Skip to content

[DO NOT MERGE] qualify the complete SP11 beta2 aggregate - #41

Closed
ooaklee wants to merge 49 commits into
sp11/ubuntu-qcom-x1e-7.2.y-betafrom
sp11/ubuntu-qcom-x1e-7.2.y-beta-qualification
Closed

[DO NOT MERGE] qualify the complete SP11 beta2 aggregate#41
ooaklee wants to merge 49 commits into
sp11/ubuntu-qcom-x1e-7.2.y-betafrom
sp11/ubuntu-qcom-x1e-7.2.y-beta-qualification

Conversation

@ooaklee

@ooaklee ooaklee commented Sep 2, 2026

Copy link
Copy Markdown
Owner

Status: test-only aggregate — do not merge

This draft PR is the review and hardware-test surface for the complete held
sp11beta2 stack. It intentionally combines several independently reviewable
topic PRs so their runtime interactions can be qualified on real hardware.

Do not merge this aggregate PR. Do not merge an individual topic merely
because this branch compiles or because its CI is green. Each topic retains its
own behavior, provenance, dependency, and hardware gates.

Base: sp11/ubuntu-qcom-x1e-7.2.y-beta at
eca65c109843c3245bc844ec8bc2adb149415bb6

Candidate: sp11/ubuntu-qcom-x1e-7.2.y-beta-qualification at
08249986a3f4efd7e0826c29e830601bfde928ed

Candidate tree: da7479fbffe997cdc980a147b4cb929d71253185

Included held topics

Order Topic Review PR Candidate topic head Required gate
1 TX DMIC capture #36 58fec71de633 X1E/X1P stereo capture, channel order, coexistence, suspend/resume, and non-SP11 capture
2 Golden v33 protected playback #39 d0b7173d9363 Full protected/ordinary/compressed playback, PDR and PA-fault recovery, topology/UCM pinning, both SP11 variants where available, non-SP11 regression, and contributor attestation
3 SP11 battery-provider containment #37 9cc0b14b6ed7 One live battery/AC provider, telemetry, plug/unplug, suspend/resume, and non-SP11 Surface behavior
4 Platform profile, fan, and low-power cap #38 1587b018fb27 Profiles, QoS cap, fan, CPU hotplug/policy teardown, failures, suspend/resume, and non-SP11 behavior; depends on #37
5 Camera parity repair #40 b26aac2cfb29 Repeated/continuous RAW10 capture, partial-start recovery, controls, zero CSID/VFE errors, privacy LED, libcamera/PipeWire/browser, and suspend/resume

The candidate also contains the provisional beta base topics already present at
eca65c109843, including display, USB resume, PSCI containment, direct touch,
pen ABI, and the guarded IMX681 camera foundation. Their runtime behavior must
be retested because the aggregate exercises shared power, DSP, camera, input,
and suspend paths together.

The experimental USB4 branch and PR #24 are not included.

Behavior and provenance policy

  • The project-qualified reference remains
    ooaklee:sp11/integration-7.2.x at 2cbd1ec3e2da.
  • Stable replay commits retain their original authors where possible.
  • Guardrail rewrites and new 7.2.2 repairs are documented as intentional
    deviations; build success is not evidence of hardware equivalence.
  • Leon Silcott-authored commits use only leon@boasi.io in this candidate.
  • Golden commits attributed to another author retain that authorship, but the
    rewritten series remains held until the required contributor sign-off or
    equivalent maintainer-approved attestation is recorded.
  • No source topic is simplified or dropped merely to make the aggregate build.

Software qualification

The exact candidate commit and tree above have completed the following:

  • integration validation and git diff --check;
  • strict per-commit checkpatch for the seven camera and twelve Golden repair
    commits with zero errors, warnings, or checks;
  • clean case-sensitive ARM64 W=1 builds of changed objects and representative
    SP11/non-SP11 DTBs;
  • schema validation for all six changed binding families;
  • complete ARM64 Image, modules, and DTB build;
  • complete source bindeb-pkg build containing 7,816 compressed modules and
    both required Denali DTBs;
  • an independent Lexr build from the remote qualification branch in its pinned
    Ubuntu environment, with exact revision/tree provenance, four-package
    closure, generated checksums, 7,816 modules, both Denali DTBs, and successful
    lexr kernel inspect.

The full Lexr run used Stubble boot-image mode to validate Lexr's package and
boot-image contract. Its small image package is structural evidence and must
not be installed as the hardware-test kernel.

Bootable source-built test package

Expected running release: 7.2.2-sp11beta2

Package SHA-256:

3d3572cd374b3cdea338d43163d93588194e9c2701e112c0aa121e3612273218  linux-headers-7.2.2-sp11beta2_7.2.2-sp11beta2-1_arm64.deb
cd4770512b14a3260988a5c1e6bee6a5268201a4fc81ccda15fb948ff23722f0  linux-image-7.2.2-sp11beta2_7.2.2-sp11beta2-1_arm64.deb
9ddd822f9a891f5656324acd93c7a8c033b8661a1f7b6ec7798ca15709d3dce0  linux-libc-dev_7.2.2-sp11beta2-1_arm64.deb

Unsigned packaged vmlinuz-7.2.2-sp11beta2 SHA-256:

26c03fdbc45bca3dea72b4bbb653a522a91e8d2ff7c481b2777b4e708979a007

The local transfer archive sp11beta2-hardware-qualification.tar contains the
bootable packages, their checksum manifest, the qualification guide, and the
read-only collector. Its SHA-256 is:

52d2197189d5ba8ffb555675bcd1443359c755bacca030f9daa34f338e041c5e

The transfer archive does not contain the Lexr Stubble image.

