The imsd repo's package CI is now the only producer of the imsd apk. The
image installs the exact registry package users get via 'apk upgrade'
(pinned version + sha256 of the registry files), so the two can no longer
diverge and the payload-parity rule between two packagings is gone.
pmbootstrap has no knob for a third-party repository, and after the main
'apk add' it re-adds every package in its local packages dir by file path,
which makes apk verify the package's own signature. Registry packages are
signed with per-run keys nobody keeps (phones trust the registry-signed
index), so apk-resign.py replaces the signature stream with one from this
run's abuild key; control and data streams stay byte-identical and the
identity checksum equals the registry's. Verified on the host with apk
3.0.8: originals UNTRUSTED, re-signed OK, checksums equal.
The publish step skips imsd-*: those files came from the registry.
The imsd repo now owns its apk packaging (packaging/aport/, imsd commit
17e0f6b); build.sh copies the aport out of the same pinned checkout it
archives, so daemon and packaging can never skew. The local
aports/modem/imsd copy is gone.
0.3.1 ships the ims-pdn-up hardening (mmcli errors logged verbatim per
attempt, connect attempts gated on network registration, IMS_IP_TYPE
configurable) — the field-debugging fix for undecodable bearer failures
(journal/users/tu11ebukk), tested on the dev phone. build-info.txt now
derives the imsd version from the aport instead of hardcoding it.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
New package fp6-vendor-blobs: a manifest-driven systemd oneshot that
copies proprietary blobs out of the stock Android partitions on first
boot. pmOS installs flash only boot+userdata, so every installed unit
still carries the stock vendor/dsp partitions - the device duplicates a
file it already contains, for its own operation, and nothing proprietary
is distributed by us. Partitions are mounted read-only (ext4 additionally
with noload - not even a journal replay touches the stock data), every
copy is sha256-pinned and a miss fails loudly, and the consuming devices
are unbound and re-probed afterwards so the feature works the same boot.
The rebind is unconditional by design: aw88261 binds on a bare i2c
chip-id probe and requests the ACF only at ASoC card init (~21 s, after
SoundWire enumeration), so a bound device can still be one that lost the
firmware race - and that failed request is never retried.
soc-fairphone-fp6-audio (pkgver 4) stops shipping the blob, installs the
manifest fragment instead, and re-runs the extractor from
post-install/post-upgrade so upgrades restore the file immediately (the
old package version removed it on upgrade). License drops back to plain
BSD-3-Clause - nothing proprietary left in the package.
Verified on the dev phone (fp6 repo journal/blobs/captures/
2026-08-24-first-boot-extractor-verification.txt): first-boot extraction
+ same-boot audio, mid-session post-upgrade recovery, and the everyday
fast-path no-op; committed files byte-identical to the tested deployment.
Assisted-by: Claude:claude-fable-5
su scrubs the environment, so the escape hatch from the previous commit
never reached the build user (verified: libcamera still built crossdirect
and failed identically).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
crossdirect's /native bridge breaks under local podman (cc: cannot execute
cc1: posix_spawnp ENOENT in meson setup) while qemu-only builds work fine;
the env flag routes the affected packages (libqmi/MM/libcamera + a new
explicit imsd pre-build, since install has no per-package flag) through
--no-cross. Identical package output, slower build; kernel stays
cross-native. CI behavior unchanged when the env is unset.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The pmOS gitlab truncates clones under load (early EOF / invalid
index-pack); the pip install runs in the root branch before clone_retry
exists, so give it its own 3-attempt loop.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Charger-insertion boots (androidboot.mode=charger, ABL-appended) divert to
a minimal charging.target instead of the full UI, ending the dead-battery
bootloop: ADSP charging/USB-PD runs, splash+panel killed ~6-10s in via an
initramfs hook, modem+cdsp stopped, radios/sensors suppressed, CPU capped.
Power key reboots to a normal boot, volume-up shows battery status,
volume-down enables USB ssh, unplug powers off. Measured >= breakeven on a
100mA-classified SDP port, strongly net-positive on real chargers.
Suspend duty-cycling (~13mA floor) exists behind an off-by-default flag:
resume from deep suspend intermittently kills the UFS link (hibern8 exit
failed ret=5) - do not enable until that kernel bug is fixed.
Byte-identical to the deployment verified on the dev phone 2026-08-24
(journal/power: r5 armed tests, crash autopsies, measurements).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
gitlab.freedesktop.org's on-demand archive endpoint 503/504s for hours
at a stretch: runs #25, #27, #30 and #31 all died in 'abuild checksum'
fetching the pinned libqmi tarball, outlasting the 3x30s in-run retry.
git clone is served from a different code path and holds up (verified
against all three repos while the archive endpoint was flaky), so clone
libqmi/ModemManager/libcamera (retried) and git-archive the pinned refs
into the aports, the same way the kernel and imsd tarballs are already
produced. The pins stay single-sourced in the APKBUILDs.
libcamera gains a checksum step: its committed sums were for the
fd.o-served tarball, and git-archive output is not byte-identical.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Run #25 died at 'pmbootstrap checksum libqmi' on a bare HTTP 503 from
gitlab.freedesktop.org. That host serves three of this pipeline's inputs
(libqmi, modemmanager and now libcamera), and its 503s are transient - it
answered 200 again minutes later - so a hiccup there should cost a retry,
not a 2-hour run.
