NVIDIA Shield Tablet nvidia-shieldtablet / tn8 Tegra K1 T124 · Kepler GK20A · armv7 RO-OS · mainline 7.0.1
Shield Tablet · 2014 · Wayland daily driver

The gaming tablet,
a Wayland daily driver.

2014's console-grade Kepler slate — first mobile GPU with real desktop-class shaders — now running sway on its own panel over an unmodified upstream kernel, where NVIDIA froze it at 3.10. Compositor, speakers, sensors and battery are up, and the Kepler GPU renders in hardware; the BCM43241 radio is the last wall — it answers nothing.

Kernel
7.0.1 · r13
Signature HW
GK20A Kepler
SoC
Tegra K1 · T124
Android life
4.4 KitKat → 7.0 Nougat
Vs. Android
3.10 → 7.0.1
42%hw parity
Phase P5 · WiFi is the wall
8 of 19 subsystems live

Hardware

Every subsystem, and exactly where it stands.

workingin progressblocked / portingnot started

Boot → userland

LIVE

Mainline 7.0.1 (LLVM-built) reaches full userland cleanly — migrated off the frozen grate fork 2026-05-11; tree + toolchain jump validated on hardware 2026-08-04.

r56 first · 7.0.1 · LLVM

Access / shell

LIVE

USB-net gadget, NCM+ACM composite, zero host-side setup — the pure-peripheral chipidea fix (dr_mode) that also cascaded to the N9.

172.16.42.1 · r73

Display / sway on glass

LIVE

DC-handover patch (grate 0011) preserves bootloader scanout; sway/pixman paints DSI-1 and Firefox-ESR loads pages over USB-NAT. Software-rendered — no GPU needed.

tegra-drm · DSI-1 · r67

Compositor + browser

LIVE

sway + foot + fuzzel auto-start on the panel at boot. Tegra K1 is a split-GPU system — tegra-drm (card0) owns the connectors, GK20A (renderD129) does the rendering — so GL clients now get real acceleration while the compositor stays on pixman.

sway · split scanout/render

WiFi

SILENT

RETRACTED — this read LIVE and was wrong. The BCM43241 never answers CMD5. Every layer is now verified correct (pinmux, clk32kg LPO, rails, reset polarity, 1.8 V signaling ON, indefinite retries since broken-cd) and the chip still declines.

SDIO 0x4324 · no CMD5

Bluetooth

SILENT

Same combo chip, same silence: hci0 enumerates and hci_uart_bcm binds, but 0xfc18 times out and BCM reset fails -110. Both radio halves dead with all enables, clock and power present.

BCM4324B3 · -110

Sensors — IMU + compass

LIVE

MPU6515 accel/gyro polled (IRQ optional) + AK8963 mag nested behind the MPU aux-i2c gate. Auto-rotate ready.

iio:device0/1 · 0x69/0x0d

CPU frequency

LIVE

4x Cortex-A15 online via PSCI; DFLL cpufreq sweeps 204 MHz–2.1 GHz. The CVB OPP table comes from the kernel, not DT.

204M–2.1G · DFLL

Battery + charging

LIVE

LC709203F fuel gauge + BQ24190 charger. charge_type knob confirmed live — the control surface batteryd needs for a charge-band tier.

53% · LC709203F

Audio out — speakers

LIVE

Confirmed by ear 2026-08-06. The gate was never the codec: the RT5639's internal mixer path (Stereo DAC MIX → SPK MIX → SPKVOL → SPO MIX) defaults off at every stage, so a card that reported route-present, 100% volume and clean PCM streaming was open-circuit inside. Music now plays through mpv → PipeWire.

RT5639 · speakers ✓

GPU acceleration

HW GL

The "FECS wall" was missing firmware — the GPU firmware directory never existed and nouveau was blacklisted. With the 8 gk20a blobs shipped, nouveau inits with zero FECS/PRIVRING errors and real hardware GL runs: GL_RENDERER=NVEA, glmark2 81 vs llvmpipe 42. Remaining: pushbuf timeouts under load.

GK20A · glmark2 81

Touchscreen

PORTING

Raydium RM31080 on SPI — no mainline driver exists. Needs a ~4000-line downstream rm31080a_ts.c port; the panel shows but is not finger-interactive without it.

