Compare commits

..

No commits in common. "main" and "b6p-pass" have entirely different histories.

919 changed files with 13 additions and 427078 deletions

10
.gitignore vendored
View file

@ -81,13 +81,3 @@ tmp/
*.pem
id_rsa*
id_ed25519*
# --- B10+ stages: raw run logs never committed (publish reports *.md and compact *-diff.txt only; see tools/publish-sanitize.py) ---
logs/b1[0-9]*/**/*
!logs/b1[0-9]*/**/
!logs/b1[0-9]*/**/*.md
!logs/b1[0-9]*/**/*-diff.txt
!logs/b10/b10b3/downstream-7f1748ce/*.txt
b1[0-9]*/**/emu/*.out
b1[0-9]*/**/emu/map-*.txt
b10/b10a/*.txt

252
NOTES.md
View file

@ -1184,255 +1184,3 @@ clean stop, rmtfs last). Validation: 3/3 RAM candidate boots, 3/3 cold boots fro
Safety: eMMC writes 0; NV partitions unchanged.
Known issues: early boot hangs before Linux (SBL1 DDR-init / after SBL1 End / lk target_init); possible battery/contact instability (UVLO reset during modem stop, pc2);
fast MSS restart re-attach needs investigation; single unreproduced cases (pc1 no RX, 22:00 stall after online SET); marginal Beeline RF at the install location.
# Session 32 — R2 early bootchain hang investigation (2026-10-01, read-only) — report `r2/R2-REPORT.md`
- 96 SBL1 starts from 41 UART logs classified (r2/table.txt). Nothing written, no reboots; live reads on pc6 boot (PMIC regmap, APSS WDT via devmem, read-only).
- SBL1 telemetry is bimodal: class B (pm_device_init ~11.75 ms, PBL ~157 ms; all PON=USB boots, all warm reboot -f) vs class A (~11.25 ms, PBL ~123 ms; PON unknown).
- "SBL1 End → no lk" hangs: 3/9 class-A starts on the new chain (15:41:10, **18:00:31 — previously unlogged**, 23:40:50) vs 0/5 on stock chain; only class-B one (23:26:59) had anomalous PMIC timings.
- Warm reboot -f (mainline): 3/9 fail (2× lk MMC-init hang + self-reset ~15 s, 1× SBL1 DDR hang); stock warm restarts 0/~9.
- APSS WDT EN=0 (not in DT); watchdog0 = PMIC PON WD, disabled (0x857=0). batt_voltage 4183–4202 mV at all failures. UVLO in POFF also appears after plain user power cuts.
- Verdict: power/contact transients = trigger; new chain (DB410c TZ/qhypstub) hangs on non-POR restarts instead of recovering; warm reboot separate SW issue. Next: T1–T3 (user hands).
# Session 32b — R2/T1 startup-class capture (2026-10-01 00:14–01:03, read-only; watcher r2/t1-watch.sh, logs logs/r2/t1/)
- Battery pulled 0.5 s with USB present: no reset (uptime continued); only MISC 0x909 06→0e latched.
- Battery-only + short power key: no start. 3 s key hold: started (board runs on battery), but UART gave nothing until USB
was plugged → CH340 GND was not tied to the board (common ground only via USB). Floating RX fed garbage into the root console
(XOFF, then after XON a TX→RX echo loop ran ~5 min executing junk: only "not found"/"Permission denied"/ed errors). Stopped with XOFF.
User then tied GND. NV check on the next good boot: modemst1/2, fsg, fsc, persist == A3 (637a71d1/9bb10190/b0a3b7e4/5f70bf18/ee48a843).
- **Class C (new):** battery inserted, no USB, 00:53:49 → pm_device_init 17110, cdt 25467, pm_driver_init 13969, SBL1 Δ 208834 → hang after SBL1 End.
Same signature as 15:45:06 (DDR hang) and 23:26:59 (after SBL1 End hang) → class C = 3/3 hang.
- **Class A captured:** USB connected first, then battery → 00:58:41 sblS 122945, pm_device_init 11285 (A) → lk target_init hang →
self-reset 00:58:57 → class B start (11803) → Linux. PON on that boot: 0808=10 (USB), 080a=02 (PS_HOLD warm reset), 080c=00, 080d=00, 0807=c8.
⇒ the lk-hang self-reset is a PS_HOLD (SoC-side) warm reset, not a PMIC key/WD reset; PON_REASON (retained over warm reset) = USB for the A power-on.
- Working hypothesis (1 sample each): start class is set by power-source order — B: battery present, USB inserted; A: USB present, battery inserted; C: battery only.
# Session 32c — R2/T2 series B (battery first, 5 s, then USB), 2026-10-01 01:07–01:12; UART logs/uart/r2t2-20261001-010713.log, results logs/r2/t2/results.tsv
- B1–B4: class B, PASS (pm_device_init 11773–11803, PBL 158–160 ms, SBL1 Δ ~190.3 ms, batt 4197–4198); PON 0807=c8 0808=10 080a=00 080c=00 080d=20; RTC continued (557/631/688/751 s).
- B5 (same procedure): **class A, PASS** (sblS 125141, pm_device_init 11285, SBL1 Δ 187972). PON diff vs B: **0807=18** (c8 in B), **080d=00** (20 in B); 0808=10 (USB) same.
**RTC at boot = 3 s → PMIC RTC was reset.**
- ⇒ **Class A = full PMIC POR** (retained domain — RTC, POFF reasons, 0807 bits 7/6 — lost); class B = power-on with PMIC retained domain alive.
Confirmed on old logs: 22:05:25 A → RTC 2 s; RTC back-calculation puts RTC resets exactly at 23:40:50 (A) and 23:26:59 (C).
Power-off gap (last console line → start) was ~13 s for B5 vs 13–17 s for B1–B4 → off-time alone doesn't explain it (proxy only).
# Session 32d — R2/T2-DURATION (60 s full power-off, battery → 5 s → USB), 2026-10-01 01:17–01:25; results logs/r2/t2d/results.tsv
- D1: class A, PASS, RTC 3 s, PON 0807=c8 0808=10 080a=00 080c=00 080d=00.
- D2: class A → lk target_init **panic: "Failure getting card's CID number" / "mmc init failed!"** (eMMC not answering lk) → PS_HOLD reset 14.8 s after panic
→ follow-up class B start → PASS (RTC 18 s, 080a=02). ⇒ the earlier "lk target_init hangs" are this lk panic (text was lost on UART before).
- D3a: class A → hang after SBL1 End, no reset in 120 s (GND wire detached during this attempt → confounded). D3b (repeat, GND re-soldered): class A, PASS, RTC 3 s, 080d=00, 0909=0e.
- **Verdict: 60 s off → class A on every start (4/4 incl. D3a)**, vs ~13–17 s off → B 4/5. Off-time decides whether the PMIC retained domain survives.
0807 is not a class marker (18 in B5, c8 in D1/D3b); markers of A = RTC reset + 080d=00.
- Class A outcomes on the new chain so far (T2+T2D): PASS 3 (B5, D1, D3b), lk eMMC panic 1 (D2), SBL1-End hang 1 (D3a, confounded).
# Session 32e — R2/T2 USB-FIRST (full-off, USB → 5 s → battery), 2026-10-01 01:29–01:42; results logs/r2/t2u/results.tsv (+ *-lk.txt per start)
- U1: class B PASS, RTC 346 (continued) — log shows board alive until 34.4 s before start → full-off ≤ ~29 s: protocol deviation, not a 60 s sample.
- U2: class B PASS, RTC 485 (continued, lost 9.4 s), full-off ≤ ~52.6 s (borderline). 080d=20.
- U3/U4/U5 (user-timed 70 s, log bounds ≤109/84/93 s — valid): class B PASS ×3; RTC continued (lost 23.3/20.4/22.9 s during off); 0807=d8; 080d=00.
lk every time: "MMC card: H4G2a …" → "Jumping to kernel via monitor"; only the normal slot2 SD-probe errors; no panic, no reset.
- Comparison ≥60 s off: battery-first (D1, D2, D3b) → class A 3/3 (RTC reset), outcomes PASS 2, lk eMMC-CID panic 1 (auto-reset 14.8 s → B PASS);
USB-first (U3–U5) → class B 3/3 (RTC survived), PASS 3/3.
- ⇒ Power-on order changes the class itself: with VBUS present first, the PMIC retained domain (RTC etc.) survives ≥70 s off; battery-first after ≥60 s off gives a full PMIC reset.
So "hang/panic probability at equal class A vs order" could not be measured — USB-first never produced class A. B5 (battery-first, ≤8 s off → A) stays unexplained.
- RTC keeps its value during off but loses time (~20–23 s per 70 s off) — backup-powered, degraded.
# Session 33 — R2/T3 (2026-10-01 01:45 → 2026-10-02 10:31): class-A repro, lk eMMC audit, UART backfeed test
- T3B source audit (lk2nd 23.1 e9c8b217): r2/T3B-LK-EMMC-AUDIT.md. Failure = CMD2 ALL_SEND_CID timeout after CMD0/CMD1 OK in mmc_identify_card;
no CMD2 retry, no slot1 re-init, no RST_n/VCC cycle → ASSERT(0) in target_sdc_init. eMMC code identical to JZ02 lk1st (8b46487); upstream has no later fix.
lk1st PANIC_REBOOT_MODE=EMERGENCY_DLOAD, but the panic dump stops after "irq r13" and a PS_HOLD reset comes ~15 s later (source unknown; lk arms no WDT on msm8916).
- T3A (battery-first, ≥70 s off, CH340 TX connected): A5, A6 → class B (RTC survived, 0807=98) → battery-first ≥60 s does NOT reliably give class A.
- T3C UART backfeed test (CH340 TX → board RX disconnected; RX/GND kept; 90 s off; battery → 5 s → USB): C1/C2/C3 = **class A 3/3, PASS 3/3, RTC 3 s each**
(PBL ~125.5 ms, pm_device_init 11285, pm_driver_init 10.8–10.9 ms at batt ~3995 mV). ⇒ backfeed from CH340 TX kept the PMIC retained domain alive (class B);
without it a ≥60 s off gives a full PMIC reset. UART also became clean (garbled SBL1/lk lines 137 → 0); new lk lines visible: "SDHC Running in HS200 mode",
"Done initialization of the card", "pm8x41_get_is_cold_boot: cold boot", "lk2nd_init()".
- Valid class-A starts so far: B5, D1, D2, D3b, C1, C2, C3 = 7 → eMMC CID panic 1/7 (D2). No new failure type. PON regs not read in T3C (no input channel).
- Logistics: CH340 replugs kill tools/uartlog.py (restart it); never run minicom while the logger runs; board NCM moved to enp60s0u1u2u1 without 172.16.42.2.
- T3C2 (2026-10-02 10:34–10:42): C4/C5/C6 class A, PASS, RTC 3 s (TX disconnected, 90 s off). Final class-A sample = 10 (B5, D1, D2, D3b, C1–C6):
PASS 9/10, CMD2/CID panic 1/10 (D2). lk output of C1–C6 identical up to "Done initialization"; first PASS/FAIL divergence = first line after target_init(). r2/T3-CLASS-A-SUMMARY.md.
- T4 (2026-10-02 10:55): read-only eMMC snapshot NOT run — no command channel (UART RX-only, no NCM shell, host lacks 172.16.42.2 without sudo).
From the C1–C6 UART kernel log: HS200 every boot, 0 mmc/sdhci error/timeout/CRC/re-tune lines. logs/r2/t4/T4-partial.txt.
- T4-A (2026-10-02 11:02–11:10): UART input to the board does not work (0 bytes back for echo/XON; board TX→host RX OK). Unexpected class-A cold boot 11:03:48
(RTC 3 s, PASS, batt 4019 mV) during the user's wiring check — whether TX was attached then is unconfirmed. UART log logs/uart/r2t4a-20261002-110229.
- T4-B build (user GO "путь 2"): r2/t4/build-telnet.sh → r2/t4/out/aurora-mm1-t4telnet.img 6db01841 (B6P image 18a25e39 reproduced bit-for-bit, + 3rd cpio
member with /init = B6P init + devpts + `telnetd -l /bin/sh -b 172.16.42.1 -p 23`). Kernel/cmdline identical to B6P. For `fastboot boot` only; NOTHING written.
Offline checks: layered /init = T4 (13721ca5), sh -n OK, busybox 1.37.0 telnetd runs under qemu, CONFIG_UNIX98_PTYS=y. Copied to 480s r2/t4/out/.
- T4-B (2026-10-02 11:24–11:28): `fastboot boot` of the T4 telnet image → `T4: telnetd started on 172.16.42.1:23`. Host NM auto-profile "Wired connection 2" (DHCP) kept flushing
172.16.42.2 → user created NM profile **aurora-ncm** (static 172.16.42.2/24, never-default, ifname enp60s0u1u2u1; "Wired connection 2" autoconnect=no).
ping OK, telnet root shell (/dev/pts/1) OK **with CH340 TX disconnected** → UART input no longer needed (while this RAM image runs).
- T4 snapshot: logs/r2/t4/T4-RESULT.md. EXT_CSD rev 6 (eMMC 4.5): PRE_EOL/LIFE_TIME undefined (0x00) → no health data; RST_n_FUNCTION=0x01 (permanently enabled);
err_stats all 0, no mmc errors in dmesg, HS200 8-bit 1.8 V. Hypothesis (unproven): RST_n glitch between CMD1 and CMD2 would match D2.
- T4-C (2026-10-02, user GO "готовь cache с telnetd, но без записи") — **NOTHING WRITTEN**. r2/t4/mkfs-cache-t4.sh (= b6p recipe; toolchain re-proved: B6P cache 9fea693a
reproduced bit-for-bit) → r2/t4/cache-extlinux-t4.img **9d3bc890…** (deterministic; e2fsck clean; Image.gz-dtb/DTB/cmdline == B6P, initrd = initramfs-t4 db47835b, label t4).
lk2nd emulator (r2/t4/emu): T4 → boot_linux reached, kernel/dtb/cmdline identical to B6P regression (S3 == b6p/emu), only ramdisk differs; F1/F3/F10 → revert to android boot (boot=emmc1).
Prepared, not run: r2/t4/T4-write.sh (diff vs B6P-write.sh = image/hashes/log dir only; old cache must be 9fea693a), r2/t4/T4-rollback.sh (→ B6P 9fea693a).
- T4-W (2026-10-02, user GO "запись", HW EDL): r2/t4/T4-write.sh → all gates passed (old cache == B6P 9fea693a, boot/aboot/GPT unchanged), **CACHE_MATCH 9d3bc890**,
sbl1/rpm/tz/hyp/recovery/modemst1/2/fsg/fsc/persist == A3, modem/system/userdata == A4pre → **T4_WRITE_VERIFIED**. Logs logs/r2/t4/W/. Rollback: r2/t4/T4-rollback.sh (→ 9fea693a).
- T4-V (2026-10-02 11:42, first normal power-on after T4-W, TX disconnected): SBL1 OK (batt 4078 mV, pm_driver_init 7594 µs, RTC 568 s → class B), lk eMMC OK,
extlinux "Trying to boot 't4'", EMMC-RO 30/30, `T4: telnetd started`, B1_OK=1. Host aurora-ncm auto-up 172.16.42.2; ping OK; telnet root shell OK (/dev/pts/0).
aurora-modem: START OK in 71.2 s (Beeline home, wwan0 bearer) — first boot without the "usb0 ping lost" rollback. **TX CH340 no longer needed for control.**
# Session 34 — R3 autonomous operation (2026-10-02) — **CLOSED, sufficiently verified**
- R3A PASS: class-A cold boot (RTC 3 s, TX disconnected, battery → USB, ~2 min off), no input → t4 → NCM (~12 s after SBL1) → telnetd → aurora-modem START OK in 66.0 s
(~77 s power-on → LTE), Beeline home, wwan0 ping 77.88.8.8 / 1.1.1.1 3/3, DNS 10.10.22.3 OK. logs/r3/r3a/R3A-RESULT.md.
- R3B PASS: aurora-ncm `nmcli con down` 60 s in steady state → controller does not notice (usb0 ping check lives only in start/reg_sm; controller exits after START OK);
bearer/LTE ping 88/88 kept, no MM/rmtfs restart; `con up` → host IP, ping, telnet back at once. logs/r3/r3b/R3B-RESULT.md.
- Open (not run): R3B2 = NCM loss during start (rollback, no auto retry). Secondary bearer DNS 194.186.191.1 times out.
# Session 35 — B7A time sources vs VNIIFTRI NTP (2026-10-02, measurement only) — logs/b7/b7a/B7A-RESULT.md
- DMS System time (ms/1000 + 315964800) = UTC − 280.2 ms (σ 1.0 ms, 18 samples, range −281.6…−278.1); no GPS leap offset. NITZ = DMS truncated to 1 s (−1.16…−0.36 s).
- ntp1/2/3.vniiftri.ru = 89.109.251.21/22/23, agree ≤ 7.7 ms; reached via temporary /32 routes on wwan0 (removed). Board clock untouched.
- Debian busybox-static has no ntpd; Alpine busybox-static 1.37.0-r20 (signature-verified) does (`ntpd -w -d`). Board busybox `date` has no %N → use `adjtimex`.
- B7B PASS (2026-10-02): live modem, validated DMS (6 gates) → one `date -u -s @N` step 1970 → 2026 at a DMS second boundary, no RTC (adjtimex stays UNSYNC).
MM/rmtfs/qmi-proxy/telnetd PIDs unchanged, bearer up, LTE ping 36/36 over 182 s, no new dmesg/lifecycle lines. ntp1.vniiftri.ru: clock −0.292 s (= DMS bias −0.28 + 12 ms step latency).
logs/b7/b7b/B7B-RESULT.md, script b7/b7b/b7b-run.sh. Board `qmicli --dms-get-time` line format: "System time: '<ms> (ms): <date>'".
- B7C PASS (2026-10-02): RAM image b7/b7c/out/aurora-mm1-b7c.img (d0c4cc00) with controller time bootstrap (aurora-modem 932c9ff2). 3/3 class-A cold boots (c5/c6/c7r):
DMS before registration = modem uptime from 1980 (rejected), valid at REG registered/attached → one date -s at uptime 24–70 s; residual vs VNIIFTRI +0.04/+0.36/+0.84 s.
Bogus NITZ 1980-01-06 seen before registration (rejected). No cache/eMMC write. logs/b7/b7c/B7C-RESULT.md. Persistent cache: separate GO.
- B7C-W (2026-10-02, user GO "запись", HW EDL): b7/b7c/cache/B7C-write.sh → all gates passed (old cache == T4 9d3bc890), **CACHE_MATCH 14fe453a**, everything else == A3/A4pre
→ **B7C_WRITE_VERIFIED**. Logs logs/b7/b7c/W/. Rollback: b7/b7c/cache/B7C-rollback.sh (→ T4 9d3bc890).
- B7C-V1 PASS (2026-10-02 17:00 UTC): normal power-on (class A, RTC 3 s) → lk "Trying to boot 'b7c'" → TIME SET at uptime 21.44 s (REG registered/attached) → START OK 73.9 s,
SNTP residual +0.262 s vs VNIIFTRI. **B7C is now the operational baseline** (cache 14fe453a). logs/b7/b7c/cV1/.
# Session 36 — B8 Wi-Fi / WCNSS (2026-10-02/03) — **CLOSED, PASS** — logs/b8/b8{a..f}/B8*-RESULT.md
- B8A (read-only audit): MSM8916 Pronto + Iris; DT &wcnss disabled (bam1), iris without compatible; kernel had no QCOM_WCNSS_PIL/WLAN/CFG80211;
wcnss.mdt+b* already in /firmware/image (upstream default name); NV only in persist (WCNSS_qcom_wlan_nv.bin 29816 B c6b71825); stock peripheral_mem 0x8b600000/6 MiB.
Stock DT has no Iris compatible; stock supplies (L9 3.3 V, L5 1.8 V) exclude WCN3660/3660B.
- B8B (RAM): +QCOM_WCNSS_PIL, DTB wcnss okay + wcnss_mem fixed 0x8b600000/0x600000 (right after mpss_mem) + iris `qcom,wcn3620` → remoteproc1 a204000 running,
edge pronto (WCNSS_CTRL…), `WCNSS Version 1.5 1.2`; without NV Pronto dies every ~46 s (`dog.c:1561 Watchdog startup timeout`). WCNSS auto-boot at ~1 s fails
(/firmware not mounted yet) → started via sysfs after START OK.
- B8C (RAM): + NV in initramfs /lib/firmware/wlan/prima → no NV error, no watchdog, Pronto stable ≥ 7 min; LTE ping 482/484. Watchdog cause = missing NV.
- B8D (RAM): + WLAN/CFG80211/MAC80211/WCN36XX built-in (CONFIG_MODULES=n), iw 6.17 → wcn36xx probe → phy0 (2.4 GHz, managed/AP/monitor, HT20/40 MCS0-7, CCMP)
→ wlan0, MAC <MAC> (lk DT from eMMC serial), rfkill 0/0, no regulatory.db (world 00); LTE 491/491.
- B8E: wlan0 up → `WCN v2.0 RadioPhy vUnknown with 19.2MHz XO`, CRM CNSS-PR-1-4-2-c4-00084 (== JZ02); hostapd 2.11-r4 test AP WPA2-PSK/CCMP ch 6 → phone connected,
held 436 s, HTTP fast. AP→sleeping-client frames delayed up to ~10 s (wcn36xx lacks set_tim; hypothesis) — open.
- JZ02 (same SoC, ssh -J 480s root@172.16.32.1, read-only reference): same WCNSS FW, NV sha, iris wcn3620, same hostapd config; wcnss_mem dynamic @0x8e200000.
- B8F: cache **857c9c30** (B7C + b8d kernel + B8B DTB + NV + iw + aurora-wifi service + hostapd; /init = T4 + 1 autostart line), RAM pre-test PASS, emulator OK,
HW EDL write → **B8F_WRITE_VERIFIED** (old cache B7C 14fe453a backed up; rollback b8/b8f/cache/B8F-rollback.sh). 3/3 class-A cold boots, no input:
START OK 72–89 s → AP ENABLED 76–94 s, phone WPA2/CCMP connected and held 168–188 s, Pronto crash 0, LTE OK, eMMC w=0, SNTP +0.40/+0.996/+0.03 s.
**B8F is now the operational baseline (cache 857c9c30).** PSK only in b8/b8f/private (never publish out/, cache image, W/*.bin).
- Open: sleeping-STA delivery delay, regulatory.db/country RU, production MAC, exact Iris chip, B7 residual at 1 s edge. Next stage: display.
# Session 37 — B9 display (2026-10-03) — **CLOSED, PASS** — logs/b9/{b9a,b9b,b9c,lk,b9l}/
- B9A (read-only audit): the panel is **not DSI**. It is a 1.44" **ST7735S 128x128 on SPI** (MIPI-DBI type C), BLSP1 QUP4 spi@78b8000 (GPIO12 MOSI, 13 MISO, 14 CS0, 15 CLK),
16 MHz, mode 3, D/C GPIO116 (`disp_dc`), RESET GPIO118 (`disp_rst_n`), RGB565, MADCTL 0xc8, GRAM offset (2,3). Backlight = PM8916 **MPP4 current sink 40 mA**
(0xa340=0x61, 0xa34c=7, 0xa346=0x80); no PWM/WLED/DCS.
- Stock LK (saved aboot) brings the panel up in aboot_init, unconditionally, ~210 ms after LK start. The 19-command sequence equals dtb_01 byte for byte.
panel_id is hardcoded to 1 (no ID read). The built-in 128x128 "4G LTE" logo is used because the splash partition is all zeros.
- Current lk1st has no SPI-panel code.
- B9B (RAM): kernel + DRM/panel-mipi-dbi/fbdev, DTB spi4 + panel (L17/L6 supplies) + MPP4 `function "sink"`/drive-strength 7 + gpio-backlight,
firmware = stock sequence (b9/b9b/mk-panel-fw.py).
- First light: image, colours, orientation and offsets all correct with no change.
- MPP4 reads back exactly 0x60 off / 0x61 on, 0x07, 0x80.
- Without fbcon nothing modesets; an fbdev unblank was needed.
- B9C: + FRAMEBUFFER_CONSOLE + FONT_6x8 only (21x16 console), cmdline `console=tty0` **before** `console=ttyMSM0` (keeps /dev/console = UART),
aurora-display service (fbcon takeover already enables the pipe → backlight on via sysfs), getty tty1, hostname aurora.
- Cache **b9ce13c9** written (B9C_WRITE_VERIFIED, backup = B8F 857c9c30).
- Cold boots: cold1 A, cold2 B (accepted by operator), cold3 A — all PASS; backlight ON→OFF→ON confirmed visually.
- **B9C is the operational baseline.**
- B9-LK audit: stock LK is not in the chain since B5a (aboot = lk1st). lk2nd cont-splash only adopts MDP; mdss_spi is msm8909/8952-only and hard-wired.
- B9L-0: lk1st `fastboot boot` of a 32-bit lk2nd 23.1 works on DB410c TZ + qhypstub.
- B9L-RAM: lk2nd 23.1 + patch (b9/b9l/lk2nd-23.1-aurora-b9l*.patch) — msm8916 QUP4 SPI clocks/pins, 16 MHz clamp, module lk2nd/aurora on CAF spi_qup
(platform mdss_spi.o NOT built: it pulls spi-display.c, which strcmp's a NULL panel.intf).
- **L17 and L6 are ON at LK time** (left on by SBL); no RPM work is needed in LK.
- Test frame, then the operator splash (`swag.png` → RGB565) shown before Linux; Linux fbcon takes over normally.
- Formal run directly from lk1st: PASS (e6849a2b). Nothing flashed.
- Open: lk1st reflash with the panel code (separate GO); ~1 s dark gap at handoff (Linux gpio-backlight pinctrl/fbcon re-init);
DT model string "RAM boot B9B"; screen UI. Next stage: battery / charging / power management.
- B9L-PERSIST (2026-10-03, GO): aboot := lk1st-b9l **15208dbb** (B9L_ABOOT_WRITE_VERIFIED, backup 3b8cd266, rollback b9/b9l/persist/B9L-rollback.sh).
First normal boot: splash at LK +340 ms → b9c → Linux fbcon, LTE/Wi-Fi OK. logs/b9/b9l/B9L-PERSIST-RESULT.md.
# Session 38 — B10 battery / charger / power management (2026-10-03/04) — **CLOSED, PASS** — logs/b10/{b10a,b10b0..b10b3,b10b5}/
- PM8916 LBC (linear charger) + VADC VBAT + BMS-VM in Linux; own supervisor on top of upstream pm8916_lbc, v1 → v4 (linux/patches/b10b3-lbc-supervisor-v3.patch,
b10/b10b3/lbc-v3-to-v4-fault-clamp.diff). Production: CHARGING 4.20 V / 450 mA / timer 512 min → HOLD (VDD_MAX 4.05 V after 60 min CV with VBAT ≥ 4.15 V)
→ USB removed → battery → new cycle on USB insert; FAULT (VBAT > 4.25 V or CHG_FAILED) = FAULT safe clamp VDD_MAX 4.00 V, latched until USB removal/reboot.
- Hardware facts: CHG_STATUS 00 + path 01 = latch (not "full"); CHG_EN = 0 does not stop the LBC; FAST_CHG_ON (RT bit5) + path 02 = fast charge;
TCHG = minutes/4 − 1 counts only in fast charge and on expiry just ends it (current continues, CHG_FAILED not set); USB_SUSP 0x1347 does not cut the input;
VDD_MAX = 4.00 V stops the input current while VBAT > 4.00 V; SBL re-initialises IBAT/CTRL/TCHG on warm reboot; software reboot to lk1st fastboot via
PON reboot reason (needs one USB replug for fastboot data).
- RAM tests: C, B, D, D2, D3, D4 (timer), t1 diag, B10B-4 actuators (test hook kernel), B10B-5 FAULT clamp regression (test trigger kernel), production
profile run (HOLD shelf ≈ 6 h), production v4 smoke.
- Persistent: cache **c3732515** (B9C + 7.2.7-aurora-b10b5 + DTB e47762d1), B10_CACHE_WRITE_VERIFIED (backup B9C b9ce13c9, rollback b10/b10b5/B10-rollback.sh);
class-A cold1/cold2 PASS. Public commit 58dcb3d.
- Limitations: clamp is no hard-off below 4.00 V; timer is no charge stop; no thermal derating; battery contact unreliable.
- Next: router stack; optional charger follow-ups (derating, hard-stop test, CV tuning) by separate GO.
# Session 39 — B11 LED audit + all-SAFE-LED run (2026-10-04) — **PASS (scope: 1 SAFE line)** — logs/b11/
- Read-only audit (B11-LED-AUDIT.md): the stock DT/Android/system/MPSS/LK have no indicator LEDs ("gpio-leds" = SIM mux only). The only proven LED line is MPP4 (LCD backlight).
MPP3 = current sink off (UNKNOWN), MPP2 = digital out HIGH and MPP1 = analog out (DO NOT TOUCH), PM GPIO1–4/VIB/unclaimed TLMM = UNKNOWN, GPIO105 out-low/106 pull-up = modem RF.
- Run r1 on the live production boot (no image, no eMMC): OFF → ON 4 s → OFF → chase 2× → restore, END OK, monitor 0 FAIL, operator saw the backlight follow the plan;
PMIC state identical pre/post. pm8916-thermal reads ~7 °C lower while the MPP4 sink is off (artefact).
- Buttons (read-only): POWER = KPDPWR (pwrkey IRQ), RESET = RESIN (PON RT bit1), MENU probably = KPDPWR too; GPIO37/107 (stock key_f2/f3) never toggle.
# Session 39b — B11C closed / B12A audio audit (2026-10-04)
- B11C: 15 populated LEDs (+~12 empty positions) inside the display frame on BOT = display backlight array (operator); LED topic closed. Annotated photo logs/b11/b11c/B11C2-annotated-bot.jpg.
- B12A (read-only, CLOSED n/a — operator: no speaker/mic in the case): stock audio = generic 8916 MTP config (PM8916 Tombak + digital codec, mixer_paths unmodified); no speaker/mic/jack visible in photos; CONFIG_SOUND=n. logs/b12/b12a/B12A-AUDIO-AUDIT.md.
# Session 40 — B12P persistent Alpine on userdata (2026-10-04) — **PASS** — logs/b12/b12p/B12P-RESULT.md
- userdata p27 = ext4 `aurora-alpine` (Alpine 3.24.2 + X11), auto-mounted at /alpine by the B12P initramfs; only p27 RW (disk RO flag lifted, all other partitions RO-verified).
- Cache **98d061ef** (B10 kernel/DTB/cmdline + overlay) B12P_CACHE_WRITE_VERIFIED, backup B10 c3732515, rollback b12/b12p/B12P-rollback.sh. RAM ram2 + cold1 PASS.
- Also built (untested on HW): kernel out-b12 (b10b5 + nftables), b12/router/ router-up/down/status + nft/dnsmasq bundle. NCM bulk transfers stall → b12/push.sh.
# Session 40b — B12Q Alpine primary rootfs (2026-10-04) — **RAM VALIDATED** — logs/b12/b12q/B12Q-ALPINE-PRIMARY-ROOT.md
- initramfs stage0 → switch_root into Alpine 3.24.2 on p27 (busybox init + OpenRC 0.63.2); LFS init kept byte-identical as /init.lfs rescue
(aurora.alpine=off, any check failure, ≥3 unconfirmed boots). p27 got 44 pkgs (bit-identical modem binaries) + OpenRC wrappers around the unchanged B6–B10 scripts.
- RAM normal1/off1/failtest1 all PASS. **Cache 59272cd3 B12Q_CACHE_WRITE_VERIFIED (backup B12P 98d061ef), cold1 PASS — Alpine is the primary rootfs.** Rollback b12/b12q/B12Q-rollback.sh.
# Session 40c — B12R router inside Alpine (2026-10-04) — **RAM VALIDATED** — logs/b12/b12r/B12R-ROUTER-RESULT.md
- Kernel 7.2.7-aurora-b12 (b10b5 + nf_tables) RAM-booted; p27 got nftables+dnsmasq+aurora-router (OpenRC, not in runlevel). Phone: DHCP .199, ya.ru OK, NAT OK, mgmt isolation drop OK.
- Beeline RSTs foreign hosts (whitelist mode) — apk works via mirror.yandex.ru. **Cache e85d862e B12R_CACHE_WRITE_VERIFIED, cold1 PASS, aurora-router in default runlevel.** Rollback b12/b12r/B12R-rollback.sh → B12Q.
# Session 41 — B13W Wayland/wlroots (2026-10-04) — **PASS** — logs/b13/B13-WAYLAND-WLROOTS-RESULT.md
- Alpine apk (mirror.yandex.ru): wlroots 0.20.2, cage 0.3.0, sway 1.12_rc3, wayvnc 0.10.0, seatd 0.9.3, foot. Pixman renderer on DRM card0 (SPI-1 128x128), no GPU.
- Cage PASS (47.5 MB, 0 % idle), Sway PASS (56.8 MB), wayvnc on Sway and on Cage PASS (172.16.42.1 only, VeNCrypt TLS + password, input OK), X11 regression PASS.
- wlroots needs mesa libgallium/LLVM files even with Pixman → `apk fix` restored the B13-pruned mesa/LLVM. Recommendation: Cage for UI, Sway+wayvnc for debug, Xorg = fallback.
# Session 42 — B14 Cage + SDL2 modem UI (2026-10-05) — **USERSPACE VALIDATED** — logs/b14/B14-UI-RESULT.md
- aurora-ui (C, SDL2 2.32.10 wayland driver, llvmpipe via EGL/wl_shm) under Cage: LTE/IP/Wi-Fi/traffic/VBAT+state/PMIC/NAT/clock on 128x128; soak 15+5 min stable.
- Pitfalls: SDL2 segfaults without wayland-libs-egl; bam-dmux wwan0 netdev counters are always 0 (UI uses wlan0); CMA EBUSY warnings came from page cache after apk installs (0 with UI after drop_caches).
- aurora-ui autostart ENABLED (GO 2026-10-05): cold1 UI up at 9.5 s uptime, router autostart ROUTER UP OK 88 s.
# Session 43 — B15 VPN: WireGuard over a TURN relay (2026-10-05) — **PASS (cold boot)** — logs/b15/B15-AUDIT.md
- Kernel 7.2.7-aurora-b15 = b10b5 sources + WIREGUARD + IP_MULTIPLE_TABLES (fragment linux/aurora-b15.config).
- Path: Wi-Fi LAN → wg0 → local relay client (127.0.0.1) → public TURN relays → own WireGuard server. Relay client = third-party static
arm64 binary (free-turn, not included); its config, the WireGuard config/keys and the server address are private and not published.
- aurora-vpn (b15/run): policy-routes only the LAN (rule 100: LAN subnet → table 51820 → wg0); the board's own traffic (incl. the relay
uplink) stays in main → wwan0, so no loop and no fwmark. Fail-closed for the LAN (no LTE leak). MTU from the WG config, MSS clamp.
- OpenRC: free-turn (supervise-daemon, respawn) + aurora-vpn in default. First ~2 min after boot: DTLS timeouts until LTE + clock are up, then self-recovers.
- Race fix: aurora-router came up after aurora-vpn and re-added its forward chain that dropped LAN→wg0 → router now skips its ruleset if table inet aurora_vpn exists.
- Cache **212e0ca9** (rollback b15/B15-rollback.sh → B12R).
# Session 44 — B16 UI pages + POWER key (2026-10-05) — b16/README.md
- aurora-ui: status row with WG handshake age; POWER key (pm8941_pwrkey evdev) wakes and cycles STATUS → CLIENTS → relay log → WG; backlight off after 180 s.
# Session 45 — B17 standalone operation + SSH (2026-10-05)
- aurora-modem: USB management-ping check only with MGMT_CHECK=1 (default 0) — it rolled the modem back when no host was attached.
- SSH (dropbear via own /etc/init.d/aurora-ssh); never `rc-service dropbear` on this image: Alpine's script needs net → starts
`networking` and a second udevd whose exit deletes /run/udev/control. nft allows tcp/22 only to the LAN address.
- Board usable without a host: SSH over Wi-Fi, telnet over USB NCM (no auth, dev).
# Session 46 — B18 USB host / OTG (2026-10-06) — **PASS, persistent**
- Kernel out-b18 = b15 + CONFIG_USB/EHCI/CHIPIDEA_HOST, usb-storage/UAS, HID, exFAT (linux/aurora-b18.config — CONFIG_USB itself was off before).
- DTB b18 = b10b3 + &usb dr_mode "otg" + usb-role-switch; boots as device (NCM); `aurora-usb host|device|status` switches the role.
No VBUS output on this board → powered hub needed (keyboard/mouse receiver verified; X with libinput).
- Cache **ac82811a** (b18/B18-write.sh), cold boot PASS; rollback b18/B18-rollback.sh → B15.
# Session 47 — B19 OpenSSH instead of dropbear (2026-10-06)
- Alpine dropbear has no X11 forwarding → openssh-server + sftp-server + xauth, host keys converted (same fingerprint), X11Forwarding yes.
`ssh -Y` over Wi-Fi works; scp/sftp work.
# Session 48 — B20 aurora-netwatch + aurora-blackbox (2026-10-06)
- Day test on battery: operator detach (`emm-detached`) left the bearer down for 30+ min → aurora-netwatch: bearer + ping every 30 s,
3 failures → disconnect + start + default route; OFF → retry after a grace period. Simulated disconnect: detected in ~80 s, recovered in 9 s.
- aurora-blackbox: /var/log/aurora/status.log once a minute + full kernel log per boot (boot counter), rotation at 2 MB.
# Session 49 — B21 Stack game, B22 direct-first VPN (2026-10-06)
- B21: a one-button game on aurora-ui page 5 (b16/src/aurora-ui.c).
- B22: second WireGuard interface wg1 directly to the server; aurora-vpnsel moves the LAN route to wg1 while its handshake is fresh,
stops the relay; falls back to wg0 via the relay when stale. LTE whitelist indicator: periodic TCP probes to domestic vs foreign hosts
→ UI shows WL / NET / LTE!. With the operator in whitelist mode the direct path is blocked → relay is used.
# Session 50 — B23 published separately (see below); B11–B22 published 2026-10-07 (scripts, configs, sources, *.md reports only).
# Session B23 — faster charging, 720 mA (2026-10-07) — **PASS, persistent** — logs/b23/B23-RESULT.md
- DTB b23 = B18 DTB + `qcom,fast-charge-safe-current = <720000>` → IBAT_MAX/IBAT_SAFE 0x04 → 0x07; kernel b18, initramfs B12Q, cmdline unchanged.
- RAM ram2 (b23/b23-boot.sh, observer b23/b23-mon.sh): laptop USB meter 0.724 A, USBIN 4.67–4.78 V, CC 55+ min, PMIC max 55.7 °C, CV from ≈4.10 V.
- Cache **01bfe522** B23_CACHE_WRITE_VERIFIED (backup B18 ac82811a, rollback b23/B23-rollback.sh); cold boot: IBAT_MAX 07, CHARGING.
- Open: worst-case thermal run (CC from ≈3.7 V with CPU load); still no thermal derating. B11–B22 not yet published.

120
README.md
View file

@ -9,7 +9,7 @@
> (см. [docs/QUICKSTART.md](docs/QUICKSTART.md)). Никогда не прошивайте NV/EFS-разделы (`modemst1`, `modemst2`, `fsg`, `fsc`, `persist`)
> с другого устройства — там калибровки RF и идентификаторы конкретного модема.
## Статус (2026-10-07)
## Статус (2026-10-01)
| Подсистема | Статус |
|---|---|
@ -23,27 +23,17 @@
| LTE Internet (DNS/ICMP/HTTP/HTTPS) | PASS |
| Direct boot с eMMC без хоста (B5) | **PASS / CLOSED** |
| B6 — lifecycle модема (RAM) | **PASS / CLOSED** |
| B6P — автозапуск модема из flash (persistent) | **PASS / CLOSED** |
| B7 — время от сети (DMS/NITZ, без RTC) | **PASS / CLOSED** |
| Wi-Fi (WCNSS/Pronto + wcn36xx, тестовая AP WPA2, автозапуск из flash) — B8 | **PASS / CLOSED** (см. ниже) |
| Индикация (LED = подсветка дисплея), кнопки POWER/RESET; аудио n/a — B11/B12A | **CLOSED** |
| Alpine Linux как основной root на userdata (OpenRC), откат в initramfs-rescue — B12P/B12Q | **PASS / persistent** |
| Router stack: NAT/firewall (nftables) + dnsmasq для Wi-Fi LAN — B12R | **PASS / persistent** |
| Wayland (Cage/Sway/wayvnc) и UI на экране 128×128 (aurora-ui, SDL2), кнопка POWER — B13/B14/B16 | **PASS** |
| VPN для LAN: WireGuard через TURN-relay (fail-closed) — B15; прямой WG с откатом на relay — B22 | **PASS** |
| Автономная работа без хоста, SSH (OpenSSH, X11 forwarding) — B17/B19 | **PASS** |
| USB host / OTG (role switch, HID, накопители через хаб с питанием) — B18 | **PASS / persistent** |
| Сторож LTE-bearer (netwatch) и журнал blackbox — B20 | **PASS** |
| Дисплей ST7735S 128×128 (SPI): DRM/fbcon tty1, подсветка, автозапуск из flash — B9 | **PASS / CLOSED** (см. ниже) |
| Батарея / зарядка: супервизор CHARGE → HOLD → батарея, FAULT safe clamp, автозапуск из flash — B10 | **PASS / CLOSED** (см. ниже) |
| Ускоренная зарядка: ток CC 450 → 720 mA (только DTB) — B23 | **PASS / persistent** (см. ниже) |
| B6P — автозапуск модема из flash (persistent) | **PASS** (см. ниже) |
| Wi-Fi (WCNSS) | TODO |
| Router stack (NAT/firewall/VPN) | TODO |
| Дисплей в Linux | TODO |
| Батарея / зарядка | TODO |
## Рабочая цепочка загрузки (baseline B5)
```
Power → stock SBL1 → DB410c TZ (TZ.BF.3.0) → qhypstub → lk1st (aboot, autoboot, splash на ST7735S через ~0.4 с)
→ cache: ext2 + extlinux/extlinux.conf → B23 (ядро b18 + DTB b23 + initramfs B12Q) → stage0 → switch_root в Alpine на userdata (p27, OpenRC)
→ модем, время, Wi-Fi AP + роутер + VPN, дисплей + aurora-ui, зарядка 720 mA, USB OTG (rescue: initramfs B9C-init при сбое Alpine)
Power → stock SBL1 → DB410c TZ (TZ.BF.3.0) → qhypstub → lk1st (aboot, autoboot)
→ cache: ext2 + extlinux/extlinux.conf → B6P (golden mm1 kernel/DTB + initramfs с автозапуском модема) → ARM64 Linux → LTE
Fallback: extlinux не найден / не парсится / не грузится → Android boot image из раздела boot (emmc1 rescue)
```
@ -55,91 +45,15 @@ Fallback: extlinux не найден / не парсится / не грузит
| GPT | stock + tz 512K→1M, tzbak перенесён в свободный промежуток @LBA 305184 | primary `6e850a5d`, backup `795952a1` |
| tz | DB410c TZ.BF.3.0-00714, дополнен нулями до 1 MiB | `8481892f` |
| hyp | qhypstub, до 512 KiB | `1a963047` |
| aboot | lk1st (lk2nd 23.1 + патч B9L: SPI-панель ST7735S + splash) autoboot, подписан qtestsign, до 1 MiB | `15208dbb` (откат: B5a lk1st `3b8cd266`) |
| aboot | lk1st (lk2nd 23.1) autoboot, подписан qtestsign, до 1 MiB | `3b8cd266` |
| boot | emmc1 rescue image (+ нули до 16 MiB) | `e9579f33` |
| cache | ext2 + extlinux + B23 (ядро 7.2.7-aurora-b18, DTB b23, initramfs B12Q → Alpine) | `01bfe522` (откат: B18 `ac82811a` → B15 `212e0ca9` → B12R `e85d862e` → B12Q `59272cd3` → B12P `98d061ef` → B10B-5 `c3732515` → B9C `b9ce13c9` → …) |
| cache | ext2 + extlinux + B6P (golden kernel/DTB/cmdline + B6P initramfs) | `9fea693a` (откат: B5b-образ `409bbb11`) |
| recovery | lk2nd 23.1 (fastboot) | `0dfa60a0` |
| userdata (p27) | ext4 `aurora-alpine`: Alpine 3.24 root (B12P+), единственный RW-раздел | — (изменяемый) |
| modem, NV/EFS, persist, system | не менялись (Linux монтирует modem FAT только RO) | — |
| modem, NV/EFS, persist, system, userdata | не менялись (Linux монтирует modem FAT только RO) | — |
Golden mm1 (Android boot image, для `fastboot boot`): `aurora-mm1.img` sha256 `38c960ef…`, ядро `7.2.7-aurora-bam1 #5`.
Все хэши целиком: `b5a/SHA256SUMS`, `b5b/SHA256SUMS`, `bootchain-migration/SHA256SUMS`, `linux/*/SHA256SUMS`, [docs/BLOBS.md](docs/BLOBS.md).
## B11–B22 — Alpine, роутер, VPN, UI, USB host (2026-10-04…06)
Подробно — NOTES.md (сессии 39–49) и отчёты в `logs/b11`…`logs/b15`.
- **B11** (`logs/b11/`): индикаторных LED на плате нет — «LED» это подсветка дисплея (MPP4); кнопки POWER = KPDPWR, RESET = RESIN. **B12A**: аудио n/a (нет динамика/микрофона).
- **B12P/Q/R** (`b12/`, `logs/b12/`): Alpine 3.24 на userdata p27; initramfs stage0 делает switch_root в Alpine (OpenRC), откат в прежний init при сбое проверок или ≥3 неподтверждённых загрузках; роутер nftables + dnsmasq для Wi-Fi LAN, изоляция управляющей сети.
- **B13/B14/B16/B21** (`b13/`, `b14/`, `b16/`): wlroots (Pixman, без GPU): Cage для UI, Sway+wayvnc для отладки; `aurora-ui` (C, SDL2) — LTE/IP/Wi-Fi/трафик/VBAT/PMIC/NAT/VPN на 128×128, страницы по кнопке POWER, гашение подсветки, игра.
- **B15/B22** (`b15/`, `b22/`): VPN только для LAN: policy routing (table 51820), fail-closed; WireGuard через TURN-relay, с B22 — прямой WG, если доступен (оператор в режиме белого списка его режет), индикатор белого списка.
- **B17/B19**: работа без хоста; SSH (OpenSSH, X11 forwarding) по Wi-Fi.
- **B18** (`b18/`): USB OTG с переключением роли (`aurora-usb`), ядро b18; VBUS платой не выдаётся.
- **B20** (`b20/`): `aurora-netwatch` (восстановление bearer после detach) и `aurora-blackbox` (`/var/log/aurora`).
## B23 status — ускоренная зарядка 720 mA: PASS, persistent (2026-10-07)
Отчёт: [`logs/b23/B23-RESULT.md`](logs/b23/B23-RESULT.md), DTS: [`linux/dts/msm8916-jz08-aurora-b23.dts`](linux/dts/msm8916-jz08-aurora-b23.dts).
- Изменено одно свойство DT: `qcom,fast-charge-safe-current` 500000 → 720000 → супервизор B10 пишет IBAT_MAX/IBAT_SAFE `0x04` (450 mA) → `0x07` (720 mA). Ядро и initramfs не менялись.
- RAM-тест на USB-порту ноутбука: USB-тестер 0.724 A, без просадки VBUS, CC 55+ мин без срывов, PMIC максимум 55.7 °C.
- Записано в cache (`b23/B23-write.sh`, HW EDL, readback + сверка разделов, `01bfe522`), холодная загрузка с eMMC: `IBAT_MAX 07`. Откат: `b23/B23-rollback.sh`.
- Фаза CC (до ≈4.1 V) примерно в 1.6 раза быстрее; хвост CV не меняется. Нагрузка платы (CPU, подсветка) идёт из того же входного тока.
- Базовый образ B23 — B18 (ядро `7.2.7-aurora-b18`, initramfs B12Q с Alpine); промежуточные этапы B11–B22 (Alpine-root, роутер, VPN, UI, USB host) в этом репозитории пока не опубликованы.
## B10 status — батарея и зарядка: CLOSED, persistent validated (2026-10-04)
Production-профиль (Li-ion 3.8 V / 3000 mAh): потолок заряда **4.20 V**, ток **450 mA**, HOLD **4.05 V**, full-min **4.15 V**,
CV-квалификация **60 min**, safety timer запрограммирован на **512 min**, FAULT safe clamp **4.00 V**.
Финальная проверка постоянной установки (cache `c3732515`): автономная class-A загрузка с eMMC; хеш живого cache перечитан и совпал;
CHARGING / FAST; USB off → NO_USB (работа от батареи без сброса) → USB on → новый цикл; LTE / Wi-Fi / NCM / дисплей PASS; 15 min стабильности PASS.
Отчёт: [`logs/b10/b10b5/B10-RESULT.md`](logs/b10/b10b5/B10-RESULT.md), дизайн: `logs/b10/b10b3/B10B3-DESIGN.md`, исходник драйвера: `b10/b10b3/pm8916_lbc-v4.c`.
- Зарядник PM8916 **LBC** (линейный) + VADC VBAT + BMS-VM: свой супервизор поверх upstream `pm8916_lbc` (`linux/patches/b10b3-lbc-supervisor-v3.patch`
+ `b10/b10b3/lbc-v3-to-v4-fault-clamp.diff` = **v4**). Состояния NO_USB → CHARGING (4.20 V / 450 mA, safety timer 512 min) → **HOLD**
(после 60 min CV при VBAT ≥ 4.15 V VDD_MAX опускается до 4.05 V: батарея стекает до полки, дальше плату питает USB) → USB вынут → батарея → USB → новый цикл.
**FAULT** (VBAT > 4.25 V или CHG_FAILED): единственная запись — **FAULT safe clamp to 4.00 V** (VDD_MAX = 0x00), защёлка до извлечения USB/перезагрузки.
- Проверено в RAM: CC/CV → HOLD, полка 4.03–4.06 V ~6 ч, USB 0.1 A на полке, HOLD → USB off → батарея без сброса, USB insert → новый цикл,
warm reboot (программный вход в lk1st fastboot через PON reboot reason), FAULT-инъекция (тестовое ядро) → USB 0.000 A; затем production smoke.
- Записано в cache (`b10/b10b5/B10-write.sh`, HW EDL, readback + сверка всех разделов) и проверено class-A загрузкой с eMMC без ввода.
- Факты о железе (подробно в `logs/b10/b10b3/B10B3-DESIGN.md`, отчётах `B10B3-*`/`B10B4-*`/`B10B5-*`, `logs/b10/b10b5/B10-RESULT.md`):
CHG_STATUS `00` + USB path `01` — защёлка, а не «заряжено»; CHG_EN = 0 заряд **не** останавливает; safety timer (TCHG = min/4 − 1) работает только
в fast-charge (FAST_CHG_ON, path `02`) и по истечении лишь выводит из него — ток идёт, CHG_FAILED не ставится; USB_SUSP (`0x1347` bit0) вход не отключает;
рабочий рычаг — VDD_MAX = 4.00 V (при VBAT > 4.00 V ток со входа → 0); после warm reboot SBL частично переинициализирует зарядник.
- Ограничения (production):
1. FAULT clamp не является гарантированным отключением заряда при VBAT < 4.00 V (зарядник может дозарядить до 4.00 V).
2. Safety timer PM8916 сам физически заряд не прекращает (по истечении только выход из fast-charge).
3. Снижение тока по температуре (thermal derating) не реализовано (PMIC до 58 °C при заряде + нагрузке CPU).
4. Контакт батареи на этой плате аппаратно ненадёжен.
Время CV 60 min — первое значение, не подбиралось.
## B9 status — дисплей PASS (2026-10-03)
- Встроенный экран — **не DSI**: 1.44" **ST7735S 128×128 на SPI** (MIPI-DBI type C), BLSP1 QUP4 `spi@78b8000`, 16 MHz, mode 3, CS0,
D/C GPIO116, RESET GPIO118, RGB565, MADCTL `0xc8`, смещение GRAM (2,3). Подсветка — PM8916 **MPP4 как current sink 40 мА**. Питание L17 2.85 V / L6 1.8 V.
Всё восстановлено из stock LK (дизассемблер) и stock DTB: 19 init-команд в LK и DT совпадают побайтно.
- Linux: upstream `panel-mipi-dbi` (firmware-файл со стоковой init-последовательностью, `b9/b9b/mk-panel-fw.py`), DRM + fbdev → `fbcon` 6x8 (21×16) на tty1,
`getty` на tty1, UART-консоль сохранена (`console=tty0` стоит **до** `console=ttyMSM0`). Подсветка: pinctrl MPP `function "sink"`, `drive-strength 7`
+ `gpio-backlight` (регистры = стоковые 0x61/0x07/0x80), включается сервисом `aurora-display` через sysfs.
- Cache B9C: 3 холодных загрузки с eMMC без ввода (2× class A + 1× class B, принято) — консоль ядра на экране, LTE + Wi-Fi AP, время, ошибок дисплея 0.
- B9L: порт SPI-панели в lk2nd/lk1st под msm8916 (CAF `spi_qup`, клоки QUP4 16 МГц, модуль `lk2nd/aurora`; L17/L6 на этапе LK уже включены SBL).
Сначала проверен в RAM (второй lk2nd через `fastboot boot`), затем **прошит в aboot** (lk1st `15208dbb`, сборка воспроизводима, запись с readback
и сверкой всех разделов). Теперь при включении splash (`b9/b9l/splash/swag.png` → RGB565) появляется через ~0.4 с, до Linux; затем fbcon.
Патч: `b9/b9l/persist/lk2nd-23.1-aurora-b9l-lk1st.patch`, запись/откат: `b9/b9l/persist/B9L-write.sh` / `B9L-rollback.sh`.
- Открыто: UI вместо консоли ядра, регулировка яркости, ~1 с темноты при передаче LK → Linux. Материалы: `b9/`, `logs/b9/`, NOTES.md сессия 37.
## B8 status — Wi-Fi PASS (2026-10-03)
- Pronto (WCNSS) через upstream `qcom_wcnss` remoteproc: штатный `wcnss.mdt` из RO-FAT `modem`, `wcnss_mem` фиксирован 0x8b600000/6 MiB,
Iris `qcom,wcn3620` (XO 19.2 MHz подтверждён прошивкой); штатный NV `WCNSS_qcom_wlan_nv.bin` из `persist` своего устройства (не публикуется).
Без NV Pronto падает по `Watchdog startup timeout` каждые ~46 с.
- Ядро: `QCOM_WCNSS_PIL`, `CFG80211`, `MAC80211`, `WCN36XX` built-in → `phy0` (2.4 GHz, AP/managed) → `wlan0`.
- Сервис `aurora-wifi`: после LTE START OK → WCNSS → wlan0 → hostapd 2.11 (тестовая AP, WPA2-PSK/CCMP, канал 6). PSK в репозитории нет (`wifi.conf.in`).
- 3/3 холодных загрузки с eMMC без ввода: AP через 76–94 с после включения, телефон подключается и держит соединение, LTE не страдает.
- Открыто: задержка кадров к клиенту в power save (у wcn36xx нет `set_tim`), нет regulatory.db (world `00`), MAC `02:…` из DT lk2nd.
- Нет DHCP/NAT/DNS/firewall — это следующий этап (router stack). Материалы: `b8/`, `logs/b8/`, NOTES.md сессия 36.
## B6P status — PASS
Implemented:
@ -188,12 +102,6 @@ Safety:
| `b6/` | первый RAM-only прототип контроллера (сессия 28) |
| `b6j/` | диагностика B6J–B6N: rmtfs-аудит, AT/QMI-снимки, state machine регистрации, харнессы |
| `b6p/` | persistent-интеграция: контроллер, сервис, конфиг, сборка initramfs/boot.img/cache, эмулятор, запись/откат, тесты |
| `b7/` | B7: время от сети (DMS/NITZ), проверка по NTP, cache B7C |
| `b8/` | B8: Wi-Fi — аудит, WCNSS/NV, wcn36xx, hostapd, сервис aurora-wifi, cache B8F (запись/откат/эмулятор) |
| `b9/` | B9: дисплей — аудит stock LK/DT, panel-mipi-dbi firmware, fbcon/сервис aurora-display, cache B9C, патч lk2nd (SPI-панель в LK) |
| `b10/` | B10: батарея/зарядка — аудит, супервизор v1–v4 (патчи/diff), тестовые DTB/сборки/скрипты, хуки B10B-4/5 (только тест), cache B10B-5 (запись/откат/эмулятор) |
| `b11/`…`b22/` | B11 LED/кнопки; B12 Alpine (rootfs, overlay, cache B12P/Q/R, роутер); B13 Wayland; B14/B16 aurora-ui (исходники); B15 VPN; B17 standalone; B18 USB OTG + cache; B20 netwatch/blackbox; B22 выбор VPN-пути |
| `b23/` | B23: ток зарядки 720 mA — сборка RAM-образа, монитор, cache B23 (сборка/эмулятор/запись/откат) |
| `tools/` | утилиты: UART-логгер, Sahara probe, распаковка boot.img, sanitizer публикации |
| `logs/` | sanitized логи: UART, QMI, ModemManager, EDL, результаты тестов |
| `android/` | снимок стокового Android (getprop, gpio, input, leds, …), sanitized |
@ -201,10 +109,6 @@ Safety:
## Что намеренно не опубликовано
Полные дампы eMMC и разделов, NV/EFS (`modemst1/2`, `fsg`, `fsc`), `persist`, `userdata`, файлы прошивки модема,
стоковые SBL1/RPM/TZ/aboot/boot/recovery/system, Firehose-программер, DB410c TZ, собранные бинарники,
Wi-Fi NV (`WCNSS_qcom_wlan_nv.bin`), PSK тестовой AP и образы с ним (B8F/B9C/B10 initramfs/cache/RAM-образы), логотип из stock LK.
С B12: `wifi.conf` (SSID/PSK), конфиги и ключи WireGuard/relay, адрес VPN-сервера, сторонний relay-клиент и его исходники, учётные данные и TLS-ключ wayvnc, `authorized_keys`, образы rootfs/cache (B12–B23).
Начиная с B10 сырые логи прогонов (мониторы, dmesg, snapshot, UART, журналы действий, дампы регистров, выводы эмулятора) не публикуются —
только отчёты `*.md` и компактные таблицы `*-diff.txt` (правила в `tools/publish-sanitize.py` и `.gitignore`).
стоковые SBL1/RPM/TZ/aboot/boot/recovery/system, Firehose-программер, DB410c TZ, собранные бинарники.
Идентификаторы (IMEI, IMSI, ICCID, eMMC CID/serial, Sahara serial, MAC, номера сот, cookies) заменены на `<PLACEHOLDER>`.
Как это сделано — `tools/publish-sanitize.py`; значения идентификаторов в репозиторий не попадают.

