Repository navigation
Changelog
This page contains the complete open-stack changelog: a state summary and highlights by area first, then the full dated log of the test campaign (since 2026-09-30) for OpenIMP, open-tx-isp, timps and the thingino integration. The same text is kept in the repository as docs/OPEN_STACK_CHANGELOG.md; a release-oriented summary per area is in CHANGELOG.md at the top level of the OpenIMP repository. Current state per feature and SoC: Feature matrix; per SoC: Per-SoC status; beyond the vendor: Beyond the vendor.
Cameras are anonymised: cam-A (T31), cam-B (T23), cam-C (T20), cam-D (T21), cam-E (T10), cam-F (T41), cam-G and cam-H (T23, other sensors), cam-I (T20), cam-J (T21). Branch names (claude/...) are historic: the branches were merged into next and deleted. Tables of the repository version are shown as lists here so they stay readable on the wiki.
All test cameras run the open kernel driver, OpenIMP and timps: cam-A (T31), cam-B (T23), cam-C (T20), cam-D (T21), cam-E (T10), cam-F (T41) and cam-H (T23). Since 2026-10-04 17:39 they run full OTA images built from thingino aperto with open-tx-isp and OpenIMP aperto: 30/30 snapshots, 0 oops, 0 VPU errors. A 24 h soak started at 17:50; the first release tag follows after it. No Ingenic or neo helper libraries remain on the images (T23 also needs no vendor helper process).
OpenIMP
- Real HEVC on T31; hardware JPEG on T31; native Helix encoder on T23 without vendor code.
- Capped rate-control modes, Allegro RC core on T31, vendor-identical OEM controllers on T10/T20, eprc on T21/T23.
- Real motion detection on T20/T21/T30; motion v2 (bounding boxes, strength, suppression after IR/gain jumps) on by default,
OPENIMP_MOTION_V2=0restores the vendor algorithm. - OSD on T20/T21 (IPU hook); real AECM echo cancellation on T31; software rotation on T31.
- Binaries 40-50 % smaller than the vendor library; rmem peak logging and shortfall hints.
open-tx-isp
- Lifecycle hardening (locking, use-after-free, STREAMOFF races, bounded tuning access) on all SoCs; module reload clean on every SoC including T41.
- Exposure readback, tuning controls wired (T23 about 45 control IDs), unknown IDs rejected.
- T21: stock AE and ADR lifted instruction by instruction; T23 vendor AE lifted (default on); T20 simple AE/AWB; T41 gc5603 tuning fix.
- Modules smaller than the vendor ones on T21, T23 and T31; 8 MB MMAP pool optional on T10/T20.
- Sensor module pinned while the ISP is open; sensor registry under
/proc/jz/sensor.
thingino integration
- Packages
openimpandopen-tx-ispare in upstream thingino branchaperto(pull request #1756), pinned to the opensensor repositories (aperto); kernel VPU/rmem stability patches (#1748, #1752), optional boot guard (#1749) and two SC2336 flip fixes (#1750, #1751) are merged there. The guardedfw_setenvfor T41 (#1738) is not upstream.
T23 sporadic Helix errno=5 (rare; the frequent frame drops had a fixed cause, a residual interrupt in the kernel wait patch) and rare unexplained hangs of earlier builds; T41 flip, day/night and AE/AWB quality, short IVS gaps; real WDR on T23; T10 image controls undocumented. See the feature matrix for the current table.
Per-area sections first, then the working sessions of the campaign (newest first). Last update of the log: 2026-10-05 22:50.
All test cameras run the open kernel driver (open-tx-isp), OpenIMP and timps. No Ingenic or neo helper libraries (libalog/libsysutils) remain on the images. Since 2026-10-04 17:39-17:47 every camera runs a full OTA image built from thingino aperto with open-tx-isp next and OpenIMP next (30/30 snapshots, 0 oops, 0 VPU errors); a 24 h soak runs since 17:50 and the first release tag follows after it.
-
cam-A (T31, fully open):
apertoimage; H.264, H.265, hardware JPEG, OSD, AEC; rmem 36 MB -
cam-B (T23, fully open (native encoder, no vendor helper)):
apertoimage; frequent Helix frame drops fixed (residual interrupt); a rare single Helix encode error (errno 5) is still open -
cam-C (T20, fully open):
apertoimage with kernel patch 0101; OEM rate controller default; A/B vs vendor measured -
cam-D (T21, fully open):
apertoimage; reference sharing on; vendor-identical eprc -
cam-E (T10, fully open):
apertoimage, boot guard auto; ispmem 6 MB -
cam-F (T41, fully open):
apertoimage (rootfs rev7, rmem 26M); H.264 and H.265; open: flip, night column noise, short IVS gaps -
cam-G, cam-H (T23, fully open): two further T23 cameras (other sensors); cam-H is part of the
apertoimage run
-
ISP tuning: Contrast/sharpness started at 0 instead of 0x80. Now: Vendor defaults. (
claude/openimp-quickfixes) -
ISP tuning T20/T21: T31 control IDs sent; wrong AeLuma ID; TotalGain/RunningMode/FPS without result pointer. Now: SDK control IDs, pointer semantics as vendor. (
claude/openimp-quickfixes,claude/exposure-readback,claude/t20-tuning-ptr) -
Day/night T20/T21: Brightness/contrast/saturation/sharpness not re-sent on switch; sinter/temper sent to rejected IDs. Now: Re-sent like vendor; table-based sinter/temper. (
claude/tseries-daynight) -
ISP tuning T23: GetSensorAttr wrote past the caller's buffer. Now: Vendor 20-byte layout via bounce buffer. (
claude/t23-sensorattr) -
ISP tuning T31: AF IDs wrong; SensorAttr/WaitFrame/ModuleControl cache-only. Now: Through the driver with vendor ABI. (
claude/t31-isp-gaps) -
Encoder rate control: CappedVBR/CappedQuality/SMART silently CBR. Now: Mapped to VBR with log line. (
claude/openimp-quickfixes) -
JPEG: Quality ignored (fixed 75 or cached only). Now: Configured quality applied. (
claude/openimp-quickfixes) -
HEVC T31: H.265 accepted but streams empty. Now: Real HEVC on the AVPU: VPS/SPS/PPS, slice headers, CABAC init as vendor. (
claude/t31-hevc) -
Encoder telemetry: Channel-stat struct one word short; bitrate not averaged; stack overflow in ChnStatQuery. Now: Vendor layout, real average, fixed. (
claude/openimp-quickfixes) -
T23 encoder: Vendor Helix worker only; worker zeroed all of rmem; wrong RPATH. Now: Per-worker rmem slices; native Helix encoder without vendor code. (
claude/t23-helix-worker-fixes,claude/t23-native-helix-2) -
Helix T20/T21/T30: Encoder issues on the Helix path. Now: Fixed. (
claude/t30-helix-fixes) -
OSD: Never drawn on T20/T21 (Helix path). Now: IPU OSD hook. (
claude/t20-osd) -
Motion detection: T20/T21/T30 always "no motion". Now: Real frame-diff IVS ported from T31/T23. (
claude/tseries-ivs) -
Audio out: Volume/mute ignored; partial OSS fragments dropped. Now: Applied; whole-fragment writes. (
claude/openimp-quickfixes,claude/t31-ao-fix) -
Framesource / VBM T21: Idle teardown freed the pool; later allocations failed in 23 MB rmem. Now: Pool parking and reuse. (
claude/t21-bringup) -
T31 HW JPEG: Software JPEG only. Now: Hardware JPEG path, hardened. (
claude/t31-hwjpeg-default) -
Audio AEC T31/T23: EnableAec only set a flag (T23) or returned fake success (T31). Now: Real WebRTC AECM (BSD-3) on the driver's speaker reference; errors when it cannot run; OPENIMP_AEC_STATS diagnostics. (
claude/aec) -
Rotation T31: SetChnRotate 90/270 returned -1. Now: Software rotation like the vendor (32x32 tiles) before OSD/IVS/encoder. (
claude/t31-rotate) -
Tools: No way to exercise T23 tuning on device. Now:
t23tune(show, max gain, IT max, DRC, defog, sinter, flip, max dgain). (claude/t23-tune-tool)
- Lifecycle hardening: locking around frame-channel ioctls, STREAMOFF races, buffers freed under a running ISP, last-close use-after-free, bounded tuning register access; rmmod oops fixed (3 clean cycles).
- Frame-channel DQBUF honours
O_NONBLOCK. - Tuning gaps: RGB coefficients as int16, AE ROI getter/setters and EXPR setter, AE histogram edges kept, correct isp-m0 gain lines, isp-w02 VIC error counters, SensorAttr, per-frame WaitFrame (
claude/t31-tuning-gaps).
- Exposure readback: Expr/EV/TotalGain were constants; now live values and vendor-format isp-m0 (
claude/exposure-readback). - Day→night kernel oops: a zeroed array was used as a wait queue; now a real wait queue (
claude/t23-tuning-wiring). - About 45 control IDs silently returned success; unknown IDs are now rejected; WB, CCM, DRC, defog, DPC, CSC, module control, live WB statistics, flip and anti-flicker wired (
claude/t23-tuning-wiring). - Night picture stayed purple: the CSC clip register write had lost its argument; night mono restored (
claude/t23-tuning-rest). - Max analog gain, IT max, SensorAttr, DRC/defog enable, non-compounding sinter (
claude/t23-tuning-rest); max ISP digital gain as a new AE stage and Bayer re-sync after sensor flip (claude/t23-flip-dgain); SetSensorFPS. - Static memory: oversized decompiler placeholder arrays shrunk; module 1,598 KB → 1,095 KB (
claude/t23-bss-shrink).
- No isp-m0 → vendor-format isp-m0; AE exposure read the table address instead of the value (
claude/exposure-readback). - Kernel oops on timps stop/restart: sensors released without unbind; fixed, 20 clean cycles (
claude/t20-stop-oops). - Max analog gain applied by the AE; line time reported instead of 0; scene-mode IT limit no longer lost (
claude/t20-ae-limits).
- Exposure readback, unreachable controls (0x2c–0x45), EV in wrong units fixed; day/night decided correctly (
claude/t21-exposure). - Night flicker (ISP gain cycling 6↔25): now the stock AE itself, lifted instruction-for-instruction from the vendor module, including the second AE stage.
- Noise: 2DNR read its parameters from a text table; denoise never followed gain; registers written without value; fixed.
- Night mono, colour blotches (lens-shading gains doubled per channel) and overexposure (fixed ADR curve) fixed; ADR and defog lifted from stock.
- Control dispatchers lifted from stock: anti-flicker, sensor FPS, readable brightness/contrast/saturation/sharpness, AE ROI/zone/histogram, flip.
- All on
claude/t21-image-fixes.
Goal: identical image behaviour, but cleaner unload/reload, less memory and checked inputs.
-
T23 (
claude/t23-robust): 10x timps stop/start incl. kill -9, 10x rmmod/insmod, 0 oops; two out-of-bounds writes fixed (2 KB and 18 KB past arrays); bss 434 → 180 KB -
T20 (
claude/t20-robust): rmmod while streaming correctly refused; 10x stop/start + 10x reload, 0 oops; decompile fixes (1 KB copy to address 0, AE reading a kernel address); all 53 user copies checked -
T31 (
claude/t31-robust): 10x reload with kill -9, vmalloc leak (252 KB/cycle) fixed, no stuck firmware thread; module 716 KB vs vendor 829 KB -
T21 (
claude/t21-robust): 10x stop/start + rmmod/insmod with a snapshot each time, 0 oops; root cause of the old reload oops: ISP statistics DMA still writing into freed buffers, now the ISP is reset first; sensor GPIO release; bss 259 → 106 KB
OpenIMP: T20 green flicker in the bottom rows fixed by filling the encoder padding rows (claude/t20-bottom-chroma; 0 green pixels in 30 frames). Faster IVS (claude/ivs-opt; T20 timps CPU 4.1 % → 2.7 % with motion on).
Aggregates: claude/open-tx-isp-all-4 and claude/openimp-all-4 (pushed); 58 merged single branches removed. claude/open-tx-isp-all-5 adds t21-robust and t31-robust-2 (T31: sensor flip with shvflip=1, unload leaks, lazy WDR buffers; MemFree drift per reload 460 → 45 KB); all four cameras flashed with -all-5 images.
Device-tested this evening (results on the cameras, pictures kept private):
-
T21 OSD on the first snapshot: The first snapshot after a (re)start or idle wake had no OSD: the IPU blend has no effect for about 2 s after a wake. OpenIMP now verifies the blend on a glyph pixel and withholds JPEG frames without a confirmed overlay; the first snapshot now carries the OSD (about 2 s later). The vendor stack (Ingenic driver + libimp, tested side by side) shows the same missing first-snapshot OSD, so this is beyond vendor. Root cause of the 2 s IPU delay still open. (
claude/t21-osd-first-jpeg(inclaude/agg-26)) -
T31 stack overwrites:
GetAfHistwrote 88 bytes into the 24-byte vendor struct (vendor kernel bug, now 24 bytes at the boundary);Get/SetAeAttroverran the caller by 80 bytes. Verified with guard arenas on cam-A: every AF/AE get writes exactly the vendor size, get/set round trips return 0. (claude/t31-af,claude/connect-round3(in agg-25)) -
T31 autofocus statistics: AF chain rebuilt (focus value, 15x15 zones, weights, histogram); metric reacts to the scene, invalid weights rejected, settings survive day/night. (
claude/t31-af) -
T23 gamma:
SetGammatakes effect at once (steep/linear curves visible, falling curve rejected, restore ok) on cam-B. (claude/t23-t31-connect) -
T20 ROI + chroma QP offset: Vendor EFE ROI registers rebuilt: in the H.264 stream a QP-51 region is visibly coarse, a QP-15 region fine; chroma QP offset 12 without colour shift. Note: an absolute ROI QP bypasses CBR (bitrate rose 1.4 → 9.9 Mbit/s), vendor semantics to be checked. (
claude/t1x-roi) -
Front crop / CSC on T10/T20/T21: Front crop (mid, top-left), invalid-value rejection and 10 on/off cycles pass on all three; CSC modes neutral in night mode. CSC mode 4 was green on T10/T20 (sign handling) – fixed, daylight check pending. (
claude/t1x-crop-csc(in agg-25)) -
T21 rotation with OSD: Rotation 0/90/270 via timps with correct colours and OSD, also across day → night → day. (
claude/t1x-rotation(in agg-25)) - T21 colours vs vendor: Two T21 cameras side by side under lamp light: open driver and Ingenic driver give nearly the same picture (AWB gains R 0x534/0x530, B 0x9d8/0x984); Bayer phase confirmed (RGGB). timps' flip path keeps correct colours. Open: magenta with the ISP tuning flip call and with re-setting AWB auto (image-function test), daylight comparison pending. (–)
-
T41 channel-restart hang: Restarting one channel while the other streams hung the SoC. Proven: hangs follow a live MSCA reprogram / no-op flip update request. Fix (flip update only on a real change, output kept like vendor on stream-off, address-only QBUF): targeted repro 35/35, start matrix 38/38, 40 min soak with diagnostics, client-mix load test running. (
claude/t41-chan-restart-hang(in agg-26)) -
T23 cam-B silent reboots: Cause found: right after a streamer start the day/night logic switches and re-asserts the mode several times; each set restarts channel 0, and the T23 driver hard-hangs on such a restart with live input (DMA into freed buffers after a process restart was also seen). Driver fix in progress (not yet proven on the device); the streamer will additionally get an option to keep the frame source enabled. (
claude/t23-chan-restart-hang(in progress)) -
Image-function test tool:
imgfx: one picture per image-changing IMP function per SoC with an automatic "set returned 0 but nothing changed" check; first run on T21. (claude/imgfx-tool) -
Boot guard follow-up: One
lsper client check instead of areadlinkper fd, comment fixes (upstream review). (thingino PR #1776) -
Feature matrix: New section "Missing / incomplete functions" per SoC and area. (
next)
-
T41 audio non-blocking read fixed (branch
claude/t41-ai-noblock, device test pending):IMP_AI_GetFramewith NOBLOCK now returns at once when no frame is ready: a capture thread fills a 16-frame FIFO (as already done on T31/T23), BLOCK callers keep the direct path, the frame timestamp is the capture time. Expected effect: the first frame of an RTSP session on T41 after well under a second instead of ~19 s.
