7.3 KiB
7.3 KiB
B11 — LED / button audit (read-only), 2026-10-04
Board: JZ08AU Aurora (MSM8916 + PM8916). Live system: eMMC cache B10B-5 c3732515, kernel 7.2.7-aurora-b10b5, uptime ≈ 53 min ("HB cold2").
Nothing was written to eMMC, PMIC, or TLMM during the audit. All reads used debugfs (/sys/kernel/debug/gpio, pinctrl/*/pinmux-pins,
regmap/0-00|0-01/registers).
Raw data:
logs/b11/live/live-debugfs-1.txt: TLMM 122 pins (dir, level, func, drive, pull), PM8916 MPP/GPIO, pinmux owners, /proc/interruptslogs/b11/live/live-pmic-ro-2.txt: PM8916 PON 0x0800–0x084f; MPP1–4 and GPIO1–4 (sid0); LPG 0xbc00 and VIB 0xc000 (sid1); inputs, backlight, leds- script:
b11/audit/b11-ro.sh(read-only)
1. Sources checked
| Source | What was looked for | Result |
|---|---|---|
Stock DT dt/dtb_01.dts (active 512MB DT) |
gpio-leds, qcom,leds-qpnp, MPP/GPIO/PWM/LPG, pinctrl |
gpio-leds node holds only the SIM mux (sim1/2/3_switch_gpio, sim_hotdet_gpio = GPIO22/23/1/20). These are not LEDs. qcom,leds-qpnp has only lcd-bl on MPP4. MPP1–3 and PM GPIO1–4 are disabled. pwm@bc00 is declared with no consumer. vibrator@c000 is okay, set to 3.1 V. |
Stock Android runtime android/leds.txt, android/gpio.txt |
/sys/class/leds |
lcd-backlight (MDSS virtual), lcd-bl (MPP4), mmc0:: (trigger only), 4× SIM switch. No indicator LED. |
Stock /system (partitions/system.bin, ext4, read via debugfs) |
/sys/class/leds/*, /sys/class/gpio/* users |
lights.msm8916.so and mmi_led.so are generic Qualcomm (red/green/blue). usbhub (gpio56) and init.qcom.post_boot.sh (gpio253–259) are generic code for other targets. Nothing is Aurora-specific. |
| Stock init.rc | LED chown list | Generic red/green/blue/yellow(+_sec, 2, 2_sec) chowns. No matching DT nodes exist. |
Stock MPSS (firmware-fat/image/modem.b21) |
LED strings | led_red/green/blue appear only in the generic TLMM pin-name table (next to lcd_rst_n, cam_flash_torch_en, kpsns0…, MTP names). They give no pin mapping and no proof that the modem drives an LED. |
| Stock LK / lk1st-b9l | LED code | Only MPP4 (backlight) and the SPI panel are used. |
| Current production DTS (b9b → b10b3 chain) | LED / keys | MPP4 → gpio-backlight (/sys/class/backlight/backlight). No gpio-leds and no gpio-keys. Only pm8941_pwrkey is an input. |
| Live TLMM / PMIC state | outputs, current sinks | See §2 and §3 |
| JZ02 (reference only) | RGB GPIO6/7/8 | Different PCB. Stock Aurora DT dropped these LEDs, and Aurora GPIO6/7/8 are unclaimed inputs with pull-down. This is not evidence of an LED on Aurora. |
2. TLMM (MSM8916 GPIO 0–121) — live state and classification
| GPIO | live | consumer / function | class |
|---|---|---|---|
| 0, 2, 3 | in, pull-down | unclaimed (BLSP1 SPI/UART1 pins) | UNKNOWN |
| 1, 20, 22, 23 | out, 1 / 0 / 0 / 0 | SIM mux (MPSS pinctrl, stock "gpio-leds" hack) | DO NOT TOUCH (modem/SIM) |
| 4, 5 | func2 | BLSP1 UART2 console | DO NOT TOUCH (UART) |
| 6–11, 16–19, 21, 24–36, 38, 39, 45–56, 60–62, 69–98, 108–112, 114, 115, 117, 119–121 | in, pull-down, func0 | unclaimed; no stock consumer (stock DT references only TPIU debug, MTP cameras, codec, usb-id) | UNKNOWN |
| 12–15 | func1 | BLSP1 QUP4 SPI → ST7735S | DO NOT TOUCH (display SPI) |
| 37 | in, low, pull-down | key_f2 (stock gpio-keys, active-high) |
button: read-only |
| 40–44 | func1 | WCNSS 5-wire (Pronto/Iris) | DO NOT TOUCH (WCNSS) |
| 57–60 (57–59 out, func1) | UIM1 | SIM interface | DO NOT TOUCH (modem/SIM) |
| 63–68 | in | codec PDM (PM8916 audio) | DO NOT TOUCH |
| 99–102 | in, no pull | GSM TX phase (RF) | DO NOT TOUCH (modem RF) |
