# B7C audit + proposed patch (not built, nothing written) Live board files == b6p/rootfs (aurora-modem 6e922dec…, init.d 533f47ea…, modem.conf 6ffb206e…) + r2/t4/rootfs/init (13721ca5…). ## Clock usage in the current controller / init | Mechanism | Clock | Affected by a REALTIME step? | |---|---|---| | now(), since(), wait_for deadlines, reg_sm T_REG deadline, log timestamps, diag file names | /proc/uptime (CLOCK_BOOTTIME) | no | | `sleep N` / `sleep 0.2` (busybox, nanosleep) | relative | no | | `timeout N` (busybox) | relative | no | | `ping -W`, `udevadm settle --timeout` | relative/monotonic | no | | qmicli / mmcli / ModemManager timeouts | GLib monotonic | no (B7B: no reaction) | | /init: only `sleep` loops | relative | no | | wall clock (`date`) | not used anywhere today | — | Conclusion: no change needed for timeouts; the patch itself uses only uptime for waits/alignment. ## Kernel out-bam1 .config: CONFIG_RTC_HCTOSYS=y, CONFIG_RTC_SYSTOHC=y (rtc0 = rtc-pm8xxx, DT without allow-set-time). SYSTOHC writes the RTC every 11 min only while STA_UNSYNC is cleared (NTP-disciplined). `date -s` keeps STA_UNSYNC (B7B: status 64). → The SNTP stage must never discipline/slew (busybox ntpd without -w would clear UNSYNC): query-only `ntpd -w`, step via `date -s` only if |offset| ≥ 1 s. ## Insertion points (fresh start path) QMI_READY (first moment DMS answers) → SIM_READY → RADIO_ONLINE (before reg_sm) → each reg_sm state transition → REGISTERED (before killall qmi-proxy) → BEARER_CONNECTED (after START OK) + background SNTP. Each probe: 2 qmicli calls (~40 ms each), raw kept in /run/aurora-modem/time-probe-N.{dms,nitz}, table /run/aurora-modem/time.tsv, one lifecycle/kmsg line. Set happens at most once ($D/time-set), only while the clock is before the build floor. Policy in the test image: TIME_REQUIRE_NITZ=1 (DMS without NITZ is logged as INVALID(no-nitz), i.e. plausible but not yet trusted) — this still answers "when is DMS first valid"; relax only after evidence. ## Patch b7/b7c/aurora-modem-b7c.diff (b6p → b7c, +55 lines), patched controller sha 932c9ff2… Locally tested under busybox sh with stubbed qmicli/date (real B7A outputs): VALID → one date -s, second probe no re-set; 1980 → INVALID(year<2026); no NITZ → INVALID(no-nitz); SNTP/nslookup parsers on real outputs. ## Planned RAM image (after GO) initramfs-t4.cpio.gz (unchanged) + appended overlay: /usr/sbin/aurora-modem (patched), /etc/aurora/build-epoch (build time), /usr/libexec/aurora/busybox (Alpine busybox-static 1.37.0-r20 aarch64, static, 1115944 B, sha a6bb1e6e…, used only as `busybox ntpd -w`). /init, init.d, modem.conf unchanged. Boot: RESET-held power-on → lk1st fastboot → `fastboot boot`. No cache/eMMC write. ## Build (2026-10-02, GO "сборка") b7/b7c/build-b7c.sh: T4 initramfs db47835b verified, mkbootimg reproduces T4 bit-for-bit, overlay (aurora-modem 932c9ff2, build-epoch 1790935600 = 2026-10-02T10:06:40Z, /usr/libexec/aurora/busybox a6bb1e6e) → out/aurora-mm1-b7c.img **d0c4cc00…** (21291008 B; ramdisk 12628896 B in the image == initramfs-b7c f219b04d). Layer extraction check: final /usr/sbin/aurora-modem, build-epoch, busybox = overlay; /init, init.d, modem.conf = T4. ntpd applet runs (qemu --help). Copied to 480s, `sha256sum -c SHA256SUMS` OK. Host driver for one cold boot: b7/b7c/b7c-boot.sh K (not run yet).