# B10B3-TESTD4-RESULT — safety timer in FAST charge: real expiry observed (unchanged v3 Test D image, low entry VBAT) Date: 2026-10-04 (UTC 2026-10-03 22:57–23:32). **Verdict: PASS — the 8-min safety timer expired exactly at t = 480 s, and its hardware effect is established: the LBC leaves the fast-charge state (FAST_CHG_ON 1→0, USB path 02→01) but does NOT stop charging and does NOT set CHG_FAILED.** Image `b10/b10b3/out-d/aurora-b10b3d.img` 43739e55 (unchanged Test D: v3 driver, charge 4.10 V, HOLD 4.00 V, full-min 4.05 V, CV 5 min, 450 mA, timer 8 min = TCHG_MAX 0x01, TCHG_EN 0x80). No manual register writes, eMMC w=0. ## Preparation Battery discharged on B9C in the 00/01 latch (USB pull/replug → board on battery, NCM alive; `d4pre-actions.txt`): 4×yes ≈ 66 min, rest DMM 3.792 V. Class A (RTC 3 s; `pre-testD4-classA-check.txt`, `pre-testD4-classA-dump.txt`, `pre-testD4-vs-preD3-diff.txt`: only 0x100B 43→03, 0x1010 01→00 + ADC/BMS/RTC). B9C DMM 3.86 V, USB 0.41 A. RESET-held reboot → fastboot +26 s → boot 22:59:17 UTC, RTC 4 s. Probe: `safety timer 8 min (TCHG_MAX 0x01), enabled` at 0.924 s (t = 0); `INIT -> CHARGING (probe, usb present), vbat 3794427 uV` at 0.960 s. ## Timeline (monitor 5 s, 370 samples, t from 0.924 s) | t | CHGR RT | path | CHG_STATUS | CHG_FAILED (0x104A) | CHG_CTRL | VADC VBAT | USBIN | |---|---|---|---|---|---|---|---| | 13 s | **20** (FAST_CHG_ON) | **02** | 05 | 00 | a0 | 3.885 V | 4.885 V | | 13–475.4 s | 20 | 02 | 05 | 00 | a0 | 3.885 → 3.908 V (CC) | 4.884–4.887 V | | **480.5 s** | **00** | **01** | 05 | 00 | a0 | 3.906 V | 4.885 V | | 480–1476 s | 00 | 01 | 05 | 00 | a0 | 3.906 → 3.934 V | unchanged | | 1476–1877 s | 00 ↔ 01 (bit0 vbat-det-lo toggling) | 01 | 05 | 00 | a0 | 3.934 → 3.947 V | unchanged | Transition between the samples at t = 475.40 s and 480.53 s → **expiry at 8 min (t ≈ 476–480.5 s)**, matching TCHG_MAX = 0x01 = (1+1)·4 min. USBIN mean before 4.8854 V (91 samples) vs after 4.8849 V (279) — the input current did not change. Operator USB meter after the event (logged 23:23:51 UTC, t ≈ 1470 s): 0.409 A (before boot 0.41 A). VBAT kept rising after the expiry (+41 mV in 23 min). VDD_MAX 04, IBAT_MAX 04, TCHG 80/01 unchanged; state stayed CHARGING (supervisor saw no CHG_FAILED → no FAULT; no CV yet, so no HOLD). No ALERT; PMIC max 52.5 °C. LTE START OK 82.7 s, ping 4/4, Wi-Fi AP enabled 87.1 s. CHGR interrupt registers 0x1011–0x1019 all 00 after the event (CHGR IRQs are not enabled by anyone → no latched status). 0x100A/0x100C/0x100D, 0x104B/0x104C (ATC in the SMBB map) 00. End dump vs class A (`d4-vs-classA-diff.txt`, charger blocks): 0x1040 08→04, 0x1044 00→04, 0x1045 0a→04, 0x1049 90→a0, 0x1061 1d→01, 0x1642 00→80 (+0x1643), status 0x100B/0x1010/0x1308 — the planned v3 set; 0x1060 80, 0x104A 00, 0x105B 09, 0x10EE 00 unchanged. ## Answers 1. CHG_FAILED changes? **No** — neither 0x104A nor the chg-failed RT bit (0x1010 bit6). 2. Charging stops? **No** — 0.41 A continues, VBAT rises; the limit remains VDD_MAX regulation. 