- T41 hard hang reproduced: the camera freezes completely (both CPUs stop, the hardware watchdog resets it after ~60 s; no kernel panic) when one channel was stopped by the streamer's idle stop while the other channel kept streaming, and the stopped channel is started again — 3 of 3 times with a targeted sequence, while 38 cold starts without that overlap were clean. Suspected: per-channel MSCA state left behind on a single-channel stop and global scaler registers reprogrammed under a lock with interrupts off at the restart. A fix against the vendor code is in progress; this has the highest priority.
-
T41 slow first frame explained: video (SPS and IDR) arrives 0.07–0.27 s after PLAY, but clients wait ~19 s for audio: the streamer drains up to 512 audio frames with non-blocking reads while OpenIMP's T41
IMP_AI_GetFrameignored the non-blocking flag (512 × ~38 ms). A fix is in progress. - Streamer timestamps on cam-B (T23): frame intervals in the RTSP stream alternate between ~40 and ~80 ms instead of a steady 66.7 ms at 15 fps (no backward steps); ffmpeg reports many non-monotonic timestamps on that camera, other cameras show 0–3 per 10 s and no picture errors. Being measured together with the streamer maintainers.
- Main stream size: the streamer timps defaults to 1920×1080 even on a 1280×720 sensor (upscaling), prudynt and raptor follow the sensor size; reported to the streamer maintainers.
- raptor over the network: main and sub stream decode without errors, two parallel clients, reconnect, ~2.2 s to the first frame, HTTPS snapshots ~0.96 s. All three streamers (timps, prudynt, raptor) therefore run on the open stack over the network.
- T10/T20/T21 crop and CSC (code ready, beyond vendor): the vendor libimp has no front-crop or CSC API on these SoCs (headers of T20 3.9.0 and T21 1.0.33); OpenIMP now offers them with the T31 control IDs: CSC presets 0–4 (T21 CSC block; T10/T20 via the RGB-to-YUV calibration table), kept across day/night; front crop full-frame only so far, a crop/zoom (ePTZ) via crop + downscaling on T21 and on the T20/T10 sub channels is being implemented and tested.
- Unconnected functions audit: every vendor IMP/SU function per SoC is being classified (real, cache-only, stub, missing, error, driver gap) and checked against what the streamers call; these gaps come first after the current feature work.
- Soak policy: no daytime soaks while the driver is being finished; a 6 h soak runs overnight.
-
Aggregate agg-24 on the cameras: OpenIMP
claude/agg-24and open-tx-ispclaude/agg-24(T20/T10 optimised and vendor-matched firmware incl. the white-balance fix, T21 stability with rollback and AF getters, VBM parking and Helix back-off, quieter T20/T10 logs, new test runner; 58/58 host tests, vendor comparison 0 differences) were flashed on cam-A…cam-E, cam-I and cam-J: 30/30 snapshots, both streams, 0 oops each. The T20/T10 ISP module in RAM is now 325/323 KB instead of 477/475 KB. Short soaks (about 3 h) are used while features are still landing; a long soak comes before the release tag. -
Boot guard fix submitted (aperto PR #1773): the false trips came from the OTA script stopping the guard only after the root file system was already read-only, from guard state kept in
/overlayacross images, and from the stable check that only knewtimpsd. Now a boot is stable after 300 s when any process holds the ISP device nodes (900 s without any ISP client), the guard is stopped before flashing, and the first boot of a different image resets its state; a real crash loop still trips. Host harness 27/27; device test pending. - soc_vpu log fix submitted (aperto PR #1774): an encode wait aborted by a dying streamer is no longer logged as "wait timeout / start vpu failed"; real timeouts still are. Kernel builds for T21, T20 and T31; not yet run on a device.
-
raptor bug reported upstream: raptor-hal passed a 0x420-byte structure to
IMP_IVS_Get/SetParam, which writes 0x448 (T10/T20/T21/T30), 0x450 (T31–T41) or 0x458 (T23) bytes — a stack overflow on every SoC plus a wrong field layout. Fix proposed in gtxaspec/raptor-hal#15. - Streamers over the network (cam-G): prudynt: both streams decode without errors, two parallel clients, reconnect, ~2.1 s to the first frame; timps on the same camera: comparable (1080p instead of 720p main stream, 2.2–2.3 s to the first frame, snapshots 0.38 s on average). raptor is being measured.
-
T41: a spontaneous reboot occurred during a long sequence of RTSP client starts (second unexplained reboot of cam-F today); an investigation with a continuous kernel log runs. Code ready for device tests: sensor flip with correct register sequence (the gc5603 SDK driver OR-ed old and new flip bits) and automatic re-apply after a sensor restart (beyond vendor), a frame-source race fix for motion detection, ioctl polish (EFAULT for bad pointers, ioctl trace lines off by default,
/dev/aisphardened). Temper (3D noise reduction) is confirmed to work at high gain (frame-to-frame noise 4–6× lower than with temper off). - T10/T20/T21 rotation (code ready): sub-stream rotation 90/270 via the T31 frame-source path (up to 704×576, sizes multiple of 16; estimated 5–7 % CPU at 640×368/15 fps); the main stream is refused with a clear log line.
- White-balance gain ranges per SoC (for streamers): T10/T20/T30 8 bit (128 = 1.0, max 255), T21/T23/T31 Q8 with a saturating 14-bit register (max 4095), T40/T41 Q10 (max 16383).
-
prudynt and raptor run on the open stack: both streamers were built against the aggregate state and run on cam-G (T23) instead of timps, without any OpenIMP change: 0 of 149 IMP/SU imports missing for prudynt, none for raptor (one optional weak symbol); no vendor helper libraries needed (the open
ingenic-system-libs-neo/libaudioprocess-neopackages cover them). Main and sub stream, JPEG, OSD, 5 restarts and a 30 min run each without oops or VPU errors; CPU prudynt ~2.4 % without a viewer, raptor ~19 % in total including its audio encoder. Network RTSP/HTTP was not tested yet (streams were captured on the camera). Found outside the open stack: raptor's video daemon crashes when motion detection is enabled (it passes a 0x420-byte structure toIMP_IVS_GetParam, which writes 0x458 bytes — a raptor stack overflow that would hit the vendor libimp too); raptor's AAC build fails with the faac version in thingino; thingino disables prudynt's hardware motion detection on the open stack. -
Boot guard and other streamers: the guard only treats a boot as stable when
timpsdruns, so with prudynt or raptor its pending mark is never cleared and any unclean reboot disables the ISP stack. Together with the OTA case from noon this goes into a follow-up for the guard. -
T41 on the aggregate state: 10 module reloads, double open,
rmmodwhile open fails cleanly, ioctl fuzzing during a live stream (more than 50,000 unknown, oversized, NULL and short-buffer calls return only ENOTTY/EFAULT/EINVAL, one warning per device node, no oops), 1 h soak without findings. The T41 top-5 indirect-call fixes could only be exercised superficially on this camera and one unexplained reboot occurred during the first run with that module (not reproducible in three repeats); they stay out of the next aggregate until a run with a serial console. -
Next aggregate in preparation: OpenIMP and open-tx-isp
claude/agg-24combine the aggregate with today's device-tested branches (T20/T10 optimised and vendor-matched firmware incl. the white-balance fix, T21 stability with rollback and AF getters, VBM parking and Helix back-off, quieter T20/T10 logs, new test runner). A soak of the current aggregate runs on five cameras as the release candidate.
-
Soak ended after 17 h (on request): 6 cameras × 69 samples, 0 encoder/VPU errors, 0 oops, all snapshots 200, no reboots. The next aggregate (OpenIMP
claude/agg-23, open-tx-ispclaude/agg-23) was then flashed on cam-A…cam-G (cam-F rootfs only): 30/30 snapshots, both streams, 0 oops each. A new soak of this state runs on five cameras; it is the candidate for the first release tag. -
Boot guard vs. full OTA: after the OTA reboot the boot guard on cam-B treated the previous boot as a crash (
pendingmark left behind) and skipped the ISP stack. Fixed on the camera withS10isp-guard clear+load; cause (OTA reboot inside the 300 s window) to be fixed in the guard/OTA script. After every flash the guard state is now checked. -
T20/T10 optimised firmware device-tested:
-Osfirmware unit behaves like-O0on cam-I (T20) and cam-E (T10): same AE/AWB, exposure, colour, sharpness; 10 reloads each, 1 h / 30 min soak, 0 oops; module in RAM 482 → 325 KB (T20) and 479 → 323 KB (T10). - T20 vendor-matched firmware device-tested: in the default configuration the picture is unchanged (the firmware is parked after the first pass; per frame only CCM/saturation/LSC, Iridix, sharpening, noise reduction, sensor control and the simple AE/AWB run). What changes: timps controls that did nothing before now work on T20 (max analog gain, DRC/Iridix strength, manual white balance), and the OEM AE converges (it stuck at minimum exposure before). Found and fixed on the device: returning from manual to auto white balance kept the manual gains until a module reload (our simple AWB, not vendor code); now back to auto within 3 s. White-balance gains are 8 bit on T20 like the vendor (128 = 1.0); the streamer will clamp values above 255.
- T21 stability device-tested on cam-J: 20 reload cycles with streaming (some with SIGKILL of the streamer), failed open followed by rmmod, AF getters, and the new rollback after a failed open (fault injection: activated parts are released, the next open streams without reloading the module); VBM rmem parking 50 cycles with a stable largest free block. The "soc_vpu wait timeout" after killing the streamer is only a misleading log line from the aborted encode of the dying process; a small kernel patch makes it debug-level.
-
Test runner fixed: since 2026-10-02 the open-tx-isp host tests had not run at all (the stale T31 WDR test failed to build, so
make -k checkbuilt everything and ran nothing). New runner runs every test with a timeout and a summary and fails on unregistered tests; the WDR test was updated to the new buffer layout. Result: 57/57 onnextand all open branches green. The T20 vendor-comparison harness now also fails on lockstep divergences and covers CCM/hysteresis boundary cases (4 deliberate mutations are caught). -
Docs: new page
docs/PERFORMANCE.md(open vs vendor per SoC, every number with its source) and a consistency pass (T21 module 452 KB, T23 vendor AE default, build docs). - Other streamers: a test whether prudynt and raptor run on the open stack (instead of timps) is in progress on cam-G.
-
T20/T10 firmware compared with the vendor module (branch, device test pending): a differential harness (
tests/t20_fw/vdiff) runs the vendortx-isp-t20.koand our recovered firmware side by side in a MIPS emulator: lockstep scenario (day, dusk, night bank, manual exposure, AE modes, full API get/set sweep), per-function replay from recorded vendor machine state, and fuzzing of math helpers and API accessors. Before: 530 divergent scenario steps, 79 of 357 functions and 52 of 68 fuzz candidates differed; after 27 fixes: 0 (at-O0and-Os). Found and fixed, among others: the OEM AE divided by zero every frame (exposure target always 0, the reason the OEM AE stalled) and lacked histogram weights; the colour matrix used wrong source matrices; the Iridix gain dropped to 0 whenever exposure fell (exp2 of negative inputs); exposure partitioning used one walking accumulator instead of two; analog-gain hysteresis, long-exposure callback pointer, sharpening and flash init; 51 API setters stored nothing (e.g. manual white balance, gain, Iridix) and register API IDs were shifted by one. Most fixes also change the default path, so colour, dynamic range and sharpness may change visibly (towards the vendor picture). Independent review and A/B device tests with image comparison on cam-I (T20) and cam-E (T10) follow. 110 vendor functions are not reached yet (DIS, WDR-FS, SPI/sbus, IIR). -
T41 unresolved indirect calls, top 5 fixed (branch, device test pending): proc write path of the IVDC block now allocates and frees real DMA memory (before: a garbage return value was used as a CPU pointer and DMA address); IVDC interrupt delivers event 0x1000007 to the notify handler; sensor mode changes send event 0x200000d; suspend/resume call the real callbacks; the two analog-gain setters whose target struct was lost by the recovery now return with a one-time warning instead of a fake success. Verified against
libt41-firmware-1.2.6-720-4494. -
T21 stability (branches, device tests running on cam-J): module unload freed the tuning memory before the last function that reads it (NULL access on rmmod after a failed open; the vendor driver has the same order); AF attribute/metric getters read wrong addresses (reachable via ioctl) and now mirror the vendor; VBM pool rmem block kept per channel across disable/enable (
OPENIMP_VBM_PARK=0disables) and a 1 s back-off after a failed Helix create. -
New test cameras: cam-I (T20 Pan v1, jxf22) and cam-J (second T21 PC420) were backed up, measured on the vendor stack and flashed with the open stack (30/30 snapshots, 0 oops). A full OTA keeps
/overlay: an old/etcfile from the previous image can override new image defaults (seen on cam-J: sensor flip parameter), check/overlay/etcafter flashing. - Docs: consistency pass over README, changelog, matrix and wikis (T21 module size 452 KB everywhere, T23 vendor AE default) and a new performance page in progress; part of this preparation was drafted by another model and verified before use.
