# B11C — unused LED footprints + MPP3: trace map and continuity plan (NO WRITES) Date: 2026-10-04. Inputs: B11-LED-AUDIT.md and B11-LED-RESULT.md (B11A/B11B closed). Nothing was switched or written in B11C. ## 0. Limitation: there are no board photos The workspace (local mirror and 480s `~/doc/modem`) contains **no photos of the PCB**. The only images are the splash, the LK logo and recovery icons. Step 1 (find all LEDs and DNP LED footprints from photos) and step 2 (read polarity, resistor values and traces from photos) therefore **cannot be done yet**. Nothing below assigns a footprint to a pin. That would be invented. What is needed (put the files in `logs/b11/b11c/photos/`): - top and bottom of the bare PCB, shot straight down, sharp at full resolution, with the shield cans as they are (do not remove them); - a close-up of every LED and every empty 2-pad LED-like footprint, together with the 1–2 small resistor pads next to it; - the silkscreen designators (D?, LED?, R?) if any are printed; - one photo with a ruler or a coin for scale. From these I can fill §2: polarity marks, R markings, which pad visibly goes to a ground pour, a VBAT/VPH plane, or a via toward the PMIC. ## 1. What is known about the candidate controllers (from audit and PMIC driver facts) | Controller | live state (read-only) | what an LED on it would look like | can it light an LED by itself | |---|---|---|---| | PM8916 **MPP3** | current-sink mode, source = off (0xa240 = 0x60), EN 0x80, I = 5 mA setting | **sink topology**: rail (VPH/VBAT) → LED anode, cathode → (R or none) → MPP3. Same as the MPP4 backlight. | yes (5–40 mA regulated sink, so no resistor is required) | | PM8916 GPIO1–4 | input, pull-down 10 µA | either sink (rail → LED → R → GPIO, open-drain low) or source (GPIO → R → LED → GND, needs a VPH-powered GPIO) | yes, with a series R | | PM8916 VIB_DRV | off, VSET 0x16 | motor-driver output, 1.2–3.1 V (pm8xxx-vibrator, PM8916 regs 0x41/0x46); polarity on this PCB is unknown | possibly (it can drive a LED+R like a small load), but this is not proven | | PM8916 MPP4 | backlight sink, ON | already used; a footprint on this net would only add an LED to the backlight | n/a | | SoC TLMM (unclaimed pins) | inputs, pull-down, 1.8 V I/O | GPIO → R → LED → GND | weak: 1.8 V I/O cannot forward-bias most LEDs, at best a red LED with a tiny current. Low prior. | | PM8916 LPG/PWM | off | only drives a pin through MPP/GPIO DTEST routing | only if a PM GPIO/MPP is the wired pin | A meter alone cannot tell **which** PMIC pin a trace reaches: MPP3, GPIO1–4 and VIB_DRV all show a similar ESD-diode signature. Continuity tells the **topology** (GND side / rail side / IC side, and whether the resistor is populated). The pin itself is identified in a later, separate **one-line identification step** (§5) or by the powered voltage map (§3, phase V), which is read-only for the board. ## 2. Footprint map (to fill in after photos and measurements) | ID | position | type (LED / DNP LED) | pad A | pad B | series R (ID, marking, Ω in-circuit) | A→ | B→ | far node diode V (fwd / rev) | far node 0 Ω to known net? | V(on) far node | topology | controller/pin | verdict | |---|---|---|---|---|---|---|---|---|---|---|---|---|---| | D? | | | | | | | | | | | | | needs continuity measurement | Verdict categories: **SAFE candidate** / **needs continuity measurement** / **not LED / unrelated** / **do not touch**. ## 3. Measurement instructions for the operator ### Safety and preparation (mandatory) 1. **Fully de-energise the board.** Pull the USB cable, **take the battery out** (the board cannot power off by software and the PMIC stays alive on battery), and **disconnect the CH340 UART wires** (TX backfeed keeps the PMIC alive, see T3C). Wait ≥ 60 s. Reason: the 2026-10-03 probe slip shorted VBAT to GND (UVLO). Continuity and diode tests on a powered board give false readings and can short rails. 