On Monday, October 10, 2016 at 8:34:19 PM UTC-4, David Shleifman wrote:
> On Oct. 10, 2016 at 9:27 AM, Unman <[email protected]> wrote
> 
> > I wouldn't assign back to dom0.
> > There's no reason why you shouldn't adopt some variation on A, and have
> > different qubes handling different controllers. Of course, you'd have to
> > make sure that you follow a consistent pattern with use of sockets.
> > You could enforce this with configuration in the policy file, and by
> > some udev rules to block anything except storage devices in the relevant
> > ports.
> 
> > unman
> 
> -------------------------------------------------------------------------
> 
> 
> 
> Before trying either "A" or "B" direction, I've stumbled upon the following 
> difficulty:- after booting, Xfce popes up a dialog box which invites user to 
> log in.  At this time, sys-usb hasn't started yet.  That is why, the USB 
> keyboard is not operational.  In essence, it is a chicken and egg problem: in 
> order to enter a password, the sys-usb VM shall be started; in order to start 
> the sys-usb VM, a valid password shall be entered.  
> 
> 
> 
> Unman> There's no reason why you shouldn't adopt some variation on AI was 
> leaning to adopt some variation of the plan "A".  Unfortunately, the 
> experience (see previous paragraph) demonstrates that it is not possible :(
> 
> 
> 
> I went forward with the plan "B":
> B-1) Stay with a single sys-usb qube and remove rear.OHCI0 controller from 
> sys-usb (using Qubes VM Manager).  I assume that the controller will be 
> returned back to dom0.  Is it correct?B-2) Remove "sys-usb dom0 
> ask,user=root" from /etc/qubes-rpc/policy/qubes.InputKeyboard.
> B-3) Remove "sys-usb dom0 ask,user=root" from 
> /etc/qubes-rpc/policy/qubes.InputMouse.
> 
> B-4) Remove rd.qubes.hide_all_usb from /etc/default/grub and run
> grub2-mkconfig -o /boot/grub2/grub.cfg in dom.  
> 
>  
> With this plan in place, I am able to log in using the USB keyboard.  
> 
> 
> 
> Further enhancements
> --------------------
> * In the step B-4, it would be nice to hide all USB controllers from dom0 
> except rear.OHCI0.  How to achieve this?
> 
> Unman> Of course, you'd have to make sure that you follow a consistent 
> pattern with use of sockets.  You could enforce this with configuration in 
> the policy file, and by some udev rules to block anything except storage 
> devices in the relevant ports. 
> * How to achieve this?  Is there some manual?  Do you mind to share an 
> example?
> 
> 
> * Correct the policy in 
> https://www.qubes-os.org/doc/usb/#how-to-use-a-usb-keyboard manual.  It 
> should be:
> 
> sys-usb dom0 ask,user=root

go with B1 man.  Like I said you can  get a ps2 adapter for your usb keyboard 
and then can have all controllers in the sys-usb if you want. But I don't think 
there is anything to be worried about having your keyboard in dom0.  Unless you 
got a real sketchy kb. (anything is possible)

As for how to hide all usb controllers except the rear OHCI0, you can't unless 
its on a separate controller.  Otherwise just add every other controller to 
sys-usb except the OHCI0 one.  Again to make sure you are correctly identifying 
your controller https://www.qubes-os.org/doc/assigning-devices/   You test with 
a device plugged in the port to identify the controller.

You can also just go into a vm settings and click on devices to get a list.  
look for what says usb, to see how many controllers you actually have.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/8edf0d77-78b2-4be7-b365-e8c88df19cd6%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to