Keep a known-good kernel and recovery route available. These local packages
are not distribution-signed; use the project's established signing process or
an explicitly configured unsigned-kernel test machine. Verify all package
checksums before installation and stop after reboot unless uname -r is
exactly 7.2.2-sp11beta2.

Hardware qualification checklist

Record the device variant, booted DTB, userspace image, exact uname -r,
pass/fail, reproduction steps, relevant logs, and known-good comparison for
every result.

  • X1E/OLED base: boot, backlight, keys, Wi-Fi/rfkill, OLED modeset and
    reconnect, external display, repeated suspend/resume.
  • X1P/LCD base: boot, backlight, keys, Wi-Fi/rfkill, external display,
    repeated suspend/resume.
  • Every USB port before and after repeated suspend/resume; s2idle recovery
    and suspend-power behavior.
  • Both direct-touch product IDs: multi-touch, IRQ cadence, controller
    recovery, runtime PM, suspend/resume, and long-run error/taint check.
  • X1E and X1P pen: hover, contact, pressure, tilt, buttons, concurrent
    touch, daemon restart, recovery, and suspend/resume.
  • Camera on X1E/OLED: repeated and continuous RAW10 capture, partial-start
    failure and clean retry, controls, CSID/VFE diagnostics, privacy LED,
    libcamera, PipeWire/browser preview, suspend/resume.
  • Golden playback: ordinary, protected, and compressed paths; graph setup
    and bypass failures; PDR; PA faults; clock ordering; suspend/resume.
  • TX DMIC: X1E and X1P stereo capture, channel order, playback coexistence,
    VA-path regression, and suspend/resume.
  • Battery/profile: exactly one live battery/AC provider, telemetry,
    plug/unplug, every profile, low-power cap, fan, CPU hotplug/policy teardown,
    failures, and suspend/resume.
  • Packaging: initramfs, correct DTB, required modules, boot-menu entry, and
    successful rollback to the known-good kernel.
  • Representative non-SP11 runtime coverage for every modified shared
    driver before treating that shared-driver topic as upstream-ready.
  • Golden contributor attestation/provenance gate satisfied.

Merge policy

This aggregate PR remains draft and must close without merge after it has
served its qualification purpose. Hardware evidence belongs here and should be
linked from the relevant topic PR.

Only an individual topic whose own dependency, behavior, provenance, SP11, and
non-SP11 gates have passed may leave draft state and merge into the beta branch.
After all approved topic PRs are merged in dependency order, reproduce and
compare the final beta tree against the qualified tree; any difference requires
an explicit audit and, where behavior could change, fresh qualification.

ooaklee and others added 30 commits September 2, 2026 19:56
Denali uses a 4.8 MHz direct-DMIC rate with the VA path clocked at
19.2 MHz. Validate the sample rate against that clock so the driver
selects DIV4, matching the native Windows programming, instead of DIV2.

Keep the existing calculation on every other machine.

This is based on geoca's Windows-parity analysis in patch 0072.

Link: https://github.com/geocausa/SP11X1e-audio/blob/a1d51ecc7416a905acdad50d31600fff7f28ac1c/patches/0072-ASoC-lpass-va-macro-SP11-match-Windows-DMIC-divider.patch
Link: 58e36b1
Co-authored-by: geoca <272055834+geocausa@users.noreply.github.com>
Signed-off-by: Leon Silcott <leon@boasi.io>
The Surface Pro 11 microphone array feeds the TX macro while the VA
macro owns its direct-DMIC pad clocks. Without a cross-macro clock
request, the TX capture path cannot reproduce the working firmware
sequence.

Add an LPASS-internal DMIC clock broker, register the Denali VA macro as
its provider, and request DMIC1 then DMIC0 from the TX DEC event group.
Validate the exact two-channel Denali route before changing the clocks.

Both the provider and consumer paths are gated by the microsoft,denali
root compatible. Other machines retain the existing VA and TX behavior;
the common broker remains unused on those systems.

This implementation follows geoca's Windows-parity work in patch 0078.

Link: https://github.com/geocausa/SP11X1e-audio/blob/a1d51ecc7416a905acdad50d31600fff7f28ac1c/patches/0078-ASoC-lpass-SP11-share-VA-DMIC-clock-with-TX-capture.patch
Link: 58e36b1
Co-authored-by: geoca <272055834+geocausa@users.noreply.github.com>
Signed-off-by: Leon Silcott <leon@boasi.io>
The Surface Pro 11 exposes its microphone array as two 48 kHz PCM
channels. The existing VA backend covers the voice path but does not
provide the regular TX-macro host capture path.

Add a TX macro link through AudioReach TX_CODEC_DMA_TX_3 and route DMIC0
and DMIC1 through the microphone regulator. Keep the existing VA capture
link available for low-power use and hardware comparison.

Link: ab34e94
Link: 58e36b1
Signed-off-by: Leon Silcott <leon@boasi.io>
Describe the optional WSA8845 VISENSE and CPS feedback paths, including
their DAI selectors and slave-only SoundWire transport properties. Add a
board-specific Denali sound-card compatible with the generic X1E80100
fallback.

[Leon: Split the source binding changes into a reviewable commit, rebased
them onto the current schemas, added the Denali sound-card compatible with
its generic fallback, and kept the new properties optional.]

