# B11 — LED / button audit (read-only), 2026-10-04 Board: JZ08AU Aurora (MSM8916 + PM8916). Live system: eMMC cache B10B-5 c3732515, kernel 7.2.7-aurora-b10b5, uptime ≈ 53 min ("HB cold2"). Nothing was written to eMMC, PMIC, or TLMM during the audit. All reads used debugfs (`/sys/kernel/debug/gpio`, `pinctrl/*/pinmux-pins`, `regmap/0-00|0-01/registers`). Raw data: - `logs/b11/live/live-debugfs-1.txt`: TLMM 122 pins (dir, level, func, drive, pull), PM8916 MPP/GPIO, pinmux owners, /proc/interrupts - `logs/b11/live/live-pmic-ro-2.txt`: PM8916 PON 0x0800–0x084f; MPP1–4 and GPIO1–4 (sid0); LPG 0xbc00 and VIB 0xc000 (sid1); inputs, backlight, leds - script: `b11/audit/b11-ro.sh` (read-only) ## 1. Sources checked | Source | What was looked for | Result | |---|---|---| | Stock DT `dt/dtb_01.dts` (active 512MB DT) | `gpio-leds`, `qcom,leds-qpnp`, MPP/GPIO/PWM/LPG, pinctrl | `gpio-leds` node holds **only the SIM mux** (`sim1/2/3_switch_gpio`, `sim_hotdet_gpio` = GPIO22/23/1/20). These are not LEDs. `qcom,leds-qpnp` has only `lcd-bl` on MPP4. MPP1–3 and PM GPIO1–4 are `disabled`. `pwm@bc00` is declared with no consumer. `vibrator@c000` is `okay`, set to 3.1 V. | | Stock Android runtime `android/leds.txt`, `android/gpio.txt` | `/sys/class/leds` | `lcd-backlight` (MDSS virtual), `lcd-bl` (MPP4), `mmc0::` (trigger only), 4× SIM switch. **No indicator LED.** | | Stock /system (`partitions/system.bin`, ext4, read via debugfs) | `/sys/class/leds/*`, `/sys/class/gpio/*` users | `lights.msm8916.so` and `mmi_led.so` are generic Qualcomm (red/green/blue). `usbhub` (gpio56) and `init.qcom.post_boot.sh` (gpio253–259) are generic code for other targets. Nothing is Aurora-specific. | | Stock init.rc | LED chown list | Generic red/green/blue/yellow(+_sec, 2, 2_sec) chowns. No matching DT nodes exist. | | Stock MPSS (`firmware-fat/image/modem.b21`) | LED strings | `led_red/green/blue` appear only in the generic TLMM pin-name table (next to `lcd_rst_n`, `cam_flash_torch_en`, `kpsns0`…, MTP names). They give no pin mapping and no proof that the modem drives an LED. | | Stock LK / lk1st-b9l | LED code | Only MPP4 (backlight) and the SPI panel are used. | | Current production DTS (b9b → b10b3 chain) | LED / keys | MPP4 → `gpio-backlight` (`/sys/class/backlight/backlight`). No gpio-leds and no gpio-keys. Only `pm8941_pwrkey` is an input. | | Live TLMM / PMIC state | outputs, current sinks | See §2 and §3 | | JZ02 (reference only) | RGB GPIO6/7/8 | Different PCB. Stock Aurora DT dropped these LEDs, and Aurora GPIO6/7/8 are unclaimed inputs with pull-down. This is not evidence of an LED on Aurora. | ## 2. TLMM (MSM8916 GPIO 0–121) — live state and classification | GPIO | live | consumer / function | class | |---|---|---|---| | 0, 2, 3 | in, pull-down | unclaimed (BLSP1 SPI/UART1 pins) | UNKNOWN | | 1, 20, 22, 23 | out, 1 / 0 / 0 / 0 | SIM mux (MPSS pinctrl, stock "gpio-leds" hack) | **DO NOT TOUCH** (modem/SIM) | | 4, 5 | func2 | BLSP1 UART2 console | **DO NOT TOUCH** (UART) | | 6–11, 16–19, 21, 24–36, 38, 39, 45–56, 60–62, 69–98, 108–112, 114, 115, 117, 119–121 | in, pull-down, func0 | unclaimed; no stock consumer (stock DT references only TPIU debug, MTP cameras, codec, usb-id) | UNKNOWN | | 12–15 | func1 | BLSP1 QUP4 SPI → ST7735S | **DO NOT TOUCH** (display SPI) | | 37 | in, low, pull-down | `key_f2` (stock gpio-keys, active-high) | button: read-only | | 40–44 | func1 | WCNSS 5-wire (Pronto/Iris) | **DO NOT TOUCH** (WCNSS) | | 57–60 (57–59 out, func1) | UIM1 | SIM interface | **DO NOT TOUCH** (modem/SIM) | | 63–68 | in | codec PDM (PM8916 audio) | **DO NOT TOUCH** | | 99–102 | in, no pull | GSM TX phase (RF) | **DO NOT TOUCH** (modem