Result update: password still rejected after reflash.
The 36-hour throttle timer expired. I made one careful attempt with my original password — typed slowly, verified each character as it displayed, confirmed the dot count matched the password length, and checked the shift state. It was rejected.
Summary of the diagnosis so far:
Reflashing the same build (2026070501) via recovery sideload completed successfully (status 0), but the outcome did not change.
Touchscreen tested OK via the emergency dialer (no ghost touches or offset).
Input display layer verified character-by-character.
Hardware and input layers appear fine, yet a password used daily for months is rejected at BFU.
This seems consistent with the earlier hypothesis in this thread: something between input submission and credential verification. For reference, my password contains special characters, in case that is relevant to the submission path.
Questions for the devs or anyone who knows:
Is there any related fix already merged or planned for the next release? If so, I will keep the device untouched and sideload the next build before considering a factory reset.
Is there anything else worth trying that does not wipe data?
I understand the encryption design means the data cannot be recovered without the correct credential — I just want to confirm whether there is any solution before giving up the data.