uzbek-plus/bootchain-migration/PREFLIGHT.md
q 105bef466a Project Aurora: mainline ARM64 Linux on JZ08AU (MSM8916) LTE modem
Sanitized research log, build/reproducibility docs, DTS, kernel configs,
patches, initramfs sources, bootchain migration plans and test logs.
B5 direct boot PASS; B6 modem lifecycle in progress.
No dumps, NV/EFS, vendor firmware or device identifiers included.
2026-09-30 17:23:18 +03:00

6.8 KiB
Raw Blame History

Aurora bootchain migration preflight (ARM64) — 2026-09-30. NOTHING WRITTEN.

1. Why ARM64 fails today (proven)

lk2nd 23.1 spin-table.c:54: !is_scm_armv8_support() && ARM64 kernel → "Cannot boot ARM64 with old SCM calling convention"; scm.c ~1060–1085: 32→64 switch = SCM SCM_SVC_MILESTONE_32_64; legacy-SCM TZ returns → ASSERT(0). Stock TZ = TZ.BF.2.2-2.2.0026 (ELF32, legacy SCM, no PSCI), ELF-identical to JZ02 stock.

2. Component requirements (evidence: JZ02 PLAN-B runs on IDENTICAL stock sbl1/rpm/tz/hyp ELF + qhypstub README)

component verdict evidence
TZ → DB410c TZ.BF.3.0-00714 (ELF64, armv8 SCM + PSCI) REQUIRED JZ02 S3: qhypstub with stock TZ.BF.2.2 → silence after SBL1. S4′: TZ.BF.3.0 + qhypstub → lk1st → PSCI v1.0 → arm64 Linux
HYP → qhypstub REQUIRED (with TZ.BF.3.0) stock hyp is ELF32; JZ02 only proven pair = TZ64 + qhypstub. qhypstub also brings RPM out of reset. Alone: insufficient (JZ02 S3)
GPT delta (tz 512K→1M, tzbak moved to empty gap) REQUIRED DB410c TZ = 605312 B > tz 524288 B, last segment ends at EOF (cannot truncate)
ABOOT → lk1st REQUIRED for a proven chain / stock aboot = UNKNOWN Only proven combo is lk1st. Stock Aurora LK (32-bit, legacy-SCM era) under TZ.BF.3.0+qhypstub never tested on any board; qhypstub README says aarch32 LK in EL1 is supported in principle
lk2nd in recovery OPTIONAL (keep untouched) with lk1st in aboot, lk1st itself gives fastboot boot; recovery stays as is
SBL1 / RPM / DDR / sec / cdt keep stock (NOT required) JZ02 runs stock sbl1 BOOT.BF.3.0.1 + stock rpm RPM.BF.2.0.1 with TZ.BF.3.0; Aurora sbl1/DDR/sec byte-identical, rpm ELF identical

3. JZ02 (working ARM64) vs Aurora (stock)

component JZ02 working Aurora stock same? role replace? risk
SBL1 stock 6a661ec9… BOOT.BF.3.0.1-00019 6a661ec9… SAME (bytes) DDR init, loads TZ/RPM/HYP/ABOOT no —
RPM stock 53b591bb… ELF identical (slack differs) SAME (ELF) power/clocks no —
DDR stock c3502047… = JZ02 SAME (bytes) DDR params for SBL1 no —
TZ DB410c TZ.BF.3.0-00714 (8481892f… padded 1M) TZ.BF.2.2-2.2.0026 DIFFERENT secure monitor, SCM/PSCI yes high (runs before aboot)
HYP qhypstub (1a963047… padded 512K) stock ELF32 (TZ.BF.2.2 hyp) DIFFERENT EL2, RPM release yes high
ABOOT lk1st JZ02 build (JZ02 node, -dirty) stock LK 2026-07 (SPI panel, charger) DIFFERENT bootloader/fastboot yes (Aurora lk1st) medium (loses Android)
GPT tz 270336..272383, tzbak 305184..306207 stock DIFFERENT (2 entries) layout yes high (table write)
QCDT/DT lk1st: appended kernel DTB stock LK: QCDT dtb_01 — kernel DT n/a (mainline DTB appended) —
Aurora region layout (tz/tzbak/hyp LBAs, splash end 305169, gap 305170..393215 all-zero, DDR 393216) == JZ02 → same GPT delta applies.
Memory map: upstream msm8916.dtsi reserves tz@86500000 (DB410c TZ) — proven on JZ02. DDR init owner = stock SBL1 (unchanged). PMIC PM8916 same; RPM unchanged.
Board-id: lk1st does not use QCDT; kernel DTB appended ("Only one appended non-skales DTB").
Display: stock LK powers + draws ST7735S splash (Config SPI PANEL); lk1st has no SPI-panel driver → no boot splash (expected change, not a fault).

