# B10B3-RBL1-RESULT — software reboot to lk1st fastboot (no RESET) and what a Linux reboot does to the LBC Date: 2026-10-04 (UTC 11:13–11:46). Interrupts the production-profile run p1 after usbpull3 (board CHARGING, VDD_MAX 08). Production-run logs saved first: `rbl1/prodrun/` (board monitor 1159 samples → also `p1-mon-board-final.txt`, dmesg → `p1/dmesg-at-rbl.txt`). ## Mechanism (sources) - lk1st (`/home/q/aurora-lkbuild/b9l-src`, `project/msm8916.mk`: `USE_PON_REBOOT_REG=1`): `aboot.c:5606` `check_hard_reboot_mode()` → `platform/msm_shared/reboot.c:84` reads PON_SOFT_RB_SPARE 0x88F bits 7:2 (and scrubs them); `reboot.h`: FASTBOOT_MODE = 0x02 → fastboot. - Kernel: CONFIG_REBOOT_MODE/SYSCON_REBOOT_MODE=y, DT `pon@800 { compatible = "qcom,pm8916-pon"; mode-bootloader = <0x02>; }`, `qcom_pon_reboot_mode_write()` writes `magic << reason_shift(2)` into 0x88F. busybox `reboot` has no argument → `b10/b10b3/rbl/reboot-bootloader` (freestanding aarch64, sha 0428be0c…): `sync` + `reboot(MAGIC1, MAGIC2, RESTART2, "bootloader")`. ## Result 1. **lk1st entered fastboot without RESET** (UART: `fastboot_init()`, `fastboot: processing commands`; host 18d1:d00d). 2. **lk1st fastboot data phase is broken after a Linux reboot**: `download:01861000` arrived, no data; after abort `fastboot: oops!`, `getvar` timed out. **A physical USB replug in lk restored it** (`getvar product: lk1st-msm8916`), then `fastboot boot` of the B9C RAM image (fa855e1c, no LBC driver writes) worked. 3. PMIC state before (v3 production image, CHARGING) → after (B9C RAM, before any driver): - RTC continuous: 34940 s → 36836 s (no RTC reset); PON_REASON1 0x808 10→**11** (b0 Hard Reset + USB), POFF_REASON1 0x80C 00→**02** (PS_HOLD), POFF_REASON2 0x80D 80→**00** (no stage-3). → a **PS_HOLD hard reset without power loss** — not a class A, not a stage-3. - **Charger registers partly back to SBL defaults:** IBAT_MAX 04→00, IBAT_SAFE 04→0a, CHG_CTRL a0→90, TCHG_MAX 7f→1d. Unchanged: VDD_MAX 08 (equal to the SBL default here — not decisive), VDD_SAFE 08, BOOT_DONE 80, 0x105B 09, 0x10EE 00, TCHG_EN 80, CHG_STATUS 05, RT 21, path 02. 0x88F 00 (scrubbed by lk1st). → After a Linux reboot SBL (or the PMIC hard reset) re-initialises at least IBAT_MAX/IBAT_SAFE/CHG_CTRL/TCHG. Whether VDD_MAX (e.g. the HOLD value 02) survives is **not yet known** (it was 08 = default in this test). This corrects the earlier blanket note "LBC settings survive warm reboots" (that was observed only for RESET/stage-3 paths in the older tests, not verified for this path). State now: B9C RAM image (no charger driver), SBL charge state (IBAT 90 mA, VDD 4.20 V), FAST + path 02.