# B9A-RESULT — display chain audit (read-only) Date: 2026-10-03. Board: Aurora JZ08AU-XPA-7J-R3, running B8F (cache `857c9c30`, kernel `7.2.7-aurora-b8d #7`). Nothing was changed: no kernel/DT build, no eMMC/cache write, no GPIO/regulator/PMIC/SPI writes, no reboot. The live snapshot only read sysfs/debugfs and PMIC registers (regmap debugfs reads). eMMC write counter = 0. ## Main finding **This is not a DSI panel and MDP is not used.** The built-in display is a **1.44" 128×128 ST7735S panel on SPI** (MIPI-DBI type C, 4-wire: SCL/SDA/CS plus a D/C GPIO). It is driven over **BLSP1 QUP4** (`spi@78b8000`, GPIO 12–15). The backlight is **PM8916 MPP4 used as a 40 mA current sink**. **Stock LK fully brings the panel up before Linux:** reset, SPI, 19 init commands, a 128×128 "4G LTE" logo built into LK, then backlight. It happens about 210 ms after LK starts. LK then passes the panel to the kernel as continuous splash (`mdss_mdp.panel=1:spi:0:qcom,mdss_spi_st7735s_wx144_128x128_cmd`). Stock LK is therefore an exact reference, and it matches the stock DT byte for byte. ## Table | Level | Stock | Current Linux | Status | |---|---|---|---| | MDP/MDSS | Present (`qcom,mdss_mdp`), used by Android only as a CPU-side fb (`fb0` 128×128, 32 bpp, `memblock-reserve 0x83200000/0xfa0000`). LK writes fb `0x83200000` and copies it over SPI, with no scanout. | `display-subsystem@1a00000` status=disabled, `DRM=n` | **Not needed**: MDP/DSI are not part of the chain | | DSI | Only `mdss_dsi_sim_video` (simulator) and an empty `mdss_dsi@1a98000`. LK also has a DSI `st7796s_320p` (id 0) that this board never uses. | Disabled | **Not used** | | "Display controller" = SPI host | BLSP1 QUP4 `0x78b8000`; GPIO12 MOSI, 13 MISO, 14 CS0, 15 CLK (func 1, 12 mA); clock 16 MHz; mode 3 (CPOL=1, CPHA=1); TX only. Kernel: `qcom,mdss_spi` + `mdss_spi_client` @16 MHz. | `spi@78b8000` **status=disabled**, `SPI_QUP=y`, no spi_master, GPIO 12–15 are reset defaults (in, pull-down) | **MISSING (1st point in Linux)** | | Panel | `st7735s wx144 128x128 command mode spi panel`; in LK `panel_id = 1` is **hardcoded** (no ID read). RGB565 (COLMOD 05), MADCTL `c8` (MY\|MX\|BGR), window col 2..129 / row 3..130. The 19-command init sequence is identical in LK and DT (`b9a-stock-lk.txt` §4). Off: `28`, `10`+120 ms. An alternative `nv3023a_jz05` is in the DT, but LK never selects it. | No panel node, no driver (`DRM_PANEL_MIPI_DBI`/`DRM_ST7735R` not built) | **MISSING** | | Regulators | Stock kernel: vdd = `8916_l17` 2.85 V, vddio = `8916_l6` 1.8 V. **Stock LK does not touch any regulator** (`target_ldo_ctrl` is a stub; LK has no RPM regulator code). | HW: **L6 ON** (EN 0x80, by SBL/RPM default). **L17 OFF** (EN 0x00, STATUS 0x00). Linux holds neither. | **Open**: is L17 needed for the panel? LK runs without enabling it (see "Open questions") | | GPIO/reset | RESET = GPIO118 (`disp_rst_n`), D/C = GPIO116 (`disp_dc`), both out, 8 mA. Reset: high 1 ms → low 1 ms → high → 120 ms. No TE, no enable GPIO (LK touches GPIO0 only with OE=0, a CAF leftover). | GPIO116/118: in, pull-down, UNCLAIMED → **panel is held in reset** | **MISSING** | | Backlight | PM8916 MPP4 current sink: MODE_CTL `0xa340=0x61`, SINK_CTL `0xa34c=0x07` (40 mA), EN `0xa346=0x80`. Turned on after init and the first frame. Android: `qcom,leds-qpnp` MPP4 `lcd-bl` 40 mA (trigger `bkl-trigger`). No PWM/WLED/DCS. | MPP4 regs = 00/00/00 (off), `/sys/class/backlight` empty | **MISSING** | | DRM/fb | Android: mdss_fb `fb0` (mdssfb_d0000, 128×128, virtual 128×256, 32 bpp). LK: fbcon 16 bpp @`0x83200000`. | `DRM=n`, `FB=n`; no `/dev/dri`, `/dev/fb*`, `/sys/class/drm\|graphics` | **MISSING** | ## Exact chain (stock → what B9 needs) ``` SoC display "controller": BLSP1 QUP4 SPI @0x78b8000 (gcc_blsp1_qup4_spi_apps_clk 16 MHz, mode 3, CS0, GPIO12-15 func1) → "DSI host": none. The SPI host itself + D/C GPIO116 = MIPI-DBI type C (4-wire) host → panel: ST7735S 128x128 (1.44" "wx144"), GRAM offset (2,3), RGB565, MADCTL 0xc8 → reset/power: L6 1.8 V on (default) [L17 2.85 V: stock kernel only, LK does not enable it]; GPIO118 1→0 (1 ms)→1, wait 120 ms → init: SLPOUT +120 ms, FRMCTR1/2/3, INVCTR 03, PWCTR1-5, VMCTR1 12, GMCTRP1/N1, MADCTL c8, COLMOD 05, CASET 2..129, RASET 3..130, DISPON, RAMWR (+ 128*128*2 B frame, D/C=1) → backlight: PM8916 MPP4 current sink 40 mA (0x61/0x07/0x80), after the first frame → framebuffer/DRM: in Linux → SPI device + panel-mipi-dbi (or st7735r) → /dev/dri/card0 (+ /dev/fb0 via fbdev emulation) ``` ### First point where things diverge 1. **Across the whole boot path, the first divergence is the bootloader.