4. Options

writes ARM64 handoff normal boot after recovery/lk2nd EDL rollback main brick risk
A hyp=qhypstub only hyp NO (JZ02 S3 hang) hangs after SBL1 unreachable HW only ws hyp proven failure → rejected
B tz=DB410c, hyp=qhypstub, aboot=stock GPT, tz, hyp plausible via lk2nd in recovery (armv8 SCM + PSCI) UNKNOWN (stock LK + Android 3.10 on TZ64 never tested; qseecom/keymaster TZ apps built for TZ.BF.2.x) lk2nd path kept (if stock LK runs) adb only if Android boots, else HW ws GPT/tz/hyp stock LK hang → only HW EDL
C tz=DB410c, hyp=qhypstub, aboot=lk1st GPT, tz, hyp, aboot YES (JZ02 S4′/S5, identical inputs) lk1st forced fastboot (Android gone) untouched, not needed lk1st fastboot oem reboot-edl (proven JZ02) + HW ws each stage lower: every stage proven on JZ02
D staged C (JZ02 order) same as C, one change per stage YES at end per stage untouched per stage per stage minimal: stage-by-stage verification
Recommended: D (= C executed in JZ02's proven order). Not hyp alone. Not B (unproven, and only saves Android which the target system does not need).

5. HW EDL without ADB — OPEN BLOCKER (must be proven before S1)

Currently proven on Aurora: only adb reboot edl. After S1 Android is gone; lk1st oem reboot-edl only works if lk1st boots. Evidence for a button path (NOT yet proven on Aurora):

  • JZ02: stock DT key_reset = GPIO37; user entered 9008 with the RESET button (PLAN-B "HW EDL proof", twice, also with lk1st in aboot).
  • upstream lk2nd msm8916-512mb-mtp.dts: GPIO37 is labelled "The EDL button" on UFI-001B/C sticks.
  • Aurora stock DT: key_f2 = GPIO37 (active-high, same pin). Test (non-destructive, no write): identify which physical button is KEY_F2 (adb shell getevent -l, press buttons), full power-off (USB + battery), hold that button, apply power/USB → expect lsusb 05c6:9008; exit = power-off. If this does not yield 9008: STOP — no bootloader writes without a hardware recovery path. Do NOT short test pads blindly.

6. Recovery path

recovery (lk2nd 23.1) stays untouched. With lk1st in aboot, development path becomes: power-on → lk1st fastboot → fastboot boot. lk1st PANIC_REBOOT_MODE=EMERGENCY_DLOAD (panic → EDL).

7. UART

lk1st = same lk2nd 23.1 target code: uart_dm_init(2,0,0x78B0000), GPIO4/5 → UART stays on BLSP1 UART2 115200 (proven for lk2nd on Aurora, lk1st on JZ02). SBL1 prints its log on the same UART (seen). qhypstub/TZ print nothing (JZ02: SBL1 → silence → lk1st).

8. Uncertainties

  1. HW EDL button on Aurora — unproven (blocker).
  2. DB410c TZ provenance: from OpenStick base.zip (JZ02); Linaro release server no longer serves files → cannot re-verify upstream origin online. Mitigation: byte-identical to image running on JZ02 hardware; signed with Qualcomm test chain = Aurora PK_HASH root.
  3. lk1st-aurora is a new build (never run): same source/tag as the lk2nd running on Aurora, same config pattern as JZ02 lk1st (bundle 512mb-mtp dtb, force fastboot), no device node → generic.
  4. Battery/charging: stock LK off-mode charging + charger decisions disappear with lk1st; PM8916 charging behaviour under lk1st/mainline untested. Keep USB power connected.
  5. Aurora MPSS is a different build than JZ02 (re-signed 2026-04-30) — irrelevant for boot, relevant later for modem under TZ.BF.3.0.
  6. Android + stock recovery will no longer boot after S1 (expected); full stock restore = rollback all stages.