Hardware
Every subsystem, and exactly where it stands. Boot and gadget are landing; most everything above the shell is still unconfirmed.
Boot / kernel
BOOTSfb_simple console boots deterministically on mainline GRATE 6.18 — printk paints a 150×240 portrait console. Regulators, PMIC, eMMC and watchdog all bind clean. Reaches /sbin/init.
Partitions / rootfs
MOUNTSgpt_sector=26623 plus the bare gpt force token land all 23 partitions (Primary GPT invalid → alternate GPT). Root mounts once the bare p2 ext4 rootfs — not the full build-tool disk image — is flashed to UDA/p22: EXT4-fs (mmcblk0p22) mounted, superblock mount count 3, last mount +3 s, state clean.
USB gadget
REGRESSEDWorked on 2026-08-09 (1a4573e2: gadget up, sshd answering ~15 s after reboot). Since then, nothing — and the 2026-08-23 boot of 36a087d6 produced no bus event at all, not even the ~+12 s full-speed attempt earlier builds gave. Historically the UDC asserts its D+ pull-up and then never answers endpoint 0: the host sees a FULL-speed device (chirp never completes), four failed descriptor reads, then unable to enumerate. A bound gadget would appear as 0525:a4a2; it never does.
Display / panel
WRONG PANELThis tablet is a JDI j,wuxga-7 — proven by the downstream kernel calling dsi_j_wuxga_7_enable, by the vendor dtb.img carrying j,wuxga-7 and no p,wuxga-10-1, and by the panel node’s boardinfo 0x65b matching displayboard=0x065b. Mainline drove it as a zero-DCS Panasonic p,wuxga-10-1 with every timing wrong; the real part needs 15 DSI init commands including Sleep Out and Display On, and a panel that never gets those stays dark with its backlight lit. As of 36a087d6 the correct driver SHIPS and is linked into the kernel (verified by its own dev_err strings in the decompressed image) — the screen is still black, but tegra-drm is =m so the panel only probes when userspace loads it, and userspace does not start. Nothing yet tests the driver.
Touchscreen
QUEUEDSPI touch confirmed present (spi-tegra114.0, event0); controller model unconfirmed pending a rooted DT read.
Wi-Fi
QUEUEDBCM43341 confirmed live under stock Android (bcmdhd is the only loaded module). brcmfmac path is known from N9/Shield but untested here.
Bluetooth
QUEUEDSame BCM43341 combo chip as Wi-Fi; BT half untested on mainline.
Audio out
QUEUEDRT5640 codec confirmed at i2c-0 0x1c — same driver family as Shield's RT5639 (snd_soc_rt5640).
Audio in / mic
QUEUEDSame RT5640 codec; capture path untested.
Sensors
BLOCKEDCore sensors sit behind board-file I2C registration, not DT — needs a rooted capture. stm8t143 cap-prox confirmed present.
GPU (GK20A)
BLOCKEDSame Kepler wall as N9/Shield/Jetson — FECS/PRIVRING context init hangs kernel-side. Track 3 (RO Lite) targets llvmpipe until it cracks fleet-wide.
Wayland / compositor
QUEUEDsway once display + a console exist; llvmpipe/software path expected first, matching Track 3.
Battery + charger
QUEUEDbq28z610 fuel gauge confirmed in live DT (i2c-1, 0x55). batteryd not wired — oldest-packs-first queue applies once P4 opens.
Suspend
QUEUEDNot reachable before display + core I/O land.
Depth + point cloud
THE DESTINATIONFisheye motion-tracking cam, IR structured-light depth, wide RGB and a precision IMU — the reason this tablet exists. Vendor libtango is closed and there is no mainline driver path today, so it stays off the critical path. But it is the eventual target, not a write-off: expose the sensors as V4L2 first, then rebuild ranging above them.
Modem (Icera)
UNSUPPORTEDNVIDIA Icera i410/i500 in-house baseband IP, discontinued 2015, no mainline driver anywhere. Device is permanently Wi-Fi-only on RO-OS.
Haptics
QUEUEDVibrator driver/model not yet identified. Fleet-wide felt-parity requirement, pending hardware ID.
Double-tap-to-wake
QUEUEDFleet-standard rung; depends on the touchscreen driver landing first.
Beyond Android
Kernel-level capabilities the stock 2014 firmware never allowed — the parity ceiling raised, not just met.
Battery intelligence
batteryd will cap charge at a mid-SoC band and track State-of-Health once P4 opens — the pack stops living at 100% 24/7.
A living kernel
An unmodified upstream-track 6.18 GRATE kernel where Android froze at a 2015 fork of 3.10 — a decade of security and driver work, once boot completes.
Gesture navigation
Swipe-based nav with haptic commit and paired audio cues is the fleet target — no dependency on a vanished nav bar.
Double-tap-to-wake
A fleet-standard rung, free from the upstream RMI/touch driver once display and touch land.
Depth, reclaimed
The fisheye, IR projector and depth sensor are still in this chassis. Android drove them through a closed vendor stack that died with the product in 2017 — the long game is V4L2 exposure on mainline, then open ranging above it.
