6db0f48170
Post-implementation review returned FAIL with two verified-CRITICAL findings; all legitimate findings fixed in this round: CRITICAL — engine wrote IC_CON/IC_TAR while enabled (DesignWare databook forbids; Linux i2c_dw_xfer_init disables first). Engine restructured: wait-idle -> disable -> program -> enable with IC_ENABLE_STATUS polling on every transfer. CRITICAL — Intel LPSS PCI bring-up skipped parent-device init. intel-lpss-i2cd now claims functions via pcid_interface (connect_by_path + enable_device), validates the real BAR size, and performs intel_lpss_init_dev's sequence (reset-deassert + 64-bit remap address at BAR0+0x200), ported from Linux drivers/mfd/intel-lpss.c. MAJOR fixes: - wait_for checks TX_ABRT before success predicates — a NACKed write no longer reports success via post-abort idle state - SCL timing corrected to Linux's formulas: HCNT uses sda_fall_ns, round-to-nearest division (FS 100/200, SS 552/652 for bxt 133 MHz) - stop=false rejected honestly instead of hanging on the idle wait - recover(): ABORT-bit cycle + disable + state flush after any failed transfer - validate_request: segment/byte/address/10-bit limits before any MMIO - i2cd + endpoint: exact-first adapter resolution; last-component matching accepted only when unambiguous - i2cd registration validates provider_scheme as a single safe scheme-name component - I2cTransferResponse gains typed status (I2cTransferStatus, serde-defaulted, wire-compatible) - endpoint::serve takes a Result-returning on_ready callback; setrens failure is fatal (fail-closed namespace reduction) - unexpected i2cd registration responses are fatal for that controller Tests: dw-i2c 5 (timing vectors, validation, resolution), intel-lpss-i2cd 1 (PCI ID table coverage), full workspace cargo check clean, base cooks for x86_64-unknown-redox. Refs: local/docs/LG-GRAM-16Z90TP-COMPATIBILITY-PLAN.md review-fix round