uzbek-plus/logs/b11/B11-LED-RESULT.md

6.2 KiB
Raw Permalink Blame History

B11 — full LED audit and all-SAFE-LED run: RESULT (2026-10-04)

Verdict: PASS, with a scope note. The audit found exactly one LED line whose control is proven safe: PM8916 MPP4, the LCD backlight current sink. It was exercised in one automatic run with every stage and full monitoring. No other line was switched.

  • Board: live production boot, eMMC cache B10B-5 c3732515, kernel 7.2.7-aurora-b10b5, "HB cold2".
  • No eMMC/cache writes. No new image. No reboot. No raw PMIC/TLMM register writes. The run used only the Linux backlight class.
  • PMIC MPP/GPIO/PON/LPG/VIB and TLMM key state are byte-identical before and after (live-pmic-ro-2.txt vs live-pmic-ro-3-post.txt).

Why no separate RAM image was built

The only SAFE line is already a Linux class device in the production kernel (/sys/class/backlight/backlight, gpio-backlight on MPP4). A RAM DTB that renames it to /sys/class/leds/aurora-led-* adds nothing to the test and would need a RESET-held fastboot boot. The operator approved running on the live boot instead. The production kernel has LEDS_GPIO=y, so a DTB-only RAM image is possible later if new SAFE lines are proven.

Main table

LED physical position GPIO/MPP/LPG active level initial state all-ON result chase result brightness verdict
L1 LCD backlight behind the 1.44" ST7735S panel PM8916 MPP4 current sink 40 mA (MODE 0x61 on / 0x60 off, SINK 0x07, EN 0x80) sink ON = lit (gpio-backlight 1) ON (bl=1, a340=61) lit: operator-confirmed; a340 60→61 2/2 cycles: operator-confirmed not tested (no PWM; LPG 0xbc00 not routed/proven) PASS / SAFE
MPP3 unknown PM8916 MPP3, current sink, source = off — off (a240=60) not switched — — UNKNOWN
PM GPIO1–4 unknown PM8916 GPIO 1–4, input with pull-down — input not switched — — UNKNOWN
VIB_DRV unknown (no motor known) PM8916 sid1 0xc000 — off not switched — — UNKNOWN
TLMM unclaimed pins (list in audit §2) — input with pull-down, func0 — input not switched — — UNKNOWN

Run r1 (logs/b11/live/b11-run-r1.log, script b11/run/b11-led-run.sh)

3415.29 PRECHECK lte=ok mpss=ok wcnss=ok wifi=ok ncm=ok disp=ok chg=Charging pmic=40504 kerr=0
3415.30 STAGE1 ALL-OFF      a340=60 bl=0
3417.31 STAGE2 ALL-ON 4s    a340=61 bl=1
3421.34 STAGE3 ALL-OFF      a340=60
3423.36 STAGE4 CHASE c1 L1 ON / 3424.07 OFF / 3424.77 c2 ON / 3425.48 OFF
3426.19 STAGE5 SKIPPED no PWM-confirmed line
3426.21 STAGE6 RESTORE      a340=61 a341=00 a346=80 a34c=07 bl=1 (= PRE)
3431.24 POSTCHECK lte=ok mpss=ok wcnss=ok wifi=ok ncm=ok disp=ok chg=Charging pmic=41033 kerr=0
3431.25 END OK
  • A background monitor ran about every 2 s. It checked LTE ping via wwan0, MPSS, WCNSS, wlan0+hostapd, usb0 NCM, the panel driver bound plus fb0, charger status, PMIC temperature, and new kernel errors. Any FAIL would have restored the line and aborted the run. There were 0 FAILs and 0 new kernel error lines. The heartbeat continued.
  • Afterwards: LTE ping 3/3, both remoteprocs running, wlan0 up, backlight 1 (live/post-health.txt).
  • Side observation: the pm8916-thermal reading drops by about 7 °C (40.5 → 33.2 °C) within 1 s of switching the 40 mA sink off, and comes back when it is switched on. That is too fast to be real heating, so it is a measurement artefact of the temperature-alarm/ADC path under MPP4 load. Account for it in thermal logic.

Buttons (read-only, b11/run/b11-btn-watch.sh, logs live/b11-btn-b1.log, b11-btn-b2.log)

No line was driven. The script polled debugfs gpio and PON RT 0x0810 every ~0.12 s. The case has 3 buttons (operator): POWER, MENU, RESET.

Button line observed notes
POWER PM8916 KPDPWR (PON RT bit0), Linux pm8941_pwrkey event0 bit0 pulses; pwrkey IRQ 2 → 36 works. Nothing in userspace acts on KEY_POWER. S2 warm reset on long hold (0x0843 = 0x80).
MENU probably also KPDPWR the 2nd press series (≈3697 s, order POWER → MENU → RESET) is also bit0; GPIO37/107 never changed not provable from software alone (MENU and POWER look identical). Needs a one-button-at-a-time recheck or continuity check.
RESET PM8916 RESIN (PON RT bit1) bit1 pulses (≈3705 s, ≈3761 s) no Linux input bound. Long hold → PMIC stage-3 reset. KPDPWR+RESIN = hard reset.
key_f2 / key_f3 (stock DT GPIO37 / GPIO107) TLMM no change in either window no button on the case drives these lines; stock gpio-keys entries are probably leftovers.

The first watcher window (b1) saw no presses because the operator had not pressed yet. Window b2 is the valid one.

Summary

  • Physical LEDs that lit: 1 LED function (LCD backlight; operator-confirmed). The operator sees no other lit indicator LED in normal operation.
  • SAFE lines found: 1 (MPP4).
  • Empty LED footprints: not mapped. No DT, firmware, or live-state evidence ties them to a line. With no continuity data they are documented only and not switched.
  • Still UNKNOWN: MPP3 (current sink, off; the most LED-like candidate), PM GPIO1–4, VIB_DRV, and all unclaimed TLMM inputs (GPIO 0, 2, 3, 6–11, 16–19, 21, 24–36, 38, 39, 45–56, 61, 62, 69–98, 108, 109, 111, 112, 114, 115, 117, 119–121).
  • DO NOT TOUCH: MPP1 (analog out), MPP2 (digital out HIGH, set by firmware), GPIO1/20/22/23 (SIM mux), 4/5 (UART), 12–15/116/118 (display), 40–44 (WCNSS), 57–60 (UIM), 63–68 (codec), 99–106 (modem RF/SSBI incl. 105 out-low and 106 pulled up), 110 (USB-ID), 113 (audio), SDC pads; PON KPDPWR/RESIN (read-only only).

Next steps (each needs a separate GO)

  1. Continuity: trace the empty LED footprints, and their series-resistor pads if present, to the SoC/PMIC. A footprint that reaches MPP3 or a PM GPIO can then become SAFE.
  2. MENU: press one button per window to confirm MENU = KPDPWR. If it is separate, find its line.
  3. Optional: MPP4 brightness by sink current (5–40 mA, SINK_CTL 0–7). This is not PWM; it needs a test kernel with a register hook or an LED driver.

Files: logs/b11/B11-LED-AUDIT.md (full audit), logs/b11/live/*, b11/audit/b11-ro.sh, b11/run/b11-led-run.sh, b11/run/b11-btn-watch.sh.