The daemon's own package CI publishes it to the registry the same way imsd's
does, so the image takes it from there: the exact apk a user later gets via
apk upgrade, sha256-pinned, re-signed for the chroot. Section 3b now fetches
both sets, and every fetched file must have a pin -- the check used to be
`grep . | sha256sum -c`, which an empty pin list would have sailed through
with nothing checked.
Three apks: the daemon, its systemd units, and the session agent, which does
nothing until a user writes ~/.config/fingerprintd/fingers.conf. The daemon
needs the kernel aport's CONFIG_QCOMTEE=m (pkgrel 101) and fp6-vendor-blobs
1-r2's mbn directive to reassemble the trustlet, both built in this run;
0.2.3 says >=1-r2 so a mismatched pair is refused rather than installed.
The CI publish step skips fingerprintd-* like imsd-*: registry-sourced, not
ours to republish. README: fingerprint in the list, and the two things a user
will otherwise report as a dead sensor -- the lock screen listens for 60
seconds after it appears, and a held press is what the matcher was measured
on -- plus the untested question of stock Android's own fingerprints after
using this.
Verified on the dev phone (fp6 repo journal/fingerprint/, 2026-09-05): the
registry 0.2.2 package enrols through Plasma's Users page and unlocks the
lock screen; 0.2.3 differs by the dependency and a post-upgrade restart. The
image build itself, with the fprintd purge inside the chroot, runs first in
CI.
The catcrafts-fp6-repo aport (signing key + repositories entry) existed
but nothing installed it: images shipped with the CI-built packages
baked in and no update channel, so 'apk upgrade' never delivered new
kernel/imsd builds despite CI publishing every apk to the registry.
Add it to extra_packages and document the registry in the README.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The stale-rpmh-votes GMU wedge (GMU fw init timeout under bursty GPU
use) is fixed in kernel builds from combined-stable >= 2026-08-14 by
carrying upstream 'drm/msm/a6xx: Fix stale rpmh votes after suspend'
(d9108bfdb746, drm-msm msm-next). This push also triggers the image
rebuild that picks the fix up.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
ssh ControlMaster keeps one authenticated connection (login typed at
most once, or never with sshpass installed); sudo answers itself via a
SUDO_ASKPASS helper carrying the image's public default password (sudo
-S would have eaten the boot image's first bytes from stdin). Helper
lives on tmpfs and evaporates with the install reboot.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
erase dtbo + flash userdata + RAM-boot + dd boot_a from Linux + verify
modem NV and report honestly. Shipped in dist/ with every release; README
points at it. The one believed-safe-but-unisolated step (userdata flash)
is self-verified by the script's final check.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Proven 2026-08-09: RAM-booting writes nothing (modemst byte-identical
after), so a fresh install that dd's boot_a and userdata from the booted
Linux never triggers the ABL's boot-flash NV wipe. Classic flash flow
documented as the wiping alternative. Details in journal/modem.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Isolated by experiment (2026-08-09, journal/modem): flash boot alone
zeroes modem NV; erase dtbo and idle fastboot visits are safe; on-device
boot-deploy (incl. apk kernel upgrades) never trips it. Likely ABL
anti-tamper on boot-image overwrite under an unlocked bootloader.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Two device-critical pieces previously applied only by the dev restore
script: masked sleep targets (idle-suspend resets the WCN combo firmware
and kills wifi ~40min - a device defect, not personalization) and imsd
enabled at boot, gated on /etc/imsd.env existing so unconfigured systems
don't boot a failing unit. A stranger now needs exactly: flash, wifi via
UI, write imsd.env, restart imsd.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
libqmi: the upstream-merged (!470, in no release yet) LOC Register Events
client-identification TLVs, taken verbatim from upstream main (532de37e).
modemmanager: the AFW engine unlock + Position Report derivation (!1463,
still draft upstream, review-hardened and verified on device). Both as
patches on Alpine's git-snapshot aports, pkgrel=100.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
imsd turns out to be fully public already (0.2.7 snapshot + emergency
stage 1 + the make build path) - no tag needed, same git-archive dance as
the kernel. callaudioshim was a load-bearing unpackaged home-dir script on
the phone (callaudiod replacement, working in-call mic mute); now an aport
autostarted at phase 1. kde-telephony's modem daemon autostart is hidden
via /etc/skel from the imsd package, mirroring the phone's user override.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Files copied byte-identical from the tested dev phone; installed to the
exact deployed paths (the spaced tplg/UCM filenames come from the machine
driver's card name). Wired into the image via extra_packages.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Learned from the pmbootstrap 3.11 source: aports overlays must replace
upstream dirs in one tree (duplicate pkgnames are a hard error), pmbootstrap
refuses root (drop to a sudo-capable build user), and export symlinks are
boot.img + fairphone-fp6.img. Stage 1 builds without imsd until the v0.3.0
tag exists. Temporary push trigger for bring-up.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Kernel aport forked from pmaports 7.1.2-r0, repointed at milos-linux
combined-stable with the tested FP6 config (+EFI_ZBOOT for packaging);
imsd + nftables aports from the pending pmaports submission. build.sh
carries TODO(validate) markers - not yet run end-to-end.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>