# Aurora ARM64 bootchain — staged write plan (NOT EXECUTED; each stage needs explicit user approval) Run on 480s: cd ~/doc/modem/jz08-aurora ; M=bootchain-migration ; O=logs/bootchain ; mkdir -p $O L=firehose/007050e100000000_394a2e47cf830150_fhprg_peek.bin (sha256 53f19350…5aca) Every edl call: --loader=$L . NEVER `edl reset`. After each stage: physical power-cycle + full UART log. Entry to EDL: S1 from Android `adb reboot edl`; later stages: lk1st `fastboot oem reboot-edl` or the HW button (S0). ## S0 — prerequisite, NO WRITE: prove hardware EDL entry (button on GPIO37 / KEY_F2). If it fails: STOP. ## S1 — aboot ← lk1st-aurora (stock tz/hyp/GPT kept; proven order on JZ02) edl --loader=$L printgpt # aboot must be 264192 / 0x100000 edl --loader=$L w aboot $M/aboot-lk1st-aurora.pad1M # e4addbf8…6482 edl --loader=$L r aboot $O/S1-aboot-readback.bin sha256sum $M/aboot-lk1st-aurora.pad1M $O/S1-aboot-readback.bin ; cmp $M/aboot-lk1st-aurora.pad1M $O/S1-aboot-readback.bin && echo S1_MATCH expect after power-cycle: SBL1 → lk1st "welcome to lk" → forced fastboot 18d1:d00d, getvar product lk1st-msm8916; test `fastboot oem reboot-edl` → 9008. ROLLBACK S1: edl w aboot $M/orig-aboot.bin ; edl r aboot $O/S1-rb.bin ; cmp $M/orig-aboot.bin $O/S1-rb.bin # fd1af167…053a ## S2 — GPT delta + copy stock tzbak to its new place (tz content unchanged) edl --loader=$L ws 0 $M/aurora-new-gpt-primary-34sectors.bin # 6e850a5d…b8b6 edl --loader=$L ws 7634911 $M/aurora-new-gpt-backup-33sectors.bin # 795952a1…e18f edl --loader=$L ws 305184 $M/orig-tzbak.bin # c6f7db26…b4af edl --loader=$L rs 0 34 $O/S2-gptp.bin ; edl --loader=$L rs 7634911 33 $O/S2-gptb.bin ; edl --loader=$L rs 305184 1024 $O/S2-tzbak.bin edl --loader=$L rs 270336 2048 $O/S2-tzarea.bin # must still equal orig-tzarea (unchanged bytes) cmp $M/aurora-new-gpt-primary-34sectors.bin $O/S2-gptp.bin ; cmp $M/aurora-new-gpt-backup-33sectors.bin $O/S2-gptb.bin cmp $M/orig-tzbak.bin $O/S2-tzbak.bin ; cmp $M/orig-tzarea-LBA270336-272383.bin $O/S2-tzarea.bin && echo S2_MATCH expect: identical boot to S1 (stock tz still first 512K of enlarged tz); getvar partition-size:tz 0x100000. ROLLBACK S2: ws 0 $M/orig-gpt-primary-LBA0-33.bin ; ws 7634911 $M/orig-gpt-backup-LBA7634911-7634943.bin ; ws 305184 $M/orig-gap-LBA305184-306207.bin ; rs + cmp each ## S3 — tz + hyp as a PAIR (never hyp alone: JZ02 S3 proved hang) edl --loader=$L ws 270336 $M/tz-db410c.pad1M # 8481892f…5363 (1 MiB, whole enlarged tz) edl --loader=$L ws 272384 $M/hyp-qhypstub.pad512K # 1a963047…4555 edl --loader=$L rs 270336 2048 $O/S3-tz.bin ; edl --loader=$L rs 272384 1024 $O/S3-hyp.bin cmp $M/tz-db410c.pad1M $O/S3-tz.bin ; cmp $M/hyp-qhypstub.pad512K $O/S3-hyp.bin && echo S3_MATCH expect: SBL1 → lk1st fastboot; lk1st detects PSCI. ROLLBACK S3: ws 270336 $M/orig-tzarea-LBA270336-272383.bin ; ws 272384 $M/orig-hyp.bin ; rs + cmp ## S4 — RAM only: fastboot boot linux/ramboot1/aurora-ramboot1.img (470ce4f8…) via lk1st ## FULL STOCK RESTORE (any state): S3 rollback → S2 rollback → S1 rollback (then Android + adb reboot edl return).