Home Forum Blog Private Support Courses
Our courses are now on YouTube! Start Watching
Hovatek Forum OPERATING SYSTEMS Android [Please help] Q30 UIS7861 Head Unit GSI Flash

[Please help] Q30 UIS7861 Head Unit GSI Flash

[Please help] Q30 UIS7861 Head Unit GSI Flash

nec093
nec093
nec093
Enthusiastic Member
5
13-08-2026, 03:31 PM
#1



I'm trying to install GSI on a head unit I purchased from AliExpress.

The head unit's specs are as follows:

Chipset: UNISOC UIS7861 (uis7861_6h10)
Android: 14 (MocorDroid14)
RAM: 4GB / ROM: 64GB
Screen: 10.25 inch, 1920x720
Bluetooth name visible in firmware: Q30_1025EFPSL / Q30_1025E4GFPSL
Kernel: Linux 5.15.123rc, compiled January 28, 2026
Partitions: A/B slot (logo_a/b, fbootlogo_a/b, boot_a/b, etc.)

The bootloader is already unlocked, but flashing system_a as-is causes a reboot right after the bootloader screen due to AVB, so I tried disabling AVB by modifying the vbmeta flags.
However, rewriting vbmeta caused verification to fail on the U-Boot side, triggering an immediate reboot, so I disassembled it and disabled the verification routines, among other things.
I've pushed my findings from investigating how to bypass U-Boot and AVB to the following repository:
https://github.com/nec093/uis7861-uboot-avb-bypass

This made it possible to fully modify system_a and other partitions, but flashing a GSI results in the following issues:

Lineage 21.0/22.2 -> bootanimation loop
AOSP 18.1 -> bootloop (kernel panic due to failed move mount of /second_stage_resources)

Currently, I'm modifying the stock ROM instead — removing unnecessary apps, patching SystemUI, etc. — so I don't strictly need to get a GSI working, but it feels like a waste to stop here, so I'd like to hear opinions from people with more expertise.
hovatek
hovatek
hovatek
Administrator
50,977
19-08-2026, 11:59 AM
#2
(13-08-2026, 03:31 PM)nec093 ...

Lineage 21.0/22.2 -> bootanimation loop
AOSP 18.1 -> bootloop (kernel panic due to failed move mount of /second_stage_resources)
..

What was the active slot after the GSI was flashed? Were you able enter fastboot and check?

Learn MediaTek, Unisoc / Spreadtrum (SPD) and Qualcomm Software Repairs @ https://www.hovatek.com/training
Note!
We have a reply schedule for Forum Support. Please try Private Support if you can't wait.
nec093
nec093
nec093
Enthusiastic Member
5
22-08-2026, 02:38 PM
#3
(19-08-2026, 11:59 AM)hovatek
(13-08-2026, 03:31 PM)nec093 ...

Lineage 21.0/22.2 -> bootanimation loop
AOSP 18.1 -> bootloop (kernel panic due to failed move mount of /second_stage_resources)
..

What was the active slot after the GSI was flashed? Were you able enter fastboot and check?

The slot was set to "a".
I applied a patch to write logs to a partition not used by the system image, but no output was produced.
I also considered the possibility of issues related to platform signing and replaced all signatures with AOSP debug signatures, but this made no difference.
Since I verified these steps using the stock ROM—where both the logger and the signature changes worked correctly—I believe the issue lies with the GSI.
As it has become difficult to resolve this through software alone, I plan to purchase a logic analyzer to see if I can extract the logs via UART.
hovatek
hovatek
hovatek
Administrator
50,977
30-08-2026, 06:50 AM
#4
(22-08-2026, 02:38 PM)nec093 ...I believe the issue lies with the GSI...

So it seems.
Please keep us updated.

Learn MediaTek, Unisoc / Spreadtrum (SPD) and Qualcomm Software Repairs @ https://www.hovatek.com/training
Note!
We have a reply schedule for Forum Support. Please try Private Support if you can't wait.
nec093
nec093
nec093
Enthusiastic Member
5
03-09-2026, 04:40 AM
#5

Mediatek Course Mediatek Course


I was able to capture the U-Boot and kernel logs via UART.
Moving forward, I will flash the GSI and proceed with the analysis.

