uzbek-plus/logs/b10/b10b3/B10B3-TESTB-RESULT.md
q 58dcb3d121 B10: battery charging — PM8916 LBC supervisor v4 (CHARGE/HOLD, FAULT safe clamp to 4.00 V) and persistent B10B-5 cache
- LBC supervisor v1..v4 (linux/patches/b10b3-lbc-supervisor-v3.patch + b10/b10b3/lbc-v3-to-v4-fault-clamp.diff):
  CHARGING 4.20 V/450 mA -> HOLD 4.05 V after 60 min CV -> battery -> new cycle on USB insert; FAULT = VDD_MAX 4.00 V clamp
- RAM tests C/B/D/D2/D3/D4 (safety timer only ends fast charge), B10B-4 actuator audit (VDD_MAX works, USB_SUSP does not),
  B10B-5 FAULT clamp regression, production run, warm reboot via PON reboot reason
- cache = B10B-5 c3732515 (HW EDL write, readback + full partition verify), class-A persistent validation
- test-only hooks/images are not part of the production kernel; images with the AP PSK are not published
2026-10-04 19:00:27 +03:00

7.6 KiB
Raw Blame History

B10B3-TESTB-RESULT — safety timer in HOLD (v3 supervisor, RAM only)

Date: 2026-10-03/04. Verdict: PASS for the production question (a long HOLD is not ended by the safety timer: no CHG_FAILED, USB path keeps carrying the board ≈ 3.5× the timer length after the 8-min mark) — with the limitation below (the timer itself was not seen to fire). Image b10/b10b3/out-b/aurora-b10b3b.img 9e66466d (same v3 kernel/initramfs/cmdline as Test C, only the DTB differs; driver code unchanged). aboot/cache untouched, eMMC writes = 0, no manual PMIC writes.

Profile (variant A, operator decision; DESIGN §8.6)

Battery ≈ 4.00 V after Test C → with 4.10 V the 8-min timer would have expired in CC (≈22 min of CC in Test C from that level). Test-only DTB linux/dts/msm8916-jz08-aurora-b10b3b.dts: charge 4.05 V (VDD_MAX 0x02), HOLD 4.00 V (0x00), full-min 4.03 V, CV 2 min, timer 8 min (TCHG_MAX 0x01), IBAT_MAX 450 mA (0x04). Values verified numerically in the compiled DTB (4050000 / 4030000 / 4000000 / 2 / 8) and in the DTB inside Image.gz-dtb (byte-identical). Build b10/b10b3/build-b10b3b.sh, boot b10b3b-boot.sh, monitor starter b10b3b-mon-start.sh (pushes the unchanged b10b3-mon.sh md5 1d2621aa…, 10 s, EVDD 02/00, VMAX 4.15 V, PMIC 60 °C alert), guarded load b10b3b-load.sh.

Bench preparation

Class-A reset (USB out, battery out ≥ 90 s, battery, USB, no RESET) → B9C, RTC 3 s; read-only checks (pre-testB-classA-check.txt, full SID0 dump pre-testB-classA-dump.txt, pre-testB-vs-baseline-diff.txt): VDD_MAX/SAFE 08/08, IBAT_MAX 00, IBAT_SAFE 0a, CHG_CTRL 90, CHG_FAILED 00, TCHG 80/1d, 0x105B 09, COMP_OVR1 00, BOOT_DONE 00, charging 05/02 — byte-identical to the pre-Test-C check; vs baseline-b9c-classA.txt only status/ADC/BMS/RTC registers differ (31), no configuration register. Pre-boot operator: DMM VBAT 4.113 V, USB meter 0.424 A (B9C, SBL charge 90 mA + board). Warm reboot from B9C (reboot over telnet) with RESET held → lk1st fastboot after 9 s → fastboot boot Test B (17:35:04 UTC).

Timeline (t = 0 at the driver probe / timer programming, dmesg 0.929 s safety timer 8 min (TCHG_MAX 0x01), enabled)

t event VADC VBAT USB meter registers
0 s INIT → CHARGING (probe, usb present) 3.973 V (probe) — VDD_MAX 02, IBAT_MAX 04, TCHG 80/01, CHG_CTRL a0, BOOT_DONE 80
≈15–30 s CC very short; first monitor sample t=15 s already CHG_STATUS 03 4.047–4.058 V — path 01
≈30 s CV criterion starts (cv_s 25 at t=55) 4.045–4.058 V — 03
153.8 s CHARGING → HOLD (dmesg 154.74, once, n_hold 1) 4.053 → 4.043 V — only VDD_MAX 02 → 00
154–480 s HOLD phase 1 4.043 → 4.033 V — 03, a0, failed 00
480 s 8-min timer mark: nothing happens 4.034 V — CHG_FAILED 00, TCHG 80/01, path 01, CHG_STATUS 03, state HOLD
480–960 s HOLD phase 1, 2× timer 4.033 → 4.022 V — unchanged
≈1170 s operator 4.017 V (DMM 4.014) 0.000 A, once 0.01 A for ~1 s unchanged
1334–1635 s 2× yes load (operator request), guard stop by 300-s timeout 3.989–4.001 V (held at the shelf) 0.08–0.10 A unchanged; USBIN 5.016 → 4.986 V
≈1700 s idle after load DMM 4.002 V 0.017 A unchanged
1787 s end dump 4.007 V — HOLD, fault none, CHG_FAILED 00, n_latch 0

Monitor: 174 samples (10 s), every sample CHG_FAILED 00, TCHG 80/01, CHG_CTRL a0, IBAT_MAX 04, CHG_STATUS/CHGR/BAT/USB RT/path 03/01/03/03/01; VDD_MAX 02 (14 samples, CHARGING) then 00 (160 samples, HOLD). 0 ALERT lines, no FAULT, no 00+01 latch.

