fp6-img/README.md
Jorijn van der Graaf ccf23abf81 install.sh: one-command modem-preserving installer
erase dtbo + flash userdata + RAM-boot + dd boot_a from Linux + verify
modem NV and report honestly. Shipped in dist/ with every release; README
points at it. The one believed-safe-but-unisolated step (userdata flash)
is self-verified by the script's final check.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-09 01:29:17 +02:00

4.6 KiB

fp6-img

Flashable postmarketOS images for the Fairphone 6, built nightly from the Catcrafts milos-linux combined-stable kernel branch, with imsd (userspace VoLTE) preinstalled.

Maintained by Jorijn van der Graaf (TheMightyCat) at Catcrafts.

Caution

Emergency calling is unverified. Calls (including 112/911) go through imsd, whose emergency path is spec-shaped but has never been verified against a live network.

What works

Everything on the combined-stable branch: display, touch, wifi, cellular data, NFC (reader), speaker audio, microphone, IMU, magnetometer, barometer, ambient light/proximity — plus VoLTE calls (both directions) through imsd.

Verified on exactly one device / one carrier (KPN NL). Reports from other carriers are very welcome.

Flashing

Download boot.img and fairphone-fp6.img from the latest release and unlock the bootloader (Fairphone's official process).

Recommended — modem-preserving install: with the phone in fastboot mode, run install.sh (also attached to every release) from the directory holding the two images:

sh install.sh

It erases dtbo, flashes the rootfs, RAM-boots the kernel (fastboot boot — verified to write nothing), writes the boot partition from inside Linux where the bootloader's NV-wipe cannot see it, then reads the modem NV back and reports the result. The bootloader never writes boot.

Classic install (simpler, but fastboot flash boot zeroes the modem's NV — cellular will be dead until you restore your modemst backup):

fastboot flash userdata fairphone-fp6.img
fastboot flash boot boot.img
fastboot erase dtbo
fastboot reboot

Default login: user / 147147 (same as official postmarketOS images — change it). Never re-lock the bootloader with a custom image installed.

Warning

fastboot flash boot zeroes the modem's NV storage on this device (modemst1/modemst2) — verified by isolation experiment; fastboot erase dtbo and idle fastboot sessions are safe. Afterwards the modem reports no IMEI and neither SIM slot answers (no-atr-received), eSIM included. The eSIM profiles themselves are safe in the eUICC; stock Android silently re-provisions the NV from fsg on boot, postmarketOS cannot.

Practical rules:

  • Back up first: from a running postmarketOS (or rooted stock), dd /dev/disk/by-partlabel/modemst1 and modemst2 to files, keep forever.
  • After install, restore them: dd back and reboot — cellular returns.
  • Never update the kernel via fastboot — installed systems update boot through on-device boot-deploy (which apk kernel upgrades run automatically), never tripping the wipe.

VoLTE configuration

imsd is installed but needs your carrier's P-CSCF address:

# /etc/imsd.env
PCSCF=<your carrier's P-CSCF IPv6 address>

Find it in a stock-firmware capture or your carrier's IMS documentation, then systemctl restart imsd (the service is enabled at boot and waits for this file to exist). See the imsd README for the full variable reference and carrier assumptions.

How it builds

build.sh drives pmbootstrap with the aports/ overlay in this repository:

  • device/linux-postmarketos-qcom-milos — the pmaports kernel aport, repointed at combined-stable (source tarball generated with git-archive; the Forgejo instance serves no source archives) with the exact kernel config the development FP6 runs.
  • modem/imsd — imsd, packaged from source. Its provides=81voltd keeps the conflicting modem-firmware IMS helper off the image (two IMS stacks cannot share one PDN).
  • main/postmarketos-config-nftables — adds the -imsd subpackage accepting imsd's IPsec-protected SIP ports on the IMS PDN (auto-installed alongside imsd).

Roadmap

  • End-to-end pipeline validation (first complete image built 2026-08-08)
  • Speaker-audio userspace files (soc-fairphone-fp6-audio: topology, amp config, UCM — byte-identical to the tested dev-phone set; blob provenance to be settled before this repo goes public)
  • imsd in the image (pinned to the public 0.3.0 commit; the phone's working call stack incl. callaudioshim and the modem-daemon autostart override ship as packages)
  • Nightly schedule once the first dispatched run is green