The maintained line of this project is the
apertobranch.mainis kept as the original author's line; all current code, documentation and releases (tagsvYYYY.MM.DD) live onaperto. Please base work and pull requests onaperto.
Open reimplementation of Ingenic's closed TX-ISP kernel driver (tx-isp-<soc>.ko) for
T10, T20, T21, T23, T30, T31, T40 and T41. The goal is behavioural equivalence with the
OEM driver: same ioctl and libimp ABI, same register sequencing, same image behaviour,
with cleaner unload/reload, checked inputs and less memory.
It works with Ingenic's unmodified libimp.so and with the open replacement
OpenIMP. Open stack = open-tx-isp + OpenIMP + a streamer
(timps). The aperto branch carries the released open stack on top of the original main line; see
Branches and releases.
This is a reverse-engineering and compatibility effort, not a greenfield pipeline: OEM binary
analysis, libimp ABI work and recovery of tuning data.
State on aperto (2026-10-04). "Fully open" = open driver, OpenIMP and streamer run from a flashed image.
| SoC | Status |
|---|---|
| T10 | Fully open; day/night, reload (5 cycles) and boot guard verified. Image controls partly documented. Module 731 KB. |
| T20 | Fully open; 1 h 44 min soak without errors, 10x stop/start and reload without an oops, rmmod during streaming refused. Module 736 KB. |
| T21 | First open bring-up, now fully open; AE/ADR/defog/AWB lifted from the vendor module. Module 452 KB (vendor 616). |
| T23 | Fully open (native encoder in OpenIMP); module 622 KB (vendor 857); vendor AE default. Frequent Helix frame drops fixed (residual interrupt, kernel patch merged upstream); still open: a rare single Helix encode error (errno 5), no real WDR. |
| T30 | Builds against a real T30 kernel; earlier bring-up on hardware. Not exercised in the latest campaign. |
| T31 | Reference SoC; SC2336, GC2053, SC301IOT; 2 h 53 min soak without errors; module 711 KB (vendor 829). |
| T40 | Device-tested earlier (T40XP/GC4653); statistics restart stability is a known limitation. Not in the latest campaign. |
| T41 | Fully open from a flashed image (H.264, H.265); reload verified (10/10); module 80 KB smaller than before. Open: flip, night column noise. |
Per feature and SoC: FEATURE_MATRIX. History: CHANGELOG.md.
- Reload and stop: 10 stop/start and rmmod/insmod cycles without an oops on T20/T21/T23/T31/T41 (T10: 5 cycles).
- T20/T10 give back about 8 MB RAM (unused 8 MiB V4L2 frame pool off by default); on a T20 the open stack measured 10.5 % streamer CPU against 25.2 % with the vendor stack, snapshots 0.20 s against 0.45 s.
- Smaller modules than the vendor on T21, T23 and T31.
- Checked inputs (all user copies, QBUF window, bounded waits), sensor module pinned while streaming.
- T21 controls and noise reduction act (the vendor ignores them), T10/T20 noise-reduction strength acts.
- Shortfall logging with a concrete parameter value when reserved memory is too small.
Details and streamer integration notes: OPENIMP_BEYOND_VENDOR.
Out-of-tree kernel modules, built against a Thingino buildroot output (toolchain and vendor
kernel tree, Linux 3.10.14 for T10-T31, 4.4.94 for T40/T41). The helper picks the SoC with SOC:
SOC=t31 ./build_local.sh # t10 t20 t21 t23 t30 t31 t40 t41
TH=/path/to/thingino-firmware SOC=t23 ./build_local.shTH, ROOT, KDIR, CROSS and ARCH can be overridden (see the comments in build_local.sh).
It builds driver/<soc>/ into tx-isp-<soc>.ko plus the diagnostic driver/tx_isp_trace.ko; when no
module for the SoC was built locally the result is a compile baseline only. The T20 driver expects the
external/ingenic-sdk submodule (git submodule update --init). Host tests for kernel-independent
primitives: make -C tests check.