-
T20/T10 recovered ISP firmware builds optimised (branch, not yet device-tested): the decompiled firmware unit (
tx_isp_t20_firmware.c, also used by T10) had to be built with-O0. A new host harness (tests/t20_fw) runs it as a host binary through init, 239 frames, AE/AWB (simple and OEM), day/night and a tuning get/set sweep, and compares register traces, outputs and state between-O0,-Osand-O2: identical (375 of 517 functions executed). Against the old code the harness catches the problems (the-Osbuild crashes). About ten real reconstruction errors were fixed to match the vendor disassembly: dropped call arguments, a table overrun, state kept on the stack instead of static, a too-small stack buffer, an inline-asm jump without return, a missing return value. Also fixed:selftest_sensor_idjumped into data (oops on call), and the OEM AE target divided by the high word instead of the histogram population, i.e. by zero on every OEM-AE frame (the default simple AE was not affected). Module T20 590 → 409 KB, T10 587 → 406 KB, largest stack frame 624 → 280 bytes;TX_ISP_FW_O0=1restores-O0for A/B. An independent review runs; device tests on cam-C and cam-E follow after the soak. - Open findings from that work: the OEM AE path stalls at minimum exposure in the harness (cause open); four further misreconstructions in rarely used paths (exp LUT accumulator, flash init, I2C sample data, API buffer size reset). A function-by-function comparison against the vendor module in an emulator (as done for the T23 AWB) is planned.
-
T41 unresolved indirect calls: the recovery turned about 126 unresolved
jalrtargets into calls of a pure math helper (private_math_exp2); about 45 sit in compiled code (ioctl fallback, sensor allocation, suspend/resume, an interrupt handler) and do nothing today. No memory corruption, but possible functional gaps; a classification is in progress. -
Code fixes on branches (next aggregate): T21
tisp_af_set_attrwrote 20 bytes past a 4-byte object and one byte to a wild address, its refresh read from an absolute address (latent: no caller today); T41 temper reaches the 3D-noise-reduction registers (host test added; measurable only as frame-to-frame noise at high gain); OpenIMP tests share one fake rmem allocator. - T20 measured now (day mode): ISP module 466 KB, MemFree 54.9 MB (vendor measured earlier 52.3 MB), streamer CPU 9.1 %, system 17.5 %, RSS 4.3 MB, 21 threads, snapshot 0.34 s average. A fresh A/B against the vendor under identical light is still open.
- T23 AWB at cold start and at night – real bug, fixed (not yet daylight-tested): the "AWB HLIL ... ret=-61" lines were not harmless. At night/IR no zone falls into the colour-temperature weight mesh (all zones R/G ≈ B/G ≈ 1.2, dark/IR noise). The vendor AWB then applies the static white-balance gains of the tuning file (CT 5000); the open driver kept the last gains instead, e.g. warm 2300 K evening gains across every streamer restart. Invisible in the greyscale IR image, but a colour cast is possible when starting in day mode in the dark and at the night → day switch. In about one in three starts the first statistics snapshot also came 17 ms after stream-on with 1 of 225 zones filled and was used anyway. Fix: behave like the vendor (unit ratios on the static gains, CT 5000, not entered into the history) and drop a first snapshot with fewer than half of the zones. Checked bit-exact against the vendor AWB in an emulator with real night zones; on cam-G at night: no -61, 0 oops, snapshots 200. Side finding: with an IQ history window > 1 the open driver smooths in the ratio domain, the vendor in the gain domain (not relevant for cam-G's sensor, window 1).
-
Next aggregate built (not flashed): OpenIMP
claude/agg-23(review-3 fixes, small fixes, Paul's audio patch, Helix T20 test flake) and open-tx-ispclaude/agg-23(T23 cold-start MSCA fix, T23 log switch, ISP small fixes, Paul's patches, T41 prototypes and ioctl hardening, T23 AWB fix). Images for all eight cameras keep the memory split each camera runs today (rmem/ispmem unchanged). Flash and device tests follow after the 24 h soak. - Soak at 6 h: 0 restarts, 0 encoder/VPU errors, 0 oops. Low MemFree on the 64 MB cameras is page cache (9-14 MB reclaimable); unreclaimable slab 4-5 MB and the streamer's RSS 3.3-4.6 MB.
-
Docs: feature matrix rewritten to the current state; T10/T20 use the pre-Helix NVPU encoder (wiki corrected); T21/T23 have no H.265 encoder in vendor libimp or hardware (
docs/T23_H265.md); Helix wording aligned (frame drops fixed, rare single errno-5 error still open). - Housekeeping: merged and superseded branches removed from the forks; two leftovers from an early T21 bring-up branch (VBM rmem block parking, Helix create back-off) will be ported and tested on cam-D; a T31 LSC fix (mirror the shading mesh only for V flip) waits for a device test.
-
Soak: 5 h on the
apertoimages, all six cameras: 0 streamer restarts, 0 encoder/VPU errors, 0 oops, every snapshot 200. On cam-F timps was restarted a few times between 21:10 and 21:45 for timps tests (no reboot, no kernel change); this is noted in the soak log. -
T41 ioctl stack overflow fixed (open-tx-isp, not yet device-tested): commands that the typed handlers did not catch fell through into decompiled code that copied 8-80 bytes from userspace into 4-byte locals on
/dev/tx-isp,/dev/isp-fsNand/dev/isp-m0. Unknown or legacy commands now get onepr_warn_onceand-ENOTTY; every command libimp/OpenIMP uses is unchanged. Stack per call shrinks slightly (184 → 168 bytes main ioctl). Only T41 was affected. A custom ISP bin path (non-default) now returns an error instead of crashing. Device test plan (wrong sizes, unknown commands, repeat during live capture) is indriver/t41/README; it runs with the next aggregate image. -
T41 controls in timps: AE compensation and 2D noise reduction (sinter) are wired in timps main; gain and exposure caps follow (units:
AeMaxAGainlinear Q10,AeMaxIntegrationTimein sensor lines at the current frame rate). DRC, DPC, defog, HLC, BLC, WDR, CCM and gamma stay unwired because the T41 driver reports them as not supported. 3D noise reduction (temper) shows no measurable effect yet and is being checked in the driver. - T41 main stream: an early-morning matrix run saw an undecodable 1080p stream; that was before the rmem best-fit fix. The main stream now reports High profile 1920x1080 and decodes cleanly.
-
Release branch named
apertoeverywhere: the planned release branch is calledapertoin the Lu-Fi forks (README, CHANGELOG, wiki) and will be added asapertoin the original opensensor repositories, whosemainstays the original author's line. thinginoapertowill pin the date tag.
-
Upstream thingino
aperto(Paul's open ISP stack branch) now carries the open stack. Merged: #1746 timps tarball hash (fresh builds failed), #1747 OTA stage-2 copy on a full overlay, #1748 + #1752 kernel VPU/rmem fixes (open/close races, double free, cache-flushBUG(), bounded killable waits, validated ioctls, Helix residual interrupt), #1749 opt-in ISP boot guard, #1750 SC2336/T31 flip result (device-tested on a production camera), #1751 SC2336/T23 flip race, #1756 OpenIMP and open-tx-isp built from the Lu-Fi forks, T23 fully on OpenIMP. In theciaostreamer branch: #1737 JXF23 GPIO ownership, reset pulse on every detect after review. -
All test cameras run images built from
aperto(cam-A…cam-F, cam-H; 17:39-17:47): 30/30 snapshots, 0 oops, 0 VPU errors; a new 24 h soak started at 17:50 (3 h so far: no streamer restart, 0 encoder errors, 0 oops). The earlier all-22 soak ran 3 h without errors. -
T23 snapshot 503 on a second channel – root cause: stale buffer addresses stay in a channel's MSCA address FIFOs after a stream stops (the vendor clears them on STREAMOFF, the open driver did not); when a second channel starts on an already running core, the hardware works through the stale addresses first and sometimes never reaches the fresh buffers. Fix: clear the FIFOs and re-arm the queued buffers before the channel's MSCA start (
msca_fifo_rearm, default on): 260 cold-start cycles without a failure (before ~1-7 %). The "AWB HLIL ... ret=-61" lines at start are expected (no zone in the colour-temperature mesh while AE settles or at night) and are now info level. Soak pending before it entersnext. -
T23 log switch: Paul's idea adapted with an explicit allow-list of pure progress messages behind
t23_runtime_trace; all errors, unknown warnings and failed results stay visible. Boot/stream-start log 522 → 78 lines, module +3.5 KB. - Memory on cam-B: the slowly falling MemFree is reclaimable kernel cache (dentries/inodes); unreclaimable slab and the streamer's RSS are flat.
-
T41 control paths: AE compensation (
AeScenceAttr.AeTargetComp), gain and exposure caps (AeExprInfo:AeMaxAGainlinear Q10,AeMaxIntegrationTimein sensor lines) and 2D/3D noise reduction (Module_Ratioindex 0/1) now reach the ISP on cam-F (measured: comp 2 lowers the target 65 → 1, gain cap 8x holds 6.9x, sinter 255 cuts wall noise from ~7 to ~1). The T41 driver used to acknowledge unknown tuning IDs with 0; DRC, DPC, defog, HLC, BLC, WDR, CCM, gamma now return "not supported" instead of a silent success. Crop/rotation (I2D) still open. AE itself regulates correctly (it was saturated at max gain in a dark room). cam-F anti-flicker set to 50 Hz. -
Two new T23 test cameras on the open stack: cam-G (T23, SC1A4T) and cam-H (T23, SC2336P), full OTA with the boot guard, rmem 22 MB: both streams High profile, 0 oops, 0 VPU errors; rmem peak 17.3 MB and 19.0 MB. First devices with these two sensors on the open stack.
-
Branch layout in thingino: the open-stack work moves from the user's
ciaofork branch to anapertobranch based on upstreamaperto(Paul's open ISP stack branch, U-Boot 2013.07 like ciao);ciaowas reverted to upstream plus the streamer work. Streamer changes land only inciaoand are merged intoapertoautomatically. The upstream PRs were closed and will be resubmitted againstaperto; the 64 KiB U-Boot env fix stays local becauseciao/apertobuild U-Boot 2013.07. -
Pins: thingino will pin the Lu-Fi forks of OpenIMP and open-tx-isp by date tag from the
apertobranch (first tag after the 24 h soak). -
apertoin the user's thingino fork is live: upstreamapertoplus the open-stack layer (streamerUSE_OPENIMP, opt-in boot guard, DPC slider, VPU/rmem kernel patches as 0098-0105 on top of Paul's 0097, OpenIMP/open-tx-isp packages pinned to the Lu-Fi forks by date tag from theirapertobranch, T23 fully on OpenIMP without vendor blobs, sensor fixes for jxf23/T21, sc4336p/T31, sc2336/T31 and the sc2336/T23 flip race, fw_ota stage-2 fix, a corrected timps tarball hash) and a merge of the streamer branchciao(timps v1.9.31). A test image for cam-B builds (rootfs 20 KB below the 8 MB flash limit — tight). Streamer changes now land only inciao; a GitHub Action mergesciaointoaperto(or opens a PR on conflicts). -
Paul's upstream
apertopatches for OpenIMP/open-tx-isp (written against the opensensor repos) are being reviewed; the useful ones will be ported to the forks with Paul as author. -
cam-H (T23, SC2336P): lying upside down on the bench — image turned 180° via the streamer's hflip+vflip.
-
First snapshot after idle: a snapshot that wakes an idle main channel can time out once (HTTP 503 after 3 s) while the sensor/ISP spins up; reported to the streamer for a longer cold-start wait.
-
Paul's upstream patches reviewed: two ported with Paul as author — the audio capture read size now always covers whole driver fragments (OpenIMP; a real bug: at 48 kHz, 44.1 kHz or stereo the fixed 1280-byte read was not a multiple of the driver fragment and could hang the audio driver unkillably; tested on cam-A and cam-C, 8 k to 48 k) and the T20 scaler cap without crop (open-tx-isp). Not ported because the fork already does it better: sample-clock audio timestamps (fork stamps in the capture thread, ±0.1 ms), a 30 s give-up on missing frames (the fork fixed the busy loop and keeps the channel recoverable), an alternative T20 WDR oops fix (the fork's fix follows the OEM code). The soc_vpu TLB experiments are left out (off by default, no benefit shown). His T23 log switch is being adapted so that only informational messages are behind it; warnings and errors stay visible.
-
Builds switched to
aperto: one build tree, one per-camera user directory, one build script with the per-camera memory sizes (rmem/ispmem) decided today; T41 from anapertoworktree with the local U-Boot 2026 env fix. First full build of all eight test cameras fromapertois running.
-
all-22 on cam-A…cam-E (full OTA, 13:01-13:07): open-tx-isp
next+ T20/T10 memory pool off + kernel hardening + T20 AE restart fix; OpenIMPnext+ hardening + rmem peak logging + Helix logging; local kernel patch 0102 (Helix residual interrupt). 30/30 snapshots, 0 oops, 0 VPU errors on every camera; sensor pin refusesrmmodon cam-A and cam-D. These components are now innext(OpenIMP 2dc60dd, open-tx-isp f9939d64). -
Helix frame drops fixed: cam-B lost 4-6 pictures per hour because the bounded-wait kernel patch treated a residual Helix interrupt (status 0x100 after a finished job) as an error. With the residue ignored: 60 min, 0 errors. Upstream: #1736 was reduced to the safe patches (VPU open/close races, rmem cache-flush
BUG()), the bounded waits follow with the fix in #1743. - T41 1080p stream fixed: rmem was exhausted, so the main channel fell back to a broken software encoder (Baseline header, grey frames). Now: stream buffers sized like the vendor (1080p 0.95 instead of 2 MB), capture buffers allocated from the bottom and everything else from the top (best fit) so an idle/restart cycle no longer fragments rmem, the software fallback is refused for video with a clear log line, and an allocation failure logs a concrete rmem suggestion. cam-F: both streams High@5.1, 5 idle/restart cycles clean. cam-F now runs rev6 (rootfs) with rmem 26M and the 64 KiB U-Boot env + Bad-CRC guard; the env stays valid across reboots.
- T41 test plan: anti-flicker and VPU load ✅; QP limits live ⚠; AE compensation, gain limits, WDR, defog/DRC, noise reduction, DPC, scene, crop and rotation have no control path yet — being implemented in OpenIMP (the streamer now answers "unsupported" instead of a silent ok).