View file

@ -1,12 +0,0 @@
#!/bin/sh
# B10A load probe: idle 20 s, 4x `yes` for 60 s, idle 30 s; sample BMS FIFO + CHGR/USB RT every 5 s. Reads only.
grep -q " /sys/kernel/debug " /proc/mounts || mount -t debugfs debugfs /sys/kernel/debug
R=/sys/kernel/debug/regmap/0-00/registers
rd() { dd if=$R bs=9 skip=$(($1)) count=$2 2>/dev/null | cut -d' ' -f2 | tr '\n' ' '; }
s() { echo "$1 $(date +%T) up=$(cut -d' ' -f1 /proc/uptime) fifo=$(rd 0x40c0 10) chgrt=$(rd 0x1010 1) usbrt=$(rd 0x1310 1) t=$(cat /sys/class/thermal/thermal_zone4/temp) f=$(cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_cur_freq)"; }
for i in 1 2 3 4; do s IDLE0; sleep 5; done
echo "LOAD-ON $(date +%T)"; for c in 1 2 3 4; do yes > /dev/null & done
for i in 1 2 3 4 5 6 7 8 9 10 11 12; do s LOAD; sleep 5; done
killall yes; echo "LOAD-OFF $(date +%T)"
for i in 1 2 3 4 5 6; do s IDLE1; sleep 5; done
echo B10A-LOAD-END

View file

@ -1,11 +0,0 @@
#!/bin/sh
# B10A 30-min read-only monitor: every 60 s read LBC/USB/BMS registers. Reads only (regmap debugfs), no writes.
grep -q " /sys/kernel/debug " /proc/mounts || mount -t debugfs debugfs /sys/kernel/debug
R=/sys/kernel/debug/regmap/0-00/registers
rd() { dd if=$R bs=9 skip=$(($1)) count=$2 2>/dev/null | cut -d' ' -f2 | tr '\n' ' '; }
i=0
while [ $i -lt ${1:-31} ]; do
echo "M $i up=$(cut -d' ' -f1 /proc/uptime) st1009=$(rd 0x1009 3) rt1010=$(rd 0x1010 1) vdd1040=$(rd 0x1040 1) ibat1044=$(rd 0x1044 1) ctrl1049=$(rd 0x1049 1) usb1308=$(rd 0x1308 2) usbrt1310=$(rd 0x1310 1) batrt1210=$(rd 0x1210 1) fifo=$(rd 0x40c0 10) ocv=$(rd 0x406a 2) bms4008=$(rd 0x4008 2) tcpu=$(cat /sys/class/thermal/thermal_zone4/temp)"
i=$((i+1)); [ $i -lt ${1:-31} ] && sleep 60
done
echo B10A-MON-END

View file

@ -1,10 +0,0 @@
#!/bin/sh
# B10A read-only: USB gadget power descriptor, cpuidle/cpufreq/suspend state.
for f in /sys/kernel/config/usb_gadget/*/configs/*/MaxPower /sys/kernel/config/usb_gadget/*/configs/*/bmAttributes; do echo "$f $(cat $f)"; done
echo "cpuidle driver: $(cat /sys/devices/system/cpu/cpuidle/current_driver 2>&1) gov: $(cat /sys/devices/system/cpu/cpuidle/current_governor 2>&1)"
for s in /sys/devices/system/cpu/cpu0/cpuidle/state*; do echo "$s $(cat $s/name) usage=$(cat $s/usage) time=$(cat $s/time)"; done
ls /sys/devices/system/cpu/cpu0/cpufreq 2>&1 | head -3
echo "online: $(cat /sys/devices/system/cpu/online) power/state: $(cat /sys/power/state) mem_sleep: $(cat /sys/power/mem_sleep 2>&1)"
cat /proc/loadavg
grep -i -E "cpuidle|psci|cpufreq|suspend" /proc/config.gz 2>/dev/null | head -1
dmesg | grep -i -E "psci|cpuidle|cpufreq|idle" | head -10

View file

@ -1,22 +0,0 @@
#!/bin/sh
# B10A read-only probe: power_supply/extcon/regulator state + PM8916 charger/BMS/VADC/PON register dump.
# Only reads (regmap debugfs positioned reads, sysfs/proc reads). No writes to any device register.
grep -q " /sys/kernel/debug " /proc/mounts || mount -t debugfs debugfs /sys/kernel/debug
R=/sys/kernel/debug/regmap/0-00/registers
echo "== B10A-PROBE-START $(date -u +%s) up $(cut -d' ' -f1 /proc/uptime)"
uname -a
echo "== power_supply"; ls -la /sys/class/power_supply/ 2>&1
for d in /sys/class/power_supply/*; do [ -e "$d/uevent" ] && { echo "-- $d"; cat "$d/uevent"; }; done
echo "== extcon"; for e in /sys/class/extcon/*; do echo "-- $e $(cat $e/name 2>/dev/null)"; cat $e/state 2>/dev/null; done
echo "== thermal"; for t in /sys/class/thermal/thermal_zone*; do echo "$t $(cat $t/type) $(cat $t/temp 2>/dev/null)"; done
echo "== hwmon"; for h in /sys/class/hwmon/*; do echo "$h $(cat $h/name)"; done
echo "== iio"; ls /sys/bus/iio/devices 2>&1
echo "== regmaps"; ls /sys/kernel/debug/regmap/
echo "== regulator_summary"; cat /sys/kernel/debug/regulator/regulator_summary 2>&1 | head -60
echo "== udc"; for u in /sys/class/udc/*; do echo "$u state=$(cat $u/state 2>/dev/null) speed=$(cat $u/current_speed 2>/dev/null)"; done
echo "== dmesg-power"; dmesg | grep -i -E "charg|batt|bms|vbus|usb_vbus|extcon|power_supply|ci_hdrc|pm8916|pon|uvlo|thermal|tsens|spmi" | head -80
echo "== interrupts"; grep -i -E "pm8916|spmi|pon|usb|chg|bat" /proc/interrupts
for blk in 0100 0800 0900 1000 1200 1300 1600 2400 2800 3100 3400 4000 a300; do
echo "== REG $blk"; dd if=$R bs=9 skip=$((0x$blk)) count=256 2>/dev/null
done
echo "== B10A-PROBE-END"

View file

@ -1,10 +0,0 @@
#!/bin/sh
# B10A read-only trend: every 30 s read BMS FIFO/status, CHGR/BAT_IF/USB RT_STS, VADC last data. Reads only.
R=/sys/kernel/debug/regmap/0-00/registers
rd() { dd if=$R bs=9 skip=$(($1)) count=$2 2>/dev/null | cut -d' ' -f2 | tr '\n' ' '; }
i=0
while [ $i -lt ${1:-10} ]; do
echo "T $(cut -d' ' -f1 /proc/uptime) bms08=$(rd 0x4008 2) fifo=$(rd 0x40c0 10) ocv=$(rd 0x406a 2) chg09=$(rd 0x1009 1) chgrt=$(rd 0x1010 1) batrt=$(rd 0x1210 1) usbrt=$(rd 0x1310 1) vadc=$(rd 0x3160 2) ch=$(rd 0x3148 1) temps=$(cat /sys/class/thermal/thermal_zone*/temp | tr '\n' ' ')"
i=$((i+1)); sleep 30
done
echo B10A-TREND-END

File diff suppressed because it is too large Load diff

File diff suppressed because it is too large Load diff

View file

@ -1,57 +0,0 @@
#!/bin/sh
# 480s side, B10B-0 boot K (RAM only). RESET-held power-on -> lk1st fastboot -> `fastboot boot` B10B-0 RAM image. Reads only over telnet.
# MODE=cold: normal power-on (no RESET, no fastboot) -> lk2nd extlinux from eMMC cache. Script only observes + reads over telnet;
# nothing is written to eMMC. Visual display checks need the operator. Adds display/fbcon/getty/console checks to the B8F snapshot.
K=$1; MODE=ram; [ -n "$K" ] || { echo "usage: $0 K"; exit 2; }
cd ~/doc/modem/jz08-aurora; O=logs/b10/b10b0/$MODE$K; mkdir -p $O; IMG=b10/b10b0/out/aurora-b10b0.img
A=$O/host-actions.txt; act() { echo "$(date -u +%H:%M:%S.%3N) $*" | tee -a $A; }
tn() { { sleep 1; sed "s/\$/\r/" "$1"; sleep $2; } | ncat 172.16.42.1 23 | tr -d "\000\r"; }
OLD=$(ps -eo pid,cmd | grep "[u]artlog.py /dev/ttyUSB0" | awk '{print $1}'); [ -n "$OLD" ] && kill $OLD; sleep 1
U=logs/uart/b10b0-$MODE$K-$(date +%Y%m%d-%H%M%S); setsid nohup python3 tools/uartlog.py /dev/ttyUSB0 $U > $U.stderr 2>&1 < /dev/null &
if [ $MODE = ram ]; then
echo "a360aee2cb822d737c7409deb71b39951e02c436f5252e88d96c0583cb81e2bb $IMG" | sha256sum -c || exit 1
act "B10B0 $MODE$K: waiting for fastboot <EMMC_SERIAL> (power off >= 90 s, then RESET held + battery -> USB)"
if fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; then act "already in fastboot - wait for power-off"; until ! fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do sleep 1; done; fi
i=0; until fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do i=$((i+1)); [ $i -ge 600 ] && { act "ABORT: no fastboot"; exit 1; }; sleep 2; done
act "fastboot present"; { fastboot boot $IMG 2>&1; echo "rc=$?"; } | tee -a $A
else
act "B10B0 $MODE$K: waiting for the board to go away (power off >= 90 s), then normal power-on WITHOUT RESET"
until ! ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do sleep 1; done; act "board unreachable (powered off)"
until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL> && { act "ABORT: board is in fastboot - RESET was held?"; exit 1; }; sleep 1; done
fi
i=0; until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do i=$((i+1)); [ $i -ge 180 ] && { act "ABORT: NCM not up"; cp $U.log $O/uart.log; exit 1; }; sleep 1; done; act "NCM ping ok"
R=$(grep -a "rtc-pm8xxx.*setting system clock" $U.log | tail -1 | sed -n 's/.*(\([0-9]*\)).*/\1/p'); C=B; [ -n "$R" ] && [ "$R" -lt 40 ] && C=A; act "RTC at boot ${R:-?} s -> class $C"
printf 'cat /proc/device-tree/model; echo; uname -r; grep -E "START OK|FAIL in|rollback" /run/aurora-modem/lifecycle.log | tail -1\n' > $O/.w
i=0; until tn $O/.w 3 | grep -qE "^\[[0-9.]+\] .*(=== START OK|FAIL in|rollback)"; do i=$((i+1)); [ $i -ge 80 ] && { act "no START OK/FAIL after ~12 min"; break; }; sleep 6; done
tn $O/.w 3 | grep -aE "Aurora|aurora-b8|START OK|FAIL" | tee -a $A
printf 'grep -E "AP ENABLED|FAIL" /run/aurora-wifi/wifi.log | tail -1\n' > $O/.a
i=0; until tn $O/.a 3 | grep -qE "^\[[0-9.]+\] (=== AP ENABLED|FAIL)"; do i=$((i+1)); [ $i -ge 20 ] && { act "no AP ENABLED/FAIL after ~3 min"; break; }; sleep 6; done
act "wifi: $(tn $O/.a 3 | grep -E '^\[[0-9.]+\] (=== AP ENABLED|FAIL)' | tail -1)"
printf 'grep -E "SNTP (check|STEP|: )" /run/aurora-modem/lifecycle.log | tail -2\n' > $O/.s
i=0; until tn $O/.s 3 | grep -qE "^\[[0-9.]+\] SNTP"; do i=$((i+1)); [ $i -ge 15 ] && break; sleep 4; done; act "sntp: $(tn $O/.s 3 | grep -E '^\[[0-9.]+\] SNTP' | tail -2 | tr '\n' ' ')"
cat > $O/.c <<'C'
echo SNAP-BEGIN; cat /proc/uptime; date -u; cat /proc/device-tree/model; echo; uname -a; cat /proc/cmdline
echo ---time; cat /run/aurora-modem/time-set; grep -E "TIME|SNTP" /run/aurora-modem/lifecycle.log | tail -4
echo ---modem; /etc/init.d/aurora-modem status
echo ---wifi; /etc/init.d/aurora-wifi status; echo ---wifilog; cat /run/aurora-wifi/wifi.log; cat /run/aurora-wifi/service.log; echo ---hostapdlog; cat /run/aurora-wifi/hostapd.log
for r in /sys/class/remoteproc/*; do echo "RP $(cat $r/name)=$(cat $r/state)"; done; iw dev
echo ---dmesg-wifi; dmesg | grep -iE "wcn36xx|wcnss|a204000|cfg80211|aurora-wifi|crash|watchdog"
echo ---ping; ping -c4 -W3 -I wwan0 77.88.8.8 | tail -2
echo ---display; /etc/init.d/aurora-display status; cat /run/aurora-display/display.log; cat /run/aurora-display/service.log
echo ---consoles; cat /sys/class/tty/console/active; for v in /sys/class/vtconsole/vtcon*; do echo "$v $(cat $v/bind) $(cat $v/name)"; done; ls -l /proc/[0-9]*/fd/0 2>/dev/null | grep -E "ttyMSM0|tty1|console" | sed "s/.* \/proc/\/proc/"
echo ---getty; hostname; ps | grep -E "[g]etty|[c]ttyhack| sh$"
echo ---fb; ls -l /dev/dri/card0 /dev/fb0; for f in name bits_per_pixel virtual_size stride; do echo "fb0 $f=$(cat /sys/class/graphics/fb0/$f)"; done; cat /sys/class/drm/card0-SPI-1/enabled /sys/class/drm/card0-SPI-1/dpms
echo ---regs; for r in /sys/class/regulator/regulator.*; do n=$(cat $r/name); case $n in l6|l17) echo "$n $(cat $r/state) $(cat $r/microvolts) users=$(cat $r/num_users)";; esac; done
echo ---bl; for f in bl_power brightness actual_brightness; do echo "bl $f=$(cat /sys/class/backlight/backlight/$f)"; done
echo ---dmesg-display; dmesg | grep -iE "drm|panel|mipi|spi_qup|78b8000|fbcon|Console: |frame buffer|backlight|aurora-display|l17"
echo ---display-errors; dmesg | grep -iE "drm|panel|mipi|spi0|fbcon|backlight|aurora-display" | grep -ciE "err|fail|timeout|warn"
echo ---iio; for d in /sys/bus/iio/devices/iio:device*; do echo "$d name=$(cat $d/name)"; ls $d | tr '\n' ' '; echo; done
for f in /sys/bus/iio/devices/iio:device*/in_*; do case $f in *_raw|*_input|*_scale|*_offset) echo "$f=$(cat $f 2>&1)";; esac; done
echo ---thermal; for t in /sys/class/thermal/thermal_zone*; do echo "$t $(cat $t/type) $(cat $t/temp)"; done
echo ---dmesg-adc; dmesg | grep -iE "vadc|iio|temp-alarm|qpnp|spmi-temp|pm8916-thermal|thermal"
echo ---emmc; awk "{print \"w=\"\$5\" s=\"\$7}" /sys/block/mmcblk0/stat
echo SNAP-END
C
tn $O/.c 25 > $O/snapshot.txt; act "snapshot: $(grep -c SNAP-END $O/snapshot.txt) end markers; $(grep -E '^RP a204' $O/snapshot.txt)"
printf 'dmesg > /tmp/dm.txt; nc -l -p 9881 < /tmp/dm.txt &\n' > $O/.d; tn $O/.d 3 >/dev/null; sleep 1; ncat --recv-only 172.16.42.1 9881 > $O/dmesg.full
cp $U.log $O/uart.log; act "B10B0 $MODE$K END - operator visual check next"

View file

@ -1,19 +0,0 @@
#!/bin/sh
# B10B-0 VBAT calibration series: N samples, P s apart. Reads IIO (VADC) + BMS FIFO/charger status via regmap debugfs (reads only).
# Shows the sample number on the display (tty1) so the operator can note the DMM value (BAT+ - BAT-) for each sample.
N=${1:-12}; P=${2:-20}
grep -q " /sys/kernel/debug " /proc/mounts || mount -t debugfs debugfs /sys/kernel/debug
R=/sys/kernel/debug/regmap/0-00/registers
rd() { dd if=$R bs=9 skip=$(($1)) count=$2 2>/dev/null | cut -d' ' -f2 | tr '\n' ' '; }
D=$(for d in /sys/bus/iio/devices/iio:device*; do [ "$(cat $d/name 2>/dev/null)" = "adc@3100" ] && echo $d; done | head -1)
[ -z "$D" ] && D=$(ls -d /sys/bus/iio/devices/iio:device* | head -1)
echo "CAL-START dev=$D name=$(cat $D/name) files: $(cd $D && ls | grep -E '^in_' | tr '\n' ' ')"
i=1
while [ $i -le $N ]; do
printf '\033[2J\033[H\n\n B10B-0 CAL\n\n SAMPLE %d / %d\n\n read DMM now\n' $i $N > /dev/tty1
v=""; for f in $D/in_voltage6_*raw $D/in_voltage6_*input $D/in_voltage7_*raw $D/in_voltage7_*input; do [ -e "$f" ] && v="$v ${f##*/}=$(cat $f)"; done
echo "S $i $(date -u +%T) up=$(cut -d' ' -f1 /proc/uptime)$v fifo=$(rd 0x40c0 10) st1009=$(rd 0x1009 1) usb1308=$(rd 0x1308 1) rt1010=$(rd 0x1010 1) tz=$(for t in /sys/class/thermal/thermal_zone*; do printf "%s:%s," $(cat $t/type) $(cat $t/temp); done)"
i=$((i + 1)); [ $i -le $N ] && sleep $P
done
printf '\033[2J\033[H\n\n B10B-0 CAL\n\n DONE\n' > /dev/tty1
echo CAL-END

View file

@ -1,13 +0,0 @@
#!/bin/sh
# B10B-0 read-only full dump of PM8916 SID0: every 0x100 peripheral block whose TYPE (offset 0x04) is non-zero. Reads only.
grep -q " /sys/kernel/debug " /proc/mounts || mount -t debugfs debugfs /sys/kernel/debug
R=/sys/kernel/debug/regmap/0-00/registers
echo "== DUMP-START up=$(cut -d' ' -f1 /proc/uptime) $(uname -r) emmc=$(awk '{print "w="$5}' /sys/block/mmcblk0/stat)"
b=1
while [ $b -lt 256 ]; do
a=$((b * 256))
t=$(dd if=$R bs=9 skip=$((a + 4)) count=1 2>/dev/null | cut -d' ' -f2)
if [ -n "$t" ] && [ "$t" != "00" ]; then dd if=$R bs=9 skip=$a count=256 2>/dev/null; fi
b=$((b + 1))
done
echo "== DUMP-END up=$(cut -d' ' -f1 /proc/uptime)"

View file

@ -1,19 +0,0 @@
#!/bin/sh
# B10B-0 RAM test image (fastboot boot only - never flash; cache B9C / aboot untouched):
# kernel = out-b10b0 (b9c + IIO + QCOM_SPMI_VADC + QCOM_SPMI_TEMP_ALARM; linux/aurora-b10b0.config). No BMS, no LBC.
# DTB = linux/dts/msm8916-jz08-aurora-b10b0.dtb (B9B DTB 7ca9cc79 + VADC channel@6 VBAT_SNS 1/3 + model string)
# initramfs + cmdline = exact B9C (b9/b9c/out). out/ contains the B8F initramfs (Wi-Fi PSK): never publish.
set -e; cd "$(dirname "$0")"; O=out; KB=/home/q/aurora-kbuild/out-b10b0; L=../../linux; B9C=../../b9/b9c/out
mkdir -p $O
echo "7ca9cc794a3b85d3b7240f6311ad03bee9e1a4a59aae2ed9438318e853f7c3dc $L/dts/msm8916-jz08-aurora-b9b.dtb" | sha256sum -c
grep " initramfs-b9c.cpio.gz\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
grep " cmdline.txt\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
for s in IIO=y QCOM_SPMI_VADC=y QCOM_SPMI_TEMP_ALARM=y 'LOCALVERSION="-aurora-b10b0"'; do grep -q "^CONFIG_$s\$" $KB/.config || { echo "STOP: CONFIG_$s"; exit 1; }; done
for s in CHARGER_PM8916_LBC BATTERY_PM8916_BMS_VM; do grep -q "^CONFIG_$s=y" $KB/.config && { echo "STOP: $s enabled"; exit 1; }; done
cp $KB/arch/arm64/boot/Image.gz $O/Image.gz; cp $KB/.config $O/config-b10b0; cp $L/dts/msm8916-jz08-aurora-b10b0.dtb $O/aurora-b10b0.dtb
cp $B9C/initramfs-b9c.cpio.gz $O/initramfs.cpio.gz; cp $B9C/cmdline.txt $O/cmdline.txt
cat $O/Image.gz $O/aurora-b10b0.dtb > $O/Image.gz-dtb
python3 ../../b6p/mkbootimg.py $O/Image.gz-dtb $O/initramfs.cpio.gz $O/cmdline.txt $O/aurora-b10b0.img
SZ=$(python3 -c "import struct;print(struct.unpack_from('<Q',open('$KB/arch/arm64/boot/Image','rb').read(24),16)[0])")
printf 'kernel image_size 0x%x, RAM-boot end 0x%x (< 0x81e00000 DTB)\n' $SZ $((0x80000000 + SZ)); [ $((0x80000000 + SZ)) -lt $((0x81e00000)) ]
(cd $O && sha256sum Image.gz aurora-b10b0.dtb Image.gz-dtb config-b10b0 cmdline.txt initramfs.cpio.gz aurora-b10b0.img > SHA256SUMS; cat SHA256SUMS); ls -l $O/aurora-b10b0.img

View file

@ -1,7 +0,0 @@
ca099bf36ab03a2ad3a984b1920723f1e619d4f69b1c8d5742b59fda55acad71 Image.gz
7837c5047ecfd6ce44ba6c3045904a68a3656ced835b7d35469f00d1fb1a88a7 aurora-b10b0.dtb
8f244e82cc425a8522515e535cca27908757b0fe26e877ddde5a6680a94710f5 Image.gz-dtb
27eab277cd2b6e74389ed9801d025d9f53046e9b2e6dac091b0a5e753e86017a config-b10b0
0fef41b262917c8ae308fa222da0017e2b3cb3ec5da1ca8ba18d0318476761a3 cmdline.txt
ac518e27e2957ad5e4515969b9a3808024e11ef8d1a79433a899a67dbc644558 initramfs.cpio.gz
a360aee2cb822d737c7409deb71b39951e02c436f5252e88d96c0583cb81e2bb aurora-b10b0.img

View file

@ -1 +0,0 @@
earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0

View file

@ -1,59 +0,0 @@
#!/bin/sh
# 480s side, B10B-1 boot K (RAM only). RESET-held power-on -> lk1st fastboot -> `fastboot boot` B10B-1 RAM image. Reads only over telnet.
# MODE=cold: normal power-on (no RESET, no fastboot) -> lk2nd extlinux from eMMC cache. Script only observes + reads over telnet;
# nothing is written to eMMC. Visual display checks need the operator. Adds display/fbcon/getty/console checks to the B8F snapshot.
K=$1; MODE=ram; [ -n "$K" ] || { echo "usage: $0 K"; exit 2; }
cd ~/doc/modem/jz08-aurora; O=logs/b10/b10b1/$MODE$K; mkdir -p $O; IMG=b10/b10b1/out/aurora-b10b1.img
A=$O/host-actions.txt; act() { echo "$(date -u +%H:%M:%S.%3N) $*" | tee -a $A; }
tn() { { sleep 1; sed "s/\$/\r/" "$1"; sleep $2; } | ncat 172.16.42.1 23 | tr -d "\000\r"; }
OLD=$(ps -eo pid,cmd | grep "[u]artlog.py /dev/ttyUSB0" | awk '{print $1}'); [ -n "$OLD" ] && kill $OLD; sleep 1
U=logs/uart/b10b1-$MODE$K-$(date +%Y%m%d-%H%M%S); setsid nohup python3 tools/uartlog.py /dev/ttyUSB0 $U > $U.stderr 2>&1 < /dev/null &
if [ $MODE = ram ]; then
echo "1029647d6a245481ff8488dabea2ab53cb15f800f5ddbb07a2737b83ae06d4ac $IMG" | sha256sum -c || exit 1
act "B10B1 $MODE$K: waiting for fastboot <EMMC_SERIAL> (power off >= 90 s, then RESET held + battery -> USB)"
if fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; then act "already in fastboot - wait for power-off"; until ! fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do sleep 1; done; fi
i=0; until fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do i=$((i+1)); [ $i -ge 1800 ] && { act "ABORT: no fastboot"; exit 1; }; sleep 2; done
act "fastboot present"; { fastboot boot $IMG 2>&1; echo "rc=$?"; } | tee -a $A
else
act "B10B1 $MODE$K: waiting for the board to go away (power off >= 90 s), then normal power-on WITHOUT RESET"
until ! ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do sleep 1; done; act "board unreachable (powered off)"
until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL> && { act "ABORT: board is in fastboot - RESET was held?"; exit 1; }; sleep 1; done
fi
i=0; until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do i=$((i+1)); [ $i -ge 180 ] && { act "ABORT: NCM not up"; cp $U.log $O/uart.log; exit 1; }; sleep 1; done; act "NCM ping ok"
R=$(grep -a "rtc-pm8xxx.*setting system clock" $U.log | tail -1 | sed -n 's/.*(\([0-9]*\)).*/\1/p'); C=B; [ -n "$R" ] && [ "$R" -lt 40 ] && C=A; act "RTC at boot ${R:-?} s -> class $C"
printf 'cat /proc/device-tree/model; echo; uname -r; grep -E "START OK|FAIL in|rollback" /run/aurora-modem/lifecycle.log | tail -1\n' > $O/.w
i=0; until tn $O/.w 3 | grep -qE "^\[[0-9.]+\] .*(=== START OK|FAIL in|rollback)"; do i=$((i+1)); [ $i -ge 80 ] && { act "no START OK/FAIL after ~12 min"; break; }; sleep 6; done
tn $O/.w 3 | grep -aE "Aurora|aurora-b8|START OK|FAIL" | tee -a $A
printf 'grep -E "AP ENABLED|FAIL" /run/aurora-wifi/wifi.log | tail -1\n' > $O/.a
i=0; until tn $O/.a 3 | grep -qE "^\[[0-9.]+\] (=== AP ENABLED|FAIL)"; do i=$((i+1)); [ $i -ge 20 ] && { act "no AP ENABLED/FAIL after ~3 min"; break; }; sleep 6; done
act "wifi: $(tn $O/.a 3 | grep -E '^\[[0-9.]+\] (=== AP ENABLED|FAIL)' | tail -1)"
printf 'grep -E "SNTP (check|STEP|: )" /run/aurora-modem/lifecycle.log | tail -2\n' > $O/.s
i=0; until tn $O/.s 3 | grep -qE "^\[[0-9.]+\] SNTP"; do i=$((i+1)); [ $i -ge 15 ] && break; sleep 4; done; act "sntp: $(tn $O/.s 3 | grep -E '^\[[0-9.]+\] SNTP' | tail -2 | tr '\n' ' ')"
cat > $O/.c <<'C'
echo SNAP-BEGIN; cat /proc/uptime; date -u; cat /proc/device-tree/model; echo; uname -a; cat /proc/cmdline
echo ---time; cat /run/aurora-modem/time-set; grep -E "TIME|SNTP" /run/aurora-modem/lifecycle.log | tail -4
echo ---modem; /etc/init.d/aurora-modem status
echo ---wifi; /etc/init.d/aurora-wifi status; echo ---wifilog; cat /run/aurora-wifi/wifi.log; cat /run/aurora-wifi/service.log; echo ---hostapdlog; cat /run/aurora-wifi/hostapd.log
for r in /sys/class/remoteproc/*; do echo "RP $(cat $r/name)=$(cat $r/state)"; done; iw dev
echo ---dmesg-wifi; dmesg | grep -iE "wcn36xx|wcnss|a204000|cfg80211|aurora-wifi|crash|watchdog"
echo ---ping; ping -c4 -W3 -I wwan0 77.88.8.8 | tail -2
echo ---display; /etc/init.d/aurora-display status; cat /run/aurora-display/display.log; cat /run/aurora-display/service.log
echo ---consoles; cat /sys/class/tty/console/active; for v in /sys/class/vtconsole/vtcon*; do echo "$v $(cat $v/bind) $(cat $v/name)"; done; ls -l /proc/[0-9]*/fd/0 2>/dev/null | grep -E "ttyMSM0|tty1|console" | sed "s/.* \/proc/\/proc/"
echo ---getty; hostname; ps | grep -E "[g]etty|[c]ttyhack| sh$"
echo ---fb; ls -l /dev/dri/card0 /dev/fb0; for f in name bits_per_pixel virtual_size stride; do echo "fb0 $f=$(cat /sys/class/graphics/fb0/$f)"; done; cat /sys/class/drm/card0-SPI-1/enabled /sys/class/drm/card0-SPI-1/dpms
echo ---regs; for r in /sys/class/regulator/regulator.*; do n=$(cat $r/name); case $n in l6|l17) echo "$n $(cat $r/state) $(cat $r/microvolts) users=$(cat $r/num_users)";; esac; done
echo ---bl; for f in bl_power brightness actual_brightness; do echo "bl $f=$(cat /sys/class/backlight/backlight/$f)"; done
echo ---dmesg-display; dmesg | grep -iE "drm|panel|mipi|spi_qup|78b8000|fbcon|Console: |frame buffer|backlight|aurora-display|l17"
echo ---display-errors; dmesg | grep -iE "drm|panel|mipi|spi0|fbcon|backlight|aurora-display" | grep -ciE "err|fail|timeout|warn"
echo ---iio; for d in /sys/bus/iio/devices/iio:device*; do echo "$d name=$(cat $d/name)"; ls $d | tr '\n' ' '; echo; done
for f in /sys/bus/iio/devices/iio:device*/in_*; do case $f in *_raw|*_input|*_scale|*_offset) echo "$f=$(cat $f 2>&1)";; esac; done
echo ---psy; ls -l /sys/class/power_supply/; for p in /sys/class/power_supply/*; do echo "-- $p"; cat $p/uevent; ls $p; done
echo ---dmesg-bms; dmesg | grep -iE "bms|battery|power_supply|4000"
echo ---thermal; for t in /sys/class/thermal/thermal_zone*; do echo "$t $(cat $t/type) $(cat $t/temp)"; done
echo ---dmesg-adc; dmesg | grep -iE "vadc|iio|temp-alarm|qpnp|spmi-temp|pm8916-thermal|thermal"
echo ---emmc; awk "{print \"w=\"\$5\" s=\"\$7}" /sys/block/mmcblk0/stat
echo SNAP-END
C
tn $O/.c 25 > $O/snapshot.txt; act "snapshot: $(grep -c SNAP-END $O/snapshot.txt) end markers; $(grep -E '^RP a204' $O/snapshot.txt)"
printf 'dmesg > /tmp/dm.txt; nc -l -p 9881 < /tmp/dm.txt &\n' > $O/.d; tn $O/.d 3 >/dev/null; sleep 1; ncat --recv-only 172.16.42.1 9881 > $O/dmesg.full
cp $U.log $O/uart.log; act "B10B1 $MODE$K END - operator visual check next"

View file

@ -1,16 +0,0 @@
#!/bin/sh
# B10B-1 series: N samples, P s apart. Reads VADC (IIO), BMS-VM power_supply properties, BMS FIFO/OCV raw and charger status (reads only).
N=${1:-12}; P=${2:-20}
grep -q " /sys/kernel/debug " /proc/mounts || mount -t debugfs debugfs /sys/kernel/debug
R=/sys/kernel/debug/regmap/0-00/registers
rd() { dd if=$R bs=9 skip=$(($1)) count=$2 2>/dev/null | cut -d' ' -f2 | tr '\n' ' '; }
D=/sys/bus/iio/devices/iio:device0; B=$(ls -d /sys/class/power_supply/*bms* 2>/dev/null | head -1)
echo "CAL-START iio=$(cat $D/name) bms=$B props: $(ls $B | tr '\n' ' ')"
i=1
while [ $i -le $N ]; do
printf '\033[2J\033[H\n\n B10B-1\n\n SAMPLE %d / %d\n' $i $N > /dev/tty1
echo "S $i $(date -u +%T) up=$(cut -d' ' -f1 /proc/uptime) r6=$(cat $D/in_voltage6_raw) r9=$(cat $D/in_voltage9_raw) r10=$(cat $D/in_voltage10_raw) vph=$(cat $D/in_voltage7_input) bms_v=$(cat $B/voltage_now 2>&1) bms_ocv=$(cat $B/voltage_ocv 2>&1) bms_st=$(cat $B/status 2>&1) bms_h=$(cat $B/health 2>&1) fifo=$(rd 0x40c0 4) ocv=$(rd 0x406a 2) st1009=$(rd 0x1009 1) usb1308=$(rd 0x1308 1) irq=$(grep -i vm_bms /proc/interrupts | awk '{print $2+$3+$4+$5}') pmt=$(cat $D/in_temp8_input)"
i=$((i + 1)); [ $i -le $N ] && sleep $P
done
printf '\033[2J\033[H\n\n B10B-1\n\n DONE\n' > /dev/tty1
echo CAL-END

View file

@ -1,19 +0,0 @@
#!/bin/sh
# B10B-1 RAM test image (fastboot boot only - never flash; cache B9C / aboot untouched):
# kernel = out-b10b1 (b10b0 + BATTERY_PM8916_BMS_VM; linux/aurora-b10b1.config). No LBC.
# DTB = linux/dts/msm8916-jz08-aurora-b10b1.dtb (B10B-0 DTB + simple-battery 3000 mAh/3.4-4.2 V + pm8916_bms okay)
# initramfs + cmdline = exact B9C (b9/b9c/out). out/ contains the B8F initramfs (Wi-Fi PSK): never publish.
set -e; cd "$(dirname "$0")"; O=out; KB=/home/q/aurora-kbuild/out-b10b1; L=../../linux; B9C=../../b9/b9c/out
mkdir -p $O
echo "7ca9cc794a3b85d3b7240f6311ad03bee9e1a4a59aae2ed9438318e853f7c3dc $L/dts/msm8916-jz08-aurora-b9b.dtb" | sha256sum -c
grep " initramfs-b9c.cpio.gz\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
grep " cmdline.txt\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
for s in IIO=y QCOM_SPMI_VADC=y BATTERY_PM8916_BMS_VM=y QCOM_SPMI_TEMP_ALARM=y 'LOCALVERSION="-aurora-b10b1"'; do grep -q "^CONFIG_$s\$" $KB/.config || { echo "STOP: CONFIG_$s"; exit 1; }; done
for s in CHARGER_PM8916_LBC; do grep -q "^CONFIG_$s=y" $KB/.config && { echo "STOP: $s enabled"; exit 1; }; done
cp $KB/arch/arm64/boot/Image.gz $O/Image.gz; cp $KB/.config $O/config-b10b1; cp $L/dts/msm8916-jz08-aurora-b10b1.dtb $O/aurora-b10b1.dtb
cp $B9C/initramfs-b9c.cpio.gz $O/initramfs.cpio.gz; cp $B9C/cmdline.txt $O/cmdline.txt
cat $O/Image.gz $O/aurora-b10b1.dtb > $O/Image.gz-dtb
python3 ../../b6p/mkbootimg.py $O/Image.gz-dtb $O/initramfs.cpio.gz $O/cmdline.txt $O/aurora-b10b1.img
SZ=$(python3 -c "import struct;print(struct.unpack_from('<Q',open('$KB/arch/arm64/boot/Image','rb').read(24),16)[0])")
printf 'kernel image_size 0x%x, RAM-boot end 0x%x (< 0x81e00000 DTB)\n' $SZ $((0x80000000 + SZ)); [ $((0x80000000 + SZ)) -lt $((0x81e00000)) ]
(cd $O && sha256sum Image.gz aurora-b10b1.dtb Image.gz-dtb config-b10b1 cmdline.txt initramfs.cpio.gz aurora-b10b1.img > SHA256SUMS; cat SHA256SUMS); ls -l $O/aurora-b10b1.img

View file

@ -1,7 +0,0 @@
fa573b4b4e1249efc9ee7db3067020086152aabfe84540c65c98242dd8077cd9 Image.gz
1400f98f8ec90ffc7c6efe04e83541d0a7b6a4e6895932e55267642c44c0d1ef aurora-b10b1.dtb
c932cdcd594034066ed286d64a065642f3e664da81ef0314f60f7afffc261832 Image.gz-dtb
5241bb0cef473c60c0ca56e10e07d2561e38c054b5e488660665a4d42f013b2a config-b10b1
0fef41b262917c8ae308fa222da0017e2b3cb3ec5da1ca8ba18d0318476761a3 cmdline.txt
ac518e27e2957ad5e4515969b9a3808024e11ef8d1a79433a899a67dbc644558 initramfs.cpio.gz
1029647d6a245481ff8488dabea2ab53cb15f800f5ddbb07a2737b83ae06d4ac aurora-b10b1.img

View file

@ -1 +0,0 @@
earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0

View file

@ -1,59 +0,0 @@
#!/bin/sh
# 480s side, B10B-2 boot K (RAM only). RESET-held power-on -> lk1st fastboot -> `fastboot boot` B10B-2 RAM image. Reads only over telnet.
# MODE=cold: normal power-on (no RESET, no fastboot) -> lk2nd extlinux from eMMC cache. Script only observes + reads over telnet;
# nothing is written to eMMC. Visual display checks need the operator. Adds display/fbcon/getty/console checks to the B8F snapshot.
K=$1; MODE=ram; [ -n "$K" ] || { echo "usage: $0 K"; exit 2; }
cd ~/doc/modem/jz08-aurora; O=logs/b10/b10b2/$MODE$K; mkdir -p $O; IMG=b10/b10b2/out/aurora-b10b2.img
A=$O/host-actions.txt; act() { echo "$(date -u +%H:%M:%S.%3N) $*" | tee -a $A; }
tn() { { sleep 1; sed "s/\$/\r/" "$1"; sleep $2; } | ncat 172.16.42.1 23 | tr -d "\000\r"; }
OLD=$(ps -eo pid,cmd | grep "[u]artlog.py /dev/ttyUSB0" | awk '{print $1}'); [ -n "$OLD" ] && kill $OLD; sleep 1
U=logs/uart/b10b2-$MODE$K-$(date +%Y%m%d-%H%M%S); setsid nohup python3 tools/uartlog.py /dev/ttyUSB0 $U > $U.stderr 2>&1 < /dev/null &
if [ $MODE = ram ]; then
echo "9f8a909604cca92b79a0678873dbd721e5266b6e7053af8e61cefc7ca684e2cc $IMG" | sha256sum -c || exit 1
act "B10B2 $MODE$K: waiting for fastboot <EMMC_SERIAL> (power off >= 90 s, then RESET held + battery -> USB)"
if fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; then act "already in fastboot - wait for power-off"; until ! fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do sleep 1; done; fi
i=0; until fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do i=$((i+1)); [ $i -ge 1800 ] && { act "ABORT: no fastboot"; exit 1; }; sleep 2; done
act "fastboot present"; { fastboot boot $IMG 2>&1; echo "rc=$?"; } | tee -a $A
else
act "B10B2 $MODE$K: waiting for the board to go away (power off >= 90 s), then normal power-on WITHOUT RESET"
until ! ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do sleep 1; done; act "board unreachable (powered off)"
until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL> && { act "ABORT: board is in fastboot - RESET was held?"; exit 1; }; sleep 1; done
fi
i=0; until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do i=$((i+1)); [ $i -ge 180 ] && { act "ABORT: NCM not up"; cp $U.log $O/uart.log; exit 1; }; sleep 1; done; act "NCM ping ok"
R=$(grep -a "rtc-pm8xxx.*setting system clock" $U.log | tail -1 | sed -n 's/.*(\([0-9]*\)).*/\1/p'); C=B; [ -n "$R" ] && [ "$R" -lt 40 ] && C=A; act "RTC at boot ${R:-?} s -> class $C"
printf 'cat /proc/device-tree/model; echo; uname -r; grep -E "START OK|FAIL in|rollback" /run/aurora-modem/lifecycle.log | tail -1\n' > $O/.w
i=0; until tn $O/.w 3 | grep -qE "^\[[0-9.]+\] .*(=== START OK|FAIL in|rollback)"; do i=$((i+1)); [ $i -ge 80 ] && { act "no START OK/FAIL after ~12 min"; break; }; sleep 6; done
tn $O/.w 3 | grep -aE "Aurora|aurora-b8|START OK|FAIL" | tee -a $A
printf 'grep -E "AP ENABLED|FAIL" /run/aurora-wifi/wifi.log | tail -1\n' > $O/.a
i=0; until tn $O/.a 3 | grep -qE "^\[[0-9.]+\] (=== AP ENABLED|FAIL)"; do i=$((i+1)); [ $i -ge 20 ] && { act "no AP ENABLED/FAIL after ~3 min"; break; }; sleep 6; done
act "wifi: $(tn $O/.a 3 | grep -E '^\[[0-9.]+\] (=== AP ENABLED|FAIL)' | tail -1)"
printf 'grep -E "SNTP (check|STEP|: )" /run/aurora-modem/lifecycle.log | tail -2\n' > $O/.s
i=0; until tn $O/.s 3 | grep -qE "^\[[0-9.]+\] SNTP"; do i=$((i+1)); [ $i -ge 15 ] && break; sleep 4; done; act "sntp: $(tn $O/.s 3 | grep -E '^\[[0-9.]+\] SNTP' | tail -2 | tr '\n' ' ')"
cat > $O/.c <<'C'
echo SNAP-BEGIN; cat /proc/uptime; date -u; cat /proc/device-tree/model; echo; uname -a; cat /proc/cmdline
echo ---time; cat /run/aurora-modem/time-set; grep -E "TIME|SNTP" /run/aurora-modem/lifecycle.log | tail -4
echo ---modem; /etc/init.d/aurora-modem status
echo ---wifi; /etc/init.d/aurora-wifi status; echo ---wifilog; cat /run/aurora-wifi/wifi.log; cat /run/aurora-wifi/service.log; echo ---hostapdlog; cat /run/aurora-wifi/hostapd.log
for r in /sys/class/remoteproc/*; do echo "RP $(cat $r/name)=$(cat $r/state)"; done; iw dev
echo ---dmesg-wifi; dmesg | grep -iE "wcn36xx|wcnss|a204000|cfg80211|aurora-wifi|crash|watchdog"
echo ---ping; ping -c4 -W3 -I wwan0 77.88.8.8 | tail -2
echo ---display; /etc/init.d/aurora-display status; cat /run/aurora-display/display.log; cat /run/aurora-display/service.log
echo ---consoles; cat /sys/class/tty/console/active; for v in /sys/class/vtconsole/vtcon*; do echo "$v $(cat $v/bind) $(cat $v/name)"; done; ls -l /proc/[0-9]*/fd/0 2>/dev/null | grep -E "ttyMSM0|tty1|console" | sed "s/.* \/proc/\/proc/"
echo ---getty; hostname; ps | grep -E "[g]etty|[c]ttyhack| sh$"
echo ---fb; ls -l /dev/dri/card0 /dev/fb0; for f in name bits_per_pixel virtual_size stride; do echo "fb0 $f=$(cat /sys/class/graphics/fb0/$f)"; done; cat /sys/class/drm/card0-SPI-1/enabled /sys/class/drm/card0-SPI-1/dpms
echo ---regs; for r in /sys/class/regulator/regulator.*; do n=$(cat $r/name); case $n in l6|l17) echo "$n $(cat $r/state) $(cat $r/microvolts) users=$(cat $r/num_users)";; esac; done
echo ---bl; for f in bl_power brightness actual_brightness; do echo "bl $f=$(cat /sys/class/backlight/backlight/$f)"; done
echo ---dmesg-display; dmesg | grep -iE "drm|panel|mipi|spi_qup|78b8000|fbcon|Console: |frame buffer|backlight|aurora-display|l17"
echo ---display-errors; dmesg | grep -iE "drm|panel|mipi|spi0|fbcon|backlight|aurora-display" | grep -ciE "err|fail|timeout|warn"
echo ---iio; for d in /sys/bus/iio/devices/iio:device*; do echo "$d name=$(cat $d/name)"; ls $d | tr '\n' ' '; echo; done
for f in /sys/bus/iio/devices/iio:device*/in_*; do case $f in *_raw|*_input|*_scale|*_offset) echo "$f=$(cat $f 2>&1)";; esac; done
echo ---psy; ls -l /sys/class/power_supply/; for p in /sys/class/power_supply/*; do echo "-- $p"; cat $p/uevent; ls $p; done
echo ---dmesg-bms; dmesg | grep -iE "bms|battery|power_supply|lbc|charger|extcon|ci_hdrc|4000|1000"
echo ---thermal; for t in /sys/class/thermal/thermal_zone*; do echo "$t $(cat $t/type) $(cat $t/temp)"; done
echo ---dmesg-adc; dmesg | grep -iE "vadc|iio|temp-alarm|qpnp|spmi-temp|pm8916-thermal|thermal"
echo ---emmc; awk "{print \"w=\"\$5\" s=\"\$7}" /sys/block/mmcblk0/stat
echo SNAP-END
C
tn $O/.c 25 > $O/snapshot.txt; act "snapshot: $(grep -c SNAP-END $O/snapshot.txt) end markers; $(grep -E '^RP a204' $O/snapshot.txt)"
printf 'dmesg > /tmp/dm.txt; nc -l -p 9881 < /tmp/dm.txt &\n' > $O/.d; tn $O/.d 3 >/dev/null; sleep 1; ncat --recv-only 172.16.42.1 9881 > $O/dmesg.full
cp $U.log $O/uart.log; act "B10B2 $MODE$K END - operator visual check next"

View file

@ -1,18 +0,0 @@
#!/bin/sh
# B10B-2 charger observation: N samples, P s apart. Reads only (IIO, power_supply sysfs, regmap debugfs, thermal).
# Prints ALERT if VADC VBAT > 4.22 V or PMIC die temp > 60 C (operator then removes USB; the script never writes).
N=${1:-120}; P=${2:-30}
grep -q " /sys/kernel/debug " /proc/mounts || mount -t debugfs debugfs /sys/kernel/debug
R=/sys/kernel/debug/regmap/0-00/registers
rd() { dd if=$R bs=9 skip=$(($1)) count=$2 2>/dev/null | cut -d' ' -f2 | tr '\n' ' '; }
D=/sys/bus/iio/devices/iio:device0; B=/sys/class/power_supply/pm8916-bms-vm; C=$(ls -d /sys/class/power_supply/*lbc* 2>/dev/null | head -1)
echo "MON-START charger=$C props: $(ls $C 2>/dev/null | tr '\n' ' ')"
i=1
while [ $i -le $N ]; do
r6=$(cat $D/in_voltage6_raw); r9=$(cat $D/in_voltage9_raw); r10=$(cat $D/in_voltage10_raw); pt=$(cat $D/in_temp8_input)
vb=$(( (625000 + (r6 - r9) * 625000 / (r10 - r9)) * 3 ))
a=""; [ $vb -gt 4220000 ] && a="$a ALERT-VBAT"; [ $pt -gt 60000 ] && a="$a ALERT-TEMP"
echo "M $i $(date -u +%T) up=$(cut -d' ' -f1 /proc/uptime) vbat=$vb r6=$r6 r9=$r9 r10=$r10 vph=$(cat $D/in_voltage7_input) usbin=$(cat $D/in_voltage0_input) bms_v=$(cat $B/voltage_now) bms_st=$(cat $B/status) fifo=$(rd 0x40c0 4) st=$(rd 0x1009 3) crt=$(rd 0x1010 1) brt=$(rd 0x1210 1) urt=$(rd 0x1310 1) usb=$(rd 0x1308 2) vdd=$(rd 0x1040 2) ibat=$(rd 0x1044 2) ctrl=$(rd 0x1049 1) tchg=$(rd 0x1060 2) bd=$(rd 0x1642 1) online=$(cat $C/online 2>&1) ccc=$(cat $C/constant_charge_current 2>&1) ccv=$(cat $C/constant_charge_voltage_max 2>&1) pmt=$pt cpu=$(cat /sys/class/thermal/thermal_zone4/temp)$a"
i=$((i + 1)); [ $i -le $N ] && sleep $P
done
echo MON-END