2. You can keep the DMM leads already soldered to VBAT/GND, as long as the battery is out. 3. Use thin, sharp probes, one pad at a time. Never bridge two neighbouring pads. ### Reference nodes (measure these first and write the values down) | Ref | where | why | |---|---|---| | GND | USB connector shell, or battery − contact | ground | | VBAT | battery + contact (or your soldered VBAT lead) | LED anode rail candidate (VPH ≈ VBAT on this board, but through the LBC FET, so it may **not** read 0 Ω) | | VBUS | USB connector pin 1 (5 V) | some designs hang a "charge/power" LED on VBUS | | BL-K | the backlight cathode pin on the display flex/connector (LED-K / LEDK), = **MPP4** node | a known PMIC MPP signature, and a check for "shares the backlight net" | | BL-A | the backlight anode pin (LED-A) | it reveals the rail the backlight uses (VPH/VBAT?) | | UART-RX / UART-TX | the pads where the CH340 was soldered (SoC GPIO5 / GPIO4) | a known SoC 1.8 V GPIO signature | For each Ref, record the **diode-mode** reading with the red probe on GND and the black probe on Ref, then reversed. Also record **resistance** Ref→GND. ### Per footprint (repeat for every LED / DNP LED, priority order in §4) Label the footprint pads A and B. If there is a polarity mark, A = the cathode side. Label the resistor pads R1 (toward the LED) and R2 (far side). | Step | DMM mode | probes | record | |---|---|---|---| | M1 | continuity / 200 Ω | A ↔ GND, B ↔ GND | Ω (0 Ω means that pad is ground) | | M2 | 200 Ω (wait 2–3 s, rail capacitors charge) | A ↔ VBAT, B ↔ VBAT, A ↔ BL-A, B ↔ BL-A, A ↔ VBUS, B ↔ VBUS | Ω | | M3 | continuity | A ↔ R1, B ↔ R1 (find which LED pad the resistor belongs to) | 0 Ω / OL | | M4 | 2 kΩ / 20 kΩ | R1 ↔ R2 | in-circuit Ω (with R populated, about its value; with R DNP, OL), plus the marking (e.g. "102" = 1 kΩ, "471" = 470 Ω) | | M5 | diode | **far node** = R2, or the LED pad that is neither GND nor rail when no R is present: red on GND, black on far node; then reversed | V fwd / V rev (an IC pin with ESD is typically ~0.4–0.7 V; OL both ways means nothing is connected) | | M6 | continuity | far node ↔ BL-K, far node ↔ UART-RX, far node ↔ UART-TX | 0 Ω / OL (exclusion checks) | | M7 | diode | across the LED pads (populated LEDs only): red on A, black on B, then reversed | the forward reading or a faint glow gives polarity | Write down: footprint ID, position (e.g. "top side, left of SIM slot"), the photo filename, and every value above. ### Phase V (optional, read-only for the board, separate operator decision): powered voltage map Only if you are comfortable doing it. Clip the black lead to the USB shell first. The board runs normally on USB with the battery in. Measure **DC volts** at each **far node** with one sharp red probe. Software state is known from the audit, so the voltage separates the candidates without any write: | expected far-node voltage (sink topology, LED anode on rail) | means | |---|---| | ≈ rail (≈ VBAT, LED dark) | high-Z pin: **MPP3** (sink off) or VIB_DRV off. Candidate MPP3. | | ≈ rail − 1.6…2.5 V, LED dark | 10 µA pull-down: **PM GPIO1–4** | | ≤ ~2.3 V, clamped | SoC 1.8 V pad (TLMM). Low priority. | | ≈ 0 V | the node is driven low or tied to GND | For source topology (LED to GND), every candidate pin is low or high-Z, so all read ≈ 0 V and phase V does not separate them. ## 4. Priority order 1. Footprints whose far node is on the **rail side + IC side** (sink topology) → **MPP3** first (the only PMIC output already configured as a sink). 2. Then sink/source footprints that fit **PM GPIO1–4**. 3. Then **VIB_DRV** (expect a single pin near the PMIC; on many boards there is a motor pad pair). 