-
Motion detection v2 is on by default (
OPENIMP_MOTION_V2=0restores the vendor algorithm). The streamer exposes boxes, strength and suppress reasons via the versionedOpenIMP_IVS_MoveGetResultExAPI. - Memory with reserve: cam-E (T10) ispmem 8 → 6 MB (temper still fits, +2 MB for Linux); cam-A (T31) rmem 50 → 36 MB (+14 MB for Linux, 3 RTSP clients + MJPEG + snapshots without allocation errors). T23/T21/T20 stay as they are (reserve too small to gain anything). Rule: measured peak or computed worst case + ≥25 % and ≥2 MB.
-
Repos: 82 merged branches deleted; tracked files cleaned (privacy: real camera/room names, IPs and local paths replaced; ~16 MB of old notes, dumps and binaries archived or removed); new README with logo, badges and changelog;
main=nextat that time (later not kept in sync;nextis authoritative); documentation wiki at the OpenIMP repo. - 24 h soak of all five cameras started at 14:15.
-
+8 MB RAM on T20/T10: the 8 MiB V4L2-MMAP frame pool is now off by default (
isp_mmap_pool_kb=0, parameter kept); only the recovered firmware unit stays -O0 (module −140 KB). MemFree with streams running: cam-C 46.7 → 55 MB, cam-E 1.9 → ~9.7 MB. The open stack now leaves more RAM free than the vendor stack on T20. [open-tx-isp claude/t20-mem-pool] - Shortfall logging instead of silent degradation: the T20/T10 driver logs once with have/need/missing and a concrete value when reserved memory is too small (e.g. "set isp_mmap_pool_kb=8104", "set ispmem >= N KB" when temper/WDR would be switched off). OpenIMP logs the rmem peak at stream start and on every new peak, and on an allocation failure "raise rmem by at least M KB (suggest rmem=M)". cam-D peak: 18.4 of 23.5 MB. [claude/t20-mem-pool, openimp claude/imp-rmem-highwater]
-
Hardening (no measurable cost):
- Kernel: T31 proc writes bounded, VIC stop busy-wait bounded (~10 ms), AE handle wait with 2 s timeout; T20/T10 IRQ registered before its data was published (oops on an early interrupt) fixed. 10 min stream + restarts on cam-A, ISR load unchanged. [open-tx-isp claude/isp-hardening-3]
- OpenIMP: repeated driver errors are rate-limited (they could log every millisecond), silent
-1returns now logged, four NULL crashes, a buffer overflow in the module-chain dump, lost items on EINTR and an OSD size overflow fixed. [openimp claude/imp-hardening-2]
- T20 AE after a streamer restart: with a very bright scene the exposure could stay overexposed after restarting timps without reloading the module (sensor exposure cache and AE state survived the sensor reset). The cache is now invalidated on every sensor sync and the AE state is reset like on a fresh load; 5/5 restarts converge on cam-C and cam-E. [open-tx-isp claude/t20-ae-restart]
-
T41 in
next: the T41 unload/flip/BCSH/isp-m0 fixes are merged into open-tx-ispnext(9e5eb1ea); all six SoC modules build. Three module reloads on cam-F clean, module 80 KB smaller. The decompiler artefacts (addresses used as constants for AWB/LSC colour temperature, ivdc registers) were already fixed there. - Image checks: cam-B (T23) colour in direct sun with the vendor AE is neutral (R/G 0.94, B/G 0.93); cam-C (T20) white balance follows smart bulbs from 2200 to 6500 K (lower limit ~2300 K keeps very warm light slightly warm). Both matrix cells are now ✅.
-
thingino integration: the T23 OEM Helix helper option and the hybrid install (/opt/openimp-t23) are removed from the openimp package; T23 runs fully open. Kernel VPU/rmem stability patches and sensor fixes are being prepared as pull requests against thingino
ciao. - T41 U-Boot environment: boot scripts writing the environment with the old 32 KiB size broke the 64 KiB environment again (U-Boot fell back to rmem=30M). Restored; the 64 KiB fix needs a guard that refuses to write when the environment already has a bad CRC (otherwise a valid but minimal environment with a network boot command could be written).
-
T41 U-Boot environment fixed for good on cam-F: with
/etc/fw_env.configat 64 KiB the environment reads without "Bad CRC"; a guardedfw_setenvrefuses to write when the CRC is bad and otherwise leaves the environment byte-identical; after a clean reboot U-Boot uses it again (rmem=24M). -
Upstream pull requests (thingino
ciao):- #1736 kernel 3.10.14: VPU (Helix/NVPU) and rmem hardening — bounded and killable waits, no double free on close, validated user pointers and register windows, cache-flush direction/range checks.
- #1737 sensor fixes: T21 jxf23 releases only its own GPIOs, T31 sc4336p vflip reports the real result.
- #1738 64 KiB U-Boot environment for 20xx U-Boot plus a guard against writing over a bad CRC.
- #1739 ISP boot guard as an opt-in package.
- Feature matrix: boot guard shipped (T20/T23/T31), T41 H.265 and T23/T41 microphone verified; speaker/AEC cells stay untested on purpose (test cameras must not play audio). T41 open cells are being tested now.
-
all-21 on all five cameras (full OTA, 10:13-10:19): open-tx-isp
next1559bf60 (all-19 + sensor pin + T23 AWB fix), openimpnextb83ebbb (all-19 + IP delta read-back), timps main a34a5a2. 30/30 snapshots and 0 oops on every camera; sub stream 0 shifts on cam-B and cam-D;rmmodof the sensor is refused while streaming on cam-A and cam-D. -
nextbranches now track the tested aggregate (fast-forward only);aperto(release branch) and the first date tag follow after a clean soak. - Open issue (stability): cam-B (T23) logs a single "Helix run failed errno=5 / vpu error status=100" every few minutes on main or sub stream; one frame is lost, the stream continues. Present since before the sub-stream fix; root-cause work started [openimp claude/t23-helix-errno5].
-
Memory review (kernel + userspace): the ~5 MB MemFree gap to the vendor stack on T20 is fully explained by an 8 MiB V4L2-MMAP frame pool that the T20/T10 driver allocates in lowmem at load time and OpenIMP never uses (the vendor driver has no such pool); timpsd itself needs 3 MB less than with the vendor libimp. In work (stability and image quality first):
- pool off by default on T20/T10 (≈ +8 MB for Linux, ~20 % of the T10's RAM), parameter kept;
- T20/T10 driver: only the recovered firmware unit stays -O0 (≈ −140 KB);
- shortfall logging: the driver and OpenIMP will log once with have/need/missing and a concrete suggestion (ispmem=, rmem=, isp_mmap_pool_kb=) when reserved memory is too small instead of silently degrading;
- rmem high-water logging in OpenIMP as the basis for shrinking rmem per camera later;
- T41: five 16 KB arrays look like decompiler artefacts (constants read as addresses) — checked as a possible arithmetic bug (−80 KB). Later, only with image checks: smaller ispmem on T20 (11→8 MB) and T10 (8→4 MB), smaller rmem after the high-water data.
-
A/B vendor vs open stack (cam-C, T20, night, same scene, same timps a34a5a2; only libimp + tx-isp differ, both full OTA images):
Metric Vendor stack Open stack timpsd CPU (all threads) 25.2 % 10.5 % System CPU busy 33.5 % 15.3 % timpsd RSS / threads 6.8 MB / 30 3.7 MB / 21 Start to first image 3.0 s 2.5 s Snapshot latency (avg of 10) 0.45 s 0.20 s Bitrate main / sub 1248 / 261 kbit/s 1311 / 200 kbit/s MemFree 52.3 MB 46.9 MB The open stack needs less than half the CPU and answers snapshots twice as fast; MemFree is ~5 MB lower because the open driver module is larger and keeps more in RAM. cam-C is back on all-20.
-
Sensor module pin fixed on T21/T31/T41: the sensor i2c driver was registered with the ISP module as owner, so the pin held the wrong module; rmmod of a sensor during streaming caused use-after-free oopses on T21. Now
rmmodis refused while streaming, 0 oops (cam-A, cam-D); T20/T10 were already correct. [open-tx-isp claude/sensor-pin-all] -
T23 white balance flip with the vendor AE fixed: the stream start cleared one black-level channel (register shared with stream enable) and the vendor AE did not rewrite it, so AWB saw +50 % blue and jumped to ~10000 K. Black level is now rewritten after stream start: stable R/B, ~5300 K on cam-B. [open-tx-isp claude/t23-ae-awb-flip]
-
T31 IP delta read-back:
SetChnQpIPDeltanow updates the valueGetChnAttrRcModereturns, like the vendor; timps QA 8b on cam-A: 46 pass, 0 fail. [openimp claude/t31-ipdelta-readback] -
Release branches:
nextcreated in openimp (d894109) and open-tx-isp (4df00ba).
- all-20 on five cameras (full OTA): open-tx-isp claude/open-tx-isp-all-19 (all-18 + second driver review fixes), openimp claude/openimp-all-19 (sub-stream reference fix + T23 OSD stride fix), timps main a34a5a2 with USE_OPENIMP=1. cam-A/B/C/D/E: 30/30 snapshots, 0 oops, 0 VPU errors.
- Sub-stream fix confirmed: the T21/T23 640x360 sub stream no longer scrolls: 0 row shifts on cam-B and cam-D over 30 s captures. cam-B logged one isolated Helix error right after a channel restart during the post-flash check; watching.
- T23 OSD: the date/time text on cam-B is clean on main and sub stream after the IPU row-pitch fix.
-
timps QA script on cam-A (T31): quiet run (no backchannel tone, no reboot), with on-device checks: RTSP main/sub/UDP all pass (A/V drift < 0.07 s, monotonic timestamps); HTTP part 110 pass / 2 warn / 1 fail. Fail:
video1.i_bias_lvlreports applied but the encoder IP delta read-back stays -1 (under investigation). -
Motion detection v2 finished (opt-in, default vendor-identical): overnight shadow/override runs on cam-C and cam-B: false alarms cam-C ~7 → ~2, cam-B 2 → 0-1, IR switch at dawn 5 → 0; real events (car, passing shadows) still detected. Bounding boxes, strength, id, age and suppress reasons via the versioned
OpenIMP_IVS_MoveGetResultExAPI; +0.4-0.6 % CPU. Car headlights sweeping the scene can still trigger. [openimp claude/imp-motion-v2] -
Release scheme agreed: fixed branches
next(integration) andaperto(release branch, fast-forward only; originally planned under the namerelease) plus date tagsvYYYY.MM.DDonapertoin openimp and open-tx-isp, so thingino'sapertobranch can pin a tag instead of a SHA on a changing branch.
-
H.265 on T41: works: the HEVC channel now uses the AVPU path like T31 (it fell into a legacy probe that blocked the core and once rebooted the box). 1080p HEVC on cam-F decodes clean, 0 oops. A stuck AVPU job now times out after 2 s and resets the core instead of hanging the camera [openimp claude/t41-h265].
-
OpenIMP review fixes: complete O_CLOEXEC, eprc gets FRAME_END for dropped pictures, T31 Allegro RC lock, forced IDR after a YUV error, T20 MB-RC table bounds; T41 CBR overshoot fix now in the main line [claude/imp-review-fixes]. Optimisations: T20 MB-RC 590 → 58 KiB, no per-frame malloc/memset; libimp T31 −34 KB, T41 −20 KB, T21 −17.5 KiB text; eprc pow() → table (bit-identical).
-
CPU: profiling on cam-A/cam-D; optimised JPEG Huffman parsing (table), OSD cache invalidation, T31 EBSP copy: timpsd T31 8.7 → 7.9 %, T21 17.5 → 15.5 % [claude/imp-cpu-opt].
-
all-19 building: open-tx-isp all-18 + openimp claude/openimp-all-17 (0f6ca940) + timps main a34a5a2 with USE_OPENIMP=1 (timps now offers DPC/defog/DRC on T10/T20/T21 with OpenIMP). T41 image with H.265 in preparation.
-
Motion detection v2 started: opt-in: background model per grid cell, suppression after IR/exposure switches, blob grouping with minimum size/duration, bounding boxes and strength via a new versioned API; vendor output unchanged when off.
-
Differences to the vendor (current): less: T31 CBR without filler NAL, T41 tuning partly unverified, MB-RC opt-in only; deliberately different: H.265 rejected on T10/T20/T21/T23, T21 ring mode without P re-encode, stricter T23 front crop; more: see OPENIMP_BEYOND_VENDOR.md and OPENIMP_SOC_DIFFS.md.
-
all-19 flashed: on cam-A, cam-D, cam-E at 00:00 (open-tx-isp all-18 e8ed540c, openimp all-17 0f6ca940, timps main a34a5a2 with USE_OPENIMP): 30/30 snapshots, 0 oops; timps now lists dpc/defog/drc strength. cam-F got rev5 (H.265, reclaim fixes, timps main). cam-B and cam-C wait for the sub-stream fix.
-
Regression found: sub-stream corruption on Helix SoCs: on T21 and T23 the 640x360 sub stream shows P-frames predicting from a wrong reference (content jumps up 8–24 px, block artefacts), correlated with helix VPU error 0x100. Main stream clean; T31/T10 clean. Present in all-16/all-17; analysis in progress (suspects: reference-ring sharing on the small channel, eprc long-term reference changes). Workaround: use the main stream.
-
T41 env bug (thingino): after an OTA the firmware runs fw_setenv with a 32 KiB env while U-Boot 2026.07 uses 64 KiB → CRC mismatch → U-Boot defaults (rmem back to 30 MB). Env rewritten by hand on cam-F; permanent fix in the thingino ciao branch (fw_env.config 0x10000), not pushed yet.
-
T30 readiness without hardware: kernel module and OpenIMP build for a real T30 kernel; 810/837 functions match the vendor; H.264 command-list register order identical to the vendor (emulator oracle); fixed a missing isp_printf export (every sensor module would have failed) and an IMPEncoderCHNAttr ABI size bug (4-byte overrun). Missing: audio (being added via the T21 path, otherwise timps would not start), T30 rate controller, 11 tuning functions, Radix H.265. Report T30-READINESS.md.
-
Intensive driver review: 0 critical, 3 high (T23 4 MB snapraw buffer allocated at insmod, VIC error IRQs not restarting the VIC on T23/T41, T31 stats DMA freed while active), 8 medium, 14 low; previous fixes verified correct. Fixes in work.
