Two fixes, verified on the AX211 (8087:0033), ibt-1040-0041.sfi, 720 KB:
1. TryHeader waited 1500+2000 ms for secure-send results after the CSS and
key/signature sends, but on success this controller stays SILENT until
the end of the whole download (traced) -- both timeouts always burned in
full. A rejection arrives within milliseconds, so 250 ms windows lose
nothing and save ~3 s per cold boot.
2. The payload now goes over the bulk OUT endpoint with up to 7 fragments
in flight (the btusb bootloader path for 0xFC09), replacing ~2900
synchronous 3-stage EP0 control transfers. Headers stay on EP0; the
ACL TX DMA ring is reused (no ACL header, no NOCP credit accounting).
DrainBulkTx() ensures all bytes reach the controller before waiting for
the download-complete result.
Also in this branch since main: IRQ-safe BT-TRACE ring (KernelLogStream in
TransferCallback deadlocked on the terminal Mutex from MSI context), xHCI
interrupt-IN ZLP length fix, always-re-arm of the BT event pipe,
InPollContext same-core owner check, TLV version read retry.
Co-Authored-By: Claude Fable 5 <[email protected]>