- LBC supervisor v1..v4 (linux/patches/b10b3-lbc-supervisor-v3.patch + b10/b10b3/lbc-v3-to-v4-fault-clamp.diff): CHARGING 4.20 V/450 mA -> HOLD 4.05 V after 60 min CV -> battery -> new cycle on USB insert; FAULT = VDD_MAX 4.00 V clamp - RAM tests C/B/D/D2/D3/D4 (safety timer only ends fast charge), B10B-4 actuator audit (VDD_MAX works, USB_SUSP does not), B10B-5 FAULT clamp regression, production run, warm reboot via PON reboot reason - cache = B10B-5 c3732515 (HW EDL write, readback + full partition verify), class-A persistent validation - test-only hooks/images are not part of the production kernel; images with the AP PSK are not published
56 lines
5 KiB
Markdown
56 lines
5 KiB
Markdown
# B10B-3 cache candidate — prepared, NOT written, NOT ready for persistent deployment
|
||
|
||
Date: 2026-10-04. **Status: candidate prepared and RAM-pretested; no cache/eMMC write. Persistent GO blocked (see Blocker).**
|
||
Contains the AP PSK (B8F initramfs) — never publish.
|
||
|
||
## Candidate
|
||
`cache-extlinux-b10b3.img` **86869061fcc971131068644542547893332f3ede9870a324eaf360824610d40a** (134217728 B, ext2, label aurora-b10b3,
|
||
UUID 4a5a3038-b6f0-4000-8000-0000b10b3c00). Built on 480s by `mkfs-cache-b10b3.sh` (278130cf) = exact B9C recipe (`b9/b9c/cache/mkfs-cache-b9c.sh`);
|
||
rebuild bit-identical; `e2fsck -fn` clean. `SHA256SUMS` in this directory.
|
||
|
||
## Composition and diff vs the live B9C cache (b9ce13c9) — `cache-contents-b9c-vs-b10b3.txt`
|
||
| file | B9C | candidate |
|
||
|---|---|---|
|
||
| /Image.gz-dtb | 632a7be8 (kernel 7.2.7-aurora-b9c + B9B DTB) | **5e69f843** (kernel 7.2.7-aurora-b10b3 1164b1c7 + production DTB) |
|
||
| DTB (fdt) | /aurora-b9c.dtb 7ca9cc79 | **/aurora-b10b3.dtb e47762d1** (`linux/dts/msm8916-jz08-aurora-b10b3.dts`) |
|
||
| /initramfs-b9c.cpio.gz | ac518e27 | ac518e27 (unchanged: B9C userspace/init/display/network) |
|
||
| extlinux.conf | label b9c, fdt aurora-b9c.dtb | label b10b3, fdt aurora-b10b3.dtb; **append identical** |
|
||
Really replaced: the kernel file and the DTB (plus label/fdt name in extlinux.conf). Kernel config b10b3 = B9C config + CHARGER_PM8916_LBC,
|
||
BATTERY_PM8916_BMS_VM, IIO, QCOM_SPMI_VADC, QCOM_VADC_COMMON, QCOM_SPMI_TEMP_ALARM (+ LOCALVERSION). Driver = v3 (`linux/patches/b10b3-lbc-supervisor-v3.patch`),
|
||
**no D3 change**. DTB = B9B DTB + layers b10b0 (VADC VBAT ch6) / b10b1 (battery 3000 mAh, BMS) / b10b2 (charger on, usbin off, extcon) / b10b3 (supervisor).
|
||
|
||
## DTB check (fdtget, /soc@0/spmi@200f000/pmic@0/charger@1000)
|
||
status "okay"; qcom,fast-charge-safe-voltage 4200000; qcom,fast-charge-safe-current 500000 (→ IBAT_MAX 450 mA); qcom,charge-timeout-minutes 512;
|
||
aurora,hold-voltage-microvolt 4050000; aurora,full-min-voltage-microvolt 4150000; aurora,cv-hold-minutes 60; io-channel-names "vbat";
|
||
/battery voltage-max-design-microvolt 4200000, charge-full-design 3000000; re-charge-voltage absent. No Test-C/B/D/T values (4.10/4.00 V, 5/2 min,
|
||
8 min, 3.94 V) present. The DTB appended to Image.gz-dtb is byte-identical to the fdt file. Model string "JZ08AU Aurora (RAM boot B10B-3)" (cosmetic).