-
all-17 on four cameras: open-tx-isp claude/open-tx-isp-all-17 e7c86107 / openimp claude/openimp-all-15 afd2d072 flashed 22:15–22:18 on cam-A, cam-C, cam-D, cam-E: 30/30 snapshots, MJPEG, MP4, 0 oops, boot guard not tripped. New: T23 module 622 KB (vendor 857), T31 711 KB (vendor 829), T21 452 KB (vendor 616); T20/T10 vendor-identical rate controller default with working quality_lvl/change_pos; DPC on T10/T20/T21, DRC and defog (Iridix floor) on T20, scene/colour effects on T10 (beyond vendor); MB-RC opt-in. cam-B waits for the review fixes.
-
T41 memory: rmem 30 → 24 MB via a new u-boot env partition image (old env backed up, MAC kept). MemFree 7.8 MB idle; 5-min stress with 3 streams + 2 snapshot loops: no OOM, no reboot, min 2.6 MB free (before: OOM after 17 s).
-
Kernel module review (independent): 0 critical, 1 high (T23: lifted AE/ADR/defog works not cancelled before freeing the stats DMA on unload → use-after-free), 6 medium, 9 low, plus optimisations (T23 .bss placeholder arrays cost up to several MB RAM). Fixes in work on claude/review-fixes-20261003.
-
Hardening: claude/isp-hardening-qbuf-pin: QBUF buffers must lie in the rmem window from the kernel command line (qbuf_guard=0 disables); the sensor module is pinned while the ISP is open (T23 device-tested: rmmod of the sensor while streaming is refused, 6 clean cycles). OpenIMP opens all device nodes with O_CLOEXEC (claude/imp-cloexec), so helper processes no longer hold /dev/isp-m0.
-
thingino ciao (maintained by the timps session): openimp pinned to the Lu-Fi fork (9eefbae, pushed; T23 OEM helper now opt-in, saves ~328 KiB); open-tx-isp and openimp pins to all-17/all-15 committed locally; timps 110ab65 (silent boot probe for day/night) pushed; boot guard available as an opt-in package (local).
-
Planned: 03:00: A/B measurement vendor vs open stack (CPU, RAM, rmem, start-up, snapshot latency) on cam-B and cam-D.
-
Feature matrix: 9 more cells closed: DPC on T10/T20/T21, DRC and defog on T20, scene/colour effects on T10, T41 video memory and stability. Remaining open: CCM/LSC readback on T10/T20 and Iridix on T10 (in work), T23 CCM in daylight, T20 AWB under artificial light (no artificial light at night; daylight A/B equal), T23 long-term hangs.
-
In work tonight: T23 review fixes (use-after-free on unload, defog allocations, front-crop overflow, ADR/AE locking, RAM placeholders) for the cam-B image; independent review of OpenIMP; CPU profiling and optimisation of OpenIMP on cam-A/cam-D; remaining matrix '?' cells on T31/T21 (audio input only); overnight soak log of all six cameras every 10 min; A/B measurement vendor vs open stack at 03:00.
-
H.265 on SoCs without HEVC hardware: on T10/T20/T21/T23 (Helix is H.264/JPEG only; Radix only on T30) OpenIMP now fails IMP_Encoder_CreateChn(PT_H265) with -1 and one clear log line, so streamers fall back to H.264 at once. The vendor returns 0 and creates an empty channel that never encodes (beyond vendor, documented). Host-tested, T21 and T23 libimp build; branch claude/h265-reject. T41: AVPU HEVC port from T31 in work (claude/t41-h265).
-
CCM/LSC readback on T10/T20: CCM/LSC now readable in isp-m0 on T10/T20; T10 CCM is updated every frame like the vendor and follows day/night, T20 mesh mirror follows hflip. T10 Iridix stays bypassed by the jxh42 IQ bank (vendor-identical); enabling it beyond vendor is a pending decision. Daylight per-CT sweep pending [claude/t1x-ccm-lsc-iridix].
-
all-18 content: open-tx-isp claude/open-tx-isp-all-18 e8ed540c / openimp claude/openimp-all-16 bec17c58, flashed 23:22–23:24 on cam-B, cam-C and cam-E: 30/30 snapshots, 0 oops; cam-B no longer carries the vendor libimp hybrid; cam-A and cam-D are still on all-17 and follow later. Contents: T23 review fixes (unload use-after-free, defog allocations, front-crop overflow, ADR/AE locking, 6 undersized objects resized to the stock size); hardening (QBUF rmem-window check, sensor module pinned while the ISP is open, O_CLOEXEC in OpenIMP); CCM/LSC readback for T10/T20; H.265 rejection on T10/T20/T21/T23.
-
T23 ADR/defog IRQ "dropout" was not a bug: timps stops the stream when there are no clients; with a permanent client the IRQ ran at 25 runs/s for 10+ min.
-
T41 H.265 in work: the channel is created, but there are no frames yet, and one test run rebooted the box; a timeout path is being added.
-
OpenIMP review: 0 critical, 3 high, 8 medium and 9 low issues plus 9 optimisations; fixes are in work.
- all-15 on all five cameras: cam-A, B, C, D, E flashed 20:20-20:30 with full OTA. Result: 30/30 snapshots, MJPEG and MP4 on both channels, 0 oops. The one exception is cam-D at 26/30, because a concurrent test restarted the streamer; it was not a crash. Aggregates: open-tx-isp-all-15 f3f40f9e, openimp-all-13 07afe9a, timps-all-15 cc8cded.
-
cam-B without the vendor libimp hybrid: /opt/openimp-t23 is gone, which saves ~328 KiB in the rootfs. Only the T23 hardware JPEG IMP_Decoder still needs the OEM worker; the worker is now optional (T23_BUILD_OEM_WORKER=1, openimp
claude/t23-no-oem-worker9eefbae). thingino will pin openimp to the Lu-Fi fork (9eefbae) for all SoCs, after a build check by the thingino maintainer session. -
Module size (
claude/open-tx-isp-size2a7214c75): emulator-identical, device-tested on cam-A and cam-B: T23 1,047 to 622 KB (vendor 857), T31 859 to 711 KB (vendor 829), T20 775 to 736 KB, T10 770 to 731 KB. T23 and T31 are now smaller than the vendor module. -
T21
ae_it_max_usnow acts (claude/t21-ae-it-max840a57ff): the GetExpr hook had been lost when the stock dispatchers were lifted, and the RANGE block of SetIntegrationTime was ignored. The vendor T21 also ignores RANGE, so this is beyond vendor; the user decision on it is pending. cam-D: cap 2000 us gives IT 68 lines and dgain 19 to 63; cap 5000 us gives 172 lines; cap 0 returns to 1125 lines. Caveat: a 4th module reload in the same boot led to segfaults and a watchdog reboot; under investigation. -
eprc macroblock RC ported (
claude/eprc-mbrc9e2bc3a): 0 deviations against the vendor in the emulator on T23 and T21 (20000 calls + 3x30 random scenes x 150 frames). The vendor uses SAS mode 3 (7 activity-class QP offsets, registers 0x40074/78/7c-84/8c/90), with no per-MB QP map. Opt-in:OPENIMP_EPRC_MBRC=1, andIMP_Encoder_SetMbRCworks per channel at runtime (on the vendor, SetMbRC has no effect and MB-RC always runs). Vendor bug: a class-table index reads past a 9-byte table into the stack; OpenIMP uses 0 there. Device test pending. -
T20/T10 OEM rate controllers as default (
claude/t1x-oem-rc-default-a13f05db18): code done, device test pending. The keys quality_lvl/change_pos act as in the vendor firmware. - timps USE_OPENIMP: build switch pushed (timps a2dccce, thingino ciao c55f73817). It changes nothing yet.
-
Stale cells refreshed (21:08): T23 AE (lifted vendor AE is the default, night test on cam-B passed), T41 flip (sensor flip registers follow live: hflip 0x022c=0x01, vflip 0x0063=0x02, off 0x00; daylight picture check pending,
claude/t41-matrix-fixes) and T41 white balance (black-picture incident not reproducible; timps calls no WB function on T41). -
T20 OEM rate controller default device-tested (
claude/t1x-oem-rc-default-a13): cam-C at 1200 kbit/s: CBR 1300 (P2 I-aware budget), VBR 1044, SMART 1019; quality_lvl 0/6 gives 1130/800 kbit/s, change_pos 50/100 gives 850/1210 kbit/s, also live via /control; decode clean, 0 oops. -
T21
ae_it_max_uskept: beyond vendor, the user decided to keep it. The docs (matrix, beyond-vendor list, SoC differences) are updated accordingly. -
MB-level RC per picture type (
claude/eprc-mbrca8b483a): registers 0x400c0/0x400c4 are now set per picture type like the vendor (T23 IDR 0x060404c1/0x61615921, P 0x030484c1/0x61615c21; T21 IDR 0x060407c1, P 0x030487c1). Device test is running. - T10 boot guard tripped: a flash reboot happened less than 300 s after a test restart, so the guard counted the load as unstable. The mark was cleared and the camera runs again. Idea: firmware updates should clear the guard's pending mark.
-
T41 module reload fixed and verified: rev2 image on cam-F: 10/10 rmmod/insmod cycles, refcnt 0, 0 oops; kill -9 of the streamer recovers 3/3. Root cause: a decompiled tuning-node helper overwrote .bss. Branch
claude/t41-matrix-fixes. -
T41 picture controls and rate control: brightness 255 gives Y 211, contrast 0 flat grey, saturation 0/255 chroma 0.1/7.1 (dark scene);
isp-m0in vendor layout (run mode, BCSH, flip mode, anti-flicker, AE); bitrate 400/1200/3000 gives 518/1195/2777 kbit/s over 30 s each (claude/t41-cbr-overshoot). Forced day/night switch test pending. -
T41 open points: the driver now writes the sensor flip synchronously (ret 0), but timps does not call SetHVFLIP live on T41 (under investigation). u-boot ignores the stored env (fw_env.config size mismatch), so changing rmem needs an env-partition image; user decision pending.
-
T21 vendor-identical eprc is the default: 0 oracle deviations; cam-D at 1200 kbit/s: CBR 1326, VBR 1096, SMART 1071. Branch
claude/eprc-t21-default. -
eprc complete (T21/T23): FIXQP, scene-cut IDR, runtime RC/fps/GOP/HSkip changes applied at the next IDR like the vendor,
SetChnHSkipon T21/T23; 0 oracle deviations. MB-level RC is not ported (separate task). Branchclaude/eprc-complete. -
T20 frame source: the snapshot debounce no longer polls the JPEG encoder: with 1 snapshot/s on both channels chn0 14.4 / chn1 15.0 fps (was 11.2 / 14.3). A sub-stream height of 270 is rounded to 272 with a warning (was: scaler hang). Branches OpenIMP
claude/openimp-t20-jpeg-align, timpsclaude/timps-jpeg-idle-nopoll. -
T10 noise reduction: Sinter/Temper strength acts (vendor: no-op): temporal noise 7.11 / 2.91 / 1.51 at temper 0 / 128 / 255, survives day/night. Branch
claude/t10-t20-nr-wdr. -
Unsupported keys (timps
claude/timps-unsupported-keys): a POST with only keys the SoC cannot apply returns 422not_supported_on_socwithok:false; unsupported keys are no longer persisted (audioCAP_ALC/CAP_SPKcount as not supported without the hardware path).IMP_ISP_QueryCapswas prototyped and withdrawn by the maintainer; not part of any release. -
T23 AE default: the lifted vendor AE becomes the default after the night test (pending at the time; done, default since all-20).
-
T31 Allegro CBR and T21 eprc device results (20:13): T31 (vendor Allegro core, default): CBR 1210 kbit/s at 1200 target and 2973 at 3000 (legacy controller 1511 / 3786, +26 % with large peaks); VBR 1163, CappedVBR 1177, CappedQuality 1174 at 1200; decode clean, 0 oops; no filler NAL written (filler=0 also at 3000). Branch
claude/t31-allegro-cbr. T21 eprc complete: SMART/CBR/VBR at 1200 kbit/s gave 1090/1305/1042; runtime HSkip N=4 gives an IDR every 4 GOPs; decode clean, 0 oops; a day/night switch does not trigger the scene-cut IDR (vendor condition: scene class 5). Branchclaude/eprc-complete. T23 eprc-complete device test is pending. -
Aggregate all-15: open-tx-isp claude/open-tx-isp-all-15 f3f40f9e, openimp claude/openimp-all-13 07afe9a, timps claude/timps-all-15 cc8cded (all without the withdrawn QueryCaps). New over all-14: smaller libimp and modules (T23/T20 rootfs back to the old layout), T31 CBR on the vendor Allegro core, eprc complete on T21/T23, P5 on the T21 revision, T20 sub-stream height and snapshot frame-rate fixes, timps 422 / unsupported keys not persisted. Flashing on cam-A, B, D, E started 20:2x; cam-C follows.
-
cam-B night test with the lifted vendor AE (default since all-14): switches to night (exposure 109303 > 4096), AE regulates (IT 1200 of 1436 lines, analog gain 133 of 160, gain reported). The all-11 problem (gain reported as 1x, never night) is gone. One night→day→night flip in the first 90 s after start, the same timps boot-measure issue as on cam-C; a timps fix is in work.
-
timps USE_OPENIMP: build switch pushed to timps main (a2dccce) and thingino ciao (timps.mk); it changes nothing yet. OpenIMP-only features are enabled under it once device-tested and present on timps main. Two premature changes were reverted: the vendor firmware does honour T21 ae_it_max and T10/T20 quality_lvl/change_pos, so we fix the open stack instead (T21 AE limit fix and T20/T10 OEM rate controller as default are in work).
-
Per-SoC difference list: new docs/OPENIMP_SOC_DIFFS.md: OpenIMP vs vendor per SoC in both directions, with API signatures and device-test status.
-
T10 rate control: super-frame fix default: the super-frame fix (P1) is now the default inside the T10 OEM controller (
OPENIMP_T10_RC=1;OPENIMP_T10_RC_SUPERFRM=0restores vendor-exact behaviour). cam-E at 1200 kbit/s: 450 to 822 kbit/s, re-encodes 800 to 0, CPU 8.3 to 5.5 %. Branchclaude/t10-rc-superfrm. -
T20 rate control: I-aware P budget: P2 is the default for CBR (
OPENIMP_T20_RC_IAWARE=0= vendor;=1forces it for VBR/SMART too). cam-C: CBR 1583 to 1300 kbit/s at 1200 (stats 1244). VBR stays vendor (with P2 it fell to 866). Branchclaude/t20-rc-iaware. -
T31 rate control: the Allegro rate-control core is the default (
OPENIMP_T31_RC_CORE=legacyrestores the old one; CBR stays legacy). Branchclaude/t31-capped-quality. -
T23 fixes: brightness/contrast/saturation/hue now act (they were reset on every stream start); T10/T20
ae_it_max_usnow limits the AE; T23 sub-stream rotation 90/270 works via the native encoder; T23IMP_Encoder_YuvSetCropimplemented (host-tested only, timps does not call it); T23 contrast/gain feedback: the driver takes the low byte like the vendor and OpenIMP remembers the gain before sending (cam-B: user contrast 100 stays). Branches open-tx-ispclaude/t23-bcsh-aeit-fix, openimpclaude/t23-yuv-native-aeit. - T21/T31 contrast: OpenIMP sends the user contrast instead of the default 128 and remembers the gain before sending (commit 6ba6f17). Code done, device test pending.