Same shape as clone_retry, applied to the checksum and build calls that
fetch sources. The kernel and imsd checksums need no retry: their tarballs
are generated locally by this script.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
34cfc09 added aports/temp/libcamera but never taught build.sh to copy it,
so run #24 built the image with pmOS's stock 99990.7.2-r1 and published no
libcamera package at all. Copy it like libqmi/modemmanager (upstream aport
deleted first - duplicate pkgnames are a pmbootstrap hard error) and build
it explicitly so the -r2 apk reaches the registry publish step.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Run 22 failed with 'catcrafts-fp6-repo: Could not find it in pmaports
or any APKINDEX': build.sh copies each overlay aport explicitly and
this one was never in the list, so pmbootstrap could not resolve the
new extra_packages entry.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The catcrafts-fp6-repo aport (signing key + repositories entry) existed
but nothing installed it: images shipped with the CI-built packages
baked in and no update channel, so 'apk upgrade' never delivered new
kernel/imsd builds despite CI publishing every apk to the registry.
Add it to extra_packages and document the registry in the README.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
erase dtbo + flash userdata + RAM-boot + dd boot_a from Linux + verify
modem NV and report honestly. Shipped in dist/ with every release; README
points at it. The one believed-safe-but-unisolated step (userdata flash)
is self-verified by the script's final check.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Full-system audit findings: without an explicit provider selection the
image installed real PulseAudio (Plasma Mobile hard-path), which claims
the card and ships a wireplumber fragment disabling hardware.audio -
zero sinks forever. Mirror the dev phone's world: pipewire backend meta
+ pipewire-pulse + echo-cancel in extra_packages, pulse meta banned via
apk conflict in fp6-device-tweaks. The two hand-made /etc audio
fragments (wireplumber no-ACP rule, AEC pair for VoLTE speakerphone)
move into soc-fairphone-fp6-audio.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Full-system audit on the flashed phone found the IMU dead: the journal's
documented reinstall-loss trio (inv-icm42600-spi modules-load - fallback-only
SPI node never coldplugs; the accel poll udev rule for auto-rotate; the
iio-sensor-proxy libssc-crash restart drop-in). All device-critical, none
personal - now packaged.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Two device-critical pieces previously applied only by the dev restore
script: masked sleep targets (idle-suspend resets the WCN combo firmware
and kills wifi ~40min - a device defect, not personalization) and imsd
enabled at boot, gated on /etc/imsd.env existing so unconfigured systems
don't boot a failing unit. A stranger now needs exactly: flash, wifi via
UI, write imsd.env, restart imsd.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
pmbootstrap's install-time build plan is not topologically sorted; the
versioned makedep made that a hard error instead of a stale-dep build.
Explicit bottom-up build restores order; no-op when current.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
pmbootstrap's build plan is not dependency-ordered: MM built first and
grabbed the cached 1.39.0 libqmi from the volume's package repo. The
versioned makedepend states the real requirement and forces our bumped
libqmi to build first. Kernel pkgver gains the source commit date so
registry-subscribed phones receive kernel updates.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The forgejo VM occasionally 500s under crawler load - a clone blip
should cost 10 seconds, not the run. dist/ keeps its inode so a shell
cd'd into it no longer breaks the next podman start.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
libqmi: the upstream-merged (!470, in no release yet) LOC Register Events
client-identification TLVs, taken verbatim from upstream main (532de37e).
modemmanager: the AFW engine unlock + Position Report derivation (!1463,
still draft upstream, review-hardened and verified on device). Both as
patches on Alpine's git-snapshot aports, pkgrel=100.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
imsd turns out to be fully public already (0.2.7 snapshot + emergency
stage 1 + the make build path) - no tag needed, same git-archive dance as
the kernel. callaudioshim was a load-bearing unpackaged home-dir script on
the phone (callaudiod replacement, working in-call mic mute); now an aport
autostarted at phase 1. kde-telephony's modem daemon autostart is hidden
via /etc/skel from the imsd package, mirroring the phone's user override.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Files copied byte-identical from the tested dev phone; installed to the
exact deployed paths (the spaced tplg/UCM filenames come from the machine
driver's card name). Wired into the image via extra_packages.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Partition nodes (loopNpM) only appear via the host devtmpfs; a privileged
container's own /dev never gains them. Drop the static mknod dance, warn
when /dev is not the host's.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Alpine's packaged pmbootstrap predates pmaports' master->main rename and
fails reading channels.cfg. Pinning also matches the version the rest of
this script was written against.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
'pmbootstrap config' demands an existing config file, so write
pmbootstrap_v3.cfg ourselves (INI, aports/device/ui/systemd). Explicit
set -eu because 'sh script' ignores shebang flags - run 3 shipped a
3.5KB 'image' because failures didn't propagate. dist/ is now the only
build-user-owned path, so the tag step's git works again.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Learned from the pmbootstrap 3.11 source: aports overlays must replace
upstream dirs in one tree (duplicate pkgnames are a hard error), pmbootstrap
refuses root (drop to a sudo-capable build user), and export symlinks are
boot.img + fairphone-fp6.img. Stage 1 builds without imsd until the v0.3.0
tag exists. Temporary push trigger for bring-up.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Kernel aport forked from pmaports 7.1.2-r0, repointed at milos-linux
combined-stable with the tested FP6 config (+EFI_ZBOOT for packaging);
imsd + nftables aports from the pending pmaports submission. build.sh
carries TODO(validate) markers - not yet run end-to-end.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>