# fingerprintd Fingerprint daemon for the Fairphone 6 (`milos`, SM7635) on mainline Linux. `fingerprintd-core` is a static library with no GLib, no libqcomtee and no system headers. Everything in it is a wire format or a state machine that was recovered by reverse-engineering, so all of it is pinned by tests that run on a dev box with no phone, no TEE and no sensor. The daemon shell holds everything that touches hardware. ## Build ```sh crafter-build # bin/fingerprintd--/fingerprintd crafter-build test # the unit suites ``` Cross-compiling for the phone: ```sh packaging/make-sysroot.sh # once; no root, no qemu, no device crafter-build -- --target=aarch64-alpine-linux-musl \ --sysroot=~/.cache/fingerprintd/sysroot-aarch64-alpine \ --march=armv8-a --mtune=generic crafter-build test --target=aarch64-alpine-linux-musl --sysroot=... \ --march=armv8-a --mtune=generic # runs the suites under qemu-aarch64 ``` The result links dynamically against the phone's own musl and libc++ (`libc++`, `libc++abi`, `libunwind`, `libgcc_s`, all already present on pmOS). The research harness this replaces had to be built `-static`, but only because it was built with the host's glibc toolchain — that constraint does not apply to a real Alpine sysroot. Verified on the device: all five suites pass cross-built and run on the phone itself, not only under emulation. ``` fprintd-enroll -f right-index-finger user ten stages, enroll-completed fprintd-list user - #0: right-index-finger fprintd-verify user (wrong finger) verify-no-match, on the first press fprintd-verify user (enrolled finger) verify-match, on the first press ``` ## Runtime dependencies, not carried here The `focal64` trustlet is proprietary and is not in this repo. It is extracted from the device's own stock Android partition on first boot by the `fp6-vendor-blobs` mechanism, the same way the audio firmware is. ## License GPL-3.0-only, see LICENSE. ## Copyright Copyright (C) 2026 Catcrafts® catcrafts.net