uzbek-plus/logs/b10/b10b3/B10B3-TESTB-RESULT.md
q 58dcb3d121 B10: battery charging — PM8916 LBC supervisor v4 (CHARGE/HOLD, FAULT safe clamp to 4.00 V) and persistent B10B-5 cache
- LBC supervisor v1..v4 (linux/patches/b10b3-lbc-supervisor-v3.patch + b10/b10b3/lbc-v3-to-v4-fault-clamp.diff):
  CHARGING 4.20 V/450 mA -> HOLD 4.05 V after 60 min CV -> battery -> new cycle on USB insert; FAULT = VDD_MAX 4.00 V clamp
- RAM tests C/B/D/D2/D3/D4 (safety timer only ends fast charge), B10B-4 actuator audit (VDD_MAX works, USB_SUSP does not),
  B10B-5 FAULT clamp regression, production run, warm reboot via PON reboot reason
- cache = B10B-5 c3732515 (HW EDL write, readback + full partition verify), class-A persistent validation
- test-only hooks/images are not part of the production kernel; images with the AP PSK are not published
2026-10-04 19:00:27 +03:00

83 lines
7.6 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# B10B3-TESTB-RESULT — safety timer in HOLD (v3 supervisor, RAM only)
Date: 2026-10-03/04. **Verdict: PASS for the production question** (a long HOLD is not ended by the safety timer: no CHG_FAILED, USB path
keeps carrying the board ≈ 3.5× the timer length after the 8-min mark) — **with the limitation below** (the timer itself was not seen to fire).
Image `b10/b10b3/out-b/aurora-b10b3b.img` 9e66466d (same v3 kernel/initramfs/cmdline as Test C, only the DTB differs; driver code unchanged).
aboot/cache untouched, eMMC writes = 0, no manual PMIC writes.
## Profile (variant A, operator decision; DESIGN §8.6)
Battery ≈ 4.00 V after Test C → with 4.10 V the 8-min timer would have expired in CC (≈22 min of CC in Test C from that level). Test-only DTB
`linux/dts/msm8916-jz08-aurora-b10b3b.dts`: charge **4.05 V** (VDD_MAX 0x02), HOLD **4.00 V** (0x00), full-min **4.03 V**, CV **2 min**,
timer **8 min** (TCHG_MAX 0x01), IBAT_MAX 450 mA (0x04). Values verified numerically in the compiled DTB (4050000 / 4030000 / 4000000 / 2 / 8)
and in the DTB inside `Image.gz-dtb` (byte-identical). Build `b10/b10b3/build-b10b3b.sh`, boot `b10b3b-boot.sh`, monitor starter `b10b3b-mon-start.sh`
(pushes the unchanged `b10b3-mon.sh` md5 1d2621aa…, 10 s, EVDD 02/00, VMAX 4.15 V, PMIC 60 °C alert), guarded load `b10b3b-load.sh`.
## Bench preparation
Class-A reset (USB out, battery out ≥ 90 s, battery, USB, no RESET) → B9C, RTC 3 s; read-only checks
(`pre-testB-classA-check.txt`, full SID0 dump `pre-testB-classA-dump.txt`, `pre-testB-vs-baseline-diff.txt`): VDD_MAX/SAFE 08/08, IBAT_MAX 00,
IBAT_SAFE 0a, CHG_CTRL 90, CHG_FAILED 00, TCHG 80/1d, 0x105B 09, COMP_OVR1 00, BOOT_DONE 00, charging 05/02 — byte-identical to the pre-Test-C
check; vs `baseline-b9c-classA.txt` only status/ADC/BMS/RTC registers differ (31), no configuration register.
Pre-boot operator: DMM VBAT 4.113 V, USB meter 0.424 A (B9C, SBL charge 90 mA + board).
Warm reboot from B9C (`reboot` over telnet) with RESET held → lk1st fastboot after 9 s → `fastboot boot` Test B (17:35:04 UTC).
## Timeline (t = 0 at the driver probe / timer programming, dmesg 0.929 s `safety timer 8 min (TCHG_MAX 0x01), enabled`)
| t | event | VADC VBAT | USB meter | registers |
|---|---|---|---|---|
| 0 s | INIT → CHARGING (probe, usb present) | 3.973 V (probe) | — | VDD_MAX 02, IBAT_MAX 04, TCHG 80/01, CHG_CTRL a0, BOOT_DONE 80 |
| ≈15–30 s | CC very short; first monitor sample t=15 s already CHG_STATUS 03 | 4.047–4.058 V | — | path 01 |
| ≈30 s | CV criterion starts (cv_s 25 at t=55) | 4.045–4.058 V | — | 03 |
| **153.8 s** | **CHARGING → HOLD** (dmesg 154.74, once, n_hold 1) | 4.053 → 4.043 V | — | **only VDD_MAX 02 → 00** |
| 154–480 s | HOLD phase 1 | 4.043 → 4.033 V | — | 03, a0, failed 00 |
| **480 s** | **8-min timer mark: nothing happens** | 4.034 V | — | CHG_FAILED 00, TCHG 80/01, path 01, CHG_STATUS 03, state HOLD |
| 480–960 s | HOLD phase 1, 2× timer | 4.033 → 4.022 V | — | unchanged |
| ≈1170 s | operator | 4.017 V (DMM 4.014) | **0.000 A**, once 0.01 A for ~1 s | unchanged |
| 1334–1635 s | 2× `yes` load (operator request), guard stop by 300-s timeout | **3.989–4.001 V** (held at the shelf) | **0.08–0.10 A** | unchanged; USBIN 5.016 → 4.986 V |
| ≈1700 s | idle after load | DMM 4.002 V | 0.017 A | unchanged |
| 1787 s | end dump | 4.007 V | — | HOLD, fault none, CHG_FAILED 00, n_latch 0 |
Monitor: 174 samples (10 s), every sample CHG_FAILED 00, TCHG 80/01, CHG_CTRL a0, IBAT_MAX 04, CHG_STATUS/CHGR/BAT/USB RT/path
03/01/03/03/01; VDD_MAX 02 (14 samples, CHARGING) then 00 (160 samples, HOLD). 0 ALERT lines, no FAULT, no 00+01 latch.
