B9: built-in display (ST7735S SPI) in Linux and persistent B9C cache

- B9A: read-only audit of stock LK/DT: the panel is an ST7735S 128x128 on SPI (BLSP1 QUP4,
  16 MHz, mode 3, D/C GPIO116, RESET GPIO118), backlight = PM8916 MPP4 current sink 40 mA.
- B9B: upstream panel-mipi-dbi with the stock init sequence as firmware; MPP4 sink via pinctrl
  + gpio-backlight; first light with correct colours/orientation/offsets.
- B9C: fbcon (6x8, 21x16) on tty1 + getty, UART console kept, aurora-display service;
  cache B9C b9ce13c9 written and verified, cold boots with LTE + Wi-Fi + display.
- B9L (RAM only): lk2nd second stage with an msm8916 SPI panel port shows a picture before Linux.
- Sanitizer: whitelist for b8/ and b9/.
This commit is contained in:
q 2026-10-03 01:45:02 +03:00
parent dddc11e57b
commit 4a7224c41f
108 changed files with 5773 additions and 5 deletions

View file

@ -1309,3 +1309,30 @@ fast MSS restart re-attach needs investigation; single unreproduced cases (pc1 n
START OK 72–89 s → AP ENABLED 76–94 s, phone WPA2/CCMP connected and held 168–188 s, Pronto crash 0, LTE OK, eMMC w=0, SNTP +0.40/+0.996/+0.03 s. START OK 72–89 s → AP ENABLED 76–94 s, phone WPA2/CCMP connected and held 168–188 s, Pronto crash 0, LTE OK, eMMC w=0, SNTP +0.40/+0.996/+0.03 s.
**B8F is now the operational baseline (cache 857c9c30).** PSK only in b8/b8f/private (never publish out/, cache image, W/*.bin). **B8F is now the operational baseline (cache 857c9c30).** PSK only in b8/b8f/private (never publish out/, cache image, W/*.bin).
- Open: sleeping-STA delivery delay, regulatory.db/country RU, production MAC, exact Iris chip, B7 residual at 1 s edge. Next stage: display. - Open: sleeping-STA delivery delay, regulatory.db/country RU, production MAC, exact Iris chip, B7 residual at 1 s edge. Next stage: display.
# Session 37 — B9 display (2026-10-03) — **CLOSED, PASS** — logs/b9/{b9a,b9b,b9c,lk,b9l}/
- B9A (read-only audit): the panel is **not DSI**. It is a 1.44" **ST7735S 128x128 on SPI** (MIPI-DBI type C), BLSP1 QUP4 spi@78b8000 (GPIO12 MOSI, 13 MISO, 14 CS0, 15 CLK),
16 MHz, mode 3, D/C GPIO116 (`disp_dc`), RESET GPIO118 (`disp_rst_n`), RGB565, MADCTL 0xc8, GRAM offset (2,3). Backlight = PM8916 **MPP4 current sink 40 mA**
(0xa340=0x61, 0xa34c=7, 0xa346=0x80); no PWM/WLED/DCS.
- Stock LK (saved aboot) brings the panel up in aboot_init, unconditionally, ~210 ms after LK start. The 19-command sequence equals dtb_01 byte for byte.
panel_id is hardcoded to 1 (no ID read). The built-in 128x128 "4G LTE" logo is used because the splash partition is all zeros.
- Current lk1st has no SPI-panel code.
- B9B (RAM): kernel + DRM/panel-mipi-dbi/fbdev, DTB spi4 + panel (L17/L6 supplies) + MPP4 `function "sink"`/drive-strength 7 + gpio-backlight,
firmware = stock sequence (b9/b9b/mk-panel-fw.py).
- First light: image, colours, orientation and offsets all correct with no change.
- MPP4 reads back exactly 0x60 off / 0x61 on, 0x07, 0x80.
- Without fbcon nothing modesets; an fbdev unblank was needed.
- B9C: + FRAMEBUFFER_CONSOLE + FONT_6x8 only (21x16 console), cmdline `console=tty0` **before** `console=ttyMSM0` (keeps /dev/console = UART),
aurora-display service (fbcon takeover already enables the pipe → backlight on via sysfs), getty tty1, hostname aurora.
- Cache **b9ce13c9** written (B9C_WRITE_VERIFIED, backup = B8F 857c9c30).
- Cold boots: cold1 A, cold2 B (accepted by operator), cold3 A — all PASS; backlight ON→OFF→ON confirmed visually.
- **B9C is the operational baseline.**
- B9-LK audit: stock LK is not in the chain since B5a (aboot = lk1st). lk2nd cont-splash only adopts MDP; mdss_spi is msm8909/8952-only and hard-wired.
- B9L-0: lk1st `fastboot boot` of a 32-bit lk2nd 23.1 works on DB410c TZ + qhypstub.
- B9L-RAM: lk2nd 23.1 + patch (b9/b9l/lk2nd-23.1-aurora-b9l*.patch) — msm8916 QUP4 SPI clocks/pins, 16 MHz clamp, module lk2nd/aurora on CAF spi_qup
(platform mdss_spi.o NOT built: it pulls spi-display.c, which strcmp's a NULL panel.intf).
- **L17 and L6 are ON at LK time** (left on by SBL); no RPM work is needed in LK.
- Test frame, then the operator splash (`swag.png` → RGB565) shown before Linux; Linux fbcon takes over normally.
- Formal run directly from lk1st: PASS (e6849a2b). Nothing flashed.
- Open: lk1st reflash with the panel code (separate GO); ~1 s dark gap at handoff (Linux gpio-backlight pinctrl/fbcon re-init);
DT model string "RAM boot B9B"; screen UI. Next stage: battery / charging / power management.

View file

@ -27,14 +27,14 @@
| B7 — время от сети (DMS/NITZ, без RTC) | **PASS / CLOSED** | | B7 — время от сети (DMS/NITZ, без RTC) | **PASS / CLOSED** |
| Wi-Fi (WCNSS/Pronto + wcn36xx, тестовая AP WPA2, автозапуск из flash) — B8 | **PASS / CLOSED** (см. ниже) | | Wi-Fi (WCNSS/Pronto + wcn36xx, тестовая AP WPA2, автозапуск из flash) — B8 | **PASS / CLOSED** (см. ниже) |
| Router stack (NAT/firewall/VPN) | TODO | | Router stack (NAT/firewall/VPN) | TODO |
| Дисплей в Linux | TODO | | Дисплей ST7735S 128×128 (SPI): DRM/fbcon tty1, подсветка, автозапуск из flash — B9 | **PASS / CLOSED** (см. ниже) |
| Батарея / зарядка | TODO | | Батарея / зарядка | TODO |
## Рабочая цепочка загрузки (baseline B5) ## Рабочая цепочка загрузки (baseline B5)
``` ```
Power → stock SBL1 → DB410c TZ (TZ.BF.3.0) → qhypstub → lk1st (aboot, autoboot) Power → stock SBL1 → DB410c TZ (TZ.BF.3.0) → qhypstub → lk1st (aboot, autoboot)
→ cache: ext2 + extlinux/extlinux.conf → B8F (ядро b8d + DTB b8b + initramfs: модем, время, Wi-Fi) → ARM64 Linux → LTE + Wi-Fi AP → cache: ext2 + extlinux/extlinux.conf → B9C (ядро b9c + DTB b9b + initramfs: модем, время, Wi-Fi, дисплей) → ARM64 Linux → LTE + Wi-Fi AP + консоль на экране
Fallback: extlinux не найден / не парсится / не грузится → Android boot image из раздела boot (emmc1 rescue) Fallback: extlinux не найден / не парсится / не грузится → Android boot image из раздела boot (emmc1 rescue)
``` ```
@ -48,13 +48,26 @@ Fallback: extlinux не найден / не парсится / не грузит
| hyp | qhypstub, до 512 KiB | `1a963047` | | hyp | qhypstub, до 512 KiB | `1a963047` |
| aboot | lk1st (lk2nd 23.1) autoboot, подписан qtestsign, до 1 MiB | `3b8cd266` | | aboot | lk1st (lk2nd 23.1) autoboot, подписан qtestsign, до 1 MiB | `3b8cd266` |
| boot | emmc1 rescue image (+ нули до 16 MiB) | `e9579f33` | | boot | emmc1 rescue image (+ нули до 16 MiB) | `e9579f33` |
| cache | ext2 + extlinux + B8F (ядро 7.2.7-aurora-b8d, DTB b8b, initramfs B7C + Wi-Fi) | `857c9c30` (откат: B7C `14fe453a` → T4 `9d3bc890` → B6P `9fea693a`) | | cache | ext2 + extlinux + B9C (ядро 7.2.7-aurora-b9c, DTB b9b, initramfs B8F + дисплей) | `b9ce13c9` (откат: B8F `857c9c30` → B7C `14fe453a` → T4 `9d3bc890` → B6P `9fea693a`) |
| recovery | lk2nd 23.1 (fastboot) | `0dfa60a0` | | recovery | lk2nd 23.1 (fastboot) | `0dfa60a0` |
| modem, NV/EFS, persist, system, userdata | не менялись (Linux монтирует modem FAT только RO) | — | | modem, NV/EFS, persist, system, userdata | не менялись (Linux монтирует modem FAT только RO) | — |
Golden mm1 (Android boot image, для `fastboot boot`): `aurora-mm1.img` sha256 `38c960ef…`, ядро `7.2.7-aurora-bam1 #5`. Golden mm1 (Android boot image, для `fastboot boot`): `aurora-mm1.img` sha256 `38c960ef…`, ядро `7.2.7-aurora-bam1 #5`.
Все хэши целиком: `b5a/SHA256SUMS`, `b5b/SHA256SUMS`, `bootchain-migration/SHA256SUMS`, `linux/*/SHA256SUMS`, [docs/BLOBS.md](docs/BLOBS.md). Все хэши целиком: `b5a/SHA256SUMS`, `b5b/SHA256SUMS`, `bootchain-migration/SHA256SUMS`, `linux/*/SHA256SUMS`, [docs/BLOBS.md](docs/BLOBS.md).
## B9 status — дисплей PASS (2026-10-03)
- Встроенный экран — **не DSI**: 1.44" **ST7735S 128×128 на SPI** (MIPI-DBI type C), BLSP1 QUP4 `spi@78b8000`, 16 MHz, mode 3, CS0,
D/C GPIO116, RESET GPIO118, RGB565, MADCTL `0xc8`, смещение GRAM (2,3). Подсветка — PM8916 **MPP4 как current sink 40 мА**. Питание L17 2.85 V / L6 1.8 V.
Всё восстановлено из stock LK (дизассемблер) и stock DTB: 19 init-команд в LK и DT совпадают побайтно.
- Linux: upstream `panel-mipi-dbi` (firmware-файл со стоковой init-последовательностью, `b9/b9b/mk-panel-fw.py`), DRM + fbdev → `fbcon` 6x8 (21×16) на tty1,
`getty` на tty1, UART-консоль сохранена (`console=tty0` стоит **до** `console=ttyMSM0`). Подсветка: pinctrl MPP `function "sink"`, `drive-strength 7`
+ `gpio-backlight` (регистры = стоковые 0x61/0x07/0x80), включается сервисом `aurora-display` через sysfs.
- Cache B9C: 3 холодных загрузки с eMMC без ввода (2× class A + 1× class B, принято) — консоль ядра на экране, LTE + Wi-Fi AP, время, ошибок дисплея 0.
- B9L (только RAM): lk2nd второй стадии с портом SPI-панели под msm8916 (`b9/b9l/lk2nd-23.1-aurora-b9l.patch`) показывает картинку **до** Linux;
L17/L6 на этапе LK уже включены SBL. lk1st с этим кодом не прошит.
- Открыто: UI вместо консоли ядра, регулировка яркости, ~1 с темноты при передаче LK → Linux, прошивка lk1st с заставкой. Материалы: `b9/`, `logs/b9/`, NOTES.md сессия 37.
## B8 status — Wi-Fi PASS (2026-10-03) ## B8 status — Wi-Fi PASS (2026-10-03)
- Pronto (WCNSS) через upstream `qcom_wcnss` remoteproc: штатный `wcnss.mdt` из RO-FAT `modem`, `wcnss_mem` фиксирован 0x8b600000/6 MiB, - Pronto (WCNSS) через upstream `qcom_wcnss` remoteproc: штатный `wcnss.mdt` из RO-FAT `modem`, `wcnss_mem` фиксирован 0x8b600000/6 MiB,
@ -116,6 +129,7 @@ Safety:
| `b6p/` | persistent-интеграция: контроллер, сервис, конфиг, сборка initramfs/boot.img/cache, эмулятор, запись/откат, тесты | | `b6p/` | persistent-интеграция: контроллер, сервис, конфиг, сборка initramfs/boot.img/cache, эмулятор, запись/откат, тесты |
| `b7/` | B7: время от сети (DMS/NITZ), проверка по NTP, cache B7C | | `b7/` | B7: время от сети (DMS/NITZ), проверка по NTP, cache B7C |
| `b8/` | B8: Wi-Fi — аудит, WCNSS/NV, wcn36xx, hostapd, сервис aurora-wifi, cache B8F (запись/откат/эмулятор) | | `b8/` | B8: Wi-Fi — аудит, WCNSS/NV, wcn36xx, hostapd, сервис aurora-wifi, cache B8F (запись/откат/эмулятор) |
| `b9/` | B9: дисплей — аудит stock LK/DT, panel-mipi-dbi firmware, fbcon/сервис aurora-display, cache B9C, патч lk2nd (SPI-панель в LK) |
| `tools/` | утилиты: UART-логгер, Sahara probe, распаковка boot.img, sanitizer публикации | | `tools/` | утилиты: UART-логгер, Sahara probe, распаковка boot.img, sanitizer публикации |
| `logs/` | sanitized логи: UART, QMI, ModemManager, EDL, результаты тестов | | `logs/` | sanitized логи: UART, QMI, ModemManager, EDL, результаты тестов |
| `android/` | снимок стокового Android (getprop, gpio, input, leds, …), sanitized | | `android/` | снимок стокового Android (getprop, gpio, input, leds, …), sanitized |
@ -124,6 +138,6 @@ Safety:
Полные дампы eMMC и разделов, NV/EFS (`modemst1/2`, `fsg`, `fsc`), `persist`, `userdata`, файлы прошивки модема, Полные дампы eMMC и разделов, NV/EFS (`modemst1/2`, `fsg`, `fsc`), `persist`, `userdata`, файлы прошивки модема,
стоковые SBL1/RPM/TZ/aboot/boot/recovery/system, Firehose-программер, DB410c TZ, собранные бинарники, стоковые SBL1/RPM/TZ/aboot/boot/recovery/system, Firehose-программер, DB410c TZ, собранные бинарники,
Wi-Fi NV (`WCNSS_qcom_wlan_nv.bin`), PSK тестовой AP и образы с ним (B8F initramfs/cache). Wi-Fi NV (`WCNSS_qcom_wlan_nv.bin`), PSK тестовой AP и образы с ним (B8F/B9C initramfs/cache), логотип из stock LK и картинка-заставка B9L.
Идентификаторы (IMEI, IMSI, ICCID, eMMC CID/serial, Sahara serial, MAC, номера сот, cookies) заменены на `<PLACEHOLDER>`. Идентификаторы (IMEI, IMSI, ICCID, eMMC CID/serial, Sahara serial, MAC, номера сот, cookies) заменены на `<PLACEHOLDER>`.
Как это сделано — `tools/publish-sanitize.py`; значения идентификаторов в репозиторий не попадают. Как это сделано — `tools/publish-sanitize.py`; значения идентификаторов в репозиторий не попадают.

8
b9/b9a/SHA256SUMS Normal file
View file

@ -0,0 +1,8 @@
d05df1c29493394d5447c4b6e9880f70aaae8e7e04ca3b244c1ea7e1a5394c40 decode-panel.py
3372e90bfa795e4185761cba5aa505ac90d70ff5fbe53da3f564dc9b25069b9e dt-extract.py
95206962a251a78ecfba6f9848a1efc1020e0680796a14856920725657376fde lkmem.py
c8858233cc912b6df7151b29a3b45a81f2429413e012c368674a10a885bf7f5b lk-xref.py
35ffa32d0c1ba11a7ad21b5fb80151a7344c9af73a1f9a53316be7bf165363ec render-lk-logo.py
aa8ffbb2b53e6123b431485c1a05bd7d4a5cba700cd5f7071c252b6a7d8870fa b9a-live.sh
ec25538528200f3b5ae77a4f023f7d881473eb2e9b1e0eea9184795f5e0438ad b9a-run.sh
ae0b80ce6967cb41d32f6a34e6d3051b879a6638d1145e185007db35e096ed19 disrange.sh

40
b9/b9a/b9a-live.sh Normal file
View file

@ -0,0 +1,40 @@
#!/bin/sh
# B9A (board side, READ-ONLY): snapshot of the display-related state of the running Aurora Linux.
# No writes to GPIO/regulators/PMIC/SPI, no sysfs writes. Only side effect: mounts debugfs if absent (no HW access).
# PMIC registers are read through the regmap debugfs "registers" file (positioned dd reads = SPMI reads only).
echo B9A-LIVE-BEGIN; cat /proc/uptime; cat /proc/device-tree/model; echo; uname -a; cat /proc/cmdline
grep -q " /sys/kernel/debug " /proc/mounts || mount -t debugfs debugfs /sys/kernel/debug
for d in /sys/class/drm /sys/class/graphics /sys/class/backlight /sys/class/leds /sys/class/spi_master /sys/bus/spi/devices /dev/dri; do
echo "--- ls $d"; ls -la $d 2>&1
done
echo "--- /dev/fb*"; ls -la /dev/fb* 2>&1
echo "--- dmesg display/spi/backlight"
dmesg | grep -iE 'display|mdss|mdp|dsi|panel|drm|framebuffer|fbcon|fb[0-9]|backlight|lcd|spi|mipi|dbi|st77|mpp|simple' || echo "(no matches)"
echo "--- DT nodes (status)"
for n in soc@0/display-subsystem@1a00000 soc@0/display-subsystem@1a00000/display-controller@1a01000 \
soc@0/display-subsystem@1a00000/dsi@1a98000 soc@0/display-subsystem@1a00000/phy@1a98300 soc@0/spi@78b8000; do
p=/proc/device-tree/$n; if [ -d $p/ ]; then printf '%s status=' $n; cat $p/status 2>/dev/null || printf '(none=okay)'; echo; else echo "$n ABSENT"; fi
done
echo "--- DT search panel/backlight/framebuffer nodes"
find /proc/device-tree/ -iname '*panel*' -o -iname '*backlight*' -o -iname '*framebuffer*' -o -iname '*lcd*' 2>/dev/null
echo "--- DT reserved-memory"; ls /proc/device-tree/reserved-memory/
echo "--- debugfs gpio (TLMM 12-15 SPI, 116 D/C, 118 RESET; PMIC MPP4)"
grep -E 'gpio(12|13|14|15|116|118) |mpp4|gpiochip' /sys/kernel/debug/gpio
echo "--- pinmux-pins TLMM 12-15,116,118"
for f in /sys/kernel/debug/pinctrl/*/pinmux-pins; do echo "# $f"; grep -E '^pin (12|13|14|15|116|118) ' $f; done
echo "--- pinctrl MPP"; for f in /sys/kernel/debug/pinctrl/*mpp*/pinconf-pins; do echo "# $f"; cat $f; done
echo "--- regulators"
for r in /sys/class/regulator/regulator.*; do printf '%s %s state=%s uV=%s users=%s\n' ${r##*/} "$(cat $r/name)" "$(cat $r/state 2>/dev/null)" "$(cat $r/microvolts 2>/dev/null)" "$(cat $r/num_users 2>/dev/null)"; done
echo "--- regulator_summary (l6/l17)"; grep -iE 'l6|l17|regulator ' /sys/kernel/debug/regulator/regulator_summary 2>/dev/null | head -20
echo "--- regmaps"; ls /sys/kernel/debug/regmap/
# rd SID ADDR N: SID0 = 0-00 (MPP, PON), SID1 = 0-01 (LDOs, LPG/PWM) in upstream pm8916.dtsi
rd() { R=/sys/kernel/debug/regmap/0-0$1/registers; echo "# PMIC sid$1 $2 +$3"; [ -r $R ] && dd if=$R bs=9 skip=$(($2)) count=$(($3)) 2>/dev/null; }
echo "--- PM8916 MPP4 block (0xa300: 04=subtype,08=status,40=MODE_CTL,41=DIG_VIN,42=PULL,46=EN_CTL,4c=SINK_CTL)"
rd 0 0xa304 2; rd 0 0xa308 1; rd 0 0xa340 8; rd 0 0xa34c 1
echo "--- PM8916 LDO6 (0x4500) / LDO17 (0x5000): 08=STATUS 40/41=VSET 45=MODE 46=EN_CTL"
rd 1 0x4504 2; rd 1 0x4508 1; rd 1 0x4540 2; rd 1 0x4545 2
rd 1 0x5004 2; rd 1 0x5008 1; rd 1 0x5040 2; rd 1 0x5045 2
echo "--- PM8916 PWM/LPG 0xbc00 (46=EN_CTL)"; rd 1 0xbc04 2; rd 1 0xbc46 1
echo "--- clocks (mdss/blsp1_qup4)"; grep -E 'mdss|qup4_spi|blsp1_ahb' /sys/kernel/debug/clk/clk_summary 2>/dev/null | head -20
echo "--- eMMC"; cat /sys/block/mmcblk0/stat
echo B9A-LIVE-END

11
b9/b9a/b9a-run.sh Normal file
View file

@ -0,0 +1,11 @@
#!/bin/sh
# B9A (480s side, READ-ONLY): push b9a-live.sh to board RAM (/tmp) over NCM nc, run it via telnet, save the output.
# Board must already be up (normal B8F boot). Nothing is written to eMMC; no reboot.
set -e; cd ~/doc/modem/jz08-aurora; O=logs/b9/b9a; mkdir -p $O; S=b9/b9a/b9a-live.sh; P=9931
tn() { { sleep 1; printf '%s\r\n' "$1"; sleep $2; } | ncat 172.16.42.1 23 | tr -d "\000\r"; }
tn "nc -l -p $P > /tmp/b9a-live.sh &" 1 > /dev/null
sleep 1; ncat --send-only 172.16.42.1 $P < $S
tn "sha256sum /tmp/b9a-live.sh" 2 | grep b9a-live
sha256sum $S
tn "sh /tmp/b9a-live.sh 2>&1" 15 | sed -n '/^B9A-LIVE-BEGIN/,/^B9A-LIVE-END/p' > $O/b9a-linux-display.raw.txt
wc -l $O/b9a-linux-display.raw.txt

45
b9/b9a/decode-panel.py Normal file
View file

@ -0,0 +1,45 @@
#!/usr/bin/env python3
"""B9A read-only: decode the ST7735S init sequence from (a) stock LK lk.bin command table and
(b) stock dtb_01 qcom,mdss-spi-on-command, and compare them byte-for-byte.
LK table (gcdb mdss_spi_cmd, 16 B each): u32 size, u32 payload_ptr, u32 wait_ms, u8 cmds_post_tg.
DT format (msm-3.10 mdss_spi_panel): repeated [wait_ms, len, cmd, params...]; wait applies after the command.
usage: decode-panel.py lk.bin dtb_01.dts"""
import re, struct, sys
BASE = 0x8f600000
lk = open(sys.argv[1], 'rb').read()
dts = open(sys.argv[2]).read()
NAMES = {0x01: 'SWRESET', 0x11: 'SLPOUT', 0x20: 'INVOFF', 0x21: 'INVON', 0x28: 'DISPOFF', 0x29: 'DISPON',
0x2a: 'CASET', 0x2b: 'RASET', 0x2c: 'RAMWR', 0x36: 'MADCTL', 0x3a: 'COLMOD', 0xb1: 'FRMCTR1',
0xb2: 'FRMCTR2', 0xb3: 'FRMCTR3', 0xb4: 'INVCTR', 0xc0: 'PWCTR1', 0xc1: 'PWCTR2', 0xc2: 'PWCTR3',
0xc3: 'PWCTR4', 0xc4: 'PWCTR5', 0xc5: 'VMCTR1', 0xe0: 'GMCTRP1', 0xe1: 'GMCTRN1', 0x10: 'SLPIN'}
def lk_cmds(table, n):
out = []
for i in range(n):
size, ptr, wait, post = struct.unpack_from('<IIIB', lk, table - BASE + 16 * i)
out.append((bytes(lk[ptr - BASE:ptr - BASE + size]), wait))
return out
def dt_cmds(node, prop):
m = re.search(re.escape(node) + r' \{.*?' + re.escape(prop) + r' = \[([0-9a-f ]+)\];', dts, re.S)
b = bytes.fromhex(m.group(1)); out = []; i = 0
while i < len(b):
wait, ln = b[i], b[i + 1]; out.append((b[i + 2:i + 2 + ln], wait)); i += 2 + ln
return out
def show(title, cmds):
print(f'== {title}: {len(cmds)} commands')
for i, (p, w) in enumerate(cmds):
print(f' {i:2d} {p[0]:02x} {NAMES.get(p[0], "?"):8s} {p[1:].hex(" "):48s} wait={w} ms')
lkc = lk_cmds(0x8f64849c, 19) # st7735s table, count 19 (pinfo+0xf4/+0xf0, panel_id 1 branch)
dtc = dt_cmds('qcom,mdss_spi_st7735s_wx144_128x128_cmd', 'qcom,mdss-spi-on-command')
show('stock LK st7735s (0x8f64849c)', lkc)
show('stock dtb_01 st7735s on-command', dtc)
print('LK == DT (payload+wait):', lkc == dtc)
for i, (a, b) in enumerate(zip(lkc, dtc)):
if a != b:
print(' diff at', i, a, b)
show('stock dtb_01 st7735s off-command', dt_cmds('qcom,mdss_spi_st7735s_wx144_128x128_cmd', 'qcom,mdss-spi-off-command'))

9
b9/b9a/disrange.sh Executable file
View file

@ -0,0 +1,9 @@
#!/bin/sh
# usage: disrange.sh lk-arm.dis START END (hex, no 0x) — print disassembly range
python3 - "$@" <<'PY'
import sys,re
f,s,e=sys.argv[1],int(sys.argv[2],16),int(sys.argv[3],16)
for l in open(f):
m=re.match(r'([0-9a-f]{8}):',l)
if m and s<=int(m.group(1),16)<e: print(l.rstrip())
PY

22
b9/b9a/dt-extract.py Normal file
View file

@ -0,0 +1,22 @@
#!/usr/bin/env python3
"""B9A read-only: print complete DT node blocks (brace-matched) whose header line matches any regex.
usage: dt-extract.py file.dts 'regex' ['regex' ...]"""
import re, sys
lines = open(sys.argv[1]).read().splitlines()
pats = [re.compile(p) for p in sys.argv[2:]]
i = 0
while i < len(lines):
l = lines[i]
if l.rstrip().endswith('{') and any(p.search(l) for p in pats):
depth = 0; j = i
while True:
depth += lines[j].count('{') - lines[j].count('}')
if depth == 0:
break
j += 1
print(f'# {sys.argv[1]}:{i + 1}-{j + 1}')
print('\n'.join(lines[i:j + 1])); print()
i = j + 1
else:
i += 1

48
b9/b9a/lk-xref.py Normal file
View file

@ -0,0 +1,48 @@
#!/usr/bin/env python3
"""B9A read-only: find literal-pool xrefs to display strings in stock LK (lk.bin @0x8f600000).
usage: lk-xref.py lk.bin lk-arm.dis 'regex' ...
Prints string addr, every literal-pool word referencing it, and the function start
(nearest preceding push/stmdb) of the ldr that loads the pool word."""
import re, sys
BASE = 0x8f600000
lk = open(sys.argv[1], 'rb').read()
dis = open(sys.argv[2]).read().splitlines()
ins = {} # addr -> (word, text)
order = []
for l in dis:
m = re.match(r'([0-9a-f]{8}):\s+([0-9a-f]{8})\s+(.*)', l)
if m:
a = int(m.group(1), 16)
ins[a] = (int(m.group(2), 16), m.group(3))
order.append(a)
def func_start(a):
while a >= BASE:
t = ins.get(a)
if t and (t[1].startswith('push') or t[1].startswith('stmdb\tsp!')):
return a
a -= 4
return None
def loaders(pool):
out = []
for a, (w, t) in ins.items():
m = re.search(r'ldr\w*\s+\w+, \[pc, #(-?\d+)\]', t)
if m and a + 8 + int(m.group(1)) == pool:
out.append(a)
return out
for pat in sys.argv[3:]:
for m in re.finditer(rb'[\x20-\x7e\t\n]{4,}', lk):
s = m.group().decode()
if not re.search(pat, s):
continue
sa = BASE + m.start()
pools = [a for a, (w, _) in ins.items() if w == sa]
print(f'STR 0x{sa:08x} {s!r}')
for p in pools:
for ld in loaders(p):
fs = func_start(ld)
print(f' pool 0x{p:08x} <- ldr 0x{ld:08x} in func 0x{fs:08x}' if fs else f' pool 0x{p:08x} <- 0x{ld:08x}')

19
b9/b9a/lkmem.py Normal file
View file

@ -0,0 +1,19 @@
#!/usr/bin/env python3
"""B9A read-only helper: dump words / strings / bytes from stock lk.bin (base 0x8f600000).
usage: lkmem.py lk.bin w ADDR N | s ADDR | b ADDR N"""
import sys, struct
BASE=0x8f600000
d=open(sys.argv[1],'rb').read()
def w(a): return struct.unpack_from('<I',d,a-BASE)[0]
def s(a):
o=a-BASE
if not (0<=o<len(d)): return None
e=d.find(b'\0',o); t=d[o:e]
return t.decode('latin1') if t and all(32<=c<127 or c in (9,10) for c in t) else None
k=sys.argv[2]; a=int(sys.argv[3],16)
if k=='w':
for i in range(int(sys.argv[4])):
v=w(a+4*i); st=s(v) if BASE<=v<BASE+len(d) else None
print(f'{a+4*i:08x}: {v:08x} {v:10d}' + (f' -> {st!r}' if st else ''))
elif k=='s': print(repr(s(a)))
elif k=='b': print(d[a-BASE:a-BASE+int(sys.argv[4])].hex(' '))

16
b9/b9a/render-lk-logo.py Normal file
View file

@ -0,0 +1,16 @@
#!/usr/bin/env python3
"""B9A read-only: render the 128x128 RGB565 (little-endian u16) default splash embedded in stock LK
(imageBuffer @0x8f64b004, used by display_image_on_screen() when the splash partition has no 'SPLASH!!' header)
to a 2x-scaled PNG. usage: render-lk-logo.py lk.bin out.png"""
import struct, sys, zlib
d = open(sys.argv[1], 'rb').read(); o = 0x8f64b004 - 0x8f600000; W = H = 128
rows = []
for y in range(H):
r = bytearray()
for x in range(W):
v = struct.unpack_from('<H', d, o + (y * W + x) * 2)[0]
r += bytes(((v >> 11 & 31) * 255 // 31, (v >> 5 & 63) * 255 // 63, (v & 31) * 255 // 31)) * 2
rows += [bytes(r)] * 2
def ch(t, b): return struct.pack('>I', len(b)) + t + b + struct.pack('>I', zlib.crc32(t + b) & 0xffffffff)
open(sys.argv[2], 'wb').write(b'\x89PNG\r\n\x1a\n' + ch(b'IHDR', struct.pack('>IIBBBBB', W * 2, H * 2, 8, 2, 0, 0, 0))
+ ch(b'IDAT', zlib.compress(b''.join(b'\0' + r for r in rows))) + ch(b'IEND', b''))

6
b9/b9b/SHA256SUMS Normal file
View file

@ -0,0 +1,6 @@
53a9fc3e6d1926ae0c5b77aa706af6ae8a3c66263426e193a677fda2d6ebf3bf build-b9b.sh
e9d3287302394e8025191b4b5b1d8bc2517c8ed10c9f9442538df1f60f5d47b8 b9b-boot.sh
1eeb3ca2b38256c3d8865269222cca7bff70912c593cfc4ad2f7b0343f6075f3 b9b-cmd.sh
2fcda05952ae08fa2aef020608c56e11d63467aab7caaed3183487f80c9e6d2a mk-panel-fw.py
544c313f10ffeb9b6a33020135a87705182d53653bb1db7a96103a7765f5cbcc gen-patterns.py
d2cc277ac4fc76d544a9b6a60b55ea61673af778b2f14b51ff40fc703e702f50 rootfs/usr/libexec/aurora/b9b/b9b-test.sh

26
b9/b9b/b9b-boot.sh Normal file
View file

@ -0,0 +1,26 @@
#!/bin/sh
# 480s side, B9B RAM boot K: RESET-held power-on -> lk1st fastboot -> `fastboot boot` B9B RAM image. Nothing is flashed;
# eMMC cache stays B8F. Then waits for LTE START OK + Wi-Fi AP ENABLED and saves the display state (b9b-test.sh state).
# Visual checks (show/bl) are run separately with b9b-cmd.sh while the operator looks at the screen.
K=$1; [ -n "$K" ] || { echo "usage: $0 K"; exit 2; }
cd ~/doc/modem/jz08-aurora; O=logs/b9/b9b/ram$K; mkdir -p $O; IMG=b9/b9b/out/aurora-b9b.img
A=$O/host-actions.txt; act() { echo "$(date -u +%H:%M:%S.%3N) $*" | tee -a $A; }
tn() { { sleep 1; sed "s/\$/\r/" "$1"; sleep $2; } | ncat 172.16.42.1 23 | tr -d "\000\r"; }
echo "46e7a6822cf5dd13e50feccb7d205f9fddb155c19ba6eaab8d42d5f9fa8ecf4e $IMG" | sha256sum -c || exit 1
OLD=$(ps -eo pid,cmd | grep "[u]artlog.py /dev/ttyUSB0" | awk '{print $1}'); [ -n "$OLD" ] && kill $OLD; sleep 1
U=logs/uart/b9b-ram$K-$(date +%Y%m%d-%H%M%S); setsid nohup python3 tools/uartlog.py /dev/ttyUSB0 $U > $U.stderr 2>&1 < /dev/null &
echo $U > $O/uartlog-path
act "B9B ram$K: waiting for fastboot <EMMC_SERIAL> (power off >= 90 s, then RESET held + battery -> USB)"
if fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; then act "already in fastboot - wait for power-off"; until ! fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do sleep 1; done; fi
i=0; until fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do i=$((i+1)); [ $i -ge 600 ] && { act "ABORT: no fastboot"; exit 1; }; sleep 2; done
act "fastboot present"; { fastboot boot $IMG 2>&1; echo "rc=$?"; } | tee -a $A
i=0; until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do i=$((i+1)); [ $i -ge 180 ] && { act "ABORT: NCM not up"; cp $U.log $O/uart.log; exit 1; }; sleep 1; done; act "NCM ping ok"
printf 'cat /proc/device-tree/model; echo; uname -r; grep -E "START OK|FAIL in|rollback" /run/aurora-modem/lifecycle.log | tail -1\n' > $O/.w
i=0; until tn $O/.w 3 | grep -qE "^\[[0-9.]+\] .*(=== START OK|FAIL in|rollback)"; do i=$((i+1)); [ $i -ge 80 ] && { act "no START OK/FAIL after ~12 min"; break; }; sleep 6; done
tn $O/.w 3 | grep -aE "Aurora|aurora-b9|START OK|FAIL" | tee -a $A
printf 'grep -E "AP ENABLED|FAIL" /run/aurora-wifi/wifi.log | tail -1\n' > $O/.a
i=0; until tn $O/.a 3 | grep -qE "^\[[0-9.]+\] (=== AP ENABLED|FAIL)"; do i=$((i+1)); [ $i -ge 20 ] && { act "no AP ENABLED/FAIL after ~3 min"; break; }; sleep 6; done
act "wifi: $(tn $O/.a 3 | grep -E '^\[[0-9.]+\] (=== AP ENABLED|FAIL)' | tail -1)"
printf '/usr/libexec/aurora/b9b/b9b-test.sh state\n' > $O/.s
tn $O/.s 12 | sed -n '/^B9B-STATE-BEGIN/,/^B9B-STATE-END/p' > $O/state-boot.txt; act "state saved ($(wc -l < $O/state-boot.txt) lines)"
cp $U.log $O/uart.log

5
b9/b9b/b9b-cmd.sh Normal file
View file

@ -0,0 +1,5 @@
#!/bin/sh
# 480s side: run one b9b-test.sh / shell command on the board over telnet and append the output to logs/b9/b9b/ramK/steps.txt.
# usage: b9b-cmd.sh K WAIT_S 'command'
K=$1; W=$2; C=$3; cd ~/doc/modem/jz08-aurora; O=logs/b9/b9b/ram$K; mkdir -p $O
{ echo "=== $(date -u +%H:%M:%S) \$ $C"; { sleep 1; printf '%s\r\n' "$C"; sleep $W; } | ncat 172.16.42.1 23 | tr -d "\000\r" | sed '1,/\$ \|# /{/^~ #\|^\s*$/d}'; } | tee -a $O/steps.txt

32
b9/b9b/build-b9b.sh Normal file
View file

@ -0,0 +1,32 @@
#!/bin/sh
# B9B RAM test image (fastboot boot only - never flash, cache B8F untouched):
# kernel = out-b9b (b8d + DRM + DRM_PANEL_MIPI_DBI + DRM_FBDEV_EMULATION, see linux/aurora-b9b.config)
# DTB = linux/dts/msm8916-jz08-aurora-b9b.dtb (B8B + spi@78b8000 + ST7735S panel-mipi-dbi + L17 + MPP4 gpio-backlight)
# initramfs = exact B8F initramfs (LTE + time + Wi-Fi autostart) + overlay: panel firmware, test frames, b9b-test.sh
# out/ contains the B8F initramfs (Wi-Fi PSK) -> never publish b9/b9b/out.
set -e; cd "$(dirname "$0")"; O=out; KB=/home/q/aurora-kbuild/out-b9b; L=../../linux; F8=../../b8/b8f/out
G=$L/artifacts/ramboot-mm1; GEN=$L/out/usr/gen_init_cpio; TS=1790726400; FW='jz08au,aurora-st7735s.bin'
mkdir -p $O
echo "abb3bd6757e77eae90b3c9eb9d8b3f09e7a906256a53c80033853eb82b8e3f2f $F8/initramfs-b8f.cpio.gz" | sha256sum -c
grep -q '^CONFIG_DRM_PANEL_MIPI_DBI=y' $KB/.config && grep -q '^CONFIG_DRM_FBDEV_EMULATION=y' $KB/.config && grep -q '^CONFIG_LOCALVERSION="-aurora-b9b"' $KB/.config
python3 mk-panel-fw.py ../../bootchain/aboot-analysis/lk.bin ../../dt/dtb_01.dts "$O/$FW" > $O/panel-fw.txt
python3 gen-patterns.py $O/patterns > /dev/null
cp $KB/arch/arm64/boot/Image.gz $O/Image.gz; cp $KB/.config $O/config-b9b; cp $L/dts/msm8916-jz08-aurora-b9b.dtb $O/aurora-b9b.dtb
cat $O/Image.gz $O/aurora-b9b.dtb > $O/Image.gz-dtb
{
echo "dir /lib/firmware 0755 0 0"
echo "file /lib/firmware/$FW $O/$FW 0644 0 0"
echo "dir /usr/libexec/aurora 0755 0 0"
echo "dir /usr/libexec/aurora/b9b 0755 0 0"
echo "file /usr/libexec/aurora/b9b/b9b-test.sh rootfs/usr/libexec/aurora/b9b/b9b-test.sh 0755 0 0"
echo "dir /usr/libexec/aurora/b9b/patterns 0755 0 0"
for f in $O/patterns/*.565 $O/patterns/*.8888; do echo "file /usr/libexec/aurora/b9b/patterns/${f##*/} $f 0644 0 0"; done
} > $O/overlay-b9b.list
$GEN -t $TS $O/overlay-b9b.list > $O/overlay-b9b.cpio
gzip -9 -n -c $O/overlay-b9b.cpio > $O/overlay-b9b.cpio.gz
cat $F8/initramfs-b8f.cpio.gz $O/overlay-b9b.cpio.gz > $O/initramfs-b9b.cpio.gz
python3 ../../b6p/mkbootimg.py $O/Image.gz-dtb $O/initramfs-b9b.cpio.gz $G/cmdline.txt $O/aurora-b9b.img
# RAM-boot layout (lk1st fastboot boot): kernel @0x80000000 + image_size must stay below DTB @0x81e00000
SZ=$(python3 -c "import struct;print(struct.unpack_from('<Q',open('$KB/arch/arm64/boot/Image','rb').read(24),16)[0])")
printf 'kernel image_size 0x%x, end 0x%x (< 0x81e00000 DTB)\n' $SZ $((0x80000000 + SZ)); [ $((0x80000000 + SZ)) -lt $((0x81e00000)) ]
(cd $O && sha256sum Image.gz aurora-b9b.dtb Image.gz-dtb config-b9b "$FW" overlay-b9b.cpio.gz initramfs-b9b.cpio.gz aurora-b9b.img > SHA256SUMS; cat SHA256SUMS); ls -l $O/aurora-b9b.img

56
b9/b9b/gen-patterns.py Normal file
View file

@ -0,0 +1,56 @@
#!/usr/bin/env python3
"""B9B: 128x128 test frames for /dev/fb0, in RGB565 (little-endian u16, fb native) and XRGB8888, plus PNG previews.
Frames: red, green, blue, white, black, and 'geo' = geometry/orientation/colour chart:
- 1-px white border on the outermost rows/columns (all 4 edges must be visible -> no crop/offset error),
- 2nd row/column inside the border black (a 1-px shift shows up as a doubled or missing line),
- corner blocks 24x24: top-left RED, top-right GREEN, bottom-left BLUE, bottom-right WHITE,
- centre: 3 vertical bars R | G | B (rows 40..87), and a yellow arrow pointing UP above them.
usage: gen-patterns.py outdir"""
import os, struct, sys, zlib
W = H = 128
O = sys.argv[1]; os.makedirs(O, exist_ok=True)
R, G, B, Wh, K, Y = (255, 0, 0), (0, 255, 0), (0, 0, 255), (255, 255, 255), (0, 0, 0), (255, 255, 0)
def solid(c): return [[c] * W for _ in range(H)]
def geo():
p = solid(K)
for y in range(H):
for x in range(W):
if x in (0, W - 1) or y in (0, H - 1):
p[y][x] = Wh
elif 2 <= x < 26 and 2 <= y < 26:
p[y][x] = R
elif W - 26 <= x < W - 2 and 2 <= y < 26:
p[y][x] = G
elif 2 <= x < 26 and H - 26 <= y < H - 2:
p[y][x] = B
elif W - 26 <= x < W - 2 and H - 26 <= y < H - 2:
p[y][x] = Wh
elif 40 <= y < 88 and 28 <= x < 100:
p[y][x] = (R, G, B)[(x - 28) // 24]
elif 6 <= y < 34 and abs(x - 63.5) <= (y - 6) * 0.5 and y < 22: # arrow head
p[y][x] = Y
elif 22 <= y < 34 and 58 <= x < 70: # arrow shaft
p[y][x] = Y
return p
def rgb565(p): return b''.join(struct.pack('<H', (r >> 3) << 11 | (g >> 2) << 5 | b >> 3) for row in p for (r, g, b) in row)
def xrgb8888(p): return b''.join(struct.pack('<I', r << 16 | g << 8 | b) for row in p for (r, g, b) in row)
def png(path, p, s=2):
def ch(t, b): return struct.pack('>I', len(b)) + t + b + struct.pack('>I', zlib.crc32(t + b) & 0xffffffff)
rows = []
for row in p:
line = b'\0' + b''.join(bytes(c) * s for c in row)
rows += [line] * s
open(path, 'wb').write(b'\x89PNG\r\n\x1a\n' + ch(b'IHDR', struct.pack('>IIBBBBB', W * s, H * s, 8, 2, 0, 0, 0))
+ ch(b'IDAT', zlib.compress(b''.join(rows))) + ch(b'IEND', b''))
frames = {'red': solid(R), 'green': solid(G), 'blue': solid(B), 'white': solid(Wh), 'black': solid(K), 'geo': geo()}
for n, p in frames.items():
open(f'{O}/{n}.565', 'wb').write(rgb565(p))
open(f'{O}/{n}.8888', 'wb').write(xrgb8888(p))
png(f'{O}/geo-expected.png', frames['geo'], 3)
print('ok', sorted(os.listdir(O)))

36
b9/b9b/mk-panel-fw.py Normal file
View file

@ -0,0 +1,36 @@
#!/usr/bin/env python3
"""B9B: build the panel-mipi-dbi firmware file from the stock Aurora ST7735S init sequence.
Source of truth = stock LK command table (lk.bin @0x8f64849c, 19 entries); it must equal stock dtb_01
qcom,mdss-spi-on-command byte-for-byte (else STOP). Nothing is "improved": same commands, same parameters, same
delays. Only the final RAMWR (0x2c, no params) is dropped - the mipi-dbi driver issues CASET/RASET/RAMWR itself
for every frame update.
Format (drivers/gpu/drm/tiny/panel-mipi-dbi.c): "MIPI DBI" + 7x00 + version 1, then cmd, nparams, params...;
delay = cmd 0x00 with 1 param (ms).
usage: mk-panel-fw.py lk.bin dtb_01.dts out.bin"""
import importlib.util, os, sys
spec = importlib.util.spec_from_file_location('dp', os.path.join(os.path.dirname(__file__), '../b9a/decode-panel.py'))
sys_argv = sys.argv; sys.argv = [sys_argv[0], sys_argv[1], sys_argv[2]]
import io, contextlib
dp = importlib.util.module_from_spec(spec)
with contextlib.redirect_stdout(io.StringIO()):
spec.loader.exec_module(dp) # defines lkc (LK table) and dtc (DT on-command)
sys.argv = sys_argv
lk, dt = dp.lkc, dp.dtc
if lk != dt or len(lk) != 19:
sys.exit('STOP: stock LK table != stock DT on-command')
assert lk[-1] == (b'\x2c', 0), lk[-1]
out = bytearray(b'MIPI DBI' + bytes(7) + bytes([1]))
for payload, wait in lk[:-1]: # 18 commands, RAMWR dropped
out += bytes([payload[0], len(payload) - 1]) + payload[1:]
if wait:
assert wait <= 255
out += bytes([0x00, 0x01, wait])
open(sys.argv[3], 'wb').write(out)
# human-readable listing
for payload, wait in lk[:-1]:
print(f'{payload[0]:02x} {dp.NAMES.get(payload[0], "?"):8s} {payload[1:].hex(" ")}' + (f' + delay {wait} ms' if wait else ''))
print(f'dropped: 2c RAMWR (driver writes memory itself); file {len(out)} bytes')

8
b9/b9b/out/SHA256SUMS Normal file
View file

@ -0,0 +1,8 @@
afdddcef1af3928a27dc6eb3973cd2a1fe1177c55ccf4b74f78555095d4897d5 Image.gz
7ca9cc794a3b85d3b7240f6311ad03bee9e1a4a59aae2ed9438318e853f7c3dc aurora-b9b.dtb
21e4a93311c3e288d3a8fca6277ed365f806735fca0aaf4c6201d5b872ef9f02 Image.gz-dtb
95d59390fee6367b0a2c0de97617dd0d693422d29aa3361e3b93a629e3f1e574 config-b9b
58697d4db45a9af85ec09e03a4212955ae3c7eed7d9f6bda82071da1b44329b4 jz08au,aurora-st7735s.bin
5b5e07bd145e549b3e6f194f51937895436f57ea8333f03a1fc307911f65174d overlay-b9b.cpio.gz
8a97e93b4a9460343d7cc9788505e35c756a0b74838637b8cc14498d43cee8c7 initramfs-b9b.cpio.gz
46e7a6822cf5dd13e50feccb7d205f9fddb155c19ba6eaab8d42d5f9fa8ecf4e aurora-b9b.img

View file

@ -0,0 +1,18 @@
dir /lib/firmware 0755 0 0
file /lib/firmware/jz08au,aurora-st7735s.bin out/jz08au,aurora-st7735s.bin 0644 0 0
dir /usr/libexec/aurora 0755 0 0
dir /usr/libexec/aurora/b9b 0755 0 0
file /usr/libexec/aurora/b9b/b9b-test.sh rootfs/usr/libexec/aurora/b9b/b9b-test.sh 0755 0 0
dir /usr/libexec/aurora/b9b/patterns 0755 0 0
file /usr/libexec/aurora/b9b/patterns/black.565 out/patterns/black.565 0644 0 0
file /usr/libexec/aurora/b9b/patterns/blue.565 out/patterns/blue.565 0644 0 0
file /usr/libexec/aurora/b9b/patterns/geo.565 out/patterns/geo.565 0644 0 0
file /usr/libexec/aurora/b9b/patterns/green.565 out/patterns/green.565 0644 0 0
file /usr/libexec/aurora/b9b/patterns/red.565 out/patterns/red.565 0644 0 0
file /usr/libexec/aurora/b9b/patterns/white.565 out/patterns/white.565 0644 0 0
file /usr/libexec/aurora/b9b/patterns/black.8888 out/patterns/black.8888 0644 0 0
file /usr/libexec/aurora/b9b/patterns/blue.8888 out/patterns/blue.8888 0644 0 0
file /usr/libexec/aurora/b9b/patterns/geo.8888 out/patterns/geo.8888 0644 0 0
file /usr/libexec/aurora/b9b/patterns/green.8888 out/patterns/green.8888 0644 0 0
file /usr/libexec/aurora/b9b/patterns/red.8888 out/patterns/red.8888 0644 0 0
file /usr/libexec/aurora/b9b/patterns/white.8888 out/patterns/white.8888 0644 0 0

