Research into native DisplayPort Multi-Stream Transport (MST) on Apple Silicon, starting with the base M5 MacBook Pro. The goal is independent external displays through ordinary USB-C / DisplayPort MST hubs, without DisplayLink or special Thunderbolt multi-DP hardware.
Research only: MacMST does not enable MST. There is no installable display driver, qualified observer hardware, or demonstrated independent same-link MST output on M5. Whether native MST can be enabled remains unknown.
Latest completed milestone: M5P11 - Low-Capacitance Receive Stage And Powered-Off Qualification (2026-09-22). Read the findings and source-backed limits.
| Area | Current Result |
|---|---|
| M5 source investigation | Static evidence identifies MST control and source packetizer programming. Independent stream ownership on one physical link remains unresolved; further packetizer reverse engineering is frozen. |
| Offline analysis | DCP trace analysis, AUX Manchester/native/I2C decoding, MST CRC/reassembly and conservative wire-evidence evaluation are implemented and tested. |
| Receive frontend | Six concrete receiver profiles assessed. No candidate meets every loading, range, protection and powered-off requirement. AUX_FRONTEND_PROTOTYPE_STILL_BLOCKED. |
| Electrical models | Conditional differential receiver models recover synthetic traffic. Typical-value capacitance and successful decoding are not hardware qualification. |
| Capture system | W1_CAPTURE_SYSTEM_NOT_READY. Analogue hardware, actual acquisition backend and 180-second capture acceptance remain unqualified. |
| Verification | 458 offline tests in nine CTest groups, including exact M5P10 result regression and deterministic M5P11 evidence replay. |
| Hardware state | CURRENT_HUB_STATE_NOT_REQUIRED. Current work needs no Mac display query, hub connection, hardware purchase or assembly. |
The closest fully sourced buffered example uses OPA810IDR stages and downstream TLV9031DBVR comparators. Its 3.4 pF/leg budget uses typical IC values and an assumed PCB allowance, not a guaranteed maximum. Documented input-to-supply paths also prevent claiming powered-off transparency. No comparator, hardware threshold, construction schematic or BOM is released.
The next proposal is M5P12_OFF_STATE_ISOLATION_CELL_QUALIFICATION: an offline study of one normally-open sense disconnect and its power-fail sequencing. It is not an approved build or hardware experiment.
- A frozen DCP observer schema and offline pipeline, with synthetic replay and conservative ownership-evidence checks.
- Independent AUX/MST decoders and W1 wire-evidence analysis, preserving unknown direction, malformed traffic and capture loss.
- Reproducible differential frontend models and condition-qualified receiver analysis, with explicit assumptions and fail-closed release gates.
- Exact component specifications and source receipts, distinguishing typical values, stated-condition limits and unknowns.
- Historical public-probe and static-analysis tooling, plus source-backed research reports. Their presence is not permission to repeat retired experiments.
Prerequisites: Python 3.9 or newer, CMake 3.20 or newer, Ninja and a C++20 compiler. On macOS, use Xcode or the Command Line Tools. The offline Python tools use the standard library; no third-party packages are downloaded.
cmake -S . -B build-offline -G Ninja -DCMAKE_BUILD_TYPE=Debug -DBUILD_TESTING=ON -DMACMST_ENABLE_HARDWARE_TESTS=OFF -DMACMST_ENABLE_DPDV_OPEN_EXPERIMENT=OFF
cmake --build build-offline
ctest --test-dir build-offline -L offline --output-on-failureThis runs only the nine offline test groups. It does not execute the native display probe, open an IOKit client, or send AUX/DPCD traffic. Golden numerical replays can take a few minutes. Broader unit and hardware suites are separate.