Link: geocausa/SP11X1e-audio@31466d6
Link: 4bcfa10
Signed-off-by: Leon Silcott <leon@boasi.io>
Let a slave describe optional banked registers implemented by a SIMPLE
data port, and let a stream provide slave-only transport overrides. The
new fields default to zero so existing SoundWire devices are unchanged.

[Leon: Split the zero-default slave transport metadata from the source
overlay and rebased it onto the current SoundWire types.]

Link: geocausa/SP11X1e-audio@31466d6
Link: 4bcfa10
Signed-off-by: Leon Silcott <leon@boasi.io>
Give the Denali sound-card compatible a private configuration and use it
to constrain the WSA VI and CPS rate, format, and channel-map setup. Other
X1E80100 sound cards keep their existing backend behavior and speaker
volume limits.

Do not carry the source branch's global AudioReach readiness variables.
Readiness must instead be represented by the relevant card and graph
instances in the runtime part of the series.

[Leon: Replaced the source global readiness and volume changes with a
Denali-private card configuration while retaining non-Denali behavior.]

Link: geocausa/SP11X1e-audio@31466d6
Link: 4f9ac01
Signed-off-by: Leon Silcott <leon@boasi.io>
Let a slave describe optional banked registers implemented by a SIMPLE
data port, and let a stream provide slave-only transport overrides. The
new fields default to zero, so existing SoundWire devices keep the current
programming path.

This is the generic core portion required by the Denali WSA8845 feedback
ports; controller and codec use is added separately.

[Leon: Split the generic SIMPLE transport/register override support from
its Qualcomm controller and codec consumers and retained the current stream
API.]

Link: geocausa/SP11X1e-audio@31466d6
Link: 5cf86f7
Signed-off-by: Leon Silcott <leon@boasi.io>
Expose companion playback streams for the two Denali WSA input DAIs so
DPCM can start VI and CPS with speaker render while SoundWire keeps their
physical direction toward the master. Merge the two amplifier channels
only for Denali's shared CPS master port.

Gate both changes on the Denali machine compatible, the WSA controller,
and DAI IDs 9 and 10. Other Qualcomm SoundWire controllers retain their
existing DAI capabilities, rates, formats, direction, and port allocation.

The source branch's global diagnostic module parameters are intentionally
not carried.

[Leon: Scoped the feedback direction, shared-port merge, and companion
DAIs to Denali WSA controller IDs 9 and 10. Omitted the source diagnostic
module parameters.]

Link: geocausa/SP11X1e-audio@31466d6
Link: 5cf86f7
Signed-off-by: Leon Silcott <leon@boasi.io>
Register separate VI and CPS feedback DAIs when a WSA884x instance has
the qcom,enable-cps property. Split its SoundWire sink and source ports,
apply the DT-selected VISENSE mask and CPS Offset1, and keep playback and
feedback stream state separate.

Devices without the property still register only the existing speaker DAI
and retain the existing port description and stream setup. This commit does
not include the Denali PA register profile or lifecycle changes.

[Leon: Split the WSA884x feedback DAI/port subset, made it an explicit
per-node opt-in with private stream state, and omitted the broad PA
lifecycle changes.]

Link: geocausa/SP11X1e-audio@31466d6
Link: e72bffc
Signed-off-by: Leon Silcott <leon@boasi.io>
On Denali, add playback-side VI and CPS endpoints so the protected render
graph can start both feedback paths atomically. Add the associated DAPM
widgets and keep the existing VI capture endpoint intact.

Build the extended DAI table from a private copy only on Denali. Other
machines continue to register the original DAI table and DAPM graph, so the
shared WSA macro driver does not redefine their TX interfaces.

[Leon: Split the WSA macro feedback endpoints, built them from a
Denali-private DAI/DAPM copy, and preserved the existing VI capture path.]

Link: geocausa/SP11X1e-audio@31466d6
Link: e72bffc
Signed-off-by: Leon Silcott <leon@boasi.io>
Add playback capabilities for the WSA TX0 and TX1 backend DAIs used by
Denali's VI and CPS protection links. Build the modified table as a
device-managed copy only for the Denali AudioReach backend provider.

Other machines and the legacy Q6AFE provider keep the existing capture-
only definitions. Propagate allocation failure from the AudioReach DAI
probe.

Link: geocausa/SP11X1e-audio@31466d6
Link: 22bdec2
Signed-off-by: Leon Silcott <leon@boasi.io>
APR receive processing can hold a service pointer after dropping
svcs_lock, while dynamic port removal used to remove and immediately
free that service. A concurrent callback could therefore use freed
memory.

Give every service a registrar reference and take callback references
while holding svcs_lock. Remove the service from the IDR first, then wait
for admitted callbacks to drain before freeing it. Apply the same unwind
discipline to static service registration failures.

gpr_free_port() may sleep and must run in process context outside the
port's own callback. This avoids self-deadlock while preserving a simple
removal contract.

Signed-off-by: Leon Silcott <leon@boasi.io>
Global AudioReach commands reused token zero and shared one result slot.
Late responses after a timeout could complete a later command or mutate
the wrong mapping handle. Dynamic graph clients could also disappear
while callbacks or command users still held them.

Assign unique tokens to synchronous global and per-client commands while
preserving the graph and position-buffer token fields. Claim replies only
when token and opcode match the active command, and update mapping handles
inside the same critical section.

