The daemon now powers the sensor and initialises the trustlet against it. On
the phone, every step of the chain returning rc=0:
gpiochip 'f100000.pinctrl' is /dev/gpiochip5 (168 lines)
sensor powered, reset released, irq=1
CMD 0x1006 INIT_SPI rc=0
CMD 0x100a PROBE_DEVICE rc=0
CMD 0x100b INIT_DEVICE rc=0
CMD 0x1004 TA_INIT rc=0
CMD 0x1020 WORK_MODE rc=0
CMD 0x100e SYNC_STATISTICS rc=0
GPIO v2 chardev ioctls directly rather than libgpiod, which is on neither the
phone nor the sysroot and would be a dependency for three lines.
The chip is found by label, and the label is not what the device tree calls it:
the node is pinctrl@f100000 so the chardev advertises "f100000.pinctrl", while
every DT reference says "tlmm". Matching on "tlmm" finds nothing, which is how
the first run failed. There is a second check on the line count, because this
SoC has another pinctrl with 23 lines and driving line 75 of the wrong
controller is not something you recover from over ssh.
The XPU guard is enforced where the line is actually opened, not only asserted
in the core. gpio8-11 are the fingerprint SPI pads and touching one is an
immediate SError with the phone rebooting where it stands, so a refusal has to
sit in front of the ioctl.
Owning the rail is what makes the session recoverable at all: one reset buys
exactly one trustlet init and a second answers -205, so a failed session needs
the rail cycled rather than the chain retried. The harness split these across
two processes and every run began by restarting the one holding the rail.
CAPTURE_IMAGE answers -201 here and that is correct, not a regression: it needs
a shared memory region whose address QTEE patches into the payload, and none is
supplied yet. That is the next piece.
21 lines
730 B
C++
21 lines
730 B
C++
// SPDX-License-Identifier: GPL-3.0-only
|
|
// SPDX-FileCopyrightText: Copyright (C) 2026 Catcrafts®
|
|
|
|
/*
|
|
fingerprintd — fingerprint daemon for the Fairphone 6 on mainline Linux.
|
|
|
|
The sensor is a FocalTech FT9391 on a TrustZone-owned SPI bus: the normal world
|
|
cannot reach it, and raw frames never leave the TEE. All capture, enrolment and
|
|
matching happen inside the focal64 trustlet. This daemon owns the sensor rail,
|
|
holds the QTEE session open, serves the storage callbacks QTEE makes back into
|
|
the normal world, and reports the matched finger id.
|
|
*/
|
|
|
|
export module Fingerprintd;
|
|
export import :Sfs;
|
|
export import :Rpmb;
|
|
export import :Ta;
|
|
export import :Engine;
|
|
export import :Store;
|
|
export import :Tee;
|
|
export import :Sensor;
|