Inspect the receiver budgets and blocked release decisions without hardware:
python3 tools/dp_aux_receiver.pyThe tests run from tracked source without historical raw captures. Generating new source-qualified candidate evidence additionally requires the exact local datasheet receipts documented in M5P11. Missing evidence is not fetched silently or treated as a passing result.
| Start Here | Scope |
|---|---|
| M5P11: low-C receiver and powered-off qualification | Latest completed work, concrete candidate rejections and all 16 qualification answers. |
| M5P10: differential-first frontend | DC-bias discrimination, four-state slicer, continuous synthetic pipeline and separate frontend/W1 gates. |
| M5P9: electrical closure | Legacy capacitive-mismatch failure and executed circuit baseline. |
| M5P7: self-built AUX observer | Protocol tools, synthetic fixtures and limits of AUX evidence. |
| M5 static conclusion | Source packetizer evidence, unresolved stream ownership and frozen reverse-engineering boundary. |
| Open questions | Current blockers and the next proposed offline investigation. |
| Research index | Full milestone history and report navigation. |
| Evidence ledger | Claims, exact sources, revisions, hashes and confidence limits. |
RETIRED_ON_DAILY_USE_M5: the private DPDV/selector-0 transport is permanently retired on the daily-use M5. NOT_READY_FOR_DPCD_TEST remains unchanged. One explicitly authorized historical open/immediate-close occurred with zero selectors; it does not authorize reuse or establish safe DPCD access.
Current work is offline. Do not connect an unqualified frontend to a Mac or DP link, drive AUX from GPIO, repeat old private-helper commands, or disable system security mechanisms. Physical experiments require separate owner approval and their own passing safety gates. No vendor or university outreach is required.
STATIC_PACKETIZER_ANALYSIS_FROZEN and NO_FURTHER_T8142_PACKETIZER_REVERSE_ENGINEERING_AUTHORIZED remain in force. Compilation and synthetic success do not prove hardware functionality. AUX allocation/ACT status does not prove actual main-link packets or independent pixels; results on other chips do not establish M5 behavior.
main includes completed research through M5P11. The annotated checkpoint
m5-aux-receiver-qualification-v1.2 marks this offline research state, not a
software or hardware-ready release. The M5P11 milestone branch remains pinned
at 41e0ce2ef43f7507787bb43dc5d403bfeaed5b69.
Earlier tags, including m5-observer-platform-gap-v1.1, preserve their original
historical conclusions. They are not moved to newer commits or interpreted as
current project-wide instructions. Completed research branches are retained.
Raw captures, downloaded datasheets, copied external sources, extracted Apple binaries, build outputs, secrets and machine-specific editor configuration are ignored by Git. Reports retain URLs, revisions, hashes, provenance and reproduction commands; a fresh clone does not contain those local artifacts. No Apple firmware or kernel binary is distributed here.
Historical observations are bound to their recorded hardware, OS and topology.
Do not assume the current display state or promote a typical component value
to a guaranteed maximum. See the evidence rules
for VERIFIED_FROM_DATASHEET, TYPICAL_ONLY, INFERRED, ASSUMED, UNKNOWN
and BLOCKING distinctions.
Historical probe tooling and milestone timeline
The material below is retained historical reference, not the current quick start or authorization to run hardware/private experiments. Milestone-specific future build labels, connection policies and readiness statements have been superseded where the current status above says so. For current work, use the offline suite.
Prerequisites: Xcode/Command Line Tools with a C++20 compiler, CMake, and Ninja (or another CMake generator). Tests and the independent capture tool also use Python 3.9 or newer. No third-party libraries are downloaded.
cmake -S . -B build -G Ninja -DCMAKE_BUILD_TYPE=Debug -DMACMST_ENABLE_HARDWARE_TESTS=OFF -DMACMST_ENABLE_DPDV_OPEN_EXPERIMENT=OFF
cmake --build build
ctest --test-dir build -L unit --output-on-failure
build/macmst probe
build/macmst probe --jsonThe probe uses public sysctl, CoreGraphics and IORegistry reads. It inspects
selected library symbols with dlsym but never invokes private AV/DP functions,
opens a user client, or sends DDC/AUX/MST transactions. It does not change display
or system settings. No sudo or security-setting changes are needed.
Output includes host, logical displays, DCP/DCPEXT-related registry paths and
immediate parent/child identities, published port/link fields, USB candidates,
symbol visibility, and conservative External device/service candidates. Pairings
and single-active-context associations are labeled INFERRED, not proven physical
routes. DPCD read capability remains UNVERIFIED; no private object is acquired.
Public DisplayPort diagnostics select only one active external display, inspect
the public CG service mapping, and conditionally enumerate framebuffer I2C buses
and transaction masks. No I2C interface is opened and no request is sent. Missing
targets, zero counts, API errors and unknown masks are reported separately.
