All checks were successful
package / package (push) Successful in 1m39s
fp6-vendor-blobs learned the mbn directive in 1-r2. The extractor before it exits on an unknown directive, so a fresh flash with 1-r1 and our 20-focal64.manifest processes the audio fragment and then fails the blobs unit on ours: a red unit, no trustlet, and nothing in the daemon's own logs to say why. Saying >=1-r2 makes apk refuse a combination that cannot work instead of installing one that fails at first boot. Existing installs never saw this -- the old fast path only checks file lines and exits before the dispatcher. apk also swaps the binary on disk and leaves the running daemon alone, which is how 0.2.2's FingerMatched signal first presented: a clean MATCH in the journal and nothing downstream, because the boot's 0.1.3 was still answering. A post-upgrade try-restart closes that. A daemon that is not running stays not running, and a build chroot without systemd is left alone. 0.2.3, so the package CI publishes it.
149 lines
7.3 KiB
Text
149 lines
7.3 KiB
Text
# SPDX-License-Identifier: GPL-3.0-only
|
|
# SPDX-FileCopyrightText: Copyright (C) 2026 Catcrafts®
|
|
# Maintainer: Jorijn van der Graaf <jorijnvdgraaf@catcrafts.net>
|
|
# Binary packaging: wraps a crafter-build binary cross-compiled per the
|
|
# README's "Cross-compiling" section into a proper apk — used by this repo's
|
|
# package CI (packaging/build-package.sh, which seds pkgver from
|
|
# implementations/main.cpp) and runnable by hand. The source tarball is
|
|
# produced by packaging/make-bin-tarball.sh. There is deliberately no
|
|
# source-building aport: the build driver is crafter-build, which is not in
|
|
# Alpine, so an APKBUILD that compiled from source could not be built by
|
|
# anyone but us either.
|
|
pkgname=fingerprintd
|
|
pkgver=0.2.3
|
|
pkgrel=0
|
|
pkgdesc="Fingerprint daemon for the Fairphone 6 (FocalTech FT9391 behind QTEE)"
|
|
url="https://forgejo.catcrafts.net/Catcrafts/fingerprintd"
|
|
arch="aarch64"
|
|
license="GPL-3.0-only"
|
|
# GLib for the D-Bus interface; libc++ because the binary is a clang/libc++
|
|
# C++26 modules build linked dynamically against the phone's own runtime.
|
|
#
|
|
# fprintd-pam is pam_fprintd, which is the point of the whole daemon: it is
|
|
# what turns a matched finger into a login. It is an install_if subpackage
|
|
# conditioned on the EXACT version fprintd-pam was built against
|
|
# (i:fprintd=1.94.5-r1), so the provides below breaks that condition and apk
|
|
# would purge it as no-longer-needed. Depending on it explicitly is what keeps
|
|
# it. It has no dependency on fprintd itself, so nothing is being forced.
|
|
#
|
|
# fp6-vendor-blobs runs the manifest fragment below, which reassembles the
|
|
# trustlet out of the stock modem partition on first boot. Without it there is
|
|
# no matcher and the unit stays inert on its ConditionPathExists -- so this is
|
|
# a real dependency, not a nicety. It is an FP6 device package; so is this.
|
|
# The mbn directive the fragment uses arrived in 1-r2; the extractor before it
|
|
# exits on an unknown directive, which on a first boot would fail the blobs
|
|
# unit after the audio fragment had run and before this one could.
|
|
depends="dbus glib libc++ fprintd-pam fp6-vendor-blobs>=1-r2"
|
|
# The versioned provides both satisfies plasma-workspace's fprintd dependency
|
|
# — its Users KCM is the fingerprint enrolment UI and speaks exactly this bus
|
|
# name — and EXCLUDES the real package, which is required rather than tidy:
|
|
# fprintd is D-Bus-activatable, so a client call would otherwise start the
|
|
# real daemon and fight for net.reactivated.Fprint. fprintd-pam is a separate
|
|
# package that does not depend on fprintd, so PAM keeps working.
|
|
#
|
|
# The cost, which is real: the fprintd-enroll/-list/-verify/-delete CLIs go
|
|
# away with the package. Enrolment then goes through Plasma's Users KCM.
|
|
provides="fprintd=$pkgver-r$pkgrel"
|
|
# The unit is the deliverable — a daemon holding QTEE's listener table open for
|
|
# the life of the boot is not something to start by hand — but abuild wants
|
|
# systemd files in their own package, and install_if puts them back on any
|
|
# system that has systemd. No OpenRC service: nothing here has ever been run
|
|
# under one, and the unit's conditions (the vendor blob, /dev/tee0) are what
|
|
# keep the package inert on a phone that cannot use it.
|
|
subpackages="$pkgname-agent $pkgname-systemd"
|
|
# nothing is compiled here, and the aarch64 ELF's NEEDED entries must not be
|
|
# traced against an x86_64 build host
|
|
options="!check !tracedeps"
|
|
source="fingerprintd-$pkgver.tar.gz"