stock-rom uart log
```
UUUUUUERS
NPK
RBS
ddr init start!!!
ADC Volt Value0x0000046B

vref_adj_p0x00000050 0x00000050
MR0 value:0x00001818
MR0 value:0x00001818
DRAM CS0 MR8/7/6/5:0x0E000601
DRAM CS1 MR8/7/6/5:0x0E000601
DRAM Type: 0x400C10C1
ddr target freq:0x00000400 MHzddr init done!!!NOTICE: BL31: v1.4, qogirl6, 1f081e2c2(release) (builder@zishcicd0052)
NOTICE: BL31: Built : 22:51:08, May 11 2024
NOTICE: CPU info: freq 1536MHz, MIPS 2303
[00000049]

U-Boot 2015.07-00001-g9926025-dirty (Aug 13 2025 - 14:52:44 +0800)QOGIRL6

DRAM: [00000135] last shutdown flag ANA_REG_GLB_POR_OFF_FLAG:0x0
Using default environment

In: Out: Err:
[00000423] Error!sysdump_save_extend_information(): sysdumpdb: Not exception mode .do nothing
[00000431] Error!add_uboot_log_to_section(): add section: bootloader_last_log failed!!
[00000470] Error!mmc_start_init(): Card did not respond to voltage select!
[00002785] enter boot mode 2
[00003339] uboot consume time:3339ms, lcd init consume:552ms, backlight on time:4194ms
[00004657] set_root_of_trust succeeded.
[00006003] Error!fdt_fixup_sp_info(): pmic node not exist!!!
[00006067] Error!fdt_fixup_uboot_log_reserved(): Cannot appendprop uboot_log-mem on/reserved-memoryFDT_ERR_EXISTS
[00006526] enter mode normal, consume time: 6526ms
[ 0.000000]c0 [ T0] Booting Linux on physical CPU 0x0000000000 [0x412fd050]
[ 0.000000]c0 [ T0] Linux version 5.4.147-android12-9-dirty (wming@qh117-R720xd) (Android (7284624, based on r416183b) clang version 12.0.5 (https://android.googlesource.com/toolchain/llvm-project c935d99d7cf2016289302412d708641d52d2f7ee), LLD 12.0.5 (/buildbot/src/android/llvm-toolchain/out/llvm-project/lld c935d99d7cf2016289302412d708641d52d2f7ee)) #68 SMP PREEMPT Wed Aug 13 14:54:42 CST 2025
[ 0.000000]c0 [ T0] Machine model: Spreadtrum UIS7861 6H10 SoC
[ 0.000000]c0 [ T0] earlycon: sprd_serial0 at MMIO 0x00000000200b0000 (options '115200n8')
[ 0.000000]c0 [ T0] printk: bootconsole [sprd_serial0] enabled
[ 0.000000]c0 [ T0] [20240718]kernel_loglevel()[88]: loglevel=1
[ 0.000000]c0 [ T0] [20250527]device_version()[112]: acc_cable=carcharger
[ 0.004000]c0 [ T1] sprd-sysdump: [sysdump_info_init]vmcore info init end!
```
hovatek
hovatek
hovatek
Administrator
50,977
03-09-2026, 07:16 AM
#6
Thanks for the update. Keep them coming
nec093
nec093
nec093
Enthusiastic Member
5
03-09-2026, 05:51 PM
#7
After some analysis and debugging, I successfully booted the GSI!
I managed to run Lineage 23 (Android 16) on a device that originally ran Android 12.

Here is a brief explanation of the steps I took:

1. Bypassed U-Boot AVB verification and the Unisoc-specific verification process (I have already pushed this to GitHub).
2. Flashed the AOSP 12 GSI and analyzed the kernel logs via UART.
3. Patched `vendor_boot` and set the log level to 7.
4. Configured the system to allow ADB connections during the boot animation while monitoring kernel logs.
5. Identified via logcat that an exception was being caused by `android.hardware.health@2.1-service`.
6. Found an incompatibility between the vendor-side and GSI-side implementations of `/lib64/android.hardware.health`, so I copied the GSI-side file to the vendor partition.
7. After a successful boot, I reverted `vendor_boot` and reset the log level to 1.

However, I have confirmed that AOSP 12 builds from phh get stuck before the boot animation due to the `rw-system.sh` script, and I have not yet resolved this issue.

I plan to upload the detailed findings to GitHub, just as I did last time.
hovatek
hovatek
hovatek
Administrator
50,977
08-09-2026, 10:52 AM
#8
(03-09-2026, 05:51 PM)nec093 After some analysis and debugging, I successfully booted the GSI!
I managed to run Lineage 23 (Android 16) on a device that originally ran Android 12.
Here is a brief explanation of the steps I took:
...

Thanks for the update!

Learn MediaTek, Unisoc / Spreadtrum (SPD) and Qualcomm Software Repairs @ https://www.hovatek.com/training
Note!
We have a reply schedule for Forum Support. Please try Private Support if you can't wait.
Users browsing this thread:
 1 Guest(s)
Users browsing this thread:
 1 Guest(s)
WhTlYt