A USB candidate is not automatically the dock.
Exit codes: 0 for a collected report, 1 for observation/report failure, 2 for
invalid arguments. Exit 0 does not establish any bus or MST functionality.
python3 tools/capture_baseline.py --probe build/macmstCreates a new ignored artifacts/probes/<UTC timestamp>/ directory with selected
raw profiler/registry values, CLI JSON, environment and SDK metadata, commands,
errors, and SHA-256 hashes. Serials, UUIDs, raw EDID and opaque/private properties
are omitted before saving. Artifacts are not complete raw machine dumps; review
product descriptors before sharing. Never commit credentials or unrelated data.
The normal unit suite does not enumerate hardware. Opt in explicitly:
cmake -S . -B build -DMACMST_ENABLE_HARDWARE_TESTS=ON
cmake --build build
ctest --test-dir build -L hardware --output-on-failureFor deterministic sanitizer tests:
cmake -S . -B build-sanitized -G Ninja -DCMAKE_BUILD_TYPE=Debug -DMACMST_ENABLE_SANITIZERS=ON
cmake --build build-sanitized
ctest --test-dir build-sanitized -L unit --output-on-failureThe unit suite also includes a mock-only isolated helper, with crash/timeout,
protocol, descriptor and reaping checks. Run it alone with
ctest --test-dir build -R '^mock_helper_isolation$' --output-on-failure.
It is not linked into production macmst and does not open any display interface.
A watchdog result is not evidence of kernel/DCP cancellation.
The DPCD decoder has no macOS dependency. It decodes synthetic or future acquired receiver bytes, not a fabricated AUX transport. On non-Apple hosts CMake builds the generic library/tests, not the macOS CLI; that cross-platform build has not yet been executed here.
M5P7 controls the current physical-state and outreach policy. Earlier milestone entries below remain historical: CURRENT_HUB_STATE_NOT_REQUIRED and OUTREACH_CAN_RUN_IN_PARALLEL supersede keep-connected/mandatory-outreach requirements. No present hub state is assumed or queried.
M5P8 retains that policy and narrows work to electrical qualification. Its analysis-only circuit is not released for construction; the pre-build review has a common-mode matching failure and unresolved protection/power-off gates.
M5P10 compares differential-first receiving and explicit idle thresholds. Its conditional model resolves nominal synthetic decoding, but no physical input stage is qualified: AUX_FRONTEND_PROTOTYPE_STILL_BLOCKED, independently of W1_CAPTURE_SYSTEM_NOT_READY. A standard two-channel analyzer interface is frozen; exact W1 recorder selection is not a frontend bench prerequisite. Future physical work is conditional M5P11; older labels below are historical.
M5P11 is now offline low-capacitance/off-state qualification, not that earlier conditional build. No concrete receiver passes every gate. The OPA810 example is 3.4 pF/leg using typical values, with an unknown guaranteed maximum and a documented unpowered clamp-loading conflict. AUX_FRONTEND_PROTOTYPE_STILL_BLOCKED; W1_CAPTURE_SYSTEM_NOT_READY. No build or connection is authorized.
