- LBC supervisor v1..v4 (linux/patches/b10b3-lbc-supervisor-v3.patch + b10/b10b3/lbc-v3-to-v4-fault-clamp.diff): CHARGING 4.20 V/450 mA -> HOLD 4.05 V after 60 min CV -> battery -> new cycle on USB insert; FAULT = VDD_MAX 4.00 V clamp - RAM tests C/B/D/D2/D3/D4 (safety timer only ends fast charge), B10B-4 actuator audit (VDD_MAX works, USB_SUSP does not), B10B-5 FAULT clamp regression, production run, warm reboot via PON reboot reason - cache = B10B-5 c3732515 (HW EDL write, readback + full partition verify), class-A persistent validation - test-only hooks/images are not part of the production kernel; images with the AP PSK are not published
7.6 KiB
B10B3-TESTB-RESULT — safety timer in HOLD (v3 supervisor, RAM only)
Date: 2026-10-03/04. Verdict: PASS for the production question (a long HOLD is not ended by the safety timer: no CHG_FAILED, USB path
keeps carrying the board ≈ 3.5× the timer length after the 8-min mark) — with the limitation below (the timer itself was not seen to fire).
Image b10/b10b3/out-b/aurora-b10b3b.img 9e66466d (same v3 kernel/initramfs/cmdline as Test C, only the DTB differs; driver code unchanged).
aboot/cache untouched, eMMC writes = 0, no manual PMIC writes.
Profile (variant A, operator decision; DESIGN §8.6)
Battery ≈ 4.00 V after Test C → with 4.10 V the 8-min timer would have expired in CC (≈22 min of CC in Test C from that level). Test-only DTB
linux/dts/msm8916-jz08-aurora-b10b3b.dts: charge 4.05 V (VDD_MAX 0x02), HOLD 4.00 V (0x00), full-min 4.03 V, CV 2 min,
timer 8 min (TCHG_MAX 0x01), IBAT_MAX 450 mA (0x04). Values verified numerically in the compiled DTB (4050000 / 4030000 / 4000000 / 2 / 8)
and in the DTB inside Image.gz-dtb (byte-identical). Build b10/b10b3/build-b10b3b.sh, boot b10b3b-boot.sh, monitor starter b10b3b-mon-start.sh
(pushes the unchanged b10b3-mon.sh md5 1d2621aa…, 10 s, EVDD 02/00, VMAX 4.15 V, PMIC 60 °C alert), guarded load b10b3b-load.sh.
Bench preparation
Class-A reset (USB out, battery out ≥ 90 s, battery, USB, no RESET) → B9C, RTC 3 s; read-only checks
(pre-testB-classA-check.txt, full SID0 dump pre-testB-classA-dump.txt, pre-testB-vs-baseline-diff.txt): VDD_MAX/SAFE 08/08, IBAT_MAX 00,
IBAT_SAFE 0a, CHG_CTRL 90, CHG_FAILED 00, TCHG 80/1d, 0x105B 09, COMP_OVR1 00, BOOT_DONE 00, charging 05/02 — byte-identical to the pre-Test-C
check; vs baseline-b9c-classA.txt only status/ADC/BMS/RTC registers differ (31), no configuration register.
Pre-boot operator: DMM VBAT 4.113 V, USB meter 0.424 A (B9C, SBL charge 90 mA + board).
Warm reboot from B9C (reboot over telnet) with RESET held → lk1st fastboot after 9 s → fastboot boot Test B (17:35:04 UTC).
Timeline (t = 0 at the driver probe / timer programming, dmesg 0.929 s safety timer 8 min (TCHG_MAX 0x01), enabled)
| t | event | VADC VBAT | USB meter | registers |
|---|---|---|---|---|
| 0 s | INIT → CHARGING (probe, usb present) | 3.973 V (probe) | — | VDD_MAX 02, IBAT_MAX 04, TCHG 80/01, CHG_CTRL a0, BOOT_DONE 80 |
| ≈15–30 s | CC very short; first monitor sample t=15 s already CHG_STATUS 03 | 4.047–4.058 V | — | path 01 |
| ≈30 s | CV criterion starts (cv_s 25 at t=55) | 4.045–4.058 V | — | 03 |
| 153.8 s | CHARGING → HOLD (dmesg 154.74, once, n_hold 1) | 4.053 → 4.043 V | — | only VDD_MAX 02 → 00 |
| 154–480 s | HOLD phase 1 | 4.043 → 4.033 V | — | 03, a0, failed 00 |
| 480 s | 8-min timer mark: nothing happens | 4.034 V | — | CHG_FAILED 00, TCHG 80/01, path 01, CHG_STATUS 03, state HOLD |
| 480–960 s | HOLD phase 1, 2× timer | 4.033 → 4.022 V | — | unchanged |
| ≈1170 s | operator | 4.017 V (DMM 4.014) | 0.000 A, once 0.01 A for ~1 s | unchanged |
| 1334–1635 s | 2× yes load (operator request), guard stop by 300-s timeout |
3.989–4.001 V (held at the shelf) | 0.08–0.10 A | unchanged; USBIN 5.016 → 4.986 V |
| ≈1700 s | idle after load | DMM 4.002 V | 0.017 A | unchanged |
| 1787 s | end dump | 4.007 V | — | HOLD, fault none, CHG_FAILED 00, n_latch 0 |
Monitor: 174 samples (10 s), every sample CHG_FAILED 00, TCHG 80/01, CHG_CTRL a0, IBAT_MAX 04, CHG_STATUS/CHGR/BAT/USB RT/path 03/01/03/03/01; VDD_MAX 02 (14 samples, CHARGING) then 00 (160 samples, HOLD). 0 ALERT lines, no FAULT, no 00+01 latch.
