uzbek-plus/bootchain-migration/PREFLIGHT.md
q 105bef466a Project Aurora: mainline ARM64 Linux on JZ08AU (MSM8916) LTE modem
Sanitized research log, build/reproducibility docs, DTS, kernel configs,
patches, initramfs sources, bootchain migration plans and test logs.
B5 direct boot PASS; B6 modem lifecycle in progress.
No dumps, NV/EFS, vendor firmware or device identifiers included.
2026-09-30 17:23:18 +03:00

68 lines
6.8 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Aurora bootchain migration preflight (ARM64) — 2026-09-30. NOTHING WRITTEN.
## 1. Why ARM64 fails today (proven)
lk2nd 23.1 `spin-table.c:54`: `!is_scm_armv8_support()` && ARM64 kernel → "Cannot boot ARM64 with old SCM calling convention";
`scm.c` ~1060–1085: 32→64 switch = SCM `SCM_SVC_MILESTONE_32_64`; legacy-SCM TZ returns → `ASSERT(0)`.
Stock TZ = TZ.BF.2.2-2.2.0026 (ELF32, legacy SCM, no PSCI), ELF-identical to JZ02 stock.
## 2. Component requirements (evidence: JZ02 PLAN-B runs on IDENTICAL stock sbl1/rpm/tz/hyp ELF + qhypstub README)
| component | verdict | evidence |
|---|---|---|
| TZ → DB410c TZ.BF.3.0-00714 (ELF64, armv8 SCM + PSCI) | **REQUIRED** | JZ02 S3: qhypstub with stock TZ.BF.2.2 → silence after SBL1. S4′: TZ.BF.3.0 + qhypstub → lk1st → PSCI v1.0 → arm64 Linux |
| HYP → qhypstub | **REQUIRED (with TZ.BF.3.0)** | stock hyp is ELF32; JZ02 only proven pair = TZ64 + qhypstub. qhypstub also brings RPM out of reset. Alone: insufficient (JZ02 S3) |
| GPT delta (tz 512K→1M, tzbak moved to empty gap) | **REQUIRED** | DB410c TZ = 605312 B > tz 524288 B, last segment ends at EOF (cannot truncate) |
| ABOOT → lk1st | **REQUIRED for a proven chain** / stock aboot = UNKNOWN | Only proven combo is lk1st. Stock Aurora LK (32-bit, legacy-SCM era) under TZ.BF.3.0+qhypstub never tested on any board; qhypstub README says aarch32 LK in EL1 is supported in principle |
| lk2nd in recovery | OPTIONAL (keep untouched) | with lk1st in aboot, lk1st itself gives `fastboot boot`; recovery stays as is |
| SBL1 / RPM / DDR / sec / cdt | keep stock (NOT required) | JZ02 runs stock sbl1 BOOT.BF.3.0.1 + stock rpm RPM.BF.2.0.1 with TZ.BF.3.0; Aurora sbl1/DDR/sec byte-identical, rpm ELF identical |
## 3. JZ02 (working ARM64) vs Aurora (stock)
| component | JZ02 working | Aurora stock | same? | role | replace? | risk |
|---|---|---|---|---|---|---|
| SBL1 | stock 6a661ec9… BOOT.BF.3.0.1-00019 | 6a661ec9… | SAME (bytes) | DDR init, loads TZ/RPM/HYP/ABOOT | no | — |
| RPM | stock 53b591bb… | ELF identical (slack differs) | SAME (ELF) | power/clocks | no | — |
| DDR | stock | c3502047… = JZ02 | SAME (bytes) | DDR params for SBL1 | no | — |
| TZ | DB410c TZ.BF.3.0-00714 (8481892f… padded 1M) | TZ.BF.2.2-2.2.0026 | DIFFERENT | secure monitor, SCM/PSCI | yes | high (runs before aboot) |
| HYP | qhypstub (1a963047… padded 512K) | stock ELF32 (TZ.BF.2.2 hyp) | DIFFERENT | EL2, RPM release | yes | high |
| ABOOT | lk1st JZ02 build (JZ02 node, -dirty) | stock LK 2026-07 (SPI panel, charger) | DIFFERENT | bootloader/fastboot | yes (Aurora lk1st) | medium (loses Android) |
| GPT | tz 270336..272383, tzbak 305184..306207 | stock | DIFFERENT (2 entries) | layout | yes | high (table write) |
| QCDT/DT | lk1st: appended kernel DTB | stock LK: QCDT dtb_01 | — | kernel DT | n/a (mainline DTB appended) | — |
Aurora region layout (tz/tzbak/hyp LBAs, splash end 305169, gap 305170..393215 all-zero, DDR 393216) == JZ02 → same GPT delta applies.