-
T10 build: duplicate
isp_printfexport fixed in open-tx-isp (no local patch needed). -
Boot guard for T20, T23, T31:
S10isp-guard+isp_open=autoadded (local image overlay, ships with the next image, not on the device yet). A load counts as stable after 300 s uptime with timpsd running; otherwise the next boot skips the ISP/sensor modules and timps untilS10isp-guard clear. -
T21 smaller and faster: kernel module 760 to 494 KB (RAM unchanged); the lifted AWB now needs 0.95x of the vendor instructions (was 1.41x), output bit-identical, cam-D isp_fw_process -10 %. Branch
claude/t21-size-awb-opt. -
T41 (cam-F): the bitrate setting had no effect because the OpenIMP T41 controller discarded a negative bucket level; fixed (
claude/t41-cbr-overshoot), host-simulated, device test pending. In the dark the gc5603 shows strong column noise, so about 10 Mbit/s even at QP 45 (separate ISP issue). The spontaneous reboot is an OOM: rmem=30M leaves 29.6 MB for Linux; 3 parallel streams plus snapshots exhaust it and the watchdog resets. Proposal: rmem about 24 MB (the vendor image uses 19 MB). After an OOM kill the sensor stays registered and AddSensor returns EBUSY until reboot; a driver fix (claude/t41-sensor-rereg) crashed on the first device load and is being analysed. The black picture after a WB POST was not reproducible (timps does not call any WB function on T41). -
T23 matrix gaps (cam-B,
claude/t23-matrix-gaps, open-tx-isp, device-tested): front crop now uses the vendor path (960x540 crop OK); the MASK control returns -EINVAL exactly as the vendor does (no stock handler). The lifted vendor AE now honours anti-flicker and reports AE luma, so backlight/highlight/AE comp work with it (backlight 10: luma 68 to 112, highlight 10: 48). Making the lifted AE the default is a pending user decision; as default, AE IT max has no effect, exactly as on the vendor. Anti-flicker device values: vendor AE 50/60/off gives IT 720/900/971, HLIL AE 720/600/711. Not bugs: IR cut/LED auto night (timps auto switches IR cut, ir850 and mono, and back) and the JPEG size (q75 tables are the IJG tables, size matches libjpeg, scene-driven). -
T41 module reload (cam-F): a rebuilt tx-isp-t41.ko with the sensor re-registration fix (
claude/t41-sensor-rereg, not in any aggregate) crashed on insmod twice (rc 139) and the box needed a power cycle. Likely cause: rmmod+insmod of tx_isp_t41 is not safe in general; a control test with the installed module is pending. The T41 kernel has no netconsole/pstore, so an oops cannot be captured after the network dies. - T10 module reload (cam-E): rmmod/insmod of tx_isp_t10 gives 'Failed to get csi clock -22' and a NULL oops in isp_csi_set_clk at stream start; module reload is unsafe on T10, the boot-time load is fine.
-
Noise reduction strength (T10/T20,
claude/t10-t20-nr-wdr+ OpenIMPclaude/t20-nr-strength): the vendor firmware renormalises the scaled Sinter/Temper table onto the IQ min/max, so only 0 acts. Now strength acts: T20 device-tested, temper 0/64/128/200 gives 0/42/85/132, sinter 0/17/35/69 at high gain, 128 = IQ, kept across day/night. T10 device test pending (reload oops). Default for T10/T20 is a pending user decision. T31: SDNS (H-S regs 0 to 0, 255 to 15), DPC thresholds and impulses vendor-identical on cam-A; T10 isp-m0 WDR flag fixed. - Other results: T20 daylight A/B of simple AWB vs vendor chain: gains 492/393 vs 488/395, neutral ROIs within 0.007, both converge in under 4 s, tungsten test open. T31 anti-flicker with a 22 ms IT cap: IT 1000/900/750 lines for off/50/60 Hz, gain compensates, daylight test pending.
-
T23 dynamic ADR and defog lifted (cam-B,
claude/t23-adr-defog, 17:50): lifted from the vendor module includingtisp_defog_soft_process; 44/44 emulator cases are identical. The core ISR now dispatches the ADR/defog IRQ callbacks (ADR was static before). Device: DRC 255 gives meanY 158 vs 119, DRC 0 gives 114; defog 255 and day/night switching work, 0 oops. Module parametersource_adr_oem=1is the default,0selects the old static path. -
T23 module size (cam-B,
claude/t23-ko-size, 17:50): 1,282,492 to 1,071,956 B stripped (tparams zero tail moved to .bss,-mno-pdr); stream OK on cam-B. The ADR lift adds ~138 KB; with both branches merged the module is ~1.21 MB. -
T10 module reload (cam-E,
claude/t10-reload-safe): 5 rmmod/insmod cycles while streaming, 0 oops. The earlier 'csi clock -22' oops came from a module built against the T20 kernel tree; the T10 build now refuses that with #error. -
T41 module reload (cam-F,
claude/t41-reload-safe): cause found statically. tx_isp_fs_remove freed the channel array while the framechan0..2 misc devices were still registered, so the next insmod oopses in misc_register. Four static work items were also not drained on unload. The fix is not yet device-tested. Testing needs the box booted without the old module (boot guard isp_open=manual), because the old module's unload leaves the bug behind. - User decisions (2026-10-03): (a) T23 default AE becomes the lifted vendor AE (vendor default), after a night-switch test in the dark that is still pending. (b) T20/T10 Sinter/Temper strength acts by default: 128 = the IQ table, so the default picture is identical to the vendor; other values act, which goes beyond the vendor.
-
All-14 aggregates flashed (19:20): open-tx-isp
claude/open-tx-isp-all-14(de10fed6), OpenIMPclaude/openimp-all-12(787d534), timpsclaude/timps-all-14(9490547). Flashed 2026-10-03 ~19:07 on cam-A, cam-C, cam-D and cam-E (full OTA). cam-A, cam-D, cam-E: 30/30 snapshots, MJPEG, MP4 on both channels, 0 oops. cam-B waits for a smaller rootfs; cam-F stays on -all-13 (image rev 1). -
Image size fixes: the rootfs of T23/T20 had grown past 0x4E0000.
claude/openimp-size(2040a03, gc-sections) andclaude/open-tx-isp-size(15232deb, strip local symbols): T23 libimp 774 to 726 KB, T20 libimp 694 to 594 KB, T23 module 1,211 to 1,047 KB, T20 module 819 to 775 KB; rootfs back to 0x4DE000 (T23) / 0x4DD000 (T20). Further driver shrinking is in work. -
T31 CBR on the vendor Allegro core:
claude/t31-allegro-cbr: CBR now uses the ported vendor core too (20 trace files + 72 x 400 random frames state-identical). Deviation: no filler NAL is written (the HRD model counts filler bits like the vendor, but a static scene's CBR stream stays below target where the vendor pads); the filler value is per picture like the vendor. Device test pending. -
eprc QP-down limit (P5) in the T21 vendor revision:
claude/eprc-t21-qp-limit, opt-in (OPENIMP_EPRC_QP_DOWN1/2). Device test pending. -
T41 module reload: root cause: a decompiled tuning-node helper used the 4-byte module parameter
ivdc_threshold_lineas a struct cdev and overwrote about 60 B of .bss includingtx_isp_bringup_level, sotx_isp_exit()bailed out early and left platform drivers, misc devices, IRQs and kthreads registered. Fixed inclaude/t41-matrix-fixes(b4ef2cf8), device test pending. T41 image rev 1 (flashed): isp-m0 now in vendor layout; reload still failed with rev 1. - Feature matrix: ? cells filled: results of the evening matrix tests (audio input only, no sound played): T31 AWB presets and IR cut/IR LED device-tested; T31 CCM/LSC follow day/night and flip; T20/T10 ISP state not observable; defog/DPC on T10/T20/T21 have no control path (keys accepted but ignored); scaler tested on T10/T20/T21; T20 snapshots on both channels cost video frames; audio input device-tested on T10/T20/T21/T31.
-
Feature detection: the static caps matrix stays (agreed with the timps session);
IMP_ISP_QueryCapswas withdrawn by the maintainer.
-
T31 rate control: vendor core ported: the Allegro VBR/CappedVBR/CappedQuality controller is ported instruction by instruction and matches the vendor code frame by frame in an emulator (2,100 trace frames + 72 random traces, 0 differences). cam-A at 1200 kbit/s: VBR 1163, CappedVBR 1177, CappedQuality 1174 kbit/s (old controller: 732 / – / 2030). Becomes the default;
OPENIMP_T31_RC_CORE=legacyrestores the old one; CBR stays on the old controller for now. -
T21 rate control: vendor-identical: the T21 vendor controller (an older eprc revision) is ported; 0 differences in 873 oracle frames and 360 random scenarios. cam-D: CBR 1326, VBR 1096, SMART 1071 kbit/s at 1200. Opt-in via
OPENIMP_T21_EPRC=1; a bug found on the way also affected T23 (CBR with very short GOPs). -
T20/T10 rate control: kernel patch 0101 lets the vendor T20 controller read its statistics registers (the hardened kernel denied it). cam-C re-flashed: CBR 1435 (+19 %, the vendor controller itself overshoots), VBR 1329, SMART 983 kbit/s — SMART was treated as VBR before, fixed. Opt-in via
OPENIMP_T20_RC=1/OPENIMP_T10_RC=1. - Better than the vendor: rate-control study: an offline simulation of all ported controllers found six improvements. Device-tested on cam-E: the T10 VBR super-frame fix stops the vendor's double encoding of nearly every frame (re-encodes 800 → 0, CPU 8.3 → 5.5 %) and becomes the default inside the T10 controller. Being built: an I-frame-aware P budget against the T20 overshoot (opt-in). The eprc QP-step limit showed no measurable effect in a day scene and stays opt-in.
- Fixes from the feature-matrix tests: T23 brightness/contrast/saturation/hue now act (they were reset on every stream start); T10/T20 max integration time now limits the AE (cam-C 300 µs → 10 lines); T23 sub-stream rotation 90°/270° works with the native encoder (the vendor helper process is not needed). 56 of 105 open matrix cells tested.
- Open: T41 (cam-F): bitrate setting has no effect (~8.2 Mbit/s), one unexplained reboot, white-balance POST once gave a black picture — in work.
- All six cameras on open-tx-isp-all-13 / openimp-all-11: flashed 14:04–14:20: 30/30 snapshots, MJPEG and MP4, 0 oops; reference-buffer sharing active on T21/T23. cam-F (T41) now boots our driver and OpenIMP from flash (kernel and rootfs flashed separately, the full image does not fit RAM for OTA).
-
Reference-buffer sharing on by default for T21/T23: the artefacts came from a missing wrap byte in the ring register; with it the picture is clean. Saves ~1.4 MB video memory;
OPENIMP_REF_SHARE=0turns it off. -
Rate control: cam-A T31: plain VBR now closed loop (1514 kbit/s at 1500 target, before 280). cam-B T23: vendor eprc controller with the vendor's CreateChn clamps — SMART 1141, CBR 1253, VBR 1255 kbit/s at 1200, decode clean (old mapping: 3203). cam-D T21: eprc approximation behind
OPENIMP_T21_EPRC=1(CBR 1338 vs 570 with the old controller); a vendor-identical T21 port is in work because the T21 vendor controller is an older revision. T20/T10: vendor controllers ported, bit-exact in the emulator (200×150 frames); on cam-C CBR overshoots 25 % because the hardened kernel denies one statistics register read — kernel allowlist fix in work, default off until then. - T31 CappedQuality decoded: differs from CappedVBR in two places: it keeps improving quality while at max bitrate and it never falls into the emergency max-QP after a scene change. A full port of the vendor rate-control core is in work, selectable and verified frame by frame in an emulator.
-
Scene mode and colour effects on T23 and T31: driver and OpenIMP support; device-tested on cam-B and cam-A: B/W, vivid, negative visible, invalid values rejected, 0 oops. timps gets
image.colorfx/image.sceneplus live fps/GOP (built, device test with next images). -
Docs for streamer authors: new
docs/OPENIMP_BEYOND_VENDOR.mdlists everything where OpenIMP behaves beyond or differently from the vendor libimp, with env switches and how to integrate or disable it. Rule: only device-tested features go in. -
Branch cleanup: forks pruned after a bundle backup: open-tx-isp 56 → 6 branches, openimp 13 → 10; the 50 old non-claude branches were unchanged copies of upstream. Test-report branches moved to
docs/test-reports/.
-
T23 daylight green cast — found and fixed (
claude/t23-day-color, device-tested on cam-B, not flashed yet): every on-demand snapshot restarts the stream, and our driver reset the white-balance gains to 1× on every stream start, so the snapshot was taken before AWB had re-converged. The vendor keeps the AWB state across stream restarts; now we do too. A side-by-side run of the original vendor stack in the same sunlit scene gave neutral colours and confirmed the cause was ours; the register comparison also corrected three stream-start values (top 0x1c, GIB 0x1008/0x1010). The HLIL AE now reaches correct exposure ~4 s after a driver reload (was ~2 min). -
Vendor T23 uses reference-buffer sharing by default: measured on cam-B with the vendor stack (ring bit set, luma ring = picture + 256 lines); the vendor libimp forces it on for ≤1080p. A register capture is being used to align our port (
claude/t23-ref-ring); the T21 opt-in stays off meanwhile. -
Rate control (
claude/rc-modes): T31 CappedVBR/CappedQuality now run the closed-loop regulator with the vendor's PSNR cap (42 dB); T20/T21 report the vendor-clamped RC values. In work: T31 plain VBR closed loop by default and vendor defaults, T23 live readback, which RC writes take effect on T10/T20/T21, and vendor-equal SMART on T23 (eprc controller + long-term background reference). -
AVPU kernel module review (outside review, verified): fixes for a minor-number leak, a use-after-free on sysfs unbind, an uninitialised list mutex and the flush range (
claude/avpu-review-fixes); kernel patch 0100 makes the rmem flush ioctl reject invalid directions instead of crashing. cam-A: reload, 3× kill -9, 5× rmmod/insmod, 0 oops. -
New T41 test camera (cam-F): OpenIMP runs against the vendor T41 driver with video, JPEG, OSD and motion detection (
claude/t41-libimp): a kernel oops from the cache flush was fixed (the T41 kernel expects a physical address), motion detection gets frames without a viewer. timps CPU ~10–12 % vs ~27 % with the vendor libimp. Our T41 driver needs an image for testing (vendor module oopses on unload); image being prepared. - timps: the OSD clock in the first snapshot after an idle period was stale (minutes to hours) — fixed (redraw on idle→active), comes with the next images; T23 access-unit limit 2 MiB + 64 KiB.
