2026-08-08 15:42:45 +02:00
|
|
|
# fp6-img
|
|
|
|
|
|
|
|
|
|
Flashable [postmarketOS](https://postmarketos.org/) images for the
|
2026-08-18 18:45:58 +02:00
|
|
|
**Fairphone 6/6+**, built nightly from the
|
2026-08-08 15:42:45 +02:00
|
|
|
[Catcrafts milos-linux](https://forgejo.catcrafts.net/Catcrafts/milos-linux)
|
|
|
|
|
`combined-stable` kernel branch, with
|
|
|
|
|
[imsd](https://forgejo.catcrafts.net/Catcrafts/imsd) (userspace VoLTE)
|
|
|
|
|
preinstalled.
|
|
|
|
|
|
|
|
|
|
Maintained by [Jorijn van der Graaf](https://catcrafts.net/about)
|
|
|
|
|
(TheMightyCat) at [Catcrafts](https://catcrafts.net/).
|
|
|
|
|
|
|
|
|
|
## What works
|
|
|
|
|
|
|
|
|
|
Everything on the `combined-stable` branch: display, touch, wifi, cellular
|
|
|
|
|
data, NFC (reader), speaker audio, microphone, IMU, magnetometer, barometer,
|
Install fingerprintd from the registry, so the image unlocks with a finger
The daemon's own package CI publishes it to the registry the same way imsd's
does, so the image takes it from there: the exact apk a user later gets via
apk upgrade, sha256-pinned, re-signed for the chroot. Section 3b now fetches
both sets, and every fetched file must have a pin -- the check used to be
`grep . | sha256sum -c`, which an empty pin list would have sailed through
with nothing checked.
Three apks: the daemon, its systemd units, and the session agent, which does
nothing until a user writes ~/.config/fingerprintd/fingers.conf. The daemon
needs the kernel aport's CONFIG_QCOMTEE=m (pkgrel 101) and fp6-vendor-blobs
1-r2's mbn directive to reassemble the trustlet, both built in this run;
0.2.3 says >=1-r2 so a mismatched pair is refused rather than installed.
The CI publish step skips fingerprintd-* like imsd-*: registry-sourced, not
ours to republish. README: fingerprint in the list, and the two things a user
will otherwise report as a dead sensor -- the lock screen listens for 60
seconds after it appears, and a held press is what the matcher was measured
on -- plus the untested question of stock Android's own fingerprints after
using this.
Verified on the dev phone (fp6 repo journal/fingerprint/, 2026-09-05): the
registry 0.2.2 package enrols through Plasma's Users page and unlocks the
lock screen; 0.2.3 differs by the dependency and a post-upgrade restart. The
image build itself, with the fprintd purge inside the chroot, runs first in
CI.
2026-09-05 20:31:37 +02:00
|
|
|
ambient light/proximity, fingerprint unlock through
|
|
|
|
|
[fingerprintd](https://forgejo.catcrafts.net/Catcrafts/fingerprintd), plus
|
|
|
|
|
VoLTE calls (both directions) through imsd.
|
2026-08-08 15:42:45 +02:00
|
|
|
|
|
|
|
|
## Flashing
|
|
|
|
|
|
2026-08-10 10:40:50 +02:00
|
|
|
Download `fp6-img.tar.xz` from the latest release and unlock the bootloader
|
|
|
|
|
([Fairphone's official process](https://support.fairphone.com/hc/en-us/articles/10492476238737)).
|
2026-08-09 01:25:20 +02:00
|
|
|
|
2026-08-09 03:33:33 +02:00
|
|
|
**Install**: with the phone in fastboot mode,
|
2026-08-10 10:40:50 +02:00
|
|
|
|
|
|
|
|
```sh
|
|
|
|
|
tar xf fp6-img.tar.xz
|
|
|
|
|
cd fp6-img
|
|
|
|
|
./install.sh
|
|
|
|
|
```
|
|
|
|
|
|
2026-08-13 23:04:02 +02:00
|
|
|
`install.sh` erases dtbo, flashes the rootfs, **RAM-boots** the kernel, writes the boot partition from
|
2026-08-10 16:22:20 +02:00
|
|
|
inside Linux where the bootloader's NV-wipe cannot see it, then reads the modem
|
|
|
|
|
NV back and reports the result. The bootloader never writes `boot`.
