fingerprintd/packaging
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Jorijn van der Graaf 1934822554 An agent, so a finger can mean something in your session
The daemon announces every matched finger on the system bus and stops there,
because root has no session bus, no display and no business starting your
applications. fingerprintd-agent is the other half: it runs as you, subscribes
properly rather than parsing gdbus monitor output, filters by uid because the
signal is visible to every local user, and maps fingers to commands from a file
you own and can edit without restarting anything.

It is a separate binary and a separate subpackage because it is a separate
trust domain. /etc/fingerprintd/actions.conf is a root shell and is guarded
like one; ~/.config/fingerprintd/fingers.conf runs your commands as you, so it
is an ordinary dotfile.

Demonstrated on the phone: one press of the unlock finger both unlocks it and
opens plasma-camera.
2026-09-05 06:21:53 +02:00
..
20-focal64.manifest A verify nobody answered is not a failure, and the trustlet is not ours to ship 2026-09-05 04:01:06 +02:00
80-fingerprintd.preset Package the daemon, so a fingerprint survives a reflash 2026-09-05 02:52:01 +02:00
actions.conf.example Drop two fields nobody needed: session was a no-op, and no-unlock is the finger 2026-09-05 05:23:40 +02:00
APKBUILD An agent, so a finger can mean something in your session 2026-09-05 06:21:53 +02:00
build-package.sh An agent, so a finger can mean something in your session 2026-09-05 06:21:53 +02:00
deploy-dev.sh Package the daemon, so a fingerprint survives a reflash 2026-09-05 02:52:01 +02:00
fingerprint-auth.pam An agent, so a finger can mean something in your session 2026-09-05 06:21:53 +02:00
fingerprintd-agent.service An agent, so a finger can mean something in your session 2026-09-05 06:21:53 +02:00
fingerprintd.json Package the daemon, so a fingerprint survives a reflash 2026-09-05 02:52:01 +02:00
fingerprintd.modules-load.conf Package the daemon, so a fingerprint survives a reflash 2026-09-05 02:52:01 +02:00
fingerprintd.service A verify nobody answered is not a failure, and the trustlet is not ours to ship 2026-09-05 04:01:06 +02:00
fingerprintd.tmpfiles.conf Package the daemon, so a fingerprint survives a reflash 2026-09-05 02:52:01 +02:00
fingers.conf.example An agent, so a finger can mean something in your session 2026-09-05 06:21:53 +02:00
fpenrol.sh fpenrol.sh: no enrolment ever received the position guidance this script claims 2026-09-03 17:44:35 +02:00
fplearn.sh fplearn.sh: a wipe leaves learning off too 2026-09-05 02:07:26 +02:00
fptrial.sh Hold, do not tap -- and stop spending the verdict on a frame that cannot carry it 2026-09-05 00:17:13 +02:00
make-bin-tarball.sh An agent, so a finger can mean something in your session 2026-09-05 06:21:53 +02:00
make-libqcomtee.sh Reach QTEE: credentials, client env and the app loader, with no QCBOR 2026-09-02 18:02:28 +02:00
make-sysroot.sh Add the cross-build sysroot recipe, verified on the device 2026-09-02 17:34:27 +02:00
mnt-persist.mount Package the daemon, so a fingerprint survives a reflash 2026-09-05 02:52:01 +02:00
net.reactivated.Fprint.conf Give a finger a meaning beyond "it was you" 2026-09-05 05:12:41 +02:00
net.reactivated.fprint.device.policy Package the daemon, so a fingerprint survives a reflash 2026-09-05 02:52:01 +02:00
net.reactivated.Fprint.service Package the daemon, so a fingerprint survives a reflash 2026-09-05 02:52:01 +02:00
postlogin.pam Ship postlogin too, the other half of the seam kscreenlocker expects 2026-09-05 05:56:47 +02:00
README.config.md Package the daemon, so a fingerprint survives a reflash 2026-09-05 02:52:01 +02:00

fingerprintd.json — where it comes from, and why this exact file

The trustlet gates its config file on common.configuration_uuid and silently falls back to built-in defaults on a mismatch, so the file is not decorative: SYNC_CONFIG returning 0 is what makes the whole init chain run.

This copy is generated, not hand-written. Its source is fp6fpcfg.py in the fp6 bring-up repo, which builds it from the captured stock configuration dump (journal/fingerprint/captures/2026-08-25-focal64-effective-config-from-stock.txt):

utilities/fp6fpcfg.py --daemon --verbose > packaging/fingerprintd.json

sha256 begins b205c756914a66f1.

Why the --verbose variant

--verbose here is the trustlet's own log level, not the daemon's. It is shipped because it is the file every accuracy number was measured on — 30/30 held presses, zero false accepts, 36-330 ms to a verdict — and the TA's log level cannot be raised again by a runtime SYNC_CONFIG, so a session that needs the matcher's own lines has to have started with it.

--daemon alone produces the same file with trustlet logging off (sha256 6c4503e628406424, four diagnosis.* keys differ and nothing else). It is plausibly the better shipping default and it is untested: no rate in the journal was measured on it. Switching is a measurement, not an edit.

The two policy keys

  • common.max_authentication_rescan_times: 0 — at the stock budget a wrong finger never yields a terminal frame, so a PAM client waits forever for the verify-no-match it needs.
  • trustlet.enable_trusted_enrollment: false — skips the challenge compare and the hw_auth_token HMAC verify. pmOS has no Gatekeeper to issue a token and nothing on pmOS verifies one.