-
Feature matrix (English) now in
docs/FEATURE_MATRIX.md/docs/feature-matrix.html.
Done and device-tested, waiting for the next aggregate (-all-13):
-
T31 privacy mask (
claude/t31-privacy-mask): the ISP mask block is now implemented like the vendor driver (4 rectangles per channel, YUV fill, follows mirror/flip). Emulator: 400/400 random sequences register-identical to the vendor module. cam-A: black and red rectangles at the right place and colour, get/clear OK. OpenIMP converts RGB mask colours to YUV like the vendor libimp (claude/t31-mask-rgb2yuv). -
T21 tuning controls (
claude/t21-tuning-controls, beyond vendor — the vendor kernel ignores them): scene is stored, colour effects black-and-white / vivid / negative work, Sinter and Temper denoise strength act on the hardware, getters return what was set; defaults stay vendor-identical. timps'sinter_strengthnow works on T21 (claude/t21-sinter-strength, 128 = vendor picture). cam-D: effects and denoise visible, 0 oops. -
T21 debug parameters removed (
claude/t21-drop-debug): module 13.8 KB smaller. -
T20/T21 encoder error limit (
claude/helix-error-limit): after 3 failed pictures the encoder is re-created, after 2 fruitless re-creates the channel stops instead of waiting 20 s per picture. cam-C and cam-D soak OK. -
T23 RC defaults (
claude/t23-rc-app-defaults): app value 0 for QP step / static time / change position now means the vendor default (3/15/2/80) instead of "off", taken from the vendor libimp 1.3.0. - cam-A sensor driver: vertical flip no longer reports a false error (local thingino patch).
- timps: T23 access-unit limit raised to 2 MiB + 64 KiB to match the encoder window, so large night IDRs are no longer dropped (other session, after review).
Investigated, not adopted:
- Reference buffer sharing (vendor BUF_SHARE_CFG): only the T21/T23 Helix hardware has the ring mode. On cam-D it saved ~1.4 MB video memory but produced magenta/green reference artefacts in the first seconds; stays off while the cause is analysed.
- timps flip reset on client connect: not a bug — timps re-applies the live config value; the test had written the register behind timps' back.
In work:
- T23 by day: with the lifted vendor AE exposure is right at once and AE compensation/highlight work, but the picture is green; with the HLIL AE the first ~2 minutes after a driver reload are overexposed. Cause under analysis (CCM bypassed since it follows the IQ bank). The lifted AE becomes default only after this is fixed.
- New T41 test camera (vendor stack): build fixes for the T41 driver and an OpenIMP T41 build are being prepared.
- Aggregates -all-10 / openimp-all-9 and -all-11 / openimp-all-10 flashed on all five cameras (incl. cam-A, which moved up from -all-5). Checks on every camera: 30/30 valid snapshots on both channels, MJPEG and both MP4 streams, 0 oops, 0 encoder errors. -all-11 was flashed staged (cam-D and cam-C first) because it carries a new kernel.
- Vendor helper libraries gone: libimp now contains the two logging functions it used from libalog; libalog/libsysutils are no longer built into the images.
- Kernel soc_vpu (patch 0099): requesting a busy VPU sleeps instead of busy-waiting up to 200 ms; on T20/T10 an encoder error interrupt now ends the wait immediately (with reset) instead of running into the timeout; per-instance bitstream counter on Helix.
- T23 motion detection fixed: after the last sub-stream viewer left, capture buffers stayed parked and motion detection got no frames (empty motion grid in the web UI). Frames are now recycled for callback-backed pools too.
- T23 memory: JPEG shares the H.264 bitstream area like the vendor pool (1.44 MB less video memory, main window back to 2 MiB).
- T23 image pipeline: DPC and CCM follow the IQ bank flags like the vendor (less night noise); a block whose parameters fail to load on a day/night switch is bypassed instead of running with the other bank's values; user bypass bits survive day/night switches.
-
T23 vendor AE (lifted, source_ae_oem=1): first picture after a stream restart no longer black, day/night refresh and gain limits wired like the vendor, AE compensation works at night. Default briefly switched to it in -all-11, but the driver then reported a constant 1× gain, so timps never switched cam-B to night — reverted in -all-11b (HLIL AE default; the vendor AE became the default again in all-20). Follow-up branch
claude/t23-ae-oem-exportexports the lifted AE's live gain/EV exactly like the vendor getters, feeds AWB/CCM/BCSH/ADR/Defog with the real EV, and repairs ADR/Defog state that the reconstruction had mapped onto unrelated memory (an event table, a CLM LUT word, a module parameter). Verified on cam-B at night in both AE modes; default stays HLIL until a daylight test. - T21: colour-temperature updates only when CT moves by more than 50 K (emulator: 62 % fewer register writes, same final state); module reload on cam-D OK.
- T20/T30 memory: JPEG bitstream buffer 1 MiB instead of a frame-sized buffer (cam-E −328 KiB; more on 1080p). Allocating encoder buffers at channel creation was measured to raise the peak and stays opt-in.
- Encoder diagnostics: one log line with the effective rate control per channel; out-of-range QP/fps values are clamped with a warning instead of silently replaced.
- JPEG robustness: if the encoder is busy or video memory is short, the last JPEG is delivered again instead of blocking; one startup warning when pools plus fixed buffers exceed video memory.
- T23 reconstruction audit (-all-12): a call-graph audit of all mis-resolved memory accesses in the decompiled T23 code found none on the default path; every reachable one (ops-table ISR and IVDC ISR counters, sensor release list walk, CCM state, an AE histogram stack overflow, AF parameter copies, MDNS/DPC/mask state) now targets the vendor's variables. cam-B: 3 module reload cycles and 90 snapshots, 0 oops; flashed 05:54.
- In work: T20/T21 encoder error limit (re-create after 3 failures, stop after 2 re-creates) waits for a device test.
-
T10 picture drifting diagonally fixed (
claude/t10-drift-fix, OpenIMP): the T10 encoder added the 16-pixel reference border twice, once for motion prediction and once for the deblocker output, which adds the border itself. Every P frame was predicted from a reference shifted by 16×16 pixels, accumulating until the next I frame (16 px after 1 frame, 160 px after 10). Now the border is added only for the prediction read, like the vendor command lists show. The overrun past the reference planes measured the evening before was the same bug. cam-E: shift 0 on both streams, 0 decode errors, flashed 01:50. Day/night switch on T10 not yet tested. -
T21 white balance at dusk (
claude/t21-awb-hyst, kernel): hysteresis band (default 10 %) on the three AWB brightness thresholds, so the parameter set and the low-light register stop toggling at dusk (emulator: 39 switches → 0 in 40 frames). While in night mode AWB is frozen and the day gains are restored after night→day, so the first day picture no longer starts orange from IR light. Both settings at 0 give the vendor behaviour (10/10 scenes identical). cam-D: night checks OK, 0 oops; dusk itself still to test. - timps (other session): an externally changed day/night mode is adopted after 20 s instead of a permanent desync warning; WB mode 0..9; firmware hides custom WB on T10/T20/T30, highlights slider 0..10. Simulation only, device test pending.
-
Remaining Ingenic libraries:
libalog.so/libsysutils.soon the images were already the openingenic-system-libs-neorebuilds, linked only by timps. Nothing from libsysutils is used; OpenIMP needed two logging symbols from libalog, now built into libimp (claude/open-sysutils). cam-C image without both libraries built and tested by bind mount (snapshot/MJPEG OK); not flashed. -
T10 sub-stream picture wrong — fixed (found via the web preview): channel 1 (640×360) showed the left half of the main picture at 1:1, vertically scaled — in both H.264 and MJPEG. libimp ruled out. Cause in the lifted firmware shared by T20/T10:
_update_ds()computed the horizontal downscaler ratio as output width / output width (always 1.0) instead of input / output (claude/t10-ch1-scaler). cam-E: ratio 2.0, full scene on channel 1, H.264 error-free; flashed 02:31. cam-C (T20) tested by module reload: no regression (its sub-stream uses the other scaler). -
Independent review of the night's seven branches: no blocking bugs. Follow-ups done (
helix-emc-size-2,t21-awb-hyst-2,open-sysutils-2, two doc branches): T21 encoder scratch layout no longer applies to T20/T10 builds; T21 AWB day-gain restore now effective (the first AWB frame used to overwrite it) and manual WB works at night (cam-D confirmed); logging fixes with syslog opt-in (OPENIMP_LOG_SYSLOG=1). Originally: T21 encoder scratch layout must not silently apply to T20/T10 builds (only measured on T21); T21 AWB day-gain restore made effective and manual WB allowed at night; logging fixes (empty-buffer read, one prototype, syslog opt-in); stale docs. -
OSD flush of edge rows only (outside contribution): not adopted. The kernel already bounds a large flush to one whole-L1/L2 index pass (
sc-jz.c), while the change raised rmem ioctls per frame from 4 to thousands for a full-frame rectangle. Only a comment explaining the band flush was taken (claude/osd-flush-band-note). - In work: T23 JPEG shares the H.264 bitstream buffer, DPC/CCM follow the IQ bank, block bypass on load failure, vendor AE as T23 default, T23 motion grid empty in the web UI; replacing the remaining Ingenic libraries (libalog, libsysutils).
Committed on single branches, tested as stated, not yet in an aggregate (next: -all-8 after the open items below).
Kernel (open-tx-isp):
-
T23 failed stream start and reload (
claude/t23-iq-fail): a reload test crashed cam-B in cycle 5: statistics DMA kept writing into freed buffers, corrupted the IQ file (CRC error -77), the ISP core refused to start but the scaler started anyway, then oopses. Now the core stats DMA is stopped on a refused start and at module exit, and STREAMON fails cleanly. cam-B: 10 reloads with kill -9, missing-IQ-file test (start refused, scaler not started), 0 oops. -
T23 sharpen block (
claude/t23-sharpen-modeflags): the sharpen parameters were never loaded (all 49 arrays read from offset 0, a latent NULL read); the block actually ran on reset values. Now loaded from the active IQ bank in vendor layout, refreshed with gain and on day/night switch; bypass bit follows the bank like vendor. cam-B: registers exactly as predicted from the IQ file. -
T23 overexposure after stream restarts (
claude/t23-ae-minit): every stream start reset the exposure to the longest step; AE needed ~4 s to come back, so on-demand snapshots in sun were blown out (64 % white). The vendor keeps the exposure across stream restarts; now the open driver does too (luma at target from the first frame). Open: cam-B hung hard twice ~45 s after loading this build (no oops, watchdog reboot); bisecting sharpen vs AE change. -
T21 white balance lifted from vendor (
claude/t21-awb-lift): AWB, CT detection, CT-driven CCM/LSC now vendor code (emulator: 10/10 scenes register-identical). cam-D: day colours match vendor (R/G 1.04 vs 1.05, B/G 0.93 vs 0.92), night mono fine, 0 oops. Open: first snapshot after start delayed (503 in 7/10 cycles at 25 s) and an "event free empty" burst at start. -
T31 tuning controls (
claude/t31-tuning-stubs): black level read-back, colour matrix presets 0–4 + user matrix, front crop get/set, scaler level now real (were stubs). Review found and fixed: crop read-back returned only the low byte, crop check used swapped axes, a colour-matrix register written with swapped bytes (wrong for limited-range presets). Boot image unchanged. Device test pending (cam-A).
OpenIMP:
-
Hardware JPEG on Helix without vendor library (
claude/helix-jpeg, T20/T21/T23): ~95 % less CPU for snapshots. cam-C passed; cam-D 10/10 (37 ms/job); cam-B 10/10 (29 ms/job). Fixed during testing: per-job memory exhaustion (buffer now allocated once per channel), truncated JPEGs could be served on T23 (now detected via the vendor's ACT_BS bit; retried with coarser tables, then quality lowered by 5 like the vendor, slowly recovered). Software fallback optional at build time (size). - Dedicated JPEG channel got no frames (same branch): timps' snapshot channel has its own frame source, OpenIMP only fed JPEG from video channels. timps then restarted the frame source every few seconds (exposure reset, snapshots 1.5–9 s). Fixed for T20/T21/T23/T30: cam-D snapshots 0.05–0.18 s, no restarts. Affects all earlier OpenIMP images.
-
OSD lines, rectangles, bitmaps (
claude/osd-line-rect, T31/T20/T21/T30): drawn like the vendor (were ignored). Review fixed a use-after-free on bitmap data and a cache hazard. cam-C: all shapes correct on both streams, clipping at the frame edge, 0 oops. -
T23 rate-control parameters (
claude/t23-enc-rc-params): quality level, change point, static time, QP steps, I-frame bias and SMART now reach the encoder at channel creation (were hard-coded) — in the vendor worker path and in the native encoder. Device test pending. -
Robustness audit, parts 2 and 3 (
claude/oimp-robust-2,claude/oimp-robust-3): harmless DQBUF/EPIPE races at channel stop now quiet; atomic worker flags; AEC reference queue heap overflow; audio-effect switch during capture (use-after-free); double stream release in the audio codec; HPF overflow; spin lock without yield on a single core. cam-C: 5 restarts, fd count constant, 0 errors.
Evening additions (all single branches now pushed, still not aggregated):
-
T21 rmem on main↔sub switching (
claude/rmem-keep, on helix-jpeg): our T21 build needed ~27.4 MB rmem for main+sub+JPEG (23 MB available) → WebRTC main↔sub switch failed and the camera restarted. Now one shared bitstream buffer sized exactly like the vendor's vpuBs (2,073,600 B), encoder buffers per picture size and allocated at CreateChn, long-lived buffers at the top. cam-D: free rmem with main+sub 0.5 → 1.56 MB (vendor ≈1.2 MB), 32+40 switch cycles OK. T21 ignores the JPEG size-limit register → JPEG now encoded in stripes with restart markers so it can never overrun; the core also drops the last partial 128-byte burst of every job (vendor too) — compensated. - Dedicated JPEG/MJPEG channel on T31 fixed too (cam-A MJPEG 24 frames/5 s, was 0 bytes).