RF) | | 103, 104 | in, pull-down | SSBI WTR0 | **DO NOT TOUCH** (RF) | | 105 | **out low**, func0, no pull | not claimed by Linux, driven by boot/MPSS firmware (ssbi_wtr1 pad as GPIO) | **DO NOT TOUCH** (modem-owned RF/GRFC, consumer unknown) | | 106 | in, **pull-up**, high | ssbi_wtr1 pad; pull set by firmware | **DO NOT TOUCH** (RF/unknown) | | 107 | in, high, pull-up | `key_f3` (stock gpio-keys, active-low) | button: read-only | | 110 | in | usb-id pin (stock) | **DO NOT TOUCH** (USB) | | 113 | in | cdc-us-euro (audio switch) | **DO NOT TOUCH** | | 116, 118 | out high, 8 mA | panel D/C, RESET (spi0.0) | **DO NOT TOUCH** (display) | | SDC1 / SDC2 / QDSD pads | — | eMMC / SD | **DO NOT TOUCH** | **No TLMM pin has evidence of an indicator LED.** No DT node, stock userspace, or live output state points to one. Every unclaimed pin is a firmware-default input with pull-down, so no LED on those pins is lit now. Because the topology is unknown, none of them may be driven (B11 rule). ## 3. PM8916 peripherals | Block | live registers | meaning | class | |---|---|---|---| | **MPP4** (0xa300) | MODE 0x61, VIN 0, EN 0x80, SINK_CTL 0x07 | current sink 40 mA, ON = LCD backlight (B9A/B9B, stock `lcd-bl`) | **SAFE** (proven in B9B/B9C/B9L) | | MPP3 (0xa200) | MODE 0x60 (sink, source = 0 → off), EN 0x80, SINK 0x00 (5 mA) | current sink configured but off. Same value on every boot since B9C baselines. No consumer in any stock layer. | UNKNOWN (likely LED-type driver, but the load is unproven) | | MPP2 (0xa100) | MODE 0x11 (digital output, **HIGH**), VIN 1, EN 0x80 | set by boot firmware; consumer unknown (could be an enable or a reference) | **DO NOT TOUCH** | | MPP1 (0xa000) | MODE 0x51 (analog output), VIN 2, EN 0x80 | analog/reference output set by firmware | **DO NOT TOUCH** | | PM GPIO1–4 (0xc000–0xc300) | input, pull-down 10 µA, EN 0x80 | stock `disabled`; consumer unknown | UNKNOWN | | LPG/PWM (sid1 0xbc00) | EN 0x00 (off) | no consumer in stock or current DT. **PWM routing to MPP4 is unproven.** | no PWM-capable LED confirmed | | VIB_DRV (sid1 0xc000) | EN 0x00, VSET 0x16 | stock `vibrator` 3.1 V; the board has no known motor; the load is unknown | UNKNOWN | | LBC charger | — | no charge-LED output (checked against downstream qpnp-linear-charger) | n/a | ## 4. Buttons (read-only) | Button | line | idle level | notes | |---|---|---|---| | POWER | PM8916 KPDPWR (PON RT 0x0810 bit0); Linux `pm8941_pwrkey` → event0 | released | S2 reset enabled (0x0843 = 0x80, warm reset after long hold). **Short presses only.** | | RESET | PM8916 RESIN (PON RT bit1) | released | no Linux input. Holding it too long → PMIC stage-3 reset (B10 note). KPDPWR+RESIN = hard reset (0x084b = 0x80). **Short presses only, never both at once.** | | key_f2 | TLMM GPIO37, active-high | low (pull-down) | not bound in current DT; poll via debugfs | | key_f3 | TLMM GPIO107, active-low | high (pull-up) | not bound in current DT; poll via debugfs | ## 5. Conclusion of the audit - SAFE LED lines: **1**, PM8916 MPP4 (LCD backlight current sink). It is already controllable in the live production system through `/sys/class/backlight/backlight` (gpio-backlight, 0/1). No PWM. - UNKNOWN: MPP3 sink, PM GPIO1–4, VIB_DRV, and all unclaimed TLMM pins. None is switched. - DO NOT TOUCH: MPP1, MPP2, GPIO1/20/22/23, 4/5, 12–15, 40–44, 57–60, 63–68, 99–106, 110, 113, 116, 118, SDC pads. - The physical indicator LEDs and empty footprints the operator sees cannot be tied to any software-controlled line from the sources available. They are likely hard-wired (power/VBUS/charge), backlight, or DNP options for another SKU. Proving that needs continuity checks on the board.