uzbek-plus/logs/b11/B11-LED-AUDIT.md

82 lines
7.3 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# B11 — LED / button audit (read-only), 2026-10-04
Board: JZ08AU Aurora (MSM8916 + PM8916). Live system: eMMC cache B10B-5 c3732515, kernel 7.2.7-aurora-b10b5, uptime ≈ 53 min ("HB cold2").
Nothing was written to eMMC, PMIC, or TLMM during the audit. All reads used debugfs (`/sys/kernel/debug/gpio`, `pinctrl/*/pinmux-pins`,
`regmap/0-00|0-01/registers`).
Raw data:
- `logs/b11/live/live-debugfs-1.txt`: TLMM 122 pins (dir, level, func, drive, pull), PM8916 MPP/GPIO, pinmux owners, /proc/interrupts
- `logs/b11/live/live-pmic-ro-2.txt`: PM8916 PON 0x0800–0x084f; MPP1–4 and GPIO1–4 (sid0); LPG 0xbc00 and VIB 0xc000 (sid1); inputs, backlight, leds
- script: `b11/audit/b11-ro.sh` (read-only)
## 1. Sources checked
| Source | What was looked for | Result |
|---|---|---|
| Stock DT `dt/dtb_01.dts` (active 512MB DT) | `gpio-leds`, `qcom,leds-qpnp`, MPP/GPIO/PWM/LPG, pinctrl | `gpio-leds` node holds **only the SIM mux** (`sim1/2/3_switch_gpio`, `sim_hotdet_gpio` = GPIO22/23/1/20). These are not LEDs. `qcom,leds-qpnp` has only `lcd-bl` on MPP4. MPP1–3 and PM GPIO1–4 are `disabled`. `pwm@bc00` is declared with no consumer. `vibrator@c000` is `okay`, set to 3.1 V. |
| Stock Android runtime `android/leds.txt`, `android/gpio.txt` | `/sys/class/leds` | `lcd-backlight` (MDSS virtual), `lcd-bl` (MPP4), `mmc0::` (trigger only), 4× SIM switch. **No indicator LED.** |
| Stock /system (`partitions/system.bin`, ext4, read via debugfs) | `/sys/class/leds/*`, `/sys/class/gpio/*` users | `lights.msm8916.so` and `mmi_led.so` are generic Qualcomm (red/green/blue). `usbhub` (gpio56) and `init.qcom.post_boot.sh` (gpio253–259) are generic code for other targets. Nothing is Aurora-specific. |
| Stock init.rc | LED chown list | Generic red/green/blue/yellow(+_sec, 2, 2_sec) chowns. No matching DT nodes exist. |
| Stock MPSS (`firmware-fat/image/modem.b21`) | LED strings | `led_red/green/blue` appear only in the generic TLMM pin-name table (next to `lcd_rst_n`, `cam_flash_torch_en`, `kpsns0`…, MTP names). They give no pin mapping and no proof that the modem drives an LED. |
| Stock LK / lk1st-b9l | LED code | Only MPP4 (backlight) and the SPI panel are used. |
| Current production DTS (b9b → b10b3 chain) | LED / keys | MPP4 → `gpio-backlight` (`/sys/class/backlight/backlight`). No gpio-leds and no gpio-keys. Only `pm8941_pwrkey` is an input. |
| Live TLMM / PMIC state | outputs, current sinks | See §2 and §3 |
| JZ02 (reference only) | RGB GPIO6/7/8 | Different PCB. Stock Aurora DT dropped these LEDs, and Aurora GPIO6/7/8 are unclaimed inputs with pull-down. This is not evidence of an LED on Aurora. |
## 2. TLMM (MSM8916 GPIO 0–121) — live state and classification
| GPIO | live | consumer / function | class |
|---|---|---|---|
| 0, 2, 3 | in, pull-down | unclaimed (BLSP1 SPI/UART1 pins) | UNKNOWN |
| 1, 20, 22, 23 | out, 1 / 0 / 0 / 0 | SIM mux (MPSS pinctrl, stock "gpio-leds" hack) | **DO NOT TOUCH** (modem/SIM) |
| 4, 5 | func2 | BLSP1 UART2 console | **DO NOT TOUCH** (UART) |
| 6–11, 16–19, 21, 24–36, 38, 39, 45–56, 60–62, 69–98, 108–112, 114, 115, 117, 119–121 | in, pull-down, func0 | unclaimed; no stock consumer (stock DT references only TPIU debug, MTP cameras, codec, usb-id) | UNKNOWN |
| 12–15 | func1 | BLSP1 QUP4 SPI → ST7735S | **DO NOT TOUCH** (display SPI) |
| 37 | in, low, pull-down | `key_f2` (stock gpio-keys, active-high) | button: read-only |
| 40–44 | func1 | WCNSS 5-wire (Pronto/Iris) | **DO NOT TOUCH** (WCNSS) |
| 57–60 (57–59 out, func1) | UIM1 | SIM interface | **DO NOT TOUCH** (modem/SIM) |
| 63–68 | in | codec PDM (PM8916 audio) | **DO NOT TOUCH** |
| 99–102 | in, no pull | GSM TX phase (RF) | **DO NOT TOUCH** (modem RF) |
| 103, 104 | in, pull-down | SSBI WTR0 | **DO NOT TOUCH** (RF) |
| 105 | **out low**, func0, no pull | not claimed by Linux, driven by boot/MPSS firmware (ssbi_wtr1 pad as GPIO) | **DO NOT TOUCH** (modem-owned RF/GRFC, consumer unknown) |
| 106 | in, **pull-up**, high | ssbi_wtr1 pad; pull set by firmware | **DO NOT TOUCH** (RF/unknown) |
| 107 | in, high, pull-up | `key_f3` (stock gpio-keys, active-low) | button: read-only |
| 110 | in | usb-id pin (stock) | **DO NOT TOUCH** (USB) |
| 113 | in | cdc-us-euro (audio switch) | **DO NOT TOUCH** |
| 116, 118 | out high, 8 mA | panel D/C, RESET (spi0.0) | **DO NOT TOUCH** (display) |