RM31080 · spi0.0

Audio in / mic

ZERO

Tested 2026-08-06 now that playback is proven: a 6 s capture returns exact digital zero — RMS 0.0, peak 0, across 288 000 samples. Not a quiet room; a live ADC always has a noise floor. The capture-side mixer path is off the same way playback was.

RT5639 ADC · rms 0.0

ALS / proximity

QUEUED

CM3217 and LTR659 sit on the bus but have no mainline driver wired yet.

0x10 · 0x23

Suspend / resume

QUEUED

Not yet attempted on the mainline boot — s2idle/LP0 unexplored post-USB-SSH.

—

Double-tap-to-wake

QUEUED

Fleet-standard rung — gated on the Raydium touch driver landing first.

DT2W · blocked-on-touch

Haptics + gesture nav

QUEUED

Fleet-wide felt-parity layer (touch-boost, vibrator commit cues) is design-pending across every device; the RO shell (P6) is where it lands.

felt-parity

Cameras

QUEUED

Front/rear sensors unprobed.

—

Cellular modem

N/A

WiFi-only hardware — the Shield Tablet ships no modem silicon.

—

Beyond Android

Kernel-level capabilities the stock 3.10.33 firmware never allowed — the parity ceiling raised, not just met.

⚡

Battery intelligence

batteryd targets a mid-SoC charge band + State-of-Health telemetry — the BQ24190 charge_type knob is confirmed live on hardware, the last piece before a real charge-capping tier.

This pack is 12 years old; stock Android just trickled it to 100% and left it there.
⇄

Shared Tegra-K1 DC handover

The same bootloader-active-scanout-preserve patch (0011) that cracked the Nexus 9 panel, now proven on Shield hardware 2026-06-29 — three T124/T132 devices sharing one fix.

A single upstream gap, not three separate device bugs — fixed once, paid off three times.
7.0

A living kernel

Migrated off the frozen grate-driver fork (v6.6.22-lts, Apr 2024) onto real upstream — now 7.0.1, LLVM-built — picking up 18 months of the GRATE maintainer's own patches that never reached Android's 3.10.33.

The device keeps getting newer instead of older.
◱

Double-tap-to-wake

Slated to fire through a native mainline touch driver once Raydium lands — no vendor wake blob, unlike the stock firmware. Arrives with the P6 RO shell.

A fleet-standard rung, free from any upstream dependency.
⇉

Gesture nav + haptics + cues

Swipe-based navigation with haptic commit and paired audio cues — the felt-parity layer 2014's TegraZone UI never had, budgeted for Track 3 richness once GK20A lands.

A modern touch-UX layer no NVIDIA gaming firmware ever shipped.

Road to RO-OS

The P0→P7 ladder, and where this device sits on it today.

Target track: 3 — RO Lite(pending GK20A) — GL-only fallback to llvmpipe, ~2 GB RAM budget. Stripped RO or sway/Sxmo; core physics, no blur; snappy via touch-boost. Native-first, no Waydroid.
P6 = RO read-only shellThe bespoke RO shell actually running: double-tap-wake, DPMS, rotation, swipe gestures — the felt-parity floor every track shares, richness scaling by GPU class above it.
P0
Boots
≈5%
P1
Access
≈15%
P2
Display + Touch
≈30%
P3
Connectivity
≈45%
P4
Core I/O
≈60%
P5
GPU + Wayland
≈75%
P6
RO-OS shell
≈90%
P7
Full parity
≈100%

Where Shield sits: a Wayland daily driver with hardware GL for its clients — P5. Boot, USB-SSH access, the DC-handover panel with sway on glass, sensors, 4-core cpufreq, battery and (since 2026-08-06) speaker audio are live, and the GK20A now renders in hardware. The wall moved: the BCM43241 radio never answers CMD5, so WiFi and Bluetooth are both silent — a P3-connectivity hole sitting underneath an otherwise P5 device, and the single blocker in front of the device now. Next rung is P6, the RO read-only shell, gated on the Raydium touch port for a finger-interactive panel — bringing the felt-parity floor (double-tap-wake, DPMS, rotation, swipe gestures) shared by every track.

Live sprint

What's on the bench right now.