View file

@ -1,19 +0,0 @@
#!/bin/sh
# B10B-2 RAM test image (fastboot boot only - never flash; cache B9C / aboot untouched):
# kernel = out-b10b2 (b10b2 + CHARGER_PM8916_LBC; linux/aurora-b10b2.config).
# DTB = linux/dts/msm8916-jz08-aurora-b10b2.dtb (B10B-1 DTB + pm8916_charger okay 4.2 V/500 mA, usbin off, usb extcon -> charger)
# initramfs + cmdline = exact B9C (b9/b9c/out). out/ contains the B8F initramfs (Wi-Fi PSK): never publish.
set -e; cd "$(dirname "$0")"; O=out; KB=/home/q/aurora-kbuild/out-b10b2; L=../../linux; B9C=../../b9/b9c/out
mkdir -p $O
echo "7ca9cc794a3b85d3b7240f6311ad03bee9e1a4a59aae2ed9438318e853f7c3dc $L/dts/msm8916-jz08-aurora-b9b.dtb" | sha256sum -c
grep " initramfs-b9c.cpio.gz\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
grep " cmdline.txt\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
for s in IIO=y QCOM_SPMI_VADC=y BATTERY_PM8916_BMS_VM=y CHARGER_PM8916_LBC=y QCOM_SPMI_TEMP_ALARM=y 'LOCALVERSION="-aurora-b10b2"'; do grep -q "^CONFIG_$s\$" $KB/.config || { echo "STOP: CONFIG_$s"; exit 1; }; done
cp $KB/arch/arm64/boot/Image.gz $O/Image.gz; cp $KB/.config $O/config-b10b2; cp $L/dts/msm8916-jz08-aurora-b10b2.dtb $O/aurora-b10b2.dtb
cp $B9C/initramfs-b9c.cpio.gz $O/initramfs.cpio.gz; cp $B9C/cmdline.txt $O/cmdline.txt
cat $O/Image.gz $O/aurora-b10b2.dtb > $O/Image.gz-dtb
python3 ../../b6p/mkbootimg.py $O/Image.gz-dtb $O/initramfs.cpio.gz $O/cmdline.txt $O/aurora-b10b2.img
SZ=$(python3 -c "import struct;print(struct.unpack_from('<Q',open('$KB/arch/arm64/boot/Image','rb').read(24),16)[0])")
printf 'kernel image_size 0x%x, RAM-boot end 0x%x (< 0x81e00000 DTB)\n' $SZ $((0x80000000 + SZ)); [ $((0x80000000 + SZ)) -lt $((0x81e00000)) ]
(cd $O && sha256sum Image.gz aurora-b10b2.dtb Image.gz-dtb config-b10b2 cmdline.txt initramfs.cpio.gz aurora-b10b2.img > SHA256SUMS; cat SHA256SUMS); ls -l $O/aurora-b10b2.img

View file

@ -1,7 +0,0 @@
1b5ac87fd4490650a8510c94de7b882da90d3080a0dbcacb070888a12da433bc Image.gz
e7e3fe3e9dae0572a1e3fee709e19e3c6fd36c187a09055f77f438a95ac4b1a5 aurora-b10b2.dtb
ed290a259e576ce6e35387cb60cee248ac317dc7b84269ce4f8f6cda37d7a363 Image.gz-dtb
08358882f778741cd949f57049c019d2df0917f368fac3f3f1da3300407f54ba config-b10b2
0fef41b262917c8ae308fa222da0017e2b3cb3ec5da1ca8ba18d0318476761a3 cmdline.txt
ac518e27e2957ad5e4515969b9a3808024e11ef8d1a79433a899a67dbc644558 initramfs.cpio.gz
9f8a909604cca92b79a0678873dbd721e5266b6e7053af8e61cefc7ca684e2cc aurora-b10b2.img

View file

@ -1 +0,0 @@
earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0

View file

@ -1,60 +0,0 @@
#!/bin/sh
# 480s side, B10B-3 boot K (RAM only). RESET-held power-on -> lk1st fastboot -> `fastboot boot` B10B-3 RAM image. Reads only over telnet.
# MODE=cold: normal power-on (no RESET, no fastboot) -> lk2nd extlinux from eMMC cache. Script only observes + reads over telnet;
# nothing is written to eMMC. Visual display checks need the operator. Adds display/fbcon/getty/console checks to the B8F snapshot.
K=$1; MODE=ram; [ -n "$K" ] || { echo "usage: $0 K"; exit 2; }
cd ~/doc/modem/jz08-aurora; O=logs/b10/b10b3/$MODE$K; mkdir -p $O; IMG=b10/b10b3/out/aurora-b10b3.img
A=$O/host-actions.txt; act() { echo "$(date -u +%H:%M:%S.%3N) $*" | tee -a $A; }
tn() { { sleep 1; sed "s/\$/\r/" "$1"; sleep $2; } | ncat 172.16.42.1 23 | tr -d "\000\r"; }
OLD=$(ps -eo pid,cmd | grep "[u]artlog.py /dev/ttyUSB0" | awk '{print $1}'); [ -n "$OLD" ] && kill $OLD; sleep 1
U=logs/uart/b10b3-$MODE$K-$(date +%Y%m%d-%H%M%S); setsid nohup python3 tools/uartlog.py /dev/ttyUSB0 $U > $U.stderr 2>&1 < /dev/null &
if [ $MODE = ram ]; then
echo "c3c885d5204ad5287ad474cc99068ca6995dc97281f2a014f383c20235bc827c $IMG" | sha256sum -c || exit 1
act "B10B3 $MODE$K: waiting for fastboot <EMMC_SERIAL> (power off >= 90 s, then RESET held + battery -> USB)"
if fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; then act "already in fastboot - wait for power-off"; until ! fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do sleep 1; done; fi
i=0; until fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do i=$((i+1)); [ $i -ge 1800 ] && { act "ABORT: no fastboot"; exit 1; }; sleep 2; done
act "fastboot present"; { fastboot boot $IMG 2>&1; echo "rc=$?"; } | tee -a $A
else
act "B10B3 $MODE$K: waiting for the board to go away (power off >= 90 s), then normal power-on WITHOUT RESET"
until ! ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do sleep 1; done; act "board unreachable (powered off)"
until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL> && { act "ABORT: board is in fastboot - RESET was held?"; exit 1; }; sleep 1; done
fi
i=0; until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do i=$((i+1)); [ $i -ge 180 ] && { act "ABORT: NCM not up"; cp $U.log $O/uart.log; exit 1; }; sleep 1; done; act "NCM ping ok"
R=$(grep -a "rtc-pm8xxx.*setting system clock" $U.log | tail -1 | sed -n 's/.*(\([0-9]*\)).*/\1/p'); C=B; [ -n "$R" ] && [ "$R" -lt 40 ] && C=A; act "RTC at boot ${R:-?} s -> class $C"
printf 'cat /proc/device-tree/model; echo; uname -r; grep -E "START OK|FAIL in|rollback" /run/aurora-modem/lifecycle.log | tail -1\n' > $O/.w
i=0; until tn $O/.w 3 | grep -qE "^\[[0-9.]+\] .*(=== START OK|FAIL in|rollback)"; do i=$((i+1)); [ $i -ge 80 ] && { act "no START OK/FAIL after ~12 min"; break; }; sleep 6; done
tn $O/.w 3 | grep -aE "Aurora|aurora-b8|START OK|FAIL" | tee -a $A
printf 'grep -E "AP ENABLED|FAIL" /run/aurora-wifi/wifi.log | tail -1\n' > $O/.a
i=0; until tn $O/.a 3 | grep -qE "^\[[0-9.]+\] (=== AP ENABLED|FAIL)"; do i=$((i+1)); [ $i -ge 20 ] && { act "no AP ENABLED/FAIL after ~3 min"; break; }; sleep 6; done
act "wifi: $(tn $O/.a 3 | grep -E '^\[[0-9.]+\] (=== AP ENABLED|FAIL)' | tail -1)"
printf 'grep -E "SNTP (check|STEP|: )" /run/aurora-modem/lifecycle.log | tail -2\n' > $O/.s
i=0; until tn $O/.s 3 | grep -qE "^\[[0-9.]+\] SNTP"; do i=$((i+1)); [ $i -ge 15 ] && break; sleep 4; done; act "sntp: $(tn $O/.s 3 | grep -E '^\[[0-9.]+\] SNTP' | tail -2 | tr '\n' ' ')"
cat > $O/.c <<'C'
echo SNAP-BEGIN; cat /proc/uptime; date -u; cat /proc/device-tree/model; echo; uname -a; cat /proc/cmdline
echo ---time; cat /run/aurora-modem/time-set; grep -E "TIME|SNTP" /run/aurora-modem/lifecycle.log | tail -4
echo ---modem; /etc/init.d/aurora-modem status
echo ---wifi; /etc/init.d/aurora-wifi status; echo ---wifilog; cat /run/aurora-wifi/wifi.log; cat /run/aurora-wifi/service.log; echo ---hostapdlog; cat /run/aurora-wifi/hostapd.log
for r in /sys/class/remoteproc/*; do echo "RP $(cat $r/name)=$(cat $r/state)"; done; iw dev
echo ---dmesg-wifi; dmesg | grep -iE "wcn36xx|wcnss|a204000|cfg80211|aurora-wifi|crash|watchdog"
echo ---ping; ping -c4 -W3 -I wwan0 77.88.8.8 | tail -2
echo ---display; /etc/init.d/aurora-display status; cat /run/aurora-display/display.log; cat /run/aurora-display/service.log
echo ---consoles; cat /sys/class/tty/console/active; for v in /sys/class/vtconsole/vtcon*; do echo "$v $(cat $v/bind) $(cat $v/name)"; done; ls -l /proc/[0-9]*/fd/0 2>/dev/null | grep -E "ttyMSM0|tty1|console" | sed "s/.* \/proc/\/proc/"
echo ---getty; hostname; ps | grep -E "[g]etty|[c]ttyhack| sh$"
echo ---fb; ls -l /dev/dri/card0 /dev/fb0; for f in name bits_per_pixel virtual_size stride; do echo "fb0 $f=$(cat /sys/class/graphics/fb0/$f)"; done; cat /sys/class/drm/card0-SPI-1/enabled /sys/class/drm/card0-SPI-1/dpms
echo ---regs; for r in /sys/class/regulator/regulator.*; do n=$(cat $r/name); case $n in l6|l17) echo "$n $(cat $r/state) $(cat $r/microvolts) users=$(cat $r/num_users)";; esac; done
echo ---bl; for f in bl_power brightness actual_brightness; do echo "bl $f=$(cat /sys/class/backlight/backlight/$f)"; done
echo ---dmesg-display; dmesg | grep -iE "drm|panel|mipi|spi_qup|78b8000|fbcon|Console: |frame buffer|backlight|aurora-display|l17"
echo ---display-errors; dmesg | grep -iE "drm|panel|mipi|spi0|fbcon|backlight|aurora-display" | grep -ciE "err|fail|timeout|warn"
echo ---iio; for d in /sys/bus/iio/devices/iio:device*; do echo "$d name=$(cat $d/name)"; ls $d | tr '\n' ' '; echo; done
for f in /sys/bus/iio/devices/iio:device*/in_*; do case $f in *_raw|*_input|*_scale|*_offset) echo "$f=$(cat $f 2>&1)";; esac; done
echo ---psy; ls -l /sys/class/power_supply/; for p in /sys/class/power_supply/*; do echo "-- $p"; cat $p/uevent; ls $p; done
echo ---dmesg-bms; dmesg | grep -iE "bms|battery|power_supply|lbc|charger|extcon|ci_hdrc|4000|1000"
echo ---lbc-state; grep -q " /sys/kernel/debug " /proc/mounts || mount -t debugfs debugfs /sys/kernel/debug; cat /sys/kernel/debug/pm8916_lbc/state; dmesg | grep -E "safety timer|supervisor|pm8916-lbc|lbc"
echo ---thermal; for t in /sys/class/thermal/thermal_zone*; do echo "$t $(cat $t/type) $(cat $t/temp)"; done
echo ---dmesg-adc; dmesg | grep -iE "vadc|iio|temp-alarm|qpnp|spmi-temp|pm8916-thermal|thermal"
echo ---emmc; awk "{print \"w=\"\$5\" s=\"\$7}" /sys/block/mmcblk0/stat
echo SNAP-END
C
tn $O/.c 25 > $O/snapshot.txt; act "snapshot: $(grep -c SNAP-END $O/snapshot.txt) end markers; $(grep -E '^RP a204' $O/snapshot.txt)"
printf 'dmesg > /tmp/dm.txt; nc -l -p 9881 < /tmp/dm.txt &\n' > $O/.d; tn $O/.d 3 >/dev/null; sleep 1; ncat --recv-only 172.16.42.1 9881 > $O/dmesg.full
cp $U.log $O/uart.log; act "B10B3 $MODE$K END - operator visual check next"

View file

@ -1,3 +0,0 @@
#!/bin/sh
# 480s side: run one shell command line on the board over telnet, print output. usage: b10b3-cmd.sh WAIT 'cmd'
W=$1; shift; { sleep 1; printf '%s\r\n' "$*"; sleep $W; } | ncat -w $((W + 6)) 172.16.42.1 23 | tr -d '\000\r' | grep -vE '^(~ #|BusyBox|Enter .help)' | sed 1d

View file

@ -1,483 +0,0 @@
--- a/drivers/iio/adc/qcom-spmi-vadc.c
+++ b/drivers/iio/adc/qcom-spmi-vadc.c
@@ -563,7 +563,7 @@
VADC_CHAN_NO_SCALE(SPARE1_03, 1)
VADC_CHAN_NO_SCALE(USB_ID_MV, 1)
VADC_CHAN_VOLT(VCOIN, 1, SCALE_DEFAULT)
- VADC_CHAN_NO_SCALE(VBAT_SNS, 1)
+ VADC_CHAN_VOLT(VBAT_SNS, 1, SCALE_DEFAULT)
VADC_CHAN_VOLT(VSYS, 1, SCALE_DEFAULT)
VADC_CHAN_TEMP(DIE_TEMP, 0, SCALE_PMIC_THERM)
VADC_CHAN_VOLT(REF_625MV, 0, SCALE_DEFAULT)
--- a/drivers/power/supply/pm8916_lbc.c
+++ b/drivers/power/supply/pm8916_lbc.c
@@ -13,6 +13,13 @@
#include <linux/delay.h>
#include <linux/interrupt.h>
#include <linux/extcon-provider.h>
+#include <linux/debugfs.h>
+#include <linux/devm-helpers.h>
+#include <linux/iio/consumer.h>
+#include <linux/mutex.h>
+#include <linux/of.h>
+#include <linux/seq_file.h>
+#include <linux/workqueue.h>
/* Two bytes: type + subtype */
#define PM8916_PERPH_TYPE 0x04
@@ -42,6 +49,25 @@
#define PM8916_LBC_CHGR_CHG_CTRL 0x49
#define PM8916_LBC_CHGR_CHG_EN BIT(7)
#define PM8916_LBC_CHGR_PSTG_EN BIT(5)
+#define PM8916_LBC_CHGR_FORCE_BATT_ON BIT(0)
+#define PM8916_LBC_CHGR_EN_MASK (PM8916_LBC_CHGR_CHG_EN | PM8916_LBC_CHGR_FORCE_BATT_ON)
+
+#define PM8916_LBC_CHGR_CHG_FAILED 0x4a
+#define PM8916_LBC_CHGR_CHG_FAILED_BIT BIT(7)
+
+/* USB_CHGPTH 0x08: 0x02 while the charge path is on, 0x01 after end of charge (observed, not documented) */
+#define PM8916_LBC_USB_PATH_STS 0x08
+#define PM8916_LBC_USB_PATH_ON BIT(1)
+
+/* Aurora B10B-3 recharge supervisor */
+#define PM8916_LBC_SUPV_PERIOD_MS 30000
+#define PM8916_LBC_SUPV_DONE_POLLS 2
+#define PM8916_LBC_SUPV_LOW_POLLS 3
+#define PM8916_LBC_SUPV_OVP_UV 4250000
+#define PM8916_LBC_TIMEOUT_DEFAULT_MIN 512
+#define PM8916_LBC_TIMEOUT_STEP_MIN 4
+#define PM8916_LBC_TIMEOUT_MAX_MIN 512
+#define PM8916_LBC_SUPV_LOG 16
#define PM8916_LBC_CHGR_MIN_CURRENT 90000
#define PM8916_LBC_CHGR_MAX_CURRENT 1440000
@@ -65,6 +91,55 @@
unsigned int charge_voltage_safe;
unsigned int charge_current_max;
unsigned int charge_current_safe;
+
+ /* recharge supervisor */
+ struct iio_channel *vbat_chan;
+ struct delayed_work supv_work;
+ struct mutex supv_lock;
+ int state;
+ int fault_reason;
+ unsigned int recharge_uv; /* production threshold from monitored-battery */
+ unsigned int timeout_min;
+ int vbat_uv;
+ int done_polls;
+ int low_polls;
+ unsigned int n_terminated;
+ unsigned int n_recharge;
+ struct {
+ time64_t t;
+ int from, to, vbat;
+ const char *why;
+ } log[PM8916_LBC_SUPV_LOG];
+ unsigned int log_n;
+ struct dentry *debugfs;
+};
+
+enum {
+ LBC_ST_INIT = 0,
+ LBC_ST_NO_USB,
+ LBC_ST_CHARGING,
+ LBC_ST_TERMINATED,
+ LBC_ST_FAULT,
+};
+
+static const char * const lbc_state_name[] = {
+ [LBC_ST_INIT] = "INIT",
+ [LBC_ST_NO_USB] = "NO_USB",
+ [LBC_ST_CHARGING] = "CHARGING",
+ [LBC_ST_TERMINATED] = "TERMINATED",
+ [LBC_ST_FAULT] = "FAULT",
+};
+
+enum {
+ LBC_FAULT_NONE = 0,
+ LBC_FAULT_TIMER,
+ LBC_FAULT_OVP,
+};
+
+static const char * const lbc_fault_name[] = {
+ [LBC_FAULT_NONE] = "none",
+ [LBC_FAULT_TIMER] = "safety-timer (CHG_FAILED)",
+ [LBC_FAULT_OVP] = "vbat-overvoltage",
};
static const unsigned int pm8916_lbc_charger_cable[] = {
@@ -79,7 +154,7 @@
LBC_MISC,
};
-static int pm8916_lbc_charger_configure(struct pm8916_lbc_charger *chg)
+static int pm8916_lbc_charger_configure(struct pm8916_lbc_charger *chg, bool set_ctrl)
{
int ret = 0;
unsigned int tmp;
@@ -107,10 +182,16 @@
if (ret)
goto error;
- ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_CHG_CTRL,
- PM8916_LBC_CHGR_CHG_EN | PM8916_LBC_CHGR_PSTG_EN);
- if (ret)
- goto error;
+ /*
+ * CHG_CTRL is written only at probe. Afterwards the recharge supervisor owns CHG_EN, so a
+ * constant_charge_current update must not re-enable charging in TERMINATED/FAULT.
+ */
+ if (set_ctrl) {
+ ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_CHG_CTRL,
+ PM8916_LBC_CHGR_CHG_EN | PM8916_LBC_CHGR_PSTG_EN);
+ if (ret)
+ goto error;
+ }
return ret;
@@ -126,6 +207,23 @@
struct pm8916_lbc_charger *chg = power_supply_get_drvdata(psy);
switch (psp) {
+ case POWER_SUPPLY_PROP_STATUS:
+ switch (chg->state) {
+ case LBC_ST_CHARGING:
+ val->intval = POWER_SUPPLY_STATUS_CHARGING;
+ break;
+ case LBC_ST_TERMINATED:
+ val->intval = POWER_SUPPLY_STATUS_FULL;
+ break;
+ case LBC_ST_NO_USB:
+ val->intval = POWER_SUPPLY_STATUS_DISCHARGING;
+ break;
+ default:
+ val->intval = POWER_SUPPLY_STATUS_NOT_CHARGING;
+ break;
+ }
+ return 0;
+
case POWER_SUPPLY_PROP_ONLINE:
val->intval = chg->online;
return 0;
@@ -152,7 +250,7 @@
switch (prop) {
case POWER_SUPPLY_PROP_CONSTANT_CHARGE_CURRENT:
chg->charge_current_max = val->intval;
- return pm8916_lbc_charger_configure(chg);
+ return pm8916_lbc_charger_configure(chg, false);
default:
return -EINVAL;
}
@@ -170,11 +268,208 @@
}
static enum power_supply_property pm8916_lbc_charger_properties[] = {
+ POWER_SUPPLY_PROP_STATUS,
POWER_SUPPLY_PROP_ONLINE,
POWER_SUPPLY_PROP_CONSTANT_CHARGE_VOLTAGE_MAX,
POWER_SUPPLY_PROP_CONSTANT_CHARGE_CURRENT,
};
+
+/*
+ * Aurora B10B-3 recharge supervisor.
+ * The LBC ends a charge cycle in hardware (end-of-charge latch: CHG_STATUS 00, USB path 01, USB input ~0) and then
+ * stays off until software gives CHG_EN a 0 -> 1 edge (downstream qpnp-linear-charger did this from BMS SOC /
+ * VBAT_DET IRQ). Verified on Aurora (B10B-3 ram1): CHG_CTRL 0x21 -> 0xa0 releases the latch.
+ * Also verified: writing CHG_EN = 0 does NOT stop the charger (USB input stays ~0.36 A), so the supervisor never
+ * uses CHG_CTRL to "turn charging off"; TERMINATED is only the hardware latch, observed after CHARGING.
+ * The supervisor polls the VADC VBAT every 30 s and restarts charging when VBAT stays below the monitored-battery
+ * re-charge-voltage-microvolt for 3 consecutive polls.
+ */
+static void lbc_supv_log(struct pm8916_lbc_charger *chg, int to, const char *why)
+{
+ unsigned int i = chg->log_n++ % PM8916_LBC_SUPV_LOG;
+
+ chg->log[i].t = ktime_get_seconds();
+ chg->log[i].from = chg->state;
+ chg->log[i].to = to;
+ chg->log[i].vbat = chg->vbat_uv;
+ chg->log[i].why = why;
+ dev_info(chg->dev, "supervisor %s -> %s (%s), vbat %d uV\n", lbc_state_name[chg->state],
+ lbc_state_name[to], why, chg->vbat_uv);
+ chg->state = to;
+}
+
+static int lbc_charge_enable(struct pm8916_lbc_charger *chg, bool en)
+{
+ /* stock-style: enabled = CHG_EN, disabled = FORCE_BATT_ON */
+ return regmap_update_bits(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_CHG_CTRL,
+ PM8916_LBC_CHGR_EN_MASK,
+ en ? PM8916_LBC_CHGR_CHG_EN : PM8916_LBC_CHGR_FORCE_BATT_ON);
+}
+
+/* the verified restart: CHG_CTRL 0x21 (CHG_EN 0) -> 20 ms -> 0xa0 (CHG_EN 1); on (re)insert also clear CHG_FAILED */
+static int lbc_charge_restart(struct pm8916_lbc_charger *chg, bool clear_failed)
+{
+ int ret;
+
+ if (clear_failed) {
+ ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_CHG_FAILED,
+ PM8916_LBC_CHGR_CHG_FAILED_BIT);
+ if (ret)
+ return ret;
+ }
+ ret = lbc_charge_enable(chg, false);
+ if (ret)
+ return ret;
+ msleep(20);
+ return lbc_charge_enable(chg, true);
+}
+
+static void lbc_supv_work(struct work_struct *work)
+{
+ struct pm8916_lbc_charger *chg = container_of(work, struct pm8916_lbc_charger, supv_work.work);
+ unsigned int usb_rt, sts, path, failed;
+ int ret, uv;
+
+ mutex_lock(&chg->supv_lock);
+
+ ret = regmap_read(chg->regmap, chg->reg[LBC_USB] + PM8916_INT_RT_STS, &usb_rt);
+ ret = ret ?: regmap_read(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_CHG_STATUS, &sts);
+ ret = ret ?: regmap_read(chg->regmap, chg->reg[LBC_USB] + PM8916_LBC_USB_PATH_STS, &path);
+ ret = ret ?: regmap_read(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_CHG_FAILED, &failed);
+ if (ret) {
+ dev_err(chg->dev, "supervisor: register read failed: %d\n", ret);
+ goto out;
+ }
+ if (!iio_read_channel_processed(chg->vbat_chan, &uv))
+ chg->vbat_uv = uv;
+ else
+ chg->vbat_uv = -1;
+
+ if (!(usb_rt & PM8916_LBC_USB_USBIN_VALID)) {
+ /* CHG_CTRL untouched; the next insert restarts with the verified edge */
+ if (chg->state != LBC_ST_NO_USB) {
+ chg->fault_reason = LBC_FAULT_NONE;
+ lbc_supv_log(chg, LBC_ST_NO_USB, "usb removed");
+ }
+ goto out;
+ }
+
+ switch (chg->state) {
+ case LBC_ST_INIT:
+ case LBC_ST_NO_USB:
+ /* probe or USB insert: always start a cycle, like stock's usbin path */
+ chg->done_polls = 0;
+ chg->low_polls = 0;
+ chg->fault_reason = LBC_FAULT_NONE;
+ if (!lbc_charge_restart(chg, true))
+ lbc_supv_log(chg, LBC_ST_CHARGING,
+ chg->state == LBC_ST_INIT ? "probe, usb present" : "usb inserted");
+ break;
+
+ case LBC_ST_CHARGING:
+ /*
+ * Safety timer expiry: the hardware stops and sets CHG_FAILED. Latch FAULT so the supervisor never
+ * restarts; no register write (CHG_EN = 0 is not a verified way to stop the charger).
+ */
+ if (failed & PM8916_LBC_CHGR_CHG_FAILED_BIT) {
+ chg->fault_reason = LBC_FAULT_TIMER;
+ lbc_supv_log(chg, LBC_ST_FAULT, "CHG_FAILED (safety timer)");
+ break;
+ }
+ if (chg->vbat_uv > PM8916_LBC_SUPV_OVP_UV) {
+ /* defence only: VDD_MAX regulates in hardware; latch FAULT = no further restarts */
+ chg->fault_reason = LBC_FAULT_OVP;
+ lbc_supv_log(chg, LBC_ST_FAULT, "vbat > 4.25 V");
+ break;
+ }
+ /* TERMINATED = hardware end-of-charge latch only; CHG_CTRL is not changed */
+ if (sts == 0 && !(path & PM8916_LBC_USB_PATH_ON))
+ chg->done_polls++;
+ else
+ chg->done_polls = 0;
+ if (chg->done_polls >= PM8916_LBC_SUPV_DONE_POLLS) {
+ chg->n_terminated++;
+ chg->low_polls = 0;
+ lbc_supv_log(chg, LBC_ST_TERMINATED, "hardware end of charge");
+ }
+ break;
+
+ case LBC_ST_TERMINATED:
+ if (!chg->recharge_uv || chg->vbat_uv < 0)
+ break;
+ if ((unsigned int)chg->vbat_uv < chg->recharge_uv)
+ chg->low_polls++;
+ else
+ chg->low_polls = 0;
+ if (chg->low_polls >= PM8916_LBC_SUPV_LOW_POLLS) {
+ chg->done_polls = 0;
+ chg->low_polls = 0;
+ if (!lbc_charge_restart(chg, false)) {
+ chg->n_recharge++;
+ lbc_supv_log(chg, LBC_ST_CHARGING, "recharge");
+ }
+ }
+ break;
+
+ case LBC_ST_FAULT:
+ /* latched: left only by USB removal/insert or reboot */
+ break;
+ }
+
+out:
+ mutex_unlock(&chg->supv_lock);
+ power_supply_changed(chg->charger);
+ queue_delayed_work(system_freezable_wq, &chg->supv_work,
+ msecs_to_jiffies(PM8916_LBC_SUPV_PERIOD_MS));
+}
+
+static int lbc_state_show(struct seq_file *s, void *unused)
+{
+ struct pm8916_lbc_charger *chg = s->private;
+ static const struct { const char *n; int blk; unsigned int off; } regs[] = {
+ { "CHG_STATUS", LBC_CHGR, PM8916_LBC_CHGR_CHG_STATUS },
+ { "CHGR_RT", LBC_CHGR, PM8916_INT_RT_STS },
+ { "CHG_CTRL", LBC_CHGR, PM8916_LBC_CHGR_CHG_CTRL },
+ { "CHG_FAILED", LBC_CHGR, PM8916_LBC_CHGR_CHG_FAILED },
+ { "VDD_MAX", LBC_CHGR, PM8916_LBC_CHGR_VDD_MAX },
+ { "IBAT_MAX", LBC_CHGR, PM8916_LBC_CHGR_IBAT_MAX },
+ { "TCHG_MAX_EN", LBC_CHGR, PM8916_LBC_CHGR_TCHG_MAX_EN },
+ { "TCHG_MAX", LBC_CHGR, PM8916_LBC_CHGR_TCHG_MAX },
+ { "USB_PATH", LBC_USB, PM8916_LBC_USB_PATH_STS },
+ { "USB_RT", LBC_USB, PM8916_INT_RT_STS },
+ { "BAT_RT", LBC_BAT_IF, PM8916_INT_RT_STS },
+ };
+ unsigned int i, v;
+
+ mutex_lock(&chg->supv_lock);
+ seq_printf(s, "state %s fault %s vbat_uv %d\n", lbc_state_name[chg->state],
+ lbc_fault_name[chg->fault_reason], chg->vbat_uv);
+ seq_printf(s, "recharge_uv %u done_polls %d low_polls %d timeout_min %u\n",
+ chg->recharge_uv, chg->done_polls, chg->low_polls, chg->timeout_min);
+ seq_printf(s, "n_terminated %u n_recharge %u\n", chg->n_terminated, chg->n_recharge);
+ for (i = 0; i < ARRAY_SIZE(regs); i++) {
+ if (regmap_read(chg->regmap, chg->reg[regs[i].blk] + regs[i].off, &v))
+ v = 0xffff;
+ seq_printf(s, "%s %02x\n", regs[i].n, v);
+ }
+ for (i = chg->log_n > PM8916_LBC_SUPV_LOG ? chg->log_n - PM8916_LBC_SUPV_LOG : 0; i < chg->log_n; i++) {
+ unsigned int j = i % PM8916_LBC_SUPV_LOG;
+
+ seq_printf(s, "log %u t=%lld %s->%s vbat=%d %s\n", i, chg->log[j].t,
+ lbc_state_name[chg->log[j].from], lbc_state_name[chg->log[j].to],
+ chg->log[j].vbat, chg->log[j].why);
+ }
+ mutex_unlock(&chg->supv_lock);
+ return 0;
+}
+DEFINE_SHOW_ATTRIBUTE(lbc_state);
+
+static void lbc_debugfs_remove(void *data)
+{
+ debugfs_remove_recursive(data);
+}
+
static irqreturn_t pm8916_lbc_charger_state_changed_irq(int irq, void *data)
{
struct pm8916_lbc_charger *chg = data;
@@ -190,6 +485,9 @@
power_supply_changed(chg->charger);
+ if (chg->vbat_chan)
+ mod_delayed_work(system_freezable_wq, &chg->supv_work, 0);
+
return IRQ_HANDLED;
}
@@ -230,10 +528,35 @@
if (ret)
return ret;
- /* Disable charger timeout. */
+ /*
+ * Keep the charger safety timer running (upstream disabled it). Same sequence as the
+ * downstream qpnp-linear-charger: timer off, TCHG_MAX = minutes / 4 - 1 (4..512 min), timer on.
+ */
+ chg->timeout_min = PM8916_LBC_TIMEOUT_DEFAULT_MIN;
+ device_property_read_u32(dev, "qcom,charge-timeout-minutes", &chg->timeout_min);
+ chg->timeout_min = clamp_t(u32, chg->timeout_min, PM8916_LBC_TIMEOUT_STEP_MIN,
+ PM8916_LBC_TIMEOUT_MAX_MIN);
+ chg->timeout_min -= chg->timeout_min % PM8916_LBC_TIMEOUT_STEP_MIN;
+
ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_TCHG_MAX_EN, 0x00);
if (ret)
return ret;
+ tmp = chg->timeout_min / PM8916_LBC_TIMEOUT_STEP_MIN - 1;
+ ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_TCHG_MAX, tmp);
+ if (ret)
+ return ret;
+ ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_TCHG_MAX_EN,
+ PM8916_LBC_CHGR_TCHG_MAX_ENABLED);
+ if (ret)
+ return ret;
+
+ ret = regmap_read(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_TCHG_MAX, &tmp);
+ if (ret)
+ return ret;
+ if (tmp != chg->timeout_min / PM8916_LBC_TIMEOUT_STEP_MIN - 1)
+ return dev_err_probe(dev, -EIO, "TCHG_MAX readback 0x%x != 0x%x\n", tmp,
+ chg->timeout_min / PM8916_LBC_TIMEOUT_STEP_MIN - 1);
+ dev_info(dev, "safety timer %u min (TCHG_MAX 0x%02x), enabled\n", chg->timeout_min, tmp);
return ret;
}
@@ -309,7 +632,7 @@
ret = pm8916_lbc_charger_probe_dt(chg);
if (ret)
- dev_err_probe(dev, ret, "Error while parsing device tree\n");
+ return dev_err_probe(dev, ret, "Error while parsing device tree\n");
psy_cfg.drv_data = chg;
psy_cfg.fwnode = dev_fwnode(dev);
@@ -322,6 +645,22 @@
if (ret)
return dev_err_probe(dev, ret, "Unable to get battery info\n");
+ chg->vbat_chan = devm_iio_channel_get(dev, "vbat");
+ if (IS_ERR(chg->vbat_chan))
+ return dev_err_probe(dev, PTR_ERR(chg->vbat_chan), "no VADC vbat channel\n");
+
+ {
+ struct device_node *bat = of_parse_phandle(dev->of_node, "monitored-battery", 0);
+
+ if (!bat || of_property_read_u32(bat, "re-charge-voltage-microvolt", &chg->recharge_uv))
+ dev_warn(dev, "no re-charge-voltage-microvolt: automatic recharge disabled\n");
+ of_node_put(bat);
+ }
+ mutex_init(&chg->supv_lock);
+ ret = devm_delayed_work_autocancel(dev, &chg->supv_work, lbc_supv_work);
+ if (ret)
+ return ret;
+
irq = platform_get_irq_byname(pdev, "usb_vbus");
if (irq < 0)
return irq;
@@ -347,10 +686,21 @@
extcon_set_state_sync(chg->edev, EXTCON_USB, chg->online);
chg->charge_voltage_max = chg->info->voltage_max_design_uv;
- ret = pm8916_lbc_charger_configure(chg);
+ ret = pm8916_lbc_charger_configure(chg, true);
if (ret)
return ret;
+ chg->debugfs = debugfs_create_dir("pm8916_lbc", NULL);
+ debugfs_create_file("state", 0444, chg->debugfs, chg, &lbc_state_fops);
+ ret = devm_add_action_or_reset(dev, lbc_debugfs_remove, chg->debugfs);
+ if (ret)
+ return ret;
+
+ dev_info(dev, "recharge supervisor: threshold %u uV, %d x %d ms below, ovp %d uV\n",
+ chg->recharge_uv, PM8916_LBC_SUPV_LOW_POLLS, PM8916_LBC_SUPV_PERIOD_MS,
+ PM8916_LBC_SUPV_OVP_UV);
+ queue_delayed_work(system_freezable_wq, &chg->supv_work, 0);
+
return 0;
comm_error:

View file

@ -1,596 +0,0 @@
--- a/drivers/iio/adc/qcom-spmi-vadc.c
+++ b/drivers/iio/adc/qcom-spmi-vadc.c
@@ -563,7 +563,7 @@
VADC_CHAN_NO_SCALE(SPARE1_03, 1)
VADC_CHAN_NO_SCALE(USB_ID_MV, 1)
VADC_CHAN_VOLT(VCOIN, 1, SCALE_DEFAULT)
- VADC_CHAN_NO_SCALE(VBAT_SNS, 1)
+ VADC_CHAN_VOLT(VBAT_SNS, 1, SCALE_DEFAULT)
VADC_CHAN_VOLT(VSYS, 1, SCALE_DEFAULT)
VADC_CHAN_TEMP(DIE_TEMP, 0, SCALE_PMIC_THERM)
VADC_CHAN_VOLT(REF_625MV, 0, SCALE_DEFAULT)
--- a/drivers/power/supply/pm8916_lbc.c
+++ b/drivers/power/supply/pm8916_lbc.c
@@ -13,6 +13,13 @@
#include <linux/delay.h>
#include <linux/interrupt.h>
#include <linux/extcon-provider.h>
+#include <linux/debugfs.h>
+#include <linux/devm-helpers.h>
+#include <linux/iio/consumer.h>
+#include <linux/mutex.h>
+#include <linux/of.h>
+#include <linux/seq_file.h>
+#include <linux/workqueue.h>
/* Two bytes: type + subtype */
#define PM8916_PERPH_TYPE 0x04
@@ -42,6 +49,30 @@
#define PM8916_LBC_CHGR_CHG_CTRL 0x49
#define PM8916_LBC_CHGR_CHG_EN BIT(7)
#define PM8916_LBC_CHGR_PSTG_EN BIT(5)
+#define PM8916_LBC_CHGR_FORCE_BATT_ON BIT(0)
+#define PM8916_LBC_CHGR_EN_MASK (PM8916_LBC_CHGR_CHG_EN | PM8916_LBC_CHGR_FORCE_BATT_ON)
+
+#define PM8916_LBC_CHGR_CHG_FAILED 0x4a
+#define PM8916_LBC_CHGR_CHG_FAILED_BIT BIT(7)
+
+/* USB_CHGPTH 0x08: 0x02 while the charge path is on, 0x01 after end of charge (observed, not documented) */
+#define PM8916_LBC_USB_PATH_STS 0x08
+#define PM8916_LBC_USB_PATH_ON BIT(1)
+
+/* Aurora B10B-3 recharge supervisor */
+#define PM8916_LBC_SUPV_PERIOD_MS 30000
+#define PM8916_LBC_SUPV_LATCH_POLLS 2
+#define PM8916_LBC_SUPV_NOCV_POLLS 2
+#define PM8916_LBC_SUPV_OVP_UV 4250000
+#define PM8916_LBC_CV_HOLD_DEFAULT_MIN 60
+#define PM8916_LBC_CHGR_CV_LOOP BIT(1)
+
+#define PM8916_LBC_MISC_BOOT_DONE 0x42
+#define PM8916_LBC_MISC_BOOT_DONE_BIT BIT(7)
+#define PM8916_LBC_TIMEOUT_DEFAULT_MIN 512
+#define PM8916_LBC_TIMEOUT_STEP_MIN 4
+#define PM8916_LBC_TIMEOUT_MAX_MIN 512
+#define PM8916_LBC_SUPV_LOG 16
#define PM8916_LBC_CHGR_MIN_CURRENT 90000
#define PM8916_LBC_CHGR_MAX_CURRENT 1440000
@@ -65,6 +96,61 @@
unsigned int charge_voltage_safe;
unsigned int charge_current_max;
unsigned int charge_current_safe;
+
+ /* charger supervisor (Aurora B10B-3 v3) */
+ struct iio_channel *vbat_chan;
+ struct delayed_work supv_work;
+ struct mutex supv_lock;
+ int state;
+ int fault_reason;
+ unsigned int hold_uv; /* aurora,hold-voltage-microvolt, 0 = HOLD disabled */
+ unsigned int full_min_uv; /* aurora,full-min-voltage-microvolt */
+ unsigned int cv_hold_min; /* aurora,cv-hold-minutes */
+ unsigned int ibat_code; /* IBAT_MAX code programmed at probe */
+ unsigned int timeout_min;
+ int vbat_uv;
+ int latch_polls;
+ int nocv_polls;
+ time64_t cv_since; /* start of the current CV run, 0 = none */
+ bool supv_ready; /* set at the end of probe; IRQ kicks only after that */
+ unsigned int n_insert;
+ unsigned int n_hold;
+ unsigned int n_latch;
+ struct {
+ time64_t t;
+ int from, to, vbat;
+ const char *why;
+ } log[PM8916_LBC_SUPV_LOG];
+ unsigned int log_n;
+ struct dentry *debugfs;
+};
+
+enum {
+ LBC_ST_INIT = 0,
+ LBC_ST_NO_USB,
+ LBC_ST_CHARGING,
+ LBC_ST_HOLD,
+ LBC_ST_FAULT,
+};
+
+static const char * const lbc_state_name[] = {
+ [LBC_ST_INIT] = "INIT",
+ [LBC_ST_NO_USB] = "NO_USB",
+ [LBC_ST_CHARGING] = "CHARGING",
+ [LBC_ST_HOLD] = "HOLD",
+ [LBC_ST_FAULT] = "FAULT",
+};
+
+enum {
+ LBC_FAULT_NONE = 0,
+ LBC_FAULT_TIMER,
+ LBC_FAULT_OVP,
+};
+
+static const char * const lbc_fault_name[] = {
+ [LBC_FAULT_NONE] = "none",
+ [LBC_FAULT_TIMER] = "safety-timer (CHG_FAILED)",
+ [LBC_FAULT_OVP] = "vbat-overvoltage",
};
static const unsigned int pm8916_lbc_charger_cable[] = {
@@ -79,7 +165,7 @@
LBC_MISC,
};
-static int pm8916_lbc_charger_configure(struct pm8916_lbc_charger *chg)
+static int pm8916_lbc_charger_configure(struct pm8916_lbc_charger *chg, bool probe)
{
int ret = 0;
unsigned int tmp;
@@ -91,9 +177,12 @@
tmp /= PM8916_LBC_CHGR_VOLTAGE_STEP;
chg->charge_voltage_max = PM8916_LBC_CHGR_MIN_VOLTAGE + tmp * PM8916_LBC_CHGR_VOLTAGE_STEP;
- ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_VDD_MAX, tmp);
- if (ret)
- goto error;
+ /* after probe the supervisor owns VDD_MAX (charge level / hold level) */
+ if (probe) {
+ ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_VDD_MAX, tmp);
+ if (ret)
+ goto error;
+ }
chg->charge_current_max = min(chg->charge_current_max, chg->charge_current_safe);
@@ -102,15 +191,22 @@
tmp = chg->charge_current_max / PM8916_LBC_CHGR_MIN_CURRENT - 1;
chg->charge_current_max = (tmp + 1) * PM8916_LBC_CHGR_MIN_CURRENT;
+ chg->ibat_code = tmp;
ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_IBAT_MAX, tmp);
if (ret)
goto error;
- ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_CHG_CTRL,
- PM8916_LBC_CHGR_CHG_EN | PM8916_LBC_CHGR_PSTG_EN);
- if (ret)
- goto error;
+ /*
+ * CHG_CTRL is written only at probe. Afterwards the supervisor owns CHG_EN, so a
+ * constant_charge_current update must not restart charging in HOLD/FAULT.
+ */
+ if (probe) {
+ ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_CHG_CTRL,
+ PM8916_LBC_CHGR_CHG_EN | PM8916_LBC_CHGR_PSTG_EN);
+ if (ret)
+ goto error;
+ }
return ret;
@@ -126,6 +222,23 @@
struct pm8916_lbc_charger *chg = power_supply_get_drvdata(psy);
switch (psp) {
+ case POWER_SUPPLY_PROP_STATUS:
+ switch (chg->state) {
+ case LBC_ST_CHARGING:
+ val->intval = POWER_SUPPLY_STATUS_CHARGING;
+ break;
+ case LBC_ST_HOLD:
+ val->intval = POWER_SUPPLY_STATUS_FULL;
+ break;
+ case LBC_ST_NO_USB:
+ val->intval = POWER_SUPPLY_STATUS_DISCHARGING;
+ break;
+ default:
+ val->intval = POWER_SUPPLY_STATUS_NOT_CHARGING;
+ break;
+ }
+ return 0;
+
case POWER_SUPPLY_PROP_ONLINE:
val->intval = chg->online;
return 0;
@@ -151,8 +264,15 @@
switch (prop) {
case POWER_SUPPLY_PROP_CONSTANT_CHARGE_CURRENT:
+ {
+ int ret;
+
+ mutex_lock(&chg->supv_lock);
chg->charge_current_max = val->intval;
- return pm8916_lbc_charger_configure(chg);
+ ret = pm8916_lbc_charger_configure(chg, false);
+ mutex_unlock(&chg->supv_lock);
+ return ret;
+ }
default:
return -EINVAL;
}
@@ -170,11 +290,265 @@
}
static enum power_supply_property pm8916_lbc_charger_properties[] = {
+ POWER_SUPPLY_PROP_STATUS,
POWER_SUPPLY_PROP_ONLINE,
POWER_SUPPLY_PROP_CONSTANT_CHARGE_VOLTAGE_MAX,
POWER_SUPPLY_PROP_CONSTANT_CHARGE_CURRENT,
};
+
+/*
+ * Aurora B10B-3 v3 charger supervisor: CHARGE -> HOLD -> (battery) -> CHARGE.
+ * Facts it relies on (B10A/B10B-2/B10B-3 tests): CHG_STATUS 00 + USB path 01 is a latch, not an end-of-charge;
+ * no hardware EOC was seen with BOOT_DONE set; CHG_EN = 0 does not stop the charger; verified levers are VDD_MAX,
+ * IBAT_MAX and the CHG_CTRL 0x21 -> 0xa0 edge (releases the latch). All decisions use the calibrated VADC VBAT.
+ * NO_USB: nothing is written.
+ * CHARGING: entered on USB insert/probe: BOOT_DONE, VDD_MAX = charge level, IBAT_MAX, restart edge.
+ * -> HOLD after the CV loop with VBAT >= full-min lasted cv-hold-minutes; 00/01 latch -> restart, stay.
+ * HOLD: only VDD_MAX = hold level; 00/01 latch -> restart edge, VDD_MAX stays at the hold level.
+ * FAULT: logical only (VBAT > 4.25 V or CHG_FAILED): no restarts. There is no verified software stop.
+ */
+static void lbc_supv_log(struct pm8916_lbc_charger *chg, int to, const char *why)
+{
+ unsigned int i = chg->log_n++ % PM8916_LBC_SUPV_LOG;
+
+ chg->log[i].t = ktime_get_seconds();
+ chg->log[i].from = chg->state;
+ chg->log[i].to = to;
+ chg->log[i].vbat = chg->vbat_uv;
+ chg->log[i].why = why;
+ if (to == LBC_ST_FAULT)
+ dev_crit(chg->dev, "supervisor %s -> FAULT (%s), vbat %d uV: restarts blocked, NO software stop available\n",
+ lbc_state_name[chg->state], why, chg->vbat_uv);
+ else
+ dev_info(chg->dev, "supervisor %s -> %s (%s), vbat %d uV\n", lbc_state_name[chg->state],
+ lbc_state_name[to], why, chg->vbat_uv);
+ chg->state = to;
+}
+
+static int lbc_charge_enable(struct pm8916_lbc_charger *chg, bool en)
+{
+ return regmap_update_bits(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_CHG_CTRL,
+ PM8916_LBC_CHGR_EN_MASK,
+ en ? PM8916_LBC_CHGR_CHG_EN : PM8916_LBC_CHGR_FORCE_BATT_ON);
+}
+
+/* the verified restart: CHG_CTRL 0x21 (CHG_EN 0) -> 20 ms -> 0xa0 (CHG_EN 1); on (re)insert also clear CHG_FAILED */
+static int lbc_charge_restart(struct pm8916_lbc_charger *chg, bool clear_failed)
+{
+ int ret;
+
+ if (clear_failed) {
+ ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_CHG_FAILED,
+ PM8916_LBC_CHGR_CHG_FAILED_BIT);
+ if (ret)
+ return ret;
+ }
+ ret = lbc_charge_enable(chg, false);
+ if (ret)
+ return ret;
+ msleep(20);
+ return lbc_charge_enable(chg, true);
+}
+
+static int lbc_set_vdd_max(struct pm8916_lbc_charger *chg, unsigned int uv)
+{
+ uv = clamp_t(u32, uv, PM8916_LBC_CHGR_MIN_VOLTAGE, chg->charge_voltage_safe);
+ return regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_VDD_MAX,
+ (uv - PM8916_LBC_CHGR_MIN_VOLTAGE) / PM8916_LBC_CHGR_VOLTAGE_STEP);
+}
+
+/* USB insert / probe with USB: start a full cycle at the charge level */
+static int lbc_enter_charging(struct pm8916_lbc_charger *chg)
+{
+ unsigned int v;
+ int ret;
+
+ ret = regmap_update_bits(chg->regmap, chg->reg[LBC_MISC] + PM8916_LBC_MISC_BOOT_DONE,
+ PM8916_LBC_MISC_BOOT_DONE_BIT, PM8916_LBC_MISC_BOOT_DONE_BIT);
+ ret = ret ?: lbc_set_vdd_max(chg, chg->charge_voltage_max);
+ ret = ret ?: regmap_read(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_IBAT_MAX, &v);
+ if (!ret && v != chg->ibat_code)
+ ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_IBAT_MAX, chg->ibat_code);
+ ret = ret ?: lbc_charge_restart(chg, true);
+ chg->latch_polls = 0;
+ chg->nocv_polls = 0;
+ chg->cv_since = 0;
+ return ret;
+}
+
+/* 00/01 latch with USB valid: count polls; restart with the verified edge (VDD_MAX untouched) */
+static bool lbc_handle_latch(struct pm8916_lbc_charger *chg, unsigned int sts, unsigned int path)
+{
+ if (sts == 0 && !(path & PM8916_LBC_USB_PATH_ON))
+ chg->latch_polls++;
+ else
+ chg->latch_polls = 0;
+ if (chg->latch_polls < PM8916_LBC_SUPV_LATCH_POLLS)
+ return false;
+ chg->latch_polls = 0;
+ chg->n_latch++;
+ if (!lbc_charge_restart(chg, false))
+ dev_warn(chg->dev, "supervisor: 00/01 latch in %s (vbat %d uV) -> restart edge #%u\n",
+ lbc_state_name[chg->state], chg->vbat_uv, chg->n_latch);
+ return true;
+}
+
+static bool lbc_check_fault(struct pm8916_lbc_charger *chg, unsigned int failed)
+{
+ if (failed & PM8916_LBC_CHGR_CHG_FAILED_BIT) {
+ chg->fault_reason = LBC_FAULT_TIMER;
+ lbc_supv_log(chg, LBC_ST_FAULT, "CHG_FAILED (safety timer)");
+ return true;
+ }
+ if (chg->vbat_uv > PM8916_LBC_SUPV_OVP_UV) {
+ chg->fault_reason = LBC_FAULT_OVP;
+ lbc_supv_log(chg, LBC_ST_FAULT, "vbat > 4.25 V");
+ return true;
+ }
+ return false;
+}
+
+static void lbc_supv_work(struct work_struct *work)
+{
+ struct pm8916_lbc_charger *chg = container_of(work, struct pm8916_lbc_charger, supv_work.work);
+ unsigned int usb_rt, sts, path, failed;
+ time64_t now = ktime_get_seconds();
+ int ret, uv;
+
+ mutex_lock(&chg->supv_lock);
+
+ ret = regmap_read(chg->regmap, chg->reg[LBC_USB] + PM8916_INT_RT_STS, &usb_rt);
+ ret = ret ?: regmap_read(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_CHG_STATUS, &sts);
+ ret = ret ?: regmap_read(chg->regmap, chg->reg[LBC_USB] + PM8916_LBC_USB_PATH_STS, &path);
+ ret = ret ?: regmap_read(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_CHG_FAILED, &failed);
+ if (ret) {
+ dev_err(chg->dev, "supervisor: register read failed: %d\n", ret);
+ goto out;
+ }
+ if (!iio_read_channel_processed(chg->vbat_chan, &uv))
+ chg->vbat_uv = uv;
+ else
+ chg->vbat_uv = -1;
+
+ if (!(usb_rt & PM8916_LBC_USB_USBIN_VALID)) {
+ if (chg->state != LBC_ST_NO_USB) {
+ chg->fault_reason = LBC_FAULT_NONE;
+ lbc_supv_log(chg, LBC_ST_NO_USB, "usb removed");
+ }
+ goto out;
+ }
+
+ switch (chg->state) {
+ case LBC_ST_INIT:
+ case LBC_ST_NO_USB:
+ chg->fault_reason = LBC_FAULT_NONE;
+ chg->n_insert++;
+ if (!lbc_enter_charging(chg))
+ lbc_supv_log(chg, LBC_ST_CHARGING,
+ chg->state == LBC_ST_INIT ? "probe, usb present" : "usb inserted");
+ break;
+
+ case LBC_ST_CHARGING:
+ if (lbc_check_fault(chg, failed))
+ break;
+ if (lbc_handle_latch(chg, sts, path)) {
+ chg->cv_since = 0;
+ chg->nocv_polls = 0;
+ break;
+ }
+ if (!chg->hold_uv || chg->vbat_uv < 0)
+ break;
+ /* CV run: CV loop bit with VBAT >= full-min; tolerate one poll without the bit (05/07 interleave) */
+ if ((unsigned int)chg->vbat_uv < chg->full_min_uv) {
+ chg->cv_since = 0;
+ chg->nocv_polls = 0;
+ break;
+ }
+ if (sts & PM8916_LBC_CHGR_CV_LOOP) {
+ chg->nocv_polls = 0;
+ if (!chg->cv_since)
+ chg->cv_since = now;
+ } else if (++chg->nocv_polls >= PM8916_LBC_SUPV_NOCV_POLLS) {
+ chg->cv_since = 0;
+ }
+ if (chg->cv_since && now - chg->cv_since >= (time64_t)chg->cv_hold_min * 60) {
+ if (!lbc_set_vdd_max(chg, chg->hold_uv)) {
+ chg->n_hold++;
+ chg->latch_polls = 0;
+ lbc_supv_log(chg, LBC_ST_HOLD, "CV time reached, VDD_MAX -> hold level");
+ }
+ }
+ break;
+
+ case LBC_ST_HOLD:
+ if (lbc_check_fault(chg, failed))
+ break;
+ /* keep the board on USB: a 00/01 latch gets the restart edge, VDD_MAX stays at the hold level */
+ lbc_handle_latch(chg, sts, path);
+ break;
+
+ case LBC_ST_FAULT:
+ /* latched: left only by USB removal/insert or reboot */
+ break;
+ }
+
+out:
+ mutex_unlock(&chg->supv_lock);
+ power_supply_changed(chg->charger);
+ queue_delayed_work(system_freezable_wq, &chg->supv_work,
+ msecs_to_jiffies(PM8916_LBC_SUPV_PERIOD_MS));
+}
+
+static int lbc_state_show(struct seq_file *s, void *unused)
+{
+ struct pm8916_lbc_charger *chg = s->private;
+ static const struct { const char *n; int blk; unsigned int off; } regs[] = {
+ { "CHG_STATUS", LBC_CHGR, PM8916_LBC_CHGR_CHG_STATUS },
+ { "CHGR_RT", LBC_CHGR, PM8916_INT_RT_STS },
+ { "CHG_CTRL", LBC_CHGR, PM8916_LBC_CHGR_CHG_CTRL },
+ { "CHG_FAILED", LBC_CHGR, PM8916_LBC_CHGR_CHG_FAILED },
+ { "VDD_MAX", LBC_CHGR, PM8916_LBC_CHGR_VDD_MAX },
+ { "IBAT_MAX", LBC_CHGR, PM8916_LBC_CHGR_IBAT_MAX },
+ { "TCHG_MAX_EN", LBC_CHGR, PM8916_LBC_CHGR_TCHG_MAX_EN },
+ { "TCHG_MAX", LBC_CHGR, PM8916_LBC_CHGR_TCHG_MAX },
+ { "USB_PATH", LBC_USB, PM8916_LBC_USB_PATH_STS },
+ { "USB_RT", LBC_USB, PM8916_INT_RT_STS },
+ { "BAT_RT", LBC_BAT_IF, PM8916_INT_RT_STS },
+ { "BOOT_DONE", LBC_MISC, PM8916_LBC_MISC_BOOT_DONE },
+ };
+ time64_t now = ktime_get_seconds();
+ unsigned int i, v;
+
+ mutex_lock(&chg->supv_lock);
+ seq_printf(s, "state %s fault %s vbat_uv %d\n", lbc_state_name[chg->state],
+ lbc_fault_name[chg->fault_reason], chg->vbat_uv);
+ seq_printf(s, "charge_uv %u hold_uv %u full_min_uv %u cv_hold_min %u cv_s %lld nocv %d timeout_min %u\n",
+ chg->charge_voltage_max, chg->hold_uv, chg->full_min_uv, chg->cv_hold_min,
+ chg->cv_since ? now - chg->cv_since : -1LL, chg->nocv_polls, chg->timeout_min);
+ seq_printf(s, "n_insert %u n_hold %u n_latch %u\n", chg->n_insert, chg->n_hold, chg->n_latch);
+ for (i = 0; i < ARRAY_SIZE(regs); i++) {
+ if (regmap_read(chg->regmap, chg->reg[regs[i].blk] + regs[i].off, &v))
+ v = 0xffff;
+ seq_printf(s, "%s %02x\n", regs[i].n, v);
+ }
+ for (i = chg->log_n > PM8916_LBC_SUPV_LOG ? chg->log_n - PM8916_LBC_SUPV_LOG : 0; i < chg->log_n; i++) {
+ unsigned int j = i % PM8916_LBC_SUPV_LOG;
+
+ seq_printf(s, "log %u t=%lld %s->%s vbat=%d %s\n", i, chg->log[j].t,
+ lbc_state_name[chg->log[j].from], lbc_state_name[chg->log[j].to],
+ chg->log[j].vbat, chg->log[j].why);
+ }
+ mutex_unlock(&chg->supv_lock);
+ return 0;
+}
+DEFINE_SHOW_ATTRIBUTE(lbc_state);
+
+static void lbc_debugfs_remove(void *data)
+{
+ debugfs_remove_recursive(data);
+}
+
static irqreturn_t pm8916_lbc_charger_state_changed_irq(int irq, void *data)
{
struct pm8916_lbc_charger *chg = data;
@@ -190,6 +564,9 @@
power_supply_changed(chg->charger);
+ if (READ_ONCE(chg->supv_ready))
+ mod_delayed_work(system_freezable_wq, &chg->supv_work, 0);
+
return IRQ_HANDLED;
}
@@ -230,10 +607,35 @@
if (ret)
return ret;
- /* Disable charger timeout. */
+ /*
+ * Keep the charger safety timer running (upstream disabled it). Same sequence as the
+ * downstream qpnp-linear-charger: timer off, TCHG_MAX = minutes / 4 - 1 (4..512 min), timer on.
+ */
+ chg->timeout_min = PM8916_LBC_TIMEOUT_DEFAULT_MIN;
+ device_property_read_u32(dev, "qcom,charge-timeout-minutes", &chg->timeout_min);
+ chg->timeout_min = clamp_t(u32, chg->timeout_min, PM8916_LBC_TIMEOUT_STEP_MIN,
+ PM8916_LBC_TIMEOUT_MAX_MIN);
+ chg->timeout_min -= chg->timeout_min % PM8916_LBC_TIMEOUT_STEP_MIN;
+
ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_TCHG_MAX_EN, 0x00);
if (ret)
return ret;
+ tmp = chg->timeout_min / PM8916_LBC_TIMEOUT_STEP_MIN - 1;
+ ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_TCHG_MAX, tmp);
+ if (ret)
+ return ret;
+ ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_TCHG_MAX_EN,
+ PM8916_LBC_CHGR_TCHG_MAX_ENABLED);
+ if (ret)
+ return ret;
+
+ ret = regmap_read(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_TCHG_MAX, &tmp);
+ if (ret)
+ return ret;
+ if (tmp != chg->timeout_min / PM8916_LBC_TIMEOUT_STEP_MIN - 1)
+ return dev_err_probe(dev, -EIO, "TCHG_MAX readback 0x%x != 0x%x\n", tmp,
+ chg->timeout_min / PM8916_LBC_TIMEOUT_STEP_MIN - 1);
+ dev_info(dev, "safety timer %u min (TCHG_MAX 0x%02x), enabled\n", chg->timeout_min, tmp);
return ret;
}
@@ -261,6 +663,7 @@
return -ENOMEM;
chg->dev = dev;
+ mutex_init(&chg->supv_lock);
chg->regmap = dev_get_regmap(pdev->dev.parent, NULL);
if (!chg->regmap)
@@ -309,7 +712,7 @@
ret = pm8916_lbc_charger_probe_dt(chg);
if (ret)
- dev_err_probe(dev, ret, "Error while parsing device tree\n");
+ return dev_err_probe(dev, ret, "Error while parsing device tree\n");
psy_cfg.drv_data = chg;
psy_cfg.fwnode = dev_fwnode(dev);
@@ -322,6 +725,21 @@
if (ret)
return dev_err_probe(dev, ret, "Unable to get battery info\n");
+ chg->vbat_chan = devm_iio_channel_get(dev, "vbat");
+ if (IS_ERR(chg->vbat_chan))
+ return dev_err_probe(dev, PTR_ERR(chg->vbat_chan), "no VADC vbat channel\n");
+
+ chg->cv_hold_min = PM8916_LBC_CV_HOLD_DEFAULT_MIN;
+ device_property_read_u32(dev, "aurora,cv-hold-minutes", &chg->cv_hold_min);
+ if (device_property_read_u32(dev, "aurora,hold-voltage-microvolt", &chg->hold_uv) ||
+ device_property_read_u32(dev, "aurora,full-min-voltage-microvolt", &chg->full_min_uv)) {
+ chg->hold_uv = 0;
+ dev_warn(dev, "no aurora,hold-voltage/full-min-voltage: HOLD disabled\n");
+ }
+ ret = devm_delayed_work_autocancel(dev, &chg->supv_work, lbc_supv_work);
+ if (ret)
+ return ret;
+
irq = platform_get_irq_byname(pdev, "usb_vbus");
if (irq < 0)
return irq;
@@ -347,10 +765,29 @@
extcon_set_state_sync(chg->edev, EXTCON_USB, chg->online);
chg->charge_voltage_max = chg->info->voltage_max_design_uv;
- ret = pm8916_lbc_charger_configure(chg);
+ ret = pm8916_lbc_charger_configure(chg, true);
+ if (ret)
+ return ret;
+
+ chg->debugfs = debugfs_create_dir("pm8916_lbc", NULL);
+ debugfs_create_file("state", 0444, chg->debugfs, chg, &lbc_state_fops);
+ ret = devm_add_action_or_reset(dev, lbc_debugfs_remove, chg->debugfs);
if (ret)
return ret;
+ if (chg->hold_uv && (chg->hold_uv < PM8916_LBC_CHGR_MIN_VOLTAGE ||
+ chg->hold_uv >= chg->charge_voltage_max ||
+ chg->full_min_uv > chg->charge_voltage_max)) {
+ dev_warn(dev, "invalid hold %u / full-min %u for charge level %u: HOLD disabled\n",
+ chg->hold_uv, chg->full_min_uv, chg->charge_voltage_max);
+ chg->hold_uv = 0;
+ }
+ dev_info(dev, "supervisor v3: charge %u uV, hold %u uV, full-min %u uV, cv %u min, IBAT_MAX code %u, ovp %d uV\n",
+ chg->charge_voltage_max, chg->hold_uv, chg->full_min_uv, chg->cv_hold_min,
+ chg->ibat_code, PM8916_LBC_SUPV_OVP_UV);
+ WRITE_ONCE(chg->supv_ready, true);
+ queue_delayed_work(system_freezable_wq, &chg->supv_work, 0);
+
return 0;
comm_error:

View file

@ -1,18 +0,0 @@
#!/bin/sh
# B10B-3 board-side observer (env VMAX = ALERT VBAT uV, EVDD = expected VDD_MAX hex): every P s append one line to /tmp/b10b3-mon.log (survives NCM/USB loss). Reads only.
P=${1:-30}
grep -q " /sys/kernel/debug " /proc/mounts || mount -t debugfs debugfs /sys/kernel/debug
R=/sys/kernel/debug/regmap/0-00/registers; S=/sys/kernel/debug/pm8916_lbc/state
rd() { dd if=$R bs=9 skip=$(($1)) count=$2 2>/dev/null | cut -d' ' -f2 | tr '\n' ' '; }
D=/sys/bus/iio/devices/iio:device0; C=/sys/class/power_supply/pm8916-lbc-chgr
trap '' HUP
i=0
while [ ! -e /tmp/b10b3-mon.stop ]; do
i=$((i + 1)); vb=$(cat $D/in_voltage6_input); pt=$(cat $D/in_temp8_input)
a=""; [ "$vb" -gt ${VMAX:-4220000} ] && a="$a ALERT-VBAT"; [ "$pt" -gt 60000 ] && a="$a ALERT-TEMP"; [ "$(rd 0x1060 1)" != "80 " ] && a="$a ALERT-TIMER"; case "$(rd 0x1040 1)" in ${EVDD:-08}" "|${EVDD2:-xx}" ") ;; *) a="$a ALERT-VDDMAX";; esac; [ "$(rd 0x1044 1)" != "04 " ] && a="$a ALERT-IBAT"
st=$(head -1 $S | tr ' ' '='); cv=$(sed -n 2p $S | sed 's/.*cv_s \([-0-9]*\) nocv \([0-9]*\).*/cv_s=\1 nocv=\2/'); cnt=$(sed -n 3p $S | tr ' ' '='); vdd=$(rd 0x1040 1)
ld=$(pgrep -c yes 2>/dev/null || ps | grep -c "[y]es$")
echo "M $i $(date -u +%T) up=$(cut -d' ' -f1 /proc/uptime) $st $cv $cnt vbat6=$vb vph=$(cat $D/in_voltage7_input) usbin=$(cat $D/in_voltage0_input) fifo=$(rd 0x40c0 4) chgst=$(rd 0x1009 1) crt=$(rd 0x1010 1) brt=$(rd 0x1210 1) urt=$(rd 0x1310 1) usbp=$(rd 0x1308 2) ctrl=$(rd 0x1049 1) vdd=$vdd ibat=$(rd 0x1044 1) tchg=$(rd 0x1060 2) failed=$(rd 0x104a 1) bd=$(rd 0x1642 1) online=$(cat $C/online) psy=$(cat $C/status) pmt=$pt cpu=$(cat /sys/class/thermal/thermal_zone4/temp) load=$ld$a" >> /tmp/b10b3-mon.log
sleep $P
done
echo "MON-END $(date -u +%T)" >> /tmp/b10b3-mon.log

View file

@ -1,8 +0,0 @@
#!/bin/sh
# 480s side: every 30 s copy the board's /tmp/b10b3-mon.log into logs/b10/b10b3/<K>-mon.txt (keeps the last good copy while NCM is down).
K=$1; cd ~/doc/modem/jz08-aurora; O=logs/b10/b10b3/$K-mon.txt
while [ ! -e logs/b10/b10b3/pull.stop ]; do
{ sleep 1; printf 'cat /tmp/b10b3-mon.log\r\n'; sleep 4; } | ncat -w 8 172.16.42.1 23 2>/dev/null | tr -d '\000\r' | grep -E '^(M |MON-END)' > $O.tmp
[ -s $O.tmp ] && [ $(wc -l < $O.tmp) -ge $(cat $O 2>/dev/null | wc -l) ] && mv $O.tmp $O
sleep 30
done

View file

@ -1,60 +0,0 @@
#!/bin/sh
# 480s side, B10B-3 Test B (TEST image) boot K (RAM only). RESET-held power-on -> lk1st fastboot -> `fastboot boot` B10B-3 RAM image. Reads only over telnet.
# MODE=cold: normal power-on (no RESET, no fastboot) -> lk2nd extlinux from eMMC cache. Script only observes + reads over telnet;
# nothing is written to eMMC. Visual display checks need the operator. Adds display/fbcon/getty/console checks to the B8F snapshot.
K=$1; MODE=ram; [ -n "$K" ] || { echo "usage: $0 K"; exit 2; }
cd ~/doc/modem/jz08-aurora; O=logs/b10/b10b3/b$K; mkdir -p $O; IMG=b10/b10b3/out-b/aurora-b10b3b.img
A=$O/host-actions.txt; act() { echo "$(date -u +%H:%M:%S.%3N) $*" | tee -a $A; }
tn() { { sleep 1; sed "s/\$/\r/" "$1"; sleep $2; } | ncat 172.16.42.1 23 | tr -d "\000\r"; }
OLD=$(ps -eo pid,cmd | grep "[u]artlog.py /dev/ttyUSB0" | awk '{print $1}'); [ -n "$OLD" ] && kill $OLD; sleep 1
U=logs/uart/b10b3b-$MODE$K-$(date +%Y%m%d-%H%M%S); setsid nohup python3 tools/uartlog.py /dev/ttyUSB0 $U > $U.stderr 2>&1 < /dev/null &
if [ $MODE = ram ]; then
echo "9e66466d64e6832865af145e365c3ee36619d3607fee3b7cd9609533d1102c06 $IMG" | sha256sum -c || exit 1
act "B10B3B $MODE$K: waiting for fastboot <EMMC_SERIAL> (power off >= 90 s, then RESET held + battery -> USB)"
if fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; then act "already in fastboot - wait for power-off"; until ! fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do sleep 1; done; fi
i=0; until fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do i=$((i+1)); [ $i -ge 1800 ] && { act "ABORT: no fastboot"; exit 1; }; sleep 2; done
act "fastboot present"; { fastboot boot $IMG 2>&1; echo "rc=$?"; } | tee -a $A
else
act "B10B3B $MODE$K: waiting for the board to go away (power off >= 90 s), then normal power-on WITHOUT RESET"
until ! ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do sleep 1; done; act "board unreachable (powered off)"
until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL> && { act "ABORT: board is in fastboot - RESET was held?"; exit 1; }; sleep 1; done
fi
i=0; until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do i=$((i+1)); [ $i -ge 180 ] && { act "ABORT: NCM not up"; cp $U.log $O/uart.log; exit 1; }; sleep 1; done; act "NCM ping ok"
R=$(grep -a "rtc-pm8xxx.*setting system clock" $U.log | tail -1 | sed -n 's/.*(\([0-9]*\)).*/\1/p'); C=B; [ -n "$R" ] && [ "$R" -lt 40 ] && C=A; act "RTC at boot ${R:-?} s -> class $C"
printf 'cat /proc/device-tree/model; echo; uname -r; grep -E "START OK|FAIL in|rollback" /run/aurora-modem/lifecycle.log | tail -1\n' > $O/.w
i=0; until tn $O/.w 3 | grep -qE "^\[[0-9.]+\] .*(=== START OK|FAIL in|rollback)"; do i=$((i+1)); [ $i -ge 80 ] && { act "no START OK/FAIL after ~12 min"; break; }; sleep 6; done
tn $O/.w 3 | grep -aE "Aurora|aurora-b8|START OK|FAIL" | tee -a $A
printf 'grep -E "AP ENABLED|FAIL" /run/aurora-wifi/wifi.log | tail -1\n' > $O/.a
i=0; until tn $O/.a 3 | grep -qE "^\[[0-9.]+\] (=== AP ENABLED|FAIL)"; do i=$((i+1)); [ $i -ge 20 ] && { act "no AP ENABLED/FAIL after ~3 min"; break; }; sleep 6; done
act "wifi: $(tn $O/.a 3 | grep -E '^\[[0-9.]+\] (=== AP ENABLED|FAIL)' | tail -1)"
printf 'grep -E "SNTP (check|STEP|: )" /run/aurora-modem/lifecycle.log | tail -2\n' > $O/.s
i=0; until tn $O/.s 3 | grep -qE "^\[[0-9.]+\] SNTP"; do i=$((i+1)); [ $i -ge 15 ] && break; sleep 4; done; act "sntp: $(tn $O/.s 3 | grep -E '^\[[0-9.]+\] SNTP' | tail -2 | tr '\n' ' ')"
cat > $O/.c <<'C'
echo SNAP-BEGIN; cat /proc/uptime; date -u; cat /proc/device-tree/model; echo; uname -a; cat /proc/cmdline
echo ---time; cat /run/aurora-modem/time-set; grep -E "TIME|SNTP" /run/aurora-modem/lifecycle.log | tail -4
echo ---modem; /etc/init.d/aurora-modem status
echo ---wifi; /etc/init.d/aurora-wifi status; echo ---wifilog; cat /run/aurora-wifi/wifi.log; cat /run/aurora-wifi/service.log; echo ---hostapdlog; cat /run/aurora-wifi/hostapd.log
for r in /sys/class/remoteproc/*; do echo "RP $(cat $r/name)=$(cat $r/state)"; done; iw dev
echo ---dmesg-wifi; dmesg | grep -iE "wcn36xx|wcnss|a204000|cfg80211|aurora-wifi|crash|watchdog"
echo ---ping; ping -c4 -W3 -I wwan0 77.88.8.8 | tail -2
echo ---display; /etc/init.d/aurora-display status; cat /run/aurora-display/display.log; cat /run/aurora-display/service.log
echo ---consoles; cat /sys/class/tty/console/active; for v in /sys/class/vtconsole/vtcon*; do echo "$v $(cat $v/bind) $(cat $v/name)"; done; ls -l /proc/[0-9]*/fd/0 2>/dev/null | grep -E "ttyMSM0|tty1|console" | sed "s/.* \/proc/\/proc/"
echo ---getty; hostname; ps | grep -E "[g]etty|[c]ttyhack| sh$"
echo ---fb; ls -l /dev/dri/card0 /dev/fb0; for f in name bits_per_pixel virtual_size stride; do echo "fb0 $f=$(cat /sys/class/graphics/fb0/$f)"; done; cat /sys/class/drm/card0-SPI-1/enabled /sys/class/drm/card0-SPI-1/dpms
echo ---regs; for r in /sys/class/regulator/regulator.*; do n=$(cat $r/name); case $n in l6|l17) echo "$n $(cat $r/state) $(cat $r/microvolts) users=$(cat $r/num_users)";; esac; done
echo ---bl; for f in bl_power brightness actual_brightness; do echo "bl $f=$(cat /sys/class/backlight/backlight/$f)"; done
echo ---dmesg-display; dmesg | grep -iE "drm|panel|mipi|spi_qup|78b8000|fbcon|Console: |frame buffer|backlight|aurora-display|l17"
echo ---display-errors; dmesg | grep -iE "drm|panel|mipi|spi0|fbcon|backlight|aurora-display" | grep -ciE "err|fail|timeout|warn"
echo ---iio; for d in /sys/bus/iio/devices/iio:device*; do echo "$d name=$(cat $d/name)"; ls $d | tr '\n' ' '; echo; done
for f in /sys/bus/iio/devices/iio:device*/in_*; do case $f in *_raw|*_input|*_scale|*_offset) echo "$f=$(cat $f 2>&1)";; esac; done
echo ---psy; ls -l /sys/class/power_supply/; for p in /sys/class/power_supply/*; do echo "-- $p"; cat $p/uevent; ls $p; done
echo ---dmesg-bms; dmesg | grep -iE "bms|battery|power_supply|lbc|charger|extcon|ci_hdrc|4000|1000"
echo ---lbc-state; grep -q " /sys/kernel/debug " /proc/mounts || mount -t debugfs debugfs /sys/kernel/debug; cat /sys/kernel/debug/pm8916_lbc/state; dmesg | grep -E "safety timer|supervisor|pm8916-lbc|lbc"
echo ---thermal; for t in /sys/class/thermal/thermal_zone*; do echo "$t $(cat $t/type) $(cat $t/temp)"; done
echo ---dmesg-adc; dmesg | grep -iE "vadc|iio|temp-alarm|qpnp|spmi-temp|pm8916-thermal|thermal"
echo ---emmc; awk "{print \"w=\"\$5\" s=\"\$7}" /sys/block/mmcblk0/stat
echo SNAP-END
C
tn $O/.c 25 > $O/snapshot.txt; act "snapshot: $(grep -c SNAP-END $O/snapshot.txt) end markers; $(grep -E '^RP a204' $O/snapshot.txt)"
printf 'dmesg > /tmp/dm.txt; nc -l -p 9881 < /tmp/dm.txt &\n' > $O/.d; tn $O/.d 3 >/dev/null; sleep 1; ncat --recv-only 172.16.42.1 9881 > $O/dmesg.full
cp $U.log $O/uart.log; act "B10B3B $MODE$K END - operator visual check next"

View file

@ -1,17 +0,0 @@
#!/bin/sh
# Test B board-side CPU load with guard: N x `yes`, stop on PMIC > 52 C, VADC VBAT < 3.95 V, or after MAX s. Writes /tmp only.
N=${1:-2}; MAX=${2:-300}; L=/tmp/b10b3b-load.log; D=/sys/bus/iio/devices/iio:device0
trap '' HUP
t0=$(cut -d. -f1 /proc/uptime); P=""
for i in $(seq 1 $N); do yes > /dev/null & P="$P $!"; done
echo "LOAD-START up=$t0 n=$N pids=$P" >> $L
why=timeout
while :; do
t=$(cut -d. -f1 /proc/uptime); vb=$(cat $D/in_voltage6_input); pt=$(cat $D/in_temp8_input)
echo "L up=$t vbat6=$vb pmt=$pt" >> $L
[ "$pt" -gt 52000 ] && { why=pmic-52C; break; }
[ "$vb" -lt 3950000 ] && { why=vbat-below-3.95V; break; }
[ $((t - t0)) -ge $MAX ] && break
sleep 5
done
kill $P; echo "LOAD-STOP up=$(cut -d' ' -f1 /proc/uptime) reason=$why" >> $L

View file

@ -1,14 +0,0 @@
#!/bin/sh
# 480s side, Test B: wait for the NEW boot's NCM, then at once push b10b3-mon.sh to the board and start it (10 s, EVDD=02/00, VMAX 4.15 V),
# then start the 30-s pull into logs/b10/b10b3/<K>-mon.txt. Board side reads only (writes /tmp only). usage: b10b3b-mon-start.sh K
K=$1; [ -n "$K" ] || { echo "usage: $0 K"; exit 2; }
cd ~/doc/modem/jz08-aurora; A=logs/b10/b10b3/$K-actions.txt; act() { echo "$(date -u +%H:%M:%S.%3N) $*" | tee -a $A; }
rm -f logs/b10/b10b3/pull.stop
act "mon-start $K: waiting for the board to go away (warm reboot)"; until ! ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do sleep 0.5; done; act "board gone"
until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do sleep 0.5; done; act "NCM up"
i=0; until { sleep 1; printf 'nc -l -p 9933 > /tmp/b10b3-mon.sh &\r\n'; sleep 1; } | ncat -w 4 172.16.42.1 23 >/dev/null 2>&1; do i=$((i+1)); [ $i -ge 60 ] && { act "ABORT: no telnet"; exit 1; }; sleep 1; done
sleep 1; ncat --send-only 172.16.42.1 9933 < b10/b10b3/b10b3-mon.sh; sleep 1
sh b10/b10b3/b10b3-cmd.sh 3 'md5sum /tmp/b10b3-mon.sh; rm -f /tmp/b10b3-mon.stop; VMAX=4150000 EVDD=02 EVDD2=00 setsid sh /tmp/b10b3-mon.sh 10 > /dev/null 2>&1 < /dev/null & sleep 1; dmesg | grep -E "safety timer|supervisor"; cut -d" " -f1 /proc/uptime' | tee -a $A
act "local md5 $(md5sum < b10/b10b3/b10b3-mon.sh)"
setsid nohup sh b10/b10b3/b10b3-pull.sh $K > /dev/null 2>&1 < /dev/null &
act "monitor started (10 s), pull started -> logs/b10/b10b3/$K-mon.txt"

View file

@ -1,60 +0,0 @@
#!/bin/sh
# 480s side, B10B-3 Test C (TEST image) boot K (RAM only). RESET-held power-on -> lk1st fastboot -> `fastboot boot` B10B-3 RAM image. Reads only over telnet.
# MODE=cold: normal power-on (no RESET, no fastboot) -> lk2nd extlinux from eMMC cache. Script only observes + reads over telnet;
# nothing is written to eMMC. Visual display checks need the operator. Adds display/fbcon/getty/console checks to the B8F snapshot.
K=$1; MODE=ram; [ -n "$K" ] || { echo "usage: $0 K"; exit 2; }
cd ~/doc/modem/jz08-aurora; O=logs/b10/b10b3/c$K; mkdir -p $O; IMG=b10/b10b3/out-c/aurora-b10b3c.img
A=$O/host-actions.txt; act() { echo "$(date -u +%H:%M:%S.%3N) $*" | tee -a $A; }
tn() { { sleep 1; sed "s/\$/\r/" "$1"; sleep $2; } | ncat 172.16.42.1 23 | tr -d "\000\r"; }
OLD=$(ps -eo pid,cmd | grep "[u]artlog.py /dev/ttyUSB0" | awk '{print $1}'); [ -n "$OLD" ] && kill $OLD; sleep 1
U=logs/uart/b10b3c-$MODE$K-$(date +%Y%m%d-%H%M%S); setsid nohup python3 tools/uartlog.py /dev/ttyUSB0 $U > $U.stderr 2>&1 < /dev/null &
if [ $MODE = ram ]; then
echo "5ff9dec079a300511883d3d6a79c72539f43c980e921c34af7916e949ca1010d $IMG" | sha256sum -c || exit 1
act "B10B3C $MODE$K: waiting for fastboot <EMMC_SERIAL> (power off >= 90 s, then RESET held + battery -> USB)"
if fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; then act "already in fastboot - wait for power-off"; until ! fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do sleep 1; done; fi
i=0; until fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do i=$((i+1)); [ $i -ge 1800 ] && { act "ABORT: no fastboot"; exit 1; }; sleep 2; done
act "fastboot present"; { fastboot boot $IMG 2>&1; echo "rc=$?"; } | tee -a $A
else
act "B10B3C $MODE$K: waiting for the board to go away (power off >= 90 s), then normal power-on WITHOUT RESET"
until ! ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do sleep 1; done; act "board unreachable (powered off)"
until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL> && { act "ABORT: board is in fastboot - RESET was held?"; exit 1; }; sleep 1; done
fi
i=0; until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do i=$((i+1)); [ $i -ge 180 ] && { act "ABORT: NCM not up"; cp $U.log $O/uart.log; exit 1; }; sleep 1; done; act "NCM ping ok"
R=$(grep -a "rtc-pm8xxx.*setting system clock" $U.log | tail -1 | sed -n 's/.*(\([0-9]*\)).*/\1/p'); C=B; [ -n "$R" ] && [ "$R" -lt 40 ] && C=A; act "RTC at boot ${R:-?} s -> class $C"
printf 'cat /proc/device-tree/model; echo; uname -r; grep -E "START OK|FAIL in|rollback" /run/aurora-modem/lifecycle.log | tail -1\n' > $O/.w
i=0; until tn $O/.w 3 | grep -qE "^\[[0-9.]+\] .*(=== START OK|FAIL in|rollback)"; do i=$((i+1)); [ $i -ge 80 ] && { act "no START OK/FAIL after ~12 min"; break; }; sleep 6; done
tn $O/.w 3 | grep -aE "Aurora|aurora-b8|START OK|FAIL" | tee -a $A
printf 'grep -E "AP ENABLED|FAIL" /run/aurora-wifi/wifi.log | tail -1\n' > $O/.a
i=0; until tn $O/.a 3 | grep -qE "^\[[0-9.]+\] (=== AP ENABLED|FAIL)"; do i=$((i+1)); [ $i -ge 20 ] && { act "no AP ENABLED/FAIL after ~3 min"; break; }; sleep 6; done
act "wifi: $(tn $O/.a 3 | grep -E '^\[[0-9.]+\] (=== AP ENABLED|FAIL)' | tail -1)"
printf 'grep -E "SNTP (check|STEP|: )" /run/aurora-modem/lifecycle.log | tail -2\n' > $O/.s
i=0; until tn $O/.s 3 | grep -qE "^\[[0-9.]+\] SNTP"; do i=$((i+1)); [ $i -ge 15 ] && break; sleep 4; done; act "sntp: $(tn $O/.s 3 | grep -E '^\[[0-9.]+\] SNTP' | tail -2 | tr '\n' ' ')"
cat > $O/.c <<'C'
echo SNAP-BEGIN; cat /proc/uptime; date -u; cat /proc/device-tree/model; echo; uname -a; cat /proc/cmdline
echo ---time; cat /run/aurora-modem/time-set; grep -E "TIME|SNTP" /run/aurora-modem/lifecycle.log | tail -4
echo ---modem; /etc/init.d/aurora-modem status
echo ---wifi; /etc/init.d/aurora-wifi status; echo ---wifilog; cat /run/aurora-wifi/wifi.log; cat /run/aurora-wifi/service.log; echo ---hostapdlog; cat /run/aurora-wifi/hostapd.log
for r in /sys/class/remoteproc/*; do echo "RP $(cat $r/name)=$(cat $r/state)"; done; iw dev
echo ---dmesg-wifi; dmesg | grep -iE "wcn36xx|wcnss|a204000|cfg80211|aurora-wifi|crash|watchdog"
echo ---ping; ping -c4 -W3 -I wwan0 77.88.8.8 | tail -2
echo ---display; /etc/init.d/aurora-display status; cat /run/aurora-display/display.log; cat /run/aurora-display/service.log
echo ---consoles; cat /sys/class/tty/console/active; for v in /sys/class/vtconsole/vtcon*; do echo "$v $(cat $v/bind) $(cat $v/name)"; done; ls -l /proc/[0-9]*/fd/0 2>/dev/null | grep -E "ttyMSM0|tty1|console" | sed "s/.* \/proc/\/proc/"
echo ---getty; hostname; ps | grep -E "[g]etty|[c]ttyhack| sh$"
echo ---fb; ls -l /dev/dri/card0 /dev/fb0; for f in name bits_per_pixel virtual_size stride; do echo "fb0 $f=$(cat /sys/class/graphics/fb0/$f)"; done; cat /sys/class/drm/card0-SPI-1/enabled /sys/class/drm/card0-SPI-1/dpms
echo ---regs; for r in /sys/class/regulator/regulator.*; do n=$(cat $r/name); case $n in l6|l17) echo "$n $(cat $r/state) $(cat $r/microvolts) users=$(cat $r/num_users)";; esac; done
echo ---bl; for f in bl_power brightness actual_brightness; do echo "bl $f=$(cat /sys/class/backlight/backlight/$f)"; done
echo ---dmesg-display; dmesg | grep -iE "drm|panel|mipi|spi_qup|78b8000|fbcon|Console: |frame buffer|backlight|aurora-display|l17"
echo ---display-errors; dmesg | grep -iE "drm|panel|mipi|spi0|fbcon|backlight|aurora-display" | grep -ciE "err|fail|timeout|warn"
echo ---iio; for d in /sys/bus/iio/devices/iio:device*; do echo "$d name=$(cat $d/name)"; ls $d | tr '\n' ' '; echo; done
for f in /sys/bus/iio/devices/iio:device*/in_*; do case $f in *_raw|*_input|*_scale|*_offset) echo "$f=$(cat $f 2>&1)";; esac; done
echo ---psy; ls -l /sys/class/power_supply/; for p in /sys/class/power_supply/*; do echo "-- $p"; cat $p/uevent; ls $p; done
echo ---dmesg-bms; dmesg | grep -iE "bms|battery|power_supply|lbc|charger|extcon|ci_hdrc|4000|1000"
echo ---lbc-state; grep -q " /sys/kernel/debug " /proc/mounts || mount -t debugfs debugfs /sys/kernel/debug; cat /sys/kernel/debug/pm8916_lbc/state; dmesg | grep -E "safety timer|supervisor|pm8916-lbc|lbc"
echo ---thermal; for t in /sys/class/thermal/thermal_zone*; do echo "$t $(cat $t/type) $(cat $t/temp)"; done
echo ---dmesg-adc; dmesg | grep -iE "vadc|iio|temp-alarm|qpnp|spmi-temp|pm8916-thermal|thermal"
echo ---emmc; awk "{print \"w=\"\$5\" s=\"\$7}" /sys/block/mmcblk0/stat
echo SNAP-END
C
tn $O/.c 25 > $O/snapshot.txt; act "snapshot: $(grep -c SNAP-END $O/snapshot.txt) end markers; $(grep -E '^RP a204' $O/snapshot.txt)"
printf 'dmesg > /tmp/dm.txt; nc -l -p 9881 < /tmp/dm.txt &\n' > $O/.d; tn $O/.d 3 >/dev/null; sleep 1; ncat --recv-only 172.16.42.1 9881 > $O/dmesg.full
cp $U.log $O/uart.log; act "B10B3C $MODE$K END - operator visual check next"

View file

@ -1,60 +0,0 @@
#!/bin/sh
# 480s side, B10B-3 CACHE CANDIDATE RAM pretest (same kernel/DTB/initramfs/cmdline as cache-extlinux-b10b3.img) boot K (RAM only). RESET-held power-on -> lk1st fastboot -> `fastboot boot` B10B-3 RAM image. Reads only over telnet.
# MODE=cold: normal power-on (no RESET, no fastboot) -> lk2nd extlinux from eMMC cache. Script only observes + reads over telnet;
# nothing is written to eMMC. Visual display checks need the operator. Adds display/fbcon/getty/console checks to the B8F snapshot.
K=$1; MODE=ram; [ -n "$K" ] || { echo "usage: $0 K"; exit 2; }
cd ~/doc/modem/jz08-aurora; O=logs/b10/b10b3/cand$K; mkdir -p $O; IMG=b10/b10b3/out/aurora-b10b3.img
A=$O/host-actions.txt; act() { echo "$(date -u +%H:%M:%S.%3N) $*" | tee -a $A; }
tn() { { sleep 1; sed "s/\$/\r/" "$1"; sleep $2; } | ncat 172.16.42.1 23 | tr -d "\000\r"; }
OLD=$(ps -eo pid,cmd | grep "[u]artlog.py /dev/ttyUSB0" | awk '{print $1}'); [ -n "$OLD" ] && kill $OLD; sleep 1
U=logs/uart/b10b3cand-$MODE$K-$(date +%Y%m%d-%H%M%S); setsid nohup python3 tools/uartlog.py /dev/ttyUSB0 $U > $U.stderr 2>&1 < /dev/null &
if [ $MODE = ram ]; then
echo "b7dc34e92148613fd7292ec21209eb7ecd7a96b721b85ab42d374ce5f40d8f84 $IMG" | sha256sum -c || exit 1
act "B10B3CAND $MODE$K: waiting for fastboot <EMMC_SERIAL> (power off >= 90 s, then RESET held + battery -> USB)"
if fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; then act "already in fastboot - wait for power-off"; until ! fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do sleep 1; done; fi
i=0; until fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do i=$((i+1)); [ $i -ge 1800 ] && { act "ABORT: no fastboot"; exit 1; }; sleep 2; done
act "fastboot present"; { fastboot boot $IMG 2>&1; echo "rc=$?"; } | tee -a $A
else
act "B10B3CAND $MODE$K: waiting for the board to go away (power off >= 90 s), then normal power-on WITHOUT RESET"
until ! ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do sleep 1; done; act "board unreachable (powered off)"
until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL> && { act "ABORT: board is in fastboot - RESET was held?"; exit 1; }; sleep 1; done
fi
i=0; until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do i=$((i+1)); [ $i -ge 180 ] && { act "ABORT: NCM not up"; cp $U.log $O/uart.log; exit 1; }; sleep 1; done; act "NCM ping ok"
R=$(grep -a "rtc-pm8xxx.*setting system clock" $U.log | tail -1 | sed -n 's/.*(\([0-9]*\)).*/\1/p'); C=B; [ -n "$R" ] && [ "$R" -lt 40 ] && C=A; act "RTC at boot ${R:-?} s -> class $C"
printf 'cat /proc/device-tree/model; echo; uname -r; grep -E "START OK|FAIL in|rollback" /run/aurora-modem/lifecycle.log | tail -1\n' > $O/.w
i=0; until tn $O/.w 3 | grep -qE "^\[[0-9.]+\] .*(=== START OK|FAIL in|rollback)"; do i=$((i+1)); [ $i -ge 80 ] && { act "no START OK/FAIL after ~12 min"; break; }; sleep 6; done
tn $O/.w 3 | grep -aE "Aurora|aurora-b8|START OK|FAIL" | tee -a $A
printf 'grep -E "AP ENABLED|FAIL" /run/aurora-wifi/wifi.log | tail -1\n' > $O/.a
i=0; until tn $O/.a 3 | grep -qE "^\[[0-9.]+\] (=== AP ENABLED|FAIL)"; do i=$((i+1)); [ $i -ge 20 ] && { act "no AP ENABLED/FAIL after ~3 min"; break; }; sleep 6; done
act "wifi: $(tn $O/.a 3 | grep -E '^\[[0-9.]+\] (=== AP ENABLED|FAIL)' | tail -1)"
printf 'grep -E "SNTP (check|STEP|: )" /run/aurora-modem/lifecycle.log | tail -2\n' > $O/.s
i=0; until tn $O/.s 3 | grep -qE "^\[[0-9.]+\] SNTP"; do i=$((i+1)); [ $i -ge 15 ] && break; sleep 4; done; act "sntp: $(tn $O/.s 3 | grep -E '^\[[0-9.]+\] SNTP' | tail -2 | tr '\n' ' ')"
cat > $O/.c <<'C'
echo SNAP-BEGIN; cat /proc/uptime; date -u; cat /proc/device-tree/model; echo; uname -a; cat /proc/cmdline
echo ---time; cat /run/aurora-modem/time-set; grep -E "TIME|SNTP" /run/aurora-modem/lifecycle.log | tail -4
echo ---modem; /etc/init.d/aurora-modem status
echo ---wifi; /etc/init.d/aurora-wifi status; echo ---wifilog; cat /run/aurora-wifi/wifi.log; cat /run/aurora-wifi/service.log; echo ---hostapdlog; cat /run/aurora-wifi/hostapd.log
for r in /sys/class/remoteproc/*; do echo "RP $(cat $r/name)=$(cat $r/state)"; done; iw dev
echo ---dmesg-wifi; dmesg | grep -iE "wcn36xx|wcnss|a204000|cfg80211|aurora-wifi|crash|watchdog"
echo ---ping; ping -c4 -W3 -I wwan0 77.88.8.8 | tail -2
echo ---display; /etc/init.d/aurora-display status; cat /run/aurora-display/display.log; cat /run/aurora-display/service.log
echo ---consoles; cat /sys/class/tty/console/active; for v in /sys/class/vtconsole/vtcon*; do echo "$v $(cat $v/bind) $(cat $v/name)"; done; ls -l /proc/[0-9]*/fd/0 2>/dev/null | grep -E "ttyMSM0|tty1|console" | sed "s/.* \/proc/\/proc/"
echo ---getty; hostname; ps | grep -E "[g]etty|[c]ttyhack| sh$"
echo ---fb; ls -l /dev/dri/card0 /dev/fb0; for f in name bits_per_pixel virtual_size stride; do echo "fb0 $f=$(cat /sys/class/graphics/fb0/$f)"; done; cat /sys/class/drm/card0-SPI-1/enabled /sys/class/drm/card0-SPI-1/dpms
echo ---regs; for r in /sys/class/regulator/regulator.*; do n=$(cat $r/name); case $n in l6|l17) echo "$n $(cat $r/state) $(cat $r/microvolts) users=$(cat $r/num_users)";; esac; done
echo ---bl; for f in bl_power brightness actual_brightness; do echo "bl $f=$(cat /sys/class/backlight/backlight/$f)"; done
echo ---dmesg-display; dmesg | grep -iE "drm|panel|mipi|spi_qup|78b8000|fbcon|Console: |frame buffer|backlight|aurora-display|l17"
echo ---display-errors; dmesg | grep -iE "drm|panel|mipi|spi0|fbcon|backlight|aurora-display" | grep -ciE "err|fail|timeout|warn"
echo ---iio; for d in /sys/bus/iio/devices/iio:device*; do echo "$d name=$(cat $d/name)"; ls $d | tr '\n' ' '; echo; done
for f in /sys/bus/iio/devices/iio:device*/in_*; do case $f in *_raw|*_input|*_scale|*_offset) echo "$f=$(cat $f 2>&1)";; esac; done
echo ---psy; ls -l /sys/class/power_supply/; for p in /sys/class/power_supply/*; do echo "-- $p"; cat $p/uevent; ls $p; done
echo ---dmesg-bms; dmesg | grep -iE "bms|battery|power_supply|lbc|charger|extcon|ci_hdrc|4000|1000"
echo ---lbc-state; grep -q " /sys/kernel/debug " /proc/mounts || mount -t debugfs debugfs /sys/kernel/debug; cat /sys/kernel/debug/pm8916_lbc/state; dmesg | grep -E "safety timer|supervisor|pm8916-lbc|lbc"
echo ---thermal; for t in /sys/class/thermal/thermal_zone*; do echo "$t $(cat $t/type) $(cat $t/temp)"; done
echo ---dmesg-adc; dmesg | grep -iE "vadc|iio|temp-alarm|qpnp|spmi-temp|pm8916-thermal|thermal"
echo ---emmc; awk "{print \"w=\"\$5\" s=\"\$7}" /sys/block/mmcblk0/stat
echo SNAP-END
C
tn $O/.c 25 > $O/snapshot.txt; act "snapshot: $(grep -c SNAP-END $O/snapshot.txt) end markers; $(grep -E '^RP a204' $O/snapshot.txt)"
printf 'dmesg > /tmp/dm.txt; nc -l -p 9881 < /tmp/dm.txt &\n' > $O/.d; tn $O/.d 3 >/dev/null; sleep 1; ncat --recv-only 172.16.42.1 9881 > $O/dmesg.full
cp $U.log $O/uart.log; act "B10B3CAND $MODE$K END - operator visual check next"

View file

@ -1,60 +0,0 @@
#!/bin/sh
# 480s side, B10B-3 Test D (TEST image) boot K (RAM only). RESET-held power-on -> lk1st fastboot -> `fastboot boot` B10B-3 RAM image. Reads only over telnet.
# MODE=cold: normal power-on (no RESET, no fastboot) -> lk2nd extlinux from eMMC cache. Script only observes + reads over telnet;
# nothing is written to eMMC. Visual display checks need the operator. Adds display/fbcon/getty/console checks to the B8F snapshot.
K=$1; MODE=ram; [ -n "$K" ] || { echo "usage: $0 K"; exit 2; }
cd ~/doc/modem/jz08-aurora; O=logs/b10/b10b3/d$K; mkdir -p $O; IMG=b10/b10b3/out-d/aurora-b10b3d.img
A=$O/host-actions.txt; act() { echo "$(date -u +%H:%M:%S.%3N) $*" | tee -a $A; }
tn() { { sleep 1; sed "s/\$/\r/" "$1"; sleep $2; } | ncat 172.16.42.1 23 | tr -d "\000\r"; }
OLD=$(ps -eo pid,cmd | grep "[u]artlog.py /dev/ttyUSB0" | awk '{print $1}'); [ -n "$OLD" ] && kill $OLD; sleep 1
U=logs/uart/b10b3d-$MODE$K-$(date +%Y%m%d-%H%M%S); setsid nohup python3 tools/uartlog.py /dev/ttyUSB0 $U > $U.stderr 2>&1 < /dev/null &
if [ $MODE = ram ]; then
echo "43739e5565e7d2dc14d6249b098130dd3094c2748dd07a4a2373394c0241b897 $IMG" | sha256sum -c || exit 1
act "B10B3D $MODE$K: waiting for fastboot <EMMC_SERIAL> (power off >= 90 s, then RESET held + battery -> USB)"
if fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; then act "already in fastboot - wait for power-off"; until ! fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do sleep 1; done; fi
i=0; until fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do i=$((i+1)); [ $i -ge 1800 ] && { act "ABORT: no fastboot"; exit 1; }; sleep 2; done
act "fastboot present"; { fastboot boot $IMG 2>&1; echo "rc=$?"; } | tee -a $A
else
act "B10B3D $MODE$K: waiting for the board to go away (power off >= 90 s), then normal power-on WITHOUT RESET"
until ! ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do sleep 1; done; act "board unreachable (powered off)"
until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL> && { act "ABORT: board is in fastboot - RESET was held?"; exit 1; }; sleep 1; done
fi
i=0; until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do i=$((i+1)); [ $i -ge 180 ] && { act "ABORT: NCM not up"; cp $U.log $O/uart.log; exit 1; }; sleep 1; done; act "NCM ping ok"
R=$(grep -a "rtc-pm8xxx.*setting system clock" $U.log | tail -1 | sed -n 's/.*(\([0-9]*\)).*/\1/p'); C=B; [ -n "$R" ] && [ "$R" -lt 40 ] && C=A; act "RTC at boot ${R:-?} s -> class $C"
printf 'cat /proc/device-tree/model; echo; uname -r; grep -E "START OK|FAIL in|rollback" /run/aurora-modem/lifecycle.log | tail -1\n' > $O/.w
i=0; until tn $O/.w 3 | grep -qE "^\[[0-9.]+\] .*(=== START OK|FAIL in|rollback)"; do i=$((i+1)); [ $i -ge 80 ] && { act "no START OK/FAIL after ~12 min"; break; }; sleep 6; done
tn $O/.w 3 | grep -aE "Aurora|aurora-b8|START OK|FAIL" | tee -a $A
printf 'grep -E "AP ENABLED|FAIL" /run/aurora-wifi/wifi.log | tail -1\n' > $O/.a
i=0; until tn $O/.a 3 | grep -qE "^\[[0-9.]+\] (=== AP ENABLED|FAIL)"; do i=$((i+1)); [ $i -ge 20 ] && { act "no AP ENABLED/FAIL after ~3 min"; break; }; sleep 6; done
act "wifi: $(tn $O/.a 3 | grep -E '^\[[0-9.]+\] (=== AP ENABLED|FAIL)' | tail -1)"
printf 'grep -E "SNTP (check|STEP|: )" /run/aurora-modem/lifecycle.log | tail -2\n' > $O/.s
i=0; until tn $O/.s 3 | grep -qE "^\[[0-9.]+\] SNTP"; do i=$((i+1)); [ $i -ge 15 ] && break; sleep 4; done; act "sntp: $(tn $O/.s 3 | grep -E '^\[[0-9.]+\] SNTP' | tail -2 | tr '\n' ' ')"
cat > $O/.c <<'C'
echo SNAP-BEGIN; cat /proc/uptime; date -u; cat /proc/device-tree/model; echo; uname -a; cat /proc/cmdline
echo ---time; cat /run/aurora-modem/time-set; grep -E "TIME|SNTP" /run/aurora-modem/lifecycle.log | tail -4
echo ---modem; /etc/init.d/aurora-modem status
echo ---wifi; /etc/init.d/aurora-wifi status; echo ---wifilog; cat /run/aurora-wifi/wifi.log; cat /run/aurora-wifi/service.log; echo ---hostapdlog; cat /run/aurora-wifi/hostapd.log
for r in /sys/class/remoteproc/*; do echo "RP $(cat $r/name)=$(cat $r/state)"; done; iw dev
echo ---dmesg-wifi; dmesg | grep -iE "wcn36xx|wcnss|a204000|cfg80211|aurora-wifi|crash|watchdog"
echo ---ping; ping -c4 -W3 -I wwan0 77.88.8.8 | tail -2
echo ---display; /etc/init.d/aurora-display status; cat /run/aurora-display/display.log; cat /run/aurora-display/service.log
echo ---consoles; cat /sys/class/tty/console/active; for v in /sys/class/vtconsole/vtcon*; do echo "$v $(cat $v/bind) $(cat $v/name)"; done; ls -l /proc/[0-9]*/fd/0 2>/dev/null | grep -E "ttyMSM0|tty1|console" | sed "s/.* \/proc/\/proc/"
echo ---getty; hostname; ps | grep -E "[g]etty|[c]ttyhack| sh$"
echo ---fb; ls -l /dev/dri/card0 /dev/fb0; for f in name bits_per_pixel virtual_size stride; do echo "fb0 $f=$(cat /sys/class/graphics/fb0/$f)"; done; cat /sys/class/drm/card0-SPI-1/enabled /sys/class/drm/card0-SPI-1/dpms
echo ---regs; for r in /sys/class/regulator/regulator.*; do n=$(cat $r/name); case $n in l6|l17) echo "$n $(cat $r/state) $(cat $r/microvolts) users=$(cat $r/num_users)";; esac; done
echo ---bl; for f in bl_power brightness actual_brightness; do echo "bl $f=$(cat /sys/class/backlight/backlight/$f)"; done
echo ---dmesg-display; dmesg | grep -iE "drm|panel|mipi|spi_qup|78b8000|fbcon|Console: |frame buffer|backlight|aurora-display|l17"
echo ---display-errors; dmesg | grep -iE "drm|panel|mipi|spi0|fbcon|backlight|aurora-display" | grep -ciE "err|fail|timeout|warn"
echo ---iio; for d in /sys/bus/iio/devices/iio:device*; do echo "$d name=$(cat $d/name)"; ls $d | tr '\n' ' '; echo; done
for f in /sys/bus/iio/devices/iio:device*/in_*; do case $f in *_raw|*_input|*_scale|*_offset) echo "$f=$(cat $f 2>&1)";; esac; done
echo ---psy; ls -l /sys/class/power_supply/; for p in /sys/class/power_supply/*; do echo "-- $p"; cat $p/uevent; ls $p; done
echo ---dmesg-bms; dmesg | grep -iE "bms|battery|power_supply|lbc|charger|extcon|ci_hdrc|4000|1000"
echo ---lbc-state; grep -q " /sys/kernel/debug " /proc/mounts || mount -t debugfs debugfs /sys/kernel/debug; cat /sys/kernel/debug/pm8916_lbc/state; dmesg | grep -E "safety timer|supervisor|pm8916-lbc|lbc"
echo ---thermal; for t in /sys/class/thermal/thermal_zone*; do echo "$t $(cat $t/type) $(cat $t/temp)"; done
echo ---dmesg-adc; dmesg | grep -iE "vadc|iio|temp-alarm|qpnp|spmi-temp|pm8916-thermal|thermal"
echo ---emmc; awk "{print \"w=\"\$5\" s=\"\$7}" /sys/block/mmcblk0/stat
echo SNAP-END
C
tn $O/.c 25 > $O/snapshot.txt; act "snapshot: $(grep -c SNAP-END $O/snapshot.txt) end markers; $(grep -E '^RP a204' $O/snapshot.txt)"
printf 'dmesg > /tmp/dm.txt; nc -l -p 9881 < /tmp/dm.txt &\n' > $O/.d; tn $O/.d 3 >/dev/null; sleep 1; ncat --recv-only 172.16.42.1 9881 > $O/dmesg.full
cp $U.log $O/uart.log; act "B10B3D $MODE$K END - operator visual check next"