| Area | Current Status |
|---|---|
| Low-C receive stage and powered-off qualification | M5P11: six concrete candidate profiles, condition-qualified capacitance accounting, explicit rail/JFET/feedback off-state circuits and preserved M5P10 replay. No complete maximum-C/off-state contract; no comparator/threshold/schematic/BOM selection. 458 offline tests pass; 82-file candidate evidence deterministic. Next proposal is offline power-fail isolation-cell qualification, not hardware build. CURRENT_HUB_STATE_NOT_REQUIRED. |
| External DCPDP path | Identified for the recorded M5/hub topology. |
| IODP read ABI | Substantially reconstructed through static analysis. |
| DPDV selector-0 path | RETIRED_ON_DAILY_USE_M5; historical reconstruction is not an available transport. |
| DCP RPC safety | Static expansion of this transport stopped after M2I; critical gates remain unresolved. |
| Public framebuffer/I2C route | Unavailable on the recorded active M5 external path; no type-4 advertisement observed. |
| Isolated DPDV open-check | One open/immediate-close runtime validated with zero selectors; in-flight-read teardown remains unproved. |
| One-byte selector readiness | NOT_READY_FOR_ONE_BYTE_DPCD_READ; NO_TRANSPORT_READY. |
| In-flight read termination | INFLIGHT_READ_TERMINATION_NOT_PROVEN; no guaranteed response-independent completion/drain of the DCP context wait. |
| Exact W06 wake/removal proof | W06_WAKE_STATE_UNRESOLVED; abandon this selector transport on the daily-use Mac. |
| Native DPCD access | Not yet exercised. |
| MST control baseline | M5_DCP_FIRMWARE_MST_CONTROL_EVIDENCE_FOUND_PACKETIZER_UNRESOLVED; identified M5 firmware has MST codec/topology and payload controls. |
| One-link MST packetizer | M5_DCP_MST_PACKETIZER_PRESENT_BUT_STREAM_BINDING_UNRESOLVED; concrete source slot-table and activation code found, but independent multi-stream binding and an architectural one-stream limit remain unproved. |
| Final stream ownership | M5_DCP_STREAM_OWNERSHIP_UNRESOLVED; MACMST_ARCHITECTURAL_VIABILITY_UNRESOLVED. Static packetizer expansion stopped after M3D. |
| Static feasibility ceiling | MACMST_STATIC_FEASIBILITY_INCONCLUSIVE; STATIC_PACKETIZER_ANALYSIS_FROZEN; NO_FURTHER_T8142_PACKETIZER_REVERSE_ENGINEERING_AUTHORIZED. |
| Evidence handoff | SACRIFICIAL_DYNAMIC_EXPERIMENT recommended conceptually on a separately approved non-daily-use system; no experiment authorized or performed. Implementation resume gates A-E are unmet. |
| Sacrificial design gate | M4P: SACRIFICIAL_EXPERIMENT_REQUIRES_UNAVAILABLE_CAPABILITY. No qualified M5 ownership observer or informative ordinary stimulus established; no experiment or security change performed. |
| Observer development scope | M4Q: M5_OBSERVER_REQUIRES_MAJOR_PLATFORM_ENABLEMENT for the current m1n1 path. Wait for upstream M5 guest/observation support; sacrificial purchase is premature. No implementation or experiment performed. |
| Upstream wait state | Resume gates: MACMST_PROJECT_STATE_UPSTREAM_BLOCKED; OBSERVER_WORK_REMAINS_BLOCKED. U1-U5 WAITING; SACRIFICIAL_M5_PURCHASE_PREMATURE. Research chain integrated and tagged m5-observer-platform-gap-v1.1; no new technical investigation or experiment. |
| Separate platform-development track | M5P0: owner authorized compile/offline self-enablement, superseding the project-wide wait restriction. Platform work stopped at upstream's tracked no-AI policy before building. Independent offline importer: 21 synthetic tests pass. M5_OBSERVER_CODE_NOT_READY_FOR_TARGET_TEST; SACRIFICIAL_M5_STILL_PREMATURE. |
| Offline observer pipeline | M5P1: OFFLINE_OBSERVER_PIPELINE_READY; frozen schema, synthetic producer/replay, conservative evidence/bundle analysis and human-only handoff. 124 focused tests; zero real-evidence passes. Target state and purchase remain not-ready/premature; USB_C_HUB_CONNECTION_NOT_REQUIRED. |
| Host source/control discovery | M5P2: RUNTIME_OBSERVER_STILL_REQUIRED; HOST_STREAM_CONTROL_PATH_UNRESOLVED. Exact 25G83 host display records, role values, RPCs and physical-port collections qualified, but same-DPTX independent sources, mirror source model and MST policy gate remain unresolved. Offline pipeline and all hardware/static safety gates unchanged; no hub connection or m1n1 access. |
