Linux fingerprint sensor daemon for QTEE devices
  • C++ 88.7%
  • Shell 11.3%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Jorijn van der Graaf 2da03d1595
Some checks failed
package / package (push) Has been cancelled
readme
2026-09-05 19:58:09 +02:00
.forgejo/workflows Package the daemon, so a fingerprint survives a reflash 2026-09-05 02:52:01 +02:00
implementations An agent, so a finger can mean something in your session 2026-09-05 06:21:53 +02:00
interfaces Drop two fields nobody needed: session was a no-op, and no-unlock is the finger 2026-09-05 05:23:40 +02:00
packaging An agent, so a finger can mean something in your session 2026-09-05 06:21:53 +02:00
tests Drop two fields nobody needed: session was a no-op, and no-unlock is the finger 2026-09-05 05:23:40 +02:00
.gitignore Initial commit: the gpfile wire format, pinned by two real containers 2026-09-02 16:02:46 +02:00
LICENSE Initial commit: the gpfile wire format, pinned by two real containers 2026-09-02 16:02:46 +02:00
lint-rules.h Initial commit: the gpfile wire format, pinned by two real containers 2026-09-02 16:02:46 +02:00
project.cpp An agent, so a finger can mean something in your session 2026-09-05 06:21:53 +02:00
README.md readme 2026-09-05 19:58:09 +02:00

fingerprintd

Fingerprint daemon for the Fairphone 6 (milos, SM7635) on mainline Linux.

fingerprintd-core is a static library with no GLib, no libqcomtee and no system headers. Everything in it is a wire format or a state machine that was recovered by reverse-engineering, so all of it is pinned by tests that run on a dev box with no phone, no TEE and no sensor. The daemon shell holds everything that touches hardware.

Build

crafter-build              # bin/fingerprintd-<target>-<march>/fingerprintd
crafter-build test         # the unit suites

Cross-compiling for the phone:

packaging/make-sysroot.sh                        # once; no root, no qemu, no device
crafter-build -- --target=aarch64-alpine-linux-musl \
  --sysroot=~/.cache/fingerprintd/sysroot-aarch64-alpine \
  --march=armv8-a --mtune=generic
crafter-build test --target=aarch64-alpine-linux-musl --sysroot=... \
  --march=armv8-a --mtune=generic                # runs the suites under qemu-aarch64

The result links dynamically against the phone's own musl and libc++ (libc++, libc++abi, libunwind, libgcc_s, all already present on pmOS). The research harness this replaces had to be built -static, but only because it was built with the host's glibc toolchain — that constraint does not apply to a real Alpine sysroot.

Verified on the device: all five suites pass cross-built and run on the phone itself, not only under emulation.

fprintd-enroll -f right-index-finger user   ten stages, enroll-completed
fprintd-list user                            - #0: right-index-finger
fprintd-verify user   (wrong finger)         verify-no-match, on the first press
fprintd-verify user   (enrolled finger)      verify-match,    on the first press

Runtime dependencies, not carried here

The focal64 trustlet is proprietary and is not in this repo. It is extracted from the device's own stock Android partition on first boot by the fp6-vendor-blobs mechanism, the same way the audio firmware is.

License

GPL-3.0-only, see LICENSE.

Copyright (C) 2026 Catcrafts® catcrafts.net