- B9A: read-only audit of stock LK/DT: the panel is an ST7735S 128x128 on SPI (BLSP1 QUP4, 16 MHz, mode 3, D/C GPIO116, RESET GPIO118), backlight = PM8916 MPP4 current sink 40 mA. - B9B: upstream panel-mipi-dbi with the stock init sequence as firmware; MPP4 sink via pinctrl + gpio-backlight; first light with correct colours/orientation/offsets. - B9C: fbcon (6x8, 21x16) on tty1 + getty, UART console kept, aurora-display service; cache B9C b9ce13c9 written and verified, cold boots with LTE + Wi-Fi + display. - B9L (RAM only): lk2nd second stage with an msm8916 SPI panel port shows a picture before Linux. - Sanitizer: whitelist for b8/ and b9/.
9.2 KiB
B9A-RESULT — display chain audit (read-only)
Date: 2026-10-03. Board: Aurora JZ08AU-XPA-7J-R3, running B8F (cache 857c9c30, kernel 7.2.7-aurora-b8d #7).
Nothing was changed: no kernel/DT build, no eMMC/cache write, no GPIO/regulator/PMIC/SPI writes, no reboot.
The live snapshot only read sysfs/debugfs and PMIC registers (regmap debugfs reads). eMMC write counter = 0.
Main finding
This is not a DSI panel and MDP is not used. The built-in display is a 1.44" 128×128 ST7735S panel on SPI
(MIPI-DBI type C, 4-wire: SCL/SDA/CS plus a D/C GPIO). It is driven over BLSP1 QUP4 (spi@78b8000, GPIO 12–15).
The backlight is PM8916 MPP4 used as a 40 mA current sink.
Stock LK fully brings the panel up before Linux: reset, SPI, 19 init commands, a 128×128 "4G LTE" logo built into LK, then backlight.
It happens about 210 ms after LK starts. LK then passes the panel to the kernel as continuous splash
(mdss_mdp.panel=1:spi:0:qcom,mdss_spi_st7735s_wx144_128x128_cmd).
Stock LK is therefore an exact reference, and it matches the stock DT byte for byte.
Table
| Level | Stock | Current Linux | Status |
|---|---|---|---|
| MDP/MDSS | Present (qcom,mdss_mdp), used by Android only as a CPU-side fb (fb0 128×128, 32 bpp, memblock-reserve 0x83200000/0xfa0000). LK writes fb 0x83200000 and copies it over SPI, with no scanout. |
display-subsystem@1a00000 status=disabled, DRM=n |
Not needed: MDP/DSI are not part of the chain |
| DSI | Only mdss_dsi_sim_video (simulator) and an empty mdss_dsi@1a98000. LK also has a DSI st7796s_320p (id 0) that this board never uses. |
Disabled | Not used |
| "Display controller" = SPI host | BLSP1 QUP4 0x78b8000; GPIO12 MOSI, 13 MISO, 14 CS0, 15 CLK (func 1, 12 mA); clock 16 MHz; mode 3 (CPOL=1, CPHA=1); TX only. Kernel: qcom,mdss_spi + mdss_spi_client @16 MHz. |
spi@78b8000 status=disabled, SPI_QUP=y, no spi_master, GPIO 12–15 are reset defaults (in, pull-down) |
MISSING (1st point in Linux) |
| Panel | st7735s wx144 128x128 command mode spi panel; in LK panel_id = 1 is hardcoded (no ID read). RGB565 (COLMOD 05), MADCTL c8 (MY|MX|BGR), window col 2..129 / row 3..130. The 19-command init sequence is identical in LK and DT (b9a-stock-lk.txt §4). Off: 28, 10+120 ms. An alternative nv3023a_jz05 is in the DT, but LK never selects it. |
No panel node, no driver (DRM_PANEL_MIPI_DBI/DRM_ST7735R not built) |
MISSING |