| Passive runtime differential | M5P3: PASSIVE_RUNTIME_TOPOLOGY_PARTIAL. Owner-confirmed ordinary hub attach after the disconnected hard pause; identical public-only captures expose one new DCPEXT0/Unit 0 display-facing tuple, one VG248 logical record and non-tunneled USB-C DP state. No same-DPTX source evidence or private call. TARGETED_PUBLIC_LOG_OBSERVATION_WARRANTED as a future proposal only; no logs collected. |
| Public lifecycle log correlation | M5P4: M5P3 published unchanged; 477 scoped historical kernel records retained. HISTORICAL_LOG_EVIDENCE_SUFFICIENT; PUBLIC_LOG_RUNTIME_PARTIAL. Reported sink count 0 -> 2 is not two identified sinks/sources; source and mirror/MST policy remain unestablished. EXTERNAL_DP_PROTOCOL_CAPTURE_WARRANTED for future planning only. Hub remains connected; no reconnect, log stream or private operation. |
| External observation architecture | M5P5: M5P4 published unchanged. AUX_CAPTURE_CAN_RESOLVE_NEXT_GATE for complete upstream topology/allocation traffic; main-link transmission and internal source ownership remain separate. Qualify temporary DPA-400/USB-C or Ellisys Std DP access; PURCHASE_NOT_YET_JUSTIFIED. Independent wire-schema design and W0-W4 ladder only; no signals captured, hardware changed or software observer executed. KEEP_CURRENT_HUB_CONNECTED. |
| AUX qualification and access | M5P6: M5P5 published unchanged. DPA-400 current product 065055/software 2.1.10; USB-C cable 546109 on the product page conflicts with manual 546127. DPA400_TOPOLOGY_COMPATIBILITY_UNRESOLVED; ELLISYS_W1_REQUIREMENTS_PARTIAL; AUX_ACCESS_NOT_READY. TEMPORARY_DPA400_ACCESS_FIRST through qualification/outreach, not a secured unit. Unsent contact package; USER_OUTREACH_REQUIRED; DO_NOT_PURCHASE_ANALYZER_YET; KEEP_CURRENT_HUB_CONNECTED. |
| Self-built AUX observer | M5P7: M5P6 published unchanged; independent AUX/MST decoders, loss-aware W1.1-W1.9 evaluation, A-H synthetic scenarios and raw-preserving bundles. 94 new tests plus 200 preserved tests pass. SELF_BUILT_AUX_OBSERVER_PRIMARY; NATIVE_DP_AUX_TAP_PREFERRED; MORE_ELECTRICAL_RESEARCH_REQUIRED. No qualified build BOM, hardware capture or M5 functionality claim. CURRENT_HUB_STATE_NOT_REQUIRED; OUTREACH_CAN_RUN_IN_PARALLEL. |
| Passive AUX electrical qualification | M5P8: symmetric AC-coupled comparator architecture, loading/idle-bias/charge models, analysis-only SPICE subcircuit and conditioned decoder fixtures. COMPARATOR_FRONTEND_PREFERRED; TLV3502_NOT_PREFERRED; POWERED_OFF_BEHAVIOR_UNRESOLVED; MORE_ELECTRICAL_RESEARCH_REQUIRED. Review 5 PASS / 1 FAIL / 10 UNRESOLVED. All 327 offline tests pass; SPICE/EDA execution and B1-B6 remain unperformed. No purchase, assembly or Mac interaction. |
| AUX electrical closure and release | M5P9: reproduced 14.2101 mV and proved capacitive mismatch dominates; perfect resistors leave 14.2082 mV. Executed numerical E0-E10 circuits and frozen-decoder pipeline profiles. Review 6 PASS / 2 FAIL / 14 UNRESOLVED; MORE_ELECTRICAL_RESEARCH_REQUIRED. All 361 offline tests pass. No construction schematic/BOM release; conditional future bench work is M5P10, not performed here. CURRENT_HUB_STATE_NOT_REQUIRED. |
| Differential-first frontend closure | M5P10: direct sensing improves modeled CM conversion but cable DC bias defeats direct slicing. Conditioned dual-window model resolves nominal synthetic completeness; N0-N12 and twelve pipeline profiles retained. Standard modular backend interface frozen. Review 10 PASS / 1 FAIL / 19 UNRESOLVED; analogue loading, off-state and component bounds prevent construction release. All 412 offline tests pass. No schematic/BOM release or hardware action. Future physical milestone M5P11. CURRENT_HUB_STATE_NOT_REQUIRED. |
The owner-controlled connected/disconnected/reconnected test now associates the External DCPEXT0 / Unit 0 DP/AV path with a ZMUIPNG 14-in-1 hub on the right-side USB-C socket. Both physical VG248 panels show the same image according to the owner, while macOS enumerates one external logical display. Published transport state reports USB-C port 4, two lanes, HBR3, and no tunneling. This experiment was not performed with the earlier HP dock.