Publish graph clients under a lifecycle lock, reject new users once
teardown begins, abort pending waits, and drain admitted users and
callbacks before releasing ports. This also corrects the position-buffer
unmap token.

Link: geocausa/SP11X1e-audio@33d5145
Link: geocausa/SP11X1e-audio@39499f0
Link: 22bdec2
Signed-off-by: Leon Silcott <leon@boasi.io>
FullIO v19c topologies add raw module stage classes and data, graph
control links, extended container placement, and integrated-backend
metadata. The 7.2 parser did not retain or emit those fields.

Parse the extended tokens and build matching graph-open payloads without
hard-coded diagnostic or volume instance IDs. Use one checked iterator
for vendor arrays and known raw records, reject truncated, reordered,
duplicate, oversized, or overflowing input before packet allocation, and
preserve the historical no-op for unsupported legacy module extensions.

[Leon: ported the format to 7.2, preserved legacy-topology no-op
behavior, and hardened raw-block bounds, ordering, duplicates, ownership,
and aggregate allocation arithmetic.]

Link: geocausa/SP11X1e-audio@31466d6
Link: geocausa/SP11X1e-audio@7af8f21
Link: 4bcfa10
Link: 22bdec2
Signed-off-by: Leon Silcott <leon@boasi.io>
FullIO protection calibration can exceed the in-band SET_CFG limit, and
its storage belongs to the DSP graph rather than global card state.

Size each graph payload from topology, allocate coherent memory through
the APM DMA device, translate the address for the DSP SID, and map it
with a graph-scoped token. Serialize buffer writes and correlate MAP,
SET_CFG, and UNMAP replies to the exact command before changing mapping
state.

Close the DSP graph before unmapping its OOB buffer. If a reply leaves
ownership ambiguous, retain the coherent memory and device reference
until reboot or a future proven reset hook rather than allowing the DMA
range to be reused.

[Leon: made OOB ownership graph-scoped, keyed reply mutation to the
current command, and retained ambiguous mappings instead of reusing DMA.]

Link: geocausa/SP11X1e-audio@9de3dc9
Link: geocausa/SP11X1e-audio@af28565
Link: geocausa/SP11X1e-audio@1ca3820
Link: geocausa/SP11X1e-audio@31466d6
Link: 22bdec2
Signed-off-by: Leon Silcott <leon@boasi.io>
FullIO v19c describes protected-speaker calibration and runtime stages
in topology. Execute graph calibration and ordered protection or bypass
SET_CFG payloads on the owning graph instead of using global card state
or hard-coded module instance IDs.

Keep configuration, bypass proof, backend readiness, start references,
and faults per graph. Enable this path only for Denali PCM clients and a
topology-declared protected graph; reject partial profiles and mixed
ordinary or protected clients. Start only after protected configuration
or both SP and SPVI bypass commands are confirmed.

Correlate every state transition and make final close consume-on-success.
If execution, close, OOB, or mapping ownership is unconfirmed, block
reuse and retain the complete client, callback context, and DMA ownership
until reboot or a future proven reset hook.

[Leon: limited the runtime to Denali plus a topology-declared protected
graph, made malformed or unconfirmed setup fail closed, serialized
backend/readiness and start references, enforced immutable shared runtime
modes, and quarantined callbacks, clients, and DMA after unconfirmed
teardown.]

Link: geocausa/SP11X1e-audio@db2af54
Link: geocausa/SP11X1e-audio@1ca3820
Link: geocausa/SP11X1e-audio@33d5145
Link: geocausa/SP11X1e-audio@31466d6
Link: geocausa/SP11X1e-audio@7af8f21
Link: 22bdec2
Signed-off-by: Leon Silcott <leon@boasi.io>
Denali speaker protection needs both VI feedback and CPS telemetry before
the protected path can be enabled. Map those backend DAIs to the graph
that owns their topology-declared integrated backend, and publish
readiness as the SoundWire links prepare or tear down.

Keep the mapping and lifecycle limited to microsoft,denali-sndcard.
Require a valid, prepared SoundWire runtime before publishing readiness,
reject readiness transitions while the graph is started, and drain the
matching FE and BE start references symmetrically. Refuse SoundWire
teardown until the graph is known stopped. Other machines and ordinary
graphs keep their existing DAI behavior.

Link: geocausa/SP11X1e-audio@31466d6
Link: geocausa/SP11X1e-audio@7af8f21
Link: 22bdec2
Link: 4f9ac01
Signed-off-by: Leon Silcott <leon@boasi.io>
Describe the optional nominal speaker load used to select board-specific
PA gain and PBR thresholds. An absent property retains the existing
8-ohm defaults.

Link: geocausa/SP11X1e-audio@967b539
Link: 40932bb
Signed-off-by: Leon Silcott <leon@boasi.io>
Read the nominal speaker load from firmware and apply the 2S 4-ohm PA
gain, PBR, class-H, VCM, and UVLO values only when the amplifier also
reports a 2S VPHX supply. Devices without the property retain the current
defaults.

[Leon: Re-lifted the profile onto the current driver, gated it by
qcom,speaker-load-ohms and a fresh hardware-confirmed 2S status, and added
explicit default restoration after failed re-attach reads.]

Link: geocausa/SP11X1e-audio@967b539
Link: 40932bb
Signed-off-by: Leon Silcott <leon@boasi.io>
Have each opted-in WSA884x report a successful, error-free PA
enable to the WSA macro. Enable both protection paths after the
second confirmed PA and disable them before the first PA teardown.