Memory map: upstream msm8916.dtsi reserves tz@86500000 (DB410c TZ) — proven on JZ02. DDR init owner = stock SBL1 (unchanged). PMIC PM8916 same; RPM unchanged.
Board-id: lk1st does not use QCDT; kernel DTB appended ("Only one appended non-skales DTB").
Display: stock LK powers + draws ST7735S splash (`Config SPI PANEL`); lk1st has no SPI-panel driver → **no boot splash** (expected change, not a fault).
## 4. Options
| | writes | ARM64 handoff | normal boot after | recovery/lk2nd | EDL | rollback | main brick risk |
|---|---|---|---|---|---|---|---|
| A hyp=qhypstub only | hyp | **NO** (JZ02 S3 hang) | hangs after SBL1 | unreachable | HW only | ws hyp | proven failure → rejected |
| B tz=DB410c, hyp=qhypstub, aboot=stock | GPT, tz, hyp | plausible via lk2nd in recovery (armv8 SCM + PSCI) | UNKNOWN (stock LK + Android 3.10 on TZ64 never tested; qseecom/keymaster TZ apps built for TZ.BF.2.x) | lk2nd path kept (if stock LK runs) | adb only if Android boots, else HW | ws GPT/tz/hyp | stock LK hang → only HW EDL |
| C tz=DB410c, hyp=qhypstub, aboot=lk1st | GPT, tz, hyp, aboot | **YES** (JZ02 S4′/S5, identical inputs) | lk1st forced fastboot (Android gone) | untouched, not needed | lk1st `fastboot oem reboot-edl` (proven JZ02) + HW | ws each stage | lower: every stage proven on JZ02 |
| D staged C (JZ02 order) | same as C, one change per stage | YES at end | per stage | untouched | per stage | per stage | minimal: stage-by-stage verification |
**Recommended: D (= C executed in JZ02's proven order).** Not hyp alone. Not B (unproven, and only saves Android which the target system does not need).
## 5. HW EDL without ADB — OPEN BLOCKER (must be proven before S1)
Currently proven on Aurora: only `adb reboot edl`. After S1 Android is gone; lk1st `oem reboot-edl` only works if lk1st boots.
Evidence for a button path (NOT yet proven on Aurora):
- JZ02: stock DT `key_reset` = GPIO37; user entered 9008 with the RESET button (PLAN-B "HW EDL proof", twice, also with lk1st in aboot).
- upstream lk2nd `msm8916-512mb-mtp.dts`: GPIO37 is labelled "The EDL button" on UFI-001B/C sticks.
- Aurora stock DT: `key_f2` = **GPIO37** (active-high, same pin).
Test (non-destructive, no write): identify which physical button is KEY_F2 (`adb shell getevent -l`, press buttons),
full power-off (USB + battery), hold that button, apply power/USB → expect `lsusb` 05c6:9008; exit = power-off.
If this does not yield 9008: STOP — no bootloader writes without a hardware recovery path. Do NOT short test pads blindly.
## 6. Recovery path
recovery (lk2nd 23.1) stays untouched. With lk1st in aboot, development path becomes: power-on → lk1st fastboot → `fastboot boot`.
lk1st PANIC_REBOOT_MODE=EMERGENCY_DLOAD (panic → EDL).
## 7. UART
lk1st = same lk2nd 23.1 target code: `uart_dm_init(2,0,0x78B0000)`, GPIO4/5 → UART stays on BLSP1 UART2 115200 (proven for lk2nd on Aurora, lk1st on JZ02).
SBL1 prints its log on the same UART (seen). qhypstub/TZ print nothing (JZ02: SBL1 → silence → lk1st).
## 8. Uncertainties
1. HW EDL button on Aurora — unproven (blocker).
2. DB410c TZ provenance: from OpenStick base.zip (JZ02); Linaro release server no longer serves files → cannot re-verify upstream origin online.
Mitigation: byte-identical to image running on JZ02 hardware; signed with Qualcomm test chain = Aurora PK_HASH root.
3. lk1st-aurora is a new build (never run): same source/tag as the lk2nd running on Aurora, same config pattern as JZ02 lk1st (bundle 512mb-mtp dtb, force fastboot), no device node → generic.
4. Battery/charging: stock LK off-mode charging + charger decisions disappear with lk1st; PM8916 charging behaviour under lk1st/mainline untested. Keep USB power connected.
5. Aurora MPSS is a different build than JZ02 (re-signed 2026-04-30) — irrelevant for boot, relevant later for modem under TZ.BF.3.0.
6. Android + stock recovery will no longer boot after S1 (expected); full stock restore = rollback all stages.