The port was written from recall and flagged its own uncertain constants
`UNCONFIRMED`. Those flags were checkable — librtlsdr is public source — so
they were checked rather than shipped as caveats. Three findings:
1. SDM register pair was WRONG. Real r82xx_set_pll writes the high byte to
0x16 and the low byte to 0x15; the port used 0x16/0x17. This was not a
mere mistune: 0x17 also carries div_buf_cur and the openD bit, so the SDM
low byte was corrupting tuner front-end configuration on every retune.
2. SDM computation used the successive-approximation loop from the `_yc`
variant, which truncates where the real r82xx_set_pll rounds:
vco_div = (pll_ref + 65536*vco_freq) / (2*pll_ref)
nint = vco_div / 65536 ; sdm = vco_div % 65536
One LSB low on 4 of 5 reference frequencies — tens of Hz, never visible
on FM, but no reason to carry a known divergence.
3. freq_ranges[] was missing its last two rows (450 and 650 MHz), so any
tune between 450 and 588 MHz inherited the 310 MHz row's front-end
settings.
The tfC column that carried the loudest UNCONFIRMED warning turned out to be
correct in all 19 existing rows — the table now matches the C field-for-field
across all 21. Test vectors regenerated from the authoritative formula and
independently re-derived: 88.5 MHz -> nint 51, sdm 9830, reg 0x14 = 0x89.
Still true and still stated in the file: none of this has touched hardware.
The arithmetic is now verified against the reference implementation; the
register pokes remain reasoned rather than observed.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>