4. SoC GPIO only if a trace visibly runs to an unclaimed TLMM pin, and is **never** any pin from the DO-NOT-TOUCH list: reset/PON/EDL (KPDPWR, RESIN, USB D+), SIM/UIM (1, 20, 22, 23, 57–60), UART (4, 5), SPI/display (12–15, 116, 118), WCNSS (40–44), RF/SSBI/GRFC (99–106), USB-ID (110), audio (63–68, 113), eMMC/SD pads, MPP1, MPP2. ## 5. Decision rules after measurement | result | verdict | |---|---| | R populated (or a sink-only design with no R) + sink topology + far node = IC pin + phase V says high-Z | **SAFE candidate → MPP3** (confirm in the RAM ID step) | | R populated + topology proven + far node = IC pin, but which PMIC pin is unknown | **needs continuity measurement** (or the ID step below) | | R DNP, or far node OL (no IC), or topology unproven | document only, **do not switch** | | far node 0 Ω to BL-K | part of the backlight (MPP4). **not a separate LED.** | | far node 0 Ω to UART/any DO-NOT-TOUCH net, or the pad is a rail/GND-only test point | **not LED / do not touch** | ## 6. One common RAM-only plan (prepared only, needs a separate GO; nothing built) Base = the production kernel **7.2.7-aurora-b10b5** unchanged. Its config already has `LEDS_GPIO=y`, `LEDS_QCOM_LPG=y`, `PWM=y`, `PINCTRL_QCOM_SPMI_PMIC=y`, `INPUT_PM8XXX_VIBRATOR=y` and `LEDS_TRIGGER_TIMER=y`, so the plan is a **DTB-only change** on top of prod DTB e47762d1. Boot it with RESET-held power-on, then `fastboot boot`. **No cache/eMMC write.** 1. **ID step (one boot, before the LED image; separate GO):** with the operator watching the footprints, one 0.5 s pulse per candidate, each preceded by a register snapshot and followed by a restore and readback: MPP3 sink 5 mA ON → OFF; then each PM GPIO that §5 left as a candidate (open-drain low for sink topology, push-pull high for source topology; never both); then VIB at minimum level 1.2 V for 0.5 s (only if a footprint was traced to the vibrator pads). Only candidates that passed continuity are pulsed. The rest stay untouched. The same monitor and abort logic as `b11/run/b11-led-run.sh`. 2. **LED image (the same boot, or a second DTB):** every confirmed line goes into one `gpio-leds` node, `aurora-led-`: - MPP3: the same recipe as B9B MPP4: `&pm8916_mpps` pinctrl `pins = "mpp3"; function = "sink"; qcom,drive-strength = ` (sink level, the lowest that is visibly lit, starting at 0 = 5 mA), output-low at probe, plus a gpio-leds entry `gpios = <&pm8916_mpps 3 GPIO_ACTIVE_HIGH>`, `default-state = "off"`. - PM GPIO n: `&pm8916_gpios` pinctrl (`function = "normal"`, `power-source` matching the rail, `drive-open-drain` for sink topology), plus a gpio-leds entry with the measured active level. - Backlight MPP4 stays on gpio-backlight (unchanged). - PWM/brightness: only if a confirmed line is a PM GPIO/MPP that the LPG can be routed to (`qcom,pm8916-pwm` + `leds-pwm`). Otherwise there is no brightness test. 3. **Run:** the existing `b11/run/b11-led-run.sh`, with `LEDS="L1:…backlight… L2:/sys/class/leds/aurora-led-x/brightness:1:0 …"`. Stages: all OFF → all ON 4 s → OFF → chase 2× → (PWM) → restore. The same monitor (LTE, Wi-Fi/WCNSS, NCM, display, charger, PMIC temp, kernel errors), pre/post PMIC dump diff with `b11/audit/b11-ro.sh`. ## 7. Current verdicts (before measurement) | footprint | resistor | controller/pin | verdict | |---|---|---|---| | LCD backlight (populated, inside the panel) | none (current sink) | PM8916 MPP4 | SAFE (done in B11B) | | all other LED / DNP LED footprints | unknown (no photos) | unknown | **needs continuity measurement** | | MPP3 | — | PM8916 MPP3 (sink, off) | SAFE candidate *only after* a footprint is traced to it, otherwise UNKNOWN | | PM GPIO1–4 | — | PM8916 GPIO1–4 | needs continuity measurement | | VIB_DRV | — | PM8916 vibrator | needs continuity measurement | | MPP1, MPP2, SIM/UART/SPI/WCNSS/UIM/RF/USB/eMMC/PON lines | — | — | do not touch | STOP. Nothing is switched without a separate GO.