Require protected feedback DAIs to have a live 2S/4-ohm
classification so VI/CPS readiness cannot outrun the PA profile.
Roll back PA and DRE state when an enable write, PA status check,
or macro lookup fails. Keep the counters, lock, and enabled state
in each WSA macro instance so non-protected cards remain unchanged.

[Leon: Replaced the source globals with per-macro state, scoped
lookup to the source card, balanced duplicate/remove events per
amp, made the helper Kconfig-safe, required a confirmed 2S/4-ohm
feedback profile, and withheld the PA event after write or FSM
errors.]

Link: geocausa/SP11X1e-audio@31466d6
Link: e72bffc
Signed-off-by: Leon Silcott <leon@boasi.io>
Describe the WSA8845 VISENSE and CPS feedback links used by the protected
speaker graph. Select them only from the Denali sound card and give that
card a board-specific compatible ahead of the generic X1E80100 fallback.

[Leon: Re-lifted only the common Denali VI/CPS graph and transport data,
added the board-specific compatible, and omitted the experimental board
target.]

Link: geocausa/SP11X1e-audio@31466d6
Link: 6035b3e
Signed-off-by: Leon Silcott <leon@boasi.io>
Describe both integrated WSA8845 speaker loads as 4 ohms so the codec can
select the matching PA profile after confirming the hardware 2S supply.

Link: geocausa/SP11X1e-audio@967b539
Link: 6035b3e
Signed-off-by: Leon Silcott <leon@boasi.io>
The SP11 FullIO topology SAL module declares ten input ports.
AR_MAX_MOD_LINKS bounds the stored output connection arrays, but it
does not bound this module metadata. Rejecting the input count prevents
the sound card from probing with -EINVAL. Keep the output-port array
bound while accepting the valid SAL declaration.

Signed-off-by: Leon Silcott <leon@boasi.io>
Qualcomm battmgr is the authoritative battery provider on the Surface
Pro 11. Do not instantiate the primary Surface Aggregator Module battery
device in the Denali-specific software-node group, avoiding a duplicate
battery provider without adding a machine quirk to the shared driver.

Keep the separate SAM AC-adapter node registered. This extracts and
narrows the Denali battery fix from the original combined touchscreen and
battery commit.

Link: 3fc7c52
Signed-off-by: Justin White <kyjus25@gmail.com>
Signed-off-by: Leon Silcott <leon@boasi.io>
The X1E Qualcomm battery manager registers qcom-battmgr-ac as the
authoritative mains supply. Retaining the Surface Aggregator ADP1 node
creates a second mains interface for the same Denali power source.

Follow the upstream Surface Laptop 7 precedent and omit the SAM AC node
from the Denali-only registry group. Keep this correction separate from
the Justin White battery-node extraction so its original authorship and
sign-off remain intact.

Link: torvalds@0488073
Signed-off-by: Leon Silcott <leon@boasi.io>
Device-tree systems can use platform-profile providers even when ACPI is
disabled, but the framework currently declines to register its class in
that case. Register the class unconditionally and create the legacy ACPI
attribute group only after ACPI has initialized successfully.

Record that group registration and use it to guard legacy notifications
and teardown. This keeps the class path independent of ACPI while also
avoiding a stale acpi_kobj after an ACPI initialization failure.

This exposes the native /sys/class/platform-profile/ interface without
creating a synthetic /sys/firmware/acpi hierarchy. Existing ACPI systems
retain the legacy aggregate attributes unchanged.

This is a contained rework of the original SP11 non-ACPI enablement.

Link: 106ad0d
Signed-off-by: Leon Silcott <leon@boasi.io>
The Surface Pro 11 has active cooling and supports SAM performance
profiles, but its registry group does not instantiate the existing
platform-profile and fan-speed devices.

Add the existing fan-capable profile node and fan-speed node only to the
Denali software-node group. Other Surface device groups are unchanged.

Link: 5c513ff
Signed-off-by: Leon Silcott <leon@boasi.io>
The Surface Pro 11 needs a lower CPU-frequency ceiling in its
low-power profile to match the validated cool-running baseline.
Describe the 2.515 GHz ceiling and default low-power selection on an
SP11-only software node.

Set up frequency-QoS only when that per-device property is present.
Devices without it retain the legacy TMP-then-fan write order,
including writes that repeat the current profile.

Track cpufreq policies through CREATE and REMOVE notifications plus a
per-device CPU-hotplug state, so a policy that is fully offline at
probe is capped when a CPU returns. Hold policy references while
attaching requests, clear stored raw pointers synchronously on REMOVE,
and stop hotplug callbacks before tearing down requests and the
notifier.

When entering low power, apply the cap before fan and TMP changes; when
leaving, restore fan and TMP before dropping the cap. If a SAM write
fails, read TMP back and reconcile fan and cap conservatively. An
unavailable cpufreq subsystem degrades to profile-only operation.

Omit the staging implementation’s no-op power-supply notifier. This is
a contained rework of the original SP11 low-power implementation.

Link: 30972bd

Signed-off-by: Leon Silcott <leon@boasi.io>
Signed-off-by: Leon Silcott <leon@boasi.io>
The CSID680 RDI path enables horizontal and vertical crop/drop without
programming the corresponding configuration. Leave these optional
operations disabled while retaining the timestamp, packing and interrupt
setup. Do not add drop-pattern writes or sensor-specific crop geometry.

Adapt the enable-bit correction from Jeroen Karsies' SP11 camera bring-up
snapshot b08f76f40b8d7b715bd4da6aef484f86142cc147. Retain the existing
upstream source attribution and limit this change to receiver setup.

