# FocalTech FT9391 trustlet (proprietary, OEM-signed) - reassembled from the # stock modem partition on-device instead of being shipped (fp6 repo # journal/blobs/, journal/fingerprint/). It is the matcher: every pixel the # sensor produces stays inside it, and no part of the daemon can substitute # for it. QTEE's signature gate is fused OEM root, measured 2026-09-03, so # there is no version of this that is our own code. # # Not one file: image/focal64.mdt plus focal64.b00..b08, placed at each ELF # segment's p_offset. The extractor tries the ACTIVE slot first (its TZ is # the one running) and the other slot as fallback. # # No sha256 pin ('-'): Fairphone re-signs this trustlet every Android # release, so a whole-image hash matches exactly one build - six builds, six # hashes, one trustlet - and the pin 0.2.3 shipped (16.82.0's) left every # unit on another build without a sensor (two of two field reports, # 2026-09-11). The extractor verifies the structure; QTEE verifies the # signature and refuses a damaged or foreign image (one flipped byte -> # ERROR_ELF_SIGNATURE_ERROR, measured 2026-09-03), and the daemon names that # verdict in its log. mbn modem_a,modem_b image focal64 /usr/lib/firmware/focal64.mbn -