Phosh image: GDM's login-screen schema, so Settings can enrol a finger
Some checks failed
image / image (push) Failing after 3h23m10s

GNOME Settings 51 shows the Users page's "Fingerprint Login" row only when
GDM's org.gnome.login-screen schema exists and its
enable-fingerprint-authentication key is true. The Phosh image logs in
through greetd/phrog, so without GDM the row never appeared and no finger
could be enrolled from the GUI; Settings never asked fingerprintd.

fp6-login-screen-schema installs GDM's schema file, unchanged, from
Alpine's gdm-48.0-r8, and nothing else of GDM. It is the only key Settings
reads, and nothing else on the image looks the schema up. replaces="gdm"
keeps a single copy if GDM is ever installed as well (tested in alpine:edge
in both orders; glib-compile-schemas stays clean). Added to the Phosh
image's packages.

Tested on the dev phone: the row appears, a thumb enrolled through
Settings' dialog, and it unlocks the lock screen.
This commit is contained in:
Jorijn van der Graaf 2026-09-23 19:55:40 +02:00
commit 8e4cc1d777
Signed by: jorijnvdgraaf
GPG key ID: 2937E59CDCC1BCFB
3 changed files with 170 additions and 2 deletions

View file

@ -0,0 +1,31 @@
# GNOME Settings shows the Users page's "Fingerprint Login" row only when
# GDM's org.gnome.login-screen schema exists and its
# enable-fingerprint-authentication key is true (51.0,
# panels/system/users/cc-user-page.c). The Phosh image logs in through
# greetd/phrog, so without GDM the row never appears and no finger can be
# enrolled from the GUI. This installs GDM's schema file unchanged, taken
# from Alpine's gdm-48.0-r8, and nothing else of GDM. It is the only key
# Settings reads from it, and nothing else on the image looks the schema up.
# replaces="gdm" keeps one copy if GDM is ever installed as well: two
# definitions of one schema make glib-compile-schemas fail for every schema.
# glib's trigger on /usr/share/glib-2.0/schemas compiles it on install.
maintainer="Jorijn van der Graaf <jorijnvdgraaf@catcrafts.net>"
pkgname=fp6-login-screen-schema
pkgver=48.0
pkgrel=0
pkgdesc="GDM's org.gnome.login-screen schema without GDM, for GNOME Settings' fingerprint row"
url="https://forgejo.catcrafts.net/Catcrafts/fp6-img"
arch="noarch"
license="GPL-2.0-or-later"
replaces="gdm"
options="!check"
source="org.gnome.login-screen.gschema.xml"
package() {
install -Dm644 "$srcdir"/org.gnome.login-screen.gschema.xml \
"$pkgdir"/usr/share/glib-2.0/schemas/org.gnome.login-screen.gschema.xml
}
sha512sums="
7ff27457fb409cf7f235c2e075455aa62045d801c592dcd43ca786478d59ba7205d5a69ea84e4fc88ce2e43607d75d8587cec96df0513435ddd114258c331694 org.gnome.login-screen.gschema.xml
"

View file

@ -0,0 +1,135 @@
<?xml version="1.0" encoding="UTF-8"?>
<schemalist gettext-domain="gdm">
<enum id="org.gnome.login-screen.BannerSource">
<value value="1" nick="settings"/>
<value value="2" nick="file"/>
</enum>
<schema id="org.gnome.login-screen" path="/org/gnome/login-screen/">
<key name="enable-fingerprint-authentication" type="b">
<default>true</default>
<summary>
Whether or not to allow fingerprint readers for login
</summary>
<description>
The login screen can optionally allow users who have enrolled
their fingerprints to log in using those prints.
</description>
</key>
<key name="enable-smartcard-authentication" type="b">
<default>true</default>
<summary>
Whether or not to allow smartcard readers for login
</summary>
<description>
The login screen can optionally allow users who have smartcards
to log in using those smartcards.
</description>
</key>
<key name="enable-switchable-authentication" type="b">
<default>false</default>
<summary>
Whether or not to allow switchable authentication for login
</summary>
<description>
The login screen can optionally allow a single PAM service to provide
multiple authentication mechanisms via a GDM PAM.
</description>
</key>
<key name="enable-password-authentication" type="b">
<default>true</default>
<summary>
Whether or not to allow passwords for login
</summary>
<description>
The login screen can be configured to disallow password authentication,
forcing the user to use smartcard or fingerprint authentication.
</description>
</key>
<key name="logo" type="s">
<default>''</default>
<summary>
Path to small image at top of user list
</summary>
<description>
The login screen can optionally show a small image to provide site
administrators and distributions a way to display branding.
</description>
</key>
<key name="fallback-logo" type="s">
<default>''</default>
<summary>
Path to small image at top of user list
</summary>
<description>
The fallback login screen can optionally show a small image to provide
site administrators and distributions a way to display branding.
</description>
</key>
<key name="disable-user-list" type="b">
<default>false</default>
<summary>
Avoid showing user list
</summary>
<description>
The login screen normally shows a list of available users to log in
as. This setting can be toggled to disable showing the user list.
</description>
</key>
<key name="banner-message-enable" type="b">
<default>false</default>
<summary>
Enable showing the banner message
</summary>
<description>
Set to true to show the banner message text.
</description>
</key>
<key name="banner-message-source" enum="org.gnome.login-screen.BannerSource">
<default>"settings"</default>
<summary>
Banner message source
</summary>
<description>
The source of the text banner message on the login screen.
</description>
</key>
<key name="banner-message-text" type="s">
<default>''</default>
<summary>
Banner message text
</summary>
<description>
Text banner message to show in the login window.
</description>
</key>
<key name="banner-message-path" type="s">
<default>''</default>
<summary>
Banner message path
</summary>
<description>
Path to text file with banner message to show in the login window.
</description>
</key>
<key name="disable-restart-buttons" type="b">
<default>false</default>
<summary>
Disable showing the restart buttons
</summary>
<description>
Set to true to disable showing the restart buttons in the login window.
</description>
</key>
<key name="allowed-failures" type="i">
<default>3</default>
<summary>
Number of allowed authentication failures
</summary>
<description>
The number of times a user is allowed to attempt authentication, before
giving up and going back to user selection.
</description>
</key>
</schema>
</schemalist>