All 97 inventoried IODP names resolve. ABI-02 resolves the CF lifecycle, authenticated PS190 caller bindings, DPDV client routing and selector-0 host read path. RPC-03 traces the lower AFK path: the host buffer is zero-filled, but the DCP wait has no local deadline and its selected abort hook is a no-op. Complete-reply/firmware semantics and selector-call authorization remain unresolved. NOT_READY_FOR_DPCD_TEST. No native AUX or DPCD transaction has been executed; MST source support remains unknown.
The research/dcp-rpc-safety follow-up revalidates the External path and adds
deadline-free admission waits, conditional recovery triggers, concrete endpoint
cleanup and fresh signing/policy evidence. Its explicit readiness matrix
keeps reply completeness, bounded waiting and cancellation blocked. It was
integrated into main by merge 2ffc77d9d532502495fca5d88291d42eed61e45b; the
research-baseline-v0.1 tag and the completed research branch are retained.
The separate research/public-dp-native investigation reports
PUBLIC_IOFRAMEBUFFER_PATH_UNAVAILABLE for the active M5 external display:
public CG mapping returns null and independent registry queries find no
IOFramebuffer/I2C interfaces. No count-call IOReturn or zero mask is fabricated
when no target exists. See the public-path evidence and limits.
That investigation was integrated into main by merge
dd439c80f7b1190f0e033dcf1a19242de2bd3039, with both completed research branches
retained. It does not change the private-path gates or claim absent AUX/MST hardware.
M2C on research/dpdv-isolation-safety traces current user-client close/death,
deferred finalization and AFK command release, and adds a test-only mock helper.
Its separate open-check matrix
remains NOT_READY_FOR_ISOLATED_DPDV_OPEN_CHECK. No private open or selector
was invoked, and NOT_READY_FOR_DPCD_TEST is unchanged. The proposed
macmst experimental dpdv-open-check command is not implemented.
M2C was integrated into main by merge
a7dc7d647e3e8fccb2e40e5cd56e3f9a8410697b, with its branch and the baseline tag
retained. M2D on research/dpdv-open-path-proof now separates
pre-selector open/close work from method dispatch.
The user-client gate is passive and provider close is owner-guarded, but meaningful
indirect/lifecycle gaps leave CALL_GRAPH_INCOMPLETE. The
applicability matrix
does not automatically import selector cancellation risks into open-only.
The isolated-open result remains not ready; no private backend or transaction
was added, and the DPCD gate is unchanged.
M2D is integrated by merge 73e0caaaf079b2177d5207f2320c5fc61dac9117.
M2E on research/dpdv-open-final-proof identifies the ordinary shared workloop,
proves local removal for a never-used native gate, and separates task ownership
from provider-open ownership. The alternate user-server factory route remains
unexcluded. The current 20-gate matrix
therefore remains NOT_READY_FOR_ISOLATED_DPDV_OPEN_CHECK for specific
ownership/work/close uncertainties, not generic graph incompleteness.
M2E is integrated by merge ce28518eb301592ed6dd3d2b75d152b1a8e54970.
The focused M2E.1 runtime discriminator
on research/dpdv-userserver-discriminator verifies native provider provenance,
but no tested public marker proves the private userServer field's value.
It returns USER_SERVER_RUNTIME_STATE_UNRESOLVED and stops static expansion;
both not-ready gates remain unchanged. No private open or privileged inspection
was performed.
M2E.1 is integrated at 1fc8f0241acec829fa732503c13a9ab588e26fb0, tagged
pre-dpdv-open-v0.2 before adding the real helper. M2F
on experiment/dpdv-open-check built and audited the isolated open-only tools,
but its fresh dry-run preflight found both displays inactive and DP LinkRate=0.
It stopped before helper selection: EXPERIMENT_NOT_RUN, zero opens/closes,
no retry. NOT_READY_FOR_DPCD_TEST remains unchanged.
