6.2 KiB
B11 — full LED audit and all-SAFE-LED run: RESULT (2026-10-04)
Verdict: PASS, with a scope note. The audit found exactly one LED line whose control is proven safe: PM8916 MPP4, the LCD backlight current sink. It was exercised in one automatic run with every stage and full monitoring. No other line was switched.
- Board: live production boot, eMMC cache B10B-5 c3732515, kernel 7.2.7-aurora-b10b5, "HB cold2".
- No eMMC/cache writes. No new image. No reboot. No raw PMIC/TLMM register writes. The run used only the Linux backlight class.
- PMIC MPP/GPIO/PON/LPG/VIB and TLMM key state are byte-identical before and after (
live-pmic-ro-2.txtvslive-pmic-ro-3-post.txt).
Why no separate RAM image was built
The only SAFE line is already a Linux class device in the production kernel (/sys/class/backlight/backlight, gpio-backlight on MPP4).
A RAM DTB that renames it to /sys/class/leds/aurora-led-* adds nothing to the test and would need a RESET-held fastboot boot.
The operator approved running on the live boot instead. The production kernel has LEDS_GPIO=y, so a DTB-only RAM image is possible later if new SAFE lines are proven.
Main table
| LED | physical position | GPIO/MPP/LPG | active level | initial state | all-ON result | chase result | brightness | verdict |
|---|---|---|---|---|---|---|---|---|
| L1 LCD backlight | behind the 1.44" ST7735S panel | PM8916 MPP4 current sink 40 mA (MODE 0x61 on / 0x60 off, SINK 0x07, EN 0x80) | sink ON = lit (gpio-backlight 1) | ON (bl=1, a340=61) | lit: operator-confirmed; a340 60→61 | 2/2 cycles: operator-confirmed | not tested (no PWM; LPG 0xbc00 not routed/proven) | PASS / SAFE |
| MPP3 | unknown | PM8916 MPP3, current sink, source = off | — | off (a240=60) | not switched | — | — | UNKNOWN |
| PM GPIO1–4 | unknown | PM8916 GPIO 1–4, input with pull-down | — | input | not switched | — | — | UNKNOWN |
| VIB_DRV | unknown (no motor known) | PM8916 sid1 0xc000 | — | off | not switched | — | — | UNKNOWN |
| TLMM unclaimed pins (list in audit §2) | — | input with pull-down, func0 | — | input | not switched | — | — | UNKNOWN |
Run r1 (logs/b11/live/b11-run-r1.log, script b11/run/b11-led-run.sh)
3415.29 PRECHECK lte=ok mpss=ok wcnss=ok wifi=ok ncm=ok disp=ok chg=Charging pmic=40504 kerr=0
3415.30 STAGE1 ALL-OFF a340=60 bl=0
3417.31 STAGE2 ALL-ON 4s a340=61 bl=1
3421.34 STAGE3 ALL-OFF a340=60
3423.36 STAGE4 CHASE c1 L1 ON / 3424.07 OFF / 3424.77 c2 ON / 3425.48 OFF
3426.19 STAGE5 SKIPPED no PWM-confirmed line
3426.21 STAGE6 RESTORE a340=61 a341=00 a346=80 a34c=07 bl=1 (= PRE)
3431.24 POSTCHECK lte=ok mpss=ok wcnss=ok wifi=ok ncm=ok disp=ok chg=Charging pmic=41033 kerr=0
3431.25 END OK
- A background monitor ran about every 2 s. It checked LTE ping via wwan0, MPSS, WCNSS, wlan0+hostapd, usb0 NCM, the panel driver bound plus fb0, charger status, PMIC temperature, and new kernel errors. Any FAIL would have restored the line and aborted the run. There were 0 FAILs and 0 new kernel error lines. The heartbeat continued.
- Afterwards: LTE ping 3/3, both remoteprocs running, wlan0 up, backlight 1 (
live/post-health.txt). - Side observation: the
pm8916-thermalreading drops by about 7 °C (40.5 → 33.2 °C) within 1 s of switching the 40 mA sink off, and comes back when it is switched on. That is too fast to be real heating, so it is a measurement artefact of the temperature-alarm/ADC path under MPP4 load. Account for it in thermal logic.
Buttons (read-only, b11/run/b11-btn-watch.sh, logs live/b11-btn-b1.log, b11-btn-b2.log)
No line was driven. The script polled debugfs gpio and PON RT 0x0810 every ~0.12 s.
The case has 3 buttons (operator): POWER, MENU, RESET.
| Button | line | observed | notes |
|---|---|---|---|
| POWER | PM8916 KPDPWR (PON RT bit0), Linux pm8941_pwrkey event0 |
bit0 pulses; pwrkey IRQ 2 → 36 | works. Nothing in userspace acts on KEY_POWER. S2 warm reset on long hold (0x0843 = 0x80). |
| MENU | probably also KPDPWR | the 2nd press series (≈3697 s, order POWER → MENU → RESET) is also bit0; GPIO37/107 never changed | not provable from software alone (MENU and POWER look identical). Needs a one-button-at-a-time recheck or continuity check. |
| RESET | PM8916 RESIN (PON RT bit1) | bit1 pulses (≈3705 s, ≈3761 s) | no Linux input bound. Long hold → PMIC stage-3 reset. KPDPWR+RESIN = hard reset. |
| key_f2 / key_f3 (stock DT GPIO37 / GPIO107) | TLMM | no change in either window | no button on the case drives these lines; stock gpio-keys entries are probably leftovers. |
The first watcher window (b1) saw no presses because the operator had not pressed yet. Window b2 is the valid one.
Summary
- Physical LEDs that lit: 1 LED function (LCD backlight; operator-confirmed). The operator sees no other lit indicator LED in normal operation.
- SAFE lines found: 1 (MPP4).
- Empty LED footprints: not mapped. No DT, firmware, or live-state evidence ties them to a line. With no continuity data they are documented only and not switched.
- Still UNKNOWN: MPP3 (current sink, off; the most LED-like candidate), PM GPIO1–4, VIB_DRV, and all unclaimed TLMM inputs (GPIO 0, 2, 3, 6–11, 16–19, 21, 24–36, 38, 39, 45–56, 61, 62, 69–98, 108, 109, 111, 112, 114, 115, 117, 119–121).
- DO NOT TOUCH: MPP1 (analog out), MPP2 (digital out HIGH, set by firmware), GPIO1/20/22/23 (SIM mux), 4/5 (UART), 12–15/116/118 (display), 40–44 (WCNSS), 57–60 (UIM), 63–68 (codec), 99–106 (modem RF/SSBI incl. 105 out-low and 106 pulled up), 110 (USB-ID), 113 (audio), SDC pads; PON KPDPWR/RESIN (read-only only).
Next steps (each needs a separate GO)
- Continuity: trace the empty LED footprints, and their series-resistor pads if present, to the SoC/PMIC. A footprint that reaches MPP3 or a PM GPIO can then become SAFE.
- MENU: press one button per window to confirm MENU = KPDPWR. If it is separate, find its line.
- Optional: MPP4 brightness by sink current (5–40 mA, SINK_CTL 0–7). This is not PWM; it needs a test kernel with a register hook or an LED driver.
Files: logs/b11/B11-LED-AUDIT.md (full audit), logs/b11/live/*, b11/audit/b11-ro.sh, b11/run/b11-led-run.sh, b11/run/b11-btn-watch.sh.