Catcrafts builds of the postmarketos image for the fairphone 6
  • Shell 84.7%
  • Python 15.3%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Jorijn van der Graaf d14fa38a98
Install fingerprintd from the registry, so the image unlocks with a finger
The daemon's own package CI publishes it to the registry the same way imsd's
does, so the image takes it from there: the exact apk a user later gets via
apk upgrade, sha256-pinned, re-signed for the chroot. Section 3b now fetches
both sets, and every fetched file must have a pin -- the check used to be
`grep . | sha256sum -c`, which an empty pin list would have sailed through
with nothing checked.

Three apks: the daemon, its systemd units, and the session agent, which does
nothing until a user writes ~/.config/fingerprintd/fingers.conf. The daemon
needs the kernel aport's CONFIG_QCOMTEE=m (pkgrel 101) and fp6-vendor-blobs
1-r2's mbn directive to reassemble the trustlet, both built in this run;
0.2.3 says >=1-r2 so a mismatched pair is refused rather than installed.

The CI publish step skips fingerprintd-* like imsd-*: registry-sourced, not
ours to republish. README: fingerprint in the list, and the two things a user
will otherwise report as a dead sensor -- the lock screen listens for 60
seconds after it appears, and a held press is what the matcher was measured
on -- plus the untested question of stock Android's own fingerprints after
using this.

Verified on the dev phone (fp6 repo journal/fingerprint/, 2026-09-05): the
registry 0.2.2 package enrols through Plasma's Users page and unlocks the
lock screen; 0.2.3 differs by the dependency and a post-upgrade restart. The
image build itself, with the fprintd purge inside the chroot, runs first in
CI.
2026-09-15 22:36:13 +02:00
.forgejo/workflows Install fingerprintd from the registry, so the image unlocks with a finger 2026-09-15 22:36:13 +02:00
aports kernel: build qcomtee, which is one line and not the coupled change we recorded 2026-09-15 22:36:12 +02:00
.gitignore gitignore dist/; fix empty then-branch (sh syntax) in the NV verdict 2026-08-09 02:44:39 +02:00
apk-resign.py imsd: sign from a readable copy of the abuild key 2026-09-15 22:36:12 +02:00
build.sh Install fingerprintd from the registry, so the image unlocks with a finger 2026-09-15 22:36:13 +02:00
install.sh debian fix 2026-09-15 22:36:12 +02:00
README.md Install fingerprintd from the registry, so the image unlocks with a finger 2026-09-15 22:36:13 +02:00

fp6-img

Flashable postmarketOS images for the Fairphone 6/6+, built nightly from the Catcrafts milos-linux combined-stable kernel branch, with imsd (userspace VoLTE) preinstalled.

Maintained by Jorijn van der Graaf (TheMightyCat) at Catcrafts.

What works

Everything on the combined-stable branch: display, touch, wifi, cellular data, NFC (reader), speaker audio, microphone, IMU, magnetometer, barometer, ambient light/proximity, fingerprint unlock through fingerprintd, plus VoLTE calls (both directions) through imsd.

Flashing

Download fp6-img.tar.xz from the latest release and unlock the bootloader (Fairphone's official process).

Install: with the phone in fastboot mode,

tar xf fp6-img.tar.xz
cd fp6-img
./install.sh

install.sh erases dtbo, flashes the rootfs, RAM-boots the kernel, writes the boot partition from inside Linux where the bootloader's NV-wipe cannot see it, then reads the modem NV back and reports the result. The bootloader never writes boot.

Default login: user / 147147 (same as official postmarketOS images — change it). Never re-lock the bootloader with a custom image installed.

VoLTE configuration

imsd is installed but needs your carrier's P-CSCF address:

# /etc/imsd.env
PCSCF=<your carrier's P-CSCF IPv6 address>

Find it in a stock-firmware capture or your carrier's IMS documentation, then systemctl restart imsd (the service is enabled at boot and waits for this file to exist). See the imsd README for the full variable reference and carrier assumptions.

Fingerprint

Enrol under Settings → Users (Plasma's own fingerprint page; the fprintd command-line tools are not installed, fingerprintd replaces that package). Hold the finger on the sensor for each of the ~20 presses rather than tapping it; a held press is what the matcher was measured on.

Two things to know:

  • The lock screen listens for a finger for 60 seconds after it appears. A press after that reaches nothing and looks like a dead sensor. Lock and unlock again to re-arm it.
  • The matcher is the phone's own proprietary trustlet, reassembled from the stock modem partition on first boot and never shipped by us. Templates are stored on the Android persist partition, sealed to the same hardware anti-rollback counter stock Android uses. Whether fingerprints enrolled under stock Android survive a return to it after using this has not been tested.

A finger can also run something in your session on a match (~/.config/fingerprintd/fingers.conf, see the fingerprintd README).