| Regulators | Stock kernel: vdd = 8916_l17 2.85 V, vddio = 8916_l6 1.8 V. Stock LK does not touch any regulator (target_ldo_ctrl is a stub; LK has no RPM regulator code). |
HW: L6 ON (EN 0x80, by SBL/RPM default). L17 OFF (EN 0x00, STATUS 0x00). Linux holds neither. | Open: is L17 needed for the panel? LK runs without enabling it (see "Open questions") |
| GPIO/reset | RESET = GPIO118 (disp_rst_n), D/C = GPIO116 (disp_dc), both out, 8 mA. Reset: high 1 ms → low 1 ms → high → 120 ms. No TE, no enable GPIO (LK touches GPIO0 only with OE=0, a CAF leftover). |
GPIO116/118: in, pull-down, UNCLAIMED → panel is held in reset | MISSING |
| Backlight | PM8916 MPP4 current sink: MODE_CTL 0xa340=0x61, SINK_CTL 0xa34c=0x07 (40 mA), EN 0xa346=0x80. Turned on after init and the first frame. Android: qcom,leds-qpnp MPP4 lcd-bl 40 mA (trigger bkl-trigger). No PWM/WLED/DCS. |
MPP4 regs = 00/00/00 (off), /sys/class/backlight empty |
MISSING |
| DRM/fb | Android: mdss_fb fb0 (mdssfb_d0000, 128×128, virtual 128×256, 32 bpp). LK: fbcon 16 bpp @0x83200000. |
DRM=n, FB=n; no /dev/dri, /dev/fb*, /sys/class/drm|graphics |
MISSING |
Exact chain (stock → what B9 needs)
SoC display "controller": BLSP1 QUP4 SPI @0x78b8000 (gcc_blsp1_qup4_spi_apps_clk 16 MHz, mode 3, CS0, GPIO12-15 func1)
→ "DSI host": none. The SPI host itself + D/C GPIO116 = MIPI-DBI type C (4-wire) host
→ panel: ST7735S 128x128 (1.44" "wx144"), GRAM offset (2,3), RGB565, MADCTL 0xc8
→ reset/power: L6 1.8 V on (default) [L17 2.85 V: stock kernel only, LK does not enable it];
GPIO118 1→0 (1 ms)→1, wait 120 ms
→ init: SLPOUT +120 ms, FRMCTR1/2/3, INVCTR 03, PWCTR1-5, VMCTR1 12, GMCTRP1/N1, MADCTL c8, COLMOD 05,
CASET 2..129, RASET 3..130, DISPON, RAMWR (+ 128*128*2 B frame, D/C=1)
→ backlight: PM8916 MPP4 current sink 40 mA (0x61/0x07/0x80), after the first frame
→ framebuffer/DRM: in Linux → SPI device + panel-mipi-dbi (or st7735r) → /dev/dri/card0 (+ /dev/fb0 via fbdev emulation)
First point where things diverge
- Across the whole boot path, the first divergence is the bootloader. Stock LK brings up the panel at ~210 ms.
The current lk1st (msm8916 lk2nd tree) has no SPI-panel code:
mdss_spi.ois only built for msm8909/msm8952. So the panel is never initialised, and its RESET stays low because of the SoC pull-down. - Within Linux, the first missing link is the SPI host:
spi@78b8000isstatus = "disabled". Everything after it is also missing: no panel node and no driver, D/C and RESET GPIOs are not described, there is no MPP4 backlight, and DRM/FB are off. MDP/DSI do not belong to this chain, so their being disabled is not the problem.
There is no simpledrm/simplefb path: no loader leaves the panel initialised, and an SPI panel has no scanout. So Linux has to bring the panel up itself, which is what B9 asks for anyway.
Open questions (do not block B9B)
- L17: it is off in hardware, while the stock kernel declares it as panel vdd and stock LK never turns it on. So either SBL1/RPM turn it on during a stock boot (unlikely: SBL1/RPM are still stock now and L17 is off), or the panel VDD is fed from another rail. B9B will settle it by testing with L17 untouched, exactly like LK.
