Tab5 OS is an open ESP-IDF/LVGL environment for the M5Stack Tab5. It combines a file browser with wired, BLE, and Wi-Fi tools for inspecting devices and saving field captures.
Published field beta: v0.6.0.
Unreleased development, 2026-09-30: main adds nine apps: Electronics and Byte Lab, Subnet Lab, Resistor Lab, Modbus TCP, RTU Frames, NTP Lab and Wake-on-LAN, and UDP Console. It also adds a Network launcher tile, a shared byte clipboard, saved serial log inspection, and peripheral, Wi-Fi input and runtime fixes. These additions are not included in v0.6.0.
Hardware coverage is recorded per feature and firmware image in the smoke checklist. The second display family, electrical/recovery/fault checks, and the recent USB brownout follow-up remain open.
| Launcher | Byte Lab: encode Float32 | RTU Frames: decode a reply |
|---|---|---|
![]() |
![]() |
![]() |
Development captures from 2026-09-29 use sample data and contain no credentials, private file contents or network/device identities. Launcher and RTU Frames are ST7121 USB captures; Byte Lab is a native LVGL host render. Click a screenshot for full size. See capture details.
flowchart LR
device["M5Stack Tab5<br/>ESP32-P4"] --> os["Tab5 OS<br/>LVGL launcher"]
os --> apps["Files, notes, clock<br/>and reader apps"]
os --> tools["GPIO, I2C, UART<br/>and BLE tools"]
os --> network["Wi-Fi tools, web<br/>and OTA updates"]
- M5Stack Tab5 (ESP32-P4)
- Original ILI9881C/GT911 and newer ST7123/ST7121 display variants through M5Stack's factory BSP
- For an existing tablet, read Install and recovery and check its partition layout before choosing an app-only, source, or factory flash. Some earlier tablets have a different layout.
- For a blank tablet or a deliberate clean recovery, download the factory image and
SHA256SUMSfrom the latest release, verify the hash, and follow the factory-image instructions. That path erases internal flash settings and files. - After boot, use System to confirm the firmware version, storage, Wi-Fi, and OTA state. Saved file paths and CSV formats are in Data formats.
M5Stack recommends ESP-IDF v5.4.2 for Tab5. Install that exact release using Espressif's setup, then open an ESP-IDF shell.
idf.py set-target esp32p4
idf.py buildBuilding does not require a connected tablet. For faster Windows rebuilds, put the ESP-IDF directory in .idf-path and use the persistent Ninja build wrapper:
.\tools\build_idf.ps1Before flashing, read the installed partition table and check the active partition/address in System. Replace COM7 with your device's port.
The app-only wrapper always writes
0x20000; it does not detect the installed layout or active slot. Use the command below only with the current partition table and activeota_0at0x20000. A legacy tablet may instead have a factory app at0x20000and activeota_0at0x420000with a 4 MiB capacity; the wrapper would update its factory slot. Do not assume0x420000applies to another tablet.
# Confirm the current partition table and active ota_0 at 0x20000 first.
.\tools\flash_idf.ps1 -Port COM7Complete source flashes (idf.py flash or the wrapper's -Full) also rewrite the bootloader, partition table and initial OTA metadata. A layout change does not migrate internal files. Follow Install and recovery with a verified backup and migration plan before choosing that path.
Normal wrapper builds retain the build tree and use project-local ccache with four jobs. In a configured ESP-IDF shell, ninja -C build -j 1 app limits an incremental app build to one job when memory is tight. For a short build/test setup, see Contributing quickstart.
See Install and recovery before a clean erase or when recovering a device that no longer boots. A clean factory recovery erases credentials, settings, both OTA slots, and internal SPIFFS data.
Generated note and telemetry files follow the documented SD-card paths and CSV conventions.
With Tab5 OS running over USB:
python .\tools\remote_desktop.py --port COM7The window mirrors the display at half size and sends clicks and drags back as touch input. Pass --scale 1 for full size.
Hold the Tab5 reset button until its green LED flashes rapidly before flashing. Use Ctrl+] to exit the monitor.
The checked-in defaults include M5Stack's required QIO, 200 MHz PSRAM, and L2-cache settings. Removing them causes MIPI display underruns on the 720p panel.
The System app installs the latest stable tagged GitHub release over Wi-Fi. Pushes and pull requests run verification; a v* tag publishes app-only and factory/recovery images, a versioned OTA manifest, checksums, license/notices, and pinned dependencies from the same build. The updater verifies compatibility, version, exact size, embedded app version, and SHA-256 before activation. Before a new stable tag, run the applicable hardware smoke checks and disclose remaining gaps in its release notes. On a matching rollback-enabled bootloader, OTA candidates remain pending until the UI has stayed healthy for 30 seconds. Updates do not silently erase NVS settings. See the OTA manifest contract and compatibility contract.
