aports: extract aw88261_acf.bin on-device instead of shipping it
All checks were successful
image / image (push) Successful in 2h24m43s

New package fp6-vendor-blobs: a manifest-driven systemd oneshot that
copies proprietary blobs out of the stock Android partitions on first
boot. pmOS installs flash only boot+userdata, so every installed unit
still carries the stock vendor/dsp partitions - the device duplicates a
file it already contains, for its own operation, and nothing proprietary
is distributed by us. Partitions are mounted read-only (ext4 additionally
with noload - not even a journal replay touches the stock data), every
copy is sha256-pinned and a miss fails loudly, and the consuming devices
are unbound and re-probed afterwards so the feature works the same boot.

The rebind is unconditional by design: aw88261 binds on a bare i2c
chip-id probe and requests the ACF only at ASoC card init (~21 s, after
SoundWire enumeration), so a bound device can still be one that lost the
firmware race - and that failed request is never retried.

soc-fairphone-fp6-audio (pkgver 4) stops shipping the blob, installs the
manifest fragment instead, and re-runs the extractor from
post-install/post-upgrade so upgrades restore the file immediately (the
old package version removed it on upgrade). License drops back to plain
BSD-3-Clause - nothing proprietary left in the package.

Verified on the dev phone (fp6 repo journal/blobs/captures/
2026-08-24-first-boot-extractor-verification.txt): first-boot extraction
+ same-boot audio, mid-session post-upgrade recovery, and the everyday
fast-path no-op; committed files byte-identical to the tested deployment.

Assisted-by: Claude:claude-fable-5
This commit is contained in:
Jorijn van der Graaf 2026-08-24 21:00:34 +02:00
commit 1e673ca1c4
9 changed files with 290 additions and 15 deletions

View file

@ -0,0 +1,47 @@
# First-boot, on-device extraction of proprietary blobs from the stock
# Android partitions, so the image never has to ship or distribute them.
# pmOS installs flash only boot+userdata: the stock vendor/dsp partitions
# stay on every installed unit, and the device duplicates files it already
# lawfully contains, for its own operation. Design, legal frame and the
# on-phone verification: fp6 repo journal/blobs/.
#
# Consumers depend on this package and install a manifest fragment into
# /usr/share/fp6-vendor-blobs/manifest.d/ (syntax in the extract script);
# their post-install/post-upgrade should also run
# /usr/lib/fp6-vendor-blobs/extract --if-device so a package upgrade that
# drops a previously-shipped blob restores the file immediately instead of
# at the next boot. First consumer: soc-fairphone-fp6-audio (aw88261 acf).
maintainer="Jorijn van der Graaf <jorijnvdgraaf@catcrafts.net>"
pkgname=fp6-vendor-blobs
pkgver=1
pkgrel=0
pkgdesc="On-device extraction of vendor blobs from the stock Android partitions"
url="https://forgejo.catcrafts.net/Catcrafts/fp6-img"
arch="noarch"
license="MIT"
# fallback mapper for when the initramfs didn't map the dynamic partitions
depends="make-dynpart-mappings"
options="!check"
source="
fp6-vendor-blobs-extract
fp6-vendor-blobs.service
"
package() {
install -Dm755 "$srcdir"/fp6-vendor-blobs-extract \
"$pkgdir"/usr/lib/fp6-vendor-blobs/extract
install -Dm644 "$srcdir"/fp6-vendor-blobs.service \
"$pkgdir"/usr/lib/systemd/system/fp6-vendor-blobs.service
# enabled unconditionally: the unit is a fast no-op once every manifest
# dest exists, and blobs appearing on first boot must not depend on a
# manual systemctl enable
mkdir -p "$pkgdir"/etc/systemd/system/multi-user.target.wants
ln -s /usr/lib/systemd/system/fp6-vendor-blobs.service \
"$pkgdir"/etc/systemd/system/multi-user.target.wants/fp6-vendor-blobs.service
mkdir -p "$pkgdir"/usr/share/fp6-vendor-blobs/manifest.d
}
sha512sums="
a71b2c86f980734d0aae6e135b26272fe52ae5603050bea52f55f7e74c8bd98c62b6194047711248d4fef40851792adc47d77c40016d99a0d68ecd2459894b80 fp6-vendor-blobs-extract
e2c03e5016f1848c57e6160ce432530b181ff5d34a5aaf1822f0ffa5fe71d16691657ada4a5789c4d4209e14e83f43aab072d01f644b07b93648f91e2a7bb0ca fp6-vendor-blobs.service
"