19
b9/b9b/out/panel-fw.txt Normal file
View file

@ -0,0 +1,19 @@
11 SLPOUT + delay 120 ms
b1 FRMCTR1 05 3a 3a
b2 FRMCTR2 05 3a 3a
b3 FRMCTR3 05 3a 3a 05 3a 3a
b4 INVCTR 03
c0 PWCTR1 62 02 04
c1 PWCTR2 c0
c2 PWCTR3 0d 00
c3 PWCTR4 8d 6a
c4 PWCTR5 8d ee
c5 VMCTR1 12
e0 GMCTRP1 03 1b 12 11 3f 3a 32 34 2f 2b 30 3a 00 01 02 05
e1 GMCTRN1 03 1b 12 11 32 2f 2a 2f 2e 2c 35 3f 00 00 01 05
36 MADCTL c8
3a COLMOD 05
2a CASET 00 02 00 81
2b RASET 00 03 00 82
29 DISPON
dropped: 2c RAMWR (driver writes memory itself); file 121 bytes

View file

@ -0,0 +1,40 @@
#!/bin/sh
# B9B board-side test helper (RAM image only). Read-only except:
# show NAME -> writes a 128x128 frame to /dev/fb0 (RAM framebuffer -> SPI panel)
# bl on|off -> backlight through the kernel gpio-backlight driver (sysfs), never raw PMIC writes
# PMIC registers are only READ (regmap debugfs positioned reads).
P=/usr/libexec/aurora/b9b
grep -q " /sys/kernel/debug " /proc/mounts || mount -t debugfs debugfs /sys/kernel/debug
rd() { R=/sys/kernel/debug/regmap/0-0$1/registers; echo "# PMIC sid$1 $2 +$3"; dd if=$R bs=9 skip=$(($2)) count=$(($3)) 2>/dev/null; }
mpp4() { echo "--- MPP4 0xa340..0xa34f (40 MODE,41 VIN,42 PULL,46 EN,48 AOUT,4a AIN,4c SINK)"; rd 0 0xa340 16; }
fbinfo() { for f in name bits_per_pixel virtual_size stride; do printf 'fb0 %s=%s\n' $f "$(cat /sys/class/graphics/fb0/$f 2>/dev/null)"; done; }
BL=$(ls -d /sys/class/backlight/* 2>/dev/null | head -1)
blinfo() { [ -n "$BL" ] && for f in bl_power brightness actual_brightness max_brightness; do printf '%s %s=%s\n' ${BL##*/} $f "$(cat $BL/$f)"; done; }
case "$1" in
state)
echo B9B-STATE-BEGIN; cat /proc/uptime; cat /proc/device-tree/model; echo; uname -r
echo "--- regulators"; for r in /sys/class/regulator/regulator.*; do n=$(cat $r/name); case $n in l6|l17) printf '%s state=%s uV=%s users=%s\n' $n "$(cat $r/state)" "$(cat $r/microvolts)" "$(cat $r/num_users)";; esac; done
grep -E ' l6 | l17 |^ +l6|^ +l17|spi|panel' /sys/kernel/debug/regulator/regulator_summary
echo "--- PMIC L6 (sid1 0x4500) / L17 (0x5000): 08 STATUS, 40/41 VSET, 46 EN"; rd 1 0x4508 1; rd 1 0x4540 2; rd 1 0x4546 1; rd 1 0x5008 1; rd 1 0x5040 2; rd 1 0x5046 1
mpp4
echo "--- dmesg"; dmesg | grep -iE 'drm|panel|mipi|dbi|spi|78b8000|backlight|fb0|framebuffer|firmware|l17|regulator' | grep -v aurora-modem
echo "--- devices"; ls -la /dev/dri /dev/fb0 2>&1; ls /sys/class/drm /sys/class/graphics /sys/class/backlight /sys/bus/spi/devices 2>&1
fbinfo; blinfo
echo "--- gpio"; grep -E 'gpio(12|13|14|15|116|118) |mpp4' /sys/kernel/debug/gpio
for f in /sys/kernel/debug/pinctrl/1000000.pinctrl*/pinmux-pins; do grep -E '^pin (12|13|14|15|116|118) ' $f; done
cat /sys/kernel/debug/pinctrl/*mpps*/pinconf-pins 2>/dev/null | grep mpp4
echo "--- clk"; grep -E 'qup4_spi' /sys/kernel/debug/clk/clk_summary
echo "--- emmc"; cat /sys/block/mmcblk0/stat
echo B9B-STATE-END;;
show)
b=$(cat /sys/class/graphics/fb0/bits_per_pixel); case $b in 16) e=565;; 32) e=8888;; *) echo "unsupported bpp $b"; exit 1;; esac
cat $P/patterns/$2.$e > /dev/fb0 && echo "SHOW $2 ($b bpp) OK";;
bl)
[ -n "$BL" ] || { echo "no backlight device"; exit 1; }
case "$2" in
on) echo 0 > $BL/bl_power; echo 1 > $BL/brightness;;
off) echo 0 > $BL/brightness;;
esac
blinfo; mpp4;;
*) echo "usage: $0 state|show NAME|bl on|off"; exit 2;;
esac

6
b9/b9c/SHA256SUMS Normal file
View file

@ -0,0 +1,6 @@
0dc217f0b65f08734337070a4eac9f57e82cf719f286f9d5f8f503ee0251ed67 build-b9c.sh
6efae7a7f7a7d88d9bb5efd63efc2df37cf35d8399bf8ae39bdfec8d1431b6f4 b9c-boot.sh
0fef41b262917c8ae308fa222da0017e2b3cb3ec5da1ca8ba18d0318476761a3 cmdline.txt
b509a57b40e095af1d9346dbd041eacbb5fda202f7cc47f25e7c1f1257bd3e9b rootfs/init
451bc06d243c92c9c14ccdf13b88953f1544ec6764a292ff77764e41df8c8aa7 rootfs/usr/sbin/aurora-display
54618e80edb44a3bb65aa59a723e3643ef29b6728b3ec072bbafcaaac3802f35 rootfs/etc/init.d/aurora-display

53
b9/b9c/b9c-boot.sh Normal file
View file

@ -0,0 +1,53 @@
#!/bin/sh
# 480s side, B9C boot K MODE (derived from b8f-boot.sh). MODE=ram: RESET-held power-on -> lk1st fastboot -> `fastboot boot` B9C RAM image.
# MODE=cold: normal power-on (no RESET, no fastboot) -> lk2nd extlinux from eMMC cache. Script only observes + reads over telnet;
# nothing is written to eMMC. Visual display checks need the operator. Adds display/fbcon/getty/console checks to the B8F snapshot.
K=$1; MODE=$2; case "$MODE" in ram|cold) ;; *) echo "usage: $0 K ram|cold"; exit 2;; esac
cd ~/doc/modem/jz08-aurora; O=logs/b9/b9c/$MODE$K; mkdir -p $O; IMG=b9/b9c/out/aurora-b9c.img
A=$O/host-actions.txt; act() { echo "$(date -u +%H:%M:%S.%3N) $*" | tee -a $A; }
tn() { { sleep 1; sed "s/\$/\r/" "$1"; sleep $2; } | ncat 172.16.42.1 23 | tr -d "\000\r"; }
OLD=$(ps -eo pid,cmd | grep "[u]artlog.py /dev/ttyUSB0" | awk '{print $1}'); [ -n "$OLD" ] && kill $OLD; sleep 1
U=logs/uart/b9c-$MODE$K-$(date +%Y%m%d-%H%M%S); setsid nohup python3 tools/uartlog.py /dev/ttyUSB0 $U > $U.stderr 2>&1 < /dev/null &
if [ $MODE = ram ]; then
echo "fa855e1c84763861d8b2f6bd7ed669e8ab625aa42178317883fabff39dec4fce $IMG" | sha256sum -c || exit 1
act "B9C $MODE$K: waiting for fastboot <EMMC_SERIAL> (power off >= 90 s, then RESET held + battery -> USB)"
if fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; then act "already in fastboot - wait for power-off"; until ! fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do sleep 1; done; fi
i=0; until fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do i=$((i+1)); [ $i -ge 600 ] && { act "ABORT: no fastboot"; exit 1; }; sleep 2; done
act "fastboot present"; { fastboot boot $IMG 2>&1; echo "rc=$?"; } | tee -a $A
else
act "B9C $MODE$K: waiting for the board to go away (power off >= 90 s), then normal power-on WITHOUT RESET"
until ! ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do sleep 1; done; act "board unreachable (powered off)"
until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL> && { act "ABORT: board is in fastboot - RESET was held?"; exit 1; }; sleep 1; done
fi
i=0; until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do i=$((i+1)); [ $i -ge 180 ] && { act "ABORT: NCM not up"; cp $U.log $O/uart.log; exit 1; }; sleep 1; done; act "NCM ping ok"
R=$(grep -a "rtc-pm8xxx.*setting system clock" $U.log | tail -1 | sed -n 's/.*(\([0-9]*\)).*/\1/p'); C=B; [ -n "$R" ] && [ "$R" -lt 40 ] && C=A; act "RTC at boot ${R:-?} s -> class $C"
printf 'cat /proc/device-tree/model; echo; uname -r; grep -E "START OK|FAIL in|rollback" /run/aurora-modem/lifecycle.log | tail -1\n' > $O/.w
i=0; until tn $O/.w 3 | grep -qE "^\[[0-9.]+\] .*(=== START OK|FAIL in|rollback)"; do i=$((i+1)); [ $i -ge 80 ] && { act "no START OK/FAIL after ~12 min"; break; }; sleep 6; done
tn $O/.w 3 | grep -aE "Aurora|aurora-b8|START OK|FAIL" | tee -a $A
printf 'grep -E "AP ENABLED|FAIL" /run/aurora-wifi/wifi.log | tail -1\n' > $O/.a
i=0; until tn $O/.a 3 | grep -qE "^\[[0-9.]+\] (=== AP ENABLED|FAIL)"; do i=$((i+1)); [ $i -ge 20 ] && { act "no AP ENABLED/FAIL after ~3 min"; break; }; sleep 6; done
act "wifi: $(tn $O/.a 3 | grep -E '^\[[0-9.]+\] (=== AP ENABLED|FAIL)' | tail -1)"
printf 'grep -E "SNTP (check|STEP|: )" /run/aurora-modem/lifecycle.log | tail -2\n' > $O/.s
i=0; until tn $O/.s 3 | grep -qE "^\[[0-9.]+\] SNTP"; do i=$((i+1)); [ $i -ge 15 ] && break; sleep 4; done; act "sntp: $(tn $O/.s 3 | grep -E '^\[[0-9.]+\] SNTP' | tail -2 | tr '\n' ' ')"
cat > $O/.c <<'C'
echo SNAP-BEGIN; cat /proc/uptime; date -u; cat /proc/device-tree/model; echo; uname -a; cat /proc/cmdline
echo ---time; cat /run/aurora-modem/time-set; grep -E "TIME|SNTP" /run/aurora-modem/lifecycle.log | tail -4
echo ---modem; /etc/init.d/aurora-modem status
echo ---wifi; /etc/init.d/aurora-wifi status; echo ---wifilog; cat /run/aurora-wifi/wifi.log; cat /run/aurora-wifi/service.log; echo ---hostapdlog; cat /run/aurora-wifi/hostapd.log
for r in /sys/class/remoteproc/*; do echo "RP $(cat $r/name)=$(cat $r/state)"; done; iw dev
echo ---dmesg-wifi; dmesg | grep -iE "wcn36xx|wcnss|a204000|cfg80211|aurora-wifi|crash|watchdog"
echo ---ping; ping -c4 -W3 -I wwan0 77.88.8.8 | tail -2
echo ---display; /etc/init.d/aurora-display status; cat /run/aurora-display/display.log; cat /run/aurora-display/service.log
echo ---consoles; cat /sys/class/tty/console/active; for v in /sys/class/vtconsole/vtcon*; do echo "$v $(cat $v/bind) $(cat $v/name)"; done; ls -l /proc/[0-9]*/fd/0 2>/dev/null | grep -E "ttyMSM0|tty1|console" | sed "s/.* \/proc/\/proc/"
echo ---getty; hostname; ps | grep -E "[g]etty|[c]ttyhack| sh$"
echo ---fb; ls -l /dev/dri/card0 /dev/fb0; for f in name bits_per_pixel virtual_size stride; do echo "fb0 $f=$(cat /sys/class/graphics/fb0/$f)"; done; cat /sys/class/drm/card0-SPI-1/enabled /sys/class/drm/card0-SPI-1/dpms
echo ---regs; for r in /sys/class/regulator/regulator.*; do n=$(cat $r/name); case $n in l6|l17) echo "$n $(cat $r/state) $(cat $r/microvolts) users=$(cat $r/num_users)";; esac; done
echo ---bl; for f in bl_power brightness actual_brightness; do echo "bl $f=$(cat /sys/class/backlight/backlight/$f)"; done
echo ---dmesg-display; dmesg | grep -iE "drm|panel|mipi|spi_qup|78b8000|fbcon|Console: |frame buffer|backlight|aurora-display|l17"
echo ---display-errors; dmesg | grep -iE "drm|panel|mipi|spi0|fbcon|backlight|aurora-display" | grep -ciE "err|fail|timeout|warn"
echo ---emmc; awk "{print \"w=\"\$5\" s=\"\$7}" /sys/block/mmcblk0/stat
echo SNAP-END
C
tn $O/.c 25 > $O/snapshot.txt; act "snapshot: $(grep -c SNAP-END $O/snapshot.txt) end markers; $(grep -E '^RP a204' $O/snapshot.txt)"
printf 'dmesg > /tmp/dm.txt; nc -l -p 9881 < /tmp/dm.txt &\n' > $O/.d; tn $O/.d 3 >/dev/null; sleep 1; ncat --recv-only 172.16.42.1 9881 > $O/dmesg.full
cp $U.log $O/uart.log; act "B9C $MODE$K END - operator visual check next"

36
b9/b9c/build-b9c.sh Normal file
View file

@ -0,0 +1,36 @@
#!/bin/sh
# B9C image: persistent display (fbcon tty1 + backlight) on top of B8F.
# kernel = out-b9c (b9b + FRAMEBUFFER_CONSOLE + FONTS/FONT_6x8 only; linux/aurora-b9c.config)
# DTB = B9B DTB unchanged (7ca9cc79)
# initramfs = exact B8F initramfs + overlay: /init (B8F + hostname/display/getty), aurora-display, panel firmware
# cmdline = B8F cmdline + console=tty0 (placed BEFORE console=ttyMSM0 so /dev/console stays the UART) + fbcon=font:6x8 consoleblank=0
# Outputs: RAM image (fastboot boot pretest) + parts for the cache candidate. out/ contains the B8F initramfs (Wi-Fi PSK): never publish.
set -e; cd "$(dirname "$0")"; O=out; KB=/home/q/aurora-kbuild/out-b9c; F8=../../b8/b8f/out; B9B=../b9b/out
GEN=../../linux/out/usr/gen_init_cpio; TS=1790726400; FW='jz08au,aurora-st7735s.bin'
mkdir -p $O
echo "abb3bd6757e77eae90b3c9eb9d8b3f09e7a906256a53c80033853eb82b8e3f2f $F8/initramfs-b8f.cpio.gz" | sha256sum -c
echo "7ca9cc794a3b85d3b7240f6311ad03bee9e1a4a59aae2ed9438318e853f7c3dc $B9B/aurora-b9b.dtb" | sha256sum -c
echo "58697d4db45a9af85ec09e03a4212955ae3c7eed7d9f6bda82071da1b44329b4 $B9B/$FW" | sha256sum -c
for s in FRAMEBUFFER_CONSOLE=y FONT_6x8=y DRM_PANEL_MIPI_DBI=y DRM_FBDEV_EMULATION=y VT_CONSOLE=y 'LOCALVERSION="-aurora-b9c"'; do grep -q "^CONFIG_$s\$" $KB/.config || { echo "STOP: CONFIG_$s"; exit 1; }; done
grep -q '^CONFIG_FONT_8x16=y' $KB/.config && { echo "STOP: extra fonts"; exit 1; }
diff -u ../../b8/b8f/rootfs/init rootfs/init > $O/init.diff || true
[ $(grep -c '^+[^+]' $O/init.diff) = 5 ] || { echo "STOP: init diff is not the expected 5 added lines"; exit 1; }
[ $(grep -c '^-[^-]' $O/init.diff) = 0 ] || { echo "STOP: init diff removes lines"; exit 1; }
cp $KB/arch/arm64/boot/Image.gz $O/Image.gz; cp $KB/.config $O/config-b9c; cp $B9B/aurora-b9b.dtb $O/aurora-b9c.dtb; cp "$B9B/$FW" "$O/$FW"
cat $O/Image.gz $O/aurora-b9c.dtb > $O/Image.gz-dtb
cat > $O/overlay-b9c.list <<L
file /init rootfs/init 0755 0 0
file /usr/sbin/aurora-display rootfs/usr/sbin/aurora-display 0755 0 0
file /etc/init.d/aurora-display rootfs/etc/init.d/aurora-display 0755 0 0
dir /lib/firmware 0755 0 0
file /lib/firmware/$FW $O/$FW 0644 0 0
L
$GEN -t $TS $O/overlay-b9c.list > $O/overlay-b9c.cpio
gzip -9 -n -c $O/overlay-b9c.cpio > $O/overlay-b9c.cpio.gz
cat $F8/initramfs-b8f.cpio.gz $O/overlay-b9c.cpio.gz > $O/initramfs-b9c.cpio.gz
cp cmdline.txt $O/cmdline.txt
python3 ../../b6p/mkbootimg.py $O/Image.gz-dtb $O/initramfs-b9c.cpio.gz $O/cmdline.txt $O/aurora-b9c.img
SZ=$(python3 -c "import struct;print(struct.unpack_from('<Q',open('$KB/arch/arm64/boot/Image','rb').read(24),16)[0])")
printf 'kernel image_size 0x%x, RAM-boot end 0x%x (< 0x81e00000 DTB)\n' $SZ $((0x80000000 + SZ)); [ $((0x80000000 + SZ)) -lt $((0x81e00000)) ]
S=$(stat -c %s $O/initramfs-b9c.cpio.gz); echo "initrd $S B"
(cd $O && sha256sum Image.gz aurora-b9c.dtb Image.gz-dtb config-b9c "$FW" cmdline.txt overlay-b9c.cpio.gz initramfs-b9c.cpio.gz aurora-b9c.img > SHA256SUMS; cat SHA256SUMS); ls -l $O/aurora-b9c.img

36
b9/b9c/cache/B9C-PREFLIGHT.md vendored Normal file
View file

@ -0,0 +1,36 @@
# B9C cache write — preflight (2026-10-03)
## Candidate
`cache-extlinux-b9c.img` **b9ce13c9…** (134217728 B, ext2, label aurora-b9c). Built on 480s by `mkfs-cache-b9c.sh` = exact B8F recipe;
only the kernel/fdt/initrd files, the append line, label and UUIDs differ. The rebuild is bit-identical and `e2fsck -fn` is clean.
**Contains the AP PSK (B8F initramfs) — never publish.** Component diff: `cache-diff-b8f-vs-b9c.txt`.
## Evidence before the write
- RAM pretest `aurora-b9c.img` fa855e1c uses the same kernel/DTB/initramfs/cmdline as the candidate. Run: fastboot, ram1, class A (RTC 6 s).
- fbcon `21x16` (6x8) took over and the panel pipe came up by itself; `aurora-display` did no unblank, backlight on → DISPLAY READY at 8.0 s.
- getty on tty1 (pid 624); hostname aurora; `/dev/console` = ttyMSM0 (console active `tty0 ttyMSM0`); UART shell on ttyMSM0.
- START OK 69.2 s, AP ENABLED 73.5 s, MPSS/WCNSS running, display errors 0, eMMC w=0.
- Operator: text visible and readable, orientation correct, no clipping; backlight OFF→ON via sysfs confirmed.
- The login prompt scrolls away under later kernel messages (ignore_loglevel) — accepted (option A).
- lk2nd emulator (`emu/`):
- S6 regression on the live B8F cache == the B8F emu run.
- S7 candidate: "Trying to boot 'b9c'", kernel 3afc6c77 (24686600 B, image_size 0x1820000, ends at DDR+0x1820000),
DTB 7ca9cc79 @DDR+0x20A9000, ramdisk ac518e27 @DDR+0x22A9000 — no overlap.
- Fault variants F1/F3/F10 → android boot (emmc1 fallback).
## Write / rollback
`B9C-write.sh` = B8F-write.sh with only the image, expected hashes, rollback references and log dir changed.
Gates, in order:
- loader;
- candidate sha + size;
- rollback image B8F 857c9c30 and the B8F readback backup;
- 9008 present; identity/geometry;
- GPT == A3; boot == emmc1; aboot == lk1st-autoboot;
- **live cache == B8F 857c9c30** — the pre-write readback is saved as `logs/b9/b9c/W/pre-cache.bin` (backup).
Then: write cache only → readback cmp → verify every other partition → `B9C_WRITE_VERIFIED`.
Rollback: `B9C-rollback.sh` → B8F cache (via HW EDL). Entry: HW EDL (battery on, D+→GND, plug USB, release).
## After the write
3 normal class-A cold boots (no RESET, no fastboot, no UART input): power off ≥ 90 s → normal power-on → `b9c-boot.sh K cold`.
In one of them, check backlight ON → OFF → ON visually via `aurora-display bl` (sysfs).

12
b9/b9c/cache/B9C-rollback.sh vendored Executable file
View file

@ -0,0 +1,12 @@
#!/bin/bash
# B9C rollback — restore the B8F cache (857c9c30, operational since 2026-10-03: B7C + Wi-Fi AP). Needs 9008 via HW EDL (D+->GND). boot/aboot untouched.
# Deeper rollback: b8/b8f/cache/B8F-rollback.sh (B7C 14fe453a), b7/b7c/cache/B7C-rollback.sh (T4 9d3bc890).
cd ~/doc/modem/jz08-aurora || exit 1
L=firehose/007050e100000000_394a2e47cf830150_fhprg_peek.bin ; O=logs/b9/b9c/rollback ; mkdir -p $O
B=b8/b8f/cache/cache-extlinux-b8f.img
[ "$(sha256sum $B | cut -d' ' -f1)" = 857c9c300055804cab673027bc8cddc010ad04bfec5d75276d8229b84846c4b2 ] || { echo "STOP: rollback image hash"; exit 1; }
lsusb | grep -q 05c6:9008 || { echo "STOP: no 9008"; exit 1; }
edl --loader=$L printgpt > $O/00-printgpt.log 2>&1
edl --loader=$L w cache $B > $O/cache-w.log 2>&1
edl --loader=$L r cache $O/cache-rb.bin > /dev/null 2>&1 ; cmp $B $O/cache-rb.bin && echo CACHE_RESTORED_B8F
sha256sum $B $O/cache-rb.bin

49
b9/b9c/cache/B9C-write.sh vendored Executable file
View file

@ -0,0 +1,49 @@
#!/bin/bash
# B9C — the ONLY write: cache := ext2 extlinux -> B9C candidate (B8F + display: b9c kernel (DRM/panel-mipi-dbi/fbcon 6x8), B9B DTB, aurora-display, tty1 getty).
# Run on 480s ONLY after explicit GO. Derived 1:1 from b8/b8f/cache/B8F-write.sh (B8F_WRITE_VERIFIED 2026-10-03); only image, expected hashes,
# rollback references and log dir changed. The pre-write readback of the live cache (must be B8F 857c9c30) is kept as backup.
# Entry: HW EDL (battery on, D+->GND, plug USB, release). Never `edl reset`. Stops at first failed gate.
cd ~/doc/modem/jz08-aurora || exit 1
L=firehose/007050e100000000_394a2e47cf830150_fhprg_peek.bin
O=logs/b9/b9c/W ; A3=logs/b5a/A3 ; P=logs/b5a/A4pre ; mkdir -p $O
NEW=b9/b9c/cache/cache-extlinux-b9c.img ; NEW_SHA=b9ce13c9f48e36a5054c0ae3c39dc3f184b1fc2eea1d57d4b8bd8e9ae800a37b
OLD_SHA=857c9c300055804cab673027bc8cddc010ad04bfec5d75276d8229b84846c4b2 # current cache = B8F extlinux
BOOT_SHA=e9579f33c7304cd47f487f2b61cd9226dc04fd3a63775d62b4b95fc15bd3ebff
ABOOT_SHA=3b8cd2667837fc7083cb28991d849f9b408a07fa743bfd05eafee7b053760f85
die(){ echo "STOP: $*"; exit 1; }
sha(){ sha256sum "$1" | cut -d" " -f1; }
E(){ edl --loader=$L "$@"; }
echo "== G0 inputs"
[ "$(sha $L)" = 53f193500c03248f0d671ab57bfe9ca8a42967e97f28403294b4b3f854075aca ] || die loader
[ "$(sha $NEW)" = $NEW_SHA ] && [ $(stat -c %s $NEW) = 134217728 ] || die candidate
[ "$(sha b8/b8f/cache/cache-extlinux-b8f.img)" = $OLD_SHA ] || die rollback-image
[ "$(sha logs/b8/b8f/W/11-cache-readback.bin)" = $OLD_SHA ] || die b8f-readback-backup
lsusb | grep -q 05c6:9008 || die "no 9008"
echo "== G1 identity + geometry + baseline"
E printgpt > $O/00-printgpt.log 2>&1 || die printgpt
grep -aq "Serial: *0x<SAHARA_SERIAL>" $O/00-printgpt.log || grep -aq "Mode detected: firehose" $O/00-printgpt.log || die serial
grep -a "^cache:" $O/00-printgpt.log | grep -q "Offset 0x000000004118c000, Length 0x0000000008000000" || die cache-geometry
E rs 0 34 $O/pre-gptp.bin >/dev/null 2>&1; cmp $O/pre-gptp.bin $A3/gpt-primary-34.bin || die gpt-changed
E r boot $O/pre-boot.bin >/dev/null 2>&1; [ "$(sha $O/pre-boot.bin)" = $BOOT_SHA ] || die boot-not-emmc1
E r aboot $O/pre-aboot.bin >/dev/null 2>&1; [ "$(sha $O/pre-aboot.bin)" = $ABOOT_SHA ] || die aboot-not-autoboot
E r cache $O/pre-cache.bin >/dev/null 2>&1; [ "$(sha $O/pre-cache.bin)" = $OLD_SHA ] || die cache-not-backup
echo "== W cache := candidate (LBA 2133088, 262144 sectors)"
E w cache $NEW > $O/10-cache-write.log 2>&1; echo "rc=$?"; grep -a "Wrote" $O/10-cache-write.log
E r cache $O/11-cache-readback.bin > $O/11-cache-readback.log 2>&1 || die readback-rc
sha256sum $NEW $O/11-cache-readback.bin
cmp $NEW $O/11-cache-readback.bin || die "CACHE READBACK MISMATCH — do NOT reboot; run b9/b9c/cache/B9C-rollback.sh"
echo CACHE_MATCH
echo "== V everything else unchanged"
E rs 0 34 $O/post-gptp.bin >/dev/null 2>&1; cmp $O/post-gptp.bin $A3/gpt-primary-34.bin || die gptp
E rs 7634911 33 $O/post-gptb.bin >/dev/null 2>&1; cmp $O/post-gptb.bin $A3/gpt-backup-33.bin || die gptb
E rs 305184 1024 $O/post-tzbak.bin >/dev/null 2>&1; cmp $O/post-tzbak.bin $A3/tzbak-305184.bin || die tzbak
E r boot $O/post-boot.bin >/dev/null 2>&1; [ "$(sha $O/post-boot.bin)" = $BOOT_SHA ] || die boot
E r aboot $O/post-aboot.bin >/dev/null 2>&1; [ "$(sha $O/post-aboot.bin)" = $ABOOT_SHA ] || die aboot
for p in sbl1 rpm tz hyp recovery modemst1 modemst2 fsg fsc persist; do
E r $p $O/post-$p.bin >/dev/null 2>&1; cmp $O/post-$p.bin $A3/$p.bin || die "$p changed"; echo "$p == A3"
done
for p in modem system userdata; do
E r $p $O/post-$p.bin >/dev/null 2>&1; cmp $O/post-$p.bin $P/$p.bin || die "$p changed"; echo "$p == A4pre"; rm -f $O/post-$p.bin
done
(cd $O && sha256sum *.bin > SHA256SUMS)
echo "B9C_WRITE_VERIFIED — power off fully (USB, then battery) before first boot"

6
b9/b9c/cache/SHA256SUMS vendored Normal file
View file

@ -0,0 +1,6 @@
b9ce13c9f48e36a5054c0ae3c39dc3f184b1fc2eea1d57d4b8bd8e9ae800a37b cache-extlinux-b9c.img
b6db2a4ba9ae55cee466e7e968a3a7dc945b3782a0e382559ae8ffbaa3fd52ea mkfs-cache-b9c.sh
bd906d6729921de01cedcbe8037008badb763d3bc7352625efabb2103b874404 B9C-write.sh
4103016467f3ca8a07fac797689b16f957655815c3c434c8f01fa12449e6c34c B9C-rollback.sh
7facbd7aec20d7a823f23a824172448dd3d21a3f9bc9cc422fe6ef4565d52e90 extlinux-b9c.conf
66cf4bc677c395503a9c68788412b58007c5ea1cb49b9fda3cb12cd9198413d1 emu/run-emu-b9c.sh

10
b9/b9c/cache/cache-diff-b8f-vs-b9c.txt vendored Normal file
View file

@ -0,0 +1,10 @@
B8F cache 857c9c30 (live) -> B9C candidate b9ce13c9 (ext2, 134217728 B, label aurora-b9c, same mkfs recipe)
file B8F B9C
Image.gz-dtb 50d63488 (b8d kernel be30b1fa + B8B DTB) 632a7be8 (b9c kernel 3afc6c77 = b8d + DRM/panel-mipi-dbi/fbdev + fbcon + FONT_6x8 only; + B9B DTB)
fdt aurora-b8f.dtb cc74b57d (B8B) aurora-b9c.dtb 7ca9cc79 (B9B = B8B + spi@78b8000 + ST7735S panel + L17 + MPP4 gpio-backlight)
initrd initramfs-b8f abb3bd67 initramfs-b9c ac518e27 = initramfs-b8f abb3bd67 (unchanged, first gzip member) + overlay 9e41cdda:
/init (B8F + 5 lines: hostname aurora, aurora-display start, getty tty1 loop), /usr/sbin/aurora-display,
/etc/init.d/aurora-display, /lib/firmware/jz08au,aurora-st7735s.bin 58697d4d (stock 18 init cmds)
append earlycon console=ttyMSM0,115200n8 earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init
ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0
lk2nd layout kernel end DDR+0x1760000, tags +0x20aa000 kernel end DDR+0x1820000, tags +0x20a9000, ramdisk +0x22a9000 (no overlap)

42
b9/b9c/cache/emu/F1-no-conf.out vendored Normal file
View file

@ -0,0 +1,42 @@
[lk] Registering wrapper bio devices...
[lk] block devices:
[lk] | dev | label | size | Leaf |
[lk] | wrp0p26 | userdata | 2542 MiB | Yes |
[lk] | wrp0p25 | recovery | 16 MiB | Yes |
[lk] | wrp0p24 | cache | 128 MiB | Yes |
[lk] | wrp0p23 | persist | 32 MiB | Yes |
[lk] | wrp0p22 | system | 800 MiB | Yes |
[lk] | wrp0p21 | boot | 16 MiB | Yes |
[lk] | wrp0p20 | sec | 16 KiB | Yes |
[lk] | wrp0p19 | fsg | 1 MiB | Yes |
[lk] | wrp0p18 | DDR | 32 KiB | Yes |
[lk] | wrp0p17 | splash | 10 MiB | Yes |
[lk] | wrp0p16 | ssd | 8 KiB | Yes |
[lk] | wrp0p15 | fsc | 1 KiB | Yes |
[lk] | wrp0p14 | misc | 1024 KiB | Yes |
[lk] | wrp0p13 | modemst2 | 1 MiB | Yes |
[lk] | wrp0p12 | modemst1 | 1 MiB | Yes |
[lk] | wrp0p11 | pad | 1024 KiB | Yes |
[lk] | wrp0p10 | hypbak | 512 KiB | Yes |
[lk] | wrp0p9 | hyp | 512 KiB | Yes |
[lk] | wrp0p8 | tzbak | 512 KiB | Yes |
[lk] | wrp0p7 | tz | 1024 KiB | Yes |
[lk] | wrp0p6 | rpmbak | 512 KiB | Yes |
[lk] | wrp0p5 | rpm | 512 KiB | Yes |
[lk] | wrp0p4 | abootbak | 1024 KiB | Yes |
[lk] | wrp0p3 | aboot | 1024 KiB | Yes |
[lk] | wrp0p2 | sbl1bak | 512 KiB | Yes |
[lk] | wrp0p1 | sbl1 | 512 KiB | Yes |
[lk] | wrp0p0 | modem | 64 MiB | Yes |
[lk] | wrp0 | | 3728 MiB | |
[lk] boot: Trying to boot from the file system...
[lk] boot: Bootable file system not found. Reverting to android boot.
HARNESS: lk2nd_boot() returned -> aboot would continue to boot_linux_from_mmc() (Android boot partition)
HARNESS: scan-candidate wrp0p26 (userdata) ext2 mount rc=-3
HARNESS: scan-candidate wrp0p25 (recovery) ext2 mount rc=-1
HARNESS: scan-candidate wrp0p24 (cache) ext2 mount rc=0
HARNESS: scan-candidate wrp0p23 (persist) ext2 mount rc=-3
HARNESS: scan-candidate wrp0p22 (system) ext2 mount rc=-3
HARNESS: scan-candidate wrp0p21 (boot) ext2 mount rc=-1
HARNESS: scan-candidate wrp0p0 (modem) ext2 mount rc=-1
HARNESS: total bytes read 45568

42
b9/b9c/cache/emu/F10-zeroed-cache.out vendored Normal file
View file

@ -0,0 +1,42 @@
[lk] Registering wrapper bio devices...
[lk] block devices:
[lk] | dev | label | size | Leaf |
[lk] | wrp0p26 | userdata | 2542 MiB | Yes |
[lk] | wrp0p25 | recovery | 16 MiB | Yes |
[lk] | wrp0p24 | cache | 128 MiB | Yes |
[lk] | wrp0p23 | persist | 32 MiB | Yes |
[lk] | wrp0p22 | system | 800 MiB | Yes |
[lk] | wrp0p21 | boot | 16 MiB | Yes |
[lk] | wrp0p20 | sec | 16 KiB | Yes |
[lk] | wrp0p19 | fsg | 1 MiB | Yes |
[lk] | wrp0p18 | DDR | 32 KiB | Yes |
[lk] | wrp0p17 | splash | 10 MiB | Yes |
[lk] | wrp0p16 | ssd | 8 KiB | Yes |
[lk] | wrp0p15 | fsc | 1 KiB | Yes |
[lk] | wrp0p14 | misc | 1024 KiB | Yes |
[lk] | wrp0p13 | modemst2 | 1 MiB | Yes |
[lk] | wrp0p12 | modemst1 | 1 MiB | Yes |
[lk] | wrp0p11 | pad | 1024 KiB | Yes |
[lk] | wrp0p10 | hypbak | 512 KiB | Yes |
[lk] | wrp0p9 | hyp | 512 KiB | Yes |
[lk] | wrp0p8 | tzbak | 512 KiB | Yes |
[lk] | wrp0p7 | tz | 1024 KiB | Yes |
[lk] | wrp0p6 | rpmbak | 512 KiB | Yes |
[lk] | wrp0p5 | rpm | 512 KiB | Yes |
[lk] | wrp0p4 | abootbak | 1024 KiB | Yes |
[lk] | wrp0p3 | aboot | 1024 KiB | Yes |
[lk] | wrp0p2 | sbl1bak | 512 KiB | Yes |
[lk] | wrp0p1 | sbl1 | 512 KiB | Yes |
[lk] | wrp0p0 | modem | 64 MiB | Yes |
[lk] | wrp0 | | 3728 MiB | |
[lk] boot: Trying to boot from the file system...
[lk] boot: Bootable file system not found. Reverting to android boot.
HARNESS: lk2nd_boot() returned -> aboot would continue to boot_linux_from_mmc() (Android boot partition)
HARNESS: scan-candidate wrp0p26 (userdata) ext2 mount rc=-3
HARNESS: scan-candidate wrp0p25 (recovery) ext2 mount rc=-1
HARNESS: scan-candidate wrp0p24 (cache) ext2 mount rc=-1
HARNESS: scan-candidate wrp0p23 (persist) ext2 mount rc=-3
HARNESS: scan-candidate wrp0p22 (system) ext2 mount rc=-3
HARNESS: scan-candidate wrp0p21 (boot) ext2 mount rc=-1
HARNESS: scan-candidate wrp0p0 (modem) ext2 mount rc=-1
HARNESS: total bytes read 28160

44
b9/b9c/cache/emu/F3-no-initrd.out vendored Normal file
View file

@ -0,0 +1,44 @@
[lk] Registering wrapper bio devices...
[lk] block devices:
[lk] | dev | label | size | Leaf |
[lk] | wrp0p26 | userdata | 2542 MiB | Yes |
[lk] | wrp0p25 | recovery | 16 MiB | Yes |
[lk] | wrp0p24 | cache | 128 MiB | Yes |
[lk] | wrp0p23 | persist | 32 MiB | Yes |
[lk] | wrp0p22 | system | 800 MiB | Yes |
[lk] | wrp0p21 | boot | 16 MiB | Yes |
[lk] | wrp0p20 | sec | 16 KiB | Yes |
[lk] | wrp0p19 | fsg | 1 MiB | Yes |
[lk] | wrp0p18 | DDR | 32 KiB | Yes |
[lk] | wrp0p17 | splash | 10 MiB | Yes |
[lk] | wrp0p16 | ssd | 8 KiB | Yes |
[lk] | wrp0p15 | fsc | 1 KiB | Yes |
[lk] | wrp0p14 | misc | 1024 KiB | Yes |
[lk] | wrp0p13 | modemst2 | 1 MiB | Yes |
[lk] | wrp0p12 | modemst1 | 1 MiB | Yes |
[lk] | wrp0p11 | pad | 1024 KiB | Yes |
[lk] | wrp0p10 | hypbak | 512 KiB | Yes |
[lk] | wrp0p9 | hyp | 512 KiB | Yes |
[lk] | wrp0p8 | tzbak | 512 KiB | Yes |
[lk] | wrp0p7 | tz | 1024 KiB | Yes |
[lk] | wrp0p6 | rpmbak | 512 KiB | Yes |
[lk] | wrp0p5 | rpm | 512 KiB | Yes |
[lk] | wrp0p4 | abootbak | 1024 KiB | Yes |
[lk] | wrp0p3 | aboot | 1024 KiB | Yes |
[lk] | wrp0p2 | sbl1bak | 512 KiB | Yes |
[lk] | wrp0p1 | sbl1 | 512 KiB | Yes |
[lk] | wrp0p0 | modem | 64 MiB | Yes |
[lk] | wrp0 | | 3728 MiB | |
[lk] boot: Trying to boot from the file system...
[lk] Initramfs /wrp0p24//initramfs-b9c.cpio.gz does not exist
[lk] Failed to parse extlinux.conf
[lk] boot: Bootable file system not found. Reverting to android boot.
HARNESS: lk2nd_boot() returned -> aboot would continue to boot_linux_from_mmc() (Android boot partition)
HARNESS: scan-candidate wrp0p26 (userdata) ext2 mount rc=-3
HARNESS: scan-candidate wrp0p25 (recovery) ext2 mount rc=-1
HARNESS: scan-candidate wrp0p24 (cache) ext2 mount rc=0
HARNESS: scan-candidate wrp0p23 (persist) ext2 mount rc=-3
HARNESS: scan-candidate wrp0p22 (system) ext2 mount rc=-3
HARNESS: scan-candidate wrp0p21 (boot) ext2 mount rc=-1
HARNESS: scan-candidate wrp0p0 (modem) ext2 mount rc=-1
HARNESS: total bytes read 49664

40
b9/b9c/cache/emu/S6-b8f-regression.out vendored Normal file
View file

@ -0,0 +1,40 @@
[lk] Registering wrapper bio devices...
[lk] block devices:
[lk] | dev | label | size | Leaf |
[lk] | wrp0p26 | userdata | 2542 MiB | Yes |
[lk] | wrp0p25 | recovery | 16 MiB | Yes |
[lk] | wrp0p24 | cache | 128 MiB | Yes |
[lk] | wrp0p23 | persist | 32 MiB | Yes |
[lk] | wrp0p22 | system | 800 MiB | Yes |
[lk] | wrp0p21 | boot | 16 MiB | Yes |
[lk] | wrp0p20 | sec | 16 KiB | Yes |
[lk] | wrp0p19 | fsg | 1 MiB | Yes |
[lk] | wrp0p18 | DDR | 32 KiB | Yes |
[lk] | wrp0p17 | splash | 10 MiB | Yes |
[lk] | wrp0p16 | ssd | 8 KiB | Yes |
[lk] | wrp0p15 | fsc | 1 KiB | Yes |
[lk] | wrp0p14 | misc | 1024 KiB | Yes |
[lk] | wrp0p13 | modemst2 | 1 MiB | Yes |
[lk] | wrp0p12 | modemst1 | 1 MiB | Yes |
[lk] | wrp0p11 | pad | 1024 KiB | Yes |
[lk] | wrp0p10 | hypbak | 512 KiB | Yes |
[lk] | wrp0p9 | hyp | 512 KiB | Yes |
[lk] | wrp0p8 | tzbak | 512 KiB | Yes |
[lk] | wrp0p7 | tz | 1024 KiB | Yes |
[lk] | wrp0p6 | rpmbak | 512 KiB | Yes |
[lk] | wrp0p5 | rpm | 512 KiB | Yes |
[lk] | wrp0p4 | abootbak | 1024 KiB | Yes |
[lk] | wrp0p3 | aboot | 1024 KiB | Yes |
[lk] | wrp0p2 | sbl1bak | 512 KiB | Yes |
[lk] | wrp0p1 | sbl1 | 512 KiB | Yes |
[lk] | wrp0p0 | modem | 64 MiB | Yes |
[lk] | wrp0 | | 3728 MiB | |
[lk] boot: Trying to boot from the file system...
[lk] Trying to boot 'b8f'
[lk] Decompressing the kernel...
HARNESS: boot_linux reached: kernel @DDR+0x0 tags @DDR+0x20aa000 ramdisk @DDR+0x22aa000 (16077951) boot_type 0
HARNESS: kernel magic 0x644d5241 image_size 0x1760000 end @DDR+0x1760000
HARNESS: cmdline 'earlycon console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init'
HARNESS: kernel sha256 be30b1fad863ffa5413157c1df74d47adbd98c86c17e517a871b20517d3b879a (23955464 bytes)
HARNESS: dtb sha256 cc74b57deeda97b8ce2bacecf78f9300923d8e5d5d37beee1a87b4c0a32b9716 (65745 bytes)
HARNESS: ramdisk sha256 abb3bd6757e77eae90b3c9eb9d8b3f09e7a906256a53c80033853eb82b8e3f2f (16077951 bytes)

40
b9/b9c/cache/emu/S7-b9c-candidate.out vendored Normal file
View file

@ -0,0 +1,40 @@
[lk] Registering wrapper bio devices...
[lk] block devices:
[lk] | dev | label | size | Leaf |
[lk] | wrp0p26 | userdata | 2542 MiB | Yes |
[lk] | wrp0p25 | recovery | 16 MiB | Yes |
[lk] | wrp0p24 | cache | 128 MiB | Yes |
[lk] | wrp0p23 | persist | 32 MiB | Yes |
[lk] | wrp0p22 | system | 800 MiB | Yes |
[lk] | wrp0p21 | boot | 16 MiB | Yes |
[lk] | wrp0p20 | sec | 16 KiB | Yes |
[lk] | wrp0p19 | fsg | 1 MiB | Yes |
[lk] | wrp0p18 | DDR | 32 KiB | Yes |
[lk] | wrp0p17 | splash | 10 MiB | Yes |
[lk] | wrp0p16 | ssd | 8 KiB | Yes |
[lk] | wrp0p15 | fsc | 1 KiB | Yes |
[lk] | wrp0p14 | misc | 1024 KiB | Yes |
[lk] | wrp0p13 | modemst2 | 1 MiB | Yes |
[lk] | wrp0p12 | modemst1 | 1 MiB | Yes |
[lk] | wrp0p11 | pad | 1024 KiB | Yes |
[lk] | wrp0p10 | hypbak | 512 KiB | Yes |
[lk] | wrp0p9 | hyp | 512 KiB | Yes |
[lk] | wrp0p8 | tzbak | 512 KiB | Yes |
[lk] | wrp0p7 | tz | 1024 KiB | Yes |
[lk] | wrp0p6 | rpmbak | 512 KiB | Yes |
[lk] | wrp0p5 | rpm | 512 KiB | Yes |
[lk] | wrp0p4 | abootbak | 1024 KiB | Yes |
[lk] | wrp0p3 | aboot | 1024 KiB | Yes |
[lk] | wrp0p2 | sbl1bak | 512 KiB | Yes |
[lk] | wrp0p1 | sbl1 | 512 KiB | Yes |
[lk] | wrp0p0 | modem | 64 MiB | Yes |
[lk] | wrp0 | | 3728 MiB | |
[lk] boot: Trying to boot from the file system...
[lk] Trying to boot 'b9c'
[lk] Decompressing the kernel...
HARNESS: boot_linux reached: kernel @DDR+0x0 tags @DDR+0x20a9000 ramdisk @DDR+0x22a9000 (16082426) boot_type 0
HARNESS: kernel magic 0x644d5241 image_size 0x1820000 end @DDR+0x1820000
HARNESS: cmdline 'earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0'
HARNESS: kernel sha256 3afc6c77f3ed4b4ad82f61914b9cca354c3bdcaf5d102d7782a0cd5577cbca61 (24686600 bytes)
HARNESS: dtb sha256 7ca9cc794a3b85d3b7240f6311ad03bee9e1a4a59aae2ed9438318e853f7c3dc (67425 bytes)
HARNESS: ramdisk sha256 ac518e27e2957ad5e4515969b9a3808024e11ef8d1a79433a899a67dbc644558 (16082426 bytes)

28
b9/b9c/cache/emu/map-F1-no-conf.txt vendored Normal file
View file

@ -0,0 +1,28 @@
0 34 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/gpt-primary-34.bin
131072 131072 /home/q/doc/modem/jz08-aurora/logs/b5a/A4pre/modem.bin
262144 1024 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/sbl1.bin
263168 1024 /home/q/doc/modem/jz08-aurora/partitions/sbl1bak.bin
264192 2048 /home/q/doc/modem/jz08-aurora/b5a/aboot-lk1st-aurora-autoboot.pad1M
266240 2048 /home/q/doc/modem/jz08-aurora/partitions/abootbak.bin
268288 1024 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/rpm.bin
269312 1024 /home/q/doc/modem/jz08-aurora/partitions/rpmbak.bin
270336 2048 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/tz.bin
305184 1024 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/tzbak-305184.bin
272384 1024 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/hyp.bin
273408 1024 /home/q/doc/modem/jz08-aurora/partitions/hypbak.bin
274432 2048 /home/q/doc/modem/jz08-aurora/partitions/pad.bin
276480 3072 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/modemst1.bin
279552 3072 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/modemst2.bin
282624 2048 /home/q/doc/modem/jz08-aurora/partitions/misc.bin
284672 2 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/fsc.bin
284674 16 /home/q/doc/modem/jz08-aurora/partitions/ssd.bin
284690 20480 /home/q/doc/modem/jz08-aurora/partitions/splash.bin
393216 64 /home/q/doc/modem/jz08-aurora/partitions/DDR.bin
393280 3072 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/fsg.bin
396352 32 /home/q/doc/modem/jz08-aurora/partitions/sec.bin
396384 32768 /home/q/doc/modem/jz08-aurora/b5a/boot-emmc1-16MiB.img
429152 1638400 /home/q/doc/modem/jz08-aurora/logs/b5a/A4pre/system.bin
2067552 65536 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/persist.bin
2133088 262144 /tmp/tmp.QnjFJPSggN/F1-no-conf.img
2395232 32768 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/recovery.bin
2428000 5206911 /home/q/doc/modem/jz08-aurora/logs/b5a/A4pre/userdata.bin