Shares the ardbeg kernel
Same T124/ardbeg board family as Shield Tablet. The shared Tegra-K1 DC-handover pattern (grate patch 0011) is already compiled in, dormant behind a DT flag — Tango inherits it for free the moment the panel node is written.
Road to RO-OS
The eight-rung ladder every device climbs; % is a rough mental model, not a precision metric.
Target track: 3 — RO Lite, alongside Nexus 5, Nexus 7 and Shield Tablet — pending GK20A: llvmpipe/software GL until the shared Tegra-K1 Kepler GPU-init wall (FECS/PRIVRING) cracks fleet-wide, then a stripped RO shell with core physics and no blur. Track 3 · RO Lite · pending GK20A
P6 (RO-OS shell) means the bespoke RO shell itself runs — double-tap-wake, rotation, gestures — the felt-parity floor every track shares. For Tango that's several rungs and a GPU fix away; today's fight is landing a shell and lighting the panel.
Live sprint
What's on the bench right now.
Early userspace — recovering a gadget that used to work
Bootloader unlocked (unlocked: yes, secure: no), full ADB + fastboot hardware capture from stock Android 4.4.2 — I2C map, GPIO buttons, host1x children, DSI panel node, partition table. TWRP debug shell established.
Ramoops + fb carveout ended the "logo melts to black" flake — printk paints a 150×240 portrait console. Shield's CDC-NCM+ACM+udhcpd gadget is ported (NCM not RNDIS — fixes macOS).
Three fixes, on-device: per-job CONFIG_CMDLINE bake (Tango's root, not Shield's) · the missing bare gpt force token (9b230b52) → Primary GPT invalid, using alternate GPT → p1…p23 · flash the bare p2 rootfs, not the full build-tool disk image (CI fix 4193a32d) → EXT4-fs (mmcblk0p22) mounted — superblock reads mount count 3, last mount +3 s, state clean.
The kernel mounts root at +3 s and then nothing happens: no crumb fired, and crumbs 2…5 run after openrc sysinit has mounted /proc and /sys, so any of them would have written. Saying it “reaches /sbin/init” was an overreach — no reset, no panic, and no usb0/SSH on the host. Instrumented inittab drops RO-DIAG markers to /dev/kmsg to name the stalling runlevel. Parallel thread: CBoot isn't loading the boot.img ramdisk (rdinit: -2) — embedding the initramfs in the kernel would fix fragile direct-root boot AND give a live USB debug shell.
Once a shell is live: dmesg, /proc/device-tree/, I2C/SPI/regulator probes — confirm WiFi (BCM43341), audio (RT5640), touch (SPI), battery (bq28z610), then climb toward display P2 and connectivity P3.
Ground truth
Pulled off the hardware via TWRP, 19 July 2026 — measured, not inferred.
CBoot passes this, but it was lost when the stock cmdline was transcribed into deviceinfo — without it mainline creates zero partitions. Necessary but not sufficient: it was also dead code without the bare gpt force token (mainline gates the alternate-GPT lookup behind force_gpt, set only by that token), and even with partitions the rootfs wouldn't mount until the bare p2 ext4 — not the full nested-GPT build-tool disk image — was flashed to UDA/p22. All three fixed on-device: root mounts clean at +3 s. Whether anything runs after that is the open question — the breadcrumbs say no.
Why it had to be measured
Both plausible derivations were wrong; either would have cost build cycles.
Partition map
23 GPT entries · disk GUID cc07b25b-e2fc-1be6-ebb4-4c836558a062 · eMMC 116 GiB
| Part | # | LBA range | Size | PARTUUID | Role |
|---|---|---|---|---|---|
| DFI | p1 | 26624–30719 | 2 MiB | 168076c6-707d-b914-a328-7cfd63a9889c | bootloader stage |
| TOS | p2 | 30720–35839 | 2 MiB | b7ed28fa-dd57-dca9-f9f7-84e058552911 | Trusted OS |
| EKS | p3 | 35840–36863 | 512 KiB | f805ab85-3d94-d638-1d42-78bdd378777c | encryption keys |
| FB | p4 | 36864–40959 | 2 MiB | ef7027ef-c0dd-45e8-0265-fd86e1085b3b | fastboot |
| WB0 | p5 | 40960–41983 | 512 KiB | 40e17b3b-89c9-1182-70ab-8148869e7874 | warm-boot stage 0 |
| NCT | p6 | 41984–46079 | 2 MiB | 103fea78-fb4f-37b2-7afa-010db4fb2ddf | NV config table |
| SOS | p7 | 46080–62463 | 8 MiB | 02f337d4-45de-6ae9-51bc-080f5e915959 | recovery — TWRP |
| DTB | p8 | 62464–70655 | 4 MiB | 87e9fef5-3470-fa78-8ff0-19a778bc66a6 | device tree blob |
| MSC | p9 | 70656–74751 | 2 MiB | 0fa780de-516e-4206-30c5-53d73bb26fb6 | misc / BCB |
