XCnathan32 see . / drivers / clk / qcom / clock-cpu-8994.c
The pll lock bit is defined as BIT(31), which is the MSB of register pll->status_reg.
On the log you posted, pll->status_reg is 0xca000100 with MSB set, this suggests the pll has locked b...
Spent the last day or so looking at this. The surnia bootloader attempts to call the SMC function 0x3000A0A. That's as far as I got without the symbols for the trustzone kernel.
Smilex93 Wifi, 3G/LTE, Sound all working. santod040 AAC still not working after disabling NuPlayer
The blog post seems to say that the issue was reported and fixed back in 2014. It's unlikely that XT1528 has this bug since it's a later device, and the Android versions for XT1528 are some flavor of Lollipop, not KitKat.
AFAIK Widevine exploit...
I don't know if it will help, but there in comment section of "Full TrustZone exploit for MSM8974" post , one user mentioned about tz_service of msm8916
also on MSM 8916 there is a function called
tz_service ; "tzbsp_oem_svc"