|
|
# apk swaps the binary on disk and leaves the running daemon alone; the
|
|
# script restarts it so an upgrade does not leave the old code answering.
|
|
install="$pkgname.post-upgrade"
|
|
|
|
package() {
|
|
cd "$srcdir/fingerprintd-$pkgver"
|
|
install -Dm755 fingerprintd "$pkgdir"/usr/bin/fingerprintd
|
|
|
|
install -Dm644 fingerprintd.service \
|
|
"$pkgdir"/usr/lib/systemd/system/fingerprintd.service
|
|
install -Dm644 mnt-persist.mount \
|
|
"$pkgdir"/usr/lib/systemd/system/mnt-persist.mount
|
|
# enabled by preset, and by an explicit .wants link so a fingerprint
|
|
# surviving a reboot never depends on a manual systemctl enable. The
|
|
# mount needs neither: fingerprintd.service pulls it in with
|
|
# RequiresMountsFor.
|
|
install -Dm644 80-fingerprintd.preset \
|
|
"$pkgdir"/usr/lib/systemd/system-preset/80-fingerprintd.preset
|
|
mkdir -p "$pkgdir"/etc/systemd/system/multi-user.target.wants
|
|
ln -s /usr/lib/systemd/system/fingerprintd.service \
|
|
"$pkgdir"/etc/systemd/system/multi-user.target.wants/fingerprintd.service
|
|
|
|
# who may own and call the bus name
|
|
install -Dm644 net.reactivated.Fprint.conf \
|
|
"$pkgdir"/usr/share/dbus-1/system.d/net.reactivated.Fprint.conf
|
|
# replaces fprintd's activation file, which points at /usr/libexec/fprintd
|
|
install -Dm644 net.reactivated.Fprint.service \
|
|
"$pkgdir"/usr/share/dbus-1/system-services/net.reactivated.Fprint.service
|
|
# the action ids fprintd defined; see the file for what enforces them
|
|
install -Dm644 net.reactivated.fprint.device.policy \
|
|
"$pkgdir"/usr/share/polkit-1/actions/net.reactivated.fprint.device.policy
|
|
|
|
# the SFS root's directories and its two symlinks into the persist mount
|
|
install -Dm644 fingerprintd.tmpfiles.conf \
|
|
"$pkgdir"/usr/lib/tmpfiles.d/fingerprintd.conf
|
|
# qcomtee -> /dev/tee0
|
|
install -Dm644 fingerprintd.modules-load.conf \
|
|
"$pkgdir"/usr/lib/modules-load.d/fingerprintd.conf
|
|
|
|
# the trustlet's configuration, generated by fp6fpcfg.py from the captured
|
|
# stock dump — see packaging/README.config.md. Not a user config file:
|
|
# the TA discards a file whose configuration_uuid does not match, and the
|
|
# two policy keys in it were each forced by a measurement.
|
|
install -Dm644 fingerprintd.json \
|
|
"$pkgdir"/usr/lib/firmware/fingerprintd.json
|
|
|
|
# the trustlet is NOT in this package and never will be: it is a
|
|
# proprietary OEM-signed blob. This tells fp6-vendor-blobs how to
|
|
# reassemble it from the phone's own stock partitions, which is the
|
|
# same mechanism soc-fairphone-fp6-audio uses for the amp config.
|
|
install -Dm644 20-focal64.manifest \
|
|
"$pkgdir"/usr/share/fp6-vendor-blobs/manifest.d/20-focal64.manifest
|
|
|
|
# The PAM service kscreenlocker substacks and Alpine does not provide.
|
|
# Vendor directory, so /etc/pam.d still overrides it.
|
|
install -Dm644 fingerprint-auth.pam \
|
|
"$pkgdir"/usr/lib/pam.d/fingerprint-auth
|
|
install -Dm644 postlogin.pam \
|
|
"$pkgdir"/usr/lib/pam.d/postlogin
|
|
|
|
# Documentation, not configuration: shipping an /etc/fingerprintd/
|
|
# actions.conf would be shipping a root shell nobody asked for. The
|
|
# feature is off until an administrator installs one.
|
|
install -Dm644 actions.conf.example \
|
|
"$pkgdir"/usr/share/doc/$pkgname/actions.conf.example
|
|
|
|
# The session half; split out below.
|
|
install -Dm755 fingerprintd-agent "$pkgdir"/usr/bin/fingerprintd-agent
|
|
install -Dm644 fingerprintd-agent.service \
|
|
"$pkgdir"/usr/lib/systemd/user/fingerprintd-agent.service
|
|
install -Dm644 fingers.conf.example \
|
|
"$pkgdir"/usr/share/doc/$pkgname/fingers.conf.example
|
|
}
|
|
|
|
agent() {
|
|
pkgdesc="Run things in your session when a fingerprint matches"
|
|
# Useful only against a daemon that emits the signal, but it is a
|
|
# SEPARATE package because it is a separate trust domain: it runs as the
|
|
# user, reads a config the user owns, and starts the user's software.
|
|
depends="$pkgname=$pkgver-r$pkgrel"
|
|
|
|
amove usr/bin/fingerprintd-agent
|
|
amove usr/lib/systemd/user/fingerprintd-agent.service
|
|
amove usr/share/doc/$pkgname/fingers.conf.example
|
|
}
|
|
|
|
systemd() {
|
|
install_if="$pkgname=$pkgver-r$pkgrel systemd"
|
|
|
|
amove usr/lib/systemd
|
|
amove etc/systemd
|
|
}
|