Files
fingerprint-switch/VALIDATION.md
T

2.7 KiB

Validation — 2026-09-20

Host: Aurora 44; libfprint 1.94.100-1.fc44; fprintd 1.94.5-5.fc44.

Completed:

  • cargo build --release --offline --locked — passed; executable at target/release/fingerprint-switch.
  • cargo test --offline --locked — 24 passed: 12 private-D-Bus lifecycle tests, 8 routing tests, 3 reader-selection tests, 1 CLI validation test. Mock buses require permission to create local sockets. They do not use the system fprintd or write biometrics.
  • cargo clippy --all-targets --offline --locked -- -D warnings — passed.
  • cargo fmt --check — passed.
  • Shell syntax checks and ShellCheck for both installer scripts — passed.
  • systemd-analyze verify — passed for temporary copies of both service units and the fprintd drop-in together. The staged unit's executable path was replaced with the built workspace binary solely for this check. Nothing was installed.
  • Final release probe --sensor external — real Microarray reader opened and released successfully through fprintd; no enrollment.
  • Final release probe --sensor internal — real Goodix reader opened and released successfully through fprintd; no enrollment.
  • Final release status — detected both readers, open lid, and selected Goodix for CLI auto mode. Goodix still listed its three existing finger enrollments; Microarray listed none.
  • ELF interpreter and dependencies resolve to system /lib64 libraries, so the binary does not depend on a Homebrew path hidden by the systemd service's ProtectHome setting.

Not yet performed:

  • Real enrollment, matching and rejection with a person touching each sensor.
  • Installing/starting the watcher or changing host authentication configuration.
  • Physical lid-close/open and USB-unplug routing with the installed service.

The tests validate policy and error handling; they do not establish fingerprint matching accuracy or prove the uninstalled system integration end to end.

Suggested hands-on check after enrollment and opt-in installation:

  1. Verify the enrolled finger on each reader using explicit CLI selection while both readers are exposed (mode both if the watcher is installed).
  2. Check rejection with a different, unenrolled finger on each reader.
  3. Set mode auto, keep the lid open and confirm list exposes Goodix.
  4. Close the lid while docked and awake; confirm Microarray is exposed and can authenticate. Existing system power settings still determine suspend behavior.
  5. Reopen the lid and confirm Goodix returns. Unplug the USB reader and check fallback. Keep a password-based session available while testing.
  6. Verify an ordinary configured fingerprint authentication flow, such as the screen lock or sudo, then test the uninstall script if rollback is desired.