After a new recovery request and explicit approval on 2026-09-13 UTC, the committed no-open check passed and one real DPDV open/close returned success with no sampled public display change. The runtime record establishes DPDV_OPEN_CLOSE_RUNTIME_VALIDATED, not a null userServer or safe selector path. The one-shot marker is consumed; no retry. The global NOT_READY_FOR_DPCD_TEST gate remains unchanged.
That runtime state is integrated at 3f5f0cd887ed2ef5c8dbadc9abb278792c3150be
and annotated as dpdv-open-runtime-v0.3. M2G's one-byte reassessment
on research/selector0-one-byte-readiness compares both transports and checks the
exact selector-0/address-0x000/length-1 contract. It finds
NO_TRANSPORT_READY and NOT_READY_FOR_ONE_BYTE_DPCD_READ: one byte does
not bound the kernel wait, recover the lost reply length or establish read
cancellation. The pure revision classifier and short-reply tests do not implement
a transport. M2G repeats no private open/close and creates no read-attempt marker.
M2G is integrated at 2b1565ee61337a368d75980af281621a5959000e, tagged
selector0-safety-v0.4. M2H's in-flight termination investigation
on research/inflight-read-termination traces the exact stack-context wait,
command ownership, concurrent close, task death and disconnect paths. It reports
INFLIGHT_READ_TERMINATION_NOT_PROVEN. The raw uninterruptible/no-deadline
wait has no proved response-independent completion-and-drain contract; conditional
error synthesis and list cleanup are different paths. Constant 500 remains an
opaque firmware parameter, not a demonstrated host deadline. No transport or
readiness gate is promoted, and no private operation or read helper is added.
M2H is integrated at 1a014d8d3c3cd35ed5381160b809cf4803d79d69, tagged
inflight-read-safety-v0.5. M2I's exact W06 proof
on research/w06-wake-or-strand establishes the stack context/event and confirms
that suspicious cleanup targets this read's pending list. It does not prove the
required cleanup-trigger ordering or universal callback quiescence:
W06_WAKE_STATE_UNRESOLVED. Further static expansion of this selector
transport is stopped; abandon it on the daily-use Mac. No selector test or
another generic graph-search milestone is proposed. NO_TRANSPORT_READY and both
not-ready execution gates remain unchanged; no proven unsafe lifetime claim or
M5 hardware capability conclusion is inferred from the unresolved result.
M2I is integrated at a882c1dc75501c03347050f1cdb91c38df2af39d, tagged
selector0-retired-v0.6. Selector 0 is RETIRED_ON_DAILY_USE_M5.
M3A source feasibility pivots to the
M5 source implementation: a pinned Linux signature oracle and static scan of 13
kernel/11 userspace images find no qualified host sideband codec, topology model
or payload allocator. The DCP firmware stream-to-payload packetizer remains
opaque, so the result is M5_MST_SOURCE_FEASIBILITY_UNRESOLVED, not a finding
that M5 cannot implement MST. The global gate is NOT_READY_FOR_DPCD_TEST.
No private operation, new selector transport or hardware experiment is proposed.
M3A is integrated at 24f2d1c3065ec0d7f80b5a53077f3e169f79368f, tagged
m5-mst-host-scan-v0.7. M3B's firmware investigation
uses the exact 25G83 BuildIdentity for Mac17,2/J704AP, which references
Firmware/dcp/t8142dcp.im4p. Range-only extraction and offline analysis identify
a real MST sideband codec, routed topology and payload/ACT control primitives.
The result is M5_DCP_FIRMWARE_MST_CONTROL_EVIDENCE_FOUND_PACKETIZER_UNRESOLVED:
multiple independently timed streams on one DPTX link are not established.
M3A's host negative is preserved; the firmware is not byte-identical to the
selected M4 image, although the MST diagnostics and exact CRC leaves are shared.
M3B's then-next ownership question was examined in M3C/M3D and is now frozen.
Selector 0 remains RETIRED_ON_DAILY_USE_M5; no private operation occurred.
M3B is integrated at c89bf66bac79893f4e6910e10d4a1126775edce7, tagged
m5-dcp-mst-control-v0.8. M3C's one-link packetizer investigation
traces the source record, selected-device descriptor, register-table writes and
ACT trigger in the retained M5 firmware. Result:
M5_DCP_MST_PACKETIZER_PRESENT_BUT_STREAM_BINDING_UNRESOLVED.