View file

@ -0,0 +1,28 @@
0 34 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/gpt-primary-34.bin
131072 131072 /home/q/doc/modem/jz08-aurora/logs/b5a/A4pre/modem.bin
262144 1024 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/sbl1.bin
263168 1024 /home/q/doc/modem/jz08-aurora/partitions/sbl1bak.bin
264192 2048 /home/q/doc/modem/jz08-aurora/b5a/aboot-lk1st-aurora-autoboot.pad1M
266240 2048 /home/q/doc/modem/jz08-aurora/partitions/abootbak.bin
268288 1024 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/rpm.bin
269312 1024 /home/q/doc/modem/jz08-aurora/partitions/rpmbak.bin
270336 2048 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/tz.bin
305184 1024 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/tzbak-305184.bin
272384 1024 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/hyp.bin
273408 1024 /home/q/doc/modem/jz08-aurora/partitions/hypbak.bin
274432 2048 /home/q/doc/modem/jz08-aurora/partitions/pad.bin
276480 3072 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/modemst1.bin
279552 3072 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/modemst2.bin
282624 2048 /home/q/doc/modem/jz08-aurora/partitions/misc.bin
284672 2 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/fsc.bin
284674 16 /home/q/doc/modem/jz08-aurora/partitions/ssd.bin
284690 20480 /home/q/doc/modem/jz08-aurora/partitions/splash.bin
393216 64 /home/q/doc/modem/jz08-aurora/partitions/DDR.bin
393280 3072 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/fsg.bin
396352 32 /home/q/doc/modem/jz08-aurora/partitions/sec.bin
396384 32768 /home/q/doc/modem/jz08-aurora/b5a/boot-emmc1-16MiB.img
429152 1638400 /home/q/doc/modem/jz08-aurora/logs/b5a/A4pre/system.bin
2067552 65536 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/persist.bin
2133088 262144 /tmp/tmp.QnjFJPSggN/F10-zeroed-cache.img
2395232 32768 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/recovery.bin
2428000 5206911 /home/q/doc/modem/jz08-aurora/logs/b5a/A4pre/userdata.bin

28
b9/b9c/cache/emu/map-F3-no-initrd.txt vendored Normal file
View file

@ -0,0 +1,28 @@
0 34 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/gpt-primary-34.bin
131072 131072 /home/q/doc/modem/jz08-aurora/logs/b5a/A4pre/modem.bin
262144 1024 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/sbl1.bin
263168 1024 /home/q/doc/modem/jz08-aurora/partitions/sbl1bak.bin
264192 2048 /home/q/doc/modem/jz08-aurora/b5a/aboot-lk1st-aurora-autoboot.pad1M
266240 2048 /home/q/doc/modem/jz08-aurora/partitions/abootbak.bin
268288 1024 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/rpm.bin
269312 1024 /home/q/doc/modem/jz08-aurora/partitions/rpmbak.bin
270336 2048 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/tz.bin
305184 1024 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/tzbak-305184.bin
272384 1024 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/hyp.bin
273408 1024 /home/q/doc/modem/jz08-aurora/partitions/hypbak.bin
274432 2048 /home/q/doc/modem/jz08-aurora/partitions/pad.bin
276480 3072 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/modemst1.bin
279552 3072 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/modemst2.bin
282624 2048 /home/q/doc/modem/jz08-aurora/partitions/misc.bin
284672 2 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/fsc.bin
284674 16 /home/q/doc/modem/jz08-aurora/partitions/ssd.bin
284690 20480 /home/q/doc/modem/jz08-aurora/partitions/splash.bin
393216 64 /home/q/doc/modem/jz08-aurora/partitions/DDR.bin
393280 3072 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/fsg.bin
396352 32 /home/q/doc/modem/jz08-aurora/partitions/sec.bin
396384 32768 /home/q/doc/modem/jz08-aurora/b5a/boot-emmc1-16MiB.img
429152 1638400 /home/q/doc/modem/jz08-aurora/logs/b5a/A4pre/system.bin
2067552 65536 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/persist.bin
2133088 262144 /tmp/tmp.QnjFJPSggN/F3-no-initrd.img
2395232 32768 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/recovery.bin
2428000 5206911 /home/q/doc/modem/jz08-aurora/logs/b5a/A4pre/userdata.bin

View file

@ -0,0 +1,28 @@
0 34 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/gpt-primary-34.bin
131072 131072 /home/q/doc/modem/jz08-aurora/logs/b5a/A4pre/modem.bin
262144 1024 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/sbl1.bin
263168 1024 /home/q/doc/modem/jz08-aurora/partitions/sbl1bak.bin
264192 2048 /home/q/doc/modem/jz08-aurora/b5a/aboot-lk1st-aurora-autoboot.pad1M
266240 2048 /home/q/doc/modem/jz08-aurora/partitions/abootbak.bin
268288 1024 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/rpm.bin
269312 1024 /home/q/doc/modem/jz08-aurora/partitions/rpmbak.bin
270336 2048 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/tz.bin
305184 1024 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/tzbak-305184.bin
272384 1024 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/hyp.bin
273408 1024 /home/q/doc/modem/jz08-aurora/partitions/hypbak.bin
274432 2048 /home/q/doc/modem/jz08-aurora/partitions/pad.bin
276480 3072 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/modemst1.bin
279552 3072 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/modemst2.bin
282624 2048 /home/q/doc/modem/jz08-aurora/partitions/misc.bin
284672 2 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/fsc.bin
284674 16 /home/q/doc/modem/jz08-aurora/partitions/ssd.bin
284690 20480 /home/q/doc/modem/jz08-aurora/partitions/splash.bin
393216 64 /home/q/doc/modem/jz08-aurora/partitions/DDR.bin
393280 3072 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/fsg.bin
396352 32 /home/q/doc/modem/jz08-aurora/partitions/sec.bin
396384 32768 /home/q/doc/modem/jz08-aurora/b5a/boot-emmc1-16MiB.img
429152 1638400 /home/q/doc/modem/jz08-aurora/logs/b5a/A4pre/system.bin
2067552 65536 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/persist.bin
2133088 262144 /home/q/doc/modem/jz08-aurora/b8/b8f/cache/cache-extlinux-b8f.img
2395232 32768 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/recovery.bin
2428000 5206911 /home/q/doc/modem/jz08-aurora/logs/b5a/A4pre/userdata.bin

View file

@ -0,0 +1,28 @@
0 34 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/gpt-primary-34.bin
131072 131072 /home/q/doc/modem/jz08-aurora/logs/b5a/A4pre/modem.bin
262144 1024 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/sbl1.bin
263168 1024 /home/q/doc/modem/jz08-aurora/partitions/sbl1bak.bin
264192 2048 /home/q/doc/modem/jz08-aurora/b5a/aboot-lk1st-aurora-autoboot.pad1M
266240 2048 /home/q/doc/modem/jz08-aurora/partitions/abootbak.bin
268288 1024 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/rpm.bin
269312 1024 /home/q/doc/modem/jz08-aurora/partitions/rpmbak.bin
270336 2048 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/tz.bin
305184 1024 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/tzbak-305184.bin
272384 1024 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/hyp.bin
273408 1024 /home/q/doc/modem/jz08-aurora/partitions/hypbak.bin
274432 2048 /home/q/doc/modem/jz08-aurora/partitions/pad.bin
276480 3072 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/modemst1.bin
279552 3072 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/modemst2.bin
282624 2048 /home/q/doc/modem/jz08-aurora/partitions/misc.bin
284672 2 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/fsc.bin
284674 16 /home/q/doc/modem/jz08-aurora/partitions/ssd.bin
284690 20480 /home/q/doc/modem/jz08-aurora/partitions/splash.bin
393216 64 /home/q/doc/modem/jz08-aurora/partitions/DDR.bin
393280 3072 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/fsg.bin
396352 32 /home/q/doc/modem/jz08-aurora/partitions/sec.bin
396384 32768 /home/q/doc/modem/jz08-aurora/b5a/boot-emmc1-16MiB.img
429152 1638400 /home/q/doc/modem/jz08-aurora/logs/b5a/A4pre/system.bin
2067552 65536 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/persist.bin
2133088 262144 /home/q/doc/modem/jz08-aurora/b9/b9c/cache/cache-extlinux-b9c.img
2395232 32768 /home/q/doc/modem/jz08-aurora/logs/b5a/A3/recovery.bin
2428000 5206911 /home/q/doc/modem/jz08-aurora/logs/b5a/A4pre/userdata.bin

13
b9/b9c/cache/emu/run-emu-b9c.sh vendored Executable file
View file

@ -0,0 +1,13 @@
#!/bin/bash
# lk2nd-23.1 extlinux emulator (b5b/emu) on: S6 (B8F cache = current flash, regression vs b8/b8f/cache/emu), S7 B9C candidate, fault variants. Offline, 480s.
cd ~/doc/modem/jz08-aurora/b9/b9c/cache/emu; E=../../../../b5b/emu; GPT=../../../../logs/b5a/A3/gpt-primary-34.bin; C=/home/q/doc/modem/jz08-aurora/b9/b9c/cache/cache-extlinux-b9c.img
run() { python3 $E/mkmap.py $2 > map-$1.txt; $E/lk2nd-scan-emu map-$1.txt $GPT $3 > $1.out 2>&1; echo "== $1 rc=$? :: $(grep -E "Trying to boot|Reverting|boot_linux reached|ramdisk sha256|Could not" $1.out | tr '\n' ' ' | cut -c1-260)"; }
run S6-b8f-regression /home/q/doc/modem/jz08-aurora/b8/b8f/cache/cache-extlinux-b8f.img 23955464
cmp <(grep HARNESS S6-b8f-regression.out) <(grep HARNESS ../../../../b8/b8f/cache/emu/S6-b8f-candidate.out) && echo " S6 HARNESS lines == b8/b8f/cache/emu/S6-b8f-candidate.out"
run S7-b9c-candidate $C 24686600; # kernel_len = B9C Image (3afc6c77, 24686600 B)
grep HARNESS S7-b9c-candidate.out
D=$(mktemp -d); v(){ cp $C $D/$1.img; chmod u+w $D/$1.img; }
v F3-no-initrd; /sbin/debugfs -w -R "rm /initramfs-b9c.cpio.gz" $D/F3-no-initrd.img >/dev/null 2>&1
v F1-no-conf; /sbin/debugfs -w -R "rm /extlinux/extlinux.conf" $D/F1-no-conf.img >/dev/null 2>&1
head -c 134217728 /dev/zero > $D/F10-zeroed-cache.img
for f in $D/F*.img; do run $(basename $f .img) $f; done; rm -rf $D

6
b9/b9c/cache/extlinux-b9c.conf vendored Normal file
View file

@ -0,0 +1,6 @@
default b9c
label b9c
linux /Image.gz-dtb
fdt /aurora-b9c.dtb
initrd /initramfs-b9c.cpio.gz
append earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0

27
b9/b9c/cache/mkfs-cache-b9c.sh vendored Executable file
View file

@ -0,0 +1,27 @@
#!/bin/bash
# B9C cache candidate: exact recipe of b8/b8f/cache/mkfs-cache-b8f.sh (857c9c30); differs only in kernel file (B9C Image.gz-dtb: b9c kernel
# + B9B DTB), fdt (B9B DTB), initrd (B9C initramfs), append (B9C cmdline = B8F + console=tty0 before the UART console + fbcon=font:6x8
# consoleblank=0), file names, extlinux label, fs label and UUIDs. Runs on 480s (mke2fs 1.47.2). Offline only.
# The image contains the AP PSK (in the initramfs) - never publish it.
set -e
cd ~/doc/modem/jz08-aurora/b9/b9c/cache
OUT=${1:-cache-extlinux-b9c.img}; F=../out
echo "0fef41b262917c8ae308fa222da0017e2b3cb3ec5da1ca8ba18d0318476761a3 $F/cmdline.txt" | sha256sum -c
echo "632a7be801978dfaddeae633d5293b3abe385f2281cc5053772e6637897a7e5a $F/Image.gz-dtb" | sha256sum -c
echo "7ca9cc794a3b85d3b7240f6311ad03bee9e1a4a59aae2ed9438318e853f7c3dc $F/aurora-b9c.dtb" | sha256sum -c
echo "ac518e27e2957ad5e4515969b9a3808024e11ef8d1a79433a899a67dbc644558 $F/initramfs-b9c.cpio.gz" | sha256sum -c
ST=$(mktemp -d); mkdir -p $ST/extlinux
cp $F/Image.gz-dtb $F/aurora-b9c.dtb $F/initramfs-b9c.cpio.gz $ST/
printf "default b9c\nlabel b9c\n\tlinux /Image.gz-dtb\n\tfdt /aurora-b9c.dtb\n\tinitrd /initramfs-b9c.cpio.gz\n\tappend %s\n" "$(cat $F/cmdline.txt)" > $ST/extlinux/extlinux.conf
cp $ST/extlinux/extlinux.conf extlinux-b9c.conf
chmod 0644 $ST/*.* $ST/extlinux/extlinux.conf; chmod 0755 $ST $ST/extlinux
find $ST -exec touch -h -d @1790726400 {} +
rm -f $OUT; truncate -s 134217728 $OUT
E2FSPROGS_FAKE_TIME=1790726400 /sbin/mke2fs -F -q -t ext2 -O none,filetype,sparse_super \
-b 4096 -I 128 -N 64 -m 0 -L aurora-b9c -U 4a5a3038-b6f0-4000-8000-00000000b9c0 \
-E root_owner=0:0,hash_seed=4a5a3038-b6f0-4000-8000-00000000b9c1 -d $ST $OUT 32768
rm -rf $ST
for f in / /lost+found /extlinux /extlinux/extlinux.conf /Image.gz-dtb /aurora-b9c.dtb /initramfs-b9c.cpio.gz; do for t in atime ctime mtime; do echo "sif $f $t @1790726400"; done; done > /tmp/b9c-sif.$$
/sbin/debugfs -w -f /tmp/b9c-sif.$$ $OUT >/dev/null 2>&1; rm -f /tmp/b9c-sif.$$
/sbin/e2fsck -fn $OUT >/dev/null 2>&1 && echo "e2fsck -fn clean"
stat -c "%n %s" $OUT; sha256sum $OUT

1
b9/b9c/cmdline.txt Normal file
View file

@ -0,0 +1 @@
earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0

9
b9/b9c/out/SHA256SUMS Normal file
View file

@ -0,0 +1,9 @@
e28f8b531193943e40848c018012093cea89250f0ca62809c040c242bbc8235c Image.gz
7ca9cc794a3b85d3b7240f6311ad03bee9e1a4a59aae2ed9438318e853f7c3dc aurora-b9c.dtb
632a7be801978dfaddeae633d5293b3abe385f2281cc5053772e6637897a7e5a Image.gz-dtb
8820db2735ce1ed58b982b0fef6159490235e3d1868bd63004a9602fe03998f8 config-b9c
58697d4db45a9af85ec09e03a4212955ae3c7eed7d9f6bda82071da1b44329b4 jz08au,aurora-st7735s.bin
0fef41b262917c8ae308fa222da0017e2b3cb3ec5da1ca8ba18d0318476761a3 cmdline.txt
9e41cdda2815b8101676c0f37455aea59d3e5d34c7ab23c02f098ad9c8639107 overlay-b9c.cpio.gz
ac518e27e2957ad5e4515969b9a3808024e11ef8d1a79433a899a67dbc644558 initramfs-b9c.cpio.gz
fa855e1c84763861d8b2f6bd7ed669e8ab625aa42178317883fabff39dec4fce aurora-b9c.img

1
b9/b9c/out/cmdline.txt Normal file
View file

@ -0,0 +1 @@
earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0

28
b9/b9c/out/init.diff Normal file
View file

@ -0,0 +1,28 @@
--- ../../b8/b8f/rootfs/init 2026-10-03 01:03:40.225791442 +0600
+++ rootfs/init 2026-10-03 03:07:15.657377190 +0600
@@ -1,6 +1,7 @@
#!/bin/busybox sh
# Aurora RAM boot MM1 — QMI1 + ModemManager (qcom-soc) + D-Bus + polkit + eudev.
# R2/T4: B6P init + telnetd on NCM. B8F: + Wi-Fi service autostart (aurora-wifi).
+# B9C: + hostname aurora, display service (fbcon/backlight on the ST7735S) and a getty on tty1.
# B6P: after eMMC RO + /firmware RO + USB NCM, autostarts /etc/init.d/aurora-modem (B6N-proven lifecycle).
# NEVER mounts, fsck's, formats, trims or writes any mmcblk* device.
# No block devices, no firmware, no radios. Never exits (failures leave the UART shell).
@@ -10,6 +11,7 @@
mount -t sysfs sysfs /sys
mount -t devtmpfs devtmpfs /dev 2>/dev/null
mount -t configfs configfs /sys/kernel/config
+hostname aurora # B9C: getty prompt 'aurora login:'
log() { echo "[init] $*"; echo "[init] $*" > /dev/kmsg 2>/dev/null; }
echo
echo "=== AURORA RAM BOOT MM1 + B6P modem service ==="
@@ -124,6 +126,9 @@
if telnetd -l /bin/sh -b 172.16.42.1 -p 23; then log "T4: telnetd started on 172.16.42.1:23"; else log "T4: telnetd start FAILED"; fi
else log "T4: no 172.16.42.1 - telnetd NOT started"; fi
+# B9C: display (no disk/radio access): fbcon on tty1 + backlight, and a display-only getty on tty1 (UART shell below unchanged).
+/etc/init.d/aurora-display start
+( while true; do getty 0 tty1 linux; sleep 2; done ) > /dev/null 2>&1 < /dev/null &
if [ "$EMMC_RO_OK" = 1 ]; then emmc_report; else log "EMMC: RO not confirmed or device missing - NO further disk access"; fi
echo "B1_OK=${B1_OK:-0}"
# B6P: modem autostart only when every eMMC device is RO and the modem FAT is mounted RO (the controller re-checks both).

View file

@ -0,0 +1,5 @@
file /init rootfs/init 0755 0 0
file /usr/sbin/aurora-display rootfs/usr/sbin/aurora-display 0755 0 0
file /etc/init.d/aurora-display rootfs/etc/init.d/aurora-display 0755 0 0
dir /lib/firmware 0755 0 0
file /lib/firmware/jz08au,aurora-st7735s.bin out/jz08au,aurora-st7735s.bin 0644 0 0

View file

@ -0,0 +1,13 @@
#!/bin/sh
# Aurora display service (B9C). Started once by /init; no OpenRC.
# /etc/init.d/aurora-display start | status — kernel cmdline 'aurora.display=off' disables autostart.
C=/usr/sbin/aurora-display; D=/run/aurora-display; L=$D/service.log
mkdir -p $D
case "$1" in
start)
grep -qw aurora.display=off /proc/cmdline && { echo "aurora-display: disabled by cmdline"; exit 0; }
( $C start >> $L 2>&1; echo "=== service start rc=$? $(cut -d' ' -f1 /proc/uptime)" >> $L ) &
echo "aurora-display: starting (pid $!, log $D/display.log)";;
status) $C status; tail -3 $D/display.log 2>/dev/null;;
*) echo "usage: $0 start|status"; exit 2;;
esac

142
b9/b9c/rootfs/init Executable file
View file

@ -0,0 +1,142 @@
#!/bin/busybox sh
# Aurora RAM boot MM1 — QMI1 + ModemManager (qcom-soc) + D-Bus + polkit + eudev.
# R2/T4: B6P init + telnetd on NCM. B8F: + Wi-Fi service autostart (aurora-wifi).
# B9C: + hostname aurora, display service (fbcon/backlight on the ST7735S) and a getty on tty1.
# B6P: after eMMC RO + /firmware RO + USB NCM, autostarts /etc/init.d/aurora-modem (B6N-proven lifecycle).
# NEVER mounts, fsck's, formats, trims or writes any mmcblk* device.
# No block devices, no firmware, no radios. Never exits (failures leave the UART shell).
/bin/busybox mkdir -p /proc /sys /dev /tmp /usr/bin /usr/sbin /sbin
/bin/busybox --install -s
mount -t proc proc /proc
mount -t sysfs sysfs /sys
mount -t devtmpfs devtmpfs /dev 2>/dev/null
mount -t configfs configfs /sys/kernel/config
hostname aurora # B9C: getty prompt 'aurora login:'
log() { echo "[init] $*"; echo "[init] $*" > /dev/kmsg 2>/dev/null; }
echo
echo "=== AURORA RAM BOOT MM1 + B6P modem service ==="
uname -a
echo "--- model"; cat /proc/device-tree/model; echo
echo "--- cmdline"; cat /proc/cmdline
emmc_ro() {
for i in $(seq 1 100); do [ -b /dev/mmcblk0 ] && break; sleep 0.1; done
if [ ! -b /dev/mmcblk0 ]; then log "EMMC: /dev/mmcblk0 did not appear"; return 1; fi
sleep 0.5 # let partition nodes settle
for d in /dev/mmcblk0 /dev/mmcblk0p* /dev/mmcblk0boot*; do [ -b "$d" ] && blockdev --setro "$d"; done
bad=0; n=0
for d in /dev/mmcblk0 /dev/mmcblk0p* /dev/mmcblk0boot*; do
[ -b "$d" ] || continue; n=$((n+1)); r=$(blockdev --getro "$d")
[ "$r" = "1" ] || { bad=1; log "EMMC-RO FAIL $d getro=$r"; }
done
echo "EMMC-RO-SUMMARY devices=$n all_ro=$([ $bad = 0 ] && echo YES || echo NO)"
[ $bad = 0 ] || return 2
log "EMMC: all $n block devices read-only (getro=1)"
}
emmc_report() {
echo "=== EMMC-INFO-BEGIN"
C=/sys/class/block/mmcblk0/device
for f in name manfid oemid cid date serial type; do echo "$f=$(cat $C/$f 2>/dev/null)"; done
echo "size_512=$(cat /sys/class/block/mmcblk0/size) logical_block=$(cat /sys/class/block/mmcblk0/queue/logical_block_size) bytes=$(blockdev --getsize64 /dev/mmcblk0)"
cat /proc/partitions
echo "=== EMMC-GPT-BEGIN (pN name start_512 size_512 ro)"
for p in /sys/class/block/mmcblk0p*; do
b=$(basename $p); nm=$(sed -n 's/^PARTNAME=//p' $p/uevent)
echo "$b $nm $(cat $p/start) $(cat $p/size) $(cat $p/ro)"
done
echo "=== EMMC-GPT-END"
echo "=== EMMC-SHA-BEGIN"
for want in sbl1 rpm DDR sec aboot hyp tz tzbak; do
for p in /sys/class/block/mmcblk0p*; do
nm=$(sed -n 's/^PARTNAME=//p' $p/uevent)
[ "$nm" = "$want" ] && echo "$nm $(basename $p) $(sha256sum /dev/$(basename $p) | cut -d' ' -f1)"
done
done
echo "=== EMMC-SHA-END"
echo "=== EMMC-INFO-END"
}
emmc_ro && EMMC_RO_OK=1 # RO FIRST, before anything else touches the disk
nv_snapshot() { # $1 = before|after ; reads RO block devices only
o=/tmp/nv-$1.txt; : > $o
for want in modemst1 modemst2 fsg fsc persist; do
for p in /sys/class/block/mmcblk0p*; do
[ "$(sed -n 's/^PARTNAME=//p' $p/uevent)" = "$want" ] && echo "$want $(basename $p) $(sha256sum /dev/$(basename $p) | cut -d' ' -f1)" >> $o
done
done
echo "stat $(cat /sys/block/mmcblk0/stat)" >> $o
}
b1_modem_fat() {
mkdir -p /dev/disk/by-partlabel /firmware
for p in /sys/class/block/mmcblk0p*; do
n=$(sed -n 's/^PARTNAME=//p' $p/uevent); [ -n "$n" ] && ln -sf /dev/$(basename $p) /dev/disk/by-partlabel/$n
done
M=$(readlink /dev/disk/by-partlabel/modem); echo "B1 modem partition by PARTLABEL: modem -> $M ro=$(blockdev --getro $M)"
[ "$(blockdev --getro $M)" = 1 ] || { log "B1: modem partition not RO - NOT mounting"; return 1; }
mount -t vfat -o ro,nosuid,nodev,noexec,shortname=lower $M /firmware || { log "B1: mount failed"; return 1; }
grep " /firmware " /proc/mounts
grep " /firmware " /proc/mounts | grep -q " ro," || { log "B1: /firmware is NOT ro - unmounting"; umount /firmware; return 1; }
(cd /firmware && find . -type f | sort | while read f; do echo "$(sha256sum "$f" | cut -d' ' -f1) ${f#./}"; done) > /tmp/fw-sha.txt
echo "B1 firmware files: $(wc -l < /tmp/fw-sha.txt)"
echo -n /firmware/image > /sys/module/firmware_class/parameters/path
log "B1: modem FAT mounted RO at /firmware, firmware path /firmware/image"
}
if [ "$EMMC_RO_OK" = 1 ]; then
echo "stat-before-B1 $(cat /sys/block/mmcblk0/stat)" > /tmp/stat-before-B1.txt
nv_snapshot before
b1_modem_fat && B1_OK=1
fi
usb_up() {
for i in $(seq 1 50); do
udc=$(ls /sys/class/udc 2>/dev/null | head -1)
[ -n "$udc" ] && break
sleep 0.2
done
echo "--- /sys/class/udc:"; ls -l /sys/class/udc 2>&1
if [ -z "$udc" ]; then log "NO UDC found - USB gadget skipped"; return 1; fi
# DEVELOPMENT-ONLY IDs (same dev setup as JZ02: Google 18d1:d001) - not for production
G=/sys/kernel/config/usb_gadget/aurora
mkdir -p $G || return 1
echo 0x18d1 > $G/idVendor
echo 0xd001 > $G/idProduct
mkdir -p $G/strings/0x409
echo "Aurora" > $G/strings/0x409/manufacturer
echo "Aurora RAM Boot" > $G/strings/0x409/product
echo "<EMMC_SERIAL>" > $G/strings/0x409/serialnumber
mkdir -p $G/functions/ncm.usb0 || { log "ncm function create FAILED"; return 1; }
mkdir -p $G/configs/c.1/strings/0x409
echo "NCM" > $G/configs/c.1/strings/0x409/configuration
ln -s $G/functions/ncm.usb0 $G/configs/c.1/
echo "$udc" > $G/UDC || { log "bind to UDC '$udc' FAILED"; return 1; }
log "usb gadget bound to UDC '$udc'"
ifc=$(cat $G/functions/ncm.usb0/ifname 2>/dev/null)
log "ncm ifname='$ifc' dev_addr=$(cat $G/functions/ncm.usb0/dev_addr) host_addr=$(cat $G/functions/ncm.usb0/host_addr)"
[ -n "$ifc" ] || return 1
ip link set lo up
ip addr add 172.16.42.1/24 dev "$ifc"
ip link set "$ifc" up
ip addr show "$ifc"
log "network: $ifc 172.16.42.1/24 up (static, no DHCP)"
}
usb_up || log "USB/NCM setup incomplete - staying on UART shell"
# R2/T4 (RAM-only, DEVELOPMENT): unauthenticated root telnet shell on the NCM link only (bind 172.16.42.1:23).
if ip addr show | grep -q " 172.16.42.1/24 "; then
mkdir -p /dev/pts; mount -t devpts devpts /dev/pts || log "T4: devpts mount FAILED"
if telnetd -l /bin/sh -b 172.16.42.1 -p 23; then log "T4: telnetd started on 172.16.42.1:23"; else log "T4: telnetd start FAILED"; fi
else log "T4: no 172.16.42.1 - telnetd NOT started"; fi
# B9C: display (no disk/radio access): fbcon on tty1 + backlight, and a display-only getty on tty1 (UART shell below unchanged).
/etc/init.d/aurora-display start
( while true; do getty 0 tty1 linux; sleep 2; done ) > /dev/null 2>&1 < /dev/null &
if [ "$EMMC_RO_OK" = 1 ]; then emmc_report; else log "EMMC: RO not confirmed or device missing - NO further disk access"; fi
echo "B1_OK=${B1_OK:-0}"
# B6P: modem autostart only when every eMMC device is RO and the modem FAT is mounted RO (the controller re-checks both).
if [ "$EMMC_RO_OK" = 1 ] && [ "$B1_OK" = 1 ]; then /etc/init.d/aurora-modem start; else log "B6P: modem autostart SKIPPED (EMMC_RO_OK=${EMMC_RO_OK:-0} B1_OK=${B1_OK:-0})"; fi
# B8F: Wi-Fi autostart (Pronto + wcn36xx + test AP) under the same RO gates; the service itself waits for modem START OK/FAIL.
if [ "$EMMC_RO_OK" = 1 ] && [ "$B1_OK" = 1 ]; then /etc/init.d/aurora-wifi start; else log "B8F: wifi autostart SKIPPED"; fi
echo "=== entering shell (exit restarts it) ==="
while true; do
setsid cttyhack sh
echo "shell exited, restarting"; sleep 1
done

View file

@ -0,0 +1,44 @@
#!/bin/sh
# Aurora display controller (B9C). ST7735S on SPI via panel-mipi-dbi (DRM) -> fb0 -> fbcon (tty1) + MPP4 backlight.
# aurora-display start : wait for fb0, make sure the display pipe is enabled (fbcon takeover modeset, or one fbdev
# unblank if nothing enabled it), then switch the backlight on through the gpio-backlight driver.
# aurora-display status : one-line state summary
# aurora-display bl on|off
# Never writes PMIC/GPIO registers directly: only fb0 'blank' and backlight sysfs attributes of the kernel drivers.
D=/run/aurora-display; L=$D/display.log; mkdir -p $D
FB=/sys/class/graphics/fb0; CON=/sys/class/drm/card0-SPI-1; BL=/sys/class/backlight/backlight
t() { cut -d' ' -f1 /proc/uptime; }
log() { echo "[$(t)] $*" >> $L; echo "[aurora-display] $*" > /dev/kmsg 2>/dev/null; }
fbcon_bound() { for v in /sys/class/vtconsole/vtcon*; do grep -q "frame buffer" $v/name 2>/dev/null && [ "$(cat $v/bind)" = 1 ] && return 0; done; return 1; }
l17_users() { for r in /sys/class/regulator/regulator.*; do [ "$(cat $r/name 2>/dev/null)" = l17 ] && { cat $r/num_users; return; }; done; echo 0; }
pipe_on() { [ "$(cat $CON/enabled 2>/dev/null)" = enabled ] && [ "$(cat $CON/dpms 2>/dev/null)" = On ] && [ "$(l17_users)" -ge 1 ]; }
state() { echo "fb0=$([ -e $FB ] && cat $FB/name) fbcon=$(fbcon_bound && echo bound || echo no) conn=$(cat $CON/enabled 2>/dev/null)/$(cat $CON/dpms 2>/dev/null) l17_users=$(l17_users) bl_power=$(cat $BL/bl_power 2>/dev/null) bl=$(cat $BL/actual_brightness 2>/dev/null)"; }
wait_for() { n=$1; shift; i=0; until "$@"; do i=$((i+1)); [ $i -ge $n ] && return 1; sleep 0.2; done; }
bl() {
[ -d $BL ] || { log "FAIL: no backlight device"; return 1; }
case $1 in
on) echo 0 > $BL/bl_power; echo 1 > $BL/brightness;;
off) echo 0 > $BL/brightness;;
esac
log "backlight $1 -> bl_power=$(cat $BL/bl_power) actual_brightness=$(cat $BL/actual_brightness)"
}
case "$1" in
start)
log "start: $(state)"
wait_for 100 test -e $FB || { log "FAIL: fb0 did not appear within 20 s"; exit 1; }
fbcon_bound && log "fbcon bound to fb0" || log "fbcon NOT bound (no framebuffer console)"
if wait_for 25 pipe_on; then
log "display pipe already enabled (by fbcon takeover) - no unblank needed"
else
log "display pipe not enabled -> fbdev unblank"
echo 0 > $FB/blank
wait_for 25 pipe_on || { log "FAIL: pipe still not enabled after unblank: $(state)"; exit 1; }
log "display pipe enabled by unblank"
fi
bl on
[ "$(cat $BL/actual_brightness)" = 1 ] || { log "FAIL: backlight did not turn on: $(state)"; exit 1; }
log "=== DISPLAY READY $(state)";;
status) state;;
bl) bl "$2";;
*) echo "usage: $0 start|status|bl on|off"; exit 2;;
esac

10
b9/b9l/BUILD-B9L.md Normal file
View file

@ -0,0 +1,10 @@
# B9L lk2nd 2nd-stage build (RAM test only — never flash without a separate GO)
- Base: lk2nd 23.1 e9c8b217 (same tree as lk2nd-build/src, cloned to /home/q/aurora-lkbuild/b9l-src; the original tree is untouched).
- Patch: lk2nd-23.1-aurora-b9l.patch (msm8916 QUP4 SPI clock + iomap, gpio_config_blsp_spi, clock_config_blsp_spi clamped to 16 MHz,
module lk2nd/aurora (st7735s.c), project hook AURORA_SPI_PANEL=1).
- Command (in b9l-src): make -j4 TOOLCHAIN_PREFIX=arm-none-eabi- LK2ND_DTBS="msm8916-512mb-mtp.dtb" AURORA_SPI_PANEL=1 lk2nd-msm8916
(differences from the B9L-0 23.1 image: no LK2ND_FORCE_FASTBOOT, + AURORA_SPI_PANEL).
- Toolchain arm-none-eabi-gcc 14.2.1 20241119. Output lk2nd-b9l-st7735s.img sha256 775986e2d562ff92840de1783d60899d23babb70fb6566a285600e99a4361499 (299024 B).
- Splash variant (2026-10-03): + AURORA_SPLASH=1 → frame = b9/b9l/splash/swag.png (128x128, alpha 255 everywhere) converted by
splash/mk-splash.py to RGB565 LE (aurora_splash.h, blob sha256 87955300). Patch: lk2nd-23.1-aurora-b9l-splash.patch.
Output lk2nd-b9l-swag.img sha256 e6849a2b. Panel init code identical to 775986e2 (geo variant).

10
b9/b9l/SHA256SUMS Normal file
View file

@ -0,0 +1,10 @@
555826ea14078690fcdd48dcac61cedd6574017f4308adc0a591cd671396d782 lk2nd-23.1-stock.img
2b8b6519946fadb4f29a1e7d234dd7a02939941347d6ccfc44348ad4f2fea296 b9l-fb.sh
775986e2d562ff92840de1783d60899d23babb70fb6566a285600e99a4361499 lk2nd-b9l-st7735s.img
e6849a2b6fb86959bb12b79985b9a9d8dc52c2b3bcf6ceafff57f7b104fe0afe lk2nd-b9l-swag.img
bb86eb620c96064b30f03b7165db793a795e23f188a3d1d684baf3680699307e lk2nd-23.1-aurora-b9l.patch
1a0cd720faeb7cc6f34b2032f6ca96b80a8a8db0813add4eafb7bd819fb5425a lk2nd-23.1-aurora-b9l-splash.patch
53e646357505e9f1256ea0145508258a0f48d99f739ebcef687bfa3d96672202 b9l-ram.sh
f126eb214ab89d3f3f71abd7ebe8960bb4ab4a13a3a7aba7115c12614d9c7adf splash/swag.png
476c9077eeb82386f0bb6c9b17b4583945d60cf262996acf971896bb94141ec6 splash/mk-splash.py
eb3e0f33bb273a7939208f58f9249dab44e044211a1933cfaf645cf9081d9f5c splash/aurora_splash.h

20
b9/b9l/b9l-fb.sh Normal file
View file

@ -0,0 +1,20 @@
#!/bin/sh
# 480s side, B9L: RESET-held power-on -> current lk1st fastboot -> `fastboot boot IMG` (2nd-stage lk2nd, RAM only).
# Nothing is flashed. Logs UART + fastboot identity before/after. usage: b9l-fb.sh TAG IMG SHA256
T=$1; IMG=$2; SHA=$3; cd ~/doc/modem/jz08-aurora; O=logs/b9/b9l/$T; mkdir -p $O; A=$O/host-actions.txt
act() { echo "$(date -u +%H:%M:%S.%3N) $*" | tee -a $A; }
echo "$SHA $IMG" | sha256sum -c || exit 1
OLD=$(ps -eo pid,cmd | grep "[u]artlog.py /dev/ttyUSB0" | awk '{print $1}'); [ -n "$OLD" ] && kill $OLD; sleep 1
U=logs/uart/b9l-$T-$(date +%Y%m%d-%H%M%S); setsid nohup python3 tools/uartlog.py /dev/ttyUSB0 $U > $U.stderr 2>&1 < /dev/null &
echo $U > $O/uartlog-path
act "B9L $T: waiting for lk1st fastboot <EMMC_SERIAL> (power off >= 90 s, then RESET held + battery -> USB)"
i=0; until fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do i=$((i+1)); [ $i -ge 600 ] && { act "ABORT: no fastboot"; exit 1; }; sleep 2; done
act "fastboot present: product=$(fastboot getvar product 2>&1 | sed -n 's/^product: //p')"
{ fastboot boot $IMG 2>&1; echo "rc=$?"; } | tee -a $A
act "waiting for second-stage fastboot (or Linux NCM)"
i=0; while [ $i -lt 90 ]; do
if fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; then act "fastboot present again: product=$(fastboot getvar product 2>&1 | sed -n 's/^product: //p') version-bootloader=$(fastboot getvar version-bootloader 2>&1 | sed -n 's/^version-bootloader: //p')"; break; fi
if ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; then act "Linux NCM ping ok"; break; fi
i=$((i+1)); sleep 2
done
sleep 3; cp $U.log $O/uart.log; act "B9L $T END"

56
b9/b9l/b9l-ram.sh Normal file
View file

@ -0,0 +1,56 @@
#!/bin/sh
# 480s side, B9L RAM test K (derived from b9c-boot.sh ram mode): RESET-held power-on -> lk1st fastboot -> `fastboot boot` the B9L 2nd-stage lk2nd
# (ST7735S init in LK) -> it boots the eMMC cache (B9C extlinux) -> Linux. Then the same LTE/Wi-Fi/display snapshot as B9C.
# MODE=cold: normal power-on (no RESET, no fastboot) -> lk2nd extlinux from eMMC cache. Script only observes + reads over telnet;
# nothing is written to eMMC. Visual display checks need the operator. Adds display/fbcon/getty/console checks to the B8F snapshot.
K=$1; MODE=$2; case "$MODE" in ram|cold) ;; *) echo "usage: $0 K ram|cold"; exit 2;; esac
cd ~/doc/modem/jz08-aurora; O=logs/b9/b9l/$MODE$K; mkdir -p $O; IMG=b9/b9l/lk2nd-b9l-swag.img
A=$O/host-actions.txt; act() { echo "$(date -u +%H:%M:%S.%3N) $*" | tee -a $A; }
tn() { { sleep 1; sed "s/\$/\r/" "$1"; sleep $2; } | ncat 172.16.42.1 23 | tr -d "\000\r"; }
OLD=$(ps -eo pid,cmd | grep "[u]artlog.py /dev/ttyUSB0" | awk '{print $1}'); [ -n "$OLD" ] && kill $OLD; sleep 1
U=logs/uart/b9l-$MODE$K-$(date +%Y%m%d-%H%M%S); setsid nohup python3 tools/uartlog.py /dev/ttyUSB0 $U > $U.stderr 2>&1 < /dev/null &
if [ $MODE = ram ]; then
echo "e6849a2b6fb86959bb12b79985b9a9d8dc52c2b3bcf6ceafff57f7b104fe0afe $IMG" | sha256sum -c || exit 1
act "B9L $MODE$K: waiting for fastboot <EMMC_SERIAL> (power off >= 90 s, then RESET held + battery -> USB)"
if fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; then act "already in fastboot - wait for power-off"; until ! fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do sleep 1; done; fi
i=0; until fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do i=$((i+1)); [ $i -ge 600 ] && { act "ABORT: no fastboot"; exit 1; }; sleep 2; done
PR=$(fastboot getvar product 2>&1 | sed -n "s/^product: //p"); act "fastboot present: product=$PR"
[ "$PR" = lk1st-msm8916 ] || { act "ABORT: not the lk1st fastboot (product=$PR) - power-cycle with RESET held"; exit 1; }
{ fastboot boot $IMG 2>&1; echo "rc=$?"; } | tee -a $A
else
act "B9L $MODE$K: waiting for the board to go away (power off >= 90 s), then normal power-on WITHOUT RESET"
until ! ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do sleep 1; done; act "board unreachable (powered off)"
until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL> && { act "ABORT: board is in fastboot - RESET was held?"; exit 1; }; sleep 1; done
fi
i=0; until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do i=$((i+1)); [ $i -ge 180 ] && { act "ABORT: NCM not up"; cp $U.log $O/uart.log; exit 1; }; sleep 1; done; act "NCM ping ok"
R=$(grep -a "rtc-pm8xxx.*setting system clock" $U.log | tail -1 | sed -n 's/.*(\([0-9]*\)).*/\1/p'); C=B; [ -n "$R" ] && [ "$R" -lt 40 ] && C=A; act "RTC at boot ${R:-?} s -> class $C"
printf 'cat /proc/device-tree/model; echo; uname -r; grep -E "START OK|FAIL in|rollback" /run/aurora-modem/lifecycle.log | tail -1\n' > $O/.w
i=0; until tn $O/.w 3 | grep -qE "^\[[0-9.]+\] .*(=== START OK|FAIL in|rollback)"; do i=$((i+1)); [ $i -ge 80 ] && { act "no START OK/FAIL after ~12 min"; break; }; sleep 6; done
tn $O/.w 3 | grep -aE "Aurora|aurora-b8|START OK|FAIL" | tee -a $A
printf 'grep -E "AP ENABLED|FAIL" /run/aurora-wifi/wifi.log | tail -1\n' > $O/.a
i=0; until tn $O/.a 3 | grep -qE "^\[[0-9.]+\] (=== AP ENABLED|FAIL)"; do i=$((i+1)); [ $i -ge 20 ] && { act "no AP ENABLED/FAIL after ~3 min"; break; }; sleep 6; done
act "wifi: $(tn $O/.a 3 | grep -E '^\[[0-9.]+\] (=== AP ENABLED|FAIL)' | tail -1)"
printf 'grep -E "SNTP (check|STEP|: )" /run/aurora-modem/lifecycle.log | tail -2\n' > $O/.s
i=0; until tn $O/.s 3 | grep -qE "^\[[0-9.]+\] SNTP"; do i=$((i+1)); [ $i -ge 15 ] && break; sleep 4; done; act "sntp: $(tn $O/.s 3 | grep -E '^\[[0-9.]+\] SNTP' | tail -2 | tr '\n' ' ')"
cat > $O/.c <<'C'
echo SNAP-BEGIN; cat /proc/uptime; date -u; cat /proc/device-tree/model; echo; uname -a; cat /proc/cmdline
echo ---time; cat /run/aurora-modem/time-set; grep -E "TIME|SNTP" /run/aurora-modem/lifecycle.log | tail -4
echo ---modem; /etc/init.d/aurora-modem status
echo ---wifi; /etc/init.d/aurora-wifi status; echo ---wifilog; cat /run/aurora-wifi/wifi.log; cat /run/aurora-wifi/service.log; echo ---hostapdlog; cat /run/aurora-wifi/hostapd.log
for r in /sys/class/remoteproc/*; do echo "RP $(cat $r/name)=$(cat $r/state)"; done; iw dev
echo ---dmesg-wifi; dmesg | grep -iE "wcn36xx|wcnss|a204000|cfg80211|aurora-wifi|crash|watchdog"
echo ---ping; ping -c4 -W3 -I wwan0 77.88.8.8 | tail -2
echo ---display; /etc/init.d/aurora-display status; cat /run/aurora-display/display.log; cat /run/aurora-display/service.log
echo ---consoles; cat /sys/class/tty/console/active; for v in /sys/class/vtconsole/vtcon*; do echo "$v $(cat $v/bind) $(cat $v/name)"; done; ls -l /proc/[0-9]*/fd/0 2>/dev/null | grep -E "ttyMSM0|tty1|console" | sed "s/.* \/proc/\/proc/"
echo ---getty; hostname; ps | grep -E "[g]etty|[c]ttyhack| sh$"
echo ---fb; ls -l /dev/dri/card0 /dev/fb0; for f in name bits_per_pixel virtual_size stride; do echo "fb0 $f=$(cat /sys/class/graphics/fb0/$f)"; done; cat /sys/class/drm/card0-SPI-1/enabled /sys/class/drm/card0-SPI-1/dpms
echo ---regs; for r in /sys/class/regulator/regulator.*; do n=$(cat $r/name); case $n in l6|l17) echo "$n $(cat $r/state) $(cat $r/microvolts) users=$(cat $r/num_users)";; esac; done
echo ---bl; for f in bl_power brightness actual_brightness; do echo "bl $f=$(cat /sys/class/backlight/backlight/$f)"; done
echo ---dmesg-display; dmesg | grep -iE "drm|panel|mipi|spi_qup|78b8000|fbcon|Console: |frame buffer|backlight|aurora-display|l17"
echo ---display-errors; dmesg | grep -iE "drm|panel|mipi|spi0|fbcon|backlight|aurora-display" | grep -ciE "err|fail|timeout|warn"
echo ---emmc; awk "{print \"w=\"\$5\" s=\"\$7}" /sys/block/mmcblk0/stat
echo SNAP-END
C
tn $O/.c 25 > $O/snapshot.txt; act "snapshot: $(grep -c SNAP-END $O/snapshot.txt) end markers; $(grep -E '^RP a204' $O/snapshot.txt)"
printf 'dmesg > /tmp/dm.txt; nc -l -p 9881 < /tmp/dm.txt &\n' > $O/.d; tn $O/.d 3 >/dev/null; sleep 1; ncat --recv-only 172.16.42.1 9881 > $O/dmesg.full
cp $U.log $O/uart.log; act "B9L $MODE$K END - operator visual check next"