** Stock LK brings up the panel at ~210 ms. The current lk1st (msm8916 lk2nd tree) has no SPI-panel code: `mdss_spi.o` is only built for msm8909/msm8952. So the panel is never initialised, and its RESET stays low because of the SoC pull-down. 2. **Within Linux, the first missing link is the SPI host:** `spi@78b8000` is `status = "disabled"`. Everything after it is also missing: no panel node and no driver, D/C and RESET GPIOs are not described, there is no MPP4 backlight, and DRM/FB are off. MDP/DSI do not belong to this chain, so their being disabled is **not** the problem. There is no simpledrm/simplefb path: no loader leaves the panel initialised, and an SPI panel has no scanout. So Linux has to bring the panel up itself, which is what B9 asks for anyway. ## Open questions (do not block B9B) - **L17**: it is off in hardware, while the stock kernel declares it as panel vdd and stock LK never turns it on. So either SBL1/RPM turn it on during a stock boot (unlikely: SBL1/RPM are still stock now and L17 is off), or the panel VDD is fed from another rail. **B9B will settle it** by testing with L17 untouched, exactly like LK. - **Exact glass model**: LK hardcodes ST7735S and does not read an ID. The vendor DT also has `nv3023a_jz05`. The cable/glass markings are unknown. A visual check in B9B confirms that the ST7735S init works on this glass. An ID read (RDDID 04h) is possible later if MISO/SDA can actually be read back (LK runs TX-only). - **Operator question**: on stock firmware, did the "4G LTE" logo appear on the screen at power-on? (LK's built-in image: `b9a-stock-lk-embedded-logo-128x128.png`, because the stock `splash` partition is all zeros.) ## Proposed B9B (RAM-only, ONE test) — waiting for GO **B9B "first light"**: boot the B8F RAM image via RESET-held power-on + `fastboot boot`. Cache B8F and the eMMC are not touched. - Kernel = `out-b8d` + `DRM=y`, `DRM_PANEL_MIPI_DBI=y`, `DRM_FBDEV_EMULATION=y` (+ the `FB` core it needs). No fbcon, no MSM DRM. - DTB = B8B DTB plus: - `&blsp_spi4 { status = "okay"; cs-gpios = <&tlmm 14 GPIO_ACTIVE_LOW>; }` (upstream style; stock used native CS0). - `panel@0`: `compatible = "aurora,st7735s-wx144", "panel-mipi-dbi-spi"`, `spi-max-frequency = <16000000>`, `spi-cpol; spi-cpha`, **`write-only`** (LK is TX-only; without it the driver's `mipi_dbi_poweron_conditional_reset` would read DCS 0Ah back over SPI and might skip init because of a garbage readback), `dc-gpios = <&tlmm 116 GPIO_ACTIVE_HIGH>`, `reset-gpios = <&tlmm 118 GPIO_ACTIVE_LOW>`, `panel-timing` 128×128 with `hback-porch = 2`, `vback-porch = 3` (the GRAM offset), and `backlight = <&lcd_bl>`. - `lcd_bl`: `gpio-backlight` on `&pm8916_mpps 4` with pinctrl `function = "sink"`, `drive-strength = <7>` (40 mA, as in LK). - **No regulator references** (exactly like stock LK). - initramfs = B8F + `/lib/firmware/aurora,st7735s-wx144.bin`: the stock 19-command sequence minus RAMWR, in the panel-mipi-dbi format (SLPOUT, then a 120 ms delay, …, MADCTL c8, COLMOD 05, DISPON). The driver loads `.bin`, and back-porch is used as the GRAM offset (panel-mipi-dbi.c:197, :366-367; checked against the 7.2.7 source). The driver turns on the backlight right after the init commands; LK does it after the first frame (a small difference, acceptable for B9B). - Test (read-mostly): check the probe in dmesg, that `/dev/dri/card0` and `/dev/fb0` exist, and read back MPP4 = 0x61/0x07/0x80 plus GPIO 116/118/12–15. Then write one static test frame to `/dev/fb0` (colour bars + a corner marker) and **the operator confirms** the image, colours and orientation. LTE and Wi-Fi must keep working, and eMMC writes must stay 0. - PASS = a correct image with backlight on, and no LTE/Wi-Fi regressions. If the screen stays dark or white, the single next variable for B9C is the panel's `power-supply = L17 2.85 V`, as the stock kernel uses. STOP. B9B only after a separate GO. ## Files - `b9a-stock-lk.txt` — stock LK: UART evidence, function map, structures, init table, backlight, splash - `b9a-stock-lk-embedded-logo-128x128.png` — the logo built into stock LK (RGB565 @`0x8f64b004`) - `b9a-stock-dt.txt` — stock dtb_01 nodes (mdss_mdp + panels, mdss_spi, spi@78b8000, pinctrl, MPP4 LED, L6/L17) - `b9a-current-dt.txt` — current B8F DTB (dtc) display-related nodes - `b9a-kconfig.txt` — kernel config audit - `b9a-linux-display.txt` (+ `.raw.txt`) — live read-only snapshot of the board - `b9a-backlight.txt` — backlight mechanism - Scripts `b9/b9a/`: `lk-xref.py`, `lkmem.py`, `disrange.sh`, `decode-panel.py`, `render-lk-logo.py`, `dt-extract.py`, `b9a-live.sh` (board), `b9a-run.sh` (480s)