bootimg-cmdline.py |
- |
Read/patch the kernel cmdline of an Android boot image, in place or to a copy. |
bootimg-repack-dtb.py |
- |
Swap the appended DTB inside an Android boot image, fixing up the header. |
bootimg-verify.py |
- |
Verify a boot.img actually carries the kernel/DTB you just built. |
dtbo-split.py |
- |
Split an Android DTBO image into its individual .dtb entries. |
fdtdump.py |
- |
Minimal flattened-devicetree dumper (no dtc on this host). |
gen-tools-doc.py |
- |
Generate docs/TOOLS.md from the tool headers. Run via make tools-doc. |
mtstall.py |
on-device; /proc |
mtstall.py SECONDS [COMM] – is the WebKit main thread computing, or blocked? |
ph-acoustic.py |
BOOTED |
ph-acoustic.py – decide “does audio actually come out / go in” with no human. |
ph-afk.sh |
BOOTED |
ph-afk.sh – stop the phone suspending itself while nobody is at the keyboard. |
ph-alsa-stage.py |
BOOTED |
Walk the ALSA PCM lifecycle one call at a time, marking /dev/kmsg before each. |
ph-applaunch-bench.sh |
on-device |
ph-applaunch-bench.sh – cold/warm application launch latency under phosh. |
ph-autologin.sh |
BOOTED |
Enable or disable greetd auto-login, which is the ONLY reliable way to get an |
ph-blankwatch.py |
on-device as the session user; grim; a screen that is ON |
Sample how much of the screen is BLANK while something is happening. |
ph-build-lock.sh |
- |
Serialise KERNEL BUILDS across parallel agents. |
ph-build.sh |
- |
shellcheck shell=bash |
ph-camstream.sh |
- |
ph-camstream.sh – one capture attempt on the IMX179 front camera, with the |
ph-capture-userspace.sh |
BOOTED |
Capture the device’s locally-built package set, so a from-scratch install |
ph-capture.sh |
BOOTED |
ph-capture.sh – arm every log channel this device has, from the HOST, and |
ph-chromium-videoarm.sh |
on-device as the session user; /tmp/sess.sh; chromium; grim; v4l2-ctl; |
ph-chromium-videoarm.sh LABEL [CHROMIUM_FLAGS…] – one PLAYBACK arm. |
ph-compass-check.py |
- |
Check the compass maths in qcom_smgr.c against floating point. |
ph-crosstax.py |
- |
ph-crosstax.py [SECONDS] – how much of a cross build runs under qemu. |
ph-cycle.sh |
any |
One display bring-up experiment: bootloader -> RAM boot -> modprobe -> capture. |
ph-decode-killstorm.sh |
on-device |
ph-decode-killstorm.sh – SIGKILL a hardware decode mid-flight, N times, |
ph-device-test.sh |
BOOTED |
One check: two concurrent ph-device.sh callers must not interleave. |
ph-device.sh |
any |
Serialise access to the ONE physical phone across parallel agents. |
ph-dpu-regs.sh |
BOOTED |
Dump and decode the DPU registers that matter for a stuck display. |
ph-dumpdiff.py |
- |
Diff a stock-Android TKDUMP capture against our camss port’s register state. |
ph-egl-dmabuf-probe.py |
on-device |
What dmabuf modifiers does EGL really advertise, per platform? |
ph-evtest.py |
- |
Dump multitouch events from an evdev node. Run ON THE DEVICE, as root. |
ph-firstpaint.sh |
- |
ph-firstpaint.sh – what the user actually waits for: launch -> first frame. |
ph-flash-boot.sh |
FASTBOOT |
Flash a boot image to slot b and come back up in pmOS, end to end, unattended. |
ph-gap.py |
BOOTED |
Measure the capture gating (HANDOFF-audio.md 2.5) as a number, per config. |
ph-gesture-bench.py |
- |
Measure how smooth the phosh session actually is. Run ON THE DEVICE as root. |
ph-greetd-login.py |
on-device as root |
Log a user into the graphical session through greetd’s IPC, from ssh. |
ph-i2c-probe.py |
- |
Scan the taimen touch i2c bus (QUP5) for the STM FTM4 at 0x49. |
ph-irq-floor.py |
BOOTED |
What is waking the CPU while nobody is using the phone? |