This remains experimental groundwork: stream counters, capture layout
and repeated starts still need validation on the target hardware.

Link: https://github.com/karsies-wq/sp11-imx681-linux/blob/b08f76f40b8d7b715bd4da6aef484f86142cc147/camss/camss-csid-680.c
Link: b910f68
Signed-off-by: Leon Silcott <leon@boasi.io>
Program period 1 and pattern 0 for the frame, pixel, and line drop
engines.
This preserves every RDI sample explicitly instead of relying on reset
values, while the independently configured IMX681 horizontal crop remains
enabled only for its exact C-PHY RAW10 geometry.

Extract the CSID portion of the hardware-qualified source commit and
preserve its author. Sensor, PHY, device-tree, and packaging changes from
that original multi-area commit are already represented by the preceding
beta camera topic.

Link: 1592ec3
Signed-off-by: Leon Silcott <leon@boasi.io>
Track the last subdevice that accepted stream start. If a later subdevice
fails, stop only the subdevices that were successfully started before
tearing down the media pipeline. Reuse the same helper for normal stream
stop and keep teardown going after nonfatal stop errors.

This preserves the CAMSS portion of the hardware-qualified source commit.
Its sensor, CCS, and packaging changes are not copied because the beta
already uses the validated standalone IMX681 driver and focused packaging.

Link: 0097c12
Signed-off-by: Leon Silcott <leon@boasi.io>
Sample read-only CSID680 receiver, packet, error, IRQ, crop, and linked-
RDI state while its clocks are still running. Sample matching VFE680
write-master and IRQ state before disabling the writer.

Keep the source branch's narrow activation signature: X1E80100,
one-trio C-PHY RAW10, 3840x2640 or its 3844-pixel pre-crop form, and the
exact packed VFE output geometry. Other SoCs, D-PHY routes, formats, and
VFE Lite remain unchanged.

This extracts the active CAMSS diagnostics from the hardware-qualified
source commit and preserves its author. The old CCS sensor diagnostics are
not copied: the qualified final tree replaced that unbound path with the
standalone IMX681 driver.

Link: 4d190bc
Signed-off-by: Leon Silcott <leon@boasi.io>
Supersede the withdrawn sp11beta1 qualification carrier after restoring
the active camera behavior identified by the final-tree parity audit.

Signed-off-by: Leon Silcott <leon@boasi.io>
The qualified integration source applied its CSID680 keep-all state and
VFE680 MIPI RAW write mode to every user of those shared blocks. Preserve
the observed behavior for the X1E80100 C-PHY RAW10 IMX681 route while
restoring the existing programming for all other formats and SoCs.

Use the already exact transport and geometry signature for containment.
For that route, keep crop/drop disabled unless the 3844-to-3840 horizontal
crop is selected, explicitly program all drop engines to keep every
sample, and select the MIPI RAW VFE write-client mode. Other routes retain
their prior RDI flags, reset-value drop state, and VFE mode.

This is an intentional guardrail relative to the qualified source, not a
claim of cross-device equivalence. The SP11 path and a non-SP11 VFE680 RDI
path both require hardware qualification before integration.

Signed-off-by: Leon Silcott <leon@boasi.io>
The hardware-qualified Denali graph uses a 48 kHz, 16-bit, stereo
pull ring with two 1920-byte periods. Restore those ALSA constraints
and map only the page which contains the 3840-byte ring.

Keep the existing generic push/pull allocation for every other card
and topology. Fail closed if the protected Denali runtime reaches
prepare with geometry other than the qualified values.

Signed-off-by: Leon Silcott <leon@boasi.io>
The qualified SP11 playback path keeps its integrated pull graph
running across ALSA STOP and reprepare, and uses the topology
soft-pause module for pause and resume. Restore the exact zero-length
parameters for instance 0x466b, register both completion events,
and retain the measured 20 ms ramp, 25 ms downstream delay, and 5 ms
completion margin.

Limit the persistent lifecycle to Denali playback with both a protected
profile and a pull endpoint. Keep the existing command correlation,
uncertain-state quarantine, and final close handling around it.

Signed-off-by: Leon Silcott <leon@boasi.io>
The hardware-qualified Denali protected profile uses the full WSA PA
gain range and selects its operating point through UCM. Do not apply
the provisional 0 dB PA cap to that profile.

Keep the -3 dB digital-volume limit everywhere, and retain the upstream
PA cap for every X1E80100 machine without the Denali speaker-feedback
guard.

Signed-off-by: Leon Silcott <leon@boasi.io>
The qualified integrated SP11 graph sends its pull-ring parameter
through the graph client port. Use that route when protection is
active so command correlation and ordering remain graph-scoped.

Preserve the existing APM service route for generic unprotected
push/pull users.

Signed-off-by: Leon Silcott <leon@boasi.io>
Restore the qualified protected graph's own uncached position page and
use its DSP address for the fixed pull ring. Read the live counter
with DMA barriers and reject zero, torn, and out-of-range indices
before updating the ALSA pointer.

Identify this lifecycle only when the protected topology contains pull
instance 0x4660 and soft-pause instance 0x466b. Preserve the generic
ALSA-owned position buffer for every other push/pull graph, and retain
uncertain mappings under the existing fail-closed teardown policy.

Use the captured SP11 subgraph order for graph-client run-state
commands. Treat a lost soft-pause completion as uncertain so the
next teardown or prepare performs a confirmed graph stop instead of
claiming that playback resumed.

