Catcrafts builds of the postmarketos image for the fairphone 6
  • Shell 84.7%
  • Python 15.3%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Jorijn van der Graaf 7bf226e73b
All checks were successful
image / image (push) Successful in 1h53m7s
fp6-vendor-blobs: the checksum the extractor change forgot, and a check that finds the next one in a second
CI run 52 failed at minute 57 with `fp6-vendor-blobs-extract: FAILED` from
abuild's checksum verification: 9575e55 changed the extractor and left its
sha512sums entry alone. Nothing was installed or published; latest is the
run-51 image.

Fix the sum, and stop paying an hour to learn it. check-aports.sh sources
every APKBUILD under aports/ and compares the committed sha512sums of its
local source files (scripts, units, configs, patches, including ones in a
subdirectory) against the files themselves. build.sh runs it before
pmbootstrap touches anything, so this class of mistake now fails in the first
seconds of a run and prints the line to paste. Aports whose sums build.sh
regenerates with pmbootstrap checksum are read from build.sh and skipped, so
the two lists cannot drift.

Verified: the checker reports exactly the run-52 mismatch on the tree as
pushed and nothing on the tree as fixed; a scratch copy with one corrupted
sum is caught; the fixed aport builds under abuild in an alpine:edge
container (the only complaint was the throwaway signing key at the index
step, which the CI's pmbootstrap flow does not have).
2026-09-05 22:26:33 +02:00
.forgejo/workflows Install fingerprintd from the registry, so the image unlocks with a finger 2026-09-05 20:31:37 +02:00
aports fp6-vendor-blobs: the checksum the extractor change forgot, and a check that finds the next one in a second 2026-09-05 22:26:33 +02:00
.gitignore gitignore dist/; fix empty then-branch (sh syntax) in the NV verdict 2026-08-09 02:44:39 +02:00
apk-resign.py imsd: sign from a readable copy of the abuild key 2026-09-02 17:21:30 +02:00
build.sh fp6-vendor-blobs: the checksum the extractor change forgot, and a check that finds the next one in a second 2026-09-05 22:26:33 +02:00
check-aports.sh fp6-vendor-blobs: the checksum the extractor change forgot, and a check that finds the next one in a second 2026-09-05 22:26:33 +02:00
install.sh debian fix 2026-08-29 00:40:38 +02:00
README.md Install fingerprintd from the registry, so the image unlocks with a finger 2026-09-05 20:31:37 +02:00

fp6-img

Flashable postmarketOS images for the Fairphone 6/6+, built nightly from the Catcrafts milos-linux combined-stable kernel branch, with imsd (userspace VoLTE) preinstalled.

Maintained by Jorijn van der Graaf (TheMightyCat) at Catcrafts.

What works

Everything on the combined-stable branch: display, touch, wifi, cellular data, NFC (reader), speaker audio, microphone, IMU, magnetometer, barometer, ambient light/proximity, fingerprint unlock through fingerprintd, plus VoLTE calls (both directions) through imsd.

Flashing

Download fp6-img.tar.xz from the latest release and unlock the bootloader (Fairphone's official process).

Install: with the phone in fastboot mode,

tar xf fp6-img.tar.xz
cd fp6-img
./install.sh

install.sh erases dtbo, flashes the rootfs, RAM-boots the kernel, writes the boot partition from inside Linux where the bootloader's NV-wipe cannot see it, then reads the modem NV back and reports the result. The bootloader never writes boot.

Default login: user / 147147 (same as official postmarketOS images — change it). Never re-lock the bootloader with a custom image installed.

VoLTE configuration

imsd is installed but needs your carrier's P-CSCF address:

# /etc/imsd.env
PCSCF=<your carrier's P-CSCF IPv6 address>

Find it in a stock-firmware capture or your carrier's IMS documentation, then systemctl restart imsd (the service is enabled at boot and waits for this file to exist). See the imsd README for the full variable reference and carrier assumptions.

Fingerprint

Enrol under Settings → Users (Plasma's own fingerprint page; the fprintd command-line tools are not installed, fingerprintd replaces that package). Hold the finger on the sensor for each of the ~20 presses rather than tapping it; a held press is what the matcher was measured on.

Two things to know:

  • The lock screen listens for a finger for 60 seconds after it appears. A press after that reaches nothing and looks like a dead sensor. Lock and unlock again to re-arm it.
  • The matcher is the phone's own proprietary trustlet, reassembled from the stock modem partition on first boot and never shipped by us. Templates are stored on the Android persist partition, sealed to the same hardware anti-rollback counter stock Android uses. Whether fingerprints enrolled under stock Android survive a return to it after using this has not been tested.

A finger can also run something in your session on a match (~/.config/fingerprintd/fingers.conf, see the fingerprintd README).