# R2/T4: read-only eMMC baseline (2026-10-02 11:27, via telnet over NCM) Board: RAM-booted r2/t4/out/aurora-mm1-t4telnet.img (6db01841, `fastboot boot`, nothing written); CH340 TX disconnected. Raw output: emmc-snapshot-20261002-112757.txt. Boot: RTC 979 s at start (class B, fastboot path), uptime 189 s at snapshot. | Field | Value | Meaning | |---|---|---| | CID | | Hynix (0x90), OEM 0x014a, H4G2a, PRV 0x2, PSN , MDT 05/2018 (lk prints "05 2002" — older decode) | | EXT_CSD_REV [192] | 0x06 | eMMC 4.5 | | PRE_EOL_INFO [267] | 0x00 | not defined | | LIFE_TIME_EST_A/B [268/269] | 0x00 / 0x00 | not defined | | RST_n_FUNCTION [162] | 0x01 | RST_n permanently ENABLED (OTP): the card resets on a low pulse on its RST_n pin | | PARTITION_CONFIG [179] | 0x38 | boot from user area, no boot ack | | HS_TIMING [185] / BUS_WIDTH [183] / DEVICE_TYPE [196] | 0x02 / 0x02 / 0x17 | HS200, 8-bit SDR | | CACHE_CTRL [33] / POWER_OFF_NOTIFICATION [34] | 0x01 / 0x01 | cache on, power-off notification enabled | | SEC_COUNT | 7634944 | 3.64 GiB | Linux ios: HS200 8-bit, 177.77 MHz, VDD 2.9–3.0 V, signal 1.8 V, driver type B. debugfs err_stats (189 s): all 15 counters = 0. dmesg: 0 mmc/sdhci error/timeout/CRC/tuning/reset lines. mmc-utils not installed (not needed). ## Conclusions - Wear/health: **no data** — EXT_CSD rev 6 (eMMC 4.5) has no PRE_EOL/LIFE_TIME fields (0x00 = undefined, not "new"). Health cannot be judged by EXT_CSD on this part. There are also no runtime error signs. - RST_n_FUNCTION = 0x01: closes the T3B §4 question. The bit is OTP and was set either at the factory or by the first lk1st PASS boot. Consequence (hypothesis, NOT proven): with RST_n active, a glitch/low level on the eMMC RST_n line resets the card to pre-idle. If that happens between CMD1 and CMD2, it gives exactly the D2 pattern (CMD1 OK → CMD2 no response). Needs a scope on RST_n to test; not a priority at 1/10. - Bus in Linux HS200 is clean at runtime; does not explain CMD2 at 400 kHz identification either way.