Catcrafts builds of the postmarketos image for the fairphone 6
  • Shell 84.7%
  • Python 15.3%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Jorijn van der Graaf 6541cb0e05
fp6-vendor-blobs: reassemble a Qualcomm trustlet, not just copy a file
The fingerprint matcher is a proprietary OEM-signed trustlet, and it is not
shipped as one file: QTEE images live in the modem partition's image/ as an
ELF header+hashes file plus one payload per program header, and the loader
wants each payload written back at its segment's p_offset. So the existing
file directive cannot reach it.

An mbn directive does, with the same guarantees file has: the sha256 is of
the reassembled image, a mismatch tries the next partition, and an unverified
image is never installed. Reassembly is not a concatenation -- segments are
page aligned but not contiguous, gaps stay zero, and two pairs of focal64's
nine segments share an offset, so they are written in index order and the
later one wins, exactly as the bring-up repo's reassemble.py does.

Verified on the dev phone against the hash QTEE has actually accepted since
August: 3600472 bytes, sha256 1930c490..., reassembled from the phone's own
modem_a. The retry path was verified too, with a deliberately wrong first
partition -- which is how the variable clobber got caught: POSIX sh has no
locals, and reassemble() taking rdir= rewrote its caller's copy to the mount
path, so the second partition would have been searched at $MNT/$MNT/...

The fast path needed teaching as well: mbn's dest is the fifth field, and a
first boot would otherwise have exited early and extracted nothing.

Not pushed. The consumer fragment lives in the fingerprintd package.
2026-09-15 22:36:12 +02:00
.forgejo/workflows imsd: install the published apk instead of building it 2026-09-15 22:36:12 +02:00
aports fp6-vendor-blobs: reassemble a Qualcomm trustlet, not just copy a file 2026-09-15 22:36:12 +02:00
.gitignore gitignore dist/; fix empty then-branch (sh syntax) in the NV verdict 2026-08-09 02:44:39 +02:00
apk-resign.py imsd: sign from a readable copy of the abuild key 2026-09-15 22:36:12 +02:00
build.sh imsd: place the re-signed apks with the packages dir's owner 2026-09-15 22:36:12 +02:00
install.sh debian fix 2026-09-15 22:36:12 +02:00
README.md readme change 2026-09-15 22:36:12 +02:00

fp6-img

Flashable postmarketOS images for the Fairphone 6/6+, built nightly from the Catcrafts milos-linux combined-stable kernel branch, with imsd (userspace VoLTE) preinstalled.

Maintained by Jorijn van der Graaf (TheMightyCat) at Catcrafts.

What works

Everything on the combined-stable branch: display, touch, wifi, cellular data, NFC (reader), speaker audio, microphone, IMU, magnetometer, barometer, ambient light/proximity plus VoLTE calls (both directions) through imsd.

Flashing

Download fp6-img.tar.xz from the latest release and unlock the bootloader (Fairphone's official process).

Install: with the phone in fastboot mode,

tar xf fp6-img.tar.xz
cd fp6-img
./install.sh

install.sh erases dtbo, flashes the rootfs, RAM-boots the kernel, writes the boot partition from inside Linux where the bootloader's NV-wipe cannot see it, then reads the modem NV back and reports the result. The bootloader never writes boot.

Default login: user / 147147 (same as official postmarketOS images — change it). Never re-lock the bootloader with a custom image installed.

VoLTE configuration

imsd is installed but needs your carrier's P-CSCF address:

# /etc/imsd.env
PCSCF=<your carrier's P-CSCF IPv6 address>

Find it in a stock-firmware capture or your carrier's IMS documentation, then systemctl restart imsd (the service is enabled at boot and waits for this file to exist). See the imsd README for the full variable reference and carrier assumptions.