# SM-T733 Linux TWRP alpha candidate

**Not yet validated by a clean install on hardware. Do not publish this as a
tested release until that rehearsal succeeds.** The kernel and desktop fixes
have worked on the development tablet; this clean image, firmware extraction,
and recovery installer are new.

Only Galaxy Tab S7 FE **SM-T733 / gts7fewifi** is supported. The first installer
requires microSD, a working unlocked bootloader, the model's working TWRP, and
matching stock firmware still accessible through recovery. It does not install
TWRP or bypass bootloader/Knox protections.

## What is installed

TWRP's **Install ZIP** writes the included BOOT image and a clean Debian 13
ext4 root to the partition named `userdata`. Android userdata, apps and internal
files are erased. The installer resolves named partitions rather than reusing
the developer's partition numbers or UUID. It expands the filesystem to fill
userdata. The GPT, recovery, bootloader, EFS, persist, metadata, vendor_boot,
DTBO, vbmeta and stock system/vendor partitions are not written. Retained stock
partitions provide firmware extraction and a simpler restore route; Android
does not run underneath Linux.

The clean account is **tablet** (UID 1000). Both tablet and root initially have
locked passwords. Set your own tablet password locally in TWRP before booting.
Root remains locked; use `sudo` with your tablet password after login. No shared
default password or owner credentials are included.

The ZIP includes the 60 Hz/native-GNOME graphics configuration, Adreno renderer,
password locking/backlight wake, power profiles, Wi-Fi integration, bounded zram,
USB policy initialization, larger keyboard, and the build-4 stability kernel.
Proprietary firmware and Widevine are not bundled. Firmware is extracted from
your own read-only stock vendor/APNHLOS mounts; the six GPU firmware hashes must
match the tested set before any partition is written.

## Before installation

1. Back up your data **off the tablet**. In TWRP back up BOOT and userdata to
   microSD or a computer, and verify that the backup is readable. Android's
   internal `/sdcard` is part of userdata and will be erased.
2. Have the exact model's stock restore files and an already working Download
   Mode restore route. Installing Linux changes normal BOOT and userdata.
   A BOOT backup alone cannot restore erased Android userdata.
3. Copy the candidate ZIP and its SHA256SUMS to microSD. Keep the archive on the
   external SD mount `/external_sd` or `/sdcard1`; this first installer refuses
   internal storage and ADB sideload. Keep adequate battery charge.
4. Check the ZIP checksum on the computer. The installer also checks complete
   payloads and readbacks. Do not proceed with a different model/firmware or
   ignore a failed checksum.
5. If userdata is encrypted, use TWRP **Wipe > Format Data**, enter `yes`, and
   reboot back into recovery before installation. This erases userdata. The
   installer refuses an active device-mapper mapping over userdata. Do not
   manually delete partitions or alter the GPT.

## Install and set the password

1. In TWRP select **Install**, choose the external microSD storage, select
   `s7fe-linux-twrp-alpha1-candidate.zip`, and swipe to install.
2. Wait for successful installation. The installer saves a verified original
   BOOT in `s7fe-pre-linux-backup` on microSD, writes userdata first, copies your
   local firmware, and writes BOOT last. Do not interrupt a write.
3. Stay in recovery. Connect USB to a computer with Android platform-tools and
   open an interactive recovery shell. Run whichever path matches your external
   SD mount (the ordinary TWRP command panel may not support interactive prompts):

   ```sh
   adb shell -t /sbin/sh /external_sd/s7fe-set-password.sh
   ```

   or:

   ```sh
   adb shell -t /sbin/sh /sdcard1/s7fe-set-password.sh
   ```

   Enter your chosen tablet password twice when `passwd` prompts. Input is
   hidden. Keep the password out of public logs. If your recovery provides a true
   interactive terminal, it can run `/sbin/sh /external_sd/s7fe-set-password.sh`
   directly instead. The helper refuses a non-interactive input stream.
4. Only after password setup succeeds, choose **Reboot > System**. Log in as
   `tablet`. Use the Samsung tablet GNOME session if a session selector appears.
   Connect Wi-Fi, choose your timezone, and test locking/wake.

This uses **Install ZIP**, not TWRP Restore and not a raw userdata image selected
as BOOT. Do not flash `userdata.ext4` to BOOT or recovery. `boot.img` on its own
does not install the Linux root or extract required device firmware.

## Restore

Return to TWRP using the already tested button sequence. Restore your verified
original BOOT and Android userdata backups from external storage. If userdata
cannot be restored or Android's encryption state is incompatible, use the
matching model's established stock restore procedure and reformat data as that
procedure requires. Do not flash a different model's stock files. TWRP recovery
is preserved by this installer; failure to boot Linux should not require deleting
or replacing recovery.

If the installer stops after writing userdata but before BOOT, Android's original
BOOT may remain while its data is erased. Return to recovery and restore; do not
assume that restoring BOOT alone restores Android or your files.

## Known limits and required rehearsal

Deep suspend/hibernation, native cameras, Bluetooth and full media audio are not
supported in this candidate. Generic ALSA discovery remains disabled to avoid a
known vendor PCM buffer crash. Netflix playback and hardware video decoding are
not established. USB hub enumeration still needs a physical check. Locking saves
backlight/clock power while retaining panel scanout; it is not deep standby.

Before public distribution, validate the complete ZIP on a backed-up SM-T733:
model/firmware preflight, TWRP installation, local password setup, normal boot,
60 Hz graphics, correct touch, Wi-Fi, lock/wake, reboot, charge-only startup and
the restore route. Record that outcome in RELEASE-STATUS.json. This is the one
missing hardware gate; static verification cannot substitute for it.