View file

@ -0,0 +1,411 @@
diff --git a/lk2nd/aurora/rules.mk b/lk2nd/aurora/rules.mk
new file mode 100644
index 00000000..3c97f9cd
--- /dev/null
+++ b/lk2nd/aurora/rules.mk
@@ -0,0 +1,9 @@
+# SPDX-License-Identifier: BSD-3-Clause
+# Aurora B9L (RAM test only): ST7735S SPI panel bring-up for the JZ08AU board (msm8916), stock-LK parameters.
+# Uses the CAF spi_qup driver directly; platform/msm_shared/mdss_spi.o is deliberately NOT built (it is hard-wired
+# to QM215/msm8909 and its presence would pull in lk2nd/device/2nd/spi-display.o, which dereferences a NULL panel.intf).
+LOCAL_DIR := $(GET_LOCAL_DIR)
+
+OBJS += \
+ platform/msm_shared/spi_qup.o \
+ $(LOCAL_DIR)/st7735s.o \
diff --git a/lk2nd/aurora/st7735s.c b/lk2nd/aurora/st7735s.c
new file mode 100644
index 00000000..8bfaeae3
--- /dev/null
+++ b/lk2nd/aurora/st7735s.c
@@ -0,0 +1,203 @@
+// SPDX-License-Identifier: BSD-3-Clause
+/*
+ * Aurora JZ08AU (msm8916) ST7735S 128x128 SPI panel bring-up — B9L RAM test only.
+ * Every parameter is taken from the stock Aurora LK (aboot) analysis (logs/b9/b9a, logs/b9/lk):
+ * BLSP1 QUP4 (0x78b8000), 16 MHz, SPI mode 3 (CLK_IDLE_HIGH, INPUT_FIRST=0), CS0, TX only;
+ * D/C = GPIO116, RESET = GPIO118 (1, 0 for 1 ms, 1, wait 120 ms); the 19 stock init commands (ending with RAMWR);
+ * one RGB565 frame (16-bit words); backlight = PM8916 MPP4 current sink 40 mA (MODE 0x61, SINK 7, EN 0x80).
+ * No regulator is touched (stock LK has no regulator code either); L6/L17 state is only read and logged.
+ * The display is NOT registered with fbcon, so lk2nd's own display code cannot draw over the test frame.
+ */
+#include <debug.h>
+#include <reg.h>
+#include <stdlib.h>
+#include <string.h>
+#include <platform.h>
+#include <platform/timer.h>
+#include <platform/gpio.h>
+#include <platform/iomap.h>
+#include <blsp_qup.h>
+#include <spi_qup.h>
+#include <pm8x41_hw.h>
+
+#include <lk2nd/init.h>
+
+#define DC_GPIO 116
+#define RST_GPIO 118
+#define W 128
+#define H 128
+
+#define TLMM_CFG(n) (TLMM_BASE_ADDR + 0x1000 * (n))
+#define TLMM_IO(n) (TLMM_BASE_ADDR + 0x1000 * (n) + 4)
+
+static struct qup_spi_dev *dev;
+
+/* stock LK table @0x8f64849c == stock dtb_01 qcom,mdss-spi-on-command (b9/b9a/decode-panel.py) */
+static const struct { uint8_t len, wait; uint8_t d[17]; } cmds[] = {
+ { 1, 120, { 0x11 } },
+ { 4, 0, { 0xb1, 0x05, 0x3a, 0x3a } },
+ { 4, 0, { 0xb2, 0x05, 0x3a, 0x3a } },
+ { 7, 0, { 0xb3, 0x05, 0x3a, 0x3a, 0x05, 0x3a, 0x3a } },
+ { 2, 0, { 0xb4, 0x03 } },
+ { 4, 0, { 0xc0, 0x62, 0x02, 0x04 } },
+ { 2, 0, { 0xc1, 0xc0 } },
+ { 3, 0, { 0xc2, 0x0d, 0x00 } },
+ { 3, 0, { 0xc3, 0x8d, 0x6a } },
+ { 3, 0, { 0xc4, 0x8d, 0xee } },
+ { 2, 0, { 0xc5, 0x12 } },
+ { 17, 0, { 0xe0, 0x03, 0x1b, 0x12, 0x11, 0x3f, 0x3a, 0x32, 0x34, 0x2f, 0x2b, 0x30, 0x3a, 0x00, 0x01, 0x02, 0x05 } },
+ { 17, 0, { 0xe1, 0x03, 0x1b, 0x12, 0x11, 0x32, 0x2f, 0x2a, 0x2f, 0x2e, 0x2c, 0x35, 0x3f, 0x00, 0x00, 0x01, 0x05 } },
+ { 2, 0, { 0x36, 0xc8 } },
+ { 2, 0, { 0x3a, 0x05 } },
+ { 5, 0, { 0x2a, 0x00, 0x02, 0x00, 0x81 } },
+ { 5, 0, { 0x2b, 0x00, 0x03, 0x00, 0x82 } },
+ { 1, 0, { 0x29 } },
+ { 1, 0, { 0x2c } },
+};
+
+static unsigned t0;
+#define LOG(fmt, ...) dprintf(INFO, "[B9L +%u ms] " fmt "\n", (unsigned)(current_time() - t0), ##__VA_ARGS__)
+
+static int spi_cmd(uint8_t c)
+{
+ int ret;
+ dev->bytes_per_word = 1;
+ dev->bit_shift_en = 1;
+ gpio_set_dir(DC_GPIO, 0); /* D/C low = command */
+ ret = spi_qup_write(dev, &c, 1);
+ gpio_set_dir(DC_GPIO, 2);
+ return ret;
+}
+
+static int spi_data(const uint8_t *b, unsigned len)
+{
+ dev->bytes_per_word = 1;
+ dev->bit_shift_en = 1;
+ gpio_set_dir(DC_GPIO, 2); /* D/C high = parameters */
+ return spi_qup_write(dev, b, len);
+}
+
+static int spi_frame(const uint8_t *b, unsigned len)
+{
+ dev->bytes_per_word = 2; /* RGB565, little-endian u16 in memory, sent MSB first (as stock LK) */
+ dev->bit_shift_en = 1;
+ dev->unpack_en = 0;
+ gpio_set_dir(DC_GPIO, 2);
+ return spi_qup_write(dev, b, len);
+}
+
+static uint16_t rgb(uint8_t r, uint8_t g, uint8_t b)
+{
+ return (r >> 3) << 11 | (g >> 2) << 5 | b >> 3;
+}
+
+/* same chart as the Linux B9B test: 1-px white border, R/G/B/W corners, R|G|B bars, yellow arrow up */
+static void draw_geo(uint16_t *p)
+{
+ const uint16_t R = rgb(255, 0, 0), G = rgb(0, 255, 0), B = rgb(0, 0, 255), Wh = rgb(255, 255, 255), Y = rgb(255, 255, 0);
+ int x, y;
+
+ for (y = 0; y < H; y++)
+ for (x = 0; x < W; x++) {
+ uint16_t c = 0;
+ int ax = x * 2 - 127; /* 2*(x - 63.5) */
+ if (x == 0 || x == W - 1 || y == 0 || y == H - 1)
+ c = Wh;
+ else if (x >= 2 && x < 26 && y >= 2 && y < 26)
+ c = R;
+ else if (x >= W - 26 && x < W - 2 && y >= 2 && y < 26)
+ c = G;
+ else if (x >= 2 && x < 26 && y >= H - 26 && y < H - 2)
+ c = B;
+ else if (x >= W - 26 && x < W - 2 && y >= H - 26 && y < H - 2)
+ c = Wh;
+ else if (y >= 40 && y < 88 && x >= 28 && x < 100)
+ c = (x - 28) < 24 ? R : (x - 28) < 48 ? G : B;
+ else if (y >= 6 && y < 22 && (ax < 0 ? -ax : ax) <= (y - 6))
+ c = Y;
+ else if (y >= 22 && y < 34 && x >= 58 && x < 70)
+ c = Y;
+ p[y * W + x] = c;
+ }
+}
+
+static void log_power(const char *when)
+{
+ /* PM8916 SID1: LDO6 0x4500, LDO17 0x5000 (08 STATUS, 46 EN_CTL); SID0: MPP4 0xa300 (40 MODE, 46 EN, 4c SINK) */
+ LOG("%s: L6 st=%02x en=%02x L17 st=%02x en=%02x vset=%02x MPP4 mode=%02x en=%02x sink=%02x", when,
+ pm8x41_reg_read(0x14508), pm8x41_reg_read(0x14546),
+ pm8x41_reg_read(0x15008), pm8x41_reg_read(0x15046), pm8x41_reg_read(0x15041),
+ pm8x41_reg_read(0xa340), pm8x41_reg_read(0xa346), pm8x41_reg_read(0xa34c));
+}
+
+static void log_hw(const char *when)
+{
+ LOG("%s: TLMM cfg/io 12=%x/%x 13=%x 14=%x 15=%x 116=%x/%x 118=%x/%x QUP4 spi CBCR=%08x RCGR=%08x/%08x", when,
+ readl(TLMM_CFG(12)), readl(TLMM_IO(12)), readl(TLMM_CFG(13)), readl(TLMM_CFG(14)), readl(TLMM_CFG(15)),
+ readl(TLMM_CFG(DC_GPIO)), readl(TLMM_IO(DC_GPIO)), readl(TLMM_CFG(RST_GPIO)), readl(TLMM_IO(RST_GPIO)),
+ readl(CLK_CTL_BASE + 0x501C), readl(CLK_CTL_BASE + 0x5024), readl(CLK_CTL_BASE + 0x5028));
+}
+
+static void aurora_st7735s_init(void)
+{
+ uint16_t *fb;
+ unsigned i, fails = 0;
+ int ret;
+
+ t0 = current_time();
+ LOG("ST7735S bring-up start (stock Aurora parameters)");
+ log_power("before");
+ log_hw("before");
+
+ /* RESET GPIO118: func0 out 8 mA, OE; 1 -> 1 ms -> 0 -> 1 ms -> 1 -> 120 ms (stock target_panel_reset) */
+ gpio_tlmm_config(RST_GPIO, 0, GPIO_OUTPUT, GPIO_NO_PULL, GPIO_8MA, 1);
+ gpio_set_dir(RST_GPIO, 2); mdelay(1);
+ gpio_set_dir(RST_GPIO, 0); mdelay(1);
+ gpio_set_dir(RST_GPIO, 2); mdelay(120);
+ LOG("reset done (GPIO118 high)");
+
+ dev = qup_blsp_spi_init(BLSP_ID_1, QUP_ID_3);
+ if (!dev) {
+ LOG("FAIL: qup_blsp_spi_init(BLSP1, QUP_ID_3)");
+ return;
+ }
+ dev->force_cs_dis = 1; /* stock SPI_IO_CONTROL = 0x401: NO_TRI_STATE | CLK_IDLE_HIGH, CS0, no FORCE_CS */
+ /* D/C GPIO116: func0 out 8 mA, OE (stock) */
+ gpio_tlmm_config(DC_GPIO, 0, GPIO_OUTPUT, GPIO_NO_PULL, GPIO_8MA, 1);
+ gpio_set_dir(DC_GPIO, 2);
+ LOG("QUP4 SPI init done: base=0x%x", dev->qup_base);
+ log_hw("after QUP init");
+
+ for (i = 0; i < sizeof(cmds) / sizeof(cmds[0]); i++) {
+ ret = spi_cmd(cmds[i].d[0]);
+ if (!ret && cmds[i].len > 1)
+ ret = spi_data(&cmds[i].d[1], cmds[i].len - 1);
+ if (ret) {
+ fails++;
+ LOG("cmd %u (0x%02x) FAILED ret=%d", i, cmds[i].d[0], ret);
+ }
+ if (cmds[i].wait)
+ mdelay(cmds[i].wait);
+ }
+ LOG("19 init commands sent, %u failures; SPI_IO_CONTROL=%x SPI_CONFIG=%x", fails,
+ readl(dev->qup_base + SPI_IO_CONTROL), readl(dev->qup_base + SPI_CONFIG));
+
+ fb = memalign(64, W * H * 2);
+ if (!fb) {
+ LOG("FAIL: no memory for frame");
+ return;
+ }
+ draw_geo(fb);
+ ret = spi_frame((const uint8_t *)fb, W * H * 2);
+ LOG("frame %ux%u RGB565 (%u bytes) sent ret=%d (fb @%p)", W, H, W * H * 2, ret, fb);
+
+ /* backlight: PM8916 MPP4 current sink, exactly the stock LK target_backlight_ctrl writes */
+ pm8x41_reg_write(0xa340, 0x61);
+ pm8x41_reg_write(0xa34c, 0x07);
+ pm8x41_reg_write(0xa346, 0x80);
+ mdelay(20);
+ log_power("after backlight");
+ log_hw("end");
+ LOG("ST7735S bring-up end - continuing lk2nd boot");
+}
+LK2ND_INIT(aurora_st7735s_init);
diff --git a/platform/msm8916/acpuclock.c b/platform/msm8916/acpuclock.c
index 158ab395..b7533e6c 100644
--- a/platform/msm8916/acpuclock.c
+++ b/platform/msm8916/acpuclock.c
@@ -529,3 +529,39 @@ void clock_config_blsp_i2c(uint8_t blsp_id, uint8_t qup_id)
return;
}
}
+
+/*
+ * Aurora B9L: SPI core clock, copied from msm8909 acpuclock.c. The CAF spi_qup driver always asks for MAX_SPEED_HZ
+ * (50 MHz, qup.h); the Aurora ST7735S panel runs at 16 MHz in stock LK (gcc_blsp1_qup4_spi_apps_clk = 16000000),
+ * so the rate is clamped here.
+ */
+#define AURORA_SPI_MAX_HZ 16000000
+void clock_config_blsp_spi(uint8_t blsp_id, uint8_t qup_id, unsigned long rate)
+{
+ uint8_t ret = 0;
+ char clk_name[64];
+
+ qup_id = qup_id + 1;
+
+ if (blsp_id != BLSP_ID_1) {
+ dprintf(CRITICAL, "Incorrect BLSP-%d configuration\n", blsp_id);
+ ASSERT(0);
+ }
+ if (rate > AURORA_SPI_MAX_HZ)
+ rate = AURORA_SPI_MAX_HZ;
+
+ snprintf(clk_name, sizeof(clk_name), "blsp1_ahb_iface_clk");
+ ret = clk_get_set_enable(clk_name, 0, 1);
+ if (ret) {
+ dprintf(CRITICAL, "%s: Failed to enable %s clock\n", __func__, clk_name);
+ return;
+ }
+
+ snprintf(clk_name, sizeof(clk_name), "gcc_blsp1_qup%u_spi_apps_clk", qup_id);
+ ret = clk_get_set_enable(clk_name, rate, 1);
+ if (ret) {
+ dprintf(CRITICAL, "%s: Failed to enable %s\n", __func__, clk_name);
+ return;
+ }
+ dprintf(INFO, "B9L: %s enabled at %lu Hz\n", clk_name, rate);
+}
diff --git a/platform/msm8916/gpio.c b/platform/msm8916/gpio.c
index 145b81ce..2912792b 100644
--- a/platform/msm8916/gpio.c
+++ b/platform/msm8916/gpio.c
@@ -26,6 +26,7 @@
* IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
*/
+#include <assert.h>
#include <debug.h>
#include <reg.h>
#include <platform/iomap.h>
@@ -99,3 +100,19 @@ void gpio_config_blsp_i2c(uint8_t blsp_id, uint8_t qup_id)
ASSERT(0);
}
}
+
+/*
+ * Aurora B9L: BLSP1 QUP4 (QUP_ID_3, 0x78b8000) SPI pins as in stock Aurora dtb_01 spi0_active/spi0_cs0_active:
+ * GPIO12 MOSI, GPIO13 MISO, GPIO15 CLK func 1, 12 mA, no pull; GPIO14 CS0 func 1 (native chip select), 2 mA, no pull.
+ */
+void gpio_config_blsp_spi(uint8_t blsp_id, uint8_t qup_id)
+{
+ if (blsp_id != BLSP_ID_1 || qup_id != QUP_ID_3) {
+ dprintf(CRITICAL, "Unsupported BLSP-%d QUP-%d SPI pin configuration\n", blsp_id, qup_id);
+ ASSERT(0);
+ }
+ gpio_tlmm_config(12, 1, GPIO_OUTPUT, GPIO_NO_PULL, GPIO_12MA, GPIO_DISABLE);
+ gpio_tlmm_config(13, 1, GPIO_OUTPUT, GPIO_NO_PULL, GPIO_12MA, GPIO_DISABLE);
+ gpio_tlmm_config(14, 1, GPIO_OUTPUT, GPIO_NO_PULL, GPIO_2MA, GPIO_DISABLE);
+ gpio_tlmm_config(15, 1, GPIO_OUTPUT, GPIO_NO_PULL, GPIO_12MA, GPIO_DISABLE);
+}
diff --git a/platform/msm8916/include/platform/clock.h b/platform/msm8916/include/platform/clock.h
index fab62591..c0f00312 100644
--- a/platform/msm8916/include/platform/clock.h
+++ b/platform/msm8916/include/platform/clock.h
@@ -95,4 +95,5 @@ void gcc_dsi_clocks_disable(uint8_t dual_dsi);
void clock_ce_enable(uint8_t instance);
void clock_ce_disable(uint8_t instance);
void clock_config_blsp_i2c(uint8_t blsp_id, uint8_t qup_id);
+void clock_config_blsp_spi(uint8_t blsp_id, uint8_t qup_id, unsigned long rate);
#endif
diff --git a/platform/msm8916/include/platform/gpio.h b/platform/msm8916/include/platform/gpio.h
index 0437aff4..ec4d5859 100644
--- a/platform/msm8916/include/platform/gpio.h
+++ b/platform/msm8916/include/platform/gpio.h
@@ -70,4 +70,5 @@ void gpio_tlmm_config(uint32_t gpio,
uint8_t drvstr,
uint32_t enable);
void gpio_config_blsp_i2c(uint8_t blsp_id, uint8_t qup_id);
+void gpio_config_blsp_spi(uint8_t blsp_id, uint8_t qup_id);
#endif
diff --git a/platform/msm8916/include/platform/iomap.h b/platform/msm8916/include/platform/iomap.h
index 86a804bb..9e9e09d0 100644
--- a/platform/msm8916/include/platform/iomap.h
+++ b/platform/msm8916/include/platform/iomap.h
@@ -126,6 +126,13 @@
#define GCC_BLSP1_QUP4_APPS_CBCR (CLK_CTL_BASE + 0x5020)
#define GCC_BLSP1_QUP4_CFG_RCGR (CLK_CTL_BASE + 0x5004)
#define GCC_BLSP1_QUP4_CMD_RCGR (CLK_CTL_BASE + 0x5000)
+/* Aurora B9L: BLSP1 QUP4 SPI clock (== msm8909 CAF, == Linux gcc-msm8916 0x5024/0x501c) */
+#define GCC_BLSP1_QUP4_SPI_APPS_CBCR (CLK_CTL_BASE + 0x501C)
+#define GCC_BLSP1_QUP4_SPI_APPS_CMD_RCGR (CLK_CTL_BASE + 0x5024)
+#define GCC_BLSP1_QUP4_SPI_CFG_RCGR (CLK_CTL_BASE + 0x5028)
+#define GCC_BLSP1_QUP4_SPI_APPS_M (CLK_CTL_BASE + 0x502C)
+#define GCC_BLSP1_QUP4_SPI_APPS_N (CLK_CTL_BASE + 0x5030)
+#define GCC_BLSP1_QUP4_SPI_APPS_D (CLK_CTL_BASE + 0x5034)
/* GPLL */
#define GPLL0_STATUS (CLK_CTL_BASE + 0x2101C)
diff --git a/platform/msm8916/msm8916-clock.c b/platform/msm8916/msm8916-clock.c
index a1b4b773..bec650a2 100644
--- a/platform/msm8916/msm8916-clock.c
+++ b/platform/msm8916/msm8916-clock.c
@@ -587,6 +587,45 @@ static struct branch_clk gcc_blsp1_qup4_i2c_apps_clk = {
},
};
+/* Aurora B9L: BLSP1 QUP4 SPI clock, copied from msm8909-clock.c (freq table == Linux gcc-msm8916) */
+static struct clk_freq_tbl ftbl_gcc_blsp1_qup4_spi_apps_clk[] = {
+ F( 960000, cxo, 10, 1, 2),
+ F( 4800000, cxo, 4, 0, 0),
+ F( 9600000, cxo, 2, 0, 0),
+ F( 16000000, gpll0, 10, 1, 5),
+ F( 19200000, cxo, 1, 0, 0),
+ F( 25000000, gpll0, 16, 1, 2),
+ F( 50000000, gpll0, 16, 0, 0),
+ F_END
+};
+
+static struct rcg_clk gcc_blsp1_qup4_spi_apps_clk_src =
+{
+ .cmd_reg = (uint32_t *) GCC_BLSP1_QUP4_SPI_APPS_CMD_RCGR,
+ .cfg_reg = (uint32_t *) GCC_BLSP1_QUP4_SPI_CFG_RCGR,
+ .m_reg = (uint32_t *) GCC_BLSP1_QUP4_SPI_APPS_M,
+ .n_reg = (uint32_t *) GCC_BLSP1_QUP4_SPI_APPS_N,
+ .d_reg = (uint32_t *) GCC_BLSP1_QUP4_SPI_APPS_D,
+ .set_rate = clock_lib2_rcg_set_rate_mnd,
+ .freq_tbl = ftbl_gcc_blsp1_qup4_spi_apps_clk,
+ .current_freq = &rcg_dummy_freq,
+
+ .c = {
+ .dbg_name = "gcc_blsp1_qup4_spi_apps_clk_src",
+ .ops = &clk_ops_rcg,
+ },
+};
+
+static struct branch_clk gcc_blsp1_qup4_spi_apps_clk = {
+ .cbcr_reg = (uint32_t *) GCC_BLSP1_QUP4_SPI_APPS_CBCR,
+ .parent = &gcc_blsp1_qup4_spi_apps_clk_src.c,
+
+ .c = {
+ .dbg_name = "gcc_blsp1_qup4_spi_apps_clk",
+ .ops = &clk_ops_branch,
+ },
+};
+
/* Need different gpll0 source value for CPU clocks */
#undef gpll0_source_val
#define gpll0_source_val 4
@@ -678,6 +717,9 @@ static struct clk_lookup msm_clocks_8916[] =
CLK_LOOKUP("gcc_blsp1_qup2_i2c_apps_clk", gcc_blsp1_qup2_i2c_apps_clk.c),
CLK_LOOKUP("blsp1_qup4_ahb_iface_clk", gcc_blsp1_ahb_clk.c),
+ CLK_LOOKUP("blsp1_ahb_iface_clk", gcc_blsp1_ahb_clk.c), /* Aurora B9L: name used by clock_config_blsp_spi */
+ CLK_LOOKUP("gcc_blsp1_qup4_spi_apps_clk_src", gcc_blsp1_qup4_spi_apps_clk_src.c),
+ CLK_LOOKUP("gcc_blsp1_qup4_spi_apps_clk", gcc_blsp1_qup4_spi_apps_clk.c),
CLK_LOOKUP("gcc_blsp1_qup4_i2c_apps_clk_src", gcc_blsp1_qup4_i2c_apps_clk_src.c),
CLK_LOOKUP("gcc_blsp1_qup4_i2c_apps_clk", gcc_blsp1_qup4_i2c_apps_clk.c),
diff --git a/project/lk2nd-msm8916.mk b/project/lk2nd-msm8916.mk
index 192ae770..88c41f4d 100644
--- a/project/lk2nd-msm8916.mk
+++ b/project/lk2nd-msm8916.mk
@@ -1,3 +1,8 @@
# SPDX-License-Identifier: BSD-3-Clause
TARGET := msm8916
include lk2nd/project/lk2nd.mk
+
+# Aurora B9L (RAM test only): ST7735S SPI panel bring-up module
+ifeq ($(AURORA_SPI_PANEL),1)
+MODULES += lk2nd/aurora
+endif

View file

@ -0,0 +1,24 @@
#!/usr/bin/env python3
"""B9L: convert a 128x128 PNG to the LK splash: RGB565 little-endian u16 (same format as the stock Aurora LK logo
@0x8f64b004), emitted as a C header for lk2nd/aurora. Alpha is composited over black (stop if the image is not 128x128).
Also writes a 2x preview PNG rendered back from the RGB565 data. usage: mk-splash.py in.png out.h preview.png"""
import struct, sys
from PIL import Image
im = Image.open(sys.argv[1])
if im.size != (128, 128):
sys.exit(f'STOP: image is {im.size}, need 128x128')
bg = Image.new('RGBA', im.size, (0, 0, 0, 255))
rgb = Image.alpha_composite(bg, im.convert('RGBA')).convert('RGB')
px = list(rgb.getdata())
words = [(r >> 3) << 11 | (g >> 2) << 5 | b >> 3 for r, g, b in px]
with open(sys.argv[2], 'w') as f:
f.write('/* Generated by b9/b9l/splash/mk-splash.py from %s: 128x128 RGB565 (LE u16 in memory) */\n' % sys.argv[1].split('/')[-1])
f.write('static const uint16_t aurora_splash[128 * 128] = {\n')
for i in range(0, len(words), 12):
f.write('\t' + ', '.join('0x%04x' % w for w in words[i:i + 12]) + ',\n')
f.write('};\n')
prev = Image.new('RGB', (128, 128))
prev.putdata([((w >> 11) * 255 // 31, (w >> 5 & 63) * 255 // 63, (w & 31) * 255 // 31) for w in words])
prev.resize((256, 256), Image.NEAREST).save(sys.argv[3])
open(sys.argv[2] + '.bin', 'wb').write(b''.join(struct.pack('<H', w) for w in words))
print('ok', len(words) * 2, 'bytes')

9
linux/aurora-b9b.config Normal file
View file

@ -0,0 +1,9 @@
# Aurora B9B: delta on top of b8d (bam1 + WCNSS + Wi-Fi). Built-in DRM core + panel-mipi-dbi (SPI ST7735S) + fbdev emulation (/dev/fb0).
# No fbcon, no MSM DRM (panel is SPI, MDP/DSI unused).
CONFIG_LOCALVERSION="-aurora-b9b"
CONFIG_DRM=y
CONFIG_DRM_PANEL_MIPI_DBI=y
CONFIG_DRM_FBDEV_EMULATION=y
CONFIG_FB_DEVICE=y
# CONFIG_FRAMEBUFFER_CONSOLE is not set
# CONFIG_DRM_MSM is not set

8
linux/aurora-b9c.config Normal file
View file

@ -0,0 +1,8 @@
# Aurora B9C: delta on top of b9b (DRM + panel-mipi-dbi + fbdev). Framebuffer console on the ST7735S with a single 6x8 font.
CONFIG_LOCALVERSION="-aurora-b9c"
CONFIG_FRAMEBUFFER_CONSOLE=y
# CONFIG_FRAMEBUFFER_CONSOLE_DEFERRED_TAKEOVER is not set
CONFIG_FONTS=y
CONFIG_FONT_6x8=y
# CONFIG_FONT_8x8 is not set
# CONFIG_FONT_8x16 is not set

View file

@ -0,0 +1,257 @@
// SPDX-License-Identifier: GPL-2.0-only
/*
* Project Aurora — JZ08AU-XPA-7J-R3 (MSM8916, 512 MB, ST7735S SPI panel).
* B9B (RAM test only) = B8B + SPI ST7735S panel (panel-mipi-dbi) + MPP4 backlight. B8B: bam1 + Pronto/WCNSS remoteproc + Iris (no WLAN stack, no NV).
* Base was RAM-BOOT MODEM1: EMMC1 + MPSS remoteproc (native Aurora firmware, rmtfs -r). No BAM-DMUX/WWAN/WCNSS. Everything that could touch
* storage, radios or power management is explicitly disabled.
*
* Hardware facts from stock Aurora dtb_01 (see NOTES.md S2.1/S12):
* console = BLSP1 UART2 serial@78b0000, GPIO4 (TX) / GPIO5 (RX), 115200 8N1.
* RAM size (memory@80000000 reg) is filled in by lk2nd from SMEM.
*/
/dts-v1/;
#include <dt-bindings/gpio/gpio.h>
#include "msm8916-pm8916.dtsi" /* + RPM regulators (USB PHY L7/L13) */
/ {
model = "JZ08AU Aurora (RAM boot B9B)";
compatible = "jz08au,aurora", "qcom,msm8916";
chassis-type = "embedded";
aliases {
serial0 = &blsp_uart2;
mmc0 = &sdhc_1; /* eMMC */
};
chosen {
stdout-path = "serial0:115200n8";
};
/*
* B8B: WCNSS/Pronto carve-out at the stock Aurora address. Stock dtb_01 "peripheral_mem"
* (pronto PIL region) = 0x8b600000 size 0x600000; wcnss.mdt is linked at 0x8b600000.
* Directly follows mpss_mem (0x86800000 + 0x4e00000 = 0x8b600000) -> no overlap.
* Same fixed-address pattern as upstream msm8916-longcheer-l8150.dts.
*/
reserved-memory {
/delete-node/ wcnss;
wcnss_mem: wcnss@8b600000 {
reg = <0x0 0x8b600000 0x0 0x600000>;
no-map;
};
};
};
&blsp_uart2 {
pinctrl-0 = <&blsp_uart2_console_default>;
pinctrl-1 = <&blsp_uart2_console_sleep>;
pinctrl-names = "default", "sleep";
status = "okay";
};
/* --- RAM boot MODEM1 safety: no SD slot, no Wi-Fi, no modem data plane --- */
/* sdhc_1 (eMMC): enabled below, READ-ONLY enforced by initramfs (blockdev --setro) */
&sdhc_2 { status = "disabled"; };
/* usb: see peripheral block below */
/* mpss: enabled below */
&bam_dmux { status = "okay"; }; /* B4b1: data-plane mux driver (no bearer) */
&bam_dmux_dma { status = "okay"; };
/* wcnss: enabled below (B8B) */
/*
* USB peripheral only (ChipIdea ci-hdrc + qcom,usb-hs-phy-msm8916, upstream bindings).
* Stock Aurora: HSUSB_1p8 = L7 1.8 V, HSUSB_3p3 = L13 3.075 V, otg-control = 2 (PMIC VBUS detect),
* PHY init-seq identical to upstream. VBUS detect via PM8916 USB_IN (as on JZ02). No host, no role switch.
*/
&pm8916_usbin {
status = "okay";
};
&usb {
dr_mode = "peripheral";
extcon = <&pm8916_usbin>;
status = "okay";
};
&usb_hs_phy {
extcon = <&pm8916_usbin>;
};
/*
* Internal eMMC (stock: bootdevice=7824900.sdhci, qcom,bus-width 8, nonremovable,
* vdd = 8916_l8 2.85-2.9 V, vdd-io = 8916_l5 1.8 V). Upstream msm8916.dtsi already provides
* bus-width = <8>, non-removable, mmc-ddr-1_8v (no HS200 = conservative), sdc1 pinctrl;
* msm8916-pm8916.dtsi provides vmmc = pm8916_l8, vqmmc = pm8916_l5. Only enable it here.
*/
&sdhc_1 {
status = "okay";
};
/*
* MPSS (modem) remoteproc, native Aurora firmware from the RO-mounted modem FAT.
* mpss_mem: stock Aurora "modem_adsp_region" base 0x86800000 size 78 MiB (0x4e00000);
* Aurora modem.mdt load span 0x86800000..0x8b300000 (75 MiB), same as stock PIL log.
* mba_mem: upstream dynamic 1 MiB. pll-supply (pm8916_l7), cx/mx rpmpd from msm8916(-pm8916).dtsi.
* Driver has auto_boot = false: MSS starts only when rmtfs (-s) requests it.
* BAM-DMUX stays disabled (no data plane at this stage).
*/
&mba_mem {
status = "okay";
};
&mpss_mem {
reg = <0x0 0x86800000 0x0 0x4e00000>;
status = "okay";
};
&mpss {
pinctrl-0 = <&sim_ctrl_default>;
pinctrl-names = "default";
status = "okay";
};
/*
* SIM routing as found on stock Aurora (dtb_01 gpio-leds default-state and live
* Android /sys/kernel/debug/gpio): gpio1 (sim3_switch) high, gpio20 (sim_hotdet),
* gpio22 (sim1_switch), gpio23 (sim2_switch) low. Passive routing only.
*/
&tlmm {
sim_ctrl_default: sim-ctrl-default-state {
sim-low-pins {
pins = "gpio20", "gpio22", "gpio23";
function = "gpio";
bias-disable;
output-low;
};
sim-high-pins {
pins = "gpio1";
function = "gpio";
bias-disable;
output-high;
};
};
};
/*
* B8B: Pronto (WCNSS) remoteproc + Iris RF. Firmware = default "wcnss.mdt" from /firmware/image (RO FAT).
* Supplies come from msm8916-pm8916.dtsi and match stock dtb_01: vddpx/vddxo = L7 1.8 V, vddrfa = S3,
* vddpa = L9 3.3 V, vdddig = L5 1.8 V.
* Iris compatible: stock DT has none (generic qcom,wcnss_wlan + qcom,has-autodetect-xo). Stock voltages exclude
* WCN3660 (vddpa 2.9-3.0 V, vdddig 1.2 V); WCN3620 vs WCN3680 have identical vregs (differ in 48 MHz XO);
* stock Pronto FW caps lack DOT11AC -> WCN3620 (controlled hypothesis, see logs/b8/b8b).
* WLAN/cfg80211/wcn36xx are NOT in this kernel; wcnss_ctrl NV download is expected to fail (no NV in rootfs).
*/
&wcnss {
status = "okay";
};
&wcnss_iris {
compatible = "qcom,wcn3620";
};
/*
* B9B: built-in display, reconstructed from stock Aurora LK (aboot) + stock dtb_01 (logs/b9/b9a/B9A-RESULT.md).
* Panel: ST7735S 128x128 on BLSP1 QUP4 (spi@78b8000), MIPI-DBI type C 4-wire: GPIO12 MOSI, 13 MISO, 14 CS0 (native), 15 CLK;
* D/C = GPIO116 (stock "disp_dc"), RESET = GPIO118 (stock "disp_rst_n"). Stock LK: 16 MHz, SPI mode 3, TX only.
* Supplies per stock dtb_01 qcom,mdss_spi: vdd = 8916_l17 2.85 V, vddio = 8916_l6 1.8 V.
* Init sequence = exact stock 19 commands (firmware file jz08au,aurora-st7735s.bin, without trailing RAMWR).
* GRAM offset X=2 / Y=3 (stock CASET 2..129, RASET 3..130) via panel-timing back porches (panel-mipi-dbi convention).
* Backlight: PM8916 MPP4 current sink 40 mA as in stock LK (MODE_CTL 0x61, SINK_CTL 7, EN_CTL 0x80 when on).
* B9B step 1: backlight is NOT linked to the panel -> stays off (MODE_CTL 0x60) until enabled by hand via sysfs after readback.
*/
&pm8916_rpm_regulators {
pm8916_l17: l17 {
regulator-min-microvolt = <2850000>;
regulator-max-microvolt = <2850000>;
};
};
&tlmm {
/* stock spi0_active: gpio12/13/15 func blsp_spi4 12 mA; spi0_cs0_active: gpio14 func blsp_spi4 2 mA (native CS0) */
blsp_spi4_b9b_default: blsp-spi4-b9b-default-state {
spi-pins {
pins = "gpio12", "gpio13", "gpio15";
function = "blsp_spi4";
drive-strength = <12>;
bias-disable;
};
cs-pins {
pins = "gpio14";
function = "blsp_spi4";
drive-strength = <2>;
bias-disable;
};
};
/* stock pmx_mdss active: gpio116 (D/C) + gpio118 (RESET), func gpio, 8 mA, no bias */
lcd_b9b_default: lcd-b9b-default-state {
pins = "gpio116", "gpio118";
function = "gpio";
drive-strength = <8>;
bias-disable;
};
};
&blsp_spi4 {
pinctrl-0 = <&blsp_spi4_b9b_default>;
pinctrl-1 = <&blsp_spi4_sleep>;
pinctrl-names = "default", "sleep";
status = "okay";
panel@0 {
compatible = "jz08au,aurora-st7735s", "panel-mipi-dbi-spi";
reg = <0>;
spi-max-frequency = <16000000>;
spi-cpol;
spi-cpha;
write-only;
dc-gpios = <&tlmm 116 GPIO_ACTIVE_HIGH>;
reset-gpios = <&tlmm 118 GPIO_ACTIVE_HIGH>; /* mipi-dbi drives 0 = in reset, 1 = run */
pinctrl-0 = <&lcd_b9b_default>;
pinctrl-names = "default";
power-supply = <&pm8916_l17>;
io-supply = <&pm8916_l6>;
format = "r5g6b5";
width-mm = <26>; /* 1.44" diagonal, square */
height-mm = <26>;
panel-timing {
hactive = <128>;
vactive = <128>;
hback-porch = <2>; /* GRAM column offset */
vback-porch = <3>; /* GRAM row offset */
clock-frequency = <0>;
hfront-porch = <0>;
vfront-porch = <0>;
hsync-len = <0>;
vsync-len = <0>;
};
};
};
&pm8916_mpps {
/* MPP4 current sink: mode 6 (sink), source sel 0, SINK_CTL = 7 (40 mA); output-low = sink off at probe */
lcd_bl_mpp4_default: mpp4-sink-state {
pins = "mpp4";
function = "sink";
drive-strength = <7>;
output-low;
};
};
/ {
lcd_backlight: backlight {
compatible = "gpio-backlight";
gpios = <&pm8916_mpps 4 GPIO_ACTIVE_HIGH>;
pinctrl-0 = <&lcd_bl_mpp4_default>;
pinctrl-names = "default";
};
};

106
logs/b9/b9a/B9A-RESULT.md Normal file
View file

@ -0,0 +1,106 @@
# B9A-RESULT — display chain audit (read-only)
Date: 2026-10-03. Board: Aurora JZ08AU-XPA-7J-R3, running B8F (cache `857c9c30`, kernel `7.2.7-aurora-b8d #7`).
Nothing was changed: no kernel/DT build, no eMMC/cache write, no GPIO/regulator/PMIC/SPI writes, no reboot.
The live snapshot only read sysfs/debugfs and PMIC registers (regmap debugfs reads). eMMC write counter = 0.
## Main finding
**This is not a DSI panel and MDP is not used.** The built-in display is a **1.44" 128×128 ST7735S panel on SPI**
(MIPI-DBI type C, 4-wire: SCL/SDA/CS plus a D/C GPIO). It is driven over **BLSP1 QUP4** (`spi@78b8000`, GPIO 12–15).
The backlight is **PM8916 MPP4 used as a 40 mA current sink**.
**Stock LK fully brings the panel up before Linux:** reset, SPI, 19 init commands, a 128×128 "4G LTE" logo built into LK, then backlight.
It happens about 210 ms after LK starts. LK then passes the panel to the kernel as continuous splash
(`mdss_mdp.panel=1:spi:0:qcom,mdss_spi_st7735s_wx144_128x128_cmd`).
Stock LK is therefore an exact reference, and it matches the stock DT byte for byte.
## Table
| Level | Stock | Current Linux | Status |
|---|---|---|---|
| MDP/MDSS | Present (`qcom,mdss_mdp`), used by Android only as a CPU-side fb (`fb0` 128×128, 32 bpp, `memblock-reserve 0x83200000/0xfa0000`). LK writes fb `0x83200000` and copies it over SPI, with no scanout. | `display-subsystem@1a00000` status=disabled, `DRM=n` | **Not needed**: MDP/DSI are not part of the chain |
| DSI | Only `mdss_dsi_sim_video` (simulator) and an empty `mdss_dsi@1a98000`. LK also has a DSI `st7796s_320p` (id 0) that this board never uses. | Disabled | **Not used** |
| "Display controller" = SPI host | BLSP1 QUP4 `0x78b8000`; GPIO12 MOSI, 13 MISO, 14 CS0, 15 CLK (func 1, 12 mA); clock 16 MHz; mode 3 (CPOL=1, CPHA=1); TX only. Kernel: `qcom,mdss_spi` + `mdss_spi_client` @16 MHz. | `spi@78b8000` **status=disabled**, `SPI_QUP=y`, no spi_master, GPIO 12–15 are reset defaults (in, pull-down) | **MISSING (1st point in Linux)** |
| Panel | `st7735s wx144 128x128 command mode spi panel`; in LK `panel_id = 1` is **hardcoded** (no ID read). RGB565 (COLMOD 05), MADCTL `c8` (MY\|MX\|BGR), window col 2..129 / row 3..130. The 19-command init sequence is identical in LK and DT (`b9a-stock-lk.txt` §4). Off: `28`, `10`+120 ms. An alternative `nv3023a_jz05` is in the DT, but LK never selects it. | No panel node, no driver (`DRM_PANEL_MIPI_DBI`/`DRM_ST7735R` not built) | **MISSING** |
| Regulators | Stock kernel: vdd = `8916_l17` 2.85 V, vddio = `8916_l6` 1.8 V. **Stock LK does not touch any regulator** (`target_ldo_ctrl` is a stub; LK has no RPM regulator code). | HW: **L6 ON** (EN 0x80, by SBL/RPM default). **L17 OFF** (EN 0x00, STATUS 0x00). Linux holds neither. | **Open**: is L17 needed for the panel? LK runs without enabling it (see "Open questions") |
| GPIO/reset | RESET = GPIO118 (`disp_rst_n`), D/C = GPIO116 (`disp_dc`), both out, 8 mA. Reset: high 1 ms → low 1 ms → high → 120 ms. No TE, no enable GPIO (LK touches GPIO0 only with OE=0, a CAF leftover). | GPIO116/118: in, pull-down, UNCLAIMED → **panel is held in reset** | **MISSING** |
| Backlight | PM8916 MPP4 current sink: MODE_CTL `0xa340=0x61`, SINK_CTL `0xa34c=0x07` (40 mA), EN `0xa346=0x80`. Turned on after init and the first frame. Android: `qcom,leds-qpnp` MPP4 `lcd-bl` 40 mA (trigger `bkl-trigger`). No PWM/WLED/DCS. | MPP4 regs = 00/00/00 (off), `/sys/class/backlight` empty | **MISSING** |
| DRM/fb | Android: mdss_fb `fb0` (mdssfb_d0000, 128×128, virtual 128×256, 32 bpp). LK: fbcon 16 bpp @`0x83200000`. | `DRM=n`, `FB=n`; no `/dev/dri`, `/dev/fb*`, `/sys/class/drm\|graphics` | **MISSING** |
## Exact chain (stock → what B9 needs)
```
SoC display "controller": BLSP1 QUP4 SPI @0x78b8000 (gcc_blsp1_qup4_spi_apps_clk 16 MHz, mode 3, CS0, GPIO12-15 func1)
→ "DSI host": none. The SPI host itself + D/C GPIO116 = MIPI-DBI type C (4-wire) host
→ panel: ST7735S 128x128 (1.44" "wx144"), GRAM offset (2,3), RGB565, MADCTL 0xc8
→ reset/power: L6 1.8 V on (default) [L17 2.85 V: stock kernel only, LK does not enable it];
GPIO118 1→0 (1 ms)→1, wait 120 ms
→ init: SLPOUT +120 ms, FRMCTR1/2/3, INVCTR 03, PWCTR1-5, VMCTR1 12, GMCTRP1/N1, MADCTL c8, COLMOD 05,
CASET 2..129, RASET 3..130, DISPON, RAMWR (+ 128*128*2 B frame, D/C=1)
→ backlight: PM8916 MPP4 current sink 40 mA (0x61/0x07/0x80), after the first frame
→ framebuffer/DRM: in Linux → SPI device + panel-mipi-dbi (or st7735r) → /dev/dri/card0 (+ /dev/fb0 via fbdev emulation)
```
### First point where things diverge
1. **Across the whole boot path, the first divergence is the bootloader.** Stock LK brings up the panel at ~210 ms.
The current lk1st (msm8916 lk2nd tree) has no SPI-panel code: `mdss_spi.o` is only built for msm8909/msm8952.
So the panel is never initialised, and its RESET stays low because of the SoC pull-down.
2. **Within Linux, the first missing link is the SPI host:** `spi@78b8000` is `status = "disabled"`.
Everything after it is also missing: no panel node and no driver, D/C and RESET GPIOs are not described,
there is no MPP4 backlight, and DRM/FB are off.
MDP/DSI do not belong to this chain, so their being disabled is **not** the problem.
There is no simpledrm/simplefb path: no loader leaves the panel initialised, and an SPI panel has no scanout.
So Linux has to bring the panel up itself, which is what B9 asks for anyway.
## Open questions (do not block B9B)
- **L17**: it is off in hardware, while the stock kernel declares it as panel vdd and stock LK never turns it on.
So either SBL1/RPM turn it on during a stock boot (unlikely: SBL1/RPM are still stock now and L17 is off),
or the panel VDD is fed from another rail. **B9B will settle it** by testing with L17 untouched, exactly like LK.
- **Exact glass model**: LK hardcodes ST7735S and does not read an ID. The vendor DT also has `nv3023a_jz05`.
The cable/glass markings are unknown. A visual check in B9B confirms that the ST7735S init works on this glass.
An ID read (RDDID 04h) is possible later if MISO/SDA can actually be read back (LK runs TX-only).
- **Operator question**: on stock firmware, did the "4G LTE" logo appear on the screen at power-on?
(LK's built-in image: `b9a-stock-lk-embedded-logo-128x128.png`, because the stock `splash` partition is all zeros.)
## Proposed B9B (RAM-only, ONE test) — waiting for GO
**B9B "first light"**: boot the B8F RAM image via RESET-held power-on + `fastboot boot`. Cache B8F and the eMMC are not touched.
- Kernel = `out-b8d` + `DRM=y`, `DRM_PANEL_MIPI_DBI=y`, `DRM_FBDEV_EMULATION=y` (+ the `FB` core it needs).
No fbcon, no MSM DRM.
- DTB = B8B DTB plus:
- `&blsp_spi4 { status = "okay"; cs-gpios = <&tlmm 14 GPIO_ACTIVE_LOW>; }` (upstream style; stock used native CS0).
- `panel@0`: `compatible = "aurora,st7735s-wx144", "panel-mipi-dbi-spi"`, `spi-max-frequency = <16000000>`,
`spi-cpol; spi-cpha`, **`write-only`** (LK is TX-only; without it the driver's `mipi_dbi_poweron_conditional_reset` would read DCS 0Ah back over SPI and might skip init because of a garbage readback), `dc-gpios = <&tlmm 116 GPIO_ACTIVE_HIGH>`, `reset-gpios = <&tlmm 118 GPIO_ACTIVE_LOW>`,
`panel-timing` 128×128 with `hback-porch = 2`, `vback-porch = 3` (the GRAM offset), and `backlight = <&lcd_bl>`.
- `lcd_bl`: `gpio-backlight` on `&pm8916_mpps 4` with pinctrl `function = "sink"`, `drive-strength = <7>`
(40 mA, as in LK).
- **No regulator references** (exactly like stock LK).
- initramfs = B8F + `/lib/firmware/aurora,st7735s-wx144.bin`: the stock 19-command sequence minus RAMWR,
in the panel-mipi-dbi format (SLPOUT, then a 120 ms delay, …, MADCTL c8, COLMOD 05, DISPON).
The driver loads `<compatible[0]>.bin`, and back-porch is used as the GRAM offset (panel-mipi-dbi.c:197, :366-367; checked against the 7.2.7 source).
The driver turns on the backlight right after the init commands; LK does it after the first frame (a small difference, acceptable for B9B).
- Test (read-mostly): check the probe in dmesg, that `/dev/dri/card0` and `/dev/fb0` exist,
and read back MPP4 = 0x61/0x07/0x80 plus GPIO 116/118/12–15.
Then write one static test frame to `/dev/fb0` (colour bars + a corner marker) and **the operator confirms** the image, colours and orientation.
LTE and Wi-Fi must keep working, and eMMC writes must stay 0.
- PASS = a correct image with backlight on, and no LTE/Wi-Fi regressions.
If the screen stays dark or white, the single next variable for B9C is the panel's `power-supply = L17 2.85 V`, as the stock kernel uses.
STOP. B9B only after a separate GO.
## Files
- `b9a-stock-lk.txt` — stock LK: UART evidence, function map, structures, init table, backlight, splash
- `b9a-stock-lk-embedded-logo-128x128.png` — the logo built into stock LK (RGB565 @`0x8f64b004`)
- `b9a-stock-dt.txt` — stock dtb_01 nodes (mdss_mdp + panels, mdss_spi, spi@78b8000, pinctrl, MPP4 LED, L6/L17)
- `b9a-current-dt.txt` — current B8F DTB (dtc) display-related nodes
- `b9a-kconfig.txt` — kernel config audit
- `b9a-linux-display.txt` (+ `.raw.txt`) — live read-only snapshot of the board
- `b9a-backlight.txt` — backlight mechanism
- Scripts `b9/b9a/`: `lk-xref.py`, `lkmem.py`, `disrange.sh`, `decode-panel.py`, `render-lk-logo.py`, `dt-extract.py`,
`b9a-live.sh` (board), `b9a-run.sh` (480s)

9
logs/b9/b9a/SHA256SUMS Normal file
View file

@ -0,0 +1,9 @@
85a5674661774690d7257acda746690483c3c0318b1884235e97c0cc3d9f2ae3 B9A-RESULT.md
ff2b9a9d074d90cad2d48c4965241fcd7b7601046be98873a0a2db4a39786979 b9a-backlight.txt
708223a6cd9fe9e72d9b67e271236bf92ee220885c04690096554c4e321ca596 b9a-current-dt.txt
257d3c5b8217a668a6865cc890ed7811ba4201cc9c0d479413c6df50e426a102 b9a-kconfig.txt
70f8188858b4ba027c75d736c82496851ab2f892d6127aa784cc01a4e5b7ed76 b9a-linux-display.raw.txt
76f4ec786065fce93569acb886596b1a46af1ff23d3a5fa40d8a30a30c78d212 b9a-linux-display.txt
01e42eb8907a05c43bd239d981511b9d2fc5d262e74d2a05099fe2e0d601d5bc b9a-stock-dt.txt
8257fbf87bb06ee137306798a1a4f050e3dcdfd266487b468fd1852c88460341 b9a-stock-lk.txt
71d1d88f0b5d84623d701f95f805d6d4aed15eb9fa2f804e97e0f3609d80b998 b9a-stock-lk-embedded-logo-128x128.png

View file

@ -0,0 +1,42 @@
# B9A — backlight mechanism. READ-ONLY.
## Answer: PM8916 MPP4 used as a constant CURRENT SINK (40 mA) for the LED backlight. On/off only in LK; no PWM, no WLED, no DCS, no GPIO,
## no separate LED-driver IC seen in any stock source.
== Stock LK (bootchain/aboot-analysis/lk.bin, target_backlight_ctrl @0x8f600b54; details in b9a-stock-lk.txt)
pm8x41 MPP struct base = 0xa300 (MPP4), mode byte = 1
write SID0 0xa340 MODE_CTL = 0x61 (mode 6 = current sink <<4, source sel 0, bit0 = 1 'on')
write SID0 0xa34c SINK_CTL = 0x07 (7 -> 40 mA; PM8916 MPP sink steps 5 mA * (n+1))
write SID0 0xa346 EN_CTL = 0x80 (master enable)
mdelay(20)
backlight descriptor: bl_interface_type 1 ("BL_WLED" label), min 1, max 0xfff, pmic 'PMIC_8941' (CAF template values)
Order in LK: panel power/reset -> SPI init -> 19 init cmds (DISPON, RAMWR) -> logo frame -> backlight ON (msm_display_init order:
panel power_func, panel on, then bl_func) -> continuous splash (left on for the kernel).
== Stock Android kernel (dt/dtb_01.dts)
qcom,leds@a300 (compatible qcom,leds-qpnp, label "mpp"):
qcom,led_mpp_4: linux,name "lcd-bl", default-trigger "bkl-trigger", default-state off,
qcom,max-current 40, qcom,current-setting 40 (mA), qcom,id 6 (QPNP_ID_LED_MPP), qcom,mode "manual",
qcom,source-sel 1, qcom,mode-ctrl 0x60 (current sink)
panel: qcom,mdss-spi-bl-pmic-control-type "bl_ctrl_wled", bl-min 1, bl-max 255 -> mdss_fb "lcd-backlight" led triggers "bkl-trigger"
-> lcd-bl (MPP4). No pwm node referenced.
Android sysfs (android/leds.txt): /sys/class/leds/lcd-backlight (mdss_fb_primary) and /sys/class/leds/lcd-bl (leds-qpnp-de736200)
Android userspace: com.qualcomm.display running; ro.sf.lcd_density 114; persist.sys.juzhen.soft.version JZ_MIFI_LCD_COM_20260709.
== Who powers / who sets brightness
- Supply of the LED string: not visible in any stock source (MPP4 only sinks current; anode presumably from VPH_PWR/VBAT — unproven, board-level).
- Enable + "brightness": MPP4 SINK_CTL (5..40 mA, 8 steps) and EN. Stock uses 40 mA fixed. Fine brightness would need MPP4 DTEST/LPG PWM
(not used by stock).
- Order: backlight AFTER panel init + first frame (avoids showing GRAM garbage).
== Current Linux (live, b9a-linux-display.txt)
MPP4: MODE_CTL 00, EN_CTL 00, SINK_CTL 00 -> OFF; /sys/class/backlight empty; /sys/class/leds has no lcd-bl.
DT: pm8916_mpps@a000 present (qcom,pm8916-mpp, gpio-controller, 4 MPPs), no pinctrl state for mpp4, pm8916_pwm disabled.
Kernel: PINCTRL_QCOM_SPMI_PMIC=y, BACKLIGHT_CLASS_DEVICE=y, BACKLIGHT_GPIO=y, LEDS_CLASS=y.
== Upstream mapping (read-only check of /home/q/aurora-kbuild/src)
drivers/pinctrl/qcom/pinctrl-spmi-mpp.c: function "sink" => MODE_CTL mode 6; "drive-strength" written RAW to SINK_CTL (0x4c) -> use 7
for 40 mA; "output-high"/gpio value => MODE_CTL bit0. EN_CTL = master enable. => DT:
&pm8916_mpps { lcd_bl_default: mpp4-state { pins = "mpp4"; function = "sink"; drive-strength = <7>; output-low; }; };
backlight: backlight { compatible = "gpio-backlight"; gpios = <&pm8916_mpps 4 GPIO_ACTIVE_HIGH>; pinctrl... };
This reproduces LK's 0x61/0x07/0x80 exactly when on (to be verified in B9B by reading back the 3 registers).

