Sync with the docs refresh: code-truth pass, Beta labels, blind-review fixes
Protocol: sync_timeout bounds; the descriptor class has no caller P1 double-blind wave adjudication (spi-hid-core.c 1-1100): the descriptor-request timeout class is classified fatal in the protocol table, but this driver never issues a descriptor sync — geometry is learned through the DESCREQ sequencer path — so the old wording implied a recovery path with no caller. Feature queries are the only synchronous-request class the driver issues. sync_timeout_ms is clamped at probe into [100, 60000] (negative/zero lose the fail-safe timeout).
wiki: P11 adjudication — single-opcode examples, read-approval shapes, 12 MHz tier Protocol: the DESCREQ / vendor-init / SET_FEATURE / GET_FEATURE examples showed the doubled-opcode legacy form (02 02 ...) as canonical while the prose two paragraphs above says one 0x02; replaced with the plain frames the driver sends by default (byte-pinned in tests/wire_frames_test.c) and named wire_double_opcode=1 as the switch for the legacy form. The read-approval step now states the field-settled 5-byte legacy default and that the 9-byte reference shape is read_frame_variant=0. Wire-Protocol: read-approval section rewritten (both shapes, the read_frame_variant values, the correct constant name SPI_HID_WIRE_OPCODE_READ); the standard-enumeration example now uses the single-opcode frames and the legacy read shape; SPI100 speed tier index 0 is 12 MHz (matching docs/SPI_REGISTERS.md and this page's own prose), not 12.5. Hardware: same 12 MHz fix in the speed configuration table. Adjudicated from the P11 doc-claim wave (legs at pin 311fecc); the other snapshot findings were already fixed on the live wiki.
Wire-Protocol + Protocol: single opcode, the real length encoding, both header offsets The pages described the doubled opcode as the frame and the header as always at offset 5. Neither matches the frames this device is driven with: the default request carries a single 0x02, and this panel prefixes its answers with three bytes, so the header sits at 8 as well. The report length is a 12-bit count of 4-byte words, not a whole-report length, and the frames carry version 2. The vendor-init frame is 18 bytes, not 19.
wiki: Protocol, Wire-Protocol, Report-Descriptor — wire-accurate rewrite
wiki: refresh for 1.5.0 and SL3 MSHW0162 support - Home: SL3/4, per-device grids, unified installer, 1.5.0/1.6.0 status - Build-and-Install: sl4a-touch.sh, DKMS 1.5.0, MOK DER, sync_timeout_ms, per-device parameter table (3456/4056, 30/33, alpha 7) - Usage & Troubleshooting: GET_REPORT timeout fix, recovery power-cycle - Hardware: MSHW0162 section (78x52, 4056 cells) - Pipeline/Multi-touch/Config-Table/Protocol/Wire: per-device notes - Architecture: dormant poll fallback note (PR #7) - Sidebar: link Standard-Touch-Mode, Multi-touch, Usage pages
docs: initial technical wiki — protocol, pipeline, config, hardware, build, reverse engineering