fp6-img/aports/device/fp6-vendor-blobs
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Jorijn van der Graaf ed18cce7d0 fp6-vendor-blobs 1-r3: extract from the active slot, and stop pinning a hash on a signed image
Two field units got no fingerprint sensor from fingerprintd 0.2.3's
manifest: its focal64 line pinned the sha256 of one Android build's
trustlet (16.82.0, the dev phone's), and Fairphone re-signs that trustlet
every release, so the pin matches exactly one of the six builds seen. A
user on 16.100.0 had to edit the manifest by hand; another ended up with
a file QTEE refuses.

The extractor now tries the active slot's partitions first
(androidboot.slot_suffix from the kernel command line): for a signed
image only the running TZ's own slot is guaranteed to load. An mbn line
may give '-' instead of a hash, which means structural verification
only: ELF64 header, every segment present at the size its program header
declares, page-aligned offsets, a sane total. The loader in TZ verifies
the signature and the per-segment hashes itself and refuses a damaged or
foreign image (one flipped byte -> ERROR_ELF_SIGNATURE_ERROR, measured),
so the whole-image hash added fragility and no protection. A real sha256
is still honoured, and the sha256 of what was installed is logged either
way.

--refresh re-derives mbn dests even when a file exists, replacing it
only with an image that verifies; consumers call it from
post-install/post-upgrade so a fresh 'apk add' needs no reboot and a
hand-placed or wrongly pinned trustlet is replaced on the next upgrade.

Verified on the dev phone (busybox): malformed inputs are refused with a
reason (missing, truncated or oversize segment; non-ELF, ELF32 or short
mdt; a garbage offset), both slots reassemble to the known-good hash, a
foreign file survives a plain run and is replaced by --refresh, a failed
refresh keeps the old file, pins still work, and the real post-upgrade
path re-derived the installed trustlet with the daemon restarting on it.
Record: fp6 repo journal/blobs/ and journal/fingerprint/, 2026-09-11.
2026-09-11 13:03:22 +02:00
..
APKBUILD fp6-vendor-blobs 1-r3: extract from the active slot, and stop pinning a hash on a signed image 2026-09-11 13:03:22 +02:00
fp6-vendor-blobs-extract fp6-vendor-blobs 1-r3: extract from the active slot, and stop pinning a hash on a signed image 2026-09-11 13:03:22 +02:00
fp6-vendor-blobs.post-upgrade aports: extract vendor blobs before udev coldplug so first-boot audio fully works 2026-08-29 21:53:02 +02:00
fp6-vendor-blobs.preset fp6-vendor-blobs: ship a systemd preset so the unit stays enabled 2026-08-28 00:57:56 +02:00
fp6-vendor-blobs.service aports: extract vendor blobs before udev coldplug so first-boot audio fully works 2026-08-29 21:53:02 +02:00