|
2026-08-09 01:29:17 +02:00
|
|
|
|
2026-08-08 15:42:45 +02:00
|
|
|
Default login: `user` / `147147` (same as official postmarketOS images —
|
|
|
|
|
change it). **Never re-lock the bootloader** with a custom image installed.
|
|
|
|
|
|
|
|
|
|
## VoLTE configuration
|
|
|
|
|
|
|
|
|
|
imsd is installed but needs your carrier's P-CSCF address:
|
|
|
|
|
|
|
|
|
|
```sh
|
|
|
|
|
# /etc/imsd.env
|
|
|
|
|
PCSCF=<your carrier's P-CSCF IPv6 address>
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Find it in a stock-firmware capture or your carrier's IMS documentation, then
|
2026-08-08 23:46:01 +02:00
|
|
|
`systemctl restart imsd` (the service is enabled at boot and waits for this
|
|
|
|
|
file to exist). See the
|
2026-08-08 15:42:45 +02:00
|
|
|
[imsd README](https://forgejo.catcrafts.net/Catcrafts/imsd) for the full
|
Install fingerprintd from the registry, so the image unlocks with a finger
The daemon's own package CI publishes it to the registry the same way imsd's
does, so the image takes it from there: the exact apk a user later gets via
apk upgrade, sha256-pinned, re-signed for the chroot. Section 3b now fetches
both sets, and every fetched file must have a pin -- the check used to be
`grep . | sha256sum -c`, which an empty pin list would have sailed through
with nothing checked.
Three apks: the daemon, its systemd units, and the session agent, which does
nothing until a user writes ~/.config/fingerprintd/fingers.conf. The daemon
needs the kernel aport's CONFIG_QCOMTEE=m (pkgrel 101) and fp6-vendor-blobs
1-r2's mbn directive to reassemble the trustlet, both built in this run;
0.2.3 says >=1-r2 so a mismatched pair is refused rather than installed.
The CI publish step skips fingerprintd-* like imsd-*: registry-sourced, not
ours to republish. README: fingerprint in the list, and the two things a user
will otherwise report as a dead sensor -- the lock screen listens for 60
seconds after it appears, and a held press is what the matcher was measured
on -- plus the untested question of stock Android's own fingerprints after
using this.
Verified on the dev phone (fp6 repo journal/fingerprint/, 2026-09-05): the
registry 0.2.2 package enrols through Plasma's Users page and unlocks the
lock screen; 0.2.3 differs by the dependency and a post-upgrade restart. The
image build itself, with the fprintd purge inside the chroot, runs first in
CI.
2026-09-05 20:31:37 +02:00
|
|
|
variable reference and carrier assumptions.
|
|
|
|
|
|
|
|
|
|
## Fingerprint
|
|
|
|
|
|
|
|
|
|
Enrol under **Settings → Users** (Plasma's own fingerprint page; the `fprintd`
|
|
|
|
|
command-line tools are not installed, fingerprintd replaces that package).
|
|
|
|
|
**Hold** the finger on the sensor for each of the ~20 presses rather than
|
|
|
|
|
tapping it; a held press is what the matcher was measured on.
|
|
|
|
|
|
|
|
|
|
Two things to know:
|
|
|
|
|
|
|
|
|
|
- The lock screen listens for a finger for **60 seconds after it appears**.
|
|
|
|
|
A press after that reaches nothing and looks like a dead sensor. Lock and
|
|
|
|
|
unlock again to re-arm it.
|
|
|
|
|
- The matcher is the phone's own proprietary trustlet, reassembled from the
|
|
|
|
|
stock modem partition on first boot and never shipped by us. Templates are
|
|
|
|
|
stored on the Android `persist` partition, sealed to the same hardware
|
|
|
|
|
anti-rollback counter stock Android uses. Whether fingerprints enrolled under
|
|
|
|
|
stock Android survive a return to it after using this has **not** been
|
|
|
|
|
tested.
|
|
|
|
|
|
|
|
|
|
A finger can also run something in your session on a match
|
|
|
|
|
(`~/.config/fingerprintd/fingers.conf`, see the fingerprintd README).
|