restore
Flashing ROM
Do not touch vbmeta on this device. GSIs boot with the stock vbmeta. --disable-verification changes the verified-boot state the encryption keys are bound to and leaves you on a "Try again" / "data is corrupt" screen, and erasing vbmeta bootloops even LineageOS 20.
-
adb reboot bootloader -
Check that you have fastboot drivers
fastboot devices -
Unlock the bootloader. This wipes the tablet.
fastboot flashing unlockConfirm it worked with
fastboot getvar unlocked. Don't trustgetpropfor this: Magisk and TrickyStore spoof it. -
Patch the GSI with GSI KeyMint Patcher first, unless it is one of the GSIs listed above that boot without patching
-
fastboot reboot fastboot -
If the image is larger than about 4 GiB, make room first:
fastboot delete-logical-partition product_a -
fastboot flash system [rom].img -
Factory Reset
fastboot -w -
fastboot reboot
The first boot takes several minutes while it creates and encrypts a new userdata.
Upgrade System
-
adb reboot fastboot -
fastboot flash system [rom].img -
fastboot reboot
No wipe is needed as long as every image reports Android 13. /data's encryption keys were created under 13, and the patcher always reports 13, so the keys keep unlocking. Stock Android 13 to patched LineageOS 21 to patched LineageOS 22 was done this way without a wipe. Switching between vanilla and GApps builds, or to a different GSI family, is still safest with a wipe.
Try a GSI without Flashing (DSU)
Install the patched image with DSU Sideloader, or with root use the app's Install with DSU button. Save the image on internal storage and keep about 5 GB free. A normal reboot returns you to your installed ROM.
If a GSI reboots straight back to your ROM, don't trust /sys/fs/pstore for the reason: on this device it replays one stale crash record forever. The failed boot's kernel log survives in the expdb partition, and the app's Why did it fail to boot? button (root) reads it.
Restore to Stock
- Flash the stock firmware with SP Flash Tool in Download Only mode, using its scatter file. See How to install XML Scatter firmware on Mediatek Devices
- Never use Format All. It erases device-specific partitions such as nvram and protect
- A sparse
super.imgcan fail at 98% in SP Flash Tool; use a raw one - If vbmeta was modified and the tablet no longer boots, reflash the stock
vbmeta.img,vbmeta_system.imgandvbmeta_vendor.imgin fastboot without any disable flags
Hardware support
Tested on patched LineageOS 22.2.
| Component | Comment |
|---|---|
| Headphone jack | Sound keeps playing through the speakers until the devinputjack overlay is enabled in Phh Treble Settings |
| WiFi | Works |
| WiFi hotspot | Works |
| Speaker | Works |
| Touchscreen / Display | Works |
| Camera | Not tested |
| Bluetooth | Not tested |
| GPS | Not tested |
| SIM / Mobile Data / Voice | Not tested |
| Widevine | L3 |
| Play Integrity | MEETS_BASIC_INTEGRITY (with Play Integrity Fork) |
Tested ROM
Without patching
AndyYan LineageOS 20 TrebleDroid-based, arm64_bgN (Android 13)
peter_gsi_arm64_20240811 (Android 14)
PeterGSI Android 16 build (Android 16)
peter_gsi_arm64_20260803 (Android 17)
Patched with GSI KeyMint Patcher
LineageOS 21 (Android 14)
LineageOS 22.2 (Android 15)
LineageOS 23.2 (Android 16)
Axion-2.8-GSI_treble_arm64-ab-VANILLA-20260904.img (Android 16), with Use root ticked
Infinity-X 3.12 (Android 16)
crDroid 10 (Android 14) and crDroid 11 (Android 15)
Lunaris-AOSP 3.12
Project CiRCLE (Android 16)
AviumUI (Android 16)
Tested by trinineba-oss on TG2403GBA, stock firmware V1.0_20241121, September 2026. |Works| | Speaker |Works| | Touchscreen / Display |Works| | Camera |Not tested| | Bluetooth |Not tested| | GPS |Not tested| | SIM / Mobile Data / Voice |Not tested| | Widevine |L3| | Play Integrit