Signed-off-by: Leon Silcott <leon@boasi.io>
The hardware-qualified FullIO pull transaction proceeds from its
protected configuration directly to the ordered graph-client START. Do
not insert the generic APM GRAPH_PREPARE command for the exact SP11
topology.

Advance the existing fail-closed prepared state locally so start still
requires successful protection configuration or confirmed bypass. All
other protected and generic graphs retain the existing PREPARE command.

Signed-off-by: Leon Silcott <leon@boasi.io>
The qualified integrated transaction configures the pull endpoint
media format before walking the protected PCM converter and MFC
chain. Restore that order for the exact SP11 topology.

Keep the existing PCM-then-shared-memory order for every ordinary
and non-SP11 graph.

Signed-off-by: Leon Silcott <leon@boasi.io>
Match the qualified position-map token and send the soft-pause
parameter over the APM service port used by the captured SP11
transaction. The exact protected-topology predicate still prevents
either path from serving another graph.

Keep pull-ring setup and event registration on the graph client,
matching their qualified routes and preserving graph-scoped command
correlation.

Signed-off-by: Leon Silcott <leon@boasi.io>
Clear the retained-map uncertainty only when the DSP definitively
rejects the matching graph-owned position mapping. This lets the
synchronous failure path release coherent DMA without treating a
confirmed NACK like an unknown DSP outcome.

Reject a second position allocation on the same graph as a defensive
backstop against overwriting retained mapping state.

Signed-off-by: Leon Silcott <leon@boasi.io>
A persistent Denali pull graph may reach prepare while it is still
DSP soft-paused. Resume it and require the matching completion before
reporting the reused graph as running.

Keep the stream uncertain on a missing completion so a later prepare
cannot silently reuse a potentially paused graph.

Signed-off-by: Leon Silcott <leon@boasi.io>
The graph-owned position mapping uses the qualified fixed BIT(30)
token. Reserve that sequence value from generated mapping tokens
and classify graph-position responses by the complete non-graph-id
token class.

This prevents a generic fixed-region mapping from becoming
indistinguishable after the sequence counter reaches the reserved
value while preserving the qualified DSP transaction.

Signed-off-by: Leon Silcott <leon@boasi.io>
Do not let a later STOP overwrite the fail-closed state left by
a missing soft-pause completion. Confirm a hard graph stop first,
then clear persistent pull state so the next prepare performs the
complete setup.

Also clear the soft-pause marker after hw_free confirms the same
recovery, preventing stale pause state from surviving into a rebuilt
graph.

Signed-off-by: Leon Silcott <leon@boasi.io>
@ooaklee

ooaklee commented Sep 3, 2026

Copy link
Copy Markdown
Owner Author

Superseded by draft qualification PR #43, which uses the established 7.2.2-jg-0sp11v6 ABI and adds the hardware A/B touch and protected-stereo parity repairs. This aggregate was never merged; retaining it closed preserves the earlier evidence without presenting the beta2 build as the current test candidate.

@ooaklee ooaklee closed this Sep 3, 2026
@ooaklee

ooaklee commented Sep 3, 2026

Copy link
Copy Markdown
Owner Author

Authoritative SP11 golden-parity ledger (3 September 2026)

This supersedes any implication that the old aggregate candidate was complete.
The source of truth is the hardware-qualified
sp11/integration-7.2.x tip 2cbd1ec3e2da, followed by its first-parent
feature merges. The unrelated 7.2.0-to-7.2.2 upstream tree delta is excluded.

OpenCode independently challenged this mapping against the local golden, beta,
and topic refs. Its findings were then checked against the actual PR bases and
heads; in particular, #47 contains the complete 38-commit playback series
directly on beta, and #40 depends only on camera support already merged by #35.

Golden functional group Golden source Beta coverage Guard/containment Current qualification
CI delta guardrails #1 971b5af8, #11 c014aab2, #15 8bd99fa merged #27, #29, #30 SP11-authored delta and ERROR-level checkpatch policy software pass
OLED DP link-rate workaround #2 8acfcf39 / 7dccfdf7 merged #28 panel/link-specific MSM DP path beta boots/display observed; targeted link/hotplug gate remains
DWC3 PHY resume recovery #3 88b64724 merged #31 opt-in snps,reinit-phy-on-resume DT property build pass; suspend/resume hardware gate remains
PSCI idle containment #5 e647fbb3 merged #32 Denali DTS disables affected cluster idle states build pass; suspend/resume hardware gate remains
Volume rocker #6 5509c5fc, follow-ups 247858bd, e3b4bf35 already in the 7.2.2 beta base as 15d9d13a and e3bd10a4 Denali gpio-keys, PM8550 GPIO 6/8 physical key events observed; v7 static was audio output, not missing key input
QSPI/SPI-HID/touch transport #4 b7b89b60, #8 7ee4adb3, #18 3fc7c524 core merged #33; event-order repair draft #45 protocol-9/QSPI and MSHW0485/product-ID gates v7 failed with residue/invalid-cookie crash; disposable v8 #46 pending
Pen/IPTSD ABI 5cf0b883, #23 2cbd1ec3 merged #34 optional Denali DT opt-in and config userspace present; depends on passing touch transport in v8
Platform profile/fan/CPU cap #7 272c6af0, #16 b6ca0e49 draft #38 SP11 SAM node group and SP11-scoped low-power cap software pass; profiles, cap, fan and suspend hardware gates remain
Qualcomm battmgr ownership #18 3fc7c524 draft #37 omit Denali SAM battery/AC software nodes; no generic driver quirk software pass; duplicate-provider/charge/AC/suspend hardware gates remain
TX DMIC capture #21 58e36b1a draft #36 Denali codec/DTS routes and shared-clock guard software pass; channel/rate/reopen/suspend capture gates remain
Golden v33 protected playback #17 537d1ac6 full 38-commit guarded replacement draft #47 Denali compatible, DT/profile, graph-client/instance and 2S/4-ohm gates v6/v7 failed left-only/static; exact disposable v9 #48 pending
IMX681 C-PHY camera #22 d915d679 basic support merged #35; receiver/stream parity draft #40 Denali graph plus explicit CAMSS/IMX681 link containment software pass only; capture/stop/restart/error-unwind hardware gates remain