View file

@ -0,0 +1,182 @@
# B9A current Linux DT (running B8F = cache 857c9c30: DTB b8/b8f/out/aurora-b8f.dtb sha256 cc74b57d..., source linux/dts/msm8916-jz08-aurora-b8b.dts)
# decompiled with dtc; display-relevant nodes only. Read-only.
# aurora-b8f.dtb(dtc):409-413
l6 {
regulator-min-microvolt = <0x1b7740>;
regulator-max-microvolt = <0x1b7740>;
phandle = <0x4e>;
};
# aurora-b8f.dtb(dtc):466-467
l17 {
};
# aurora-b8f.dtb(dtc):1315-1332
blsp-spi4-default-state {
phandle = <0x7d>;
spi-pins {
pins = "gpio12", "gpio13", "gpio15";
function = "blsp_spi4";
drive-strength = <0x0c>;
bias-disable;
};
cs-pins {
pins = "gpio14";
function = "gpio";
drive-strength = <0x10>;
bias-disable;
output-high;
};
};
# aurora-b8f.dtb(dtc):1334-1340
blsp-spi4-sleep-state {
pins = "gpio12", "gpio13", "gpio14", "gpio15";
function = "gpio";
drive-strength = <0x02>;
bias-pull-down;
phandle = <0x7e>;
};
# aurora-b8f.dtb(dtc):1763-1857
display-subsystem@1a00000 {
status = "disabled";
compatible = "qcom,mdss";
reg = <0x1a00000 0x1000 0x1ac8000 0x3000>;
reg-names = "mdss_phys", "vbif_phys";
power-domains = <0x13 0x02>;
clocks = <0x13 0x6d 0x13 0x6e 0x13 0x73>;
clock-names = "iface", "bus", "vsync";
interrupts = <0x00 0x48 0x04>;
resets = <0x13 0x34>;
interrupt-controller;
#interrupt-cells = <0x01>;
#address-cells = <0x01>;
#size-cells = <0x01>;
ranges;
phandle = <0x4a>;
display-controller@1a01000 {
compatible = "qcom,msm8916-mdp5", "qcom,mdp5";
reg = <0x1a01000 0x89000>;
reg-names = "mdp_phys";
interrupt-parent = <0x4a>;
interrupts = <0x00>;
clocks = <0x13 0x6d 0x13 0x6e 0x13 0x71 0x13 0x73>;
clock-names = "iface", "bus", "core", "vsync";
iommus = <0x4b 0x04>;
phandle = <0xc7>;
ports {
#address-cells = <0x01>;
#size-cells = <0x00>;
port@0 {
reg = <0x00>;
endpoint {
remote-endpoint = <0x4c>;
phandle = <0x4f>;
};
};
};
};
dsi@1a98000 {
compatible = "qcom,msm8916-dsi-ctrl", "qcom,mdss-dsi-ctrl";
reg = <0x1a98000 0x25c>;
reg-names = "dsi_ctrl";
interrupt-parent = <0x4a>;
interrupts = <0x04>;
assigned-clocks = <0x13 0x2b 0x13 0x2e>;
assigned-clock-parents = <0x49 0x00 0x49 0x01>;
clocks = <0x13 0x71 0x13 0x6d 0x13 0x6e 0x13 0x6f 0x13 0x72 0x13 0x70>;
clock-names = "mdp_core", "iface", "bus", "byte", "pixel", "core";
phys = <0x49>;
#address-cells = <0x01>;
#size-cells = <0x00>;
vdda-supply = <0x4d>;
vddio-supply = <0x4e>;
phandle = <0xc8>;
ports {
#address-cells = <0x01>;
#size-cells = <0x00>;
port@0 {
reg = <0x00>;
endpoint {
remote-endpoint = <0x4f>;
phandle = <0x4c>;
};
};
port@1 {
reg = <0x01>;
endpoint {
phandle = <0xc9>;
};
};
};
};
phy@1a98300 {
compatible = "qcom,dsi-phy-28nm-lp";
reg = <0x1a98300 0xd4 0x1a98500 0x280 0x1a98780 0x30>;
reg-names = "dsi_pll", "dsi_phy", "dsi_phy_regulator";
#clock-cells = <0x01>;
#phy-cells = <0x00>;
clocks = <0x13 0x6d 0x19>;
clock-names = "iface", "ref";
vddio-supply = <0x4e>;
phandle = <0x49>;
};
};
# aurora-b8f.dtb(dtc):2144-2153
mpps@a000 {
compatible = "qcom,pm8916-mpp", "qcom,spmi-mpp";
reg = <0xa000>;
gpio-controller;
#gpio-cells = <0x02>;
gpio-ranges = <0x55 0x00 0x00 0x04>;
interrupt-controller;
#interrupt-cells = <0x02>;
phandle = <0x55>;
};
# aurora-b8f.dtb(dtc):2174-2179
pwm {
compatible = "qcom,pm8916-pwm";
#pwm-cells = <0x02>;
status = "disabled";
phandle = <0xd3>;
};
# aurora-b8f.dtb(dtc):2569-2584
spi@78b8000 {
compatible = "qcom,spi-qup-v2.2.1";
reg = <0x78b8000 0x500>;
interrupts = <0x00 0x62 0x04>;
clocks = <0x13 0x3f 0x13 0x36>;
clock-names = "core", "iface";
dmas = <0x6c 0x0a 0x6c 0x0b>;
dma-names = "tx", "rx";
pinctrl-names = "default", "sleep";
pinctrl-0 = <0x7d>;
pinctrl-1 = <0x7e>;
#address-cells = <0x01>;
#size-cells = <0x00>;
status = "disabled";
phandle = <0xee>;
};
# search for panel/backlight/framebuffer/simple-framebuffer/mipi-dbi/st7735 strings:
(none)
# live board confirmation: see b9a-linux-display.txt (display-subsystem status=disabled, spi@78b8000 status=disabled, no panel/backlight nodes)

View file

@ -0,0 +1,84 @@
# B9A kernel config audit (READ-ONLY). Running kernel 7.2.7-aurora-b8d #7 (B8F cache 857c9c30).
# config: /home/q/aurora-kbuild/out-b8d/.config sha256 bfe2ac4d0b721600...; Image.gz from out-b8d is a byte-prefix of b8/b8f/out/Image.gz-dtb (verified).
# fragment linux/aurora-b8d.config adds only WLAN/CFG80211/MAC80211/WCN36XX on top of b8b.
# CONFIG_MODULES is not set
# CONFIG_DRM is not set
CONFIG_DRM_MSM (not in .config: not selectable — dependency unmet)
CONFIG_DRM_MSM_MDP5 (not in .config: not selectable — dependency unmet)
CONFIG_DRM_MSM_DSI (not in .config: not selectable — dependency unmet)
CONFIG_DRM_PANEL (not in .config: not selectable — dependency unmet)
CONFIG_DRM_MIPI_DBI (not in .config: not selectable — dependency unmet)
CONFIG_DRM_PANEL_MIPI_DBI (not in .config: not selectable — dependency unmet)
CONFIG_DRM_ST7735R (not in .config: not selectable — dependency unmet)
CONFIG_DRM_SIMPLEDRM (not in .config: not selectable — dependency unmet)
CONFIG_DRM_FBDEV_EMULATION (not in .config: not selectable — dependency unmet)
CONFIG_DRM_CLIENT_SELECTION (not in .config: not selectable — dependency unmet)
CONFIG_DRM_KMS_HELPER (not in .config: not selectable — dependency unmet)
CONFIG_DRM_GEM_DMA_HELPER (not in .config: not selectable — dependency unmet)
# CONFIG_FB is not set
CONFIG_FB_CORE (not in .config: not selectable — dependency unmet)
CONFIG_FB_DEVICE (not in .config: not selectable — dependency unmet)
CONFIG_FB_SIMPLE (not in .config: not selectable — dependency unmet)
CONFIG_SYSFB_SIMPLEFB (not in .config: not selectable — dependency unmet)
# CONFIG_STAGING is not set
CONFIG_FB_TFT (not in .config: not selectable — dependency unmet)
CONFIG_FB_TFT_ST7735R (not in .config: not selectable — dependency unmet)
CONFIG_FRAMEBUFFER_CONSOLE (not in .config: not selectable — dependency unmet)
CONFIG_VT=y
CONFIG_VT_CONSOLE=y
CONFIG_DUMMY_CONSOLE=y
CONFIG_LOGO (not in .config: not selectable — dependency unmet)
CONFIG_SPI=y
CONFIG_SPI_MASTER=y
CONFIG_SPI_QUP=y
CONFIG_SPI_SPIDEV=y
CONFIG_QCOM_BAM_DMA=y
CONFIG_BACKLIGHT_CLASS_DEVICE=y
CONFIG_BACKLIGHT_GPIO=y
CONFIG_BACKLIGHT_PWM=y
CONFIG_BACKLIGHT_QCOM_WLED=y
# CONFIG_BACKLIGHT_LED is not set
CONFIG_LEDS_CLASS=y
CONFIG_LEDS_GPIO=y
CONFIG_LEDS_QCOM_LPG=y
CONFIG_PWM=y
CONFIG_PINCTRL_MSM8916=y
CONFIG_PINCTRL_QCOM_SPMI_PMIC=y
CONFIG_GPIOLIB=y
CONFIG_GPIO_CDEV=y
CONFIG_GPIO_SYSFS (not in .config: not selectable — dependency unmet)
CONFIG_REGULATOR=y
CONFIG_REGULATOR_QCOM_SMD_RPM=y
CONFIG_REGULATOR_FIXED_VOLTAGE=y
CONFIG_COMMON_CLK_QCOM=y
CONFIG_MSM_GCC_8916=y
CONFIG_QCOM_RPMPD=y
CONFIG_IOMMU_SUPPORT=y
CONFIG_QCOM_IOMMU=y
CONFIG_CMA=y
CONFIG_DMA_CMA=y
CONFIG_FW_LOADER=y
CONFIG_DEBUG_FS=y
# Summary
# - DRM=n, FB=n: no DRM core, no fbdev, no framebuffer console -> /dev/dri, /dev/fb*, /sys/class/drm|graphics cannot exist.
# - DRM_MSM (MDP5/DSI) is irrelevant for this board: the panel is NOT on DSI/MDP; it is an SPI (MIPI-DBI type C, 4-wire D/C) panel on BLSP1 QUP4.
# - SPI_QUP=y and SPI_SPIDEV=y already present (controller driver exists; DT node disabled).
# - BACKLIGHT_CLASS_DEVICE=y, BACKLIGHT_GPIO=y, PINCTRL_QCOM_SPMI_PMIC=y present -> MPP4 current-sink + gpio-backlight is buildable without new symbols.
# - Needed for an upstream panel driver: DRM + DRM_PANEL_MIPI_DBI (exact stock init via firmware file) or DRM_ST7735R (okaya,rh128128t; fixed generic init).
# Both select DRM_MIPI_DBI/DRM_KMS_HELPER/DRM_GEM_DMA_HELPER/BACKLIGHT_CLASS_DEVICE; /dev/fb0 additionally needs DRM_FBDEV_EMULATION (+FB).
# - simpledrm/simplefb NOT applicable: no scanout engine and no LK-initialised framebuffer in the current boot chain (SPI panel keeps its own GRAM).
# - CONFIG_MODULES=n -> everything must be built-in.
# Kconfig source facts (kernel tree /home/q/aurora-kbuild/src, 7.2.7):
69:config DRM_PANEL_MIPI_DBI
70- tristate "DRM support for MIPI DBI compatible panels"
71- depends on DRM && SPI
72- select DRM_CLIENT_SELECTION
55:config DRM_ST7735R
56- tristate "DRM support for Sitronix ST7715R/ST7735R display panels"
57- depends on DRM && SPI
58- select DRM_CLIENT_SELECTION
# st7735r.c rh128128t_cfg: 128x128, left_offset=2, top_offset=3, rgb=true -> MADCTL MX|MY|RGB(bit3)=0xc8 (== stock MADCTL c8, == stock CASET 2..129 / RASET 3..130)
# but its init values differ from stock (FRMCTR 01 2c 2d vs 05 3a 3a, INVCTR 07 vs 03, PWCTR1 a2 02 84 vs 62 02 04, VMCTR1 0e vs 12, different gamma).

View file

@ -0,0 +1,166 @@
B9A-LIVE-BEGIN
1334.94 5280.61
JZ08AU Aurora (RAM boot B8B)
Linux (none) 7.2.7-aurora-b8d #7 SMP PREEMPT Sat Oct 3 00:22:35 +06 2026 aarch64 GNU/Linux
earlycon console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init
--- ls /sys/class/drm
ls: /sys/class/drm: No such file or directory
--- ls /sys/class/graphics
ls: /sys/class/graphics: No such file or directory
--- ls /sys/class/backlight
total 0
drwxr-xr-x 2 root root 0 Oct 2 19:47 .
drwxr-xr-x 67 root root 0 Jan 1 1970 ..
--- ls /sys/class/leds
total 0
drwxr-xr-x 2 root root 0 Oct 2 19:47 .
drwxr-xr-x 67 root root 0 Jan 1 1970 ..
lrwxrwxrwx 1 root root 0 Oct 2 19:47 mmc0:: -> ../../devices/platform/soc@0/7824900.mmc/leds/mmc0::
--- ls /sys/class/spi_master
total 0
drwxr-xr-x 2 root root 0 Oct 2 19:47 .
drwxr-xr-x 67 root root 0 Jan 1 1970 ..
--- ls /sys/bus/spi/devices
total 0
drwxr-xr-x 2 root root 0 Oct 2 19:47 .
drwxr-xr-x 4 root root 0 Oct 2 19:47 ..
--- ls /dev/dri
ls: /dev/dri: No such file or directory
--- /dev/fb*
ls: /dev/fb*: No such file or directory
--- dmesg display/spi/backlight
[ 61.077499] [aurora-modem] mmcli -m 0 --simple-connect="apn=internet.beeline.ru,user=beeline,password=***,allowed-auth=pap,ip-type=ipv4"
--- DT nodes (status)
soc@0/display-subsystem@1a00000 status=disabled
soc@0/display-subsystem@1a00000/display-controller@1a01000 status=(none=okay)
soc@0/display-subsystem@1a00000/dsi@1a98000 status=(none=okay)
soc@0/display-subsystem@1a00000/phy@1a98300 status=(none=okay)
soc@0/spi@78b8000 status=disabled
--- DT search panel/backlight/framebuffer nodes
--- DT reserved-memory
#address-cells name smem@86300000
#size-cells ranges tz-apps@86000000
hypervisor@86400000 reserved@86680000 tz@86500000
mba rfsa@867e0000 venus
mpss@86800000 rmtfs@86700000 wcnss@8b600000
--- debugfs gpio (TLMM 12-15 SPI, 116 D/C, 118 RESET; PMIC MPP4)
gpiochip0: 122 GPIOs, parent: platform/1000000.pinctrl, 1000000.pinctrl:
gpio12 : in low func0 2mA pull down
gpio13 : in low func0 2mA pull down
gpio14 : in low func0 2mA pull down
gpio15 : in low func0 2mA pull down
gpio116 : in low func0 2mA pull down
gpio118 : in low func0 2mA pull down
gpiochip1: 4 GPIOs, parent: platform/200f000.spmi:pmic@0:mpps@a000, 200f000.spmi:pmic@0:mpps@a000:
mpp4 : ---
gpiochip2: 4 GPIOs, parent: platform/200f000.spmi:pmic@0:gpio@c000, 200f000.spmi:pmic@0:gpio@c000:
--- pinmux-pins TLMM 12-15,116,118
# /sys/kernel/debug/pinctrl/1000000.pinctrl/pinmux-pins
pin 12 (GPIO_12): UNCLAIMED
pin 13 (GPIO_13): UNCLAIMED
pin 14 (GPIO_14): UNCLAIMED
pin 15 (GPIO_15): UNCLAIMED
pin 116 (GPIO_116): UNCLAIMED
pin 118 (GPIO_118): UNCLAIMED
# /sys/kernel/debug/pinctrl/200f000.spmi:pmic@0:gpio@c000/pinmux-pins
# /sys/kernel/debug/pinctrl/200f000.spmi:pmic@0:mpps@a000/pinmux-pins
--- pinctrl MPP
# /sys/kernel/debug/pinctrl/200f000.spmi:pmic@0:mpps@a000/pinconf-pins
Pin config settings per pin
Format: pin (name): configs
pin 0 (mpp1):
pin 1 (mpp2):
pin 2 (mpp3):
pin 3 (mpp4):
--- regulators
regulator.0 regulator-dummy state= uV= users=5
regulator.1 s3 state=enabled uV=1300000 users=2
regulator.10 l9 state=disabled uV=3300000 users=0
regulator.11 l10 state=disabled uV=0 users=0
regulator.12 l11 state=disabled uV=2950000 users=0
regulator.13 l12 state=disabled uV=1800000 users=0
regulator.14 l13 state=enabled uV=3075000 users=1
regulator.15 l14 state=disabled uV=0 users=0
regulator.16 l15 state=disabled uV=0 users=0
regulator.17 l16 state=disabled uV=0 users=0
regulator.18 l17 state=disabled uV=0 users=0
regulator.19 l18 state=disabled uV=0 users=0
regulator.2 s4 state=enabled uV=1850000 users=3
regulator.3 l1 state=disabled uV=0 users=0
regulator.4 l2 state=enabled uV=1200000 users=1
regulator.5 l4 state=disabled uV=0 users=0
regulator.6 l5 state=enabled uV=1800000 users=2
regulator.7 l6 state=disabled uV=1800000 users=0
regulator.8 l7 state=enabled uV=1800000 users=2
regulator.9 l8 state=enabled uV=2900000 users=1
--- regulator_summary (l6/l17)
regulator use open bypass opmode voltage current min max
l6 0 0 0 unknown 1800mV 0mA 1800mV 1800mV
l17 0 0 0 unknown 0mV 0mA 0mV 0mV
--- regmaps
0-00 4a9000.thermal-sensor-tm
0-01 500000.interconnect
1800000.clock-controller 580000.interconnect
1905000.hwlock b011000.mailbox
400000.interconnect b016000.clock
4a9000.thermal-sensor-srot dummy-syscon@0x0000000001937000
--- PM8916 MPP4 block (0xa300: 04=subtype,08=status,40=MODE_CTL,41=DIG_VIN,42=PULL,46=EN_CTL,4c=SINK_CTL)
# PMIC sid0 0xa304 +2
a304: 11
a305: 04
# PMIC sid0 0xa308 +1
a308: 00
# PMIC sid0 0xa340 +8
a340: 00
a341: 00
a342: 00
a343: 00
a344: 00
a345: 00
a346: 00
a347: 00
# PMIC sid0 0xa34c +1
a34c: 00
--- PM8916 LDO6 (0x4500) / LDO17 (0x5000): 08=STATUS 40/41=VSET 45=MODE 46=EN_CTL
# PMIC sid1 0x4504 +2
4504: 21
4505: 2a
# PMIC sid1 0x4508 +1
4508: 82
# PMIC sid1 0x4540 +2
4540: 00
4541: 04
# PMIC sid1 0x4545 +2
4545: 80
4546: 80
# PMIC sid1 0x5004 +2
5004: 21
5005: 0b
# PMIC sid1 0x5008 +1
5008: 00
# PMIC sid1 0x5040 +2
5040: 00
5041: 58
# PMIC sid1 0x5045 +2
5045: 80
5046: 00
--- PM8916 PWM/LPG 0xbc00 (46=EN_CTL)
# PMIC sid1 0xbc04 +2
bc04: 13
bc05: 0b
# PMIC sid1 0xbc46 +1
bc46: 00
--- clocks (mdss/blsp1_qup4)
gcc_mdss_vsync_clk 0 0 0 19200000 0 0 50000 N deviceless no_connection_id
gcc_mdss_pclk0_clk 0 0 0 19200000 0 0 50000 N deviceless no_connection_id
gcc_mdss_mdp_clk 0 0 0 19200000 0 0 50000 N deviceless no_connection_id
gcc_mdss_esc0_clk 0 0 0 19200000 0 0 50000 N deviceless no_connection_id
gcc_mdss_byte0_clk 0 0 0 19200000 0 0 50000 N deviceless no_connection_id
blsp1_qup4_spi_apps_clk_src 0 0 0 19200000 0 0 50000 N deviceless no_connection_id
gcc_blsp1_qup4_spi_apps_clk 0 0 0 19200000 0 0 50000 N deviceless no_connection_id
gcc_mdss_axi_clk 0 0 0 200000000 0 0 50000 N deviceless no_connection_id
gcc_mdss_ahb_clk 0 0 0 100000000 0 0 50000 N deviceless no_connection_id
gcc_blsp1_ahb_clk 3 4 0 100000000 0 0 50000 Y 78b0000.serial iface
--- eMMC
1117 45 193701 2669 0 0 0 0 0 1168 2669 0 0 0 0 0 0
B9A-LIVE-END

View file

@ -0,0 +1,195 @@
# B9A — current Linux display state (live, READ-ONLY). Board running B8F (cache 857c9c30, kernel 7.2.7-aurora-b8d #7), uptime ~1335 s.
# Collected 2026-10-03 by b9/b9a/b9a-run.sh (480s) -> b9/b9a/b9a-live.sh on board (/tmp, RAM). Raw output: b9a-linux-display.raw.txt.
# Only side effect: debugfs mount check (already mounted). No GPIO/regulator/PMIC/SPI writes. eMMC write counters unchanged (stat col 5 = 0).
== Summary
/sys/class/drm : ABSENT (CONFIG_DRM=n)
/sys/class/graphics : ABSENT (CONFIG_FB=n)
/dev/dri/*, /dev/fb* : ABSENT
/sys/class/backlight : empty
/sys/class/leds : only mmc0::
/sys/class/spi_master : empty (spi@78b8000 status=disabled in DT)
/sys/bus/spi/devices : empty
dmesg display/drm/fb/spi/backlight/panel : no matches (only an unrelated aurora-modem line)
DT: display-subsystem@1a00000 status=disabled (upstream MDP5/DSI nodes inherited, irrelevant), spi@78b8000 status=disabled,
no panel / backlight / framebuffer nodes
TLMM GPIO 12,13,14,15 (SPI), 116 (D/C), 118 (RESET): all "in low func0 2mA pull down" = power-on reset defaults, UNCLAIMED
=> panel RESET line is held LOW by the SoC pull-down (panel kept in reset), no SPI clock.
PM8916 MPP4 (SID0 0xa300): subtype 0x11/0x04 present; MODE_CTL 0xa340=00, EN_CTL 0xa346=00, SINK_CTL 0xa34c=00 => backlight sink OFF
(stock LK writes 0x61 / 0x80 / 0x07).
PM8916 L6 (SID1 0x4500): STATUS 0x4508=0x82 (VREG_OK), EN_CTL 0x4546=0x80 => ON at HW level (1.8 V; Linux: l6 'disabled', 0 users — Linux
did not enable it; it is on by SBL/RPM default)
PM8916 L17 (SID1 0x5000): STATUS 0x5008=0x00, EN_CTL 0x5046=0x00 => OFF at HW level (Linux: l17 'disabled', 0 users, no constraints)
PM8916 LPG/PWM (SID1 0xbc00): EN 0x00 (off, DT node disabled)
Clocks: gcc_blsp1_qup4_spi_apps_clk and all gcc_mdss_* : enable_count 0
== Conclusion: NO part of the display pipeline exists in the current Linux (no controller bound, no panel driver, no backlight device,
no fb/DRM core). The panel itself has also never been initialised in this boot (lk1st does not touch it; RESET is held low).
== Raw snapshot
B9A-LIVE-BEGIN
1334.94 5280.61
JZ08AU Aurora (RAM boot B8B)
Linux (none) 7.2.7-aurora-b8d #7 SMP PREEMPT Sat Oct 3 00:22:35 +06 2026 aarch64 GNU/Linux
earlycon console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init
--- ls /sys/class/drm
ls: /sys/class/drm: No such file or directory
--- ls /sys/class/graphics
ls: /sys/class/graphics: No such file or directory
--- ls /sys/class/backlight
total 0
drwxr-xr-x 2 root root 0 Oct 2 19:47 .
drwxr-xr-x 67 root root 0 Jan 1 1970 ..
--- ls /sys/class/leds
total 0
drwxr-xr-x 2 root root 0 Oct 2 19:47 .
drwxr-xr-x 67 root root 0 Jan 1 1970 ..
lrwxrwxrwx 1 root root 0 Oct 2 19:47 mmc0:: -> ../../devices/platform/soc@0/7824900.mmc/leds/mmc0::
--- ls /sys/class/spi_master
total 0
drwxr-xr-x 2 root root 0 Oct 2 19:47 .
drwxr-xr-x 67 root root 0 Jan 1 1970 ..
--- ls /sys/bus/spi/devices
total 0
drwxr-xr-x 2 root root 0 Oct 2 19:47 .
drwxr-xr-x 4 root root 0 Oct 2 19:47 ..
--- ls /dev/dri
ls: /dev/dri: No such file or directory
--- /dev/fb*
ls: /dev/fb*: No such file or directory
--- dmesg display/spi/backlight
[ 61.077499] [aurora-modem] mmcli -m 0 --simple-connect="apn=internet.beeline.ru,user=beeline,password=***,allowed-auth=pap,ip-type=ipv4"
--- DT nodes (status)
soc@0/display-subsystem@1a00000 status=disabled
soc@0/display-subsystem@1a00000/display-controller@1a01000 status=(none=okay)
soc@0/display-subsystem@1a00000/dsi@1a98000 status=(none=okay)
soc@0/display-subsystem@1a00000/phy@1a98300 status=(none=okay)
soc@0/spi@78b8000 status=disabled
--- DT search panel/backlight/framebuffer nodes
--- DT reserved-memory
#address-cells name smem@86300000
#size-cells ranges tz-apps@86000000
hypervisor@86400000 reserved@86680000 tz@86500000
mba rfsa@867e0000 venus
mpss@86800000 rmtfs@86700000 wcnss@8b600000
--- debugfs gpio (TLMM 12-15 SPI, 116 D/C, 118 RESET; PMIC MPP4)
gpiochip0: 122 GPIOs, parent: platform/1000000.pinctrl, 1000000.pinctrl:
gpio12 : in low func0 2mA pull down
gpio13 : in low func0 2mA pull down
gpio14 : in low func0 2mA pull down
gpio15 : in low func0 2mA pull down
gpio116 : in low func0 2mA pull down
gpio118 : in low func0 2mA pull down
gpiochip1: 4 GPIOs, parent: platform/200f000.spmi:pmic@0:mpps@a000, 200f000.spmi:pmic@0:mpps@a000:
mpp4 : ---
gpiochip2: 4 GPIOs, parent: platform/200f000.spmi:pmic@0:gpio@c000, 200f000.spmi:pmic@0:gpio@c000:
--- pinmux-pins TLMM 12-15,116,118
# /sys/kernel/debug/pinctrl/1000000.pinctrl/pinmux-pins
pin 12 (GPIO_12): UNCLAIMED
pin 13 (GPIO_13): UNCLAIMED
pin 14 (GPIO_14): UNCLAIMED
pin 15 (GPIO_15): UNCLAIMED
pin 116 (GPIO_116): UNCLAIMED
pin 118 (GPIO_118): UNCLAIMED
# /sys/kernel/debug/pinctrl/200f000.spmi:pmic@0:gpio@c000/pinmux-pins
# /sys/kernel/debug/pinctrl/200f000.spmi:pmic@0:mpps@a000/pinmux-pins
--- pinctrl MPP
# /sys/kernel/debug/pinctrl/200f000.spmi:pmic@0:mpps@a000/pinconf-pins
Pin config settings per pin
Format: pin (name): configs
pin 0 (mpp1):
pin 1 (mpp2):
pin 2 (mpp3):
pin 3 (mpp4):
--- regulators
regulator.0 regulator-dummy state= uV= users=5
regulator.1 s3 state=enabled uV=1300000 users=2
regulator.10 l9 state=disabled uV=3300000 users=0
regulator.11 l10 state=disabled uV=0 users=0
regulator.12 l11 state=disabled uV=2950000 users=0
regulator.13 l12 state=disabled uV=1800000 users=0
regulator.14 l13 state=enabled uV=3075000 users=1
regulator.15 l14 state=disabled uV=0 users=0
regulator.16 l15 state=disabled uV=0 users=0
regulator.17 l16 state=disabled uV=0 users=0
regulator.18 l17 state=disabled uV=0 users=0
regulator.19 l18 state=disabled uV=0 users=0
regulator.2 s4 state=enabled uV=1850000 users=3
regulator.3 l1 state=disabled uV=0 users=0
regulator.4 l2 state=enabled uV=1200000 users=1
regulator.5 l4 state=disabled uV=0 users=0
regulator.6 l5 state=enabled uV=1800000 users=2
regulator.7 l6 state=disabled uV=1800000 users=0
regulator.8 l7 state=enabled uV=1800000 users=2
regulator.9 l8 state=enabled uV=2900000 users=1
--- regulator_summary (l6/l17)
regulator use open bypass opmode voltage current min max
l6 0 0 0 unknown 1800mV 0mA 1800mV 1800mV
l17 0 0 0 unknown 0mV 0mA 0mV 0mV
--- regmaps
0-00 4a9000.thermal-sensor-tm
0-01 500000.interconnect
1800000.clock-controller 580000.interconnect
1905000.hwlock b011000.mailbox
400000.interconnect b016000.clock
4a9000.thermal-sensor-srot dummy-syscon@0x0000000001937000
--- PM8916 MPP4 block (0xa300: 04=subtype,08=status,40=MODE_CTL,41=DIG_VIN,42=PULL,46=EN_CTL,4c=SINK_CTL)
# PMIC sid0 0xa304 +2
a304: 11
a305: 04
# PMIC sid0 0xa308 +1
a308: 00
# PMIC sid0 0xa340 +8
a340: 00
a341: 00
a342: 00
a343: 00
a344: 00
a345: 00
a346: 00
a347: 00
# PMIC sid0 0xa34c +1
a34c: 00
--- PM8916 LDO6 (0x4500) / LDO17 (0x5000): 08=STATUS 40/41=VSET 45=MODE 46=EN_CTL
# PMIC sid1 0x4504 +2
4504: 21
4505: 2a
# PMIC sid1 0x4508 +1
4508: 82
# PMIC sid1 0x4540 +2
4540: 00
4541: 04
# PMIC sid1 0x4545 +2
4545: 80
4546: 80
# PMIC sid1 0x5004 +2
5004: 21
5005: 0b
# PMIC sid1 0x5008 +1
5008: 00
# PMIC sid1 0x5040 +2
5040: 00
5041: 58
# PMIC sid1 0x5045 +2
5045: 80
5046: 00
--- PM8916 PWM/LPG 0xbc00 (46=EN_CTL)
# PMIC sid1 0xbc04 +2
bc04: 13
bc05: 0b
# PMIC sid1 0xbc46 +1
bc46: 00
--- clocks (mdss/blsp1_qup4)
gcc_mdss_vsync_clk 0 0 0 19200000 0 0 50000 N deviceless no_connection_id
gcc_mdss_pclk0_clk 0 0 0 19200000 0 0 50000 N deviceless no_connection_id
gcc_mdss_mdp_clk 0 0 0 19200000 0 0 50000 N deviceless no_connection_id
gcc_mdss_esc0_clk 0 0 0 19200000 0 0 50000 N deviceless no_connection_id
gcc_mdss_byte0_clk 0 0 0 19200000 0 0 50000 N deviceless no_connection_id
blsp1_qup4_spi_apps_clk_src 0 0 0 19200000 0 0 50000 N deviceless no_connection_id
gcc_blsp1_qup4_spi_apps_clk 0 0 0 19200000 0 0 50000 N deviceless no_connection_id
gcc_mdss_axi_clk 0 0 0 200000000 0 0 50000 N deviceless no_connection_id
gcc_mdss_ahb_clk 0 0 0 100000000 0 0 50000 N deviceless no_connection_id
gcc_blsp1_ahb_clk 3 4 0 100000000 0 0 50000 Y 78b0000.serial iface
--- eMMC
1117 45 193701 2669 0 0 0 0 0 1168 2669 0 0 0 0 0 0
B9A-LIVE-END

View file

@ -0,0 +1,449 @@
# B9A stock DT display chain (dtb_01 = 512MB MTP board-id 8/0x100, used by stock LK; dtb_00 display nodes are byte-identical, see below)
# source: dt/dtb_01.dts (decompiled stock QCDT from partitions/boot.bin). Read-only extraction by b9/b9a/dt-extract.py
# dt/dtb_01.dts:1183-1354
qcom,mdss_mdp@1a00000 {
compatible = "qcom,mdss_mdp";
reg = <0x1a00000 0x90000 0x1ac8000 0x3000>;
reg-names = "mdp_phys", "vbif_phys";
interrupts = <0x00 0x48 0x00>;
vdd-supply = <0x40>;
qcom,msm-bus,name = "mdss_mdp";
qcom,msm-bus,num-cases = <0x03>;
qcom,msm-bus,num-paths = <0x01>;
qcom,msm-bus,vectors-KBps = <0x16 0x200 0x00 0x00 0x16 0x200 0x00 0x61a800 0x16 0x200 0x00 0x61a800>;
qcom,mdss-ab-factor = <0x01 0x01>;
qcom,mdss-ib-factor = <0x02 0x01>;
qcom,mdss-clk-factor = <0x69 0x64>;
qcom,max-bandwidth-low-kbps = <0x10c8e0>;
qcom,max-bandwidth-high-kbps = <0x10c8e0>;
qcom,mdss-vbif-qos-rt-setting = <0x02 0x02 0x02 0x02>;
qcom,mdss-vbif-qos-nrt-setting = <0x01 0x01 0x01 0x01>;
qcom,mdss-mdp-reg-offset = <0x1000>;
qcom,max-clk-rate = <0x1312d000>;
qcom,mdss-pipe-vig-off = <0x5000>;
qcom,mdss-pipe-rgb-off = <0x15000 0x17000>;
qcom,mdss-pipe-dma-off = <0x25000>;
qcom,mdss-pipe-vig-fetch-id = <0x01>;
qcom,mdss-pipe-rgb-fetch-id = <0x07 0x08>;
qcom,mdss-pipe-dma-fetch-id = <0x04>;
qcom,mdss-pipe-vig-xin-id = <0x00>;
qcom,mdss-pipe-rgb-xin-id = <0x01 0x05>;
qcom,mdss-pipe-dma-xin-id = <0x02>;
qcom,mdss-pipe-vig-clk-ctrl-offsets = <0x2ac 0x00 0x00>;
qcom,mdss-pipe-rgb-clk-ctrl-offsets = <0x2ac 0x04 0x08 0x2b4 0x04 0x08>;
qcom,mdss-pipe-dma-clk-ctrl-offsets = <0x2ac 0x08 0x0c>;
qcom,mdss-smp-data = <0x08 0x2000>;
qcom,mdss-ctl-off = <0x2000 0x2200 0x2400>;
qcom,mdss-mixer-intf-off = <0x45000>;
qcom,mdss-mixer-wb-off = <0x48000>;
qcom,mdss-dspp-off = <0x55000>;
qcom,mdss-pingpong-off = <0x71000>;
qcom,mdss-wb-off = <0x65000 0x65800 0x66000>;
qcom,mdss-intf-off = <0x00 0x6b800>;
qcom,mdss-rot-block-size = <0x40>;
qcom,mdss-wfd-mode = "dedicated";
qcom,mdss-has-non-scalar-rgb;
qcom,mdss-has-decimation;
qcom,mdss-traffic-shaper-enabled;
vdd-cx-supply = <0x41>;
clocks = <0x3d 0xbfb92ed3 0x3d 0x668f51de 0x3d 0x6dc1f8f1 0x3d 0x22f3521f 0x3d 0x32a09f1f>;
clock-names = "iface_clk", "bus_clk", "core_clk_src", "core_clk", "vsync_clk";
qcom,vbif-settings = <0x04 0x01 0xd8 0x707 0x124 0x03>;
qcom,mdp-settings = <0x11e4 0x00 0x65048 0x08 0x65848 0x08 0x66048 0x08>;
qcom,mdss-prefill-outstanding-buffer-bytes = <0x400>;
qcom,mdss-prefill-y-buffer-bytes = <0x00>;
qcom,mdss-prefill-scaler-buffer-lines-bilinear = <0x02>;
qcom,mdss-prefill-scaler-buffer-lines-caf = <0x04>;
qcom,mdss-prefill-post-scaler-buffer-pixels = <0x00>;
qcom,mdss-prefill-pingpong-buffer-pixels = <0x1000>;
qcom,mdss-prefill-fbc-lines = <0x00>;
qcom,mdss-pref-prim-intf = "dsi";
linux,phandle = <0x45>;
phandle = <0x45>;
qcom,mdss_fb_primary {
cell-index = <0x00>;
compatible = "qcom,mdss-fb";
qcom,memblock-reserve = <0x83200000 0xfa0000>;
linux,phandle = <0x44>;
phandle = <0x44>;
};
qcom,mdss_fb_wfd {
cell-index = <0x01>;
compatible = "qcom,mdss-fb";
};
qcom,mdss_dsi_sim_video {
qcom,mdss-dsi-panel-name = "Simulator video mode dsi panel";
qcom,mdss-dsi-panel-controller = <0x42>;
qcom,mdss-dsi-panel-type = "dsi_video_mode";
qcom,mdss-dsi-panel-destination = "display_1";
qcom,mdss-dsi-panel-framerate = <0x3c>;
qcom,mdss-dsi-virtual-channel-id = <0x00>;
qcom,mdss-dsi-stream = <0x00>;
qcom,mdss-dsi-panel-width = <0x280>;
qcom,mdss-dsi-panel-height = <0x1e0>;
qcom,mdss-dsi-h-front-porch = <0x06>;
qcom,mdss-dsi-h-back-porch = <0x06>;
qcom,mdss-dsi-h-pulse-width = <0x02>;
qcom,mdss-dsi-h-sync-skew = <0x00>;
qcom,mdss-dsi-v-back-porch = <0x06>;
qcom,mdss-dsi-v-front-porch = <0x06>;
qcom,mdss-dsi-v-pulse-width = <0x02>;
qcom,mdss-dsi-h-left-border = <0x00>;
qcom,mdss-dsi-h-right-border = <0x00>;
qcom,mdss-dsi-v-top-border = <0x00>;
qcom,mdss-dsi-v-bottom-border = <0x00>;
qcom,mdss-dsi-bpp = <0x18>;
qcom,mdss-dsi-underflow-color = <0xff>;
qcom,mdss-dsi-border-color = <0x00>;
qcom,mdss-dsi-on-command = [32 01 00 00 00 00 02 00 00];
qcom,mdss-dsi-off-command = [22 01 00 00 00 00 02 00 00];
qcom,mdss-dsi-on-command-state = "dsi_lp_mode";
qcom,mdss-dsi-off-command-state = "dsi_lp_mode";
qcom,mdss-dsi-h-sync-pulse = <0x00>;
qcom,mdss-dsi-traffic-mode = "non_burst_sync_event";
qcom,mdss-dsi-bllp-eof-power-mode;
qcom,mdss-dsi-bllp-power-mode;
qcom,mdss-dsi-lane-0-state;
qcom,mdss-dsi-lane-1-state;
qcom,mdss-dsi-lane-2-state;
qcom,mdss-dsi-lane-3-state;
qcom,mdss-dsi-panel-timings = <0x00 0x00 0x00>;
qcom,mdss-dsi-t-clk-post = <0x04>;
qcom,mdss-dsi-t-clk-pre = <0x1b>;
qcom,mdss-dsi-dma-trigger = "trigger_sw";
qcom,mdss-dsi-mdp-trigger = "none";
qcom,mdss-dsi-reset-sequence = <0x01 0x14 0x00 0xc8 0x01 0x14>;
};
qcom,mdss_spi_st7735s_wx144_128x128_cmd {
qcom,mdss-spi-panel-name = "st7735s wx144 128x128 command mode spi panel";
qcom,mdss-spi-panel-destination = "display_1";
qcom,mdss-spi-panel-controller = <0x43>;
qcom,mdss-spi-panel-framerate = <0x14>;
qcom,mdss-spi-panel-width = <0x80>;
qcom,mdss-spi-panel-height = <0x80>;
qcom,mdss-spi-h-front-porch = <0x4f>;
qcom,mdss-spi-h-back-porch = <0x3b>;
qcom,mdss-spi-h-pulse-width = <0x3c>;
qcom,mdss-spi-v-back-porch = <0x0a>;
qcom,mdss-spi-v-front-porch = <0x07>;
qcom,mdss-spi-v-pulse-width = <0x02>;
qcom,mdss-spi-h-left-border = <0x00>;
qcom,mdss-spi-h-right-border = <0x00>;
qcom,mdss-spi-v-top-border = <0x00>;
qcom,mdss-spi-v-bottom-border = <0x00>;
qcom,mdss-spi-bpp = <0x10>;
qcom,mdss-spi-on-command = [78 01 11 00 04 b1 05 3a 3a 00 04 b2 05 3a 3a 00 07 b3 05 3a 3a 05 3a 3a 00 02 b4 03 00 04 c0 62 02 04 00 02 c1 c0 00 03 c2 0d 00 00 03 c3 8d 6a 00 03 c4 8d ee 00 02 c5 12 00 11 e0 03 1b 12 11 3f 3a 32 34 2f 2b 30 3a 00 01 02 05 00 11 e1 03 1b 12 11 32 2f 2a 2f 2e 2c 35 3f 00 00 01 05 00 02 36 c8 00 02 3a 05 00 05 2a 00 02 00 81 00 05 2b 00 03 00 82 00 01 29 00 01 2c];
qcom,mdss-spi-off-command = [00 01 28 78 01 10];
qcom,mdss-spi-bl-min-level = <0x01>;
qcom,mdss-spi-bl-max-level = <0xff>;
qcom,mdss-spi-bl-pmic-control-type = "bl_ctrl_wled";
qcom,mdss-spi-reset-sequence = <0x01 0x01 0x00 0x01 0x01 0x78>;
qcom,cont-splash-enabled;
linux,phandle = <0x48>;
phandle = <0x48>;
};
qcom,mdss_spi_nv3023a_jz05_128x128_cmd {
qcom,mdss-spi-panel-name = "nv3023a jz05 128x128 command mode spi panel";
qcom,mdss-spi-panel-destination = "display_1";
qcom,mdss-spi-panel-controller = <0x43>;
qcom,mdss-spi-panel-framerate = <0x1b>;
qcom,mdss-spi-panel-width = <0x80>;
qcom,mdss-spi-panel-height = <0x80>;
qcom,mdss-spi-h-front-porch = <0x4f>;
qcom,mdss-spi-h-back-porch = <0x3b>;
qcom,mdss-spi-h-pulse-width = <0x3c>;
qcom,mdss-spi-v-back-porch = <0x0a>;
qcom,mdss-spi-v-front-porch = <0x07>;
qcom,mdss-spi-v-pulse-width = <0x02>;
qcom,mdss-spi-h-left-border = <0x00>;
qcom,mdss-spi-h-right-border = <0x00>;
qcom,mdss-spi-v-top-border = <0x00>;
qcom,mdss-spi-v-bottom-border = <0x00>;
qcom,mdss-spi-bpp = <0x10>;
qcom,mdss-spi-on-command = [00 02 ff a5 00 02 3e 09 00 02 3a 65 00 02 82 00 00 02 63 0f 00 02 64 0f 00 02 b4 24 00 02 b5 30 00 02 83 03 00 02 86 04 00 02 87 16 00 02 88 0f 00 02 89 2d 00 02 93 63 00 02 96 81 00 02 c3 10 00 02 e6 00 00 02 99 01 00 02 70 07 00 02 71 15 00 02 72 18 00 02 73 10 00 02 74 17 00 02 75 1b 00 02 76 38 00 02 77 0a 00 02 78 04 00 02 79 3c 00 02 7a 06 00 02 7b 0c 00 02 7c 11 00 02 7d 0b 00 02 7e 08 00 02 7f 12 00 02 a0 0d 00 02 a1 3e 00 02 a2 0b 00 02 a3 0f 00 02 a4 0a 00 02 a5 23 00 02 a6 48 00 02 a7 04 00 02 a8 05 00 02 a9 45 00 02 aa 0a 00 02 ab 12 00 02 ac 0d 00 02 ad 06 00 02 ae 3e 00 02 af 12 00 02 ff 00 78 01 11 00 02 36 88 00 01 21 00 05 2a 00 00 00 7f 00 05 2b 00 00 00 7f 0a 01 29 00 01 2c];
qcom,mdss-spi-off-command = [00 01 28 78 01 10];
qcom,mdss-spi-bl-min-level = <0x01>;
qcom,mdss-spi-bl-max-level = <0xff>;
qcom,mdss-spi-bl-pmic-control-type = "bl_ctrl_wled";
qcom,mdss-spi-reset-sequence = <0x01 0x01 0x00 0x01 0x01 0x14>;
};
};
# dt/dtb_01.dts:1356-1359
qcom,mdss_dsi@1a98000 {
linux,phandle = <0x42>;
phandle = <0x42>;
};
# dt/dtb_01.dts:1361-1399
qcom,mdss_spi {
compatible = "qcom,mdss-spi-display";
label = "mdss spi panel";
qcom,mdss-fb-map = <0x44>;
qcom,mdss-mdp = <0x45>;
vdd-supply = <0x46>;
vddio-supply = <0x47>;
qcom,spi-pref-prim-pan = <0x48>;
pinctrl-names = "mdss_default", "mdss_sleep";
pinctrl-0 = <0x49>;
pinctrl-1 = <0x4a>;
qcom,platform-reset-gpio = <0x4b 0x76 0x00>;
qcom,platform-spi-dc-gpio = <0x4b 0x74 0x00>;
linux,phandle = <0x43>;
phandle = <0x43>;
qcom,panel-supply-entries {
#address-cells = <0x01>;
#size-cells = <0x00>;
qcom,panel-supply-entry@0 {
reg = <0x00>;
qcom,supply-name = "vdd";
qcom,supply-min-voltage = <0x2b7cd0>;
qcom,supply-max-voltage = <0x2b7cd0>;
qcom,supply-enable-load = <0x186a0>;
qcom,supply-disable-load = <0x64>;
};
qcom,panel-supply-entry@1 {
reg = <0x01>;
qcom,supply-name = "vddio";
qcom,supply-min-voltage = <0x1b7740>;
qcom,supply-max-voltage = <0x1b7740>;
qcom,supply-enable-load = <0x186a0>;
qcom,supply-disable-load = <0x64>;
};
};
};
# dt/dtb_01.dts:1401-1437
qcom,mdss_dsi_pll@1a98300 {
label = "MDSS DSI 0 PLL";
cell-index = <0x00>;
#clock-cells = <0x01>;
reg = <0x1a98300 0xd4>;
reg-names = "pll_base";
gdsc-supply = <0x40>;
vddio-supply = <0x47>;
clocks = <0x3d 0xbfb92ed3>;
clock-names = "iface_clk";
clock-rate = <0x00>;
linux,phandle = <0xa7>;
phandle = <0xa7>;
qcom,platform-supply-entries {
#address-cells = <0x01>;
#size-cells = <0x00>;
qcom,platform-supply-entry@0 {
reg = <0x00>;
qcom,supply-name = "gdsc";
qcom,supply-min-voltage = <0x00>;
qcom,supply-max-voltage = <0x00>;
qcom,supply-enable-load = <0x00>;
qcom,supply-disable-load = <0x00>;
};
qcom,platform-supply-entry@1 {
reg = <0x01>;
qcom,supply-name = "vddio";
qcom,supply-min-voltage = <0x1b7740>;
qcom,supply-max-voltage = <0x1b7740>;
qcom,supply-enable-load = <0x186a0>;
qcom,supply-disable-load = <0x64>;
};
};
};
# dt/dtb_01.dts:3487-3506
rpm-regulator-ldoa6 {
compatible = "qcom,rpm-smd-regulator-resource";
qcom,resource-name = "ldoa";
qcom,resource-id = <0x06>;
qcom,regulator-type = <0x00>;
qcom,hpm-min-load = <0x2710>;
status = "okay";
regulator-l6 {
compatible = "qcom,rpm-smd-regulator";
regulator-name = "8916_l6";
qcom,set = <0x03>;
status = "okay";
regulator-min-microvolt = <0x1b7740>;
regulator-max-microvolt = <0x1b7740>;
qcom,init-voltage = <0x1b7740>;
linux,phandle = <0x47>;
phandle = <0x47>;
};
};
# dt/dtb_01.dts:3732-3751
rpm-regulator-ldoa17 {
compatible = "qcom,rpm-smd-regulator-resource";
qcom,resource-name = "ldoa";
qcom,resource-id = <0x11>;
qcom,regulator-type = <0x00>;
qcom,hpm-min-load = <0x2710>;
status = "okay";
regulator-l17 {
compatible = "qcom,rpm-smd-regulator";
regulator-name = "8916_l17";
qcom,set = <0x03>;
status = "okay";
regulator-min-microvolt = <0x2b7cd0>;
regulator-max-microvolt = <0x2b7cd0>;
qcom,init-voltage = <0x2b7cd0>;
linux,phandle = <0x46>;
phandle = <0x46>;
};
};
# dt/dtb_01.dts:4333-4362
spi@78b8000 {
compatible = "qcom,spi-qup-v2";
#address-cells = <0x01>;
#size-cells = <0x00>;
reg-names = "spi_physical", "spi_bam_physical";
reg = <0x78b8000 0x600 0x7884000 0x23000>;
interrupt-names = "spi_irq", "spi_bam_irq";
interrupts = <0x00 0x62 0x00 0x00 0xee 0x00>;
spi-max-frequency = <0x2faf080>;
pinctrl-names = "default", "sleep";
pinctrl-0 = <0xc6 0xc7>;
pinctrl-1 = <0xc8 0xc9>;
clocks = <0x3d 0x8caa5b4f 0x3d 0x80f8722f>;
clock-names = "iface_clk", "core_clk";
qcom,infinite-mode = <0x00>;
qcom,use-bam;
qcom,use-pinctrl;
qcom,ver-reg-exists;
qcom,bam-consumer-pipe-index = <0x0a>;
qcom,bam-producer-pipe-index = <0x0b>;
qcom,master-id = <0x56>;
status = "okay";
qcom,mdss_spi_client {
reg = <0x00>;
compatible = "qcom,mdss-spi-client";
label = "MDSS SPI QUP4 CLIENT";
spi-max-frequency = <0xf42400>;
};
};
# dt/dtb_01.dts:4893-4911
qcom,leds@a300 {
compatible = "qcom,leds-qpnp";
reg = <0xa300 0x100>;
label = "mpp";
status = "okay";
qcom,led_mpp_4 {
label = "mpp";
linux,name = "lcd-bl";
linux,default-trigger = "bkl-trigger";
qcom,default-state = "off";
qcom,max-current = <0x28>;
qcom,current-setting = <0x28>;
qcom,id = <0x06>;
qcom,mode = "manual";
qcom,source-sel = <0x01>;
qcom,mode-ctrl = <0x60>;
};
};
# dt/dtb_01.dts:6017-6029
spi0_active {
qcom,pins = <0xde 0x0c 0xde 0x0d 0xde 0x0f>;
qcom,num-grp-pins = <0x03>;
qcom,pin-func = <0x01>;
label = "spi0-active";
default {
drive-strength = <0x0c>;
bias-disable = <0x00>;
linux,phandle = <0xc6>;
phandle = <0xc6>;
};
};
# dt/dtb_01.dts:6031-6043
spi0_suspend {
qcom,pins = <0xde 0x0c 0xde 0x0d 0xde 0x0f>;
qcom,num-grp-pins = <0x03>;
qcom,pin-func = <0x00>;
label = "spi0-suspend";
sleep {
drive-strength = <0x02>;
bias-pull-down;
linux,phandle = <0xc8>;
phandle = <0xc8>;
};
};
# dt/dtb_01.dts:6045-6057
spi0_cs0_active {
qcom,pins = <0xde 0x0e>;
qcom,num-grp-pins = <0x01>;
qcom,pin-func = <0x01>;
label = "spi0-cs0-active";
cs0_active {
drive-strength = <0x02>;
bias-disable = <0x00>;
linux,phandle = <0xc7>;
phandle = <0xc7>;
};
};
# dt/dtb_01.dts:6059-6071
spi0_cs0_suspend {
qcom,pins = <0xde 0x0e>;
qcom,num-grp-pins = <0x01>;
qcom,pin-func = <0x00>;
label = "spi0-cs0-suspend";
cs0_sleep {
drive-strength = <0x02>;
bias-disable = <0x00>;
linux,phandle = <0xc9>;
phandle = <0xc9>;
};
};
# dt/dtb_01.dts:6389-6410
pmx_mdss {
label = "mdss-pins";
qcom,pin-func = <0x00>;
qcom,num-grp-pins = <0x02>;
qcom,pins = <0xde 0x76 0xde 0x74>;
active {
drive-strength = <0x08>;
bias-disable = <0x00>;
output-high;
linux,phandle = <0x49>;
phandle = <0x49>;
};
suspend {
drive-strength = <0x02>;
bias-pull-down;
output-low;
linux,phandle = <0x4a>;
phandle = <0x4a>;
};
};
# reserved memory / splash
1246: qcom,memblock-reserve = <0x83200000 0xfa0000>;
1324: qcom,cont-splash-enabled;
# dtb_00 vs dtb_01 display-node sha (phandles stripped): identical