Checks
- Timer programmed as designed: TCHG_MAX 0x01 (8 min), TCHG_MAX_EN 80, readback OK at probe: PASS.
- CHARGING → HOLD before the timer mark: PASS (t = 153.8 s, 326 s of HOLD before t = 480 s).
- CHG_FAILED in CV/HOLD: never set — up to t = 1787 s (≈ 3.7× the timer, ≈ 27 min of HOLD).
- USB path after the timer mark: alive. Decisive at the shelf: with a 2×CPU load at t ≈ 1334–1635 s (≈ 14–19 min after the 8-min mark) the charger held VBAT at 4.000 V (3.989–4.001) and USB supplied 0.08–0.10 A (USBIN sagged 30 mV). A silent timer cut would have shown 0 A and VBAT falling below 4.00 V. No drop to battery.
- The 0.000 A at t ≈ 1170 s is HOLD phase 1 (VBAT above the 4.00 V shelf, VPH = VBAT; same as Test C phase 1 ≈0.01 A) — not a timer effect.
- Only the planned registers changed — full SID0 diff end vs class-A check (
b1-vs-classA-diff.txt, 45 lines): CHGR/BAT_IF/USB/MISC config exactly the Test C set with the Test B timer value: 0x1040 08→00 (HOLD), 0x1044 00→04, 0x1045 0a→04, 0x1049 90→a0, 0x1061 1d→01, 0x1642 00→80 (+0x1643 0b); status 0x1009 05→03, 0x1308 02→01. Unchanged: 0x1060 80 (timer enabled), 0x104A 00, 0x105B 09 (termination), 0x10EE 00 (COMP_OVR1), 0x1041 08. Outside the charger: 0x0608/0x060E and 0x2411–0x2446 identical to the Test C diff (kernel drivers of the b10b3 image), ADC 0x31xx–0x33xx, BMS 0x40xx, RTC 0x60xx (measurements/counters), and PON 0x080D 00→80 (see observation 2). - LTE START OK 73.6 s, ping 4/4 via wwan0; Wi-Fi AP aurora-b8f enabled 77.3 s, Pronto running; NCM ok; eMMC writes 0 (all dumps, snapshot).
- PMIC temperature max 47.5 °C (during the 2×CPU load; limit 60 °C, guard 52 °C not reached). CPU 56 °C.
Limitation (not hidden)
The test shows that CHG_FAILED is not set in CV/HOLD within ≈ 27 min with an 8-min timer. Because CC lasted only ≈ 15–30 s, it does not show that the timer fires at all (e.g. counts only in CC/fast-charge, or does not fire in this configuration). There is no positive control: the safety timer is not a verified protection. A positive control (timer expiry during a long CC, observe CHG_FAILED and the path) is a separate test and needs its own GO.
Observations
- HOLD for this profile was already in phase 1 at 4.05 → 4.00 V: ≈ −1.4 mV/min like Test C; the shelf was reached by load after ≈ 20 min.
- Warm reboot with RESET held gave a PMIC stage-3 reset this time: PON POFF_REASON2 0x080D = 0x80 (b7 STAGE3, decode
b6p/test/pon-decode.txt) in the Test B boot, 00 in the B9C boot before; and the RTC read only 6 s at boot ≈ 37 min after the class A (Test C: 192 s). Likely the RESIN hold exceeded the S3 timer (operator held RESET ≈ 5 s + reboot + 9 s). Consequence for Test B: none (the PMIC came up at defaults, the driver programmed everything at probe, t = 0 is the probe). Hypothesis — not separately tested. - Monitor field
load=stays 0 during the load (busyboxpgrep -c/pspattern does not match); the load window is taken fromb1-load.txt. Cosmetic, monitor only. - Known cosmetic: debugfs
cv_skeeps counting in HOLD (1757 at the end).
Files (logs/b10/b10b3/, copies on 480s)
pre-testB-classA-check.txt, pre-testB-classA-dump.txt, pre-testB-vs-baseline-diff.txt (class A proof); b1/ (host-actions, snapshot,
dmesg.full, dmesg-final, dmesg-end, uart.log); b1-actions.txt (operator readings, actions); b1-boot.out, b1-monstart.out;
b1-mon.txt (pull), b1-mon-board-copy.txt, b1-mon-board-final.txt (complete board log, 174 samples + MON-END); b1-load.txt;
b1-final-dump.txt / b1-final-state.txt (t ≈ 1003 s), b1-end-dump.txt / b1-end-state.txt (t ≈ 1786 s); b1-vs-classA-diff.txt.
UART logs/uart/b10b3b-ram1-20261003-203339.log (480s).
State after the test
Board left in HOLD on the Test B RAM image (VDD_MAX 4.00 V, TCHG_MAX 0x01 enabled, USB carrying the board), monitor/pull/load stopped. Test registers survive warm reboots → class-A reset required before the next test / before relying on B9C SBL defaults.