Checks

  • Timer programmed as designed: TCHG_MAX 0x01 (8 min), TCHG_MAX_EN 80, readback OK at probe: PASS.
  • CHARGING → HOLD before the timer mark: PASS (t = 153.8 s, 326 s of HOLD before t = 480 s).
  • CHG_FAILED in CV/HOLD: never set — up to t = 1787 s (≈ 3.7× the timer, ≈ 27 min of HOLD).
  • USB path after the timer mark: alive. Decisive at the shelf: with a 2×CPU load at t ≈ 1334–1635 s (≈ 14–19 min after the 8-min mark) the charger held VBAT at 4.000 V (3.989–4.001) and USB supplied 0.08–0.10 A (USBIN sagged 30 mV). A silent timer cut would have shown 0 A and VBAT falling below 4.00 V. No drop to battery.
  • The 0.000 A at t ≈ 1170 s is HOLD phase 1 (VBAT above the 4.00 V shelf, VPH = VBAT; same as Test C phase 1 ≈0.01 A) — not a timer effect.
  • Only the planned registers changed — full SID0 diff end vs class-A check (b1-vs-classA-diff.txt, 45 lines): CHGR/BAT_IF/USB/MISC config exactly the Test C set with the Test B timer value: 0x1040 08→00 (HOLD), 0x1044 00→04, 0x1045 0a→04, 0x1049 90→a0, 0x1061 1d→01, 0x1642 00→80 (+0x1643 0b); status 0x1009 05→03, 0x1308 02→01. Unchanged: 0x1060 80 (timer enabled), 0x104A 00, 0x105B 09 (termination), 0x10EE 00 (COMP_OVR1), 0x1041 08. Outside the charger: 0x0608/0x060E and 0x2411–0x2446 identical to the Test C diff (kernel drivers of the b10b3 image), ADC 0x31xx–0x33xx, BMS 0x40xx, RTC 0x60xx (measurements/counters), and PON 0x080D 00→80 (see observation 2).
  • LTE START OK 73.6 s, ping 4/4 via wwan0; Wi-Fi AP aurora-b8f enabled 77.3 s, Pronto running; NCM ok; eMMC writes 0 (all dumps, snapshot).
  • PMIC temperature max 47.5 °C (during the 2×CPU load; limit 60 °C, guard 52 °C not reached). CPU 56 °C.

Limitation (not hidden)

The test shows that CHG_FAILED is not set in CV/HOLD within ≈ 27 min with an 8-min timer. Because CC lasted only ≈ 15–30 s, it does not show that the timer fires at all (e.g. counts only in CC/fast-charge, or does not fire in this configuration). There is no positive control: the safety timer is not a verified protection. A positive control (timer expiry during a long CC, observe CHG_FAILED and the path) is a separate test and needs its own GO.

Observations

  1. HOLD for this profile was already in phase 1 at 4.05 → 4.00 V: ≈ −1.4 mV/min like Test C; the shelf was reached by load after ≈ 20 min.
  2. Warm reboot with RESET held gave a PMIC stage-3 reset this time: PON POFF_REASON2 0x080D = 0x80 (b7 STAGE3, decode b6p/test/pon-decode.txt) in the Test B boot, 00 in the B9C boot before; and the RTC read only 6 s at boot ≈ 37 min after the class A (Test C: 192 s). Likely the RESIN hold exceeded the S3 timer (operator held RESET ≈ 5 s + reboot + 9 s). Consequence for Test B: none (the PMIC came up at defaults, the driver programmed everything at probe, t = 0 is the probe). Hypothesis — not separately tested.
  3. Monitor field load= stays 0 during the load (busybox pgrep -c/ps pattern does not match); the load window is taken from b1-load.txt. Cosmetic, monitor only.
  4. Known cosmetic: debugfs cv_s keeps counting in HOLD (1757 at the end).

Files (logs/b10/b10b3/, copies on 480s)

pre-testB-classA-check.txt, pre-testB-classA-dump.txt, pre-testB-vs-baseline-diff.txt (class A proof); b1/ (host-actions, snapshot, dmesg.full, dmesg-final, dmesg-end, uart.log); b1-actions.txt (operator readings, actions); b1-boot.out, b1-monstart.out; b1-mon.txt (pull), b1-mon-board-copy.txt, b1-mon-board-final.txt (complete board log, 174 samples + MON-END); b1-load.txt; b1-final-dump.txt / b1-final-state.txt (t ≈ 1003 s), b1-end-dump.txt / b1-end-state.txt (t ≈ 1786 s); b1-vs-classA-diff.txt. UART logs/uart/b10b3b-ram1-20261003-203339.log (480s).

State after the test

Board left in HOLD on the Test B RAM image (VDD_MAX 4.00 V, TCHG_MAX 0x01 enabled, USB carrying the board), monitor/pull/load stopped. Test registers survive warm reboots → class-A reset required before the next test / before relying on B9C SBL defaults.