View file

@ -0,0 +1,134 @@
# B9A — stock LK (aboot) display analysis. READ-ONLY.
# Source: partitions/aboot.bin (stock backup, ELF, entry 0x8f600000) -> bootchain/aboot-analysis/lk.bin (load seg 0x8f600000+0x530c8),
# lk-arm.dis (objdump). Tools: b9/b9a/lk-xref.py, lkmem.py, disrange.sh, decode-panel.py, render-lk-logo.py.
# NOTE: stock LK is no longer on the eMMC (aboot = lk1st-aurora-autoboot since B5a); this is the saved original.
## VERDICT: YES — stock LK fully brings up the panel before Linux (power/reset, SPI init, 19-cmd init, frame write, backlight),
## at ~210 ms after LK start, and hands it to the kernel as continuous splash (cmdline mdss_mdp.panel=1:spi:0:qcom,mdss_spi_st7735s_wx144_128x128_cmd).
== 1. UART evidence (stock boots, logs/uart/coldboot-20260929-200018.log, preflight-recovery-20260929-201150.log)
20:01:01.630 [0] welcome to lk
20:01:01.630 [10] target_init()
20:01:01.830 [210] Panel power on done
20:01:01.830 [210] Config SPI PANEL.
20:01:02.230 [500] cmdline: console=ttyHSL0,115200,n8 androidboot.console=ttyHSL0 androidboot.hardware=qcom user_debug=31 msm_rtb.filter=0x3F ehci-hcd.park=3 androidboot.bootdevice=7824900.sdhci andro
20:01:46.857 [0] welcome to lk
20:01:46.857 [10] target_init()
20:01:47.057 [210] Panel power on done
20:01:47.057 [210] Config SPI PANEL.
logs/uart/lk2nd-boottest-20260929-203353.log:20:34:56.320 [210] Panel power on done
logs/uart/lk2nd-boottest-20260929-203353.log:20:34:56.320 [210] Config SPI PANEL.
logs/uart/preflight-recovery-20260929-201150.log:20:12:20.096 [210] Panel power on done
logs/uart/preflight-recovery-20260929-201150.log:20:12:20.096 [210] Config SPI PANEL.
logs/uart/preflight-recovery-20260929-201150.log:20:13:09.732 [210] Panel power on done
logs/uart/preflight-recovery-20260929-201150.log:20:13:09.732 [210] Config SPI PANEL.
logs/uart/preflight-recovery-20260929-201150.log:20:19:21.864 [210] Panel power on done
logs/uart/preflight-recovery-20260929-201150.log:20:19:21.864 [210] Config SPI PANEL.
logs/uart/preflight-recovery-20260929-201150.log:20:19:49.496 [210] Panel power on done
logs/uart/preflight-recovery-20260929-201150.log:20:19:49.496 [210] Config SPI PANEL.
logs/uart/preflight-recovery-20260929-201150.log:20:33:24.573 [210] Panel power on done
logs/uart/preflight-recovery-20260929-201150.log:20:33:24.574 [210] Config SPI PANEL.
logs/uart/preflight-recovery-20260929-201150.log:20:33:39.596 [210] Panel power on done
logs/uart/preflight-recovery-20260929-201150.log:20:33:39.596 [210] Config SPI PANEL.
20:01:04.031 [ 0.000000] Node qcom,mdss_fb_primary memblock_reserve memory 83200000-841a0000
20:01:04.231 [ 0.000000] Kernel command line: console=ttyHSL0,115200,n8 androidboot.console=ttyHSL0 androidboot.hardware=qcom user_debug=31 msm_rtb.filter=0x3F ehci-hcd.park=3 androidboot.bootdevice=7824900.sdhci androidboot.emmc=true androidboot.serialno=3
20:01:04.632 [ 0.144515] KPI: Bootloader display count = 23838
20:01:05.834 [ 0.620091] mdss_spi_panel_probe: Ctrl name = mdss spi panel
20:01:05.835 [ 0.620348] mdss_spi_panel_init: Panel Name = st7735s wx144 128x128 command mode spi panel
20:01:05.835 [ 0.620665] mdss_spi_panel_init: Continuous splash enabled
20:01:07.439 [ 4.037439] mdss_fb_register: FrameBuffer[0] 128x128 registered successfully!
Current chain (lk1st-aurora-autoboot, e.g. logs/uart/b7cV1-20261002-195525.log): NO "Panel power on"/"Config SPI PANEL" lines.
lk2nd source: platform/msm_shared/rules.mk builds mdss_spi.o only for PLATFORM msm8909/msm8952; lk2nd/device/2nd/spi-display.c only
re-uses a panel "initialized by previous bootloader" (240x320 fixed). => current msm8916 lk1st has no SPI-panel code at all.
== 2. Function map (stock LK, addresses in 0x8f6xxxxx)
0x8f600eac display init loop -> gcdb_display_init(0x8f616918)(rev, MDP_REV=12, fb_base=0x83200000)
0x8f600f20 oem_panel_select(): panel_id := 1 (HARDCODED, mov r5,#1; str -> 0x8f654408), prints "lcd_id == st7735s spi lcd"
unconditionally (NO ID read over SPI, no ID GPIO). id 0 -> qcom,mdss_dsi_st7796s_320p_video (DSI), id 1 -> st7735s (19 cmds),
id 2 -> qcom,mdss_spi_nv3023a_jz05_128x128_cmd (58 cmds). Aurora stock LK always uses id 1.
0x8f616918 gcdb_display_init(): "SPI panel select and init start", pinfo.type = 13 (SPI_PANEL), power_func=0x8f6165e0, bl_func=0x8f616698
0x8f6165e0 mdss_spi panel power: target_ldo_ctrl(0x8f600e98) then target_panel_reset(0x8f600bb8); prints "Panel power on done"
0x8f600e98 target_ldo_ctrl(): STUB `mov r0,#0; bx lr` -> stock LK switches NO regulator. No RPM 'ldoa'/'smpa' request code in LK at all.
0x8f600bb8 target_panel_reset(enable): (board hw_id 8 MTP) gpio_tlmm_config(0,...,enable=0)+gpio_set(0,HIGH) [CAF enable_gpio leftover,
OE bit 9 = 0 -> GPIO0 not driven], then reset GPIO 118: tlmm_config(118, func0, dir out, nopull, drv=3 (8 mA), OE=1),
set HIGH, then seq pin_state {1,0,1} / sleep {1,1,120} ms => RST high 1 ms, LOW 1 ms, HIGH, wait 120 ms.
(QRD hw_id 11/subtype 4 branch drives TPS65132 on I2C 0x3e — not this board.)
0x8f600b54 target_backlight_ctrl(bl, en): if bl_interface_type != 2 (DCS): PM8916 MPP4 (base 0xa300, SID0):
MODE_CTL(0xa340) = 0x60|1 = 0x61 (current-sink mode, enable), SINK_CTL(0xa34c) = 7 (=40 mA), EN_CTL(0xa346) = en<<7 (0x80);
mdelay(20). No PWM/LPG, no WLED (PM8916 has no WLED; "bl_ctrl_wled" in panel data is a CAF label).
0x8f6107e4 spi_qup_init(blsp=1, qup=3): base = (3+0x78b5)<<12 = 0x078b8000 (BLSP1 QUP4)
0x8f601bc8 BLSP1 QUP4 pinmux: TLMM cfg regs 0x0100c000..0x0100f000 = GPIO12 (MOSI), 13 (MISO), 14 (CS_N), 15 (CLK), func 1
0x8f6019d4 clock_config_blsp_spi: gcc_blsp1_qup4_spi_apps_clk = 16 000 000 Hz (0x00f42400)
0x8f610924 QUP regs: QUP_CONFIG=0x180 (SPI mode, NO_INPUT), SPI_CONFIG(0x300)=0 (INPUT_FIRST=0 -> CPHA=1), SPI_IO_CONTROL(0x304)=0x401
(NO_TRI_STATE|CLK_IDLE_HIGH -> CPOL=1) => SPI mode 3 (spi-qup.c semantics), write-only (TX), native CS0.
0x8f610b6c mdss_spi panel on: D/C GPIO 116 tlmm_config(func0, out, nopull, drv 3, OE); per cmd: D/C LOW + 1 cmd byte (0x8f6109f4),
D/C HIGH + params (0x8f610a80), mdelay(wait). Frame: D/C HIGH, 16-bit words, len = w*h*bpp/8 (0x8f610b00/0x8f610c64).
0x8f61659c display_image_on_screen(): fbcon_clear; fetch splash partition; if no "SPLASH!!" header -> built-in 128x128 RGB565 image
@0x8f64b004 (memcpy 128*128*2 to fb 0x83200000, then SPI flush). Stock splash partition = 10 MiB of zeros (sha in
partitions/SHA256SUMS) => stock shows the built-in "4G LTE" logo (rendered: b9a-stock-lk-embedded-logo-128x128.png).
0x8f60d78c "Continuous splash enabled, keeping panel alive." -> panel left ON for the kernel.
0x8f6166e8 cmdline builder: " mdss_mdp.panel=" + "1:spi:0:" + panel node id.
== 3. Panel data structures (stock LK, panel_id 1)
paneldata @0x8f648288: node 'qcom,mdss_spi_st7735s_wx144_128x128_cmd', controller 'spi:0:', compatible 'qcom,mdss-spi-panel',
interface 10, destination DISPLAY_1, framerate 27 (DT node says 20; irrelevant for a GRAM panel)
resolution @0x8f647e8c: 128 x 128, h fp/bp/pw 79/59/60, v 10/7/2 (porches meaningless for SPI command-mode)
color @0x8f648410: 16 bpp (RGB565), order 0
reset @0x8f6483ec: pin_state {1,0,1,0,0} sleep {1,1,120,0,0} ms, direction 2 (== DT qcom,mdss-spi-reset-sequence <1 1 0 1 1 0x78>)
backlight @0x8f648728: interface 1 (BL_WLED label -> MPP4 path above), min 1, max 0xfff, step 100, pmic ctrl 1, model 'PMIC_8941'
on-commands @0x8f64849c: 19 x {u32 size, u32 ptr, u32 wait, u8 post_tg}, count 19 (pinfo+0xf0/0xf4)
== 4. Init sequence: stock LK vs stock DT (b9/b9a/decode-panel.py)
== stock LK st7735s (0x8f64849c): 19 commands
0 11 SLPOUT wait=120 ms
1 b1 FRMCTR1 05 3a 3a wait=0 ms
2 b2 FRMCTR2 05 3a 3a wait=0 ms
3 b3 FRMCTR3 05 3a 3a 05 3a 3a wait=0 ms
4 b4 INVCTR 03 wait=0 ms
5 c0 PWCTR1 62 02 04 wait=0 ms
6 c1 PWCTR2 c0 wait=0 ms
7 c2 PWCTR3 0d 00 wait=0 ms
8 c3 PWCTR4 8d 6a wait=0 ms
9 c4 PWCTR5 8d ee wait=0 ms
10 c5 VMCTR1 12 wait=0 ms
11 e0 GMCTRP1 03 1b 12 11 3f 3a 32 34 2f 2b 30 3a 00 01 02 05 wait=0 ms
12 e1 GMCTRN1 03 1b 12 11 32 2f 2a 2f 2e 2c 35 3f 00 00 01 05 wait=0 ms
13 36 MADCTL c8 wait=0 ms
14 3a COLMOD 05 wait=0 ms
15 2a CASET 00 02 00 81 wait=0 ms
16 2b RASET 00 03 00 82 wait=0 ms
17 29 DISPON wait=0 ms
18 2c RAMWR wait=0 ms
== stock dtb_01 st7735s on-command: 19 commands
0 11 SLPOUT wait=120 ms
1 b1 FRMCTR1 05 3a 3a wait=0 ms
2 b2 FRMCTR2 05 3a 3a wait=0 ms
3 b3 FRMCTR3 05 3a 3a 05 3a 3a wait=0 ms
4 b4 INVCTR 03 wait=0 ms
5 c0 PWCTR1 62 02 04 wait=0 ms
6 c1 PWCTR2 c0 wait=0 ms
7 c2 PWCTR3 0d 00 wait=0 ms
8 c3 PWCTR4 8d 6a wait=0 ms
9 c4 PWCTR5 8d ee wait=0 ms
10 c5 VMCTR1 12 wait=0 ms
11 e0 GMCTRP1 03 1b 12 11 3f 3a 32 34 2f 2b 30 3a 00 01 02 05 wait=0 ms
12 e1 GMCTRN1 03 1b 12 11 32 2f 2a 2f 2e 2c 35 3f 00 00 01 05 wait=0 ms
13 36 MADCTL c8 wait=0 ms
14 3a COLMOD 05 wait=0 ms
15 2a CASET 00 02 00 81 wait=0 ms
16 2b RASET 00 03 00 82 wait=0 ms
17 29 DISPON wait=0 ms
18 2c RAMWR wait=0 ms
LK == DT (payload+wait): True
== stock dtb_01 st7735s off-command: 2 commands
0 28 DISPOFF wait=0 ms
1 10 SLPIN wait=120 ms
Interpretation: ST7735S (ST7735-family command set; MADCTL 0xc8 = MY|MX|BGR, COLMOD 0x05 = 16 bpp RGB565,
visible window column 2..129, row 3..130 => 128x128 glass on a 132x162 GRAM with offset (2,3)).
== 5. Things stock LK does NOT do
- no regulator control (L17/L6 untouched; whatever SBL1/RPM left on is used)
- no panel ID read (hardcoded id 1)
- no TE GPIO, no DSI, no MDP scanout (SPI panel has own GRAM; fb 0x83200000 is only a CPU-side buffer)
- no PWM brightness (MPP4 sink fixed 40 mA, on/off)

83
logs/b9/b9b/B9B-RESULT.md Normal file
View file

@ -0,0 +1,83 @@
# B9B-RESULT — first light: ST7735S through Linux DRM / MIPI-DBI (RAM-only)
Date: 2026-10-03. **Result: PASS.**
The image was RAM-booted with `fastboot boot` after a RESET-held power-on. Nothing was flashed.
The eMMC cache is still B8F `857c9c30`, and `mmcblk0` writes = 0 for the whole boot.
## Image
| Component | sha256 | Notes |
|---|---|---|
| `b9/b9b/out/aurora-b9b.img` | `46e7a682…` | boot.img v0, golden mm1 cmdline |
| kernel `Image.gz` | `afdddcef…` | `7.2.7-aurora-b9b #8`. b8d plus `DRM`, `DRM_PANEL_MIPI_DBI`, `DRM_FBDEV_EMULATION`, `FB_DEVICE`, and the symbols they select. No fbcon, no MSM DRM (fragment `linux/aurora-b9b.config`). image_size 0x1820000, so the kernel ends at 0x81820000, below the DTB at 0x81e00000. |
| `aurora-b9b.dtb` | `7ca9cc79…` | `linux/dts/msm8916-jz08-aurora-b9b.dts` = B8B plus the display nodes |
| `jz08au,aurora-st7735s.bin` | `58697d4d…` | 121 B. The stock LK 19-command table, with an assert that it equals stock dtb_01; only the trailing RAMWR is dropped. Generated by `b9/b9b/mk-panel-fw.py`. |
| initramfs | `8a97e93b…` | Exact B8F initramfs (`abb3bd67`) plus an overlay: firmware, test frames, `b9b-test.sh` |
The out dir contains the B8F initramfs, which includes the Wi-Fi PSK, so `b9/b9b/out` must never be published.
The logs were scanned for the PSK: none found.
## DT (as used)
- `spi@78b8000` (BLSP1 QUP4): okay. Pinctrl as in stock: GPIO12/13/15 `blsp_spi4` 12 mA, GPIO14 `blsp_spi4` 2 mA (native CS0).
- `panel@0`:
- compatible `jz08au,aurora-st7735s` + `panel-mipi-dbi-spi`; `spi-max-frequency 16000000`; `spi-cpol` + `spi-cpha` (mode 3); `write-only`.
- `dc-gpios` tlmm 116, `reset-gpios` tlmm 118; GPIOs configured as gpio, 8 mA, no bias (stock pmx_mdss).
- `power-supply` = L17 2.85 V, `io-supply` = L6 1.8 V.
- `format "r5g6b5"`; `panel-timing` 128×128 with `hback-porch 2` / `vback-porch 3` (the GRAM offset).
- Backlight: `gpio-backlight` on `pm8916_mpps 4`, pinctrl `function "sink"`, `drive-strength 7`, `output-low`.
It is deliberately not linked to the panel (B9B step split), and is switched only through the kernel driver (sysfs).
## Steps and evidence (logs `ram1/`: `host-actions.txt`, `uart.log`, `state-boot.txt`, `steps.txt`)
1. **fastboot boot:** OK, rc=0. NCM up 11 s later.
2. **Probe:**
- `spi_qup 78b8000.spi: IN:block:16, fifo:64…` at 0.71 s.
- `l17: Bringing 0uV into 2850000-2850000uV`.
- `[drm] Initialized panel-mipi-dbi 1.0.0 for spi0.0 on minor 0` at 1.43 s.
- `panel-mipi-dbi-spi spi0.0: [drm] fb0: panel-mipi-dbid frame buffer device`.
- No display-related errors.
3. **Devices:** `/dev/dri/card0`, `/sys/class/drm/card0-SPI-1`, `/dev/fb0`.
fb0 is 16 bpp, 128×128, stride 256; `/sys/class/backlight/backlight` exists.
4. **Regulators:**
- After boot: L17/L6 opened by `spi0.0-power` / `spi0.0-io` but with use=0, because without fbcon nothing had done a modeset yet.
L17 was physically off (EN 0x00).
- The modeset was triggered the normal way: `echo 0 > /sys/class/graphics/fb0/blank` (fbdev unblank → atomic commit → pipe enable).
After that: L17 **STATUS 0x82, EN 0x80, 2.85 V**, L6 use 1, `gcc_blsp1_qup4_spi_apps_clk` = **16 000 000 Hz**.
GPIO118 high (out of reset), GPIO116 driven.
5. **Frame:** `b9b-test.sh show geo` wrote the RGB565 frame into `/dev/fb0`.
6. **Backlight MPP4** (PMIC reads only; nothing written raw):
| State | 0xa340 MODE | 0xa346 EN | 0xa34c SINK | 0xa341/42/48/4a |
|---|---|---|---|---|
| Before Linux (B9A, reset defaults) | 00 | 00 | 00 | 00 |
| Probe (pinctrl "sink", off) | 60 | 80 | 07 | 00 (unchanged) |
| `bl on` (sysfs bl_power 0, brightness 1) | **61** | **80** | **07** | 00 |
| `bl off` | 60 | 80 | 07 | 00 |
| `bl on` again | 61 | 80 | 07 | 00 |
On = **exactly the stock LK values** (0x61 / 0x07 / 0x80: current sink, 40 mA, enabled).
Off/on control works through the driver.
7. **Operator visual check** (geo chart: white 1-px border, R/G/B/W corners, R|G|B bars, yellow arrow):
**image visible, arrow points up, colours correct, border complete on all 4 sides.**
So 128×128, offset X=2/Y=3, MADCTL `c8` + RGB565 and orientation are all correct with no changes.
8. **LTE/Wi-Fi:** START OK in 62.3 s; `ping -I wwan0 77.88.8.8` 5/5; AP `aurora-b8f` ch6 ENABLED in 66 s; MPSS and WCNSS remoteproc running.
Same boot-time-only messages as B8F (early `wcnss.mdt` -2 before /firmware is mounted, no `regulatory.db`).
9. **eMMC:** `/sys/block/mmcblk0/stat` write fields = 0 at 96 s and at 219 s.
## Differences from stock LK (by design or inherent to the driver)
- The mipi-dbi driver does its own hardware reset (low ≥20 µs, high, 120 ms) and sends SWRESET (0x01) before the firmware commands.
Stock does high 1 ms → low 1 ms → high → 120 ms, with no SWRESET. The init commands, parameters and the 120 ms delay are otherwise identical.
- Linux enables L17/L6 explicitly; stock LK switches no regulators.
- Without fbcon, the fbdev client does not modeset by itself. Pipe enable needs an unblank, or a future DRM/fbdev user.
This matters for B9C/persistent integration: the init script must unblank (or open DRM) at boot.
## Open (not blocking)
- With the backlight on, the panel is off/on via MPP4 only (no dimming; sink 5–40 mA is possible later via drive-strength or an LPG).
- Backlight off was verified by register readback only; the operator visually confirmed "on".
- Autostart (unblank + backlight), panel blanking and suspend are not done yet. **Router stack: not touched.**
STOP — B9B complete, waiting for the next GO.

10
logs/b9/b9b/SHA256SUMS Normal file
View file

@ -0,0 +1,10 @@
0b571177616cf16b7dec19feaa55a8a7ff4935325daaec4d4b8a1b315e150bd5 ./B9B-RESULT.md
e1c577339d830d981229a197879d6a9307755ea60e9900bd26e9c8444396871e ./boot1.console
a039d82f47d8a6263b7db20fb06853b3deb849dff77ee83c53d7d141c5080e59 ./ram1/.a
a54d5eb31dbb832e75c5489b1ee7008bf233a502b89092cabc3cacad161b0c6d ./ram1/host-actions.txt
cc363512e90d041b0a6b79f99de2eda29983a1268b444ff98342aa5c281c55e2 ./ram1/.s
7edb3b16941e63f52513fc2f13127ca5ea0a3cf5b4298a6d6c9b5129844402d9 ./ram1/state-boot.txt
dc948a390a5a29c1faac0250e63b68093036ff786611d12060e57945008b044c ./ram1/steps.txt
4b23f2ae345bf8b2bec8f19033e536138b4433beb5a7f3aaf42c0dcf407ed027 ./ram1/uart.log
71b5fb5c834761fae804e1377fd5f22639cf3a06629e5ded0a21d915dc56c0b4 ./ram1/uartlog-path
bb904287620f59f51fd40ef729cffd48464ce407d72f901933a02957b451b17d ./ram1/.w

View file

@ -0,0 +1,13 @@
20:54:54.067 B9B ram1: waiting for fastboot <EMMC_SERIAL> (power off >= 90 s, then RESET held + battery -> USB)
20:57:44.431 fastboot present
Sending 'boot.img' (24948 KB) OKAY [ 0.787s]
Booting OKAY [ 0.542s]
Finished. Total time: 1.350s
rc=0
20:57:55.799 NCM ping ok
~ # cat /proc/device-tree/model; echo; uname -r; grep -E "START OK|FAIL in|rollb
JZ08AU Aurora (RAM boot B9B)
7.2.7-aurora-b9b
[71.69] === START OK in 62.3s (wwan0 10.45.150.163/29, routes: 10.10.22.3 194.186.191.1 77.88.8.8 1.1.1.1 )
20:59:21.884 wifi: [75.52] === AP ENABLED ssid=aurora-b8f ch=6 pid=2537 in 66.16s
20:59:34.893 state saved (116 lines)

View file

@ -0,0 +1,116 @@
B9B-STATE-BEGIN
96.35 345.00
JZ08AU Aurora (RAM boot B9B)
7.2.7-aurora-b9b
--- regulators
l17 state=disabled uV=2850000 users=0
l6 state=disabled uV=1800000 users=0
l6 0 1 0 unknown 1800mV 0mA 1800mV 1800mV
spi0.0-io 0 0mA 0mV 0mV
l17 0 1 0 unknown 2850mV 0mA 2850mV 2850mV
spi0.0-power 0 0mA 0mV 0mV
--- PMIC L6 (sid1 0x4500) / L17 (0x5000): 08 STATUS, 40/41 VSET, 46 EN
# PMIC sid1 0x4508 +1
4508: 82
# PMIC sid1 0x4540 +2
4540: 00
4541: 04
# PMIC sid1 0x4546 +1
4546: 80
# PMIC sid1 0x5008 +1
5008: 00
# PMIC sid1 0x5040 +2
5040: 00
5041: 58
# PMIC sid1 0x5046 +1
5046: 00
--- MPP4 0xa340..0xa34f (40 MODE,41 VIN,42 PULL,46 EN,48 AOUT,4a AIN,4c SINK)
# PMIC sid0 0xa340 +16
a340: 60
a341: 00
a342: 00
a343: 00
a344: 00
a345: 00
a346: 80
a347: 00
a348: 00
a349: 00
a34a: 00
a34b: 00
a34c: 07
a34d: 00
a34e: 00
a34f: 00
--- dmesg
[ 0.000000] psci: PSCIv1.0 detected in firmware.
[ 0.000000] psci: [Firmware Bug]: failed to set PC mode: -3
[ 0.397114] qcom_scm firmware:scm: SHM Bridge not supported
[ 0.401809] qcom_scm firmware:scm: qseecom: found qseecom with version 0x800000
[ 0.406963] qcom_scm firmware:scm: qseecom: untested machine, skipping
[ 0.709853] spi_qup 78b8000.spi: IN:block:16, fifo:64, OUT:block:16, fifo:64
[ 0.996260] qcom-wcnss-pil a204000.remoteproc: supply vddcx not found, using dummy regulator
[ 1.007264] a204000.remoteproc.iris: failed to get regulators
[ 1.048298] qcom-wcnss-pil a204000.remoteproc: supply vddcx not found, using dummy regulator
[ 1.051116] l17: Bringing 0uV into 2850000-2850000uV
[ 1.419418] remoteproc remoteproc1: Direct firmware load for wcnss.mdt failed with error -2
[ 1.430342] remoteproc remoteproc1: Direct firmware load for wcnss.mdt failed with error -2
[ 1.430518] [drm] Initialized panel-mipi-dbi 1.0.0 for spi0.0 on minor 0
[ 1.436520] remoteproc remoteproc1: request_firmware failed: -2
[ 1.452334] panel-mipi-dbi-spi spi0.0: [drm] fb0: panel-mipi-dbid frame buffer device
[ 1.460144] cfg80211: Loading compiled-in X.509 certificates for regulatory database
[ 1.485907] faux_driver regulatory: Direct firmware load for regulatory.db failed with error -2
[ 1.489931] cfg80211: failed to load regulatory.db
[ 7.154116] [init] B1: modem FAT mounted RO at /firmware, firmware path /firmware/image
[ 74.564849] wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO' and CRM version 'CNSS-PR-1-4-2-c4-00084'
[ 74.564953] wcn36xx: firmware API 1.5.1.2, 41 stations, 2 bssids
[ 74.617786] [aurora-wifi] wlan0 up addr=<MAC> (wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO')
--- devices
crw------- 1 root root 29, 0 Oct 2 20:58 /dev/fb0
/dev/dri:
total 0
drwxr-xr-x 3 root root 80 Oct 2 20:58 .
drwxr-xr-x 11 root root 4220 Oct 2 20:58 ..
drwxr-xr-x 2 root root 60 Oct 2 20:58 by-path
crw------- 1 root root 226, 0 Oct 2 20:58 card0
/sys/bus/spi/devices:
spi0.0
/sys/class/backlight:
backlight
/sys/class/drm:
card0 card0-SPI-1 version
/sys/class/graphics:
fb0
fb0 name=panel-mipi-dbid
fb0 bits_per_pixel=16
fb0 virtual_size=128,128
fb0 stride=256
backlight bl_power=4
backlight brightness=1
backlight actual_brightness=1
backlight max_brightness=1
--- gpio
gpio12 : in low func1 12mA no pull
gpio13 : in low func1 12mA no pull
gpio14 : in high func1 2mA no pull
gpio15 : in low func1 12mA no pull
gpio116 : out low func0 8mA no pull
gpio118 : out high func0 8mA no pull
mpp4 : out sink vin-0 0 low
pin 12 (GPIO_12): device 78b8000.spi function blsp_spi4 group gpio12
pin 13 (GPIO_13): device 78b8000.spi function blsp_spi4 group gpio13
pin 14 (GPIO_14): device 78b8000.spi function blsp_spi4 group gpio14
pin 15 (GPIO_15): device 78b8000.spi function blsp_spi4 group gpio15
pin 116 (GPIO_116): device spi0.0 function gpio group gpio116
pin 118 (GPIO_118): device spi0.0 function gpio group gpio118
pin 3 (mpp4):
--- clk
blsp1_qup4_spi_apps_clk_src 0 0 0 19200000 0 0 50000 N deviceless no_connection_id
gcc_blsp1_qup4_spi_apps_clk 0 0 0 19200000 0 0 50000 N 78b8000.spi core
--- emmc
1119 43 193701 2473 0 0 0 0 0 1176 2473 0 0 0 0 0 0
B9B-STATE-END

239
logs/b9/b9b/ram1/steps.txt Normal file
View file

@ -0,0 +1,239 @@
=== 20:59:59 $ echo 0 > /sys/class/graphics/fb0/blank; echo rc=$?; dmesg | tail -5
<EFBFBD><EFBFBD><01><><1F><><01><>
BusyBox v1.37.0 (Debian 1:1.37.0-6+b9) built-in shell (ash)
Enter 'help' for a list of built-in commands.
rc=0
[ 74.564953] wcn36xx: firmware API 1.5.1.2, 41 stations, 2 bssids
[ 74.617786] [aurora-wifi] wlan0 up addr=<MAC> (wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO')
[ 75.668381] [aurora-wifi] === AP ENABLED ssid=aurora-b8f ch=6 pid=2537 in 66.16s
[ 87.277311] [aurora-modem] SNTP check ( 89.109.251.21 89.109.251.22 89.109.251.23): 14 replies; best offset delay server: +0.972631 0.056675 89.109.251.21: (offset > 0 = clock behind)
[ 87.281956] [aurora-modem] SNTP: |offset| < 1s - clock kept (no slew: STA_UNSYNC stays, RTC_SYSTOHC never engages)
~ # === 21:00:03 $ /usr/libexec/aurora/b9b/b9b-test.sh state
<EFBFBD><EFBFBD><01><><1F><><01><>
BusyBox v1.37.0 (Debian 1:1.37.0-6+b9) built-in shell (ash)
Enter 'help' for a list of built-in commands.
B9B-STATE-BEGIN
138.29 511.71
JZ08AU Aurora (RAM boot B9B)
7.2.7-aurora-b9b
--- regulators
l17 state=enabled uV=2850000 users=1
l6 state=enabled uV=1800000 users=1
l6 1 1 0 unknown 1800mV 0mA 1800mV 1800mV
spi0.0-io 1 0mA 0mV 0mV
l17 1 1 0 unknown 2850mV 0mA 2850mV 2850mV
spi0.0-power 1 0mA 0mV 0mV
--- PMIC L6 (sid1 0x4500) / L17 (0x5000): 08 STATUS, 40/41 VSET, 46 EN
# PMIC sid1 0x4508 +1
4508: 82
# PMIC sid1 0x4540 +2
4540: 00
4541: 04
# PMIC sid1 0x4546 +1
4546: 80
# PMIC sid1 0x5008 +1
5008: 82
# PMIC sid1 0x5040 +2
5040: 00
5041: 58
# PMIC sid1 0x5046 +1
5046: 80
--- MPP4 0xa340..0xa34f (40 MODE,41 VIN,42 PULL,46 EN,48 AOUT,4a AIN,4c SINK)
# PMIC sid0 0xa340 +16
a340: 60
a341: 00
a342: 00
a343: 00
a344: 00
a345: 00
a346: 80
a347: 00
a348: 00
a349: 00
a34a: 00
a34b: 00
a34c: 07
a34d: 00
a34e: 00
a34f: 00
--- dmesg
[ 0.000000] psci: PSCIv1.0 detected in firmware.
[ 0.000000] psci: [Firmware Bug]: failed to set PC mode: -3
[ 0.397114] qcom_scm firmware:scm: SHM Bridge not supported
[ 0.401809] qcom_scm firmware:scm: qseecom: found qseecom with version 0x800000
[ 0.406963] qcom_scm firmware:scm: qseecom: untested machine, skipping
[ 0.709853] spi_qup 78b8000.spi: IN:block:16, fifo:64, OUT:block:16, fifo:64
[ 0.996260] qcom-wcnss-pil a204000.remoteproc: supply vddcx not found, using dummy regulator
[ 1.007264] a204000.remoteproc.iris: failed to get regulators
[ 1.048298] qcom-wcnss-pil a204000.remoteproc: supply vddcx not found, using dummy regulator
[ 1.051116] l17: Bringing 0uV into 2850000-2850000uV
[ 1.419418] remoteproc remoteproc1: Direct firmware load for wcnss.mdt failed with error -2
[ 1.430342] remoteproc remoteproc1: Direct firmware load for wcnss.mdt failed with error -2
[ 1.430518] [drm] Initialized panel-mipi-dbi 1.0.0 for spi0.0 on minor 0
[ 1.436520] remoteproc remoteproc1: request_firmware failed: -2
[ 1.452334] panel-mipi-dbi-spi spi0.0: [drm] fb0: panel-mipi-dbid frame buffer device
[ 1.460144] cfg80211: Loading compiled-in X.509 certificates for regulatory database
[ 1.485907] faux_driver regulatory: Direct firmware load for regulatory.db failed with error -2
[ 1.489931] cfg80211: failed to load regulatory.db
[ 7.154116] [init] B1: modem FAT mounted RO at /firmware, firmware path /firmware/image
[ 74.564849] wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO' and CRM version 'CNSS-PR-1-4-2-c4-00084'
[ 74.564953] wcn36xx: firmware API 1.5.1.2, 41 stations, 2 bssids
[ 74.617786] [aurora-wifi] wlan0 up addr=<MAC> (wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO')
--- devices
crw------- 1 root root 29, 0 Oct 2 20:58 /dev/fb0
/dev/dri:
total 0
drwxr-xr-x 3 root root 80 Oct 2 20:58 .
drwxr-xr-x 11 root root 4220 Oct 2 20:58 ..
drwxr-xr-x 2 root root 60 Oct 2 20:58 by-path
crw------- 1 root root 226, 0 Oct 2 20:58 card0
/sys/bus/spi/devices:
spi0.0
/sys/class/backlight:
backlight
/sys/class/drm:
card0 card0-SPI-1 version
/sys/class/graphics:
fb0
fb0 name=panel-mipi-dbid
fb0 bits_per_pixel=16
fb0 virtual_size=128,128
fb0 stride=256
backlight bl_power=4
backlight brightness=1
backlight actual_brightness=1
backlight max_brightness=1
--- gpio
gpio12 : in low func1 12mA no pull
gpio13 : in low func1 12mA no pull
gpio14 : in high func1 2mA no pull
gpio15 : in high func1 12mA no pull
gpio116 : out high func0 8mA no pull
gpio118 : out high func0 8mA no pull
mpp4 : out sink vin-0 0 low
pin 12 (GPIO_12): device 78b8000.spi function blsp_spi4 group gpio12
pin 13 (GPIO_13): device 78b8000.spi function blsp_spi4 group gpio13
pin 14 (GPIO_14): device 78b8000.spi function blsp_spi4 group gpio14
pin 15 (GPIO_15): device 78b8000.spi function blsp_spi4 group gpio15
pin 116 (GPIO_116): device spi0.0 function gpio group gpio116
pin 118 (GPIO_118): device spi0.0 function gpio group gpio118
pin 3 (mpp4):
--- clk
blsp1_qup4_spi_apps_clk_src 0 0 0 16000000 0 0 60000 N deviceless no_connection_id
gcc_blsp1_qup4_spi_apps_clk 0 0 0 16000000 0 0 50000 N 78b8000.spi core
--- emmc
1119 43 193701 2473 0 0 0 0 0 1176 2473 0 0 0 0 0 0
B9B-STATE-END
~ # === 21:00:24 $ /usr/libexec/aurora/b9b/b9b-test.sh show geo; dmesg | grep -iE "drm|panel|spi|mipi" | tail -3
<EFBFBD><EFBFBD><01><><1F><><01><>
BusyBox v1.37.0 (Debian 1:1.37.0-6+b9) built-in shell (ash)
Enter 'help' for a list of built-in commands.
i|mipi" | tail -3
SHOW geo (16 bpp) OK
[ 0.709853] spi_qup 78b8000.spi: IN:block:16, fifo:64, OUT:block:16, fifo:64
[ 1.430518] [drm] Initialized panel-mipi-dbi 1.0.0 for spi0.0 on minor 0
[ 1.452334] panel-mipi-dbi-spi spi0.0: [drm] fb0: panel-mipi-dbid frame buffer device
~ # === 21:00:28 $ /usr/libexec/aurora/b9b/b9b-test.sh bl on
<EFBFBD><EFBFBD><01><><1F><><01><>
BusyBox v1.37.0 (Debian 1:1.37.0-6+b9) built-in shell (ash)
Enter 'help' for a list of built-in commands.
backlight bl_power=0
backlight brightness=1
backlight actual_brightness=1
backlight max_brightness=1
--- MPP4 0xa340..0xa34f (40 MODE,41 VIN,42 PULL,46 EN,48 AOUT,4a AIN,4c SINK)
# PMIC sid0 0xa340 +16
a340: 61
a341: 00
a342: 00
a343: 00
a344: 00
a345: 00
a346: 80
a347: 00
a348: 00
a349: 00
a34a: 00
a34b: 00
a34c: 07
a34d: 00
a34e: 00
a34f: 00
~ # === 21:01:10 $ /usr/libexec/aurora/b9b/b9b-test.sh bl off
<EFBFBD><EFBFBD><01><><1F><><01><>
BusyBox v1.37.0 (Debian 1:1.37.0-6+b9) built-in shell (ash)
Enter 'help' for a list of built-in commands.
backlight bl_power=0
backlight brightness=0
backlight actual_brightness=0
backlight max_brightness=1
--- MPP4 0xa340..0xa34f (40 MODE,41 VIN,42 PULL,46 EN,48 AOUT,4a AIN,4c SINK)
# PMIC sid0 0xa340 +16
a340: 60
a341: 00
a342: 00
a343: 00
a344: 00
a345: 00
a346: 80
a347: 00
a348: 00
a349: 00
a34a: 00
a34b: 00
a34c: 07
a34d: 00
a34e: 00
a34f: 00
~ # === 21:01:15 $ /usr/libexec/aurora/b9b/b9b-test.sh bl on
<EFBFBD><EFBFBD><01><><1F><><01><>
BusyBox v1.37.0 (Debian 1:1.37.0-6+b9) built-in shell (ash)
Enter 'help' for a list of built-in commands.
backlight bl_power=0
backlight brightness=1
backlight actual_brightness=1
backlight max_brightness=1
--- MPP4 0xa340..0xa34f (40 MODE,41 VIN,42 PULL,46 EN,48 AOUT,4a AIN,4c SINK)
# PMIC sid0 0xa340 +16
a340: 61
a341: 00
a342: 00
a343: 00
a344: 00
a345: 00
a346: 80
a347: 00
a348: 00
a349: 00
a34a: 00
a34b: 00
a34c: 07
a34d: 00
a34e: 00
a34f: 00
~ # === 21:01:20 $ ping -c5 -W3 -I wwan0 77.88.8.8 | tail -2; /etc/init.d/aurora-wifi status | tail -3; iw dev wlan0 info | grep -E "ssid|type|channel"; for r in /sys/class/remoteproc/*; do echo RP $(cat $r/name)=$(cat $r/state); done; cat /sys/block/mmcblk0/stat; dmesg | grep -ciE "error|fail" ; dmesg | grep -iE "drm|panel|mipi|spi0|backlight" | grep -iE "err|fail|warn"; cat /proc/uptime
<EFBFBD><EFBFBD><01><><1F><><01><>
BusyBox v1.37.0 (Debian 1:1.37.0-6+b9) built-in shell (ash)
Enter 'help' for a list of built-in commands.
tail -3; iw dev wlan0 info | grep -E "ssid|type|channel"; for r in /sys/class/re
moteproc/*; do echo RP $(cat $r/name)=$(cat $r/state); done; cat /sys/block/mmcb
lk0/stat; dmesg | grep -ciE "error|fail" ; dmesg | grep -iE "drm|panel|mipi|spi0
|backlight" | grep -iE "err|fail|warn"; cat /proc/uptime
5 packets transmitted, 5 packets received, 0% packet loss
round-trip min/avg/max = 52.104/83.332/194.048 ms
[72.41] WCNSS /sys/class/remoteproc/remoteproc1 state=running
[74.47] wlan0 up addr=<MAC> (wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO')
[75.52] === AP ENABLED ssid=aurora-b8f ch=6 pid=2537 in 66.16s
ssid aurora-b8f
type AP
channel 6 (2437 MHz), width: 20 MHz, center1: 2437 MHz
RP 4080000.remoteproc=running
RP a204000.remoteproc=running
1119 43 193701 2473 0 0 0 0 0 1176 2473 0 0 0 0 0 0
9
219.16 833.27
~ # 