3. CHG_STATUS / CHG_CTRL / path: CHG_STATUS 05 and CHG_CTRL a0 unchanged; **path 02 → 01, FAST_CHG_ON 1 → 0**. 4. USB still powers the system: yes (charging + board from USB). 5. Automatic recovery: FAST_CHG_ON did not return within 23 min; since charging never stopped there is nothing to recover from. 6. Driver intervention: none needed for charging to continue; v3's FAULT path is never triggered by this expiry. ## Consequences (combined with T1DIAG/D2/D3) - TCHG encoding `minutes/4 − 1` and counting from the probe programming are confirmed on hardware (8 min ± 5 s). - **"path 01 + current + FAST_CHG_ON 0" is the LBC's non-fast charging state**: entered after a TCHG expiry (this test) and directly at the restart when VBAT is above the ≈ 3.90–3.93 V threshold (VBAT_DET-like; Tests B/C/D/D2/D3). The vbat-det-lo RT bit started toggling here at VADC ≈ 3.93 V under charge — consistent with that threshold. - **The safety timer is not a charge-stop protection on PM8916 LBC in this configuration**: it only ends the fast-charge state; current continues. Tests B/C/D never ran the timer because they never entered fast charge. Charging is bounded by VDD_MAX only (and the v3 HOLD logic). Board left CHARGING (path 01) on the Test D image. Logs: d4/, d4-*.txt, d4-after-event-regs.txt, UART logs/uart/b10b3d-ram4-20261004-015813.log (480s). ## Continuation in the same run (2026-10-04 UTC 23:44–01:13): HOLD, USB pull from HOLD, re-insert Monitor restarted at 30 s (`d4-mon-board-final2.txt`, pull `d4hold-mon.txt`). CC continued in path 01 (≈ 1.9 mV/min), CV from ≈ t 7090 s, **CHARGING → HOLD at uptime 7251.1 s** (VDD_MAX 04→00), no ALERT. **USB pull from v3 HOLD (usbpull2): PASS** — heartbeat via /dev/kmsg on UART every 5 s (`usbpull2-pre.txt`, `d4/uart-full.log`): 27 beats, max gap 5.02 s, no SBL/boot; uptime continuous 7297 → 7439 s. Operator DMM 4.024 V → brief dip ≈ 3.9 V at the pull → 4.024 V (10 s). Supervisor: `HOLD -> NO_USB (usb removed)` 7352.4 s (vbat 3.980 V), no writes; USB back after ≈ 69 s: `NO_USB -> CHARGING (usb inserted)` 7421.3 s (vbat 4.020 V; VDD_MAX 04 + restart edge). The earlier reset at a USB pull from the v3 path-01 state (t1pre-actions.txt, 22:27) did not reproduce. **After the re-insert: FAST_CHG_ON + path 02 (RT 21) at VBAT 4.020 V** — above the 3.90–3.93 V entry threshold seen at probe → the threshold rule applies to the probe-time restart (after SBL charging), not to a fresh USB insertion; the exact condition is open. Operator: DMM 4.02 → 4.08 V, USB 0.346 A, then 0.2 A (CV). CV from ≈ 7450 s, **HOLD at 7759.0 s**: at the HOLD write (VDD_MAX 04→00, below VBAT) **FAST_CHG_ON 21→01 and path 02→01 immediately** → the expected TCHG expiry at ≈ 7901 s was not observable (no fast state any more). So HOLD itself ends the fast state; the timer cannot act in HOLD. End dump 2 (`d4-end2-dump.txt`, up 8122 s): HOLD, n_insert 2, n_hold 2, n_latch 0, CHG_FAILED 00, eMMC w=0. Board left in HOLD on the Test D image.