Dependency and integration order

Explicit exclusion

USB4 PR #24 is a separate post-golden experiment, not baseline parity. Its own
commits call it a top-port experiment and isolated test image, and it is based
on (rather than contained in) the qualified golden tip. Track and qualify it
separately after baseline beta parity.

Remaining path to beta

  1. Qualify v8 touch/pen and v9 audio independently against v19.
  2. Qualify camera, TX DMIC, battery ownership, and platform profile groups with
    their recorded failure-path tests.
  3. Resolve contributor attestation/DCO and pin required topology/UCM inputs.
  4. Rebase qualified topics in dependency order, preserving all behavior and
    authorship; produce a new ABI-distinct aggregate.
  5. Run full software gates plus device-wide regression testing before any final
    merge into sp11/ubuntu-qcom-x1e-7.2.y-beta.

This ledger records coverage and gates; it is not approval to merge any open
topic.

@ooaklee

ooaklee commented Sep 3, 2026

Copy link
Copy Markdown
Owner Author

Pairwise commit-tree integration audit of the six reusable topic heads found one concrete conflict only: #37 vs #38 in drivers/platform/surface/surface_aggregator_registry.c. This confirms #38 must be rebased after qualified #37 and the combined SP11 node group must retain both battmgr ownership and profile/fan nodes. All other 14 topic pairs merge cleanly at their current heads, including #36 with #47. Shared subsystem scope is still a regression-test dependency, but it is not presently a textual merge conflict.

@ooaklee

ooaklee commented Sep 3, 2026

Copy link
Copy Markdown
Owner Author

Independent semantic-parity audit: TX DMIC, battery, platform profile

A fresh tree-level audit plus an independent OpenCode review found no missing v19 runtime behavior in the three remaining topics:

  • ASoC: re-lift guarded SP11 TX DMIC capture #36 TX DMIC — PASS: retains the Denali-only 19.2 MHz/DIV4 selection, shared VA-to-TX DMIC clock broker, exact two-channel route, and TX_CODEC_DMA_TX_3 DT link.
  • platform/surface: re-lift SP11 battery-provider containment #37 battery provider — PASS: replaces the shared-driver Denali -ENODEV quirk with the narrower SP11 registry policy. Both SAM battery and SAM AC nodes are omitted, leaving Qualcomm battmgr authoritative.
  • platform/surface: re-lift contained SP11 platform profile #38 platform profile — PASS: retains the SP11 default low-power selection and 2,515,000 kHz ceiling through SP11-only properties, while improving cpufreq hotplug/error lifecycle. Dropping the no-op power-supply notifier and synthetic /sys/firmware/acpi shim is deliberate; the native platform-profile class remains available without ACPI.

Deterministic integration check: #37 and #38 have one expected textual conflict in ssam_node_group_sp11[]. Merge #37 first, then relift #38 so the resolved group contains ssam_node_tmp_perf_profile_sp11 and ssam_node_fan_speed, with neither ssam_node_bat_ac nor ssam_node_bat_main. #36 is conflict-free with both.

This is source-semantic qualification only. Hardware qualification remains required before merging these topics into beta.

@ooaklee

ooaklee commented Sep 3, 2026

Copy link
Copy Markdown
Owner Author

Guardrail integration and exact relift checkpoint

CI-only PR #49 is merged into beta at 91baa27098d56592add2662bbdb48518b3da8442. It retains the beta-wide report and now rejects any source-level checkpatch error, warning, or check in each real topic commit; it also requires a current linear topic history.

Reusable topics #36, #37, #38, #40, #45, and #47 plus qualification PRs #46 and #48 were re-lifted onto that exact beta tip using force-with-lease. Before each update, the non-CI topic delta and author/date/message stream were hash-compared with the prior branch and found identical. The v8/v9 old-to-new tree comparisons contain only the validator script, so the existing hardware-test packages remain valid.

All eight PRs are now individually clean and green under the new remote per-commit gate. No hardware-dependent topic was merged.

@ooaklee

ooaklee commented Sep 3, 2026

Copy link
Copy Markdown
Owner Author

Commit-message hygiene checkpoint

The avoidable full-patch findings in #45, #40, and #47 were removed with message-only rewrites. Each final tree and author identity/date/subject stream is unchanged; the refreshed v8/v9 qualification trees are byte-identical to the built trees. All affected remote checks pass.

The only remaining full-patch attribution warnings are the explicitly documented Co-authored-by/missing-DCO cases associated with geoca’s work. Those are not being normalized by automation: contributor confirmation is required before kernel-style Co-developed-by plus matching Signed-off-by trailers can be asserted.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants