fp6-img/README.md
Jorijn van der Graaf 42d28305ca README: the modemst wipe is 'fastboot flash boot', precisely
Isolated by experiment (2026-08-09, journal/modem): flash boot alone
zeroes modem NV; erase dtbo and idle fastboot visits are safe; on-device
boot-deploy (incl. apk kernel upgrades) never trips it. Likely ABL
anti-tamper on boot-image overwrite under an unlocked bootloader.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-09 01:10:16 +02:00

4 KiB

fp6-img

Flashable postmarketOS images for the Fairphone 6, built nightly from the Catcrafts milos-linux combined-stable kernel branch, with imsd (userspace VoLTE) preinstalled.

Maintained by Jorijn van der Graaf (TheMightyCat) at Catcrafts.

Caution

Emergency calling is unverified. Calls (including 112/911) go through imsd, whose emergency path is spec-shaped but has never been verified against a live network.

What works

Everything on the combined-stable branch: display, touch, wifi, cellular data, NFC (reader), speaker audio, microphone, IMU, magnetometer, barometer, ambient light/proximity — plus VoLTE calls (both directions) through imsd.

Verified on exactly one device / one carrier (KPN NL). Reports from other carriers are very welcome.

Flashing

Download boot.img and fairphone-fp6.img from the latest release, unlock the bootloader (Fairphone's official process), then:

fastboot flash userdata fairphone-fp6.img
fastboot flash boot boot.img
fastboot erase dtbo
fastboot reboot

Default login: user / 147147 (same as official postmarketOS images — change it). Never re-lock the bootloader with a custom image installed.

Warning

fastboot flash boot zeroes the modem's NV storage on this device (modemst1/modemst2) — verified by isolation experiment; fastboot erase dtbo and idle fastboot sessions are safe. Afterwards the modem reports no IMEI and neither SIM slot answers (no-atr-received), eSIM included. The eSIM profiles themselves are safe in the eUICC; stock Android silently re-provisions the NV from fsg on boot, postmarketOS cannot.

Practical rules:

  • Back up first: from a running postmarketOS (or rooted stock), dd /dev/disk/by-partlabel/modemst1 and modemst2 to files, keep forever.
  • After install, restore them: dd back and reboot — cellular returns.
  • Never update the kernel via fastboot — installed systems update boot through on-device boot-deploy (which apk kernel upgrades run automatically), never tripping the wipe.

VoLTE configuration

imsd is installed but needs your carrier's P-CSCF address:

# /etc/imsd.env
PCSCF=<your carrier's P-CSCF IPv6 address>

Find it in a stock-firmware capture or your carrier's IMS documentation, then systemctl restart imsd (the service is enabled at boot and waits for this file to exist). See the imsd README for the full variable reference and carrier assumptions.

How it builds

build.sh drives pmbootstrap with the aports/ overlay in this repository:

  • device/linux-postmarketos-qcom-milos — the pmaports kernel aport, repointed at combined-stable (source tarball generated with git-archive; the Forgejo instance serves no source archives) with the exact kernel config the development FP6 runs.
  • modem/imsd — imsd, packaged from source. Its provides=81voltd keeps the conflicting modem-firmware IMS helper off the image (two IMS stacks cannot share one PDN).
  • main/postmarketos-config-nftables — adds the -imsd subpackage accepting imsd's IPsec-protected SIP ports on the IMS PDN (auto-installed alongside imsd).

Roadmap

  • End-to-end pipeline validation (first complete image built 2026-08-08)
  • Speaker-audio userspace files (soc-fairphone-fp6-audio: topology, amp config, UCM — byte-identical to the tested dev-phone set; blob provenance to be settled before this repo goes public)
  • imsd in the image (pinned to the public 0.3.0 commit; the phone's working call stack incl. callaudioshim and the modem-daemon autostart override ship as packages)
  • Nightly schedule once the first dispatched run is green