View file

@ -1,14 +0,0 @@
#!/bin/sh
# 480s side, Test D: wait for the NEW boot's NCM, then at once push b10b3-mon.sh to the board and start it (5 s, EVDD=04/00, VMAX 4.15 V),
# then start the 30-s pull into logs/b10/b10b3/<K>-mon.txt. Board side reads only (writes /tmp only). usage: b10b3b-mon-start.sh K
K=$1; [ -n "$K" ] || { echo "usage: $0 K"; exit 2; }
cd ~/doc/modem/jz08-aurora; A=logs/b10/b10b3/$K-actions.txt; act() { echo "$(date -u +%H:%M:%S.%3N) $*" | tee -a $A; }
rm -f logs/b10/b10b3/pull.stop
act "mon-start $K: waiting for the board to go away (warm reboot)"; until ! ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do sleep 0.5; done; act "board gone"
until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do sleep 0.5; done; act "NCM up"
i=0; until { sleep 1; printf 'nc -l -p 9943 > /tmp/b10b3-mon.sh &\r\n'; sleep 1; } | ncat -w 4 172.16.42.1 23 >/dev/null 2>&1; do i=$((i+1)); [ $i -ge 60 ] && { act "ABORT: no telnet"; exit 1; }; sleep 1; done
sleep 1; ncat --send-only 172.16.42.1 9943 < b10/b10b3/b10b3-mon.sh; sleep 1
sh b10/b10b3/b10b3-cmd.sh 3 'md5sum /tmp/b10b3-mon.sh; rm -f /tmp/b10b3-mon.stop; VMAX=4150000 EVDD=04 EVDD2=00 setsid sh /tmp/b10b3-mon.sh 5 > /dev/null 2>&1 < /dev/null & sleep 1; dmesg | grep -E "safety timer|supervisor"; cut -d" " -f1 /proc/uptime' | tee -a $A
act "local md5 $(md5sum < b10/b10b3/b10b3-mon.sh)"
setsid nohup sh b10/b10b3/b10b3-pull.sh $K > /dev/null 2>&1 < /dev/null &
act "monitor started (5 s), pull started -> logs/b10/b10b3/$K-mon.txt"

View file

@ -1,60 +0,0 @@
#!/bin/sh
# 480s side, B10B-3 Test D3 (TEST image) boot K (RAM only). RESET-held power-on -> lk1st fastboot -> `fastboot boot` B10B-3 RAM image. Reads only over telnet.
# MODE=cold: normal power-on (no RESET, no fastboot) -> lk2nd extlinux from eMMC cache. Script only observes + reads over telnet;
# nothing is written to eMMC. Visual display checks need the operator. Adds display/fbcon/getty/console checks to the B8F snapshot.
K=$1; MODE=ram; [ -n "$K" ] || { echo "usage: $0 K"; exit 2; }
cd ~/doc/modem/jz08-aurora; O=logs/b10/b10b3/d3r$K; mkdir -p $O; IMG=b10/b10b3/out-d3/aurora-b10b3d3.img
A=$O/host-actions.txt; act() { echo "$(date -u +%H:%M:%S.%3N) $*" | tee -a $A; }
tn() { { sleep 1; sed "s/\$/\r/" "$1"; sleep $2; } | ncat 172.16.42.1 23 | tr -d "\000\r"; }
OLD=$(ps -eo pid,cmd | grep "[u]artlog.py /dev/ttyUSB0" | awk '{print $1}'); [ -n "$OLD" ] && kill $OLD; sleep 1
U=logs/uart/b10b3d3-$MODE$K-$(date +%Y%m%d-%H%M%S); setsid nohup python3 tools/uartlog.py /dev/ttyUSB0 $U > $U.stderr 2>&1 < /dev/null &
if [ $MODE = ram ]; then
echo "4645a7ec012e4c83af4f496ce03431024a758c64c679da45f7b6445edef777f9 $IMG" | sha256sum -c || exit 1
act "B10B3D3 $MODE$K: waiting for fastboot <EMMC_SERIAL> (power off >= 90 s, then RESET held + battery -> USB)"
if fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; then act "already in fastboot - wait for power-off"; until ! fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do sleep 1; done; fi
i=0; until fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do i=$((i+1)); [ $i -ge 1800 ] && { act "ABORT: no fastboot"; exit 1; }; sleep 2; done
act "fastboot present"; { fastboot boot $IMG 2>&1; echo "rc=$?"; } | tee -a $A
else
act "B10B3D3 $MODE$K: waiting for the board to go away (power off >= 90 s), then normal power-on WITHOUT RESET"
until ! ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do sleep 1; done; act "board unreachable (powered off)"
until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL> && { act "ABORT: board is in fastboot - RESET was held?"; exit 1; }; sleep 1; done
fi
i=0; until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do i=$((i+1)); [ $i -ge 180 ] && { act "ABORT: NCM not up"; cp $U.log $O/uart.log; exit 1; }; sleep 1; done; act "NCM ping ok"
R=$(grep -a "rtc-pm8xxx.*setting system clock" $U.log | tail -1 | sed -n 's/.*(\([0-9]*\)).*/\1/p'); C=B; [ -n "$R" ] && [ "$R" -lt 40 ] && C=A; act "RTC at boot ${R:-?} s -> class $C"
printf 'cat /proc/device-tree/model; echo; uname -r; grep -E "START OK|FAIL in|rollback" /run/aurora-modem/lifecycle.log | tail -1\n' > $O/.w
i=0; until tn $O/.w 3 | grep -qE "^\[[0-9.]+\] .*(=== START OK|FAIL in|rollback)"; do i=$((i+1)); [ $i -ge 80 ] && { act "no START OK/FAIL after ~12 min"; break; }; sleep 6; done
tn $O/.w 3 | grep -aE "Aurora|aurora-b8|START OK|FAIL" | tee -a $A
printf 'grep -E "AP ENABLED|FAIL" /run/aurora-wifi/wifi.log | tail -1\n' > $O/.a
i=0; until tn $O/.a 3 | grep -qE "^\[[0-9.]+\] (=== AP ENABLED|FAIL)"; do i=$((i+1)); [ $i -ge 20 ] && { act "no AP ENABLED/FAIL after ~3 min"; break; }; sleep 6; done
act "wifi: $(tn $O/.a 3 | grep -E '^\[[0-9.]+\] (=== AP ENABLED|FAIL)' | tail -1)"
printf 'grep -E "SNTP (check|STEP|: )" /run/aurora-modem/lifecycle.log | tail -2\n' > $O/.s
i=0; until tn $O/.s 3 | grep -qE "^\[[0-9.]+\] SNTP"; do i=$((i+1)); [ $i -ge 15 ] && break; sleep 4; done; act "sntp: $(tn $O/.s 3 | grep -E '^\[[0-9.]+\] SNTP' | tail -2 | tr '\n' ' ')"
cat > $O/.c <<'C'
echo SNAP-BEGIN; cat /proc/uptime; date -u; cat /proc/device-tree/model; echo; uname -a; cat /proc/cmdline
echo ---time; cat /run/aurora-modem/time-set; grep -E "TIME|SNTP" /run/aurora-modem/lifecycle.log | tail -4
echo ---modem; /etc/init.d/aurora-modem status
echo ---wifi; /etc/init.d/aurora-wifi status; echo ---wifilog; cat /run/aurora-wifi/wifi.log; cat /run/aurora-wifi/service.log; echo ---hostapdlog; cat /run/aurora-wifi/hostapd.log
for r in /sys/class/remoteproc/*; do echo "RP $(cat $r/name)=$(cat $r/state)"; done; iw dev
echo ---dmesg-wifi; dmesg | grep -iE "wcn36xx|wcnss|a204000|cfg80211|aurora-wifi|crash|watchdog"
echo ---ping; ping -c4 -W3 -I wwan0 77.88.8.8 | tail -2
echo ---display; /etc/init.d/aurora-display status; cat /run/aurora-display/display.log; cat /run/aurora-display/service.log
echo ---consoles; cat /sys/class/tty/console/active; for v in /sys/class/vtconsole/vtcon*; do echo "$v $(cat $v/bind) $(cat $v/name)"; done; ls -l /proc/[0-9]*/fd/0 2>/dev/null | grep -E "ttyMSM0|tty1|console" | sed "s/.* \/proc/\/proc/"
echo ---getty; hostname; ps | grep -E "[g]etty|[c]ttyhack| sh$"
echo ---fb; ls -l /dev/dri/card0 /dev/fb0; for f in name bits_per_pixel virtual_size stride; do echo "fb0 $f=$(cat /sys/class/graphics/fb0/$f)"; done; cat /sys/class/drm/card0-SPI-1/enabled /sys/class/drm/card0-SPI-1/dpms
echo ---regs; for r in /sys/class/regulator/regulator.*; do n=$(cat $r/name); case $n in l6|l17) echo "$n $(cat $r/state) $(cat $r/microvolts) users=$(cat $r/num_users)";; esac; done
echo ---bl; for f in bl_power brightness actual_brightness; do echo "bl $f=$(cat /sys/class/backlight/backlight/$f)"; done
echo ---dmesg-display; dmesg | grep -iE "drm|panel|mipi|spi_qup|78b8000|fbcon|Console: |frame buffer|backlight|aurora-display|l17"
echo ---display-errors; dmesg | grep -iE "drm|panel|mipi|spi0|fbcon|backlight|aurora-display" | grep -ciE "err|fail|timeout|warn"
echo ---iio; for d in /sys/bus/iio/devices/iio:device*; do echo "$d name=$(cat $d/name)"; ls $d | tr '\n' ' '; echo; done
for f in /sys/bus/iio/devices/iio:device*/in_*; do case $f in *_raw|*_input|*_scale|*_offset) echo "$f=$(cat $f 2>&1)";; esac; done
echo ---psy; ls -l /sys/class/power_supply/; for p in /sys/class/power_supply/*; do echo "-- $p"; cat $p/uevent; ls $p; done
echo ---dmesg-bms; dmesg | grep -iE "bms|battery|power_supply|lbc|charger|extcon|ci_hdrc|4000|1000"
echo ---lbc-state; grep -q " /sys/kernel/debug " /proc/mounts || mount -t debugfs debugfs /sys/kernel/debug; cat /sys/kernel/debug/pm8916_lbc/state; dmesg | grep -E "safety timer|supervisor|pm8916-lbc|lbc"
echo ---thermal; for t in /sys/class/thermal/thermal_zone*; do echo "$t $(cat $t/type) $(cat $t/temp)"; done
echo ---dmesg-adc; dmesg | grep -iE "vadc|iio|temp-alarm|qpnp|spmi-temp|pm8916-thermal|thermal"
echo ---emmc; awk "{print \"w=\"\$5\" s=\"\$7}" /sys/block/mmcblk0/stat
echo SNAP-END
C
tn $O/.c 25 > $O/snapshot.txt; act "snapshot: $(grep -c SNAP-END $O/snapshot.txt) end markers; $(grep -E '^RP a204' $O/snapshot.txt)"
printf 'dmesg > /tmp/dm.txt; nc -l -p 9881 < /tmp/dm.txt &\n' > $O/.d; tn $O/.d 3 >/dev/null; sleep 1; ncat --recv-only 172.16.42.1 9881 > $O/dmesg.full
cp $U.log $O/uart.log; act "B10B3D3 $MODE$K END - operator visual check next"

View file

@ -1,60 +0,0 @@
#!/bin/sh
# 480s side, B10B-3 production-profile (TEST image) boot K (RAM only). RESET-held power-on -> lk1st fastboot -> `fastboot boot` B10B-3 RAM image. Reads only over telnet.
# MODE=cold: normal power-on (no RESET, no fastboot) -> lk2nd extlinux from eMMC cache. Script only observes + reads over telnet;
# nothing is written to eMMC. Visual display checks need the operator. Adds display/fbcon/getty/console checks to the B8F snapshot.
K=$1; MODE=ram; [ -n "$K" ] || { echo "usage: $0 K"; exit 2; }
cd ~/doc/modem/jz08-aurora; O=logs/b10/b10b3/p$K; mkdir -p $O; IMG=b10/b10b3/out-p/aurora-b10b3p.img
A=$O/host-actions.txt; act() { echo "$(date -u +%H:%M:%S.%3N) $*" | tee -a $A; }
tn() { { sleep 1; sed "s/\$/\r/" "$1"; sleep $2; } | ncat 172.16.42.1 23 | tr -d "\000\r"; }
OLD=$(ps -eo pid,cmd | grep "[u]artlog.py /dev/ttyUSB0" | awk '{print $1}'); [ -n "$OLD" ] && kill $OLD; sleep 1
U=logs/uart/b10b3p-$MODE$K-$(date +%Y%m%d-%H%M%S); setsid nohup python3 tools/uartlog.py /dev/ttyUSB0 $U > $U.stderr 2>&1 < /dev/null &
if [ $MODE = ram ]; then
echo "8bcd613e029b9b72a2105e1aaf93572601345871c6917b178cd5fd462816e8aa $IMG" | sha256sum -c || exit 1
act "B10B3P $MODE$K: waiting for fastboot <EMMC_SERIAL> (power off >= 90 s, then RESET held + battery -> USB)"
if fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; then act "already in fastboot - wait for power-off"; until ! fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do sleep 1; done; fi
i=0; until fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do i=$((i+1)); [ $i -ge 1800 ] && { act "ABORT: no fastboot"; exit 1; }; sleep 2; done
act "fastboot present"; { fastboot boot $IMG 2>&1; echo "rc=$?"; } | tee -a $A
else
act "B10B3P $MODE$K: waiting for the board to go away (power off >= 90 s), then normal power-on WITHOUT RESET"
until ! ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do sleep 1; done; act "board unreachable (powered off)"
until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL> && { act "ABORT: board is in fastboot - RESET was held?"; exit 1; }; sleep 1; done
fi
i=0; until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do i=$((i+1)); [ $i -ge 180 ] && { act "ABORT: NCM not up"; cp $U.log $O/uart.log; exit 1; }; sleep 1; done; act "NCM ping ok"
R=$(grep -a "rtc-pm8xxx.*setting system clock" $U.log | tail -1 | sed -n 's/.*(\([0-9]*\)).*/\1/p'); C=B; [ -n "$R" ] && [ "$R" -lt 40 ] && C=A; act "RTC at boot ${R:-?} s -> class $C"
printf 'cat /proc/device-tree/model; echo; uname -r; grep -E "START OK|FAIL in|rollback" /run/aurora-modem/lifecycle.log | tail -1\n' > $O/.w
i=0; until tn $O/.w 3 | grep -qE "^\[[0-9.]+\] .*(=== START OK|FAIL in|rollback)"; do i=$((i+1)); [ $i -ge 80 ] && { act "no START OK/FAIL after ~12 min"; break; }; sleep 6; done
tn $O/.w 3 | grep -aE "Aurora|aurora-b8|START OK|FAIL" | tee -a $A
printf 'grep -E "AP ENABLED|FAIL" /run/aurora-wifi/wifi.log | tail -1\n' > $O/.a
i=0; until tn $O/.a 3 | grep -qE "^\[[0-9.]+\] (=== AP ENABLED|FAIL)"; do i=$((i+1)); [ $i -ge 20 ] && { act "no AP ENABLED/FAIL after ~3 min"; break; }; sleep 6; done
act "wifi: $(tn $O/.a 3 | grep -E '^\[[0-9.]+\] (=== AP ENABLED|FAIL)' | tail -1)"
printf 'grep -E "SNTP (check|STEP|: )" /run/aurora-modem/lifecycle.log | tail -2\n' > $O/.s
i=0; until tn $O/.s 3 | grep -qE "^\[[0-9.]+\] SNTP"; do i=$((i+1)); [ $i -ge 15 ] && break; sleep 4; done; act "sntp: $(tn $O/.s 3 | grep -E '^\[[0-9.]+\] SNTP' | tail -2 | tr '\n' ' ')"
cat > $O/.c <<'C'
echo SNAP-BEGIN; cat /proc/uptime; date -u; cat /proc/device-tree/model; echo; uname -a; cat /proc/cmdline
echo ---time; cat /run/aurora-modem/time-set; grep -E "TIME|SNTP" /run/aurora-modem/lifecycle.log | tail -4
echo ---modem; /etc/init.d/aurora-modem status
echo ---wifi; /etc/init.d/aurora-wifi status; echo ---wifilog; cat /run/aurora-wifi/wifi.log; cat /run/aurora-wifi/service.log; echo ---hostapdlog; cat /run/aurora-wifi/hostapd.log
for r in /sys/class/remoteproc/*; do echo "RP $(cat $r/name)=$(cat $r/state)"; done; iw dev
echo ---dmesg-wifi; dmesg | grep -iE "wcn36xx|wcnss|a204000|cfg80211|aurora-wifi|crash|watchdog"
echo ---ping; ping -c4 -W3 -I wwan0 77.88.8.8 | tail -2
echo ---display; /etc/init.d/aurora-display status; cat /run/aurora-display/display.log; cat /run/aurora-display/service.log
echo ---consoles; cat /sys/class/tty/console/active; for v in /sys/class/vtconsole/vtcon*; do echo "$v $(cat $v/bind) $(cat $v/name)"; done; ls -l /proc/[0-9]*/fd/0 2>/dev/null | grep -E "ttyMSM0|tty1|console" | sed "s/.* \/proc/\/proc/"
echo ---getty; hostname; ps | grep -E "[g]etty|[c]ttyhack| sh$"
echo ---fb; ls -l /dev/dri/card0 /dev/fb0; for f in name bits_per_pixel virtual_size stride; do echo "fb0 $f=$(cat /sys/class/graphics/fb0/$f)"; done; cat /sys/class/drm/card0-SPI-1/enabled /sys/class/drm/card0-SPI-1/dpms
echo ---regs; for r in /sys/class/regulator/regulator.*; do n=$(cat $r/name); case $n in l6|l17) echo "$n $(cat $r/state) $(cat $r/microvolts) users=$(cat $r/num_users)";; esac; done
echo ---bl; for f in bl_power brightness actual_brightness; do echo "bl $f=$(cat /sys/class/backlight/backlight/$f)"; done
echo ---dmesg-display; dmesg | grep -iE "drm|panel|mipi|spi_qup|78b8000|fbcon|Console: |frame buffer|backlight|aurora-display|l17"
echo ---display-errors; dmesg | grep -iE "drm|panel|mipi|spi0|fbcon|backlight|aurora-display" | grep -ciE "err|fail|timeout|warn"
echo ---iio; for d in /sys/bus/iio/devices/iio:device*; do echo "$d name=$(cat $d/name)"; ls $d | tr '\n' ' '; echo; done
for f in /sys/bus/iio/devices/iio:device*/in_*; do case $f in *_raw|*_input|*_scale|*_offset) echo "$f=$(cat $f 2>&1)";; esac; done
echo ---psy; ls -l /sys/class/power_supply/; for p in /sys/class/power_supply/*; do echo "-- $p"; cat $p/uevent; ls $p; done
echo ---dmesg-bms; dmesg | grep -iE "bms|battery|power_supply|lbc|charger|extcon|ci_hdrc|4000|1000"
echo ---lbc-state; grep -q " /sys/kernel/debug " /proc/mounts || mount -t debugfs debugfs /sys/kernel/debug; cat /sys/kernel/debug/pm8916_lbc/state; dmesg | grep -E "safety timer|supervisor|pm8916-lbc|lbc"
echo ---thermal; for t in /sys/class/thermal/thermal_zone*; do echo "$t $(cat $t/type) $(cat $t/temp)"; done
echo ---dmesg-adc; dmesg | grep -iE "vadc|iio|temp-alarm|qpnp|spmi-temp|pm8916-thermal|thermal"
echo ---emmc; awk "{print \"w=\"\$5\" s=\"\$7}" /sys/block/mmcblk0/stat
echo SNAP-END
C
tn $O/.c 25 > $O/snapshot.txt; act "snapshot: $(grep -c SNAP-END $O/snapshot.txt) end markers; $(grep -E '^RP a204' $O/snapshot.txt)"
printf 'dmesg > /tmp/dm.txt; nc -l -p 9881 < /tmp/dm.txt &\n' > $O/.d; tn $O/.d 3 >/dev/null; sleep 1; ncat --recv-only 172.16.42.1 9881 > $O/dmesg.full
cp $U.log $O/uart.log; act "B10B3P $MODE$K END - operator visual check next"

View file

@ -1,14 +0,0 @@
#!/bin/sh
# 480s side, production-profile run: wait for the NEW boot's NCM, then at once push b10b3-mon.sh to the board and start it (5 s, EVDD=08/02, VMAX 4.23 V),
# then start the 30-s pull into logs/b10/b10b3/<K>-mon.txt. Board side reads only (writes /tmp only). usage: b10b3b-mon-start.sh K
K=$1; [ -n "$K" ] || { echo "usage: $0 K"; exit 2; }
cd ~/doc/modem/jz08-aurora; A=logs/b10/b10b3/$K-actions.txt; act() { echo "$(date -u +%H:%M:%S.%3N) $*" | tee -a $A; }
rm -f logs/b10/b10b3/pull.stop
act "mon-start $K: waiting for lk1st fastboot (RESET-held reboot), then for the new boot"; until fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do sleep 1; done; act "fastboot seen"; until ! fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do sleep 1; done; act "fastboot gone (booting)"
until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do sleep 0.5; done; act "NCM up"
i=0; until { sleep 1; printf 'nc -l -p 9981 > /tmp/b10b3-mon.sh &\r\n'; sleep 1; } | ncat -w 4 172.16.42.1 23 >/dev/null 2>&1; do i=$((i+1)); [ $i -ge 60 ] && { act "ABORT: no telnet"; exit 1; }; sleep 1; done
sleep 1; ncat --send-only 172.16.42.1 9981 < b10/b10b3/b10b3-mon.sh; sleep 1
sh b10/b10b3/b10b3-cmd.sh 3 'md5sum /tmp/b10b3-mon.sh; rm -f /tmp/b10b3-mon.stop; VMAX=4230000 EVDD=08 EVDD2=02 setsid sh /tmp/b10b3-mon.sh 30 > /dev/null 2>&1 < /dev/null & sleep 1; dmesg | grep -E "safety timer|supervisor"; cut -d" " -f1 /proc/uptime' | tee -a $A
act "local md5 $(md5sum < b10/b10b3/b10b3-mon.sh)"
setsid nohup sh b10/b10b3/b10b3-pull.sh $K > /dev/null 2>&1 < /dev/null &
act "monitor started (30 s), pull started -> logs/b10/b10b3/$K-mon.txt"

View file

@ -1,60 +0,0 @@
#!/bin/sh
# 480s side, B10B-3T (TEST image) boot K (RAM only). RESET-held power-on -> lk1st fastboot -> `fastboot boot` B10B-3 RAM image. Reads only over telnet.
# MODE=cold: normal power-on (no RESET, no fastboot) -> lk2nd extlinux from eMMC cache. Script only observes + reads over telnet;
# nothing is written to eMMC. Visual display checks need the operator. Adds display/fbcon/getty/console checks to the B8F snapshot.
K=$1; MODE=ram; [ -n "$K" ] || { echo "usage: $0 K"; exit 2; }
cd ~/doc/modem/jz08-aurora; O=logs/b10/b10b3/t$K; mkdir -p $O; IMG=b10/b10b3/out-t/aurora-b10b3t.img
A=$O/host-actions.txt; act() { echo "$(date -u +%H:%M:%S.%3N) $*" | tee -a $A; }
tn() { { sleep 1; sed "s/\$/\r/" "$1"; sleep $2; } | ncat 172.16.42.1 23 | tr -d "\000\r"; }
OLD=$(ps -eo pid,cmd | grep "[u]artlog.py /dev/ttyUSB0" | awk '{print $1}'); [ -n "$OLD" ] && kill $OLD; sleep 1
U=logs/uart/b10b3t-$MODE$K-$(date +%Y%m%d-%H%M%S); setsid nohup python3 tools/uartlog.py /dev/ttyUSB0 $U > $U.stderr 2>&1 < /dev/null &
if [ $MODE = ram ]; then
echo "dfe2fae69f0c64be85bc972e2e8502e9bef262fa5dbb5e77b3c76ed183a89f1f $IMG" | sha256sum -c || exit 1
act "B10B3 $MODE$K: waiting for fastboot <EMMC_SERIAL> (power off >= 90 s, then RESET held + battery -> USB)"
if fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; then act "already in fastboot - wait for power-off"; until ! fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do sleep 1; done; fi
i=0; until fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do i=$((i+1)); [ $i -ge 1800 ] && { act "ABORT: no fastboot"; exit 1; }; sleep 2; done
act "fastboot present"; { fastboot boot $IMG 2>&1; echo "rc=$?"; } | tee -a $A
else
act "B10B3 $MODE$K: waiting for the board to go away (power off >= 90 s), then normal power-on WITHOUT RESET"
until ! ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do sleep 1; done; act "board unreachable (powered off)"
until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL> && { act "ABORT: board is in fastboot - RESET was held?"; exit 1; }; sleep 1; done
fi
i=0; until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do i=$((i+1)); [ $i -ge 180 ] && { act "ABORT: NCM not up"; cp $U.log $O/uart.log; exit 1; }; sleep 1; done; act "NCM ping ok"
R=$(grep -a "rtc-pm8xxx.*setting system clock" $U.log | tail -1 | sed -n 's/.*(\([0-9]*\)).*/\1/p'); C=B; [ -n "$R" ] && [ "$R" -lt 40 ] && C=A; act "RTC at boot ${R:-?} s -> class $C"
printf 'cat /proc/device-tree/model; echo; uname -r; grep -E "START OK|FAIL in|rollback" /run/aurora-modem/lifecycle.log | tail -1\n' > $O/.w
i=0; until tn $O/.w 3 | grep -qE "^\[[0-9.]+\] .*(=== START OK|FAIL in|rollback)"; do i=$((i+1)); [ $i -ge 80 ] && { act "no START OK/FAIL after ~12 min"; break; }; sleep 6; done
tn $O/.w 3 | grep -aE "Aurora|aurora-b8|START OK|FAIL" | tee -a $A
printf 'grep -E "AP ENABLED|FAIL" /run/aurora-wifi/wifi.log | tail -1\n' > $O/.a
i=0; until tn $O/.a 3 | grep -qE "^\[[0-9.]+\] (=== AP ENABLED|FAIL)"; do i=$((i+1)); [ $i -ge 20 ] && { act "no AP ENABLED/FAIL after ~3 min"; break; }; sleep 6; done
act "wifi: $(tn $O/.a 3 | grep -E '^\[[0-9.]+\] (=== AP ENABLED|FAIL)' | tail -1)"
printf 'grep -E "SNTP (check|STEP|: )" /run/aurora-modem/lifecycle.log | tail -2\n' > $O/.s
i=0; until tn $O/.s 3 | grep -qE "^\[[0-9.]+\] SNTP"; do i=$((i+1)); [ $i -ge 15 ] && break; sleep 4; done; act "sntp: $(tn $O/.s 3 | grep -E '^\[[0-9.]+\] SNTP' | tail -2 | tr '\n' ' ')"
cat > $O/.c <<'C'
echo SNAP-BEGIN; cat /proc/uptime; date -u; cat /proc/device-tree/model; echo; uname -a; cat /proc/cmdline
echo ---time; cat /run/aurora-modem/time-set; grep -E "TIME|SNTP" /run/aurora-modem/lifecycle.log | tail -4
echo ---modem; /etc/init.d/aurora-modem status
echo ---wifi; /etc/init.d/aurora-wifi status; echo ---wifilog; cat /run/aurora-wifi/wifi.log; cat /run/aurora-wifi/service.log; echo ---hostapdlog; cat /run/aurora-wifi/hostapd.log
for r in /sys/class/remoteproc/*; do echo "RP $(cat $r/name)=$(cat $r/state)"; done; iw dev
echo ---dmesg-wifi; dmesg | grep -iE "wcn36xx|wcnss|a204000|cfg80211|aurora-wifi|crash|watchdog"
echo ---ping; ping -c4 -W3 -I wwan0 77.88.8.8 | tail -2
echo ---display; /etc/init.d/aurora-display status; cat /run/aurora-display/display.log; cat /run/aurora-display/service.log
echo ---consoles; cat /sys/class/tty/console/active; for v in /sys/class/vtconsole/vtcon*; do echo "$v $(cat $v/bind) $(cat $v/name)"; done; ls -l /proc/[0-9]*/fd/0 2>/dev/null | grep -E "ttyMSM0|tty1|console" | sed "s/.* \/proc/\/proc/"
echo ---getty; hostname; ps | grep -E "[g]etty|[c]ttyhack| sh$"
echo ---fb; ls -l /dev/dri/card0 /dev/fb0; for f in name bits_per_pixel virtual_size stride; do echo "fb0 $f=$(cat /sys/class/graphics/fb0/$f)"; done; cat /sys/class/drm/card0-SPI-1/enabled /sys/class/drm/card0-SPI-1/dpms
echo ---regs; for r in /sys/class/regulator/regulator.*; do n=$(cat $r/name); case $n in l6|l17) echo "$n $(cat $r/state) $(cat $r/microvolts) users=$(cat $r/num_users)";; esac; done
echo ---bl; for f in bl_power brightness actual_brightness; do echo "bl $f=$(cat /sys/class/backlight/backlight/$f)"; done
echo ---dmesg-display; dmesg | grep -iE "drm|panel|mipi|spi_qup|78b8000|fbcon|Console: |frame buffer|backlight|aurora-display|l17"
echo ---display-errors; dmesg | grep -iE "drm|panel|mipi|spi0|fbcon|backlight|aurora-display" | grep -ciE "err|fail|timeout|warn"
echo ---iio; for d in /sys/bus/iio/devices/iio:device*; do echo "$d name=$(cat $d/name)"; ls $d | tr '\n' ' '; echo; done
for f in /sys/bus/iio/devices/iio:device*/in_*; do case $f in *_raw|*_input|*_scale|*_offset) echo "$f=$(cat $f 2>&1)";; esac; done
echo ---psy; ls -l /sys/class/power_supply/; for p in /sys/class/power_supply/*; do echo "-- $p"; cat $p/uevent; ls $p; done
echo ---dmesg-bms; dmesg | grep -iE "bms|battery|power_supply|lbc|charger|extcon|ci_hdrc|4000|1000"
echo ---lbc-state; grep -q " /sys/kernel/debug " /proc/mounts || mount -t debugfs debugfs /sys/kernel/debug; cat /sys/kernel/debug/pm8916_lbc/state; dmesg | grep -E "safety timer|supervisor|pm8916-lbc|lbc"
echo ---thermal; for t in /sys/class/thermal/thermal_zone*; do echo "$t $(cat $t/type) $(cat $t/temp)"; done
echo ---dmesg-adc; dmesg | grep -iE "vadc|iio|temp-alarm|qpnp|spmi-temp|pm8916-thermal|thermal"
echo ---emmc; awk "{print \"w=\"\$5\" s=\"\$7}" /sys/block/mmcblk0/stat
echo SNAP-END
C
tn $O/.c 25 > $O/snapshot.txt; act "snapshot: $(grep -c SNAP-END $O/snapshot.txt) end markers; $(grep -E '^RP a204' $O/snapshot.txt)"
printf 'dmesg > /tmp/dm.txt; nc -l -p 9881 < /tmp/dm.txt &\n' > $O/.d; tn $O/.d 3 >/dev/null; sleep 1; ncat --recv-only 172.16.42.1 9881 > $O/dmesg.full
cp $U.log $O/uart.log; act "B10B3 $MODE$K END - operator visual check next"

View file

@ -1,18 +0,0 @@
#!/bin/sh
# Pre-t1 discharge (board on battery): N x `yes`, stop when VADC VBAT <= VMIN uV (3 samples in a row), PMIC > 55 C, or after MAX s. Writes /tmp only.
N=${1:-4}; MAX=${2:-5400}; VMIN=${3:-3880000}; L=/tmp/b10b3t-dis.log; low=0; D=/sys/bus/iio/devices/iio:device0
trap '' HUP
C=/sys/class/power_supply/pm8916-lbc-chgr/online; echo "WAIT-USB-OFF up=$(cut -d" " -f1 /proc/uptime)" >> $L; while [ "$(cat $C)" != 0 ]; do sleep 2; done; echo "USB-OFF up=$(cut -d" " -f1 /proc/uptime)" >> $L
t0=$(cut -d. -f1 /proc/uptime); P=""
for i in $(seq 1 $N); do yes > /dev/null & P="$P $!"; done
echo "LOAD-START up=$t0 n=$N pids=$P" >> $L
why=timeout
while :; do
t=$(cut -d. -f1 /proc/uptime); vb=$(cat $D/in_voltage6_input); pt=$(cat $D/in_temp8_input)
echo "L up=$t vbat6=$vb pmt=$pt" >> $L
[ "$pt" -gt 55000 ] && { why=pmic-55C; break; }
if [ "$vb" -le $VMIN ]; then low=$((low + 1)); else low=0; fi; [ $low -ge 3 ] && { why=vbat-reached-VMIN; break; }
[ $((t - t0)) -ge $MAX ] && break
sleep 10
done
kill $P; echo "LOAD-STOP up=$(cut -d' ' -f1 /proc/uptime) reason=$why" >> $L

View file

@ -1,14 +0,0 @@
#!/bin/sh
# 480s side, t1 diagnostic (B10B-3T v2 image, FAST_CHG_ON check): wait for the NEW boot's NCM, then at once push b10b3-mon.sh to the board and start it (5 s, EVDD=00/00, VMAX 4.15 V),
# then start the 30-s pull into logs/b10/b10b3/<K>-mon.txt. Board side reads only (writes /tmp only). usage: b10b3b-mon-start.sh K
K=$1; [ -n "$K" ] || { echo "usage: $0 K"; exit 2; }
cd ~/doc/modem/jz08-aurora; A=logs/b10/b10b3/$K-actions.txt; act() { echo "$(date -u +%H:%M:%S.%3N) $*" | tee -a $A; }
rm -f logs/b10/b10b3/pull.stop
act "mon-start $K: waiting for the board to go away (warm reboot)"; until ! ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do sleep 0.5; done; act "board gone"
until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do sleep 0.5; done; act "NCM up"
i=0; until { sleep 1; printf 'nc -l -p 9957 > /tmp/b10b3-mon.sh &\r\n'; sleep 1; } | ncat -w 4 172.16.42.1 23 >/dev/null 2>&1; do i=$((i+1)); [ $i -ge 60 ] && { act "ABORT: no telnet"; exit 1; }; sleep 1; done
sleep 1; ncat --send-only 172.16.42.1 9957 < b10/b10b3/b10b3-mon.sh; sleep 1
sh b10/b10b3/b10b3-cmd.sh 3 'md5sum /tmp/b10b3-mon.sh; rm -f /tmp/b10b3-mon.stop; VMAX=4150000 EVDD=00 EVDD2=00 setsid sh /tmp/b10b3-mon.sh 5 > /dev/null 2>&1 < /dev/null & sleep 1; dmesg | grep -E "safety timer|supervisor"; cut -d" " -f1 /proc/uptime' | tee -a $A
act "local md5 $(md5sum < b10/b10b3/b10b3-mon.sh)"
setsid nohup sh b10/b10b3/b10b3-pull.sh $K > /dev/null 2>&1 < /dev/null &
act "monitor started (5 s), pull started -> logs/b10/b10b3/$K-mon.txt"

View file

@ -1,14 +0,0 @@
#!/bin/sh
# B10B-4 board side: apply ONE hook command (or "none") and log fast: 1 s x 12, then 5 s x 10 (≈ 62 s). Reads only, except the single hook write.
# usage: b10b4-act.sh TAG "susp 1"|"vdd 0"|"ibat 0"|none -> /tmp/b4-TAG.log
T=$1; CMD=$2; L=/tmp/b4-$T.log; R=/sys/kernel/debug/regmap/0-00/registers; D=/sys/bus/iio/devices/iio:device0; H=/sys/kernel/debug/pm8916_lbc/b10b4
grep -q " /sys/kernel/debug " /proc/mounts || mount -t debugfs debugfs /sys/kernel/debug
rd() { dd if=$R bs=9 skip=$(($1)) count=1 2>/dev/null | cut -d' ' -f2; }
s() { echo "S $1 up=$(cut -d' ' -f1 /proc/uptime) vbat=$(cat $D/in_voltage6_input) vph=$(cat $D/in_voltage7_input) usbin=$(cat $D/in_voltage0_input) pmt=$(cat $D/in_temp8_input) chgst=$(rd 0x1009) crt=$(rd 0x1010) urt=$(rd 0x1310) path=$(rd 0x1308) susp=$(rd 0x1347) vdd=$(rd 0x1040) ibat=$(rd 0x1044) ctrl=$(rd 0x1049) failed=$(rd 0x104a) st=$(head -1 /sys/kernel/debug/pm8916_lbc/state | cut -d' ' -f2)" >> $L; }
trap '' HUP
echo "BEGIN $T cmd='$CMD' $(date -u +%T)" >> $L
s pre; s pre
if [ "$CMD" != none ]; then echo "$CMD" > $H; echo "WRITE rc=$? '$CMD' up=$(cut -d' ' -f1 /proc/uptime)" >> $L; dmesg | grep "B10B-4 TEST hook" | tail -1 >> $L; fi
i=0; while [ $i -lt 12 ]; do s "+${i}s"; sleep 1; i=$((i+1)); done
i=0; while [ $i -lt 10 ]; do sleep 5; s "+$((12+5*i+5))s"; i=$((i+1)); done
echo "END $T $(date -u +%T)" >> $L

View file

@ -1,60 +0,0 @@
#!/bin/sh
# 480s side, B10B-4 actuator-audit TEST image (TEST-ONLY kernel, debugfs pm8916_lbc/b10b4) boot K (RAM only). RESET-held power-on -> lk1st fastboot -> `fastboot boot` B10B-3 RAM image. Reads only over telnet.
# MODE=cold: normal power-on (no RESET, no fastboot) -> lk2nd extlinux from eMMC cache. Script only observes + reads over telnet;
# nothing is written to eMMC. Visual display checks need the operator. Adds display/fbcon/getty/console checks to the B8F snapshot.
K=$1; MODE=ram; [ -n "$K" ] || { echo "usage: $0 K"; exit 2; }
cd ~/doc/modem/jz08-aurora; O=logs/b10/b10b3/b4r$K; mkdir -p $O; IMG=b10/b10b3/out-b4/aurora-b10b4.img
A=$O/host-actions.txt; act() { echo "$(date -u +%H:%M:%S.%3N) $*" | tee -a $A; }
tn() { { sleep 1; sed "s/\$/\r/" "$1"; sleep $2; } | ncat 172.16.42.1 23 | tr -d "\000\r"; }
OLD=$(ps -eo pid,cmd | grep "[u]artlog.py /dev/ttyUSB0" | awk '{print $1}'); [ -n "$OLD" ] && kill $OLD; sleep 1
U=logs/uart/b10b4-$MODE$K-$(date +%Y%m%d-%H%M%S); setsid nohup python3 tools/uartlog.py /dev/ttyUSB0 $U > $U.stderr 2>&1 < /dev/null &
if [ $MODE = ram ]; then
echo "eeff682053ac49abfa3952a2d3957dcbf5cd384280f35647ec40eb83835dc38b $IMG" | sha256sum -c || exit 1
act "B10B4 $MODE$K: waiting for fastboot <EMMC_SERIAL> (power off >= 90 s, then RESET held + battery -> USB)"
if fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; then act "already in fastboot - wait for power-off"; until ! fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do sleep 1; done; fi
i=0; until fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do i=$((i+1)); [ $i -ge 1800 ] && { act "ABORT: no fastboot"; exit 1; }; sleep 2; done
act "fastboot present"; { fastboot boot $IMG 2>&1; echo "rc=$?"; } | tee -a $A
else
act "B10B4 $MODE$K: waiting for the board to go away (power off >= 90 s), then normal power-on WITHOUT RESET"
until ! ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do sleep 1; done; act "board unreachable (powered off)"
until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL> && { act "ABORT: board is in fastboot - RESET was held?"; exit 1; }; sleep 1; done
fi
i=0; until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do i=$((i+1)); [ $i -ge 180 ] && { act "ABORT: NCM not up"; cp $U.log $O/uart.log; exit 1; }; sleep 1; done; act "NCM ping ok"
R=$(grep -a "rtc-pm8xxx.*setting system clock" $U.log | tail -1 | sed -n 's/.*(\([0-9]*\)).*/\1/p'); C=B; [ -n "$R" ] && [ "$R" -lt 40 ] && C=A; act "RTC at boot ${R:-?} s -> class $C"
printf 'cat /proc/device-tree/model; echo; uname -r; grep -E "START OK|FAIL in|rollback" /run/aurora-modem/lifecycle.log | tail -1\n' > $O/.w
i=0; until tn $O/.w 3 | grep -qE "^\[[0-9.]+\] .*(=== START OK|FAIL in|rollback)"; do i=$((i+1)); [ $i -ge 80 ] && { act "no START OK/FAIL after ~12 min"; break; }; sleep 6; done
tn $O/.w 3 | grep -aE "Aurora|aurora-b8|START OK|FAIL" | tee -a $A
printf 'grep -E "AP ENABLED|FAIL" /run/aurora-wifi/wifi.log | tail -1\n' > $O/.a
i=0; until tn $O/.a 3 | grep -qE "^\[[0-9.]+\] (=== AP ENABLED|FAIL)"; do i=$((i+1)); [ $i -ge 20 ] && { act "no AP ENABLED/FAIL after ~3 min"; break; }; sleep 6; done
act "wifi: $(tn $O/.a 3 | grep -E '^\[[0-9.]+\] (=== AP ENABLED|FAIL)' | tail -1)"
printf 'grep -E "SNTP (check|STEP|: )" /run/aurora-modem/lifecycle.log | tail -2\n' > $O/.s
i=0; until tn $O/.s 3 | grep -qE "^\[[0-9.]+\] SNTP"; do i=$((i+1)); [ $i -ge 15 ] && break; sleep 4; done; act "sntp: $(tn $O/.s 3 | grep -E '^\[[0-9.]+\] SNTP' | tail -2 | tr '\n' ' ')"
cat > $O/.c <<'C'
echo SNAP-BEGIN; cat /proc/uptime; date -u; cat /proc/device-tree/model; echo; uname -a; cat /proc/cmdline
echo ---time; cat /run/aurora-modem/time-set; grep -E "TIME|SNTP" /run/aurora-modem/lifecycle.log | tail -4
echo ---modem; /etc/init.d/aurora-modem status
echo ---wifi; /etc/init.d/aurora-wifi status; echo ---wifilog; cat /run/aurora-wifi/wifi.log; cat /run/aurora-wifi/service.log; echo ---hostapdlog; cat /run/aurora-wifi/hostapd.log
for r in /sys/class/remoteproc/*; do echo "RP $(cat $r/name)=$(cat $r/state)"; done; iw dev
echo ---dmesg-wifi; dmesg | grep -iE "wcn36xx|wcnss|a204000|cfg80211|aurora-wifi|crash|watchdog"
echo ---ping; ping -c4 -W3 -I wwan0 77.88.8.8 | tail -2
echo ---display; /etc/init.d/aurora-display status; cat /run/aurora-display/display.log; cat /run/aurora-display/service.log
echo ---consoles; cat /sys/class/tty/console/active; for v in /sys/class/vtconsole/vtcon*; do echo "$v $(cat $v/bind) $(cat $v/name)"; done; ls -l /proc/[0-9]*/fd/0 2>/dev/null | grep -E "ttyMSM0|tty1|console" | sed "s/.* \/proc/\/proc/"
echo ---getty; hostname; ps | grep -E "[g]etty|[c]ttyhack| sh$"
echo ---fb; ls -l /dev/dri/card0 /dev/fb0; for f in name bits_per_pixel virtual_size stride; do echo "fb0 $f=$(cat /sys/class/graphics/fb0/$f)"; done; cat /sys/class/drm/card0-SPI-1/enabled /sys/class/drm/card0-SPI-1/dpms
echo ---regs; for r in /sys/class/regulator/regulator.*; do n=$(cat $r/name); case $n in l6|l17) echo "$n $(cat $r/state) $(cat $r/microvolts) users=$(cat $r/num_users)";; esac; done
echo ---bl; for f in bl_power brightness actual_brightness; do echo "bl $f=$(cat /sys/class/backlight/backlight/$f)"; done
echo ---dmesg-display; dmesg | grep -iE "drm|panel|mipi|spi_qup|78b8000|fbcon|Console: |frame buffer|backlight|aurora-display|l17"
echo ---display-errors; dmesg | grep -iE "drm|panel|mipi|spi0|fbcon|backlight|aurora-display" | grep -ciE "err|fail|timeout|warn"
echo ---iio; for d in /sys/bus/iio/devices/iio:device*; do echo "$d name=$(cat $d/name)"; ls $d | tr '\n' ' '; echo; done
for f in /sys/bus/iio/devices/iio:device*/in_*; do case $f in *_raw|*_input|*_scale|*_offset) echo "$f=$(cat $f 2>&1)";; esac; done
echo ---psy; ls -l /sys/class/power_supply/; for p in /sys/class/power_supply/*; do echo "-- $p"; cat $p/uevent; ls $p; done
echo ---dmesg-bms; dmesg | grep -iE "bms|battery|power_supply|lbc|charger|extcon|ci_hdrc|4000|1000"
echo ---lbc-state; grep -q " /sys/kernel/debug " /proc/mounts || mount -t debugfs debugfs /sys/kernel/debug; cat /sys/kernel/debug/pm8916_lbc/state; dmesg | grep -E "safety timer|supervisor|pm8916-lbc|lbc"
echo ---thermal; for t in /sys/class/thermal/thermal_zone*; do echo "$t $(cat $t/type) $(cat $t/temp)"; done
echo ---dmesg-adc; dmesg | grep -iE "vadc|iio|temp-alarm|qpnp|spmi-temp|pm8916-thermal|thermal"
echo ---emmc; awk "{print \"w=\"\$5\" s=\"\$7}" /sys/block/mmcblk0/stat
echo SNAP-END
C
tn $O/.c 25 > $O/snapshot.txt; act "snapshot: $(grep -c SNAP-END $O/snapshot.txt) end markers; $(grep -E '^RP a204' $O/snapshot.txt)"
printf 'dmesg > /tmp/dm.txt; nc -l -p 9881 < /tmp/dm.txt &\n' > $O/.d; tn $O/.d 3 >/dev/null; sleep 1; ncat --recv-only 172.16.42.1 9881 > $O/dmesg.full
cp $U.log $O/uart.log; act "B10B4 $MODE$K END - operator visual check next"

View file

@ -1,14 +0,0 @@
#!/bin/sh
# 480s side, B10B-4 actuator audit: wait for the NEW boot's NCM, then at once push b10b3-mon.sh to the board and start it (5 s, EVDD=08/02, VMAX 4.23 V),
# then start the 30-s pull into logs/b10/b10b3/<K>-mon.txt. Board side reads only (writes /tmp only). usage: b10b3b-mon-start.sh K
K=$1; [ -n "$K" ] || { echo "usage: $0 K"; exit 2; }
cd ~/doc/modem/jz08-aurora; A=logs/b10/b10b3/$K-actions.txt; act() { echo "$(date -u +%H:%M:%S.%3N) $*" | tee -a $A; }
rm -f logs/b10/b10b3/pull.stop
act "mon-start $K: waiting for lk1st fastboot (RESET-held reboot), then for the new boot"; until fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do sleep 1; done; act "fastboot seen"; until ! fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do sleep 1; done; act "fastboot gone (booting)"
until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do sleep 0.5; done; act "NCM up"
i=0; until { sleep 1; printf 'nc -l -p 9981 > /tmp/b10b3-mon.sh &\r\n'; sleep 1; } | ncat -w 4 172.16.42.1 23 >/dev/null 2>&1; do i=$((i+1)); [ $i -ge 60 ] && { act "ABORT: no telnet"; exit 1; }; sleep 1; done
sleep 1; ncat --send-only 172.16.42.1 9981 < b10/b10b3/b10b3-mon.sh; sleep 1
sh b10/b10b3/b10b3-cmd.sh 3 'md5sum /tmp/b10b3-mon.sh; rm -f /tmp/b10b3-mon.stop; VMAX=4230000 EVDD=08 EVDD2=02 setsid sh /tmp/b10b3-mon.sh 30 > /dev/null 2>&1 < /dev/null & sleep 1; dmesg | grep -E "safety timer|supervisor"; cut -d" " -f1 /proc/uptime' | tee -a $A
act "local md5 $(md5sum < b10/b10b3/b10b3-mon.sh)"
setsid nohup sh b10/b10b3/b10b3-pull.sh $K > /dev/null 2>&1 < /dev/null &
act "monitor started (30 s), pull started -> logs/b10/b10b3/$K-mon.txt"

View file

@ -1,14 +0,0 @@
#!/bin/sh
# B10B-5 board side: arm ONE TEST OVP FAULT injection ("ovp") or "none" and log fast: 1 s x 12, then 5 s x 10 (≈ 62 s). Reads only, except the single hook write.
# usage: b10b4-act.sh TAG "susp 1"|"vdd 0"|"ibat 0"|none -> /tmp/b4-TAG.log
T=$1; CMD=$2; L=/tmp/b5-$T.log; R=/sys/kernel/debug/regmap/0-00/registers; D=/sys/bus/iio/devices/iio:device0; H=/sys/kernel/debug/pm8916_lbc/b10b5_fault
grep -q " /sys/kernel/debug " /proc/mounts || mount -t debugfs debugfs /sys/kernel/debug
rd() { dd if=$R bs=9 skip=$(($1)) count=1 2>/dev/null | cut -d' ' -f2; }
s() { echo "S $1 up=$(cut -d' ' -f1 /proc/uptime) vbat=$(cat $D/in_voltage6_input) vph=$(cat $D/in_voltage7_input) usbin=$(cat $D/in_voltage0_input) pmt=$(cat $D/in_temp8_input) chgst=$(rd 0x1009) crt=$(rd 0x1010) urt=$(rd 0x1310) path=$(rd 0x1308) susp=$(rd 0x1347) vdd=$(rd 0x1040) ibat=$(rd 0x1044) ctrl=$(rd 0x1049) failed=$(rd 0x104a) st=$(head -1 /sys/kernel/debug/pm8916_lbc/state | cut -d' ' -f2)" >> $L; }
trap '' HUP
echo "BEGIN $T cmd='$CMD' $(date -u +%T)" >> $L
s pre; s pre
if [ "$CMD" != none ]; then echo "$CMD" > $H; echo "WRITE rc=$? '$CMD' up=$(cut -d' ' -f1 /proc/uptime)" >> $L; sleep 1; dmesg | grep -E "FAULT safe clamp|B10B-5 TEST|-> FAULT" | tail -3 >> $L; fi
i=0; while [ $i -lt 12 ]; do s "+${i}s"; sleep 1; i=$((i+1)); done
i=0; while [ $i -lt 22 ]; do sleep 5; s "+$((12+5*i+5))s"; i=$((i+1)); done
echo "END $T $(date -u +%T)" >> $L