| 103, 104 | in, pull-down | SSBI WTR0 | DO NOT TOUCH (RF) |
| 105 | out low, func0, no pull | not claimed by Linux, driven by boot/MPSS firmware (ssbi_wtr1 pad as GPIO) | DO NOT TOUCH (modem-owned RF/GRFC, consumer unknown) |
| 106 | in, pull-up, high | ssbi_wtr1 pad; pull set by firmware | DO NOT TOUCH (RF/unknown) |
| 107 | in, high, pull-up | key_f3 (stock gpio-keys, active-low) |
button: read-only |
| 110 | in | usb-id pin (stock) | DO NOT TOUCH (USB) |
| 113 | in | cdc-us-euro (audio switch) | DO NOT TOUCH |
| 116, 118 | out high, 8 mA | panel D/C, RESET (spi0.0) | DO NOT TOUCH (display) |
| SDC1 / SDC2 / QDSD pads | — | eMMC / SD | DO NOT TOUCH |
No TLMM pin has evidence of an indicator LED. No DT node, stock userspace, or live output state points to one. Every unclaimed pin is a firmware-default input with pull-down, so no LED on those pins is lit now. Because the topology is unknown, none of them may be driven (B11 rule).
3. PM8916 peripherals
| Block | live registers | meaning | class |
|---|---|---|---|
| MPP4 (0xa300) | MODE 0x61, VIN 0, EN 0x80, SINK_CTL 0x07 | current sink 40 mA, ON = LCD backlight (B9A/B9B, stock lcd-bl) |
SAFE (proven in B9B/B9C/B9L) |
| MPP3 (0xa200) | MODE 0x60 (sink, source = 0 → off), EN 0x80, SINK 0x00 (5 mA) | current sink configured but off. Same value on every boot since B9C baselines. No consumer in any stock layer. | UNKNOWN (likely LED-type driver, but the load is unproven) |
| MPP2 (0xa100) | MODE 0x11 (digital output, HIGH), VIN 1, EN 0x80 | set by boot firmware; consumer unknown (could be an enable or a reference) | DO NOT TOUCH |
| MPP1 (0xa000) | MODE 0x51 (analog output), VIN 2, EN 0x80 | analog/reference output set by firmware | DO NOT TOUCH |
| PM GPIO1–4 (0xc000–0xc300) | input, pull-down 10 µA, EN 0x80 | stock disabled; consumer unknown |
UNKNOWN |
| LPG/PWM (sid1 0xbc00) | EN 0x00 (off) | no consumer in stock or current DT. PWM routing to MPP4 is unproven. | no PWM-capable LED confirmed |
| VIB_DRV (sid1 0xc000) | EN 0x00, VSET 0x16 | stock vibrator 3.1 V; the board has no known motor; the load is unknown |
UNKNOWN |
| LBC charger | — | no charge-LED output (checked against downstream qpnp-linear-charger) | n/a |
4. Buttons (read-only)
| Button | line | idle level | notes |
|---|---|---|---|
| POWER | PM8916 KPDPWR (PON RT 0x0810 bit0); Linux pm8941_pwrkey → event0 |
released | S2 reset enabled (0x0843 = 0x80, warm reset after long hold). Short presses only. |
| RESET | PM8916 RESIN (PON RT bit1) | released | no Linux input. Holding it too long → PMIC stage-3 reset (B10 note). KPDPWR+RESIN = hard reset (0x084b = 0x80). Short presses only, never both at once. |
| key_f2 | TLMM GPIO37, active-high | low (pull-down) | not bound in current DT; poll via debugfs |
| key_f3 | TLMM GPIO107, active-low | high (pull-up) | not bound in current DT; poll via debugfs |
5. Conclusion of the audit
- SAFE LED lines: 1, PM8916 MPP4 (LCD backlight current sink). It is already controllable in the live production system through
/sys/class/backlight/backlight(gpio-backlight, 0/1). No PWM. - UNKNOWN: MPP3 sink, PM GPIO1–4, VIB_DRV, and all unclaimed TLMM pins. None is switched.
- DO NOT TOUCH: MPP1, MPP2, GPIO1/20/22/23, 4/5, 12–15, 40–44, 57–60, 63–68, 99–106, 110, 113, 116, 118, SDC pads.
- The physical indicator LEDs and empty footprints the operator sees cannot be tied to any software-controlled line from the sources available. They are likely hard-wired (power/VBUS/charge), backlight, or DNP options for another SKU. Proving that needs continuity checks on the board.