| SDC1 / SDC2 / QDSD pads | — | eMMC / SD | **DO NOT TOUCH** |
**No TLMM pin has evidence of an indicator LED.** No DT node, stock userspace, or live output state points to one.
Every unclaimed pin is a firmware-default input with pull-down, so no LED on those pins is lit now.
Because the topology is unknown, none of them may be driven (B11 rule).
## 3. PM8916 peripherals
| Block | live registers | meaning | class |
|---|---|---|---|
| **MPP4** (0xa300) | MODE 0x61, VIN 0, EN 0x80, SINK_CTL 0x07 | current sink 40 mA, ON = LCD backlight (B9A/B9B, stock `lcd-bl`) | **SAFE** (proven in B9B/B9C/B9L) |
| MPP3 (0xa200) | MODE 0x60 (sink, source = 0 → off), EN 0x80, SINK 0x00 (5 mA) | current sink configured but off. Same value on every boot since B9C baselines. No consumer in any stock layer. | UNKNOWN (likely LED-type driver, but the load is unproven) |
| MPP2 (0xa100) | MODE 0x11 (digital output, **HIGH**), VIN 1, EN 0x80 | set by boot firmware; consumer unknown (could be an enable or a reference) | **DO NOT TOUCH** |
| MPP1 (0xa000) | MODE 0x51 (analog output), VIN 2, EN 0x80 | analog/reference output set by firmware | **DO NOT TOUCH** |
| PM GPIO1–4 (0xc000–0xc300) | input, pull-down 10 µA, EN 0x80 | stock `disabled`; consumer unknown | UNKNOWN |
| LPG/PWM (sid1 0xbc00) | EN 0x00 (off) | no consumer in stock or current DT. **PWM routing to MPP4 is unproven.** | no PWM-capable LED confirmed |
| VIB_DRV (sid1 0xc000) | EN 0x00, VSET 0x16 | stock `vibrator` 3.1 V; the board has no known motor; the load is unknown | UNKNOWN |
| LBC charger | — | no charge-LED output (checked against downstream qpnp-linear-charger) | n/a |
## 4. Buttons (read-only)
| Button | line | idle level | notes |
|---|---|---|---|
| POWER | PM8916 KPDPWR (PON RT 0x0810 bit0); Linux `pm8941_pwrkey` → event0 | released | S2 reset enabled (0x0843 = 0x80, warm reset after long hold). **Short presses only.** |
| RESET | PM8916 RESIN (PON RT bit1) | released | no Linux input. Holding it too long → PMIC stage-3 reset (B10 note). KPDPWR+RESIN = hard reset (0x084b = 0x80). **Short presses only, never both at once.** |
| key_f2 | TLMM GPIO37, active-high | low (pull-down) | not bound in current DT; poll via debugfs |
| key_f3 | TLMM GPIO107, active-low | high (pull-up) | not bound in current DT; poll via debugfs |
## 5. Conclusion of the audit
- SAFE LED lines: **1**, PM8916 MPP4 (LCD backlight current sink). It is already controllable in the live production system through
`/sys/class/backlight/backlight` (gpio-backlight, 0/1). No PWM.
- UNKNOWN: MPP3 sink, PM GPIO1–4, VIB_DRV, and all unclaimed TLMM pins. None is switched.
- DO NOT TOUCH: MPP1, MPP2, GPIO1/20/22/23, 4/5, 12–15, 40–44, 57–60, 63–68, 99–106, 110, 113, 116, 118, SDC pads.
- The physical indicator LEDs and empty footprints the operator sees cannot be tied to any software-controlled line from the sources available.
They are likely hard-wired (power/VBUS/charge), backlight, or DNP options for another SKU. Proving that needs continuity checks on the board.