View file

@ -1,60 +0,0 @@
#!/bin/sh
# 480s side, B10B-5 PRODUCTION v4 RAM smoke test (no test hooks) boot K (RAM only). RESET-held power-on -> lk1st fastboot -> `fastboot boot` B10B-3 RAM image. Reads only over telnet.
# MODE=cold: normal power-on (no RESET, no fastboot) -> lk2nd extlinux from eMMC cache. Script only observes + reads over telnet;
# nothing is written to eMMC. Visual display checks need the operator. Adds display/fbcon/getty/console checks to the B8F snapshot.
K=$1; MODE=ram; [ -n "$K" ] || { echo "usage: $0 K"; exit 2; }
cd ~/doc/modem/jz08-aurora; O=logs/b10/b10b3/b5p$K; mkdir -p $O; IMG=b10/b10b3/out-v4/aurora-b10b5.img
A=$O/host-actions.txt; act() { echo "$(date -u +%H:%M:%S.%3N) $*" | tee -a $A; }
tn() { { sleep 1; sed "s/\$/\r/" "$1"; sleep $2; } | ncat 172.16.42.1 23 | tr -d "\000\r"; }
OLD=$(ps -eo pid,cmd | grep "[u]artlog.py /dev/ttyUSB0" | awk '{print $1}'); [ -n "$OLD" ] && kill $OLD; sleep 1
U=logs/uart/b10b5p-$MODE$K-$(date +%Y%m%d-%H%M%S); setsid nohup python3 tools/uartlog.py /dev/ttyUSB0 $U > $U.stderr 2>&1 < /dev/null &
if [ $MODE = ram ]; then
echo "386502d3ca68b1c4dfb4bbf354f3abc48cfab497143a39f6272b79a3899c1e9b $IMG" | sha256sum -c || exit 1
act "B10B5P $MODE$K: waiting for fastboot <EMMC_SERIAL> (power off >= 90 s, then RESET held + battery -> USB)"
if fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; then act "already in fastboot - wait for power-off"; until ! fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do sleep 1; done; fi
i=0; until fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do i=$((i+1)); [ $i -ge 1800 ] && { act "ABORT: no fastboot"; exit 1; }; sleep 2; done
act "fastboot present"; { fastboot boot $IMG 2>&1; echo "rc=$?"; } | tee -a $A
else
act "B10B5P $MODE$K: waiting for the board to go away (power off >= 90 s), then normal power-on WITHOUT RESET"
until ! ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do sleep 1; done; act "board unreachable (powered off)"
until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL> && { act "ABORT: board is in fastboot - RESET was held?"; exit 1; }; sleep 1; done
fi
i=0; until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do i=$((i+1)); [ $i -ge 180 ] && { act "ABORT: NCM not up"; cp $U.log $O/uart.log; exit 1; }; sleep 1; done; act "NCM ping ok"
R=$(grep -a "rtc-pm8xxx.*setting system clock" $U.log | tail -1 | sed -n 's/.*(\([0-9]*\)).*/\1/p'); C=B; [ -n "$R" ] && [ "$R" -lt 40 ] && C=A; act "RTC at boot ${R:-?} s -> class $C"
printf 'cat /proc/device-tree/model; echo; uname -r; grep -E "START OK|FAIL in|rollback" /run/aurora-modem/lifecycle.log | tail -1\n' > $O/.w
i=0; until tn $O/.w 3 | grep -qE "^\[[0-9.]+\] .*(=== START OK|FAIL in|rollback)"; do i=$((i+1)); [ $i -ge 80 ] && { act "no START OK/FAIL after ~12 min"; break; }; sleep 6; done
tn $O/.w 3 | grep -aE "Aurora|aurora-b8|START OK|FAIL" | tee -a $A
printf 'grep -E "AP ENABLED|FAIL" /run/aurora-wifi/wifi.log | tail -1\n' > $O/.a
i=0; until tn $O/.a 3 | grep -qE "^\[[0-9.]+\] (=== AP ENABLED|FAIL)"; do i=$((i+1)); [ $i -ge 20 ] && { act "no AP ENABLED/FAIL after ~3 min"; break; }; sleep 6; done
act "wifi: $(tn $O/.a 3 | grep -E '^\[[0-9.]+\] (=== AP ENABLED|FAIL)' | tail -1)"
printf 'grep -E "SNTP (check|STEP|: )" /run/aurora-modem/lifecycle.log | tail -2\n' > $O/.s
i=0; until tn $O/.s 3 | grep -qE "^\[[0-9.]+\] SNTP"; do i=$((i+1)); [ $i -ge 15 ] && break; sleep 4; done; act "sntp: $(tn $O/.s 3 | grep -E '^\[[0-9.]+\] SNTP' | tail -2 | tr '\n' ' ')"
cat > $O/.c <<'C'
echo SNAP-BEGIN; cat /proc/uptime; date -u; cat /proc/device-tree/model; echo; uname -a; cat /proc/cmdline
echo ---time; cat /run/aurora-modem/time-set; grep -E "TIME|SNTP" /run/aurora-modem/lifecycle.log | tail -4
echo ---modem; /etc/init.d/aurora-modem status
echo ---wifi; /etc/init.d/aurora-wifi status; echo ---wifilog; cat /run/aurora-wifi/wifi.log; cat /run/aurora-wifi/service.log; echo ---hostapdlog; cat /run/aurora-wifi/hostapd.log
for r in /sys/class/remoteproc/*; do echo "RP $(cat $r/name)=$(cat $r/state)"; done; iw dev
echo ---dmesg-wifi; dmesg | grep -iE "wcn36xx|wcnss|a204000|cfg80211|aurora-wifi|crash|watchdog"
echo ---ping; ping -c4 -W3 -I wwan0 77.88.8.8 | tail -2
echo ---display; /etc/init.d/aurora-display status; cat /run/aurora-display/display.log; cat /run/aurora-display/service.log
echo ---consoles; cat /sys/class/tty/console/active; for v in /sys/class/vtconsole/vtcon*; do echo "$v $(cat $v/bind) $(cat $v/name)"; done; ls -l /proc/[0-9]*/fd/0 2>/dev/null | grep -E "ttyMSM0|tty1|console" | sed "s/.* \/proc/\/proc/"
echo ---getty; hostname; ps | grep -E "[g]etty|[c]ttyhack| sh$"
echo ---fb; ls -l /dev/dri/card0 /dev/fb0; for f in name bits_per_pixel virtual_size stride; do echo "fb0 $f=$(cat /sys/class/graphics/fb0/$f)"; done; cat /sys/class/drm/card0-SPI-1/enabled /sys/class/drm/card0-SPI-1/dpms
echo ---regs; for r in /sys/class/regulator/regulator.*; do n=$(cat $r/name); case $n in l6|l17) echo "$n $(cat $r/state) $(cat $r/microvolts) users=$(cat $r/num_users)";; esac; done
echo ---bl; for f in bl_power brightness actual_brightness; do echo "bl $f=$(cat /sys/class/backlight/backlight/$f)"; done
echo ---dmesg-display; dmesg | grep -iE "drm|panel|mipi|spi_qup|78b8000|fbcon|Console: |frame buffer|backlight|aurora-display|l17"
echo ---display-errors; dmesg | grep -iE "drm|panel|mipi|spi0|fbcon|backlight|aurora-display" | grep -ciE "err|fail|timeout|warn"
echo ---iio; for d in /sys/bus/iio/devices/iio:device*; do echo "$d name=$(cat $d/name)"; ls $d | tr '\n' ' '; echo; done
for f in /sys/bus/iio/devices/iio:device*/in_*; do case $f in *_raw|*_input|*_scale|*_offset) echo "$f=$(cat $f 2>&1)";; esac; done
echo ---psy; ls -l /sys/class/power_supply/; for p in /sys/class/power_supply/*; do echo "-- $p"; cat $p/uevent; ls $p; done
echo ---dmesg-bms; dmesg | grep -iE "bms|battery|power_supply|lbc|charger|extcon|ci_hdrc|4000|1000"
echo ---lbc-state; grep -q " /sys/kernel/debug " /proc/mounts || mount -t debugfs debugfs /sys/kernel/debug; cat /sys/kernel/debug/pm8916_lbc/state; dmesg | grep -E "safety timer|supervisor|pm8916-lbc|lbc"
echo ---thermal; for t in /sys/class/thermal/thermal_zone*; do echo "$t $(cat $t/type) $(cat $t/temp)"; done
echo ---dmesg-adc; dmesg | grep -iE "vadc|iio|temp-alarm|qpnp|spmi-temp|pm8916-thermal|thermal"
echo ---emmc; awk "{print \"w=\"\$5\" s=\"\$7}" /sys/block/mmcblk0/stat
echo SNAP-END
C
tn $O/.c 25 > $O/snapshot.txt; act "snapshot: $(grep -c SNAP-END $O/snapshot.txt) end markers; $(grep -E '^RP a204' $O/snapshot.txt)"
printf 'dmesg > /tmp/dm.txt; nc -l -p 9881 < /tmp/dm.txt &\n' > $O/.d; tn $O/.d 3 >/dev/null; sleep 1; ncat --recv-only 172.16.42.1 9881 > $O/dmesg.full
cp $U.log $O/uart.log; act "B10B5P $MODE$K END - operator visual check next"

View file

@ -1,60 +0,0 @@
#!/bin/sh
# 480s side, B10B-5 FAULT-clamp regression TEST image (TEST-ONLY kernel v4 + FAULT injection) boot K (RAM only). RESET-held power-on -> lk1st fastboot -> `fastboot boot` B10B-3 RAM image. Reads only over telnet.
# MODE=cold: normal power-on (no RESET, no fastboot) -> lk2nd extlinux from eMMC cache. Script only observes + reads over telnet;
# nothing is written to eMMC. Visual display checks need the operator. Adds display/fbcon/getty/console checks to the B8F snapshot.
K=$1; MODE=ram; [ -n "$K" ] || { echo "usage: $0 K"; exit 2; }
cd ~/doc/modem/jz08-aurora; O=logs/b10/b10b3/b5r$K; mkdir -p $O; IMG=b10/b10b3/out-b5t/aurora-b10b5t.img
A=$O/host-actions.txt; act() { echo "$(date -u +%H:%M:%S.%3N) $*" | tee -a $A; }
tn() { { sleep 1; sed "s/\$/\r/" "$1"; sleep $2; } | ncat 172.16.42.1 23 | tr -d "\000\r"; }
OLD=$(ps -eo pid,cmd | grep "[u]artlog.py /dev/ttyUSB0" | awk '{print $1}'); [ -n "$OLD" ] && kill $OLD; sleep 1
U=logs/uart/b10b5t-$MODE$K-$(date +%Y%m%d-%H%M%S); setsid nohup python3 tools/uartlog.py /dev/ttyUSB0 $U > $U.stderr 2>&1 < /dev/null &
if [ $MODE = ram ]; then
echo "ea37a67cb488b627bd52603cf7c686e34d1c7e5232bfdb13b891b7f89f2e1cae $IMG" | sha256sum -c || exit 1
act "B10B5T $MODE$K: waiting for fastboot <EMMC_SERIAL> (power off >= 90 s, then RESET held + battery -> USB)"
if fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; then act "already in fastboot - wait for power-off"; until ! fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do sleep 1; done; fi
i=0; until fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL>; do i=$((i+1)); [ $i -ge 1800 ] && { act "ABORT: no fastboot"; exit 1; }; sleep 2; done
act "fastboot present"; { fastboot boot $IMG 2>&1; echo "rc=$?"; } | tee -a $A
else
act "B10B5T $MODE$K: waiting for the board to go away (power off >= 90 s), then normal power-on WITHOUT RESET"
until ! ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do sleep 1; done; act "board unreachable (powered off)"
until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do fastboot devices 2>/dev/null | grep -q <EMMC_SERIAL> && { act "ABORT: board is in fastboot - RESET was held?"; exit 1; }; sleep 1; done
fi
i=0; until ping -c1 -W1 172.16.42.1 >/dev/null 2>&1; do i=$((i+1)); [ $i -ge 180 ] && { act "ABORT: NCM not up"; cp $U.log $O/uart.log; exit 1; }; sleep 1; done; act "NCM ping ok"
R=$(grep -a "rtc-pm8xxx.*setting system clock" $U.log | tail -1 | sed -n 's/.*(\([0-9]*\)).*/\1/p'); C=B; [ -n "$R" ] && [ "$R" -lt 40 ] && C=A; act "RTC at boot ${R:-?} s -> class $C"
printf 'cat /proc/device-tree/model; echo; uname -r; grep -E "START OK|FAIL in|rollback" /run/aurora-modem/lifecycle.log | tail -1\n' > $O/.w
i=0; until tn $O/.w 3 | grep -qE "^\[[0-9.]+\] .*(=== START OK|FAIL in|rollback)"; do i=$((i+1)); [ $i -ge 80 ] && { act "no START OK/FAIL after ~12 min"; break; }; sleep 6; done
tn $O/.w 3 | grep -aE "Aurora|aurora-b8|START OK|FAIL" | tee -a $A
printf 'grep -E "AP ENABLED|FAIL" /run/aurora-wifi/wifi.log | tail -1\n' > $O/.a
i=0; until tn $O/.a 3 | grep -qE "^\[[0-9.]+\] (=== AP ENABLED|FAIL)"; do i=$((i+1)); [ $i -ge 20 ] && { act "no AP ENABLED/FAIL after ~3 min"; break; }; sleep 6; done
act "wifi: $(tn $O/.a 3 | grep -E '^\[[0-9.]+\] (=== AP ENABLED|FAIL)' | tail -1)"
printf 'grep -E "SNTP (check|STEP|: )" /run/aurora-modem/lifecycle.log | tail -2\n' > $O/.s
i=0; until tn $O/.s 3 | grep -qE "^\[[0-9.]+\] SNTP"; do i=$((i+1)); [ $i -ge 15 ] && break; sleep 4; done; act "sntp: $(tn $O/.s 3 | grep -E '^\[[0-9.]+\] SNTP' | tail -2 | tr '\n' ' ')"
cat > $O/.c <<'C'
echo SNAP-BEGIN; cat /proc/uptime; date -u; cat /proc/device-tree/model; echo; uname -a; cat /proc/cmdline
echo ---time; cat /run/aurora-modem/time-set; grep -E "TIME|SNTP" /run/aurora-modem/lifecycle.log | tail -4
echo ---modem; /etc/init.d/aurora-modem status
echo ---wifi; /etc/init.d/aurora-wifi status; echo ---wifilog; cat /run/aurora-wifi/wifi.log; cat /run/aurora-wifi/service.log; echo ---hostapdlog; cat /run/aurora-wifi/hostapd.log
for r in /sys/class/remoteproc/*; do echo "RP $(cat $r/name)=$(cat $r/state)"; done; iw dev
echo ---dmesg-wifi; dmesg | grep -iE "wcn36xx|wcnss|a204000|cfg80211|aurora-wifi|crash|watchdog"
echo ---ping; ping -c4 -W3 -I wwan0 77.88.8.8 | tail -2
echo ---display; /etc/init.d/aurora-display status; cat /run/aurora-display/display.log; cat /run/aurora-display/service.log
echo ---consoles; cat /sys/class/tty/console/active; for v in /sys/class/vtconsole/vtcon*; do echo "$v $(cat $v/bind) $(cat $v/name)"; done; ls -l /proc/[0-9]*/fd/0 2>/dev/null | grep -E "ttyMSM0|tty1|console" | sed "s/.* \/proc/\/proc/"
echo ---getty; hostname; ps | grep -E "[g]etty|[c]ttyhack| sh$"
echo ---fb; ls -l /dev/dri/card0 /dev/fb0; for f in name bits_per_pixel virtual_size stride; do echo "fb0 $f=$(cat /sys/class/graphics/fb0/$f)"; done; cat /sys/class/drm/card0-SPI-1/enabled /sys/class/drm/card0-SPI-1/dpms
echo ---regs; for r in /sys/class/regulator/regulator.*; do n=$(cat $r/name); case $n in l6|l17) echo "$n $(cat $r/state) $(cat $r/microvolts) users=$(cat $r/num_users)";; esac; done
echo ---bl; for f in bl_power brightness actual_brightness; do echo "bl $f=$(cat /sys/class/backlight/backlight/$f)"; done
echo ---dmesg-display; dmesg | grep -iE "drm|panel|mipi|spi_qup|78b8000|fbcon|Console: |frame buffer|backlight|aurora-display|l17"
echo ---display-errors; dmesg | grep -iE "drm|panel|mipi|spi0|fbcon|backlight|aurora-display" | grep -ciE "err|fail|timeout|warn"
echo ---iio; for d in /sys/bus/iio/devices/iio:device*; do echo "$d name=$(cat $d/name)"; ls $d | tr '\n' ' '; echo; done
for f in /sys/bus/iio/devices/iio:device*/in_*; do case $f in *_raw|*_input|*_scale|*_offset) echo "$f=$(cat $f 2>&1)";; esac; done
echo ---psy; ls -l /sys/class/power_supply/; for p in /sys/class/power_supply/*; do echo "-- $p"; cat $p/uevent; ls $p; done
echo ---dmesg-bms; dmesg | grep -iE "bms|battery|power_supply|lbc|charger|extcon|ci_hdrc|4000|1000"
echo ---lbc-state; grep -q " /sys/kernel/debug " /proc/mounts || mount -t debugfs debugfs /sys/kernel/debug; cat /sys/kernel/debug/pm8916_lbc/state; dmesg | grep -E "safety timer|supervisor|pm8916-lbc|lbc"
echo ---thermal; for t in /sys/class/thermal/thermal_zone*; do echo "$t $(cat $t/type) $(cat $t/temp)"; done
echo ---dmesg-adc; dmesg | grep -iE "vadc|iio|temp-alarm|qpnp|spmi-temp|pm8916-thermal|thermal"
echo ---emmc; awk "{print \"w=\"\$5\" s=\"\$7}" /sys/block/mmcblk0/stat
echo SNAP-END
C
tn $O/.c 25 > $O/snapshot.txt; act "snapshot: $(grep -c SNAP-END $O/snapshot.txt) end markers; $(grep -E '^RP a204' $O/snapshot.txt)"
printf 'dmesg > /tmp/dm.txt; nc -l -p 9881 < /tmp/dm.txt &\n' > $O/.d; tn $O/.d 3 >/dev/null; sleep 1; ncat --recv-only 172.16.42.1 9881 > $O/dmesg.full
cp $U.log $O/uart.log; act "B10B5T $MODE$K END - operator visual check next"

View file

@ -1,17 +0,0 @@
#!/bin/sh
# Pre-t1 discharge on B9C (no VADC; VBAT read by the operator's DMM): N x `yes`, stop on /tmp/b9c-dis.stop, CPU > 80 C, or after MAX s. Writes /tmp only.
N=${1:-4}; MAX=${2:-3600}; L=/tmp/b9c-dis.log
trap '' HUP
t0=$(cut -d. -f1 /proc/uptime); P=""
for i in $(seq 1 $N); do yes > /dev/null & P="$P $!"; done
echo "LOAD-START up=$t0 n=$N pids=$P" >> $L
why=timeout
while :; do
t=$(cut -d. -f1 /proc/uptime); ct=$(cat /sys/class/thermal/thermal_zone*/temp | sort -n | tail -1)
echo "L up=$t cpumax=$ct" >> $L
[ -e /tmp/b9c-dis.stop ] && { why=operator; break; }
[ "$ct" -gt 80000 ] && { why=cpu-80C; break; }
[ $((t - t0)) -ge $MAX ] && break
sleep 10
done
kill $P; echo "LOAD-STOP up=$(cut -d' ' -f1 /proc/uptime) reason=$why" >> $L

View file

@ -1,19 +0,0 @@
#!/bin/sh
# B10B-3 RAM test image (fastboot boot only - never flash; cache B9C / aboot untouched):
# kernel = out-b10b3 (b10b2 options; built from /home/q/aurora-kbuild/src-b10b3 = src + linux/patches/b10b3-lbc-supervisor-v3.patch).
# DTB = linux/dts/msm8916-jz08-aurora-b10b3.dtb (production v3 values: 4.20 V / HOLD 4.05 V / full-min 4.15 V / CV 60 min / 450 mA / 512 min)
# initramfs + cmdline = exact B9C (b9/b9c/out). out/ contains the B8F initramfs (Wi-Fi PSK): never publish.
set -e; cd "$(dirname "$0")"; O=out; KB=/home/q/aurora-kbuild/out-b10b3; L=../../linux; B9C=../../b9/b9c/out
mkdir -p $O
echo "7ca9cc794a3b85d3b7240f6311ad03bee9e1a4a59aae2ed9438318e853f7c3dc $L/dts/msm8916-jz08-aurora-b9b.dtb" | sha256sum -c
grep " initramfs-b9c.cpio.gz\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
grep " cmdline.txt\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
for s in IIO=y QCOM_SPMI_VADC=y BATTERY_PM8916_BMS_VM=y CHARGER_PM8916_LBC=y QCOM_SPMI_TEMP_ALARM=y 'LOCALVERSION="-aurora-b10b3"'; do grep -q "^CONFIG_$s\$" $KB/.config || { echo "STOP: CONFIG_$s"; exit 1; }; done
cp $KB/arch/arm64/boot/Image.gz $O/Image.gz; cp $KB/.config $O/config-b10b3; cp $L/dts/msm8916-jz08-aurora-b10b3.dtb $O/aurora-b10b3.dtb
cp $B9C/initramfs-b9c.cpio.gz $O/initramfs.cpio.gz; cp $B9C/cmdline.txt $O/cmdline.txt
cat $O/Image.gz $O/aurora-b10b3.dtb > $O/Image.gz-dtb
python3 ../../b6p/mkbootimg.py $O/Image.gz-dtb $O/initramfs.cpio.gz $O/cmdline.txt $O/aurora-b10b3.img
SZ=$(python3 -c "import struct;print(struct.unpack_from('<Q',open('$KB/arch/arm64/boot/Image','rb').read(24),16)[0])")
printf 'kernel image_size 0x%x, RAM-boot end 0x%x (< 0x81e00000 DTB)\n' $SZ $((0x80000000 + SZ)); [ $((0x80000000 + SZ)) -lt $((0x81e00000)) ]
(cd $O && sha256sum Image.gz aurora-b10b3.dtb Image.gz-dtb config-b10b3 cmdline.txt initramfs.cpio.gz aurora-b10b3.img > SHA256SUMS; cat SHA256SUMS); ls -l $O/aurora-b10b3.img

View file

@ -1,19 +0,0 @@
#!/bin/sh
# B10B-3 Test B TEST-ONLY RAM image (safety timer in HOLD; never for persistent use) (fastboot boot only - never flash; cache B9C / aboot untouched):
# kernel = out-b10b3 (b10b2 options; built from /home/q/aurora-kbuild/src-b10b3 = src + linux/patches/b10b3-lbc-supervisor-v3.patch).
# DTB = linux/dts/msm8916-jz08-aurora-b10b3b.dtb (TEST B: production v3 DTB with charge 4.05 V, hold 4.00 V, full-min 4.03 V, cv 2 min, timer 8 min)
# initramfs + cmdline = exact B9C (b9/b9c/out). out/ contains the B8F initramfs (Wi-Fi PSK): never publish.
set -e; cd "$(dirname "$0")"; O=out-b; KB=/home/q/aurora-kbuild/out-b10b3; L=../../linux; B9C=../../b9/b9c/out
mkdir -p $O
echo "7ca9cc794a3b85d3b7240f6311ad03bee9e1a4a59aae2ed9438318e853f7c3dc $L/dts/msm8916-jz08-aurora-b9b.dtb" | sha256sum -c
grep " initramfs-b9c.cpio.gz\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
grep " cmdline.txt\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
for s in IIO=y QCOM_SPMI_VADC=y BATTERY_PM8916_BMS_VM=y CHARGER_PM8916_LBC=y QCOM_SPMI_TEMP_ALARM=y 'LOCALVERSION="-aurora-b10b3"'; do grep -q "^CONFIG_$s\$" $KB/.config || { echo "STOP: CONFIG_$s"; exit 1; }; done
cp $KB/arch/arm64/boot/Image.gz $O/Image.gz; cp $KB/.config $O/config-b10b3; cp $L/dts/msm8916-jz08-aurora-b10b3b.dtb $O/aurora-b10b3b.dtb
cp $B9C/initramfs-b9c.cpio.gz $O/initramfs.cpio.gz; cp $B9C/cmdline.txt $O/cmdline.txt
cat $O/Image.gz $O/aurora-b10b3b.dtb > $O/Image.gz-dtb
python3 ../../b6p/mkbootimg.py $O/Image.gz-dtb $O/initramfs.cpio.gz $O/cmdline.txt $O/aurora-b10b3b.img
SZ=$(python3 -c "import struct;print(struct.unpack_from('<Q',open('$KB/arch/arm64/boot/Image','rb').read(24),16)[0])")
printf 'kernel image_size 0x%x, RAM-boot end 0x%x (< 0x81e00000 DTB)\n' $SZ $((0x80000000 + SZ)); [ $((0x80000000 + SZ)) -lt $((0x81e00000)) ]
(cd $O && sha256sum Image.gz aurora-b10b3b.dtb Image.gz-dtb config-b10b3 cmdline.txt initramfs.cpio.gz aurora-b10b3b.img > SHA256SUMS; cat SHA256SUMS); ls -l $O/aurora-b10b3b.img

View file

@ -1,19 +0,0 @@
#!/bin/sh
# B10B-3 Test C TEST-ONLY RAM image (HOLD mechanism; never for persistent use) (fastboot boot only - never flash; cache B9C / aboot untouched):
# kernel = out-b10b3 (b10b2 options; built from /home/q/aurora-kbuild/src-b10b3 = src + linux/patches/b10b3-lbc-supervisor-v3.patch).
# DTB = linux/dts/msm8916-jz08-aurora-b10b3c.dtb (TEST C: production v3 DTB with charge 4.10 V, hold 4.00 V, full-min 4.05 V, cv 5 min)
# initramfs + cmdline = exact B9C (b9/b9c/out). out/ contains the B8F initramfs (Wi-Fi PSK): never publish.
set -e; cd "$(dirname "$0")"; O=out-c; KB=/home/q/aurora-kbuild/out-b10b3; L=../../linux; B9C=../../b9/b9c/out
mkdir -p $O
echo "7ca9cc794a3b85d3b7240f6311ad03bee9e1a4a59aae2ed9438318e853f7c3dc $L/dts/msm8916-jz08-aurora-b9b.dtb" | sha256sum -c
grep " initramfs-b9c.cpio.gz\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
grep " cmdline.txt\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
for s in IIO=y QCOM_SPMI_VADC=y BATTERY_PM8916_BMS_VM=y CHARGER_PM8916_LBC=y QCOM_SPMI_TEMP_ALARM=y 'LOCALVERSION="-aurora-b10b3"'; do grep -q "^CONFIG_$s\$" $KB/.config || { echo "STOP: CONFIG_$s"; exit 1; }; done
cp $KB/arch/arm64/boot/Image.gz $O/Image.gz; cp $KB/.config $O/config-b10b3; cp $L/dts/msm8916-jz08-aurora-b10b3c.dtb $O/aurora-b10b3c.dtb
cp $B9C/initramfs-b9c.cpio.gz $O/initramfs.cpio.gz; cp $B9C/cmdline.txt $O/cmdline.txt
cat $O/Image.gz $O/aurora-b10b3c.dtb > $O/Image.gz-dtb
python3 ../../b6p/mkbootimg.py $O/Image.gz-dtb $O/initramfs.cpio.gz $O/cmdline.txt $O/aurora-b10b3c.img
SZ=$(python3 -c "import struct;print(struct.unpack_from('<Q',open('$KB/arch/arm64/boot/Image','rb').read(24),16)[0])")
printf 'kernel image_size 0x%x, RAM-boot end 0x%x (< 0x81e00000 DTB)\n' $SZ $((0x80000000 + SZ)); [ $((0x80000000 + SZ)) -lt $((0x81e00000)) ]
(cd $O && sha256sum Image.gz aurora-b10b3c.dtb Image.gz-dtb config-b10b3 cmdline.txt initramfs.cpio.gz aurora-b10b3c.img > SHA256SUMS; cat SHA256SUMS); ls -l $O/aurora-b10b3c.img

View file

@ -1,19 +0,0 @@
#!/bin/sh
# B10B-3 Test D TEST-ONLY RAM image (safety timer expiry in CHARGING; never for persistent use) (fastboot boot only - never flash; cache B9C / aboot untouched):
# kernel = out-b10b3 (b10b2 options; built from /home/q/aurora-kbuild/src-b10b3 = src + linux/patches/b10b3-lbc-supervisor-v3.patch).
# DTB = linux/dts/msm8916-jz08-aurora-b10b3d.dtb (TEST D: production v3 DTB with charge 4.10 V, hold 4.00 V, full-min 4.05 V, cv 5 min, timer 8 min)
# initramfs + cmdline = exact B9C (b9/b9c/out). out/ contains the B8F initramfs (Wi-Fi PSK): never publish.
set -e; cd "$(dirname "$0")"; O=out-d; KB=/home/q/aurora-kbuild/out-b10b3; L=../../linux; B9C=../../b9/b9c/out
mkdir -p $O
echo "7ca9cc794a3b85d3b7240f6311ad03bee9e1a4a59aae2ed9438318e853f7c3dc $L/dts/msm8916-jz08-aurora-b9b.dtb" | sha256sum -c
grep " initramfs-b9c.cpio.gz\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
grep " cmdline.txt\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
for s in IIO=y QCOM_SPMI_VADC=y BATTERY_PM8916_BMS_VM=y CHARGER_PM8916_LBC=y QCOM_SPMI_TEMP_ALARM=y 'LOCALVERSION="-aurora-b10b3"'; do grep -q "^CONFIG_$s\$" $KB/.config || { echo "STOP: CONFIG_$s"; exit 1; }; done
cp $KB/arch/arm64/boot/Image.gz $O/Image.gz; cp $KB/.config $O/config-b10b3; cp $L/dts/msm8916-jz08-aurora-b10b3d.dtb $O/aurora-b10b3d.dtb
cp $B9C/initramfs-b9c.cpio.gz $O/initramfs.cpio.gz; cp $B9C/cmdline.txt $O/cmdline.txt
cat $O/Image.gz $O/aurora-b10b3d.dtb > $O/Image.gz-dtb
python3 ../../b6p/mkbootimg.py $O/Image.gz-dtb $O/initramfs.cpio.gz $O/cmdline.txt $O/aurora-b10b3d.img
SZ=$(python3 -c "import struct;print(struct.unpack_from('<Q',open('$KB/arch/arm64/boot/Image','rb').read(24),16)[0])")
printf 'kernel image_size 0x%x, RAM-boot end 0x%x (< 0x81e00000 DTB)\n' $SZ $((0x80000000 + SZ)); [ $((0x80000000 + SZ)) -lt $((0x81e00000)) ]
(cd $O && sha256sum Image.gz aurora-b10b3d.dtb Image.gz-dtb config-b10b3 cmdline.txt initramfs.cpio.gz aurora-b10b3d.img > SHA256SUMS; cat SHA256SUMS); ls -l $O/aurora-b10b3d.img

View file

@ -1,19 +0,0 @@
#!/bin/sh
# B10B-3 Test D3 TEST-ONLY RAM image (D3 kernel: VDD_MAX written at CHARGING entry only if different; safety timer expiry in CHARGING; never for persistent use) (fastboot boot only - never flash; cache B9C / aboot untouched):
# kernel = out-b10b3d3 (v3 + b10/b10b3/lbc-v3-to-d3.diff; tree /home/q/aurora-kbuild/src-b10b3d3).
# DTB = linux/dts/msm8916-jz08-aurora-b10b3d.dtb (TEST D: production v3 DTB with charge 4.10 V, hold 4.00 V, full-min 4.05 V, cv 5 min, timer 8 min)
# initramfs + cmdline = exact B9C (b9/b9c/out). out/ contains the B8F initramfs (Wi-Fi PSK): never publish.
set -e; cd "$(dirname "$0")"; O=out-d3; KB=/home/q/aurora-kbuild/out-b10b3d3; L=../../linux; B9C=../../b9/b9c/out
mkdir -p $O
echo "7ca9cc794a3b85d3b7240f6311ad03bee9e1a4a59aae2ed9438318e853f7c3dc $L/dts/msm8916-jz08-aurora-b9b.dtb" | sha256sum -c
grep " initramfs-b9c.cpio.gz\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
grep " cmdline.txt\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
for s in IIO=y QCOM_SPMI_VADC=y BATTERY_PM8916_BMS_VM=y CHARGER_PM8916_LBC=y QCOM_SPMI_TEMP_ALARM=y 'LOCALVERSION="-aurora-b10b3"'; do grep -q "^CONFIG_$s\$" $KB/.config || { echo "STOP: CONFIG_$s"; exit 1; }; done
cp $KB/arch/arm64/boot/Image.gz $O/Image.gz; cp $KB/.config $O/config-b10b3; cp $L/dts/msm8916-jz08-aurora-b10b3d.dtb $O/aurora-b10b3d.dtb
cp $B9C/initramfs-b9c.cpio.gz $O/initramfs.cpio.gz; cp $B9C/cmdline.txt $O/cmdline.txt
cat $O/Image.gz $O/aurora-b10b3d.dtb > $O/Image.gz-dtb
python3 ../../b6p/mkbootimg.py $O/Image.gz-dtb $O/initramfs.cpio.gz $O/cmdline.txt $O/aurora-b10b3d3.img
SZ=$(python3 -c "import struct;print(struct.unpack_from('<Q',open('$KB/arch/arm64/boot/Image','rb').read(24),16)[0])")
printf 'kernel image_size 0x%x, RAM-boot end 0x%x (< 0x81e00000 DTB)\n' $SZ $((0x80000000 + SZ)); [ $((0x80000000 + SZ)) -lt $((0x81e00000)) ]
(cd $O && sha256sum Image.gz aurora-b10b3d.dtb Image.gz-dtb config-b10b3 cmdline.txt initramfs.cpio.gz aurora-b10b3d3.img > SHA256SUMS; cat SHA256SUMS); ls -l $O/aurora-b10b3d3.img

View file

@ -1,19 +0,0 @@
#!/bin/sh
# B10B-3 Production-profile TEST RAM image (DESIGN 8.7 final RAM run; never flash) (fastboot boot only - never flash; cache B9C / aboot untouched):
# kernel = out-b10b3 (b10b2 options; built from /home/q/aurora-kbuild/src-b10b3 = src + linux/patches/b10b3-lbc-supervisor-v3.patch).
# DTB = linux/dts/msm8916-jz08-aurora-b10b3p.dtb (production values: 4.20 V / HOLD 4.05 V / full-min 4.15 V / CV 60 min / 450 mA / 512 min; model string only differs)
# initramfs + cmdline = exact B9C (b9/b9c/out). out/ contains the B8F initramfs (Wi-Fi PSK): never publish.
set -e; cd "$(dirname "$0")"; O=out-p; KB=/home/q/aurora-kbuild/out-b10b3; L=../../linux; B9C=../../b9/b9c/out
mkdir -p $O
echo "7ca9cc794a3b85d3b7240f6311ad03bee9e1a4a59aae2ed9438318e853f7c3dc $L/dts/msm8916-jz08-aurora-b9b.dtb" | sha256sum -c
grep " initramfs-b9c.cpio.gz\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
grep " cmdline.txt\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
for s in IIO=y QCOM_SPMI_VADC=y BATTERY_PM8916_BMS_VM=y CHARGER_PM8916_LBC=y QCOM_SPMI_TEMP_ALARM=y 'LOCALVERSION="-aurora-b10b3"'; do grep -q "^CONFIG_$s\$" $KB/.config || { echo "STOP: CONFIG_$s"; exit 1; }; done
cp $KB/arch/arm64/boot/Image.gz $O/Image.gz; cp $KB/.config $O/config-b10b3; cp $L/dts/msm8916-jz08-aurora-b10b3p.dtb $O/aurora-b10b3p.dtb
cp $B9C/initramfs-b9c.cpio.gz $O/initramfs.cpio.gz; cp $B9C/cmdline.txt $O/cmdline.txt
cat $O/Image.gz $O/aurora-b10b3p.dtb > $O/Image.gz-dtb
python3 ../../b6p/mkbootimg.py $O/Image.gz-dtb $O/initramfs.cpio.gz $O/cmdline.txt $O/aurora-b10b3p.img
SZ=$(python3 -c "import struct;print(struct.unpack_from('<Q',open('$KB/arch/arm64/boot/Image','rb').read(24),16)[0])")
printf 'kernel image_size 0x%x, RAM-boot end 0x%x (< 0x81e00000 DTB)\n' $SZ $((0x80000000 + SZ)); [ $((0x80000000 + SZ)) -lt $((0x81e00000)) ]
(cd $O && sha256sum Image.gz aurora-b10b3p.dtb Image.gz-dtb config-b10b3 cmdline.txt initramfs.cpio.gz aurora-b10b3p.img > SHA256SUMS; cat SHA256SUMS); ls -l $O/aurora-b10b3p.img

View file

@ -1,19 +0,0 @@
#!/bin/sh
# B10B-3T TEST-ONLY RAM image (accelerated recharge test; never for persistent use) (fastboot boot only - never flash; cache B9C / aboot untouched):
# kernel = out-b10b3 (b10b2 options; built from /home/q/aurora-kbuild/src-b10b3 = src + linux/patches/b10b3-lbc-recharge-supervisor.patch).
# DTB = linux/dts/msm8916-jz08-aurora-b10b3t.dtb (TEST: production B10B-3 DTB with battery max 4.00 V and re-charge 3.94 V)
# initramfs + cmdline = exact B9C (b9/b9c/out). out/ contains the B8F initramfs (Wi-Fi PSK): never publish.
set -e; cd "$(dirname "$0")"; O=out-t; KB=/home/q/aurora-kbuild/out-b10b3; L=../../linux; B9C=../../b9/b9c/out
mkdir -p $O
echo "7ca9cc794a3b85d3b7240f6311ad03bee9e1a4a59aae2ed9438318e853f7c3dc $L/dts/msm8916-jz08-aurora-b9b.dtb" | sha256sum -c
grep " initramfs-b9c.cpio.gz\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
grep " cmdline.txt\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
for s in IIO=y QCOM_SPMI_VADC=y BATTERY_PM8916_BMS_VM=y CHARGER_PM8916_LBC=y QCOM_SPMI_TEMP_ALARM=y 'LOCALVERSION="-aurora-b10b3"'; do grep -q "^CONFIG_$s\$" $KB/.config || { echo "STOP: CONFIG_$s"; exit 1; }; done
cp $KB/arch/arm64/boot/Image.gz $O/Image.gz; cp $KB/.config $O/config-b10b3; cp $L/dts/msm8916-jz08-aurora-b10b3t.dtb $O/aurora-b10b3t.dtb
cp $B9C/initramfs-b9c.cpio.gz $O/initramfs.cpio.gz; cp $B9C/cmdline.txt $O/cmdline.txt
cat $O/Image.gz $O/aurora-b10b3t.dtb > $O/Image.gz-dtb
python3 ../../b6p/mkbootimg.py $O/Image.gz-dtb $O/initramfs.cpio.gz $O/cmdline.txt $O/aurora-b10b3t.img
SZ=$(python3 -c "import struct;print(struct.unpack_from('<Q',open('$KB/arch/arm64/boot/Image','rb').read(24),16)[0])")
printf 'kernel image_size 0x%x, RAM-boot end 0x%x (< 0x81e00000 DTB)\n' $SZ $((0x80000000 + SZ)); [ $((0x80000000 + SZ)) -lt $((0x81e00000)) ]
(cd $O && sha256sum Image.gz aurora-b10b3t.dtb Image.gz-dtb config-b10b3 cmdline.txt initramfs.cpio.gz aurora-b10b3t.img > SHA256SUMS; cat SHA256SUMS); ls -l $O/aurora-b10b3t.img

View file

@ -1,19 +0,0 @@
#!/bin/sh
# B10B-4 actuator-audit TEST RAM image (TEST-ONLY kernel with debugfs pm8916_lbc/b10b4; never flash, never cache) (fastboot boot only - never flash; cache B9C / aboot untouched):
# kernel = out-b10b4 (7.2.7-aurora-b10b4-debug = v3 + b10/b10b3/lbc-v3-to-b10b4-debug.diff, CHARGER_PM8916_LBC_B10B4_DEBUG=y; tree src-b10b4).
# DTB = linux/dts/msm8916-jz08-aurora-b10b4.dtb (production values: 4.20 V / HOLD 4.05 V / full-min 4.15 V / CV 60 min / 450 mA / 512 min; model string only differs)
# initramfs + cmdline = exact B9C (b9/b9c/out). out/ contains the B8F initramfs (Wi-Fi PSK): never publish.
set -e; cd "$(dirname "$0")"; O=out-b4; KB=/home/q/aurora-kbuild/out-b10b4; L=../../linux; B9C=../../b9/b9c/out
mkdir -p $O
echo "7ca9cc794a3b85d3b7240f6311ad03bee9e1a4a59aae2ed9438318e853f7c3dc $L/dts/msm8916-jz08-aurora-b9b.dtb" | sha256sum -c
grep " initramfs-b9c.cpio.gz\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
grep " cmdline.txt\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
for s in IIO=y QCOM_SPMI_VADC=y BATTERY_PM8916_BMS_VM=y CHARGER_PM8916_LBC=y QCOM_SPMI_TEMP_ALARM=y 'LOCALVERSION="-aurora-b10b4-debug"' CHARGER_PM8916_LBC_B10B4_DEBUG=y; do grep -q "^CONFIG_$s\$" $KB/.config || { echo "STOP: CONFIG_$s"; exit 1; }; done
cp $KB/arch/arm64/boot/Image.gz $O/Image.gz; cp $KB/.config $O/config-b10b4; cp $L/dts/msm8916-jz08-aurora-b10b4.dtb $O/aurora-b10b4.dtb
cp $B9C/initramfs-b9c.cpio.gz $O/initramfs.cpio.gz; cp $B9C/cmdline.txt $O/cmdline.txt
cat $O/Image.gz $O/aurora-b10b4.dtb > $O/Image.gz-dtb
python3 ../../b6p/mkbootimg.py $O/Image.gz-dtb $O/initramfs.cpio.gz $O/cmdline.txt $O/aurora-b10b4.img
SZ=$(python3 -c "import struct;print(struct.unpack_from('<Q',open('$KB/arch/arm64/boot/Image','rb').read(24),16)[0])")
printf 'kernel image_size 0x%x, RAM-boot end 0x%x (< 0x81e00000 DTB)\n' $SZ $((0x80000000 + SZ)); [ $((0x80000000 + SZ)) -lt $((0x81e00000)) ]
(cd $O && sha256sum Image.gz aurora-b10b4.dtb Image.gz-dtb config-b10b4 cmdline.txt initramfs.cpio.gz aurora-b10b4.img > SHA256SUMS; cat SHA256SUMS); ls -l $O/aurora-b10b4.img

View file

@ -1,21 +0,0 @@
#!/bin/sh
# B10B-5 PRODUCTION v4 image (v3 + FAULT safe clamp to 4.00 V; no test hooks) - RAM pretest + parts for the cache candidate (fastboot boot only - never flash):
# kernel = out-b10b5 (7.2.7-aurora-b10b5 = v3 + b10/b10b3/lbc-v3-to-v4-fault-clamp.diff; tree src-b10b5; config = b10b3 + LOCALVERSION only).
# DTB = linux/dts/msm8916-jz08-aurora-b10b3.dtb (production v3 values: 4.20 V / HOLD 4.05 V / full-min 4.15 V / CV 60 min / 450 mA / 512 min)
# initramfs + cmdline = exact B9C (b9/b9c/out). out/ contains the B8F initramfs (Wi-Fi PSK): never publish.
set -e; cd "$(dirname "$0")"; O=out-v4; KB=/home/q/aurora-kbuild/out-b10b5; L=../../linux; B9C=../../b9/b9c/out
mkdir -p $O
echo "7ca9cc794a3b85d3b7240f6311ad03bee9e1a4a59aae2ed9438318e853f7c3dc $L/dts/msm8916-jz08-aurora-b9b.dtb" | sha256sum -c
grep " initramfs-b9c.cpio.gz\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
grep " cmdline.txt\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
for s in IIO=y QCOM_SPMI_VADC=y BATTERY_PM8916_BMS_VM=y CHARGER_PM8916_LBC=y QCOM_SPMI_TEMP_ALARM=y 'LOCALVERSION="-aurora-b10b5"'; do grep -q "^CONFIG_$s\$" $KB/.config || { echo "STOP: CONFIG_$s"; exit 1; }; done
grep -q "B10B5_TEST\|B10B4_DEBUG" $KB/.config && { echo "STOP: test hook symbol in production config"; exit 1; }
zcat $KB/arch/arm64/boot/Image.gz | strings | grep -qE "B10B-5 TEST|B10B-4 TEST" && { echo "STOP: test hook strings in production kernel"; exit 1; }
cp $KB/arch/arm64/boot/Image.gz $O/Image.gz; cp $KB/.config $O/config-b10b5; cp $L/dts/msm8916-jz08-aurora-b10b3.dtb $O/aurora-b10b3.dtb
cp $B9C/initramfs-b9c.cpio.gz $O/initramfs.cpio.gz; cp $B9C/cmdline.txt $O/cmdline.txt
cat $O/Image.gz $O/aurora-b10b3.dtb > $O/Image.gz-dtb
python3 ../../b6p/mkbootimg.py $O/Image.gz-dtb $O/initramfs.cpio.gz $O/cmdline.txt $O/aurora-b10b5.img
SZ=$(python3 -c "import struct;print(struct.unpack_from('<Q',open('$KB/arch/arm64/boot/Image','rb').read(24),16)[0])")
printf 'kernel image_size 0x%x, RAM-boot end 0x%x (< 0x81e00000 DTB)\n' $SZ $((0x80000000 + SZ)); [ $((0x80000000 + SZ)) -lt $((0x81e00000)) ]
(cd $O && sha256sum Image.gz aurora-b10b3.dtb Image.gz-dtb config-b10b5 cmdline.txt initramfs.cpio.gz aurora-b10b5.img > SHA256SUMS; cat SHA256SUMS); ls -l $O/aurora-b10b5.img

View file

@ -1,19 +0,0 @@
#!/bin/sh
# B10B-5 FAULT-clamp regression TEST RAM image (TEST-ONLY kernel v4 + debugfs pm8916_lbc/b10b5_fault; never flash, never cache) (fastboot boot only - never flash; cache B9C / aboot untouched):
# kernel = out-b10b5 test build (7.2.7-aurora-b10b5-test = v4 [lbc-v3-to-v4-fault-clamp.diff] + lbc-v4-to-v4test-fault-inject.diff, CHARGER_PM8916_LBC_B10B5_TEST=y; tree src-b10b5).
# DTB = linux/dts/msm8916-jz08-aurora-b10b5t.dtb (production values: 4.20 V / HOLD 4.05 V / full-min 4.15 V / CV 60 min / 450 mA / 512 min; model string only differs)
# initramfs + cmdline = exact B9C (b9/b9c/out). out/ contains the B8F initramfs (Wi-Fi PSK): never publish.
set -e; cd "$(dirname "$0")"; O=out-b5t; KB=/home/q/aurora-kbuild/out-b10b5; L=../../linux; B9C=../../b9/b9c/out
mkdir -p $O
echo "7ca9cc794a3b85d3b7240f6311ad03bee9e1a4a59aae2ed9438318e853f7c3dc $L/dts/msm8916-jz08-aurora-b9b.dtb" | sha256sum -c
grep " initramfs-b9c.cpio.gz\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
grep " cmdline.txt\$" $B9C/SHA256SUMS | sed "s| | $B9C/|" | sha256sum -c
for s in IIO=y QCOM_SPMI_VADC=y BATTERY_PM8916_BMS_VM=y CHARGER_PM8916_LBC=y QCOM_SPMI_TEMP_ALARM=y 'LOCALVERSION="-aurora-b10b5-test"' CHARGER_PM8916_LBC_B10B5_TEST=y; do grep -q "^CONFIG_$s\$" $KB/.config || { echo "STOP: CONFIG_$s"; exit 1; }; done
cp $KB/arch/arm64/boot/Image.gz $O/Image.gz; cp $KB/.config $O/config-b10b5t; cp $L/dts/msm8916-jz08-aurora-b10b5t.dtb $O/aurora-b10b5t.dtb
cp $B9C/initramfs-b9c.cpio.gz $O/initramfs.cpio.gz; cp $B9C/cmdline.txt $O/cmdline.txt
cat $O/Image.gz $O/aurora-b10b5t.dtb > $O/Image.gz-dtb
python3 ../../b6p/mkbootimg.py $O/Image.gz-dtb $O/initramfs.cpio.gz $O/cmdline.txt $O/aurora-b10b5t.img
SZ=$(python3 -c "import struct;print(struct.unpack_from('<Q',open('$KB/arch/arm64/boot/Image','rb').read(24),16)[0])")
printf 'kernel image_size 0x%x, RAM-boot end 0x%x (< 0x81e00000 DTB)\n' $SZ $((0x80000000 + SZ)); [ $((0x80000000 + SZ)) -lt $((0x81e00000)) ]
(cd $O && sha256sum Image.gz aurora-b10b5t.dtb Image.gz-dtb config-b10b5t cmdline.txt initramfs.cpio.gz aurora-b10b5t.img > SHA256SUMS; cat SHA256SUMS); ls -l $O/aurora-b10b5t.img

View file

@ -1,4 +0,0 @@
c37325156a6f4c013982cf01bcb5b2ddb026b0298e9c3ec0be87f57d693464b8 cache-extlinux-b10b5.img
7e80063945bcd017d61c3ef285f14b7216a54ca103c796d67628fff917a7b83d mkfs-cache-b10b5.sh
b6d9ecdc0cc09528704ffca440f645ac1438c0ffc81176591c2c92ba6d4b4d1c extlinux-b10b5.conf
98bfaf2d8d44698bcc33181fd89d339a8eb3b01ccdfea5c6df71d70f6369e256 emu/run-emu-b10b5.sh

View file

@ -1,10 +0,0 @@
== cache-extlinux-b10b3
5e69f8431d42a9ddb9d64f06dcc408cd8dbfa9dffdba7e9b06e4ba58075ed1c7 Image.gz-dtb
e47762d1dcd0af6e2acb711fa47ecc13769cd6bcb81259ce50635e8b18b6514a aurora-b10b3.dtb
9b6584fcc71ae74f6c84cba6c9bcd2576ae8c59edee2fad5b9d0753f54f8ca19 extlinux_extlinux.conf
ac518e27e2957ad5e4515969b9a3808024e11ef8d1a79433a899a67dbc644558 initramfs-b9c.cpio.gz
== cache-extlinux-b10b5
b0ea04666c4ab979067fe9c0015bda0e9c8ac742678321e57b18e841c9c69f95 Image.gz-dtb
e47762d1dcd0af6e2acb711fa47ecc13769cd6bcb81259ce50635e8b18b6514a aurora-b10b3.dtb
b6d9ecdc0cc09528704ffca440f645ac1438c0ffc81176591c2c92ba6d4b4d1c extlinux_extlinux.conf
ac518e27e2957ad5e4515969b9a3808024e11ef8d1a79433a899a67dbc644558 initramfs-b9c.cpio.gz

View file

@ -1,13 +0,0 @@
#!/bin/bash
# lk2nd-23.1 extlinux emulator (b5b/emu) on: S8 (B9C cache = current flash, regression vs b9/b9c/cache/emu S7), S10 B10B-5 (v4) candidate, fault variants. Offline, 480s.
cd ~/doc/modem/jz08-aurora/b10/b10b3/cache-v4/emu; E=../../../../b5b/emu; GPT=../../../../logs/b5a/A3/gpt-primary-34.bin; C=/home/q/doc/modem/jz08-aurora/b10/b10b3/cache-v4/cache-extlinux-b10b5.img
run() { python3 $E/mkmap.py $2 > map-$1.txt; $E/lk2nd-scan-emu map-$1.txt $GPT $3 > $1.out 2>&1; echo "== $1 rc=$? :: $(grep -E "Trying to boot|Reverting|boot_linux reached|ramdisk sha256|Could not" $1.out | tr '\n' ' ' | cut -c1-260)"; }
run S8-b9c-regression /home/q/doc/modem/jz08-aurora/b9/b9c/cache/cache-extlinux-b9c.img 24686600
cmp <(grep HARNESS S8-b9c-regression.out) <(grep HARNESS ../../../../b9/b9c/cache/emu/S7-b9c-candidate.out) && echo " S8 HARNESS lines == b9/b9c/cache/emu/S7-b9c-candidate.out"
run S10-b10b5-candidate $C 24754184; # kernel_len = b10b5 Image (8c8bfccb, 24754184 B)
grep HARNESS S10-b10b5-candidate.out
D=$(mktemp -d); v(){ cp $C $D/$1.img; chmod u+w $D/$1.img; }
v F3-no-initrd; /sbin/debugfs -w -R "rm /initramfs-b9c.cpio.gz" $D/F3-no-initrd.img >/dev/null 2>&1
v F1-no-conf; /sbin/debugfs -w -R "rm /extlinux/extlinux.conf" $D/F1-no-conf.img >/dev/null 2>&1
head -c 134217728 /dev/zero > $D/F10-zeroed-cache.img
for f in $D/F*.img; do run $(basename $f .img) $f; done; rm -rf $D

View file

@ -1,6 +0,0 @@
default b10b5
label b10b5
linux /Image.gz-dtb
fdt /aurora-b10b3.dtb
initrd /initramfs-b9c.cpio.gz
append earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0

View file

@ -1,27 +0,0 @@
#!/bin/bash
# B10B-5 cache CANDIDATE (v4 = v3 + FAULT safe clamp; NOT for writing without a separate GO): exact recipe of b10/b10b3/cache/mkfs-cache-b10b3.sh (86869061);
# differs only in the kernel file (Image.gz-dtb = kernel 7.2.7-aurora-b10b5 96b71ec3 + the same production DTB e47762d1),
# fdt (production DTB), file names, extlinux label, fs label and UUIDs. initrd and append = B9C unchanged. Runs on 480s (mke2fs 1.47.2). Offline only.
# The image contains the AP PSK (in the initramfs) - never publish it.
set -e
cd ~/doc/modem/jz08-aurora/b10/b10b3/cache-v4
OUT=${1:-cache-extlinux-b10b5.img}; F=../out-v4
echo "0fef41b262917c8ae308fa222da0017e2b3cb3ec5da1ca8ba18d0318476761a3 $F/cmdline.txt" | sha256sum -c
echo "b0ea04666c4ab979067fe9c0015bda0e9c8ac742678321e57b18e841c9c69f95 $F/Image.gz-dtb" | sha256sum -c
echo "e47762d1dcd0af6e2acb711fa47ecc13769cd6bcb81259ce50635e8b18b6514a $F/aurora-b10b3.dtb" | sha256sum -c
echo "ac518e27e2957ad5e4515969b9a3808024e11ef8d1a79433a899a67dbc644558 $F/initramfs.cpio.gz" | sha256sum -c
ST=$(mktemp -d); mkdir -p $ST/extlinux
cp $F/Image.gz-dtb $F/aurora-b10b3.dtb $ST/; cp $F/initramfs.cpio.gz $ST/initramfs-b9c.cpio.gz
printf "default b10b5\nlabel b10b5\n\tlinux /Image.gz-dtb\n\tfdt /aurora-b10b3.dtb\n\tinitrd /initramfs-b9c.cpio.gz\n\tappend %s\n" "$(cat $F/cmdline.txt)" > $ST/extlinux/extlinux.conf
cp $ST/extlinux/extlinux.conf extlinux-b10b5.conf
chmod 0644 $ST/*.* $ST/extlinux/extlinux.conf; chmod 0755 $ST $ST/extlinux
find $ST -exec touch -h -d @1790726400 {} +
rm -f $OUT; truncate -s 134217728 $OUT
E2FSPROGS_FAKE_TIME=1790726400 /sbin/mke2fs -F -q -t ext2 -O none,filetype,sparse_super \
-b 4096 -I 128 -N 64 -m 0 -L aurora-b10b5 -U 4a5a3038-b6f0-4000-8000-0000b10b5c00 \
-E root_owner=0:0,hash_seed=4a5a3038-b6f0-4000-8000-0000b10b5c01 -d $ST $OUT 32768
rm -rf $ST
for f in / /lost+found /extlinux /extlinux/extlinux.conf /Image.gz-dtb /aurora-b10b3.dtb /initramfs-b9c.cpio.gz; do for t in atime ctime mtime; do echo "sif $f $t @1790726400"; done; done > /tmp/b10b5-sif.$$
/sbin/debugfs -w -f /tmp/b10b5-sif.$$ $OUT >/dev/null 2>&1; rm -f /tmp/b10b5-sif.$$
/sbin/e2fsck -fn $OUT >/dev/null 2>&1 && echo "e2fsck -fn clean"
stat -c "%n %s" $OUT; sha256sum $OUT

View file

@ -1,56 +0,0 @@
# B10B-3 cache candidate — prepared, NOT written, NOT ready for persistent deployment
Date: 2026-10-04. **Status: candidate prepared and RAM-pretested; no cache/eMMC write. Persistent GO blocked (see Blocker).**
Contains the AP PSK (B8F initramfs) — never publish.
## Candidate
`cache-extlinux-b10b3.img` **86869061fcc971131068644542547893332f3ede9870a324eaf360824610d40a** (134217728 B, ext2, label aurora-b10b3,
UUID 4a5a3038-b6f0-4000-8000-0000b10b3c00). Built on 480s by `mkfs-cache-b10b3.sh` (278130cf) = exact B9C recipe (`b9/b9c/cache/mkfs-cache-b9c.sh`);
rebuild bit-identical; `e2fsck -fn` clean. `SHA256SUMS` in this directory.
## Composition and diff vs the live B9C cache (b9ce13c9) — `cache-contents-b9c-vs-b10b3.txt`
| file | B9C | candidate |
|---|---|---|
| /Image.gz-dtb | 632a7be8 (kernel 7.2.7-aurora-b9c + B9B DTB) | **5e69f843** (kernel 7.2.7-aurora-b10b3 1164b1c7 + production DTB) |
| DTB (fdt) | /aurora-b9c.dtb 7ca9cc79 | **/aurora-b10b3.dtb e47762d1** (`linux/dts/msm8916-jz08-aurora-b10b3.dts`) |
| /initramfs-b9c.cpio.gz | ac518e27 | ac518e27 (unchanged: B9C userspace/init/display/network) |
| extlinux.conf | label b9c, fdt aurora-b9c.dtb | label b10b3, fdt aurora-b10b3.dtb; **append identical** |
Really replaced: the kernel file and the DTB (plus label/fdt name in extlinux.conf). Kernel config b10b3 = B9C config + CHARGER_PM8916_LBC,
BATTERY_PM8916_BMS_VM, IIO, QCOM_SPMI_VADC, QCOM_VADC_COMMON, QCOM_SPMI_TEMP_ALARM (+ LOCALVERSION). Driver = v3 (`linux/patches/b10b3-lbc-supervisor-v3.patch`),
**no D3 change**. DTB = B9B DTB + layers b10b0 (VADC VBAT ch6) / b10b1 (battery 3000 mAh, BMS) / b10b2 (charger on, usbin off, extcon) / b10b3 (supervisor).
## DTB check (fdtget, /soc@0/spmi@200f000/pmic@0/charger@1000)
status "okay"; qcom,fast-charge-safe-voltage 4200000; qcom,fast-charge-safe-current 500000 (→ IBAT_MAX 450 mA); qcom,charge-timeout-minutes 512;
aurora,hold-voltage-microvolt 4050000; aurora,full-min-voltage-microvolt 4150000; aurora,cv-hold-minutes 60; io-channel-names "vbat";
/battery voltage-max-design-microvolt 4200000, charge-full-design 3000000; re-charge-voltage absent. No Test-C/B/D/T values (4.10/4.00 V, 5/2 min,
8 min, 3.94 V) present. The DTB appended to Image.gz-dtb is byte-identical to the fdt file. Model string "JZ08AU Aurora (RAM boot B10B-3)" (cosmetic).
## lk2nd emulator (`emu/run-emu-b10b3.sh`, b5b/emu)
- S8 regression on the live B9C cache == b9/b9c/cache/emu S7 (HARNESS lines identical).
- S9 candidate: "Trying to boot 'b10b3'", kernel 5afd371e (24754184 B, image_size 0x1830000, ends DDR+0x1830000), DTB e47762d1 @DDR+0x20A9000,
ramdisk ac518e27 @DDR+0x22A9000 — no overlap; cmdline = B9C.
- F1 (no conf) / F3 (no initrd) / F10 (zeroed cache) → "Reverting to android boot" (emmc1 fallback).
## RAM pretest (class A, run cand1; `logs/b10/b10b3/cand1*`, `pre-cand-classA-*`)
RAM image `b10/b10b3/out/aurora-b10b3.img` b7dc34e9 = same kernel/DTB/initramfs/cmdline as the candidate. Class A proven (RTC 3 s, SBL charger
defaults, dump diff ADC/BMS/RTC only). RESET-held boot (stage-3 again, RTC 5 s — harness only).
- probe: `safety timer 512 min (TCHG_MAX 0x7f), enabled`; `supervisor v3: charge 4200000, hold 4050000, full-min 4150000, cv 60 min, IBAT_MAX code 4`;
`INIT -> CHARGING (probe, usb present)` at 4.072 V.
- registers: VDD_MAX 08 (4.20 V), IBAT_MAX 04 (450 mA), CHG_CTRL a0, TCHG 80/7f, BOOT_DONE 80, CHG_FAILED 00, CHG_STATUS 05; no latch; 0 ALERT.
- VADC: VBAT 4.159 V (under charge), USBIN 4.884 V; PMIC 45.7 °C (VADC) / 44.6 °C (pm8916-thermal), CPU ≈ 44–46 °C.
- LTE START OK 73.7 s, ping 4/4; Wi-Fi AP enabled 77.3 s, MSS + WCNSS running; NCM ok; DISPLAY READY 7.8 s (fbcon bound, backlight on, 0 errors);
eMMC writes 0. 60-min CV/HOLD not repeated (state machine validated in B10B3-RESULT.md).
Board left CHARGING on the RAM pretest image; nothing written.
## Blocker before any persistent GO
**FAULT currently has no verified physical charge-stop actuator; the safety timer also does not stop charging** (Test D4: expiry only ends the
fast-charge state, current continues, CHG_FAILED not set; CHG_EN = 0 does not stop the LBC). FAULT in v3 is logical only.
## Proposed next test (needs a separate GO; RAM only, not executed)
**B10B-4 — emergency actuator search.** Test-only kernel hook (debugfs, RAM image only) or manual regmap writes per approved list, each step:
class-A start, CHARGING at ≈ 0.4 A, apply one actuator, observe USB current (meter), CHG_STATUS, RT, path, VBAT, PMIC 30–60 s, then revert:
1. USB_SUSP (0x1347 bit0 = 1): does input current go to ≈ 0, does the board drop to battery, does it survive; release → recovery.
2. IBAT_MAX minimum (0x1044 = 00, 90 mA): residual current with the board load.
3. VDD_MAX minimum (0x1040 = 00, 4.00 V) when VBAT > 4.00 V: does charging stop (HOLD phase-1 already suggests yes).
4. Combination (2 + 3) and, if 1 works, 1 alone as the FAULT action.
Pass criterion for an actuator: battery current stops within seconds, no 00/01 latch, board keeps running (from USB or battery), reversible.