In flight

The radio wall — BCM43241 answers nothing

✓
Sway on glass — 2026-07-11

The Tegra-K1 DC-handover patch (grate 0011) preserves bootloader scanout; sway/pixman lights DSI-1 and Firefox-ESR loads pages over USB-NAT. A running Wayland session on the panel — no GPU required.

r67 · DSI-1 · llvmpipe 42 ✓
✓
Speakers — confirmed by ear, 2026-08-06

The card had looked correct for weeks: route present, volume 100%, PCM streaming, no XRUN, MCLK+BCLK live. Every one of those checks sat above the actual break — the RT5639's own internal mixer chain was off at every stage, so the DAC never reached the Class-D amp. Music now plays through mpv → PipeWire.

RT5639 · SPK MIX chain · speakers ✓
✓
The GPU wall was missing firmware

Recorded across the fleet for months as a FECS/PRIVRING kernel bug. It was two missing files: the GPU firmware directory never existed, and nouveau was blacklisted. With the 8 gk20a blobs shipped it inits with zero faults — glmark2 81 vs llvmpipe's 42.

GK20A · NVEA · glmark2 81 ✓
✓
Core I/O all up

USB-SSH (NCM+ACM, zero host config), 4×A15 via PSCI, DFLL cpufreq 204 MHz–2.1 GHz, sensors, and the BQ24190 charge knob — the full P4 layer live on hardware.

PSCI · DFLL · batteryd knob ✓
→
BCM43241 will not answer

The hardest remaining wall, and the one entry on this page that used to claim success. Pinmux, clk32kg LPO, rails, reset polarity and 1.8 V signaling are all verified correct on hardware, and since broken-cd the host retries forever — CMD and DAT sit idle-HIGH and never toggle. Bluetooth is silent on the same die.

no CMD5 · WiFi + BT · below the DT
→
Kepler pushbuf timeouts under load

A far later wall than "FECS won't init": the engine initialises and executes real command streams, but a submission path times out (nv50cal_space: -110, 310× in one run) with zero FECS/gr/PRIVRING errors. It is what caps a 128-core Kepler at ~1.9× software.

GK20A · pushbuf · caps glmark2 at 81

The die, and what it drives

Every wire labelled with the bus it really runs on; every block coloured by what has been proven on this tablet, not by what the silicon is capable of. Re-triaged subsystem by subsystem on 2026-08-16 against build bf3d89f7 — so the dark blocks are measured holes, not unexplored ground.

TEGRA K1 · T124 28 nm · 4×A15 @ 204–2116.5 MHz · DFLL · idles 204 MHz (stock idled 312) CPU · 4×A15 20 OPPs · no cpuidle GPU · GK20A nouveau · GLES 3.2 HOST1X 50000000 · engine bus DC · DSI card0-DSI-1 · 59.960 Hz AHUB · I2S1 rt5640-aif1 · card 0 HDMI · SOR HPD fixed r15 · untested SDHCI4 · eMMC 700b0600 · root SDHCI1 · SDIO 700b0000 · no CMD5, ever chipidea USB peripheral · NCM + ACM SPI1 7000d400 · disabled SOC_THERM 5 zones · ONE cooler VDE · VIC · MSENC VI/CSI/ISP · no driver PANEL · AUO B080UAN01 1200×1920 · full 60 Hz parity BACKLIGHT PWM ch1 · 9 → 256 levels in r15 TOUCH · Raydium RM31080 absent — no bus, no driver CODEC · RT5639 speakers ✓ · mic routed in r15 DSI · 4-lane · 155.67 MHz PWM · 40161 ns spi1 · CS0 · 18 MHz i2s1 WiFi · BCM43241 silent · power-cycled ~1 Hz BT · BCM4324B3 CTS never asserts · tx = 0 eMMC · 14.7 GiB root p23 · gpt_sector=41983 SDIO 4-bit · 1.8 V uartc · 3 Mbaud HS200 · 8-bit PMIC · TPS65913 palmas · every rail up CHARGER · BQ24190 Tier A 75–80 % cap LIVE GAUGE · LC709203F SoC ok · SoH impossible IMU · MPU6515 + AK8963 · matrix r15 INA3221 was 10× low · fixed r15 ALS · CM3217 present · no driver i2c-0 “gen1” · i2c-1 “gen2” · i2c-4 “pwr”

Read the dark blocks as the roadmap: touch is the gate (no SPI master, no driver, and the vendor stack turns out to live in userspace), WiFi and Bluetooth are one silent chip whose last host-side excuse was eliminated on 2026-08-16, and VDE/VI/CSI are deliberate non-goals — mainline has no T124 backend and software decode already holds 1080p60 at 58 °C.