• 15 Posts
  • 259 Comments
Joined 1 year ago
cake
Cake day: June 30th, 2025

help-circle
  • Not sure why you are asking this in a linux phone community but this is the generative AI policy of flathub, pretty much the store for linux phones:

    Generative AI policy

    Submitters must disclose any AI-generated code, documentation, packaging, or other material they know or reasonably believe is included in the application or its Flathub packaging. The disclosure must identify the affected parts and approximate extent.

    Flathub manifests must not contain AI-generated or AI-assisted content. Disclosure does not exempt manifests from this restriction.

    AI used only for research, discussion, or debugging does not need disclosure when no generated material is included in the application or its Flathub packaging. Other disclosed AI-generated material is evaluated at reviewer discretion. Reviewers may reject a submission, including without further review, based on the extent or role of generated material or concerns about its review, quality, or maintainability. Disclosure does not create a presumption of acceptance.

    AI tools or agents must not open or automate Flathub submission pull requests, or generate their commit messages, descriptions, review comments, or replies. Submitters must not request AI-agent reviews.

    Undisclosed or materially misrepresented AI-generated material, or prohibited AI-generated submission or review interactions, may result in rejection. Repeated violations may result in a permanent ban from future submissions and activities.

    https://docs.flathub.org/docs/for-app-authors/requirements#generative-ai-policy

    In general also outside AI specifically the requirements are pretty strict.











  • Yes that is possible in the technical sense, possible in the sense that i can make it idk.

    A big part of it is regulation i believe, i also don’t know it fully so take this with a grain of salt but i believe there is alot of regulation that must make it so that users are not allowed to modify the radio, now i think this doesn’t forbid open source but it does forbid the user being able to actually change it, as far as i understand atleast.



  • Not exactly,

    fingerprintd really is a package for FP6 style devices, adding support for different devices to it will require alot of work, not sure if i would call it a rewrite as the better approach is probably a new package for this hardware that provides the same interface.

    For imsd the story is different, most of it is ims code that doesn’t care what the underlying hardware is, adding another modem type here is not alot of work, but i was also looking for a QMI compatible modem in which case it will just work with minimal changes.



  • I wasn’t trying to deflect my apologies, it was a genuine question if such audits are the norm, and if so i would hope it to be possible to do such an external security audit for a reasonable price.

    If we are talking about external surface like the phone being seized no i don’t think so, fingerprintd is pretty much the coupling between the trustlet and userspace, it only authenticates once the trustlet says so, so any attack surface lies in the trustlet, which sadly is closed source.

    Fingerprintd is in control of the size of this surface however as it passes arguments that control it, i will make these arguments user configurable so users can decide for themselves.