|
||
|
||
## lk2nd emulator (`emu/run-emu-b10b3.sh`, b5b/emu)
|
||
- S8 regression on the live B9C cache == b9/b9c/cache/emu S7 (HARNESS lines identical).
|
||
- S9 candidate: "Trying to boot 'b10b3'", kernel 5afd371e (24754184 B, image_size 0x1830000, ends DDR+0x1830000), DTB e47762d1 @DDR+0x20A9000,
|
||
ramdisk ac518e27 @DDR+0x22A9000 — no overlap; cmdline = B9C.
|
||
- F1 (no conf) / F3 (no initrd) / F10 (zeroed cache) → "Reverting to android boot" (emmc1 fallback).
|
||
|
||
## RAM pretest (class A, run cand1; `logs/b10/b10b3/cand1*`, `pre-cand-classA-*`)
|
||
RAM image `b10/b10b3/out/aurora-b10b3.img` b7dc34e9 = same kernel/DTB/initramfs/cmdline as the candidate. Class A proven (RTC 3 s, SBL charger
|
||
defaults, dump diff ADC/BMS/RTC only). RESET-held boot (stage-3 again, RTC 5 s — harness only).
|
||
- probe: `safety timer 512 min (TCHG_MAX 0x7f), enabled`; `supervisor v3: charge 4200000, hold 4050000, full-min 4150000, cv 60 min, IBAT_MAX code 4`;
|
||
`INIT -> CHARGING (probe, usb present)` at 4.072 V.
|
||
- registers: VDD_MAX 08 (4.20 V), IBAT_MAX 04 (450 mA), CHG_CTRL a0, TCHG 80/7f, BOOT_DONE 80, CHG_FAILED 00, CHG_STATUS 05; no latch; 0 ALERT.
|
||
- VADC: VBAT 4.159 V (under charge), USBIN 4.884 V; PMIC 45.7 °C (VADC) / 44.6 °C (pm8916-thermal), CPU ≈ 44–46 °C.
|
||
- LTE START OK 73.7 s, ping 4/4; Wi-Fi AP enabled 77.3 s, MSS + WCNSS running; NCM ok; DISPLAY READY 7.8 s (fbcon bound, backlight on, 0 errors);
|
||
eMMC writes 0. 60-min CV/HOLD not repeated (state machine validated in B10B3-RESULT.md).
|
||
Board left CHARGING on the RAM pretest image; nothing written.
|
||
|
||
## Blocker before any persistent GO
|
||
**FAULT currently has no verified physical charge-stop actuator; the safety timer also does not stop charging** (Test D4: expiry only ends the
|
||
fast-charge state, current continues, CHG_FAILED not set; CHG_EN = 0 does not stop the LBC). FAULT in v3 is logical only.
|
||
|
||
## Proposed next test (needs a separate GO; RAM only, not executed)
|
||
**B10B-4 — emergency actuator search.** Test-only kernel hook (debugfs, RAM image only) or manual regmap writes per approved list, each step:
|
||
class-A start, CHARGING at ≈ 0.4 A, apply one actuator, observe USB current (meter), CHG_STATUS, RT, path, VBAT, PMIC 30–60 s, then revert:
|
||
1. USB_SUSP (0x1347 bit0 = 1): does input current go to ≈ 0, does the board drop to battery, does it survive; release → recovery.
|
||
2. IBAT_MAX minimum (0x1044 = 00, 90 mA): residual current with the board load.
|
||
3. VDD_MAX minimum (0x1040 = 00, 4.00 V) when VBAT > 4.00 V: does charging stop (HOLD phase-1 already suggests yes).
|
||
4. Combination (2 + 3) and, if 1 works, 1 alone as the FAULT action.
|
||
Pass criterion for an actuator: battery current stops within seconds, no 00/01 latch, board keeps running (from USB or battery), reversible.
|