Install fingerprintd from the registry, so the image unlocks with a finger
Some checks failed
image / image (push) Failing after 57m23s
Some checks failed
image / image (push) Failing after 57m23s
The daemon's own package CI publishes it to the registry the same way imsd's does, so the image takes it from there: the exact apk a user later gets via apk upgrade, sha256-pinned, re-signed for the chroot. Section 3b now fetches both sets, and every fetched file must have a pin -- the check used to be `grep . | sha256sum -c`, which an empty pin list would have sailed through with nothing checked. Three apks: the daemon, its systemd units, and the session agent, which does nothing until a user writes ~/.config/fingerprintd/fingers.conf. The daemon needs the kernel aport's CONFIG_QCOMTEE=m (pkgrel 101) and fp6-vendor-blobs 1-r2's mbn directive to reassemble the trustlet, both built in this run; 0.2.3 says >=1-r2 so a mismatched pair is refused rather than installed. The CI publish step skips fingerprintd-* like imsd-*: registry-sourced, not ours to republish. README: fingerprint in the list, and the two things a user will otherwise report as a dead sensor -- the lock screen listens for 60 seconds after it appears, and a held press is what the matcher was measured on -- plus the untested question of stock Android's own fingerprints after using this. Verified on the dev phone (fp6 repo journal/fingerprint/, 2026-09-05): the registry 0.2.2 package enrols through Plasma's Users page and unlocks the lock screen; 0.2.3 differs by the dependency and a post-upgrade restart. The image build itself, with the fprintd purge inside the chroot, runs first in CI.
This commit is contained in:
parent
155b427478
commit
2a4427919e
3 changed files with 67 additions and 20 deletions
|
|
@ -50,8 +50,8 @@ jobs:
|
|||
# the FP6 patches to the next upstream version bump. Requires the
|
||||
# PACKAGE_TOKEN repo secret (catbot account, package:write scope);
|
||||
# skips quietly until it exists. 409 = same version already published.
|
||||
# imsd is skipped: build.sh 3b took it FROM the registry (re-signed
|
||||
# for the chroot), so it is not ours to publish.
|
||||
# imsd and fingerprintd are skipped: build.sh 3b took them FROM the
|
||||
# registry (re-signed for the chroot), so they are not ours to publish.
|
||||
- name: Publish packages to the apk registry
|
||||
env:
|
||||
PACKAGE_TOKEN: ${{ secrets.PACKAGE_TOKEN }}
|
||||
|
|
@ -65,7 +65,7 @@ jobs:
|
|||
for f in /home/build/.local/var/pmbootstrap/packages/*/aarch64/*.apk; do
|
||||
[ -e "$f" ] || continue
|
||||
case "$(basename "$f")" in
|
||||
imsd-*) echo "registry-sourced, not republished: $(basename "$f")"; continue ;;
|
||||
imsd-*|fingerprintd-*) echo "registry-sourced, not republished: $(basename "$f")"; continue ;;
|
||||
esac
|
||||
found=1
|
||||
code=$(curl -s -o /dev/null -w '%{http_code}' \
|
||||
|
|
|
|||
Loading…
Reference in a new issue