View file

@ -1,4 +0,0 @@
86869061fcc971131068644542547893332f3ede9870a324eaf360824610d40a cache-extlinux-b10b3.img
278130cfeabdc625c91accd2f29d660f65eec4b04f917325f43d574711df64fb mkfs-cache-b10b3.sh
9b6584fcc71ae74f6c84cba6c9bcd2576ae8c59edee2fad5b9d0753f54f8ca19 extlinux-b10b3.conf
d34697d23c65fa5d31478522b5551b074f208e5314e4e4b0ba72a5be819f105a emu/run-emu-b10b3.sh

View file

@ -1,10 +0,0 @@
== cache-extlinux-b10b3
5e69f8431d42a9ddb9d64f06dcc408cd8dbfa9dffdba7e9b06e4ba58075ed1c7 Image.gz-dtb
e47762d1dcd0af6e2acb711fa47ecc13769cd6bcb81259ce50635e8b18b6514a aurora-b10b3.dtb
9b6584fcc71ae74f6c84cba6c9bcd2576ae8c59edee2fad5b9d0753f54f8ca19 extlinux_extlinux.conf
ac518e27e2957ad5e4515969b9a3808024e11ef8d1a79433a899a67dbc644558 initramfs-b9c.cpio.gz
== cache-extlinux-b9c
632a7be801978dfaddeae633d5293b3abe385f2281cc5053772e6637897a7e5a Image.gz-dtb
7ca9cc794a3b85d3b7240f6311ad03bee9e1a4a59aae2ed9438318e853f7c3dc aurora-b9c.dtb
7facbd7aec20d7a823f23a824172448dd3d21a3f9bc9cc422fe6ef4565d52e90 extlinux_extlinux.conf
ac518e27e2957ad5e4515969b9a3808024e11ef8d1a79433a899a67dbc644558 initramfs-b9c.cpio.gz

View file

@ -1,13 +0,0 @@
#!/bin/bash
# lk2nd-23.1 extlinux emulator (b5b/emu) on: S8 (B9C cache = current flash, regression vs b9/b9c/cache/emu S7), S9 B10B-3 candidate, fault variants. Offline, 480s.
cd ~/doc/modem/jz08-aurora/b10/b10b3/cache/emu; E=../../../../b5b/emu; GPT=../../../../logs/b5a/A3/gpt-primary-34.bin; C=/home/q/doc/modem/jz08-aurora/b10/b10b3/cache/cache-extlinux-b10b3.img
run() { python3 $E/mkmap.py $2 > map-$1.txt; $E/lk2nd-scan-emu map-$1.txt $GPT $3 > $1.out 2>&1; echo "== $1 rc=$? :: $(grep -E "Trying to boot|Reverting|boot_linux reached|ramdisk sha256|Could not" $1.out | tr '\n' ' ' | cut -c1-260)"; }
run S8-b9c-regression /home/q/doc/modem/jz08-aurora/b9/b9c/cache/cache-extlinux-b9c.img 24686600
cmp <(grep HARNESS S8-b9c-regression.out) <(grep HARNESS ../../../../b9/b9c/cache/emu/S7-b9c-candidate.out) && echo " S8 HARNESS lines == b9/b9c/cache/emu/S7-b9c-candidate.out"
run S9-b10b3-candidate $C 24754184; # kernel_len = b10b3 Image (5afd371e, 24754184 B)
grep HARNESS S9-b10b3-candidate.out
D=$(mktemp -d); v(){ cp $C $D/$1.img; chmod u+w $D/$1.img; }
v F3-no-initrd; /sbin/debugfs -w -R "rm /initramfs-b9c.cpio.gz" $D/F3-no-initrd.img >/dev/null 2>&1
v F1-no-conf; /sbin/debugfs -w -R "rm /extlinux/extlinux.conf" $D/F1-no-conf.img >/dev/null 2>&1
head -c 134217728 /dev/zero > $D/F10-zeroed-cache.img
for f in $D/F*.img; do run $(basename $f .img) $f; done; rm -rf $D

View file

@ -1,6 +0,0 @@
default b10b3
label b10b3
linux /Image.gz-dtb
fdt /aurora-b10b3.dtb
initrd /initramfs-b9c.cpio.gz
append earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0

View file

@ -1,27 +0,0 @@
#!/bin/bash
# B10B-3 cache CANDIDATE (not for writing without a separate GO): exact recipe of b9/b9c/cache/mkfs-cache-b9c.sh (b9ce13c9); differs only in
# the kernel file (b10b3 production Image.gz-dtb = kernel 7.2.7-aurora-b10b3 1164b1c7 + production DTB msm8916-jz08-aurora-b10b3 e47762d1),
# fdt (production DTB), file names, extlinux label, fs label and UUIDs. initrd and append = B9C unchanged. Runs on 480s (mke2fs 1.47.2). Offline only.
# The image contains the AP PSK (in the initramfs) - never publish it.
set -e
cd ~/doc/modem/jz08-aurora/b10/b10b3/cache
OUT=${1:-cache-extlinux-b10b3.img}; F=../out
echo "0fef41b262917c8ae308fa222da0017e2b3cb3ec5da1ca8ba18d0318476761a3 $F/cmdline.txt" | sha256sum -c
echo "5e69f8431d42a9ddb9d64f06dcc408cd8dbfa9dffdba7e9b06e4ba58075ed1c7 $F/Image.gz-dtb" | sha256sum -c
echo "e47762d1dcd0af6e2acb711fa47ecc13769cd6bcb81259ce50635e8b18b6514a $F/aurora-b10b3.dtb" | sha256sum -c
echo "ac518e27e2957ad5e4515969b9a3808024e11ef8d1a79433a899a67dbc644558 $F/initramfs.cpio.gz" | sha256sum -c
ST=$(mktemp -d); mkdir -p $ST/extlinux
cp $F/Image.gz-dtb $F/aurora-b10b3.dtb $ST/; cp $F/initramfs.cpio.gz $ST/initramfs-b9c.cpio.gz
printf "default b10b3\nlabel b10b3\n\tlinux /Image.gz-dtb\n\tfdt /aurora-b10b3.dtb\n\tinitrd /initramfs-b9c.cpio.gz\n\tappend %s\n" "$(cat $F/cmdline.txt)" > $ST/extlinux/extlinux.conf
cp $ST/extlinux/extlinux.conf extlinux-b10b3.conf
chmod 0644 $ST/*.* $ST/extlinux/extlinux.conf; chmod 0755 $ST $ST/extlinux
find $ST -exec touch -h -d @1790726400 {} +
rm -f $OUT; truncate -s 134217728 $OUT
E2FSPROGS_FAKE_TIME=1790726400 /sbin/mke2fs -F -q -t ext2 -O none,filetype,sparse_super \
-b 4096 -I 128 -N 64 -m 0 -L aurora-b10b3 -U 4a5a3038-b6f0-4000-8000-0000b10b3c00 \
-E root_owner=0:0,hash_seed=4a5a3038-b6f0-4000-8000-0000b10b3c01 -d $ST $OUT 32768
rm -rf $ST
for f in / /lost+found /extlinux /extlinux/extlinux.conf /Image.gz-dtb /aurora-b10b3.dtb /initramfs-b9c.cpio.gz; do for t in atime ctime mtime; do echo "sif $f $t @1790726400"; done; done > /tmp/b10b3-sif.$$
/sbin/debugfs -w -f /tmp/b10b3-sif.$$ $OUT >/dev/null 2>&1; rm -f /tmp/b10b3-sif.$$
/sbin/e2fsck -fn $OUT >/dev/null 2>&1 && echo "e2fsck -fn clean"
stat -c "%n %s" $OUT; sha256sum $OUT

View file

@ -1,176 +0,0 @@
--- v1
+++ v2
@@ -99,14 +99,12 @@
int state;
int fault_reason;
unsigned int recharge_uv; /* production threshold from monitored-battery */
- u32 test_recharge_uv; /* debugfs test-only override, 0 = off */
unsigned int timeout_min;
int vbat_uv;
int done_polls;
int low_polls;
unsigned int n_terminated;
unsigned int n_recharge;
- unsigned int n_forced;
struct {
time64_t t;
int from, to, vbat;
@@ -279,9 +277,12 @@
/*
* Aurora B10B-3 recharge supervisor.
- * The LBC ends a charge cycle in hardware (iterm comparator) and then stays off until software gives CHG_EN a
- * 0 -> 1 edge (downstream qpnp-linear-charger did this from BMS SOC / VBAT_DET IRQ). This supervisor polls the
- * VADC VBAT every 30 s and restarts charging when VBAT stays below the monitored-battery
+ * The LBC ends a charge cycle in hardware (end-of-charge latch: CHG_STATUS 00, USB path 01, USB input ~0) and then
+ * stays off until software gives CHG_EN a 0 -> 1 edge (downstream qpnp-linear-charger did this from BMS SOC /
+ * VBAT_DET IRQ). Verified on Aurora (B10B-3 ram1): CHG_CTRL 0x21 -> 0xa0 releases the latch.
+ * Also verified: writing CHG_EN = 0 does NOT stop the charger (USB input stays ~0.36 A), so the supervisor never
+ * uses CHG_CTRL to "turn charging off"; TERMINATED is only the hardware latch, observed after CHARGING.
+ * The supervisor polls the VADC VBAT every 30 s and restarts charging when VBAT stays below the monitored-battery
* re-charge-voltage-microvolt for 3 consecutive polls.
*/
static void lbc_supv_log(struct pm8916_lbc_charger *chg, int to, const char *why)
@@ -306,7 +307,7 @@
en ? PM8916_LBC_CHGR_CHG_EN : PM8916_LBC_CHGR_FORCE_BATT_ON);
}
-/* explicit CHG_EN 0 -> 1 edge; on (re)insert also clear a latched CHG_FAILED */
+/* the verified restart: CHG_CTRL 0x21 (CHG_EN 0) -> 20 ms -> 0xa0 (CHG_EN 1); on (re)insert also clear CHG_FAILED */
static int lbc_charge_restart(struct pm8916_lbc_charger *chg, bool clear_failed)
{
int ret;
@@ -324,11 +325,6 @@
return lbc_charge_enable(chg, true);
}
-static unsigned int lbc_recharge_uv(struct pm8916_lbc_charger *chg)
-{
- return chg->test_recharge_uv ? chg->test_recharge_uv : chg->recharge_uv;
-}
-
static void lbc_supv_work(struct work_struct *work)
{
struct pm8916_lbc_charger *chg = container_of(work, struct pm8916_lbc_charger, supv_work.work);
@@ -351,8 +347,8 @@
chg->vbat_uv = -1;
if (!(usb_rt & PM8916_LBC_USB_USBIN_VALID)) {
+ /* CHG_CTRL untouched; the next insert restarts with the verified edge */
if (chg->state != LBC_ST_NO_USB) {
- lbc_charge_enable(chg, false);
chg->fault_reason = LBC_FAULT_NONE;
lbc_supv_log(chg, LBC_ST_NO_USB, "usb removed");
}
@@ -372,24 +368,27 @@
break;
case LBC_ST_CHARGING:
- if (chg->vbat_uv > PM8916_LBC_SUPV_OVP_UV) {
- lbc_charge_enable(chg, false);
- chg->fault_reason = LBC_FAULT_OVP;
- lbc_supv_log(chg, LBC_ST_FAULT, "vbat > 4.25 V");
- break;
- }
+ /*
+ * Safety timer expiry: the hardware stops and sets CHG_FAILED. Latch FAULT so the supervisor never
+ * restarts; no register write (CHG_EN = 0 is not a verified way to stop the charger).
+ */
if (failed & PM8916_LBC_CHGR_CHG_FAILED_BIT) {
- lbc_charge_enable(chg, false);
chg->fault_reason = LBC_FAULT_TIMER;
lbc_supv_log(chg, LBC_ST_FAULT, "CHG_FAILED (safety timer)");
break;
}
+ if (chg->vbat_uv > PM8916_LBC_SUPV_OVP_UV) {
+ /* defence only: VDD_MAX regulates in hardware; latch FAULT = no further restarts */
+ chg->fault_reason = LBC_FAULT_OVP;
+ lbc_supv_log(chg, LBC_ST_FAULT, "vbat > 4.25 V");
+ break;
+ }
+ /* TERMINATED = hardware end-of-charge latch only; CHG_CTRL is not changed */
if (sts == 0 && !(path & PM8916_LBC_USB_PATH_ON))
chg->done_polls++;
else
chg->done_polls = 0;
if (chg->done_polls >= PM8916_LBC_SUPV_DONE_POLLS) {
- lbc_charge_enable(chg, false);
chg->n_terminated++;
chg->low_polls = 0;
lbc_supv_log(chg, LBC_ST_TERMINATED, "hardware end of charge");
@@ -397,18 +396,18 @@
break;
case LBC_ST_TERMINATED:
- if (!lbc_recharge_uv(chg) || chg->vbat_uv < 0)
+ if (!chg->recharge_uv || chg->vbat_uv < 0)
break;
- if ((unsigned int)chg->vbat_uv < lbc_recharge_uv(chg))
+ if ((unsigned int)chg->vbat_uv < chg->recharge_uv)
chg->low_polls++;
else
chg->low_polls = 0;
if (chg->low_polls >= PM8916_LBC_SUPV_LOW_POLLS) {
chg->done_polls = 0;
- if (!lbc_charge_enable(chg, true)) {
+ chg->low_polls = 0;
+ if (!lbc_charge_restart(chg, false)) {
chg->n_recharge++;
- lbc_supv_log(chg, LBC_ST_CHARGING,
- chg->test_recharge_uv ? "recharge (TEST threshold)" : "recharge");
+ lbc_supv_log(chg, LBC_ST_CHARGING, "recharge");
}
}
break;
@@ -446,11 +445,9 @@
mutex_lock(&chg->supv_lock);
seq_printf(s, "state %s fault %s vbat_uv %d\n", lbc_state_name[chg->state],
lbc_fault_name[chg->fault_reason], chg->vbat_uv);
- seq_printf(s, "recharge_uv %u (production %u, test %u) done_polls %d low_polls %d timeout_min %u\n",
- lbc_recharge_uv(chg), chg->recharge_uv, chg->test_recharge_uv, chg->done_polls,
- chg->low_polls, chg->timeout_min);
- seq_printf(s, "n_terminated %u n_recharge %u n_forced %u\n", chg->n_terminated,
- chg->n_recharge, chg->n_forced);
+ seq_printf(s, "recharge_uv %u done_polls %d low_polls %d timeout_min %u\n",
+ chg->recharge_uv, chg->done_polls, chg->low_polls, chg->timeout_min);
+ seq_printf(s, "n_terminated %u n_recharge %u\n", chg->n_terminated, chg->n_recharge);
for (i = 0; i < ARRAY_SIZE(regs); i++) {
if (regmap_read(chg->regmap, chg->reg[regs[i].blk] + regs[i].off, &v))
v = 0xffff;
@@ -468,27 +465,6 @@
}
DEFINE_SHOW_ATTRIBUTE(lbc_state);
-/* TEST ONLY (RAM test images): the supervisor performs its normal TERMINATED action now. */
-static ssize_t lbc_force_terminate_write(struct file *file, const char __user *buf, size_t len,
- loff_t *ppos)
-{
- struct pm8916_lbc_charger *chg = file->private_data;
-
- mutex_lock(&chg->supv_lock);
- if (chg->state == LBC_ST_CHARGING && !lbc_charge_enable(chg, false)) {
- chg->n_forced++;
- chg->low_polls = 0;
- lbc_supv_log(chg, LBC_ST_TERMINATED, "FORCED by test hook");
- }
- mutex_unlock(&chg->supv_lock);
- return len;
-}
-
-static const struct file_operations lbc_force_terminate_fops = {
- .open = simple_open,
- .write = lbc_force_terminate_write,
-};
-
static void lbc_debugfs_remove(void *data)
{
debugfs_remove_recursive(data);
@@ -716,8 +692,6 @@
chg->debugfs = debugfs_create_dir("pm8916_lbc", NULL);
debugfs_create_file("state", 0444, chg->debugfs, chg, &lbc_state_fops);
- debugfs_create_file("force_terminate", 0200, chg->debugfs, chg, &lbc_force_terminate_fops);
- debugfs_create_u32("test_recharge_uv", 0600, chg->debugfs, &chg->test_recharge_uv);
ret = devm_add_action_or_reset(dev, lbc_debugfs_remove, chg->debugfs);
if (ret)
return ret;

View file

@ -1,434 +0,0 @@
--- v2
+++ v3
@@ -61,9 +61,14 @@
/* Aurora B10B-3 recharge supervisor */
#define PM8916_LBC_SUPV_PERIOD_MS 30000
-#define PM8916_LBC_SUPV_DONE_POLLS 2
-#define PM8916_LBC_SUPV_LOW_POLLS 3
+#define PM8916_LBC_SUPV_LATCH_POLLS 2
+#define PM8916_LBC_SUPV_NOCV_POLLS 2
#define PM8916_LBC_SUPV_OVP_UV 4250000
+#define PM8916_LBC_CV_HOLD_DEFAULT_MIN 60
+#define PM8916_LBC_CHGR_CV_LOOP BIT(1)
+
+#define PM8916_LBC_MISC_BOOT_DONE 0x42
+#define PM8916_LBC_MISC_BOOT_DONE_BIT BIT(7)
#define PM8916_LBC_TIMEOUT_DEFAULT_MIN 512
#define PM8916_LBC_TIMEOUT_STEP_MIN 4
#define PM8916_LBC_TIMEOUT_MAX_MIN 512
@@ -92,19 +97,25 @@
unsigned int charge_current_max;
unsigned int charge_current_safe;
- /* recharge supervisor */
+ /* charger supervisor (Aurora B10B-3 v3) */
struct iio_channel *vbat_chan;
struct delayed_work supv_work;
struct mutex supv_lock;
int state;
int fault_reason;
- unsigned int recharge_uv; /* production threshold from monitored-battery */
+ unsigned int hold_uv; /* aurora,hold-voltage-microvolt, 0 = HOLD disabled */
+ unsigned int full_min_uv; /* aurora,full-min-voltage-microvolt */
+ unsigned int cv_hold_min; /* aurora,cv-hold-minutes */
+ unsigned int ibat_code; /* IBAT_MAX code programmed at probe */
unsigned int timeout_min;
int vbat_uv;
- int done_polls;
- int low_polls;
- unsigned int n_terminated;
- unsigned int n_recharge;
+ int latch_polls;
+ int nocv_polls;
+ time64_t cv_since; /* start of the current CV run, 0 = none */
+ bool supv_ready; /* set at the end of probe; IRQ kicks only after that */
+ unsigned int n_insert;
+ unsigned int n_hold;
+ unsigned int n_latch;
struct {
time64_t t;
int from, to, vbat;
@@ -118,7 +129,7 @@
LBC_ST_INIT = 0,
LBC_ST_NO_USB,
LBC_ST_CHARGING,
- LBC_ST_TERMINATED,
+ LBC_ST_HOLD,
LBC_ST_FAULT,
};
@@ -126,7 +137,7 @@
[LBC_ST_INIT] = "INIT",
[LBC_ST_NO_USB] = "NO_USB",
[LBC_ST_CHARGING] = "CHARGING",
- [LBC_ST_TERMINATED] = "TERMINATED",
+ [LBC_ST_HOLD] = "HOLD",
[LBC_ST_FAULT] = "FAULT",
};
@@ -154,7 +165,7 @@
LBC_MISC,
};
-static int pm8916_lbc_charger_configure(struct pm8916_lbc_charger *chg, bool set_ctrl)
+static int pm8916_lbc_charger_configure(struct pm8916_lbc_charger *chg, bool probe)
{
int ret = 0;
unsigned int tmp;
@@ -166,9 +177,12 @@
tmp /= PM8916_LBC_CHGR_VOLTAGE_STEP;
chg->charge_voltage_max = PM8916_LBC_CHGR_MIN_VOLTAGE + tmp * PM8916_LBC_CHGR_VOLTAGE_STEP;
- ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_VDD_MAX, tmp);
- if (ret)
- goto error;
+ /* after probe the supervisor owns VDD_MAX (charge level / hold level) */
+ if (probe) {
+ ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_VDD_MAX, tmp);
+ if (ret)
+ goto error;
+ }
chg->charge_current_max = min(chg->charge_current_max, chg->charge_current_safe);
@@ -177,16 +191,17 @@
tmp = chg->charge_current_max / PM8916_LBC_CHGR_MIN_CURRENT - 1;
chg->charge_current_max = (tmp + 1) * PM8916_LBC_CHGR_MIN_CURRENT;
+ chg->ibat_code = tmp;
ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_IBAT_MAX, tmp);
if (ret)
goto error;
/*
- * CHG_CTRL is written only at probe. Afterwards the recharge supervisor owns CHG_EN, so a
- * constant_charge_current update must not re-enable charging in TERMINATED/FAULT.
+ * CHG_CTRL is written only at probe. Afterwards the supervisor owns CHG_EN, so a
+ * constant_charge_current update must not restart charging in HOLD/FAULT.
*/
- if (set_ctrl) {
+ if (probe) {
ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_CHG_CTRL,
PM8916_LBC_CHGR_CHG_EN | PM8916_LBC_CHGR_PSTG_EN);
if (ret)
@@ -212,7 +227,7 @@
case LBC_ST_CHARGING:
val->intval = POWER_SUPPLY_STATUS_CHARGING;
break;
- case LBC_ST_TERMINATED:
+ case LBC_ST_HOLD:
val->intval = POWER_SUPPLY_STATUS_FULL;
break;
case LBC_ST_NO_USB:
@@ -249,8 +264,15 @@
switch (prop) {
case POWER_SUPPLY_PROP_CONSTANT_CHARGE_CURRENT:
+ {
+ int ret;
+
+ mutex_lock(&chg->supv_lock);
chg->charge_current_max = val->intval;
- return pm8916_lbc_charger_configure(chg, false);
+ ret = pm8916_lbc_charger_configure(chg, false);
+ mutex_unlock(&chg->supv_lock);
+ return ret;
+ }
default:
return -EINVAL;
}
@@ -276,14 +298,15 @@
/*
- * Aurora B10B-3 recharge supervisor.
- * The LBC ends a charge cycle in hardware (end-of-charge latch: CHG_STATUS 00, USB path 01, USB input ~0) and then
- * stays off until software gives CHG_EN a 0 -> 1 edge (downstream qpnp-linear-charger did this from BMS SOC /
- * VBAT_DET IRQ). Verified on Aurora (B10B-3 ram1): CHG_CTRL 0x21 -> 0xa0 releases the latch.
- * Also verified: writing CHG_EN = 0 does NOT stop the charger (USB input stays ~0.36 A), so the supervisor never
- * uses CHG_CTRL to "turn charging off"; TERMINATED is only the hardware latch, observed after CHARGING.
- * The supervisor polls the VADC VBAT every 30 s and restarts charging when VBAT stays below the monitored-battery
- * re-charge-voltage-microvolt for 3 consecutive polls.
+ * Aurora B10B-3 v3 charger supervisor: CHARGE -> HOLD -> (battery) -> CHARGE.
+ * Facts it relies on (B10A/B10B-2/B10B-3 tests): CHG_STATUS 00 + USB path 01 is a latch, not an end-of-charge;
+ * no hardware EOC was seen with BOOT_DONE set; CHG_EN = 0 does not stop the charger; verified levers are VDD_MAX,
+ * IBAT_MAX and the CHG_CTRL 0x21 -> 0xa0 edge (releases the latch). All decisions use the calibrated VADC VBAT.
+ * NO_USB: nothing is written.
+ * CHARGING: entered on USB insert/probe: BOOT_DONE, VDD_MAX = charge level, IBAT_MAX, restart edge.
+ * -> HOLD after the CV loop with VBAT >= full-min lasted cv-hold-minutes; 00/01 latch -> restart, stay.
+ * HOLD: only VDD_MAX = hold level; 00/01 latch -> restart edge, VDD_MAX stays at the hold level.
+ * FAULT: logical only (VBAT > 4.25 V or CHG_FAILED): no restarts. There is no verified software stop.
*/
static void lbc_supv_log(struct pm8916_lbc_charger *chg, int to, const char *why)
{
@@ -294,14 +317,17 @@
chg->log[i].to = to;
chg->log[i].vbat = chg->vbat_uv;
chg->log[i].why = why;
- dev_info(chg->dev, "supervisor %s -> %s (%s), vbat %d uV\n", lbc_state_name[chg->state],
- lbc_state_name[to], why, chg->vbat_uv);
+ if (to == LBC_ST_FAULT)
+ dev_crit(chg->dev, "supervisor %s -> FAULT (%s), vbat %d uV: restarts blocked, NO software stop available\n",
+ lbc_state_name[chg->state], why, chg->vbat_uv);
+ else
+ dev_info(chg->dev, "supervisor %s -> %s (%s), vbat %d uV\n", lbc_state_name[chg->state],
+ lbc_state_name[to], why, chg->vbat_uv);
chg->state = to;
}
static int lbc_charge_enable(struct pm8916_lbc_charger *chg, bool en)
{
- /* stock-style: enabled = CHG_EN, disabled = FORCE_BATT_ON */
return regmap_update_bits(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_CHG_CTRL,
PM8916_LBC_CHGR_EN_MASK,
en ? PM8916_LBC_CHGR_CHG_EN : PM8916_LBC_CHGR_FORCE_BATT_ON);
@@ -325,10 +351,69 @@
return lbc_charge_enable(chg, true);
}
+static int lbc_set_vdd_max(struct pm8916_lbc_charger *chg, unsigned int uv)
+{
+ uv = clamp_t(u32, uv, PM8916_LBC_CHGR_MIN_VOLTAGE, chg->charge_voltage_safe);
+ return regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_VDD_MAX,
+ (uv - PM8916_LBC_CHGR_MIN_VOLTAGE) / PM8916_LBC_CHGR_VOLTAGE_STEP);
+}
+
+/* USB insert / probe with USB: start a full cycle at the charge level */
+static int lbc_enter_charging(struct pm8916_lbc_charger *chg)
+{
+ unsigned int v;
+ int ret;
+
+ ret = regmap_update_bits(chg->regmap, chg->reg[LBC_MISC] + PM8916_LBC_MISC_BOOT_DONE,
+ PM8916_LBC_MISC_BOOT_DONE_BIT, PM8916_LBC_MISC_BOOT_DONE_BIT);
+ ret = ret ?: lbc_set_vdd_max(chg, chg->charge_voltage_max);
+ ret = ret ?: regmap_read(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_IBAT_MAX, &v);
+ if (!ret && v != chg->ibat_code)
+ ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_IBAT_MAX, chg->ibat_code);
+ ret = ret ?: lbc_charge_restart(chg, true);
+ chg->latch_polls = 0;
+ chg->nocv_polls = 0;
+ chg->cv_since = 0;
+ return ret;
+}
+
+/* 00/01 latch with USB valid: count polls; restart with the verified edge (VDD_MAX untouched) */
+static bool lbc_handle_latch(struct pm8916_lbc_charger *chg, unsigned int sts, unsigned int path)
+{
+ if (sts == 0 && !(path & PM8916_LBC_USB_PATH_ON))
+ chg->latch_polls++;
+ else
+ chg->latch_polls = 0;
+ if (chg->latch_polls < PM8916_LBC_SUPV_LATCH_POLLS)
+ return false;
+ chg->latch_polls = 0;
+ chg->n_latch++;
+ if (!lbc_charge_restart(chg, false))
+ dev_warn(chg->dev, "supervisor: 00/01 latch in %s (vbat %d uV) -> restart edge #%u\n",
+ lbc_state_name[chg->state], chg->vbat_uv, chg->n_latch);
+ return true;
+}
+
+static bool lbc_check_fault(struct pm8916_lbc_charger *chg, unsigned int failed)
+{
+ if (failed & PM8916_LBC_CHGR_CHG_FAILED_BIT) {
+ chg->fault_reason = LBC_FAULT_TIMER;
+ lbc_supv_log(chg, LBC_ST_FAULT, "CHG_FAILED (safety timer)");
+ return true;
+ }
+ if (chg->vbat_uv > PM8916_LBC_SUPV_OVP_UV) {
+ chg->fault_reason = LBC_FAULT_OVP;
+ lbc_supv_log(chg, LBC_ST_FAULT, "vbat > 4.25 V");
+ return true;
+ }
+ return false;
+}
+
static void lbc_supv_work(struct work_struct *work)
{
struct pm8916_lbc_charger *chg = container_of(work, struct pm8916_lbc_charger, supv_work.work);
unsigned int usb_rt, sts, path, failed;
+ time64_t now = ktime_get_seconds();
int ret, uv;
mutex_lock(&chg->supv_lock);
@@ -347,7 +432,6 @@
chg->vbat_uv = -1;
if (!(usb_rt & PM8916_LBC_USB_USBIN_VALID)) {
- /* CHG_CTRL untouched; the next insert restarts with the verified edge */
if (chg->state != LBC_ST_NO_USB) {
chg->fault_reason = LBC_FAULT_NONE;
lbc_supv_log(chg, LBC_ST_NO_USB, "usb removed");
@@ -358,58 +442,50 @@
switch (chg->state) {
case LBC_ST_INIT:
case LBC_ST_NO_USB:
- /* probe or USB insert: always start a cycle, like stock's usbin path */
- chg->done_polls = 0;
- chg->low_polls = 0;
chg->fault_reason = LBC_FAULT_NONE;
- if (!lbc_charge_restart(chg, true))
+ chg->n_insert++;
+ if (!lbc_enter_charging(chg))
lbc_supv_log(chg, LBC_ST_CHARGING,
chg->state == LBC_ST_INIT ? "probe, usb present" : "usb inserted");
break;
case LBC_ST_CHARGING:
- /*
- * Safety timer expiry: the hardware stops and sets CHG_FAILED. Latch FAULT so the supervisor never
- * restarts; no register write (CHG_EN = 0 is not a verified way to stop the charger).
- */
- if (failed & PM8916_LBC_CHGR_CHG_FAILED_BIT) {
- chg->fault_reason = LBC_FAULT_TIMER;
- lbc_supv_log(chg, LBC_ST_FAULT, "CHG_FAILED (safety timer)");
+ if (lbc_check_fault(chg, failed))
+ break;
+ if (lbc_handle_latch(chg, sts, path)) {
+ chg->cv_since = 0;
+ chg->nocv_polls = 0;
break;
}
- if (chg->vbat_uv > PM8916_LBC_SUPV_OVP_UV) {
- /* defence only: VDD_MAX regulates in hardware; latch FAULT = no further restarts */
- chg->fault_reason = LBC_FAULT_OVP;
- lbc_supv_log(chg, LBC_ST_FAULT, "vbat > 4.25 V");
+ if (!chg->hold_uv || chg->vbat_uv < 0)
break;
+ /* CV run: CV loop bit with VBAT >= full-min; tolerate one poll without the bit (05/07 interleave) */
+ if ((unsigned int)chg->vbat_uv < chg->full_min_uv) {
+ chg->cv_since = 0;
+ chg->nocv_polls = 0;
+ break;
+ }
+ if (sts & PM8916_LBC_CHGR_CV_LOOP) {
+ chg->nocv_polls = 0;
+ if (!chg->cv_since)
+ chg->cv_since = now;
+ } else if (++chg->nocv_polls >= PM8916_LBC_SUPV_NOCV_POLLS) {
+ chg->cv_since = 0;
}
- /* TERMINATED = hardware end-of-charge latch only; CHG_CTRL is not changed */
- if (sts == 0 && !(path & PM8916_LBC_USB_PATH_ON))
- chg->done_polls++;
- else
- chg->done_polls = 0;
- if (chg->done_polls >= PM8916_LBC_SUPV_DONE_POLLS) {
- chg->n_terminated++;
- chg->low_polls = 0;
- lbc_supv_log(chg, LBC_ST_TERMINATED, "hardware end of charge");
+ if (chg->cv_since && now - chg->cv_since >= (time64_t)chg->cv_hold_min * 60) {
+ if (!lbc_set_vdd_max(chg, chg->hold_uv)) {
+ chg->n_hold++;
+ chg->latch_polls = 0;
+ lbc_supv_log(chg, LBC_ST_HOLD, "CV time reached, VDD_MAX -> hold level");
+ }
}
break;
- case LBC_ST_TERMINATED:
- if (!chg->recharge_uv || chg->vbat_uv < 0)
+ case LBC_ST_HOLD:
+ if (lbc_check_fault(chg, failed))
break;
- if ((unsigned int)chg->vbat_uv < chg->recharge_uv)
- chg->low_polls++;
- else
- chg->low_polls = 0;
- if (chg->low_polls >= PM8916_LBC_SUPV_LOW_POLLS) {
- chg->done_polls = 0;
- chg->low_polls = 0;
- if (!lbc_charge_restart(chg, false)) {
- chg->n_recharge++;
- lbc_supv_log(chg, LBC_ST_CHARGING, "recharge");
- }
- }
+ /* keep the board on USB: a 00/01 latch gets the restart edge, VDD_MAX stays at the hold level */
+ lbc_handle_latch(chg, sts, path);
break;
case LBC_ST_FAULT:
@@ -439,15 +515,18 @@
{ "USB_PATH", LBC_USB, PM8916_LBC_USB_PATH_STS },
{ "USB_RT", LBC_USB, PM8916_INT_RT_STS },
{ "BAT_RT", LBC_BAT_IF, PM8916_INT_RT_STS },
+ { "BOOT_DONE", LBC_MISC, PM8916_LBC_MISC_BOOT_DONE },
};
+ time64_t now = ktime_get_seconds();
unsigned int i, v;
mutex_lock(&chg->supv_lock);
seq_printf(s, "state %s fault %s vbat_uv %d\n", lbc_state_name[chg->state],
lbc_fault_name[chg->fault_reason], chg->vbat_uv);
- seq_printf(s, "recharge_uv %u done_polls %d low_polls %d timeout_min %u\n",
- chg->recharge_uv, chg->done_polls, chg->low_polls, chg->timeout_min);
- seq_printf(s, "n_terminated %u n_recharge %u\n", chg->n_terminated, chg->n_recharge);
+ seq_printf(s, "charge_uv %u hold_uv %u full_min_uv %u cv_hold_min %u cv_s %lld nocv %d timeout_min %u\n",
+ chg->charge_voltage_max, chg->hold_uv, chg->full_min_uv, chg->cv_hold_min,
+ chg->cv_since ? now - chg->cv_since : -1LL, chg->nocv_polls, chg->timeout_min);
+ seq_printf(s, "n_insert %u n_hold %u n_latch %u\n", chg->n_insert, chg->n_hold, chg->n_latch);
for (i = 0; i < ARRAY_SIZE(regs); i++) {
if (regmap_read(chg->regmap, chg->reg[regs[i].blk] + regs[i].off, &v))
v = 0xffff;
@@ -485,7 +564,7 @@
power_supply_changed(chg->charger);
- if (chg->vbat_chan)
+ if (READ_ONCE(chg->supv_ready))
mod_delayed_work(system_freezable_wq, &chg->supv_work, 0);
return IRQ_HANDLED;
@@ -584,6 +663,7 @@
return -ENOMEM;
chg->dev = dev;
+ mutex_init(&chg->supv_lock);
chg->regmap = dev_get_regmap(pdev->dev.parent, NULL);
if (!chg->regmap)
@@ -649,14 +729,13 @@
if (IS_ERR(chg->vbat_chan))
return dev_err_probe(dev, PTR_ERR(chg->vbat_chan), "no VADC vbat channel\n");
- {
- struct device_node *bat = of_parse_phandle(dev->of_node, "monitored-battery", 0);
-
- if (!bat || of_property_read_u32(bat, "re-charge-voltage-microvolt", &chg->recharge_uv))
- dev_warn(dev, "no re-charge-voltage-microvolt: automatic recharge disabled\n");
- of_node_put(bat);
+ chg->cv_hold_min = PM8916_LBC_CV_HOLD_DEFAULT_MIN;
+ device_property_read_u32(dev, "aurora,cv-hold-minutes", &chg->cv_hold_min);
+ if (device_property_read_u32(dev, "aurora,hold-voltage-microvolt", &chg->hold_uv) ||
+ device_property_read_u32(dev, "aurora,full-min-voltage-microvolt", &chg->full_min_uv)) {
+ chg->hold_uv = 0;
+ dev_warn(dev, "no aurora,hold-voltage/full-min-voltage: HOLD disabled\n");
}
- mutex_init(&chg->supv_lock);
ret = devm_delayed_work_autocancel(dev, &chg->supv_work, lbc_supv_work);
if (ret)
return ret;
@@ -696,9 +775,17 @@
if (ret)
return ret;
- dev_info(dev, "recharge supervisor: threshold %u uV, %d x %d ms below, ovp %d uV\n",
- chg->recharge_uv, PM8916_LBC_SUPV_LOW_POLLS, PM8916_LBC_SUPV_PERIOD_MS,
- PM8916_LBC_SUPV_OVP_UV);
+ if (chg->hold_uv && (chg->hold_uv < PM8916_LBC_CHGR_MIN_VOLTAGE ||
+ chg->hold_uv >= chg->charge_voltage_max ||
+ chg->full_min_uv > chg->charge_voltage_max)) {
+ dev_warn(dev, "invalid hold %u / full-min %u for charge level %u: HOLD disabled\n",
+ chg->hold_uv, chg->full_min_uv, chg->charge_voltage_max);
+ chg->hold_uv = 0;
+ }
+ dev_info(dev, "supervisor v3: charge %u uV, hold %u uV, full-min %u uV, cv %u min, IBAT_MAX code %u, ovp %d uV\n",
+ chg->charge_voltage_max, chg->hold_uv, chg->full_min_uv, chg->cv_hold_min,
+ chg->ibat_code, PM8916_LBC_SUPV_OVP_UV);
+ WRITE_ONCE(chg->supv_ready, true);
queue_delayed_work(system_freezable_wq, &chg->supv_work, 0);
return 0;

View file

@ -1,122 +0,0 @@
--- src-b10b3/drivers/power/supply/Kconfig 2026-09-21 19:09:00.000000000 +0600
+++ src-b10b4/drivers/power/supply/Kconfig 2026-10-04 18:42:45.872000000 +0600
@@ -768,6 +768,15 @@
To compile this driver as module, choose M here: the
module will be called pm8916_lbc.
+config CHARGER_PM8916_LBC_B10B4_DEBUG
+ bool "Aurora B10B-4 TEST-ONLY charger actuator debugfs hook"
+ depends on CHARGER_PM8916_LBC && DEBUG_FS
+ default n
+ help
+ TEST-ONLY (Aurora B10B-4, RAM images only). Adds the write-only debugfs file
+ pm8916_lbc/b10b4 accepting exactly "susp 0|1" (USB_SUSP bit0), "vdd <0..8>"
+ (VDD_MAX) and "ibat <0..4>" (IBAT_MAX). Never enable in a production image.
+
config CHARGER_BQ2415X
tristate "TI BQ2415x battery charger driver"
depends on I2C
--- src-b10b3/drivers/power/supply/pm8916_lbc.c 2026-10-03 21:11:03.584000000 +0600
+++ src-b10b4/drivers/power/supply/pm8916_lbc.c 2026-10-04 18:17:19.300000000 +0600
@@ -20,6 +20,11 @@
#include <linux/of.h>
#include <linux/seq_file.h>
#include <linux/workqueue.h>
+#ifdef CONFIG_CHARGER_PM8916_LBC_B10B4_DEBUG
+#include <linux/fs.h>
+#include <linux/string.h>
+#include <linux/uaccess.h>
+#endif
/* Two bytes: type + subtype */
#define PM8916_PERPH_TYPE 0x04
@@ -544,6 +549,78 @@
}
DEFINE_SHOW_ATTRIBUTE(lbc_state);
+#ifdef CONFIG_CHARGER_PM8916_LBC_B10B4_DEBUG
+/*
+ * Aurora B10B-4 TEST-ONLY actuator hook (Kconfig CHARGER_PM8916_LBC_B10B4_DEBUG, default n, RAM test images only).
+ * Write-only debugfs file pm8916_lbc/b10b4, exactly one of:
+ * "susp 0|1" USB_SUSP (USB block + 0x47) bit0 only, masked update
+ * "vdd <code>" VDD_MAX (CHGR block + 0x40), code 0x00..0x08 (4.000..4.200 V)
+ * "ibat <code>" IBAT_MAX (CHGR block + 0x44), code 0x00..0x04 (90..450 mA)
+ * Anything else (unknown command, extra/missing argument, out-of-range value) -> -EINVAL without any write.
+ * Taken under supv_lock (the supervisor/charger lock); old/new/readback logged with dev_warn. Supervisor logic unchanged.
+ */
+#define PM8916_LBC_USB_SUSP 0x47
+#define PM8916_LBC_USB_SUSP_BIT BIT(0)
+
+static ssize_t lbc_b10b4_write(struct file *file, const char __user *ubuf, size_t len, loff_t *ppos)
+{
+ struct pm8916_lbc_charger *chg = file->private_data;
+ char buf[32], *p, *cmd, *arg;
+ unsigned int val, addr, mask, old, rb;
+ int ret;
+
+ if (len == 0 || len >= sizeof(buf))
+ return -EINVAL;
+ if (copy_from_user(buf, ubuf, len))
+ return -EFAULT;
+ buf[len] = 0;
+ p = strim(buf);
+ cmd = strsep(&p, " ");
+ arg = strsep(&p, " ");
+ if (!cmd || !arg || p || kstrtouint(arg, 0, &val))
+ return -EINVAL;
+
+ if (!strcmp(cmd, "susp") && val <= 1) {
+ addr = chg->reg[LBC_USB] + PM8916_LBC_USB_SUSP;
+ mask = PM8916_LBC_USB_SUSP_BIT;
+ } else if (!strcmp(cmd, "vdd") && val <= 0x08) {
+ addr = chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_VDD_MAX;
+ mask = 0xff;
+ } else if (!strcmp(cmd, "ibat") && val <= 0x04) {
+ addr = chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_IBAT_MAX;
+ mask = 0xff;
+ } else {
+ return -EINVAL;
+ }
+
+ mutex_lock(&chg->supv_lock);
+ ret = regmap_read(chg->regmap, addr, &old);
+ if (!ret) {
+ if (mask == 0xff)
+ ret = regmap_write(chg->regmap, addr, val);
+ else
+ ret = regmap_update_bits(chg->regmap, addr, mask, val ? mask : 0);
+ }
+ if (!ret)
+ ret = regmap_read(chg->regmap, addr, &rb);
+ mutex_unlock(&chg->supv_lock);
+
+ if (ret) {
+ dev_warn(chg->dev, "B10B-4 TEST hook: %s %u at 0x%04x failed: %d\n", cmd, val, addr, ret);
+ return ret;
+ }
+ dev_warn(chg->dev, "B10B-4 TEST hook: %s %u -> reg 0x%04x old 0x%02x readback 0x%02x\n", cmd, val, addr, old, rb);
+ return len;
+}
+
+static const struct file_operations lbc_b10b4_fops = {
+ .owner = THIS_MODULE,
+ .open = simple_open,
+ .write = lbc_b10b4_write,
+ .llseek = noop_llseek,
+};
+#endif
+
static void lbc_debugfs_remove(void *data)
{
debugfs_remove_recursive(data);
@@ -771,6 +848,10 @@
chg->debugfs = debugfs_create_dir("pm8916_lbc", NULL);
debugfs_create_file("state", 0444, chg->debugfs, chg, &lbc_state_fops);
+#ifdef CONFIG_CHARGER_PM8916_LBC_B10B4_DEBUG
+ debugfs_create_file("b10b4", 0200, chg->debugfs, chg, &lbc_b10b4_fops);
+ dev_warn(dev, "B10B-4 TEST-ONLY actuator hook enabled (debugfs pm8916_lbc/b10b4) - never in production\n");
+#endif
ret = devm_add_action_or_reset(dev, lbc_debugfs_remove, chg->debugfs);
if (ret)
return ret;

View file

@ -1,14 +0,0 @@
--- src-b10b3/drivers/power/supply/pm8916_lbc.c 2026-10-03 21:11:03.584000000 +0600
+++ src-b10b3d3/drivers/power/supply/pm8916_lbc.c 2026-10-04 03:03:45.276000000 +0600
@@ -366,7 +366,10 @@
ret = regmap_update_bits(chg->regmap, chg->reg[LBC_MISC] + PM8916_LBC_MISC_BOOT_DONE,
PM8916_LBC_MISC_BOOT_DONE_BIT, PM8916_LBC_MISC_BOOT_DONE_BIT);
- ret = ret ?: lbc_set_vdd_max(chg, chg->charge_voltage_max);
+ /* D3: write VDD_MAX only if it differs (v2 did not rewrite it right before the restart edge) */
+ ret = ret ?: regmap_read(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_VDD_MAX, &v);
+ if (!ret && v != (chg->charge_voltage_max - PM8916_LBC_CHGR_MIN_VOLTAGE) / PM8916_LBC_CHGR_VOLTAGE_STEP)
+ ret = lbc_set_vdd_max(chg, chg->charge_voltage_max);
ret = ret ?: regmap_read(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_IBAT_MAX, &v);
if (!ret && v != chg->ibat_code)
ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_IBAT_MAX, chg->ibat_code);