External GPIO and I2C signals are 3.3 V only. External 5 V is off at boot and Tab5 OS does not currently expose a control to enable it. See pin and interface safety before connecting external hardware.
See ROADMAP.md for the long-term product plan and current execution checkpoint.
Architecture, troubleshooting, privacy, contribution, security-reporting, compatibility, and hardware-test contracts live in docs/, CONTRIBUTING, and SECURITY.
For help, check Troubleshooting or open a bug report. Share vulnerabilities privately through SECURITY.
The vendored components/m5stack_tab5/ board support comes from the Apache-2.0-licensed component inside M5Stack's M5Tab5-UserDemo; that repository's root license is MIT. The ST7121 driver retains Espressif's Apache-2.0 headers. Managed dependencies are pinned in dependencies.lock; see Third-party notices.
These features are implemented on main; a checked item does not mean that every hardware or fault case has passed. The smoke checklist records measured coverage.
- ESP32-P4 boot
- Display and backlight
- Touch input
- SPIFFS/microSD file browser
- Saved Scope and I2C capture graphs in Files, with zoom, pan, cursor values, and visible-range statistics
- Saved UART and RS-485 logs in Files, with timestamped RX/TX paging, filters, hex/ASCII views, and selected-record copy to the byte clipboard
- Notes, counter, and system apps
- Offline Electronics and Byte Lab apps for circuit/RC calculations, hex/ASCII decoding, integer/Float32 encoding and interpretation, and payload checksums
- Subnet Lab for offline IPv4 prefix/netmask calculations, broadcast and host ranges, and peer membership checks
- Resistor Lab for four/five color bands, tolerance ranges, numeric/R-decimal SMD markings, and EIA-96 decoding
- Internet-synced RTC clock with persistent daily alarms and snooze
- Milwaukee weather plus a static time/date screensaver with hourly and daily forecasts
- GPIO control and eight-channel ADC oscilloscope with frequency/duty measurement, persistent calibration, and SD capture
- External Grove I2C scan, 100/400 kHz reads of 1-32 bytes, one-byte watch/SD capture, saved-read copy into Byte Lab, and gated write on G53/G54
- UART1 and onboard RS-485 terminal with separate transmit/display formats, explicit line endings, exact byte history, clipboard paste/frozen RX copy, and SD capture
- Bounded SPI2 master console with selectable mode/clock, explicit M5-Bus chip-select, and saved RX copy into Byte Lab
- G6 PWM and bounded single-pulse generator with isolated LEDC resources and automatic timeout
- User-controlled Govee H5075 monitoring and COLMI R12 health tools
- User-controlled KICKR cycling telemetry with SD ride logging
- Timed Servo Toy control on G0 with sine sweeps at selectable 0.05-1.00 Hz, random motion, isolated PWM resources, and safe output release
- Persistent brightness, dimmed idle screen, and configurable timed screen-off
- Recoverable notes plus durable ride, summary, ebook, and heart-rate storage paths
- Wi-Fi settings with channel/RSSI scan, password Show/Hide and a compact keyboard, plus a Network launcher app for address details, DNS lookup, four-probe ping, and mDNS service discovery
- HTTP request console with verified HTTPS, gated cleartext, cooperative Cancel/Home, a 15-second transport budget, bounded response headers/previews, and opt-in redacted SD metadata logs
- Modbus TCP inspector with bounded register/coil reads, signed/unsigned/Float32 views and byte-order selection, TCP testing, exception reporting, and cancellation
- RTU Frames for offline Modbus read-frame construction, CRC validation, reply decoding, and request copy to Serial; native checks, firmware build, and ST7121 example/clipboard handoff pass, with wired-fixture and broader panel checks pending
- NTP Lab and Wake-on-LAN for time-server measurements and explicitly confirmed device wake packets
- UDP Console for confirmed hex/ASCII datagrams, bounded reply previews, source-port selection, and cancellation
- Shared byte clipboard for preparing Byte Lab/RTU payloads in Serial, UDP, SPI or MQTT and inspecting complete captured replies without retyping
- MQTT 3.1.1 publish/subscribe console with verified TLS, explicit device-local TLS profiles, QoS/retain visibility, bounded history, and opt-in payload-free SD metadata logs; COPY RX shares complete 0-128-byte binary receives with Byte Lab, and PASTE BYTES prepares an exact byte publish for explicit review/send
- Opt-in generic BLE advertisement scanner and GATT explorer with explicit connections, bounded discovery, reads, notifications/indications, complete received-value copy into Byte Lab, gated raw writes, and atomic evidence snapshots
- AI chat client through an authenticated HTTPS relay
- Start/stop microphone transcription with a live waveform
- Reader-mode web browser with HTTPS and clickable links
- SD-card ebook reader with three first-run Project Gutenberg classics
- Application launcher
- USB remote desktop
- HTTPS OTA updates with rollback support on a matching bootloader and partition layout
Apache-2.0. See Third-party notices.