View file

@ -0,0 +1 @@
logs/uart/b9b-ram1-20261002-235454

49
logs/b9/b9c/B9C-RESULT.md Normal file
View file

@ -0,0 +1,49 @@
# B9C-RESULT — persistent display stack (ST7735S, fbcon tty1, MPP4 backlight) — PASS (2026-10-03)
**The eMMC cache is now B9C `b9ce13c9`** (B9C_WRITE_VERIFIED). It replaces B8F `857c9c30`; the B8F image is kept as backup/rollback.
## What B9C adds on top of B8F
| part | change |
|---|---|
| kernel | b9c 3afc6c77 = b8d + DRM + DRM_PANEL_MIPI_DBI + DRM_FBDEV_EMULATION + FRAMEBUFFER_CONSOLE + FONTS with FONT_6x8 only (`linux/aurora-b9b.config`, `linux/aurora-b9c.config`) |
| DTB | B9B 7ca9cc79: spi@78b8000 (native CS0, stock pinctrl), panel `jz08au,aurora-st7735s` + `panel-mipi-dbi-spi` (16 MHz, mode 3, write-only, D/C 116, RESET 118, power L17 2.85 V, io L6 1.8 V, r5g6b5, 128x128, back porches 2/3), L17 constraints, MPP4 sink (drive-strength 7) + gpio-backlight |
| firmware | `/lib/firmware/jz08au,aurora-st7735s.bin` 58697d4d = the stock LK/dtb_01 init sequence (18 commands + the 120 ms SLPOUT delay; RAMWR left to the driver) |
| initramfs | B8F abb3bd67 + overlay: /init (+5 lines: `hostname aurora`, `/etc/init.d/aurora-display start`, getty loop on tty1), `/usr/sbin/aurora-display`, `/etc/init.d/aurora-display` |
| cmdline | `earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0`. `console=tty0` is placed before the UART console so that `/dev/console` (and the cttyhack UART shell) stays on ttyMSM0. |
aurora-display: waits for fb0 → if fbcon's takeover already enabled the pipe (connector enabled/On + L17 used) it does **no** unblank (no double init);
otherwise it does one fbdev unblank → backlight on through the gpio-backlight sysfs (never raw PMIC writes) → `=== DISPLAY READY`.
In every run the fbcon takeover enabled the pipe by itself.
## Path
- B9B (RAM): first light via panel-mipi-dbi, colours/orientation/offsets confirmed (logs/b9/b9b).
- B9C RAM pretest `aurora-b9c.img` fa855e1c (ram1, class A): fbcon 21x16, DISPLAY READY 8.0 s, getty tty1, UART shell, LTE/Wi-Fi OK; operator: text readable,
orientation right, nothing clipped, backlight OFF→ON. The login prompt scrolls away under the later kernel messages (ignore_loglevel) — accepted (option A).
- Cache candidate `b9/b9c/cache/cache-extlinux-b9c.img` b9ce13c9 (B8F mkfs recipe, bit-identical rebuild, e2fsck clean).
lk2nd emulator: S6 regression == B8F; S7 "Trying to boot 'b9c'", kernel end DDR+0x1820000 < tags +0x20a9000 < ramdisk +0x22a9000; F1/F3/F10 → emmc1 fallback.
- Write (HW EDL, `B9C-write.sh`): live cache == B8F 857c9c30 (pre-cache.bin = backup) → write → CACHE_MATCH → all other partitions == A3/A4pre → **B9C_WRITE_VERIFIED** (logs/b9/b9c/W).
## Cold boots (normal power-on, no RESET, no fastboot, no UART input, no manual commands)
| run | class | display | console/getty | LTE / Wi-Fi | time | other |
|---|---|---|---|---|---|---|
| cold1 | **A** (RTC 3 s) | fbcon 21x16 1.77 s, DISPLAY READY 7.8 s, no unblank, errors 0 | console tty0+ttyMSM0, getty tty1, hostname aurora, UART shell on ttyMSM0 | START OK 76.4 s, AP ENABLED 80.6 s, ping 4/4 | DMS/NITZ VALID, SNTP +0.55 s | MPSS+WCNSS running, crash 0, eMMC w=0; **backlight ON→OFF→ON confirmed visually** (sysfs) |
| cold2-classB | **B** (RTC 585 s, ~12 s off) | same, DISPLAY READY 7.8 s, errors 0 | same | START OK 73.8 s, AP ENABLED 78.6 s, ping 4/4 | VALID, SNTP +0.46 s | crash 0, w=0 — **counted by operator decision (relaxed criterion)** |
| cold3 | **A** (RTC 3 s) | fbcon 1.78 s, DISPLAY READY 7.35 s, errors 0 | same | START OK 76.3 s, AP ENABLED 80.2 s, ping 4/4 | VALID, SNTP +0.09 s | crash 0, w=0 |
Not counted:
- `cold1-invalid`: the battery dropped out at ~27 s; the second start was class B and the modem controller rolled back because the USB host was not reachable;
the display part was OK.
- `cold1-aborted`: the driver was stopped before power-on, while B9L was run in between.
**Deviation:** the B9C criterion was "3/3 class A"; the result is 2× class A + 1× class B, accepted explicitly by the operator.
## Rollback
`b9/b9c/cache/B9C-rollback.sh` (HW EDL) → B8F 857c9c30. Deeper: B8F-rollback.sh → B7C 14fe453a.
## Not in scope / open
- Screen content is a live kernel console. A real UI comes in a later stage.
- No backlight dimming (MPP4 sink is on/off at 40 mA).
- About 1 s of dark screen between the bootloader and Linux. The display before Linux needs the B9L lk2nd port; B9L-RAM PASS (logs/b9/lk, logs/b9/b9l); flashing lk1st needs a separate GO.
- The device-tree model string still says "RAM boot B9B" (cosmetic, inherited from the B9B DTS).
**B9 CLOSED.**

23
logs/b9/b9c/W-console.txt Normal file
View file

@ -0,0 +1,23 @@
== G0 inputs
== G1 identity + geometry + baseline
== W cache := candidate (LBA 2133088, 262144 sectors)
rc=0
Wrote b9/b9c/cache/cache-extlinux-b9c.img to sector 2133088.
b9ce13c9f48e36a5054c0ae3c39dc3f184b1fc2eea1d57d4b8bd8e9ae800a37b b9/b9c/cache/cache-extlinux-b9c.img
b9ce13c9f48e36a5054c0ae3c39dc3f184b1fc2eea1d57d4b8bd8e9ae800a37b logs/b9/b9c/W/11-cache-readback.bin
CACHE_MATCH
== V everything else unchanged
sbl1 == A3
rpm == A3
tz == A3
hyp == A3
recovery == A3
modemst1 == A3
modemst2 == A3
fsg == A3
fsc == A3
persist == A3
modem == A4pre
system == A4pre
userdata == A4pre
B9C_WRITE_VERIFIED — power off fully (USB, then battery) before first boot

View file

@ -0,0 +1,69 @@
Qualcomm Sahara / Firehose Client V3.62 (c) B.Kerler 2018-2025.
main - Using loader firehose/007050e100000000_394a2e47cf830150_fhprg_peek.bin ...
main - Waiting for the device
main - Device detected :)
sahara - Protocol version: 2, Version supported: 1
main - Mode detected: sahara
sahara -
Version 0x2
------------------------
HWID: 0x007050e100000000 (MSM_ID:0x007050e1,OEM_ID:0x0000,MODEL_ID:0x0000)
CPU detected: "MSM8916"
PK_HASH: 0xcc3153a80293939b90d02d3bf8b23e0292e452fef662c74998421adad42a380f
Serial: 0x<SAHARA_SERIAL>
sahara - Protocol version: 2, Version supported: 1
sahara - Uploading loader firehose/007050e100000000_394a2e47cf830150_fhprg_peek.bin ...
sahara - 32-Bit mode detected.
sahara - Loader successfully uploaded.
main - Trying to connect to firehose loader ...
firehose_client
firehose_client - [LIB]: No --memory option set, we assume "eMMC" as default ..., if it fails, try using "--memory" with "UFS","NAND" or "spinor" instead !
firehose
firehose - [LIB]: Host's payload to target size is too large
firehose
firehose - [LIB]: logbuf@0x0801D0A0 fh@0x08019F08
firehose
firehose - [LIB]: !DEBUG! rsp.data: 'bytearray(b'<?xml version="1.0" encoding="UTF-8" ?><data><log value="logbuf@0x0801D0A0 fh@0x08019F08" /></data>')'
firehose - TargetName=MSM8916
firehose - MemoryName=eMMC
firehose - Version=1
firehose - Trying to read first storage sector...
firehose - Running configure...
firehose_client - Supported functions:
-----------------
Parsing Lun 0:
GPT Table:
-------------
modem: Offset 0x0000000004000000, Length 0x0000000004000000, Flags 0x1000000000000000, UUID 3d989bf0-d07d-1e91-a264-af709697f663, Type EFI_BASIC_DATA, Active False
sbl1: Offset 0x0000000008000000, Length 0x0000000000080000, Flags 0x0000000000000000, UUID 1b6c30d5-bd18-6545-356a-f1425997876e, Type 0xdea0ba2c, Active False
sbl1bak: Offset 0x0000000008080000, Length 0x0000000000080000, Flags 0x0000000000000000, UUID 9ed2083d-386f-32ef-4bef-946dce6a9277, Type EFI_BASIC_DATA, Active False
aboot: Offset 0x0000000008100000, Length 0x0000000000100000, Flags 0x0000000000000000, UUID 87b2dbde-0f34-1616-ef92-64b61e3820e1, Type 0x400ffdcd, Active False
abootbak: Offset 0x0000000008200000, Length 0x0000000000100000, Flags 0x0000000000000000, UUID 8942be05-fe81-ad19-58d5-a47cf6f28983, Type EFI_BASIC_DATA, Active False
rpm: Offset 0x0000000008300000, Length 0x0000000000080000, Flags 0x0000000000000000, UUID 78404e1a-cca3-eae7-6d9c-175a8a951490, Type 0x98df793, Active False
rpmbak: Offset 0x0000000008380000, Length 0x0000000000080000, Flags 0x0000000000000000, UUID 4c9e9f1f-a313-ae8f-6048-d077244223bf, Type EFI_BASIC_DATA, Active False
tz: Offset 0x0000000008400000, Length 0x0000000000100000, Flags 0x0000000000000000, UUID 8165e1d2-0aff-c224-31bb-8e7d26c9b865, Type 0xa053aa7f, Active False
tzbak: Offset 0x0000000009504000, Length 0x0000000000080000, Flags 0x0000000000000000, UUID 55bca949-6a02-9e27-e8d0-a6fee655f8a5, Type EFI_BASIC_DATA, Active False
hyp: Offset 0x0000000008500000, Length 0x0000000000080000, Flags 0x0000000000000000, UUID 6f3bd8d5-6441-b0b1-50f8-3db08db71a3e, Type 0xe1a6a689, Active False
hypbak: Offset 0x0000000008580000, Length 0x0000000000080000, Flags 0x0000000000000000, UUID 9453b2e0-49a9-ec07-7d3e-ecf25ee7ce30, Type EFI_BASIC_DATA, Active False
pad: Offset 0x0000000008600000, Length 0x0000000000100000, Flags 0x0000000000000000, UUID 11833981-0bdc-fe03-ff38-cf174fea4855, Type EFI_BASIC_DATA, Active False
modemst1: Offset 0x0000000008700000, Length 0x0000000000180000, Flags 0x0000000000000000, UUID 7f8fc1bc-7157-c803-b539-49204286be1f, Type 0xebbeadaf, Active False
modemst2: Offset 0x0000000008880000, Length 0x0000000000180000, Flags 0x0000000000000000, UUID a260d16e-cde5-7834-bae2-9a835e930538, Type 0xa288b1f, Active False
misc: Offset 0x0000000008a00000, Length 0x0000000000100000, Flags 0x0000000000000000, UUID 16011655-25d4-6066-a7df-90f6fee740fd, Type 0x20117f86, Active False
fsc: Offset 0x0000000008b00000, Length 0x0000000000000400, Flags 0x0000000000000000, UUID 6070d45d-e39a-201f-85ea-eff4dc5b2ad9, Type 0x57b90a16, Active False
ssd: Offset 0x0000000008b00400, Length 0x0000000000002000, Flags 0x0000000000000000, UUID eb5d446e-dca1-c48f-a46f-23ccf9a32d9d, Type 0x2c86e742, Active False
splash: Offset 0x0000000008b02400, Length 0x0000000000a00000, Flags 0x0000000000000000, UUID 17a56593-755a-4f9e-584c-a986c825d03c, Type 0x20117f86, Active False
DDR: Offset 0x000000000c000000, Length 0x0000000000008000, Flags 0x1000000000000000, UUID 708298a7-c75e-4858-bdf9-1d8e94857b8a, Type 0x20a0c19c, Active False
fsg: Offset 0x000000000c008000, Length 0x0000000000180000, Flags 0x1000000000000000, UUID 63874400-826f-d643-5a66-d6e8703754b6, Type 0x638ff8e2, Active False
sec: Offset 0x000000000c188000, Length 0x0000000000004000, Flags 0x1000000000000000, UUID 057d8b8f-2449-5ddf-8456-35cf05e7e8fb, Type 0x303e6ac3, Active False
boot: Offset 0x000000000c18c000, Length 0x0000000001000000, Flags 0x1000000000000000, UUID 61102f04-b91f-1560-ccd7-66e00ed67495, Type 0x20117f86, Active False
system: Offset 0x000000000d18c000, Length 0x0000000032000000, Flags 0x1000000000000000, UUID 1d988a4e-968a-8c2d-afc6-287f4b46ee6f, Type EFI_BASIC_DATA, Active False
persist: Offset 0x000000003f18c000, Length 0x0000000002000000, Flags 0x1000000000000000, UUID 566b9d65-2509-0732-2788-e523ed49b36a, Type EFI_BASIC_DATA, Active False
cache: Offset 0x000000004118c000, Length 0x0000000008000000, Flags 0x1000000000000000, UUID ca4b35d5-45ba-55f8-22cc-69cdc47758f4, Type EFI_BASIC_DATA, Active False
recovery: Offset 0x000000004918c000, Length 0x0000000001000000, Flags 0x1000000000000000, UUID c4bf1e63-a9c0-312d-ef3c-4f0be2d8f23f, Type 0x20117f86, Active False
userdata: Offset 0x000000004a18c000, Length 0x000000009ee6fe00, Flags 0x1000000000000000, UUID 18e3370b-8846-0ff0-bb9b-f8812f2299a4, Type EFI_BASIC_DATA, Active False
Total disk size:0x00000000e9000000, sectors:0x0000000000748000

File diff suppressed because one or more lines are too long

File diff suppressed because one or more lines are too long

20
logs/b9/b9c/W/SHA256SUMS Normal file
View file

@ -0,0 +1,20 @@
b9ce13c9f48e36a5054c0ae3c39dc3f184b1fc2eea1d57d4b8bd8e9ae800a37b 11-cache-readback.bin
3b8cd2667837fc7083cb28991d849f9b408a07fa743bfd05eafee7b053760f85 post-aboot.bin
e9579f33c7304cd47f487f2b61cd9226dc04fd3a63775d62b4b95fc15bd3ebff post-boot.bin
5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef post-fsc.bin
b0a3b7e46bc420f39120cfa7f2049027cba59383d52c78ad9576049ad40982aa post-fsg.bin
795952a1a5965ca2118afcb0add9cd1d358a09ec9a43ca4208cfad40c99de18f post-gptb.bin
6e850a5dfe5400da346962a54e41491cb0e4c5ac3543dd4799c8bc0ee5c3b8b6 post-gptp.bin
1a963047a4302569da2ddbda726b65c57f5181c0e290ca983dcd2fc529f74555 post-hyp.bin
637a71d17f1a43017aad52b9fdd4c8534e84672f1e602340f7350f293c8ed52a post-modemst1.bin
9bb101903b2e17f815f0139773d5381384fba2511528fc81e2cb49da9bee94f5 post-modemst2.bin
ee48a8438c4e5473d3f59bc25f1c5976510d09b1879fe7246f5d7bbb9949b915 post-persist.bin
0dfa60a03a742ab2bf9f6e91e3887142cb7a0af2dd37c6373f7942703cd011e1 post-recovery.bin
5a9b857ba6c3af1c848c6e57bbaf9cefcedc3629e5536d27e87b336c67a281fd post-rpm.bin
6a661ec947c1d935316f9d8731b5314e7502bde5825ebbfc3d2860d081b4096d post-sbl1.bin
8481892fe56fc810e4322b7e6838bf071695e4fc1380c16b21973d7fab325363 post-tz.bin
c6f7db266a14227ca7e7b0343661089298e4c4320a9522e3e695b5e069e6b4af post-tzbak.bin
3b8cd2667837fc7083cb28991d849f9b408a07fa743bfd05eafee7b053760f85 pre-aboot.bin
e9579f33c7304cd47f487f2b61cd9226dc04fd3a63775d62b4b95fc15bd3ebff pre-boot.bin
857c9c300055804cab673027bc8cddc010ad04bfec5d75276d8229b84846c4b2 pre-cache.bin
6e850a5dfe5400da346962a54e41491cb0e4c5ac3543dd4799c8bc0ee5c3b8b6 pre-gptp.bin

View file

@ -0,0 +1 @@
driver stopped before power-on (B9L inserted)

View file

@ -0,0 +1,2 @@
21:35:01.808 B9C cold1: waiting for the board to go away (power off >= 90 s), then normal power-on WITHOUT RESET
21:35:25.924 board unreachable (powered off)

View file

@ -0,0 +1 @@
INVALID: operator power events - battery dropped at ~27 s in boot 1, boot 2 class B (RTC 31 s) + modem usb0-ping rollback; display part OK

View file

@ -0,0 +1,10 @@
21:28:50.833 B9C cold1: waiting for the board to go away (power off >= 90 s), then normal power-on WITHOUT RESET
21:28:51.837 board unreachable (powered off)
21:29:42.806 NCM ping ok
21:29:42.811 RTC at boot 3 s -> class A
~ # cat /proc/device-tree/model; echo; uname -r; grep -E "START OK|FAIL in|rollb
JZ08AU Aurora (RAM boot B9B)
21:31:12.907 wifi: [25.91] === AP ENABLED ssid=aurora-b8f ch=6 pid=1705 in 16.56s
21:33:13.128 sntp:
21:33:39.145 snapshot: 2 end markers; RP a204000.remoteproc=running
21:33:44.176 B9C cold1 END - operator visual check next

View file

@ -0,0 +1,190 @@
<EFBFBD><EFBFBD><01><><1F><><01><>
BusyBox v1.37.0 (Debian 1:1.37.0-6+b9) built-in shell (ash)
Enter 'help' for a list of built-in commands.
~ # echo SNAP-BEGIN; cat /proc/uptime; date -u; cat /proc/device-tree/model; ech
o; uname -a; cat /proc/cmdline
SNAP-BEGIN
191.38 750.11
Thu Jan 1 00:03:42 UTC 1970
JZ08AU Aurora (RAM boot B9B)
Linux aurora 7.2.7-aurora-b9c #9 SMP PREEMPT Sat Oct 3 03:06:50 +06 2026 aarch64 GNU/Linux
earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0
~ # echo ---time; cat /run/aurora-modem/time-set; grep -E "TIME|SNTP" /run/auror
a-modem/lifecycle.log | tail -4
---time
cat: can't open '/run/aurora-modem/time-set': No such file or directory
[13.30] TIME probe 1 [QMI_READY]: dms_ms=3247 dms_utc=315964803.247 nitz=none dms-nitz=- clock=44 -> INVALID (year<2026)
[13.47] TIME probe 2 [SIM_READY]: dms_ms=3417 dms_utc=315964803.417 nitz=none dms-nitz=- clock=44 -> INVALID (year<2026)
[16.84] TIME probe 3 [RADIO_ONLINE]: dms_ms=6790 dms_utc=315964806.790 nitz=none dms-nitz=- clock=47 -> INVALID (year<2026)
~ # echo ---modem; /etc/init.d/aurora-modem status
---modem
service: idle
controller: OFF
remoteproc: 4080000.remoteproc offline (/sys/class/remoteproc/remoteproc0) fw=mba.mbn
rmtfs: pid='' writes_logged=0
qmi dev: absent qmi-proxy=''
daemons: udevd='' dbus='' polkitd='' ModemManager=''
mm: n/a
wwan up: 0 of 8
routes:
bam-dmux: suspended active_ms=0 suspended_ms=190733 control=auto
usb0: 172.16.42.1/24 route-to-host: 172.16.42.2 dev usb0 src 172.16.42.1
emmc: writes_completed=0 sectors_written=0
time: 1970-01-01 00:03:42 UTC; set: no; probes: 3
dmesg-errs: 0
~ # echo ---wifi; /etc/init.d/aurora-wifi status; echo ---wifilog; cat /run/auro
ra-wifi/wifi.log; cat /run/aurora-wifi/service.log; echo ---hostapdlog; cat /run
/aurora-wifi/hostapd.log
---wifi
service: idle
remoteproc: a204000.remoteproc running (/sys/class/remoteproc/remoteproc1)
crash=0 watchdog=0 fatal=0
wlan0: wlan0: <BROADCAST,MULTICAST,UP,LOWER_UP> ssid aurora-b8f type AP channel 6 (2437 MHz), width: 20 MHz, center1: 2437 MHz
hostapd: pid=1705 0 connects, 0 disconnects
[23.01] WCNSS /sys/class/remoteproc/remoteproc1 state=running
[24.87] wlan0 up addr=<MAC> (wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO')
[25.91] === AP ENABLED ssid=aurora-b8f ch=6 pid=1705 in 16.56s
---wifilog
[9.35] === WIFI START (wait for modem START OK/FAIL up to 300s)
[22.47] modem gate after 13s: [22.04] rollback: full stop
[23.01] WCNSS /sys/class/remoteproc/remoteproc1 state=running
[24.87] wlan0 up addr=<MAC> (wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO')
[25.91] === AP ENABLED ssid=aurora-b8f ch=6 pid=1705 in 16.56s
[9.35] === WIFI START (wait for modem START OK/FAIL up to 300s)
[22.47] modem gate after 13s: [22.04] rollback: full stop
[23.01] WCNSS /sys/class/remoteproc/remoteproc1 state=running
[24.87] wlan0 up addr=<MAC> (wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO')
[25.91] === AP ENABLED ssid=aurora-b8f ch=6 pid=1705 in 16.56s
=== service start rc=0 25.92
---hostapdlog
56.152522: VLAN: vlan_set_name_type: SET_VLAN_NAME_TYPE_CMD name_type=2 failed: No error information
56.260276: wlan0: interface state UNINITIALIZED->ENABLED
56.260394: wlan0: AP-ENABLED
~ # for r in /sys/class/remoteproc/*; do echo "RP $(cat $r/name)=$(cat $r/state)
"; done; iw dev
RP 4080000.remoteproc=offline
RP a204000.remoteproc=running
phy#0
Interface wlan0
ifindex 12
wdev 0x1
addr <MAC>
ssid aurora-b8f
type AP
channel 6 (2437 MHz), width: 20 MHz, center1: 2437 MHz
txpower 20.00 dBm
multicast TXQ:
qsz-byt qsz-pkt flows drops marks overlmt hashcol tx-bytes tx-packets
0 0 0 0 0 0 0 0 0
~ # echo ---dmesg-wifi; dmesg | grep -iE "wcn36xx|wcnss|a204000|cfg80211|aurora-
wifi|crash|watchdog"
---dmesg-wifi
[ 0.000000] OF: reserved mem: 0x000000008b600000..0x000000008bbfffff (6144 KiB) nomap non-reusable wcnss@8b600000
[ 0.967917] remoteproc remoteproc0: releasing a204000.remoteproc
[ 0.997334] qcom-wcnss-pil a204000.remoteproc: supply vddcx not found, using dummy regulator
[ 1.007298] a204000.remoteproc.iris: failed to get regulators
[ 1.019899] remoteproc remoteproc0: releasing a204000.remoteproc
[ 1.050982] qcom-wcnss-pil a204000.remoteproc: supply vddcx not found, using dummy regulator
[ 1.059076] remoteproc remoteproc1: a204000.remoteproc is available
[ 1.082517] cfg80211: Loading compiled-in X.509 certificates for regulatory database
[ 1.413433] remoteproc remoteproc1: Direct firmware load for wcnss.mdt failed with error -2
[ 1.416180] remoteproc remoteproc1: powering up a204000.remoteproc
[ 1.416301] remoteproc remoteproc1: Direct firmware load for wcnss.mdt failed with error -2
[ 1.474319] cfg80211: failed to load regulatory.db
[ 9.499887] [aurora-wifi] === WIFI START (wait for modem START OK/FAIL up to 300s)
[ 22.627081] [aurora-wifi] modem gate after 13s: [22.04] rollback: full stop
[ 22.650546] remoteproc remoteproc1: powering up a204000.remoteproc
[ 22.656102] remoteproc remoteproc1: Booting fw image wcnss.mdt, size 7260
[ 23.142056] remoteproc remoteproc1: remote processor a204000.remoteproc is now up
[ 23.158300] [aurora-wifi] WCNSS /sys/class/remoteproc/remoteproc1 state=running
[ 23.263446] qcom_wcnss_ctrl remoteproc1:smd-edge.WCNSS_CTRL.-1.-1: WCNSS Version 1.5 1.2
[ 23.285578] wcn36xx: mac address: <MAC>
[ 24.957953] wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO' and CRM version 'CNSS-PR-1-4-2-c4-00084'
[ 24.972180] wcn36xx: firmware API 1.5.1.2, 41 stations, 2 bssids
[ 25.020230] [aurora-wifi] wlan0 up addr=<MAC> (wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO')
[ 26.064437] [aurora-wifi] === AP ENABLED ssid=aurora-b8f ch=6 pid=1705 in 16.56s
~ # echo ---ping; ping -c4 -W3 -I wwan0 77.88.8.8 | tail -2
---ping
ping: sendto: Network is unreachable
PING 77.88.8.8 (77.88.8.8): 56 data bytes
~ # echo ---display; /etc/init.d/aurora-display status; cat /run/aurora-display/
display.log; cat /run/aurora-display/service.log
---display
fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=0 bl=1
[7.18] display pipe already enabled (by fbcon takeover) - no unblank needed
[7.20] backlight on -> bl_power=0 actual_brightness=1
[7.27] === DISPLAY READY fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=0 bl=1
[7.08] start: fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=4 bl=1
[7.11] fbcon bound to fb0
[7.18] display pipe already enabled (by fbcon takeover) - no unblank needed
[7.20] backlight on -> bl_power=0 actual_brightness=1
[7.27] === DISPLAY READY fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=0 bl=1
=== service start rc=0 7.27
~ # echo ---consoles; cat /sys/class/tty/console/active; for v in /sys/class/vtc
onsole/vtcon*; do echo "$v $(cat $v/bind) $(cat $v/name)"; done; ls -l /proc/[0-
9]*/fd/0 2>/dev/null | grep -E "ttyMSM0|tty1|console" | sed "s/.* \/proc/\/proc/
"
---consoles
tty0 ttyMSM0
/sys/class/vtconsole/vtcon0 0 (S) dummy device
/sys/class/vtconsole/vtcon1 1 (M) frame buffer device
/proc/1/fd/0 -> /dev/console
/proc/1118/fd/0 -> /dev/ttyMSM0
/proc/627/fd/0 -> /dev/tty1
~ # echo ---getty; hostname; ps | grep -E "[g]etty|[c]ttyhack| sh$"
---getty
aurora
627 root getty 0 tty1 linux
1118 root sh
~ # echo ---fb; ls -l /dev/dri/card0 /dev/fb0; for f in name bits_per_pixel virt
ual_size stride; do echo "fb0 $f=$(cat /sys/class/graphics/fb0/$f)"; done; cat /
sys/class/drm/card0-SPI-1/enabled /sys/class/drm/card0-SPI-1/dpms
---fb
crw------- 1 root root 226, 0 Jan 1 00:00 /dev/dri/card0
crw------- 1 root root 29, 0 Jan 1 00:00 /dev/fb0
fb0 name=panel-mipi-dbid
fb0 bits_per_pixel=16
fb0 virtual_size=128,128
fb0 stride=256
enabled
On
~ # echo ---regs; for r in /sys/class/regulator/regulator.*; do n=$(cat $r/name)
; case $n in l6|l17) echo "$n $(cat $r/state) $(cat $r/microvolts) users=$(cat $
r/num_users)";; esac; done
---regs
l17 enabled 2850000 users=1
l6 enabled 1800000 users=1
~ # echo ---bl; for f in bl_power brightness actual_brightness; do echo "bl $f=$
(cat /sys/class/backlight/backlight/$f)"; done
---bl
bl bl_power=0
bl brightness=1
bl actual_brightness=1
~ # echo ---dmesg-display; dmesg | grep -iE "drm|panel|mipi|spi_qup|78b8000|fbco
n|Console: |frame buffer|backlight|aurora-display|l17"
---dmesg-display
[ 0.000000] Kernel command line: earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0
[ 0.010993] Console: colour dummy device 80x25
[ 0.717746] spi_qup 78b8000.spi: IN:block:16, fifo:64, OUT:block:16, fifo:64
[ 1.066705] l17: Bringing 0uV into 2850000-2850000uV
[ 1.416263] [drm] Initialized panel-mipi-dbi 1.0.0 for spi0.0 on minor 0
[ 1.796720] Console: switching to colour frame buffer device 21x16
[ 1.860388] panel-mipi-dbi-spi spi0.0: [drm] fb0: panel-mipi-dbid frame buffer device
[ 7.233896] [aurora-display] start: fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=4 bl=1
[ 7.258541] [aurora-display] fbcon bound to fb0
[ 7.333314] [aurora-display] display pipe already enabled (by fbcon takeover) - no unblank needed
[ 7.354476] [aurora-display] backlight on -> bl_power=0 actual_brightness=1
[ 7.418169] [aurora-display] === DISPLAY READY fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=0 bl=1
~ # echo ---display-errors; dmesg | grep -iE "drm|panel|mipi|spi0|fbcon|backligh
t|aurora-display" | grep -ciE "err|fail|timeout|warn"
---display-errors
0
~ # echo ---emmc; awk "{print \"w=\"\$5\" s=\"\$7}" /sys/block/mmcblk0/stat
---emmc
w=0 s=0
~ # echo SNAP-END
SNAP-END
~ # 

View file

@ -0,0 +1 @@
COLD1 PASS (class A, LTE, Wi-Fi, time, display, fbcon, getty, UART, bl visual)

View file

@ -0,0 +1,10 @@
=== 22:23:55 bl off
[168.43] backlight off -> bl_power=0 actual_brightness=0
=== 22:27:48 bl on (repeat, operator missed off)
[401.38] backlight on -> bl_power=0 actual_brightness=1
=== 22:28:01 bl off (operator watching)
[414.51] backlight off -> bl_power=0 actual_brightness=0
=== 22:29:23 bl on (final)
[496.52] backlight on -> bl_power=0 actual_brightness=1
operator: console visible with bl on (22:27:48), screen dark after bl off (22:28:01)
operator: screen back on with console after final bl on (22:29:23) -> backlight ON->OFF->ON visual PASS

View file

@ -0,0 +1,11 @@
22:18:59.176 B9C cold1: waiting for the board to go away (power off >= 90 s), then normal power-on WITHOUT RESET
22:19:29.333 board unreachable (powered off)
22:21:17.262 NCM ping ok
22:21:17.266 RTC at boot 3 s -> class A
~ # cat /proc/device-tree/model; echo; uname -r; grep -E "START OK|FAIL in|rollb
JZ08AU Aurora (RAM boot B9B)
[86.21] === START OK in 76.4s (wwan0 10.87.46.139/29, routes: 10.10.22.3 194.186.191.1 77.88.8.8 1.1.1.1 )
22:22:53.435 wifi: [90.41] === AP ENABLED ssid=aurora-b8f ch=6 pid=2784 in 80.6s
22:23:01.457 sntp: [101.66] SNTP check ( 89.109.251.21 89.109.251.22 89.109.251.23): 14 replies; best offset delay server: +0.553920 0.063431 89.109.251.23: (offset > 0 = clock behind)
22:23:27.478 snapshot: 2 end markers; RP a204000.remoteproc=running
22:23:32.512 B9C cold1 END - operator visual check next

View file

@ -0,0 +1,200 @@
<EFBFBD><EFBFBD><01><><1F><><01><>
BusyBox v1.37.0 (Debian 1:1.37.0-6+b9) built-in shell (ash)
Enter 'help' for a list of built-in commands.
~ # echo SNAP-BEGIN; cat /proc/uptime; date -u; cat /proc/device-tree/model; ech
o; uname -a; cat /proc/cmdline
SNAP-BEGIN
114.57 415.96
Fri Oct 2 22:23:01 UTC 2026
JZ08AU Aurora (RAM boot B9B)
Linux aurora 7.2.7-aurora-b9c #9 SMP PREEMPT Sat Oct 3 03:06:50 +06 2026 aarch64 GNU/Linux
earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0
~ # echo ---time; cat /run/aurora-modem/time-set; grep -E "TIME|SNTP" /run/auror
a-modem/lifecycle.log | tail -4
---time
1790979692 24.63 REG:registered/attached qmi-dms
[24.78] TIME probe 6 [REGISTERED]: dms_ms=1475014892088 dms_utc=1790979692.088 nitz=2026-10-02 22:21:32 dms-nitz=+0.12 clock=1790979692 -> VALID (ok)
[86.32] TIME probe 7 [BEARER_CONNECTED]: dms_ms=1475014953624 dms_utc=1790979753.624 nitz=2026-10-02 22:22:33 dms-nitz=+0.66 clock=1790979753 -> VALID (ok)
[101.66] SNTP check ( 89.109.251.21 89.109.251.22 89.109.251.23): 14 replies; best offset delay server: +0.553920 0.063431 89.109.251.23: (offset > 0 = clock behind)
[101.68] SNTP: |offset| < 1s - clock kept (no slew: STA_UNSYNC stays, RTC_SYSTOHC never engages)
~ # echo ---modem; /etc/init.d/aurora-modem status
---modem
service: idle
controller: BEARER_CONNECTED
remoteproc: 4080000.remoteproc running (/sys/class/remoteproc/remoteproc0) fw=mba.mbn
rmtfs: pid='1158' writes_logged=1
qmi dev: /dev/wwan0qmi0 qmi-proxy='2040'
daemons: udevd='1917' dbus='1947' polkitd='1951' ModemManager='1962'
mm plugin: qcom-soc
mm primary port: wwan0qmi0
mm state: connected
mm power state: on
mm access tech: lte
mm signal quality: 67% (recent)
mm operator name: Beeline
mm registration: home
bearer 1: Status connected: yes; interface: wwan0; address: 10.87.46.139;
wwan: wwan0 UP 10.87.46.139/29
wwan up: 1 of 8
routes: 1.1.1.1 dev wwan0 scope link src 10.87.46.139 ;10.10.22.3 dev wwan0 scope link src 10.87.46.139 ;10.87.46.136/29 dev wwan0 scope link src 10.87.46.139 ;77.88.8.8 dev wwan0 scope link src 10.87.46.139 ;89.109.251.21 dev wwan0 scope link src 10.87.46.139 ;89.109.251.22 dev wwan0 scope link src 10.87.46.139 ;89.109.251.23 dev wwan0 scope link src 10.87.46.139 ;194.186.191.1 dev wwan0 scope link src 10.87.46.139 ;
bam-dmux: suspended active_ms=8114 suspended_ms=106102 control=auto
usb0: 172.16.42.1/24 route-to-host: 172.16.42.2 dev usb0 src 172.16.42.1
emmc: writes_completed=0 sectors_written=0
time: 2026-10-02 22:23:02 UTC; set: 1790979692 24.63 REG:registered/attached qmi-dms; probes: 7
dmesg-errs: 0
~ # echo ---wifi; /etc/init.d/aurora-wifi status; echo ---wifilog; cat /run/auro
ra-wifi/wifi.log; cat /run/aurora-wifi/service.log; echo ---hostapdlog; cat /run
/aurora-wifi/hostapd.log
---wifi
service: idle
remoteproc: a204000.remoteproc running (/sys/class/remoteproc/remoteproc1)
crash=0 watchdog=0 fatal=0
wlan0: wlan0: <BROADCAST,MULTICAST,UP,LOWER_UP> ssid aurora-b8f type AP channel 6 (2437 MHz), width: 20 MHz, center1: 2437 MHz
hostapd: pid=2784 0 connects, 0 disconnects
[87.06] WCNSS /sys/class/remoteproc/remoteproc1 state=running
[89.37] wlan0 up addr=<MAC> (wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO')
[90.41] === AP ENABLED ssid=aurora-b8f ch=6 pid=2784 in 80.6s
---wifilog
[9.81] === WIFI START (wait for modem START OK/FAIL up to 300s)
[86.52] modem gate after 76s: [86.21] === START OK in 76.4s (wwan0 10.87.46.139/29, routes: 10.10.22.3 194.186
[87.06] WCNSS /sys/class/remoteproc/remoteproc1 state=running
[89.37] wlan0 up addr=<MAC> (wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO')
[90.41] === AP ENABLED ssid=aurora-b8f ch=6 pid=2784 in 80.6s
[9.81] === WIFI START (wait for modem START OK/FAIL up to 300s)
[86.52] modem gate after 76s: [86.21] === START OK in 76.4s (wwan0 10.87.46.139/29, routes: 10.10.22.3 194.186
[87.06] WCNSS /sys/class/remoteproc/remoteproc1 state=running
[89.37] wlan0 up addr=<MAC> (wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO')
[90.41] === AP ENABLED ssid=aurora-b8f ch=6 pid=2784 in 80.6s
=== service start rc=0 90.43
---hostapdlog
1790979757.163659: VLAN: vlan_set_name_type: SET_VLAN_NAME_TYPE_CMD name_type=2 failed: No error information
1790979757.271190: wlan0: interface state UNINITIALIZED->ENABLED
1790979757.271302: wlan0: AP-ENABLED
~ # for r in /sys/class/remoteproc/*; do echo "RP $(cat $r/name)=$(cat $r/state)
"; done; iw dev
RP 4080000.remoteproc=running
RP a204000.remoteproc=running
phy#0
Interface wlan0
ifindex 12
wdev 0x1
addr <MAC>
ssid aurora-b8f
type AP
channel 6 (2437 MHz), width: 20 MHz, center1: 2437 MHz
txpower 20.00 dBm
multicast TXQ:
qsz-byt qsz-pkt flows drops marks overlmt hashcol tx-bytes tx-packets
0 0 0 0 0 0 0 0 0
~ # echo ---dmesg-wifi; dmesg | grep -iE "wcn36xx|wcnss|a204000|cfg80211|aurora-
wifi|crash|watchdog"
---dmesg-wifi
[ 0.000000] OF: reserved mem: 0x000000008b600000..0x000000008bbfffff (6144 KiB) nomap non-reusable wcnss@8b600000
[ 0.967574] remoteproc remoteproc0: releasing a204000.remoteproc
[ 1.000995] qcom-wcnss-pil a204000.remoteproc: supply vddcx not found, using dummy regulator
[ 1.011579] a204000.remoteproc.iris: failed to get regulators
[ 1.029461] remoteproc remoteproc0: releasing a204000.remoteproc
[ 1.054067] qcom-wcnss-pil a204000.remoteproc: supply vddcx not found, using dummy regulator
[ 1.069841] remoteproc remoteproc1: a204000.remoteproc is available
[ 1.411647] remoteproc remoteproc1: Direct firmware load for wcnss.mdt failed with error -2
[ 1.414316] remoteproc remoteproc1: powering up a204000.remoteproc
[ 1.422554] remoteproc remoteproc1: Direct firmware load for wcnss.mdt failed with error -2
[ 1.802566] cfg80211: Loading compiled-in X.509 certificates for regulatory database
[ 1.828827] cfg80211: failed to load regulatory.db
[ 9.962967] [aurora-wifi] === WIFI START (wait for modem START OK/FAIL up to 300s)
[ 86.675329] [aurora-wifi] modem gate after 76s: [86.21] === START OK in 76.4s (wwan0 10.87.46.139/29, routes: 10.10.22.3 194.186
[ 86.709311] remoteproc remoteproc1: powering up a204000.remoteproc
[ 86.716131] remoteproc remoteproc1: Booting fw image wcnss.mdt, size 7260
[ 87.198893] remoteproc remoteproc1: remote processor a204000.remoteproc is now up
[ 87.210890] [aurora-wifi] WCNSS /sys/class/remoteproc/remoteproc1 state=running
[ 87.315033] qcom_wcnss_ctrl remoteproc1:smd-edge.WCNSS_CTRL.-1.-1: WCNSS Version 1.5 1.2
[ 87.339677] wcn36xx: mac address: <MAC>
[ 89.457602] wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO' and CRM version 'CNSS-PR-1-4-2-c4-00084'
[ 89.472006] wcn36xx: firmware API 1.5.1.2, 41 stations, 2 bssids
[ 89.520503] [aurora-wifi] wlan0 up addr=<MAC> (wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO')
[ 90.566277] [aurora-wifi] === AP ENABLED ssid=aurora-b8f ch=6 pid=2784 in 80.6s
~ # echo ---ping; ping -c4 -W3 -I wwan0 77.88.8.8 | tail -2
---ping
4 packets transmitted, 4 packets received, 0% packet loss
round-trip min/avg/max = 50.970/90.957/201.941 ms
~ # echo ---display; /etc/init.d/aurora-display status; cat /run/aurora-display/
display.log; cat /run/aurora-display/service.log
---display
fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=0 bl=1
[7.76] display pipe already enabled (by fbcon takeover) - no unblank needed
[7.78] backlight on -> bl_power=0 actual_brightness=1
[7.84] === DISPLAY READY fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=0 bl=1
[7.68] start: fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=4 bl=1
[7.70] fbcon bound to fb0
[7.76] display pipe already enabled (by fbcon takeover) - no unblank needed
[7.78] backlight on -> bl_power=0 actual_brightness=1
[7.84] === DISPLAY READY fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=0 bl=1
=== service start rc=0 7.85
~ # echo ---consoles; cat /sys/class/tty/console/active; for v in /sys/class/vtc
onsole/vtcon*; do echo "$v $(cat $v/bind) $(cat $v/name)"; done; ls -l /proc/[0-
9]*/fd/0 2>/dev/null | grep -E "ttyMSM0|tty1|console" | sed "s/.* \/proc/\/proc/
"
---consoles
tty0 ttyMSM0
/sys/class/vtconsole/vtcon0 0 (S) dummy device
/sys/class/vtconsole/vtcon1 1 (M) frame buffer device
/proc/1/fd/0 -> /dev/console
/proc/1120/fd/0 -> /dev/ttyMSM0
/proc/627/fd/0 -> /dev/tty1
~ # echo ---getty; hostname; ps | grep -E "[g]etty|[c]ttyhack| sh$"
---getty
aurora
627 root getty 0 tty1 linux
1120 root sh
~ # echo ---fb; ls -l /dev/dri/card0 /dev/fb0; for f in name bits_per_pixel virt
ual_size stride; do echo "fb0 $f=$(cat /sys/class/graphics/fb0/$f)"; done; cat /
sys/class/drm/card0-SPI-1/enabled /sys/class/drm/card0-SPI-1/dpms
---fb
crw------- 1 root root 226, 0 Oct 2 22:21 /dev/dri/card0
crw------- 1 root root 29, 0 Oct 2 22:21 /dev/fb0
fb0 name=panel-mipi-dbid
fb0 bits_per_pixel=16
fb0 virtual_size=128,128
fb0 stride=256
enabled
On
~ # echo ---regs; for r in /sys/class/regulator/regulator.*; do n=$(cat $r/name)
; case $n in l6|l17) echo "$n $(cat $r/state) $(cat $r/microvolts) users=$(cat $
r/num_users)";; esac; done
---regs
l17 enabled 2850000 users=1
l6 enabled 1800000 users=1
~ # echo ---bl; for f in bl_power brightness actual_brightness; do echo "bl $f=$
(cat /sys/class/backlight/backlight/$f)"; done
---bl
bl bl_power=0
bl brightness=1
bl actual_brightness=1
~ # echo ---dmesg-display; dmesg | grep -iE "drm|panel|mipi|spi_qup|78b8000|fbco
n|Console: |frame buffer|backlight|aurora-display|l17"
---dmesg-display
[ 0.000000] Kernel command line: earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0
[ 0.010997] Console: colour dummy device 80x25
[ 0.716749] spi_qup 78b8000.spi: IN:block:16, fifo:64, OUT:block:16, fifo:64
[ 1.057090] l17: Bringing 0uV into 2850000-2850000uV
[ 1.422655] [drm] Initialized panel-mipi-dbi 1.0.0 for spi0.0 on minor 0
[ 1.770186] Console: switching to colour frame buffer device 21x16
[ 1.793786] panel-mipi-dbi-spi spi0.0: [drm] fb0: panel-mipi-dbid frame buffer device
[ 7.836096] [aurora-display] start: fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=4 bl=1
[ 7.855541] [aurora-display] fbcon bound to fb0
[ 7.912706] [aurora-display] display pipe already enabled (by fbcon takeover) - no unblank needed
[ 7.928810] [aurora-display] backlight on -> bl_power=0 actual_brightness=1
[ 7.994088] [aurora-display] === DISPLAY READY fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=0 bl=1
~ # echo ---display-errors; dmesg | grep -iE "drm|panel|mipi|spi0|fbcon|backligh
t|aurora-display" | grep -ciE "err|fail|timeout|warn"
---display-errors
0
~ # echo ---emmc; awk "{print \"w=\"\$5\" s=\"\$7}" /sys/block/mmcblk0/stat
---emmc
w=0 s=0
~ # echo SNAP-END
SNAP-END
~ # 

View file

@ -0,0 +1,2 @@
NOT COUNTED: class B (RTC 585 s, ~12 s off). Functionally all PASS.
COUNTED as run 2/3 by operator decision (relaxed criterion: one class-B run accepted). Functionally all PASS.