View file

@ -1,79 +0,0 @@
--- src-b10b3/drivers/power/supply/pm8916_lbc.c 2026-10-03 21:11:03.584000000 +0600
+++ src-b10b5/drivers/power/supply/pm8916_lbc.c 2026-10-04 20:07:45.456000000 +0600
@@ -298,7 +298,7 @@
/*
- * Aurora B10B-3 v3 charger supervisor: CHARGE -> HOLD -> (battery) -> CHARGE.
+ * Aurora B10B-3 v4 charger supervisor: CHARGE -> HOLD -> (battery) -> CHARGE (v4 = v3 + FAULT safe clamp, B10B-5).
* Facts it relies on (B10A/B10B-2/B10B-3 tests): CHG_STATUS 00 + USB path 01 is a latch, not an end-of-charge;
* no hardware EOC was seen with BOOT_DONE set; CHG_EN = 0 does not stop the charger; verified levers are VDD_MAX,
* IBAT_MAX and the CHG_CTRL 0x21 -> 0xa0 edge (releases the latch). All decisions use the calibrated VADC VBAT.
@@ -306,7 +306,10 @@
* CHARGING: entered on USB insert/probe: BOOT_DONE, VDD_MAX = charge level, IBAT_MAX, restart edge.
* -> HOLD after the CV loop with VBAT >= full-min lasted cv-hold-minutes; 00/01 latch -> restart, stay.
* HOLD: only VDD_MAX = hold level; 00/01 latch -> restart edge, VDD_MAX stays at the hold level.
- * FAULT: logical only (VBAT > 4.25 V or CHG_FAILED): no restarts. There is no verified software stop.
+ * FAULT: entered on VBAT > 4.25 V or CHG_FAILED; on entry only VDD_MAX = 0x00 (FAULT safe clamp to 4.00 V, B10B-4) +
+ * readback; no further charger writes, no restarts; left only by USB removal (-> NO_USB) or reboot.
+ * The clamp is NOT a guaranteed charge disconnect: with VBAT > 4.00 V charging stops and the board runs
+ * from the battery; with VBAT < 4.00 V the charger may still charge up to 4.00 V.
*/
static void lbc_supv_log(struct pm8916_lbc_charger *chg, int to, const char *why)
{
@@ -318,7 +321,7 @@
chg->log[i].vbat = chg->vbat_uv;
chg->log[i].why = why;
if (to == LBC_ST_FAULT)
- dev_crit(chg->dev, "supervisor %s -> FAULT (%s), vbat %d uV: restarts blocked, NO software stop available\n",
+ dev_crit(chg->dev, "supervisor %s -> FAULT (%s), vbat %d uV: restarts blocked, FAULT safe clamp to 4.00 V\n",
lbc_state_name[chg->state], why, chg->vbat_uv);
else
dev_info(chg->dev, "supervisor %s -> %s (%s), vbat %d uV\n", lbc_state_name[chg->state],
@@ -394,18 +397,36 @@
return true;
}
+/*
+ * FAULT safe clamp to 4.00 V (B10B-4): the only charger write on FAULT entry is VDD_MAX = 0x00 (lowest LBC step).
+ * Not a guaranteed charge disconnect - below 4.00 V the charger may still charge up to 4.00 V.
+ */
+static void lbc_fault_clamp(struct pm8916_lbc_charger *chg, const char *why)
+{
+ unsigned int old = 0xff, rb = 0xff;
+ int ret;
+
+ ret = regmap_read(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_VDD_MAX, &old);
+ ret = ret ?: regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_VDD_MAX, 0x00);
+ ret = ret ?: regmap_read(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_VDD_MAX, &rb);
+ dev_crit(chg->dev, "FAULT safe clamp to 4.00 V: cause %s, vbat %d uV, VDD_MAX old 0x%02x -> readback 0x%02x (ret %d)\n",
+ why, chg->vbat_uv, old, rb, ret);
+}
+
+static bool lbc_enter_fault(struct pm8916_lbc_charger *chg, int reason, const char *why)
+{
+ chg->fault_reason = reason;
+ lbc_fault_clamp(chg, why);
+ lbc_supv_log(chg, LBC_ST_FAULT, why);
+ return true;
+}
+
static bool lbc_check_fault(struct pm8916_lbc_charger *chg, unsigned int failed)
{
- if (failed & PM8916_LBC_CHGR_CHG_FAILED_BIT) {
- chg->fault_reason = LBC_FAULT_TIMER;
- lbc_supv_log(chg, LBC_ST_FAULT, "CHG_FAILED (safety timer)");
- return true;
- }
- if (chg->vbat_uv > PM8916_LBC_SUPV_OVP_UV) {
- chg->fault_reason = LBC_FAULT_OVP;
- lbc_supv_log(chg, LBC_ST_FAULT, "vbat > 4.25 V");
- return true;
- }
+ if (failed & PM8916_LBC_CHGR_CHG_FAILED_BIT)
+ return lbc_enter_fault(chg, LBC_FAULT_TIMER, "CHG_FAILED (safety timer)");
+ if (chg->vbat_uv > PM8916_LBC_SUPV_OVP_UV)
+ return lbc_enter_fault(chg, LBC_FAULT_OVP, "vbat > 4.25 V");
return false;
}

View file

@ -1,104 +0,0 @@
--- src-b10b3/drivers/power/supply/Kconfig 2026-09-21 19:09:00.000000000 +0600
+++ src-b10b5/drivers/power/supply/Kconfig 2026-10-04 20:08:07.140000000 +0600
@@ -768,6 +768,16 @@
To compile this driver as module, choose M here: the
module will be called pm8916_lbc.
+config CHARGER_PM8916_LBC_B10B5_TEST
+ bool "Aurora B10B-5 TEST-ONLY FAULT injection debugfs"
+ depends on CHARGER_PM8916_LBC && DEBUG_FS
+ default n
+ help
+ TEST-ONLY (Aurora B10B-5 RAM regression). Adds the write-only debugfs file
+ pm8916_lbc/b10b5_fault; writing "ovp" makes the next supervisor fault check
+ take the production OVP FAULT path (FAULT safe clamp) without a real OVP.
+ Never enable in a production image.
+
config CHARGER_BQ2415X
tristate "TI BQ2415x battery charger driver"
depends on I2C
--- /tmp/v4.c 2026-10-04 20:08:07.092000000 +0600
+++ src-b10b5/drivers/power/supply/pm8916_lbc.c 2026-10-04 20:08:07.140000000 +0600
@@ -20,6 +20,11 @@
#include <linux/of.h>
#include <linux/seq_file.h>
#include <linux/workqueue.h>
+#ifdef CONFIG_CHARGER_PM8916_LBC_B10B5_TEST
+#include <linux/fs.h>
+#include <linux/string.h>
+#include <linux/uaccess.h>
+#endif
/* Two bytes: type + subtype */
#define PM8916_PERPH_TYPE 0x04
@@ -103,6 +108,9 @@
struct mutex supv_lock;
int state;
int fault_reason;
+#ifdef CONFIG_CHARGER_PM8916_LBC_B10B5_TEST
+ bool test_fault_ovp; /* B10B-5 TEST-ONLY one-shot OVP injection */
+#endif
unsigned int hold_uv; /* aurora,hold-voltage-microvolt, 0 = HOLD disabled */
unsigned int full_min_uv; /* aurora,full-min-voltage-microvolt */
unsigned int cv_hold_min; /* aurora,cv-hold-minutes */
@@ -427,6 +435,12 @@
return lbc_enter_fault(chg, LBC_FAULT_TIMER, "CHG_FAILED (safety timer)");
if (chg->vbat_uv > PM8916_LBC_SUPV_OVP_UV)
return lbc_enter_fault(chg, LBC_FAULT_OVP, "vbat > 4.25 V");
+#ifdef CONFIG_CHARGER_PM8916_LBC_B10B5_TEST
+ if (chg->test_fault_ovp) {
+ chg->test_fault_ovp = false;
+ return lbc_enter_fault(chg, LBC_FAULT_OVP, "TEST-injected OVP (B10B-5)");
+ }
+#endif
return false;
}
@@ -565,6 +579,36 @@
}
DEFINE_SHOW_ATTRIBUTE(lbc_state);
+#ifdef CONFIG_CHARGER_PM8916_LBC_B10B5_TEST
+/* B10B-5 TEST-ONLY: "ovp" arms a one-shot OVP condition for the next supervisor fault check (production FAULT path). */
+static ssize_t lbc_b10b5_fault_write(struct file *file, const char __user *ubuf, size_t len, loff_t *ppos)
+{
+ struct pm8916_lbc_charger *chg = file->private_data;
+ char buf[8];
+
+ if (len == 0 || len >= sizeof(buf))
+ return -EINVAL;
+ if (copy_from_user(buf, ubuf, len))
+ return -EFAULT;
+ buf[len] = 0;
+ if (strcmp(strim(buf), "ovp"))
+ return -EINVAL;
+ mutex_lock(&chg->supv_lock);
+ chg->test_fault_ovp = true;
+ mutex_unlock(&chg->supv_lock);
+ dev_warn(chg->dev, "B10B-5 TEST: OVP FAULT injection armed (state %s)\n", lbc_state_name[chg->state]);
+ mod_delayed_work(system_freezable_wq, &chg->supv_work, 0);
+ return len;
+}
+
+static const struct file_operations lbc_b10b5_fault_fops = {
+ .owner = THIS_MODULE,
+ .open = simple_open,
+ .write = lbc_b10b5_fault_write,
+ .llseek = noop_llseek,
+};
+#endif
+
static void lbc_debugfs_remove(void *data)
{
debugfs_remove_recursive(data);
@@ -792,6 +836,10 @@
chg->debugfs = debugfs_create_dir("pm8916_lbc", NULL);
debugfs_create_file("state", 0444, chg->debugfs, chg, &lbc_state_fops);
+#ifdef CONFIG_CHARGER_PM8916_LBC_B10B5_TEST
+ debugfs_create_file("b10b5_fault", 0200, chg->debugfs, chg, &lbc_b10b5_fault_fops);
+ dev_warn(dev, "B10B-5 TEST-ONLY FAULT injection enabled (debugfs pm8916_lbc/b10b5_fault) - never in production\n");
+#endif
ret = devm_add_action_or_reset(dev, lbc_debugfs_remove, chg->debugfs);
if (ret)
return ret;

View file

@ -1,7 +0,0 @@
1164b1c73e9a31a1c55c4585ae5db411a786756e7fa0ff56c8fcd7e574f329d6 Image.gz
f8ddac428b447d44945fc4c89fe47c2285feebb1a51c05c398fecf3e017ab745 aurora-b10b3b.dtb
bcb638e59a100467d20ac291d2b854c694ccd8c3b6f79e1be6265e8f0b40e1d9 Image.gz-dtb
5285ea4a490f48d3ca90aedf9663382282b2a32d6423fce1f038f405cd3e76f3 config-b10b3
0fef41b262917c8ae308fa222da0017e2b3cb3ec5da1ca8ba18d0318476761a3 cmdline.txt
ac518e27e2957ad5e4515969b9a3808024e11ef8d1a79433a899a67dbc644558 initramfs.cpio.gz
9e66466d64e6832865af145e365c3ee36619d3607fee3b7cd9609533d1102c06 aurora-b10b3b.img

View file

@ -1 +0,0 @@
earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0

View file

@ -1,7 +0,0 @@
2c802f6454708917e1ab641a0537fc1be4b4a842ce1b4610bcb35ab5afc0a372 Image.gz
627d86be244e36724ae655ca9e79155c5432badc4472aac8fab638b61fea6c82 aurora-b10b4.dtb
08803c8bbdaf2386188a1ac6f4572a5631ce6123eabe5a33835cddb16982550b Image.gz-dtb
3c32ec627f6331bdf59923e8037eee0e840c6bbb2f9e3eda5b7ed454ffe0bee9 config-b10b4
0fef41b262917c8ae308fa222da0017e2b3cb3ec5da1ca8ba18d0318476761a3 cmdline.txt
ac518e27e2957ad5e4515969b9a3808024e11ef8d1a79433a899a67dbc644558 initramfs.cpio.gz
eeff682053ac49abfa3952a2d3957dcbf5cd384280f35647ec40eb83835dc38b aurora-b10b4.img

View file

@ -1 +0,0 @@
earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0

View file

@ -1,7 +0,0 @@
218c4444878448bc447b8280fd6abe43c40551dd4a92c4cef5de382b6981deed Image.gz
5461b92d1dd999095ad7951a0fbf4b3325071fb2b9981488aca40d2189d52f6a aurora-b10b5t.dtb
d80b6042c239bbf6b36191b0bac8ae00b37b3065d892626d4a4a930ae9eed743 Image.gz-dtb
6ebb91cb68ac09391e68ff4fcd6f7610a7e0b84f223fcd84a6be2f19cd4db3bb config-b10b5t
0fef41b262917c8ae308fa222da0017e2b3cb3ec5da1ca8ba18d0318476761a3 cmdline.txt
ac518e27e2957ad5e4515969b9a3808024e11ef8d1a79433a899a67dbc644558 initramfs.cpio.gz
ea37a67cb488b627bd52603cf7c686e34d1c7e5232bfdb13b891b7f89f2e1cae aurora-b10b5t.img

View file

@ -1 +0,0 @@
earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0

View file

@ -1,7 +0,0 @@
1164b1c73e9a31a1c55c4585ae5db411a786756e7fa0ff56c8fcd7e574f329d6 Image.gz
78a9b80ead17ff8ef74bea41bc70edbcf705eb0824f5877c95a09ed3e7e50ce5 aurora-b10b3c.dtb
518beb4a953712b9ca4258f1b84d6d07dac9cebefb3259685a417e1f5af221ad Image.gz-dtb
5285ea4a490f48d3ca90aedf9663382282b2a32d6423fce1f038f405cd3e76f3 config-b10b3
0fef41b262917c8ae308fa222da0017e2b3cb3ec5da1ca8ba18d0318476761a3 cmdline.txt
ac518e27e2957ad5e4515969b9a3808024e11ef8d1a79433a899a67dbc644558 initramfs.cpio.gz
5ff9dec079a300511883d3d6a79c72539f43c980e921c34af7916e949ca1010d aurora-b10b3c.img

View file

@ -1 +0,0 @@
earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0

View file

@ -1,7 +0,0 @@
1164b1c73e9a31a1c55c4585ae5db411a786756e7fa0ff56c8fcd7e574f329d6 Image.gz
d7bcd0420a6cd024f19847f131554116ffc69dfeb60f81612553ed28a9c55fcd aurora-b10b3d.dtb
9cc85f538af41848e7ad84e3a8f69f7c01f4eef02b51501b7617edabe691600b Image.gz-dtb
5285ea4a490f48d3ca90aedf9663382282b2a32d6423fce1f038f405cd3e76f3 config-b10b3
0fef41b262917c8ae308fa222da0017e2b3cb3ec5da1ca8ba18d0318476761a3 cmdline.txt
ac518e27e2957ad5e4515969b9a3808024e11ef8d1a79433a899a67dbc644558 initramfs.cpio.gz
43739e5565e7d2dc14d6249b098130dd3094c2748dd07a4a2373394c0241b897 aurora-b10b3d.img

View file

@ -1 +0,0 @@
earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0

View file

@ -1,7 +0,0 @@
654deeffca56484b5ddc4e29446882c982278120fc194fe8caef11e2e93527bf Image.gz
d7bcd0420a6cd024f19847f131554116ffc69dfeb60f81612553ed28a9c55fcd aurora-b10b3d.dtb
9b6e4c594c420e0e22f085c6a716924c39f132b19730c7eaf59cf1a61127bf5e Image.gz-dtb
5285ea4a490f48d3ca90aedf9663382282b2a32d6423fce1f038f405cd3e76f3 config-b10b3
0fef41b262917c8ae308fa222da0017e2b3cb3ec5da1ca8ba18d0318476761a3 cmdline.txt
ac518e27e2957ad5e4515969b9a3808024e11ef8d1a79433a899a67dbc644558 initramfs.cpio.gz
4645a7ec012e4c83af4f496ce03431024a758c64c679da45f7b6445edef777f9 aurora-b10b3d3.img

View file

@ -1 +0,0 @@
earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0

View file

@ -1,7 +0,0 @@
1164b1c73e9a31a1c55c4585ae5db411a786756e7fa0ff56c8fcd7e574f329d6 Image.gz
45fa135de91f13b1ba5503bd3f9556ac45fad2346871b55583a6a84b0c10b1fb aurora-b10b3p.dtb
7168f88e5ac01fe35298b6086e20682d0c254fc0a09d1cf05ec12eb7f90aecb4 Image.gz-dtb
5285ea4a490f48d3ca90aedf9663382282b2a32d6423fce1f038f405cd3e76f3 config-b10b3
0fef41b262917c8ae308fa222da0017e2b3cb3ec5da1ca8ba18d0318476761a3 cmdline.txt
ac518e27e2957ad5e4515969b9a3808024e11ef8d1a79433a899a67dbc644558 initramfs.cpio.gz
8bcd613e029b9b72a2105e1aaf93572601345871c6917b178cd5fd462816e8aa aurora-b10b3p.img

View file

@ -1 +0,0 @@
earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0

View file

@ -1,7 +0,0 @@
f46dfbc7e18ed458c13e8ec221131acdccbede3dde7177d9b53199720f1b61c9 Image.gz
d550669b2c5231dc73dc38015d780a66bf4801e3961d3cb2d0bdf2b4a625b4af aurora-b10b3t.dtb
2b941e3312fd5eae2a87040e14e6616207121e4ce3b7f32274c32b70ba2685d0 Image.gz-dtb
5285ea4a490f48d3ca90aedf9663382282b2a32d6423fce1f038f405cd3e76f3 config-b10b3
0fef41b262917c8ae308fa222da0017e2b3cb3ec5da1ca8ba18d0318476761a3 cmdline.txt
ac518e27e2957ad5e4515969b9a3808024e11ef8d1a79433a899a67dbc644558 initramfs.cpio.gz
dfe2fae69f0c64be85bc972e2e8502e9bef262fa5dbb5e77b3c76ed183a89f1f aurora-b10b3t.img

View file

@ -1 +0,0 @@
earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0

View file

@ -1,7 +0,0 @@
96b71ec30673d838e48ef667332cf2607d10a6a66907b6b71410a9606f37b1ca Image.gz
e47762d1dcd0af6e2acb711fa47ecc13769cd6bcb81259ce50635e8b18b6514a aurora-b10b3.dtb
b0ea04666c4ab979067fe9c0015bda0e9c8ac742678321e57b18e841c9c69f95 Image.gz-dtb
e49e999f7eebda62eece169ad072d8e855212e35b26cee0c81adeb78a068dc58 config-b10b5
0fef41b262917c8ae308fa222da0017e2b3cb3ec5da1ca8ba18d0318476761a3 cmdline.txt
ac518e27e2957ad5e4515969b9a3808024e11ef8d1a79433a899a67dbc644558 initramfs.cpio.gz
386502d3ca68b1c4dfb4bbf354f3abc48cfab497143a39f6272b79a3899c1e9b aurora-b10b5.img

View file

@ -1 +0,0 @@
earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0

View file

@ -1,7 +0,0 @@
1164b1c73e9a31a1c55c4585ae5db411a786756e7fa0ff56c8fcd7e574f329d6 Image.gz
e47762d1dcd0af6e2acb711fa47ecc13769cd6bcb81259ce50635e8b18b6514a aurora-b10b3.dtb
5e69f8431d42a9ddb9d64f06dcc408cd8dbfa9dffdba7e9b06e4ba58075ed1c7 Image.gz-dtb
5285ea4a490f48d3ca90aedf9663382282b2a32d6423fce1f038f405cd3e76f3 config-b10b3
0fef41b262917c8ae308fa222da0017e2b3cb3ec5da1ca8ba18d0318476761a3 cmdline.txt
ac518e27e2957ad5e4515969b9a3808024e11ef8d1a79433a899a67dbc644558 initramfs.cpio.gz
b7dc34e92148613fd7292ec21209eb7ecd7a96b721b85ab42d374ce5f40d8f84 aurora-b10b3.img

View file

@ -1 +0,0 @@
earlycon console=tty0 console=ttyMSM0,115200n8 ignore_loglevel loglevel=8 rdinit=/init fbcon=font:6x8 consoleblank=0

View file

@ -1,838 +0,0 @@
// SPDX-License-Identifier: GPL-2.0-only
/*
* Copyright (c) 2023, Nikita Travkin <nikita@trvn.ru>
*/
#include <linux/errno.h>
#include <linux/module.h>
#include <linux/platform_device.h>
#include <linux/power_supply.h>
#include <linux/property.h>
#include <linux/regmap.h>
#include <linux/slab.h>
#include <linux/delay.h>
#include <linux/interrupt.h>
#include <linux/extcon-provider.h>
#include <linux/debugfs.h>
#include <linux/devm-helpers.h>
#include <linux/iio/consumer.h>
#include <linux/mutex.h>
#include <linux/of.h>
#include <linux/seq_file.h>
#include <linux/workqueue.h>
/* Two bytes: type + subtype */
#define PM8916_PERPH_TYPE 0x04
#define PM8916_LBC_CHGR_TYPE 0x1502
#define PM8916_LBC_BAT_IF_TYPE 0x1602
#define PM8916_LBC_USB_TYPE 0x1702
#define PM8916_LBC_MISC_TYPE 0x1802
#define PM8916_LBC_CHGR_CHG_OPTION 0x08
#define PM8916_LBC_CHGR_PMIC_CHARGER BIT(7)
#define PM8916_LBC_CHGR_CHG_STATUS 0x09
#define PM8916_INT_RT_STS 0x10
#define PM8916_LBC_USB_USBIN_VALID BIT(1)
#define PM8916_LBC_CHGR_VDD_MAX 0x40
#define PM8916_LBC_CHGR_VDD_SAFE 0x41
#define PM8916_LBC_CHGR_IBAT_MAX 0x44
#define PM8916_LBC_CHGR_IBAT_SAFE 0x45
#define PM8916_LBC_CHGR_TCHG_MAX_EN 0x60
#define PM8916_LBC_CHGR_TCHG_MAX_ENABLED BIT(7)
#define PM8916_LBC_CHGR_TCHG_MAX 0x61
#define PM8916_LBC_CHGR_CHG_CTRL 0x49
#define PM8916_LBC_CHGR_CHG_EN BIT(7)
#define PM8916_LBC_CHGR_PSTG_EN BIT(5)
#define PM8916_LBC_CHGR_FORCE_BATT_ON BIT(0)
#define PM8916_LBC_CHGR_EN_MASK (PM8916_LBC_CHGR_CHG_EN | PM8916_LBC_CHGR_FORCE_BATT_ON)
#define PM8916_LBC_CHGR_CHG_FAILED 0x4a
#define PM8916_LBC_CHGR_CHG_FAILED_BIT BIT(7)
/* USB_CHGPTH 0x08: 0x02 while the charge path is on, 0x01 after end of charge (observed, not documented) */
#define PM8916_LBC_USB_PATH_STS 0x08
#define PM8916_LBC_USB_PATH_ON BIT(1)
/* Aurora B10B-3 recharge supervisor */
#define PM8916_LBC_SUPV_PERIOD_MS 30000
#define PM8916_LBC_SUPV_LATCH_POLLS 2
#define PM8916_LBC_SUPV_NOCV_POLLS 2
#define PM8916_LBC_SUPV_OVP_UV 4250000
#define PM8916_LBC_CV_HOLD_DEFAULT_MIN 60
#define PM8916_LBC_CHGR_CV_LOOP BIT(1)
#define PM8916_LBC_MISC_BOOT_DONE 0x42
#define PM8916_LBC_MISC_BOOT_DONE_BIT BIT(7)
#define PM8916_LBC_TIMEOUT_DEFAULT_MIN 512
#define PM8916_LBC_TIMEOUT_STEP_MIN 4
#define PM8916_LBC_TIMEOUT_MAX_MIN 512
#define PM8916_LBC_SUPV_LOG 16
#define PM8916_LBC_CHGR_MIN_CURRENT 90000
#define PM8916_LBC_CHGR_MAX_CURRENT 1440000
#define PM8916_LBC_CHGR_MIN_VOLTAGE 4000000
#define PM8916_LBC_CHGR_MAX_VOLTAGE 4775000
#define PM8916_LBC_CHGR_VOLTAGE_STEP 25000
#define PM8916_LBC_CHGR_MIN_TIME 4
#define PM8916_LBC_CHGR_MAX_TIME 256
struct pm8916_lbc_charger {
struct device *dev;
struct extcon_dev *edev;
struct power_supply *charger;
struct power_supply_battery_info *info;
struct regmap *regmap;
unsigned int reg[4];
bool online;
unsigned int charge_voltage_max;
unsigned int charge_voltage_safe;
unsigned int charge_current_max;
unsigned int charge_current_safe;
/* charger supervisor (Aurora B10B-3 v3) */
struct iio_channel *vbat_chan;
struct delayed_work supv_work;
struct mutex supv_lock;
int state;
int fault_reason;
unsigned int hold_uv; /* aurora,hold-voltage-microvolt, 0 = HOLD disabled */
unsigned int full_min_uv; /* aurora,full-min-voltage-microvolt */
unsigned int cv_hold_min; /* aurora,cv-hold-minutes */
unsigned int ibat_code; /* IBAT_MAX code programmed at probe */
unsigned int timeout_min;
int vbat_uv;
int latch_polls;
int nocv_polls;
time64_t cv_since; /* start of the current CV run, 0 = none */
bool supv_ready; /* set at the end of probe; IRQ kicks only after that */
unsigned int n_insert;
unsigned int n_hold;
unsigned int n_latch;
struct {
time64_t t;
int from, to, vbat;
const char *why;
} log[PM8916_LBC_SUPV_LOG];
unsigned int log_n;
struct dentry *debugfs;
};
enum {
LBC_ST_INIT = 0,
LBC_ST_NO_USB,
LBC_ST_CHARGING,
LBC_ST_HOLD,
LBC_ST_FAULT,
};
static const char * const lbc_state_name[] = {
[LBC_ST_INIT] = "INIT",
[LBC_ST_NO_USB] = "NO_USB",
[LBC_ST_CHARGING] = "CHARGING",
[LBC_ST_HOLD] = "HOLD",
[LBC_ST_FAULT] = "FAULT",
};
enum {
LBC_FAULT_NONE = 0,
LBC_FAULT_TIMER,
LBC_FAULT_OVP,
};
static const char * const lbc_fault_name[] = {
[LBC_FAULT_NONE] = "none",
[LBC_FAULT_TIMER] = "safety-timer (CHG_FAILED)",
[LBC_FAULT_OVP] = "vbat-overvoltage",
};
static const unsigned int pm8916_lbc_charger_cable[] = {
EXTCON_USB,
EXTCON_NONE,
};
enum {
LBC_CHGR = 0,
LBC_BAT_IF,
LBC_USB,
LBC_MISC,
};
static int pm8916_lbc_charger_configure(struct pm8916_lbc_charger *chg, bool probe)
{
int ret = 0;
unsigned int tmp;
chg->charge_voltage_max = clamp_t(u32, chg->charge_voltage_max,
PM8916_LBC_CHGR_MIN_VOLTAGE, chg->charge_voltage_safe);
tmp = chg->charge_voltage_max - PM8916_LBC_CHGR_MIN_VOLTAGE;
tmp /= PM8916_LBC_CHGR_VOLTAGE_STEP;
chg->charge_voltage_max = PM8916_LBC_CHGR_MIN_VOLTAGE + tmp * PM8916_LBC_CHGR_VOLTAGE_STEP;
/* after probe the supervisor owns VDD_MAX (charge level / hold level) */
if (probe) {
ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_VDD_MAX, tmp);
if (ret)
goto error;
}
chg->charge_current_max = min(chg->charge_current_max, chg->charge_current_safe);
tmp = clamp_t(u32, chg->charge_current_max,
PM8916_LBC_CHGR_MIN_CURRENT, PM8916_LBC_CHGR_MAX_CURRENT);
tmp = chg->charge_current_max / PM8916_LBC_CHGR_MIN_CURRENT - 1;
chg->charge_current_max = (tmp + 1) * PM8916_LBC_CHGR_MIN_CURRENT;
chg->ibat_code = tmp;
ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_IBAT_MAX, tmp);
if (ret)
goto error;
/*
* CHG_CTRL is written only at probe. Afterwards the supervisor owns CHG_EN, so a
* constant_charge_current update must not restart charging in HOLD/FAULT.
*/
if (probe) {
ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_CHG_CTRL,
PM8916_LBC_CHGR_CHG_EN | PM8916_LBC_CHGR_PSTG_EN);
if (ret)
goto error;
}
return ret;
error:
dev_err(chg->dev, "Failed to configure charging: %pe\n", ERR_PTR(ret));
return ret;
}
static int pm8916_lbc_charger_get_property(struct power_supply *psy,
enum power_supply_property psp,
union power_supply_propval *val)
{
struct pm8916_lbc_charger *chg = power_supply_get_drvdata(psy);
switch (psp) {
case POWER_SUPPLY_PROP_STATUS:
switch (chg->state) {
case LBC_ST_CHARGING:
val->intval = POWER_SUPPLY_STATUS_CHARGING;
break;
case LBC_ST_HOLD:
val->intval = POWER_SUPPLY_STATUS_FULL;
break;
case LBC_ST_NO_USB:
val->intval = POWER_SUPPLY_STATUS_DISCHARGING;
break;
default:
val->intval = POWER_SUPPLY_STATUS_NOT_CHARGING;
break;
}
return 0;
case POWER_SUPPLY_PROP_ONLINE:
val->intval = chg->online;
return 0;
case POWER_SUPPLY_PROP_CONSTANT_CHARGE_VOLTAGE_MAX:
val->intval = chg->charge_voltage_max;
return 0;
case POWER_SUPPLY_PROP_CONSTANT_CHARGE_CURRENT:
val->intval = chg->charge_current_max;
return 0;
default:
return -EINVAL;
};
}
static int pm8916_lbc_charger_set_property(struct power_supply *psy,
enum power_supply_property prop,
const union power_supply_propval *val)
{
struct pm8916_lbc_charger *chg = power_supply_get_drvdata(psy);
switch (prop) {
case POWER_SUPPLY_PROP_CONSTANT_CHARGE_CURRENT:
{
int ret;
mutex_lock(&chg->supv_lock);
chg->charge_current_max = val->intval;
ret = pm8916_lbc_charger_configure(chg, false);
mutex_unlock(&chg->supv_lock);
return ret;
}
default:
return -EINVAL;
}
}
static int pm8916_lbc_charger_property_is_writeable(struct power_supply *psy,
enum power_supply_property psp)
{
switch (psp) {
case POWER_SUPPLY_PROP_CONSTANT_CHARGE_CURRENT:
return true;
default:
return false;
}
}
static enum power_supply_property pm8916_lbc_charger_properties[] = {
POWER_SUPPLY_PROP_STATUS,
POWER_SUPPLY_PROP_ONLINE,
POWER_SUPPLY_PROP_CONSTANT_CHARGE_VOLTAGE_MAX,
POWER_SUPPLY_PROP_CONSTANT_CHARGE_CURRENT,
};
/*
* Aurora B10B-3 v4 charger supervisor: CHARGE -> HOLD -> (battery) -> CHARGE (v4 = v3 + FAULT safe clamp, B10B-5).
* Facts it relies on (B10A/B10B-2/B10B-3 tests): CHG_STATUS 00 + USB path 01 is a latch, not an end-of-charge;
* no hardware EOC was seen with BOOT_DONE set; CHG_EN = 0 does not stop the charger; verified levers are VDD_MAX,
* IBAT_MAX and the CHG_CTRL 0x21 -> 0xa0 edge (releases the latch). All decisions use the calibrated VADC VBAT.
* NO_USB: nothing is written.
* CHARGING: entered on USB insert/probe: BOOT_DONE, VDD_MAX = charge level, IBAT_MAX, restart edge.
* -> HOLD after the CV loop with VBAT >= full-min lasted cv-hold-minutes; 00/01 latch -> restart, stay.
* HOLD: only VDD_MAX = hold level; 00/01 latch -> restart edge, VDD_MAX stays at the hold level.
* FAULT: entered on VBAT > 4.25 V or CHG_FAILED; on entry only VDD_MAX = 0x00 (FAULT safe clamp to 4.00 V, B10B-4) +
* readback; no further charger writes, no restarts; left only by USB removal (-> NO_USB) or reboot.
* The clamp is NOT a guaranteed charge disconnect: with VBAT > 4.00 V charging stops and the board runs
* from the battery; with VBAT < 4.00 V the charger may still charge up to 4.00 V.
*/
static void lbc_supv_log(struct pm8916_lbc_charger *chg, int to, const char *why)
{
unsigned int i = chg->log_n++ % PM8916_LBC_SUPV_LOG;
chg->log[i].t = ktime_get_seconds();
chg->log[i].from = chg->state;
chg->log[i].to = to;
chg->log[i].vbat = chg->vbat_uv;
chg->log[i].why = why;
if (to == LBC_ST_FAULT)
dev_crit(chg->dev, "supervisor %s -> FAULT (%s), vbat %d uV: restarts blocked, FAULT safe clamp to 4.00 V\n",
lbc_state_name[chg->state], why, chg->vbat_uv);
else
dev_info(chg->dev, "supervisor %s -> %s (%s), vbat %d uV\n", lbc_state_name[chg->state],
lbc_state_name[to], why, chg->vbat_uv);
chg->state = to;
}
static int lbc_charge_enable(struct pm8916_lbc_charger *chg, bool en)
{
return regmap_update_bits(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_CHG_CTRL,
PM8916_LBC_CHGR_EN_MASK,
en ? PM8916_LBC_CHGR_CHG_EN : PM8916_LBC_CHGR_FORCE_BATT_ON);
}
/* the verified restart: CHG_CTRL 0x21 (CHG_EN 0) -> 20 ms -> 0xa0 (CHG_EN 1); on (re)insert also clear CHG_FAILED */
static int lbc_charge_restart(struct pm8916_lbc_charger *chg, bool clear_failed)
{
int ret;
if (clear_failed) {
ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_CHG_FAILED,
PM8916_LBC_CHGR_CHG_FAILED_BIT);
if (ret)
return ret;
}
ret = lbc_charge_enable(chg, false);
if (ret)
return ret;
msleep(20);
return lbc_charge_enable(chg, true);
}
static int lbc_set_vdd_max(struct pm8916_lbc_charger *chg, unsigned int uv)
{
uv = clamp_t(u32, uv, PM8916_LBC_CHGR_MIN_VOLTAGE, chg->charge_voltage_safe);
return regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_VDD_MAX,
(uv - PM8916_LBC_CHGR_MIN_VOLTAGE) / PM8916_LBC_CHGR_VOLTAGE_STEP);
}
/* USB insert / probe with USB: start a full cycle at the charge level */
static int lbc_enter_charging(struct pm8916_lbc_charger *chg)
{
unsigned int v;
int ret;
ret = regmap_update_bits(chg->regmap, chg->reg[LBC_MISC] + PM8916_LBC_MISC_BOOT_DONE,
PM8916_LBC_MISC_BOOT_DONE_BIT, PM8916_LBC_MISC_BOOT_DONE_BIT);
ret = ret ?: lbc_set_vdd_max(chg, chg->charge_voltage_max);
ret = ret ?: regmap_read(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_IBAT_MAX, &v);
if (!ret && v != chg->ibat_code)
ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_IBAT_MAX, chg->ibat_code);
ret = ret ?: lbc_charge_restart(chg, true);
chg->latch_polls = 0;
chg->nocv_polls = 0;
chg->cv_since = 0;
return ret;
}
/* 00/01 latch with USB valid: count polls; restart with the verified edge (VDD_MAX untouched) */
static bool lbc_handle_latch(struct pm8916_lbc_charger *chg, unsigned int sts, unsigned int path)
{
if (sts == 0 && !(path & PM8916_LBC_USB_PATH_ON))
chg->latch_polls++;
else
chg->latch_polls = 0;
if (chg->latch_polls < PM8916_LBC_SUPV_LATCH_POLLS)
return false;
chg->latch_polls = 0;
chg->n_latch++;
if (!lbc_charge_restart(chg, false))
dev_warn(chg->dev, "supervisor: 00/01 latch in %s (vbat %d uV) -> restart edge #%u\n",
lbc_state_name[chg->state], chg->vbat_uv, chg->n_latch);
return true;
}
/*
* FAULT safe clamp to 4.00 V (B10B-4): the only charger write on FAULT entry is VDD_MAX = 0x00 (lowest LBC step).
* Not a guaranteed charge disconnect - below 4.00 V the charger may still charge up to 4.00 V.
*/
static void lbc_fault_clamp(struct pm8916_lbc_charger *chg, const char *why)
{
unsigned int old = 0xff, rb = 0xff;
int ret;
ret = regmap_read(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_VDD_MAX, &old);
ret = ret ?: regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_VDD_MAX, 0x00);
ret = ret ?: regmap_read(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_VDD_MAX, &rb);
dev_crit(chg->dev, "FAULT safe clamp to 4.00 V: cause %s, vbat %d uV, VDD_MAX old 0x%02x -> readback 0x%02x (ret %d)\n",
why, chg->vbat_uv, old, rb, ret);
}
static bool lbc_enter_fault(struct pm8916_lbc_charger *chg, int reason, const char *why)
{
chg->fault_reason = reason;
lbc_fault_clamp(chg, why);
lbc_supv_log(chg, LBC_ST_FAULT, why);
return true;
}
static bool lbc_check_fault(struct pm8916_lbc_charger *chg, unsigned int failed)
{
if (failed & PM8916_LBC_CHGR_CHG_FAILED_BIT)
return lbc_enter_fault(chg, LBC_FAULT_TIMER, "CHG_FAILED (safety timer)");
if (chg->vbat_uv > PM8916_LBC_SUPV_OVP_UV)
return lbc_enter_fault(chg, LBC_FAULT_OVP, "vbat > 4.25 V");
return false;
}
static void lbc_supv_work(struct work_struct *work)
{
struct pm8916_lbc_charger *chg = container_of(work, struct pm8916_lbc_charger, supv_work.work);
unsigned int usb_rt, sts, path, failed;
time64_t now = ktime_get_seconds();
int ret, uv;
mutex_lock(&chg->supv_lock);
ret = regmap_read(chg->regmap, chg->reg[LBC_USB] + PM8916_INT_RT_STS, &usb_rt);
ret = ret ?: regmap_read(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_CHG_STATUS, &sts);
ret = ret ?: regmap_read(chg->regmap, chg->reg[LBC_USB] + PM8916_LBC_USB_PATH_STS, &path);
ret = ret ?: regmap_read(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_CHG_FAILED, &failed);
if (ret) {
dev_err(chg->dev, "supervisor: register read failed: %d\n", ret);
goto out;
}
if (!iio_read_channel_processed(chg->vbat_chan, &uv))
chg->vbat_uv = uv;
else
chg->vbat_uv = -1;
if (!(usb_rt & PM8916_LBC_USB_USBIN_VALID)) {
if (chg->state != LBC_ST_NO_USB) {
chg->fault_reason = LBC_FAULT_NONE;
lbc_supv_log(chg, LBC_ST_NO_USB, "usb removed");
}
goto out;
}
switch (chg->state) {
case LBC_ST_INIT:
case LBC_ST_NO_USB:
chg->fault_reason = LBC_FAULT_NONE;
chg->n_insert++;
if (!lbc_enter_charging(chg))
lbc_supv_log(chg, LBC_ST_CHARGING,
chg->state == LBC_ST_INIT ? "probe, usb present" : "usb inserted");
break;
case LBC_ST_CHARGING:
if (lbc_check_fault(chg, failed))
break;
if (lbc_handle_latch(chg, sts, path)) {
chg->cv_since = 0;
chg->nocv_polls = 0;
break;
}
if (!chg->hold_uv || chg->vbat_uv < 0)
break;
/* CV run: CV loop bit with VBAT >= full-min; tolerate one poll without the bit (05/07 interleave) */
if ((unsigned int)chg->vbat_uv < chg->full_min_uv) {
chg->cv_since = 0;
chg->nocv_polls = 0;
break;
}
if (sts & PM8916_LBC_CHGR_CV_LOOP) {
chg->nocv_polls = 0;
if (!chg->cv_since)
chg->cv_since = now;
} else if (++chg->nocv_polls >= PM8916_LBC_SUPV_NOCV_POLLS) {
chg->cv_since = 0;
}
if (chg->cv_since && now - chg->cv_since >= (time64_t)chg->cv_hold_min * 60) {
if (!lbc_set_vdd_max(chg, chg->hold_uv)) {
chg->n_hold++;
chg->latch_polls = 0;
lbc_supv_log(chg, LBC_ST_HOLD, "CV time reached, VDD_MAX -> hold level");
}
}
break;
case LBC_ST_HOLD:
if (lbc_check_fault(chg, failed))
break;
/* keep the board on USB: a 00/01 latch gets the restart edge, VDD_MAX stays at the hold level */
lbc_handle_latch(chg, sts, path);
break;
case LBC_ST_FAULT:
/* latched: left only by USB removal/insert or reboot */
break;
}
out:
mutex_unlock(&chg->supv_lock);
power_supply_changed(chg->charger);
queue_delayed_work(system_freezable_wq, &chg->supv_work,
msecs_to_jiffies(PM8916_LBC_SUPV_PERIOD_MS));
}
static int lbc_state_show(struct seq_file *s, void *unused)
{
struct pm8916_lbc_charger *chg = s->private;
static const struct { const char *n; int blk; unsigned int off; } regs[] = {
{ "CHG_STATUS", LBC_CHGR, PM8916_LBC_CHGR_CHG_STATUS },
{ "CHGR_RT", LBC_CHGR, PM8916_INT_RT_STS },
{ "CHG_CTRL", LBC_CHGR, PM8916_LBC_CHGR_CHG_CTRL },
{ "CHG_FAILED", LBC_CHGR, PM8916_LBC_CHGR_CHG_FAILED },
{ "VDD_MAX", LBC_CHGR, PM8916_LBC_CHGR_VDD_MAX },
{ "IBAT_MAX", LBC_CHGR, PM8916_LBC_CHGR_IBAT_MAX },
{ "TCHG_MAX_EN", LBC_CHGR, PM8916_LBC_CHGR_TCHG_MAX_EN },
{ "TCHG_MAX", LBC_CHGR, PM8916_LBC_CHGR_TCHG_MAX },
{ "USB_PATH", LBC_USB, PM8916_LBC_USB_PATH_STS },
{ "USB_RT", LBC_USB, PM8916_INT_RT_STS },
{ "BAT_RT", LBC_BAT_IF, PM8916_INT_RT_STS },
{ "BOOT_DONE", LBC_MISC, PM8916_LBC_MISC_BOOT_DONE },
};
time64_t now = ktime_get_seconds();
unsigned int i, v;
mutex_lock(&chg->supv_lock);
seq_printf(s, "state %s fault %s vbat_uv %d\n", lbc_state_name[chg->state],
lbc_fault_name[chg->fault_reason], chg->vbat_uv);
seq_printf(s, "charge_uv %u hold_uv %u full_min_uv %u cv_hold_min %u cv_s %lld nocv %d timeout_min %u\n",
chg->charge_voltage_max, chg->hold_uv, chg->full_min_uv, chg->cv_hold_min,
chg->cv_since ? now - chg->cv_since : -1LL, chg->nocv_polls, chg->timeout_min);
seq_printf(s, "n_insert %u n_hold %u n_latch %u\n", chg->n_insert, chg->n_hold, chg->n_latch);
for (i = 0; i < ARRAY_SIZE(regs); i++) {
if (regmap_read(chg->regmap, chg->reg[regs[i].blk] + regs[i].off, &v))
v = 0xffff;
seq_printf(s, "%s %02x\n", regs[i].n, v);
}
for (i = chg->log_n > PM8916_LBC_SUPV_LOG ? chg->log_n - PM8916_LBC_SUPV_LOG : 0; i < chg->log_n; i++) {
unsigned int j = i % PM8916_LBC_SUPV_LOG;
seq_printf(s, "log %u t=%lld %s->%s vbat=%d %s\n", i, chg->log[j].t,
lbc_state_name[chg->log[j].from], lbc_state_name[chg->log[j].to],
chg->log[j].vbat, chg->log[j].why);
}
mutex_unlock(&chg->supv_lock);
return 0;
}
DEFINE_SHOW_ATTRIBUTE(lbc_state);
static void lbc_debugfs_remove(void *data)
{
debugfs_remove_recursive(data);
}
static irqreturn_t pm8916_lbc_charger_state_changed_irq(int irq, void *data)
{
struct pm8916_lbc_charger *chg = data;
unsigned int tmp;
int ret;
ret = regmap_read(chg->regmap, chg->reg[LBC_USB] + PM8916_INT_RT_STS, &tmp);
if (ret)
return IRQ_HANDLED;
chg->online = !!(tmp & PM8916_LBC_USB_USBIN_VALID);
extcon_set_state_sync(chg->edev, EXTCON_USB, chg->online);
power_supply_changed(chg->charger);
if (READ_ONCE(chg->supv_ready))
mod_delayed_work(system_freezable_wq, &chg->supv_work, 0);
return IRQ_HANDLED;
}
static int pm8916_lbc_charger_probe_dt(struct pm8916_lbc_charger *chg)
{
struct device *dev = chg->dev;
int ret = 0;
unsigned int tmp;
ret = device_property_read_u32(dev, "qcom,fast-charge-safe-voltage", &chg->charge_voltage_safe);
if (ret)
return ret;
if (chg->charge_voltage_safe < PM8916_LBC_CHGR_MIN_VOLTAGE)
return -EINVAL;
chg->charge_voltage_safe = clamp_t(u32, chg->charge_voltage_safe,
PM8916_LBC_CHGR_MIN_VOLTAGE, PM8916_LBC_CHGR_MAX_VOLTAGE);
tmp = chg->charge_voltage_safe - PM8916_LBC_CHGR_MIN_VOLTAGE;
tmp /= PM8916_LBC_CHGR_VOLTAGE_STEP;
ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_VDD_SAFE, tmp);
if (ret)
return ret;
ret = device_property_read_u32(dev, "qcom,fast-charge-safe-current", &chg->charge_current_safe);
if (ret)
return ret;
if (chg->charge_current_safe < PM8916_LBC_CHGR_MIN_CURRENT)
return -EINVAL;
chg->charge_current_safe = clamp_t(u32, chg->charge_current_safe,
PM8916_LBC_CHGR_MIN_CURRENT, PM8916_LBC_CHGR_MAX_CURRENT);
chg->charge_current_max = chg->charge_current_safe;
tmp = chg->charge_current_safe / PM8916_LBC_CHGR_MIN_CURRENT - 1;
ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_IBAT_SAFE, tmp);
if (ret)
return ret;
/*
* Keep the charger safety timer running (upstream disabled it). Same sequence as the
* downstream qpnp-linear-charger: timer off, TCHG_MAX = minutes / 4 - 1 (4..512 min), timer on.
*/
chg->timeout_min = PM8916_LBC_TIMEOUT_DEFAULT_MIN;
device_property_read_u32(dev, "qcom,charge-timeout-minutes", &chg->timeout_min);
chg->timeout_min = clamp_t(u32, chg->timeout_min, PM8916_LBC_TIMEOUT_STEP_MIN,
PM8916_LBC_TIMEOUT_MAX_MIN);
chg->timeout_min -= chg->timeout_min % PM8916_LBC_TIMEOUT_STEP_MIN;
ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_TCHG_MAX_EN, 0x00);
if (ret)
return ret;
tmp = chg->timeout_min / PM8916_LBC_TIMEOUT_STEP_MIN - 1;
ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_TCHG_MAX, tmp);
if (ret)
return ret;
ret = regmap_write(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_TCHG_MAX_EN,
PM8916_LBC_CHGR_TCHG_MAX_ENABLED);
if (ret)
return ret;
ret = regmap_read(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_TCHG_MAX, &tmp);
if (ret)
return ret;
if (tmp != chg->timeout_min / PM8916_LBC_TIMEOUT_STEP_MIN - 1)
return dev_err_probe(dev, -EIO, "TCHG_MAX readback 0x%x != 0x%x\n", tmp,
chg->timeout_min / PM8916_LBC_TIMEOUT_STEP_MIN - 1);
dev_info(dev, "safety timer %u min (TCHG_MAX 0x%02x), enabled\n", chg->timeout_min, tmp);
return ret;
}
static const struct power_supply_desc pm8916_lbc_charger_psy_desc = {
.name = "pm8916-lbc-chgr",
.type = POWER_SUPPLY_TYPE_USB,
.properties = pm8916_lbc_charger_properties,
.num_properties = ARRAY_SIZE(pm8916_lbc_charger_properties),
.get_property = pm8916_lbc_charger_get_property,
.set_property = pm8916_lbc_charger_set_property,
.property_is_writeable = pm8916_lbc_charger_property_is_writeable,
};
static int pm8916_lbc_charger_probe(struct platform_device *pdev)
{
struct device *dev = &pdev->dev;
struct pm8916_lbc_charger *chg;
struct power_supply_config psy_cfg = {};
int ret, len, irq;
unsigned int tmp;
chg = devm_kzalloc(dev, sizeof(*chg), GFP_KERNEL);
if (!chg)
return -ENOMEM;
chg->dev = dev;
mutex_init(&chg->supv_lock);
chg->regmap = dev_get_regmap(pdev->dev.parent, NULL);
if (!chg->regmap)
return -ENODEV;
len = device_property_count_u32(dev, "reg");
if (len < 0)
return len;
if (len != 4)
return dev_err_probe(dev, -EINVAL,
"Wrong amount of reg values: %d (4 expected)\n", len);
ret = device_property_read_u32_array(dev, "reg", chg->reg, len);
if (ret)
return ret;
ret = regmap_bulk_read(chg->regmap, chg->reg[LBC_CHGR] + PM8916_PERPH_TYPE, &tmp, 2);
if (ret)
goto comm_error;
if (tmp != PM8916_LBC_CHGR_TYPE)
goto type_error;
ret = regmap_bulk_read(chg->regmap, chg->reg[LBC_BAT_IF] + PM8916_PERPH_TYPE, &tmp, 2);
if (ret)
goto comm_error;
if (tmp != PM8916_LBC_BAT_IF_TYPE)
goto type_error;
ret = regmap_bulk_read(chg->regmap, chg->reg[LBC_USB] + PM8916_PERPH_TYPE, &tmp, 2);
if (ret)
goto comm_error;
if (tmp != PM8916_LBC_USB_TYPE)
goto type_error;
ret = regmap_bulk_read(chg->regmap, chg->reg[LBC_MISC] + PM8916_PERPH_TYPE, &tmp, 2);
if (ret)
goto comm_error;
if (tmp != PM8916_LBC_MISC_TYPE)
goto type_error;
ret = regmap_read(chg->regmap, chg->reg[LBC_CHGR] + PM8916_LBC_CHGR_CHG_OPTION, &tmp);
if (ret)
goto comm_error;
if (tmp != PM8916_LBC_CHGR_PMIC_CHARGER)
dev_err_probe(dev, -ENODEV, "The system is using an external charger\n");
ret = pm8916_lbc_charger_probe_dt(chg);
if (ret)
return dev_err_probe(dev, ret, "Error while parsing device tree\n");
psy_cfg.drv_data = chg;
psy_cfg.fwnode = dev_fwnode(dev);
chg->charger = devm_power_supply_register(dev, &pm8916_lbc_charger_psy_desc, &psy_cfg);
if (IS_ERR(chg->charger))
return dev_err_probe(dev, PTR_ERR(chg->charger), "Unable to register charger\n");
ret = power_supply_get_battery_info(chg->charger, &chg->info);
if (ret)
return dev_err_probe(dev, ret, "Unable to get battery info\n");
chg->vbat_chan = devm_iio_channel_get(dev, "vbat");
if (IS_ERR(chg->vbat_chan))
return dev_err_probe(dev, PTR_ERR(chg->vbat_chan), "no VADC vbat channel\n");
chg->cv_hold_min = PM8916_LBC_CV_HOLD_DEFAULT_MIN;
device_property_read_u32(dev, "aurora,cv-hold-minutes", &chg->cv_hold_min);
if (device_property_read_u32(dev, "aurora,hold-voltage-microvolt", &chg->hold_uv) ||
device_property_read_u32(dev, "aurora,full-min-voltage-microvolt", &chg->full_min_uv)) {
chg->hold_uv = 0;
dev_warn(dev, "no aurora,hold-voltage/full-min-voltage: HOLD disabled\n");
}
ret = devm_delayed_work_autocancel(dev, &chg->supv_work, lbc_supv_work);
if (ret)
return ret;
irq = platform_get_irq_byname(pdev, "usb_vbus");
if (irq < 0)
return irq;
chg->edev = devm_extcon_dev_allocate(dev, pm8916_lbc_charger_cable);
if (IS_ERR(chg->edev))
return PTR_ERR(chg->edev);
ret = devm_extcon_dev_register(dev, chg->edev);
if (ret < 0)
return dev_err_probe(dev, ret, "failed to register extcon device\n");
ret = devm_request_threaded_irq(dev, irq, NULL, pm8916_lbc_charger_state_changed_irq,
IRQF_ONESHOT, "pm8916_lbc", chg);
if (ret)
return ret;
ret = regmap_read(chg->regmap, chg->reg[LBC_USB] + PM8916_INT_RT_STS, &tmp);
if (ret)
goto comm_error;
chg->online = !!(tmp & PM8916_LBC_USB_USBIN_VALID);
extcon_set_state_sync(chg->edev, EXTCON_USB, chg->online);
chg->charge_voltage_max = chg->info->voltage_max_design_uv;
ret = pm8916_lbc_charger_configure(chg, true);
if (ret)
return ret;
chg->debugfs = debugfs_create_dir("pm8916_lbc", NULL);
debugfs_create_file("state", 0444, chg->debugfs, chg, &lbc_state_fops);
ret = devm_add_action_or_reset(dev, lbc_debugfs_remove, chg->debugfs);
if (ret)
return ret;
if (chg->hold_uv && (chg->hold_uv < PM8916_LBC_CHGR_MIN_VOLTAGE ||
chg->hold_uv >= chg->charge_voltage_max ||
chg->full_min_uv > chg->charge_voltage_max)) {
dev_warn(dev, "invalid hold %u / full-min %u for charge level %u: HOLD disabled\n",
chg->hold_uv, chg->full_min_uv, chg->charge_voltage_max);
chg->hold_uv = 0;
}
dev_info(dev, "supervisor v3: charge %u uV, hold %u uV, full-min %u uV, cv %u min, IBAT_MAX code %u, ovp %d uV\n",
chg->charge_voltage_max, chg->hold_uv, chg->full_min_uv, chg->cv_hold_min,
chg->ibat_code, PM8916_LBC_SUPV_OVP_UV);
WRITE_ONCE(chg->supv_ready, true);
queue_delayed_work(system_freezable_wq, &chg->supv_work, 0);
return 0;
comm_error:
return dev_err_probe(dev, ret, "Unable to communicate with device\n");
type_error:
return dev_err_probe(dev, -ENODEV, "Device reported wrong type: 0x%X\n", tmp);
}
static const struct of_device_id pm8916_lbc_charger_of_match[] = {
{ .compatible = "qcom,pm8916-lbc", },
{}
};
MODULE_DEVICE_TABLE(of, pm8916_lbc_charger_of_match);
static struct platform_driver pm8916_lbc_charger_driver = {
.driver = {
.name = "pm8916-lbc",
.of_match_table = pm8916_lbc_charger_of_match,
},
.probe = pm8916_lbc_charger_probe,
};
module_platform_driver(pm8916_lbc_charger_driver);
MODULE_DESCRIPTION("pm8916 LBC driver");
MODULE_AUTHOR("Nikita Travkin <nikita@trvn.ru>");
MODULE_LICENSE("GPL");

Some files were not shown because too many files have changed in this diff Show more