| USP | p10 | 74752–140287 | 32 MiB | 9d7b60d3-032c-c9ce-7d8b-41dfb064bb12 | dmesg dump target |
| MDA | p11 | 140288–144383 | 2 MiB | ddb0bf6b-dce0-24ff-e99c-1be69c31029f | misc data |
| FCT | p12 | 144384–177151 | 16 MiB | ff9011a9-ea9a-8e48-151b-8e873b504005 | factory config |
| PES | p13 | 177152–2696191 | 1.2 GiB | 89ed7044-dad2-7d85-b157-14eaec3d3def | persist — holds serial |
| PEK | p14 | 2696192–5215231 | 1.2 GiB | aa96a2d4-f468-8d63-9197-5d6a290556f8 | persist backup |
| LBP | p15 | 5215232–5223423 | 4 MiB | 29b8dc74-2beb-31b5-6c36-c1b13f4172c2 | low-battery bitmap |
| CHG | p16 | 5223424–5231615 | 4 MiB | 7bf4d06a-fab9-12cc-50f5-8a1d20f9d1a5 | charging bitmap |
| FBP | p17 | 5231616–5239807 | 4 MiB | 88489df7-9249-5de0-e360-b9815a9f4dc2 | charged bitmap |
| FCG | p18 | 5239808–5247999 | 4 MiB | 4928ff83-7388-d1f4-18fe-007432c60c6d | fully-charged bitmap |
| LNX | p19 | 5248000–5264383 | 8 MiB | 75ff9f49-2218-c128-6cf5-d3dd6e7788ab | boot — kernel + ramdisk |
| CAC | p20 | 5264384–8213503 | 1.4 GiB | 5fe18d3c-d0f3-148d-f865-c9a97ce40579 | cache — pstore target |
| APP | p21 | 8213504–11162623 | 1.4 GiB | 0d28378a-52da-219b-d6c8-cf6790b6d7f7 | stock Android /system |
| UDA | p22 | 11162624–244284415 | 111 GiB | ecc238d8-8a2e-1d7b-a12d-ca516860d98a | RO-OS rootfs |
| GPT | p23 | 244284416–244285439 | 512 B | 09aa0ae6-ba0c-b3aa-33ac-59aa1a12b375 | backup GPT |
Pin by PARTUUID, never /dev/mmcblkNpM — mainline enumerates this eMMC as mmcblk1 while TWRP and the downstream 3.10 kernel both see mmcblk0.
Recovering the TWRP shell
The chicken-and-egg that gated all of the above.
Stock DTB is the key
TWRP needs the stock 3.10 DTB on the dtb partition, and it was lost with the build cache. Recovered from the stock KitKat nvflash package — tegra124-ardbeg.dtb, embedding nvidia,ardbeg and a source path matching the live ADB capture.
A 3.10 DTB is not the stock DTB
LineageOS 16's dtb.img looks equivalent and is not — LOS 16 pairs with a PSCI bootloader this tablet doesn't have. Flashing it gave "booting recovery kernel image", then silence.
Full stock restore is possible
The KitKat package is a complete nvflash set and ships a Linux nvflash binary, so restore runs from the bringup host. APX-mode entry for CBoot 1.3 is still unverified and gates the path.
PES p13 holds the serial
The restore package has no persist.img, so a --create run would lose this unit's identity permanently. Backed up. NCT is a red herring despite the "do not touch" warning — 28 nonzero bytes of 2 MiB, no serial, no MAC.
Ruled out
Falsified against mainline source and hardware — recorded so they aren't chased again.
Nexus 9 analog-pad fix
Predicts a bound gadget with PORTSC.CCS=0. Tango has no UDC at all — a strictly earlier failure. Both layers are already compiled into GRATE patch 0008.
Missing chipidea config
CONFIG_USB_CHIPIDEA_TEGRA is present, and nvidia,tegra124-udc sits in the driver's match table.
Missing nvidia,phy phandle
ci_hdrc_tegra hard-requires it, and it arrives from the SoC dtsi — the board DTS only overrides compatible.
CBoot cmdline truncation
Shield's ~220-char cut does not happen here: fbcon=font:VGA8x8 sits at offset 432 and demonstrably applied.
gpt_sector is computable
The mainline formula targets the BACKUP GPT near the end of the device; the real primary GPT sits at a low, bootloader-defined sector. Measure it.
NCT holds the serial
Despite the partition-map warning, NCT carries 28 nonzero bytes of 2 MiB — no serial, no MAC. Identity lives in PES p13.
System block diagram
Every programmable block inside the Tegra 124, and the chip that actually hangs off each one on this tablet — read out of the vendor device tree and the downstream kernel's own boot log, not from a spec sheet. Full values in the as-built datasheet.
j,wuxga-7 that needs fifteen DSI init commands including Sleep Out and Display On; mainline currently drives it as a zero-DCS panel with timings taken from the Panasonic p,wuxga-10-1 that this unit does not have. The USB device controller asserts its pull-up and then never answers endpoint 0, so the gadget — and with it the serial console and the network tether — never appears. Everything drawn grey is not broken; it is simply behind those two.