## Checks
- Timer programmed as designed: TCHG_MAX 0x01 (8 min), TCHG_MAX_EN 80, readback OK at probe: PASS.
- CHARGING → HOLD before the timer mark: PASS (t = 153.8 s, 326 s of HOLD before t = 480 s).
- **CHG_FAILED in CV/HOLD: never set** — up to t = 1787 s (≈ 3.7× the timer, ≈ 27 min of HOLD).
- **USB path after the timer mark: alive.** Decisive at the shelf: with a 2×CPU load at t ≈ 1334–1635 s (≈ 14–19 min after the 8-min mark) the
charger held VBAT at 4.000 V (3.989–4.001) and USB supplied 0.08–0.10 A (USBIN sagged 30 mV). A silent timer cut would have shown 0 A and VBAT
falling below 4.00 V. No drop to battery.
- The 0.000 A at t ≈ 1170 s is HOLD phase 1 (VBAT above the 4.00 V shelf, VPH = VBAT; same as Test C phase 1 ≈0.01 A) — not a timer effect.
- Only the planned registers changed — full SID0 diff end vs class-A check (`b1-vs-classA-diff.txt`, 45 lines):
CHGR/BAT_IF/USB/MISC config exactly the Test C set with the Test B timer value:
0x1040 08→00 (HOLD), 0x1044 00→04, 0x1045 0a→04, 0x1049 90→a0, **0x1061 1d→01**, 0x1642 00→80 (+0x1643 0b); status 0x1009 05→03, 0x1308 02→01.
Unchanged: 0x1060 80 (timer enabled), 0x104A 00, 0x105B 09 (termination), 0x10EE 00 (COMP_OVR1), 0x1041 08.
Outside the charger: 0x0608/0x060E and 0x2411–0x2446 identical to the Test C diff (kernel drivers of the b10b3 image), ADC 0x31xx–0x33xx,
BMS 0x40xx, RTC 0x60xx (measurements/counters), and PON 0x080D 00→80 (see observation 2).
- LTE START OK 73.6 s, ping 4/4 via wwan0; Wi-Fi AP aurora-b8f enabled 77.3 s, Pronto running; NCM ok; eMMC writes 0 (all dumps, snapshot).
- PMIC temperature max 47.5 °C (during the 2×CPU load; limit 60 °C, guard 52 °C not reached). CPU 56 °C.
## Limitation (not hidden)
The test shows that **CHG_FAILED is not set in CV/HOLD** within ≈ 27 min with an 8-min timer. Because CC lasted only ≈ 15–30 s, it does **not**
show that the timer fires at all (e.g. counts only in CC/fast-charge, or does not fire in this configuration). There is no positive control:
the safety timer is **not** a verified protection. A positive control (timer expiry during a long CC, observe CHG_FAILED and the path) is a
separate test and needs its own GO.
## Observations
1. HOLD for this profile was already in phase 1 at 4.05 → 4.00 V: ≈ −1.4 mV/min like Test C; the shelf was reached by load after ≈ 20 min.
2. **Warm reboot with RESET held gave a PMIC stage-3 reset this time:** PON POFF_REASON2 0x080D = 0x80 (b7 STAGE3, decode `b6p/test/pon-decode.txt`)
in the Test B boot, 00 in the B9C boot before; and the RTC read only 6 s at boot ≈ 37 min after the class A (Test C: 192 s). Likely the RESIN hold
exceeded the S3 timer (operator held RESET ≈ 5 s + reboot + 9 s). Consequence for Test B: none (the PMIC came up at defaults, the driver programmed
everything at probe, t = 0 is the probe). Hypothesis — not separately tested.
3. Monitor field `load=` stays 0 during the load (busybox `pgrep -c`/`ps` pattern does not match); the load window is taken from `b1-load.txt`.
Cosmetic, monitor only.
4. Known cosmetic: debugfs `cv_s` keeps counting in HOLD (1757 at the end).
## Files (logs/b10/b10b3/, copies on 480s)
`pre-testB-classA-check.txt`, `pre-testB-classA-dump.txt`, `pre-testB-vs-baseline-diff.txt` (class A proof); `b1/` (host-actions, snapshot,
dmesg.full, dmesg-final, dmesg-end, uart.log); `b1-actions.txt` (operator readings, actions); `b1-boot.out`, `b1-monstart.out`;
`b1-mon.txt` (pull), `b1-mon-board-copy.txt`, `b1-mon-board-final.txt` (complete board log, 174 samples + MON-END); `b1-load.txt`;
`b1-final-dump.txt` / `b1-final-state.txt` (t ≈ 1003 s), `b1-end-dump.txt` / `b1-end-state.txt` (t ≈ 1786 s); `b1-vs-classA-diff.txt`.
UART `logs/uart/b10b3b-ram1-20261003-203339.log` (480s).
## State after the test
Board left in HOLD on the Test B RAM image (VDD_MAX 4.00 V, TCHG_MAX 0x01 enabled, USB carrying the board), monitor/pull/load stopped.
Test registers survive warm reboots → class-A reset required before the next test / before relying on B9C SBL defaults.