View file

@ -0,0 +1,11 @@
22:30:28.274 B9C cold2: waiting for the board to go away (power off >= 90 s), then normal power-on WITHOUT RESET
22:30:47.353 board unreachable (powered off)
22:30:59.932 NCM ping ok
22:30:59.940 RTC at boot 585 s -> class B
~ # cat /proc/device-tree/model; echo; uname -r; grep -E "START OK|FAIL in|rollb
JZ08AU Aurora (RAM boot B9B)
[83.58] === START OK in 73.8s (wwan0 10.47.129.24/28, routes: 10.10.22.1 194.186.191.1 77.88.8.8 1.1.1.1 )
22:32:36.091 wifi: [88.40] === AP ENABLED ssid=aurora-b8f ch=6 pid=2727 in 78.59s
22:32:44.112 sntp: [99.04] SNTP check ( 89.109.251.21 89.109.251.22 89.109.251.23): 12 replies; best offset delay server: +0.462342 0.043965 89.109.251.22: (offset > 0 = clock behind)
22:33:10.126 snapshot: 2 end markers; RP a204000.remoteproc=running
22:33:15.159 B9C cold2 END - operator visual check next

View file

@ -0,0 +1,200 @@
<EFBFBD><EFBFBD><01><><1F><><01><>
BusyBox v1.37.0 (Debian 1:1.37.0-6+b9) built-in shell (ash)
Enter 'help' for a list of built-in commands.
~ # echo SNAP-BEGIN; cat /proc/uptime; date -u; cat /proc/device-tree/model; ech
o; uname -a; cat /proc/cmdline
SNAP-BEGIN
114.64 415.93
Fri Oct 2 22:32:44 UTC 2026
JZ08AU Aurora (RAM boot B9B)
Linux aurora 7.2.7-aurora-b9c #9 SMP PREEMPT Sat Oct 3 03:06:50 +06 2026 aarch64 GNU/Linux
earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0
~ # echo ---time; cat /run/aurora-modem/time-set; grep -E "TIME|SNTP" /run/auror
a-modem/lifecycle.log | tail -4
---time
1790980272 21.96 REG:registered/attached qmi-dms
[22.10] TIME probe 6 [REGISTERED]: dms_ms=1475015472076 dms_utc=1790980272.076 nitz=2026-10-02 22:31:12 dms-nitz=+0.11 clock=1790980272 -> VALID (ok)
[83.69] TIME probe 7 [BEARER_CONNECTED]: dms_ms=1475015533658 dms_utc=1790980333.658 nitz=2026-10-02 22:32:13 dms-nitz=+0.69 clock=1790980333 -> VALID (ok)
[99.04] SNTP check ( 89.109.251.21 89.109.251.22 89.109.251.23): 12 replies; best offset delay server: +0.462342 0.043965 89.109.251.22: (offset > 0 = clock behind)
[99.05] SNTP: |offset| < 1s - clock kept (no slew: STA_UNSYNC stays, RTC_SYSTOHC never engages)
~ # echo ---modem; /etc/init.d/aurora-modem status
---modem
service: idle
controller: BEARER_CONNECTED
remoteproc: 4080000.remoteproc running (/sys/class/remoteproc/remoteproc0) fw=mba.mbn
rmtfs: pid='1157' writes_logged=1
qmi dev: /dev/wwan0qmi0 qmi-proxy='1978'
daemons: udevd='1857' dbus='1886' polkitd='1890' ModemManager='1901'
mm plugin: qcom-soc
mm primary port: wwan0qmi0
mm state: connected
mm power state: on
mm access tech: lte
mm signal quality: 70% (recent)
mm operator name: Beeline
mm registration: home
bearer 1: Status connected: yes; interface: wwan0; address: 10.47.129.24;
wwan: wwan0 UP 10.47.129.24/28
wwan up: 1 of 8
routes: 1.1.1.1 dev wwan0 scope link src 10.47.129.24 ;10.10.22.1 dev wwan0 scope link src 10.47.129.24 ;10.47.129.16/28 dev wwan0 scope link src 10.47.129.24 ;77.88.8.8 dev wwan0 scope link src 10.47.129.24 ;89.109.251.21 dev wwan0 scope link src 10.47.129.24 ;89.109.251.22 dev wwan0 scope link src 10.47.129.24 ;89.109.251.23 dev wwan0 scope link src 10.47.129.24 ;194.186.191.1 dev wwan0 scope link src 10.47.129.24 ;
bam-dmux: suspended active_ms=9350 suspended_ms=104936 control=auto
usb0: 172.16.42.1/24 route-to-host: 172.16.42.2 dev usb0 src 172.16.42.1
emmc: writes_completed=0 sectors_written=0
time: 2026-10-02 22:32:45 UTC; set: 1790980272 21.96 REG:registered/attached qmi-dms; probes: 7
dmesg-errs: 0
~ # echo ---wifi; /etc/init.d/aurora-wifi status; echo ---wifilog; cat /run/auro
ra-wifi/wifi.log; cat /run/aurora-wifi/service.log; echo ---hostapdlog; cat /run
/aurora-wifi/hostapd.log
---wifi
service: idle
remoteproc: a204000.remoteproc running (/sys/class/remoteproc/remoteproc1)
crash=0 watchdog=0 fatal=0
wlan0: wlan0: <BROADCAST,MULTICAST,UP,LOWER_UP> ssid aurora-b8f type AP channel 6 (2437 MHz), width: 20 MHz, center1: 2437 MHz
hostapd: pid=2727 0 connects, 0 disconnects
[85.03] WCNSS /sys/class/remoteproc/remoteproc1 state=running
[87.35] wlan0 up addr=<MAC> (wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO')
[88.40] === AP ENABLED ssid=aurora-b8f ch=6 pid=2727 in 78.59s
---wifilog
[9.81] === WIFI START (wait for modem START OK/FAIL up to 300s)
[84.52] modem gate after 74s: [83.58] === START OK in 73.8s (wwan0 10.47.129.24/28, routes: 10.10.22.1 194.186
[85.03] WCNSS /sys/class/remoteproc/remoteproc1 state=running
[87.35] wlan0 up addr=<MAC> (wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO')
[88.40] === AP ENABLED ssid=aurora-b8f ch=6 pid=2727 in 78.59s
[9.81] === WIFI START (wait for modem START OK/FAIL up to 300s)
[84.52] modem gate after 74s: [83.58] === START OK in 73.8s (wwan0 10.47.129.24/28, routes: 10.10.22.1 194.186
[85.03] WCNSS /sys/class/remoteproc/remoteproc1 state=running
[87.35] wlan0 up addr=<MAC> (wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO')
[88.40] === AP ENABLED ssid=aurora-b8f ch=6 pid=2727 in 78.59s
=== service start rc=0 88.41
---hostapdlog
1790980337.783765: VLAN: vlan_set_name_type: SET_VLAN_NAME_TYPE_CMD name_type=2 failed: No error information
1790980337.896921: wlan0: interface state UNINITIALIZED->ENABLED
1790980337.897032: wlan0: AP-ENABLED
~ # for r in /sys/class/remoteproc/*; do echo "RP $(cat $r/name)=$(cat $r/state)
"; done; iw dev
RP 4080000.remoteproc=running
RP a204000.remoteproc=running
phy#0
Interface wlan0
ifindex 12
wdev 0x1
addr <MAC>
ssid aurora-b8f
type AP
channel 6 (2437 MHz), width: 20 MHz, center1: 2437 MHz
txpower 20.00 dBm
multicast TXQ:
qsz-byt qsz-pkt flows drops marks overlmt hashcol tx-bytes tx-packets
0 0 0 0 0 0 0 0 0
~ # echo ---dmesg-wifi; dmesg | grep -iE "wcn36xx|wcnss|a204000|cfg80211|aurora-
wifi|crash|watchdog"
---dmesg-wifi
[ 0.000000] OF: reserved mem: 0x000000008b600000..0x000000008bbfffff (6144 KiB) nomap non-reusable wcnss@8b600000
[ 0.965312] remoteproc remoteproc0: releasing a204000.remoteproc
[ 1.002622] qcom-wcnss-pil a204000.remoteproc: supply vddcx not found, using dummy regulator
[ 1.011184] a204000.remoteproc.iris: failed to get regulators
[ 1.023968] remoteproc remoteproc0: releasing a204000.remoteproc
[ 1.051759] qcom-wcnss-pil a204000.remoteproc: supply vddcx not found, using dummy regulator
[ 1.062237] remoteproc remoteproc1: a204000.remoteproc is available
[ 1.419707] remoteproc remoteproc1: Direct firmware load for wcnss.mdt failed with error -2
[ 1.422378] remoteproc remoteproc1: powering up a204000.remoteproc
[ 1.430632] remoteproc remoteproc1: Direct firmware load for wcnss.mdt failed with error -2
[ 1.826329] cfg80211: Loading compiled-in X.509 certificates for regulatory database
[ 1.845885] cfg80211: failed to load regulatory.db
[ 9.964582] [aurora-wifi] === WIFI START (wait for modem START OK/FAIL up to 300s)
[ 84.671514] [aurora-wifi] modem gate after 74s: [83.58] === START OK in 73.8s (wwan0 10.47.129.24/28, routes: 10.10.22.1 194.186
[ 84.688451] remoteproc remoteproc1: powering up a204000.remoteproc
[ 84.690305] remoteproc remoteproc1: Booting fw image wcnss.mdt, size 7260
[ 85.175943] remoteproc remoteproc1: remote processor a204000.remoteproc is now up
[ 85.186871] [aurora-wifi] WCNSS /sys/class/remoteproc/remoteproc1 state=running
[ 85.301221] qcom_wcnss_ctrl remoteproc1:smd-edge.WCNSS_CTRL.-1.-1: WCNSS Version 1.5 1.2
[ 85.321899] wcn36xx: mac address: <MAC>
[ 87.439645] wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO' and CRM version 'CNSS-PR-1-4-2-c4-00084'
[ 87.454042] wcn36xx: firmware API 1.5.1.2, 41 stations, 2 bssids
[ 87.502627] [aurora-wifi] wlan0 up addr=<MAC> (wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO')
[ 88.553268] [aurora-wifi] === AP ENABLED ssid=aurora-b8f ch=6 pid=2727 in 78.59s
~ # echo ---ping; ping -c4 -W3 -I wwan0 77.88.8.8 | tail -2
---ping
4 packets transmitted, 4 packets received, 0% packet loss
round-trip min/avg/max = 52.127/95.256/200.200 ms
~ # echo ---display; /etc/init.d/aurora-display status; cat /run/aurora-display/
display.log; cat /run/aurora-display/service.log
---display
fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=0 bl=1
[7.76] display pipe already enabled (by fbcon takeover) - no unblank needed
[7.77] backlight on -> bl_power=0 actual_brightness=1
[7.83] === DISPLAY READY fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=0 bl=1
[7.67] start: fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=4 bl=1
[7.69] fbcon bound to fb0
[7.76] display pipe already enabled (by fbcon takeover) - no unblank needed
[7.77] backlight on -> bl_power=0 actual_brightness=1
[7.83] === DISPLAY READY fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=0 bl=1
=== service start rc=0 7.84
~ # echo ---consoles; cat /sys/class/tty/console/active; for v in /sys/class/vtc
onsole/vtcon*; do echo "$v $(cat $v/bind) $(cat $v/name)"; done; ls -l /proc/[0-
9]*/fd/0 2>/dev/null | grep -E "ttyMSM0|tty1|console" | sed "s/.* \/proc/\/proc/
"
---consoles
tty0 ttyMSM0
/sys/class/vtconsole/vtcon0 0 (S) dummy device
/sys/class/vtconsole/vtcon1 1 (M) frame buffer device
/proc/1/fd/0 -> /dev/console
/proc/1119/fd/0 -> /dev/ttyMSM0
/proc/625/fd/0 -> /dev/tty1
~ # echo ---getty; hostname; ps | grep -E "[g]etty|[c]ttyhack| sh$"
---getty
aurora
625 root getty 0 tty1 linux
1119 root sh
~ # echo ---fb; ls -l /dev/dri/card0 /dev/fb0; for f in name bits_per_pixel virt
ual_size stride; do echo "fb0 $f=$(cat /sys/class/graphics/fb0/$f)"; done; cat /
sys/class/drm/card0-SPI-1/enabled /sys/class/drm/card0-SPI-1/dpms
---fb
crw------- 1 root root 226, 0 Oct 2 22:31 /dev/dri/card0
crw------- 1 root root 29, 0 Oct 2 22:31 /dev/fb0
fb0 name=panel-mipi-dbid
fb0 bits_per_pixel=16
fb0 virtual_size=128,128
fb0 stride=256
enabled
On
~ # echo ---regs; for r in /sys/class/regulator/regulator.*; do n=$(cat $r/name)
; case $n in l6|l17) echo "$n $(cat $r/state) $(cat $r/microvolts) users=$(cat $
r/num_users)";; esac; done
---regs
l17 enabled 2850000 users=1
l6 enabled 1800000 users=1
~ # echo ---bl; for f in bl_power brightness actual_brightness; do echo "bl $f=$
(cat /sys/class/backlight/backlight/$f)"; done
---bl
bl bl_power=0
bl brightness=1
bl actual_brightness=1
~ # echo ---dmesg-display; dmesg | grep -iE "drm|panel|mipi|spi_qup|78b8000|fbco
n|Console: |frame buffer|backlight|aurora-display|l17"
---dmesg-display
[ 0.000000] Kernel command line: earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0
[ 0.010994] Console: colour dummy device 80x25
[ 0.715619] spi_qup 78b8000.spi: IN:block:16, fifo:64, OUT:block:16, fifo:64
[ 1.056985] l17: Bringing 0uV into 2850000-2850000uV
[ 1.430753] [drm] Initialized panel-mipi-dbi 1.0.0 for spi0.0 on minor 0
[ 1.767397] Console: switching to colour frame buffer device 21x16
[ 1.813450] panel-mipi-dbi-spi spi0.0: [drm] fb0: panel-mipi-dbid frame buffer device
[ 7.827222] [aurora-display] start: fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=4 bl=1
[ 7.842854] [aurora-display] fbcon bound to fb0
[ 7.908096] [aurora-display] display pipe already enabled (by fbcon takeover) - no unblank needed
[ 7.922579] [aurora-display] backlight on -> bl_power=0 actual_brightness=1
[ 7.987211] [aurora-display] === DISPLAY READY fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=0 bl=1
~ # echo ---display-errors; dmesg | grep -iE "drm|panel|mipi|spi0|fbcon|backligh
t|aurora-display" | grep -ciE "err|fail|timeout|warn"
---display-errors
0
~ # echo ---emmc; awk "{print \"w=\"\$5\" s=\"\$7}" /sys/block/mmcblk0/stat
---emmc
w=0 s=0
~ # echo SNAP-END
SNAP-END
~ # 

View file

@ -0,0 +1,11 @@
22:36:40.791 B9C cold3: waiting for the board to go away (power off >= 90 s), then normal power-on WITHOUT RESET
22:36:41.800 board unreachable (powered off)
22:37:58.090 NCM ping ok
22:37:58.094 RTC at boot 3 s -> class A
~ # cat /proc/device-tree/model; echo; uname -r; grep -E "START OK|FAIL in|rollb
JZ08AU Aurora (RAM boot B9B)
[85.70] === START OK in 76.3s (wwan0 10.46.48.247/28, routes: 10.10.22.1 194.186.191.1 77.88.8.8 1.1.1.1 )
22:39:34.245 wifi: [89.59] === AP ENABLED ssid=aurora-b8f ch=6 pid=2875 in 80.16s
22:39:42.268 sntp: [101.14] SNTP check ( 89.109.251.21 89.109.251.22 89.109.251.23): 14 replies; best offset delay server: +0.094072 0.039913 89.109.251.21: (offset > 0 = clock behind)
22:40:08.281 snapshot: 2 end markers; RP a204000.remoteproc=running
22:40:13.313 B9C cold3 END - operator visual check next

View file

@ -0,0 +1,200 @@
<EFBFBD><EFBFBD><01><><1F><><01><>
BusyBox v1.37.0 (Debian 1:1.37.0-6+b9) built-in shell (ash)
Enter 'help' for a list of built-in commands.
~ # echo SNAP-BEGIN; cat /proc/uptime; date -u; cat /proc/device-tree/model; ech
o; uname -a; cat /proc/cmdline
SNAP-BEGIN
115.38 418.39
Fri Oct 2 22:39:43 UTC 2026
JZ08AU Aurora (RAM boot B9B)
Linux aurora 7.2.7-aurora-b9c #9 SMP PREEMPT Sat Oct 3 03:06:50 +06 2026 aarch64 GNU/Linux
earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0
~ # echo ---time; cat /run/aurora-modem/time-set; grep -E "TIME|SNTP" /run/auror
a-modem/lifecycle.log | tail -4
---time
1790980689 21.17 REG:not-registered-searching/detached qmi-dms
[24.73] TIME probe 7 [REGISTERED]: dms_ms=1475015892501 dms_utc=1790980692.501 nitz=2026-10-02 22:38:12 dms-nitz=+0.54 clock=1790980692 -> VALID (ok)
[85.85] TIME probe 8 [BEARER_CONNECTED]: dms_ms=1475015953596 dms_utc=1790980753.596 nitz=2026-10-02 22:39:13 dms-nitz=+0.64 clock=1790980753 -> VALID (ok)
[101.14] SNTP check ( 89.109.251.21 89.109.251.22 89.109.251.23): 14 replies; best offset delay server: +0.094072 0.039913 89.109.251.21: (offset > 0 = clock behind)
[101.16] SNTP: |offset| < 1s - clock kept (no slew: STA_UNSYNC stays, RTC_SYSTOHC never engages)
~ # echo ---modem; /etc/init.d/aurora-modem status
---modem
service: idle
controller: BEARER_CONNECTED
remoteproc: 4080000.remoteproc running (/sys/class/remoteproc/remoteproc0) fw=mba.mbn
rmtfs: pid='1159' writes_logged=1
qmi dev: /dev/wwan0qmi0 qmi-proxy='2129'
daemons: udevd='2009' dbus='2037' polkitd='2041' ModemManager='2052'
mm plugin: qcom-soc
mm primary port: wwan0qmi0
mm state: connected
mm power state: on
mm access tech: lte
mm signal quality: 57% (recent)
mm operator name: Beeline
mm registration: home
bearer 1: Status connected: yes; interface: wwan0; address: 10.46.48.247;
wwan: wwan0 UP 10.46.48.247/28
wwan up: 1 of 8
routes: 1.1.1.1 dev wwan0 scope link src 10.46.48.247 ;10.10.22.1 dev wwan0 scope link src 10.46.48.247 ;10.46.48.240/28 dev wwan0 scope link src 10.46.48.247 ;77.88.8.8 dev wwan0 scope link src 10.46.48.247 ;89.109.251.21 dev wwan0 scope link src 10.46.48.247 ;89.109.251.22 dev wwan0 scope link src 10.46.48.247 ;89.109.251.23 dev wwan0 scope link src 10.46.48.247 ;194.186.191.1 dev wwan0 scope link src 10.46.48.247 ;
bam-dmux: suspended active_ms=10351 suspended_ms=104686 control=auto
usb0: 172.16.42.1/24 route-to-host: 172.16.42.2 dev usb0 src 172.16.42.1
emmc: writes_completed=0 sectors_written=0
time: 2026-10-02 22:39:43 UTC; set: 1790980689 21.17 REG:not-registered-searching/detached qmi-dms; probes: 8
dmesg-errs: 0
~ # echo ---wifi; /etc/init.d/aurora-wifi status; echo ---wifilog; cat /run/auro
ra-wifi/wifi.log; cat /run/aurora-wifi/service.log; echo ---hostapdlog; cat /run
/aurora-wifi/hostapd.log
---wifi
service: idle
remoteproc: a204000.remoteproc running (/sys/class/remoteproc/remoteproc1)
crash=0 watchdog=0 fatal=0
wlan0: wlan0: <BROADCAST,MULTICAST,UP,LOWER_UP> ssid aurora-b8f type AP channel 6 (2437 MHz), width: 20 MHz, center1: 2437 MHz
hostapd: pid=2875 0 connects, 0 disconnects
[86.69] WCNSS /sys/class/remoteproc/remoteproc1 state=running
[88.53] wlan0 up addr=<MAC> (wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO')
[89.59] === AP ENABLED ssid=aurora-b8f ch=6 pid=2875 in 80.16s
---wifilog
[9.44] === WIFI START (wait for modem START OK/FAIL up to 300s)
[86.19] modem gate after 76s: [85.70] === START OK in 76.3s (wwan0 10.46.48.247/28, routes: 10.10.22.1 194.186
[86.69] WCNSS /sys/class/remoteproc/remoteproc1 state=running
[88.53] wlan0 up addr=<MAC> (wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO')
[89.59] === AP ENABLED ssid=aurora-b8f ch=6 pid=2875 in 80.16s
[9.44] === WIFI START (wait for modem START OK/FAIL up to 300s)
[86.19] modem gate after 76s: [85.70] === START OK in 76.3s (wwan0 10.46.48.247/28, routes: 10.10.22.1 194.186
[86.69] WCNSS /sys/class/remoteproc/remoteproc1 state=running
[88.53] wlan0 up addr=<MAC> (wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO')
[89.59] === AP ENABLED ssid=aurora-b8f ch=6 pid=2875 in 80.16s
=== service start rc=0 89.61
---hostapdlog
1790980756.755702: VLAN: vlan_set_name_type: SET_VLAN_NAME_TYPE_CMD name_type=2 failed: No error information
1790980756.855176: wlan0: interface state UNINITIALIZED->ENABLED
1790980756.855299: wlan0: AP-ENABLED
~ # for r in /sys/class/remoteproc/*; do echo "RP $(cat $r/name)=$(cat $r/state)
"; done; iw dev
RP 4080000.remoteproc=running
RP a204000.remoteproc=running
phy#0
Interface wlan0
ifindex 12
wdev 0x1
addr <MAC>
ssid aurora-b8f
type AP
channel 6 (2437 MHz), width: 20 MHz, center1: 2437 MHz
txpower 20.00 dBm
multicast TXQ:
qsz-byt qsz-pkt flows drops marks overlmt hashcol tx-bytes tx-packets
0 0 0 0 0 0 0 0 0
~ # echo ---dmesg-wifi; dmesg | grep -iE "wcn36xx|wcnss|a204000|cfg80211|aurora-
wifi|crash|watchdog"
---dmesg-wifi
[ 0.000000] OF: reserved mem: 0x000000008b600000..0x000000008bbfffff (6144 KiB) nomap non-reusable wcnss@8b600000
[ 0.957567] remoteproc remoteproc0: releasing a204000.remoteproc
[ 0.994394] qcom-wcnss-pil a204000.remoteproc: supply vddcx not found, using dummy regulator
[ 1.003641] a204000.remoteproc.iris: failed to get regulators
[ 1.016164] remoteproc remoteproc0: releasing a204000.remoteproc
[ 1.042751] qcom-wcnss-pil a204000.remoteproc: supply vddcx not found, using dummy regulator
[ 1.049686] remoteproc remoteproc1: a204000.remoteproc is available
[ 1.073565] cfg80211: Loading compiled-in X.509 certificates for regulatory database
[ 1.410083] remoteproc remoteproc1: Direct firmware load for wcnss.mdt failed with error -2
[ 1.412861] cfg80211: failed to load regulatory.db
[ 1.412895] remoteproc remoteproc1: powering up a204000.remoteproc
[ 1.440730] remoteproc remoteproc1: Direct firmware load for wcnss.mdt failed with error -2
[ 9.592677] [aurora-wifi] === WIFI START (wait for modem START OK/FAIL up to 300s)
[ 86.337924] [aurora-wifi] modem gate after 76s: [85.70] === START OK in 76.3s (wwan0 10.46.48.247/28, routes: 10.10.22.1 194.186
[ 86.365190] remoteproc remoteproc1: powering up a204000.remoteproc
[ 86.370800] remoteproc remoteproc1: Booting fw image wcnss.mdt, size 7260
[ 86.834752] remoteproc remoteproc1: remote processor a204000.remoteproc is now up
[ 86.843016] [aurora-wifi] WCNSS /sys/class/remoteproc/remoteproc1 state=running
[ 86.959391] qcom_wcnss_ctrl remoteproc1:smd-edge.WCNSS_CTRL.-1.-1: WCNSS Version 1.5 1.2
[ 86.984542] wcn36xx: mac address: <MAC>
[ 88.623626] wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO' and CRM version 'CNSS-PR-1-4-2-c4-00084'
[ 88.638275] wcn36xx: firmware API 1.5.1.2, 41 stations, 2 bssids
[ 88.686700] [aurora-wifi] wlan0 up addr=<MAC> (wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO')
[ 89.749483] [aurora-wifi] === AP ENABLED ssid=aurora-b8f ch=6 pid=2875 in 80.16s
~ # echo ---ping; ping -c4 -W3 -I wwan0 77.88.8.8 | tail -2
---ping
4 packets transmitted, 4 packets received, 0% packet loss
round-trip min/avg/max = 54.312/93.723/199.633 ms
~ # echo ---display; /etc/init.d/aurora-display status; cat /run/aurora-display/
display.log; cat /run/aurora-display/service.log
---display
fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=0 bl=1
[7.28] display pipe already enabled (by fbcon takeover) - no unblank needed
[7.29] backlight on -> bl_power=0 actual_brightness=1
[7.35] === DISPLAY READY fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=0 bl=1
[7.20] start: fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=4 bl=1
[7.22] fbcon bound to fb0
[7.28] display pipe already enabled (by fbcon takeover) - no unblank needed
[7.29] backlight on -> bl_power=0 actual_brightness=1
[7.35] === DISPLAY READY fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=0 bl=1
=== service start rc=0 7.36
~ # echo ---consoles; cat /sys/class/tty/console/active; for v in /sys/class/vtc
onsole/vtcon*; do echo "$v $(cat $v/bind) $(cat $v/name)"; done; ls -l /proc/[0-
9]*/fd/0 2>/dev/null | grep -E "ttyMSM0|tty1|console" | sed "s/.* \/proc/\/proc/
"
---consoles
tty0 ttyMSM0
/sys/class/vtconsole/vtcon0 0 (S) dummy device
/sys/class/vtconsole/vtcon1 1 (M) frame buffer device
/proc/1/fd/0 -> /dev/console
/proc/1121/fd/0 -> /dev/ttyMSM0
/proc/627/fd/0 -> /dev/tty1
~ # echo ---getty; hostname; ps | grep -E "[g]etty|[c]ttyhack| sh$"
---getty
aurora
627 root getty 0 tty1 linux
1121 root sh
~ # echo ---fb; ls -l /dev/dri/card0 /dev/fb0; for f in name bits_per_pixel virt
ual_size stride; do echo "fb0 $f=$(cat /sys/class/graphics/fb0/$f)"; done; cat /
sys/class/drm/card0-SPI-1/enabled /sys/class/drm/card0-SPI-1/dpms
---fb
crw------- 1 root root 226, 0 Oct 2 22:38 /dev/dri/card0
crw------- 1 root root 29, 0 Oct 2 22:38 /dev/fb0
fb0 name=panel-mipi-dbid
fb0 bits_per_pixel=16
fb0 virtual_size=128,128
fb0 stride=256
enabled
On
~ # echo ---regs; for r in /sys/class/regulator/regulator.*; do n=$(cat $r/name)
; case $n in l6|l17) echo "$n $(cat $r/state) $(cat $r/microvolts) users=$(cat $
r/num_users)";; esac; done
---regs
l17 enabled 2850000 users=1
l6 enabled 1800000 users=1
~ # echo ---bl; for f in bl_power brightness actual_brightness; do echo "bl $f=$
(cat /sys/class/backlight/backlight/$f)"; done
---bl
bl bl_power=0
bl brightness=1
bl actual_brightness=1
~ # echo ---dmesg-display; dmesg | grep -iE "drm|panel|mipi|spi_qup|78b8000|fbco
n|Console: |frame buffer|backlight|aurora-display|l17"
---dmesg-display
[ 0.000000] Kernel command line: earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0
[ 0.010997] Console: colour dummy device 80x25
[ 0.708997] spi_qup 78b8000.spi: IN:block:16, fifo:64, OUT:block:16, fifo:64
[ 1.057948] l17: Bringing 0uV into 2850000-2850000uV
[ 1.412965] [drm] Initialized panel-mipi-dbi 1.0.0 for spi0.0 on minor 0
[ 1.782025] Console: switching to colour frame buffer device 21x16
[ 1.820979] panel-mipi-dbi-spi spi0.0: [drm] fb0: panel-mipi-dbid frame buffer device
[ 7.354443] [aurora-display] start: fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=4 bl=1
[ 7.375150] [aurora-display] fbcon bound to fb0
[ 7.429145] [aurora-display] display pipe already enabled (by fbcon takeover) - no unblank needed
[ 7.438990] [aurora-display] backlight on -> bl_power=0 actual_brightness=1
[ 7.505174] [aurora-display] === DISPLAY READY fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=0 bl=1
~ # echo ---display-errors; dmesg | grep -iE "drm|panel|mipi|spi0|fbcon|backligh
t|aurora-display" | grep -ciE "err|fail|timeout|warn"
---display-errors
0
~ # echo ---emmc; awk "{print \"w=\"\$5\" s=\"\$7}" /sys/block/mmcblk0/stat
---emmc
w=0 s=0
~ # echo SNAP-END
SNAP-END
~ # 

View file

@ -0,0 +1,22 @@
=== 21:13:37 bl off
[165.04] backlight off -> bl_power=0 actual_brightness=0
=== 21:15:16 bl on
[264.48] backlight on -> bl_power=0 actual_brightness=1
VCS-BEGIN
0 = clock behind)
[ 94.748364] [auror
a-modem] SNTP: |offse
t| < 1s - clock kept
(no slew: STA_UNSYNC
stays, RTC_SYSTOHC ne
ver engages)
[ 165.192028] [auror
a-display] backlight
off -> bl_power=0 act
ual_brightness=0
[ 264.634290] [auror
a-display] backlight
on -> bl_power=0 actu
al_brightness=1
VCS-END

View file

@ -0,0 +1,15 @@
21:08:25.167 B9C ram1: waiting for fastboot <EMMC_SERIAL> (power off >= 90 s, then RESET held + battery -> USB)
21:10:51.321 fastboot present
Sending 'boot.img' (24964 KB) OKAY [ 0.788s]
Booting OKAY [ 0.537s]
Finished. Total time: 1.347s
rc=0
21:11:04.685 NCM ping ok
21:11:04.688 RTC at boot 6 s -> class A
~ # cat /proc/device-tree/model; echo; uname -r; grep -E "START OK|FAIL in|rollb
JZ08AU Aurora (RAM boot B9B)
[79.16] === START OK in 69.2s (wwan0 10.40.174.62/30, routes: 10.10.22.3 194.186.191.1 77.88.8.8 1.1.1.1 )
21:12:30.772 wifi: [83.49] === AP ENABLED ssid=aurora-b8f ch=6 pid=2798 in 73.51s
21:12:38.787 sntp: [94.58] SNTP check ( 89.109.251.21 89.109.251.22 89.109.251.23): 14 replies; best offset delay server: +0.200034 0.058931 89.109.251.23: (offset > 0 = clock behind)
21:13:04.797 snapshot: 2 end markers; RP a204000.remoteproc=running
21:13:09.819 B9C ram1 END - operator visual check next

View file

@ -0,0 +1,200 @@
<EFBFBD><EFBFBD><01><><1F><><01><>
BusyBox v1.37.0 (Debian 1:1.37.0-6+b9) built-in shell (ash)
Enter 'help' for a list of built-in commands.
~ # echo SNAP-BEGIN; cat /proc/uptime; date -u; cat /proc/device-tree/model; ech
o; uname -a; cat /proc/cmdline
SNAP-BEGIN
106.35 382.47
Fri Oct 2 21:12:39 UTC 2026
JZ08AU Aurora (RAM boot B9B)
Linux aurora 7.2.7-aurora-b9c #9 SMP PREEMPT Sat Oct 3 03:06:50 +06 2026 aarch64 GNU/Linux
earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0
~ # echo ---time; cat /run/aurora-modem/time-set; grep -E "TIME|SNTP" /run/auror
a-modem/lifecycle.log | tail -4
---time
1790975479 25.72 REG:registered/attached qmi-dms
[25.88] TIME probe 7 [REGISTERED]: dms_ms=1475010679079 dms_utc=1790975479.079 nitz=2026-10-02 21:11:19 dms-nitz=+0.12 clock=1790975479 -> VALID (ok)
[79.27] TIME probe 8 [BEARER_CONNECTED]: dms_ms=1475010732480 dms_utc=1790975532.480 nitz=2026-10-02 21:12:12 dms-nitz=+0.52 clock=1790975532 -> VALID (ok)
[94.58] SNTP check ( 89.109.251.21 89.109.251.22 89.109.251.23): 14 replies; best offset delay server: +0.200034 0.058931 89.109.251.23: (offset > 0 = clock behind)
[94.60] SNTP: |offset| < 1s - clock kept (no slew: STA_UNSYNC stays, RTC_SYSTOHC never engages)
~ # echo ---modem; /etc/init.d/aurora-modem status
---modem
service: idle
controller: BEARER_CONNECTED
remoteproc: 4080000.remoteproc running (/sys/class/remoteproc/remoteproc0) fw=mba.mbn
rmtfs: pid='1157' writes_logged=1
qmi dev: /dev/wwan0qmi0 qmi-proxy='2131'
daemons: udevd='2008' dbus='2039' polkitd='2043' ModemManager='2054'
mm plugin: qcom-soc
mm primary port: wwan0qmi0
mm state: connected
mm power state: on
mm access tech: lte
mm signal quality: 75% (recent)
mm operator name: Beeline
mm registration: home
bearer 1: Status connected: yes; interface: wwan0; address: 10.40.174.62;
wwan: wwan0 UP 10.40.174.62/30
wwan up: 1 of 8
routes: 1.1.1.1 dev wwan0 scope link src 10.40.174.62 ;10.10.22.3 dev wwan0 scope link src 10.40.174.62 ;10.40.174.60/30 dev wwan0 scope link src 10.40.174.62 ;77.88.8.8 dev wwan0 scope link src 10.40.174.62 ;89.109.251.21 dev wwan0 scope link src 10.40.174.62 ;89.109.251.22 dev wwan0 scope link src 10.40.174.62 ;89.109.251.23 dev wwan0 scope link src 10.40.174.62 ;194.186.191.1 dev wwan0 scope link src 10.40.174.62 ;
bam-dmux: suspended active_ms=10408 suspended_ms=95595 control=auto
usb0: 172.16.42.1/24 route-to-host: 172.16.42.2 dev usb0 src 172.16.42.1
emmc: writes_completed=0 sectors_written=0
time: 2026-10-02 21:12:40 UTC; set: 1790975479 25.72 REG:registered/attached qmi-dms; probes: 8
dmesg-errs: 0
~ # echo ---wifi; /etc/init.d/aurora-wifi status; echo ---wifilog; cat /run/auro
ra-wifi/wifi.log; cat /run/aurora-wifi/service.log; echo ---hostapdlog; cat /run
/aurora-wifi/hostapd.log
---wifi
service: idle
remoteproc: a204000.remoteproc running (/sys/class/remoteproc/remoteproc1)
crash=0 watchdog=0 fatal=0
wlan0: wlan0: <BROADCAST,MULTICAST,UP,LOWER_UP> ssid aurora-b8f type AP channel 6 (2437 MHz), width: 20 MHz, center1: 2437 MHz
hostapd: pid=2798 0 connects, 0 disconnects
[80.14] WCNSS /sys/class/remoteproc/remoteproc1 state=running
[82.43] wlan0 up addr=<MAC> (wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO')
[83.49] === AP ENABLED ssid=aurora-b8f ch=6 pid=2798 in 73.51s
---wifilog
[9.97] === WIFI START (wait for modem START OK/FAIL up to 300s)
[79.64] modem gate after 69s: [79.16] === START OK in 69.2s (wwan0 10.40.174.62/30, routes: 10.10.22.3 194.186
[80.14] WCNSS /sys/class/remoteproc/remoteproc1 state=running
[82.43] wlan0 up addr=<MAC> (wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO')
[83.49] === AP ENABLED ssid=aurora-b8f ch=6 pid=2798 in 73.51s
[9.97] === WIFI START (wait for modem START OK/FAIL up to 300s)
[79.64] modem gate after 69s: [79.16] === START OK in 69.2s (wwan0 10.40.174.62/30, routes: 10.10.22.3 194.186
[80.14] WCNSS /sys/class/remoteproc/remoteproc1 state=running
[82.43] wlan0 up addr=<MAC> (wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO')
[83.49] === AP ENABLED ssid=aurora-b8f ch=6 pid=2798 in 73.51s
=== service start rc=0 83.49
---hostapdlog
1790975536.099229: VLAN: vlan_set_name_type: SET_VLAN_NAME_TYPE_CMD name_type=2 failed: No error information
1790975536.207331: wlan0: interface state UNINITIALIZED->ENABLED
1790975536.207374: wlan0: AP-ENABLED
~ # for r in /sys/class/remoteproc/*; do echo "RP $(cat $r/name)=$(cat $r/state)
"; done; iw dev
RP 4080000.remoteproc=running
RP a204000.remoteproc=running
phy#0
Interface wlan0
ifindex 12
wdev 0x1
addr <MAC>
ssid aurora-b8f
type AP
channel 6 (2437 MHz), width: 20 MHz, center1: 2437 MHz
txpower 20.00 dBm
multicast TXQ:
qsz-byt qsz-pkt flows drops marks overlmt hashcol tx-bytes tx-packets
0 0 0 0 0 0 0 0 0
~ # echo ---dmesg-wifi; dmesg | grep -iE "wcn36xx|wcnss|a204000|cfg80211|aurora-
wifi|crash|watchdog"
---dmesg-wifi
[ 0.000000] OF: reserved mem: 0x000000008b600000..0x000000008bbfffff (6144 KiB) nomap non-reusable wcnss@8b600000
[ 0.961935] remoteproc remoteproc0: releasing a204000.remoteproc
[ 1.003548] qcom-wcnss-pil a204000.remoteproc: supply vddcx not found, using dummy regulator
[ 1.013128] a204000.remoteproc.iris: failed to get regulators
[ 1.025283] remoteproc remoteproc0: releasing a204000.remoteproc
[ 1.052213] qcom-wcnss-pil a204000.remoteproc: supply vddcx not found, using dummy regulator
[ 1.059124] remoteproc remoteproc1: a204000.remoteproc is available
[ 1.412647] remoteproc remoteproc1: Direct firmware load for wcnss.mdt failed with error -2
[ 1.415410] remoteproc remoteproc1: powering up a204000.remoteproc
[ 1.423546] remoteproc remoteproc1: Direct firmware load for wcnss.mdt failed with error -2
[ 1.820229] cfg80211: Loading compiled-in X.509 certificates for regulatory database
[ 1.844138] cfg80211: failed to load regulatory.db
[ 10.128085] [aurora-wifi] === WIFI START (wait for modem START OK/FAIL up to 300s)
[ 79.793435] [aurora-wifi] modem gate after 69s: [79.16] === START OK in 69.2s (wwan0 10.40.174.62/30, routes: 10.10.22.3 194.186
[ 79.810171] remoteproc remoteproc1: powering up a204000.remoteproc
[ 79.812850] remoteproc remoteproc1: Booting fw image wcnss.mdt, size 7260
[ 80.285375] remoteproc remoteproc1: remote processor a204000.remoteproc is now up
[ 80.293907] [aurora-wifi] WCNSS /sys/class/remoteproc/remoteproc1 state=running
[ 80.405386] qcom_wcnss_ctrl remoteproc1:smd-edge.WCNSS_CTRL.-1.-1: WCNSS Version 1.5 1.2
[ 80.430465] wcn36xx: mac address: <MAC>
[ 82.520309] wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO' and CRM version 'CNSS-PR-1-4-2-c4-00084'
[ 82.534379] wcn36xx: firmware API 1.5.1.2, 41 stations, 2 bssids
[ 82.582629] [aurora-wifi] wlan0 up addr=<MAC> (wcn36xx: firmware WLAN version 'WCN v2.0 RadioPhy vUnknown with 19.2MHz XO')
[ 83.641068] [aurora-wifi] === AP ENABLED ssid=aurora-b8f ch=6 pid=2798 in 73.51s
~ # echo ---ping; ping -c4 -W3 -I wwan0 77.88.8.8 | tail -2
---ping
4 packets transmitted, 4 packets received, 0% packet loss
round-trip min/avg/max = 46.725/88.795/198.153 ms
~ # echo ---display; /etc/init.d/aurora-display status; cat /run/aurora-display/
display.log; cat /run/aurora-display/service.log
---display
fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=0 bl=1
[7.94] display pipe already enabled (by fbcon takeover) - no unblank needed
[7.95] backlight on -> bl_power=0 actual_brightness=1
[8.01] === DISPLAY READY fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=0 bl=1
[7.88] start: fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=4 bl=1
[7.89] fbcon bound to fb0
[7.94] display pipe already enabled (by fbcon takeover) - no unblank needed
[7.95] backlight on -> bl_power=0 actual_brightness=1
[8.01] === DISPLAY READY fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=0 bl=1
=== service start rc=0 8.02
~ # echo ---consoles; cat /sys/class/tty/console/active; for v in /sys/class/vtc
onsole/vtcon*; do echo "$v $(cat $v/bind) $(cat $v/name)"; done; ls -l /proc/[0-
9]*/fd/0 2>/dev/null | grep -E "ttyMSM0|tty1|console" | sed "s/.* \/proc/\/proc/
"
---consoles
tty0 ttyMSM0
/sys/class/vtconsole/vtcon0 0 (S) dummy device
/sys/class/vtconsole/vtcon1 1 (M) frame buffer device
/proc/1/fd/0 -> /dev/console
/proc/1119/fd/0 -> /dev/ttyMSM0
/proc/624/fd/0 -> /dev/tty1
~ # echo ---getty; hostname; ps | grep -E "[g]etty|[c]ttyhack| sh$"
---getty
aurora
624 root getty 0 tty1 linux
1119 root sh
~ # echo ---fb; ls -l /dev/dri/card0 /dev/fb0; for f in name bits_per_pixel virt
ual_size stride; do echo "fb0 $f=$(cat /sys/class/graphics/fb0/$f)"; done; cat /
sys/class/drm/card0-SPI-1/enabled /sys/class/drm/card0-SPI-1/dpms
---fb
crw------- 1 root root 226, 0 Oct 2 21:11 /dev/dri/card0
crw------- 1 root root 29, 0 Oct 2 21:11 /dev/fb0
fb0 name=panel-mipi-dbid
fb0 bits_per_pixel=16
fb0 virtual_size=128,128
fb0 stride=256
enabled
On
~ # echo ---regs; for r in /sys/class/regulator/regulator.*; do n=$(cat $r/name)
; case $n in l6|l17) echo "$n $(cat $r/state) $(cat $r/microvolts) users=$(cat $
r/num_users)";; esac; done
---regs
l17 enabled 2850000 users=1
l6 enabled 1800000 users=1
~ # echo ---bl; for f in bl_power brightness actual_brightness; do echo "bl $f=$
(cat /sys/class/backlight/backlight/$f)"; done
---bl
bl bl_power=0
bl brightness=1
bl actual_brightness=1
~ # echo ---dmesg-display; dmesg | grep -iE "drm|panel|mipi|spi_qup|78b8000|fbco
n|Console: |frame buffer|backlight|aurora-display|l17"
---dmesg-display
[ 0.000000] Kernel command line: earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0
[ 0.010996] Console: colour dummy device 80x25
[ 0.714412] spi_qup 78b8000.spi: IN:block:16, fifo:64, OUT:block:16, fifo:64
[ 1.053503] l17: Bringing 0uV into 2850000-2850000uV
[ 1.423634] [drm] Initialized panel-mipi-dbi 1.0.0 for spi0.0 on minor 0
[ 1.769095] Console: switching to colour frame buffer device 21x16
[ 1.811271] panel-mipi-dbi-spi spi0.0: [drm] fb0: panel-mipi-dbid frame buffer device
[ 8.030612] [aurora-display] start: fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=4 bl=1
[ 8.045081] [aurora-display] fbcon bound to fb0
[ 8.090388] [aurora-display] display pipe already enabled (by fbcon takeover) - no unblank needed
[ 8.103591] [aurora-display] backlight on -> bl_power=0 actual_brightness=1
[ 8.163651] [aurora-display] === DISPLAY READY fb0=panel-mipi-dbid fbcon=bound conn=enabled/On l17_users=1 bl_power=0 bl=1
~ # echo ---display-errors; dmesg | grep -iE "drm|panel|mipi|spi0|fbcon|backligh
t|aurora-display" | grep -ciE "err|fail|timeout|warn"
---display-errors
0
~ # echo ---emmc; awk "{print \"w=\"\$5\" s=\"\$7}" /sys/block/mmcblk0/stat
---emmc
w=0 s=0
~ # echo SNAP-END
SNAP-END
~ # 

View file

@ -0,0 +1,14 @@
# B9L-0 — lk1st chainloads an unmodified 32-bit lk2nd 23.1 (RAM only) — PASS (2026-10-03)
RESET-held power-on → lk1st fastboot (`product lk1st-msm8916`) → `fastboot boot b9/b9l/lk2nd-23.1-stock.img`
(= lk2nd-build/out/lk2nd.img 555826ea, FORCE_FASTBOOT). Nothing written.
UART (`l0/uart.log`):
- lk1st: `[1360] fastboot: boot` → `booting linux @ 0x80008000, ramdisk @ 0x82000000 (1), tags/device tree @ 0x81e00000`
- 2nd LK: `welcome to lk` → `lk2nd_init()` → `Booted @ 0x80008000, r0=0x0, r1=0x0, r2=0x81e00000` → `Found valid DTB with 1867 bytes total`
→ `Command line from previous bootloader: lk2nd androidboot.emmc=true …` → `No continuous splash: MDP GDSC is not enabled`
→ `Fastboot mode was forced with compile-time flag.` → `fastboot: processing commands`
- host: `fastboot getvar product` → `lk2nd-msm8916`, `kernel: lk`.
=> A second-stage 32-bit LK runs on the migrated chain (DB410c TZ + qhypstub). Basis for B9L-RAM.
(Driver note: the first identity probe after `boot` raced with lk1st still being enumerated; re-checked by hand.)

View file

@ -0,0 +1,63 @@
# B9L-RAM — ST7735S initialised by a second-stage lk2nd before Linux (RAM only) — PASS (2026-10-03)
Image `b9/b9l/lk2nd-b9l-st7735s.img` **775986e2** = lk2nd 23.1 + `b9/b9l/lk2nd-23.1-aurora-b9l.patch`, without FORCE_FASTBOOT
(`BUILD-B9L.md`). Nothing was written: aboot, boot, cache and eMMC are untouched (mmcblk0 write fields = 0); cache is still B9C b9ce13c9.
## Chain actually used (run `l1x`)
power (RESET) → lk1st fastboot → [B9L-0 left the board in lk2nd 23.1 fastboot] → `fastboot boot` B9L image from lk2nd 23.1
→ B9L lk2nd: ST7735S init → extlinux `b9c` from the eMMC cache → Linux B9C.
This is one extra RAM stage compared with the planned "directly from lk1st" run. The operator asked to boot from the
fastboot that was already running; the panel code path is identical. A direct-from-lk1st repeat is optional (`b9l-ram.sh 1 ram`).
## LK log (`l1x/uart-full.log`)
```
[70] [B9L +0 ms] before: L6 st=82 en=80 L17 st=82 en=80 vset=58 MPP4 mode=00 en=00 sink=00
[80] [B9L +10 ms] before: TLMM 12..15/116/118 cfg=1 (reset default) QUP4 spi CBCR=80000000 (off)
[210] [B9L +140 ms] reset done (GPIO118 high) (1 → 1 ms → 0 → 1 ms → 1 → 120 ms)
[220] B9L: gcc_blsp1_qup4_spi_apps_clk enabled at 16000000 Hz
[230] [B9L +160 ms] after QUP init: TLMM 12/13/15=344 (func1 12 mA) 14=204 (func1 2 mA) 116/118=2c0 out high; CBCR=00000001 RCGR cfg=00002113
[360] [B9L +290 ms] 19 init commands sent, 0 failures; SPI_IO_CONTROL=401 SPI_CONFIG=0 (== stock LK)
[400] [B9L +330 ms] frame 128x128 RGB565 (32768 bytes) sent ret=0
[430] [B9L +360 ms] after backlight: L6 st=82 en=80 L17 st=82 en=80 MPP4 mode=61 en=80 sink=07 (== stock LK)
[450] [B9L +380 ms] ST7735S bring-up end - continuing lk2nd boot
[710] Trying to boot 'b9c' → [1580] booting linux @ 0x80000000
```
**Power question answered:** at LK time **L17 is ON** (STATUS 0x82, EN 0x80) and L6 is ON. They are left on by SBL1/RPM, as the CAF comment says
("enabled in SBL"). No RPM/L17 workaround is needed in LK. The L17-OFF reading of B9A was taken in running Linux without a
panel consumer, so L17 is switched off somewhere between LK and that point (not investigated; irrelevant now because Linux holds L17).
## Linux takeover (UART kernel time)
| t | event |
|---|---|
| 0.72 s | spi_qup 78b8000.spi |
| 1.07 s | `l17: Bringing 0uV into 2850000-2850000uV` (regulator taken by the panel) |
| 1.11 s | clk: disabling unused clocks |
| 1.42 s | `[drm] Initialized panel-mipi-dbi` |
| 1.78 s | `Console: switching to colour frame buffer device 21x16` (fbcon modeset = panel reset + re-init) |
| 7.35 s | aurora-display: backlight on → DISPLAY READY (no unblank needed) |
Then: START OK 73.0 s, AP ENABLED 77.1 s, MPSS + WCNSS running, ping 4/4, display errors 0, eMMC w=0.
## Operator (visual)
1. The test frame with backlight appeared **before Linux**.
2. Colours, orientation and border are correct (same chart as the Linux B9B test).
3. It stayed "about a second or a bit more", then the screen was dark "for about a second", then the Linux console.
The dark gap is the Linux-side handoff: the panel is re-initialised at the fbcon takeover, and MPP4 is set to off by the
gpio-backlight pinctrl state until aurora-display switches it on. The exact moment of the backlight-off was not logged.
The observed gap was shorter than the ~6 s estimate.
## Verdict
PASS: image before Linux, held until the Linux takeover, Linux DRM/fbcon normal, LTE/Wi-Fi/B9C unaffected, no writes.
lk1st is NOT reflashed (needs a separate GO). Optional improvement for later: keep the backlight on across the handoff on the Linux side.
## Formal run `ram1` (2026-10-03 22:16 UTC): directly from lk1st — PASS → B9L-RAM CLOSED
- Image `lk2nd-b9l-swag.img` **e6849a2b**: the same panel code as 775986e2, frame = operator splash `splash/swag.png`
(RGB565 via `splash/mk-splash.py`, blob 87955300). Driver `b9l-ram.sh 1 ram` with a gate: `fastboot boot` only when product == lk1st-msm8916.
- Chain: RESET power-on → `product=lk1st-msm8916` → `fastboot boot` → B9L lk2nd (UART: exactly 2× "welcome to lk") → `Trying to boot 'b9c'` → Linux.
Class A (RTC 5 s).
- LK: L6/L17 st=82 en=80; 16 MHz; `SPI_IO_CONTROL=401 SPI_CONFIG=0`; 19 commands, 0 failures; `frame source: splash image`, sent ret=0;
MPP4 61/80/07; bring-up 380 ms.
- Operator: splash visible before Linux.
- Linux: DRM 1.41 s, fbcon 21x16 1.74 s, DISPLAY READY 8.08 s (no unblank), display errors 0; START OK 75.6 s, AP ENABLED 79.7 s,
SNTP OK, MPSS+WCNSS running, ping 4/4, eMMC w=0.
Nothing was flashed. Reflashing lk1st with this code needs a separate GO.

View file

@ -0,0 +1,12 @@
21:42:33.413 B9L l0: waiting for lk1st fastboot <EMMC_SERIAL> (power off >= 90 s, then RESET held + battery -> USB)
21:43:33.792 fastboot present: product=lk1st-msm8916
Sending 'boot.img' (284 KB) OKAY [ 0.011s]
Booting OKAY [ 0.022s]
Finished. Total time: 0.034s
rc=0
21:43:33.831 waiting for second-stage fastboot (or Linux NCM)
21:43:33.845 fastboot present again: product= version-bootloader=
21:43:36.849 B9L l0 END
product: lk2nd-msm8916
version-bootloader:
kernel: lk

Some files were not shown because too many files have changed in this diff Show more