-
T21 white balance: event callbacks run with IRQs off like the vendor (pool overflow at stream start gone; worst IRQs-off 1.05 ms, like vendor); review fixes incl. a real lifted-code bug (
fix_point_mult3_64returned a·b·b instead of a·b·c in ae_tune2) (claude/t21-review-fixes); module RAM 688 → 638 KB (vendor 616) (claude/t21-mem). -
T23: gain index for all gain-driven blocks was linear instead of log2 (denoise/sharpen far too strong from 2× gain) (
claude/t23-gain-index); vendor AE0 chain lifted and emulator-identical in 6 scenes incl. 50 Hz flicker, behindsource_ae_oem(default off at the time; default on since all-20) (claude/t23-ae-lift); AE resume by EV (claude/t23-ae-resume-ev); frame-path fixes (claude/t23-hang-debug903b9e18). - T23 hard hang (3× in afternoon sun, silent, watchdog reboot): not reproduced in ~3 h of evening stress; kernel soc_vpu/helix defects found and patched for a future image (not yet built); an encoder that stops producing frames at very large frames (QP 10) was found and is being examined.
-
T20 white balance: presets/manual never applied (T20 uses OpenIMP's simple AWB; recovered firmware had several decompilation errors) — fixed, presets in the correct direction on cam-C (
claude/t20-wb-presets); work on the vendor AWB chain continues (claude/t20-oem-awb). - OpenIMP robustness 2+3, ISP gaps (scene mode, colour effects, T21 DRC/DNS), ISP probe tool, T20 log flood silenced: pushed by a second session.
- T10L (report from a Thingino maintainer): day/night panic, EFE job never completes, 8 MiB probe pool — under analysis.
Late evening (aggregates built, more fixes on single branches):
-
All five test cameras now run the open stack. cam-B (T23) is fully open: native H.264 encoder is the default (
claude/t23-native-default), the image no longer contains the OEM helixd worker or the vendor libimp (rootfs 324 KB smaller). cam-E (T10) booted the open stack for the first time (driver/t10, OpenIMP T20 build with runtime T10 detection, current timps/WebUI, boot guard). Both: MJPEG 25 frames/5 s, snapshots OK, no oops. -
T20 fixes (
claude/t20-flip-sharpness, not yet in an image): vertical flip computed the UV start from the 16-aligned height — the DMA wrote 12 chroma lines past the end of the frame buffer and the top rows got no colour (pink/green band); sharpness never applied in the default path because the firmware worker is parked — now updated in the compact AE loop (edge energy 13/230/700 for 0/128/255, was flat). -
T23 image controls (
claude/t23-image-controls): contrast only acts in the day bank (the sc2336 night bank disables the contrast curve, same on the vendor stack); AE compensation works; backlight/highlights and AE compensation fixed for the lifted vendor AE; WDR needs the dynamic ADR port (open). -
T10 integrated into the aggregates (
open-tx-isp-all-9fa7ac42b,openimp-all-89a2e33d2): merging uncovered a real bug — the T10 NVPU writes 21 KB (luma) / 10 KB (chroma) past each padded reference plane on every picture, which in the aggregate's top-down layout hit the bitstream window and made the stream undecodable; reference planes are now sized for it.isp_printfis exported only in the T10 module build. cam-E: 60 s / 1501 frames error-free, MJPEG, 3 day/night switches without oops. An open-stack image for cam-E is being built. - cam-B to become fully open: native H.264 encoder as T23 default and an image without the OEM helixd worker / vendor libimp are being prepared (until now the T23 default still used the OEM worker).
- New user reports being worked on: T23 contrast, AE compensation, WDR and backlight without visible effect; T20 vertical flip gives pink stripes; T20 sharpness without effect.
-
cam-D memory: T21 H.264 EMC scratch sized exactly like the vendor (1080p 996 KiB instead of 2 MiB; vendor offsets reproduced; only one sub-buffer is written by the hardware, measured on the device). Free rmem with main+sub+MJPEG 1.56 → 2.76 MB (vendor ≈1.2 MB). FIXQP IDR pictures now at QP−3 like the vendor (
claude/helix-emc-size, not yet in an aggregate). -
-all-9 / openimp-all-8 flashed on cam-B, cam-C, cam-D (00:35):
open-tx-isp-all-9(T23 IRQ_NONE, T20 vendor-AWB chain behind a switch, T10 fixes, T23 vendor AE behind a switch) andopenimp-all-8(MJPEG fix, T23 overflow v2 + optional hard limit, review nits), plus kernel soc_vpu patches 0095–0098. All up, no oops, MJPEG 25 frames/5 s, snapshots OK; flashed without the usual pre-reboot thanks to a fixed OTA script. T10 encoder support (t10-cpuid) is being merged into the aggregate and re-tested on cam-E. -
After midnight: MJPEG regression fixed (
claude/oimp-jpeg-src-fix: the fan-out decision is per poll again but only waits for a video channel that is actually receiving; cam-C 25 frames/5 s with and without a video consumer). T23 IRQ handlers return IRQ_NONE when nothing is pending, unused IVDC IRQ stays off (claude/t23-irq-none; cam-B clean). Kernel soc_vpu hardening patch 0098 (bounded waits, user-pointer validation, register ioctl restricted to the VPU window, per-file channel release) plus an optional hard bitstream limit for the T23 native encoder (claude/t23-bsf-limit, only active with the patched kernel). Small OpenIMP review fixes (claude/oimp-nits, written by another model, reviewed). Night device tests on cam-B/cam-D: restarts and channel cycling clean; T23 native rate-control parameters take effect; T21 tuning getters return defaults (being checked). 98 merged local worktrees removed. Next aggregatesopen-tx-isp-all-9/openimp-all-8and images for all four cameras are being built (not flashed). - Status of the beyond-vendor improvement ideas (maintainer decides each one): 16 implemented or approved, 2 rejected, 42 open. Approved tonight and in work: hardening of the kernel soc_vpu driver (bounded waits, user-pointer validation, register-ioctl restricted), a hard T23 bitstream limit via the BSF interrupt (needs the patched kernel), and T23 IRQ handlers returning IRQ_NONE when nothing is pending.
- -all-8 images flashed on cam-B, cam-C, cam-D (23:42; cam-A pending): all up, no oops. Known regression found right after: the dedicated MJPEG/JPEG channel delivers no frames again (merge interaction in openimp-all-7), fix in progress. T23 overflow fix v2 (2 MiB window, scratch between bitstream and references) tested on cam-B: 0 decode errors, forced overflows handled without reference damage. T23 vendor AE (default off) tested at night: picture at target brightness where the substitute stayed black.
-
New aggregates pushed:
claude/open-tx-isp-all-8(bfdb0e3e) andclaude/openimp-all-7(cb85922d) — everything from today except the T23 debug commit, the default-off T23 vendor-AE lift and work in progress. All modules/libimps build without new warnings; all host tests green. 24 merged single branches deleted. - cam-D WebRTC main↔sub switching confirmed working by the user with the rmem fix.
-
T23 native H.264 bitstream overflow (
claude/t23-enc-overflow, local): a frame larger than the 1 MiB window was retried at the same QP until the channel stopped (timps then restarted the camera). Now dropped + QP raised (+4, decaying), IDR if the reference was damaged. Device finding: the core ignores the window and keeps writing up to 1.79 MB, overwriting the reference buffer behind it — a serious candidate for the afternoon hangs (sun → ~1 MB IDRs). The vendor only truncates the length. -
T10L (report by a Thingino maintainer, now with a T10 test camera): day/night panic root cause found — our reconstruction of
wdr_mode()zeroed the general FSM manager pointer (only hit when ispmem leaves room for WDR, i.e. on T10); the T10 encoder needs its own command list (captured from the vendor encoder, word-for-word host test) selected at run time; 8 MiB MMAP pool made optional. cam-E (T10): 720p H.264 25 fps error-free, 10 day/night switches without oops. Branchesclaude/t10-fixes,claude/t10-efepushed. -
T20 vendor AWB chain (
claude/t20-oem-awb, behindt20_simple_awb=0, default unchanged): several decompilation errors fixed (mesh never called, wrong offsets, NR event FSM broken, firmware worker parked after the first pass); runs stable on cam-C, white-paper check in daylight pending. - cam-B colours with IR/white LED: not a driver bug — white balance was stored as manual in the streamer config (left over from the old WB-mode clamp).
An independent code review (no critical findings) led to these fixes, now in the -all-6 aggregates:
- Kernel: deadlock between sensor unload and reading
/proc/jz/sensor/*(shared sinfo code); orphan sensor slots no longer point at unloaded modules; T21 open/release counted every open as the first (same bug in the vendor driver) — now counted and serialised; T23/T31 last-close races with foreign frame-channel users; dead global tuning buffer removed (T31); T20 refuses to release the active sensor; T21 error paths; T23 LSC flip locked, small leak fixed; unreachable decompiled T23 setters disabled. Tested on cam-A (T31), cam-D (T21) and cam-C (T20): foreign open/close while streaming, proc reads during sensor unload, repeated reloads. The T20 test exposed one more case: the T20 sensor module unloads without unregistering, leaving a dangling driver pointer that/proc/jz/sensor/*/nameread after unload (oops). Fixed by a module notifier that clears slots of any module being unloaded (claude/open-tx-isp-all-7); retest on cam-C passed (10 sensor reloads during proc reads, 0 oops). - OpenIMP: T23 native reconfigure uses a parameter snapshot (no divide-by-zero race); T31 lambda tables are generated from a formula instead of being copied from the vendor binary (output bit-identical, 12 documented ±1 entries); top-level NOTICE incl. WebRTC AECM (BSD-3) and x264-derived H.264 code (GPL-2.0+); committed test binary removed; width alignment check; level recomputed on bitrate change; rotation state published atomically; T23 AEC uses the driver's reference offset.
- timps (separate session): no OSD clamp on rotated streams under OpenIMP (tested on cam-A); motion detection uses the sub stream by default (walk test on cam-A, no false alarms; on a T31 with vendor libimp about 85 % less IVS CPU).
Current aggregates: claude/open-tx-isp-all-7 (all-6 + sinfo module-notifier fix) and claude/openimp-all-6. All single branches and older aggregates contained in them were deleted (2026-10-02: 58 + 3 + 4 branches). Kept: docs and test-result branches, plus three old unmerged branches pending a decision (t31-isp-lifecycle, t31-isp-perf, OpenIMP t31-series).
- timps: AE IT max can be reset to 0 again (PR #3, merged).
- thingino: the packages
openimpandopen-tx-ispare in the upstream branchaperto(#1756), selected withBR2_PACKAGE_THINGINO_ISP_OPENand pinned by commit SHA to the Lu-Fi forks (next); T23 runs fully on OpenIMP, the vendor library under/opt/openimp-t23and the helixd hybrid are gone. A tag will be pinned once the first date tag exists onaperto. - Merged upstream (
aperto): kernel VPU/rmem stability patches (#1748, #1752), optional boot guardS10isp-guardwith u-bootisp_open=manual|auto|off(#1749, default off), SC2336 flip fixes (#1750, #1751), OTA fix (#1747), timps tarball hash (#1746). Closed without merge (superseded by theapertoversions): #1736, #1738 (64 KiBfw_env.configandfw_setenvguard for T41; not upstream), #1739, #1743. - T21 image: sensor
shvflip=1, TLS and WebRTC enabled.
- Full-stack soak, 25 fps (T31): 2 h 53 min, 260,648 frames, 1030/1030 snapshots, 0 errors
- HEVC decode (T31): 2 × 900 frames, 0 decode errors
- Native Helix soak, 25 fps (T23): 2 h 34 min, 231,668 frames, 0 decode errors, ~6 % CPU
- Tuning checks with t23tune (T23): Gain/IT limits with AE retime, DRC/defog bits, idempotent sinter, flip, max dgain: all pass
- Night mono (T23, T21): Chroma exactly 0
- Stop/start cycles (T20): 20 cycles, 0 oops, no hung process
- Motion detection (T20): 6/6 events, 0 false alarms in 2 min
- Long soak, 25 fps (T20): 1 h 44 min, 156,517 frames per stream, 0 errors
- Night stability (T21): ISP gain constant (was cycling 6↔25)
- Colour blotches (T21): Chroma spatial σ 30 → 6
- Day exposure (T21): Mean Y 235 (blown out) → 120, natural colour
- AEC speech loopback (T31): Echo vs pauses 29 → 9 dB (−18 dB); AECM ERLE 44 dB
- Rotation 1280x704 → 704x1280 (T31): Correct picture; 9 ms/frame at 15 fps
- Native encoder soak (in progress) (T23): 25 fps both streams, 0 encoder errors, ~6–7 % CPU
- Stock-lift equivalence (emulator) (T21): AE 8/8, ADR 40/40, defog 40/40, dispatchers identical
- libimp code + data, T21: vendor ~1.0 MB, open ~0.5 MB. Open saves about half
- libimp code + data, T23: vendor ~1.26 MB, open ~0.6 MB. Native encoder also drops the helixd vendor library
- libimp code + data, T31: vendor ~1.05 MB, open ~0.57 MB
- Kernel module, T21: vendor 616 KB, open 452 KB. After the size work of 2026-10-03/04 (was 805 KB)
-
Kernel module, T23: vendor 857 KB, open 622 KB. After
t23-bss-shrinkand the size work (was 1,607 KB) - Kernel module, T31: vendor 829 KB, open 711 KB
- T23: rare single Helix encode error (errno 5; the frequent frame drops are fixed, see 2026-10-04 afternoon); real WDR missing.
- T41: flip, night column noise (gc5603), short IVS gaps, OOM with three parallel streams,
AddSensorEBUSY after an OOM kill; day/night and AE/AWB quality untested; ioctl hardening awaits its device test; temper effect; crop/rotation (I2D). - T21: a 4th module reload in one boot crashed once (under investigation); VBM rmem block parking and Helix create back-off to be ported.
- T23: AWB fix (static gains when no zone matches) awaits a daylight test.
- AEC device tests on T23/T21/T20 (no speaker tests on the shared test cameras).
- First release tag after the 24 h soak;
apertobranch not created yet. - Improvements beyond vendor behaviour are collected separately and decided by the maintainer.
Both repositories: next is the tested integration branch (fast-forward only); main is the fork default branch and is not kept in sync (it lags behind next; next is authoritative). All aggregate and topic branches (claude/*-all-N and the single branches) that were merged into next have been deleted; branch names in the tables above are historic. Planned: aperto (release branch, fast-forward only) and date tags vYYYY.MM.DD after the first clean soak.
Numbers come from on-device measurements and host checks during the campaign.