MPI3508

Panel-specific touchscreen configuration for Pi 5 / Kali / Xorg-libinput.

View the Project on GitHub SecurityRonin/MPI3508

Validation and limits

Current evidence boundary

The production candidate is signed commit 107a14e28a6d5d5242310fba19f3077b4caece5f, installer SHA256 3ffe690f5a9e77fab8cf4c1f8cb6d2939ed4890a52a0ae0b2a8d0d6906c51029. It compares only content hash, size, owner and mode when checking files recorded by an earlier run, because inode and device numbers on the FAT boot partition change across a remount or reboot. Install also shows the full diff of every file it will change before confirmation. Source-stage checks recorded on 8 October 2026 passed compilation, lint, formatting and bounded public-tree/commit-message scans. The full suite discovered 114 methods: 113 executed with one platform skip on Darwin, and the optimized unsafe-path and bootstrap subsets each passed nine methods. GitHub Actions on ubuntu-latest (x86-64) ran the same checks with Python 3.11 and 3.14: 114 methods each, one platform skip, including the native Linux preflight refusal control. The Linux arm64 run recorded for the earlier candidate has not been repeated for this one. The remount tests simulate a new inode and device number; they do not remount a real FAT filesystem.

An independent review passed the candidate on 8 October 2026. The pinned public download matches the installer SHA256 above, and this documentation is built and deployed by GitHub Pages.

The new public installer has not been run on the reference Pi. The inherited reference record concerns a manually configured panel, not an installation by this program.

Evidence What it supports Limit
[QUOTED] Scrubbed reference record, supplied 6 October 2026 A panel-specific profile and recorded startup/property readback on one panel Raw hardware observations were not independently repeated for this document. No fresh physical edge test.
[OBSERVED] Debian-published upstream libinput manual and pinned vendor source, read 6 October 2026 The documented option format and the contents of those source revisions A documented option or vendor preset does not establish a particular panel’s accuracy.
Synthetic installer tests (T3) Configuration, refusal and transaction behavior in constructed fixtures Revision-bound independent execution is recorded above; author-created fixtures are not an independent oracle for panel accuracy.
Native Linux path controls (T2) Selected install/restore, unexpected-mount refusals and descriptor-alias/cache checks on real Linux filesystems Chosen container scenarios, not a Pi installation or an arbitrary privileged dynamic-overmount test.
Source-contract C oracle (T2) C structure layout, ioctl request values and decoding of chosen ABI bytes agree with the Python implementation Compiled on Darwin against pinned Linux header fragments with synthetic values, not against a running Pi kernel.

Reference profile

The supplied profile is pi5-kali-reference: Raspberry Pi 5 / Kali arm64 / Xorg-libinput, ADS7846 X/Y bounds 200–3900, x-plate resistance 150 ohms and reference wiring assumptions. Its full nine-value matrix is:

-0.002296031116191308 -0.9921051268461499 1.0030508935417717 -1.025727266567984 -0.012705460331736715 1.0049107831524058 0 0 1

These values are copied from the supplied scrubbed profile, not a new fit or an independent measurement. The profile uses libinput’s inclusive ABS endpoint normalization. Recorded property persistence is different from physical accuracy. No pixel-error bound, edge-coverage result, accuracy percentage or cross-unit compatibility result is available in this publication record.

What verification must distinguish

The acceptance contract separates:

  1. Saved-file verification: an independent read of installed configuration, including equality of the complete parsed ADS7846 parameter set, not merely reuse of the planner’s output.
  2. Runtime observation: available device-tree parameters, ABS bounds, Xorg rule application, live libinput matrix and identity Coordinate Transformation Matrix. Device selection uses identifying properties, not changing event numbers or process IDs.
  3. Physical acceptance: stylus tests across the actual display, including edges. Automatic verification does not perform this.

Missing runtime access is “unavailable” or “not examined”, not a successful check and not proof of mismatch. Install success is a saved-state result only. Other hardware, wiring, Wayland and display geometries remain outside this reference profile.

Installer test scope

The required independent suite covers configuration scope and line endings; explicit profiles; conflict and unsupported-environment refusals; linked/unsafe paths; malformed state; idempotence; concurrent drift; transactional failure points; rollback; interrupted work; and drift-safe restore. Real CLI/filesystem transactions must also be exercised in disposable Linux. Tests of synthetic files cannot establish behavior on a physical Pi.

The independent checker, not the implementation author, owns acceptance. Publication requires compilation, full tests, lint, formatting and secret/private-identifier checks at the delivery revision, including commit messages. A clean source tree and deployed documentation links are separate publication checks.

Native Linux mount scope

The source observes opened descriptors and rechecks held handles against their current paths. Only the exact /boot/firmware directory may introduce a separately mounted filesystem; that exception does not extend to its target file. An unavailable mount observation remains distinct from an observed unexpected boundary.

Selected native Linux controls (T2) completed install/restore on an ordinary tree and with /boot/firmware backed by a bind mount or tmpfs. Unexpected directory, target-file and lock-file mounts refused before transactional checkpoints, with the examined fixture and host manifests unchanged. Separate cache controls used actual alias descriptors. Successful restoration recovered recorded target bytes and metadata, while atomic replacement changed inode identity and durable transaction state remained.

The native descriptor reader agreed with independently read Linux fdinfo/mountinfo. Constructed grammar and read-error controls are T3. Container processes had no effective or bounding capabilities and NoNewPrivs was set. These are bounded observations: arbitrary concurrent mount manipulation by a process with CAP_SYS_ADMIN was not examined. Descriptor-alias/cache controls are not a dynamic-overmount test, and neither establishes runtime touch accuracy on a Pi.

Sources read

The Xorg libinput manual’s CalibrationMatrix entry specifies nine space-separated floating-point values forming a 3×3 matrix. The Debian-published packaged upstream manual and the libinput project’s configuration documentation were read on 6 October 2026:

The upstream GitLab raw-manual endpoint returned a bot challenge during this documentation check; the option claim above is supported by the packaged manual actually read, not by that response.

The following pinned vendor scripts copy the MPI3508 calibration preset and include evdev installation logic. Their referenced presets contain Calibration set to 3945 233 3939 183 and SwapAxes set to 1:

Those presets exist and may work with an appropriate evdev setup. Their source does not establish that they are universally wrong, that this libinput profile fits every MPI3508, or that either vendor tested this project’s target environment.

Guide · Privacy Policy · Terms of Service · © 2026 Security Ronin Ltd