ph-key.py |
- |
Inject a key press through /dev/uinput. Run ON THE DEVICE as root. |
ph-kmsglog.py |
- |
Follow /dev/kmsg into a file, fsync’d per record, so the kernel log tail |
ph-lte-load.py |
- |
Generate sustained traffic that REALLY goes out over LTE. Run ON THE DEVICE. |
ph-mempressure.sh |
on-device |
ph-mempressure.sh – one line per second of the memory-ceiling vital signs. |
ph-mic-check.sh |
BOOTED |
ph-mic-check.sh – is the microphone producing AUDIO, or just a noise floor? |
ph-mic-test.sh |
BOOTED |
ph-mic-test.sh [DMIC0..DMIC5] [seconds] [rate] – runs ON THE PHONE. |
ph-mic-watch.sh |
BOOTED |
ph-mic-watch.sh [seconds] – runs ON THE PHONE. |
ph-micwatch.sh |
BOOTED |
ph-micwatch.sh – sample whether anything is holding the microphone open. |
ph-modcrc.py |
BOOTED |
Compare the __versions (modversions) sections of two .ko files. |
ph-modstack.sh |
on-device |
Reading the module stack, for tkmod’s reload path. SOURCED, never run: |
ph-mount-cal.py |
BOOTED |
Measure the accelerometer mount matrix from four guided poses. |
ph-mt-doctor.py |
on-device as root |
Diagnose and clear phantom touch contacts. |
ph-mtstate.py |
- |
Print the CURRENT multitouch slot state of an evdev node, without waiting. |
ph-nfc-portal-probe.py |
on-device |
Assert what an app on the NFC portal’s fd can and cannot do. |
ph-perf-ab.sh |
- |
ph-perf-ab.sh – interleaved A/B of a tuning knob against real frame timings. |
ph-phy-reinit.py |
- |
Re-run the CSIPHY v5.0.1 init sequence by hand, WHILE the sensor is already |
ph-phy-settle-sweep.py |
- |
Sweep the CSIPHY settle count over its whole 0..255 range against a LIVE |
ph-phy-sweep.py |
- |
Sweep CSIPHY CMN_CTRL5 (the lane-enable mask) against a LIVE transmitting |
ph-phystat.py |
- |
Read (and optionally poke) the SoC CSIPHY common block live. |
ph-prox-check.py |
BOOTED |
Check that qcom_smgr suppresses the proximity IR crosstalk in the ALS. |
ph-push-module.sh |
BOOTED |
Install a freshly built kernel module onto the running phone, no reflash. |
ph-rangehttp.py |
on-device |
Serve a directory over HTTP with byte-range support, for |
ph-reboot.sh |
any |
Reboot the phone and return the INSTANT ssh answers again. |
ph-recover.sh |
any |
ph-recover.sh – one command to get taimen back after the 2026-08-01 incident, |
ph-regdump.py |
- |
Dump an MMIO range via /dev/mem, one mmap’d process. |
ph-ringdump.py |
- |
Decode the ringbuffer out of an adreno devcoredump into CP packets. |
ph-scrollarm.sh |
on-device as the session user |
ph-scrollarm.sh LABEL [ENV…] – one PURE-SCROLL arm, with no video playing. |
ph-sensor-poke.py |
- |
Live 16-bit-register I2C access to the IMX179, for use WHILE camss holds the |
ph-sensorstream.sh |
- |
ph-sensorstream.sh – stream the REAL sensor path, imx179 -> CSIPHY -> CSID -> |
ph-session-cpu.sh |
on-device |
ph-session-cpu.sh – rank a graphical session’s user units by cumulative CPU. |
ph-soak.sh |
on-device |
ph-soak.sh – the on-device half of the D2 / 72 h stability soak. |
ph-stallcatch.py |
on-device as root |
ph-stallcatch.py SECONDS COMM THREAD_SUBSTR [IDLE_MS] – when THREAD of the |
ph-stream.sh |
BOOTED |
Stream a command’s output from the phone to a host file, across reboots. |
ph-strip-btf.py |
- |
Make a kernel module’s .BTF section invisible to the module loader. |
ph-supervise.sh |
any |
ph-supervise.sh – keep the phone alive during unattended work. |
ph-suspend-guard-check.sh |
BOOTED |
ph-suspend-guard-check.sh – prove the suspend guard actually blocks, WITHOUT |
ph-sysstate.sh |
on-device |
Print one compact line of system state per second, forever. |
