# Aurora bootchain migration preflight (ARM64) — 2026-09-30. NOTHING WRITTEN. ## 1. Why ARM64 fails today (proven) lk2nd 23.1 `spin-table.c:54`: `!is_scm_armv8_support()` && ARM64 kernel → "Cannot boot ARM64 with old SCM calling convention"; `scm.c` ~1060–1085: 32→64 switch = SCM `SCM_SVC_MILESTONE_32_64`; legacy-SCM TZ returns → `ASSERT(0)`. Stock TZ = TZ.BF.2.2-2.2.0026 (ELF32, legacy SCM, no PSCI), ELF-identical to JZ02 stock. ## 2. Component requirements (evidence: JZ02 PLAN-B runs on IDENTICAL stock sbl1/rpm/tz/hyp ELF + qhypstub README) | component | verdict | evidence | |---|---|---| | TZ → DB410c TZ.BF.3.0-00714 (ELF64, armv8 SCM + PSCI) | **REQUIRED** | JZ02 S3: qhypstub with stock TZ.BF.2.2 → silence after SBL1. S4′: TZ.BF.3.0 + qhypstub → lk1st → PSCI v1.0 → arm64 Linux | | HYP → qhypstub | **REQUIRED (with TZ.BF.3.0)** | stock hyp is ELF32; JZ02 only proven pair = TZ64 + qhypstub. qhypstub also brings RPM out of reset. Alone: insufficient (JZ02 S3) | | GPT delta (tz 512K→1M, tzbak moved to empty gap) | **REQUIRED** | DB410c TZ = 605312 B > tz 524288 B, last segment ends at EOF (cannot truncate) | | ABOOT → lk1st | **REQUIRED for a proven chain** / stock aboot = UNKNOWN | Only proven combo is lk1st. Stock Aurora LK (32-bit, legacy-SCM era) under TZ.BF.3.0+qhypstub never tested on any board; qhypstub README says aarch32 LK in EL1 is supported in principle | | lk2nd in recovery | OPTIONAL (keep untouched) | with lk1st in aboot, lk1st itself gives `fastboot boot`; recovery stays as is | | SBL1 / RPM / DDR / sec / cdt | keep stock (NOT required) | JZ02 runs stock sbl1 BOOT.BF.3.0.1 + stock rpm RPM.BF.2.0.1 with TZ.BF.3.0; Aurora sbl1/DDR/sec byte-identical, rpm ELF identical | ## 3. JZ02 (working ARM64) vs Aurora (stock) | component | JZ02 working | Aurora stock | same? | role | replace? | risk | |---|---|---|---|---|---|---| | SBL1 | stock 6a661ec9… BOOT.BF.3.0.1-00019 | 6a661ec9… | SAME (bytes) | DDR init, loads TZ/RPM/HYP/ABOOT | no | — | | RPM | stock 53b591bb… | ELF identical (slack differs) | SAME (ELF) | power/clocks | no | — | | DDR | stock | c3502047… = JZ02 | SAME (bytes) | DDR params for SBL1 | no | — | | TZ | DB410c TZ.BF.3.0-00714 (8481892f… padded 1M) | TZ.BF.2.2-2.2.0026 | DIFFERENT | secure monitor, SCM/PSCI | yes | high (runs before aboot) | | HYP | qhypstub (1a963047… padded 512K) | stock ELF32 (TZ.BF.2.2 hyp) | DIFFERENT | EL2, RPM release | yes | high | | ABOOT | lk1st JZ02 build (JZ02 node, -dirty) | stock LK 2026-07 (SPI panel, charger) | DIFFERENT | bootloader/fastboot | yes (Aurora lk1st) | medium (loses Android) | | GPT | tz 270336..272383, tzbak 305184..306207 | stock | DIFFERENT (2 entries) | layout | yes | high (table write) | | QCDT/DT | lk1st: appended kernel DTB | stock LK: QCDT dtb_01 | — | kernel DT | n/a (mainline DTB appended) | — | Aurora region layout (tz/tzbak/hyp LBAs, splash end 305169, gap 305170..393215 all-zero, DDR 393216) == JZ02 → same GPT delta applies. Memory map: upstream msm8916.dtsi reserves tz@86500000 (DB410c TZ) — proven on JZ02. DDR init owner = stock SBL1 (unchanged). PMIC PM8916 same; RPM unchanged. Board-id: lk1st does not use QCDT; kernel DTB appended ("Only one appended non-skales DTB"). Display: stock LK powers + draws ST7735S splash (`Config SPI PANEL`); lk1st has no SPI-panel driver → **no boot splash** (expected change, not a fault). ## 4. Options | | writes | ARM64 handoff | normal boot after | recovery/lk2nd | EDL | rollback | main brick risk | |---|---|---|---|---|---|---|---| | A hyp=qhypstub only | hyp | **NO** (JZ02 S3 hang) | hangs after SBL1 | unreachable | HW only | ws hyp | proven failure → rejected | | B tz=DB410c, hyp=qhypstub, aboot=stock | GPT, tz, hyp | plausible via lk2nd in recovery (armv8 SCM + PSCI) | UNKNOWN (stock LK + Android 3.10 on TZ64 never tested; qseecom/keymaster TZ apps built for TZ.BF.2.x) | lk2nd path kept (if stock LK runs) | adb only if Android boots, else HW | ws GPT/tz/hyp | stock LK hang → only HW EDL | | C tz=DB410c, hyp=qhypstub, aboot=lk1st | GPT, tz, hyp, aboot | **YES** (JZ02 S4′/S5, identical inputs) | lk1st forced fastboot (Android gone) | untouched, not needed | lk1st `fastboot oem reboot-edl` (proven JZ02) + HW | ws each stage | lower: every stage proven on JZ02 | | D staged C (JZ02 order) | same as C, one change per stage | YES at end | per stage | untouched | per stage | per stage | minimal: stage-by-stage verification | **Recommended: D (= C executed in JZ02's proven order).** Not hyp alone. Not B (unproven, and only saves Android which the target system does not need). ## 5. HW EDL without ADB — OPEN BLOCKER (must be proven before S1) Currently proven on Aurora: only `adb reboot edl`. After S1 Android is gone; lk1st `oem reboot-edl` only works if lk1st boots. Evidence for a button path (NOT yet proven on Aurora): - JZ02: stock DT `key_reset` = GPIO37; user entered 9008 with the RESET button (PLAN-B "HW EDL proof", twice, also with lk1st in aboot). - upstream lk2nd `msm8916-512mb-mtp.dts`: GPIO37 is labelled "The EDL button" on UFI-001B/C sticks. - Aurora stock DT: `key_f2` = **GPIO37** (active-high, same pin). Test (non-destructive, no write): identify which physical button is KEY_F2 (`adb shell getevent -l`, press buttons), full power-off (USB + battery), hold that button, apply power/USB → expect `lsusb` 05c6:9008; exit = power-off. If this does not yield 9008: STOP — no bootloader writes without a hardware recovery path. Do NOT short test pads blindly. ## 6. Recovery path recovery (lk2nd 23.1) stays untouched. With lk1st in aboot, development path becomes: power-on → lk1st fastboot → `fastboot boot`. lk1st PANIC_REBOOT_MODE=EMERGENCY_DLOAD (panic → EDL). ## 7. UART lk1st = same lk2nd 23.1 target code: `uart_dm_init(2,0,0x78B0000)`, GPIO4/5 → UART stays on BLSP1 UART2 115200 (proven for lk2nd on Aurora, lk1st on JZ02). SBL1 prints its log on the same UART (seen). qhypstub/TZ print nothing (JZ02: SBL1 → silence → lk1st). ## 8. Uncertainties 1. HW EDL button on Aurora — unproven (blocker). 2. DB410c TZ provenance: from OpenStick base.zip (JZ02); Linaro release server no longer serves files → cannot re-verify upstream origin online. Mitigation: byte-identical to image running on JZ02 hardware; signed with Qualcomm test chain = Aurora PK_HASH root. 3. lk1st-aurora is a new build (never run): same source/tag as the lk2nd running on Aurora, same config pattern as JZ02 lk1st (bundle 512mb-mtp dtb, force fastboot), no device node → generic. 4. Battery/charging: stock LK off-mode charging + charger decisions disappear with lk1st; PM8916 charging behaviour under lk1st/mainline untested. Keep USB power connected. 5. Aurora MPSS is a different build than JZ02 (re-signed 2026-04-30) — irrelevant for boot, relevant later for modem under TZ.BF.3.0. 6. Android + stock recovery will no longer boot after S1 (expected); full stock restore = rollback all stages.