Print the trustlet's rc on every enrol press, and let deploy-dev.sh pass extra flags

A refused enrolment sample is one of two things: an image the algorithm saw and
turned down (rc=0, samples remaining unchanged) or an error the trustlet never
got past (a negative rc). The touch line printed the count and the fid but not
the rc, so a run of twenty-two refusals in a row said nothing about which it was.
It does now.

EXTRA=... on deploy-dev.sh appends daemon flags, so a diagnostic session can
come up with --ta-log without editing the script or the unit by hand.
This commit is contained in:
Jorijn van der Graaf 2026-09-04 22:58:22 +02:00
commit a3d3dcb4af
2 changed files with 12 additions and 3 deletions

View file

@ -1296,7 +1296,13 @@ public:
// exactly like "finished".
enrol.Observe(r.samplesRemaining, true);
if (r.fid != 0 && r.fid != ta::FidPoison) out.fid = r.fid;
std::println(" touch: rem={} fid={:#x}", r.samplesRemaining, r.fid);
// The rc is the trustlet's own word on the press. A refused
// sample with rc=0 was seen and turned down by the
// algorithm; a negative rc is an error it never got past.
// Without this a run of 22 refusals says nothing about
// which of the two it was.
std::println(" touch: rem={} fid={:#x} rc={}{}", r.samplesRemaining,
r.fid, r.rc, r.rc ? std::format(" ({})", ta::StrError(r.rc)) : "");
}
if (ev == ta::Event::FingerReleased && pressHadTouch) {
// The press is over. Did it move the count?