ph-tgstream.sh |
- |
ph-tgstream.sh – capture from the CSID’s own test generator. |
ph-thermal-ramp.sh |
- |
ph-thermal-ramp.sh – the six-phase thermal ramp, with an abort that works. |
ph-thermal.sh |
BOOTED |
Keep a phone from being cooked by back-to-back measurement arms. |
ph-threadcpus.py |
on-device; a running process to watch |
Which CPU does each of a process’s threads actually run on, and at what clock. |
ph-tone.py |
- |
Generate an acoustic probe signal, to be played on the HOST while the phone |
ph-touch.py |
- |
Inject touch gestures through /dev/uinput. Run ON THE DEVICE as root. |
ph-uclamp.py |
on-device; CONFIG_UCLAMP_TASK=y; same uid as the target |
Raise the scheduler’s utilization floor for a running app’s threads. |
ph-ui.py |
on-device |
Drive and inspect the phosh session deterministically. Run ON THE DEVICE. |
ph-vibrate.py |
- |
Play a rumble effect through the force-feedback API. Run ON THE DEVICE. |
ph-videoarm.sh |
on-device as the session user |
ph-videoarm.sh LABEL [ENV…] – one PLAYBACK arm on a LOCAL clip. |
ph-wake-cycle.py |
on-device |
Press the power key on a loop and count the blank/unblank transitions that |
ph-wav-verdict.py |
- |
Decide whether a capture contains real microphone audio. |
ph-webarm.sh |
on-device as the session user |
ph-webarm.sh LABEL [ENV…] – one YouTube arm with the page state PROVEN |
ph-webbench.sh |
on-device as the session user |
ph-webbench.sh – browser smoothness A/B on a deterministic heavy page. |
ph-webdraws.sh |
on-device with passwordless sudo; perf; CONFIG_UPROBE_EVENTS; a running |
ph-webdraws.sh [SECONDS] – the compositor’s draw census per frame. |
ph-webeval.py |
on-device; ph-webvq.py beside it; browser launched with WEBKIT_INSPECTOR_HTTP_SERVER=127.0.0.1:9222 |
Evaluate JavaScript in the current page through WebKit’s remote inspector. |
ph-webframe.sh |
on-device with passwordless sudo; perf; CONFIG_UPROBE_EVENTS; |
ph-webframe.sh [SECONDS] – where each compositor frame’s period goes. |
ph-weblayers.py |
on-device; ph-webvq.py beside it; browser launched with WEBKIT_INSPECTOR_HTTP_SERVER=127.0.0.1:9222 |
Dump the composited layer tree of the current page through the remote inspector. |
ph-webvq.py |
on-device; Epiphany launched with WEBKIT_INSPECTOR_HTTP_SERVER=127.0.0.1:9222 |
Poll a |
ph-wifi-audit.sh |
- |
ph-wifi-audit.sh – end-to-end WiFi stack audit for taimen (ath10k/WCN3990). |
ph-wifi-soak.sh |
on-device |
ph-wifi-soak.sh – watch a WiFi link for the two ways it fails quietly. |
ph-wkoffsets.sh |
BOOTED – to name the build under test; falls back to the newest apk, |
ph-wkoffsets.sh [SYMBOL…] – uprobe offsets for WebKit phase entry points, |
ph-wkphase.sh |
on-device with passwordless sudo; CONFIG_UPROBE_EVENTS. Offsets come |
ph-wkphase.sh arm|measure [SECONDS]|off – where the WebKit MAIN THREAD’s |
ph-wlgaps.py |
- |
Where a client’s late frames actually are, from a WAYLAND_DEBUG=1 log. |
ph-wol.py |
any |
Wake a sleeping phone over wifi with a WoWLAN magic packet, without hands. |
powerhintd.py |
on-device |
powerhintd – Android’s power hints for a mainline phone. |
rootfs-uuid.py |
- |
Read the filesystem UUIDs out of a pmOS rootfs image, without mounting it. |
stallwatch.sh |
BOOTED |
stallwatch.sh – detect the taimen PID-1 freeze from the HOST. |
threadcpu.py |
on-device; /proc |
threadcpu.py [SECONDS] [PROC-MATCH] – per-thread CPU of a multithreaded app. |
tsh.py |
INITRAMFS |
Run a command on the pmOS initramfs debug shell (busybox telnetd, $HOST:23). |
wkbuckets.py |
- |
wkbuckets.py PERF-REPORT-FILE – what phase of WebKit owns the main thread, |