View file

@ -33,13 +33,14 @@ REGISTRY=https://forgejo.catcrafts.net/api/packages/Catcrafts/alpine/edge/fp6
# FP6IMG_UI: which postmarketOS UI the image boots into. plasma-mobile (the # FP6IMG_UI: which postmarketOS UI the image boots into. plasma-mobile (the
# default) gets imsd-dialerd from the imsd package itself; phosh gets the # default) gets imsd-dialerd from the imsd package itself; phosh gets the
# opt-in imsd-ofono subpackage (imsd-ofonod + the GNOME Calls plugin # opt-in imsd-ofono subpackage (imsd-ofonod + the GNOME Calls plugin
# override) on top. Everything else in the package set is UI-agnostic. The # override) and fp6-login-screen-schema (GNOME Settings' fingerprint row) on
# top. Everything else in the package set is UI-agnostic. The
# archive is named after it: fp6-img.tar.xz for plasma-mobile, # archive is named after it: fp6-img.tar.xz for plasma-mobile,
# fp6-img-<ui>.tar.xz otherwise, so one release can carry both. # fp6-img-<ui>.tar.xz otherwise, so one release can carry both.
FP6IMG_UI=${FP6IMG_UI:-plasma-mobile} FP6IMG_UI=${FP6IMG_UI:-plasma-mobile}
case "$FP6IMG_UI" in case "$FP6IMG_UI" in
plasma-mobile) UI_PACKAGES=; IMG_NAME=fp6-img ;; plasma-mobile) UI_PACKAGES=; IMG_NAME=fp6-img ;;
phosh) UI_PACKAGES=,imsd-ofono; IMG_NAME=fp6-img-phosh ;; phosh) UI_PACKAGES=,imsd-ofono,fp6-login-screen-schema; IMG_NAME=fp6-img-phosh ;;
*) echo "FP6IMG_UI=$FP6IMG_UI: expected plasma-mobile or phosh" >&2; exit 1 ;; *) echo "FP6IMG_UI=$FP6IMG_UI: expected plasma-mobile or phosh" >&2; exit 1 ;;
esac esac
PMAPORTS_REPO=https://gitlab.postmarketos.org/postmarketOS/pmaports.git PMAPORTS_REPO=https://gitlab.postmarketos.org/postmarketOS/pmaports.git
@ -159,6 +160,7 @@ cp -r aports/device/linux-postmarketos-qcom-milos "$WORK/pmaports/device/testing
cp -r aports/device/soc-fairphone-fp6-audio "$WORK/pmaports/device/" cp -r aports/device/soc-fairphone-fp6-audio "$WORK/pmaports/device/"
cp -r aports/device/fp6-vendor-blobs "$WORK/pmaports/device/" cp -r aports/device/fp6-vendor-blobs "$WORK/pmaports/device/"
cp -r aports/device/callaudioshim "$WORK/pmaports/device/" cp -r aports/device/callaudioshim "$WORK/pmaports/device/"
cp -r aports/device/fp6-login-screen-schema "$WORK/pmaports/device/"
cp -r aports/device/fp6-device-tweaks "$WORK/pmaports/device/" cp -r aports/device/fp6-device-tweaks "$WORK/pmaports/device/"
cp -r aports/device/fp6-charging-mode "$WORK/pmaports/device/" cp -r aports/device/fp6-charging-mode "$WORK/pmaports/device/"
cp -r aports/device/catcrafts-fp6-repo "$WORK/pmaports/device/" cp -r aports/device/catcrafts-fp6-repo "$WORK/pmaports/device/"