The recovered path replaces one table using payload ID 1; neither that literal
nor its 64 slot fields proves an architectural stream limit or multi-stream
support. M3C authorized one final packetizer-object ownership pass, completed below.
No private operation or hardware experiment occurred; selector retirement and
NOT_READY_FOR_DPCD_TEST are unchanged.
M3C is integrated at 5beb1ac304a1715dc9fb7cad9b3322819b8fd140, tagged
m5-dcp-packetizer-v0.9. M3D's final ownership proof
finds runtime controller registration, collection-based attachment, scalar
selected-device replacement and scalar current timing. It proves neither
multiple concurrent source contexts on one physical DPTX nor a hard one-stream
architectural limit: M5_DCP_STREAM_OWNERSHIP_UNRESOLVED and
MACMST_ARCHITECTURAL_VIABILITY_UNRESOLVED. The single remaining opacity is
runtime source-controller membership of one physical T8142 DPTX register owner.
Stop static packetizer expansion. No M3E graph search or M4A host-control
discovery is proposed. M3C's packetizer baseline, selector retirement and DPCD
gate remain unchanged; M3D performed zero hardware/private display operations.
M3D is integrated at c5bc1b1bacd7742a4bbc1b54285336e9d51302a5, permanently
tagged m5-mst-static-ceiling-v1.0. M3E0's static conclusion and handoff
freezes MACMST_STATIC_FEASIBILITY_INCONCLUSIVE without weakening the proven
MST control/source packetizer or claiming a global single-stream limit.
The frozen opacity is:
Runtime source-controller membership of one physical T8142 DPTX register owner.
The handoff compares exactly four new evidence sources
and recommends only a separately risk-reviewed SACRIFICIAL_DYNAMIC_EXPERIMENT
on a non-daily-use system. No experiment is implemented or executed; all
implementation resume gates
remain unmet. STATIC_PACKETIZER_ANALYSIS_FROZEN and
NO_FURTHER_T8142_PACKETIZER_REVERSE_ENGINEERING_AUTHORIZED apply.
For a fresh clone, build the probe before optionally creating a public capture:
python3 tools/capture_baseline.py --probe build/macmstThe collector prints a new UTC-named directory. The following source-feasibility commands are historical reproduction examples, not authorized next work after the static ceiling:
python3 tools/scan_mst.py --inventory --output artifacts/probes/m3a-local/inventory.json
python3 tools/scan_mst.py --kernel-image com.apple.iokit.IODisplayPortFamily --output artifacts/probes/m3a-local/dp.jsonThis parses local image files, requires a running-kernel UUID match and never
invokes private IODP functions or updater code. See the
M3A reproduction and scope.
Earlier static/selector investigation commands and next-step proposals are
historical, not instructions to resume packetizer analysis or that transport. The proposed
macmst experimental dpcd-read command is not implemented.
Historical capture identities, hashes, binary UUIDs and preferred addresses in the reports are deliberate provenance, not reusable device handles or portable call targets. Raw captures, copied upstream sources, Apple binaries, builds and local editor configuration are excluded from Git. A fresh clone does not contain those artifacts; reproduce observations locally and check hardware/OS identity before comparing findings. No Apple binary is distributed by this project.
- Execution plan and verification
- Evidence ledger and exact sources
- M5/DCP stack baseline
- Native AUX investigation
- Dock observations
- Connected/disconnected differential and graph
- IODP API and M2-02 readiness
- ABI-02 lifecycle, dispatch and remaining safety gates
- RPC-03 request/reply, wait and cancellation contract
- DPDV authorization analysis
- Public DisplayPort-native API and M5 enumeration
- M2C isolation, teardown and open-only safety
- M2E.1 discriminator and historical open-only proofs
- M2G one-byte selector contract and 19 readiness gates
- M2H in-flight read lifetime, waits and termination result
- M2I exact W06 wake/removal proof and mandatory stop
- M3A M5 MST source feasibility and firmware boundary
- M3B identified M5 DCP firmware, MST controls and packetizer limit
- Pinned MST source signature oracle
- Protocol constants and decoding
- Language/architecture ADR
No project license has been selected or included. This baseline does not grant a reuse license. Linked upstream projects retain their own licenses.