- Exact glass model: LK hardcodes ST7735S and does not read an ID. The vendor DT also has
nv3023a_jz05. The cable/glass markings are unknown. A visual check in B9B confirms that the ST7735S init works on this glass. An ID read (RDDID 04h) is possible later if MISO/SDA can actually be read back (LK runs TX-only). - Operator question: on stock firmware, did the "4G LTE" logo appear on the screen at power-on?
(LK's built-in image:
b9a-stock-lk-embedded-logo-128x128.png, because the stocksplashpartition is all zeros.)
Proposed B9B (RAM-only, ONE test) — waiting for GO
B9B "first light": boot the B8F RAM image via RESET-held power-on + fastboot boot. Cache B8F and the eMMC are not touched.
- Kernel =
out-b8d+DRM=y,DRM_PANEL_MIPI_DBI=y,DRM_FBDEV_EMULATION=y(+ theFBcore it needs). No fbcon, no MSM DRM. - DTB = B8B DTB plus:
&blsp_spi4 { status = "okay"; cs-gpios = <&tlmm 14 GPIO_ACTIVE_LOW>; }(upstream style; stock used native CS0).panel@0:compatible = "aurora,st7735s-wx144", "panel-mipi-dbi-spi",spi-max-frequency = <16000000>,spi-cpol; spi-cpha,write-only(LK is TX-only; without it the driver'smipi_dbi_poweron_conditional_resetwould read DCS 0Ah back over SPI and might skip init because of a garbage readback),dc-gpios = <&tlmm 116 GPIO_ACTIVE_HIGH>,reset-gpios = <&tlmm 118 GPIO_ACTIVE_LOW>,panel-timing128×128 withhback-porch = 2,vback-porch = 3(the GRAM offset), andbacklight = <&lcd_bl>.lcd_bl:gpio-backlighton&pm8916_mpps 4with pinctrlfunction = "sink",drive-strength = <7>(40 mA, as in LK).- No regulator references (exactly like stock LK).
- initramfs = B8F +
/lib/firmware/aurora,st7735s-wx144.bin: the stock 19-command sequence minus RAMWR, in the panel-mipi-dbi format (SLPOUT, then a 120 ms delay, …, MADCTL c8, COLMOD 05, DISPON). The driver loads<compatible[0]>.bin, and back-porch is used as the GRAM offset (panel-mipi-dbi.c:197, :366-367; checked against the 7.2.7 source). The driver turns on the backlight right after the init commands; LK does it after the first frame (a small difference, acceptable for B9B). - Test (read-mostly): check the probe in dmesg, that
/dev/dri/card0and/dev/fb0exist, and read back MPP4 = 0x61/0x07/0x80 plus GPIO 116/118/12–15. Then write one static test frame to/dev/fb0(colour bars + a corner marker) and the operator confirms the image, colours and orientation. LTE and Wi-Fi must keep working, and eMMC writes must stay 0. - PASS = a correct image with backlight on, and no LTE/Wi-Fi regressions.
If the screen stays dark or white, the single next variable for B9C is the panel's
power-supply = L17 2.85 V, as the stock kernel uses.
STOP. B9B only after a separate GO.
Files
b9a-stock-lk.txt— stock LK: UART evidence, function map, structures, init table, backlight, splashb9a-stock-lk-embedded-logo-128x128.png— the logo built into stock LK (RGB565 @0x8f64b004)b9a-stock-dt.txt— stock dtb_01 nodes (mdss_mdp + panels, mdss_spi, spi@78b8000, pinctrl, MPP4 LED, L6/L17)b9a-current-dt.txt— current B8F DTB (dtc) display-related nodesb9a-kconfig.txt— kernel config auditb9a-linux-display.txt(+.raw.txt) — live read-only snapshot of the boardb9a-backlight.txt— backlight mechanism- Scripts
b9/b9a/:lk-xref.py,lkmem.py,disrange.sh,decode-panel.py,render-lk-logo.py,dt-extract.py,b9a-live.sh(board),b9a-run.sh(480s)