The packages open-tx-isp (this driver) and openimp (userspace) are in the upstream
thingino-firmware branch aperto
(#1756), selected with
BR2_PACKAGE_THINGINO_ISP_OPEN (menu "ISP stack") and pinned by commit SHA to the aperto branches
of the opensensor repositories. The module is installed as tx-isp-<soc>.ko and replaces the proprietary one;
SDK sensor, audio and AVPU modules stay. The kernel VPU/rmem stability patches
(#1748,
#1752) are merged there. The optional
boot guard BR2_PACKAGE_THINGINO_ISP_GUARD (#1749,
default off; isp_open=auto|manual|off) skips the ISP/sensor modules after an unstable load so a bad
driver cannot boot-loop the camera. Once the first date tag exists on aperto, thingino's aperto branch will pin that tag instead of a SHA.
main: the original author's line (opensensor). It is left untouched and is a strict ancestor ofaperto.aperto: the open stack release line: OpenIMP + open-tx-isp, as used by the thinginoapertobranch. Fast-forward only; every commit was flashed and checked on cameras. Releases are taggedvYYYY.MM.DDon this branch, and thingino pins a tag instead of a SHA.- Development and the device-test campaign happen in the Lu-Fi forks (branch
next= integration,claude/<topic>= topic branches); tested work reachesapertofromnextafter a clean soak. - Companion repository: opensensor/openimp (branch
aperto). Both repositories are released together; use matching tags.
- Wiki (one wiki for both repositories): module parameters, memory (rmem, ispmem, MMAP pool), troubleshooting, install and boot guard, release scheme.
docs/T31_ISP_ARCHITECTURE.md: hardware and driver architecturedocs/ISP_SOC_ALGORITHM_VARIANCE.md: algorithm differences between SoCsdocs/DRIVER_REUSE_PLAN.md,docs/SHARED_DRIVER_LIBRARY.md: shared codedocs/IMAGE_TUNING_PRD.md: image tuning plandocs/ISP_PERFORMANCE_BENCHMARK.md: on-device CPU/memory baselinedocs/V4L2_CAPTURE_PATH.md: V4L2 capture architecturedocs/INTERRUPT_DEBUG_GUIDE.md: interrupt debuggingdocs/re/: reverse-engineering dumps (T31 vendor module HLIL)- Per SoC:
driver/t10/README.md,driver/t20/README.md,driver/t21/README.md(+COMPARATIVE_ANALYSIS.md),driver/t23/README.md,driver/t30/README.md,driver/t31/README.md,driver/t40/README.md,driver/t41/README.md
Layout: driver/<soc>/ per-SoC driver, driver/common/ and driver/include/tx_isp/ shared code and
interfaces, docs/ notes, tests/ host tests and oracle checks, tools/ on-device probes and generators,
sensor-src/ sensor sources used by the T10/T20 builds.
Open an issue at opensensor/open-tx-isp (kernel driver, ISP, memory) or opensensor/openimp when unsure. Please include the SoC and sensor, the revisions of open-tx-isp, OpenIMP and the streamer, dmesg (including any shortfall line such as set ispmem >= N KB), the streamer log, the stream set and the rmem/ispmem values. Do not post addresses, credentials or location names. Details: Troubleshooting.
Contributions are welcome when grounded in OEM binary analysis, libimp ABI validation, hardware
logs or captures, tuning/calibration recovery or documentation. For behavioural changes state the OEM
evidence, the files changed, how it was validated and what remains uncertain.
Prior art from the Ingenic / Thingino reverse-engineering community, especially thingino-firmware, ingenic-sdk and OpenIMP, and the upstream opensensor/open-tx-isp.
This project is licensed under the GNU General Public License (GPLv3).
Not affiliated with or endorsed by Ingenic Semiconductor. "Ingenic" is used only to name the SoCs this project supports.